Browse Topic: Electronic control units

Items (1,537)
This paper proposes a nonlinear and robust State-Dependent Riccati Equation (SDRE) combined with H∞ control architecture for brake- by-wire systems, specifically designed to handle severe tire-road friction variations and μ-split scenarios. The primary objective is to maximize deceleration capabilities while rigorously maintaining yaw stability, trajectory tracking, and passenger comfort through jerk limitation. Situated within the domain of active safety, this research addresses robustness against real-world uncertainties by utilizing a high-fidelity 14-degree-of-freedom vehicle model that accounts for longitudinal, lateral, and yaw dynamics, suspension-induced pitch and roll effects, and nonlinear tire behavior with explicit load transfer. To ensure near-optimal slip tracking under variable surface conditions, the system employs online friction estimation via Extended and Unscented Kalman Filters (EKF/UKF) fusing wheel and IMU data to adaptively adjust slip targets. The control strategy is bifurcated: the SDRE component manages dominant nonlinearities through state-dependent gains to prevent wheel lock-up, while the H∞ component provides robust disturbance rejection against parametric uncertainties such as mass variations and sensor noise. Control efforts are distributed via a Quadratic Programming (QP) torque allocator featuring anti-windup mechanisms and explicit saturation handling to compensate for lateral drift during μ-split braking. Validation is conducted through a Model- in-the-Loop (MIL) to Software-in-the-Loop (SIL) pipeline using scenarios including wet surfaces and panic braking. Simulation results demonstrate enhanced yaw stability and controlled deceleration profiles compared to conventional baselines, ensuring computational feasibility for automotive Electronic Control Units (ECUs).
Cubillos, Ximena Celia Méndez
Series hybrid electric vehicles (HEVs) employ an electric motor for propulsion, while the internal combustion engine operates solely as a generator under energy-efficient speed and load conditions. Owing to this architecture, series HEVs can achieve high fuel efficiency with a relatively simple control structure. However, conventional energy management systems (EMSs) often prioritize battery state-of-charge (SOC) stabilization, which can lead to frequent engine start–stop operations and unnecessary fuel consumption, particularly in short-trip driving. This study aims to enhance energy management performance in series HEVs by optimizing engine power generation timing based on predicted short-trip duration. A computationally efficient, rule-based prediction model is developed using real-world driving data, in which short-trip duration is estimated from vehicle speed and acceleration. Due to its low computational load, the proposed model is suitable for implementation in an onboard electronic control unit (ECU). The proposed control strategy initiates engine power generation when the battery SOC is low and the predicted trip duration is long, and suppresses generation when the SOC is sufficiently high or the predicted trip is short. A detailed vehicle model incorporating an engine, generator, electric motor, inverter, and battery is developed in Modelica to evaluate the proposed strategy. Simulation results demonstrate that the proposed EMS significantly reduces the frequency of engine start–stop events, leading to fuel economy improvements of 3.6% under the WLTC (excluding the extra-high phase) and 13.4% in a real-world urban–rural driving cycle, compared with a commercialized baseline vehicle. These results confirm the effectiveness and practical applicability of the proposed EMS for passenger vehicle applications.
Mizushima, NorifumiSato, AkiraKuboyama, TatsuyaMoriyoshi, Yasuo
Electronic Control Units (ECUs) have played a pivotal role in transforming motorcars of yore into the modern vehicles we see on our roads today. They actively regulate the actuation of individual components and thus determine the characteristics of the whole system. In this, the behavior of the control functions heavily depends on their calibration parameters which engineers traditionally design by hand. This is taking place in an environment of rising customer expectations and steadily shorter product development cycles. At the same time, legislative requirements are increasing while emission standards are getting stricter. Considering the number of vehicle variants on top of all that, the conventional method is losing its practical and financial viability. Prior work has already demonstrated that optimal control functions can be automatically developed with reinforcement learning (RL); since the resulting functions are represented by artificial neural networks, they lack explainability, a circumstance which renders them challenging to employ in production vehicles. In this article, we present an explainable approach to automating the calibration process using residual RL which follows established automotive development principles. Its applicability is demonstrated by means of a map-based air path controller in a series control unit using a hardware-in-the-loop (HiL) platform. Starting with a sub-optimal map, the proposed methodology quickly converges to a calibration which closely resembles the reference in the series ECU. The results prove that the approach is suitable for the industry where it leads to better calibrations in significantly less time and requires virtually no human intervention.
Kampmeier, AndreasBadalian, KevinKoch, LucasLee, Sung-YongAndert, Jakob
Vehicle software updates are released more frequently and in increasingly shorter cycles, which places growing pressure on vehicle quality and final assembly line stability. In production environments, software related issues do not remain limited to the digital domain, since errors introduced by software updates can interrupt flashing and commissioning processes, slow down assembly, and increase rework, thereby directly affecting production throughput. Electronic control units are particularly sensitive to software updates because they are flashed and commissioned during vehicle production under strict timing constraints, and changes to flashing sequences, memory structures, configuration parameters, or function definitions can negatively influence commissioning behavior. This paper presents a novel approach where an established quality measure – First Time Quality (FTQ) – is used to quantify the impact of software updates in the final assembly. By comparing FTQ values from production weeks with software updates to reference weeks without software changes, the analysis identifies total FTQ deviations of 7 to 11 percentage points relative to a reference level of approximately 98.6 percent for major software releases. A two-stage root-cause classification combining automated error categorization with expert validation attributes approximately 3 to 4 percentage points of this deviation to software-update-related commissioning errors. Wilson score confidence intervals and Newcombe intervals confirm that these deviations are statistically robust at production-scale sample sizes. FTQ recovery to reference levels typically occurs within one to three weeks after a major release. Using real production data from a vehicle plant, the analysis demonstrates that even comparatively small reductions in FTQ indicate a relevant degradation of production quality and can propagate into downstream quality behavior. These findings show that FTQ is a suitable and production relevant indicator for determining the impact magnitude of software updates in automotive manufacturing and for supporting data-driven decisions in the software release process.
El Asad, AimanKöhler, KatjaHahn, MichaelReuss, Hans-Christian
Aircraft lighting systems play a vital role in ensuring operational safety, visibility, and regulatory compliance. Exterior lighting systems are essential for aircraft identification, navigation, collision avoidance, and ground operations under varying environmental conditions. These systems typically include navigation lights, anti-collision lights, landing and taxi lights. An aircraft lighting system comprises light sources, optical elements, electronic control units, power interfaces, wiring harnesses, and mechanical mounting structures. Among these components, optics are critical as they control light distribution, intensity, color accuracy, and efficiency while withstanding harsh aerospace environments such as vibration, thermal cycling, and aerodynamic loads. Aircraft exterior lights are subjected to severe thermo-mechanical stresses due to aerodynamic loading, vibration, and thermal cycling. The use of high-performance optical polymers such as Cyclo Olefin Polymers (COP) provides excellent light transmission and stability; however, their relatively lower mechanical toughness makes them susceptible to stress-induced cracking during assembly. In the baseline configuration, the Circuit Board Assembly (CBA) was fastened directly onto the optic using self-tapping screws. During assembly, frequent crack initiation was observed in the optic around the fastener locations, leading to concerns regarding reliability and maintainability. To address this issue, a redesigned mounting approach was developed that eliminated direct fastener penetration into the optic. Instead, the CBA is retained using a precision clamping mechanism, thereby distributing assembly loads uniformly and avoiding localized stress concentrations. COP material was retained due to its superior optical characteristics and compliance with photometric requirements for aircraft lighting applications. The redesigned optic-CBA interface was validated through Highly Accelerated Life Test (HALT), incorporating combined vibration, temperature, and thermal shock profiles. Test results confirmed that the new clamping design prevented crack formation, improved mechanical robustness, and ensured long-term optical performance. This paper presents the problem definition, root cause analysis of fastener-induced cracking, the design rationale for adopting a clamp-based mechanism, and detailed HALT validation results. The study highlights the importance of integrating material properties, fastening strategies, and environmental testing in the design of aerospace lighting systems. The proposed design methodology provides a pathway to enhance reliability and lifecycle performance of critical optical components in aircraft applications.
