Controllability evaluation method and device for vehicle function safety, and related equipment

Through real-time simulation machines and vehicle driving simulation equipment, the target test scenario is simulated, and the driver's behavioral information is collected for functional failures, combined with vehicle operating status information, the problem of lack of quantitative data in the existing technology is solved, and the controllability assessment of vehicle functional safety is achieved.

CN120449322APending Publication Date: 2025-08-08CHINA INTELLIGENT & CONNECTED VEHICLES (BEIJING) RES INST CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510935262.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The lack of quantitative data support in the prior art, especially the real behavioral data of the driver's interaction with the cockpit environment, has led to the inability to effectively evaluate the controllability of the vehicle's functional safety.

Method used

Through a real-time simulation machine, the target failure signal is sent when the driver drives a vehicle to simulate the driving equipment, and the driver can obtain driving behavior information and vehicle operation status information for the driver to deal with functional failures, and send this information to the evaluation server to determine the controllability evaluation level based on the values and weights of the multi-dimensional evaluation indicators.

Benefits of technology

It realizes an effective assessment of the safety and controllability of the vehicle, truly reflects the behavior of the driver interacting with the cockpit environment, and provides quantitative controllability evaluation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120449322A_ABST
    Figure CN120449322A_ABST
Patent Text Reader

Abstract

The invention discloses a controllability evaluation method and device for vehicle function safety and related equipment. The real-time simulation machine can send a target fault signal to the vehicle driving simulation equipment based on a preset target test scene under the condition that a driver drives the vehicle driving simulation equipment, so that the vehicle driving simulation equipment simulates a target function fault corresponding to the target fault signal; the operation state information of the vehicle driving simulation equipment in the target test scene and the driving behavior information of a driver for coping with the target function fault are obtained, wherein the operation state information and the driving behavior information comprise the numerical values of preset multi-dimensional evaluation indexes; then the running state information and the driving behavior information are sent to an evaluation server; and finally, the evaluation server determines the controllability evaluation level of the vehicle function safety according to the numerical values of the multi-dimensional evaluation indexes and the preset weight of each evaluation index. According to the embodiment of the invention, the controllability of the vehicle function safety can be effectively evaluated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of vehicle technology, and in particular relates to a controllability assessment method, device and related equipment for vehicle functional safety. Background Art

[0002] The Automotive Safety Integrity Level (ASIL) is the core system used in the ISO 26262 standard to assess automotive functional safety risks. It categorizes risks into four levels, ranging from ASIL-A to ASIL-D, based on three variables: severity, controllability, and exposure. This rating helps vehicle manufacturers and component suppliers conduct targeted safety development and design to ensure system functional safety. Controllability primarily reflects the driver's ability to avoid accidents, with four levels ranging from CO to C3. However, controllability assessments currently rely primarily on expert experience and lack quantitative data support, particularly real-world behavioral data involving driver interaction with the cockpit environment. Current functional safety controllability assessments based on real vehicles present high risks and incomplete coverage of test scenarios, making it difficult to effectively assess the controllability of automotive functional safety. Summary of the Invention

[0003] The embodiments of the present application provide a method, apparatus, and related equipment for evaluating the controllability of vehicle functional safety, which can effectively evaluate the controllability of vehicle functional safety.

[0004] In a first aspect, an embodiment of the present application provides a controllability assessment method for vehicle functional safety, applied to a real-time simulator, the method comprising: When a driver is driving a vehicle driving simulation device, sending a target fault signal to the vehicle driving simulation device based on a preset target test scenario, so that the vehicle driving simulation device simulates a target functional fault corresponding to the target fault signal; Obtaining operating state information of the vehicle driving simulation device and driving behavior information of the driver in response to the target functional failure under the target test scenario, wherein the operating state information and the driving behavior information include values of preset multi-dimensional evaluation indicators; The operating status information and the driving behavior information are sent to an evaluation server, so that the evaluation server determines the controllability evaluation level of the vehicle functional safety according to the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator.

[0005] In a second aspect, an embodiment of the present application provides a controllability assessment method for vehicle functional safety, which is applied to an assessment server. The method includes: Receiving operating status information of a vehicle driving simulation device and driving behavior information of a driver in response to a target functional failure under a target test scenario acquired and sent by a real-time simulator, wherein the operating status information and the driving behavior information include values of preset multi-dimensional evaluation indicators, and the target functional failure is a functional failure corresponding to a target fault signal simulated by the vehicle driving simulation device, and the target fault signal is sent by the real-time simulator to the vehicle driving simulation device based on the preset target test scenario when the driver is driving the vehicle driving simulation device; The controllability evaluation level of the vehicle functional safety is determined based on the values of the multi-dimensional evaluation indicators and the preset weights of the evaluation indicators.

[0006] In a third aspect, an embodiment of the present application provides a controllability assessment device for vehicle functional safety, which is applied to a real-time simulator. The device includes: A first sending module is configured to send a target fault signal to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates a target functional fault corresponding to the target fault signal; A first acquisition module is configured to acquire operating state information of the vehicle driving simulation device and driving behavior information of the driver in response to the target functional failure under the target test scenario, wherein the operating state information and the driving behavior information include numerical values of preset multi-dimensional evaluation indicators; The second sending module is used to send the operating status information and the driving behavior information to the evaluation server, so that the evaluation server determines the controllability evaluation level of the vehicle functional safety according to the numerical value of the multi-dimensional evaluation indicator and the preset weight of each evaluation indicator.

[0007] In a fourth aspect, an embodiment of the present application provides a controllability assessment device for vehicle functional safety, which is applied to an assessment server, and the device includes: a receiving module, configured to receive operating status information of a vehicle driving simulation device and driving behavior information of a driver in response to a target functional failure under a target test scenario, acquired and sent by a real-time simulator, wherein the operating status information and the driving behavior information include numerical values of preset multi-dimensional evaluation indicators, the target functional failure being a functional failure corresponding to a target fault signal simulated by the vehicle driving simulation device, the target fault signal being sent by the real-time simulator to the vehicle driving simulation device based on the preset target test scenario when the driver is driving the vehicle driving simulation device; The first determination module is used to determine the controllability evaluation level of the vehicle functional safety according to the numerical value of the multi-dimensional evaluation index and the preset weight of each evaluation index.

[0008] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the controllability assessment method for vehicle functional safety as described in any one of the above items.

[0009] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implements the controllability assessment method for vehicle functional safety as described in any one of the above items.

[0010] In a seventh aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the controllability assessment method for vehicle functional safety as described in any one of the above items.

