USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN - - PowerPoint PPT Presentation

using hazard analysis to make early architecture
SMART_READER_LITE
LIVE PREVIEW

USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN - - PowerPoint PPT Presentation

USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN AUTONOMOUS AUTOMOTIVE APPLICATION SATURN 2015 Joakim Frberg Architecture Analysis for an Autonomous Hauler A Safe Autonomous Machine: Early Architecture Decisions


slide-1
SLIDE 1

USING HAZARD ANALYSIS TO MAKE EARLY ARCHITECTURE DECISIONS FOR AN AUTONOMOUS AUTOMOTIVE APPLICATION

SATURN 2015 Joakim Fröberg

slide-2
SLIDE 2

Architecture Analysis for an Autonomous Hauler

slide-3
SLIDE 3

A Safe Autonomous Machine: Early Architecture Decisions

  • Functional safety and ASIL? Do

we have any hazards?

  • Partitioning – Different

criticality separated. How so?

  • Redundancy – Costly and possibly

certifiable, So how to do?

slide-4
SLIDE 4

Combining three things

Autonomous Hauler Application Preliminary Hazard Analysis System Architecture

slide-5
SLIDE 5

Study

Autonomous application scope and usage Logic function block architecture Preliminary hazard analysis – ISO26262 Early architecture design synthesis

Wanted: Method to make early decisions right

slide-6
SLIDE 6

Applications of autonomy

  • Very different functionality and qualities
slide-7
SLIDE 7

Autonomy: scope change

slide-8
SLIDE 8

Application – Automated Hauler

  • Scope: Quarry usage
  • Site operator at control

desk

  • Mixed fleet
  • People and vehicles
  • Production – loading and tipping, crusher, piles
slide-9
SLIDE 9

Preliminary Hazard Analysis

Function blocks for system

Function Hazard Severity Exposure Controlla-bility ASIL Detect pedestrian Fatal collision S3 E2 C3 C

Result Hazards classified - ASIL About 100 Hazards classified

slide-10
SLIDE 10

Decomposition - Redundancy

ISO 26262 Road vehicles – Functional safety – Part 9: Automotive Safety Integrity Level (ASIL)- Oriented and safety-oriented analyses

slide-11
SLIDE 11

Architecture

  • J. Albus et. al. 4D/RCS: “A reference model architecture for unmanned

vehicle systems version 2.0,” National Institute of Standards and Technology, Gaithersburg, Maryland.

slide-12
SLIDE 12

System architecture – a decision stack

Map Sensor fusion Actuator control Autonomy decisions Sensor input

slide-13
SLIDE 13

Example

Detect vehicle Plan passing trajectory Execute pass Detection Planning Actuator Execution Detect ground conditions Plan for non tilt trajectory Execute plan Analysis

slide-14
SLIDE 14

Implications for architecture

Detection Planning Analysis Actuator Execution Possible separation of unclassified safety integrity Possible separation of higher safety integrity System Off board

slide-15
SLIDE 15

Redundancy & Partitioning

  • Redundancy can be employed at

perception – difficult at behaviour

  • Restrict classified functions to lower

layers

slide-16
SLIDE 16

Conclusion

  • A PHA can aid architecture decisions early
  • Separating critical subsystems
  • Redundancy suited for perception functions

Autonomous hauler application PHA Architecture

slide-17
SLIDE 17

Contact & Questions

  • joakim.froberg@sics.se, joakim.froberg@mdh.se