Method for determining permissible state variable boundary value of technical system in vehicle

JP2023106322A5Pending Publication Date: 2025-12-24ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023001281
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-01-19
Filing Date
2023-01-06
Publication Date
2025-12-24

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a method for determining a permissible state variable boundary value of a technical system in a vehicle.SOLUTION: Controllability of a subsystem is ascertained on the basis of an ASIL characteristic number, and the state variable boundary value is determined from the controllability.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The invention relates to a method for determining tolerance limits of state variables of technical systems in a vehicle, which can influence driving state variables in the vehicle. [Background technology]

[0002] It is known to associate technical systems in a vehicle with risk rating parameters that characterize the risk potential of the technical systems. These risk rating parameters, called ASILs (Automotive Safety Integrity Levels), may be assigned to different degrees for different technical systems in a vehicle depending on the risk potential. A distinction is made between four ASIL parameter numbers A, B, C, and D, where ASIL A only encompasses a relatively low risk potential, while ASIL D indicates a high risk potential. Technical systems in a vehicle that are of high safety importance, such as braking or steering systems, are usually rated ASIL D.

[0003] The ASIL characteristic number consists of a characteristic quantity for the occurrence probability related to the frequency distribution of the state variables of the driving situation, a characteristic quantity for the controllability of the dangerous situation in the event of a malfunction in this driving situation, and a characteristic quantity for the severity of the dangerous situation. Each of these characteristic quantities is associated with a numerical value, and in this case the ASIL characteristic number is obtained by summing these numerical values. Summary of the Invention

[0004] Using the method according to the present invention, it is possible to determine the tolerance limits of state variables of a technical system in a vehicle based on ASIL characteristic numbers so that the ASIL characteristic numbers of the technical system in the vehicle are complied with. This method, which proceeds in several steps, first observes the subsystems that are components of the technical system, but assesses them using their own ASIL characteristic numbers. In the first step, an ASIL characteristic number is assigned to the subsystem, either by definition, by assessing the risk potential of the subsystem, or by determination or confirmation, by making an assessment based on different characteristic variables of the subsystem and determining the ASIL characteristic number from this assessment.

[0005] A subsystem may form a structural unit within the observed technical system and contribute to realizing the implementation of the technical system, for example, a sensor device in a vehicle that detects one or more driving state variables (e.g., the lateral acceleration of the vehicle) while driving.

[0006] After the ASIL characteristic number of the subsystem is set, the next step is to determine the controllability of the subsystem, which indicates one of the three characteristic quantities together with the occurrence probability and severity and additionally constitutes the ASIL characteristic number. The controllability of the subsystem is determined from the previously determined ASIL characteristic number of the subsystem, excluding the current occurrence probability associated with the frequency distribution of one state quantity of the subsystem and excluding the current severity determined from one state quantity of the subsystem. The occurrence probability of the subsystem is advantageously determined based on field or experimental data of the corresponding state quantity of the subsystem, where the field or experimental data is assumed to be known, for example, from multiple previous reference runs. The severity of the subsystem is determined from one state quantity of the subsystem, for example, based on experimental data layers. Preferably, the same state quantity, for example, the lateral acceleration of the vehicle, on which the occurrence probability and severity of the subsystem are based is important.

[0007] After determining the controllability of the subsystems, the next step is to incorporate the controllability values ​​into the determination of the tolerance limits of the state variables of the technical system. In addition to the controllability of the subsystems, the ASIL characteristic values ​​that apply to the entire technical system are also taken into account. Alternatively or additionally, the ASIL characteristic values ​​for the current driving situation related to the entire technical system may also be taken into account.

[0008] This procedure allows the determination of the tolerance limits of the state variables of a technical system based on relatively little initial information. All that is required is knowledge of the subsystems and the ASIL characteristic numbers of the technical system, the occurrence probability and severity of the subsystems, and a functional or experimental relationship between the desired limit values ​​of the state variables and the controllability of the subsystems and the associated ASIL characteristic numbers of the technical system. The controllability of the subsystems determined in the method according to the present invention is the starting point for determining the desired limit values ​​of the state variables.