Vialta, FredericoS, NikhilKatageri, PraveenSP, PradeepSingh, Abhimanyu Kumar
This study presents a torque distribution strategy for dual-motor electric vehicles utilizing a Deep Deterministic Policy Gradient reinforcement learning algorithm designed to optimize energy consumption. By using a simplified architecture and replicable reward functions, the proposed agents rely exclusively on standard CAN bus signals, commanded longitudinal force, and the motors’ velocities, eliminating the need for specialized sensors or complex plant models. Two reinforcement agents are trained using two different reward functions: power-based and State of Charge-based. These agents are validated through high-fidelity CarSim–Simulink co-simulations across soft, medium, and severe acceleration scenarios, in which they demonstrate superior performance to traditional adaptive methods. In the most demanding scenario, a typical adaptive strategy achieves an additional 7.8% of power consumption and 85% of optimal energy recovery, while the proposed reinforcement learning strategies reach 0.6% more consumption and 95% energy recovery during braking compared to the theoretical optimum. These results highlight a practical, reliable solution for maximizing efficiency in dual-motor powertrains without significant computational burden on existing electronic control units.
Meléndez-Useros, MiguelViadero-Monasterio, FernandoLópez-Boada, María JesúsLópez-Boada, Beatriz
In recent years, the use of software-defined platforms has become increasingly prevalent. As a result, flashing ECUs has become an important factor in ensuring efficiency, quality, and compliance in vehicle production. Conventional approaches, such as final end-of-line flashing, are increasingly unsuitable for the growing amounts of data, complex dependencies, mixed physics and protocols, and traceability requirements. This SAE paper presents the current trends and challenges in ECU flashing. It highlights the impact of the exponential growth in software payloads and the necessary migration to offline and parallel workflows. This can only be achieved through closer integration with automated and robot-assisted production, considering the requirements of cybersecurity and verifiability. It also addresses the shift toward end-to-end flashing ecosystems, where updates are performed consistently from a single source covering the assembly line, warehouses, yards, workshops, and over-the-air updates. By comparing old and new approaches to high-speed flashing and presenting a new flashing strategy for OEMs derived from this, the paper provides a framework for understanding the future of ECU flashing on its way to software-defined mobility.
Böhlen, BorisBudak, OguzWells, Michael
The objective of this paper is to understand the effort required to integrate the hardware and software of in-vehicle cybersecurity systems. The in-vehicle cybersecurity method discussed is the SAE J1939-91C, which involves Network formation, Rekeying, and secure Message Exchange between Electronic Control Units (ECUs). The SAE J1939-91C network security protocol operates over a CAN-FD network to perform necessary cryptographic operations and key generation. To evaluate the method, test vectors were created to validate SAE J1939-91C key generations and cryptographic operations on the simulated ECU in-vehicle network system hardware (such as the Beacon or Pi devices). We introduce a lightweight, transport-agnostic benchmark comprising deterministic AES-CMAC test vectors and a simple verification utility, requiring no specialized hardware or build system. This minimal artifact set enables reproducible and machine-parsable validation of SAE J1939-91C security across diverse lab environments.
Zachos, MarkMedam, Krishna Teja
Automotive Original Equipment Manufacturers (OEMs) closely guard information about their products due to the significant investment in vehicle research and development. However, advancing automotive innovation often requires insights from existing systems to improve safety, efficiency, and performance. The Controller Area Network (CAN) bus remains the industry standard for communication between electronic control units (ECUs), yet CAN message specifications are typically proprietary and undocumented. This paper presents a case study involving the reverse engineering of CAN messages from a 2024 Toyota Grand Highlander powertrain. By capturing and analyzing communication between a diagnostics tester and the vehicle’s ECUs and replicating the communication, substituting A CANcase and software in place of a diagnostics tester, we were able to reverse engineer the vehicle’s CAN bus, demonstrating a practical methodology for decoding and interpreting CAN traffic without prior access to proprietary data. The approach highlights both general principles and OEM-specific variations in message structure and encoding. The goal of this work is to support researchers and engineers in developing their own reverse engineering workflows. It illustrates that while the foundational techniques are consistent, adapting to vehicle-specific implementations is essential. The paper aims to provide a replicable process and to encourage further exploration in the field of automotive CAN analysis.
Bolarinwa, EmmanuelPeters, Diane
Software-defined vehicles (SDVs) are reshaping automotive control architectures by shifting intelligence to embedded systems, where computational efficiency is paramount. This paper presents a systematic evaluation of control strategies (PID, LQR, MPC) for the classical control problem involving inverted pendulum on a cart under strict embedded constraints representative of software-defined vehicle ECUs. The objective is to evaluate and compare the performance of advanced control algorithms under varying control objectives when deployed on microcontrollers with constrained computational and memory resources, representative of the limitations encountered in embedded platforms used for SDVs. Furthermore, the study illustrates systematic optimization strategies that enable these algorithms to achieve real-time execution within such resource-constrained environments. Each control strategy is implemented with careful consideration of algorithmic complexity, real-time responsiveness, and resource utilization. Performance is evaluated across key metrics, enabling a comparative analysis that highlights trade-offs between control fidelity and hardware efficiency. By demonstrating how advanced control logic can be effectively deployed on constrained hardware, this work supports the broader goal of enabling intelligent, responsive vehicle behavior through software-centric design. The findings are particularly relevant for automotive and embedded engineers developing control systems for SDVs, where balancing performance and resource constraints is critical to achieving scalable, safe, and adaptive vehicle functionality.
Vupparige, VarunPandya, Vidit
Negotiating Keys for applications such as message authentication within a vehicle presents many problems as, in designing the algorithm; the algorithm must be able to be utilized by small, fixed-point processors. In addition, if there is a desire to do this algorithm in the manufacturing environment, there are severe time constraints placed on how long this algorithm can take, as there are strict station time requirements, which are expensive to change, and any time utilized in the plant can negatively affect vehicle throughput. Additionally, negotiating these keys between many ECUs can greatly increase the time required to negotiate a common key using standard multi-party Diffie-Hellman. Timing would also be an issue in the case of using pair-wise Diffie-Hellman for encryption and distribution of keys utilizing a key master. To solve these problems in multi-party key negotiation, we have utilized the Elliptic Curve variation of the Burmester-Desmedt (ECBD) algorithm. ECBD is relatively fast for a large number of ECUs, though the primary benefit of utilizing this algorithm is that calculation times for key negotiation vary only slightly for a wide range of number of participants. This enables the easy planning of negotiation time based on the number of keys the vehicle requires without worrying about the number of ECUs that require each key. This approach also has advantages over key injection and direct key distribution schemes because it does not require a secure environment at any point in the process. Thus, ECBD can be implemented without a secure clean room in either the manufacturing or maintenance environments. This is especially valuable in the maintenance environment, as it enables easy compliance with right to repair laws without endangering vehicle cyber security.
Van Dam, TheoMazzara, Bill
The emergence of AI-driven autonomy in modern vehicles marks a pivotal evolution in transportation, but it also introduces deep system-level vulnerabilities that span from sensor interface tampering to compute unit compromise and untrusted communication links. Autonomous vehicles (AVs) operate as distributed intelligent systems, relying on real-time data exchange between zonal gateways, AI compute platforms, and safety-critical electronic control units (ECUs). These interactions must be protected from hardware-based attacks that could compromise functional safety, system integrity, or operational availability. The deployment of AI-driven AVs introduces unprecedented levels of complexity. Sensors, AI compute clusters, and actuators communicate over multiple interfaces including Ethernet, PCIe, and MIPI, exposing vehicles to potential cybersecurity attacks. This paper proposes a unified, layered hardware security architecture tailored for AI-powered automated vehicles. Grounded in current automotive Ethernet and zonal architectures, it provides end-to-end trust using hardware interface security, accelerated- cryptography, and SRAM PUF-based key provisioning. All security primitives are anchored to hardware root of trust, delivering cryptographic identity, secure boot enforcement, and trusted key storage across the entire vehicle lifecycle.
