Computer-implemented method and control unit for determining a required safety integrity level of safety-related vehicle functions

DE502023004169D1Active Publication Date: 2026-06-03ROBERT BOSCH GMBH

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
ROBERT BOSCH GMBH
Filing Date
2023-07-03
Publication Date
2026-06-03

AI Technical Summary

Technical Problem

Existing methods for determining the safety integrity level (ASIL) of safety-related vehicle functions are based on assumptions during the development phase, leading to potential misclassification of functions as less critical than they should be, especially in environmental perception, resulting in insufficient safety or reliability in specific situations.

Method used

A method and control unit that dynamically determine the safety integrity level of safety-related vehicle functions using a combination of infrastructure data and vehicle sensor data, allowing for situation-dependent assessment and leveraging external resources like cloud or edge computing to validate and adjust sensor data in real-time, thereby improving reliability.

Benefits of technology

Enhances the reliability of safety-related vehicle functions by accurately adjusting sensor operation and algorithm usage based on real-time environmental conditions, reducing resource consumption and enhancing safety in varying scenarios.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a computer-implemented method for determining a required safety integrity level of safety-related vehicle functions of an environment model comprising a plurality of safety-related vehicle functions.

[0002] Furthermore, the invention relates to a control unit for determining a required safety integrity level of safety-related vehicle functions of an environment model comprising a plurality of safety-related vehicle functions.

[0003] Safety standards such as ISO 26262 describe the recommended approach for developing safety-related functions. A first step is determining the safety integrity of functions based on a risk analysis, such as the Hazard Analysis and Risk Assessment (HARA) in ISO 26262. This is carried out during the development phase based on assumptions about the use of the function or the system that contains the function in question.

[0004] In ISO 26262, this is done, for example, using parameters such as the probability of occurrence of a situation in which a malfunction could be dangerous, the potential controllability of this malfunction, and the severity of the impact if this malfunction cannot be controlled in this situation. The assessment then yields a necessary safety integrity level (e.g., ASIL) for a function, based on which the necessary development processes and safety mechanisms are derived from the safety standard.

[0005] This results in both applicable design and test methods for the hardware and software, as well as the necessary ASIL compliance of hardware components on which the safety-related software later runs, which can be achieved, for example, through extensive diagnostics and the provision of hardware redundancies.

[0006] DE 102015200422 A1 discloses a vehicle control and calculation system comprising a task controller in the vehicle, a vehicle-specific calculation manager in a cloud network, and a wireless data channel that couples the task controller and the cloud network, wherein the task controller performs operational tasks in the vehicle using data-related resources in the cloud network, wherein, upon initiation of one of the operational tasks, the task controller sends an exchange signal to the calculation manager as a resource request, wherein the calculation manager calls at least one cloud-based agent from a database of predetermined agents in response to the exchange signal, and wherein the task controller completes the operational task by communicating with the called agent.

[0007] DE 102019214453 A1 discloses a method for the safe execution of a function provided by a motor vehicle, comprising the following steps: receiving infrastructure data signals representing infrastructure data intended for a function provided by a motor vehicle, receiving safety condition signals representing at least one safety condition that must be met for the function to be executed based on the infrastructure data, checking whether the at least one safety condition is met, determining whether the function may be executed based on the infrastructure data based on a result of the check, generating result signals representing a result of the determination, and outputting the generated result signals.

[0008] DE 10 2019 218 078 A1 discloses a method on board a motor vehicle comprising steps of recording determinations of a predetermined set of facts in the vicinity of the motor vehicle, wherein the determinations are carried out on the basis of different information sources; of selecting one of the information sources; of determining a significance of determinations on the basis of the selected information source; and of determining the set of facts on the basis of the recorded determinations.

[0009] US 7,102,496 B1 discloses a sensor system for use in a vehicle that integrates sensor data from more than one sensor to facilitate collision avoidance and other types of sensor-related processing. All sensor data can be comprehensively integrated by a threat assessment subsystem within the sensor system.

