Function safety assessment method and device and vehicle

By considering the response behavior of external traffic participants in vehicle functional safety assessment, hazard analysis and risk assessment are carried out, and the chain hazard problem caused by ignoring external traffic participants in the prior art is solved, achieving a more comprehensive safety assessment and a higher safety level.

CN120080864APending Publication Date: 2025-06-03CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510568921.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

The prior art ignores the response behavior of external traffic participants in vehicle functional safety analysis, resulting in possible chain hazard events and increasing safety risks.

Method used

A functional safety assessment method is proposed to determine the original safety level by obtaining the original risk scenario of the vehicle, conducting hazard analysis and risk assessment. Then, based on the assumptions of external traffic participants, further hazard analysis and risk assessment are carried out, and the safety level is updated, and the target safety level is finally determined.

Benefits of technology

By considering the response behavior of external traffic participants, neglected secondary hazards can be assessed, ensuring that the target safety level covers multi-level chain hazard risk scenarios and avoids greater safety risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120080864A_ABST
    Figure CN120080864A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a function safety assessment method and device and a vehicle. The method comprises the steps of obtaining an original risk scene of a vehicle, performing hazard analysis and risk assessment to obtain an original safety level, and obtaining an external hypothesis based on external traffic participants under the condition that the original risk scene comprises the external traffic participants; under the condition that the external hypothesis is related to the vehicle safety, performing hazard analysis and risk assessment based on the external hypothesis and the original risk scene to obtain an updated safety level of the vehicle; and determining a target security level of the vehicle based on the original security level and the updated security level. Through the above mode, the external hypothesis is the response behavior expected to be adopted by the traffic participant in the original risk scene, and the updated security level is obtained based on the external hypothesis and the original risk scene, so that secondary hazards neglected in the related mode can be evaluated, the target security level is ensured to cover the multi-level linkage hazard risk scene, and the safety of the traffic participant is improved. And thus, greater risks are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of vehicles, and more specifically, to a functional safety assessment method, apparatus, and vehicle. Background Art

[0002] With the continuous development of vehicle technologies, in order to meet the diverse vehicle usage needs of users, intelligent driving assistance functions related to vehicles are also constantly improving. In related methods, in order to avoid unacceptable risks caused by electronic and electrical failures, vehicle manufacturers use the functional safety standard GB / T34590 to perform functional safety analysis on vehicles to obtain the corresponding functional safety level of the vehicles. However, in related methods, taking the adaptive cruise control function as an example, the incorrect braking of the vehicle itself may cause the vehicle behind to brake urgently, thereby triggering a chain reaction of the vehicles behind the vehicle behind, resulting in greater safety risks. Therefore, there is also a problem in related methods that after the vehicle is controlled based on the functional safety level, chain hazard events may be triggered by surrounding vehicles. Summary of the Invention

[0003] In view of the above problems, the present application provides a functional safety assessment method, apparatus, and vehicle to improve the above problems.

[0004] In a first aspect, the present application provides a functional safety assessment method, the method comprising: Obtain the original risk scenario of the vehicle, perform hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle, where the original risk scenario includes the state of the vehicle under a preset functional abnormality, the behavior of the vehicle under a preset functional abnormality, driver operations, driving scenarios, and driving environments; When the driving scenario in the original risk scenario includes external traffic participants, obtain an external hypothesis based on the external traffic participants, where the external hypothesis includes the response behavior expected to be taken by the external traffic participants in the original risk scenario; When the external hypothesis is relevant to vehicle safety, perform hazard analysis and risk assessment based on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle; Determine the target safety level of the vehicle based on the original safety level and the updated safety level.

[0005] Optionally, the obtaining an external hypothesis based on the external traffic participants includes: Based on the external traffic participants, determine the state, position, and response behavior of the external traffic participants from a preset behavior library; Based on the external traffic participants, the states corresponding to the external traffic participants, the positions of the external traffic participants, and the response behaviors of the external traffic participants, the external hypothesis is obtained.

[0006] Optionally, the hazard analysis and risk assessment based on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle includes: Based on the external hypothesis and the original risk scenario, a comprehensive scenario is obtained; Based on the probabilities of multiple sub-scenarios occurring in the comprehensive scenario, the probability of the comprehensive scenario occurring is obtained to obtain the exposure level of the vehicle under the condition of considering the external hypothesis, where the sub-scenario is the state of the vehicle under a preset functional abnormality or the behavior of the vehicle under a preset functional abnormality or the driver's operation or the state of the external traffic participants or the response behavior of the external traffic participants or the driving environment; Estimate the probabilities of the driver and the external traffic participants being injured and the degree of injury in the comprehensive scenario to obtain the injury level of the vehicle under the condition of considering the external hypothesis; Estimate the probability of the driver and the external traffic participants avoiding injury in the comprehensive scenario to obtain the controllability level of the vehicle under the condition of considering the external hypothesis; Based on the exposure level, the controllability level, and the injury level, the updated safety level of the vehicle is determined.

[0007] Optionally, the determination of the target safety level of the vehicle based on the original safety level and the updated safety level includes: When the original safety level is higher than the updated safety level, determine the target safety level of the vehicle as the original safety level; When the updated safety level is higher than the original safety level, determine the target safety level of the vehicle as the updated safety level.

[0008] Optionally, when the updated safety level is higher than the original safety level, determining the target safety level of the vehicle as the updated safety level further includes: When the updated safety level is higher than the original safety level, determine whether to adopt the updated safety level as the target safety level based on preset requirements; When it is determined based on preset requirements to adopt the updated safety level, determine the target safety level of the vehicle as the updated safety level; When it is determined based on preset requirements not to adopt the updated safety level, adjust the external hypothesis and re-determine the target safety level of the vehicle.

[0009] Optionally, the method further includes: When the original risk scenario does not include external traffic participants, determining the safety level of the vehicle as the original safety level.

[0010] Optionally, the method further includes: When the external hypothesis is not related to the safety of the vehicle, determining the safety level of the vehicle as the original safety level.

[0011] In a second aspect, the present application provides a functional safety assessment method device, the device includes: An external hypothesis determination unit, configured to obtain the original risk scenario of the vehicle, perform hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle, where the original risk scenario includes the state of the vehicle under a preset functional abnormality, the behavior of the vehicle under a preset functional abnormality, the driving scenario, and the driving environment; when the driving scenario in the original risk scenario includes external traffic participants, based on the external traffic participants, obtain an external hypothesis, where the external hypothesis is the response behavior expected to be taken by the external traffic participants in the original risk scenario; A safety level determination unit, configured to, when the external hypothesis is related to the vehicle safety, perform hazard analysis and risk assessment based on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle; based on the original safety level and the updated safety level, determine the target safety level of the vehicle.

