Functional Safety (ISO26262) And SOTIF (ISO/PAS21448) Webinar

Transcription

Functional Safety (ISO26262) and SOTIF (ISO/PAS21448)WebinarDr. Arnulf Braatz/Andreas Horn, June 16th 2020V1.10 2020-05-12

Welcome and IntroductionWebinar: Functional Safety and SOTIFSpeaker:Dr. Arnulf BraatzQ&A:Andreas HornTechnical Notes2/28 AudioThere should be music to hear.If the audio transmission over the Internet is notworking, ask for the participation in a conference call.Contact the "host" in the "chat" window. ScreenDisable your screen saver. Feedback & communicationOpen and review the "chat" window to get all organizational messages of the "hosts".Use the "chat" window to the "host" to contact all organizational WebEx and transfer requests or disturbances.Use the "Q & A" window instead of the "chat" window for substantive questions about the webinar.Ask your questions at "All Panelists". Questions are answered online during and after the presentation. Slides & PresentationWithin 1-2 days after the webinar, you will receive a link to the slides and additional information.After the webinar a link will guide you to a feedback form.We are looking forward to receiving your feedback to continuously improve our services. 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Welcome and IntroductionVector Group DevelopmentVector provides tools for developing,testing, calibration and diagnosticsas well as software components anddevelopment services.USAFranceDetroitParisGermanyStuttgart, Brunswick, Hamburg, Karlsruhe, Munich, RegensburgGreat BritainSwedenBirminghamGothenburgNetworkingVector provides components andengineering services for thenetworking of electronic systems.JapanTokyo, NagoyaItalyOptimizationVector provides a comprehensiveconsulting portfolio as well assuitable tools o Paulo3/28India 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12ChinaShanghai

Welcome and IntroductionVector Client Survey 2020: Risk of vicious circleLong-term challenges70%Safety &Security60%Quality50%Innovative productsFlexibility30%Vicious cycle: cost pressure lack of competences less innovation and quality Complexity Distributeddevelopment20%10%Competencesand knowledgeDigital transformation40%Cost term ChallengesVector Client Survey 2020.Details: www.vector.com/trends.Horizontal axis shows short-term challenges;vertical axis shows mid-term challenges.Sum 300% due to 5 answers per question. Strongvalidity with 4% response rate of 2000 recipients fromdifferent industries worldwide.Vector provides tailored consulting solutions to keep OEM and suppliers competitive:Efficiency – Quality – Competences4/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

