Vehicle functional safety analysis method, storage medium and computer program product

By simulating and evaluating lane keeping assist (LKA) failure scenarios, identifying target failure events, and developing functional safety control strategies, this approach addresses the issues of low scenario coverage and incomplete safety requirements in existing LKA safety analysis technologies, achieving more efficient and comprehensive safety analysis.

CN118953389BActive Publication Date: 2026-01-02CHINA FAW CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411194379.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-28
Publication Date
2026-01-02
Estimated Expiration
2044-08-28

AI Technical Summary

Technical Problem

The existing technology for lane keeping assist (LKA) has low coverage of safety hazard analysis scenarios and lacks universality. Furthermore, functional safety requirements are difficult to propose through positive analysis, resulting in incomplete safety strategies.

Method used

By acquiring information on failure scenarios associated with lane keeping assist, simulating multiple failure scenarios, identifying target failure events, conducting assessments to obtain event assessment results, and determining functional safety control strategies and allocating corresponding functional safety requirements based on the results.

Benefits of technology

It improves the safety analysis efficiency and effectiveness of lane keeping assist, ensures safety and robustness in diverse environments, and provides a more comprehensive safety strategy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118953389B_ABST
    Figure CN118953389B_ABST
Patent Text Reader

Abstract

The application discloses a vehicle functional safety analysis method, a storage medium and a computer program product. The method comprises the following steps: acquiring a plurality of failure scene information associated with a lane keeping assistance function; determining a target failure event based on the plurality of failure scene information; performing evaluation processing on the target failure event to obtain an event evaluation result; and determining a functional safety control strategy based on the event evaluation result. The application solves the technical problem of low analysis efficiency and poor analysis effect of the lane keeping assistance function safety analysis method provided in the related art.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of intelligent driving, in particular, to a vehicle functional safety analysis method, a storage medium and a computer program product. BACKGROUND

[0002] Lane Keeping Assist (LKA) is an important intelligent driving assistance function, which can help the driver to ensure the vehicle to drive straight in the lane at high speed. However, since LKA will intervene in the steering of the vehicle, which will affect the safety of the vehicle, it is important to analyze the functional safety hazard of LKA. However, the safety hazard analysis of LKA function in the related art is mostly based on the fixed highway scene, the scene coverage is low, and the hazard analysis lacks universality. In addition, the derivation of functional safety requirements often depends on the safety requirements of the camera, radar and other controllers, which makes it difficult to propose safety requirements through safety analysis and reasonable allocation.

[0003] At present, there is no effective solution to the above problems. SUMMARY

[0004] The embodiments of the present application provide a vehicle functional safety analysis method, a storage medium and a computer program product to at least solve the technical problems of low efficiency and poor analysis effect of the vehicle functional safety analysis method provided in the related art in analyzing the safety of the lane keeping assistance function.

[0005] According to an aspect of an embodiment of the present application, a vehicle functional safety analysis method is provided, comprising: obtaining a plurality of failure scene information associated with a lane keeping assistance function, wherein the plurality of failure scene information is used to simulate a plurality of functional failure scenes corresponding to the lane keeping assistance function; determining a target failure event based on the plurality of failure scene information, wherein the target failure event is used to determine the type of functional failure of a target vehicle in the driving process; performing evaluation processing on the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine the functional safety level corresponding to the lane keeping assistance function; determining a functional safety control strategy based on the event evaluation result, wherein the functional safety control strategy is used to allocate the functional safety requirements corresponding to the lane keeping assistance function.

[0006] Optionally, determining the target failure event based on the failure scene information comprises: performing scene analysis processing on the failure scene information to obtain a scene analysis result; performing classification processing based on the analysis result to obtain a failure classification result; and determining the target failure event according to the failure classification result.

[0007] Optionally, the target failure event includes an unexpected steering event and a control failure event of the target vehicle.

[0008] Optionally, the target failure event is evaluated to obtain an event evaluation result, including: obtaining a plurality of preset evaluation indexes, wherein the preset evaluation indexes are used to evaluate the target failure event from multiple dimensions; and evaluating the target failure event by using the plurality of preset evaluation indexes to obtain the event evaluation result.

[0009] Optionally, the plurality of preset evaluation indexes include: a first index, a second index, and a third index, wherein the first index is used to evaluate an event influence degree corresponding to the target failure event, the second index is used to evaluate an event occurrence probability corresponding to the target failure event, and the third index is used to evaluate a user controllable degree corresponding to the target failure event.

[0010] Optionally, determining the functional safety control strategy based on the event evaluation result includes: determining a functional safety target based on the event evaluation result; and determining the functional safety control strategy according to the functional safety target.

[0011] Optionally, determining the functional safety control strategy according to the functional safety target includes: obtaining system architecture information of the target vehicle; and distributing the functional safety requirements based on the system architecture information and the functional safety target to obtain the functional safety control strategy.

