Intelligent networked vehicle safety test method, device, equipment, storage medium and product
By utilizing intelligent connected vehicle safety testing methods and automated scripts and simulated network nodes, the problems of cumbersome operation and human error in real vehicle functional safety testing have been solved, and efficient and accurate test result generation has been achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUOQI (BEIJING) TESTING TECHNOLOGY CO LTD
- Filing Date
- 2026-03-13
- Publication Date
- 2026-06-26
AI Technical Summary
In existing real-vehicle functional safety testing, the testing procedures are cumbersome, time-consuming, and prone to inaccurate results due to human error, affecting testing efficiency and accuracy.
The intelligent connected vehicle safety testing method utilizes an operation panel to trigger automated scripts, accurately locates access points, creates simulated network nodes, automatically executes test cases, and obtains execution results through data acquisition devices to generate accurate vehicle safety test results.
It simplifies the testing process, improves testing efficiency, reduces the complexity of manual operations, and ensures the accuracy and repeatability of test results.
Smart Images

Figure CN122293544A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle testing technology, and in particular to a method, apparatus, equipment, storage medium and product for safety testing of intelligent connected vehicles. Background Technology
[0002] As automotive electronic and electrical architectures become increasingly complex, vehicle functions rely heavily on the coordination and real-time communication between multiple domain controllers. To ensure the safety and reliability of the entire vehicle under complex operating environments, comprehensive functional safety testing must be conducted in real-world vehicle environments. This type of real-vehicle testing is a crucial step in verifying system safety performance and ensuring that products meet market standards; its efficiency and reliability directly impact the vehicle development cycle and the final safety level.
[0003] In current real-vehicle functional safety testing practices, the testing process heavily relies on manual operation. During fault injection and test data acquisition, testers need to frequently perform multiple independent manual steps. This approach is not only cumbersome and time-consuming, but also highly susceptible to human error, leading to test interruptions, data omissions, or recording errors, severely impacting the accuracy of test results. Summary of the Invention
[0004] This application provides a method, apparatus, equipment, storage medium, and product for testing the safety of intelligent connected vehicles, aiming to solve the technical problems in related technologies where cumbersome testing operations affect the accuracy of test results.
[0005] In a first aspect, this application provides a safety testing method for intelligent connected vehicles. The method is applied to a vehicle testing system, which includes an operation panel, an onboard communication signal transceiver, and a data acquisition device. The method includes: In response to user input on the target fault test control on the operation panel, the target test script and target test cases of the target fault test control are determined; Based on the target test cases and the vehicle network topology, determine the access point of the vehicle communication signal transceiver in the vehicle network. The vehicle communication signal transceiver is connected to the vehicle network through the access point. According to the requirements of the target test case, a simulated network node is created through the vehicle communication signal transceiver device. The simulated network node is a virtual node that simulates the specific unit function of a real vehicle network that is directly connected to the access point. The simulation network nodes simulate vehicle signals, and the target test cases corresponding to the target fault test controls are executed based on the target test script. The execution results corresponding to the target test cases are obtained through data acquisition devices; The vehicle safety test results are determined based on the execution results.
[0006] In some possible implementations, the step of simulating vehicle signals through the simulation network nodes and executing target test cases corresponding to the target fault test controls based on the target test script includes: Based on the simulated network nodes, target packets corresponding to each target test case are intercepted on the corresponding communication channels. Trigger the target test script, and modify the corresponding target message according to each target test case using the target test script; Based on the simulated vehicle signals of the simulated network nodes, the modified target message is forwarded to execute the target test case corresponding to the target fault test control.
[0007] In some possible implementations, triggering the target test script and modifying the corresponding target message according to each target test case includes: Trigger the target test script, and replace the field data of the target fields in each of the target messages with the test data in the corresponding target test cases; Based on the message data fields of the target message after each field data is replaced, recalculate the corresponding first checksum; Based on each of the first check codes, the original check codes in each of the target messages are changed to obtain the modified target messages.
[0008] In some possible implementations, obtaining the execution results corresponding to the target test cases through a data acquisition device includes: When the target test case is triggered, vehicle data within a preset time period is acquired through a data acquisition device, and the vehicle data includes timestamps. Based on the timestamp, extract the execution results corresponding to the target test cases from the vehicle data.
[0009] In some possible implementations, determining the vehicle safety test result based on the execution result includes: The first comparison result is obtained by comparing the actual response time in each of the execution results with the preset response time threshold in the corresponding target test case. The actual vehicle state in each execution result is compared with the preset safety state in the corresponding target test case to obtain a second comparison result. The vehicle safety test results are determined based on the first comparison result and the second comparison result.
[0010] In some possible implementations, creating a simulated network node through the vehicle-mounted communication signal transceiver device according to the requirements of the target test case includes: Based on the vehicle unit connected to the vehicle communication signal transceiver and the requirements of the target test case, determine the test vehicle unit that needs to be simulated. The vehicle-mounted communication signal transceiver is used to simulate the communication behavior of each test vehicle unit and create a simulation network node corresponding to each test vehicle unit.
[0011] In some possible implementations, determining the access point of the on-board communication signal transceiver in the vehicle network based on the target test cases and the vehicle network topology includes: Identify the target vehicle unit corresponding to the fault signal that needs to be injected for the target test case; Based on the vehicle network topology diagram and each target vehicle unit, determine the communication path corresponding to the execution of the target test cases; Based on the communication path, the access point of the vehicle communication signal transceiver in the vehicle network is determined, and the access point is located in the communication path.