[0011] In the controllability evaluation method, device, and related equipment of the vehicle functional safety of the embodiment of the present application, a real-time simulator can send a target fault signal to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates the target functional fault corresponding to the target fault signal; and obtain the operating state information of the vehicle driving simulation device and the driving behavior information of the driver in response to the target functional fault in the target test scenario, the operating state information and the driving behavior information include the values of the preset multi-dimensional evaluation indicators; then send the operating state information and the driving behavior information to the evaluation server; the evaluation server finally determines the controllability evaluation level of the vehicle functional safety based on the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator. In this way, in the embodiment of the present application, by simulating the target test scenario through the real-time simulator and the vehicle driving simulation device, the driving behavior information of the driver in response to the target functional fault can be collected. Such driving behavior information truly reflects the behavior of the driver interacting with the cockpit environment, and is combined with the operating state information of the vehicle driving simulation device in the target test scenario to achieve an effective evaluation of the controllability of the vehicle functional safety. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0013] Figure 1 This is an architecture diagram of a controllability assessment system for vehicle functional safety provided by an embodiment of the present application; Figure 21 is a flow chart of a method for evaluating the controllability of vehicle functional safety provided in an embodiment of the present application; Figure 3 This is a schematic diagram of the corresponding elements of the six-layer scenario architecture theory provided in the embodiment of the present application; Figure 4 1 is a schematic structural diagram of a controllability assessment device for vehicle functional safety provided in an embodiment of the present application; Figure 5 is a structural diagram of another vehicle functional safety controllability assessment device provided by an embodiment of the present application; Figure 6 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0014] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0015] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.

[0016] The Automotive Safety Integrity Level (ASIL) is the core system used in the ISO 26262 standard to assess automotive functional safety risks. It categorizes risks into four levels, ranging from ASIL-A to ASIL-D, based on severity, controllability, and exposure. This rating helps automakers and component suppliers conduct targeted safety development and design to ensure system functional safety. Controllability primarily reflects the driver's ability to avoid accidents, with four levels ranging from CO to C3. However, controllability assessment currently relies primarily on expert experience and lacks real-world behavioral data on driver interaction with the cabin environment, making it difficult to effectively evaluate the controllability of automotive functional safety.

[0017] In order to solve the problems of the prior art, the embodiments of the present application provide a method, apparatus, and related equipment for evaluating the controllability of vehicle functional safety. The following first introduces the vehicle functional safety controllability evaluation system provided by the embodiments of the present application.

[0018] Figure 1 FIG1 shows an architecture diagram of a vehicle functional safety controllability evaluation system provided by an embodiment of the present application. Figure 1 As shown, the controllability evaluation system 100 for vehicle functional safety may include: a vehicle driving simulation device 101, a real-time simulator 102 and an evaluation server 103, and the vehicle driving simulation device 101, the real-time simulator 102 and the evaluation server 103 are communicatively connected.

[0019] The vehicle driving simulation device 101 may include a free motion simulation system, a simulated cockpit, and a data acquisition system. The free motion simulation system can simulate physical movements of the vehicle, such as acceleration, braking, steering, pitch, roll, and yaw, to achieve motion simulation under different vehicle operating conditions and enhance immersion. The simulated cockpit includes a realistic human-machine interface, rearview mirrors, steering wheel, and pedals, making the environment within the simulated cockpit as realistic as possible. The data acquisition system can capture various types of driving behaviors of the driver.

[0020] The real-time simulator 102 can be a computer system capable of responding to and processing inputs promptly and generating outputs within a specified timeframe, all within strict time constraints. The real-time simulator 102 can load a vehicle dynamics model, a virtual environment model, and a fault injection model. It is responsible for highly accurate simulation of vehicle dynamics, environmental scenarios, and faults, and interacts with the vehicle driving simulator 101 in real time. Its core objective is to replicate the operating conditions of a real vehicle in the laboratory to verify functional safety.

[0021] The evaluation server 103 may be a computer or host computer that communicates with and controls the operation of the vehicle driving simulation device 101 and the real-time simulator 102. In the embodiment of the present application, the evaluation server 103 may determine the controllability evaluation level of the vehicle functional safety based on the values of the multi-dimensional evaluation indicators in the operating status information and driving behavior information and the preset weights of each evaluation indicator.

[0022] The vehicle driving simulation device 101, real-time simulator 102, and evaluation server 103 are connected to each other. For example, the driving simulation device 101 and the real-time simulator 102 can achieve μs-level interaction via CAN FD / EtherCAT, ensuring a real-time closed-loop between driver input and the vehicle model. The real-time simulator 102 and the evaluation server 103 transmit massive amounts of data via TCP / IP+XCP, supporting non-real-time analysis and storage.

[0023] Figure 2 The flow chart of the controllability evaluation method of vehicle functional safety provided by one embodiment of the present application is shown. Figure 1 The controllability assessment system for vehicle functional safety is shown in FIG. Figure 2 As shown, a controllability assessment method 200 for vehicle functional safety may include the following steps S201 to S205: S201, when a driver is driving a vehicle driving simulation device, the real-time simulator sends a target fault signal to the vehicle driving simulation device based on a preset target test scenario; S202, the vehicle driving simulation device simulates a target functional fault corresponding to the target fault signal; S203. The real-time simulator obtains operating status information of the vehicle driving simulation device and driving behavior information of the driver in response to the target functional failure in the target test scenario, where the operating status information and driving behavior information include values of preset multi-dimensional evaluation indicators; S204, the real-time simulator sends the operating status information and driving behavior information to the evaluation server; S205. The evaluation server determines the controllability evaluation level of the vehicle functional safety according to the values of the multi-dimensional evaluation indicators and the preset weights of the evaluation indicators.

[0024] In the controllability evaluation method of vehicle functional safety in an embodiment of the present application, a real-time simulator can send a target fault signal to a vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates the target functional fault corresponding to the target fault signal; and obtain the operating state information of the vehicle driving simulation device and the driving behavior information of the driver in response to the target functional fault in the target test scenario, the operating state information and the driving behavior information including the values of the preset multi-dimensional evaluation indicators; then send the operating state information and the driving behavior information to the evaluation server; the evaluation server finally determines the controllability evaluation level of the vehicle functional safety based on the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator. In this way, in the embodiment of the present application, by simulating the target test scenario through the real-time simulator and the vehicle driving simulation device, the driving behavior information of the driver in response to the target functional fault can be collected. Such driving behavior information truly reflects the behavior of the driver interacting with the cockpit environment, and is combined with the operating state information of the vehicle driving simulation device in the target test scenario to achieve an effective evaluation of the controllability of the vehicle functional safety.

[0025] In S201 , the driver driving the vehicle driving simulation device may, for example, enter a simulated driving cockpit and familiarize himself with various actuators in the simulated driving cockpit until he is fully proficient in them.

[0026] The above-mentioned target test scenario, for example, may refer to a virtual driving environment that is pre-designed to verify specific functions or performance and contains key variables and boundary conditions. By precisely controlling parameters such as the vehicle, environment, and faults, it simulates interactions in the real world or extreme working conditions.

[0027] The target fault signal may be a fault signal corresponding to a target functional fault in the target test scenario. Functional faults may include loss, overshoot, undershoot, reverse, unexpected activation, delay, or jamming of drive, brake, or steering.

