Skip to main content
QUICK REVIEW

[Paper Review] A Taxonomy to Unify Fault Tolerance Regimes for Automotive Systems: Defining Fail-Operational, Fail-Degraded, and Fail-Safe

Torben Stolte, Stefan Ackermann|arXiv (Cornell University)|Jun 21, 2021
Safety Systems Engineering in AutonomyEngineering54 references42 citations
TL;DR

This paper proposes a standardized taxonomy to unify the definitions of fault tolerance regimes—fail-operational, fail-degraded, and fail-safe—in automotive systems. Based on ISO 26262 and systems engineering principles, it introduces four criteria—functionality, nominal and available performance, and a refined safe state definition—to enable consistent classification across hierarchical system levels, verified through two automotive examples.

ABSTRACT

This paper presents a taxonomy that allows defining the fault tolerance regimes fail-operational, fail-degraded, and fail-safe in the context of automotive systems. Fault tolerance regimes such as these are widely used in recent publications related to automated driving, yet without definitions. This largely holds true for automotive safety standards, too. We show that fault tolerance regimes defined in scientific publications related to the automotive domain are partially ambiguous as well as taxonomically unrelated. The presented taxonomy is based on terminology stemming from ISO 26262 as well as from systems engineering. It uses four criteria to distinguish fault tolerance regimes. In addition to fail-operational, fail-degraded, and fail-safe, the core terminology consists of operational and fail-unsafe. These terms are supported by definitions of available performance, nominal performance, functionality, and a concise definition of the safe state. For verification, we show by means of two examples from the automotive domain that the taxonomy can be applied to hierarchical systems of different complexity.

Motivation & Objective

  • Address the lack of standardized definitions for fault tolerance regimes in automotive safety literature and standards.
  • Resolve inconsistencies and ambiguities in existing definitions of fail-operational, fail-degraded, and fail-safe across publications and standards.
  • Establish a coherent, verifiable taxonomy applicable across different system levels in automotive systems, from component to vehicle level.
  • Provide clear, formal definitions for core terms including functionality, nominal performance, available performance, and safe state to support safety argumentation.
  • Enable consistent communication and specification in interdisciplinary development projects and safety-critical systems, especially for SAE Level 4+ automated vehicles.

Proposed method

  • Develop a taxonomy based on terminology from ISO 26262 and systems engineering, using four key criteria: functionality, nominal performance, available performance, and safe state.
  • Define the safe state as a condition where no harm results from system behavior, resolving inconsistencies in prior standards like ISO 26262 and ISO/TR 4804.
  • Introduce the terms operational and fail-unsafe as foundational concepts to distinguish fault tolerance regimes based on functionality and safety outcomes.
  • Apply the taxonomy to two automotive examples: a steer-by-wire system and a vehicle control system, demonstrating its use at different architectural levels.
  • Verify the taxonomy’s consistency and applicability by analyzing fault combinations and system behavior under defined fault conditions.
  • Ensure compatibility with existing safety standards, particularly ISO 26262, while extending applicability beyond vehicle-level analysis to subsystems and components.

Experimental results

Research questions

  • RQ1How can fault tolerance regimes such as fail-operational, fail-degraded, and fail-safe be consistently defined in the context of automotive systems to eliminate ambiguity?
  • RQ2What criteria are necessary to distinguish between fault tolerance regimes in a way that supports safety engineering and verification?
  • RQ3How can the concept of the safe state be formally and unambiguously defined to resolve contradictions in existing standards?
  • RQ4To what extent can the proposed taxonomy be applied across different system levels, from components to full vehicles?
  • RQ5Can the taxonomy be used to evaluate systems under multiple concurrent faults, and how does it support safety argumentation for SAE Level 4+ automated vehicles?

Key findings

  • The paper establishes a formal taxonomy that distinguishes fault tolerance regimes using four criteria: functionality, nominal performance, available performance, and a refined definition of the safe state.
  • The safe state is defined as a condition where no harm results from system behavior, resolving inconsistencies found in ISO 26262, ISO/DIS 21448, and ISO/TR 4804.
  • The taxonomy enables consistent classification of systems under specific fault combinations, ensuring that fault tolerance regimes are not applied generically but contextually.
  • The taxonomy is verified through two automotive examples—steer-by-wire and vehicle control systems—demonstrating its applicability at different system levels.
  • The proposed definitions are compatible with ISO 26262 and ISO/TR 4804 but extend beyond their scope by enabling application at subsystem and component levels.
  • The taxonomy supports safety argumentation for SAE Level 4+ automated vehicles by eliminating the reliance on human fallback and formalizing fault tolerance behavior.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.