Browse Topic: Safety critical systems

Items (336)
Time-Sensitive Networking (TSN) is an emerging technology that has garnered popularity among the US DoD and others for its deterministic properties while using flexible, ubiquitous Ethernet as its core. However, individual TSN devices will support the TSN features of only some of the vast array of amendments and extensions that make up the full IEEE 802 TSN standards. This functional and modular approach offers great flexibility, but it also increases the complexity of network planning, analysis, verification, etc. as well as potentially leading to unexpected emergent behavior that must be addressed before a TSN network can be truly said to be qualified for use with safety-critical systems. Using industry experience gained certifying other deterministic networks to DO-254 and DO-178C Design Assurance Level A (DAL-A) and applying it to the analysis, testing, and validation of a deterministic TSN Ethernet digital backbone offers a roadmap for overcoming these challenges. Such an approach must seek to satisfy the three basic building-blocks of 1) Device-Level Standards Conformance, 2) System-Level Performance and Interoperability, and 3) Network Composability and Determinism.
Finnegan, DanielZischka, WolframSoares, Alvaro
To this point in aviation history, a typical aircraft type certification program has focused on the constituent systems that make up the aircraft, decomposing them further and further down until reaching their elemental parts and how they interact. This approach has traditionally treated the actual communication technology as only an interface, with technology and implementation based on a decision between multiple stakeholders via an ICD and high-level requirements. This has been necessary to ensure the accurate and on-time delivery of safety-critical data between nodes. When using legacy point-to-point or bus-based data communication technologies like ARINC 429 or MIL-STD-1553, this approach has worked well enough as these technologies are relatively straightforward and proven technologies. However, as onboard bandwidth needs for safety-critical data increase, these legacy technologies are increasingly no longer capable of meeting the needs of system integrators. Ubiquitous, high-bandwidth Ethernet is the obvious solution to these needs and, indeed, it has been used for quite some time in onboard networking applications for low Development Assurance Level (DAL)/non-safety critical data. However, as Ethernet moves into high-DAL applications, the certification of the Ethernet network itself becomes a major complexity that must be addressed directly.
Mustillo, MichaelFinnegan, DanielZischka, Wolfram
Modern aircraft have an established need for a high-performance, open standards solution to interconnect increasing number of digital components including sensors, actuators, controllers, processors, displays and data concentrators. The aircraft can be envisioned as a distributed system requiring highly available, reliable, and deterministic communication network - often termed as digital backbone - for safe operation. This paper introduces a new zonal architecture for aerospace onboard networks using Time-Sensitive Networking (TSN). TSN is an open standard based deterministic Ethernet solution for mission and safety critical networks in aerospace industry that truly meets the Modular Open Standards Approach (MOSA) requirements. This paper also presents a reference implementation of the proposed digital backbone architecture using commercial-off-the-shelf hardware from multiple vendors. Experimental data from laboratory evaluation shows stability, performance, and reliability that meets or exceeds the needs of aerospace use cases. The proposed next generation digital backbone provides significant size, weight, and power savings as well as enables hardware and software modularity using open standards. A specific use case of such a digital backbone is the US Army's Future Vertical Lift (FVL) program, but the proposed architecture is generally applicable to all aircraft networks.
Jabbar, AbdulJanakaraj, Prabhu
The paper deals with the status of development and qualification/certification of electromechanical actuation for Helicopters and VTOL applications with the focus on aspects relevant to the Fault-Tolerance. In particular a linear Electromechanical Actuator (EMA) architecture is presented, derived from a fault tolerant ballscrew-based differential (speed-summing arrangement) actuation system patented by UMBRAGROUP S.p.A. The focus is on safety-critical and high reliability/availability requirements for electromechanical actuation certification. The main characteristic is the use of two independent mechanical actuation channels in the same envelope driven by independent Motor Control Electronics (MCEs). At the state of the art, the presented fault-tolerant architecture is under development in flight-critical swashplate application for eVTOL platform and under feasibility study in flight-critical swashplate application for CS27 platform.
Biagetti, FrancescoPelliccia, StefanoMalleret, FredericBorgarelli, Nicola
Recent field experience has indicated significant problems with some types of wire and cables as routed on aircraft landing gear. This SAE Aerospace Information Report (AIR) is intended to identify environmental concerns the designer should consider, materials that appear to be most suitable for use in these areas, routing, clamping, and other protection techniques that are appropriate in these applications. In recent years aircraft certification regulatory agencies introduced new regulations regarding Electrical Wiring Interconnection Systems (EWIS) to further enhance safety of the associated systems and aircraft overall.
