Method and controller for determining a safety integrity level for a safety-related vehicle function of a motor vehicle

EP4552014A1Pending Publication Date: 2025-05-14ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023738482
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-06
Filing Date
2023-07-03
Publication Date
2025-05-14

AI Technical Summary

Technical Problem

Current methods for determining the safety integrity level (ASIL) of safety-related vehicle functions are based on assumptions about worst-case scenarios, which may not accurately reflect the actual danger of malfunctions in various situations, limiting the dynamic allocation of these functions to external systems that may not comply with security standards like ISO 26262.

Method used

A computer-implemented method and control device that dynamically determine the safety integrity level of safety-related vehicle functions using real-time infrastructure and vehicle sensor data, allowing for situation-dependent allocation of these functions to internal or external systems based on current driving conditions and available resources, enabling outsourcing of functions to external systems while ensuring ASIL compliance.

Benefits of technology

Enables real-time, context-dependent determination of safety integrity levels, allowing for efficient resource allocation and outsourcing of safety-related functions, particularly beneficial for automated driving tasks, by accurately assessing the criticality of driving situations and available system integrity, thereby enhancing safety and flexibility in vehicle E/E architectures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a computer-implemented method for determining a safety integrity level (14) for a safety-related vehicle function (12) of a motor vehicle. The method has the steps of providing (S1) at least one infrastructure and / or vehicle sensor data signal (10) which represents infrastructure and / or vehicle sensor data that is determined for a safety-related vehicle function (12) provided by means of a motor vehicle; determining (S2) a safety integrity level (14) for the safety-related vehicle function (12) on the basis of the provided infrastructure and / or vehicle sensor data signal (10), and allocating (S3) a calculation of the safety-related vehicle function (12) to a vehicle-internal and / or a vehicle-external system while taking into consideration the specified safety integrity of the vehicle-internal and / or the vehicle-external system. The invention additionally relates a controller (20) for determining a safety integrity level (14) for a safety-related vehicle function (12) of a motor vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] title

[0003] Method and control device for determining a safety integrity level of a safety-related vehicle function of a motor vehicle

[0004] The invention relates to a method for determining a safety integrity level of a safety-related vehicle function of a motor vehicle.

[0005] Furthermore, the invention relates to a control device for determining a safety integrity level of a safety-related vehicle function of a motor vehicle.

[0006] Safety standards such as ISO 26262 describe the recommended approach for developing safety-related functions. A first step is determining the safety integrity of functions based on a risk analysis, e.g., the Hazard Analysis and Risk Assessment (HARA) in ISO 26262. This is performed during development based on assumptions about the use of the function or the system containing the function in question.

[0007] In ISO 26262, for example, this is done using the parameters of the probability of occurrence of a situation in which a malfunction could be dangerous, the potential controllability of this malfunction, and the severity of the impact if this malfunction cannot be controlled in this situation. The assessment then results in a required safety integrity level (e.g., ASIL) for a function, based on which the necessary development processes and safety mechanisms are derived from the safety standard. This results in both applicable design and test methods for the hardware and software, as well as the required ASIL compliance of hardware components on which the safety-related software will later run. This can be achieved, for example, through extensive diagnostics and the provision of hardware redundancies.

[0008] DE 102015200422 A1 discloses a vehicle control and computation system comprising a task controller in the vehicle, a vehicle-specific computation manager in a cloud network, and a wireless data channel coupling the task controller and the cloud network, wherein the task controller performs operational tasks in the vehicle using data-related resources in the cloud network, wherein upon initiation of one of the operational tasks, the task controller sends an exchange signal to the computation manager as a resource request, wherein the computation manager calls at least one cloud-based agent from a database of predetermined agents in response to the exchange signal, and wherein the task controller completes the operational task by communicating with the called agent.

[0009] DE 102019214453 A1 discloses a method for safely executing a function provided by a motor vehicle, comprising the following steps: receiving infrastructure data signals representing infrastructure data intended for a function provided by a motor vehicle, receiving safety condition signals representing at least one safety condition that must be met in order for the function to be executed based on the infrastructure data, checking whether the at least one safety condition is met, determining whether the function may be executed based on the infrastructure data based on a result of the checking, generating result signals representing a result of the determining, and outputting the generated result signals.

[0010] Typically, the ASIL of a function is determined and assigned during development based on assumptions about worst-case scenarios. However, considering the multitude of possible situations, it is easy to understand that a malfunction of a safety-related function is not dangerous in many of these situations. This applies both to primary functions such as actuator control, e.g., unintentional engine shutdown at standstill, and to secondary functions such as environmental perception, e.g., object detection in distant areas during slow travel.