[0012] Secondly, this application provides a safety testing device for intelligent connected vehicles, the device comprising: The response module is used to respond to the user's input on the target fault test control on the operation panel and determine the target test script and target test cases of the target fault test control. The determination module is used to determine the access point of the vehicle communication signal transceiver in the vehicle network based on the target test cases and the vehicle network topology. An access module is used to connect the vehicle communication signal transceiver to the vehicle network through the access point; A creation module is used to create simulated network nodes through the vehicle communication signal transceiver device according to the requirements of the target test case. The simulated network nodes are virtual nodes that simulate the specific unit functions of a real vehicle network that are directly connected to the access point. The execution module is used to simulate vehicle signals through the simulation network nodes and execute target test cases corresponding to the target fault test controls based on the target test script. The acquisition module is used to acquire the execution results corresponding to the target test cases through a data acquisition device. The determination module is also used to determine the vehicle safety test results based on the execution results.
[0013] Thirdly, this application provides a safety testing device for intelligent connected vehicles, the device comprising: a processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the safety testing method for intelligent connected vehicles as described above.
[0014] Fourthly, this application provides a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the intelligent connected vehicle safety testing method described above.
[0015] Fifthly, this application provides a computer program product in which the instructions are executed by the processor of an electronic device, causing the electronic device to perform the intelligent connected vehicle safety testing method described above.
[0016] The intelligent connected vehicle safety testing method, apparatus, equipment, storage medium, and product provided in this application's embodiments accurately locate access points through test cases and network topology, ensuring the targeted nature of fault injection and the realism of test scenarios during test case execution. Furthermore, based on physical connections, the test environment is rapidly constructed through the creation of simulation nodes. On this basis, users can directly trigger automated scripts through the operation panel, encapsulating professional testing capabilities into standardized operations. This automates the execution of multiple complex steps in the testing process, reducing the complexity of manual operations while improving testing efficiency. Finally, by collecting and analyzing the data from the test case execution results, the system automatically acquires and compares test data to generate accurate vehicle safety test results. The solution uses automated scripts to uniformly schedule the execution of test cases, ensuring the realism of test scenarios and the accuracy of test data injection. Users trigger automated scripts through the operation panel, driving the scripts to precisely control simulation nodes to complete the test, thereby transforming manual operations into a deterministic and repeatable automated process, simplifying testing operations and ensuring the accuracy of test results. Attached Figure Description
[0017] This application can be better understood from the following description of specific embodiments in conjunction with the accompanying drawings, wherein: Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings, wherein the same or similar reference numerals denote the same or similar features.
[0018] Figure 1 This is a flowchart of a safety testing method for intelligent connected vehicles provided in one embodiment of this application; Figure 2 This is a flowchart of a safety testing method for intelligent connected vehicles provided in another embodiment of this application; Figure 3 This is a schematic diagram of the intelligent connected vehicle safety testing system in this application. Figure 4 This is a schematic diagram of the structure of an intelligent connected vehicle safety testing device provided in one embodiment of this application; Figure 5 This is a schematic diagram of the hardware structure of the intelligent connected vehicle safety testing equipment provided in this application embodiment. Detailed Implementation
[0019] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0020] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0021] In modern intelligent connected vehicles, the realization of vehicle functions relies on the coordinated work of multiple domain controllers, such as the intelligent driving domain, powertrain domain, chassis domain, body domain, and cockpit domain. These controllers manage functions such as autonomous driving, powertrain, and body control, and exchange data and transmit commands through high-speed buses and middleware.
[0022] With the rapid development of intelligent connected and autonomous driving technologies, electronic and electrical architectures are becoming increasingly complex, making functional safety testing of automotive controllers more challenging. Ensuring coordination, communication, and information security between domain controllers has become paramount. Functional safety testing not only requires verification of individual Electronic Control Units (ECUs) or subsystems but must also encompass comprehensive testing at the vehicle level. Testing methods include hardware-in-the-loop, driving simulator, and real-world road testing to ensure system safety and stability under complex road conditions and driving environments. While simulation testing can effectively cover high-risk scenarios and shorten testing cycles, it cannot completely replace the importance of real-vehicle testing in verifying automotive functional safety and reliability. Real-vehicle testing remains the final hurdle to ensuring overall vehicle functional safety and mass production compliance.
[0023] Existing real-vehicle functional safety testing technologies require testers to manually restart the CANoe (CAN open environment) and activate the video recording function each time a test is performed and new test data is recorded. This process is not only cumbersome and time-consuming, but also prone to data loss or mismatch due to human error, affecting testing efficiency and accuracy.
[0024] To improve the efficiency of real-vehicle functional safety testing and simplify the operation process, there is an urgent need for a system and method that can optimize the fault injection process and automate data naming and storage.
[0025] To address the problems of existing technologies, embodiments of this application provide a method, apparatus, device, storage medium, and product for safety testing of intelligent connected vehicles. The method for safety testing of intelligent connected vehicles provided in this application embodiment will be described first below.
[0026] Figure 1 This illustration shows a flowchart of a safety testing method for intelligent connected vehicles according to an embodiment of this application. The method is applied to a vehicle testing system, which includes an operation panel, an onboard communication signal transceiver, and a data acquisition device, such as... Figure 1 As shown, the method includes the following steps: S101 to S107.
[0027] S101: In response to user input on the target fault test control on the operation panel, determine the target test script and target test cases for the target fault test control.
