2026-09-21 · Équipe éditoriale KeXinMaterials
ISO 26262 ASIL Automobile + ADAS / EV Sécurité Fonctionnelle Mallette de Protection B2B Guide
ISO 26262:2018 Edition 2 "Véhicules routiers - Sécurité fonctionnelle" est la norme mondiale de sécurité fonctionnelle automobile. Requis pour ADAS, EV, freinage, direction, airbag.
ISO 26262 Scope + ASIL Determination
ISO 26262:2018 Edition 2. 12 parts. ASIL A-D determined by Severity x Exposure x Controllability.
ISO 26262:2018: "Road vehicles - Functional safety". Edition 2 (2018). Replaces Edition 1 (2011). Currently active Edition 2.
12 parts: Part 1 (Vocabulary), Part 2 (Management of functional safety), Part 3 (Concept phase), Part 4 (Product development at system level), Part 5 (Product development at hardware level), Part 6 (Product development at software level), Part 7 (Production, operation, service, decommissioning), Part 8 (Supporting processes), Part 9 (ASIL-oriented and safety-oriented analyses), Part 10 (Guidelines on ISO 26262), Part 11 (Guidelines on application of ISO 26262 to semiconductors), Part 12 (Adaptation of ISO 26262 for motorcycles).
Scope: Road vehicles - passenger cars, light commercial, heavy trucks, buses, motorcycles, trailers. Excludes special-purpose vehicles, agricultural, rail.
Application: Safety-related E/E systems. Including sensors (radar, lidar, camera, ultrasonic), ECUs (powertrain, chassis, ADAS, body, infotainment), actuators (brakes, throttle, steering), wiring harnesses.
ASIL determination per ISO 26262-3:2018: Severity (S0-S3) x Exposure (E0-E4) x Controllability (C0-C3). Tables per ISO 26262-3 Table 4-6.
Severity: S0 (no injuries), S1 (light to moderate injuries), S2 (severe to life-threatening injuries, survival probable), S3 (life-threatening to fatal injuries, survival uncertain).
Exposure: E0 (incredibly rare), E1 (very low probability), E2 (low probability), E3 (medium probability), E4 (high probability - occurs during every driving cycle).
Controllability: C0 (controllable in general), C1 (simply controllable - 99% of drivers can avoid), C2 (normally controllable - 90% of drivers can avoid), C3 (difficult to control or uncontrollable - less than 90% of drivers can avoid).
ASIL QM (Quality Management): Non-safety functions. ISO 26262 § 4. QM does not require additional safety processes beyond QM. Used for functions where S+E+C does not result in ASIL A-D.
ASIL A: Lowest ASIL. Typical: S1 + E1 + C1. Requires basic safety processes. Failure rate < 100 FIT.
ASIL B: Low-medium. S2 + E2 + C2. Requires structured safety processes. Failure rate < 100 FIT.
ASIL C: Medium-high. S3 + E3 + C2. Requires semi-formal methods. Failure rate < 100 FIT.
ASIL D: Highest. S3 + E4 + C3. Requires formal methods. Failure rate < 10 FIT.
HARA + Item Definition + Functional Safety Concept
Item definition + HARA + functional safety concept per ISO 26262-3 + -4.
Item definition per ISO 26262-3 § 5: Define system under scope (item / system). Function + boundary + interfaces + operating modes + environmental conditions + actuators + sensors.
Example item: Adaptive cruise control (ACC). Function - maintain safe distance. Boundary - radar + ECU + throttle + brake. Operating modes - following / stopping / accelerating / emergency brake.
Hazard analysis + risk assessment (HARA) per ISO 26262-3 § 6: Identify hazards + hazardous events. Determine ASIL per hazardous event. Derive safety goals.
Hazard identification methods: FMEA (AIAG-VDA 2019), brainstorming, expert interviews, similar item analysis, field data analysis.
Hazard example: ACC does not detect stationary vehicle. Hazardous event: ACC failure causes collision. Severity S3, Exposure E4, Controllability C3. ASIL D.
Safety goal: Avoid collision with stationary vehicle. Allocated ASIL D. Traced through safety lifecycle.
Functional safety concept per ISO 26262-4 § 6: Derive functional safety requirements (FSR) from safety goals. Allocate FSR to system architecture (system / hardware / software).
FSR example: ACC shall detect stationary vehicle at > 100m distance. FSR allocated to system + radar + ECU + brake actuator.
