Autonomous ship operation state evaluation method considering multi-state component degradation

Through the system theoretical process analysis method, the functional control structure and multi-state safety function of the autonomous ship are established, which solves the risk problem of the autonomous ship system deviating from the design operation range, realizes more accurate risk assessment and preventive measures, and improves the safety and reliability of operations.

CN120143884AActive Publication Date: 2025-06-13DALIAN MARITIME UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510291736.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-13
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

In autonomous ship systems, the lack of effective monitoring and evaluation mechanisms leads to the system or function deviating from the design operation range and increasing the risk of accidents.

Method used

System theoretical process analysis method is used to establish the functional control structure of autonomous ships, and a multi-state safety function and system risk function are constructed to evaluate the safety and risk level of autonomous ships under different operating states.

Benefits of technology

Through the multi-state evaluation method, the risk control process of autonomous ships can be captured more accurately, the time for guaranteed response and backup response can be predicted, the autonomous ships can be prevented from deviating from operating boundaries, and the safety and reliability of operations can be improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120143884A_ABST
    Figure CN120143884A_ABST
Patent Text Reader

Abstract

The invention discloses an autonomous ship operation state evaluation method considering multi-state component degradation, and the method comprises the steps: building a function control structure of an autonomous ship in a remote control mode, and determining a multi-state safety function and a system risk function of an autonomous ship subsystem; therefore, the time of the prediction guarantee response, the time of the backup response and the critical moment when the system risk exceeds the set system risk level in the critical state are obtained, and the operation state of the autonomous ship in the remote control mode is evaluated. Through an interaction mechanism between a function control structure and a multi-component subsystem of the system in multiple operation states, a unique risk control process of the autonomous ship can be more accurately captured, and a basic support is provided for a scientific risk management strategy and a decision process in autonomous ship operation; theoretical support is provided for preventing the autonomous ship from deviating from the operation boundary.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multi-state degradation systems, and particularly to an autonomous ship operation state evaluation method considering the degradation of multi-state components. Background Art

[0002] In the new pattern of the development of the shipping industry based on digitization and aiming at autonomy, autonomous shipping has become one of the most prominent trends in the current shipping industry. Among them, whether it is remote control or full autonomy, autonomous ships are crucial elements and carriers. Enhanced automation does not mean that a ship is an autonomous ship. The main difference between an autonomous ship and a traditional ship is the introduction of autonomous or remote operation technologies to enhance or replace the functions performed by seafarers on board when executing or controlling these ship functions. Compared with the latter, the dynamic changes in the operation mode have significantly enhanced the interaction complexity, decomposition complexity, and non-linear complexity of the operation of the autonomous ship system. The transformation of control and operation modes has given rise to new safety requirements, and strict supervision is required to ensure the safety of human life at sea, the cargo on board, and the ship itself. However, in the process of the intelligent transformation and autonomous development of the ship system, the risk prevention and control shows a trend from fragmentation to integration, and the information interaction changes from a single system to a pan-systematic one, further requiring the risk prevention and control strategy of ship operation to shift from a saturated whole-process leak stoppage to a pre-control systematic prevention and control.

[0003] At present, the International Maritime Organization (IMO) is formulating the International Code of Safety for Ships Operating in the Autonomous Mode (MASS Code) to provide an international regulatory framework and solutions for addressing the key functions of remote control and autonomous operation. The design and operation of autonomous ships require additional guidance to ensure that their safety level is comparable to the expected level of conventional ships, ultimately ensuring the safe, reliable, and environmentally friendly operation of autonomous ships. From the perspective of the operation of autonomous ships, the MASS Code identifies and emphasizes some new operating states and state transition paths. Compared with traditional ships, there is an Operational Design Domain (ODD) within the acceptable risk condition (ARC), which provides the conditions, relevant control modes, and operating modes for autonomous ships under remote control and autonomous operation. The operating boundaries of autonomous ships consist of the Operational Design Domain and the acceptable risk condition, providing the operating capabilities and limitations of the ship as well as the ship-specific capabilities and limitations. Once the system or function deviates from its Operational Design Domain, but the ship as an integrated system can continue to operate within its operating boundaries, the deviation from its Operational Design Domain should be regarded as a degraded state. The ship can operate normally in the degraded state, which is usually caused by the degradation of a single autonomous or remote operating system. Once the ship deviates from its operating boundaries, the ship should take a Fallback Response to further avoid the possibility of deviating from normal operation. As long as the ship cannot stay within the operating conditions, a minimal risk manoeuvre (MRM) should be executed to maintain the minimal risk condition (MRC) to maintain the lowest level of safety. If the degradation of the system and components is not well monitored and the change in the operating state is detected, the state transition of autonomous ships is easily overlooked and even leads to accidents. Summary of the Invention

[0004] The present invention discloses a method for evaluating the operating state of an autonomous ship considering the degradation of multi-state components to overcome the above technical problems.

[0005] To achieve the above object, the technical solution of the present invention is as follows:

[0006] A method for evaluating the operating state of an autonomous ship considering the degradation of multi-state components, comprising the following steps:

[0007] S1: Based on the system-theoretic process analysis method, establish the functional control structure of an autonomous ship in the remote control mode;

[0008] S2: Establish a multi-state safety function for the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain the safety function of the autonomous ship subsystem in the \(u\)-th operating state, where \(u\) represents the operating state and \(u\geq1\).