[0012] Optionally, the plurality of functional failure scenarios corresponding to the lane keeping assistance function include: an activation failure scenario, an inhibition failure scenario, an intervention failure scenario, and an intervention exit failure scenario.

[0013] According to one of the embodiments of the present application, a vehicle functional safety analysis device is also provided, including: an acquisition module configured to acquire failure scenario information associated with a lane keeping assistance function, wherein the failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function; a first determination module configured to determine a target failure event based on the failure scenario information, wherein the target failure event is used to determine a functional failure type of a target vehicle during driving; an evaluation module configured to evaluate the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine a functional safety level corresponding to the lane keeping assistance function; and a second determination module configured to determine a functional safety control strategy based on the event evaluation result, wherein the functional safety control strategy is used to distribute functional safety requirements corresponding to the lane keeping assistance function.

[0014] Optionally, the first determination module is further configured to: perform scenario analysis on the plurality of failure scenario information to obtain a scenario analysis result; perform classification processing based on the analysis result to obtain a failure classification result; and determine the target failure event according to the failure classification result.

[0015] Optionally, the target failure event includes: an unexpected turning event and a control failure event of the target vehicle.

[0016] Optionally, the evaluation module is further configured to: acquire a plurality of preset evaluation indexes, wherein the preset evaluation indexes are used to evaluate the target failure event from a plurality of dimensions; and perform evaluation processing on the target failure event by using the plurality of preset evaluation indexes to obtain an event evaluation result.

[0017] The plurality of preset evaluation indexes include: a first index, a second index, and a third index, the first index is used to evaluate an event influence degree corresponding to the target failure event, the second index is used to evaluate an event occurrence probability corresponding to the target failure event, and the third index is used to evaluate a user controllable degree corresponding to the target failure event.

[0018] Optionally, the second determination module is further configured to: determine a functional safety target based on the event evaluation result; and determine a functional safety control strategy according to the functional safety target.

[0019] Optionally, the second determination module is further configured to: acquire system architecture information of the target vehicle; and perform allocation processing on the functional safety requirement based on the system architecture information and the functional safety target to obtain the functional safety control strategy.

[0020] According to an embodiment of the present application, a non-volatile storage medium is also provided, and the storage medium stores a computer program, wherein the computer program is configured to execute the vehicle functional safety analysis method in the embodiments of the present application when running.

[0021] According to an embodiment of the present application, a computer program product is also provided, and the computer program product includes computer instructions, and the computer instructions are executed by a processor to implement the vehicle functional safety analysis method in the embodiments of the present application.

[0022] According to an embodiment of the present application, an electronic device is also provided, and the electronic device includes: a processor; and a memory configured to store processor-executable instructions; wherein the processor is configured to execute the instructions to implement the vehicle functional safety analysis method in the embodiments of the present application.

[0023] In the embodiments of the present application, by acquiring failure scenario information associated with the lane keeping assistance function, determining a target failure event based on the failure scenario information, performing evaluation processing on the target failure event to obtain an event evaluation result, and finally determining a functional safety control strategy based on the event evaluation result, the purpose of analyzing the safety of the vehicle function is achieved, thereby realizing the technical effect of improving the safety analysis efficiency and analysis effect of the lane keeping assistance function, and further solving the technical problems of low safety analysis efficiency and poor analysis effect of the lane keeping assistance function in the vehicle functional safety analysis method provided in the related art. BRIEF DESCRIPTION OF DRAWINGS

[0024] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:

[0025] Figure 1 is a schematic diagram of a vehicle functional safety analysis method according to an embodiment of the present application;

[0026] Figure 2 is a process schematic diagram of an event assessment method according to an embodiment of the present application;

[0027] Figure 3 is a process schematic diagram of a functional safety requirement allocation according to an embodiment of the present application;

[0028] Figure 4 is a structural block diagram of a vehicle functional safety analysis apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0029] In order to enable persons skilled in the art to better understand the schemes of the present application, the technical schemes in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative work should fall within the scope of protection of the present application.

[0030] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0031] The safety hazard analysis of LKA function in the related art is often limited to fixed scenes such as highways, and lacks comprehensive consideration of diversified environments such as urban roads and rural roads. In urban traffic, lane lines are usually not as clear as highways, and the types and behavior patterns of traffic participants are more complex and variable. On rural roads, lane lines may not be standardized, and road conditions are more diverse, resulting in low coverage of safety hazard analysis scenes and insufficient universality of safety evaluation. In addition, the functional safety requirements are derived by reverse engineering from the safety requirements of existing sensors such as cameras and radars, ignoring the specific safety risks that LKA as a whole may face in different scenarios. For example, errors or failures of sensors may cause LKA to make incorrect lane judgments, and even slight lane deviations on highways may quickly escalate, causing serious consequences. On urban roads, LKA needs to cope with more dynamic obstacles and non-standard traffic behaviors, thereby placing higher requirements on the robustness and intelligence of LKA. Therefore, relying solely on reverse engineering to determine safety requirements may not fully capture the safety requirements of LKA, thereby failing to specify corresponding safety strategies based on safety requirements.

