Function security detection method and device, electronic equipment and storage medium
By injecting the fault signal and recording the level state change moment, the problem of difficulty in measuring the fault processing time in the prior art is solved, and high-precision fault processing time measurement is realized to ensure the safety of the automotive system in the case of failure.
Patent Information
- Application Number
- CN202510629886.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-08-19
AI Technical Summary
The prior art is difficult to accurately measure the fault handling time, making it difficult to evaluate the functional safety of automotive electronic systems in the event of a failure.
By injecting the fault signal and recording the fault signal injection time and the level state change signal generated when the system responds, the software behavior is converted into a measurable physical behavior and the fault processing time is calculated.
It realizes high-precision and interference-free fault handling time measurement, ensuring that the system has enough time to deal with faults before the hazard incident occurs, and reducing the level of hazards in the automobile operation.
Smart Images

Figure CN120508082A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of functional safety technology, and in particular to a functional safety detection method, device, electronic equipment and storage medium. Background Art
[0002] As the automotive industry rapidly develops toward intelligence and electrification, the electronic systems within vehicles are becoming increasingly complex, with significantly higher levels of integration and software dependency. Technological upgrades also bring with them a higher risk of systemic failures and random hardware failures. Therefore, the functional safety of vehicles has become particularly important, directly impacting the life and property safety of drivers, passengers, and other road users. The goal of functional safety is to ensure that the system can still operate safely or enter a safe state in the event of a fault, thereby reducing the potential hazards caused by electronic system failures. In functional safety assessments, fault handling time is a key indicator of whether a system can respond to a fault within a specified timeframe. It represents the time interval from the occurrence of a fault to the DUT (system under test) entering a safe state. Its significance lies in ensuring that the system can respond and recover to a safe state within a specified timeframe, thereby reducing the level of hazard to vehicle operation.
[0003] In related technologies, fault injection testing is usually used to verify the effectiveness of automotive functional safety mechanisms. For example, hardware fault injection tools are used to briefly change sensor signals or interrupt a communication bus to simulate actual failure conditions. The DUT identifies the fault, responds, and handles the fault. However, since fault identification and fault response are implemented by the sampling and filtering code and safety mechanism code inside the DUT, this process is a software behavior and is difficult to capture or measure, making it difficult to measure the fault handling time. Summary of the Invention
[0004] The problem solved by the present invention is how to accurately measure the fault processing time.
[0005] To solve the above problems, the present invention provides a functional safety detection method, device, electronic device and storage medium.
[0006] In a first aspect, the present invention provides a functional safety testing method, comprising:
[0007] In response to a fault signal injected into the system under test, determining a first time according to a time when the fault signal is injected;
[0008] In response to a level state change signal outputted by a first signal terminal of the system under test, determining a second time according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers the activation of the safety mechanism;
[0009] A fault processing time is determined according to the first time and the second time.
[0010] Optionally, in response to a fault signal injected into the system under test, determining the first time according to a time when the fault signal is injected includes:
[0011] injecting a fault signal into the second signal terminal of the system under test through a fault generating system;
[0012] When it is detected that the fault signal triggers a level state change at the second signal terminal, the moment when the level state of the second signal terminal changes is determined to be the first moment.
[0013] Optionally, before injecting a fault signal into the second signal terminal of the system under test through the fault generating system, the method further includes:
[0014] defining a fault type and fault parameters by the fault generating system, wherein the fault type includes one of an undervoltage fault, an overvoltage fault, a voltage mutation fault, and a voltage fluctuation fault, and the fault parameters include at least one of a fault amplitude, a fault duration, and a fault triggering mode;
[0015] Based on the fault type and the fault parameters, the fault generating system drives a voltage regulating circuit to simulate a voltage fault and generates the fault signal.
[0016] Optionally, determining the moment when the level state of the second signal terminal changes as the first moment includes:
[0017] When the fault signal triggers the level of the second signal end to switch from the first level to the second level, the end time of the first level or the start time of the second level is determined as the first time.
[0018] Optionally, determining the second time according to the time at which the first signal terminal outputs the level state change signal includes:
[0019] When the system under test switches from the third level to the fourth level, the end time of the third level or the start time of the fourth level is determined to be the second time, wherein the level state change signal is a signal representing the switch from the current third level to the fourth level.
