Function safety design method, device and equipment for automatic emergency braking system and storage medium
By determining the working scenarios and failure modes of the automatic emergency braking system, designing functional safety requirements and technical safety requirements, the functional safety design problems at the vehicle level of the AEB system are solved, and accurate emergency braking and safety guarantees are achieved in various driving scenarios.
Patent Information
- Application Number
- CN202510110842.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-27
AI Technical Summary
The functional safety design of existing intelligent driving systems mainly focuses on steering scenarios, and it is difficult to effectively design the functional safety architecture at the vehicle level of the AEB system, resulting in unintended braking of the AEB system of autonomous driving vehicles.
Determine the working scenario of the automatic emergency braking system by determining the road type, road conditions and driving behavior, analyze the possible abnormal types to set the failure mode, and design functional safety requirements and technical safety requirements based on these scenarios and modes to complete the functional safety design of the automatic emergency braking system.
Ensure that the automatic emergency braking system can accurately identify and perform emergency braking operations in various driving scenarios, identify potential safety risks, and meet the most basic safety guarantees when a failure or imminent failure, thereby avoiding the harm caused by unanticipated braking and ensuring traffic safety.
Smart Images

Figure CN120039237A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of vehicle safety, and particularly to a functional safety design method, device, equipment and storage medium for an automatic emergency braking system. Background Art
[0002] While intelligent driving provides convenience for traffic participants, it also brings safety risks. The control of intelligent driving vehicles is determined by chips and electronic and electrical components. Due to the inherent characteristics of electrons, chips and electronic and electrical components will inevitably have failures and faults. The failures of these electronic and electrical components will cause abnormal behaviors of the vehicle, such as unexpected acceleration of the vehicle, hitting a vehicle or a pedestrian; unexpected braking of the vehicle, resulting in a rear-end collision between the following vehicle and the self-vehicle. In the case where emergency braking is not required, due to the functional safety design problem of the AEB (Autonomous Emergency Braking) system, the vehicle will unexpectedly generate emergency braking, resulting in a rear-end collision of the following vehicle and causing harm.
[0003] Currently, the functional safety design of existing intelligent driving systems mainly focuses on steering scenarios. For the existing control technology of automatic emergency braking systems, how to design the functional safety architecture at the vehicle level of the AEB system to prevent unexpected braking of the AEB system of autonomous driving vehicles has become a problem to be solved.
[0004] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of the present application is to provide a functional safety design method, device, equipment and storage medium for an automatic emergency braking system, aiming to solve the technical problem of how to design the functional safety architecture at the vehicle level of the AEB system to prevent unexpected braking of the AEB system of autonomous driving vehicles.
[0006] To achieve the above purpose, the present application proposes a functional safety design method for an automatic emergency braking system, and the method includes:
[0007] Determine the working scenario of the automatic emergency braking system according to the road type, road surface conditions and driving behavior to obtain the target working scenario;
[0008] Determine the failure mode of the automatic emergency braking system according to the abnormal type of the automatic emergency braking system to obtain the target failure mode;
[0009] Design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode to complete the functional safety design of the automatic emergency braking system.
[0010] In one embodiment, the step of designing the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode includes:
[0011] Determine a hazard event according to the target working scenario and the target failure mode;
[0012] Evaluate the safety level of the hazard event to obtain a hazard event safety level result;
[0013] Determine the functional safety objectives of the automatic emergency braking system according to the hazard event safety level result;
[0014] Design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the functional safety objectives.
[0015] In one embodiment, the step of evaluating the safety level of the hazard event to obtain a hazard event safety level result includes:
[0016] Obtain the environmental state information, the self-vehicle driving state information, and the obstacle dynamic information of the hazard event;
[0017] Determine the exposure of the hazard event according to the environmental state information;
[0018] Determine the severity and controllability of the hazard event according to the driving state information and the obstacle dynamic information;
[0019] Determine the safety level of the hazard event according to the exposure, the severity, and the controllability to obtain a hazard event safety level result.
[0020] In one embodiment, the step of designing the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the functional safety objectives includes:
[0021] Design the functional safety requirements of the automatic emergency braking system from the aspects of the accuracy of obstacle perception information, the accuracy of deceleration control, the braking responsiveness of the actuator, the security of link information, the timeliness of fault detection, and the fault tolerance;
[0022] Design the technical safety requirements of the automatic emergency braking system from the aspects of information verification, hardware selection, hierarchical architecture construction, diagnostic strategy formulation, and safety strategy formulation according to the functional safety requirements.
[0023] In one embodiment, after the step of designing the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode to complete the functional safety design of the automatic emergency braking system, it further includes:
[0024] Perform fault diagnosis on the automatic emergency braking system according to the fault diagnosis strategy to obtain the target fault diagnosis result;
[0025] When the target fault diagnosis result does not meet the preset requirements, obtain the current braking information and braking request information;
[0026] Determine the fault code type of the automatic emergency braking system based on the current braking information and braking request information.
[0027] In one embodiment, the fault diagnosis strategy includes a perception diagnosis strategy and a regulation and control diagnosis strategy, and the target fault diagnosis result includes a first fault diagnosis result and a second fault diagnosis result;
[0028] The step of performing fault diagnosis on the automatic emergency braking system according to the fault diagnosis strategy to obtain the target fault diagnosis result includes:
[0029] Perform perception system diagnosis, radar fault diagnosis, camera fault diagnosis, and vehicle system diagnosis according to the perception diagnosis strategy to obtain the first fault diagnosis result;
[0030] Perform regulation and control system diagnosis, regulation and control system threshold monitoring, braking system fault diagnosis, and braking system threshold monitoring according to the regulation and control diagnosis strategy to obtain the second fault diagnosis result.
[0031] In one embodiment, the step of determining the fault code type of the automatic emergency braking system based on the current braking information and braking request information includes:
[0032] Calculate deceleration difference information, deceleration product information, and deceleration ratio information based on the current braking information and braking request information;
[0033] Determine the fault code type of the automatic emergency braking system based on the deceleration difference information, the deceleration product information, and the deceleration ratio information.
[0034] In addition, to achieve the above object, the present application also proposes a functional safety design device for an automatic emergency braking system, and the functional safety design device for the automatic emergency braking system includes:
[0035] A scenario definition module for determining the working scenario of the automatic emergency braking system according to the road type, road surface conditions, and driving behavior to obtain the target working scenario;
[0036] A mode definition module for determining the failure mode of the automatic emergency braking system according to the abnormal type of the automatic emergency braking system to obtain the target failure mode;
[0037] A safety design module is used to design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode, so as to complete the functional safety design of the automatic emergency braking system.
[0038] In addition, to achieve the above object, the present application also provides a device for functional safety design of an automatic emergency braking system, the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program is configured to implement the steps of the method for functional safety design of an automatic emergency braking system as described above.
[0039] In addition, to achieve the above object, the present application also provides a storage medium, the storage medium is a computer-readable storage medium, a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the method for functional safety design of an automatic emergency braking system as described above.
[0040] In addition, to achieve the above object, the present application also provides a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps of the method for functional safety design of an automatic emergency braking system as described above.
