0% found this document useful (0 votes)
32 views8 pages

SafetyGoalsAndFunctional PDF

Uploaded by

Haru Việt Nam
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
32 views8 pages

SafetyGoalsAndFunctional PDF

Uploaded by

Haru Việt Nam
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

2016 IEEE 19th International Conference on Intelligent Transportation Systems (ITSC)

Windsor Oceanico Hotel, Rio de Janeiro, Brazil, November 1-4, 2016

Safety Goals and Functional Safety Requirements for Actuation


Systems of Automated Vehicles*
Torben Stolte1 , Gerrit Bagschik1 , and Markus Maurer1

Abstract— Increasing automation of vehicle guidance is one Desired Mission

Controller
of the major trends in the automotive industry. Some auto mak- Vehicle
ers have announced that automated vehicles will be deployed Trajectory Automation Scene*
in public traffic by the end of this decade (level 4 in sense of Controller
the definition of SAE, level 5 later). Until then, one central

Controller
challenge is ensuring functional safety of automated vehicles. Vehicle

Sensor
Still, it is not clear how safety concepts for automated vehicles Actuation Scene*
can be designed appropriately. This affects all parts of vehicle Controller Aggregation
automation systems: environment perception, decision making,

Actuator
Actuator
and actuation. In this contribution we derive safety goals and Steering,

Sensor
functional safety requirements according to ISO 26262 for ac- Brakes, Motion Sensing
tuation systems of automated vehicles systematically, following Drives
a systems theory based approach. The findings summarize

Sensor
Wheel and

Process
elaborate measures to be implemented in actuation systems of Environment
Vehicle Perception
automated vehicles when operated without human supervision. Dynamics

Process
I. I NTRODUCTION Vehicle Vehicle in its
One of the major trends in the automotive industry is Motion Environment
increasing automation of vehicle guidance. Still, the chal-
lenge exists to ensure and substantiate safety of vehicles Fig. 1. Vehicle actuation system (dashed) as actuator in a generic control
operating without human supervisor corresponding to SAE loop of a vehicle automation system; *For definition cf. [15]
levels 3 (until handing over to the driver), 4, and 5 [12].
On the one hand, it is not clear how systems operating in moving an automated vehicle along a trajectory generated by
open environments with a non-quantifiable set of operational a vehicle automation controller. This includes actuators such
scenarios can be validated [16]. On the other hand, system as steering, brakes, and drives, but also superimposed control
designs must be found which enable the safe operation of loops controlling wheel rotational dynamics and overall
automated vehicles in open environments. vehicle dynamics in terms of trajectory follow control.
According to recent statements from industrial contrib- In Section II of this paper, related work regarding safety
utors in the field of vehicle automation, the first highly goals and functional safety requirements of automated ve-
automated vehicles will be introduced into the market by the hicles is presented. Section III contains a description of a
end of this decade. Yet, safety concepts and corresponding systematic top-down approach for deriving safety goals and
safety requirements of automated vehicles are only partially functional safety requirements based on systems theory. This
discussed in the ITS community. In our understanding, this is analysis’ main results are given in Section IV followed by
crucial before deploying automated vehicles in public traffic. an evaluation in Section V, while detailed tables with all
In order to promote discussions about safety concepts of identified safety goals and functional safety requirements can
automated vehicles, we present safety goals2 and functional be found in the Appendix.
safety requirements2 for vehicle actuation systems in this
II. R ELATED W ORK
contribution. As depicted in Fig. 1, we understand vehicle
actuation systems as comprising all components required for In a previous paper, we demonstrated that vehicle actuation
systems must be considered for ensuring functional safety
*Our research is partially funded by the German Federal Ministry of automated vehicles [14]. Yet, few publications are known
of Economics and Technology (BMWi) within the scope of the project
aFAS [13].
to us which address functional safety of vehicle actuation
1 Torben Stolte, Gerrit Bagschik, and Markus Maurer are systems of automated vehicles. Due to the absence of a
with the Institute of Control Engineering at Technische human driver, supervision and failure correction must be
Universität Braunschweig, 38106 Braunschweig, Germany. implemented in electronic systems. For this, aspects such
{stolte,bagschik,maurer}@[Link]
2 Terms according to ISO 26262 [4, Part 1]. Safety goals are top-level as actuator topology, necessary degree of redundancy, sus-
safety requirements, which are further detailed by functional and technical pension kinematics, as well as designs of controllers must
safety requirements. Functional safety requirements specify system behavior be considered.
and measures required for functional safety without respecting technical im-
plementations. In contrast, technical safety requirements describe technical As actuators are completely controlled by electronic sys-
implementations required for safety. tems, actuation in the context of automated driving is