Technical safety concept per ISO 26262-4 § 7: Hardware + software requirements from FSR. Define technical safety requirements (TSR) + system architecture + interfaces.
TSR example: Radar shall detect stationary vehicle with > 99% probability at > 100m. Brake shall apply < 1.5s after detection. ECU shall coordinate within < 100ms.
ASIL decomposition per ISO 26262-9 § 5: Decompose ASIL D into 2 x ASIL B (C) requirements. Reduces redundancy burden. Rules: (1) Must be sufficient independence. (2) Same ASIL or lower at receiving element. (3) CCF score >= 65 per Annex F.
Common decomposition patterns: ASIL D = ASIL B (C) + ASIL B (C). ASIL C = ASIL B + QM. ASIL B = ASIL A + QM.
Hardware Metrics (SPFM / LFM / PMHF)
Hardware metrics per ISO 26262-5. Single Point Fault Metric + Latent Fault Metric + Probabilistic Metric for random Hardware Failures.
Hardware metrics per ISO 26262-5:2018 Table 4-6. Single Point Fault Metric (SPFM) + Latent Fault Metric (LFM) + Probabilistic Metric for random Hardware Failures (PMHF).
SPFM (Single Point Fault Metric): Coverage of single point faults + residual faults by safety mechanisms. SPFM = 1 - (lambda SPF + lambda RF) / lambda.
SPFM target per ASIL: ASIL A 90%, ASIL B 90%, ASIL C 97%, ASIL D 99%.
LFM (Latent Fault Metric): Coverage of latent faults by safety mechanisms. Latent fault = fault not detected by driver + not detected by safety mechanism. LFM = 1 - lambda MPF / (lambda MPF + lambda S + lambda RF).
LFM target per ASIL: ASIL A 60%, ASIL B 60%, ASIL C 80%, ASIL D 90%.
PMHF (Probabilistic Metric for random Hardware Failures): Probability of violation of safety goal per hour. PMHF < threshold.
PMHF target per ASIL: ASIL A < 100 FIT, ASIL B < 100 FIT, ASIL C < 100 FIT, ASIL D < 10 FIT. (1 FIT = 10^-9 /h).
Diagnostic coverage per ASIL: Per ISO 26262-5 Table D.2-D.5. Categories low / medium / high coverage per safety mechanism.
Fault models: Single point fault (SPF) + Residual fault (RF) + Multiple point fault (MPF) + Latent fault. Per ISO 26262-5 § 7.4.
Hardware architecture: Per ISO 26262-5 § 7.5. Channel-based. 1oo1, 1oo2, 2oo2, 2oo3, 2oo4 voting patterns.
Hardware FMEA + FMEDA: Failure Modes Effects and Diagnostic Analysis per IEC 60812 + ISO 26262-5 § 7.5.5. Failure rate + failure mode + diagnostic coverage + SPFM/LFM/PMHF.
Semiconductor per ISO 26262-11:2018. Special considerations for integrated circuits. Dependent failure analysis + temperature derating + semiconductor aging.
B2B recommendation: For automotive cases containing ECUs / ADAS / EV powertrain, require ISO 26262:2018 hardware metrics + SPFM >= 99% (ASIL D) + LFM >= 90% (ASIL D) + PMHF < 10 FIT (ASIL D) + hardware FMEA + FMEDA.
Software Metrics (MC/DC) + AUTOSAR
Software metrics per ISO 26262-6. MC/DC for ASIL D. AUTOSAR + safety mechanisms + C coding standards.
Software metrics per ISO 26262-6:2018 Table 5-8. Software architectural metrics + software unit metrics + software integration metrics + software testing metrics.
Structural coverage: Per ISO 26262-6 § 9. Statement coverage (C0) + Branch coverage (C1) + MC/DC (Modified Condition / Decision Coverage).
Structural coverage per ASIL: ASIL A = Statement coverage. ASIL B = Branch coverage. ASIL C = Branch + 100% condition + 100% decision. ASIL D = MC/DC (Modified Condition / Decision Coverage).
MC/DC: Modified Condition / Decision Coverage. Each condition in a decision must be shown to independently affect the decision result. Required for ASIL D software.
Software architectural metrics: Per ISO 26262-6 § 5. Coupling + cohesion + interface complexity + modularity.
C coding standards: MISRA C:2012 (mandatory for automotive). MISRA C++:2008 (for C++). MISRA C:2023 (latest revision).
