L3 intelligent driving system hardware architecture expected function safety hazard risk assessment method

By constructing a scenario-architecture mapping model and a risk quantification assessment model, the deficiencies in hazard identification and risk assessment in Level 3 autonomous driving systems are addressed, a closed-loop assessment from functional safety to architectural safety is achieved, the comprehensiveness of hazard identification and the accuracy of assessment are improved, and system design optimization is guided.

CN120670231APending Publication Date: 2025-09-19东风悦享科技有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510694682.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In existing technologies for Level 3 autonomous driving systems, hazard identification is not fully associated with the hardware architecture, risk assessment granularity is insufficient, and there is a lack of closed-loop optimization, resulting in a disconnect between scenarios and architecture, making it difficult to identify risk links and guide the design of hazard mitigation plans.

Method used

Build a scenario-architecture mapping model, identify and classify hazards through the hazard identification model, build a risk quantification assessment model for assessment, and optimize and iteratively evaluate the architecture through the quantitative assessment model. Introduce the Architecture Impact Factor (AIF) to achieve a closed-loop assessment from functional safety to architectural safety.

Benefits of technology

It improves the comprehensiveness of hazard identification and the accuracy of assessment, provides risk assessment at the system architecture level, guides system design optimization, and realizes a closed-loop assessment from functional safety to architectural safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120670231A_ABST
    Figure CN120670231A_ABST
Patent Text Reader

Abstract

The invention relates to an L3 intelligent driving system hardware architecture expected function safety hazard risk assessment method, and the method comprises the steps: M1, obtaining the data information of a typical scene and a system hardware architecture in the operation process of an L3 intelligent driving system, constructing a scene-architecture mapping model, and carrying out the representation of a mapping relation between each scene parameter and a hardware architecture assembly, obtaining data information of a mapping relationship between each scene parameter and the hardware architecture component; and M2, based on the data information of the mapping relationship between each scene parameter and the hardware architecture component, identifying and classifying the hazard by adopting an architecture-caused hazard identification model to obtain data information of the classification of the hazard caused by the architecture. According to the method, closed-loop assessment from function security to architecture security is realized, the comprehensiveness of hazard identification and the accuracy of assessment are improved, and assessment on a system architecture level in a hazard analysis and risk assessment process can be supplemented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent driving technology, and in particular to a method for assessing the expected functional safety hazard risks of an L3 intelligent driving system hardware architecture. Background Art

[0002] As autonomous driving technology evolves toward Level 3 (conditional autonomous driving), the system's perception, decision-making, and control capabilities for complex scenarios have significantly improved. However, intended functional safety issues (such as misidentification and misoperation) caused by system functional limitations or external scenario interference have become a major source of risk. When conducting hazard identification and analysis based on intended functional safety analysis methods, the focus is usually on functional-level hazard analysis. Hazard identification and judgment lacks consideration of the associated system architecture design, which can lead to the following issues during actual development and implementation:

[0003] (1) Disconnection between scenarios and architecture: Hazard identification is not fully associated with the hardware architecture (such as sensor layout and domain controller redundancy scheme design), making it difficult to identify risk links at the architectural level;

[0004] (2) Insufficient granularity in risk assessment: The standard approach assesses risk based solely on the probability of functional failure and does not specifically consider the impact of architectural design on risk links.

[0005] (3) Lack of closed-loop optimization: The design of hazard mitigation solutions cannot be guided by adjusting the architectural solution. Summary of the Invention

[0006] In view of the above problems, the present invention provides a method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system. It not only realizes a closed-loop assessment from functional safety to architectural safety, improves the comprehensiveness of hazard identification and the accuracy of assessment, but also supplements the assessment of the system architecture level during the hazard analysis and risk assessment process.

[0007] In order to achieve the above-mentioned and other related purposes, the present invention provides the following technical solutions:

[0008] A method for risk assessment of expected functional safety hazards of an L3 intelligent driving system hardware architecture, the method comprising:

[0009] M1. During the operation of the Level 3 intelligent driving system, obtain data information on typical scenarios and the system hardware architecture, construct a scenario-architecture mapping model to characterize the mapping relationship between each scenario parameter and the hardware architecture component, and obtain data information on the mapping relationship between each scenario parameter and the hardware architecture component;

[0010] M2. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, the architecture-induced hazard identification model is used to identify and classify hazards to obtain data information of the architecture-induced hazard classification;

[0011] M3. Based on the data information on the hazard classification caused by the architecture, construct a risk quantification assessment model to assess the risks caused by the architecture and obtain data information on the risk assessment value caused by the architecture;

[0012] M4. Based on the data information of the risk assessment value caused by the architecture, a quantitative assessment model is constructed to optimize and iteratively evaluate the architecture to obtain data information of the risk assessment of the system hardware architecture.

