An autonomous ship operation state evaluation method considering multi-state component degradation

By establishing a functional control structure and multi-state safety functions for autonomous ships, the problem of component degradation assessment in autonomous ships has been solved, enabling accurate assessment and risk control of the operational status of autonomous ships and ensuring their safety and reliability.

CN120143884BActive Publication Date: 2025-11-07DALIAN MARITIME UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510291736.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-11-07
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

In autonomous ship systems, existing technologies struggle to effectively monitor and assess the degradation of multi-state components, leading to overlooked changes in operational status and potentially causing safety hazards and accidents.

Method used

Using a systems theory process analysis approach, a functional control structure for autonomous ships is established. Through multi-state safety functions and system risk functions, the safety and risk of autonomous ship subsystems under different operating states are evaluated, the support response and backup response times are predicted, and the risk level under critical states is identified.

Benefits of technology

It enables accurate assessment of the operational status of autonomous vessels, timely prediction and prevention of deviations from operational boundaries, provides scientific risk management strategies, and ensures the safe and reliable operation of autonomous vessels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120143884B_ABST
    Figure CN120143884B_ABST
Patent Text Reader

Abstract

The application discloses a kind of autonomous ship operating state evaluation methods considering multi-state component degradation, establishes the function control structure of autonomous ship in remote control mode, and determines the multi-state safety function of autonomous ship subsystem and system risk function, to obtain the time of predicted guarantee response, the time of backup response and the critical time when system risk exceeds the critical state system risk level set, to evaluate the operating state of autonomous ship in remote control mode.The application can more accurately capture the unique risk control process of autonomous ship through the function control structure of system in multiple operating states and the interaction mechanism between multi-component subsystems, and provides basic support for scientific risk management strategy and decision-making process in autonomous ship operation, and provides theoretical support for preventing autonomous ship from deviating from operating boundary.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of multi-state degradation system, and particularly relates to a self-propelled ship operation state evaluation method considering multi-state component degradation. BACKGROUND

[0002] In the new pattern of the development of the shipping industry based on digitization and aiming at autonomy, autonomous shipping has become one of the most prominent trends in the current shipping industry. Among them, whether it is remote control or complete autonomy, autonomous ships are essential elements and carriers. Enhanced automation does not mean that the ship is an autonomous ship. The main difference between autonomous ships and traditional ships is the introduction of autonomous or remote operation technology to enhance or replace the functions performed by ship crew in executing or controlling these ship functions. Compared with the latter, the dynamic change of the operation mode significantly enhances the interactive complexity, decomposition complexity and nonlinearity complexity of the autonomous ship system operation. The change of control and operation mode gives birth to new safety requirements, which need to be protected through strict supervision to ensure the safety of the lives at sea, the goods on the ship and the ship itself. However, in the process of the intelligent transformation and autonomous development of the ship system, the risk prevention and control presents a trend from fragmentation to integration, and the information interaction changes from a single system to a pan-system, which further requires the risk prevention and control strategy of the ship operation to change from the saturated full-process plugging to the pre-control type systematic prevention and control.

[0003] At present, the International Maritime Organization (IMO) is developing the Maritime Autonomous Surface Ship Code (MASS Code) to provide an international regulatory framework and solutions to address key functions of remote control and autonomous operation. The design and operation of autonomous ships require additional guidance to ensure that their safety level is comparable to that expected for conventional ships and ultimately to ensure that autonomous ships are safe, reliable and environmentally friendly to operate. From the perspective of autonomous ship operation, the MASS Code identifies and emphasizes some new operational states and state transition paths. Compared with conventional ships, there is an Operational Design Domain (ODD) within the acceptable risk condition (ARC), which provides the conditions, related control modes and operational modes of autonomous ships under remote control and autonomous operation. The operational boundaries of autonomous ships are composed of the design operational domain and the acceptable risk condition, which provide the operational capabilities and limitations of the ship and the ship-specific capabilities and limitations. Deviation from the design operational domain should be considered as a degraded state once the system or function deviates from its design operational domain, but the ship as an integrated system can continue to operate within its operational boundaries. The ship can operate normally in a degraded state, which is usually caused by the degradation of a single autonomous or remotely operated system. Once the ship deviates from its operational boundaries, the ship should take fallback response to further avoid the possibility of deviating from normal operation. As long as the ship cannot stay within the operating conditions, minimal risk manoeuvre (MRM) should be performed to maintain the minimal risk condition (MRC) to maintain the state of the lowest degree of safety. If the degradation of the system and components is not well monitored and the change of the operating state is detected, the state transition of the autonomous ship is easy to be ignored, and even leads to accidents. SUMMARY

[0004] The present application discloses a method for evaluating the operating state of an autonomous ship considering the degradation of multi-state components, to overcome the above technical problems.

