Some features might even require fail-operational behavior, so that they must be provided
even in the presence of random hardware failures. A new fault-tolerant SW/HW architecture
for electric vehicles provides inherent safety capabilities that enable fail-operational
features. In this paper we introduce a formal model of this architecture and an approach to
calculate valid deployments of mixed-critical software-components to the execution nodes …