[0009] S3: According to the safety function of the autonomous ship subsystem in the \(u\)-th operating state, obtain the average life of the autonomous ship subsystem within the safety state subset to obtain the time of the predicted safeguard response and the time of the backup response.

[0010] S4: Establish a system risk function for the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain the critical moment when the system risk exceeds the set system risk level in the critical state.

[0011] S5: Evaluate the operating state of the remotely controlled autonomous ship according to the critical moment when the system risk exceeds the set system risk level in the critical state, the predicted safeguard response time, and the backup response time.

[0012] Further, in S2, the multi-state safety function is expressed by the following formula:

[0013] s (i) (t)=[1,s (i) (t,1),s (i) (t,2),s (i) (t,3),s (i) (t,4)],t∈[0,∞)

[0014]

[0015] In the formula: s (i) (t) represents the five-state safety function of the \(i\)-th autonomous ship subsystem; s (i) (t,u) represents the safety function of the \(i\)-th autonomous ship subsystem in the \(u\)-th operating state; t represents the moment; represents the safety function of the \(b\)-th secondary component under the \(a\)-th primary component in the \(i\)-th autonomous ship subsystem in the \(u\)-th operating state; A i represents the total number of primary components in the \(i\)-th autonomous ship subsystem; represents the total number of secondary components included in the \(a\)-th primary component in the \(i\)-th autonomous ship subsystem; u represents the operating state;

[0016] Among them,

[0017]

[0018] In the formula, Denotes the b-th secondary component under the a-th primary component in the 1st autonomous ship subsystem The safety function in the u-th operating state, i.e., the navigation subsystem S 1 The b-th secondary component under the a-th primary component in The safety function in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 1st autonomous ship subsystem The transition intensity in the u-th operating state; The b-th secondary component under the a-th primary component in the 2nd autonomous ship subsystem The safety function in the u-th operating state, i.e., the autonomous engine monitoring and control subsystem S 2 The b-th secondary component under the a-th primary component in The safety function in the u-th operating state; The b-th secondary component under the a-th primary component in the 3rd autonomous ship subsystem The safety function in the u-th operating state, i.e., the environmental sensor subsystem S 3 The b-th secondary component under the a-th primary component in The safety function in the u-th operating state; The b-th secondary component under the a-th primary component in the 4th autonomous ship subsystem The safety function in the u-th operating state, i.e., the communication subsystem S 4 The b-th secondary component under the a-th primary component in The safety function in the u-th operating state; The b-th secondary component under the a-th primary component in the 5th autonomous ship subsystem The safety function in the u-th operating state, i.e., the remote operation center subsystem S 5 The b-th secondary component under the a-th primary component in The safety function in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 2nd autonomous ship subsystem The transition intensity in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 3rd autonomous ship subsystem The transition intensity in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 4th autonomous ship subsystem The transition intensity in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 5th autonomous ship subsystem The transition intensity in the u-th operating state; exp[·] represents the exponential distribution.

[0019] Furthermore, in S3, the average lifetime of the autonomous ship subsystem within the safe state subset is obtained as follows:

[0020]

[0021] In the formula: Denotes the average lifetime of the autonomous ship subsystem within the safe state subset; s (i) (t, u) represents the safety function of the i-th autonomous ship subsystem in the u-th operating state; t represents the time; u represents the operating state;

[0022]

[0023] In the formula: t 后备 Denotes the backup response time; t 预测 Denotes the time for predicting the safeguard response.

[0024] Furthermore, in S4, the system risk function of the autonomous ship subsystem is established as follows:

[0025] R(t) = 1 - s(t, r)

[0026] In the formula: R(t) represents the system risk function; s(t, r) represents the safety function of the remotely controlled ship in the critical state; r represents the critical state; t represents the time.

[0027] Furthermore, the formula for obtaining the critical time when the system risk in the critical state exceeds the set system risk level is as follows:

[0028] τ = R -1 (t) = R -1 (δ)

[0029] In the formula: τ represents the critical time when the system risk in the critical state r exceeds the set system risk level, R(t) represents the system risk function; R -1 (t) represents the inverse function of the system risk function R(t); δ represents the set system risk level.

[0030] Furthermore, the functional control structure includes multiple autonomous ship subsystems;

[0031] The autonomous ship subsystem includes several primary components connected in series;

[0032] The primary component includes several secondary components connected in parallel.

[0033] Further, the multiple autonomous ship subsystems include a navigation subsystem S connected in series in sequence 1 , an autonomous engine monitoring and control subsystem S 2 , an environmental sensor subsystem S 3 , a communication subsystem S 4 and a remote operation center subsystem S 5 ;

[0034] The first-level components under the navigation subsystem S 1 include an integrated bridge system and an autonomous navigation system;

[0035] The first-level components under the autonomous engine monitoring and control subsystem S 2 include a main engine a steering gear, a generator, and auxiliary engines

[0036] Among them, the second-level components under the steering gear include a first steering gear and a second steering gear

[0037] The second-level components under the generator include a first generator a second generator a third generator a fourth generator

[0038] The first-level components under the environmental sensor subsystem S 3 include a global navigation satellite system a radar an electronic chart a lidar an infrared camera a gyrocompass a log a fathometer a vessel automatic identification system a global maritime distress and safety system

