European Conference on Nanoelectronics and Embedded Systems for Electric Mobility

Size: px
Start display at page:

Download "European Conference on Nanoelectronics and Embedded Systems for Electric Mobility"

Transcription

1 European Conference on Nanoelectronics and Embedded Systems for Electric Mobility ecocity emotion th September 2014, Erlangen, Germany Scalable Functional Safety Architecture for Electric Mobility Applications Michael Steindl Martin Winkler Christian Miedl AVL Software and Functions, Germany

2 Presentation Outline Introduction State of the art Hardware Architecture New approach: Hardware Qualifier Emergency Operation Scenario Standby Scenario Conclusion

3 Introduction Functional safety: Freedom of unacceptable risk due to hazards caused by an faulty E/E systems Examples for functional risks in electric cars: unintended acceleration unintended loss of braking capability Failures in E/E systems can be classified in two categories: Systematic failures (e.g. software bug, specification fault) Random failures (e.g. unpredictable HW fault) Source: AVL

4 Introduction Measures are necessary to deal with such failures: Systematic failures Use suitable development processes and methods Random failures Use high quality components (perfectness) Use redundancy Detection of errors Transition to safe state Error correction/ reconfiguration Source: AVL

5 Introduction Fail-safe system: Provides a safe state which can be achieved and maintained without the support of the Control Unit Individual and dependent failures that lead to a loss of service are safe Deactivation of service is generally safe Intended fault reaction Fail-operational system: Safe state can not be achieved and/or maintained without the support of the ECU Deactivation / loss of service is generally unsafe Source: Wikipedia

6 State of the art Hardware Architecture Hardware Architecture for Electronic throttle control (Fail-safe system) Analogue inputs ADC Check Input variables "Regular" XCU Functions Request for Failsafe Limitations MC XCU DRI DRI Disable to safety-relevant power stages (e.g., injection and throttle) Process Monitoring or Copy of Process Monitoring Processor Monitoring Question Answer Evaluation Processor Monitoring Reset MU Function (L1) Process Monitoring (L2) Copy of Process Monitoring (L2 ) Processor Monitoring (L3) Source: EGAS-AK

7 disable State of the art Hardware Architecture VCU Microcontroller Inverter Input (Acceleration Pedal) Application SW Com. Interface Torque Request Process Mon. Q/A AVL Monitoring Unit VCU Safe State request is indicated to the system by disabling CAN drivers Limitations: No communication possible in case of an error (debugging, re-flashing ) No distinction between error and normal system states with disabled safety mechanisms (e.g. start-up) Difficult to test during runtime (switch-off path check)

8 State of the art Hardware Architecture VCU Microcontroller Inverter Input (Acceleration Pedal) Application SW Com. Interface Torque Request Process Mon. disable Q/A AVL Monitoring Unit Limitations: Additional Hardware elements necessary costs VCU Safe State request is indicated to the system by additional switch off path

9 New approach: Hardware Qualifier VCU Microcontroller Inverter Input Application SW Com. Interface Regular Output + HW-Qualifier Process Mon. Q/A HW-Qualifier AVL Monitoring Unit Monitoring Unit determines µc HW-Status (HW-Qualifier) HW-Qualifier is communicated over existing interfaces to inverter via protected transfer Inverter evaluates received HW-Qualifier and selects suitable system reaction Advantages: No communication cut-off in case of an error No redundant switch off path Distinction between error and normal system states with disabled safety mechanisms Increased diagnostic capability of switch-off path Degraded fault reaction possible HW status can be easily provided to multiple control units

10 Standby Scenario VCU Input Microcontroller Application SW Process Mon. Output Com. Interface Regular Output Standby Output + HW-Qualifier BCU MC Q/A. Input AVL Monitoring Unit Standby - SW µc HW Status Standby Output Com. Interface Microcontroller is completely switched-off in certain operation modes (standby) Standby functionality is provided by MU Standby state is signaled to Inverter via HW Qualifier Advantages: Reduced system energy consumption Enhanced system wake-up concepts possible: Several sources possible, e.g.: Analog in Digital in CAN/Flexray/SPI/I²C Complex evaluation possible

11 Emergency Operation Scenario VCU Inverter Input Microcontroller Application SW Output Com. Interface Regular Output Process Mon. Backup Output + HW-Qualifier Q/A. Input AVL Monitoring Unit Redundant ASW HW- Qualifier Backup Output Com. Interface Monitoring Unit provides redundant ASW functionality Error state is signaled to inverter via HW Qualifier (Inverter limitation) Advantages: Increased system availability due to emergency operation functionality of Monitoring Unit in case of faulty main microcontroller Additional resources for nonsafety functionalities on Monitoring Unit available

12 Conclusion ECU error indication to System (Hardware Qualifier) Safe State request via CAN without disabling CAN drivers No additional hardware connections necessary Distinction between error and normal system states with disabled safety mechanisms possible Graded fault reaction possible Stand-by concept Operation without main µc Less quiescent current Wake-up concept Complex evaluation of arbitrary input sources possible Emergency Operation (Fault-tolerant system design) Limited functionality possible in case of an error

13 Conclusion Fully compliant to normative requirements (ISO26262, EGAS Concept) Cost efficient Scalable to customer requirements to provide enhanced functionality without additional hardware

14 Thank you for your attention! Contact Dr. Michael Steindl Martin Winkler Christian Miedl AVL Software and Functions GmbH Im Gewerbepark B27 D Regensburg

