AURIX After-Lunch-Seminar Performance meets Safety. Safety & Security with professional Software-Components. Björn Assmann (Hitex GmbH)

Size: px
Start display at page:

Download "AURIX After-Lunch-Seminar Performance meets Safety. Safety & Security with professional Software-Components. Björn Assmann (Hitex GmbH)"

Transcription

1 Building a safe and secure embedded world AURIX After-Lunch-Seminar Performance meets Safety Safety & Security with professional Software-Components Björn Assmann (Hitex GmbH)

2 Agenda 14:00 Begrüßung und Einführung 14:15 AURIX TM Family Überblick (EBV) 14:35 Performance meets Safety mit AURIX Mikrocontrollern (Infineon) 15:30 Mit neuen Werkzeugen sicher ans Ziel (Tasking) 16:10 Kaffeepause 16:30 Modellbasierte Entwicklung mit AURIX (Hitex) 16:50 Safety & Security mit professionellen Software-Komponenten (Hitex) 17:35 PDH* Angebot am Beispiel erfolgreicher Kundenprojekte (Hitex) 18:00 Abschluss mit Expertentalk bei Drinks und Fingerfood *Hitex ist AURIX Preferred Design House 2

3 Table of content Introduction & Overview about Safety and Security Demands of the standards and failure types Low Level Driver and embedded real-time OS Infineon SafeTlib Aurix 1G SafeTlib Aurix 1G integration service by Hitex Outlook about Hitex SafeTpack Aurix 2G Summary 3

4 Sicherheit What is Security and Safety? Security Protect the System against unauthorized external influence Safety Avoid harm and injuries caused by malfunctioning of the System Security Safe and Secure System Safety 4

5 Functional safety definition Functional safety is about absence of unreasonable risk due to hazards caused by malfunctioning behaviour of E/E systems Hazards: potential source of harm Harm: physical injury or damage to the health of persons Failures are the main impairment to safety: Systematic failures: failure, related in a deterministic way to a certain cause, that can only be eliminated by a change of the design or of the manufacturing process, operational procedures, documentation or other relevant factors Random HW failures: failure that can occur unpredictably during the lifetime of a hardware element and that follows a probability distribution 5

6 Systematic Failures vs. Random Failures Systematic-Inherently Unsafe Random-Sometimes Unsafe 6

7 Safety Standards IEC61508 Electrical, electronic and programmable electronic systems IEC Household appl. IEC Medical IEC 501xx Railway ISO13849 Machinery ISO26262 Automotive 7

8 Safety Standards IEC61508 Electrical, electronic and programmable electronic systems SIL 1 SIL 2 SIL 3 SIL 4 IEC Household appl. IEC Medical IEC 501xx Railway ISO13849 Machinery ISO26262 Automotive Class A Class B Class C Cat 1 Cat 2 Cat 3 PL A PL B PL C PL D ASIL A ASIL B ASIL C ASIL D 8

9 Demands of the standards (Safety) Analyse failures Reduction of failures to fulfil Safety Integrity Level Reduction of systematically failures Reduction of random failures 9

10 Demands of the standards (Systematically failures) In all stages of the development process measures have to be planned executed and documented to manage verify and assess functional safety. V-Model approach Traceability 10

11 Demands of the standards (Statistical failures) Total failure rate λ total Safe λ S Detected Undetected λ SD λ SU Dangerous λ D Detected Undetected λ DD λ DU The proportion of safe failures (Safe Failure Fraction SFF) describes the proportion of safe failures towards the total failure rate of a subsystem. SFF = Σλ S + Σλ DD Σλ total = 1 Σλ DU Σλ total The diagnostic coverage (DC) describes how many dangerous failures can be detected. DC = 1 Σλ DU Σλ D = λ DD λ D 11

12 Demands of the standards (Statistical failures) Dangerous Undetectable Failures Dangerous Detectable Failures Safe Failures Dangerous Undetectable Failures λ DU Dangerous Detectable Failures λ DD The proportion of safe failures (Safe Failure Fraction SFF) describes the proportion of safe failures towards the total failure rate of a subsystem. SFF = Σλ S + Σλ DD Σλ total = 1 Σλ DU Σλ total The diagnostic coverage (DC) describes how many dangerous failures can be detected. DC = 1 Σλ DU Σλ D = λ DD λ D 12

13 Demands of the standards (Statistical failures) Failures in time Failures 1 FIT = 10 9 Hours SIL Level PFH [failure h] ASIL Level PMHF [failure h] SIL to < 10 8 ASIL D < 10 8 SIL to < 10 7 ASIL C < 10 7 SIL to < 10 6 ASIL B < 10 7 SIL to < 10 5 ASIL A No requirements 13

14 Risk Reduction to fulfil Safety Integrity Level Product without any safety measures With Safety Measure 1 With Safety Measure 2 With Safety Measure 3 With Safety Measure 4 Necessary minimal risk reduction With Safety Measure 5 With Safety Measure With Safety Measure n 0Risk Tolerable Risk Actual risk reduction Residual Risk Copyright Hitex GmbH All rights reserved. 14

15 Safety Mechanism Overview Safety Element out of Context (SEooC) Safety System/Item Safety Mechanisms Hardware Safety Mechanisms (AoU) Assumptions of Use 15

16 Safety Mechanism Definition & Classification Safety mechanism = Technical solution to detect faults or control failures in order to achieve or maintain a safe state. Measures to avoid faults Measures to control faults Safety mechanism effective within the element (Structural & Functional Measures) Safety measurers applied during development of element (Procedural Measures) Safety mechanisms are classified as: Hardware safety mechanism [HW] Assumptions of Use [AoU] 16

17 Safety Mechanism [SM1] & [SM2] Safety mechanisms are also classified as: Mechanisms to mitigate single point and residual faults [SM1] Supports the Single-Point fault Metric Usually carried out continuously / repeated cyclically ASIL B ASIL C ASIL D Single-Point Fault Metric 90% 97% 99% Mechanisms to avoid dual faults from being latent [SM2] Supports the Latent-Fault Metric Usually carried out once per driving cycle ASIL B ASIL C ASIL D Latent-Fault Metric 60% 80% 90% 17

18 Fault classification Fault Potential to violate a Fault in a no yes Potential to violate a no safety goal only in no safety related safety goal? combination with an element? independent fault? yes yes no Safety mechanism in place? yes Potential to violate a safety goal only in combination with 2 independent faults? yes no no Violation of safety goal prevented? yes yes Failure prevented from being latent? yes Failure prevented from being latent? no no No Part (Safe) SPF (Single Point Fault) RF (Residual Fault) DPF det. (Detected Dual-Point Fault) DPF lat. (Latent Dual-Point Fault) MPF det. (Detected Multiple Point Fault) MPF lat. (Latent Multiple Point Fault) Safe 18