[0005] To achieve the above purpose, the technical scheme of the present application is:

[0006] A method for evaluating the operating state of an autonomous ship considering the degradation of multi-state components, comprising the following steps:

[0007] S1: based on the system theory process analysis method, a functional control structure of the autonomous ship in the remote control mode is established;

[0008] S2: establishing a multi-state safety function of the autonomous ship subsystem based on a functional control structure of the autonomous ship to obtain a safety function of the autonomous ship subsystem in a u-th operating state; wherein, u represents an operating state, u≥1;

[0009] S3: obtaining an average lifetime of the autonomous ship subsystem within a safety state subset according to the safety function of the autonomous ship subsystem in the u-th operating state to obtain a time of a predicted safeguard response and a time of a backup response;

[0010] S4: establishing a system risk function of the autonomous ship subsystem based on a functional control structure of the autonomous ship to obtain a critical time at which a system risk exceeds a set system risk level in a critical state;

[0011] S5: evaluating an operating state of the autonomous ship in a remote control mode according to the critical time at which the system risk exceeds the set system risk level in the critical state, the predicted time of the safeguard response and the time of the backup response.

[0012] Further, in the S2, the multi-state safety function is expressed by the following formula:

[0013] s (i) (t)=[1,s (i) (t,1),s (i) (t,2),s (i) (t,3),s (i) (t,4)],t∈[0,∞)

[0014]

[0015] In the formula, s (i) (t) represents a five-state safety function of the i-th autonomous ship subsystem; s (i) (t,u) represents a safety function of the i-th autonomous ship subsystem in the u-th operating state; t represents a time; a b-th secondary component under an a-th primary component in the i-th autonomous ship subsystem safety function in the u-th operating state; A i represents a total number of primary components in the i-th autonomous ship subsystem; represents a total number of secondary components contained in the a-th primary component in the i-th autonomous ship subsystem; u represents an operating state;

[0016] wherein,

[0017]

[0018] In the formula, represents the bth secondary component under the ath primary component in the 1st autonomous ship subsystem the safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the navigation subsystem S1 the safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 1st autonomous ship subsystem the migration strength in the u-th operating state; the bth secondary component under the ath primary component in the 2nd autonomous ship subsystem the safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the autonomous engine monitoring and control subsystem S2 the safety function in the u-th operating state; the bth secondary component under the ath primary component in the 3rd autonomous ship subsystem the safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the environmental sensor subsystem S3 the safety function in the u-th operating state; the bth secondary component under the ath primary component in the 4th autonomous ship subsystem the safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the communication subsystem S4 the safety function in the u-th operating state; the bth secondary component under the ath primary component in the 5th autonomous ship subsystem the safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the remote operating center subsystem S5 the safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 2nd autonomous ship subsystem the migration strength in the u-th operating state; represents the bth secondary component under the ath primary component in the 3rd autonomous ship subsystem the migration strength in the u-th operating state; represents the bth secondary component under the ath primary component in the 4th autonomous ship subsystem the migration strength in the u-th operating state; represents the bth secondary component under the ath primary component in the 5th autonomous ship subsystem the migration strength in the u-th operating state; exp[·] represents an exponential distribution.

[0019] Further, the average lifetime of the autonomous ship subsystem within the safety state subset is obtained as follows in S3:

[0020]

[0021] wherein: represents the average lifetime of the autonomous ship subsystem within the safety state subset; s (i) (t, u) represents the safety function of the i-th autonomous ship subsystem at the u-th operating state; t represents the time; u represents the operating state;

[0022]

[0023] wherein: t 后备 represents the backup response time; t 预测 represents the time of predicted guarantee response.

[0024] Further, the system risk function of the autonomous ship subsystem is established as follows in S4:

[0025] R(t) = 1 - s(t, r)

[0026] wherein: R(t) represents the system risk function; s(t, r) represents the safety function of the remotely controlled ship at the critical state; r represents the critical state; t represents the time.

[0027] Further, the formula for obtaining the critical time at which the system risk at the critical state exceeds the set system risk level is as follows:

[0028] τ = R -1 (t) = R -1 (δ)

[0029] wherein: τ represents the critical time at which the system risk at the critical state r exceeds the set system risk level, R(t) represents the system risk function; R -1 (t) represents the inverse function of the system risk function R(t); δ represents the set system risk level.

[0030] Further, the functional control structure comprises a plurality of autonomous ship subsystems;

[0031] The autonomous ship subsystem comprises a plurality of series-connected primary components;

[0032] The primary component comprises a plurality of parallel-connected secondary components.

[0033] Further, the plurality of autonomous ship subsystems comprises, in series, a navigation subsystem S1, an autonomous engine monitoring and control subsystem S2, an environmental sensor subsystem S3, a communication subsystem S4, and a remote operation center subsystem S5;

[0034] The first-level components under the navigation subsystem S1 comprise an integrated bridge system and an autonomous navigation system;

[0035] The first-level components under the autonomous engine monitoring and control subsystem S2 comprise main engines steering engines, generators, auxiliary engines

[0036] Among them, the second-level components under the steering engine comprise a first steering engine and a second steering engine

[0037] The second-level components under the generator comprise a first generator a second generator a third generator a fourth generator

[0038] The first-level components under the environmental sensor subsystem S3 comprise a global navigation satellite system a radar an electronic chart a lidar an infrared camera a gyrocompass a log a depth sounder a ship automatic identification system a global maritime distress and safety system

