ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles

Intland Software GmbH
Intland Software GmbH Intland Software GmbH
ISO/PAS 21448 (SOTIF) in the
Development of ADAS /
Autonomous Vehicles
Szabolcs Agai
Safety & Regulatory Expert, Intland Software
Laszlo Katona
Business Analyst, Intland Software
Agenda • Aspects of vehicle safety
• Scope of ASPICE, ISO 26262, and SOTIF
• ISO 26262 vs SOTIF
• Risk mitigation
• SOTIF use cases in codeBeamer
• codeBeamer’s SOTIF workspace design
• Founded in 1998, HQ in Stuttgart, Germany
• Active in safety-critical markets
for over 10 years
• Products and processes
certified by TÜV Nord and TÜV Süd
About
Intland Software
Factors customers consider when buying a car
Safety
Quality
Fuel consumption / Sustainability
Price
Ease of operation
Comfort
Technical innovation
Size / Storage space
Design
Resale value
Power of the engine
Brand image
Integrated communication
72 23
62 32
46 42
44 43
35 46
31 46
28 42
25 43
26 40
25 39
21 36
21 29
15 35
Very important
Rather important
*Source: E. &. Young, “Autonomes Fahren – Die Zukunft des PKW Marktes?”
Vehicle architecture
Purpose-built layers of components
Components:
Mechanical
Hardware
Software
Others (Liquids, oils, glues, etc.)
OEM – Tier 1 – Tier 2 – … – Tier n
Aspects of vehicle safety
Passive
safety
Active
safety
Functional
safety
Lessons learned
Automotive value
chain
Final
Assembly
Light module
Cockpit Door system
Control unit Window
Radio unit Handles Cladding
Individual parts
Domain Domain HW Scope View
OEM Vehicle
OEM Tier 1 Subsystem
Tier 1 ECU
Tier 2 MCU
OEM
Suppliers
Automotive standards & regulatory landscape
Vienna Convention on Road Traffic 1968, AMD 2016
SAE J 3016-2018
Useful Safe
ISO 11270:2014 LKAS
ISO 15622:2018 ACC
ISO 17387:2008 LCDAS
Automotive SPICE
ISO 26262:2018
ISO/PAS 21448:2019
SOTIF
UL 4600:2020
Safety standards
Safety
Functional Safety
ISO 26262
SOTIF
Cybersecurity
ASPICE
Question to the audience:
What is your company’s greatest
challenge with regards to safety
standards?
Scope of ASPICE
5
4
3
2
1
Generic Practice
Generic Resources
Base
Practices
Work
Products
ISO 26262
Scope of ISO 26262
Random
errors
Systematic
errors
We can calculate, estimate,
and plan for failures
Control:
Safety Analysis
(DFMEA,PFMEA,FMEDA,
DFA, etc. - ISO 26262)
(SW & HW Design)
Probability is 100%, failures
can come anytime
Control:
Process control measures
(ASPICE, ISO 26262)
Scope of SOTIF
Safety Technique Process Definition
Methods
Lifecycle
Scope of SOTIF regarding SAE levels
Assisted
Partial automation
Conditional automation
High automation
Full automation
SOTIF
Performance
limitations
Disturbances of
sensors and
algorithms
Failed human
interaction including
misuse
Differences between ISO 26262 and SOTIF
ISO 26262
Malfunctioning E/E system due to failures
SOTIF
Malfunctioning failure-free system
Failure scenario analysis
Unsafe Safe
Known
Unknown
2 1
3 4
Mitigation of risks
1
4 4
1
3
2
3
2
Known 2 1
Unsafe Safe
Unknown 3 4
Types of testing for risk mitigation
Simulation HIL Test Closed Track Public Road
codeBeamer use cases based on SOTIF
Safety Technique
Lifecycle &
Process Definition
Methods
Use case 1 Use case 2
Use case 3
Use case 1: SOTIF Lifecycle and processes
Intended functionality
Hazards
Triggering events
SOTIF risk mitigation
V&V strategy
Verification area 2
Validation area 3
SOTIF release
Use case 2: Methods
Accidents (FARS, etc.)
Road collections
Critical sets
Others
Variables (environment)
Driver
fault
Sensor errors
Performance
Permutation
Driving Simulator
HIL Tests
Closed track tests
Scenario
Repository
ADAS scenario management in codeBeamer
ADAS scenario management in codeBeamer
Scenario development process
Scenario description language
Scenario description language
Use case 3: Safety technique
Known and
unknown
triggering effects
(including
reasonably
foreseeable
misuse) as part of
the scenario
Occurence over
the operating
lifetime
Outputs: SOTIF-relevant hazardous events (leading to credible harm)
& acceptance criteria (Validation targets)
Potentially
hazardous
behaviour
System
Hazard
Operational
Situation
Probability of
exposure
&
Hazardous
Event
& Harm
Reactions of the
involved persons
Controllability
Severity
Legend: Causality Evaluated characteristics
codeBeamer’s SOTIF workspace design
Processes
Methods
Practices
Roles
Activities
Stages
Collaborative
workflows
Work products
Roles
Activities
Stages
Intelligent
design
contents
codeBeamer’s SOTIF workspace design
Workflows
Information Access Roles
Contents
ALM
codeBeamer’s SOTIF workspace design
Workflows
Information Access Roles
Contents
ALM - Automotive Template
SOTIF
example
workspace
Live demo:
SOTIF Workspace in
codeBeamer
Questions and Answers
1 de 36