[0032] According to an embodiment of the present application, a method for analyzing the functional safety of a vehicle is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.

[0033] The method embodiments can be executed in an electronic device or similar computing device comprising a memory and a processor. Taking a computer terminal as an example, the computer terminal can include one or more processors (the processor can include, but is not limited to, a processing device such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Digital Signal Processing (DSP) chip, a Micro Controller Unit (MCU), a Field Programmable Gate Array (FPGA), a Neural-network Processor Unit (NPU), a Tensor Processing Unit (TPU), an Artificial Intelligence (AI) type processor, etc.) and a memory for storing data. Optionally, the above computer terminal can also include a transmission device for communication function, an input and output device, and a display device. Those skilled in the art can understand that the above structural description is only illustrative, and does not limit the structure of the above computer terminal. For example, the computer terminal can include more or less components than the above structural description, or have a different configuration from the above structural description.

[0034] The memory can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the vehicle functional safety analysis method in the embodiments of the present application. The processor executes various functional applications and data processing by running the computer program stored in the memory, that is, implements the vehicle functional safety analysis method described above. The memory can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory can further include a memory remotely arranged with respect to the processor, which can be connected to the mobile terminal through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0035] The transmission device is configured to receive or transmit data via a network. The network can include, for example, a wireless network provided by a mobile terminal's communication provider. In one example, the transmission device includes a network interface controller (NIC) that can connect to other network devices through a base station to communicate with the Internet. In one example, the transmission device can be a radio frequency (RF) module that is configured to communicate with the Internet via wireless means.

[0036] The display device can be, for example, a touch screen type liquid crystal display (LCD) and a touch display (also referred to as a "touch screen" or "touch display screen"). The liquid crystal display can enable a user to interact with a user interface of the mobile terminal. In some embodiments, the mobile terminal has a graphical user interface (GUI) with which a user can interact with the GUI through finger contacts and / or gestures on the touch-sensitive surface, where the human-machine interaction functions can optionally include creating web pages, drawing, word processing, creating electronic documents, playing games, video conferencing, instant messaging, sending / receiving e-mail, call interfaces, playing digital video, playing digital music, and / or web browsing, etc., executable instructions for performing the above human-machine interaction functions are configured / stored in one or more computer program products or readable storage media executable by the processor.

[0037] Figure 1 A vehicle functional safety analysis method according to an embodiment of the present application is shown in FIG. 11, which includes the following steps: Figure 1

[0038] In step S11, failure scenario information associated with the lane keeping assistance function is obtained, wherein the failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function.

[0039] In step S12, a target failure event is determined based on the failure scenario information, wherein the target failure event is used to determine the functional failure type of the target vehicle during driving.

[0040] In step S13, the target failure event is evaluated to obtain an event evaluation result, wherein the event evaluation result is used to determine the functional safety level of the lane keeping assistance function.

[0041] In step S14, a functional safety control strategy is determined based on the event evaluation result, wherein the functional safety control strategy is used to allocate the functional safety requirements corresponding to the lane keeping assistance function.

[0042] ​The above failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function, and thus can reflect the association between the lane keeping assistance function and the plurality of functional failure scenarios. By simulating a plurality of functional failure scenarios corresponding to the lane keeping assistance function, potential risks in various failure scenarios can be systematically identified and evaluated, thereby providing a basis for formulating corresponding safety measures and improvement schemes.

[0043] The above target failure event is used to determine the type of functional failure of the target vehicle during driving, and thus can reflect the possible impact of the type of functional failure on the safe operation of the vehicle. Any type of functional failure can cause the vehicle to be unable to travel in the expected manner, thereby affecting the safe operation of the vehicle to varying degrees.

[0044] The above event evaluation result is used to determine the functional safety level corresponding to the lane keeping assistance function, which includes but is not limited to the Automotive Safety Integrity Level (ASIL). ASIL is a level standard used to evaluate the importance of safety-related systems or components in automotive systems. The ISO 26262 standard defines four different ASIL levels: A, B, C, and D, wherein: ASIL A: the lowest level, indicating that the risk of this function is minimal; ASIL B: a higher level, indicating that the risk of this function is slightly higher; ASIL C: a higher level, indicating that the risk of this function is significantly increased; ASIL D: the highest level, indicating that the safety risk of this function is the highest.

[0045] The above functional safety control strategy is used to allocate the functional safety requirements corresponding to the lane keeping assistance function. Based on the event evaluation result, the functional safety control strategy is determined, thereby allocating the functional safety requirements, which helps to improve the overall safety performance of intelligent vehicles and provides drivers with a safer and more reliable driving assistance experience.