AUTOSAR stands for AUTomotive Open Systems ARchitecture. Partnership of automotive Car Manufacturers and their Suppliers

AUTOSAR stands for AUTomotive Open Systems ARchitecture. Partnership of automotive Car Manufacturers and their Suppliers Introduction stands for AUTomotive Open Systems ARchitecture Electronic Control Unit Partnership of automotive Car Manufacturers and their Suppliers Source for ECU: Robert Bosch GmbH 2 Introduction Members

More information

The Safe State: Design Patterns and Degradation Mechanisms for Fail- Operational Systems

The Safe State: Design Patterns and Degradation Mechanisms for Fail- Operational Systems The Safe State: Design Patterns and Degradation Mechanisms for Fail- Operational Systems Alexander Much 2015-11-11 Agenda About EB Automotive Motivation Comparison of different architectures Concept for

More information

Is This What the Future Will Look Like?

Is This What the Future Will Look Like? Is This What the Future Will Look Like? Implementing fault tolerant system architectures with AUTOSAR basic software Highly automated driving adds new requirements to existing safety concepts. It is no

More information

Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO standard

Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO standard Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO 26262 standard NMI Automotive Electronics Systems 2013 Event Victor Reyes Technical Marketing System

More information

Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist

Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist Internet of Things Group 2 Internet of Things Group 3 Autonomous systems: computing platform Intelligent eyes Vision. Intelligent

More information

FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO SPEAKER. Dept. of Electrical Engineering, National Taipei University

FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO SPEAKER. Dept. of Electrical Engineering, National Taipei University FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO-26262 Kuen-Long Lu 1, 2,Yung-Yuan Chen 1, and Li-Ren Huang 2 SPEAKER 1 Dept. of Electrical Engineering, National Taipei University 2

More information

Frequently Asked Questions

Frequently Asked Questions Product Name: System Basis Chips (SBCs) Date: April 2013 Application: Automotive ECUs Datasheet: www.infineon.com/sbc Contact Person: Norbert Ulshoefer/Antonio Monetti Note: The following information is

More information

Deriving safety requirements according to ISO for complex systems: How to avoid getting lost?

Deriving safety requirements according to ISO for complex systems: How to avoid getting lost? Deriving safety requirements according to ISO 26262 for complex systems: How to avoid getting lost? Thomas Frese, Ford-Werke GmbH, Köln; Denis Hatebur, ITESYS GmbH, Dortmund; Hans-Jörg Aryus, SystemA GmbH,

More information

Autonomous Driving From Fail-Safe to Fail-Operational Systems

Autonomous Driving From Fail-Safe to Fail-Operational Systems Autonomous Driving From Fail-Safe to Fail-Operational Systems Rudolf Grave December 3, 2015 Agenda About EB Automotive Autonomous Driving Requirements for a future car infrastructure Concepts for fail-operational

More information

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309 June 25th, 2007 Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309 Christopher Temple Automotive Systems Technology Manager Overview Functional Safety Basics Functional

More information

Securing the future of mobility

Securing the future of mobility Kaspersky Transportation System Security AVL Software and Functions Securing the future of mobility www.kaspersky.com #truecybersecurity Securing the future of mobility Connected car benefits The need

More information

Software Architecture. Definition of Software Architecture. The importance of software architecture. Contents of a good architectural model

Software Architecture. Definition of Software Architecture. The importance of software architecture. Contents of a good architectural model Software Architecture Definition of Software Architecture Software architecture is process of designing g the global organization of a software system, including: Dividing software into subsystems. Deciding

More information

Scalable and Flexible Software Platforms for High-Performance ECUs. Christoph Dietachmayr Sr. Engineering Manager, Elektrobit November 8, 2018

Scalable and Flexible Software Platforms for High-Performance ECUs. Christoph Dietachmayr Sr. Engineering Manager, Elektrobit November 8, 2018 Scalable and Flexible Software Platforms for High-Performance ECUs Christoph Dietachmayr Sr. Engineering Manager, November 8, Agenda A New E/E Architectures and High-Performance ECUs B Non-Functional Aspects:

More information

Siemens Safety Integrated Take a safe step into the future

Siemens Safety Integrated Take a safe step into the future Engineered with TIA Portal Machine Safety Life-Cycle Siemens Safety Integrated Take a safe step into the future Unrestricted / Siemens Industry Inc. 2015. All Rights Reserved. www.usa.siemens.com/safety

More information

Functional Safety on Multicore Microcontrollers for Industrial Applications. Thomas Barth (h-da) Prof. Dr.-Ing. Peter Fromm (h-da)

Functional Safety on Multicore Microcontrollers for Industrial Applications. Thomas Barth (h-da) Prof. Dr.-Ing. Peter Fromm (h-da) Functional Safety on Multicore Microcontrollers for Industrial Applications Thomas Barth (h-da) Prof. Dr.-Ing. Peter Fromm (h-da) Contents Functional Safety Multicore Motivation ISO13849 Implemented Software

More information

ISO meets AUTOSAR - First Lessons Learned Dr. Günther Heling

ISO meets AUTOSAR - First Lessons Learned Dr. Günther Heling ISO 26262 meets AUTOSAR - First Lessons Learned Dr. Günther Heling Agenda 1. ISO 26262 and AUTOSAR Two Basic Contradictions Top-Down vs. Reuse Concentration vs. Distribution 2. Approach Mixed ASIL System

