A real vehicle functional safety test system based on fault injection
The real-vehicle functional safety testing system based on fault injection enables unified communication and electrical fault injection without modifying the vehicle wiring harness or ECU. This solves the problems of long testing cycles, high costs, and complex operations in existing technologies, and improves testing efficiency and real-time equipment management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 上海北汇信息科技有限公司
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-29
AI Technical Summary
Existing vehicle fault injection technologies require modification of vehicle wiring harnesses or removal of ECUs, resulting in long testing cycles, high costs, and a lack of unified, controllable, and recordable injection capabilities for communication and electrical faults. Furthermore, the cost of repeated equipment configuration is high, and on-site operations are complex.
The system employs a real-vehicle functional safety testing system based on fault injection, which includes a host computer software module, a real-time control module, a bus simulation device, a customized fault injection module, a three-way switching device, vehicle model adaptation connectors, and an evaluation module. It realizes a unified platform for communication message injection and electrical fault injection, supports joint scenario testing, does not require wiring or ECU disassembly, and provides one-click restoration of the original vehicle state and fault code clearing.
It significantly reduces test preparation and recovery time, supports complex injection strategies and automated regression testing, achieves real-time performance and stability, can automatically troubleshoot faults, reduces the cost of repeated equipment configuration, and improves test efficiency.
Smart Images

Figure CN122109661A_ABST
Abstract
Description
Technical Field
[0002] This invention relates to the field of electrical testing technology, and more specifically, to a real-vehicle functional safety testing system based on fault injection. Background Technology
[0004] Existing real-vehicle fault injection methods typically require modification of the vehicle wiring harness, removal or replacement of the ECU, or can only be completed on a simulation platform (bench), resulting in long testing cycles, slow recovery, high costs, and an inability to directly reflect the real-vehicle environment.
[0005] Some solutions employ a single injection method (supporting only communication or only electrical systems), lacking the ability to inject both communication and electrical faults in a unified, controllable, and recordable manner.
[0006] The lack of convenient cross-vehicle connectors and a unified control panel leads to high costs of repeated equipment configuration and complex on-site operation.
[0007] In view of this, the present invention provides a real vehicle functional safety test system based on fault injection, which can use a series test equipment to inject faults into the vehicle bus and electrical circuits without changing the wiring of the controller under test (ECU) and the whole vehicle, thereby verifying the functional safety performance of the controller under test under various communication and electrical anomalies. Summary of the Invention
[0009] The purpose of this invention is to provide a real-vehicle functional safety testing system based on fault injection, which solves the following technical problems:
[0010] How to use a series test equipment to inject faults into the vehicle bus and electrical circuits without changing the wiring of the controller under test (ECU) and the whole vehicle, so as to verify the functional safety performance of the ECU under various communication and electrical anomalies.
[0011] The objective of this invention can be achieved through the following technical solutions:
[0012] A real-vehicle functional safety testing system based on fault injection includes:
[0013] The host computer software module is used for test scenario editing, injection script management, test result display and historical data management.
[0014] The real-time control module communicates with the host computer software module via Ethernet and is responsible for issuing real-time control commands, monitoring hardware status, acquiring high-frequency data, and storing local logs.
[0015] A bus emulation device, which is used to transparently forward, intercept, tamper with and inject bus messages such as CAN / CANFD and Ethernet under the instructions of the real-time control module;
[0016] A customized fault injection module is used to apply short circuit, open circuit, overvoltage, undervoltage, and power / ground faults under the command of the real-time control module.
[0017] The three-way switching device is used to switch signal paths under the control of the real-time control module, thereby switching between normal forwarding mode and fault injection mode.
[0018] Vehicle model adapter connector, which is used for communication connection between the controller under test and the customized fault injection module, to support rapid adaptation to different vehicle models;
[0019] An evaluation module is used to evaluate the operating status of the bus emulation device.
[0020] Through the above technical solution, a single programmable platform is realized for communication message injection and electrical fault injection, supporting joint scenarios. At the same time, there is no need to modify wiring or disassemble the ECU. The original vehicle state can be restored with one click and fault code clearing is supported, which significantly reduces test preparation and recovery time. It can also ensure real-time performance while supporting complex injection strategies and automated regression testing. Finally, the invention can automatically troubleshoot its own bus simulation equipment based on the operation process.
