Transcription
Safety Analysis ofHeavy-Duty Truck Platooning SystemsDoug PapeBattelleSAE INTERNATIONAL
Safety Analysis ofHeavy-Duty Truck Platooning SystemsBattelle is conducting this research for NHTSAList ofCurrent and FutureProductsHazard AnalysisandRisk AssessmentStudy Completion: Summer 2020.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAESafety Analysis
A Sampling of Platooning ProjectsPelotonVolvoTexas A&M Transportation InstituteTARDECSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Safety Analysis ofHeavy-Duty Truck Platooning SystemsList ofCurrent and FutureProductsSAE INTERNATIONALHazard AnalysisandRisk AssessmentSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAESafety Analysis
HazardsAn event that poses danger to people, the system, or the environmentCaused by human error, hardware failure, or software defect (usually)May be caused by limits of system design (scenario not anticipated)SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Identifying HazardsPreliminary Hazard Analysis (PHA)More formalized than brainstormingDecompose the design to subsystems or blocks Identify failures of the function of each block Identify failures of the interfaces Identify failures from the environment and from human factorsThen characterize the risk of every hazard.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Risk CharacterizationSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Risk CharacterizationISO 26262 addsa third dimension—ControllabilitySAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Classes of Hazards We Are Considering Communication failures (message lost, delayed, corrupted)Component failures (hardware failures, software errors)Vehicle factors (brake failures, differences in brake rates)Environmental factors (weather, other traffic)Driver issues (lack of training, acclimatization with the system)Human factors (reliance, fatigue, workload, fumes from closefollowing, trust in the other driver, standardization across brands)SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Safety Analysis ofHeavy-Duty Truck Platooning SystemsList ofCurrent and FutureProductsSAE INTERNATIONALHazard AnalysisandRisk AssessmentSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAESafety Analysis
Common Safety Analysis TechniquesFailure Modes & Effects AnalysisFMEABottom UpSAE INTERNATIONALFault Tree AnalysisFTATop DownSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Failure Modes & Effects AnalysisBottom UpA Failure Modes & Effects Analysis determineshow a system might failand the likely effects of particular modes of a failure.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Failure Modes & Effects AnalysisWhat cango wrongwith the input?SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Failure Modes & Effects AnalysisWhat isthe effecton the output?What cango wrongwith the input?SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Failure Modes & Effects AnalysisHow bad?What isthe effecton the output?What cango wrongwith the input?SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Failure Modes & Effects AnalysisHow bad?What isthe effecton the output?What cango wrongwith the input?SAE INTERNATIONALWhat are thecauses?Safety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Failure Modes & Effects AnalysisHow bad?What isthe effecton the output?How often?What cango wrongwith the input?SAE INTERNATIONALWhat are thecauses?Safety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAEWhat canbe done?
Fault Tree Analysis (FTA)Top DownA Fault Tree Analysis isa deductive analytical techniquewhere an undesirable state is specified.FTA demonstrates how resistant a system is to initiating faults.FTA of complex systems is labor intensivebut beneficial.SAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Top-Down ApproachSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Top-Down ApproachSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Top-Down ApproachFadeSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Top-Down ApproachFadeSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Human FactorsAnalysis Techniques Task analysis Workload assessment Activity sequence diagramPossible Faults Distraction or boredom Confusing messageSAE INTERNATIONALSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Questions?SAE INTERNATIONALContact Information:Doug Papepape@battelle.orgNHTSA Program Lead:Alrik SvensonAlrik.Svenson@dot.govSafety Analysis of Heavy-Duty Truck Platooning SystemsCopyright SAE International. Further use or distribution is not permitted without permission from SAE
Safety Analysis of Heavy-Duty Truck Platooning Systems Communication failures (message lost, delayed, corrupted) Component failures (hardware failures, software errors) Vehicle factors (brake failures, differences in brak