Autopilot is not a place I want bit level errors to happen.
ps. not really a car person but dang that Model X looks nice - announced Feb 2012 but still not shipping?
Autopilot is not a place I want bit level errors to happen.
ps. not really a car person but dang that Model X looks nice - announced Feb 2012 but still not shipping?
TI has an overview of the safety features in their Hercules microcontrollers here:
For example, if something goes wrong with the processor on your industrial robot arm, you just stop all the motors and activate all the brakes. No need to figure out which of the processors is right, have an engineer come out and fix the bug that caused the disagreement.
On the other hand, if something goes wrong with the processor during your space shuttle launch, it would not help to turn off all the rockets - better to have an election algorithm so things can keep working.
Is a self-driving car more like the first case or the second? Depends if the driver is ready to take the wheel :)
There are far too many situations where a switchover time of [user initial reaction time + initial response time] is high enough to be rather dangerous.
http://www.freescale.com/webapp/sps/site/application.jsp?cod...
I'm not a car person or expert in the field but I've done a little bit of work on automotive systems. As the other responders pointed out these systems are designed to, ECC or not, do things like (at the slightest sign of inconsistency or error)
- reset and recover very quickly
- enter reduced functionality or failsafe modes
- fully disable themselves and anything that might cause you to rely on them
They're fundamentally built around the eventuality of them failing and with consideration of the things that need to happen when they fail. They don't usually rely on 'well, we'll just put in a somewhat more reliable component'.