Interior and Mirror Cameras
The cameras that face the other way. Camera monitor systems that replace mirrors and interior cameras that watch the driver: where their ASIL comes from, the fault that is bit-perfect and no longer true, and the safety architecture that catches it.
- Chapters
- 15
- Chapters
- Catalogued Faults
- 18
- Catalogued Faults
- Safety Mechanisms
- 11
- Safety Mechanisms
- Worked Example
- 1
- Worked Example
- 01Cameras That Face the Other Way
- 02The Rulebook: UN R46, ISO 16505, the GSR and ISO 26262
- 03Anatomy of a Camera Chain: Photons to Pixels to Judgement
- 04What Can Go Wrong: Hazards and HARA
- 05From Safety Goals to a Safety Concept
Why it pays for itself
Design for the failure that actually happens
A mirror camera rarely goes black. It freezes, tears, or keeps showing a frame that is bit-perfect and no longer true. The fault catalogue is written per stage rather than per symptom, and the chapter on freshness shows why the obvious counter-measure is usually placed where it detects nothing.
Get the type approval and the safety case in the right order
UN R46 and ISO 16505 fix the field of view, the luminance and the latency ceiling before ISO 26262 opens, and the GSR delegated acts do the same for driver drowsiness and attention warning. The guide separates what is already decided from what you still get to design, and shows why the two requirement sets have to be traced apart.
Know where each camera gets its ASIL from
The mirror camera closes a control loop through a human, so its rating comes from what the driver cannot do without it. The interior camera gates another function's authority and inherits its rating. Two different sources, two different safety concepts, and a chapter each.
Argue a single-channel chain honestly
There is no fusion partner and no second channel. The metrics chapter walks an illustrative FMEDA element by element, shows what diagnostic coverage can and cannot mean for an image, and is explicit about who bears the residual when nothing downstream checks the picture.
What you’ll be able to do
Separate approval requirements from safety requirements
Trace UN R46, ISO 16505 and the GSR delegated acts apart from ISO 26262 requirements, and know which of the two fixed a given number before you started designing.
Write a fault catalogue per stage
Build the catalogue against the chain rather than against symptoms, so that freeze, tear and stale-but-valid each land on the stage that produces them.
Place a freshness check where it detects something
Choose the mint and check points of a frame identity deliberately, and state which elements of the chain the chosen placement leaves uncovered.
Specify a degradation requirement
Replace "inform the driver and degrade gracefully" with a requirement that names the trigger, the indication, the timing and the state the system ends in.
Argue a single-channel chain
Run the FMEDA on a chain with no second channel, be explicit about what diagnostic coverage means for an image, and say who carries the residual risk.
Chapter by chapter
- 01
Cameras That Face the Other Way
Two cameras and two consumers: the mirror that became a monitor and the camera that watches the driver. Why both exist, and the hundred milliseconds they share.
- Two cameras, two consumers
- Why they exist
- The same hundred milliseconds
- 02
The Rulebook: UN R46, ISO 16505, the GSR and ISO 26262
Three kinds of authority over one device. The mirror rulebook, the driver rulebook with its privacy clause, the occupant rulebook, and where ISO 26262, ISO 21448 and ISO/PAS 8800 sit relative to all of them.
- UN R46 and ISO 16505
- The GSR and Euro NCAP
- Where ISO 26262 sits
- 03
Anatomy of a Camera Chain: Photons to Pixels to Judgement
Photons to pixels to judgement: the lens and cover glass, the illuminator and its photon budget, the sensor, the link and image processor, the monitor, and the glass-to-glass latency budget.
- The photon budget
- Sensor to processor
- Glass-to-glass latency
- 04
What Can Go Wrong: Hazards and HARA
Three items and three boundaries. The hazards of a view against the hazards of a judgement, and why severity, exposure and controllability are arguments rather than lookups.
- Hazards of a view
- Hazards of a judgement
- Controllability as argument
- 05
From Safety Goals to a Safety Concept
Why a blank mirror is not a safe state, the fault tolerant time interval measured against a glance, the driver monitor's clock that belongs to someone else, and a warning that cannot itself freeze.
- A blank mirror is not safe
- FTTI against a glance
- A warning that cannot freeze
- 06
The Fault Catalogue and the Mechanisms That Catch Them
Eighteen faults written per stage rather than per symptom, against eleven mechanisms with their latencies and their reach. Freeze is easy, stale is harder, correct is not provable.
