Vehicle Trajectory Validation for Fault-Aware Motion Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vehicle trajectories generated using faulty hardware or software can lead to undesirable consequences when used for controlling vehicle operations, such as autonomous vehicles, due to potential faults or operational parameter violations.

Innovation Solution

Implementing a system that receives a vehicle trajectory, identifies the software operations and hardware components involved in its generation, detects fault conditions or operational parameter violations, and selectively chooses an alternative trajectory to ensure safe and reliable motion commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vehicle trajectory is generated using data from hardware and software components, then the trajectory can be used to control vehicle operations, but the trajectory may contain faults or cause operational parameter violations leading to undesirable consequences

Engineering Contradiction:
Improvetrajectory reliabilityVSAvoidfault propagation to downstream systems
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation of the vehicle trajectory by identifying fault conditions in hardware and software components before the trajectory is executed. This includes detecting faults in sensors, processors, and other components that generated the trajectory data, and validating operational parameters against predefined limits. By performing these checks in advance, the system prevents faulty trajectories from being used to control vehicle operations, thereby eliminating harmful effects before they can propagate to downstream systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation system that acts as a mediator between the trajectory generation process and the vehicle control system. This intermediary layer includes a fault detection module that identifies faults in hardware and software components, and a validation module that checks whether the trajectory violates operational parameter limits. This intermediary system filters out faulty trajectories before they reach the vehicle control system, preventing harmful effects without requiring changes to the underlying hardware or software components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fault detection and validation operations are performed on vehicle trajectory, then harmful effects are eliminated, but additional processing time and system complexity are introduced

Engineering Contradiction:
Improvevehicle operation safetyVSAvoidtrajectory validation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation system is segmented into distinct functional modules: a fault detection module that identifies faults in hardware and software components, and a validation module that checks operational parameters against predefined limits. This segmentation allows each module to perform its specific function independently, making the overall system more manageable and maintainable. The modular structure also enables the system to scale and adapt to different vehicle configurations without requiring complete redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-validation by automatically detecting faults in its own hardware and software components and validating its generated trajectories against predefined operational limits. The fault detection module monitors the health of sensors, processors, and other components that generate trajectory data, and the validation module checks whether the trajectory violates operational parameter limits. This self-service capability eliminates the need for external validation systems, reducing overall system complexity while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If fault detection operations are performed on hardware and software components, then faulty trajectories can be identified, but the detection process requires additional computational resources and time

Engineering Contradiction:
Improvefault detection accuracyVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system changes the parameters of fault detection by using predefined fault condition signatures and operational parameter limits that are optimized for efficient detection. Instead of performing exhaustive analysis of all possible fault modes, the system checks for specific fault conditions that are most likely to occur or have the greatest impact on safety. This parameter optimization allows the system to maintain high detection accuracy while reducing computational energy consumption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240010211A1Systems and methods for selectively using a vehicle trajectory
Publication Date: 2024.01.11 FORD GLOBAL TECH LLC
  • US20240010211A1 patent drawing
  • US20240010211A1 patent drawing
  • US20240010211A1 patent drawing

AI summary

Disclosed herein are systems, methods, and computer program products for selectively using vehicle trajectories. The methods comprise: receiving a vehicle trajectory (VT) prior to being used to generate motion commands (MCs) for a vehicle; identifying software and/or hardware components of the vehicle that produced data used to generate VT; determining whether a fault condition exists that is associated with VT based on (i) a detection that the software/hardware component(s) did or did not experience a fault or operational condition of a type while producing the data used to generate VT and/or (ii) a detection that VT would or would not cause violation of limit(s) for an operational parameter of the vehicle; selecting VT when the fault condition does not exist or another VT when the fault condition does exist; and causing the motion commands to be generated using VT or the another VT which was selected.