A fault tree construction method for automotive systems considering expected functional safety
By constructing an automotive system fault tree that takes into account the expected functional safety, the problem that traditional methods are unable to evaluate complex scenarios in autonomous driving environments is solved. This enables effective representation and safety analysis of functional failures and expected functional failure events, guides testing, and improves the safety of autonomous vehicles.
Patent Information
- Application Number
- CN202411613709.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-13
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-11-13
AI Technical Summary
Traditional fault tree analysis methods cannot meet the requirements of the expected functional safety of automobiles and cannot effectively evaluate complex scenarios in autonomous driving environments, resulting in functional safety issues appearing in specific scenarios.
A fault tree construction method for automotive systems that takes into account expected functional safety is adopted. By defining the structure diagram of the autonomous driving vehicle, setting the top event, using logical gates such as OR gates and prohibit gates to connect dangerous events, reversely traversing and decomposing sub-events, constructing a fault tree, considering environmental factors and incomplete coverage models, and expanding the human-computer interaction model.
It can better represent functional failures and expected functional failure events in automotive systems, provide scenario information in the design phase, guide testing, deduce accident causes through qualitative and quantitative analysis, and improve the safety analysis capabilities of autonomous vehicles.
Smart Images

Figure CN119472604B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of automobile fault tree construction, and in particular to a method for constructing an automobile system fault tree taking into account expected functional safety. Background Art
[0002] Fault tree analysis focuses on the occurrence of top events, describing the logical relationship between basic events and the top event. Traditional static fault trees are constructed using AND and OR gates, while dynamic fault trees are constructed using dynamic logic gates such as priority AND gates, cold standby gates, and functional dependency gates. Fault tree analysis remains one of the most widely used safety analysis techniques, with widespread application in a wide range of fields, including aerospace, nuclear energy, electric power, chemical engineering, and transportation.
[0003] In recent years, the rapid development of artificial intelligence (AI) has led to the widespread application of autonomous driving technology in automotive systems, paving the way for the emergence of the concept of "intended functional safety." This concept aims to address the limitations of traditional "functional safety," which focuses on performance deficiencies. In intended functional safety, scenarios are a crucial aspect of assessing the intended functional safety of a vehicle. Although automotive functions have undergone extensive testing, due to the complexity of the driving environment, intended functional safety issues may only manifest in certain scenarios. Traditional fault tree construction methods, which focus on the functional safety of automotive systems and functional failures of automotive systems / components, no longer meet the intended functional safety requirements of vehicles. Summary of the Invention
[0004] The present invention proposes a method for constructing a fault tree of an automobile system taking into account the expected functional safety, so as to solve the technical problem that the prior art does not take the expected functional safety of the automobile into consideration.
[0005] To solve the above technical problems, the present invention provides a method for constructing a fault tree for an automobile system taking into account expected functional safety, comprising the following steps:
[0006] Step S1: defining a structure diagram of an autonomous driving vehicle for which a fault tree is to be constructed;
[0007] Step S2: setting an initial scenario and setting a top event; the top event represents an accident that causes a hazard;
[0008] Step S3: Connect all dangerous events that cause the top event with the top event through an OR gate;
[0009] Step S4: converting the dangerous event into a dangerous event of the execution system in the automobile system structure;
[0010] Step S5: For each of the dangerous events, reverse traverse the autonomous driving vehicle structure diagram to decompose the dangerous event to obtain several sub-events that cause the dangerous event. Based on the category of the sub-event, the sub-event of the dangerous event of the input component is used as the dangerous event of the new round of iteration, and step S5 is repeated until the fault tree is constructed; the sub-events include the functional failure event of the current component, the expected functional failure event of the current component, and the dangerous event of the input component of the current component.
[0011] Preferably, step S5 includes:
[0012] Step S51: If the functional failure event of the current component can lead to the current dangerous event, then the relationship between the functional failure event and the dangerous event is expressed according to the corresponding logic;
[0013] Step S52: If the expected functional failure event of the current component can lead to the current dangerous event, first use an OR gate to list the corresponding expected functional failure events, and use corresponding logic gates to represent the relationship between the events;
[0014] Step S53: If the dangerous event of the input component of the current component can cause the current dangerous event to occur, then the dangerous event is inserted and the process returns to step S5 for traversal.