C Suriyanarayanan, PavIacob, Radu
Floating-point arithmetic is widely used in automotive embedded software to scale Controller Area Network signals and calibration parameters with fractional factors such as 0.1. However, floating-point operations, even on microcontrollers equipped with floating-point units, can increase execution time and CPU load. In AUTOSAR architectures, converting floating-point scaling to fixed-point is not trivial because scaling semantics must be integrated consistently across components, yet AUTOSAR platform toolchains offer only limited automation at the Application Data Type level. Although CompuMethod definitions can express scaling, integration typically remains manual and distributed across application software components, reducing consistency and reusability. This study presents an architecture-driven methodology that formalizes fixed-point scaling as a centralized architectural service, realized through a parser-driven fixed-point macro generation pipeline. Standardized CAN DBC and calibration metadata are parsed to automatically generate integer-only macros for raw-to-physical and physical-to-raw transformations. The generated macros are integrated into dedicated AUTOSAR-compliant Scaling Service software components, consolidating scaling logic and improving reliability and maintainability. The approach requires no changes to toolchains, compiler settings, or hardware, enabling direct deployment in AUTOSAR-based software. The methodology was applied to a production-grade Integrated Charging Control Unit targeting Electric Vehicle Communication Controller software. Evaluation included cycle-accurate profiling, edge-based timing, isolated CPU load calculation, and average current measurement. Results show a 98.84% reduction in floating-point operations and a 92.67% reduction in conversion-related source lines. Task execution time decreased by 16.13%, CPU load decreased by 6.88%, and average current consumption showed a repeatable 0.81% reduction. These results demonstrate that the proposed methodology improves execution efficiency and is applicable to production AUTOSAR-based ECUs.
Lee, HoseokKo, Donggun
An on-road study has been conducted where a modern vehicle with a 3L turbocharged, PFDI gasoline engine was upfitted with appropriately sized uncoated GPFs for soot capture in a dual-bank exhaust line. The tested GPFs, whether clean or pre-loaded, were weighed to track their soot-load trends between representative real-world driving routes, where sensor data and exhaust temperature data was recorded. Thus, characterization of the passive soot regeneration process in the uncoated GPF was linked to elevated temperatures and vehicle drive cycles speeds.
Craig, AngusWarkins, Jason
This SAE Information Report is applicable to all types of automotive Electrical/Electronic (E/E) system architectures. It is important to develop a standard approach to commanding differentiable vehicle power policies from a centralized host Electronic Control Unit (ECU) location to applicable and capable ECUs and devices for maximum energy and thermal efficiency while creating and maintaining reuse across the ecosystem. Thus, adoption at a global level will enable efficiencies in product development and validation between all Original Equipment Manufacturers (OEMs) and the supply chain while maximizing reuse of ECUs and devices including respective power policies and capabilities between OEM vehicle systems. The definition of the Central System Power Manager (CSPM), VPPM Agent, Element Descriptor Tables, Element Descriptor Files, reference diagrams, and feature definitions are considered applicable and in scope for definition and standardization under SAE J3311. Software libraries and deployment, power state transition definition, vehicle network, protocol, component E/E topology/structure, electrical implementation schematics, and cybersecurity of transmission and storage of data are considered out of scope for definition and standardization under SAE J3311.
Vehicle Platform Power Management Committee
Modern vehicles require sophisticated, secure communication systems to handle the growing complexity of automotive technology. As in-vehicle networks become more integrated with external wireless services, they face increasing cybersecurity vulnerabilities. This paper introduces a specialized Proxy based security architecture designed specifically for Internet Protocol (IP) based communication within vehicles. The framework utilizes proxy servers as security gatekeepers that mediate data exchanges between Electronic Control Units (ECUs) and outside networks. At its foundation, this architecture implements comprehensive traffic management capabilities including filtering, validation, and encryption to ensure only legitimate data traverses the vehicle's internal systems. By embedding proxies within the automotive middleware layer, the framework enables advanced protective measures such as intrusion detection systems, granular access controls, and protected over-the-air (OTA) update channels. This strategy enhances both data security and system isolation, creating protective boundaries between critical vehicle operations and potential external attacks. The architecture particularly excels in supporting Vehicle-to-Everything (V2X) connectivity, facilitating seamless information exchange between vehicles, roadside infrastructure, and pedestrians. This capability is essential for enhancing roadway safety, optimizing traffic flow, and supporting autonomous driving technologies. The system incorporates dedicated proxy modules for specialized protocols including Trivial File Transfer Protocol (TFTP), Diagnostic Over Internet Protocol (Doip), and Message Queuing Telemetry Transport (MQTT), each fulfilling specific functions in vehicle diagnostics, software updates, and telemetry data management. Performance evaluations will measure latency and throughput metrics to validate the architecture's efficiency and reliability. The framework's modular design aims to provide scalability and adaptability to accommodate both technological advancements and emerging security challenges. The proxy-based security framework presented offers a holistic and forward-looking approach to safeguarding in-vehicle networks. It provides automotive manufacturers with the tools to develop connected vehicles that combine intelligence and efficiency with robust protection against diverse cybersecurity threats.
M, ArvindPraneetha, Appana DurgaRemalli, Ravi Teja
As vehicles evolve toward increased automation and comfort, Power Operated Tailgate (POT) have become a common feature, especially in premium and mid-segment vehicles. These systems, although user-friendly on the surface, involve complex interactions between electronic control units (ECUs), sensors, actuators, and mechanical systems. Ensuring the reliability, safety, and robustness of these features under diverse operating conditions presents a significant validation challenge. Traditional testing methods, which rely heavily on physical prototypes and manual interaction, are often time-consuming, expensive, and prone to human error. Moreover, testing certain safety [3] features, such as anti-pinch or stall protection, under real physical conditions poses inherent risks and limitations. This paper presents a Hardware-in-Loop (HiL)[1] based testing approach for POT [2] systems, offering a safer, faster, and more comprehensive alternative to conventional validation methods. The HiL platform is built around a real-time test environment using Real Time Software, framework, integrated with MATLAB/Simulink [5] based plant models representing motor behaviour, hall sensors, and tailgate dynamics. The ECU under test communicates via CAN [4] and other physical I/Os, while the plant models simulate realistic vehicle responses in real time. The HiL approach enables full automation of functional, diagnostic, and safety validation of the tailgate system including open/close commands, fault injections (open circuit, short faults), latch and sensor logic, and anti-pinch scenarios. This methodology significantly reduces prototype dependence, accelerates ECU software validation, and increases overall test coverage. Results show substantial improvements in fault detection, regression testing efficiency. The proposed solution demonstrates how HiL [1] testing is not only a cost-effective validation method but also a strategic enabler for scalable and safe development of automotive mechatronic systems. This paper concludes by discussing the long-term benefits and future scope of enhancing the HiL setup with remote diagnostics, and seamless integration with other systems. The automotive industry is undergoing a transformation with a growing emphasis on comfort, convenience, and automation. Power Operated Tailgate (POT) have become an integral part of modern vehicles, offering hands-free access, anti-pinch
More, ShwetaGhanwat, HemantShetti, SurajJape, AkshayKulkarni, ShraddhaJagdale, Nitin
The rapid evolution of electric vehicles (EVs) has amplified the demand for highly integrated, efficient, and intelligent powertrain architectures. In the current automotive landscape, EV powertrain systems are often composed of discrete ECUs such as the OBC, MCU, DC-DC Converter, PDU, and VCU, each operating in isolation. This fragmented approach adds wiring harness complexity, control latency, system inefficiency, and inflates costs making it harder for OEMs to scale operations, lower expenses, and accelerate time-to-market. The technical gap lies in the absence of a centralized intelligence capable of seamlessly managing and synchronizing the five key powertrain aggregates: OBC, MCU, DC-DC, PDU, and VCU under a unified software and hardware platform. This fragmentation leads to redundancy in computation, increased BOM cost, and challenges in system diagnostics, leading to sub-optimal vehicle performance. This paper addresses the core issue of fragmented control architectures in EV powertrains by proposing a domain controller based integrated solution for EV powertrain referred as Integrated Powertrain Domain Controller (IPDC).