A-5B Gears, Struts and Couplings Committee NEW Name Goes Her
This SAE Aerospace Standard (AS) defines the items that shall be considered when creating a fiber optic cable assembly specification and source control drawing intended for installation on aerospace platforms.
AS-3 Fiber Optics and Applied Photonics Committee
This document is not a standard, it is a candidate for a standard being submitted to SAE for their consideration as a comment to SAE J2735. The term SAE J2735 SE candidate is used within this document to refer to this submission. This document specifies dialogs, messages, and the data frames and data elements that make up the messages specifically for use by applications intended to utilize the 5.9 GHz Dedicated Short Range Communications for Wireless Access in Vehicular Environments (DSRC/WAVE, referenced in this document simply as “DSRC"), communications systems. Although the scope of this Standard is focused on DSRC, these dialogs, messages, data frames and data elements have been designed, to the extent possible, to be of use for applications that may be deployed in conjunction with other wireless communications technologies. This standard therefore specifies the definitive message structure and provides sufficient background information to allow readers to properly interpret the message definitions from the point of view of an application developer implementing the messages according to the DSRC Standards.
V2X Communications Steering Committee
The security of connected health technology is often assumed to exist when it does not, or considered to be prohibitively expensive or complex, or, worst of all, relegated to an afterthought. This is dangerous thinking, especially as the industry increasingly moves to a smartphone-based command-and-control model for these safety-critical applications.
On Perception Safety Requirements and Multi Sensor Systems for Automated Driving Systems2020-01-01014/14/2020
One major challenge in designing SAE level 3-5 Automated Driving Systems (ADS) is to define requirements for the perception system that would enable argumentation for safe operation. The safety requirements on the perception system can only be fulfilled through redundancy in the sensor hardware. It is, however, a challenge to specify the redundancy that is required in the sensor system. Safe operation for an ADS is significantly more difficult compared to advanced driver assistance systems (ADAS). The safety argumentation for ADAS typically argues that in case of a failure in the sensor array a fail-silent behavior is acceptable because the human driver can take control of the vehicle back. This argumentation however is not possible when developing level 4 or higher automation. This paper investigates prerequisites for applying a systematic methodology for analyzing redundancy in a multi-sensor system and the relation to a conceptual ADS functional architecture. This analysis must address the complexity that comes with partially overlapping sensor data from different sensors and considers variations in performance and characteristics due to changes in the environmental conditions. The paper introduces the term incomplete redundancy and presents a systematic methodology for analyzing redundancy. The aim is to provide arguments for how several sensors in a system, when appropriately combined, meet an assigned safety requirement on a higher level. Each sensor will then be assigned a certain responsibility and contributes with a sub-set of information. A set of questions of importance to address as a foundation for such a methodology are defined and discussed. The definitions of redundancy and independence between sensors are discussed as well as contract-based functional safety to adapt to different environmental and operating conditions.
Cassel, AndersBergenhem, CarlChristensen, Ole MartinHeyn, Hans-MartinLeadersson-Olsson, SusannaMajdandzic, MarioSun, PengThorsén, AndersTrygvesson, Jörgen
Runtime Active Safety Risk-Assessment of Highly Autonomous Vehicles for Safe Nominal Behavior2020-01-01074/14/2020
Fatal crashes involving automated driving systems, has been raising the concern of minimum standard requirement for safety, reliability and performance required for Autonomous Driving System (ADS)/Advanced Driver Assistance System (ADAS) before this cutting-edge technology takes on public roads. Hence, in order to ensure necessary safety requirements of ADS/ADAS systems we propose a runtime active safety assurance module known as SConSert. SConSert performs dynamic risk assessment of “Sensing, Planning and Action module of ADS/ADAS”; to provide minimal risk maneuver in any given driving scenario. The dynamic risk assessment of ADS/ADAS system is based on the operational design domain (ODD) knowledge of the driving scenario plus the sensor capability, ADS/ADAS algorithm requirement and capability, and finally smooth and collision free maneuver requirement. So, the main concept behind SConSert is runtime derivation of situational and conditional set of contracts for a given driving scenario and ADS/ADAS system ODD; fulfillment or violation of which can help in runtime dynamic risk assessment of ADS/ADAS to plan minimal safe behavior such that necessary safety requirements can be achieved. Finally, through experiment we show that proposed runtime active assurance safety module can handle complex driving scenario, and present simulation and experimental results that emphasizes the importance of the proposed runtime safety assurance module and shows that the proposed system is capable of performing runtime dynamic risk assessment in order to keep the automated driving systems always within the safe sate that is the automated driving system always perform within its ODD.
