Intelligent connected vehicle safety and controllability evaluation method
Patent Information
- Application Number
- CN202410976224.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-19
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2044-07-19
AI Technical Summary
[0004]本发明提供了一种针对智能网联汽车融合安全可控性的评估方法,可以解决现有的评估方法不仅只考虑单一功能,而且只考虑人为干预的风险可控性的问题
从基于目标系统自身的自主风险可控性、基于驾乘接入的风险可控性以及基于远程介入的风险可控性三个层面对智能网联汽车融合安全可控性进行分析评估。通过这种多层次的评估方法,可以全面地分析智能网联汽车在不同场景下的安全风险管理机制,确保在自主控制、人工干预以及远程监控等情况下,全面评估和理解控制风险的难易程度。
Smart Images

Figure CN118606769B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent connected vehicle technology, and in particular to an evaluation method for the integrated safety and controllability of intelligent connected vehicles. Background Technology
[0002] With the continuous advancement of intelligent connected vehicle technology and its increasingly widespread application in the automotive market, the coupling relationships between traffic objects are constantly strengthening. Automobiles face a situation of integrated development of functional safety, anticipated functional safety, and information security, leading to increased safety risks. Ensuring the multifaceted safety of intelligent connected vehicles is a highly challenging issue. The automotive functional safety standard ISO 26262 uses HARA (Hazard Analysis and Reliability Assessment) for safety analysis during the conceptual design phase. Based on three parameters—severity (S), probability of exposure (E), and controllability (C)—identified by a hazard event, the vehicle integrity level ASIL is determined for the classification and assessment of vehicle system safety. Controllability (C) refers to the estimated probability that the driver or other potentially at-risk personnel can adequately control a hazard event to avoid specific harm. This controllability assessment only considers the controllability of risks based on human intervention.
[0003] However, with the continuous development of intelligent connected vehicle technology, when autonomous driving technology reaches Level 3 or higher, the controllability of autonomous risks in the vehicle system needs to be considered. Simultaneously, with the increasing maturity of vehicle-road-cloud integration technology, the controllability of risks from remote monitoring cannot be ignored. Furthermore, existing controllability assessment methods mostly focus on assessing the controllability of a single function within the system, and there is no comprehensive, integrated safety and controllability assessment method specifically for intelligent connected vehicles. Summary of the Invention
[0004] This invention provides an evaluation method for the integrated safety and controllability of intelligent connected vehicles, which solves the problem that existing evaluation methods not only consider a single function but also only the risk controllability of human intervention. The specific technical solution is as follows: On the one hand, an evaluation method for the integrated safety and controllability of intelligent connected vehicles is provided, the method comprising: An abstract model is created for the target system of the intelligent connected vehicle, and based on the abstract model, the safety association system, the set of human-machine interaction content, and the information flow chain of each remote intervention command related to the target system are analyzed and confirmed. Based on the information flow chain of the security association system, the interactive content set, and each remote intervention command, the autonomous risk controllability gain coefficient, the human misuse coefficient of driver and passenger intervention, and the remote intervention controllability gain coefficient are determined respectively. Obtain a list of unsafe behaviors, and comprehensively evaluate the risk controllability of each unsafe behavior in the list under each corresponding scenario based on the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient.
[0005] On the other hand, an evaluation device for the integrated safety and controllability of intelligent connected vehicles is provided, the device comprising: The modeling module is used to abstractly model the target system of intelligent connected vehicles, and analyze and confirm the security association system, human-machine interaction content set, and information flow chain of each remote intervention command related to the target system based on the abstract model. The determination module is used to determine the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient based on the information flow chain of the security association system, the interactive content set, and each remote intervention command, respectively. The assessment module is used to obtain a list of unsafe behaviors and to comprehensively assess the risk controllability of each unsafe behavior in the list in each corresponding scenario based on the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient.
[0006] On the other hand, a computer device is provided, the computer device including a memory and a processor, the memory for storing a computer program, and the processor for executing the computer program stored in the memory to implement the steps of the method described above.