[0028] S102: Based on the target test cases and the vehicle network topology, determine the access point of the vehicle communication signal transceiver in the vehicle network.
[0029] S103: Connect the vehicle communication signal transceiver to the vehicle network via the access point.
[0030] S104: Based on the requirements of the target test case, create a simulated network node through the vehicle communication signal transceiver. The simulated network node is a virtual node that simulates the specific unit function of a real vehicle network that is directly connected to the access point.
[0031] S105: Simulate vehicle signals through simulated network nodes, and execute target test cases corresponding to the target fault test controls based on the target test script.
[0032] S106: Obtain the execution results corresponding to the target test cases through the data acquisition device.
[0033] S107: Determine the vehicle safety test results based on the execution results.
[0034] In the specific implementation of S101, the operation panel detects input events triggered by the user through touch, click, or selection, and converts these events into electrical signals that are transmitted to the processing unit. The processing unit parses the input signals, identifies the unique identifier of the target fault test control, and then accesses a pre-stored mapping database that associates each fault test control with its corresponding test script and test case files. For example, if the user clicks a control labeled "Brake Fault Test," the system retrieves the test script and test cases specifically designed to simulate anti-lock braking system (ABS) faults from the repository based on the control.
[0035] In the specific implementation of S102, after obtaining the target test cases, the system analyzes the test requirements specified in the test cases and calls the vehicle network topology database. The vehicle network topology diagram describes the physical and logical layout of the vehicle's internal network in graphical or data structure form, including bus types, node locations, and connection relationships. The system executes a matching algorithm to compare the test requirements with network segments in the topology diagram. Specifically, it identifies the specific unit that needs intervention in the test cases and then locates the communication bus node or port connected to that unit in the topology diagram.
[0036] In order to accurately determine the access point, in some implementations, S102 may include the following steps: S1021 to S1023.
[0037] S1021: Determine the target vehicle unit corresponding to the fault signal that needs to be injected for the target test case.
[0038] S1022: Based on the vehicle network topology diagram and each target vehicle unit, determine the communication path corresponding to the execution of the target test cases.
[0039] S1023: Based on the communication path, determine the access point of the vehicle communication signal transceiver in the vehicle network. The access point is located in the communication path.
[0040] In the specific implementation of S1021, the processing unit reads the configuration file or script of the target test case. This file predefines detailed parameters for fault simulation, including the type of signal to be injected, signal characteristics, and the physical or logical unit to which the signal belongs in the real vehicle network. The system extracts these parameters through a parsing algorithm and performs mapping matching based on a pre-stored vehicle unit database. For example, if the test case specifies injecting a "high out-of-range engine coolant temperature sensor signal" fault, the system parses the signal identifier and fault mode from the test case, then queries the database for the vehicle unit associated with the signal identifier, determining it to be the "coolant temperature monitoring subunit within the engine control module".
[0041] In the specific implementation of S1022, the processing unit loads vehicle network topology data stored in a graph structure. This data contains all network nodes and the communication media connecting these nodes. Taking each target vehicle unit as a starting point or key point, a path traversal algorithm is executed in the topology graph to analyze the propagation path of the signal from the injection point to the target unit and possible related response units. Specifically, all intermediate nodes and bus segments on the path are identified. For example, if the target vehicle unit is a "window control module" located on the body network, and a fault signal needs to be injected from the test device to affect this module, the connection point of the module is located in the topology graph, and a physical and logical path from the potential access point through the gateway to the body bus is derived in reverse.
[0042] In the specific implementation of S1023, the determined communication path is analyzed, the possible connection locations on the path are evaluated, and the optimal access point is selected according to preset optimization rules. The access point is located within the communication path to ensure that the test device can communicate effectively with the target vehicle unit. Specifically, the determination process involves the processing unit comparing the compatibility of the device's hardware interface with the interface types on the path and verifying the network status after access to confirm feasibility.
[0043] The above-described implementation method of this application determines the target vehicle unit corresponding to the fault signal to be injected for the target test case, then determines the communication path corresponding to the execution of the target test case based on the vehicle network topology and each target vehicle unit, and then determines the access point of the vehicle communication signal transceiver in the vehicle network based on the communication path. The access point is located in the communication path, thereby accurately determining the access point.
[0044] In the specific implementation of S103, if the access point is a physical interface, the device physically connects to the interface via a cable or wireless adapter and initiates the hardware driver to establish an electrical connection. If it is a logical access point, the device synchronizes with the vehicle network protocol stack through software configuration. Specifically, the access process involves the device sending an initialization signal to the access point, verifying network communication parameters, and executing a handshake protocol to ensure data link layer stability.
[0045] In the specific implementation of S104, node configuration parameters are read from the test cases using node simulation software, and a virtual node object is dynamically instantiated. This simulation node simulates the function of a specific unit directly connected to the access point in a real vehicle network. For example, if the test case needs to simulate the failure of a vehicle speed sensor, a simulation node is created to simulate the vehicle speed sensor sending abnormal data frames.
[0046] In order to quickly create simulated network nodes, in some implementations, S104 may include the following steps: S1041 to S1042.
[0047] S1041: Determine the test vehicle unit to be simulated based on the vehicle unit connected to the vehicle communication signal transceiver and the requirements of the target test case.
[0048] S1042: Using the vehicle-mounted communication signal transceiver, simulate the communication behavior of each test vehicle unit and create a simulation network node corresponding to each test vehicle unit.
