Method, device, system and product for analyzing expected function safety of intelligent driving function
By using the expected functional safety analysis method for intelligent driving functions, combined with HAZOP or STPA analysis, potential hazard events can be identified and assessed, thus addressing the problem of insufficient functional safety in intelligent connected vehicles and improving vehicle safety and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA FAW CO LTD
- Filing Date
- 2025-12-08
- Publication Date
- 2026-05-12
AI Technical Summary
In existing technologies, failures in the electronic and electrical systems of intelligent connected vehicles can affect vehicle safety. Relying solely on functional safety cannot completely solve the safety risks caused by insufficient expected functions or human error, and further improvements in vehicle safety are needed.
The expected functional safety analysis method for intelligent driving functions is adopted. By using HAZOP or STPA analysis, combined with target function use cases, keyword extraction and whole vehicle hazard level analysis, potential hazard events are identified and risk assessments are conducted to determine the degree of danger and controllability, thus achieving expected functional safety analysis.
It improves the safety and reliability of the intelligent driving function system, and enhances the overall safety and controllability of the vehicle through system-level fault analysis and risk assessment.
Smart Images

Figure CN122019216A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle technology, and more specifically to a method, apparatus, system, and product for predictive functional safety analysis of intelligent driving functions. Background Technology
[0002] For intelligent connected vehicles, the failure of electronic and electrical systems can affect the overall safety of the vehicle. Currently, vehicle safety management generally adopts a functional safety approach, which addresses software and hardware system failures. However, functional safety alone is insufficient; therefore, anticipated functional safety (SOTIF) is also necessary. SOTIF serves as a supplement to functional safety, and its safety risks stem from insufficient anticipated functionality or human error. Therefore, how to further improve vehicle safety through SOTIF is a crucial technical issue that the industry urgently needs to research. Summary of the Invention
[0003] This invention provides a method, apparatus, system, and product for analyzing the expected functional safety of intelligent driving functions, in order to solve the technical problem of how to further improve vehicle safety through expected functional safety, and at least provide a beneficial option or create conditions.
[0004] This invention provides a method for expected functional safety analysis of intelligent driving functions, comprising: acquiring functional use cases in intelligent driving functions, and recording the functional use cases as target functional use cases; extracting keywords from the target functional use cases to obtain target keywords; and combining the target keywords to perform system-level fault analysis on the target functional use cases using a set analysis method to obtain system-level fault performance information. Based on the fault performance information and referring to the pre-set vehicle-level hazard category table, the current vehicle hazard level is determined and recorded as the target vehicle hazard level; the scenario in which the target functional use case occurs is determined and recorded as the target scenario; based on the combined analysis of the target vehicle hazard level and the target scenario, a hazard event is obtained and recorded as the target hazard event; Based on the target hazard event, a potential danger is identified and recorded as a target potential danger; a risk analysis is performed on the target hazard event to obtain the degree of danger and the degree of controllability; the degree of danger is compared with zero to obtain a first comparison result; the degree of controllability is compared with zero to obtain a second comparison result; and an acceptance result is determined based on the first comparison result and the second comparison result.
[0005] Furthermore, the specified analytical method includes either HAZOP analysis or STPA analysis.
[0006] Furthermore, determining the acceptance result based on the first comparison result and the second comparison result specifically includes: when the first comparison result reflects that the degree of danger is greater than zero; and the second comparison result reflects that the degree of controllability is greater than zero; then the acceptance result is determined to be: unacceptable; otherwise, the acceptance result is determined to be: acceptable.
[0007] Furthermore, the expected functional safety analysis method for the intelligent driving function also includes: setting a first data unit, a second data unit, a third data unit, a fourth data unit, a fifth data unit, a sixth data unit, a seventh data unit, an eighth data unit, a ninth data unit, a tenth data unit, an eleventh data unit, and a twelfth data unit; The first data unit is used to record information about the target functional use case; the second data unit is used to record information about the target keyword; the third data unit is used to record information about the system-level fault performance; the fourth data unit is used to record information about the target vehicle hazard level; the fifth data unit is used to record information about the target scenario; the sixth data unit is used to record information about the target hazard event; the seventh data unit is used to record information about the target potential hazard; the eighth data unit is used to record information about the degree of hazard and its comparison with zero; the ninth data unit is used to record information about the first comparison result; the tenth data unit is used to record information about the degree of controllability and its comparison with zero; the eleventh data unit is used to record information about the second comparison result; and the twelfth data unit is used to record information about the acceptance result.