[0041] One or more technical solutions proposed by the present application have at least the following technical effects:
[0042] Determine the working scenario of the automatic emergency braking system according to the road type, road surface conditions and driving behavior to obtain the target working scenario; determine the failure mode of the automatic emergency braking system according to the abnormal type of the automatic emergency braking system to obtain the target failure mode; design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode, so as to complete the functional safety design of the automatic emergency braking system. By combining the road type, road surface conditions and driving behavior to determine the target working scenario of the automatic emergency braking system, it is ensured that the automatic emergency braking system can accurately identify and execute emergency braking operations in various driving scenarios. By analyzing the possible abnormal types of the automatic emergency braking system, the target failure mode of the automatic emergency braking system is set, clarifying the potential safety risks of the automatic emergency braking system. According to the target working scenario and the target failure mode, detailed functional safety requirements and technical safety requirements are designed, which can ensure that the automatic emergency braking system can still meet the most basic safety guarantee when a fault or an impending fault occurs, so as to avoid unexpected braking of the AEB system of an autonomous vehicle causing life or property damage and ensuring traffic safety. Description of the Drawings
[0043] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present application and, together with the specification, are used to explain the principles of the present application.
[0044] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0045] Figure 1 It is a schematic flowchart provided for the first embodiment of the functional safety design method of the automatic emergency braking system of the present application;
[0046] Figure 2 It is an example diagram of severity assessment provided for the first embodiment of the functional safety design method of the automatic emergency braking system of the present application;
[0047] Figure 3 It is an example diagram of controllability assessment provided for the first embodiment of the functional safety design method of the automatic emergency braking system of the present application;
[0048] Figure 4 It is a schematic flowchart provided for the second embodiment of the functional safety design method of the automatic emergency braking system of the present application;
[0049] Figure 5 It is a fault diagnosis structure diagram of the AEB system provided for the second embodiment of the functional safety design method of the automatic emergency braking system of the present application;
[0050] Figure 6 It is a schematic module structure diagram of the functional safety design device of the automatic emergency braking system according to the embodiment of the present application;
[0051] Figure 7 It is a schematic device structure diagram of the hardware operating environment involved in the functional safety design method of the automatic emergency braking system according to the embodiment of the present application.
[0052] The implementation, functional features, and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. Specific Embodiments
[0053] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0054] To better understand the technical solutions of the present application, the following will be described in detail in combination with the accompanying drawings of the specification and the specific embodiments.
[0055] The main solution of the embodiment of the present application is:
[0056] Determine the working scenarios of the automatic emergency braking system according to the road type, road surface conditions, and driving behavior to obtain the target working scenarios;
[0057] Determine the failure modes of the automatic emergency braking system according to the abnormal types of the automatic emergency braking system to obtain the target failure modes;
[0058] Design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenarios and the target failure modes to complete the functional safety design of the automatic emergency braking system.
[0059] In this embodiment, for the convenience of description, the following will be described with the recognition functional safety architecture design device as the execution subject.
[0060] While intelligent driving provides convenience for traffic participants, it also brings safety risks. The control of intelligent driving vehicles is determined by chips and electronic and electrical components. Due to the inherent characteristics of electrons, chips and electronic and electrical components will inevitably have failures and faults. The failures of these electronic and electrical components will cause abnormal behaviors of the vehicle, such as the vehicle accelerating unexpectedly and hitting other vehicles or pedestrians; the vehicle braking unexpectedly, causing the following vehicle to rear-end the self-vehicle. In the case where emergency braking is not required, due to the functional safety design problem of the AEB (Autonomous Emergency Braking) system, the vehicle will unexpectedly perform emergency braking, resulting in the following vehicle rear-ending and causing harm.
[0061] Currently, the functional safety design of existing intelligent driving systems mainly focuses on the steering scenario. For the existing control technology of the automatic emergency braking system, how to design the functional safety architecture at the vehicle level of the AEB system to prevent the AEB system of autonomous driving vehicles from performing unexpected braking has become a problem to be solved.
[0062] This application proposes a solution. By combining the road type, road surface conditions, and driving behavior to determine the target working scenarios of the automatic emergency braking system, it ensures that the automatic emergency braking system can accurately identify and perform emergency braking operations in various driving scenarios. By analyzing the possible abnormal types of the automatic emergency braking system, the target failure modes of the automatic emergency braking system are set, clarifying the potential safety risks of the automatic emergency braking system. According to the target working scenarios and the target failure modes, detailed functional safety requirements and technical safety requirements are designed, which can ensure that the automatic emergency braking system can still meet the most basic safety guarantees when it fails or is about to fail, preventing the AEB system of autonomous driving vehicles from performing unexpected braking and causing harm to life or property, and ensuring traffic safety.
[0063] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device or a functional safety design device that can implement the above functions. Hereinafter, the functional safety design device will be taken as an example to illustrate this embodiment and the following embodiments.
[0064] Based on this, the embodiment of the present application provides a functional safety design method for an automatic emergency braking system. Refer to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the functional safety design method for the automatic emergency braking system of the present application.
[0065] In this embodiment, the functional safety design method for the automatic emergency braking system includes steps S10 to S40:
[0066] Step S10, determine the working scenario of the automatic emergency braking system according to the road type, road surface conditions, and driving behavior to obtain the target working scenario;
[0067] It should be noted that in a scenario with heavy traffic, or when the driver is distracted or the vehicle speed is high, the abnormal appearance of moving or stationary targets in front of the vehicle will pose a high collision risk. At this time, the Autonomous Emergency Braking (AEB) system will take over the vehicle in time and control the vehicle to perform emergency braking with a large deceleration to avoid the occurrence of a collision or reduce the collision severity. However, in the case where emergency braking is not required, due to the functional safety design problem of the AEB system, the vehicle will unexpectedly perform emergency braking, resulting in a rear-end collision of the following vehicle and causing harm. Conducting research on the functional safety technology at the vehicle level for the existing AEB system and formulating the corresponding functional safety architecture can effectively identify and prevent possible failure modes of the AEB system, ensure that the AEB system can still maintain or switch to the safe mode when a failure occurs, thereby reducing safety risks and protecting the lives of drivers and passengers.
[0068] The functions of the AEB system are defined as follows: The AEB system is used in an intelligent driving system. It can sense the collision risk of the target in front (vehicles, pedestrians) through sensors. When a collision risk occurs, the AEB system takes corresponding actions according to the degree of danger and the driver's behavior, specifically including Forward Collision Warning (FCW), Brake Prefill (BP), Aggressive Warning Brake (AWB), Autonomous Emergency Braking (AEB), and Emergency Brake Assist (EBA), etc., so as to avoid or mitigate collisions.
[0069] The external interfaces defined for the AEB system include: signals related to Electronic Stability Control (ESC) of the braking system, signals related to the Vehicle Control Unit (VCU) of the powertrain system, signals related to the Attitude Control Unit (ACU) of the inertial navigation system, signals related to seat belts, signals related to doors, signals related to the brake pedal, and signals related to the accelerator pedal.
[0070] It should be noted that when defining the working scenarios of the AEB system to obtain the target working scenarios, it should at least include road types, road surface conditions, and driving behaviors. Specifically, road types can include highways, urban elevated roads, and urban roads, etc.; road surface conditions can include dry road surfaces and slippery road surfaces, etc.; driving behaviors can include straight driving and lane changing. Further, it can also be divided into high speed, medium speed, and low speed.