[0012] In a third aspect, the present application provides a vehicle, including one or more processors and a memory; one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the above method.

[0013] In a fourth aspect, the present application provides a computer-readable storage medium, in which program code is stored, and when the program code runs, the above method is executed.

[0014] A functional safety assessment method, device, vehicle, and storage medium provided by the present application, after obtaining the original risk scenario of the vehicle, perform a hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle. When the driving scenario in the original risk scenario includes external traffic participants, an external hypothesis is obtained based on the external traffic participants, and the external hypothesis includes the response behavior expected to be taken by the external traffic participants in the original risk scenario. When the external hypothesis is relevant to vehicle safety, a hazard analysis and risk assessment are performed based on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle. Based on the original safety level and the updated safety level, the target safety level of the vehicle is determined.

[0015] In the present application, through the above method, since the external hypothesis is the response behavior expected to be taken by the external traffic participants in the original risk scenario, and the updated safety level is obtained based on the external hypothesis and the original risk scenario, secondary hazards ignored in related methods can be evaluated, ensuring that the target safety level covers multi-level chain hazard risk scenarios, and further avoiding greater risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 Shows a flowchart of a functional safety assessment method proposed in an embodiment of the present application; Figure 2 Shows a flowchart of an implementation method of step S130 in a functional safety assessment method proposed in an embodiment of the present application; Figure 3 Shows a flowchart of a functional safety assessment method proposed in an embodiment of the present application; Figure 4 Shows a flowchart of a functional safety assessment method proposed in an embodiment of the present application; Figure 5 Shows a flowchart of a preferred functional safety assessment method proposed in an embodiment of the present application; Figure 6 Shows a structural block diagram of a functional safety assessment method device proposed in an embodiment of the present application; Figure 7 Shows a structural block diagram of a vehicle proposed by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0019] In the accompanying drawings, sometimes for clarity, the sizes of the constituent elements, the thicknesses of the layers, or the areas may be exaggerated. Therefore, any implementation of the present disclosure is not necessarily limited to the sizes shown in the figures, and the shapes and sizes of the components in the figures do not reflect the true proportions. In addition, the accompanying drawings schematically show ideal examples, and any implementation of the present disclosure is not limited to the shapes or values shown in the accompanying drawings.

[0020] In the related art, in order to avoid unacceptable risks caused by electronic and electrical failures, vehicle manufacturers use the functional safety standard GB / T 34590 to perform functional safety analysis on vehicles to obtain the corresponding functional safety level of the vehicle. However, in the related methods, taking the adaptive cruise control function as an example, the wrong braking of the vehicle may cause the following vehicle to brake urgently, which may trigger a chain reaction of the vehicles behind the following vehicle, resulting in greater safety risks. Therefore, there is also a problem that after the vehicle is controlled based on the functional safety level, the surrounding vehicles may trigger a chain of hazard events in the related methods.

[0021] Therefore, in the embodiments of the present application, a functional safety assessment method is proposed. After obtaining the original risk scenario of the vehicle, a hazard analysis and risk assessment are performed on the original risk scenario to obtain the original safety level of the vehicle. When the driving scenario in the original risk scenario includes external traffic participants, an external hypothesis is obtained based on the external traffic participants. The external hypothesis includes the response behavior expected to be taken by the external traffic participants in the original risk scenario. When the external hypothesis is related to vehicle safety, a hazard analysis and risk assessment are performed based on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle. Based on the original safety level and the updated safety level, the target safety level of the vehicle is determined.

[0022] In the present application, through the above method, since the external hypothesis is the response behavior expected to be taken by traffic participants in the original risk scenario, and the updated safety level is obtained based on the external hypothesis and the original risk scenario, secondary hazards ignored in the related methods can be evaluated, ensuring that the target safety level covers multi-level chain hazard risk scenarios, and thus avoiding greater risks.

[0023] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are explained first. The nouns and terms involved in the embodiments of the present application are applicable to the following explanations.

[0024] HARA analysis (Hazard Analysis and Risk Assessment): It can be used to identify and evaluate potential hazards of automotive electrical and electronic systems and determine their risk levels. Among them, the content of HARA analysis can include hazard identification, assessment of exposure, severity, and controllability, so as to finally determine the Automotive Safety Integrity Level (ASIL). In the present application, the exposure analysis can be used to evaluate the probability of a certain hazard scenario occurring during the vehicle life cycle. The severity analysis can be used to evaluate the severity of potential hazards to personnel, property, or the environment. The controllability analysis can be used to evaluate the ability of the driver or other road users to avoid harm when a hazard occurs.

[0025] ACC (Adaptive Cruise Control): It can be an advanced driver assistance system that can monitor the speed and distance of the vehicle ahead through radar or camera and automatically adjust the speed of the vehicle to maintain a safe following distance.

[0026] The embodiments of the present application will be described below with reference to the accompanying drawings.

[0027] Please refer to Figure 1 , a functional safety assessment method provided by an embodiment of the present application, the method includes: S110: Obtain the original risk scenario of the vehicle, and perform hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle.

[0028] Among them, the original risk scenario can include the state of the vehicle under a preset functional abnormality, the behavior of the vehicle under a preset functional abnormality, driver operations, driving scenarios, and driving environments. The preset function can be an assisted driving function or an autonomous driving function preset in the vehicle and controlled by the electrical and electronic system; in the embodiments of the present application, the preset function can include but is not limited to ACC, automatic parking control, and automatic emergency braking; the preset functional abnormality can be a situation where the preset function fails during vehicle driving. The state of the vehicle can be the real-time physical parameters of the vehicle, which can include but are not limited to vehicle speed, acceleration, steering angle, gear position, and light status; as an example, the state of the vehicle under a preset functional abnormality can be that the current speed of the vehicle is a km / h and the current acceleration of the vehicle is b m / s2 etc. The behavior of the vehicle can be the actions taken by the vehicle. In this application, the behavior of the vehicle under abnormal preset functions can include, but is not limited to, unexpected acceleration / deceleration, steering failure, and lighting failure. The driver operation can be the intervention behavior taken by the driver under abnormal preset functions. In this application, the driver operation can include, but is not limited to, emergency braking, manual steering, and switching driving modes. The driving scenario can be the current driving situation of the vehicle, which can include, but is not limited to, highway following situation and urban traffic jam situation. The driving environment can include, but is not limited to, weather (rain / snow), lighting (night / tunnel), and road type (highway / urban road).

[0029] Among them, the original safety level can be the safety level obtained by evaluating the vehicle-level failure scenario through HARA analysis when the preset function of the vehicle is abnormal. In the embodiments of this application, the original safety level can include five levels, namely QM (Quality Management), ASIL A (the lowest safety level), ASIL B (medium safety level), ASIL C (high safety level), and ASIL D (the highest safety level).

