Dynamic security boundary control method and system fusing FuSa and SOTIF
By integrating FuSa and SOTIF dynamic safety boundary control methods, and using a risk transfer knowledge graph to calculate a comprehensive risk assessment value, which is then mapped to the constraints of vehicle dynamic control parameters, the safety problem of hardware failure coupled with complex scenarios in intelligent driving systems is solved, and real-time safety control of vehicles is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD
- Filing Date
- 2026-02-06
- Publication Date
- 2026-04-24
AI Technical Summary
In existing intelligent driving systems, functional safety and expected functional safety measures operate independently, which makes it impossible to effectively coordinate responses when hardware failures and complex scenarios overlap. It lacks the ability to dynamically identify and close-loop control coupled risks, making it difficult to achieve real-time adaptive adjustment of safety boundaries.
By acquiring parameters of vehicle functional safety status and expected functional safety scenarios, coupled analysis is performed using a risk transmission knowledge graph to calculate a comprehensive risk assessment value, which is then mapped to constraints of vehicle dynamic control parameters to achieve real-time control of vehicle operation and ensure operation within safety boundaries.
It achieves unified quantification of hardware failures and scenario risks, dynamically adjusts safety boundaries, and ensures that vehicles always maintain a safe state under complex operating conditions, thus avoiding accidents.
Smart Images

Figure CN121912992A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle safety technology, and more specifically, to a dynamic safety boundary control method and system that integrates FuSa and SOTIF. Background Technology
[0002] Currently, the safety assurance system for intelligent driving systems mainly follows two technical pillars: Functional Safety (FuSa) and Expected Functional Safety (SOTIF). Functional Safety, based on the ISO 26262 standard, aims to address risks arising from the failure of electronic and electrical systems (such as hardware malfunctions or software errors). Expected Functional Safety, based on the ISO 21448 standard, focuses on risks that may arise when the system is functioning normally but is affected by non-fault factors such as scenario complexity, perception limitations, or environmental uncertainties. These two standards provide a safety foundation for intelligent driving vehicles from different dimensions, but in practice, they are often designed and implemented as independent technical fields.
[0003] In existing technologies, functional safety and intended functional safety measures typically employ separate architectures and response mechanisms. For example, when the functional safety monitoring module detects brake booster performance degradation, the system may only passively warn the user by illuminating a warning light on the dashboard; however, in a slippery cornering scenario, the electronic stability control system (ESC) may independently intervene to adjust wheel braking force to prevent vehicle skidding. This independent operating mode leads to a lack of information exchange and mismatched strategies between the two systems. When hardware failures are compounded by complex scenarios (such as brake booster performance degradation occurring simultaneously on a slippery corner), the system cannot effectively coordinate its responses. Independent response measures may be insufficient to mitigate the risk aggregation effect caused by "fault-scenario" coupling, and may even amplify risks due to conflicting or delayed responses, exposing the current technological gaps in handling cross-domain coupled risks.
[0004] Furthermore, existing research often focuses on a single dimension, such as the construction of driving scenario knowledge graphs or the quantitative analysis of single failure modes, but fails to organically integrate functional safety status with expected functional safety scenarios. This results in a lack of dynamic identification and closed-loop control capabilities for coupled risks, making it difficult to achieve real-time adaptive adjustment of safety boundaries. Therefore, there is an urgent need in this field for an integrated solution that can collaboratively handle cross-domain risks of FuSa and SOTIF to improve the overall safety of intelligent driving systems under complex and degraded conditions. Summary of the Invention
[0005] This invention addresses the technical problems existing in the prior art by providing a dynamic safety boundary control method and system that integrates FuSa and SOTIF, effectively avoiding the risk superposition caused by the inadequacy of a single safety measure, and ensuring that the vehicle always travels within the dynamically adjusted safety limits.
[0006] According to a first aspect of the present invention, a dynamic security boundary control method integrating FuSa and SOTIF is provided, comprising: S1. Obtain internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. S2, mapping the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value; S3 controls the vehicle to operate within the safe boundary based on the constraints obtained from the mapping.
