RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    ISO 26262 기반 자율주행 차량의 Degradation Safety Mechanism 연구 = Research on the Degradation Safety Mechanism of Autonomous Driving Vehicles Based on ISO 26262

    한글로보기

    https://www.riss.kr/link?id=T17278180

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    As the future automobile market begins to transition to software-defined vehicles, autonomous driving systems are becoming a key element. Therefore, in order to continue to increase the complexity of electric/electronic systems in vehicles and prevent accidents due to system defects, research on ISO 26262-based safety mechanisms is becoming more prominent. Currently, most vehicles use Fail-Safe in the event of a system defect. Fail-Safe is a method of immediately deactivating the system or handing over control to the driver when a defect occurs. However, for advanced autonomous driving technology, fail-operational research that allows the system to continue operating even in case of a defect is active. In order to implement fail-operational, hardware and software redundancy strategies are essential, and through this, even if a single defect occurs, the function of the system is maintained using hardware and software that operates normally.
    However, if the Redundancy strategy is not possible due to multiple defects, the system can perform functions, but there is no means to determine the defects. As a result, a situation where hardware and software are not trusted can occur and a dangerous state can be reached. Therefore, in situations where the Redundancy strategy is impossible, a strategy is needed to secure safety through a safety mechanism. Degradation Mode is an important strategy for satisfying this situation and autonomous driving above SAE Level 3, but the applied research is insufficient. In addition, studies considering the driving situation of the lateral vehicle when performing the Minimal Risk Maneuver, which is referred to in Degradation Mode, are insufficient.
    In this paper, the autonomous driving system was simulated with Adaptive Cruise Control and Lane Following Assistant using sensors, and the risk of longitudinal autonomous driving systems was analyzed and evaluated based on ISO 26262 Part 3 and 4. In addition, a degradation safety mechanism was developed to improve the reliability of the developed autonomous driving system. Item Definition, Hazard Analysis and Risk Assessment, Functional Safety Requirement, and Technical Safety Requirement were conducted according to ISO 26262 Part 3 and 4 before developing the safety mechanism of the autonomous driving system. Based on the requirements, a Degradation safety mechanism was developed, such as speed deceleration, MRM performance after a certain period of time, and shoulder stop in situations where the Redundancy strategy was not possible. MRM was performed by calculating the safety area based on Time to Collision and Relative Speed using front/back sensors before and after MRM was performed. In addition, MRM was performed using desired yawrate-based Rear Wheel Steering for path followability.
    To verify the Degradation safety mechanism, this study used Mathworks' MATLAB/Simulink and IPG's CarMaker to perform Model-in-the-Loop Simulation verification. To determine the effectiveness of the Degradation safety mechanism, it was verified in scenarios such as front vehicle stop, front/rear vehicle reduction/acceleration in single sensor fault situations and no Redundancy strategy, and a safety mechanism for expanding the response area of the autonomous driving system is proposed.
    번역하기

    As the future automobile market begins to transition to software-defined vehicles, autonomous driving systems are becoming a key element. Therefore, in order to continue to increase the complexity of electric/electronic systems in vehicles and prevent...

