AEB optimization method, system and device based on expected function safety analysis and medium
By constructing a vehicle control model and analysis strategy, potential hazardous events of the AEB function were identified and optimized, which solved the shortcomings of the AEB automatic emergency braking function in terms of expected functional safety and achieved accurate risk positioning and traceable optimization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA FAW CO LTD
- Filing Date
- 2025-12-09
- Publication Date
- 2026-05-15
AI Technical Summary
In the existing technology, the optimization of the AEB automatic emergency braking function in terms of expected functional safety is insufficient, resulting in potential safety risks not being effectively addressed.
By constructing a vehicle control model, we identify hazardous events in the architectural elements of the braking function, use functional and behavioral analysis strategies to determine the acceptability of hazardous events, analyze potential functional deficiencies and triggering conditions, determine optimization strategies for the braking function, form an optimization database, and execute optimization strategies.
It enables precise risk identification and traceability of AEB functions before hazards occur, eliminates risk omissions, and provides a clear optimization path.
Smart Images

Figure CN122043929A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle technology, and in particular to an AEB optimization method, system, device and medium based on expected functional safety analysis. Background Technology
[0002] SOTIF (Safety Intended for Functional Functions) complements functional safety. While functional safety addresses hardware and software system failures, SOTIF-related safety risks in vehicles stem from insufficient anticipated functionality or human error. In the passenger vehicle sector, AEB (Autonomous Emergency Braking) has become standard equipment on many models, and even a mandatory safety feature on some luxury brands. Current technologies mostly improve upon SOTIF functions, but rarely optimize the automatic emergency braking function while SOTIF is operating to address specific system limitations that could lead to hazards. Summary of the Invention
[0003] The main objective of this application is to propose an AEB optimization method, system, device, and medium based on expected functional safety analysis, so as to provide an optimization strategy for AEB functions, a clear path from problem to solution, and achieve accurate risk location and traceability.
[0004] To achieve the above objectives, one aspect of this application proposes an AEB optimization method based on expected functional safety analysis, the method comprising: Obtain the current external and internal factors of the vehicle, and construct a vehicle control model based on the external and internal factors; The architectural elements within the vehicle control model are classified and integrated, identified based on the architectural elements, and the hazardous events corresponding to the braking function are determined using the established functional analysis strategy. Using the established behavioral analysis strategy, determine whether the hazardous event is acceptable, classify unacceptable hazardous events, and identify unsafe control behaviors; By analyzing the potential functional deficiencies and triggering conditions of the unsafe control behaviors, the expected functional safety improvement measures corresponding to the architectural elements of the braking function are determined, and the braking function optimization strategy is obtained.
[0005] In some embodiments, determining the hazardous event corresponding to the architectural element of the braking function includes: Set analysis objectives, and based on the analysis objectives, determine the scope of harm and safety constraints of the hazardous event; Based on the scope of the hazard and the safety constraints, identify the hazardous behaviors that the architectural elements of the braking function can produce. The hazardous event is determined by combining the hazardous scenarios set for the braking function with the hazardous behaviors.
[0006] In some embodiments, determining the anticipated functional safety improvements for the architectural element corresponding to the braking function includes: For the aforementioned insecure control behavior, the corresponding architectural element is determined, and based on the functionality of the corresponding architectural element in the insecure control behavior, potential operational events with potential functional deficiencies are identified. Based on the corresponding architectural elements, determine the conditions that trigger the corresponding potential running events, obtain the triggering conditions, and analyze the triggering conditions.
[0007] In some embodiments, the braking function optimization strategies are integrated to form an optimization database. When the corresponding architectural element has the hazard event, the corresponding braking function optimization strategy is queried from the optimization database and executed.
[0008] To achieve the above objectives, another aspect of this application proposes an AEB optimization system based on expected functional safety analysis, the system comprising: The model building module is used to acquire the external and internal factors of the current vehicle and build a vehicle control model based on the external and internal factors. The event determination module is used to classify and integrate the architectural elements within the vehicle control model, identify the architectural elements, and use the set functional analysis strategy to determine the hazardous events corresponding to the architectural elements of the braking function. The behavior recognition module is used to determine whether the hazardous event is acceptable by using the set behavior analysis strategy, classify the unacceptable hazardous events, and identify unsafe control behaviors. The strategy determination module is used to analyze the potential functional deficiencies and triggering conditions of the unsafe control behavior, determine the expected functional safety improvement measures of the architectural elements corresponding to the braking function, and obtain the braking function optimization strategy.
