Safety of the Intended Functionality of Lane-Centering and Lane-Changing Maneuvers of a Generic Level 3 Highway Chauffeur System (Report No
Total Page:16
File Type:pdf, Size:1020Kb
DOT HS 812 879 November 2020 Safety of the Intended Functionality of Lane- Centering and Lane- Changing Maneuvers of a Generic Level 3 Highway Chauffeur System DISCLAIMER This publication is distributed by the U.S. Department of Transportation, National Highway Traffic Safety Administration, in the interest of information exchange. The opinions, findings, and conclusions expressed in this publication are those of the authors and not necessarily those of the Department of Transportation or the National Highway Traffic Safety Administration. The United States Government assumes no liability for its contents or use thereof. If trade or manufacturers’ names or products are mentioned, it is because they are considered essential to the object of the publications and should not be construed as an endorsement. The United States Government does not endorse products or manufacturers. Suggested APA Format Citation: Becker, C. J., Brewer, J. C., & Yount, L. J. (2020, November). Safety of the intended functionality of lane-centering and lane-changing maneuvers of a generic level 3 highway chauffeur system (Report No. DOT HS 812 879). National Highway Traffic Safety Administration. Technical Report Documentation Page 1. Report No. 2. Government Accession No. 3. Recipient’s Catalog No. DOT HS 812 879 4. Title and Subtitle 5. Report Date Safety of the Intended Functionality of Lane-Centering and Lane-Changing November 2020 Maneuvers of a Generic Level 3 Highway Chauffeur System 6. Performing Organization Code 7. Authors 8. Performing Organization Report No. Christopher Becker, John Brewer, and Larry Yount DOT-VNTSC-NHTSA-19-02 9. Performing Organization Name and Address 10. Work Unit No. (TRAIS) John A.Volpe National Transportation Systems Center 55 Broadway 11. Contract or Grant No. Cambridge, MA 02142 12. Sponsoring Agency Name and Address 13. Type of Report and Period Covered National Highway Traffic Safety Administration Final Report Electronic Systems Safety Division 1200 New Jersey Avenue SE. 14. Sponsoring Agency Code Washington, DC 20590 15. Supplementary Notes Paul Rau was the Contracting Officer’s Representative for this project. 16. Abstract This report describes the findings from applying Safety of the Intended Functionality (SOTIF) concepts as described in the Publicly Available Specification (PAS) ISO 21448 to the lane-changing and lane-centering maneuvers of a generic Level 3 highway chauffeur system. This report compares the SOTIF process described in PAS 21448 with the automotive industry’s voluntary functional safety standard, ISO 26262. This report then develops a generalized Level 3 highway chauffeur system, and identifies potential vehicle-level hazards, triggering events, and SOTIF mitigation measures. Finally, this report presents an approach for developing candidate scenarios to evaluate safety relevant triggering events and discusses current SOTIF evaluation approaches. 17. Key Words 18. Distribution Statement Safety of the Intended Functionality, SOTIF, PAS 21448, triggering event, Document is available to the highway chauffeur system, systems-theoretic process analysis, STPA public from the National Technical Information Service, www.ntis.gov 19 Security Classif. (of this report) 20. Security Classif. (of this page) 21 No. of Pages 22. Price Unclassified Unclassified 145 Form DOT F 1700.7 (8-72) Reproduction of completed page authorized i Table of Contents List of Acronyms ....................................................................................................................................... vii Executive Summary .................................................................................................................................... 1 1 Introduction ........................................................................................................................................ 3 1.1 Project Background ....................................................................................................................... 3 1.2 Analysis Scope .............................................................................................................................. 3 2 Safety of the Intended Functionality Overview ............................................................................... 4 2.1 Publicly Available Specification 21448 ........................................................................................ 4 2.2 Integration With Functional Safety Analysis ................................................................................ 6 2.3 Integrated Analysis Approach ....................................................................................................... 8 3 Scenario Development Framework ................................................................................................ 12 3.1 Permanent-Regional Variables ................................................................................................... 13 3.2 Permanent-Local Variables ......................................................................................................... 13 3.3 Compounding Events and Conditions ......................................................................................... 14 3.4 Non-Typical Events and Conditions ........................................................................................... 14 4 Generic Highway Chauffeur System Description ......................................................................... 15 4.1 Functional Description ................................................................................................................ 15 4.1.1 System Goals ...................................................................................................................... 15 4.1.2 Anticipated Use Cases ........................................................................................................ 16 4.1.3 System Operation ................................................................................................................ 16 4.1.4 Authority Over Vehicle Dynamics ..................................................................................... 16 4.1.5 Key System Dependencies .................................................................................................. 17 4.2 System Description ..................................................................................................................... 17 4.2.1 Sensors ................................................................................................................................ 17 4.2.2 Algorithms .......................................................................................................................... 19 4.2.3 Degradation Concept ........................................................................................................... 23 4.3 Functional Block Diagram .......................................................................................................... 24 4.4 Analysis Assumptions ................................................................................................................. 26 5 Vehicle-Level Hazard Analysis ....................................................................................................... 27 5.1 Possible Hazardous Events ......................................................................................................... 27 5.1.1 Potential Vehicle-Level Losses ........................................................................................... 27 5.1.2 Potential Vehicle-Level Hazard Identification .................................................................... 28 5.1.3 Relevant Operational Situations .......................................................................................... 29 5.2 Risk Assessment ......................................................................................................................... 31 5.3 Example Safety Goals ................................................................................................................. 36 6 Example Triggering Events ............................................................................................................. 37 ii 6.1 Type I Triggering Events ............................................................................................................ 37 6.1.1 Camera ................................................................................................................................ 37 6.1.2 Radar ................................................................................................................................... 38 6.1.3 GPS/Maps ........................................................................................................................... 39 6.1.4 Algorithms .......................................................................................................................... 40 6.1.5 General ................................................................................................................................ 45 6.2 Type II Triggering Events ........................................................................................................... 45 6.2.1 Human-Machine Interface .................................................................................................. 46 6.2.2 Driver Recognition .............................................................................................................. 47 6.2.3 Driver Judgement ...............................................................................................................