Rathour, Swarn SinghIshigooka, TasukuOtsuka, SatoshiMARTIN, RAUL
Replacement of a 50cc Two-stroke Engine with an Electric Powertrain2019-32-06231/24/2020
As global regulations look to create a dramatic reduction in CO2 emission and other forms of pollution, companies with products that rely on engine technology must be ready to take on the electrification challenge. Applications that remain using two-stroke engine technology continue to exist due to their very high power density requirements. However, their history of higher pollution compared to four-stroke engines makes them a target to be regulated out of existence. Such high power two-stroke applications include high performance off-road motorcycles. In this type of product, electrification can solve not only pollution challenges but market challenges, such as ridership and public perception. By addressing the core problems presented by the two-stroke engine and turning challenges into opportunity, a strong attraction is created to convert a two-stroke engine motorcycle to an electric vehicle. With Automotive electric vehicle technology paving the way, the basis for cost effective electric motorcycle powertrain is explored for a 50cc off-road motorcycle application. The 50cc engine and motorcycle represent a special product where size, performance, and cost have a high sensitivity. The 50cc product also represents an area of great opportunity for the product as it is connected to the youth riding segment that establishes the future of motorcycle riding. With both strong opportunity and strong challenges, the electrification solution for a 50cc application provides broad justification for mass market adoption across the motorcycle industry. Challenges will be presented towards a OEM level product where design change is to be minimized without compromising performance. Various challenges include system design, packaging, supply chain, product lifecycle, competition readiness, safety, and cost. Opportunities will be discussed in the context of how the electrified powertrain can create a better product for the rider and solve challenges to enable the next generation of motorcycling. These opportunities include manufacturing advantages, environmental harmony, and new features.
Beeker, Jesse
As the complexities of avionic systems increase, our system-level verification methods have remained stagnant. New requirements are added with each iteration of design, impacting the level of testing needed for full test coverage, while hardware or software updates require verification testing that transcends its predecessors. At Triumph Integrated Systems, (Triumph), DO-178 B/C level A formal qualification testing requires several engineer reviewers to verify a system works as intended. Generally, it takes a week or less to execute a test and gather data, but several weeks to evaluate said test. There is opportunity for improvement in this system. This paper describes how Triumph Engine Control Systems' Automated Criteria Evaluation (ACE) takes the test case review process time and reduces it effectively. ACE is intended to replace one human reviewer using MathWorks® based programing, which breaks down natural criteria language for interpretation and evaluation. ACE aims to increase efficiency, assure precision, improve repeatability, and has the potential to lower development costs. This paper highlights how ACE will drastically cut criteria evaluation time while increasing productivity and accuracy of test review results without impacting the integrity or safety of the tested Level A software.
Singh, RamandeepGiobbi, Analise
Model-Based Software Development: Functional Safety Compliance via Built-In Tool Intelligence2019-01-10414/2/2019
Today’s automobiles are among the most sophisticated machines on the planet. Much of the functionality of modern automobiles emanates from embedded software features that control electronic, mechanical or pneumatic devices. Over the past few decades the number of software features and the associated code has grown exponentially and the respective embedded software systems have reached a level of complexity which is increasingly difficult to manage. As a consequence, recalls due to software defects have become a major concern and today constitute about 50% of the overall warranty cost [1]. Since the operation of automobiles has severe public safety implications, the development of embedded automotive software has become subject to stringent functional safety standards (ISO 26262) and compliance with these standards has become a major hurdle in the development of automotive software. This paper outlines a tool-based solution that satisfies an important subset of functional safety standards via built-in intelligence. The solution marks a major step towards an agile, safety compliant development process that does not impose restrictions regarding product innovation. The core concept of this tool-based solution is centralized architecture and data management. By way of this concept, the tool-based solution detects and prevents interface and data inconsistencies not only during the software development process but throughout the lifecycle of the software product.
Turin, Raymond C.
