Teleoperation Safety Architecture for Autonomous Vehicle Fallback Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face challenges in navigating unknown or hazardous environments without human input, particularly at autonomous driving levels 3 to 5, where traditional methods like handing control back to a passenger may not be feasible.

Innovation Solution

The implementation of an end-to-end safety architecture that uses a layered safety policy monitoring system, allowing for remote control of autonomous vehicles while ensuring safety through viable and safe command validation, and enabling minimum risk maneuvers in case of communication disruptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional disjoint architectures are used for remote systems and autonomous vehicles, then system design flexibility is maintained, but safety reliability and communication consistency deteriorate

Engineering Contradiction:
ImprovesafetyVSAvoidarchitecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the remote system architecture and autonomous vehicle architecture into a unified end-to-end safety architecture. This integration ensures consistent safety policies across both systems, improving reliability by eliminating communication inconsistencies and security vulnerabilities associated with disjoint architectures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal safety policy framework that serves multiple functions: it validates operator commands, monitors communication integrity, ensures security compliance, and coordinates fallback maneuvers. This multi-functional approach maintains design flexibility while improving safety through a single cohesive architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If layered safety policy monitoring is implemented, then command accuracy and safety are improved, but system complexity increases

Engineering Contradiction:
Improvecommand accuracyVSAvoidsystem
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments safety monitoring into distinct layers: operator command validation layer, communication integrity layer, and vehicle execution layer. Each layer handles specific safety checks independently, improving command accuracy through systematic validation while managing complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary safety policy monitors that act as mediators between the remote operator, communication systems, and autonomous vehicle. These intermediaries validate commands and filter unsafe operations before execution, improving command accuracy while centralizing complexity management in dedicated safety components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If remote control is used for autonomous vehicles, then operational versatility is improved, but communication latency and safety risks increase

Engineering Contradiction:
ImproveoperationalVSAvoidsafety
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary safety validation of operator commands before transmission to the autonomous vehicle. The safety policy framework pre-checks command feasibility and safety implications, preventing unsafe commands from being executed even if communication latency occurs, thus maintaining safety while enabling remote operational versatility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent prepares fallback maneuvers and safety protocols in advance, cushioning against potential communication failures or latency issues. When remote control is used, pre-planned safety measures are ready to activate if communication disruptions occur, maintaining operational versatility while protecting against safety risks.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Reliability

If communication disruptions occur, then system robustness is tested, but operational safety and control reliability deteriorate

Engineering Contradiction:
ImprovecontrolVSAvoidcommunication disruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback mechanisms that monitor communication status between remote systems and autonomous vehicles. When disruptions are detected, the feedback loop triggers safety protocols and fallback maneuvers, maintaining control reliability by automatically responding to communication issues rather than allowing them to compromise safety.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes operational parameters dynamically based on communication status. When communication is reliable, remote control parameters are optimized for versatility. When disruptions occur, parameters shift to prioritize safety, activating pre-planned fallback maneuvers and reducing operational complexity to maintain control reliability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250068160A1Teleoperation architectures for autonomous systems and applications
Publication Date: 2025.02.27 NVIDIA CORP
  • US20250068160A1 patent drawing
  • US20250068160A1 patent drawing
  • US20250068160A1 patent drawing

AI summary

In various examples, teleoperation architectures for safe control of machines are described. Systems and methods are disclosed that use an end-to-end safety architecture that covers both a vehicle or machine and a remote system providing a control center, where the vehicle or machine is at least partly or temporarily configured for control by the remote system. In some examples, the end-to-end architecture uses a layered safety policy monitoring system, where the remote system uses first policies to ensure that operator commands are viable and the vehicle uses second policies to ensure that the operator commands are safe to perform (e.g., will not cause collisions with other objects). Additionally, in some examples, the end-to-end architecture allows for the vehicle to perform minimum risk maneuvers, also referred to as “control fallbacks,” if problems were to occur.