[0049] In the specific implementation of S1041, the onboard communication signal transceiver detects and enumerates real vehicle units that are accessible or directly interactive within the communication range of the access point. Secondly, the system synchronously parses the detailed requirements of the target test cases, which clearly define the unit functions that must virtually exist in the network environment to complete the fault test. Subsequently, the enumerated list of real connected units is compared and analyzed with the list of virtual unit functions required by the test cases. Through matching and elimination logic, it determines which functional units are missing in the real network environment or need to be replaced by simulation, thus ultimately selecting the test vehicle units that need to be represented by simulated nodes.
[0050] In the specific implementation of S1042, for each test vehicle unit to be simulated, the simulation engine dynamically loads or instantiates the corresponding communication behavior model from the behavior model library based on the unit's type and test requirements. Simulating communication behavior specifically involves configuring all network attributes of the virtual node, such as assigning a unique network identifier, setting communication protocol parameters, and defining its specific message sending and receiving behavior patterns. Subsequently, based on these configurations, an independent simulation network node instance compatible with the real network protocol stack is created. Each created node is applied to the vehicle network as a virtual, functional entity.
[0051] The above-described implementation method of this application determines the test vehicle units to be simulated based on the vehicle units connected to the vehicle communication signal transceiver and the requirements of the target test cases. Then, the communication behavior of each test vehicle unit is simulated through the vehicle communication signal transceiver, and a simulation network node corresponding to each test vehicle unit is created, thereby quickly creating simulation network nodes.
[0052] In the specific implementation of S105, the simulation node loads the target test script, which contains a series of executable instructions. The node operates sequentially according to the script; for example, the script might require the node to periodically send simulated brake pressure signals to test the response of the electronic stability control system. The node generates messages conforming to the vehicle network protocol and embeds the signal values into the message data field, injecting them into the vehicle network via the onboard communication signal transceiver. During execution, the node parses the script instructions in real time and adjusts the signal behavior accordingly.
[0053] To ensure accurate execution of test cases, in some implementations, reference is made to... Figure 2 S105 may include the following steps: S201 to S203.
[0054] S201: Based on the simulation network node, intercept the target packets corresponding to each target test case on the corresponding communication channel.
[0055] S202: Trigger the target test script, and modify the corresponding target message according to each target test case through the target test script.
[0056] S203: Based on the simulated network node, simulate vehicle signals and forward the modified target message to execute the target test case corresponding to the target fault test control.
[0057] In the specific implementation of S201, each simulation node sets up one or more software filters at the protocol stack layer according to the identity of the simulated vehicle unit and the requirements of the test cases being executed. These filters are configured based on the characteristic identifiers of the packets. When packets are transmitted on the network, the network interface hardware and underlying drivers of the simulation node first receive all raw packets flowing through the channel, and then the filtering logic performs a fast comparison. During the interception process, once the characteristics of a packet match the preset conditions of any filter, the packet will be captured and copied to a dedicated buffer of the simulation node, while its original transmission process is temporarily suspended or marked for subsequent processing.
[0058] In the specific implementation of S202, after the script within the simulation node is activated, the buffered target message is passed to the script as an input parameter. The target test script predefines modification logic and instruction sequences for different message types and fault modes. During message modification, the script first parses the original structure and content of the intercepted message, and then recalculates and edits the message data according to the detailed requirements of the current test case. Changes may involve simulating signal values, modifying message status bits, or reconstructing the entire message frame structure. For example, for an intercepted collision sensor signal message, the instruction in the test script might change the byte representing the "acceleration value" in the message data field from a normal low value to an extremely high fault value to simulate a violent false collision event.
[0059] In the specific implementation of S203, the simulated node reloads the modified message into its network protocol stack's send queue. Strictly adhering to the timing requirements of the vehicle network communication protocol, the node injects the modified message into the original communication channel through its network interface. This forwarding of the message overrides the propagation of the original message within the network, ensuring that other real vehicle units on the network receive and process the tampered fault signal.
[0060] The above-described implementation method of this application involves intercepting target packets corresponding to each target test case on the corresponding communication channel by simulating network nodes, then triggering target test scripts, modifying the corresponding target packets according to each target test case by the target test scripts, and then forwarding the modified target packets based on vehicle signals simulated by the simulated network nodes to execute the target test cases corresponding to the target fault test controls, thereby accurately executing the test cases.
[0061] In order to fully modify the message, in some implementations, S202 may include the following steps: S2021 to S2023.
[0062] S2021: Trigger the target test script, which replaces the field data of the target fields in each target message with the test data in the corresponding target test case.
[0063] S2022: Recalculate the corresponding first checksum based on the message data fields of the target message after each field data is replaced.
[0064] S2023: Based on each first checksum, modify the original checksum in each target message to obtain the modified target message.
[0065] In the specific implementation of S2021, the target test script first parses the protocol format of the current message to locate the specific target field that needs to be tampered with. Based on the predefined fault modes in the target test cases, the script extracts the corresponding test data. Subsequently, a replacement operation is performed, directly overwriting or rewriting the original field data of the target field in the message with the extracted test data.
[0066] In the specific implementation of S2022, the complete message data field of the target message after the entire field data is replaced is read, and a verification algorithm that matches the vehicle network communication protocol is called. The updated message data field is used as input to generate a new first verification code that uniquely corresponds to the current data content.
[0067] In the specific implementation of S2023, the specific field area storing the original checksum in the target message to be modified is located. Then, the value of the newly calculated first checksum is used to directly overwrite the original checksum value stored in that field area. The integrity verification information of the message is updated to ensure consistency with the tampered message data content, resulting in a modified target message with content and checksum consistency.
