Hazard analysis and risk assessment method and system based on scene classification, terminal and medium

By constructing a multi-dimensional parameterized scenario type library, and defining scenario types using dimensions such as vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk states, the efficiency and consistency issues of hazard analysis and risk assessment in intelligent driving systems are solved, achieving complete scenario coverage and objectivity of assessment results.

CN121806805APending Publication Date: 2026-04-07SINO TRUK JINAN POWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-25
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing hazard analysis and risk assessment methods in intelligent driving systems suffer from problems such as huge workload, incomplete scenario coverage, strong subjectivity and poor consistency of assessment results, especially in complex and dynamic traffic environments where it is difficult to effectively manage scenario complexity.

Method used

By constructing a multi-dimensional parameterized scenario type library, scenario types are defined using dimensions such as vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk status. Hazards are mapped and risk assessments are conducted to ensure the completeness of analysis coverage and improve the objectivity and consistency of the assessment.

Benefits of technology

It reduces the workload of manual enumeration and analysis, improves the efficiency of hazard analysis and risk assessment, ensures the integrity of scenario coverage and the consistency of assessment results, and reduces the differences in subjective judgment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121806805A_ABST
    Figure CN121806805A_ABST
Patent Text Reader

Abstract

The invention relates to the field of vehicle function safety, and particularly provides a hazard analysis and risk assessment method and system based on scene classification, a terminal and a medium, and the method comprises the steps: recognizing a function failure mode of a target system, and determining the whole vehicle hazard caused by the function failure mode; establishing a scene type library formed by a plurality of preset scene types, wherein each scene type is defined by at least two dimensions of a self-vehicle working condition, a vehicle speed range, a driving behavior mode and a surrounding risk state; mapping the determined whole vehicle hazard to at least one related scene type where the hazard can occur in a scene type library to form a scene hazard event; and performing risk assessment on the scenarized hazardous event, determining the severity, the exposure rate and the controllability of the scenarized hazardous event, further determining the automobile safety integrity level of the scenarized hazardous event, and exporting a corresponding safety target and a safety state based on the automobile safety integrity level. According to the invention, the efficiency, objectivity and consistency of hazard analysis and risk assessment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle functional safety, specifically to a hazard analysis and risk assessment method, system, terminal, and medium based on scenario classification. Background Technology

[0002] As vehicles become increasingly intelligent and connected, the functions of intelligent driving systems are becoming more complex, making functional safety a core concern for the industry. In road vehicle functional safety standards, Hazard Analysis and Risk Assessment (HARA) aims to systematically identify potential hazards and determine their safety integrity levels, thereby providing a basis for setting safety objectives.

[0003] Currently, the HARA method commonly used in related technologies typically follows this process: first, identifying system functions and their possible failure modes; then, analyzing the potential vehicle-wide hazards caused by the failure; and finally, assessing the severity (S), exposure (E), and controllability (C) of the hazard event, based on considerations of the event's occurrence scenario, to determine the vehicle's Safety Integrity Level (ASIL). However, in practice, especially when dealing with systems closely interacting with complex and dynamic traffic environments, such as Automatic Emergency Braking (AEB) and Adaptive Cruise Control (ACC), existing methods face significant challenges. Firstly, these methods require analysts to enumerate various specific driving scenarios where hazard events might occur based on experience, resulting in a massive workload and a high risk of overlooking certain boundary or long-tail scenarios, making it difficult to guarantee complete scenario coverage. This leads to low feasibility and efficiency when dealing with complex systems. Furthermore, for the same hazard event, different analysts may assess its exposure (E) and controllability (C) based on different implicit scenario assumptions, resulting in highly subjective and inconsistent assessment results. Therefore, there is an urgent need for a hazard analysis and risk assessment development methodology that can effectively manage scenario complexity, ensure the integrity of analysis, and improve the objectivity and consistency of assessments, in order to meet the requirements of functional safety development for intelligent driving systems. Summary of the Invention

[0004] To address the aforementioned issues, this invention provides a hazard analysis and risk assessment method, system, terminal, and medium based on scenario classification. By constructing a multi-dimensional parameterized scenario type library, hazard mapping and risk assessment are standardized, thereby improving the efficiency, objectivity, and consistency of hazard analysis and risk assessment (HARA) while ensuring the completeness of analysis coverage.

[0005] In a first aspect, the technical solution of the present invention provides a hazard analysis and risk assessment method based on scenario classification, comprising the following steps: Identify at least one functional failure mode of the target system, and for each functional failure mode, determine the vehicle-wide hazard it causes. Establish a scenario type library consisting of multiple preset scenario types, where each scenario type is defined by at least two dimensions from the following: vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk states. The identified vehicle hazards are mapped to at least one relevant scenario type in the scenario type library where the hazard can occur, forming scenario-based hazard events; Conduct risk assessments on scenario-based hazard events to determine their severity, exposure rate, and controllability; Based on the determined severity, exposure rate, and controllability, the vehicle safety integrity level of the scenario-based hazard event is determined, and the corresponding safety objectives and safety status are derived based on the vehicle safety integrity level.

[0006] Secondly, the technical solution of the present invention provides a hazard analysis and risk assessment system based on scenario classification, comprising: The vehicle hazard determination module is used to identify at least one functional failure mode of the target system and, for each functional failure mode, determine the vehicle hazard it causes. The scenario type library construction module is used to build a scenario type library consisting of multiple preset scenario types, where each scenario type is defined by at least two dimensions from the following: vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk states. The scenario-based hazard event generation module is used to map the identified vehicle hazards to at least one relevant scenario type in the scenario type library where the hazard can occur, thereby forming a scenario-based hazard event. The event risk assessment module is used to conduct risk assessments on scenario-based hazardous events to determine their severity, exposure rate, and controllability. The safety target and status export module is used to determine the vehicle safety integrity level of a scenario-based hazard event based on the determined severity, exposure rate, and controllability, and to export the corresponding safety target and safety status based on the vehicle safety integrity level.

[0007] Thirdly, the technical solution of the present invention provides a terminal, comprising: Memory for storing scenario-based hazard analysis and risk assessment programs; A processor for implementing the steps of the scenario-based hazard analysis and risk assessment method as described in any of the preceding claims when executing the scenario-based hazard analysis and risk assessment procedure.

[0008] Fourthly, the present invention provides a computer-readable storage medium storing a scenario-based hazard analysis and risk assessment program, wherein the scenario-based hazard analysis and risk assessment program, when executed by a processor, implements the steps of the scenario-based hazard analysis and risk assessment method as described in any of the preceding claims.

[0009] As can be seen from the above technical solutions, this application has the following advantages: By pre-constructing a structured scenario type library, infinite specific scenarios are summarized into finite scenario types defined by multiple dimensions such as vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk states. When analyzing hazards, it is only necessary to map the hazards to the relevant preset scenario types, rather than exhaustively listing all possible situations, thereby significantly reducing the workload of manual enumeration and analysis and improving the efficiency of HARA work; Based on the scenario dimensions and parameter levels defined by the operating design domain and system functions, it ensures that the scenario type library can systematically cover all possible operating environments of the vehicle. Through structured combination generation, it avoids scenario omissions caused by relying on personal experience and improves the reliability of comprehensive risk identification; Furthermore, by establishing a risk assessment parameter library and ASIL judgment table, the assessment of severity, exposure rate, and controllability is objectively associated with specific scenario dimension parameters, reducing subjective judgment differences in the assessment process and ensuring the consistency and comparability of assessment results between different personnel and different projects. Attached Figure Description

[0010] To more clearly illustrate the technical solution of this application, the accompanying drawings used in the description will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a schematic diagram of a hazard analysis and risk assessment method based on scenario classification, provided as an embodiment of the present invention.

