A function safety test method for a brake-by-wire system
By using HAZOP analysis to set up test scenarios and combining fault injection and multi-dimensional evaluation, the shortcomings of functional safety testing for brake-by-wire systems are addressed, achieving efficient and reliable functional safety verification and meeting the testing requirements of complex systems.
Patent Information
- Application Number
- CN202311346077.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-17
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2043-10-17
AI Technical Summary
Existing technologies lack comprehensive testing methods for more complex and functionally safe brake-by-wire systems (such as eBooster+ESC), especially in advanced driver assistance systems and automatic parking systems, where functional safety testing needs and requirements are not effectively met.
The HAZOP analysis method was used to set up test scenarios. By combining fault injection and driver subjective evaluation with objective data, a multi-dimensional evaluation was conducted to ensure that the test vehicle met the conditions before functional safety testing was carried out. This included fault mode verification and hazard analysis. Typical test scenarios and test conditions were used, and a comprehensive judgment was made by combining objective evaluation indicators and subjective evaluation records.
It enables efficient functional safety verification and validation of brake-by-wire systems, with reliable test results that comprehensively cover different scenarios and failure modes, providing clear test evaluation indicators to ensure system functional safety.
Smart Images

Figure CN117389245B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicle testing, in particular to a function safety test method for a brake-by-wire system. BACKGROUND
[0002] With the development of intelligent and electric vehicles, the status of functional safety is increasingly prominent. A series of important documents such as "Automobile Industry Medium and Long-term Development Plan" have established the importance of functional safety in the standard system construction of intelligent and connected vehicles. The Ministry of Industry and Information Technology has clearly included functional safety and expected functional safety protection, network security protection into the product access management method. At the same time, with the development of the new energy intelligent vehicle market, the penetration rate of brake-by-wire is getting higher and higher, and the "eBooster+ESC" Two-box scheme has become the most mainstream brake-by-wire system in the market. In addition, with the popularization of high-order auxiliary driving systems and automatic parking systems, "eBooster+ESC" also plays an important role in them. This system is a key system involving functional safety, and it is necessary to test and verify its functional safety.
[0003] However, the current brake functional safety related standards are still in the pre-research stage, and there is no relatively perfect test method. Especially for "eBooster+ESC" and other more functional and more complex brake-by-wire systems, the test requirements for functional safety are higher, and there is an urgent need for a functional safety test scheme that can meet the test requirements of such systems. SUMMARY
[0004] The present application aims to provide a brake-by-wire system functional safety test method, which can efficiently complete the functional safety confirmation and verification of the brake-by-wire system, and the test evaluation index is clear.
[0005] The basic scheme provided by the present application is: a brake-by-wire system functional safety test method, comprising the following steps:
[0006] S1, install the test equipment and detect whether the test vehicle state meets the test conditions, if not, check and debug the test vehicle and test equipment and then detect the test vehicle state again, if still not meet, stop the test and fully investigate the problem; when the vehicle state meets the test conditions, execute the next step;
[0007] S2, the driver drives the test vehicle to normally drive according to the preset test scene; the test scene is set according to the HAZOP analysis method;
[0008] S3, fault injection is performed to the test vehicle without prompting the driver, while detecting the state information of the test vehicle, and recording the subjective evaluation content of the driver, and after the test vehicle is completely controllable, the recording is stopped and the fault is cleared, and the next step is executed;
[0009] S4, the test vehicle state is detected again whether it meets the test conditions, if not, the vehicle and equipment are checked and debugged, and the vehicle state is detected again, if still not met, the test is stopped and the problem is fully investigated, and when the test vehicle state meets the test conditions, the next step is executed;
[0010] S5, whether the fault mode leading to the hazard in the test scene has been tested and verified is checked, if not, the fault mode is changed and step S3 is executed, and the test in the test scene is continued, if yes, the next step is executed;
[0011] S6, whether all typical test scenes have been tested is checked, if not, the test scene is changed, and step S2 is executed, if yes, the test is ended, and the next step is executed;
[0012] S7, after the test is ended, the state information of the test vehicle is analyzed, objective evaluation data is obtained, and whether the functional safety test is passed is determined combined with the acceptable standard of objective evaluation and the subjective evaluation record.
