Browse Topic: Safety regulations and standards

Items (845)
The Primary Author has been involved in Army Aviation Development and Acquisition since the Utility Tactical Transport Aircraft System (UTTAS), Advanced Attack Helicopter (AAH), Army Helicopter Improvement Program (AHIP), and Light Helicopter Experimental (LHX) Programs in the mid-1970s to the mid-1980s. The first three of these programs successfully made it to production aircraft, while the LHX became the RAH-66 Comanche and was canceled primarily due to technical problems and cost overruns. The initiation of the next phase by the Army Aviation Development (ADD) Directorate for Future Vertical Lift (FVL) did not occur until the beginning of the 2015-2000 timeframe. This was 35 years since the last Army Aviation Development in 1980. To help sustain this FVL development, the Primary Author led, oversaw, and helped conduct a program through the National Rotorcraft Technology Center (NRTC) in the 2015-2016 timeframe. It was called the Development Assurance Value-Based Acquisition (DAVBA) Program1. It included the following team members: Georgia Tech, University of Alabama Huntsville (UAH), Dassault Systèmes, and Clausewitz Technology. The Army ADD plan funded it for FY2015- 2016 through the NRTC. The objectives were to provide the Future Vertical Lift (FVL) Program with a Development Assurance for Airworthiness Qualification and a Value-Based Acquisition Overall Evaluation Criterion (OEC) for FARA and FLRAA concepts.. However, Army Aviation only funded the first phase in 2015, as FVL funds were then transferred to the new Army Futures Command. This paper will illustrate how DAVBA could have saved the Future Attack and Reconnaissance Aircraft Program (FARA) Program as well as providing a more cost effective Future Long Range Assault Aircraft (FLRAA) Program.
Schrage, Daniel
To this point in aviation history, a typical aircraft type certification program has focused on the constituent systems that make up the aircraft, decomposing them further and further down until reaching their elemental parts and how they interact. This approach has traditionally treated the actual communication technology as only an interface, with technology and implementation based on a decision between multiple stakeholders via an ICD and high-level requirements. This has been necessary to ensure the accurate and on-time delivery of safety-critical data between nodes. When using legacy point-to-point or bus-based data communication technologies like ARINC 429 or MIL-STD-1553, this approach has worked well enough as these technologies are relatively straightforward and proven technologies. However, as onboard bandwidth needs for safety-critical data increase, these legacy technologies are increasingly no longer capable of meeting the needs of system integrators. Ubiquitous, high-bandwidth Ethernet is the obvious solution to these needs and, indeed, it has been used for quite some time in onboard networking applications for low Development Assurance Level (DAL)/non-safety critical data. However, as Ethernet moves into high-DAL applications, the certification of the Ethernet network itself becomes a major complexity that must be addressed directly.
Mustillo, MichaelFinnegan, DanielZischka, Wolfram
Adaptive cruise control (ACC) is an enhancement of conventional cruise control systems that allows the ACC-equipped vehicle to follow a forward vehicle at a pre-selected time gap, up to a driver selected speed, by controlling the engine, power train, and/or service brakes. This SAE Standard focuses on specifying the minimum requirements for ACC system operating characteristics and elements of the user interface. This document applies to original equipment and aftermarket ACC systems for passenger vehicles (including motorcycles). This document does not apply to heavy vehicles (GVWR > 10,000 lbs. or 4,536 kg). Furthermore, this document does not address other variations on ACC, such as “stop & go” ACC, that can bring the equipped vehicle to a stop and reaccelerate. Future revisions of this document should consider enhanced versions of ACC, as well as the integration of ACC with Forward Vehicle Collision Warning Systems (FVCWS).
Advanced Driver Assistance Systems (ADAS) Committee
This SAE Recommended Practice provides common data output formats and definitions for a variety of data elements that may be useful for analyzing the performance of automated driving system (ADS) during an event that meets the trigger threshold criteria specified in this document. The document is intended to govern data element definitions, to provide a minimum data element set, and to specify a common ADS data logger record format as applicable for motor vehicle applications. Automated driving systems (ADSs) perform the complete dynamic driving task (DDT) while engaged. In the absence of a human “driver,” the ADS itself could be the only witness of a collision event. As such, a definition of the ADS data recording is necessary in order to standardize information available to the accident reconstructionist. For this purpose, the data elements defined herein supplement the SAE J1698-1 defined EDR in order to facilitate the determination of the background and events leading up to a collision in an ADS-operated vehicle. The data elements defined in this document are unique to Level 3, 4, or 5 ADS features, as defined by SAE J3016, and provide additional background of the events leading up to a crash or crash-like event. The data from sensors such as camera(s), LiDAR(s) etc. will provide information in the absence of a human driver. The data included in the ADS data logger is expected to be used in conjunction with the SAE J1698 event data recorder (EDR) record and traditional accident reconstruction analysis. The EDR and ADS data logger will capture information leading up to the triggered event, at a minimum. There are no facts to support that recording data for greater than 5 seconds pre-event would change the outcome of any crash analysis. Thus, the recommended recording duration for a data logger is 5 seconds pre-event, same as an EDR. Due to the potential for sensor and/or communication failure during a crash event, the recommendation is that data should be collected post-crash for impact and rollover sensors for up to 250 ms. ADS technology is still being developed and is not yet commercially deployed. Therefore, this SAE Recommended Practice is intended as a guide toward standard practice and is subject to change to keep pace with experience and technical advances.
