Method and device for identifying a latent fault in a vehicle function

The method identifies and corrects latent faults in vehicle safety systems by simulating real-world hazard scenarios, improving safety and reliability through systematic testing and response verification.

DE102024206571A1Pending Publication Date: 2026-01-15ROBERT BOSCH GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102024206571
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-11
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Existing vehicle safety systems lack a systematic method to identify latent faults in safety functions, which can lead to incomplete or delayed responses to potential hazards, compromising safety and reliability.

Method used

A method involving receiving test hazard warnings, performing predefined vehicle responses, comparing them to target responses, and identifying deviations to detect latent faults, with optional steps for data negotiation, signal connection establishment, and response simulation under real-world conditions.

Benefits of technology

Enables proactive identification and correction of latent faults, enhancing vehicle safety and reliability by ensuring timely and accurate responses to potential hazards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for identifying a latent fault in at least one vehicle function, in particular a safety function, in a vehicle, comprising the steps: - Receiving a test hazard warning from another road user or infrastructure component by the vehicle, wherein the test hazard warning includes data specific to a time, place and / or a traffic situation, particularly a dangerous one; - Performing at least one of the responses to the test hazard message that are predefined or predefinable in the vehicle; - Comparing the at least one reaction performed with a target reaction; - Identifying the latent error depending on a result of the comparison.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method and a device for data processing for identifying a latent fault in at least one vehicle function, in particular a safety function, in a vehicle. State of the art

[0002] The European Telecommunications Standards Organisation (ETSI) has described various safety functions for intelligent transport systems (ITS) based on Vehicle-to-Everything (V2X) technology. These functions include, in particular, traffic hazard warnings, which alert drivers to various road hazards, such as wrong-way driver warnings, warnings of stationary vehicles, traffic condition warnings, signal violation warnings, and construction zone warnings. These warnings enable vehicles to prepare for potential hazards, even if they are not yet directly visible, by, for example, pre-conditioning the braking system to allow for faster automated emergency braking (AEB).

[0003] The unpublished German patent application with file number 102023212930.2 discloses a method for the dynamic assessment of a risk of a future traffic situation for a vehicle, wherein the method comprises a series of steps aimed at collecting and analyzing data in order to assess the risk of a future traffic situation and to initiate measures to reduce the risk. Disclosure of the invention

[0004] Against this background, the approach presented here provides a method for identifying a latent fault in at least one vehicle function, in particular a safety function, in a vehicle. The method comprises the following steps: - Receiving a test hazard warning from another road user or infrastructure component by the vehicle. This test hazard warning contains data specific to a particular time, location, and / or a particularly dangerous traffic situation. This allows the vehicle's response to be tested in realistic and relevant scenarios that could occur in real-world traffic. - Perform at least one of the vehicle's predefined or predefinable responses to the test hazard message. These responses are designed to reflect the vehicle's usual actions in response to real-world hazards, thus creating a realistic test environment. - Comparing the at least one executed response with a target response. This step involves evaluating whether the vehicle's reaction to the test hazard message meets expectations and safety requirements. This comparison allows deviations and potential weaknesses in the vehicle's responsiveness to be identified. - Identifying the latent fault based on a comparison result. If the vehicle's actual response deviates from the expected target response, this is considered an indicator of a latent fault. Identifying such faults is crucial for implementing preventative measures that improve the vehicle's safety and reliability. Advantages of the invention

[0005] By implementing this procedure, a systematic method is provided to verify and optimize the effectiveness and safety of vehicle functions by proactively identifying and addressing potential sources of error.

[0006] Further advantages arise from the sub-claims.

[0007] In a preferred embodiment of the method for identifying latent faults in vehicle functions, a specific step of negotiating the content of a test hazard message takes place before the actual step of receiving it. This negotiation, particularly regarding the data to be included in the test hazard message, occurs with another road user or an infrastructure component. This embodiment enables targeted and needs-based adaptation of the test hazard message to the specific requirements and conditions of the traffic environment. By negotiating the content of the test hazard message, it can be ensured that the data relevant for identifying latent faults are included in the test scenarios.This increases the effectiveness of the procedure by enabling a more precise simulation of real hazardous situations and thus contributing to improved vehicle safety.

