„When we’re talking about highly automated driving, we are also talking about a shift from ‚Fail safe‘ to ‚Fail operation‘.“
This goal can’t be achieved by a one-channel-system and leads to a redundant system, using two ASIL (Automotive Safety Integrity Level) components. But as there is usually only one power generator within a car, a mixed ASIL-QM design is the result. Hence any potential negative impact of failure by a QM component for an ASIL component must be prevented.