Method, device and processor for determining functional safety requirements in a vehicle control system
By identifying abnormal control behaviors and their consequences in the vehicle control system, establishing linkages, and determining functional defects, the problem of inaccurate expected functional safety requirements in the vehicle control system is solved, thereby achieving system safety and reliability.
Patent Information
- Application Number
- CN202411296265.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-14
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2044-09-14
AI Technical Summary
The lack of clear and quantitative methods in the existing technology to determine the expected functional safety requirements of vehicle control systems leads to inaccurate functional safety requirements and potential risks and vulnerabilities.
By acquiring the control element set, output information set, and control behavior set of the vehicle control system, abnormal control behaviors and their results are identified, link relationships are established, functional defects are determined, and expected functional safety requirements are determined based on this.
This enables the effective identification of expected functional safety requirements in vehicle control systems, resulting in a comprehensive and unified requirements analysis, reducing system risks, and ensuring system safety and reliability.
Smart Images

Figure CN119078863B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicles, and in particular, to a method and device for determining safety requirements of intended functionality in a vehicle control system and a processor. BACKGROUND
[0002] At present, intelligent driving, as an innovative technology, brings the vehicle industry into a new era. It not only provides a more convenient transportation mode, but also improves traffic safety and efficiency. However, due to the limitation of the current scientific and technological level, the vehicle control system for intelligent driving, such as the intelligent driving system, still has some potential risks and challenges. Therefore, how to determine the safety requirements of intended functionality (SOTIF) of the vehicle control system is crucial to ensure the stable and reliable operation of the vehicle control system.
[0003] In the related art, due to the lack of clear and quantitative analysis, design, testing, and evaluation methods and indicators for analyzing the SOTIF requirements of the vehicle control system, there is a lack of perfect and unified requirement analysis, which makes the determined safety requirements of the functionality inaccurate, thereby there are potential risks and vulnerabilities in the design and implementation process of the vehicle control system. Therefore, there is still a technical problem that the safety requirements of intended functionality in the vehicle control system cannot be effectively determined.
[0004] In view of the above technical problem that the safety requirements of intended functionality in the vehicle control system cannot be effectively determined, no effective solution has been proposed so far. SUMMARY
[0005] The embodiments of the present application provide a method and device for determining safety requirements of intended functionality in a vehicle control system and a processor to at least solve the technical problem that the safety requirements of intended functionality in the vehicle control system cannot be effectively determined.
[0006] According to an aspect of an embodiment of the present application, a method for determining expected functional safety requirements in a vehicle control system is provided. The method can include: obtaining a control element set of a vehicle control system of a vehicle, and an output information set and a control behavior set corresponding to the control element set, wherein the control element set includes at least one control element, the output information set includes at least one output information, the output information is obtained by controlling the control element, and the control behavior set includes at least one control behavior, the control behavior is a behavior issued by the vehicle control system and used for controlling the control element to perform; determining at least one abnormal control behavior corresponding to at least one control behavior in the control behavior set, and determining at least one abnormal behavior result associated with the at least one abnormal control behavior, wherein the abnormal behavior result is used to represent an abnormal influence on the vehicle caused by performing the abnormal control behavior; linking a relationship between the control element set, the output information set, the control behavior set, the abnormal control behavior, and the abnormal behavior result to obtain a linking result; determining a functional defect result set corresponding to the control element set based on the linking result, wherein the functional defect result set includes at least one functional defect result, and the functional defect result is used to represent a functional defect existing in a corresponding control element in the control element set; and determining expected functional safety requirements of the vehicle control system based on the linking result and the functional defect result set, wherein the expected functional safety requirements are used to represent a strategy to be performed to overcome the functional defect.
[0007] Optionally, obtaining the output information set corresponding to the control element set includes: obtaining input information of at least one control element in the control element set; determining output information corresponding to the at least one control element based on the input information and the corresponding control element; and obtaining the output information set based on the output information corresponding to the at least one control element in the control element set.
[0008] Optionally, determining the at least one abnormal control behavior corresponding to the at least one control behavior in the control behavior set includes: applying a keyword to the at least one control behavior in the control behavior set to obtain the corresponding abnormal control behavior, wherein the keyword is used to identify a problem existing when the control behavior is performed.
[0009] Optionally, the keyword includes at least one of the following: a first keyword, a second keyword, a third keyword, a fourth keyword, a fifth keyword, and a sixth keyword, wherein the first keyword is used to represent that the control behavior is not performed in a case where the control behavior needs to be performed, the second keyword is used to represent that a time of performing the control behavior exceeds a time range threshold, the third keyword is used to represent that a degree of performing the control behavior exceeds a degree range threshold, the fourth keyword is used to represent that a direction of performing the control behavior is abnormal, the fifth keyword is used to represent that a time of ending the control behavior is earlier than a target time and / or a time length of performing the control behavior exceeds a time length threshold, and the sixth keyword is used to represent that the control behavior is performed in a case where the control behavior does not need to be performed.
[0010] Optionally, the linking result is a linking relationship table, wherein, the relationships among the control element set, the output information set, the control action set, the abnormal control action, and the abnormal behavior result are linked to obtain the linking result, including: detecting at least one output information in the output information set and at least one control action in the control action set to obtain a detection result, wherein the detection result is used to indicate whether the output information can affect the corresponding control action; and based on the control element set, the output information set, the control action set, the abnormal control action, the abnormal behavior result, and the detection result, obtaining the linking relationship table.
[0011] Optionally, based on the linking result, the function defect result set corresponding to the control element set is determined, including: obtaining type information of at least one control element in the control element set in the linking result; based on the type information, determining a defect analysis dimension corresponding to the at least one control element and defect analysis information under the defect analysis dimension; determining a corresponding function defect information set and a trigger condition set under the defect analysis information; and linking the relationship between the function defect information set and the trigger condition set to obtain the function defect result set.
[0012] Optionally, the defect analysis dimension includes a first defect analysis dimension and a second defect analysis dimension, the first defect analysis dimension is a defect analysis dimension common to control elements, and the second defect analysis dimension is a defect analysis dimension unique to different control elements, wherein, based on the type information, the defect analysis dimension corresponding to the at least one control element and the defect analysis information under the defect analysis dimension are determined, including: in response to the type information being a sensor type, determining that the first defect analysis dimension includes at least one of the following: installation position of the control element, vibration condition of the control element, temperature condition of the control element, and aging degree of the control element; and in response to the type information being an algorithm type, determining that the first defect analysis dimension includes at least one of the following: model robustness of the control element and model generalization of the control element.
[0013] Optionally, the types of the trigger conditions in the trigger condition set include at least one of the following: a disturbance condition of the control element, a disturbance condition of an environment in which the vehicle is located, a disturbance condition of the vehicle control, and a misuse condition of a target object in the vehicle.
[0014] Optionally, before determining the expected functional safety requirement of the vehicle control system based on the linking result and the function defect result set, the method further includes: linking the relationship between the linking result and the function defect result set to obtain a target linking result; and determining an association attribute between the abnormal behavior result and the defect information set and the trigger condition set from the target linking result, wherein the association attribute is used to indicate the association degree between the abnormal behavior result and the defect information set and the trigger condition set.
[0015] Optionally, determining the expected functional safety requirement of the vehicle control system based on the linkage result and the functional defect result set comprises: determining the expected functional safety requirement based on the target linkage result and the associated attribute.
[0016] According to another aspect of the embodiments of the present application, a device for determining an expected functional safety requirement in a vehicle control system is further provided. The device can include: an obtaining unit configured to obtain a control element set of a vehicle control system of a vehicle, and an output information set and a control action set corresponding to the control element set, wherein the control element set includes at least one control element, the output information set includes at least one output information, the output information is obtained by controlling the control element, and the control action set includes at least one control action, the control action is an action issued by the vehicle control system and used to control the control element to execute; a first determining unit configured to determine at least one abnormal control action corresponding to at least one control action in the control action set, and determine at least one abnormal behavior result associated with the at least one abnormal control action, wherein the abnormal behavior result is used to represent an abnormal influence on the vehicle caused by executing the abnormal control action; a linkage unit configured to link relationships among the control element set, the output information set, the control action set, the abnormal control action, and the abnormal behavior result to obtain a linkage result; a second determining unit configured to determine a functional defect result set corresponding to the control element set based on the linkage result, wherein the functional defect result set includes at least one functional defect result, and the functional defect result is used to represent a functional defect existing in the control element corresponding to the control element set; and a third determining unit configured to determine an expected functional safety requirement of the vehicle control system based on the linkage result and the functional defect result set, wherein the expected functional safety requirement is used to represent a strategy to be executed to overcome the functional defect.
[0017] According to another aspect of the embodiments of the present application, a computer readable storage medium is further provided. The computer readable storage medium includes a stored program, wherein the program, when executed, controls a device in which the computer readable storage medium is located to perform the method for determining an expected functional safety requirement in a vehicle control system according to the embodiments of the present application.
[0018] According to another aspect of the embodiments of the present application, a processor is further provided. The processor is used to execute a program, wherein the program, when executed, performs the method for determining an expected functional safety requirement in a vehicle control system according to the embodiments of the present application.
[0019] According to another aspect of the embodiments of the present application, a computer program product is further provided. The computer program product includes a computer program, and the computer program, when executed by a processor, implements the method for determining an expected functional safety requirement in a vehicle control system according to the embodiments of the present application.
[0020] In the embodiment of the present application, if it is necessary to determine the expected functional safety requirement of the vehicle control system, the set of control elements and the set of output information in the vehicle control system can be determined, and the corresponding set of control behaviors can be sorted out. Each control behavior in the set of control behaviors is analyzed to determine the risk implied therein, and the corresponding abnormal control behavior is obtained. The abnormal behavior result caused in the vehicle by the abnormal control behavior can be determined. The relationship between the above-mentioned set of control elements, set of output information, set of control behaviors, abnormal control behavior and abnormal behavior result is linked to obtain the corresponding linking result. The functional defects of each control element in the set of control elements are analyzed from the linking result to obtain the set of functional defect results. According to the set of functional defect results and the linking result, the expected functional safety requirement of the vehicle control system can be proposed. In the embodiment, through the above-mentioned method, the hazard behavior of the whole vehicle can be traced back from each control element in the vehicle control system, so that a perfect and unified requirement analysis is formed. Further, the technical effect that the expected functional safety requirement of the vehicle control system can be effectively determined is realized, and the technical problem that the expected functional safety requirement of the vehicle control system cannot be effectively determined is solved. BRIEF DESCRIPTION OF DRAWINGS
[0021] The drawings described herein are used to provide further understanding of the present application, and form a part of the present application. The illustrative embodiments of the present application and their descriptions serve to explain the present application, and do not constitute an improper limitation on the present application. In the drawings:
[0022] Figure 1 is a flowchart of a method for determining the expected functional safety requirement of a vehicle control system according to an embodiment of the present application;
[0023] Figure 2 is a flowchart of a method for analyzing the expected functional safety requirement according to an embodiment of the present application;
[0024] Figure 3 is a schematic diagram of a device for determining the expected functional safety requirement of a vehicle control system according to an embodiment of the present application. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should fall within the scope of protection of the present application.
[0026] It is to be understood that the terms "first", "second", and the like, used in the description and the claims of the application and the above-described drawings, are used to distinguish similar objects, and are not necessarily used to describe a particular sequential or chronological order. It should be understood that the data thus used can be interchanged, where appropriate, so that the embodiments of the application described herein can be carried out in other than the order shown or described herein. Furthermore, the terms "comprise" and "have", and any variations thereof, are intended to cover non-exclusive inclusions, for example, a process, method, system, product, or apparatus that comprises a list of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to such processes, methods, products, or apparatuses.
[0027] According to an embodiment of the application, an embodiment of a method for determining expected functional safety requirements in a vehicle control system is provided. It should be noted that the steps shown in the flowcharts of the drawings can be executed in a computer system, such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0028] Figure 1 is a flowchart of a method for determining expected functional safety requirements in a vehicle control system according to an embodiment of the application, as shown in Figure 1 The method can comprise the following steps:
[0029] In step S102, a set of control elements of a vehicle control system of a vehicle is obtained, as well as a set of output information and a set of control behaviors corresponding to the set of control elements.
[0030] In the technical solution provided in step S102 of the application, if the vehicle is an intelligent driving vehicle, the vehicle control system can be an intelligent driving system, referred to as a driving system. The set of control elements includes at least one control element. The control element can be a system architecture element, referred to as an architecture element, in the control architecture of the vehicle control system. The set of control elements can be represented in the form of an element list, which can include the number of control elements and the name of the control elements.
