Autonomous Vehicle Failover Control for Emergency Safe-State Transition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated driving vehicles lack a reliable mechanism to maintain safety without a human backup level, as existing fault detection and recovery methods rely on redundant components and human intervention when failures occur.

Innovation Solution

A method and device that utilize distributed computational nodes to execute application instances, with a failover apparatus that plans and executes an emergency trajectory to transition the vehicle into a safe state by switching to redundant application instances and using separate signal and control lines, even when redundancy conditions cannot be met or an unrecoverable malfunction is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a human backup level is used to assume control when automated driving fails, then the system can handle unrecoverable malfunctions, but the system cannot ensure safety when no human is available to take over

Engineering Contradiction:
Improvesafety assuranceVSAvoidoperational capability without human backup
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The failover apparatus enables the automated driving system to self-manage safety-critical functions without human intervention. When faults are detected in the automated driving system, the failover apparatus automatically activates redundant application instances and executes emergency trajectories, allowing the system to service itself during critical failures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system prepares redundant application instances and failover mechanisms in advance before failures occur. The redundant computational resources are pre-configured and can be immediately activated when faults are detected, providing a safety cushion that ensures continuous safe operation even when unrecoverable malfunctions occur.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If redundant application instances are switched to when faults are detected, then system continuity is maintained, but redundancy conditions and segregation conditions may not be restored within specified time

Engineering Contradiction:
Improvesystem continuityVSAvoidreconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Redundant application instances are pre-configured and prepared in advance on the computational nodes. When faults occur, the system can immediately switch to these pre-prepared instances without needing to create or configure them during the emergency response, significantly reducing reconfiguration time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system prioritizes rapid failover by skipping non-critical reconfiguration steps and directly activating redundant instances. The failover apparatus executes emergency trajectories and safety-critical functions immediately without waiting for full system reconfiguration, ensuring continuity of essential functions within specified time constraints.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If separate signal lines and control lines are used for the failover apparatus, then safety is improved by isolating fault paths, but device complexity increases

Engineering Contradiction:
Improvefault isolationVSAvoidsignal line configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control architecture is segmented into separate signal lines and control lines for the failover apparatus, physically isolating safety-critical communication paths from the main automated driving system. This segmentation ensures that faults in the primary system cannot propagate to the failover apparatus, providing robust fault isolation despite increased wiring complexity.

Inventive Principle:
Principle #1Segmentation

4Reliability

If the vehicle transitions to a safe state by executing an emergency trajectory, then safety is ensured, but the automated driving function is interrupted

Engineering Contradiction:
Improvesafety state transitionVSAvoidautomated driving availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system proactively executes emergency trajectories and safety transitions before the automated driving system can be compromised by undetected faults. By anticipating potential failures and pre-planning safe state transitions, the system ensures safety is maintained while minimizing the duration and impact of automated driving interruptions.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11745748B2Method and device for operating an automatically driving vehicle
Publication Date: 2023.09.05 VOLKSWAGEN AG
  • US11745748B2 patent drawing
  • US11745748B2 patent drawing

AI summary

The disclosure provides a method for operating an automatically driving vehicle, wherein application instances are executed over several computational nodes, wherein recognized faults are reacted to by switching to redundant application instances and then reconfiguring the configuration to restore specified redundancy conditions and/or segregation conditions, wherein the vehicle is transitioned to a safe state using at least one failover apparatus when at least one specified redundancy condition and/or at least one segregation condition cannot be met by the reconfiguration, and/or a specified time for reconfiguration is exceeded, and/or an unrecoverable malfunction has been recognized, wherein the at least one failover apparatus plans an emergency trajectory using a trajectory planner, wherein sensor data are detected via separate signal lines and supplied to the at least one failover apparatus, and wherein control signals are generated and transmitted via separate control lines to an actuator system of the vehicle.