978-1-5090-1889-5/16/$31.00 ©2016 IEEE 2191


strongly linked to automotive by-wire systems such as III. S ELECTED A PPROACH
steer-by-wire or brake-by-wire. Several publications address
As the most recent standard available, the international
safety aspects connected to by-wire actuators. A compre-
standard ISO 26262 [4] must be applied with respect to
hensive overview of publications regarding functional safety
ensuring functional safety of the functionality of automated
of by-wire systems in the automotive domain is given by
vehicles. ISO 26262 requires determination of safety goals as
Bergmiller [2]. Aspects such as redundancy regarding the
part of hazard analysis and risk assessment and derivation of
structure of electronic control units, sensors, actuators, and
functional safety requirements which are performed during
power supply, as well as fault-tolerant and deterministic
the concept phase of a development process [4, Part 3,
communication network topology is required to a certain
7.4.4 and 8.4.2]. In our previous paper [14], we utilized
extent. Additionally, Bergmiller extends these considera-
the System-Theoretic Process Analysis (STPA) in order to
tions towards a safety concept for the experimental vehicle
examine vehicle actuation systems systematically regarding
MOBILE of Technische Universität Braunschweig. The ve-
malfunctional behavior which is a required input for a hazard
hicle features brake-by-wire, steer-by-wire, and throttle-by-
analysis and risk assessment. Consistent with Raste [9] as
wire at each wheel individually. Still, the vehicle is controlled
well as Mallya [8], we utilize STPA again for determining
by a human driver.
safety goals and deriving functional safety requirements for
Although these contributions address many aspects that
actuation systems of automated vehicles systematically.
are potentially highly relevant for actuation systems of auto-
Leveson developed STPA as one of a growing set of
mated vehicles as well, they focus on human-controlled by-
methods subsumed as System Theoretic Accident Model and
wire systems. In contrast, Hörwick presents a safety concept
Processes3 [6]. As STAMP/STPA is based on systems the-
for partially automated vehicle system (SAE level 3) [3]. This
ory, safety relevant systems are modeled in terms of control
system still requires a human driver as a fallback layer, yet
loops. Within these control loops, STPA targets systematic
Hörwick identified safety requirements which are potentially
identification of unsafe control actions and associated causes.
applicable to highly or fully automated vehicles (SAE levels
STPA consists of three basic steps: Step 0 contains estab-
4 and 5). Among these, Hörwick lists safety requirements
lishing fundamentals for subsequent steps, Step 1 identifies
for vehicle actuation systems. He demands redundantly con-
unsafe control actions, and Step 2 consists of an analysis
trollable brakes and redundant steering actuators. These are
of causes of the identified unsafe control actions. With these
supported by generating yaw moment by differential braking
results, safety requirements can be derived on different levels
in case of steering loss. Furthermore, inertial sensors and
of abstraction.
connected motion estimation are supposed to be designed
The fundamentals established in Step 0 comprise, among
redundantly.
others, accident and hazard identification as well as modeling
Raste considers safety goals and safety requirements for a
the considered system as hierarchical control structure. For
SAE level 3 system, too [9]. In line with our understanding,
example, in Fig. 1 the vehicle actuation system as actuator
Raste sees trajectories as input to vehicle actuation systems.
itself contains subordinate control loops.
For vehicle actuation systems, he introduces redundancy
structures consisting of two parallel paths. The first path For identifying unsafe control actions in Step 1, Leveson
executes the normal operation, while the second path is proposes four basic assumptions for control actions being
in hot-standby. The second path can take over control in unsafe [6, pp. 213]. These are:
case the first path malfunctions. Again, elements such as • A control action required is not provided or is not
redundant design of controllers, actuators, sensors, as well followed.
as power supply are met. Additionally, Raste presents some • A control action is provided although not required.
safety goals regarding steering. These can be summed up by • A potentially safe control action is provided too early,
unintended steering must be avoided and intended steering too late, at the wrong time, or in the wrong sequence.
must be ensured. • A control action required for safety is stopped too soon
Reschka presents general deliberations regarding func- or applied too long.
tional safety of automated vehicles [11]. Reschka also gen- Applying these assumptions on the control actions of a
erally requires redundant design of sensors, actuators, and system yields a list of unsafe control actions. For each of
power supply for ensuring functional safety of automated ve- the identified control actions, top-level safety requirements
hicles which also applies to actuation systems. Beyond this, can be derived, namely safety goals in terms of ISO 26262.
he argues in line with Bergmiller [2] that functional redun- Step 2 of STPA comprises a causal analysis. In gen-
dancies can be beneficial for ensuring functional safety. Uti- eral, Step 2 is the most challenging part of STPA because
lization of functional redundancies is proposed by Kim [5], it requires more experience compared to Step 1 as less
too. guidance is provided [7]. By examining not only control
Altogether, basic considerations regarding safety mech-
anisms of actuations systems in the context of automated 3 The terminology related to STAMP is strongly influenced by systems