[0020] Optionally, determining the fault handling time according to the first moment and the second moment includes:
[0021] A time difference between the first moment and the second moment is determined as the fault processing time.
[0022] Optionally, the functional safety testing method further includes:
[0023] When the fault signal is injected into the system under test, the fault is identified by the system under test and the safety mechanism is executed;
[0024] And / or, when the fault corresponding to the fault signal is eliminated, the level of the first signal terminal is reset by controlling the system under test.
[0025] In a second aspect, the present invention provides a functional safety detection device, comprising:
[0026] A first module is configured to respond to a fault signal injected into the system under test and determine a first time according to a time when the fault signal is injected;
[0027] a second module, configured to respond to a level state change signal outputted by a first signal terminal of the system under test and determine a second time according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers the start of a safety mechanism;
[0028] The third module is used to determine the fault processing time according to the first moment and the second moment.
[0029] In a third aspect, the present invention provides an electronic device comprising a memory and a processor;
[0030] The memory is used to store computer programs;
[0031] The processor is configured to implement the functional safety detection method as described in the first aspect when executing the computer program.
[0032] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the functional safety detection method as described in the first aspect is implemented.
[0033] The beneficial effects of the functional safety detection method of the present invention are: in response to a fault signal injected into the system under test, a first moment is determined according to the moment of fault signal injection; when the safety mechanism corresponding to the fault signal is activated, a level state change signal is generated and output to the first signal end; a second moment is determined according to the moment when the first signal end outputs the level state change signal, and the software behavior that cannot be physically measured in the relevant technology is converted into a physical behavior of measurable level state change, and then the fault processing time can be determined according to the first moment and the second moment, thereby achieving high-precision and interference-free fault processing time measurement. Since the fault processing time is an important indicator for measuring the time required for the system to detect, respond and complete processing after a fault occurs, by accurately measuring the fault processing time, it is possible to accurately evaluate whether the system meets the real-time requirements, and then accurately evaluate the functional safety of the system, ensuring that the system has sufficient time to handle the fault before the hazardous event occurs, so as to reduce the level of hazard to the operation of the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 Schematic diagram of the functional safety testing method according to an embodiment of the present invention;
[0035] Figure 2 A schematic diagram of a process for determining a first moment in an embodiment of the present invention;
[0036] Figure 3 A schematic diagram of a process for generating a fault signal according to an embodiment of the present invention;
[0037] Figure 4 Schematic diagram of the principle of the functional safety detection method according to an embodiment of the present invention;
[0038] Figure 5 Schematic diagram of the framework of a functional safety detection system according to an embodiment of the present invention;
[0039] Figure 6 Schematic diagram of the structure of a functional safety detection device according to an embodiment of the present invention;
[0040] Figure 7 Schematic diagram of the structure of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0041] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, specific embodiments of the present invention are described in detail below with reference to the accompanying drawings. Although certain embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as being limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.
[0042] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.
[0043] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to"; the term "based on" means "based at least in part on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc. mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0044] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0045] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0046] like Figure 1 As shown, an embodiment of the present invention provides a functional safety detection method, including:
[0047] S100: In response to a fault signal injected into a system under test, determining a first time according to a time when the fault signal is injected.
[0048] Specifically, during functional safety testing, a fault signal is injected into a normally operating device under test (DUT) to simulate the occurrence of a fault, and the moment of injection of the fault signal (ie, the first moment) is recorded.
[0049] S200: In response to a level state change signal output by a first signal terminal of the system under test, determine a second moment according to the moment when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and output to the first signal terminal when the fault signal triggers the start of a safety mechanism.
[0050] Specifically, after a fault signal is injected into the system under test, voltage anomalies and other conditions will occur. The built-in safety mechanism code of the system under test will process the voltage anomaly identified by the sampling program. The fault signal triggers the safety mechanism to start, generate a level state change signal and output it to the first signal terminal, and record the moment when the first signal terminal outputs the level state change signal (i.e., the second moment).
[0051] S300: Determine a fault processing time according to the first moment and the second moment.
