Method, device, equipment and medium for establishing expected functional safety trigger scenario library
By obtaining the list of hazardous events and conducting UCA analysis, a trigger scenario library is built, which solves the problem that the expected functional safety standards in the existing technology cannot be converted into specific test scenarios, and improves the safety of autonomous vehicles.
Patent Information
- Application Number
- CN202411334661.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2044-09-24
AI Technical Summary
The prior art cannot effectively convert the standard specifications of expected functional safety into specific test scenarios, resulting in insufficient safety evaluation and testing operationality of autonomous vehicles.
By obtaining the list of hazardous events, adding safety constraints, conducting UCA analysis, determining the source of the UCA hierarchy, and building a trigger scene library, including road characteristics, environmental characteristics, main vehicle characteristics and traffic participants characteristics, forming a logical scenario and building a specific trigger scene.
The performance limitation analysis of the autonomous driving system is realized, and the expected functional safety trigger scenario database covering trigger conditions can be built in a targeted manner, improving the safety of autonomous driving vehicles.
Smart Images

Figure CN119294069B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of automobile control technology, and in particular to a method, device, equipment and medium for establishing an expected functional safety trigger scenario library. Background Art
[0002] The development of autonomous driving technology and a deeper understanding of safety issues are driving the advancement of autonomous driving. As autonomous driving technology progresses from Level 2 to Level 3, traditional safety assurance measures are no longer sufficient to meet the safety requirements of autonomous vehicles. Consequently, Safety of the Intended Functionality (SOTIF) has emerged.
[0003] With the continuous advancement of autonomous driving technology, more and more advanced autonomous driving features are being developed and put into practical use. While these technologies improve road safety and travel convenience, they also introduce new safety risks. Autonomous driving systems must operate in a variety of complex environments and scenarios, such as varying weather conditions, road conditions, and traffic behaviors. These complexities far exceed the operational scope of traditional vehicles and present unprecedented safety challenges. Traditional vehicle safety systems, centered around quality assurance and primarily focused on preventing, detecting, and eliminating random hardware failures and systemic faults, are no longer fully applicable to autonomous vehicles.
[0004] In actual operation, autonomous vehicles may encounter non-fault-related safety issues due to design deficiencies, performance limitations, or external environmental factors. These issues are often not effectively addressed in traditional safety systems. Governments and international organizations are developing regulations and standards to ensure the safety of autonomous vehicles, and intended functional safety has become a key component of these regulations and standards. Intended functional safety focuses on safety issues that may arise even if the system operates normally as designed due to design deficiencies, performance limitations, or external environmental factors. The requirements of intended functional safety encourage developers to identify and assess potential risks during the design and testing phases, driving them to continuously optimize systems and improve performance. As the automotive industry evolves toward intelligence and connectivity, intended functional safety has become an industry consensus and demand, driving technological innovation and standardization efforts across the industry.
[0005] There are roughly 23 existing analysis methods, including requirements analysis, external and internal interface analysis, equivalence class generation and analysis, boundary value analysis, and knowledge- or experience-based error guessing. Literature and industry research reveal that the three most commonly used methods are FMEA (Failure Mode and Effects Analysis), FTA (Fault Tree Analysis), and STPA (Systems Theoretic Process Analysis). However, in actual applications, many companies avoid ignoring certain interactions between system components, and there are limitations in operability and practicality. In actual analysis operations, effectively translating the specifications in the standard into specific test scenarios and accurately evaluating the results remains a major challenge, often requiring highly professional technicians to operate and interpret them.
[0006] Therefore, it is urgent to propose a method, device, equipment and medium for establishing a trigger scenario library for expected functional safety to solve the technical problem in the existing technology that the specifications in the standard cannot be effectively converted into specific test scenarios. Summary of the Invention
[0007] To overcome the problems existing in the related art, the present disclosure provides a method, apparatus, device and medium for establishing a trigger scenario library for expected functional safety, so as to solve the technical problem in the related art that the specifications in the standard cannot be effectively converted into specific test scenarios.