driving have been discussed widely. However, no systematic theory. Hence, Levenson utilizes the term safety constraint in place of safety
requirement, cf. [7]. For better readability and due to not yet consistent
derivation of safety goals and functional safety requirements terminology related to STAMP, we utilize terminology of ISO 26262 in this
has been performed yet. paper [4, Part 1].

2192
1

Vehicle Dynamics Controller


Motion
Estimation 2 3 2
Wheel Rotational Wheel Rotational
Dynamics Controller Dynamics Controller

4 5 4 5
Drive Brake Steering Drive Brake
Controller Controller Controller Controller Controller
6 7 8 6 7
Drive Brake Steering Drive Brake
Dynamics Dynamics Dynamics Dynamics Dynamics

Wheel Motion Wheel and Tire Dynamics Wheel and Tire Dynamics
Wheel Motion
Sensors
Sensors

Vehicle Motion Overall Vehicle Dynamics


Sensors

Front Left Wheel Front Right Wheel


Physical Coupling Control Flow 1 Control Action C Process

Fig. 2. Control structure of actuation systems of automated vehicles [14]

actions but all parts of the established control structure, drive. Yet, the identified control actions immanent to vehicle
potential causes for unsafe control actions are identified. actuation systems remain the same.
Subsequently, these causes can be addressed in according Found control actions – listed in Table II – summarize
functional safety requirements. Leveson provides guidance to the functionalities of vehicle actuation systems. At this point
users for applying Step 2 in the form of a reference control of the analysis, it is not clear how functionalities will be
loop that demonstrates how each part can cause unsafe technically implemented later. Due to the top-down approach
control actions [6, pp. 92]. Table I sums up potential causes followed here, selected functionalities can be implemented
taken from the reference control loop. However, Leveson also accessing different parts of the control loop. For instance,
states that additional causes can exist. either brakes or drives can be used for anti-spin control.
Thus, some control actions are allocated to multiple control
IV. A NALYSIS outputs. Furthermore, control outputs of vehicle actuation
Applying these three steps to actuation systems of auto- systems are normally quasi-continuous while control outputs
mated vehicles yields the following findings. considered in STAMP/STPA are usually discrete (e.g. ”open

A. Fundamentals
TABLE I
Regarding vehicle actuation systems, the fundamentals, C AUSAL FACTORS FOR C ONTROL ACTIONS B ECOMING U NSAFE
which we identified in our previous paper [14], are adopted ACCORDING TO L EVESON [6]
for the purpose of this contribution. As depicted in Fig. 1, a
trajectory is the control input of vehicle actuation systems. Component Causal Factor
Thus, the main functionality of vehicle actuation systems is Inadequate control algorithm
trajectory follow control. Consequently, the related hazard is Controller Process model inconsistent, incomplete, or incorrect
Inappropriate, ineffective, or missing control action
that the vehicle is not following its intended trajectory. This
can potentially result in an accident by colliding with other Inadequate or missing feedback
Feedback delays
traffic participants or stationary objects. Sensor
Measurement inaccurancies
The derived control structure as central input for the Inadequate operation
following steps is given in Fig. 2. The structure is based on Inadequate operation
the actuator topology of the experimental vehicle MOBILE Actuator Delayed operation
featuring all-wheel steering, all-wheel drive, and electrome- Component Failure
chanical brakes [2]. By summarizing or omitting actuators, Conflicting Control Actions
Process Changes over time
the structure can be adopted to different actuator topologies. Unidentified or out-of-range disturbances
For instance, coupling two steered front wheels yields front Process input missing or wrong
axle steering or omitting front wheel drives yields rear axle

