Company: Valeo Powertrain Systems Business Company: Valeo Powertrain Systems Business

Size: px
Start display at page:

Download "Company: Valeo Powertrain Systems Business Company: Valeo Powertrain Systems Business"

Transcription

1 "La démarche «Building» appliquée à la Sûreté de Fonctionnement des onduleurs" Building strategy application to functional safety of inverters Hicham LAHBIL Amélie THIONVILLE Company: Valeo Powertrain Systems Business Company: Valeo Powertrain Systems Business Group\ Electronic Product Group Group \ Electronic Product Group Address: Créteil, 2 rue Andrée Boulle Address: CERGY SAINT CHRISTOPHE, 14 avenue des Béguines Résumé Cette publication présente une nouvelle démarche en cours de déploiement, elle concerne le métier de sûreté de fonctionnement, Cette démarche permet d optimiser et de factoriser les efforts d études et de développement, dans le cas d une organisation développant diverses produits présentant des similitudes. L objectif est de pouvoir utiliser des «building» préeistants, déjà conçus, vérifiés et validés. Cette démarche permet un gain important de temps et de ressource, et permet une meilleure agilité dans les développements des onduleurs Summary This paper presents a new approach being deployed for dependability discipline; this approach allows optimizing and communalizing the study and development efforts in the case of an organization developing diverse products with similarities. The aim is to use the "building " eisting, already designed, verified and validated. This approach enables a significant gain in terms of time and resource, and allows for better agility in the developments of inverters 1 Introduction Different inverters used in different automotive applications (12V, 48V or High voltages) present many common points, this fact imply that many modules are similar, these module have the same definition, and generally the same limits and interfaces. Only some adaptations are needed to move from one application to another one, theses modules are what we call building s, Concretely, at the first level, an inverter consists of control parts and power parts, than at the second level the control parts consist of different hardware s and at the third level, we have software with its own specific hierarchy 2 VALEO Safety lifecycle: Before detailing the approach, it is important to present the safety lifecycle applied in the VALEO methodology, it describes different safety activities. The concerned activities by this paper approach are surrounded by red dotted circles. Subset of Customer Safety goal Requirements Component specification Elicitation FSC PHA UE list SFMEA Qual FTA Customer safety analysis FTA Quant System Validation Test Safety Tests Acceptance Test Component design TSC FMEDA / FTA Qual./ DFA FMEDA / FTA Quant. Component Validation test Safety Tests HW, SW specification Elicitation TSC (HW, SW) HW, SW Validation Safety Tests HW, SW design Safety HW, SW architecture efmea SW Safety Analysis HW, SW Integration and test Safety Tests HW/SW implementation Figure 1. Overall safety process description Communication 8F /1 page 1/8

2 3 Inverter environment Generally, inverters are used to control machines, the functions of the system (inverter + machine) are: Generator mode to supply the vehicle power network (Battery and different loads) Motor mode to provide torque to vehicle to start engine or to assist thermal engine (hybridization) The inverter may be integrated with machine or may be standalone, the system (inverter + machine) may be Belt Driven or beltless: Electric Motor directly on the crankshaft of the engine Electric Motor between engine and gearbo with an additional clutch Electric Motor behind the gearbo through a disconnect clutch To loads Vehicle power network (12V or 48V) CAN BUS network Battery VCU Inverter Machine Electrical energy conversion to mechanical energy to vehicle Vehicle mechanical energy conversion to electrical energy 4 Building approach Figure 2. Inverter environment How Building approach could be done for safety discipline? In this paper, we will try to answer this question by focusing on two eamples of safety activities (Technical safety concept and efmea) The first steps are: 1) Make a list of different developed products. 2) Define list of safety goals allocated to these products and their ASIL. 3) Determine architecture similarities between applications Different inverters are generally concerned by the same list of safety goals, some difference linked to characterization of safety goals eist (threshold values, reaction time ) but these differences are not a barrier to building approach. The ASIL level of safety goals may vary from one application to another, in these cases, the idea is to take into account the highest ASIL if there is no significant over cost, and otherwise the component is developed depending on the ASIL. To introduce net chapter, the figure below gives hierarchy and link between safety goals obtained from Hazard analysis and risk assessment activity applied at system level, and declined to functional safety requirements allocated to components of the system. Hazard analysis and risk assessment Safety goal 1 Safety goals 2 Safety goal n requirement 1 requirement 2 requirement 3 requirement 4 requirement n Figure 3. The different levels of safety requirements Communication 8F /1 page 2/8