[0039] The first-level components under the communication subsystem S 4 include a communication controller and a very high frequency

[0040] The first-level components under the remote operation center subsystem S 5 include a remote operation center

[0041] Advantageous effects: A method for evaluating the operating state of an autonomous ship considering the degradation of multi-state components of the present invention establishes a functional control structure of an autonomous ship in a remote control mode, determines the multi-state safety function and system risk function of the autonomous ship subsystems, and thereby obtains the time for predicting the safeguard response, the time for the backup response, and the critical moment when the system risk exceeds the set system risk level under critical conditions, so as to evaluate the operating state of the autonomous ship in the remote control mode. Through the functional control structure of the system in multiple operating states and the interaction mechanism between multi-component subsystems, the present invention can more accurately capture the unique risk control process of the autonomous ship, and provide basic support for the scientific risk management strategy and decision-making process in the operation of the autonomous ship, and provide theoretical support for preventing the autonomous ship from deviating from the operating boundary. Description of the Drawings

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0043] Figure 1 It is a flowchart of the method for evaluating the operating state of an autonomous ship considering the degradation of multi-state components of the present invention;

[0044] Figure 2 It is the functional control structure of an autonomous ship (with crew on board) in the remote control mode in the embodiment of the present invention;

[0045] Figure 3 It is the series-parallel structure of components in the subsystem of a remote control ship (with crew on board) in the embodiment of the present invention;

[0046] Figure 4 It is a schematic diagram of the change in the safety state of the system and components in the embodiment of the present invention;

[0047] Figure 5 It is the navigation subsystem S in the embodiment of the present invention 1 Safety function diagram;

[0048] Figure 6 It is the autonomous engine monitoring and control subsystem S in the embodiment of the present invention 2 Safety function diagram;

[0049] Figure 7 It is the environmental sensor subsystem S in the embodiment of the present invention 3 Safety function diagram;

[0050] Figure 8The communication subsystem S in the embodiment of the present invention 4 Safety function diagram;

[0051] Figure 9 The remote operation center subsystem S in the embodiment of the present invention 5 Safety function diagram;

[0052] Figure 10 The risk function diagram of the autonomous ship system in the embodiment of the present invention. Specific implementation manners

[0053] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0054] This embodiment introduces an evaluation method for the operating state of an autonomous ship considering the degradation of multi-state components, as Figure 1 shown, including the following steps:

[0055] S1: Based on the system theory process analysis method, establish the functional control structure of the autonomous ship in the remote control mode;

[0056] Preferably, the functional control structure includes multiple autonomous ship subsystems; the multiple autonomous ship subsystems are connected in series;

[0057] The autonomous ship subsystem includes several first-level components connected in series;

[0058] The first-level component includes several second-level components connected in parallel;

[0059] Preferably, the multiple autonomous ship subsystems include: navigation subsystem S 1 , autonomous engine monitoring and control subsystem S 2 , environmental sensor subsystem S 3 , communication subsystem S 4 and remote operation center subsystem S 5 ;

[0060] The first-level components under the navigation subsystem S 1 include the integrated bridge system and the autonomous navigation system

[0061] The first-level components under the autonomous engine monitoring and control subsystem S 2 include the main engine Steering gear, generator, auxiliary machinery Among them, the secondary components under the steering gear include the first steering gear and the second steering gear The secondary components under the generator include the first generator The second generator The third generator The fourth generator

[0062] The said environmental sensor subsystem S 3 The primary components under it include the Global Navigation Satellite System Radar Electronic chart Lidar Infrared camera Gyrocompass Log Depth sounder Automatic Identification System (AIS) for ships Global Maritime Distress and Safety System (GMDSS)

[0063] The said communication subsystem S 4 The primary components under it include a communication controller and Very High Frequency (VHF)

[0064] The said remote operation center subsystem S 5 The primary components under it include a remote operation center

[0065] Specifically, in this embodiment, the Systems Theoretic Process Analysis (STPA) method is used to divide an autonomous ship in the remote control mode into a large system composed of multiple autonomous ship subsystems, and determine the operating state of the autonomous ship in a specific scenario. This is a conventional technology for those skilled in the art, and the division process will not be described in detail here. Among them, the autonomous ship in the remote control mode is a conventional technology in the field, and this embodiment only uses it, so it will not be described in detail herein.

[0066] Specifically, the first step of the systems theoretic process analysis method is to define the analysis purpose, including the system boundary and system objectives. In this example, the system boundary is defined as a remotely controlled ship with a small number of crew members operating within the operating boundary, and the analysis objective is to support the smooth introduction of autonomous ships and avoid autonomous ships operating outside their operating boundaries. In this embodiment, the unacceptable losses related to this stage are defined as follows:

[0067] L-1: Loss of confidentiality, integrity, and availability of mission data

[0068] L-2: The remote control center loses the monitoring and / or control of the autonomous ship;

[0069] L-3: The function of operating normally within the operating boundary is lost;

[0070] L-4: Below the safety level expected of a conventional ship;

[0071] L-5: The feasibility of introducing the autonomous ship is lost.

[0072] Among them, L represents unacceptable losses. Among L-1, …, L-5, the severity of the unacceptable losses changes from low to high.

