{"id":1342,"date":"2013-10-11T10:19:46","date_gmt":"2013-10-11T17:19:46","guid":{"rendered":"https:\/\/blogs.plm.automation.siemens.com\/t5\/Polarion-Blog\/Safety-programming-and-distributed-development-required-by-ISO\/ba-p\/380783"},"modified":"2026-03-26T05:37:39","modified_gmt":"2026-03-26T09:37:39","slug":"safety-programming-and-distributed-development-required-by-iso-26262-part-3","status":"publish","type":"post","link":"https:\/\/blogs.sw.siemens.com\/polarion\/safety-programming-and-distributed-development-required-by-iso-26262-part-3\/","title":{"rendered":"Safety programming and distributed development required by ISO 26262 (Part 3)"},"content":{"rendered":"<p><SPAN style=\"font-style: italic;\">By Takao Futagami, TOYO Corporation<\/SPAN><\/p>\n<p><A href=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/TOYO-Corp.jpg\" rel=\"nofollow noopener noreferrer\"><IMG class=\"alignleft size-thumbnail wp-image-3965\" alt=\"TOYO Corporation\" src=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/TOYO-Corp-150x150.jpg\" width=\"150\" height=\"150\" \/><\/A><br \/>\n<H2>Distributed development brings better outcome<\/H2><br \/>\nThe development scale for an instrument like REINA-11 (discussed in <A href=\"http:\/\/blog.polarion.com\/archives\/3977\" rel=\"nofollow noopener noreferrer\">Part 2<\/A>) is small, and the specifications are simple &#8211; you could imagine this more easily if I say, the development scale is equal to that of a small-scale body ECU. So, in the design stage, you can achieve a sufficient ASIL if you carry out appropriate state analysis and actual time modeling using three fundamentals <EM>RateMonotonicActivation<\/EM>, <EM>ReactionByEvent<\/EM> and <EM>RunToCompletion<\/EM>.<br \/>\n<!--more--><br \/>\nOn the other hand, the spec changes and program enhancements continuously occur based on the experiment results in the development phase, and many variations are rapidly derived for various destinations in the operation phase. For this reason, the safety-oriented detail design on the programming stage is important. The configuration management and traceability requirements specified in ISO26262 are required to be carried out at the same level as the safety programming. The trace and configuration management can be manually conducted in the case of a small-scale development at one location, but doing them manually could plant new defects in products when the development is carried out at several locations with large time differences. To be more specific, it is usually thought risky, for instance, to design the sensor function of a product in Tokyo and do the programming in Fukuoka (a large city in Kyushu island of Japan) and the communication function the other way around.<\/p>\n<p><!--more--><\/p>\n<p>However, if it becomes possible to overcome the disadvantages of multi-location development by utilizing networks and tools, the development freedom and the product safety will both improve since skilled people can participate in the development regardless of their work places. In order to realize the safety programming conforming to ISO 26262, it is desirable that the quality evaluation incorporating <A href=\"http:\/\/en.wikipedia.org\/wiki\/MISRA_C\" rel=\"nofollow noopener noreferrer\">MISRA-C<\/A> is automated. This is because the declaration by a programmer to the effect that &#8220;I did the coding in compliance with MISRA-C as much as I can&#8221; is not regarded as enough compliance with ASIL. At many development sites, engineers having safety programming skills are in short supply, and just realizing the bottom line of the state-of-the-art development (e.g. code peer review) mentioned in ISO 26262 is difficult. Although this shortage of human resources was made up by a large number of execution tests in the past, from the viewpoint of ISO 26262, this method cannot fully guarantee the code safety. Any ASIL has a review mechanism, and the review evidence is required to be recorded. The companies having enough skilled engineers to spare for such time-consuming tasks are quite rare.<\/p>\n<p><A href=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/ISO26262-Distribution-Toyo.png\" rel=\"nofollow noopener noreferrer\"><IMG class=\"alignright size-medium wp-image-4038\" alt=\"Network topography illuatration\" src=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/ISO26262-Distribution-Toyo-300x258.png\" width=\"300\" height=\"258\" \/><\/A>In order to automate this troublesome process, we have prepared a real-time quality evaluation environment. In this environment, anyone in the development team can monitor the program quality in real time on a daily basis and can exchange opinions online with their manager for&nbsp; improvement.&nbsp; It is natural that the requirements for development change due to the results of the performance\/operation tests at the system level \u2013 the requirements and design conditions also change during the development period.&nbsp; Adding traceability to these changes is also time-consuming for engineers in the field.