[0010] Typically, the ASIL of a function is determined and fixed during the development phase based on assumptions about "worst-case" situations. However, considering the multitude of possible situations, it is easy to see that the malfunction of a safety-related function is not dangerous in many of them. This applies to both primary functions, such as actuator control (e.g., unintentional engine shutdown while stationary), and secondary functions, such as environmental perception (e.g., object detection in distant areas at low speeds).

[0011] On the other hand, in environmental perception, due to incorrect or insufficient specification of safety requirements during the design phase, it can also happen that in specific situations functions for generating the environmental model, e.g. sensor coverage of a specific viewing area, are classified with too low a safety criticality and consequently are not executed with sufficient safety or reliability.

[0012] The invention is therefore based on the objective of providing an improved method and control unit for determining a required safety integrity level of safety-related vehicle functions of an environment model having a plurality of safety-related vehicle functions, which enables a situation-dependent determination of a safety integrity level of a safety-related vehicle function.

[0013] The problem is solved by a computer-implemented method for determining a required safety integrity level of safety-related vehicle functions of an environment model having a plurality of safety-related vehicle functions with the features of claim 1.

[0014] Furthermore, the problem is solved with a control unit for determining a required safety integrity level of safety-related vehicle functions of an environment model having a plurality of safety-related vehicle functions with the features of claim 13.

[0015] Furthermore, the problem is solved with a computer program having the features of claim 14 and a computer-readable data carrier having the features of claim 15. Disclosure of the invention

[0016] The present invention provides a computer-implemented method for determining a required safety integrity level of safety-related vehicle functions of an environment model of a vehicle environment that includes a plurality of safety-related vehicle functions.

[0017] The procedure includes providing at least one infrastructure data signal representing infrastructure data and at least one vehicle sensor data signal representing vehicle sensor data, each of which is intended for the majority of safety-related vehicle functions.

[0018] The procedure further includes determining a safety integrity level of the majority of safety-related vehicle functions based on the provided at least one infrastructure data signal and the at least one vehicle sensor data signal, wherein the at least one vehicle sensor data signal with a first weighting and the at least one infrastructure data signal with a second weighting contribute to determining the required safety integrity level of the majority of safety-related vehicle functions.

[0019] The safety integrity level can be calculated, for example, by a weighted sum of the data signal from at least one vehicle sensor and the data signal from at least one vehicle sensor.

[0020] The safety integrity level of the vehicle function represents or describes a level or stage of the safety integrity of the vehicle function. The safety integrity of the vehicle function refers in particular to the reliability of the vehicle function, which can be determined, for example, by means of a risk assessment.

[0021] The present invention further provides a control unit for determining a required safety integrity level of safety-related vehicle functions of an environment model comprising a plurality of safety-related vehicle functions.

[0022] The control unit includes initial means for providing at least one infrastructure data signal representing infrastructure data and at least one vehicle sensor data signal representing vehicle sensor data, each of which is intended for the majority of safety-related vehicle functions.

[0023] Furthermore, the control unit includes second means for determining a required safety integrity level of the majority of safety-related vehicle functions based on the provided at least one infrastructure data signal and the at least one vehicle sensor data signal, wherein the second means are configured to incorporate the at least one vehicle sensor data signal with a first weighting and the at least one infrastructure data signal with a second weighting into the determination of the safety integrity level of the majority of safety-related vehicle functions.

[0024] The present invention further provides a computer program with program code for carrying out the method according to the invention when the computer program is executed on a computer, and a computer-readable data carrier with program code of a computer program for carrying out the method according to the invention when the computer program is executed on a computer.

[0025] Typically, a safety-related function is implemented using dedicated software developed with the appropriate ASIL and on dedicated hardware developed with the appropriate ASIL. Therefore, in traditional vehicle E / E architectures, there is no advantage to dynamically implementing functions on hardware and software with different ASILs, as the necessary hardware and software are already available.

