Expected Functional Safety Analysis Method for Map Matching Positioning
By combining forward and reverse analysis methods, the SOTIF hazard event model was established, and the unknown risk problem of map matching positioning system in complex environments was solved, and a more complete and reliable expected functional safety analysis of autonomous vehicles was achieved.
Patent Information
- Application Number
- CN202211728607.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-12-30
AI Technical Summary
In the prior art, the map matching positioning system fails to fully explore hazardous scenarios and trigger conditions in complex environments, resulting in the autonomous vehicle facing unknown safety risks and lacking a systematic expected functional safety analysis solution.
Using a combination of forward analysis and reverse analysis, hazard scenarios and trigger conditions are set, SOTIF hazard event model is established, unacceptable vehicle-level hazard events are identified through risk assessment and loop verification, new trigger conditions are refined, and a more complete expected functional safety analysis framework is built.
Through system engineering theory, we use expert experience and the advantages of reverse analysis to comprehensively analyze hazard scenarios and trigger conditions, reduce safety risks during tracking of autonomous driving trajectory, and improve the completeness and reliability of analysis.
Smart Images

Figure CN116184980B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of the intended functional safety of autonomous vehicles, and particularly to an intended functional safety analysis method for map matching positioning. Background Art
[0002] Safety accidents of autonomous vehicles indicate that the vehicle hazards caused by faults in the electronically controlled systems currently concerned by functional safety can no longer cover the vehicle hazards caused by design deficiencies or performance limitations (collectively referred to as functional deficiencies) of the electronically controlled systems under certain triggering conditions (such as environmental interference or human misuse) when the autonomous vehicles operate in complex and unknown scenarios. Based on this situation, the research on Safety Of The Intended Functionality (SOTIF) has gradually developed, and the industry believes that the research on the intended functional safety of each key technology of autonomous driving is the only way to ensure the vehicle safety. At the same time, as one of the key basic technologies of autonomous driving, the feature matching positioning based on maps is a research hotspot at home and abroad, but there is little research on its intended functional safety, and the related technical field is relatively blank.
[0003] After investigation, the functional deficiency problems of the map matching positioning system are reflected in the "mismatch between the map and the real environment", which can be specifically divided into three aspects: repeated environmental features, environmental feature interference, and environmental feature change. For this functional deficiency, most of the existing research is limited to improving the scene adaptation ability of the matching positioning. For example, how to ensure the positioning accuracy under bad weather, high dynamics, and few feature conditions, and usually solve the problems faced from the aspects of algorithm software improvement and sensor hardware configuration. However, in the real environment, the number of hazard scenarios and the forms of triggering conditions are difficult to fully explore. If only targeted processing is carried out for the existing hazard scenarios, the positioning function will still face huge unknown risks in actual applications.
[0004] Based on this, it is necessary to explore as many hazard scenarios and triggering conditions as possible that the positioning function will face when operating in a preset environment at the beginning of the positioning function design, so as to reduce the unknown risks during actual operation. Although the ISO 21448 standard gives the general idea of SOTIF analysis to solve such problems, there is a lack of a systematic analysis scheme for the intended functional safety of map matching positioning. Summary of the Invention
[0005] The present disclosure aims to at least partly solve one of the technical problems in the related technologies.
[0006] To this end, the embodiments of the present disclosure provide an intended functional safety analysis method for map matching positioning that can obtain more comprehensive and effective hazard scenarios and triggering conditions, including:
[0007] Forward analysis: Set the hazard scenarios for map-matching positioning and the triggering conditions in the hazard scenarios, analyze the vehicle-level hazards caused by the triggering conditions in the hazard scenarios, and evaluate their risk levels. Establish a SOTIF hazard event model from the hazard scenarios, triggering conditions, vehicle-level hazards, and vehicle-level hazard events.
[0008] Combined forward and reverse analysis: Set a risk level threshold, and regard the vehicle-level hazard events with a risk level greater than the risk level threshold as unacceptable vehicle-level hazard events; identify the potential damages of autonomous driving accidents in the vehicle operation scenarios, and analyze the new vehicle-level hazard events that cause the potential damages. Integrate the unacceptable vehicle-level hazard events with the new vehicle-level hazard events to obtain the integrated vehicle-level hazard events.
