ISO PAS 21448:2019 pdf free.Road vehicles一Safety of the intended functionality
The functional and system specification provides an adequate understanding of the system and its functionality so that the activities in subsequent phases can be performed. This includes a list of all performance limitations and their countermeasures. Some limitations and countermeasures are known and documented before the SOTIF related process begins while others are revealed as a result of the SOTIF activities.
Each iteration of the SOTIF related activity (Figure 9) can result in engineering activity and an update to this specification. Each iteration relies on this specification being up to date, such that it reflects all information discovered in previous iterations. Cooperation between all development parties (OEM, Tier1,TierN) is used to discover limitations and develop countermeasures during all development phases.
The functional and system specification lists performance limitations of every individual mechanisms,algorithms, or elements related to the safety of the intended functionality. The system is thus designed considering such limitations and ensuring that countermeasures are taken to mitigate their effect on the overall system if needed.
As the SOTIF activities identify new limitations and consequences (Clause 7), and define new mitigation measures (Clause 8), the functional and system specification is updated. This will ensure that all the required work is done both for closure of previous iterations, and at the beginning of the next iteration.
Specifically, the design includes considerations of system limitations that can result in erroneous subsystem output values being reported with high confidence (low confidence values might be ignored by design) and which can lead to potentially hazardous behaviour. Examples of limitations include incorrect classification, incorrect measurements, incorrect tracking, misdetection, ghosts, incorrect target selection, incorrect kinematic estimation, etc.
The final system architecture achieves robustness by considering every component, technology and system limitation. The system development is based on the assumption made about the limitations in design. Implementing measures to ensure SOTIF and integrating them into the functional and system specification, decreases the sizes of Area 2 and Area 3, and increases overall robustness by increasing the size of Area 1. Area 3 testing is used to uncover new issues only when the countermeasures, with respect to the original system design, are incomplete or not applicable to newly introduced use cases.ISO PAS 21448 pdf download.