[0007] On the other hand, a computer-readable storage medium is provided, wherein a computer program is stored therein, and when the computer program is executed by a processor, it implements the steps of the method described above.
[0008] On the other hand, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the method described above.
[0009] The technical solution provided by this invention can bring at least the following beneficial effects: The integrated safety controllability of intelligent connected vehicles is analyzed and evaluated from three levels: the controllability of autonomous risks based on the target system itself, the controllability of risks based on driver and passenger access, and the controllability of risks based on remote intervention. This multi-level evaluation method allows for a comprehensive analysis of the safety risk management mechanisms of intelligent connected vehicles in different scenarios, ensuring a thorough assessment and understanding of the ease or difficulty of controlling risks under conditions of autonomous control, manual intervention, and remote monitoring. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a flowchart of an evaluation method for the integrated safety and controllability of intelligent connected vehicles provided by an embodiment of the present invention; Figure 2 This is an abstract modeling framework diagram provided in one embodiment of the present invention; Figure 3 This is a structural diagram of an evaluation device for the integrated safety and controllability of intelligent connected vehicles, provided by an embodiment of the present invention. Figure 4 This is a hardware architecture diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0012] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0013] The following describes the specific implementation of the above concept.
[0014] Please refer to Figure 1 This invention provides an evaluation method for the integrated safety and controllability of intelligent connected vehicles, the method comprising: Step 100: Abstract model the target system of the intelligent connected vehicle, and analyze and confirm the safety association system, human-machine interaction content set, and information flow chain of each remote intervention command related to the target system based on the abstract model. Step 102: Based on the information flow chain of the security association system, the interactive content set, and each remote intervention command, determine the autonomous risk controllability gain coefficient, the human misuse coefficient of driver and passenger intervention, and the remote intervention controllability gain coefficient. Step 104: Obtain a list of unsafe behaviors and comprehensively evaluate the risk controllability of each unsafe behavior in the corresponding scenario based on the autonomous risk controllability gain coefficient, human misuse coefficient, and remote intervention controllability gain coefficient.
[0015] It should be noted that the "controllability" mentioned in this invention is defined according to ISO 26262. According to this standard, the higher the assessment value, the more difficult the risk control is.
[0016] In this embodiment of the invention, the integrated safety controllability of intelligent connected vehicles is analyzed and evaluated from three levels: the controllability of autonomous risks based on the target system itself, the controllability of risks based on driver and passenger access, and the controllability of risks based on remote intervention. This multi-level evaluation method allows for a comprehensive analysis of the safety risk management mechanisms of intelligent connected vehicles in different scenarios, ensuring a comprehensive assessment and understanding of the ease or difficulty of controlling risks under conditions of autonomous control, manual intervention, and remote monitoring.
[0017] The following description Figure 1 The execution method for each step is shown.
[0018] For step 100: In this step, based on the system specifications and definitions, it is necessary to confirm the system's security objectives and overall security requirements, and to abstractly model the system specifications and structure. Specifically, by establishing abstract models of cognition, decision-making, action, information flow, and energy flow, the functional logical relationships between the internal components of the system are constructed, such as... Figure 2 As shown. It is understandable that when analyzing a specific system, it is not necessary to force the inclusion of... Figure 2 Instead of displaying all components, you can select and adjust relevant components based on the actual situation.
[0019] Here, perception refers to the system's ability to sense the external environment, including but not limited to using sensors such as temperature sensors, pressure sensors, cameras, and lidar to collect information about the external environment. Decision-making refers to the system's ability to formulate corresponding strategies and output instructions based on external information, including but not limited to hardware such as ECUs and software such as decision-making algorithms. Action mainly refers to the ability to receive decision-making instructions and execute actions, including but not limited to controllers, control algorithms, and actuators. Information flow refers to the process of information exchange between various sub-components and the outside world, such as operation instructions and sensed information. Energy flow refers to the process of energy exchange between various sub-components and the outside world, including the mechanical energy transmitted through transmission mechanisms and hydraulic lines.
