OICA IWG AECSAPRIL 2016 AECS REGULATION POST-CRASH CHECK WITH HMI TEST METHOD SUMMARY -ASIL determination – ISO26262 -Pre-requirements for HMI test method.

Slides:



Advertisements
Similar presentations
eCall for Powered Two Wheelers Opportunities and Challenges
Advertisements

Accident Emergency Call System (AECS)
IHRA-ITS UN-ECE WP.29 ITS Informal Group Geneva, March, 2013 Overview of International Activities to Limit Distraction Document No. ITS (21st ITS,
Crane Operations Objective
MySOS User Guide.
Combining Product Risk Management & Design Controls
National Highway Traffic Safety Administration Electrical Safety William Joel Sánchez.
Climatic, Mechanical resistance and EMC requirements Russian justification Accident Emergency Call System (AECS) 4 th meeting Paris April 28 th - 30 th.
Current idea in IG AECS to demonstrate AECS functions after (R94,95) crash tests. -Situation is not the same for all OEM’s -Countermeasures listed above.
Proposals for homologation of AECD and Installation in vehicle DRAFT status
 Design creates a new artifact (system, component or process) to meet a given need.  Broad Classifications ◦ Creative Designs – the first PDAs ◦ Variant.
Telematics & Automatic Crash Notification Michigan Traffic Safety Summit February 28, 2006.
Proposal for a new UNECE regulation on recyclability of motor vehicles Informal Document GRPE Reply to the Comments of the Russian Federation Informal.
Views from different perspectives
German point of view Results of the national meeting of German experts Automatic Emergency Call Systems.
Implementation of Global Satellite Navigation System (GLONASS) for In-Vehicle Emergency Call Systems: Status and Further Development Presented by the Russian.
AECS: draft UN Regulation Industry observations based on the current developments at the informal group June WP agenda item 8.6.
Outline of Definition of Automated Driving Technology Document No. ITS/AD (5th ITS/AD, 24 June 2015, agenda item 3-2) Submitted by Japan.
Presentation for Document ACSF-03-03_rev1 Oliver Kloeckner September rd meeting of the IG ASCF Munich, Airport Informal Document.
Damage Mitigation Braking System
Ministry of Industry and Trade of Russian Federation October 2013 Deputy director of the Department of transport and special engineering industry V. Kaganov.
Progress report of GRSG informal group on Accident Emergency Call System (AECS) Transmitted by Chair of the AECS IWG Informal document GRSG
Ministry of Industry and Trade of Russian Federation June 2013 Deputy director of the Department of transport and special engineering industry V. Kaganov.
1 ACSF Test Procedure Draft proposal – For discussion OICA and CLEPA proposal for the IG Group ACSF Tokyo, 2015, June Informal Document ACSF
Product & Technology Quality. Excellence. Support SIL Explanation 27.JAN 2006 Automation & Safety.
Validation | Slide 1 of 27 August 2006 Validation Supplementary Training Modules on Good Manufacturing Practice WHO Technical Report Series, No. 937, 2006.
Informal document GRSG
Draft progress report of GRSG informal group on Accident Emergency Call System (AECS) Transmitted by chair of IWG AECS Informal document GRSG-106-ХХ 106.
THE MINISTRY OF INDUSTRY AND TRADE OF THE RUSSIAN FEDERATION Dr. B.V.Kisulenko, V.A. Burmistrov 162-th meeting of WP March 2014, PROPOSAL FOR AMENDMENTS.
(社)日本自動車工業会・安全部会 1 1 (C) Copyright Japan Automobile Manufacturers Association, Inc., All rights reserved. Proposal for demonstrate procedure of AECS functional.
Tbilisi, SMS AND VIDEO FIRE AND CO GAS DETECTORSeCALL MOBILE APPLICATONGPS TRACKER CONTENT: MAPS.
Progress report of GRSG informal group on Accident Emergency Call System (AECS) Transmitted by the Chair of AECS IWG Informal document GRSG
4.2.1.Position determination Proposed modifications AECS 12 nd. meeting Moscow, 9-11 February 2016.
ABSTRACT: eCall for CDMA SOURCE: Tony Lee Mike Lim TITLE: CDMA eCall Overview TSG-AC.
Non Paper regarding component approvals UNECE AECS.
GSC Global Standards Collaboration GSC#10 28 August – 2 September 2005 Sophia Antipolis, France 1 eCALL In Vehicle System to provide information at car.
PRESENTED BY:- P.SREENIVASULU ROLL NO:-12AT5A0420 IV-B.Tech ECE.
OICA IWG AECSFEBRUARY 2016 AECS REGULATION POST-CRASH CHECK WITH HMI METHOD.
Task Force on Electro-magnetic Compatibility (TF EMC) Status report of TF to GRE-75 Friday, 8 April 2016 Informal document GRE (75 th GRE, 5-8 April.
Telematics derived from the Greek words “Tele” and “matos”, Tele means (far away) and matos means (derivative of Greek word machinari), Combinedly telematics.
D4 In-vehicle technology. Fleet Operator Recognition Scheme (FORS) FORS is important to our company because.
Process Safety Management Soft Skills Programme Nexus Alliance Ltd.
Transmitted by the Experts of TRL (EC)
AECS Accident Emergency Call System
Suggestion for Summarizing Process of the Principles
Guide for the application of CSM design targets (CSM DT)
Analysis of Current Maturity Models and Standards
Initial project results: Annex 6 – 20 Sept 2016
ACSF-C2 2-actions system
Informal document GRRF-86-36
Compliant Installation of Voice Alarm Systems
IVECO Proposal for Revised CoP Procedure
Proposals from the Informal Working Group on AEBS
DATA STORAGE SYSTEM FOR AUTOMATED DRIVING (DSSAD)
Transmitted by the expert from ISO
Submitted by the experts of OICA
Reason for performance difference between LVW and GVW
Proposals from the Informal Working Group on AEBS
DATA STORAGE SYSTEM FOR AUTOMATED DRIVING (DSSAD)
Safety concept for automated driving systems
Behaviour of M2 & M3 general construction in case of Fire Event
International Telecommunication Union CITS meeting 8 March 2019 Geneva Status report of the GRVA activities Context, current activities and impact François.
Progress report of GRSG informal group
C-EDR Introduction of Chinese Mandatory National Standard
Informal document GRRF-78-41
Submitted by the expert
AECS sled testing (NAMI’ testing centre)
Status of discussion about “Reversing Motion” in VRU-Proxi
CLEPA comments on OBD II GTR 18 Draft
Chinese Mandatory National Standard
Presentation transcript:

OICA IWG AECSAPRIL 2016 AECS REGULATION POST-CRASH CHECK WITH HMI TEST METHOD SUMMARY -ASIL determination – ISO Pre-requirements for HMI test method -HMI check procedure proposal -Glossary

OICA IWG AECSAPRIL 2016 ASIL determination – ISO ASIL = Automotive Safety Integrity Level

OICA IWG AECSAPRIL 2016 Determination of the level of ASIL for AECS The ISO26262 standard provides a risk-based approach to determine ASIL (Automotive Safety Integrity Level) for safety function in E/E systems for road vehicles. It also provides analytical method to identify impacting defaults on safety functions. Classification of hazardous events Class of severity : S2 (severe and life-threatening injuries - survival probable) Class of probability of exposure : E1 (very low probability) Class of controllability : C3 (Difficult to control / uncontrolable) ASIL Classification  According the Table4 ISO26262  ASIL = Quality Management (QM)  The class QM means no high level requirement for safe design (see annex) to comply with ISO26262, and therefore, AECS is not considered as a Safety Systemsee annex

OICA IWG AECSAPRIL 2016 Consequences for AECS AECS should not be considered as a safety system, and therefore, it doesn’t need to have a complete and complex approval method. Nevertheless, for using the HMI test method, this methodology (ISO26262) shall be a pre-requirement.

OICA IWG AECSAPRIL 2016 Pre-requirements for HMI test method 1- FAILURE DETECTION 2- STATUS and FAILURE INDICATION 02

OICA IWG AECSAPRIL 2016 Method Pre-requirements : FAILURE DETECTION This test method can be used only if the AECD/AECS is capable to check and diagnose : 1- the electrical connections between all of the following devices : - AECD control unit - PLMN communication module (NAD, SIM, …) + antenna - GNSS receiver + antenna - Power source (for a dedicated source) - Warning signal and Information signal devices (HMI) - Microphone - Loud speaker [-Trigger signal generator (e.g. Airbag Control Unit)] 2- the status of the : - PLMN and GNSS modules (internal failure) - PLMN coverage - Energy available in the power source (autonomy)

OICA IWG AECSAPRIL 2016 Pre-requirements : STATUS and FAILURE INDICATION This test method can be used only if the AECD/AECS is capable to indicate by a visual or audible mean : 1- a failure (see the list of failure in the previous slide) 2- the status information for the following : - AECS operational - PLMN availability - Automatic trigger detection + Establishment of a connection with the PSAP (*) - Connected to the PSAP + MSD sending (*) - Voice communication with PSAP (*) - End of normal call - Impossible to contact PSAP The status above identified by a (*) are merged in the AECS information signal (« system is processed ») This test method can be used only if the AECD/AECS is capable to treat/manage an emergency call during the approval crash tests even if there is no mobile phone network coverage.