[0009] In some embodiments, the event determination module includes: The target setting unit is used to set analysis targets and determine the hazard scope and safety constraints of the hazardous event based on the analysis targets. A behavior determination unit is configured to identify the hazardous behaviors that the architectural elements of the braking function can produce, based on the scope of the hazard and the safety constraints. The event determination unit is used to determine the hazard event by combining the set hazard scenarios of the braking function and the hazard behavior.
[0010] In some embodiments, the strategy determination module includes: The first analysis unit is used to determine the corresponding architectural element for the insecure control behavior, and based on the function of the corresponding architectural element in the insecure control behavior, determine potential operational events with potential functional deficiencies. The second analysis unit is used to determine the conditions for triggering the corresponding potential running event based on the corresponding architectural element, obtain the triggering conditions, and analyze the triggering conditions.
[0011] In some embodiments, the system further includes: The strategy invocation module is used to integrate the braking function optimization strategies to form an optimization database. When the corresponding architectural element has the hazard event, the module queries the optimization database for the corresponding braking function optimization strategy and executes the corresponding braking function optimization strategy.
[0012] To achieve the above objectives, another aspect of the present application provides a vehicle control device, including a memory, a processor, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the above-described AEB optimization method based on expected functional safety analysis.
[0013] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described AEB optimization method based on expected functional safety analysis.
[0014] The embodiments of this application include at least the following beneficial effects: This application provides an AEB optimization method, system, device, and medium based on expected functional safety analysis. This solution constructs a vehicle control model based on external and internal factors, numbers and describes the architectural elements through this model, uses a set functional analysis strategy to determine the hazardous events corresponding to the architectural elements of the braking function, uses a set behavioral analysis strategy to determine whether the hazardous events are acceptable, roughly classifies unacceptable hazards, analyzes the unsafe control behaviors of the AEB function, and obtains the optimization strategy for the AEB function. This eliminates risk omissions from the root, provides a clear path from problem to solution, achieves accurate risk positioning and traceability, and enables optimization before hazards occur. Attached Figure Description
[0015] Figure 1 This is a flowchart of the AEB optimization method based on expected functional safety analysis provided in the embodiments of this application; Figure 2 This is a schematic diagram of the framework of the AEB optimization system based on expected functional safety analysis provided in the embodiments of this application. Figure 3 This is a schematic diagram of the hardware structure framework of the vehicle control device provided in the embodiments of this application. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.
[0017] It is understood that the terms "first," "second," etc., used in this application may be used to describe various concepts herein, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of embodiments of this application, Ethernet signaling information may also be referred to as interface signaling information, and similarly, interface signaling information may also be referred to as Ethernet signaling information. Depending on the context, the words "if" or "when" as used herein may be interpreted as "when," "in response to a determination," or "in the event of a determination."
[0018] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0020] In some embodiments of one aspect of the present invention Figure 1 This is an optional flowchart of the AEB optimization method based on expected functional safety analysis provided in the embodiments of this application. Figure 1 The method may include, but is not limited to, steps S100 to S400.
[0021] Step S100: Obtain the current external and internal factors of the vehicle, and construct a vehicle control model based on the external and internal factors.
[0022] Step S200: Classify and integrate the architectural elements within the vehicle control model, identify them based on the architectural elements, and use the established functional analysis strategy to determine the hazardous events corresponding to the architectural elements of the braking function.
[0023] Step S300: Using the established behavior analysis strategy, determine whether the hazard event is acceptable, classify unacceptable hazard events, and identify unsafe control behaviors.
[0024] Step S400: Analyze the potential functional deficiencies and triggering conditions of unsafe control behaviors, determine the expected functional safety improvement measures for the architectural elements corresponding to the braking function, and obtain the braking function optimization strategy.