Event Data Recorder Committee
Leveraging Systems Theoretic Process Analysis (STPA) for Efficient ISO 26262 Compliance2021-01-00674/6/2021
There has been a significant increase - both in the content of electronics and software in vehicles as well as in recalls attributed to these components and systems. The advanced features, including the onset of autonomous vehicles accompanied by millions of lines of code in software have exponentially increased the complexity of vehicle systems and decreased effectiveness of many of the safety analysis techniques being used to identify hazards and safety requirements - for example, FMEA, FTA, ETA, etc.- which were invented decades before the existence of complexities of such magnitude. This paper examines a new hazard identification technique formalized by Nancy G Leveson of Massachusetts Institute of Technology (MIT), USA in her book “Engineering a Safer World” and further elaborated in the STPA Handbook co-authored with John P Thomas in March 2018. This paper explains how the STPA technique could be effectively used to comply with ISO 26262 in various phases of the “V” lifecycle of product development and later during production, operation, service, and decommissioning. It is interesting to note that although STPA is referenced in the Standard for Safety for the Evaluation of Autonomous Products, UL 4600, the ISO 26262:2018 standard second edition makes no explicit reference to this technique although it allows practitioners to use any suitable technique so long as evidence can be provided that the objectives of the applicable clauses are met. Some reference(s) to prior work in this context will also be provided.
Bongirwar, Rajiv
Driving Automation System Test Scenario Development Process Creation and Software-in-the-Loop Implementation2021-01-00624/6/2021
Automated driving systems (ADS) are one of the key modern technologies that are changing the way we perceive mobility and transportation. In addition to providing significant access to mobility, they can also be useful in decreasing the number of road accidents. For these benefits to be realized, candidate ADS need to be proven as safe, robust, and reliable; both by design and in the performance of navigating their operational design domain (ODD). This paper proposes a multi-pronged approach to evaluate the safety performance of a hypothetical candidate system. Safety performance is assessed through using a set of test cases/scenarios that provide substantial coverage of those potentially encountered in an ODD. This systematic process is used to create a library of scenarios, specific to a defined domain. Beginning with a system-specific ODD definition, a set of core competencies are identified. These core competencies are then considered both in isolation and in conjunction with other potential confounding factors (e.g. other traffic or atmospheric conditions); with “edge cases” being represented as compounded or unique sets of confounding factors. Using this approach, a candidate scenario set is presented, along with a discussion of nuances and necessary considerations in scenario selection. These approaches are combined in a simulated environment to demonstrate their use. Finally, a strategy is proposed to automate the overall scenario testing process to make the execution less cumbersome. This process of test scenario creation strictly follows the ISO 26262 concept phase to verify the safety goals and functional safety requirements.
Patil, MayurLybarger, AlexanderMidlam-Mohler, ShawnStoddart, Evan
This document provides nomenclature and references to related documents for heavy vehicle event data recorders (HVEDR) for heavy-duty (HD) ground wheeled vehicles. The SAE J2728 series of documents consists of the following:
Truck and Bus Event Data Recorder Committee
In the early days of quality management, prior to 1980s, the focus seemed to be on "Quality Control" or "Quality Assurance". Emphasis was placed on inspection and testing. Quality was about conformance to specification. Non-Conformance Reports were representative of quality control. Our understanding of quality management has evolved, largely based on the Toyota Quality and Concurrent Engineering Approach of moving it off the production line for Integrated Product and Process Development (IPPD) [1]. In the late 1980s industry experienced similar difficulties in understanding and adopting quality management. The ideas behind managing quality are quite abstract. Quality is primarily about understanding and satisfying a customer's expectations. This includes implicit expectations, as well as explicit expectations. The techniques of specification, inspection and testing only make sense in that wider context. Formal risk management was developed in the late 1980s and throughout the 1990s. Risk management principles are now widely understood and applied. Functional Safety Management (FSM) simply applies quality management to systems that are designed to control risk. [2] The standards for FSM and Development Assurance (DA) are relatively new. SAE ARP 4754 and ARP 4761 for complex aircraft systems were introduced in 1996 and DO-178 for software in 1998. In 2010 ARP 4754A [3] was created for movement from federated avionics systems to distributed integrated avionics systems which set the stage for Integrated Modular Avionics (IMA) in DO 297 [4]. The Army identified IMA as a critical technology in its Joint Common Architecture (JCA) Final Report [5] and is seeking to provide a Modular Open Systems Architecture (MOSA) approach to its Future Vertical Lift (FVL) programs. [6] The aim is to build and upgrade FVL mission systems without expensive proprietary interfaces. New capabilities from a choice of developers will adapt to emerging threats. The mission system architecture demonstration (MSAD) Program has awarded six contracts to avionics vendors to develop MOSA tools and rules. A capstone demonstration wraps-up this December 2020 and will generate a final report and provide guidance for Future Attack and Reconnaissance Aircraft (FARA), FLRAA and FUAS architectures. MOSA flexibility and economy come to legacy helicopters with the Aviation Mission Common Server (AMCS), which transitions the legacy fleet from single-purpose/single-vendor architectures to more adaptable modules and components. Nonproprietary, government-controlled, open system standards interface new software applications without going to each platform maker for integration. [6] This paper will review FSM, DA, and Open IMA in these civil aircraft standards, compare them with Army Aviation's current Army Military Airworthiness Certification Criteria (AMACC) [7] and recommend a Civil Military FSM DA Framework for FVL and on how AMACC could be modified for FVL Open Systems Architectures (OSA) Certification using a Modular Open Systems Approach (MOSA). [8]
Daniel, Dr.Lewis, Dr.
Australia has embarked on an extraordinary reform to design, develop and implement a new and contemporary Defence Aviation Safety Framework. The program seeks to establish a single Defence Aviation Safety Authority (DASA) and issue a comprehensive and integrated suite of Defence Aviation Safety Regulation (DASR) for initial and continuing airworthiness, flight operations, air navigation, aerodromes (inclusive of ship-borne heliports) and safety management systems. While reforms of this scale can often be triggered by reviews into major aircraft accidents, such as The Nimrod Review by Charles Haddon-Cave QC in October 2009, Australia initiated the reform when new aircraft fleets were being introduced and at a time of arguably high-levels of aviation safety. The purpose of this paper is therefore to explain the compelling reason for change; providing a twenty-five-year retrospective analysis of Australia’s previous Defence aviation safety framework to give a rich picture of the difficulties faced by increased commercialization from the late 1990s, globalization in the 2000s, and the recent emergence of strict work, health and safety legislation in Australia.