Simulation Based Hybrid Electric Vehicle Components Sizing and Fuel Economy Prediction by Using Design of Experiments and Stochastic Process Model2019-01-03574/2/2019
The aim of this study is to evaluate the Fuel Economy (FE) over the driving cycle for a 48 Volt P2 technology vehicle with different component ratings (battery and electric machine) in the hybrid powertrain, using simulation and Design of Experiments (DoE) tools. The P2 architecture was selected for this study based on an initial assessment of a wide number of possibilities, using the Ricardo “Architecture Independent Modelling (AIM)” toolset. This allows rapid evaluation of different powertrain options independently of a defined hybrid control strategy. For the vehicle with P2 architecture, a DoE test matrix of battery capacity and electric machine power rating was created. The test matrix was then imported into the simulation environment to perform the driving cycle FE simulations. Then, a 48 V P2 Hybrid Electric Vehicle (HEV) FE emulator model was created and interrogated using model visualisation and optimisation methods. For the HEV without an on-board charger (i.e. no Plug-in capability), legislation strictly requires the HEV to complete the driving cycle with a balanced battery State-Of-Charge (SOC) when doing the FE test. Therefore, the paper also compares two methods, optimisation and DoE, for calibrating the HEV control strategy to achieve charge neutrality, and discusses the pros and cons of these methods.
Bao, RanBaxter, JamesRevereault, Pascal
A Stochastic Physical Simulation Framework to Quantify the Effect of Rainfall on Automotive Lidar2019-01-01344/2/2019
The performance of environment perceiving sensors such as e.g. lidar, radar, camera and ultrasonic sensors is safety critical for automated driving vehicles. Therefore, one has to assess the sensors’ performance to assure the automated driving system’s safety. The performance of these sensors is however to some degree sensitive towards adverse weather conditions. A challenge is to quantify the effect of adverse weather conditions on the sensor’s performance early in the development of an automated driving system. This challenge is addressed in this work for lidar sensors. The lidar equation was previously employed in this context to derive estimates of a lidar’s maximum range in different weather conditions. In this work, we present a stochastic simulation framework based on a probabilistic extension of the lidar equation, to quantify the effect of adverse rainfall conditions on a lidar’s raw detection performance. To this end, we combine basic probabilistic models for key rainfall parameters with Mie theory and the theory of signal detection in a Monte Carlo simulation framework. This allows to analyze and optimize a sensor’s design early in the sensor development, when physical testing is not yet possible. A challenge not addressed in this work is to include the effect of road spray water on the lidar’s performance. Combining the effect of other noise sources with the presented framework in a ray tracer is an opportunity for realistic physical lidar simulations and would allow to virtually estimate the performance of a lidar’s object detection and tracking performance. Such simulations could contribute to verify the safety of automated driving functionalities.
Berk, MarioDura, MichaelVargas Rivero, JoseSchubert, OlafKroll, Hans-MartinBuschardt, BorisStraub, Daniel
Reliability Case Analysis of an Autonomous Air Cooling System (AACS) for Aerospace Applications2018-01-191610/30/2018
Current More Electric Aircraft (MEA) utilize Liquid Cooling Systems (LCS) for cooling on-board power electronics. In such LCS, coolant pipes around the structure of the aircraft are used to supply water glycol based coolant to sink heat from power electronics and other heat loads in the electronic bay. The extracted heat is then transferred to ram air through downstream heat exchangers. This paper presents a reliability examination of a proposed alternative Autonomous Air Cooling System (AACS) for a twin engine civil MEA case study. The proposed AACS utilizes cabin air as the coolant which is in turn supplied using the electric Environmental Control System (ECS) within the MEA. The AACS consists of electrical blowers allocated to each heat load which subsequently drive the outflow cabin air through the heat sinks of the power electronics for heat extraction. No additional heat exchanger is required after this stage in which the heated air is directly expelled overboard. One key advantage is the avoidance of liquid coolant leakage with the removal of liquid coolant from the MEA. It is necessary that the expected reliability of the AACS is in line with the equivalent LCS and is compliant with Federal Aviation Administration/previous Joint Aviation Authorities (FAA/JAA) reliability limits. Accordingly, this paper evaluates the reliability of the proposed AACS as well as the subsequent operation of safety critical components of the ECS and Electrical Power System (EPS) that the AACS is cooling. The analysis results show that the proposed AACS can provide comparable reliability to an LCS and is expected to be compliant with FAA/JAA reliability limits.