[0008] In a further embodiment, the step of receiving or negotiating the test hazard message can be provided for when a predetermined or predefinable relative distance between the vehicle and the other road user or infrastructure component is reached or falls below a certain threshold. This adaptation enables dynamic and situation-dependent communication, ensuring that the test hazard messages are initiated precisely when the spatial configuration between the vehicle and other road users or infrastructure elements provides a realistic test environment. This increases the efficiency and relevance of the test procedure by enabling the simulation of hazardous situations under conditions that more closely resemble real-world traffic conditions.

[0009] In a further embodiment, the relative distance at which the step of receiving or negotiating the test hazard message is initiated can be substantially equivalent to the vehicle's braking distance. Specifically, this distance can be more than 25% and less than 250% of the vehicle's braking distance. This specification ensures that the test hazard messages are triggered under conditions that have immediate relevance to driving safety by reflecting the critical distance for a safe vehicle response to potential hazards. By aligning the test conditions with a range closely related to the vehicle's braking distance, a realistic assessment of vehicle responses is enabled, which contributes to the precise identification and correction of latent defects and thus enhances the safety of the vehicle and its occupants.

[0010] In a further embodiment, it may be provided that, prior to receiving or negotiating the test hazard message, a step of establishing a signal connection with the other road user or infrastructure component takes place. This procedure ensures that a reliable communication basis is established between the participating units before critical information is exchanged. Establishing such a connection before the actual information exchange enables efficient and interference-free transmission of the test hazard messages. This is particularly important for ensuring the integrity and accuracy of the transmitted data, which in turn improves the reliability of the entire procedure for identifying latent faults in vehicle functions.

[0011] In a further embodiment, the step of establishing the signal connection can be carried out via a higher-level instance, in particular a cloud, with this higher-level instance acting as an intermediary between the vehicle and the other road user or infrastructure component. This configuration enables centralized control and coordination of the communication processes, which increases the efficiency and reliability of data transmission. By using a cloud or a similar higher-level instance as an intermediary, complex negotiation and reception processes can be simplified and standardized, which improves compatibility between different systems and enables broader applicability of the method.This structure significantly contributes to the scalability and flexibility of the process by supporting seamless integration into existing and future vehicle communication systems.

[0012] In a further embodiment, the vehicle's response during the execution step can either correspond to a response to an actual hazard warning or occur without or with only reduced actuator intervention in the vehicle's components. This adaptation makes it possible to test the vehicle's responsiveness to simulated hazardous situations without endangering the safety of the occupants or other road users. The ability to vary the intensity of actuator intervention allows for the investigation of different scenarios and their effects on vehicle behavior under controlled conditions. This contributes to a deeper understanding of the capabilities and limitations of the vehicle systems, ultimately leading to the identification and correction of latent faults and improving overall vehicle safety.

[0013] In a further embodiment, the comparison step may include a check to determine whether the test hazard message was received within a predefined or predetermined time, received within a predefined or predetermined error tolerance, interpreted within a predefined or predetermined time, and / or interpreted within a predefined or predetermined error tolerance. Alternatively or additionally, it is checked whether the vehicle's response was implemented within a predefined or predetermined time and / or implemented within a predefined or predetermined error tolerance. This check enables a detailed evaluation of the efficiency and accuracy with which the vehicle responds to the test hazard messages.By defining specific time windows and tolerances for receiving and interpreting test hazard messages, as well as for the vehicle's responses, latent faults can be precisely identified. This methodical approach helps improve the reliability and safety of vehicle systems by ensuring that these systems function effectively and correctly under various conditions.

