It s all about safety and validation

Size: px
Start display at page:

Download "It s all about safety and validation"

Transcription

1 It s all about safety and validation Dr. Karl-Heinz Glander ZF DivA GEE ADAS Function & Algorithm Internal

2 Agenda 1. Motivation 2. Introduction into ISO DPAS (SOTIF, Safety Of The Intended Functionality) 3. SOTIF and ISO Verification and Validation of Automated Vehicles: Extending of SOTIF for Automated Driving 5. Remarks on Validation of AI Algorithms 6. Summary Internal 2

3 01 Motivation Internal 3

4 Ancient vision of the future But this happened in between

5 Nominal Performance 5

6 Nominal Performance source: source:

7 02 Introduction into ISO DPAS Safety Of The Intended Function (SOTIF) Internal 7

8 Safety Of The Intended Functionality (SOTIF) Systems, which rely on sensors, complex algorithms and actuators implemented by electrical and/or electronic (E/E) systems, can lead to safety violations if a hazardous decision about the environment is made by the processing algorithm, based on the sensor input, even in the absence of fault in the system. ISO 26262:2011 addresses the safety risks that arise from malfunctions of the E/E systemin vehicles. A proper understanding of the function, its behavior and its limitations (including the human/machine interface) is key to ensuring the user s safety. SOTIF assumes that the E/E malfunctions of the item are addressed using ISO The activities of SOTIF are additional to those given in ISO SOTIF provides guidance on the design, verification and validation measures applicable to avoid a malfunctioning behavior in the system in the absence of faults, resulting from technological and system definition shortcomings. 8

9 Safety Of Intended Function Basis Understanding of Scope The SoTIFdiscussion has evolved from a problem of handling implicit complex items. Nominal performance limits of the sensing system are accepted on the risk of (very rare) situations leading to violations of SGs, without any fault in the sensing system itself. The SoTIFdiscussion is a consequence of improper safety requirement refinement and/or of improper item definition, i.e. the initial requirement statement. If the intended function is potentially hazardous in some situation, then the item is simply not well defined. 9

10 Evolution of the use case categories Minimize area 2 and 3 functional improvement use case restrictions test result evaluation 10

11 Flowchart of the SOTIF activities 11

12 03 SOTIF and ISO26262 Internal 12

13 ISO & SOTIF Mapping 13

14 Combination of safety analysis 14

15 Development Cycle incl. SOTIF activities System Engineering and System Test HARA Development Phase FuSa & SOTIF Item Definition System Description I. Scenarios Def n. System Development* 5 System Specification Verification& Validation Planning System V&V Plan FuSa& SOTIF V&V V&V Approach V&V Techniques 9 V&V Approach(es) V&V Techniques 6 II. Safety Eval. Safety Goals incl. ASIL levels Functional ETA Functional Safety Concept Use Cases Scenarios 7 Verification& Validation Phase Test Report Residual Risk Evaluation 12 7 * According to AutoSPICE Functional Safety Req. incl. ASIL levels Technical Safety Concept 7 System FTA Technical Safety Req. incl. ASIL levels 8 Requirements System Arch. & System Requ. Design Design FMEA 8 Validates Verifies System Test Specification System Integration Test Specification FuSa& SOTIF SOTIF

16 04 Verification and Validation of Automated Vehicles: Extending of SOTIF for Automated Driving Internal 16

17 Iterative development 6, 7-Hazard Identification and Evaluation of triggering events Derivation of test scenarios regarding triggering events 5-Functional and System specification Derivation of test scenarios regarding use cases, error guessing and field experience 8-Functional modifications to reduce SOTIF risk Tolerable risk of harm? Acceptable residual risk? 10-Verification of the SOTIF (Area 2) Test track, public road, simulation Prototype vehicles and measurement equipment 11-Validation of the SOTIF (Area 3) Public road Preseries vehicles Fleet tests 12-Methodology and Criteria for SOTIF release Risk accepted 17

18 Extending of SOTIF Flowchart for AD 18

19 HARA process for Automated Driving Phase I: Scenario Definition Mapping Mapping Mapping + Aggregation Operating States Resulting Situations Resulting Scenarios Representative Scenarios Situations Environmental Situations/Events Products Phase II: Safety Evaluation Mapping Risk Assessment Legend Representative Scenarios Generic Hazards Automation Level Hazardous Events ASIL Rated Safety Goals + Safe States Product specific Product & Level specific 19

20 HARA process example Phase I: Scenario Definition Operating State Vehicle drives forward Situation On a motorway with low speed Phase II: Safety Evaluation Representative Scenario Dangerous obstacle occurs in lane Hazard Intended deceleration is not initiated Automation Level Conditional Automation Mapping Mapping Mapping + Aggregation Mapping Resulting Situation Vehicle drives forward on a motorway with low speed Environmental Event With obstacles on the road Hazardous Event Conditional automated HTJA is not initiating braking when dangerous obstacle occurs in lane Risk Assessment Resulting Scenario Vehicle drives on a motorway with low speed with obstacles on the road Product Highway Traffic Jam Assist (HTJA) Safety Goal and Safe State ASIL B: Collision with hazardous objects shall be avoided. A. Longitudinal control is taken over by driver. B. As long as the driver has not taken over the driving task, any deceleration is automatically initiated until standstill within ego lane is reached (or) an automatic collision avoidance maneuver is performed. Representative Scenario Dangerous obstacle occurs in lane Legend Generic Product specific Product & Level specific 20

21 Addressing SOTIF Vehicle Validation: Where do I need to drive? Conditions / Events Weather / Visibility Diver behaviour Road & Lane Surrounding vehicle Miscellaneous environmental events Relevant night, fog, low sun in the morning or evening, with other vehicles or people close to the ego vehicle, heavy snowfall, water spray by ahead driving or passing vehicles, sandstorm, heavy rain, with leaves on the lane, with changing brightness caused by shadows etc. Eyes-off, Hands-off approaching lane end, with different kinds of lane markings, and curvy road, on surface with low friction, on rough roads etc. Traffic jam (low/med/hi), ego vehicle is involved in accident Use cases and targets for the function are more important than driving for millions of KM The analysis of traffic statistics can provide an initial idea about a reasonable target for validation mileage: We want our systems to be more robust than the most advanced AD currently available: humans Where needs to be driven is more important than how much we need to drive: It is important to stimulate the system to handle all critical uses cases and exercise all critical detection characteristics Driver events Door open, Driving style inaccurate in lane etc. Surrounding vehicles events Emergency vehicle approaches, etc. With autonomous driving on the horizon, how much and where to drive is a debate that needs to be taken seriously! 21