[0009] The method can be applied to various technical systems including different subsystems and various driving situations. Considerable application is, for example, to driving situations involving braking, acceleration, and / or steering processes. Correspondingly, the method can be applied to longitudinal and / or lateral dynamic driving situations. When observing the state variables of a subsystem, the current severity of which is determined, the lateral acceleration of the vehicle is of interest, for example.

[0010] A subsystem functioning as a subset of a technical system in a vehicle may be formed, for example, as a sensor device in the vehicle, via which one or more vehicle state variables for the longitudinal and / or lateral dynamics of the vehicle, possibly also for the vertical dynamics, can be determined. For example, the lateral acceleration of the vehicle can be determined via the sensor device. Depending on the implementation, a specific ASIL value can be assigned to the sensor device, for example, the value ASIL B, or, by combining different sensor sources, a higher ASIL characteristic number, for example, ASIL C. In this case, the ASIL characteristic number can relate to a specific state variable determined using the sensor device, for example, the lateral acceleration.

[0011] The method can be applied to various technical systems in a vehicle and various driving situations. In an advantageous embodiment, the technical system in the vehicle to which the present invention relates is configured as an autonomous or partially autonomous driver assistance system. An example of an autonomous or partially autonomous driver assistance system is an electronic stability system such as an ESP (Electronic Stability Program). In the case of a driver assistance system, the technical system in the vehicle may include various components such as a brake system and a drive system in the vehicle.

[0012] The current probability of occurrence of a state variable of a subsystem, which must be determined for the controllability of the subsystem and which relates to the frequency distribution of the state variable, can be determined according to an advantageous embodiment from a characteristic curve which shows the distribution of this state variable in relation to the same state variable, which characteristic curve is advantageously based on experimental data.

[0013] According to a further preferred embodiment, the state variable tolerance limit value relates to a fault quantity of the technical system. The fault quantity is, for example, a fault moment of the vehicle. According to a further preferred embodiment, the state variable tolerance limit value based on the controllability of the subsystem can be calculated from empirical relationships derived from the controllability. Alternatively, physical relationships are also worth considering.

[0014] According to a further advantageous embodiment, the controllability of a subsystem is set to a value less than the total ASIL number of the subsystem excluding the current probability of occurrence and excluding the current severity, and for safety reasons the controllability is set to a value less than the value that would result from the total ASIL number excluding the probability of occurrence and excluding the severity, in particular reduced by the value 1.

[0015] The present invention further relates to a controller including means adapted to implement the above-mentioned method, said means including at least one storage unit, at least one calculation unit, a controller input, and a controller output. The controller can be used to activate, in particular, adjustable components of a technical system, for example, a brake system component such as an ESP pump if the technical system is implemented as an electronic stability program. The controller can take into account state variable limit values, for example, when implementing drive dynamics control.

[0016] The invention further relates to a technical system in a vehicle, such as an ESP system, which can be used to influence one or more driving state variables, and which is configured to include the above-mentioned controller.

[0017] The invention further relates to a computer program product comprising program code configured to perform the above-mentioned method steps, the computer program product running in the above-mentioned controller.

[0018] Further advantages and expedient embodiments can be seen from the further claims, the description and the drawings. [Brief explanation of the drawings]

[0019] [Figure 1] 1 is a block diagram with method steps for determining tolerance limits for state quantities of a technical system in a vehicle taking into account ASIL characteristic numbers; [Figure 2] FIG. 2 is an enlarged view of the last block in FIG. DETAILED DESCRIPTION OF THE INVENTION

[0020] A flow chart of a method for determining state variable tolerance limits is shown in FIG. 1. The state variable tolerance limits apply to technical systems in a vehicle, such as the Electronic Stability Program (ESP), which can implement automatic interventions in the brake system. The ESP system is based on sensor information acquired via the vehicle's sensor device in block 1. This is concerned in particular with vehicle state variables in the longitudinal and lateral directions in the speed and acceleration planes. Yaw moments around the vehicle's vertical axis may also be detected.