[0028] The above-mentioned real-time simulator sends a target fault signal to the vehicle driving simulation device based on a preset target test scenario. For example, the real-time simulator may send a target fault signal to the vehicle driving simulation device via CAN FD / EtherCAT based on a preset target test scenario.

[0029] In S202, the target functional failure is the functional failure to be tested. The target functional failure corresponding to the target fault signal may be, for example, one of loss, over-amplitude, under-amplitude, reverse, unexpected activation, delay, or jamming of the drive, brake, or steering categories.

[0030] In S203, the operating status information of the vehicle driving simulation device may describe the operating status of the simulated vehicle, including vehicle speed, acceleration, driving trajectory, and the like.

[0031] The above-mentioned driving behavior information of the driver in response to the target function failure may be a description of the driver's behavior in response to the target function failure, such as the driver's reaction time, operating habits, difficulty of operation, etc.

[0032] The above-mentioned operating status information and driving behavior information may include the values of preset multi-dimensional evaluation indicators, among which the multi-dimensional evaluation indicators may specifically cover the operating status of the vehicle, such as vehicle speed, acceleration, driving trajectory and other indicators; they may also cover driver behavior, including the driver's reaction time, operating habits, difficulty of operation and other indicators; at the same time, environmental conditions are also a part that cannot be ignored. Indicators such as weather conditions, road conditions, and surrounding traffic flow should all be included in the multi-dimensional evaluation indicators, as well as the final results, including whether the vehicle has collided, rolled over, or driven out of the lane line and other indicators.

[0033] It should be noted that the multidimensional evaluation indicators can cover the vehicle's operating status (such as vehicle speed, acceleration, driving trajectory, etc.), driver behavior (including driver's reaction time, operating habits, difficulty of operation, etc.), and environmental conditions (such as weather conditions, road conditions, surrounding traffic flow and other elements should be included) as well as the final result (including whether the vehicle collides, rolls over, drives out of the lane line, etc.). After correlation analysis of these parameters and related factors, the parameters or factors that play a decisive role in the controllability assessment are determined as multidimensional evaluation indicators.

[0034] The above-mentioned real-time simulator obtains the operating status information of the vehicle driving simulation device under the target test scenario and the driving behavior information of the driver in response to the target functional failure. For example, the real-time simulator can directly obtain the operating status information of the vehicle driving simulation device under the target test scenario from the loaded vehicle dynamics model, virtual environment model and fault injection model, and obtain the driving behavior information of the driver in response to the target functional failure collected by the data acquisition system through CAN FD / EtherCAT.

[0035] In S204 , the real-time simulator sends the operating status information and the driving behavior information to the evaluation server. For example, the real-time simulator sends the operating status information and the driving behavior information to the evaluation server via TCP / IP+XCP.

[0036] In S205, the above-mentioned evaluation server determines the controllability evaluation level of the vehicle functional safety based on the numerical values of the multidimensional evaluation indicators and the preset weights of each evaluation indicator. For example, the evaluation server may multiply the numerical values of the multidimensional evaluation indicators by the preset weights of each evaluation indicator, and sum them up to obtain the controllability score of the vehicle functional safety; then map the controllability score to the score intervals corresponding to the preset multiple evaluation levels to determine the controllability evaluation level of the vehicle functional safety, with different evaluation levels corresponding to different score intervals. Alternatively, the numerical values of each evaluation indicator may be normalized to obtain the dimensionless numerical values of each evaluation indicator; then multiply the dimensionless numerical values of the multidimensional evaluation indicators by the preset weights of each evaluation indicator, and sum them up to obtain the controllability score of the vehicle functional safety; finally, map the controllability score to the score intervals corresponding to the preset multiple evaluation levels to determine the controllability evaluation level of the vehicle functional safety, with different evaluation levels corresponding to different score intervals.

[0037] As an implementation of the present application, in order to generate a more comprehensive test scenario, before S201, the method may further include: The real-time simulator constructs a vehicle dynamics model in response to the first configuration operation, the vehicle dynamics model being used to simulate the behavior of the vehicle in the target test scenario; The real-time simulation machine constructs a virtual environment model in response to the second configuration operation, the environment model being used to simulate an environment in a target test scenario; The real-time simulator builds a fault injection model, which is used to set a target fault signal, which is used to trigger a target functional fault in a target test scenario. The real-time simulator generates target test scenarios based on the vehicle dynamics model, virtual environment model and fault injection model.

[0038] The vehicle dynamics model described above is a set of computer models that describe the laws of vehicle motion through mathematical equations. They can be used to simulate the vehicle's behavior in the target test scenario, such as acceleration, braking, steering, pitch, roll, and yaw. It should be noted that the dynamic performance of different vehicles varies.

[0039] The above-mentioned environmental model can be used to simulate the environment in the target test scenario, such as the road shape, road facilities, physical restrictions, movable entities, environmental conditions and digital information in the simulated environment.

[0040] The above fault injection model can be used to set a target fault signal to trigger a target functional fault in a target test scenario.

[0041] The target test scenario is generated according to the vehicle dynamics model, the virtual environment model and the fault injection model. For example, the normal operation of the vehicle in the target test scenario can be constructed according to the vehicle dynamics model and the virtual environment model, and then the target functional failure is triggered by the fault injection model.

[0042] In the embodiment of the present application, by separately constructing a vehicle dynamics model, a virtual environment model, and a fault injection model, as many test scenarios as possible can be covered, making the generated test scenarios more comprehensive.

[0043] In some embodiments, in response to the first configuration operation, constructing the vehicle dynamics model may specifically include: In response to the first configuration operation, parameters of the vehicle body, transmission system, braking system, steering system, suspension and tires are configured to construct a vehicle dynamics model.

[0044] The above-mentioned vehicle body parameters mainly include the vehicle's exterior dimensions, wheelbase, track width, sprung mass and moment of inertia around each axis; the transmission system modeling takes into account the transmission efficiency of the clutch, transmission, drive shaft, differential, etc.; the braking system modeling takes into account the pipeline transmission delay time, ABS slip rate characteristics, brake pressure distribution, the relationship between the caliper and the braking torque, etc.; the steering system modeling mainly includes the steering column moment of inertia, steering gear type, damping, steering system C characteristics, etc.; the suspension mainly includes K characteristics and C characteristics, covering the relationship between wheel hop displacement and wheel center lateral displacement, etc.; in terms of tire modeling, it covers the mechanical properties of the tire under complex working conditions (such as lateral force, longitudinal force, return torque, etc.).

[0045] In an embodiment of the present application, in response to a first configuration operation, the parameters of the vehicle body, transmission system, braking system, steering system, suspension and tires are configured to construct a vehicle dynamics model, thereby realizing the dynamic performance of different vehicles.

[0046] In some embodiments, in response to the second configuration operation, constructing the virtual environment model may specifically include: In response to the second configuration operation, a virtual environment model is constructed according to the road shape, road facilities, physical limitations, movable entities, environmental conditions, and digital information.

