| ISO |
13209-2 |
Ed. 2 |
Road vehicles — Open Test sequence eXchange format (OTX) — Part 2: Core data model specification and requirements |
This document defines the OTX core requirements and data model specifications.
The requirements are derived from the use cases described in ISO 13209-1. They are listed in the requirements section.
The data model specification aims at an exhaustive definition of all OTX core features implemented to satisfy the core requirements. Since OTX is designed for describing test sequences, which themselves represent a kind of program, the core data model follows the basic concepts common to most programming languages.
Thus, this document establishes rules for syntactical entities like parameterised procedures, constant and variable declarations, data types, basic arithmetic, logic and string operations, flow control statements like loop, branch or return, simple statements like assignment or procedure call as well as exception handling mechanisms. Each of these syntactical entities is accompanied by semantic rules which determine how OTX documents are interpreted. The syntax rules are provided by UML class diagrams and XML schemas, whereas the semantics are given by UML activity diagrams and prose definitions.
With respect to documentation use cases, special attention is paid to defining a specification/realisation concept (which allows for “hybrid” test sequences: human readable test sequences that are at the same time machine-readable) and so-called floating comments (which can refer to more than one node of the sequence).
The core data model does not define any statements, expressions or data types that are dependent on a specific area of application.
For the convenience of the user, the ISO 13209-2 OTX XML schema definition file (XSD) is published alongside this document.
|
2022-07-01 |
Published |
Testing, Verification & Validation |
Link |
| ISO |
PAS 11585 |
Ed. 1 |
Road vehicles — Partial driving automation — Technical characteristics of conditional hands-free driving systems |
This document provides technical characteristics of partial driving automation system according to ISO/SAE PAS 22736 and associated control strategies enabling hands-free driving. These technical characteristics, together with an appropriate operational design domain enable the proper usage of such partial driving automation systems which is supervised by drivers. This document does not address performance limits, verification and validation of such systems.
|
2023-09-01 |
Published |
AD/ADAS functions |
Link |
| ISO |
TS 17691 |
Ed. 1 |
Road vehicles — Principles for human remote support of automated systems |
This document presents a model of human capabilities and limitations for remote support of automated driving systems and associated principles that facilitate safe interactions. Topics include work hand-over, perception and actuation, and passenger management. The focus of this document is the roles of remote monitor and remote assistant where they are beyond the line of sight of the vehicle. The role of remote driver is not included however, the model and principles could be extended to other remote roles with consideration of the additional human requirements. The principles are written generally to support system development and provide guidance on how to evaluate human-automation-environment system performance without specifying any particular implementation. This document is limited to low-speed automated driving. Driver training, licensing, and fitness are not within the scope of this document.
|
|
Under Development |
Human Interaction |
Link |
| ISO |
PAS 8800 |
|
Road Vehicles — Safety and artificial intelligence |
This document defines safety-related properties and risk factors impacting the insufficient performance and malfunctioning behaviour of Artificial Intelligence (AI) within a road vehicle context. It describes a framework that addresses all phases of the development and deployment lifecycle. This includes the derivation of suitable safety requirements on the function, considerations related to data quality and completeness, architectural measures for the control and mitigation of failures, tools used to support AI, verification and validation techniques as well as the evidence required to support an assurance argument for the overall safety of the system.
|
|
Under Development |
Safety |
Link |
| ISO |
/TS 5083 |
Ed. 1 |
Road vehicles — Safety and cybersecurity for automated driving systems — Design, verification and validation |
This document describes steps for developing and validating automated driving systems based on basic safety principles derived from worldwide applicable publications. It considers safety- and cybersecurity-by-design, as well as verification and validation methods for automated driving systems focused on vehicles with level 3 and level 4 features according to SAE J3016:2018. In addition, it outlines cybersecurity considerations intersecting with objectives for safety of automated driving systems.
|
2025-04-01 |
Published |
Cybersecurity, Safety |
Link |
| ISO |
TS 5083 |
|
Road vehicles — Safety for automated driving systems — Design, verification and validation |
This document provides an overview and guidance of the steps for developing and validating an automated vehicle equipped with a safe automated driving system. The approach is based on top level safety goals and basic principles derived from worldwide applicable publications. It considers safety by design, verification and validation methods for automated driving focused on SAE level 3 and level 4 vehicles according to ISO/SAE PAS 22736. In addition, it outlines cybersecurity considerations throughout all described steps.
The document is intended to be applied to road vehicles (incl. trucks and busses, i.e. road vehicles > 3,5to) excluding motorcycles.
|
|
Under Development |
Safety |
Link |
| ISO |
21448 |
Ed. 1 |
Road vehicles — Safety of the intended functionality |
This document provides a general argument framework and guidance on measures to ensure the safety of the intended functionality (SOTIF), which is the absence of unreasonable risk due to a hazard caused by functional insufficiencies, i.e.:
a) the insufficiencies of specification of the intended functionality at the vehicle level; or
b) the insufficiencies of specification or performance insufficiencies in the implementation of electric and/or electronic (E/E) elements in the system.
