A functional safety design verification method, device, equipment and medium

By introducing functional safety testing layer software into the device under test, fault injection and verification are performed, solving the problem of difficulty in testing software functional safety in existing technologies. This enables comprehensive functional safety testing of automotive electronic control systems and improves the reliability and coverage of the tests.

CN116204434BActive Publication Date: 2025-11-11IMOTION AUTOMOTIVE TECH (SUZHOU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310204599.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-06
Publication Date
2025-11-11
Estimated Expiration
2043-03-06

AI Technical Summary

Technical Problem

Existing technologies make it difficult to conduct functional safety testing of software, especially in automotive electronic control systems. Fault injection testing mainly focuses on interface testing at the vehicle level or the interface level of a single ECU, which cannot effectively verify whether the software functions meet functional safety requirements.

Method used

By introducing functional safety test layer software into the device under test, test information is acquired and faults are injected to verify whether the functional safety layer software can meet functional safety requirements. This includes an information transmission module, a fault injection module, and a verification module. The output controller outputs target information to the target vehicle to determine the function of the functional safety layer software.

Benefits of technology

It enables comprehensive testing of the internal functional safety design of the device under test, improves the reliability and coverage of the test, and ensures that the functional safety layer software plays a functional safety role in actual software and vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116204434B_ABST
    Figure CN116204434B_ABST
Patent Text Reader

Abstract

This application discloses a functional safety design verification method, apparatus, device, and medium, relating to the field of computer technology and applied to the device under test. It includes functional layer software, functional safety test layer software, functional safety layer software, and an output controller. The method includes: outputting a calculated first information value to the functional safety test layer software via the functional layer software; injecting a fault into a temporary information value determined from the first information value via the functional safety test layer software to obtain a fault injection value; and, when the fault injection value and a reference information value determined from the calculated second information value are inconsistent, outputting corresponding target information to the target vehicle via the output controller, so that the functional safety layer software is deemed to be fulfilling its functional safety function when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results. The functional safety test layer software is used to inject faults to determine whether the functional safety layer software is functioning correctly.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a method, apparatus, device, and medium for functional safety design verification. Background Technology

[0002] Currently, with the maturity of automotive electronics technology, automotive electronic control technology has developed rapidly. The diversification of electronic control systems included in vehicles has made automotive functions increasingly perfect. Since electronic control systems play a key role in realizing various functions, their reliability and stability are receiving increasing attention. In order to ensure that various functions of real vehicles meet the design requirements for reliability and stability, various tests need to be carried out on these modules during the real vehicle development process. Among them, fault injection testing is an important part of the safety development testing project.

[0003] Currently, most fault injection tests are based on interface testing at the vehicle level or interface testing of a single ECU (Electronic Control Unit). For situations where it is necessary to verify whether the software functional design itself can meet functional safety requirements, due to the high testing difficulty, only some code-level tests are performed, and internal testing of the ECU cannot be performed. Moreover, such tests are not software functional safety level tests.

[0004] In conclusion, how to conduct functional safety testing of software is an urgent problem to be solved. Summary of the Invention

[0005] In view of this, the purpose of this invention is to provide a functional safety design verification method, apparatus, device, and medium, capable of performing software functional safety layer testing to fully verify whether the functional safety layer software performs its functional safety function. The specific solution is as follows:

[0006] In a first aspect, this application discloses a functional safety design verification method applied to a device under test, wherein the device under test includes functional layer software, functional safety test layer software, and functional safety layer software, and the method includes:

[0007] The functional layer software acquires test information and outputs the test information and the first information value calculated for the latest vehicle function information to the functional safety test layer software.

[0008] The functional safety test layer software performs fault injection on the temporary information value determined from the first information value based on the test information to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and sends the fault injection value to the functional safety layer software.

[0009] The functional safety layer software acquires the test information, and when the fault injection value and the reference information value that meets the functional safety requirements, determined from the second information value calculated based on the test information from the latest vehicle functional information, are inconsistent, the output controller outputs corresponding target information to the target vehicle, so that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results.

[0010] Optionally, the functional safety test layer software includes a connection interface to the functional layer software, a test script submodule, and a connection interface to the functional safety layer software; the test script submodule includes several test scripts; the several test scripts are different test scripts generated using different test cases set for the device under test that do not meet functional safety requirements.

[0011] Optionally, the step of injecting a fault into a temporary information value determined from the first information value based on the test information using the functional safety test layer software to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and sending the fault injection value to the functional safety layer software, includes:

[0012] The test information and the first information value are obtained through the connection function layer software interface of the functional safety test layer software, and the test information and the first information value are sent to the test script submodule.