[0047] In response to the second configuration operation, a virtual environment model is constructed according to road shape, road facilities, physical restrictions, movable entities, environmental conditions, and digital information. For example, the virtual environment model can be constructed based on a six-layer scenario architecture theory. The first layer is road geometry and topology, covering road type, geometry, elevation, cross-section, surface features, and intersection information. The second layer focuses on road facilities and restrictions, including road boundaries and traffic signs. The third layer involves temporary physical restrictions, such as traffic accidents and road work signs. The fourth layer is movable entities, including information such as entity type, entity manipulation, and the relative position of the entity to the vehicle. This layer mainly targets other traffic participants on the road, such as vehicles and pedestrians. The fifth layer describes environmental conditions, including time, climate, lighting, and road adhesion. The sixth layer is digital information, covering digital content such as V2X communication and high-precision maps. This layer of related information is less involved in this application.

[0048] In an embodiment of the present application, in response to the second configuration operation, a virtual environment model is constructed according to road shape, road facilities, physical restrictions, movable entities, environmental conditions and digital information, and the configuration of different virtual environments can be achieved.

[0049] In some embodiments, constructing the fault injection model may specifically include: A fault injection model is constructed based on various preset functional faults and various fault manifestations. The various functional faults include driving function faults, braking function faults, and steering function faults. The various fault manifestations include function loss, unexpected increase, unexpected decrease, unexpected reversal, unexpected activation, function delay, and function jamming. In response to the third configuration operation, a target fault signal corresponding to the target functional fault is set in the fault injection model.

[0050] The above-mentioned multiple functional failures may include driving function failure, braking function failure and steering function failure. In the embodiment of the present application, the multiple functional failures are not limited to these, and may also be set according to actual needs, which is not specifically limited here.

[0051] The above-mentioned various fault manifestations may include function loss, unexpected increase, unexpected decrease, unexpected reversal, unexpected activation, function delay and function stagnation. In the embodiment of the present application, the various fault manifestations are not limited to these and can also be set according to actual needs, which is not specifically limited here.

[0052] The third configuration operation described above may be used to configure the corresponding relationship between the target functional fault and the target fault signal.

[0053] In an embodiment of the present application, a fault injection model is constructed based on a plurality of preset functional faults and a plurality of fault manifestations, and then, in response to a third configuration operation, a target fault signal corresponding to a target functional fault is set in the fault injection model, thereby triggering different functional faults.

[0054] In some embodiments, the above S205 may specifically include: Normalize the values of each evaluation index to obtain the dimensionless value of each evaluation index; The controllability assessment level of vehicle functional safety is determined based on the dimensionless values of the multidimensional assessment indicators and the preset weights of each assessment indicator.

[0055] In the actual application of controllability assessment, there is a problem that cannot be ignored, that is, there are significant differences in the numerical values and units of various indicators. This difference makes it impossible for each indicator to be directly involved in the calculation, so it is necessary to de-dimensionalize the indicators. Normalization can return the data characteristics to a unified dimension and solve the problem of excessive dimensional differences. Therefore, the normalization method can be used to convert dimensional indicators into dimensionless indicators so that the data are at the same level after normalization. There are many ways to perform the above normalization. For example, the maximum and minimum normalization method can be used. This method is a scaler that converts the indicator data to [0, 1]. The specific method is as follows:

[0056] in, is the indicator data, that is, the value of the evaluation indicator, It is the dimensionless value after the evaluation index is mapped to the interval [0, 1]. is the maximum value of the indicator data, is the minimum value of the indicator data. In addition, the maximum and minimum standard method can also map the data to any range through certain changes. The specific method is as follows:

[0057] in, yes A dimensionless value after mapping to an arbitrary range, is the minimum value in any range, is the maximum value in any range.

[0058] In the embodiment of the present application, by normalizing the values of each evaluation indicator, the problem of excessive dimensional difference can be solved, and the dimensionless values of each evaluation indicator can be obtained, which can enhance data comparability. Then, based on the dimensionless values of the multidimensional evaluation indicators and the preset weights of each evaluation indicator, the controllability evaluation level of the vehicle functional safety can be efficiently determined.

[0059] In some embodiments, determining the controllability assessment level of vehicle functional safety based on the dimensionless values of the multi-dimensional assessment indicators and the preset weights of the assessment indicators may specifically include: The controllability score of vehicle functional safety is calculated based on the dimensionless values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator; The controllability score is mapped to the score range corresponding to multiple preset assessment levels to determine the controllability assessment level of vehicle functional safety. Different assessment levels correspond to different score ranges.

[0060] The aforementioned multiple assessment levels, for example, may be C0, C1, C2, and C3. C0 (Easily Controllable): The hazard scenario can be easily avoided by most drivers, requiring no active intervention or only routine maneuvers (such as light braking or steering). Example: A vehicle slightly deviates from its lane at low speed, and the driver naturally corrects the vehicle. C1 (Easy Controllable): The hazard can be avoided by most drivers through normal reactions, with relatively low operational difficulty (such as braking after a clear warning). Example: After the system triggers a visual / auditory alarm, the driver brakes promptly to avoid a rear-end collision. C2 (Difficult to Controllable): The hazard requires high driver skill or quick reaction to avoid, and some drivers may not be able to successfully handle it. Example: Sudden emergency braking requires the driver to fully apply the brakes and maintain a firm grip on the steering wheel within a very short period of time. C3 (Difficult to Controllable or Uncontrollable): The hazard is extremely difficult to avoid, and even expert drivers may fail, or the scenario is inherently uncontrollable (such as a tire blowout at high speed resulting in loss of control). Example: An electronic system malfunction causes complete steering failure.

[0061] The above-mentioned different evaluation levels correspond to different scoring intervals. For example, C0 may correspond to a scoring interval of 90-100; C1 may correspond to a scoring interval of 70-90; C2 may correspond to a scoring interval of 30-70; and C3 may correspond to a scoring interval of 0-30. Of course, in the embodiment of the present application, the correspondence between evaluation levels and scoring intervals is not limited to this and can also be set according to the actual needs of the user, and is not specifically limited here.

[0062] In an embodiment of the present application, the controllability score of the vehicle functional safety can be accurately calculated through the dimensionless values of the multidimensional evaluation indicators and the preset weights of each evaluation indicator, and the controllability score can be mapped to the score interval corresponding to the preset multiple evaluation levels, and finally the controllability evaluation level of the vehicle functional safety is determined, thereby effectively and accurately reflecting the driver's ability to avoid accidents.

[0063] As another implementation of the present application, in order to effectively avoid inconsistent judgments, before S205, the method may further include: The evaluation server obtains a judgment matrix of the multidimensional evaluation index, where the judgment matrix includes multiple element values, and the element values are used to represent the importance between two evaluation indicators in the multidimensional evaluation index; The evaluation server calculates the consistency ratio value of the judgment matrix. The consistency ratio value is the ratio of the consistency index in the judgment matrix to the random consistency index. When the consistency ratio value is less than the preset threshold, the evaluation server determines the weight of each evaluation indicator according to the judgment matrix; When the consistency ratio value is greater than or equal to a preset threshold, the evaluation server modifies the judgment matrix to obtain a modified judgment matrix, and determines the weight of each evaluation indicator according to the modified judgment matrix.