2193
TABLE II TABLE III
C ONTROL ACTIONS OF THE C ONTROL O UTPUTS DEPICTED IN F IG . 2 S AFETY G OALS FOR V EHICLE ACTUATION S YSTEMS OF AUTOMATED
V EHICLES
Control Output Control Action
1 Set new target trajectory
2 Set new target wheel torque ID Safety Goal
3 Set new target steering angle SG01 VDC must set a new target wheel torque when required.
4 Change drive brake torque SG02 VDC must set a new target wheel torque only when required.
4 Change target brake torque SG03 VDC must set a new target steering angle when required.
4 Perform anti-lock control SG04 VDC must set a new target steering angle only when required.
4 Perform anti-spin control SG05 WRDC must change target brake torque when required.
5 Change target brake torque SG06 WRDC must change target brake torque only when required.
5 Perform anti-lock control SG07 WRDC must change target drive torque when required.
5 Perform anti-spin control SG08 WRDC must change target drive torque only when required.
6 Apply drive torque SG09 Anti-lock control must be performed only when required.
7 Engage brake SG10 Anti-lock control must be performed when required.
8 Hold steering angle SG11 Anti-spin control must be performed only when required.
8 Change steering angle SG12 Anti-spin control must be performed when required.
SG13 Drive Controller must apply drive torque when required.
SG14 Drive Controller must apply drive torque only when required.
door”). To address this, we considered the control outputs SG15 Brake Controller must engage brake when required.
from a functional perspective [14]. Consequently, some con- SG16 Brake Controller must engage brake only when required.
trol outputs feature multiple control actions. SG17 SC must change steering angle when required.
SG18 SC must change steering angle only when required.
B. Determining Safety Goals SG19 SC must hold steering angle when required.
SG20 SC must hold steering angle only when required.
We already showed [14], that each identified control action
VDC: Vehicle Dynamics Controller
possesses unsafe control actions regarding all four assump- WRDC: Wheel Rotational Dynamics Controller
tions Leveson suggests for conducting STPA. Yet, as our SC: Steering Controller
previous contribution had a different scope, we did determine
neither safety goals nor functional safety requirements. In for missing feedback of single sensors. Simultaneously, cycle
order to determine safety goals, we considered each unsafe time and jitter must be within acceptable bounds. Further-
control action and defined a corresponding safety goal4 . As more, sensors must indicate their operational status, such that
the superordinate vehicle automation controller is out of consuming components can evaluate whether the received
scope of this paper, we assume it functioning as intended, signals are suitable for proper operation.
which is in line with ISO 26262 [4, Part 3, [Link].2]. Thus, Processes refer to each system dynamic controlled by a
the trajectory input 1 is not considered. However, analyzing controller. As a foundation for safety, we require state-of-
an entire automated vehicle would require this. the-art electrical and mechanical design. Still, changes of
For a detailed list of considered unsafe control actions the process over time (wear, electrical/mechanical aging)
and defined safety goals see Table IV in the Appendix. and even failures can occur. Hence, an important part of
Table III summarizes the determined safety goals. Each the derived functional safety requirements is monitoring.
control action obtains two safety goals. For each control Monitoring addresses not only electrical but also mechanical
action, these two safety goals are structured similarly. On the components of the processes and is accompanied by feeding
one hand, the first safety goal demands that the control action back perceived process degradations to the superordinate
must be executed when required for safe operation. On the controller. This also comprises out-of-range or unidentified
other hand, this control action must only be executed when disturbances (e.g. an implausible system state vector). For
required for safe operation. We suppose the term required to wheel rotational and overall vehicle dynamics, control ac-
contain logical as well as timing aspects. tions can be conflicting, for example when at one wheel the
brake is engaged while the drive applies a positive torque.
C. Derivation of Functional Safety Requirements Therefore, control actions applied to the same process must
Once safety goals are determined, functional safety re- target the same process behavior.
quirements can be derived. For this, the control structure As each controller serves as an actuator within a superim-
depicted in Fig. 2 was examined by means of the reference posed control loop, controllers and actuators are considered
control loop and the related causal factors for unsafe control together. First of all, applied control algorithms must be
actions of Leveson [6, pp. 92]. Detailed results are displayed capable of handling model uncertainties and disturbances.
in Table V in the Appendix. The underlying dynamics model must be sufficiently precise
With reference to the basic components of a control loop – and the internal representation of the process state must
controller, actuator, sensor, and process – basic principles are comply with the physical process state. The latter also relates
recurrently applied. For sensors, it is required to compensate to the sensor requirements stated above. Furthermore, in-
time actuation is required. Thus, appropriate execution time
4 According to ISO 26262, an Automotive Safety Integrity Level (ASIL)
and execution jitter are required for executing control com-
must be assigned to each safety goal. However, this is strongly dependent on
specific functionalities of vehicle automation systems and related operational mands. Again, monitoring is required, here regarding proper
scenarios. This goes beyond the scope of this contribution. functioning of the control algorithm as well as regarding

