Autonomous Vehicle Redundancy Architecture With Health-Based Output Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional architectures for controlling autonomous vehicles are costly and technically complex due to the need for lockstep systems and high ASIL D components, which are not efficiently addressed by existing redundancy features.
Innovation Solution
A redundant architecture using multiple computing units (CU) and a vehicle control unit (VCU) that determines which outputs to use from redundant sensors and CU computers based on health states and error messages, allowing for efficient operation and safe stopping of the vehicle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If lockstep systems and high ASIL D components are used for autonomous vehicle control, then reliability is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The system divides autonomous vehicle control into multiple independent computing units (CU1, CU2, CU3), each capable of independent operation. Each CU processes sensor data and generates control commands separately, allowing the system to segment the control function while maintaining high reliability through redundancy. This segmentation reduces the complexity of any single unit while achieving ASIL D-level reliability at the system level.
Solution Approach 2:
The system implements beforehand cushioning by pre-configuring multiple redundant computing units and sensor systems before operation. The architecture includes backup CUs and redundant sensor sets that are ready to take over immediately if a failure occurs. This prior preparation ensures reliability without requiring complex real-time decision-making during failures, thereby reducing operational complexity.
2Reliability
If multiple redundant computing units and sensors are deployed, then reliability is improved, but implementation cost increases
Solution Approach 1:
The system dynamically selects which computing units and sensor outputs to use based on real-time health monitoring and performance evaluation. The VCU continuously assesses the state of each CU and sensor, dynamically switching between redundant components as needed. This dynamic approach allows the system to maintain high reliability with fewer active components at any given time, reducing the effective quantity of components needed compared to static redundancy configurations.
Solution Approach 2:
The redundant computing units and sensors perform self-diagnosis and self-reporting of their operational status. Each CU monitors its own health and communicates status to the VCU, allowing the system to automatically identify and isolate failures without external intervention. This self-service capability reduces the need for additional monitoring hardware and simplifies the management of redundant components, effectively reducing the burden of having multiple redundant parts.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A redundant hardware and software architecture can be designed to enable vehicles to be operated in an autonomous mode while improving the reliability and/or safety of such vehicles. A system for redundant architecture can include a set of at least two redundant sensors coupled to a vehicle and configured to provide timestamped sensor data to each of a plurality of computing unit (CU) computers. The CU computers can process the sensor data simultaneously based on at least a time value indicative of an absolute time or a relative time and based on the timestamped sensor data. The CU computers provide to a vehicle control unit (VCU) computer at least two sets of outputs configured to instruct a plurality of devices in a vehicle and cause the vehicle to be driven.