[0009] Reverse analysis: Analyze the unsafe control behaviors based on the integrated vehicle-level hazard events, and identify the causal scenarios from the unsafe control behaviors.
[0010] Loop verification: Refine the new hazard scenarios and new triggering conditions based on the causal scenarios identified by the reverse analysis. Establish a new SOTIF hazard event model from the new hazard scenarios, new triggering conditions, and the integrated vehicle-level hazard events. Evaluate the risk level of the integrated vehicle-level hazard events to determine whether the vehicle-level hazard event is unacceptable.
[0011] Take the triggering conditions corresponding to all vehicle-level hazard events that reach the risk level threshold as the effective triggering conditions in the hazard scenarios, constituting the analysis results of the expected functional safety of map-matching positioning.
[0012] In some embodiments, the established SOTIF hazard event model is:
[0013]
[0014] Where represents "form", → represents "cause", s I and t I are respectively the defined initial hazard scenario and initial triggering condition, i C is the functional deficiency at the perception component level obtained by forward analysis, i S is the output deficiency at the positioning system level obtained by forward analysis, b V is the vehicle-level hazard behavior obtained by forward analysis, h V is the vehicle-level hazard obtained by forward analysis, s0 is the operation scenario, e V is the vehicle-level hazard event obtained by forward analysis, h H is the damage caused.
[0015] In some embodiments, the risk level threshold is set to 0.
[0016] In some embodiments, the risk level ε of each vehicle-level hazard event is set according to the following formula:
[0017] ε = f(x, y, z)
[0018] where f(·) is the functional relationship between the risk level ε and the exposure probability E evaluated according to the occurrence probability of the operating scenario s O the controllability C evaluated according to whether the vehicle-level hazard event e x is controllable, and the severity S evaluated according to the damage h V among the levels x, y, z; y H z
[0019] The vehicle-level hazards with a risk level ε > 0 are regarded as unacceptable vehicle-level hazards.
[0020] In some embodiments, the unacceptable vehicle-level hazard event ue V and the new vehicle-level hazard event caused by the potential damage The fusion process is to eliminate the same vehicle-level hazard events and only retain the different vehicle-level hazard events.
[0021] In some embodiments, the path adopted for reverse analysis is:
[0022]
[0023] where ← represents "attributed to", U represents "fusion", cs R is the causal scenario, uca R is the unsafe control behavior, e V is the unacceptable vehicle-level hazard event, is the new vehicle-level hazard event, is the damage to be avoided.
[0024] In some embodiments, the loop check includes:
[0025] Refining and locating the insufficient output of the positioning system the insufficient function of the perception component level and the trigger condition t R respectively from the causal scenarios of the results of the reverse analysis. The refining process is expressed as: represents "refining", - represents "eliminating", t I is the defined initial trigger condition. Discard the trigger conditions in t R that are consistent with the results of the forward analysis. The remaining trigger conditions in t R are used as the new trigger conditions Extract the hazard scenario s by synthesizing the scenario information in the comprehensive reverse analysis R , where the scenario corresponding to the newly added trigger condition is the newly added hazard scenario
[0026] Based on the above information extracted by reverse analysis, establish a newly added SOTIF hazard event model and inject it into the "risk assessment" stage of the forward analysis to evaluate the risk level ε of the vehicle-level hazard events therein R , and clarify whether it is unacceptable, so as to realize the loop verification of the newly added SOTIF hazard event model
[0027] In some embodiments, the effective trigger conditions under the hazard scenario include the effective trigger condition et obtained from the initial trigger condition I and the effective trigger condition et obtained from the newly added trigger condition A .
