Emergency state control method and system for vehicle function safety test
By providing automatic and manual emergency triggering paths in vehicle functional safety testing, the risks to vehicle and personnel safety during testing are addressed, and safety control under extreme conditions is achieved, ensuring the safety and controllability of the vehicle in emergency situations.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DEEPAL AUTOMOBILE TECH CO LTD
- Filing Date
- 2026-02-26
- Publication Date
- 2026-05-01
AI Technical Summary
Current vehicle functional safety tests do not adequately consider safety protection in emergency situations, posing significant safety risks and impacting the safety of vehicles and test personnel.
Two independent emergency triggering paths are provided: an automatic triggering path based on status monitoring and communication control, and a manual triggering path based on physical cut-off operation. The host computer monitors the vehicle status and automatically triggers safety control operations, or the low-voltage power supply is manually cut off through a physical emergency stop switch to ensure vehicle safety.
It effectively ensures the safety of vehicles during functional safety testing, especially under extreme failure conditions, ensuring the safety of the driver and the vehicle, and providing a dual safety protection mechanism of automatic and manual operation.
Smart Images

Figure CN121956972A_ABST
Abstract
Description
An emergency control method and system for vehicle functional safety testing Technical Field
[0001] This application relates to the field of vehicle functional testing, specifically to an emergency state control method and system for vehicle functional safety testing. Background Technology
[0002] Vehicle functional testing, as the final step in functional safety development, is a fundamental guarantee supporting high-quality industrial development and technological innovation. It also ensures thorough preparation for meeting the stringent verification requirements necessary for product regulatory approval and large-scale commercialization. Vehicle functional testing comprises three main aspects: hardware and software integration testing, system integration testing, and vehicle functional safety integration testing. Vehicle functional safety integration testing involves integrating relevant components into the vehicle and conducting tests in a real-world vehicle environment. In the V-model development process, testing verifies and confirms the development content; therefore, vehicle functional safety testing is a crucial component of vehicle testing and a vital means of verifying the correct implementation of safety requirements or strategies.
[0003] However, existing vehicle functional safety testing technologies focus primarily on functional safety test case design and testing methodologies, neglecting to address the control of testing risks. Vehicle functional safety testing, including fault injection, boundary value analysis, and error guessing, often involves extreme conditions, posing significant safety risks not only to the vehicle but also to the personal safety of test personnel. Therefore, prioritizing the safety of both the vehicle and personnel, and developing emergency control measures for vehicle functional safety testing, is a crucial priority. Summary of the Invention
[0004] This invention provides an emergency state control method and system for vehicle functional safety testing, which addresses the issue that vehicle safety protection in emergency states is not considered during vehicle functional safety testing.
[0005] The technical solution of this invention is as follows:
[0006] Firstly, this application provides an emergency state control method for vehicle functional safety testing, comprising:
[0007] During the process of simulating vehicle functional safety testing, at least two independent emergency state triggering paths are provided: an automatic triggering path based on status monitoring and communication control, and a manual triggering path based on physical disconnection operation.
[0008] In response to an emergency control command triggered via any triggering path, the corresponding safety control operation is executed to bring the simulated test vehicle into a safe state.
[0009] The host computer determines the vehicle's emergency status and automatically triggers a path, enabling signal tampering and vehicle safety status control based on the communication link layer. This allows for immediate triggering of safety mechanisms to ensure the safety of the driver and vehicle. Simultaneously, a manual trigger path provides effective backup and redundancy, physically cutting off low-voltage power to hard-stop the entire test emergency, further ensuring the vehicle remains under driver control. These two independent safety trigger paths and independent response mechanisms ensure the safety of the vehicle and personnel during functional safety testing, especially under extreme failure conditions.
[0010] The automatic trigger path is configured as follows:
[0011] The measured values of the target observations in the test cases currently being executed by the simulated test vehicle are monitored by the host computer.
[0012] When the measured value of the target observation does not match the corresponding test threshold, it is determined that the simulated test vehicle is still in an emergency state, and the emergency state control command is automatically issued.
[0013] The steps for executing the corresponding safety control operation in response to an emergency control command triggered via any triggering path, so as to bring the simulated test vehicle into a safe state, include:
[0014] In response to an emergency control command triggered via the automatic triggering path, the communication link between the intelligent driving system of the simulated test vehicle and external devices is cut off.
[0015] After the communication link is cut off, if it is determined that the simulated test vehicle is still in an emergency state, a preset collision signal is injected into the simulated test vehicle through a fault injection device to trigger the simulated test vehicle to interrupt power output.