[0068] The above-described implementation method of this application involves triggering a target test script, which replaces the field data of the target fields in each target message with the test data in the corresponding target test case. Then, based on the message data fields of the target messages after the field data replacement, the corresponding first checksum is recalculated. Subsequently, based on each first checksum, the original checksum in each target message is changed to obtain the changed target message, thereby completely modifying the message.
[0069] In the specific implementation of S106, the data acquisition device is physically or logically connected to key points of the vehicle network and configured in monitoring mode. The device begins acquiring data based on preset trigger conditions, capturing items including network traffic, message content, error frames, timing stamps, and system status variables. For example, when a fault signal is injected by a simulation node, the data acquisition device records the response messages from all ECUs on the bus, changes in error counters, and voltage fluctuations.
[0070] In order to obtain accurate vehicle safety test results, in some implementations, S106 may include the following steps: S1061 to S1062.
[0071] S1061: When the target test case is triggered, vehicle data within the corresponding preset time period is obtained through the data acquisition device. The vehicle data includes timestamps.
[0072] S1062: Based on the timestamp, extract the execution results from the vehicle data corresponding to the target test case.
[0073] In the specific implementation of S1061, a synchronization start command is sent to the data acquisition device at the moment when the simulated network node begins to inject or tamper with signals to simulate a fault. The data acquisition device then starts recording on one or more of its data channels. These channels are connected to key monitoring points in the vehicle network. The process of acquiring vehicle data is continuous. The device captures raw electrical signals at a preset sampling rate and converts them into data frames through a protocol decoder. Simultaneously, a timestamp is appended to each decoded data frame. The preset time period is defined by the test case itself, and vehicle data within the corresponding preset time period is acquired by the data acquisition device.
[0074] In the specific implementation of S1062, the recorded, timestamped raw vehicle dataset is loaded. Then, based on the predefined logic of the target test case, the key event time windows requiring attention are identified. Using the test case trigger time or fault injection success time as a benchmark, and according to the result observation interval defined in the test case, all data records falling within this time window are quickly located and extracted from the raw data using timestamp indexes. Further, based on the specific signals or message identifiers that the test case focuses on, the data within this window is filtered to obtain the execution result dataset directly related to the test.
[0075] The above-described implementation method of this application obtains vehicle data within a preset time period through a data acquisition device when a target test case is triggered. The vehicle data includes timestamps. Then, based on the timestamps, the execution results corresponding to the target test case are extracted from the vehicle data, thereby accurately obtaining the vehicle safety test results.
[0076] In the specific implementation of S107, the processing unit calls the analysis module to compare the collected data with the expected behavior defined in the target test cases. During the analysis, the data format is parsed, performance indicators are calculated, and a rule engine is applied to detect anomalies. When the result is determined, the system generates a structured report, indicating whether the test passed or failed, and attaches detailed diagnostic information.
[0077] The intelligent connected vehicle safety testing method provided in this application accurately locates access points through test cases and network topology, ensuring the targeted nature of fault injection and the realism of test scenarios during test case execution. Furthermore, based on physical connections, it achieves rapid construction of the test environment through the creation of simulation nodes. On this basis, users can directly trigger automated scripts through the operation panel, encapsulating professional testing capabilities into standardized operations. This automates the execution of multiple complex steps in the testing process, reducing the complexity of manual operations while improving testing efficiency. Finally, by collecting and analyzing the data from the test case execution results, the method automatically acquires and compares test data to generate accurate vehicle safety test results. The solution uses automated scripts to uniformly schedule the execution of test cases, ensuring the realism of test scenarios and the accuracy of test data injection. Users trigger automated scripts through the operation panel, driving the scripts to precisely control simulation nodes to complete the test, thereby transforming manual operations into a deterministic and repeatable automated process, simplifying testing operations and ensuring the accuracy of test results.
[0078] In order to perform a complete vehicle safety comparison, in some implementations, S107 may include the following steps: S1071 to S1073.
[0079] S1071: Compare the actual response time in each execution result with the preset response time threshold in the corresponding target test case to obtain the first comparison result.
[0080] S1072: Compare the actual vehicle state in each execution result with the preset safety state in the corresponding target test case to obtain the second comparison result.
[0081] S1073: Determine the vehicle safety test results based on the first comparison results and the second comparison results.
[0082] In the specific implementation of S1071, the processing unit first parses the actual occurrence time of key events related to the test logic from the structured execution result data. Based on predefined rules, it identifies the timestamps of specific messages or signals representing system responses, and calculates their actual response times using the fault injection time or trigger event time as a reference point. Subsequently, it reads the preset response time thresholds defined for each monitored event in the target test case. Each calculated actual response time is compared one by one with its corresponding threshold to obtain the first comparison result.
[0083] In the specific implementation of S1072, the execution result data is parsed to extract the actual vehicle state that the key subsystems of the vehicle ultimately achieve or continue to exhibit within the test time window. State information may include diagnostic fault codes set by specific electronic control units, values of the controller's internal state machine, the final position of actuators, or safety status identifiers for network communication. Simultaneously, the expected preset safety states are read from the target test cases. The extracted actual states are then compared item by item with the preset safety state conditions in the test cases to determine whether the actual states fully meet or include all preset safety requirements, thus obtaining a second comparison result.