[0052] Specifically, combined Figure 4 As shown, the fault processing time is determined by the time difference between the first moment and the second moment, for example, the fault processing time t=the second moment t(B)-the first moment t(A).
[0053] In this embodiment, in response to a fault signal injected into the system under test, a first moment is determined according to the moment when the fault signal is injected. When the safety mechanism corresponding to the fault signal is activated, a level state change signal is generated and output to the first signal terminal. The second moment is determined according to the moment when the level state change signal is output from the first signal terminal. The software behavior that cannot be physically measured in the related art is converted into a physical behavior of measurable level state change, and the fault processing time can be determined according to the first moment and the second moment, thereby achieving high-precision and interference-free fault processing time measurement. Since the fault processing time is an important indicator to measure the time required for the system to detect, respond and complete processing after a fault occurs, by accurately measuring the fault processing time, it is possible to accurately evaluate whether the system meets the real-time requirements, and then accurately evaluate the functional safety of the system, ensuring that the system has sufficient time to handle the fault before a hazardous event occurs, thereby reducing the level of hazard to vehicle operation.
[0054] Optionally, in response to a fault signal injected into the system under test, determining the first time according to a time when the fault signal is injected includes:
[0055] S110: Injecting a fault signal into the second signal terminal of the system under test through the fault generating system.
[0056] Specifically, combined Figure 2 and Figure 5 As shown, the fault generation system (or voltage fault injection system; such as a voltage source) is used to simulate a voltage fault in a circuit module, and injects a fault signal into the second signal terminal of the system under test (corresponding to the circuit module of the system under test) through the fault generation system.
[0057] Among them, combined Figure 5As shown, the system under test includes a microcontroller unit (MCU) and a circuit to be tested. The microcontroller unit (MCU) integrates sampling and filtering code (i.e., a program for sampling and filtering the circuit) and safety mechanism code (i.e., a software program for processing voltage anomalies identified by the sampling program).
[0058] S120: When it is detected that the fault signal triggers a level state change at the second signal terminal, determine the moment when the level state of the second signal terminal changes as the first moment.
[0059] Specifically, combined Figure 2 As shown, the fault signal triggers the second signal terminal to change its level state. At this time, the moment when the level state of the second signal terminal changes is the first moment.
[0060] In this optional embodiment, a fault signal is injected into the second signal end of the system under test through the fault generating system. When it is detected that the fault signal triggers a level state change at the second signal end, the moment when the level state changes at the second signal end is determined to be the first moment, thereby achieving accurate measurement of the first moment and accurately determining the fault processing time.
[0061] Optionally, before injecting a fault signal into the second signal terminal of the system under test through the fault generating system, the method further includes:
[0062] S101: defining a fault type and fault parameters through the fault generating system, wherein the fault type includes one of an undervoltage fault, an overvoltage fault, a voltage mutation fault, and a voltage fluctuation fault, and the fault parameters include at least one of a fault amplitude, a fault duration, and a fault triggering mode.
[0063] Specifically, combined Figure 3 As shown, before simulating a voltage fault through a fault generation system, the fault type and fault parameters are defined. For example, the fault type includes one of an undervoltage fault, an overvoltage fault, a voltage mutation fault, and a voltage fluctuation fault. The fault parameters include at least one of a fault amplitude (such as a voltage drop to 70% of the rated value or a rise to 130% of the rated value), a fault duration (a transient change as short as nanoseconds, or a voltage anomaly as long as seconds), and a fault triggering mode (such as a timing trigger, an external signal trigger, or a random trigger).
[0064] S102: Based on the fault type and the fault parameters, drive a voltage regulation circuit to simulate a voltage fault through the fault generation system to generate the fault signal.
[0065] Specifically, combined Figure 3As shown, taking undervoltage fault as an example, the fault generation system can drive a controllable resistor or a buck converter to reduce the output voltage, simulating an undervoltage fault and maintaining the set abnormal voltage state for a duration ranging from a few microseconds to several seconds.
[0066] In this optional embodiment, based on predefined fault types and fault parameters, the fault generation system drives the voltage regulation circuit to simulate a voltage fault and generate a fault signal, which can test the reliability of the functional safety of the system under test under different faults.