[0028] The expected functional safety analysis method for map matching positioning provided by the embodiments of the present disclosure has the following characteristics and beneficial effects
[0029] The expected functional safety analysis method for map matching positioning provided by the embodiments of the present disclosure is based on the system engineering theory and uses the means of combining forward and reverse analysis with loop verification to combine forward analysis and reverse analysis to obtain more comprehensive and effective hazard scenarios and trigger conditions. Compared with the existing general architecture, this architecture makes full use of the advantages of the forward analysis method in making full use of expert experience and the advantages of the reverse analysis method in improving the analysis completeness. Establish a forward and reverse analysis association through unacceptable vehicle-level hazard events, extract the reverse analysis results, establish a newly added SOTIF hazard event model for loop verification. Thus, the hazard scenarios and the effective trigger conditions therein can be analyzed more completely and reliably, reducing the risks faced during autonomous driving trajectory tracking BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The drawings are only for the purpose of illustrating specific embodiments and are not considered to be a limitation of the present application
[0031] Figure 1 is the overall flowchart of the expected functional safety analysis method provided by the embodiments of the present disclosure
[0032] Figure 2 is the trajectory tracking system architecture of the present disclosure based on high-precision map feature matching positioning DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] In order to make the objectives, technical solutions and advantages of the present disclosure more clearly understood, the following further describes the present disclosure in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present disclosure and are not used to limit the present disclosure.
[0034] On the contrary, the present disclosure covers any alternatives, modifications, equivalent methods and solutions made within the spirit and scope of the present disclosure defined by the claims. Further, in order to enable the public to better understand the present disclosure, some specific details are described in detail in the following detailed description of the present disclosure. Those skilled in the art can fully understand the present disclosure without the description of these details.
[0035] The present disclosure is a map matching positioning system SOTIF analysis method for autonomous driving trajectory tracking control, which combines the forward hazard analysis and risk assessment (Hazard Analysis and Risk Assessment, HARA) analysis process with the reverse system theory process analysis (System Theoretic Process Analysis, STPA) method based on "forward and reverse combination" and "loop verification". See Figure 1 , the expected functional safety analysis method for map matching positioning provided by the embodiments of the present disclosure includes:
[0036] Forward analysis: Set the hazard scenarios of map matching positioning and the triggering conditions in the hazard scenarios, analyze the vehicle-level hazards caused by the triggering conditions in the hazard scenarios, and evaluate their risk levels. Establish a SOTIF hazard event model from the hazard scenarios, triggering conditions, vehicle-level hazards, and vehicle-level hazard events.
[0037] Combination of forward and reverse analysis: Set a risk level threshold, and regard the vehicle-level hazard events with a risk level greater than the risk level threshold as unacceptable vehicle-level hazard events; identify the potential damages of autonomous driving accidents in the vehicle operation scenarios, and combine the vehicle operation scenarios to analyze the new vehicle-level hazard events that cause the potential damages. Integrate the unacceptable vehicle-level hazard events with the new vehicle-level hazard events that cause potential damages to obtain the integrated vehicle-level hazard events.
[0038] Reverse analysis: Analyze the unsafe control behaviors based on the integrated vehicle-level hazard events, and identify the causal scenarios from the unsafe control behaviors.
[0039] Loop verification: According to the causal scenarios identified by the reverse analysis, refine the new hazard scenarios and new triggering conditions. The new hazard scenarios, new triggering conditions, and integrated vehicle-level hazard events form a new SOTIF hazard event model. Evaluate the risk level of the integrated vehicle-level hazard events in it, and determine whether the vehicle-level hazard event is unacceptable.
[0040] For all vehicle-level hazard events that reach the risk level threshold, their corresponding triggering conditions are used as the effective triggering conditions in the hazard scenario, constituting the analysis result of the expected functional safety of map matching positioning.
[0041] In some embodiments, the SOTIF forward analysis process of the map feature matching positioning system for trajectory tracking control is described in detail:
[0042] Taking the following scenario in the urban area as an example for analysis: driving during the day in clear weather, the vehicle is driving at a medium speed on a road with a large curvature, some lane lines are covered by snow, there are shoulder guards on both sides of the road, and lamp posts and traffic signs are covered by snow.