3 4.1 Safety goals allocation Safety goal are top-level safety requirement resulting from the hazard analysis and risk assessment, to illustrate the approach, the table below gives an eample of a list of safety goals allocated to three similar applications Applications Application A ASIL Application B ASIL Application C ASIL Safety goal_001 C C C Safety goal_002 C C Safety goal_003 C B B Safety goal_004 A A A Safety goal_005 C C Safety Goal_006 B B A Table 1. Safety Goals Allocation The allocation of safety goals to the different elements is done after performing two types of safety analyses; deductive and inductive analyses (FTA and FMEA) Usually a safety goal is allocated to components or subsystems responsible of its violation, but it may also be allocated to components or subsystems that are not and do not participate in any way to its violation, this option allows in the design of the system to share and optimize development efforts between different sub systems. 4.2 requirements Allocation The functional safety requirements are derived from the safety goals, and then allocated to the product; the net table gives list of functional safety requirements allocated to different applications Applications coverage Application A ASIL Application B ASIL Application C ASIL FSR_001 SG_001 X C X C X C FSR_002 SG_001 X C X C X C FSR_003 SG_002 X C X C FSR_004 SG_002 X C X C FSR_005 SG_003 X C X B X B FSR_006 SG_003 X C X B X B FSR_007 SG_004 X A X A X A FSR_008 SG_005 X C X C FSR_009 SG_005 X C X C FSR_010 SG_006 X B X B X A FSR_011 SG_006 X B X B Table 2. FSR allocation to different applications After safety goals refinement into Functional Safety Requirements allocated to different applications. Then the Functional Safety Requirements are allocated to a component by refinement to a list of technical safety requirements allocated to the functional s of the component architecture. Functionnal Safety requirements Technical Safety requirements HW or SW requirements Communication 8F /1 page 3/8

4 4.3 Architectures similarities Net figures are given as eamples, common of three similar applications are shown in blue color, Voltage 2 Voltage 1 s Protection2 Protection4 Power supply BUS communication Protection1 MCU Drivers Protection3 Power parts WDG Position Sensors Temperature s Figure 4. Application A architecture Voltage 1 Protection2 Protection4 Power supply BUS communication Protection1 MCU Drivers Power parts WDG Position Sensors Temperature s Figure 5. Application B architecture Voltage 2 Voltage 1 Protection2 Power supply BUS communication Protection1 MCU Drivers Protection3 Power parts WDG Position Sensors Temperature s Figure 6. Application C architecture Communication 8F /1 page 4/8

5 4.4 Technical safety requirements The net table shows how the functional safety requirements are allocated to functional s of different architectures of the three applications, the idea behind this allocation table is to know common requirements between different applications. Common modules and common functional safety requirements are shown in blue color. Block FSR_001 FSR_002 FSR_003 FSR_004 FSR_005 FSR_006 FSR_007 FSR_008 FSR_009 FSR_010 FSR_011 Protection3 Voltage s 2 s Protection1 Application A Application B Application C Protection2 MCU WDG Power supply BUS com Position s Temperature Table 3. FSR allocation to different building s drivers Voltage 1 Power Protection4 After the allocation of FSRs to different building is done, the technical safety requirements are specified, this level of specification is shared between different applications (when it concern common building ). Communication 8F /1 page 5/8