[0084] In the specific implementation of S1073, a preset result comprehensive judgment rule is invoked. Based on this rule, all judgment conclusions in the first and second comparison results are logically aggregated and analyzed to determine the vehicle safety test result. For example, referring to the above example, if all response times in the first comparison result are "passed" and all safety states in the second comparison result are "compliant", then the final safety test result determined by the system is "passed". If the response time of a certain secondary system times out but all safety states are compliant, it may be judged as "partially passed" according to the rules.
[0085] The above-described implementation method of this application obtains a first comparison result by comparing the actual response time in each execution result with the preset response time threshold in the corresponding target test case. Then, it compares the actual vehicle state in each execution result with the preset safety state in the corresponding target test case to obtain a second comparison result. Based on the first comparison result and the second comparison result, the vehicle safety test result is determined, thereby performing a complete vehicle safety comparison.
[0086] In some implementations, reference Figure 3 The hardware components include CANoe hardware, data acquisition sensors (such as cameras for recording vehicle-related status information displayed on the instrument panel and central control screen), and processing devices (such as a test laptop). During operation, the wiring harness between the ECU under test and the gateway is disconnected, forming two networks: CAN1 (ECU under test) and CAN2 (gateway). CAN1 is connected to CANoe channel 1, and CAN2 is connected to CANoe channel 2. The CANoe hardware is connected to the test laptop via a USB cable. When the gateway / ECU sends CAN messages to CANoe, CANoe modifies and integrates the messages using a fault injection script, recalculates the CRC, and then sends the processed messages to the ECU / gateway, thus modifying and forwarding data on both channels. During fault injection, the system automatically records test data, and after the test is completed, the system automatically generates a test report.
[0087] Furthermore, the system includes a fault injection module, a data storage module, and a data analysis module. The fault injection module includes a fault injection script and a one-click fault injection panel. When test conditions are met, the operator clicks the fault control to be injected on the one-click fault injection panel, automatically completing the fault injection operation. The data storage module includes data acquisition sensors and automated data recording and storage scripts. The fault injection script and the automated data recording and storage script are integrated into a "fault injection and data storage script." When the operator clicks the fault injection control, the corresponding event is triggered, and the fault injection and data storage script is run. The data analysis module includes a data analysis script. After the test data recording is completed, a test report is automatically generated through in-depth analysis of the fault injection type, time, and system response.
[0088] In the specific implementation process of the solution, the first step is to design and write corresponding test cases based on the requirements of real vehicle functional safety testing. The test case writing can support multiple fault types, including signal loss, signal abnormality, short circuit, open circuit, etc., covering a variety of functional safety testing scenarios.
[0089] Based on the actual vehicle network topology diagram, a fault injection test wiring diagram for the entire vehicle was designed, and the wiring harness was modified accordingly. Based on the fault injection test wiring diagram, the wiring harness for the communication lines between the ECU under test and the gateway was modified to ensure that faults can be accurately injected into the target module.
[0090] Establish a test project. This includes setting up a simulation network, creating system variables, and configuring hardware channels.
[0091] Develop a fault injection and data storage panel. Based on this panel, develop a one-click fault injection panel that integrates various fault injection controls. Operators can automatically inject faults into the target controller simply by clicking on the fault control.
[0092] Develop fault injection and data storage scripts. Based on the test cases, develop corresponding fault injection and data storage scripts. These scripts control the specific injection conditions and timing of faults, support fault injection for different controllers and sensors, and automatically name and save test data.
[0093] Test execution. When the test requirements are met, the operator selects the fault control to be injected through the fault injection and data storage panel. After clicking the button, the system automatically completes the fault injection operation. The injected fault types cover a variety of common scenarios such as signal loss and signal abnormality, reducing the possibility of human error.
[0094] Test data analysis and test report generation. After the test is completed, the test report is automatically generated by comparing the data collected during the test with the safety status. The report includes key information such as the time point of fault injection, fault type, system response time, vehicle status, and whether the test passed.
[0095] For example, the primary verification should be that the ECU should avoid activating the parking function when the steering system malfunctions. The test case is as follows: The vehicle is started, the Auto Parking Assist (APA) system is in standby mode, and a fault injection is performed on the steering system upon vehicle startup.
[0096] Next, a fault injection test wiring diagram was designed. Based on the actual vehicle network topology, it was determined that the steering system sends APA information to the gateway, which then sends the signal to the ECU controller. Therefore, the fault injection test wiring diagram should be the communication network between the gateway and the ECU. The wiring harness was then modified. According to the fault injection test wiring diagram, the wiring harness between the ECU and the gateway was disconnected using wiring harness modification tools, forming two CAN networks: CAN1 (ECU end) and CAN2 (gateway end). CAN1 is connected to CANoe channel 1, and CAN2 is connected to CANoe channel 2, making the CANoe hardware serially connected between the ECU and the gateway.
[0097] Then, a test project was established. Using the CANoe software, two simulation nodes, CAN1* and CAN2*, were created. CAN1* was set as the ECU, corresponding to channel 1 of the CANoe hardware; CAN2* was set as the gateway, corresponding to channel 2 of the CANoe hardware; and a gateway node APA_GW was created to enable communication between CAN1* and CAN2*.
[0098] The necessary system variables are created in the testing software, including switch variables for controlling gateway functions, variables representing fault injection signals, and variables for defining test data names and storage paths. Subsequently, corresponding operation controls are created in the software's panel editing interface, and each control is associated with the aforementioned system variables, thus constructing a human-computer interactive interface.
