Method and device for performing a vehicle safety function

By transmitting V2X data with functional safety indicators in structured containers, the reliability and safety of vehicle safety functions are enhanced, allowing compliance with higher ASIL standards.

WO2025201860A1PCT designated stage Publication Date: 2025-10-02CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/056511
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-25
Filing Date
2025-03-11
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Current V2X systems do not allow for the implementation of safety-critical vehicle functions that meet Automotive Safety Integrity Level (ASIL) requirements beyond the 'Quality Management' level, due to uncertainties in the reliability and safety of the data used for these functions.

Method used

A method and device that acquire and transmit V2X data along with functional safety indicators, such as fault rates and error detection times, within structured containers to ensure the reliability and safety of the data for safety-critical vehicle functions.

Benefits of technology

Enables the implementation of safety-critical vehicle functions that meet higher ASIL requirements by ensuring the reliability and safety of the data used, preventing unsafe triggering of vehicle safety functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025056511_02102025_PF_FP_ABST
    Figure EP2025056511_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to methods, devices, a system and a data structure for performing a safety function in a vehicle. For this purpose, a transmitter in a communication network acquires data for a V2X message, acquires associated functional safety indicators, and transmits the acquired data together with the functional safety indicators. On the receiver side, data are received, together with functional safety indicators, in the communication network, and on the basis of the received functional safety indicators, a conclusion is drawn as to whether the data can be used in a safety function. A data structure used for this purpose comprises V2X data and associated functional safety indicators, the V2X data being contained in a first container and the associated functional safety indicators being contained in a second container.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]202400769 1 Method and device for carrying out a vehicle safety function The invention relates to a method for carrying out a safety function of a vehicle according to the preamble of the main claim and to devices for carrying out this method according to the preamble of the auxiliary claim. Modern vehicles are increasingly equipped with active and passive safety devices. The safety devices are generally functional units of the vehicle which are designed to carry out special safety functions partially or fully automatically. Typically, a safety function serves to ensure the safest possible state orTo restore or maintain vehicle operation in order to avoid or at least minimize any danger to people and property, as well as personal injury or property damage. Such safety functions include, for example, the deployment of an airbag or the braking of individual or multiple wheels of the vehicle using an ESC system, but also safety functions that fully or partially assume control of the moving vehicle and, for example, automatically change the speed or direction of the vehicle, for example to avoid a rear-end collision or to evade an obstacle. The safety functions must meet special requirements with regard to their functional safety in order to avoid any danger even in the event of a defect, such as a short circuit in an electronic component.Hazards are usually created by the unintentional triggering of the safety function; for example, the aim is to prevent a defect from unintentionally triggering an emergency evasive maneuver that would cause the vehicle to leave the road. The following terms are used that are to be understood in the context of functional safety according to the definitions in the ISO 26262 and IEC 61508 standards. To carry out safety functions, data is necessary that contains information required for the performance of the safety function, for example, about the operating or movement state of the vehicle. This data can, for example, be derived from sensor data from a sensor unit in the vehicle, such as a sensor unit for detecting wheel speeds or for detecting a collision.Furthermore, this data can also originate from other vehicles in the vicinity of the vehicle that are involved in the aforementioned dangerous incident or situation. To take these other vehicles' data into account, it can be transmitted to the vehicle via a data connection. Similar security requirements apply to this data as to the safety function itself, so that corrupted data will not pose a risk. Such data transmission can occur using different transmission technologies. One such technology in question is known as V2X. Different implementation standards exist for this (SAE, IEEE, ETSI, 3GPP, CSAE, etc.). Different communication technologies are used for data transmission (DSRC, ITS-G5, LTE-V2X, 5G NR V2X, LTE, 5G, Wi-Fi, Bluetooth, etc.).Vehicle-to-X communication is understood in particular to mean direct communication between vehicles and / or between vehicles and infrastructure facilities. For example, it can be vehicle-to-vehicle communication or vehicle-to-infrastructure communication. If reference is made to such