A functional safety assurance device, method, and unmanned vehicle

By introducing a runtime safety assurance device for complex controllers, safety controllers, and decision-making modules into intelligent unmanned systems, the uncertainty of the safety properties of learning algorithm models in autonomous vehicles is solved, realizing the safe and efficient operation of the system in real-world environments, and making it applicable to a variety of intelligent unmanned systems.

CN115743169BActive Publication Date: 2026-05-01HANGZHOU TURING INTELLIGENT TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU TURING INTELLIGENT TECHNOLOGY CO LTD
Filing Date
2022-10-19
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies in intelligent unmanned systems, especially driverless vehicles, struggle to effectively guarantee the safety and accuracy of learning algorithm models. This leads to uncertainties and uninterpretability in the safety properties of the system in practical applications. Existing testing methods are costly, lack reusability, and the results of simulation verification and abstract model verification deviate significantly from the actual system.

Method used

A runtime functional safety assurance device is adopted, including a complex controller, a safety controller, and a decision module. By monitoring and predicting the system state in real time, the controller is switched to ensure safety. The reachable state set method is used to predict safety properties and switch controllers to ensure that the system operates in a safety-critical state.

Benefits of technology

It achieves functional safety assurance during the operation of intelligent unmanned systems, solves the problem that the safety analysis results of abstract models are difficult to apply to actual systems, ensures the efficient operation and safety of system functions, and is applicable to a variety of intelligent unmanned systems, especially driverless vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115743169B_ABST
    Figure CN115743169B_ABST
Patent Text Reader

Abstract

The application discloses a kind of functional safety assurance device, method and unmanned vehicle, including controlled system: complex controller, for controlling controlled system in normal state runs;Safety controller, for controlling controlled system in safety critical state runs;Safety controller has higher safety than complex controller;Decision module, for real-time monitoring to controlled system operating state, and according to the state of the controlled system running is predicted according to monitoring result, according to the prediction result completes between complex controller and safety controller switching;In the case where it is judged that safety constraint is not violated in prediction, then using complex controller controls controlled system in normal state runs;When it is judged that safety constraint is violated in prediction, switch to safety controller controls controlled system in safety critical state runs, guarantee the safety of controlled system operating state.
Need to check novelty before this filing date? Find Prior Art

Description

A functional safety assurance device, method, and unmanned vehicle Technical Field

[0001] This invention relates to the fields of intelligent algorithms, cyber-physical systems and trusted software technology, as well as intelligent driving of vehicles, and particularly to a runtime functional safety assurance device and method for intelligent unmanned systems, and an unmanned vehicle using the above-mentioned device and method. Background Technology

[0002] In recent years, with the rapid development of neural network-based learning algorithms, intelligent unmanned systems have increasingly adopted these algorithms to achieve functions such as system perception, decision-making, and control, as exemplified by the well-known autonomous vehicle systems. However, learning algorithms typically employ a data-driven approach, resulting in neural network models with uninterpretable and uncertain behaviors. The correctness and accuracy of these models heavily depend on the quality of the training samples. When the sample data contains perturbations (such as attack samples) or deviations in distribution (such as unknown samples), the model may produce incorrect results, making the safety assurance of intelligent unmanned systems a highly challenging technical problem.

[0003] Commonly used methods for ensuring the safety of intelligent unmanned systems mainly include physical testing, simulation testing, and formal verification. Physical testing involves constructing realistic test scenarios in closed test fields or open venues to analyze and evaluate the safety of intelligent unmanned systems. Simulation testing, on the other hand, involves constructing corresponding test scenarios in a virtual environment for virtual testing. Testing can statistically evaluate the safety of intelligent unmanned systems. Formal verification involves constructing an abstract mathematical model of the intelligent unmanned system and then using formal verification or mathematical proof methods to analyze its safety.

[0004] However, the above methods have significant limitations in practical applications. Physical testing methods are difficult to control in terms of cost and lack reusability; even minor changes to the system (such as code upgrades) require retesting. Simulation testing, while effectively reducing costs, faces challenges such as difficulty in measuring the similarity between the simulation and real environments, and difficulty in guaranteeing the completeness and coverage of simulation scenarios. Formal verification methods, to ensure the feasibility of security analysis, require constructing an abstract model of the system. However, abstract models struggle to accurately characterize the behavior of actual systems, and complex controllers based on learning algorithms often possess self-learning and self-evolution capabilities. This can lead to discrepancies between verification results based on abstract models and the actual system's behavior, thus failing to fully guarantee the security of the real system. Summary of the Invention

[0005] To address the problems existing in the prior art, the present invention aims to propose a method and apparatus for ensuring runtime functional safety of intelligent unmanned systems, as well as an intelligent unmanned vehicle using the method and apparatus. Based on a runtime safety assurance architecture, this method monitors and predicts the system's behavior during actual operation in real time, analyzes and determines whether a given safety property is violated, and further analyzes possible safety assurance measures for situations where safety properties may be violated, ensuring that the system can avoid violations of safety properties.

