Method and device for operating a control unit for safety-critical applications in a motor vehicle

By switching to a backup safety mechanism with a lower integrity level when faults occur in motor vehicle safety systems, the method enhances system availability and ensures safe operation, transitioning to a safe state when the backup mechanism is no longer viable.

WO2025125526A1PCT designated stage expired Publication Date: 2025-06-19ROBERT BOSCH GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/086102
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-12
Filing Date
2024-12-12
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing safety mechanisms in motor vehicles can lead to reduced system availability when errors occur, as they may cause the entire vehicle system to enter a safe state, even if redundant mechanisms are not effectively utilized.

Method used

Implementing a method that switches to a backup safety mechanism with a lower safety integrity level upon detection of a fault in a component or function used by a primary safety mechanism, while controlling the backup mechanism securely through monitoring and activation limits.

Benefits of technology

This approach increases the availability of the vehicle system by allowing continued operation through a backup safety mechanism, while ensuring safety by transitioning to a safe state when the backup mechanism is unavailable or exceeds its activation limits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024086102_19062025_PF_FP_ABST
    Figure EP2024086102_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method for operating a vehicle system (1), comprising the following steps: - invoking (S2) a safety mechanism if a safety objective is violated (S1); - if an error in the execution of the safety mechanism is detected (S4), invoking a backup safety mechanism associated with the safety objective; - if an error in the backup safety mechanism is detected, bringing the vehicle system into a safe state; - preventing (S12) the backup safety mechanism from being invoked depending on an activation limit specification associated with the violated safety objective.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] title

[0003] Method and device for operating a control unit for safety-critical applications in a motor vehicle

[0004] Technical area

[0005] The invention relates to measures for the safe operation of control units in motor vehicles, in particular measures for implementing safety mechanisms in the event of a component failure in a motor vehicle.

[0006] Technical background

[0007] If a safety-critical failure of a component or function in a vehicle is detected, a safety mechanism defined according to a safety objective is invoked. The ISO 26262 standard specifies the safety objectives used for components and functions in the vehicle. These safety objectives are based on an ASIL rating, which is based on the parameters of probability of occurrence, severity, and controllability.

[0008] For each safety objective, a safe state is defined that the vehicle system assumes. The implemented safety mechanism switches to this safe state if the safety objective is violated. However, errors affecting components and functions of the safety mechanism can also cause the entire vehicle system to enter a safe state. This reduces the availability of the vehicle system. However, high system availability is required, especially for commercial vehicle applications. Providing redundant safety mechanisms with the same level of integrity is relatively complex. Disclosure of the Invention

[0009] According to the invention, a method for operating a vehicle system with safety mechanisms according to claim 1 as well as a corresponding device and a vehicle system according to the independent claims are provided.

[0010] Further embodiments are specified in the dependent claims.

[0011] According to a first aspect, a method for operating a vehicle system is provided, comprising the following steps:

[0012] Calling a security mechanism when a security goal is violated,

[0013] If an error is detected in the execution of the security mechanism, calling a backup security mechanism associated with the security target;

[0014] If a fault is detected in the backup safety mechanism, bring the vehicle system into a safe state;

[0015] Preventing the backup security mechanism from being invoked or stopping it depending on an activation limit specification associated with the violated security target.

[0016] Faults in components or functions within a vehicle system, particularly control units, sensors, or actuators, are assigned to safety objectives. A safety objective is a defined result or condition to be achieved in the area of ​​vehicle safety and includes one or more diagnostic functions that monitor functions or components of the vehicle system for one or more fault criteria. Each safety objective is assigned a safety mechanism that is invoked as soon as a corresponding monitoring function indicates a fault.

[0017] A safety mechanism represents one or more predetermined functions that are designed to be called when a safety-critical error occurs. However, these safety mechanisms may utilize other components or functions that are also faulty. This typically results in the entire vehicle system being placed in a safe state in which all vehicle functions are deactivated, rendering it nonfunctional.

[0018] According to the above method, the availability of the vehicle system is now increased by switching to a backup safety mechanism with a lower safety integrity level upon the occurrence of a fault in a component or function used by a safety mechanism activated due to a malfunction or error. The backup safety mechanism is controlled in a secure manner by appropriate monitoring, time-dependently and depending on an activation limit specification. Such a method offers the possibility of a redundant safety mechanism with existing components and functions in the vehicle system, thus achieving overall improved availability of the vehicle system without additional effort.

[0019] The backup security mechanism may be designed to have a lower security integrity level than the security mechanism in which the failure occurred.

