Method for generating fusion security requirements, electronic device and storage medium

By defining relevant items and functional design specifications for lateral control functions, conducting hazard and operability analysis, obtaining a list of hazard events, identifying target hazard events, and establishing a functional safety architecture, the problem of low safety and reliability of vehicle lateral control functions in existing technologies is solved, resulting in a shorter development cycle and improved safety.

CN119142352BActive Publication Date: 2026-06-02SINO TRUK JINAN POWER CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SINO TRUK JINAN POWER CO LTD
Filing Date
2024-08-26
Publication Date
2026-06-02

Smart Images

  • Figure CN119142352B_ABST
    Figure CN119142352B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of fusion security demand generation method, electronic equipment and storage medium.The method is in the development process of heavy vehicle automatic lateral control function, define the lateral control function related item including implementation function and expected function, obtain the hazard event of lateral control function related item by hazard and operability analysis, obtain the safety target of hazard event, vehicle safety integrity level and residual risk acceptance by hazard and risk analysis method, according to vehicle safety integrity level and residual risk acceptance, obtain target risk level in risk level table, establish function safety architecture according to target risk level and safety target, obtain safety constraint condition based on function safety architecture, and safety constraint body condition is converted into target safety demand, to analyze the hazard caused by lateral control failure and expected function deficiency, improve the development efficiency of automatic lateral control function, reduce development cycle, improve reliability and safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to intelligent connected vehicle technology, and more particularly to a method for generating integrated safety requirements, electronic devices, and storage media. Background Technology

[0002] With the rapid development of intelligence and connectivity, the information domain and physical domain of intelligent connected vehicles are accelerating their integration. Functional safety and expected functional safety are intertwined, mutually influential, and mutually coupled, and may even transform and derive from each other under specific conditions.

[0003] Existing solutions typically involve separate safety analyses and designs for the development of functional safety and expected functional safety for vehicle lateral control. However, analyzing functional safety and expected functional safety separately leads to a long development cycle and incomplete safety requirements, which in turn can result in hazards.

[0004] Therefore, existing solutions, when developing functional safety requirements for vehicle lateral control, involve separate and independent analyses of functional safety and expected functional safety, resulting in a long development cycle and incomplete safety requirements, thus leading to low safety and reliability of vehicle lateral control functions. Summary of the Invention

[0005] This application provides a method for generating integrated safety requirements, an electronic device, and a storage medium to shorten the development cycle and improve safety requirements when developing functional safety requirements for vehicle lateral control, thereby enhancing the safety and reliability of vehicle lateral control functions.

[0006] In a first aspect, embodiments of this application provide a method for generating integrated security requirements, including:

[0007] Define lateral control function related items and functional design specifications. The lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle. The lateral realized functions are used to indicate the lane keeping function. The functional design specifications are used to indicate the vehicle's status information and operating environment.

[0008] Hazard and operability analysis is conducted to obtain a list of hazard events related to the lateral control function, and target hazard events are identified in the list of hazard events by keyword.

[0009] The safety objectives, vehicle safety integrity level, and residual risk tolerance of the target hazard event are obtained through hazard and risk analysis methods.

[0010] Based on the vehicle safety integrity level and residual risk tolerance, a target risk level is obtained, and a functional safety architecture is established based on the target risk level and the safety objective.

[0011] Based on the functional safety architecture, security constraints are obtained, and the security constraints are transformed into target security requirements.

[0012] In one possible implementation, the lateral anticipation functions include: function activation, function deactivation, lane line recognition, judgment and decision-making, and function execution.

[0013] The function activation is used to indicate that the vehicle enters the lane keeping state, the function deactivation is used to indicate that the vehicle exits the lane keeping state, the lane line recognition is used to indicate the recognition distance between the vehicle and the lane lines on both sides, the judgment decision is used to indicate whether to activate the steering function based on the recognition distance, and the function execution is used to indicate the execution of the lane keeping function when the deviation distance between the vehicle's centerline and the lane centerline exceeds a threshold.