[0012] Figure 2 This is a schematic block diagram of a hazard analysis and risk assessment system based on scenario classification, provided for an embodiment of the present invention.

[0013] Figure 3 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present invention. Detailed Implementation

[0014] To make the purpose, features, and advantages of this application more apparent and understandable, specific embodiments and accompanying drawings will be used to clearly and completely describe the technical solution protected by this application. Obviously, the embodiments described below are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0015] Unless otherwise defined, all technical and scientific terms used in this application have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used in this application and in the specification of this invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.

[0016] Figure 1 This is a schematic flowchart illustrating a hazard analysis and risk assessment method based on scenario classification, provided as an embodiment of the present invention. Figure 1 The executing entity can be a scenario-based hazard analysis and risk assessment system. The scenario-based hazard analysis and risk assessment method provided in this embodiment of the invention is executed by a computer device, and correspondingly, the scenario-based hazard analysis and risk assessment system runs on the computer device. Depending on different needs, the order of the steps in this flowchart can be changed, and some steps can be omitted.

[0017] like Figure 1 As shown, the method includes the following steps.

[0018] S1, identify at least one functional failure mode of the target system, and for each functional failure mode, determine the vehicle-wide hazard it causes.

[0019] Specifically, the Hazard and Operability Analysis (HAZOP) method is used to perform systematic deviation analysis on system functions based on preset keywords, thereby identifying functional failure modes. Subsequently, based on engineering knowledge and historical data, a causal mapping table between each failure mode and potential vehicle hazards is constructed.

[0020] S2, establish a scenario type library consisting of multiple preset scenario types, where each scenario type is defined by at least two dimensions from the following: vehicle operating conditions, vehicle speed range, driving behavior pattern, and surrounding risk state.

[0021] Specifically, the set of operational environments and conditions suitable for vehicle operation is extracted from the target system's Operational Design Domain (ODD) configuration file and functional safety requirements specification. Four main dimension fields are defined for scenario classification: vehicle operating condition, vehicle speed range, driving behavior pattern, and surrounding risk state. Discretized parameter level values ​​are configured for each dimension. A scenario combination generation engine is invoked, and all possible scenario type combinations are automatically generated through Cartesian product operations or combinations with imposed constraints. These combinations are then structured and stored to form a scenario type library. This step transforms the enumeration of infinite scenarios into combinations of finite dimensions, ensuring the theoretical completeness of scenario coverage.

[0022] S3. Map the identified vehicle hazard to at least one relevant scenario type in the scenario type library where the hazard can occur, forming a scenario-based hazard event.

[0023] Specifically, a hazard-scenario determination matrix is ​​constructed and applied. This matrix uses all preset vehicle hazard types as rows and all values ​​of the "surrounding risk status" dimension from the scenario type library as columns. During mapping, the algorithm automatically traverses the scenario type library, extracts the "surrounding risk status" value for each scenario type, and queries the determination matrix. Only scenario types with a query result of "true" are determined as the "related scenario type" of that hazard. For each such combination, the system automatically generates a structured "scenario-based hazard event" data record. This step, through objective and coded logical judgment, ensures that the association between hazards and scenarios is consistent, traceable, and repeatable, eliminating differences in risk assessment caused by different scenario assumptions. S4 conducts risk assessments on scenario-based hazard events to determine their severity, exposure rate, and controllability.

[0024] Specifically, a risk assessment parameter library is constructed, which pre-establishes mapping relationships between scenario-level parameters and S / E / C level values. For example, "Severity (S)" is mainly associated with the "Speed ​​Range" level (high speeds correspond to higher S values); "Exposure (E)" is associated with "Vehicle Condition" and "Driving Behavior Pattern" (e.g., the E value may be higher in "urban congestion" conditions); and "Controllability (C)" is associated with "Driving Behavior Pattern" and "Surrounding Risk State" (e.g., the C value is lower when sudden braking occurs while "lane keeping"). During the assessment, scenario-level parameters are automatically extracted from each scenario-based hazard event record and queried from this parameter library to obtain the corresponding S, E, and C level values. This step achieves risk level judgment through parameter querying with predefined rules, improving the objectivity and consistency of the evaluation.

[0025] S5 determines the vehicle safety integrity level of a scenario-based hazard event based on the determined severity, exposure rate, and controllability, and derives the corresponding safety objectives and safety status based on the vehicle safety integrity level.

[0026] Specifically, the system queries a predefined ASIL determination table to determine the level, generates specific security requirements by calling the security target template library and executing security status decision logic, ensures that the determination of security integrity level follows the standard, and derives standardized security requirements, thereby improving the efficiency and quality of the entire security development lifecycle.

[0027] Furthermore, as a refinement and extension of the specific implementation of the above embodiments, in order to fully illustrate the specific implementation process in this embodiment, another hazard analysis and risk assessment method based on scenario classification is provided, which includes the following steps.

[0028] S100 identifies functional failure modes and determines vehicle-wide hazards.

[0029] This step identifies at least one functional failure mode of the target system and, for each functional failure mode, determines the vehicle-wide hazard it causes, specifically including the following steps S100.1 to S100.3.

[0030] S100.1, based on the preset system function description and interface definition, uses the hazard and operability analysis method to perform keyword-guided system deviation analysis on the expected function of the target system.

[0031] Obtain and load the target system's design documents, such as the "System Functional Specification" and "Interface Control Document," to determine the system's expected functions, performance boundaries, and interactions with external systems. Decompose the target system into several logical functional units as analysis nodes. For example, for an Automatic Emergency Braking (AEB) system, its core nodes may include "forward target perception," "collision risk calculation," "brake request generation," and "brake execution."

[0032] For each analysis node's expected functionality, a pre-defined set of standardized HAZOP guide words or keywords are applied to identify potential deviations from that functionality. The guide words include: No Function: The function is completely disabled; More of Function: The function output is too strong, too early, or lasts too long; Less of Function: The function output is too weak, too late, or too short in duration; Reverse Function: A function performs the opposite operation as expected. Stuck Function: The function output remains in a fixed state and cannot be changed; Unintended Function: A function is provided when it should not be activated; Unintended No Function: The function failed to be provided when it should have been activated.

[0033] Each "node-guide word" combination is analyzed, and the specific functional deviations are recorded. This process is completed by filling out a structured HAZOP analysis form, ensuring that all possible deviations are described and avoiding random omissions based on experience.

[0034] S100.2, based on systematic deviation analysis, identifies and outputs a list of functional failure modes corresponding to the target system.

[0035] Each specific functional deviation recorded in S100.1 is translated into a standard functional failure mode description according to the terminology specifications in the field of functional safety. For example, for the "brake request generation" node of AEB, the deviation that may arise from applying the guiding term "unintended provision of function" is "issuing a brake request when there is no collision risk", which can be translated into the functional failure mode: "unintended activation of AEB".

