Vehicle Control Unit Redundancy for Network Failure Degradation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional automated driving systems face challenges in transitioning control back to the driver safely and efficiently, particularly in ensuring error-tolerant safety-relevant functions that maintain vehicle functionality even in the event of network failures.
Innovation Solution
A control system with independently redundant communication and low-voltage networks, along with a degradation device for diagnosing errors and selectively degrading control units, ensuring continued functionality for safe vehicle operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single communication network and single low-voltage network are used, then the device complexity is reduced, but the reliability deteriorates because the system becomes vulnerable to network failures that could compromise safety-relevant functions
Solution Approach 1:
The communication system is segmented into two independently redundant communication networks (first and second communication networks), each capable of transferring messages between control units. Similarly, the electrical supply is segmented into two independently redundant low-voltage networks. This segmentation ensures that a failure in one network does not compromise the entire system, as the other network can maintain functionality of safety-relevant control units.
Solution Approach 2:
The system implements beforehand cushioning by providing redundant communication and power supply networks before failures occur. The degradation device continuously monitors network status and can selectively degrade (shut down) non-critical control units when a network failure is detected, ensuring that safety-relevant functions remain protected and operational throughout the error state.
2Reliability
If control units are selectively shut off during network failure, then the reliability of remaining functions is improved, but the productivity deteriorates due to reduced vehicle functionality
Solution Approach 1:
The degradation device implements partial action by selectively shutting down only those control units that are not safety-relevant when a network failure occurs. Non-critical control units are degraded (shut down) to prevent error propagation, while safety-relevant control units maintain full functionality through the redundant network. This approach ensures the vehicle can still perform essential safety functions while non-essential functions are temporarily reduced.
3Productivity
If the system maintains full functionality during errors, then the productivity is preserved, but the reliability deteriorates because errors can propagate through the system causing sudden function loss
Solution Approach 1:
The degradation device extracts and isolates non-safety-relevant control units from the active network when a failure is detected. By taking these non-critical control units out of operation (degrading them), the system prevents potential error propagation while maintaining continuous operation of safety-relevant functions through the redundant communication and power supply networks.
Data Source
AI summary
A control unit for a vehicle. The control unit includes: interfaces for the connection to two independently redundant communication networks, messages to and from the control unit being transferrable via a second communication network, and vice versa, in the event of a failure of a first communication network; and interfaces for the electrical supply of the control unit via two independently redundant low-voltage networks. it being possible to electrically supply the control unit via a second low-voltage network, and vice versa, in the event of an error in a first low-voltage network.