[0021] As a further technical solution of the present invention: the real-time control module is also used to perform the following steps:
[0022] During the initialization phase, the control three-way switching device is in transparent forwarding mode, and baseline messages and electrical parameters are collected.
[0023] Receive the injection script sent by the host computer software module, and control the three-way switching device to switch to the simulation path and the injection path according to the script timing;
[0024] The control bus simulation device and electrical fault injection module execute corresponding fault injection operations;
[0025] Real-time acquisition of bus data and electrical waveforms during the injection process, and recording to local storage;
[0026] After the injection is completed or when the protection condition is triggered, the three-way switching device is prioritized to be restored to transparent forwarding mode, and vehicle fault clearing operation is performed.
[0027] The test results and logs are uploaded to the host computer software module.
[0028] As a further technical solution of the present invention, the testing process includes the following steps:
[0029] S1. The real-time control module controls the three-way switching device to be in transparent forwarding mode, and collects and records baseline data;
[0030] S2. The host computer software module sends the test scenario and injected script to the real-time control module;
[0031] S3. The real-time control module controls the three-way switching device to switch to the fault injection path according to the script timing, and controls the bus simulation device and the electrical fault injection module to perform fault injection.
[0032] S4. The real-time control module collects data during the injection process, including messages, electrical waveforms, and controller response signals, and records them locally;
[0033] S5. After the injection is completed, the real-time control module controls the three-way switching device to restore the transparent forwarding mode and performs vehicle fault clearing;
[0034] S6. The real-time control module uploads test data and logs to the host computer software module for result analysis and report generation.
[0035] As a further technical solution of the present invention: the operation process of the evaluation module includes:
[0036] After a delay determination is completed, the bus emulation device uses its built-in interception counter to count the number of packets that should have been intercepted and the number of packets that were actually intercepted, and obtains the number of packets that were missed.
[0037] Set the discrimination interval The number of missed intercepted packets is then compared with the discrimination interval;
[0038] If the number of missed intercepted packets is not less than Then it is determined that the current overall simulation equipment needs maintenance;
[0039] If the number of missed intercepted packets is no greater than Therefore, it is determined that the current overall simulation equipment does not require maintenance.
[0040] If the number of missed intercepted packets falls within the discrimination range, an evaluation score is obtained based on the response time, adjacent missed packet interval, and missed packet quantity during the delay judgment process, and the current bus simulation device is evaluated based on the evaluation score.
[0041] As a further technical solution of the present invention: the process of setting the discrimination interval includes:
[0042] Obtain the usage history data of the current bus emulation device and devices of the same model as the current bus emulation device, and calculate the failure rate of the same model of bus emulation device under different numbers of missed reports based on the usage history data;
[0043] Set the discrimination interval based on the failure rate.
[0044] As a further technical solution of the present invention: the process of obtaining the evaluation score includes:
[0045] Through the formula:
[0046]
[0047] Obtain assessment scores, among which It is the response time of the i-th delay determination process. The interval between adjacent missed reports, It is the preset standard time. These are compensation parameters set based on the device type. This represents the number of missed reports in the currently completed delay determination process. It is based on the preset standard value of the underreporting rate.
[0048] As a further technical solution of the present invention: the process of obtaining the adjacent missed detection interval includes:
[0049] Obtain the determination time for delay and the sending interval of fault messages;
[0050] The maximum number of intervals is obtained based on the determination time of delay and the sending interval of fault messages;
[0051] Generate an equal number of interval positions based on the maximum number of intervals and obtain the false negative probability for each interval position based on the device type of the current bus simulation device;
[0052] The interval between adjacent missed reports is calculated based on the probability of missed reports and the interval location.
[0053] As a further technical solution of the present invention: the process of calculating and obtaining the adjacent missed reporting interval includes:
[0054] Through the formula:
[0055]
[0056] in, It is the probability of a missed report at the k-th interval position, where k is a non-zero positive integer not greater than n, and n is the maximum number of intervals.