[0073] By defining unacceptable losses, the operating state of the system can be better understood. Therefore, this method can define the safety state of the autonomous ship in a specific scenario. Specifically, in this example, the safety state of the system, subsystem and its components is represented by z′. When the value of z′ is different, the description of the safety state is as follows:

[0074] z′ = 4: The remotely controlled ship operates safely;

[0075] z′ = 3: The remotely controlled ship operates relatively safely, but there is a possibility of causing L-1;

[0076] z′ = 2: The remotely controlled ship operates moderately safely, but there is a possibility of causing L-1 and L-2;

[0077] z′ = 1: The remotely controlled ship operates relatively dangerously, with the possibility of causing L-1, L-2 and L-3;

[0078] z′ = 0: The remotely controlled ship operates dangerously, with the possibility of causing L-1, L-2, L-3, L-4 and L-5.

[0079] Among them, z′ represents the safety status; when z′ = 4, the autonomous ship is in a safe operating state. In this embodiment, u represents the operating state, where u = 1 means that the autonomous ship subsystem and the primary and secondary components under the autonomous ship subsystem operate in the safety status subset {z′ = 1, z′ = 2, z′ = 3, z′ = 4}, u = 2 means that the autonomous ship subsystem and the primary and secondary components under the autonomous ship subsystem operate in the safety status subset {z′ = 2, z′ = 3, z′ = 4}, u = 3 means that the autonomous ship subsystem and the primary and secondary components under the autonomous ship subsystem operate in the safety status subset {z′ = 3, z′ = 4}, u = 4 means that the autonomous ship subsystem and the primary and secondary components under the autonomous ship subsystem operate in the safety status subset {z′ = 4}, and the safety status subset is a set composed of the safety status z′.

[0080] In this embodiment, the system theory process analysis method is introduced. According to the functional requirements of all components in the autonomous ship in the remote control mode, the functional control structure of the system is created, and thus the division of the autonomous ship components is obtained. According to the responsibilities and functional requirements of all components, the autonomous ship in the remote control mode is reorganized and divided into a complex system composed of five autonomous ship subsystems. The functional control structure is as Figure 2 shown. In this structure, the remote control ship and the remote operation center are regarded as a unified system, which is composed of five autonomous ship subsystems, including the navigation subsystem S 1 , the autonomous engine monitoring and control subsystem S 2 , the environmental sensor subsystem S 3 , the communication subsystem S 4 and the remote operation center subsystem S 5 , where S i represents the i-th subsystem in the system, i = 1, 2,..., I is the index number, and I is the total number of subsystems;

[0081] Among them, each autonomous ship subsystem is a subsystem with a series structure composed of multiple components / a subsystem with a parallel structure, or a subsystem with a combined series-parallel structure. The navigation subsystem S 1 is composed of the integrated bridge system and the autonomous navigation system . The autonomous engine monitoring and control subsystem S 2 is composed of the propulsion and steering system, the generator set and other auxiliary mechanisms. Among them, the propulsion and steering system includes 1 main engine and 2 steering gears . The generator set includes 4 generators . Other auxiliary machines are regarded as being composed of 1 overall component . The environmental sensor subsystem S 3By the Global Navigation Satellite System Radar Electronic chart Lidar Infrared camera Gyrocompass Log Depth sounder Automatic Identification System (AIS) for ships Global Maritime Distress and Safety System (GMDSS) Communication subsystem S 4 Consists of a communication controller and VHF Remote operation center subsystem S 5 Consists only of the overall component remote operation center constitutes.

[0082] Among them, the five autonomous ship subsystems in this embodiment are connected in series to form a five-state system. It means that there are a first-level components in the i-th subsystem, where there are b second-level components in parallel under the a-th first-level component, where a = 1, 2,..., A, b = 1, 2,..., B a , A is the total number of first-level components in the i-th autonomous ship subsystem, B a represents the total number of second-level components included in the a-th first-level component. According to the two typical safety structures (series system / parallel system) of the multi-state system, the series-parallel structure of the components in the remote control ship system and subsystem in this embodiment is as Figure 3 shown.

[0083] S2: Establish a multi-state safety function of the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain the safety function of the autonomous ship subsystem in the u-th operating state;

[0084] Preferably, the multi-state safety function of the autonomous ship subsystem is represented by the following formula:

[0085] s (i) (t) = [1, s (i) (t, 1), s (i) (t, 2), s (i) (t, 3), s (i) (t, 4)], t ∈ [0, ∞)(T1)

[0086]

[0087] In the formula: s (i) (t) represents the five-state safety function of the i-th autonomous ship subsystem; s (i)(t, u) represents the safety function of the i-th autonomous ship subsystem in the u-th operating state; t represents the time; represents the b-th secondary component under the a-th primary component in the i-th autonomous ship subsystem and its safety function in the u-th operating state; A i represents the total number of primary components in the i-th autonomous ship subsystem; represents the total number of secondary components contained in the a-th primary component in the i-th autonomous ship subsystem; u represents the operating state, where u = 1 means the autonomous ship subsystem and the primary and secondary components under it are operating in the safety state subset {z′ = 1, z′ = 2, z′ = 3, z′ = 4}, u = 2 means the autonomous ship subsystem and the primary and secondary components under it are operating in the safety state subset {z′ = 2, z′ = 3, z′ = 4}, u = 3 means the autonomous ship subsystem and the primary and secondary components under it are operating in the safety state subset {z′ = 3, z′ = 4}, u = 4 means the autonomous ship subsystem and the primary and secondary components under it are operating in the safety state subset {z′ = 4}, and the safety state subset is a set composed of the safety states z′.