[0007] Based on the above technical solution, the present invention can also be improved as follows.
[0008] Optionally, step S1 includes: S101, real-time acquisition of functional safety status data from the vehicle bus or electronic control unit as the internal parameter, and acquisition of scene semantic information output by the environmental perception system as the external parameter; S102, the obtained internal and external parameters are input into a pre-constructed risk transmission knowledge graph for coupling analysis. The knowledge graph defines the relationship between fault events, scenario features and risk status and the risk transmission weight. S103, Based on the results of the coupling analysis, the comprehensive risk assessment value is calculated using a quantitative model.
[0009] Optionally, the internal parameters include at least: CPU load and memory error rate of key electronic control units, calibration deviation / temperature / data refresh rate of sensors, and response delay or current anomaly of actuators; The external parameters include at least: scene complexity score based on scene graph analysis, probability of trajectory prediction conflict between the vehicle and other vehicles, influence factors of weather and lighting conditions on the perception system, and road geometric features such as curvature and slope.
[0010] Optionally, the quantitative model calculates the comprehensive risk assessment value based on probability, expressed as:
[0011] in, The comprehensive risk assessment value, The basic functional safety risk value is calculated based on the aforementioned internal parameters. The expected functional safety basic risk value is calculated based on the external parameters, where K_f is a preset functional safety basic risk weighting coefficient, and K_s is a preset expected functional safety basic risk weighting coefficient. This is the coupling amplification coefficient for a specific combination of fault events and scenario features, obtained from the risk transmission knowledge graph; i represents the index variable of the specific combination of fault events and scenario features identified in the risk transmission knowledge graph. Let be the risk value corresponding to the specific fault event involved in the combination of the i-th specific fault event and scenario features. It represents the risk value corresponding to the specific scenario feature involved in the combination of the i-th specific fault event and scenario feature.
[0012] Optionally, step S2 includes: S201, The comprehensive risk assessment value is input into a preset parameter mapping function to calculate the boundary value of at least one vehicle dynamic control parameter; S202, set the boundary value as a time-varying constraint in the model predictive control framework optimization problem; S203, within each control cycle, solve the optimization problem with the time-varying constraints and output the optimal control sequence that satisfies the current dynamic safety boundary.
[0013] Optionally, the parameter mapping function is a monotonic function, which makes the calculated boundary value change in a more stringent direction as the comprehensive risk assessment value increases.
[0014] Optionally, the vehicle dynamic control parameters include at least one of the following: minimum safe distance, maximum permissible speed in curves, and lateral safety margin.
[0015] Optionally, step S202 includes: The boundary values are mapped to constraints on state variables or control input variables in the model predictive control state space; Specifically, the boundary value of the minimum safe time distance is mapped to the constraint of the vehicle's longitudinal distance, the boundary value of the maximum permissible speed on the curve is mapped to the constraint of the vehicle's longitudinal speed, and the boundary value of the lateral safety margin is mapped to the constraint of the vehicle's lateral position.
[0016] Optionally, step S3 includes: The control commands generated based on the aforementioned constraints will undergo priority arbitration and command coordination; among them, safety control commands generated to avoid coupling risks will be given higher priority than other comfort-oriented or efficiency-oriented control commands. After arbitration and instruction coordination, control commands are issued to the corresponding vehicle actuators to control the vehicle to operate within the safety boundaries.
[0017] According to a second aspect of the present invention, a dynamic safety boundary control system integrating FuSa and SOTIF is provided, comprising: The coupled risk identification module is configured to acquire internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. A dynamic safety boundary calculation engine is configured to map the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value. The coordinating actuator arbitration module is configured to generate control commands based on the mapped constraints and coordinate the actions of the vehicle actuators to keep the vehicle operating within the safety boundaries.
[0018] According to a third aspect of the present invention, an electronic device is provided, including a memory and a processor, wherein the processor is configured to implement the steps of the above-described dynamic security boundary control method integrating FuSa and SOTIF when executing a computer management program stored in the memory.