[0031] Optionally, the element list refers to listing each element in the control architecture, including all control elements, modules, and subsystems in the vehicle control system. The element list can include sensors, controllers, actuators, algorithm modules, etc. By listing the element list, all components and functional modules in the system can be clearly understood.
[0032] It should be noted that the above-mentioned control elements are only for illustration, and are not specifically limited herein, as long as the control elements can ensure the functional safety and stable operation of the vehicle control system, which are within the protection scope of the embodiments of the application.
[0033] Optionally, the output information set includes at least one output information, and the output information is obtained by controlling the control element. The output information can be an architecture element output or a control element output. The output information set can be represented in the form of an output list, and the output list can include the number of the control element, the name of the control element, and the control element output. For example, the output information can be information collected by controlling the control element or a control result obtained by controlling the control element. For example, if the control element is a camera, the corresponding output information can be a video stream; if the control element is a visual perception module, the corresponding output information can be information about obstacles around the vehicle, traffic lights on the road, and the like. It should be noted that the above output information is only an example and is not specifically limited herein.
[0034] Optionally, the output list refers to the output list of each element in the control architecture, that is, the output that can be generated by each element. The output list can include detection data of a sensor, an instruction of a controller, an action of an actuator, and the like. By analyzing the output list, the function and role of each element and its influence on the entire system can be determined.
[0035] Optionally, the control behavior set includes at least one control behavior. The control behavior can be issued by the vehicle control system and used to control the behavior executed by the control element. For example, it can be a steering instruction or a deceleration instruction provided by the intelligent driving master controller in the intelligent driving system, which is only an example and is not specifically limited.
[0036] Optionally, the control behavior refers to various operations and behaviors performed by the automatic driving system during operation, including acceleration, braking, steering, obstacle avoidance, and following control actions of the vehicle. By analyzing and defining the control behavior of the system, the behavior logic of the system under different conditions can be clearly understood.
[0037] In this embodiment, the control elements set, output information set of the control architecture of the vehicle control system can be combed, and the control behavior can be combed, wherein the control architecture refers to the overall structure and organization mode for realizing vehicle control and driving decision in the automatic driving system. The control architecture defines the connection relationship and interaction logic between various control elements in the vehicle control system to ensure that the vehicle can be correctly controlled and operated according to the environment and user input. In the control architecture, various control elements play different roles and functions and work together to realize the automatic driving function of the vehicle. For example, sensors are used to collect environmental information, controllers are used to process and analyze sensor data, and actuators are used to execute control instructions. The design of the control architecture needs to consider the stability, reliability, real-time performance and other aspects of the system to ensure that the system can safely and efficiently run. In summary, the control architecture is a key component of the automatic driving system, which specifies the relationship and interaction between various control elements in the system, and is the basis for the design and development of the vehicle control system.
[0038] In the embodiment of the application, the control behavior, element list and output list are closely related in the design of the intelligent driving system, and they jointly constitute the control architecture and operation logic of the system. The control behavior is various operations and behaviors performed by the system in the automatic driving process, such as acceleration, braking, steering and other control actions. The element list includes all control elements in the system, such as sensors, controllers, actuators and the like. Each control behavior corresponds to one or more control elements in the system, and these control elements jointly realize the control behavior. The relationship between the control behavior and the control element is the basis of the system control architecture, and through the element list listed in the list, the control elements involved in the control behavior can be determined to clarify the working principle and function allocation of the system. The output list includes the output that each control element may generate, such as sensor data, controller instructions, actuator actions and the like. The data and instructions in the output list play a key role in the execution process of the control behavior, and they are the basis and basis for the realization of the control behavior. The result of the control behavior can be verified and monitored through the output list to ensure that the system runs normally and produces correct output during execution.
[0039] Therefore, the control behavior, element list and output list are closely related. The control behavior defines the operation and behavior logic of the system, the element list lists the control elements in the system, and the output list reflects the output result of each control element. By understanding and integrating the relationship between the three, the control architecture of the intelligent driving system can be better designed and managed to ensure that the system can run efficiently and safely.
[0040] Step S104, determine at least one abnormal control behavior corresponding to at least one control behavior in the control behavior set, and determine at least one abnormal behavior result associated with the at least one abnormal control behavior.
[0041] In the technical solution provided by the above step S104 of the present application, the abnormal control behavior can be an unsafe control behavior corresponding to the control behavior, which can be caused by the failure of the control time, duration, etc. of the control behavior. Here, only examples are given, and no specific limitations are made. If the control behavior is a steering instruction provided by the intelligent driver controller, the unsafe control behavior can be that the intelligent driver controller does not send a steering instruction to the actuator. The abnormal behavior result can be used to represent the abnormal influence of the execution of the abnormal control behavior on the vehicle, which can also be called a harmful behavior. For example, if the abnormal control behavior is that the main driver controller unexpectedly sends a steering instruction to the actuator, the corresponding abnormal behavior result is to unexpectedly provide a steering torque. Here, only examples are given, and no specific limitations are made.
[0042] Optionally, the unsafe control behavior refers to the control operation or behavior that may cause safety problems or risks in the process of sorting out the control behavior. The unsafe control behavior can include abnormal braking, wrong steering, misjudgment of traffic signals, etc., which can cause system out of control or dangerous behavior. The harmful behavior refers to the possible dangerous or accident behavior caused by the unsafe control behavior, which can cause the vehicle to lose control, collision, reverse, etc. In this embodiment, by analyzing and linking the unsafe control behavior and the harmful behavior, potential safety risks and problems can be identified.
[0043] In this embodiment, after determining the control behavior set, the abnormal control behavior corresponding to each control behavior in the control behavior set can be determined, and the abnormal behavior result associated with each abnormal control behavior can be determined.
[0044] Optionally, the control behavior is sorted out, the corresponding unsafe control behavior is analyzed, and the harmful behavior is linked. In this process, the control behavior of the system can be sorted out, the possible unsafe control behavior can be identified, and it can be linked with the possible harmful behavior. The above method helps to identify potential safety hazards and risk points in the system.
[0045] Step S106, link the relationship between the control element set, the output information set, the control behavior set, the abnormal control behavior and the abnormal behavior result, and obtain a linking result.
[0046] In the technical solution of the above step S106 of the present application, the linking result can be a linking relationship table.
[0047] Optionally, the link relationship table is used to record and display the association and link relationship between each element in the system. Through the link relationship table, the interaction and influence between each component in the system can be clearly understood, which helps the decision-making and improvement in the system design and analysis process. The link relationship table can help to sort out the structure and components of the system, clearly show the relationship and connection mode between each element in the system, and help to understand the overall architecture of the system. Through the link relationship table, potential problems and risk points in the system can be identified. According to the link relationship between elements, factors that may cause unsafe behavior or harmful behavior can be predicted and analyzed. It can also help to identify bottlenecks and contradictions in the system, guide the optimization and improvement of system design. By analyzing the link relationship, unreasonable places in the system can be found, and corresponding improvement schemes can be put forward. It is more helpful for risk management and safety assessment of the system. By analyzing the link relationship between elements, the security risks and problems of the system can be identified, so as to effectively reduce the risk of the system and ensure the safety and reliability of the system. It can also provide important reference for system design and decision-making. According to the information in the link relationship table, reasonable decisions and adjustments can be made to ensure that the system can run as expected.
[0048] In general, the link relationship table can be used to better understand the structure and operation logic of the system, identify potential problems and risks, and propose effective solutions. By reasonably using the link relationship table, the safety, stability and reliability of the system can be improved, providing important support for the design and development of intelligent driving systems.
[0049] In this embodiment, after determining the control behavior set and the abnormal control behavior and abnormal behavior result corresponding to each control behavior in the control behavior set, the relationship between the above-mentioned determined control element set, output information set, control behavior set, abnormal control behavior and abnormal behavior result can be analyzed and linked to obtain a link result.
[0050] Optionally, starting from the architecture element, it is judged whether each output of the architecture element affects each control behavior. The link relationship table of the architecture element, element output, control behavior, unsafe control behavior and harmful behavior is obtained. That is, starting from the architecture element of the system, it is analyzed whether the output of each element will affect the control behavior of the system. By establishing the link relationship table between the architecture element, element output, control behavior, unsafe control behavior and harmful behavior, the influence relationship between each element and behavior in the system can be clearly understood, which helps to identify potential safety risks.
[0051] In the embodiments of the present application, starting from the architecture elements of the system, the output of each architecture element is analyzed to determine whether the output will affect each control behavior. Through the above process, a correlation and linkage relationship table between the architecture elements, element outputs, control behaviors, unsafe control behaviors, and harmful behaviors can be established to better understand the operation logic and potential safety risks of the system.
[0052] Optionally, starting from the architecture elements: the architecture elements are the basic components in the system, including sensors, controllers, actuators, etc. Each architecture element is analyzed to understand its functions and effects, as well as its possible outputs. For the output of each architecture element, it is determined whether it will affect each control behavior in the system, as well as the degree and manner of the influence. According to the analysis of the architecture elements, element outputs, control behaviors, unsafe control behaviors, and harmful behaviors, a correlation and linkage relationship table is established. This table can clearly show the influence of the output of each architecture element on each control behavior, as well as the relationship between unsafe control behaviors and harmful behaviors. According to the analysis of the influence of the output on the control behavior, the architecture element outputs that may cause unsafe control behaviors and harmful behaviors are identified. Unsafe control behaviors refer to control operations that may cause the system to lose control or produce dangerous behaviors, while harmful behaviors refer to possible dangerous or accident behaviors caused by unsafe control behaviors.
[0053] Through the above method, the effects and influences of each architecture element in the system can be better analyzed to ensure the matching and coordination between the control behaviors and outputs of the system, and potential safety hazards and risk points are identified. The establishment of the linkage relationship table between the architecture elements, element outputs, control behaviors, unsafe control behaviors, and harmful behaviors helps to comprehensively evaluate the functional safety of the system and propose corresponding improvement measures and preventive measures to ensure that the system can safely and reliably operate under various conditions.
[0054] Step S108, based on the linkage results, determining a set of functional defect results corresponding to the set of control elements.
[0055] In the technical solution provided by the above step S108 of the present application, the set of functional defect results can include at least one functional defect result. The functional defect result is used to represent the functional defect existing in the corresponding control element in the set of control elements. The functional defect can be used to represent the potential functional deficiency in the control element. The functional defect result can include the potential functional deficiency and the triggering condition.
[0056] Optionally, the potential functional deficiency refers to a situation where a control element in the vehicle control system fails to meet certain functional or performance requirements in design or actual operation. In an intelligent driving system, the potential functional deficiency can manifest as the system's inability to correctly identify obstacles, make correct decisions or control actions, etc. Through deductive analysis, potential functional defects or deficiencies in system design can be identified for timely improvement and adjustment. It should be noted that the above-mentioned potential functional deficiencies are only for illustration and are not specifically limited herein.
[0057] Optionally, the trigger condition is a condition or situation that causes the system to produce a specific behavior or event. In an intelligent driving system, trigger conditions can include environmental changes, sensor data anomalies, user operations, and other factors. By analyzing the trigger conditions deductively, it can be determined how the system will respond or behave in certain situations and how to effectively respond to the trigger conditions. It should be noted that the above-mentioned trigger conditions are only for illustration and are not specifically limited herein.
[0058] For example, assuming that the architectural element of an intelligent driving system is a forward-facing camera, deductive analysis can reveal the following potential functional deficiencies and trigger conditions: the potential functional deficiency can be the insufficient performance of the forward-facing camera in color contrast and brightness contrast, which can cause the system to fail to accurately identify road signs or obstacles. The trigger condition can be that the camera cannot correctly identify road signs under strong light conditions, and the trigger condition is that the light intensity exceeds the recognition range of the camera.
[0059] In the embodiments of the present application, by analyzing potential functional deficiencies and trigger conditions, potential problems and risks in the system can be identified to take appropriate improvement measures and optimization strategies to improve the safety and reliability of intelligent driving systems. Deductive analysis helps to fully understand the potential risks of the system, thereby ensuring the safe operation of the system under various conditions.
[0060] In this embodiment, after linking the relationships between the control element set, the output information set, the control behavior set, the abnormal control behavior, and the abnormal behavior result to obtain the linking result, the functional defect result set corresponding to the control element set can be determined based on the linking result.
[0061] Optionally, each functional deficiency and trigger condition is linked to a harmful behavior through the architectural element, and is judged and sorted. Each identified functional deficiency and trigger condition is linked to a possible harmful behavior through the architectural element. These linkages are judged and sorted to determine how individual functional deficiencies and trigger conditions in the system can lead to the occurrence of harmful behaviors.