[0008] One or more embodiments of this specification provide a method for establishing a trigger scenario library for expected functional safety, including the following steps:
[0009] Obtain a list of hazardous events and add safety constraints for each hazardous event;
[0010] Performing a UCA analysis on the security constraint to obtain UCA analysis result data;
[0011] Determining a UCA level source corresponding to the UCA analysis result data, and analyzing the performance limitations of the autonomous driving system based on the UCA level source;
[0012] The trigger conditions of hazardous events are obtained according to the performance limitations of the autonomous driving system, and multiple trigger scenarios are constructed for the trigger conditions to form a trigger scenario library.
[0013] Preferably, obtaining the triggering condition of a hazardous event according to the performance limitation of the autonomous driving system comprises the following steps:
[0014] According to the performance limitations of the autonomous driving system, the triggering conditions of the hazardous event are obtained from the triggering condition element classification system according to the triggering mechanism.
[0015] Preferably, constructing multiple trigger scenarios for the trigger conditions to form a trigger scenario library specifically includes the following steps:
[0016] Acquiring scene key features according to the triggering conditions, wherein the scene key features include road features, environmental features, main vehicle features, and traffic participant features;
[0017] Obtaining the hazard type and ODD parameters of the hazard event;
[0018] Add the key features of the scenario to the hazard type to construct a functional scenario description;
[0019] Statistically analyzing the data of the functional scenario description to obtain the relevant parameter distribution of the functional scenario description, thereby obtaining the logical scenario;
[0020] The parameters in the logical scenario are resampled to determine the values of the key parameters of the corresponding scenario and to construct a specific triggering scenario.
[0021] Preferably, performing UCA analysis on the security constraint to obtain UCA analysis result data includes the following steps:
[0022] Performing UCA analysis on the security constraint through the guide words to obtain UCA analysis result data.
[0023] Preferably, determining the UCA level source corresponding to the UCA analysis result data comprises the following steps:
[0024] The UCA hierarchical sources include UCA primary sources, UCA secondary sources and UCA tertiary sources;
[0025] The UCA analysis result data is disassembled and analyzed to determine the cause of the UCA, thereby determining the corresponding UCA level source.
[0026] One or more embodiments of this specification provide a device for establishing a trigger scenario library for expected functional safety, including:
[0027] The acquisition module is used to obtain a list of hazardous events and add safety constraints to each hazardous event;
[0028] An analysis module, configured to perform a UCA analysis on the security constraint to obtain UCA analysis result data;
[0029] a level determination module, configured to determine a UCA level source corresponding to the UCA analysis result data, and analyze the performance limitations of the autonomous driving system based on the UCA level source;
[0030] A scenario library construction module is used to obtain the trigger conditions of hazardous events based on the performance limitations of the autonomous driving system, construct multiple trigger scenarios for the trigger conditions, and form a trigger scenario library.
[0031] Preferably, the scenario library construction module further includes a triggering unit, which is used to obtain the triggering conditions of the hazardous event from the triggering condition element classification system according to the performance limitations of the autonomous driving system and the triggering mechanism.
[0032] Preferably, the scenario library construction module further includes a scenario library construction unit, which is used to obtain scenario key features according to the trigger conditions, wherein the scenario key features include road features, environmental features, main vehicle features and traffic participant features;
[0033] Obtaining the hazard type and ODD parameters of the hazard event;
[0034] Add the key features of the scenario to the hazard type to construct a functional scenario description;
[0035] Statistically analyzing the data of the functional scenario description to obtain the relevant parameter distribution of the functional scenario description, thereby obtaining the logical scenario;
[0036] The parameters in the logical scenario are resampled to determine the values of the key parameters of the corresponding scenario and to construct a specific triggering scenario.
[0037] One or more embodiments of this specification provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for establishing a trigger scenario library for expected functional safety as described above is implemented.
[0038] One or more embodiments of this specification provide a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the steps of the method for establishing a trigger scenario library for expected functional safety are implemented as described above.