communication within the scope of this application, it can take place without mediation by a mobile network or a similar external infrastructure or can also be based on a mobile network. As mentioned above, vehicle-to-X communication can take place using the IEEE 802.11p or LTE-V2X or 5G NR standards. Vehicle-to-X communication can also be referred to as C2X communication or V2X communication.The sub-areas can be referred to as C2C (Car-to-Car), V2V (Vehicle-to-Vehicle) or C2I (Car-to-Infrastructure), V2I (Vehicle-to-Infrastructure) or even C2X (Car-to-Everything), V2X (Vehicle-to-Everything). However, there is usually uncertainty as to whether the data currently available for performing the respective safety function (and the information contained in the data) are sufficiently safe and reliable to perform this safety function. The associated field of functional safety is described in the ISO 26262 standard. In general, the unimpaired quality and reliability of the data is important to ensure the performance of the safety function. Such an impairment could, for example, lead to the safety function being performed at the wrong time or using incorrectly calculated parameters.202400769 3 Basic conceptual ideas on this topic can be found in the published patent application DE 102012215343. However, currently available V2X systems do not allow functionally critical safety functions to be implemented in such a way that they meet the requirements of higher levels, for example, Automotive Safety Integrity Level (ASIL) above the “Quality Management” (QM) level. It is therefore the object of the present invention to specify a method and a device which each allow the most reliable and safe implementation of safety functions of a vehicle under the condition of ASIL>QM. This object is achieved according to the invention by methods and devices according to the main claims and by an overall system according to the auxiliary claim. Further developments and special implementation methods of the method and of the overall system arise from the dependent claims.According to one embodiment of the present invention, a method for a transmitter in a communications network comprises acquiring data for a V2X message, acquiring associated functional safety indicators, and transmitting the acquired data together with the functional safety indicators. Acquiring data for a V2X message means acquiring information and data required in a networked traffic system, such as the position, direction, and speed of the vehicle, the steering angle, as well as information about any ABS activation, and sensor information from radar or ultrasonic sensors. Likewise, information received from other vehicles, for example, via V2X or other radio channels, may be acquired.The associated functional safety indicators provide information relevant to functional safety aspects, such as information on the quality and / or error limits of the previously acquired V2X data. Examples of such safety indicators are: fault rate (^), diagnostic coverage (DC), probability of failure on demand (PFD), failure detection time (tDet). Definitions can be found in the ISO26262 standard. The information on quality and error limits can be available internally at the transmitter. Since the signal quality achievable by the sensors used is known, such a value can be stored in a memory device in the transmitter. If the quality and / or error limits are dependent on speed, temperature, or similar, this can also be taken into account.In an advantageous embodiment, the captured data can be sent together with the associated functional safety indicators in the form of a V2X message, wherein this message comprises at least two containers. The term "container" used here refers to sections or fields of data structures. Data is usually present as a data structure and is also stored, sent, and received as such. The structure of data, for example of a data packet, is generally predetermined and contains, for example, a header that specifies the type of data packet, an area with payload data, and a concluding part that may contain, for example, a CRC checksum.If the area with payload data is divided into two or more sub-areas containing data of different origins, meanings, or uses, it is useful to divide these sub-areas logically; these subdivisions are referred to as containers. If necessary or appropriate, containers themselves can contain containers that enable a more fine-grained subdivision or structuring of the payload data area. Such containers often have names that facilitate handling and understanding. For example, a localization container can contain data used to determine a location, and a management container can, among other things, include spatial and temporal reference values ​​and serve to create a clear basis for orientation using a navigation system. For example, one of the containers can be a management container.A further container can comprise one or more of the functional safety indicators; this further container can expediently be referred to as a safety container. In one embodiment, the aforementioned V2X message is a message as defined in ETSI TS 102984-2. Thus, a message is used that is already used in the context of V2X communication, thereby achieving the greatest possible compatibility with known systems. Examples of such a message are CAM, MAP, SPAT, CPM, MCM, DENM, or IVI messages.Although reference is repeatedly made to ETSI TS 102984-2 in this discussion, it