[0030] As a way, when developers develop relevant functions in the vehicle (assisted driving functions or autonomous driving functions controlled by the electronic and electrical system), they can screen and obtain the state of the vehicle under abnormal preset functions, the behavior of the vehicle under abnormal preset functions, driver operations, driving scenarios, and driving environments from the risk scenario library to obtain the original risk scenario. Then, they can perform HARA analysis on the original risk scenario. Specifically, they can perform exposure analysis, harm analysis, and controllability analysis on the original risk scenario respectively, so as to obtain the corresponding exposure level, harm level, and controllability level. Furthermore, they can obtain the original safety level based on the exposure level, harm level, and controllability level.

[0031] Among them, the risk scenario library can be a structured database, which can be used to store various scenario information related to vehicle functional safety (the state of the vehicle under abnormal preset functions, the behavior of the vehicle under abnormal preset functions, driver operations, driving scenarios, driving environments, etc.).

[0032] Optionally, when developers obtain the original risk scenario from the risk scenario library, they can first input the specific type of function abnormality (for example, unexpected braking of the ACC system) to match the state of the vehicle under abnormal preset functions or the behavior of the vehicle under abnormal preset functions or driver operations or driving scenarios or driving environments based on the function abnormality type, so as to combine the multiple matched information to obtain the original risk scenario.

[0033] In the embodiments of the present application, the original risk scenario can be embodied in ways such as text, pictures, videos, etc. As an example, the original risk scenario can specifically be that the vehicle is traveling on a highway at a speed of 100 km / h and is about to enter a tunnel, but the headlights on the vehicle cannot be turned on normally (since the light changes from bright to dark and the headlights cannot be turned on normally, the driver will lose part of the field of vision). Therefore, the potential risks of the vehicle include, but are not limited to, colliding with the vehicle in front and colliding with the road edge; thus, the HARA analysis can be performed on the original risk scenario to obtain the original safety level corresponding to the original risk scenario.

[0034] S120: When the driving scenario in the original risk scenario includes external traffic participants, an external hypothesis is obtained based on the external traffic participants.

[0035] Among them, the external traffic participants can include, but are not limited to, large vehicles, small vehicles, pedestrians, cyclists, and other traffic participants. The external hypothesis can include the response behaviors expected to be taken by the external traffic participants in the original risk scenario.

[0036] As a way, when developers develop vehicle-related functions, they can define the response behaviors taken by external traffic participants based on the behaviors of the vehicle when the preset function is abnormal based on the experience of researchers to obtain the external hypothesis.

[0037] As another way, based on the external traffic participants, the state of the external traffic participants, the position of the external traffic participants, and the response behaviors of the external traffic participants can be determined from the preset behavior library; based on the external traffic participants, the state corresponding to the external traffic participants, the position of the external traffic participants, and the response behaviors of the external traffic participants, an external hypothesis is obtained.

[0038] Among them, the preset behavior library can be a structured database, which can be used to store the response behaviors that external traffic participants (such as other vehicles, pedestrians, cyclists, etc.) may take in different scenarios; in the embodiments of the present application, the information stored in the preset behavior library can include, but is not limited to, the type of the external traffic participants, the state of the external traffic participants, the position of the external traffic participants, and the response behaviors of the external traffic participants. The type of the external traffic participants can include, but is not limited to, vehicles, pedestrians, cyclists, and other traffic participants.

[0039] In an embodiment of the present application, when the external traffic participant is a vehicle, the state of the external traffic participant may include, but is not limited to, vehicle speed, acceleration, steering angle, gear position, and light state. The position of the external traffic participant may include, but is not limited to, the position relative to the host vehicle (such as in front of the host vehicle, behind the host vehicle, far behind the host vehicle, beside the host vehicle, etc.), the distance relative to the host vehicle (such as following distance, lateral distance, etc.), and the road position (such as within the lane line, intersection, etc.). The response behavior of the external traffic participant may include, but is not limited to, braking (such as deceleration magnitude, braking timing, etc.), steering (such as avoidance direction, steering angle, etc.), accelerating, and no response.

[0040] In an embodiment of the present application, when the external traffic participant is a pedestrian, the state of the external traffic participant may include, but is not limited to, walking speed, walking direction, mobility, etc. The position of the external traffic participant may include, but is not limited to, the distance from the host vehicle and the area where the pedestrian is located (such as on the sidewalk, in the middle of the road, near the lane line, etc.). The response behavior of the external traffic participant may include, but is not limited to, accelerating to pass, retreating to the sidewalk, and stopping moving forward.

[0041] Optionally, the behaviors of typical traffic participants can be extracted based on real traffic data (such as in-vehicle sensor logs), and behavior data in different scenarios can be generated based on simulation tests to construct a preset behavior library.

[0042] Optionally, when a developer obtains an external hypothesis from the preset behavior library, the behavior of the host vehicle under abnormal preset functions and the external traffic participant can be input to match the external traffic participant, the state corresponding to the external traffic participant, the position of the external traffic participant, the response behavior of the external traffic participant, etc., so that multiple matched information can be combined to obtain the external hypothesis.

[0043] As a way, before obtaining an external hypothesis based on the external traffic participant, it can be first determined whether the driving scenario in the original risk scenario includes an external traffic participant, so that when the driving scenario in the original risk scenario includes an external traffic participant, an external hypothesis can be obtained based on the external traffic participant. In an embodiment of the present application, techniques such as sensor detection, data fusion, and data analysis can be used to determine whether the driving scenario in the original risk scenario includes an external traffic participant.

[0044] Optionally, when the original risk scenario does not include an external traffic participant, the safety level of the vehicle can be determined as the original safety level.

[0045] In an embodiment of the present application, after obtaining the original risk scenario, it is determined whether the original risk scenario includes external traffic participants. If there are external traffic participants, the external traffic participants can be analyzed based on a preset behavior library to further analyze whether a chain risk hazard will occur. If there are no external traffic participants, the safety level can be directly determined to be the original safety level. Only when the original risk scenario involves external traffic participants, an external hypothesis analysis is performed to avoid redundant evaluation of irrelevant scenarios, thereby improving analysis efficiency and reducing redundant calculations.

[0046] S130: When the external assumption is related to vehicle safety, perform hazard analysis and risk assessment based on the external assumption and the original risk scenario to obtain an updated safety level of the vehicle.