[0013] The test script submodule determines the target test script based on the test information, and uses the target test script to inject faults into the temporary information value determined from the first information value based on the test information, thereby obtaining a fault injection value that does not meet the functional safety requirements of the device under test.

[0014] The fault injection value is sent to the functional safety layer software through the connection functional safety layer software interface of the functional safety test layer software.

[0015] Optionally, the first information value is an information value calculated by the functional layer software for the latest vehicle function information; the second information value is an information value calculated by the functional safety layer software for the latest vehicle function information and the functional safety requirements; the latest vehicle function information is information sent by the input controller associated with the device under test to the functional layer software and the functional safety layer software based on a preset period.

[0016] Optionally, the latest vehicle function information includes numerical information and status information.

[0017] Optionally, the step of injecting a fault injection value that does not meet the functional safety requirements of the device under test by injecting a temporary information value determined from the first information value based on the test information using the functional safety test layer software includes:

[0018] The functional safety test layer software modifies the first state value of the target state information determined from the first information value based on the test information to obtain a second state value that does not meet the functional safety requirements of the device under test.

[0019] Accordingly, the step of obtaining the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements, determined from the second information value calculated based on the test information from the latest vehicle functional information, are inconsistent, outputting corresponding target information to the target vehicle through the control output device includes:

[0020] The test information is obtained through the functional safety layer software, and a third state value of the target state information that meets the functional safety requirements is determined from the second information value calculated for the latest vehicle function information based on the test information.

[0021] The comparison result is obtained by comparing the third state value and the second state value. If the comparison result is inconsistent, the error message corresponding to the target state information is output to the target vehicle through the control output device.

[0022] Optionally, the step of injecting a fault injection value that does not meet the functional safety requirements of the device under test by injecting a temporary information value determined from the first information value based on the test information using the functional safety test layer software includes:

[0023] The functional safety testing layer software modifies the first value of the target value information determined from the first information value based on the test information to obtain a second value that does not meet the functional safety requirements of the device under test.

[0024] Accordingly, the step of obtaining the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements, determined from the second information value calculated based on the test information from the latest vehicle functional information, are inconsistent, outputting corresponding target information to the target vehicle through the control output device includes:

[0025] The test information is obtained through the functional safety layer software, and the numerical range of the target numerical information that meets the functional safety requirements is determined from the second information value calculated for the latest vehicle functional information based on the test information.

[0026] The comparison result is obtained by comparing the value range value and the second value. If the comparison result is that the second value exceeds the value range value, the output value is determined according to the preset rule and based on the second value and the value range value. The output value and the error prompt information corresponding to the target value information are output to the target vehicle through the control output device.

[0027] Secondly, this application discloses a functional safety design verification device applied to a device under test, the device under test including functional layer software, functional safety test layer software, and functional safety layer software, the method comprising:

[0028] The information transmission module is used to acquire test information through the functional layer software and output the test information and a first information value calculated for the latest vehicle functional information to the functional safety test layer software.

[0029] The fault injection module is used to inject a fault into a temporary information value determined from the first information value based on the test information through the functional safety test layer software to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and to send the fault injection value to the functional safety layer software.

[0030] The verification module is used to acquire the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements determined from the second information value calculated based on the test information for the latest vehicle functional information are inconsistent, the module outputs corresponding target information to the target vehicle through the output controller, so as to determine that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results.

[0031] Thirdly, this application discloses an electronic device, including:

[0032] Memory, used to store computer programs;

[0033] A processor is used to execute the computer program to implement the aforementioned disclosed functional safety design verification method.

[0034] Fourthly, this application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned disclosed functional safety design verification method.