[0013] Furthermore, in step M1, the constructing of the scene-architecture mapping model to characterize the mapping relationship between each scene parameter and the hardware architecture component includes:

[0014] M11. Decompose the data information of the typical scene into a set of sub-scenes to obtain data information of the sub-scenes;

[0015] M12. Decompose the data information of the system hardware architecture into a three-level structure of hardware layer, software layer and communication layer to obtain the data information of the three-level structure of the system;

[0016] M13. Based on the data information of the three-level structure of the system and the data information of the sub-scene, establish a mapping function Q,

[0017] ,

[0018] Among them, x is the data information of the three-level structure of the system, y is the data information of the sub-scene, ɑ1, ɑ2 and ɑ3 are weight coefficients, which characterize the dependency relationship between each sub-scene parameter and the hardware architecture component, and obtain the data information of the mapping relationship between each scene parameter and the hardware architecture component.

[0019] Furthermore, the constraints of the weight coefficients ɑ1, ɑ2 and ɑ3 are:

[0020] .

[0021] Furthermore, the data information of the typical scenarios includes data information of highway entry and urban intersection scenarios, the set of sub-scenario includes parameter combinations of lighting conditions, traffic flow density and road sign clarity, the hardware layer includes perception components, domain controllers and actuators, the software layer includes perception algorithm modules and decision control planning modules, and the communication layer includes bus protocols and data transmission delays.

[0022] Furthermore, in step M2, identifying and classifying hazards using the architecture-induced hazard identification model includes:

[0023] M21. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, establish a risk point detection function W that causes the architecture to fail the scenario.

[0024] ,

[0025] Among them, z is the data information of the mapping relationship between each scenario parameter and the hardware architecture component, β1, β2 and β3 are the detection factors of the risk points of the architecture causing scenario failure. The risk points of the architecture are characterized to obtain the data information of the risk points of the architecture;

[0026] M22. Generate an architecture hazard scenario library based on the architecture risk point data and scenario parameters;

[0027] M23. Based on the architecture hazard scenario library, build a standard function R,

[0028] ,

[0029] Among them, h i is the i-th element in the architecture hazard scenario library, γ i The penalty factor is used to identify and classify hazards, and obtain data information on hazard classification caused by the architecture.

[0030] Furthermore, the detection factors β1, β2 and β3 of the risk point of scenario failure caused by the architecture are:

[0031] ,

[0032] ,

[0033] ,

[0034] Among them, z is the data information of the mapping relationship between each scene parameter and the hardware architecture component.

[0035] Furthermore, in step M3, the construction of a risk quantification assessment model to assess the risks caused by the architecture includes:

[0036] M31. Based on the data on the hazard classification caused by the architecture, introduce architectural impact factors to quantify the amplification or suppression effect of architectural design on risks.

[0037] M32. Risk assessment function G caused by building architecture,

[0038] G=P(H)×S×AIF,

[0039] Where P(H) is the probability of occurrence of the hazard scenario, S is the severity of the hazard, and AIF is the architecture impact factor;

[0040] M33. Based on the risk assessment function G caused by the architecture, the risk caused by the architecture is assessed to obtain data information of the risk assessment value caused by the architecture.

[0041] Furthermore, in step M4, constructing a quantitative evaluation model to optimize and iteratively evaluate the architecture includes:

[0042] M41. Based on the risk assessment data resulting from the architecture, propose architecture improvement plans for high-risk scenarios;

[0043] M42. Re-enter the optimized architecture into the quantitative assessment model to verify the risk reduction effect.

[0044] In order to achieve the above-mentioned objectives and other related objectives, the present invention also provides an L3 intelligent driving system hardware architecture expected functional safety hazard risk assessment system, including a computer device that is programmed or configured to execute any one of the steps of the L3 intelligent driving system hardware architecture expected functional safety hazard risk assessment method.

[0045] In order to achieve the above-mentioned objectives and other related objectives, the present invention also provides a computer-readable storage medium, which stores a computer program programmed or configured to execute any one of the methods for assessing the expected functional safety hazards of the hardware architecture of an L3 intelligent driving system.