[0057] The above technical solution provides a method for managing bus simulation devices based on operational feedback. When intercepting packets, bus simulation devices may miss some packets. If a packet is missed during the delay period, repeated interception is required to trigger the controller. Clearly, the bus simulation device's ability to intercept the current packet is crucial for triggering the controller. Currently, the interception capability of bus simulation devices is generally evaluated after testing through equipment maintenance and repair, which lacks real-time responsiveness. The evaluation score provided by this invention can achieve real-time evaluation of the current bus simulation device's interception capability based on operational parameters, which is significant for the stability of the testing process and the status management of the bus simulation device.
[0058] As a further technical solution of the present invention: the bus simulation device includes a first simulation component and a second simulation component. The first simulation component and the second simulation component are connected in parallel and the connection state with the controller under test is controlled by a circuit switch. After a cold start, the bus simulation device uses the first simulation component to connect with the controller under test. The evaluation score is set with a safety threshold. If the evaluation score is greater than the safety threshold, it is determined that the current bus device can continue to be used. Otherwise, it is determined that the current bus device needs to disconnect the connection between the first simulation component and the controller under test and switch the connection between the second simulation component and the controller under test.
[0059] The beneficial effects of this invention are:
[0060] This invention realizes a single programmable platform for communication message injection and electrical fault injection, supports joint scenarios, and eliminates the need for wiring or ECU disassembly. It restores the original vehicle state with one click and supports fault code clearing, significantly reducing test preparation and recovery time. It also ensures real-time performance while supporting complex injection strategies and automated regression testing. Finally, this invention can automatically troubleshoot its own bus simulation equipment based on the running process.
[0061] The evaluation score provided by this invention can evaluate the interception capability of the current bus emulation device in real time based on the parameters of the operation process, which is of positive significance for the stability of the testing process and the status management of the bus emulation device. Attached Figure Description
[0063] The invention will now be further described with reference to the accompanying drawings.
[0064] Figure 1 This is a schematic diagram of the module connection relationship of the present invention;
[0065] Figure 2 This is a flowchart of the evaluation process steps of the evaluation module of the present invention. Detailed Implementation
[0067] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0068] Please see Figures 1-2 As shown, in one embodiment, a real-vehicle functional safety testing system based on fault injection is provided, comprising:
[0069] The host computer software module is used for test scenario editing, injection script management, test result display, and historical data management.
[0070] The real-time control module communicates with the host computer software module via Ethernet and is responsible for issuing real-time control commands, monitoring hardware status, acquiring high-frequency data, and storing local logs.
[0071] Bus emulation devices are used to transparently forward, intercept, tamper with, and inject bus messages such as CAN / CAN FD and Ethernet under the instructions of the real-time control module.
[0072] A custom fault injection module is used to apply short circuit, open circuit, overvoltage, undervoltage, and power / ground faults under the command of the real-time control module.
[0073] Three-way switching device, the three-way switching device is used to switch signal paths under the control of real-time control module to realize the switching between normal forwarding mode and fault injection mode;
[0074] Vehicle model adapter connector: The vehicle model adapter connector is used for communication connection between the controller under test and the customized fault injection module to support rapid adaptation to different vehicle models.
[0075] The evaluation module is used to evaluate the operating status of the bus emulation device.
[0076] It should be noted that the general usage process is as follows:
[0077] The system connects and initializes the test equipment, connecting it in series with the controller under test (DUT) and the vehicle using vehicle model connectors. The real-time machine (RTM) establishes control channels with each piece of hardware and performs self-tests to confirm the default transparent forwarding state. The host computer uploads the test scenario and injection parameters to the RTM via Ethernet. Baseline acquisition is then performed; the RTM acquires baseline messages and electrical parameters in transparent mode, saves them locally, and pushes them to the host computer. Next, a script is injected via the RTM. Specifically, a customized three-way switching device is used to switch the path to the bus simulation device / fault injection module. Then, message interception / modification / forgery is performed on the bus, or short circuits / open circuits / over / under voltage are applied to the circuits. Simultaneously, the RTM samples and records waveforms and messages.