[0019] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, on which a computer management class program is stored, wherein when executed by a processor, the computer management class program implements the steps of the above-described dynamic security boundary control method integrating FuSa and SOTIF.
[0020] This invention provides a dynamic safety boundary control method, system, electronic device, and storage medium that integrates FuSa and SOTIF. First, it acquires in real-time internal functional safety status parameters (such as ECU operating status and sensor data) and external expected functional safety scenario parameters (such as road environment and traffic conditions). These two types of parameters, belonging to different safety domains, are fused to calculate a unified comprehensive risk assessment value. Then, this comprehensive risk assessment value is mapped and transformed into constraints for vehicle dynamic control parameters (such as vehicle speed and distance), with the constraint stringency increasing with the risk value. Finally, the system directly controls vehicle operation based on these dynamically generated constraints, forming a closed loop from risk perception to execution control.
[0021] This invention achieves unified risk quantification by integrating two types of safety parameters, thus solving the problem of isolated operation of functional safety and expected functional safety measures in traditional solutions. By establishing a direct mapping relationship between risk values and control parameter constraints, it realizes the ability to dynamically adjust the safety boundary according to the risk level. Finally, it directly controls the vehicle through constraints, ensuring that the vehicle always maintains a safe state under complex working conditions by automatically adjusting operating parameters (such as reducing vehicle speed and increasing intervals), effectively preventing accidents in complex risk scenarios. Attached Figure Description
[0022] Figure 1A flowchart of a dynamic safety boundary control method integrating FuSa and SOTIF provided by the present invention; Figure 2 A simplified flowchart of a dynamic security boundary control method integrating FuSa and SOTIF provided for one embodiment; Figure 3 A block diagram of a dynamic safety boundary control system integrating FuSa and SOTIF is provided for this invention; Figure 4 This is a schematic diagram of the data flow of a dynamic safety boundary control system that integrates FuSa and SOTIF in one embodiment. Figure 5 A schematic diagram of the hardware structure of a possible electronic device provided by the present invention; Figure 6 This is a schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. Detailed Implementation
[0023] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.
[0024] In this embodiment of the invention, when collecting, processing, and storing user personal information (such as images, behavioral characteristics, etc.), the implementation of the technical solution strictly adheres to the principles of legality, legitimacy, and necessity, as well as the core rule of "notification-consent." Specifically, before information collection, the system clearly informs the user of the purpose, method, scope, and usage rules of information collection through an interactive interface, and requires the user's active authorization and consent. The entire information processing process employs data encryption, access control, and other technical measures to ensure information security, and establishes mechanisms to facilitate users' exercise of their rights (such as querying, correcting, withdrawing consent, and deleting information). For exceptions stipulated by law (such as those necessary for fulfilling statutory duties or responding to public health emergencies), their application is strictly limited to the scope and limits authorized by law, ensuring that the technical solution does not contain any content that violates the law, social morality, or harms the public interest.
[0025] Figure 1 A flowchart of a dynamic safety boundary control method integrating FuSa and SOTIF provided by this invention. Figure 2 A simplified flowchart of a dynamic security boundary control method integrating FuSa and SOTIF is provided for one embodiment, combined with... Figure 1 and Figure 2 As shown, the method includes steps S1 to S3: S1. Obtain internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenarios, and calculate a comprehensive risk assessment value based on the internal and external parameters.
[0026] This step can be adopted. Figure 3 The system's coupled risk identification module is illustrated, which acquires two types of data in real time: first, functional safety parameters reflecting the hardware health status collected via the vehicle bus, such as CPU load of key ECUs, sensor calibration deviations, and actuator response delays; and second, scene feature parameters obtained through the environmental perception system, such as road curvature, weather conditions, and traffic participant behavior predictions. The acquired parameters are input into a pre-constructed risk transmission knowledge graph for coupled analysis. A quantitative model calculates a comprehensive risk value, which simultaneously reflects the combined impact of hardware anomalies and scene complexity.
