Browse Topic: Safety regulations and standards
ISO 26262ISO/SAE 21434ISTQB/ASPICEMOSAGCIAVICTORY
Modern mission-critical ground vehicle systems must adapt to rapidly evolving threats, deploying changes in months or days while maintaining reliable and safe operation. Historic manual development and testing methods cannot keep pace without compromising safety assurances. Continuous Integration and Continuous Deployment (CI/CD) pipelines offer proven approaches to accelerating development, but implementing them for mission-critical systems requires careful attention to verification rigor. This paper presents a practical framework for implementing CI/CD pipelines across any level of rigor, from rapid prototyping to DO-178C and ISO 26262 certified systems. Drawing on experience from aviation, medical device, and ground vehicle development, the framework provides guidance for each pipeline stage based on the system’s desired level of rigor. This framework includes an examination of the value of Software-in-the-Loop vs Hardware-in-the-Loop testing to optimize development timelines while maintaining software quality.
The Electro-Mechanical Brake (EMB) system is an essential technology for safe braking in modern vehicles. However, the adoption of multi-controller architectures has introduced new challenges to conventional Safe State strategies. Traditionally, the Safe State defined in functional safety means "function shutdown," and in accordance with ISO 26262-1:2018 (Part 1: Vocabulary), aims for an "operational mode without risks exceeding reasonable levels." However, in the multi-controller architecture of EMB systems, the Fail-Operational Safe State concept is applied, where the system continues to provide limited functions even in the event of faults. It is essential to verify whether such operational modes actually satisfy the safety requirements of ISO 26262-3 and ISO 26262-4. This paper redefines the Safe State according to failure modes in EMB systems, analyzes system state transitions, and presents a coherence analysis methodology for validating the availability of resources required to provide limited functions in the Fail-Operational Safe State. Through this approach, potential design defects in multi-controller-based EMB systems can be detected early, validated across 1,149,952 fault scenarios with zero total-failure outcomes, and traceability of functional safety requirements can be established.
The Electro-Mechanical Brake (EMB) system is a dry-type Brake-by-Wire technology that eliminates hydraulic components and directly controls friction braking using electrical actuators at each wheel. The EMB architecture consists of a Main Center Control Unit, a redundant Backup Center Control Unit, and four Wheel Control Units communicating via CAN FD. Due to its direct involvement in vehicle braking, compliance with ISO 26262 functional safety requirements is critical. As system complexity increases, potential risks such as hardware failures and communication faults must be systematically addressed. The proposed TSC was developed according to ISO 26262, covering the concept phase (Part 3), system-level development (Part 4), and software implementation (Part 6). Safety goals and Functional Safety Requirements derived from HARA are used to guide system architecture design and TSC development. Key design principles include modularity, redundancy, fault detection, and fail-safe operation. Verification is conducted at both system and vehicle levels using ECU-in-the-Loop Simulation (EILS), Hardware-in-the-Loop Simulation (HILS), and real-vehicle tests. Fault scenarios, including Main Center Control Unit failures and CAN communication losses, are injected using a custom LabVIEW-based fault injection tool. The study evaluates Fault Tolerant Time Interval (FTTI) settings, error handling mechanisms, and control handover strategies under fault conditions. The results show that redundancy and localized communication enable stable operation and smooth control transfer within the FTTI window without noticeable impact on braking performance or driver awareness. This study demonstrates the robustness of the proposed EMB architecture. Future work will focus on prognostics and maintenance strategies to support safe deployment in autonomous and electric vehicles. [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]
Since 2019, sex equity in traffic crashes has been a highly debated topic in vehicle safety, especially following the 2019 study by Forman et al. (1) claiming that female occupants face a 73 percent greater risk of serious injury in frontal crashes compared to male occupants. This was soon followed by a Consumer Reports Article by Keith Barry (2), which attempted to identify underlying factors contributing to the higher risk. These have been embraced by several parties since 2019. Firstly, it was alleged that vehicle design practice over the last four decades considered safety for the male population only and ignored that of the female as evidenced by the exclusive use of the mid-sized male Anthropomorphic Test Devices (ATDs) in Regulatory and Safety Ratings tests and not with an average sized female ATD. The absence of such an ATD for testing of vehicles “set the course for four decades’ worth of car safety design, with deadly consequences” (2). Secondly, although there is a recognition of the fact that Regulatory testing with a Small Female ATD, the Hybrid III-05F, was introduced in the FMVSS208 in 2003, this ATD was only a scaled version of the average male ATD of the 1970’s implying that this ATD is incapable of driving the design of restraint systems for females due to “They’re put together differently. Their material properties—their structure—is different” (2). Thirdly, according to a quote “These same trends have been observed in many, many studies in the past.” We assume that the trends refer to the apparent disparity in safety of females when compared to those of males. This document aims to outline historical activities, associated research and the development of countermeasures addressing crashworthiness concerns related to vehicle safety for females, as well as factors affecting both males and females, such as age-related impacts. This paper deals mainly with the frontal crash modes, mentions side impacts briefly as it affected designs of inflatable restraints for side impact to protect the smaller portion of the population from inflation induced injuries but the history behind the use of female ATDs by IIHS and NHTSA in full scale testing is not covered. Where ever possible, the time periods of reported activities related to female safety have been divided to pre-1997 corresponding to a change in US frontal crash regulation to address serious-to-fatal injuries to females and children, between 1997 to 2003 corresponding to the proposal by Canada for its frontal impact standard, and between 2003 and 2006 when the Advanced Restraint Regulation in the US FMVSS 208 was promulgated. This was followed by activities between 2007 and 2019, and post 2019 period.