[0020] Subsequently, based on the system abstraction model, the impact of human operation and the external environment on the target system is considered, as well as the impact of the target system's output on vehicle behavior. Simultaneously, the safety-related systems upon which the target system depends must be analyzed and determined; for example, the normal operation of the Automatic Emergency Braking (AEB) system depends on the normal operation of the braking system. Furthermore, the set of human-machine interaction content during driver intervention and the information flow chain of each remote intervention command must be analyzed and determined.
[0021] Regarding step 102: Next, the determination methods of the three gain coefficients—autonomous risk controllability gain coefficient, human misuse coefficient of driver and passenger intervention, and remote intervention controllability gain coefficient—will be explained in detail.
[0022] In some implementations, the autonomous risk controllability gain coefficient is determined as follows: Determine the association category between each associated system and the target system within the security association system; Based on the degree of dependence of the target system on the association system with the association category of supportive association, the gain coefficient corresponding to each association system with supportive association is quantified. Based on the redundancy of the association system with the association category of redundancy, the gain coefficient of the redundancy association is quantified. Based on the degree of protection of the associated system with the association category of protective association, the gain coefficient of the protective association is quantified. Based on the gain coefficients of each associated system corresponding to the supporting association, the gain coefficients of the redundant association, and the gain coefficients of the protective association, the autonomous risk controllability gain coefficient is determined.
[0023] In this embodiment, the relationship between the target system and its associated safety systems is analyzed to determine the association categories, including supportive associations, redundant associations, and protective associations. Supportive associations refer to situations where the target system's safety functions depend on the functions of the associated system, such as AEB's safety issues relying on the normal operation of the braking system's basic functions. Redundant associations refer to situations where, when a safety risk occurs in the target system, a backup system can provide redundant functions to improve reliability. Protective associations refer to situations where, in addition to the target system's own protective functions, there are additional safety protection systems, such as a "safety co-pilot system."
[0024] By analyzing the degree of dependence of the target system on the associated systems in supporting relationships, the gain coefficients corresponding to each associated system in the supporting relationships are quantified. It can be understood that the higher the degree of dependence, the lower the gain coefficient, which will increase the assessment value of autonomous risk controllability; that is, the degree of dependence and the controllability gain coefficient are inversely proportional.
[0025] Based on the redundancy of associated systems in redundant associations, the gain coefficient of redundant associations is quantified. It can be understood that the higher the redundancy of associated systems in redundant associations, the higher the gain coefficient of redundant associations, which will reduce the controllability assessment value. That is, the number of associated systems in redundant associations is inversely proportional to the controllability gain coefficient.
[0026] Based on the degree of protection of the associated system in a protective association, the gain coefficient of the protective association is quantified. It can be understood that the higher the gain coefficient of the protective association, the lower the controllability assessment value; that is, the degree of protection of the associated system in a protective association is inversely proportional to the controllability gain coefficient.
[0027] The gain coefficients of the supporting correlations, the redundancy correlations, and the protective correlations are multiplied together to obtain the autonomous risk controllability gain coefficient. .
[0028] In some implementations, the human misuse factor is determined as follows: Determine whether each interactive element in the set of human-computer interaction content is informational or action-based. Obtain a predetermined level of difficulty for the driver to understand information-based interactions, as well as a preset coefficient for each level; Determine the level of difficulty for the driver to understand each interactive content belonging to the information category in the interactive content set, and determine the misuse coefficient of each interactive content belonging to the information category based on a preset coefficient; Obtain the predetermined complexity level of the action-type interaction when executed by the driver, as well as the preset coefficient for each level; Determine the complexity level of each interactive content belonging to the action class in the interactive content set, so as to determine the misuse coefficient of each interactive content belonging to the action class; The human misuse coefficient is determined based on the misuse coefficients of each interactive content belonging to the information category and the misuse coefficients of each interactive content belonging to the action category.