Hood, JamesMarzocca, PierSinha, Arvind
This SAE Standard provides test procedures for air and air-over-hydraulic disc or drum brakes used for on-highway commercial vehicles over 4536 kg (10000 pounds) GVWR. This recommended practice includes the pass/fail criteria of Federal Motor Vehicle Safety Standard No. TP-121D-01.
Truck and Bus Foundation Brake Committee
This SAE standard specifies a message set, and its data frames and data elements, for use by applications that use vehicle-to-everything (V2X) communications systems. While the data dictionary was originally designed for use over DSRC, this document is intended to be independent of the underlying communications protocols used to exchange data between participants in V2X applications.
V2X Core Technical Committee
Truck crashes on Wyoming mountain passes due to brake heating has been a long-standing issue due to the steep downgrades that characterize some routes in the state. The grade severity rating system (GSRS) developed by the Federal Highway Administration (FHWA) to recommend maximum safe speeds has been identified as a viable countermeasure to reducing the incidence of downgrade truck crashes. However, several decades have passed since the GSRS was developed. In the decades since its development, truck features have undergone radical changes in terms of design. The streamlined design of tractors and trailers, use of drag reduction devices, changes in engine features, and adoption of radial tires have led to a reduction in the non-brake forces that retard motion. Truck brakes have also changed along with retarder characteristics. This has meant that maximum safe speeds recommended by the GSRS have been conservative. This article discusses tests and results involved in updating the GSRS. Maximum safe speeds from the updated GSRS model was compared to the previous FHWA model and was found to be higher while allowing for faster descent. The effect of the GSRS on retarder use was also evaluated using the updated model. The updated GSRS model should increase driver confidence in recommended speeds while improving Wyoming mountain pass safety.
Moomen, MilhanKsaibati, Khaled
AVSC Best Practice for Describing an Operational Design Domain: Conceptual Framework and LexiconAVSC000022020044/15/2020
An ADS-operated vehicle’s operational design domain (ODD) is defined by the manufacturer based on numerous factors. Research is underway at other organizations to define and organize ODD elements into taxonomies and other relational constructs. In order to enhance collaboration and communication between manufacturers and developers and transportation authorities, common terms and consistent frameworks are needed. The conceptual framework presented by Automated Vehicle Safety Consortium establishes a lexicon that can be used consistently by ADS developers and manufacturers responsible for defining their ADS ODD. A common framework and lexicon will reduce confusion, align expectations, and therefore build public trust, acceptance, and confidence. The guidance in this document is intended for: The technical community (e.g. manufacturers and developers) Public agencies (e.g. regulatory authorities) Infrastructure owner-operators The public This document, Best Practice for Describing an Operational Design Domain: Conceptual Framework and Lexicon is a critical first step. It offers a conceptual framework for manufacturers and developers to use when communicating with public agencies and the general public about their ADS’s ODD. It also details a list of potential variables with definitions that manufacturers and developers might use to describe certain aspects of the ODDs of their ADS-operated vehicles. It was developed with fleet-managed, SAE Level 4 vehicles in mind — i.e. vehicles requiring no human intervention to operate within their ODD. These vehicles are NOT privately owned.
Automated Vehicle Safety Consortium
Assessment of Collision Markings on Non-Used Vehicle Seat Belt Restraint Systems2020-01-09754/14/2020
Forensic investigators of automobile collisions are commonly tasked with determining whether physical evidence observed on restraint systems is consistent with the occupant’s use or non-use of the seat belt restraint. The characteristics of collision-induced markings generated on seat belt systems are not solely dependent on the belted status of the occupant, but also the technological features incorporated in the seat belt assembly. As the state-of-the-art for seat belt assemblies has changed over time, so has the constellation of physical evidence typically created on seat belt restraint systems. Pretensioner deployment can leave physical evidence on restraint system hardware in the absence of occupant loading. This study presents examples of physical evidence collected from seat belt systems involved in real-world collisions, which were initially alleged to affirm proper belt use, but were ultimately proven to be evidence of non-use. Several laboratory demonstrations were conducted to investigate physical evidence created on restraint system hardware as a result of pretensioner deployments of non-used seat belts in a variety of incompletely stowed conditions. The demonstrations show the initial positions of the seat belt assemblies necessary to produce the distinct physical evidence documented in the real-world samples. The physical evidence observed on the real-world restraint systems were consistent with the markings produced in the laboratory demonstrations. The presence of physical evidence on restraint system hardware and webbing is inadequate to conclude that a seat belt restraint was in use. Careful consideration of restraint system physical evidence combined with restraint system geometry and incorporated technological features can distinguish physical evidence related to seat belt use or non-use during a collision event. These examples will be useful to investigators for the assessment of physical evidence and diagnosis of seat belt use.
Gregg, Richard H.Petroskey, Karla J.
Evaluation of Occupant Kinematics during Low- to Moderate-Speed Side Impacts2020-01-12224/14/2020
While nearly 50 percent of occupants in side-impact collisions are in vehicles that experience a velocity change (delta-V) below 15.0 kph (9.3 mph), full scale crash testing research at these delta-Vs is limited. Understanding occupant kinematics in response to these types of side impacts can be important to the design of side-impact safety countermeasures, as well as for evaluating potential interactions with interior vehicle structures and/or with other occupants in the vehicle. In the current study, two full-scale crash tests were performed utilizing a late-model, mid-size sedan with disabled airbags. The test vehicle was impacted by a non-deformable moving barrier on the driver side at an impact speed of 10.0 kph (6.2 mph) in the first test and then on the passenger side at an impact speed of 21.6 kph (13.4 mph) in the second test, resulting in vehicle lateral delta-Vs of 6.1 kph (3.8 mph) and 14.0 kph (8.7 mph), respectively. As can occur in real-world collisions, the initial impacts to the vehicle were followed by subsequent lower severity contacts. In both tests, Hybrid III 50th percentile male anthropomorphic test devices (ATDs) were restrained in the driver and right front passenger seats. The current study allowed for comparison of the near- and far-side occupant kinematics during the multiple vehicle contacts. The occupant kinematics were evaluated using high-speed video recordings of the collisions. Motion tracking was used to evaluate excursion magnitudes and excursion velocities during these collisions and demonstrated that, in general, the magnitudes of occupant excursion and velocity were greater in the higher-speed collision than in the lower-speed collision. Occupant motions relative to vehicle structures and relative to the other occupant were evaluated. In general, the kinematics included oscillatory responses of the ATDs following the initial motion toward the impact and return motion toward and beyond the original seated position. No significant occupant-to-occupant contact was seen in the current study, and head contact with vehicle side window glazing was only observed with the near-side ATD in the higher-speed impact where side curtain airbag deployment would have occurred.