[0078] In complex scenarios, the real-time machine can simultaneously control multiple hardware modules to achieve joint injection.
[0079] Finally, recovery and fault clearing are performed, with the real-time machine taking priority. When injection ends or protection is triggered, the real-time machine first restores the three-way device to the default transparent output, disconnects the fault injection output, and executes the vehicle fault clearing script (if applicable). Then, the results and logs are uploaded to the host computer.
[0080] Playback and reproduction are initiated by the host computer and executed by the real-time machine. Finally, the host computer requests the playback of the recorded scene, and the real-time machine replays it with the same timing and hardware control instructions, ensuring real-time performance and reproducibility.
[0081] In this embodiment, communication message injection and electrical fault injection are implemented on the same programmable platform, supporting joint scenarios. At the same time, there is no need to modify the wiring or disassemble the ECU. The original vehicle state can be restored with one click and fault code clearing is supported, which significantly reduces test preparation and recovery time. It can also ensure real-time performance while supporting complex injection strategies and automated regression testing. Finally, the present invention can automatically troubleshoot its own bus simulation equipment according to the operation process.
[0082] Furthermore, the real-time control module is also used to perform the following steps:
[0083] During the initialization phase, the control three-way switching device is in transparent forwarding mode, and baseline messages and electrical parameters are collected.
[0084] Receive the injection script sent by the host computer software module, and control the three-way switching device to switch to the simulation path and the injection path according to the script timing;
[0085] The control bus simulation device and electrical fault injection module execute corresponding fault injection operations;
[0086] Real-time acquisition of bus data and electrical waveforms during the injection process, and recording to local storage;
[0087] After the injection is completed or when the protection condition is triggered, the three-way switching device is prioritized to be restored to transparent forwarding mode, and vehicle fault clearing operation is performed.
[0088] The test results and logs are uploaded to the host computer software module.
[0089] In addition, the testing process includes the following steps:
[0090] S1. The real-time control module controls the three-way switching device to be in transparent forwarding mode, and collects and records baseline data;
[0091] S2. The host computer software module sends the test scenario and injected script to the real-time control module;
[0092] S3. The real-time control module controls the three-way switching device to switch to the fault injection path according to the script timing, and controls the bus simulation device and the electrical fault injection module to perform fault injection.
[0093] S4. The real-time control module collects data during the injection process, including messages, electrical waveforms, and controller response signals, and records them locally;
[0094] S5. After the injection is completed, the real-time control module controls the three-way switching device to restore the transparent forwarding mode and performs vehicle fault clearing;
[0095] S6. The real-time control module uploads test data and logs to the host computer software module for result analysis and report generation.
[0096] The evaluation module's operation process includes:
[0097] After a delay judgment is completed, the bus simulation device uses its built-in interception counter to count the number of packets that should be intercepted and the number of packets that are actually intercepted, and obtains the number of packets that are missed. It should be noted that when simulating a fault by intercepting packets, a judgment time for delay judgment is set. If the controller does not receive any packets within this judgment time, it will issue a corresponding functional error. This process is called a delay judgment process.
[0098] Set the discrimination interval The number of missed intercepted packets is then compared with the discrimination interval;
[0099] If the number of missed intercepted packets is not less than Then it is determined that the current overall simulation equipment needs maintenance;
[0100] If the number of missed intercepted packets is no greater than Therefore, it is determined that the current overall simulation equipment does not require maintenance.
[0101] If the number of missed intercepted packets falls within the discrimination range, an evaluation score is obtained based on the response time, adjacent missed packet interval, and missed packet quantity during the delay judgment process, and the current bus simulation device is evaluated based on the evaluation score.
[0102] The process of setting the discrimination interval includes:
[0103] Obtain the usage history data of the current bus emulation device and devices of the same model as the current bus emulation device, and calculate the failure rate of the same model of bus emulation device under different numbers of missed reports based on the usage history data. For example, if there are 5,000 devices of the same model, and one missed report occurs, then the failure rate is 0.2%. Similarly, the failure rate under ten missed reports is the ratio of the number of devices that detected failure to the total number of devices.