[0099] Next, an automated script is used. This script first declares the target communication message and creates flags to control message forwarding, as well as local variables associated with user operations. The script includes an initialization module that synchronously sets relevant variables and forwarding flags based on the state of the switch controls on the control panel. The core signal processing module is responsible for real-time monitoring of messages on the communication channel and, based on the state of the forwarding flags, decides whether to forward directly or modify specific fault signals (e.g., change the signal value to a specified fault state value) and re-verify them before forwarding the processed message to the target controller. Simultaneously, the script's integrated data logging module automatically starts at the beginning of the test and automatically generates a timestamped independent test task file each time a fault injection operation is performed, saving all logs and video data to a preset path.
[0100] Finally, during the test execution phase, the operator triggers the test with a single click using the fault injection control on the panel, and the system automatically completes the fault injection and system function activation. After the test, the system automatically analyzes the recorded data, accurately matches fault events and system responses through time synchronization, and compares the actual system behavior with the security expectations specified in the test cases (e.g., a certain function should not be activated within a specific time). Ultimately, it automatically generates a complete report containing fault details, response time, system status, and test conclusions.
[0101] Based on the intelligent connected vehicle safety testing method provided in the above embodiments, this application also provides specific implementation methods of the intelligent connected vehicle safety testing device. Please refer to the following embodiments.
[0102] First see Figure 4 The intelligent connected vehicle safety testing device 400 provided in this application embodiment includes the following modules: The response module 401 is used to respond to the user's input on the target fault test control on the operation panel and determine the target test script and target test cases of the target fault test control.
[0103] The determination module 402 is used to determine the access point of the vehicle communication signal transceiver in the vehicle network based on the target test cases and the vehicle network topology.
[0104] Access module 403 is used to connect the vehicle communication signal transceiver to the vehicle network through an access point.
[0105] Module 404 is created to create simulated network nodes through the vehicle communication signal transceiver device according to the requirements of the target test cases. The simulated network nodes are virtual nodes that simulate the specific unit functions of a real vehicle network that are directly connected to the access point.
[0106] The execution module 405 is used to simulate vehicle signals through simulated network nodes and execute target test cases corresponding to the target fault test controls based on the target test script.
[0107] The acquisition module 406 is used to acquire the execution results corresponding to the target test cases through the data acquisition device.
[0108] The determination module 402 is also used to determine the vehicle safety test results based on the execution results.
[0109] As one implementation of this application, execution module 405 includes: The interception unit is used to intercept target packets corresponding to each target test case on the corresponding communication channel based on the simulated network node.
[0110] The triggering unit is used to trigger the target test script, which then modifies the corresponding target message according to each target test case.
[0111] The forwarding unit is used to simulate vehicle signals based on simulated network nodes and forward the modified target message to execute the target test case corresponding to the target fault test control.
[0112] As one implementation of this application, the triggering unit includes: The replacement subunit is used to trigger the target test script, which replaces the field data of the target fields in each target message with the test data in the corresponding target test case.
[0113] The calculation subunit is used to recalculate the corresponding first checksum based on the message data fields of the target message after each field data is replaced.
[0114] The modification sub-unit is used to modify the original checksum in each target message based on each first checksum, so as to obtain the modified target message.
[0115] As one implementation of this application, module 406 includes: The triggering unit is used to acquire vehicle data within a preset time period through a data acquisition device when the target test case is triggered. The vehicle data includes timestamps.
[0116] The extraction unit is used to extract the execution results corresponding to the target test cases from the vehicle data based on the timestamp.
[0117] As one implementation of this application, module 402 includes: The comparison unit is used to compare the actual response time in each execution result with the preset response time threshold in the corresponding target test case to obtain the first comparison result.
[0118] The comparison unit is also used to compare the actual vehicle state in each execution result with the preset safety state in the corresponding target test case to obtain a second comparison result.
[0119] The determining unit is used to determine the vehicle safety test results based on the first comparison result and the second comparison result.
[0120] As one implementation of this application, module 404 is created, including: The determination unit is used to determine the test vehicle unit to be simulated based on the vehicle unit connected to the vehicle communication signal transceiver and the requirements of the target test case.
[0121] A creation unit is used to simulate the communication behavior of each test vehicle unit through an onboard communication signal transceiver device, and to create a simulation network node corresponding to each test vehicle unit.
[0122] As one implementation of this application, module 402 includes: The determination unit is used to determine the target vehicle unit corresponding to the fault signal that needs to be injected for the target test case.
[0123] The determination unit is used to determine the communication path corresponding to the execution of the target test cases based on the vehicle network topology diagram and each target vehicle unit.
[0124] The determining unit is also used to determine the access point of the vehicle communication signal transceiver in the vehicle network based on the communication path, wherein the access point is located in the communication path.
[0125] The modules in the intelligent connected vehicle safety testing device provided in this application embodiment can implement the various steps in the above-mentioned intelligent connected vehicle safety testing method and achieve the corresponding effects. For the sake of brevity, they will not be described in detail here.
[0126] Figure 5 A schematic diagram of the structure of the intelligent connected vehicle safety testing hardware provided in an embodiment of this application is shown.
[0127] The intelligent connected vehicle safety testing equipment may include a processor 501 and a memory 502 storing computer program instructions.
[0128] Specifically, the processor 501 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0129] Memory 502 may include mass storage for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 502 is non-volatile solid-state memory.
[0130] The memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, a memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the intelligent connected vehicle safety testing method according to any embodiment of this disclosure.
[0131] The processor 501 reads and executes computer program instructions stored in the memory 502 to implement any of the intelligent connected vehicle safety testing methods in the above embodiments.