[0039] The first-level components under the communication subsystem S4 comprise a communication controller and a very high frequency

[0040] The first-level components under the remote operation center subsystem S5 comprise a remote operation center

[0041] Beneficial effects: the autonomous ship operation state evaluation method considering multi-state component degradation of the application, establishes the function control structure of the autonomous ship in the remote control mode, and determines the multi-state safety function of the autonomous ship subsystem and the system risk function, so as to obtain the time of predicting guarantee response, the time of backup response and the critical time when the system risk exceeds the set system risk level in the critical state, so as to evaluate the operation state of the autonomous ship in the remote control mode. The function control structure of the system in multiple operation states and the interaction mechanism between multiple component subsystems can more accurately capture the unique risk control process of the autonomous ship, and provide basic support for scientific risk management strategy and decision-making process in autonomous ship operation, and provide theoretical support for preventing autonomous ship from deviating from the operation boundary. BRIEF DESCRIPTION OF DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0043] Figure 1 Flow chart of the autonomous ship operation state evaluation method considering multi-state component degradation of the present application;

[0044] Figure 2 Function control structure of the autonomous ship (crew on the ship) in the remote control mode in the embodiment of the present application;

[0045] Figure 3 Series-parallel structure of the components in the subsystem of the remote control ship (crew on the ship) in the embodiment of the present application;

[0046] Figure 4 System and component safety state change diagram in the embodiment of the present application;

[0047] Figure 5 Navigation subsystem S1 safety function diagram in the embodiment of the present application;

[0048] Figure 6 Autonomous engine monitoring and control subsystem S2 safety function diagram in the embodiment of the present application;

[0049] Figure 7 Environment sensor subsystem S3 safety function diagram in the embodiment of the present application;

[0050] Figure 8 Communication subsystem S4 safety function diagram in the embodiment of the present application;

[0051] Figure 9 Safety function diagram for remote operation center subsystem S5 in embodiments of the present application;

[0052] Figure 10 Risk function diagram for autonomous ship system in embodiments of the present application. DETAILED DESCRIPTION

[0053] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0054] The present embodiment introduces a method for evaluating the running state of an autonomous ship considering the degradation of multi-state components, as shown in Figure 1 The method comprises the following steps:

[0055] S1: based on a system theory process analysis method, a function control structure of an autonomous ship in a remote control mode is established;

[0056] Preferably, the function control structure comprises a plurality of autonomous ship subsystems; the plurality of autonomous ship subsystems are connected in series.

[0057] The autonomous ship subsystems comprise a plurality of first-level components connected in series.

[0058] The first-level components comprise a plurality of second-level components connected in parallel.

[0059] Preferably, the plurality of autonomous ship subsystems comprise a navigation subsystem S1, an autonomous engine monitoring and control subsystem S2, an environmental sensor subsystem S3, a communication subsystem S4 and a remote operation center subsystem S5.

[0060] The first-level components under the navigation subsystem S1 comprise an integrated bridge system and an autonomous navigation system

[0061] The first-level components under the autonomous engine monitoring and control subsystem S2 comprise a main engine a rudder engine, a generator, an auxiliary engine The second-level components under the rudder engine comprise a first rudder engine and a second rudder engine The second-level components under the generator comprise a first generator a second generator a third generator Fourth generator

[0062] The first level components under the environmental sensor subsystem S3 include a global navigation satellite system Radar Electronic chart Lidar Infrared camera Gyrocompass Log Depth sounder Automatic identification system Global maritime distress and safety system

[0063] The first level components under the communication subsystem S4 include a communication controller And very high frequency

[0064] The first level components under the remote operation center subsystem S5 include a remote operation center

[0065] Specifically, the embodiment utilizes the Systems Theoretic Process Analysis (STPA) method to divide the remotely controlled autonomous ship into a large system composed of multiple autonomous ship subsystems and determine the operating state of the autonomous ship in a specific scenario, which is a routine technique for those skilled in the art, and the division process will not be described in detail. The remotely controlled autonomous ship is a routine technique in the field, and the embodiment only uses it, so it will not be described in detail.

[0066] Specifically, the first step of the Systems Theoretic Process Analysis method needs to define the analysis purpose, including system boundary and system target. In this example, the system boundary is defined as the remotely controlled ship with a small number of crew operating within the operating boundary, and the analysis target is to support the smooth introduction of the autonomous ship and avoid the autonomous ship operating outside its operating boundary. In this embodiment, the unacceptable losses related to this stage are defined as follows:

[0067] L-1: loss of confidentiality, integrity, and availability of mission data;

[0068] L-2: loss of monitoring and / or control of the autonomous ship by the remote control center;

[0069] L-3: loss of functionality for normal operation within the operating boundary;

[0070] L-4: lower than the expected safety level of conventional ships;

[0071] L-5: loss of feasibility of introducing autonomous ship.

[0072] wherein L represents unacceptable loss. Among L-1,…,L-5, the severity of unacceptable loss varies from low to high.