6 When many building s are used in an application, the structure of the technical safety concept looks like to: General chapters Architecture chapter Technical safety concept Technical safety requirements Chapter on TSRS of non building s Chapter on TSRs of Building 1 Chapter on TSRs of Building 2 Common chapters Specific chapters... Chapter on TSRs of Building s n Figure 6. Eample of use of building Eample of shared technical safety concept : CAN communication safety requirements The CAN communication requirements are allocated to MCU to secure CAN frames containing critical data with ASIL. Net requirements are specified in a generic way for CAN building : Identifier TSR_Application_X_013 ASIL Upward traceability: TSR_Application_X_013 TSR_Application_X_014 CAN frames containing ASIL A/B/C/D data shall be protected by an appropriate timeout monitoring compliant with the safety concept ASIL C/D data transmitted on CAN shall be protected with a sequence counter ASIL A or B or C or D ASIL C or D FSR_Application_X_006 FSR_Application_X_00 TSR_Application_X_015 ASIL C/D data transmitted on CAN shall be protected with an applicative CRC ASIL C or D FSR_Application_X_ efmea building strategy The second activity concerned by Building approach in this paper is efmea (electronic Failure Modes and Effect Analysis), in Valeo methodology, it is a qualitative and quantitative analysis done at each hardware level, it identifies basic event (Failure modes) and associated failure rate to feed FMEDA and FTA safety analyses. Inputs for this analysis are electronic components reliability failure rates and failures modes, reliability failure rate is changing depending on application mission profile, But failure modes of component are the same, local effect are generally similar, a few adaptations are needed depending on the application. Eample of HW building, the function is to measure the +BAT voltage Communication 8F /1 page 6/8

7 Figure 7. HW building When known building s are designed in the same way, safety analysis like efmea could be done commonly; the table below gives an etract of an efmea of a building as eample: Block ID Block Name Part ID Part Description Part Failure Mode +BAT_MEASUREMENT R3200 RES 100K 1% 100mW TF 100PPM BAT_MEASUREMENT R3200 RES 100K 1% 100mW TF 100PPM BAT_MEASUREMENT R3201 RES 7.32K 1% 100mW TF 100ppm BAT_MEASUREMENT R3201 RES 7.32K 1% 100mW TF 100ppm 0603 open circuit Parameter change open circuit Parameter change Local Effects at output (Basic events) loss of +Bat measurement function no effect loss of +Bat measurement function no effect +BAT_MEASUREMENT C3202 CAP 1nF 10% 50V X8R 0603 open circuit no effect +BAT_MEASUREMENT C3202 CAP 1nF 10% 50V X8R 0603 short circuit loss of +Bat measurement function +BAT_MEASUREMENT D3200 +BAT_MEASUREMENT D3200 DIOD SCHOT DUAL 200mA 30V BAT54S SOT23 open circuit degration of pulse protection DIOD SCHOT DUAL 200mA 30V BAT54S SOT23 short circuit degration of pulse protection Table 4. +Bat voltage measurement efmea Effects at component level Specific to each application This efmea could be reused in every application using this building ; only a review of the effect at component level could change, the largest part is already ready for use. 5 Conclusion Building approach allows saving time and enables a good reactivity to develop products, to insure effectiveness of this approach, a good understanding of ISO26262 and a good proimity with HW and SW development teams are necessary. This approach could be epanded to many other safety activities like FMEDA and test activities, 6 Acknowledgement Thanks goes to everyone having made possible the accomplishment of this paper. 7 References [1] ISO26262 INTERNATIONAL STANDARD. [2] Building Blocks Strategy / François PELLIER [3] Valeo Safety Methodology (M.LEEMAN) 8 Glossary ASIL: Automotive Safety Integrity Level. CAN: Controller Area Network. CRC: Cyclic Redundancy Check efmea: Electronic Failure Modes and Effects Analysis FMEDA: Failure Modes and effects Diagnosis Analysis FSC: Functional Safety Concept. FSR: requirement. FTA: Fault tree Analysis HW: Hardware. Communication 8F /1 page 7/8