[0132] In one example, the intelligent connected vehicle safety testing equipment may also include a communication interface 503 and a bus 510. For example, Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 510 and complete communication with each other.
[0133] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0134] Bus 510 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 510 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.
[0135] Furthermore, in conjunction with the methods for safety testing of intelligent connected vehicles described in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the methods for safety testing of intelligent connected vehicles described in the above embodiments.
[0136] This application also provides a computer program product, including a computer program, which, when executed, implements any of the methods for intelligent connected vehicle safety testing described in the above embodiments.
[0137] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0138] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0139] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0140] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can also be implemented by an FPGA performing the specified functions or actions, or can be implemented by a combination of an FPGA and computer instructions.
[0141] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for intelligent connected vehicle safety testing, the method comprising: The method is applied to a vehicle testing system, which includes an operation panel, an on-board communication signal transceiver, and a data acquisition device. The method includes: In response to user input on the target fault test control on the operation panel, the target test script and target test cases of the target fault test control are determined; Based on the target test cases and the vehicle network topology, determine the access point of the vehicle communication signal transceiver in the vehicle network. The vehicle communication signal transceiver is connected to the vehicle network through the access point. According to the requirements of the target test case, a simulated network node is created through the vehicle communication signal transceiver device. The simulated network node is a virtual node that simulates the specific unit function of a real vehicle network that is directly connected to the access point. The simulation network nodes simulate vehicle signals, and the target test cases corresponding to the target fault test controls are executed based on the target test script. The execution results corresponding to the target test cases are obtained through data acquisition devices; The vehicle safety test results are determined based on the execution results.
2. The SNV safety testing method of claim 1, wherein, The step of simulating vehicle signals through the simulation network nodes and executing target test cases corresponding to the target fault test controls based on the target test script includes: Based on the simulated network nodes, target packets corresponding to each target test case are intercepted on the corresponding communication channels. Trigger the target test script, and modify the corresponding target message according to each target test case using the target test script; Based on the simulated vehicle signals of the simulated network nodes, the modified target message is forwarded to execute the target test case corresponding to the target fault test control.
3. The SNV safety testing method of claim 2, wherein, The triggering of the target test script involves modifying the corresponding target message according to each target test case, including: Trigger the target test script, and replace the field data of the target fields in each of the target messages with the test data in the corresponding target test cases; Based on the message data fields of the target message after each field data is replaced, recalculate the corresponding first checksum; Based on each of the first check codes, the original check codes in each of the target messages are changed to obtain the modified target messages.
4. The SNV safety testing method of claim 1, wherein, The step of acquiring the execution results corresponding to the target test cases through the data acquisition device includes: When the target test case is triggered, vehicle data within a preset time period is acquired through a data acquisition device, and the vehicle data includes timestamps. Based on the timestamp, extract the execution results corresponding to the target test cases from the vehicle data.
5. The SNV safety testing method of claim 1, wherein, Determining the vehicle safety test result based on the execution result includes: The first comparison result is obtained by comparing the actual response time in each of the execution results with the preset response time threshold in the corresponding target test case. The actual vehicle state in each execution result is compared with the preset safety state in the corresponding target test case to obtain a second comparison result. The vehicle safety test results are determined based on the first comparison result and the second comparison result.
6. The SNV safety testing method of claim 1, wherein, The step of creating a simulated network node through the vehicle-mounted communication signal transceiver device according to the requirements of the target test case includes: Based on the vehicle unit connected to the vehicle communication signal transceiver and the requirements of the target test case, determine the test vehicle unit that needs to be simulated. The vehicle-mounted communication signal transceiver is used to simulate the communication behavior of each test vehicle unit and create a simulation network node corresponding to each test vehicle unit.
7. The intelligent connected vehicle safety testing method according to any one of claims 1 to 6, characterized in that, The step of determining the access point of the vehicle communication signal transceiver in the vehicle network based on the target test cases and the vehicle network topology includes: Identify the target vehicle unit corresponding to the fault signal that needs to be injected for the target test case; Based on the vehicle network topology diagram and each target vehicle unit, determine the communication path corresponding to the execution of the target test cases; Based on the communication path, the access point of the vehicle communication signal transceiver in the vehicle network is determined, and the access point is located in the communication path.
8. A safety testing device for intelligent connected vehicles, characterized in that, The device includes: The response module is used to respond to the user's input on the target fault test control on the operation panel and determine the target test script and target test cases of the target fault test control. The determination module is used to determine the access point of the vehicle communication signal transceiver in the vehicle network based on the target test cases and the vehicle network topology. An access module is used to connect the vehicle communication signal transceiver to the vehicle network through the access point; A creation module is used to create simulated network nodes through the vehicle communication signal transceiver device according to the requirements of the target test case. The simulated network nodes are virtual nodes that simulate the specific unit functions of a real vehicle network that are directly connected to the access point. The execution module is used to simulate vehicle signals through the simulation network nodes and execute target test cases corresponding to the target fault test controls based on the target test script. The acquisition module is used to acquire the execution results corresponding to the target test cases through a data acquisition device. The determination module is also used to determine the vehicle safety test results based on the execution results.
9. A safety testing device for intelligent connected vehicles, characterized in that, The device includes: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the intelligent connected vehicle safety testing method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the intelligent connected vehicle safety testing method as described in any one of claims 1-7.
11. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the intelligent connected vehicle safety testing method as described in any one of claims 1-7.