22 Real-world Synthesis System V&V Strategy Extensive verification and validation through combination of test approaches V&V for AD System & Components SyntheticScenarios using Simulation Import & parameterize Real World Data FOT Performance Test DB GIDAS SOTIF V&V Area 2 Definition of V&V Strategy 10 Scenario DB (Synthetic + Real World) 22

23 Determination of System Failure Rate Scenario #1 Scenario #2 P(Scene#1)= 10-5 /h P(Scene#2)= 10-6 /h Scenario #n P(Scene#n)= 10 -? /h FIXED VALUES by Data Modelling or Real World Data Goal: P F < /h for unprotected system X P F = X X (estimation: fleet of vehicles x km lifetime / average speed of 40 km/h) P F, System (Scene#1)= 10-7 /h Sensor Sensor Sensor P F, System (Scene#2)= 10-6 /h System Configuration Brake Steering Powertrain AD Functions & SDE P F, System (Scene#n)= 10 -? /h HMI ENGINEERING VARIABLES by Quality and Redundancy

24 Simulation of Relevant Scenarios N-dim. parameter space for specific use case/feature N-dim. parameter space for specific use case/feature Coverage of scenario space Simulative variation 1. Define representative sample of the overall scenario space and all relevant parameters. 2. Assign criticality (ASIL level related) to these scenarios. 3. Decision on the extend of testing based on Point 2. 24

25 ZF Approach to Functional Testing Serial Ready Collection of synthetic scenarios Systematic Test Scenario Generation Experience based randomized Test scenario Collection of real world data (Euro) Field Operational Tests GIDAS NCAP World-wide L2 Fleetbased data collection Validate Models Semantic and Synthesized Scenario DB Statistical rating, assessment of severity & derivation of parameters Real world scenario DB ZF Test Methods Test Scenario DB Parameter Variation & Distribution to different test environments Test environments Vehicle Tests Static & Dyn Simulator HiL (Network of ECUs) SiL (AD Algos) Industry/Consortiums

26 SOTIF Example: Automated Highway Exit (AHEx) Test Report Residual Risk Evaluation Minimized residual risk by: SY_Req (KPIs) V&V Plan amount variety quality HIL mileage Result: Residual risk is acceptable. hours driver locations ambience real world data driving simulator SIL Unknown Use Case Quantified Targets Fulfilled? YES Residual Risk Evaluation 12 Residual risk accepted? YES 26

27 05 Remarks on Validation of AI Algorithms Internal 27

28 Powers and Risks of Machine Learning Techniques Sitawarin et al. (2018), arxiv: Black box: Difficult or impossible to understand failure Tech:AD Berlin 2018 ZF Div A GEE ADAS Function & Algorithm Dr. Karl-Heinz Glander It s all about safety and validation 28

29 Strategy for Integration of Machine Learning Techniques for AD Problem with misclassifications Semantic knowledge is missing Humans also cannot always explain their thought processes: We intuitively trust/gauge people Solution Stick to very limited competence frame Test for completeness More difficult for complex classifiers Strategicrevenue.com 29

30 How to Understand Artificial Intelligence Visualization of functional layers Lower: simple things Higher: more complex structures Top: identifiesobjectasawhole nvidia.com Deep dream (Google, 2015) Strategy to capture decision making process Reverse process: algorithm to generate objects Shows how different deep learning is from human perception Artifactswouldbeignoredbyahuman 30

31 Different Approaches for AD and their Limitations End-to-end approach Small networks for well-defined tasks Input Measured sensor data (e.g. radar) Higher level processed data Network Complex network across all functional layers of AD (1000s units per layer, 100s of layers) Small network in one functional layer of AD Output Operation commands (e.g. brakes) Classifications/decisions Benefits vs. Risks +One simple architecture for all scenarios Complex architecture, use case based Test for completeness impossible + Test for completeness possible Impossible to predict failures Causal relationship unclear due to complexity +Defined competence frame: limitations known + Failures can be understood 31

32 Summary Systematic approach to System Safety and (new) Verification & Validation Methods are key for the Industrialization of Automated Vehicles Unified HARA approach allows combination of SOTIF and ISO26262 in standard system engineering approach Function and scenario driven approach to HARA; can be easily applied to all previously evaluated products A catalogue of evaluated scenarios covering all ZF Automated Driving products is automatically developed over time Inconsistencies between diverse products and automation levels can be easily recognized and corrected Differences and similarities from functional safety point of view between diverse products and automation levels can be easily emphasized to facilitate architectural decisions Validation of Automated Driving needs quality data not necessarily massive amount of data No need to drive billions of km or miles. All the key characteristics of the system shall be exercised during the development. The scenarios are expanded to cover the requirements for the intended use. Then completeness can also be argued for SOTIF and must also include statistical confidence. Validation of Artificial Intelligence needs cautious approach in utilizing NN

33 Thank you Dr. Karl-Heinz Glander Chief Engineering Manager Automated Driving & Integral Cognitive Safety ZF Group - TRW Automotive GmbH Hansaallee 190, Düsseldorf Karl-Heinz.Glander@zf.com, ZF Friedrichshafen AG behält sich sämtliche Rechte an den gezeigten technischeninformationeneinschließlichder RechtezurHinterlegungvon Schutzrechtsanmeldungen und an daraus entstehenden Schutzrechten im In- und Ausland vor. ZF Friedrichshafen AG reserves all rights regarding the shown technical information including the right to file industrial property right applications and the industrial property rights resulting from these in Germany and abroad. Internal 33

Verification of Simulation-Based Release Procedure for an Advanced Driver Assistance System. Dirk Fratzke, Julian King TÜV Süd ZF Friedrichshafen IPG

Verification of Simulation-Based Release Procedure for an Advanced Driver Assistance System. Dirk Fratzke, Julian King TÜV Süd ZF Friedrichshafen IPG Verification of Simulation-Based Release Procedure for an Advanced Driver Assistance System Dirk Fratzke, Julian King TÜV Süd ZF Friedrichshafen IPG Project Objective & Contributions Addendum 78 UN Regulation