&nbsp; We therefore have also implemented, in the development of REINA-11 source code, a mechanism for managing these changes in a coherent way.&nbsp; With this mechanism, it became possible to trace which design\/source code was revised\/tested from such changes as real-time requirement changes for the controllability measurement and calibration process changes.<\/p>\n<p>Having concluded in developing&nbsp; REINA-11 that it is appropriate to put a well-known OA tool in the frontend and put a full-fledged configuration management tool on the backbone, we have put together a server-client system with commercial tools and open source tools.<br \/>\n<H3>What we got<\/H3><br \/>\nUnder this development environment, we outsourced software development to a programmer who had skills for the embedded programming but not for the MISRA-C programming. The figure below shows the metric change in the MISRA-C quality of the code.<\/p>\n<p><DIV style=\"background-color: #F9F9F9;border: 1px solid #CCCCCC;padding: 3px;font: 11px\/1.4em Arial, sans-serif;margin: 0.5em 0pt 0.5em 0.8em;width:300px;\"><A href=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/MISRA-C.jpg\" rel=\"nofollow noopener noreferrer\"><IMG class=\"size-medium wp-image-3993\" alt=\"Graph showing MISRA-C metric improvement\" src=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/MISRA-C-300x189.jpg\" width=\"300\" height=\"189\" \/><\/A><DIV style=\"text-align:center;\"> <SPAN style=\"font-style: italic;\">Graph showing MISRA-C metric improvement. Number of warnings are reduced by skillful engineer lives in remote location<\/SPAN><\/DIV> <\/DIV><\/p>\n<p>It has become clear that it is possible to perform effective distributed development in terms of both the cost and the concurrent development, when a programmer who is not familiar with MISRA-C but can develop programs of a certain quality level works together with a programmer acquainted with MISRA-C.<\/p>\n<p>The distributed development has been done in the multi-country development and the large-scale development. However, it was difficult to benefit from the distributed development in the past due to the costs required for the server operation and for the specialists to prepare tool environments. Now, it has become clear that even small-scale teams can use operable distributed environments thanks to today\u2019s highly-advanced ICT environment.<\/p>\n<p>We are thinking of providing distributed development environments for ISO 26262 compliance as our solution in the future in addition to REINA-11.<\/p>\n<p><SPAN style=\"font-style: italic;\">To be continued<\/SPAN><\/p>\n<p><HR \/><\/p>\n<p><DIV style=\"font-style: italic; margin-bottom: 18px;\">Editor&#8217;s Note:<br \/>\nTakao Futagami specializes in risk analysis at TOYO Corporation, Polarion Software&#8217;s country partner for Japan<\/DIV><\/p>\n<p><HR \/><\/p>\n<p><DIV style=\"margin: 26px 0;\" align=\"center\"><A href=\"http:\/\/www.polarion.com\/company\/events\/webinarondemand.php?title=Hazard+Analysis+and+Risk+Assessment+According+to+ISO+26262\" rel=\"nofollow noopener noreferrer\"><IMG class=\"aligncenter size-full wp-image-4032\" alt=\"Free webinar banner image\" src=\"http:\/\/community.plm.automation.siemens.com\/legacyfs\/online\/siemensplm_blogs\/2013\/09\/Hazard-Risk-Analysis-Accord.png\" width=\"603\" height=\"204\" \/><\/A><\/DIV><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Takao Futagami, TOYO Corporation <\/p>\n<p> Distributed development brings better outcome<br \/>\nThe development scale for an instrument like REINA-11 (discussed in Part 2) is small, and the specifications a&#8230;<\/p>\n","protected":false},"author":57253,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spanish_translation":"","french_translation":"","german_translation":"","italian_translation":"","polish_translation":"","japanese_translation":"","chinese_translation":"","footnotes":""},"categories":[1],"tags":[],"industry":[],"product":[],"coauthors":[],"class_list":["post-1342","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/posts\/1342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/users\/57253"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/comments?post=1342"}],"version-history":[{"count":1,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/posts\/1342\/revisions"}],"predecessor-version":[{"id":1343,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/posts\/1342\/revisions\/1343"}],"wp:attachment":[{"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/media?parent=1342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/categories?post=1342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/tags?post=1342"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/industry?post=1342"},{"taxonomy":"product","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/product?post=1342"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.sw.siemens.com\/polarion\/wp-json\/wp\/v2\/coauthors?post=1342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}