Safety detection method for vehicle, safety detection device for vehicle, and vehicle system
By assessing the severity, controllability, and frequency of initial hazard events affecting vehicles, and taking corresponding measures to improve and update them, the problem of insufficient objectivity in the effectiveness assessment of expected functional safety measures was resolved, thereby improving vehicle safety.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SUZHOU ZHITU TECH CO LTD
- Filing Date
- 2023-12-19
- Publication Date
- 2026-05-29
AI Technical Summary
The effectiveness assessment of anticipated functional safety measures in existing technologies is not objective enough, and objective and impartial analysis cannot be conducted.
By acquiring initial hazard events involving vehicles, assessing their severity, controllability, and frequency, determining their acceptability, and taking appropriate measures to improve them if they are unacceptable, until the measures are effective, and updating ineffective measures, thus achieving an objective assessment of safety measures.
It enables an objective assessment of the intended functional safety measures, ensures vehicle safety, reduces the severity, controllability, and frequency of hazardous events, and improves the effectiveness of safety measures.
Smart Images

Figure CN117719450B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of intelligent driving, and more specifically, to a vehicle safety detection method, a vehicle safety detection device, a computer-readable storage medium, and a vehicle system. Background Technology
[0002] Currently, the three standards in the automotive field are ISO 21448 for anticipated functional safety, ISO 26262 for functional safety, and ISO 21434 for cybersecurity. Functional safety addresses the hazards caused by random and systematic failures within a system, resulting in safety incidents, including hardware and software malfunctions. Hazards occurring when the system is functioning normally are not considered within the scope of functional safety. Due to performance limitations of sensors or algorithms, and driver misoperation of the system, the anticipated functional safety specifications aim to address these issues. However, in the anticipated functional safety analysis process, the evaluation of the effectiveness of anticipated functional safety measures heavily relies on expert review, making objective and impartial analysis difficult.
[0003] Therefore, there is an urgent need for a method to address the problem of insufficient objectivity in the assessment of the effectiveness of expected functional safety measures. Summary of the Invention
[0004] The main objective of this application is to provide a vehicle safety testing method, a vehicle safety testing device, a computer-readable storage medium, and a vehicle system, so as to at least solve the problem that the effectiveness assessment of expected functional safety measures in the prior art is not objective enough.
[0005] According to one aspect of this application, a vehicle safety detection method is provided, comprising: an acquisition step, acquiring an initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability; a first determination step, acquiring a first severity, a first controllability, and a first frequency of the initial hazard event, and determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency, wherein the first severity is used to characterize whether the initial hazard event will cause harm to a person, the first controllability is used to characterize whether the initial hazard event is controllable, the first frequency is used to characterize the frequency of occurrence of the initial hazard event during the life cycle of the vehicle, and whether the initial hazard event is acceptable is used to characterize whether potential functional deficiencies and The process includes: identifying and evaluating triggering conditions; a processing step where, if the initial hazard event is unacceptable, initial measures corresponding to the initial hazard event are obtained, and the initial measures are used to improve system performance limitations to obtain a processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency; a second determination step where the second severity, the second controllability, and the second frequency of the processed hazard event are obtained, and the effectiveness of the initial measures is determined based on the second severity, the second controllability, and the second frequency of the processed hazard event; and an update step where, if the initial measures are ineffective, the initial measures are updated to make the updated initial measures effective to obtain updated measures.
[0006] Optionally, the acquisition step includes: simulating the functions of the vehicle using a hazard and operability analysis method to obtain the initial hazard event.
[0007] Optionally, obtaining the first severity, the first controllability, and the first frequency of the initial hazard event includes one of the following: processing the initial hazard event using a system theory process analysis method to obtain the first severity, the first controllability, and the first frequency; or processing the initial hazard event using a cause-effect tree analysis method to obtain the first severity, the first controllability, and the first frequency.
[0008] Optionally, determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency includes: determining that the initial hazard event is acceptable if the first severity indicates that the initial hazard event will not cause harm to a person; determining that the initial hazard event is acceptable if the first controllability indicates that the initial hazard event is controllable; and determining a first value based on the relative speed at which the initial hazard event will cause harm to a person, a second value based on the vehicle's ability to avoid the initial hazard event, and a third value based on the frequency of the initial hazard event occurring in the vehicle's life cycle, wherein the first value and the frequency of the initial hazard event are related to the relative speed at which the initial hazard event will cause harm to a person. The relative speed at which a person causes harm is positively correlated with the vehicle's ability to avoid the initial hazard event. The vehicle's ability to avoid the initial hazard event is the time required for the driver to take over the vehicle when the vehicle's performance is limited and it cannot drive safely in a scenario including triggering conditions. The second value is positively correlated with the vehicle's ability to avoid the initial hazard event, and the third value is positively correlated with the frequency of the initial hazard event occurring in the vehicle's life cycle. It is determined whether the sum of the first value, the second value, and the third value is greater than or equal to a first threshold, wherein the first threshold is greater than 0. If the sum of the first value, the second value, and the third value is less than the first threshold, the initial hazard event is determined to be acceptable. If the sum of the first value, the second value, and the third value is greater than or equal to the first threshold, the initial hazard event is determined to be unacceptable.
[0009] Optionally, obtaining the initial measures corresponding to the initial hazard event includes: obtaining a mapping relationship between the hazard event and the response measures, wherein the response measures are used to reduce the hazard of the hazard event; and determining the response measures corresponding to the hazard event that is the same as the initial hazard event as the initial measures.
[0010] Optionally, the second determining step includes: The second determining step includes: determining that the post-treatment hazard event is acceptable if the second severity indicates that the post-treatment hazard event will not cause harm to a person; determining that the post-treatment hazard event is acceptable if the second controllability indicates that the post-treatment hazard event is controllable; and determining a fourth value based on the relative speed at which the post-treatment hazard event will cause harm to a person, a fifth value based on the vehicle's ability to avoid the post-treatment hazard event, and a sixth value based on the frequency of the post-treatment hazard event occurring during the vehicle's lifespan, wherein the fourth value is relative to the relative speed at which the post-treatment hazard event will cause harm to a person. The speed is positively correlated with the vehicle's ability to avoid the initial hazard event, which is the time required for the driver to take over the vehicle when the vehicle's performance is limited and the vehicle cannot drive safely in a scenario including the triggering conditions. The fifth value is positively correlated with the vehicle's ability to avoid the post-treatment hazard event, and the sixth value is positively correlated with the frequency of the post-treatment hazard event occurring in the vehicle's life cycle. It is determined whether the sum of the fourth, fifth, and sixth values is greater than or equal to a second threshold, where the second threshold is greater than 0. If the sum of the fourth, fifth, and sixth values is less than the second threshold, the post-treatment hazard event is determined to be acceptable. If the sum of the fourth, fifth, and sixth values is greater than or equal to the second threshold, the post-treatment hazard event is determined to be unacceptable.
