Fully Fail-Operational Drive-by-Wire: When the Safe State Means Continuing to Drive

In traditional vehicle systems, a safety strategy may involve shutting down a malfunctioning function and returning control to the driver. But what happens when there is no longer a driver available as a fallback?

For autonomous and teleoperated vehicles, this changes a fundamental assumption of the safety architecture: the safe state can no longer simply mean “off.” Control over the vehicle’s movement must be maintained even after a fault occurs—at least until a safe state can be achieved. For the drive-by-wire-based control layer, this means that steering, braking, and propulsion must remain controllable even in the event of a fault. This is precisely where the architecture behind Safety-by-Wire® comes into play.

From Safety Objectives to Technical Architecture

Functional safety initially focuses on safety objectives. These describe which hazardous conditions must be prevented—for example, unintended steering movements, loss of braking function, or unintended propulsion.

To turn this into a real system, two translation steps are necessary. The functional safety concept defines which functions and safety mechanisms are required. The technical safety concept then translates these into concrete hardware and software architectures: sensors, computing paths, communication, power supply, diagnostics, and actuators.

This turns the safety objective into a central architectural question: What must be redundant to ensure that a single failure does not lead to a loss of vehicle control?

Redundancy must be consistent throughout

Two control units alone do not make a system fail-operational. If, for example, both share the same power supply, a critical communication path, or other common resources, a common failure path remains.

NX NextMotion therefore relies on a consistent, multi-redundant architecture. Physical separation encompasses two channels across the entire chain of operation—from computing and communication paths to power control and actuators. Both sides are designed to meet ASIL D requirements. In addition, the system features redundant sensor systems, continuous diagnostics, and redundant power paths. The goal is not merely to detect a fault. The system must be able to manage the fault and continue to perform safety-critical functions within defined performance limits and response times.

Degradation Instead of Shutdown

In this context, “fail-operational” does not mean that a vehicle continues to operate indefinitely and unchanged after every fault. A defined degradation concept is crucial. Depending on the fault condition, the architecture can switch from full performance to a limited operating state or initiate a maneuver that minimizes risk. Every transition must be specified and completed within the designated fault tolerance time.

The key difference from the traditional shutdown principle is that control over the vehicle’s movement is maintained. This is particularly crucial for autonomous and teleoperated vehicles. An abrupt shutdown of a safety-critical movement function can itself pose a hazard.

Fully Fail-Operational: Redundancy on Four Axes

However, even the term “fail-operational” leaves room for interpretation. Which function remains available after which failure, for how long, and with what level of performance? Arnold NextG therefore uses the term “Fully Fail-Operational” for NX NextMotion as a deliberately narrower working definition. This is not a new normative category, but rather a technically verifiable description of the architectural requirement.

Fully Fail-Operational considers redundancy along four axes of completeness:

  • Function: The primary safety-critical motion functions—steering, braking, and propulsion—are designed to be fail-operational.
  • Channel: Two physically separate ASIL-D channels map the safety-critical chain of action. The loss of one side must not result in the loss of function.
  • Control source: Autonomous driving systems, teleoperation, and human intervention can be accommodated within the same architecture. A deterministic arbitration mechanism determines which control path is valid.
  • Power: The power supply is also designed to be redundant and supplemented with a buffer source for defined degradation windows.

It is only the interplay of these four levels that defines the standard Arnold NextG associates with “Fully Fail-Operational.”

Why This Is Relevant for OEMs and Integrators

For OEMs and system integrators, it is therefore worthwhile to take a closer look at what the term “fail-operational” actually entails. Is only a single function redundant—or is the entire motion control system redundant? Are two channels truly independent, or do they share critical components? What happens if a power supply fails? Which control source takes over in the event of a fault? And what functionality is actually still available during a degradation state?

These questions determine whether redundancy exists merely at the component level or supports the entire safety-critical chain of operations. For a drive-by-wire platform designed to support autonomous, teleoperated, and manual vehicle control, this end-to-end redundancy becomes a critical architectural feature.

Conclusion: The safe state is control

With the elimination of the driver as a permanent fallback, the safety architecture undergoes a fundamental change. A safety-critical system must not simply cease to function after a failure if doing so would result in the loss of control over the vehicle.

Drive-by-wire must therefore do more than simply execute electronic commands for steering, braking, and propulsion. The control layer must be designed to keep these functions controllable even in the event of a failure.

At Arnold NextG, “Fully Fail-Operational” describes this requirement: Redundancy is not considered on a case-by-case basis, but rather across functions, channels, control sources, and power supplies. NX NextMotion thus translates the safety goals of Safety-by-Wire® into a concrete, multi-redundant, fail-operational system architecture. Because for autonomous and teleoperated mobility, safety does not simply mean coming to a standstill.

Safety means maintaining control.

WE CONTROL WHAT MOVES

Über die Arnold NextG GmbH

Über Arnold NextG:
Arnold NextG realisiert die Safety-by-Wire®-Technologie von morgen: das mehrfach redundante Zentralsteuergerät NX NextMotion ermöglicht eine ausfallsichere und individuelle Implementierung, fahrzeugplattform-unabhängig und weltweit einzigartig. Mit dem System können autonome Fahrzeugkonzepte sicher und nach den neuesten Hard- und Software- sowie Sicherheitsstandards umgesetzt werden, ebenso wie Remote-, Teleoperation- oder Platooning- Lösungen Als unabhängiger Vorausentwickler, Inkubator und Systemlieferant übernimmt Arnold NextG die Planung und Umsetzung – von der Vision bis zur Straßenzulassung. Mit der Straßenzulassung von NX NextMotion setzen wir den globalen Drive-by-Wire-Standard. www.arnoldnextg.de

About Arnold NextG:
Arnold NextG realizes the safety-by-wire® technology of tomorrow: The multi-redundant central control unit NX NextMotion enables a fail-operational and individual implementation, independent of the vehicle platform and unique worldwide. The system can be used to safely implement autonomous vehicle concepts in accordance with the latest hardware, software and safety standards, as well as remote control, teleoperation or platooning solutions. As an independent pre-developer, incubator and system supplier, Arnold NextG takes care of planning and implementation – from vision to road approval. With the road approval of NX NextMotion, we are setting the global drive-by-wire standard. www.arnoldnextg.com

Firmenkontakt und Herausgeber der Meldung:

Arnold NextG GmbH
Breite 3
72539 Pfronstetten-Aichelau
Telefon: +49 171 5340377
http://www.arnoldnextg.de

Ansprechpartner:
Anke Leuschke
Pressesprecherin
E-Mail: anke.leuschke@arnoldnextg.de
Für die oben stehende Story ist allein der jeweils angegebene Herausgeber (siehe Firmenkontakt oben) verantwortlich. Dieser ist in der Regel auch Urheber des Pressetextes, sowie der angehängten Bild-, Ton-, Video-, Medien- und Informationsmaterialien. Die United News Network GmbH übernimmt keine Haftung für die Korrektheit oder Vollständigkeit der dargestellten Meldung. Auch bei Übertragungsfehlern oder anderen Störungen haftet sie nur im Fall von Vorsatz oder grober Fahrlässigkeit. Die Nutzung von hier archivierten Informationen zur Eigeninformation und redaktionellen Weiterverarbeitung ist in der Regel kostenfrei. Bitte klären Sie vor einer Weiterverwendung urheberrechtliche Fragen mit dem angegebenen Herausgeber. Eine systematische Speicherung dieser Daten sowie die Verwendung auch von Teilen dieses Datenbankwerks sind nur mit schriftlicher Genehmigung durch die United News Network GmbH gestattet.

counterpixel