Serialized Vehicle Safety Computing for Autonomous Failover Stop
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated vehicles face challenges in ensuring safe operation after a critical component, such as a vehicle computing platform, fails, as they are unable to perform necessary calculations for safe navigation.
Innovation Solution
Implementing a vehicle safety system with serialized or combined serial-parallel computing architectures that allow for automated safety response measures, including generating and sending vehicle control commands to ensure a safe stop, even after a computing platform failure, by utilizing future trajectory information and sensor data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a vehicle computing platform fails, then the vehicle loses the ability to perform computationally intensive calculations for safe autonomous operation, but the vehicle safety system can take over to ensure continued safe operation for a limited period
Solution Approach 1:
The computing architecture is segmented into distinct functional components: a main vehicle computing platform for normal autonomous operations and a separate vehicle safety system for failure response. This segmentation allows the safety system to independently handle critical safety functions without being dependent on the main platform's continuous operation.
Solution Approach 2:
The vehicle safety system receives and stores future trajectory information in advance from the main computing platform before any failure occurs. This preliminary action ensures that when the main platform fails, the safety system immediately has the necessary navigation data to continue safe operation without requiring real-time calculations.
2Loss of time
If the vehicle uses a serialized computing architecture with separate safety system, then the safety response time is improved, but the overall system complexity increases
Solution Approach 1:
The safety-critical functions are extracted from the main computing platform and placed into a dedicated vehicle safety system. This extraction eliminates the need for complex inter-process communication and failover mechanisms, allowing the safety system to respond immediately to failures without being burdened by the complexity of integrated systems.
Solution Approach 2:
The vehicle safety system acts as an intermediary between the main computing platform and the vehicle actuation systems. It receives trajectory information from the main platform and sends control commands to actuators, simplifying the architecture by providing a clear, dedicated communication path that reduces response time.
3Reliability
If the vehicle safety system utilizes stored trajectory information, then the ability to maintain safe operation after failure is improved, but the duration of safe operation is limited by the stored information period
Solution Approach 1:
The main computing platform continuously provides future trajectory information to the vehicle safety system in advance, allowing the safety system to build up a buffer of navigation data. This preliminary action ensures that when failure occurs, the vehicle can operate safely for the duration of the stored trajectory information without immediate human intervention.
Data Source
AI summary
Described herein are systems, methods, and non-transitory computer-readable media for implementing automated vehicle safety response measures to ensure continued safe automated vehicle operation for a limited period of time after a vehicle component or vehicle system that supports an automated vehicle driving function fails. When a critical vehicle component/system such as a vehicle computing platform fails, the vehicle is likely no longer capable of performing calculations required to safely operate and navigate the vehicle in an autonomous manner, or at a minimum, is no longer able to ensure the accuracy of such calculations. In such a scenario, the automated vehicle safety response measures disclosed herein can ensure - despite failure of the vehicle component/system -continued safe automated operation of the vehicle for a limited period of time in order to bring the vehicle to a safe stop.