[0027] S2, mapping the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value.
[0028] This step transforms the obtained comprehensive risk value into specific safety boundary parameter values using a preset mapping function. Figure 3 This demonstrates the implementation of the system's dynamic safety boundary calculation engine. For example, the higher the risk value, the more automatically the system calculates the minimum safe following distance and the lower the permissible speed for curves. The boundary values dynamically calculated in this step are set as real-time constraints for the model predictive control algorithm, ensuring that vehicle control commands always meet the safety requirements under the current risk level.
[0029] S3 controls the vehicle to operate within the safe boundary based on the constraints obtained from the mapping.
[0030] This step coordinates the execution of the constrained control commands generated by S2 through an arbitrator. Figure 3 The system's coordinating actuator arbitrator is illustrated. The arbitrator prioritizes safety commands issued to avoid high risks and breaks them down into specific action commands for actuators such as steering, braking, and driving. For example, when braking performance degradation and a slippery road surface are detected, the system coordinates to limit engine output and apply light braking in advance to ensure the vehicle smoothly decelerates to within safe limits.
[0031] Understandably, given the deficiencies in the background technology, this invention proposes a dynamic security boundary control method that integrates FuSa and SOTIF, which can employ... Figure 3The system implementation is shown. This method achieves unified quantification of hardware failure risk and scenario risk, which are traditionally handled separately, by real-time fusion of internal vehicle functional safety parameters and external scenario parameters and calculation of a comprehensive risk assessment value. By directly mapping the comprehensive risk assessment value to the constraints of vehicle dynamic control parameters, the strictness of the safety boundary can be adjusted in real time according to the risk level. Finally, the vehicle operation is directly controlled through the constraints, ensuring that the vehicle remains in a safe state under complex operating conditions by dynamically tightening control parameters (such as vehicle speed and distance), effectively solving the problem of insufficient response from a single safety measure when faults and scenarios are coupled.
[0032] Based on the above technical solutions, the embodiments of the present invention can be further improved as follows.
[0033] In one possible embodiment, step S1 includes sub-steps S101 to S103: S101, real-time acquisition of functional safety status data from the vehicle bus or electronic control unit as the internal parameter, and acquisition of scene semantic information output by the environmental perception system as the external parameter; The internal parameters include at least: CPU load and memory error rate of key electronic control units, calibration deviation / temperature / data refresh rate of sensors, and response delay or current abnormality of actuators; The external parameters include at least: scene complexity score based on scene graph analysis, probability of trajectory prediction conflict between the vehicle and other vehicles, influence factors of weather and lighting conditions on the perception system, and road geometric features such as curvature and slope.
[0034] In practical applications, for example, the system collects the internal parameters in real time via the vehicle bus (such as detecting that the CPU load of the electronic stability control system ECU exceeds a threshold, or that there is an anomaly in the data refresh of the millimeter-wave radar), while simultaneously acquiring the external parameters from the environmental perception system (such as a scene complexity score indicating a high probability of conflict, or road curvature data indicating a sharp bend). These specific parameters serve as the basic data input for subsequent coupled analysis steps, providing data support for risk quantification. For example... Figure 4 As shown in the implementation scenario, when both "brake response delay" and "low road surface slip coefficient" are collected simultaneously, the system can identify the coupling risk scenario of decreased braking performance and low-adhesion road surface.
[0035] S102, the obtained internal and external parameters are input into a pre-constructed risk transmission knowledge graph for coupling analysis. The knowledge graph defines the relationship between fault events, scenario features and risk status and the risk transmission weight.
[0036] S103, Based on the results of the coupling analysis, the comprehensive risk assessment value is calculated using a quantitative model.