[0036] The failure modes generated by all analysis nodes are merged and organized, duplicates are eliminated, and a list of functional failure modes of the target system is formed.

[0037] S100.3 For each functional failure mode, by constructing a causal mapping relationship between it and potential vehicle hazards, at least one vehicle hazard caused by the failure mode is identified.

[0038] For each item in the failure mode list, based on vehicle dynamics, traffic participant interaction principles, and engineering judgment, a causal logic deduction is performed: "If this failure mode occurs, in the worst-case scenario, what hazardous condition or accident might the vehicle experience?" The results of the causal analysis are structured to construct a "failure mode-vehicle hazard" mapping matrix or table. The rows of this matrix represent functional failure modes, and the columns are pre-defined vehicle hazard types, such as: rear-end collision with the vehicle in front, collision with an obstacle in front, rear-end collision with the vehicle behind, side collision, loss of control, etc. The causal relationship is recorded in the corresponding cells using Boolean values ​​(yes / no) or text descriptions.

[0039] For example: For the failure mode "AEB braking force request less than expected", the corresponding vehicle hazard is "rear-end collision with the vehicle in front / collision with an obstacle in front". For the failure mode "AEB unexpectedly activated", the corresponding vehicle hazard is "rear-end collision with the vehicle behind".

[0040] S200, build a scene type library.

[0041] This step establishes a scenario type library consisting of multiple preset scenario types to abstract the real driving environment into a finite scenario type library, specifically including the following steps S200.1 to S200.5.

[0042] S200.1, Obtain and load the target system's runtime design domain configuration file and functional safety requirements specification, and parse the set of environmental conditions and operating conditions for vehicle operation from the configuration file as basic input data.

[0043] The Operational Design Domain (ODD) configuration file defines the external environmental conditions (such as road type, weather, lighting, traffic rules, etc.) and vehicle operating conditions under which the system is expected to function normally. The Functional Safety Requirements Specification includes scenario requirements or assumptions that have a special impact on system safety analysis.

[0044] Use script tools to parse key parameters from the above configuration files. For example, extract "Supported road types: urban expressways, highways" and "Supported weather conditions: sunny, light rain" from the ODD; extract "Parking scenarios need to be considered" and "The risk of following too closely needs to be considered" from the functional safety requirements.

[0045] The parsed entries are organized into a structured "environmental condition set" and "operational condition set". The dataset constitutes the input and constraint conditions for subsequently defining scene dimensions and parameter levels, ensuring that the construction of the scene library conforms to the design intent and safety goals.

[0046] S200.2, Based on the basic input data, generate and store a dimension definition table for scene classification; the dimension definition table shall contain at least four main dimension fields: “vehicle operating condition”, “vehicle speed range”, “driving behavior mode” and “surrounding risk status”.

[0047] This step, based on the input data obtained in step S200.1, determines several key characteristics affecting the occurrence and risk level of hazards according to functional safety analysis. These characteristics include four dimensions: vehicle operating condition, vehicle speed range, driving behavior pattern, and surrounding risk state. Vehicle operating condition describes the macroscopic environmental state of the vehicle; vehicle speed range describes the dynamic key parameters of the vehicle; driving behavior pattern describes the longitudinal / lateral control tasks being performed by the vehicle; and surrounding risk state describes the existence and state of key traffic participants closely related to vehicle safety.

[0048] Create a scenario dimension definition table in the database or configuration file. This table should contain at least the following fields: "Dimension ID", "Dimension Name", "Dimension Description", and "Enabled".

[0049] S200.3, configure at least two discretized parameter level values ​​for each primary dimension field in the dimension definition table, and store them as a level configuration table.

[0050] a) The level values ​​configured for the "Vehicle Condition" dimension include: urban roads, highways, congested roads, and rainy roads.

[0051] "Automotive operating conditions" describe the relatively stable environment and traffic conditions in which the vehicle operates. Its classification covers the most important environmental types within the Operational Design Domain (ODD) of a system (such as AEB), which have a significant impact on the system's perception, decision-making, and execution capabilities.

[0052] Urban roads: This refers to the structured road environment within a typical city, characterized by relatively dense traffic participants, frequent intersections, low-to-medium speed driving, and complex traffic signals and rules. This level primarily assesses the system's safety performance in highly dynamic, close-range interactive environments.

[0053] Highways: These refer to closed, high-grade road environments characterized by high speeds, one-way traffic, no intersections, and a relatively homogeneous range of traffic participants. This level emphasizes the system's safety capabilities under high-speed, long-distance perception and response conditions, and is particularly sensitive to false alarms.

[0054] Congested traffic conditions: This specifically refers to the slow, stop-and-go driving state of vehicles on roads (whether urban roads or highways) due to excessive traffic volume. This level focuses on the functional safety of the system under conditions of extremely low speed, extremely close following distance, and frequent start-stop, especially the requirements for "creeping" following and prevention of "phantom braking".

[0055] Rainy Road Conditions: This is a cross-sectional environmental condition level, referring to the road environment during rainy weather. It emphasizes the impact of the environment on the performance of sensors such as cameras and radar, as well as the coefficient of friction between tires and the road surface. Functional safety analysis of the system at this level needs to consider factors such as degraded perception performance and increased braking distance.

[0056] Setting these rating values ​​will direct the description of "operating conditions" to specific, verifiable test scenarios or operating environments with known high risks, providing an objective and distinguishable basis for determining "exposure rate (E)" in subsequent risk assessments.

[0057] b) The level values ​​configured for the "vehicle speed range" dimension are divided by vehicle speed thresholds, including: high speed above the first threshold, medium speed between the first and second thresholds, and low speed below the second threshold.

[0058] "Vehicle speed range" is a dimension describing the key dynamic performance of a vehicle, directly related to the severity of an accident and the system's reaction time. This dimension is defined and quantifiable by using vehicle speed thresholds for segmentation.

[0059] High speed refers to vehicle speeds exceeding the first threshold V1 (e.g., V1 = 80 km / h). Within this range, vehicle kinetic energy is enormous, and any functional malfunction could lead to catastrophic consequences; simultaneously, the system's tolerance window for decision-making and execution is extremely short. This level is typically directly associated with a high severity (S) assessment.

[0060] Medium speed refers to a vehicle speed between the first threshold V1 and the second threshold V2 (for example, V2 = 30 km / h, i.e., 30 km / h < vehicle speed ≤ 80 km / h). This is the common cruising speed range for vehicles, and the risk and controllability are between high and low speeds, making it a core area of ​​concern in functional safety analysis.

[0061] Low speed refers to a vehicle speed below or equal to the second threshold V2 (e.g., speed ≤ 30 km / h). This mainly includes scenarios such as following other vehicles in congested traffic and parking. Although the severity of a collision may be lower, functional abnormalities in this range (such as unexpected acceleration) may lead to close-range collisions with pedestrians or other vehicles, and drivers have higher expectations for the "micro-management" of the vehicle.

[0062] The thresholding definition method in this embodiment allows scenarios to be accurately classified according to different risk characteristics. In the subsequent "risk assessment parameter library" (step S400), rules can be established to map 'high speed' level to severity S3 and 'low speed' to S1, linking the objective parameters of the scenario to the risk assessment parameters S, thereby improving the objectivity of the analysis.

