Safety-Aware Comparator for Redundant Subsystems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Highly Automated Driving (HAD) systems face challenges in identifying and addressing potential safety issues due to systemic errors, particularly in redundant subsystems implementing different algorithms, which can lead to premature disengagement and safety conflicts, as existing methods rely on majority voting that may not detect all safety critical conflicts.
Innovation Solution
A safety-aware comparison method and system that analyzes projected travel paths and object locations from multiple redundant subsystems, using a comparator to determine matches, mismatches, and safety conflicts, and provides appropriate world models or path plans to an arbiter to avoid safety issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If majority voting is used to compare redundant subsystems, then system simplicity is maintained, but safety conflict detection capability deteriorates
Solution Approach 1:
The comparison process is segmented into two distinct stages: first comparing projected travel paths between subsystems, then separately comparing detected object data. This segmentation allows each comparison type to be optimized independently, improving safety conflict detection without overwhelming system complexity.
Solution Approach 2:
An intermediary comparison module is introduced between the redundant subsystems and the arbitration logic. This module performs detailed path and object comparisons, generating structured comparison results that enable more reliable safety conflict detection while keeping the overall system architecture manageable.
2Reliability
If detailed path and object comparison is performed, then safety conflict detection is improved, but computational complexity increases
Solution Approach 1:
The complex comparison task is divided into manageable segments: path projection comparison, object location comparison, object shape comparison, and conflict determination. Each segment processes specific aspects of the data, reducing the cognitive and computational load while maintaining comprehensive safety analysis.
Solution Approach 2:
The system performs preliminary path projections from multiple subsystems before conducting detailed comparisons. By pre-processing and visualizing projected paths, the system prepares data in a form that facilitates more efficient and targeted safety conflict detection in subsequent comparison stages.
3Reliability
If redundant subsystems use different algorithms, then systematic error detection is improved, but agreement between subsystems deteriorates
Solution Approach 1:
The comparison module acts as an intermediary that reconciles differences between subsystems using different algorithms. By systematically comparing paths and objects from heterogeneous subsystems, it identifies systematic errors while providing a unified framework for decision-making, balancing diversity benefits with operational coherence.
Solution Approach 2:
The system implements feedback mechanisms where comparison results from redundant subsystems are fed back into the arbitration process. This feedback loop allows the system to learn from discrepancies between different algorithm implementations, improving systematic error detection while gradually enhancing subsystem agreement through iterative refinement.
Data Source
AI summary
A method, system and device are disclosed for determining safety conflicts in redundant subsystems of autonomous vehicles. Each redundant subsystem calculates a world model or path plan, including locations, dimensions, and orientations of moving and stationary objects, as well as projected travel paths for moving objects in the future. The travel paths and projected future world models are subsequently compared using a geometric overlay operation. If at future time moments the projected world models match within predefined margins, the comparison results in a match. In case of a mismatch at a given future moment between projected world models, a determination is made as to whether the autonomous vehicle and all road users in this future moment are safe from collision or driving off the drivable space or road based on a geometric overlay operation.