[0039] The present disclosure provides a method, device, equipment and medium for establishing an expected functional safety trigger scenario library, which has the advantages of obtaining a list of hazardous events, adding safety constraints for each hazardous event, providing constraint filtering for the analysis of hazardous events, and constituting weak points; performing UCA analysis on the safety constraints to obtain UCA analysis result data, which can fully determine whether there is a dangerous behavior; determining the UCA hierarchical source corresponding to the UCA analysis result data, analyzing the performance limitations of the autonomous driving system based on the UCA hierarchical source, and analyzing and disassembling the causes of the hazardous events and associating them with specific components of the vehicle through the UCA hierarchy; obtaining the triggering conditions of the hazardous events based on the performance limitations of the autonomous driving system, constructing multiple triggering scenarios for the triggering conditions, and forming a triggering scenario library, which can establish an expected functional safety trigger scenario library covering the triggering conditions in a targeted manner, and effectively improve the safety of autonomous driving vehicles. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate one or more embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0041] Figure 1 A flowchart of a method for establishing a trigger scenario library for expected functional safety provided in one or more embodiments of this specification;
[0042] Figure 2 A schematic diagram of specific guide words provided for one or more embodiments of this specification;
[0043] Figure 3 A schematic diagram of the UCA hierarchy provided for one or more embodiments of this specification;
[0044] Figure 4 the scope and potential impact of road features provided for one or more embodiments of this specification;
[0045] Figure 5 A schematic diagram of the structure of a device for establishing a trigger scenario library for expected functional safety provided in one or more embodiments of this specification;
[0046] Figure 6 A schematic diagram of the structure of a computer device provided in one or more embodiments of this specification. DETAILED DESCRIPTION
[0047] In order to enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below in conjunction with the drawings in one or more embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this invention.
[0048] The present invention will be described in detail below with reference to specific implementation methods and the accompanying drawings.
[0049] Method Example
[0050] According to an embodiment of the present invention, a method for establishing a trigger scenario library for expected functional safety is provided, such as Figure 1 FIG. 1 is a flow chart of a method for establishing a trigger scenario library for expected functional safety according to an embodiment of the present invention. The method for establishing a trigger scenario library for expected functional safety according to an embodiment of the present invention includes the following steps:
[0051] S110. Obtain a list of hazardous events from data pre-collected in the autonomous driving system, add safety constraints for each hazardous event, read out the vehicle-level hazard corresponding to each hazardous event, and add safety constraints to the software, such as the vehicle should identify and avoid collisions with vehicles in front, the vehicle should identify and avoid collisions with stationary objects in front, etc.
[0052] S120, perform UCA (Unsafe Control Action) analysis on the safety constraint to obtain UCA analysis result data. The UCA analysis is performed on the safety constraint through the guide word. The purpose of the UCA analysis is to obtain UCA analysis result data, that is, what the unsafe control action is. These unsafe control actions can be used to infer trigger conditions. Typical UCA analysis result data include the presence of a stationary vehicle ahead and the system failing to provide braking torque in time. Figure 2 As shown, it is a schematic diagram of the specific guide words provided in this embodiment.
[0053] S130. Determine the UCA hierarchical source corresponding to the UCA analysis result data, and analyze the performance limitations of the autonomous driving system based on the UCA hierarchical source. Specifically, analyze and deconstruct the unsafe control behavior. The unsafe control behavior may manifest as failure to provide necessary control, provision of incorrect control, improper control execution time, or improper duration of continuous control behavior. Here, we need to add causal scenario analysis to explain how factors such as incorrect feedback, insufficient requirements, and design errors lead to the occurrence of unsafe control behavior and ultimately cause harm by constructing scenarios. This source analysis step helps to generate the trigger conditions for expected functional safety and identify mitigation measures. The UCA hierarchy can be divided into three levels. The first-level source is the perception system, the second-level source is the software algorithm, and the third-level source is a deeper level, such as semantic segmentation errors, target detection errors, depth prediction errors, etc. Figure 3 The figure shows a schematic diagram of the UCA hierarchy provided by this embodiment.
[0054] S140. Obtain trigger conditions for hazardous events based on the performance limitations of the autonomous driving system. Associate the performance limitations of specific components of the vehicle with the description of the limitations of the autonomous driving system. For example, if a camera is not functional enough, the associated performance limitations are also the performance limitations of the system or subsystem. Construct multiple trigger scenarios for the trigger conditions to form a trigger scenario library.
