[Samuel]
Safety + Security investigator
First: Single fault FTTI/FDTI/FRTI
And for the dual point failiure the FTTI/FDTI/FRTI listed as following:
IF is the intended functionality, SM1 is the safety mechanisms to IF, and SM2 is the safety mechanims for SM1
Here, we take following scenario:
For IFfault, it will be monitored by SM1, and SM1 will be monitored by SM2
Here theIF and SM1 they combined together as Multiple point failure.
Supposeafter IF fault happens, t times, the SM1 will got fault (t
1.IFwill still got fault, and no detection for IF fault, SM1 will coming intofault, and SM2 will detection it, after FDTI2 + FRTI2, the SM1 will come backto safe state, and back to monitor the IF fault, so after FDTI1 + FRT2, thewhole IF will come into safe state, then for the whole system, which will cometo safe state
2.Whenin SM2 in fault, not back to safe state, at that time, IF are in the faultstate, the whole system are in degradation mode; and when SM1 come to safestate, and start to diagnose the IF fault, the system are in normal detectionmode
So, forthe dual point failure, here the
FHTI(Dualpoint)=t + FDTI_1 + FDTI _2 + FRTI_1 + FRTI_2
FDTI(Dualpoint)= t + FDTI_1 + FDTI_2 + FRTI_2
FRTI(Dual point)= FRT_2
For the degradation time, it is merely ( t +FDTI_2 + FRTI_2 +FDTI_1)
Second: combining SOTIF consideration (Level 3 )
And system architecture as following:
https://mp.weixin.qq.com/s?__biz=Mzg5NTIwMTEzOA==&mid=2247484397&idx=1&sn=9ea285d9ef41821a16398045dc3b1e92&chksm=c012b9f0f76530e6acb3046ea11f71d37e9a97f5475b7f6196afffb22570a7cbac1db617f279&token=486327309&lang=zh_CN#rd
Suppose the ADS function1 fault, and which have the safety mechanism SM1 to monitor itself, and SM2 to monitor SM2, and if the IF fault, then the whole system will fallback to ready user.
Based on above scenario, it is the dual point failure plus SOTIF the FTTI/FDTI/FRTI the scenario.
Then it will be like that:
FDTI(Dual point)= FDTI_IF_1 + EOTI1 + FDTI_FB_1
FRTI (Dual point)= FRTI
FDTI(Dual point)= t + FDTI_2 + FRTI_2 + FDTI_1 + EOTI + FDTI_FALLBACK_1
FRTI (Dual point)= FRTI_FALLBACK
已完成
数据加载中