More information

10 th AUTOSAR Open Conference

10 th AUTOSAR Open Conference 10 th AUTOSAR Open Conference Dr. Moritz Neukirchner Elektrobit Automotive GmbH Building Performance ECUs with Adaptive AUTOSAR AUTOSAR Nov-2017 Major market trends and their impact Trends Impact on E/E

More information

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility. HIL platform for EV charging and microgrid emulation

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility. HIL platform for EV charging and microgrid emulation European Conference on Nanoelectronics and Embedded Systems for Electric Mobility emobility emotion 25-26 th September 2013, Toulouse, France HIL platform for EV charging and microgrid emulation Salvador

More information

LION SAFE Remote I/O System. LÜTZE TRANSPORTATION GMBH Dimitrios Koutrouvis V00

LION SAFE Remote I/O System. LÜTZE TRANSPORTATION GMBH Dimitrios Koutrouvis V00 Page 1 LÜTZE TRANSPORTATION GMBH Dimitrios Koutrouvis V00 Actual Market Situation New Safety Requirements from Standards and Authorities Governance European Union (EU) ==> European Railway Agency (ERA)

More information

MC33903/4/5 Block Diagram. Analog, Mixed-Signal and Power Management. Legend. MCU Voltage Regulator (V DD ) Internal CAN Regulator (V CAN )

MC33903/4/5 Block Diagram. Analog, Mixed-Signal and Power Management. Legend. MCU Voltage Regulator (V DD ) Internal CAN Regulator (V CAN ) Analog, Mixed-Signal and MC33903/4/5 System Basis Chip Gen2 with High Speed and Interface Overview The MC33903/4/5 is the second generation family of System Basis Chips, which combine several features

More information

Failure Diagnosis and Prognosis for Automotive Systems. Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010

Failure Diagnosis and Prognosis for Automotive Systems. Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010 Failure Diagnosis and Prognosis for Automotive Systems Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010 Automotive Challenges and Goals Driver Challenges Goals Energy Rising cost of petroleum

More information

What functional safety module designers need from IC developers

What functional safety module designers need from IC developers What functional safety module designers need from IC developers Embedded Platforms Conference Microcontrollers and Peripherals Nov 9 th 2016 14:50 15:30 TOM MEANY Introduction This presentation gives a

More information

FSO Webnair FSO Safety Functions Module. ABB Group February 11, 2015 Slide 1

FSO Webnair FSO Safety Functions Module. ABB Group February 11, 2015 Slide 1 FSO Webnair FSO Safety Functions Module February 11, 2015 Slide 1 Competence Requirements for ABB Commissioner / Service Engineer of ACS880 Drives with FSO The integrated Safety Function Module (FSO; option

More information

Entwicklung zuverlässiger Software-Systeme, Stuttgart 30.Juni 2011

Entwicklung zuverlässiger Software-Systeme, Stuttgart 30.Juni 2011 Entwicklung zuverlässiger Software-Systeme, Stuttgart 30.Juni 2011 Tools and Methods for Validation and Verification as requested by ISO26262 1 Introduction ISO26262 ISO 26262 is the adaptation of IEC

More information

Trusted Platform Modules Automotive applications and differentiation from HSM

Trusted Platform Modules Automotive applications and differentiation from HSM Trusted Platform Modules Automotive applications and differentiation from HSM Cyber Security Symposium 2017, Stuttgart Martin Brunner, Infineon Technologies Axiom: Whatever is connected can (and will)

More information

Functional Safety on Multicore Microcontrollers for Industrial Applications

Functional Safety on Multicore Microcontrollers for Industrial Applications Functional Safety on Multicore Microcontrollers for Industrial Applications Thomas Barth Department of Electrical Engineering Hochschule Darmstadt University of Applied Sciences Darmstadt, Germany thomas.barth@h-da.de

More information

Taking the Right Turn with Safe and Modular Solutions for the Automotive Industry

Taking the Right Turn with Safe and Modular Solutions for the Automotive Industry Taking the Right Turn with Safe and Modular Solutions for the Automotive Industry A Time-Triggered Middleware for Safety- Critical Automotive Applications Ayhan Mehmet, Maximilian Rosenblattl, Wilfried

More information

Analysis and Development of Fail-Operational Automotive Mechatronic Systems

Analysis and Development of Fail-Operational Automotive Mechatronic Systems ISBN 978-93-84422-37-0 2015 International Conference on Advances in Software, Control and Mechanical Engineering (ICSCME'2015) Antalya (Turkey) Sept. 7-8, 2015 pp. 1-7 Analysis and Development of Fail-Operational

More information

New developments about PL and SIL. Present harmonised versions, background and changes.

New developments about PL and SIL. Present harmonised versions, background and changes. Safety evevt 2017 Functional safety New developments about PL and SIL. Present harmonised versions, background and changes. siemens.com ISO/ TC 199 and IEC/ TC 44 joint working group 1 - Merging project

More information

Welcome to the overview of ACS880 functional safety, FSO-11 Safety functions module.

