Run-Time Risk Mitigation in Automated Vehicles: A Model for Studying Preparatory Steps

09/08/2017
by   Mario Gleirscher, et al.
0

We assume that autonomous or highly automated driving (AD) will be accompanied by tough assurance obligations exceeding the requirements of even recent revisions of ISO 26262 or SOTIF. Hence, automotive control and safety engineers have to (i) comprehensively analyze the driving process and its control loop, (ii) identify relevant hazards stemming from this loop, (iii) establish feasible automated measures for the effective mitigation of these hazards or the alleviation of their consequences. By studying an example, this article investigates some achievements in the modeling for the steps (i), (ii), and (iii), amenable to formal verification of desired properties derived from potential assurance obligations such as the global existence of an effective mitigation strategy. In addition, the proposed approach is meant for step-wise refinement towards the automated synthesis of AD safety controllers implementing such properties.

READ FULL TEXT

page 4

page 6

page 8

page 9

page 11

research
02/22/2018

From Hazard Analysis to Hazard Mitigation Planning: The Automated Driving Case

Vehicle safety depends on (a) the range of identified hazards and (b) th...
research
08/31/2023

On the Safety of Connected Cruise Control: Analysis and Synthesis with Control Barrier Functions

Connected automated vehicles have shown great potential to improve the e...
research
08/20/2023

Formal Verification of Safety Architectures for Automated Driving

Safety architectures play a crucial role in the safety assurance of auto...
research
12/01/2019

AD-EYE: A Co-simulation Platform for Early Verification of Functional Safety Concepts

Automated Driving is revolutionizing many of the traditional ways of ope...
research
11/02/2020

A Formally Verified Fail-Operational Safety Concept for Automated Driving

Modern Automated Driving (AD) systems rely on safety measures to handle ...
research
12/04/2019

ATRIUM – Architecting Under Uncertainty for ISO 26262 compliance

The ISO 26262 is currently the dominant standard for assuring functional...
research
09/19/2019

The Colliding Reciprocal Dance Problem: A Mitigation Strategy with Application to Automotive Active Safety Systems

A reciprocal dance occurs when two mobile agents attempt to pass each ot...

Please sign up or login with your details

Forgot password? Click here to reset