[0073] By defining unacceptable loss, the operating state of the system can be better understood, and therefore the method can define the safety state of the autonomous ship in a specific scenario. Specifically, in this example, the safety state of the system, subsystem and its components is represented by z', and the description of the safety state is as follows when z' takes different values:

[0074] z'=4: the remote-controlled ship is running safely;

[0075] z'=3: the remote-controlled ship is running relatively safely, but has the possibility of causing L-1;

[0076] z'=2: the remote-controlled ship is running generally safely, but has the possibility of causing L-1 and L-2;

[0077] z'=1: the remote-controlled ship is running in danger, with the possibility of causing L-1, L-2 and L-3;

[0078] z'=0: the remote-controlled ship is running in danger, with the possibility of causing L-1, L-2, L-3, L-4 and L-5.

[0079] wherein z' represents the safety state; when z'=4, the autonomous ship is in a safe running state. In this embodiment, u represents the running state, wherein u=1 indicates that the autonomous ship subsystem and the first-level components and second-level components under the autonomous ship subsystem run in the safety state subset {z'=1, z'=2, z'=3, z'=4}, u=2 indicates that the autonomous ship subsystem and the first-level components and second-level components under the autonomous ship subsystem run in the safety state subset {z'=2, z'=3, z'=4}, u=3 indicates that the autonomous ship subsystem and the first-level components and second-level components under the autonomous ship subsystem run in the safety state subset {z'=3, z'=4}, u=4 indicates that the autonomous ship subsystem and the first-level components and second-level components under the autonomous ship subsystem run in the safety state subset {z'=4}, and the safety state subset is a set composed of safety states z'.

[0080] This embodiment introduces a system theory process analysis method, creates a functional control structure of the system according to the functional requirements of all components in the remote-controlled autonomous ship, and obtains the division of the autonomous ship components. According to the responsibilities and functional requirements of all components, the remote-controlled autonomous ship is divided into a complex system composed of five autonomous ship subsystems, and the functional control structure is as followsFigure 2 As shown. In this structure, the remotely controlled vessel and the remote operations center are considered as a unified system, consisting of five autonomous vessel subsystems: navigation subsystem S1, autonomous engine monitoring and control subsystem S2, environmental sensor subsystem S3, communication subsystem S4, and remote operations center subsystem S5. i This represents the i-th subsystem in the system, where i = 1, 2, ..., I is the index number and I is the total number of subsystems.

[0081] Each autonomous vessel subsystem is composed of multiple components arranged in a series / parallel structure, or a combination of series and parallel structures. The navigation subsystem S1 consists of the integrated bridge system. Autonomous navigation system Composition. The autonomous engine monitoring and control subsystem S2 consists of a propulsion and steering system, a generator set, and other auxiliary systems, wherein the propulsion and steering system includes one main engine. 2 servos The generator set includes 4 generators. Other auxiliary equipment is considered as a single overall component. Composition; Environmental sensor subsystem S3 consists of the Global Navigation Satellite System radar Electronic nautical chart LiDAR Infrared camera Top Compass Speedometer depth sounder Automatic Identification System (AIS) Global Maritime Distress and Safety System The communication subsystem S4 consists of a communication controller. and VHF Composition; the remote operation center subsystem S5 consists only of the overall remote operation center component. constitute.

[0082] In this embodiment, the five autonomous ship subsystems are connected in series to form a five-state system. Let represent that the i-th subsystem has 'a' primary components, and each 'a' primary component has 'b' parallel secondary components, where a = 1, 2, ..., A, b = 1, 2, ..., B. a Let A be the total number of components in the i-th autonomous ship subsystem, and B be the total number of components in the i-th autonomous ship subsystem. a This represents the total number of secondary components contained in the a-th primary component. Based on the two typical safety structures of multi-state systems (series system / parallel system), the series and parallel structures of the remote-controlled ship system and its subsystems in this embodiment are as follows: Figure 3 As shown.

[0083] S2: establishing a multi-state safety function of the autonomous ship subsystem based on a functional control structure of the autonomous ship to obtain a safety function of the autonomous ship subsystem in the u-th operating state;

[0084] Preferably, the multi-state safety function of the autonomous ship subsystem is expressed by the following formula:

[0085] s (i) (t) = [1, s (i) (t, 1), s (i) (t, 2), s (i) (t, 3), s (i) (t, 4)], t ∈ [0, ∞) (T1)

[0086]

[0087] In the formula, s (i) (t) represents the five-state safety function of the i-th autonomous ship subsystem; s (i) (t, u) represents the safety function of the i-th autonomous ship subsystem in the u-th operating state; t represents the time; represents the b-th secondary component under the a-th primary component in the i-th autonomous ship subsystem safety function in the u-th operating state; A i represents the total number of primary components in the i-th autonomous ship subsystem; represents the total number of secondary components contained in the a-th primary component in the i-th autonomous ship subsystem; u represents the operating state, wherein, wherein, u = 1 represents that the autonomous ship subsystem and the primary components and secondary components under the autonomous ship subsystem operate in the safety state subset {z' = 1, z' = 2, z' = 3, z' = 4}, u = 2 represents that the autonomous ship subsystem and the primary components and secondary components under the autonomous ship subsystem operate in the safety state subset {z' = 2, z' = 3, z' = 4}, u = 3 represents that the autonomous ship subsystem and the primary components and secondary components under the autonomous ship subsystem operate in the safety state subset {z' = 3, z' = 4}, u = 4 represents that the autonomous ship subsystem and the primary components and secondary components under the autonomous ship subsystem operate in the safety state subset {z' = 4}, and the safety state subset is a set composed of safety states z'.