[0088] Among them, the multi-state safety function of the component is represented by the following formula:

[0089]

[0090] In the formula: represents the safety function of the b-th secondary component under the a-th primary component in the i-th autonomous ship subsystem in the u-th operating state;

[0091] Specifically, the safety state of the autonomous ship subsystem and its components can only transfer to a worse state over time, as Figure 4 shown. Due to the different functions and characteristics of the components within the autonomous ship subsystem, their degradation processes will also follow different failure distribution functions. Among them, the exponential distribution is applicable to systems with a constant failure rate, which means the failure probability of the system does not change over time. It is usually used to describe the failure time of electronic components because electronic components usually have a constant failure rate. The Weibull distribution is applicable to systems with a time-varying failure rate. When the shape parameter in the Weibull distribution is equal to 2, the failure rate increases linearly with time, also known as the Rayleigh distribution. It is usually used to describe the failure time of mechanical systems, such as bearings and gears. Since the environmental sensor subsystem S 3 and the communication subsystem S 4The failure rate of components in the [system name] is usually related to electronic components, so their failure time distribution function is more in line with the exponential distribution. The autonomous engine monitoring and control subsystem S 2 consists of the main engine, auxiliary engines, generators, and other auxiliary equipment. Such equipment usually fails due to material fatigue or other factors during operation. During the product life cycle, the risk of wear failure increases steadily. Therefore, the Rayleigh distribution is used to model the components within this subsystem.

[0092] In addition, for large systems, accurate system reliability functions and risk functions imply very complex functional forms, which is a serious constraint in the case of limited resources. Moreover, complex functional forms reduce the interpretability of the model, which is not conducive to the decision-making of managers. It is necessary to assume that the failure time distribution function follows the exponential distribution. Relatively speaking, the navigation subsystem S 1 composed of software and hardware, the communication subsystem S 4 and the remote operation center subsystem S 5 can be regarded as large systems. It is prudent to assume that the multi-state safety functions of components in the subsystem follow the exponential distribution.

[0093] Therefore, the safety function of components within the autonomous ship subsystem in the u-th operating state is expressed by the following formula:

[0094]

[0095] In the formula, represents the safety function of the b-th secondary component under the a-th primary component in the first autonomous ship subsystem in the u-th operating state, that is, the safety function of the b-th secondary component under the a-th primary component 1 in the navigation subsystem S in the u-th operating state; represents the transition intensity of the b-th secondary component under the a-th primary component in the first autonomous ship subsystem in the u-th operating state; The safety function of the b-th secondary component under the a-th primary component in the second autonomous ship subsystem in the u-th operating state, that is, the safety function of the b-th secondary component under the a-th primary component 2 in the autonomous engine monitoring and control subsystem S in the u-th operating state; The safety function of the b-th secondary component under the a-th primary component in the third autonomous ship subsystem in the u-th operating state, that is, the safety function of the b-th secondary component under the a-th primary component 3The b-th secondary component under the a-th primary component in The security function in the u-th operating state; The b-th secondary component under the a-th primary component in the 4th autonomous ship subsystem The security function in the u-th operating state, i.e., the communication subsystem S 4 The b-th secondary component under the a-th primary component in The security function in the u-th operating state; The b-th secondary component under the a-th primary component in the 5th autonomous ship subsystem The security function in the u-th operating state, i.e., the remote operation center subsystem S 5 The b-th secondary component under the a-th primary component in The security function in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 2nd autonomous ship subsystem The transition intensity in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 3rd autonomous ship subsystem The transition intensity in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 4th autonomous ship subsystem The transition intensity in the u-th operating state; Denotes the b-th secondary component under the a-th primary component in the 5th autonomous ship subsystem The transition intensity in the u-th operating state; exp[·] represents the exponential distribution;

[0096] Specifically, in this embodiment, the transition intensity refers to the probability that the system / component transitions from one state to another;

[0097] Among them, the multi-state security functions of the five autonomous ship subsystems are represented as follows:

[0098] s(t,u) = s (1) (t,u)·s (2) (t,u)·s (3) (t,u)·s (4) (t,u)·s (5) (t,u) (T5)

[0099] In the formula, s(t,u) represents the security function of the autonomous ship in the remote control mode in the u-th operating state; s (i) (t,u) (i = 1, 2, 3, 4, 5) represents the security function of the i-th autonomous ship subsystem in the u-th operating state.