[0055] The method provided in this embodiment obtains a list of hazardous events, adds safety constraints to each hazardous event, provides constraint filtering for the analysis of hazardous events, and constitutes a weak point; performs UCA analysis on the safety constraints to obtain UCA analysis result data, which can fully determine whether there is a dangerous behavior; determines the UCA hierarchical source corresponding to the UCA analysis result data, analyzes the performance limitations of the autonomous driving system based on the UCA hierarchical source, analyzes and decomposes the causes of the hazardous events, and associates them with specific components of the vehicle through the UCA hierarchy; obtains the triggering conditions of the hazardous events based on the performance limitations of the autonomous driving system, constructs multiple triggering scenarios for the triggering conditions, and forms a triggering scenario library, which can specifically establish an expected functional safety triggering scenario library covering the triggering conditions, effectively improving the safety of autonomous driving vehicles.
[0056] In one embodiment, obtaining a trigger condition for a hazardous event based on the performance limitations of the autonomous driving system includes the following steps:
[0057] According to the performance limitations of the autonomous driving system, the triggering conditions of the hazardous event are obtained from the triggering condition element classification system according to the triggering mechanism. Table 1 is a schematic diagram of the triggering condition element classification system provided in this embodiment.
[0058] Table 1. Trigger condition factor classification system
[0059]
[0060] The method provided in this embodiment obtains the trigger conditions corresponding to the performance limitations of the autonomous driving system through a trigger mechanism, thereby forming a trigger scenario. It can analyze the causes of hazardous events from the system's defects, thereby providing reliable data support for establishing a safe trigger scenario library.
[0061] In one embodiment, constructing multiple trigger scenarios for the trigger conditions to form a trigger scenario library specifically includes the following steps:
[0062] The key features of the scene are acquired according to the triggering conditions, wherein the key features of the scene include road features, environmental features, main vehicle features, and traffic participant features.
[0063] Road features are physical infrastructure elements in the scene, and are a collection of elements such as road structures and road facilities within the limited scope of the scene. The element range of road features includes road type, road geometry, road style, lane lines, lane width, road elevation, traffic light settings, and road surface conditions. Among them, the values of the scene element road type example are urban roads, highways, parking lots, rural roads, etc. The importance of road features lies in that different road types have different traffic characteristics and driving behavior patterns. Road geometry affects the vehicle's driving trajectory, and road conditions directly affect the vehicle's driving stability and braking effect. Including these elements in scene construction can define the vehicle's driving environment, help simulate the diversity and complexity of the real world, and ensure that the autonomous driving system performs as expected in different road environments. Figure 4 As shown, the scope and potential impact of the road features provided for this embodiment.
[0064] Environmental characteristics are a crucial factor in perception. These factors include weather, precipitation, wind speed, daytime, nighttime, angle between the light source and the horizon, direct illumination intensity, ambient light intensity, visibility range, and friction coefficient. Each factor can be individually configured, such as weather conditions like sunny with few clouds or rainy with moderate rain. These environmental characteristics are crucial variables for autonomous driving systems, directly impacting sensor perception performance, vehicle dynamics, and the accuracy of system decisions. For example, precipitation affects road slipperiness, which in turn impacts braking distance and handling. Under varying light intensities, autonomous driving systems must adjust sensor sensitivity to ensure accurate environmental recognition. Incorporating diverse weather conditions into scenario construction ensures that autonomous driving systems can function as intended in all climates.
[0065] The main vehicle characteristics specify the behavior of the vehicle in the scene. The elements of the main vehicle characteristics include longitudinal initial velocity, longitudinal acceleration, current lane offset, moving target, lane, lateral initial velocity, and lateral acceleration.
