Vehicle function safety simulation analysis method, device and equipment and readable storage medium

By establishing a vehicle simulation model and injecting failure risks, identifying hazardous events, assessing the safety integrity level, and determining the design value of the fault tolerance time interval, the problem of inaccuracy caused by expert experience is solved, and the determination of the fault tolerance time interval and the precision of safety design are achieved quickly and accurately.

CN121723686APending Publication Date: 2026-03-24DONGFENG AUTOMOBILE COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-18
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, the determination and decomposition of fault tolerance time intervals mainly rely on expert experience, leading to inaccuracies in vehicle functional safety.

Method used

A vehicle simulation model is established, and failure risks are injected through a multi-scenario mechanical and electrical coupling failure risk model. Hazardous events are identified, severity levels and controllability are assessed, the vehicle safety integrity level is output, and the design value of the fault tolerance time interval is determined. Iterative optimization is carried out through simulation verification.

Benefits of technology

It enables rapid and accurate determination of fault tolerance time intervals, improves the development efficiency and effectiveness of vehicle functional safety, reduces the misjudgment rate, and ensures that safety design matches actual working conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121723686A_ABST
    Figure CN121723686A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle function safety simulation analysis method, device and equipment and a readable storage medium. The vehicle function safety simulation analysis method comprises the steps that a vehicle simulation model is established; injecting a failure risk through a multi-scene mechanical and electrical coupling failure risk model, and outputting an automobile safety integrity level of a hazardous event by evaluating a severity level, an exposure probability and controllability of the hazardous event; injecting a fault into the vehicle simulation model, and performing simulation verification to obtain a fault detection time interval, a diagnosis response time delay, a response instruction communication time delay, an execution mechanical response time delay, a test value of each decomposition item of a vehicle dynamics response margin, a test value of a fault tolerance time interval, and a fault coverage failure risk; and performing comparison verification on each design value and the test value so as to perform iterative optimization on the fault tolerance time interval and the design value of each decomposition item. According to the invention, the accuracy of determining and decomposing the fault tolerance time interval can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle safety technology, and in particular to a vehicle functional safety simulation analysis method, apparatus, equipment, and readable storage medium. Background Technology

[0002] Functional safety is a crucial consideration in the design of automotive electronic and electrical systems. When a safety-related fault occurs, effective measures must be taken within a reasonable time interval to ensure the safe operation or degradation of the system and avoid or mitigate potential harm to personnel. The Fault Tolerant Time Interval (FTTI) refers to the shortest time interval from the occurrence of an internal system fault to the potential occurrence of a hazardous event, assuming that safety mechanisms are not activated.

[0003] However, the determination and decomposition of fault tolerance time intervals currently rely mainly on expert experience, and inaccurate determination and decomposition of fault tolerance time intervals seriously affect the functional safety of vehicles. Summary of the Invention

[0004] This application provides a vehicle functional safety simulation analysis method, apparatus, equipment, and readable storage medium, aiming to solve the technical problem that the determination and decomposition of fault tolerance time intervals currently rely mainly on expert experience, and the inaccuracy in the determination and decomposition of fault tolerance time intervals seriously affects the functional safety of vehicles.

[0005] In a first aspect, embodiments of this application provide a vehicle functional safety simulation analysis method, the vehicle functional safety simulation analysis method comprising: A vehicle simulation model is established, which includes a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model. Failure risks are injected through a multi-scenario mechanical and electrical coupling failure risk model. Hazardous events are identified through a vehicle full-domain control interaction model, vehicle dynamics model, control and communication delay model, and traffic environment model. By assessing the severity level, exposure probability, and controllability of the hazardous events, the vehicle safety integrity level of the hazardous events is output. If the vehicle safety integrity level is greater than the preset level, then the safety target corresponding to the hazard event is determined, the design value of the fault tolerance time interval corresponding to the safety target is determined, and the design values ​​of each decomposed item, such as the fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, are obtained from the design value of the fault tolerance time interval. Faults are injected into the vehicle simulation model, and the test values ​​of each decomposition item of fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, vehicle dynamic response margin, and fault tolerance time interval are obtained through simulation verification, thereby covering the failure risk of the fault coverage. The design values ​​and test values ​​are compared and verified to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item.

[0006] Optionally, the vehicle functional safety simulation analysis method further includes: Faults were injected into the vehicle simulation model for different operating conditions, and the proportion of all operating conditions in which the design value of the fault tolerance time interval was less than the test value was verified by simulation. If the statistical proportion is greater than the preset proportion, the vehicle simulation model, safety target, fault tolerance time interval and design values ​​of each decomposition item are adjusted, and the simulation is re-verified until the statistical proportion is no greater than the preset proportion.

[0007] Optionally, the step of comparing and verifying the various design values ​​and test values ​​to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item includes: If the test value of each decomposition item is greater than the design value, then the design value of each decomposition item will be optimized and adjusted.

[0008] Optionally, if the test value of each decomposition item is greater than the design value, then optimizing and adjusting the design value of each decomposition item includes: If the test value of the fault detection time interval is greater than the design value, the fault detection algorithm will be adjusted. If the test value of the diagnostic response delay is greater than the design value, the priority of the fault response task will be adjusted. If the test value for the instruction communication latency is greater than the design value, adjust the communication configuration; If the test value of the mechanical response delay is greater than the design value, the actuator characteristic parameters should be adjusted.

[0009] Optionally, the design value of the fault detection time interval is greater than the basic time margin of the detection capability, the design value of the diagnostic response delay is greater than the fastest response threshold of the main controller's periodic scheduling, the design value of the response command communication delay is greater than the basic time margin of the communication delay, the design value of the execution mechanical response delay is greater than the lower limit of the physical response of the actuator, and the design value of the vehicle dynamic response margin is the lower limit of the vehicle dynamic characteristics.