[0047] The updated safety level may be the safety level obtained by HARA analysis of vehicle-level failure scenarios and external assumptions when a preset function of the vehicle fails. In the embodiment of the present application, the updated safety level may include five levels, namely, QM (Quality Management), ASIL A (minimum safety level), ASIL B (medium safety level), ASIL C (high safety level), and ASIL D (highest safety level).

[0048] As a method, before obtaining the updated safety level of the vehicle, it is possible to first determine whether the external assumptions obtained are related to vehicle safety, so that when the external assumptions are related to vehicle safety, hazard analysis and risk assessment can be performed on the external assumptions and the original risk scenario to obtain the updated safety level of the vehicle. In the embodiment of the present application, it is possible to determine whether the external assumptions are related to vehicle safety based on the hazard identification analysis in the HARA analysis.

[0049] In the related art, when performing functional safety analysis, usually only the direct risk of failure of the electronic and electrical systems of the vehicle is focused on, ignoring the response of external traffic participants (such as the following vehicle and pedestrians) triggered by the behavior of the vehicle, which in turn causes greater risks. As an example, when the vehicle brakes unexpectedly due to ACC abnormality, the vehicle brakes at a deceleration of A1, and it is assumed that the following vehicle avoids at a deceleration of A2, but it is not analyzed whether the braking of the rear vehicle will cause the rear vehicle of the following vehicle to rear-end. Therefore, in the embodiment of the present application, by introducing external assumptions (i.e., clarifying the response behavior of external traffic participants), the potential risks in the functional safety of the vehicle can be more comprehensively identified and evaluated, ensuring that the safety analysis is not limited to the vehicle system, but also covers the chain risks associated with external traffic participants, so that a more comprehensive safety assessment can be achieved.

[0050] As a way, Figure 2As shown, based on external assumptions and the original risk scenario, a hazard analysis and risk assessment are performed to obtain the updated safety level of the vehicle, including: S131: Based on the external assumptions and the original risk scenario, obtain a comprehensive scenario.

[0051] Among them, the comprehensive scenario can be a complete risk scenario formed by combining external assumptions on the basis of the original risk scenario, covering the scenarios of the vehicle itself and external traffic participants; the comprehensive scenario can include the state of the vehicle under preset functional abnormalities, the behavior of the vehicle under preset functional abnormalities, driver operations, the state of external traffic participants, the response behaviors of external traffic participants, driving scenarios, driving environments, etc.

[0052] In the embodiments of the present application, a fusion algorithm based on a Probabilistic Graphical Model (PGM) and Fault Tree Analysis (FTA) can be used to fuse external assumptions with the original risk scenario to obtain a comprehensive scenario.

[0053] S132: Based on the probabilities of multiple sub-scenarios in the comprehensive scenario occurring, obtain the probability of the comprehensive scenario occurring, so as to obtain the exposure level of the vehicle under the condition of considering the external assumptions.

[0054] Among them, the sub-scenario can be the state of the vehicle under preset functional abnormalities or the behavior of the vehicle under preset functional abnormalities or driver operations or the state of the external traffic participants or the response behaviors of external traffic participants or the driving environment. In the embodiments of the present application, the exposure level can include four levels, namely E1 (very low probability), E2 (low probability), E3 (medium probability), and E4 (high probability).

[0055] As a way, based on the probabilities of multiple sub-scenarios occurring, the probability of the comprehensive scenario occurring can be obtained.

[0056] Optionally, if each sub-scenario is independent, the probability of the comprehensive scenario can be the product of the probabilities of all sub-scenarios.

[0057] As an example, taking the failure of the vehicle's headlights as an example, sub-scenario 1 can be that the vehicle is driving on the highway and enters a tunnel, and the probability of sub-scenario 1 occurring can be P11; sub-scenario 2 can be that there is a vehicle driving within x1 meters behind the vehicle (the vehicle brakes with a deceleration of a1, and the vehicle behind brakes with a deceleration of a2), and the probability of sub-scenario 2 occurring can be P12; sub-scenario 3 can be that the road surface is wet and slippery on a rainy day, and the probability of sub-scenario 3 occurring can be P13. Then the probability of a collision occurring in this comprehensive scenario can be P = P11 * P12 * P13.

[0058] Optionally, if there are dependencies between sub-scenarios (e.g., the braking of the following vehicle depends on the braking of the host vehicle), conditional probability needs to be introduced, and then the probability of the combined scenario occurring can be obtained.

[0059] As an example, taking the unexpected braking of the host vehicle as an example, sub-scenario 1 can be that the vehicle is driving on the highway and enters a tunnel, and the probability of sub-scenario 1 occurring can be P21. Sub-scenario 2 can be that there is a first vehicle driving within x1 meters behind the host vehicle (the host vehicle brakes with a deceleration of a1, and the first vehicle brakes with a deceleration of a2), and the probability of sub-scenario 2 occurring can be P22. Sub-scenario 3 can be that there is a second vehicle driving within x2 meters behind the first vehicle (the second vehicle brakes with a deceleration of a3), and the probability of sub-scenario 3 occurring can be P23. Sub-scenario 4 can be that the road surface is wet and slippery on a rainy day, and the probability of sub-scenario 4 occurring can be P24. Since there is a dependency between sub-scenario 2 and sub-scenario 3, the conditional probability between sub-scenario 2 and sub-scenario 3 can be calculated as P2. Then, the probability of a collision occurring in this combined scenario can be P = P21 * P2 * P24.

[0060] In the embodiment of the present application, after obtaining the probability of the combined scenario occurring, based on the mapping relationship between the probability of the combined scenario occurring and the exposure level, the exposure level of the vehicle under the consideration of external hypothesis conditions can be determined. In the present application, the mapping relationship between the probability of the combined scenario occurring and the exposure level can be defined based on the experience of researchers and can be adjusted based on the results of multiple experiments. As an example, the mapping relationship between the probability of the combined scenario occurring and the exposure level can be defined as follows: when P ≤ b1, the exposure level is E1; when b1 < P ≤ b2, the exposure level is E2; when b3 < P ≤ b4, the exposure level is E3; when b4 < P ≤ b5, the exposure level is E4, where b1 is much smaller than b2, b2 is much smaller than b3, b3 is much smaller than b4, b4 is much smaller than b5; and b1 > 0, b5 ≤ 1.

[0061] As another way, in the embodiment of the present application, the duration of the combined scenario can also be obtained, and based on the mapping relationship between the duration of the combined scenario and the exposure level, the exposure level of the vehicle under the consideration of external hypothesis conditions can be determined. Among them, the duration of the combined scenario can be the time length during which the vehicle continuously stays in this situation in the combined scenario. In the present application, the mapping relationship between the duration of the combined scenario and the exposure level can be defined based on the experience of researchers and can be adjusted based on the results of multiple experiments.