More information

Autonomous Driving the uncrashable car? What it takes to make self-driving vehicles safe and reliable traffic participants

Autonomous Driving the uncrashable car? What it takes to make self-driving vehicles safe and reliable traffic participants Autonomous Driving the uncrashable car? What it takes to make self-driving vehicles safe and reliable traffic participants Dr. Frank Keck, MMB Conference 2018, Erlangen, Germany Internal Agenda Zukunft

More information

Using STPA in Compliance with ISO26262 for developing a Safe Architecture for Fully Automated Vehicles

Using STPA in Compliance with ISO26262 for developing a Safe Architecture for Fully Automated Vehicles Bitte decken Sie die schraffierte Fläche mit einem Bild ab. Please cover the shaded area with a picture. (24,4 x 11,0 cm) Using STPA in Compliance with ISO26262 for developing a Safe Architecture for Fully

More information

Functional Safety & Machine Learning - argumentation for safety case -

Functional Safety & Machine Learning - argumentation for safety case - Functional Safety & Machine Learning - argumentation for safety case - Dr. Stefan Schinzer, Praveen Parthibanathan, Dr. Rafal Dorociak E-EST212, Functional Safety platforms & ADAS HELLA GmbH & Co. KGaA

More information

ZF Escalation Model Supplier / Purchased Parts

ZF Escalation Model Supplier / Purchased Parts MOTION AND MOBILITY ZF Escalation Model Supplier / Purchased Parts Detlef Döpfner SGMD ZF Friedrichshafen AG Agenda 1. 2. 3. 4. 5. Purpose Inclusion to the Escalation Model Contents of the Escalation Levels

More information

Using STPA in Compliance with ISO26262 for developing a Safe Architecture for Fully Automated Vehicles

Using STPA in Compliance with ISO26262 for developing a Safe Architecture for Fully Automated Vehicles Bitte decken Sie die schraffierte Fläche mit einem Bild ab. Please cover the shaded area with a picture. (24,4 x 11,0 cm) Using STPA in Compliance with ISO26262 for developing a Safe Architecture for Fully

More information

SOLUTIONS Where innovation drives development

SOLUTIONS Where innovation drives development SOLUTIONS Where innovation drives development Software Validation Mechatronics cmore-automotive.com Software From functional software requirements to final software release Our strengths are in the development

More information

Functional Safety with ISO Principles and Practice Dr. Christof Ebert, Dr. Arnulf Braatz Vector Consulting Services

Functional Safety with ISO Principles and Practice Dr. Christof Ebert, Dr. Arnulf Braatz Vector Consulting Services Functional Safety with ISO 26262 Principles and Practice Dr. Christof Ebert, Dr. Arnulf Braatz Vector Consulting Services Content Challenges with Implementing Functional Safety Basic Concepts Vector Experiences

More information

AVL List GmbH (Headquarters) Autonomous Driving. Validation and Testing - Challenges. Dr. Mihai Nica, Hermann Felbinger. Public

AVL List GmbH (Headquarters) Autonomous Driving. Validation and Testing - Challenges. Dr. Mihai Nica, Hermann Felbinger. Public AVL List GmbH (Headquarters) Autonomous Driving Validation and Testing - Challenges Dr. Mihai Nica, Hermann Felbinger Our Experience for your Success AVL achieves unique results in regards to the development

More information

Avoiding wind turbine tonalities A structured, system based approach. Frederik Vanhollebeke ZF Wind Power Technology

Avoiding wind turbine tonalities A structured, system based approach. Frederik Vanhollebeke ZF Wind Power Technology Avoiding wind turbine tonalities A structured, system based approach Frederik Vanhollebeke Wind Power Technology 1 2014-12-10 EWEA Wind Turbine Sound 2014 Avoiding wind turbine tonalities Agenda 1. Wind

More information

Functional Safety Implications for Development Infrastructures

Functional Safety Implications for Development Infrastructures Functional Safety Implications for Development Infrastructures Dr. Erwin Petry KUGLER MAAG CIE GmbH Leibnizstraße 11 70806 Kornwestheim Germany Mobile: +49 173 67 87 337 Tel: +49 7154-1796-222 Fax: +49

More information

Testing of level-3 Systems

Testing of level-3 Systems Testing of level-3 Systems stepping through the current PEGASUS approach Dr. Helmut Schittenhelm 9th November 2017 Starting point: Approval-Trap * Up to now, system behavior in traffic is considered a

More information

A Strategy for Assessing Safe Use of Sensors in Autonomous Road Vehicles

A Strategy for Assessing Safe Use of Sensors in Autonomous Road Vehicles Authors' version for self-archiving A Strategy for Assessing Safe Use of Sensors in Autonomous Road Vehicles Rolf Johansson 1,2, Samieh Alissa 3, Staffan Bengtsson 4, Carl Bergenhem 5, Olof Bridal 6, Anders

More information

Functional Safety: ISO26262

Functional Safety: ISO26262 Functional Safety: ISO26262 Seminar Paper Embedded systems group Aniket Kolhapurkar, University of Kaiserslautern, Germany kolhapur@rhrk.uni kl.de September 8, 2015 1 Abstract Functions in car, such as

More information

Developing Safe Autonomous Vehicles for Innovative Transportation Experiences

Developing Safe Autonomous Vehicles for Innovative Transportation Experiences Developing Safe Autonomous Vehicles for Innovative Transportation Experiences CIMdata Commentary Key takeaways: Siemens PLM Software (Siemens) has a deep understanding of the verification and validation

More information

DNA for Automated Driving. Jeremy Dahan May 8 th, 2017

DNA for Automated Driving. Jeremy Dahan May 8 th, 2017 Jeremy Dahan May 8 th, 2017 Radar Camera LIDAR Sonar Steering Wheel Sensors 30 25 20 15 10 Wheel Speeds IMU / Gyro 5 0 Global Position 1999: Mercedes S-Class Distronic 2002: VW Phaeton ACC Moving objects

More information

Software Framework for Highly Automated Driving EB robinos. Jared Combs July 27, 2017