is of course possible to implement the invention within the framework of other standards. For example, the implementation can be carried out for messages according to SAE J 2735, which is commonly used in the USA, or for messages according to TCSAE 53-2017-CH, which is commonly used in China. In one embodiment, the additional container (hereinafter also referred to as the second container to distinguish it from the first container, which was previously referred to as the management container) comprises one or more of: safety timestamp, time confidence, safety message counter, safety ID, development process (DevProcess), fault rate of the data generating unit, and / or FacilityLayer CRC checksum.A timestamp can be included to assign a unique point in time to data, for example, the time at which the data was generated or received, or the time at which the contents of the second container were last modified. The time confidence indicates the degree of temporal accuracy. The "Safety Message Counter" is a counter value that is continuously incremented with each generated message. The safety ID serves to further secure the second container to prevent confusion between different senders at the receiver. The "Development Process" specification indicates which requirements the development process meets during software development. The "Fault Rate" specifies the failure or error rate of the unit that generated the data. The "Facility Layer CRC" checksum can be used to verify the integrity of at least part of the message content.In particular, the failure rate can be advantageously used in the present invention, since the failure rate also has the property of a Key Performance Indicator (KPI), which indicates the reliability associated with the unit that generates part of the data contained in the V2X message. In a further advantageous embodiment, the second container comprises at least one of the following indicators, which can be contained in a sub-container included in the second container: - Rate of undetected critical errors (failure rate), or - Failure detection time (failure detection time), or 202400769 6 - Protection level (protection level), or - List of signals or the data of the V2X message to which the indicators apply. This second container can be referred to as a "Safety Signal Container"; this term describes the use of the information contained in this container.The second container can contain additional information or indicators and is not limited to the four KPIs mentioned. For example, it could contain information that indicates a measure of the mutual independence of the data in the message; this information is often referred to as a "beta" parameter. Each of the one or more subcontainers contains information related to a specific type of information. For example, one subcontainer can refer to time information signals and specify related safety indicators; another subcontainer can refer to position or speed signals and specify other related safety indicators.The majority of the information contained in the sub-container, like the failure rate mentioned above, represents key performance indicators (KPIs), also referred to as 'indicators' for short, and can be used within the scope of the present invention to decide whether the data transmitted within the scope of the invention can be used in a safety function. One of the KPIs is the rate of undetected critical errors. This refers to an indication of the maximum number of undetected critical errors per unit of time that can be contained in the transmitted data. If a corresponding threshold is exceeded, it can be decided that the data associated with this KPI will not be used in a safety function. Another KPI is the error detection time. Here, a comparison with a threshold can also be used to decide that the associated data will not be used for the safety functions.Another KPI is the protection level, which indicates the accuracy of the associated data. This accuracy includes both systematic errors and random errors. Here, too, if a threshold is exceeded, the data can be omitted from use within a security function. The sub-container then also contains a list of the signals to which the KPI applies. Within the scope of the present invention, it is possible for the sub-container to include one or more of the previously mentioned KPIs; of course, it can be particularly advantageous if all four KPIs discussed are included in the sub-container.202400769 7 Likewise, an embodiment comprises a method for a receiver in a communication network receiving data together with the functional safety indicators and deriving, based on the received functional safety indicators, whether the data is used in safety functions. The method for the receiver represents the counterpart to the previously described method for the sender. In one embodiment, a V2X message comprises the received V2X data and the associated functional safety indicators, wherein the V2X message comprises at least two containers, wherein a first container comprises the V2X data and a second container comprises the associated functional safety indicators.In a further embodiment, the second container comprises one or more of: safety timestamp, time confidence, safety message counter, safety ID, development process (DevProcess), failure rate of the data generating unit, and / or FacilityLayer CRC. In a further advantageous embodiment, the second container comprises at least one of the following