[0035] As can be seen, this application obtains test information through the functional layer software and outputs the test information and a first information value calculated for the latest vehicle functional information to the functional safety test layer software; the functional safety test layer software performs fault injection on a temporary information value determined from the first information value based on the test information to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and sends the fault injection value to the functional safety layer software; the functional safety layer software obtains the test information, and when the fault injection value and a reference information value that meets the functional safety requirements determined from a second information value calculated for the latest vehicle functional information based on the test information are inconsistent, the output controller outputs corresponding target information to the target vehicle, so that when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results, it is determined that the functional safety layer software plays a functional safety role. Therefore, this application adds functional safety testing layer software to the device under test (DUT) to inject faults and obtain fault injection values ​​that do not meet functional safety requirements for testing the software's functional safety level. In this application, if the target information and the actual performance are consistent with the expected results determined based on the test information, then the transmitted target information meets functional safety requirements. This indicates that the functional safety layer software avoids sending information related to fault injection values ​​that do not meet functional safety requirements to the target vehicle, thus the functional safety layer software plays a functional safety role. This application performs fault injection in the actual software, and then judges whether the safety function is played by obtaining target information after fault injection and judging the actual vehicle performance based on the target information. In other words, the testing work is arranged in the actual software and vehicle, rather than just testing the interface layer at the code level, thus improving the reliability of the test. Furthermore, the test in this application tests the internal functional safety design of the DUT, that is, the functional safety layer software, rather than just testing the interface layer of the DUT, thus achieving high test coverage. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0037] Figure 1 This is a flowchart of a functional safety design verification method disclosed in this application;

[0038] Figure 2 This application discloses a specific functional safety design verification method flowchart;

[0039] Figure 3 This is a schematic diagram of a functional safety test layer software structure disclosed in this application;

[0040] Figure 4 This is a schematic diagram of the first internal structure and output controller of a device under test disclosed in this application;

[0041] Figure 5 This is a schematic diagram of the internal second structure and output controller of the device under test disclosed in this application.

[0042] Figure 6 This is a schematic diagram of the structure of a functional safety design verification device disclosed in this application;

[0043] Figure 7 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] Currently, most fault injection tests are based on interface testing at the vehicle level or interface testing of a single ECU. For situations where it is necessary to verify whether the software functional design itself can meet functional safety requirements, due to the high testing difficulty, only some code-level tests are performed. Such tests are not software functional safety level tests.

[0046] Therefore, this application proposes a functional safety function verification scheme, which can perform software functional safety level testing to fully verify whether the functional safety layer software plays a functional safety role.

[0047] This application discloses a functional safety design verification method applied to a device under test (DUT). The DUT includes functional layer software, functional safety test layer software, and functional safety layer software. (See also...) Figure 1 As shown, the method includes:

[0048] Step S11: Obtain test information through the functional layer software, and output the test information and the first information value calculated for the latest vehicle function information to the functional safety test layer software.

[0049] In this embodiment of the application, the device under test belongs to a functional safety design verification system. The functional safety design verification system includes a fault triggering module, the device under test, and a monitoring and recording module. The device under test includes functional layer software, functional safety test layer software, functional safety layer software with functional safety design, and an output controller.

[0050] It should be noted that this application obtains the test information sent by the fault triggering module through the functional layer software; the test information includes a test identifier and a test trigger signal. It should also be noted that the fault triggering module sends the test information selected by the user according to the test requirements to the device under test. At this time, the functional layer software in the device under test obtains the test information, and the functional layer software sends the first information value calculated based on the latest vehicle function information and the test information to the functional safety test layer software.

[0051] In this embodiment, the first information value is an information value calculated by the functional layer software for the latest vehicle function information; the latest vehicle function information is information sent by the input controller associated with the device under test to the functional layer software and the functional safety layer software based on a preset period; the first information value includes different information values ​​corresponding to different latest vehicle function information. It should be noted that the preset period can be specifically set according to the actual situation, and the preset period includes, but is not limited to, 10ms and 20ms, and is not specifically limited here.

[0052] It should be noted that the latest vehicle function information includes, but is not limited to, status information and numerical information. When the device under test corresponds to ADAS (Advanced Driving Assistance System) functions, the latest vehicle function information includes, but is not limited to, status information, vehicle speed information, and acceleration information, where the vehicle speed information and the acceleration information are numerical information. For example, the functional layer software uses the acquired acceleration information (e.g., acceleration increase of 2 m / s²) to... 2 Calculate the current acceleration information (e.g., 4 m / s²). 2 The calculated value at this point is an acceleration of 4 m / s². 2 Of course, there are also cases where the acceleration changes to 0.

[0053] It should be noted that this application also outputs the first information value to the output control module through the functional layer software, for use in the subsequent output of information values ​​that do not participate in fault injection. Alternatively, it is not necessary to output the first information value to the output control module; instead, the output controller can output that the first information value is obtained and output from the functional layer software.

[0054] Step S12: The functional safety test layer software performs fault injection on the temporary information value determined from the first information value based on the test information to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and sends the fault injection value to the functional safety layer software.