[0029] In this embodiment, the interaction content between the human driver and the system is divided into information-based and action-based types. It is necessary to determine whether each interaction in the set is information-based or action-based. Information-based interactions are system prompts to inform the driver and passengers of information, such as visual warnings and auditory reminders. Action-based interactions require the driver and passengers to perform corresponding actions based on prompts, such as taking over the steering wheel or pressing the brake pedal. To assess the ease with which the driver understands information-based interactions and the complexity of the driver executing action-based interactions, an interaction content level table needs to be pre-created, and a preset coefficient needs to be determined for each level, as shown in Table 1 below.
[0030] Table 1 Interactive Content Level Table In the information category, the preset coefficient for the level of understanding information, and in the action category, the preset coefficient for the level of reaction, is 1. The preset coefficient increases with the level of understanding complexity and the level of operation complexity. It can be understood that the larger the preset coefficient, the less controllable the system.
[0031] By determining the level of difficulty for the driver to understand each information-based interactive content in the set of interactive content, the preset coefficient for that level can be determined as the misuse coefficient for that interactive content. Similarly, by determining the level of complexity for each action-based interactive content in the set of interactive content, the preset coefficient for that level can be determined as the misuse coefficient for that interactive content. The human misuse coefficient is determined by multiplying the misuse coefficients of each interactive content in the set of interactive content. .
[0032] In some implementations, the remote intervention controllability gain coefficient is determined as follows: For each remote intervention command, execute: Identify the nodes in the information flow chain corresponding to the current remote intervention command that are vulnerable to network attacks; Assess the probability coefficient of each node being attacked by the network, and the impact coefficient of the attack on the remote control function, in order to determine the remote intervention controllability gain coefficient corresponding to the current remote intervention command.
[0033] In this embodiment, a node refers to a relevant component along the flow path in the information flow chain. When analyzing the controllability of remote intervention, the vehicle-side control chain for remote intervention is first identified, including the entire process from receiving information from the vehicle to final execution, and the flow path and related components of the control information flow are analyzed. First, the probability coefficient of a network attack achieving an effective attack on a node in the remote control chain is assessed. Based on information security attribute analysis, a mapping relationship is established between threats and functional failures and performance degradation of components in the control chain to analyze and determine the impact coefficient of network attacks on remote control functions, such as incomplete, tampered, or leaked information. For example, when the automatic emergency braking system (AEB) or braking function of a vehicle is remotely controlled to complete emergency braking, if the network attack targets a function unrelated to the braking process, such as the AEB's prompt for human intervention, although these attacks may lead to unsafe vehicle behavior, they do not directly affect the controllability based on remote intervention; therefore, they are not considered in this case. Based on this, the remote intervention controllability gain coefficient can be obtained. This coefficient can quantify the impact of information security threats on the controllability of remote intervention.
[0034] Regarding step 104: In some implementations, step 104 may include: For each scenario of every unsafe behavior in the unsafe behavior list, execute the following: Obtain a pre-generated classification table of autonomous risk controllability, driver / passenger intervention controllability, and remote intervention controllability; Based on the classification level table, the autonomous risk controllability level, driver / passenger intervention controllability level, and remote intervention controllability level of the current unsafe behavior in the current scenario are determined respectively; Based on the autonomous risk controllability level, driver / passenger intervention controllability level, and remote intervention controllability level of the current unsafe behavior in the current scenario, as well as the autonomous risk controllability gain coefficient, human misuse coefficient, and remote intervention controllability gain coefficient, the risk controllability of the current unsafe behavior in the current scenario is comprehensively assessed.
[0035] It should be noted that by decoupling vehicle behavior in lateral and longitudinal motion, the following five unsafe behaviors are derived, summarized in Table 2 below: Table 2 Unsafe behaviors of vehicles In this embodiment, the controllability classification level table is shown in Table 3 below.