[0062] Optionally, each functional deficiency and trigger condition is linked to a harmful behavior through the architectural elements, and judgment and sorting are performed. The above method is very important, because only when the association between the functional deficiency and the trigger condition and the harmful behavior is clear, can the risk assessment and risk management be effectively performed. Each functional deficiency can be explicitly listed, such as system crash, data loss, etc. The trigger condition can also be determined, that is, the specific situation or event that causes the functional deficiency to occur, such as network failure, user error operation, etc. Each functional deficiency and trigger condition can also be associated with the possible harmful behavior, for example, system crash may cause service interruption, data loss may cause information leakage, etc.
[0063] After the association is performed, the above association can be judged and sorted, the influence degree of each functional deficiency and trigger condition on system security is evaluated, and it is determined which is the most critical and needs to be focused on, so that targeted risk management can be performed, and corresponding measures can be taken to reduce the possibility and influence degree of risk occurrence. In summary, by linking the functional deficiency, the trigger condition and the harmful behavior through the architectural elements, and performing judgment and sorting, it is helpful to more comprehensively understand the security risks existing in the system, and to provide effective reference basis for risk management.
[0064] Optionally, potential functional deficiencies and trigger conditions are analyzed in a deductive manner from the architectural elements. The potential functional deficiencies and trigger conditions can be analyzed in a deductive manner from the architectural elements of the system. Through logical reasoning and analysis, the possible functional defects or trigger condition deficiencies in the system design are identified, which helps to prevent potential problems in advance.
[0065] Optionally, potential functional deficiencies and trigger conditions are analyzed in a deductive manner from the architectural elements. The above method aims to identify possible functional defects or trigger condition deficiencies in the system design through logical reasoning and analysis, so as to prevent possible problems or unsafe behaviors of the system.
[0066] Optionally, a comprehensive review and analysis of the architectural elements of the system is performed. Understanding the function and role of each architectural element, as well as its position and impact in the system, is crucial for subsequent deductive analysis. Deduction is a method of logical reasoning that draws new conclusions or results through reasoning and inference from known conditions and rules. In the above process, the architectural elements, functions and roles of the system are analyzed by deductive method, and the possible functional deficiencies and trigger condition deficiencies are inferred, that is, the system cannot correctly perform the expected functions or respond to specific trigger conditions in some cases. During the deductive analysis process, it is necessary to identify possible functional deficiencies, that is, some functions in the system cannot meet user needs or design requirements. This may include situations where some control behaviors cannot be implemented, some outputs cannot be triggered correctly, etc. At the same time, it can also be determined that there may be trigger condition deficiencies, that is, the system cannot correctly respond to some specific trigger conditions. This may cause the control behavior of the system to produce errors or instability. By analyzing potential functional deficiencies and trigger conditions through deductive methods, problems can be identified early and appropriate preventive measures and improvement plans can be proposed. This helps to identify potential risks in a timely manner and improve the safety and reliability of the system.
[0067] In the embodiments of the present application, by starting from the architectural elements and analyzing potential functional deficiencies and trigger conditions through deductive methods, it can help to prevent problems that may occur during the design and development of the system, and improve the stability and safety of the system. The above method is an important part of the system design and development process, which helps to identify potential risks in advance and take appropriate measures to ensure that the system can operate as expected.
[0068] Step S110, based on the link result and the function defect result set, determining the expected functional safety requirement of the vehicle control system.
[0069] In the technical solution provided by the above step S110 of the present application, the expected functional safety requirement can be used to represent the strategy to be executed to overcome the functional defects, and the expected functional safety requirement can also be referred to as the functional safety requirement.
[0070] Optionally, the expected functional safety requirement refers to the safety performance requirement that must be met when designing the intelligent driving system, to ensure that the system can still provide safe and reliable functions in the event of a failure or abnormal situation. By analyzing the correlation between the elements of the control architecture, the control behavior, the unsafe control behavior, and the hazardous behavior, the functional safety requirements required by the system are determined. The expected functional safety requirement mainly includes the following aspects: ensuring the correctness and reliability of system functions, the functional safety requirement should ensure that the system can correctly perform the designed functions and maintain reliability under various conditions, avoiding insufficient or failure functions. Guarantee the robustness of the system to external environment and interference, the functional safety requirement should consider the robustness of the system under various external environmental conditions, including the influence of weather, light, road conditions and other factors on the system, to ensure that the system can run stably and respond correctly. Improve the fault diagnosis and fault tolerance capability of the system, the functional safety requirement should include the diagnosis and processing capability of the system to faults, which can identify problems in time and take measures to ensure that the system can safely park or enter a safe mode when a fault occurs. Ensure the safe interaction of the system with other vehicles and traffic participants, the functional safety requirement should consider the safe interaction of the system with other vehicles, pedestrians, bicycles and other traffic participants, to ensure that the system can predict and avoid potential collision risks. Ensure the data security and privacy protection of the system, the functional safety requirement should include the protection of vehicle data and the safe handling of privacy information by the system, to prevent data leakage and unauthorized access.
[0071] By clearly defining and analyzing the expected functional safety requirement, the safety performance requirements that the system needs to meet during the design and development process can be better considered, thereby ensuring that the intelligent driving system has high safety and reliability. At the same time, the expected functional safety requirement also provides an important basis for the verification, testing and certification of the system.
[0072] For example, if the architecture element is a camera, the potential insufficient function is the insufficient performance of the camera color contrast and brightness contrast, and the triggering condition is that the target object has weak color contrast or sensitive contrast. The corresponding expected functional safety requirement can be "avoiding the reduction of sensor accuracy for target objects, lane lines, road edges, etc. with weak color contrast or sensitive contrast". It should be noted that the above-mentioned expected functional safety requirement is only for illustration and is not specifically limited here.
[0073] In this embodiment, after determining the functional defect result set corresponding to the control element set based on the link result, the expected functional safety requirement of the vehicle control system can be determined based on the link result and the functional defect result set.
[0074] Optionally, based on the functional deficiencies, trigger conditions, and harmful behaviors identified in the previous analysis, the expected functional safety requirements are proposed. These requirements can be improvements or requirements for the functional deficiencies, trigger conditions, and harmful behaviors to ensure that the system can operate safely and reliably under various conditions. The above method helps to improve the safety and reliability of the system and reduce the risk of system failure or accident.
[0075] Optionally, based on the functional deficiencies, trigger conditions, and harmful behaviors identified in the previous analysis, the expected functional safety requirements are proposed. These requirements can be improvements or requirements for the functional deficiencies, trigger conditions, and harmful behaviors to ensure that the system can operate safely and reliably under various conditions. The above method helps to improve the safety and reliability of the system and reduce the risk of system failure or accident.
[0076] Optionally, based on the functional deficiencies, trigger conditions, and harmful behaviors identified in the previous analysis, the expected functional safety requirements are proposed. These requirements can be improvements or requirements for the functional deficiencies, trigger conditions, and harmful behaviors to ensure that the system can operate safely and reliably under various conditions. The above method helps to improve the safety and reliability of the system and reduce the risk of system failure or accident.
[0077] In the process of proposing functional safety requirements, it is necessary to ensure that the above requirements have measurability, verifiability and traceability, so that in the subsequent design, development and testing process, it can be verified whether the system meets these requirements. In addition, functional safety requirements also need to be coordinated and integrated with other system requirements to ensure that the system meets the safety requirements while also achieving other functional and performance requirements. In summary, based on the functional deficiencies, trigger conditions, and harmful behaviors, the expected functional safety requirements are proposed, which is an important step to ensure the safety of the system, and can provide clear guidance for subsequent system design and development, to establish a more secure and reliable system.
[0078] The above steps S102 to S110 of the present application can be used to determine the expected functional safety requirements of the vehicle control system, determine the control element set and the output information set in the vehicle control system, and sort out the corresponding control behavior set. Each control behavior in the control behavior set is analyzed to determine the risks implied therein, and the corresponding abnormal control behavior is obtained. The abnormal behavior result caused in the vehicle by the abnormal control behavior can be determined. The relationship between the control element set, the output information set, the control behavior set, the abnormal control behavior, and the abnormal behavior result is linked to obtain the corresponding linking result. The functional defects of each control element in the control element set are analyzed from the linking result to obtain a functional defect result set. According to the functional defect result set and the linking result, the expected functional safety requirements of the vehicle control system can be proposed. In this embodiment, the above method can trace the hazard behavior of the whole vehicle from each control element in the vehicle control system, thereby forming a perfect and unified requirement analysis. Furthermore, the technical effect of effectively determining the expected functional safety requirements of the vehicle control system is achieved, and the technical problem of being unable to effectively determine the expected functional safety requirements of the vehicle control system is solved.
[0079] The above method of this embodiment will be further introduced below.
[0080] As an optional embodiment, in step S102, the output information set corresponding to the control element set is obtained, including: obtaining the input information of at least one control element in the control element set; determining the output information corresponding to the at least one control element based on the input information and the corresponding control element; and obtaining the output information set based on the output information corresponding to the at least one control element in the control element set.
[0081] In this embodiment, in the process of obtaining the output information set corresponding to the control element set, the input information of each control element in the control element set can be obtained, and the output information corresponding to the control element can be determined according to the input information and the corresponding control element. The output information of all control elements is summarized to obtain the output information set, wherein the input information can be the system architecture element input. The output information can be the system architecture element output.
[0082] Optionally, the system architecture element can include a vehicle internal element, a vehicle external element, and a smart driving controller internal element. The vehicle internal element can include a sensor, such as a camera, a radar, etc., can also include an actuator, such as a steering system, a brake system, an acceleration system, etc., and can also include a vehicle control unit, etc. The vehicle external element can include road markings, other vehicles, pedestrians, and other external environmental elements, etc. The smart driving controller internal element can include a decision module, a planning module, a perception module, and other functional modules inside the intelligent driving controller.
[0083] Optionally, the system architecture element input can include sensor data, external environment data, and user input, etc. Sensor data can be obtained by sensors inside the vehicle to obtain information about the environment around the vehicle, such as road conditions, other vehicles, pedestrians, etc. External environment data can include information from external elements such as road markings, other vehicles, pedestrians, etc. User input can include driver instructions or system user interface input. It should be noted that the above system architecture element input is only for illustration and is not limited here.
[0084] Optionally, the system architecture element output can be control instructions, state information, and alarm information. Control instructions can be generated by the decision-making module inside the intelligent driving controller according to sensor data and environment data, including steering, acceleration, braking, and other control instructions. State information can be output by the system to monitor the current vehicle state, predicted driving path, and surrounding environment information in real time. Alarm information can be output to the driver or other systems when the system detects dangerous or abnormal situations. It should be noted that the above system architecture element output is only for illustration and is not limited here.
[0085] Optionally, the system architecture element input refers to the input data, signals or information received and processed by each component or module in the system. These inputs are usually used to trigger specific functions, algorithms or control behaviors of the system. The content and format of the system architecture element input depend on the design and functional requirements of the system, which can be environmental data collected by sensors, user input commands, outputs from other system modules, etc.
[0086] In the embodiments of the present application, the input of the system architecture element can be various forms of data or signals, which are determined according to the design and requirements of the system. For the two sensors of camera and radar, the input of camera is visual information and the input of radar is radar wave echo data. These input data are very important for the environment perception and decision-making of intelligent driving system. Through processing and analysis of these input data, the system can realize the perception of surrounding environment and the decision-making of driving behavior.
[0087] Optionally, designing a control architecture for intelligent driving function is a key step to ensure that the system can effectively realize the function of automatic driving. When designing the control architecture of intelligent driving function, it is necessary to ensure that the cooperation and information transmission between system architecture elements are effective and reliable, and at the same time, the real-time, safety and scalability of the system are considered. The control architecture should be able to comprehensively cover all elements within the functional range, ensuring that the system can stably and efficiently realize the function of automatic driving.
[0088] Optionally, it is very important to define the control architecture of intelligent driving functions according to the scope of functions, because the design of the control architecture should be able to cover all elements within the scope of functions to ensure that the system can effectively achieve the automatic driving function. Setting up a complete control architecture needs to consider the cooperation and interaction between these elements to ensure that the system can stably and efficiently achieve the automatic driving function and can effectively deal with various driving scenarios and environmental changes.
[0089] Optionally, through the input and output of architecture elements, different functional modules can realize the transmission and exchange of data, realize the cooperation and coordination between various modules in the system. Sensor data and external environment data provide real-time environmental information for the system, user input provides operation instructions for the system, and state information and control instructions are the output of the system, guiding the driving and control of the vehicle. By reasonably designing and managing the input and output, it can ensure that the system can efficiently run, realize the intelligent driving function, and improve the safety and comfort of driving.