[0025] Steps S100 to S400 as shown in the embodiments of this application involve constructing a vehicle control model based on external and internal factors, numbering and describing the architectural elements through this model, identifying hazardous events corresponding to the architectural elements of the braking function using the established functional analysis strategy, determining whether the hazardous events are acceptable using the established behavioral analysis strategy, roughly classifying unacceptable hazards, analyzing the unsafe control behaviors of the AEB function, and obtaining optimization strategies for the AEB function. This approach eliminates risk omissions at the source, provides a clear path from problem to solution, achieves precise risk location and traceability, and enables optimization before hazards occur.
[0026] In some embodiments of S100, external and internal factors of the current vehicle are obtained.
[0027] External factors include: wiper control signals triggered by the driver, function switch signals, pedal travel, CDP switch signals, steering wheel signals, and human-machine interface trigger commands.
[0028] In-vehicle factors include: power status information, vehicle status information, vehicle actuator information, and perception information.
[0029] In this embodiment, external and internal factors may also include other information, but no specific limitations are imposed in this embodiment.
[0030] Based on the above information, with the feedback control loop as the core, the control flow diagram is drawn to demonstrate how the various components achieve constraints through control behavior and feedback, thereby constructing a vehicle control model.
[0031] In some embodiments of S200, architectural elements within the vehicle control model are categorized and integrated.
[0032] Based on the defined element categories, the functional components in the S100 model are divided into: vehicle exterior elements, sensing functions, and interactive display functions. Each category is assigned an architectural element number, and its corresponding function is described. The elements categorized above are then integrated to form a table.
[0033] For example, millimeter-wave radar, belonging to the sensing function, is designated as sen-6 in the architecture. Its core functions include ranging, velocity measurement, and azimuth measurement. In this embodiment, the element category may also include other categories, and no limitation is imposed in this embodiment.
[0034] Based on the established functional analysis strategy, the architectural elements are identified. Through the functions of the architectural elements, the hazardous events that the architectural elements can cause are listed and determined. From these, the hazardous events caused by the AEB function are selected.
[0035] The functional analysis strategy can be the HAZOP analysis strategy and / or the STPA analysis strategy, or it can be the individual application or combination of other analysis strategies. In this embodiment, no restrictions are placed on the functional analysis method.
[0036] In some embodiments of S300, the established behavior analysis strategy is used to determine whether the current hazard event is acceptable. Unacceptable hazards are roughly classified into three categories: function failure to trigger, function false trigger, and alarm function related.
[0037] Identify the hazard events corresponding to the AEB architecture elements, and determine the control actions (CA) and unsafe control actions (UCA) in the hazard events by analyzing the AEB functions.
[0038] Specifically, operational data prior to a hazardous event is obtained, and predicted data after the hazardous event is predicted using the established prediction model. Based on the predicted and operational data, the severity and controllability of the current hazardous event are calculated. If both severity and controllability are greater than zero, the risk is considered unacceptable. If either is zero, i.e., the severity is zero, or the event is completely controllable, then the risk is acceptable.
[0039] For example, in a hazardous event involving braking and deceleration, the control behavior CA is: VDC provides a deceleration command, keyword: should have been provided but not provided; UCA is: VDC provides a deceleration command, but the vehicle should have decelerated but no deceleration command was provided; related hazardous behavior: after AEB is activated, the vehicle does not brake and decelerate; related hazards: loss or reduction of deceleration capability, including loss or disengagement of active braking function; scenarios including triggering conditions: when there is a collision risk ahead and the driver must react but the driver does not brake, the vehicle automatically performs emergency braking; when the driver actively brakes but the braking force is insufficient, the vehicle automatically increases the braking force; the AEB status is: activated state.
[0040] The behavior analysis strategy set can be the STPA analysis strategy or other analysis strategies. In this embodiment, no restriction is placed on the behavior analysis strategy.
[0041] In some embodiments of S400, the FITC analysis strategy is used to analyze the potential functional deficiencies and triggering conditions of unsafe control behaviors, determine the expected functional safety improvement measures for the architectural elements corresponding to the braking function, and obtain the braking function optimization strategy.
[0042] In some embodiments of this invention, the hazardous event of S200 includes the following steps: S210, Set the analysis objectives, and based on the analysis objectives, determine the scope of the hazard and safety constraints of the hazard event.
[0043] S220 identifies the hazardous behaviors that the architectural elements of the braking function can produce, based on the scope of the hazard and safety constraints.