19 Safety Mechanism Naming convention To identify these properties, following conventions are followed by Infineon documents: SM1/2[HW/AoU].<Part Name>:<Safety Mechanism> Example 1 SM1[HW].CPU:LOCKSTEP Lockstep architecture to detect errors in CPU Example 2 SM2[AoU].CPU:LOCKSTEP.ALARM_TEST Testing of LSCU by fault injection Example 3 SM1[HW].SRI:CLKMON SRI Clock frequency monitor Example 4 SM2[AoU].CLK:CLKMON Testing of Clock frequency monitor Short outlook to SafeTlib: The SafeTlib software implements several AoUs SafeTlib provides tests to ensure the integrity of the safety mechanisms of the vital parts 19

20 Reflexion for customer Problem 1: How to fulfil the demand safety integrity level? How to fulfil all AoU during software development for Infineon AURIX? Problem 2: Effort (Time & Costs) T Safety Critical Code = 2 4 T Non Safety Critical Code Source: The Industrial Take-up Formal Methods in Safety-Critical and other Areas: A Perspective Jonathan Bowen (University Oxford) and Voictoria Stavridou (University of London) 20

21 Solutions and Products from Hitex

22 Low Level Drivers Only drivers for safety or security critical peripherals have to be developed according to process Access to peripherals needed by the SafeTlib is included in the SafeTlib Write from scratch AURIX User Manual is extensive Relations of peripherals may be complex If development process needed big effort AURIX Experts can do it faster 22

23 Low Level Drivers Only drivers for safety or security critical peripherals have to be developed according to process Access to peripherals needed by the SafeTlib is included in the SafeTlib Write from scratch Use free illd drivers Easier to understand than User Manual Examples available No safety documentation like specification and validation documents 23

24 Low Level Drivers Only drivers for safety or security critical peripherals have to be developed according to process Access to peripherals needed by the SafeTlib is included in the SafeTlib Write from scratch Use free illd drivers Buy MCAL drivers AUTOSAR compatible Developed according to ISO26262 ASIL B BASE Package, MEM Package, COM Package, COM enhanced Package, LIB Package, CDT Package Configuration with TRESOS Studio Configuration and Integration Service offered by Hitex 24

25 Low Level Drivers Only drivers for safety or security critical peripherals have to be developed according to process Access to peripherals needed by the SafeTlib is included in the SafeTlib Write from scratch Use free illd drivers Buy MCAL drivers Buy Hitex industrial drivers Developed according to ISO26262 ASIL B & IEC61508 Full validation on request Available for MCU, IO, ADC, GTM, MultiCan, Quad Encoder, Hall Encoder, QSPI, ASC 25

26 RTOS, SAFERTOS, Real-time OS

27 RTOS, SAFERTOS, Real-time OS Product RTOS SAFERTOS RTOS PXROS Comment RTOS is a key part of the application and dividing safe and unsafe components, provides an scheduler and RTOS Objects but has to be save! And you have to designed and validated by yourself. SAFERTOS is a safety certified Real Time Operating System and based on FreeRTOS, but pre-certified for ISO ASIL D and also for IEC SIL 3 by TÜV SÜD. Each core has an instance of SAFERTOS Deployment of tasks at build time Message Queues and Semaphores are intercore compatible Professional certified PXROS One RTOS for all cores Dynamical optimization of tasks during runtime 27

28 MCAL Drivers Infineon MC-ISAR Packages

29 MCU WDG GPT FLS RAM TEST SPI LIN CAN FlexRay PORT DIO ICU PWM ADC SCI MEM Check FADC... AUTOSAR MCAL Driver for AURIX Family MC-ISAR Product Overview Application Layer MC-ISAR: MicroController Infineon Software Architecture System Services On-Board Device Abstraction AUTOSAR Run Time Enviroment (RTE) Memory Services Memory Abstraction Communication Services Communication Abstraction I/O Hardware Abstraction Complex Device Driver MC-ISAR: MCU, WDG, GPT, SPI, PORT, DIO, ICU, PWM, ADC MC-ISAR COM Basic: CAN, CanTrcv, LIN MC-ISAR COM Enhanced: FlexRay, Ethernet MC-ISAR MEM: FLASH, FEE MC-ISAR MCAL CD: SCI, MEMCheck, FADC, etc. for TriCore MCAL Microcontroller AUTOSAR in production since 2009 Infineon MC-ISAR driver (MicroController Infineon Software ARchitecture) Enabled via partners 29

30 Infineon SafeTlib A1G

31 SafeTlib Reduction of dangerous statistical errors AURIX MCU 32

32 SafeTlib Reduction of dangerous statistical errors HW Safety Mechanisms AURIX MCU 33

33 SafeTlib Reduction of dangerous statistical errors Assumptions of use HW Safety Mechanisms AURIX MCU 34

34 SafeTlib Reduction of dangerous statistical errors PRO-SIL SafeTlib Assumptions of use HW Safety Mechanisms AURIX MCU 35

35 SafeTlib Reduction of dangerous statistical errors Documentation PRO-SIL SafeTlib Assumptions of use HW Safety Mechanisms AURIX MCU 36

36 Hardware vs. SafeTlib & Safety Mechanism

37 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller AURIX MCU Peripheral A RAM FLASH Peripheral C Peripheral B CPU Peripheral D Clock Power CAN SMU other systems 38

38 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller Safe computing ensured by delayed Lockstep CPU with diverse Layout AURIX MCU Peripheral A RAM FLASH Peripheral C Peripheral B CPU Peripheral D Clock Power CAN SMU other systems 39

39 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller Safe computing ensured by delayed Lockstep CPU with diverse Layout Peripheral A AURIX MCU RAM FLASH Safe data and code storage ensured by ECC (DEDSEC for SRAM, TEDDEC for FLASH), Address Peripheral Monitoring C and Memory Protection Unit Peripheral B CPU Peripheral D Clock Power CAN SMU other systems 40

40 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller Safe intra chip communication ensured by E2E monitoring for data and address failures using ECC on SRI Bus Peripheral A AURIX MCU RAM FLASH Safe computing ensured by delayed Lockstep CPU with diverse Layout Safe data and code storage ensured by ECC (DEDSEC for SRAM, TEDDEC for FLASH), Address Peripheral Monitoring C and Memory Protection Unit Peripheral B CPU Peripheral D Clock Power CAN SMU other systems 41

41 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller Safe intra chip communication ensured by E2E monitoring for data and address failures using ECC on SRI Bus Peripheral A AURIX MCU RAM FLASH Safe computing ensured by delayed Lockstep CPU with diverse Layout Safe data and code storage ensured by ECC (DEDSEC for SRAM, TEDDEC for FLASH), Address Peripheral Monitoring C and Memory Protection Unit Peripheral B CPU Peripheral D Configurable error reaction/handling and Fault Signaling on FSP Pin Clock Power CAN SMU other systems 42

42 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller Safe intra chip communication ensured by E2E monitoring for data and address failures using ECC on SRI Bus Peripheral A AURIX MCU RAM FLASH Safe computing ensured by delayed Lockstep CPU with diverse Layout Safe data and code storage ensured by ECC (DEDSEC for SRAM, TEDDEC for FLASH), Address Peripheral Monitoring C and Memory Protection Unit Peripheral B Frequency range monitoring Power Supply range monitoring CPU Peripheral D Configurable error reaction/handling Clock Power CAN SMU other systems 43