[0010] Optionally, the step of comparing and verifying the various design values ​​and test values ​​to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item includes: Under the condition that the constraints are met, the design values ​​of each decomposition item are increased according to the preset step size, and the simulation verification is performed through the vehicle simulation model to output the range of design values ​​of each decomposition item. The constraint is that the sum of the design values ​​of each decomposition item is less than the design value of the fault tolerance time interval.

[0011] Secondly, embodiments of this application provide a vehicle functional safety simulation analysis device, the vehicle functional safety simulation analysis device comprising: A module is established to build a vehicle simulation model, which includes a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model. The hazard analysis module is used to inject failure risks through a multi-scenario mechanical and electrical coupling failure risk model, identify hazard events through a vehicle full-domain control interaction model, vehicle dynamics model, control and communication delay model, and traffic environment model, and output the vehicle safety integrity level of the hazard event by assessing the severity level, exposure probability, and controllability of the hazard event. The decomposition module is used to determine the safety target corresponding to the hazard event if the vehicle safety integrity level is greater than the preset level, determine the design value of the fault tolerance time interval corresponding to the safety target, and obtain the design values ​​of each decomposition item, such as fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, obtained by decomposing the design value of the fault tolerance time interval. The simulation verification module is used to inject faults into the vehicle simulation model and obtain test values ​​for each decomposed item of fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, vehicle dynamic response margin, and fault tolerance time interval through simulation verification, thereby covering the failure risk. The iterative optimization module is used to compare and verify various design values ​​and test values, so as to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item.

[0012] Optionally, the vehicle functional safety simulation analysis device further includes a multi-condition verification module, used for: Faults were injected into the vehicle simulation model for different operating conditions, and the proportion of all operating conditions in which the design value of the fault tolerance time interval was less than the test value was verified by simulation. If the statistical proportion is greater than the preset proportion, the vehicle simulation model, safety target, fault tolerance time interval and design values ​​of each decomposition item are adjusted, and the simulation is re-verified until the statistical proportion is no greater than the preset proportion.

[0013] Thirdly, embodiments of this application provide a vehicle functional safety simulation analysis device, which includes a processor, a memory, and a vehicle functional safety simulation analysis program stored in the memory and executable by the processor. When the vehicle functional safety simulation analysis program is executed by the processor, it implements the steps of the vehicle functional safety simulation analysis method as described above.

[0014] Fourthly, embodiments of this application provide a readable storage medium storing a vehicle functional safety simulation analysis program, wherein when the vehicle functional safety simulation analysis program is executed by a processor, it implements the steps of the vehicle functional safety simulation analysis method as described above.

[0015] The beneficial effects of the technical solutions provided in this application include: In this embodiment, a vehicle simulation model is established, comprising a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model. Failure risks are injected through the multi-scenario mechanical and electrical coupling failure risk model. Hazardous events are identified through the vehicle global control interaction model, vehicle dynamics model, control and communication delay model, and traffic environment model. The severity level, exposure probability, and controllability of the hazardous events are evaluated, and the vehicle safety integrity level of the hazardous event is output. If the vehicle safety integrity level is greater than a preset level, the safety target corresponding to the hazardous event is determined. The design value of the corresponding fault tolerance time interval is obtained, and the design values ​​of each decomposition item, including fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, are obtained from the design value of the fault tolerance time interval. Faults are injected into the vehicle simulation model, and the test values ​​of each decomposition item, including fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, as well as the test value of the fault tolerance time interval, are obtained through simulation verification. The fault coverage failure risk is then assessed. The design values ​​and test values ​​are compared and verified to iteratively optimize the design values ​​of the fault tolerance time interval and each decomposition item. Through the embodiments of this application, by establishing a comprehensive vehicle simulation model, in the hazard analysis phase, failure risks are injected to accurately identify hazardous events and assess the vehicle safety integrity level of the hazardous events. If the vehicle safety integrity level is high, it indicates that safety measures are needed to prevent the occurrence of hazardous events. Based on preset safety standards, the corresponding safety objectives and the corresponding design values ​​of fault tolerance time intervals, as well as the design values ​​of each decomposition item of the fault tolerance time interval, can be determined. Through automated quantitative assessment of failure risks, the fault tolerance time interval can be determined quickly and accurately. Then, in the simulation verification phase, by injecting faults that can cover failure scenarios, the vehicle simulation model outputs the fault tolerance time interval and the test values ​​of each decomposition item. The design values ​​and test values ​​are compared and verified, thereby enabling rapid iterative optimization of the design values ​​of the fault tolerance time interval and each decomposition item. This achieves an automated closed loop of simulation model - hazard analysis - safety design - determination and decomposition of fault tolerance time interval - simulation verification. More refined decomposition of the fault tolerance time interval can improve the accuracy of the fault tolerance time interval, and rapid simulation iterative optimization can improve the efficiency and effectiveness of vehicle functional safety development. Attached Figure Description

[0016] Figure 1 This is a flowchart illustrating an embodiment of the vehicle functional safety simulation analysis method of this application; Figure 2This is a schematic diagram of the vehicle full-domain control interaction model architecture of an embodiment of the vehicle functional safety simulation analysis method of this application; Figure 3 This is a schematic diagram of the FTTI decomposition principle of an embodiment of the vehicle functional safety simulation analysis method of this application; Figure 4 This is a schematic diagram of FTTI decomposition of an unexpected torque scenario according to an embodiment of the vehicle functional safety simulation analysis method of this application; Figure 5 This is a schematic diagram of the joint simulation verification platform architecture of an embodiment of the vehicle functional safety simulation analysis method of this application; Figure 6 This is a schematic diagram of the functional modules of an embodiment of the vehicle functional safety simulation analysis device of this application; Figure 7 This is a schematic diagram of the hardware structure of the vehicle functional safety simulation analysis equipment involved in the embodiments of this application. Detailed Implementation

[0017] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0019] In a first aspect, embodiments of this application provide a vehicle functional safety simulation analysis method.