Kumar, MayankDeosarkar, PankajInamdar, SumerTayade, Nikhil
With the increasing complexity and connectivity in modern vehicles, cybersecurity has become an indispensable technology. In the era of Software-Defined Vehicles (SDVs) and Ethernet-based architectures, robust authentication between Electronic Control Units (ECUs) is critical to establish a trust. Further, the cloud connected ECUs must perform authentication with backend servers. These authentication requirements often demand multiple certificates to be provisioned within a vehicle, ensuring secure communication between various combinations of ECUs. As a result, a single ECU may end up storing multiple certificates, each serving a specific purpose. This work proposes a method to limit the number of certificates required in a given ECU without compromising security. We introduce a Cross-Intermediate Certificate Authority (Cross-ICA) Trust Architecture, which enables the use of a single certificate per ECU for inter-ECU communication as well as backend server authentication. In this architecture, each ECU is issued a certificate from an Intermediate Certificate Authority (ICA), with all ICAs anchored to a common Root CA. The ICAs are structured based on the nature or domain of the ECU (e.g., infotainment, telematics, ADAS), while maintaining trust through the shared root. During the authentication handshake, the ECU presents its certificate chain. The receiving party (another ECU or backend server) verifies the chain up to the common root, thus establishing mutual trust, even if their certificates originate from different ICAs. The participating ECUs don’t need prior information about certificate chains of each other. This approach reduces certificate storage requirements, simplifies certificate management, and maintains strong security by leveraging a scalable trust model anchored to a unified root. The proposed method is primarily validated in a virtual environment using an OpenSSL implementation. Additionally, the approach is verified on a simulation setup involving two ECU and cloud connectivity, establishing mTLS with certificates issued by cross-signed Intermediate Certificate Authorities (ICAs).
Venugopal, VaisakhGoyal, YogendraRaja J, SolomonRai, AjayRath, Sowjanya
There is rapidly increasing advancement in Connectivity, Autonomous, Subscription and Electrification features in vehicles which are being developed. These trends have resulted in an increase in attack surface and security risks on vehicles. To handle these growing risks, it has become important to include passive security systems such as Intrusion detection systems (IDS) which can detect successful or possible attempts of intrusion into vehicle systems compromising their security. In vehicles based on Zonal Architecture, two types of IDS can be implemented, Network based IDS (NIDS) and Host Based IDS (HIDS). The NIDS is implemented in Gateway Electronic Control Unit (ECU) and can monitor multiple networks connected to Gateway, whereas the HIDS usually monitors one single host ECU. Extensive research material is available on NIDS for CAN Networks. For example, the CAN Network in a vehicle is monitored for various abnormal behaviours such as increased busload and invalid signal values. But most of the literature doesn't answer the question, how to ensure the monitoring achieved by NIDS is sufficient? In this paper we try to answer the question by deriving requirements for security monitoring of in-vehicle CAN network using a novel method to guarantee sufficiency in terms of having better coverage of intrusion scenarios. We employ a fusion of (i) Threat Analysis and Risk Assessment approach and (ii) Attack Tree Based approach for deriving security monitoring requirements for the CAN network. We show that security requirements derived by our approach have better coverage of intrusion scenarios, thus enhancing the efficiency in intrusion detection.
E L, Nanda KumarMutagi, MeghaSonnad, PreetiSharma, Dhiraj
With the rapid advancement of connected vehicle technologies, infotainment Electronic Control Units (ECUs) have become central to user interaction and connectivity within modern vehicles. However, this enhanced functionality has introduced new vulnerabilities to cyberattacks. This paper explores the application of Artificial Intelligence (AI) in enhancing the cybersecurity framework of infotainment ECUs. The study introduces AI-powered modules for threat detection and response, presents an integrated architecture, and validates performance through simulation using MATLAB, CANoe, and NS-3. This approach addresses real-time intrusion detection, anomaly analysis, and voice command security. Key benefits include zero-day exploit resistance, scalability, and continuous protection via OTA updates. The paper references real-world automotive cyberattack cases such as OTA vulnerability patches, Connected Drive exploits, and Uconnect hack, emphasizing the critical need for AI-enabled proactive cybersecurity frameworks.
More, ShwetaKulkarni, ShraddhaKumar, PriyanshuGhanwat, HemantJoshi, Vivek
The automotive industry is undergoing a transformational shift with the addition of Virtual ECU in the development of software and validation. The Level 3 Virtual ECU concept will lead to the transformation in the SDLC process, as early detection of defects will have a significant impact on cost and effort reduction. This paper explains the application of a Level 3 virtual ECU which can enable to perform testing in initial period considering the Shift Left Strategy, which will significantly reduce development time. This paper demonstrates various development and validation strategies of virtual ECU and how it can impact project timeline.
Bhopi, AmeySengar, Bhan
The proliferation of connectivity features (V2X, OTA updates, diagnostics) in modern two-wheelers significantly expands the attack surface, demanding robust security measures. However, the anticipated arrival of quantum computers threatens to break widely deployed publickey cryptography (RSA, ECC), rendering current security protocols obsolete. This paper addresses the critical need for quantum-resistant security in the automotive domain, specifically focusing on the unique challenges of two-wheeler embedded systems. This work presents an original analytical and experimental evaluation of implementing selected Post-Quantum Cryptography (PQC) algorithms, primarily focusing on NIST PQC standardization candidates (e.g., lattice-based KEMs/signatures like Kyber/Dilithium), on microcontroller platforms representative of those used in two-wheeler Electronic Control Units (ECUs) - typically ARM Cortex-M series devices characterized by limited computational power, memory (RAM/ROM), and strict real-time requirements. Our experimental study involved porting and optimizing PQC reference implementations for these constrained environments. We rigorously benchmarked key performance indicators, including key generation time, encapsulation/decapsulation speeds, signing/verification times, and memory footprint (stack usage, code size). The results demonstrate the feasibility of deploying specific PQC schemes, achieving practical execution times (e.g., key operations completing within tens to hundreds of milliseconds) and manageable memory overhead (fitting within typical MCU constraints) for securing functions like secure boot, firmware updates, and authenticated communication. Performance trade-offs between different PQC algorithms regarding speed, key/signature sizes, and memory consumption are analyzed. The significance of this contribution lies in providing the first quantitative performance data and feasibility analysis for PQC adoption within the specific context of two-wheeler embedded systems. These findings offer crucial insights for OEMs and suppliers planning the transition to quantum-safe security architectures, ensuring the long-term security and trustworthiness of connected two-wheelers against future cryptographic threats.
Mishra, Abhigyan
This study introduces a novel Large Language Model (LLM)-driven approach for comprehensive diagnosis and prognostics of vehicle faults, leveraging Diagnostic Trouble Codes (DTCs) in line with industry-standard automation protocols. The proposed model asks for significant advancement in automotive diagnostics by reasoning through the root causes behind the fault codes given by DTC document to enhance fault interpretability and maintenance efficiency, primarily for the technician and in few cases, the vehicle owner. Here LLM is trained on vehicle specific service manuals, sensor datasets, historical fault logs, and Original Equipment Manufacturer (OEM)-specific DTC definitions, which leads to context-aware understanding of the vehicle situation and correlation of incoming faults. Approach validation has been done using field level real-world vehicle dataset for different running scenarios, demonstrating model’s ability to detect complex fault chains and successfully predicting the associated root cause. By utilizing time series based future projection of the vehicle pattern, this approach could also predict the probable future faults as well as the requisite steps needed to prevent them. Overall, key contributions of this work include: (1) a modular diagnostic framework that seamlessly integrates different electronic control unit (ECU) architectures for sequential root cause analysis of vehicle faults, (2) cross-platform compatibility allowing utility across varied vehicle models and platforms, and (3) a user-friendly interface that eliminates the need for technical expertise by generating output data into simple, actionable insights. This work was benchmarked against traditional rule-based diagnostic tools and showed 50-70% reduction in the troubleshooting time for Root cause analysis (RCA). In the prognosis front, model could predict upcoming possible faults in the Battery behavior with significant accuracy. The framework also supports continuous learning by integrating new fault patterns, ensuring adaptability over time. This paper establishes the potential of integrating advanced language models into the automotive diagnostics pipeline and provides a scalable, intelligent, and intuitive solution for next-generation vehicle fault management.