[0037] For example, specific parameters collected (such as camera calibration deviation exceeding 0.5 degrees, and the perception system detecting a nighttime heavy rain scene) can be input into a risk transmission knowledge graph for coupled analysis: the knowledge graph will identify the association edge between the "camera calibration deviation" node and the "nighttime heavy rain" node, and calculate the comprehensive risk value that is significantly improved after the superposition of independent risks through the weight coefficient defined on the edge (such as the magnification coefficient of 3.0), thereby quantitatively characterizing the risk situation of visual perception ability being weakened due to hardware anomalies under severe weather conditions.
[0038] In one possible embodiment, the quantification model calculates the comprehensive risk assessment value based on probability, expressed as:
[0039] in, The comprehensive risk assessment value, The basic functional safety risk value is calculated based on the aforementioned internal parameters. The expected functional safety basic risk value is calculated based on the external parameters, where K_f is a preset functional safety basic risk weighting coefficient, and K_s is a preset expected functional safety basic risk weighting coefficient. This is the coupling amplification coefficient for a specific combination of fault events and scenario features, obtained from the risk transmission knowledge graph; i represents the index variable of the specific combination of fault events and scenario features identified in the risk transmission knowledge graph. Let be the risk value corresponding to the specific fault event involved in the combination of the i-th specific fault event and scenario features. It represents the risk value corresponding to the specific scenario feature involved in the combination of the i-th specific fault event and scenario feature.
[0040] For example, in practical implementation, when the risk transmission knowledge graph identifies the coupling relationship between "camera calibration deviation > 0.5 degrees" (corresponding to R_fusa_1 = 0.6) and "heavy rain at night" (corresponding to R_sotif_1 = 0.7), the coupling amplification coefficient C_1 = 3.0 for this combination is obtained from the graph. At the same time, the system calculates the basic functional safety risk value R_fusa = 0.8 (weight K_f = 0.5) and the basic scenario risk value R_sotif = 0.9 (weight K_s = 0.5). Finally, the comprehensive risk value is calculated using the above quantitative formula: R_coupled = 0.8 × 0.5 + 0.9 × 0.5 + (3.0 × 0.6 × 0.7) = 1.51. This value is significantly higher than the simple risk superposition value (0.85), accurately reflecting the risk amplification effect caused by the superposition of hardware anomalies and severe weather.
[0041] In one possible embodiment, step S2 includes sub-steps S201-S203: S201, the comprehensive risk assessment value is input to a preset parameter mapping function to calculate the boundary value of at least one vehicle dynamic control parameter; wherein, the parameter mapping function is a monotonic function, so that the calculated boundary value changes in a more stringent direction as the comprehensive risk assessment value increases; the vehicle dynamic control parameter includes at least one of minimum safe distance, maximum permissible speed in curves, and lateral safety margin.
[0042] For example, when the system inputs a comprehensive risk assessment value (e.g., R_coupled=0.8) into a preset parameter mapping function, this function follows monotonicity, making the output boundary values more stringent as the risk increases. Specifically, for example, the minimum safe headway is increased from the base value of 2.0 seconds to 3.5 seconds through function calculation, while the maximum permissible speed on curves is limited from the design value of 60 km / h to 40 km / h. This change reflects how the vehicle's dynamic control parameters dynamically adapt to the risk level, ensuring that safety constraints are automatically tightened in high-risk scenarios.
[0043] S202, setting the boundary values as time-varying constraints in the model predictive control framework optimization problem, specifically including: The boundary values are mapped to constraints on state variables or control input variables in the model predictive control state space; Specifically, the boundary value of the minimum safe time distance is mapped to the constraint of the vehicle's longitudinal distance, the boundary value of the maximum permissible speed on the curve is mapped to the constraint of the vehicle's longitudinal speed, and the boundary value of the lateral safety margin is mapped to the constraint of the vehicle's lateral position.