[0046] The present invention has the following positive effects:

[0047] 1. The present invention characterizes the mapping relationship between each scenario parameter and the hardware architecture component by constructing a scenario-architecture mapping model, and identifies and classifies hazards in combination with the architecture-induced hazard identification model. Not only does it achieve full-link analysis from expected functional safety to hardware design through scenario-architecture mapping, but it also achieves a closed-loop assessment from functional safety to architectural safety by associating scenario analysis with system architecture design, thereby improving the comprehensiveness of hazard identification and the accuracy of assessment.

[0048] 2. This invention evaluates the risks caused by the architecture by constructing a risk quantification model, and combines this model with architecture optimization and iterative evaluation. This not only introduces the architectural impact quantification factor (AIF), avoiding the oversimplification of risks in traditional methods, but also allows for the traceability of the relationship between hazards and architectural components, providing a clear direction for system design optimization. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1Schematic diagram of the method flow of the present invention;

[0050] Figure 2 A schematic diagram of the process of constructing a scenario-architecture mapping model of the present invention;

[0051] Figure 3 A schematic diagram of the flow of the hazard identification model resulting from the architecture of the present invention;

[0052] Figure 4 A schematic diagram of the process of constructing a risk quantification assessment model of the present invention;

[0053] Figure 5 The figure is a flow chart of the construction of the quantitative evaluation model of the present invention. DETAILED DESCRIPTION

[0054] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0055] Example 1: Figure 1 As shown, a method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system is provided, the method comprising:

[0056] M1. During the operation of the Level 3 intelligent driving system, obtain data information on typical scenarios and the system hardware architecture, construct a scenario-architecture mapping model to characterize the mapping relationship between each scenario parameter and the hardware architecture component, and obtain data information on the mapping relationship between each scenario parameter and the hardware architecture component;

[0057] M2. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, the architecture-induced hazard identification model is used to identify and classify hazards to obtain data information of the architecture-induced hazard classification;

[0058] M3. Based on the data information on the hazard classification caused by the architecture, construct a risk quantification assessment model to assess the risks caused by the architecture and obtain data information on the risk assessment value caused by the architecture;

[0059] M4. Based on the data information of the risk assessment value caused by the architecture, a quantitative assessment model is constructed to optimize and iteratively evaluate the architecture to obtain data information of the risk assessment of the system hardware architecture.

[0060] In this embodiment, if Figure 2As shown, in step M1, the construction of the scene-architecture mapping model to characterize the mapping relationship between each scene parameter and the hardware architecture component includes:

[0061] M11. Decompose the data information of the typical scene into a set of sub-scenes to obtain data information of the sub-scenes;

[0062] M12. Decompose the data information of the system hardware architecture into a three-level structure of hardware layer, software layer and communication layer to obtain the data information of the three-level structure of the system;

[0063] M13. Based on the data information of the three-level structure of the system and the data information of the sub-scene, establish a mapping function Q,

[0064] ,

[0065] Among them, x is the data information of the three-level structure of the system, y is the data information of the sub-scene, ɑ1, ɑ2 and ɑ3 are weight coefficients, which characterize the dependency relationship between each sub-scene parameter and the hardware architecture component, and obtain the data information of the mapping relationship between each scene parameter and the hardware architecture component.

[0066] Furthermore, the constraints of the weight coefficients ɑ1, ɑ2 and ɑ3 are:

[0067] .

[0068] Furthermore, the data information of the typical scenarios includes data information of highway entry and urban intersection scenarios, the set of sub-scenario includes parameter combinations of lighting conditions, traffic flow density and road sign clarity, the hardware layer includes perception components, domain controllers and actuators, the software layer includes perception algorithm modules and decision control planning modules, and the communication layer includes bus protocols and data transmission delays.

[0069] In this embodiment, if Figure 3 As shown, in step M2, the use of the architecture-induced hazard identification model to identify and classify hazards includes:

[0070] M21. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, establish a risk point detection function W that causes the architecture to fail the scenario.

[0071] ,

[0072] Among them, z is the data information of the mapping relationship between each scenario parameter and the hardware architecture component, β1, β2 and β3 are the detection factors of the risk points of the architecture causing scenario failure. The risk points of the architecture are characterized to obtain the data information of the risk points of the architecture;

[0073] M22. Generate an architecture hazard scenario library based on the architecture risk point data and scenario parameters;

[0074] M23. Based on the architecture hazard scenario library, build a standard function R,

[0075] ,

[0076] Among them, h i is the i-th element in the architecture hazard scenario library, γ i The penalty factor is used to identify and classify hazards, and obtain data information on hazard classification caused by the architecture.

