← Work / Foundations / Varden Labs

Varden Labs · Summer 2015

Wireless e-stop

A handheld dead-man’s switch that let us run Varden’s self-driving golf cart with nobody on board. Hold the trigger and the vehicle may drive; let go, or lose the link, and it brakes.

Role
Mechanical design, build and integration
When
Summer 2015
Inside
Particle Core (Wi-Fi MCU) · USB battery · LEDs · microswitch trigger
Vehicle
NI roboRIO behind a Linux PC
The handheld wireless e-stop with its antenna
The handheld unit
2 s
After releasing the trigger, at full brake, before outputs disable
2 layers
Of redundancy: a rolling watchdog packet, and a hard power-off
0
People needed on board for demos

Why

Within about ten minutes of our first golf cart working, my co-founder and I had both jumped out and were running around a field in front of it, with no way to stop it except chasing it down. An empty vehicle driving itself had a huge effect on people watching, so to keep giving those demos safely we needed a wireless way to stop it.

How it works

The cart used a National Instruments roboRIO (built for FIRST Robotics, which we both knew well) to interface with the vehicle and take commands from a Linux PC. Its watchdog only enables outputs while it keeps receiving a specific UDP packet, which we had already reverse-engineered so the PC could supply it.

So we put a router on the vehicle to create a local network, and had a handheld Wi-Fi unit send the packet to the PC, which relayed it to the roboRIO. I designed and built the enclosure around a Particle Core Wi-Fi microcontroller, a repackaged rechargeable USB battery, a couple of LEDs and a microswitch trigger.

Exploded CAD of the e-stop enclosure: a red top cap with a green trigger lever and yellow antenna, a magenta body tube, and an orange bottom cap
Enclosure in exploded CAD

Watchdog relay

  1. Handset
    Trigger heldParticle Core over Wi-Fi
  2. Network
    Router on the vehicleLocal network
  3. Computer
    Linux PCRelays packets both ways
  4. Controller
    NI roboRIOOutputs enabled only while its changing watchdog packet is answered
The vehicle only drives while the handset keeps answeringSimplified

Fail-safe behaviour

  1. Holding the trigger enables the vehicle; releasing it applies full brake for two seconds, then disables the outputs.
  2. The packet is a response to a continuously changing packet from the roboRIO, so replaying an old one does nothing, and only the handset knows how to answer. Everything else just relays.
  3. If the handset’s software or switch fails, it can simply be powered off from the bottom, which stops transmission.

Related