Fong, Chung ManNorman, PatrickSeki, Naoki
AS-3 Fiber Optics and Applied Photonics Committee
ABSTRACT It is impossible to open a newspaper, turn on a television, or visit a news website these days without being barraged with cybersecurity related news. Every domain is being attacked, penetrated, and impacted by cyber-crime and the range, complexity, and frequency of attacks is expanding daily. Across the board we face a wide range of adversaries from disgruntled employees to nation states that are bent on taking our critical systems down temporarily or permanently. Avionics systems are not immune from this and over the past several years, cybersecurity policies and the Risk Management Framework (DoD 8510.01) approach to securing US cyber systems, have been maturing and rapidly growing in adoption. However, many in the avionics community remain uninformed regarding the impacts of these new policies and initiatives to their systems nor how best to ensure they are taking a practical and efficient approach to implementing them. Gone are the days of a magic box that all of the security requirements are allocated to. Modern Cybersecurity is a systems discipline and cuts across the entire avionics suite. This paper will introduce the Risk Management Framework (RMF) and Cybersecurity and discuss what they are, how we got here, how they are related, and how they are impacting and will impact legacy and future avionics systems on tactical military aircraft. The paper will present some observations and best practices associated with application of Cybersecurity and RMF to avionics. It will also include some benefits of safety critical designs toward cyber-hardening and where safety and security are mutually exclusive. It will touch briefly on some impacts to avionics systems related to hot Cybersecurity topics such as HBSS (Host Based Security System), STIGs (Security Technical Implementation Guides), Static code analysis, DoD PKI (Department of Defense Public Key Infrastructure), electronic delivery, and insider threats. The paper will include a perspective on the development environment, the deployed systems, and deployment sites and how RMF and Cybersecurity impact both the contractor and the DoD customer related to these perspectives.
Marek, James
ABSTRACT Power Architecture® processors have dominated aviation safety-critical processing since the late 1990s, when major processing vendors exited the MIL-qualified and/or aviation-certified markets. Since that time, four trends have emerged: 1. Military and commercial safety certification has become more rigorous 2. Server/desktop architectures have focused on performance at the expense of determinism 3. System-on-Chip (SoC) architectures are offered, with multiple processing cores (multicore) in a single package to increase performance over single-core processors 4. The industrial automation industry is increasing safety requirements for autonomous manufacturing, and the automotive industry is offering driver assistance, including autonomous operation, creating a large market for relatively low-power, high-integrity processing Although the Power Architecture will remain a viable aviation processor technology for some time, new-to-our-industry processing products and architectures are poised to enter (or re-enter) the aviation market. Automotive and aviation markets require similar capabilities that make the avionics market attractive to processing vendors currently supplying the automotive market: • Longer product availability lifetimes (5-15 years) than consumer/server-grade processors • Low power draw • Extended temperature operation • High safety integrity This paper introduces the microprocessor industry support and certification issues. High-level activities to bring safetycritical products to civil and military aviation using Multi-Core Processors (MCPs) are also discussed, based on current Rockwell Collins MCP civil aviation development, with all cores operational, supporting Design Assurance Level (DAL) A. A high-level comparison between automotive and civil /military aviation safety requirements will be discussed. The leading alternative processing architectures are introduced with their history and their vendor’s interest and activities in support of the aviation market. Next steps are described in the areas of MCP certification, alignment of automotive/avionics safety requirements, and potential vendor activities. Finally, our conclusions are summarized.
Gerhold, ScottDunham, MikeSletteland, Branden
Development of the Hybrid Supervisory Controller for a Pre-Transmission Hybrid Electric Vehicle for Year 3 of the EcoCAR3 Competition2018-01-10124/3/2018
This paper details the Wayne State University development of the Hybrid Supervisory Controller strategies for the Year 3 of the EcoCAR 3 competition. Included in this paper are the processes for developing the strategies for the supervisory control system, which includes the torque distribution among the powertrain components, and the diagnostic strategies adopted to guarantee the safety critical functionalities of the vehicle. The EcoCAR 3 competition challenges sixteen North American universities to re-engineer the 2016 Chevrolet Camaro to reduce its environmental impact without compromising its performance and consumer acceptability. During the Year 3 of the competition the team has refined the control strategies designed in the previous years, to enable the powertrain full functionalities and achieve better energy consumption over pre-determined drive cycles. The paper introduces the algorithms developed for the hybrid supervisory controller for the torque distribution among the main powertrain components, the management of the HV battery state of charge and the diagnostic features that guarantee safe vehicle operations. The algorithms are developed using MathWorks MATLAB 2015. The results obtained from the simulation over standardized drive cycles are also presented and discussed.