[0015] Preferably, step S51 connects the environmental factors to the fault tree through a prohibition gate when expressing the functional failure event of the current component.
[0016] Preferably, in step S52 , the triggering condition of the expected functional failure event is represented by a prohibition gate.
[0017] Preferably, step S5 also includes: if the current component is an execution or decision-making system of an autonomous driving vehicle, the functional failure events of steps S51, S52 and S53, the expected functional failure events and the dangerous events of the input components are connected to the driver situational awareness error events through an AND gate, and then connected to the dangerous events.
[0018] Preferably, in step S4, the driver situation awareness error event that can lead to the dangerous event is connected to the dangerous event through an OR gate.
[0019] Preferably, when constructing the fault tree, uncovered faults of redundant components are also analyzed by using an incomplete coverage model.
[0020] Preferably, the driver situation awareness error event includes:
[0021] 1) The autonomous driving system makes an incorrect perception / decision or execution result, but the driver is unaware of the error and fails to take over the vehicle;
[0022] 2) The autonomous driving system makes the correct perception / decision or execution result, but the driver believes that the autonomous driving system makes the wrong perception / decision or execution result, causing the driver to take over the car and make incorrect driving behavior.
[0023] The beneficial effects of the present invention include at least the following: the fault tree constructed by the present invention can better represent functional failure events and expected functional failure events in the automotive system structure. By traversing the fault tree, it is possible to obtain scenario information that needs to be considered during the design phase, so that testing can be carried out during the testing phase. Qualitative analysis of the fault tree can deduce the combination of functional failure / expected functional failure events that led to the accident. In addition, quantitative analysis can also analyze the conditionally independent and conditionally dependent events present in the fault tree, which facilitates safety analysis of autonomous vehicles. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 Schematic diagram of a method flow in an embodiment of the present invention;
[0025] Figure 2 This is a schematic diagram of a fault tree of expected functional failure according to an embodiment of the present invention;
[0026] Figure 3 A schematic diagram of a fault tree of underlying causes of failure of an expected function according to an embodiment of the present invention;
[0027] Figure 4 This is a schematic diagram of the structure of an autonomous driving vehicle according to an embodiment of the present invention;
[0028] Figure 5 This is a fault tree diagram of an embodiment of the present invention that does not consider the incomplete coverage model;
[0029] Figure 6 A fault tree diagram of an incomplete coverage model is considered for an embodiment of the present invention;
[0030] Figure 7 Schematic diagram of the perception-decision-execution architecture of an autonomous driving vehicle according to an embodiment of the present invention;
[0031] Figure 8 A schematic diagram of a driver takeover model for an autonomous vehicle according to an embodiment of the present invention;
[0032] Figure 9 A schematic diagram of the interaction between a driver and an automatic driving system according to an embodiment of the present invention;
[0033] Figure 10 A fault tree diagram of a human-computer interaction model according to an embodiment of the present invention;
[0034] Figure 11A fault tree diagram constructed by the human-computer interaction model according to an embodiment of the present invention based on whether the autonomous driving perception / decision-making system has made a correct decision;
[0035] Figure 12 A schematic diagram of a fault tree constructed for a top event according to an embodiment of the present invention;
[0036] Figure 13 This is a schematic diagram of a fault tree constructed for a collision accident between a vehicle and a preceding vehicle according to an embodiment of the present invention;
[0037] Figure 14 A schematic diagram of a fault tree constructed for a dangerous event of a brake actuation system not working properly according to an embodiment of the present invention;
[0038] Figure 15 A schematic diagram of a fault tree constructed for a dangerous event in which the autonomous driving decision-making system does not work properly according to an embodiment of the present invention;
[0039] Figure 16 A schematic diagram of a fault tree constructed for a brake execution system failure according to an embodiment of the present invention;
[0040] Figure 17 This is a fault tree diagram constructed for the expected functional failure of the brake execution system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0041] The following is a clear and complete description of the technical solutions in the embodiments of the present invention, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts are within the scope of protection of the present invention.