Welcome to the overview of ACS880 functional safety, FSO-11 Safety functions module. Welcome to the overview of ACS880 functional safety, FSO-11 Safety functions module. 1 The e-learning sessions about FSO-11 safety functions module contain the following topics. A general overview More

More information

SINAMICS SINAMICS G120. Frequency inverter with Control Units CU240E-2 CU240E-2 DP CU240E-2 F CU240E-2 DP-F. Function Manual Safety Integrated 07/2010

SINAMICS SINAMICS G120. Frequency inverter with Control Units CU240E-2 CU240E-2 DP CU240E-2 F CU240E-2 DP-F. Function Manual Safety Integrated 07/2010 SINAMICS G120 Frequency inverter with Control Units CU240E-2 CU240E-2 DP CU240E-2 F CU240E-2 DP-F Function Manual Safety Integrated 07/2010 SINAMICS Answers for industry. Safety Integrated Function Manual,

More information

Functional Safety Architectural Challenges for Autonomous Drive

Functional Safety Architectural Challenges for Autonomous Drive Functional Safety Architectural Challenges for Autonomous Drive Ritesh Tyagi: August 2018 Topics Market Forces Functional Safety Overview Deeper Look Fail-Safe vs Fail-Operational Architectural Considerations

More information

Migration of SES to FPGA Based Architectural Concepts

Migration of SES to FPGA Based Architectural Concepts Migration of SES to FPG Based rchitectural Concepts M. Steindl 1, J. Mottok 1, H. Meier 1,F. Schiller 2, M. Fruechtl 2 1 Regensburg University of pplied Sciences Department of Electronics and Information

More information

Functional Safety for Electronic Control

Functional Safety for Electronic Control HYDAC ELECTRONIC Functional Safety for Electronic Control April 20, 2016 Speaker Eric Ringholm HYDAC ELECTRONIC Division Manager Component range for modern machines Software Product Range Agenda Functional

More information

MASP Chapter on Safety and Security

MASP Chapter on Safety and Security MASP Chapter on Safety and Security Daniel Watzenig Graz, Austria https://artemis.eu MASP Chapter on Safety & Security Daniel Watzenig daniel.watzenig@v2c2.at Francois Tuot francois.tuot@gemalto.com Antonio

More information

EV2274A. (SBC) MC33CFS6500 microprocessor

EV2274A. (SBC) MC33CFS6500 microprocessor EV2274A Micro control unit NXP MPC5744 ISO26262 ASIL-D integrity level 200MHz 2.5M Flash 384K SRAM Float Point Capability (SBC) MC33CFS6500 microprocessor Inputs 15 Analog Inputs 21 Digital Inputs 4 Frequency

More information

Model Based Development and Code Generation for Automotive Embedded Systems. April 26, 2017 Dr. Gergely Pintér, Dr. Máté Kovács thyssenkrupp Steering

Model Based Development and Code Generation for Automotive Embedded Systems. April 26, 2017 Dr. Gergely Pintér, Dr. Máté Kovács thyssenkrupp Steering Model Based Development and Code Generation for Automotive Embedded Systems April 26, 2017 Dr. Gergely Pintér, Dr. Máté Kovács Agenda Model Based Development and Code Generation for Automotive Embedded

More information

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. Electronic Motor DRC Functional Safety

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. Electronic Motor DRC Functional Safety Drive Technology \ Drive Automation \ System Integration \ Services Manual Electronic Motor DRC Functional Safety Edition 02/2012 19376812 / EN SEW-EURODRIVE Driving the world Contents Contents 1 General

More information

Create, Embed, Empower. Crevavi Technologies Company profile

Create, Embed, Empower. Crevavi Technologies Company profile Create, Embed, Empower Crevavi Technologies Company profile Copyright Crevavi 2018 About Crevavi Technologies Estd in 2011. Based in India. Offices in Bangalore and Mysore Branches in US, Germany and Australia

More information

Operator Station (V8.0) SIMATIC. Process Control System PCS 7 Operator Station (V8.0) Preface 1. The PCS 7 Operator Station

Operator Station (V8.0) SIMATIC. Process Control System PCS 7 Operator Station (V8.0) Preface 1. The PCS 7 Operator Station SIMATIC Process Control System PCS 7 Configuration Manual Preface 1 The PCS 7 Operator Station 2 Introduction to OS configuration 3 Setting languages 4 Configuring OS data in SIMATIC Manager 5 Configuring

More information

Introduction to Adaptive AUTOSAR. Dheeraj Sharma July 27, 2017

Introduction to Adaptive AUTOSAR. Dheeraj Sharma July 27, 2017 Introduction to Adaptive AUTOSAR Dheeraj Sharma July 27, 2017 Overview Software Platform and scope of Adaptive AUTOSAR Adaptive AUTOSAR architecture and roadmap EB Adaptive Platform and Prototyping solution

More information

Servo drives. SafeMotion

Servo drives. SafeMotion 2 Bosch Rexroth AG Electric Drives and Controls Documentation Instructions Intelligent and reliable Safety category 3, PL d, SIL 2 Extensive safety functions Minimum response times Independent of the control

More information

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. MOVITRAC MC07B Functional Safety

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. MOVITRAC MC07B Functional Safety Drive Technology \ Drive Automation \ System Integration \ Services Manual MOVITRAC MC07B Functional Safety Edition 12/2011 19396414 / EN SEW-EURODRIVE Driving the world Contents Contents 1 General Information...

More information

CAN application Driving controls in the cab of railway engines.