[0064] The judgment matrix may include multiple element values, wherein the element value is used to represent the importance between two evaluation indicators in the multidimensional evaluation indicator.

[0065] The judgment matrix for obtaining the multi-dimensional evaluation indicators may be a judgment matrix for receiving scores assigned by experts on the importance of each pair of evaluation indicators in the multi-dimensional evaluation indicators.

[0066] The consistency ratio value CR can be the ratio of the consistency index CI to the random consistency index RI in the judgment matrix, as shown in the following formula:

[0067] Among them, the consistency index (CI) can be used to quantify the degree of logical contradiction in the judgment matrix and reflect whether the decision makers maintain consistency in thinking when making pairwise comparisons. , where λmax is the maximum eigenvalue of the judgment matrix, and n is the order of the matrix (the number of indicators to be compared). The random consistency index (RI) can be a benchmark value generated by statistical methods to eliminate the influence of the matrix order on CI and provide an objective reference for consistency testing. n Order positive reciprocal matrix (elements are randomly assigned, satisfying aij =1 / aji ), calculate the average CI value of these random matrices, which is RI.

[0068] The above-mentioned preset threshold value can be 0.1, for example. When the consistency ratio value is less than the preset threshold value, the weight of each evaluation indicator is determined according to the judgment matrix. That is, when CR < 0.1, it indicates that the judgment matrix has good consistency. After the consistency check, the weight of each evaluation indicator can be determined according to the judgment matrix.

[0069] When the consistency ratio is greater than or equal to the preset threshold, the judgment matrix is modified to obtain a modified judgment matrix, and the weights of each evaluation indicator are determined based on the modified judgment matrix. In other words, when CR ≥ 0.1, the consistency is poor, and the judgment matrix needs to be modified and re-checked for consistency. The weights of each evaluation indicator are determined based on the modified judgment matrix.

[0070] In the embodiment of the present application, calculating the consistency ratio value of the judgment matrix can effectively avoid inconsistent judgments in the judgment matrix and ensure that there is a rigorous and logical progressive relationship between the importance of different indicators reflected by the judgment matrix.

[0071] To facilitate understanding of the controllability assessment method for vehicle functional safety in the embodiment of the present application, the actual application process of the controllability assessment method for vehicle functional safety is described as follows: 1. Build a driver-in-the-loop (DIL) functional safety and controllability quantitative assessment device, including dynamics simulation software (equivalent to the aforementioned vehicle dynamics model, virtual environment model, and fault injection model), a multi-degree-of-freedom driving simulation platform, a simulated cockpit, and a data acquisition system (equivalent to the aforementioned vehicle driving simulation equipment). The dynamics simulation software can configure the environment, vehicle dynamics, and fault triggers in hazardous scenarios, and calculate the vehicle's acceleration, braking, steering, pitch, roll, yaw, and other motion states to effectively simulate the vehicle's motion state. It can also output vehicle kinematic and dynamic index parameters and interact with the driver. The driving simulation platform can simulate the vehicle's physical motion, such as acceleration, braking, steering, pitch, roll, and yaw, to simulate the vehicle's motion under different operating conditions and enhance the sense of immersion. The simulated cockpit includes a realistic HMI (human-machine interface), rearview mirrors, steering wheel, and pedals, making the environment within the simulated cockpit as realistic as possible. The data acquisition system captures the driver's various driving behaviors.

[0072] Second, vehicle dynamics modeling. Within the dynamics simulation software, relevant vehicle parameters are configured, including the body, drivetrain, braking system, steering system, suspension, and tires. Body parameters primarily include vehicle dimensions, wheelbase, track width, sprung mass, and moments of inertia about various axes. Drivetrain modeling considers the transmission efficiency of the clutch, transmission, driveshaft, and differential. Braking system modeling considers pipeline transmission delays, ABS slip characteristics, brake pressure distribution, and the relationship between calipers and braking torque. Steering system modeling primarily includes steering column moment of inertia, steering gear type, damping, and steering system C characteristics. Suspension modeling primarily includes K and C characteristics, covering the relationship between wheel hop displacement and wheel center lateral displacement. Tire modeling encompasses tire mechanical properties under complex operating conditions (such as lateral force, longitudinal force, and aligning torque). By configuring relevant parameters for the body, drivetrain, braking system, steering system, suspension, and tires, a vehicle dynamics model (i.e., the aforementioned vehicle dynamics model) is constructed.

[0073] 3. After completing the construction of the quantitative evaluation device for functional safety controllability based on the driver in the loop, further build the scenario model based on the following Figure 3 The six-layer scenario architecture theory shown builds a typical scenario model (i.e., the virtual environment model mentioned above). The first layer is road geometry and topology, covering road type, geometry, elevation, cross-section, surface features, and intersection information. The second layer focuses on road facilities and restrictions, including road boundaries and traffic signs. The third layer involves temporary physical restrictions, such as traffic accidents and road work signs. The fourth layer is movable entities, including information such as entity type, entity manipulation, and the entity's position relative to the vehicle. This layer mainly focuses on other traffic participants on the road, such as vehicles and pedestrians. The fifth layer describes environmental conditions, including time, climate, lighting, and road adhesion. The sixth layer is digital information, covering digital content such as V2X communication and high-precision maps. This layer of related information is less involved in this application.

[0074] 4. Build a fault injection model and set event-based fault triggers in the existing dynamics simulation software. Based on the HAZOP methodology, fault types are categorized as function loss, unexpected increase, unexpected decrease, unexpected reversal, unexpected activation, function delay, and function stagnation (equivalent to the various fault manifestations mentioned above). The main functions are categorized as drive, braking, and steering (equivalent to the various functional failures mentioned above). The manifestations of these fault types on the three functions are shown in Table 1-3 below: Table 1 Driver function failure

[0075] Table 2 Braking function failure

[0076] Table 3 Steering function failure

[0077] 5. Conduct integrated debugging of various models, multi-degree-of-freedom driving simulation platforms, simulated cockpits, and data acquisition systems to ensure system operation. Recruit drivers to enter the simulated cockpit and, without prior notice, conduct fault injection testing to test their real-world reactions. After testing begins, drivers will first familiarize themselves with the various actuators within the simulated cockpit. Once fully proficient, fault injection will be performed after a period of time. Fault types include the aforementioned drive, brake, and steering failures, such as loss, overshoot, undershoot, reverse, unexpected activation, delay, and jamming. This will test the driver's actual driving behavior under real-world conditions. Collect relevant actuator actuation parameters, driver reaction time, and vehicle motion parameters.