Software Framework for Highly Automated Driving EB robinos. Jared Combs July 27, 2017 Software Framework for Highly Automated Driving EB robinos Jared Combs July 27, 2017 Radar Camera LIDAR Sonar Steering Wheel Sensors 30 25 20 15 10 Wheel Speeds IMU / Gyro 5 0 Global Position 1999: Mercedes

More information

Development ACSF of Category B2 (SAE Level 3 & 4) Requirements

Development ACSF of Category B2 (SAE Level 3 & 4) Requirements Informal Document - ACSF-17-03-Rev.1 Reference Document Development ACSF of Category B2 (SAE Level 3 & 4) Requirements Objectives The objective of the ACSF IWG (as agreed by GRRF) is to develop proposals

More information

Iterative Application of STPA for an Automotive System

Iterative Application of STPA for an Automotive System Iterative Application of STPA for an Automotive System GM Team Joe D Ambrosio Rami Debouk Dave Hartfelder Padma Sundaram Mark Vernacchia Sigrid Wagner MIT Team John Thomas Table of Contents Introduction/Background

More information

On the necessity of open cooperation between gearbox supplier and wind turbine OEM to avoid wind turbine tonalities

On the necessity of open cooperation between gearbox supplier and wind turbine OEM to avoid wind turbine tonalities Ben Marrant, Fred Vanhollebeke IW ZF Friedrichshafen AG MOTION AND MOBILITY On the necessity of open cooperation between gearbox supplier and wind turbine OEM to avoid wind turbine tonalities Agenda 1.

More information

Implementation of requirements from ISO in the development of E/E components and systems

Implementation of requirements from ISO in the development of E/E components and systems Implementation of requirements from ISO 26262 in the development of E/E components and systems Challenges & Approach Automotive Electronics and Electrical Systems Forum 2008 May 6, 2008, Stuttgart, Germany

More information

» Software in Tractors: Aspects of Development, Maintenance and Support «

» Software in Tractors: Aspects of Development, Maintenance and Support « Session: Information Technology for Agricultural Machines» Software in Tractors: Aspects of Development, Maintenance and Support «Dipl.-Ing. Rainer Hofmann, AGCO GmbH, Germany Development of Software is

More information

How to Reach Complete Safety Requirement Refinement for Autonomous Vehicles

How to Reach Complete Safety Requirement Refinement for Autonomous Vehicles How to Reach Complete Safety Requirement Refinement for Autonomous Vehicles Carl Bergenhem, Rolf Johansson, Andreas Söderberg, Jonas Nilsson, Jörgen Tryggvesson, Martin Törngren, Stig Ursing To cite this

More information

Evaluation of the AdaptIVe functions

Evaluation of the AdaptIVe functions András Várhelyi Erwin de Gelder Evaluation of the AdaptIVe functions User-related assessment and In-traffic behavior assessment Final Event Aachen, Germany 29 June 2017 // Evaluation of AdaptIVe functions

More information

How to make a complete hazard analysis and risk assessment for autonomous vehicles?

How to make a complete hazard analysis and risk assessment for autonomous vehicles? 1 How to make a complete hazard analysis and risk assessment for autonomous vehicles? FUSE Final Seminar 2016-09-23 2 From driver assistance to driver replacement Driving on highway- ADAS Driving on highway-ad

More information

Integrating Functional Safety with ARM. November, 2015 Lifeng Geng, Embedded Marketing Manager

Integrating Functional Safety with ARM. November, 2015 Lifeng Geng, Embedded Marketing Manager Integrating Functional Safety with ARM November, 2015 Lifeng Geng, Embedded Marketing Manager 1 ARM: The World s Most Scalable Architecture ARM ecosystem meets needs of vertical markets from sensors to

More information

Highly Autonomous Vehicle Validation:

Highly Autonomous Vehicle Validation: Highly Autonomous Vehicle Validation: It s more than just road testing! Prof. Philip Koopman How Do You Validate Autonomous Vehicles? Self-driving cars are so cool! But also kind of scary Is a billion

More information

Code of Practice for development, validation and market introduction of ADAS

Code of Practice for development, validation and market introduction of ADAS Code of Practice for development, validation and market introduction of ADAS Dr. Juergen Schwarz (DaimlerChrysler AG) RESPONSE 3, München, 04.04. 2006 1 Consortium Partner RESPONSE 3, München, 04.04. 2006

More information

Automotive Safety and Security in a Verification Continuum Context

Automotive Safety and Security in a Verification Continuum Context Automotive Safety and Security in a Verification Continuum Context Accelerating the Development of Automotive Electronic Systems Jean-Marc Forey Automotive Functional Safety Professional Synopsys Inc.

More information

ISO : Rustam Rakhimov (DMS Lab)

ISO : Rustam Rakhimov (DMS Lab) ISO 26262 : 2011 Rustam Rakhimov (DMS Lab) Introduction Adaptation of IEC 61508 to road vehicles Influenced by ISO 16949 Quality Management System The first comprehensive standard that addresses safety

More information

A Classification of Driver Assistance Systems

A Classification of Driver Assistance Systems International Conference Artificial Intelligence, Intelligent Transport Systems 25-28 May 2016, Brest, Belarus A Classification of Driver Assistance Systems George Yannis, Professor Costas Antoniou, Associate

More information

Development Tools for Active Safety Systems: PreScan and VeHIL

Development Tools for Active Safety Systems: PreScan and VeHIL Development Tools for Active Safety Systems: PreScan and VeHIL F. Hendriks, M. Tideman and R. Pelders, TNO Automotive, The Netherlands R. Bours and X.Liu, TASS, China Keywords: Active safety systems; ADAS;

More information

FUnctional Safety and Evolvable architectures for autonomy Project partners Funding

FUnctional Safety and Evolvable architectures for autonomy Project partners Funding Project Summary FUnctional Safety and Evolvable architectures for autonomy Project partners Funding 2 FUSE FUnctional Safety and Evolvable architectures for autonomy The Project In this report we summarise

More information

Driver Assistance and Autonomous Driving

Driver Assistance and Autonomous Driving Driver Assistance and Autonomous Driving Opportunities, Challenges, Solutions New levels at comfort, safety & efficiency Peter Schoeggl, Mario Oswald, Rainer Voegl, Philipp Clement, Michael Stolz, Erich