43 Analog /digital Inputs Analog /digital outputs AURIX Safety Microcontroller Hardware safety mechanisms like CRC and Timestamp for DMA AURIX MCU Peripheral A RAM FLASH Peripheral C Peripheral B CPU Peripheral D Clock Power CAN Application safety mechanisms keywords: SMU - Redundancy - Plausibility Checks - E2E Protection other systems 44

44 Safety Concept with external Watchdog Communication Redundant Data Input AURIX Data Output Sensor System Diagnostic application dependent input Safe computation application dependent output Diagnostic Actuator System TLF35584 Safety Mechanism Power Supply Monitor Power Supply SMU Watchdog + Error Pin Monitor SPI/IO SMU ErrorPin Safety Path Control #2 Clock Safety Path Control 45

45 Safety Concept with external Watchdog Communication Redundant Data Input AURIX Data Output Sensor System Voltage Monitoring to detect under and Diagnostic over voltage of the external supply application dependent input Safe computation application dependent output Diagnostic Actuator System TLF35584 Safety Mechanism Power Supply Monitor Power Supply SMU Watchdog + Error Pin Monitor SPI/IO SMU ErrorPin Safety Path Control #2 Clock Safety Path Control 46

46 Safety Concept with external Watchdog Communication Redundant Data Input AURIX Data Output Sensor System Voltage Monitoring to detect under and Diagnostic over voltage of the external supply application dependent input Safe computation application dependent output Diagnostic Actuator System TLF35584 Power Supply Monitor Power Supply Safety Mechanism Time Window Watchdog for detection of common cause failures SMU Watchdog + Error Pin Monitor SPI/IO SMU ErrorPin Safety Path Control #2 Clock Safety Path Control 47

47 Safety Concept with external Watchdog Communication Redundant Data Input AURIX Data Output Sensor System Voltage Monitoring to detect under and Diagnostic over voltage of the external supply application dependent input Safe computation application dependent output Diagnostic Actuator System TLF35584 Power Supply Monitor Power Supply Safety Mechanism Time Window Watchdog for detection of common cause failures SMU Monitoring of FSP to perform a reaction in case that FSP enters the fault state Watchdog + Error Pin Monitor SPI/IO SMU ErrorPin Safety Path Control #2 Clock Safety Path Control 48

48 SafeTlib and HW Safety Measures vs. Faults SPF (Single Point Fault) detection: Lockstep CPU, ECC/EDC on memories and buses, redundant peripherals, SFR Test, SBST (Software Based Self-Test) for TriCore CPU LF (Latent Fault) detection: HW BIST, SBST CCF (Common Cause Fault) mitigation: Clock and voltage monitors, layout diversity, functional diversity, multiple watchdogs SafeTlib Set of software functions for self test of safety relevant hardware and HW safety measures Test routines to verify error reporting capability of HW Safety Measures 49

49 SafeTlib Components Common Modules Test Handler SMU driver Safe Watchdog Interface Example Watchdog Manager Test Manager Startup Sequence 50

50 Infineon Pro-SIL SafeTlib Package Upper Layer RefApp External Device Control Safe Watchdog Manager (SafeWdgM) Test Manager (TstM) Safe Watchdog Interface (SafeWdgIf) Internal Watchdog Driver (SafeWdgInt) SafeWdgCD External TLF35584 Watchdog Driver (SafeWdgExtTlf) QSPI Driver for External Watchdog (SafeWdgQspi) External CIC61508 Watchdog Driver (SafeWdgExtCic) ASCLIN Driver For External Watchdog (SafeWdgAscLin) Microcontroller Test Library (MicroTestLib) SafeTlibCD Test Handler (TestHandler) SMU Driver (SMU) BSW SPB, Core, SCU, SMU, Safety WDT QSPI ASCLIN LBIST, MBIST, PFLASH, SRAM, IR, SMU DMA, IOM, SFF, LMU, PMU, SRI Microcontroller 51

51 Infineon SafeTlib Hitex integration for customer

52 Hitex SafeTlib A1G Integration for customer Software: Check preconditions and prepare system for SafeTlib execution Callback functions for several detected failures IFX TLF35584 or Aurix internal safety watchdog configuration and cyclic servicing Multicore support 53

53 Hitex SafeTlib A1G Integration Framework 54

54 Hitex SafeTpack for Aurix 2G

55 Hitex SafeTpack A2G Outlook AURIX 2G does not need the SafeTlib MicroTest library but You still need to: Manage the TLF35584 safety watchdog Manage the internal watchdogs Run the LBIST, MBIST, MONBIST Run ASIL-D checks of critical SFRs Run the CPU and SPU SBSTs Host the AoU (Assumption of Use) functions Handle safety-relevant errors Hitex A2G SafeTpack These functions have a huge effect on the overall SPFM (Single Point Fault Metric), LFM (Latent Fault Metric) and FIT rate of the system. 56

56 Inside A2G SafeTpack 57

57 Summary

58 Summary AURIX has a complete environment feasible for safety and security Aurix hardware is designed for safety Functional safety has high demands on development cycle and microcontroller tests Make or buy decision is influenced by safety and security demands AURIX safety and security experts are increasing speed and reliability 63

59 Stay in contact with us Beray Yilmaz Account Manager PDH & Middleware Tel Fax Your personal contact Dr. Kurt Böhringer Head of Engineering Tel Fax Michael Weiß Senior Account Manager Embedded Solutions Tel Fax

What functional safety module designers need from IC developers

What functional safety module designers need from IC developers What functional safety module designers need from IC developers Embedded Platforms Conference Microcontrollers and Peripherals Nov 9 th 2016 14:50 15:30 TOM MEANY Introduction This presentation gives a

More information

Functional Safety on Multicore Microcontrollers for Industrial Applications. Thomas Barth (h-da) Prof. Dr.-Ing. Peter Fromm (h-da)

Functional Safety on Multicore Microcontrollers for Industrial Applications. Thomas Barth (h-da) Prof. Dr.-Ing. Peter Fromm (h-da) Functional Safety on Multicore Microcontrollers for Industrial Applications Thomas Barth (h-da) Prof. Dr.-Ing. Peter Fromm (h-da) Contents Functional Safety Multicore Motivation ISO13849 Implemented Software

More information

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309 June 25th, 2007 Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309 Christopher Temple Automotive Systems Technology Manager Overview Functional Safety Basics Functional

More information

FUNCTIONAL SAFETY AND THE GPU. Richard Bramley, 5/11/2017

FUNCTIONAL SAFETY AND THE GPU. Richard Bramley, 5/11/2017 FUNCTIONAL SAFETY AND THE GPU Richard Bramley, 5/11/2017 How good is good enough What is functional safety AGENDA Functional safety and the GPU Safety support in Nvidia GPU Conclusions 2 HOW GOOD IS GOOD