[0078] 6. The collected multi-dimensional parameters need to be mapped to a single goal, namely controllability. Therefore, multi-dimensional indicators such as driver reaction time, control difficulty, vehicle speed, acceleration, and collision are comprehensively considered. Each indicator is assigned a corresponding weight, and finally a total score is calculated. The main steps include: (1) Confirmation of multidimensional quantitative indicators (equivalent to the above multidimensional evaluation indicators) When conducting a controllability assessment, the first task is to identify the specific parameters and factors that will determine the final quantitative results. This should include the vehicle's operating state, including key indicators such as speed, acceleration, and driving trajectory; driver behavior, including reaction time, operating habits, and ease of control; and environmental conditions, including weather conditions, road conditions, and surrounding traffic flow. Finally, the final outcome, including whether the vehicle collided, rolled over, or left the lane, can be determined. With these confirmed multi-dimensional quantitative indicators as a foundation, subsequent quantitative assessments can be conducted based on them.

[0079] (2) De-dimensionalizing indicators The practical application of quantitative controllability assessment faces a significant problem: the significant differences in numerical values and units between the indicators in the indicator layer. This difference prevents the indicators from being directly included in the calculation, so they need to be dimensionless. Normalization can reduce data features to a unified dimension, resolving the problem of excessive dimensional differences. Therefore, normalization is used to convert dimensional indicators into dimensionless ones, so that the normalized data is at the same level. There are many ways to normalize, including the maximum-minimum normalization method, which is a scaler that converts the indicator data to [0, 1]. The specific method is as follows:

[0080] in is the maximum value of the indicator data, It is the minimum value of the indicator data. The maximum and minimum standard method can also map the data to any range through certain changes. The specific method is as follows: .

[0081] (3) Comparison of relative importance of indicators Constructing a judgment matrix is a key step in the quantitative controllability assessment process. This process relies on comparing the relative importance of indicators. The values in the judgment matrix carry significant meaning, intuitively reflecting the importance of each indicator and its corresponding weighting. Ultimately, by multiplying the judgment matrix with the corresponding indicator data, a quantitative score is generated, ultimately achieving the goal of quantitatively assessing controllability.

[0082] However, in actual practice, if only a single indicator is used to score its importance, it often leads to many problems. On the one hand, this scoring method is easily interfered with by subjective factors. After all, everyone's perception of the importance of a single indicator may vary greatly, and there is a lack of a relatively objective and unified reference standard. On the other hand, since there are no other indicators to compare with it, scoring a single indicator in isolation is likely to cause a distortion of the importance reflected by the indicator. The resulting deviation may be continuously amplified in subsequent quantitative evaluations, seriously affecting the accuracy and reliability of the final evaluation results. On the contrary, by conducting a comparative evaluation of the two indicators, the above problems can be effectively circumvented, and the relative importance relationship between the two indicators can be clearly and accurately assessed.

[0083] (4) Consistency check In order to effectively avoid inconsistent judgments and ensure that there is a rigorous and logical progressive relationship between the importance of different indicators reflected in the judgment matrix, it is particularly important to perform consistency checking on the judgment matrix.

[0084] When carrying out consistency verification, it is necessary to introduce the consistency index CI and the random consistency index RI to jointly calculate the consistency ratio CR of indicators at the same level. The calculation formula is as follows:

[0085] When CR is less than 0.1, the judgment matrix has good consistency and passes the consistency check; when CR is greater than or equal to 0.1, the consistency is poor and the judgment matrix needs to be corrected and re-checked for consistency.

[0086] (5) Weight calculation In a judgment matrix that has passed consistency verification, each element will be assigned different values due to differences in the importance of the indicators. In order to make the quantitative evaluation score more meaningful and facilitate the subsequent setting of appropriate thresholds for quantitative evaluation of controllability, it is necessary to further calculate the weight vector based on the judgment matrix that has passed consistency verification.

[0087] (6) Calculation of total score and quantitative rating The final quantitative score (equivalent to the controllability score of the vehicle functional safety mentioned above) is calculated using the dimensionless parameters and weight vector, and a quantitative assessment of the controllability is performed based on the grade range of the score (equivalent to the controllability assessment grade mentioned above).

[0088] In the embodiment of the present application, the real driver, vehicle dynamics model, fault injection model, driving simulator, etc. can be coupled and linked by simulation means to realize functional safety controllability testing. In addition, through the form of a driver in the loop, the controllability after the simulated fault injection is truly evaluated without informing the driver in advance, and the driver's actual performance when facing various unexpected faults is evaluated, and relatively objective evaluation index parameters are output. It is also possible to conduct a comprehensive analysis and quantitative evaluation of multi-dimensional indicators, and finally map them into a controllability rating, which can optimize the original purely subjective evaluation into a quantitative evaluation based on objective parameters, thereby improving the objectivity and accuracy of the evaluation.

[0089] Based on the controllability assessment method for vehicle functional safety provided in the above embodiments, this application also provides a specific implementation of a controllability assessment device for vehicle functional safety. Please refer to the following embodiments.

[0090] like Figure 4 As shown, the vehicle functional safety controllability assessment device 400 provided in an embodiment of the present application is applied to a real-time simulator. The above-mentioned device 400 may include the following modules: a first sending module 401, a first acquisition module 402 and a second sending module 403.

[0091] The first sending module 401 is configured to send a target fault signal to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates a target functional fault corresponding to the target fault signal; A first acquisition module 402 is configured to acquire operating status information of the vehicle driving simulation device and driving behavior information of the driver in response to a target functional failure in a target test scenario, wherein the operating status information and driving behavior information include values of preset multi-dimensional evaluation indicators; The second sending module 403 is used to send the operating status information and driving behavior information to the evaluation server, so that the evaluation server determines the controllability evaluation level of the vehicle functional safety according to the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator.

[0092] In the controllability evaluation device for vehicle functional safety of the embodiment of the present application, a real-time simulator can send a target fault signal to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates the target functional fault corresponding to the target fault signal; and obtain the operating state information of the vehicle driving simulation device and the driving behavior information of the driver in response to the target functional fault in the target test scenario, the operating state information and the driving behavior information including the values of the preset multi-dimensional evaluation indicators; then send the operating state information and the driving behavior information to the evaluation server; the evaluation server finally determines the controllability evaluation level of the vehicle functional safety based on the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator. In this way, in the embodiment of the present application, by simulating the target test scenario by the real-time simulator and the vehicle driving simulation device, the driving behavior information of the driver in response to the target functional fault can be collected. Such driving behavior information truly reflects the behavior of the driver in interacting with the cockpit environment, and is combined with the operating state information of the vehicle driving simulation device in the target test scenario to achieve an effective evaluation of the controllability of the vehicle functional safety.

[0093] As an implementation of the present application, in order to generate a more comprehensive test scenario, the apparatus 400 may further include: A first building module is configured to build a vehicle dynamics model in response to a first configuration operation, the vehicle dynamics model being used to simulate the behavior of a vehicle in a target test scenario; A second building module is configured to build a virtual environment model in response to a second configuration operation, where the environment model is used to simulate an environment in a target test scenario; The third building module is used to build a fault injection model, which is used to set a target fault signal, and the target fault signal is used to trigger a target functional fault in a target test scenario; The generation module is used to generate target test scenarios based on the vehicle dynamics model, virtual environment model and fault injection model.