    As the future automobile market begins to transition to software-defined vehicles, autonomous driving systems are becoming a key element. Therefore, in order to continue to increase the complexity of electric/electronic systems in vehicles and prevent accidents due to system defects, research on ISO 26262-based safety mechanisms is becoming more prominent. Currently, most vehicles use Fail-Safe in the event of a system defect. Fail-Safe is a method of immediately deactivating the system or handing over control to the driver when a defect occurs. However, for advanced autonomous driving technology, fail-operational research that allows the system to continue operating even in case of a defect is active. In order to implement fail-operational, hardware and software redundancy strategies are essential, and through this, even if a single defect occurs, the function of the system is maintained using hardware and software that operates normally.
    However, if the Redundancy strategy is not possible due to multiple defects, the system can perform functions, but there is no means to determine the defects. As a result, a situation where hardware and software are not trusted can occur and a dangerous state can be reached. Therefore, in situations where the Redundancy strategy is impossible, a strategy is needed to secure safety through a safety mechanism. Degradation Mode is an important strategy for satisfying this situation and autonomous driving above SAE Level 3, but the applied research is insufficient. In addition, studies considering the driving situation of the lateral vehicle when performing the Minimal Risk Maneuver, which is referred to in Degradation Mode, are insufficient.
    In this paper, the autonomous driving system was simulated with Adaptive Cruise Control and Lane Following Assistant using sensors, and the risk of longitudinal autonomous driving systems was analyzed and evaluated based on ISO 26262 Part 3 and 4. In addition, a degradation safety mechanism was developed to improve the reliability of the developed autonomous driving system. Item Definition, Hazard Analysis and Risk Assessment, Functional Safety Requirement, and Technical Safety Requirement were conducted according to ISO 26262 Part 3 and 4 before developing the safety mechanism of the autonomous driving system. Based on the requirements, a Degradation safety mechanism was developed, such as speed deceleration, MRM performance after a certain period of time, and shoulder stop in situations where the Redundancy strategy was not possible. MRM was performed by calculating the safety area based on Time to Collision and Relative Speed using front/back sensors before and after MRM was performed. In addition, MRM was performed using desired yawrate-based Rear Wheel Steering for path followability.
    To verify the Degradation safety mechanism, this study used Mathworks' MATLAB/Simulink and IPG's CarMaker to perform Model-in-the-Loop Simulation verification. To determine the effectiveness of the Degradation safety mechanism, it was verified in scenarios such as front vehicle stop, front/rear vehicle reduction/acceleration in single sensor fault situations and no Redundancy strategy, and a safety mechanism for expanding the response area of the autonomous driving system is proposed.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    미래 자동차 시장은 Software-Defined Vehicle로 전환을 시작하면서 자율주행 시스템이 핵심 요소로 자리 잡고 있다. 따라서 차량 내 전기/전자 시스템의 복잡성이 계속 증가하고 시스템의 결함으로 인한 사고방지를 위해 ISO 26262(자동차 기능 안전) 기반 안전 메커니즘 연구가 더욱 부각되고 있다. 현재 대부분의 차량은 시스템 결함 발생 시 Fail-Safe를 사용하고 있다. Fail-Safe는 결함이 발생하면 즉시 시스템을 비활성화하거나 운전자에게 제어권을 넘기는 방식이다. 그러나, 고도화된 자율주행 기술을 위해 결함 상황에서도 시스템이 계속 작동할 수 있는 Fail-Operational 연구가 활발하다. Fail-Operational을 구현하기 위해 하드웨어 및 소프트웨어 Redundancy 전략이 필수적이고, 이를 통해 단일 결함이 발생하더라도 정상 작동하는 하드웨어 및 소프트웨어를 사용하여 시스템의 기능을 유지한다.
    하지만, 다중 결함으로 인해 Redundancy 전략이 불가능한 경우 시스템은 기능을 수행할 순 있지만 결함을 판단할 수단이 없다. 이로 인해, 하드웨어 및 소프트웨어를 신뢰할 수 없는 상황이 발생해 위험 상태에 도달할 수 있다. 따라서, Redundancy 전략이 불가능한 상황에서 안전 메커니즘을 통해 안전성 확보를 위한 전략이 필요하다. 이러한 상황을 만족하고 SAE Level 3 이상의 자율주행을 위해 기능 저하 모드(Degradation Mode)는 중요한 전략이지만 적용된 연구가 부족하다. 또한 Degradation Mode에 언급되는 MRM(Minimal Risk Maneuver) 수행 시 측방 차량의 주행 상황을 고려한 연구가 부족하다.
    본 논문에서는 센서를 활용하여 적응형 크루즈 컨트롤(Adaptive Cruise Control, ACC) 및 차로 유지 보조(Lane Following Assist, LFA)로 자율주행 시스템을 모사하였고 ISO 26262 Part 3, 4를 기반으로 종 방향 자율주행 시스템의 위험 분석 및 평가하였다. 또한, 개발한 자율주행 시스템의 신뢰성 향상을 위해 Degradation 안전 메커니즘을 개발하였다. 자율주행 시스템의 안전 메커니즘을 개발하기 전 ISO 26262 Part 3, 4에 따라 아이템 정의(Item Definition), 위험원 분석 및 위험 평가(Hazard Analysis and Risk Assessment, HARA), 기능 안전 요구사항(Functional Safety Requirement, FSR), 기술 안전 요구사항(Technical Safety Requirement, TSR) 등을 진행하였다. 요구사항을 기반으로 Redundancy 전략 가능 상황에서 기능을 유지하고 Redundancy 전략이 불가능한 상황에서 속도 감속, 일정 시간 이후 MRM 수행, 갓길 정차 등 Degradation 안전 메커니즘을 개발하였다. MRM 수행 전 전/후측방 센서를 활용하여 충돌 시간(Time to Collision, TTC) 및 상대 속도 기반의 안전 영역을 계산하여 MRM 수행하였다. 또한, 경로 추종성을 위해 목표 요 레이트(ψ ̇_des) 기반 후륜 조향(Rear Wheel Steering, RWS)을 사용하여 MRM을 수행하였다.
    본 연구는 Degradation 안전 메커니즘을 검증하기 위해 Mathworks 사의 MATLAB/Simulink와 IPG 사의 CarMaker를 활용하여 MILS (Model-in-the-Loop Simulation) 검증을 수행하였다. Degradation 안전 메커니즘의 유효성 판단을 위해 센서 단일 결함 상황 및 Redundancy 전략 불가 상황에서 전방 차량 정지, 전/후측방 차량 감/가속 등의 시나리오에서 검증했으며 자율주행 시스템의 대응 영역 확장을 위한 안전 메커니즘을 제안한다.
    번역하기