More information

Functional Safety on Multicore Microcontrollers for Industrial Applications

Functional Safety on Multicore Microcontrollers for Industrial Applications Functional Safety on Multicore Microcontrollers for Industrial Applications Thomas Barth Department of Electrical Engineering Hochschule Darmstadt University of Applied Sciences Darmstadt, Germany thomas.barth@h-da.de

More information

Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, ColdFire+, C- Ware, the Energy Efficient Solutions logo, Kinetis,

Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, ColdFire+, C- Ware, the Energy Efficient Solutions logo, Kinetis, July 19, 2013 Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, ColdFire+, C- Ware, the Energy Efficient Solutions logo, Kinetis, mobilegt, PEG, PowerQUICC, Processor Expert,

More information

Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation

Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation Prof. Dr.-Ing. Stefan Kowalewski Chair Informatik 11, Embedded Software Laboratory RWTH Aachen University Summer Semester

More information

Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems

Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems Kyung-Jung Lee, Young-Hun Ki, and Hyun-Sik Ahn Abstract In this paper, we propose a hardware and software design method

More information

ISO meets AUTOSAR - First Lessons Learned Dr. Günther Heling

ISO meets AUTOSAR - First Lessons Learned Dr. Günther Heling ISO 26262 meets AUTOSAR - First Lessons Learned Dr. Günther Heling Agenda 1. ISO 26262 and AUTOSAR Two Basic Contradictions Top-Down vs. Reuse Concentration vs. Distribution 2. Approach Mixed ASIL System

More information

Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, C-Ware, t he Energy Efficient Solutions logo, mobilegt, PowerQUICC,

Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, C-Ware, t he Energy Efficient Solutions logo, mobilegt, PowerQUICC, Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, C-Ware, t he Energy Efficient Solutions logo, mobilegt, PowerQUICC, QorIQ, StarCore and Symphony are trademarks of Freescale

More information

Adaptive AUTOSAR: Infrastructure Software for Advanced Driver Assistance. Chris Thibeault June 7, 2016

Adaptive AUTOSAR: Infrastructure Software for Advanced Driver Assistance. Chris Thibeault June 7, 2016 Adaptive : Infrastructure Software for Advanced Driver Assistance Chris Thibeault June 7, 2016 Agenda for Adaptive Platform Introduction Goals for the presentation What is the Adaptive Platform? Why do

More information

Deriving safety requirements according to ISO for complex systems: How to avoid getting lost?

Deriving safety requirements according to ISO for complex systems: How to avoid getting lost? Deriving safety requirements according to ISO 26262 for complex systems: How to avoid getting lost? Thomas Frese, Ford-Werke GmbH, Köln; Denis Hatebur, ITESYS GmbH, Dortmund; Hans-Jörg Aryus, SystemA GmbH,

More information

AUTOSAR stands for AUTomotive Open Systems ARchitecture. Partnership of automotive Car Manufacturers and their Suppliers

AUTOSAR stands for AUTomotive Open Systems ARchitecture. Partnership of automotive Car Manufacturers and their Suppliers Introduction stands for AUTomotive Open Systems ARchitecture Electronic Control Unit Partnership of automotive Car Manufacturers and their Suppliers Source for ECU: Robert Bosch GmbH 2 Introduction Members

More information

Driver Assistance Pushes New Flash Functionalities

Driver Assistance Pushes New Flash Functionalities Driver Assistance Pushes New Flash Functionalities Anil Gupta Technical Executive Winbond Electronics Corporation Santa Clara, CA 1 Automotive and ADAS terminology ECC use to increase reliability of Flash

More information

Is This What the Future Will Look Like?

Is This What the Future Will Look Like? Is This What the Future Will Look Like? Implementing fault tolerant system architectures with AUTOSAR basic software Highly automated driving adds new requirements to existing safety concepts. It is no

More information

FUNCTIONAL SAFETY FOR INDUSTRIAL AUTOMATION

FUNCTIONAL SAFETY FOR INDUSTRIAL AUTOMATION FUNCTIONAL SAFETY FOR INDUSTRIAL AUTOMATION 2017.11 The term Functional Safety has become a topic of great interest. Functional Safety generally means that malfunctions of the operating systems or applications

More information

Type 9160 / Transmitter supply unit / Isolating repeater. Safety manual

Type 9160 / Transmitter supply unit / Isolating repeater. Safety manual Type 9160 / 9163 Transmitter supply unit / Isolating repeater Safety manual Safety manual English Content 1 General information... 3 1.1 Manufacturer... 3 1.2 Information regarding the Safety Manual...

More information

Arccore AB 2017, all rights reserved. Accelerating innovation

Arccore AB 2017, all rights reserved. Accelerating innovation 2017-03-02 Arccore AB 2017, all rights reserved Accelerating innovation ARCCORE in brief Independent vendor of automotive-sw with focus on AUTOSAR Integration, adaptation and service Incorporated 2009

More information

88 Dugald Campbell. Making Industrial Systems Safer Meeting the IEC standards

88 Dugald Campbell. Making Industrial Systems Safer Meeting the IEC standards 88 Dugald Campbell Making Industrial Systems Safer Meeting the IEC 60730 standards Introduction With the introduction of the International Electrotechnical Commission s IEC 60730 standards series, household

More information

Isolation of Cores. Reduce costs of mixed-critical systems by using a divide-and-conquer startegy on core level

Isolation of Cores. Reduce costs of mixed-critical systems by using a divide-and-conquer startegy on core level Isolation of s Reduce costs of mixed-critical systems by using a divide-and-conquer startegy on core level Claus Stellwag, Elektrobit Automotive GmbH; Thorsten Rosenthal, Delphi; Swapnil Gandhi, Delphi

More information

Software integration challenge multi-core experience from real world projects

Software integration challenge multi-core experience from real world projects Software integration challenge multi-core experience from real world projects Rudolf Grave 17.06.2015 Agenda About EB Automotive Motivation Constraints for mapping functions to cores AUTOSAR & MultiCore

More information

FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO SPEAKER. Dept. of Electrical Engineering, National Taipei University

FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO SPEAKER. Dept. of Electrical Engineering, National Taipei University FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO-26262 Kuen-Long Lu 1, 2,Yung-Yuan Chen 1, and Li-Ren Huang 2 SPEAKER 1 Dept. of Electrical Engineering, National Taipei University 2

More information

Type Switching repeater. Safety manual

Type Switching repeater. Safety manual Type 9170 Switching repeater Safety manual Safety manual English Content 1 General information... 3 1.1 Manufacturer... 3 1.2 Information regarding the Safety Manual... 3 1.3 Area of application... 3 1.4

More information

Virtual Hardware ECU How to Significantly Increase Your Testing Throughput!