[0066] The importance of the main vehicle characteristics in a scenario is reflected in the simulation and control of vehicle behavior. For example, the initial longitudinal velocity and longitudinal acceleration determine the change in vehicle speed during driving. By setting and adjusting the parameters of these characteristic elements, different driving styles can be simulated. The current lane offset determines the position of the vehicle in the lane. By setting and adjusting the parameters of these characteristic elements, the accuracy of the lane keeping function can be verified. The initial lateral velocity and lateral acceleration determine the change in vehicle speed in the horizontal direction. By adjusting the parameter settings, the vehicle's driving conditions on roads with different curvatures can be simulated. The main vehicle characteristics simulate the vehicle's driving behavior in various complex traffic scenarios, thereby providing data support for the training and testing of autonomous driving systems. The composition of the main vehicle characteristics can be represented as a multidimensional function, with each element being a degree of freedom of the function. For example, the initial longitudinal velocity (v_x0), longitudinal acceleration (a_x), current lane offset (d_lane), target (target), lane (lane), initial lateral velocity (v_y0) and lateral acceleration (a_y) can form a seven-dimensional characteristic function F: F = (v_x0, a_x, d_lane, target, lane, v_y0, a_y). This characteristic function F defines the behavior of the vehicle at a specific point in time. By changing these parameters, different driving behaviors and scenario conditions can be simulated. The automatic system makes decisions based on the current state of the main vehicle and the predicted future state. These decisions can be expressed as a mapping function D from the current state to the future state:
[0067] D:F→F′;
[0068] Where F' is the expected feature at a certain moment in the future. The goal of the decision function D is to find the optimal control strategy so that the vehicle can reach the destination safely and efficiently.
[0069] In summary, the importance of host vehicle characteristics in scenario construction lies not only in the precise description of vehicle behavior, but also in the ability to conduct risk assessment and decision making through these characteristics.
[0070] Traffic object characteristics define the behavior and interactions of these objects. Elements of traffic object characteristics include new traffic objects, initial lanes, reference objects, longitudinal relative distances, initial lane offsets, and longitudinal target speeds. The importance of traffic object characteristics in scene construction lies in their accuracy in simulating real-world traffic conditions. Scene elements are enriched by selecting new traffic objects. The initial lane determines the initial position and possible movement paths of the objects. Furthermore, by setting longitudinal relative distances, the vehicle's following and collision avoidance responsiveness can be correlated.
[0071] According to the hazard type, it is determined whether the hazard is within the vehicle operation design domain (ODD), and the hazard type and ODD parameters of the hazard event are obtained.
[0072] The scenario key features are added to the hazard type. Based on the hazard type and the analyzed key features, a functional scenario description containing relevant feature elements is constructed, which can be expressed as:
[0073] S = f(r, e, m, t);
[0074] Then S is a scene consisting of four feature sets, where:
[0075] r is a set of road features, where r n is a specific road condition parameter value; r={r1,r2,...,r n};
[0076] e is the set of environmental features, where e n is a parameter value for a specific environmental condition; e={e1,e2,...,e n};
[0077] m is the main vehicle feature set, where m n is a specific vehicle behavior parameter value; m={m1,m2,...,m n};
[0078] t is the feature set of traffic participants, where t n is the value of the behavior parameter of a specific traffic participant; t={t1,t2,...,t n}.
[0079] According to the filled-in functional scenario description, the data of the functional scenario description is statistically analyzed to obtain the relevant parameter distribution of the functional scenario description, thereby obtaining the logical scenario.
[0080] The parameters in the logical scenario are resampled to determine the values of the key parameters of the corresponding scenario and to construct a triggering scenario.
[0081] The method provided in this embodiment establishes a functional scenario description containing characteristic elements, obtains the distribution of relevant parameters describing the scenario through statistical analysis of data, and thus obtains the logical scenario, which can accurately locate the corresponding scenario and improve the security of the system.
[0082] Device embodiment
[0083] According to an embodiment of the present invention, a device for establishing a trigger scenario library for expected functional safety is provided, such as Figure 5 FIG. 1 is a schematic diagram of a structure of a device for establishing a trigger scenario library for expected functional safety according to an embodiment of the present invention. The device for establishing a trigger scenario library for expected functional safety according to an embodiment of the present invention includes:
[0084] The acquisition module 51 is used to acquire a list of hazardous events and add safety constraints to each hazardous event.