    미래 자동차 시장은 Software-Defined Vehicle로 전환을 시작하면서 자율주행 시스템이 핵심 요소로 자리 잡고 있다. 따라서 차량 내 전기/전자 시스템의 복잡성이 계속 증가하고 시스템의 결함으...

    미래 자동차 시장은 Software-Defined Vehicle로 전환을 시작하면서 자율주행 시스템이 핵심 요소로 자리 잡고 있다. 따라서 차량 내 전기/전자 시스템의 복잡성이 계속 증가하고 시스템의 결함으로 인한 사고방지를 위해 ISO 26262(자동차 기능 안전) 기반 안전 메커니즘 연구가 더욱 부각되고 있다. 현재 대부분의 차량은 시스템 결함 발생 시 Fail-Safe를 사용하고 있다. Fail-Safe는 결함이 발생하면 즉시 시스템을 비활성화하거나 운전자에게 제어권을 넘기는 방식이다. 그러나, 고도화된 자율주행 기술을 위해 결함 상황에서도 시스템이 계속 작동할 수 있는 Fail-Operational 연구가 활발하다. Fail-Operational을 구현하기 위해 하드웨어 및 소프트웨어 Redundancy 전략이 필수적이고, 이를 통해 단일 결함이 발생하더라도 정상 작동하는 하드웨어 및 소프트웨어를 사용하여 시스템의 기능을 유지한다.
    하지만, 다중 결함으로 인해 Redundancy 전략이 불가능한 경우 시스템은 기능을 수행할 순 있지만 결함을 판단할 수단이 없다. 이로 인해, 하드웨어 및 소프트웨어를 신뢰할 수 없는 상황이 발생해 위험 상태에 도달할 수 있다. 따라서, Redundancy 전략이 불가능한 상황에서 안전 메커니즘을 통해 안전성 확보를 위한 전략이 필요하다. 이러한 상황을 만족하고 SAE Level 3 이상의 자율주행을 위해 기능 저하 모드(Degradation Mode)는 중요한 전략이지만 적용된 연구가 부족하다. 또한 Degradation Mode에 언급되는 MRM(Minimal Risk Maneuver) 수행 시 측방 차량의 주행 상황을 고려한 연구가 부족하다.
    본 논문에서는 센서를 활용하여 적응형 크루즈 컨트롤(Adaptive Cruise Control, ACC) 및 차로 유지 보조(Lane Following Assist, LFA)로 자율주행 시스템을 모사하였고 ISO 26262 Part 3, 4를 기반으로 종 방향 자율주행 시스템의 위험 분석 및 평가하였다. 또한, 개발한 자율주행 시스템의 신뢰성 향상을 위해 Degradation 안전 메커니즘을 개발하였다. 자율주행 시스템의 안전 메커니즘을 개발하기 전 ISO 26262 Part 3, 4에 따라 아이템 정의(Item Definition), 위험원 분석 및 위험 평가(Hazard Analysis and Risk Assessment, HARA), 기능 안전 요구사항(Functional Safety Requirement, FSR), 기술 안전 요구사항(Technical Safety Requirement, TSR) 등을 진행하였다. 요구사항을 기반으로 Redundancy 전략 가능 상황에서 기능을 유지하고 Redundancy 전략이 불가능한 상황에서 속도 감속, 일정 시간 이후 MRM 수행, 갓길 정차 등 Degradation 안전 메커니즘을 개발하였다. MRM 수행 전 전/후측방 센서를 활용하여 충돌 시간(Time to Collision, TTC) 및 상대 속도 기반의 안전 영역을 계산하여 MRM 수행하였다. 또한, 경로 추종성을 위해 목표 요 레이트(ψ ̇_des) 기반 후륜 조향(Rear Wheel Steering, RWS)을 사용하여 MRM을 수행하였다.
    본 연구는 Degradation 안전 메커니즘을 검증하기 위해 Mathworks 사의 MATLAB/Simulink와 IPG 사의 CarMaker를 활용하여 MILS (Model-in-the-Loop Simulation) 검증을 수행하였다. Degradation 안전 메커니즘의 유효성 판단을 위해 센서 단일 결함 상황 및 Redundancy 전략 불가 상황에서 전방 차량 정지, 전/후측방 차량 감/가속 등의 시나리오에서 검증했으며 자율주행 시스템의 대응 영역 확장을 위한 안전 메커니즘을 제안한다.