[0014] In a further embodiment, a latent fault can be identified if the test hazard message is not received within a predefined or predetermined time, not received within a predefined or predetermined error tolerance, not interpreted within a predefined or predetermined time, and / or not interpreted within a predefined or predetermined error tolerance. Alternatively or additionally, a latent fault is identified if the vehicle's response is not implemented within a predefined or predetermined time and / or not implemented within a predefined or predetermined error tolerance. This approach enables the precise and systematic identification of weaknesses in the vehicle's response chain to potential hazards.By defining clear criteria for time and fault tolerances, this method provides a structured framework for evaluating the performance and reliability of vehicle systems. Identifying latent faults based on this framework is crucial for initiating targeted measures to improve vehicle safety and minimize traffic risks.

[0015] In a further embodiment, it can be provided that, upon identification of a latent fault, an output signal is generated, depending on the type of fault identified, in such a way as to restore or at least increase the safety of the affected vehicle function. This measure aims to react immediately to the detection of weaknesses by initiating adaptive or corrective actions specifically tailored to the type of fault. This targeted response to identified faults not only minimizes the immediate danger but also improves the overall reliability and safety of the vehicle in the long term. This proactive approach supports the continuous optimization of vehicle functions and contributes significantly to increasing road safety.

[0016] In a further embodiment, the output signal generated upon identification of a latent fault can be used to make specific adjustments to enhance the safety of the vehicle's operation. These adjustments include modifying the vehicle's driving strategy, configuring at least some vehicle components, and / or issuing a warning to the driver, which can be visual, audible, and / or haptic. Adjusting the driving strategy allows the vehicle's behavior to be proactively adapted to the detected hazardous situation in order to minimize risks. Configuring vehicle components enables the identified fault to be rectified or mitigated directly. Issuing warnings to the driver serves to raise awareness of the situation and allow for manual intervention if necessary.These targeted measures contribute to immediately improving the safety of the vehicle and at the same time offer the possibility of making long-term adjustments to avoid similar errors in the future.

[0017] In a further embodiment, it can be provided that, upon identification of a latent fault, particularly depending on the type of fault identified, this latent fault is forwarded to an external unit, especially a cloud. This step serves to further analyze the latent fault and / or to make the information about the fault available to other road users. Forwarding the fault to an external unit enables in-depth analysis that goes beyond the immediate capabilities of the vehicle and can contribute to the development of solutions that improve the safety not only of the individual vehicle but also of the entire road network. Making this information available to other road users increases general awareness of potential hazards and enables a collective adaptation of driving behavior, thus increasing overall road safety.This networking and exchange of security information plays a crucial role in the realization of an intelligent and reactive transport system that proactively responds to identified risks.

[0018] A data processing device, in particular an in-vehicle device, is provided, specifically designed to execute the method according to one of the previously described embodiments. This device is equipped with the necessary hardware and software components to efficiently and reliably perform the various steps of the method, from negotiating and receiving test hazard messages and analyzing vehicle responses to identifying latent faults and forwarding them to external units. The device may, for example, include sensors, communication modules, processing units, and storage media that work together to enable real-time data acquisition, transmission, and analysis.Integrating this device into the vehicle system enables continuous monitoring and improvement of vehicle safety by identifying and addressing potential vulnerabilities before they can lead to real-world hazards. The device thus serves as a central element of a comprehensive safety management system within the vehicle.

[0019] A computer program is provided which includes commands that, when executed by a computer or device, particularly according to the embodiment described above, cause it to execute the method according to one of the embodiments described above. This program is designed to control and automate the specific steps of the method for identifying latent faults in vehicle functions, from the initial communication with other road users or infrastructure components to the analysis of and response to identified faults. The commands contained in the computer program are designed to instruct the data processing device in the vehicle to perform the necessary operations precisely and efficiently.Implementing this program expands and optimizes the device's functionality to improve vehicle safety through proactive fault detection and handling. The computer program thus provides a flexible and scalable solution for integrating advanced safety technologies into modern vehicles.