CAN application Driving controls in the cab of railway engines. CAN application Driving controls in the cab of railway engines. Jeremy Retham, Deuta-Werke During the current development of a modular drivers desk for trains a major factor that has to be considered is

More information

Solving functional safety challenges in Automotive with NOR Flash Memory

Solving functional safety challenges in Automotive with NOR Flash Memory Solving functional safety challenges in Automotive with NOR Flash Memory Sandeep Krishnegowda Marketing Director Flash Business Unit Cypress Semiconductor 1 Flash Memory Summit 2018 / Santa Clara, CA Automotive

More information

Process Historian Administration SIMATIC. Process Historian V8.0 Update 1 Process Historian Administration. Basics 1. Hardware configuration 2

Process Historian Administration SIMATIC. Process Historian V8.0 Update 1 Process Historian Administration. Basics 1. Hardware configuration 2 Basics 1 Hardware configuration 2 SIMATIC Process Historian V8.0 Update 1 Management console 3 Process control messages 4 System Manual 04/2012 A5E03916798-02 Legal information Legal information Warning

More information

Introduction to Safety PLCs GuardLogix & CIP Safety

Introduction to Safety PLCs GuardLogix & CIP Safety Introduction to Safety PLCs GuardLogix & CIP Safety Jon Riemer Solution Architect Safety & Security Functional Safety Engineer (TÜV Rheinland) Cyber Security Specialist (TÜV Rheinland) 2018 Rockwell Automation

More information

Industrial Embedded Systems - Design for Harsh Environment - Dr. Alexander Walsch

Industrial Embedded Systems - Design for Harsh Environment - Dr. Alexander Walsch Industrial Embedded Systems - Design for Harsh Environment - Dr. Alexander Walsch alexander.walsch@ge.com WS 2011/12 Technical University Munich (TUM) Introduction - Our Backgrounds O&G Energy Sensor systems

More information

Click ISO to edit Master title style Update on development of the standard

Click ISO to edit Master title style Update on development of the standard Click ISO 26262 to edit Master title style Update on development of the standard Dr David Ward Head of Functional Safety January 2016 Agenda Why update ISO 26262? What is the process for updating the standard?

More information

Virtualization of Heterogeneous Electronic Control Units Testing and Validating Car2X Communication

Virtualization of Heterogeneous Electronic Control Units Testing and Validating Car2X Communication Testing and Validating Car2X Communication 1 Public ETAS-PGA 2017-07-06 ETAS GmbH 2017. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, Testing and Validating Car2X

More information

Formal Verification and Automatic Testing for Model-based Development in compliance with ISO 26262

Formal Verification and Automatic Testing for Model-based Development in compliance with ISO 26262 Formal Verification and Automatic Testing for Model-based Development in compliance with ISO 26262 Is your software safe? Do you have evidence? 2 BTC Embedded Systems AG proprietary all rights reserved

More information

SIMATIC. Process Control System PCS 7 Software update with utilization of new functions. Security information 1. Preface 2.

SIMATIC. Process Control System PCS 7 Software update with utilization of new functions. Security information 1. Preface 2. Security information 1 Preface 2 SIMATIC Process Control System PCS 7 Software update with utilization of new functions Service Manual Introduction 3 Overview of Upgrade Steps 4 Preparing for the software

More information

Enabling Increased Safety with Fault Robustness in Microcontroller Applications

Enabling Increased Safety with Fault Robustness in Microcontroller Applications Enabling Increased Safety with Fault Robustness in Microcontroller Applications Wayne Lyons ARM 110 Fulbourn Road Cambridge CB1 9NJ, England Abstract All safety-critical or high-reliability applications

More information

Application Note. AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO )

Application Note. AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO ) Application Note AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO 13849-1) Contents 1 Introduction 3 1.1 Purpose... 3 1.2 Document history... 4 1.3 Validity...

More information

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. MOVITRAC MC07B Functional Safety

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. MOVITRAC MC07B Functional Safety Drive Technology \ Drive Automation \ System Integration \ Services Manual MOVITRAC Functional Safety Edition 12/2011 19396414 / EN SEW-EURODRIVE Driving the world Contents Contents 1 General Information...

More information

Revision. MOVIPRO with EtherNet/IP or Modbus TCP Fieldbus Interface * _1017*

Revision. MOVIPRO with EtherNet/IP or Modbus TCP Fieldbus Interface * _1017* Drive Technology \ Drive Automation \ System Integration \ Services *22497064_1017* Revision MOVIPRO with EtherNet/IP or Modbus TCP Fieldbus Interface Edition 10/2017 22497064/EN SEW-EURODRIVE Driving

More information

Handling Challenges of Multi-Core Technology in Automotive Software Engineering

Handling Challenges of Multi-Core Technology in Automotive Software Engineering Model Based Development Tools for Embedded Multi-Core Systems Handling Challenges of Multi-Core Technology in Automotive Software Engineering VECTOR INDIA CONFERENCE 2017 Timing-Architects Embedded Systems

More information

Issues in Programming Language Design for Embedded RT Systems

Issues in Programming Language Design for Embedded RT Systems CSE 237B Fall 2009 Issues in Programming Language Design for Embedded RT Systems Reliability and Fault Tolerance Exceptions and Exception Handling Rajesh Gupta University of California, San Diego ES Characteristics

More information

EH2175A. Main Microprocessor Infineon Aurix TC MHz 4M Flash 472K SRAM Float Point Capability Dual Core Safety Check V Operating Voltage

EH2175A. Main Microprocessor Infineon Aurix TC MHz 4M Flash 472K SRAM Float Point Capability Dual Core Safety Check V Operating Voltage EH2175A Main Microprocessor Infineon Aurix TC275 200MHz 4M Flash 472K SRAM Float Point Capability Dual Core Safety Check Inputs 15 Analog Inputs 20 Digital Inputs 2 Frequency Inputs 1 Wake-up Input 9-16

More information

A specification proposed by JASPAR has been adopted for AUTOSAR.