[0104] The discrimination interval is set based on the failure rate. For example, the largest number of missed alarms with a failure rate below 0.5% can be selected as the discrimination interval. The minimum number of missed reports with a failure rate above 85% is selected as the discrimination interval. value.
[0105] The process of obtaining an assessment score includes:
[0106] Through the formula:
[0107]
[0108] Obtain assessment scores, among which It is the response time of the i-th delay determination process. The interval between adjacent missed reports, It is the preset standard time. These are compensation parameters set based on the device type, with values ranging from 0.7 to 1.2. This represents the number of missed reports in the currently completed delay determination process. It is based on a preset standard value for the number of missed reports, and the largest number of missed reports with a failure rate of less than 5% is generally selected as the standard value.
[0109] The process of obtaining adjacent missed detection intervals includes:
[0110] Obtain the determination time for delay and the sending interval of fault messages;
[0111] The maximum number of intervals is obtained based on the determination time of delay and the sending interval of fault messages;
[0112] Generate an equal number of interval positions based on the maximum number of intervals and obtain the false negative probability for each interval position based on the device type of the current bus simulation device;
[0113] The interval between adjacent missed reports is calculated based on the probability of missed reports and the interval location.
[0114] The process of calculating and obtaining the interval between adjacent missed reports includes:
[0115] Through the formula:
[0116]
[0117] in, It is the probability of a missed report at the k-th interval position, where k is a non-zero positive integer not greater than n, and n is the maximum number of intervals, which is also the total number of interval positions.
[0118] This embodiment provides a solution for managing bus emulation devices based on runtime feedback. When intercepting packets, bus emulation devices may miss some packets. If a packet is missed during the delay period, repeated interception is required to trigger the controller. Obviously, the interception capability of the bus emulation device is the key to triggering the controller. Currently, the interception capability of bus emulation devices is generally evaluated through equipment maintenance and repair after testing, which is not timely. The evaluation score provided by this invention can realize real-time evaluation of the current interception capability of the bus emulation device based on the parameters of the runtime process, which has positive significance for the stability of the testing process and the status management of the bus emulation device.
[0119] The bus emulation device includes a first emulation component and a second emulation component. The first and second emulation components are connected in parallel and their connection status with the controller under test is controlled by a circuit switch. After a cold start, the bus emulation device uses the first emulation component to connect with the controller under test. The evaluation score is set with a safety threshold. If the evaluation score is greater than the safety threshold, it is determined that the current bus device can continue to be used. Otherwise, it is determined that the current bus device needs to disconnect the connection between the first emulation component and the controller under test and switch the connection between the second emulation component and the controller under test.
[0120] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the claims of this invention should still fall within the patent coverage of this invention.
Claims
1. A real-vehicle functional safety testing system based on fault injection, characterized in that, include: The host computer software module is used for test scenario editing, injection script management, test result display and historical data management. The real-time control module communicates with the host computer software module via Ethernet and is responsible for issuing real-time control commands, monitoring hardware status, acquiring high-frequency data, and storing local logs. A bus emulation device, which is used to transparently forward, intercept, tamper with and inject bus messages such as CAN / CAN FD and Ethernet under the instructions of the real-time control module; A customized fault injection module is used to apply short circuit, open circuit, overvoltage, undervoltage, and power / ground faults under the command of the real-time control module. The three-way switching device is used to switch signal paths under the control of the real-time control module, thereby switching between normal forwarding mode and fault injection mode. Vehicle model adapter connector, which is used for communication connection between the controller under test and the customized fault injection module, to support rapid adaptation to different vehicle models; An evaluation module is used to evaluate the operating status of the bus emulation device.
2. The real-vehicle functional safety testing system based on fault injection according to claim 1, characterized in that, The real-time control module is also used to perform the following steps: During the initialization phase, the control three-way switching device is in transparent forwarding mode, and baseline messages and electrical parameters are collected. Receive the injection script sent by the host computer software module, and control the three-way switching device to switch to the simulation path and the injection path according to the script timing; The control bus simulation device and electrical fault injection module execute corresponding fault injection operations; Real-time acquisition of bus data and electrical waveforms during the injection process, and recording to local storage; After the injection is completed or when the protection condition is triggered, the three-way switching device is prioritized to be restored to transparent forwarding mode, and vehicle fault clearing operation is performed. The test results and logs are uploaded to the host computer software module.