Letter from the Guest Editor
Letter from the Editor-in-Chief
A demonstration ride shows the glare-free, game-changing power of adaptive driving beams, already available in Europe. An approval test from NHTSA is proving difficult for OEMs to pass. I'm riding in the second row of a Lincoln Navigator fitted with Forvia Hella's adaptive driving beam (ADB) headlight system. The low- and high-beams are on, blasting everything in front of us for between 350 and 500 feet (122 and 152 m) with a bright, daylight-temperature LED light. Even traffic and street signs at the edges of the road, which normally aren't as well illuminated, are bathed in brightness. A car pulls out in front of us, and the system instantly adjusts, creating a tunnel of unlit space on and just next to the vehicle ahead. So even though we still have high beams on the rest of the road, that driver isn't facing the harsh glare that is the No. 1 complaint about today's high-intensity headlight systems.
Some Automated / Autonomous Vehicles (AVs) have unique seating configurations (stagecoach and campfire seating) which present expanded occupant safety challenges. Significant portions of the National Highway Traffic Safety Administration (NHTSA) Federal Motor Vehicle Safety Standards (FMVSS) do not yet align with AVs containing unique seating. This paper series takes the NHTSA occupant safety standard approach for conventional forward-facing seat vehicles where many compliance evaluations are in the frequently occupied front row and expands it to stagecoach and campfire AVs where the rear seating row is anticipated to be frequently occupied. The approaches proposed are from a logic-based safety-focused analysis and in many cases previously published material. The goal of this paper series is to offer regulatory proposals that enable equivalent performance for these AVs to existing forward-facing seating vehicle occupant safety standards and meet Executive Order 13045 on child safety. Part 1 (this paper) focuses on occupant protection for the front and rear seating rows in stagecoach and campfire seating AVs for: front impacts (FMVSS-208), windshield mounting (FMVSS-212), windshield glazing (FMVSS-219), rear impacts (FMVSS-301/305), head restraints (FMVSS-202a), head impacts (FMVSS-201), side impacts (FMVSS-214), roof crush (FMVSS-216a), ejection mitigation (FMVSS-226), and door pinch (a potential FMVSS-118 addition). Some of the proposals address occupant performance for vehicles without traditional leg and restraint reaction surfaces. In addition, an interior safety sensing approach that assesses if occupants are properly restrained before a ride can begin is proposed as an alternative / a replacement for unbelted in-position occupant performance compliance evaluations. This document also provides regulatory condition thoughts for AVs without a usable driver seat location. Part 2 (SAE paper 2026-01-0576) discusses interior safety sensing and associated messaging. These approaches can be used in industry-wide regulatory next step contemplation and deliberation for unique interior seating arrangement AVs, including public discussions, safety research, approach proposal development, and rulemaking efforts.
This paper contains Part 2 of a two-part paper series proposing potential regulatory approaches for occupant safety in Automated / Autonomous Vehicles (AVs) with unique seating configurations (stagecoach and campfire seating). Part 2 focuses on interior safety sensing, associated messaging, and ride control approaches both prior to and during a ride. Assessments are also proposed after significant vehicle braking and crash events. The proposed conditions are to be assessed in a static vehicle environment with humans segmented by occupant size and an infant dummy. On the vehicle seat and on the vehicle floor occupant detection conditions are proposed along with restraint usage detection conditions for vehicle seat belt usage, Child Restraint Seat (CRS) usage, CRS seat belt usage, and Lower Anchors and Tethers for Children (LATCH) system usage. These conditions may be detected by sensors / computer algorithms and human monitoring and thus are technology agnostic. The topics of animal detection and cargo detection are also discussed. Part 1 of this paper series (SAE paper 2026-01-0578) proposed using interior safety sensing as an alternative / a replacement for the National Highway Traffic Safety Administration (NHTSA) Federal Motor Vehicle Safety Standard 208 (FMVSS-208) Occupant Crash Protection unbelted in-position occupant compliance conditions. This paper proposes conditions involving occupant and seat belt restraint usage detection. This evaluation approach strives to prevent unbelted occupants and is an improvement over restraint countermeasures for unbelted occupants. This paper also discusses and proposes visual and audible safety messaging for prior to the ride occupant education and for occupant and restraint usage detection outcomes. Vehicle level ride control actions are suggested such as preventing a ride when improperly restrained occupants are detected. These approaches can be used in industry-wide regulatory next step contemplation for unique interior seating arrangement AVs. When adopted, these approaches would likely reside in an expanded version of FMVSS-208.