[0088] wherein the multi-state safety function of the component is expressed by the following formula:

[0089]

[0090] In the formula: denotes the bth secondary component under the ath primary component in the ith autonomous ship subsystem the safety function in the u-th operating state;

[0091] In particular, the safety state of autonomous ship subsystems and components can only transfer to a worse state over time, as Figure 4 shown. Since the functions and characteristics of components within autonomous ship subsystems are different, their degradation processes will also obey different failure distribution functions. Among them, the exponential distribution is suitable for systems with constant failure rates, which means that the failure probability of the system does not change over time. It is usually used to describe the failure time of electronic components, because electronic components usually have a constant failure rate. The Weibull distribution is suitable for systems with time-varying failure rates. When the shape parameter in the Weibull distribution is equal to 2, the failure rate increases linearly with time, also known as the Rayleigh distribution. It is usually used to describe the failure time of mechanical systems, such as bearings and gears. Since the failure rates of components in the environmental sensor subsystem S3 and the communication subsystem S4 are usually related to electronic components, their failure time distribution functions are more consistent with the exponential distribution. The autonomous engine monitoring and control subsystem S2 is composed of main engines, auxiliary engines, generators and other auxiliary engines, which usually fail due to material fatigue or other factors during operation. During the product life, the risk of wear failure steadily increases. Therefore, the Rayleigh distribution is used to model the components in this subsystem.

[0092] In addition, for large systems, the exact system reliability function and risk function means a very complex functional form, which is a serious constraint in the case of limited resources. In addition, complex functional forms will reduce the interpretability of the model, which is not conducive to the decision-making of managers. It is necessary to assume that the failure time distribution function obeys the exponential distribution. Relatively speaking, the navigation subsystem S1, the communication subsystem S4, and the remote operation center subsystem S5 composed of software and hardware can be regarded as large systems. It is prudent to assume that the multi-state safety function of components in the subsystem follows the exponential distribution.

[0093] Therefore, the safety function of components in the autonomous ship subsystem in the u-th operating state is represented by the following formula:

[0094]

[0095] wherein, denotes the bth secondary component under the ath primary component in the ith autonomous ship subsystem the safety function in the u-th operating state, i.e., the bth secondary component under the ath primary component in the navigation subsystem S1 the safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 1st autonomous ship subsystem migration intensity in the u-th operating state; represents the bth secondary component under the ath primary component in the 2nd autonomous ship subsystem safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the autonomous engine monitoring and control subsystem S2 safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 3rd autonomous ship subsystem safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the environmental sensor subsystem S3 safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 4th autonomous ship subsystem safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the communication subsystem S4 safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 5th autonomous ship subsystem safety function in the u-th operating state, i.e. the bth secondary component under the ath primary component in the remote operation center subsystem S5 safety function in the u-th operating state; represents the bth secondary component under the ath primary component in the 2nd autonomous ship subsystem migration intensity in the u-th operating state; represents the bth secondary component under the ath primary component in the 3rd autonomous ship subsystem migration intensity in the u-th operating state; represents the bth secondary component under the ath primary component in the 4th autonomous ship subsystem migration intensity in the u-th operating state; represents the bth secondary component under the ath primary component in the 5th autonomous ship subsystem migration intensity in the u-th operating state; exp[·] represents an exponential distribution;

[0096] In particular, in the present embodiment, the migration intensity refers to the probability of a system / component transitioning from one state to another;

[0097] wherein the multi-state safety functions of the five autonomous ship subsystems are represented as follows:

[0098] s(t,u) = s (1) (t,u)·s (2) (t,u)·s (3) (t,u)·s (4) (t,u)·s (5) (t,u) (T5)

[0099] In the formula, s(t,u) represents the safety function of the autonomous ship in the remote control mode in the u-th running state; s (i) (t,u) (i = 1, 2, 3, 4, 5) represents the safety function of the i-th autonomous ship subsystem in the u-th running state.

[0100] S3: According to the safety function of the autonomous ship subsystem in the u-th running state, the average life of the autonomous ship subsystem in the safety state subset is obtained to obtain the time of the predicted guarantee response and the time of the backup response;

[0101] Preferably, the average life of the autonomous ship subsystem in the safety state subset is obtained as follows:

[0102]

[0103] In the formula: represents the average life of the autonomous ship subsystem in the safety state subset; s (i) (t,u) represents the safety function of the i-th autonomous ship subsystem in the u-th running state; t represents the time; and u represents the running state.

[0104]

[0105] In the formula: t 后备 represents the backup response time; t 预测 represents the time of the predicted guarantee response.