[0100] S3: Obtain the average life of the autonomous vessel subsystem within the safe state subset according to the safety function of the autonomous vessel subsystem in the u-th operating state, so as to obtain the time of the predicted safeguard response and the time of the backup response;

[0101] Preferably, the average life of the autonomous vessel subsystem within the safe state subset is obtained as follows:

[0102]

[0103] In the formula: represents the average life of the autonomous vessel subsystem within the safe state subset; s (i) (t, u) represents the safety function of the i-th autonomous vessel subsystem in the u-th operating state; t represents the time; u represents the operating state;

[0104]

[0105] In the formula: t 后备 represents the backup response time; t 预测 represents the time of the predicted safeguard response;

[0106] Specifically, compared with traditional vessels, autonomous vessels have an operational design domain (ODD) within the acceptable risk condition (ARC), which is used to provide the conditions, relevant control modes, and operational modes of autonomous vessels under remote control and autonomous operation. The operational boundaries of autonomous vessels consist of the operational design domain and the acceptable risk condition, providing the operational capabilities and limitations of the vessel and the vessel-specific capabilities and limitations. Once the system or function deviates from its operational design domain, but the vessel as an integrated system can continue to operate within its operational boundaries, the deviation from its operational design domain should be regarded as a degraded state. The vessel can operate normally in the degraded state, which is usually caused by the degradation of a single autonomous or remote operating system. Once the vessel deviates from its operational boundaries, the vessel should take a backup response to further avoid the possibility of deviating from normal operation. As long as the vessel cannot stay within the operational boundaries, the minimal risk manoeuvre (MRM) should be executed to maintain the lowest level of safety under the minimal risk condition (MRC).

[0107] Although the operating state of the autonomous ship is poor when u = 1, the degradation of this state has no serious impact on ship damage and casualties. Therefore, it will maintain its function for a longer time and remain in an acceptable limit state. Combining the migration process of the operating state of the autonomous ship described above, the backup response time can be predicted through the average life of the autonomous ship subsystem within the subset of safe states, and the backup response time can guide decision-makers to implement responses in a timely manner to prevent deviation from the system operation experience.

[0108] Specifically, by taking safeguard responses at a predetermined time interval, that is, before the time for predicting the safeguard response, such responses allow the operator to solve potential abnormal problems within the ODD, thus avoiding transitioning to a degraded state. Such safeguard responses enable the operator to solve potential abnormal problems within the ODD, and the safeguard response time can guide decision-makers to implement timely responses to maintain a high availability and safety level during autonomous operation.

[0109] S4: Establish a system risk function for the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain the critical moment when the system risk exceeds the set system risk level under the critical state;

[0110] Preferably, the system risk function of the autonomous ship subsystem is established as follows:

[0111] R(t) = 1 - s(t,r)(T9)

[0112] Where: R(t) represents the system risk function; s(t,r) represents the safety function of the remotely controlled ship under the critical state; r represents the critical state; t represents the moment.

[0113] Preferably, the formula for obtaining the critical moment when the system risk exceeds the set system risk level under the critical state r is as follows:

[0114] τ = R -1 (t) = R -1 (δ)(T10)

[0115] Where: τ represents the critical moment when the system risk exceeds the set system risk level under the critical state r, R(t) represents the system risk function; R -1 (t) represents the inverse function of the system risk function R(t); δ represents the set system risk level.

[0116] Specifically, in this embodiment, the set system risk level is defined as δ, and the critical moment when the system risk exceeds δ is calculated by the following formula:

[0117] τ = R -1 (δ).

[0118] S5: Based on the critical moment when the system risk exceeds the set system risk level at the critical state r, the predicted time for guarantee response, and the time for backup response, evaluate the operating state of the autonomous ship in the remote control mode.

[0119] Among them, after obtaining the critical moment when the system risk exceeds the set system risk level at the critical state r, the predicted time for guarantee response, and the time for backup response, those skilled in the art can, based on the conventional techniques in the art, evaluate the operating state of the autonomous ship in the remote control mode. Therefore, the specific evaluation method is not described in detail here.

[0120] A specific example of the present invention is as follows:

[0121] Among them, several factors need to be considered when using expert judgment to determine the migration intensity of the safe state subset of various components, including component complexity, technical level, operating duration, and environmental conditions. The basic information of the experts is shown in Table 1. "ω 1 = complexity" refers to the inherent complexity of the component itself; "ω 2 = technical level" represents the intelligence level of the component and its ability to complete tasks; "ω 3 = operating duration" reflects the total working time of the component during ship navigation, and "ω 4 = environmental conditions" is related to the environment in which the component operates. Each factor is evaluated within the range of 1 to 10. In this embodiment, four marine scientists and two deck officers were invited to give their opinions. They are familiar with ship machinery and have profound insights into the development of autonomous ships. During the scoring process, the mean time between failures of a certain component is known, so the failure rate of this component in this state is expressed as ε 1 . Assume that both the score and the score coefficient are proportional to the actual failure rate, as shown in the equations from (T11) to (T14).

