Fail-operational Safety Architecture for ADASAD Systems and a Model-driven Approach for Dependent Failure Analysis