Di Russo, MiriamZhu, GuilinBalakrishnan, SajjanKu, Jerry
Electromagnetic Compatibility and Interference - Design Methodology, Challenges and Guidelines for Avionics Product and Systems2017-01-21189/19/2017
Avionics industry is moving towards more electric & lightweight aircrafts. Electromagnetic effects becomes significantly challenging as materials starts moving towards composite type. Traditional methods for controlling EMC will not be sufficient. This shift increases the complexity of in-flight hardware elements for EMI/EMC control. This paper discusses the need for EMI/EMC Control and brings out the analysis & applicability of various EMI/EMC standards in aerospace, commercial and industrial electronic products, provides comparative study with respect to levels. The study include various sections of DO-160 and applicable guidelines for controlling EMI/EMC with respect to LRU (Line Replaceable Unit) & wire/cable harnesses. Also presents guidelines with respect to shielding of components, selection of components, grounding schemes, filter topologies and layout considerations. It provides comparative study made for different filters, good layout examples, generic simulation examples and lessons learnt from the failures. An attempt is made to propose the design methodology to be adapted for successful design for Electromagnetic effects. This paper puts forth the various challenges like size constraints, isolation requirements, component shielding, cost of EMI filters, weight, layout of- high speed & mixed signal boards and interference due to new wireless devices getting added on aircraft. The paper makes an effort to provide the possible mitigation methods for the same. Implementation methods like H-Field dominance, smaller loop area, EMI gaskets, shielding of cables and magnetic field control have been discussed. Various pain points with respect to qualification and reusability approach have been discussed. Probable solutions to overcome those have been outlined in this paper.
Vadgaonkar, Prashant Sbanik, Diptar
Considerations for Safe Store Operation on Manned and Unmanned VehiclesAIR6027A (Current)6/27/2017
The information presented in this AIR is intended to provide designers of armed unmanned systems with guidelines that may be applied to ensure safe integration and operation of weapons on unmanned platforms. The guidelines have been developed from experiences gained in the design and operation of weapons on manned aircraft that have been accepted by relevant safety authorities in the USA and Europe and proven effective over many years. Whilst the guidelines have been developed from experience with aircraft operations, the concepts are considered equally applicable to non-aircraft systems, such as those used on the surface or undersea environments. This document does not attempt to define or describe a comprehensive safety program for unmanned systems. System Safety is a system characteristic and a non-functional requirement. It has to be addressed at each level of system design, system integration and during each phase of system operation. System safety is achieved when the system operation does not cause inadvertent personnel injuries, destruction of the system or damage to the environment. Section 3 of the document contains an introduction to methods by which the safety of a system can be assessed. Section 4 describes the safety principles commonly applied to the design and operation of weapons on manned aircraft. Section 5 describes how the safety principles established for manned aircraft may be applied to unmanned systems, Section 6 provides conclusions and recommendations.
AS-1B Aircraft Store Integration Committee
ABSTRACT Loss of the primary lubrication in a helicopter gearbox can result in a very rapid or even immediate failure of the system due to the much-reduced heat removal and the degrading tribological performance of the highly loaded gear contacts. While a limited understanding of this topic may be an acceptable risk for ground vehicles, however, a properly functioning gearbox is flight safety critical for helicopters. Therefore a deeper understanding of the degradation mechanisms is essential to accurately assess the time duration in which the helicopter gearbox can function under oil-out conditions and evaluate designs targeting the desired extension. Current methods for predicting the gearbox life and performance under the loss-of-lubrication situation are indeed largely experimental and experience-based and they provide only limited insights into the underlying physics of the evolving tribology of gears and bearings. One of the major technical barriers that currently limit the physics-based predictive capability is a lack of reliable, quantitative modeling of lubricant retention on the gear tooth surface after the loss of lubrication. This paper first describes the film thickness measurement with the white light interferometry for the lubricant remaining on a glass disc after a certain number of revolutions at a given speed. This is followed by a description of a 3D numerical ANSYS CFX® model which mimics the experimental set-up. The controlling model parameters are the centrifugal and viscous forces, surface tension, temperature, and lubricant-disc contact angle. The predicted effects of rotation speed and temperature are validated by the experimental results. Finally, the modeling methodology is used to simulate the lubricant retention on a gear tooth surface over the range of temperature and speed of a typical helicopter gearbox.