[0008] Furthermore, the first data unit, the second data unit, the third data unit, the fourth data unit, the fifth data unit, the sixth data unit, the seventh data unit, the eighth data unit, the ninth data unit, the tenth data unit, the eleventh data unit, and the twelfth data unit are arranged and integrated in sequence to form a data group.
[0009] On the other hand, an expected functional safety analysis device for intelligent driving functions is provided, comprising: a processor and a memory; the memory is used to store a computer-readable program; when the computer-readable program is executed by the processor, the processor causes the processor to implement the expected functional safety analysis method for intelligent driving functions as described in any of the above technical solutions.
[0010] On the other hand, a predictive functional safety analysis system for intelligent driving functions is provided, including: an acquisition module, an extraction module, an analysis module, a first determination module, a second determination module, a third determination module, and a fourth determination module; The acquisition module is used to: acquire functional use cases in the intelligent driving function, and record the functional use cases as target functional use cases; The extraction module is used to: extract keywords from the target functional use cases to obtain target keywords; The analysis module is used to: combine target keywords and perform system-level fault analysis on the target functional use cases using a set analysis method to obtain system-level fault performance information; The first determining module is used to: determine the current vehicle hazard level by comparing the fault performance information with a pre-set vehicle level hazard category table, and record the vehicle hazard level as the target vehicle hazard level; The second determining module is used to: determine the scenario in which the target functional use case occurs, and record the scenario as the target scenario; The third determining module is used to: analyze the combined hazard level of the target vehicle and the target scenario to obtain a hazard event, and record the hazard event as a target hazard event; determine potential hazards based on the target hazard event, and record the potential hazards as target potential hazards; The fourth determining module is used to: perform risk analysis on the target hazard event to obtain the degree of danger and the degree of controllability; compare the degree of danger with zero to obtain a first comparison result; compare the degree of controllability with zero to obtain a second comparison result; and determine the acceptance result based on the first comparison result and the second comparison result.
[0011] Furthermore, the specified analytical method includes either HAZOP analysis or STPA analysis.
[0012] Furthermore, in the fourth determining module, determining the acceptance result based on the first comparison result and the second comparison result specifically includes: when the first comparison result reflects that the degree of danger is greater than zero; and the second comparison result reflects that the degree of controllability is greater than zero; then the acceptance result is determined to be: unacceptable; otherwise, the acceptance result is determined to be: acceptable.
[0013] On the other hand, a computer program product is provided, including a computer program that, when executed by a processor, implements the expected functional safety analysis method for the intelligent driving function described in any of the above technical solutions.
[0014] This invention has at least the following beneficial effects: The method of this invention starts from the target functional use case, and based on the principle of hazard + scenario, analyzes and obtains hazard events by combining the target vehicle hazard with the target scenario. It then decomposes the hazard events into hazard degree and controllability degree, and performs corresponding comparisons. The acceptance result is determined by the comparison results. This achieves the expected safety analysis of functional use cases in the intelligent driving function environment, improving the safety and reliability of the entire intelligent driving function system. Simultaneously, this invention also provides corresponding devices, systems, and program products. The beneficial effects of these devices, systems, and program products are similar to those of the method, and will not be repeated here. This invention is mainly used in the field of vehicle technology. Attached Figure Description
[0015] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the technical solutions of the present invention, and do not constitute a limitation on the technical solutions of the present invention.
[0016] Figure 1 This is a flowchart illustrating the steps of the expected functional safety analysis method for intelligent driving functions; Figure 2 This is a schematic diagram of the structure of the expected functional safety analysis device for intelligent driving functions; Figure 3 This is the hardware structure of the expected functional safety analysis device for intelligent driving function in another embodiment; Figure 4 This is a schematic diagram of the system connection structure of the expected functional safety analysis system for intelligent driving functions. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0018] It should be noted that although functional modules are divided in the system diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0019] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.