    더보기

    목차 (Table of Contents)

    • 제 1 장 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구 동향 및 목적 2
    • 제 2 장 Vehicle Modeling 5
    • 2.1 Carmaker 5
    • 제 1 장 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구 동향 및 목적 2
    • 제 2 장 Vehicle Modeling 5
    • 2.1 Carmaker 5
    • 2.2 Longitudinal Vehicle Model 7
    • 2.3 Bicycle Model 9
    • 제 3 장 자율주행 및 샤시 시스템 12
    • 3.1 초기 제어 아키텍처 12
    • 3.2 종 방향 제어기 13
    • 3.2.1 ACC 제어기 13
    • 3.3 횡 방향 제어기 16
    • 3.3.1 LFA 제어기 16
    • 3.3.2 RWS 제어기 18
    • 제 4 장 ISO 26262 기반 기능 안전 분석 20
    • 4.1 ISO 26262 Part 3,4 개요 20
    • 4.2 아이템 정의 21
    • 4.3 위험원 분석 및 위험 평가 22
    • 4.4 안전 목표 위배 요인 분석 26
    • 4.5 기능/기술 안전 요구사항 도출 28
    • 제 5 장 Degradation 안전 메커니즘 개발 30
    • 5.1 Degradation 안전 메커니즘 개요. 30
    • 5.2 Object 센서 Triple Module Redundancy 32
    • 5.3 차속 센서 Analytical Redundancy 33
    • 5.3 Degradation Phase 36
    • 제 6 장 Degradation 안전 메커니즘 검증 39
    • 6.1 TestCase 1 : 차속 센서 오프셋 Phase 1 천이 41
    • 6.2 TestCase 2 : Object 센서 오프셋 Phase 1 천이 42
    • 6.3 TestCase 3 : Object 센서 손실 Phase 1 천이 43
    • 6.4 TestCase 4 : 차속 센서 손실 Phase A 천이 44
    • 6.5 TestCase 5 : Object Redundancy 센서 손실 Phase A 천이 45
    • 6.6 TestCase 6 : Phase B MRM 수행 검증 1 46
    • 6.7 TestCase 7 : Phase B MRM 수행 검증 2 48
    • 6.8 TestCase 8 : Degradation Phase 검증 50
    • 6.9 Extended TestCase : 주차 센서를 이용한 Phase B 수행 검증 52
    • 제 7 장 결론 54
    • References 56
    • Abstract 59
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