Acharya, RanadipMaglieri, JohnZhang, HuanChaudhry, ZaffirThompson, Bruce
Foreseeable Misuse in Automated Driving Vehicles - The Human Factor in Fatal Accidents of Complex Automation2017-01-00593/28/2017
Today, highly automated driving is paving the road for full autonomy. Highly automated vehicles can monitor the environment and make decisions more accurately and faster than humans to create safer driving conditions while ultimately achieving full automation to relieve the driver completely from participating in driving. As much as this transition from advanced driving assistance systems to fully automated driving will create frontiers for re-designing the in-vehicle experience for customers, it will continue to pose significant challenges for the industry as it did in the past and does so today. As we transfer more responsibility, functionality and control from human to machine, technologies become more complex, less transparent and making constant safe-guarding a challenge. With automation, potential misuse and insufficient system safety design are important factors that can cause fatal accidents, such as in TESLA autopilot incident. This paper investigates the human factor in fatal accidents from foreseeable misuse and insufficient system safety design perspectives. Fatal incidents, caused by different generations of autonomous systems are analyzed. Liability and product compliance topics of safety critical systems, procedures and controlled environment, are investigated for US regulations. Competency of automotive industry standards are evaluated within today’s automation needs, and compared against proven-in-use standards from other industries, especially from aviation. As a result, this paper unveils industry challenges in complex automated systems, caused by human factor, foreseeable misuse and insufficient system safety design to prevent fatal incidents.
Serter, BarbarosBeul, ChristianLang, ManuelaSchmidt, Wiebke
Identifying Security Vulnerabilities Early in the ECU Software Development Lifecycle2017-01-16573/28/2017
In the past few years, automotive electronic control units (ECUs) have been the focus of many studies regarding the ability to affect the deterministic operation of safety critical cyber-physical systems. Researchers have been able to successfully demonstrate flaws in security design that have considerable, dramatic impacts on the functional safety of a target vehicle. With the rapid increase in data connectivity within a modern automobile, the attack surface has been greatly broadened to allow adversaries remote access to vehicle control system software and networks. This has serious implications, as a vast number of vulnerability disclosures released by security researchers point directly to common programming bugs and software quality issues as the root cause of successful exploits which can compromise the vehicle as a whole. In this paper, we aim to bring to light the most prominent categories of bugs found during the software development life cycle of an automotive ECU. We employ the method of static code analysis using reference coding standards such as MISRA and CERT C secure coding guidelines, to identify categories of software bugs which are most likely to remain in the vehicle, undetected as zero-day security vulnerabilities. We further examine the security issues originating from each category and provide an insight into the systematic elimination of crucial security-related bugs, much earlier in the software development life cycle. In the long term, we expect such an approach to drastically reduce the amount of attack vectors available for exploit in the ECU's software and limit the scope of damage possible by a malicious adversary.
Edwards, JesseKashani, Ameer
Hardware/Software Co-Design of an Automotive Embedded Firewall2017-01-16593/28/2017
The automotive industry experiences a major change as vehicles are gradually becoming a part of the Internet. Security concepts based on the closed-world assumption cannot be deployed anymore due to a constantly changing adversary model. Automotive Ethernet as future in-vehicle network and a new E/E Architecture have different security requirements than Ethernet known from traditional IT and legacy systems. In order to achieve a high level of security, a new multi-layer approach in the vehicle which responds to special automotive requirements has to be introduced. One essential layer of this holistic security concept is to restrict non-authorized access by the deployment of embedded firewalls. This paper addresses the introduction of automotive firewalls into the next-generation domain architecture with a focus on partitioning of its features in hardware and software. Based on the deployment of the firewall in the in-vehicle network, the corresponding adversary model and automotive requirements such as latency, jitter, CPU load and memory consumption are going to be discussed. Drivers behind these metrics are primarily safety concerns and cost and thus are relevant for both OEMs and hardware manufacturers. As a result, a reasonable implementation of an automotive firewall system has to be a trade-off between hardware and software in order to meet the above-named automotive requirements. We implemented the firewall on an Infineon AURIX TriCore and Altera Cyclone V FPGA to analyze these metrics. The paper shows the options and decision points to find an optimal partitioning between hardware and software for an automotive embedded firewall system.
Pesé, Mert D.Schmidt, KarstenZweck, Harald
Items per page:
1 – 50 of 336