AgendaWelcome and Introduction Challenges and ConceptsVector Safety ExperiencesConclusions and Outlook5/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsMany functions are safety relatedElectrical Power SteeringUnintended steering andloss of steering assistCollision AvoidanceAcceleration instead ofdeceleration in trafficElectronic Park BrakeUnintended activationin motionAirbagUnintended deploymentduring normal operationMal-functions caused by failures of E/E systems6/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsFunctional Safety – Wide ImpactIdeaSystemTestSystemReq. AnalysisSystemIntegrationSystemDesignComponentReq. AnalysisOEMSupplierManagement ActivityComponentDesignEngineering ActivityAffected by ISO nagementWide impact on entire life-cycle Risk of gaps and inconsistencies7/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsEffectFunctional Safety – Many MethodsHazardInability to performthe required functionas specifiedFailureFailureFailure4Incorrect state thatmay lead to a failureCause of the error,e.g. code mistakeErrorX1FaultX2Error3XErrorXFaultFaultSystem layer1 Fault prevention Guidelines Processes2 Fault detection Code analysis Review, Test3 Fault tolerance Redundant design Memory protection4 Robustness Redundant shut-off Fail-operationalMany methods and techniques Risk of uninformed usage8/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsParts of ISO 26262:2018 – 2nd Edition – Main ChangesISO/PAS 21448 Road vehicles -- Safety of the intended functionality (SOTIF)1. Vocabulary2. Management of functional safety3. Conceptphase4. Product development at thesystem level12. Adaption ofISO 26262 formotorcycles5. Productdevelopment atthe hardwarelevel7. Productionand operation6. Productdevelopment atthe softwarelevel8. Supporting processes8-13 to 8-169. ASIL-oriented and safety-oriented analyses10. Guideline on ISO 2626211. Application of ISO 26262 to semiconductor9/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsScope of SOTIF (ISO/PAS 21448)Safety of the intended functionality (SOTIF) – The absence of unreasonable risk due to hazardsresulting from functional insufficiencies of the intended functionality or by reasonably foreseeable misuseby persons.Area 2 & 3 toolarge meansunacceptableresidual risk4123SOTIF activitiesprovide anargument thatthe residual riskis acceptablePAS 21448 Maximize Area 1 Minimize Area 2 & 3StartingPointGoal for thefinishedDevelopmentPAS 21448, chapter4, figure 8Unknown safe scenarios (Area 4)known safe scenarios (Area 1)known unsafe scenarios (Area 2)MentalModelunknown unsafe scenarios (Area 3)Note: Intentional alteration of the system operation (Feature abuse) is not in scope.10/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsOverview Automotive Safety: Functional Safety & SOTIFSOTIF: Triggering events are analyzed if acceptable or function needs to be modified.Triggering event:Limited max torqueTriggering event:Camera sensor blindedby sunsetMisuse: Applinghighway traffic signrecognition in urbantrafficFunctional Safety: Methods required by ISO 26262 focus on those faults need to be identified and mitigated, whichpotentially violate a safety goal. systematic & random faults of HW &SW11/28 known limitations of sensors, actuators and algorithms, environmental conditions and foreseeable misuse (PAS 214448, Chapter 7.2) 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsLegal Liability: State of the art of science and technologyProcessConferences, white papers, etc.-Safety ManagementProject ManagementRisk ManagementQuality AssuranceRequirements-Mgmt.Configuration-Mgmt.Test Management ISO 26262Process governance (e.g. CMMI, SPICE)Basic regulations: Laws, statutory provisions, nongovernmental standards (ISO9001, ISO/TS 16949, etc.)Technology- Measures against random HWfailures- Measures against systematic failures(System, HW, SW)- Development of safety concepts- Implementation of safetymechanisms- Methods- FMEA,FTA- FMEDA- Analysis of dependent failures- ASIL decomposition- 12/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsBasic Concept of ISO 26262: Risk Classification by „ASIL“RiskR SeverityxProbabilitySPEx sary IntegrityASILAutomotive Safety Integrity Level( required integrity of a function)ResidualRiskToleratedRiskE/E functionsRisk byadd. FunctionSafety functionsRisk levelSource: IEC 61508:201013/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsDevelopment – HARA for deriving Safety Goals and ASILMalfunction ofAdaptive Front SteeringECSASILNo superimposition 100 km/hHighwayWet roadE3C1S3ASteering inversion 50 km/h 100 km/hMain RoadDry roadE4C3S3DOversteering 50 km/h 100 km/hMain RoadDry roadE4C3S3DOversteeringParking 10 km/hSide RoadDry roadE4C1S1QMExposure: E3: 1-10% of averageoperating time E4: 10% of averageoperation time14/28Operational SituationControllability (Average Driver): C1: Hazardous situation is simplycontrollable C3: Hazardous situation is usually notcontrollable 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12Severity: S1: Light to moderateinjuries S3: Critical injuries

Challenges and ConceptsEfficient Traceability and ConsistencySafety GoalsSG1HZ1, HZ3 ASIL BHazard Analysis &Risk AssessmentSafety Goal 1SG2HZ2ASIL D.Item DefinitionSafety Goal 2System ArchitecturalDesign (external input).Functional SafetyConceptFunctional Safety RequirementsFSR 1SG1ASIL BFunct. Safety Req. 1FSR 2SG1ASIL BFunct. Safety Req. 2.Allocation of FSRs toarchitectural elements.Refinement ofArchitectural DesignTechnical SafetyConceptTechnical Safety RequirementsRequirementsTSR 1.1FSR Technical1ASIL B SafetyKomp1Tech. Safety Req. 1.1TechnicalSafetyRequirementsTSR 1.1FSR 1ASIL BKomp1Tech. Safety Req. 1.1Allocation of TSRs toarchitectural elementsTSR 1.2FSR 1ASIL BKomp1Tech. Safety Req. 1.2TSR 1.1FSR 1ASIL BHW/SW Tech. Safety Req. 1.1TSR 1.2FSR 1ASIL BKomp1Tech. Safety Req. 1.2.TSR 1.2FSR 1ASIL BHW/SW Tech. Safety Req. 1.2.15/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12System Architectural Design

Challenges and ConceptsFMEA and FTA – Safety Analysis on System and HW levelMost common methods forsafety-oriented analysesFMEA16/28FTA Failure Mode Effect Analysis Fault Tree Analysis Inductive analysis method Deductive analysis method Used to identify root causes offailures and effects of failures inthe system. Used to identify root causes offailures and their correlation inthe system. Can only be applied to an existingdesign or implementation. Development of designalternatives Discovery of unexpectedscenarios 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and ConceptsApproaches to Risk ReductionObjectives:FailureRandomFailure RedundancySafety mechanisms(“Diagnostics”)Self-tests Technical measures againstsystematic system, HW andSW failures: Make unavoidable failures safeRedundancyDiagnosticsSelf-testsModular HW/SWarchitectureArchitecture patternsDefensive programming Methodological measures to ensurethe application of a safety-conformdevelopment process: Top-down design flow Requirements based engineering Design methods Analysis techniques Test methods Traceability Reproducibility Detailed process requirements Process MeasuresProduct MeasuresISO26262 (ASIL)17/28Avoid failuresSystematicFailureTechnical measures againstrandom HW failures: 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Challenges and Concepts?Your Questions?Remark: If we are not able to answer your question within the hour we will send you the answer viamail in the coming days!18/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