[0020] HAZOP analysis, short for Hazard and Operability Study, is a structured and systematic risk assessment method. It is primarily used to identify potential deviations from the intended design in a process or system, and to analyze the resulting hazards (safety incidents) and operability issues (impacts on production efficiency and stability).
[0021] STPA analysis, short for Systems Theory Process Analysis, is a forward-looking, systems theory-based hazard analysis method. It is suitable for safety assessments of complex systems and is particularly adept at identifying interactive risks that traditional methods struggle to cover. The core idea of STPA is that accidents do not occur due to the failure of individual components, but rather because the interactions between system components are not properly controlled, leading to an unsafe state.
[0022] The main objective of this invention is to solve the technical problem of how to further improve vehicle safety through expected functional safety, thereby enhancing the safety of the entire intelligent driving function system.
[0023] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating the steps of the expected functional safety analysis method for intelligent driving functions.
[0024] To achieve this technical goal, this application discloses a method for predictive functional safety analysis of intelligent driving functions. The method for predictive functional safety analysis of intelligent driving functions can be executed by a software program. When the software program is executed, the steps it implements include: Step 1, obtaining functional use cases in intelligent driving functions and recording the functional use cases as target functional use cases.
[0025] The software program establishes a connection with the intelligent driving function system and obtains functional use cases from the corresponding interfaces of the intelligent driving function system. The expected safety of the function is determined through analysis of these functional use cases. For ease of description, the obtained functional use cases are denoted as target functional use cases.
[0026] Step 2: Extract keywords from the target functional use cases to obtain target keywords.
[0027] Once the software program has identified the target functional use cases, it can invoke a keyword extraction model to extract keywords from them, thereby identifying keywords that reflect the fault condition. For ease of description, these keywords will be referred to as target keywords.
[0028] Step 3: Combining the target keywords, perform system-level fault analysis on the target functional use cases using the established analysis method to obtain system-level fault performance information.
[0029] After obtaining the target keywords, the software program employs a pre-defined analysis method to analyze the target functional use cases in conjunction with the target keywords, considering potential deficiencies. It is noteworthy that the combination of different parts of the functional use cases with the target keywords must be considered to ensure as comprehensive a comprehensive understanding of potential functional deficiencies as possible. This step yields system-level fault performance information. The software program invokes a program model capable of executing the pre-defined analysis method and uses the corresponding program model to analyze the target keywords and target functional use cases, thereby obtaining system-level fault performance information. The analysis method integrated into the program model is either HAZOP analysis or STPA analysis. In this specific embodiment, HAZOP (Hazard and Operability Study) analysis is used.
[0030] Step 4: Based on the fault performance information, compare it with the pre-set vehicle level hazard category table to determine the current vehicle hazard level, and record the vehicle hazard level as the target vehicle hazard level.
[0031] After obtaining fault manifestation information (system level), the software program can retrieve a pre-set vehicle-level hazard category table and look up the corresponding vehicle hazard level for the fault manifestation information. This determines the hazard situation at the vehicle level. For ease of description, this vehicle hazard level is denoted as the target vehicle hazard level.
[0032] Step 5: Determine the scenario in which the target functional use case occurs, and denote the scenario as the target scenario.
[0033] Determining a hazardous event generally requires considering the context. Therefore, in this step, the software program needs to obtain the context in which the current target function use case occurs. The software program establishes a connection with the corresponding interface of the vehicle's intelligent driving function system to determine the current context. For ease of description, this context will be referred to as the target context.
[0034] Step 6: Based on the combined analysis of the target vehicle hazard level and the target scenario, obtain the hazard event and record the hazard event as the target hazard event; determine the potential hazard based on the target hazard event and record the potential hazard as the target potential hazard.
[0035] After determining the target vehicle's hazard level and the target scenario, the software program can integrate and analyze these two factors based on the principle of "hazard + scenario" to identify the corresponding hazard event. For ease of description, this hazard event is referred to as the target hazard event. Of course, to further break down and analyze the target hazard event, a potential risk analysis is also required. The software program can retrieve the corresponding analysis model and use it to analyze the potential risks of the target hazard event, thereby determining the target's potential risks.