[0020] Each component and function in a vehicle system is assigned a safety objective, which is determined by a specific ASIL integrity level based on a probability of occurrence, a severity level, and controllability, particularly by a driver. In general, a reduction in the probability of occurrence while maintaining the same severity level and controllability leads to a reduction in the ASIL integrity level.

[0021] The above procedure now provides for switching to the backup safety mechanism when an error occurs during the execution of the safety mechanism associated with a previously violated safety objective, rather than immediately transitioning to a passive safe state of the vehicle system. This increases the availability of the vehicle system.

[0022] For this purpose, at least one backup safety mechanism is assigned to each safety mechanism according to an assignment table, which is also assigned an activation limit specification that specifies the total driving time of the backup safety mechanism and / or the number of driving cycles during which the backup safety mechanism is active.

[0023] If the backup safety mechanism is unavailable, the vehicle system is brought into a safe state defined for the corresponding safety objective. If the backup safety mechanism is available, i.e., the components and functions used are error-free, the activation limit for the respective backup safety mechanism, which can be defined, for example, as the permitted driving time or maximum number of driving cycles, is retrieved from the mapping table.

[0024] The vehicle system's safety objective is then monitored with respect to the backup safety mechanism using the activation limit until the activation limit no longer allows the backup safety mechanism to be used. Once the activation limit associated with the backup safety mechanism has expired, the vehicle system is brought into a safe state defined for the safety objective.

[0025] In addition to the activation limit, the driver of the vehicle can be informed about the activation of the backup safety mechanism and be advised of the need for a workshop visit.

[0026] It may be provided that the number of driving cycles and the total driving time during the active backup safety mechanism are stored in the activation limit memory at the beginning of the driving cycle or at the end of the driving cycle.

[0027] The activation limit is implemented using a non-volatile activation limit memory in which the driving time since the first call of the backup safety mechanism and the driving cycles performed since the first call of the backup safety mechanism are securely logged.

[0028] Furthermore, after each storage of the number of driving cycles and the total driving time, the storage can be checked, in particular using a checksum. Write and read operations to / in this activation limit memory can be verified by determining a checksum. Each time the activation limit memory is changed, the checksum is recalculated and saved together with the information on the driving time and driving cycles. If the maximum driving time and / or the maximum number of driving cycles specified by the activation limit are reached or exceeded without the error being rectified, the vehicle system is brought into a safe state.

[0029] After each write operation to the activation limit memory, this activation limit memory is checked by a write analysis operation to monitor the functionality of the memory in question.

[0030] According to a further aspect, a device, in particular a data processing device, is provided for carrying out the above method.

[0031] Brief description of the drawings

[0032] Embodiments are explained in more detail below with reference to the attached drawings. They show:

[0033] Figure 1 is a schematic representation of a vehicle system with

[0034] Control units connected to a variety of sensors and actuators;

[0035] Figure 2 is a flowchart illustrating a method for operating a vehicle system.

[0036] Description of embodiments

[0037] Figure 1 shows a schematic representation of a vehicle system 1 with control units 2, each of which is connected to a plurality of sensors 3 and actuators 4 as components. The control units 2 are designed to execute vehicle functions based on software and / or hardware with the components 3, 4 of the vehicle system 1. Furthermore, monitoring functions are implemented in the control unit 2, which monitor the components 3, 4, the control units 2, and the vehicle functions implemented in the control units 2 for compliance with safety objectives. If a safety objective is not met, a safety mechanism derived from a predefined assignment table is called accordingly.

[0038] The mapping table assigns a corresponding safety mechanism of a specific ASIL integrity level to a safety target. The mapping table also assigns each of the safety targets a backup safety mechanism of an ASIL integrity level, which typically meets a lower safety standard. For example, if the safety target is assigned an ASIL B safety integrity level, the backup safety mechanism can be assigned an ASIL A integrity level.

[0039] Furthermore, each backup safety mechanism is assigned an activity limit specification. The activity limit specification specifies one or more time-limiting maximum values ​​that indicate how long the backup safety mechanism may be active. The maximum values ​​can include, for example, a maximum cumulative driving time with the backup safety mechanism active or a maximum number of driving cycles in which the backup safety mechanism is active.

[0040] A method for operating the vehicle system 1 with safety mechanism is described in more detail using the flow chart in Figure 2.

[0041] In step S1, it is first checked whether an error has occurred in a component 2, 3, or a function in the vehicle system 1. This error is detected based on a violation of a safety objective.

[0042] If this is the case (alternative: Yes), the process continues with step S2. Otherwise (alternative: No), the process returns to step S1.