[0063] c) The level values ​​configured for the "driving behavior mode" dimension include: lane keeping, following, lane changing, and parking.

[0064] "Driving behavior mode" describes the longitudinal and lateral control tasks that the vehicle is performing. It reflects the current intentions and attention allocation of the driver or autonomous driving system and directly affects the ability to react to unexpected events.

[0065] Lane keeping driving refers to a vehicle maintaining stable movement within its lane, with the driver or system primarily responsible for speed control and lane centering. In this mode, the driver may be in a relatively relaxed "monitoring" state, and their preparedness and reaction speed to unexpected system interventions may be lower, thus affecting the "controllability (C)" assessment.

[0066] Following the vehicle in front refers to a vehicle actively adjusting its speed to maintain a safe following distance. This mode involves close-range interaction between vehicles, requiring a high degree of smoothness and accuracy in the system's response. Failure of this function may result in a rear-end collision or cause a rear-end collision by the vehicle behind.

[0067] Lane changing refers to a vehicle performing lateral movement, moving from one lane to an adjacent lane. This is a high-risk, high-dynamic driving behavior involving judgment of blind spots and vehicles approaching from the sides and rear. In this mode, any unexpected longitudinal intervention of the system can lead to serious lateral instability or a collision.

[0068] Parking refers to the low-speed, high-precision movement of a vehicle within a space to complete a parking or exiting maneuver. This mode typically occurs in congested, complex environments, where drivers have extremely high expectations for precise vehicle control. Failure to perform this function may result in property damage or minor personal injury.

[0069] The classification of driving behavior patterns provides crucial context for assessing “exposure (E)” and “controllability (C)”. For example, “lane keeping” may have a high exposure (E) on highways, while unintended braking during “lane changing” behavior typically has a very low controllability (C) assessment.

[0070] d) The level values ​​configured for the “surrounding risk status” dimension include: obstacle in front, vehicle driving closely behind, vehicle to the side, and no risky vehicles around.

[0071] The “Surrounding Risk Status” identifies and enumerates the presence and relative positions of key traffic participants directly related to vehicle safety. This dimension is a direct and necessary condition for determining whether a hazardous event is likely to occur.

[0072] An obstacle ahead refers to a potential collision target such as a vehicle, pedestrian, or stationary object existing in front of the vehicle's trajectory. This is a typical risk source that triggers the Forward Collision Warning (FCW) or Automatic Emergency Braking (AEB) functions.

[0073] "A vehicle is traveling close behind" means that there is a vehicle following closely behind your vehicle. This is a key prerequisite for assessing the danger of a rear-end collision caused by your vehicle's unexpected deceleration.

[0074] "Vehicles on the side" refers to vehicles traveling side-by-side in the adjacent lane to the side of your vehicle. This situation primarily affects the safety of decision-making regarding lane changes and side-collision avoidance, and is also a necessary condition for assessing the risk of a side collision.

[0075] "No risk vehicles in the vicinity" means that there are no such risky vehicles or obstacles within a certain range around the vehicle. This state is often used to analyze whether unintended functions would still cause harm in a "clean" environment, or as a low-risk scenario in "exposure (E)" assessment.

[0076] The level setting of this dimension is used to construct the "hazard-scenario judgment matrix". The Boolean values ​​in the matrix are set based on the relationship between the value of this dimension and the "necessary traffic environment conditions" between the vehicle hazard types.

[0077] S200.4 invokes the scene combination generation engine, reads the dimension definition table and the level configuration table, and performs Cartesian product operations or constraint combinations on the parameter level values ​​of different dimensions according to the preset combination rules to generate all possible scene type combinations.

[0078] Specifically, the scene combination generation engine is invoked. This engine performs calculations according to preset combination rules, which employ Cartesian products, representing all combinations across all dimensions and levels. For example, assuming the four dimensions have 4, 3, 4, and 4 levels respectively, theoretically, 4 x 3 x 4 x 4 = 192 basic scene types will be generated. It should be noted that in some cases, constraints can be imposed based on engineering knowledge to filter out invalid combinations that are impossible or unnecessary to consider in reality, generating an optimized set of scene types, such as filtering out the combination of "parking" behavior and "high-speed" vehicle speed.

[0079] S200.5, The generated scene type combinations are structured and stored to form a scene type library; each record in the scene type library corresponds to a unique scene type and includes the dimension fields that constitute it and the corresponding parameter level values.

[0080] Design the data table structure for the scene type library. Each record contains a unique scene type ID and various dimension fields, the values ​​of which are the corresponding parameter level values. Combine all the scene types generated in step S200.4 and write them one by one into the database or file system according to the above structure to complete the construction of the scene type library.

[0081] S300 generates scenario-based hazard events.

[0082] This step maps the identified vehicle hazards to at least one relevant scenario type in the scenario type library where the hazard can occur, forming a scenario-based hazard event. Specifically, it includes the following steps S300.1 to S300.3.

[0083] S300.1 Construct a hazard-scenario determination matrix. This matrix has a preset set of vehicle hazard types as rows and all value levels of the "surrounding risk state" dimension in the scenario type library as columns. The matrix elements are Boolean values, used to characterize whether the corresponding vehicle hazard type is likely to occur under the surrounding risk state. The Boolean value is set according to the following: the matrix element is set to true if and only if a certain "surrounding risk state" is a necessary traffic environment condition that causes the corresponding vehicle hazard type.

[0084] Specifically, based on the failure mode-vehicle hazard mapping table output in step S101.3, all unique "vehicle hazard types" are extracted to form a preset "vehicle hazard type set". For example: {"rear-end collision with the vehicle in front", "collision with an obstacle in front", "rear-end collision with the vehicle behind", "side collision"}. The vehicle hazard types constitute the rows of the hazard-scenario judgment matrix.

[0085] Extract all defined parameter level values ​​from the "Surrounding Risk Status" dimension of the "Scenario Type Library" constructed in step S200. For example: {"Obstacle ahead", "Vehicle driving close behind", "Vehicle to the side", "No risky vehicles nearby"}. Scenario types constitute columns of the hazard-scenario judgment matrix.

[0086] Set a "True" or "False" value for each cell in the matrix (corresponding to a hazard type and an surrounding risk state). The setting is based on the engineering logic principle: a cell is set to "True" only if a certain "surrounding risk state" is a "necessary traffic environment condition" that triggers the corresponding "vehicle hazard type".

[0087] "Necessary traffic environmental conditions" refers to the state of the most direct, external traffic participants or objects that are essential for the occurrence of the hazardous event. This judgment is based on physical laws and accident causation theories, excluding indirect or ambiguous connections.

[0088] For example, the danger of a "rear-end collision" requires a "necessary traffic environment condition" of a vehicle traveling at close range behind the vehicle. Therefore, the matrix element is "true" only when the "surrounding risk state" is "a vehicle traveling at close range behind"; for states such as "an obstacle in front", "a vehicle to the side", or "no risky vehicles nearby", the matrix element is "false". The danger of a "collision with an obstacle in front" requires a "necessary traffic environment condition" of an obstacle in front of the vehicle. Therefore, the matrix element is "true" only when the "surrounding risk state" is "an obstacle in front".