[0085] The analysis module 52 is configured to perform UCA analysis on the security constraints to obtain UCA analysis result data.
[0086] The level determination module 53 is configured to determine a UCA level source corresponding to the UCA analysis result data, and analyze the performance limitations of the autonomous driving system based on the UCA level source.
[0087] The scenario library construction module 54 is used to obtain the triggering conditions of the hazardous event according to the performance limitations of the autonomous driving system, and construct multiple triggering scenarios for the triggering conditions to form a triggering scenario library.
[0088] In the device provided in this embodiment, the acquisition module 51 obtains a list of hazardous events, adds safety constraints to each hazardous event, provides constraint filtering for the analysis of hazardous events, and constitutes a weak point; the analysis module 52 performs UCA analysis on the safety constraints to obtain UCA analysis result data, which can fully determine whether there is a dangerous behavior; the hierarchy determination module 53 determines the UCA hierarchy source corresponding to the UCA analysis result data, analyzes the performance limitations of the autonomous driving system based on the UCA hierarchy source, analyzes and decomposes the causes of the hazardous events, and associates them with specific components of the vehicle through the UCA hierarchy; the scenario library construction module 54 obtains the triggering conditions of the hazardous events based on the performance limitations of the autonomous driving system, constructs multiple triggering scenarios for the triggering conditions, and forms a triggering scenario library, which can establish a targeted expected functional safety triggering scenario library covering the triggering conditions, effectively improving the safety of autonomous driving vehicles.
[0089] In one embodiment, the scenario library construction module 54 further includes a trigger unit 541, which is used to obtain the trigger condition of the hazardous event from the trigger condition element classification system according to the performance limitation of the autonomous driving system and the trigger mechanism.
[0090] The device provided in this embodiment obtains the trigger conditions corresponding to the performance limitations of the autonomous driving system through a trigger mechanism, thereby forming a trigger scenario. It can analyze the causes of hazardous events from the system's defects, thereby providing reliable data support for establishing a safe trigger scenario library.
[0091] In one embodiment, the scenario library construction module 54 further includes a scenario library construction unit 542 for acquiring scenario key features according to the trigger conditions, wherein the scenario key features include road features, environmental features, main vehicle features, and traffic participant features.
[0092] Obtain the hazard type and ODD parameters of the hazard event.
[0093] The key features of the scenario are added to the hazard type to construct a functional scenario description.
[0094] Statistically analyze the data of the functional scenario description to obtain the relevant parameter distribution of the functional scenario description, thereby obtaining the logical scenario.
[0095] The parameters in the logical scenario are resampled to determine the values of the key parameters of the corresponding scenario and to construct a triggering scenario.
[0096] The device provided in this embodiment establishes a functional scenario description containing characteristic elements, obtains the distribution of relevant parameters describing the scenario through statistical analysis of data, and thus obtains the logical scenario, which can accurately locate the corresponding scenario and improve the security of the system.
[0097] The embodiment of the present invention is an apparatus embodiment corresponding to the above-mentioned method embodiment. The specific operations of the processing steps of each module can be understood by referring to the description of the method embodiment, and will not be repeated here.
[0098] like Figure 6 As shown, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for establishing a trigger scenario library for the expected functional safety in the above-mentioned embodiment, or implements the method for establishing a trigger scenario library for the expected functional safety in the above-mentioned embodiment when the computer program is executed by a processor.
[0099] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0100] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments. The device and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative efforts.
[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and the contents not described in detail in the specification of the present invention are common knowledge to those skilled in the art.
Claims
1. A method for establishing a trigger scenario library for expected functional safety, characterized in that: The following steps are involved: Obtain a list of hazardous events, read out the vehicle-level hazard corresponding to each hazardous event, and add safety constraints for each hazardous event; Performing a UCA analysis on the safety constraint to obtain UCA analysis result data, wherein the UCA analysis result data is used to derive a triggering condition for an unsafe behavior; Determine the UCA hierarchical source corresponding to the UCA analysis result data, and analyze the performance limitations of the autonomous driving system based on the UCA hierarchical source. This includes analyzing and deconstructing unsafe control behaviors, incorporating causal scenario analysis, and constructing scenarios to explain the occurrence of unsafe control behaviors and the resulting harm. The trigger conditions of hazardous events are obtained according to the performance limitations of the autonomous driving system, and multiple trigger scenarios are constructed for the trigger conditions to form a trigger scenario library.