[0014] In one possible implementation, the status information includes: driving status, driver information, and equipment status, wherein the driving status is used to indicate changes in vehicle speed, the driver information is used to indicate the driver's identity information and driving status, and the equipment status is used to indicate whether each on-board device is operating normally.

[0015] The operating environment includes scene features and environmental information. The scene features are used to indicate the road type and road boundaries, and the environmental information is used to indicate the weather, lighting, and road surface conditions when the vehicle is driving.

[0016] In one possible implementation, obtaining a list of hazard events related to the lateral control function includes:

[0017] Based on the aforementioned functional design specifications, failure information for each function in the relevant items of the lateral control function is obtained through the aforementioned hazard and operability analysis.

[0018] Based on the failure information, the corresponding hazard events for each function are obtained. The list of hazard events includes the hazard events corresponding to each function. The failure information includes loss of steering request, excessive steering request angle, excessive steering request angle, reverse steering request, unexpected steering, and stuck steering request.

[0019] In one possible implementation, obtaining the safety objective, vehicle safety integrity level, and residual risk acceptance of the target hazard event includes:

[0020] Based on the aforementioned functional design specifications, the severity, exposure rate, and controllability of the target hazard event are obtained through the aforementioned hazard and risk analysis methods.

[0021] The vehicle safety integrity level is obtained based on the severity, exposure rate, and controllability, and the residual risk acceptance level is obtained based on the severity and controllability, wherein the residual risk acceptance level includes acceptable risk, conditionally tolerable risk, or unacceptable risk.

[0022] In one possible implementation, obtaining the target risk level based on the vehicle safety integrity level and residual risk acceptability includes:

[0023] In the risk level table, risk level information is obtained based on the combination of the vehicle safety integrity level and the residual risk acceptance level. The target risk level is determined through the risk level information, wherein the risk level information includes low, medium, high or severe.

[0024] The risk level table pre-stores a first mapping relationship and a second mapping relationship. The first mapping relationship is used to indicate the positive correlation between the vehicle safety integrity level and the risk level information, and the second mapping relationship is used to indicate the positive correlation between the residual risk acceptance and the risk level information.

[0025] In one possible implementation, a functional safety architecture is established based on the target risk level and the security objective, including:

[0026] When the target risk level is medium, high or severe, the functional safety architecture is established based on the security objective, and the functional safety architecture is used to reduce the target risk level to low.

[0027] When the target risk level is low, the functional safety architecture is not established.

[0028] Secondly, embodiments of this application provide a fusion security requirement generation apparatus, comprising:

[0029] The acquisition module is used to define lateral control function related items and functional design specifications. The lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle. The lateral realized functions are used to indicate the lane keeping function. The functional design specifications are used to indicate the vehicle's status information and operating environment.

[0030] The processing module is used to obtain a list of hazard events related to the lateral control function through hazard and operability analysis. In the list of hazard events, target hazard events are identified by keywords. The safety objectives, vehicle safety integrity level and residual risk acceptance of the target hazard events are obtained through hazard and risk analysis methods.

[0031] The control module is used to obtain a target risk level based on the vehicle safety integrity level and residual risk acceptance level, establish a functional safety architecture based on the target risk level and the safety objective, obtain safety constraints based on the functional safety architecture, and transform the safety constraints into target safety requirements.

[0032] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0033] The memory stores computer-executed instructions;

[0034] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0035] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0036] The integrated safety requirement generation method, electronic device, and storage medium provided in this application, during the development of automatic lateral control functions for heavy vehicles, define lateral control function-related items, including implemented and expected functions. Through hazard and operability analysis, a list of hazard events for these lateral control function-related items is obtained. Target hazard events are identified in this list. Through hazard and risk analysis methods, the safety objectives, vehicle safety integrity level, and residual risk acceptance of the target hazard events are obtained. Based on the vehicle safety integrity level and residual risk acceptance, the target risk level is obtained from a risk level table. A functional safety architecture is established based on the target risk level and safety objectives. Safety constraints are obtained based on the functional safety architecture and transformed into target safety requirements. This comprehensively analyzes the hazards caused by lateral control failures and insufficient expected functions, effectively improving the development efficiency of automatic lateral control, reducing the development cycle, and enhancing product reliability and safety. Attached Figure Description

