Startseite Themen Brennpunkt INNOVATIONSPREIS-IT IT-Bestenliste INDUSTRIEPREIS INDUSTRIE-Bestenliste TrafficGenerator
INNOVATIONSPREIS-IT 2017

Drucken
Mittelstandspresse

01.09.2026

Functional Safety for Drive-by-Wire: How a Comprehensive Safety Case Demonstrates Safety from Requirements Through to Operation

NX NextMotion integrates safety objectives, system architecture, analyses, and tests into a comprehensive Drive-by-Wire Safety Case. With Safety-by-Wire®, verification begins before production code—and extends beyond the start of production.

From Requirement to Safety Case: Requirements-in-the-Loop, FMEDA and FTA are applied early in the development process. Safety Engineering, fault injection and validation systematically build the chain of evidence through to the Safety Case.
From Requirement to Safety Case: Requirements-in-the-Loop, FMEDA and FTA are applied early in the development process. Safety Engineering, fault injection and validation systematically build the chain of evidence through to the Safety Case.

Pfronstetten-Aichelau, 01.09.2026 (PresseBox) - A safety-critical drive-by-wire system may be technically sound in its design. For OEMs, Tier 1 suppliers, and system integrators, however, that alone is not enough. Functional safety must be verifiably demonstrated—both to auditors and regulatory agencies as well as within the organization’s own development team: Why was a safety objective defined? What requirements were derived from it? How does the system architecture implement these requirements? And what analyses and tests demonstrate that the intended safety mechanisms are actually effective?

The safety case links precisely these levels into a consistent chain of reasoning and evidence. The path from each safety goal—through requirements and architecture—to the test result must be traceable—and vice versa.

For NX NextMotion, a drive-by-wire-based control layer for autonomous and teleoperated vehicles, this traceability is an essential component of system development. After all, when steering, braking, and propulsion are controlled entirely electronically, it is not only the safety architecture that must be robust—the evidence of its effectiveness must be as well.

The Safety Case Is Not Just a Pile of Paper

A safety case is not created simply by compiling as many supporting documents as possible at the end of the project. Traceability is crucial. For every safety objective, it must be possible to trace the path from requirements and architecture through to analyses and test results—and from every test result back to the safety requirement it verifies. With Safety-by-Wire(®),this chain of evidence therefore begins in the early development phases and accompanies NX NextMotion throughout its entire lifecycle.

Requirements-in-the-Loop: Verify Before Implementation

One of the most costly sources of errors in system development does not necessarily lie in the code. Even incomplete, contradictory, or unfulfillable requirements can carry over into the architecture, implementation, and testing phases. Arnold NextG therefore starts right at the requirements stage.

With Requirements-in-the-Loop, requirements and scenarios are verified through simulation in the early system phases—before the first line of production code is written. The goal is to identify contradictions, gaps, or unfulfillable combinations while they can still be corrected at the requirements level. This approach is integrated into requirements gathering and analysis—specifically, in the Automotive SPICE framework at SYS.1 and SYS.2. As a result, safety verification does not begin only on the verification side of the development model, but already during the specification phase.

FMEDA and FTA: Quantitatively Evaluating Architecture

Quantitative safety analyses are conducted in parallel with the development of the system architecture.

FMEDA—Failure Modes, Effects, and Diagnostics Analysis—examines possible failure modes of hardware components, their effects, and the effectiveness of diagnostics. It thus provides a basis for assessing whether dangerous single-event failures are detected and latent faults are sufficiently controlled.

Fault Tree Analysis (FTA) takes the opposite perspective. Starting from an undesirable top-level event—such as the loss of steering function—it examines which individual events or combinations of events could lead to it.

For a multi-redundant, fully fail-operational drive-by-wire architecture, this interplay is particularly crucial. It is not enough for redundancy to simply be plausible; the safety case must provide verifiable evidence that the architecture meets the underlying safety objectives.