AgendaWelcome and IntroductionChallenges and Concepts Vector Safety ExperiencesConclusions and Outlook19/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Vector Safety ExperiencesVector Experiences – Support Throughout the Life-CycleSystemReq. AnalysisItem DefinitionHazard andRisk AnalysisSystem SafetyConceptQualitativeSafety AnalysesSystemDesignComponentReq. omponentImplementationDIASafety tionQuantitativeSafety AnalysesConsistently plan and systematically maintain safety artefacts20/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Vector Safety ExperiencesExample SW Safety Analysis - SW-FMEA: Vector Best (D)6RPNComponentSystemFailure Effect12Root casueSW Safety Analysis assumes occurrence of SW faults based on complexity of SW.21/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Vector Safety ExperiencesExample FSC – SysML Block Diagram as Vector Best PracticeSysML is a semiformal notation andrecommended byISO 26262:Functional safety is about requirements & solution development (Two-Pillar approach)22/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Vector Safety ExperiencesVector Experiences – Development Interface Agreement (DIA)List of relevantartefactsMinimum scope: 60 artefactsProject specific tailoring, applicationand trackingOEMUse the DIA for comprehensive definition of the customer/supplier interfaces. Extend theusage to not safety related artefacts23/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Vector Safety ExperiencesVector Experiences – Security Directly Impacts SafetyFunctional Safety(ISO/PAS21448, ISO 26262) Hazard analysisand risk assessmentFunctions and risk mitigationSafety engineeringAssets, Threatsand RiskAssessmentSecurity GoalsandRequirementsSafety GoalsandRequirementsSecurityConceptSecurity not sufficiently addressedSecurityImplementationFunctional andTechnicalSafetyConceptSafetyImplementation Security architecture(J3061,ISO/SAE 21434) methods dataformatsfunctionality Threat,&Attackand risk analysis Attack paths and vulnerabilities Security engineering- Security & Safety are interactingand demand holistic systems engineering- For fast start security engineering shouldbe connected to safety framework24/28SafetyManagementafter SOPOp. Scenarios,Hazard, RiskAssessment 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12Safety erificationSecurity ificationSecurityManagementin Service

AgendaWelcome and IntroductionChallenges and ConceptsVector Safety Experiences 25/28Conclusions and Outlook 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Conclusions and OutlookISO26262 Experience Increasing functional safety capabilities Majority of OEM s include ISO26262 compliance in their contracts Independent audits and assessments are performed Methods for qualitative and quantitative analysis are available ASIL D HW and SW components are available as SeooC But Many suppliers do not have full ISO26262 compliance because they develop based on legacysystems Suppliers and OEMs need to further improve field observation and abilities to efficiently maintain asafety case New suppliers, e.g. for electric powertrain or ADAS, struggle with ramping up a safety process Security risks increasingly hamper functional safety Functional safety processes in many cases create overheads– which could be done at much lower costFunctional safety can be efficiently achieved on the basis of mature developmentprocesses together with a competent partner.26/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Conclusions and OutlookVector: Comprehensive Portfolio for Security and SafetyVector Cyber Security and Safety SolutionsSecurity and SafetyConsultingAUTOSAR BasicSoftwareTools(PLM, Architecture,Test, Diagnosis etc.)HW based SecurityEngineering Services for Safety and ecuritywww.vector.com/consulting 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Conclusions and OutlookVector Safety SolutionsTrainings and media Training “Functional Safety with ISO 26262”Stuttgart, continuouslywww.vector.com/training-safety Virtual trainings Free white papers www.vector.com/media-safety Vector Forum – Achieving Engineering Competitiveness(25 June 2020), on your computer – It is a virtual vector-forum/2020/ Further free Webinars:2020-06-17 Automotive Cybersecurity – Challenges and Practical ars/ 28/28 2020. Vector Consulting Services GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V1.10 2020-05-12

Parts of ISO 26262:2018 -2nd Edition -Main Changes Challenges and Concepts ISO/PAS 21448 Road vehicles -- Safety of the intended functionality (SOTIF) 1. Vocabulary 2. Management of functional safety 3. Concept phase 4. Product development at the system level 5. Product development at the hardware level 6. Product development at the .