[0062] S133: Estimate the probability and degree of injury of the driver and the external traffic participants in the combined scenario to obtain the injury level of the vehicle under the consideration of the external hypothesis conditions.

[0063] As a way, the probabilities and degrees of injury of the driver and external traffic participants in a comprehensive scenario can be calculated by establishing a collision injury model (simulating typical collision scenarios through simulation tools and quantifying the degree of injury in combination with biomechanical injury criteria).

[0064] In an embodiment of the present application, after obtaining the probabilities and degrees of injury of the driver and external traffic participants in a comprehensive scenario, based on the mapping relationship between the injury probability and the injury degree - injury level, the injury level of the vehicle under consideration of external hypothetical conditions can be determined. Among them, the injury level can include four levels, namely S0 (no injury), S1 (mild and / or moderate injury), S2 (severe injury), and S3 (life-threatening injury and / or fatal injury). In the present application, the mapping relationship between the injury probability, the degree of injury, and the injury level can be defined based on the experience of researchers and can be adjusted based on the results of multiple experiments.

[0065] Exemplarily, if the comprehensive scenario is that the driving speed of the vehicle is 60 km / h, a side collision braking distance of 5 m, and a collision angle of 90° collides with a pedestrian, and based on the collision injury model, the fatal injury probability of the pedestrian is calculated to be 32%, and the degree of injury is evaluated as the head HIC value = 856 (>1000 is fatal), and the chest compression amount = 32 mm (critical value), so that the injury level in this comprehensive scenario can be determined to be level S3.

[0066] S134: Estimate the probabilities of the driver and the external traffic participants avoiding injury in a comprehensive scenario to obtain the controllability level of the vehicle under consideration of the external hypothetical conditions.

[0067] As a way, the probabilities of the driver and external traffic participants avoiding injury in a comprehensive scenario can be calculated by an evaluation model (through driver reaction time testing, vehicle active safety system response efficacy evaluation, and external participant avoidance space calculation).

[0068] In an embodiment of the present application, after obtaining the probabilities of the driver and external traffic participants avoiding injury in a comprehensive scenario, based on the mapping relationship between the probability of avoiding injury and the controllability level, the controllability level of the vehicle under consideration of external hypothetical conditions can be determined. Among them, the controllability level can include four levels, namely C0 (fully controllable), C1 (basically controllable), C2 (partially controllable), and C3 (almost uncontrollable). In the present application, the mapping relationship between the probability of avoiding injury and the controllability level can be defined based on the experience of researchers and can be adjusted based on the results of multiple experiments.

[0069] S135: Determine the updated safety level of the vehicle based on the exposure level, the controllability level, and the injury level.

[0070] In an embodiment of the present application, based on the original risk scenario and external assumptions, a superimposed comprehensive scenario can be obtained, so that the exposure analysis, controllability analysis, and harm analysis can be sequentially performed on the comprehensive scenario to obtain the corresponding exposure level, controllability level, and harm level. Then, based on the exposure level, controllability level, and harm level, the updated safety level of the vehicle can be determined. As an example, as shown in Table 1, the updated safety level of the vehicle can be determined by looking up a table.

[0071] Table 1:

[0072] S140: Determine the target safety level of the vehicle based on the original safety level and the updated safety level.

[0073] Among them, the target safety level can be the safety level finally determined for the vehicle when a preset function fails.

[0074] As a way, when the original safety level is higher than the updated safety level, determine the target safety level of the vehicle as the original safety level; when the updated safety level is higher than the original safety level, determine the target safety level of the vehicle as the updated safety level.

[0075] In an embodiment of the present application, if the original safety level is higher than the updated safety level, this means that after introducing external assumptions, the resulting safety risk is still lower than the safety risk of the original risk scenario. Therefore, the target safety level of the vehicle can be determined as the original safety level. On the contrary, if the updated safety level is higher than the original safety level, this means that after introducing external assumptions, the resulting safety risk is higher than the safety risk of the original risk scenario. Therefore, the target safety level of the vehicle can be determined as the updated safety level.

[0076] As a way, when the updated safety level is higher than the original safety level, it can be determined whether to adopt the updated safety level as the target safety level based on preset requirements; when it is determined to adopt the updated safety level based on preset requirements, determine the target safety level of the vehicle as the updated safety level; when it is determined not to adopt the updated safety level based on preset requirements, adjust the external assumptions and re-determine the target safety level of the vehicle.

[0077] Among them, the preset requirements can be the requirements that R & D personnel set in advance for the safety level based on R & D requirements.

[0078] In an embodiment of the present application, if the updated safety level is higher than the original safety level, it is possible to determine whether the updated safety level meets the requirements of a preset safety level to determine whether to adopt the updated safety level as the target safety level. Thus, when the updated safety level meets the requirements of the preset safety level, the target safety level of the vehicle can be determined as the updated safety level.

[0079] Optionally, if the updated safety level does not meet the requirements of the preset safety level, the external assumptions in step S120 can be adjusted to re-determine the target safety level of the vehicle.

[0080] In an embodiment of the present application, by comparing the original safety level with the updated safety level and selecting the one with the higher safety level as the finally adopted level (i.e., the target safety level), it is possible to ensure that the vehicle system always meets the strictest safety requirements. This decision-making logic not only ensures the sufficiency of the safety design but also avoids underestimation of the safety level during the analysis process. Furthermore, it can ensure that after considering the external assumptions, the target safety level of the vehicle can reflect more strict safety requirements, effectively cope with potential risks, and guarantee the safety of the vehicle and traffic participants.

[0081] A functional safety assessment method provided in this embodiment, after obtaining the original risk scenario of the vehicle, conducts a hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle. When the driving scenario in the original risk scenario includes external traffic participants, external assumptions are obtained based on the external traffic participants, and the external assumptions include the response behaviors expected to be taken by the external traffic participants in the original risk scenario. When the external assumptions are related to vehicle safety, a hazard analysis and risk assessment are conducted based on the external assumptions and the original risk scenario to obtain the updated safety level of the vehicle. Based on the original safety level and the updated safety level, the target safety level of the vehicle is determined. By the above method, since the external assumptions are the response behaviors expected to be taken by traffic participants in the original risk scenario, and the updated safety level is obtained based on the external assumptions and the original risk scenario, it is possible to evaluate secondary hazards ignored in related methods, ensure that the target safety level covers multi-level chain hazard risk scenarios, and thus avoid greater risks.

[0082] A functional safety assessment method provided in this embodiment Please refer to Figure 3 , a functional safety assessment method provided in an embodiment of the present application, the method includes: S210: Obtain the original risk scenario of the vehicle, and conduct a hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle.

[0083] S220: When the driving scenario in the original risk scenario includes external traffic participants, an external hypothesis is obtained based on the external traffic participants.