indicators, which may be contained in a sub-container included in the second container: - failure rate of undetected critical errors (failure rate), or - failure detection time (failure detection time), or - protection level (protection level), or - list of signals (V2X data) to which the indicators apply.The information is distributed between the second container or sub-container based on whether the information relates to all V2X data or only applies to a subset of the data. In the first case, it is advantageous and expedient to transmit the information in the second container (also referred to as the "safety container"); in the second case, it is appropriate to transmit the information in one of the sub-containers (also referred to as the "safety signal container"). A further embodiment relates to a transmitting device in a communications network, wherein the transmitting device comprises a first acquisition module that acquires data for a 202400769 8 V2X message, a second acquisition module that acquires one or more associated functional safety indicators, and a transmitting device that transmits the acquired data together with the acquired one or more associated functional safety indicators.A further embodiment relates to a receiving device comprising a receiving module that receives V2X data together with functional safety indicators, a decision module that decides, based on the functional safety indicators, whether the V2X data is used in a safety function, and a control module that controls a safety function using the V2X data. A further embodiment comprises the previously described transmitting and receiving devices. A further embodiment relates to a data structure for use in a V2X communication network, wherein the data structure comprises V2X data and associated functional safety indicators, and the data structure comprises at least a first container that comprises the V2X data and a second container that comprises at least one of the associated functional safety indicators.The method described here and the overall system described here are explained in more detail below. It shows: Fig. 1 a system according to an embodiment of the present invention, and Fig. 2 a data concept according to an embodiment of the present invention Fig. 1 shows a system 100 which comprises a transmitting device or transmitting unit 110 and a receiving device or receiving unit 120. The system 100 enables a transmitting function to be carried out by a transmitting unit 110, which in the following illustrative example is a first vehicle 110. Furthermore, the system 100 enables a receiving function to be carried out by a receiving unit 120, which in the following illustrative example is a second vehicle 120. The terms transmitting device, transmitting unit or first vehicle are used interchangeably; to improve comprehensibility, the most appropriate term is used in the respective context.The same applies to the description of the receiver side. 202400769 9 The transmitting and / or receiving units 110, 120 can be any road users such as vehicles or pedestrians carrying a suitably equipped mobile device such as a smartphone, but other units with transmitting and / or receiving functions can also be integrated into the V2X network. Other units that could be considered include traffic lights equipped with the appropriate sensors and transmit / receive technology. Transmission in the V2X network can be carried out using various wireless communication technologies, such as DSRC, ITS-G5, 5G NR-V2X, Bluetooth, etc. In general, such data transmission is referred to as vehicle-to-vehicle (V2V) communication or, in an even more general case, can be referred to as V2X communication.It is not absolutely necessary for the communication to be between two vehicles; one of the communication participants can also be a so-called roadside unit, such as the traffic light system mentioned above, or even the pedestrian mentioned above. In the example used here, the first vehicle 110 includes V2X data as well as the recorded functional safety indicators. The V2X data is recorded by a first recording module 111, and the V2X data is generated by sensors arranged in the vehicle 110. For this purpose, ultrasonic sensors, cameras, radar sensors, dynamic sensors (e.g., IMUs), and / or positioning systems that use GNSS can be used, as a non-exhaustive list. These sensors allow the surroundings of the vehicle 110 and the vehicle 110 itself to be observed. Internal status information can also be used, for example, whether the ABS system has been triggered.V2X data that vehicle 110 may have received from other vehicles may also be considered as a possible source of V2X data. For example, it is possible for another vehicle to detect the presence of objects and communicate this to vehicle 110 via a V2X message. Information obtained in this way can, of course, also be sent by transmitting device 110 within the scope of the present invention. The data acquired by first acquisition module 111 is transmitted to a second acquisition module 112. Second acquisition module 112 is configured to acquire or determine the functional safety indicators associated with the V2X data. For this purpose, it is possible, for example, for the second acquisition module 112 to access information stored in a storage device, which information indicates the values ​​of the functional safety indicators for data from a specific data source.For example, if the V2X data relates to