Pandey, SuchitJoshi, PawanKondhare, ManishCH, Sri RamGajbhiye, AbhishekS, Adm Akhinlal
Automotive systems are increasingly adopting data-driven and intelligent functionality in the areas of predictive maintenance, virtual sensors and diagnostics. This has led to a need for the AI models to be directly run on vehicle ECUs. However, most of these ECUs – especially those in cost-sensitive or legacy platforms lack the computational capacity and parallel processing support required for standard AI implementations. Given the stringent real-time and reliability requirements in automotive environments, deploying such models presents a unique challenge. This paper proposes a practical methodology to optimize both the training and deployment phases of AI models for low-computation ECUs that operate without parallelism. Designing lightweight model architectures, using pruning and quantization techniques to minimize resource utilization, and putting in place a strategy appropriate for single-threaded execution are the three main objectives of the developed approach. The goal is to guarantee that the final models satisfy real-time requirements without sacrificing prediction accuracy. To evaluate the effectiveness of the proposed method, a set of use cases relevant to automotive virtual sensors and condition monitoring were selected. Importantly, latency remains within the acceptable limits for in-vehicle ECUs. Analysis was performed for memory and CPU usage to ensure that the reliability of the operation is never compromised. This work provides a path for deploying AI in embedded automotive environments without the need for hardware upgrades. It supports OEMs and suppliers aiming to bring intelligent features to market efficiently while staying within the constraints of existing ECU platforms.
Sharma, SahilMathew, Melvin John
Threat Analysis and Risk Assessment (TARA) is a continuous activity, acting as a foundation of cybersecurity analysis for electrical and electronics automotive products. Existing TARA methodologies in the automotive domain exhibits challenges due to redundant and manual processes, particularly in handling recurring common assets across Electronic Control Units (ECUs) and functional domains. Two primary approaches observed for performing TARA are Manual-Asset-Centric TARA and Catalogue-Driven TARA. Manual-Asset Centric TARA is constructed from scratch by manually identifying the assets, calculating risks by likelihood, and impact determination. Catalogue-Driven TARA utilizes the precompiled likelihood and impact against identified assets. Both approaches lack standardized and modular mechanisms for abstraction and reuse. This results in poor scalability, increased efforts, and difficulty in maintaining consistency across vehicle platforms. The proposed method in this research overcomes such challenges, named as “MOSAIC-TARA”. It is a Modular, Scalable, Adaptive, Interoperable, Comprehensive TARA, decomposing a vehicle system into functional domains or ECUs, and further into its components. Each module is independently assessed and analyzed for potential threats, damage scenarios, and security goals, formulating the multiple TARA modules. These independent individual TARAs are then aggregated based on the architecture to derive ECU level TARA. The modularity of this method supports reusability of assessments across different ECUs, functional domains, and vehicle platforms. This enables optimized and efficient TARA tailored to different system configurations. Additionally, the presented approach introduces damage scenarios classification based on impact criticality, as the same component may lead to varying damage impact depending on the context. Thus, the TARA modules are developed for various levels of damage impacts, provides adaptability towards impact criticality of selected ECU or its functions. MOSIAC-TARA aligns with ISO/SAE 21434 and supports efficient reusable risk-driven design.
Goyal, YogendraSinha, SwatiSutar, SwapnilJaisingh, Sanjay
Artificial Intelligence and Machine learning models have a large scope and application in Automotive embedded systems. These models are used in the automotive world for various applications like calibration, simulation, predictions, etc. These models are generally very accurate and play the role of a virtual sensor. However, the AI/ML models are resource intensive which makes them difficult to execute on largely optimized automotive embedded systems. The models also need to follow safety standards like ASIL-D. The current work involves creating a Global DoE with ETAS ASCMO to generate data from a 125cc single to create AI/ML model for the engine outputs like Torque, T3, Mid-cat temperatures etc. The created models were validated across the operating space of the engine and found to have good accuracies. With ETAS Embedded AI Coder, the torque and T3 prediction AI models were converted to embedded code which can be easily used as a virtual sensor in real time. Using these AI models, accurate predictions can be made on the ECU in real time without an actual sensor, thus paving to remove these sensors and reduce cost per vehicle.
Chouhan, Vineet SinghBulandani, SaurabhKumar, AlokVarsha, AnuroopaP R, Renjith
The rising software complexity in Automotive industry demands reusable, hardware-agnostic development frameworks. AUTOSAR (Automotive Open System Architecture) provides a standardized, scalable ECU software architecture but cost-effective tooling and modern workflows are critical for broad adoption and competitiveness. One such area is for AUTOSAR configuration and authoring of Autosar architecture. Current solutions include commercial offerings built by vendors on top of ARTOP (ArTOP is an eclipse-based ecosystem maintained by AUTOSAR consortium) and open-source python implementations. Commercial tools are prohibitive in cost, have complicated development workflows, are difficult to automate and lack quick integration with other tools. Python-based solutions are often community driven with small developer teams and face challenges. These tools are not mature enough, have staggered development, security concerns, liability issues, lack of approvals and other similar issues. These libraries do not use ArTOP, which Autosar Consortium updates with every release, thus more work for keeping them up to date. Thus, we explore a custom, fully validated, in-house tool chain based on ArTOP. By engaging our experience, the solution will cover most development use cases. Using ArTOP as a base, we reduce the effort required for each new release. The solution is cost effective, has a modular development workflow, customizable validation rules and transformation pipelines. The tool also has an exposed API layer for automation, CI/CD, external tool integration, which can be leveraged to harness generative AI for authoring, compliance, and development. The new tool is poised to further slash development cycles and democratize AUTOSAR configuration for domain experts—delivering a scalable, liability-backed foundation for next-generation automotive software toolchains. In this paper, we detail the proposed Autosar workflow, tool architecture, highlighting benefits. We also explore development and maintenance strategy. Lastly, we will explore AI assisted authoring and compliance use cases.
Daware, KartikGarg, MuditPasupuleti, Raju
The Vehicle software is moving towards software-centric architectures and hence software-defined vehicles. With this transition, there is a need to handle various challenges posed during development and validation. Some of the challenges include unavailability of hardware limiting the evaluation of various hardware options, board bring-up and hence leading to delays in software development targeted for the hardware, eventually leading to delayed validation cycles. To overcome the above challenges, we present in this whitepaper a virtual ECU (vECU) framework integrated with a CI/CD pipeline. A Virtual ECU (Electronic Control Unit) is a software-based emulation of a physical ECU. The adoption of virtual ECUs empowers development teams to commence software development prior to the availability of physical hardware. Multiple tools are available to demonstrate virtual ECUs, for example, QEMU, Synopsys, QNX Cabin, etc. vECU setup, when paired with a CI/CD pipeline, allows continuous integration, rapid iterations, and improved testing coverage. The integrated framework for virtual ECU and CI/CD thereby Significantly expedites the entire software lifecycle, enabling early-stage software development and validation. This research paper presents a vECU framework developed using QEMU as the virtualization tool to simulate NXP high-performance compute platforms. Instead of directly emulating hardware, custom Yocto-based images for GoldBox and i.MX8 were run on QEMU to replicate Body, Gateway, and Cluster functionalities. For CI/CD integration, Gerrit, Jenkins, and Azure DevOps were used to enable automated builds, reviews, and validation workflows. To establish communication, CAN and Ethernet protocols were utilized. Specifically, vSomeIP was used over Ethernet to enable service-oriented communication. Integration of this framework into the SDV workflow has shown significant improvements in early development and validation.