[0011] Optionally, the updating step includes: repeating the processing step and the second determining step at least once, and updating the initial measure in the processing step to a predetermined measure during the repetition until the predetermined measure is determined to be effective; determining the predetermined measure in the processing step during the last repetition as the updated measure.
[0012] According to another aspect of this application, a vehicle safety detection device is provided, comprising: an acquisition unit, configured to acquire an initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability; and a first determination unit, configured to acquire, in a first determination step, a first severity, a first controllability, and a first frequency of the initial hazard event, and determine whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency, wherein the first severity characterizes whether the initial hazard event will cause harm to a person, the first controllability characterizes whether the initial hazard event is controllable, the first frequency characterizes the frequency of occurrence of the initial hazard event during the vehicle's life cycle, and whether the initial hazard event is acceptable characterizes whether potential functional deficiencies and trigger conditions are considered. The system comprises: an identification and assessment unit; a processing unit, configured to, in the case that the initial hazard event is unacceptable, obtain an initial measure corresponding to the initial hazard event and use the initial measure to improve the system performance limitations, thereby obtaining a processed hazard event, wherein the initial measure is used to reduce at least one of the first severity, the first controllability, and the first frequency; a second determination unit, configured to, in the second determination step, obtain a second severity, a second controllability, and a second frequency of the processed hazard event, and determine whether the initial measure is effective based on the second severity, the second controllability, and the second frequency of the processed hazard event; and an update unit, configured to, in the case that the initial measure is ineffective, update the initial measure to make the updated initial measure effective, thereby obtaining an updated measure.
[0013] According to another aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform any of the methods described above.
[0014] According to another aspect of this application, a vehicle system is provided, comprising: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs including methods for performing any one of the methods described.
[0015] Applying the technical solution of this application, firstly, an initial hazard event with a probability greater than a preset probability that affects the safety of the vehicle is obtained; based on a first severity, a first controllability, and a first frequency, it is determined whether the initial hazard event is acceptable; if the initial hazard event is unacceptable, initial measures corresponding to the initial hazard event are obtained, and the initial measures are used to handle the initial hazard event, resulting in a handled hazard event; based on a second severity, a second controllability, and a second frequency of the handled hazard event, it is determined whether the initial measures are effective; if the initial measures are ineffective, the initial measures are updated to make the updated initial measures effective, resulting in updated measures. The above method determines whether the severity of the initial hazard event is acceptable based on its severity, controllability, and frequency. If the severity is too high, corresponding measures are taken to resolve the issue, resulting in a handled hazard event. Based on changes in the severity, controllability, and frequency of the handled hazard event, the effectiveness of the measures is determined again. This method achieves an objective assessment of the effectiveness of safety measures, solving the problem of insufficient objectivity in the effectiveness assessment of expected functional safety measures in the prior art. Attached Figure Description
[0016] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:
[0017] Figure 1 A hardware structure block diagram of a mobile terminal for performing a vehicle safety detection method according to an embodiment of this application is shown;
[0018] Figure 2 A schematic flowchart of a vehicle safety detection method according to an embodiment of this application is shown;
[0019] Figure 3 A detailed flowchart of a vehicle safety detection method according to an embodiment of this application is shown.
[0020] Figure 4 A detailed flowchart of another vehicle safety detection method provided according to an embodiment of this application is shown;
[0021] Figure 5 A structural block diagram of a vehicle safety detection device provided according to an embodiment of this application is shown.
[0022] The above figures include the following reference numerals:
[0023] 102. Processor; 104. Memory; 106. Transmission device; 108. Input / output device. Detailed Implementation
[0024] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.
[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0027] As described in the background section, the effectiveness assessment of expected functional safety measures in the prior art is not objective enough. To solve the above problems, embodiments of this application provide a vehicle safety detection method, a vehicle safety detection device, a computer-readable storage medium, and a vehicle system.
[0028] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0029] The methods and embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure block diagram of a mobile terminal for a vehicle safety detection method according to an embodiment of the present invention. Figure 1 As shown, a mobile terminal may include one or more ( Figure 1Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the mobile terminal described above. For example, the mobile terminal may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0030] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the vehicle safety detection method in this embodiment of the invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of the aforementioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the aforementioned networks may include wireless networks provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0031] This embodiment provides a vehicle safety detection method that runs on a mobile terminal, computer terminal or similar computing device. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Also, although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0032] Figure 2 This is a flowchart of a vehicle safety detection method according to an embodiment of this application. Figure 2 As shown, the method includes the following steps:
[0033] Step S201, acquisition step, acquire the initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability;
[0034] Specifically, potential hazardous events during vehicle operation can be obtained through various methods, such as hazard analysis, risk assessment, and hazard feasibility analysis.
[0035] Step S202, the first determining step, involves obtaining the first severity of the initial hazard event, the first controllability of the initial hazard event, and the first frequency of the initial hazard event, and determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity is used to characterize whether the initial hazard event will cause harm to a person, the first controllability is used to characterize whether the initial hazard event is controllable, the first frequency is used to characterize the frequency of the initial hazard event occurring in the life cycle of the vehicle, and whether the initial hazard event is acceptable is used to characterize whether to conduct an identification and assessment of potential functional deficiencies and triggering conditions.
[0036] Specifically, whether the initial hazard event is acceptable is used to characterize the severity of the initial hazard event. If the severity of the initial hazard event is too high, then the initial hazard event is unacceptable; if the severity of the initial hazard event is low, then the initial hazard event is acceptable.
[0037] Step S203, processing step: if the initial hazard event is unacceptable, obtain the initial measures corresponding to the initial hazard event, and use the initial measures to improve the system performance limitations to obtain the processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency.
