SafetyGoalsAndFunctional PDF
SafetyGoalsAndFunctional PDF
Controller
of the major trends in the automotive industry. Some auto mak- Vehicle
ers have announced that automated vehicles will be deployed Trajectory Automation Scene*
in public traffic by the end of this decade (level 4 in sense of Controller
the definition of SAE, level 5 later). Until then, one central
Controller
challenge is ensuring functional safety of automated vehicles. Vehicle
Sensor
Still, it is not clear how safety concepts for automated vehicles Actuation Scene*
can be designed appropriately. This affects all parts of vehicle Controller Aggregation
automation systems: environment perception, decision making,
Actuator
Actuator
and actuation. In this contribution we derive safety goals and Steering,
Sensor
functional safety requirements according to ISO 26262 for ac- Brakes, Motion Sensing
tuation systems of automated vehicles systematically, following Drives
a systems theory based approach. The findings summarize
Sensor
Wheel and
Process
elaborate measures to be implemented in actuation systems of Environment
Vehicle Perception
automated vehicles when operated without human supervision. Dynamics
Process
I. I NTRODUCTION Vehicle Vehicle in its
One of the major trends in the automotive industry is Motion Environment
increasing automation of vehicle guidance. Still, the chal-
lenge exists to ensure and substantiate safety of vehicles Fig. 1. Vehicle actuation system (dashed) as actuator in a generic control
operating without human supervisor corresponding to SAE loop of a vehicle automation system; *For definition cf. [15]
levels 3 (until handing over to the driver), 4, and 5 [12].
On the one hand, it is not clear how systems operating in moving an automated vehicle along a trajectory generated by
open environments with a non-quantifiable set of operational a vehicle automation controller. This includes actuators such
scenarios can be validated [16]. On the other hand, system as steering, brakes, and drives, but also superimposed control
designs must be found which enable the safe operation of loops controlling wheel rotational dynamics and overall
automated vehicles in open environments. vehicle dynamics in terms of trajectory follow control.
According to recent statements from industrial contrib- In Section II of this paper, related work regarding safety
utors in the field of vehicle automation, the first highly goals and functional safety requirements of automated ve-
automated vehicles will be introduced into the market by the hicles is presented. Section III contains a description of a
end of this decade. Yet, safety concepts and corresponding systematic top-down approach for deriving safety goals and
safety requirements of automated vehicles are only partially functional safety requirements based on systems theory. This
discussed in the ITS community. In our understanding, this is analysis’ main results are given in Section IV followed by
crucial before deploying automated vehicles in public traffic. an evaluation in Section V, while detailed tables with all
In order to promote discussions about safety concepts of identified safety goals and functional safety requirements can
automated vehicles, we present safety goals2 and functional be found in the Appendix.
safety requirements2 for vehicle actuation systems in this
II. R ELATED W ORK
contribution. As depicted in Fig. 1, we understand vehicle
actuation systems as comprising all components required for In a previous paper, we demonstrated that vehicle actuation
systems must be considered for ensuring functional safety
*Our research is partially funded by the German Federal Ministry of automated vehicles [14]. Yet, few publications are known
of Economics and Technology (BMWi) within the scope of the project
aFAS [13].
to us which address functional safety of vehicle actuation
1 Torben Stolte, Gerrit Bagschik, and Markus Maurer are systems of automated vehicles. Due to the absence of a
with the Institute of Control Engineering at Technische human driver, supervision and failure correction must be
Universität Braunschweig, 38106 Braunschweig, Germany. implemented in electronic systems. For this, aspects such
{stolte,bagschik,maurer}@[Link]
2 Terms according to ISO 26262 [4, Part 1]. Safety goals are top-level as actuator topology, necessary degree of redundancy, sus-
safety requirements, which are further detailed by functional and technical pension kinematics, as well as designs of controllers must
safety requirements. Functional safety requirements specify system behavior be considered.
and measures required for functional safety without respecting technical im-
plementations. In contrast, technical safety requirements describe technical As actuators are completely controlled by electronic sys-
implementations required for safety. tems, actuation in the context of automated driving is
driving have been discussed widely. However, no systematic theory. Hence, Levenson utilizes the term safety constraint in place of safety
requirement, cf. [7]. For better readability and due to not yet consistent
derivation of safety goals and functional safety requirements terminology related to STAMP, we utilize terminology of ISO 26262 in this
has been performed yet. paper [4, Part 1].