[0026] Future vehicle E / E architectures will be heavily networked with external systems, such as cloud, edge, other vehicles, and / or smart devices. This offers the possibility of outsourcing functions. However, the ASIL of a function is a limitation for this outsourcing, as these external systems are often not developed according to a safety standard such as ISO 26262 and therefore do not offer the necessary ASIL compliance.

[0027] One idea of ​​the present invention is therefore to determine the relevant or critical and non-relevant or non-critical areas of the environment model during operation not only from within the vehicle - directly or indirectly via scenario recognition - but also to make them locally available via local information, such as a connection to a cloud, e.g. a static and / or dynamic map or spatial computing, to a local edge server or to a dedicated local transmitting unit, e.g. a retrofit device at a traffic light.

[0028] Thus, the safety criticality of perception functions in certain areas around an ego-vehicle at a geographical location can be advantageously determined more effectively based on current local perception or through statistical evaluation of historical local measurement data.

[0029] This verified additional information allows misjudgments by the vehicle's sensors to be corrected internally, thus increasing safety. These misjudgments can be caused both by a faulty perception of the situation by the vehicle and by a miscalculation by the developer of the potential for critical events.

[0030] This allows design flaws, such as overlooking specific edge and corner cases, to be compensated for locally after the fact, thus increasing security. This information can be comprehensively validated over a long period – even during operation – before being released externally. This improves reliability and facilitates the security argumentation for the overall system.

[0031] With high reliability of the information, e.g. transmitted via metadata or otherwise guaranteed, the vehicle can also better implement the calculation of the environment model, perception functions and / or sub-functions) in areas that have been locally determined to be non-safety-relevant, based on external specifications, by, for example, providing less redundancy, suspending measurement cycles, reducing resolution, or completely foregoing data acquisition.

[0032] This temporarily frees up resources that can be used for other functions. Furthermore, a potential in-vehicle determination of real-time safety requirements could be implemented more efficiently via this second, highly reliable path, or even temporarily and / or locally omitted entirely, thereby also freeing up resources, at least temporarily.

[0033] According to a preferred further development, at least one infrastructure data signal is intended to contain information about which regional areas of the vehicle's environment exhibit which safety integrity level. This allows for the determination of the degree to which the regional areas of the vehicle's environment are safety-critical.

[0034] According to a further preferred development, it is provided that at least one infrastructure data signal contains information about static obstacles, traffic infrastructure and / or dynamic objects.

[0035] Static obstacles can include, for example, fallen stones next to a slope, frequent potholes in spring, lost cargo, bicycles and / or scooters on the road next to a bicycle or scooter parking area, and / or overhanging branches. Dynamic objects can include, for example, vehicles cutting in sharply from a road with poor visibility, and / or a bicycle path entering from the right on a sloping road.

[0036] According to a further preferred development, it is provided that at least one infrastructure data signal contains information about a type of object that occurs with a given probability in regional areas of the vehicle's environment and a type of object that does not occur with a given probability in regional areas of the vehicle's environment.

[0037] Frequently occurring objects might include, for example, trucks entering a company premises, motorcyclists on weekends, children in front of a school, and / or costumed individuals near a carnival parade. Less frequently occurring objects might include, for example, pedestrians from an area inaccessible to people, particularly due to a no-entry sign and / or physically inaccessible locations or walls or fences that cannot be crossed.

[0038] According to a further preferred development, at least one infrastructure data signal is intended to contain information about traffic density, time of day, weather, lighting conditions, and / or the position of the sun. These factors can then be included in determining the safety integrity level.

[0039] According to a further preferred embodiment, data, in particular a control signal for activating at least one vehicle sensor, are generated based on the determined safety integrity level of the majority of safety-related vehicle functions. This data represents which sensor modalities, in particular video, radar, lidar, ultrasound, and / or microphone, are to be used to cover regional areas of the vehicle's environment by vehicle sensors. This advantageously improves the safety integrity level of the majority of safety-related vehicle functions.