[0043] The forward analysis path is as Figure 1 shown, which includes 5 steps: "defining the hazard scenario", "determining the initial triggering conditions", "analyzing functional deficiencies", "hazard analysis", and "risk assessment", and are described separately as follows:
[0044] First, through preliminary research, expert consultation, and group discussion, the initial hazard scenario s I and the initial triggering condition t I are excavated and refined. Here, "initial" refers to the incomplete initial analysis result. According to ISO 21448, a hazard scenario refers to a scenario that will produce a hazard behavior; the triggering condition is a specific condition of the scenario, acting as the starting condition for triggering subsequent system hazard behaviors. The initial hazard scenario s I in this case is: some lane lines are covered by snow, and there are shoulder guards, lamp posts, and traffic signs covered by snow on both sides of the road; the initial triggering condition t I is: in the snow-covered scenario, the sensor cannot accurately identify the corresponding environmental features in the map, resulting in a reduction in the available features for matching.
[0045] Then, based on the autonomous driving trajectory tracking control framework, as Figure 2 shown, analyze the functional deficiency modes at the perception component level and the positioning system level, and establish the "initial triggering condition t I - the functional deficiency i C at the perception component level obtained through forward analysis - the output deficiency i S at the positioning system level obtained through forward analysis" conduction path, where "functional deficiency" refers to incomplete specifications or insufficient performance, and "output deficiency" refers to incorrect output results. The functional deficiency i C at the perception component level obtained through forward analysis in this case is: (a) the sensor has insufficient ability to identify locally occluded features, and (b) the types of features available for matching in the map are insufficient; the output deficiency i S at the positioning system level obtained through forward analysis is: positioning signal jitter and offset.
[0046] Next, conduct a hazard analysis. Take the functional deficiency mode at the positioning system level as the input. Based on the working principle of the trajectory tracking system, analyze and obtain the vehicle-level hazard behavior b V and the resulting vehicle-level hazard h V , and then combine with the operating scenario s O to form the vehicle-level hazard event e V . The vehicle-level hazard event e V will cause damage h h under uncontrollable conditions. Based on the above hazard propagation link, establish the SOTIF hazard event model as follows: where represents "forming", and → represents "causing". The vehicle-level hazard behavior b V in this case is: the vehicle exhibits unexpected acceleration and steering behaviors; the resulting vehicle-level hazard h V is: the vehicle has unexpected longitudinal and lateral movements; the vehicle-level hazard event e V is: on a large-curvature road with a shoulder guardrail, the vehicle has unexpected longitudinal and lateral movements; the resulting damage h H is: the vehicle collides with the guardrail after losing control, injuring the vehicle occupants. Therefore, the established SOTIF hazard event model is shown in Table 1 below:
[0047] Table 1
[0048]
[0049] Finally, based on the SOTIF hazard event model established in the previous step, evaluate the risk level ε of the vehicle-level hazard event e V in each model. Combine the ISO26262 and ISO21448 standards, and evaluate the exposure probability E O based on the probability of occurrence of the operating scenario s x , evaluate the controllability C V based on whether the vehicle-level hazard event e y is controllable, and evaluate the severity S H based on the damage h z . Among them, the risk level ε can be designed as the relationship between the levels of E x , C y , and S z , that is: ε = f(x, y, z), where f(·) is the relationship between the risk level ε and E x , C y , and S zThe functional relationship among the levels x, y, and z. According to the ISO21448 standard, the exposure probability is not a decisive factor in risk assessment. Therefore, in the embodiments of the present disclosure, it is simply defined that ε = y + z. The vehicle-level hazard events with a risk level of 0 are not processed. Otherwise, after testing and validating the SOTIF hazard event model, through the function improvement strategy, the occurrence of vehicle-level hazard events in the SOTIF hazard event model is avoided. According to GB / T 34590.3, in this case, the proportion of ice and snow weather in the vehicle operation time is less than 1%, so E x is rated as E2; ice and snow weather belongs to the conventional operation design domain. Passengers may perceive the abnormal yaw of the vehicle in the snow-covered scenario and take the initiative to take over. However, generally, the users who can actively avoid hazards should be less than 90%. Therefore, the controllability C y is rated as C3; when the vehicle loses control and rushes onto the road shoulder and hits the guardrail at a medium speed of 30 km / h, it may cause moderate injuries to personnel but does not endanger the lives of the occupants. Therefore, the severity S z is rated as S1. The risk level ε = 4, which is greater than 0. The risk of vehicle-level hazard events in the SOTIF hazard event model is unacceptable.