[0020] In one embodiment, reference is made to Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the vehicle functional safety simulation analysis method of this application, as shown below. Figure 1 As shown, the vehicle functional safety simulation analysis method includes: Step S10: Establish a vehicle simulation model, which includes a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model.

[0021] In this embodiment, a comprehensive and high-precision vehicle simulation model is first established, referring to... Figure 2 , Figure 2 This is a schematic diagram of the vehicle full-domain control interaction model architecture of an embodiment of the vehicle functional safety simulation analysis method of this application, as shown below. Figure 2As shown, a vehicle-wide control interaction model can be constructed based on the electronic and electrical architecture of commercial vehicles (such as the interaction topology of the power domain controller PDCU, chassis domain Onebox, and energy domain MCU). This model digitally maps the sensor-controller-actuator link using a directed multigraph G=(V,E), where node V includes the accelerator pedal, brake master cylinder, and motor controller, and edge E defines attributes such as period / jitter / worst execution time (WCET) / bus period, forming a dynamic interaction matrix A. This synchronously reconstructs the time-domain response boundary conditions (e.g., the upper limit of braking command transmission delay is 20ms). The vehicle-wide control interaction model analyzes multi-source input signals such as accelerator pedal displacement gradient and brake master cylinder pressure changes to identify driving behavior feature maps in real time. Simultaneously, it integrates parameters such as the remaining charge status of the high-voltage battery and the thermal load of the drive motor. During vehicle operating mode transitions, it dynamically calculates the drive / braking torque distribution strategy and finally transmits the optimized torque command synchronously to the motor controller and integrated brake-by-wire system (Onebox) via a high-speed bus, achieving coordinated control and safety constraints across the entire power link. The vehicle dynamics model employs a multibody dynamics approach, with key parameters (mass m = 2.5 tons, wheelbase L = 3.2 m, braking limit a_max = 8 m / s², adhesion coefficient μ = 0.6) 100% matched to the actual vehicle bench calibration data. The control and communication delay model configures communication parameters based on the CAN bus protocol (transmission cycle 10 ms). The traffic environment model integrates dynamic elements such as road geometry (e.g., curve curvature 15 m), traffic signal phase (red light cycle 30 s), and pedestrian movement trajectory (speed 1.2 m / s). The multi-scenario mechanical and electrical coupling failure risk model targets typical operating conditions such as high-frequency start-stop in urban logistics (acceleration gradient > 3 m / s²) and intercity heavy-load uphill climbing (gradient > 8%), and pre-sets a fault mode library (e.g., sudden change in drive torque ± 20%, loss of steering assist 50%), achieving full coverage of failure scenarios from the system level to the vehicle level. By hierarchically modeling and dynamically reconstructing the electronic and electrical architecture, traditional static scenarios are transformed into quantifiable and reproducible digital twin environments. The constructed vehicle simulation model greatly improves simulation confidence. Compared with real vehicle testing, it significantly reduces scenario coverage costs and eliminates reliance on expert experience, providing an objective data basis for subsequent hazard analysis and supporting the accurate determination of ASIL level (Automotive Safety Integrity Level).

[0022] Step S20: Inject failure risks through a multi-scenario mechanical and electrical coupling failure risk model; identify hazardous events through a vehicle full-domain control interaction model, vehicle dynamics model, control and communication delay model, and traffic environment model; and output the vehicle safety integrity level of the hazardous event by assessing its severity level, exposure probability, and controllability.

[0023] In this embodiment, during the hazard analysis phase, taking the parking condition at a transportation hub (a densely populated pedestrian area with a high probability of exposure) as an example, the risk of abnormal failure of the drive torque command of the PDCU (Power Domain Controller) is injected into the multi-scenario mechanical and electrical coupling failure risk model (amplitude +15%). The vehicle's full-domain control interaction model analyzes the fault propagation path (PDCU (Power Domain Controller) → Onebox (Integrated Brake Controller)), the vehicle dynamics model calculates the vehicle's forward lurch distance (0.3m) and collision speed (1.2m / s), and the traffic environment model dynamically simulates the pedestrian's position (1.5m from the vehicle, with the direction of movement intersecting the vehicle's trajectory). Based on the ISO 26262 standard, the following quantitative assessments can be performed: Severity level S=3 (collision energy corresponds to moderate injury, due to the pedestrian's mass of 50kg and vehicle speed <5km / h), Exposure probability E=4 (traffic density >30veh / km, high fault triggering frequency), Controllability C=2 (driver's reaction time >1.5s, low feasibility of braking intervention), and the vehicle safety integrity level is automatically output as ASIL B. By upgrading hazard analysis from subjective experience to objective data-driven approaches, and through dynamic calculations of vehicle-environment interactions (e.g., collision energy = 0.5 × m × v²), the system automates the mapping of vehicle safety integrity levels (severity level S, probability of exposure E, and controllability C), providing quantifiable engineering basis for defining safety objectives. Furthermore, the system rapidly incorporates various failure risks through multi-scenario mechanical and electrical coupling failure risk models, quickly improving HARA (Hazard Analysis and Risk Assessment) coverage and reducing false positive rates.