3. The real-vehicle functional safety testing system based on fault injection according to claim 1, characterized in that, The testing process includes the following steps: S1. The real-time control module controls the three-way switching device to be in transparent forwarding mode, and collects and records baseline data; S2. The host computer software module sends the test scenario and injected script to the real-time control module; S3. The real-time control module controls the three-way switching device to switch to the fault injection path according to the script timing, and controls the bus simulation device and the electrical fault injection module to perform fault injection. S4. The real-time control module collects data during the injection process, including messages, electrical waveforms, and controller response signals, and records them locally; S5. After the injection is completed, the real-time control module controls the three-way switching device to restore the transparent forwarding mode and performs vehicle fault clearing; S6. The real-time control module uploads test data and logs to the host computer software module for result analysis and report generation.
4. The real-vehicle functional safety testing system based on fault injection according to claim 1, characterized in that, The operation process of the evaluation module includes: After a delay determination is completed, the bus emulation device uses its built-in interception counter to count the number of packets that should have been intercepted and the number of packets that were actually intercepted, and obtains the number of packets that were missed. Set the discrimination interval The number of missed intercepted packets is then compared with the discrimination interval; If the number of missed intercepted packets is not less than Then it is determined that the current overall simulation equipment needs maintenance; If the number of missed intercepted packets is no greater than Therefore, it is determined that the current overall simulation equipment does not require maintenance. If the number of missed intercepted packets falls within the discrimination range, an evaluation score is obtained based on the response time, adjacent missed packet interval, and missed packet quantity during the delay judgment process, and the current bus simulation device is evaluated based on the evaluation score.
5. A real-vehicle functional safety testing system based on fault injection according to claim 4, characterized in that, The process of setting the discrimination interval includes: Obtain the usage history data of the current bus emulation device and devices of the same model as the current bus emulation device, and calculate the failure rate of the same model of bus emulation device under different numbers of missed reports based on the usage history data; Set the discrimination interval based on the failure rate.
6. The real-vehicle functional safety testing system based on fault injection according to claim 1, characterized in that, The process of obtaining an assessment score includes: Through the formula: Obtain assessment scores, among which It is the response time of the i-th delay determination process. The interval between adjacent missed reports, It is the preset standard time. These are compensation parameters set based on the device type. This represents the number of missed reports in the currently completed delay determination process. It is based on the preset standard value of the underreporting rate.
7. A real-vehicle functional safety testing system based on fault injection according to claim 6, characterized in that, The process of obtaining the adjacent missed detection interval includes: Obtain the determination time for delay and the sending interval of fault messages; The maximum number of intervals is obtained based on the determination time of delay and the sending interval of fault messages; Generate an equal number of interval positions based on the maximum number of intervals and obtain the false negative probability for each interval position based on the device type of the current bus simulation device; The interval between adjacent missed reports is calculated based on the probability of missed reports and the interval location.
8. A real-vehicle functional safety testing system based on fault injection according to claim 7, characterized in that, The process of calculating and obtaining the interval between adjacent missed reports includes: Through the formula: in, It is the probability of a missed report at the k-th interval position, where k is a non-zero positive integer not greater than n, and n is the maximum number of intervals.
9. A real-vehicle functional safety testing system based on fault injection according to claim 4, characterized in that, The bus simulation device includes a first simulation component and a second simulation component. The first and second simulation components are connected in parallel and their connection status with the controller under test is controlled by a circuit switch. After a cold start, the bus simulation device uses the first simulation component to connect with the controller under test. The evaluation score is set with a safety threshold. If the evaluation score is greater than the safety threshold, it is determined that the current bus device can continue to be used; otherwise, it is determined that the current bus device needs to disconnect the connection between the first simulation component and the controller under test and switch the connection between the second simulation component and the controller under test.