Vehicle Failure Tier Control for Safe Autonomous Degradation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle control systems for autonomous and semi-autonomous vehicles lack effective management and analysis of system or component failures, which can lead to inadequate corrective actions and safety issues, especially in scenarios where immediate shutdown is not feasible or desirable, such as with freight-bearing vehicles on shared roadways.
Innovation Solution
A vehicle control system comprising task nodes, an aggregator node, and a behavior planning node that implements a tiered failure mode framework to monitor, manage, and respond to failures in real-time, enabling safe and responsible degeneration of autonomous vehicle operation by raising failure flags, determining failure tiers, and executing appropriate actions, including irreversible or reversible stops.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If immediate shutdown is implemented upon system or component failure, then safety response time is improved, but operational continuity and economic loss are worsened
Solution Approach 1:
The system dynamically adjusts the shutdown response based on failure severity. For critical failures, immediate shutdown is executed to ensure safety. For non-critical failures, the system maintains operational continuity by switching to degraded modes or alternative components, thus resolving the contradiction between safety response time and operational continuity
Solution Approach 2:
The failure management system segments failures into different severity levels (critical, major, minor). This segmentation allows differentiated response strategies: critical failures trigger immediate shutdown while non-critical failures allow continued operation with monitoring, thereby balancing safety requirements with operational continuity
2Reliability
If comprehensive monitoring and logging of all components is implemented, then failure traceability is improved, but system complexity and computational load are worsened
Solution Approach 1:
The monitoring system segments components by their criticality level and implements differentiated monitoring strategies. Critical components receive comprehensive monitoring and logging, while non-critical components receive reduced monitoring. This segmentation maintains high failure traceability for essential systems while reducing overall system complexity
Solution Approach 2:
The system applies different monitoring intensities to different components based on their local importance to safety and operation. High-criticality components have detailed monitoring with high sampling rates and extensive logging, while low-criticality components have minimal monitoring, thus achieving effective failure traceability without uniform complexity across all systems
3Reliability
If immediate shutdown is implemented upon failure, then safety is improved, but harmful effects from sudden stops are worsened
Solution Approach 1:
The shutdown process is dynamically controlled based on the vehicle's current state and failure type. The system adjusts deceleration rates, steering angles, and brake application forces in real-time to minimize harmful effects while maintaining safety. This dynamic control allows safe shutdown without the abrupt stops that cause harm
Solution Approach 2:
The system prepares cushioning measures before actual shutdown occurs. When a failure is detected, the system first activates safety nets such as redundant components, then gradually reduces system load, and finally executes controlled shutdown. This beforehand cushioning prevents the harmful effects of sudden stops while maintaining safety throughout the process
Data Source
AI summary
A vehicle control system for controlling a vehicle, including a set of task nodes, wherein each of the set of task nodes compares a failure criterion to input to the task node to generate a failure flag and provides output to at least one other task node of the set of task nodes; an aggregator node directly communicatively coupled to each of the set of task nodes, and wherein the aggregator node: receives a set of failure flags from the set of task nodes, determines a failure tier based on the set of failure flags, and generates a failure tier message defining the failure tier; and, a behavior planning node communicatively coupled to the aggregator node, wherein the behavior planning node: receives the failure tier message, and in response to the failure tier defined by the failure tier message, generates vehicle control instructions.