[0040] According to a further preferred enhancement, it is provided that, based on the determined safety integrity level of the majority of safety-related vehicle functions, initial data, in particular a control signal for activating at least one vehicle sensor, are generated. This data represents the sensor redundancy, sensor resolution, and / or sensor measurement frequency required to cover regional areas of the vehicle's environment. This ensures more precise sensor detection of a scenario by the safety-related vehicle function.

[0041] According to a further preferred enhancement, it is provided that, based on the determined safety integrity level of the majority of safety-related vehicle functions, secondary data, in particular a control signal, are generated to weight perception functions, object models, and / or motion models regarding their suitability for detecting a vehicle environment. This can be carried out particularly if different variants for a perception function are available.

[0042] According to a further preferred development, it is provided that, based on the specific safety integrity level of the majority of safety-related vehicle functions, third-party data, in particular a control signal, are generated for selecting an algorithm type, especially a Kalman filter or a deep learning-based algorithm. Thus, an optimal algorithm for the respective situation can be used in each case.

[0043] According to a further preferred embodiment, it is provided that, based on the determined safety integrity level of the majority of safety-related vehicle functions, fourth data, in particular a control signal, is generated for setting at least one limit value of an object detector. This advantageously reduces the occurrence of erroneous object detection.

[0044] According to a further preferred development, it is provided that, based on the determined safety integrity level of the majority of safety-related vehicle functions, fifth data, in particular a control signal, is generated for selecting a control unit, especially for carrying out the safety-related vehicle functions. This can be done if several systems or control units are available for the same perception function.

[0045] According to a further preferred development, at least one infrastructure data signal is provided before or while passing through a section of the road monitored by vehicle sensors. This allows the at least one provided infrastructure data signal to support the determination of the safety integrity level of the majority of safety-related vehicle functions.

[0046] The described configurations and training programs can be combined in any way desired.

[0047] Further possible embodiments, developments and implementations of the invention also include combinations of features of the invention described previously or subsequently with regard to the exemplary embodiments that are not explicitly mentioned. Brief description of the drawings

[0048] The accompanying drawings are intended to provide a further understanding of the embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain the principles and concepts of the invention.

[0049] Other embodiments and many of the aforementioned advantages become apparent with reference to the drawings. The elements depicted in the drawings are not necessarily shown to scale.

[0050] They show: Fig. 1 a flowchart of a computer-implemented method for determining a required safety integrity level of a safety-related vehicle function of a motor vehicle according to a preferred embodiment of the invention; and Fig. 2 a schematic representation of a control unit for determining a required safety integrity level of a safety-related vehicle function of a motor vehicle according to the preferred embodiment of the invention.

[0051] That is Fig. 1 shown computer-implemented methods for determining a required safety integrity level 14 safety-related vehicle functions 12 of an environment model of a vehicle environment having a plurality of safety-related vehicle functions 12.

[0052] The procedure includes providing S1 at least one infrastructure data signal 10a representing infrastructure data and at least one vehicle sensor data signal 10b representing vehicle sensor data, each of which is intended for the majority of safety-related vehicle functions 12.

[0053] Furthermore, the procedure includes determining S2 a safety integrity level 14 of the plurality of safety-related vehicle functions 12 based on the provided at least one infrastructure data signal 10a and the at least one vehicle sensor data signal 10b, wherein the at least one vehicle sensor data signal 10b with a first weighting 16a and the at least one infrastructure data signal 10a with a second weighting 16b are incorporated into the determination of the safety integrity level 14 of the plurality of safety-related vehicle functions 12.