[0071] Exemplarily, for the vehicle driving scenarios in which the AEB system is used, the set target working scenarios can include the following 8 categories: a1. High-speed straight driving, a2. Medium-speed straight driving, a3. Low-speed straight driving, a4. Driving on a slippery road surface, a5. Lane changing on a highway, a6. Medium-speed lane changing on an urban road, a7. Lane changing on a slippery road surface on a highway, a8. Lane changing on a slippery road surface on an urban road. Among them, high-speed straight driving can be further divided into straight driving on a highway, straight driving on an urban elevated road, etc.; medium-speed straight driving can be further set as medium-speed straight driving on an urban road, and further can be set as medium-speed straight driving on a dry road surface of an urban road, etc.; low-speed straight driving can be further set according to traffic conditions such as roads with traffic jams (where pedestrians cross around), etc.; driving on a slippery road surface can be further divided into driving on a slippery road surface of an urban road and straight driving on a slippery road surface of a highway, etc.
[0072] Step S20: Determine the failure mode of the automatic emergency braking system according to the abnormal type of the automatic emergency braking system to obtain the target failure mode;
[0073] It should be noted that when defining the failure mode of the AEB system to obtain the target failure mode, the abnormal types of the AEB system need to be defined in detail. Specifically, the failure mode of the AEB system can be obtained in the way of Hazard and Operability Study (HAZOP) of functional safety. In the field of functional safety, the HAZOP method is used to analyze the system failure mode, identify possible hazard events, and evaluate their impact on the safety of the AEB system. Considering that when the AEB system takes over the vehicle, it needs to control the vehicle to achieve emergency braking with a large deceleration to avoid the occurrence of collision or reduce the collision degree, the abnormal types of the AEB system should at least include the abnormal starting time of the AEB system function to avoid unexpected braking. The abnormal types of the AEB system can also include the abnormal braking force output of the AEB system. Further, it can also include the abnormal timing of braking force output, the abnormal magnitude of braking force output, and the abnormal failure of braking force output.
[0074] Exemplarily, the failure modes set for the AEB system can include the following 7 categories: b1. The AEB system has no braking force output; b2. The braking force of the AEB system is insufficient; b3. The braking force of the AEB system is too large; b4. The function of the AEB system is unexpectedly activated; b5. The braking force exits too early after the function of the AEB system is activated; b6. The braking force output of the AEB system is too late; b7. The braking force output of the AEB system is stuck. Among them, b1 and b7 correspond to the abnormal failure of braking force output; b2 and b3 correspond to the abnormal magnitude of braking force output; b5 and b6 correspond to the abnormal timing of braking force output, and b4 corresponds to the abnormal starting time of the AEB system function. By defining the failure mode of the AEB system in detail, it can ensure that the AEB system transitions to a safe state under different fault conditions.
[0075] Step S30: Design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode to complete the functional safety design of the automatic emergency braking system.
[0076] It should be understood that when analyzing the functional safety of the AEB system at the vehicle level, after clarifying the target operating scenarios and target failure modes of the AEB system, hazard analysis and risk assessment can be carried out based on the target operating scenarios and target failure modes, so as to identify and determine possible hazard events. For each hazard event, systematic hazard analysis and risk assessment are carried out, and the assessment content includes severity, exposure, and controllability, so as to quantify potential safety risks and determine the corresponding Automotive Safety Integrity Level (ASIL) according to the assessment results. On this basis, specific functional safety goals of the AEB system can be set, and these goals can be mapped to the functional safety requirements (FSR) and technical safety requirements (TSR) of the AEB system to ensure that all safety performance indicators in the design and implementation process of the AEB system can meet the functional safety standards, thus ensuring the safe operation of the AEB system in complex environments.
[0077] In a feasible implementation manner, step S30 may include steps S31 to S34:
[0078] Step S31, determining a hazard event according to the target operating scenario and the target failure mode;
[0079] It should be noted that a hazard event refers to a situation where the AEB system may lose its function or cause adverse consequences under the failure mode corresponding to the operating scenario, such as causing casualties, environmental damage, or property losses. Combining the defined number of target operating scenarios and the number of target failure modes, all possible hazard events for the AEB system can be obtained.
[0080] Exemplarily, for the 8 types of target operating scenarios and 7 types of target failure modes defined in the above step examples, 8×7 = 56 hazard events of the AEB system can be determined.
[0081] Step S32, evaluating the safety level of the hazard event to obtain a hazard event safety level result;
[0082] It should be noted that the safety level is the Automotive Safety Integrity Level (ASIL). In the process of evaluating the safety level of a hazard event, the ASIL level can be determined according to the Safety Evaluation Concept (SEC) methodology of functional safety and combined with the quantitative evaluation method of SEC. SEC is a functional safety assessment methodology used to determine the Safety Integrity Level (SIL) or Automotive Safety Integrity Level (ASIL) of a system or component, including the identification, evaluation, and formulation of control measures for potential failures of the system. Specifically, when evaluating the safety level of a hazard event, the reference standard can be the evaluation matrix in the ISO 26262 standard, including the Severity (S), Exposure (E), and Controllability (C) of the hazard event. Among them, the severity S is used to evaluate the severity of the consequences that may occur when the AEB system fails, ranging from no injury to fatal injury; the exposure E is used to evaluate the probability of occurrence or the possibility of exposure of the AEB system failure, ranging from very unlikely to very likely; the controllability C is used to evaluate the driver's response ability when the failure occurs, ranging from easy to control to uncontrollable.
[0083] After obtaining the severity S, exposure E, and controllability C of the hazard event, the ASIL level of each hazard event can be determined by referring to the automotive safety integrity level table. The safety level includes a total of 5 levels: QM, A - D. Among them, QM means that although there is a hazard risk, it can be effectively controlled only through quality management measures, and there is no need to set corresponding safety function goals. The safety level result of the hazard event includes the ASIL level evaluated for each hazard event.
[0084] In a feasible implementation manner, step S32 may include: obtaining the environmental state information, the self - vehicle driving state information, and the obstacle dynamic information of the hazard event; determining the exposure of the hazard event according to the environmental state information; determining the severity and controllability of the hazard event according to the driving state information and the obstacle dynamic information; determining the safety level of the hazard event according to the exposure, the severity, and the controllability, and obtaining the safety level result of the hazard event.
[0085] It should be noted that when evaluating the severity S, exposure E, and controllability C of a hazard event, it is necessary to obtain the environmental state information of the hazard event, the driving state information of the host vehicle, and the dynamic information of the obstacle. Among them, the environmental state information includes the road type of the hazard event (such as urban road, highway, etc.), the road surface condition (such as dry road surface or slippery road surface, etc.), and the driving operation (such as going straight or turning, etc.). The driving state information of the host vehicle includes the driving parameters of the host vehicle under the corresponding environmental state information, such as vehicle speed, acceleration, following distance, etc. The dynamic information of the obstacle is the dynamic information of the front target obstacle (vehicle, pedestrian, roadblock) that is about to have a collision risk with the host vehicle. For a stationary obstacle, it can be the distance of the obstacle, etc. For a moving obstacle, it can be the speed of the obstacle, the acceleration of the obstacle, etc.
