Autonomous Vehicle Failover Control for Emergency Safe-State Transition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated driving vehicles lack a reliable mechanism to maintain safety without a human backup level, as existing fault detection and recovery methods rely on redundant components and human intervention when failures occur.
Innovation Solution
A method and device that utilize distributed computational nodes to execute application instances, with a failover apparatus that plans and executes an emergency trajectory to transition the vehicle into a safe state by switching to redundant application instances and using separate signal and control lines, even when redundancy conditions cannot be met or an unrecoverable malfunction is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a human backup level is used to assume control when automated driving fails, then the system can handle unrecoverable malfunctions, but the system cannot ensure safety when no human is available to take over
Solution Approach 1:
The failover apparatus enables the automated driving system to self-manage safety-critical functions without human intervention. When faults are detected in the automated driving system, the failover apparatus automatically activates redundant application instances and executes emergency trajectories, allowing the system to service itself during critical failures.
Solution Approach 2:
The system prepares redundant application instances and failover mechanisms in advance before failures occur. The redundant computational resources are pre-configured and can be immediately activated when faults are detected, providing a safety cushion that ensures continuous safe operation even when unrecoverable malfunctions occur.
2Reliability
If redundant application instances are switched to when faults are detected, then system continuity is maintained, but redundancy conditions and segregation conditions may not be restored within specified time
Solution Approach 1:
Redundant application instances are pre-configured and prepared in advance on the computational nodes. When faults occur, the system can immediately switch to these pre-prepared instances without needing to create or configure them during the emergency response, significantly reducing reconfiguration time.
Solution Approach 2:
The system prioritizes rapid failover by skipping non-critical reconfiguration steps and directly activating redundant instances. The failover apparatus executes emergency trajectories and safety-critical functions immediately without waiting for full system reconfiguration, ensuring continuity of essential functions within specified time constraints.
3Reliability
If separate signal lines and control lines are used for the failover apparatus, then safety is improved by isolating fault paths, but device complexity increases
Solution Approach 1:
The control architecture is segmented into separate signal lines and control lines for the failover apparatus, physically isolating safety-critical communication paths from the main automated driving system. This segmentation ensures that faults in the primary system cannot propagate to the failover apparatus, providing robust fault isolation despite increased wiring complexity.
4Reliability
If the vehicle transitions to a safe state by executing an emergency trajectory, then safety is ensured, but the automated driving function is interrupted
Solution Approach 1:
The system proactively executes emergency trajectories and safety transitions before the automated driving system can be compromised by undetected faults. By anticipating potential failures and pre-planning safe state transitions, the system ensures safety is maintained while minimizing the duration and impact of automated driving interruptions.
Data Source
AI summary
The disclosure provides a method for operating an automatically driving vehicle, wherein application instances are executed over several computational nodes, wherein recognized faults are reacted to by switching to redundant application instances and then reconfiguring the configuration to restore specified redundancy conditions and/or segregation conditions, wherein the vehicle is transitioned to a safe state using at least one failover apparatus when at least one specified redundancy condition and/or at least one segregation condition cannot be met by the reconfiguration, and/or a specified time for reconfiguration is exceeded, and/or an unrecoverable malfunction has been recognized, wherein the at least one failover apparatus plans an emergency trajectory using a trajectory planner, wherein sensor data are detected via separate signal lines and supplied to the at least one failover apparatus, and wherein control signals are generated and transmitted via separate control lines to an actuator system of the vehicle.