[0011] The invention is therefore based on the object of providing an improved method and control device for determining a safety integrity level of a safety-related vehicle function of a motor vehicle, which enables a situation-dependent determination of a safety integrity level of a safety-related vehicle function.

[0012] The object is achieved by a computer-implemented method for determining a safety integrity level of a safety-related vehicle function of a motor vehicle having the features of patent claim 1.

[0013] Furthermore, the object is achieved with a control device for determining a safety integrity level of a safety-related vehicle function of a motor vehicle having the features of patent claim 13.

[0014] Furthermore, the object is achieved by a computer program having the features of patent claim 14 and a computer-readable data carrier having the features of patent claim 15.

[0015] Disclosure of the invention

[0016] The present invention provides a computer-implemented method for determining a safety integrity level of a safety-related vehicle function of a motor vehicle.

[0017] The method comprises providing at least one infrastructure and / or vehicle sensor data signal, which represents infrastructure and / or vehicle sensor data intended for a safety-related vehicle function provided by a motor vehicle. Furthermore, the method comprises determining the safety integrity level of the safety-related vehicle function based on the provided at least one infrastructure and / or vehicle sensor data signal. The method further comprises allocating a calculation of the safety-related vehicle function to an internal and / or external system, taking into account a predetermined safety integrity of the internal and / or external system.

[0018] The safety integrity level of a vehicle function represents or describes a level or stage of the safety integrity of the vehicle function. The safety integrity of a vehicle function specifically refers to the reliability of the vehicle function, which can be determined, for example, through a risk assessment.

[0019] The safety integrity of the vehicle-internal and / or external system can be represented, for example, by an ASIL score or ASIL value.

[0020] The present invention further provides a control device for determining a safety integrity level of a safety-related vehicle function of a motor vehicle.

[0021] The control unit comprises means for receiving the at least one infrastructure and / or vehicle sensor data signal, which represents infrastructure and / or vehicle sensor data intended for a safety-related vehicle function provided by a motor vehicle.

[0022] The control unit further comprises means for determining a safety integrity level of the safety-related vehicle function based on the provided infrastructure and / or vehicle sensor data signal. The control unit further comprises means for allocating a calculation of the safety-related vehicle function to an internal and / or external vehicle system, taking into account a predetermined safety integrity of the internal and / or external vehicle system.

[0023] The present invention further provides a computer program with program code for carrying out the method according to the invention when the computer program is executed on a computer, as well as a computer-readable data carrier with program code of a computer program for carrying out the method according to the invention when the computer program is executed on a computer.

[0024] Typically, a safety-related function is implemented using dedicated software developed with the corresponding ASIL and on dedicated hardware developed with the corresponding ASIL. In traditional vehicle E / E architectures, there is therefore no advantage in dynamically implementing functions on hardware and software with different ASILs, as the corresponding hardware and software are already available.

[0025] However, future vehicle E / E architectures will be heavily interconnected with external systems, such as the cloud, the edge, other vehicles, and / or smart devices. This offers the opportunity to outsource functions. However, the ASIL of a function is a limitation for this outsourcing, as these external systems are often not developed according to a safety standard such as ISO 26262 and therefore do not offer the necessary ASIL compliance.

[0026] One idea of ​​the present invention is therefore to enable a dynamic, in particular real-time, determination of the ASIL of safety-related functions or sub-functions on the basis of a currently given context such as a driving situation and / or a vehicle state.

[0027] Thus, a controlled outsourcing of these functions or subfunctions to external systems can advantageously be carried out, taking into account the given safety integrity of these external systems. According to a preferred development, the allocation of the calculation of the safety-related vehicle function to the in-vehicle and / or external system is carried out if the specified safety integrity of the in-vehicle and / or external system meets the determined safety integrity level of the safety-related vehicle function.

[0028] This also allows inherently safety-related functions to be dynamically outsourced from the vehicle to free up internal resources or use them for more complex safety-related calculations. This is particularly advantageous for automated driving functions such as environmental awareness, adaptive behavior planning, and / or trajectory planning, whose computational effort can vary significantly depending on the given driving situation, e.g., the complexity of the driving situation and the environment.

[0029] According to a further preferred development, the at least one provided infrastructure and / or vehicle sensor data signal comprises driving situation parameters, in particular a vehicle speed, a direction of movement, and / or a geographical position, of an ego vehicle, in particular the motor vehicle. Thus, a current driving situation is precisely mapped in the infrastructure and / or vehicle sensor data signal.