[0086] It should be understood that the exposure of a single element (such as road type, road surface condition, and driving operation) in the environmental state information can be evaluated based on the VDA702 standard. At the same time, combined with project experience, the exposure after the superposition of multiple elements can be determined to obtain the exposure E of the hazard event. Through theoretical calculation and simulation, the severity S and controllability C of the hazard event can be accurately determined. Specifically, by combining the driving state information of the host vehicle and the dynamic information of the obstacle, the relative speed when the host vehicle collides with the obstacle can be calculated, and the time required for the driver of the host vehicle to react before the collision (i.e., the driver reaction time). According to the relative speed, the damage degrees of the host vehicle and the obstacle during the collision can be evaluated to obtain the severity S of the hazard event. According to the driver reaction time, it can be evaluated to what extent the driver can avoid the obstacle after taking over the vehicle to obtain the controllability C of the hazard event. After obtaining the severity S, exposure E, and controllability C of the hazard event, the ASIL level of the hazard event can be determined by referring to the automotive safety integrity level table.
[0087] Exemplarily, for a hazard event, on a dry road surface of a highway, driving straight at a medium speed, the autonomous vehicle has an unexpected braking. Assuming that the front target obstacle is a vehicle driving straight, the speeds of the front and rear vehicles are the same, the vehicle speed is 70 kph, the rear vehicle is the host vehicle, and the Predictive Emergency Braking System (PEBS) function unexpectedly outputs full braking force, resulting in an unexpected braking of the vehicle. If the rear vehicle cannot brake in time, it will cause a rear-end collision. Taking the vehicle speed of 70 kph (about 19.44 m / s) in a more severe scenario, the following distance (safe following distance) S 0 is 19.44 m (1 s following time interval), the deceleration of the front vehicle is 10 m / s 2 , after the driver of the rear vehicle notices the deceleration of the front vehicle, decelerates at 10 m / s 2 for deceleration.
[0088] At this time, based on the VDA702 standard and project experience, for highways, the exposure level is E4; for dry roads, the exposure level is E4; for straight driving, the exposure level is E4. After combining the above scenarios, the exposure rate is E4, that is, the exposure level of this hazard event is E4.
[0089] Refer to Figure 2 , Figure 2 This is the severity assessment example diagram provided for the first embodiment of the functional safety design method of the automatic emergency braking system of this application. As Figure 2 shown, by combining the driving state information of the host vehicle, that is, the initial speed v and the safe following distance S 0 , and the dynamic information of the obstacle, that is, the deceleration a of the vehicle in front, the relative vehicle speed ΔV when the front and rear vehicles collide can be calculated, and then the severity of this hazard event can be evaluated as S3.
[0090] Refer to Figure 3 , Figure 3 This is the controllability assessment example diagram provided for the first embodiment of the functional safety design method of the automatic emergency braking system of this application. As Figure 3 shown, by combining the driving state information of the host vehicle, that is, the initial speed v 1 , the following distance S 0 , and the deceleration a after the reaction of the driver of the vehicle behind 2 , and the dynamic information of the obstacle, that is, the deceleration a of the vehicle in front 1 , the reaction time t1 left for the driver can be calculated as 1.009 s, and then the controllability of this hazard event can be evaluated as C2.
[0091] In summary, by referring to the automotive safety integrity level table, it can be obtained that for straight driving at medium speed on a dry road of a highway, the ASIL level of the hazard event corresponding to the unexpected output of full braking force by the AEB system is C level.
[0092] Step S33, determine the functional safety target of the automatic emergency braking system according to the safety level result of the hazard event;
[0093] It should be noted that after obtaining the safety level result of the hazard event, the safety level of each hazard event, that is, the ASIL level, can be determined according to the safety level result of the hazard event. For hazard events with an ASIL level above QM, corresponding functional safety targets need to be set to reduce the harm to road traffic caused by abnormal activation timing of the AEB system function and abnormal braking force output of the AEB system, and ensure road traffic safety. For hazard events with the same ASIL level, the same safety target can be set, indicating that the same or similar technical means can be adopted to achieve the safety guarantee of the AEB system.
[0094] Specifically, when an unexpected deceleration occurs, if the following vehicle has no time to react, it will collide with the preceding vehicle, and the severity level will vary according to the relative vehicle speed at the time of the collision. Therefore, the functional safety goal set for the AEB system should avoid the unexpected activation of the AEB system and avoid the AEB system outputting unexpected braking force, which may lead to vehicle hazards.
[0095] Exemplarily, the ASIL levels of the 56 hazard events of the AEB system in the above example are evaluated, and the highest ASIL level obtained is ASIL C. The safety goals can be set correspondingly according to the characteristics of the hazard events at each ASIL level, as shown in Table 1 below. The safety state in the table is the state that the AEB system needs to transition to in order to avoid or reduce the traffic hazards caused by the unexpected activation of the AEB system and the output of unexpected braking force.
[0096] Table 1
[0097]
[0098] Step S34: Design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the functional safety goal.
[0099] It should be understood that after setting the specific functional safety goal of the AEB system, the functional safety goal can be mapped to the functional safety requirements (FSR) and technical safety requirements (TSR) of the AEB system to ensure that all safety performance indicators in the design and implementation process of the AEB system can meet the functional safety standards, thereby ensuring the safe operation of the AEB system in a complex environment.
[0100] In a feasible implementation manner, step S34 may include steps S341 to S342:
[0101] Step S341: Design the functional safety requirements of the automatic emergency braking system from the aspects of obstacle perception information accuracy, deceleration control accuracy, actuator braking responsiveness, link information security, fault detection timeliness, and fault tolerance according to the functional safety goal;
[0102] It should be noted that by decomposing the set functional safety objectives through a fault tree, functional safety requirements can be obtained. The functional safety requirements for the accuracy of obstacle perception information are used to prevent the transmission of incorrect or false obstacle information (such as false alarms or missed detections of obstacles). The functional safety requirements for the accuracy of deceleration control are used to ensure that the controller can output an appropriate deceleration according to actual needs after obtaining accurate obstacle information, and the deceleration should not be too large or too small. The functional safety requirements for the braking responsiveness of the actuator are used to ensure that the actuator can respond to the braking requirements of the controller for the vehicle and perform correct braking operations. The functional safety requirements for the security of link information are used to ensure that the data transmitted between the perception system, the controller, and the actuator is accurate and effective. The functional safety requirements for timely fault detection are used to ensure that when a fault occurs in the AEB system, the fault can be detected and reported in a timely manner within the specified time, and corresponding alarm information can be sent to the driver. The functional safety requirements for fault tolerance are used to ensure that when a fault occurs in the AEB system, the vehicle can be transitioned to a safe state.
[0103] Exemplarily, the functional safety requirements TSR set for the AEB system can be as follows:
[0104] FSR1: Ensure that the perception system does not send obstacle information unexpectedly;
[0105] FSR2: Ensure that the controller system outputs correct deceleration information based on the obstacle information;
[0106] FSR3: Ensure that the actuator ESC correctly responds to the braking request of the controller;
[0107] FSR4: Ensure that the information sent from the perception system to the controller has undergone a secure link detection;
[0108] FSR5: Ensure that the information sent from the controller system to the actuator has undergone a secure link detection;
[0109] FSR6: Ensure that the controller does not output an excessive deceleration;
[0110] FSR7: Ensure that the actuator does not output an excessive deceleration;
[0111] FSR8: After a system failure, it can be detected within a certain time and the corresponding fault time and fault code can be output;
[0112] FSR9: Ensure that when a fault is detected, the system can issue an alarm and turn on the fault light to alert the driver;
[0113] FSR10: Ensure that when a tolerable fault occurs, there is a redundant fault tolerance control algorithm to transition the vehicle to a safe state;
[0114] FSR11: Ensure that when a serious system failure occurs, the vehicle is steered to the side of the road and emergency braking is initiated to bring it into a safe state.