2192
1
4 5 4 5
Drive Brake Steering Drive Brake
Controller Controller Controller Controller Controller
6 7 8 6 7
Drive Brake Steering Drive Brake
Dynamics Dynamics Dynamics Dynamics Dynamics
Wheel Motion Wheel and Tire Dynamics Wheel and Tire Dynamics
Wheel Motion
Sensors
Sensors
actions but all parts of the established control structure, drive. Yet, the identified control actions immanent to vehicle
potential causes for unsafe control actions are identified. actuation systems remain the same.
Subsequently, these causes can be addressed in according Found control actions – listed in Table II – summarize
functional safety requirements. Leveson provides guidance to the functionalities of vehicle actuation systems. At this point
users for applying Step 2 in the form of a reference control of the analysis, it is not clear how functionalities will be
loop that demonstrates how each part can cause unsafe technically implemented later. Due to the top-down approach
control actions [6, pp. 92]. Table I sums up potential causes followed here, selected functionalities can be implemented
taken from the reference control loop. However, Leveson also accessing different parts of the control loop. For instance,
states that additional causes can exist. either brakes or drives can be used for anti-spin control.
Thus, some control actions are allocated to multiple control
IV. A NALYSIS outputs. Furthermore, control outputs of vehicle actuation
Applying these three steps to actuation systems of auto- systems are normally quasi-continuous while control outputs
mated vehicles yields the following findings. considered in STAMP/STPA are usually discrete (e.g. ”open
A. Fundamentals
TABLE I
Regarding vehicle actuation systems, the fundamentals, C AUSAL FACTORS FOR C ONTROL ACTIONS B ECOMING U NSAFE
which we identified in our previous paper [14], are adopted ACCORDING TO L EVESON [6]
for the purpose of this contribution. As depicted in Fig. 1, a
trajectory is the control input of vehicle actuation systems. Component Causal Factor
Thus, the main functionality of vehicle actuation systems is Inadequate control algorithm
trajectory follow control. Consequently, the related hazard is Controller Process model inconsistent, incomplete, or incorrect
Inappropriate, ineffective, or missing control action
that the vehicle is not following its intended trajectory. This
can potentially result in an accident by colliding with other Inadequate or missing feedback
Feedback delays
traffic participants or stationary objects. Sensor
Measurement inaccurancies
The derived control structure as central input for the Inadequate operation
following steps is given in Fig. 2. The structure is based on Inadequate operation
the actuator topology of the experimental vehicle MOBILE Actuator Delayed operation
featuring all-wheel steering, all-wheel drive, and electrome- Component Failure
chanical brakes [2]. By summarizing or omitting actuators, Conflicting Control Actions
Process Changes over time
the structure can be adopted to different actuator topologies. Unidentified or out-of-range disturbances
For instance, coupling two steered front wheels yields front Process input missing or wrong
axle steering or omitting front wheel drives yields rear axle
2193
TABLE II TABLE III
C ONTROL ACTIONS OF THE C ONTROL O UTPUTS DEPICTED IN F IG . 2 S AFETY G OALS FOR V EHICLE ACTUATION S YSTEMS OF AUTOMATED
V EHICLES
Control Output Control Action
1 Set new target trajectory
2 Set new target wheel torque ID Safety Goal
3 Set new target steering angle SG01 VDC must set a new target wheel torque when required.
4 Change drive brake torque SG02 VDC must set a new target wheel torque only when required.
4 Change target brake torque SG03 VDC must set a new target steering angle when required.
4 Perform anti-lock control SG04 VDC must set a new target steering angle only when required.
4 Perform anti-spin control SG05 WRDC must change target brake torque when required.
5 Change target brake torque SG06 WRDC must change target brake torque only when required.
5 Perform anti-lock control SG07 WRDC must change target drive torque when required.
5 Perform anti-spin control SG08 WRDC must change target drive torque only when required.
6 Apply drive torque SG09 Anti-lock control must be performed only when required.
7 Engage brake SG10 Anti-lock control must be performed when required.
8 Hold steering angle SG11 Anti-spin control must be performed only when required.
8 Change steering angle SG12 Anti-spin control must be performed when required.
SG13 Drive Controller must apply drive torque when required.