[0013] The working principle and advantages of the present application are that:
[0014] The present application is based on the structure and function of the EHB Two-box brake system for safety analysis, deriving functional safety requirements, confirming fault modes and vehicle hazards, and formulating verification and confirmation plans on the vehicle level according to the fault modes and vehicle hazards. According to the verification and confirmation plans, functional safety tests are carried out, and the vehicle state needs to be detected whether it meets the test requirements at the beginning of each test to avoid test failure. After the test is ended, the test results need to be analyzed to determine whether the brake-by-wire system meets the functional safety requirements. The present application can efficiently complete the functional safety confirmation and verification of the brake-by-wire system. Among them, the test method adopts typical test scenes and different test steps under different test scenes, which can conveniently test the test vehicle and its brake system. And in the evaluation stage, the test evaluation index is extracted, and the evaluation is carried out combined with the objective evaluation data and the subjective evaluation record, which can comprehensively evaluate the test results from multiple angles, and the evaluation reliability is high. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 It is a method flowchart of an embodiment of the functional safety test method of the brake-by-wire system. DETAILED DESCRIPTION
[0016] The following detailed explanation illustrates the specific implementation methods:
[0017] The basic implementation examples are as follows: Figure 1 As shown: A functional safety testing method for a brake-by-wire system includes the following steps:
[0018] Preparatory steps: S01, check whether the input file of the test vehicle contains detailed information on the architecture and corresponding functions of the brake-by-wire system; if so, proceed to step S03; if not, proceed to the next step.
[0019] S02, based on existing technical manuals and specifications, analyze and derive the architecture and corresponding functions of the brake-by-wire system, and confirm with the supplier. After confirmation, proceed to the next step. Specifically, in this embodiment, taking the Two-box solution as an example, based on the technical manual and related technical specifications, the specific architecture of eBooster and ESC can be drawn, and their internal and external interfaces can be clarified to facilitate the execution of S03.
[0020] S03: Based on the existing brake-by-wire system architecture and corresponding functions, analyze the failure modes of the brake-by-wire system, identify the hazards to the entire vehicle caused by the failure, select typical test scenarios for the hazards to the entire vehicle, formulate a functional safety test plan and a fault injection implementation plan, and execute S1 after preparation is completed.
[0021] Specifically, based on the existing brake-by-wire system architecture, the fault modes can be analyzed to include controller faults, network faults, power supply faults, ESC faults, and eBooster faults. Combining the specific functions of eBooster and ESC, such as service brake, parking brake, anti-lock braking system (ABS), and regenerative braking, the overall vehicle hazards resulting from different functional failures are derived and categorized, including insufficient braking force, excessive braking force, unexpected braking, unexpected non-braking, and braking delay. The hazards at the vehicle level can be summarized as unexpected longitudinal movement and unexpected lateral movement. That is, the overall vehicle hazards here include unexpected longitudinal movement and unexpected lateral movement.
[0022] The vehicle hazard events obtained from the HAZOP analysis method are then used to generate typical test scenarios. As shown in Appendix Table 1, the typical test scenarios include: Scenario 1: Driving straight on a highway at 100 km / h, with the vehicle in front at 60 km / h and a distance of 100m between them; the vehicle requests braking but has no braking force or insufficient braking force; Scenario 2: Parking on an 8% gradient road section with no braking force or insufficient braking force; Scenario 3: Normal cruising on urban roads in Drive mode; the vehicle requests braking but has excessive braking force; Scenario 4: Driving straight on a highway at 100 km / h, with low-friction road surface, in Drive mode, and unexpected braking. This process is repeated until all typical test scenarios are identified.
[0023] Table 1. Examples of Typical Scenarios
[0024]
[0025]
[0026] S1. Install the test equipment and check whether the test vehicle status meets the test conditions. If not, check and debug the test vehicle and test equipment, and then check the test vehicle status again. If it still does not meet the conditions, stop the test and thoroughly investigate the problem. When the vehicle status meets the test conditions, proceed to the next step.
[0027] S2, the driver drives the test vehicle normally according to the preset test scenario. The test scenario is set according to the HAZOP analysis method, and the specific analysis steps are as described in S03.
[0028] In this embodiment, the driver drives the test vehicle at a speed of 100 km / h along the center line of the test track on a horizontal road surface, with no other vehicles within 200m in front of or behind the vehicle.
[0029] S3 injects a fault into the test vehicle without alerting the driver, while simultaneously detecting the test vehicle's status information and recording the driver's subjective evaluation. Once the test vehicle is fully under control, recording stops and the fault is cleared before proceeding to the next step.
[0030] The fault injection methods include injecting faults through communication faults, hard wiring faults, software faults, sensor faults, and power supply faults; and the next test condition can only be tested after all fault injection tests under the current test condition have been completed. Specifically, in this embodiment, the fault injection method used here includes short-circuiting the brake pedal displacement sensor.