George, JuffDavis, MathieuSharpe, SarahOlberding, JosephImler, StacyBove, Robert
Road Curvature Decomposition for Autonomous Guidance2020-01-10244/14/2020
Vehicle autonomy is critically dependent on an accurate identification and mathematical representation of road and lane geometries. Many road lane identification systems are ad hoc (e.g., machine vision and lane keeping systems) or utilize finely-discretized path data and vehicle tracking systems such as GPS. A novel Midwest Discrete Curvature (MDC) method is proposed in which geodetic road data is parsed along road directions and digitally stored in a road data matrix. Road data is discretized to geospatial points and curvature and road tangent vectorization, which can be utilized to generate consistent, mathematically-defined road profiles with deterministic boundary conditions, consistent non-holonomic boundary constraints, and a smooth, differentiable path which connects critical road coordinates. The method was evaluated by discretizing three road segments: a hypothetical road consistent with the American Association of State Highway and Transportation Officials (AASHTO) Green Book design standards, a road segment discretized using satellite photography and GPS data points, and an in-vehicle GPS trace collected at 10 Hz. Improvements and further research were recommended to expand findings, but results indicated potential for implementation into road modeling which could be the foundation of new autonomous vehicle guidance systems that are complimentary to existing autonomous systems.
Jacome, RicardoStolle, CodySweigard, Michael
Assessment of Several THOR Thoracic Injury Criteria based on a New Post Mortem Human Subject Test Series and Recommendations2019-22-00123/31/2020
Several studies, available in the literature, were conducted to establish the most relevant criterion for predicting the thoracic injury risk on the THOR dummy. The criteria, such as the maximum deflection or a combination of parameters including the difference between the chest right and left deflections, were all developed based on given samples of Post Mortem Human Subject (PMHS). However, they were not validated against independent data and they are not always consistent with the observations from field data analysis. For this reason, 8 additional PMHS and matching THOR tests were carried out to assess the ability of the criteria to predict risks. Accident investigations showed that a reduction of the belt loads reduces the risk of rib fractures. Two configurations with different levels of force limitation were therefore chosen. A configuration representing an average European vehicle was chosen as a reference. It consists of a 3-point belt with a 3.5 kN and then 2 kN digressive limiter, combined with a 54-liter airbag. For better reproducibility and durability, the tests were performed with a pre-inflated bag and a semi-rigid seat. In this first configuration, the THOR dummy had a maximum resulting deflection of 43 mm. To differentiate the criteria, the second configuration was chosen such that it resulted in about the same deflection on the THOR dummy, but with a 5 kN belt force limitation combined with a lower pressure airbag. To reach this target of 43 mm, the pulse severity was lowered. Some criteria were higher in this second configuration, which allows them to be distinguished from the maximum deflection criterion. Four tests on four PMHS were performed in each configuration. The injury assessments showed that the total number of fractures was almost the same in both configurations, but that the number of separated fractures was greater in the 5 kN configuration. 25% of the subjects sustained AIS >3 injuries related to the number of displaced fractures in the 3.5/2 kN load limitation configuration. The result increased to 75% in the 5kN configuration. In total, 8 PMHS and the matching THOR tests were performed and used to assess the ability of the thoracic criteria to predict rib fractures in 2 types of chest loading configurations. The test results did not allow to conclude on the relevance of the criteria measured on the THOR dummy for the total number of rib fractures identified at autopsy (NFR). However, clearly different assessments for separated rib fractures (NSFR), make it possible to differentiate the criteria. The maximum resultant deflection failed to properly predict separated rib fractures while other criteria that include the left-to-right rib deflection difference did.
Trosseille, XavierPetit, PhilippeUriot, JérômePotier, PascalBaudrit, Pascal
Factors Affecting Child Injury Risk in Motor-Vehicle Crashes2019-22-00083/31/2020
Current recommendations for restraining child occupants are based on biomechanical testing and data from national and international field studies primarily conducted prior to 2011. We hypothesized that analysis to identify factors associated with pediatric injury in motor-vehicle crashes using a national database of more recent police-reported crashes in the United States involving children under age 13 where type of child restraint system (CRS) is recorded would support previous recommendations. Weighted data were extracted from the National Automotive Sampling System General Estimates System (NASS-GES) for crash years 2010 to 2015. Injury outcomes were grouped as CO (possible and no injury) or KAB (killed, incapacitating injury, non-incapacitating injury). Restraint was characterized as optimal, suboptimal, or unrestrained based on current best practice recommendations. Analysis used survey methods to identify factors associated with injury. Factors with significant effect on pediatric injury risk include restraint type, child age, driver injury, driver alcohol use, seating position, and crash direction. Compared to children using optimal restraint, unrestrained children have 4.9 (13-year-old) to 5.6 (< 1-year-old) times higher odds of injury, while suboptimally restrained children have 1.1 (13-year-old) to 1.9 (< 1-year-old) times higher odds of injury. As indicated by the differences in odds ratios, effects of restraint type attenuate with age. Results support current best practice recommendations to use each stage of child restraint (rear-facing CRS, forward-facing harnessed CRS, belt-positioning booster seat, lap and shoulder belt) as long as possible before switching to the next step.