OICA IWG AECSAPRIL 2016 HMI check procedure proposal 03

OICA IWG AECSAPRIL 2016 AECD/AECS test phases for test methods 1 to 4 (current situation) EMC R10 Mobile network access check HMI check Power Supply check GNSS checkSled test Crash-tests R94 / R95 Crash-tests R94 / R95 Audio test PART I AECD PART II AECS R94/95 tests Functional check Test methods 1 to 4 Test methods 1, 2 and 3 : 1 day Test method 4 : > 1 day MSD content Subjective Audio test HMI – status indication R94 and/or R95 operations + Electric Vehicle Safety measures R94 and/or R95 operations + Electric Vehicle Safety measures 1 day

OICA IWG AECSAPRIL 2016 AECD/AECS test phases for test method 5 : HMI test method (new) EMC R10 Mobile network access check HMI check Power Supply check GNSS checkSled test Crash-tests R94 / R95 Crash-tests R94 / R95 Audio test PART I AECD PART II AECS R94/95 tests Voice intelligibility test MSD content 1 day <1 hour 1 day Check the HMI recording Visual check of the audio parts (speaker, mic) R94 and/or R95 operations + (optional) Electric Vehicle Safety measures R94 and/or R95 operations + (optional) Electric Vehicle Safety measures eCall pre-crash operations only for Method 5 HMI check Method 5

OICA IWG AECSAPRIL 2016 Pre-crash procedure These operations are to be done before the R94 (frontal) and/or the R95 (Lateral) crash tests : 1- Proceed to a functional check by test methods 1 to 4 following a manual call : - Conformity of the content of the MSD (location, time stamp, vehicle identification) - Hands-free voice communication assessment  As in the European eCall regulation, the subjective voice intelligibility test method should be allowed, as the objective test method, at the demand of the applicant. 2- Install, in the vehicle, a mean of record the behavior of the warning and information signals during the crashes (R94 and R95). It could be, for example, a video/audio camera, or a recorder for electrical signals.

OICA IWG AECSAPRIL 2016 After the R94 or R95 crash, the Technical Service will check the recording of the warning and information signals to verify if the HMI sequence defined by the manufacturer is compliant. Post-crash procedure

OICA IWG AECSAPRIL 2016 Examples of compliant sequences of warning and information signal during a crash test in function of the PLMN availability (not to be considered as a reference for HMI which could include texts or speaches, other colors..) Automatic Trigger detected Establishing connection with PSAP Connected to PSAP MSD sending If a failure is detected, the warning indication will be permanently switched ON AECS operational PLMN ok Post-crash procedure With PLMN coverage Without PLMN coverage Crash event R94/R95 Crash event R94/R95 Fast Slow Impossible to contact PSAP after time-out Trigger event AECS operational PLMN Nok Voice communication with PSAP End of normal call BIP Automatic eCall detected Establishing connection with PSAP Trigger event The GNSS coverage impacts only on the MSD content Fast 5 minutes BIP

OICA IWG AECSAPRIL After the R94 or R95 crash, the Technical Service will check the recording of the warning and information signals to verify if the HMI sequence defined by the manufacturer is compliant. 2- A visual check will be done to verify the eventual damage on the audio devices (loud-speaker and the microphone) and PLMN antenna, if visible.  In the case of the audio devices or PLMN antenna are not visible, or if the audio devices or PLMN antenna show important damages, at the demand of the Technical Service, an additional subjective audio test should be done by test methods 1 to 4. Past/Fail criteria

OICA IWG AECSAPRIL 2016 Thank you

OICA IWG AECSAPRIL 2016 Glossary 04

OICA IWG AECSAPRIL 2016 AECD: Accident Emergency Call Device AECS: Accident Emergency Call System ASIL: Automotive Safety Integrity Level HMI: Human Machine Interface/Interaction PLMN: Public Lan Mobile Network GNSS: Global Navigation Satellite System NAD: Network Access Device SIM: Subscriber Identity Module MSD: Minimum Set of Data PSAP: Public Safety Answering Point

OICA IWG AECSAPRIL 2016 Annex on high level requirement for safety functions, ISO

OICA IWG AECSAPRIL 2016 This design method rates ASIL of safety functions (e.g. driving- braking functions..) and leads to design concepts including safe fallback mode and redundancies for safety and availability, according to default impacts on given architecture 1- a functionnal analysis based on customer final risks (OEM’s agreement through international standard) 2- a detailled analysis indentifies impacts from all system defaults.. to associated default tree ISO 26262, a method for safe design all defaults From functional architecture.. Customer feared event: e.g. no braking ! Customer feared event: e.g. no braking ! System feared event: e.g. command failure ! System feared event: e.g. command failure !