[0042] The main execution stages of an autonomous vehicle include perception, decision-making, and execution. Therefore, the expected functional safety in the embodiments of the present invention mainly targets the expected functional safety issues that occur in these three stages.
[0043] like Figure 1 As shown, an embodiment of the present invention provides a method for constructing a fault tree of an automobile system considering expected functional safety, including the following steps:
[0044] Step S1: defining a structure diagram of an autonomous driving vehicle for which a fault tree is to be constructed;
[0045] Step S2: Set the initial scenario and set the top event; the top event represents the accident that causes the hazard;
[0046] Step S3: Connect all dangerous events that cause the top event with the top event through an OR gate;
[0047] Step S4: converting the dangerous event into a dangerous event of the execution system in the automobile system structure;
[0048] Step S5: For each hazardous event, reverse traverse the autonomous vehicle structure diagram to decompose the hazardous event into several sub-events that lead to the hazardous event. Based on the sub-event category, the sub-event of the input component hazardous event category is selected as the hazardous event for the next iteration. Step S5 is repeated until the fault tree is constructed; the expected functional safety is considered during the fault tree construction process.
[0049] Scenarios are crucial for intended functional safety. This embodiment utilizes inhibit gates within a fault tree to address the limitations of traditional static fault trees in representing scenarios in autonomous vehicles. The use of inhibit gates demonstrates the scenarios under which certain defects in the autonomous driving system are triggered, effectively embodying the concept of intended functional safety. Furthermore, the representation of scenarios using inhibit gates allows for the enumeration of possible causes of an event within that scenario, further guiding autonomous vehicle testing.
[0050] like Figure 2 As shown in the figure, consider a following vehicle scenario. One possible scenario for a collision between the ego vehicle and the preceding vehicle is the preceding vehicle suddenly braking, represented by a prohibit gate in the figure. In this scenario, the possible causes of the collision between the ego vehicle and the preceding vehicle include: (a) a functional failure of the brake component; (b) the brake component did not fail, and the braking operation was performed in time, but the braking distance was too long; (c) the brake component did not fail, but the braking operation was not performed or was performed too late. Each cause is connected to the prohibit gate through an OR gate.
[0051] like Figure 3 As shown in Figure 2, this method can also indicate the underlying cause of expected function failure. Although the camera can still work normally, in conditions of low visibility such as rainy and snowy weather, the camera may not be able to recognize the vehicle ahead, resulting in expected function failure.
[0052] Step S1 defines the structure diagram of the autonomous vehicle. In the structure diagram, the components of the autonomous vehicle and the relationships between the components need to be specified. For example, a simple autonomous vehicle structure is as follows: Figure 4As shown in the figure, the autonomous vehicle consists of a perception system, a decision-making system, and an execution system. The perception system utilizes radar and cameras for redundancy, while the decision-making system uses two sets of computing chips. If one set fails, the other can continue to function normally and execute the decision-making task. Electronic control units are installed on each of the four wheels, each with dual redundancy for enhanced safety. The autonomous vehicle system uses the perception system to perceive the surrounding environment and its own information, which is then transmitted to the decision-making system for task decision-making. After the decision-making system makes its decision, it sends a response instruction to the execution system for execution.
[0053] Wherein, step S5 includes the following steps:
[0054] Step 51: If the functional failure event of the current component can lead to the occurrence of the current dangerous event, the relationship between the occurrence of the functional failure event and the occurrence of the dangerous event is expressed according to the corresponding logic. In the embodiment of the present invention, when expressing the functional failure of the basic component, in order to further refine the fault process, environmental factors (scenarios) are taken into account, because environmental factors can also cause the component to fail. In addition, even with sufficient redundancy, a failure generated by a component, such as erroneous data, can propagate to other components and cause the entire system to fail. In order to further increase the accuracy of fault tree construction, the embodiment of the present invention also takes into account the incomplete coverage model in the functional failure event of the component.
[0055] Step 52: If the expected functional failure event of the current component can lead to the current dangerous event, first use the OR gate to list the corresponding expected functional failure events, use the inhibit gate to represent the triggering conditions of the current environment, and use the corresponding logic gate to represent the relationship between the events.