[0006] This invention provides a device for ensuring the functional safety of intelligent unmanned systems during operation. The device includes a controlled system and three components: a complex controller for controlling the controlled system to operate in a normal state; a safety controller for controlling the controlled system to operate in a safety-critical state; the safety controller has higher security than the complex controller; and a decision module for real-time monitoring of the operating status of the controlled system, predicting the operating status of the controlled system based on the monitoring results, and switching between the complex controller and the safety controller based on the prediction results. Specifically, if it is determined that no safety constraints have been violated, the complex controller is used to control the controlled system to operate in a normal state; if it is determined that safety constraints have been violated, the system switches to the safety controller to control the controlled system to operate in a safety-critical state.

[0007] Furthermore, the complex controller is a complex controller based on or driven by a learning algorithm, which can achieve more efficient control than a safety controller. The complex controller in this application is a controller based on an open-source control program or an existing controller provided by a third party.

[0008] Furthermore, the decision-making module predicts and monitors the state of the intelligent unmanned system during operation by predicting the state changes of the controlled system within a certain time period. The prediction and monitoring are calculated using the reachable state set method, as follows:

[0009] Let the operating state of the controlled system be denoted as x. Given the safety constraints φ that the controlled system must satisfy, all states that satisfy this safety property constitute a set, called the safe state set; conversely, those that satisfy the constraints φ are called the unsafe state set. If the current operating state x of the controlled system is a safe state, and under the action of the safety controller, the future reachable states of the system are still within the safe state set, then x is called a recoverable state. All recoverable states constitute a subset of the safe state set, denoted by S. A Represents the recoverable state set S. A This can be understood as a fixed point of the safety controller: when the controlled system is in state S under initial conditions. A In this case, under the action of the safety controller, the system state will always be in S. AIf the system is in a recoverable state set S A Furthermore, under the influence of a complex controller, when it is predicted that the system is about to leave the recoverable state set S... A When necessary, the controlled system is kept in a safe state set by switching to the safety controller.

[0010] Furthermore, in the reachable state set method used in the predictive monitoring, the controlled system has a corresponding control cycle, represented by Δ. When the controlled system performs a complex controller switch, the switch command needs to take effect within the next control cycle. Therefore, it is necessary not only to ensure that the current state x is within the set S, but also to ensure that the current state x is within the set S. A In addition, it is also necessary to ensure all reachable states of the system within one control cycle, using S B Let (x, △) represent all elements in set S. A In, that is When the reachable state space S of the system is within a control cycle Δ time... B (x, △) is not completely contained in set S A At that time, under the action of a complex controller, the controlled system may deviate from set S within a time interval of Δ. A To ensure the safety of system operation, the switching conditions for the controlled system to switch from a complex controller to a safety controller are set according to the following set of inclusion relationships:

[0011] Furthermore, the intelligent unmanned system is an intelligent unmanned vehicle, the controlled system is a controlled vehicle, and the complex controller is a complex controller based on or driven by a learning algorithm. When there are no obstacles or vehicles within a safe distance in front of or around the controlled vehicle, the complex controller driven by the learning algorithm operates in a normal state without safety risks. When the vehicle enters a state with potential safety risks, the decision module switches the control to the safety controller to ensure that the vehicle does not collide.

[0012] On the other hand, the present invention provides a method for ensuring runtime functional safety of intelligent unmanned systems, characterized in that the method is applied to the device for ensuring runtime functional safety of intelligent unmanned systems according to the present invention, and the method includes the following steps:

[0013] S1. Complex controllers control the controlled system to operate under normal conditions;

[0014] S2. The decision module monitors the operating status of the controlled system in real time and predicts the operating status of the controlled system based on the monitoring results; it then determines whether the safety constraints are violated based on the prediction.

[0015] S3. If the decision module determines that the controlled system has violated safety constraints, it switches to the safety controller to control the controlled system to enter a safety-critical state.