[0037] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0038] Figure 1 Flowchart of the method for generating integrated security requirements provided in this application Figure 1 ;

[0039] Figure 2 Flowchart of the method for generating integrated security requirements provided in this application Figure 2 ;

[0040] Figure 3 The risk level diagram provided for this application;

[0041] Figure 4 A schematic diagram of the security architecture provided for this application;

[0042] Figure 5 A schematic diagram of the fusion security requirements generation device provided in this application;

[0043] Figure 6 A schematic diagram of the structure of the electronic device provided in this application.

[0044] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation

[0045] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0046] Intelligent connected vehicles are a new generation of cyber-physical systems equipped with advanced onboard sensors, controllers, and actuators, integrating modern communication and network technologies, artificial intelligence, and other capabilities, including complex environment perception, intelligent decision-making, and collaborative control. When developing functions such as lateral control in intelligent connected vehicles, functional safety and anticipated functional safety are indispensable components of the autonomous driving system design.

[0047] Based on existing industry standards, functional safety focuses on whether a system can enter a safe state after failure to avoid greater harm, while anticipated functional safety focuses on the inadequacy of anticipated functions at the vehicle level, the performance limitations of electronic and electrical system elements, and use cases where human misuse could lead to the activation or deactivation of functions. Current solutions typically develop functional safety and anticipated functional safety for vehicle lateral control separately. However, this approach results in lengthy development cycles and incomplete safety requirements, leading to lower safety and reliability of vehicle lateral control functions.

[0048] Therefore, this application provides a method for generating integrated safety requirements. During the development of automatic lateral control functions for heavy vehicles, it defines lateral control function-related items, including the implemented function and the expected function. Through hazard and operability analysis, it obtains a list of hazard events for these lateral control function-related items. Target hazard events are identified in this list. Through hazard and risk analysis, it obtains the safety objective, vehicle safety integrity level, and residual risk acceptance of the target hazard event. Based on the vehicle safety integrity level and residual risk acceptance, it obtains the target risk level from a risk level table. A functional safety architecture is established based on the target risk level and safety objective. Safety constraints are obtained based on the functional safety architecture and transformed into target safety requirements. This comprehensively analyzes the hazards caused by lateral control failure and insufficient expected function, effectively improving the development efficiency of automatic lateral control, reducing the development cycle, and enhancing product reliability and safety.

[0049] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0050] Figure 1 Flowchart of the method for generating integrated security requirements provided in this application Figure 1 ,like Figure 1 As shown, the method includes:

[0051] S101. Define lateral control function related items and functional design specifications. The lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle. The lateral realized functions are used to indicate the lane keeping function. The functional design specifications are used to indicate the vehicle's status information and operating environment.

[0052] Specifically, for the automatic lateral control function of heavy vehicles, the definition of fusion-related items and functional design specifications is defined. The definition of fusion-related items includes functional description, fusion safety boundaries and regulatory requirements, dependencies and interaction information with other systems in the vehicle, composition of the automatic lateral control system, and known performance limitations and functional deficiencies.

[0053] The functional description indicates the implemented and expected functions of automatic lateral control in the safety lifecycle. The expected functions include the vehicle-level SOTIF (Safety of the Intended Functionality) policy, use cases where the function may be activated or deactivated, the transition between activation and deactivation use cases, and the description of decision logic. The functional description also indicates the relevant system architecture and its components for implementing and expected functions, the potential consequences of insufficient behavior, performance limitations, reasonably foreseeable misuse identification trigger conditions, and countermeasures.

[0054] S102. Through hazard and operability analysis, obtain a list of hazard events related to the lateral control function. In the list of hazard events, identify target hazard events by keyword. Through hazard and risk analysis methods, obtain the safety objectives, vehicle safety integrity level, and residual risk acceptance of the target hazard events.