[0046] Exemplarily, the failure scenarios that the lane keeping assistance function may encounter are collected through the CAN bus data of the vehicle, sensor detection reports, and user feedback, and the collected failure scenario information is analyzed to determine the target failure event, and then the target failure event is risk evaluated to obtain the event evaluation result. Finally, based on the event evaluation result, the functional safety control strategy corresponding to the target failure event is determined, and the safety requirements are allocated.

[0047] Based on the steps S11 to S13, the failure scenario information associated with the lane keeping assistance function is obtained, the target failure event is determined based on the failure scenario information, the target failure event is evaluated, the event evaluation result is obtained, and finally the functional safety control strategy is determined based on the event evaluation result, thereby achieving the purpose of safety analysis of the vehicle function, improving the efficiency and effect of the lane keeping assistance function safety analysis, and solving the technical problems of low efficiency and poor effect of the lane keeping assistance function safety analysis provided by the related art.

[0048] The vehicle function safety analysis method in the embodiments of the present application is further introduced below.

[0049] Optionally, in step S12, the target failure event is determined based on the failure scenario information, including:

[0050] In step S121, the failure scenario information is analyzed and processed to obtain a scene analysis result.

[0051] In step S122, the analysis result is classified to obtain a failure classification result.

[0052] In step S123, the target failure event is determined according to the failure classification result.

[0053] The purpose of the above-mentioned scene analysis processing is to identify and analyze various situations and environments that the vehicle may encounter under the condition of a specific function failure. Through scene analysis processing, the performance of the lane keeping assistance function under various conditions can be better understood, thereby providing support for formulating effective functional safety control strategies, and helping to improve the safety of the vehicle and reduce potential risks caused by function failure.

[0054] The purpose of the above-mentioned classification processing is to simplify the complex and diverse failure scenarios into several typical failure modes that are easy to understand and representative, so as to facilitate subsequent evaluation and processing. Through classification processing based on the classification result, the failure classification result is obtained, which can improve the efficiency of failure analysis and enhance the pertinence and effectiveness of processing failure problems.

[0055] Specifically, by identifying and analyzing various situations and environments that the vehicle may encounter under the condition of a specific function failure, the scene analysis result is obtained. Further, the complex and diverse failure scenarios are simplified into several typical failure modes that are easy to understand and representative, and the failure classification result is obtained. Finally, the target failure event is determined according to the failure classification result.

[0056] Exemplarily, in the process of determining the target failure event based on the failure scenario information, first, various failure scenarios that the system may encounter need to be comprehensively collected and sorted, and then the failure scenarios are classified according to the influence of the failure scenarios on the performance and safety of the system, so as to determine the severity thereof. For example, the failure scenarios can be divided into three levels of low risk, medium risk and high risk, wherein the high-risk failure scenario may have a serious impact on the safety of the driver and passengers, and therefore the high-risk failure event needs to be analyzed and evaluated as the target failure event. After the target failure event is determined, the failure cause, failure mode and failure impact of the target failure event can be further analyzed in detail, so as to better understand the risk characteristics of the system.

[0057] Based on the above optional embodiments, by performing scene analysis processing on the failure scenario information to obtain a scene analysis result, and performing classification processing based on the analysis result to obtain a failure classification result, and determining the target failure event according to the failure classification result, the rapid identification and response of the failure event can be realized, thereby improving the safety and reliability of the system.

[0058] Optionally, in step S123, the target failure event includes an unexpected steering event and a control failure event of the target vehicle.

[0059] The above unexpected steering event generally refers to a steering behavior of the vehicle that is not intended by the driver during the driving process of the vehicle due to a fault of the control system of the vehicle itself or interference of external factors. In an automatic driving or assisted driving system, unexpected steering can be caused by various reasons, such as sensor failure, actuator failure and communication interference. The unexpected steering event can cause the vehicle to collide, thereby seriously affecting the safety of the vehicle, passengers and other road users.

[0060] The above control failure event generally refers to a situation in which the driver loses or is limited in the ability to control the vehicle during the operation of the vehicle due to some reason, and thus cannot control the driving state of the vehicle in the expected manner. Failure of key components such as steering system, braking system and power transmission system can all lead to the occurrence of control failure event. Failure of the steering system can cause the vehicle to be unable to steer as intended by the driver, failure of the braking system can cause the vehicle to be unable to stop or decelerate within the expected distance, and failure of the power transmission system can affect the acceleration performance or driving function of the vehicle. The occurrence of the control failure event not only threatens the safety of the driver, but also poses potential risks to the safety of passengers, pedestrians and other road users.

[0061] Optionally, in step S13, the target failure event is evaluated to obtain an event evaluation result, which includes:

[0062] In step S131, a plurality of preset evaluation indexes are obtained, wherein the preset evaluation indexes are used to evaluate the risk level of the target failure event from multiple dimensions.

[0063] In step S132, the target failure event is evaluated by using the plurality of preset evaluation indexes to obtain an event evaluation result.