position information, the values ​​of the security indicators for the position information can be stored in a GPS module (not shown here). Likewise, the security indicators of a radar system, an ultrasonic sensor, or other modules providing V2X data can be stored in a sensor itself, in an associated database, or elsewhere. If one embodiment provides for the generation of a checksum (CRC), the information that the second detection module 112 received from the first detection module 111 is used to generate and provide the checksum. Alternatively, the checksum can also be generated by the first detection module 111 and sent to the second detection module 112. This information is then transmitted from the module 112 to the second vehicle 120 using a transmitting device 113.The V2X data acquired by the transmitting unit 110 can, for example, be information about the vehicle's own driving status or other information obtained from sensors or functions. The information about the driving status can, for example, include information that emergency braking has been initiated, but also information about the vehicle speed or about detected traffic objects such as pedestrians or vehicles. In addition to the V2X data, the transmitting unit 110 also has functional safety indicators. The functional safety indicators are designed such that they can be used by a receiver to determine whether or not the V2X data can be used for a safety function. These functional safety indicators, also referred to as functional KPIs, will be described in more detail later.In the example used here, the second vehicle 120 comprises a receiving module 121, which receives the data transmitted by the transmitting unit 110. The structure of the received data allows the received data to be split back into the original V2X data and the associated functional safety indicators. The obtained V2X data can be used to trigger safety functions if the review of the safety indicators shows that the data meets the requirements of the functions. The present invention thus enables the triggering of safety functions that were previously not possible because it could not be ensured that the functional safety requirements were met. In one embodiment, the received information, comprising the V2X data and the associated functional safety indicators, is forwarded to a decision module 122.In an alternative embodiment (not shown), the information may only include the associated functional safety indicators (in this case, the received V2X data may be transmitted directly to a control module 123). The decision module 122 decides, based on the received information, whether to use the data if the data has the necessary reliability, wherein the reliability is assessed based on the functional safety indicators. Based on the decision of the decision module 122, a control module 123 then controls the safety function based at least in part on the received information. The decision module may also use further information, for example, data from sensors (not shown) present in the second vehicle 120.The safety function addressed here can, for example, involve automatically triggered full or partial braking of the vehicle using the vehicle's electronic braking system. The safety function can also initiate automatic avoidance of an obstacle using an evasive action assistant or automatically stabilize the vehicle by braking one or more of the vehicle's wheels and / or by reducing the vehicle's engine power. A further safety function is possible with the inclusion of infrastructure units such as traffic lights; here, for example, driving authorizations can be issued with the help of this invention.In a further illustrative example, it can be provided that the safety functions relate to an active or passive function, wherein the safety function is an electronic braking system and triggers automatic brake boosting and / or the safety function is an emergency braking assistant and triggers automatically triggered full or partial braking of the vehicle, and / or the safety function is an evasive assistant and triggers automatic avoidance of an obstacle and / or the safety function is an ESC unit and triggers automatic stabilization of the vehicle, in particular by braking one or more wheels of the vehicle and / or 202400769 12 by throttling an engine power of the vehicle, and / or the safety function is an airbag system and triggers ignition of the airbag.As mentioned above, functional safety indicators are so-called functional KPIs, or key performance indicators. These KPIs include one or more of: - an error rate of the processing unit(s) that generate the original message, - the rate of undetected critical errors for the individual data items in the message, - an error detection time, and - a protection level. These KPIs indicate which types of errors are associated with specific data, as well as the severity of each error. The error can be composed of different contributions, so there is an error rate of the processing units that originally provide the data.In the case of a sensor, this indicates the measurement accuracy of the sensor. Furthermore, it can be specified whether there is a rate of undetected errors for this sensor; this error is in addition to the error resulting from the measurement accuracy. Furthermore, an error detection time can be specified. This indicates a time after which a check is carried out to determine whether the signals comply with the specified