[0031] S4. Check again whether the test vehicle status meets the test conditions. If not, check and debug the vehicle and equipment, and then check the vehicle status again. If it still does not meet the conditions, stop the test and thoroughly investigate the problem. When the test vehicle status meets the test conditions, proceed to the next step.
[0032] S5, check whether all fault modes that cause harm in this test scenario have been tested and verified; if not, change the fault mode and execute step S3 to continue testing in this test scenario; if yes, execute the next step.
[0033] Specifically, in this embodiment, the fault modes are selected to be changed sequentially as follows: communication interface failure causing unexpected activation of the service brake, parking control device short circuit, and communication interface failure causing excessive braking force of electric components. Step S3 is executed again to continue testing under this test scenario. After all fault modes have been tested and verified, the next step is executed.
[0034] S6, check if all typical test scenarios have been tested successfully; if not, change the test scenario and execute step S2; if yes, end the test and execute the next step.
[0035] Specifically, in this embodiment, the test scenario is changed to the driver driving the test vehicle to stop on a slope with a gradient of 8% or greater, and then step S2 is executed. The fault modes in this test scenario include short circuit or open circuit of the parking control device and open circuit of the four-wheel caliper motor. After all test scenarios are completed, the test ends and the next step is executed.
[0036] S7. After the test is completed, the test vehicle status information is analyzed to obtain objective evaluation data. Combined with the acceptable standards of the objective evaluation and the subjective evaluation records, the functional safety test is determined to have passed. Specifically, if both the objective evaluation test and the subjective evaluation test are passed, the functional safety test is considered to have passed.
[0037] Specifically, the objective evaluation data includes the maximum yaw rate, lane departure distance, fault indication time, and driver operation time.
[0038] The objective evaluation data is calculated according to the following formula:
[0039] s1 = max Y(t), t∈[t1 t2]; where s1 is the maximum yaw rate; Y(t) is the magnitude of the yaw rate of the test vehicle at a certain moment; t1 and t2 are the start and end times of the test, respectively;
[0040]
[0041] Where s2 is the lane departure distance; These represent the average lane departure distances before and after the fault injection; t i The time of fault injection; n1 and n2 represent the time from t1 to t2 respectively. i The number of sampling points at time t i The number of sampling points up to time t2; l(t) is the distance the test vehicle deviates from the lane centerline at a certain time;
[0042] t3=t p -t i Where t3 is the fault indication time; t p The time when the fault message is recorded.
[0043] t4=t s +t b +t z Where t4 is the driver's operation time; t s The driver's reaction time is the sum of the driver's neural delay and muscle delay. Research indicates that the driver's neural delay during braking is 0.2-0.4 seconds, and the driver's muscle delay is 0.1-1.12 seconds. For optimal braking safety, the delay times are taken as the upper limit. Therefore, t... s It is 1.52s; t b For braking system response time, although brake-by-wire systems respond faster, for safety reasons, based on relevant standards and testing experience, t b Take the upper limit, which is 0.6s; t z For braking time, t z =|(V t -V0)| / a, where V t V0 represents the speed of the vehicle itself, V0 represents the speed of the vehicle in front or behind, or the speed of an obstacle or pedestrian. When there is only one vehicle in the test scenario, V0 = 0; a represents the braking deceleration. Based on testing experience and referring to emergency braking conditions, a is taken as 8 m / s². 2 .
[0044] When the objective evaluation data shows that the maximum yaw rate is ≤3° / s, the lane departure distance is ≤0.4m, the fault indication time is ≤1s, and the driver operation time is ≥1.52+0.6+|(V t When -V0)| / a, the objective evaluation test is considered to have passed, as shown in Table 2.
[0045] Table 2 Acceptable Criteria for Objective Evaluation
[0046] Objective evaluation index Acceptable standard Yaw angle ≤15° Lane offset distance ≤0.75m Fault prompt time ≤1s Driver operation time ≥ 1.52 + 0.6 + |V t - V0) / a
[0047] The driver's subjective evaluation uses a 7-point scoring system. The evaluation scale is divided into 7 consecutive scales: 1 to 3 points represent the unsatisfactory range, 5 to 7 points represent the satisfactory range, and 4 is the dividing line. As shown in Table 3; when the subjective evaluation score is ≥5 points, the subjective evaluation test is considered passed.