A specification proposed by JASPAR has been adopted for AUTOSAR. Japan Automotive Software Platform and Architecture A specification proposed by JASPAR has been adopted for AUTOSAR. JASPAR General Incorporated Association 1. Introduction An RTE profile specification

More information

Welcome to the Safety functions training module for ACS880 cabinet-built industrial drives.

Welcome to the Safety functions training module for ACS880 cabinet-built industrial drives. Welcome to the Safety functions training module for ACS880 cabinet-built industrial drives. 1 In this presentation we will discuss safety options for ACS880 cabinet-built drives, FSO-12 safety functions

More information

SIListra. Coded Processing in Medical Devices. Dr. Martin Süßkraut (TU-Dresden / SIListra Systems)

SIListra. Coded Processing in Medical Devices. Dr. Martin Süßkraut (TU-Dresden / SIListra Systems) SIListra making systems safer Coded Processing in Medical Devices Dr. Martin Süßkraut (TU-Dresden / SIListra Systems) martin.suesskraut@se.inf.tu-dresden.de Embedded goes Medical 5./6. Oct. 2011 1 SIListra

More information

AVL ELECTRIFICATION TEST SOLUTIONS

AVL ELECTRIFICATION TEST SOLUTIONS AVL ELECTRIFICATION TEST SOLUTIONS E-INTEGRATION TEST SYSTEM Mario Propst AVL List GmbH (Headquarters) CONTENT o Applications o System solutions o Product solutions o Use cases o Customer References Mario

More information

Isolation of Cores. Reduce costs of mixed-critical systems by using a divide-and-conquer startegy on core level

Isolation of Cores. Reduce costs of mixed-critical systems by using a divide-and-conquer startegy on core level Isolation of s Reduce costs of mixed-critical systems by using a divide-and-conquer startegy on core level Claus Stellwag, Elektrobit Automotive GmbH; Thorsten Rosenthal, Delphi; Swapnil Gandhi, Delphi

More information

How Microcontrollers help GPUs in Autonomous Drive

How Microcontrollers help GPUs in Autonomous Drive How Microcontrollers help GPUs in Autonomous Drive GTC 2017 Munich, 2017-10-12 Hans Adlkofer, VP Automotive System department Outline 1 Main Safety concepts 2 Sensor Fusion architecture and functionalities

More information

FUNCTIONAL SAFETY AND THE GPU. Richard Bramley, 5/11/2017

FUNCTIONAL SAFETY AND THE GPU. Richard Bramley, 5/11/2017 FUNCTIONAL SAFETY AND THE GPU Richard Bramley, 5/11/2017 How good is good enough What is functional safety AGENDA Functional safety and the GPU Safety support in Nvidia GPU Conclusions 2 HOW GOOD IS GOOD

More information

Certified Automotive Software Tester Sample Exam Paper Syllabus Version 2.0

Certified Automotive Software Tester Sample Exam Paper Syllabus Version 2.0 Surname, Name: Gender: male female Company address: Telephone: Fax: E-mail-address: Invoice address: Training provider: Trainer: Certified Automotive Software Tester Sample Exam Paper Syllabus Version

More information

SIMATIC. Safety Engineering in SIMATIC S7. Preface. Overview of Fail-safe Systems. Configurations and Help with Selection. Communication Options 3

SIMATIC. Safety Engineering in SIMATIC S7. Preface. Overview of Fail-safe Systems. Configurations and Help with Selection. Communication Options 3 SIMATIC SIMATIC System Manual Preface Overview of Fail-safe Systems 1 Configurations and Help with Selection 2 Communication Options 3 Safety in F-Systems 4 Achievable Safety Classes with F-I/O 5 Configuring

More information

Tools and Methods for Validation and Verification as requested by ISO26262

Tools and Methods for Validation and Verification as requested by ISO26262 Tools and for Validation and Verification as requested by ISO26262 Markus Gebhardt, Axel Kaske ETAS GmbH Markus.Gebhardt@etas.com Axel.Kaske@etas.com 1 Abstract The following article will have a look on

More information

DI 8x24VDC ST digital input module SIMATIC. ET 200SP DI 8x24VDC ST digital input module (6ES7131-6BF00-0BA0) Preface. Documentation guide

DI 8x24VDC ST digital input module SIMATIC. ET 200SP DI 8x24VDC ST digital input module (6ES7131-6BF00-0BA0) Preface. Documentation guide DI 8x24VDC ST digital input module (6ES7131-6BF00-0BA0) SIMATIC ET 200SP DI 8x24VDC ST digital input module (6ES7131-6BF00-0BA0) Manual Preface Documentation guide 1 Product overview 2 Connecting 3 Parameter

More information

VT System Smart HIL Testing

VT System Smart HIL Testing VT System Smart HIL Testing V1.0 2010-06-04 Agenda > ECU Testing Testing a Door Control Unit Summary and Outlook Slide: 2 ECU Testing I/O Access for ECU Testing ECU has to be tested in its natural environment

More information

Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems

Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems Kyung-Jung Lee, Young-Hun Ki, and Hyun-Sik Ahn Abstract In this paper, we propose a hardware and software design method

