


Expert Breakdown: Validating Freedom from Interference (FFI) between QM and ASIL-D
Architecture: Classic AUTOSAR R22-11, zero-heap design with static allocation only. No dynamic memory (MISRA Rule 21.3 compliant). Spatial isolation enforced via MPU regions per OS-Application. Temporal isolation via OsTaskExecutionBudget and timing protection. Communication via IOC with E2E Profile P11.
HSM Enforcement: Evita Full HSM, FW 3.1. SHE+ key isolation, secure boot verification chain, and hardware firewall. QM domain has no physical access to ASIL-D NVM, keys, or secure RAM. All crypto services routed through CSM -> Crypto Driver -> HSM. HSM acts as safety guardian, not just crypto accelerator.
HIL Validation: dSPACE SCALEXIO HIL. Fault injection campaign: 1000+ tests including pointer corruption, stack overflow, and MPU violation attempts from QM tasks. Result: 100% containment. No ASIL-D data corruption, no timing overrun. Measured safe-state transition: 8.7µs (FTTI Requirement: <10µs).
Conclusion: Full FFI achieved per ISO 26262-6 Annex D. Zero interference on memory, timing, and data exchange. Architecture ready for ASIL-D product audit.