[0122] ε j = K j ·ε 1 (T11)

[0123] ∏ω c = k j (T12)

[0124]

[0125] In the formula: ε j represents the unknown failure rate; K j represents the coefficient for intermediate calculation; ε 1 represents the known failure rate; ω c(c=1,2,3,4) represents the factors to be considered in determining the migration strength of the security status subset of various components; k j k represents the value obtained by multiplying the four scoring factors of the component to be scored; 1 The value representing the product of the four scoring factors for a component with a known failure rate, μ j represents the unknown conditional life span; μ 1 represents the known conditional lifespan;

[0126] The conditional life usually refers to the time that a component can continue to maintain its function under specific conditions. Therefore, the approximate value It can be expressed as the mean time between failures. The conditional life is usually calculated using the following formula:

[0127]

[0128] Where: μ(u) represents the conditional life of the system in the safety state subset; represents the approximate value of μ(u); E[T(u)] represents the average value of the conditional life T(u) of the component in the safe operating state subset {u,u+1,…,z}, and E is the calculation symbol of the mean value; represents an estimate of the unknown migration strength;

[0129] According to expert judgment as shown in Table 1, the estimated value of unknown migration intensity for a given system component's MTBF is Calculated by the following formula:

[0130]

[0131] Where: MTTF means mean time to failure;

[0132] Table 1 Expert information

[0133]

[0134] Given that subsystem S 1 , S 3 and S 5 It is part of the bridge equipment, subsystem S 1 and S 5 The components use S 5 of Conduct an assessment. 2 and S 3 of (Except subsystem S 3 Components In the discussion and interview process, each subsystem The results are shown in Table 2. Among them, the integrated bridge system Autonomous navigation system Infrared camera Communication controller and remote operation center The estimated value of the unknown migration intensity of is calculated from the data judged by experts.

[0135] Table 2 shows, through discussion and interviews, the

[0136]

[0137]

[0138] Currently, the estimation of the migration intensity of the subset of the system component safety state mainly relies on expert judgment.

[0139] Using the data judged by experts, the safety functions of the components within each subsystem of the remotely controlled ship are as follows.

[0140]

[0141]

[0142] Substitute the system safety function of the subsystem components into the safety functions of each subsystem, and generate the corresponding function images, Figures 5 to 9 which respectively show the images of the safety functions of the remotely controlled ship components under different subsystems in different operating states.

[0143] In this example, assuming that the critical operating state of the system and its components is r = 3, the system risk function is given by the following formula:

[0144] r(t) = 1 - s(t,3)(T18)

[0145] The system risk function image is as Figure 10 shown. Assuming δ = 0.05, the moment when the system risk function exceeds the predetermined safety threshold is:

[0146] τ = 0.040(T19)

[0147] Identifying the moment when the system risk function exceeds the predetermined safety threshold can provide technical support for the decision-making of the regular maintenance strategy. Therefore, in this example, when the system runs continuously for 350.4 hours (τ = 0.040), the system is extremely likely to lose the confidentiality, integrity, and availability of mission data.

[0148]

[0149] Equation T20 is the calculated average life of the system operating within the safety threshold, t 后备Capable of predicting the backup response time, t 预测 Capable of predicting the safeguard response time. In this example, if the autonomous ship system has not been effectively and timely maintained after 189.8 consecutive days of operation, the likelihood that the safety level is lower than the expected level of a traditionally operated ship and the feasibility of introducing autonomous ships will increase significantly. Other results show that the degradation rate of the hardware facilities is faster than that of the software system. Among the hardware facilities, the degradation of the AEMC subsystem is the most serious threat, and the average lifespan of the environmental sensors breaking the initial safety state deserves high attention. Both are most likely to cause the autonomous ship to deviate from its operating boundary.

[0150] Table 3 Average Lifespans of Systems and Subsystems

[0151]

[0152] An autonomous ship operating state evaluation method considering the degradation of multi-state components in this embodiment develops an operating state evaluation framework from the perspective of system safety, which plays a crucial role in minimizing unnecessary state migrations and preventing the gradual deterioration of the system condition. This embodiment can predict the time when the ship enters the degradation state and the degradation state, thereby evaluating the operating safety of the autonomous ship and preventing the ship from deviating from the OE (operating boundary):

[0153] 1. This embodiment is an evaluation framework capable of evaluating the operating state of a ship from the perspective of system safety. The evaluation process considers the functional control structure of the entire system and the interaction mechanism between multi-component subsystems, providing basic support for scientific risk management strategies and decision-making processes in autonomous ship operations, and thus providing a reference for the formulation of maritime management strategies.

[0154] 2. This embodiment innovatively extends the traditional system operating state assumption from binary "normal - fault" to multi-state, enabling a more accurate capture of the unique risk control process of autonomous ships.

[0155] 3. This embodiment also introduces STPA to generate a functional control structure that helps with multi-state system modeling. A remotely controlled ship (carrying seafarers on board) is used as a real-case study to demonstrate the applicability of the method in the proposed framework.

[0156] 4. This embodiment can reveal the migration mechanism of the operating state of autonomous ships and deduce the implementation deadlines for safeguard response and backup response. The research results can provide theoretical support for preventing autonomous ships from deviating from the operating boundary.

[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for evaluating the operating status of an autonomous ship considering multi-state component degradation, characterized in that: The steps include: S1: Establish the functional control structure of the autonomous ship in remote control mode based on the system theory process analysis method; S2: establishing a multi-state safety function of the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain a safety function of the autonomous ship subsystem in the uth operating state; wherein u represents the operating state, and u≥1; S3: According to the safety function of the autonomous ship subsystem in the uth operating state, the average life of the autonomous ship subsystem in the safety state subset is obtained to obtain the predicted guarantee response time and backup response time; S4: establishing a system risk function of the autonomous ship subsystem based on the functional control structure of the autonomous ship to obtain a critical moment when the system risk exceeds a set system risk level under a critical state; S5: Evaluate the operating status of the autonomous ship in remote control mode based on the critical moment when the system risk exceeds the set system risk level in the critical state, the predicted time of the safeguard response and the time of the backup response.