[0064] The preset evaluation indexes are used to evaluate the risk level of the target failure event from multiple dimensions. By comprehensively considering various risks and consequences that the target failure event may cause in actual application, and based on the preset evaluation indexes from multiple dimensions, the target failure event is deeply analyzed and evaluated. By obtaining the preset evaluation indexes, a solid basis is provided for determining the risk level of the target failure event, which helps to identify and strengthen the potential safety weak links, thereby improving the safety and reliability of the entire system.

[0065] Based on the above optional embodiment, by obtaining a plurality of preset evaluation indexes and evaluating the target failure event by using the plurality of preset evaluation indexes to obtain an event evaluation result, strong support and guarantee can be provided for the risk management and control of the target failure event, thereby helping to improve the stability and safety of the system.

[0066] Optionally, in step S131, the plurality of preset evaluation indexes include a first index, a second index, and a third index, wherein the first index is used to evaluate the event impact degree corresponding to the target failure event, the second index is used to evaluate the event occurrence probability corresponding to the target failure event, and the third index is used to evaluate the user controllability corresponding to the target failure event.

[0067] The first index is used to evaluate the severity (S) corresponding to the target failure event, that is, to evaluate the maximum damage range and severity that may be caused when the target failure event occurs. By quantifying the impact degree of the target failure event on personnel safety, property loss, and environmental impact, etc., a basis is provided for first identifying and processing high-impact events.

[0068] The second index is used to evaluate the exposure (E) corresponding to the target failure event, that is, to evaluate the probability of occurrence of the target failure event. By analyzing historical data, failure modes, environmental conditions, and system reliability, etc., the frequency of event occurrence is predicted and estimated, which can determine the probability of occurrence of the target failure event, and helps to allocate resources and control risks for the target failure event with the highest occurrence probability in priority.

[0069] The third index is used to evaluate the controllability (C) corresponding to the target failure event, that is, to evaluate the control ability and intervention effect of the driver on the target failure event when the target failure event occurs. By measuring the ability of the user to improve or alleviate the hazard event through self-operation when facing the target failure event, including but not limited to the reaction time to the failure warning and the effectiveness of the treatment measures. The controllability of the user directly affects the design and implementation of the risk mitigation strategy.

[0070] Figure 2 is a process schematic diagram of an event evaluation method according to an embodiment of the present application, as Figure 2 shown, an event evaluation method with three dimensions of severity, exposure and controllability is constructed, and two target failure events of unexpected steering and driver uncontrollability are evaluated.

[0071] Exemplarily, the functional safety level of the evaluated target failure event is represented by the combination of the three letters S, E and C and numbers, and the larger the number is, the higher the functional safety level is. The unexpected steering and driver uncontrollability caused by LKA failure will cause vehicle collision and other serious hazards, so S3; LKA function is mostly started in highway scene, but unexpected start and driver uncontrollability after unexpected start of the hazard event may not only occur in highway, but also cover multiple scenes, so the exposure is high, E4; the unexpected steering and driver uncontrollability caused by LKA failure will cause the driver to be unable to put the vehicle into a safe state, so the controllability is low, C3. The unexpected steering and driver uncontrollability caused by LKA failure are evaluated as S3, E4 and C3, and the functional safety level is ASIL D.

[0072] Based on the above optional embodiment, by presetting the evaluation indexes to evaluate the event influence degree, event occurrence probability and user controllability, the danger of the target failure event can be accurately quantitatively analyzed, and the specific influence and possibility of each failure event can be analyzed in depth, so that the influence of the failure event on the overall safety performance of the vehicle can be more accurately determined, thereby providing an important reference for formulating effective safety measures and optimizing vehicle design.

[0073] Optionally, in step S14, determining the functional safety control strategy based on the event evaluation result comprises:

[0074] Step S141, determining the functional safety target based on the event evaluation result;

[0075] Step S142, determining the functional safety control strategy according to the functional safety target.

[0076] The core of the above functional safety target includes avoiding unintended steering and avoiding the occurrence of control failure events. Unintended steering generally refers to the steering behavior of the vehicle opposite to the driver's intention due to system functional abnormalities, and control failure may involve the system's inability to respond to the driver's control instructions or inability to provide necessary steering assistance.

[0077] Illustratively, in order to avoid the occurrence of unintended steering and control failure events, it is necessary to comprehensively analyze and identify various failure modes and scenarios that may affect functional safety from the LKA function specification, define and evaluate the target failure events for each failure mode, and determine the functional safety target according to the event evaluation results.

[0078] Illustratively, after determining the target failure events, the target failure events are comprehensively evaluated by the event evaluation method, and the functional safety target of avoiding unintended steering or control failure is determined according to the evaluation results, so as to determine the functional safety control strategy according to the specific functional safety target.

[0079] Based on the above optional embodiment, the functional safety target is determined by the event evaluation result, and the functional safety control strategy is determined according to the functional safety target, so as to ensure that unintended steering is avoided when the function fails, or the driver can maintain effective control of the vehicle in any case.