[0036] Step 7: Perform a risk analysis on the target hazard event to obtain the degree of danger and the degree of controllability; compare the degree of danger with zero to obtain a first comparison result; compare the degree of controllability with zero to obtain a second comparison result; determine the acceptance result based on the first comparison result and the second comparison result.
[0037] After identifying the target hazard event, the software program can further analyze and break it down. Based on predefined rules, the target hazard event is decomposed into a degree of harm (S) and a degree of controllability (C). The degree of harm (S) reflects the extent of harm caused by the target hazard event, and it is generally compared to zero. When the degree of harm equals zero, it can be considered that there is no harm; when the degree of harm is greater than zero, it can be considered that there is harm. For ease of identification, after obtaining the degree of harm, the software program also compares it with zero to obtain the first comparison result.
[0038] The controllability level (C) reflects the degree to which a target hazardous event can be controlled. It is generally compared with zero. When the controllability level is equal to zero, it can be considered controllable; when the controllability level is greater than zero, it can be considered uncontrollable. For ease of identification, after obtaining the controllability level, the software also compares it with zero to obtain a second comparison result.
[0039] After obtaining the first comparison result and the second comparison result, the software program can use these results to determine whether the hazardous event reflected by the current target functional use case is acceptable. Generally, if the first comparison result reflects a hazard level greater than zero, and the second comparison result reflects a controllability level greater than zero, then the acceptance result is determined to be unacceptable; otherwise, the acceptance result is determined to be acceptable.
[0040] This invention analyzes hazard events by starting with target functional use cases and applying the principle of hazard + scenario. It combines the hazards of the entire vehicle with the hazards of the target scenario to identify hazard events. The hazard events are then decomposed into severity and controllability levels and compared accordingly. The acceptance outcome is determined based on the comparison results. This achieves the expected safety analysis of functional use cases within the intelligent driving function environment, improving the safety and reliability of the entire intelligent driving function system.
[0041] To facilitate the retrieval of the entire data, in some further specific embodiments, the expected functional safety analysis method for intelligent driving functions further includes: setting a first data unit, a second data unit, a third data unit, a fourth data unit, a fifth data unit, a sixth data unit, a seventh data unit, an eighth data unit, a ninth data unit, a tenth data unit, an eleventh data unit, and a twelfth data unit.
[0042] These data units are used to store information used throughout the analysis process, facilitating subsequent retrieval. Specifically, the first data unit records information about the target functional use case; the second data unit records information about the target keywords; the third data unit records system-level fault performance information; the fourth data unit records information about the target vehicle hazard level; the fifth data unit records information about the target scenario; the sixth data unit records information about the target hazardous event; the seventh data unit records information about the target potential hazard; the eighth data unit records the degree of hazard and its comparison with zero; the ninth data unit records information about the first comparison result; the tenth data unit records information about the degree of controllability and its comparison with zero; the eleventh data unit records information about the second comparison result; and the twelfth data unit records information about the accepted result.
[0043] To facilitate searching, the first data unit, the second data unit, the third data unit, the fourth data unit, the fifth data unit, the sixth data unit, the seventh data unit, the eighth data unit, the ninth data unit, the tenth data unit, the eleventh data unit, and the twelfth data unit are arranged and integrated in sequence to form a data group.
[0044] refer to Figure 2 , Figure 2 This is a schematic diagram of the structure of the expected functional safety analysis device for intelligent driving functions.
[0045] On the other hand, a device for analyzing the expected functional safety of intelligent driving functions is provided, comprising: a processor and a memory, wherein the memory is used to store a computer-readable program. When the computer-readable program is executed by the processor, the processor causes the processor to implement the method for analyzing the expected functional safety of intelligent driving functions as described in any of the above specific embodiments.
[0046] Those skilled in the art will understand that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. As is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0047] Please see Figure 3 , Figure 3 This is another embodiment of the hardware structure of the expected functional safety analysis device for intelligent driving functions. The expected functional safety analysis device for intelligent driving functions includes: a processor 901, a memory 902, an input / output interface 903, a communication interface 904, and a bus 905.
[0048] The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the expected functional safety analysis method of the intelligent driving function provided in the embodiments of this application.
[0049] The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the methods described in the embodiments of this application.
[0050] The input / output interface 903 is used to implement information input and output.