SG14 Drive Controller must apply drive torque only when required.
door”). To address this, we considered the control outputs SG15 Brake Controller must engage brake when required.
from a functional perspective [14]. Consequently, some con- SG16 Brake Controller must engage brake only when required.
trol outputs feature multiple control actions. SG17 SC must change steering angle when required.
SG18 SC must change steering angle only when required.
B. Determining Safety Goals SG19 SC must hold steering angle when required.
SG20 SC must hold steering angle only when required.
We already showed [14], that each identified control action
VDC: Vehicle Dynamics Controller
possesses unsafe control actions regarding all four assump- WRDC: Wheel Rotational Dynamics Controller
tions Leveson suggests for conducting STPA. Yet, as our SC: Steering Controller
previous contribution had a different scope, we did determine
neither safety goals nor functional safety requirements. In for missing feedback of single sensors. Simultaneously, cycle
order to determine safety goals, we considered each unsafe time and jitter must be within acceptable bounds. Further-
control action and defined a corresponding safety goal4 . As more, sensors must indicate their operational status, such that
the superordinate vehicle automation controller is out of consuming components can evaluate whether the received
scope of this paper, we assume it functioning as intended, signals are suitable for proper operation.
which is in line with ISO 26262 [4, Part 3, [Link].2]. Thus, Processes refer to each system dynamic controlled by a
the trajectory input 1 is not considered. However, analyzing controller. As a foundation for safety, we require state-of-
an entire automated vehicle would require this. the-art electrical and mechanical design. Still, changes of
For a detailed list of considered unsafe control actions the process over time (wear, electrical/mechanical aging)
and defined safety goals see Table IV in the Appendix. and even failures can occur. Hence, an important part of
Table III summarizes the determined safety goals. Each the derived functional safety requirements is monitoring.
control action obtains two safety goals. For each control Monitoring addresses not only electrical but also mechanical
action, these two safety goals are structured similarly. On the components of the processes and is accompanied by feeding
one hand, the first safety goal demands that the control action back perceived process degradations to the superordinate
must be executed when required for safe operation. On the controller. This also comprises out-of-range or unidentified
other hand, this control action must only be executed when disturbances (e.g. an implausible system state vector). For
required for safe operation. We suppose the term required to wheel rotational and overall vehicle dynamics, control ac-
contain logical as well as timing aspects. tions can be conflicting, for example when at one wheel the
brake is engaged while the drive applies a positive torque.
C. Derivation of Functional Safety Requirements Therefore, control actions applied to the same process must
Once safety goals are determined, functional safety re- target the same process behavior.
quirements can be derived. For this, the control structure As each controller serves as an actuator within a superim-
depicted in Fig. 2 was examined by means of the reference posed control loop, controllers and actuators are considered
control loop and the related causal factors for unsafe control together. First of all, applied control algorithms must be
actions of Leveson [6, pp. 92]. Detailed results are displayed capable of handling model uncertainties and disturbances.
in Table V in the Appendix. The underlying dynamics model must be sufficiently precise
With reference to the basic components of a control loop – and the internal representation of the process state must
controller, actuator, sensor, and process – basic principles are comply with the physical process state. The latter also relates
recurrently applied. For sensors, it is required to compensate to the sensor requirements stated above. Furthermore, in-
time actuation is required. Thus, appropriate execution time
4 According to ISO 26262, an Automotive Safety Integrity Level (ASIL)
and execution jitter are required for executing control com-
must be assigned to each safety goal. However, this is strongly dependent on
specific functionalities of vehicle automation systems and related operational mands. Again, monitoring is required, here regarding proper
scenarios. This goes beyond the scope of this contribution. functioning of the control algorithm as well as regarding
2194
the operational state of controller and controlled process. VI. C ONCLUSION
Last but not least, controllers need to be designed fail- In this paper, we systematically determined safety goals
operational. Fail-operational requirements can be mitigated and derived functional safety requirements for actuation
to fail-safe requirements, presumed it can be proven that systems of automated vehicles. The findings imply, that
failures can be compensated for in any case by utilizing measures must be adopted which go beyond state-of-the-
functionally redundant actuation. Yet, this strongly depends art of recent production vehicles for ensuring functional
on an automated vehicle’s actuator topology and the maximal safety of automated vehicles. Despite high importance for
capabilities of its actuators. series deployment of automated vehicles, safety requirements
Common to all parts of the control system, continuous and are hardly discussed within the ITS community. Hence, we
sufficient power supply is required in order to ensure proper would like to put these findings forward to discussion.
functionality.