[0089] S300.2, for the vehicle hazard, perform a traversal mapping operation, including: extracting the type identifier of the vehicle hazard, querying the hazard-scenario determination matrix based on the type identifier, and obtaining its corresponding row vector; traversing the scenario type library, extracting the value of the "surrounding risk status" dimension for each scenario type in the library, and querying the corresponding column in the row vector based on the value; if the query result is true, then determine that the current scenario type is a related scenario type of the vehicle hazard.

[0090] This step utilizes the judgment matrix constructed in the previous step to automatically find all relevant scenarios in the scenario type library for all vehicle hazards identified in step S101.

[0091] The inputs are: ① List of vehicle hazards (from S101.3); ② Scenario type library (from S200.5); ③ Hazard-scenario judgment matrix (from S300.1).

[0092] Execute the following loop for each hazard in the list: a) Hazard Identifier Extraction and Matrix Row Query: Extract the type identifier of the current hazard (e.g., "HZ001: Rear-end Collision"), and query the hazard-scenario determination matrix based on this identifier to obtain its corresponding row vector. This row vector is a Boolean array that intuitively displays the correlation between the hazard and various "surrounding risk states".

[0093] b) Scene library traversal and matching: Traverse each record in the scene type library, i.e., each scene type. For the currently traversed scene type: Extract key dimension values: Extract the specific values ​​of the "surrounding risk status" dimension in the record of this scenario type, such as "a vehicle is driving close behind"; Table lookup determination: Using the extracted "surrounding risk status" value as an index, query the corresponding column in the row vector obtained in step a; Result determination: If the query result is "true", then the current scenario type is determined to be a "related scenario type" of this vehicle hazard. This is because, according to the determination matrix, this scenario possesses the "necessary traffic environment conditions" that lead to the occurrence of this hazard. If the result is "false", then skip.

[0094] S300.3 For each "vehicle hazard - scenario type" combination that is determined to be relevant, a structured scenario-based hazard event data record is generated; the data record includes: associated functional failure mode identifier, vehicle hazard type identifier, relevant scenario type identifier and its complete set of dimensional parameters.

[0095] This step encapsulates the discrete mapping relationship obtained in the previous step into a structured analysis object, namely, a scenario-based hazard event.

[0096] Define a data structure for contextualized hazard events, whose fields must include at least: Event Unique ID: Used for unique identification and management; Related functional failure mode identifier: trace back to the root cause of this hazard (from S101.2). Vehicle Hazard Type Identification: Clearly define what the hazard is (from S101.3); Relevant scenario type identification: clearly indicating the environment in which the hazard may occur (judgment results from S300.2); A complete set of dimensional parameters: This records all specific parameter level values ​​for "vehicle operating conditions," "vehicle speed range," "driving behavior pattern," and "surrounding risk status" under this scenario type. This provides the complete contextual information needed to assess risk.

[0097] For each "hazard identifier, scenario type identifier" pair output by S300.2, the corresponding functional failure mode identifier is found according to the "functional failure mode - vehicle hazard" mapping relationship. Based on the "scenario type identifier," its complete set of dimensional parameters is retrieved from the scenario type library. All the above information, along with the newly generated unique event ID, is assembled into a complete scenario-based hazard event data record. All generated records are then aggregated to form a scenario-based hazard event set.

[0098] S400 conducts risk assessments for scenario-based hazard events.

[0099] This step involves conducting a risk assessment of scenario-based hazard events to determine their severity, exposure rate, and controllability, specifically including the following steps S400.1 to S400.2.

[0100] S400.1, invoke the risk assessment parameter library, which stores the mapping relationship of assessment benchmark values ​​associated with scene dimension parameters, wherein: the assessment benchmark value of severity is associated with the "vehicle speed range" level in the scene dimension; the assessment benchmark value of exposure rate is associated with the "vehicle operating condition" and "driving behavior mode" levels in the scene dimension; and the assessment benchmark value of controllability is associated with the "driving behavior mode" and "surrounding risk status" levels in the scene dimension.

[0101] This step establishes a structured knowledge base that defines how the objective characteristics (dimensional parameters) of a scenario determine the three attributes of risk (S / E / C).

[0102] Specifically, referring to guiding examples in standards such as ISO 26262 / GB / T 34590, industry best practices, and historical accident data and test data accumulated within the enterprise, as well as based on physical laws, ergonomics, and traffic participant interaction models, we analyze the impact of different scenario characteristics on the consequences of hazards, the probability of occurrence, and the possibility of driver intervention, and construct a mapping relationship for the parameter set.

[0103] The mapping relationships in the parameter library include a severity (S) mapping table, an exposure rate (E) mapping table, and a controllability (C) mapping table.

[0104] The Severity (S) mapping table's assessment baseline is strongly correlated with the "Speed ​​Range" level in the scenario dimension. This is because, in vehicle collisions, vehicle speed is one of the most critical physical factors determining the severity of occupant injury. For example, the table might define: "High Speed" level maps to S3 (fatal / life-threatening), "Medium Speed" to S2 (serious / grievous injury), and "Low Speed" to S1 (minor / minor injury). This correlation anchors the assessment of S from a vague definition of the consequences to the measurable, objective parameter of "vehicle speed."

[0105] The evaluation baseline of the Exposure Rate (E) mapping table is associated with the "Vehicle Condition" and "Driving Behavior Mode" levels in the scenario dimension. Exposure rate assesses the "probability of the vehicle being in a specific scenario". For example, "Vehicle Condition" as "urban congestion" and "Driving Behavior Mode" as "following" is generally considered to have a high exposure rate (e.g., E4) because this is a common driving situation; "Vehicle Condition" as "highway" and "Driving Behavior Mode" as "lane changing" may have a medium exposure rate (e.g., E3); and "Parking" behavior may have a low exposure rate (e.g., E2).

[0106] The controllability (C) mapping table's assessment baseline is correlated with the "driving behavior mode" and "surrounding risk state" levels in the scenario dimension. Controllability assesses the ease with which a driver or other traffic participants can avoid harm in a given scenario. For example, when the "driving behavior mode" is "lane keeping" (the driver may be less vigilant) and the "surrounding risk state" is "a vehicle is approaching closely from behind," the driver has virtually no chance of avoiding a rear-end collision due to "unintended braking," resulting in extremely low controllability (e.g., C3). When the "driving behavior mode" is "parking" (low speed, attentive) and the "surrounding risk state" is "no risky vehicles nearby," the controllability may be higher for minor abnormal movements (e.g., C1).

[0107] S400.2 Perform parameterized assessment on scenario-based hazard events, including: querying the parameter library and mapping the corresponding severity level value based on the "vehicle speed range" level corresponding to the scenario type identifier of the scenario-based hazard event; querying the parameter library and mapping the corresponding exposure rate level value based on the "vehicle operating condition" and "driving behavior mode" levels corresponding to the scenario type identifier of the scenario-based hazard event; and querying the parameter library and mapping the corresponding controllability level value based on the "driving behavior mode" and "surrounding risk state" levels corresponding to the scenario type identifier of the scenario-based hazard event.

[0108] This step utilizes the parameter library loaded in the previous step to batch and automatically assign risk parameters to the input set of scenario-based hazard events. The input is the "set of scenario-based hazard events" output from step S300.3, where each record already contains a complete set of scenario-dimensional parameters.