[0051] The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0052] Bus 905 transmits information between various components of the device, such as processor 901, memory 902, input / output interface 903, and communication interface 904.
[0053] The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.
[0054] refer to Figure 4 , Figure 4 This is a schematic diagram of the system connection structure of the expected functional safety analysis system for intelligent driving functions.
[0055] A system for analyzing the expected functional safety of intelligent driving functions is provided, comprising: an acquisition module, an extraction module, an analysis module, a first determination module, a second determination module, a third determination module, and a fourth determination module; The acquisition module is used to: acquire functional use cases in the intelligent driving function, and record the functional use cases as target functional use cases.
[0056] The acquisition module establishes a connection with the intelligent driving function system and retrieves functional use cases from the corresponding interfaces of the intelligent driving function system. The expected safety of the function is determined through analysis of these functional use cases. For ease of description, the obtained functional use cases are denoted as target functional use cases.
[0057] The extraction module is used to: extract keywords from the target functional use cases to obtain target keywords.
[0058] Once the extraction module has identified the target functional use cases, it can invoke the keyword extraction model to extract keywords from them, thereby identifying keywords that reflect the fault condition. For ease of description, these keywords will be referred to as target keywords.
[0059] The analysis module is used to: combine target keywords and perform system-level fault analysis on the target functional use cases using a set analysis method to obtain system-level fault performance information.
[0060] After obtaining the target keywords, the analysis module uses a pre-defined analysis method to analyze the target functional use cases, considering potential deficiencies. It is noteworthy that the combination of different parts of the functional use cases with the target keywords must be considered to ensure as comprehensive a comprehensive understanding of potential functional deficiencies as possible. This step yields system-level fault performance information. The analysis module invokes a program model capable of executing the pre-defined analysis method and uses the corresponding program model to analyze the target keywords and target functional use cases, thereby obtaining system-level fault performance information. The analysis method integrated into the program model is either HAZOP analysis or STPA analysis. In this specific embodiment, HAZOP (Hazard and Operability Study) analysis is used.
[0061] The first determining module is used to: determine the current vehicle hazard level by comparing the fault performance information with a pre-set vehicle level hazard category table, and record the vehicle hazard level as the target vehicle hazard level.
[0062] After obtaining the fault manifestation information (system level), the first determining module can retrieve a pre-set vehicle-level hazard category table and look up the vehicle hazard level corresponding to the fault manifestation information. This determines the hazard situation at the vehicle level. For ease of description, this vehicle hazard level is denoted as the target vehicle hazard level.
[0063] The second determining module is used to: determine the scenario in which the target functional use case occurs, and record the scenario as the target scenario.
[0064] The determination of a hazardous event generally requires consideration of the context. Therefore, the second determination module needs to obtain the context in which the current target functional use case occurs. This second determination module establishes a connection with the corresponding interface of the vehicle's intelligent driving function system to determine the current context. For ease of description, this context will be referred to as the target context.
[0065] The third determining module is used to: analyze the combined hazard level of the target vehicle and the target scenario to obtain a hazard event, and record the hazard event as a target hazard event; determine potential hazards based on the target hazard event, and record the potential hazards as target potential hazards.
[0066] After determining the hazard level and target scenario of the target vehicle, the third determination module can integrate and analyze these two factors based on the principle of hazard + scenario to identify the corresponding hazard event. For ease of description, this hazard event is referred to as the target hazard event. Of course, to further break down and analyze the target hazard event, a potential risk analysis is also required. The third determination module can retrieve the corresponding analysis model to perform a potential analysis of the target hazard event, thereby determining the potential risk of the target.
[0067] The fourth determining module is used to: perform risk analysis on the target hazard event to obtain the degree of danger and the degree of controllability; compare the degree of danger with zero to obtain a first comparison result; compare the degree of controllability with zero to obtain a second comparison result; and determine the acceptance result based on the first comparison result and the second comparison result.
[0068] After identifying the target hazard event, the fourth determination module can further analyze and break it down. Based on predefined rules, the target hazard event is broken down into hazard level (S) and controllability level (C). Hazard level (S) reflects the degree of harm caused by the target hazard event, and is generally compared to zero. When the hazard level equals zero, it can be considered that there is no harm; when the hazard level is greater than zero, it can be considered that there is harm. For ease of identification, after obtaining the hazard level, the software program also compares it with zero to obtain the first comparison result.
