Skip to main content
QUICK REVIEW

[论文解读] Using STPA in Compliance with ISO 26262 for Developing a Safe Architecture for Fully Automated Vehicles

Asim Abdulkhaleq, Stefan Wagner|arXiv (Cornell University)|Mar 10, 2017
Safety Systems Engineering in Autonomy参考文献 7被引用 9
一句话总结

本文提出将系统理论过程分析(STPA)集成到ISO 26262安全生命周期中,以增强全自动驾驶车辆的危险分析。通过在早期概念阶段应用STPA,作者识别出超越部件故障的系统级危险——共发现24起事故、176项危险、27项不安全控制行为及129种不安全场景,证明了STPA在推导详细安全约束并扩展ISO 26262安全范围方面的有效性。

ABSTRACT

Safety has become of paramount importance in the development lifecycle of the modern automobile systems. However, the current automotive safety standard ISO 26262 does not specify clearly the methods for safety analysis. Different methods are recommended for this purpose. FTA (Fault Tree Analysis) and FMEA (Failure Mode and Effects Analysis) are used in the most recent ISO 26262 applications to identify component failures, errors and faults that lead to specific hazards (in the presence of faults). However, these methods are based on reliability theory, and they are not adequate to address new hazards caused by dysfunctional component interactions, software failure or human error. A holistic approach was developed called STPA (Systems-Theoretic Process Analysis) which addresses more types of hazards and treats safety as a dynamic control problem rather than an individual component failure. STPA also addresses types of hazardous causes in the absence of failure. Accordingly, there is a need for investigating hazard analysis techniques like STPA. In this paper, we present a concept on how to use STPA to extend the safety scope of ISO 26262 and support the Hazard Analysis and Risk Assessments (HARA) process. We applied the proposed concept to a current project of a fully automated vehicle at Continental. As a result, we identified 24 system- level accidents, 176 hazards, 27 unsafe control actions, and 129 unsafe scenarios. We conclude that STPA is an effective and efficient approach to derive detailed safety constraints. STPA can support the functional safety engineers to evaluate the architectural design of fully automated vehicles and build the functional safety concept.

研究动机与目标

  • 为解决ISO 26262在识别由功能失调的部件交互、软件故障或人为错误引发的危险方面的局限性。
  • 通过引入STPA作为补充的危险分析方法,扩展ISO 26262的安全范围。
  • 为在早期概念阶段定义系统项目并推导安全约束提供系统化方法。
  • 支持功能安全工程师制定详细的安全需求及自动驾驶车辆架构的功能安全概念。

提出的方法

  • 应用STPA步骤0,在概念开发前定义系统项目并建立基础安全约束。
  • 使用STPA步骤1,基于控制结构和目标违反情况,识别系统级事故和不安全控制行为。
  • 采用STPA步骤2,建立受控过程的模型,并为每项不安全控制行为推导因果场景。
  • 将HARA中派生的操作情境和模式映射到STPA流程模型中,以丰富场景分析。
  • 将STPA结果作为输入整合到HARA过程中,以增强危险识别和安全约束推导。
  • 利用STPA-HARA联合方法推导详细的安全需求,并支持架构级安全评估。

实验结果

研究问题

  • RQ1如何将STPA集成到ISO 26262安全生命周期中,以将危险分析扩展至超越部件故障的范围?
  • RQ2STPA识别出的危险类型中,有哪些是ISO 26262传统FMEA和FTA方法可能遗漏的?
  • RQ3STPA如何支持在早期概念阶段定义系统项目和安全约束?
  • RQ4与仅使用ISO 26262的HARA相比,STPA在多大程度上提升了安全需求的完整性和深度?
  • RQ5如何系统性地对齐STPA与HARA,以支持功能安全概念的开发?

主要发现

  • STPA在全自动驾驶车辆项目中识别出24起系统级事故和176项危险,显著扩展了传统ISO 26262方法的危险识别范围。
  • 该方法揭示了27项不安全控制行为和129种不安全场景,其中许多源于非故障原因,如软件错误和部件交互。
  • STPA支持推导出详细的安全约束,有助于架构级安全评估和功能安全概念开发。
  • STPA与HARA的整合为在开发生命周期早期定义系统项目和建立安全需求提供了系统性指导。
  • 结果表明,STPA能有效应对动态安全问题,并通过识别在无部件故障情况下的危险,补充了ISO 26262。
  • 本研究证实了STPA在提升复杂自动驾驶车辆系统功能安全工程方面的价值。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。