This book provides full scope of automotive ECU development activities including cybersecurity and safety plus SOTIF.
Every computing system has two, and only two attributes: Data Value and Data timing, which represent fully the system functionalities from the system external behavior point of view.
The data driven system engineering is the approach to develop the system by focusing on the two attributes mentioned above, in which, the data values are derived by the system operation concept design, and the data timing is derived by the system latency design. Based on which, this book provides a full range of system and software engineering development activities:
Requirement Elicitation
Requirement Engineering
System and Software Architecture Design
System Operation Concept Design
System and Software Structure Design
Electronic Architect Design
Functionality Allocation
Failure Mode and Effect Analysis (FMEA)
Safety including SOTIF
Cybersecurity (full compliant with UN ECE 155/156)
System and software Verification
System and Software Integration and Verification
System and Software Black Box Verification
each of which has its own clearly defined scope and approach, which is different from the conventional development, in some cases even different from some ISO standards, for example:
Safety Development: the safety requirements for every part in a vehicle are cascaded from the vehicle safety requirements, which is different from the Concept Phase in the Part 3 of ISO 26262, and the functional safety development will be fully covered by (1) Reliability (2) Availability (3) Quality.
Error Detection and Protection: there are only two types of errors to be detected in a computing system: Data Value error and Data Timing error, to detect which, there are only two aspects to be considered: (1) input data (2) middle data and output data in addition to the platform error detection. The approaches of detection and protection include (1) data transfer protocol check, (2) data range and reasonable value check, (3) execution time check and control.
FMEA: this book provides the optimized approach by following the data relationships between the input data, middle data and output data, which will be both inductive and deductive, and re-use the system operation concept that is built at the system development first phase, to make the development efficient.
Cybersecurity: this book provides the full solution to cover the UN ECE 155 by implementing three aspects: (1) Trusted contents in the ECU (2) Authenticated access to the ECU (3) Authenticated communication with the ECU.
Requirement Engineering: This book makes the goal and scope of requirement engineering in the computing system development specific, accurate and measurable by defining the scope as: the requirement engineering is to use the computer executable information to describe the system under development which consists only two types of information: Signal and Test Case, and defining the requirement quality measurement as: (1) Signals, either input or output signals, shall be computer readable. (2) Test cases shall be executable in the system.
System Architecture Design: The goal of system architecture design is to provide the platform that transfers and transforms the input signal to become the required output signal via some middle data. This book introduces the following system functional modulizations based on the AUTOSAR that satisfies a generic automotive ECU structure: (1) Feature Function (2) Diagnostic Service (3) Cybersecurity Function (4) Serial Signal Manager (5) Application Mode Manager (6) AUTOSAR, and based on the characteristics of those functions, the book provides the approach to design the electronic architecture and allocate the functions to the architecture.