2. The method for establishing a trigger scenario library according to claim 1, wherein: The step of obtaining trigger conditions for hazardous events based on the performance limitations of the autonomous driving system includes the following steps: According to the performance limitations of the autonomous driving system, the triggering conditions of the hazardous event are obtained from the triggering condition element classification system according to the triggering mechanism.
3. The method for establishing a trigger scenario library according to claim 1, wherein: The constructing of multiple trigger scenarios for the trigger conditions to form a trigger scenario library specifically includes the following steps: Acquiring scene key features according to the triggering conditions, wherein the scene key features include road features, environmental features, main vehicle features, and traffic participant features; Obtaining the hazard type and ODD parameters of the hazard event; Add the key features of the scenario to the hazard type to construct a functional scenario description; Statistically analyzing the data of the functional scenario description to obtain the relevant parameter distribution of the functional scenario description, thereby obtaining the logical scenario; The parameters in the logical scenario are resampled to determine the values of the key parameters of the corresponding scenario and to construct a triggering scenario.
4. The method for establishing a trigger scenario library according to claim 1, wherein: The performing of UCA analysis on the security constraint to obtain UCA analysis result data comprises the following steps: Performing UCA analysis on the security constraint through the guide words to obtain UCA analysis result data.
5. The method for establishing a trigger scenario library according to claim 1 or 4, wherein: Determining the UCA level source corresponding to the UCA analysis result data includes the following steps: The UCA hierarchical sources include UCA primary sources, UCA secondary sources and UCA tertiary sources; The UCA analysis result data is disassembled and analyzed to determine the cause of the UCA, thereby determining the corresponding UCA level source.
6. A device for establishing a trigger scenario library for expected functional safety, characterized in that: include: The acquisition module is used to obtain a list of hazardous events, read out the vehicle-level hazard corresponding to each hazardous event, and add safety constraints for each hazardous event; An analysis module, configured to perform a UCA analysis on the security constraint to obtain UCA analysis result data; A hierarchy determination module is used to determine the UCA hierarchy source corresponding to the UCA analysis result data, and analyze the performance limitations of the autonomous driving system based on the UCA hierarchy source. This module analyzes and deconstructs unsafe control behaviors, incorporates causal scenario analysis, and constructs scenarios to explain the occurrence of unsafe control behaviors and the resulting harm. A scenario library construction module is used to obtain the trigger conditions of hazardous events based on the performance limitations of the autonomous driving system, construct multiple trigger scenarios for the trigger conditions, and form a trigger scenario library.
7. The device for establishing a trigger scenario library according to claim 6, wherein: The scenario library construction module also includes a trigger unit, which is used to obtain the trigger conditions of the hazardous event from the trigger condition element classification system according to the performance limitations of the autonomous driving system and the trigger mechanism.
8. The device for establishing a trigger scenario library according to claim 6, wherein: The scenario library construction module further includes a scenario library construction unit for acquiring scenario key features according to the triggering conditions, wherein the scenario key features include road features, environmental features, main vehicle features, and traffic participant features; Obtaining the hazard type and ODD parameters of the hazard event; Add the key features of the scenario to the hazard type to construct a functional scenario description; Statistically analyzing the data of the functional scenario description to obtain the relevant parameter distribution of the functional scenario description, thereby obtaining the logical scenario; The parameters in the logical scenario are resampled to determine the values of the key parameters of the corresponding scenario and to construct a triggering scenario.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method for establishing a trigger scenario library for expected functional safety according to any one of claims 1 to 5 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method for establishing a trigger scenario library for expected functional safety as claimed in any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Performance-limited expected function safety optimization method for automatic driving decision-making system
CN115270450A
Intelligent networked automobile function safety and expected function safety linkage verification method
CN116186884A