Executive Summary
As vehicles evolve from mechanically-defined systems into continuously updated software platforms, functional safety must evolve with them. Software updates delivered after Start of Production can alter safety-relevant behaviour, introduce new hazards, and expand the attack surface – repeatedly across a vehicle’s entire operational life. The white paper, “Functional Safety in Software-Defined Vehicles: An Integrated Engineering Assurance Model,” presents a rigorous, vendor-neutral framework for engineering and sustaining functional safety across the full SDV lifecycle.
This technical guide explains how four foundational standards, ISO 26262, ISO 21448 SOTIF, ISO/SAE 21434, and ISO 24089 must be integrated into a single assurance model rather than treated as parallel workstreams. It demonstrates how each standard addresses a distinct threat taxonomy, how their claims interact, and how a unified Claims-Arguments-Evidence structure keeps all four aligned across every software release.
The white paper covers the architectural pillars that define the SDV safety challenge: compute consolidation and platform-level failure modes; Freedom from Interference across mixed-criticality partitions; OTA update safety and mixed-version hazard management; virtual validation defensibility; and safe AI/ML integration. A fully worked example built around the Central Compute Health Monitor and Degraded Mode Manager brings the framework to life, covering safety goals, FTTI allocation, a four-mode degraded state machine, and a complete V&V evidence package, evaluated against three enforcement path architectures with clear selection guidance.
Whether you are a system architect, safety manager, cybersecurity lead, or V&V specialist, this white paper delivers the engineering depth needed to build a defensible, release-ready functional safety case in the continuous-delivery era.
Key areas
- The four-standard integrated assurance model and how ISO 26262, SOTIF, ISO/SAE 21434, and ISO 24089 interact at the claim level
- SDV architectural pillars and their characteristic safety failure modes
- Freedom from Interference: evidence dimensions across CPU, memory, DMA, I/O, and communication
- The three-layer watchdog chain: partition-local, SoC system-level, and safety island
- The CCHM and DMM worked on an example that included a state machine, fault classification, and FTTI budgets.
- Three enforcement path architectures: Safety Island, Zonal Fallback, and Dual, with selection criteria
- OTA release governance: four-gate checklist, release safety dossier, and staged rollout
- Safety-informed CI/CD: automated evidence generation and release gate integration