Fail-safe EE architecture for automated driving
First Claim
1. A system comprising:
- a first computer unit having a first interface configured to connect to a sensor and to an actuator;
a second computer unit having a second interface configured to connect to the sensor and to the actuator;
a third interface configured to connect the first computer unit and the second computer unit to each other; and
a human-machine interface configured to transfer a handover request for performance of an automated driving function by means of separate interfaces to the first computer unit and the second computer unit, the first computer unit and the second computer unit being configured to mutually and separately indicate a takeover of the automated driving function to the human-machine interface, the human-machine interface being configured to only transfer the automated driving function to the first computer unit if each of the first computer unit and the second computer unit indicate that they are operating correctly and can perform the automated driving function,wherein at least one of the first computer unit, the second computer unit, and the actuator are configured to control which of the first computer unit and the second computer unit can effectively activate the actuator.
1 Assignment
0 Petitions
Accused Products
Abstract
A system with a first computer unit and with a second computer unit, wherein the first computer unit comprises a first interface to enable connection to at least one sensor and to at least one actuator, wherein the second computer unit comprises a second interface to enable connection to at least one sensor and to at least one actuator, wherein the first and the second computer units can be connected to each other by means of a further interface, wherein the actuator comprises an interface, wherein depending on the first or on the second operating state the interface determines whether a control command for a driving function is adopted by the first or the second computer unit, so that in the first operating state only the first computer unit can activate the actuator and in a second operating state only the second computer unit can activate the actuator.
17 Citations
19 Claims
-
1. A system comprising:
-
a first computer unit having a first interface configured to connect to a sensor and to an actuator; a second computer unit having a second interface configured to connect to the sensor and to the actuator; a third interface configured to connect the first computer unit and the second computer unit to each other; and a human-machine interface configured to transfer a handover request for performance of an automated driving function by means of separate interfaces to the first computer unit and the second computer unit, the first computer unit and the second computer unit being configured to mutually and separately indicate a takeover of the automated driving function to the human-machine interface, the human-machine interface being configured to only transfer the automated driving function to the first computer unit if each of the first computer unit and the second computer unit indicate that they are operating correctly and can perform the automated driving function, wherein at least one of the first computer unit, the second computer unit, and the actuator are configured to control which of the first computer unit and the second computer unit can effectively activate the actuator. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17)
-
-
18. A method for the operation of a system having a first computer unit and a second computer unit, the first computer unit having an first interface configured to connect to a sensor and to an actuator the second computer unit having an second interface configured to connect to the sensor and to the actuator, the system further having a third interface configured to connect the first computer unit and the second computer unit to each other, the system further having a human-machine interface, the method comprising:
-
controlling, with at least one of the first computer unit, the second computer unit, and the actuator, which of the first computer unit and the second computer unit can effectively activate the actuator; and transferring, with the human-machine interface, a handover request for performance of an automated driving function by means of separate interfaces to the first computer unit and the second computer unit, the first computer unit and the second computer unit being configured to mutually and separately indicate a takeover of the automated driving function to the human-machine interface, the human-machine interface being configured to only transfer the automated driving function to the first computer unit if each of first computer unit and the second computer unit indicate that they are operating correctly and can perform the automated driving function.
-
-
19. A system comprising:
-
a first computer unit having a first interface configured to connect to a sensor and to an actuator, ; a second computer unit having a second interface configured to connect to the sensor and to the actuator; and a third interface configured to connect the first computer unit and the second computer unit to each other, wherein at least one of the first computer unit, the second computer unit, and the actuator are configured to control which of the first computer unit and the second computer unit can effectively activate the actuator, wherein the first computer unit is configured to (i) compute a first automated driving function and (ii) transmit the computed first automated driving function to the second computer unit, and the second computer unit is configured to (i) independently compute a second automated driving function that is the same as the first automated driving function, (ii) compare the independently computed second automated driving function with the first automated driving function, and (iii) check for a malfunction of the second computer unit based on the comparison.
-
Specification