[0077] In this embodiment, the detection factors β1, β2 and β3 of the risk point of the architecture causing scenario failure are:

[0078] ,

[0079] ,

[0080] ,

[0081] Among them, z is the data information of the mapping relationship between each scene parameter and the hardware architecture component.

[0082] Example 2: Based on the method for risk assessment of expected functional safety hazards of an L3 intelligent driving system hardware architecture in Example 1, the present invention is further illustrated and described below.

[0083] like Figure 1 As shown, a method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system is provided, the method comprising:

[0084] M1. During the operation of the Level 3 intelligent driving system, obtain data information on typical scenarios and the system hardware architecture, construct a scenario-architecture mapping model to characterize the mapping relationship between each scenario parameter and the hardware architecture component, and obtain data information on the mapping relationship between each scenario parameter and the hardware architecture component;

[0085] M2. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, the architecture-induced hazard identification model is used to identify and classify hazards to obtain data information of the architecture-induced hazard classification;

[0086] M3. Based on the data information on the hazard classification caused by the architecture, construct a risk quantification assessment model to assess the risks caused by the architecture and obtain data information on the risk assessment value caused by the architecture;

[0087] M4. Based on the data information of the risk assessment value caused by the architecture, a quantitative assessment model is constructed to optimize and iteratively evaluate the architecture to obtain data information of the risk assessment of the system hardware architecture.

[0088] In this embodiment, if Figure 4 As shown, in step M3, the construction of a risk quantification assessment model to assess the risks caused by the architecture includes:

[0089] M31. Based on the data on the hazard classification caused by the architecture, introduce architectural impact factors to quantify the amplification or suppression effect of architectural design on risks.

[0090] M32. Risk assessment function G caused by building architecture,

[0091] G=P(H)×S×AIF,

[0092] Where P(H) is the probability of occurrence of the hazard scenario, S is the severity of the hazard, and AIF is the architecture impact factor;

[0093] M33. Based on the risk assessment function G caused by the architecture, the risk caused by the architecture is assessed to obtain data information of the risk assessment value caused by the architecture.

[0094] In this embodiment, if Figure 5 As shown, in step M4, the construction of a quantitative evaluation model to optimize and iteratively evaluate the architecture includes:

[0095] M41. Based on the risk assessment data resulting from the architecture, propose architecture improvement plans for high-risk scenarios;

[0096] M42. Re-enter the optimized architecture into the quantitative assessment model to verify the risk reduction effect.

[0097] In this embodiment, the risk assessment of the L3 autonomous driving system in the "tunnel entry and exit scenario" is taken as an example:

[0098] Scene decomposition: Define sub-scene parameters as "lighting mutation intensity", "lane line clarity", and "distance to the preceding vehicle";

[0099] Architecture mapping: Correlating camera exposure algorithm, image processing chip computing power, and lane detection module;

[0100] Hazard identification: Detects the hazard link where "strong light interference causing camera overexposure" may lead to "lane line misidentification";

[0101] Risk calculation: If P(H)=0.1, S=5, and AIF=1.2 (due to insufficient chip computing power leading to algorithm recovery delay), then R=0.6 (high risk);

[0102] Optimization solution: Increase HDR camera hardware redundancy and optimize the exposure control algorithm timing to reduce the AIF to 0.8 and the risk value to R = 0.4 (medium risk).

[0103] In this embodiment, the present invention provides a system for assessing the risk of safety hazards of expected functions of the hardware architecture of an L3 intelligent driving system, including a computer device that is programmed or configured to execute any one of the steps of the method for assessing the risk of safety hazards of expected functions of the hardware architecture of an L3 intelligent driving system.

[0104] In this embodiment, the present invention also provides a computer-readable storage medium, which stores a computer program programmed or configured to execute any one of the methods for assessing the expected functional safety hazard risks of the L3 intelligent driving system hardware architecture.

[0105] Any reference to memory, storage, database, or other medium used in the embodiments provided herein may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM).

[0106] In summary, the present invention not only achieves a closed-loop assessment from functional safety to architectural safety, improving the comprehensiveness of hazard identification and the accuracy of assessment, but also supplements the assessment of the system architecture level during hazard analysis and risk assessment.

