Navigating the Shift to
Continuous SDV Development:
Bridging architecture, implementation, and
compliance
Robert ter Waarbeek
Automotive Industry Manager (EMEA)
Agenda
▪ SDV
▪ “The perfect storm”
▪ Continuous re-deployment
of safety critical software
▪ Conclusion
2
Brand-distinctive features and main customer
Software Defined Vehicle value will come from Software
Customer Expectations demand Technology & Innovation
Clean and Safe mobility Electrification
Digital Life continuity Autonomy
Connectivity
monetize
invest
Business Opportunity
App stores, SW features on demand
SW services subscription plans
3
Automotive industry is facing the perfect storm
Change everything at same time at speed to enable SDV
Technology Processes
• New E/E & Software • Single delivery → continues
Architectures development
• Connectivity • Development and deploy in the
cloud
Collaboration & People
• Evolving OEM1-TIER1-TIER2 relationships
• Focus on differentiation software
4
• Organization & structural changes
Software-Defined Vehicles
Modern Software Practices Reliability
Data-Driven Functionality Functional Safety
Leverages Cloud Physical Components
5
Software-Defined Vehicles
Modern Software Practices Reliability
Data-Driven Functionality Functional Safety
Leverages Cloud Physical Components
6 6
Navigate the perfect SDV storm
New E/E Software Software Virtualization Using Data Safety and
Architectures Architectures factory Cyber-security
Industry Scaling to the V-Model and Organizational System …
collaboration cloud continuous Transformation Engineering
development
7
Driving factors for continuous re-deployment of safety
critical software.
(re-)certification,
update delivery
missed
2 weaknesses
DEVELOP
1 DEPLOY
6 New Idea
DEV OPS OPERATE
7
BUILD
5
3 TEST MONITOR
attack
➔ Agility & Consistency
8
Embedded components are significant attack surface (2024)
52%
43%
of attack vectors
start with embedded systems
(this presentation)
15%
13%
9%
7%
4% 3%
2% 2% 2%
9
Source: Upstream Security 2024, based on 900+ automotive incidents. Note: multiple vectors can be used in each attack.
Safety depends on Security, and vice versa
System/Product
Security Safety
Fault
“New”
behavior Failure,
Hazard
Attacker
Control
…
Information
disclosure
Security prevents abuse, safety prevents hazard
10
(Safety and) Security is a Process, not a Product *
updates
Covered with safety workflows: New tasks for security:
• Design for reliability/failure • Incident monitoring & updates
• Focus on what is known • Focus on what is unknown
• Rigorous testing • Design for malicious attacks
• … • …
1. Re-use/extend current safety measures with security in mind
2. Design safe and secure system
* [Link]
11
Continuous System Care
DEPLOY
DESIGN
Development Operations OPERATE
BUILD
TEST MONITOR
12
Example:
redeploy safety critical BEV software (after an attack/idea)
BMS HVAC (Cabin HPC)
Dependencies
Driveline Controls Thermal ECU
13
Update Requirements and Architecture
& Design safe and secure system
Requirements System Continuous
Analysis System Release
Requirements System Care
Threat/risk System
assessm.,
Security concept / System Design Integration and
allocate
Security architecture
sec. reqs Test
1. Leverage architecture models to structure risk analysis
SW
2. Calculate risk impact from Design
threats SW Test
3. Document formal cybersecurity requirements
SW
Implementation
14
Update Requirements and Architecture
Update
Requirements and Architecture
requirements
and traceability
Interoperability Live – SysML v2 API in Action
▪ SysML v2 is just a language and the SysML v2
API is just an API
▪ but they lay the foundation for the future of
system system analysis SOA MBSE.
decomposition and optimization definitions
SysML 2
([Link]
15 v2-api-in-action) All trademarks, logos and brand names are the property of their respective owners.
SW Design & Implementation
System Continuous
System Release
Requirements System Care
System
System Design Integration and
Test
Secure
modeling,
SW Design SW Test
counter-
measures
Secure Compliant C/C++ Code-level
SW security & proof
code
generation Implementation robustness
analysis
17
Optimize Right & Shift Left
Qualcomm®
OPTIMIZE RIGHT Hexagon NPU for Snapdragon
MODEL-BASED DESIGN
Embedded Systems
Algorithm Design and Code Generation Microcontroller
Requirements On-board HPC
and Microprocessor Infineon
Architecture Simulation
AURIX TC4.x microcontroller
Cloud
Controller
Full System Components Virtual Processor Scenarios
SHIFT LEFT
NXP®
GoldBox for in-vehicle HPC
Develop software independent from target hardware
18
All trademarks, logos and brand names are the property of their respective owners.
Maximize reuse through modular and adaptable development
Software Component
(HW/Middleware independent)
1. Re-target to middle-ware leveraging „adaptors“
2. Automate (major parts of) HW optimization
µCs HPCs Cloud Mobile
19
V&V with Cyber-security perspective
System Continuous
System Release
Requirements reqs. System Care
System Intrusion Intrusion
System security
System Design Integration and Tests &
reqs. integration test Detection
Test Detection
and verification Reaction
SWtesting,
Req. security
SW Design reqs. SW Test Fuzz testing, test
integration
Attack
and Sim.
verification
SW
Implementation
20
SDV’s compliance with regulations
▪ e.g. UN-Regulation (No. 155&156) and ISO standards (24089) for safe and
secure automotive software updates
UN R156 Source: R156e ([Link]
21
Tracking changes and minimizing re-certification (R.156)
Not
impacted
Modified
signal
Must
re-test
Modified
file
22
How to scale continuous verification and validation
▪ UN Regulation (No. 155&156) and ISO standards (24089) for safe and secure
automotive software updates
UN R156 Source: R156e ([Link]
23
SDV’s compliance with regulations & shift left
Validate all variants in the fleet
Scalable software factory
including system simulation
MIL SIL HIL Vehicle
Shift left
Development process
Use each test method where it adds value to the V&V process.
24
Validate and optimize all variants in the fleet
Radiator
Condenser
Chiller
PTC
Evaporator Cabin
DC-DC
Battery Heater
Driveline
Motor
Charger
Build holistic BEV model Simulate & analyze Optimize
including software (hardware), software & calibration
25
Observations of leaders in the industry
▪ Increasing reliance on system-level simulation for software
development
▪ Include system simulation throughout the development loop
▪ Distribute simulation to all engineers
–Integrating system-level simulation into software development
environment
26
Closed loop simulation with Adaptative Autosar in Linux
Runtime
28 | 28
Collaborative Simulations in the Cloud
• Run parallel
simulations
• Automate model
checks, simulations,
report generation in
CI pipelines
• Automatically
generate code,
interactively or • Integrate application • Integrate
in CI pipeline code with production with
middleware detailed
virtual ECU
30
Background: Algorithm Only
Foreground: Algorithm + Production Middleware + Virtual Processor
31 31
Conclusion
▪ Industry is in a perfect storm
▪ Agility & Consistency needed to enable new features and react quick and
compliant to security treats
▪ Simulations & Virtualization throughout the development and make them
accessible to everyone in Software Factories
▪ Collaboration is key
32
MathWorks collaborations to support automotive companies the SDV transition
Semiconductor eco-system Supplier eco-system New and established OEMs
33
Let’s navigate the storm together
34 34
Thank you!
Robert ter Waarbeek
Automotive Industry Manager (EMEA)
35 rterwaar@[Link]