[0044] For example, when the system calculates that the minimum safe headway needs to be increased to 3.2 seconds, the cornering speed limit needs to be reduced to 45 km / h, and the lateral safety margin needs to be increased to 1.2 meters based on the risk value, this step maps these boundary values to specific constraints in model predictive control: the minimum safe headway is transformed into the threshold that the distance between the vehicle and the vehicle in front in the prediction time domain is not less than the dynamically calculated threshold, the cornering speed limit is transformed into the upper limit of longitudinal speed under lateral acceleration constraints, and the lateral safety margin is transformed into the lateral distance constraint between the vehicle profile and the lane boundary, so that the MPC controller is directly limited by these safety boundaries when solving the optimal trajectory.
[0045] S203, within each control cycle, solve the optimization problem with the time-varying constraints and output the optimal control sequence that satisfies the current dynamic safety boundary.
[0046] For example, after the system generates constraints such as a minimum safe distance of 3.2 seconds and a cornering speed limit of 45 km / h based on the risk value, the model predictive controller will solve an optimization problem containing these time-varying constraints within each 100-millisecond control cycle: by predicting the relative motion state between the vehicle and the vehicle in front in the next 5 seconds, it calculates a set of optimal control sequences (such as [acceleration -0.3 m / s² at 0.2s, steering angle 0.5° at 0.4s...]). Under the premise of satisfying the safe distance and speed constraints, the sequence smoothly tracks the predetermined trajectory, and finally sends the first command of the sequence to the actuator to achieve closed-loop control.
[0047] It is understandable that this embodiment dynamically transforms the comprehensive risk assessment value into boundary values of specific control parameters such as minimum safe distance and maximum speed on curves through a monotonic mapping function, and uses these boundary values as time-varying constraints in model predictive control. This allows the system to automatically tighten or relax safety requirements based on the real-time risk level. By mapping the boundary values to state variable constraints such as longitudinal distance, speed, and lateral position, it ensures that the vehicle always meets the dynamic safety boundary when tracking the path, thereby effectively preventing collisions in high-risk scenarios (such as slippery curves) while avoiding overly conservative intervention in low-risk scenarios, thus improving overall safety and adaptability.
[0048] In one possible embodiment, step S3 includes: S301, the control commands generated based on the constraints are subject to priority arbitration and command coordination; wherein, safety control commands generated to avoid coupling risks are given higher priority than other comfort or efficiency-oriented control commands. S302, after arbitration and instruction coordination, the control command is issued to the corresponding vehicle actuator to control the vehicle to operate within the safety boundary.
[0049] For example Figure 4 As shown in the data stream, when the vehicle enters a wet and slippery curve (SOTIF scenario) with "curvature = 0.005, adhesion coefficient = 0.5" and detects "brake booster performance degradation of 0.2%" (FuSa fault), the coupling risk identification module identifies the high coupling risk between "braking delay" and "wet and slippery curve" by querying the knowledge graph, and outputs a comprehensive risk level R_coupled = 0.8 (high). The dynamic safety boundary calculation engine then dynamically adjusts the minimum safe time interval (MinTTC) from 2.0 seconds to 3.0 seconds based on a monotonic mapping function, and reduces the curve speed limit from 80km / h to 60km / h. At this time, these boundary values are used as time-varying constraints input to the MPC controller to solve and generate high-priority safety boundary instructions such as "deceleration -0.3m / s², +steering angle X°".
[0050] Upon receiving this high-priority safety boundary instruction, the co-actuator arbitrator immediately suppresses the conventional comfort or efficiency control instructions and coordinates and decomposes the instructions into specific operations for the chassis domain controller: on the one hand, it coordinates the braking system to establish braking pressure in advance to reduce vehicle speed; on the other hand, it adjusts the intervention threshold and timing of the electronic stability control system (ESC) to maintain lateral stability, and ultimately controls the vehicle to safely pass through the danger zone in a state of "reduced speed and smooth cornering".
