239
Constrained Autonomy
This chapter will not try to link the concept of constrained autonomy to h uman–
machine interface ( HMI) research as that is clearly outside the author’s expertise.
However, the proposal put forward here is that both trust and sensemaking to some
degree may be linked to the relationship between T MR and T DL . If the system consistently is able to determine T DL and alert the operator before T MR elapses, one can
argue that the operator should get more consistent trust in the automation system’s
ability, both to control the process under normal conditions and to warn the operator
when something requires the operator’s attention. It will be left to experts in the HMI
field to validate this proposal and investigate what consequences these ideas have for
the operator and for the design of the HMI. This issue is complex and it is difficult,
if not impossible to draw any clear conclusions on what is the best strategy for building a suitable level of operator trust ( Hoff & Bashir 2015). However, some issues that
seem to give positive effects are determinism in automation responses, minimizing
false alerts and making it as clear as possible what the automation system is able to
do, what it actually does and where the operator’s intervention is required. Again, it
can be argued that a higher emphasis on the deadlines and response times may be
important to achieve these objectives.
The remaining part of the chapter will concentrate on the technical aspects of
constrained autonomy and how it can be implemented.
THE OPERATIONAL ENVELOPE
The operational envelope ( OE) can be defined as “ The specific conditions under
which a given autonomous ship system is designed to function, including, but not
limited to, its environmental conditions and the different mission or voyage phases,
as well as all anticipated failures.” The definition of OE is based on the concept of the
“ Operational Design Domain” that was defined in SAE J3016 ( 2016) and developed
further for use on autonomous ships in Rødseth ( 2018). The name has later been
changed to operational envelope (OE) during the work on a standard terminology for
autonomous ships ( ISO 2020b).
The OE will be directly linked to the Ship Control Tasks ( SCT) which will specify the details of the different tasks or processes to be performed. The OE and SCT
will also specify the division of responsibilities between humans and automation.
The OE and SCT can be defined on basis of a “concept of operations” document,
or CONOPS. Figure 14.2 is a simplified object diagram that illustrates objects and
relationships related to the OE and SCT.
The two large boxes at the bottom left are the constraints on the OE given by operational limitations in the ship system as well as the properties of the environment.
Additional constraints will be added by the concept of operation, e.g. the ship cannot
operate at night or during wintertime ( phases and functions). The same factors that
define the constraints will also play a role in determining the dynamic conditions for
SCT.
The darker boxes represent the OE itself as well as the additional fall-back space
which contains minimum risk conditions ( MRCs). MRCs will be activated when the
limits of the OE are exceeded. The OE will normally be divided into subdivisions,
usually based on the mission phases and the relevant ship processes. As an example,
Précédent

- 262/293

Suivant