[0020] A computer-readable medium is provided on which the computer program according to the previously described embodiment is stored. This medium can be in various forms, for example, as a hard drive, SSD, USB flash drive, SD card, CD-ROM, or as part of an integrated memory module within the device according to the previously described embodiment. Storing the computer program on such a medium enables easy installation and updating of the software required to execute the method according to one of the previously described embodiments. Providing the program on a physical data carrier or in a downloadable digital format ensures compatibility with a wide range of vehicle systems and data processing devices.The computer-readable medium thus serves as a key component for the implementation and dissemination of the technology, which aims to improve vehicle safety by identifying and addressing latent defects. Brief description of the drawing

[0021] Exemplary embodiments of the invention are shown schematically in the drawings and explained in more detail in the following description. The same reference numerals are used for the elements shown in the various figures that have a similar effect, thus omitting a repeated description of the elements.

[0022] They show: Fig. 1. A schematic representation of a method and a device, as well as a computer program and a storage medium according to exemplary embodiments; and Fig. 2 a schematic representation of the process according to an exemplary embodiment.

[0023] As explained above, the present invention describes a method and a device that advantageously enable the verification and optimization of the effectiveness and safety of vehicle functions. In particular, latent (dormant) faults can exist along a signal and processing chain of V2X safety functions / services, preventing the safety functions / services from being fully implemented. Such malfunctions can manifest as complete failure or critical delays. These faults are often not detected early during normal operation because the safety functions / services are only called sporadically. However, regular, dedicated testing of the safety functions / services during normal operation allows for their early detection and the initiation of mitigation measures.

[0024] Fig. Figure 1 illustrates, according to embodiments of the invention (on the left), a method 100 for identifying a latent fault in at least one vehicle function, in particular a safety function, in a vehicle 1.

[0025] Furthermore, the vehicle 1, a data processing device 10, a storage medium 15, and a computer program 20 according to exemplary embodiments of the invention are schematically depicted (on the right-hand side). The device 10 is integrated into or arranged on the vehicle 1. Additionally, a further road user 2, designed as another vehicle 2, and an infrastructure component 5, designed as a Roadside Unit (RSU 5), are shown in the lower right-hand illustration. The further vehicle 2 can be directly connected to the vehicle 1 via signaling (indicated by arrow 4). The further vehicle 2 can additionally or alternatively be connected to the vehicle 1 via signaling via the RSU 5 (indicated by arrows 5 and 6). The vehicle 1 can additionally or alternatively be connected to the RSU 5 via signaling (indicated by arrow 6).Vehicle 1, the other vehicle 2 and / or the RSU 5 can be connected to a Cloud 8 via signaling, with the Cloud 8 also ensuring a signaling connection between Vehicle 1, the other vehicle 2 and / or the RSU 5.

[0026] According to a first procedural step 103, a test hazard message can be received by the vehicle 1 from another road user 2 or an infrastructure component 5, wherein the test hazard message includes data that is specific to a time, a place and / or a traffic situation, in particular a dangerous one.

[0027] Subsequently, according to a second procedure step 104, at least one of the predefined or predefinable reactions to the test hazard message can be carried out in the vehicle 1. In particular, in the execution step 104, the reaction can correspond to an actual hazard message or the reaction can be carried out without or with only reduced actuator intervention in components of the vehicle.

[0028] Subsequently, in a third process step 105, the at least one implemented reaction can be compared with a target reaction. In particular, in the comparison step 105, it can be checked whether the test hazard message was received within a predefined or specified time, received within a predefined or specified error tolerance, interpreted within a predefined or specified time, and / or interpreted within a predefined or specified error tolerance, and / or whether the reaction was implemented within a predefined or specified time and / or implemented within a predefined or specified error tolerance.