[0055] In this embodiment, it is necessary to determine the temporary information for fault injection based on the test information from the first information value. The functional safety requirement is the functional requirement that enables the target vehicle to function normally. When the latest vehicle functional information is target state information, the safety functional requirement of the target state information is used to specifically define the state value corresponding to the target state information; when the latest vehicle functional information is target numerical information, the safety functional requirement of the target numerical information is used to specifically define the numerical range corresponding to the target numerical information, for example, the acceleration safety requirement is 2 m / s². 2 Up to 8m / s 2 .

[0056] In one specific embodiment, the functional safety testing layer software modifies the first state value of the target state information determined from the first information value based on the test information to obtain a second state value that does not meet the functional safety requirements of the device under test. The temporary information value is the first state value of the target state information, and the fault injection value is the second state value.

[0057] In another specific embodiment, the functional safety testing layer software modifies the first value of the target numerical information determined from the first information value based on the test information to obtain a second value that does not meet the functional safety requirements of the device under test; wherein, the temporary information value is the first value of the target numerical information, and the fault injection value is the second value. For example, the temporary information value, i.e., the first value, is an acceleration of 4 m / s². 2 At that time, a fault injection was performed (acceleration increased by 8 m / s²). 2 The fault injection value, also known as the second numerical acceleration, was obtained as 12 m / s². 2 However, the acceleration safety requirement is 2 m / s². 2 Up to 8m / s 2 Therefore, the second value does not meet the functional safety requirements of the device under test.

[0058] It should be noted that, apart from the temporary information value, the other information values ​​in the first information value can be sent directly to the functional safety layer software through the functional safety test layer software without fault injection.

[0059] Step S13: Obtain the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements determined from the second information value calculated based on the test information for the latest vehicle functional information are inconsistent, output the corresponding target information to the target vehicle through the output controller, so as to determine that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results.

[0060] In this embodiment of the application, the test information sent by the fault triggering module is obtained through the functional safety layer software; the second information value is the information value calculated by the functional safety layer software based on the latest vehicle function information and the functional safety requirements; the latest vehicle function information is the information sent by the input controller associated with the device under test to the functional layer software and the functional safety layer software based on a preset period.

[0061] In one specific embodiment, the test information is obtained through the functional safety layer software, and a third state value of the target state information that meets the functional safety requirements is determined from the second information value calculated for the latest vehicle functional information based on the test information; the third state value and the second state value are compared to obtain a comparison result; if the comparison result is inconsistent, an error message corresponding to the target state information is sent to the target vehicle. It should be noted that the first state value and the third state value may be the same or different. In addition, due to the existence of the fault injection process, the second state value and the third state value may not be consistent.

[0062] It should be noted that the error message information includes, but is not limited to, DTC (fault code) information.

[0063] In another specific embodiment, the test information is obtained through the functional safety layer software, and based on the test information, a target numerical information range that meets the functional safety requirements is determined from the second information value calculated for the latest vehicle functional information. The numerical range value and the second value are compared to obtain a comparison result. If the comparison result indicates that the second value exceeds the numerical range value, an output value is determined according to a preset rule and based on the second value and the numerical range value. The output value and the error message corresponding to the target numerical information are then output to the target vehicle through the control output device. It should be noted that due to the fault injection process, the second value will definitely exceed the numerical range value.

[0064] It should be noted that the error message includes a first enable signal, which prevents the output controller from outputting a temporary information value (e.g., a second value or a second status value).

[0065] It should be noted that the preset rule can be to randomly select a value from the value range as the output value when the second value exceeds the value range, or to select the value that is smaller than the second value among the maximum and minimum values ​​in the value range as the output value.

[0066] In this embodiment, after the output controller outputs the corresponding target information to the target vehicle, the monitoring and recording module monitors and records the target information and the actual performance of the target vehicle based on the target information. When the target information and the actual performance are consistent with the expected results, it is determined that the functional safety layer software has performed its functional safety function. It is understood that the expected results are the target preset information and target preset performance specified by the target test script. It should be noted that a test report can be generated based on the target information, actual performance, expected results, and the above comparison results for subsequent review.

[0067] In one specific embodiment, the monitoring and recording module monitors and records the error messages corresponding to the target status information and the actual performance of the target vehicle based on the error messages. If the error messages and the actual performance are consistent with the expected results determined based on the test information, then the functional safety layer software performs its functional safety function. It should be noted that the actual performance may be exiting the device under test after receiving the error message.