8 LPFM: MCU: SG: SPFM: SW: TSC: TSR: WDG: +Bat: Latent-Point Fault Metric. Microcontroller Unit Safety Goal. Single-point fault metric. Software. Technical Safety Concept Technical Safety Requirement. Watchdog Battery Voltage Communication 8F /1 page 8/8

Deriving safety requirements according to ISO for complex systems: How to avoid getting lost?

Deriving safety requirements according to ISO for complex systems: How to avoid getting lost? Deriving safety requirements according to ISO 26262 for complex systems: How to avoid getting lost? Thomas Frese, Ford-Werke GmbH, Köln; Denis Hatebur, ITESYS GmbH, Dortmund; Hans-Jörg Aryus, SystemA GmbH,

More information

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309 June 25th, 2007 Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309 Christopher Temple Automotive Systems Technology Manager Overview Functional Safety Basics Functional

More information

Software architecture in ASPICE and Even-André Karlsson

Software architecture in ASPICE and Even-André Karlsson Software architecture in ASPICE and 26262 Even-André Karlsson Agenda Overall comparison (3 min) Why is the architecture documentation difficult? (2 min) ASPICE requirements (8 min) 26262 requirements (12

More information

Failure Diagnosis and Prognosis for Automotive Systems. Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010

Failure Diagnosis and Prognosis for Automotive Systems. Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010 Failure Diagnosis and Prognosis for Automotive Systems Tom Fuhrman General Motors R&D IFIP Workshop June 25-27, 2010 Automotive Challenges and Goals Driver Challenges Goals Energy Rising cost of petroleum

More information

FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO SPEAKER. Dept. of Electrical Engineering, National Taipei University

FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO SPEAKER. Dept. of Electrical Engineering, National Taipei University FMEDA-Based Fault Injection and Data Analysis in Compliance with ISO-26262 Kuen-Long Lu 1, 2,Yung-Yuan Chen 1, and Li-Ren Huang 2 SPEAKER 1 Dept. of Electrical Engineering, National Taipei University 2

More information

Safe Automotive software architecture (SAFE) WP3 Deliverable D331a2: Proposal for extension of metamodel for error failure and propagation analysis

Safe Automotive software architecture (SAFE) WP3 Deliverable D331a2: Proposal for extension of metamodel for error failure and propagation analysis Contract number: ITEA2 10039 Safe Automotive software architecture (SAFE) ITEA Roadmap application domains: Major: Services, Systems & Software Creation Minor: Society ITEA Roadmap technology categories:

More information

Safety Argument based on GSN for Automotive Control Systems. Yutaka Matsubara Nagoya University

Safety Argument based on GSN for Automotive Control Systems. Yutaka Matsubara Nagoya University 1 Safety Argument based on GSN for Automotive Control Systems Yutaka Matsubara Nagoya University yutaka@ertl.jp 02.26.2014 2 Agenda 1. Safety argument in ISO26262 2. Requirements related to safety argument

More information

Understanding SW Test Libraries (STL) for safetyrelated integrated circuits and the value of white-box SIL2(3) ASILB(D) YOGITECH faultrobust STL

Understanding SW Test Libraries (STL) for safetyrelated integrated circuits and the value of white-box SIL2(3) ASILB(D) YOGITECH faultrobust STL Understanding SW Test Libraries (STL) for safetyrelated integrated circuits and the value of white-box SIL2(3) ASILB(D) YOGITECH faultrobust STL Riccardo Mariani White Paper n. 001/2014 Riccardo Mariani

