Vehicle Control Redundancy for Communication and Power Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle control systems lack sufficient redundancy in communication and power networks, which can lead to sudden failures in critical functions like braking and steering, especially during automated driving.
Innovation Solution
A control system with independently redundant communication and low-voltage networks, along with a diagnostic module that selectively degrades non-critical systems to maintain minimum functionality for safety-relevant systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vehicle control systems use single communication and power networks, then device complexity is reduced, but reliability deteriorates due to sudden failures in critical functions
Solution Approach 1:
The vehicle's communication and power supply systems are segmented into multiple independent redundant networks. Each network operates separately with galvanic isolation, allowing the system to maintain functionality even if one network fails. This segmentation directly addresses the reliability improvement while managing complexity through modular architecture.
Solution Approach 2:
The system implements beforehand cushioning by preparing backup communication and power networks in advance. When a failure is detected in one network, the system can immediately switch to the redundant network without sudden functional loss. This prior preparation ensures critical functions like braking and steering remain operational, resolving the reliability-complexity contradiction.
2Reliability
If all electrical consumers remain operational during network failures, then function availability is maintained, but energy consumption increases and system stability deteriorates
Solution Approach 1:
The control device selectively switches off non-critical electrical consumers when network failures are detected, maintaining only the minimum necessary functionality for safety-relevant systems. This partial action approach ensures system stability by reducing load on the remaining functional network while consuming less energy, directly addressing the contradiction between reliability and energy usage.
Solution Approach 2:
Different electrical consumers are treated differently based on their criticality. Safety-relevant systems maintain full operational quality, while non-critical consumers are switched off or degraded. This local quality differentiation allows the system to stabilize the network by managing energy consumption selectively without compromising essential functions.
3Ease of operation
If the system maintains full functionality of all consumers during failures, then serviceability is improved, but the ability to maintain minimum safety functionality deteriorates when resources are limited
Solution Approach 1:
The system dynamically adjusts the operational status of electrical consumers based on real-time network conditions and failure scenarios. The control device can switch between different operational modes: full functionality when all networks are operational, and selective degradation when failures occur. This dynamic adaptability ensures that minimum safety functionality is maintained while preserving serviceability of critical systems.
Solution Approach 2:
The control device continuously monitors the status of communication and power networks, using this feedback information to make informed decisions about which electrical consumers to switch off or degrade. This feedback mechanism ensures that the system maintains minimum safety functionality by prioritizing critical consumers while managing limited resources effectively, resolving the contradiction between serviceability and reliability.
Data Source
Figure 1
Figure 2~3
AI summary
Control device (5; 6; 7; 8; 10) for a vehicle, having: - interfaces (5a...5d; 6a...6d; 7a...7d; 8a...8d) for connection to two independently redundant communication networks (KN1, KN2), wherein, as a result of failure of a first communication network (KN1), messages can be transmitted to and from the control device (5; 6; 7; 8; 10) via a second communication network (KN2) and vice versa; and - interfaces for supplying the control device (5; 6; 7; 8; 10) with electricity via two independently redundant low-voltage networks (NN1, NN2), wherein in the event of a fault in a first low-voltage network (NN1), the control device (5; 6; 7; 8; 10) can be supplied with electricity via a second low-voltage network (NN2) and vice versa.