Benedetti, MarcoKlinich, Kathleen D.Manary, Miriam A.Flannagan, Carol A. C.
Evaluation of the Injury Risks of Truck Occupants Involved in a Crash as a Result of Errant Truck Platoons09-08-01-00013/11/2020
Truck platooning comprises a number of trucks equipped with automated lateral and longitudinal vehicle control technology, which allows them to move in tight formation with short following distances. This study is an initial step toward developing an understanding of the occupant injury risks associated with the multiple sequential impacts between truck platoons and roadside safety barriers, regardless of whether the crash is associated with a malfunction of automated control or human operation. Full-scale crash impacts of a tractor-trailer platoon into a concrete bridge guardrail were simulated for a specific Test Level condition according to the Manual for Assessing Safety Hardware (MASH) standards. The model of the bridge barrier was developed based on its drawings, and material properties were assigned according to literature data. The impact simulation of the first impact was validated against a full-scale crash test conducted by the Midwest Roadside Safety Facility (MwRSF) based on resulting vehicle kinematics and then a higher-fidelity truck cabin model including interior structures was used to evaluate the occupant dynamics and associated safety risks during the impact event. The injury risks of the truck occupants were evaluated using Hybrid-III (HIII) and Test device for Human Occupant Restraint (THOR) dummy occupant models representing a 50th percentile male. The occupant risks of injury calculated at body region level or overall showed low injury probabilities for vehicle occupants. The motions of the dummy model and the injury risks results suggested that the three-point seatbelt system employed in this study provided good protection for vehicle occupants in this impact scenario. Simulations with the Finite Element (FE) models developed in this study could help to understand the effectiveness of roadside safety device improvements and the necessity of platooning constraint modifications before utilization of truck platooning.
Jin, HanxiangSharma, RoshanMeng, YunzhuUntaroiu, AlexandrinaDoerzaph, ZacharyDobrovolny, Chiara SilvestriUntaroiu, Costin Daniel
Taking over vehicle control from a Level 3 conditionally automated vehicle can be a demanding task for a driver, to which great research effort has been contributed in recent years. Nevertheless, more attention should be given to the following aspects. The present research of take-over either only considers the influence of drivers’ visual and second task in single scenarios. However, the drivers’ NMS (Neuromuscular) characteristic hasn’t been investigated yet, especially in complex traffic scenarios. In this paper, a take-over experiment with complex traffic scenarios are conducted to observe the state of vehicle state and arm’ EMG (Electromyography) signal. After that, the driving styles are recognized based on the experimental data. Finally, a take-over level with driving style is proposed by clustering based on the condition of human-vehicle-road.
Hanbing, WeiYanhong, WuYuxuan, ZhangRui, Xu
The Principles of Operation Framework: A Comprehensive Classification Concept for Automated Driving Functions12-03-01-00032/18/2020
The levels of sustained vehicle automation, as recently updated by SAE in J3016 (status: 06/2018), have become common knowledge. They facilitate overall understanding of the issue. Sustained automation describes the shift in workload from purely human-driven vehicles to full automation. Duties of the driver are assigned to the machine as automation levels rise. Yet sustained driving automation does not cover “automated driving” as a whole. Automated driving functions operating on a nonsustained basis cannot be classified by means of levels describing continuous automation. Emergency braking, e.g., is obviously an intensive, but discontinuous, automation of a single task. It cannot be classified under the regime of sustained automation. The resulting lack of visibility of these important functions cannot satisfy - especially in the light of effect they take on traffic safety. Therefore, in order to reach a full picture of automated driving, this article proposes a comprehensive approach that can map out different characteristics as “Principles of Operation” at top level. On this basis informing and warning functions as well as functions intervening only temporarily in near-accident situations can be described. Moreover levels for temporarily intervening functions are proposed - meant to be the counterpart of the sustained levels already in place. This results in a detailed and independent classification for accident-prone situations and finally provides for the visibility these important functions deserve in the context of ongoing discussions on the larger “Automated Driving” issue.
Shi, ElisabethGasser, Tom MichaelSeeck, AndreAuerswald, Rico
Footrest Design to Reduce Lower Leg Injury in Frontal Crashes2019-36-00901/13/2020
The frontal impact is the most common vehicle crash type in accidents involving cars. During a vehicle frontal impact, the injuries are caused by occupant body moving forward and impacting the vehicle interior parts. The performance of the vehicle body and the interior parts design may influence on the occupant injury levels. Injuries in the occupant lower body are usually affected by the vehicle lower body deformation and the design of the interior lower parts (lower instrument panel, pedals, floor and footrest). When the purpose is to reduce the injury of a specific body region, the modification of the interior part design can be more effective in terms of impacts in mass, costs and development time than a modification in the vehicle body. The objective of the study was to develop a new footrest design to reduce the injury level of the left driver leg in a frontal crash condition. It was also evaluated the influence of the vehicle body deformation on the driver leg injury. There were manufactured footrest prototypes with different shapes and materials to check the influence on the leg injury. There were performed physical sled tests to evaluate the performance of different parts designs. The tests shown an average of 40% reduction in the leg injury with the new parts. The influence on the footrest usability (comfort) with the different shapes and materials was also considered. It was possible to reduce the injury to required levels and keep footrest comfort at acceptable levels. The best solution meet the safety, comfort and costs targets to allow parts regular production.