The rapid advancement of advanced driver assistance systems (ADAS), automated driving and electrification has significantly increased the software content and complexity within modern vehicles. Consequently, ensuring both high process quality and compliance or qualification with functional safety standards becomes critically important. Automotive Software Process Improvement and Capability Determination (ASPICE 4.0) focus on Process quality and Capability Maturity, while ISO 26262:2018 emphasizes engineering guidelines for functional safety and risk mitigation. The efficient integration of the process and standard remains a key challenge due to differences in their objectives, terminologies, and assessment criteria. The misalignment between ASPICE 4.0 and ISO 26262:2018 standard often results in duplicated efforts, rework of work products, and delays in product release schedules. This paper proposes a unified framework to bridge ASPICE 4.0 process areas with ISO 26262:2018 safety standard recommendations and activities. The framework introduces a refined V-model that integrates safety lifecycle activities directly into ASPICE 4.0 process workflows, enabling a harmonized and systematic approach to software development and safety compliance. While maintaining a focus on system engineering (SYS) and software engineering (SWE) process areas, this paper also discusses how the hardware engineering (HWE) process and support process (SUP) areas in ASPICE 4.0 can be mapped to the ISO 26262:2018 standard. In addition, the proposed framework addresses the concept phase of the safety lifecycle, encompassing item definition, HARA, safety goals and functional safety concept (FSC). This technique facilitates higher process efficiency, reduces redundant activities, and enhances product quality while maintaining compliance with both standards. The harmonized approach presented in this paper provides a holistic solution to current industry challenges by enabling incorporation of safety practices within automotive software development process. This ensures that vehicle systems meet quality and safety expectations, supporting timely product delivery in an increasingly competitive and regulated automotive market.
The automotive industry is evolving from a reactive, independently self-determined approach to cybersecurity, complicated by a complex supply chain. Over time, this has resulted in a fragmented industry comprised of any number of proprietary solutions verses a standardized, regulated paradigm to facilitate a platform-oriented approach. This document, an update on collaborative work from the SAE Vehicle Electrical Hardware Security Task Force (TEVEES18B) and GlobalPlatform Automotive Task Force, outlines this transition strategy. An extensible number of additional examples of use cases of Global Platform Technologies are explored in this document.
A Detroit-based startup says its device can analyze brain activity to help figure out whether a driver is impaired. The impaired driver-detection business has been heating up since even before NHTSA announced in 2024 that it was working what would eventually be a mandate that vehicles be able to detect impaired drivers and mitigate the danger they represent to the motoring public.
Military and aerospace applications have become increasingly complex real-time systems. Multi-core SoCs improve performance but create new challenges in maintaining and verifying deterministic behavior. Connected systems require exceptional security to protect code from external cyberattacks. Evolving functional safety and reliability standards that keep raising the bar mean developers need to begin comprehensive testing sooner if they are going to meet tighter design schedules. Finally, certifying these complex systems has become even more difficult. To help OEMs meet these challenges, the RISC-V architecture has been designed with unique capabilities that support reliability and security in the development of safety-critical applications. With its open instruction set architecture, modularity, and extensibility, RISC-V accelerates the design of functionally safe systems while reducing the complexity, cost, and risk associated with certification to standards like DO-178C and ISO 26262.
A crash energy absorption technique and method improve the safety and structural integrity of electric vehicle battery packs during collisions, complying with global regulations. This analysis details an assembly featuring a battery housing for mounting battery cells, a crash member connected to the battery housing's periphery, and flexural members linked to the crash member. The flexural members are designed to absorb impact forces by deforming and storing potential energy during sudden impacts. This approach ensures energy is stored within the flexural elements and then transferred to the battery cells through progressive crushing. The design effectively delays intrusion, enhances battery safety, and minimizes cell-level damage. This solution improves occupant safety and prevents thermal runaway incidents while maintaining the battery's overall performance and reliability in EVs.
Items per page:
50
1 – 50 of 927