[0109] For each event record in the set, perform the following iterative steps: Extract the specific dimension parameter level value corresponding to the associated scenario type from the current event record, query the mapping, and determine the severity (S), exposure rate (E), and controllability (C).

[0110] Specifically, the "Speed ​​Range" rating is extracted and used as input to query the "Severity (S) Mapping Table" to obtain the output S rating value, which converts objective characteristics such as "high speed" into a risk severity rating. Rating values ​​for "Vehicle Operating Condition" and "Driving Behavior Pattern" are extracted and their combination is used as joint input to query the "Exposure Rate (E) Mapping Table" to obtain the output E rating value, which reflects the probability assessment of the vehicle's exposure to a risky environment under this specific operating condition and behavior combination. Rating values ​​for "Driving Behavior Pattern" and "Ambient Risk State" are extracted and their combination is used as joint input to query the "Controllability (C) Mapping Table" to obtain the output C rating value, which assesses the avoidability of the hazard under this specific behavior pattern and risky environment.

[0111] The S, E, and C level values ​​obtained from the assessment are used as new fields to update the current scenario-based hazard event record. After processing all events, a set of scenario-based hazard events with risk assessment parameters bound to them is output.

[0112] S500, export security targets and security status.

[0113] This step first determines the vehicle safety integrity level of the scenario-based hazard event based on the determined severity, exposure rate, and controllability. Then, based on the vehicle safety integrity level, the corresponding safety objectives and safety status are derived, specifically including the following steps S500.1 to S500.8.

[0114] S500.1, Load the predefined vehicle safety integrity level judgment table; the judgment table takes the combination of severity, exposure rate and controllability levels as input conditions and the corresponding vehicle safety integrity level as the output result.

[0115] This step loads a standardized set of conversion rules to map the S / E / C level combination to the ASIL level, ensuring that the ASIL determination complies with international / domestic functional safety standards.

[0116] The decision table is a predefined two-dimensional or multi-dimensional lookup table. Its input is discrete S, E, and C level values, and its output is the corresponding ASIL level (QM, ASIL A, ASIL B, ASIL C, ASIL D) or "undefined". The decision logic follows the combination rules defined in the standard.

[0117] The table can be a configuration file built into the tool, a database table, or a constant array hard-coded in the algorithm.

[0118] S500.2 For each scenario-based hazard event, extract its corresponding severity, exposure rate, and controllability level values; use the level values ​​of each dimension as joint input conditions to query the vehicle safety integrity level judgment table to obtain the corresponding vehicle safety integrity level.

[0119] This step determines the ASIL level for each scenario-based hazard event for which S / E / C have been assessed. The input is the set of scenario-based hazard events with bound S / E / C levels, output from step S400. For each event record in the set, the bound Severity (S), Exposure Rate (E), and Controllability (C) level values ​​are extracted to form a combined input key. This key is used as input to query the ASIL determination table loaded in step S500.1 to obtain the query result, i.e., the ASIL level corresponding to the hazard event. The obtained ASIL level value is then used as a new field to update the current event record.

[0120] S500.3 sets a quality management level threshold and marks scenario-based hazard events with a vehicle safety integrity level higher than the threshold as high safety requirement events.

[0121] This step performs an initial screening of events based on ASIL levels and sets a Quality Management (QM) level as a threshold according to functional safety standards. QM means that the risk of the hazard event can be controlled through routine quality management processes without the need to assign specific safety objectives. All event records with determined ASIL levels are iterated through, and events with ASIL levels higher than QM (i.e., ASIL A / B / C / D) are automatically marked as "high safety requirement events".

[0122] S500.4 analyzes and extracts the associated functional failure mode code and vehicle hazard type code for each high safety requirement event.

[0123] This step extracts necessary input information for the automatic generation of safety objectives. For each event marked as "high safety requirement," the system parses and extracts the Functional Failure Mode Code (FMEA) and Vehicle Hazard Type Code from its records. The FMEA indicates the root technical cause of the hazard, such as "FMEA-001: Unexpected AEB activation." The Vehicle Hazard Type Code indicates the final manifestation of the hazard, such as "HAZ-003: Rear-end collision."

[0124] S500.5 calls the pre-compiled safety target template library; this template library stores standardized statement templates that match different functional failure mode types and vehicle hazard types.

[0125] S500.6 Based on the extracted failure mode code and hazard type code, a matching search is performed in the template library to obtain the corresponding standardized statement template, and the specific parameters are substituted into the placeholders in the template to generate the safety target text.

[0126] Steps S500.5 and S500.6 standardize and template the expression of security requirements to address potential ambiguities and inconsistencies in natural language descriptions.

[0127] The safety target template library is a predefined knowledge base in which one or more standardized statement templates are stored for each common combination of "functional failure mode type" and "vehicle hazard type".

[0128] Template structure example: "Prevent [harmful consequences for the whole vehicle] caused by [failure behavior] of [failure mode subject]". Specific template example: For the failure mode "AEB unexpected activation" and the hazard "rear-end collision", the template may be: "Prevent the vehicle from being rear-ended by a vehicle due to unexpected activation of the automatic emergency braking system". Based on the "failure mode code" and "hazard type code" extracted from the event, a matching search is performed in the template library to find the corresponding standardized statement template. Then, the specific parameters in the event record are substituted into the placeholders in the template to generate the safety target text. For example, substituting the specific system name "Forward Collision Warning System" into the [failure mode body] of the template will finally generate "Prevent the vehicle from being rear-ended by a vehicle due to unexpected activation of the forward collision warning system". S500.7, for each safety objective, executes safety state decision logic, including: selecting one or more safety states from a predefined set of safety states based on the detectability of failure modes, the redundancy of the system architecture, and the controllable time window under the current driving scenario; the safety state is the operating mode or degraded mode that the system should enter to ensure the vehicle is in a safe state when a relevant fault is detected.

[0129] The decision-making logic considers the detectability of the failure mode, the redundancy of the system architecture, and the controllable time window in the current driving scenario. The detectability of the failure mode indicates whether the failure can be reliably and promptly detected by the system monitoring mechanism. The redundancy of the system architecture indicates whether the system has backup paths or the ability to operate in a degraded manner. The controllable time window in the current driving scenario indicates how much time the system or driver has to react from the occurrence of the failure to the development of harm, based on the current scenario.

[0130] Based on the above input, predefined decision-making logic is executed to select one or more of the most suitable states from a predefined set of safety states. The set of safety states includes entering limp-home mode, shutting down affected functional modules, switching to a backup / redundant system, maintaining current operation but activating the highest level of audible and visual alarms, and performing a safe stop. Finally, one or more explicit safety state identifiers are determined for the current safety objective, such as "State_02: Enter limp-home mode, maximum speed limited to 60 km / h".

[0131] Regarding the detectability of failure modes, the decision logic first assesses whether the failure modes related to the safety objective can be reliably and promptly detected by the diagnostic mechanisms or monitoring units in the design. If the failure can be diagnosed quickly and reliably, the decision logic tends to choose proactive and granular safety states, such as "switching to the standby system" or "entering a limp mode with restrictions," to maximize functional availability while ensuring safety. If the failure is difficult to detect or takes too long to detect, the decision logic will prioritize safety and tend to choose conservative and deterministic safety states, such as "immediately shutting down affected functions" or "performing a safe shutdown," because the system does not have enough time for complex fault handling and state transitions.

