Workflow between ISO 26262 and ISO 21448 Standards for Autonomous Vehicles

Kaushik Madala, Carlos Avalos-Gonzalez, G. Krithivasan
{"title":"Workflow between ISO 26262 and ISO 21448 Standards for Autonomous Vehicles","authors":"Kaushik Madala, Carlos Avalos-Gonzalez, G. Krithivasan","doi":"10.56094/jss.v57i1.6","DOIUrl":null,"url":null,"abstract":"Assuring safety is important in autonomous vehicles. The safety related to autonomous vehicles can be primarily viewed from two perspectives: the functional safety (FuSa) perspective and the safety of the intended functionality (SOTIF) perspective. While FuSa ensures the system has an acceptable risk with respect to malfunctions of electrical and electronic components, SOTIF ensures the system has an acceptable risk with respect to functional insufficiencies and performance limitations. \nISO 26262 and ISO 21448 are the state-of-the-art international standards used to ensure compliance with FuSa and SOTIF for autonomous automotive systems, respectively. The ISO 21448 standard mentions the need for alignment of ISO 26262 activities with the ISO 21448 activities and describes the mapping at a very high level. However, given the iterative nature of SOTIF activities in ISO 21448, the workflow between the two standards is not a direct one-toone mapping. Hence, we need a clear understanding how we can align ISO 26262 and ISO 21448 activities, and on how analysis done in one standard can impact the other. \nTo achieve this, in this paper we propose a detailed workflow between ISO 26262 and ISO 21448 standards. We discuss guidelines on how to find if a change to design due to SOTIF modification can affect FuSa analysis and vice versa. We also discuss the aspects we need to consider for agile development when we want to ensure the system being","PeriodicalId":250838,"journal":{"name":"Journal of System Safety","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of System Safety","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.56094/jss.v57i1.6","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Assuring safety is important in autonomous vehicles. The safety related to autonomous vehicles can be primarily viewed from two perspectives: the functional safety (FuSa) perspective and the safety of the intended functionality (SOTIF) perspective. While FuSa ensures the system has an acceptable risk with respect to malfunctions of electrical and electronic components, SOTIF ensures the system has an acceptable risk with respect to functional insufficiencies and performance limitations. ISO 26262 and ISO 21448 are the state-of-the-art international standards used to ensure compliance with FuSa and SOTIF for autonomous automotive systems, respectively. The ISO 21448 standard mentions the need for alignment of ISO 26262 activities with the ISO 21448 activities and describes the mapping at a very high level. However, given the iterative nature of SOTIF activities in ISO 21448, the workflow between the two standards is not a direct one-toone mapping. Hence, we need a clear understanding how we can align ISO 26262 and ISO 21448 activities, and on how analysis done in one standard can impact the other. To achieve this, in this paper we propose a detailed workflow between ISO 26262 and ISO 21448 standards. We discuss guidelines on how to find if a change to design due to SOTIF modification can affect FuSa analysis and vice versa. We also discuss the aspects we need to consider for agile development when we want to ensure the system being
自动驾驶汽车ISO 26262和ISO 21448标准之间的工作流程
确保安全对于自动驾驶汽车来说非常重要。与自动驾驶汽车相关的安全主要可以从两个角度来看待:功能安全(FuSa)角度和预期功能安全(SOTIF)角度。FuSa确保系统在电气和电子元件故障方面具有可接受的风险,SOTIF确保系统在功能不足和性能限制方面具有可接受的风险。ISO 26262和ISO 21448是最先进的国际标准,分别用于确保自动驾驶汽车系统符合FuSa和SOTIF。ISO 21448标准提到了将ISO 26262活动与ISO 21448活动保持一致的需要,并在非常高的级别上描述了映射。然而,考虑到ISO 21448中SOTIF活动的迭代性质,两个标准之间的工作流并不是直接的一对一映射。因此,我们需要清楚地了解如何使ISO 26262和ISO 21448活动保持一致,以及在一个标准中进行的分析如何影响另一个标准。为了实现这一点,在本文中我们提出了ISO 26262和ISO 21448标准之间的详细工作流程。我们将讨论如何发现由于SOTIF修改而导致的设计更改是否会影响FuSa分析,反之亦然。我们还讨论了当我们想要确保系统的稳定性时,我们需要考虑的敏捷开发方面
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信