[0115] FSR12: Ensure that the vehicle is transitioned to a safe state within the fault tolerance time interval of the system.
[0116] Among them, the accuracy level of obstacle perception information corresponds to FSR1; the accuracy level of deceleration control corresponds to FSR2, FSR6, and FSR7; the braking responsiveness level of the actuator corresponds to FSR3; the security level of link information corresponds to FSR4 and FSR5; the timeliness level of fault detection corresponds to FSR8 and FSR9; the fault tolerance level corresponds to FSR10, FSR11, and FSR12.
[0117] Step S342: According to the functional safety requirements, design the technical safety requirements of the automatic emergency braking system from the aspects of information verification, hardware selection, hierarchical architecture construction, diagnostic strategy formulation, and safety strategy formulation.
[0118] It should be noted that the functional safety requirements of the AEB system need to be realized through technical means. The requirements for the realized technical means (such as software, hardware, and method strategies) are the technical safety requirements, which need to be set correspondingly. The technical safety requirements for information verification are used to verify obstacle information, CAN bus data, and braking deceleration information. The technical safety requirements for hardware selection are used to ensure that the MCU meets the functional safety requirements. The technical safety requirements for hierarchical architecture construction are used for a multi-layer architecture designed to effectively respond to different driving scenarios. The technical safety requirements for diagnostic strategy formulation are used to design the details of fault diagnosis. The technical safety requirements for safety strategy formulation are used to ensure communication safety, the safety of the AEB system during braking execution, and fault handling safety.
[0119] Exemplarily, the technical safety requirements TSR set for the AEB system can be as follows:
[0120] TSR1: To ensure the correctness of the obstacle information sent by the perception system, design to obtain target information from two different paths or methods and perform fusion verification.
[0121] TSR2: All CAN buses need to perform E2E verification.
[0122] TSR3: The AEB system should correctly calculate the AEB braking deceleration based on environmental perception sensors and vehicle self-information.
[0123] TSR4: To correctly issue a braking request from the controller, it is necessary to select an MCU that meets the functional safety requirements.
[0124] TSR5: The overall deceleration request output of the AEB system needs to reach the ASIL B level. The specific method is as follows: The deceleration module of the AEB system needs to be designed with a two-layer architecture, namely L1 layer, L2 layer, and L3 layer. Among them, the L1 layer normally calculates the deceleration of the AEB system based on perception and vehicle information, and the safety level can be developed according to QM; the L2 layer algorithm needs to monitor the output of the L1 layer algorithm based on the current vehicle signal, and it is of ASIL B level. If the L2 layer determines that the current vehicle signal meets the AEB system output, the L2 layer algorithm will output the output of the L1 layer algorithm. If the L2 layer determines that the current vehicle signal does not meet the AEB system output, the L2 layer algorithm will limit the output of the L1 layer algorithm; in order to prevent the controller from issuing excessive deceleration, it is necessary to design a threshold monitoring layer for the L3 layer to verify the deceleration issued by the controller.
[0125] TSR6: The deceleration request and deceleration value sent by the AEB system to the actuator ESC are designed with a strategy that requires a secure communication protection mechanism.
[0126] TSR7: In order to ensure that the fault diagnosis module can detect and output the corresponding fault code and fault time within 100 ms, it is necessary to design a fault diagnosis strategy.
[0127] TSR8: The design strategy is that the braking deceleration request sent by the AEB system should be less than the TBD limit value (obtained according to calibration and safety confirmation tests).
[0128] TSR9: The design strategy is that in each power-on cycle, the AEB system needs to perform a power-on self-check. If the self-check fails, it should be prohibited from entering the AEB system function in the current power-on cycle, and the fault information should be correctly sent to the IVI with E2E communication protection within TBD ms.
[0129] TSR10: The design strategy is that if the AEB has entered the safe state and the AEB can ensure the normal use of the AEB function, then the AEB is not allowed to recover from the safe state within 1000 ms.
[0130] Among them, the information verification layer corresponds to TSR1, TSR2, and TSR3; the hardware selection layer corresponds to TSR4; the hierarchical architecture construction layer corresponds to TSR5; the diagnostic strategy formulation layer corresponds to TSR9; the safety strategy formulation layer corresponds to TSR6, TSR8, and TSR10.
[0131] This embodiment provides a functional safety design method for an automatic emergency braking system. The working scenarios of the automatic emergency braking system are determined according to the road type, road surface conditions, and driving behavior to obtain the target working scenarios; the failure modes of the automatic emergency braking system are determined according to the abnormal types of the automatic emergency braking system to obtain the target failure modes; the functional safety requirements and technical safety requirements of the automatic emergency braking system are designed according to the target working scenarios and the target failure modes to complete the functional safety design of the automatic emergency braking system. By combining the road type, road surface conditions, and driving behavior to determine the target working scenarios of the automatic emergency braking system, it is ensured that the automatic emergency braking system can accurately identify and execute emergency braking operations in various driving scenarios. By analyzing the possible abnormal types of the automatic emergency braking system, the target failure modes of the automatic emergency braking system are set, clarifying the potential safety risks of the automatic emergency braking system. According to the target working scenarios and target failure modes, detailed functional safety requirements and technical safety requirements are designed, which can ensure that the automatic emergency braking system can still meet the most basic safety guarantees in case of failure or impending failure, so as to avoid unexpected braking of the AEB system of autonomous vehicles causing life or property damage and ensuring traffic safety.
[0132] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as that in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 4 , after step S30, the functional safety design method of the automatic emergency braking system further includes steps S40 to S60:
[0133] Step S40, perform fault diagnosis on the automatic emergency braking system according to the fault diagnosis strategy to obtain the target fault diagnosis result;
[0134] It should be noted that after the design of the AEB system functional safety architecture in the above steps S10 to S30 is completed, the implementation of the AEB system application layer will be carried out based on the functional safety requirements and technical safety requirements. After that, each time the vehicle is powered on, a power-on self-check will be performed to check whether there is a fault in the AEB system functional safety module according to the fault diagnosis strategy to obtain the target fault diagnosis result. If it is determined that the AEB system functional safety module is faulty according to the target fault diagnosis result, the AEB system will be prohibited from starting. Among them, by performing fault tree analysis (FTA) and failure mode and effect analysis (FMEA) on the system architecture, the fault modes that may lead to violation of the safety target are identified, and the AEB system functional safety module can be obtained.
[0135] Refer to Figure 5 , Figure 5This is the fault diagnosis structure diagram of the AEB system provided by the second embodiment of the functional safety design method for the automatic emergency braking system of the present application. The AEB system includes a perception system and a planning and control system. The fault diagnosis results of the radar, camera, and vehicle system are received through the perception system, as well as the fault diagnosis results of the braking system and the threshold monitoring results of the braking system of the braking system. The diagnosis results of the perception system are integrated and fed back into the planning and control system. The data provided by the perception system is integrated through the planning and control system, and the planning and control system diagnosis and threshold monitoring are performed to obtain the target fault diagnosis result to ensure that the AEB system operates within the safety parameters. When it is determined according to the target fault diagnosis result that the AEB system has not failed, a normal system fault code is output. At this time, the braking system of the vehicle will receive an instruction from the planning and control system when the AEB system function is activated and perform a braking operation.