More information

Agile in Braking Systems

Agile in Braking Systems Agile in Braking Systems Dr. Ingo Alfter, Hermann Bressmer, ZF Group Dr. Ulrich Bodenhausen, Vector Consulting Services 1/21 ZF Friedrichshafen AG Welcome Authors Dr. Ingo Alfter is Chief Engineer Global

More information

A handle on the future

A handle on the future Translated article Die Zukunft im Griff, Automobil Elektronik 05-06 / 2018 A handle on the future Virtualized testing and XiL for automated driving Advanced driver assistance systems (ADAS) have come so

More information

The Timing Model TIMMO Methodology Guest Lecture at Chalmers University

The Timing Model TIMMO Methodology Guest Lecture at Chalmers University ITEA 2 06005: Timing Model The Timing Model Methodology Guest Lecture at Chalmers University Stefan Kuntz, Continental Automotive GmbH 10-02-2009 Methodology Page 1 Welcome About Stefan Kuntz Studied Electrical

More information

Second Generation Model-based Testing

Second Generation Model-based Testing CyPhyAssure Spring School Second Generation Model-based Testing Provably Strong Testing Methods for the Certification of Autonomous Systems Part I of III Motivation and Challenges Jan Peleska University

More information

Application of MBD to Development of ECU Prototype for EPS

Application of MBD to Development of ECU Prototype for EPS Technology Introduction Application of MBD to Development of ECU Prototype for EPS KOBAYASHI Masayuki 1 Introduction Conventionally, most of the embedded control systems have been developed, using a document-based

More information

Overview of the 2nd Edition of ISO 26262: Functional Safety Road Vehicles

Overview of the 2nd Edition of ISO 26262: Functional Safety Road Vehicles Overview of the 2nd Edition of ISO 26262: Functional Safety Road Vehicles Rami Debouk, General Motors Company, Warren, MI, USA ABSTRACT Functional safety is of utmost importance in the development of safety-critical

More information

Solutions.

Solutions. Products Services Software Platforms Data Intelligence Solutions www.autonomoustuff.com About AutonomouStuff Innovative Products www.autonomoustuff.com/products AutonomouStuff is the world s leader in

More information

Autonomous Drive. Restricted Circulation L&T Technology Services

Autonomous Drive. Restricted Circulation L&T Technology Services Autonomous Drive Restricted Circulation L&T Technology Services 2016 1 Projects Products Services WE COME FROM A LINEAGE OF INNOVATION & GROWTH Larsen & Toubro founded in 1938 by Danish engineers L&T is

More information

Deliverable D21.3 Generic platform core demonstrator available in lab

Deliverable D21.3 Generic platform core demonstrator available in lab Highly automated vehicles for intelligent transport 7th Framework programme ICT-2007.6.1 ICT for intelligent vehicles and mobility services Grant agreement no.: 212154 The future of driving. Deliverable

More information

Building Behavioral Competency into STPA Process Models for Automated Driving Systems

Building Behavioral Competency into STPA Process Models for Automated Driving Systems Building Behavioral Competency into STPA Process Models for Automated Driving Systems Shawn A. Cook, Hsing-Hua Fan, Krzysztof Pennar, Padma Sundaram General Motors Introduction Behavioral Competency is

More information

Kfz Elektronik Entwicklung: Trends und Herausforderungen im IoT-Zeitalter

Kfz Elektronik Entwicklung: Trends und Herausforderungen im IoT-Zeitalter Kfz Elektronik Entwicklung: Trends und Herausforderungen im IoT-Zeitalter Speed the delivery of sophisticated and connected vehicles MERKS MOTOR MUSEUM GmbH, Klingenhofstraße 51, 90411 Nürnberg 26 th of

More information

Tool box for the benefit estimation of active and passive safety systems in terms of injury severity reduction and collision avoidance

Tool box for the benefit estimation of active and passive safety systems in terms of injury severity reduction and collision avoidance Tool box for the benefit estimation of active and passive safety systems in terms of injury severity reduction and collision avoidance Abstract H Liers, L Hannawald* *Verkehrsunfallforschung an der TU

More information

Overview of the 2nd Edition of ISO 26262: Functional Safety Road Vehicles

Overview of the 2nd Edition of ISO 26262: Functional Safety Road Vehicles Overview of the 2nd Edition of ISO 26262: Functional Safety Road Vehicles Rami Debouk GM Research and Development rami.debouk@gm.com August 16 th, 2018 2010 ISSC Functional Minneapolis, Safety Road Vehicles

More information

Deliverable D22.1 DRIVE C2X methodology framework (abstract)

Deliverable D22.1 DRIVE C2X methodology framework (abstract) Deliverable D22.1 DRIVE C2X methodology framework (abstract) Version number Version 1.0 Dissemination level PU Lead contractor VTT Due date 30.06.2011 Date of preparation 29.09.2011 Deliverable D22.1 Version

More information

FUNCTIONAL SAFE STAHLDATEN SERVICE FOR AUTOMATED DRIVING

FUNCTIONAL SAFE STAHLDATEN SERVICE FOR AUTOMATED DRIVING FUNCTIONAL SAFE STAHLDATEN SERVICE FOR AUTOMATED DRIVING ConCarExpo 05./06.07.2017, Berlin Uwe Beher, ESG Elektroniksystem- und Logistik-GmbH Thomas Weyrath, ESG Elektroniksystem- und Logistik-GmbH AGENDA

More information

elektrobit.com Driver assistance software EB Assist solutions

elektrobit.com Driver assistance software EB Assist solutions elektrobit.com Driver assistance software EB Assist solutions From driver assistance systems to automated driving Automated driving leads to more comfortable driving and makes the road safer and more secure.