Kimura, Tsuguo EduardoRossi, Gilvan Pradade Freitas, Paulus Hanser
This SAE EDGE™ Research Report identifies key unsettled issues of interest to the automotive industry regarding the challenges of achieving optimal model fidelity for developing, validating, and verifying vehicles capable of automated driving. Three main issues are outlined that merit immediate interest: First, assuring that simulation models represent their real-world counterparts, how to quantify simulation model fidelity, and how to assess system risk. Second, developing a universal simulation model interface and language for verifying, simulating, and calibrating automated driving sensors. Third, characterizing and determining the different requirements for sensor, vehicle, environment, and human driver models. SAE EDGE™ Research Reports are preliminary investigations of new technologies. The three technical issues identified in this report need to be discussed in greater depth with the aims of, first, clarifying the scope of the industry-wide alignment needed; second, prioritizing the issues requiring resolution; and, third, creating a plan to generate the necessary frameworks, practices, and protocols. NOTE: SAE EDGE™ Research Reports are intended to identify and illuminate key issues in emerging, but still unsettled, technologies of interest to the mobility industry. The goal of SAE EDGE™ Research Reports is to stimulate discussion and work in the hope of promoting and speeding resolution of identified issues. SAE EDGE™ Research Reports are not intended to resolve the issues they identify or close any topic to further scrutiny. Click here to access the full SAE EDGETM Research Report portfolio.
Beiker, Sven
Localization Requirements for Autonomous Vehicles12-02-03-00129/24/2019
Autonomous vehicles require precise knowledge of their position and orientation in all weather and traffic conditions for path planning, perception, control, and general safe operation. Here we derive these requirements for autonomous vehicles based on first principles. We begin with the safety integrity level, defining the allowable probability of failure per hour of operation based on desired improvements on road safety today. This draws comparisons with the localization integrity levels required in aviation and rail where similar numbers are derived at 10−8 probability of failure per hour of operation. We then define the geometry of the problem where the aim is to maintain knowledge that the vehicle is within its lane and to determine what road level it is on. Longitudinal, lateral, and vertical localization error bounds (alert limits) and 95% accuracy requirements are derived based on the United States (US) road geometry standards (lane width, curvature, and vertical clearance) and allowable vehicle dimensions. For passenger vehicles operating on freeway roads, the result is a required lateral error bound of 0.57 m (0.20 m, 95%), a longitudinal bound of 1.40 m (0.48 m, 95%), a vertical bound of 1.30 m (0.43 m, 95%), and an attitude bound in each direction of 1.50° (0.51°, 95%). On local streets, the road geometry makes requirements more stringent where lateral and longitudinal error bounds of 0.29 m (0.10 m, 95%) are needed with an orientation requirement of 0.50° (0.17°, 95%).
Reid, Tyler G.R.Houts, Sarah E.Cammarata, RobertMills, GrahamAgarwal, SiddharthVora, AnkitPandey, Gaurav
The Research on Validation and Verification Method of Configuration Data for IMA Resources Allocation2019-01-18509/16/2019
Integrated Modular Avionics (IMA) system comprises IMA platform and hosted applications. The IMA platform provides the hosted applications with shared resources, e.g. computing, memory, communication, health monitoring resources. As a bridge between them, the IMA configuration data specifies how these shared resources are allocated to each hosted application. The IMA configuration data, which is different from real hardware and software code, should be validated and verified as an important portion of IMA system. After a brief introduction of IMA system, development processes, and general means of compliance for certification, this paper proposed an Architecture Analysis and Design Language (AADL) model of IMA configuration based on a case study of airborne datalink system. Based on the model, the IMA configuration data is abstracted and categorized into several types, with the correspondent means of compliance identified for each type. Furthermore, the associated roles and responsibilities are discussed for IMA configuration data validation and verification. The IMA configuration data specific means of compliance, the validation and verification processes, the roles and responsibilities, together form a method for validating and verifying the IMA configuration data for shared resources allocation, which can be applied to all partitioning systems beyond avionics.
Wang, YunshengLi, Yan-xiao
Model-Based Software Development: Functional Safety Compliance via Built-In Tool Intelligence2019-01-10414/2/2019
Today’s automobiles are among the most sophisticated machines on the planet. Much of the functionality of modern automobiles emanates from embedded software features that control electronic, mechanical or pneumatic devices. Over the past few decades the number of software features and the associated code has grown exponentially and the respective embedded software systems have reached a level of complexity which is increasingly difficult to manage. As a consequence, recalls due to software defects have become a major concern and today constitute about 50% of the overall warranty cost [1]. Since the operation of automobiles has severe public safety implications, the development of embedded automotive software has become subject to stringent functional safety standards (ISO 26262) and compliance with these standards has become a major hurdle in the development of automotive software. This paper outlines a tool-based solution that satisfies an important subset of functional safety standards via built-in intelligence. The solution marks a major step towards an agile, safety compliant development process that does not impose restrictions regarding product innovation. The core concept of this tool-based solution is centralized architecture and data management. By way of this concept, the tool-based solution detects and prevents interface and data inconsistencies not only during the software development process but throughout the lifecycle of the software product.
Turin, Raymond C.
A 3D Simulation Methodology for Predicting the Effects of Blasts on a Vehicle Body2019-01-10334/2/2019
Triggered explosions are increasingly becoming common in the world today leading to the loss of precious lives under the most unexpected circumstances. In most scenarios, ordinary citizens are the targets of such attacks, making it essential to design countermeasures in open areas as well as in mobility systems to minimize the destructive effects of such explosive-induced blasts. It would be rather difficult and to an extent risky to carry out physical experiments mimicking blasts in real world scenarios. In terms of mechanics, the problem is essentially one of fluid-structure interaction in which pressure waves in the surrounding air are generated by detonating an explosive charge which then have the potential to cause severe damage to any obstacle on the path of these high-energy waves. An alternative to physical testing would be to use an advanced simulation technique such as an ALE (Arbitrary Lagrangian-Eulerian)-based explicit nonlinear finite element formulation implemented in a well-known solver such as LS-DYNA. It has been observed by the present authors that the previously reported explorations in this area are primarily laboratory testing of structural components supplemented with an axisymmetric or a 2D finite element analysis. In the present study, keeping in mind the need for evaluating the effect of an arbitrarily located blast on a complex system such as a passenger car, a 3D finite element modelling approach has been deployed for capturing the effect of a blast not only on the vehicle underbody but also on an occupant in the form of a Hybrid III dummy with a modified lower limb corresponding to a MIL-LX leg. Initially, the consistency of the present 3D ALE-based modeling approach is verified by obtaining good correlation of computed pressure-time curve at a point in space at a given distance from a 1.5 kg explosive charge, with a published test result. The study is then extended to the simulation of effect of blast on a passenger car represented by a previously-validated finite element model for front impact safety assessment.