[0036] Table 3 Controllability Classification Table In this embodiment of the invention, the risk controllability of the current unsafe behavior in the current scenario is assessed in the following manner: In the formula, To ensure that the risk of the r-th unsafe behavior is controllable in the t-th scenario, , and These are the gain coefficients for autonomous risk controllability, human misuse, and remote intervention controllability, respectively. and These are the autonomous risk controllability level, the driver / passenger intervention controllability level, and the remote intervention controllability level, respectively, for the current unsafe behavior in the current scenario.
[0037] Therefore, in this embodiment of the invention, when analyzing the controllability of autonomous risks, not only is the system's own risk control capability considered, but also the correlation between security functions of different systems is incorporated into the risk control capability assessment. If the implementation of the target system's security functions depends on other basic systems, backup systems with functional redundancy, or monitoring systems, these factors will affect the system's own risk control capability, and this impact is quantified as a gain coefficient. When analyzing the controllability based on driver intervention, the impact of human misuse on controllability is considered based on the complexity and difficulty of human-machine interaction, and quantified as a human misuse coefficient. In addition, the impact of network attack threats on control risks based on remote intervention is also considered. Through this multi-level assessment method, the safety risk management mechanism of intelligent connected vehicles in different scenarios can be comprehensively analyzed, ensuring a comprehensive assessment and understanding of the difficulty of controlling risks under autonomous control, human intervention, and remote monitoring conditions.
[0038] Please refer to Figure 3 This invention provides an evaluation device for the integrated safety and controllability of intelligent connected vehicles, the device comprising: Modeling module 301 is used to abstractly model the target system of intelligent connected vehicles, and analyze and confirm the safety association system, human-machine interaction content set, and information flow chain of various remote intervention commands related to the target system based on the abstract model. The determination module 302 is used to determine the autonomous risk controllability gain coefficient, the human misuse coefficient of driver and passenger intervention, and the remote intervention controllability gain coefficient based on the information flow chain of the security association system, the interactive content set, and each remote intervention command, respectively. The assessment module 303 is used to obtain a list of unsafe behaviors and to comprehensively assess the risk controllability of each unsafe behavior in the list in each corresponding scenario based on the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient.
[0039] In one embodiment of the present invention, the autonomous risk controllability gain coefficient in the determining module 302 is determined in the following manner: Determine the association category between each associated system and the target system within the security association system; Based on the degree of dependence of the target system on the association system with the association category of supportive association, the gain coefficient corresponding to each association system with supportive association is quantified. Based on the redundancy of the association system with the association category of redundancy, the gain coefficient of the redundancy association is quantified. Based on the degree of protection of the associated system with the association category of protective association, the gain coefficient of the protective association is quantified. Based on the gain coefficients of each associated system corresponding to the supporting association, the gain coefficients of the redundant association, and the gain coefficients of the protective association, the autonomous risk controllability gain coefficient is determined.
[0040] In one embodiment of the present invention, the human misuse coefficient in the determination module 302 is determined in the following manner: Determine whether each interactive element in the set of human-computer interaction content is informational or action-based. Obtain a predetermined level of difficulty for the driver to understand information-based interactions, as well as a preset coefficient for each level; Determine the level of difficulty for the driver to understand each interactive content belonging to the information category in the interactive content set, and determine the misuse coefficient of each interactive content belonging to the information category based on a preset coefficient; Obtain the predetermined complexity level of the action-type interaction when executed by the driver, as well as the preset coefficient for each level; Determine the complexity level of each interactive content belonging to the action class in the interactive content set, so as to determine the misuse coefficient of each interactive content belonging to the action class; The human misuse coefficient is determined based on the misuse coefficients of each interactive content belonging to the information category and the misuse coefficients of each interactive content belonging to the action category.