[0056] Step 53: If the dangerous event of the input component of the current component can cause the current dangerous event to occur, then insert the dangerous event and return to step 5 for traversal.
[0057] The incomplete coverage model mentioned in step S51 is explained as follows: Traditional fault-tolerant systems are mainly implemented through component redundancy. Under the redundancy mechanism, when a component fails, the system can still perform its functions normally due to the existence of redundancy. However, under the incomplete coverage model, even with sufficient redundancy, a failure generated by a component, such as incorrect data, can spread to other components, causing the entire system to fail. Consider a brake control unit with two redundancies of electronic control units A and B. If the incomplete coverage model is not considered, its fault tree is as follows: Figure 5 As shown, this fault tree only considers the coverage faults of electronic control units A and B. After considering the incomplete coverage model, the fault tree is as follows Figure 6In this fault tree, in addition to the covered faults of the electronic control units A and B, the uncovered faults of the electronic control units A and B are also considered.
[0058] In addition, in the autonomous vehicle system, human factors are also an important factor that cannot be ignored. The driver changes from the role of system operator to supervisor. The perception-decision-execution architecture of the autonomous vehicle is as follows: Figure 7 As shown, the driver's takeover model is as follows Figure 8 As shown in Figure 2, the interaction between the driver and the autonomous driving system is as follows: Figure 9 As shown in the figure. Although the driver is relieved of the tiring task of driving, they still need to remain attentive to their surroundings, maintain a certain level of situational awareness, and intervene promptly when dangerous situations arise. With the support of augmented reality or AI visualization technologies, and thanks to the high computing performance of computing chips, perception and decision-making results are often displayed simultaneously, allowing the driver to perceive the autonomous vehicle's perception and decision-making results. In this case, the driver can intervene not only during the autonomous vehicle's execution phase but also during the perception / decision-making phase. Furthermore, if the driver perceives an erroneous perception / decision result, they may not choose to take over the vehicle directly, but instead place their hands on the steering wheel and their foot on the brake pedal. This increases the driver's success rate when they subsequently attempt to take over the vehicle.
[0059] Under this human-computer interaction model, there are two reasons why autonomous vehicles may crash.
[0060] 1) The autonomous driving system makes an incorrect perception / decision or execution result, but the driver does not notice the incorrect result, resulting in the driver not taking over the car.
[0061] 2) The autonomous driving system makes a correct perception / decision or execution result, but the driver believes that the autonomous driving system makes an incorrect perception / decision or execution result, causing the driver to take over the vehicle and possibly make incorrect driving behavior.
[0062] The fault tree constructed is as follows Figure 10 As shown, considering the above-mentioned following scenario, depending on whether the autonomous driving perception / decision-making system makes the correct decision, the fault tree is as follows: Figure 11 shown.
[0063] When constructing the overall fault tree, if the current component is an execution or decision-making system, the functional failure events, expected functional failure events, and dangerous events of the input components mentioned in steps S51, S52, and S53 are connected to the aforementioned driver situational awareness error event through an AND gate, and then connected to the current dangerous event. For the dangerous event in step S4, if the aforementioned driver situational awareness error event can also cause it to occur, this event is connected to the dangerous event through an OR gate.
[0064] The embodiment of the present invention is as follows Figure 4 The automobile system structure diagram shown is used for explanation. The initial scenario selected is that there is a vehicle driving in a relatively close distance in front of the vehicle, that is, the vehicle following scenario. On the basis of the initial scenario, the collision scenario between the vehicle and the vehicle in front and the collision scenario between the vehicle and the roads on both sides are further refined. According to the method of the present invention, the functional failure events and expected functional failure events in the automobile system structure are listed from top to bottom. After constructing the fault tree, the structure diagram is searched for its main functional failure events, and the possible uncovered failures of the components are connected to the main functional failure events through OR gates. Part of the fault tree constructed is shown in the figure. Figures 12 to 17 shown.
[0065] In this fault tree, we can see the scenarios represented by the forbidden gates. By traversing this fault tree, we can identify scenarios that need to be considered during the design phase, allowing for testing during the testing phase. Qualitative analysis of the fault tree can deduce the combination of functional failures and expected functional failures that led to the accident. Furthermore, quantitative analysis can also reveal the conditionally independent and conditionally dependent events present in the fault tree.
