汽车功能安全理论基础

从事功能安全工作以来,未有系统性地撰写一些文章,一是懒二是没找到合适的地儿;准备从这里开启、写点儿小文,有兴趣的读者能一块儿盘盘道,不错!挺好!

3.141
safety measure
(2018)
activity or technical solution to avoid or control systematic failures (3.164) and to detect or control random hardware failures (3.118), or mitigate their harmful effects
Note 1 to entry: Safety measures include safety mechanisms (3.142).
EXAMPLE FMEA, or software without the use of global variables.
1.110
safety measure
(2011)
activity or technical solution to avoid or control systematic failures (1.130) and to detect random hardware failures (1.92) or control random hardware failures, or mitigate their harmful effects
NOTE 1 Examples of safety measures are FMEA and software without the use of global variables.
NOTE 2 Safety measures include safety mechanisms (1.111).
安全措施的描述,两个版本没有区别,仅control的用词先后而已,对于这个control 随机硬件失效,还是有点模棱两可的,或mitigate,tolerate都叫control,关于什么是mitigate和tolerate待议;
safety measure == 活动+安全机制(技术路径),activity + safety mechanism,活动即避免系统性失效的流程,诸如安全化的设计流程,推荐化的设计方案,推荐化的验证措施等等,技术路径即探测随机硬件故障发生与否以及发生后的reaction,技术路径具有on duty的特性。
3.142
safety mechanism
(2018)
technical solution implemented by E/E functions or elements (3.41), or by other technologies (3.105), to detect and mitigate or tolerate faults (3.54) or control or avoid failures (3.50) in order to maintain intended functionality (3.83) or achieve or maintain a safe state (3.131)
Note 1 to entry: Safety mechanisms are implemented within the item (3.84) to prevent faults (3.54) from leading to single-point failures (3.155) and to prevent faults (3.54) from being latent faults (3.85).
Note 2 to entry: The safety mechanism is either:
a) able to transition to, or maintain the item (3.84) in a safe state (3.131), or
b) able to alert the driver such that the driver is expected to control the effect of the failure (3.50), as defined in
the functional safety concept (3.68).
1.111
safety mechanism
(2011)
technical solution implemented by E/E functions or elements (1.32), or by other technologies (1.84), to detect faults (1.42) or control failures (1.39) in order to achieve or maintain a safe state (1.102)
NOTE 1 Safety mechanisms are implemented within the item (1.69) to prevent faults from leading to single-point failures (1.121) or to reduce residual failures and to prevent faults from being latent.
NOTE 2 The safety mechanism is either
a) able to transition to, or maintain, the item in a safe state, or
b) able to alert the driver such that the driver is expected to control the effect of the failure (1.39),as defined in the functional safety concept (1.52).
两个版本对于安全机制的描述略有不同,新版增加了对于故障falut的mitigate和tolerate以及对于后续reaction的一种新增的模式即intended functionality,mitigate 和tolerate是对于detect的适当补充,毕竟detect之后都会做这些事情,intended functionality是为了马上要颁布的ISO 21448(SOTIF预期功能安全)做一个铺垫,即功能安全或者汽车功能安全ISO26262解决的问题为 when fail ,fail safe 而ISO 21448 所强调的是when fail ,fail operational(NOT JUST SHUT DOWN AND ALERTING) ,在26262保障安全的前提下执行21448使其更可操enhance availability of a vehicle when malfunctioning
安全机制强调实时性,在故障产生时探测到,然后reaction以不让其产生failure或者是当failure产生时,进行相应的控制措施,不让这个failure 造成harmful effects;
REACTION:在26262里定义的安全机制就是shut down + 报警(源于61508的安全concept),因为26262顶多用到辅助驾驶,对于自动驾驶26262并不适用;
DETECTION: 探测随机硬件故障中的单点故障,探测随机硬件故障中的潜在故障;单点故障往往在很短的时间内应被探测出来,潜在故障应在一个汽车周期里被探测出来;一般地,单点故障所谓很短的时间应参考FTTI,fault tolerate time interval,进行设计,而汽车周期一般乘用车一小时,商用车10小时;关于FTTI与SM的时间需要待详细议论,因为这个是一个FuSa的核心问题。

safety mechanism , technical solution implemented by EE or other technology to detect/mitigate/tolerate FAULTS or avoid/control FAILURES in order to maintain intended functionality or achieve safe state
safety measure ,activity or technical solution to avoid systematic failure or control random HW failures ,or mitigate both above failures’ effects.
/
3.23
confirmation measure

confirmation review (3.24), audit (3.5) or assessment (3.4) concerning functional safety (3.67)
3.24
confirmation review

confirmation that a work product (3.185) provides sufficient and convincing evidence of their contribution to the achievement of functional safety (3.67) considering the corresponding objectives
and requirements of ISO 26262
Note 1 to entry: A complete list of confirmation reviews is given in ISO 26262-2.

/
Confirmation measure 认可措施
3.23
confirmation measure(2018)
confirmation review (3.24), audit (3.5) or assessment (3.4) concerning functional safety (3.67)
1.17
confirmation measure
(2011)
confirmation review (1.18), audit (1.5) or assessment (1.4) concerning functional safety (1.51)
Nothing is changed between version 2011 and version 2018 for the definition of confirmation measure

confirmation review(2011)
confirmation that a work product meets the requirements of ISO 26262 with the required level of independence (1.61) of the reviewer
NOTE 1 A complete list of confirmation reviews is given in ISO 26262-2.
NOTE 2 The goal of confirmation reviews is to ensure compliance with ISO 26262.
3.24
confirmation review
(2018)
confirmation that a work product (3.185) provides sufficient and convincing evidence of their contribution to the achievement of functional safety (3.67) considering the corresponding objectives
and requirements of ISO 26262
Note 1 to entry: A complete list of confirmation reviews is given in ISO 26262-2.
Note 2 to entry: The goal of confirmation reviews is to ensure compliance with the ISO 26262 series of standards.

Description of meets the requirements is took the place by the description of provide sufficient evidence ,which is more concessions
So for the easy understanding of definition of conception above,to conclude
confirmation measure: confirmation review + audit+assessment
confirmation review: if WP meet requirements?
audit: does the process be followed?
assessment: did requirements and process be complied?
/
safe state(2018)
operating mode (3.102), in case of a failure (3.50), of an item (3.84) without an unreasonable level of risk (3.128)
Note 1 to entry: See Figure 5.
Note 2 to entry: While normal operation can be considered safe, the definition of safe state is only in the case of failure (3.50) in the context of the ISO 26262 series of standards.
EXAMPLE Switched-off mode (for systems (3.163) that are not fault tolerant).
safe state(2011)
operating mode (1.81) of an item (1.69) without an unreasonable level of risk (1.99)
EXAMPLE Intended operating mode; degraded operating mode; switched-off mode.

New definition of safe state emphasize safe state is in the case of a failure occuring,normal working condition is no longer account in safe state.

在这里插入图片描述

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值