More information

Link: https://www.springerprofessional.de/en/testing-system-for-integrated-highly-interconnected-safety-syste/

Link: https://www.springerprofessional.de/en/testing-system-for-integrated-highly-interconnected-safety-syste/ Link: https://www.springerprofessional.de/en/testing-system-for-integrated-highly-interconnected-safety-syste/6115370 Development Active and Passive safety Authors Dipl.-Ing. (FH) Kathrin Sattler is a

More information

Rockwell Task E Page 1. Precursor Systems Analyses of Automated Highway Systems. AHS PSA Malfunction Management and Analysis

Rockwell Task E Page 1. Precursor Systems Analyses of Automated Highway Systems. AHS PSA Malfunction Management and Analysis Rockwell Task E Page 1 Precursor Systems Analyses of Automated Highway Systems RESOURCE MATERIALS AHS PSA Malfunction Management and Analysis U.S. Department of Transportation Federal Highway Administration

More information

Development of a Cooperative Tractor-Implement Combination

Development of a Cooperative Tractor-Implement Combination Development of a Cooperative Tractor-Implement Combination While driver assistance systems such as adaptive cruise control and lane-keeping assistants are increasingly handling longitudinal and lateral

More information

EUROPEAN COMMISSION SEVENTH FRAMEWORK PROGRAMME. Theme: ICT. Small or medium-scale focused research projects (STREP) FP7-ICT

EUROPEAN COMMISSION SEVENTH FRAMEWORK PROGRAMME. Theme: ICT. Small or medium-scale focused research projects (STREP) FP7-ICT Ref. Ares(2014)4249386-17/12/2014 EUROPEAN COMMISSION SEVENTH FRAMEWORK PROGRAMME Theme: ICT Small or medium-scale focused research projects (STREP) FP7-ICT-2013-10 Objective ICT-2013.6.5 Co-operative

More information

Heterogeneous Compute in Automotive and IoT. May 31, June 1,

Heterogeneous Compute in Automotive and IoT. May 31, June 1, Heterogeneous Compute in Automotive and IoT May 31, June 1, 2017 www.imgtec.com heterogeneous hɛt(ə)rə(ʊ)ˈdʒiːnɪəs adjective Diverse in character or content. Hetero from the Greek, meaning other gen a

More information

Commercial vehicles Functional safety implementation process and challenges. Dr Chitra Thyagarajan Safety and Reliability Consultant Mahindra Satyam

Commercial vehicles Functional safety implementation process and challenges. Dr Chitra Thyagarajan Safety and Reliability Consultant Mahindra Satyam Commercial vehicles Functional safety implementation process and challenges Dr Chitra Thyagarajan Safety and Reliability Consultant Mahindra Satyam Agenda Functional safety Importance of safety in commercial

More information

Development of a Cooperative Tractor-Implement Combination

Development of a Cooperative Tractor-Implement Combination Technical Article Development of a Cooperative Tractor-Implement Combination While driver assistance systems such as adaptive cruise control and lane-keeping assistants are increasingly handling longitudinal

More information

A Model-Based Reference Workflow for the Development of Safety-Critical Software

A Model-Based Reference Workflow for the Development of Safety-Critical Software A Model-Based Reference Workflow for the Development of Safety-Critical Software A. Michael Beine 1 1: dspace GmbH, Rathenaustraße 26, 33102 Paderborn Abstract: Model-based software development is increasingly

More information

10 Giugno System Driven Product Development Beppe Grimaldi Manager, Professional Services

10 Giugno System Driven Product Development Beppe Grimaldi Manager, Professional Services 10 Giugno 2014 System Driven Product Development Beppe Grimaldi Manager, Professional Services Smarter Decisions for Industry AGENDA Automotive Global Scenario SPL Investment on System Engineering Traditional

More information

Utilization of Test Regions Worldwide for AD Validation. Philip Dietl, Dr. Stefan Bernsteiner Tech.AD, , Berlin

Utilization of Test Regions Worldwide for AD Validation. Philip Dietl, Dr. Stefan Bernsteiner Tech.AD, , Berlin Utilization of Test Regions Worldwide for AD Validation Philip Dietl, Dr. Stefan Bernsteiner Tech.AD, 06.03.2018, Berlin Agenda 1) Introduction 2) Validation of AD Functions at Magna Steyr 3) International

More information

Automated Connected - Mobile

Automated Connected - Mobile Automated Connected - Mobile Status of the National Action Plan Automated Driving Productivity gains: for Vienna about 100 Mio. hours per year! Accessibility: 100%! Value creation: +30% Individual mobility

More information

Development of AUTOSAR Software Components with Model-Based Design

Development of AUTOSAR Software Components with Model-Based Design Development of AUTOSAR Software Components with Model-Based Design Guido Sandmann Automotive Marketing Manager, EMEA The MathWorks Joachim Schlosser Senior Team Leader Application Engineering The MathWorks

More information

Development of Safety Related Systems

Development of Safety Related Systems July 2015 LatticeSemiconductor 7 th Floor,111SW5 th Avenue Portland,Oregon97204USA Telephone:(503)268I8000 www.latticesemi.com WP004 The increasing degree of automation brings a lot of comfort and flexibility

More information

Missing no Interaction Using STPA for Identifying Hazardous Interactions of Automated Driving Systems

Missing no Interaction Using STPA for Identifying Hazardous Interactions of Automated Driving Systems Special Issue Article: The 5 th European STAMP Workshop (ESW) 2017, Chief Editor: Svana Helen Björnsdottir, Reykjavik University Missing no Interaction Using STPA for Identifying Hazardous Interactions

More information

FACILITATING AGRICULTURE AUTOMATION USING STANDARDS

FACILITATING AGRICULTURE AUTOMATION USING STANDARDS FACILITATING AGRICULTURE AUTOMATION USING STANDARDS Robert K. Benneweis P. Eng Outline Available standards Developing standards Implemented automation Standard based automation implementation Potential

More information

SAFE an ITEA2 project / SAFE-E an Eurostars project. Contract number: ITEA Contract number: Eurostars 6095 Safe-E

SAFE an ITEA2 project / SAFE-E an Eurostars project. Contract number: ITEA Contract number: Eurostars 6095 Safe-E Contract number: ITEA2 10039 Safe-E Contract number: Eurostars 6095 Safe-E Safe Automotive software architecture (SAFE) & Safe Automotive software architecture Extension (SAFE-E) WP3.2.1 System and software

More information

SAFESPOT. Cooperative vehicles and road infrastructure for road safety. Masters Thesis: The Use of Spatial Databases in Cooperative Vehicle Systems

SAFESPOT. Cooperative vehicles and road infrastructure for road safety. Masters Thesis: The Use of Spatial Databases in Cooperative Vehicle Systems SAFESPOT Cooperative vehicles and road infrastructure for road safety Masters Thesis: The Use of Spatial Databases in Cooperative Vehicle Systems Tilman Klar Tele Atlas (Germany), tilman.klar@teleatlas.com

More information

Connected and Automated Trucks: What and When?