ACKNOWLEDGMENT
V. E VALUATION We would like to thank our project partners from the aFAS
consortium and our colleagues for their support of our work.
Due to missing or inaccessible similar analyses, it is hard
to validate whether the safety goals and functional safety R EFERENCES
requirements found are, on the one hand, complete and, [1] aFAS Consortium, Hazard Analysis and Risk Assessment of the Project
on the other hand, appropriate to serve as top-level safety aFAS, T. Stolte, G. Bagschik, and A. Reschka, Eds., Apr. 2016, Version
requirements for actuation systems of automated vehicles. 00-00-10, unpublished preliminary project result.
[2] P. J. Bergmiller, “Towards Functional Safety in Drive-by-Wire Ve-
Regarding the determination of safety goals, partial results hicles,” Dissertation, Technische Universität Braunschweig, Braun-
presented by Raste [9] indicate that at least the double schweig, Germany, 2015.
[3] M. Hörwick, “Sicherheitskonzept für hochautomatisierte Fahrerassis-
consideration of each control action is suitable. Furthermore, tenzsysteme,” Dissertation, Technische Universität München, Munich,
preliminary results of a hazard analysis and risk assess- Germany, 2011.
ment conducted within the project aFAS5 also show similar [4] ISO, “ISO 26262: Road vehicles - Functional Safety,” International
Organization for Standardization, Geneva, Switzerland, Standard ISO
results to some extent [1]. For instance, two safety goals 26262:2011, Nov. 2011.
are assigned regarding braking: 1. Brake actuation must be [5] J. Kim, R. R. Rajkumar, and M. Jochim, “Towards dependable
ensured when actuation is required. 2. Undesired braking autonomous driving vehicles: a system-level approach,” ACM SIGBED
Review, vol. 10, no. 1, pp. 29–32, 2013.
must be avoided. In contrast, for steering, only avoiding [6] N. G. Leveson, Engineering a Safer World: Systems Thinking Applied
of undesired actuation is demanded. Due to low velocities to Safety. Cambridge, MA, USA: MIT Press, 2011.
during automated operation, the vehicle can be stopped in [7] N. G. Leveson and J. Thomas, “An STPA Primer,” 2013.
[8] A. Mallya, V. Pantelic, M. Adedjouma, M. Lawford, and A. Wassyng,
case no steering request is executed. For automated vehicles “Using STPA in an ISO 26262 Compliant Process,” in Computer
with a more comprehensive functional range as considered in Safety, Reliability, and Security, ser. Lecture Notes in Computer
this paper, i.a. higher velocities, this is not a suitable solution. Science, A. Skavhaug, J. Guiochet, and F. Bitsch, Eds. Springer
International Publishing, Sep. 2016, no. 9922, pp. 117–129.
Just as for safety goals, no direct comparison for derived [9] T. Raste, “Fallback Strategy for Automated Driving Using STPA,”
functional safety requirements is available. Generally, the Amsterdam, The Netherlands, Oct. 2015.
functional safety requirements we derived reutilize principles [10] A. Reschka, G. Bagschik, S. Ulbrich, M. Nolte, and M. Maurer,
“Ability and skill graphs for system modeling, online monitoring,
and mechanisms quoted in Section II. As human drivers are and decision support for vehicle guidance systems,” in 2015 IEEE
completely out of the loop, all tasks related to driving must Intelligent Vehicles Symposium (IV), Jun. 2015, pp. 933–939.
be executed by electronic systems. This includes continuous [11] A. Reschka, “Safety Concept for Autonomous Vehicles,” in Au-
tonomous Driving, M. Maurer, J. C. Gerdes, B. Lenz, and H. Winner,
evaluation of the actual capabilities of the vehicle in sense of Eds. Berlin, Heidelberg, Germany: Springer Berlin Heidelberg, 2016,
a self-representation as – among others – recently discussed pp. 473–496.