[0107] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system, characterized by: The method comprises: M1. During the operation of the Level 3 intelligent driving system, obtain data information on typical scenarios and the system hardware architecture, construct a scenario-architecture mapping model to characterize the mapping relationship between each scenario parameter and the hardware architecture component, and obtain data information on the mapping relationship between each scenario parameter and the hardware architecture component; M2. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, the architecture-induced hazard identification model is used to identify and classify hazards to obtain data information of the architecture-induced hazard classification; M3. Based on the data information on the hazard classification caused by the architecture, construct a risk quantification assessment model to assess the risks caused by the architecture and obtain data information on the risk assessment value caused by the architecture; M4. Based on the data information of the risk assessment value caused by the architecture, a quantitative assessment model is constructed to optimize and iteratively evaluate the architecture to obtain data information of the risk assessment of the system hardware architecture.

2. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 1 is characterized in that: In step M1, the construction of the scene-architecture mapping model to characterize the mapping relationship between each scene parameter and the hardware architecture component includes: M11. Decompose the data information of the typical scene into a set of sub-scenes to obtain data information of the sub-scenes; M12. Decompose the data information of the system hardware architecture into a three-level structure of hardware layer, software layer and communication layer to obtain the data information of the three-level structure of the system; M13. Based on the data information of the three-level structure of the system and the data information of the sub-scene, establish a mapping function Q, , Among them, x is the data information of the three-level structure of the system, y is the data information of the sub-scene, ɑ1, ɑ2 and ɑ3 are weight coefficients, which characterize the dependency relationship between each sub-scene parameter and the hardware architecture component, and obtain the data information of the mapping relationship between each scene parameter and the hardware architecture component.

3. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 2 is characterized by: The constraints of the weight coefficients ɑ1, ɑ2 and ɑ3 are: 。 4. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 2 is characterized by: The data information of the typical scenarios includes data information of highway entry and urban intersection scenarios. The set of sub-scenarios includes a parameter combination of lighting conditions, traffic flow density and road sign clarity. The hardware layer includes perception components, domain controllers and actuators. The software layer includes a perception algorithm module and a decision control planning module. The communication layer includes a bus protocol and data transmission delay.

5. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 1 is characterized in that: In step M2, identifying and classifying hazards using the architecture-induced hazard identification model includes: M21. Based on the data information of the mapping relationship between each scenario parameter and the hardware architecture component, establish a risk point detection function W that causes the architecture to fail the scenario. , Among them, z is the data information of the mapping relationship between each scenario parameter and the hardware architecture component, β1, β2 and β3 are the detection factors of the risk points of the architecture causing scenario failure. The risk points of the architecture are characterized to obtain the data information of the risk points of the architecture; M22. Generate an architecture hazard scenario library based on the architecture risk point data and scenario parameters; M23. Based on the architecture hazard scenario library, build a standard function R, , Among them, h i is the i-th element in the architecture hazard scenario library, γ i The penalty factor is used to identify and classify hazards, and obtain data information on hazard classification caused by the architecture.

6. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 5 is characterized by: The detection factors β1, β2 and β3 of the risk point of scenario failure caused by the architecture are: , , , Among them, z is the data information of the mapping relationship between each scene parameter and the hardware architecture component.

7. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 1 is characterized in that: In step M3, the risk quantification assessment model is constructed to assess the risks caused by the architecture, including: M31. Based on the data on the hazard classification caused by the architecture, introduce architectural impact factors to quantify the amplification or suppression effect of architectural design on risks. M32. Risk assessment function G caused by building architecture, G=P(H)×S×AIF, Where P(H) is the probability of occurrence of the hazard scenario, S is the severity of the hazard, and AIF is the architecture impact factor; M33. Based on the risk assessment function G caused by the architecture, the risk caused by the architecture is assessed to obtain data information of the risk assessment value caused by the architecture.

8. The method for risk assessment of expected functional safety hazards of the hardware architecture of an L3 intelligent driving system according to claim 1 is characterized in that: In step M4, the construction of a quantitative evaluation model to optimize and iteratively evaluate the architecture includes: M41. Based on the risk assessment data resulting from the architecture, propose architecture improvement plans for high-risk scenarios; M42. Re-enter the optimized architecture into the quantitative assessment model to verify the risk reduction effect.

9. A system for assessing the expected functional safety hazards of the hardware architecture of an L3 intelligent driving system, comprising a computer device, characterized in that: The computer device is programmed or configured to execute the steps of the method for assessing the expected functional safety hazard risk of the hardware architecture of an L3 intelligent driving system as described in any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program that is programmed or configured to execute the L3 intelligent driving system hardware architecture expected functional safety hazard risk assessment method as described in any one of claims 1 to 8.