[0030] According to a further preferred development, it is provided that the provided at least one infrastructure and / or vehicle sensor data signal comprises or is a criticality parameter of a current driving situation, in particular a distance and / or a relative movement of the motor vehicle to static and / or dynamic objects in certain areas of a vehicle environment.

[0031] This also allows the criticality of the current driving situation to be included in determining the safety integrity level of the safety-related vehicle function. According to a further preferred development, the provided at least one infrastructure and / or vehicle sensor data signal includes or includes areas stored on a map in which predefined object types, in particular people and / or vehicles, are not located with a predefined minimum probability, as well as areas defined relative to the motor vehicle. This also allows infrastructure data to be included in determining the safety integrity level of the safety-related vehicle function.

[0032] According to a further preferred development, determining the safety integrity level of the safety-related vehicle function comprises a dynamic classification of a vehicle environment using a classification algorithm, wherein the classification algorithm is applied to the provided at least one infrastructure and / or vehicle sensor data signal and outputs a plurality of classes representing the safety integrity level of the safety-related vehicle function. The safety integrity level thus determined, in particular the ASIL, therefore serves as the basis for allocating the calculation of the safety-related vehicle function to an internal and / or external vehicle system.

[0033] According to a further preferred development, it is provided that the safety-related vehicle function is a steering, braking and / or acceleration function of the vehicle.

[0034] This makes it possible to determine whether, for example, unintentional braking is dangerous because there is a vehicle behind the vehicle. It can also be used to assess whether unintentional steering or braking is dangerous or not, depending on the vehicle's speed and surroundings.

[0035] According to a further preferred development, it is provided that the safety-related vehicle function is an environment detection function which detects which areas of an environment model to be calculated are relevant for determining safe behavior of the motor vehicle and which are not.

[0036] For example, the recognition of traffic lights is relevant or not depending on the situation in an area, e.g. less relevant for far ahead with low ego-

[0037] Speed ​​and the known absence / deactivation of traffic lights on the route, which data can be obtained from static or dynamic map information.

[0038] Furthermore, traffic light detection is less relevant, for example, when there are known to be no traffic lights in certain fields of vision, when driving on a motorway, in the field of vision to the left or straight ahead when making a right turn, or when starting off.

[0039] Furthermore, the detection of people is less relevant or less safety-critical for more distant or cordoned-off areas from which people cannot realistically reach the area in front of the vehicle, as well as areas in which no people can realistically be present, e.g. in a tunnel or on a motorway.

[0040] According to a further preferred development, it is provided that the safety integrity level of the safety-related vehicle function is determined based on a real-time criticality, in particular using at least one real-time infrastructure and / or vehicle sensor data signal.

[0041] The real-time criticality of the data thus enables real-time outsourcing or allocation of the calculation of the safety-related vehicle function to an internal and / or external system.

[0042] According to a further preferred development, it is provided that resources available in the vehicle and in the vehicle environment for calculating the safety-related vehicle function, in particular the safety integrity level of a required control unit and / or a computer-implemented method operated on the control unit, are determined and a maximum latency required for calculating the safety-related vehicle function using these resources is determined.

[0043] This data can therefore also be stored locally in the vehicle in a database (e.g. integrity / performance map of the resources available from a regional position).

[0044] According to a further preferred development, it is provided that the allocation of the calculation of the safety-related vehicle function, the safety integrity level of which falls below a predetermined threshold value, is carried out on the vehicle control unit.

[0045] This allows, for example, execution of the software on an internal control unit, on the "safety" core (e.g. Lockstep-CP U) of the control unit, which corresponds to a high ASIL, execution on a less secured core, e.g. only with "QM rating", execution on redundant GPUs, with comparison of the results, which corresponds to a high ASIL and / or execution on a single GPU with a lower ASIL or "QM rating".

[0046] According to a further preferred development, it is provided that a function execution via V2X is requested on an external system, in particular an edge, fog and / or cloud server, a control unit of another road user and / or a smart device, in particular a smartphone.

[0047] This allows execution on an external system developed according to a high safety integrity level, execution on redundant external systems with low safety integrity or pure "QM rating", with local comparison of the results for a higher safety integrity ("SW Lockstep") and execution on a single external system with low safety integrity or pure "QM rating".

[0048] The described embodiments and further developments can be combined with one another as desired. Further possible embodiments, further developments, and implementations of the invention also include combinations of features of the invention not explicitly mentioned above or described below with regard to the exemplary embodiments.

[0049] Short description of the drawings

[0050] The accompanying drawings are intended to provide a further understanding of embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain principles and concepts of the invention.

