Method and device for operating a control unit for safety-critical applications in a motor vehicle
The method of employing a backup safety mechanism with a lower integrity level to manage faults in motor vehicle systems enhances system availability by allowing continued operation with existing components, while ensuring safe transitions when necessary.
Patent Information
- Application Number
- DE102023212549
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-12
- Publication Date
- 2025-06-12
AI Technical Summary
Existing safety mechanisms in motor vehicles often lead to the entire vehicle system transitioning to a safe state even when errors occur in components or functions of the safety mechanism, reducing system availability, especially in commercial vehicles.
A method is introduced that involves calling a backup safety mechanism with a lower safety integrity level when a fault occurs in a component or function used by a safety mechanism, and controlling this backup mechanism through monitoring with time-dependent and activation limitation indications.
This approach increases the availability of the vehicle system by allowing the use of redundant safety mechanisms with existing components and functions, without additional outlay, while ensuring the vehicle transitions to a safe state when necessary.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical FieldThe invention relates to measures for the safe operation of control units in motor vehicles, in particular measures for implementing safety mechanisms in the event of failure of a component in a motor vehicle.Background ArtIf a safety-critical fault of a component or a function in a vehicle is detected, a safety mechanism which is defined in accordance with a safety destination is called up. The ISO 26262 standard specifies the safety goals used for components and functions in the vehicle. These safety goals are based on an ASIL rating that is based on the probability of occurrence, severity and controllability parameters.For each safety objective, a safe state is defined that is occupied by the vehicle system. The implemented safety mechanism switches to this safe state when the safety target is violated. However, errors involving components and functions of the safety mechanism may also result in the entire vehicle system transitioning to a safe state. This reduces the availability of the vehicle system. However, high availability of the system is required, in particular for applications of commercial vehicles. However, the provision of redundant safety mechanisms of the same integrity level is relatively complicated.Disclosure of the InventionAccording to the invention, a method for operating a vehicle system having safety mechanisms according to Claim 1 and a corresponding device and a vehicle system according to the subordinate claims are provided.Further embodiments are given in the dependent claims.According to a first aspect, a method for operating a vehicle system is provided, having the following steps:calling a security mechanism when a security target is violated,detecting a failure in execution of the security mechanism, invoking a backup security mechanism associated with the security target;detecting a failure in the backup safety mechanism, bringing the vehicle system into a safe state;inhibiting the calling or stopping of the backup safety mechanism depending on an activation limitation indication associated with the violated safety target.Errors in components or functions in a vehicle system, in particular of control units, sensors or actuators, are assigned to safety goals. A safety objective is a defined result or state that is to be reached in the area of vehicle safety and comprises one or more diagnostic functions with which functions or components of the vehicle system are monitored with regard to one or more fault criteria. Each safety destination is assigned a safety mechanism which is called up as soon as a corresponding monitoring indicates an error.A safety mechanism represents one or more predetermined functions to be invoked when a safety critical fault has occurred. However, these security mechanisms may utilize other components or functions that are also faulty. This has led up to now to the entire vehicle system being brought into a safe state in which all vehicle functions are deactivated and this is thus no longer functional.According to the above method, it is now provided to increase the availability of the vehicle system by switching to a backup safety mechanism having a lower safety integrity level in the event of a fault occurring in a component or function used by a safety mechanism activated due to a fault or a fault. In this case, the backup safety mechanism is controlled in a secured manner by a corresponding monitoring in a time-dependent manner and as a function of an activation limitation indication. Such a method offers the possibility of a redundant safety mechanism with existing components and functions in the vehicle system, so that overall a better availability of the vehicle system is achieved without additional outlay.It may be provided that the backup safety mechanism corresponds to a lower safety integrity level than the safety mechanism at which the fault has occurred.Each component and function in a vehicle system is associated with a safety target that is determined to a particular ASIL integrity level based on probability of occurrence, severity, and controllability, particularly by a driver. In general, a reduction in the probability of occurrence at the same severity level and the same controllability leads to a reduction in the ASIL integrity level.The above method now provides