[0136] In a feasible implementation manner, the fault diagnosis strategy includes a perception diagnosis strategy and a planning and control diagnosis strategy, and the target fault diagnosis result includes a first fault diagnosis result and a second fault diagnosis result; step S40 may include steps S41 to S42:
[0137] Step S41, perform perception system diagnosis, radar fault diagnosis, camera fault diagnosis, and vehicle system diagnosis according to the perception diagnosis strategy to obtain the first fault diagnosis result;
[0138] It should be noted that the perception diagnosis strategy includes a perception system diagnosis strategy, a radar fault diagnosis strategy, a camera fault diagnosis strategy, and a vehicle system diagnosis strategy.
[0139] Specifically, when performing perception system diagnosis according to the perception system diagnosis strategy, at least one of the following faults of the perception system will be detected by the perception system diagnosis module: 1. Perception system undervoltage fault; 2. Perception system overvoltage fault; 3. Perception system main chip overheating fault; 4. Perception system internal Watchdog fault; 5. Perception system internal and external communication fault; 6. Perception system timing fault; 7. Perception system software operation timeout fault; 8. Perception system software jamming fault. Summarize the above detection information to obtain the perception system diagnosis result.
[0140] When performing radar fault diagnosis according to the radar fault diagnosis strategy, the radar fault diagnosis module will detect at least one of the following faults of the radar: 1. Radar undervoltage fault; 2. Radar overvoltage fault; 3. Radar calibration fault; 4. Radar main chip overheating fault; 5. Radar internal FLASH fault, fault when powering on and off to read the program and system parameters; 6. Radar internal Watchdog&rest fault; 7. Radar receiving vehicle body data fault; 8. Radar internal clock signal frequency exceeding the specified range; 9. Radar internal electromagnetic wave transmitter fault; 10. Radar internal receiving antenna fault; 11. Radar internal SPI fault. Summarize the above detection information to obtain the radar fault diagnosis result.
[0141] When performing camera fault diagnosis according to the camera fault diagnosis strategy, the camera fault diagnosis module will detect at least one of the following faults of the camera: 1. Camera undervoltage fault; 2. Camera overvoltage fault; 3. Camera calibration fault; 4. Camera main chip overheating fault; 5. Camera internal Watchdog fault; 6. Camera receiving vehicle body data fault; 7. Camera internal clock signal fault; 8. Camera internal image production module fault; 9. Abnormal camera frame rate; 10. Camera internal I2C fault; 11. Camera internal register read-back function fault; 12. Camera video sequence fault. Summarize the above detection information to obtain the camera fault diagnosis result.
[0142] When performing vehicle system diagnosis according to the vehicle system diagnosis strategy, the vehicle system diagnosis module will monitor at least one of the following signal abnormalities of the vehicle system: 1. Monitoring the validity of the door signal; 2. Door open / close signal; 3. Monitoring the validity of the driver's seat belt signal; 4. Driver's seat belt open / close signal; 5. Monitoring the validity of the vehicle speed / wheel speed signal; 6. Vehicle speed / wheel speed signal; 7. Monitoring the validity of the vehicle actual lateral and longitudinal acceleration signals sent by the vehicle inertial navigation system; 8. Vehicle actual lateral and longitudinal acceleration signals; 9. Monitoring the validity of the brake pedal signal; 10. Brake pedal depressed / not depressed signal; 11. Monitoring the validity of the accelerator pedal signal; 12. Accelerator pedal depressed / not depressed signal. Summarize the above detection information to obtain the vehicle system diagnosis result.
[0143] It should be understood that the perception system diagnosis result, radar fault diagnosis result, camera fault diagnosis result and vehicle system diagnosis result are integrated to obtain the first fault diagnosis result.
[0144] Step S42, perform regulation and control system diagnosis, regulation and control system threshold monitoring, braking system fault diagnosis and braking system threshold monitoring according to the regulation and control diagnosis strategy to obtain the second fault diagnosis result.
[0145] It should be noted that the regulation and control diagnosis strategy includes the regulation and control system diagnosis strategy, the regulation and control system threshold monitoring strategy, the braking system fault diagnosis strategy, and the braking system threshold monitoring strategy.
[0146] Specifically, when diagnosing the regulation and control system according to the regulation and control system diagnosis strategy, at least one of the following faults of the regulation and control system will be detected through the regulation and control system diagnosis module: 1. Undervoltage fault of the regulation and control system; 2. Overvoltage fault of the regulation and control system; 3. Overheating fault of the main chip of the regulation and control system; 4. Internal Watchdog fault of the regulation and control system; 5. Internal and external communication fault of the regulation and control system; 6. Timing fault of the regulation and control system; 7. Software running timeout fault of the regulation and control system; 8. Software jamming fault of the regulation and control system. Summarize the above detection information to obtain the regulation and control system diagnosis result.
[0147] When monitoring the regulation and control system threshold according to the regulation and control system threshold monitoring strategy, the following parameter anomalies of the regulation and control system will be monitored through the regulation and control system threshold monitoring module: The deceleration request sent by the regulation and control system exceeds the threshold a. Summarize the above detection information to obtain the regulation and control system threshold monitoring result.
[0148] When diagnosing the braking system fault according to the braking system fault diagnosis strategy, at least one of the following faults of the braking system will be detected through the braking system fault diagnosis module: 1. Undervoltage fault of the braking system; 2. Overvoltage fault of the braking system; 3. Calibration fault of the braking system; 4. Overheating fault of the main chip of the braking system; 5. Internal FLASH fault of the braking system, fault when reading the program and system parameters during power-on and power-off; 6. Internal Watchdog&rest fault of the braking system; 7. Fault of receiving vehicle body data by the braking system; 8. The frequency of the internal clock signal of the braking system exceeds the specified range; 9. Solenoid valve fault of the braking system; 10. Motor fault of the braking system; 11. Internal sensor fault of the braking system. Summarize the above detection information to obtain the braking system fault diagnosis result.
[0149] When monitoring the braking system threshold according to the braking system threshold monitoring strategy, whether the braking system data is abnormal will be monitored through the braking system threshold monitoring module: 1. The deceleration request sent by the AEB system to the braking system exceeds the threshold a; 2. The actual deceleration of the vehicle exceeds the deceleration request of the braking system. Summarize the above detection information to obtain the braking system threshold monitoring result.
[0150] It should be understood that the regulation and control system diagnosis result, the regulation and control system threshold monitoring result, the braking system fault diagnosis result, and the braking system threshold monitoring result are integrated to obtain the second fault diagnosis result.
[0151] Step S50, when the target fault diagnosis result does not meet the preset requirements, obtain the current braking information and braking request information;
[0152] It should be understood that the target fault diagnosis result meeting the preset requirements means that when the functional safety module of the AEB system is fault-diagnosed according to the fault diagnosis strategy, no abnormality is detected and the system normal fault code is output. At this time, the AEB system will work normally. If the target fault diagnosis result does not meet the preset requirements, that is, when the system normal fault code is not received, the current braking information of the vehicle will be obtained through the Inertial Measurement Unit (IMU), and at the same time, the braking request information will be obtained according to the braking request requested by the AEB system, and the current braking information and the braking request information will be compared and judged to further detect whether there is an abnormal braking force output of the AEB system and an abnormal braking force output of the AEB system.