[0080] Optionally, in step S142, determining the functional safety control strategy according to the functional safety target comprises:

[0081] Step S1421, acquiring system architecture information of the target vehicle;

[0082] Step S1422, distributing and processing the functional safety requirements based on the system architecture information and the functional safety target to obtain the functional safety control strategy.

[0083] The system architecture information of the target vehicle includes three parts: perception layer, decision layer and execution layer. By referring to the system architecture, the automobile parts participating in the LKA function are uniformly divided into perception layer, decision layer and execution layer. The perception layer is mainly responsible for collecting and processing external environmental information of the vehicle driving state, such as monitoring the surrounding traffic conditions and road information in real time through cameras, radars and other sensors; the decision layer is mainly responsible for receiving data from the perception layer, combining with the vehicle's internal control logic and algorithm, making quick and accurate judgments and decisions, and generating corresponding control instructions to ensure safe driving of the vehicle under various complex traffic conditions; the execution layer directly responds to the instructions of the decision layer, and controls the steering, acceleration and braking of the vehicle execution mechanism to realize precise control of the vehicle.

[0084] Figure 3is a process diagram of functional safety requirement allocation according to an embodiment of the present application, as shown in Figure 3 As shown, the functional safety requirement allocation refers to allocation and processing of the functional safety requirement based on the system architecture information and the functional safety target.

[0085] For example, the allocation and processing of the functional safety requirement based on the system architecture information and the functional safety target obtains the functional safety control strategy. The safety requirement corresponding to the perception layer includes but is not limited to that the radar should correctly identify the front obstacle information, the camera should correctly identify the front vehicle or pedestrian, and the accelerator pedal or steering wheel should correctly receive the signal; the safety requirement corresponding to the decision layer includes but is not limited to that the LKA should correctly calculate the deviation direction, the output torque should not exceed the functional limit interval, and the LKA function should be turned off in the case of its own functional failure; and the safety requirement corresponding to the control layer includes but is not limited to that the control steering system should correctly output the torque request, the LKA function output should be shielded when the driver's operation request is received, and the LKA function should be turned off in the case of steering functional failure.

[0086] For example, in the case that the functional safety target is to avoid outputting unexpected steering, the safety requirement is allocated to the perception layer and the control layer. The perception layer controls the radar and the camera to correctly identify the front obstacle information, and the accelerator pedal or the steering wheel to correctly receive the signal; and the control layer controls the steering system to correctly output the torque request, and shields the LKA function output when the driver's operation request is received, and turns off the LKA function in the case of steering functional failure.

[0087] For example, in the case that the functional safety target is to avoid the driver's inability to operate, the safety requirement is allocated to the decision layer and the control layer. The decision layer controls the LKA to correctly calculate the deviation direction and limits the output torque within its functional limit interval, and turns off the LKA function in the case of its own functional failure; and the control layer controls the steering system to correctly output the torque request, and shields the LKA function output when the driver's operation request is received, and turns off the LKA function in the case of steering functional failure.

[0088] It should be noted that the safety requirement is allocated based on the function of different components, such as the safety target of avoiding unexpected steering. Since the control layer can ensure that no unexpected torque is output when the function is not turned on, and the functional safety level of the control layer in the system is higher, the requirement is allocated to the perception layer and the control layer, and no requirement is allocated to the decision layer, so as to promote the implementation of the functional safety requirement.

[0089] Based on the above optional embodiment, by acquiring the perception layer, decision layer and execution layer of the target vehicle, and based on the perception layer, decision layer, execution layer and avoiding output unexpected steering, avoiding the functional safety target that the driver cannot control, the functional safety demand is allocated and processed, and the functional safety control strategy is obtained. Not only ensures that the functional safety demand is fully covered, but also can respond to various complex traffic environments and sudden conditions in time, so as to propose safety requirements through safety analysis and reasonable allocation.

[0090] Optionally, in step S11, the plurality of function failure scenarios corresponding to the lane keeping assistance function include: activation failure scenario, inhibition failure scenario, intervention failure scenario and intervention exit failure scenario.

[0091] The above-mentioned activation failure scenario, that is, LKA function activation, refers to automatically starting when the vehicle is driving at a high speed and detecting that it may deviate from the current lane, thereby providing steering support or intervention to the driver to help the vehicle stay in the center of the lane or the preset position;

[0092] The above-mentioned inhibition failure scenario, that is, LKA function inhibition, refers to the case where the lane keeping assistance system is not suitable or does not need to intervene, and the system can automatically stop its auxiliary function to avoid unnecessary interference or potential danger to the driver, and ensure the flexibility and safety of driving;

[0093] The above-mentioned intervention failure scenario, that is, LKA function intervention, refers to that when the vehicle is driving and it is identified that it will deviate from the current lane, the system will automatically make a slight steering intervention to help the driver maintain the vehicle in the center of the lane;

[0094] The above-mentioned intervention exit failure scenario, that is, LKA function intervention exit, refers to that during the driving of the vehicle, the system automatically detects the lane line and assists the driver to keep the vehicle driving in the predetermined lane, when it is detected that the driver intentionally changes lane or the vehicle is about to deviate from the lane, the system will intervene in time to prevent lane deviation, or after the driver actively operates the turn signal, the system exits the auxiliary control and allows the vehicle to change lane according to the intention of the driver, ensuring the safety and stability of the vehicle driving.

