Safety Analysis Of Heavy-Duty Truck Platooning Systems

Transcription

Safety Analysis ofHeavy-Duty Truck Platooning SystemsDoug PapeBattelleSAE INTERNATIONAL

Safety Analysis ofHeavy-Duty Truck Platooning SystemsBattelle is conducting this research for NHTSAList ofCurrent and FutureProductsHazard AnalysisandRisk AssessmentStudy Completion: Summer 2020.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAESafety Analysis

A Sampling of Platooning ProjectsPelotonVolvoTexas A&M Transportation InstituteTARDECSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Safety Analysis ofHeavy-Duty Truck Platooning SystemsList ofCurrent and FutureProductsSAE INTERNATIONALHazard AnalysisandRisk AssessmentSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAESafety Analysis

HazardsAn event that poses danger to people, the system, or the environmentCaused by human error, hardware failure, or software defect (usually)May be caused by limits of system design (scenario not anticipated)SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Identifying HazardsPreliminary Hazard Analysis (PHA)More formalized than brainstormingDecompose the design to subsystems or blocks Identify failures of the function of each block Identify failures of the interfaces Identify failures from the environment and from human factorsThen characterize the risk of every hazard.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Risk CharacterizationSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Risk CharacterizationISO 26262 addsa third dimension—ControllabilitySAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Classes of Hazards We Are Considering Communication failures (message lost, delayed, corrupted)Component failures (hardware failures, software errors)Vehicle factors (brake failures, differences in brake rates)Environmental factors (weather, other traffic)Driver issues (lack of training, acclimatization with the system)Human factors (reliance, fatigue, workload, fumes from closefollowing, trust in the other driver, standardization across brands)SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Safety Analysis ofHeavy-Duty Truck Platooning SystemsList ofCurrent and FutureProductsSAE INTERNATIONALHazard AnalysisandRisk AssessmentSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAESafety Analysis

Common Safety Analysis TechniquesFailure Modes & Effects AnalysisFMEABottom UpSAE INTERNATIONALFault Tree AnalysisFTATop DownSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Failure Modes & Effects AnalysisBottom UpA Failure Modes & Effects Analysis determineshow a system might failand the likely effects of particular modes of a failure.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Failure Modes & Effects AnalysisWhat cango wrongwith the input?SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Failure Modes & Effects AnalysisWhat isthe effecton the output?What cango wrongwith the input?SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Failure Modes & Effects AnalysisHow bad?What isthe effecton the output?What cango wrongwith the input?SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Failure Modes & Effects AnalysisHow bad?What isthe effecton the output?What cango wrongwith the input?SAE INTERNATIONALWhat are thecauses?Safety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Failure Modes & Effects AnalysisHow bad?What isthe effecton the output?How often?What cango wrongwith the input?SAE INTERNATIONALWhat are thecauses?Safety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAEWhat canbe done?

Fault Tree Analysis (FTA)Top DownA Fault Tree Analysis isa deductive analytical techniquewhere an undesirable state is specified.FTA demonstrates how resistant a system is to initiating faults.FTA of complex systems is labor intensivebut beneficial.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Top-Down ApproachSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Top-Down ApproachSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Top-Down ApproachFadeSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Top-Down ApproachFadeSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Human FactorsAnalysis Techniques Task analysis Workload assessment Activity sequence diagramPossible Faults Distraction or boredom Confusing messageSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Questions?SAE INTERNATIONALContact Information:Doug Papepape@battelle.orgNHTSA Program Lead:Alrik SvensonAlrik.Svenson@dot.govSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE

Safety Analysis of Heavy-Duty Truck Platooning Systems Communication failures (message lost, delayed, corrupted) Component failures (hardware failures, software errors) Vehicle factors (brake failures, differences in brak