[0016] Furthermore, the intelligent unmanned system is an intelligent unmanned vehicle. For obstacle avoidance safety, the relative distance between the intelligent unmanned vehicle and the obstacle at time t is denoted as d. t Use at any time Let's represent it as follows: Then the obstacle avoidance safety constraints are: d t >0.

[0017] Furthermore, the calculation method for the functional safety guarantee is as follows:

[0018] When the controlled vehicle and the vehicle in front are both traveling in the same direction, at time t, the relative distance between the two vehicles is d. t To avoid a collision between the two vehicles, d t It must be greater than the safety threshold d safe This ensures that the controlled vehicle has sufficient distance to brake to a relative stop in an emergency; the controlled vehicle estimates the safety threshold d in real time. safe And determine d t >d safe If the condition is not met, then apply the brakes to avoid a collision.

[0019] Specifically, at time t, the speeds of the vehicle in front and the controlled vehicle are denoted as v, respectively. a t and v e t Both the vehicle in front and the controlled vehicle undergo uniform acceleration during braking, with accelerations denoted as constants u. a and u e Then the time it takes for the controlled vehicle to come to a complete stop is: t e stop =v e / u e During this time period, the difference in distance traveled by the two vehicles is: (1 / 2)*(|u e -u a |)*(t e stop ) 2 +(v e -v a )*(t e stop This distance, d, is the safe distance to avoid a collision between the controlled vehicles. safe .

[0020] Furthermore, the present invention also provides an intelligent unmanned vehicle, wherein the vehicle applies the device and method for ensuring the runtime functional safety of intelligent unmanned systems according to the present invention.

[0021] The advantages of the apparatus and method according to the present invention include: (1) providing functional safety guarantees during the operation of the controlled system, thereby solving the problem that the safety analysis results of the abstract model during system design are difficult to apply to the actual system; (2) achieving efficient operation of system functions while ensuring functional safety, avoiding functional degradation; and (3) being applicable to various types of intelligent unmanned systems and having versatility. Attached Figure Description

[0022] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application.

[0023] Figure 1 is a schematic diagram of the architecture of the functional safety assurance device and method according to the present invention;

[0024] Figure 2 is a schematic diagram of the controlled system operation state of the functional safety assurance device and method according to the present invention;

[0025] Figure 3 is a functional logic diagram of the decision module of the functional safety assurance device and method according to the present invention;

[0026] Figure 4 is a schematic diagram of the automatic collision avoidance control of the intelligent unmanned vehicle according to the present invention;

[0027] Figure 5 is a schematic diagram of the runtime security guarantee method for the state space according to the present invention;

[0028] Figure 6 is a schematic diagram of an autonomous driving collision avoidance control system based on a runtime safety assurance architecture according to the present invention. Detailed Implementation

[0029] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0030] In the description of this invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0031] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0032] The specific embodiments of the present invention will be described in detail below with reference to Figures 1-6. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0033] To achieve the above objectives, the device and method for ensuring the runtime safety of intelligent unmanned systems according to the present invention include the following: (1) the architecture of the device for ensuring the runtime functional safety of intelligent unmanned systems; and (2) the runtime state prediction and monitoring of intelligent unmanned systems.

[0034] (1) Architecture of the runtime functional safety assurance device for intelligent unmanned systems

[0035] The architecture of the runtime functional safety assurance device according to the present invention, as shown in Figure 1, includes a controlled system 1 and three components: a complex controller 2, which typically refers to a complex controller with high performance but whose safety cannot be rigorously verified or proven, such as a learning-driven complex controller; a safety controller 3, which typically refers to a complex controller whose safety can be rigorously verified or proven and can enforce safety under abnormal conditions; and a decision module 4, which is a monitor for the operation of the controlled system 1, enabling real-time monitoring of the operating status of the controlled system 1 and determining whether the controlled system 1 will violate safety constraints, thereby enabling switching between the complex controller 2 and the safety controller 3.

[0036] The operating states of the controlled system 1 are divided into two categories: normal state and safety-critical state. The normal state refers to a state without safety risks; the safety-critical state refers to a state that may violate safety constraints, but under reasonable control logic, the controlled system can still avoid violating these constraints. For example, for collision avoidance safety in an autonomous driving system, the normal state refers to a state where the distance between the controlled vehicle and obstacles or other vehicles is relatively far, while the safety-critical state refers to a state where the distance between the controlled vehicle and obstacles or other vehicles is below a certain safety threshold, which is usually a non-linear function of vehicle speed and other physical parameters. In the safety-critical state, complex controllers, such as those based on learning algorithms or learning-driven complex controllers, may cause the safety properties of the controlled system to be violated due to output uncertainty. Therefore, the runtime monitor predicts the state of the controlled system under the action of the complex controller over a future period by acquiring environmental perception data. If the controlled system does not exhibit a state that violates safety properties, the runtime monitor selects the output of the complex controller as the actual control output. Otherwise, it switches control from the complex controller to the safety controller, thereby maximizing the use of the complex controller for efficient control while still ensuring that the controlled system meets safety constraints.