Singh, JyotsanaShaikh, ArshiyaMane, RahulBurangi, Piyush
Thermal comfort is increasingly recognized as a vital component of the in-vehicle user experience, influencing both occupant satisfaction and perceived vehicle quality. At the core of this functionality is the Climate Control Module (CCM), a dedicated embedded Electronic Control Unit (ECU) within automotive HVAC system [6]. The CCM orchestrates temperature regulation, airflow distribution, and dynamic environmental adaptation based on sensor inputs and user preferences. This paper introduces a comprehensive Hardware-in-the-Loop (HIL) [3] testing framework to validate CCM performance under realistic and repeatable conditions. The framework eliminates the dependencies on physical input devices—such as the Climate Control Head (CCH) and Infotainment Head Unit (HU)—by implementing virtual interfaces using real-time controller, and Dynamic System modelling framework for plant models. These virtual components replicate the behaviour of physical systems, enabling closed loop testing with high fidelity. Sensor data simulate critical environmental parameters including solar radiation load, outside air temperature (OAT), and evaporator temperature etc. Actuator of HVAC components such as blower motors, air flap actuators, and compressor control systems are used to represent real loads. The HIL setup supports real-time signal simulation, protocol emulation over LIN and CAN networks, and automated test execution. Additionally, fault injection capabilities allow for robust validation of diagnostic strategies and safety mechanisms. The framework facilitates early-stage validation, accelerates development cycles, and enhances product maturity by enabling exhaustive scenario testing without reliance on physical prototypes. Key outcomes include improved test coverage, reduced time-to-market, and scalable integration for future vehicle platforms. The paper also outlines future directions, including the incorporation of thermal intelligence through AI/ML algorithms, and the deployment of remote or cloud-based testing environments to support distributed development teams.
More, ShwetaShinde, VivekTurankar, DarshanaPatel, DafiyaGosavi, SantoshGhanwat, Hemant
In the development of the automotive electronic control unit (ECU), to keep performance at the desired level, what remains constant is to verify, evaluate, and validate electronic control units. Nowadays, Cars have multiple ECUs even in the range of fifty. Software is validated by a tester using a target ECU, Controller Area network (CAN) communication, and some Input/Output simulation techniques. Also, in some applications, a virtual environment is created for testing. In this paper, the method of Integration testing of Automotive Open System Architecture (AUTOSAR) modules is presented with AUTOSAR software specification as its input. This makes standard test cases as SWS remains the same for AUTOSAR standard release. It enables a platform to efficiently test all layers of AUTOSAR base software (BSW) modules after integration. For the demonstration, TriCore micro controller TC377TX from Infineon is used. Same controllers are usually used in the development of automotive ECUs for various applications. Using winIDEA debugger, setup becomes easier to operate for any new person as it supports both debug and flash mode operation. A simplistic approach is presented in this paper to use the setup while testing. Requirement based testing covers all the implemented features in the software, their connections with higher and lower layers in AUTOSAR architecture. Certain test cases require CAN communication for transferring signals to different ECUs and receive information from them. For those test cases, CANoe Vector hardware is used. Testing using debugging methods is covered in the WinIDEA debugger by checking local and Global variables and putting the breakpoints. For writing test cases and maintaining the defect logs, documentation is prepared and tracked. Requirement traceability is maintained with the test cases to find test case for any requirement easily. This system improvises efficiency and simplifies the testing of AUTOSAR based development. Also, paper demonstrates it as a standard process.
Kelkar, RenuPatil, Vardhman
This paper presents a novel Hardware-in-the-Loop (HiL) testing framework for validating panoramic Sunroof systems independent of infotainment module availability. The increasing complexity of modern automotive features—such as rain-sensing auto-close, global closure, and voice-command operation—has rendered traditional vehicle-based validation methods inefficient, resource-intensive, and late in the development cycle. To overcome these challenges, a real-time HiL system was developed using the Real time simulation, integrated with Simulink-based models for simulation, control, and fault injection. Unlike prior approaches that depend on complete vehicle integration, this methodology enables early-stage testing of Sunroof ECU behavior across open, close, tilt, and shade operations, even under multi-source input conflicts and fault conditions. Key innovations include the emulation of real-world conditions such as simultaneous voice and manual commands, sensor faults, and environmental triggers using a software-controlled test environment. The system helps more than 60 automated test cases and makes regression testing easier without hardware reconfiguration, accelerating feedback cycles and enhancing software readiness. The results show that the framework efficiently identifies test case failures and speeds up validation timelines. The simulation model allows reuse for all ECU variants and streamlines test expansion for future functionalities. Simulation contributes a scalable and infotainment-free testing approach that enhances product quality, reduces dependency on physical prototypes, and supports continuous system integration in automotive control system.
Ghanwat, HemantLad, Aniket SuryakantJoshi, VivekMore, Shweta
Modern vehicles use a network of Electronic Control Units (ECUs) that transmit over thousands of signals. The production of these ECUs is fraught with cybersecurity challenges that can lead to significant vulnerabilities, which pose risks not only to the suppliers but also to Original Equipment Manufacturers (OEMs) and end users. The automotive industry increasingly relies on sophisticated electronic systems but there is a lack of standardized approach to ensure implementation of robust cybersecurity measures during ECU production. It is imperative to establish effective safeguards against potential threats to ensure vehicle and passenger safety. This paper proposes a comprehensive approach to enhancing cybersecurity in ECU production. Key measures include the activation of cybersecurity protections in production units, secure flashing at plant and memory upload process, effective plant password generation, and securing the debug interface to prevent unauthorized access. By implementing these measures during the production process, suppliers can significantly reduce the risk of security breaches. The value of this paper lies in its potential to standardize and recommend essential cybersecurity practices within existing standards. By adhering to these proposed processes, suppliers can uniformly enhance the security in ECU production, thereby minimizing vulnerabilities. This uniformity not only benefits the suppliers but also ensures a higher level of protection for OEMs and end users. The recommendations provided in this paper aim to contribute to the development of robust cybersecurity standards in the automotive industry, fostering a safer and more secure production environment. The study is based on current and existing cybersecurity implementations at the supplier side during the ECU production process. The findings and recommendations are derived from practical experience and observations, aiming to provide actionable insights. This paper is at the stage of proposing these recommendations for inclusion in available cybersecurity standards, with the goal of achieving widespread adoption across the industry.
Kulanthaisamy, NagarajanM S, TejaswiniSankar, Ganesh
The proliferation of wireless charging technology in electric vehicles (EVs) introduces novel cybersecurity challenges that require comprehensive threat analysis and resilient design strategies. This paper presents a proactive framework for assessing and mitigating cybersecurity risks in wireless charger Electronic Control Units (ECUs), addressing the unique vulnerabilities inherent in electromagnetic power transfer systems. Through systematic threat modeling, vulnerability assessment, and the development of defense-in-depth strategies, this research establishes design principles for creating robust wireless charging ecosystems resistant to cyber threats. The proposed framework integrates hardware security modules, encrypted communication protocols, and adaptive threat detection mechanisms to ensure operational integrity while maintaining charging efficiency. Experimental validation demonstrates the effectiveness of the proposed security measures in preventing unauthorized access, data manipulation, and service disruption attacks while preserving system performance.
Uthaman, SreekumarMulay, Abhijit BGadekar, Pundlik
With the rapid adoption of electric vehicles (EVs), ensuring the reliability, safety, and cost-effectiveness of power electronic subsystems such as onboard chargers, DC-DC converters, and vehicle control units (VCUs) has become a critical engineering focus. These components require thorough validation using precise calibration and communication protocols. This paper presents the development and implementation of an optimized software stack for the Universal Measurement and Calibration Protocol (XCP), aimed at real-time validation of VCUs using next-generation communication methods such as CAN, CAN-FD, and Ethernet. The stack facilitates read/write access to the ECU’s internal memory in runtime, enabling efficient diagnostics, calibration, and parameter tuning without hardware modifications. It is designed to be modular, platform-independent, and compatible with microcontrollers across different EV platforms. By utilizing the ASAM-compliant protocol architecture, the proposed system significantly reduces dependency on expensive proprietary tools, offering a cost-effective alternative for the Indian EV industry.