[0051] Other embodiments and many of the aforementioned advantages will become apparent upon review of the drawings. The elements illustrated in the drawings are not necessarily drawn to scale.

[0052] They show:

[0053] Fig. 1 is a flowchart of a computer-implemented method for determining a safety integrity level of a safety-related vehicle function of a motor vehicle according to a preferred embodiment of the invention; and

[0054] Fig. 2 is a schematic representation of a control unit for determining a safety integrity level of a safety-related vehicle function of a motor vehicle according to the preferred embodiment of the invention.

[0055] The computer-implemented method shown in Fig. 1 for determining a safety integrity level 14 of a safety-related vehicle function 12 of a motor vehicle comprises providing S1 at least one infrastructure and / or vehicle sensor data signal 10, which represents infrastructure and / or vehicle sensor data intended for a safety-related vehicle function 12 provided by a motor vehicle. The safety-related vehicle function is understood here as a safety-relevant aspect of the vehicle, such as a function relating to acceleration, braking, and / or steering intervention.

[0056] The method further comprises determining S2 a safety integrity level 14 of the safety-related vehicle function 12 based on the provided at least one infrastructure and / or vehicle sensor data signal 10 and allocating S3 a calculation of the safety-related vehicle function 12 to an internal and / or external system 16, 18 taking into account a predetermined safety integrity of the internal and / or external system 16, 18.

[0057] The allocation of the calculation of the safety-related vehicle function 12 is carried out to the vehicle-internal and / or vehicle-external system 16, 18 if the specified safety integrity of the vehicle-internal and / or vehicle-external system 16, 18 meets the determined safety integrity level 14 of the safety-related vehicle function 12.

[0058] The provided at least one infrastructure and / or vehicle sensor data signal 10 comprises driving situation parameters, in particular a vehicle speed, a direction of movement and / or a geographical position, of an ego vehicle, in particular the motor vehicle.

[0059] The provided infrastructure and / or vehicle sensor data signal 10 further comprises or is a criticality parameter of a current driving situation, in particular a distance and / or relative movement of the motor vehicle to static and / or dynamic objects in specific areas of a vehicle's surroundings. Furthermore, the provided at least one infrastructure and / or vehicle sensor data signal 10 includes areas stored on a map in which predefined object types, in particular people and / or vehicles, are not located with a predefined minimum probability, as well as areas defined relative to the motor vehicle.

[0060] Determining the safety integrity level 14 of the safety-related vehicle function 12 comprises a dynamic classification of a vehicle environment using a classification algorithm.

[0061] The classification algorithm is applied to the provided at least one infrastructure and / or vehicle sensor data signal 10 and outputs a plurality of classes representing the safety integrity level 14 of the safety-related vehicle function 12. The output classes are different safety integrity levels 14, in particular different ASILs, of the safety-related vehicle function 12.

[0062] The safety-related vehicle function 12 is a steering, braking, and / or acceleration function of the vehicle. Furthermore, the safety-related vehicle function 12 is an environment detection function that detects which areas of an environment model to be calculated are relevant for determining the safe behavior of the motor vehicle and which are not.

[0063] The safety integrity level 14 of the safety-related vehicle function 12 is determined based on real-time criticality, in particular using real-time infrastructure and / or vehicle sensor data signals 10.

[0064] Available resources in the vehicle and the vehicle environment are determined for calculating the safety-related vehicle function 12, in particular the safety integrity level 14 of a required control unit and / or a computer-implemented method operated on the control unit 20. Furthermore, a maximum latency required to calculate the safety-related vehicle function 12 using these resources is determined. The allocation of the calculation of the safety-related vehicle function 12, whose safety integrity level 14 falls below a predetermined threshold, is executed on the control unit 20. Function execution via V2X is requested on an external system, in particular an edge server, fog, cloud, control unit 20 of another road user, or smart device. Vehicle-to-everything V2X is the communication between a vehicle and any device that can influence the vehicle or be influenced by it.

[0065] Fig. 2 shows a schematic representation of a control unit for determining a safety integrity level 14 of a safety-related vehicle function 12 of a motor vehicle according to the preferred embodiment of the invention.

[0066] The control unit 20 comprises means 22 for receiving at least one infrastructure and / or vehicle sensor data signal 10, which represents infrastructure and / or vehicle sensor data intended for a safety-related vehicle function 12 provided by a motor vehicle.

[0067] Furthermore, the control unit comprises means 24 for determining a safety integrity level 14 of the safety-related vehicle function 12 based on the provided at least one infrastructure and / or vehicle sensor data signal 10.

