Vehicle Motion Control Safety
The choreography, not the hands: how five requesters, four actuator domains and one shared friction budget become a coordinated chassis function that a safety case can carry.
- Chapters
- 14
- Chapters
- Requesters arbitrated
- 5
- Requesters arbitrated
- Coordinator failure shapes
- 4
- Coordinator failure shapes
- Pitfalls dismantled
- 10
- Pitfalls dismantled
- 01One Vehicle, Many Hands
- 02The Physics Every Actuator Shares
- 03Motion Hazards and the HARA
- 04Motion Requests and Capability Contracts
- 05Control Allocation
Why it pays for itself
See the hazards no component owns
Coordinated motion produces hazardous events with every subsystem in range and in health. The guide shows how to anchor the analysis at vehicle level so those events get analyzed once rather than four times or never.
Make the interaction layer testable
Requests, capability contracts, arbitration rules and allocation constraints turn an implicit negotiation in the tires into artifacts that can be reviewed, versioned and verified from both sides of every seam.
Design the degraded vehicle on purpose
Coordinator failure shapes, aligned timeouts, a short ladder of mode contracts and a fallback distribution rule replace whatever behavior would otherwise emerge in the order the fault happened to choose.
What you’ll be able to do
Analyze Motion Hazards at Vehicle Level
Anchor the hazard analysis on what the vehicle does rather than on which actuator moved, and recognize the hazardous events that emerge from coordination with no component broken.
Specify Requests and Capability Contracts
Design motion request and capability interfaces whose semantics, source authority, freshness and integrity turn coordination faults into detectable events instead of permanent ones.
Choose Arbitration and Allocation Deliberately
Pick the arbitration scheme and allocation family whose characteristic failure shape and verification cost you can live with, and treat the objective ordering as a safety requirement.
Detect the Combination Fault
Build envelope monitors and cross-domain plausibility residuals with the independence they need, and separate detection of an inconsistency from attribution of a culprit.
Design Degradation Instead of Improvising It
Build a short ladder of mode contracts, distribute each fallback into hardware that survives the faults forcing entry, and keep every ECU on the same rung through a bounded transition.
Own the End-to-End Timing and the Evidence
Decompose the fault-to-reaction budget across ECUs and suppliers, then verify the composition through contract tests, arbiter truth tables, allocation invariants and seam fault injection.
Chapter by chapter
- 01
One Vehicle, Many Hands
How the chassis accumulated actuators one function at a time, why individually safe systems do not compose into a safe vehicle, and what electrification, by-wire paths and central compute changed about the overlap.
- The composition problem
- Why now
- The new safety boundary
- 02
The Physics Every Actuator Shares
Strip the product names away and every subsystem requests force at one of four contact patches. The friction budget, the role of vertical load, the three different ways to make a car rotate, and what the edge of the envelope does to a controller.
- Shared friction budget
- Load transfer
- Equivalent yaw sources
- 03
Motion Hazards and the HARA
Why motion hazards are named at vehicle level rather than at the actuator, how magnitude, duration and situation decide the classification, and the integration twist: a motion hazard can emerge with every component healthy.
- Vehicle-level anchoring
- The SAE J2980 anchor
- Hazards with no broken part
- ISO 21448 boundary
- 04
Motion Requests and Capability Contracts
The move from point-to-point wiring to published contracts: what a motion request must carry beyond a value, how high or low on the abstraction ladder it should speak, and why the reverse direction, what an actuator can deliver right now, matters more than the forward one.
- Request semantics
- Abstraction ladder
- Honest capability
- Violations as a failure catalog
- 05
Control Allocation
One agreed vehicle-level demand, four wheels and three force sources. Brake blending as the everyday case, the allocation families and what each costs in verification, why the constraints and the objective ordering are the real safety content, and how allocators fail.
- Over-actuation surplus
- Blending seam
- Objective ordering
- ASIL of the allocator
- 06
Authority and Arbitration
Before anything is allocated, something has to win. The requester roster, the characteristic failure shape each arbitration scheme carries, why authority is directional rather than a scalar priority, and why high authority must be granted for a bounded interval that expires.
- Scheme failure shapes
- Directional authority
- Time-bounded grants
- Chatter and hysteresis
- 07
Incompatible Requests and Cross-Domain Plausibility
The combination fault: every request in range, fresh and authorized, and the set still wrong. Envelope monitoring against authorized intent and physics, cross-domain residuals, the independence a monitor actually needs, and the harder problem of deciding whom to react against.
- Combination faults
- Envelope monitoring
- Cross-domain residuals
- Detection versus attribution
- 08
Saturation and Degraded Capability
Reaching a limit is not a fault. How to separate controlled saturation from silent capability loss, how reallocation buys back a shortfall and what discipline keeps it from oscillating, and the derating mechanisms that starve different motion axes on different timescales.
- Saturation versus fault
- Reallocation discipline
- Derating catalog
- Shrinking the offer first
- 09
Common Dependencies and Dependent Failures
The domains look independent on the org chart and share power, sensors, wires, time and code. The shared-resource inventory, cascading versus common cause, the shared-sensor betrayal where every monitor agrees about a vehicle that does not exist, and power as the super-dependency.
- Coupling inventory
- Shared-sensor blindness
- Power coupling
- The dependency you installed
- 10
When the Motion Coordinator Fails
Four output failure shapes, four different vehicles: silent, frozen, babbling and partial. The fail-silent coordinator with actuator-local fallback, the staggered-timeout trap, when fail-operational is required instead, and how actuators detect the coordinator from below.
- Four failure shapes
- Local fallback set
- Staggered timeouts
- Takeover state continuity
- 11
Graceful Degradation and Fallback Distribution
Less is a place the vehicle must know how to live in. Rungs as mode contracts with entry conditions and exit policy, the structural rule that a fallback must survive what forced entry into it, mode agreement across ECUs, and why availability itself can be safety-related.
- Ladder as design object
- Fallback distribution rule
- Mode agreement window
- Minimum risk manoeuvre limits
- 12
Timing Across the Chain
A motion request lives through several worlds with different clocks. FTTI decomposition across ECUs and suppliers, why a late command is a different command, the timing faults beyond plain lateness, and the shared time base every cross-domain comparison silently assumes.
- End-to-end budget ownership
- FTTI decomposition
- Jitter and ordering
- Timestamp at the source
- 13
Verifying a Coordinated Function
Every actuator passed its tests; now test the thing none of them is. Why the interaction space cannot be enumerated, the structural answer of contracts, truth tables and invariants, fault injection at the seams, vehicle-level scenarios, and what the evidence pack has to contain.
- Combinatorics problem
- Structure beats enumeration
- Seam fault injection
- Transition coverage
- 14
Worked Example: A Coordinated Motion Architecture
One illustrative vehicle with every idea of the guide wearing concrete values: safety goals, the architecture with contracts on each element, arbitration and allocation made specific, a dependent failure excerpt, the instantiated degradation ladder, a closed timing budget, verification highlights and ten recurring pitfalls.
- Architecture with contracts
- DFA findings
- Instantiated ladder
- Ten pitfalls
Who this guide is for
- Chassis and vehicle motion engineers building a coordination or integration layer
- Safety engineers writing the concept for a function that spans braking, steering and propulsion
- E/E architects deciding where arbitration and allocation live and what happens when they stop
- Integrators who must verify a composition after every subsystem has passed its own tests
- Engineers moving from single-actuator safety arguments to vehicle-level ones
Frequently Asked Questions
Common questions about Vehicle Motion Control Safety
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.