Virtual Hardware ECU How to Significantly Increase Your Testing Throughput! Virtual Hardware ECU How to Significantly Increase Your Testing Throughput! Elektrobit Tech Day Jason Niatas Synopsys Inc. July 27, 2017 2017 Synopsys, Inc. 1 Agenda Automotive electronic evolution and

More information

A tool based estimation computation method of MCU random failure rate &functional safety metrics

A tool based estimation computation method of MCU random failure rate &functional safety metrics A tool based estimation computation method of MCU random failure rate &functional safety metrics Yogitech / Texas Instruments Riccardo Mariani YOGITECH, CTO Hoiman Low TI Safety MCU, FSCAE July / 2015

More information

Service & Support. Functional Safety One Position switch. Safe Machine Concepts without Detours. benefit from the Safety Evaluation Tool.

Service & Support. Functional Safety One Position switch. Safe Machine Concepts without Detours. benefit from the Safety Evaluation Tool. Cover Sheet Functional Safety One Position switch SIRIUS 3SE5 FAQ November 2010 Safe Machine Concepts without Detours benefit from the Safety Evaluation Tool. Service & Support Answers for industry. Question

More information

Taking the Right Turn with Safe and Modular Solutions for the Automotive Industry

Taking the Right Turn with Safe and Modular Solutions for the Automotive Industry Taking the Right Turn with Safe and Modular Solutions for the Automotive Industry A Time-Triggered Middleware for Safety- Critical Automotive Applications Ayhan Mehmet, Maximilian Rosenblattl, Wilfried

More information

PLUS+1 SC Controller SC0XX-1XX Controller Family

PLUS+1 SC Controller SC0XX-1XX Controller Family MAKING MODERN LIVING POSSIBLE Safety Manual PLUS+1 SC Controller SC0XX-1XX Controller Family powersolutions.danfoss.com Revision history Table of revisions Date Changed Rev December 2014 First edition

More information

Functional Safety Design Packages for STM32 & STM8 MCUs

Functional Safety Design Packages for STM32 & STM8 MCUs Functional Safety Design Packages for STM32 & STM8 MCUs Achieve functional safety certifications with ST MCUs With its Functional Safety Design Packages based on robust built-in MCU safety features, ST

More information

How Microcontrollers help GPUs in Autonomous Drive

How Microcontrollers help GPUs in Autonomous Drive How Microcontrollers help GPUs in Autonomous Drive GTC 2017 Munich, 2017-10-12 Hans Adlkofer, VP Automotive System department Outline 1 Main Safety concepts 2 Sensor Fusion architecture and functionalities

More information

Dr. Andreas Both / Zhang Enqin Automotive Runtime Software

Dr. Andreas Both / Zhang Enqin Automotive Runtime Software Nov 6, 2008 Getting Started with Freescale's AUTOSAR OS and Microcontroller Abstraction Layer (MCAL) Software Packages PA110 Dr. Andreas Both / Zhang Enqin Automotive Runtime Software owners. Freescale

More information

Functional Example AS-FE-I-013-V13-EN

Functional Example AS-FE-I-013-V13-EN Functional Example AS-FE-I-013-V13-EN SIMATIC Safety Integrated for Factory Automation Practical Application of IEC 62061 Illustrated Using an Application Example with SIMATIC S7 Distributed Safety Preliminary

More information

2 Control Equipment for General Applications

2 Control Equipment for General Applications Control Equipment for General Applications The use of electronic, programmable controls in mobile machines is becoming more and more important due to the ever increasing demands for functionality, efficiency

More information

Safety Manual. Vibration Control Type 663. Standard Zone-1-21 Zone Edition: English

Safety Manual. Vibration Control Type 663. Standard Zone-1-21 Zone Edition: English Safety Manual Vibration Control Type 663 Standard Zone-1-21 Zone-2-22 Edition: 21.06.2012 English Safety Manual Vibration Control Type 663 Standard Zone-1-21 Zone-2-22 Achtung! Before Start-Up Procedure

More information

SIRIUS Safety Integrated. Modular safety system 3RK3

SIRIUS Safety Integrated. Modular safety system 3RK3 Functional Example CD-FE-I-048-V10-EN SIRIUS Safety Integrated Modular safety system 3RK3 Emergency Stop with monitored Start and Protective Door with automatic start according to category 4 in EN 954-1.

More information

OPTISWITCH 5300C. Safety Manual. Vibrating Level Switch. Relay (2 x SPDT) With SIL qualification

OPTISWITCH 5300C. Safety Manual. Vibrating Level Switch. Relay (2 x SPDT) With SIL qualification OPTISWITCH 5300C Safety Manual Vibrating Level Switch Relay (2 x SPDT) With SIL qualification Contents Contents 1 Document language 2 Scope 2.1 Instrument version... 4 2.2 Area of application... 4 2.3

More information

Modern Computer Architecture. Lecture 12 embedded Applications, classical DSP, automotive (Tricore)

Modern Computer Architecture. Lecture 12 embedded Applications, classical DSP, automotive (Tricore) Modern Computer Architecture Lecture 12 embedded Applications, classical DSP, automotive (Tricore) Outline Lecture 12 Embedded Systems on a Chip Microcontrollers Digital Signal Processors (DSP) Applications:

More information

SPC5 MCAL overview. ZHANG Livia

SPC5 MCAL overview. ZHANG Livia SPC5 MCAL overview ZHANG Livia Senior Application Engineer, Micro BU ADG Marketing and Application Greater China & South Asia Region STMicroelectronics AUTOSAR Idea 2 Standardize the software architecture

More information

FSO Webnair FSO Safety Functions Module. ABB Group February 11, 2015 Slide 1

FSO Webnair FSO Safety Functions Module. ABB Group February 11, 2015 Slide 1 FSO Webnair FSO Safety Functions Module February 11, 2015 Slide 1 Competence Requirements for ABB Commissioner / Service Engineer of ACS880 Drives with FSO The integrated Safety Function Module (FSO; option

More information

Safety Manual for Qorivva MPC5643L Devices Supported: MPC5643L

Safety Manual for Qorivva MPC5643L Devices Supported: MPC5643L Safety Manual for Qorivva MPC5643L Devices Supported: MPC5643L (NOTE: Replaces the Safety Application Guide for MPC5643L MPC5643LSAG) MPC5643LSM Rev. 2 04/2013 How to Reach Us: Home Page: freescale.com

More information

Safety Manual VEGASWING 61, 63. Relay (DPDT) With SIL qualification. Document ID: 52082

Safety Manual VEGASWING 61, 63. Relay (DPDT) With SIL qualification. Document ID: 52082 Safety Manual VEGASWING 61, 63 Relay (DPDT) With SIL qualification Document ID: 52082 Contents Contents 1 Document language 2 Scope 2.1 Instrument version... 4 2.2 Area of application... 4 2.3 SIL conformity...