2194
the operational state of controller and controlled process. VI. C ONCLUSION
Last but not least, controllers need to be designed fail- In this paper, we systematically determined safety goals
operational. Fail-operational requirements can be mitigated and derived functional safety requirements for actuation
to fail-safe requirements, presumed it can be proven that systems of automated vehicles. The findings imply, that
failures can be compensated for in any case by utilizing measures must be adopted which go beyond state-of-the-
functionally redundant actuation. Yet, this strongly depends art of recent production vehicles for ensuring functional
on an automated vehicle’s actuator topology and the maximal safety of automated vehicles. Despite high importance for
capabilities of its actuators. series deployment of automated vehicles, safety requirements
Common to all parts of the control system, continuous and are hardly discussed within the ITS community. Hence, we
sufficient power supply is required in order to ensure proper would like to put these findings forward to discussion.
functionality.
ACKNOWLEDGMENT
V. E VALUATION We would like to thank our project partners from the aFAS
consortium and our colleagues for their support of our work.
Due to missing or inaccessible similar analyses, it is hard
to validate whether the safety goals and functional safety R EFERENCES
requirements found are, on the one hand, complete and, [1] aFAS Consortium, Hazard Analysis and Risk Assessment of the Project
on the other hand, appropriate to serve as top-level safety aFAS, T. Stolte, G. Bagschik, and A. Reschka, Eds., Apr. 2016, Version
requirements for actuation systems of automated vehicles. 00-00-10, unpublished preliminary project result.
[2] P. J. Bergmiller, “Towards Functional Safety in Drive-by-Wire Ve-
Regarding the determination of safety goals, partial results hicles,” Dissertation, Technische Universität Braunschweig, Braun-
presented by Raste [9] indicate that at least the double schweig, Germany, 2015.
[3] M. Hörwick, “Sicherheitskonzept für hochautomatisierte Fahrerassis-
consideration of each control action is suitable. Furthermore, tenzsysteme,” Dissertation, Technische Universität München, Munich,
preliminary results of a hazard analysis and risk assess- Germany, 2011.
ment conducted within the project aFAS5 also show similar [4] ISO, “ISO 26262: Road vehicles - Functional Safety,” International
Organization for Standardization, Geneva, Switzerland, Standard ISO
results to some extent [1]. For instance, two safety goals 26262:2011, Nov. 2011.
are assigned regarding braking: 1. Brake actuation must be [5] J. Kim, R. R. Rajkumar, and M. Jochim, “Towards dependable
ensured when actuation is required. 2. Undesired braking autonomous driving vehicles: a system-level approach,” ACM SIGBED
Review, vol. 10, no. 1, pp. 29–32, 2013.
must be avoided. In contrast, for steering, only avoiding [6] N. G. Leveson, Engineering a Safer World: Systems Thinking Applied
of undesired actuation is demanded. Due to low velocities to Safety. Cambridge, MA, USA: MIT Press, 2011.
during automated operation, the vehicle can be stopped in [7] N. G. Leveson and J. Thomas, “An STPA Primer,” 2013.
[8] A. Mallya, V. Pantelic, M. Adedjouma, M. Lawford, and A. Wassyng,
case no steering request is executed. For automated vehicles “Using STPA in an ISO 26262 Compliant Process,” in Computer
with a more comprehensive functional range as considered in Safety, Reliability, and Security, ser. Lecture Notes in Computer
this paper, i.a. higher velocities, this is not a suitable solution. Science, A. Skavhaug, J. Guiochet, and F. Bitsch, Eds. Springer
International Publishing, Sep. 2016, no. 9922, pp. 117–129.
Just as for safety goals, no direct comparison for derived [9] T. Raste, “Fallback Strategy for Automated Driving Using STPA,”
functional safety requirements is available. Generally, the Amsterdam, The Netherlands, Oct. 2015.
functional safety requirements we derived reutilize principles [10] A. Reschka, G. Bagschik, S. Ulbrich, M. Nolte, and M. Maurer,
“Ability and skill graphs for system modeling, online monitoring,
and mechanisms quoted in Section II. As human drivers are and decision support for vehicle guidance systems,” in 2015 IEEE
completely out of the loop, all tasks related to driving must Intelligent Vehicles Symposium (IV), Jun. 2015, pp. 933–939.
be executed by electronic systems. This includes continuous [11] A. Reschka, “Safety Concept for Autonomous Vehicles,” in Au-
tonomous Driving, M. Maurer, J. C. Gerdes, B. Lenz, and H. Winner,
evaluation of the actual capabilities of the vehicle in sense of Eds. Berlin, Heidelberg, Germany: Springer Berlin Heidelberg, 2016,
a self-representation as – among others – recently discussed pp. 473–496.
by Bergmiller for by-wire actuation [2] or Reschka et al. [12] SAE, “Taxonomy and Definitions for Terms Related to On-Road
Motor Vehicle Automated Driving Systems,” Society of Automotive
for automated driving [10]. This is already addressed in the Engineers, Standard J3016, Jan. 2014.
functional safety requirements derived in this paper. For in- [13] T. Stolte, A. Reschka, G. Bagschik, and M. Maurer, “Towards Au-
stance, unusual noise originating from suspensions can refer tomated Driving: Unmanned Protective Vehicle for Highway Hard
Shoulder Road Works,” in 2015 IEEE 18th International Conference
to a loose mechanical linkage. Yet, it is not clear whether on Intelligent Transportation Systems, Sep. 2015, pp. 672–677.
all measures presented are sufficient or – in contrast – are [14] T. Stolte, R. S. Hosse, U. Becker, and M. Maurer, “On Functional
at least partially too excessive. Consequently, the functional Safety of Vehicle Actuation Systems in the Context of Automated
Driving,” in Advances in Automotive Control 2016, Norrköping, Swe-
safety requirements generically derived in this paper must be den, Jun. 2016, pp. 586–591.
challenged in reference to suitability. [15] S. Ulbrich, T. Menzel, A. Reschka, F. Schuldt, and M. Maurer,
“Defining and Substantiating the Terms Scene, Situation, and Scenario
5 Automatisch for Automated Driving,” in 2015 IEEE 18th International Conference
fahrerlos fahrendes Absicherungsfahrzeug für
on Intelligent Transportation Systems (ITSC), Sep. 2015, pp. 982–988.
Arbeitsstellen auf Autobahnen (German: Automated Unmanned Protective
[16] H. Winner, M. Graupner, and W. Wachenfeldt, “How to Address the
Vehicle for Highway Hard Shoulder Road Works). Within the project, the
Approval Trap for Autonomous Vehicles (Keynote),” in 2015 IEEE
consortium targets developing an unmanned protective vehicle for road
18th International Conference on Intelligent Transportation Systems
works on German highway hard shoulders, cf. [13]. The vehicle will be
(ITSC), Sep. 2015.
operated without a safety driver and without supervision at low speeds up
to 10 kph during public traffic on hard shoulders of German highways.
Ensuring functional safety is one of the key aspects of the project.