From Simulation to the Real Vehicle

As the system matures, the validation process gradually shifts from the virtual to the real world. Software-in-the-Loop (SiL) tests functional logic in a simulated environment. Hardware-in-the-Loop (HiL) integrates real control hardware and enables targeted fault injections under reproducible conditions. Finally, Vehicle-in-the-Loop (ViL) connects the real vehicle to a simulated environment.

This chain is particularly essential for safety-critical drive-by-wire functions. Errors in communication, power supply, or control—as well as defined multiple faults and transitions between operating states—can be specifically investigated without first having to generate such situations during road or machine operation. Real-world vehicle operation remains indispensable, however, as it supplements the simulation with conditions and interactions that cannot be fully anticipated.

Validation Does Not End with SOP

A safety case is not complete once production begins. Software updates alter systems over their lifetime. Field data provides new insights into real-world operating conditions. Monitoring can reveal deviations that did not occur during development.

For a platform like NX NextMotion, the verification structure must therefore be updatable. Findings from operation must be fed back into the safety case, and changes must be evaluated in a controlled manner. Safety-by-Wire® thus views the safety case as a living verification structure spanning the entire lifecycle—from initial requirements through development and validation to operation and updates.

Independent Review as Part of the Process

Another factor is the timing of the independent assessment. If an assessment takes place only at the end of a project, weaknesses can indeed be identified—but correcting them often involves considerable effort. With Safety-by-Wire®, therefore, the independent assessment accompanies the verification process throughout the development phases. The goal is to critically review architectural and verification decisions at a stage when they can still be efficiently adjusted.

This provides a pre-developed basis for verification in customer projects. It does not replace the safety case for the entire vehicle or the manufacturer’s responsibility for type approval and application—but it does create a foundation upon which project-specific safety arguments can be built.

What OEMs and Integrators Should Consider

When evaluating a safety-critical drive-by-wire platform, therefore, simply asking whether it meets ASIL D or features a fail-operational architecture is not sufficient. It is equally important to determine when the verification process begins, whether safety objectives are consistently traceable all the way to test results, and what quantitative analyses underpin the architecture. It should also be clarified which fault scenarios were actually injected into SiL, HiL, or ViL, how independent the assessment is, and how the safety case is updated after production begins.

After all, the quality of a safety architecture is demonstrated not only by what it can do technically, but also by how robustly this capability can be verified.

Conclusion: Safety is a verifiable property

The Safety Case completes the Safety-by-Wire® functional safety chain. The standards define the framework. The hazard analysis leads to safety objectives. The principle of the most stringent requirement consolidates these objectives across different vehicle domains. The Fully Fail-Operational architecture implements these objectives technically. And the Safety Case links requirements, architecture, analyses, and tests into a traceable chain of evidence.

For NX NextMotion, this chain begins before the first line of production code is written and extends beyond the start of production into ongoing operations. After all, safe control over steering, braking, and propulsion must not only be technically guaranteed—it must also remain verifiable.

WE CONTROL WHAT MOVES

Ansprechpartner

Anke Leuschke
Zuständigkeitsbereich: Pressesprecherin

Über Arnold NextG GmbH:

Arnold NextG realizes the safety-by-wire® technology of tomorrow: The multi-redundant central control unit NX NextMotion enables a fail-operational and individual implementation, independent of the vehicle platform and unique worldwide. The system can be used to safely implement autonomous vehicle concepts in accordance with the latest hardware, software and safety standards, as well as remote control, teleoperation or platooning solutions. As an independent pre-developer, incubator and system supplier, Arnold NextG takes care of planning and implementation - from vision to road approval. With the road approval of NX NextMotion, we are setting the global drive-by-wire standard. www.arnoldnextg.com

Datei-Anlagen:


(381 kB)
1625545.attachment

From Requirement to Safety Case: Requirements-in-the-Loop, FMEDA and FTA are applied early in the development process. Safety Engineering, fault injection and validation systematically build the chain of evidence through to the Safety Case.