[0055] Specifically, after defining the relevant items and functional design specifications of the lateral control function, the functional failures of the lateral control are obtained through the Hazard and Operability Study (HAZOP) method, and performance deficiency analysis is performed. Based on the obtained functional failures, a fusion hazard event list is generated, which is a combination of scenarios and failures.

[0056] Furthermore, through hazard and risk analysis methods, we identify and classify each hazard event, i.e., acquire target hazard events, define acceptance criteria, define safety measures for hazard behaviors, and safety confirmation objectives derived from acceptance criteria. We then formulate integrated safety objectives to prevent hazard events from occurring or to mitigate their severity, i.e., acquire safety objectives for target hazard events, vehicle safety integrity levels, and residual risk acceptance.

[0057] S103. Based on the vehicle safety integrity level and residual risk tolerance, obtain the target risk level, and establish a functional safety architecture based on the target risk level and the safety objective.

[0058] Specifically, after obtaining the safety objectives, vehicle safety integrity level, and residual risk acceptance of the target hazard event, the target risk level of the target hazard event is obtained by looking up the vehicle safety integrity level and residual risk acceptance in a pre-set risk level table, that is, the fusion risk level is determined. The risk level table is used to indicate the risk assessment criteria for the fusion of functional safety and expected functional safety.

[0059] S104. Based on the functional safety architecture, obtain the safety constraints and transform the safety constraints into target safety requirements;

[0060] Specifically, after obtaining the functional safety architecture, unsafe control behaviors are identified and analyzed based on the architecture to determine safety constraints. These constraints can be safety mechanisms, algorithm requirements, sensor / controller performance requirements, and driver behavior requirements. The safety constraints are then refined into target safety requirements, which include functional safety requirements and anticipated functional safety requirements.

[0061] This application provides a method for generating integrated safety requirements. During the development of automatic lateral control functions for heavy vehicles, it defines lateral control function-related items, including implemented and expected functions. Through hazard and operability analysis, a list of hazard events for these lateral control function-related items is obtained. Target hazard events are identified in this list. Through hazard and risk analysis, the safety objectives, vehicle safety integrity level, and residual risk acceptance of the target hazard events are obtained. Based on the vehicle safety integrity level and residual risk acceptance, the target risk level is obtained from a risk level table. A functional safety architecture is established based on the target risk level and safety objectives. Safety constraints are obtained based on the functional safety architecture and transformed into target safety requirements. This comprehensively analyzes the hazards caused by lateral control failures and insufficient expected functions, effectively improving the development efficiency of automatic lateral control, reducing the development cycle, and enhancing product reliability and safety.

[0062] Figure 2 Flowchart of the method for generating integrated security requirements provided in this application Figure 2 , Figure 3 The risk level diagram provided for this application Figure 4 The security architecture diagram provided in this application, combined with Figure 2 , Figure 3 and Figure 4 As shown, the method for generating integrated security requirements is described in detail. This method includes:

[0063] S201. Define lateral control function related items and functional design specifications, wherein the lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle;

[0064] Specifically, the lateral anticipation function includes: function activation, function deactivation, lane line recognition, judgment and decision, and function execution. Function activation instructs the vehicle to enter lane-keeping mode; function deactivation instructs the vehicle to exit lane-keeping mode; lane line recognition indicates the recognition distance between the vehicle and the lane lines on both sides; judgment and decision instructs whether to activate the steering function based on the recognition distance; function execution instructs the execution of the lane-keeping function when the deviation between the vehicle's centerline and the lane centerline exceeds a threshold; and the lateral implementation function instructs whether lane-keeping is needed based on the current vehicle conditions and executes lane-keeping when necessary. Further, the relevant items for the lateral control function are shown in the table below:

[0065]

[0066] Furthermore, the functional design specifications indicate the vehicle's status information and operating environment. Status information includes driving status, driver information, and equipment status. Driving status indicates changes in vehicle speed; driver information indicates the driver's identity and driving status; equipment status indicates whether each onboard device is operating normally; and the operating environment includes scene characteristics and environmental information. Scene characteristics indicate road type and road boundaries, while environmental information indicates weather, lighting, and road surface conditions during vehicle operation. The functional design specifications are shown in the table below:

[0067]

[0068] S202. Based on the functional design specifications, obtain the failure information of each function in the relevant items of the horizontal control function through the hazard and operability analysis;

[0069] Specifically, after defining the relevant items and functional design specifications for lateral control functions, the HAZOP method (Hazard and Operability Analysis) built into the MA tool is used to create functional failures for intelligent lateral control and perform performance deficiency analysis. This involves obtaining failure information for lateral control functions such as lane keeping assist. The failure information for lane keeping assist is shown in the following failure table:

[0070]

[0071] The failure information includes lost steering request, excessive steering request angle, excessive steering request angle, reversed steering request, unexpected steering, and stuck steering request.

[0072] S203. Obtain the hazard events corresponding to each function based on the failure information. The hazard event list includes the hazard events corresponding to each function. In the hazard event list, target hazard events are identified by keywords.

[0073] Specifically, after obtaining each failure information, an intelligent horizontal control scenario library is created based on the failure information and the built-in scenario library of MA. The tool can automatically generate a list of integrated hazard events, such as combinations of scenarios and failures, and use each combination of scenarios and failures as the corresponding hazard event. By identifying the same keywords in the failure table, the target hazard event is obtained based on the same keywords.

[0074] S204. Based on the functional design specifications, the severity, exposure rate, and controllability of the target hazard event are obtained through the hazard and risk analysis method.

[0075] Specifically, after obtaining the hazard events corresponding to each failure information, the safety objectives of the corresponding hazard events, i.e., the integrated safety objectives, severity (S), exposure rate (E), and controllability (C), are obtained through HARA (Hazard Analysis and Risk Assessment) method. Based on the severity, exposure rate, and controllability of each hazard event, the corresponding vehicle safety integrity level (ASIL level) and residual risk acceptance level are obtained. The safety objectives are used to indicate the functions that meet the normal operation of the project.

[0076] S205. Obtain the vehicle safety integrity level based on the severity, exposure rate, and controllability; obtain the residual risk acceptability based on the severity and controllability.

[0077] Specifically, after obtaining the severity, exposure rate, and controllability of each hazard event, the ASIL level of each hazard event is determined based on severity (S), exposure rate (E), and controllability (C). The acceptance criteria for residual risk are determined based on severity (S) and controllability (C). For failure information such as hazard events corresponding to unexpected steering, the vehicle safety integrity level and residual risk acceptance of the target hazard event are shown in the following criterion table:

[0078]

[0079] Residual risk acceptance includes acceptable risk, conditionally tolerable risk, or unacceptable risk.

[0080] S206. In the risk level table, risk level information is obtained based on the combination of the vehicle safety integrity level and the residual risk acceptance, and the target risk level is determined through the risk level information;

[0081] Specifically, after obtaining the vehicle safety integrity level and residual risk acceptance for each hazard event, the corresponding risk level information is retrieved from the risk level table based on the vehicle safety integrity level and residual risk acceptance for the target hazard event. The target risk level, i.e., the hazard event risk level, is then determined using this risk level information. The risk level information includes low, medium, high, or severe. The risk level table is shown below:

[0082]

[0083] The risk level table pre-stores a first mapping relationship and a second mapping relationship. The first mapping relationship is used to indicate the positive correlation between the vehicle safety integrity level and the risk level information. The second mapping relationship is used to indicate the positive correlation between the residual risk acceptability and the risk level information. For example, when the ASIL level, that is, the vehicle safety integrity level, is B and the residual risk is unacceptable, the corresponding risk level information is obtained from the risk level table, and the target risk level indicated by the risk level information is high.

[0084] S207. When the target risk level is medium, high or severe, the functional safety architecture is established based on the security target, and the functional safety architecture is used to reduce the target risk level to low.

