Engineering and Hardening of Functional Fail-Operational Architectures for Highly Automated Driving

Adler, Rasmus; Akram, Mohammed Naveed; Feth, Patrik; Fukuda, Takeshi; Ishigooka, Tasuku; Otsuka, Satoshi; Schneider, Daniel; Yoshimura, Kentaro · 2019 · Crossref

DOI: 10.1109/issrew.2019.00038

archive: archived pipeline: cataloged verified

Get this paper ↗ (DOI — opens at the source; we link to it, we don't host it)

Summary

This paper addresses the engineering challenge of designing fail-operational architectures for highly automated driving, which must maintain safe operation despite sensor or component failures, unlike traditional fail-safe systems. The authors argue that the complexity of these architectures, particularly regarding adaptation behaviors and the definition of the Operational Design Domain (ODD), requires systematic modeling to ensure resilience. The work presents a tailored methodology applied in a highway pilot case study involving Fraunhofer IESE and Hitachi, aiming to facilitate early design-stage decisions and optimize the trade-off between operational capability and system cost. The methodology extends actor-oriented modeling by introducing a type system that defines semantic types, quality properties, and algorithm types for each function. Algorithms are modeled with pre- and post-conditions based on input quality and assumptions, allowing the system to switch between calculation variants (e.g., GPS-based vs. wheel-speed-based ego speed) at runtime. The authors enhanced this approach to explicitly model the ODD by linking real-world attributes (e.g., "tunnel," "rain") to technical constraints (e.g., "No GPS"). They also incorporated a deployment view and failure model to simulate how internal component failures trigger adaptation. This allows the system to determine active algorithms and resulting operating modes (full, degraded, or non-operational) for any given combination of real-world conditions and failures. The study implemented two primary analyses: reachability and quantitative reachability. Reachability analysis iterated over all possible ODD combinations to identify unreachable algorithms and verify that safety-critical shutdowns do not occur unexpectedly. In the case study, this revealed millions of potential system configurations, highlighting the necessity of systematic modeling. Quantitative analysis assigned probabilities to real-world attributes to estimate the likelihood of entering degraded or non-operational modes. This enabled engineers to make evidence-based decisions, such as avoiding the development of rarely used algorithms or identifying insufficient resilience in specific scenarios. The authors note that while stochastic dependencies between attributes were simplified in the case study, the approach provides a framework for rigorous risk assessment. The significance of this work lies in providing a structured method for hardening fail-operational architectures early in the development process. By making adaptation behaviors and ODD constraints explicit, the methodology fosters a common understanding among safety and function engineers, reducing the risk of late-stage rework. The authors conclude that this approach is essential for managing the complexity of automated driving systems, ensuring that the defined fail-operational behavior is appropriate for the intended ODD. The successful application in the highway pilot demonstrates the method's viability for industry adoption, particularly as standards like ISO 21448 mandate rigorous ODD specification.

Provenance

The full processing record for this entry. Every stage of this paper's journey through the pipeline is logged — what ran, with which tool and model, how many attempts it took, and when it last completed.

StageOutcomeToolModelPromptAttemptsCompleted
discover success Crossref 1 2026-08-09
archive success semantic_scholar 6 2026-08-09
extract success pdftotext 4 2026-08-10
clean success clean 2 2026-08-10
chunk success chunk 2 2026-08-10
embed success embed Qwen/Qwen3-Embedding-8B 2 2026-08-10
promote success 1 2026-08-09
summarize success llm qwen3.6-27b-nvidia summ-v5 2 2026-08-10
tag success vector_similarity 17 2026-08-11
verify success 2 2026-08-10

Summary generated by qwen3.6-27b-nvidia on 2026-08-10; verification: verified.

Topics

Ranked by relevance to this paper. Hover a topic for its definition.

Information type

What kind of knowledge this paper contributes, grouped by family — independent of topic (what it is about) and method (how it was studied).