[0044] S230, in conjunction with the hazardous scenarios and hazardous behaviors set for the braking function, determines the hazardous event.
[0045] In this embodiment, the functional analysis strategy combines HAZOP and STPA strategies as an example. The analysis objective is clearly defined: the loss to be prevented is identified, and the numerical range of the analyzed element, i.e., the hazard range, is defined. System states that may lead to loss under specific environmental conditions are identified, and the hazard events are expressed in reverse to form the safety constraints that must be met, thereby obtaining the scenarios for subsequent triggering conditions.
[0046] By using the aforementioned hazard scope and safety constraints, and by setting keywords and numerical ranges, we can identify the hazardous behaviors that the architectural elements of the braking function can produce.
[0047] The harmful act is then combined with the scenario that would turn the harm into injury to obtain the harmful event, and the harmful event is identified.
[0048] In some embodiments of this invention, the analysis process of S300 includes the following steps: S310, for insecure control behaviors, identify the corresponding architectural elements, and based on the functions of the corresponding architectural elements in insecure control behaviors, identify potential runtime events with potential functional deficiencies. S320 determines the conditions for triggering the corresponding potential runtime events based on the corresponding architectural elements, obtains the triggering conditions, and analyzes the triggering conditions.
[0049] In this embodiment, the FITC analysis strategy is used to analyze which architectural elements (such as sensors, ECUs, actuators, software algorithms, communication buses, etc.) caused this unsafe control behavior.
[0050] For the data generated by each architectural element identified in the previous step, determine how its core functions behave during the process leading to insecure control behavior. Identify functions that exist but whose performance, accuracy, or robustness is insufficient to cope with specific scenarios. Concretize the above into a describable event to obtain potential runtime events. For each potential operational event, identify the direct trigger. Based on the direct trigger, determine the conditions that trigger the corresponding potential operational event, calculate the probability and detectability of the conditions, and thus determine the conditions that reach the threshold. Use these conditions as triggering conditions, analyze them, and thus determine the corresponding optimization strategy for the AEB function.
[0051] In some embodiments of one aspect of the present invention, the method further includes: S500 integrates braking function optimization strategies into an optimization database. When a hazard event occurs in a corresponding architectural element, the corresponding braking function optimization strategy is queried from the optimization database and executed.
[0052] In this embodiment, all braking function optimization strategies are integrated to form an optimization database. When a hazard event occurs in the corresponding architectural element, the corresponding braking function optimization strategy is determined from the optimization database, and the user or the corresponding component driving the vehicle is prompted to execute the corresponding braking function optimization strategy.
[0053] For example, taking the front-view camera as an example, the flicker suppression of the front-view camera is insufficient, triggered by the target having LED lighting equipment. The proposed SOTIF safety requirement is that, when the vehicle is running, the sensor should avoid being unable to correctly collect data on the target vehicle, traffic facilities, obstacles, etc., due to the target having LED materials with flickering properties. The final SOTIF improvement measure for the AEB function is to extend the camera's exposure time to maintain a certain dynamic range level, which is longer than the LED drive cycle.
[0054] Reference Figure 2 Another embodiment of this application also provides an AEB optimization system based on expected functional safety analysis, comprising: The model building module is used to obtain the external and internal factors of the current vehicle and build a vehicle control model based on these factors.
[0055] The event determination module is used to classify and integrate the architectural elements within the vehicle control model, identify them based on the architectural elements, and use the established functional analysis strategy to determine the hazardous events corresponding to the architectural elements of the braking function.
[0056] The behavior recognition module is used to determine whether a hazard event is acceptable by using the established behavior analysis strategy, classify unacceptable hazard events, and identify unsafe control behaviors.
[0057] The strategy determination module is used to analyze potential functional deficiencies and triggering conditions of unsafe control behaviors, determine the expected functional safety improvement measures for the architectural elements corresponding to the braking function, and obtain the braking function optimization strategy.
[0058] In the model building module, obtain the external and internal factors of the current vehicle.
[0059] External factors include: wiper control signals triggered by the driver, function switch signals, pedal travel, CDP switch signals, steering wheel signals, and human-machine interface trigger commands.