Ramachandra, SankethDeb, AnindyaChou, Clifford
Influence of DISH, Ankylosis, Spondylosis and Osteophytes on Serious-to-Fatal Spinal Fractures and Cord Injury in Rear Impacts2019-01-10284/2/2019
Seats have become stronger over the past two decades and remain more upright in rear impacts. While head restraints are higher and more forward providing support for the head and neck, serious-to-fatal injuries to the thoracic and cervical spine have been seen in occupants with spinal disorders, such as DISH (diffuse idiopathic skeletal hyperostosis), ankylosis, spondylosis and/or osteophytes that ossify the joints in the spine. This case study addresses the influence of spinal disorders on fracture-dislocation and spinal cord injury in rear impacts with relatively upright seats. Nineteen field accidents were investigated where serious-to-fatal injuries of the thoracic and cervical spine occurred with the seat remaining upright or slightly reclined. The occupants were lap-shoulder belted, some with belt pretensioning and cinching latch plate. The occupants were older and had pre-existing disorders of the spine, including DISH, ankylosis, spondylosis and/or osteophytes that ossify the spinal joints. The crashes were summarized and the mechanism for injury was analyzed. The 19 cases involved fracture-dislocation and spinal cord injury at areas of the spine where DISH, ankylosis, spondylosis and/or osteophytes ossified the intervertebral soft tissues causing stiff and brittle joints that were vulnerable to fracture-dislocation by straightening of the spine. Published sled tests at 40 km/h (25 mph) with the 50th Hybrid III showed that peak chest acceleration was 13.5 ± 2.4 g (n=7) and head acceleration was 26.0 ± 12.0 g (n=8). Sled testing at 16 km/h (10 mph) with the BioRID IIg involved T1 x-accelerations of 12.6 ± 2.4 g (n=12) and head x-accelerations of 10.1 ± 0.2 g (n=12). These levels of acceleration are sufficient to fracture the calcified spine of the older occupants without ramping or moving off the support from the seatback and head restraint. A new injury mechanism for spinal fracture-dislocation is described in older occupants with spinal disorders. The occupant remains supported by the relatively upright seatback and high and forward head restraint. The accelerations that bring the occupant up to the delta V are sufficient to fracture-dislocate the calcified spine that tries to straighten in the crash.
Viano, DavidParenteau, ChantalWhite, Samuel
GPU Implementation for Automatic Lane Tracking in Self-Driving Cars2019-01-06804/2/2019
The development of efficient algorithms has been the focus of automobile engineers since self-driving cars become popular. This is due to the potential benefits we can get from self-driving cars and how they can improve safety on our roads. Despite the good promises that come with self-driving cars development, it is way behind being a perfect system because of the complexity of our environment. A self-driving car must understand its environment before it makes decisions on how to navigate, and this might be difficult because the changes in our environment is non-deterministic. With the development of computer vision, some key problems in intelligent driving have been active research areas. The advances made in the field of artificial intelligence made it possible for researchers to try solving these problems with artificial intelligence. Lane detection and tracking is one of the critical problems that need to be effectively implemented. The ability of a self-driving car to successfully drive from point A to point B without going off track is dependent on lane tracking. Lane tracking in self-driving cars is a computationally intensive task and a fast implementation is needed to help a self-driving car track lanes in real-time to make the right decision at the right time. Lane tracking in self-driving cars is also dependent on the visibility of lane markings on the road. It will be difficult for a self-driving car to track lanes if the lane marking has faded, blocked by an object, or there were no lane markings on the road. Most available lane tracking implementations in the literature do not give account to these two problems. Our implementation is to solve these two problems by using artificial intelligence techniques to track lanes in all conditions and using GPU computing on NVIDIA Jetson TX2 to speed-up the process.
Yusuf, AyomideAlawneh, Shadi
Evaluation of Harness Tightening Procedures for Child Restraint System (CRS) Sled Testing2019-01-06174/2/2019
Sled testing procedures should reflect a rigorous level of repeatability across trials and reproducibility across testing facilities. Currently, different testing facilities use various methods to set the harness tension for child restraint system (CRS) sled tests. The objective of this study is to identify which harness tightening procedure(s) produce tensions within a reasonable target range while showing adequate reproducibility, repeatability, and ease-of-use. Five harness tightening procedures were selected: A) FMVSS 213 procedure, B) a 3-prong tension gauge, C) ECE R44/R129 procedure, D) two finger method, and E) pinch test. Two CRS models were instrumented with a tension load cell in the harness system. Seven sled room operators were recruited to perform each of the five harness tightening procedures for ten repetitions apiece on both instrumented CRS using a Hybrid III 3-year-old. The static harness tension measured by the load cell was recorded after each procedure was completed. Data were analyzed for mean, variance, reproducibility, and repeatability. Operator feedback surveys were used to quantify ease-of-use. The ECE R44/R129 procedure produced harness tensions which were quite low. The two finger procedure produced the highest tensions while the 3-prong tension gauge, pinch test, and FMVSS 213 procedures produced mid-level tensions. Poor repeatability was apparent for all five harness tightening procedures. The FMVSS 213 method ranked lowest for ease-of-use. Operators preferred using the 3-prong gauge, two finger method, and pinch test. The load cell readings were sensitive to the order and direction in which the operators adjusted the harness components. High amounts of friction within the harness might prevent it from acting as a homogeneous, continuous system. Sequential tightening of the various sections of harness and/or monitoring the tension at multiple locations might be valuable.