[0038] Specifically, anticipated functional safety measures may reduce the severity of the hazard or improve the controllability of the system or the driver, such as limiting the operating speed range of platooning functions or limiting the acceleration and deceleration threshold range at different operating speeds; anticipated functional safety measures may also reduce the frequency of potential triggering conditions, such as limiting the operation of platooning functions in extreme weather or driver status monitoring.
[0039] Step S204, the second determination step, obtains the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard, and determines whether the above-mentioned initial measures are effective based on the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard.
[0040] Specifically, after adding the intended functional safety measures, the unreasonable risk of hazardous events is reduced, mitigated, or avoided. By reassessing the severity, controllability, and frequency of triggering events, the effectiveness of the measures can be further evaluated.
[0041] Step S205, update step: if the above initial measures are invalid, update the above initial measures to make the updated initial measures effective, and obtain the updated measures.
[0042] Specifically, if the initial measures mentioned above are effective, there is no need to update them. If the initial measures mentioned above are ineffective, anticipatory functional safety measures should be designed and the initial measures updated to reduce, mitigate, or avoid the anticipatory functional safety risks of the hazard event.
[0043] This embodiment first identifies an initial hazard event that has a probability greater than a preset probability of affecting the safety of the vehicle. Based on a first severity, a first controllability, and a first frequency, it is determined whether the initial hazard event is acceptable. If the initial hazard event is unacceptable, initial measures corresponding to the initial hazard event are obtained and applied to handle the initial hazard event, resulting in a handled hazard event. Based on a second severity, a second controllability, and a second frequency of the handled hazard event, it is determined whether the initial measures are effective. If the initial measures are ineffective, they are updated to make the updated initial measures effective, resulting in updated measures. This method determines whether the severity of the initial hazard event is acceptable based on its severity, controllability, and frequency. If the severity is too high, corresponding measures are taken to resolve the issue, resulting in a handled hazard event. The effectiveness of the measures is then determined again based on changes in the severity, controllability, and frequency of the handled hazard event. This method achieves an objective assessment of the effectiveness of safety measures, solving the problem of insufficient objectivity in the effectiveness assessment of expected functional safety measures in existing technologies.
[0044] In specific implementation, step S201 can be achieved through the following steps: Step S2011, using a hazard and operability analysis method to simulate the functions of the vehicle to obtain the initial hazard event. This method can further quickly obtain the initial hazard event.
[0045] Specifically, Hazard and Operability Analysis (HAZOP) employs a deviation-based two-way qualitative causal reasoning method, essentially a qualitative analysis. Through backward reasoning, it identifies the potential causes of the hazard; through forward reasoning, it identifies the possible adverse consequences of the hazard, analyzes the effectiveness of existing control measures, and proposes supplementary measures when necessary, ultimately reducing the risk to an acceptable level. Alternatively, the risk of a hazardous event can be preliminarily assessed based on the table below. Severity is categorized as S0, S1, S2, and S3, and controllability as C0, C1, C2, and C3, as shown in the table below.
[0046] Table 1. Preliminary assessment of the risk of hazardous events.
[0047]
[0048] To further and more quickly obtain the aforementioned first severity, first controllability, and first frequency, step S202 of this application can be implemented through one of the following steps: Step S2021, using a system theory process analysis method to process the aforementioned initial hazard event to obtain the aforementioned first severity, the aforementioned first controllability, and the aforementioned first frequency; Step S2022, using a cause-and-effect tree analysis method to process the aforementioned initial hazard event to obtain the aforementioned first severity, the aforementioned first controllability, and the aforementioned first frequency.
[0049] Specifically, System Theoretic Process Analysis (STPA) is a system safety analysis method that analyzes system events and failures based on the principles and methods of system theory. By analyzing the system's structure and function, it identifies system error and failure modes and proposes improvement measures to enhance system safety and reliability. A causal tree is a graphical tool used to display the causal relationships between a series of events. In a causal tree, one event can lead to another, and another event may lead to more events. These events are represented as nodes, and the causal relationships between them are represented as directed edges. Causal trees can help better understand why an event occurs and to take appropriate measures to reduce risks or prevent future events from occurring. The above methods identify functional deficiencies and triggering conditions that lead to potential hazardous events, including: potential functional deficiencies and triggering conditions related to planning algorithms, potential functional deficiencies and triggering conditions related to sensors and actuators, and reasonably foreseeable direct or indirect misuse. Hazardous events may be caused by expected functional deficiencies triggered by triggering conditions, or they may be caused by expected functional deficiencies leading to hazardous behavior under specific conditions in a driving scenario. Therefore, the order of analysis can be from expected functional deficiencies to potential triggering conditions, or from specific conditions in a driving scenario to expected functional deficiencies.
[0050] Step S202 can also be implemented in other ways, for example: Step S2023, the first severity level indicates that the initial hazard event will not cause harm to people, and the initial hazard event is determined to be acceptable; Step S2024, the first controllability level indicates that the initial hazard event is controllable, and the initial hazard event is determined to be acceptable; Step S2025, when the first severity level indicates that the initial hazard event will cause harm to people and the first controllability level indicates that the initial hazard event is uncontrollable, a first value is determined based on the relative speed at which the initial hazard event will cause harm to people, a second value is determined based on the vehicle's ability to avoid the initial hazard event, and a third value is determined based on the frequency of the initial hazard event occurring during the vehicle's life cycle, wherein the first value is positively correlated with the relative speed at which the initial hazard event will cause harm to people. The method defines the vehicle's ability to avoid the initial hazard event as the time required for the driver to take over the vehicle when its performance is limited and the vehicle cannot drive safely under certain conditions, including the triggering conditions. The second value is positively correlated with the vehicle's ability to avoid the initial hazard event, and the third value is positively correlated with the frequency of the initial hazard event during the vehicle's lifecycle. Step S2026 determines whether the sum of the first, second, and third values is greater than or equal to a first threshold, where the first threshold is greater than 0. Step S2027 determines that the initial hazard event is acceptable if the sum of the first, second, and third values is less than the first threshold. Step S2028 determines that the initial hazard event is unacceptable if the sum of the first, second, and third values is greater than or equal to the first threshold. This method can further achieve risk assessment for initial hazard events.
[0051] Specifically, the first value corresponding to the first severity can be S1`, S2`, and S3`; the second value corresponding to the first controllability can be C1`, C2`, and C3`; and the third value corresponding to the first frequency can be O1`, O2`, O3`, O4`, O5`, and O6`. Based on the first, second, and third values, an initial hazard event assessment is performed, as shown in the table below.