2195
APPENDIX

TABLE IV
U NSAFE C ONTROL ACTIONS AND S AFETY G OALS OF ACTUATION S YSTEMS OF AUTOMATED V EHICLES

CA Unsafe Control Action Safety Goal Index


2 A new target wheel torque is not set although required. VDC must set a new target wheel torque when required. SG01
2 A new target wheel torque is set although not required. VDC must set a new target wheel torque only when required. SG02
2 A new target wheel torque is set too late. VDC must set a new target wheel torque when required. SG01
2 A new target wheel torque is applied too long. VDC must set a new target wheel torque when required. SG01
2 A new target wheel torque is released too soon VDC must set a new target wheel torque when required. SG01
3 New target steering angle is not set although required. VDC must set a new target steering angle when required. SG03
3 A new target steering angle is set although not desired. VDC must set a new target steering angle only when required. SG04
3 A new target steering angle is set too late. VDC must set a new target steering angle when required. SG03
3 A new target steering angle is applied too long. VDC must set a new target steering angle when required. SG03
4 5 Target brake torque is not changed although required. WRDC must change target brake torque when required. SG05
4 5 Target brake torque is changed although not required. WRDC must change target brake torque only when required. SG06
4 5 Target brake torque is changed too late. WRDC must change target brake torque when required. SG05
4 5 Target brake torque is applied too long. WRDC must change target brake torque when required. SG05
5 Target drive torque is not changed although required. WRDC must change target drive torque when required. SG07
5 Target drive torque is changed although required. WRDC must change target drive torque only when required. SG08
5 Target drive torque is changed too late. WRDC must change target drive torque when required. SG07
5 Target drive torque is applied too long. WRDC must change target drive torque when required. SG07
4 5 Anti-lock control is performed although not required. Anti-lock control must be performed only when required. SG09
4 5 Anti-lock control is not performed although required. Anti-lock control must be performed when required. SG10
4 5 Anti-lock control is performed too late. Anti-lock control must be performed when required. SG10
4 5 Anti-lock control is performed too soon. Anti-lock control must be performed only when required. SG09
4 5 Anti-spin control is performed although not required. Anti-spin control must be performed only when required. SG11
4 5 Anti-spin control is not performed although required. Anti-spin control must be performed when required. SG12
4 5 Anti-spin control is performed too late. Anti-spin control must be performed when required. SG12
4 5 Anti-spin control is performed too soon. Anti-spin control must be performed only when required. SG11
6 Drive torque is not applied although required. Drive Controller must apply drive torque when required. SG13
6 Drive torque is applied although not required. Drive Controller must apply drive torque only when required. SG14
6 Drive torque is applied too late. Drive Controller must apply drive torque when required. SG13
6 Drive torque is applied too long. Drive Controller must apply drive torque only when required. SG14
7 Brake torque is not applied although required. Brake Controller must engage brake when required. SG15
7 Brake torque is applied although not required. Brake Controller must engage brake only when required. SG16
7 Brake torque is applied too late. Brake Controller must engage brake when required. SG15
7 Brake torque is applied too long. Brake Controller must engage brake only when required. SG16
8 Steering angle is not changed although required. SC must change steering angle when required. SG17
8 Steering angle is changed although it is required not to change. SC must change steering angle only when required. SG18
8 Steering angle changes too late. SC must change steering angle when required. SG17
8 Steering angle is changed too long. SC must hold steering angle when required. SG19
8 Steering angle is not held although required. SC must hold steering angle when required. SG19
8 Steering angle is held although it is required to change. SC must hold steering angle only when required. SG20
8 Steering angle is held too late. SC must hold steering angle when required. SG19
8 Steering angle is held too long. SC must change steering angle when required. SG17
CA: Control Action (cf. Fig. 2), VDC: Vehicle Dynamics Controller, WRDC: Wheel Rotational Dynamics Controller, SC: Steering Controller

TABLE V
F UNCTIONAL S AFETY R EQUIREMENTS FOR ACTUATION S YSTEMS OF AUTOMATED V EHICLES