[0090] As an optional embodiment, in step S104, determining at least one abnormal control behavior corresponding to at least one control behavior in the control behavior set comprises: applying a keyword to at least one control behavior in the control behavior set to obtain a corresponding abnormal control behavior, wherein the keyword is used to identify problems existing when the control behavior is executed.
[0091] In this embodiment, in the process of determining the abnormal control behavior corresponding to each control behavior in the control behavior set, a keyword can be applied to each control behavior in the control behavior set to obtain the corresponding abnormal control behavior, wherein the keyword can be used to identify problems existing when the control behavior is executed.
[0092] Optionally, for each external output of the intelligent driving master controller, it is defined as a control behavior, and then the control behavior list is sorted and arranged. The control behavior list is a clear definition and arrangement of the control instructions or behaviors of the system output, so that the system can accurately and stably achieve the required function.
[0093] Optionally, for each external output of the intelligent driving master controller, such as steering control, acceleration control, brake control, etc., the specific control behavior can be explicitly defined, including the purpose of control, the action performed, the target state, etc. For example, the control behavior of steering control can be defined as "according to the position of the obstacle in front of the vehicle and the lane line information, perform steering action to keep the vehicle in the safe driving lane". By sorting out the various outputs of the intelligent driving master controller, defining each as a control behavior, and organizing a list. This list should include all the control behaviors involved, sorted by function or priority, to ensure that each control behavior is clearly defined and described. In the process of forming the control behavior list, the correlation and influence between each control behavior can be analyzed to ensure their coordination and consistency. For example, there may be interaction between steering control and acceleration control, which needs to be coordinated and synchronized. By listing and organizing the control behaviors of the intelligent driving system, the system development team can better understand the functional requirements and implementation logic of the system, improving the maintainability and reliability of the system. At the same time, the control behavior list can also be used as a basis for system testing and verification, to verify whether the system performs control behaviors as expected, thereby ensuring the safety and stability of the system.
[0094] Optionally, after applying the keywords to each control behavior, the unsafe control behavior is obtained, and then linking the unsafe control behavior with the hazard behavior is very important to help identify potential risks and safety problems in the system.
[0095] Optionally, for each unsafe control behavior, it needs to be linked with the possible hazard behavior to analyze its potential safety risks and consequences. For example, providing steering control instructions too late may cause the vehicle to deviate from the lane, increasing the risk of collision with other vehicles. By linking and analyzing unsafe control behaviors with hazard behaviors, system designers can better identify and handle potential safety problems and take appropriate measures to reduce the likelihood of risk occurrence.
[0096] As an optional embodiment, the keywords include at least one of the following: a first keyword, a second keyword, a third keyword, a fourth keyword, a fifth keyword, and a sixth keyword, wherein the first keyword is used to represent that the control behavior is not executed in a situation where it needs to be executed, the second keyword is used to represent that the time of executing the control behavior exceeds a time range threshold, the third keyword is used to represent that the degree of executing the control behavior exceeds a degree range threshold, the fourth keyword is used to represent that the direction of executing the control behavior is abnormal, the fifth keyword is used to represent that the time of ending the control behavior is earlier than a target time, and / or the duration of executing the control behavior exceeds a duration threshold, and the sixth keyword is used to represent that the control behavior is executed in a situation where it does not need to be executed.
[0097] In this embodiment, the keywords can include at least one of a first keyword, a second keyword, a third keyword, a fourth keyword, a fifth keyword, and a sixth keyword. The first keyword can be used to represent that a control action should be provided but is not provided in a situation where the control action needs to be performed. The second keyword can be used to represent that a control action is performed beyond a time range threshold, i.e., the control action is provided too early or too late. The third keyword can be used to represent that a control action is performed beyond a degree range threshold, i.e., the control action is provided too much or too little. The fourth keyword can be used to represent that a control action is performed in an abnormal direction, i.e., the control action is provided in a reverse direction. The fifth keyword can be used to represent that a control action is ended too early than a target time, and / or, a control action is performed for a time period beyond a time period threshold, i.e., the control action is provided too early or performed for too long. The sixth keyword can be used to represent that a control action is performed in a situation where the control action does not need to be performed, i.e., the control action is provided unexpectedly.
[0098] It should be noted that the keywords described above are only for illustration and are not specifically limited herein.
[0099] Optionally, the control action should be provided but is not provided, which can cause the system to fail to make a critical control decision in time, thereby causing a safety hazard. For example, a brake control instruction is not provided in an emergency situation, which can cause a collision to be unavoidable. The control instruction is provided too early or too late, which can cause the system to react too late or act excessively delayed, thereby affecting driving safety. For example, a steering control instruction is provided too late, which can cause the vehicle to deviate from the lane. The control instruction is provided too much or too little, which can cause the vehicle to travel unstably or out of control. For example, an acceleration control instruction is provided excessively, which can cause the vehicle to accelerate out of control. The control instruction is provided in a reverse direction, which can cause the vehicle to travel in a wrong direction, thereby increasing the risk of traffic accidents. The control instruction is provided too early or for too long, which can cause the vehicle to fail to stop in time in an emergency situation, thereby causing a collision accident. The control instruction is provided unexpectedly, which can cause the system to behave abnormally, thereby increasing the risk of the vehicle being out of control.
[0100] As an optional embodiment, the linking result is a linking relationship table, and the step S106 of linking the relationships among the control element set, the output information set, the control action set, the abnormal control action, and the abnormal behavior result to obtain the linking result includes: detecting at least one output information in the output information set and at least one control action in the control action set to obtain a detection result, where the detection result is used to represent whether the output information can affect the corresponding control action; and obtaining the linking relationship table based on the control element set, the output information set, the control action set, the abnormal control action, the abnormal behavior result, and the detection result.
[0101] In this embodiment, in the process of linking the relationships between the control element set, the output information set, the control action set, the unsafe control action and the hazard action result, the output information in the output information set and the control action in the control action set can be detected to obtain a detection result. If the detection result is that the output information can affect the corresponding control action, the above-mentioned various sets and the detection result can be linked to obtain a link relationship table, wherein the link result can be the link relationship table. The detection result can be used to indicate whether the output information can affect the control result.
[0102] Optionally, starting from the architecture element, it is judged whether each item of output affects each item of control action, and then through the link relationship from the architecture element to the control action, to the unsafe control action, and finally to the hazard action, the potential risks and safety problems in the system can be identified.
[0103] Optionally, the output of each architecture element of the intelligent driving system is analyzed to judge whether the output affects each control action. For example, whether the information output by the sensor affects the generation of the corresponding control instruction by the decision module. After judging the influence of the output of the architecture element on the control action, it is further analyzed whether there is an unsafe control action. For example, if the information output by the sensor is incorrect, the intelligent driving master controller may provide incorrect steering instructions. The unsafe control action can be linked to the hazard action that may be caused, and the potential risks and hazards that may be caused by the unsafe control action can be determined. For example, the intelligent driving master controller providing incorrect steering instructions may cause the system to lose lateral control function in the active state, increasing the risk of collision with other vehicles.
[0104] In the embodiment of the present application, through the above-mentioned analysis process, the potential safety hazards and risks in the system can be comprehensively understood, and the system can be improved and optimized in a targeted manner, thereby improving the safety and reliability of the system. The method of link relationship analysis is helpful for safety evaluation and risk management of the system, and ensures that the intelligent driving system can safely and reliably operate in various situations.
[0105] As an optional embodiment, in step S108, based on the link result, a function defect result set corresponding to the control element set is determined, including: obtaining type information of at least one control element in the control element set in the link result; based on the type information, determining a defect analysis dimension corresponding to the at least one control element, and corresponding defect analysis information under the defect analysis dimension; determining a corresponding function defect information set and a trigger condition set under the defect analysis information; and linking the relationship between the function defect information set and the trigger condition set to obtain the function defect result set.
[0106] In this embodiment, in the process of determining the function defect result set corresponding to the control element set based on the link result, the type information of each control element in the control element set in the link result can be obtained. Based on the type information, the defect analysis dimension corresponding to the control element and the defect analysis information under the defect analysis dimension can be determined. The corresponding function defect information set and trigger condition set under the defect analysis information can be determined. The relationship between the function defect information set and the trigger condition set is linked to obtain the function defect result set, wherein the function defect information set can be a potential functional deficiency. The trigger condition set can be a trigger condition. The type information can be the type of different control elements, such as sensor type, algorithm type, etc. It should be noted that the above type information is only for example, and is not specifically limited here, and can be determined according to the actual control element.
[0107] Optionally, by starting from each architecture element, the potential functional deficiency and the trigger condition are analyzed in a deductive manner, which can help to identify possible defects and risks in the system design, so as to take corresponding measures to improve the safety and reliability of the system.
[0108] Optionally, for each architecture element in the system, such as a sensor, a perception module, a decision module, etc., the function thereof is analyzed respectively, and the possible functional deficiency and potential risk thereof are considered. Starting from the output of each architecture element, the possible missing function or deficiency in the system is considered through deductive reasoning. For example, if the data output by a sensor is unstable or has errors, it may cause the perception module to fail to accurately identify obstacles, resulting in system decision errors. The possible functional deficiencies of each architecture element, such as data accuracy, real-time performance, fault tolerance, etc., and the conditions or situations triggering these functional deficiencies are analyzed. For example, when a sensor is disturbed or blocked, it may cause inaccurate data, and the trigger condition may be adverse weather or environmental conditions. By analyzing the potential functional deficiency and the trigger condition, the risk points in the system are identified, and corresponding improvement suggestions and measures are proposed to reduce the possibility of risk occurrence. For example, sensor redundancy can be considered, data processing algorithms can be improved, or the fault tolerance of the system can be strengthened, etc.
[0109] In the embodiments of the present application, by starting from each architecture element, the potential functional deficiency and the trigger condition are analyzed in a deductive manner, which can comprehensively review the design and implementation of the system, identify potential risks and security risks, and take preventive and improvement measures in advance, thereby improving the safety and reliability of the system. This analysis method helps system designers and developers to fully understand the potential problems of the system and take timely measures to improve it, ensuring that the intelligent driving system can safely and reliably operate in various situations.
[0110] As an optional embodiment, the defect analysis dimension includes a first defect analysis dimension and a second defect analysis dimension, the first defect analysis dimension is a defect analysis dimension common to control elements, and the second defect analysis dimension is a defect analysis dimension unique to different control elements, wherein, based on the type information, determining the defect analysis dimension corresponding to the at least one control element and the defect analysis information corresponding to the defect analysis dimension includes: in response to the type information being a sensor type, determining that the first defect analysis dimension includes at least one of the following: a mounting position of the control element, a vibration condition of the control element, a temperature condition of the control element, and an aging degree of the control element; and in response to the type information being an algorithm type, determining that the first defect analysis dimension includes at least one of the following: a model robustness of the control element and a model generalization of the control element.
[0111] In this embodiment, in the process of determining the defect analysis dimension corresponding to the control element and the defect analysis information therein based on the type information, if the type information is a sensor type, it can be determined that the first defect analysis dimension can include at least a safe position, a vibration condition, a temperature condition, and an aging degree of the control element. If the type information is an algorithm type, it can be determined that the first defect analysis dimension can include at least a model robustness and a model generalization of the control element. The defect analysis dimension can include a first defect analysis dimension and a second defect analysis dimension. The first defect analysis dimension can be a defect analysis dimension common to control elements. The second defect analysis dimension can be a defect analysis dimension unique to different control elements, i.e., a dimension of a special characteristic.
[0112] Optionally, for sensor type analysis, analysis can be performed according to two different dimensions, including a common analysis dimension and a sensor-specific characteristic analysis dimension.
[0113] Optionally, the common analysis dimension under the sensor type can include: mounting position, internal and external parameter calibration, vibration, temperature influence, aging / corrosion, and electromagnetic interference. The mounting position plays an important role in the performance and function of the sensor, and different mounting positions can affect the observation range, sensitivity, and accuracy of the sensor. The calibration of internal and external parameters is crucial to the accuracy and stability of sensor output data, and needs to be calibrated and calibrated regularly. The vehicle may be affected by vibration during operation, and the performance and stability of the sensor in a vibrating environment need to be considered. Temperature changes can affect the performance and accuracy of the sensor, especially in extreme temperature conditions, the sensor may fail. The sensor may be subject to aging or corrosion over time, affecting the performance of the sensor, which needs to be checked and maintained regularly. Electromagnetic interference can cause interference or distortion of sensor output data, and appropriate shielding measures need to be taken to ensure normal operation of the sensor.