[0052] Table 2 Initial Hazard Event Assessment Form
[0053]
[0054]
[0055] In some embodiments, step S203 can be implemented through the following steps: Step S2031, obtaining the mapping relationship between hazardous events and countermeasures, wherein the countermeasures are used to reduce the harm of the hazardous events; Step S2032, determining the countermeasures corresponding to the hazardous events that are the same as the initial hazardous events as the initial measures. This method can quickly obtain the initial measures.
[0056] Specifically, taking platooning as an example, the aforementioned predetermined measures include the expected functional objectives of the platooning function and its description; use cases for function activation and deactivation; and the interaction relationships between the autonomous driving system and the driver and other road users during the operation of the platooning function. It also includes a detailed description of the operational design domain of the platooning function, the dependencies of system elements, interactions or interfaces; known reasonably foreseeable misuses, system performance limitations, etc.; and alarm and degradation strategies for the platooning function, as well as other information sufficient to support the expected functional safety analysis activities of the platooning function.
[0057] In some embodiments, step S204 can be implemented through the following steps: Step S2041, the second severity level indicates that the post-treatment hazard event will not cause harm to humans, and the post-treatment hazard event is determined to be acceptable; Step S2042, the second controllability level indicates that the post-treatment hazard event is controllable, and the post-treatment hazard event is determined to be acceptable; Step S2043, when the second severity level indicates that the post-treatment hazard event will cause harm to humans and the second controllability level indicates that the post-treatment hazard event is uncontrollable, a fourth value is determined based on the relative speed at which the post-treatment hazard event will cause harm to humans, a fifth value is determined based on the vehicle's ability to avoid the post-treatment hazard event, and a sixth value is determined based on the frequency of the post-treatment hazard event occurring during the vehicle's life cycle, wherein the fourth value is related to the relative speed at which the post-treatment hazard event will cause harm to humans. The fifth value is positively correlated with the vehicle's ability to avoid the initial hazardous event, which is the time required for the driver to take over the vehicle when the vehicle's performance is limited and it cannot drive safely in a scenario including the triggering conditions. The sixth value is positively correlated with the frequency of the treated hazardous event during the vehicle's life cycle. Step S2044: Determine whether the sum of the fourth, fifth, and sixth values is greater than or equal to a second threshold, wherein the second threshold is greater than 0. Step S2045: If the sum of the fourth, fifth, and sixth values is less than the second threshold, determine that the treated hazardous event is acceptable. Step S2046: If the sum of the fourth, fifth, and sixth values is greater than or equal to the second threshold, determine that the treated hazardous event is unacceptable. This method can further assess the residual risk of treated hazardous events.
[0058] Specifically, the fourth value corresponding to the second severity can be S0, S1, S2, and S3; the fifth value corresponding to the second controllability can be C0, C1, C2, and C3; and the sixth value corresponding to the second frequency can be O1, O2, O3, O4, O5, and O6. Based on the fourth, fifth, and sixth values, an initial hazard event assessment is performed, as shown in the table below.
[0059] Table 3. Post-treatment Hazard Assessment Table
[0060]
[0061]
[0062] In some other embodiments, step S205 can be implemented through the following steps: Step S2051, repeating the above processing steps and the second determination step at least once, and updating the initial measure in the processing steps to a predetermined measure during the repetition until the predetermined measure is determined to be effective; Step S2052, determining the predetermined measure in the processing steps during the last repetition as the updated measure. This method, by updating invalid measures to effective measures, can further ensure the effectiveness of the expected functional safety.
[0063] Specifically, taking platooning as an example, the measures include, but are not limited to: modifications to the design of the platooning function system, restrictions on the expected functions of the platooning function, transfer of platooning function authority to the driver, and reduction, mitigation, or avoidance of the impact of reasonably foreseeable misuse.
[0064] To enable those skilled in the art to better understand the technical solution of this application, the implementation process of the vehicle safety detection method of this application will be described in detail below with reference to specific embodiments.
[0065] This embodiment relates to a specific vehicle safety detection method, taking platooning as an example, such as... Figure 3 As shown, it includes the following steps:
[0066] Step S11: Formation driving function specifications and design;
[0067] Step S12: Hazard identification and assessment of platooning function;
[0068] Step S13: Determine whether the hazard is controllable or poses a hazard;
[0069] Step S14: In uncontrollable and hazardous situations, identify and assess the inadequacy of the platooning function and the triggering conditions;
[0070] Step S15: If the risk is unacceptable, modify the platooning function to address the SOTIF-related risks;
[0071] Step S16: Evaluate the effectiveness of SOTIF improvement measures. If the residual risk is unacceptable, update and iterate the measures until the residual risk is acceptable.
[0072] This embodiment relates to another specific vehicle safety detection method, such as... Figure 4 As shown, it includes the following steps:
[0073] Step S21: Functional specification definition and system design;
[0074] Step S22: Identification and assessment of potential hazardous behaviors, using HAZOP and SOTIF HARA to identify and assess potential hazardous events, and to evaluate the severity and controllability of the hazardous events;
[0075] Step S23: Identify and assess potential functional deficiencies and potential triggering conditions. Identify potential functional deficiencies and triggering conditions for hazard events through STPA or STA, and assess the acceptability of the system response through severity, controllability, and frequency.
[0076] Step S24: Functional modification and measure effectiveness assessment, analyze the impact of the expected functional safety measures on the severity, controllability and frequency of functional deficiencies and triggering conditions, determine whether the residual risks are acceptable, and assess the effectiveness of the SOTIF measures;
[0077] Step S25: Verification and validation of known and unknown scenarios, formulate verification and validation strategies, set acceptance criteria for expected functional safety residual risks, and confirm that expected functional safety meets release criteria;
[0078] Step S26: Update functional specifications and system design.
[0079] This application also provides a vehicle safety detection device. It should be noted that the vehicle safety detection device of this application can be used to execute the vehicle safety detection method provided in this application. This device is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0080] The following describes the vehicle safety detection device provided in the embodiments of this application.
[0081] Figure 5 This is a schematic diagram of a vehicle safety detection device according to an embodiment of this application. Figure 5 As shown, the device includes:
[0082] The acquisition unit 10 is used for the acquisition step to acquire the initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability.