[0041] In one embodiment of the present invention, the remote intervention controllability gain coefficient in the determining module 302 is determined in the following manner: For each remote intervention command, execute: Identify the nodes in the information flow chain corresponding to the current remote intervention command that are vulnerable to network attacks; Assess the probability coefficient of each node being attacked by the network, and the impact coefficient of the attack on the remote control function, in order to determine the remote intervention controllability gain coefficient corresponding to the current remote intervention command.
[0042] In one embodiment of the present invention, the evaluation module 303 is used to perform: For each scenario of every unsafe behavior in the unsafe behavior list, execute the following: Obtain a pre-generated classification table of autonomous risk controllability, driver / passenger intervention controllability, and remote intervention controllability; Based on the classification level table, the autonomous risk controllability level, driver / passenger intervention controllability level, and remote intervention controllability level of the current unsafe behavior in the current scenario are determined respectively; Based on the autonomous risk controllability level, driver / passenger intervention controllability level, and remote intervention controllability level of the current unsafe behavior in the current scenario, as well as the autonomous risk controllability gain coefficient, human misuse coefficient, and remote intervention controllability gain coefficient, the risk controllability of the current unsafe behavior in the current scenario is comprehensively assessed.
[0043] In one embodiment of the present invention, the risk controllability of the current unsafe behavior in the current scenario in the evaluation module 303 is evaluated in the following manner: In the formula, To ensure the risk of the r-th unsafe behavior is controllable in the t-th scenario. , and These are the gain coefficients for autonomous risk controllability, human misuse, and remote intervention controllability, respectively. , and These are the autonomous risk controllability level, the driver / passenger intervention controllability level, and the remote intervention controllability level, respectively, for the current unsafe behavior in the current scenario.
[0044] It should be noted that the evaluation device for the integrated safety and controllability of intelligent connected vehicles provided in the above embodiments is only an example of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the above device embodiments and method embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.
[0045] Embodiments of this application also provide a computer device, please refer to... Figure 4 The computer device includes a processor and a memory, the memory storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by the processor to implement the evaluation method for the integrated safety and controllability of intelligent connected vehicles provided in the above-described method embodiments.
[0046] Embodiments of this application also provide a computer-readable storage medium storing at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to implement the assessment and protection method for the integrated safety and controllability of intelligent connected vehicles provided in the above-described method embodiments.
[0047] Embodiments of this application also provide a computer program product, which includes a computer program. A processor of a computer device reads the computer program from a computer-readable storage medium and executes the computer program, causing the computer device to perform any of the above embodiments of the evaluation method for the integrated safety and controllability of intelligent connected vehicles.
[0048] For ease of description, the above systems or devices are described separately as various modules or units based on their functions. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware components.
[0049] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0050] Finally, it should be noted that in this document, relational terms such as first, second, third, and fourth are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0051] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for evaluating the integrated safety and controllability of intelligent connected vehicles, characterized in that, The method includes: An abstract model is created for the target system of the intelligent connected vehicle, and based on the abstract model, the safety association system, the set of human-machine interaction content, and the information flow chain of each remote intervention command related to the target system are analyzed and confirmed. Based on the information flow chain of the security association system, the interactive content set, and each remote intervention command, the autonomous risk controllability gain coefficient, the human misuse coefficient of driver and passenger intervention, and the remote intervention controllability gain coefficient are determined respectively. Obtain a list of unsafe behaviors, and comprehensively evaluate the risk controllability of each unsafe behavior in the list in each corresponding scenario based on the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient. The autonomous risk controllability gain coefficient is determined in the following way: Determine the association category between each associated system in the security association system and the target system; Based on the degree of dependence of the target system on the association system whose association category is supportive association, the gain coefficient corresponding to each association system of supportive association is quantified. Based on the redundancy of the association system whose association category is redundant association, the gain coefficient of the redundant association is quantified. Based on the degree of protection of the associated system whose association category is protective association, the