[0024] Step S30: If the vehicle safety integrity level is greater than the preset level, then determine the safety target corresponding to the hazard event, determine the design value of the fault tolerance time interval corresponding to the safety target, and obtain the design values ​​of each decomposed item, such as the fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, obtained by decomposing the design value of the fault tolerance time interval.

[0025] In this embodiment, for example, when the ASIL level (e.g., Level B) is higher than the preset level (Level A), the corresponding safety objective can be automatically determined as "preventing driving force output without driving intent" based on the preset safety standard. The design value of the corresponding Fault Tolerance Time Interval (FTTI) is automatically determined, for example, to be 300ms. The design values ​​of the Fault Detection Time Interval (FDTI), obtained from the FTTI (e.g., 300ms), are also obtained: FDTI (e.g., 50ms), Diagnostic Response Delay (t1), Response Command Communication Delay (t2), Execution Mechanical Response Delay (t3), Execution Mechanical Response Delay (t3), and Vehicle Dynamics Response Margin (t_dyn), t_dyn, are obtained, satisfying the constraint FDTI + t1 + t2 + t3 + t_dyn = The design value of FTTI is 300ms. This automatically determined design value must be less than the test value of FTTI output by the vehicle simulation model during the hazard analysis phase. The test value of FTTI is the difference between the collision trigger time (th) and the fault occurrence time (tf) output by the vehicle simulation model. For example, in a traffic hub scenario, th = 1.8s and tf = 0.3s, then the test value of FTTI = th - tf = 1.8s - 0.3s = 1500ms. The FTTI decomposition process strictly follows the principle of "dynamic coupling of fault propagation paths," quantifying the impact of system-level failures (such as the interaction between braking and power domains) and incorporating them into the time chain. This avoids the inaccuracy in timing caused by neglecting multi-domain coordination, a problem inherent in traditional methods. Furthermore, fine-grained decomposition improves the allocation accuracy of FTTI, ensuring dynamic matching between safety mechanisms and actual operating conditions, reducing the design deviation rate of safety targets, and enhancing the credibility of functional safety development.

[0026] Reference Figure 3 , Figure 3 This is a schematic diagram of the FTTI decomposition principle of an embodiment of the vehicle functional safety simulation analysis method of this application, as shown below. Figure 3 As shown, the core principle that the Fault Handling Time Interval (FHTI) must be shorter than the Fault Tolerance Time Interval (FTTI) must be strictly followed during the safety mechanism design process. The system must fully execute the fault identification, safety protection activation, and vehicle state stabilization processes within the time frame specified by the FTTI, thereby achieving a safe state transition before a dangerous condition occurs. (Refer to...) Figure 4 , Figure 4 This is a schematic diagram of FTTI decomposition for an unexpected torque scenario in an embodiment of the vehicle functional safety simulation analysis method of this application, as shown below. Figure 4As shown, taking an unexpected torque scenario as an example, the system needs to complete the entire process control within the FTTI time threshold when the vehicle collides with the obstacle. The Fault Handling Time Interval (FHTI) represents the entire time from the triggering of torque anomaly to the system achieving vehicle steady state through safety mechanisms. The FFDTI corresponds to the detection period from the occurrence of torque fault to the PDCU completing fault identification based on acceleration verification. The FRTI is defined as the response period from the PDCU confirming the anomaly to the Onebox executing the braking strategy to bring the vehicle to a safe state. Based on the system's hierarchical interaction characteristics, the FRTI can be refined into a three-tiered operation chain: t1, the stage from PDCU fault diagnosis to braking command generation; t2, the communication delay t2 for the control command to be transmitted to the Onebox via the vehicle network; t3, the stage t3 where the Onebox drives the mechanical braking mechanism to achieve deceleration establishment; and t4, the system needs to reserve a dynamic response margin t4 from braking effectiveness to the vehicle coming to a complete stop, ensuring the achievement of safety goals.

[0027] Step S40: Inject faults into the vehicle simulation model, and obtain test values ​​for each decomposed item of fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, vehicle dynamic response margin, and fault tolerance time interval through simulation verification, thereby covering the failure risk of the fault.

[0028] In this embodiment, refer to Figure 5 , Figure 5 This is a schematic diagram of the joint simulation verification platform architecture of an embodiment of the vehicle functional safety simulation analysis method of this application, as shown below. Figure 5As shown, in the simulation verification phase, the injected fault needs to be able to trigger the failure risk in step S20, so as to perform corresponding simulation verification for the safety objectives, fault detection time intervals and design values ​​of each decomposition item determined in step S30. For example, for the rapid acceleration condition of urban logistics (such as the vehicle speed accelerating from 0 to 30km / h), an unexpected driving torque fault (amplitude +25%) is injected into the vehicle simulation model. The simulation platform runs iteratively with a uniform time step of 10ms: the vehicle dynamics model outputs real-time speed / acceleration data (v(t)), the controller and communication model record the PDCU fault detection time (FDTI test value 45ms), t1 (fault confirmation to command generation 75ms), t2 (CAN bus transmission 15ms); the fault injection model triggers the Onebox mechanical response, and the actuator model feeds back t3 (braking force establishment 48ms); the vehicle dynamics module dynamically calculates t_dyn (braking to standstill 95ms); the FTTI test value is generated in real time as 1450ms through the collision event trigger condition H(x,t) (such as v_real(t)>v_lim and the positions overlap). By utilizing the "virtual-physical hybrid verification" mechanism of the co-simulation platform, the spatiotemporal coupling effect of electronic control signal propagation (t2) and mechanical execution dynamics (t3) is analyzed simultaneously (such as response delay caused by signal jitter), replacing the static testing of the traditional rotating drum test bench, effectively improving the credibility of vehicle functional safety design.