Uthaman, Sreekumar
The rapid evolution of in-vehicle electronic systems toward zonal based architectures introduces a new layer of complexity in automotive diagnostics. Traditional architectures, built on Controller Area Network (CAN) and Local Interconnect Network (LIN) protocols, operate on a uniform Real-Time Operating System (RTOS), enabling simplified and consistent diagnostic workflows across Electronic Control Units (ECUs). However, next-generation platforms must accommodate diverse communication protocols (e.g., CAN, LIN, DoIP, SOME/IP) and heterogeneous operating systems (e.g., RTOS, Linux, QNX), resulting in fragmented and inflexible diagnostic processes. This paper presents a Diagnostic controller that addresses these challenges by enabling unified, scalable, and adaptive diagnostic capabilities across modern vehicle platforms. The proposed system consolidates protocol handling at the application level, abstracts diagnostic complexities, and allows cross-platform communication through hypervisor-based services. Diagnostic configurations are decoupled from static software builds and delivered dynamically as configuration files, supporting real-time adaptability to software updates and Over-The-Air (OTA) changes. This architecture also facilitates seamless interoperability across operating systems and enables service-based diagnostics in line with the industry’s move toward software-defined vehicles. The result is a robust, future-ready diagnostic solution optimized for high software variability, platform heterogeneity, and increasing system complexity in modern automotive ecosystems.
Mukherjee, SoumyadeepRaman, Kothanda
Modern automotive systems are increasingly integrating advanced human-machine interfaces, including TFT displays, to enhance driver experience and functionality. Ensuring the reliability of these systems under diverse operating conditions is critical, especially given their role in vehicle control. This paper presents a Hardware-in-the-Loop (HIL) testing methodology for validation of rotary switch with TFT display. The HIL setup simulates real-world vehicle conditions, including CAN communication, power fluctuations and user interactions, enabling early detection of potential failure modes such as display flickering or communication loss. The results demonstrate improved robustness and reliability of the gear selection switch, supporting its deployment across multiple vehicle platforms.
Bhuyan, AnuragJahagirdar, ShwetaKhandekar, Dhiraj
The proposal of GSR 16(E) in India promotes six airbags in passenger vehicles, aiming to enhance occupant safety. In parallel, the new Bharat New Car Assessment Program (BNCAP) outlines performance protocols that demand robust airbag deployment strategies to achieve a five-star safety rating. One of the critical challenges in meeting both regulatory and consumer safety expectations is the optimal packaging of the airbag Electronic Control Unit (ECU) and its associated impact sensors. These must perform reliably across regulatory tests, BNCAP protocols, and real-world accident scenarios. The location of side acceleration ‘g’ side impact sensors—whether mounted on the side sill, B-pillar, C-pillar, or door structures—is pivotal to achieving consistent and timely side airbag deployment. These sensors must also demonstrate immunity to false triggers or missed events in both static and dynamic misuse and abuse conditions. Ensuring robust sensor performance under these varied conditions is key to the success of the system. This study focuses on evaluating acceleration-based side impact sensors placed at different locations within the vehicle structure, assessing their sensitivity and correlation with airbag deployment performance. Additionally, for compact vehicles where faster deployment of side airbag is essential, the use of pressure-based sensors was investigated. The findings of this study were instrumental in finalizing the optimal packaging strategy for both acceleration and pressure sensors in six-airbag systems.
Kudale, ShaileshRao, Guruprakashwayal, VirendraGoswami, Tarun
As automotive electronic systems become increasingly complex, the demand for robust data security and privacy protection mechanisms has grown significantly. The AUTOSAR (Automotive Open System Architecture) standard has emerged as a widely adopted framework in the automotive industry due to its strong support for interoperability, functional safety, and cybersecurity. Within the AUTOSAR Classic Platform (CP), the Crypto Stack Service as a core component that enables critical security functionalities such as encryption, decryption, digital signature verification, and key management. However, the deployment of the Crypto Stack across heterogeneous Electronic Control Units (ECUs) introduces a series of technical challenges. These challenges stem primarily from variations in hardware resources, differences in operating system implementations, and inconsistencies in software execution environments. As a result, issues such as architectural compatibility, task scheduling efficiency, and secure communication between modules must be addressed for successful integration. This paper presents a systematic adaptation framework for the AUTOSAR Crypto Stack, focusing on three key layers of the software architecture: the Operating System (OS), the Runtime Environment (RTE), and the crypto driver abstraction. The proposed solution includes optimized task scheduling strategies, standardized RTE service encapsulation, and a dynamic dispatch mechanism for coordinating software- and hardware-based crypto processing. To validate the proposed adaptation strategy, a real-world prototype was developed using the NXP S32K148 platform. The system was tested through the generation and verification of MAC, simulating realistic automotive use cases. Experimental results demonstrate that the solution meets the stringent real-time and security requirements of automotive systems, providing valuable insights for the secure deployment of Crypto Stack in modern vehicles.
Wu, ShudiFan, SunjiaYu, YaqiXiu, Jiapeng
This study presents three methods for obtaining the latency of an indirect injection Electro-Injector as a function of the applied voltage. This parameter is relevant for the linearization of the injected mass in order to model fuel mass delivery on modern ECUs. For this purpose, the authors built a test bench, with the intent of running analysis on the results of tests of mass differential between injections, circulating current, and mechanical vibration. The authors gathered data over the iterative experiments and correlated the mass differential, vibration data and current measurements. The authors observed that with a reduction of supply voltage at the injector’s pins, a greater injector dead time made itself present displaying a need for a compensation of opening time in function of voltage since the injector’s needle takes a longer amount of time in partially open positions. Modern ECU manufacturers broadly use the data obtained by this type of iterative experiment to accurately model fuel mass-flow over different boundary conditions not limited only to supply voltage but also differential pressure and fuel temperatures.
Juliatti, Rafael MotterOliveira, Julia Mathias deMorais Hanriot, Sérgio deSilveira, Hairton Júnior Jose daMoreira, Vinicius Guerra
The modern vehicle electrical architecture consists, on average, of 30 integrated electronic modules (ABS, infotainment, instrument panel, etc.), also known as Electronic Control Units (ECUs), and approximately 300 peripherals such as sensors (collision, temperature, oxygen, position, pressure, etc.) and actuators (window motor, mirror motor, relays, airbag inflator, windshield wiper, etc.). This increase in component integration imposes significant challenges to system installation and design. The interconnection of multiple devices renders harness design an arduous and time-consuming task, especially when conducted manually, resulting in error-prone and suboptimal outcomes. Such a scenario highlights the pressing need for studies on harness routing optimization in the automotive industry. Historically, wiring harness design practices have transitioned from manual approaches to the adoption of advanced computational tools. This methodological transition encompasses the use of various techniques, such as algorithms, 3D simulation, and machine learning, aiming for effective solutions to this complex challenge. In this context, the present work aims to conduct a literature review on wiring harness routing optimization strategies, with an emphasis on their application in vehicular electrical architecture. The current academic literature indicates that advancements in optimization approaches are crucial, especially through the application of methods such as Genetic Algorithms, Agent-Based Modeling and Simulation, Integer Linear Programming (ILP) and Linear Programming (LP) applied to the Steiner Tree Problem, Simulated Annealing, Ant Colony Systems, Particle Swarm, among others. Such methodologies are fundamental not only for developing lighter and more compact harnesses but also for a more efficient exploration of available physical space, culminating in layout development time optimization.
Ribeiro, ThiagoReis, BrenoBarreto, ZeusGaleno, AntônioPereira, MarceloFerreira, Fláavio Fabrício V. M.