[0114] It should be noted that the above general analysis dimensions are only for illustration and are not specifically limited here.
[0115] Optionally, the analysis dimensions of sensor-specific characteristics can include lighting conditions, color contrast, or light-dark contrast. For example, for cameras, analysis can be performed from characteristics such as color contrast, light-dark contrast, strong light conditions, weak light conditions, etc. For example, strong light conditions can cause image overexposure, and weak light conditions can cause image noise to increase. For radar sensors, characteristics such as detection range, angle resolution, speed measurement accuracy, etc. can be analyzed to understand the performance of the radar under different environmental conditions. For lidar, characteristics such as ranging accuracy, angle resolution, scanning speed, etc. can be analyzed, and the reflection characteristics of various terrains and objects are also considered.
[0116] It should be noted that the above analysis dimensions of sensor-specific characteristics are only for illustration and are not specifically limited here.
[0117] In the embodiments of the present application, through the above method, the importance and influencing factors of sensors in intelligent driving systems can be comprehensively understood, which helps to consider various potential influencing factors when designing and deploying sensor systems, thereby improving the performance, stability and safety of the system. For different types of sensors, more detailed analysis and consideration can be made according to their specific characteristics to ensure that the system can work normally in various scenarios.
[0118] Optionally, for algorithm analysis, the same two different dimensions can also be used for analysis, including general analysis dimensions and algorithm-specific characteristic analysis dimensions.
[0119] Optionally, the general analysis dimensions of algorithms can include model robustness, systematic errors in labeling process, insufficient training data set, model generalization, vehicle motion posture, communication bandwidth, and computing load, etc. The robustness of the algorithm model refers to its stability and adaptability to noise, interference and abnormal situations, and the robustness of the algorithm under different environments needs to be considered. The labeling data set may have systematic errors, such as inaccurate labeling or missing labels, which will affect the training and performance of the algorithm. The quality and quantity of the training data set are crucial to the performance of the algorithm, and insufficient training data may cause the model to overfit or underfit. The generalization ability of the algorithm model refers to its performance on unseen data, and the generalization performance of the algorithm model needs to be considered. The motion of the vehicle in different postures may affect the perception and decision-making of the algorithm, and the influence of the vehicle motion posture on the algorithm needs to be considered. The algorithm may require a large amount of data transmission and processing in real-time scenarios, and the limitation of communication bandwidth may affect the performance and real-time performance of the algorithm. The computational complexity and load of the algorithm have an important influence on the real-time performance and efficiency of the system, and the limitation of computing resources needs to be considered.
[0120] It should be noted that the analysis dimensions of the above-mentioned algorithm general characteristics are only for illustration and are not specifically limited here.
[0121] Optionally, the analysis dimensions of algorithm-specific characteristics can include visual perception, radar perception, lidar perception, etc. For visual perception algorithms, analysis can be performed from characteristics such as floating objects, weather, unconventional vehicles, unconventional pedestrians, unconventional lane lines, construction areas, etc. These characteristics can affect the accuracy and stability of visual perception algorithms. For radar perception algorithms, their ability to recognize different materials, shapes, and stray signals, as well as the performance of radar in different environments, can be analyzed. For lidar perception algorithms, characteristics such as complex terrain and obstacle detection can be analyzed to understand the perception capabilities of lidar in different scenarios.
[0122] It should be noted that the analysis dimensions of the above-mentioned algorithm-specific characteristics are only for illustration and are not specifically limited here.
[0123] In the embodiments of the present application, the above-mentioned method can fully consider the importance and influencing factors of algorithms in intelligent driving systems, which helps to consider various potential influencing factors when designing and deploying algorithm systems, and improves the performance, stability and safety of the system. According to different types of algorithms, more detailed analysis and consideration can be made for their specific characteristics to ensure that the system can work normally in various scenarios. This analysis method helps system designers and developers to identify potential problems in the system and take timely measures to improve it, ensuring that the intelligent driving system can safely and reliably operate in various situations.
[0124] As an optional embodiment, the types of trigger conditions in the trigger condition set include at least one of the following: control element exists disturbance condition, vehicle environment exists disturbance condition, vehicle control exists disturbance condition, and target object in vehicle exists misuse condition.
[0125] In this embodiment, the types of trigger conditions in the trigger condition set can include control element exists disturbance condition, vehicle environment exists disturbance condition, vehicle control exists disturbance condition, and target object in vehicle exists misuse condition. Among them, the control element exists disturbance condition can be sensor disturbance. The vehicle environment exists disturbance condition can be traffic disturbance. The vehicle control exists disturbance condition can be vehicle control disturbance. The target object in vehicle exists misuse condition can be personnel misuse. It should be noted that the above-mentioned types of trigger conditions are only for illustration and are not specifically limited here.
[0126] Optionally, analyzing potential functional deficiencies and trigger conditions is a very important step in system safety analysis. Trigger conditions can be specific situations or events that lead to system functional deficiencies or safety problems, helping to identify potential risks and safety hazards in the system.
[0127] Optionally, the types of trigger conditions can include sensor disturbances, traffic disturbances, vehicle control disturbances, and human misuse, etc. Sensor disturbances can include sensor data anomalies, sensor failures, sensor errors, etc., which can cause the system's perception ability to decline or fail. Traffic disturbances can include sudden changes in road traffic conditions, abnormal behavior of other vehicles or pedestrians, etc., which can affect system decision-making and planning. Vehicle control disturbances can include vehicle control system failures, control command errors, actuator failures, etc., which can cause the vehicle to lose control or fail to operate normally. Human misuse can include driver misoperation, system operator parameter misconfiguration, etc., which can affect the normal operation and safety of the system.
[0128] Optionally, each trigger condition can be analyzed in detail to understand its possible causes and impact. Link the trigger conditions with system functional deficiencies or safety problems, analyze the specific functional deficiencies or harmful behaviors that each trigger condition can cause. According to the importance and impact of the trigger conditions, the system can be risk assessed and prioritized to determine which trigger conditions need to be focused on and handled. Based on the analysis results, appropriate measures and preventive measures are developed to reduce the likelihood of trigger conditions occurring and ensure that the system can safely and reliably operate in the face of various situations.
[0129] In the embodiments of the present application, through the analysis of trigger conditions, system designers and developers can identify potential risks and safety hazards in the system, and conduct targeted risk management and safety improvement. Combined with the analysis of potential functional deficiencies and trigger conditions, the safety of the system can be comprehensively evaluated, and appropriate measures can be taken to ensure the safe and reliable operation of the system. This analysis method helps to improve the safety and reliability of the system, and ensures the normal operation of the intelligent driving system.
[0130] As an optional embodiment, before determining the expected functional safety requirements of the vehicle control system based on the link results and the functional defect result set, the method further includes: linking the relationship between the link results and the functional defect results to obtain target link results; determining abnormal behavior results from the target link results, and the association attributes between the defect information set and the trigger condition set, wherein the association attributes are used to represent the association degree between the abnormal behavior results and the defect information set and the trigger condition set.
[0131] In this embodiment, between determining the expected functional safety requirements of the vehicle control system based on the linking results and the functional defect result set, the relationship between the linking results and the functional defect results can be linked to obtain target linking results. The abnormal behavior results can be determined from the target linking results, and the association attributes between the defect information set and the trigger condition set, wherein the association attributes are used to represent the high degree of association between the abnormal behavior results and the defect information set and the trigger condition set, and can be used to represent the correlation between the functional deficiencies and the trigger conditions and the hazardous behaviors.
[0132] Optionally, the architectural elements are associated with the functional deficiencies and the trigger conditions to determine their correlation with the hazardous behaviors. This can help better understand the potential problems existing in the system and determine which functional deficiencies or trigger conditions may cause a specific hazardous behavior to occur.
[0133] Optionally, each functional deficiency and trigger condition is matched with a hazardous behavior. The corresponding association can be quickly found according to the previously established links. Each match can be evaluated to determine its degree of correlation. This evaluation can be based on the likelihood and severity of the impact on the occurrence of the hazardous behavior. Functional deficiencies or trigger conditions with high correlation may directly cause the occurrence of hazardous behaviors, or increase the likelihood and severity of the occurrence of hazardous behaviors. In this case, these problems can be focused on and measures can be considered to address or mitigate their impact. Functional deficiencies or trigger conditions with medium correlation may have some impact on the occurrence of hazardous behaviors, but not as significant as those with high correlation. In this case, improvements can be considered in future designs to improve the safety and reliability of the system. Functional deficiencies or trigger conditions with low correlation may only have a small impact on hazardous behaviors, or may not directly cause the occurrence of hazardous behaviors. In this case, these problems can be used as alternatives for improvement and left for further optimization later.
[0134] In the embodiments of the present application, by evaluating and organizing the correlation between functional deficiencies, trigger conditions and hazardous behaviors, the potential problems existing in the system can be better understood, and targeted improvements can be made to improve the safety and reliability of the system.
[0135] As an optional embodiment, step S110, determining the expected functional safety requirements of the vehicle control system based on the linking results and the functional defect result set, includes: determining the expected functional safety requirements based on the target linking results and the association attributes.
[0136] In this embodiment, the expected functional safety requirements can be determined based on the target linking results and the association attributes.
[0137] Optionally, it is very important to propose expected functional safety requirements for functional deficiencies, trigger conditions and harmful behaviors. Functional safety requirements refer to the safety performance requirements that a system must meet to ensure that the system can still provide safe and reliable functions when a fault or abnormal situation occurs.
[0138] In the embodiment of the present application, if it is necessary to determine the expected functional safety requirements of the vehicle control system, the set of control elements and the set of output information in the vehicle control system can be determined, and the corresponding set of control behaviors can be sorted out. Each control behavior in the set of control behaviors is analyzed to determine the risks implied therein, and the corresponding abnormal control behavior is obtained. The abnormal behavior result caused in the vehicle by the abnormal control behavior can be determined. The relationship between the above-mentioned control element set, output information set, control behavior set, abnormal control behavior and abnormal behavior result is linked to obtain the corresponding linking result. The functional defects of each control element in the control element set are analyzed from the linking result to obtain the functional defect result set. According to the functional defect result set and the linking result, the expected functional safety requirements of the vehicle control system can be proposed. In this embodiment, through the above-mentioned method, the harmful behaviors of the whole vehicle can be traced back from each control element in the vehicle control system, thereby forming a perfect and unified requirement analysis. Further, the technical effect of effectively determining the expected functional safety requirements of the vehicle control system is realized, and the technical problem of being unable to effectively determine the expected functional safety requirements of the vehicle control system is solved.
[0139] The technical solutions of the embodiments of the present application will be described below in conjunction with preferred embodiments.
[0140] Currently, intelligent driving, as an innovative technology, has brought the vehicle industry into a new era. It not only provides a more convenient transportation mode, but also improves traffic safety and efficiency. However, due to the limitations of current scientific and technological level, intelligent driving systems still have some potential risks and challenges.
[0141] Optionally, the intelligent driving system may be affected by the performance limitations of the equipment. If the hardware equipment of the system is not advanced enough or is unstable, it may cause the system to run unstably or fail, thereby increasing the risk of traffic accidents. The algorithm of the intelligent driving system may also have defects. If the algorithm design of the system is unreasonable or has vulnerabilities, it may cause the system to make wrong judgments, thereby causing traffic accidents. In addition, the intelligent driving system is also susceptible to interference from the running environment factors. For example, adverse weather conditions, complex road conditions, etc. may affect the normal operation of the system and increase the risk of accidents. Human misuse is also a potential risk factor. Some drivers may over-rely on the capabilities of the intelligent driving system, or use the system incorrectly, thereby causing accidents.
[0142] Therefore, in the process of popularizing and applying intelligent driving technology, attention must be paid to the safety and stability of the system, and the research and optimization of hardware devices and algorithms must be strengthened to ensure that the system can operate stably and reliably. At the same time, it is also necessary to strengthen the training and education of drivers and guide them to use the intelligent driving system correctly to avoid risks caused by human misuse. Only in this way can intelligent driving technology truly play its advantages and bring greater impetus to the development of the vehicle industry. Intelligent driving systems rely on various sensors, processors, and communication devices such as hardware devices to achieve automatic driving functions. If the performance of these devices is limited, it may affect the accuracy and stability of the system. For example, if the resolution of the laser radar sensor is not high enough, it may not be able to accurately identify obstacles on the road, leading to system errors.
