A Safety Argumentation for Fail-Operational Automotive Systems in Compliance with ISO 26262

Tobias Schmid, Stefanie Schraufstetter, S. Wagner, Dominik Hellhake
{"title":"A Safety Argumentation for Fail-Operational Automotive Systems in Compliance with ISO 26262","authors":"Tobias Schmid, Stefanie Schraufstetter, S. Wagner, Dominik Hellhake","doi":"10.1109/ICSRS48664.2019.8987656","DOIUrl":null,"url":null,"abstract":"For highly automated driving, fail-operational driving systems are indispensable to prevent hazardous situations in case of an E/E failure. That requires redundant system design and enhanced safety analysis for ensuring fault tolerance and further operation. Existing work addresses attributes of fail-operational systems relevant for safety, however the sufficiency of safety analysis has not been investigated. We therefore aim to identify relevant safety aspects for fail-operational systems in ISO 26262 which require analysis to ensure compliance. Further we deduce a fault model for a fail-operational driving system containing the relevant failure modes. By consolidating the fault-model and ISO 26262 into a safety argumentation using the goal structure notation we provide a safety argumentation for a fail-operational driving system sufficient according to ISO 26262. Whereas conventional fail-silent systems can be analysed on the sub-system level, fail-operational systems requires overarching analysis on the system level. We therefore determine objectives of this analysis, structure those according to the necessary level and determine the relations given by mutual contributions. With our work, we provide a framework for safety argumentation of a fail-operational driving system in compliance with ISO 26262 regarding safety analysis.","PeriodicalId":430931,"journal":{"name":"2019 4th International Conference on System Reliability and Safety (ICSRS)","volume":"183 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 4th International Conference on System Reliability and Safety (ICSRS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSRS48664.2019.8987656","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

For highly automated driving, fail-operational driving systems are indispensable to prevent hazardous situations in case of an E/E failure. That requires redundant system design and enhanced safety analysis for ensuring fault tolerance and further operation. Existing work addresses attributes of fail-operational systems relevant for safety, however the sufficiency of safety analysis has not been investigated. We therefore aim to identify relevant safety aspects for fail-operational systems in ISO 26262 which require analysis to ensure compliance. Further we deduce a fault model for a fail-operational driving system containing the relevant failure modes. By consolidating the fault-model and ISO 26262 into a safety argumentation using the goal structure notation we provide a safety argumentation for a fail-operational driving system sufficient according to ISO 26262. Whereas conventional fail-silent systems can be analysed on the sub-system level, fail-operational systems requires overarching analysis on the system level. We therefore determine objectives of this analysis, structure those according to the necessary level and determine the relations given by mutual contributions. With our work, we provide a framework for safety argumentation of a fail-operational driving system in compliance with ISO 26262 regarding safety analysis.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
符合ISO 26262的故障操作汽车系统的安全论证
对于高度自动化驾驶,故障操作驾驶系统是必不可少的,以防止发生E/E故障时的危险情况。这需要冗余的系统设计和增强的安全分析,以确保容错性和进一步的运行。现有的工作涉及与安全有关的故障操作系统的属性,但是安全分析的充分性尚未得到调查。因此,我们的目标是确定ISO 26262中故障操作系统的相关安全方面,需要分析以确保合规性。进一步推导了包含相关失效模式的故障运行驱动系统的故障模型。通过使用目标结构符号将故障模型和ISO 26262整合成一个安全论证,我们提供了一个充分符合ISO 26262的故障运行驱动系统的安全论证。传统的故障沉默系统可以在子系统级别进行分析,而故障运行系统则需要在系统级别进行总体分析。因此,我们确定这一分析的目标,根据必要的水平组织这些目标,并确定相互贡献所产生的关系。通过我们的工作,我们为符合ISO 26262安全分析的故障驾驶系统的安全论证提供了一个框架。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Towards a Model-centric Approach for Developing Dependable Smart Grid Applications Reliability of Systems with Simultaneous and Consecutive Failures Interval Type-2 Fuzzy Reliability Modeling for Recycling Facility Condition Based Maintenance for Industrial Labeling Machine Accellerating PRISM Validation of Vehicle Platooning Through Machine Learning
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1