Component Type Causal Factor Functional Safety Requirement


Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Drive- Continuous and sufficient power supply for drive-internal sensors.
internal Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Brake- Continuous and sufficient power supply for brake-internal sensors.
internal Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Continued on next page

2196
Table V: Continued from previous page
Component Type Causal Factor Functional Safety Requirement

Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Steering- Continuous and sufficient power supply for steering-internal sensors.
internal Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Wheel Continuous and sufficient power supply for wheel motion sensors.
Motion Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized and compensated for.
Vehicle Continuous and sufficient power supply for vehicle motion sensors.
Motion Sensor Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensors Measurement inaccuracies Sufficient measurement accuracy for drive operation must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Inadequate or missing feedback Inadequate or missing feedback must be recognized.
Continuous and sufficient power supply for motion estimation.
Motion Feedback delays Updated feedback must be available in required cycle time and jitter.
Sensor Sufficient measurement accuracy for wheel rotational dynamics control and vehicle
Estimation Measurement inaccuracies
dynamics control must be ensured.
Inadequate operation Monitoring of operational state of drive-internal sensors and report to controller.
Component failure Electrical and mechanical design according to state of the art.
Monitoring of electrical and mechanical components and report to superordinate
controller.
Conflicting control actions Does not apply, only one controller.
Brake Monitoring of electrical and mechanical components and report to superordinate
Process Changes over time
Dynamics controller.
Unidentified or out-of-range Brake controller must recognize brakes operating beyond design limits and react
disturbances appropriately (e.g. failure state).
Process input missing or wrong Continuous and sufficient power supply for brake.
Component failure Electrical and mechanical design according to state of the art.
Monitoring of electrical and mechanical components and report to superordinate
controller.
Conflicting control actions Does not apply, only one controller.
Drive Monitoring of electrical and mechanical components and report to superordinate
Process Changes over time
Dynamics controller.
Unidentified or out-of-range Drive controller must recognize drive operating beyond design limits and react
disturbances appropriately (e.g. failure state).
Process input missing or wrong Continuous and sufficient power supply for drive.
Component failure Electrical and mechanical design according to state of the art.
Monitoring of electrical and mechanical components and report to superordinate
controller.
Conflicting control actions Does not apply, only one controller.
Steering Monitoring of electrical and mechanical components and report to superordinate
Process Changes over time
Dynamics controller.
Unidentified or out-of-range Steering controller must recognize steering operating beyond design limits and
disturbances react appropriately (e.g. failure state).
Process input missing or wrong Continuous and sufficient power supply for steering.
Component failure Design of suspension kinematics, wheel, and tires according to state of the art.
Monitoring of suspension kinematics, wheel, and tire as well as report to
superordinate controller.
Wheel and Conflicting control actions Exclusion of drive and brake actuation with different.
Tire Process Monitoring of suspension kinematics, wheel, and tire as well as report to
Changes over time
Dynamics superordinate controller.
Unidentified or out-of-range Brake and drive controller must recognize wheel operating beyond design limits
disturbances and react appropriately (e.g. failure state).
Process input missing or wrong Does not apply, no additional process input.
Component failure Considered with wheel and tire dynamics.
Control actions of the vehicle dynamics controller must target the same vehicle
Conflicting control actions
Overall motion.
Vehicle Process Changes over time Considered with wheel and tire dynamics.
Dynamics Unidentified or out-of-range Vehicle dynamics controller must recognize vehicle dynamics operating beyond
disturbances limits of handling and react appropriately.
Process input missing or wrong Does not apply, no additional process input.
Continued on next page