More information

FUNCTIONAL SAFETY AND THE GPU. Richard Bramley, 5/11/2017

FUNCTIONAL SAFETY AND THE GPU. Richard Bramley, 5/11/2017 FUNCTIONAL SAFETY AND THE GPU Richard Bramley, 5/11/2017 How good is good enough What is functional safety AGENDA Functional safety and the GPU Safety support in Nvidia GPU Conclusions 2 HOW GOOD IS GOOD

More information

Functional safety in BATTERY MANAGEMENT SYSTEMS

Functional safety in BATTERY MANAGEMENT SYSTEMS Functional safety in BATTERY MANAGEMENT SYSTEMS LiTHIUM BALANCE history 2014 2015 2016 2011 2012 1 st OEM cust. in production 300 projects completed ISO 9001 certified 400 projects completed 500 projects

More information

Certified Automotive Software Tester Sample Exam Paper Syllabus Version 2.0

Certified Automotive Software Tester Sample Exam Paper Syllabus Version 2.0 Surname, Name: Gender: male female Company address: Telephone: Fax: E-mail-address: Invoice address: Training provider: Trainer: Certified Automotive Software Tester Sample Exam Paper Syllabus Version

More information

Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems

Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems Automotive ECU Design with Functional Safety for Electro-Mechanical Actuator Systems Kyung-Jung Lee, Young-Hun Ki, and Hyun-Sik Ahn Abstract In this paper, we propose a hardware and software design method

More information

What functional safety module designers need from IC developers

What functional safety module designers need from IC developers What functional safety module designers need from IC developers Embedded Platforms Conference Microcontrollers and Peripherals Nov 9 th 2016 14:50 15:30 TOM MEANY Introduction This presentation gives a

More information

ISO Functional Safety Management in the Autonomous Car industry and the overview of the required safety lifecycle.

ISO Functional Safety Management in the Autonomous Car industry and the overview of the required safety lifecycle. ISO 26262 Functional Safety Management in the Autonomous Car industry and the overview of the required safety lifecycle TÜV SÜD America PSES San Diego Chapter Meeting Sep. 12, 2017 TÜV SÜD AG Slide 1 Functional

More information

AN5333. Safety application notes for MC24XS4 family. Document information

AN5333. Safety application notes for MC24XS4 family. Document information Rev. 3.0 26 January 2018 Application note Document information Information Content Keywords Abstract This document discusses the safety requirements for the use of an NXP product and in functional safety

More information

Alexandre Esper, Geoffrey Nelissen, Vincent Nélis, Eduardo Tovar

Alexandre Esper, Geoffrey Nelissen, Vincent Nélis, Eduardo Tovar Alexandre Esper, Geoffrey Nelissen, Vincent Nélis, Eduardo Tovar Current status MC model gradually gaining in sophistication Current status MC model gradually gaining in sophistication Issue Safety-related

More information

Functional Safety Design Packages for STM32 & STM8 MCUs

Functional Safety Design Packages for STM32 & STM8 MCUs Functional Safety Design Packages for STM32 & STM8 MCUs Achieve functional safety certifications with ST MCUs With its Functional Safety Design Packages based on robust built-in MCU safety features, ST

More information

Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, ColdFire+, C- Ware, the Energy Efficient Solutions logo, Kinetis,

Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, ColdFire+, C- Ware, the Energy Efficient Solutions logo, Kinetis, July 19, 2013 Freescale, the Freescale logo, AltiVec, C-5, CodeTEST, CodeWarrior, ColdFire, ColdFire+, C- Ware, the Energy Efficient Solutions logo, Kinetis, mobilegt, PEG, PowerQUICC, Processor Expert,

More information

Verification Futures The next three years. February 2015 Nick Heaton, Distinguished Engineer

Verification Futures The next three years. February 2015 Nick Heaton, Distinguished Engineer Verification Futures The next three years February 2015 Nick Heaton, Distinguished Engineer Let s rewind to November 2011 2 2014 Cadence Design Systems, Inc. All rights reserved. November 2011 SoC Integration