[0050] The forward analysis of the embodiments of the present disclosure evaluates and validates the initial trigger conditions obtained based on expert experience, and excavates the SOTIF hazard event model of map matching and positioning in a reasonable urban scenario. However, since the method of exhaustive enumeration based on expert experience cannot consider all scenarios, the obtained model is obviously not complete. Based on this, it is necessary to conduct analysis from different perspectives to excavate more trigger conditions.
[0051] In some embodiments, the process of establishing the association between the forward analysis and the reverse analysis of SOTIF is described in detail:
[0052] In the initial stage of the reverse analysis, the forms of damage are limited and easy to enumerate. Therefore, it is not necessary to supplement the damage results of the forward analysis. However, the newly added vehicle-level hazard events related to damage are diverse and not easy to list completely. Therefore, the unacceptable vehicle-level hazard events ue of the forward analysis V are used as supplements to the newly added vehicle-level hazard events . For the above reasons, it is necessary to establish the association between the forward analysis and the reverse analysis. The method is: input the unacceptable vehicle-level hazard events ue obtained from the forward analysis V into the reverse analysis. In the stage of integrating hazard events, they are integrated with the identified newly added vehicle-level hazard events As the initial condition for the subsequent steps of reverse analysis. Fusion means: eliminating duplicate vehicle-level hazard events and only retaining different vehicle-level hazard events. (Note: In reverse analysis, "harm" is called "loss" in STPA, which refers to valuable things of stakeholders, including "personal injury", "property damage", etc. In this disclosure, for the specific object of the vehicle, harm only refers to the personal injury or health damage of traffic participants; the vehicle-level hazard events in reverse analysis are "system-level hazards" in the STPA method)
[0053] In some embodiments, the SOTIF reverse analysis process of the map feature matching positioning system for trajectory tracking control is described in detail:
[0054] The reverse analysis is as Figure 1 shown, and includes 5 steps: "defining the analysis purpose", "fusing hazard events", "system control solution modeling", "determining unsafe control behaviors", and "identifying causal scenarios", which are described separately as follows:
[0055] First, according to STPA, during the stage of defining the analysis purpose, define the harm that needs to be avoided For example: [L-1] = vehicle occupants are injured. Based on the harm, identify the system-level hazard, and its template is: [system-level hazard] = <system> & <unsafe condition> & [resulting harm], for example:
[0056] [H-1] = <vehicle> <too close to the lane guardrail> [L-1];
[0057] [H-2] = <vehicle> <too close to the vehicle in front> [L-1];
[0058] [H-3] = <vehicle> <too close to the vehicle behind> [L-1];
[0059] Refine sub-hazards based on the system-level hazard. For example, for [H-1]:
[0060] [H-1.1] = The vehicle suddenly makes an unexpected lateral movement when driving on a large-curvature road with a shoulder guardrail;
[0061] [H-1.2] = The vehicle suddenly makes an unexpected acceleration movement when driving on a large-curvature road with a shoulder guardrail;
[0062] Then fuse the hazard events, and fuse the system-level hazard with the unacceptable vehicle-level hazard event ue V For example, the ue provided by the forward analysis VIt is: the vehicle undergoes unexpected longitudinal and lateral movements when there are no other vehicles around and no shoulder protection exists on the road. It is similar to sub-hazards [H-1.1] and [H-1.2], so ue is excluded. V , retain [H-1.1], [H-1.2], [H-2.X], [H-3.X] and export them. [H-2.X] and [H-3.X] respectively represent sub-hazards refined from [H-2] and [H-3].
[0063] Secondly, establish a system control structure model, as Figure 2 shown. This system is a path tracking control framework, mainly including sensing components: lidar, high-precision map (virtual sensing component); positioning system: matching positioning algorithm; vehicle control: trajectory tracking controller. The logical relationship is: the lidar senses the external environment to generate point cloud information, which is matched with the map feature elements, and the pose information is obtained through optimal solution. The trajectory tracking controller solves the steering, driving, and braking commands according to the vehicle's own pose information, combined with the reference path and vehicle state information, and sends them to the vehicle for execution. Among them, changes in the external environment will affect the sensing performance of the lidar and at the same time affect the accuracy of the high-precision map.