[0094] In some embodiments, the first construction module is specifically configured to configure parameters of the vehicle body, transmission system, braking system, steering system, suspension, and tires in response to a first configuration operation to construct a vehicle dynamics model.

[0095] In some embodiments, the second construction module is specifically configured to construct a virtual environment model in response to the second configuration operation according to road shape, road facilities, physical restrictions, movable entities, environmental conditions and digital information.

[0096] In some embodiments, the third building block may specifically include: A construction unit is used to construct a fault injection model based on a plurality of preset functional faults and a plurality of fault manifestations. The plurality of functional faults include driving function faults, braking function faults, and steering function faults. The plurality of fault manifestations include function loss, unexpected increase, unexpected decrease, unexpected reversal, unexpected activation, function delay, and function jamming. The setting unit is configured to set a target fault signal corresponding to a target functional fault in the fault injection model in response to a third configuration operation.

[0097] like Figure 5 As shown, the vehicle functional safety controllability assessment device 500 provided in an embodiment of the present application is applied to an assessment server. The above-mentioned device 500 may include the following modules: a receiving module 501 and a calculating module 502.

[0098] A receiving module 501 is configured to receive operating status information of a vehicle driving simulation device and driving behavior information of a driver in response to a target functional failure under a target test scenario, acquired and transmitted by a real-time simulator. The operating status information and driving behavior information include values of preset multi-dimensional evaluation indicators. The target functional failure is a functional failure corresponding to a target fault signal simulated by the vehicle driving simulation device. The target fault signal is transmitted by the real-time simulator to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device. The first determination module 502 is configured to determine the controllability evaluation level of the vehicle functional safety according to the values of the multi-dimensional evaluation indicators and the preset weights of the evaluation indicators.

[0099] In the controllability evaluation device for vehicle functional safety of the embodiment of the present application, a real-time simulator can send a target fault signal to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates the target functional fault corresponding to the target fault signal; and obtain the operating state information of the vehicle driving simulation device and the driving behavior information of the driver in response to the target functional fault in the target test scenario, the operating state information and the driving behavior information including the values of the preset multi-dimensional evaluation indicators; then send the operating state information and the driving behavior information to the evaluation server; the evaluation server finally determines the controllability evaluation level of the vehicle functional safety based on the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator. In this way, in the embodiment of the present application, by simulating the target test scenario by the real-time simulator and the vehicle driving simulation device, the driving behavior information of the driver in response to the target functional fault can be collected. Such driving behavior information truly reflects the behavior of the driver in interacting with the cockpit environment, and is combined with the operating state information of the vehicle driving simulation device in the target test scenario to achieve an effective evaluation of the controllability of the vehicle functional safety.

[0100] In some embodiments, the first determining module 502 may specifically include: A normalization processing unit, used to normalize the values of each evaluation index to obtain a dimensionless value of each evaluation index; The determination unit is used to determine the controllability evaluation level of the vehicle functional safety based on the dimensionless values of the multidimensional evaluation indicators and the preset weights of each evaluation indicator.

[0101] In some embodiments, the determining unit may specifically include: A calculation subunit, configured to calculate a controllability score of vehicle functional safety based on the dimensionless values of the multidimensional evaluation indicators and the preset weights of the evaluation indicators; The determination subunit is used to map the controllability score to the score interval corresponding to the preset multiple evaluation levels, determine the controllability evaluation level of the vehicle functional safety, and different evaluation levels correspond to different score intervals.

[0102] As another implementation of the present application, in order to effectively avoid inconsistent judgments, the apparatus 500 may further include: A second acquisition module is used to obtain a judgment matrix of a multidimensional evaluation index, where the judgment matrix includes multiple element values, and the element values are used to represent the importance between two evaluation indicators in the multidimensional evaluation index; A calculation module is used to calculate the consistency ratio value of the judgment matrix, where the consistency ratio value is the ratio of the consistency index in the judgment matrix to the random consistency index; A second determination module is used to determine the weight of each evaluation indicator according to the judgment matrix when the consistency ratio value is less than a preset threshold; The correction module is used to correct the judgment matrix when the consistency ratio value is greater than or equal to a preset threshold to obtain a corrected judgment matrix, and determine the weight of each evaluation indicator according to the corrected judgment matrix.

[0103] Figure 6 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application is shown.

[0104] The electronic device may include a processor 601 and a memory 602 storing computer program instructions.

[0105] Specifically, the processor 601 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0106] Memory 602 may include a large-capacity memory for data or instructions. By way of example and not limitation, memory 602 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 602 may include removable or non-removable (or fixed) media. Where appropriate, memory 602 may be internal or external to the integrated gateway disaster recovery device. In a specific embodiment, memory 602 is a non-volatile solid-state memory.

[0107] In certain embodiments, the memory 602 may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.

[0108] The processor 601 reads and executes computer program instructions stored in the memory 602 to implement any one of the controllability assessment methods for vehicle functional safety in the above embodiments.

[0109] In one example, the electronic device may further include a communication interface 603 and a bus 610. Figure 6 As shown, the processor 601, the memory 602, and the communication interface 603 are connected via a bus 610 and communicate with each other.

[0110] The communication interface 603 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0111] The bus 610 includes hardware, software, or both that couples components of the electronic device to each other. By way of example, and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industrial Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 610 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.

[0112] The electronic device can execute the controllability evaluation method of vehicle functional safety in the embodiment of the present application, thereby realizing the combination of Figure 2 、 Figure 4 and Figure 5 A controllability assessment method and apparatus for vehicle functional safety are described.

[0113] In addition, in conjunction with the vehicle functional safety controllability assessment method in the above-mentioned embodiments, embodiments of the present application may provide a computer-readable storage medium for implementation. The computer-readable storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any of the vehicle functional safety controllability assessment methods in the above-mentioned embodiments is implemented.

[0114] An embodiment of the present application also provides a computer program product, including a computer program, which, when processed and executed, implements any one of the vehicle functional safety controllability assessment methods in the above embodiments.

[0115] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0116] The functional blocks shown in the block diagrams described above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they may be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, and the like. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments may be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or communication link. "Machine-readable medium" may include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memory, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and the like. Code segments may be downloaded via a computer network such as the Internet or an intranet.

[0117] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0118] Aspects of the present disclosure have been described above with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block in the flowcharts and / or block diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine such that execution of these instructions by the processor of the computer or other programmable data processing device enables the implementation of the functions / actions specified in one or more blocks in the flowcharts and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block in the block diagrams and / or flowcharts, as well as combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware that performs the specified functions or actions, or by a combination of dedicated hardware and computer instructions.