[0021] Block 1 with the sensor device represents a subsystem in the vehicle's technical system (ESP system). The subsystem according to block 1 can be considered as a component of the technical system, in which case the sensor information is also provided to other systems in the vehicle.

[0022] The purpose of the method is to provide, at the exit of block 5, state quantity tolerance limits which must not be exceeded in the technical system for safety reasons. In the particular embodiment of Figures 1 and 2, the state quantity tolerance limits are the permissible fault yaw moments.

[0023] This method utilizes ASIL characteristic numbers for both the subsystem of the sensor device according to Block 1 and the entire technical system. The ASIL characteristic number is additively composed of a characteristic quantity for the occurrence probability E associated with the frequency distribution of the state variables, a characteristic quantity for the controllability C of the hazardous situation in the event of a malfunction in the driving situation, and a characteristic quantity for the severity S of the hazardous situation. The total ASIL number N, consisting of the sum of the occurrence probability E, controllability C, and severity S, can occupy a maximum value of 10. The occurrence probability E lies between the integer values ​​1 and 4, where 1 indicates extremely rare and 4 indicates constant occurrence. The controllability C lies between the integer values ​​0 and 3, where 0 means that the event is controllable by anyone, and 3 indicates that it is controllable for a specific group of people to a 90% or less probability. The severity S lies between the integer values ​​0 and 3, where 0 indicates no danger and 3 indicates potentially severe injury or death.

[0024] The total ASIL number N typically lies within a range of values ​​between 7 and 10. N=7 is characterized by ASIL A, N=8 by ASIL B, N=9 by ASIL C, and N=10 by ASIL D. ASIL A indicates the lowest safety level, and ASIL D indicates the highest safety level.

[0025] For safety-critical technical systems in a vehicle, such as braking systems, ASIL D is usually applied.

[0026] For a technical system to be sufficiently safe and to avoid dangerous situations, the sum of the characteristics for the probability of occurrence E, the characteristics for controllability C and the characteristics for severity S must be less than the associated total ASIL number N.

[0027] E+C+S <n(ASIL)

[0028] For example, the technical system is assessed to ASIL D (N=10), so the total of E+C+S should be 9.

[0029] The sensor device according to block 1 measures the lateral acceleration a y In the next method step according to block 2, the measured lateral acceleration a y is visualized to form the current occurrence probability E, which is performed using experimental field data. In this embodiment, the occurrence probability E is approximately 3.

[0030] In the next method step according to block 3, the value associated with the controllability C is determined. Block 3 contains as input variables the occurrence probability E, the severity S and the ASIL characteristic number of the subsystem of block 1, i.e. the sensor device. For safety reasons, the severity S is set to a maximum value of 3. The ASIL characteristic number is approximately C, which corresponds to an ASIL characteristic number N=9. Using these input variables,

[0031] C <n(ASIL)-E-S

[0032] From the relationship above, we determine the controllability C of the subsystem by Block 1. For N=9, E=3, S=3, the above inequality gives us a value for controllability C, which must be less than 3, and therefore set to the value 2.

[0033] This value of controllability C flows into the next block 4 as an input quantity, and in block 4, the maximum allowable fault yaw rate is calculated from controllability C.

number

number

[0034] The allowable fault yaw rate determined in block 4

number

number

[0035] Block 5 is shown in more detail in Figure 2. Separate observations are made for the inside-of-curve (blocks 5.1, 5.2) and outside-of-curve (blocks 5.3, 5.4) cases, which are physically generated and consequently have different amplitudes. However, the basic physics model is the same for both the inside-of-curve and outside-of-curve cases, simply the allowable input yaw rate.

