SW Architecture & Unit Design
Master ISO 26262-6 software architectural design principles, safety design patterns, Freedom from Interference, AUTOSAR architecture, and unit design techniques for safety-critical automotive software.
- Chapters
- 14
- Chapters
- Core Topic
- FFI
- Core Topic
- Architecture
- AUTOSAR
- Architecture
- Design Depth
- ASIL-D
- Design Depth
- 01Overview & Scope
- 02Theoretical Foundations
- 03Architectural Design Principles
- 04Architecture Patterns
- 05Unit Design
Why it pays for itself
Architect with the right principles
Apply the ISO 26262-6 design principles - modularity, encapsulation, low coupling, high cohesion, defensive design - plus safety patterns such as monitor-actuator, safety wrapper and 1oo2 voting.
Partition mixed-criticality software
Master freedom from interference for mixed-ASIL designs: temporal and spatial partitioning, information hiding, and communication integrity between components of different ASIL on one ECU.
Design units that pass verification
Write unit designs with proper data types, range checks, pre and postconditions and documented invariants, structured for the reviews and structural coverage testing that follow.
What you’ll be able to do
Design Safety Architectures
Apply ISO 26262-6 architectural design principles and proven safety patterns to create modular, analyzable, and verifiable software structures.
Implement FFI Partitioning
Enforce Freedom from Interference between mixed-criticality software components using temporal partitioning, spatial partitioning, and communication integrity mechanisms.
Apply SW Safety Mechanisms
Select and implement the right software safety mechanisms for each failure mode including range checks, program flow monitoring, and E2E protection.
Design AUTOSAR Safety Applications
Structure AUTOSAR-based software with appropriate OS application configuration, memory protection, and communication stack safety settings.
Handle Mixed-Criticality Systems
Design software architectures where ASIL-A through ASIL-D components coexist with proper isolation, monitoring, and decomposition strategies.
Verify Architecture & Unit Design
Plan and execute architecture verification activities with appropriate methods, independence levels, and completeness criteria per ISO 26262-6.
Chapter by chapter
- 01
Overview & Scope
Introduce the scope of software architectural and unit design within ISO 26262-6, clarify the relationship between architectural design, unit design, and implementation, and map to the V-Cycle phases.
- Scope definition
- V-Cycle placement
- Phase relationships
- 02
Theoretical Foundations
Build the theoretical foundation for safety-oriented software design including fault models, error propagation, design for testability, and the role of formal specification in high-ASIL components.
- Fault models
- Error propagation
- Formal specification
- 03
Architectural Design Principles
Apply ISO 26262-6 architectural design principles including modularity, encapsulation, low coupling, high cohesion, and the use of defensive design strategies to prevent error propagation.
- Modularity & encapsulation
- Coupling & cohesion
- Defensive design
- 04
Architecture Patterns
Explore architectural patterns for safety-critical software including monitor-actuator, watchdog supervisor, safety wrapper, heterogeneous redundancy, and 1oo2 voting architectures with ASIL applicability guidance.
- Monitor-actuator pattern
- Safety wrapper pattern
- Voting architectures
- 05
Unit Design
Apply unit design principles per ISO 26262-6 including proper use of data types, range checking, pre/postcondition definition, invariant documentation, and design for structural testability.
- Data type design
- Pre/postconditions
- Structural testability
- 06
Freedom from Interference
Master Freedom from Interference (FFI) requirements for mixed-criticality software. Covers temporal partitioning, spatial partitioning, information hiding, and communication integrity between components of different ASIL.
- Temporal partitioning
- Spatial partitioning
- Information hiding
- 07
SW DFA & Safety Analysis
Apply software-level Dependent Failure Analysis (DFA) and safety analysis techniques including FMEA at software level, FTA for software failures, and common cause failure analysis for redundant software channels.