[0153] Step S60, determining the fault code type of the automatic emergency braking system based on the current braking information and the braking request information.
[0154] It should be noted that according to the current braking information, the actual braking deceleration of the vehicle can be determined, and according to the braking request information, the desired braking deceleration can be obtained. By calculating the difference between the actual braking deceleration and the desired braking deceleration, different possible fault types of the AEB system can be identified and classified, and the fault code type of the automatic emergency braking system can be obtained.
[0155] In a feasible implementation manner, step S60 may include steps S61 to S62:
[0156] Step S61, calculating deceleration difference information, deceleration product information, and deceleration ratio information based on the current braking information and the braking request information;
[0157] It should be noted that after obtaining the actual braking deceleration and the desired braking deceleration of the vehicle according to the current braking information and the braking request information, the absolute value of the difference between the actual braking deceleration and the desired braking deceleration will be calculated to obtain the deceleration difference information; the product of the actual braking deceleration and the desired braking deceleration will be calculated to obtain the deceleration product information; the ratio of the difference between the actual braking deceleration and the desired deceleration to the desired deceleration will be calculated to obtain the deceleration ratio information.
[0158] Step S62, determining the fault code type of the automatic emergency braking system based on the deceleration difference information, the deceleration product information, and the deceleration ratio information.
[0159] It should be noted that the fault code types of the automatic emergency braking system include fault codes related to the loss of emergency braking ability, fault codes related to the AEB system error request drive, fault codes related to excessive or too small braking force, fault codes related to unexpected emergency braking, and fault codes related to unexpected emergency braking.
[0160] Specifically, when the deceleration difference information is the expected braking deceleration, it is considered that the failure occurring in the AEB system at this time is the loss of emergency braking ability, and a fault code related to the loss of emergency braking ability is output; when the deceleration product information is negative, it is considered that the fault occurring in the AEB system at this time is the vehicle generating an incorrect driving force, and a fault code related to an incorrect request for driving in the AEB system is output; when the deceleration ratio information ranges between (0, 1), it is considered that the fault occurring in the AEB system at this time is that the emergency braking is too large or too small, and a fault code related to the emergency braking being too large or too small is output; when the deceleration difference information is an arbitrary constant, it is considered that the fault occurring in the AEB system at this time is the unexpected generation of emergency braking, and a fault code related to the unexpected emergency braking is output; when the deceleration difference information, the deceleration product information, and the deceleration ratio information do not meet any of the above situations, it is considered that the AEB system has an emergency braking jamming fault, and a fault code related to the AEB system jamming is output.
[0161] It should be understood that when determining a fault in the AEB system, while obtaining the type of fault code of the automatic emergency braking system, the time of fault occurrence, that is, the system fault time, is also obtained, and corresponding safety control strategies are executed according to the fault code type and the system fault time, so that the AEB system transitions to a safe state after a fault occurs, ensuring the life and property safety of traffic participants.
[0162] This embodiment provides a method for designing the functional safety of an automatic emergency braking system. The automatic emergency braking system is fault diagnosed according to a fault diagnosis strategy to obtain a target fault diagnosis result; when the target fault diagnosis result does not meet the preset requirements, current braking information and braking request information are obtained; based on the current braking information and the braking request information, the type of fault code of the automatic emergency braking system is determined. Through the fault diagnosis strategy, comprehensive fault detection and diagnosis of the automatic emergency braking system are carried out to ensure that the system can timely identify and respond to potential faults during operation. After the initial fault diagnosis of the automatic emergency braking system according to the fault diagnosis strategy, if the fault diagnosis result does not meet the preset requirements, the current braking information and braking request information are obtained, and the fault code type is determined by combining these information, so as to further accurately identify and classify the fault types of the automatic emergency braking system, thereby providing a basis for subsequent fault handling and effectively improving the reliability and safety of the automatic emergency braking system.
[0163] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the method for designing the functional safety of the automatic emergency braking system of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0164] The present application also provides a functional safety design device for an automatic emergency braking system. Please refer to Figure 6 The functional safety design device for the automatic emergency braking system includes:
[0165] A scenario definition module 10, configured to determine the working scenario of the automatic emergency braking system according to the road type, road surface conditions, and driving behavior, so as to obtain a target working scenario;
[0166] A mode definition module 20, configured to determine the failure mode of the automatic emergency braking system according to the abnormal type of the automatic emergency braking system, so as to obtain a target failure mode;
[0167] A safety design module 30, configured to design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode, so as to complete the functional safety design of the automatic emergency braking system.
[0168] In one embodiment, the safety design module 30 is further configured to determine a hazard event according to the target working scenario and the target failure mode; evaluate the safety level of the hazard event to obtain a hazard event safety level result; determine the functional safety target of the automatic emergency braking system according to the hazard event safety level result; and design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the functional safety target.
[0169] In one embodiment, the safety design module 30 is further configured to obtain the environmental state information, the self-vehicle driving state information, and the obstacle dynamic information of the hazard event; determine the exposure of the hazard event according to the environmental state information; determine the severity and controllability of the hazard event according to the driving state information and the obstacle dynamic information; and determine the safety level of the hazard event according to the exposure, the severity, and the controllability to obtain a hazard event safety level result.
[0170] In one embodiment, the safety design module 30 is further configured to design the functional safety requirements of the automatic emergency braking system from the aspects of obstacle perception information accuracy, deceleration control accuracy, actuator braking responsiveness, link information security, fault detection timeliness, and fault tolerance according to the functional safety target; and design the technical safety requirements of the automatic emergency braking system from the aspects of information verification, hardware selection, hierarchical architecture construction, diagnostic strategy formulation, and safety strategy formulation according to the functional safety requirements.
[0171] In one embodiment, the safety design module 30 is further configured to perform a fault diagnosis on the automatic emergency braking system according to a fault diagnosis strategy to obtain a target fault diagnosis result; when the target fault diagnosis result does not meet the preset requirements, obtain current braking information and braking request information; and determine a fault code type of the automatic emergency braking system based on the current braking information and the braking request information.
[0172] In one embodiment, the safety design module 30 is further configured to perform a perception system diagnosis, a radar fault diagnosis, a camera fault diagnosis, and a vehicle system diagnosis according to the perception diagnosis strategy to obtain the first fault diagnosis result; and perform a control system diagnosis, a control system threshold monitoring, a braking system fault diagnosis, and a braking system threshold monitoring according to the control diagnosis strategy to obtain the second fault diagnosis result.
[0173] In one embodiment, the safety design module 30 is further configured to calculate deceleration difference information, deceleration product information, and deceleration ratio information based on the current braking information and the braking request information; and determine a fault code type of the automatic emergency braking system based on the deceleration difference information, the deceleration product information, and the deceleration ratio information.
[0174] The automatic emergency braking system functional safety design device provided by the present application adopts the automatic emergency braking system functional safety design method in the above embodiment, and can solve the technical problem of how to design the functional safety architecture of the AEB system at the vehicle level to prevent the AEB system of an autonomous vehicle from experiencing unexpected braking. Compared with the prior art, the beneficial effects of the automatic emergency braking system functional safety design device provided by the present application are the same as those of the automatic emergency braking system functional safety design method provided by the above embodiment, and other technical features in the automatic emergency braking system functional safety design device are the same as those disclosed in the above embodiment method, and will not be elaborated herein.
