Redundant Processor Architecture for ASIL-D Fault Tolerance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multiprocessor architectures are inadequate for meeting the requirements of autonomous vehicles, particularly in implementing ASIL-D specifications and ensuring fault-tolerant execution of safety functions without shutting down components.
Innovation Solution
A fault-tolerant system with a dual processor architecture featuring triple redundancy, where each processor has multiple cores and a controller to compare results, allowing for identification and deactivation of defective cores and ensuring continuous operation by redistributing sensor signals and procedures across cores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multiprocessor architectures are used, then system complexity is reduced, but reliability and fault tolerance for ASIL-D specifications cannot be achieved
Solution Approach 1:
The system is divided into multiple independent processors (first processor with first and second cores, second processor with first and second cores), each capable of executing safety functions independently. This segmentation enables fault isolation where a failure in one core does not affect other cores or processors, achieving ASIL-D fault tolerance while maintaining manageable architectural complexity through modular design.
Solution Approach 2:
Each processor core is equipped with dedicated comparison logic and controller that locally monitors and compares results from core executions. The first processor's controller compares results between its first and second cores, while the second processor's controller performs similar comparisons. This local quality approach enables distributed fault detection and tolerance without requiring centralized complex monitoring systems.
2Reliability
If components are deactivated upon error detection, then system reliability is improved, but availability decreases due to complete system shutdown
Solution Approach 1:
The system dynamically adjusts its operational state based on detected faults. When an error is detected in one core, the system does not shut down completely but rather dynamically reconfigures by deactivating only the defective core while keeping other cores and processors operational. The controller identifies the defective core and redirects task execution to functional cores, maintaining system availability while ensuring safety functions continue to execute reliably.
Solution Approach 2:
The system performs beforehand cushioning by executing procedures multiple times on different cores and comparing results before any fault occurs. The redundant comparison logic is pre-configured to detect discrepancies and trigger appropriate responses. This prior cushioning ensures that when faults do occur, the system already has mechanisms in place to maintain operation, preventing complete shutdown and preserving availability.
3Productivity
If triple redundancy is implemented with multiple cores, then system availability is increased, but device complexity increases
Solution Approach 1:
Each processor core is designed with universal functionality to execute the same safety procedures, allowing any functional core to take over the role of any other core. The first and second cores of the first processor, along with the first and second cores of the second processor, are all capable of executing the same safety functions. This multi-functionality enables flexible fault tolerance where any core can serve as backup for another, increasing availability without requiring specialized redundant components.
Solution Approach 2:
The system merges the comparison and control functions into integrated controllers that manage multiple cores. The first processor's controller combines result comparison between first and second cores with the ability to identify defective cores and redirect execution. Similarly, the second processor's controller merges comparison and control functions. This merging reduces the need for separate dedicated comparison hardware, achieving triple redundancy while minimizing additional complexity.
Data Source
AI summary
The present disclosure relates to an assembly including a first processor having a first core, a second core and a controller, and a second processor having a first core, and wherein the first core and the second core of the first processor, and the first core of the second processor are configured to execute a first procedure. The controller of the first processor is configured to compare a first result from executing the first procedure on the first core of the first processor with a second result from executing the first procedure on the second core of the first processor; and comparing each of the first and second results with a third result from executing the first procedure on the first core of the second processor, if the first and second results differ from one another.