[0095] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software on a general hardware platform as necessary, and of course can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product in essence or in the form of a part that contributes to the prior art, and the computer software product is stored in a storage medium (such as a ROM / RAM, a magnetic disk, or an optical disk), and includes a plurality of instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device) to execute the method described in each embodiment of the present application.

[0096] In the embodiments of the present application, a vehicle functional safety analysis device is also provided, which is used to implement the above embodiments and preferred embodiments, and will not be described again. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware is also possible and is contemplated.

[0097] Figure 4 is a structural block diagram of a vehicle functional safety analysis device according to one of the embodiments of the present application, as shown in Figure 4 , the device comprises:

[0098] The acquisition module 401 is configured to acquire failure scenario information associated with the lane keeping assistance function, wherein the failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function.

[0099] The first determination module 402 is configured to determine a target failure event based on the failure scenario information, wherein the target failure event is used to determine the type of functional failure of the target vehicle during driving.

[0100] The evaluation module 403 is configured to perform evaluation processing on the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine the functional safety level corresponding to the lane keeping assistance function.

[0101] The second determination module 404 is configured to determine a functional safety control strategy based on the event evaluation result, wherein the functional safety control strategy is used to allocate the functional safety requirements corresponding to the lane keeping assistance function.

[0102] Optionally, the first determination module 402 is further configured to: perform scene analysis processing on the plurality of failure scenario information to obtain a scene analysis result; perform classification processing based on the analysis result to obtain a failure classification result; and determine the target failure event according to the failure classification result.

[0103] The target failure event includes an unexpected steering event and a control failure event of the target vehicle.

[0104] Optionally, the evaluation module 403 is further configured to: obtain a plurality of preset evaluation indexes, wherein the preset evaluation indexes are used to evaluate the target failure event from multiple dimensions; and perform evaluation processing on the target failure event by using the plurality of preset evaluation indexes to obtain an event evaluation result.

[0105] The plurality of preset evaluation indexes include a first index, a second index, and a third index, the first index is used to evaluate an event influence degree corresponding to the target failure event, the second index is used to evaluate an event occurrence probability corresponding to the target failure event, and the third index is used to evaluate a user controllable degree corresponding to the target failure event.

[0106] Optionally, the second determination module 404 is further configured to: determine a functional safety target based on the event evaluation result; and determine a functional safety control strategy according to the functional safety target.

[0107] Optionally, the second determination module 404 is further configured to: obtain system architecture information of the target vehicle; and perform allocation processing on a functional safety requirement based on the system architecture information and the functional safety target to obtain the functional safety control strategy.

[0108] It should be noted that the above modules can be implemented by software or hardware, and for the latter, the following implementation manners can be used, but are not limited thereto: the above modules are located in the same processor; or the above modules are located in different processors in any combination.

[0109] According to another aspect of the embodiment of the present application, a computer readable storage medium is also provided, which includes a stored executable program, wherein when the executable program is executed, the device where the storage medium is located performs the vehicle functional safety analysis method described above.

[0110] Optionally, in the embodiment, the above storage medium can be configured to store a computer program for performing the following steps:

[0111] S1, obtain failure scenario information associated with a lane keeping assistance function, wherein the failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function;

[0112] S2, determine a target failure event based on the failure scenario information, wherein the target failure event is used to determine a functional failure type of a target vehicle in a driving process;

[0113] S3, perform evaluation processing on the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine a functional safety level of the lane keeping assistance function.

[0114] S4, determining a functional safety control strategy based on the event evaluation result, wherein the functional safety control strategy is used to allocate a functional safety requirement corresponding to the lane keeping assistance function.

[0115] Optionally, in the embodiment, the storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various computer program storage media.

[0116] According to another aspect of the embodiment of the present application, an electronic device is also provided, which includes a memory storing an executable program, and a processor configured to run the program, wherein the program, when running, performs the vehicle functional safety analysis method.

[0117] Optionally, in the embodiment, the processor can be configured to perform the following steps by using the computer program.

[0118] S1, obtaining failure scenario information associated with the lane keeping assistance function, wherein the failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function;

[0119] S2, determining a target failure event based on the failure scenario information, wherein the target failure event is used to determine a functional failure type of a target vehicle in a driving process;

[0120] S3, performing evaluation processing on the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine a functional safety level corresponding to the lane keeping assistance function;

[0121] S4, determining a functional safety control strategy based on the event evaluation result, wherein the functional safety control strategy is used to allocate a functional safety requirement corresponding to the lane keeping assistance function.