for switching over to the backup safety mechanism in the event of a fault occurring during the execution of the safety mechanism which is associated with a previously violated safety target and for not immediately changing over to a passive safe state of the vehicle system. This increases the availability of the vehicle system.For this purpose, each safety mechanism is assigned at least one backup safety mechanism according to an assignment table, to which an activation limitation indication is also assigned, which indicates the total travel time of the backup safety mechanism and / or which indicates the number of travel cycles during which the backup safety mechanism is active.If the backup safety mechanism is not available, the vehicle system is brought into a safe state defined for the corresponding safety destination. If the backup safety mechanism is available, i.e. the components and functions used are error-free, the activation limitation indication, which can be determined, for example, as permitted driving time or maximum number of driving cycles, is retrieved from the assignment table for the relevant backup safety mechanism.Then, the safety target of the vehicle system with respect to the backup safety mechanism is monitored with the activation limit until the activation limit does not allow further application of the backup safety mechanism. Once the activation limit associated with the backup safety mechanism has expired, the vehicle system is brought into a safe state defined for the safety destination.In addition to the activation limitation, the driver of the vehicle can be informed of the activation of the backup safety mechanism and can be alerted to the need for service to a workshop visit.It can be provided that the number of driving cycles and the total driving duration during the active backup safety mechanism are stored in the activation limiting memory at the beginning of the driving cycle or at the end of the driving cycle.The activation limitation is implemented using a nonvolatile activation limitation memory, in which the travel time since the first call to the backup safety mechanism and the travel cycles carried out since the first call to the backup safety mechanism are logged in a safe manner.Furthermore, after each storage of the number of driving cycles and the total driving duration, a check of the storage can be carried out, in particular with the aid of a checksum.Write and read operations to / in this activation boundary memory can be checked by determining a checksum. Each time the activation memory is changed, the checksum is recomputed and stored together with the information about the journey duration and the journey cycles. If the maximum travel duration predefined by the activation limitation and / or the maximum number of travel cycles is reached or exceeded without error correction having taken place, the vehicle system is brought into a safe state.After each write operation to the activation limit memory, this activation limit memory is checked by a write analysis operation to monitor the functionality of the memory in question.According to a further aspect, an apparatus, in particular a data processing device, is provided for carrying out the above method.Brief Description of the DrawingsEmbodiments are explained in more detail below with reference to the attached drawings. The following are shown: FIG. 1 is a schematic illustration of a vehicle system having controllers connected to a plurality of sensors and actuators; FIG. 2 is a flow chart illustrating a method of operating a vehicle system.DESCRIPTION OF EMBODIMENTSFIG. 1 shows a schematic illustration of a vehicle system 1 having control units 2 which are each connected as components to a multiplicity of sensors 3 and actuators 4. The control units 2 are designed to execute on the basis of software and / or hardware vehicle functions using the components 3, 4 of the vehicle system 1.Monitoring functions are also implemented in control unit 2, which monitors components 3, 4, control units 2 and the vehicle functions implemented in control units 2 for compliance with safety goals. If a security goal is not complied with, a security mechanism is called accordingly, which results from a predefined assignment table.The mapping table assigns a corresponding security mechanism of a particular ASIL integrity level to a security target. The mapping table further assigns each of the security objectives a backup security mechanism of an ASIL integrity level that typically satisfies a lower security standard. For example, if a safety integrity level ASIL B is associated with the safety target, the backup safety mechanism may be associated with an integrity level ASIL A.Furthermore, each backup safety mechanism is assigned an activity limitation indication. The activity limit indication indicates one or more time-limiting maximum values indicating how long the backup safety mechanism may be active. The maximum values can comprise, for example, a maximum cumulative travel duration when the backup safety mechanism is active, or a maximum number of travel cycles in which the backup safety mechanism is active.A method for operating the vehicle system 1 with safety mechanism will be described in more detail with reference to the flow chart of FIG. 2.In step S 1, it is first checked whether a fault has occurred in a component 2, 3 or a function in the vehicle system 1. This fault is detected on the basis of an injury to a safety target.If this is the case (alternative: yes), the method continues with step S 2. Otherwise (alternative: no), the system jumps back to step S 1.In step S 2, a security mechanism is called