[0068] In another specific embodiment, the monitoring and recording module monitors and records the output value, the error message corresponding to the target value, and the actual performance of the target vehicle. If the output value, the error message corresponding to the target value, and the actual performance are consistent with the expected result determined based on the test information, then the functional safety layer software performs its functional safety function. If the target value range corresponds to vehicle speed information, then the actual performance can be driving with the output value as the vehicle speed.

[0069] It should be noted that after the other information values ​​in the first information value, excluding the temporary information value, are sent to the functional safety layer software through the functional safety test layer software, if the other information values ​​match the corresponding other information values ​​in the second information value, excluding the second information value, a second enable signal can be sent to the output controller so that the output controller can output the other information values ​​obtained from the functional layer software; if there are inconsistent information values ​​in the other information values ​​during the comparison process, the output controller will send information indicating that the functional safety design verification system product is erroneous.

[0070] As can be seen, this application adds functional safety testing layer software to the device under test (DUT) to perform fault injection and obtain fault injection results that do not meet functional safety requirements, so as to conduct software functional safety level testing. In this application, if the target information and the actual performance are consistent with the expected results determined based on the test information, it indicates that the target information issued according to the comparison results meets the functional safety requirements. This means that the functional safety layer software avoids sending relevant information of fault injection results that do not meet functional safety requirements to the target vehicle, thus the functional safety layer software plays a functional safety role. This application performs fault injection in the actual software, and then judges whether the safety role is played by obtaining target information after fault injection and the actual vehicle performance based on the target information. That is, the testing work is arranged in the actual software and vehicle, rather than just testing the code level of the interface layer, which improves the reliability of the test. In addition, the test of this application tests the functional safety design inside the DUT, that is, tests the functional safety layer software, rather than just testing the interface layer of the DUT, so the test coverage is high.

[0071] This application discloses a specific functional safety design verification method applied to a device under test (DUT). The DUT includes functional layer software, functional safety test layer software, functional safety layer software, and an output controller. The functional safety test layer software includes an interface connecting to the functional layer software, a test script submodule, and an interface connecting to the functional safety layer software. Compared to the previous embodiment, this embodiment further explains and optimizes the technical solution. See also... Figure 2 As shown, it specifically includes:

[0072] Step S21: Obtain test information through the functional layer software, and output the test information and the first information value calculated for the latest vehicle function information to the functional safety test layer software.

[0073] In the embodiments of this application, such as Figure 3 The diagram shown is a schematic of the functional safety test layer software structure. The functional safety test layer software includes an interface for connecting to the functional layer software, a test script submodule, and an interface for connecting to the functional safety layer software.

[0074] In this embodiment, the test script submodule includes several test scripts; these test scripts are different test scripts generated by the central processing unit using different test cases set for the device under test that do not meet functional safety requirements. It should be noted that before obtaining the test information sent by the fault triggering module through the connection function layer software interface, the central processing unit generates several test scripts and integrates them into the functional safety test layer software to obtain the test script submodule. Then, a real vehicle environment is built, allowing the entire process to be completed in a real vehicle environment.

[0075] In this embodiment of the application, the test information includes a test identifier and test trigger information. The test identifier has a one-to-one correspondence with the test script. It should be noted that the test trigger information may be sent to the functional safety test layer software or may not be sent to the functional safety test layer software.

[0076] Step S22: Obtain the test information and the first information value through the connection function layer software interface of the functional safety test layer software, and send the test information and the first information value to the test script submodule.

[0077] Step S23: The test script submodule determines the target test script based on the test information, and uses the target test script to inject faults into the temporary information value determined from the first information value based on the test information, thereby obtaining a fault injection value that does not meet the functional safety requirements of the device under test.

[0078] In this embodiment of the application, a one-to-one correspondence between the test identifier and the vehicle function can be established in advance (at this time, the test identifier and the first information value calculated based on the latest vehicle function information have a one-to-one correspondence), so that a temporary information value can be determined from the first information value based on the test identifier in the future.

[0079] In another specific embodiment, the vehicle function corresponding to the test script can be recorded in the test script to establish a one-to-one correspondence between the test script and the first information value, so as to obtain the temporary information value from the first information value based on the test script later.

[0080] In this embodiment, a pre-set test script is used for fault injection, eliminating the need for manual operation and making the verification process faster and simpler.

[0081] Step S24: Send the fault injection value to the functional safety layer software through the connection functional safety layer software interface of the functional safety test layer software.

[0082] Step S25: Obtain the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements determined from the second information value calculated based on the test information for the latest vehicle functional information are inconsistent, output the corresponding target information to the target vehicle through the output controller, so as to determine that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results.

[0083] For a more detailed description of the process of step S25, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.

