Articles | Open Access |

Evolving Safety Assurance and Cybersecurity Certification Frameworks for Autonomous and Software-Defined Automotive Systems: A Model-Driven and Regulatory Perspective

Jonathan Weiss , Department of Systems Engineering, University of Stuttgart, Germany

Abstract

The rapid transformation of automotive systems into highly autonomous, software-defined, and interconnected platforms has significantly challenged traditional paradigms of safety assurance and certification. This research investigates the evolution of safety and cybersecurity frameworks within the context of modern automotive and cyber-physical systems, emphasizing the need for open, adaptive, and model-driven approaches. Drawing upon a diverse body of literature encompassing safety certification challenges, regulatory frameworks such as ISO/SAE 21434 and United Nations cybersecurity regulations, and model-based architectural methodologies including EAST-ADL2, the study critically analyzes the limitations of conventional assurance methods. It further explores the integration of formal modeling techniques, automated safety analysis, and runtime fault tolerance mechanisms in addressing the complexity of autonomous vehicle systems. The methodology employs qualitative synthesis and case-oriented analytical frameworks to examine both theoretical and applied perspectives, including insights from software engineering case studies and focus group-based evaluations. The findings reveal that while existing standards provide a structured foundation for safety and cybersecurity, they struggle to accommodate the dynamic and evolving nature of software-defined vehicles. Model-driven development and automated compliance tools emerge as promising enablers of scalable and adaptive assurance processes. However, challenges persist in aligning regulatory requirements with real-time system behavior, ensuring interoperability across stakeholders, and maintaining assurance validity over continuous updates. The study concludes by proposing a holistic framework that integrates regulatory compliance, model-based engineering, and adaptive certification mechanisms to support the next generation of resilient automotive systems.

Keywords

Safety assurance, automotive cybersecurity, model-driven development, autonomous vehicles

References

Ruiz A., Sabetzfadeh M., Panaroni P., et al. Challenges for an open and evolutionary approach to safety assurance and certification of safety-critical systems. IEEE, 2011.

Runeson P., Höst M., Rainer A., Regnell B. Case Study Research in Software Engineering. Wiley, 2012.

Schneider F.B. Cybersecurity education in universities. IEEE Security and Privacy, 2013.

Smithson J. Using and analysing focus groups: limitations and possibilities. International Journal of Social Research Methodology, 2000.

Technical Committee ISO/IEC JTC 1/SC 27. ISO/IEC 27000:2018 Information technology — Security techniques — Information security management systems — Overview and vocabulary, 2018.

Technical Committee ISO/TC 22/SC 32. ISO/SAE 21434 Road vehicles — Cybersecurity engineering, 2021.

The 104th United States Congress. Health Insurance Portability and Accountability Act (HIPAA), 1996.

Ullah K.W., Ahmed A.S., Ylitalo J. Towards building an automated security compliance tool for the cloud. IEEE International Conference on Trust, Security and Privacy in Computing and Communications, 2013.

United Nations ECE/TRANS/WP.29. UN regulation no. 156 - uniform provisions concerning the approval of vehicles with regards to software update and software updates management system, 2021.

United Nations ECE/TRANS/WP.29. UN regulation no. 155 - uniform provisions concerning the approval of vehicles with regard to cyber security and cyber security management system, 2021.

Cuenot P., Frey P., Johansson R., Lönn H., Reiser M.-O., Servat D., Tavakoli Kolagari R., Chen D.J. Developing Automotive Products Using the EAST-ADL2, an AUTOSAR Compliant Architecture Description Language, 2008.

Törner F., Chen D.J., Johansson R., Lönn H., Törngren M. Supporting an Automotive Safety Case through Systematic Model Based Development - the EAST-ADL2 Approach. SAE Technical Paper, 2008.

International Electrotechnical Commission. Functional safety of electrical/electronic/programmable electronic safety-related systems - Part 0: Functional safety and IEC 61508, 2005.

Martin T., Chen D.J., Malvius D., Axelsson J. Model based development of automotive embedded systems. Automotive Embedded Systems Handbook, 2008.

Arnold A., Griffault A., Point G., Rauzy A. The Altarica formalism for describing concurrent systems. Fundamenta Informaticae, 2000.

Bozzano M., Villafiorita A., et al. ESACS: an integrated methodology for design and safety analysis of complex systems. European Safety and Reliability Conference, 2003.

Papadopoulos Y., Grante C. Evolving car designs using model-based automated safety analysis and optimization techniques. Journal of Systems and Software, 2005.

Adedjouma M., Pedroza G., Bannour B. Representative safety assessment of autonomous vehicle for public transportation. IEEE International Symposium on Real-Time Distributed Computing, 2018.

Adler R., Feth P., Schneider D. Safety engineering for autonomous vehicles. IEEE/IFIP International Conference on Dependable Systems and Networks Workshop, 2016.

Al-Sharman M., Murdoch D., Cao D., Lv C., Zweiri Y., Rayside D., Melek W. A sensorless state estimation for a safety-oriented cyber-physical system in urban driving: Deep learning approach. IEEE/CAA Journal of Automatica Sinica, 2021.

Abdul Salam Abdul Karim. (2023). Fault-Tolerant Dual-Core Lockstep Architecture for Automotive Zonal Controllers Using NXP S32G Processors. International Journal of Intelligent Systems and Applications in Engineering, 11(11s), 877-885. Retrieved from https://ijisae.org/index.php/IJISAE/article/view/7749

Article Statistics

Copyright License

Download Citations

How to Cite

Jonathan Weiss. (2025). Evolving Safety Assurance and Cybersecurity Certification Frameworks for Autonomous and Software-Defined Automotive Systems: A Model-Driven and Regulatory Perspective. International Journal Of Management And Economics Fundamental, 5(10), 90–94. Retrieved from https://theusajournals.com/index.php/ijmef/article/view/9642