[0064] Then determine the unsafe control behavior uca R , for the four types of unsafe control given by STPA: (1) failure to provide control behavior leads to danger, (2) providing control behavior leads to danger, (3) providing a potentially safe control behavior but the provided node is too early, too late, or in the wrong order, (4) the control behavior lasts too long or stops too early, analyze the steering, braking, and driving control behaviors of the trajectory tracking control. For the sake of brief explanation, only the steering control behavior is analyzed in this case. For the sake of correspondence with the forward analysis, only [H-1.1] is analyzed in this embodiment, and the analysis results are shown in Table 2 below.
[0065] Table 2
[0066]
[0067]
[0068] Finally, identify the causal scenario cs R . According to the STPA description, the causal scenario is: the inducing factors that may lead to unsafe control behavior and danger. Since the output of the positioning system is the input of the trajectory tracking controller, therefore, consider "why there is unsafe control behavior" from the controller input end, and do not consider insufficient execution from the actuator end. Only the causal scenario for [UCA-1] is analyzed below, as shown in Table 3. Thus, establish a reverse analysis path: where ← represents "attributed to".
[0069] Table 3
[0070]
[0071] The reverse analysis of the embodiments of the present disclosure starts from "harm", combines the unacceptable vehicle-level hazard events in the forward analysis, and gradually analyzes the causal scenarios according to the STPA method. The triggering conditions that are richer and more complete than expert experience can be extracted from the causal scenarios.
[0072] In some embodiments, the process of establishing a new SOTIF hazard event model and performing a loop check is described in detail:
[0073] Refine and locate the insufficient output of the positioning system from the causal scenarios of the reverse analysis Refine the insufficient functions at the perception component level Refine the triggering condition t R , as shown in Table 4 below. According to the results in Table 4, it can be obtained that: Trigger condition (1) is consistent with the forward analysis, and the harm obtained from it is consistent with the forward analysis. Therefore, this trigger condition is discarded, and trigger condition (2) is used as the new trigger condition "Refine" is represented by "", and "excluding" is represented by "-". Then, by integrating the scenario information in the reverse analysis, the hazard scenario s is refined R , where the scenario corresponding to the new trigger condition is the new hazard scenario
[0074] Table 4
[0075]
[0076]
[0077] Based on the above information from the reverse analysis, a new SOTIF hazard event model is established, as shown in Table 5 below. It is injected into the "risk assessment" stage of the forward analysis, and a loop check of the new SOTIF hazard event model is performed to evaluate the risk level ε of the integrated vehicle-level hazard event R , and determine whether it is unacceptable. For the cases in Table 5, the probability of the operating scenario occurring is low, accounting for less than 1% of the vehicle operating time. Therefore, E x The rating is E2; when the vehicle is driving on a road with a large curvature and there is a large vehicle blocking in the front at a short distance, passengers may perceive the abnormal yaw of the vehicle and take the initiative to take over. However, generally, the users who can actively avoid hazards should be less than 90%. Therefore, the controllability rating is C3; when the vehicle is out of control at a medium speed of 30 km / h and rushes onto the road shoulder and hits the guardrail, it may cause serious injuries to people. Therefore, the severity rating is S2. The risk level ε of the integrated vehicle-level hazard event R = 5, which is greater than 0, and its risk is unacceptable.
[0078] Table 5
[0079]
[0080]
[0081] In the embodiments of the present disclosure, by extracting the results of reverse analysis, a new SOTIF hazard event model is established, and then a risk assessment method is used for loopback verification to form an analysis closed-loop, thereby effectively verifying the new SOTIF hazard event model obtained by reverse analysis and obtaining new triggering conditions with risks.
[0082] In some embodiments, filtering and outputting the SOTIF analysis results includes:
[0083] Outputting effective triggering conditions under hazard scenarios: After performing hazard analysis, outputting a new SOTIF hazard event model that satisfies the risk level ε>0. The triggering conditions in the model are the effective triggering conditions, including the effective triggering condition et obtained from the initial triggering condition I and the effective triggering condition et obtained from the new triggering condition A . By outputting the effective triggering conditions, the unknown hazard scenarios are reduced, and the problem of identifying unknown hazards as known hazards is solved.