[0016] Based on multiple predefined test observations related to vehicle emergency states, target observations are selected from the test cases currently being executed by the simulated test vehicle.
[0017] The target observation is one or more of the multiple test observations.
[0018] When the target observation is a first-category target observation with a numerical value, if the deviation between the measured value of the target observation and the corresponding test threshold exceeds a preset percentage, it is determined that the measured value of the target observation does not match the corresponding test threshold.
[0019] When the target observation is a second-category target observation with a state, if the measured value of the target observation and the corresponding test threshold are different, it is determined that the measured value of the target observation and the corresponding test threshold do not match.
[0020] The process of triggering the interruption of power output of the simulated test vehicle includes: triggering the power system of the simulated test vehicle to stop torque output, and triggering the battery system of the simulated test vehicle to cut off high voltage output.
[0021] The manual trigger path is configured as follows:
[0022] Emergency control commands are generated in response to the tester's operation of the physical emergency stop switch.
[0023] The steps for executing the corresponding safety control operation in response to an emergency control command triggered via any triggering path, so as to bring the simulated test vehicle into a safe state, include:
[0024] In response to an emergency control command generated via the manually triggered path, the low-voltage power supply to at least one associated control unit in the intelligent driving system and power system of the simulated test vehicle is cut off, thereby interrupting the power output of the simulated test vehicle.
[0025] Secondly, this application also provides an emergency state control system for vehicle functional safety testing, including: a host computer, a fault injection device, and a physical emergency stop switch;
[0026] The host computer is configured to connect to the communication network of the simulated test vehicle and is used to monitor the measured values of the target observations in the test cases currently being executed by the simulated test vehicle during the vehicle functional safety test. When it is confirmed that the simulated test vehicle is handling an emergency state because the measured value of the target observation does not match the corresponding test threshold, an emergency state control command is issued.
[0027] The fault injection device is communicatively connected to the host computer and serially connected to the vehicle's communication network. It is configured to respond to the emergency state control command and perform safety control operations on the vehicle to bring the simulated test vehicle into a safe state.
[0028] The physical emergency stop switch is connected in series between the vehicle's low-voltage power supply and the power supply line of at least one associated control unit, the associated control unit including at least one of an intelligent driving control unit and a powertrain control unit; the physical emergency stop switch is configured to physically disconnect the low-voltage power supply to the at least one associated control unit in response to manual operation by an operator.
[0029] In some embodiments, target observations are selected from the test cases currently being executed by the simulated test vehicle based on a number of predefined test observations related to a vehicle emergency state.
[0030] The target observation is one or more of the multiple test observations. Attached Figure Description
[0031] Figure 1 is a flowchart illustrating the emergency state control method for vehicle functional safety testing in an embodiment of this application.
[0032] Figure 2 is a structural block diagram of the vehicle functional safety test emergency control device in the embodiment of this application. Detailed Implementation
[0033] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0034] Referring to Figure 1, an embodiment of this application provides an emergency state control method for vehicle functional safety testing, including:
[0035] S101 provides at least two independent emergency state triggering paths during the process of simulating a test vehicle performing vehicle functional safety testing: an automatic triggering path based on status monitoring and communication control, and a manual triggering path based on physical disconnection operation.
[0036] S102, in response to an emergency control command triggered by any triggering path, executes the corresponding safety control operation to bring the simulated test vehicle into a safe state.
[0037] Vehicle functional safety testing is a complete verification process in which an automated testing system led by a host computer injects simulated faults into the electronic and electrical systems of a test vehicle, and monitors and verifies in real time whether the vehicle can correctly trigger safety mechanisms and enter a safe state in accordance with the predetermined safety requirements of the corresponding standards. The host computer parses and executes pre-written test case scripts sequentially, translating abstract test steps (such as simulating a wheel speed sensor signal short-circuiting to ground for 100ms) into low-level commands that the fault injector can recognize. The host computer sends these commands to the fault injector precisely and at precise intervals via communication lines (such as Ethernet or USB). The fault injector uses its internal hardware relays, analog switches, power loads, and message interference chips to precisely interfere with the system under test on the simulated test vehicle. For example, it can actually short-circuit a sensor line to the power supply or ground to create a real voltage drop; it can actually insert error frames into the CAN bus, modify specific message data, or take an ECU offline. Subsequently, each monitor (such as an oscilloscope, torque sensor, or bus monitor) performs its own monitoring work, and the monitored data is uploaded to the central software of the host computer in real time or in blocks through their respective interfaces (Ethernet, GPIB, USB).