by Bergmiller for by-wire actuation [2] or Reschka et al. [12] SAE, “Taxonomy and Definitions for Terms Related to On-Road
Motor Vehicle Automated Driving Systems,” Society of Automotive
for automated driving [10]. This is already addressed in the Engineers, Standard J3016, Jan. 2014.
functional safety requirements derived in this paper. For in- [13] T. Stolte, A. Reschka, G. Bagschik, and M. Maurer, “Towards Au-
stance, unusual noise originating from suspensions can refer tomated Driving: Unmanned Protective Vehicle for Highway Hard
Shoulder Road Works,” in 2015 IEEE 18th International Conference
to a loose mechanical linkage. Yet, it is not clear whether on Intelligent Transportation Systems, Sep. 2015, pp. 672–677.
all measures presented are sufficient or – in contrast – are [14] T. Stolte, R. S. Hosse, U. Becker, and M. Maurer, “On Functional
at least partially too excessive. Consequently, the functional Safety of Vehicle Actuation Systems in the Context of Automated
Driving,” in Advances in Automotive Control 2016, Norrköping, Swe-
safety requirements generically derived in this paper must be den, Jun. 2016, pp. 586–591.
challenged in reference to suitability. [15] S. Ulbrich, T. Menzel, A. Reschka, F. Schuldt, and M. Maurer,
“Defining and Substantiating the Terms Scene, Situation, and Scenario
5 Automatisch for Automated Driving,” in 2015 IEEE 18th International Conference
fahrerlos fahrendes Absicherungsfahrzeug für
on Intelligent Transportation Systems (ITSC), Sep. 2015, pp. 982–988.
Arbeitsstellen auf Autobahnen (German: Automated Unmanned Protective
[16] H. Winner, M. Graupner, and W. Wachenfeldt, “How to Address the
Vehicle for Highway Hard Shoulder Road Works). Within the project, the
Approval Trap for Autonomous Vehicles (Keynote),” in 2015 IEEE
consortium targets developing an unmanned protective vehicle for road
18th International Conference on Intelligent Transportation Systems
works on German highway hard shoulders, cf. [13]. The vehicle will be
(ITSC), Sep. 2015.
operated without a safety driver and without supervision at low speeds up
to 10 kph during public traffic on hard shoulders of German highways.
Ensuring functional safety is one of the key aspects of the project.
2195
APPENDIX
TABLE IV
U NSAFE C ONTROL ACTIONS AND S AFETY G OALS OF ACTUATION S YSTEMS OF AUTOMATED V EHICLES
TABLE V
F UNCTIONAL S AFETY R EQUIREMENTS FOR ACTUATION S YSTEMS OF AUTOMATED V EHICLES
2196
Table V: Continued from previous page
Component Type Causal Factor Functional Safety Requirement
Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Steering- Continuous and sufficient power supply for steering-internal sensors.
internal Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Wheel Continuous and sufficient power supply for wheel motion sensors.
Motion Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Vehicle Continuous and sufficient power supply for vehicle motion sensors.
Motion Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized.
Continuous and sufficient power supply for motion estimation.
Motion Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensor Sufficient measurement accuracy for wheel rotational dynamics control and vehicle
Estimation Measurement inaccuracies
dynamics control must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Component failure Electrical and mechanical design according to state of the art.
Monitoring of electrical and mechanical components and report to superordinate
controller.
Conflicting control actions Does not apply, only one controller.
Brake Monitoring of electrical and mechanical components and report to superordinate
Process Changes over time
Dynamics controller.
Unidentified or out-of-range Brake controller must recognize brakes operating beyond design limits and react
disturbances appropriately (e.g. failure state).
Process input missing or wrong Continuous and sufficient power supply for brake.
Component failure Electrical and mechanical design according to state of the art.
Monitoring of electrical and mechanical components and report to superordinate
controller.
Conflicting control actions Does not apply, only one controller.
Drive Monitoring of electrical and mechanical components and report to superordinate
Process Changes over time
Dynamics controller.
Unidentified or out-of-range Drive controller must recognize drive operating beyond design limits and react
disturbances appropriately (e.g. failure state).
Process input missing or wrong Continuous and sufficient power supply for drive.
Component failure Electrical and mechanical design according to state of the art.
Monitoring of electrical and mechanical components and report to superordinate
controller.
