[gtranslate]

Designing an AUTOSAR RTE Platform for ASIL-D Complianceon Infineon AURIX™ TC389

Requisimus  |  Automotive Embedded Software  |  Functional Safety  —  July 15, 2026  |  9 min read

ASIL-D30+40%TC389
ISO 26262 Safety Integrity LevelAUTOSAR Software Components IntegratedReduction in Integration EffortInfineon AURIX Multicore MCU Platform

Project Details

PlatformAUTOSAR Classic Platform
MCUInfineon AURIX™ TC389 (3× TriCore + HSM)
Safety LevelISO 26262 ASIL-D
SWCs Integrated30+
DomainPowertrain / Functional Safety

The Challenge

As modern vehicles become increasingly software-defined, OEMs and Tier-1 suppliers require embedded platforms that deliver deterministic performance, functional safety, and long-term scalability. One global automotive customer approached our engineering team to design and integrate an AUTOSAR Run-Time Environment (RTE) for an ASIL-D safety application running on the Infineon AURIX™ TC389 multicore microcontroller.

The objective was to create a robust software architecture meeting stringent ISO 26262 ASIL-D requirements while providing a reusable platform for future vehicle programmes — including powertrain, chassis, ADAS, and domain controllers.

Key Requirements

  • ASIL-D compliant software architecture fully aligned with ISO 26262:2018
  • Deterministic communication between AUTOSAR Software Components (SWCs) via port-based RTE interfaces
  • Reliable multicore execution on the TC389 with task partitioning, core affinity, and MPU-enforced spatial isolation
  • Efficient integration with Basic Software (BSW), MCAL, and AUTOSAR OS
  • High software quality with complete traceability, verification, and validation evidence
  • Reduced integration effort for multiple ECU variants across vehicle programmes

In addition, the platform needed to satisfy demanding timing constraints while maintaining maintainability and long-term scalability for future software-defined vehicle initiatives.

AUTOSAR Platform Architecture

The diagram above shows the Safety RTE data flow between AUTOSAR Software Components (SWCs) and the Infineon TC389 MCU, with End-to-End (E2E) protection implemented in the CDD module.

Complete TX (solid arrows) and RX (dashed arrows) data flow. The CDD in ASIL memory implements E2E protection on every Safety PDU: CRC and BZ (Alive Counter) are added on TX and verified on RX using AUTOSAR E2E Profile 2 / Profile 5, ensuring ISO 26262 ASIL-D communication fault detection across all CAN and Ethernet interfaces.

Solution & Engineering Activities

1. AUTOSAR Software Component Architecture Design

Defined the full SWC architecture including port interfaces, data types, and inter-component communication patterns. Applied AUTOSAR port-based design to achieve clean separation between application logic and infrastructure — a foundation for ASIL-D compliance and long-term reuse across vehicle programmes.

2. RTE Configuration & Integration

Configured the Run-Time Environment using the AUTOSAR toolchain, defining Runnables, trigger conditions, and data mapping for 30+ SWCs. Implemented Sender/Receiver and Client/Server communication patterns with explicit E2E protection to satisfy ISO 26262 safety communication requirements at the SWC interface level.

3. Multicore Task Mapping & OS Configuration (TC389)

Mapped Runnables to AUTOSAR OS tasks across the three TriCore cores of the TC389 MCU. Defined ASIL-D and QM partitions using the TC389’s hardware Memory Protection Unit (MPU) to achieve spatial isolation between safety-critical and quality-managed software. Configured lockstep operation for safety-critical cores and fine-tuned the schedule table for deterministic timing behaviour.

4. BSW & MCAL Integration

Integrated and configured all required BSW modules: Communication Stack (COM, PDUR, CANIF), Diagnostics (DCM, DEM, FIM), Memory Services (NvM, WdgM, CRC), and AUTOSAR OS with SchM. Provided MCAL drivers generated from the TC389 hardware description for GPIO, ADC, SPI, CAN, Ethernet, and FlexRay peripherals — abstracting all hardware register access from application software. The End-to-End (E2E) Protection Library was integrated and configured across all Safety PDU transmission and reception paths. E2E profiles (Profile 2 / Profile 5) were applied at the AUTOSAR COM layer to protect safety-relevant signals against data corruption, message loss, and out-of-sequence delivery.

5. Safety Verification, Testing & Traceability

Executed static analysis (MISRA C), unit testing, and integration testing aligned to ASPICE SWE.4–SWE.6. Produced complete software safety documentation including the Software Safety Plan, FMEA, DFMEA, and requirements traceability matrix — providing the safety evidence required for ISO 26262 ASIL-D assessment by the customer’s functional safety assessor.

Business Impact

Accelerated Platform Integration Delivered a validated, production-ready AUTOSAR RTE platform ahead of programme milestones, enabling immediate application software integration.40% Reduction in Integration Effort Reusable SWC interfaces, standardised RTE configuration, and documented BSW templates reduced effort for subsequent ECU variants by 40%.
ASIL-D Compliance Foundation Complete safety evidence package — traceability matrix, FMEA, unit test reports — provided a strong foundation for ISO 26262 ASIL-D certification with the customer’s functional safety assessor.Future-Ready Multicore Architecture The TC389-based AUTOSAR platform enables seamless integration of future ADAS, electrification, and domain controller workloads without redesign.

Technologies & Standards

CategoryTechnologies
PlatformAUTOSAR Classic Platform | Run-Time Environment (RTE)
MCUInfineon AURIX™ TC389 (3× TriCore + HSM)
Functional SafetyISO 26262:2018 ASIL-D
ProcessASPICE SWE.1–SWE.6
Coding StandardEmbedded C | MISRA-C:2012
BSW / MCALAUTOSAR OS | SchM | EcuM | WdgM | NvM | DCM | DEM
CommunicationCAN | Ethernet (DoIP) | FlexRay | LIN
Safety MechanismsE2E Protection (CRC + BZ Counter) | MPU | Lockstep | WdgM
Tools & ALMIBM DOORS | Static Analysis (MISRA) | Unit Testing
CybersecurityISO 21434
Ready to Build Your AUTOSAR Safety Platform? From AUTOSAR SWC architecture to full ASIL-D evidence delivery, Requisimus provides end-to-end embedded software engineering for the most demanding automotive safety programmes — across powertrain, chassis, ADAS, and domain controllers. Contact: Basavaraj.Tarihalli@requisimus.com  |  Website: www.requisimus.com