[0083] Specifically, potential hazardous events during vehicle operation can be obtained through various methods, such as hazard analysis, risk assessment, and hazard feasibility analysis.
[0084] The first determining unit 20 is used in the first determining step to obtain the first severity of the initial hazard event, the first controllability of the initial hazard event, and the first frequency of the initial hazard event, and to determine whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity is used to characterize whether the initial hazard event will cause harm to a person, the first controllability is used to characterize whether the initial hazard event is controllable, the first frequency is used to characterize the frequency of the initial hazard event occurring in the life cycle of the vehicle, and whether the initial hazard event is acceptable is used to characterize whether to conduct an identification and assessment of potential functional deficiencies and triggering conditions.
[0085] Specifically, whether the initial hazard event is acceptable is used to characterize the severity of the initial hazard event. If the severity of the initial hazard event is too high, then the initial hazard event is unacceptable; if the severity of the initial hazard event is low, then the initial hazard event is acceptable.
[0086] The processing unit 30 is used for processing steps, in the case that the initial hazard event is unacceptable, to obtain the initial measures corresponding to the initial hazard event, and to improve the system performance limitations by adopting the initial measures to obtain the processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability and the first frequency.
[0087] Specifically, anticipated functional safety measures may reduce the severity of the hazard or improve the controllability of the system or the driver, such as limiting the operating speed range of platooning functions or limiting the acceleration and deceleration threshold range at different operating speeds; anticipated functional safety measures may also reduce the frequency of potential triggering conditions, such as limiting the operation of platooning functions in extreme weather or driver status monitoring.
[0088] The second determining unit 40 is used in the second determining step to obtain the second severity of the harm event after treatment, the second controllability of the harm event after treatment, and the second frequency of the harm event after treatment, and to determine whether the initial measures are effective based on the second severity of the harm event after treatment, the second controllability of the harm event after treatment, and the second frequency of the harm event after treatment.
[0089] Specifically, after adding the intended functional safety measures, the unreasonable risk of hazardous events is reduced, mitigated, or avoided. By reassessing the severity, controllability, and frequency of triggering events, the effectiveness of the measures can be further evaluated.
[0090] The updating unit 50 is used for the updating step. If the above-mentioned initial measures are invalid, the initial measures are updated to make the updated initial measures effective, thereby obtaining the updated measures.
[0091] Specifically, if the initial measures mentioned above are effective, there is no need to update them. If the initial measures mentioned above are ineffective, anticipatory functional safety measures should be designed and the initial measures updated to reduce, mitigate, or avoid the anticipatory functional safety risks of the hazard event.
[0092] In this embodiment, the acquisition unit acquires an initial hazard event whose probability of affecting the safety of the vehicle is greater than a preset probability; the first determination unit determines whether the initial hazard event is acceptable based on a first severity, a first controllability, and a first frequency; if the initial hazard event is unacceptable, the processing unit acquires the initial measures corresponding to the initial hazard event and processes the initial hazard event using the initial measures to obtain a processed hazard event; the second determination unit determines whether the initial measures are effective based on a second severity, a second controllability, and a second frequency of the processed hazard event; if the initial measures are ineffective, the updating unit updates the initial measures to make the updated initial measures effective, obtaining updated measures. The above method determines whether the severity of the initial hazard event is acceptable based on its severity, controllability, and frequency. If the severity is too high, corresponding measures are taken to resolve the issue, resulting in a processed hazard event. The effectiveness of the measures is then determined again based on changes in the severity, controllability, and frequency of the processed hazard event. This method achieves an objective assessment of the effectiveness of safety measures, solving the problem of insufficient objectivity in the effectiveness assessment of expected functional safety measures in the prior art.
[0093] In its specific implementation, the upper acquisition unit includes a first processing module, which is used to simulate the functions of the aforementioned vehicle using hazard and operability analysis methods to obtain the aforementioned initial hazard events. This device can further acquire the initial hazard events more quickly.
[0094] Specifically, Hazard and Operability Analysis (HAZOP) employs a deviation-based two-way qualitative causal reasoning method, essentially a qualitative analysis. Through backward reasoning, it identifies the potential causes of the hazard; through forward reasoning, it identifies the possible adverse consequences of the hazard, analyzes the effectiveness of existing control measures, and proposes supplementary measures when necessary, ultimately reducing the risk to an acceptable level. Alternatively, the risk of a hazardous event can be preliminarily assessed based on the following table: severity is categorized as S0, S1, S2, and S3, and controllability as C0, C1, C2, and C3, as shown in Table 1.
[0095] To further and more quickly obtain the aforementioned first severity, first controllability, and first frequency, the first determining unit of this application includes a second processing module and a third processing module. The second processing module is used to process the aforementioned initial hazard event using a system theory process analysis method to obtain the aforementioned first severity, first controllability, and first frequency. The third processing module is used to process the aforementioned initial hazard event using a cause-and-effect tree analysis method to obtain the aforementioned first severity, first controllability, and first frequency.
[0096] Specifically, System Theoretic Process Analysis (STPA) is a system safety analysis method that analyzes system events and failures based on the principles and methods of system theory. By analyzing the system's structure and function, it identifies system error and failure modes and proposes improvement measures to enhance system safety and reliability. A causal tree is a graphical tool used to display the causal relationships between a series of events. In a causal tree, one event can lead to another, and another event may lead to more events. These events are represented as nodes, and the causal relationships between them are represented as directed edges. Causal trees can help better understand why an event occurs and to take appropriate measures to reduce risks or prevent future events from occurring. The above methods identify functional deficiencies and triggering conditions that lead to potential hazardous events, including: potential functional deficiencies and triggering conditions related to planning algorithms, potential functional deficiencies and triggering conditions related to sensors and actuators, and reasonably foreseeable direct or indirect misuse. Hazardous events may be caused by expected functional deficiencies triggered by triggering conditions, or they may be caused by expected functional deficiencies leading to hazardous behavior under specific conditions in a driving scenario. Therefore, the order of analysis can be from expected functional deficiencies to potential triggering conditions, or from specific conditions in a driving scenario to expected functional deficiencies.