protection level or not, or whether other critical errors have occurred. Thus, any non-compliance can be detected and reported after this time at the latest. The protection level indicates the deviation from the true value at which the transmitting unit classifies the detected deviation as a critical error. On the receiver side, there are requirements regarding the accuracy of the received data; these requirements specify the maximum permissible error level in the data.By comparing the protection level with these requirements, under the proviso that the protection level must be lower than the requirement, the receiver can then decide on the use of the transmitted data. Fig. 2 shows the structural layout of a message 150 as it is sent from the transmitting unit 110 to the receiving unit 120. To increase clarity, the message 150 is illustrated using a so-called DENM message, but the inventive concept is not limited to DENM messages. In general, the invention can be used in a variety of messages used in traffic telematics systems, also known as ITS - Intelligent Transport(ation) Systems, especially in cooperative systems, also known as C-ITS. Such systems are used in road, rail, maritime, and air traffic.In particular, the invention can be used in messages of ETSI TS 102894-2, such as the aforementioned CAM, MAP, SPAT, CPM, MCM, or IVI messages. The message 150 comprises a header 150a, which can contain a protocol version, a message identifier (Message ID), and a station identifier (Station ID). In addition, the message 150 contains, as previously described, several containers, in this example a management container 151, which contains information such as timestamps and position information. Furthermore, other optional containers such as a situation container 152 and a location container 153 can be included. Their description is omitted here, since these containers are not essential to the present invention. In one embodiment of the message 150 according to the invention, a further container 154 is included in the message 150.This container can be referred to as a safety container 154. It is understood that the name of the container is not essential to the invention, but its function or its contents are. Therefore, all containers that fulfill the same function or provide the same contents fall under the concept of the invention presented here. This safety container 154 can have information such as a time stamp and numbering, but this information is optional or not essential to the invention. The container 154 can comprise one or more sub-containers 155. In the example given, container 154, referred to here as a safety container 154, comprises three sub-containers 155, referred to here as a safety signal container 155. In the most general case, it is possible for the security container 154 not to comprise a safety signal container 155.These safety signal containers 155 include the previously mentioned functional KPIs: 202400769 14 undetected critical error rate for the individual message content, error detection time, protection level, list of associated V2X data. Since many data items have a common source and thus also common safety KPIs, embodiments may provide for groups of signals that have common safety KPIs to be formed within a safety container. These groups can be identified by each subcontainer beginning with a list of signal names or signal positions in the message. The structure of a DENM message is shown below, in which the concept of the invention can be found.StationID 123456 123456 Decentralized Management Con- ActionID StationID 707 Environmental tainer SequenceNumber Notification Reference Timestamp 9876543210 Message DetectionTimestamp 9876543110 45000000 ReferencePosition Latitude 2000000 Longitude SemiAxisLength(semiMajorConfidence) PosConfidence-Ellipse SemiAxisLength(semiMinorConfidence) HeadingValue(semiMajorOrientation) AltitudeValue Altitude AltitudeConfidence ValidityDuration 10s StationType passengerCar(5) SituationContainer InformationQuality highest(7) dangerousSituation(99) CauseCode(eventType) CauseCodeType emergencyElectronicBrakeEngaged(1) SubCauseCodeType DeltaReferencePosition EventHistory EventPoint(1..23) 1900 ~ 70km / h LocationContainer Speed (Opt.) SpeedValue 30 SpeedConfidence wgs84South(1800) Heading (Opt.) HeadingValue equalOrWithinOneDegree (10) HeadingConfidence PathPoint(0..40) Traces PathHistory(0..7) SafetyContainer (Opt.) safety timestamp 98765432 202400769 15 time confidence 10ms safetymessagecounter 1234 safety ID 707 Fault rate 10fit referenceTime, detectionTime SafetySignalContainer linked signals 10fit (Opt.) lamda_DU 101ms t_Det 10ms ProtectionLevel ReferencePosition, SafetySignalContainer linked signals 40fit (Opt.) lamda_DU 95ms t_Det 5.3m ProtectionLevel SpeedValue, SpeedConfidence SafetySignalContainer linked signals 0.1fit (Opt.) lamda_DU 25ms t_Det 52cm / s ProtectionLevel all others SafetySignalContainer linked signals 10fit (Opt.) lamda_DU 0 beta 110ms t_Det 0 = digital information ProtectionLevel denm crc 0x12345678 This message structure clearly illustrates the message structure with containers and subcontainers. The aforementioned first container can be identified as the management container, which contains the V2X payload data in the form of longitude, latitude, and altitude.The second container is called the "Safety Container" and comprises several sub-containers, referred to as "Safety Signal Containers." These sub-containers contain information about the associated payload data ("linked signals") and the associated safety indicators, e.g., protection level or failure rate (lambda_DU). In the last "Safety Signal Container," an additional field, "beta," is added, which can be useful under certain conditions. This describes the independence of the transmitted data. This is intended to clarify that the number and composition of the data fields in the Safety Signal Container is variable and can be adapted to the respective circumstances. 