Safety Companion Monitoring for Automated Driving Compute Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated driving systems face challenges in ensuring safety and compliance with safety standards while being cost-effective and efficient, particularly due to the complexity and cost of implementing run-time failure mitigation capabilities and modular redundancy in hardware components.
Innovation Solution
A bifurcated system architecture is introduced, comprising an automated driving compute subsystem and an independent safety companion subsystem, where the safety companion subsystem independently monitors the compute hardware and applications for run-time failures, allowing for cost-effective and modular safety monitoring that meets safety standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If run-time failure mitigation capabilities and modular redundancy are implemented in hardware components, then safety and compliance with safety standards are improved, but device complexity and cost increase
Solution Approach 1:
The system is divided into two independent subsystems: an automated driving compute subsystem that performs driving tasks, and a safety companion subsystem that independently monitors the compute subsystem. This segmentation allows safety monitoring to be handled by a separate, simpler module rather than embedding complex redundancy in every hardware component, thus improving safety while managing device complexity.
Solution Approach 2:
The safety companion subsystem acts as an intermediary that independently monitors the compute subsystem for run-time failures. This intermediary approach enables safety monitoring without requiring complex redundancy built into the primary compute hardware, resolving the contradiction between safety and device complexity.
2Reliability
If run-time failure mitigation capabilities and modular redundancy are implemented in hardware components, then safety and compliance with safety standards are improved, but cost increases
Solution Approach 1:
By segmenting the system into a compute subsystem and a separate safety companion subsystem, the patent enables independent development and optimization of each component. The safety companion can be implemented as a more cost-effective modular unit compared to embedding full redundancy in the primary compute hardware, thus improving safety while reducing overall system cost.
Solution Approach 2:
The safety companion subsystem creates a simplified copy or model of the compute subsystem's critical functions for monitoring purposes only. This copying approach allows safety monitoring without duplicating the entire expensive compute hardware, achieving safety compliance at lower cost.
3Device complexity
If a unified system architecture is used for both driving computation and safety monitoring, then integration is simplified, but development timeline and optimization capability are reduced
Solution Approach 1:
The system is segmented into independent compute and safety monitoring subsystems that can be developed, tested, and optimized separately. This segmentation enables parallel development timelines for each subsystem while maintaining clear integration interfaces, thus improving productivity without sacrificing integration simplicity.
Solution Approach 2:
The safety companion subsystem is designed with universal monitoring capabilities that can independently assess the compute subsystem's safety status. This universal design allows the safety module to be developed independently while still providing comprehensive safety monitoring, improving development speed without complicating integration.
Data Source
AI summary
An automated driving system includes a security companion subsystem to access data generated at a compute subsystem of the automated driving system, which indicates a determination by the compute subsystem associated with an automated driving task. The security companion subsystem determines whether the determination is safe based on the data. The security companion subsystem is configured to realize a higher safety integrity level than the compute subsystem.