[0043] In step S2, a safety mechanism is called or activated that is assigned to the safety objective according to the assignment table. In step S3, a check is made to determine whether the safety mechanism can be called or activated after the error has occurred in component 2, 3, or the function in vehicle system 1. If the safety mechanism cannot be called (alternative: No), e.g., because an error has occurred, the method continues with step S4. Otherwise (alternative: Yes), the method continues with step S11.

[0044] In step S11, the safety mechanism is further executed accordingly to allow continued operation of vehicle system 1. If necessary, the detected error can be signaled.

[0045] In step S4, the backup security mechanism associated with the security mechanism is retrieved from the mapping table and executed.

[0046] Furthermore, in step S5, an activation limit specification is retrieved from the assignment table, which specifies, for example, a maximum number of driving cycles and / or a maximum driving duration when the backup safety mechanism is active.

[0047] In step S6, a check is performed to determine whether a constantly updated number of driving cycles in the activation limit memory has reached a predefined threshold value of the activation limit information, or whether the driving time in the activation limit memory has reached or exceeded a predefined threshold value of the activation limit information. Furthermore, a check can be performed to determine whether an error has occurred in the backup safety mechanism. If one of the above criteria is met (alternative: yes), the method continues with step S12, the vehicle is brought into a safe state, and reactivation of the backup safety mechanism is prevented. Otherwise (alternative: no), the method continues with step S7.

[0048] In step S7, a check is made to determine whether the current trip should be terminated. If this is the case (alternative: yes), the process continues with step S8. Otherwise (alternative: no), the process returns to step S6.

[0049] In step S8, upon termination of an active ferry operation, a travel cycle counter is incremented / decremented accordingly. Alternatively or additionally, a travel time counter can be updated with the duration of the last active ferry operation. After the end of the trip, the total travel time during the active backup safety mechanism and the travel cycle count of the travel cycle counter are stored in the activation limit memory. Additionally, a checksum can be generated and stored.

[0050] The driving cycle is terminated in step S9.

[0051] In step S10, a check is made to determine whether a new drive cycle should be started. If this is the case (alternative: yes), the method continues with step S1. Otherwise (alternative: no), the method returns to step S10.

[0052] If, during operation of the backup safety mechanism, it is determined that the conditions specified by the activation limit specification are met, i.e., the maximum number of drive cycles and the maximum drive duration while the backup activation mechanism is active are exceeded, the backup safety mechanism is deactivated and the vehicle is placed in a safe state in step S12. In particular, the safe state corresponds to a state in which vehicle components 2, 3 and vehicle functions are not actively operated. Typically, all vehicle functions are deactivated.

[0053] While the activation limit memory is being written, a subsequent readout can be used to check whether the storage was performed correctly. If the activation limit information was not stored correctly, vehicle system 1 can be put into a safe state.

Claims

Claims 1 . Computer-implemented method for operating a vehicle system (1), comprising the following steps: Calling (S2) a security mechanism when a security objective is violated (S1), If an error in the execution of the security mechanism is detected (S4), calling a backup security mechanism associated with the security target; If a fault is detected in the backup safety mechanism, bring the vehicle system into a safe state; Preventing (S12) the invocation of the backup security mechanism depending on an activation limit specification associated with the violated security target.

2. The method of claim 1, wherein the backup security mechanism corresponds to a lower security integrity level than the security mechanism.

3. The method according to claim 1 or 2, wherein the activation limit indication indicates a maximum number of driving cycles and / or a maximum driving duration with the backup safety mechanism active.

4. The method according to any one of claims 1 to 3, wherein the number of driving cycles and the total driving time during the active backup safety mechanism are stored in the activation limit memory at the beginning of the driving cycle or at the end of the driving cycle.

5. The method according to claim 4, wherein after each storage of the number of driving cycles and the total driving time, a check of the storage is carried out, in particular by means of a checksum.

6. Device, in particular a data processing device, for carrying out one of the methods according to one of claims 1 to 8.

7. A computer program product comprising instructions which, when the program is executed by at least one data processing device, cause the device to carry out the steps of the method according to one of claims 1 to 8.

8. A machine-readable storage medium comprising instructions which, when executed by at least one data processing device, cause the device to carry out the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and arrangement for monitoring at least one battery, battery with such an arrangement, and a motor vehicle with a corresponding battery

    DE102010041492A1

  • emergency evacuation USING AUTONOMOUS DRIVING

    DE102017125494A1

  • Brake control system

    DE102019207517A1

  • Autonomous driving control system and control method and device

    US20230011677A1