[0048] Table 3 Subjective Evaluation Table
[0049]
[0050] In this embodiment, the vehicle yaw angle, lane departure distance, and driver operation time information are extracted sequentially based on the vehicle status information, and the changes or maximum values of each indicator are calculated. For example, in a straight-line driving scenario test at a vehicle speed of 100 km / h, the injected fault is a short circuit in the brake pedal displacement sensor. The driver's subjective evaluation of controllability during the test (refer to Table 3) is recorded as 6 points. Then, the corresponding indicators are extracted and the maximum yaw rate is calculated to be 0.78° / s, the lane departure distance is 0.18m, the fault indication time is 0.25s, and the driver operation time is >10s. Combined with the objective test acceptable standards (refer to Table 2), both the objective evaluation test and the subjective evaluation test are passed. Therefore, the functional safety test of the brake-by-wire system is deemed to have passed.
[0051] Furthermore, it should be noted that this embodiment only illustrates some scenario types and failure modes. In actual testing, it is necessary to combine vehicle configuration and safety analysis to specifically analyze and derive the test scenarios and failure modes for specific functions, and ensure the coverage of the test. In addition, objective indicators can be specifically analyzed and extracted according to test conditions, functional requirements and relevant standards. Typical extractable indicators include, but are not limited to, lateral acceleration, lane departure distance, braking deceleration, braking distance, response time, execution time, overshoot, steady-state error and parking release time, etc.
[0052] This embodiment provides a functional safety testing method for brake-by-wire systems, which can efficiently complete the functional safety verification and validation of brake-by-wire systems. Furthermore, the test evaluation indicators are clear and the reliability is high.
[0053] Specifically, this solution first conducts a safety analysis based on the structure and function of the braking system, deriving functional safety requirements, identifying failure modes and vehicle-wide hazards, and then developing a vehicle-level verification and validation plan based on these criteria. Functional safety testing is conducted according to the verification and validation plan. At the start of each test, the vehicle's condition is checked to ensure it meets the test requirements, preventing test failure. After the tests, the results are analyzed to determine whether the brake-by-wire system meets the functional safety requirements. The overall testing process is highly compatible with the structure and function of the braking system, enabling targeted and effective determination of the brake-by-wire system's functional safety status. Furthermore, the testing process can encompass different test scenarios, failure modes, and vehicle-wide hazard conditions, providing comprehensive testing.
[0054] Secondly, this solution combines the analytical methods of the functional safety concept phase to formulate a relatively detailed vehicle-level verification and validation plan, clarifies typical failure modes and scenario types, and proposes key evaluation indicators. It provides a feasible method for the functional safety validation and verification of the brake-by-wire system, and can evaluate the functional safety level of the brake-by-wire system from both subjective and objective perspectives. It can also serve as a reference and improve the testing and verification of brake-by-wire.
[0055] The above descriptions are merely embodiments of the present invention. Commonly known structures and characteristics of the solutions are not described in detail here. Those skilled in the art are aware of all common technical knowledge in the field prior to the application date or priority date, are aware of all existing technologies in that field, and have the ability to apply conventional experimental methods prior to that date. Those skilled in the art can, under the guidance of this application, improve and implement this solution in combination with their own capabilities. Some typical known structures or methods should not be obstacles for those skilled in the art to implement this application. It should be noted that those skilled in the art can make several modifications and improvements without departing from the structure of the present invention. These should also be considered within the scope of protection of the present invention, and will not affect the effectiveness of the implementation of the present invention or the practicality of the patent.
Claims
1. A method for functional safety testing of a brake-by-wire system, characterized in that, Includes the following steps: S1. Install the test equipment and check whether the test vehicle status meets the test conditions. If not, check and debug the test vehicle and test equipment, and then check the test vehicle status again. If it still does not meet the conditions, stop the test and thoroughly investigate the problem. When the vehicle status meets the test conditions, proceed to the next step. S2, the driver drives the test vehicle normally according to the preset test scenario; The test scenario was set according to the HAZOP analysis method; S3: Inject a fault into the test vehicle without alerting the driver, while simultaneously detecting the test vehicle's status information and recording the driver's subjective evaluation. Once the test vehicle is fully under control, stop recording, clear the fault, and proceed to the next step. S4. Check again whether the test vehicle status meets the test conditions. If not, check and debug the vehicle and equipment, and then check the vehicle status again. If it still does not meet the conditions, stop the test and thoroughly investigate the problem. When the test vehicle status meets the test conditions, proceed to the next step. S5, check whether all fault modes that cause harm in this test scenario have been tested and verified; if not, change the fault mode and execute step S3 to continue testing in this test scenario; if yes, execute the next step. S6, check if all typical test scenarios have been tested successfully; if not, change the test scenario and execute step S2; if yes, end the test and execute the next step. S7. After the test is completed, the test vehicle status information is analyzed to obtain objective evaluation data; and combined with the acceptable standards of the objective evaluation and the subjective evaluation records, it is determined whether the functional safety test has passed.