[0054] The at least one Infrastructure Data Signal 10a also contains information about which regional areas have which Security Integrity Level 14. Furthermore, the at least one Infrastructure Data Signal 10a contains information about static obstacles, traffic infrastructure, and / or dynamic objects. The at least one Infrastructure Data Signal 10a also contains information about a type of object that occurs in regional areas with a given probability and a type of object that does not occur in regional areas with a given probability. Additionally, the at least one Infrastructure Data Signal 10a contains information about traffic density, time of day, weather, lighting conditions, and / or the position of the sun.

[0055] Based on the determined safety integrity level 14 of the majority of safety-related vehicle functions 12, initial data D1, in particular a control signal for controlling at least one vehicle sensor 18, are generated, which represent with which sensor modalities, in particular video, radar, lidar, ultrasound and / or microphone, regional areas of the vehicle's environment are to be covered by vehicle sensors 18.

[0056] Furthermore, based on the determined safety integrity level 14 of the majority of safety-related vehicle functions 12, second data D2, in particular a control signal for controlling at least one vehicle sensor 18, are generated, which represent with which sensor redundancy, sensor resolution and / or sensor measurement frequency regional areas of the vehicle's environment are to be covered.

[0057] Furthermore, based on the determined safety integrity level 14 of the majority of safety-related vehicle functions 12 third data D3, in particular a control signal, are generated to weight perception functions, object models and / or motion models regarding their suitability for detecting a vehicle environment.

[0058] Furthermore, based on the determined safety integrity level 14 of the majority of safety-related vehicle functions 12 fourth data D4, in particular a control signal, are generated for the selection of an algorithm type, in particular a Kalman filter or a deep learning-based algorithm.

[0059] Based on the defined safety integrity level 14 of the majority of safety-related vehicle functions 12, fifth data D5, in particular a control signal, is generated for setting at least one limit value of an object detector. Furthermore, based on the defined safety integrity level 14 of the majority of safety-related vehicle functions 12, sixth data D6, in particular a control signal, is generated for selecting a control unit, in particular for carrying out the safety-related vehicle functions 12. The at least one infrastructure data signal 10a is also provided either before or while passing through a section of the route detected by vehicle sensors 18.

[0060] Fig. 2Figure 1 shows a schematic representation of a control unit for determining a required safety integrity level 14 of a safety-related vehicle function 12 of a motor vehicle according to the preferred embodiment of the invention.

[0061] The control unit 20 comprises first means 22 for providing at least one infrastructure data signal 10a representing infrastructure data and at least one vehicle sensor data signal 10b representing vehicle sensor data, each of which is intended for the majority of safety-related vehicle functions 12.

[0062] Furthermore, the control unit 20 comprises second means 24 for determining a required safety integrity level 14 of the plurality of safety-related vehicle functions 12 based on the provided at least one infrastructure data signal 10a and the at least one vehicle sensor data signal 10b, wherein the second means 24 are configured to incorporate the at least one vehicle sensor data signal 10b with a first weighting 16a and the at least one infrastructure data signal 10a with a second weighting 16b into the determination of the safety integrity level 14 of the plurality of safety-related vehicle functions 12.

Claims

1. Computer-implemented method for determining a required safety integrity level (14) of safety-related vehicle functions (12) of an environmental model of an environment of a vehicle comprising a plurality of safety-related vehicle functions (12), comprising the steps of: providing (S1) at least one infrastructure data signal (10a) representing infrastructure data and at least one vehicle sensor data signal (10b) representing vehicle sensor data, each of which is intended for the plurality of safety-related vehicle functions (12); and determining (S2) a safety integrity level (14) of the plurality of safety-related vehicle functions (12) based on the provided at least one infrastructure data signal (10a) and the at least one vehicle sensor data signal (10b), wherein the vehicle sensor data signal (10b) with a first weighting (16a) and the infrastructure data signal (10a) with a second weighting (16b) contribute to determining the required safety integrity level (14) of the plurality of safety-related vehicle functions (12).