More information

XMC Class-B library software. September 2016

XMC Class-B library software. September 2016 XMC Class-B library software September 2016 Agenda 1 Overview for boot mode index in XMC1000 2 Key feature: built-in safety features in peripheral 3 Key feature: VDE certified software library 4 System

More information

Functional Safety for Electronic Control

Functional Safety for Electronic Control HYDAC ELECTRONIC Functional Safety for Electronic Control April 20, 2016 Speaker Eric Ringholm HYDAC ELECTRONIC Division Manager Component range for modern machines Software Product Range Agenda Functional

More information

Failure Diagnosis and Prognosis for Automotive Systems. Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010

Failure Diagnosis and Prognosis for Automotive Systems. Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010 Failure Diagnosis and Prognosis for Automotive Systems Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010 Automotive Challenges and Goals Driver Challenges Goals Energy Rising cost of petroleum

More information

Hardware safety integrity (HSI) in IEC 61508/ IEC 61511

Hardware safety integrity (HSI) in IEC 61508/ IEC 61511 1 Hardware safety integrity (HSI) in IEC 61508/ IEC 61511 ESReDA 2006 June 7-8, 2006 Mary Ann Lundteigen mary.a.lundteigen@ntnu.no mary.a.lundteigen@sintef.no 2 Overview 1. Objective 2. Some concepts &

More information

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility European Conference on Nanoelectronics and Embedded Systems for Electric Mobility ecocity emotion 24-25 th September 2014, Erlangen, Germany Scalable Functional Safety Architecture for Electric Mobility

More information

Vibrating Switches SITRANS LVL 200S, LVL 200E. Relay (DPDT) With SIL qualification. Safety Manual. Siemens Parts

Vibrating Switches SITRANS LVL 200S, LVL 200E. Relay (DPDT) With SIL qualification. Safety Manual. Siemens Parts Siemens Parts Vibrating Switches SITRANS LVL 200S, LVL 200E Relay (DPDT) With SIL qualification Safety Manual Contents 1 Document language 2 Scope 2.1 Instrument version... 4 2.2 Area of application...

More information

AN5013 Application note

AN5013 Application note Application note SPC584Cx/SPC58ECx FCCU fault sources and reaction Introduction This application note describes the FCCU input fault sources. Furthermore, for each of them, it describes how to verify the

More information

Original operating instructions Safety relay with relay outputs G1501S / / 2016

Original operating instructions Safety relay with relay outputs G1501S / / 2016 Original operating instructions Safety relay with relay outputs G50S UK 8023637 / 00 02 / 206 Contents Preliminary note...4. Symbols used...4 2 Safety instructions...5 3 Items supplied...6 4 Functions

More information

Proline Prowirl 72, 73

Proline Prowirl 72, 73 Functional Safety Manual Vortex flow measuring system with 4 20 ma output signal Application Monitoring of maximum and/or minimum flow in systems which are required to comply with particular safety system

More information

Handling Challenges of Multi-Core Technology in Automotive Software Engineering

Handling Challenges of Multi-Core Technology in Automotive Software Engineering Model Based Development Tools for Embedded Multi-Core Systems Handling Challenges of Multi-Core Technology in Automotive Software Engineering VECTOR INDIA CONFERENCE 2017 Timing-Architects Embedded Systems

More information

Hercules ARM Cortex -R4 System Architecture. Processor Overview

Hercules ARM Cortex -R4 System Architecture. Processor Overview Hercules ARM Cortex -R4 System Architecture Processor Overview What is Hercules? TI s 32-bit ARM Cortex -R4/R5 MCU family for Industrial, Automotive, and Transportation Safety Hardware Safety Features

More information

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis Failure Modes, Effects and Diagnostic Analysis Project: 9106 HART Transparent Repeater and 9107 HART Transparent Driver Customer: PR electronics A/S Rønde Denmark Contract No.: PR electronics 06/03-19

More information

Original operating instructions Safety relay with relay outputs with and without delay G1502S / / 2016

Original operating instructions Safety relay with relay outputs with and without delay G1502S / / 2016 Original operating instructions Safety relay with relay outputs with and without delay UK G50S 803638 / 00 0 / 06 Contents Preliminary note...4. Symbols used...4 Safety instructions...5 3 Items supplied...6

More information

SPC58NE84E7, SPC58NE84C3

SPC58NE84E7, SPC58NE84C3 SPC58NE84E7, SPC58NE84C3 32-bit Power Architecture microcontroller for automotive ASIL-D applications Data brief - preliminary data Features LFBGA292 (17 x 17 x 1.7 mm) elqfp176 (24 x 24 x 1.4 mm) Two

More information

New developments about PL and SIL. Present harmonised versions, background and changes.

New developments about PL and SIL. Present harmonised versions, background and changes. Safety evevt 2017 Functional safety New developments about PL and SIL. Present harmonised versions, background and changes. siemens.com ISO/ TC 199 and IEC/ TC 44 joint working group 1 - Merging project

More information

Safety Manual. VEGABAR series ma/hart - two-wire and slave sensors With SIL qualification. Document ID: 48369

Safety Manual. VEGABAR series ma/hart - two-wire and slave sensors With SIL qualification. Document ID: 48369 Safety Manual VEGABAR series 80 4 20 ma/hart - two-wire and slave sensors With SIL qualification Document ID: 48369 Contents Contents 1 Document language... 3 2 Scope... 4 2.1 Instrument version... 4 2.2

More information

New ARMv8-R technology for real-time control in safetyrelated

New ARMv8-R technology for real-time control in safetyrelated New ARMv8-R technology for real-time control in safetyrelated applications James Scobie Product manager ARM Technical Symposium China: Automotive, Industrial & Functional Safety October 31 st 2016 November

More information

Foundation Fieldbus Safety Instrumented System (FF SIS) FF-SIS Meeting. Hannover. April 21, 2004

Foundation Fieldbus Safety Instrumented System (FF SIS) FF-SIS Meeting. Hannover. April 21, 2004 Foundation Fieldbus Safety Instrumented System (FF SIS) FF-SIS Meeting Hannover April 21, 2004 1 Foundation Fieldbus Safety Instrumented System (FF SIS) Principles of Safety Related Bus-System and Protocols

More information

Functional safety manual RB223

Functional safety manual RB223 SD00011R/09/EN/13.13 71238251 Products Solutions Services Functional safety manual RB223 Passive barrier Application Galvanic isolation of active 0/4 to 20 ma signals from transmitters, valves and adjusters,

More information

DEPENDABLE PROCESSOR DESIGN

DEPENDABLE PROCESSOR DESIGN DEPENDABLE PROCESSOR DESIGN Matteo Carminati Politecnico di Milano - October 31st, 2012 Partially inspired by P. Harrod (ARM) presentation at the Test Spring School 2012 - Annecy (France) OUTLINE What?

