Vehicle Controller Grouping for Non-Redundant Fail-Safe Driving Assistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fail-safe E/E architectures for automated driving require redundant configurations of controllers and actuators to maintain operation in case of failures, leading to increased complexity and resource overhead.
Innovation Solution
A network topology is implemented where multiple controllers share operating functions and are divided into groups, allowing for equivalent operation functions to be maintained through non-redundant backup by other controllers in case of failures, using network communication to switch to failure modes until the driver resumes control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a redundant configuration of controllers and actuators is used to maintain operation in case of failures, then the reliability of the automated driving system is improved, but the device complexity and resource overhead increase
Solution Approach 1:
The patent applies multi-functionality by enabling normal controllers to perform both their primary functions and backup functions. When a failure occurs, normal controllers dynamically switch to providing backup operations, allowing the same hardware to serve multiple purposes without requiring dedicated redundant components for each failure scenario.
Solution Approach 2:
The patent merges the backup function into the normal controller group rather than maintaining separate redundant controllers. The control system integrates failure detection, failure information transmission, and backup execution capabilities into the existing controller architecture, combining multiple functions into a unified system that reduces overall complexity.
2Reliability
If multiple controllers are configured to share operating functions, then the reliability is improved, but the number of sensors, controllers, and actuators increases
Solution Approach 1:
The patent implements dynamic controller grouping where controllers can transition between normal and backup roles based on system state. The controller groups are not fixed but can be reconfigured dynamically when failures occur, allowing the same physical controllers to adapt their functional roles rather than requiring static redundant hardware configurations.
Solution Approach 2:
The normal controllers perform self-service by automatically detecting failures, transmitting failure information, and executing backup operations when needed. The system uses its existing resources to provide backup functionality without requiring external or dedicated backup components, allowing controllers to serve themselves and the system in multiple capacities.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
When a failure occurs in any one of a plurality of controllers installed in a vehicle, an operation function is realized that is equivalent to the operation function that is lost due to the failure without resorting to a redundantly configured control system. Then, based on an architecture that realizes equivalent operation functions with each controller group, a plurality of on-board controllers (1-7, 21-26) are divided into a first controller group (A) and a second controller group (B) to construct a network topology. In the method for controlling a driving assisted vehicle, it is determined whether a failure has occurred in any one of the plurality of controllers (1-7, 21-26). Upon determining that a failure has occurred in any one of the plurality of controllers (1-7, 21-26), failure information is sent to a normal controller group other than a failed controller group to which the failed controller belongs via a network communication line. When the normal controller group receives the failure information via the network communication line, the controllers constituting the normal controller group execute a failure mode for backing up the operation function of the failed controller group.