A DDS-based reference architecture demonstrating how connected Software-Defined Vehicles can use edge and cloud services while preserving isolation and deterministic behavior in safety-critical functions.
eProsima has completed SAFE-EDGE, a prototype architecture developed within the O-CEI project through its Horizon Europe Open Call. SAFE-EDGE demonstrates how Software-Defined Vehicles (SDVs) can remain connected to edge and cloud services while keeping their safety-critical decision path isolated, deterministic and independent from the availability of external services.
Modern vehicles increasingly depend on connectivity for remote updates, cloud-assisted services, energy optimization and edge-based intelligence. But safety-critical vehicle decisions cannot depend on the availability or behavior of those external systems. SAFE-EDGE addresses this challenge by architecture.
Safety and connectivity, without one compromising the other
At the core of SAFE-EDGE is a strict separation between safety-critical logic and everything else. Functions such as emergency handling, fault detection and vehicle operating decisions run in an isolated, deterministic environment on a QNX-based real-time platform. Non-critical functions (including telemetry, infotainment and remote updates) run separately from the safety-critical domain, preserving architectural isolation between connected services and the vehicle's safety decision path.
Communication between the vehicle, the edge and the server runs over DDS using explicit, well-defined data contracts. Every piece of information exchanged between domains has a known structure and meaning, reducing ambiguity and making the overall system easier to integrate, extend and verify.
Demonstrating behavior under failure and load
The integrated SAFE-EDGE prototype exercises the architecture under representative operating conditions rather than only showing a static design. The demo includes loss of server connectivity, loss of edge availability, low battery state-of-charge conditions, and additional CPU and I/O load while observing end-to-end and policy-reaction latency.
When external services become unavailable, the vehicle detects the change and transitions to the appropriate degraded policy while the safety-critical decision path remains local. When battery state of charge falls below the configured threshold, the same runtime path evaluates the new condition and updates the active vehicle policy. The dashboard exposes these transitions together with node status, communication health and latency evolution
Why it matters
SafeEDGE's approach delivers several concrete advantages:
- Deterministic safety behavior. Critical decisions are designed to execute with predictable timing and bounded communication, independently from non-critical services.
- Clear domain isolation. Safety and non-safety functions are separated so connected services do not become part of the safety-critical decision path.
- Graceful degraded operation. Loss of server or edge connectivity can be detected and reflected in the vehicle policy without making safe operation dependent on those external services.
- Energy-aware decision-making. Vehicle energy state can be treated as an input to the runtime policy path, allowing safety behavior to react to conditions such as low state of charge.
- Observable real-time behavior. The integrated demo measures end-to-end and policy-reaction latency and shows how those metrics evolve under additional system load.
Built on Safe DDS, open through Fast DDS
The vehicle's safety-critical domain is built on eProsima Safe DDS, an ISO 26262 ASIL D-certified DDS implementation designed for functional-safety environments. Safe DDS provides deterministic communication, bounded resource usage and a software foundation developed with certification requirements in mind
Outside the safety-critical boundary, the edge and server domains can use eProsima Fast DDS, the open-source implementation of the OMG DDS standard. This makes the non-safety side of the architecture broadly accessible while preserving the same DDS data model across vehicle, edge and server.
Using shared DDS/IDL contracts across the architecture helps preserve compatibility and traceability as components evolve. The result is a system that uses the appropriate middleware for each domain: Safe DDS where functional-safety requirements matter most, and Fast DDS where openness and broad availability are priorities
From SAFE-EDGE to production automotive architectures
SAFE-EDGE is a prototype reference architecture, not a production vehicle platform. Its value is to demonstrate a practical path for combining open-standard DDS communication, functional-safety middleware, QNX-based isolation and edge/cloud connectivity in Software-Defined Vehicle architectures.
About SAFE-EDGE and O-CEI
SAFE-EDGE was developed by eProsima within the O-CEI (Open CloudEdgeIoT) project through its Horizon Europe Open Call, addressing the Vehicle as Software for Vehicle Safety challenge. The project demonstrates a connected vehicle architecture based on strict domain separation, DDS interoperability and deterministic communication across vehicle, edge and server environments.