Mais conteúdo relacionado

Mais procurados(20)

ISO 26262 Unit Testing | Functional Safety in Automotive ISO 26262 Unit Testing | Functional Safety in Automotive
ISO 26262 Unit Testing | Functional Safety in Automotive
Embitel Technologies (I) PVT LTD473 visualizações
Requirements of ISO 26262Requirements of ISO 26262
Requirements of ISO 26262
Torben Haagh2K visualizações
Introduction to functional safetyIntroduction to functional safety
Introduction to functional safety
Cefriel8.7K visualizações
HARA ISO 26262: What is HARA and Why is it Required?HARA ISO 26262: What is HARA and Why is it Required?
HARA ISO 26262: What is HARA and Why is it Required?
Embitel Technologies (I) PVT LTD561 visualizações
Frequently Asked Question (FAQ's)  on ISO 26262 Functional SafetyFrequently Asked Question (FAQ's)  on ISO 26262 Functional Safety
Frequently Asked Question (FAQ's) on ISO 26262 Functional Safety
Embitel Technologies (I) PVT LTD2.2K visualizações
How to Apply Functional Safety to Autosar ECU'sHow to Apply Functional Safety to Autosar ECU's
How to Apply Functional Safety to Autosar ECU's
Renesas America893 visualizações
Iso26262 component reuse_webinarIso26262 component reuse_webinar
Iso26262 component reuse_webinar
محمدعبد الحى4K visualizações
19 Jun 2018 - Hazard Analysis and Functional Safety Compliance 19 Jun 2018 - Hazard Analysis and Functional Safety Compliance
19 Jun 2018 - Hazard Analysis and Functional Safety Compliance
Intland Software GmbH 823 visualizações
S.steele functional safety pptS.steele functional safety ppt
S.steele functional safety ppt
Simon Steele2.3K visualizações
Functional safety standards_for_machineryFunctional safety standards_for_machinery
Functional safety standards_for_machinery
ie-net ingenieursvereniging vzw1.3K visualizações
SEooC ISO 26262 | What is Safety Element Out of Context in Automotive Functio...SEooC ISO 26262 | What is Safety Element Out of Context in Automotive Functio...
SEooC ISO 26262 | What is Safety Element Out of Context in Automotive Functio...
Embitel Technologies (I) PVT LTD1.3K visualizações
Achieve iso 26262 certificationAchieve iso 26262 certification
Achieve iso 26262 certification
PRQA11K visualizações
AUToSAR introductionAUToSAR introduction
AUToSAR introduction
ELAbbasSalahHatata3.6K visualizações
Automotive SPICE Level 3 and Beyond with codeBeamer ALMAutomotive SPICE Level 3 and Beyond with codeBeamer ALM
Automotive SPICE Level 3 and Beyond with codeBeamer ALM
Intland Software GmbH 2.9K visualizações