This document provides guidance on the applicable design, verification and validation measures, as well as activities during the operation phase, that are needed to achieve and maintain the SOTIF.
This document is applicable to intended functionalities where proper situational awareness is essential to safety and where such situational awareness is derived from complex sensors and processing algorithms, especially functionalities of emergency intervention systems and systems having levels of driving automation from 1 to 5[2].
This document is applicable to intended functionalities that include one or more E/E systems installed in series production road vehicles, excluding mopeds.
Reasonably foreseeable misuse is in the scope of this document. In addition, operation or assistance of a vehicle by a remote user or communication with a back office that can affect vehicle decision making is in scope of this document when it can lead to safety hazards.
This document does not apply to:
— faults covered by the ISO 26262 series;
— cybersecurity threats;
— hazards directly caused by the system technology (e.g. eye damage from the beam of a lidar);
— hazards related to electric shock, fire, smoke, heat, radiation, toxicity, flammability, reactivity, release of energy and similar hazards, unless directly caused by the intended functionality of E/E systems; and
— deliberate actions that clearly violate the system’s intended use, (which are considered feature abuse).
This document is not intended for functions of existing systems for which well-established and well-trusted design, verification and validation (V&V) measures exist (e.g. dynamic stability control systems, airbags).
|
2022-06-01 |
Published |
Management/ Engineering Standards, Safety |
Link |
| ISO |
24650 |
|
Road Vehicles — Sensors for automated driving under adverse weather conditions — Assessment of the cleaning system |
This document proposes a standard test procedure, in order to assess the efficiency of cleaning systems for sensors. It addresses the following conditions:
— Dust / Mud
— Frost / Snow
— Mist / Rain
There is no preferred cleaning system described as this document is intended to be technologically neutral and performance oriented for the cleaning system and not for the sensor detection. For this reason, the assessment method is fully independent from the sensor technology and from the data generated by the sensor itself during use.
The scope is entirely focussed on the cleanliness of the front sensor surface.
This document does not address continuous contamination, such as continuous rain, as the efficiency of the cleaning system could only be assessed from the interior of the sensor in those situations.
For a non-continuous contamination, this document includes intermittent cleaning considered as a succession of periodically launched cleaning cycles as defined in 3.2.
This document does not include specific day/night time conditions during the test as they have no impact on the results and the mean of cleaning remains similar. However, a better cleaning efficiency may be sought for the night.
This document does not include contamination with insects due to the difficulty to get a homogeneous application.
The cleaning system efficiency must be related to the tested sensor.
This document does not provide any direct indicator co-related to the sensor performance but limited to the evaluation in terms of apparent visual removal of the contaminant in terms of superficial coverage.
This document does not include evaluation on the preventive countermeasure taken from its installation design point of view. Aerodynamic design affect how mud sprayed out from running vehicle or rain droplet could reach and build-up onto sensor frontal protection layer. Countermeasure design is out of scope of this document.
Note - Work item deleted after DIS stage
|
|
Deleted |
Testing, Verification & Validation |
Link |
| ISO |
24089 |
Ed. 1 |
Road vehicles — Software update engineering |
This document specifies requirements and recommendations for software update engineering for road vehicles on both the organizational and the project level.
This document is applicable to road vehicles whose software can be updated.
The requirements and recommendations in this document apply to vehicles, vehicle systems, ECUs, infrastructure, and the assembly and deployment of software update packages after the initial development.
This document is applicable to organizations involved in software update engineering for road vehicles. Such organizations can include vehicle manufacturers, suppliers, and their subsidiaries or partners.
This document establishes a common understanding for communicating and managing activities and responsibilities among organizations and related parties.
The development of software for vehicle functions, except for software update engineering, is outside the scope of this document.
Finally, this document does not prescribe specific technologies or solutions for software update engineering.
|
2023-02-01 |
Published |
Management/ Engineering Standards |
Link |
| ISO |
19206-1 |
Ed. 1 |
Road vehicles — Test devices for target vehicles, vulnerable road users and other objects, for assessment of active safety functions — Part 1: Requirements for passenger vehicle rear-end targets |
This document specifies performance requirements for surrogate targets used to assess the system detection and activation performance of active safety systems.
This document specifies the properties of a vehicle target that will allow it to represent a passenger vehicle in terms of size, shape, reflection properties, etc. for testing purposes. The document addresses the detection requirements for a vehicle target in terms of sensing technologies commonly in use at the time of publication of this document, and where possible, anticipated future sensing technologies. It also addresses methodologies to verify the target response properties to these sensors, as well as performance requirements for the target carrier.
This document specifies the properties of the vehicle target for simulation of rear-end scenarios, with overlap greater than 50 %. The specifications of vehicle targets in this document are intended to address current and anticipated test protocols related to safety critical events in which the subject vehicle approaches a stopped, braking or slower moving (target) vehicle from behind and in the forward path of the subject vehicle.
This document does not address the test procedures in terms of speeds, positions, or timing of events. Performance criteria for the active safety system are also not addressed.
|
2018-12-01 |
Published |
Testing, Verification & Validation |
Link |