[0084] As can be seen, this application utilizes the test script in the test script submodule of the functional safety test layer software to inject faults into the temporary information value from the first information value to obtain fault injection results that do not meet the functional safety requirements, so as to conduct software functional safety level testing; the existence of the test script makes the verification process faster and simpler.

[0085] For example, see a specific ADAS function. Figure 4 The diagram shows the internal structure and output controller of the device under test (DUT). The DUT includes functional layer software, functional safety layer software, and an output controller. The main process for normal ADAS function implementation is as follows: The input signals (vehicle function change information) are all the signals required to implement this ADAS function, including state machine signals, vehicle speed signals, acceleration / deceleration feedback signals, etc. These signals are stored in different locations within the DUT to prevent common-cause failures in the input signals of the functional layer software and the functional safety layer software. The functional layer software is the normal ADAS function implementation module. In systems that do not require functional safety, only the functional layer software is needed to meet normal functional requirements. However, to meet the functional safety requirements of this ADAS function, functional safety layer software is introduced during the ADAS function design process.

[0086] In this ADAS function, the output of the functional layer software is actually the status signal and acceleration / deceleration signal of this ADAS function. If this ADAS function has no functional safety requirements (no functional safety layer software), the output of the functional layer software can be directly output through the output controller. After the vehicle actuator receives this control signal, it can implement acceleration, deceleration and other controls on the vehicle. If this ADAS function has functional safety requirements (with functional safety layer software), the functional safety layer software actually runs synchronously while the functional layer software is running. The functional layer software obtains acceleration and deceleration values ​​(for the vehicle speed signal) and determines whether the ADAS function meets the activation requirements (for the functional state machine signal) based on the input vehicle speed signal and functional state machine signal. The functional safety layer software calculates the acceleration and deceleration limits of this ADAS function and determines whether the ADAS function meets the activation requirements based on the input vehicle speed signal and functional state machine signal. The functional layer software sends its output results to the functional safety software module. The functional safety layer software compares the calculation results with the output results of the functional layer software. If the comparison result indicates that the acceleration and deceleration values ​​are within the acceleration and deceleration limits, the acceleration and deceleration values ​​output by the functional layer software are directly transmitted through the output controller module. Output: If the comparison result indicates that the acceleration / deceleration value is outside the acceleration / deceleration limit, then the maximum value or any value of the acceleration / deceleration limit will be directly output through the output controller; if the comparison result indicates that the judgment results of the functional layer software and the functional layer safety software regarding whether the ADAS function meets the activation requirements are different (different state values ​​corresponding to the state machine signals), then the functional safety layer software will put this ADAS function into a safe state (such as ADAS function exit), and output the corresponding error message information, including DTC information, through the output controller; if the comparison result indicates that the judgment results of the functional layer software and the functional layer safety software regarding whether the ADAS function meets the activation requirements are the same (the same state values ​​corresponding to the state machine signals), then the output result (state value) of the functional layer software will be directly output through the output controller module.

[0087] The above process describes the functional safety procedures for a specific ADAS function. To verify the completeness and effectiveness of the functional safety layer software design, testing and verification are required after the design is completed. See [link / reference] Figure 5 The diagram shows the internal second structure and output controller of the device under test. Functional safety test layer software is introduced into the device under test. The functional safety test layer software mainly acquires the output of the functional layer software and injects faults according to functional safety requirements, and then transmits it to the functional safety layer software. The functional safety layer software controls the output controller module by judgment and outputs the results to the actual vehicle through the signal output interface. The test results and the actual vehicle performance are observed and recorded by the monitoring / recording system, thereby verifying whether the functional safety layer plays a functional safety role.

[0088] Taking the ADAS function mentioned above as an example, in order to test the functional safety layer for different functional safety requirements (different fault injections), it is necessary to send the test ID number and test trigger signal to the device under test according to the test requirements through the fault trigger module, and then send it to the functional safety test layer software through the internal signal link of the device under test, and then transmit it to the test script submodule of the functional safety test layer software, thereby triggering the functional safety test layer software to perform corresponding fault injection. The functional safety test layer software receives results from the functional layer software, including the status signals of the ADAS function and the acceleration / deceleration signals of the target. It then injects faults into the ADAS function's output, such as changing the ADAS function's status signal (which should be suppressed, correct information) to "the ADAS function should be activated, incorrect information." This incorrect information is then output to the functional safety layer software. The functional safety layer software, based on its own calculations, judges and compares the incorrect information. If necessary, it performs error handling, causing the ADAS function to enter a safe state (e.g., ADAS function deactivation). The output controller then outputs corresponding error messages, including DTC (Disruption Troubleshooting) information, and finally, the error messages are output to the actual vehicle via the signal output interface. A monitoring / recording system observes and records the test results and the actual vehicle's performance, thus verifying whether the functional safety layer is functioning correctly.

