Architectures/HD content · probable path · edge profile
Public reference architecture

eHorizon & ADAS Map

Qualified road-ahead context with explicit validity and safe withdrawal.

Bind map, localization, route, probable path, attribute, consumer and interface versions; never let map context masquerade as perception or vehicle control.

Know which component owns the state—and what it must never infer.

Every layer exposes an authoritative responsibility and an explicit non-authority boundary.

01
SAAS-06 / content operations

HD/ADAS content

OwnsVersioned corridor geometry, topology and attributes

Must not inferContent does not establish current vehicle position

02
FW-01 / FW-02

Localization and route

OwnsPosition candidates, confidence and active route context

Must not inferAmbiguity remains alternatives

03
FW-07

Horizon runtime

OwnsRanked probable path and bounded offset profiles

Must not inferNever outputs perception or control

04
ADASIS/NDS/OEM interface

Consumer adapter

OwnsNegotiated schema, rate, length and validity

Must not inferConsumer safety decision remains in owning ECU

State advances through evidence—not optimistic UI.

Each transition names both the action and the identity or version evidence that makes it reproducible.

  1. 01

    Qualify context

    Resolve coverage, content signature, localization, route and consumer capability.

    map/route/localization/consumer versions
  2. 02

    Build probable path

    Rank bounded alternatives from topology and declared route evidence.

    path IDs · probability/quality · branching
  3. 03

    Encode profile

    Publish allowlisted attributes with offset, source, validity and confidence.

    attribute schema · horizon fingerprint
  4. 04

    Deliver

    Negotiate consumer rate, length, schema and freshness.

    consumer ID · interface revision · timestamps
  5. 05

    Replay

    Reproduce exact output from immutable inputs without a vehicle.

    input/output fingerprint · versions · checks

Interfaces that a production program must own.

01

Qualified context

Coverage, map, localization, route and consumer identity.

02

Probable path

Ranked segments, alternatives, horizon length and confidence.

03

Attribute profile

Offsets, units, validity, source and allowlist.

04

Delivery/replay

Consumer negotiation, timing, fingerprints and no-control boundary.

Failure states stay truthful and useful.

Ambiguous ramp/path

Publish ranked alternatives or shorten/withdraw rather than guarantee one path.

Low localization confidence

Fail closed and publish no qualified output.

Stale/incompatible content

Mark stale/unavailable and prevent current-validity claims.

Consumer schema not allowlisted

Reject negotiation and deliver no profile.

Privilege follows the narrowest useful boundary.

  • Signed content and consumer allowlists
  • Least-privilege attributes by ECU/function
  • Fixed bounds and resource budgets in edge runtime
  • No visualization or unrelated layer leakage
  • Map context explicitly not perception or control

A green demo is not a production acceptance case.

  • 01Corridor coverage/quality and content signature
  • 02Ramp ambiguity, low confidence and stale content tests
  • 03ADASIS/NDS/OEM interface conformance
  • 04Fixed-bound timing/memory and target integration
  • 05Exact replay plus safety-boundary tamper verifier

Compose the system without collapsing product ownership.

Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.

OEM program workshop

Turn the eHorizon & ADAS Map reference into your program architecture.

Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.