[0119] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A controllability assessment method for vehicle functional safety, characterized in that: Applied to a real-time simulation machine, the method includes: When a driver is driving a vehicle driving simulation device, sending a target fault signal to the vehicle driving simulation device based on a preset target test scenario, so that the vehicle driving simulation device simulates a target functional fault corresponding to the target fault signal; Obtaining operating state information of the vehicle driving simulation device and driving behavior information of the driver in response to the target functional failure under the target test scenario, wherein the operating state information and the driving behavior information include values of preset multi-dimensional evaluation indicators; The operating status information and the driving behavior information are sent to an evaluation server, so that the evaluation server determines the controllability evaluation level of the vehicle functional safety according to the values of the multi-dimensional evaluation indicators and the preset weights of each evaluation indicator.

2. The method according to claim 1, characterized in that Before sending the target fault signal to the vehicle driving simulation device based on the preset target test scenario, the method further includes: In response to the first configuration operation, constructing a vehicle dynamics model, the vehicle dynamics model being used to simulate the behavior of the vehicle in the target test scenario; In response to the second configuration operation, constructing a virtual environment model, wherein the environment model is used to simulate the environment in the target test scenario; Constructing a fault injection model, wherein the fault injection model is used to set the target fault signal, and the target fault signal is used to trigger the target functional fault in the target test scenario; The target test scenario is generated according to the vehicle dynamics model, the virtual environment model and the fault injection model.

3. The method according to claim 2, characterized in that The constructing of the vehicle dynamics model in response to the first configuration operation includes: In response to the first configuration operation, parameters of the vehicle body, transmission system, braking system, steering system, suspension and tires are configured to construct a vehicle dynamics model.

4. The method according to claim 2, characterized in that The step of constructing a virtual environment model in response to the second configuration operation includes: In response to the second configuration operation, a virtual environment model is constructed according to the road shape, road facilities, physical limitations, movable entities, environmental conditions, and digital information.

5. The method according to claim 2, characterized in that The constructing of the fault injection model includes: Constructing a fault injection model based on various preset functional faults and various fault manifestations, including driving function faults, braking function faults, and steering function faults, and various fault manifestations including function loss, unexpected increase, unexpected decrease, unexpected reversal, unexpected activation, function delay, and function stagnation; In response to a third configuration operation, the target fault signal corresponding to the target functional fault is set in the fault injection model.

6. A controllability assessment method for vehicle functional safety, characterized in that: Applied to an evaluation server, the method includes: Receiving operating status information of a vehicle driving simulation device and driving behavior information of a driver in response to a target functional failure under a target test scenario acquired and sent by a real-time simulator, wherein the operating status information and the driving behavior information include values of preset multi-dimensional evaluation indicators, and the target functional failure is a functional failure corresponding to a target fault signal simulated by the vehicle driving simulation device, and the target fault signal is sent by the real-time simulator to the vehicle driving simulation device based on the preset target test scenario when the driver is driving the vehicle driving simulation device; The controllability evaluation level of the vehicle functional safety is determined based on the values of the multi-dimensional evaluation indicators and the preset weights of the evaluation indicators.

7. The method according to claim 6, characterized in that Determining the controllability evaluation level of vehicle functional safety based on the values of the multi-dimensional evaluation indicators and the preset weights of the evaluation indicators includes: Normalizing the values of the evaluation indicators to obtain dimensionless values of the evaluation indicators; The controllability evaluation level of the vehicle functional safety is determined based on the dimensionless numerical value of the multidimensional evaluation index and the preset weight of each evaluation index.

8. The method according to claim 7, characterized in that Determining the controllability evaluation level of vehicle functional safety based on the dimensionless values of the multidimensional evaluation indicators and the preset weights of the evaluation indicators includes: Calculating a controllability score for vehicle functional safety based on the dimensionless values of the multidimensional evaluation indicators and the preset weights of the evaluation indicators; The controllability score is mapped to a score interval corresponding to a plurality of preset evaluation levels to determine the controllability evaluation level of the vehicle functional safety, where different evaluation levels correspond to different score intervals.

9. The method according to claim 6, characterized in that Before determining the controllability evaluation level of vehicle functional safety based on the values of the multi-dimensional evaluation indicators and the preset weights of the evaluation indicators, the method further includes: Obtaining a judgment matrix of the multidimensional evaluation index, the judgment matrix including a plurality of element values, the element values being used to represent the importance between two evaluation indicators in the multidimensional evaluation index; Calculating a consistency ratio value of the judgment matrix, where the consistency ratio value is a ratio of a consistency index to a random consistency index in the judgment matrix; When the consistency ratio value is less than a preset threshold, determining the weight of each evaluation indicator according to the judgment matrix; When the consistency ratio value is greater than or equal to the preset threshold, the judgment matrix is corrected to obtain a corrected judgment matrix, and the weight of each evaluation indicator is determined according to the corrected judgment matrix.

10. A controllability assessment device for vehicle functional safety, characterized in that: Applied to a real-time simulation machine, the device comprises: A first sending module is configured to send a target fault signal to the vehicle driving simulation device based on a preset target test scenario when the driver is driving the vehicle driving simulation device, so that the vehicle driving simulation device simulates a target functional fault corresponding to the target fault signal; A first acquisition module is configured to acquire operating state information of the vehicle driving simulation device and driving behavior information of the driver in response to the target functional failure under the target test scenario, wherein the operating state information and the driving behavior information include numerical values of preset multi-dimensional evaluation indicators; The second sending module is used to send the operating status information and the driving behavior information to the evaluation server, so that the evaluation server determines the controllability evaluation level of the vehicle functional safety according to the numerical value of the multi-dimensional evaluation indicator and the preset weight of each evaluation indicator.

11. A controllability assessment device for vehicle functional safety, characterized in that: Applied to an evaluation server, the device comprises: a receiving module, configured to receive operating status information of a vehicle driving simulation device and driving behavior information of a driver in response to a target functional failure under a target test scenario, acquired and sent by a real-time simulator, wherein the operating status information and the driving behavior information include numerical values of preset multi-dimensional evaluation indicators, the target functional failure being a functional failure corresponding to a target fault signal simulated by the vehicle driving simulation device, the target fault signal being sent by the real-time simulator to the vehicle driving simulation device based on the preset target test scenario when the driver is driving the vehicle driving simulation device; The first determination module is used to determine the controllability evaluation level of the vehicle functional safety according to the numerical value of the multi-dimensional evaluation index and the preset weight of each evaluation index.

12. An electronic device, characterized in that: The device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the controllability assessment method for vehicle functional safety as described in any one of claims 1 to 9.

13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the controllability assessment method for vehicle functional safety according to any one of claims 1 to 9.

14. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the controllability assessment method for vehicle functional safety as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Driving performance testing method and device for autonomous vehicle

    CN109520744A

  • Vehicle function safety controllability grade evaluation method, device, equipment and medium

    CN117422344A

  • Vehicle control method and device, equipment, storage medium and product

    CN118753315A

  • Vehicle safety acceptance criterion evaluation test system and method

    CN119226143A

  • In-vehicle emotion based service providing device and method of controlling the same

    KR1020220014674A