[0067] Optionally, determining the moment when the level state of the second signal terminal changes as the first moment includes:
[0068] When the fault signal triggers the level of the second signal end to switch from the first level to the second level, the end time of the first level or the start time of the second level is determined as the first time.
[0069] Specifically, taking an overvoltage fault as an example, when the level of the second signal terminal switches from a first level (eg, 3.3V) to a second level (4.5V), the end time of the first level or the start time of the second level may be used as the first moment.
[0070] In this optional embodiment, by taking the end time of the first level or the start time of the second level as the first time, accurate measurement of the first time is achieved, thereby accurately determining the fault processing time.
[0071] Optionally, determining the second time according to the time at which the first signal terminal outputs the level state change signal includes:
[0072] When the system under test switches from the third level to the fourth level, the end time of the third level or the start time of the fourth level is determined to be the second time, wherein the level state change signal is a signal representing the switch from the current third level to the fourth level.
[0073] Specifically, the GPIO (General-Purpose Input / Output) port of the system under test defaults to a high level (the third level, such as 3.3V or 5V). When a fault is detected, the level state changes and the GPIO becomes a low level (the fourth level, such as 0V). The end time of the third level or the start time of the fourth level can be used as the second moment.
[0074] In this optional embodiment, by taking the end time of the third level or the start time of the fourth level as the second time, accurate measurement of the second time is achieved, thereby accurately determining the fault processing time.
[0075] Optionally, determining the fault handling time according to the first moment and the second moment includes:
[0076] A time difference between the first moment and the second moment is determined as the fault processing time.
[0077] Specifically, the fault processing time represents the time interval from the occurrence of the fault (corresponding to the first moment) to the completion of the fault processing by the system (corresponding to the second moment), which can be obtained by Figure 5 The oscilloscope shown measures the time difference between two waveforms (eg, a waveform corresponding to the first level and a waveform corresponding to the fourth level) so that the measurement accuracy meets the millisecond or even nanosecond level, thereby accurately determining the fault processing time.
[0078] In this optional embodiment, the fault handling time is determined based on the time difference between the first moment and the second moment, for example, an oscilloscope measures the waveform time difference, so that the measurement accuracy meets the millisecond or even nanosecond level, thereby accurately determining the fault handling time.
[0079] Optionally, the functional safety testing method further includes:
[0080] When the fault signal is injected into the system under test, the fault is identified by the system under test and the safety mechanism is executed;
[0081] And / or, when the fault corresponding to the fault signal is eliminated, the level of the first signal terminal is reset by controlling the system under test.
[0082] Specifically, when a fault signal is injected into the system under test, the system under test executes a safety mechanism, such as entering a degraded mode (such as reducing the processor clock frequency) or starting a redundant system (such as switching to a backup power supply or a secondary processor). When the fault corresponding to the fault signal is eliminated, the level of the first signal end is reset.
[0083] In this optional embodiment, by setting a safety mechanism and level reset, it can be ensured that the system under test handles the fault in a timely manner and recovers to a safe state after the fault handling is completed, thereby avoiding or reducing potential safety risks.
[0084] like Figure 6 As shown, an embodiment of the present invention provides a functional safety detection device 600, including:
[0085] A first module 610 is configured to respond to a fault signal injected into the system under test and determine a first time according to a time when the fault signal is injected;
[0086] A second module 620 is configured to determine a second time in response to a level state change signal outputted by a first signal terminal of the system under test according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers activation of the safety mechanism;
[0087] The third module 630 is configured to determine a fault processing time according to the first moment and the second moment.
[0088] like Figure 7 As shown, an electronic device 700 provided by an embodiment of the present invention includes a memory 720 and a processor 710; the memory 720 is used to store computer programs; the processor 710 is used to implement the functional safety detection method as described above when executing the computer program.
[0089] In other words, an electronic device 700 includes a memory 720 and a processor 710 coupled to the memory 720; the memory 720 is configured to store a computer program; and the processor 710 is configured to perform the following operations when executing the computer program:
[0090] In response to a fault signal injected into the system under test, determining a first time according to a time when the fault signal is injected;
[0091] In response to a level state change signal outputted by a first signal terminal of the system under test, determining a second time according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers the activation of the safety mechanism;
[0092] A fault processing time is determined according to the first time and the second time.