[0029] Step S50: Compare and verify the various design values ​​and test values ​​to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item.

[0030] In this embodiment, by comparing various design values ​​and test values, the system verifies whether the design value of the fault tolerance time interval can meet the safety objectives and whether the design values ​​of each decomposition item are reasonable. This allows for iterative optimization by adjusting the design values ​​of the fault tolerance time interval and each decomposition item. For example, by comparing the design value (FDTI=50ms, t1=80ms, t2=20ms, t3=50ms, t_dyn=100ms) with the test value output by the vehicle simulation model (FDTI=45ms, t1=75ms, t2=15ms, t3=48ms, t_dyn=95ms), if the test value of a certain decomposition item is greater than the design value, it indicates that the decomposition item needs targeted optimization. If the test value FTTI=1450ms output by the vehicle simulation model is greater than the design value of FTTI, it indicates that the design value of FTTI meets the safety requirements. The system automatically outputs a verification pass report and records the delay of each step. If, under continuous braking conditions in mountainous areas (8% gradient, 3-ton load), the FDTI test value of 120ms > the design value of 50ms, then an iteration is triggered: adjust the fault detection algorithm (e.g., introduce Kalman filtering to improve signal verification speed), and after resimulation, the FDTI test value decreases to 95ms, then the design value of FDTI can be adjusted to 95ms. Based on the "time link closed-loop verification" mechanism, the difference between the design value and the test value is transformed into optimization input, and a closed loop of "model-decomposition-simulation" is achieved through dynamic feedback of time-series parameters.

[0031] In this embodiment, through hierarchical modeling and dynamic boundary reconstruction of the electronic and electrical architecture, traditional static scenarios are transformed into quantifiable and reproducible digital twin environments. The constructed vehicle simulation model significantly improves simulation confidence, significantly reduces scenario coverage costs and eliminates reliance on expert experience compared to real vehicle testing, providing an objective data foundation for subsequent hazard analysis and supporting accurate determination of ASIL (Automotive Safety Integrity Level). By upgrading hazard analysis from subjective experience to objective data-driven approaches, and through dynamic calculations of vehicle-environment interaction (e.g., collision energy = 0.5 × m × v²), the automated mapping of automotive safety integrity levels (severity level S, exposure probability E, controllability C) is achieved, providing quantifiable engineering basis for safety target definition. The multi-scenario mechanical and electrical coupling failure risk model can quickly inject various failure risks, rapidly improving HARA (Hazard Analysis and Risk Assessment) coverage and reducing misjudgment rates. The FTTI decomposition process strictly adheres to the principle of "dynamic coupling of fault propagation paths," quantifying the impact of system-level failures (such as the interaction between braking and power domains) and incorporating them into the time link. This avoids the "ignoring of multi-domain coordination leading to timing inaccuracies" common in traditional methods. Furthermore, fine-grained decomposition improves the allocation accuracy of FTTI, ensuring dynamic matching between safety mechanisms and actual operating conditions, reducing the design deviation rate of safety targets, and enhancing the credibility of functional safety development. Utilizing the "virtual-physical hybrid verification" mechanism of the co-simulation platform, the spatiotemporal coupling effect of electronic control signal propagation (t2) and mechanical execution dynamics (t3) is simultaneously analyzed (e.g., response delay caused by signal jitter), replacing the static testing of traditional rotary test benches and effectively improving the credibility of vehicle functional safety design. By comparing various design values ​​and test values, the design value of the fault tolerance time interval is verified to meet the safety objectives, and the design values ​​of each decomposition item are verified to be reasonable. This allows for iterative optimization by adjusting the fault tolerance time interval and the design values ​​of each decomposition item. Based on the "time link closed-loop verification" mechanism, the difference between design values ​​and test values ​​is transformed into optimization input, achieving a closed loop of "model-decomposition-simulation" through dynamic feedback of timing parameters.

[0032] Furthermore, in one embodiment, the vehicle functional safety simulation analysis method further includes: Faults were injected into the vehicle simulation model for different operating conditions, and the proportion of all operating conditions in which the design value of the fault tolerance time interval was less than the test value was verified by simulation. If the statistical proportion is greater than the preset proportion, the vehicle simulation model, safety target, fault tolerance time interval and design values ​​of each decomposition item are adjusted, and the simulation is re-verified until the statistical proportion is no greater than the preset proportion.

[0033] In this embodiment, for example, for five typical working conditions including urban roads (congestion rate > 40%), highways (vehicle speed > 80 km / h), mountain roads (gradient > 8%), rural roads (many blind spots), and bad weather (visibility < 50 m), three fault modes are injected for each type (a total of 15 groups of combinations). The proportion of the FTTI design value (300 ms) less than the FTTI test value is statistically calculated. If in 15 groups of simulations, 3 groups of working conditions (such as mountain climbing) show FTTI_design < FTTI_test, with a proportion of 20%, which is lower than the preset proportion of 30% (set based on enterprise safety standards), the system determines that no optimization is required. If the proportion reaches 40%, the FTTI_design can be adjusted to 350 ms, and the safety target can be optimized (such as increasing the braking priority weight). After re-verification, the proportion drops to 15% < 30%, meeting the requirements. By covering "extreme boundary conditions" through batch simulations of multiple working conditions and ensuring the robustness of safety design with statistical probability, the leap from "single-point verification" to "global coverage" of safety design is achieved, enabling the determination and decomposition scheme of FTTI to meet requirements under most working conditions, significantly reducing the risk of false alarms of functional safety of mass-produced products, and enhancing market competitiveness.

[0034] Further, in one embodiment, step S50 includes: If the test value of each decomposition item is greater than the design value, optimize and adjust the design value of each decomposition item.