Similar a ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles

AutoSpice Agile Hand in HandAutoSpice Agile Hand in Hand
AutoSpice Agile Hand in HandRuchika Sachdeva
4.7K visualizações21 slides
FuSA_upload.pptxFuSA_upload.pptx
FuSA_upload.pptxssuser058892
24 visualizações18 slides
ISO-26262-Webinar.pptxISO-26262-Webinar.pptx
ISO-26262-Webinar.pptxKarthika Keshav
87 visualizações24 slides

Similar a ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles(20)

AutoSpice Agile Hand in HandAutoSpice Agile Hand in Hand
AutoSpice Agile Hand in Hand
Ruchika Sachdeva4.7K visualizações
FuSA_upload.pptxFuSA_upload.pptx
FuSA_upload.pptx
ssuser05889224 visualizações
ISO-26262-Webinar.pptxISO-26262-Webinar.pptx
ISO-26262-Webinar.pptx
Karthika Keshav87 visualizações
Verification of IVI Over-The-Air using UML/OCLVerification of IVI Over-The-Air using UML/OCL
Verification of IVI Over-The-Air using UML/OCL
Seungjoo Kim1.3K visualizações
Sw qual joint webinar deck (5)Sw qual joint webinar deck (5)
Sw qual joint webinar deck (5)
Seapine Software1.2K visualizações
Webinar: Traceability Over the Entire Lifecycle in codeBeamerWebinar: Traceability Over the Entire Lifecycle in codeBeamer
Webinar: Traceability Over the Entire Lifecycle in codeBeamer
Intland Software GmbH 430 visualizações
Top 5 best practice for delivering secure in-vehicle softwareTop 5 best practice for delivering secure in-vehicle software
Top 5 best practice for delivering secure in-vehicle software
Rogue Wave Software 811 visualizações
ProSET BrochureProSET Brochure
ProSET Brochure
Simon Burwood170 visualizações
Why safety plan is critical in development of iso 26262 complaint Why safety plan is critical in development of iso 26262 complaint
Why safety plan is critical in development of iso 26262 complaint
Embitel Technologies (I) PVT LTD222 visualizações
Agile + ISO 26262: Using Agile in Automotive DevelopmentAgile + ISO 26262: Using Agile in Automotive Development
Agile + ISO 26262: Using Agile in Automotive Development
Intland Software GmbH 1.6K visualizações
Managing securityforautomotivesocManaging securityforautomotivesoc
Managing securityforautomotivesoc
Pankaj Singh805 visualizações
Towards 0-bug software in the automotive industryTowards 0-bug software in the automotive industry
Towards 0-bug software in the automotive industry
Ashley Zupkus104 visualizações

Mais de Intland Software GmbH (20)

Dr. Andreas Birk: Agile Practices for Medical Device DevelopmentDr. Andreas Birk: Agile Practices for Medical Device Development
Dr. Andreas Birk: Agile Practices for Medical Device Development
Intland Software GmbH 1K visualizações
Dr. Andreas Birk: Approaches to Agile in Medical Device DevelopmentDr. Andreas Birk: Approaches to Agile in Medical Device Development
Dr. Andreas Birk: Approaches to Agile in Medical Device Development
Intland Software GmbH 1.3K visualizações

Último(20)