[0132] For example: If diagnostic coverage is high AND diagnostic time is less than a controllable time window, then consider "switching to a redundant system" or "entering restrictive limp mode". If diagnostic coverage is low or diagnostic time is ≥ controllable time window, then "Immediate shutdown" or "Perform safe shutdown" should be selected.

[0133] Regarding the redundancy capabilities of the system architecture, the decision logic assesses whether the system possesses physical or logical backup paths, degraded operating modes, or additional safety mechanisms in the event of a failure. If the system is designed with hot backup, cold backup, or functional degradation paths, the decision logic will prioritize a safe state that utilizes this redundancy capability, such as "switching to a standby / redundant system," to achieve uninterrupted functionality or a gentle degradation. If the system has a single-point architecture or limited redundancy capabilities, the decision logic will choose a more basic safety state that does not rely on additional hardware resources, such as "disabling the function" or "activating alarms and relying on driver takeover."

[0134] For example: If a hot backup channel with the same performance exists, then the preferred option is "Switch to the backup system"; If only a degraded performance alternative exists, then you can choose to "enter limp home mode (performance limited)"; If there is no hardware redundancy and the software cannot isolate the fault, then "Disable affected functional modules" should be selected.

[0135] Given a controllable time window in the current driving scenario, the decision logic, combined with the specific scenario parameters associated with the safety objective, estimates the shortest time from when a fault is detected to when the harm is unavoidable. If the time window is ample, there is sufficient time to perform complex fault handling, state transitions, and even attempt recovery. The decision logic may allow for step-by-step, gradual safety states, such as first "activating a high-level alarm" and waiting for driver takeover, then "entering limp mode" if ineffective. If the time window is tight, the system must bring the vehicle to a deterministic safety state within a very short time. The decision logic will force the selection of a safety state with extremely low response latency and high determinism, such as "immediately applying a minimum-risk strategy (e.g., emergency braking to a stop)" or "instantly switching to a pre-calculated stable degradation mode."

[0136] For example: If the controllable time window > T1 (e.g., 5 seconds) THEN, a composite state including "driver takeover alarm period" can be considered. If the controllable time window is ≤ T2 (e.g., 500 milliseconds), then "Execute the predefined minimum risk operation immediately" must be selected.

[0137] The decision logic takes the evaluation results of the above three dimensions as input, executes a set of predefined decision rules, and selects one or more state identifiers from the predefined set of security states.

[0138] S500.8 associates and binds the generated security target and security status with the high-security-requirement event record and stores them in the security requirement specification library.

[0139] The generated security target text and the determined security status identifier are associated and bound with the original "high security requirement event" record. This completes the record, creating a full traceability chain from failure mode, hazard, scenario, S / E / C, ASIL to security target and security status. All event records bound to security requirements are stored in the security requirement specification library.

[0140] The foregoing has described in detail an embodiment of a hazard analysis and risk assessment method based on scenario classification. Based on the hazard analysis and risk assessment method based on scenario classification described in the above embodiment, this invention also provides a hazard analysis and risk assessment system based on scenario classification corresponding to the method.

[0141] Figure 2This is a schematic block diagram of a scenario-based hazard analysis and risk assessment system provided in an embodiment of the present invention. In this embodiment, the scenario-based hazard analysis and risk assessment system 200 can be divided into multiple functional modules according to its functions. A module, as referred to in this invention, is a series of computer program segments that can be executed by at least one processor and perform a fixed function, and is stored in memory.

[0142] The vehicle hazard determination module 210 is used to identify at least one functional failure mode of the target system and, for each functional failure mode, determine the vehicle hazard it causes.

[0143] The scenario type library construction module 220 is used to build a scenario type library consisting of multiple preset scenario types, wherein each scenario type is defined by at least two dimensions of vehicle operating conditions, vehicle speed range, driving behavior mode and surrounding risk state.

[0144] The scenario-based hazard event generation module 230 is used to map the determined vehicle hazard to at least one relevant scenario type in the scenario type library where the hazard can occur, thereby forming a scenario-based hazard event.

[0145] The event risk assessment module 240 is used to conduct risk assessments on scenario-based hazard events to determine their severity, exposure rate, and controllability.

[0146] The safety target and status export module 250 is used to determine the vehicle safety integrity level of a scenario-based hazard event based on the determined severity, exposure rate and controllability, and to export the corresponding safety target and safety status based on the vehicle safety integrity level.

[0147] The scenario-based hazard analysis and risk assessment system of this embodiment is used to implement the aforementioned scenario-based hazard analysis and risk assessment method. Therefore, the specific implementation of this system can be found in the embodiment section of the scenario-based hazard analysis and risk assessment method above. Thus, its specific implementation can be referred to the description of the corresponding embodiments, and will not be elaborated here.

[0148] Furthermore, since the scenario-based hazard analysis and risk assessment system of this embodiment is used to implement the aforementioned scenario-based hazard analysis and risk assessment method, its function corresponds to the function of the above method, and will not be repeated here.

[0149] Figure 3This is a schematic diagram of a terminal 300 provided in an embodiment of the present invention, including: a processor 310, a memory 320, and a communication unit 330. The processor 310 is used to implement the process steps of the above-described embodiment of the hazard analysis and risk assessment method based on scene classification when implementing the hazard analysis and risk assessment program based on scene classification stored in the memory 320.

[0150] This invention also provides a computer storage medium, which may be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc. The computer storage medium stores a scenario-based hazard analysis and risk assessment program. When executed by a processor, the scenario-based hazard analysis and risk assessment program implements the process steps of the above-described scenario-based hazard analysis and risk assessment method embodiment.

[0151] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A hazard analysis and risk assessment method based on scenario classification, characterized in that, Includes the following steps: Identify at least one functional failure mode of the target system, and for each functional failure mode, determine the vehicle-wide hazard it causes. Establish a scenario type library consisting of multiple preset scenario types, where each scenario type is defined by at least two dimensions from the following: vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk states. The identified vehicle hazards are mapped to at least one relevant scenario type in the scenario type library where the hazard can occur, forming scenario-based hazard events; Conduct risk assessments on scenario-based hazard events to determine their severity, exposure rate, and controllability; Based on the determined severity, exposure rate, and controllability, the vehicle safety integrity level of the scenario-based hazard event is determined, and the corresponding safety objectives and safety status are derived based on the vehicle safety integrity level.

2. The hazard analysis and risk assessment method based on scenario classification according to claim 1, characterized in that, Identify at least one functional failure mode of the target system, and for each functional failure mode, determine the resulting vehicle-wide hazards, specifically including: Based on the pre-defined system function description and interface definition, a hazard and operability analysis method is used to perform a keyword-guided systematic deviation analysis on the expected function of the target system. Based on systematic deviation analysis, identify and output a list of functional failure modes corresponding to the target system; For each functional failure mode, at least one vehicle hazard caused by that failure mode is identified by constructing a causal mapping relationship between it and potential vehicle hazards.