[0097] The aforementioned first determining unit further includes a first determining module, a second determining module, a third determining module, a fourth determining module, a fifth determining module, and a sixth determining module. The first determining module is used to determine that the initial hazard event is acceptable when the first severity indicates that the initial hazard event will not cause harm to a person. The second determining module is used to determine that the initial hazard event is acceptable when the first controllability indicates that the initial hazard event is controllable. The third determining module is used to determine a first value based on the relative speed at which the initial hazard event will cause harm to a person, a second value based on the vehicle's ability to avoid the initial hazard event, and a third value based on the frequency of the initial hazard event occurring during the vehicle's lifespan, when the first severity indicates that the initial hazard event will cause harm to a person and the first controllability indicates that the initial hazard event is uncontrollable. The first value is related to the initial hazard event. The relative speed at which an event poses a threat to a person is positively correlated with the vehicle's ability to avoid the initial hazard event. The vehicle's ability to avoid the initial hazard event is defined as the time required for the driver to take over the vehicle when its performance is limited and it cannot drive safely under certain conditions, including the triggering conditions. The second value is positively correlated with the vehicle's ability to avoid the initial hazard event, and the third value is positively correlated with the frequency of the initial hazard event during the vehicle's lifespan. The fourth determining module determines whether the sum of the first, second, and third values is greater than or equal to a first threshold, where the first threshold is greater than 0. The fifth determining module determines that the initial hazard event is acceptable if the sum of the first, second, and third values is less than the first threshold. The sixth determining module determines that the initial hazard event is unacceptable if the sum of the first, second, and third values is greater than or equal to the first threshold. This device can further perform risk assessment for initial hazard events.
[0098] Specifically, the first value corresponding to the first severity can be S1`, S2`, and S3`; the second value corresponding to the first controllability can be C1`, C2`, and C3`; and the third value corresponding to the first frequency can be O1`, O2`, O3`, O4`, O5`, and O6`. Based on the first, second, and third values, an initial hazard event assessment is performed, as shown in Table 2.
[0099] In some embodiments, the processing unit includes an acquisition module and a seventh determination module. The acquisition module acquires the mapping relationship between hazardous events and countermeasures, wherein the countermeasures are used to reduce the harm of the hazardous events. The seventh determination module determines the countermeasures corresponding to the hazardous events that are identical to the initial hazardous events as the initial measures. This device can quickly acquire the initial measures.
[0100] Specifically, taking platooning as an example, the aforementioned predetermined measures include the expected functional objectives of the platooning function and its description; use cases for function activation and deactivation; and the interaction relationships between the autonomous driving system and the driver and other road users during the operation of the platooning function. It also includes a detailed description of the operational design domain of the platooning function, the dependencies of system elements, interactions or interfaces; known reasonably foreseeable misuses, system performance limitations, etc.; and alarm and degradation strategies for the platooning function, as well as other information sufficient to support the expected functional safety analysis activities of the platooning function.
[0101] In some embodiments, the second determining unit includes an eighth determining module, a ninth determining module, a tenth determining module, an eleventh determining module, a twelfth determining module, and a thirteenth determining module. The eighth determining module is used to determine that the post-treatment hazard is acceptable when the second severity indicates that the post-treatment hazard will not cause harm to a person. The ninth determining module is used to determine that the post-treatment hazard is acceptable when the second controllability indicates that the post-treatment hazard is controllable. The tenth determining module is used to determine a fourth value based on the relative speed at which the post-treatment hazard will cause harm to a person, a fifth value based on the vehicle's ability to avoid the post-treatment hazard, and a sixth value based on the frequency of the post-treatment hazard occurring during the vehicle's lifespan, when the second severity indicates that the post-treatment hazard will cause harm to a person and the second controllability indicates that the post-treatment hazard is uncontrollable. The fourth value is related to... The relative speed at which the aforementioned post-treatment hazard events will cause harm to humans is positively correlated. The vehicle's ability to avoid the initial hazard event is the time required for the driver to take over the vehicle when the vehicle's performance is limited and it cannot drive safely in a scenario including the triggering conditions. The fifth value is positively correlated with the vehicle's ability to avoid the aforementioned post-treatment hazard events, and the sixth value is positively correlated with the frequency of the aforementioned post-treatment hazard events occurring during the vehicle's life cycle. The eleventh determining module is used to determine whether the sum of the fourth, fifth, and sixth values is greater than or equal to a second threshold, wherein the second threshold is greater than 0. The twelfth determining module is used to determine that the aforementioned post-treatment hazard event is acceptable if the sum of the fourth, fifth, and sixth values is less than the second threshold. The thirteenth determining module is used to determine that the aforementioned post-treatment hazard event is unacceptable if the sum of the fourth, fifth, and sixth values is greater than or equal to the second threshold. This device can further assess the residual risk of post-treatment hazard events.
[0102] Specifically, the fourth value corresponding to the second severity can be S0, S1, S2, and S3; the fifth value corresponding to the second controllability can be C0, C1, C2, and C3; and the sixth value corresponding to the second frequency can be O1, O2, O3, O4, O5, and O6. Based on the fourth, fifth, and sixth values, an initial hazard event assessment is performed, as shown in Table 3.
[0103] In other embodiments, the updating unit includes a repeating module and a fourteenth determining module. The repeating module is used to repeat the processing steps and the second determining step at least once, and during the repeating process, updates the initial measure in the processing steps to a predetermined measure until the predetermined measure is determined to be effective. The fourteenth determining module is used to determine that the predetermined measure in the processing steps during the last repeating process is the updated measure. By updating invalid measures to valid measures, this device can further ensure the effectiveness of the intended functional safety.
[0104] Specifically, taking platooning as an example, the measures include, but are not limited to: modifications to the design of the platooning function system, restrictions on the expected functions of the platooning function, transfer of platooning function authority to the driver, and reduction, mitigation, or avoidance of the impact of reasonably foreseeable misuse.
[0105] The aforementioned vehicle safety detection device includes a processor and a memory. The acquisition unit, first determination unit, processing unit, second determination unit, and update unit are all stored as program units in the memory. The processor executes these program units stored in the memory to achieve the corresponding functions. All of the above modules reside in the same processor; alternatively, the modules may be located in different processors in any combination.
[0106] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and vehicle safety can be detected by adjusting kernel parameters.
[0107] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0108] This invention provides a computer-readable storage medium including a stored program, wherein, when the program is executed, it controls the device containing the computer-readable storage medium to perform the vehicle safety detection method.