[0085] Specifically, after obtaining the target risk level and safety objectives, a functional safety architecture is established based on the safety objectives and the target risk level of the target hazard events. The ASIL level is then assigned to the electronic and electrical units that cause the hazard events through the functional safety architecture. The verification objective of expected functional safety is to achieve the expected horizontal functions to reduce the risk to a reasonable level, that is, to reduce the target risk level to a low level. The reasonable level is defined as: the incidence rate of accidents caused by the function is less than or equal to the incidence rate of the same accidents caused by humans.

[0086] Furthermore, the concept of ASIL (Autonomous System Indicator) levels for functional safety objectives is used to determine verification targets. Different ASIL levels have different requirements for hardware and software, and different verification requirements. For details, refer to the ISO 26262 standard. The functional safety architecture includes signal interaction information between various units such as sensing units, logic control units, and execution units. The signal interaction information indicates control signals and feedback signals. Each control signal or feedback signal can serve as a control behavior. When the target risk level is low, a functional safety architecture is not established.

[0087] S208. Based on the functional safety architecture, obtain the safety constraints and transform the safety constraints into target safety requirements;

[0088] Specifically, after obtaining the functional safety architecture, each control behavior is determined based on the control signal or feedback signal. In each control behavior, unsafe control behaviors are identified using the STPA (Systems-Theoretic Process Analysis) method. Based on the unsafe control behaviors, safety constraints are determined. Safety constraints can be safety mechanisms, algorithm requirements, sensor / controller performance requirements, and driver behavior requirements.

[0089] The target safety requirements include functional safety requirements and expected functional safety requirements, which need to be refined through safety constraints. Functional safety requirements related to the failure of electronic and electrical systems need to be assigned ASIL levels. ASIL levels are inherited from the safety targets. After obtaining the target safety requirements, the safety implementation is verified and confirmed based on the target safety requirements.

[0090] This application provides a method for generating integrated safety requirements. During the development of automatic lateral control functions for heavy vehicles, it defines lateral control function-related items, including implemented and expected functions. Through hazard and operability analysis, a list of hazard events for these lateral control function-related items is obtained. Target hazard events are identified in this list. Through hazard and risk analysis, the safety objectives, vehicle safety integrity level, and residual risk acceptance of the target hazard events are obtained. Based on the vehicle safety integrity level and residual risk acceptance, the target risk level is obtained from a risk level table. A functional safety architecture is established based on the target risk level and safety objectives. Safety constraints are obtained based on the functional safety architecture and transformed into target safety requirements. This comprehensively analyzes the hazards caused by lateral control failures and insufficient expected functions, effectively improving the development efficiency of automatic lateral control, reducing the development cycle, and enhancing product reliability and safety.

[0091] Figure 5 A schematic diagram of the fusion security requirements generation device provided in this application is shown below. Figure 4 As shown, the fusion security requirements generation device 50 provided in this embodiment includes:

[0092] The acquisition module 501 is used to define lateral control function related items and functional design specifications. The lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle. The lateral realized functions are used to indicate the lane keeping function. The functional design specifications are used to indicate the vehicle's status information and operating environment.

[0093] The processing module 502 is used to obtain a list of hazard events related to the lateral control function through hazard and operability analysis. In the list of hazard events, target hazard events are identified by keywords. The safety objectives, vehicle safety integrity level and residual risk acceptance of the target hazard events are obtained through hazard and risk analysis methods.

[0094] The control module 503 is used to obtain a target risk level based on the vehicle safety integrity level and residual risk acceptance level, establish a functional safety architecture based on the target risk level and the safety target, obtain safety constraints based on the functional safety architecture, and transform the safety constraints into target safety requirements.

[0095] In one possible implementation, the acquisition module 501 is specifically used to define the expected lateral functions, including: function activation, function exit, lane line recognition, judgment and decision-making, and function execution.

[0096] The function activation is used to indicate that the vehicle enters the lane keeping state, the function deactivation is used to indicate that the vehicle exits the lane keeping state, the lane line recognition is used to indicate the recognition distance between the vehicle and the lane lines on both sides, the judgment decision is used to indicate whether to activate the steering function based on the recognition distance, and the function execution is used to indicate the execution of the lane keeping function when the deviation distance between the vehicle's centerline and the lane centerline exceeds a threshold.