2. Computer-implemented method according to Claim 1, wherein the at least one infrastructure data signal (10a) has information about which regional areas of the environment of the vehicle have which safety integrity level (14).

3. Computer-implemented method according to Claim 1 or 2, wherein the at least one infrastructure data signal (10a) has information about static obstacles, a traffic infrastructure and / or dynamic objects.

4. Computer-implemented method according to one of the preceding claims, wherein the at least one infrastructure data signal (10a) has information about a type of objects occurring with a predefined probability in regional areas of the environment of the vehicle and a type of objects not occurring with a predefined probability in regional areas of the environment of the vehicle.

5. Computer-implemented method according to one of the preceding claims, wherein the at least one infrastructure data signal (10a) has information about a traffic density, a time, weather, light conditions, and / or a position of the sun.

6. Computer-implemented method according to one of the preceding claims, wherein, based on the determined safety integrity level (14) of the plurality of safety-related vehicle functions (12), first data (D1), in particular a control signal for controlling at least one vehicle sensor (18), are generated and represent the sensor modalities, in particular video, radar, lidar, ultrasound and / or microphone, with which regional areas of the environment of the vehicle must be covered by vehicle sensors (18).

7. Computer-implemented method according to one of the preceding claims, wherein, based on the determined safety integrity level (14) of the plurality of safety-related vehicle functions (12), second data (D2), in particular a control signal for controlling at least one vehicle sensor (18), are generated and represent the sensor redundancy, sensor resolution and / or sensor measurement frequency with which regional areas of the environment of the vehicle must be covered.

8. Computer-implemented method according to one of the preceding claims, wherein, based on the determined safety integrity level (14) of the plurality of safety-related vehicle functions (12), third data (D3), in particular a control signal, for weighting perception functions, object models and / or motion models regarding their suitability for capturing a vehicle environment are generated.

9. Computer-implemented method according to one of the preceding claims, wherein, based on the determined safety integrity level (14) of the plurality of safety-related vehicle functions (12), fourth data (D4), in particular a control signal, for selecting an algorithm type, in particular a Kalman filter or a deep-learning-based algorithm, are generated.

10. Computer-implemented method according to one of the preceding claims, wherein, based on the determined safety integrity level (14) of the plurality of safety-related vehicle functions (12), fifth data (D5), in particular a control signal, for setting at least one limit value of an object detector are generated.

11. Computer-implemented method according to one of the preceding claims, wherein, based on the determined safety integrity level (14) of the plurality of safety-related vehicle functions (12), sixth data (D6), in particular a control signal, for selecting a control device, in particular for carrying out the safety-related vehicle functions (12), are generated.

12. Computer-implemented method according to one of the preceding claims, wherein the at least one infrastructure data signal (10a) is provided before or when driving through a route section captured by vehicle sensors (18).

13. Control device (20) for determining a required safety integrity level (14) of safety-related vehicle functions (12) of an environmental model of an environment of a vehicle comprising a plurality of safety-related vehicle functions (12), comprising: first means (22) for providing at least one infrastructure data signal (10a) representing infrastructure data and at least one vehicle sensor data signal (10b) representing vehicle sensor data, each of which is intended for the plurality of safety-related vehicle functions (12); and second means (24) for determining (S2) a safety integrity level (14) of the plurality of safety-related vehicle functions (12) based on the provided at least one infrastructure data signal (10a) and the at least one vehicle sensor data signal (10b), wherein the second means (24) are configured to incorporate the at least one vehicle sensor data signal (10b) with a first weighting (16a) and the at least one infrastructure data signal (10a) with a second weighting (16b) for determining the required safety integrity level (14) of the plurality of safety-related vehicle functions (12).

14. Computer program comprising program code for carrying out the method according to one of Claims 1 to 12 when the computer program is executed on a computer.

15. Computer-readable data carrier comprising program code of a computer program for carrying out the method according to one of Claims 1 to 12 when the computer program is executed on a computer.