[0029] Subsequently, according to a fourth procedural step 106, the latent fault can be identified depending on a result of the comparison. A latent fault can be identified, for example, if the test hazard message was not received within a predefined or specified time, not received within a predefined or specified error tolerance, not interpreted within a predefined or specified time, and / or not interpreted within a predefined or specified error tolerance, and / or if the response was not implemented within a predefined or specified time and / or not implemented within a predefined or specified error tolerance.

[0030] Optionally, if a latent fault has been identified (106), an output signal can be generated in a further process step (107) such that the safety of the vehicle function is restored or at least increased. In particular, the output signal can be used to adjust a driving strategy of the vehicle, to configure at least individual components of the vehicle, and / or to issue a warning to the driver of the vehicle, in particular a visual, acoustic, and / or haptic warning.

[0031] Optionally, if a latent fault has been identified, in particular depending on the identified latent fault, the latent fault can be forwarded to an external vehicle unit, in particular to the cloud, in order to further analyze the latent fault and / or make it available to other road users.

[0032] Optionally, prior to the receiving step 103, a negotiation step 102 of the content of the test hazard message to be received, in particular the data, can take place with the other road user 2 or the infrastructure component 5. Specifically, the receiving step 103 or the negotiation step 102 can then take place when a predetermined or predefinable relative distance between the vehicle 1 and the other road user 2 or the infrastructure component 5 has been reached or fallen below. For example, the relative distance can essentially correspond to a braking distance, in particular more than 25% and less than 250% of the braking distance, of the vehicle 1.

[0033] Optionally, prior to the step of receiving 103 or negotiating 102, a step of establishing a signal connection 4, 6 with the other traffic participant 2 or the infrastructure component 5 can take place. In particular, the step of establishing the signal connection 101 can be carried out via a higher-level instance, especially the cloud 8, whereby the higher-level instance acts as an intermediary.

[0034] It may also be provided that the steps of procedure 100 are repeated or carried out continuously.

[0035] The process steps 101-107 can be performed by the data processing device 10. The device 10 is, for example, configured as a computer and can include means for executing the steps of a process 100 according to exemplary embodiments of the invention. As previously explained, the device 10 can be integrated into the vehicle 1. Furthermore, the device 10 can have a computer program 50 according to exemplary embodiments of the invention. When executed by a computer or the device 10, the computer program 50 can cause it to execute the steps of the process 100 according to exemplary embodiments of the invention. By way of example, the device 10 can be part of the cloud 8, so that the process described below can run at least partially in the cloud 8.

[0036] In Fig.Figure 2 is a schematic representation of the procedure for identifying a latent fault in at least one vehicle function, in particular a safety function, in vehicle 1 according to a further embodiment. Vehicle 1 travels along a section 30 of a road 31, on which another vehicle 2 is traveling ahead of vehicle 1 and on which a third vehicle 2a is approaching vehicle 1. Vehicle 1 receives a test hazard message 40 from the other vehicle 2 via a signal connection 4.

[0037] Alternatively, vehicle 1 can receive the test hazard message 40 from the third vehicle 2a via the signal connection 4a and / or via a connection via the cloud 8.

[0038] Before receiving the test hazard message 40, vehicle 1 and the other vehicle 2 or the third vehicle 2a can connect via the signal connection 4, 4a or via the cloud 8 and negotiate the content of the test hazard message 40 to be received, in particular the data. This can be done, for example, based on the relative positions between vehicle 1 and the other vehicle 2 or the third vehicle 2a. Preferably, vehicle 1 and the other vehicle 2 or the third vehicle 2a are located at a braking distance from each other, i.e., that the relative distance essentially corresponds to a braking distance, in particular more than 25% and less than 250% of the braking distance, of vehicle 1.