[0051] Figure 3 This invention provides a structural diagram of a dynamic safety boundary control system integrating FuSa and SOTIF. Figure 4 for Figure 3 The diagram shows the data flow of the system in a specific implementation scenario. (Combined with...) Figure 3 and Figure 4 As shown, a dynamic safety boundary control system integrating FuSa and SOTIF includes a coupled risk identification module, a dynamic safety boundary calculation engine, and a cooperative executor arbitration module, wherein: The coupled risk identification module is configured to acquire internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. A dynamic safety boundary calculation engine is configured to map the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value. The coordinating actuator arbitration module is configured to generate control commands based on the mapped constraints and coordinate the actions of the vehicle actuators to keep the vehicle operating within the safety boundaries.
[0052] It is understood that the dynamic safety boundary control system integrating FuSa and SOTIF provided by the present invention corresponds to the dynamic safety boundary control method integrating FuSa and SOTIF provided in the foregoing embodiments. The relevant technical features of the dynamic safety boundary control system integrating FuSa and SOTIF can be referred to the relevant technical features of the dynamic safety boundary control method integrating FuSa and SOTIF, and will not be repeated here.
[0053] Please see Figure 5 , Figure 5 This is a schematic diagram illustrating an embodiment of the electronic device provided in this invention. For example... Figure 5 As shown, this embodiment of the invention provides an electronic device 500, including a memory 510, a processor 520, and a computer program 511 stored in the memory 510 and executable on the processor 520. When the processor 520 executes the computer program 511, it performs the following steps: S1. Obtain internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. S2, mapping the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value; S3 controls the vehicle to operate within the safe boundary based on the constraints obtained from the mapping.
[0054] Please see Figure 6 , Figure 6 This is a schematic diagram illustrating an embodiment of a computer-readable storage medium provided by the present invention. (See diagram below.) Figure 6 As shown, this embodiment provides a computer-readable storage medium 600, on which a computer program 511 is stored. When the computer program 511 is executed by a processor, it performs the following steps: S1. Obtain internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. S2, mapping the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value; S3 controls the vehicle to operate within the safe boundary based on the constraints obtained from the mapping.
[0055] This invention provides a dynamic safety boundary control method, system, electronic device, and storage medium that integrates FuSa and SOTIF. It collects functional safety status data from the vehicle bus in real time (such as ECU CPU load, sensor calibration deviation, and actuator response delay) and scene semantic information output by the environmental perception system (such as road curvature, weather conditions, and traffic conflict probability). These two types of parameters are input into a pre-constructed "fault-scenario-risk" knowledge graph for coupled analysis, and a quantitative model is used to calculate a comprehensive risk assessment value. This comprehensive risk assessment value is directly transformed into specific boundary values for control parameters such as minimum safe distance and maximum speed in curves through a monotonic mapping function. These boundary values are used as time-varying constraints for the model predictive control optimization problem. After solving each control cycle, an arbitrator coordinates the generated control commands with the highest priority to coordinate actuator actions such as braking and steering. When a vehicle experiences brake booster performance degradation on a wet, slippery curve, the system can identify this coupled risk and automatically reduce the permissible speed on the curve and increase the following distance. At the same time, it coordinates the early intervention of the ESP and braking system to avoid skidding or rear-end collisions caused by insufficient individual safety measures, thus achieving closed-loop safety protection from risk identification to execution control.
[0056] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0057] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0058] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0059] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0060] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0061] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0062] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A dynamic safety boundary control method integrating FuSa and SOTIF, characterized in that, include: S1. Obtain internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. S2, mapping the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value; S3 controls the vehicle to operate within the safe boundary based on the constraints obtained from the mapping.
2. The dynamic safety boundary control method integrating FuSa and SOTIF according to claim 1, characterized in that, Step S1 includes: S101, real-time acquisition of functional safety status data from the vehicle bus or electronic control unit as the internal parameter, and acquisition of scene semantic information output by the environmental perception system as the external parameter; S102, the obtained internal and external parameters are input into a pre-constructed risk transmission knowledge graph for coupling analysis. The knowledge graph defines the relationship between fault events, scenario features and risk status and the risk transmission weight. S103, Based on the results of the coupling analysis, the comprehensive risk assessment value is calculated using a quantitative model.