.conf Go 2023 - SIEM project @ SNF.conf Go 2023 - SIEM project @ SNF
.conf Go 2023 - SIEM project @ SNF
Splunk134 visualizações
ISWC2023-McGuinnessTWC16x9FinalShort.pdfISWC2023-McGuinnessTWC16x9FinalShort.pdf
ISWC2023-McGuinnessTWC16x9FinalShort.pdf
Deborah McGuinness80 visualizações
ChatGPT and AI for Web DevelopersChatGPT and AI for Web Developers
ChatGPT and AI for Web Developers
Maximiliano Firtman143 visualizações
Green Leaf Consulting: Capabilities DeckGreen Leaf Consulting: Capabilities Deck
Green Leaf Consulting: Capabilities Deck
GreenLeafConsulting147 visualizações
Java Platform Approach 1.0 - Picnic MeetupJava Platform Approach 1.0 - Picnic Meetup
Java Platform Approach 1.0 - Picnic Meetup
Rick Ossendrijver20 visualizações
[2023] Putting the R! in R&D.pdf[2023] Putting the R! in R&D.pdf
[2023] Putting the R! in R&D.pdf
Eleanor McHugh31 visualizações
METHOD AND SYSTEM FOR PREDICTING OPTIMAL LOAD FOR WHICH THE YIELD IS MAXIMUM ...METHOD AND SYSTEM FOR PREDICTING OPTIMAL LOAD FOR WHICH THE YIELD IS MAXIMUM ...
METHOD AND SYSTEM FOR PREDICTING OPTIMAL LOAD FOR WHICH THE YIELD IS MAXIMUM ...
Prity Khastgir IPR Strategic India Patent Attorney Amplify Innovation22 visualizações
Architecting multi-cloud ready applicationsArchitecting multi-cloud ready applications
Architecting multi-cloud ready applications
Swaminathan Vetri43 visualizações
CXL at OCPCXL at OCP
CXL at OCP
CXL Forum158 visualizações
AMD: 4th Generation EPYC CXL DemoAMD: 4th Generation EPYC CXL Demo
AMD: 4th Generation EPYC CXL Demo
CXL Forum113 visualizações
Web Dev - 1 PPT.pdfWeb Dev - 1 PPT.pdf
Web Dev - 1 PPT.pdf
gdsczhcet44 visualizações
PyCon ID 2023 - Ridwan Fadjar Septian.pdfPyCon ID 2023 - Ridwan Fadjar Septian.pdf
PyCon ID 2023 - Ridwan Fadjar Septian.pdf
Ridwan Fadjar161 visualizações
Business Analyst Series 2023 -  Week 2 Session 3Business Analyst Series 2023 -  Week 2 Session 3
Business Analyst Series 2023 - Week 2 Session 3
DianaGray10290 visualizações