More information

Software architecture in ASPICE and Even-André Karlsson

Software architecture in ASPICE and Even-André Karlsson Software architecture in ASPICE and 26262 Even-André Karlsson Agenda Overall comparison (3 min) Why is the architecture documentation difficult? (2 min) ASPICE requirements (8 min) 26262 requirements (12

More information

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. Control Cabinet Inverter MOVITRAC B Functional Safety

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. Control Cabinet Inverter MOVITRAC B Functional Safety Drive Technology \ Drive Automation \ System Integration \ Services Manual Control Cabinet Inverter MOVITRAC B Functional Safety Edition 05/2009 16811216 / EN SEW-EURODRIVE Driving the world Content Content

More information

Application of CIP Safety for functional safety in motion applications - analysis of CIP Safety motion application use case scenarios

Application of CIP Safety for functional safety in motion applications - analysis of CIP Safety motion application use case scenarios Application of CIP Safety for functional safety in motion applications - analysis of CIP Safety motion application use case scenarios www.odva.org Ludwig Leurs Bosch Rexroth AG Bob Hirschinger Rockwell

More information

Increasing Design Confidence Model and Code Verification

Increasing Design Confidence Model and Code Verification Increasing Design Confidence Model and Code Verification 2017 The MathWorks, Inc. 1 The Cost of Failure Ariane 5 $7,500,000,000 Rocket & payload lost 2 The Cost of Failure USS Yorktown 0 Knots Top speed

More information

FOR IOT PRODUCT DEVELOPMENT

FOR IOT PRODUCT DEVELOPMENT FOR IOT PRODUCT DEVELOPMENT TRONSHOW IEEE2050-2018 STANDARD 2018/12/12 ATSUSHI HASEGAWA INDUSTRIAL SOLUTION BUSINESS UNIT RENESAS ELECTRONICS CORPORATION SOLUTION OFFERINGS FOR FOCUS DOMAINS To develop

More information

CIP Safety for Drives

CIP Safety for Drives Pascal Hampikian System Strategy & Architecture Marketing Leader Schneider Electric CIP Safety for Drives Bob Hirschinger Principle Applications Engineer Rockwell Automation Ludwig Leurs Project Director

More information

Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation

Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation Prof. Dr.-Ing. Stefan Kowalewski Chair Informatik 11, Embedded Software Laboratory RWTH Aachen University Summer Semester

More information

MSK2. May 2012 Frankie Chan (IFAP ATV SMD SAE)

MSK2. May 2012 Frankie Chan (IFAP ATV SMD SAE) MSK2 SW framework May 2012 Frankie Chan (IFAP ATV SMD SAE) MSK2 SW Framework Provide small engine Hardware Platform to user to speed up the Engine Control Unit (ECU) development. The MSK2 SW framework

More information

Intrinsically safe batch controller Batching Master 110i

Intrinsically safe batch controller Batching Master 110i Intrinsically safe batch controller Batching Master 110i Installation Guide BVS 04 AT E 172 Revision 12.2 IBS BatchControl GmbH Im Sträßchen 2-4 Tel.: ++49 2441 9199 801 53925 Kall Fax.: ++49 2441 9199

More information

Welcome to the safety functions configuration training module for ACS880 Cabinet-built industrial drives.

Welcome to the safety functions configuration training module for ACS880 Cabinet-built industrial drives. Welcome to the safety functions configuration training module for ACS880 Cabinet-built industrial drives. 1 After viewing this presentation you will be able to describe: The functionality of cabinet-built

More information

SINUMERIK Safety Integrated. Possible Encoder Connections

SINUMERIK Safety Integrated. Possible Encoder Connections SINUMERIK Safety Integrated Possible Encoder Connections siemens.de/safety 1-encoder Safety Servomotor / spindle motor / torque motor SMI DQI 1FW motors 1FW motors 1FW motors Motor with analog interface

More information

EXPERIENCES FROM MODEL BASED DEVELOPMENT OF DRIVE-BY-WIRE CONTROL SYSTEMS

EXPERIENCES FROM MODEL BASED DEVELOPMENT OF DRIVE-BY-WIRE CONTROL SYSTEMS EXPERIENCES FROM MODEL BASED DEVELOPMENT OF DRIVE-BY-WIRE CONTROL SYSTEMS Per Johannessen 1, Fredrik Törner 1 and Jan Torin 2 1 Volvo Car Corporation, Department 94221, ELIN, SE-405 31 Göteborg, SWEDEN;

More information

ACT20X-(2)HTI-(2)SAO Temperature/mA converter. Safety Manual

ACT20X-(2)HTI-(2)SAO Temperature/mA converter. Safety Manual ACT20X-(2)HTI-(2)SAO Temperature/mA converter Safety Manual 1.1 Revision history Version Date Change 00 04/2014 First Edition 01 11/2017 Products added 1.2 Validity This manual is valid for the following

More information

Testing for the Unexpected Using PXI

Testing for the Unexpected Using PXI Testing for the Unexpected Using PXI An Automated Method of Injecting Faults for Engine Management Development By Shaun Fuller Pickering Interfaces Ltd. What will happen if a fault occurs in an automotive

More information

ET 200SP distributed I/O system SIMATIC. ET 200SP ET 200SP distributed I/O system. Preface. Product overview. Application planning 2.