[0084] S230: When the external hypothesis has nothing to do with the safety of the vehicle, determine that the safety level of the vehicle is the original safety level.

[0085] As a way, it can be judged whether the obtained external hypothesis is related to vehicle safety, so that when the external hypothesis has nothing to do with vehicle safety, the safety level of the vehicle can be directly determined as the original safety level. In the embodiments of the present application, it can be judged whether the external hypothesis is related to vehicle safety based on the hazard identification analysis in HARA analysis.

[0086] In the embodiments of the present application, by introducing an external hypothesis, and only when the external hypothesis is related to vehicle safety, the original safety level is re-evaluated and updated, and when the external hypothesis has nothing to do with vehicle safety, the safety level of the vehicle is directly determined as the original safety level, thus avoiding unnecessary safety level adjustments and improving the efficiency and accuracy of safety assessment.

[0087] A functional safety assessment method provided in this embodiment, through the above method, makes it so that since the external hypothesis is the response behavior expected by traffic participants in the original risk scenario, and an updated safety level is obtained based on the external hypothesis and the original risk scenario, secondary hazards ignored in related methods can be evaluated, ensuring that the target safety level covers multi-level chain hazard risk scenarios, and thus avoiding greater risks. And, in the embodiments of the present application, only when the external hypothesis is related to vehicle safety, the original safety level is re-evaluated and updated, and when the external hypothesis has nothing to do with vehicle safety, the safety level of the vehicle is directly determined as the original safety level, thus avoiding unnecessary safety level adjustments and improving the efficiency and accuracy of safety assessment.

[0088] Please refer to Figure 4 , a functional safety assessment method provided in the embodiments of the present application, is applied to a vehicle, and the method includes: S310: Obtain the original risk scenario of the vehicle, and perform hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle.

[0089] Among them, the original risk scenario may include the state of the vehicle under preset functional abnormalities, the behavior of the vehicle under preset functional abnormalities, the driver's operations, the driving scenario, and the driving environment when the driver is driving the vehicle.

[0090] As a way, when a driver is driving a vehicle, the state of the vehicle under a preset functional abnormality, the behavior of the vehicle under a preset functional abnormality, the driver's operations, the driving scenario, and the driving environment can be collected based on the data collection devices on the vehicle to obtain an original risk scenario. Then, the original risk scenario can be analyzed by HARA to obtain an original safety level. In the embodiments of the present application, the data collection devices may include, but are not limited to, in-vehicle cameras, in-vehicle radars, wheel speed sensors, acceleration sensors, angular velocity sensors, etc.

[0091] S320: When the driving scenario in the original risk scenario includes external traffic participants, an external hypothesis is obtained based on the external traffic participants.

[0092] Among them, the external traffic participants may include, but are not limited to, large vehicles, small vehicles, pedestrians, cyclists, and other traffic participating objects. The external hypothesis may include the response behaviors expected to be taken by the external traffic participants in the original risk scenario.

[0093] As a way, when a driver is driving a vehicle, it can be determined whether the original risk scenario includes external traffic participants based on the sensor system on the vehicle. Thus, when the driving scenario in the original risk scenario includes external traffic participants, the type, state, location, and response behaviors of the external traffic participants can be obtained to obtain an external hypothesis.

[0094] Optionally, when the original risk scenario does not include external traffic participants, the safety level of the vehicle can be directly determined as the original safety level.

[0095] In the embodiments of the present application, after obtaining the original risk scenario, it is determined whether the original risk scenario includes external traffic participants. If there are external traffic participants, the external traffic participants can be analyzed based on a preset behavior library to further analyze whether there will be a hazard of cascading risks. If there are no external traffic participants, the safety level can be directly determined as the original safety level. Only when the original risk scenario involves external traffic participants, an external hypothesis analysis is performed, avoiding redundant evaluation of irrelevant scenarios, improving the analysis efficiency, and reducing redundant calculations.

[0096] S330: When the external hypothesis is related to vehicle safety, a hazard analysis and risk assessment are performed based on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle.

[0097] As a way, before obtaining the updated safety level, it is possible to first determine whether the obtained external hypothesis is related to vehicle safety. Thus, in the case where the external hypothesis is related to vehicle safety, hazard analysis and risk assessment can be performed on the external hypothesis and the original risk scenario to obtain the updated safety level of the vehicle. In the embodiments of the present application, it is possible to determine whether the external hypothesis is related to vehicle safety based on the hazard identification analysis in the HARA analysis.

[0098] Optionally, in the case where the external hypothesis is not related to vehicle safety, the safety level of the vehicle can be directly determined as the original safety level.

[0099] S341: In the case where the original safety level is higher than the updated safety level, determine the target safety level of the vehicle as the original safety level.

[0100] S342: In the case where the updated safety level is higher than the original safety level, determine the target safety level of the vehicle as the updated safety level.

[0101] As a way, in the case where the updated safety level is higher than the original safety level, it is possible to determine whether to adopt the updated safety level as the target safety level based on a preset requirement; in the case where it is determined to adopt the updated safety level based on the preset requirement, determine the target safety level of the vehicle as the updated safety level; in the case where it is determined not to adopt the updated safety level based on the preset requirement, adjust the external hypothesis and re-determine the target safety level of the vehicle.

[0102] Among them, the preset requirement can be the minimum requirement that the driver sets for the safety level based on their own needs.

[0103] In the embodiments of the present application, if the updated safety level is higher than the original safety level, then it is possible to determine whether the updated safety level meets the minimum requirement of the safety level, so as to determine whether to adopt the updated safety level as the target safety level.

[0104] Optionally, if the updated safety level does not meet the minimum requirement of the safety level, the external hypothesis in step S320 can be adjusted to re-determine the target safety level of the vehicle.

[0105] In the embodiment of the present application, by comparing the original safety level with the updated safety level and selecting the one with the higher safety level as the finally adopted level (i.e., the target safety level), it can be ensured that the safety level of the vehicle always meets the safety requirements of the driver. The driver can set a minimum standard for the safety level according to their own driving habits, acceptance of risks, and requirements of a specific driving environment. By comparing the original safety level and the updated safety level, the vehicle system can automatically determine whether the safety level needs to be adjusted, so as to provide a safety guarantee that better suits the driver's needs. If the updated safety level fails to meet the minimum requirements set by the driver, the system will re-evaluate by adjusting the external assumptions to ensure that the finally determined target safety level can provide sufficient safety guarantee for the driver and make the driver feel more at ease during driving.

