Safe Engineering: An Example of Application of a Recent Accident Model to Automated Driving
摘要
Safe roads and roadsides, safe vehicles, safe speed, safe road use, post-crash care: these are a summary of the safe system paradigm which is being popular for a few decades. Explicitly, this paradigm claims for safety by design. As for vehicles, concrete applications are technical regulations, standards, norms, car assessment program, codes of practices, guidelines, statements of principles, external and companies’ internal safety standards and verification/validation plans, etc. Obviously, safety by design starts by understanding and ends by proposing countermeasures to prevent/mitigate the hazards and their consequences. The starting point is therefore the use of a conceptual “accident model” required to bring insights with a formal structure into how crashes and injuries occur, how they should be analyzed and how they can be prevented or mitigated. The paper described the STAMP approach (Systems-Theoretic Accident Model and Processes), an accident causality model based on control theory and systems theory (Leveson in Engineering a safer world: systems thinking applied to safety. Engineering systems. MIT Press, Cambridge, MA, 2011). STAMP integrates into engineering safety analysis causal factors such as software, human factors, new technologies, social and organization structures and safety culture. It is designed to address complex systems. The method behind the approach is Systems-Theoretic Process Analysis (STPA), the hazard operational analysis technique (Leveson and Thomas in An STPA primer. MIT, Cambridge, MA, 2013; STPA handbook. The European Law Student’s Association, Brussels, 2018). STAMP and STPA now receive more and more attention and interest, especially when new technologies and complex systems are considered. STPA proposes a stepwise methodological process. Once the definitions of accidents/hazards/safety constraints are made, a control structure of the whole system must be described (including relationships, i.e., control actions and information feedback, between all components (or “controllers”) of the system). Every controller imposes control processes and safety constraints on the level underneath. Every controller has a process model that includes the understanding and representations that controllers have of the controlled process. They are kept up to date through feedback loops. Accidents occur when the system gets into a hazardous state due to the inadequate enforcement of safety constraints on the system behavior. An example of control structure at the micro level is proposed in the paper as for interactions between vehicles, users and environment for automated driving. An example of control at a higher or macro-level would show relationships (control and feedback) between all stakeholders (standardization and regulation bodies, European Commission, ministries, insurance companies, road vehicle industry, driving school, hospitals, road operators, etc.). The next step consists of identifying potential unsafe actions from one processor to another. They lead to listing a first series of safety requirements. The next step consists of identifying scenarios (or control flaws) that could lead to unsafe control actions. Leveson and Thomas (STPA handbook. The European Law Student’s Association, Brussels, 2018) give guidance on how the scenarios could be generated. Once the scenarios are determined, the safety requirements can be refined and enhanced. Generally, this refinement ends up increasing the number of initial requirements and making them more precise and accurate. The paper proposes to apply STPA to the safety of automated vehicles. A list of 63 macro safety requirements is proposed that can be used both for the design of such vehicles and eventually the analysis of crashes involving them.