[0106] In particular, the autonomous ship has a design operating domain (ODD) within acceptable risk conditions (ARC) for providing conditions, related control modes and operating modes of the autonomous ship under remote control and autonomous operation compared to a conventional ship. The autonomous ship operating boundary is composed of the design operating domain and the acceptable risk conditions, providing the operational capabilities and limitations of the ship and the ship-specific capabilities and limitations. A deviation from the design operating domain should be considered as a degraded state once the system or function deviates from its design operating domain, but the ship as an integrated system is able to continue operating within its operating boundary. The ship is able to operate normally in a degraded state, which is usually caused by the degradation of a single autonomous or remote operated system. Once the ship deviates from its operating boundary, the ship should take a back-up response to further avoid the possibility of deviating from normal operation. As long as the ship cannot stay within the operating boundary, a minimal risk manoeuvre (MRM) should be performed to maintain a state of minimal safety under minimal risk conditions (MRC).

[0107] Although the operating state of the autonomous ship is worse when u = 1, the degradation of this state has no serious impact on ship damage and casualties. Therefore, it will maintain the function for a longer period of time and remain in an acceptable limit state. In combination with the migration process of the autonomous ship operating state described above, the back-up response time can be predicted by the average lifetime of the autonomous ship subsystem within the safe state subset, which can guide the decision maker to implement a response in time to prevent deviation from the system operating experience.

[0108] In particular, such a back-up response allows the operator to address potential abnormal problems within the ODD, thereby avoiding transition to a degraded state by taking a back-up response before a predetermined time interval, i.e. before the predicted back-up response time. Such a back-up response enables the operator to address potential abnormal problems within the ODD, and the back-up response time can guide the decision maker to implement a response in time to maintain a high level of availability and safety in autonomous operation.

[0109] S4: establishing a system risk function of the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain a critical time at which the system risk exceeds a set system risk level in a critical state;

[0110] Preferably, the system risk function of the autonomous ship subsystem is established as follows:

[0111] R(t) = 1 - s(t, r)(T9)

[0112] Wherein: R(t) represents a system risk function; s(t, r) represents a safety function of the remotely controlled ship in a critical state; r represents a critical state; and t represents a time.

[0113] Preferably, the formula for obtaining the critical time at which the system risk in the critical state r exceeds the set system risk level is as follows:

[0114] τ = R -1 (t) = R -1 (δ)(T10)

[0115] Wherein: τ represents the critical time at which the system risk in the critical state r exceeds the set system risk level, R(t) represents a system risk function; R -1 (t) represents an inverse function of the system risk function R(t); and δ represents the set system risk level.

[0116] Specifically, in the embodiment, the set system risk level is defined as δ, and the critical time at which the system risk exceeds δ is calculated by the following formula:

[0117] τ = R -1 (δ).

[0118] S5: Based on the critical time at which the system risk in the critical state r exceeds the set system risk level, the predicted time of the guarantee response, and the time of the backup response, the running state of the autonomous ship in the remote control mode is evaluated.

[0119] Wherein, after the critical time at which the system risk in the critical state r exceeds the set system risk level, the predicted time of the guarantee response, and the time of the backup response are obtained, the person skilled in the art can evaluate the running state of the autonomous ship in the remote control mode based on the conventional technology in the field, and thus the specific evaluation method is not described in detail.

[0120] A specific embodiment of the present application is as follows:

[0121] Where the safety state subset migration strength of various components is determined by expert judgment, several factors need to be considered, including component complexity, technical level, operation duration, and environmental conditions. The basic information of the experts is shown in Table 1. "ω1=complexity" refers to the inherent complexity of the component; "ω2=technical level" represents the intelligence level of the component and its ability to complete tasks; "ω3=operation duration" reflects the total working time of the component during the ship voyage; and "ω4=environmental conditions" is related to the environment in which the component operates, and each factor is evaluated in the range of 1 to 10. In this embodiment, four marine scientists and two deck officers were invited to express their opinions. They are familiar with ship machinery and have a deep understanding of the development of autonomous ships. During the scoring process, the average failure-free time of a certain component is known, so the failure rate of the component in this state is represented as ε1. It is assumed that both the score and the score coefficient are proportional to the actual failure rate, as shown in equations (T11) to (T14).

[0122] ε j = K j · ε1 (T11)

[0123] ∏ω c = k j (T12)

[0124]

[0125] Where: ε j represents the unknown failure rate; K j represents the coefficient for intermediate calculation; ε1represents the known failure rate; ω c (c=1, 2, 3, 4) represents the factors that need to be considered to determine the safety state subset migration strength of various components; k j represents the value of the multiplication of the four scoring factors of the component to be scored; k1represents the value of the multiplication of the four scoring factors of the component with known failure rate; μ j represents the unknown conditional life; and μ1represents the known conditional life.