[0035] In this embodiment, when the test value of a certain decomposition item is greater than the design value, it indicates that this decomposition item needs to be optimized and adjusted specifically. The optimization of decomposition items is related to system physical characteristics and software design, etc. Through "problem positioning - precise optimization - rapid iterative optimization", ineffective adjustments can be avoided, and an FDTI decomposition scheme that meets safety requirements can be designed quickly.

[0036] Further, in one embodiment, the "if the test value of each decomposition item is greater than the design value, optimize and adjust the design value of each decomposition item" includes: If the test value of the fault detection time interval is greater than the design value, adjust the fault detection algorithm; If the test value of the diagnostic response delay is greater than the design value, adjust the priority of the fault response task; If the test value of the response command communication delay is greater than the design value, adjust the communication configuration; If the test value of the execution mechanical response delay is greater than the design value, adjust the characteristic parameters of the actuator.

[0037] In this embodiment, for example, when the Fault Detection Time Interval (FDTI) test value (120ms) is greater than the design value (50ms), the fault detection mechanism is optimized by introducing a real-time signal cross-validation algorithm based on deep learning, reducing the diagnosis time from 120ms to within 50ms; when the diagnostic response delay (t1) test value (90ms) is greater than the design value (80ms), the main controller task scheduling priority is adjusted, dynamically promoting the braking diagnostic task from low priority to the highest priority, shortening the decision delay by 10ms; when the response command communication delay (t2) test value (25ms) is greater than the design value (20ms), the CAN bus communication configuration is optimized (e.g., reducing the bus load rate from 70% to 60%), reducing network jitter by 5ms; when the mechanical response delay (t3) test value (60ms) is greater than the design value (50ms), the Onebox actuator drive circuit response threshold is adjusted (e.g., optimizing the voltage trigger threshold from 12V to 10V), reducing the mechanical delay from 60ms to 48ms. The optimization of decomposition items strictly follows the coupling relationship of "physical characteristics-timing constraints". The optimization of fault detection algorithm depends on the noise characteristics of sensors (the theoretical detection limit is 10ms at a sampling frequency of 100Hz). The task priority adjustment is based on the dynamic allocation model of controller computing power (PDCU real-time task scheduling queue analysis). The communication configuration optimization comes from the bus protocol jitter distribution statistics (CAN standard jitter 10ms). The adjustment of actuator parameters matches the physical response curve of mechanical actuators (such as the nonlinear relationship between the response time and voltage of solenoid valves). The optimization is achieved through the closed loop of "test value deviation positioning - precise physical mechanism adaptation", avoiding the defects of "blindly increasing design values ​​leading to resource waste" in traditional methods.

[0038] Furthermore, in one embodiment, the design value of the fault detection time interval is greater than the basic time margin of the detection capability, the design value of the diagnostic response delay is greater than the fastest response threshold of the main controller's periodic scheduling, the design value of the response instruction communication delay is greater than the basic time margin of the communication delay, the design value of the execution mechanical response delay is greater than the lower limit of the physical response of the actuator, and the design value of the vehicle dynamics response margin is the lower limit of the vehicle dynamics characteristics.

[0039] In this embodiment, the designed value of FDTI is 50 ms > the basic time margin of detection ability of 10 ms (the theoretical lower limit based on the sensor sampling frequency of 100 Hz), ensuring that diagnosis can still be completed under signal noise interference; the designed value of the response delay t1 for diagnosis is 80 ms > the fastest response threshold of 50 ms for the main controller cycle scheduling (based on the measured value of the PDCU computing power), avoiding task scheduling conflicts; the designed value of the response delay t2 for coping with instructions is 20 ms > the basic time margin of communication delay of 10 ms (the standard jitter of the CAN bus protocol is 10 ms), adapting to network fluctuations; the designed value of the mechanical response delay t3 for execution is 50 ms > the lower physical response limit value of the actuator of 40 ms (based on the measured data of the mechanical actuation delay of Onebox), ensuring braking redundancy; the designed margin of vehicle dynamic response t_dyn is 100 ms > the lower limit value of vehicle dynamic characteristics of 80 ms (based on the braking distance model d = 0.5 × a_max × t_dyn²), covering vehicle mass fluctuations (±0.5 tons) and changes in adhesion coefficient (μ = 0.4 - 0.8). All designed values are set within the engineering safety boundary, and by quantitative constraints (such as t_dyn > 80 ms), over-tight design is avoided; this constraint system enables the safety design to remain effective under extreme working conditions (such as μ = 0.4 on a wet and slippery road surface), eliminates the risk of "disconnection between time margin calculation and reality", improves the engineering applicability of the functional safety scheme, and reduces the vehicle-level failure rate.

[0040] Further, in one embodiment, step S50 includes: Under the condition of meeting the constraint conditions, the designed values of each decomposition item are increased respectively according to a preset step size, and simulation verification iteration is carried out through a vehicle simulation model, and the designed value ranges of each decomposition item are output, where the constraint condition is that the sum of the designed values of each decomposition item is less than the designed value of the fault tolerance time interval.

[0041] In this embodiment, the designed value ranges of each decomposition item are output. Taking the mechanical response delay t3 for execution as an example, under the condition that the designed values of each decomposition item meet the constraint conditions (FDTI + t1 + t2 + t3 + t_dyn < FTTI), the designed value of t3 is iteratively increased in steps of 10 ms: such as t3 from 50 ms → 60 ms → 70 ms, and simulation verification is carried out again for each step. The optimized range of the designed value of t3 is output as 50 - 60 ms. By parameter scanning (preset step size of 10 ms), the optimal margin is found within the safety boundary, avoiding resource waste caused by blindly increasing the designed value, thereby realizing the automatic optimization of FTTI decomposition.