[0038] In this embodiment of the application, the automatic triggering path based on status monitoring and communication control is specifically configured as follows:
[0039] The measured values of the target observations in the test cases currently being executed by the simulated test vehicle are monitored by the host computer.
[0040] When the measured value of the target observation does not match the corresponding test threshold, it is determined that the simulated test vehicle is still in an emergency state, and the emergency state control command is automatically issued.
[0041] Among them, target observations are selected from the test cases currently being executed by the simulated test vehicle, based on multiple predefined test observations related to vehicle emergency states;
[0042] The target observation is one or more of the multiple test observations.
[0043] Among them, the predefined test observations related to vehicle emergency states are a set of key performance indicators and signals used in functional safety testing to proactively identify whether a simulated test vehicle is entering or about to enter an unexpected dangerous physical state in real time. These test observations are typically not dependent on specific test case logic, but are defined based on general safety principles of vehicle dynamics, system thermal management, electrical safety, and functional logic. Examples include: vehicle dynamics safety data such as lateral acceleration, brake master cylinder pressure, brake master cylinder deceleration, drive motor torque, and wheel speed difference; system thermal management and electrical safety data such as high-voltage battery pack temperature, drive motor temperature, and high-voltage circuit insulation resistance; and functional logic safety data such as conflicting combinations of safety-critical DTCs in diagnostic messages, illegal jumps in the safety state machine, and inconsistencies between critical actuator states and instructions.
[0044] Each test case records the relevant threshold values for the corresponding observations.
[0045] In this embodiment of the application, when the target observation is a first category target observation with a numerical value, if the deviation between the measured value of the target observation and the corresponding test threshold exceeds a preset percentage, it is determined that the measured value of the target observation does not match the corresponding test threshold.
[0046] When the target observation is a second-category target observation with a state, if the measured value of the target observation and the corresponding test threshold are different, it is determined that the measured value of the target observation and the corresponding test threshold do not match.
[0047] Specifically, for the first category of target observations, when comparing the real-time measured values of the target observations with a pre-set safety threshold, the percentage of relative deviation between the two is calculated. If this percentage deviation exceeds another preset allowable fluctuation range, the current state is determined to be mismatched with the expected safety range, regardless of whether the measured value is higher or lower than the threshold. This effectively avoids the problem of poor adaptability to observations of different magnitudes due to fixed tolerances, and can simultaneously warn of both performance degradation and abnormal enhancement risks, thereby achieving more sensitive and configurable abnormal state detection.
[0048] Taking the testing of an electronic power steering system as an example, the safe threshold for output torque in the test cases is set to no more than 5 Nm. The preset allowable deviation percentage is 20%. If the measured torque of the system reaches 6 Nm during the test, its deviation from the threshold is calculated to be 1 Nm, with a deviation percentage of 20%. Since this value equals the preset percentage, the system determines that it matches, and the test continues. If the measured torque rises to 6.1 Nm, the deviation percentage is 22%, which exceeds the 20% allowable range. At this point, the system immediately determines that the torque state is abnormal and does not match the safe threshold. It then automatically triggers an emergency control command, cuts off the power steering, and activates an alarm to prevent handling hazards caused by excessive steering torque.
[0049] For the second category of target observations, let's take the monitoring of driving mode status in an autonomous driving system as an example. A predefined safety test threshold requires that when a perception sensor malfunctions severely, the system must switch from autonomous driving mode to a minimum-risk state. During testing, after the host computer injects a perception failure fault, it continuously monitors the target observation of the driving mode status. If the actual measured state is still autonomous driving mode, or erroneously switches to manual mode, this is fundamentally different from the minimum-risk state threshold requirement and is immediately judged as a state mismatch.
[0050] In this embodiment of the application, the step of executing a corresponding safety control operation in response to an emergency control command triggered by any triggering path, so as to bring the simulated test vehicle into a safe state, includes:
[0051] In response to an emergency control command triggered via the automatic triggering path, the communication link between the intelligent driving system of the simulated test vehicle and external devices is cut off.
[0052] After the communication link is cut off, if it is determined that the simulated test vehicle is still in an emergency state, a preset collision signal is injected into the simulated test vehicle through a fault injection device to trigger the simulated test vehicle to interrupt power output.