202400769 16 The presented safety container can be used for all ETSI C-ITS messages, not just for the DENM shown in the example.The safety container can be attached to each individual case, and the above-mentioned groups, to which the KPIs apply across the board, can be defined using signal names or the position of data within the message. The inventive Safety Qualifier enables, as previously described, the implementation of safety-critical V2X functions in accordance with ISO26262. The information in the individual safety signal containers enables the calculation of individual failure rates, which can then be summed up, for example. The resulting failure rate can then be used for comparison with a required maximum failure rate. If the total exceeds the maximum failure rate, a decision can be made not to use the corresponding information to decide whether to trigger a safety function.As a purely illustrative example, a potential hazardous situation is cited here: the situation in which a broken-down vehicle sends messages informing other vehicles that there is a broken-down vehicle on the route, so that these vehicles can activate appropriate safety functions if necessary. For example, braking can be triggered if a vehicle approaches the broken-down vehicle at excessive speed. Such a so-called stationary vehicle warning (SVW) with braking represents a safety improvement over a warning alone, as it can prevent accidents. With appropriately adjusted parameters, this can also be used for automated vehicles.The KPIs provided in the containers according to the invention can be used as follows; the abbreviations used are: ^ : Error rate of all errors, ^D: Rate of dangerous errors, ^DU: Rate of undetected dangerous errors, PFH: Probability of Failure per Hour (Probability of Failure per Hour) 1 fit = 10. -9 / h (“fit”=“Failure in time” according to IEC61508 and ISO26262) DC: Diagnostic coverage e.g. DCDU = (1-^DU / ^D) TTF: Time to failure t Det : Failure Detection time – time until a fault is detected 202400769 17 ESC: Electronic Stability Control = electronic braking system The calculation of the rate of a dangerous failure is done by summing up the error rates on the transmitter side PFH TX , on the recipient side PFH RX and on the transmission path PFH Comm : PFH=PFH TX + PFH RX +PFH Comm ,The transmitter-side error rate is calculated as the sum of the error rates. The calculation takes into account the use of 8 dynamic values: speed, longitudinal and lateral acceleration, yaw rate, and their respective confidences, as well as four position values: location, orientation, and their confidences: PFHTX = ^TX,DU,total = ^DU,ESC + ^DU,Pos + ^DU,TX = 8*^DU,ESC,Signal + 4*^DU,Pos,Signal + ^DU,TX = 8*0.1fit + 4*40fit + 10fit = 171fit. As can be seen, the ^^values ​​were taken from the safety signal containers of the previously described message. For the value PFHComm, PFHComm = 1fit applies here. This is achieved by using a checksum (CRC) with a Hamming distance of 6 and additional data such as counter, ID, etc. Furthermore, PFHRX = PFHTX applies under the assumption that identical devices are assumed on the transmitter and receiver sides, in the general case PFH RX≠ PFHTX. However, since the receiver always knows its own PFHRX, it can use the corresponding value in the calculation. This results in: PFH = PFH TX + PFH RX +PFH Comm = 343 fit This allows a safety function to meet ASIL A requirements, as the input data used remains below the threshold of 1000 fit specified in ISO 26262. To achieve the next higher ASIL B level, the sent safety indicators must be better. For example, if DCPos>90% and DCTX>91%, ^DU,Pos,Signal<10 fit and ^ DU,TX < 9fit so the PFH TX<50fit and thus PFH<100fit, with which ASIL B requirements can be met. It should be noted that terms such as "having", "comprising", etc. do not exclude other elements or steps, and terms such as "a" or "an" do not exclude a plurality. Reference symbols in the claims are not to be regarded as limiting. 202400769 18 It should also be noted that configurations, features and variants of the invention which are described in the various designs or exemplary embodiments and / or shown in the figures can be combined with one another as desired. Individual or multiple features are interchangeable with one another as desired. Resulting feature combinations are to be understood as being covered by the disclosure of this application.References in dependent claims are not to be understood as a waiver of independent, objective protection for the features of the referenced subclaims. These features can also be combined with other features as desired. Features that are disclosed only in the description, or features that are disclosed in the description or in a claim only in conjunction with other features, can in principle be of independent, essential importance to the invention. They can therefore also be included individually in claims to distinguish them from the prior art.