Connected and Automated Trucks: What and When? Connected and Automated Trucks: What and When? Steven E. Shladover, Sc.D. California PATH Program University of California, Berkeley International Urban Freight Conference Long Beach, October 18, 2017

More information

The ADAS SWOT Analysis A Strategy for Reducing Costs and Increasing Quality in ADAS Testing

The ADAS SWOT Analysis A Strategy for Reducing Costs and Increasing Quality in ADAS Testing The ADAS SWOT Analysis A Strategy for Reducing Costs and Increasing Quality in ADAS Testing Andreas Haja, Carsten Koch and Lars Klitzke Faculty of Technology, Hochschule Emden/Leer, University of Applied

More information

Code of Practice. EUCAR Annual Conference th November 2018, Brussels. Robert Martinez v. Bülow, BMW Group

Code of Practice. EUCAR Annual Conference th November 2018, Brussels. Robert Martinez v. Bülow, BMW Group Code of Practice EUCAR Annual Conference 2018 7 th November 2018, Brussels Robert Martinez v. Bülow, BMW Group www.l3pilot.eu Twitter@_L3Pilot_ LinkedInL3Pilot History of the Code of Practice (CoP). PReVENT:

More information

Seite 1. KUGLER MAAG CIE GmbH

Seite 1. KUGLER MAAG CIE GmbH Requirements Engineering and Management with ISO 26262 and Automotive SPICE October 25, 2012 Milan 10th Workshop on Automotive Software & Systems Fabio Bella Kugler Maag Cie KUGLER MAAG CIE GmbH Seite

More information

On Safety Validation of Automated Driving Systems using Extreme Value Theory

On Safety Validation of Automated Driving Systems using Extreme Value Theory Thesis for the Degree of Licentiate of Engineering On Safety Validation of Automated Driving Systems using Extreme Value Theory Daniel Åsljung Department of Electrical Engieneering Chalmers University

More information

Safety cannot rely on testing

Safety cannot rely on testing Standards 1 Computer-based systems (generically referred to as programmable electronic systems) are being used in all application sectors to perform non-safety functions and, increasingly, to perform safety

More information

Safety Management Center. DNV IT Global Services Safety Engineering / Management in the automotive industry. Content

Safety Management Center. DNV IT Global Services Safety Engineering / Management in the automotive industry. Content DNV IT Global Services Safety Engineering / Management in the automotive industry Enhancing Trust and Confidence in IT Automotive SPIN Italia 4 Workshop on Automotive Software Torino, 11.12.2009 Dr. Klaus

More information

Building a Safety Case for Automated Mobility: Smart Cities and Autonomous Mobility Getting There Safely

Building a Safety Case for Automated Mobility: Smart Cities and Autonomous Mobility Getting There Safely Building a Safety Case for Automated Mobility: Smart Cities and Autonomous Mobility Getting There Safely Building a Safety Case for Automated Mobility: Smart Cities and Autonomous Mobility Getting There

More information

Simulation Analytics

Simulation Analytics Simulation Analytics Powerful Techniques for Generating Additional Insights Mark Peco, CBIP mark.peco@gmail.com Objectives Basic capabilities of computer simulation Categories of simulation techniques

More information

Best Practices in Quality Assurance

Best Practices in Quality Assurance MOTION AND MOBILITY Best Practices in Quality Assurance Norbert Fröschl DTEQ1 ZF Friedrichshafen AG Agenda 1. 2. 3. 4. 5. Introduction Software Quality Assurance - Best Practices How does Stages Help How

More information

Project Control & Management

Project Control & Management Project Control & Management Dr Alireza Mousavi, Department of Electronics and Computer Engineering Brunel, UK Technische Akademie Esslingen (TAE) Lecture 10 1 We will be discussing 1. Project Management

More information

AUTONOMOUS VEHICLES & HD MAP CREATION TEACHING A MACHINE HOW TO DRIVE ITSELF

AUTONOMOUS VEHICLES & HD MAP CREATION TEACHING A MACHINE HOW TO DRIVE ITSELF AUTONOMOUS VEHICLES & HD MAP CREATION TEACHING A MACHINE HOW TO DRIVE ITSELF CHRIS THIBODEAU SENIOR VICE PRESIDENT AUTONOMOUS DRIVING Ushr - Autonomous Driving Ushr Company History Industry leading & 1

More information

Functional Architecture as the Core of Model-Based Systems Engineering

Functional Architecture as the Core of Model-Based Systems Engineering Boeing Defense, Space & Security Integrated Product Functional as the Core of Model-Based Systems Engineering Ronald S. Carson, PhD Barbara J. Sheeley The Boeing Company Presented to National Defense Industrial

More information

The impact of intelligent routing on traffic congestion. Nick Cohn

The impact of intelligent routing on traffic congestion. Nick Cohn The impact of intelligent routing on traffic congestion Nick Cohn Contents CONGESTION INDEX DYNAMIC NAVIGATION EFFECTS COOPERATIVE TRAFFIC MANAGEMENT (NEAR) FUTURE Congestion Index 3 4 Goals of Congestion

More information

Development Support. Worldwide Activities Support in all Areas of Safety

Development Support.   Worldwide Activities Support in all Areas of Safety Consulting Training Development Support Worldwide Activities Support in all Areas of Safety innotec GmbH Heinrich-Wildung-Weg 3 D-21224 Rosengarten +49-4105-1559182 innotec GmbH Salurner Straße 16 A-5020

More information

This project has received funding from the European Union s Horizon 2020 research and innovation programme under the Marie-Sklodowska-Curie grant

This project has received funding from the European Union s Horizon 2020 research and innovation programme under the Marie-Sklodowska-Curie grant This project has received funding from the European Union s Horizon 2020 research and innovation programme under the Marie-Sklodowska-Curie grant agreement number 721624. Introduction to Functional Safety

More information

Available online at Procedia Engineering 45 (2012 ) Peter KAFKA*

Available online at   Procedia Engineering 45 (2012 ) Peter KAFKA* Available online at www.sciencedirect.com Procedia Engineering 45 (2012 ) 2 10 2012 International Symposium on Safety Science and Technology The Automotive Standard ISO 26262, the innovative driver for