[0060] In-vehicle factors include: power status information, vehicle status information, vehicle actuator information, and perception information.
[0061] In this embodiment, external and internal factors may also include other information, but no specific limitations are imposed in this embodiment.
[0062] Based on the above information, with the feedback control loop as the core, the control flow diagram is drawn to demonstrate how the various components achieve constraints through control behavior and feedback, thereby constructing a vehicle control model.
[0063] In the event determination module, the architectural elements within the vehicle control model are categorized and integrated.
[0064] Based on the defined element categories, the functional components in the model are divided into: vehicle exterior elements, sensing functions, and interactive display functions. Each category is assigned an architectural element number, and its corresponding function is described. The elements categorized above are then integrated and presented in a table.
[0065] For example, millimeter-wave radar, belonging to the sensing function, is designated as sen-6 in the architecture. Its core functions include ranging, velocity measurement, and azimuth measurement. In this embodiment, the element category may also include other categories, and no limitation is imposed in this embodiment.
[0066] Based on the established functional analysis strategy, the architectural elements are identified. Through the functions of the architectural elements, the hazardous events that the architectural elements can cause are listed and determined. From these, the hazardous events caused by the AEB function are selected.
[0067] The functional analysis strategy can be the HAZOP analysis strategy and / or the STPA analysis strategy, or it can be the individual application or combination of other analysis strategies. In this embodiment, no restrictions are placed on the functional analysis method.
[0068] In the behavior recognition module, the established behavior analysis strategy is used to determine whether the current hazard event is acceptable. Unacceptable hazards are roughly classified into three categories: function failure to trigger, function false trigger, and alarm function related.
[0069] Identify the hazard events corresponding to the AEB architecture elements, and determine the control actions (CA) and unsafe control actions (UCA) in the hazard events by analyzing the AEB functions.
[0070] Specifically, operational data prior to a hazardous event is obtained, and predicted data after the hazardous event is predicted using the established prediction model. Based on the predicted and operational data, the severity and controllability of the current hazardous event are calculated. If both severity and controllability are greater than zero, the risk is considered unacceptable. If either is zero, i.e., the severity is zero, or the event is completely controllable, then the risk is acceptable.
[0071] For example, in a hazardous event involving braking and deceleration, the control behavior CA is: VDC provides a deceleration command, keyword: should have been provided but not provided; UCA is: VDC provides a deceleration command, but the vehicle should have decelerated but no deceleration command was provided; related hazardous behavior: after AEB is activated, the vehicle does not brake and decelerate; related hazards: loss or reduction of deceleration capability, including loss or disengagement of active braking function; scenarios including triggering conditions: when there is a collision risk ahead and the driver must react but the driver does not brake, the vehicle automatically performs emergency braking; when the driver actively brakes but the braking force is insufficient, the vehicle automatically increases the braking force; the AEB status is: activated state.
[0072] The behavior analysis strategy set can be the STPA analysis strategy or other analysis strategies. In this embodiment, no restriction is placed on the behavior analysis strategy.
[0073] In the strategy determination module, the FITC analysis strategy is used to analyze the potential functional deficiencies and triggering conditions of unsafe control behaviors, determine the expected functional safety improvement measures for the architectural elements corresponding to the braking function, and obtain the braking function optimization strategy.
[0074] In another embodiment of this application, the event determination module includes: The target setting unit is used to set analysis targets and, based on the analysis targets, determine the scope of hazard and safety constraints of the hazardous event.
[0075] The behavior determination unit is used to identify the hazardous behaviors that the architectural elements of the braking function can produce, based on the scope of the hazard and safety constraints.
[0076] The event determination unit is used to determine the hazardous event by combining the hazardous scenarios and hazardous behaviors set for the braking function.
[0077] In the target setting unit, the functional analysis strategy, taking the combination of HAZOP and STPA analysis strategies as an example, clarifies the analysis objective: it clarifies the loss to be prevented and defines the numerical range of the analyzed elements, i.e., the hazard range. It identifies system states that may lead to loss under specific environmental conditions, reverse-expresses the hazard events, forms the safety constraints that must be met, and thus obtains the scenarios of subsequent triggering conditions.
