Fail-Operational Vehicle Controller Redundancy via Safety Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Fail-operational systems in vehicles face challenges in managing simultaneous failures of primary and secondary controllers, leading to potential safety hazards and system instability.
Innovation Solution
Implementing a redundant configuration for controllers to perform cross-checks and transfer control to a safety controller upon detection of a common fault, ensuring vehicle functions like propulsion, braking, and steering can be maintained even when primary and secondary controllers fail simultaneously.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a redundant configuration with primary and secondary controllers is implemented, then system reliability is improved, but device complexity increases
Solution Approach 1:
The control system is segmented into distinct functional units: primary controller, secondary controller, and safety controller. Each controller handles specific functions and can operate independently, allowing the system to maintain reliability through distribution while managing complexity through modular architecture
Solution Approach 2:
A control module acts as an intermediary that manages the interaction between primary and secondary controllers. This mediator coordinates cross-checks, monitors fault conditions, and orchestrates control transfers, thereby improving reliability through coordinated redundancy while containing complexity within a dedicated management component
2Measurement precision
If cross-checks between primary and secondary controllers are performed, then detection precision is improved, but device complexity increases
Solution Approach 1:
The cross-check functionality is merged into the control module, which consolidates the monitoring and comparison logic in a single location. This allows precise fault detection through coordinated verification of primary and secondary controllers while managing complexity by centralizing the check logic rather than distributing it across multiple independent components
3Reliability
If control transfer to safety controller is implemented upon common fault detection, then system reliability is improved, but device complexity increases
Solution Approach 1:
The safety controller is pre-configured and positioned in standby readiness before any fault occurs. The control module is pre-programmed with fault detection logic and transfer protocols, enabling immediate action upon fault detection without requiring complex real-time decision algorithms, thus improving fail-operational capability while managing architecture complexity through advance preparation
Data Source
AI summary
Methods and systems for compensating for common failures in fail operational systems are described herein. An example system may include a primary controller configured to perform functions of a vehicle such as propulsion, braking and steering and a secondary controller configured in a redundant configuration with the primary controller. The controllers may perform cross-checks of each other and may each perform internal self-checks as well. Additionally, the system may include a control module configured to transfer control of the vehicle between the controllers based on detecting a fault. The control module may detect a common fault of the controllers that causes the control module to output a common fault signal. In response, the system may transfer of control to a safety controller configured to perform the vehicle functions until the system may transfer control back to the primary controller.


