首页> 外文会议>SAE World Congress Experience >A Method towards the Systematic Architecting of Functionally Safe Automated Driving- Leveraging Diagnostic Specifications for FSC design
【24h】

A Method towards the Systematic Architecting of Functionally Safe Automated Driving- Leveraging Diagnostic Specifications for FSC design

机译:用于FSC设计功能安全自动化驱动诊断规范的系统架构方法

获取原文

摘要

With the advent of ISO 26262 there is an increased emphasis on top-down design in the automotive industry. While the standard delivers a best practice framework and a reference safety lifecycle, it lacks detailed requirements for its various constituent phases. The lack of guidance becomes especially evident for the reuse of legacy components and subsystems, the most common scenario in the cost-sensitive automotive domain, leaving vehicle architects and safety engineers to rely on experience without methodological support for their decisions. This poses particular challenges in the industry which is currently undergoing many significant changes due to new features like connectivity, servitization, electrification and automation. In this paper we focus on automated driving where multiple subsystems, both new and legacy, need to coordinate to realize a safety-critical function. This paper introduces a method to support consistent design of a work product required by ISO 26262, the Functional Safety Concept (FSC). The method arises from and addresses a need within the industry for architectural analysis, rationale management and reuse of legacy subsystems. The method makes use of an existing work product, the diagnostic specifications of a subsystem, to assist in performing a systematic assessment of the influence a human driver, in the design of the subsystem. The output of the method is a report with an abstraction level suitable for a vehicle architect, used as a basis for decisions related to the FSC such as generating a Preliminary Architecture (PA) and building up argumentation for verification of the FSC. The proposed method is tested in a safety-critical braking subsystem at one of the largest heavy vehicle manufacturers in Sweden, Scania C.V. AB. The results demonstrate the benefits of the method including (i) reuse of pre-existing work products, (ii) gathering requirements for automated driving functions while designing the PA and FSC, (iii) the parallelization of work across the organization on the basis of expertise, and (iv) the applicability of the method across all types of subsystems.
机译:随着ISO 26262的到来有一个更加强调自上而下的设计在汽车行业。虽然标准提供了一个最佳实践框架和参考安全生命周期,它缺乏对于其各组成相的详细要求。缺乏指导的传统组件和子系统,在成本敏感的汽车领域最常见的场景重用变得尤为明显,让车辆建筑师和安全工程师依靠经验,没有对自己的决策方法支持。这引起了目前正在经历由于新功能,如连接性,服务化,电气化与自动化许多显著变化的行业特定的挑战。在本文中,我们专注于自动驾驶的,其中多个子系统,新的和旧的,需要进行协调,以实现安全关键功能。本文介绍了以支持ISO 26262功能安全概念(FSC)要求的工作产品的一贯设计的方法。该方法源于和地址,行业内的需求结构分析,合理管理和遗留子系统的重用。该方法利用现有的工作成果,一个子系统的诊断规范,以协助执行影响的人驾驶的系统评估,在子系统的设计。该方法的输出是适合于车辆建筑师的抽象级别,作为相关的FSC诸如生成一个初步架构(PA)和建立论证的FSC的验证决策的基础的报告。该方法是在安全性至关重要的制动子系统在最大的重型汽车制造商在瑞典,斯堪尼亚C.V.一个测试AB。结果表明该方法包括预先存在的工作产品(I)重用的好处,(二)收集需求的自动驾驶功能而设计的PA和FSC,(III)在整个组织工作的基础上,并行专门知识,和(iv)在所有类型的子系统的方法的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号