[0143] Optionally, the activities and activity requirements in each stage of the life cycle of the autonomous driving system refer to the different stages that the system needs to go through and the specific activities that need to be carried out and the requirements that need to be met in the development, deployment, and operation of the autonomous driving system. The above stages and activities are to ensure that the autonomous driving system can operate safely and reliably, meet user requirements and regulatory requirements.
[0144] Optionally, in the requirement analysis stage, the user's requirements and expectations can be clearly defined, and the system's function and performance requirements can be determined. The activities in this stage include communication with users, requirement collection and analysis, determination of system function requirements and performance indicators. In the design stage, the overall architecture of the system and the design of each module can be designed according to the results of the requirement analysis. The activities in this stage include system architecture design, module design, algorithm design, etc. In the development and testing stage, the software and hardware of the system can be actually developed and tested. The activities in this stage include coding, integration testing, system testing, performance testing, etc. In the deployment and operation stage, the system will be deployed to actual vehicles and start running. The activities in this stage include system deployment, user training, operation monitoring, etc.
[0145] In each stage of the activity, there are corresponding activity requirements, including but not limited to requirement documents, design documents, test plans, verification reports, etc. These requirement files record the design ideas, implementation methods, test results, etc. of the system in each stage, which helps to ensure that the system can meet user requirements and quality standards throughout its life cycle.
[0146] In summary, the understanding of the activities and activity requirements in each stage of the life cycle of the autonomous driving system helps the system to clearly define the process and requirements of system development, and ensures that the safety, reliability, and performance of the system meet the requirements of users and regulations.
[0147] Optionally, to improve the safety of intelligent driving, the International Standardization Organization working group (ISO / TC22 / SC32 / WG8) launched the research work of ISO 21448 in February 2016, and after 6 years of development, the first edition of the expected function safety standard was released in June 2022. ISO 21448 gives the activities and activity requirements in each stage of the life cycle of an autonomous driving system. In China, to improve the attention of enterprises to the development of expected function safety, the Ministry of Industry and Information Technology "Guidelines for Access Management of Intelligent Networked Vehicle Production Enterprises and Products (Trial)" and "Road Traffic Safety Law (Revised Draft)" etc. all make clear requirements for SOTIF, and put the expected function safety into the vehicle access examination items.
[0148] Optionally, although the international standards and domestic laws and regulations attach great importance to and require expected function safety, in the specific implementation process, there is a lack of clear and quantitative analysis, design, testing, evaluation methods and indicators, leading to a lack of unified path for the implementation and landing of the standards. Especially in the aspect of SOTIF demand analysis, due to the lack of unified and perfect methods, there are certain challenges in the completeness and accuracy of demand analysis. The unclear and quantitative SOTIF analysis, design, testing and evaluation methods and indicators may bring the following difficulties and challenges to enterprises and related institutions in the implementation of intelligent driving technology: 1) the unclearness of methods and indicators will lead to inconsistent methods used by different enterprises and institutions in SOTIF analysis, design, testing and evaluation, lack of unified standards, making it difficult to compare and verify the results; 2) the lack of clear and quantitative indicators and methods may cause the incompleteness and inaccuracy of SOTIF demand analysis, leading to potential risks and vulnerabilities in the design and implementation process of the system; 3) in the absence of clear SOTIF analysis, design, testing and evaluation methods and indicators, it may be difficult to ensure the safety and reliability of intelligent driving systems to meet the requirements of regulations and users, increasing the risk of system problems.
[0149] The embodiment of the application proposes a method for analyzing expected functional safety requirements, which has systematicity, completeness and rationality, and is used to ensure that the automatic driving system meets the expected functional safety requirements during the design and development process. By deductive analysis of expected functional safety function deficiency and trigger condition, the functions of the automatic driving system are analyzed to identify possible functional deficiencies or trigger condition deficiencies in the system. Functional deficiency refers to the function that the system cannot meet the user's expectations or design requirements, and trigger condition deficiency refers to the system's inability to correctly respond to certain specific trigger conditions. Through deductive analysis of these problems, potential risks and problems in the system can be determined. The analysis from the architecture elements to the vehicle-level hazard behavior analyzes the architecture elements of the system and traces back to the hazard behavior that may be caused at the vehicle level. This process helps to determine the relevance between the elements in the system and the hazard behavior that may be caused. This helps to identify potential risk points in the system design and ensures that the system will not cause hazard behavior during normal operation. By linking the functional deficiency and trigger condition with the hazard behavior through the architecture elements, the previously identified functional deficiency and trigger condition deficiency are associated and linked with the hazard behavior that may be caused. This helps to determine the key problems and risk points in the system design and lays the foundation for proposing expected functional safety requirements. By connecting these elements, potential problems in the system can be more clearly identified, and corresponding solutions can be proposed.
[0150] Through the above method, the systematicity, completeness and rationality of the expected functional safety requirement analysis can be ensured. This helps to identify potential safety risks early in the design and development process of the automatic driving system and propose corresponding preventive measures and improvement schemes to ensure the functional safety and reliability of the system. The application of this method helps to improve the safety level of the automatic driving system and ensure the safety of users and road traffic. Thus, the technical effect of effectively determining the expected functional safety requirements in the vehicle control system is achieved, and the technical problem of being unable to effectively determine the expected functional safety requirements in the vehicle control system is solved.
[0151] The following further introduces the embodiment of the application.
[0152] In the embodiment of the application, three analysis methods are proposed to solve the problems of expected functional safety design for intelligent driving systems.
[0153] Optionally, the functional safety deficiency and trigger condition deduction analysis method is expected to identify potential functional deficiencies and trigger condition deficiencies in the system through deductive analysis. By deeply analyzing and deducing the system functions and trigger conditions, it can help determine the possible functional defects or error responses of the system in certain situations. This helps to identify potential problems in advance and avoid functional defects in system design that may cause safety risks.
[0154] Optionally, the analysis method from architecture elements to vehicle hazard behavior is to analyze the relationship between the architecture elements of the system, trace how these elements are related to each other, and identify potential risk points that may lead to vehicle hazard behavior. By deeply understanding the overall architecture of the system and the interaction between elements, it can help identify key issues and potential risks in system design, so as to prevent potential hazard behavior in advance.
[0155] Optionally, the method of linking functional deficiencies and trigger conditions to hazard behavior through architecture elements and proposing expected functional safety requirements is to connect and associate the previously identified functional deficiencies and trigger condition deficiencies with the potential hazard behavior that may be triggered, and propose corresponding expected functional safety requirements. Through linkage analysis, potential problems in the system can be identified and corresponding solutions can be proposed to ensure that the system can safely operate in various situations. This helps to improve the safety and reliability of the system and ensures that safety factors are fully considered in the design and implementation process.
[0156] In the embodiment of the present application, through the application of the above three analysis methods, the functions and architecture of the system can be better understood, and potential safety problems and risks can be identified, so as to improve the safety and reliability of the system and ensure that the intelligent driving system can safely operate in various situations. The comprehensive application of these methods helps to improve the safety level of the intelligent driving system and ensure the safety of users and road traffic.
[0157] In this embodiment, Figure 2 is a flowchart of an expected functional safety requirement analysis method according to an embodiment of the present application, as Figure 2 shown, the method can include the following steps:
[0158] Step S201, design the control architecture of the intelligent driving system, and sort out the element list and output list of the control architecture.
[0159] In this embodiment, the control architecture of the intelligent driving function is designed. The contents include at least: system architecture elements; system architecture element inputs; system architecture element outputs.
[0160] Optionally, the control architecture should be defined according to the scope of functions, all elements within the scope of functions should be included, including vehicle internal elements, vehicle external elements, intelligent driving controller internal elements, etc.
[0161] For example, Table 1 is an example list of intelligent driving function system architecture elements in an embodiment of the present application. As shown in Table 1, the example list of elements of the intelligent driving function system architecture includes sensors, perception modules, decision modules, planning modules, control modules, and human-computer interaction modules, etc. The sensors can include: front main view camera (sensor-01), front narrow view camera (sensor-02), panoramic view camera (sensor-03), rear view camera (sensor-04), which are used to obtain visual information of the environment around the vehicle, including the scene in front, side and rear. Laser radar (sensor-05), millimeter wave radar (sensor-06), which are used to measure the distance and shape information of the environment around the vehicle, and can provide more accurate obstacle detection and tracking. The perception modules can include: front visual perception module (HAD-01), full visual perception module (HAD-02), Lidar perception module (HAD-03), which are responsible for processing the data obtained by the sensors, perceiving and recognizing the environment around the vehicle, and providing real-time environmental perception information. Map positioning module (HAD-04) is used for positioning of the vehicle and processing of map data, helping the vehicle to accurately position and navigate. Multi-sensor fusion module (HAD-05) processes the data fused by different sensors, improving the accuracy and robustness of environmental perception. Prediction module (HAD-06) predicts the behavior of other vehicles, pedestrians, etc. according to the environmental perception information and historical data, providing reference for decision making.
[0162] For example, as shown in Table 1, a decision module, a planning module, and a control module can also be included. The decision module (HAD-07) makes specific driving decisions such as acceleration, deceleration, and steering based on the information provided by the perception module and the prediction module. The planning module (HAD-08) plans the driving path of the vehicle based on the driving instructions generated by the decision module to ensure safe and efficient driving of the vehicle. The control module (HAD-09) is responsible for converting the path generated by the planning module into actual control instructions to control the steering, acceleration, and braking of the vehicle. Control actuators such as steering actuators (control-01), drive actuators (control-02), braking actuators (control-03), and parking actuators (control-04) can also be included. The above actuators are responsible for executing the control instructions generated by the control module to realize the automatic control function of the vehicle. A human-machine interaction module (Human-Machine Interface, HMI) (HMI-01) can also be included to interact with the driver, display system status and warning information to the driver, and accept driver input.
[0163] The above architecture elements constitute the key components of the intelligent driving function system, and the cooperation and interaction between them can realize the automatic driving function of the vehicle and improve the safety, comfort, and efficiency of driving. Through detailed analysis of these architecture elements, the working principle and function implementation of the intelligent driving system can be better understood.
[0164] Table 1: Example list of intelligent driving function system architecture elements
[0165] Architecture element number Architecture element sensor-01 Front main-view camera sensor-02 Front narrow-view camera sensor-03 Perimeter-view camera sensor-04 Rear-view camera sensor-05 Laser radar sensor-06 Millimeter wave radar HAD-01 Front-view perception module HAD-02 All-view perception module HAD-03 Lidar perception module HAD-04 Map positioning module HAD-05 Multi-sensor fusion module HAD-06 Prediction module HAD-07 Decision module HAD-08 Planning module HAD-09 Control module control-01 Steering actuator control-02 Driving actuator control-03 Braking actuator control-04 Parking actuator HMI-01 HMI …… ……
[0166] For example, the input and output of the architecture elements are used to clarify the interaction between the architecture elements, and the output of the architecture elements is shown in Table 2. Table 2 is an example list of intelligent driving function system architecture element outputs according to an embodiment of the present application. As shown in Table 2, in the intelligent driving function system architecture, the output of the architecture elements plays a crucial role in the normal operation and decision-making of the system. The output information of the architecture elements is the key data of the intelligent driving system, through which the system can perceive and understand the environment around the vehicle in real time, identify obstacles, traffic signs, and lines, etc., to provide accurate input for the decision module and the planning module, and help the system make safe and efficient driving decisions. These output information is crucial for the correct operation of the intelligent driving system and the safety of driving.
[0167] Table 2: Example list of intelligent driving function system architecture element outputs
[0168]
[0169] Step S202, comb the control behavior, apply the keyword to get the unsafe control behavior, and link it with the hazard behavior.
[0170] In this embodiment, for each external output of the intelligent driving master controller, it is defined as a control behavior, and the control behavior list is sorted out. For each control behavior, the unsafe control behavior is obtained by applying the keyword. The selected keyword is: should be provided but not provided, provided too early or too late, provided too much or too little, provided in the opposite direction, provided too early or applied for too long, provided unexpectedly. For each unsafe control behavior, link it with the hazard behavior.
[0171] For example, Table 3 is an example list of unsafe control behaviors obtained by the embodiment of the present application. As shown in Table 3, by linking the unsafe control behavior with the hazard behavior, the specific hazards that each unsafe control behavior may cause can be clearly pointed out. For example, when the intelligent driving master controller provides a steering instruction, if the steering instruction provided is in the opposite direction, it may cause the system to provide a reverse steering torque, thereby causing the hazard behavior of the system to lose the lateral control function in the intelligent driving function activated state. Through the analysis of the unsafe control behavior and its potential hazards, the system designer and developer can identify potential safety risks and take corresponding measures to reduce the probability of occurrence of these risks, thereby improving the safety and reliability of the system. This analysis method helps to comprehensively evaluate and improve the system.
