Software Tool Qualification According to ISO 26262
نویسندگان
چکیده
International standards that define requirements for the development of safety-related systems typically also define required confidence levels for the software tools used to develop those systems. The standards define—to a greater or lesser extent— procedures to classify, validate, certify, or qualify tools. To date, there is no common approach for tool validation, certification, and qualification across safety standards. Different standards attach different levels of importance to tool validation, certification, and qualification, and suggest different approaches to gain confidence in the tools used. With ISO 26262 ―Road Vehicles Functional Safety‖ on the horizon, automotive software practitioners will need to understand and implement the new software tool classification and qualification requirements laid out in this standard. ISO 26262 is the adaptation of IEC 61508 to comply with needs specific to the application sector of electric / electronic systems (E/E systems) within road vehicles. This adaptation applies to all activities during the safety lifecycle of systems composed of electrical, electronic, and software elements that provide safety-related functions. Clause 11 of ISO 26262-8 provides guidance on software tool classification and qualification. The clause applies, if the safety lifecycle incorporates using a software tool, such that (1) activities or tasks required by ISO 26262 rely on the correct functioning of that tool, and (2) relevant outputs of that tool are not fully examined or verified. This paper describes the tool classification and qualification approach of ISO/FDIS 26262 and summarizes the authors’ firsthand experiences with implementing this approach for development and verification tools. ISO/FDIS 26262 TOOL QUALIFICATION APPROACH This section provides a brief overview on the tool qualification approach as outlined in the final draft standard. International standards that define requirements for the development of safety-related systems typically also define the required level of confidence for the software tools used to develop these systems. To varying degrees, these standards define procedures to classify, validate, certify, or qualify tools. To date, there is no common approach for tool validation, certification, and qualification that can be applied to all safety standards. Different standards attach different levels of importance to these objectives and suggest different approaches to gain confidence in the tools used [CMR10]. ISO/FDIS 26262 ―Road Vehicles Functional Safety‖ [ISO/DIS 26262] is the adaptation of IEC 61508 [IEC 61508] to comply with needs specific to the application sector of electric / electronic systems (E/E systems) within road vehicles. This adaptation applies to all activities during the safety lifecycle of systems composed of electrical, electronic, and software elements that provide safety-related functions. As per ISO/FDIS 26262-8, 11, a software tool (or a software tool chain) used in the safety lifecycle, in a way that (1) activities or tasks required by ISO 26262 rely on the correct functioning of that tool, and (2) relevant outputs of that tool are not fully examined or verified, need to be assessed, classified, and potentially qualified. ISO/FDIS 26262-8 provides criteria to determine the required level
منابع مشابه
ISO 26262 - Exemplary Tool Classification of Model-Based Design Tools
Tool classification is an important part of the tool qualification process required by ISO 26262 since it determines the required confidence level for each tool in use. To cover the variety of tools used by practitioners, the standard only provides a framework for tool classification and leaves it up to the applicant to instantiate this framework. To illustrate the ISO 26262 tool classification...
متن کاملQualifying Software Tools According to ISO 26262
The growing adoption of safety standards in the automotive industry results in an increasing interest in as well as an increasing uncertainty about software tool certification and qualification. With ISO 26262 on the horizon, new tool qualification requirements need to be understood and implemented by automotive software practitioners. This paper summarizes the tool qualification approach of IS...
متن کاملISO 26262 - Tool chain analysis reduces tool qualification costs
Software tools in safety related projects are indispensable, but also introduce risks. A tool error may lead to the injection or non-detection of a fault in the product. For this reason the safety norm for road vehicles, ISO 26262, requires determination of a tool confidence level for each software tool. In this paper we present a model-based approach to represent a tool chain, its potential er...
متن کاملPolitecnico di Torino Porto Institutional Repository [ Proceeding ] An Overview of Software - based Support Tools for ISO 26262
Safety in the automotive domain is becoming more and more important with the ever increasing level of complexity in emerging technologies built-in into the cars. As a stimulus for industry to refine its safety measures related to electrical, electronic and software systems in the cars, the ISO 26262 standard has been recently introduced. Developing safety-related systems according to this stand...
متن کاملEfficient and Trustworthy Tool Qualification for Model-Based Testing Tools
The application of test automation tools in a safety-critical context requires so-called tool qualification according to the applicable standards. The objective of this qualification is to justify that verification steps automated by the tool will not lead to faulty systems under test to be accepted as fit for purpose. In this paper we review the tool qualification requirements of the standards...
متن کامل