[0066] The embodiment of the present invention further provides a human-computer interaction model to expand the construction of the fault tree.
[0067] The technical features of the above embodiments may be combined in any manner. To simplify the description, not all possible combinations of the technical features in the above embodiments are described. Only preferred embodiments of the present invention are presented. While the description is relatively specific and detailed, it should not be construed as limiting the scope of the present invention. As long as there are no contradictions in the combination of these technical features, they should be considered to be within the scope of this specification.
[0068] It should be noted that those skilled in the art may make various modifications and improvements without departing from the scope of the present invention, and these modifications and improvements fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be based on the appended claims.
Claims
1. A method for constructing a fault tree for an automotive system considering expected functional safety, characterized by: The following steps are involved: Step S1: defining a structure diagram of an autonomous driving vehicle for which a fault tree is to be constructed; Step S2: setting an initial scenario and setting a top event; the top event represents an accident that causes a hazard; Step S3: Connect all dangerous events that cause the top event with the top event through an OR gate; Step S4: converting the dangerous event into a dangerous event of the execution system in the automobile system structure; Step S5: For each of the dangerous events, reverse traverse the autonomous driving vehicle structure diagram to decompose the dangerous event to obtain several sub-events that cause the dangerous event. Based on the category of the sub-event, the sub-event of the dangerous event of the input component is used as the dangerous event of the new round of iteration, and step S5 is repeated until the fault tree is constructed; the sub-events include the functional failure event of the current component, the expected functional failure event of the current component, and the dangerous event of the input component of the current component.
2. The method for constructing a fault tree for an automobile system considering expected functional safety according to claim 1, characterized in that: Step S5 includes: Step S51: If the functional failure event of the current component can lead to the current dangerous event, then the relationship between the functional failure event and the dangerous event is expressed according to the corresponding logic; Step S52: If the expected functional failure event of the current component can lead to the current dangerous event, first use an OR gate to list the corresponding expected functional failure events, and use corresponding logic gates to represent the relationship between the events; Step S53: If the dangerous event of the input component of the current component can cause the current dangerous event to occur, then the dangerous event is inserted and the process returns to step S5 for traversal.
3. The method for constructing a fault tree for an automobile system considering expected functional safety according to claim 2, characterized in that: Step S51 connects the environmental factor to the fault tree through a prohibition gate when expressing the functional failure of the current component.
4. The method for constructing a fault tree for an automobile system considering expected functional safety according to claim 3, characterized in that: In step S52 , the triggering condition of the expected function failure is represented by a prohibition gate.
5. The method for constructing a fault tree for an automobile system considering expected functional safety according to claim 4, characterized in that: Step S5 also includes: if the current component is the execution or decision-making system of an autonomous driving vehicle, the functional failure events of steps S51, S52 and S53, the expected functional failure events and the dangerous events of the input components are connected to the driver situational awareness error events through an AND gate, and then connected to the dangerous events.
6. The method for constructing a fault tree for an automobile system considering expected functional safety according to claim 1, characterized in that: In step S4 , the driver situation awareness error event that can lead to the dangerous event is connected to the dangerous event through an OR gate.
7. The method for constructing a fault tree for an automobile system considering expected functional safety according to claim 1, characterized in that: When constructing the fault tree, uncovered faults of redundant components are also analyzed through incomplete coverage models.
8. A method for constructing a fault tree for an automobile system considering expected functional safety according to claim 5 or 6, characterized in that: The driver situation awareness error events include: 1) The autonomous driving system makes an incorrect perception / decision or execution result, but the driver is unaware of the error and fails to take over the vehicle; 2) The autonomous driving system makes the correct perception / decision or execution result, but the driver believes that the autonomous driving system makes the wrong perception / decision or execution result, causing the driver to take over the car and make incorrect driving behavior.
Citation Information
Patent Citations
Predicted function safety analysis method and system for automobile intelligent driving system
CN117726208A
Safety tree model-based electric vehicle operation and maintenance optimization method
WO2020211846A1