This paper addresses the challenge of increasing hardware complexity, long development cycles and high costs associated with integrating multiple systems. The research explores the potential of Large Language Models (LLMs) when applied as chatbots to revolutionize the design and development of automotive electrical hardware systems, encompassing areas such as convenience features, safety systems, advanced lighting, vehicle body control and modular electronic control units. A key focus is on how LLMs can automate cost-reduction design tasks, including design optimization, requirements verification and component validation, ultimately driving down expenses without compromising performance or reliability. Furthermore, the research investigates how LLMs can assist in decision-making by providing data-driven insights that inform critical design choices and facilitate enhanced team collaboration, leading to improved productivity through innovative tools and streamlined workflows. In that sense, the project’s scope includes creating a Data Warehouse with relevant design, features offering, testing and quality feedback data to train the LLMs. A research tool based on LLMs will be developed to offer optimization recommendations, such as identifying oversizing, suggesting cost reduction and hardware modularization. The tool will be seamlessly integrated into the cost-reduction engineering teams’ workflow, promoting agility and modernization. The expectation is that this research will drive innovation, enhance competitiveness and promote sustainability within the automotive sector, leading to accelerated time-to-market for new vehicle models, improved engineering efficiency in the development of electrical hardware systems and a strengthened market position for automotive OEMs. Ultimately, the goal is to create more efficient, safer and feature-rich automotive experiences while simultaneously optimizing cost-effectiveness in the design and production of advanced electrical systems.
Ribeiro, Riquelmy Oliveira deSouza Santos, Gabriella deBatista, Victor GnoattoPeres, Renan Luis CassianoSantos, Jean Carlo Villares dosFerreira, Flávio Fabrício V. M.Murari, Thiago B.
Simulation has become mission-critical for ADAS development. Model-based systems engineering can integrate modeling and simulation from the start of the design process. Advanced Driver Assistance Systems (ADAS) are transforming vehicle safety, acting as the bridge between conventional driving and full autonomy. From adaptive cruise control to emergency braking and blind-spot detection, these technologies rely on a dense network of radar sensors, antennas, electronic control units and software. What unites them is the need for precise functionality under complex real-world situations. Achieving full reliability requires more than testing on the road; it demands a virtual approach grounded in simulation. Simulation has become mission-critical for ADAS development. As new vehicles integrate dozens of sensors into tightly constrained spaces, even subtle design decisions can affect system performance. Radar solutions, in particular, present unique challenges, especially as vehicle surfaces grow more complex and the number of onboard systems increases.
Eichler, Jan
This research paper proposes a framework based on lumped parameter thermal networks (LPTN) to understand the system behavior of thermally stressed component spaces in automotive vehicles. LPTNs offer an energy-based, low-degree-of-freedom model that can represent arbitrary thermal systems inside automotive vehicles. The time response of these low-order models can be calculated using standard ordinary differential equation solvers. The paper showcases the modeling of LPTNs and the calculation of their time response by using an electronic control unit (ECU) of a BMW 7 series. The use of LPTNs instead of exponential functions reduced the MAE in this example by 60.5%. Furthermore, a system identification approach for experimental temperature curves has been developed and implemented. System identification aims to mathematically model system behavior and predict system output. This paper compares least-square estimation (LSE) with constrained minimization (CM), where CM has a higher MAE by 5.3% but remains physically feasible. Additionally, this work proposes a physical parameter estimation framework. The parameter estimation problem is formulated as a minimization problem leveraging a state space representation of the LPTN. The estimation of parameters becomes physically interpretable through the introduction of boundary conditions for identifiable parameters. The framework to solve the minimization is based on sequential least-square quadratic programming and is implemented using the SciPy toolbox. The prediction of an unseen cooling use case by an LPTN with physically estimated parameters displays a MAE of 1.95 K. Measures to tackle the ill-posed character of parameter estimation are proposed. Finally, this paper discusses the use of neural networks in this context.
Kehe, MaximilianEnke, WolframRottengruber, Hermann
This information report identifies and evaluates isolation building blocks applicable to TA sandboxing within a HPSE. These building blocks can be used to support SAE J3101 TA requirements for sandboxing of TAs and secure communication between TAs. TAs must execute within their own trust domain to prevent compromise of the HPSE and other TAs. TA trust domain isolation strength may vary depending on the risk profile of the TA deployed, hence the requirement for isolation building blocks to match the risk profile. A multitenancy TA HPSE has a higher risk profile than multiple TAs from the same source (e.g., OEM). TA multitenancy must not compromise the security properties of the HPSE (the secure integration and execution of trusted multi-vendor code). In this report, we provide information on the following: HPSE TA use cases and risk profiles HPSE TA isolation building blocks for manufacturers Threat analysis to determine the effectiveness of isolation security models As the ECU E/E architecture continues to evolve, we must consider the following classification of ECUs and System on Chips (SoCs) for which isolation building blocks apply: Application Processor Core(s) Realtime Processor Core(s) Microcontroller Core(s) An ECU can be composed of a Normal Environment and Protected Environment (HPSE). Normal Environment is typically separated into user and kernel level privileges, with applications executing at the user privilege level. TAs only execute within the HPSE, and the HPSE is typically divided into user and kernel level privileges which are orthogonal to Normal Environment privileges. The TAs will execute at the same user privilege level within the HPSE; therefore, the isolation building blocks must be implemented at a higher privilege level, such as the HPSE kernel, to ensure that the sandboxing policy can be enforced. The TAs access to HPSE resources is restricted at load time by the sandbox policy which operates at a higher privilege level to the TAs. This report also differentiates between isolation methods which are applied within the HPSE and isolation methods applied at the ECU level when there is consolidation of ECUs into domain controller or HPC, i.e., isolation abstraction.
Vehicle Electrical System Security Committee
The rapid evolution of autonomy in Off-Highway Vehicles (OHVs)—spanning agriculture, mining, and construction—demands robust cybersecurity strategies. Sensor-control systems, the cognitive core of autonomous OHVs, operate in harsh, connectivity-limited environments. This paper presents a structured approach to applying threat modeling to these architectures, ensuring secure-by-design systems that uphold safety, resilience, and operational integrity.
Kotal, Amit
The calibration of automotive electronic control units is a critical and resource-intensive task in modern powertrain development. Optimizing parameters such as transmission shift schedules for minimum fuel consumption traditionally requires extensive prototype testing by expert calibrators. This process is costly, time-consuming, and subject to variability in environmental conditions and human judgment. In this paper, an artificial calibrator is introduced – a software agent that autonomously tunes transmission shift maps using reinforcement learning (RL) in a Software-in-the-Loop (SiL) simulation environment. The RL-based calibrator explores shift schedule parameters and learns from fuel consumption feedback, thereby achieving objective and reproducible optimizations within the controlled SiL environment. Applied to a 7-speed dual-clutch transmission (DCT) model of a Mild Hybrid Electric Vehicle (MHEV), the approach yielded significant fuel efficiency improvements. In a case study on a 4.7 km Worldwide harmonized Light-Duty vehicles Test Cycle (WLTC) driving segment, the RL-optimized shift strategy reduced fuel consumption from a baseline of 0.46 L to 0.37 L. Furthermore, when starting from an already optimized shift map representative of a series production vehicle’s calibration, the artificial calibrator further enhanced fuel efficiency, achieving approximately a 0.6 % reduction in fuel consumption for the 4.7 km segment and nearly a 5 % reduction for the full WLTC. The artificial calibrator thus demonstrates a promising methodology to frontload calibration tasks in simulation, thereby offering the potential to reduce reliance on resource-intensive physical testing and to significantly accelerate the development of fuel-efficient powertrain control software.. The direct compatibility of parameter files with real vehicle Electronic Control Unit (ECUs) and the validated SiL behavior suggest high transferability of learned strategies, offering the potential for minimal fine-tuning on physical vehicles post-simulation.
Kengne Dzegou, Thierry JuniorSchober, FlorianRebesberger, RonHenze, Roman
This paper describes the design and characteristics of the knock sensor. The sensor is already used as a commodity product for automotive applications and used by all automotive OEMs for spark ignited combustion engines. With the arrival of the electronic fuel injection on the two wheelers, further optimization of the combustion can be obtained. Although there are many publications on the engine knock strategy, little is known publicly about the sensor itself. The knock sensor is an accelerometer based on a piezoelectric component; it provides an analog signal of the engine vibration. The Electronic Control Unit will filter the signal according to a specific strategy and defines the presence and intensity of the engine knock. The ECU will act accordingly on the ignition timing. The inner structure as well as the mechanical and electrical interface are described in this article.
van Est, JeroenPrieu, Corentin
Items per page:
1 – 50 of 1537