[0078] In the behavior determination unit, the harmful behaviors that the architectural elements of the braking function can produce are identified by using the above-mentioned hazard range and safety constraints, and by setting keywords and numerical ranges.
[0079] In the event determination unit, the harmful behavior is combined with the scenario that would turn the harm into injury to obtain the harmful event and determine the harmful event.
[0080] In another embodiment of this application, the strategy determination module includes: The first analysis unit is used to identify the corresponding architectural elements for insecure control behaviors, and based on the functions of the corresponding architectural elements in insecure control behaviors, to identify potential runtime events with potential functional deficiencies.
[0081] The second analysis unit is used to determine the conditions that trigger the corresponding potential runtime events based on the corresponding architectural elements, obtain the triggering conditions, and analyze the triggering conditions.
[0082] In the first analysis unit, the FITC analysis strategy is used to analyze which architectural elements (such as sensors, ECUs, actuators, software algorithms, communication buses, etc.) are responsible for this unsafe control behavior.
[0083] For the data generated by each architectural element identified in the previous step, determine how its core functions behave during the process leading to insecure control behavior. Identify functions that exist but whose performance, accuracy, or robustness is insufficient to cope with specific scenarios. Concretize the above into a describable event to obtain potential runtime events. In the second analysis unit, for each potential operational event, a direct cause is identified. Based on the direct cause, the conditions that trigger the corresponding potential operational event are determined, and the probability and detectability of the conditions are calculated to determine the conditions that reach the threshold. These conditions are then used as triggering conditions, and the triggering conditions are analyzed to determine the corresponding optimization strategy for the AEB function.
[0084] In another embodiment of this application, the system further includes: The strategy invocation module is used to integrate braking function optimization strategies to form an optimization database. When a corresponding architectural element has a hazard event, the module queries the optimization database for the corresponding braking function optimization strategy and executes the corresponding braking function optimization strategy.
[0085] In this embodiment, all braking function optimization strategies are integrated to form an optimization database. When a hazard event occurs in the corresponding architectural element, the corresponding braking function optimization strategy is determined from the optimization database, and the user or the corresponding component driving the vehicle is prompted to execute the corresponding braking function optimization strategy.
[0086] For example, taking the front-view camera as an example, the flicker suppression of the front-view camera is insufficient, triggered by the target having LED lighting equipment. The proposed SOTIF safety requirement is that, when the vehicle is running, the sensor should avoid being unable to correctly collect data on the target vehicle, traffic facilities, obstacles, etc., due to the target having LED materials with flickering properties. The final SOTIF improvement measure for the AEB function is to extend the camera's exposure time to maintain a certain dynamic range level, which is longer than the LED drive cycle.
[0087] Another embodiment of this application provides a vehicle control device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned AEB optimization method based on expected functional safety analysis. This vehicle control device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0088] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0089] Please see Figure 3 , Figure 3 The hardware structure of a vehicle control device according to another embodiment is illustrated. The vehicle control device includes: The processor can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to achieve the technical solutions provided in the embodiments of this application. The memory can be implemented in the form of read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory and called and executed by the processor using the AEB optimization method based on expected functional safety analysis of the embodiments of this application. Input / output interfaces are used to implement information input and output; The communication interface is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). A bus is used to transfer information between various components of a device, such as processors, memory, input / output interfaces, and communication interfaces. The processor, memory, input / output interfaces, and communication interfaces communicate with each other within the device via a bus.
[0090] This invention also provides a vehicle including the AEB optimization method based on expected functional safety analysis described in the above embodiments.
[0091] The vehicle can be a private car, such as a sedan, SUV, MPV, or pickup truck. It can also be a commercial vehicle, such as a van, bus, small truck, or large semi-trailer. The vehicle must have an electric motor capable of outputting power or acting as a generator to store mechanical energy. When the vehicle is a new energy vehicle, it can be a hybrid or a pure electric vehicle.
[0092] Since the vehicle applies all the technical solutions of the above-described vehicle control device, it has at least all the beneficial effects brought about by the technical solutions of the above embodiments, which will not be repeated here.
[0093] Another embodiment of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described AEB optimization method based on expected functional safety analysis.
[0094] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.