More information

Measuring and Assessing Software Quality

Measuring and Assessing Software Quality Measuring and Assessing Software Quality Issues, Challenges and Practical Approaches Kostas Kontogiannis Associate Professor, NTUA kkontog@softlab.ntua.gr The Software Life Cycle Maintenance Requirements

More information

Automotive Systems Engineering und Functional Safety: The Way Forward

Automotive Systems Engineering und Functional Safety: The Way Forward Automotive Systems Engineering und Functional Safety: The Way Forward Dr. Simon Burton Albert Habermann Vector Informatik GmbH Ingersheimer Strasse 24 70499 Stuttgart, Germany +49 711 80670 1529 albert.habermann@vector.com

More information

Functional Safety of Driver Assistance

Functional Safety of Driver Assistance Functional Safety of Driver Assistance 6 Systems and ISO 26262 Ulf Wilhelm, Susanne Ebel, and Alexander Weitzel Contents 1 Objectives of Functional Safety... 110 1.1 Overview... 110 1.2 Objectives and

More information

Autonomous Vehicle WHITE paper

Autonomous Vehicle WHITE paper www.hcltech.com Autonomous Vehicle WHITE paper Table of Contents Abstract Abbreviations Market Trends and Challenges Solution Best Practices Conclusion Reference Author Info 3 3 4 4 9 10 10 10 Abstract

More information

From Advanced Active Safety Systems to Automated Systems: From to and beyond. Dr. Angelos Amditis Research Director I-Sense, ICCS

From Advanced Active Safety Systems to Automated Systems: From to and beyond. Dr. Angelos Amditis Research Director I-Sense, ICCS From Advanced Active Safety Systems to Automated Systems: From to and beyond Dr. Angelos Amditis Research Director I-Sense, ICCS Contents o Introduction o Motivation o Levels of automation o Evolution

More information

Systematic Testing with Quality-Oriented Test Strategies

Systematic Testing with Quality-Oriented Test Strategies Insert picture and click Align Title Graphic. Systematic Testing with Quality-Oriented Test Strategies Dr. Simon Burton, Manager Vector Consulting Services GmbH 2010. Vector Consulting Services GmbH. All

More information

Software Tools. Mechatronics, Embedded Control System Design, CAD, Finite Element Analysis, Information Technology and Big Data Areas.

Software Tools. Mechatronics, Embedded Control System Design, CAD, Finite Element Analysis, Information Technology and Big Data Areas. Mechatronics, Embedded Control System Design, CAD, Finite Element Analysis, Information Technology and Big Data Areas. Our Vision is to be the best technology services and products company with global

More information

High Quality of Service Highway (HQoSH) for automated vehicle

High Quality of Service Highway (HQoSH) for automated vehicle HQoSH - ITS Congress Rosario 1 High Quality of Service Highway (HQoSH) for automated vehicle Jacques Ehrlich Chair of PIARC TC B.1 HQoSH - ITS Congress Rosario 2 Introduction: why automation? To improve

More information

Dipl.-Ing. Felix Lotz. System Architecture & Behavior Planning

Dipl.-Ing. Felix Lotz. System Architecture & Behavior Planning Dipl.-Ing. Felix Lotz System Architecture & Behavior Planning 2 System Architecture & Behavior Planning Agenda Motivation and Challenges of Architecture Design PRORETA 3 Functional Architecture Insight

More information

The AI Car: Ramifications, Risks, & Opportunities

The AI Car: Ramifications, Risks, & Opportunities The AI Car: Ramifications, Risks, & Opportunities Heather Ashton Research Manager IDC Manufacturing Insights Jeff Hojlo Program Director IDC Manufacturing Insights Agenda Industry Trends, What s Driving

More information

AUTOMATING SAFETY ENGINEERING WITH MODEL-BASED TECHNIQUES

AUTOMATING SAFETY ENGINEERING WITH MODEL-BASED TECHNIQUES WHITE PAPER AUTOMATING SAFETY ENGINEERING WITH MODEL-BASED TECHNIQUES E-mail: WWW: info@metacase.com http://www.metacase.com Ylistönmäentie 31 FI 40500 Jyväskylä, Finland Phone +358 400 648 606 Fax +358

More information

Automated Black Box Testing Using High Level Abstraction SUMMARY 1 INTRODUCTION. 1.1 Background

Automated Black Box Testing Using High Level Abstraction SUMMARY 1 INTRODUCTION. 1.1 Background Automated Black Box Testing Using High Level Abstraction Dake Song, MIRSE, USA Dr Uli Dobler, FIRSE, Germany Zach Song, EIT, Canada SUMMARY One of the big bottlenecks of modern signalling projects lies

More information

AdaptIVe Current Status

AdaptIVe Current Status Felix Fahrenkrog Institut für Kraftfahrzeuge, RWTH Aachen University AdaptIVe Current Status Bordeaux 04 October 2015 // AdaptIVe structure 2 // 4 October 2015 // Projects facts Budget: EUR 25 Million

More information

HVTT15: Fleet Safety Technology and Management: Woodrooffe INTEGRATING SAFETY TECHNOLOGY AND MANAGEMENT PRACTICE FOR IMPROVED FLEET SAFETY

HVTT15: Fleet Safety Technology and Management: Woodrooffe INTEGRATING SAFETY TECHNOLOGY AND MANAGEMENT PRACTICE FOR IMPROVED FLEET SAFETY INTEGRATING SAFETY TECHNOLOGY AND MANAGEMENT PRACTICE FOR IMPROVED FLEET SAFETY J.H. WOODROOFFE Woodrooffe Dynamics Ltd Research Scientist Emeritus University of Michigan. Abstract This paper examines

More information

SeamleSS Implementation. based on ISO 26262

SeamleSS Implementation. based on ISO 26262 SeamleSS Implementation of ECU Software based on ISO 26262 Growing use of the ISO 26262 standard is producing clearly defined requirements for the development and validation of E/E systems. Vector describes

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: Rosemount 5300 Series 4-20mA HART Guided Wave Radar Level and Interface Transmitter Device Label SW 2.A1 2.J0 Customer: Rosemount Tank Radar (an Emerson

More information