2. The method for evaluating the operating status of an autonomous ship considering multi-state component degradation according to claim 1, characterized in that: In S2, the multi-state security function is expressed by the following formula: s (i) (t)=[1,s (i) (t,1),s (i) (t,2),s (i) (t,3),s (i) (t,4)],t∈[0,∞) Where: s (i) (t) represents the five-state safety function of the ith autonomous ship subsystem; s (i) (t,u) represents the safety function of the ith autonomous ship subsystem in the uth operating state; t represents the time; represents the bth secondary component under the ath primary component in the i-th autonomous ship subsystem The safety function in the uth operating state; A i represents the total number of first-level components in the ith autonomous ship subsystem; represents the total number of secondary components contained in the ath primary component in the ith autonomous ship subsystem; u represents the operating state; in, In the formula, Represents the bth second-level component under the ath first-level component in the first autonomous ship subsystem The safety function in the uth operating state is the bth second-level component under the ath first-level component in the navigation subsystem S1. Safety function in the uth operating state; Represents the bth second-level component under the ath first-level component in the first autonomous ship subsystem Migration intensity in the uth operating state; The bth second-level component under the ath first-level component in the second autonomous ship subsystem Safety function in the uth operating state, i.e., the bth second-level component under the ath first-level component in the autonomous engine monitoring and control subsystem S2 Safety function in the uth operating state; The bth second-level component under the ath first-level component in the third autonomous ship subsystem The safety function in the uth operating state is the bth secondary component under the ath primary component in the environmental sensor subsystem S3. Safety function in the uth operating state; The bth second-level component under the ath first-level component in the 4th autonomous ship subsystem The safety function in the uth operating state, i.e., the bth secondary component under the ath primary component in the communication subsystem S4 Safety function in the uth operating state; The bth second-level component under the ath first-level component in the fifth autonomous ship subsystem The safety function in the uth operating state, i.e., the bth secondary component under the ath primary component in the remote operation center subsystem S5 Safety function in the uth operating state; Represents the bth second-level component under the ath first-level component in the second autonomous ship subsystem Migration intensity in the uth operating state; Represents the bth second-level component under the ath first-level component in the third autonomous ship subsystem Migration intensity in the uth operating state; Represents the bth second-level component under the ath first-level component in the fourth autonomous ship subsystem Migration intensity in the uth operating state; Represents the bth second-level component under the ath first-level component in the fifth autonomous ship subsystem Migration intensity at the uth operating state; exp[·] represents exponential distribution.

3. The method for evaluating the operating status of an autonomous ship considering multi-state component degradation according to claim 1, characterized in that: In S3, the average life of the autonomous ship subsystem in the safe state subset is obtained as follows: Where: represents the average lifespan of the autonomous ship subsystem in a subset of safe states; s (i) (t,u) represents the safety function of the ith autonomous ship subsystem in the uth operating state; t represents the time; u represents the operating state; Where: t 后备 Indicates the backup response time; t 预测 Indicates the predicted assurance response time.

4. The method for evaluating the operating status of an autonomous ship considering multi-state component degradation according to claim 1, characterized in that: In S4, the system risk function of the autonomous ship subsystem is established as follows: R(t)=1-s(t,r) Where: R(t) represents the system risk function; s(t,r) represents the safety function of the remote-controlled ship under critical state; r represents the critical state; t represents the time.

5. The method for evaluating the operating status of an autonomous ship considering multi-state component degradation according to claim 4, characterized in that: The formula used to obtain the critical moment when the system risk exceeds the set system risk level under the critical state is as follows: τ=R -1 (t)=R -1 (d) Where: τ represents the critical moment when the system risk exceeds the set system risk level under the critical state r, R(t) represents the system risk function; R -1 (t) represents the inverse function of the system risk function R(t); δ represents the set system risk level.

6. The method for evaluating the operating status of an autonomous ship considering multi-state component degradation according to claim 1, characterized in that: The functional control structure includes a plurality of autonomous ship subsystems; The autonomous ship subsystem includes a number of first-level components connected in series; The primary assembly includes a plurality of secondary assemblies connected in parallel.

7. The method for evaluating the operating status of an autonomous ship considering multi-state component degradation according to claim 6, characterized in that: The plurality of autonomous ship subsystems include a navigation subsystem S1, an autonomous engine monitoring and control subsystem S2, an environmental sensor subsystem S3, a communication subsystem S4 and a remote operation center subsystem S5 which are connected in series in sequence; The first-level components under the navigation subsystem S1 include an integrated bridge system and autonomous navigation systems; The first-level components under the autonomous engine monitoring and control subsystem S2 include the host Steering gear, generator, auxiliary engine Among them, the secondary components under the steering gear include the first steering gear And the second steering gear The secondary components under the generator include the first generator Second generator The third generator Fourth generator The first-level components under the environmental sensor subsystem S3 include a global navigation satellite system radar Electronic Navigational Charts LiDAR Infrared camera Gyrocompass Taximeter depth sounder Automatic Vessel Identification System Global Maritime Distress and Safety System The first-level components under the communication subsystem S4 include a communication controller and VHF The first-level components under the remote operation center subsystem S5 include a remote operation center