A Safety Argumentation for Fail-Operational Automotive Systems in Compliance with ISO 26262

Tobias Schmid, Stefanie Schraufstetter, S. Wagner, Dominik Hellhake
{"title":"A Safety Argumentation for Fail-Operational Automotive Systems in Compliance with ISO 26262","authors":"Tobias Schmid, Stefanie Schraufstetter, S. Wagner, Dominik Hellhake","doi":"10.1109/ICSRS48664.2019.8987656","DOIUrl":null,"url":null,"abstract":"For highly automated driving, fail-operational driving systems are indispensable to prevent hazardous situations in case of an E/E failure. That requires redundant system design and enhanced safety analysis for ensuring fault tolerance and further operation. Existing work addresses attributes of fail-operational systems relevant for safety, however the sufficiency of safety analysis has not been investigated. We therefore aim to identify relevant safety aspects for fail-operational systems in ISO 26262 which require analysis to ensure compliance. Further we deduce a fault model for a fail-operational driving system containing the relevant failure modes. By consolidating the fault-model and ISO 26262 into a safety argumentation using the goal structure notation we provide a safety argumentation for a fail-operational driving system sufficient according to ISO 26262. Whereas conventional fail-silent systems can be analysed on the sub-system level, fail-operational systems requires overarching analysis on the system level. We therefore determine objectives of this analysis, structure those according to the necessary level and determine the relations given by mutual contributions. With our work, we provide a framework for safety argumentation of a fail-operational driving system in compliance with ISO 26262 regarding safety analysis.","PeriodicalId":430931,"journal":{"name":"2019 4th International Conference on System Reliability and Safety (ICSRS)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2019-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 4th International Conference on System Reliability and Safety (ICSRS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSRS48664.2019.8987656","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

For highly automated driving, fail-operational driving systems are indispensable to prevent hazardous situations in case of an E/E failure. That requires redundant system design and enhanced safety analysis for ensuring fault tolerance and further operation. Existing work addresses attributes of fail-operational systems relevant for safety, however the sufficiency of safety analysis has not been investigated. We therefore aim to identify relevant safety aspects for fail-operational systems in ISO 26262 which require analysis to ensure compliance. Further we deduce a fault model for a fail-operational driving system containing the relevant failure modes. By consolidating the fault-model and ISO 26262 into a safety argumentation using the goal structure notation we provide a safety argumentation for a fail-operational driving system sufficient according to ISO 26262. Whereas conventional fail-silent systems can be analysed on the sub-system level, fail-operational systems requires overarching analysis on the system level. We therefore determine objectives of this analysis, structure those according to the necessary level and determine the relations given by mutual contributions. With our work, we provide a framework for safety argumentation of a fail-operational driving system in compliance with ISO 26262 regarding safety analysis.
符合ISO 26262的故障操作汽车系统的安全论证
对于高度自动化驾驶,故障操作驾驶系统是必不可少的,以防止发生E/E故障时的危险情况。这需要冗余的系统设计和增强的安全分析,以确保容错性和进一步的运行。现有的工作涉及与安全有关的故障操作系统的属性,但是安全分析的充分性尚未得到调查。因此,我们的目标是确定ISO 26262中故障操作系统的相关安全方面,需要分析以确保合规性。进一步推导了包含相关失效模式的故障运行驱动系统的故障模型。通过使用目标结构符号将故障模型和ISO 26262整合成一个安全论证,我们提供了一个充分符合ISO 26262的故障运行驱动系统的安全论证。传统的故障沉默系统可以在子系统级别进行分析,而故障运行系统则需要在系统级别进行总体分析。因此,我们确定这一分析的目标,根据必要的水平组织这些目标,并确定相互贡献所产生的关系。通过我们的工作,我们为符合ISO 26262安全分析的故障驾驶系统的安全论证提供了一个框架。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信