3. The dynamic safety boundary control method integrating FuSa and SOTIF according to claim 2, characterized in that, The internal parameters include at least: CPU load and memory error rate of key electronic control units, calibration deviation / temperature / data refresh rate of sensors, and response delay or current abnormality of actuators; The external parameters include at least: scene complexity score based on scene graph analysis, probability of trajectory prediction conflict between the vehicle and other vehicles, influence factors of weather and lighting conditions on the perception system, and road geometric features such as curvature and slope.
4. The dynamic safety boundary control method integrating FuSa and SOTIF according to claim 2, characterized in that, The quantitative model calculates the comprehensive risk assessment value based on probability, and it is expressed as follows: in, The comprehensive risk assessment value, The basic functional safety risk value is calculated based on the aforementioned internal parameters. The expected functional safety basic risk value is calculated based on the external parameters, where K_f is a preset functional safety basic risk weighting coefficient, and K_s is a preset expected functional safety basic risk weighting coefficient. This is the coupling amplification coefficient for a specific combination of fault events and scenario features, obtained from the risk transmission knowledge graph; i represents the index variable of the specific combination of fault events and scenario features identified in the risk transmission knowledge graph. Let be the risk value corresponding to the specific fault event involved in the combination of the i-th specific fault event and scenario features. It represents the risk value corresponding to the specific scenario feature involved in the combination of the i-th specific fault event and scenario feature.
5. A dynamic safety boundary control method integrating FuSa and SOTIF according to any one of claims 1 to 4, characterized in that, Step S2 includes: S201, The comprehensive risk assessment value is input into a preset parameter mapping function to calculate the boundary value of at least one vehicle dynamic control parameter; S202, set the boundary value as a time-varying constraint in the model predictive control framework optimization problem; S203, within each control cycle, solve the optimization problem with the time-varying constraints and output the optimal control sequence that satisfies the current dynamic safety boundary.
6. The dynamic security boundary control method integrating FuSa and SOTIF according to claim 5, characterized in that, The parameter mapping function is a monotonic function, which causes the calculated boundary value to change in a more stringent direction as the comprehensive risk assessment value increases.
7. The dynamic safety boundary control method integrating FuSa and SOTIF according to claim 5, characterized in that, The vehicle dynamic control parameters include at least one of the following: minimum safe distance, maximum permissible speed in curves, and lateral safety margin.
8. The dynamic security boundary control method integrating FuSa and SOTIF according to claim 7, characterized in that, Step S202 includes: The boundary values are mapped to constraints on state variables or control input variables in the model predictive control state space; Specifically, the boundary value of the minimum safe time distance is mapped to the constraint of the vehicle's longitudinal distance, the boundary value of the maximum permissible speed on the curve is mapped to the constraint of the vehicle's longitudinal speed, and the boundary value of the lateral safety margin is mapped to the constraint of the vehicle's lateral position.
9. The dynamic safety boundary control method integrating FuSa and SOTIF according to claim 6, characterized in that, Step S3 includes: The control commands generated based on the aforementioned constraints will undergo priority arbitration and command coordination; among them, safety control commands generated to avoid coupling risks will be given higher priority than other comfort-oriented or efficiency-oriented control commands. After arbitration and instruction coordination, control commands are issued to the corresponding vehicle actuators to control the vehicle to operate within the safety boundaries.
10. A dynamic safety boundary control system integrating FuSa and SOTIF, characterized in that, include: The coupled risk identification module is configured to acquire internal parameters characterizing the functional safety status of the vehicle and external parameters characterizing the expected functional safety scenario, and calculate a comprehensive risk assessment value based on the internal and external parameters. A dynamic safety boundary calculation engine is configured to map the comprehensive risk assessment value to constraints of at least one vehicle dynamic control parameter, wherein the stringency of the constraints is positively correlated with the comprehensive risk assessment value. The coordinating actuator arbitration module is configured to generate control commands based on the mapped constraints and coordinate the actions of the vehicle actuators to keep the vehicle operating within the safety boundaries.