I think two or three parallel systems might minimize downtime or hang-time. Have it as autopilot by consensus. If one system says danger, prime the brakes and re-evaluate. If two say danger, take action.
Heck. That's probably how they'll do it, anyway. Many automotive systems have built in redundancy for safety reasons.
|