Claims

202400769 19 patent claims 1. A method for a transmitter in a V2X communication network, the method comprising: capturing data for a V2X message; capturing one or more associated functional safety indicators; transmitting the captured data together with the captured one or more associated functional safety indicators.

2. The method according to claim 1, wherein the captured data is transmitted together with the captured functional safety indicators in the form of a V2X message, and wherein the V2X message comprises at least a first container comprising the data for a V2X message and a second container comprising at least one of the captured associated functional safety indicators. 3.The method according to claim 2, wherein the second container contains at least one of the following information: - safety timestamp; - time confidence; - safety message counter; - safety ID; - DevProcess; - failure rate of a data generating unit; or - FacilityLayer CRC.

4. The method according to claim 2 or 3, wherein the second container comprises one or more sub-containers, wherein a sub-container comprises at least one of the following indicators: - rate of undetected critical errors; - error detection time; - protection level; - list of data to which the indicators apply. 202400769 20 5. A method for a receiver in a V2X communication network, the method comprising: receiving V2X data together with functional safety indicators; deriving, based on the functional safety indicators, whether the V2X data is used in a safety function; and using the V2X data in the safety function.

6. The method according to claim 5, wherein the received V2X data and the associated functional safety indicators are included in a V2X message, the V2X message comprising at least a first container comprising the V2X data and a second container comprising at least one of the associated functional safety indicators. 7.Method according to claim 6, wherein the second container contains at least one of the following information: - safety timestamp - time confidence - safety message counter - safety ID - DevProcess - failure rate of a data generating unit - FacilityLayer checksum CRC 8. Method according to claim 6 or 7, wherein the second container comprises one or more sub-containers, wherein a sub-container comprises at least one of the following indicators: - rate of undetected critical errors; - error detection time; - protection level; - list of signals to which the indicators apply. 202400769 21 9. A transmitting device (110) in a V2X communication network, comprising: a first acquisition module (111) configured to acquire data for a V2X message; a second acquisition module (112) configured to acquire one or more associated functional safety indicators; and a transmitting module (113) configured to transmit the data acquired by the first acquisition module (111) together with the one or more associated functional safety indicators acquired by the second acquisition module (112). 10.A receiving device in a V2X communication network, comprising: a receiving module (121) configured to receive V2X data together with functional safety indicators; a decision module (122) configured to decide, based on the functional safety indicators, whether the V2X data is used in a safety function; and a control module (123) configured to control a safety function using the V2X data based on the decision of the decision module.

11. A communication system (100) in a V2X communication network, comprising: a transmitting device according to claim 9; and a receiving device according to claim 10. 12.A data structure (150) for use in a V2X communication network, the data structure comprising: V2X data; and associated functional safety indicators; wherein the data structure comprises at least a first container (151) comprising the V2X data and a second container (154) comprising at least one of the associated functional safety indicators.

Citation Information

Patent Citations

  • Method for performing a safety function of a vehicle and system for performing the method

    DE102012215343A1

  • Verification of messages using hash chaining

    US20210314748A1