Redundant Vehicle Controller Switching Without a Central Arbitrator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicle architectures face challenges in seamlessly switching between redundant systems during failures, which can lead to unsafe vehicle control if the backup system does not engage quickly enough, potentially causing collisions or other dangers.
Innovation Solution
A redundant vehicle control system with multiple control units operating in macro-lockstep, each executing the same control routine, allows vehicle subsystems to independently arbitrate based on self-reported health scores to select the healthiest processor for control, eliminating the need for a central arbitrator and ensuring seamless transition in case of failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a central arbitrator is used to switch between redundant control units, then the switching logic is centralized and simplified, but the system introduces a single point of failure that compromises safety
Solution Approach 1:
The patent removes the central arbitrator from the system architecture. Instead of having a dedicated switching component, the arbitration function is extracted and distributed to the control units themselves, which independently evaluate their own health status and initiate switching without external coordination, thereby eliminating the single point of failure while maintaining switching capability
Solution Approach 2:
The centralized arbitration function is segmented and distributed across multiple control units. Each control unit independently performs health assessment and switching decisions, transforming a monolithic arbitration system into a distributed architecture where no single component controls the entire switching process, thus improving reliability through redundancy
2Reliability
If health monitoring is implemented to enable seamless switching, then safety and reliability are improved, but the device complexity and computational overhead increase
Solution Approach 1:
The control units perform self-diagnosis and self-assessment of their own health status without requiring external monitoring systems. Each control unit independently evaluates its operational state, enabling the system to maintain high reliability through distributed self-monitoring while avoiding the complexity of a centralized health monitoring infrastructure
Solution Approach 2:
The health monitoring function is merged with the control units themselves rather than being a separate system. The control units integrate their own health assessment capabilities, combining the control function and monitoring function into a single unified component, thereby reducing overall system complexity while maintaining seamless switching capability
Data Source
AI summary
Safe operation of vehicle controllers is described. In one or more implementations, a system includes a vehicle network, a plurality of edge devices in communication with the vehicle network and operable to implement vehicle operations, and a vehicle control system in communication with the vehicle network and having at least two processors configured to redundantly control the vehicle operations implemented by the edge devices. Each of the processors is operable to self-report a respective processor health to the vehicle network for enabling each edge device to independently arbitrate to be controlled by a healthiest processor.