[0106] A functional safety assessment method provided in this embodiment enables, through the above method, that since the external assumption is the response behavior expected by traffic participants in the original risk scenario, and the updated safety level is obtained based on the external assumption and the original risk scenario, it is possible to evaluate secondary hazards ignored in related methods, ensure that the target safety level covers multi-level chain hazard risk scenarios, and thus avoid greater risks. Also, in the embodiment of the present application, the driver can set a minimum standard for the safety level according to their own driving habits, acceptance of risks, and requirements of a specific driving environment. By comparing the original safety level and the updated safety level, the vehicle system can automatically determine whether the safety level needs to be adjusted, so as to provide a safety guarantee that better suits the driver's needs. If the updated safety level fails to meet the minimum requirements set by the driver, the system will re-evaluate by adjusting the external assumptions to ensure that the finally determined target safety level can provide sufficient safety guarantee for the driver and make the driver feel more at ease during driving.

[0107] To better understand the solutions of all embodiments of the present application, the basic business process of the functional safety assessment method of the present application will be introduced below.

[0108] Please refer to Figure 5 , the original risk scenario can be obtained based on step S1, and a HARA analysis is performed on the original risk scenario to obtain the original safety level. Then, it is determined based on step S2 whether the original risk scenario includes external traffic participants. If the original risk scenario does not include external traffic participants, the target safety level can be determined as the original safety level based on step S11; if the original risk scenario includes external traffic participants, the external assumption can be determined based on the external traffic participants, and then it is determined based on step S3 whether the external assumption is related to vehicle safety. If the external assumption is not related to vehicle safety, the target safety level can be determined as the original safety level based on step S11.

[0109] If the external assumption is related to vehicle safety, a comprehensive scenario can be obtained based on the external assumption and the original risk scenario in step S4, so that exposure analysis, controllability analysis, and harmfulness analysis can be performed on the comprehensive scenario respectively in step S5 to obtain the corresponding exposure level, controllability level, and harmfulness level. Then, based on the exposure level, controllability level, and harmfulness level in step S6, an updated safety level can be obtained, and it can be determined in step S7 whether the updated safety level is higher than the original safety level. If the updated safety level is lower than the original safety level, the target safety level can be determined as the original safety level based on step S11; if the updated safety level is higher than the original safety level, it can be determined in step S8 whether to adopt the updated safety level. If the updated safety level is adopted, the target safety level can be determined as the updated safety level based on step S9; if the updated safety level is not adopted, the external assumption determined based on the external traffic participants after step S2 can be adjusted until the target safety level is determined.

[0110] Please refer to Figure 6 , a functional safety assessment method device 600 provided by the present application, the device 600 includes: An external assumption determination unit 610, configured to obtain the original risk scenario of the vehicle, perform hazard analysis and risk assessment on the original risk scenario to obtain the original safety level of the vehicle, where the original risk scenario includes the state of the vehicle under a preset functional abnormality, the behavior of the vehicle under a preset functional abnormality, the driving scenario, and the driving environment; when the driving scenario in the original risk scenario includes an external traffic participant, an external assumption is obtained based on the external traffic participant, and the external assumption is the response behavior that the external traffic participant is expected to take in the original risk scenario.

[0111] A safety level determination unit 620, configured to perform hazard analysis and risk assessment based on the external assumption and the original risk scenario to obtain the updated safety level of the vehicle when the external assumption is related to vehicle safety; determine the target safety level of the vehicle based on the original safety level and the updated safety level.

[0112] As a way, the external assumption determination unit 620 is specifically configured to determine the state, position, and response behavior of the external traffic participant from a preset behavior library based on the external traffic participant; obtain the external assumption based on the external traffic participant, the corresponding state of the external traffic participant, the position of the external traffic participant, and the response behavior of the external traffic participant.

[0113] As a way, the safety level determination unit 620 is specifically configured to obtain a comprehensive scenario based on the external assumption and the original risk scenario; obtain the probability of occurrence of the comprehensive scenario based on the probabilities of occurrence of multiple sub-scenarios in the comprehensive scenario, so as to obtain the exposure level of the vehicle under the condition of considering the external assumption, where the sub-scenario is the state of the vehicle under a preset functional abnormality or the behavior of the vehicle under a preset functional abnormality or the driver's operation or the state of the external traffic participants or the response behavior of the external traffic participants or the driving environment; estimate the probabilities of the driver and the external traffic participants being injured and the degree of injury in the comprehensive scenario, so as to obtain the injury level of the vehicle under the condition of considering the external assumption; estimate the probability of the driver and the external traffic participants avoiding injury in the comprehensive scenario, so as to obtain the controllability level of the vehicle under the condition of considering the external assumption; and determine the updated safety level of the vehicle based on the exposure level, the controllability level, and the injury level.

[0114] As a way, the safety level determination unit 620 is specifically configured to determine that the target safety level of the vehicle is the original safety level when the original safety level is higher than the updated safety level; and determine that the target safety level of the vehicle is the updated safety level when the updated safety level is higher than the original safety level.

[0115] Optionally, the safety level determination unit 620 is specifically configured to determine whether to adopt the updated safety level as the target safety level based on a preset requirement when the updated safety level is higher than the original safety level; determine that the target safety level of the vehicle is the updated safety level when it is determined based on the preset requirement to adopt the updated safety level; and adjust the external assumption and re-determine the target safety level of the vehicle when it is determined based on the preset requirement not to adopt the updated safety level.

[0116] As a way, the safety level determination unit 620 is specifically configured to determine that the safety level of the vehicle is the original safety level when the original risk scenario does not include external traffic participants.

[0117] As a way, the safety level determination unit 620 is specifically configured to determine that the safety level of the vehicle is the original safety level when the external assumption has nothing to do with the safety of the vehicle.

[0118] Next, a vehicle provided by the present application will be described in conjunction with Figure 7 a vehicle provided by the present application.

[0119] Please refer to Figure 7, based on the above functional safety assessment method and device, another vehicle 100 capable of executing the foregoing functional safety assessment method is further provided in an embodiment of the present application. The vehicle 100 includes a processor 102, a memory 104, a communication module 106, and a data acquisition device 108. Among them, a program that can execute the content in the foregoing embodiment is stored in the memory 104, and the processor 102 can execute the program stored in the memory 104.

[0120] Among them, the processor 102 may include one or more processing cores. The processor 102 uses various interfaces and lines to connect various parts within the entire vehicle 100, and executes various functions of the vehicle 100 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 104, and by calling data stored in the memory 104. Optionally, the processor 102 may be implemented in at least one hardware form of a network processor (Neural network Processing Unit, NPU), a digital signal processing (Digital Signal Processing, DSP), a field programmable gate array (Field-Programmable GateArray, FPGA), or a programmable logic array (Programmable Logic Array, PLA). The processor 102 may integrate one or a combination of several of a central processing unit (Central Processing Unit, CPU), a graphics processing unit (Graphics Processing Unit, GPU), a network processor (Neural network Processing Unit, NPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the displayed content; the NPU is responsible for processing multimedia data such as videos and images; the modem is responsible for processing wireless communications. It can be understood that the above modem may not be integrated into the processor 102 and may be implemented separately through a communication chip.