[0093] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the functional safety detection method described above is implemented.
[0094] In other words, a non-volatile computer-readable storage medium stores a computer program, which, when executed by a processor, causes the processor to perform the following operations:
[0095] In response to a fault signal injected into the system under test, determining a first time according to a time when the fault signal is injected;
[0096] In response to a level state change signal outputted by a first signal terminal of the system under test, determining a second time according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers the activation of the safety mechanism;
[0097] A fault processing time is determined according to the first time and the second time.
[0098] An electronic device 700 that can serve as a server or client of the present invention will now be described, which is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device 700 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device 700 can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0099] The electronic device 700 includes a computing unit that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) or a computer program loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The computing unit, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.
[0100] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM). In this application, the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments of the present invention. In addition, the functional units in the various embodiments of the present invention can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into a single unit. The above-mentioned integrated units can be implemented in the form of hardware or software functional units.
[0101] Although the present invention is disclosed as above, the protection scope of the present invention is not limited thereto. Those skilled in the art may make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will fall within the protection scope of the present invention.
Claims
1. A functional safety testing method, characterized in that: include: In response to a fault signal injected into the system under test, determining a first time according to a time when the fault signal is injected; In response to a level state change signal outputted by a first signal terminal of the system under test, determining a second time according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers the activation of the safety mechanism; A fault processing time is determined according to the first time and the second time.
2. The functional safety testing method according to claim 1, characterized in that: In response to the fault signal injected into the system under test, determining the first time according to the time of injection of the fault signal comprises: injecting a fault signal into the second signal terminal of the system under test through a fault generating system; When it is detected that the fault signal triggers a level state change at the second signal terminal, the moment when the level state of the second signal terminal changes is determined to be the first moment.
3. The functional safety testing method according to claim 2, characterized in that: Before injecting a fault signal into the second signal terminal of the system under test through the fault generating system, the method further includes: defining a fault type and fault parameters by the fault generating system, wherein the fault type includes one of an undervoltage fault, an overvoltage fault, a voltage mutation fault, and a voltage fluctuation fault, and the fault parameters include at least one of a fault amplitude, a fault duration, and a fault triggering mode; Based on the fault type and the fault parameters, the fault generating system drives a voltage regulating circuit to simulate a voltage fault and generates the fault signal.
4. The functional safety testing method according to claim 2, characterized in that: The determining that the moment when the level state of the second signal terminal changes is the first moment includes: When the fault signal triggers the level of the second signal end to switch from the first level to the second level, the end time of the first level or the start time of the second level is determined as the first time.
5. The functional safety testing method according to claim 2, characterized in that: Determining the second time according to the time when the first signal terminal outputs the level state change signal includes: When the system under test switches from the third level to the fourth level, the end time of the third level or the start time of the fourth level is determined to be the second time, wherein the level state change signal is a signal representing the switch from the current third level to the fourth level.
6. The functional safety testing method according to claim 5, characterized in that: Determining the fault handling time according to the first moment and the second moment includes: A time difference between the first moment and the second moment is determined as the fault processing time.
7. The functional safety testing method according to any one of claims 1 to 6, characterized in that: The functional safety testing method further includes: When the fault signal is injected into the system under test, the fault is identified by the system under test and the safety mechanism is executed; And / or, when the fault corresponding to the fault signal is eliminated, the level of the first signal terminal is reset by controlling the system under test.
8. A functional safety testing device, characterized in that: include: A first module is configured to respond to a fault signal injected into the system under test and determine a first time according to a time when the fault signal is injected; a second module, configured to respond to a level state change signal outputted by a first signal terminal of the system under test and determine a second time according to a time when the first signal terminal outputs the level state change signal, wherein the level state change signal is generated and outputted to the first signal terminal when the fault signal triggers the start of a safety mechanism; The third module is used to determine the fault processing time according to the first moment and the second moment.
9. An electronic device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is configured to implement the functional safety testing method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by the processor, the functional safety detection method according to any one of claims 1 to 7 is implemented.