More information

Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist

Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist Internet of Things Group 2 Internet of Things Group 3 Autonomous systems: computing platform Intelligent eyes Vision. Intelligent

More information

10 th AUTOSAR Open Conference

10 th AUTOSAR Open Conference 10 th AUTOSAR Open Conference Dr. Moritz Neukirchner Elektrobit Automotive GmbH Building Performance ECUs with Adaptive AUTOSAR AUTOSAR Nov-2017 Major market trends and their impact Trends Impact on E/E

More information

Products Solutions Services. Functional Safety. How to determine a Safety integrity Level (SIL 1,2 or 3)

Products Solutions Services. Functional Safety. How to determine a Safety integrity Level (SIL 1,2 or 3) Products Solutions Services Functional Safety How to determine a Safety integrity Level (SIL 1,2 or 3) Slide 1 Functional Safety Facts Agenda of the next 45 min SIL 1,2 or 3 Let s apply IEC61511 SIS, whats

More information

Safety-related controls SIRIUS Safety Integrated

Safety-related controls SIRIUS Safety Integrated Functional Example CD-FE-I-018-V30-EN Safety-related controls SIRIUS Safety Integrated with monitored start up to SIL 1 acc. to IEC 62061 and PL c acc. to ISO 13849-1 with a SIRIUS safety relay 3TK28 with

More information

Software Architecture for Secure ECUs. Rudolf Grave EB TechDay-June 2015

Software Architecture for Secure ECUs. Rudolf Grave EB TechDay-June 2015 Software Architecture for Secure ECUs Rudolf Grave EB TechDay-June 2015 Agenda No safety without security and vice versa Established Safety Concepts Safety Analysis Methods for Security Analysis Secure

More information

AS-i Safety Relay Output Module with Diagnostic Slave

AS-i Safety Relay Output Module with Diagnostic Slave AS-i Safety Relay Output Module with Diagnostic Slave User Manual...supports the requirements for AS-i Safety up to SIL3 Revision date: 2016-03-9 Subject to modifications without notice. Generally, this

More information

Assessment of Safety Functions of Lignite Mining Equipment according to the requirements of Functional Safety.

Assessment of Safety Functions of Lignite Mining Equipment according to the requirements of Functional Safety. Assessment of Safety Functions of Lignite Mining Equipment according to the requirements of Functional Safety. Implementation of the Machinery Directive based on proven-in-use, company standards and regulations.

More information

The Safe State: Design Patterns and Degradation Mechanisms for Fail- Operational Systems

The Safe State: Design Patterns and Degradation Mechanisms for Fail- Operational Systems The Safe State: Design Patterns and Degradation Mechanisms for Fail- Operational Systems Alexander Much 2015-11-11 Agenda About EB Automotive Motivation Comparison of different architectures Concept for

More information

FUNCTIONAL SAFETY CHARACTERISTICS

FUNCTIONAL SAFETY CHARACTERISTICS FUNCTIONAL SAFETY CHARACTERISTICS Functional Safety values for Phoenix Contact Safety products Application note 105016_en_02 PHOENIX CONTACT 12-04- 1 Aim of this document This application note is a central

More information

Enabling Increased Safety with Fault Robustness in Microcontroller Applications

Enabling Increased Safety with Fault Robustness in Microcontroller Applications Enabling Increased Safety with Fault Robustness in Microcontroller Applications Wayne Lyons ARM 110 Fulbourn Road Cambridge CB1 9NJ, England Abstract All safety-critical or high-reliability applications

More information

Advanced IP solutions enabling the autonomous driving revolution

Advanced IP solutions enabling the autonomous driving revolution Advanced IP solutions enabling the autonomous driving revolution Chris Turner Director, Emerging Technology & Strategy, Embedded & Automotive Arm Shanghai, Beijing, Shenzhen Arm Tech Symposia 2017 Agenda

More information

LION SAFE Remote I/O System. LÜTZE TRANSPORTATION GMBH Dimitrios Koutrouvis V00

LION SAFE Remote I/O System. LÜTZE TRANSPORTATION GMBH Dimitrios Koutrouvis V00 Page 1 LÜTZE TRANSPORTATION GMBH Dimitrios Koutrouvis V00 Actual Market Situation New Safety Requirements from Standards and Authorities Governance European Union (EU) ==> European Railway Agency (ERA)

More information

Certified Automotive Software Tester Sample Exam Paper Syllabus Version 2.0

Certified Automotive Software Tester Sample Exam Paper Syllabus Version 2.0 Surname, Name: Gender: male female Company address: Telephone: Fax: E-mail-address: Invoice address: Training provider: Trainer: Certified Automotive Software Tester Sample Exam Paper Syllabus Version

More information

PLUS+1 Safety Controllers SC0XX-1XX Safety Controller Family

PLUS+1 Safety Controllers SC0XX-1XX Safety Controller Family PLUS+1 Safety Controllers www.danfoss.com Revision history Table of revisions Date Changed Rev December 2018 Updated user application software development requirements 0404 August 2018 Corrected typo 0403

More information

Emerging Integrated Drive Controller

Emerging Integrated Drive Controller Emerging Integrated Drive Controller Ramesh Ramamoorthy - Senior Drive solution Expert & Sam Sabapathy - SMTS (Senior Member of the Technical Staff) C2000 System Solutions Industrial Drives & Functional

More information

ISO26262 This Changes Everything!

ISO26262 This Changes Everything! Subset of material used at this year s DVCon Europe ISO26262 This Changes Everything! John Brennan, Viktor Preis Cadence Design Systems, Inc. Accellera Systems Initiative 1 Four disruptive trends in Automotive

More information

Functional safety in BATTERY MANAGEMENT SYSTEMS

Functional safety in BATTERY MANAGEMENT SYSTEMS Functional safety in BATTERY MANAGEMENT SYSTEMS LiTHIUM BALANCE history 2014 2015 2016 2011 2012 1 st OEM cust. in production 300 projects completed ISO 9001 certified 400 projects completed 500 projects

More information

Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO standard

Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO standard Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO 26262 standard NMI Automotive Electronics Systems 2013 Event Victor Reyes Technical Marketing System

More information

Click ISO to edit Master title style Update on development of the standard

Click ISO to edit Master title style Update on development of the standard Click ISO 26262 to edit Master title style Update on development of the standard Dr David Ward Head of Functional Safety January 2016 Agenda Why update ISO 26262? What is the process for updating the standard?

More information

SAFETY MANUAL SIL Switch Amplifier

SAFETY MANUAL SIL Switch Amplifier PROCESS AUTOMATION SAFETY MANUAL SIL Switch Amplifier KCD2-SOT-(Ex)*(.LB)(.SP), KCD2-ST-(Ex)*(.LB)(.SP) ISO9001 2 With regard to the supply of products, the current issue of the following document is applicable:

More information

Predictable hardware: The AURIX Microcontroller Family

Predictable hardware: The AURIX Microcontroller Family Predictable hardware: The AURIX Microcontroller Family Worst-Case Execution Time Analysis WCET 2013, July 9, 2013, Paris, France Jens Harnisch (Jens.Harnisch@Infineon.com), Infineon Technologies AG, Automotive

More information

Detector Control System board for FAIR. J. A. Lucio Martínez Infrastructure and Computer Systems in Data Processing (IRI) Goethe University Frankfurt

Detector Control System board for FAIR. J. A. Lucio Martínez Infrastructure and Computer Systems in Data Processing (IRI) Goethe University Frankfurt Detector Control System board for FAIR J. A. Lucio Martínez Infrastructure and Computer Systems in Data Processing (IRI) Goethe University Frankfurt For the PANDA Collaboration Meeting in Darmstadt, 08.06.2016