[0037] The key to the aforementioned runtime safety guarantee method lies in the runtime monitor that implements state monitoring and complex controller switching logic. First, this module needs to guarantee correctness. Correctness means that when the controlled system enters a safety-critical state and a situation arises that may violate safety attributes, the monitor can promptly switch control to the safety controller. As mentioned above, the monitor needs to be predictive: violations of monitoring attributes must occur before violations of safety attributes are committed. Second, this module also needs to be optimal. A simple decision logic is to always use the safety controller, which is clearly not optimal. Optimality means that the controlled system only switches to the safety controller when necessary; under non-necessary conditions, the controlled system primarily uses the complex controller.

[0038] (2) Predictive monitoring of runtime status of intelligent unmanned systems

[0039] By monitoring the operational state of the controlled system, the impact of the output of a complex controller based on a learning algorithm on the system's state can be analyzed, thereby determining whether the complex controller based on the learning algorithm will lead to a violation of the system's safety attributes. However, simply monitoring the current state of the controlled system is insufficient to guarantee safety. For example, considering obstacle avoidance safety, let d be the relative distance between the intelligent autonomous vehicle and the obstacle (assuming it is stationary) at time t. t Use at any time This indicates the safety requirements: d t>0. If only the current relative distance d is monitored. t When d appears t When the velocity is 0, the agent will be unable to avoid collisions when its velocity is not zero. To ensure safety, runtime monitoring also needs to predict the state changes of the controlled system over a certain time period, and be able to determine in advance whether the operating state of the controlled system will violate safety attributes.

[0040] This paper explains the basic idea of ​​runtime predictive monitoring from the perspective of the reachable state set method. Given the safety property φ that the controlled system needs to satisfy, all states that satisfy this property constitute a set, called the safe state set. Conversely, the unsafe state set is called the unsafe state set, as shown in the unsafe region in Figure 5. Assuming that the current state x of the controlled system is a safe state, and that under the action of the safety controller, the future reachable states of the controlled system remain within the safe state set, then x is called a recoverable state. All recoverable states constitute a subset of the safe state set, as shown in Figure 5 (S). A The region shown. Intuitively, this set can be understood as a fixed point of the safety controller: when the controlled system is in state S under initial conditions. A In this case, under the action of the safety controller, the controlled system will always be in state S. A Therefore, if the controlled system is in the recoverable state set S A Even under the influence of complex controllers, the controlled system maintains a safety guarantee: when the controlled system is about to leave the set S... A In such cases, the system can remain in a safe state set by switching to the safety controller.

[0041] Considering that the controlled system has a corresponding control cycle in real-world scenarios, we use Δ to represent it. When the controlled system performs complex controller switching, the switching command needs to take effect within the next control cycle. Therefore, in reality, it is necessary not only to ensure that the current state x is within the set S... A In addition, it is also necessary to ensure that all reachable states S of the controlled system within one control cycle are guaranteed. B (x, △) are all in set S A In, that is When the reachable state space S of the controlled system is within a control cycle Δ time... B (x, △) is not completely contained in S A If so, then under the action of a complex controller, the controlled system may deviate from S within a time interval of Δ. A For example, in Figure 5, when the controlled system is in state x, the condition... If the condition is met, the controlled system can continue to use a complex controller; if the controlled system is in state x′, the above condition is not met, and the controlled system may leave the set of safe states. To ensure safety, the controlled system should switch from the complex controller to the safe controller. In summary, without considering hardware failure of the controlled system (i.e., failure of the complex controller), the switching condition for the controlled system to switch from the complex controller to the safe controller can be expressed as the following set inclusion relationship:

[0042] The architecture of an autonomous driving collision avoidance control system based on a runtime guarantee method is shown in Figure 6. It mainly consists of three parts: a learning-driven complex controller, which is a collision avoidance complex controller based on machine learning algorithms; a safety controller; and a decision module, which is the runtime monitor shown in Figure 6. The learning-driven complex controller operates in a state without safety risk, such as when there are no obstacles or vehicles in front of the controlled vehicle. When the vehicle enters a state with potential safety risk, the runtime monitor switches control to the safety controller to ensure that the vehicle does not collide.