[0068] The control unit further comprises means 26 for allocating S3 a calculation of the safety-related vehicle function 12 to an internal and / or external vehicle system, taking into account a predetermined safety integrity of the internal and / or external vehicle system.

Claims

Claims 1. A computer-implemented method for determining a safety integrity level (14) of a safety-related vehicle function (12) of a motor vehicle, comprising the steps of: providing (S1) at least one infrastructure and / or vehicle sensor data signal (10) representing infrastructure and / or vehicle sensor data intended for a safety-related vehicle function (12) provided by a motor vehicle; Determining (S2) the safety integrity level (14) of the safety-related vehicle function (12) based on the provided at least one infrastructure and / or vehicle sensor data signal (10); and Allocation (S3) of a calculation of the safety-related vehicle function (12) to an internal and / or external system (16, 18) taking into account a predetermined safety integrity of the internal and / or external system (16, 18).

2. Computer-implemented method according to claim 1, wherein the allocation of the calculation of the safety-related vehicle function (12) to the vehicle-internal and / or vehicle-external system (16, 18) is carried out if the predetermined safety integrity of the vehicle-internal and / or vehicle-external system (16, 18) satisfies the determined safety integrity level (14) of the safety-related vehicle function (12).

3. Computer-implemented method according to claim 1 or 2, wherein the provided at least one infrastructure and / or vehicle sensor data signal (10) comprises driving situation parameters, in particular a Vehicle speed, a direction of movement and / or a geographical position of an ego vehicle, in particular the motor vehicle.

4. Computer-implemented method according to one of the preceding claims, wherein the provided at least one infrastructure and / or vehicle sensor data signal (10) comprises a criticality parameter of a current driving situation, in particular a distance and / or a relative movement of the motor vehicle to static and / or dynamic objects in certain areas of a vehicle environment.

5. Computer-implemented method according to one of the preceding claims, wherein the provided infrastructure and / or vehicle sensor data signal (10) comprises areas stored in a map in which predetermined object types, in particular persons and / or vehicles, are not located with a predetermined minimum probability, as well as areas defined relative to the motor vehicle.

6. Computer-implemented method according to one of the preceding claims, wherein determining the safety integrity level (14) of the safety-related vehicle function (12) comprises a dynamic classification of a vehicle environment using a classification algorithm, wherein the classification algorithm is applied to the provided at least one infrastructure and / or vehicle sensor data signal (10) and outputs a plurality of classes representing the safety integrity level (14) of the safety-related vehicle function (12).

7. Computer-implemented method according to one of the preceding claims, wherein the safety-related vehicle function (12) is a steering, braking and / or acceleration function of the vehicle.

8. Computer-implemented method according to one of the preceding claims, wherein the safety-related vehicle function (12) is a Environment detection function is the function that detects which areas of an environment model to be calculated are relevant for determining the safe behavior of the motor vehicle and which are not.

9. Computer-implemented method according to one of the preceding claims, wherein the safety integrity level (14) of the safety-related vehicle function (12) is determined based on a real-time criticality, in particular using real-time infrastructure and / or vehicle sensor data signals (10).

10. Computer-implemented method according to one of the preceding claims, wherein resources available in the vehicle and in the vehicle environment for calculating the safety-related vehicle function (12), in particular the safety integrity level (14) of a required control unit and / or a computer-implemented method operated on the control unit (20) are determined and a maximum latency required for calculating the safety-related vehicle function (12) using these resources is determined.

11. Computer-implemented method according to one of the preceding claims, wherein the allocation of the calculation of the safety-related vehicle function (12) whose safety integrity level (14) falls below a predetermined threshold value is carried out on the control unit (20).

12. Computer-implemented method according to one of the preceding claims, wherein a function execution is requested via V2X on an external system, in particular an edge server, fog, cloud, control unit (20) of another road user, smart device. Control unit (20) for determining a safety integrity level (14) of a safety-related vehicle function (12) of a motor vehicle, comprising: Means (22) for providing at least one infrastructure and / or vehicle sensor data signal (10) representing infrastructure and / or vehicle sensor data intended for a safety-related vehicle function (12) provided by a motor vehicle; Means (24) for determining the safety integrity level (14) of the safety-related vehicle function (12) based on the provided at least one infrastructure and / or vehicle sensor data signal (10); and Means (26) for allocating (S3) a calculation of the safety-related vehicle function (12) to an internal and / or external system, taking into account a predetermined safety integrity of the internal and / or external system. A computer program with program code for carrying out the method according to one of claims 1 to 12 when the computer program is executed on a computer. A computer-readable data carrier with program code of a computer program for carrying out the method according to one of claims 1 to 12 when the computer program is executed on a computer.