[0042] In a second aspect, the embodiments of the present application further provide a vehicle functional safety simulation analysis device.

[0043] In one embodiment, referring to Figure 6 , Figure 6This is a functional module diagram of an embodiment of the vehicle functional safety simulation analysis device of this application, as shown below. Figure 6 As shown, the vehicle functional safety simulation analysis device includes: Module 10 is used to establish a vehicle simulation model, which includes a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model. The hazard analysis module 20 is used to inject failure risks through a multi-scenario mechanical and electrical coupling failure risk model, identify hazard events through a vehicle full-domain control interaction model, a vehicle dynamics model, a control and communication delay model, and a traffic environment model, and output the vehicle safety integrity level of the hazard event by assessing the severity level, exposure probability, and controllability of the hazard event. The decomposition module 30 is used to determine the safety target corresponding to the hazard event if the vehicle safety integrity level is greater than the preset level, determine the design value of the fault tolerance time interval corresponding to the safety target, and obtain the design values ​​of each decomposition item, such as the fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, obtained by decomposing the design value of the fault tolerance time interval. The simulation verification module 40 is used to inject faults into the vehicle simulation model and obtain test values ​​of each decomposed item of fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, vehicle dynamic response margin, and fault tolerance time interval through simulation verification, thereby covering the failure risk. The iterative optimization module 50 is used to compare and verify the various design values ​​and test values, so as to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item.

[0044] Furthermore, in one embodiment, the vehicle functional safety simulation analysis device further includes a multi-condition verification module, used for: Faults were injected into the vehicle simulation model for different operating conditions, and the proportion of all operating conditions in which the design value of the fault tolerance time interval was less than the test value was verified by simulation. If the statistical proportion is greater than the preset proportion, the vehicle simulation model, safety target, fault tolerance time interval and design values ​​of each decomposition item are adjusted, and the simulation is re-verified until the statistical proportion is no greater than the preset proportion.

[0045] Furthermore, in one embodiment, the iterative optimization module 50 includes an iterative optimization unit, used for: If the test value of each decomposition item is greater than the design value, then the design value of each decomposition item will be optimized and adjusted.

[0046] Furthermore, in one embodiment, the iterative optimization unit is used for: If the test value of the fault detection time interval is greater than the design value, the fault detection algorithm will be adjusted. If the test value of the diagnostic response delay is greater than the design value, the priority of the fault response task will be adjusted. If the test value for the instruction communication latency is greater than the design value, adjust the communication configuration; If the test value of the mechanical response delay is greater than the design value, the actuator characteristic parameters should be adjusted.

[0047] Furthermore, in one embodiment, the design value of the fault detection time interval is greater than the basic time margin of the detection capability, the design value of the diagnostic response delay is greater than the fastest response threshold of the main controller's periodic scheduling, the design value of the response instruction communication delay is greater than the basic time margin of the communication delay, the design value of the execution mechanical response delay is greater than the lower limit of the physical response of the actuator, and the design value of the vehicle dynamics response margin is the lower limit of the vehicle dynamics characteristics.

[0048] Furthermore, in one embodiment, the iterative optimization module 50 is used for: Under the condition that the constraints are met, the design values ​​of each decomposition item are increased according to the preset step size, and the simulation verification is performed through the vehicle simulation model to output the range of design values ​​of each decomposition item. The constraint is that the sum of the design values ​​of each decomposition item is less than the design value of the fault tolerance time interval.

[0049] The functions of each module in the above-mentioned vehicle functional safety simulation analysis device correspond to the steps in the above-mentioned vehicle functional safety simulation analysis method embodiment, and their functions and implementation processes will not be described in detail here.

[0050] Thirdly, embodiments of this application provide a vehicle functional safety simulation analysis device.

[0051] Reference Figure 7 , Figure 7 This is a schematic diagram of the hardware structure of the vehicle functional safety simulation analysis device involved in the embodiments of this application. In this embodiment, the vehicle functional safety simulation analysis device may include a processor, a memory, a communication interface, and a communication bus.

[0052] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.

[0053] The communication interface includes input / output (I / O) interfaces, physical interfaces, and logical interfaces used for interconnecting components within the vehicle functional safety simulation analysis equipment, as well as interfaces used for interconnecting the vehicle functional safety simulation analysis equipment with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.

[0054] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0055] The processor can be a general-purpose processor, which can call the vehicle functional safety simulation analysis program stored in the memory and execute the vehicle functional safety simulation analysis method provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the vehicle functional safety simulation analysis program is called can be referred to in the various embodiments of the vehicle functional safety simulation analysis method of this application, and will not be repeated here.

[0056] Those skilled in the art will understand that Figure 7 The hardware structure shown does not constitute a limitation of this application and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0057] Fourthly, embodiments of this application also provide a readable storage medium.

[0058] The present application has a readable storage medium storing a vehicle functional safety simulation analysis program, wherein when the vehicle functional safety simulation analysis program is executed by a processor, it implements the steps of the vehicle functional safety simulation analysis method described above.

[0059] The method implemented when the vehicle functional safety simulation analysis program is executed can be referred to in various embodiments of the vehicle functional safety simulation analysis method of this application, and will not be repeated here.

[0060] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0061] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.

[0062] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.

[0063] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.

[0064] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.

[0065] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.