[0126] The conditional life generally refers to the time during which the component can continue to maintain its function under certain conditions, and therefore, the approximation can be represented by the average failure-free time. The conditional life is generally calculated using the following formula:

[0127]

[0128] Where: μ(u) represents the conditional life of the system in the safety state subset. represents an approximation of μ(u); E[T(u)] represents the average of the component condition life T(u) over the subset of safe operating states {u, u+1,..., z}, E being the symbol for average; represents an estimate of the unknown transition intensity;

[0129] Based on expert judgment as shown in Table 1, given the average time between failures of the system components, the estimate of the unknown transition intensity is calculated from the following equation:

[0130]

[0131] where MTTF represents the average time between failures;

[0132] Table 1 Expert Information

[0133]

[0134] Given that subsystems S1, S3, and S5 are part of the bridge equipment, the components of subsystems S1 and S5 use S5's evaluation. The components of S2 and S3 (except for the components of subsystem S3 ) are obtained from historical documents and are considered known quantities. During the discussion and interviews, the results for each subsystem are shown in Table 2. Therein, the estimate of the unknown transition intensity for the integrated bridge system Autopilot Infrared camera Communication controller and the remote operations center is calculated from the data of the expert judgment.

[0135] Table 2 Results from the discussion and interviews for the

[0136]

[0137]

[0138] Currently, the estimate of the transition intensity of the subset of safe states of a system component relies mainly on expert judgment.

[0139] Using the data of the expert judgment, the safety function of the components in each subsystem of the remotely controlled ship is as follows.

[0140]

[0141]

[0142] The system safety function of the subsystem component is substituted into the safety function of each subsystem, and the corresponding function image is generated, Figures 5 to 9 The images of the safety function of the remote control ship component in different operating states under different subsystems are shown respectively.

[0143] In this example, it is assumed that the critical operating state of the system and its components is r = 3, and the system risk function is given by the following formula:

[0144] r(t) = 1 - s(t, 3) (T18)

[0145] The system risk function image is shown in Figure 10 Assuming δ = 0.05, the time when the system risk function exceeds the predetermined safety threshold is:

[0146] τ = 0.040 (T19)

[0147] Identifying the time when the system risk function exceeds the predetermined safety threshold can provide technical support for the decision of the periodic maintenance strategy, so in this example, when the system is continuously operated for 350.4 hours (τ = 0.040), the system is highly likely to lose the confidentiality, integrity and availability of the mission data.

[0148]

[0149] The formula T20 is the calculated average life of the system operating within the safety threshold, t 后备 The standby response time t 预测 The guarantee response time can be predicted. In this example, if the autonomous ship system has not been effectively and timely maintained after being continuously operated for 189.8 days, the possibility of the safety level being lower than the expected level of the conventional operating ship and the feasibility of introducing the autonomous ship will greatly increase. Other results show that the degradation speed of the hardware facilities is faster than that of the software system, and in the hardware facilities, the degradation of the AEMC subsystem is the most serious threat, and the average life of the environmental sensor breaking the initial safety state is highly concerned, both of which are most likely to cause the autonomous ship to deviate from its operating boundary.

[0150] Table 3 Average life of system and subsystem

[0151]

[0152] The autonomous ship operating state evaluation method considering the degradation of multi-state components in this embodiment develops an operating state evaluation framework from the perspective of system safety, which plays a crucial role in minimizing unnecessary state transitions and preventing the system condition from gradually deteriorating. This embodiment can predict the time when the ship enters the degradation state and the degradation state to evaluate the operating safety of the autonomous ship and prevent the ship from deviating from the OE (operating boundary):

[0153] 1. The embodiment is an evaluation framework that can evaluate the operational state of a ship from a system safety perspective. The evaluation process takes into account the functional control structure of the whole system and the interaction mechanism between multi-component subsystems, providing basic support for scientific risk management strategies and decision-making processes in autonomous ship operations, thereby providing a reference for the formulation of maritime management strategies.

[0154] 2. The embodiment innovatively extends the traditional system operational state assumption from binary "normal-failure" to multi-state, which can more accurately capture the unique risk control process of autonomous ships.

[0155] 3. The embodiment also introduces STPA to generate a functional control structure that helps to model multi-state systems. A remotely controlled ship (with seafarers on board) is used as a real case study to demonstrate the applicability of the method in the proposed framework.

[0156] 4. The embodiment can reveal the migration mechanism of the operational state of the autonomous ship, and derive the implementation deadline of the safeguard response and backup response. The research results can provide theoretical support for preventing autonomous ships from deviating from the operational boundary.

[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent substitutions for some or all of the technical features; and these modifications or substitutions do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for autonomous ship operational state assessment considering multi-state component degradation, characterized by, The method comprises the following steps: S1: establishing a function control structure of the autonomous ship in the remote control mode based on a system theory process analysis method; S2: establishing a multi-state safety function of the autonomous ship subsystems based on the functional control structure of the autonomous ship, to obtain the safety function of the autonomous ship subsystem in the first u operating state; wherein, u represents the operating state, u ≥1; S3: obtain the average lifetime of the autonomous ship subsystem within the safety state subset according to the safety function of the autonomous ship subsystem in the first u running state, to obtain the time of the predicted guaranteed response and the time of the backup response. In the S3, the average life of the autonomous ship subsystem within the safety state subset is obtained as follows: wherein: represents the average lifetime of the autonomous ship subsystem within the safety state subset; represents the safety function of the i th autonomous ship subsystem in the u th operating state; represents the time instant; represents the operating state; In the formulae: denotes the backup response time; denotes the time to predictively secure the response. S4: establishing a system risk function of the autonomous ship subsystem based on the function control structure of the autonomous ship, to obtain a critical time when the system risk exceeds a set system risk level in the critical state; S5: evaluating the running state of the autonomous ship in the remote control mode according to the critical time when the system risk exceeds the set system risk level in the critical state, the predicted time of the guarantee response and the time of the backup response.