[0053] Upon receiving an emergency control command, the fault injection device triggers safety measures, including suspending the communication link between the intelligent driving system and the outside world. If the vehicle's emergency situation does not change significantly, the fault injection device will continue to trigger a second layer of safety mechanism. This involves modifying the current collision-related signals of the vehicle to emit collision signals that affect the vehicle's power. Upon receiving the collision signal, the torque control unit of the simulated test vehicle immediately enters a drive output stop state, thus ensuring the interruption of abnormal power output. Simultaneously, the power battery unit of the simulated test vehicle performs a high-voltage cutoff operation, providing further protection for stopping power output.
[0054] In the above automatic triggering path, for abnormal emergency states that occur during vehicle testing, the above safety path can first trigger relevant safety measures from the source end - intelligent driving system, and then trigger relevant safety measures from the execution end - power system. The power system end includes two levels, torque control unit and high voltage energy unit, to perform synchronous interruption operations, thereby further ensuring that the vehicle emergency state can be effectively controlled.
[0055] In this embodiment of the application, the manual trigger path is configured as follows:
[0056] Emergency control commands are generated in response to the tester's operation of the physical emergency stop switch.
[0057] At this time, in response to an emergency control command triggered via any triggering path, the steps for executing the corresponding safety control operation to bring the simulated test vehicle into a safe state include:
[0058] In response to an emergency control command generated via the manually triggered path, the low-voltage power supply to at least one associated control unit in the intelligent driving system and power system of the simulated test vehicle is cut off, thereby interrupting the power output of the simulated test vehicle.
[0059] When the emergency switch is pressed, the vehicle's relevant systems will lose low-voltage power supply. The intelligent driving system will exit control of the vehicle due to the stop of low-voltage power supply, thus stopping the abnormal control state at the source. The power system will also stop the output of the drive torque control unit due to the stop of low-voltage power supply, thus interrupting the abnormal power output of the vehicle. The intelligent driving system and the power system will simultaneously exit control of the vehicle, the test personnel will take over, and the vehicle will exit the emergency state.
[0060] Compared to automatic triggering paths, manual triggering paths rely on the driver's reaction and are based on the failure or delay of automatic triggering paths. When the driver realizes that the vehicle is out of control or that there is a test risk, he will actively press the emergency stop switch of the simulated test vehicle, causing the relevant systems of the simulated test vehicle to lose low-voltage power supply.
[0061] Referring to Figure 2, this application embodiment also provides an emergency state control system for vehicle functional safety testing, including: a host computer, a fault injection device, and a physical emergency stop switch;
[0062] The host computer is configured to connect to the communication network of the simulated test vehicle and is used to monitor the measured values of the target observations in the test cases currently being executed by the simulated test vehicle during the vehicle functional safety test. When it is confirmed that the simulated test vehicle is handling an emergency state because the measured value of the target observation does not match the corresponding test threshold, an emergency state control command is issued.
[0063] The fault injection device is communicatively connected to the host computer and serially connected to the vehicle's communication network. It is configured to respond to the emergency state control command and perform safety control operations on the vehicle to bring the simulated test vehicle into a safe state.
[0064] The physical emergency stop switch is connected in series between the vehicle's low-voltage power supply and the power supply line of at least one associated control unit, the associated control unit including at least one of an intelligent driving control unit and a powertrain control unit; the physical emergency stop switch is configured to physically disconnect the low-voltage power supply to the at least one associated control unit in response to manual operation by an operator.
[0065] The host computer is a device that connects to the fault injection device, collects vehicle status signals, and determines the vehicle's emergency status. The host computer provides a user interface for functional safety testing, which can display the corresponding fault injection interface, signal or message operation management, and software flashing functions for the fault injection device. During the test, the vehicle's status, test execution, and judgment are all completed by the host computer according to instructions.
[0066] Fault injection devices serve as serial connections between controllers and the bus. They are connected in series between different controllers and are responsible for processing signals or messages in the communication network during operation.
[0067] The emergency stop switch is connected in series between each associated controller of the simulated test vehicle and the low-voltage power supply. The emergency stop switch is used to control the low-voltage power supply of the intelligent driving control unit and the power system unit.
[0068] The necessary tooling harnesses include the physical connections of the entire system, including the communication network physical layer, low-voltage power supply lines, and upper computer data acquisition harnesses.
[0069] Among them, target observations are selected from the test cases currently being executed by the simulated test vehicle, based on multiple predefined test observations related to vehicle emergency states;
[0070] The target observation is one or more of the multiple test observations.