[0066] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A vehicle functional safety simulation analysis method, characterized in that, The vehicle functional safety simulation analysis method includes: A vehicle simulation model is established, which includes a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model. Failure risks are injected through a multi-scenario mechanical and electrical coupling failure risk model. Hazardous events are identified through a vehicle full-domain control interaction model, vehicle dynamics model, control and communication delay model, and traffic environment model. By assessing the severity level, exposure probability, and controllability of the hazardous events, the vehicle safety integrity level of the hazardous events is output. If the vehicle safety integrity level is greater than the preset level, then the safety target corresponding to the hazard event is determined, the design value of the fault tolerance time interval corresponding to the safety target is determined, and the design values ​​of each decomposed item, such as the fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, are obtained from the design value of the fault tolerance time interval. Faults are injected into the vehicle simulation model, and the test values ​​of each decomposition item of fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, vehicle dynamic response margin, and fault tolerance time interval are obtained through simulation verification, thereby covering the failure risk of the fault coverage. The design values ​​and test values ​​are compared and verified to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item.

2. The vehicle functional safety simulation analysis method as described in claim 1, characterized in that, The vehicle functional safety simulation analysis method also includes: Faults were injected into the vehicle simulation model for different operating conditions, and the proportion of all operating conditions in which the design value of the fault tolerance time interval was less than the test value was verified by simulation. If the statistical proportion is greater than the preset proportion, the vehicle simulation model, safety target, fault tolerance time interval and design values ​​of each decomposition item are adjusted, and the simulation is re-verified until the statistical proportion is no greater than the preset proportion.

3. The vehicle functional safety simulation analysis method as described in claim 1, characterized in that, The step of comparing and verifying various design values ​​and test values ​​to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item includes: If the test value of each decomposition item is greater than the design value, then the design value of each decomposition item will be optimized and adjusted.

4. The vehicle functional safety simulation analysis method as described in claim 3, characterized in that, If the test value of each decomposition item is greater than the design value, then optimizing and adjusting the design value of each decomposition item includes: If the test value of the fault detection time interval is greater than the design value, the fault detection algorithm will be adjusted. If the test value of the diagnostic response delay is greater than the design value, the priority of the fault response task will be adjusted. If the test value for the instruction communication latency is greater than the design value, adjust the communication configuration; If the test value of the mechanical response delay is greater than the design value, the actuator characteristic parameters should be adjusted.

5. The vehicle functional safety simulation analysis method as described in claim 1, characterized in that, The design value of the fault detection time interval is greater than the basic time margin of the detection capability; the design value of the diagnostic response delay is greater than the fastest response threshold of the main controller's periodic scheduling; the design value of the response command communication delay is greater than the basic time margin of the communication delay; the design value of the execution mechanical response delay is greater than the lower limit of the physical response of the actuator; and the design value of the vehicle dynamics response margin is the lower limit of the vehicle dynamics characteristics.

6. The vehicle functional safety simulation analysis method as described in claim 5, characterized in that, The step of comparing and verifying various design values ​​and test values ​​to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item includes: Under the condition that the constraints are met, the design values ​​of each decomposition item are increased according to the preset step size, and the simulation verification is performed through the vehicle simulation model to output the range of design values ​​of each decomposition item. The constraint is that the sum of the design values ​​of each decomposition item is less than the design value of the fault tolerance time interval.

7. A vehicle functional safety simulation analysis device, characterized in that, The vehicle functional safety simulation analysis device includes: A module is established to build a vehicle simulation model, which includes a vehicle global control interaction model, a vehicle dynamics model, a control and communication delay model, a traffic environment model, and a multi-scenario mechanical and electrical coupling failure risk model. The hazard analysis module is used to inject failure risks through a multi-scenario mechanical and electrical coupling failure risk model, identify hazard events through a vehicle full-domain control interaction model, vehicle dynamics model, control and communication delay model, and traffic environment model, and output the vehicle safety integrity level of the hazard event by assessing the severity level, exposure probability, and controllability of the hazard event. The decomposition module is used to determine the safety target corresponding to the hazard event if the vehicle safety integrity level is greater than the preset level, determine the design value of the fault tolerance time interval corresponding to the safety target, and obtain the design values ​​of each decomposition item, such as fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, and vehicle dynamic response margin, obtained by decomposing the design value of the fault tolerance time interval. The simulation verification module is used to inject faults into the vehicle simulation model and obtain test values ​​for each decomposed item of fault detection time interval, diagnostic response delay, response command communication delay, execution mechanical response delay, vehicle dynamic response margin, and fault tolerance time interval through simulation verification, thereby covering the failure risk. The iterative optimization module is used to compare and verify various design values ​​and test values, so as to iteratively optimize the fault tolerance time interval and the design values ​​of each decomposition item.

8. The vehicle functional safety simulation analysis device as described in claim 7, characterized in that, The vehicle functional safety simulation analysis device also includes a multi-condition verification module, used for: Faults were injected into the vehicle simulation model for different operating conditions, and the proportion of all operating conditions in which the design value of the fault tolerance time interval was less than the test value was verified by simulation. If the statistical proportion is greater than the preset proportion, the vehicle simulation model, safety target, fault tolerance time interval and design values ​​of each decomposition item are adjusted, and the simulation is re-verified until the statistical proportion is no greater than the preset proportion.

9. A vehicle functional safety simulation analysis device, characterized in that, The vehicle functional safety simulation analysis device includes a processor, a memory, and a vehicle functional safety simulation analysis program stored in the memory and executable by the processor, wherein when the vehicle functional safety simulation analysis program is executed by the processor, it implements the steps of the vehicle functional safety simulation analysis method as described in any one of claims 1 to 6.

10. A readable storage medium, characterized in that, The readable storage medium stores a vehicle functional safety simulation analysis program, wherein when the vehicle functional safety simulation analysis program is executed by a processor, it implements the steps of the vehicle functional safety simulation analysis method as described in any one of claims 1 to 6.