number

[0036] In block 5.1, the allowable yaw rate is first changed for the inside of the curve rotation case, which is then input to block 5.2 as an input quantity. In block 5.2, the allowable yaw moment for the inside of the curve rotation case is determined based on the physical relationship. In blocks 5.3 and 5.4, the corresponding determination for the outside of the curve rotation case is performed. At the exit of block 5, the allowable obstacle yaw moment M is determined based on the allowable yaw moments for the inside and outside of the curve rotation cases. Zmax A corridor of [Explanation of symbols]

[0037] 1 Subsystem a y Lateral acceleration (state quantity) C Controllability E Probability of occurrence M Zmax State quantity allowable limit value S Severity

Claims

1. state variable tolerance limits (M Zmax ) on the basis of ASIL characteristic numbers (Automotive Safety Integrity Level) which characterize the risk potential of the technical system and which are constituted by a characteristic quantity for the probability of occurrence (E) related to the frequency distribution of state quantities of a driving situation, a characteristic quantity for the controllability (C) of a hazardous situation in the event of a malfunction in the driving situation, and a characteristic quantity for the severity (S) of the hazardous situation, wherein each ASIL characteristic number is associated with a total ASIL number (n) which is the sum of the probability of occurrence (E), the controllability (C) and the severity (S), said method comprising the following method steps: - method steps for setting or determining the ASIL characteristic numbers of a subsystem (1) of the technical system; - One state quantity (a y ) and one state quantity (a y determining the controllability (C) of the subsystem (1) from the total ASIL number (n) of the subsystem (1), excluding the current severity (S) determined from the total ASIL number (n); - determining the state variable tolerance limit values ​​(M) of the technical system on the basis of the controllability (C) of the subsystem (1) ascertained and taking into account the predefined ASIL characteristic values ​​(ASIL D) for the technical system and / or the current driving situation; Zmax ) and A method comprising:

2. 2. The method according to claim 1, wherein the driving situation is a braking and / or steering process in the vehicle.

3. 3. The method according to claim 1, wherein the subsystem (1) is formed as a sensor device in the vehicle.

4. 3. The method according to claim 1 or 2, characterized in that the technical system in the vehicle is configured as an autonomous or partially autonomous driver assistance system.

5. 3. The method according to claim 1, wherein the technical system in the vehicle is configured as an electronic stability control system, for example as an electronic stability program (ESP).

6. 3. The method according to claim 1, wherein the occurrence probability (E) associated with the frequency distribution of the state quantity of the subsystem (1) is determined from a characteristic curve showing the distribution of the state quantity associated with the state quantity.

7. The state quantity of the subsystem (1) is the lateral acceleration (a y 3. The method according to claim 1 or 2, characterized in that

8. 3. The method according to claim 1, wherein the state variable tolerance limit values ​​determined from the determined controllability (C) of the subsystem relate to the disturbance variables of the technical system.

9. The state quantity allowable limit value (M Zmax 3. The method according to claim 1, wherein the yaw moment is related to the obstacle yaw moment.

10. The state quantity tolerance limit value (M Zmax 3. The method of claim 1 or 2, wherein the controllability (C) of the subsystem is calculated from an empirical relationship derived from the controllability (C) of the subsystem.

11. The state quantity tolerance limit value (M Zmax 3. The method of claim 1 or 2, wherein the controllability (C) of the subsystem is calculated either directly from physical relationships or indirectly from the controllability (C) of the subsystem.

12. 3. The method of claim 1 or 2, characterized in that (Block C) the controllability (C) of the subsystem (1) is set to a value less than the total ASIL number (n) of the subsystem (1) excluding the current probability of occurrence (E) and excluding the current severity (S).

13. A controller comprising means adapted to carry out the method according to claim 1 or 2.

14. 14. A technical system in a vehicle, for example an ESP system, for influencing driving state variables, comprising a controller according to claim 13.

15. A computer program product comprising a program code, the program code being configured to perform the steps of the method according to claim 1 or 2 when the computer program product is running in a controller according to claim 13.