gain coefficient of the protective association is quantified; Based on the gain coefficients of each associated system corresponding to the supporting association, the gain coefficient of the redundant association, and the gain coefficient of the protective association, the autonomous risk controllability gain coefficient is determined. The human misuse coefficient is determined in the following way: Determine whether each interactive element in the set of human-computer interaction content is informational or action-based. Obtain a predetermined level of difficulty for the driver to understand information-based interactions, as well as a preset coefficient for each level; Determine the level of difficulty for the driver to understand each interactive content belonging to the information category in the set of interactive content, so as to determine the misuse coefficient of each interactive content belonging to the information category based on the preset coefficient; Obtain the predetermined complexity level of the action-type interaction when executed by the driver, as well as the preset coefficient for each level; Determine the complexity level of each interactive content belonging to the action category in the set of interactive content, so as to determine the misuse coefficient of each interactive content belonging to the action category; The human misuse coefficient is determined based on the misuse coefficients of each interactive content belonging to the information category and the misuse coefficients of each interactive content belonging to the action category. The remote intervention controllability gain coefficient is determined in the following way: For each remote intervention command, execute: Identify the nodes in the information flow chain corresponding to the current remote intervention command that are vulnerable to network attacks; Assess the probability coefficient of each node being attacked by the network, and the impact coefficient of the attack on the remote control function, in order to determine the remote intervention controllability gain coefficient corresponding to the current remote intervention command.
2. The method as described in claim 1, characterized in that, The process of obtaining the list of unsafe behaviors involves comprehensively evaluating the risk controllability of each unsafe behavior in the list under various corresponding scenarios based on the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient. This includes: For each scenario of every unsafe behavior in the unsafe behavior list, execute the following: Obtain a pre-generated classification table of autonomous risk controllability, driver / passenger intervention controllability, and remote intervention controllability; Based on the classification table, the autonomous risk controllability level, driver / passenger intervention controllability level, and remote intervention controllability level of the current unsafe behavior in the current scenario are determined respectively. Based on the autonomous risk controllability level, driver / passenger intervention controllability level, and remote intervention controllability level of the current unsafe behavior in the current scenario, as well as the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient, the risk controllability of the current unsafe behavior in the current scenario is comprehensively assessed.
3. The method as described in claim 2, characterized in that, The controllability of the risks posed by the current unsafe behavior in the current scenario is assessed in the following ways: In the formula, To ensure that the risk of the r-th unsafe behavior is controllable in the t-th scenario, , and These are respectively the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient. , and These are the autonomous risk controllability level, the driver / passenger intervention controllability level, and the remote intervention controllability level, respectively, for the current unsafe behavior in the current scenario.
4. An evaluation device for the integrated safety and controllability of intelligent connected vehicles, used to implement the steps of the method described in any one of claims 1-3, characterized in that, The device includes: The modeling module is used to abstractly model the target system of intelligent connected vehicles, and analyze and confirm the security association system, human-machine interaction content set, and information flow chain of each remote intervention command related to the target system based on the abstract model. The determination module is used to determine the autonomous risk controllability gain coefficient, the human misuse coefficient of driver and passenger intervention, and the remote intervention controllability gain coefficient based on the information flow chain of the security association system, the interactive content set, and each remote intervention command, respectively. The assessment module is used to obtain a list of unsafe behaviors and to comprehensively assess the risk controllability of each unsafe behavior in the list in each corresponding scenario based on the autonomous risk controllability gain coefficient, the human misuse coefficient, and the remote intervention controllability gain coefficient.
5. A computer device, characterized in that, The computer device includes a memory and a processor. The memory is used to store computer programs, and the processor is used to execute the computer programs stored in the memory to implement the steps of the method according to any one of claims 1-3.
6. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the steps of the method described in any one of claims 1-3.
7. A computer program product, characterized in that, Includes a computer program, which, when executed by a processor, implements the steps of the method according to any one of claims 1-3.
Citation Information
Patent Citations
Vehicle function safety controllability grade evaluation method, device, equipment and medium
CN117422344A
Risk assessment method, system and equipment for intelligent network connection industrial control system and medium
CN117579388A