[0109] Specifically, vehicle safety inspection methods include:
[0110] Step S201, acquisition step, acquire the initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability;
[0111] Step S202, the first determining step, involves obtaining the first severity of the initial hazard event, the first controllability of the initial hazard event, and the first frequency of the initial hazard event, and determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity characterizes whether the initial hazard event will cause harm to a person, the first controllability characterizes whether the initial hazard event is controllable, the first frequency characterizes the frequency of the initial hazard event occurring during the vehicle's lifecycle, and whether the initial hazard event is acceptable characterizes whether measures should be taken to address the initial hazard event.
[0112] Step S203, processing step: if the initial hazard event is unacceptable, obtain the initial measures corresponding to the initial hazard event, and use the initial measures to process the initial hazard event to obtain the processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency.
[0113] Step S204, the second determination step, obtains the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard, and determines whether the above-mentioned initial measures are effective based on the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard.
[0114] Step S205, update step: if the above initial measures are invalid, update the above initial measures to make the updated initial measures effective, and obtain the updated measures.
[0115] This invention provides a processor for running a program, wherein the program executes the vehicle safety detection method during operation.
[0116] Specifically, vehicle safety inspection methods include:
[0117] Step S201, acquisition step, acquire the initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability;
[0118] Step S202, the first determining step, involves obtaining the first severity of the initial hazard event, the first controllability of the initial hazard event, and the first frequency of the initial hazard event, and determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity characterizes whether the initial hazard event will cause harm to a person, the first controllability characterizes whether the initial hazard event is controllable, the first frequency characterizes the frequency of the initial hazard event occurring during the vehicle's lifecycle, and whether the initial hazard event is acceptable characterizes whether measures should be taken to address the initial hazard event.
[0119] Step S203, processing step: if the initial hazard event is unacceptable, obtain the initial measures corresponding to the initial hazard event, and use the initial measures to process the initial hazard event to obtain the processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency.
[0120] Step S204, the second determination step, obtains the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard, and determines whether the above-mentioned initial measures are effective based on the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard.
[0121] Step S205, update step: if the above initial measures are invalid, update the above initial measures to make the updated initial measures effective, and obtain the updated measures.
[0122] This invention provides a device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs at least the following steps:
[0123] Step S201, acquisition step, acquire the initial hazard event of the vehicle, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability;
[0124] Step S202, the first determining step, involves obtaining the first severity of the initial hazard event, the first controllability of the initial hazard event, and the first frequency of the initial hazard event, and determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity characterizes whether the initial hazard event will cause harm to a person, the first controllability characterizes whether the initial hazard event is controllable, the first frequency characterizes the frequency of the initial hazard event occurring during the vehicle's lifecycle, and whether the initial hazard event is acceptable characterizes whether measures should be taken to address the initial hazard event.
[0125] Step S203, processing step: if the initial hazard event is unacceptable, obtain the initial measures corresponding to the initial hazard event, and use the initial measures to process the initial hazard event to obtain the processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency.
[0126] Step S204, the second determination step, obtains the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard, and determines whether the above-mentioned initial measures are effective based on the second severity of the above-mentioned post-treatment hazard, the second controllability of the above-mentioned post-treatment hazard, and the second frequency of the above-mentioned post-treatment hazard.
[0127] Step S205, update step: if the above initial measures are invalid, update the above initial measures to make the updated initial measures effective, and obtain the updated measures.
[0128] The devices mentioned in this article can be servers, PCs, tablets, mobile phones, etc.
[0129] This application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program that initializes the above-described method steps:
[0130] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those described herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.
[0131] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0132] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0133] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0134] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0135] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0136] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0137] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0138] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0139] As can be seen from the above description, the embodiments of this application achieve the following technical effects:
[0140] 1) The vehicle safety detection method of this application firstly identifies an initial hazard event that has a probability greater than a preset probability of affecting the safety of the vehicle; then, based on a first severity, a first controllability, and a first frequency, determines whether the initial hazard event is acceptable; if the initial hazard event is unacceptable, it acquires the initial measures corresponding to the initial hazard event and applies these measures to address the initial hazard event, resulting in a post-treatment hazard event; based on a second severity, a second controllability, and a second frequency of the post-treatment hazard event, it determines whether the initial measures are effective; if the initial measures are ineffective, they are updated to make the updated initial measures effective, resulting in updated measures. This method determines whether the severity of the initial hazard event is acceptable based on its severity, controllability, and frequency. If the severity is too high, corresponding measures are taken to address it, resulting in a post-treatment hazard event. The effectiveness of the measures is then determined again based on changes in the severity, controllability, and frequency of the post-treatment hazard event. This method achieves an objective assessment of the effectiveness of safety measures, solving the problem of insufficient objectivity in the effectiveness assessment of expected functional safety measures in existing technologies.
[0141] 2) The vehicle safety detection device of this application includes an acquisition unit that acquires an initial hazard event of the vehicle whose probability of affecting the vehicle's safety is greater than a preset probability; a first determination unit that determines whether the initial hazard event is acceptable based on a first severity, a first controllability, and a first frequency; a processing unit that, if the initial hazard event is unacceptable, acquires the initial measures corresponding to the initial hazard event and processes the initial hazard event using the initial measures to obtain a processed hazard event; a second determination unit that, based on a second severity, a second controllability, and a second frequency of the processed hazard event, determines whether the initial measures are effective; and an update unit that, if the initial measures are ineffective, updates the initial measures to make the updated initial measures effective, obtaining updated measures. This method determines whether the severity of the initial hazard event is acceptable based on its severity, controllability, and frequency. If the severity is too high, corresponding measures are taken to resolve the issue, resulting in a processed hazard event. The effectiveness of the measures is then determined again based on changes in the severity, controllability, and frequency of the processed hazard event. This method achieves an objective assessment of the effectiveness of safety measures. This addresses the problem that the effectiveness assessment of intended functional safety measures in existing technologies is not objective enough.
[0142] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A method for safety inspection of a vehicle, characterized in that, include: The acquisition step involves acquiring the initial hazard event of the vehicle and the first cause that triggers the initial hazard event, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability. The first determining step involves acquiring the first severity of the first cause, the first controllability of the first cause, and the first frequency of the first cause, and determining whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity characterizes whether the initial hazard event will cause harm to a person, the first controllability characterizes whether the initial hazard event is controllable, the first frequency characterizes the frequency of the initial hazard event occurring during the vehicle's lifecycle, and whether the initial hazard event is acceptable characterizes whether to conduct an identification and assessment of potential functional deficiencies and triggering conditions. The processing steps involve obtaining initial measures corresponding to the initial hazard event if the initial hazard event is unacceptable, and using the initial measures to improve the system performance limitations to obtain a processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency; The second determining step involves obtaining the second severity, the second controllability, and the second frequency of the second cause that triggered the harm event after the treatment, and determining whether the initial measures are effective based on the second severity, the second controllability, and the second frequency. The update step involves updating the initial measure if it is ineffective, so that the updated initial measure becomes effective, thus obtaining the updated measure.
