Nicole Pappler, AlektoMetis | Open Source Summit Europe 2022
AlektoMetis CTO Nicole Pappler explains why the appeal of the open source Zephyr operating system in application environments where safety is critical.
Transcript
This is texturing TV. Hey guys, welcome back to the open source summit. We're here in Dublin Ireland.
It's beautiful and it's gorgeous and we have Nicole Pappler who's with us? And she's in charge of safety for the Zephyr project Zephyr is in charge of the real-time operating systems for embedded systems and Edge Computing platforms, and she's gonna figure out ways to work with people to use that in use cases that require a high amount of safety Nicole Welcome, Michelle. Hi nice to be here nice to me.
So why does this need a special program? What's Difficult about it? What's the challenges?
And what are you trying to accomplish? Oh, yeah, there's a lot of challenges and what what let's say the base that we trying to accomplish with. Let's say the safety section of the cephyr project is to have this, you know, neat little embedded operating system in safety related application so that there's an operating system available in open source that is reliable enough and that you can trust and that has every thing you need for the safety compliance approval of a complete system.
So really yeah from base to application. So these systems are really hardened in that they need to be, you know, absolutely reliable. Will there be tests or certifications or how will that kind of play aiming for a safety certification in the end?
Which is a combination of your having an audit and assessment and then providing from our side all these reliability information which is a tests. That's something that already done in the suffer project, but bring this into a format there when that safety certification really accepts this as proof of tests as proof of complete coverage. That's something that we are currently working on.
Now the folks who build these types of applications already have some systems in place. I'm what's in it for them to go with an open source. What's going to be the attraction?
Well, we'll get them to stand up and go. Whoo, I can't wait. Yeah.
So yeah, it's it's the main thing that you always have when you go open source, you have your completely vendor neutral you are avoiding locked in mechanisms. You'll find open Community to interact with you have a better chance to let's say to also work with the project to to get feature requests or functionality requests to the project. It's you can get involved it's open.
So it's you're not so dependent as on let's say the standard operating system vendors And hopefully the total cost will be lower too, right? How much do I pay for a license? Yeah, you won't pay for a license, but you still have the efforts of integrating and of testing in your context.
So yeah, I'm sure in the end, you know, I think the business people would need to answer that because that's more to the total cost of an operating system in your project then simply. The cost for a license in the end I think for full or higher volume products for sure will be lower cost. Anything involving safety tends to attract a lot of attention from governments.
So are you going to help work with the government side of these things and say to these people, you know Zephyrs reliable and work with the manufacturers or you leave that to the manufacturers and they'll take care of that or how involved will you guys be so From the safety point of view were not involved with the government. So the government now is all governments are facing the security topics. So with the safety, it's I think it's more the staple that's always there that you expect you expect a car to be safe.
You expect a medical device to not kill the patient. You just expect safety to be there for I the last 20 30 50 years. So you just expected to be there and the security is the one thing that's now popping up into all faces and saying okay.
Yeah. We also we also want a security we rely on the safety wherever it's coming from and we want the security. So at the moment the focus of the government is very strong on the security which also affects the safety so you can't really separate things but say with Government interaction we leave this to security guys at the moment.
Do you think there'll be a lot of lawyers involved as we go forward? It seems like there's a opportunities for all kinds of misunderstandings and litigation. There are lawyers always involved with the safety.
It's you know with product reliability and one aim of you know, following these safety certification or safety compliance programs is to show two lawyers to show yeah in when in the end you have have a crush or something that will affect people negatively and you have to prove that you did everything possible to avoid this. So that's more or less the aim of yeah showing safety compliance showing compliance with state of the art method showing compliance with architectural schemes and how to provide a reliable and robust system. And yeah that's lawyers are always involved with the sense of yeah, checking in the case.
Something goes wrong who is to blame so it's more or less. Also avoiding the blame game. Um having really proved, you know, you can always say I have the best Engineers.
I have the best process. I have the best product but you need to prove that you need to prove that. It's better best also in the sense of reliability of not killing people.
One of people underestimate about being in these use cases. And what is it that in your experience? You've seen people kind of Overlook and then get hung up on later that they should have worked on earlier essay from a technical perspective.
It's always okay. We need to have a safe product and let's buy a bunch of safe components plug them together and have a safe product and it's actually more to that. So it's always about the architecture of the complete system so that the components however expensive they have been or however great the certification results are that really fit together and they fit the use case of your product.
So that's when we go back to an operating system that it's really as flexible as configurable and as reliable in the configurations as it can get right and we're talking about use cases that can involve personal health care be or whatever because it's a really small operating system and it can go into devices that might be in your ear like this one and so it will have a lot of implications in terms of lifestyle that go beyond just you know, whether or not it's secure from a hacking perspective. So if that's the case Should people start raining applications for this with those goals in mind and if I'm a software developer, what should I be thinking about for the software that's going to sit on top of these devices. Do I need a safety review for that too?
And what does it look like? Yeah. Sure.
So what I said before it's not just only plugging things together and getting certified components for it. It's also do this. The test is fit together.
So from the suffer perspective, we will provide information on how an application or how also the underlying Hardware needs to look to work with the safety operating system. So on the one inside when you look about yeah developers writing applications. Yeah follow or read the safety manual follow us the best practices for your own application.
So make it as robust make it as you know, having no flaws with sense of yeah, you don't try to avoid our abilities try to avoid unspecified Behavior. Make sure you really Implement what Wanted to implement that you think about a safe and sound product architecture that you think about a safe and sound a safety concept that you say. Okay, what are what can go wrong with my product and how do I want to avoid this?
And then how can I detect the things that I want to avoid? And what do I do if I detect this so really go from that think about what can go wrong? How can I detect this?
How can I avoid this? And what will I do if I detect this? And then yeah follow the procedures follow sound engineering principles.
So, is there a zephyr safety manual or somebody writing that there will there will be so yeah, it's an ongoing process. So we really started with setting up what we need. And identifying safety claims and safety requirements or let's say the safety functionality the scope that the project will provide for a safety application and that information will go into the safety manual plus information how to really integrate plus information.
How do I test that my application and setho works together in a safe way. Are you looking for volunteers to help with this? I mean you're recruiting folks.
Okay. So what ideally would you need from folks who went? So at the moment attendance in the Safety Committee is limited to members of the project.
But you can always contact us with our Discord Channel Discord Channel. There's a safety Channel inside that's open for everybody if you want to get involved. Contact us.
We will find a way to integrate you to the project, hopefully and yeah, we're always happy to cooperate and to to talk to people who want to know about the current status who have requests regarding safety who have an actual use case that they're working on with and they want to use surface so We depend a lot about interaction, and that's maybe also one of the nice things of Open Source. You can always contact us. We're open we're open to requests.
We're open to questions. We're open to collaborations. All right, folks a little bit of a reminder Safety First.
Hey, thanks for being on the show. Thank you, and we'll be back in a few minutes.