[0089] Accordingly, this application also discloses a functional safety design verification device for a device under test (DUT), the DUT including functional layer software, functional safety test layer software, functional safety layer software, and output control. (See also...) Figure 6 As shown, the device includes:

[0090] Information transmission module 11 is used to acquire test information through the functional layer software and output the test information and a first information value calculated for the latest vehicle functional information to the functional safety test layer software.

[0091] The fault injection module 12 is used to inject faults into the temporary information value determined from the first information value based on the test information through the functional safety test layer software to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and send the fault injection value to the functional safety layer software.

[0092] The verification module 13 is used to obtain the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements determined from the second information value calculated based on the test information for the latest vehicle functional information are inconsistent, the output controller outputs corresponding target information to the target vehicle, so as to determine that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results.

[0093] For more detailed information on the working process of each of the above modules, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.

[0094] As can be seen, this application adds functional safety testing layer software to the device under test (DUT) to perform fault injection and obtain fault injection values ​​that do not meet functional safety requirements for software functional safety testing. In this application, if the target information and the actual performance are consistent with the expected results determined based on the test information, then the transmitted target information meets functional safety requirements. This indicates that the functional safety layer software avoids sending information related to fault injection values ​​that do not meet functional safety requirements to the target vehicle, thus the functional safety layer software plays a functional safety role. This application performs fault injection in the actual software, and then judges whether the safety function is played by obtaining target information after fault injection and judging the actual vehicle performance based on the target information. In other words, the testing work is arranged in the actual software and vehicle, rather than just testing the interface layer at the code level, which improves the reliability of the test. Furthermore, the test in this application tests the internal functional safety design of the DUT, that is, the functional safety layer software, rather than just the interface layer of the DUT, thus achieving high test coverage.

[0095] Furthermore, embodiments of this application also provide an electronic device. Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0096] Figure 7 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a display screen 23, an input / output interface 24, a communication interface 25, a power supply 26, and a communication bus 27. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the functional safety design verification method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0097] In this embodiment, the power supply 26 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 25 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 24 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0098] Furthermore, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk, or optical disk, etc. The resources stored thereon may include computer programs 221, and the storage method may be temporary storage or permanent storage. The computer programs 221 may include, in addition to computer programs capable of performing the functional safety design verification method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, computer programs capable of performing other specific tasks.

[0099] Furthermore, embodiments of this application also disclose a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned disclosed functional safety design verification method.

[0100] For the specific steps of this method, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.

[0101] The various embodiments in this application are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. For the same or similar parts between the various embodiments, refer to each other. As for the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and relevant parts can be referred to in the method section.

[0102] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0103] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0104] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0105] The functional safety design verification method, apparatus, device, and storage medium provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A functional safety design verification method, characterized in that, Applied to a device under test, the device under test includes functional layer software, functional safety test layer software, functional safety layer software, and an output controller. The method includes: The functional layer software acquires test information and outputs the test information and the first information value calculated for the latest vehicle function information to the functional safety test layer software. The functional safety test layer software performs fault injection on the temporary information value determined from the first information value based on the test information to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and sends the fault injection value to the functional safety layer software. The functional safety layer software acquires the test information, and when the fault injection value and the reference information value that meets the functional safety requirements determined from the second information value calculated based on the test information for the latest vehicle functional information are inconsistent, the output controller outputs corresponding target information to the target vehicle, so that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results. The functional safety test layer software includes a connection interface to the functional layer software, a test script submodule, and a connection interface to the functional safety layer software; the test script submodule includes several test scripts; the several test scripts are different test scripts generated using different test cases set for the device under test that do not meet the functional safety requirements; The step of injecting a fault injection value that does not meet the functional safety requirements of the device under test by performing fault injection on a temporary information value determined from the first information value based on the test information through the functional safety test layer software, and sending the fault injection value to the functional safety layer software, includes: The test information and the first information value are obtained through the connection function layer software interface of the functional safety test layer software, and the test information and the first information value are sent to the test script submodule. The test script submodule determines the target test script based on the test information, and uses the target test script to inject faults into the temporary information value determined from the first information value based on the test information, thereby obtaining a fault injection value that does not meet the functional safety requirements of the device under test. The fault injection value is sent to the functional safety layer software through the connection functional safety layer software interface of the functional safety test layer software.