[0071] It should be understood that the application of this application is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims. Those skilled in the art can understand that implementing all or part of the processes of the above embodiments and making equivalent changes according to the claims of this application still fall within the scope of this application.
Claims
1. An emergency state control method for vehicle functional safety testing, characterized in that... This includes providing at least two independent emergency triggering paths during the process of simulating vehicle functional safety testing: an automatic triggering path based on status monitoring and communication control, and a manual triggering path based on physical disconnection operations. In response to an emergency control command triggered via any triggering path, the corresponding safety control operation is executed to bring the simulated test vehicle into a safe state.
2. The emergency state control method for vehicle functional safety testing according to claim 1, characterized in that... The automatic triggering path is configured as follows: the host computer monitors the measured values of the target observations in the test cases currently being executed by the simulated test vehicle; when the measured values of the target observations do not match the corresponding test thresholds, the simulated test vehicle is determined to still be in an emergency state, and the emergency state control command is automatically issued.
3. The emergency state control method for vehicle functional safety testing according to claim 2, characterized in that... The steps for executing corresponding safety control operations in response to an emergency control command triggered via any triggering path to bring the simulated test vehicle into a safe state include: in response to the emergency control command triggered via the automatic triggering path, disconnecting the communication link between the intelligent driving system of the simulated test vehicle and external devices; after disconnecting the communication link, if it is determined that the simulated test vehicle is still in an emergency state, injecting a preset collision signal into the simulated test vehicle through a fault injection device to trigger the simulated test vehicle to interrupt power output.
4. The emergency state control method for vehicle functional safety testing according to claim 2 or 3, characterized in that... Based on multiple predefined test observations related to vehicle emergency states, target observations are selected from the test cases currently being executed by the simulated test vehicle. The target observation is one or more of the multiple test observations.
5. The emergency state control method for vehicle functional safety testing according to claim 4, characterized in that... When the target observation is a first-category target observation with a numerical value, if the deviation ratio between the measured value of the target observation and the corresponding test threshold exceeds a preset ratio, it is determined that the measured value of the target observation does not match the corresponding test threshold; when the target observation is a second-category target observation with a state, if the state between the measured value of the target observation and the corresponding test threshold is different, it is determined that the measured value of the target observation does not match the corresponding test threshold.
6. The emergency state control method for vehicle functional safety testing according to claim 3, characterized in that... The process of triggering the interruption of power output of the simulated test vehicle includes: triggering the power system of the simulated test vehicle to stop torque output, and triggering the battery system of the simulated test vehicle to cut off high voltage output.
7. The emergency state control method for vehicle functional safety testing according to claim 1, characterized in that... The manual trigger path is configured to generate an emergency control command in response to the tester's operation of the physical emergency stop switch.
8. The emergency state control method for vehicle functional safety testing according to claim 7, characterized in that, The step of executing a corresponding safety control operation in response to an emergency control command triggered by any triggering path to bring the simulated test vehicle into a safe state includes: in response to the emergency control command generated by the manual triggering path, cutting off the low-voltage power supply to at least one associated control unit in the intelligent driving system and power system of the simulated test vehicle, thereby interrupting the power output of the simulated test vehicle.
9. An emergency control system for vehicle functional safety testing, characterized in that, include: Host computer, fault injection device and physical emergency stop switch; The host computer is configured to connect to the communication network of the simulated test vehicle. During the performance of vehicle functional safety testing on the simulated test vehicle, it monitors the measured values of target observations in the currently executed test cases. When the simulated test vehicle is confirmed to be in an emergency state due to a mismatch between the measured value of the target observation and the corresponding test threshold, it issues an emergency state control command. The fault injection device is communicatively connected to the host computer and connected in series in the vehicle's communication network. It is configured to respond to the emergency state control command and perform safety control operations on the vehicle to bring the simulated test vehicle into a safe state. The physical emergency stop switch is connected in series between the vehicle's low-voltage power supply and the power supply line of at least one associated control unit, which includes at least one of an intelligent driving control unit and a powertrain control unit. The physical emergency stop switch is configured to physically disconnect the low-voltage power supply to the at least one associated control unit in response to manual operation by the operator.
10. The emergency control system for vehicle functional safety testing according to claim 9, characterized in that, Based on multiple predefined test observations related to vehicle emergency states, target observations are selected from the test cases currently being executed by the simulated test vehicle. The target observation is one or more of the multiple test observations.