^

Safe and secure – Software-defined vehicle architectures increase demand for robust code


On the way to the software-defined vehicle, network processors are necessary that are adapted to the requirements of new vehicle architectures, such as the S32G3 series from NXP. The LDRA Tool Suite provides the appropriate support for the component series. It reduces the cost and effort of developing, testing, and certifying software running on S32G3 MPUs.

The convergence of convenience, security, and connectivity features in the automotive sector has led development teams to shift from distributed and domain-based computing architectures to zonal architectures. To provide support for fully software-defined vehicles (SDVs), these new architectures reduce the complexity and cost associated with wiring and harnesses running through the entire vehicle. Instead, the various features are grouped according to their location in the vehicle and managed with the help of sophisticated network processors. However, the implementation of features and systems based on such architectures requires new platforms and software tools that are designed to maintain safety and security and thus comply with standards such as ISO 26262, ISO/SAE 21434, ISO 21448 (SOTIF) and AUTOSAR. These new architectures are supported by NXP Semiconductors’ S32G3 series of in-vehicle network processors, as well as the static and dynamic source code analysis capabilities of the LDRA Tool Suite. Together, these technologies and tools reduce the effort required to develop, deploy, update, and maintain zonal architectures and software.
Figure 1: Comparison between domain-based and zonal vehicle architectures© NXP Semiconductors

 

Zonal architectures on the rise

Modern SDVs are increasingly developing into complex systems consisting of interconnected computer zones. These zones, which implement certain functional areas such as the powertrain, driver assistance systems or infotainment, must be able to work together smoothly on the one hand, but on the other hand be physically separated from each other in the vehicle. There are the following differences between the traditional domain architectures and the new zonal architectures (Figure 1):
  • Domain architectures group features by logical function, each of which has its own electronic control unit (ECU). The ECUs communicate via domain-specific networks and with gateways that allow communication with other ECU networks, which is why the effort on network components and cables is greater here than with zonal architectures.
  • Zonal architectures structure the features according to their location more physically within the vehicle. Here, too, an ECU is available in each case, and gateways manage the communication between the zones. The physical proximity between the components of each zone reduces the amount of cabling required, which saves space and weight and tends to increase the overall achievable processing speed.

In terms of software, these architectures improve modularity, scalability, and flexibility compared to the traditional, centralized approach. Manufacturers can integrate and update features at a more granular level – always under the premise that the software development toolchain is updated to support distributed vehicle networks at this level in addition to safety and security compliance.

Dealing with new software complexities

The NXP S32G3 processor series is specifically designed to support domain-oriented and zonal vehicle architectures. By integrating Arm Cortex-A and Cortex-M cores with powerful timing, security and networking components, these automotive-grade systems-on-chip (SoCs) can provide the computing power needed to enable the creation of multiple virtualized domains and zones on the same platform. This approach facilitates the consolidation and isolation of software components to meet the strict functional, safety, and security requirements of automotive applications.

Domain and zone architectures make it necessary to rethink software design, development, testing, and compliance in many ways:
  • Domain and zone controllers distribute the need for real-time performance, additional memory, and high-speed communications across multiple ECUs instead of a smaller number of centralized components.
  • Controllers may require virtualization-enabled support for functions with different Automotive Safety Integrity Levels (ASILs).
  • The increased number of controllers and communication channels can increase the number of attack surfaces, which in turn can increase the potential for security vulnerabilities and threats.
  • Domains and zones allow for richer, more granular control of OTA and FOTA updates, accelerating release cycles across multiple codebases.
  • Thanks to virtualization, the update cycles of hardware and software do not have to be one after the other.
By addressing these challenges and helping to support the benefits described, the LDRA Tool Suite, together with the NXP S32 Design Studio IDE, helps reduce the cost and effort associated with testing and certifying software intended to run on NXP S32G3 processors.
Figure 2: The capabilities of the LDRA Tool Suite at a glance© LDRA

 

Reducing development risks

LDRA’s static and dynamic analysis tools can significantly reduce development risks by providing insight into the quality and performance of each code, allowing potential defects, vulnerabilities, and non-compliance to be detected at an early stage of development. Specifically, the LDRA Tool Suite (Figure 2) offers the following capabilities:
  • Conformity to coding standards (industrial or user-defined) such as MISRA, CWE or CERT
  • Automated test case, harness and stub generation for robustness tests
  • Automatically generate evidence for software certifications and approval processes
  • ISO 9001:2015 certified quality management system with certifications from TÜV SÜD and SGS-TÜV Saar
  • Support and compliance with ISO 26262 to ASIL D, ISO/SAE 21434, AUTOSAR and ASPICE
In addition, LDRA has added new capabilities for the NXP S32G3 processor series to its existing support for NXP products. With the help of the LDRA plugin for the NXP S32 Design Studio IDE and the Target License Package (TLP) specifically for the S32G3 processor, it is possible to fully automate and integrate software testing and compliance between the development host and the target system.
The LDRA TLP is optimized to minimize the impact and effort on the target system. The final, instrumented executable is so efficient that it runs on 8-bit CPUs with 8K flash memory and 2K RAM.
With a range of testing capabilities that include static and dynamic analysis, automated unit testing, and automated worst-case execution-time analysis, LDRA tools help reduce manual work and enable efficient detection and remediation of software issues and vulnerabilities. They also support compliance activities and evidence gathering for the ISO 26262, ISO/SAE 21434, AUTOSAR, and ASPICE standards. Capabilities of this kind are ideal for improving the productivity, robustness, and compliance of SDVs with zonal architectures.


Solutions for future software-defined vehicles

In view of the fact that more and more functions are implemented with software, the switch from distributed and domain-based computer architectures to zonal architectures is unavoidable. With advanced capabilities and support for virtualized domains and zones, NXP’s S32G3 processors play a critical role in this transformation. Supported by the LDRA Tool Suite, software developers can more effectively manage code complexity, streamline release efforts, and ensure compliance with relevant safety and security standards. (corner)

The Author- Stephen Di Camillo
Who works as a Technical Marketing and Business Development Manager at LDRA.

FREE 30 Day
TRIAL

Email Us

Email: info@ldra.com

Call Us

EMEA: +44 (0)151 649 9300

USA: +1 (855) 855 5372

INDIA: +91 80 4080 8707

Connect with LDRA