[0039] The test hazard message 40 includes data specific to a time of danger, a location of danger, and / or a traffic situation, particularly a dangerous one. Preferably, the traffic situation is such that emergency braking, particularly automatic braking, becomes necessary for vehicle 1. Preferably, the time of the danger is in the immediate future for vehicle 1 and is chosen such that, in the event of a necessary automatic emergency braking, this could still be successfully carried out depending on the relative position of vehicle 1 from the location of the danger. Preferably, the location of the danger and / or the traffic situation is in the immediate vicinity, particularly on the route segment 30 of vehicle 1. Here, the location of the danger can preferably be based on map information from vehicle 1 and / or the other vehicle 2.Furthermore, the location of the danger may preferably depend on a, in particular momentary, position of the vehicle 1, on a, in particular momentary, speed 50, on a tolerance or reaction time 52 of the vehicle 1 (or its driver) and / or on a braking distance 54 (depending on the speed 50 of the vehicle 1) of the vehicle 1.

[0040] In particular, immediately after receiving the test hazard message 40, vehicle 1 performs a predefined or predefinable reaction to the test hazard message 40. This reaction can correspond to an actual hazard message, so that vehicle 1 reacts to the test hazard message 40 as if an actual hazard message were present.

[0041] Alternatively, the response can occur without or with reduced actuator intervention in components of vehicle 1. For this purpose, the test hazard message 40 can be explicitly marked as such, for example by transmitting additional information or by containing erroneous entries in the data of the test hazard message 40.

[0042] The vehicle 1 or device 10 then compares the implemented response with a target response, particularly based on the data from the test hazard message 40 and its transmission time. This process checks whether the test hazard message 40 was received within a predefined or predetermined time, received within a predefined or predetermined error tolerance, and / or interpreted within a predefined or predetermined error tolerance, and / or whether the response was implemented within a predefined or predetermined time and / or interpreted within a predefined or predetermined error tolerance.

[0043] If it turns out that the test hazard message 40 was not received within a predefined or specified time and / or not within a predefined or specified error tolerance, then, for example, a fault in the signal connection 4, 4a to the further vehicle 2 or the third vehicle 2a and / or to the cloud 8 can be inferred.

[0044] If it turns out that the test hazard message 40 was not interpreted within a predefined or specified error tolerance and / or was not interpreted within a predefined or specified time, then, for example, a fault in a processing system of vehicle 1 can be inferred.

[0045] If it turns out that the test hazard message 40 did not result in a reaction within a predeterminable or specified time and / or not within a predeterminable or specified error tolerance (for example, through timely and appropriate preconditioning of the braking system of vehicle 1 in the event of automatic emergency braking), then, for example, a fault in an actuator system, in particular the braking system, of vehicle 1 can be inferred.

[0046] If such a (latent) fault is present, an output signal can be generated, depending on the identified latent fault, in such a way as to restore or at least increase the safety of the vehicle's function. In particular, the output signal can be used to adjust a driving strategy of vehicle 1, reconfigure at least one component of vehicle 1, and / or issue a warning, in particular visual, acoustic, and / or haptic, to the driver of vehicle 1.

[0047] For example, the driving strategy may be adjusted (e.g., driving slower at specific geolocal points; rejecting the assumption that automatic emergency braking will be reported in time via V2X communication), the system configuration may be adjusted (e.g., brake preload or other actuator systems even without a V2X message), or the driver may be warned that the respective vehicle function, especially safety function, is not available or only available to a limited extent.

[0048] Optionally, if a latent fault is identified, and depending on the specific latent fault, it can be forwarded to an external unit, particularly Cloud 8, for further analysis and / or to make it available to other road users. This effectively creates a geolocal data collection. By executing this vehicle function multiple times across a fleet of vehicles, a Quality of Service (QoS) map for event-based V2X safety functions can be generated in the backend / Cloud 8. This map can then be used by the fleet to determine the availability and speed of the V2X safety function and to adjust its driving / system strategy accordingly.