- Eighteen faults by stage
- Eleven mechanisms
- Freeze, stale, correct
- 07
The Numbers: Hardware Metrics on a Camera Chain
Three metrics in two sentences and one channel. An illustrative FMEDA element by element, what diagnostic coverage can mean for an image, and who bears the residual with no second channel.
- Illustrative FMEDA
- Coverage for an image
- Who bears the residual
- 08
When Nothing Is Broken: Performance Limits and SOTIF
A hazard with no fault in it. The triggering conditions of a mirror and of a face, two ways to be wrong and who pays for each, and what ISO/PAS 8800 adds when the estimator is a component.
- Triggering conditions
- Two ways to be wrong
- What ISO/PAS 8800 adds
- 09
Implementation: The Safety Architecture
Partition first, a QM pipeline beside an ASIL monitor. Frame identity that travels with the data and is checked where it ends, the illuminator interlock in hardware, and the latency budget allocated across suppliers.
- QM pipeline, ASIL monitor
- Frame identity
- The illuminator interlock
- 10
Process: Suppliers, Qualification, Type Approval and Privacy
Who builds what, qualifying the parts for the environment of a door, verification from fault injection to the test house, and privacy engineering for a camera that watches a person.
- The supply chain
- AEC-Q and ISO 16750
- Privacy engineering
- 11
Worked Example: A Truck Mirror Replacement and a Driver Monitor
The item drawn on the truck, six hazardous events and three safety goals, requirements with numbers attached, the architecture and latency budget in milliseconds, then a driver monitor behind a hands-off assist.
- Six hazardous events
- Latency in milliseconds
- Two parts, one exercise
- 12
Versus ADAS Cameras: Who Looks at the Picture
Two consumers and two definitions of quality. Latency means two different things, controllability puts the human first and last, and off is a safe state for an assist but not for a mirror.
- Two definitions of quality
- Two meanings of latency
- Safe-state semantics
- 13
Versus ADAS Cameras: Metrics, Mechanisms and Safe States
A chain with no fusion partner, the mirror as benchmark, a monitor whose ASIL is derived rather than intrinsic, light that must not hurt the eye, and three shapes of safe state.
- No fusion partner
- Derived ASIL
- Three shapes of safe state
- 14
Versus ADAS Cameras: Regulation, Validation and Data
A prescriptive bench against a performance-based road, function mandates validated on people, privacy as a constraint on validation, and what to take from the ADAS toolkit and what to leave.
- Bench versus road
- Validated on people
- What to leave behind
- 15
The One-Page Story
Why two cameras fit on one page, and the poster, tables and ten sentences that carry the whole argument into a design review.
- Two cameras, one page
- The poster and tables
- Ten sentences
Not just text: the visual toolkit
Photon Budget Lab
The light the illuminator has to put on the scene for the sensor to return a usable frame, and what happens to the budget as the scene fights back.
Identity Journey
Where a frame identity is minted and where it is checked, and which elements of the chain each placement can and cannot cover.
Latency Waterfall
The glass-to-glass budget stage by stage, next to the time-to-indication that nobody quotes.
Coverage and Latency Matrix
Eighteen catalogued faults against eleven mechanisms, with the detection latency and reach of each one.
Mirror Class Fields
The fields of view a camera monitor system has to reproduce to replace a mirror class, drawn on the vehicle.
Illuminator Interlock
The hardware circuit that keeps an infrared illuminator inside its eye-safety limit independently of the software driving it.
FMEDA Bench
The illustrative FMEDA for a single-channel camera chain, element by element.
Mini-HARA Explorer
The hazardous events of a view and of a judgement, with the severity, exposure and controllability argument behind each rating.
A Truck Mirror Replacement and a Driver Monitor
One exercise in two parts: a camera monitor system replacing the mirrors on a heavy truck, then a driver monitoring camera sitting behind a hands-off assist - the same chain, two completely different sources of ASIL.
- The item drawn on the truck, with its boundary and its interfaces
- Six hazardous events reduced to three safety goals
- Requirements with numbers attached rather than adjectives
- The architecture and its latency budget, in milliseconds across suppliers
- The FMEDA summary and the verification list that closes it
Full worked example available with an Expert plan
Who this guide is for
- Engineers on camera monitor systems replacing class II, IV or VI mirrors on cars and trucks
- Teams building driver monitoring for hands-off assist, drowsiness warning or occupant detection
- Safety managers who have to hold a type-approval trace and an ISO 26262 trace side by side
- Architects allocating a latency budget across a supply chain they do not fully control
- Anyone who has written "inform the driver and degrade gracefully" and been asked what that means
Frequently Asked Questions
Common questions about Interior and Mirror Cameras
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 74-guide library. No credit card required.