[0069] The controllability level (C) reflects the degree to which a target hazardous event can be controlled. It is generally compared with zero. When the controllability level is equal to zero, it can be considered controllable; when the controllability level is greater than zero, it can be considered uncontrollable. For ease of identification, after obtaining the controllability level, the software also compares it with zero to obtain a second comparison result.
[0070] After obtaining the first comparison result and the second comparison result, the fourth determining module can use these results to determine whether the hazard event reflected by the current target functional use case is acceptable. Generally, if the first comparison result reflects a hazard level greater than zero, and the second comparison result reflects a controllability level greater than zero, then the acceptance result is determined to be unacceptable; otherwise, the acceptance result is determined to be acceptable.
[0071] To facilitate access to the entire data, in some further specific embodiments, the expected functional safety analysis system for intelligent driving functions also includes a storage module, which is used to set a first data unit, a second data unit, a third data unit, a fourth data unit, a fifth data unit, a sixth data unit, a seventh data unit, an eighth data unit, a ninth data unit, a tenth data unit, an eleventh data unit, and a twelfth data unit.
[0072] These data units are used to store information used throughout the analysis process, facilitating subsequent retrieval. Specifically, the first data unit records information about the target functional use case; the second data unit records information about the target keywords; the third data unit records system-level fault performance information; the fourth data unit records information about the target vehicle hazard level; the fifth data unit records information about the target scenario; the sixth data unit records information about the target hazardous event; the seventh data unit records information about the target potential hazard; the eighth data unit records the degree of hazard and its comparison with zero; the ninth data unit records information about the first comparison result; the tenth data unit records information about the degree of controllability and its comparison with zero; the eleventh data unit records information about the second comparison result; and the twelfth data unit records information about the accepted result.
[0073] To facilitate searching, the first data unit, the second data unit, the third data unit, the fourth data unit, the fifth data unit, the sixth data unit, the seventh data unit, the eighth data unit, the ninth data unit, the tenth data unit, the eleventh data unit, and the twelfth data unit are arranged and integrated in sequence to form a data group.
[0074] On the other hand, a computer-readable storage medium is provided, wherein a processor-executable program is stored, which, when executed by a processor, is used to implement the expected functional safety analysis method for intelligent driving functions as described in any of the above specific embodiments.
[0075] This application also discloses a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. The processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the expected functional safety analysis method for the intelligent driving function as described in any of the preceding embodiments.
[0076] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatuses.
[0077] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0078] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, apparatuses, or units, and may be electrical, mechanical, or other forms.
[0079] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0080] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0081] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0082] Although the description of this application has been quite detailed and particularly focused on several of the described embodiments, it is not intended to limit itself to any of these details or embodiments or any particular embodiment. Rather, it should be considered as effectively covering the intended scope of this application by referring to the appended claims and taking into account the prior art, which provides for a broad possible interpretation of these claims. Furthermore, the foregoing description of this application with respect to embodiments foreseeable by the inventors is intended to provide a useful description, and non-substantial modifications to this application that have not yet been foreseen may still represent equivalent modifications.
[0083] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
Claims
1. A method for predictive functional safety analysis of intelligent driving functions, characterized in that, include: Obtain the functional use cases in the intelligent driving function, and denote the functional use cases as the target functional use cases; Keyword extraction is performed on the target functional use cases to obtain target keywords; By combining the target keywords and using the established analysis method, system-level fault analysis is performed on the target functional use cases to obtain system-level fault performance information; Based on the fault performance information, the current vehicle hazard level is determined by comparing it with a pre-set vehicle level hazard category table, and the vehicle hazard level is recorded as the target vehicle hazard level. Identify the scenario in which the target functional use case occurs, and denote the scenario as the target scenario; Based on the combined analysis of the target vehicle hazard level and the target scenario, a hazard event is obtained, and the hazard event is recorded as the target hazard event; Based on the target hazard event, potential hazards are identified, and these potential hazards are recorded as target potential hazards. A risk analysis is performed on the target hazardous event to determine its degree of danger and controllability. The degree of danger is compared with zero to obtain the first comparison result; The controllability level is compared with zero to obtain a second comparison result; The acceptance result is determined based on the first comparison result and the second comparison result.