up or activated, which is assigned to the security destination according to the assignment table.In step S 3, it is checked whether the safety mechanism can be called or activated after the occurrence of the fault in the component 2, 3 or the function in the vehicle system 1. If the security mechanism cannot be called (alternative: no), for example because a fault has occurred, the method continues with step S 4; otherwise (alternative: yes), the method continues with step S 11.In step S 11, the safety mechanism is correspondingly further executed in order to be able to continue to operate the vehicle system 1. If necessary, the detected error can be signaled.In step S4, the backup security mechanism associated with the security mechanism is retrieved from the association table and executed.Furthermore, in step S 5, an activation limitation indication is retrieved from the assignment table, which indicates, for example, a maximum number of driving cycles and / or a maximum driving duration when the backup safety mechanism is active.In step S 6, it is checked whether a continuously updated driving cycle number in the activation limiting memory has reached a predefined threshold value of the activation limiting indication or whether the driving time in the activation limiting memory has reached or exceeded a predefined threshold value of the activation limiting indication. Further, it may be checked whether a failure has occurred in the backup safety mechanism. If one of the above criteria is fulfilled (alternative: yes), the method is continued with step S 12, the vehicle is brought into a safe state and the backup safety mechanism is prevented from being activated again. Otherwise (alternative: no), the method continues with step S 7.In step S7, it is checked whether the current travel should be terminated. If this is the case (alternative: yes), the method continues with step S 8. Otherwise (alternative: no), the system jumps back to step S 6.In step S 8, a driving cycle counter is incremented / decremented accordingly upon termination of an active driving operation. Alternatively or additionally, a travel time counter can be updated with the duration of the last active travel mode. Accordingly, after the end of the travel, the total travel time during the backup active safety mechanism and the travel cycle number of the travel cycle counter are stored in the activation limit memory. In addition, a checksum can be generated and stored.The driving cycle is ended in step S 9.In step S 10, it is checked whether a new driving cycle is to be started. If this is the case (alternative: yes), the method continues with step S 1. Otherwise (alternative: no), the system jumps back to step S 10.If it is determined during the operation of the backup safety mechanism that the conditions specified by the activation limit indication are met, i.e. the maximum number of driving cycles and the maximum travel duration during the active backup activation mechanism are exceeded, the backup safety mechanism is deactivated and the vehicle is brought into a safe state in step S 12. In particular, the safe state corresponds to a state in which the vehicle components 2, 3 and vehicle functions are not actively operated. As a rule, all vehicle functions are deactivated.During the writing of the activation limiting memory, a check can be made by a subsequent read-out as to whether the storage has taken place correctly. If the activation limitation indication is not stored correctly, the vehicle system 1 can be brought into a safe state.
Claims
Computer-implemented method for operating a vehicle system (1), having the following steps: - calling (S2) a safety mechanism if a safety target is violated (S1), - upon detection (S4) of a fault in the execution of the safety mechanism, calling a backup safety mechanism assigned to the safety target; - upon detection of a fault in the backup safety mechanism, bringing the vehicle system into a safe state; - disabling (S12) the calling of the backup safety mechanism depending on an activation limitation indication assigned to the violated safety target.The method of claim 1, wherein the backup security mechanism corresponds to a lower level of security integrity than the security mechanism.Method according to claim 1 or 2, wherein the activation limitation indication indicates a maximum number of driving cycles and / or a maximum driving duration when the backup safety mechanism is active.The method according to any one of claims 1 to 3, wherein the driving cycle number and the total driving duration during the backup active safety mechanism are stored in the activation limit memory at the beginning of the driving cycle or at the end of the driving cycle.Method according to Claim 4, wherein after each storage of the number of driving cycles and the total driving duration, a check of the storage is carried out, in particular with the aid of a checksum.Device, in particular a data processing device, for carrying out one of the methods according to one of Claims 1 to 8.A computer program product comprising instructions which, when the program is executed by at least one data processing device, cause the program to carry out the steps of the method according to any one of claims 1 to 8.A machine readable storage medium comprising instructions which, when executed by at least one data processing device, cause the at least one data processing device to carry out the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for performing a safety function of a vehicle and system for performing the method
DE102012215343A1
Method for automatically bringing a vehicle into a safe state
DE102023000353A1