[0095] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0096] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0097] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0098] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0099] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0100] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0101] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0102] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0103] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0104] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. An AEB optimization method based on expected functional safety analysis, characterized in that, The method includes: Obtain the current external and internal factors of the vehicle, and construct a vehicle control model based on the external and internal factors; The architectural elements within the vehicle control model are classified and integrated, identified based on the architectural elements, and the hazardous events corresponding to the braking function are determined using the established functional analysis strategy. Using the established behavioral analysis strategy, determine whether the hazardous event is acceptable, classify unacceptable hazardous events, and identify unsafe control behaviors; By analyzing the potential functional deficiencies and triggering conditions of the unsafe control behaviors, the expected functional safety improvement measures corresponding to the architectural elements of the braking function are determined, and the braking function optimization strategy is obtained.
2. The AEB optimization method based on expected functional safety analysis according to claim 1, characterized in that, The determination of the hazardous events corresponding to the architectural element of the braking function includes: Set analysis objectives, and based on the analysis objectives, determine the scope of harm and safety constraints of the hazardous event; Based on the scope of the hazard and the safety constraints, identify the hazardous behaviors that the architectural elements of the braking function can produce. The hazardous event is determined by combining the hazardous scenarios set for the braking function with the hazardous behaviors.
3. The AEB optimization method based on expected functional safety analysis according to claim 1, characterized in that, The analysis of potential functional deficiencies and triggering conditions for the aforementioned unsafe control behaviors includes: For the aforementioned insecure control behavior, the corresponding architectural element is determined, and based on the functionality of the corresponding architectural element in the insecure control behavior, potential operational events with potential functional deficiencies are identified. Based on the corresponding architectural elements, determine the conditions that trigger the corresponding potential running events, obtain the triggering conditions, and analyze the triggering conditions.
4. The AEB optimization method based on expected functional safety analysis according to claim 1, characterized in that, The method further includes: The braking function optimization strategies are integrated to form an optimization database. When the corresponding architectural element has the hazard event, the corresponding braking function optimization strategy is queried from the optimization database and executed.
5. An AEB optimization system based on expected functional safety analysis, characterized in that, The system includes: The model building module is used to acquire the external and internal factors of the current vehicle and build a vehicle control model based on the external and internal factors. The event determination module is used to classify and integrate the architectural elements within the vehicle control model, identify the architectural elements, and use the set functional analysis strategy to determine the hazardous events corresponding to the architectural elements of the braking function. The behavior recognition module is used to determine whether the hazardous event is acceptable by using the set behavior analysis strategy, classify the unacceptable hazardous events, and identify unsafe control behaviors. The strategy determination module is used to analyze the potential functional deficiencies and triggering conditions of the unsafe control behavior, determine the expected functional safety improvement measures of the architectural elements corresponding to the braking function, and obtain the braking function optimization strategy.
6. The AEB optimization system based on expected functional safety analysis according to claim 5, characterized in that, The event determination module includes: The target setting unit is used to set analysis targets and determine the hazard scope and safety constraints of the hazardous event based on the analysis targets. A behavior determination unit is configured to identify the hazardous behaviors that the architectural elements of the braking function can produce, based on the scope of the hazard and the safety constraints. The event determination unit is used to determine the hazard event by combining the set hazard scenarios of the braking function and the hazard behavior.
7. The AEB optimization system based on expected functional safety analysis according to claim 5, characterized in that, The strategy determination module includes: The first analysis unit is used to determine the corresponding architectural element for the insecure control behavior, and based on the function of the corresponding architectural element in the insecure control behavior, determine potential operational events with potential functional deficiencies. The second analysis unit is used to determine the conditions for triggering the corresponding potential running event based on the corresponding architectural element, obtain the triggering conditions, and analyze the triggering conditions.
8. The AEB optimization system based on expected functional safety analysis according to claim 5, characterized in that, The system also includes: The strategy invocation module is used to integrate the braking function optimization strategies to form an optimization database. When the corresponding architectural element has the hazard event, the module queries the optimization database for the corresponding braking function optimization strategy and executes the corresponding braking function optimization strategy.
9. A vehicle control device, characterized in that, It includes a memory, a processor, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the AEB optimization method based on expected functional safety analysis as described in any one of claims 1 to 4.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the AEB optimization method based on expected functional safety analysis as described in any one of claims 1 to 4.