[0097] In one possible implementation, the acquisition module 501 is specifically used to define status information including: driving status, driver information and equipment status. The driving status is used to indicate the speed change of the vehicle, the driver information is used to indicate the driver's identity information and driving status, and the equipment status is used to indicate whether each on-board device is operating normally.

[0098] The operating environment includes scene features and environmental information. The scene features are used to indicate the road type and road boundaries, and the environmental information is used to indicate the weather, lighting, and road surface conditions when the vehicle is driving.

[0099] In one possible implementation, the processing module 502 is specifically used to obtain failure information of each function in the relevant items of the lateral control function based on the functional design specifications and through the hazard and operability analysis.

[0100] Based on the failure information, the corresponding hazard events for each function are obtained. The list of hazard events includes the hazard events corresponding to each function. The failure information includes loss of steering request, excessive steering request angle, excessive steering request angle, reverse steering request, unexpected steering, and stuck steering request.

[0101] In one possible implementation, the processing module 502 is specifically used to obtain the severity, exposure rate, and controllability of the target hazard event based on the functional design specifications and through the hazard and risk analysis method.

[0102] The vehicle safety integrity level is obtained based on the severity, exposure rate, and controllability, and the residual risk acceptance level is obtained based on the severity and controllability, wherein the residual risk acceptance level includes acceptable risk, conditionally tolerable risk, or unacceptable risk.

[0103] In one possible implementation, the processing module 502 is specifically used to obtain risk level information from the risk level table based on the combination of the vehicle safety integrity level and the residual risk acceptance, and to determine the target risk level through the risk level information, wherein the risk level information includes low, medium, high or severe.

[0104] The risk level table pre-stores a first mapping relationship and a second mapping relationship. The first mapping relationship is used to indicate the positive correlation between the vehicle safety integrity level and the risk level information, and the second mapping relationship is used to indicate the positive correlation between the residual risk acceptance and the risk level information.

[0105] In one possible implementation, the control module 503 is specifically used to establish the functional safety architecture based on the security objective when the target risk level is medium, high or severe, and the functional safety architecture is used to reduce the target risk level to low.

[0106] When the target risk level is low, the functional safety architecture is not established.

[0107] The fusion security requirement generation device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0108] Figure 6 A schematic diagram of the structure of the electronic device provided in this application. Figure 6 As shown, the electronic device 60 provided in this embodiment includes at least one processor 601 and a memory 602. Optionally, the device 60 further includes a communication component 603. The processor 601, memory 602, and communication component 603 are connected via a bus 604.

[0109] In a specific implementation, at least one processor 601 executes computer execution instructions stored in memory 602, causing at least one processor 601 to perform the above-described method.

[0110] The specific implementation process of processor 601 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0111] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0112] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0113] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0114] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0115] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0116] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0117] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0118] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0119] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0120] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0121] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0122] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0123] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A method for generating integrated security requirements, characterized in that, include: Define lateral control function related items and functional design specifications. The lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle. The lateral realized functions are used to indicate the lane keeping function. The functional design specifications are used to indicate the vehicle's status information and operating environment. Through hazard and operability analysis, a list of hazard events related to the lateral control function is obtained, and target hazard events are identified in the list of hazard events by keyword. The safety objectives, vehicle safety integrity level, and residual risk tolerance of the target hazard event are obtained through hazard and risk analysis methods. Based on the vehicle safety integrity level and residual risk tolerance, a target risk level is obtained, and a functional safety architecture is established based on the target risk level and the safety objective. Based on the functional safety architecture, security constraints are obtained and transformed into target security requirements. The step of obtaining the target risk level based on the vehicle safety integrity level and residual risk acceptance includes: In the risk level table, risk level information is obtained based on the combination of the vehicle safety integrity level and the residual risk acceptance level. The target risk level is determined through the risk level information, wherein the risk level information includes low, medium, high or severe. The risk level table pre-stores a first mapping relationship and a second mapping relationship. The first mapping relationship is used to indicate the positive correlation between the vehicle safety integrity level and the risk level information, and the second mapping relationship is used to indicate the positive correlation between the residual risk acceptance and the risk level information.