2. The method according to claim 1, characterized in that, The acquisition steps include: The functions of the vehicle are simulated using a hazard and operability analysis method to obtain the initial hazard event.
3. The method according to claim 1, characterized in that, Obtaining the first severity of the first cause, the first controllability of the first cause, and the first frequency of the first cause includes one of the following: The initial hazard event is processed using a system theory process analysis method to obtain the first severity, the first controllability, and the first frequency; The initial hazard event is processed using the cause-effect tree analysis method to obtain the first severity, the first controllability, and the first frequency.
4. The method according to claim 1, characterized in that, Determining whether the initial hazardous event is acceptable based on the first severity, the first controllability, and the first frequency includes: The first severity level determines that the initial hazard event is acceptable if it characterizes that the initial hazard event will not pose a danger to a person. The first controllability determines that the initial hazard event is acceptable if it is characterized as being controllable. Given that the first severity level indicates that the initial hazard event will cause harm to a person, and the first controllability level indicates that the initial hazard event is uncontrollable, a first value is determined based on the relative speed at which the initial hazard event will cause harm to a person; a second value is determined based on the vehicle's ability to avoid the initial hazard event; and a third value is determined based on the frequency of the initial hazard event occurring in the vehicle's life cycle. The first value is positively correlated with the relative speed at which the initial hazard event will cause harm to a person. The vehicle's ability to avoid the initial hazard event is defined as the time required for the driver to take over the vehicle when the vehicle's performance is limited and the vehicle cannot drive safely in a scenario including triggering conditions. The second value is positively correlated with the vehicle's ability to avoid the initial hazard event, and the third value is positively correlated with the frequency of the initial hazard event occurring in the vehicle's life cycle. Determine whether the sum of the first value, the second value, and the third value is greater than or equal to a first threshold, wherein the first threshold is greater than 0; If the sum of the first value, the second value, and the third value is less than the first threshold, the initial hazard event is determined to be acceptable. If the sum of the first value, the second value, and the third value is greater than or equal to the first threshold, the initial hazard event is determined to be unacceptable.
5. The method according to claim 1, characterized in that, Obtaining the initial measures corresponding to the initial hazard event includes: Obtain the mapping relationship between hazardous events and response measures, wherein the response measures are used to reduce the harm of the hazardous events; The response measure corresponding to the hazard event that is the same as the initial hazard event is identified as the initial measure.
6. The method according to claim 1, characterized in that, The second determining step includes: The second severity level determines that the post-treatment hazard is acceptable if it characterizes that the post-treatment hazard will not pose a danger to a person. The second controllability determines that the post-treatment hazard is acceptable if it characterizes that the post-treatment hazard is controllable. When the second severity level characterizes the harm the treated hazard event will cause to a person, and the second controllability level characterizes the uncontrollability of the treated hazard event, a fourth value is determined based on the relative speed at which the treated hazard event will cause harm to a person; a fifth value is determined based on the vehicle's ability to avoid the treated hazard event; and a sixth value is determined based on the frequency of the treated hazard event occurring in the vehicle's life cycle. The fourth value is positively correlated with the relative speed at which the treated hazard event will cause harm to a person. The vehicle's ability to avoid the initial hazard event is the time required for the driver to take over the vehicle when the vehicle's performance is limited and the vehicle cannot drive safely in a scenario including triggering conditions. The fifth value is positively correlated with the vehicle's ability to avoid the treated hazard event, and the sixth value is positively correlated with the frequency of the treated hazard event occurring in the vehicle's life cycle. Determine whether the sum of the fourth value, the fifth value, and the sixth value is greater than or equal to a second threshold, wherein the second threshold is greater than 0; If the sum of the fourth, fifth, and sixth values is less than the second threshold, the post-treatment hazard event is determined to be acceptable. If the sum of the fourth, fifth, and sixth values is greater than or equal to the second threshold, the post-treatment hazard is determined to be unacceptable.
7. The method according to any one of claims 1 to 6, characterized in that, The update steps include: Repeat the processing step and the second determining step at least once, and update the initial measure in the processing step to a predetermined measure during the repetition until the predetermined measure is determined to be effective; The predetermined measure in the processing step of the last repetition process is determined to be the update measure.
8. A vehicle safety detection device, characterized in that, include: The acquisition unit is used to acquire the initial hazard event of the vehicle and the first cause that triggers the initial hazard event, wherein the initial hazard event is an event whose probability of affecting the safety of the vehicle is greater than a preset probability; A first determining unit is used in a first determining step to obtain a first severity of the first cause, a first controllability of the first cause, and a first frequency of the first cause, and to determine whether the initial hazard event is acceptable based on the first severity, the first controllability, and the first frequency. The first severity is used to characterize whether the initial hazard event will cause harm to a person, the first controllability is used to characterize whether the initial hazard event is controllable, the first frequency is used to characterize the frequency of the initial hazard event occurring in the life cycle of the vehicle, and whether the initial hazard event is acceptable is used to characterize whether to conduct an identification and assessment of potential functional deficiencies and triggering conditions. A processing unit is configured to process steps, wherein, if the initial hazard event is unacceptable, obtain initial measures corresponding to the initial hazard event, and use the initial measures to improve the system performance limitations to obtain a processed hazard event, wherein the initial measures are used to reduce at least one of the first severity, the first controllability, and the first frequency; The second determining unit is used in the second determining step to obtain the second severity, the second controllability, and the second frequency of the second cause that triggered the harm event after treatment, and to determine whether the initial measures are effective based on the second severity, the second controllability, and the second frequency. An update unit is used for the update step, which updates the initial measure when the initial measure is invalid, so that the updated initial measure is valid, thereby obtaining an updated measure.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform the method according to any one of claims 1 to 7.
10. A vehicle system, characterized in that, include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs comprising methods for performing any one of claims 1 to 7.