2. The method for autonomous ship operational state assessment considering multi-state component degradation according to claim 1, characterized in that, In the S2, the multi-state safety function is expressed by the following formula: In the formula: Indicates the first i Five-state safety function of an autonomous ship subsystem; Indicates the first i The autonomous ship subsystem in the first u Safety functions in each running state; Indicates time; Indicates the first i The first autonomous ship subsystem a The first-level component b Secondary components In the u Safety functions in each running state; Indicates the first i The total number of first-level components in an autonomous ship subsystem; Indicates the first i The first autonomous ship subsystem a The total number of second-level components contained in a first-level component; Indicates the running status; Wherein, wherein represents the 1st secondary component under the 1st primary component in the 1st autonomous ship subsystem a b the safety function in the 1st operating state, i.e. the 1st secondary component under the 1st primary component in the navigation subsystem u a b the safety function in the 1st operating state; u represents the 1st secondary component under the 1st primary component in the 1st autonomous ship subsystem a b the migration intensity in the 1st operating state; u the 1st secondary component under the 1st primary component in the 2nd autonomous ship subsystem a b the safety function in the 1st operating state, i.e. the 1st secondary component under the 1st primary component in the autonomous engine monitoring and control subsystem u a b the safety function in the 1st operating state; u the 1st secondary component under the 1st primary component in the 3rd autonomous ship subsystem a b the safety function in the 1st operating state, i.e. the 1st secondary component under the 1st primary component in the environmental sensor subsystem u a b the safety function in the 1st operating state; u the 1st secondary component under the 1st primary component in the 4th autonomous ship subsystem a b the safety function in the 1st operating state, i.e. the 1st secondary component under the 1st primary component in the communication subsystem u a b the safety function in the 1st operating state; u the 1st secondary component under the 1st primary component in the 5th autonomous ship subsystem a ​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​The first-level component b Secondary components In the u Security functions in each operational state, namely the remote operation center subsystem. The first in a The first-level component b Secondary components In the u Safety functions in each running state; This indicates the first [unit / item] in the second autonomous ship subsystem. a The first-level component b Secondary components In the u Migration intensity in each running state; This indicates the third autonomous ship subsystem. a The first-level component b Secondary components In the u Migration intensity in each running state; This indicates the fourth autonomous ship subsystem. a The first-level component b Secondary components In the u Migration intensity in each running state; This represents the b-th secondary component under the a-th primary component in the fifth autonomous ship subsystem. The migration strength in the u-th running state; This represents an exponential distribution.

3. The method for autonomous ship operational state assessment considering multi-state component degradation according to claim 1, characterized in that, In the S4, the system risk function of the autonomous ship subsystem is established as follows: In the formula: represents a system risk function; represents a safety function of the remotely controlled ship in a critical state; represents a critical state; represents a time.

4. The method for autonomous ship operational state assessment considering multi-state component degradation according to claim 1, characterized in that, The formula for obtaining the critical time when the system risk exceeds the set system risk level in the critical state is as follows: where: denotes the critical state r the critical time at which the system risk exceeds a set system risk level, denotes the system risk function; denotes the system risk function the inverse function of the system risk function; δ denotes the set system risk level.

5. The method for autonomous ship operational state assessment considering multi-state component degradation according to claim 1, characterized in that, The function control structure comprises a plurality of autonomous ship subsystems; The autonomous ship subsystem comprises a plurality of first-level components connected in series; The first-level component comprises a plurality of second-level components connected in parallel.

6. The method for autonomous ship operational state assessment considering multi-state component degradation according to claim 5, characterized in that, The plurality of autonomous vessel subsystems includes, in series connection, a navigation subsystem , an autonomous engine monitoring and control subsystem , an environmental sensor subsystem , a communication subsystem , and a remote operations center subsystem ; The navigation subsystem The lower level components include an integrated bridge system and an autonomous navigation system; The autonomous engine monitoring and control subsystem The lower level components include the host , steering gear, generator, auxiliary machinery ; The second-level components under the steering engine include a first steering engine and a second steering engine ​ The second level components under the generator include a first generator , a second generator , a third generator , a fourth generator ; The environmental sensor subsystem The next level components include global navigation satellite system , radar , electronic chart , lidar , infrared camera , gyrocompass , log , depth sounder , automatic identification system , global maritime distress and safety system ; The communication subsystem The lower level components include a communication controller And very high frequency ; The remote operations center subsystem The lower level components include a remote operations center .