2. The method for functional safety testing of a brake-by-wire system according to claim 1, characterized in that, Before S1, there is a preparatory step; the preparatory step includes: S01, checking whether the input file of the test vehicle contains detailed information on the brake-by-wire system architecture and corresponding functions; if so, proceed to step S03; if not, proceed to the next step; S02. Based on existing technical manuals and specifications, analyze and derive the architecture and corresponding functions of the brake-by-wire system, and confirm with the supplier. Once confirmed, proceed to the next step. S03: Based on the existing brake-by-wire system architecture and corresponding functions, analyze the failure modes of the brake-by-wire system, identify the hazards to the entire vehicle caused by the failure, select typical test scenarios for the hazards to the entire vehicle, formulate a functional safety test plan and a fault injection implementation plan, and execute S1 after preparation is completed.
3. The method for functional safety testing of a brake-by-wire system according to claim 2, characterized in that, In S03, the fault modes include controller fault, network fault, power supply fault, ESC fault, and eBooster fault; the vehicle hazards include unintended longitudinal movement and unintended lateral movement.
4. The method for functional safety testing of a brake-by-wire system according to claim 2, characterized in that, The typical test scenarios include: Scenario 1: Driving straight on a highway at 100 km / h, with the vehicle in front at 60 km / h and a distance of 100m between them; the vehicle requests braking but there is no braking force or the braking force is too weak; Scenario 2: Parking on an 8% gradient road with no braking force or insufficient braking force; Scenario 3: Normal cruising on urban roads in Drive mode; the vehicle requests braking but the braking force is too strong; Scenario 4: Driving straight on a highway at 100 km / h with low-friction surface; the vehicle is in Drive mode and performs unexpected braking.
5. The method for functional safety testing of a brake-by-wire system according to claim 1, characterized in that, The fault injection methods include injecting faults through communication faults, hard wiring faults, software faults, sensor faults, and power supply faults; and the next test condition can only be tested after all fault injection tests under the current test condition have been completed.
6. The method for functional safety testing of a brake-by-wire system according to claim 1, characterized in that, The objective evaluation data includes the maximum yaw rate, lane departure distance, fault indication time, and driver operation time.
7. The functional safety testing method for a brake-by-wire system according to claim 6, characterized in that, The objective evaluation data is calculated according to the following formula: s1 = max Y(t), t∈[t1 t2]; where s1 is the maximum yaw rate; Y(t) is the magnitude of the yaw rate of the test vehicle at a certain moment; t1 and t2 are the start and end times of the test, respectively; Where s2 is the lane departure distance; These represent the average lane departure distances before and after the fault injection; t i The time of fault injection; n1 and n2 represent the time from t1 to t2 respectively. i The number of sampling points at time t i The number of sampling points up to time t2; l(t) is the distance the test vehicle deviates from the lane centerline at a certain time; t3=t p -t i Where t3 is the fault indication time; t p The recording time of the fault message; t4=t s +t b +t z Where t4 is the driver's operation time; t s t represents the driver's reaction time. b t is the braking system response time. z For braking time, t z =|(V t -V0)| / a, where V t V0 represents the speed of the vehicle itself, V0 represents the speed of the vehicle in front or behind, or the speed of an obstacle or pedestrian. When there is only one vehicle in the test scenario, V0 = 0; a represents the braking deceleration, and a is taken as 8 m / s². 2 .
8. The method for functional safety testing of a brake-by-wire system according to claim 7, characterized in that, When the objective evaluation data shows that the maximum yaw rate is ≤3° / s, the lane departure distance is ≤0.4m, the fault indication time is ≤1s, and the driver operation time is ≥1.52+0.6+|(V t When -V0)| / a, the objective evaluation test is considered passed.
9. The functional safety testing method for a brake-by-wire system according to claim 1, characterized in that, The driver's subjective evaluation is scored on a 7-point scale; when the subjective evaluation score is ≥5 points, the subjective evaluation test is considered passed.
10. The functional safety testing method for a brake-by-wire system according to claim 1, characterized in that, When both the objective evaluation test and the subjective evaluation test are passed, the functional safety test is deemed to have passed.
Citation Information
Patent Citations
Performance evaluation method for vehicle-road cooperative automatic emergency braking system
CN111649955A
Intelligent vehicle braking and parking capacity testing method considering passenger comfort
CN112362356A