<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<title>Automotive - Safety &amp; Security</title>
<link href="http://dl.gi.de/handle/20.500.12116/21097" rel="alternate"/>
<subtitle/>
<id>http://dl.gi.de/handle/20.500.12116/21097</id>
<updated>2026-07-21T13:36:55Z</updated>
<dc:date>2026-07-21T13:36:55Z</dc:date>
<entry>
<title>Why current memory management units are not suited for automotive ECUs</title>
<link href="http://dl.gi.de/handle/20.500.12116/17568" rel="alternate"/>
<author>
<name>Schneider, Jörn</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/17568</id>
<updated>2019-03-28T12:21:40Z</updated>
<published>2012-01-01T00:00:00Z</published>
<summary type="text">Why current memory management units are not suited for automotive ECUs
Schneider, Jörn
Plödereder, Erhard; Dencker, Peter; Klenk, Herbert; Keller, Hubert B.; Spitzer, Silke
A major trend in automotive industry is to enrich driver and passenger experience with an increasing amount of consumer electronics and car-2-x functionality. A close interaction between this added functionality and the classical automotive domains allows for innovations that are valuable to the end customer and cannot be outplayed easily by devices with a pure consumer electronic origin. Innovations of this class require a tight coupling, for instance by executing programs from both worlds on the same microprocessor. The latter introduces many challenges, especially regarding reliability, security and safety of such systems. A unified memory management fulfilling the requirements of the consumer electronics and automotive application could help to address these issues and is a challenge by itself. This paper shows that the prevailing implementation scheme for memory management units (MMUs) is not suited for the needs of such systems and points out a solution direction.
</summary>
<dc:date>2012-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Freedom from interference for AUTOSAR-based ECUs: a partitioned AUTOSAR stack</title>
<link href="http://dl.gi.de/handle/20.500.12116/17567" rel="alternate"/>
<author>
<name>Haworth, David</name>
</author>
<author>
<name>Jordan, Tobias</name>
</author>
<author>
<name>Mattausch, Alexander</name>
</author>
<author>
<name>Much, Alexander</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/17567</id>
<updated>2019-03-28T12:21:40Z</updated>
<published>2012-01-01T00:00:00Z</published>
<summary type="text">Freedom from interference for AUTOSAR-based ECUs: a partitioned AUTOSAR stack
Haworth, David; Jordan, Tobias; Mattausch, Alexander; Much, Alexander
Plödereder, Erhard; Dencker, Peter; Klenk, Herbert; Keller, Hubert B.; Spitzer, Silke
AUTOSAR1 is a standard for the development of software for embedded devices, primarily created for the automotive domain. It specifies a software architecture with more than 80 software modules that provide services to one or more software components. With the trend towards integrating safety-relevant systems into embedded devices, conformance with standards such as ISO 26262 [ISO11] or ISO/IEC 61508 [IEC10] becomes increasingly important. This article presents an approach to providing freedom from interference between software components by using the MPU2 available on many modern microcontrollers. Each software component gets its own dedicated memory area, a so-called memory partition. This concept is well known in other industries like the aerospace industry, where the IMA3 architecture is now well established. The memory partitioning mechanism is implemented by a microkernel, which integrates seamlessly into the architecture specified by AUTOSAR. The development has been performed as SEooC4 as described in ISO 26262, which is a new development approach. We describe the procedure for developing an SEooC.
</summary>
<dc:date>2012-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Static verification of non-functional software requirements in the ISO-26262</title>
<link href="http://dl.gi.de/handle/20.500.12116/17564" rel="alternate"/>
<author>
<name>Kästner, Daniel</name>
</author>
<author>
<name>Ferdinand, Christian</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/17564</id>
<updated>2019-03-28T12:21:40Z</updated>
<published>2012-01-01T00:00:00Z</published>
<summary type="text">Static verification of non-functional software requirements in the ISO-26262
Kästner, Daniel; Ferdinand, Christian
Plödereder, Erhard; Dencker, Peter; Klenk, Herbert; Keller, Hubert B.; Spitzer, Silke
The norm ISO-26262 aims at ascertaining the functional safety of Automotive Electric/Electronic Systems. It is not focused on purely functional system properties, but also demands to exclude nonfunctional safety hazards in case they are critical for a correct functioning of the system. Examples are violations of timing constraints in real-time software and software crashes due to runtime errors or stack overflows. The ISO-26262 ranks the static verification of program properties among the prominent goals of the software design and implementation phase. Static program analyzers are available that can prove the absence of certain non-functional programming errors, including those mentioned above. Static analyzers can be applied at different stages of the development process and can be used to complement or replace dynamic test methods. This article gives an overview of static program analysis techniques focusing on non-functional program properties, investigates the non-functional requirements of the ISO-26262 and discusses the role of static analyzers in the ISO-26262.
</summary>
<dc:date>2012-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Extraktion von Interthread-Kommunikation in eingebetteten Systemen</title>
<link href="http://dl.gi.de/handle/20.500.12116/17565" rel="alternate"/>
<author>
<name>Wittiger, Martin</name>
</author>
<author>
<name>Keul, Steffen</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/17565</id>
<updated>2019-03-28T12:21:40Z</updated>
<published>2012-01-01T00:00:00Z</published>
<summary type="text">Extraktion von Interthread-Kommunikation in eingebetteten Systemen
Wittiger, Martin; Keul, Steffen
Plödereder, Erhard; Dencker, Peter; Klenk, Herbert; Keller, Hubert B.; Spitzer, Silke
Mit der zunehmenden Verbreitung von Multicore-Rechnern werden Multicore-Architekturen auch in eingebetteten Systemen mehr und mehr Einzug halten. Zusätzlich zu den Schwierigkeiten der Softwareentwicklung für Singlecore-Plattformen müssen Software-Ingenieure somit die Herausforderungen bewältigen, bestehende Systeme zuverlässig und fehlerfrei auf Multicores zu portieren und dabei dennoch das Parallelisierungspotential möglichst effektiv zu nutzen. Bislang existiert kaum Werkzeugunterstützung, um diese Portierung in der Praxis durchzuführen. Unsere Ar- beit verfolgt das Ziel, Algorithmen und Werkzeuge zu entwickeln, die existierende Steuersoftware im Automotive-Bereich semi-automatisiert auf Multicore-Plattformen portieren können. In diesem Beitrag wird eine statische Analysetechnik vorgestellt, mit der aus dem Quelltext eines eingebetteten Systems Kommunikationsgraphen extrahiert werden können. Diese können verwendet werden, um Modifikationsbedarf in bestehender Software zu identifizieren, und eignen sich als Grundlage für die spä- tere Partitionierung. Die vorgestellten Algorithmen wurden prototypisch in unserer Programmanalyse-Toolsuite Bauhaus implementiert und ihre prinzipielle Tauglichkeit wurde durch Anwendung auf bestehende industrielle Softwaresysteme bestätigt.
</summary>
<dc:date>2012-01-01T00:00:00Z</dc:date>
</entry>
</feed>