More information

Report. Certificate M6A SIMATIC S7 Distributed Safety

Report. Certificate M6A SIMATIC S7 Distributed Safety Report to the Certificate M6A 17 05 67803 014 Safety-Related Programmable Systems SIMATIC S7 Distributed Safety Manufacturer: Siemens AG DF FA AS Gleiwitzer Str. 555 D-90475 Nürnberg Revision 3.1 dated

More information

Cyber security mechanisms for connected vehicles

Cyber security mechanisms for connected vehicles Infineon Security Partner Network Partner Use Case Cyber security mechanisms for connected vehicles Protecting automotive vehicle networks and business models from cyber security attacks Products AURIX

More information

FMEDA Report Failure Modes, Effects and Diagnostic Analysis and Proven-in-use -assessment KF**-CRG2-**1.D. Transmitter supply isolator

FMEDA Report Failure Modes, Effects and Diagnostic Analysis and Proven-in-use -assessment KF**-CRG2-**1.D. Transmitter supply isolator FMEDA Report Failure Modes, Effects and Diagnostic Analysis and Proven-in-use -assessment Device Model Number: Transmitter supply isolator Pepperl+Fuchs GmbH Mannheim Germany Mannheim norm sheet 1 of 10

More information

TEVATRON TECHNOLOGIES PVT. LTD Embedded! Robotics! IoT! VLSI Design! Projects! Technical Consultancy! Education! STEM! Software!

TEVATRON TECHNOLOGIES PVT. LTD Embedded! Robotics! IoT! VLSI Design! Projects! Technical Consultancy! Education! STEM! Software! Summer Training 2016 Advance Embedded Systems Fast track of AVR and detailed working on STM32 ARM Processor with RTOS- Real Time Operating Systems Covering 1. Hands on Topics and Sessions Covered in Summer

More information

Functional Safety Architectural Challenges for Autonomous Drive

Functional Safety Architectural Challenges for Autonomous Drive Functional Safety Architectural Challenges for Autonomous Drive Ritesh Tyagi: August 2018 Topics Market Forces Functional Safety Overview Deeper Look Fail-Safe vs Fail-Operational Architectural Considerations

More information

AS-i Safety Relay Output Module with Diagnostic Slave

AS-i Safety Relay Output Module with Diagnostic Slave AS-i Safety Relay Output Module with Diagnostic Slave User Manual Revision date: 2013-01-30...supports the requirements for AS-i Safety up to SIL3 Subject to modifications without notice. Generally, this

More information

Hardware Safety Integrity. Hardware Safety Design Life-Cycle

Hardware Safety Integrity. Hardware Safety Design Life-Cycle Hardware Safety Integrity Architecture esign and Safety Assessment of Safety Instrumented Systems Budapest University of Technology and Economics epartment of Measurement and Information Systems Hardware

More information

Application Note. AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO )

Application Note. AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO ) Application Note AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO 13849-1) Contents 1 Introduction 3 1.1 Purpose... 3 1.2 Document history... 4 1.3 Validity...

More information

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis Failure Modes, Effects and Diagnostic Analysis Project: Relay couplers IM73-12-R/24VUC and IM73-12-R/230VAC Customer: Hans Turck GmbH & Co. KG Mühlheim Germany Contract No.: TURCK 06/02-16 Report No.:

More information

MANUAL Functional Safety

MANUAL Functional Safety PROCESS AUTOMATION MANUAL Functional Safety Repeater KFD0-CS-(Ex)*.54*, KFD0-CS-(Ex)*.56* ISO9001 2 With regard to the supply of products, the current issue of the following document is applicable: The

More information

Low voltage switchgear and controlgear functional safety aspects

Low voltage switchgear and controlgear functional safety aspects Low voltage switchgear and controlgear functional safety aspects Guidance how to use low voltage switchgear and controlgear in functional safety applications Picture Siemens AG A message from the CAPIEL

More information

Safety Manual for MagniV Safety Devices MC9S12ZVL(S), MC9S12ZVM(C/L), MC9S12ZVC(A), MC9S12ZVH(Y/L), MC9S12ZVB, MC9S12ZVFP

Safety Manual for MagniV Safety Devices MC9S12ZVL(S), MC9S12ZVM(C/L), MC9S12ZVC(A), MC9S12ZVH(Y/L), MC9S12ZVB, MC9S12ZVFP Safety Manual for MagniV Safety Devices MC9S12ZVL(S), MC9S12ZVM(C/L), MC9S12ZVC(A), MC9S12ZVH(Y/L), MC9S12ZVB, MC9S12ZVFP Document Number: MC9S12ZVxSM Rev. 2, 07/2015 2 Freescale Semiconductor, Inc. Contents

More information

Original operating instructions Fail-safe inductive sensor GI712S

Original operating instructions Fail-safe inductive sensor GI712S Original operating instructions Fail-safe inductive sensor GI712S 80236527 / 00 12 / 2016 Contents 1 Preliminary note...3 1.1 Symbols used...3 1.2 Warning signs used...3 2 Safety instructions...4 2.1 Safety-related

More information

Original operating instructions Fail-safe inductive sensor GG711S

Original operating instructions Fail-safe inductive sensor GG711S Original operating instructions Fail-safe inductive sensor GG7S 8236522 / 2 / 26 Contents Preliminary note...3. Symbols used...3.2 Warning signs used...3 2 Safety instructions...4 2. Safety-related requirements

More information

EH2175A. Main Microprocessor Infineon Aurix TC MHz 4M Flash 472K SRAM Float Point Capability Dual Core Safety Check V Operating Voltage

EH2175A. Main Microprocessor Infineon Aurix TC MHz 4M Flash 472K SRAM Float Point Capability Dual Core Safety Check V Operating Voltage EH2175A Main Microprocessor Infineon Aurix TC275 200MHz 4M Flash 472K SRAM Float Point Capability Dual Core Safety Check Inputs 15 Analog Inputs 20 Digital Inputs 2 Frequency Inputs 1 Wake-up Input 9-16

More information

The ApplicATion of SIL. Position Paper of

The ApplicATion of SIL. Position Paper of The ApplicATion of SIL Position Paper of the SIL Platform 1. The Application of SIL: Position Paper of the SIL Platform What is the SIL Platform? Why issue a SIL statement? What are the basics of SIL

More information

Model Based Development and Code Generation for Automotive Embedded Systems. April 26, 2017 Dr. Gergely Pintér, Dr. Máté Kovács thyssenkrupp Steering

Model Based Development and Code Generation for Automotive Embedded Systems. April 26, 2017 Dr. Gergely Pintér, Dr. Máté Kovács thyssenkrupp Steering Model Based Development and Code Generation for Automotive Embedded Systems April 26, 2017 Dr. Gergely Pintér, Dr. Máté Kovács Agenda Model Based Development and Code Generation for Automotive Embedded

More information