2. The method for predictive functional safety analysis of intelligent driving functions according to claim 1, characterized in that, The analytical methods specified include: HAZOP analysis or STPA analysis.
3. The method for predictive functional safety analysis of intelligent driving functions according to claim 1, characterized in that, The determination of the acceptance result based on the first comparison result and the second comparison result specifically includes: when the first comparison result reflects that the degree of danger is greater than zero; and the second comparison result reflects that the degree of controllability is greater than zero; then the acceptance result is determined to be: unacceptable; otherwise, the acceptance result is determined to be: acceptable.
4. The method for predictive functional safety analysis of intelligent driving functions according to claim 1, characterized in that, Also includes: Set up the first data unit, the second data unit, the third data unit, the fourth data unit, the fifth data unit, the sixth data unit, the seventh data unit, the eighth data unit, the ninth data unit, the tenth data unit, the eleventh data unit, and the twelfth data unit; The first data unit is used to record information about the target functional use case; the second data unit is used to record information about the target keyword; the third data unit is used to record information about the system-level fault performance; the fourth data unit is used to record information about the target vehicle hazard level; the fifth data unit is used to record information about the target scenario; the sixth data unit is used to record information about the target hazard event; the seventh data unit is used to record information about the target potential hazard; the eighth data unit is used to record the degree of hazard and its comparison with zero; and the ninth data unit is used to record information about the first comparison result. The tenth data unit is used to record the degree of controllability and its comparison with zero; the eleventh data unit is used to record the information of the second comparison result; and the twelfth data unit is used to record the information of the acceptance result.
5. The method for predictive functional safety analysis of intelligent driving functions according to claim 1, characterized in that, The first, second, third, fourth, fifth, sixth, seventh, eighth, ninth, tenth, eleventh, and twelfth data units are arranged and integrated in sequence to form a data group.
6. A device for analyzing the expected functional safety of intelligent driving functions, characterized in that, include: processor; Memory, used to store computer-readable programs; When the computer-readable program is executed by the processor, the processor implements the expected functional safety analysis method for intelligent driving functions as described in any one of claims 1-5.
7. A predictive functional safety analysis system for intelligent driving functions, characterized in that, include: The module includes an acquisition module, an extraction module, an analysis module, a first determination module, a second determination module, a third determination module, and a fourth determination module. The acquisition module is used to: acquire functional use cases in the intelligent driving function, and record the functional use cases as target functional use cases; The extraction module is used to: extract keywords from the target functional use cases to obtain target keywords; The analysis module is used to: combine target keywords and perform system-level fault analysis on the target functional use cases using a set analysis method to obtain system-level fault performance information; The first determining module is used to: determine the current vehicle hazard level by comparing the fault performance information with a pre-set vehicle level hazard category table, and record the vehicle hazard level as the target vehicle hazard level; The second determining module is used to: determine the scenario in which the target functional use case occurs, and record the scenario as the target scenario; The third determining module is used to: analyze the combination of the target vehicle hazard level and the target scenario to obtain a hazard event, and record the hazard event as a target hazard event; Based on the target hazard event, potential hazards are identified, and these potential hazards are recorded as target potential hazards. The fourth determining module is used to: perform risk analysis on the target hazard event to obtain the degree of danger and the degree of controllability; compare the degree of danger with zero to obtain a first comparison result; The controllability level is compared with zero to obtain a second comparison result; The acceptance result is determined based on the first comparison result and the second comparison result.
8. The expected functional safety analysis system for intelligent driving functions according to claim 7, characterized in that, The analytical methods specified include: HAZOP analysis or STPA analysis.
9. The expected functional safety analysis system for intelligent driving functions according to claim 7, characterized in that, In the fourth determination module, determining the acceptance result based on the first comparison result and the second comparison result specifically includes: when the first comparison result reflects that the degree of danger is greater than zero; and the second comparison result reflects that the degree of controllability is greater than zero; then the acceptance result is determined to be: unacceptable; otherwise, the acceptance result is determined to be: acceptable.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the expected functional safety analysis method for the intelligent driving function as described in any one of claims 1 to 5.