[0175] The present application provides an automatic emergency braking system functional safety design device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the automatic emergency braking system functional safety design method in the first embodiment above.
[0176] Next, refer to Figure 7It shows a schematic structural diagram of a device suitable for implementing the functional safety design of the automatic emergency braking system according to the embodiments of the present application. The device for the functional safety design of the automatic emergency braking system in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions: tablet computers), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The shown device for the functional safety design of the automatic emergency braking system is merely an example and should not impose any limitation on the functions and scope of use of the embodiments of the present application.
[0177] As Figure 7 shown, the device for the functional safety design of the automatic emergency braking system may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the device for the functional safety design of the automatic emergency braking system are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the device for the functional safety design of the automatic emergency braking system to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a device for the functional safety design of the automatic emergency braking system having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be implemented or had alternatively.
[0178] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.
[0179] The functional safety design device of the automatic emergency braking system provided by the present application adopts the functional safety design method of the automatic emergency braking system in the above embodiments, and can solve the technical problem of how to design the functional safety architecture of the AEB system at the vehicle level to prevent the AEB system of autonomous vehicles from having unexpected braking. Compared with the prior art, the beneficial effects of the functional safety design device of the automatic emergency braking system provided by the present application are the same as those of the functional safety design method of the automatic emergency braking system provided by the above embodiments, and other technical features in the functional safety design device of the automatic emergency braking system are the same as those disclosed in the method of the previous embodiment, and will not be elaborated here.
[0180] It should be understood that the various parts disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0181] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0182] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the functional safety design method of the automatic emergency braking system in the above embodiments.
[0183] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0184] The above computer-readable storage medium can be included in the functional safety design device of the automatic emergency braking system; or it can exist separately without being assembled into the functional safety design device of the automatic emergency braking system.
[0185] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by the functional safety design device of the automatic emergency braking system, the functional safety design device of the automatic emergency braking system is enabled to: determine the working scenario of the automatic emergency braking system based on the road type, road surface conditions, and driving behavior to obtain the target working scenario; determine the failure mode of the automatic emergency braking system based on the abnormal type of the automatic emergency braking system to obtain the target failure mode; design the functional safety requirements and technical safety requirements of the automatic emergency braking system based on the target working scenario and the target failure mode to complete the functional safety design of the automatic emergency braking system.
[0186] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).
[0187] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0188] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0189] The readable storage medium provided by this application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned functional safety design method of the automatic emergency braking system, which can solve the technical problem of how to design the functional safety architecture of the AEB system at the vehicle level to prevent the AEB system of autonomous vehicles from experiencing unexpected braking. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the functional safety design method of the automatic emergency braking system provided by the above embodiment, and will not be elaborated here.
[0190] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it realizes the steps of the functional safety design method of the automatic emergency braking system as described above.
[0191] The computer program product provided by this application can solve the technical problem of how to design the functional safety architecture of the AEB system at the vehicle level to prevent the AEB system of autonomous vehicles from experiencing unexpected braking. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as those of the functional safety design method of the automatic emergency braking system provided by the above embodiment, and will not be elaborated here.
[0192] The above are only some embodiments of this application, and thus do not limit the patent scope of this application. Any equivalent structural transformation made under the technical concept of this application by using the content of the specification and drawings of this application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of this application.
Claims
1. A functional safety design method for an automatic emergency braking system, characterized in that: The method includes: Determine the working scenario of the automatic emergency braking system according to the road type, road conditions and driving behavior, and obtain the target working scenario; determining a failure mode of the automatic emergency braking system according to an abnormality type of the automatic emergency braking system to obtain a target failure mode; The functional safety requirements and technical safety requirements of the automatic emergency braking system are designed according to the target working scenario and the target failure mode to complete the functional safety design of the automatic emergency braking system.
2. The method according to claim 1, characterized in that The step of designing the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode comprises: Determining a hazardous event based on the target working scenario and the target failure mode; Assess the safety level of the hazardous event and obtain a safety level result of the hazardous event; Determine the functional safety target of the automatic emergency braking system according to the safety level result of the hazardous event; The functional safety requirements and technical safety requirements of the automatic emergency braking system are designed according to the functional safety goals.
3. The method according to claim 2, characterized in that The step of evaluating the safety level of the hazardous event to obtain a result of the safety level of the hazardous event includes: Obtaining environmental status information of the hazardous event, vehicle driving status information, and obstacle dynamic information; Determining the exposure level of the hazardous event according to the environmental status information; Determining the severity and controllability of the hazardous event according to the driving state information and the obstacle dynamic information; The safety level of the hazardous event is determined according to the exposure, the severity and the controllability, and a safety level result of the hazardous event is obtained.
4. The method according to claim 2, characterized in that The step of designing the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the functional safety goals includes: According to the functional safety objectives, the functional safety requirements of the automatic emergency braking system are designed from the aspects of obstacle perception information accuracy, deceleration control precision, actuator braking responsiveness, link information security, fault detection timeliness and fault tolerance; According to the functional safety requirements, the technical safety requirements of the automatic emergency braking system are designed from the levels of information verification, hardware selection, layered architecture construction, diagnostic strategy formulation and safety strategy formulation.
5. The method according to claim 1, characterized in that After the step of designing the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode to complete the functional safety design of the automatic emergency braking system, the method further includes: Performing fault diagnosis on the automatic emergency braking system according to a fault diagnosis strategy to obtain a target fault diagnosis result; When the target fault diagnosis result does not meet the preset requirements, obtaining current braking information and braking request information; A fault code type of the automatic emergency braking system is determined based on the current braking information and the braking request information.
6. The method according to claim 5, characterized in that The fault diagnosis strategy includes a perception diagnosis strategy and a regulation and control diagnosis strategy, and the target fault diagnosis result includes a first fault diagnosis result and a second fault diagnosis result; The step of performing fault diagnosis on the automatic emergency braking system according to the fault diagnosis strategy to obtain a target fault diagnosis result comprises: Performing perception system diagnosis, radar fault diagnosis, camera fault diagnosis, and vehicle system diagnosis according to the perception diagnosis strategy to obtain the first fault diagnosis result; According to the control diagnosis strategy, control system diagnosis, control system threshold monitoring, brake system fault diagnosis and brake system threshold monitoring are performed to obtain the second fault diagnosis result.
7. The method according to claim 5, characterized in that The step of determining the fault code type of the automatic emergency braking system based on the current braking information and the braking request information comprises: Calculating deceleration difference information, deceleration product information, and deceleration ratio information based on the current braking information and the braking request information; A fault code type of the automatic emergency braking system is determined based on the deceleration difference information, the deceleration product information, and the deceleration ratio information.
8. A functional safety design device for an automatic emergency braking system, characterized in that: The device comprises: A scenario definition module is used to determine the working scenario of the automatic emergency braking system according to the road type, road conditions and driving behavior to obtain the target working scenario; A mode definition module, used to determine a failure mode of the automatic emergency braking system according to an abnormality type of the automatic emergency braking system to obtain a target failure mode; A safety design module is used to design the functional safety requirements and technical safety requirements of the automatic emergency braking system according to the target working scenario and the target failure mode, so as to complete the functional safety design of the automatic emergency braking system.
9. An automatic emergency braking system functional safety design device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the functional safety design method for an automatic emergency braking system according to any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the functional safety design method for an automatic emergency braking system as described in any one of claims 1 to 7 are implemented.