MISRA C:2012 Rule categories: Mandatory + Required + Advisory. 143 rules + 16 directives. Cover C language pitfalls.
MISRA C compliance: Deviations must be documented. 100% compliance not required (some rules have known deviations). Document per ISO 26262-6.
AUTOSAR (Automotive Open System Architecture): Per AUTOSAR Release 4.x + R21-11. Classic Platform + Adaptive Platform. ISO 26262-compatible software architecture.
AUTOSAR safety mechanisms: Memory partitioning + end-to-end protection (E2E) + watchdog + over/under voltage detection + over temperature detection + ECC memory + lockstep CPU.
End-to-end protection (E2E): AUTOSAR E2E profiles 1, 2, 4, 5, 6, 7, 8, 11. CRC + counter + alive counter + SID. Required for safety-critical signal transmission.
B2B recommendation: For automotive software case, require MISRA C:2012 100% rule compliance + documented deviations + MC/DC for ASIL D + AUTOSAR E2E + safety mechanisms + software unit + integration + testing metrics.
SOTIF (ISO 21448) + Autonomous + Safety Case
SOTIF ISO 21448 for autonomous / AI driving. Safety case documentation. UN R157 + R155 + R156 + R131 + R155 cybersecurity.
SOTIF (Safety of the Intended Functionality): Per ISO 21448:2022. Complements ISO 26262 for autonomous + AI systems. Addresses performance limitation + triggering condition + insufficient situational awareness.
SOTIF scope: Perception (sensor limitations), decision (AI / ML), actuation (vehicle dynamics). Includes edge cases + corner cases + rare scenarios.
SOTIF vs ISO 26262: ISO 26262 covers systematic + random hardware failures. SOTIF covers intended functionality limitations (e.g., sensor does not see white truck on white background).
SOTIF process: (1) SOTIF analysis. (2) Identification of triggering conditions. (3) Risk evaluation per scenario. (4) SOTIF measures. (5) Validation by argument + test. (6) Release for series production.
SOTIF triggering conditions: Sensor limitations (range, weather, occlusion), AI limitations (edge cases, adversarial), actuator limitations (latency, drift).
UN R157 (Automated Lane Keeping System ALKS): UN regulation. Level 3 automation on highways. SAE J3016 Level 3.
UN R155 (Cyber Security Management System CSMS): UN regulation. Cybersecurity for automotive. Effective July 2022 (new types) / July 2024 (all registrations).
UN R156 (Software Update Management System SUMS): UN regulation. OTA software update management. Effective July 2022.
UN R131 (Advanced Emergency Braking System AEBS): UN regulation. Forward-facing camera + radar. Effective 2024 for trucks + buses.
Safety case per ISO 26262-2 § 7: Structured argument + evidence. Top-level claim - sub-claims - evidence. Goal: provide convincing argument that item is safe for release.
Safety case contents: Item definition + HARA + safety goals + functional safety concept + technical safety concept + hardware + software + production + service + field monitoring.
B2B recommendation: For autonomous / AI / EV / ADAS cases, require ISO 26262:2018 ASIL C/D + ISO 21448:2022 SOTIF + UN R157 + R155 + R156 + R131 compliance + safety case documentation + field monitoring.
Points clés
- ISO 26262:2018 Edition 2 is global automotive functional safety. 12 parts. ASIL A-D + QM. Required for ADAS / EV / autonomous / braking / steering / airbag / powertrain.
- ASIL determination: Severity (S0-S3) x Exposure (E0-E4) x Controllability (C0-C3). ASIL D highest. Replaces IEC 61508 in automotive sector.
- ASIL decomposition per ISO 26262-9: ASIL D = 2 x ASIL B (C). Reduces redundancy burden. Rules: independence + receiving ASIL + CCF score >= 65.
- Hardware metrics: SPFM >= 99% (ASIL D) + LFM >= 90% (ASIL D) + PMHF < 10 FIT (ASIL D). Software metrics: MC/DC for ASIL D + MISRA C:2012 + AUTOSAR E2E.
- SOTIF (ISO 21448:2022) complements ISO 26262 for autonomous + AI. Addresses performance limitation + triggering condition. UN R157 / R155 / R156 / R131 regulations.
- B2B recommendation: For automotive case, require ISO 26262 ASIL C/D + SOTIF ISO 21448 + UN R155 CSMS + UN R156 SUMS + safety case + field monitoring + hardware FMEA + software MC/DC.
FAQ
q
a
q
a
q
a
q
a
q
a
q
a