发明名称 Methods and systems for compensating for common failures in fail operational systems
摘要 Methods and systems for compensating for common failures in fail operational systems are described herein. An example system may include a primary controller configured to perform functions of a vehicle such as propulsion, braking and steering and a secondary controller configured in a redundant configuration with the primary controller. The controllers may perform cross-checks of each other and may each perform internal self-checks as well. Additionally, the system may include a control module configured to transfer control of the vehicle between the controllers based on detecting a fault. The control module may detect a common fault of the controllers that causes the control module to output a common fault signal. In response, the system may transfer of control to a safety controller configured to perform the vehicle functions until the system may transfer control back to the primary controller.
申请公布号 US9195232(B1) 申请公布日期 2015.11.24
申请号 US201414172906 申请日期 2014.02.05
申请人 Google Inc. 发明人 Egnor Daniel Trawick;Zbrozek Alexander;Schultz Andrew
分类号 G01C22/00;G05D1/00 主分类号 G01C22/00
代理机构 McDonnell Boehnen Hulbert & Berghoff LLP 代理人 McDonnell Boehnen Hulbert & Berghoff LLP
主权项 1. A system comprising: a primary controller configured to perform functions associated with control of operation of a vehicle including vehicle propulsion, braking and steering; a secondary controller configured in a redundant configuration as the primary controller, wherein the primary controller and the secondary controller are configured to operate based on execution of a first set of logic and perform cross-checks of each other; a control module configured to transfer control of operation of the vehicle between the primary controller and the secondary controller based on a detected fault at one of the primary controller and the secondary controller, wherein the control module is further configured to detect a common fault of the primary controller and the secondary controller and the control module is configured to responsively output a common fault signal; a safety controller coupled to the control module configured to operate based on execution of a second set of logic independent of operation of the primary controller and the secondary controller, and based on receiving the common fault signal the safety controller is configured to receive transfer of control of operation of the vehicle; and to perform functions associated with control of operation of the vehicle including vehicle braking.
地址 Mountain View CA US