- SW-level FMEA
- SW FTA
- Common cause analysis
- 08
AUTOSAR Architecture
Design safety-compliant software architectures using the AUTOSAR framework. Covers AUTOSAR layered architecture for safety, memory protection configuration, OS application design, and integration with the safety architecture.
- AUTOSAR layers for safety
- Memory protection config
- OS application design
- 09
SW Safety Mechanisms
Implement software safety mechanisms including range checks, plausibility monitoring, program flow monitoring, CRC verification, end-to-end protection, and alive counters as per ISO 26262 method requirements.
- Range & plausibility checks
- Program flow monitoring
- E2E protection
- 10
Coding Guidelines Integration
Integrate coding guidelines (MISRA C, AUTOSAR C++14) with architectural and unit design. Learn how design decisions upstream reduce guideline violations and how static analysis fits into the design verification workflow.
- MISRA integration
- Design-to-guideline mapping
- Static analysis role
- 11
Mixed-Criticality Design
Design systems where software components of different ASILs coexist on the same hardware. Master ASIL decomposition at software level, partition isolation strategies, and the role of the OS in mixed-criticality enforcement.
- SW ASIL decomposition
- Partition isolation
- OS role in criticality
- 12
ML/AI Integration
Address the architectural challenges of integrating machine learning components into safety-critical software. Covers safety wrapper patterns for ML, SOTIF boundary handling, monitoring strategies, and current ISO/PAS 21448 guidance.
- ML safety wrappers
- SOTIF boundary handling
- Monitoring strategies
- 13
Verification & Review
Verify software architecture and unit design using design reviews, walk-throughs, architecture analysis methods (ATAM, SAAM), and model checking techniques. Learn independence requirements for ASIL-C and ASIL-D reviews.
- Architecture reviews
- ATAM/SAAM methods
- Independence requirements
- 14
Best Practices
Industry best practices for efficient and compliant SW architectural design including design pattern libraries, architecture documentation templates, and lessons learned from common safety assessment findings.
- Design pattern libraries
- Documentation templates
- Assessment lessons
Not just text: the visual toolkit
Architecture Pattern Explorer
Interactive library of safety architecture patterns with ASIL applicability, structural diagrams, pros/cons, and example use cases for each pattern.
FFI Partitioning Visualizer
Visual demonstration of temporal and spatial partitioning between mixed-criticality software components with configurable partition boundaries and violation detection.
SW Safety Mechanism Selector
Decision tool mapping failure modes to appropriate software safety mechanisms with diagnostic coverage estimates and implementation complexity ratings.
AUTOSAR Safety Stack
Interactive AUTOSAR architecture diagram highlighting safety-relevant layers, memory protection unit configuration, OS application boundaries, and inter-application communication.
Mixed-Criticality Decomposition
Visual tool for planning ASIL decomposition at software level showing valid channel combinations, independence requirements, and FFI obligations for each configuration.
Unit Design Template
Interactive unit design specification template with fields for pre/postconditions, data ranges, error handling strategy, and testability considerations linked to ASIL requirements.
SW Architecture for ASIL-D Steering Angle Controller
Complete architectural design walkthrough for a steering angle controller with FFI between diagnostic monitor (ASIL-D) and actuation control (ASIL-D), including AUTOSAR implementation.
- SW safety requirements analysis and architectural decomposition strategy
- Monitor-actuator pattern selection and FFI partitioning design
- OS application configuration for spatial and temporal partitioning
- SW safety mechanism selection for each identified failure mode
- Architecture DFA and independence requirements verification
- Unit design specification for the plausibility monitoring component
Unlock 5 more design phases
Who this guide is for
- Embedded software engineers on their first ASIL-rated project
- Software architects putting QM and ASIL components on the same ECU
- AUTOSAR integrators configuring memory protection and OS applications for safety
- Developers who need their unit designs to survive an ISO 26262-6 verification review
Frequently Asked Questions
Common questions about SW Architecture & Unit Design
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.