[0043] Figure 4 illustrates the basic principle of a complex controller based on runtime guarantees using a simple car-following scenario. Assume the following car is the controlled vehicle, and both vehicles are traveling in the same direction (i.e., the leading car is not reversing). At time t, the speed of the controlled vehicle is v. t The relative distance between the two vehicles is d. t To avoid a collision between the two vehicles, d t It must be greater than a certain threshold d safe This ensures that the controlled vehicle has sufficient time to brake to a relatively stationary state in an emergency. Threshold d safe Also known as safe (braking) distance.

[0044] The controlled vehicle needs to estimate d in real time. safe And determine d t >d safe If the condition is not met, braking must be applied to avoid a collision. More generally, in two-dimensional motion, the safe distance can be generalized as a safe area, also known as the safe envelope, as shown in the elliptical area in front of the red controlled vehicle in Figure 5. Therefore, to ensure no collision occurs, the controlled vehicle needs to estimate the safe area in real time during each control cycle and determine that, within the current control cycle, adjacent vehicles (including the vehicle in front and vehicles in adjacent lanes) must be outside the safe area.

[0045] Specifically, when the controlled vehicle and the vehicle in front are both traveling in the same direction, at time t, the relative distance between the two vehicles is d. t To avoid a collision between the two vehicles, d t It must be greater than the safety threshold dsafe This ensures that the controlled vehicle has sufficient distance to brake to a relative stop in an emergency; the controlled vehicle estimates the safety threshold d in real time. safe And determine d t >d safe If the condition is not met, then apply the brakes to avoid a collision.

[0046] Specifically, at time t, the speeds of the vehicle in front and the controlled vehicle are denoted as v, respectively. a t and v e t Both the vehicle in front and the controlled vehicle undergo uniform acceleration during braking, with accelerations denoted as constants u. a and u e Then the time it takes for the controlled vehicle to come to a complete stop is: t e stop =v e / u e During this time period, the difference in distance traveled by the two vehicles is: (1 / 2)*(|u e -u a |)*(t e stop ) 2 +(v e -v a )*(t e stop This distance, d, is the safe distance to avoid a collision between the controlled vehicles. safe .

[0047] For example, suppose the speed of the controlled vehicle is v e =20m / s, acceleration u e = -4m / s 2 The speed of the vehicle in front, v a =15m / s, acceleration u a = -3m / s 2 Using the above calculation process and method, d safe =1 / 2*(|u e -u a |)*(v e / u e ) 2 +(v e -v a )*(v e / u e )=1 / 2*(4-3)*(20 / 4) 2 +(20-15)*20 / 4=37.5m.

[0048] The apparatus and method provided by this invention can provide functional safety guarantees during system operation, thereby solving the problem that the safety analysis results of the abstract model during system design are difficult to apply to the actual system; it can achieve efficient operation of system functions while ensuring functional safety and avoid functional degradation; it can be applied to a variety of intelligent unmanned systems and has versatility, and is especially suitable for application in unmanned vehicle systems.

[0049] In the description of this specification, references to terms such as "embodiment," "example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, those skilled in the art can combine or combine the different embodiments or examples described in this specification and the features therein without causing contradiction.

[0050] While embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions, and alterations to the above embodiments within the scope of the present invention.

Claims

1. A device for ensuring the functional safety of intelligent unmanned systems during operation, characterized in that, The device includes: a controlled system; a complex controller for controlling the controlled system to operate in a normal state; a safety controller for controlling the controlled system to operate in a safety-critical state; and a decision module for real-time monitoring of the operating state of the controlled system, predicting the operating state of the controlled system based on the monitoring results, and switching between the complex controller and the safety controller based on the prediction results. If it is determined that no safety constraints are violated, the complex controller is used to control the controlled system to operate in a normal state; if it is determined that safety constraints are violated, the control module switches to the safety controller to control the controlled system to operate in a safety-critical state. The decision module predicts and monitors the operating state of the intelligent unmanned system by predicting the state changes of the controlled system within a certain time period. The prediction and monitoring adopts the reachable state set method, with the following specific steps: The operating state of the controlled system is denoted as x; the safety constraints that the controlled system needs to satisfy are given. All states that satisfy the safety properties constitute a set called the safe state set; conversely, the unsafe state set is the unsafe state set. If the current operating state x of the controlled system is a safe state, and under the action of the safety controller, the future reachable states of the controlled system are still within the safe state set, then x is called a recoverable state. All recoverable states constitute a subset of the safe state set, denoted by the symbol S. A Represents the recoverable state set S. A Let S be a fixed point of the safety controller: when the controlled system is in state S under initial conditions. A In this process, under the control of the safety controller, the controlled system will always be in the S state. A In the middle; if the controlled system is in the recoverable state set S A Furthermore, under the action of the complex controller, when it is predicted that the controlled system is about to leave the recoverable state set S A When necessary, the controlled system is kept in a safe state set by switching to the safety controller.