Mansfield, JulieBaker, GretchenBolte, John
Enabling Efficient Functional Safety Audits - The Missing Link between ISO 26262 and Automotive SPICE2019-01-01444/2/2019
In the field of electric and electronic (E/E) design for the automotive industry, there are separate traditions related to functional safety and software quality assurance. Both relying on the evaluation of the processes used; Automotive SPICE provides detailed guidance on how to perform this evaluation whilst ISO 26262 does not and simply mention Automotive SPICE as one possible solution. ISO 26262 additionally requires for an evaluation of the functional safety achieved by the product and uses the process evaluation (or functional safety audit in ISO 26262 terms) to support the final functional safety assessment. The purpose is to evaluate the implementation of the necessary safety processes according to the claimed scope defined in the safety plan. Automotive SPICE does not make a distinction on whether the application of the software under evaluation is safety related or not. ISO 26262 requires formal functional safety audits as a minimum for the part of the life cycle activities related to elements having ASIL C and ASIL D requirements In this paper we show how the link between ISO 26262 and Automotive SPICE can be established by the formalization of a process assessment model (PAM) fulfilling the purpose of a functional safety audit according to ISO 26262. This PAM is named SS 7740, as it has been developed by industry contributors in Sweden. The second edition of SS 7740 is based on ISO 26262 Edition 1 and Automotive SPICE version 2.5. Currently work ongoing to publish Edition 3 of SS 7740, where the assessment model relates to the process capabilities called for by ISO 26262 Edition 2 and referencing the Automotive SPICE version 3.1 In ISO 26262 there is a general proposal to coordinate the functional safety audit with an Automotive SPICE assessment. However, it is also noted that the Automotive SPICE assessment as such is not sufficient for this purpose. This implies that a dedicated process assessment model, complementary to Automotive SPICE, is necessary in order to specifically audit the processes prescribed by ISO 26262. In the paper the complete structure of SS 7740 is described in detail, and it is also shown how combined Functional Safety Audits and Automotive SPICE Assessments are performed in a coordinated way.
Johansson, RolfJohannessen, PerBorg, JonasIbarra, Ireri
Estimation of the Relative Roles of Belt-Wearing Rate, Crash Speed Change, and Several Occupant Variables in Frontal Impacts for Two Levels of Injury2019-01-12194/2/2019
Driver injury probabilities in real-world frontal crashes were statistically modeled to estimate the relative roles of five variables of topical interest. One variable pertained to behavior (belt-wearing rate), one pertained to crash circumstances (speed change), and three pertained to occupant demographics (sex, age, and body mass index). The attendant analysis was composed of two parts: (1) baseline statistical modeling to help recover the past, and (2) sensitivity analyses to help consider the future. In Part 1, risk functions were generated from statistical analysis of real-world data pertaining to 1998-2014 model-year light passenger cars/trucks in 11-1 o’clock, full-engagement frontal crashes documented in the National Automotive Sampling System (NASS, 1997-2014). The selected data yielded a weighted estimate of 1,269,178 crash-involved drivers. Those data were parsed for four subpopulations: two levels of belt use (properly-belted vs. unbelted) and two levels of driver injury (moderate-to-maximum, MAIS2+ vs. serious-to-maximum, MAIS3+). For each subpopulation, a baseline statistical model was generated via logistic regression, cast as a function of the studied variables. Each risk function was assessed for statistical significance (p-value for each term) and statistical associativity (Goodman-Kruskal Gamma). The four resulting risk functions had some statistical insignificance and fair fidelity, with Gammas ranging from 0.54 to 0.73. However, the risk functions demonstrated excellent fidelity for estimating aggregate injury rates (function-estimated vs. directly-estimated). They were accordingly applied in Part 2. In Part 2, sensitivity studies were conducted by (a) perturbing the studied variables in the NASS dataset to generate thousands of hypothetical NASS files, (b) applying the risk functions to estimate attendant net injury rates, and (c) relating the net injury rates to the variations. Specifically, net injury rates and mean statistics were generated for 15,552 hypothetical NASS datasets involving both belted and unbelted drivers. Those data were then normalized by the means of the baseline NASS file. Finally, power functions were developed to relate the resulting dimensionless net injury-rate data to the five dimensionless predictor variables. Those functions demonstrated excellent fidelity (R2≥0.95), and their exponents helped quantify the relative role of the five studied variables. Belt-wearing rate and speed change were determined to be the most influential, followed by age, body mass index, and sex. These findings might help guide engineers and regulators.
Laituri, TonyHenry, ScottLi, Guosong
A Software Tool for Injury Analysis of Blast and Crash Data2019-01-12254/2/2019
In recent years the U.S. Army Tank-Automotive Research, Development, and Engineering Center (TARDEC) has been investigating the survivability and injury mechanisms of underbody blast and crash, and their effects on personnel, with the use of Anthropomorphic Test Devices (ATD), or crash test dummies. Injury Assessment Reference Values (IARV) for crash have been researched for decades, and the US Army Research Laboratory (ARL), some years ago, also developed IARVs for underbody blast for the Hybrid III 50th percentile ATD. More recently, TARDEC extended these IARVs for the 5th and 95th percentile. With the advent of TARDEC’s Occupant Protection Laboratory large amounts of data were accumulated, which brought an interest in automating the analysis, and so a software tool was developed. The interactive in-house written software, called ICalc, allows the user to open test data files acquired from blast testing, drop tower testing, and crash testing. Data can be automatically bias corrected (zeroed), filtered, and graphed with pertinent IARV functions automatically applied. Data from multiple sensor channels and multiple files may be graphed together for comparison and analysis. Besides being used interactively, the application can run “scripts” to graph a complete data test series automatically with the pertinent IARVs applied, along with calculated velocities and displacements for acceleration channels. A report document can be generated consisting of all accompanying graphs with an IARV summary table and bar chart showing percentage of injury for each data channel. The time to process the data and produce a report has been reduced from hours to minutes. The software is scheduled to be released under the open code software license agreement in early 2019.
Bryk, DarrylFoster, Craig
Items per page:
1 – 50 of 845