2. The functional safety design verification method according to claim 1, characterized in that, The first information value is the information value calculated by the functional layer software for the latest vehicle function information; the second information value is the information value calculated by the functional safety layer software for the latest vehicle function information and the functional safety requirements; the latest vehicle function information is the information sent by the input controller associated with the device under test to the functional layer software and the functional safety layer software based on a preset period.

3. The functional safety design verification method according to claim 1 or 2, characterized in that, The latest vehicle function information includes numerical information and status information.

4. The functional safety design verification method according to claim 3, characterized in that, The step of injecting fault values ​​that do not meet the functional safety requirements of the device under test by using the functional safety testing layer software to inject faults into temporary information values ​​determined from the first information values ​​based on the test information, including: The functional safety test layer software modifies the first state value of the target state information determined from the first information value based on the test information to obtain a second state value that does not meet the functional safety requirements of the device under test. Accordingly, the step of obtaining the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements, determined from the second information value calculated based on the test information from the latest vehicle functional information, are inconsistent, outputting corresponding target information to the target vehicle through the output controller includes: The test information is obtained through the functional safety layer software, and a third state value of the target state information that meets the functional safety requirements is determined from the second information value calculated for the latest vehicle function information based on the test information. The comparison result is obtained by comparing the third state value and the second state value. If the comparison result is inconsistent, the error message corresponding to the target state information is output to the target vehicle through the output controller.

5. The functional safety design verification method according to claim 3, characterized in that, The step of injecting fault values ​​that do not meet the functional safety requirements of the device under test by using the functional safety testing layer software to inject faults into temporary information values ​​determined from the first information values ​​based on the test information, including: The functional safety testing layer software modifies the first value of the target value information determined from the first information value based on the test information to obtain a second value that does not meet the functional safety requirements of the device under test. Accordingly, the step of obtaining the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements, determined from the second information value calculated based on the test information from the latest vehicle functional information, are inconsistent, outputting corresponding target information to the target vehicle through the output controller includes: The test information is obtained through the functional safety layer software, and the numerical range of the target numerical information that meets the functional safety requirements is determined from the second information value calculated for the latest vehicle functional information based on the test information. The comparison result is obtained by comparing the numerical range value and the second value. If the comparison result is that the second value exceeds the numerical range value, the output value is determined according to the preset rule and based on the second value and the numerical range value. The output controller outputs the error message corresponding to the output value and the target value information to the target vehicle.

6. A functional safety design verification device, characterized in that, Applied to the device under test, the device under test includes functional layer software, functional safety test layer software, functional safety layer software, and an output controller. The device includes: The information transmission module is used to acquire test information through the functional layer software and output the test information and a first information value calculated for the latest vehicle functional information to the functional safety test layer software. The fault injection module is used to inject a fault into a temporary information value determined from the first information value based on the test information through the functional safety test layer software to obtain a fault injection value that does not meet the functional safety requirements of the device under test, and to send the fault injection value to the functional safety layer software. The verification module is used to acquire the test information through the functional safety layer software, and when the fault injection value and the reference information value that meets the functional safety requirements determined from the second information value calculated based on the test information from the latest vehicle functional information are inconsistent, the module outputs corresponding target information to the target vehicle through the output controller, so as to determine that the functional safety layer software plays a functional safety role when the target information and the actual performance of the target vehicle based on the target information are consistent with the expected results. The functional safety test layer software includes a connection interface to the functional layer software, a test script submodule, and a connection interface to the functional safety layer software; the test script submodule includes several test scripts; the several test scripts are different test scripts generated using different test cases set for the device under test that do not meet the functional safety requirements; Specifically, the fault injection module is used to: obtain the test information and the first information value through the connection function layer software interface of the functional safety test layer software, and send the test information and the first information value to the test script submodule; determine a target test script based on the test information through the test script submodule, and use the target test script to inject faults into a temporary information value determined from the first information value based on the test information, thereby obtaining a fault injection value that does not meet the functional safety requirements of the device under test; and send the fault injection value to the functional safety layer software through the connection function safety layer software interface of the functional safety test layer software.

7. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the functional safety design verification method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, Used to store a computer program; wherein, when the computer program is executed by a processor, it implements the functional safety design verification method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Software fault injection method and system

    CN103559112A

  • Fault injection method and device, equipment and storage medium

    CN114510381A