2. The device for ensuring the runtime functional safety of intelligent unmanned systems according to claim 1, characterized in that, In the reachable state set method used in the predictive monitoring, the controlled system has a corresponding control cycle, denoted by Δ. When the controlled system performs a complex controller switch, the switch command must take effect within the next control cycle. The effective condition is that the current state x of the controlled system needs to be within the set S. A In the middle; and predicting and guaranteeing all reachable states of the controlled system within one control cycle, denoted by S. B Let (x, △) represent all elements in set S. A In, that is, S B (x,△) S A When the reachable state space S of the controlled system is within one control cycle Δ time... B (x, △) is not completely contained in set S A When the controlled system is under the action of a complex controller, the switching condition for the controlled system to switch from the complex controller to the safety controller is set according to the following set inclusion relationship: S B (x,△) S A 。 3. The device for ensuring the runtime functional safety of intelligent unmanned systems according to claim 2, characterized in that, The intelligent unmanned system is an intelligent unmanned vehicle, and the controlled system is a controlled vehicle. When there are no obstacles or vehicles in front of or around the controlled vehicle at a safe distance, the complex controller operates in a normal state without safety risks. When the vehicle enters a state with potential safety risks, the decision module switches the control to the safety controller to ensure that the vehicle does not collide.

4. A method for ensuring runtime functional safety of intelligent unmanned systems, characterized in that, The method is applied to the runtime functional safety assurance device for intelligent unmanned systems according to any one of claims 1-3, and the method includes the following steps: S1. A complex controller controls the controlled system to operate in a normal state; S2. A decision module monitors the operating state of the controlled system in real time and predicts the operating state of the controlled system based on the monitoring results; and determines whether the safety constraints are violated based on the prediction results; S3. If the decision module determines that the controlled system violates the safety constraints, it switches to a safety controller to control the controlled system to operate in a safety-critical state.

5. The method for ensuring runtime functional safety of intelligent unmanned systems according to claim 4, characterized in that, The intelligent unmanned system is an intelligent unmanned vehicle. For obstacle avoidance safety, the relative distance between the intelligent unmanned vehicle and the obstacle at time t is denoted as d. t Use at any time To represent, the obstacle avoidance safety constraints are as follows: > 0, d t > 0。 6. The method for ensuring runtime functional safety of intelligent unmanned systems according to claim 5, characterized in that, The functional safety assurance method is calculated as follows: when the controlled vehicle and the vehicle in front are both traveling in the same direction, at time t, the relative distance between the two vehicles is d. t , d t Greater than the safety threshold d safe This ensures that the controlled vehicle has sufficient distance to brake to a relative stop in an emergency; the controlled vehicle estimates the safety threshold d in real time. safe And determine d t > d safe If the condition is not met, then apply the brakes to avoid a collision; specifically, at time t, the speeds of the vehicle in front and the controlled vehicle are denoted as v. a t and v e t Both the vehicle in front and the controlled vehicle undergo uniform acceleration during braking, with accelerations denoted as constants u. a and u e The time it takes for the controlled vehicle to come to a complete stop is: t e stop = v e / u e During this time, the difference in distance traveled by the two vehicles is: (1 / 2) * (|u e - u a |) * (t e stop ) 2 + (v e - v a ) *(t e stop This distance, d, is the safe distance to avoid a collision between the controlled vehicles. safe .

7. An intelligent unmanned vehicle, characterized in that, The vehicle employs the runtime functional safety assurance device for intelligent unmanned systems as described in any one of claims 1-3.

8. An intelligent unmanned vehicle, characterized in that, The vehicle employs the runtime functional safety assurance method for intelligent unmanned systems as described in any one of claims 4-6.

Citation Information

Patent Citations

  • Emergency handling system for an autonomous driving vehicle (ADV)

    CN108068818A