[0172] Table 3 Unsafe Control Behavior Example List
[0173]
[0174] Step S203, triggered from the architecture element, for each output, determine whether it affects each control behavior, and obtain the link relationship table of architecture element, element output, control behavior, unsafe control behavior, and hazard behavior.
[0175] In this embodiment, starting from the architecture element, for each output, determine whether it affects each control behavior. The link relationship from the architecture element to the control behavior, to the unsafe control behavior, and to the hazard behavior.
[0176] For example, Table 4 is an example list of intelligent driving function system architecture element outputs according to an embodiment of the present application. As shown in Table 4, an example list of intelligent driving function system architecture element outputs is shown, as well as their linkages with control behaviors, unsafe control behaviors, and hazardous behaviors. The numbers and names of different architecture elements are listed, as well as their output contents, such as the video stream output by the front main camera, the obstacle output by the front vision perception module, etc. The numbers and descriptions of control behaviors are listed, as well as the judgment of whether the output of the architecture element will affect the control behavior. For example, the video stream output by the architecture element front main camera has an impact on the control behavior "intelligent driving master controller provides steering instruction". Specific unsafe control behaviors and possible hazardous behaviors are shown. For example, for the control behavior "intelligent driving master controller provides steering instruction", if the intelligent driving master controller does not send a steering instruction to the actuator, it may cause the hazardous behavior of loss of lateral control function in the intelligent driving function active state.
[0177] Through this way of display and analysis, the correlation between architecture element outputs, control behaviors, unsafe control behaviors, and hazardous behaviors can be clearly understood. This helps system designers and developers to identify potential risks and safety problems in the system, take timely measures for improvement and optimization, and improve the safety and reliability of the system. The above analysis method is helpful for safety evaluation and risk management of the system, to ensure that the intelligent driving system can safely and reliably operate in various situations.
[0178] Table 4: Example list of intelligent driving function system architecture element outputs
[0179]
[0180]
[0181]
[0182] Step S204: Starting from the architecture elements, the potential functional deficiencies and triggering conditions are analyzed in a deductive manner.
[0183] In this embodiment, starting from each architecture element, the potential functional deficiencies and triggering conditions are analyzed in a deductive manner.
[0184] Optionally, for sensors, there are two analysis dimensions, including: installation position, internal and external parameter calibration, vibration, temperature influence, aging / corrosion, electromagnetic interference, etc. Another is the analysis dimension of sensor-specific characteristics, such as cameras which can be analyzed from the dimensions of weak color contrast or light and dark contrast, strong light conditions, weak light conditions, etc.
[0185] Optionally, for algorithmic classes, there are also two analysis dimensions, where the common analysis dimensions include: model robustness, labeling process systematic errors, training dataset insufficiency, model generalization, vehicle motion posture, communication bandwidth, computational load, etc. The other is the analysis dimension of algorithm-specific characteristics, such as visual perception can be analyzed from the dimensions of floating objects, weather, unconventional vehicles, unconventional pedestrians, unconventional lane lines, construction areas, etc.
[0186] Optionally, potential functional deficiencies can also be analyzed first, or trigger conditions can also be analyzed first. The types of trigger conditions include: sensor disturbance, traffic disturbance, vehicle control disturbance, and personnel misuse.
[0187] For example, Table 5 is a potential functional deficiency and trigger condition analysis example list according to an embodiment of the present application, as shown in Table 5, potential functional deficiency and trigger condition analysis examples of two architecture elements are given, which are sensor-01 and HAD-01. For sensor-01 (front main view camera), its potential functional deficiency description includes installation position, internal and external parameter calibration, vibration, temperature influence, aging / corrosion, and electromagnetic interference, etc. Specifically, its specific characteristics are weak color contrast or light and dark contrast, which leads to the inability to correctly identify the target object under strong light or weak light conditions. Trigger conditions include strong light conditions (such as strong sunlight in the afternoon, opposite vehicle turning on high beam) and weak light conditions, etc. For HAD-01 (front visual perception module), its potential functional deficiency description includes model robustness, labeling process systematic errors, training dataset insufficiency, model generalization, vehicle motion posture, communication bandwidth, and computational load, etc. Its specific characteristics are the inability to correctly identify floating objects (such as fallen leaves, paper, garbage bags, etc.), weather influences (such as rain, snow, fog, high-density dust, etc.), and unconventional target objects (such as unconventional vehicles, unconventional pedestrians, unconventional lane lines, and construction areas, etc.). Trigger conditions include floating objects blocking the sensor surface, weather influences causing target pixel blur, and unconventional target objects appearing in the field of view.
[0188] In summary, detailed analysis of potential functional deficiencies and trigger conditions of architecture elements can help identify problems and propose solutions to ensure the stability and reliability of the system.
[0189] Table 5 Potential functional deficiency and trigger condition analysis example list
[0190]
[0191]
[0192] Step S205, link each item of functional deficiency and trigger condition with the hazardous behavior through the architecture element, and make judgments and arrangements.
[0193] In this embodiment, the link between the architecture element and the hazardous behavior has been formed in step S203, and the link between the architecture element and the potential functional deficiency and trigger condition has been formed in step S204. Therefore, each functional deficiency and trigger condition can be linked to the hazardous behavior through the architecture element, and then judged and sorted, mainly judging the relevance of the functional deficiency and trigger condition to the hazardous behavior, which is divided into three levels of high / medium / low.
[0194] For example, Table 6 is an example list of relevance analysis between potential functional deficiencies and trigger conditions and hazardous behaviors according to an embodiment of the present application, as shown in Table 6, which lists examples of relevance analysis between potential functional deficiencies and trigger conditions and hazardous behaviors.
[0195] For example, as shown in Table 6, taking sensor-01 and HAD-01 as an example, sensor-01 is a front-facing camera, the potential functional deficiency is described as the performance deficiency of color contrast and brightness contrast of the front-facing camera, and the trigger condition is described as the target object having weak color contrast or light-dark contrast, such as white lane lines in strong light, green vehicles in green forest background, and black clothing pedestrians in front of black vehicles. The relevance analysis shows that in the activated state of the intelligent driving function, it may cause the loss of lateral control function, the system to provide unintended steering torque, to provide excessive / small steering torque, to provide reverse steering torque, the loss of longitudinal control function, the system to provide unintended excessive deceleration, to provide too small / lost deceleration, and other hazardous behaviors. Among them, the abnormal provision degree of steering torque and the loss degree of longitudinal control function are evaluated as high risk. HAD-01 is a front vision perception module, the potential functional deficiency is described as the vision perception module being unable to correctly recognize, and the trigger condition is described as the items shielding the sensor surface causing the vision sensor to have incomplete consecutive frames. The relevance analysis shows that in the activated state of the intelligent driving function, it may cause the loss of lateral control function, the system to provide unintended steering torque, to provide excessive / small steering torque, to provide reverse steering torque, the loss of longitudinal control function, the system to provide unintended excessive deceleration, to provide too small / lost deceleration, and other hazardous behaviors. Among them, the abnormal provision degree of steering torque and the loss degree of longitudinal control function are evaluated as high risk.
[0196] By analyzing the examples in Table 6, it can be concluded that there is a certain correlation between potential functional deficiencies and trigger conditions and hazardous behaviors. By analyzing these correlations, potential safety problems can be better identified and solved, thereby improving the safety and reliability of intelligent driving systems.
[0197] Table 6: Example list of relevance analysis between potential functional deficiencies and trigger conditions and hazardous behaviors
[0198]
[0199]
[0200]
[0201] Step S206, according to the functional deficiency, trigger condition, harmful behavior, the expected functional safety requirement is proposed.
[0202] In this embodiment, according to the results analyzed in step S205, the expected functional safety requirement is proposed for the functional deficiency, trigger condition, harmful behavior.
[0203] For example, Table 7 is an example list of expected functional safety requirement analysis according to an embodiment of the present application. As shown in Table 7, if the potential functional deficiency, trigger condition, harmful behavior, relevance analysis and expected functional safety requirement of the front main view camera for the architecture element are described in detail. Potential functional deficiency description: the color contrast and brightness contrast performance of the front main view camera is insufficient, which may cause the camera to fail to accurately identify the target object in the case of the target object having weak color contrast or light and dark contrast, such as white lane lines in strong light, green vehicles in green forest background, etc. Trigger condition description: the trigger condition is that the target object has weak color contrast or light and dark contrast in the intelligent driving function activated state, such as white lane lines in strong light, green vehicles in green forest background, etc. These conditions may cause the system to lose, provide unexpected steering torque or provide excessive steering torque in the lateral control function. Harmful behavior description: according to the trigger condition, it may cause the loss of lateral control function, the system to provide unexpected steering torque or provide excessive steering torque in the intelligent driving function activated state, which may affect the handling and safety of the vehicle.
[0204] As shown in Table 7, through relevance analysis, the relevance between potential functional deficiency, trigger condition and harmful behavior is evaluated, and the risk level of different harmful behaviors is determined from low to high. According to the analysis of potential functional deficiency and trigger condition, the expected functional safety requirement is proposed, that is, the sensor should avoid reducing the sensing accuracy for target objects, lane lines, road edges, etc. with weak color contrast or light and dark contrast, in order to avoid causing harmful behaviors such as loss of lateral control function, system to provide unexpected steering torque or provide excessive steering torque.
[0205] By analyzing the content in Table 7, it can be seen that the functional deficiency, trigger condition and harmful behavior of the system architecture element are analyzed in detail in order to identify potential problems and risks, and to propose corresponding functional safety requirements to ensure the safety and reliability of the intelligent driving system. Such analysis helps designers to understand the potential risks that may exist in the system, and to take timely measures to improve and optimize.
[0206] Table 7 is an example list of expected functional safety requirement analysis
[0207]
[0208]
[0209]
[0210]
[0211]
[0212]
[0213]
[0214]
[0215] In the embodiment of the present application, if the expected functional safety requirement of the vehicle control system needs to be determined, the control element set and the output information set in the vehicle control system can be determined, and the corresponding control behavior set can be sorted out. Each control behavior in the control behavior set is analyzed to determine the risk hidden therein, and the corresponding abnormal control behavior is obtained. The abnormal behavior result caused in the vehicle by the abnormal control behavior can be determined. The relationship between the control element set, the output information set, the control behavior set, the abnormal control behavior and the abnormal behavior result is linked to obtain the corresponding linking result. The functional defects of each control element in the control element set are analyzed from the linking result to obtain the functional defect result set. According to the functional defect result set and the linking result, the expected functional safety requirement of the vehicle control system can be proposed. In this embodiment, through the above method, the hazard behavior of the whole vehicle can be traced back from each control element in the vehicle control system, so that a perfect and unified requirement analysis is formed. Further, the technical effect that the expected functional safety requirement of the vehicle control system can be effectively determined is realized, and the technical problem that the expected functional safety requirement of the vehicle control system cannot be effectively determined is solved.
[0216] According to the embodiment of the present application, a vehicle control system expected functional safety requirement determination device is also provided. It should be noted that the vehicle control system expected functional safety requirement determination device can be used to execute the vehicle control system expected functional safety requirement determination method in the above embodiment.
[0217] Figure 3 FIG. 1 is a schematic diagram of a vehicle control system expected functional safety requirement determination device according to an embodiment of the present application. As shown in FIG. 1, the vehicle control system expected functional safety requirement determination device includes a control element set determination unit 10, an output information set determination unit 20, a control behavior set determination unit 30, an abnormal control behavior determination unit 40, an abnormal behavior result determination unit 50, a linking result determination unit 60, a functional defect result set determination unit 70, and a functional safety requirement determination unit 80. Figure 3As shown, the determination apparatus 300 of the expected functional safety requirement in the vehicle control system can include an acquisition unit 302, a first determination unit 304, a linking unit 306, a second determination unit 308, and a third determination unit 310.
[0218] The acquisition unit 302 is configured to acquire a control element set of a vehicle control system of a vehicle, and an output information set and a control action set corresponding to the control element set, wherein the control element set includes at least one control element, the output information set includes at least one output information, the output information is obtained by controlling the control element, and the control action set includes at least one control action, the control action is issued by the vehicle control system and is used to control the behavior of the control element.
[0219] The first determination unit 304 is configured to determine at least one abnormal control action corresponding to at least one control action in the control action set, and determine at least one abnormal behavior result associated with the at least one abnormal control action, wherein the abnormal behavior result is used to represent the abnormal influence on the vehicle caused by executing the abnormal control action.