3. The hazard analysis and risk assessment method based on scenario classification according to claim 1, characterized in that, Establish a scene type library consisting of multiple preset scene types, specifically including: Obtain and load the target system's runtime design domain configuration file and functional safety requirements specification, and parse the set of environmental conditions and operating conditions for vehicle operation from the configuration file as basic input data; Based on the basic input data, a dimension definition table for scene classification is generated and stored; the dimension definition table contains at least four main dimension fields: "vehicle operating condition", "vehicle speed range", "driving behavior mode" and "surrounding risk status". For each primary dimension field in the dimension definition table, configure at least two discretized parameter level values ​​and store them as a level configuration table; wherein: a) The level values ​​configured for the "Vehicle Operating Conditions" dimension include: urban roads, highways, congested road conditions, and rainy road conditions; b) The level values ​​configured for the "vehicle speed range" dimension are divided according to vehicle speed thresholds, including: high speed above the first threshold, medium speed between the first and second thresholds, and low speed below the second threshold. c) The level values ​​configured for the "driving behavior mode" dimension include: lane keeping, following, lane changing, and parking; d) The level values ​​configured for the "surrounding risk status" dimension include: obstacle in front, vehicle driving closely behind, vehicle to the side, and no risky vehicles around; The scene combination generation engine is invoked, the dimension definition table and the level configuration table are read, and the parameter level values ​​of different dimensions are combined by Cartesian product operation or constraint combination according to the preset combination rules to generate all possible scene type combinations. The generated scene types are combined and stored in a structured manner to form a scene type library; each record in the scene type library corresponds to a unique scene type and includes the dimension fields that constitute it and the corresponding parameter level values.

4. The hazard analysis and risk assessment method based on scenario classification according to claim 3, characterized in that, The identified vehicle hazards are mapped to at least one relevant scenario type in the scenario type library where the hazard can occur, forming scenario-based hazard events, specifically including: A hazard-scenario determination matrix is ​​constructed. This matrix has a preset set of vehicle hazard types as rows and all value levels of the "surrounding risk state" dimension in the scenario type library as columns. The matrix elements are Boolean values, which are used to characterize whether the corresponding vehicle hazard type is likely to occur under the surrounding risk state. The Boolean values ​​are set according to the following: the matrix element is set to true if and only if a certain "surrounding risk state" is a necessary traffic environment condition that triggers the corresponding vehicle hazard type. For the vehicle hazard, a traversal mapping operation is performed, including: extracting the type identifier of the vehicle hazard, querying the hazard-scenario determination matrix based on the type identifier, and obtaining its corresponding row vector; traversing the scenario type library, extracting the value of the "surrounding risk status" dimension for each scenario type in the library, and querying the corresponding column in the row vector based on the value; if the query result is true, then the current scenario type is determined to be a related scenario type of the vehicle hazard. For each "vehicle hazard - scenario type" combination that is determined to be relevant, a structured scenario-based hazard event data record is generated; the data record includes: associated functional failure mode identifier, vehicle hazard type identifier, relevant scenario type identifier and its complete set of dimensional parameters.

5. The hazard analysis and risk assessment method based on scenario classification according to claim 4, characterized in that, Conduct risk assessments for scenario-based hazard events to determine their severity, exposure rate, and controllability, specifically including: The risk assessment parameter library is invoked. The parameter library stores the mapping relationship of assessment benchmark values ​​associated with scene dimension parameters, wherein: the assessment benchmark value of severity is associated with the "vehicle speed range" level in the scene dimension; the assessment benchmark value of exposure rate is associated with the "vehicle operating condition" and "driving behavior mode" levels in the scene dimension; and the assessment benchmark value of controllability is associated with the "driving behavior mode" and "surrounding risk status" levels in the scene dimension. Parametric assessments are performed on scenario-based hazard events, including: querying a parameter library to obtain the corresponding severity level value based on the "vehicle speed range" level corresponding to the scenario type identifier of the scenario-based hazard event; querying a parameter library to obtain the corresponding exposure rate level value based on the "vehicle operating condition" and "driving behavior mode" levels corresponding to the scenario type identifier of the scenario-based hazard event; and querying a parameter library to obtain the corresponding controllability level value based on the "driving behavior mode" and "surrounding risk state" levels corresponding to the scenario type identifier of the scenario-based hazard event.

6. The hazard analysis and risk assessment method based on scenario classification according to claim 1, characterized in that, Based on the determined severity, exposure rate, and controllability, the vehicle safety integrity level of the scenario-based hazard event is determined, specifically including: Load a predefined vehicle safety integrity level judgment table; the judgment table takes a combination of severity, exposure rate and controllability levels as input conditions and the corresponding vehicle safety integrity level as the output result. For each scenario-based hazard event, extract its corresponding severity, exposure rate, and controllability level values; use the level values ​​of each dimension as joint input conditions to query the vehicle safety integrity level judgment table and obtain the corresponding vehicle safety integrity level.

7. The hazard analysis and risk assessment method based on scenario classification according to claim 6, characterized in that, Based on the vehicle safety integrity level, the corresponding safety objectives and safety status are derived, specifically including: Set a quality management level threshold and mark scenario-based hazard events with a vehicle safety integrity level higher than the threshold as high safety requirement events; For each high-safety-requirement event, analyze and extract its associated functional failure mode code and vehicle hazard type code; Call the pre-compiled safety target template library; this template library stores standardized statement templates that match different functional failure mode types and vehicle hazard types; Based on the extracted failure mode codes and hazard type codes, a matching search is performed in the template library to obtain the corresponding standardized statement templates. The specific parameters are then substituted into the placeholders in the templates to generate the safety target text. For each safety objective, execute safety state decision logic, including: selecting one or more safety states from a predefined set of safety states based on the detectability of failure modes, the redundancy of the system architecture, and the controllable time window under the current driving scenario; the safety state is the operating mode or degraded mode that the system should enter to ensure the vehicle is in a safe state when a relevant fault is detected. The generated security goals and security states are associated and bound with the high-security-requirement event records and stored in the security requirements specification library.

8. A hazard analysis and risk assessment system based on scenario classification, characterized in that, include: The vehicle hazard determination module is used to identify at least one functional failure mode of the target system and, for each functional failure mode, determine the vehicle hazard it causes. The scenario type library construction module is used to build a scenario type library consisting of multiple preset scenario types, where each scenario type is defined by at least two dimensions from the following: vehicle operating conditions, vehicle speed range, driving behavior patterns, and surrounding risk status. The scenario-based hazard event generation module is used to map the identified vehicle hazards to at least one relevant scenario type in the scenario type library where the hazard can occur, thereby forming a scenario-based hazard event. The event risk assessment module is used to conduct risk assessments on scenario-based hazardous events to determine their severity, exposure rate, and controllability. The safety target and status export module is used to determine the vehicle safety integrity level of a scenario-based hazard event based on the determined severity, exposure rate, and controllability, and to export the corresponding safety target and safety status based on the vehicle safety integrity level.

9. A terminal, characterized in that, include: Memory for storing scenario-based hazard analysis and risk assessment programs; A processor, configured to implement the steps of the scenario-based hazard analysis and risk assessment method as described in any one of claims 1 to 7 when executing the scenario-based hazard analysis and risk assessment procedure.

10. A computer-readable storage medium, characterized in that, The readable storage medium stores a scenario-based hazard analysis and risk assessment program, which, when executed by a processor, implements the steps of the scenario-based hazard analysis and risk assessment method as described in any one of claims 1 to 7.