Conflicting control actions Does not apply, only one controller.
Steering Monitoring of electrical and mechanical components and report to superordinate
Process Changes over time
Dynamics controller.
Unidentified or out-of-range Steering controller must recognize steering operating beyond design limits and
disturbances react appropriately (e.g. failure state).
Process input missing or wrong Continuous and sufficient power supply for steering.
Component failure Design of suspension kinematics, wheel, and tires according to state of the art.
Monitoring of suspension kinematics, wheel, and tire as well as report to
superordinate controller.
Wheel and Conflicting control actions Exclusion of drive and brake actuation with different.
Tire Process Monitoring of suspension kinematics, wheel, and tire as well as report to
Changes over time
Dynamics superordinate controller.
Unidentified or out-of-range Brake and drive controller must recognize wheel operating beyond design limits
disturbances and react appropriately (e.g. failure state).
Process input missing or wrong Does not apply, no additional process input.
Component failure Considered with wheel and tire dynamics.
Control actions of the vehicle dynamics controller must target the same vehicle
Conflicting control actions
Overall motion.
Vehicle Process Changes over time Considered with wheel and tire dynamics.
Dynamics Unidentified or out-of-range Vehicle dynamics controller must recognize vehicle dynamics operating beyond
disturbances limits of handling and react appropriately.
Process input missing or wrong Does not apply, no additional process input.
Continued on next page
2197
Table V: Continued from previous page
Component Type Causal Factor Functional Safety Requirement
Control algorithm robust against uncertainties of the steering dynamics model and
Inadequate control algorithm
disturbances.
Process model inconsistent,
Sufficiently precise and validated steering dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Steering Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for steering controller.
Controller Actuator missing control action
Fail-operational design of steering controller.
Monitoring of operational state of steering controller and process and report to
superordinate controller.
Inadequate operation Fail-operational design of steering.
Delayed operation Operation of steering controller must be provided in required cycle time and jitter.
Control algorithm robust against uncertainties of the brake dynamics model and
Inadequate control algorithm
disturbances.
Process model inconsistent,
Sufficiently precise and validated brake dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Brake Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for brake controller.
Controller Actuator missing control action
Fail-operational design of brake controller.
Monitoring of operational state of brake controller and process and report to
superordinate controller.
Inadequate operation Fail-operational design of brake.
Delayed operation Operation of brake controller must be provided in required cycle time and jitter.
Control algorithm robust against uncertainties of the drive dynamics model and
Inadequate control algorithm
disturbances.
Process model inconsistent,
Sufficiently precise and validated drive dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Drive Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for drive controller.
Controller Actuator missing control action
Fail-operational design of drive controller.
Monitoring of operational state of drive controller and process and report to
superordinate controller.
Inadequate operation Fail-operational design of drive.
Delayed operation Operation of drive controller must be provided in required cycle time and jitter.
Control algorithm robust against uncertainties of the wheel rotational dynamics
Inadequate control algorithm
model and disturbances.
Fault-tolerant wheel rotational dynamics control algorithm.
Process model inconsistent,
Sufficiently precise and validated wheel rotational dynamics model.
incomplete, or incorrect
Wheel Process variables must comply with the physical process state.
Rotational Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for wheel rotational dynamics controller.
Dynamics Actuator missing control action
Controller Fail-operational design of wheel rotational dynamics controller.
Monitoring of operational state of wheel rotational dynamics controller and
process and report to superordinate controller.
Inadequate operation Covered by underlying control loops.
Operation of wheel rotational dynamics controller must be provided in required
Delayed operation
cycle time and jitter.
Control algorithm robust against uncertainties of the vehicle dynamics model and
Inadequate control algorithm
disturbances.
Fault-tolerant vehicle dynamics control algorithm.
Process model inconsistent,
Sufficiently precise and validated vehicle dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Vehicle
Controller, Inappropriate, ineffective, or
Dynamics Continuous and sufficient power supply for vehicle dynamics controller.
Actuator missing control action
Controller
Fail-operational design of vehicle dynamics controller.
Monitoring of operational state of vehicle dynamics controller and process and
report to superordinate controller.
Inadequate operation Covered by underlying control loops.
Operation of vehicle dynamics controller must be provided in required cycle time
Delayed operation
and jitter.
Table concluded
2198