2197
Table V: Continued from previous page
Component Type Causal Factor Functional Safety Requirement

Control algorithm robust against uncertainties of the steering dynamics model and
Inadequate control algorithm
disturbances.
Process model inconsistent,
Sufficiently precise and validated steering dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Steering Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for steering controller.
Controller Actuator missing control action
Fail-operational design of steering controller.
Monitoring of operational state of steering controller and process and report to
superordinate controller.
Inadequate operation Fail-operational design of steering.
Delayed operation Operation of steering controller must be provided in required cycle time and jitter.
Control algorithm robust against uncertainties of the brake dynamics model and
Inadequate control algorithm
disturbances.
Process model inconsistent,
Sufficiently precise and validated brake dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Brake Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for brake controller.
Controller Actuator missing control action
Fail-operational design of brake controller.
Monitoring of operational state of brake controller and process and report to
superordinate controller.
Inadequate operation Fail-operational design of brake.
Delayed operation Operation of brake controller must be provided in required cycle time and jitter.
Control algorithm robust against uncertainties of the drive dynamics model and
Inadequate control algorithm
disturbances.
Process model inconsistent,
Sufficiently precise and validated drive dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Drive Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for drive controller.
Controller Actuator missing control action
Fail-operational design of drive controller.
Monitoring of operational state of drive controller and process and report to
superordinate controller.
Inadequate operation Fail-operational design of drive.
Delayed operation Operation of drive controller must be provided in required cycle time and jitter.
Control algorithm robust against uncertainties of the wheel rotational dynamics
Inadequate control algorithm
model and disturbances.
Fault-tolerant wheel rotational dynamics control algorithm.
Process model inconsistent,
Sufficiently precise and validated wheel rotational dynamics model.
incomplete, or incorrect
Wheel Process variables must comply with the physical process state.
Rotational Controller, Inappropriate, ineffective, or
Continuous and sufficient power supply for wheel rotational dynamics controller.
Dynamics Actuator missing control action
Controller Fail-operational design of wheel rotational dynamics controller.
Monitoring of operational state of wheel rotational dynamics controller and
process and report to superordinate controller.
Inadequate operation Covered by underlying control loops.
Operation of wheel rotational dynamics controller must be provided in required
Delayed operation
cycle time and jitter.
Control algorithm robust against uncertainties of the vehicle dynamics model and
Inadequate control algorithm
disturbances.
Fault-tolerant vehicle dynamics control algorithm.
Process model inconsistent,
Sufficiently precise and validated vehicle dynamics model.
incomplete, or incorrect
Process variables must comply with the physical process state.
Vehicle
Controller, Inappropriate, ineffective, or
Dynamics Continuous and sufficient power supply for vehicle dynamics controller.
Actuator missing control action
Controller
Fail-operational design of vehicle dynamics controller.
Monitoring of operational state of vehicle dynamics controller and process and
report to superordinate controller.
Inadequate operation Covered by underlying control loops.
Operation of vehicle dynamics controller must be provided in required cycle time
Delayed operation
and jitter.
Table concluded

2198

You might also like