Failure management in a vehicle

US9604585B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9604585-B2
Application numberUS-201514663917-A
CountryUS
Kind codeB2
Filing dateMar 20, 2015
Priority dateJul 11, 2014
Publication dateMar 28, 2017
Grant dateMar 28, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system includes first and second failsafe devices. Each of the failsafe devices includes a processor and a memory. The memory stores instructions executable by the processor for performing at least one of detecting a fault and providing a communication concerning a fault. The system further includes an arbitration bus connecting the first and second failsafe devices. The communication concerning the fault may be provided from a first one of the first and second failsafe devices to a second one of the first and second failsafe devices.

First claim

Opening claim text (preview).

The invention claimed is: 1. A vehicle system including a control sub-system, the control sub-system comprising: first and second failsafe devices, each of the failsafe devices comprising a processor and a memory, the memory storing instructions executable by the processor for performing at least one of detecting a fault and providing a communication concerning a fault; and an arbitration bus connecting the first and second failsafe devices, and wherein the communication concerning the fault is provided from a first one of the first and second failsafe devices to a second one of the first and second failsafe devices via the arbitration bus, wherein one of the first and second failsafe devices selects one of a plurality of communication buses for communication with at least one component sub-system based at least in part on the communication concerning the fault received over the arbitration bus. 2. The vehicle system of claim 1 , wherein the at least one component sub-system is communicatively coupled to the first failsafe device via one of the plurality of communication buses and to the second failsafe device via another of the plurality of communication buses. 3. The vehicle system of claim 2 , wherein the plurality of communication buses includes a first communications bus and a second communications bus, the first and second communications buses being distinct from the arbitration bus. 4. The vehicle system of claim 3 , the at least one vehicle component sub-system including third and fourth failsafe devices, each of the third and fourth failsafe devices comprising a processor and a memory, the memory storing instructions executable by the processor for performing at least one of detecting a fault in providing a communication concerning the fault. 5. The vehicle system of claim 4 , further comprising an arbitration sub-system, the arbitration sub-system including first and second failsafe devices. 6. The vehicle system of claim 3 , where the first failsafe device monitors communications over the first communication bus and the second failsafe device monitors communications over the second communication bus, and wherein the first failsafe device selects the first communication bus for communication with the component sub-system in response to the communication concerning the fault received from the second failsafe device over the arbitration bus. 7. The vehicle system of claim 1 , wherein the first failsafe device is powered by a first power source and the second failsafe device is powered by a second power source. 8. The vehicle system of claim 1 , wherein each of the first and second failsafe devices are programmed for substantially performing operations of the subsystem that are performed by the other failsafe device under normal conditions, detecting a fault, and providing a communication concerning a fault. 9. The vehicle system of claim 1 , wherein the system is in a vehicle and the control subsystem is an autonomous vehicle control subsystem. 10. A system in a vehicle, comprising: a first subsystem comprising first and second failsafe devices; a second subsystem comprising third and fourth failsafe devices; a first communications bus and a second communications bus; and a first arbitration bus connecting the first and second failsafe devices, wherein the communication concerning the fault is provided from a first one of the first and second failsafe devices to a second one of the first and second failsafe devices over the first arbitration bus; wherein each of the failsafe devices comprising a processor and a memory, the memory storing instructions executable by the processor for performing at least one of detecting a fault and providing a communication concerning a fault; and the first and third failsafe devices are communicatively connected via the first communications bus and the second and fourth failsafe devices are connected via the second communications bus, wherein one of the first and second failsafe devices selects one of the first and second communication bus for communication with at least one of the third and fourth failsafe devices based at least in part on the communication concerning the fault received over the arbitration bus. 11. The system of claim 10 , further comprising a second arbitration bus connecting the third and fourth failsafe devices, wherein the communication concerning the fault is provided from a first one of the third and fourth failsafe devices to a second one of the third and fourth failsafe devices over the second arbitration bus. 12. The system of claim 10 , wherein the first subsystem is an autonomous operation subsystem and the second subsystem is one of a powertrain subsystem, a brake subsystem, a steering subsystem, and a lighting subsystem. 13. The system of claim 10 , further comprising a plurality of second subsystems. 14. The system of claim 10 , wherein the first failsafe device is powered by a first power source and the second failsafe device is powered by a second power source. 15. The system of claim 10 , wherein each of the first and second failsafe devices are programmed for substantially performing operations of the subsystem that are performed by the other failsafe device under normal conditions, detecting a fault, and providing a communication concerning a fault. 16. A system in a vehicle, comprising: an autonomous operation subsystem comprising first and second failsafe devices in communication over an arbitration bus; a second subsystem; a first communications bus and a second communications bus; wherein each of the failsafe devices comprising a processor and a memory, the memory storing instructions executable by the processor for performing at least one of detecting a fault and providing a communication concerning a fault; and each of the failsafe devices are further programmed to transmit the communication concerning the fault to the other failsafe device over the arbitration bus and, in the event of a fault in the other failsafe device, provide at least some communications to the second subsystem, over one of the first communication bus and the second communication bus, that the other device is programmed to provide, wherein one of the first and second failsafe devices selects one of the first and second communication bus for communication with the second subsystem based at least in part on the communication concerning the fault received over the arbitration bus. 17. The system of claim 16 , wherein the first failsafe device is powered by a first power source and the second failsafe device is powered by a second power source. 18. The system of claim 16 , wherein each of the first and second failsafe devices are programmed for substantially performing operations of the subsystem that are performed by the other failsafe device under normal conditions, detecting a fault, and providing a communication concerning a fault.

Assignees

Inventors

Classifications

  • for supply of electrical power to vehicle subsystems {or for (circuit arrangements for charging batteries H02J7/00)} · CPC title

  • for measuring vehicle parameters and indicating critical, abnormal or dangerous conditions · CPC title

  • G06F11/16Primary

    Error detection or correction of the data by redundancy in hardware · CPC title

  • Avoiding failures by using redundant parts · CPC title

  • using redundant signals or controls · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9604585B2 cover?
A system includes first and second failsafe devices. Each of the failsafe devices includes a processor and a memory. The memory stores instructions executable by the processor for performing at least one of detecting a fault and providing a communication concerning a fault. The system further includes an arbitration bus connecting the first and second failsafe devices. The communication concern…
Who is the assignee on this patent?
Ford Global Tech Llc
What technology area does this patent fall under?
Primary CPC classification B60R16/0232. Mapped technology areas include Operations & Transport.
When was this patent published?
Publication date Tue Mar 28 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).