Claims

[1] Method (100) for identifying a latent fault in at least one vehicle function, in particular a safety function, in a vehicle (1), comprising the steps: - Receiving (103) a test hazard message (40) from another road user (2) or an infrastructure component (5) by the vehicle (1), wherein the test hazard message (40) includes data specific to a time, place and / or a traffic situation, in particular a dangerous one; - Perform (104) at least one of the responses to the test hazard message (40) that are predefined or predefinable in the vehicle (1); - Compare (105) the at least one reaction carried out with a target reaction; - Identifying (106) the latent error depending on a result of the comparison. [2] Method (100) according to claim 1, characterized by, that prior to the step of receiving (103) a step of negotiating (102) the content of the test hazard message to be received (40), in particular the data, takes place with the other road user (2) or the infrastructure component (5). [3] Method (100) according to claim 1 or 2, characterized by , that the step of receiving (103) or negotiating (102) takes place when a predetermined or predetermined relative distance between the vehicle (1) and the other road user (2) or the infrastructure component (5) is reached or falls below a certain threshold. [4] Method (100) according to claim 3, characterized by , that the relative distance is essentially equivalent to a braking distance, in particular more than 25% and less than 250% of the braking distance, of the vehicle (1). [5] Method (100) according to any one of the preceding claims, characterized by, that before the step of receiving (103) or negotiating (102) a step of establishing (101) a signaling connection (4, 6) with the other road user (2) or the infrastructure component (5) takes place. [6] Method (100) according to claim 5, characterized by , that the step of establishing (101) the signal connection (5, 6) is carried out via a higher-level instance, in particular a cloud (8), with the higher-level instance acting as an intermediary. [7] Method (100) according to any one of the preceding claims, characterized by , that in the step of carrying out (104) the reaction corresponds to an actual hazard warning or that the reaction takes place without or with only a reduced actuator intervention in components of the vehicle (1). [8] Method (100) according to any one of the preceding claims, characterized by, that in the comparison step (105) it is checked whether the test hazard message (40) was received within a predefinable or specified time, received within a predefinable or specified error tolerance, interpreted within a predefinable or specified time and / or interpreted within a predefinable or specified error tolerance and / or whether the response was implemented within a predefinable or specified time and / or implemented within a predefinable or specified error tolerance. [9] Method (100) according to any one of the preceding claims, characterized by, that a latent fault is identified if the test hazard message (40) is not received within a predeterminable or predetermined time, is not received within a predeterminable or predetermined fault tolerance, is not interpreted within a predeterminable or predetermined time and / or is not interpreted within a predeterminable or predetermined fault tolerance and / or if the response is not implemented within a predeterminable or predetermined time and / or is not implemented within a predeterminable or predetermined fault tolerance. [10] Method (100) according to any one of the preceding claims, characterized by , that if a latent fault is identified, an output signal is generated depending on the identified latent fault in such a way that the safety of the vehicle function is restored or at least increased. [11] Method (100) according to claim 10, characterized by, that the output signal is used to adapt a driving strategy of the vehicle (1), to configure at least individual components of the vehicle (1) and / or to issue a warning to the driver of the vehicle (1), in particular an optical, acoustic and / or haptic warning. [12] Method (100) according to any one of the preceding claims, characterized by , that if a latent fault is identified, in particular depending on the identified latent fault, the latent fault is forwarded to an external vehicle unit, in particular to a cloud (8) in order to further analyze the latent fault and / or make it available to other road users (2). [13] Device (10) for data processing, in particular an in-vehicle device, which is configured to carry out the method (100) according to any one of claims 1 to 12. [14] Computer program (20) comprising instructions which, when the computer program (20) is executed by a computer or by a device (10) according to claim 13, cause it to execute the method (100) according to any one of claims 1 to 12. [15] Computer-readable medium (15) on which the computer program (20) according to claim 14 is stored.

Citation Information

Patent Citations

  • Method, system, vehicle, and a computer program for executing a test procedure

    DE102018213011A1

  • Procedure for automated vehicle control and infrastructure arrangement

    DE102021212438A1

  • Method for verifying that a system comprising several individual components performs a function jointly through the several individual components

    DE102022205943A1

  • Method for carrying out a safety function of a vehicle and system for carrying out the method

    US9566966B2