[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85586-en":3,"doc-seo-85586-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85586,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","Shedding Light onto Safety Integrity Level and Basic Software Constraints in a Real-World Automotive Application","Automotive electronic control units (ECUs) are highly complex embedded systems where cause–effect chains connect sensor inputs to actuator outputs. Beyond timing and data age, safety integrity level (SIL) strongly constrains function colocation, task allocation, and memory isolation to protect safety-critical behavior. AUTOSAR basic software (BSW)—operating system, runtime environment, communication, and diagnostics—adds overhead whose impact depends on SIL and task characteristics. A real-world case study introduces the Driverator Framework to generate industrially realistic application instances, including SIL classifications, BSW overheads, and memory consumption.","arXiv :2605 .04837v 3 [ cs . SE] 11 Jul 2026  \n1  \nShedding Light onto Safety Integrity Level and Basic Software Constraints in a Real-World Automotive Application: Case Study with Driverator Framework  \nTobias Denzinger \\# CARIAD SE, Ingolstadt, Germany Matthias Becker \\#   \nKTH Royal Institute of Technology Stockholm, Sweden Peter Ulbrich \\#   \nTechnische Universität Dortmund, Germany  \n~~ Abstract ~~  \nAutomotive electronic control units (ECUs) constitute highly complex embedded systems comprising hundreds of functions, numerous software components, and multiple mutually dependent tasks. A common architectural pattern in such systems is represented by cause–effect chains. While existing research has extensively addressed the temporal analysis and optimization of these chains—particularly with respect to data age and reaction time—other non-functional properties have received comparatively limited attention. Among these properties, the safety integrity level (SIL) plays a central role in system design, as it directly constrains task allocation and colocation decisions. Inappropriate sharing of functions or the interleaving of tasks with different safety classifications may jeopardize the integrity of safety-critical functionality. Moreover, AUTOSAR basic software (BSW), including  \nthe operating system, runtime environment, communication services, and diagnostic components, introduces additional design complexity that depends on task characteristics and SIL classifications. Memory requirements further intensify this challenge, since heterogeneous memory architecturesand SIL-dependent constraints impose strict limitations on feasible task mappings. This case study provides a detailed characterization of a real-world automotive application, with particular emphasis on SIL constraints, AUTOSAR BSW impact, and memory requirements. We introduce the Driverator Framework, which enables researchers to generate application instances that reflect the characteristics of realistic industrial systems. Unlike existing case studies, Driverator incorporates additional systemrelevant aspects, including SIL classifications, basic software overheads, and memory consumption.  \nTool availability. The Driverator tool and accompanying case-study material are archived as [5] at [https://doi.org/10.17877/TUDODATA-2026-MOR12ARE](https://doi.org/10.17877/TUDODATA-2026-MOR12ARE).  \n 1  Introduction  \nIn recent years, automotive electronic control units (ECUs) have undergone a substantial increase in complexity, driven by the integration of multiple applications, advanced driver-assistance functions, and the stringent architectural requirements imposed by functional safety standards such as ISO 26262 [7] . Modern automotive ECUs typically integrate tens to hundreds of interconnected software components (SW-Cs), whose design is constrained by non-functional requirements, including timing, memory consumption, and, in particular, Safety Integrity Levels (SILs) . SIL classifications have a direct impact on architectural design decisions, as they impose strict constraints on function colocation, task allocation, and memory isolation. These constraints become especially relevant in heterogeneous hardware architectures, where safety properties may differ across processing cores and memory regions. An inappropriate synthesis or allocation of tasks with different SIL classifications can compromise system integrity, resulting in safety risks as well as architectural inefficiencies.  \nAutomotive systems are further characterized by their reliance on standardized software platforms such as AUTOSAR [2] . AUTOSAR provides basic software (BSW) services, including  \n2 Case Study with Driverator Framework  \nFigure 1 Extraction of respective application and basic software characteristics according to the highlighted V-model phases.  \noperating systems, runtime environments (RTEs), communication stacks, and diagnostic services. While these components constitute essential ","cbCaiu1wbyayoO4O","https://ap.wps.com/l/cbCaiu1wbyayoO4O","pdf",931941,2,1,11,"English","en",105,"# Introduction\n# Case Study with Driverator Framework","[{\"question\":\"How do safety integrity levels (SIL) influence ECU software architecture decisions?\",\"answer\":\"SIL classifications constrain function colocation and task allocation while also requiring memory isolation. Incorrect sharing or interleaving across different SILs can threaten safety integrity and cause architectural inefficiencies.\"},{\"question\":\"What role does AUTOSAR basic software (BSW) play in meeting SIL and resource constraints?\",\"answer\":\"AUTOSAR BSW components such as the operating system, RTE, communication stacks, and diagnostics contribute overhead and complexity. Their overhead depends on functional and non-functional properties, creating interdependence between safety requirements and system performance.\"},{\"question\":\"What is the purpose of the Driverator Framework in the presented case study?\",\"answer\":\"Driverator enables researchers to generate application instances reflecting realistic industrial systems. It explicitly incorporates SIL classifications, basic software overheads, and memory consumption, distinguishing it from earlier case-study approaches.\"}]",1784204761,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"shedding-light-onto-safety-integrity-level-and-basic-software-constraints-in-a-real-world-automotive-application","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/shedding-light-onto-safety-integrity-level-and-basic-software-constraints-in-a-real-world-automotive-application/85586/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"How do safety integrity levels (SIL) influence ECU software architecture decisions?","Question",{"text":75,"@type":76},"SIL classifications constrain function colocation and task allocation while also requiring memory isolation. Incorrect sharing or interleaving across different SILs can threaten safety integrity and cause architectural inefficiencies.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What role does AUTOSAR basic software (BSW) play in meeting SIL and resource constraints?",{"text":80,"@type":76},"AUTOSAR BSW components such as the operating system, RTE, communication stacks, and diagnostics contribute overhead and complexity. Their overhead depends on functional and non-functional properties, creating interdependence between safety requirements and system performance.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the purpose of the Driverator Framework in the presented case study?",{"text":84,"@type":76},"Driverator enables researchers to generate application instances reflecting realistic industrial systems. It explicitly incorporates SIL classifications, basic software overheads, and memory consumption, distinguishing it from earlier case-study approaches.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]