[0122] According to another aspect of the embodiment of the present application, a computer program product is also provided, which includes a computer program, and the computer program, when executed by a processor, implements the vehicle functional safety analysis method.

[0123] Optionally, in the embodiment, the computer program product can be a computer program configured to perform the following steps:

[0124] S1, obtaining failure scenario information associated with the lane keeping assistance function, wherein the failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function;

[0125] S2, determine a target failure event based on the failure scenario information, wherein the target failure event is used to determine a functional failure type of the target vehicle in the driving process;

[0126] S3, perform evaluation processing on the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine a functional safety level corresponding to the lane keeping assistance function;

[0127] S4, determine a functional safety control strategy based on the event evaluation result, wherein the functional safety control strategy is used to allocate a functional safety requirement corresponding to the lane keeping assistance function.

[0128] In the above embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0129] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of the units can be a logical function division, and actual implementation can have another division way, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or modules shown or discussed can be indirect coupling or communication connection through some interfaces, units or modules, which can be electrical or other forms.

[0130] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment scheme.

[0131] In addition, each functional unit in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0132] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0133] The above is only the preferred embodiment of the present application, and it should be pointed out that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should be considered as the protection scope of the present application.

Claims

1. A method of functional safety analysis of a vehicle, characterized in that, The method comprises the following steps: obtaining a plurality of failure scenario information associated with a lane keeping assistance function, wherein the plurality of failure scenario information is used to simulate a plurality of functional failure scenarios corresponding to the lane keeping assistance function; determining a target failure event based on the plurality of failure scenario information, wherein the target failure event is used to determine the type of functional failure of the target vehicle during driving; evaluating the target failure event to obtain an event evaluation result, wherein the event evaluation result is used to determine the functional safety level corresponding to the lane keeping assistance function; determining a functional safety target based on the event evaluation result; obtaining system architecture information of the target vehicle, wherein the system architecture information comprises a perception layer, a decision layer and a control layer, the safety requirements corresponding to the perception layer include correct identification of front obstacle information by radar, correct identification of front vehicle or pedestrian by camera, and correct signal reception by accelerator pedal or steering wheel; the safety requirements corresponding to the decision layer include correct calculation of deviation direction by the lane keeping assistance function, output torque not exceeding the functional limit interval, and shutting down the lane keeping assistance function in case of self-functional failure; the safety requirements corresponding to the control layer include correct output torque request by the control steering system, shielding the lane keeping assistance function output when receiving the driver's operation request, and shutting down the lane keeping assistance function in case of steering function failure; distributing the functional safety requirements corresponding to the lane keeping assistance function based on the system architecture information and the functional safety target to obtain a functional safety control strategy, wherein when the functional safety target is to avoid non-expected steering, the functional safety requirements are distributed to the perception layer and the control layer, and when the functional safety target is to avoid the driver's inability to operate, the functional safety requirements are distributed to the decision layer and the control layer.

2. The vehicle functional safety analysis method according to claim 1, characterized in that, Determining the target failure event based on the plurality of failure scenario information comprises: performing scene analysis on the plurality of failure scenario information to obtain a scene analysis result; performing classification processing based on the analysis result to obtain a failure classification result; determining the target failure event according to the failure classification result.

3. The vehicle functional safety analysis method according to claim 2, characterized in that, The target failure event includes a non-expected steering event and a control failure event of the target vehicle.

4. The vehicle functional safety analysis method according to claim 1, characterized by, The evaluation processing of the target failure event to obtain the event evaluation result comprises: obtaining a plurality of preset evaluation indexes, wherein the preset evaluation indexes are used to evaluate the risk level of the target failure event from multiple dimensions; using the plurality of preset evaluation indexes to evaluate the target failure event to obtain the event evaluation result.

5. The vehicle functional safety analysis method according to claim 4, characterized by, The plurality of preset evaluation indexes include a first index, a second index and a third index, wherein the first index is used to evaluate the event influence degree corresponding to the target failure event, the second index is used to evaluate the event occurrence probability corresponding to the target failure event, and the third index is used to evaluate the user controllability corresponding to the target failure event.

6. A non-volatile storage medium, comprising: The storage medium stores a computer program, wherein the computer program is configured to execute the vehicle functional safety analysis method described in any one of claims 1 to 5 when running.

7. A computer program product, characterised in that, The computer program product comprises computer instructions which, when executed by a processor, implement the vehicle functional safety analysis method as claimed in any one of claims 1 to 5.

8. An electronic device, comprising: Comprise: a processor; a memory for storing instructions executable by the processor; wherein the processor is configured to execute the instructions to implement the vehicle functional safety analysis method as claimed in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Intelligent vehicle VS-LKA system function safety concept analysis method

    CN111400823A

  • Data processing method and device of lane keeping assistance system, and storage medium

    CN115408021A