[0121] The memory 104 may include a Random Access Memory (RAM), and may also include a Read-Only Memory and a Double Data Rate (DDR) synchronous dynamic random access memory. The memory 104 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 104 may include a program storage area and a data storage area. Among them, the program storage area can store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the following various method embodiments, etc. The data storage area can also store data created during the use of the vehicle 100 (such as a phone book, audio and video data, chat record data), etc.

[0122] The communication module 106 can be used to implement information interaction between the vehicle 100 and other devices. For example, it can transmit device control instructions, manipulation request instructions, and status information acquisition instructions, etc. When the other device is specifically different devices, the corresponding communication module 106 may be different.

[0123] The data acquisition device 108 may include an in-vehicle camera, an in-vehicle radar, a wheel speed sensor, an acceleration sensor, an angular velocity sensor, etc.

[0124] A computer-readable storage medium provided by an embodiment of this application. Program code is stored in the computer-readable storage medium, and the program code can be called by a processor to execute the method described in the above method embodiments.

[0125] The computer-readable storage medium can be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read-Only Memory), an EPROM, a hard disk, or a ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium has a storage space for program code for executing any method step in the above method. These program codes can be read out from or written into one or more computer program products. The program code can be compressed in an appropriate form, for example.

[0126] Embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate means for implementing the functions specified in one or more flows and / or one or more blocks in the flow. Figure 1 one or more flows and / or Figure 1 blocks.

[0127] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in one or more flows and / or one or more blocks in the flow. Figure 1 one or more flows and / or Figure 1 blocks.

[0128] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one or more flows and / or one or more blocks in the flow. Figure 1 one or more flows and / or Figure 1 blocks.

[0129] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.

[0130] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising the said element.

[0131] The above has introduced in detail a functional safety assessment method, device and vehicle provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A functional safety assessment method, characterized in that: The method comprises: Obtaining an original risk scenario of the vehicle, and performing hazard analysis and risk assessment on the original risk scenario to obtain an original safety level of the vehicle, wherein the original risk scenario includes a state of the vehicle under a preset functional abnormality, a behavior of the vehicle under a preset functional abnormality, driver operation, driving scenario, and driving environment; In the case where the driving scenario in the original risk scenario includes an external traffic participant, an external hypothesis is obtained based on the external traffic participant, wherein the external hypothesis includes a response behavior that the external traffic participant is expected to take in the original risk scenario; In the case where the external assumption is related to vehicle safety, performing hazard analysis and risk assessment based on the external assumption and the original risk scenario to obtain an updated safety level of the vehicle; A target safety level of the vehicle is determined based on the original safety level and the updated safety level.

2. The method according to claim 1, characterized in that The obtaining of external assumptions based on the external traffic participants includes: Based on the external traffic participant, determining the state of the external traffic participant, the position of the external traffic participant, and the response behavior of the external traffic participant from a preset behavior library; The external hypothesis is obtained based on the external traffic participant, the state corresponding to the external traffic participant, the position of the external traffic participant, and the response behavior of the external traffic participant.

3. The method according to claim 1, characterized in that The performing hazard analysis and risk assessment based on the external assumption and the original risk scenario to obtain an updated safety level of the vehicle includes: Based on the external assumptions and the original risk scenario, a comprehensive scenario is obtained; Based on the probability of occurrence of multiple sub-scenarios in the comprehensive scenario, the probability of occurrence of the comprehensive scenario is obtained to obtain the exposure level of the vehicle under the external assumption conditions, wherein the sub-scenario is the state of the vehicle under a preset functional abnormality or the behavior of the vehicle under a preset functional abnormality or the driver's operation or the state of the external traffic participant or the response behavior or driving environment of the external traffic participant; estimating the probability and degree of injury to the driver and the external traffic participants in a comprehensive scenario, so as to obtain the injury level of the vehicle under the external assumptions; estimating the probability of avoiding injury to the driver and the external traffic participants in a comprehensive scenario to obtain a controllability level of the vehicle under the external assumptions; An updated safety level of the vehicle is determined based on the exposure level, the controllability level, and the damage level.

4. The method according to claim 1, characterized in that: The step of determining a target safety level of the vehicle based on the original safety level and the updated safety level includes: In a case where the original safety level is higher than the updated safety level, determining the target safety level of the vehicle to be the original safety level; In a case where the updated safety level is higher than the original safety level, the target safety level of the vehicle is determined to be the updated safety level.

5. The method according to claim 4, characterized in that When the updated safety level is higher than the original safety level, determining the target safety level of the vehicle as the updated safety level further includes: In the case where the updated security level is higher than the original security level, determining whether to adopt the updated security level as the target security level based on preset requirements; In the case where it is determined to adopt the updated safety level based on the preset requirements, determining the target safety level of the vehicle to be the updated safety level; In the case where it is determined not to adopt the updated safety level based on the preset requirements, the external assumption is adjusted to redefine the target safety level of the vehicle.

6. The method according to claim 1, characterized in that The method further comprises: When the original risk scenario does not include external traffic participants, the safety level of the vehicle is determined to be the original safety level.

7. The method according to claim 1, characterized in that The method further comprises: In a case where the external assumption is irrelevant to the safety of the vehicle, the safety level of the vehicle is determined to be an original safety level.

8. A functional safety assessment method and device, characterized in that: The device comprises: an external hypothesis determination unit, configured to obtain an original risk scenario of the vehicle, and to perform hazard analysis and risk assessment on the original risk scenario to obtain an original safety level of the vehicle, wherein the original risk scenario includes a state of the vehicle under a preset functional abnormality, a behavior of the vehicle under a preset functional abnormality, a driving scenario, and a driving environment; in a case where the driving scenario in the original risk scenario includes an external traffic participant, an external hypothesis is obtained based on the external traffic participant, and the external hypothesis is a response behavior that the external traffic participant is expected to take under the original risk scenario; A safety level determination unit is used to perform hazard analysis and risk assessment based on the external assumptions and the original risk scenario to obtain an updated safety level of the vehicle when the external assumptions are related to vehicle safety; and to determine a target safety level of the vehicle based on the original safety level and the updated safety level.

9. A vehicle, characterized in that: including one or more processors and memory; One or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to execute the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, wherein when the program code is run, the method according to any one of claims 1 to 7 is executed.