ISO/PAS 21448 (SOTIF) in the Development of ADAS and Autonomous Vehicles

  • 1. ISO/PAS 21448 (SOTIF) in the Development of ADAS / Autonomous Vehicles Szabolcs Agai Safety & Regulatory Expert, Intland Software Laszlo Katona Business Analyst, Intland Software
  • 2. Agenda • Aspects of vehicle safety • Scope of ASPICE, ISO 26262, and SOTIF • ISO 26262 vs SOTIF • Risk mitigation • SOTIF use cases in codeBeamer • codeBeamer’s SOTIF workspace design
  • 3. • Founded in 1998, HQ in Stuttgart, Germany • Active in safety-critical markets for over 10 years • Products and processes certified by TÜV Nord and TÜV Süd About Intland Software
  • 4. Factors customers consider when buying a car Safety Quality Fuel consumption / Sustainability Price Ease of operation Comfort Technical innovation Size / Storage space Design Resale value Power of the engine Brand image Integrated communication 72 23 62 32 46 42 44 43 35 46 31 46 28 42 25 43 26 40 25 39 21 36 21 29 15 35 Very important Rather important *Source: E. &. Young, “Autonomes Fahren – Die Zukunft des PKW Marktes?”
  • 5. Vehicle architecture Purpose-built layers of components Components: Mechanical Hardware Software Others (Liquids, oils, glues, etc.) OEM – Tier 1 – Tier 2 – … – Tier n
  • 6. Aspects of vehicle safety Passive safety Active safety Functional safety
  • 8. Automotive value chain Final Assembly Light module Cockpit Door system Control unit Window Radio unit Handles Cladding Individual parts Domain Domain HW Scope View OEM Vehicle OEM Tier 1 Subsystem Tier 1 ECU Tier 2 MCU OEM Suppliers
  • 9. Automotive standards & regulatory landscape Vienna Convention on Road Traffic 1968, AMD 2016 SAE J 3016-2018 Useful Safe ISO 11270:2014 LKAS ISO 15622:2018 ACC ISO 17387:2008 LCDAS Automotive SPICE ISO 26262:2018 ISO/PAS 21448:2019 SOTIF UL 4600:2020
  • 10. Safety standards Safety Functional Safety ISO 26262 SOTIF Cybersecurity ASPICE
  • 11. Question to the audience: What is your company’s greatest challenge with regards to safety standards?
  • 12. Scope of ASPICE 5 4 3 2 1 Generic Practice Generic Resources Base Practices Work Products
  • 13. ISO 26262 Scope of ISO 26262 Random errors Systematic errors We can calculate, estimate, and plan for failures Control: Safety Analysis (DFMEA,PFMEA,FMEDA, DFA, etc. - ISO 26262) (SW & HW Design) Probability is 100%, failures can come anytime Control: Process control measures (ASPICE, ISO 26262)
  • 14. Scope of SOTIF Safety Technique Process Definition Methods Lifecycle
  • 15. Scope of SOTIF regarding SAE levels Assisted Partial automation Conditional automation High automation Full automation SOTIF
  • 19. Differences between ISO 26262 and SOTIF ISO 26262 Malfunctioning E/E system due to failures SOTIF Malfunctioning failure-free system
  • 20. Failure scenario analysis Unsafe Safe Known Unknown 2 1 3 4
  • 21. Mitigation of risks 1 4 4 1 3 2 3 2 Known 2 1 Unsafe Safe Unknown 3 4
  • 22. Types of testing for risk mitigation Simulation HIL Test Closed Track Public Road
  • 23. codeBeamer use cases based on SOTIF Safety Technique Lifecycle & Process Definition Methods Use case 1 Use case 2 Use case 3
  • 24. Use case 1: SOTIF Lifecycle and processes Intended functionality Hazards Triggering events SOTIF risk mitigation V&V strategy Verification area 2 Validation area 3 SOTIF release
  • 25. Use case 2: Methods Accidents (FARS, etc.) Road collections Critical sets Others Variables (environment) Driver fault Sensor errors Performance Permutation Driving Simulator HIL Tests Closed track tests Scenario Repository
  • 26. ADAS scenario management in codeBeamer
  • 27. ADAS scenario management in codeBeamer
  • 31. Use case 3: Safety technique Known and unknown triggering effects (including reasonably foreseeable misuse) as part of the scenario Occurence over the operating lifetime Outputs: SOTIF-relevant hazardous events (leading to credible harm) & acceptance criteria (Validation targets) Potentially hazardous behaviour System Hazard Operational Situation Probability of exposure & Hazardous Event & Harm Reactions of the involved persons Controllability Severity Legend: Causality Evaluated characteristics
  • 32. codeBeamer’s SOTIF workspace design Processes Methods Practices Roles Activities Stages Collaborative workflows Work products Roles Activities Stages Intelligent design contents
  • 33. codeBeamer’s SOTIF workspace design Workflows Information Access Roles Contents ALM
  • 34. codeBeamer’s SOTIF workspace design Workflows Information Access Roles Contents ALM - Automotive Template SOTIF example workspace
  • 35. Live demo: SOTIF Workspace in codeBeamer