[0220] The linking unit 306 is configured to link the relationships between the control element set, the output information set, the control action set, the abnormal control action, and the abnormal behavior result, to obtain a linking result.
[0221] The second determination unit 308 is configured to determine a functional defect result set corresponding to the control element set based on the linking result, wherein the functional defect result set includes at least one functional defect result, and the functional defect result is used to represent a functional defect existing in the corresponding control element in the control element set.
[0222] The third determination unit 310 is configured to determine the expected functional safety requirement of the vehicle control system based on the linking result and the functional defect result set, wherein the expected functional safety requirement is used to represent a strategy to be executed to overcome the functional defect.
[0223] Optionally, the acquisition unit 302 can include a first acquisition module configured to acquire input information of at least one control element in the control element set, a first determination module configured to determine output information corresponding to the at least one control element based on the input information and the corresponding control element, and a second determination module configured to obtain the output information set based on the output information corresponding to the at least one control element in the control element set.
[0224] Optionally, the first determination unit 304 can include an application module configured to apply a keyword to at least one control action in the control action set to obtain the corresponding abnormal control action, wherein the keyword is used to identify problems existing when the control action is executed.
[0225] Optionally, the linking unit 306 can include: a detection module, configured to detect at least one output information in the output information set and at least one control behavior in the control behavior set to obtain a detection result, where the detection result is used to indicate whether the output information can affect the corresponding control behavior; and a third determination module, configured to obtain the linking relationship table based on the control element set, the output information set, the control behavior set, the abnormal control behavior, the abnormal behavior result, and the detection result.
[0226] Optionally, the second determination unit 308 can include: a second acquisition module, configured to acquire type information of at least one control element in the linking result; a fourth determination module, configured to determine a defect analysis dimension corresponding to the at least one control element and corresponding defect analysis information under the defect analysis dimension based on the type information; a fifth determination module, configured to determine a corresponding function defect information set and a trigger condition set under the defect analysis information; and a linking module, configured to link a relationship between the function defect information set and the trigger condition set to obtain a function defect result set.
[0227] Optionally, the fourth determination module can include: a first determination submodule, configured to, in response to the type information being a sensor type, determine that the first defect analysis dimension at least includes one of the following: an installation position of the control element, a vibration condition of the control element, a temperature condition of the control element, and an aging degree of the control element; and a second determination submodule, configured to, in response to the type information being an algorithm type, determine that the first defect analysis dimension at least includes one of the following: model robustness of the control element and model generalization of the control element.
[0228] Optionally, the apparatus can further include: a first linking unit, configured to link a relationship between the linking result and the function defect result to obtain a target linking result; and a fourth determination unit, configured to determine, from the target linking result, an association attribute between the abnormal behavior result and the defect information set and the trigger condition set, where the association attribute is used to indicate an association degree between the abnormal behavior result and the defect information set and the trigger condition set.
[0229] Optionally, the third determination unit 310 can include a sixth determination module, configured to determine an expected function safety requirement based on the target linking result and the association attribute.
[0230] In the embodiment of the present application, the control element set of the vehicle control system of the vehicle is acquired by the acquisition unit 302, and the output information set and the control behavior set corresponding to the control element set are acquired; at least one abnormal control behavior corresponding to at least one control behavior in the control behavior set is determined by the first determination unit 304, and at least one abnormal behavior result associated with the at least one abnormal control behavior is determined; the relationship between the control element set, the output information set, the control behavior set, the abnormal control behavior and the abnormal behavior result is linked by the linking unit 306 to obtain a linking result; the function defect result set corresponding to the control element set is determined based on the linking result by the second determination unit 308; the expected functional safety requirement of the vehicle control system is determined based on the linking result and the function defect result set by the third determination unit 310, thereby solving the technical problem that the expected functional safety requirement in the vehicle control system cannot be effectively determined, and achieving the technical effect that the expected functional safety requirement in the vehicle control system can be effectively determined.
[0231] According to the embodiment of the present application, a computer readable storage medium is also provided, which includes a stored program, wherein the program executes the determination method of the expected functional safety requirement in the vehicle control system in the above-mentioned embodiments.
[0232] According to the embodiment of the present application, a processor is also provided, which is used to run a program, wherein the program runs to execute the determination method of the expected functional safety requirement in the vehicle control system in the above-mentioned embodiments.
[0233] The embodiment of the present application also provides a computer program product. Optionally, in the embodiment, the computer program product can include a computer program, and the computer program implements the determination method of the expected functional safety requirement in the vehicle control system of the above-mentioned embodiment of the present application when executed by the processor.
[0234] According to the embodiment of the present application, a vehicle is also provided, which is used to execute the determination method of the expected functional safety requirement in the vehicle control system of the embodiment of the present application.
[0235] In the above-mentioned embodiments of the present application, the description of each embodiment has its own focus, and the part not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0236] In several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented in other manners. For example, the described unit embodiments can be divided into other ways, for example, the units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, access layers, or middleware layers, and can be in electrical, mechanical, or other forms.
[0237] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, can be located in one place, or can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0238] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can be physically present alone, or two or more units can be integrated into one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0239] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the present application, essentially or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0240] The above description is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, several improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present application.
Claims
1. A method for determining expected functional safety requirements in a vehicle control system, characterized in that, include: The system acquires a set of control elements of the vehicle control system, as well as a set of output information and a set of control behaviors corresponding to the set of control elements. The set of control elements includes at least one control element, the set of output information includes at least one output information, the output information is obtained by controlling the control element, and the set of control behaviors includes at least one control behavior, the control behavior is issued by the vehicle control system to control the execution of the control element. Determine at least one abnormal control behavior corresponding to at least one control behavior in the set of control behaviors, and determine at least one abnormal behavior result associated with at least one of the abnormal control behaviors, wherein the abnormal behavior result is used to represent the abnormal impact of executing the abnormal control behavior on the vehicle. Link the relationships between the control element set, the output information set, the control behavior set, the abnormal control behavior, and the abnormal behavior result to obtain the linking result; Based on the linking results, a functional defect result set corresponding to the control element set is determined, wherein the functional defect result set includes at least one functional defect result, which is used to represent the functional defect existing in the control element corresponding to the control element set; Based on the linking results and the functional defect result set, the expected functional safety requirements of the vehicle control system are determined, wherein the expected functional safety requirements represent the strategies to be implemented to overcome the functional defects. Specifically, determining the functional defect result set corresponding to the control element set based on the linking results includes: obtaining type information of at least one control element in the control element set from the linking results; determining the defect analysis dimension corresponding to at least one control element and the corresponding defect analysis information under the defect analysis dimension based on the type information; determining the corresponding functional defect information set and trigger condition set under the defect analysis information; and linking the relationship between the functional defect information set and the trigger condition set to obtain the functional defect result set.
2. The method according to claim 1, characterized in that, Obtaining the output information set corresponding to the control element set includes: Obtain input information from at least one of the control elements in the control element set; Based on the input information and the corresponding control element, determine the output information corresponding to at least one of the control elements; The output information set is obtained based on the output information corresponding to at least one of the control elements in the control element set.
3. The method according to claim 1, characterized in that, Determining at least one abnormal control behavior corresponding to at least one control behavior in the set of control behaviors includes: By applying keywords to at least one of the control behaviors in the set of control behaviors, the corresponding abnormal control behavior is obtained, wherein the keywords are used to identify problems that exist when executing the control behavior.
4. The method according to claim 3, characterized in that, The keywords include at least one of the following: a first keyword, a second keyword, a third keyword, a fourth keyword, a fifth keyword, and a sixth keyword, wherein the first keyword indicates that the control behavior was not executed when it was required; the second keyword indicates that the execution time of the control behavior exceeded a time range threshold; the third keyword indicates that the degree of execution of the control behavior exceeded a degree range threshold; the fourth keyword indicates that the direction of execution of the control behavior was abnormal; the fifth keyword indicates that the end time of the control behavior was earlier than the target time, and / or that the duration of execution of the control behavior exceeded a duration threshold; and the sixth keyword indicates that the control behavior was executed when it was not required.
5. The method according to claim 4, characterized in that, The linking result is a link relationship table, wherein the relationships between the control element set, the output information set, the control behavior set, the abnormal control behavior, and the abnormal behavior result are linked to obtain the linking result, including: At least one output information in the output information set and at least one control behavior in the control behavior set are detected to obtain a detection result, wherein the detection result is used to indicate whether the output information can affect the corresponding control behavior; The link relationship table is obtained based on the control element set, the output information set, the control behavior set, the abnormal control behavior, the abnormal behavior result, and the detection result.
6. The method according to claim 1, characterized in that, The defect analysis dimension includes a first defect analysis dimension and a second defect analysis dimension. The first defect analysis dimension is a common defect analysis dimension for the control elements, and the second defect analysis dimension is a defect analysis dimension unique to different control elements. Based on the type information, determining the defect analysis dimension corresponding to at least one control element, and the corresponding defect analysis information under that defect analysis dimension, includes: In response to the type information being a sensor type, the first defect analysis dimension is determined to include at least one of the following: the installation location of the control element, the vibration status of the control element, the temperature status of the control element, and the aging degree of the control element; In response to the type information being an algorithm type, the first defect analysis dimension is determined to include at least one of the following: the model robustness of the control element, and the model generalization of the control element.
7. The method according to claim 1, characterized in that, The triggering conditions set includes at least one of the following types: the control element is disturbed, the vehicle's environment is disturbed, the vehicle control is disturbed, or the target object in the vehicle is misused.
8. The method according to claim 1, characterized in that, Before determining the expected functional safety requirements of the vehicle control system based on the linking results and the functional defect result set, the method further includes: Link the relationship between the linking results and the functional defect results to obtain the target linking results; The abnormal behavior result is determined from the target link result, and the association attribute between it and the defect information set and the trigger condition set is determined, wherein the association attribute is used to represent the degree of association between the abnormal behavior result and the defect information set and the trigger condition set.
9. The method according to claim 8, characterized in that, Based on the linking results and the functional defect result set, the expected functional safety requirements of the vehicle control system are determined, including: Based on the target link results and the associated attributes, the expected functional security requirements are determined.
10. A device for determining expected functional safety requirements in a vehicle control system, characterized in that, include: The acquisition unit is used to acquire a set of control elements of the vehicle control system of the vehicle, as well as a set of output information and a set of control behaviors corresponding to the set of control elements. The set of control elements includes at least one control element, the set of output information includes at least one output information, the output information is obtained by controlling the control element, and the set of control behaviors includes at least one control behavior, the control behavior is issued by the vehicle control system to control the execution of the control element. The first determining unit is configured to determine at least one abnormal control behavior corresponding to at least one control behavior in the set of control behaviors, and to determine at least one abnormal behavior result associated with at least one of the abnormal control behaviors, wherein the abnormal behavior result is used to represent the abnormal impact of executing the abnormal control behavior on the vehicle. The linking unit is used to link the relationships between the control element set, the output information set, the control behavior set, the abnormal control behavior, and the abnormal behavior result to obtain the linking result; The second determining unit is used to determine the functional defect result set corresponding to the control element set based on the linking result, wherein the functional defect result set includes at least one functional defect result, which is used to represent the functional defect existing in the control element corresponding to the control element set. The third determining unit is used to determine the expected functional safety requirements of the vehicle control system based on the linking results and the functional defect result set, wherein the expected functional safety requirements are used to represent the strategies to be implemented to overcome the functional defects; The second determining unit is configured to perform the following steps to determine the functional defect result set: obtain type information of at least one control element in the control element set of the linking results; based on the type information, determine the defect analysis dimension corresponding to the at least one control element, and the defect analysis information corresponding to the defect analysis dimension; determine the corresponding functional defect information set and trigger condition set under the defect analysis information; link the relationship between the functional defect information set and the trigger condition set to obtain the functional defect result set.
11. A processor, characterized in that, The processor is used to run a program, wherein the program, when run by the processor, performs the method for determining the expected functional safety requirements in the vehicle control system according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform the method for determining the expected functional safety requirements in the vehicle control system according to any one of claims 1 to 9.
13. An electronic device, characterized in that, It includes a memory and a processor, the memory storing a computer program, and the processor being configured to run the computer program to perform a method for determining expected functional safety requirements in a vehicle control system according to any one of claims 1 to 9.
14. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements a method for determining the expected functional safety requirements in a vehicle control system according to any one of claims 1 to 9.
15. A vehicle, characterized in that, A method for determining the expected functional safety requirements in a vehicle control system as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Intelligent vehicle transverse control system function safety concept stage analysis method
CN112849262A
STPA-based automatic emergency braking system expected function safety demand analysis method
CN117622216A