[0084] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0085] Although the examples of the present invention have been shown and described above, it can be understood that the above examples are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above examples within the scope of the present invention.
Claims
1. An expected functional safety analysis method for map matching positioning, characterized in that, Including: Forward analysis: Set the hazard scenarios for map matching positioning and the triggering conditions in the hazard scenarios, analyze the vehicle-level hazards caused by the triggering conditions in the hazard scenarios, and evaluate their risk levels. Establish a SOTIF hazard event model from the hazard scenarios, triggering conditions, vehicle-level hazards, and vehicle-level hazard events. Combined forward and reverse analysis: Set a risk level threshold, regard the vehicle-level hazard events with a risk level greater than the risk level threshold as unacceptable vehicle-level hazard events, identify the potential damages of autonomous driving accidents in the vehicle operation scenarios, and analyze the new vehicle-level hazard events that cause the potential damages. Integrate the unacceptable vehicle-level hazard events and the new vehicle-level hazard events to obtain the integrated vehicle-level hazard events. Reverse analysis: Analyze the unsafe control behaviors based on the integrated vehicle-level hazard events, and identify the causal scenarios from the unsafe control behaviors. Loop verification: According to the causal scenarios identified by the reverse analysis, refine the new hazard scenarios and new triggering conditions, establish a new SOTIF hazard event model from the new hazard scenarios, new triggering conditions, and the integrated vehicle-level hazard events, evaluate the risk level of the integrated vehicle-level hazard events, and determine whether the vehicle-level hazard events are unacceptable. Take the triggering conditions corresponding to all the vehicle-level hazard events that reach the risk level threshold as the effective triggering conditions in the hazard scenarios, and form the analysis results of the expected functional safety of map matching positioning.
2. The expected functional safety analysis method according to claim 1, wherein Set the risk level threshold to 0.
3. The expected functional safety analysis method according to claim 1, characterized in that, Set the risk level ε of each vehicle-level hazard event according to the following formula: ε = f(x, y, z) where f(·) is the function relationship between the risk level ε and the exposure probability E evaluated according to the probability of the occurrence of the operation scenario x , the controllability C evaluated according to whether the vehicle-level hazard event is controllable y , the severity S evaluated according to the damage caused z among the levels x, y, z, and this method defines ε = y + z; Regard the vehicle-level hazard events with ε > 0 as unacceptable vehicle-level hazard events.
4. The expected functional safety analysis method according to claim 1, wherein For the integration process of the unacceptable vehicle-level hazards and the new vehicle-level hazards that cause potential damages, the same vehicle-level hazard events are eliminated, and only the different vehicle-level hazard events are retained.
5. The expected functional safety analysis method according to claim 1, wherein The loop verification includes: From the cause scenario cs of the result of reverse analysis R respectively refine the insufficient output of the positioning system and the insufficient functions at the perception component level and the triggering condition t R , and the refinement process is expressed as: represents "refinement", - represents "removal", and t I is the defined initial triggering condition. Discard the triggering conditions in t R that are consistent with the results of forward analysis. The remaining triggering conditions in t R are used as newly added triggering conditions Integrate the scenario information in the reverse analysis to refine the hazard scenario s R , where the scenario corresponding to the newly added triggering condition is the newly added hazard scenario Based on the above information refined through reverse analysis, establish a new SOTIF hazard event model, inject it into the risk assessment stage of forward analysis, and evaluate the risk level ε of vehicle-level hazard events therein R , clarify whether it is unacceptable, and implement a loop check on the new SOTIF hazard event model.
6. The expected functional safety analysis method according to claim 1, wherein The effective triggering conditions in the described hazard scenarios include the effective triggering condition et obtained from the initial triggering conditions I and the effective triggering condition et obtained from the newly added triggering conditions A .
Citation Information
Patent Citations
Method for carrying out hazard assessment by risk analysis on road vehicle speediness
CN108510185A
Processing device, processing method, processing program, and processing system
WO2022168672A1