As the future automobile market begins to transition to software-defined vehicles, autonomous driving systems are becoming a key element. Therefore, in order to continue to increase the complexity of electric/electronic systems in vehicles and prevent...
As the future automobile market begins to transition to software-defined vehicles, autonomous driving systems are becoming a key element. Therefore, in order to continue to increase the complexity of electric/electronic systems in vehicles and prevent accidents due to system defects, research on ISO 26262-based safety mechanisms is becoming more prominent. Currently, most vehicles use Fail-Safe in the event of a system defect. Fail-Safe is a method of immediately deactivating the system or handing over control to the driver when a defect occurs. However, for advanced autonomous driving technology, fail-operational research that allows the system to continue operating even in case of a defect is active. In order to implement fail-operational, hardware and software redundancy strategies are essential, and through this, even if a single defect occurs, the function of the system is maintained using hardware and software that operates normally.
However, if the Redundancy strategy is not possible due to multiple defects, the system can perform functions, but there is no means to determine the defects. As a result, a situation where hardware and software are not trusted can occur and a dangerous state can be reached. Therefore, in situations where the Redundancy strategy is impossible, a strategy is needed to secure safety through a safety mechanism. Degradation Mode is an important strategy for satisfying this situation and autonomous driving above SAE Level 3, but the applied research is insufficient. In addition, studies considering the driving situation of the lateral vehicle when performing the Minimal Risk Maneuver, which is referred to in Degradation Mode, are insufficient.
In this paper, the autonomous driving system was simulated with Adaptive Cruise Control and Lane Following Assistant using sensors, and the risk of longitudinal autonomous driving systems was analyzed and evaluated based on ISO 26262 Part 3 and 4. In addition, a degradation safety mechanism was developed to improve the reliability of the developed autonomous driving system. Item Definition, Hazard Analysis and Risk Assessment, Functional Safety Requirement, and Technical Safety Requirement were conducted according to ISO 26262 Part 3 and 4 before developing the safety mechanism of the autonomous driving system. Based on the requirements, a Degradation safety mechanism was developed, such as speed deceleration, MRM performance after a certain period of time, and shoulder stop in situations where the Redundancy strategy was not possible. MRM was performed by calculating the safety area based on Time to Collision and Relative Speed using front/back sensors before and after MRM was performed. In addition, MRM was performed using desired yawrate-based Rear Wheel Steering for path followability.
To verify the Degradation safety mechanism, this study used Mathworks' MATLAB/Simulink and IPG's CarMaker to perform Model-in-the-Loop Simulation verification. To determine the effectiveness of the Degradation safety mechanism, it was verified in scenarios such as front vehicle stop, front/rear vehicle reduction/acceleration in single sensor fault situations and no Redundancy strategy, and a safety mechanism for expanding the response area of the autonomous driving system is proposed.