using hazard analysis to make early architecture
play

USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN - PowerPoint PPT Presentation

USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN AUTONOMOUS AUTOMOTIVE APPLICATION SATURN 2015 Joakim Frberg Architecture Analysis for an Autonomous Hauler A Safe Autonomous Machine: Early Architecture Decisions


  1. USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN AUTONOMOUS AUTOMOTIVE APPLICATION SATURN 2015 Joakim Fröberg

  2. Architecture Analysis for an Autonomous Hauler

  3. A Safe Autonomous Machine: Early Architecture Decisions • Functional safety and ASIL? Do we have any hazards? • Redundancy – Costly and possibly certifiable, So how to do? • Partitioning – Different criticality separated. How so?

  4. Combining three things Autonomous Preliminary System Hauler Hazard Architecture Application Analysis

  5. Study Autonomous Logic function block Preliminary hazard Early architecture application scope architecture analysis – ISO26262 design synthesis and usage Wanted: Method to make early decisions right

  6. Applications of autonomy • Very different functionality and qualities

  7. Autonomy: scope change

  8. Application – Automated Hauler • Production – loading and tipping, crusher, piles • Scope: Quarry usage • Site operator at control desk • Mixed fleet • People and vehicles

  9. Preliminary Hazard Analysis Function Hazard Severity Exposure Controlla-bility ASIL Detect pedestrian Fatal S3 E2 C3 C collision Function blocks for system Result Hazards classified - ASIL About 100 Hazards classified

  10. Decomposition - Redundancy ISO 26262 Road vehicles – Functional safety – Part 9: Automotive Safety Integrity Level (ASIL)- Oriented and safety-oriented analyses

  11. Architecture J. Albus et. al. 4D/RCS: “A reference model architecture for unmanned vehicle systems version 2.0,” National Institute of Standards and Technology, Gaithersburg, Maryland.

  12. System architecture – a decision stack Sensor fusion Autonomy decisions Map Sensor input Actuator control

  13. Example Plan passing Detect vehicle Execute pass trajectory Detection Planning Execution Actuator Detect ground Plan for non tilt Execute plan conditions trajectory Analysis

  14. Implications for architecture System Off board Possible separation of unclassified safety integrity Planning Analysis Detection Execution Possible separation of higher safety integrity Actuator

  15. Redundancy & Partitioning • Redundancy can be employed at perception – difficult at behaviour • Restrict classified functions to lower layers

  16. Conclusion • A PHA can aid architecture decisions early • Separating critical subsystems • Redundancy suited for perception functions PHA Architecture Autonomous hauler application

  17. Contact & Questions • joakim.froberg@sics.se, joakim.froberg@mdh.se

Recommend


More recommend