A Generic Method for a Bottom-Up ASIL Decomposition

  • Alessandro FrigerioEmail author
  • Bart Vermeulen
  • Kees Goossens
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 11093)


Automotive Safety Integrity Level (ASIL) decomposition is a technique presented in the ISO 26262: Road Vehicles - Functional Safety standard. Its purpose is to satisfy safety-critical requirements by decomposing them into less critical ones. This procedure requires a system-level validation, and the elements of the architecture to which the decomposed requirements are allocated must be analyzed in terms of Common-Cause Faults (CCF). In this work, we present a generic method for a bottom-up ASIL decomposition, which can be used during the development of a new product. The system architecture is described in a three-layer model, from which fault trees are generated, formed by the application, resource, and physical layers and their mappings. A CCF analysis is performed on the fault trees to verify the absence of possible common faults between the redundant elements and to validate the ASIL decomposition.


ADAS ASIL decomposition Automotive architecture Common-Cause fault analysis Fault trees Functional safety ISO 26262 



The work in this paper is supported by TU/e Impuls program, a strategic cooperation between NXP Semiconductors and Eindhoven University of Technology. The authors thank all reviewers for their helpful comments and suggestions that helped improve and clarify this paper.


  1. 1.
    Boland, J.P., Proschan, F.: The reliability of K out of N systems. Ann. Probab. 11(3), 760–764 (1983)MathSciNetCrossRefGoogle Scholar
  2. 2.
    Brunner, S., Roder, J., Kucera, M., Waas, T.: Automotive E/E-architecture enhancements by usage of ethernet TSN. In: 13th Workshop Intelligent Solutions in Embedded Systems, pp. 9–13, June 2017.
  3. 3.
    Čepin, M.: Reliability block diagram. Assessment of Power System Reliability, pp. 119–123. Springer, London (2011). Scholar
  4. 4.
    D’Ambrosio, J.G., Debouk, R.: ASIL decomposition: the good, the bad, and the ugly. Technical report, SAE Technical Paper (2013)Google Scholar
  5. 5.
  6. 6.
    Ghadhab, M., Junges, S., Katoen, J.-P., Kuntz, M., Volk, M.: Model-based safety analysis for vehicle guidance systems. In: Tonetta, S., Schoitsch, E., Bitsch, F. (eds.) SAFECOMP 2017. LNCS, vol. 10488, pp. 3–19. Springer, Cham (2017). Scholar
  7. 7.
    IEC 61508 Edition 2.0. Principles and Use in the Management of Safety (2010)Google Scholar
  8. 8.
    ISO 26262–2011: Road vehicles - Functional safety - Part 9: ASIL-oriented and Safety-oriented Analyses (2011)Google Scholar
  9. 9.
    Jo, K., Kim, J., Kim, D., Jang, C., Sunwoo, M.: Development of autonomous car - part II: a case study on the implementation of an autonomous driving system based on distributed architecture. IEEE Trans. Ind. Electron. 62(8), 5119–5132 (2015). Scholar
  10. 10.
    Lin, C.W., Rao, L., D’Ambrosio, J., Sangiovanni-Vincentelli, A.: Electrical architecture optimization and selection-cost minimization via wire routing and wire sizing. SAE Int. J. Passeng. Cars-Electron. Electr. Syst. 7(2014–01–0320), 502–509 (2014). Scholar
  11. 11.
    McKelvin Jr, M.L., Eirea, G., Pinello, C., Kanajan, S., Sangiovanni-Vincentelli, A.L.: A formal approach to fault tree synthesis for the analysis of distributed fault tolerant systems. In: Proceedings of the 5th ACM International Conference on Embedded Software, pp. 237–246. EMSOFT 2005, ACM, New York (2005).
  12. 12.
    Papadopoulos, Y., et al.: Automatic allocation of safety integrity levels. In: Proceedings of the 1st Workshop on Critical Automotive Applications: Robustness and Safety, pp. 7–10. ACM (2010)Google Scholar
  13. 13.
    Reinhardt, D., Kucera, M.: Domain controlled architecture - a new approach for large scale software integrated automotive systems. Pervasive Embed. Comput. Commun. Syst. 13, 221–226 (2013)Google Scholar
  14. 14.
    Schtz, B., Voss, S., Zverlov, S.: Automating design-space exploration: optimal deployment of automotive SW-components in an ISO26262 context. In: 2015 52nd ACM/EDAC/IEEE Design Automation Conference (DAC), pp. 1–6 (June 2015).
  15. 15.
    Sommer, S., et al.: RACE: a centralized platform computer based architecture for automotive applications. In: IEEE International Electric Vehicle Conference, pp. 1–6. IEEE (2013)Google Scholar
  16. 16.
    Ulbrich, S., et al.: Towards a functional system architecture for automated vehicles. arXiv preprint arXiv:1703.08557 (2017)
  17. 17.
    Ward, D.D., Crozier, S.E.: The uses and abuses of ASIL decomposition in ISO 26262. In: 7th IET International Conference on System Safety, Incorporating the Cyber Security Conference, pp. 1–6. IET (2012)Google Scholar

Copyright information

© Springer Nature Switzerland AG 2018

Authors and Affiliations

  • Alessandro Frigerio
    • 1
    Email author
  • Bart Vermeulen
    • 2
  • Kees Goossens
    • 1
  1. 1.Eindhoven University of TechnologyEindhovenThe Netherlands
  2. 2.NXP SemiconductorsEindhovenThe Netherlands

Personalised recommendations