ET 200SP distributed I/O system SIMATIC. ET 200SP ET 200SP distributed I/O system. Preface. Product overview. Application planning 2. Preface Product overview 1 SIMATIC ET 200SP Product Information Application planning 2 Installation 3 Connecting 4 Configuring 5 Maintenance 6 Technical specifications 7 Accessories/spare parts 8 Translation

More information

ST (6ES7132-6FD00-0BB1)

ST (6ES7132-6FD00-0BB1) SIMATIC ET 200SP Digital output module DQ 4x24..230VAC/2A ST (6ES7132-6FD00-0BB1) Manual Edition 02/2014 Answers for industry. DQ 4x24..230VAC/2A ST Preface Guide to documentation 1 SIMATIC ET 200SP DQ

More information

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility. An OCPP Energy Service Platform based on IoT

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility. An OCPP Energy Service Platform based on IoT European Conference on Nanoelectronics and Embedded Systems for Electric Mobility ecocity emotion 24-25 th September 2014, Erlangen, Germany An OCPP Energy Service Platform based on IoT Ángeles Rodríguez

More information

SIMATIC. Process Control System PCS 7 Compendium Part D - Operation and Maintenance (V8.2) Security information 1. Preface 2

SIMATIC. Process Control System PCS 7 Compendium Part D - Operation and Maintenance (V8.2) Security information 1. Preface 2 Security information 1 Preface 2 SIMATIC Process Control System PCS 7 Compendium Part D - Operation and Maintenance (V8.2) Operating Manual Installing updates and service packs 3 What's new? 4 Replacing

More information

Notes U695. (1) Vehicle power supply must meet the normal operating voltage, such as

Notes U695. (1) Vehicle power supply must meet the normal operating voltage, such as STATEMENT (1) This manual is designed for the U695 product, any company or individual are not permit to replicate and backup it in any form if they don't have the authority license from UIFTECH CO., LTD

More information

On Design for Reliability

On Design for Reliability On Design for Reliability of Electronics in Nanosatellite Olga Mamoutova (presenter) Andrey Antonov Peter the Great St. Petersburg State Polytechnic University, Russia Dpt. of Computer Systems & Software

More information

SCADA Software. 3.1 SCADA communication architectures SCADA system

SCADA Software. 3.1 SCADA communication architectures SCADA system 3 SCADA Software 3.1 SCADA communication architectures 3.1.1 SCADA system A supervisory control and data acquisition (SCADA) system means a system consisting of a number of remote terminal units (RTUs)

More information

Operation and Settings of CPU & Power Modules, series 9440

Operation and Settings of CPU & Power Modules, series 9440 Operating Instructions Operation and Settings of CPU & Power Modules, series 9440 Operation and Settings of CPU & Power Modules, series 9440 R. STAHL SCHALTGERÄTE GMBH Am Bahnhof 30 D-74638 Waldenburg

More information

Options for ABB drives. User s manual Emergency stop, stop category 0 (option +Q951) for ACS880-07/17/37 drives

Options for ABB drives. User s manual Emergency stop, stop category 0 (option +Q951) for ACS880-07/17/37 drives Options for ABB drives User s manual Emergency stop, stop category 0 (option +Q951) for ACS880-07/17/37 drives List of related manuals Drive hardware manuals and guides ACS880-07 drives (560 to 2800 kw)

More information

IMPLEMENTATION OF SENSOR DIAGNOSIS BASED ON AUTOSAR

IMPLEMENTATION OF SENSOR DIAGNOSIS BASED ON AUTOSAR International Journal of Latest Trends in Engineering and Technology Vol.(8)Issue(3), pp.215-221 DOI: http://dx.doi.org/10.21172/1.83.032 e-issn:2278-621x IMPLEMENTATION OF SENSOR DIAGNOSIS BASED ON AUTOSAR

More information

Intelligent Middleware. Smart Embedded Management Agent. Cloud. Remote Management and Analytics. July 2014 Markus Grebing Product Manager

Intelligent Middleware. Smart Embedded Management Agent. Cloud. Remote Management and Analytics. July 2014 Markus Grebing Product Manager Intelligent Middleware Smart Embedded Management Agent + Cloud Remote Management and Analytics July 2014 Markus Grebing Product Manager Smart Embedded Management Agent SEMA The intention of SEMA Device

More information

STMicroelectronics Automotive MCU Technical Day

STMicroelectronics Automotive MCU Technical Day STMicroelectronics Automotive MCU Technical Day 意法半导体汽车微控制器技术日 ETAS Embedded SW and Embedded Security Solutions 2017 年 ST 汽车 MCU 技术日 2017 年 6 月 6 日, 上海 2017 年 6 月 8 日, 深圳 2017 年 6 月 13 日, 北京 Embedded SW

More information

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. CCU Universal Module Application Module

Drive Technology \ Drive Automation \ System Integration \ Services. Manual. CCU Universal Module Application Module Drive Technology \ Drive Automation \ System Integration \ Services Manual CCU Universal Module Application Module Edition 05/2011 17061210 / EN SEW-EURODRIVE Driving the world Contents Contents 1 General

More information

DEPENDABLE PROCESSOR DESIGN

DEPENDABLE PROCESSOR DESIGN DEPENDABLE PROCESSOR DESIGN Matteo Carminati Politecnico di Milano - October 31st, 2012 Partially inspired by P. Harrod (ARM) presentation at the Test Spring School 2012 - Annecy (France) OUTLINE What?

More information