2. The method according to claim 1, characterized in that, The lateral expected functions include: function activation, function deactivation, lane line recognition, judgment and decision-making, and function execution. The function activation is used to indicate that the vehicle enters the lane keeping state, the function deactivation is used to indicate that the vehicle exits the lane keeping state, the lane line recognition is used to indicate the recognition distance between the vehicle and the lane lines on both sides, the judgment decision is used to indicate whether to activate the steering function based on the recognition distance, and the function execution is used to indicate the execution of the lane keeping function when the deviation distance between the vehicle's centerline and the lane centerline exceeds a threshold.

3. The method according to claim 1, characterized in that, The status information includes: driving status, driver information, and equipment status. The driving status is used to indicate changes in vehicle speed, the driver information is used to indicate the driver's identity information and driving status, and the equipment status is used to indicate whether each on-board device is operating normally. The operating environment includes scene features and environmental information. The scene features are used to indicate the road type and road boundaries, and the environmental information is used to indicate the weather, lighting, and road surface conditions when the vehicle is driving.

4. The method according to claim 1, characterized in that, The process of obtaining the hazard event list related to the lateral control function includes: Based on the aforementioned functional design specifications, failure information for each function in the relevant items of the lateral control function is obtained through the aforementioned hazard and operability analysis. Based on the failure information, the corresponding hazard events for each function are obtained. The list of hazard events includes the hazard events corresponding to each function. The failure information includes loss of steering request, excessive steering request angle, excessive steering request angle, reverse steering request, unexpected steering, and stuck steering request.

5. The method according to claim 1, characterized in that, The acquisition of the safety objectives, vehicle safety integrity level, and residual risk acceptance of the target hazard event includes: Based on the aforementioned functional design specifications, the severity, exposure rate, and controllability of the target hazard event are obtained through the aforementioned hazard and risk analysis methods. The vehicle safety integrity level is obtained based on the severity, exposure rate, and controllability, and the residual risk acceptance level is obtained based on the severity and controllability, wherein the residual risk acceptance level includes acceptable risk, conditionally tolerable risk, or unacceptable risk.

6. The method according to claim 1, characterized in that, The step of establishing a functional safety architecture based on the target risk level and the security objective includes: When the target risk level is medium, high or severe, the functional safety architecture is established based on the security objective, and the functional safety architecture is used to reduce the target risk level to low. When the target risk level is low, the functional safety architecture is not established.

7. A device for generating integrated security requirements, characterized in that, include: The acquisition module is used to define lateral control function related items and functional design specifications. The lateral control function related items are used to indicate the lateral realized functions and lateral expected functions of the vehicle during its safety life cycle. The lateral realized functions are used to indicate the lane keeping function. The functional design specifications are used to indicate the vehicle's status information and operating environment. The processing module is used to obtain a list of hazard events related to the lateral control function through hazard and operability analysis. In the list of hazard events, target hazard events are identified by keywords. The safety objectives, vehicle safety integrity level and residual risk acceptance of the target hazard events are obtained through hazard and risk analysis methods. The control module is used to obtain a target risk level based on the vehicle safety integrity level and residual risk acceptance level, establish a functional safety architecture based on the target risk level and the safety target, obtain safety constraints based on the functional safety architecture, and transform the safety constraints into target safety requirements. The processing module is specifically used to obtain risk level information from a risk level table based on the combination of the vehicle safety integrity level and the residual risk acceptance, and to determine the target risk level through the risk level information. The risk level information includes low, medium, high, or severe. The risk level table pre-stores a first mapping relationship and a second mapping relationship. The first mapping relationship is used to indicate the positive correlation between the vehicle safety integrity level and the risk level information, and the second mapping relationship is used to indicate the positive correlation between the residual risk acceptance and the risk level information.

8. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.