More information

MC33903/4/5 Block Diagram. Analog, Mixed-Signal and Power Management. Legend. MCU Voltage Regulator (V DD ) Internal CAN Regulator (V CAN )

MC33903/4/5 Block Diagram. Analog, Mixed-Signal and Power Management. Legend. MCU Voltage Regulator (V DD ) Internal CAN Regulator (V CAN ) Analog, Mixed-Signal and MC33903/4/5 System Basis Chip Gen2 with High Speed and Interface Overview The MC33903/4/5 is the second generation family of System Basis Chips, which combine several features

More information

NORME ISO : APPLICATION SUR LE LOGICIEL DU BOITIER DE SERVITUDE INTELLIGENT (BSI) DE PSA

NORME ISO : APPLICATION SUR LE LOGICIEL DU BOITIER DE SERVITUDE INTELLIGENT (BSI) DE PSA NORME ISO 26262 : APPLICATION SUR LE LOGICIEL DU BOITIER DE SERVITUDE INTELLIGENT (BSI) DE PSA ISO 26262 STANDARD : APPLICATION ON THE PSA BODY CONTROL MODULE (BCM) Alin MIHALACHE Fabrice BEDOUCHA SECTOR

More information

Is This What the Future Will Look Like?

Is This What the Future Will Look Like? Is This What the Future Will Look Like? Implementing fault tolerant system architectures with AUTOSAR basic software Highly automated driving adds new requirements to existing safety concepts. It is no

More information

Click ISO to edit Master title style Update on development of the standard

Click ISO to edit Master title style Update on development of the standard Click ISO 26262 to edit Master title style Update on development of the standard Dr David Ward Head of Functional Safety January 2016 Agenda Why update ISO 26262? What is the process for updating the standard?

More information

Solving functional safety challenges in Automotive with NOR Flash Memory

Solving functional safety challenges in Automotive with NOR Flash Memory Solving functional safety challenges in Automotive with NOR Flash Memory Sandeep Krishnegowda Marketing Director Flash Business Unit Cypress Semiconductor 1 Flash Memory Summit 2018 / Santa Clara, CA Automotive

More information

Automotive Functional Safety

Automotive Functional Safety Automotive Functional Safety Complexity, Confidence, Compliance, Certification Farmington, 2018-03-22 23.03.2018 150 years TÜV SÜD 150 years of inspiring trust Inspiring trust since 1866 The year 2016

More information

OPERATING INSTRUCTION

OPERATING INSTRUCTION OPERATING INSTRUCTION AUTORANGING MULTIMETER MAX Ω F C 10A MAX every 15 min. COM V SAFETY INFORMATION The following safety information must be observed to insure maximum personal safety during the operation

More information

Safety Driven Optimization Approach for Automotive Systems. Slim DHOUIBI, PhD Student, VALEO - LARIS

Safety Driven Optimization Approach for Automotive Systems. Slim DHOUIBI, PhD Student, VALEO - LARIS Safety Driven Optimization Approach for Automotive Systems Slim DHOUIBI, PhD Student, VALEO - LARIS Tuesday, Feb 3, 2015 Context and Objective Motives : o Safety constraints have a deep impact on the design

More information

COMPASS: FORMAL METHODS FOR SYSTEM-SOFTWARE CO-ENGINEERING

COMPASS: FORMAL METHODS FOR SYSTEM-SOFTWARE CO-ENGINEERING COMPASS: FORMAL METHODS FOR SYSTEM-SOFTWARE CO-ENGINEERING Viet Yen Nguyen Lehrstuhl für Informatik 2, RWTH Aachen University nguyen@cs.rwth-aachen.de Technology Innovation Days, ESA/ESTEC, 2011 ABOUT

More information

NTC/PTC- SIMULATION NTCS channel version

NTC/PTC- SIMULATION NTCS channel version NTC/PTC- SIMULATION 2-channel version MORE SAFETY AND CONTROL FOR YOUR DEVELOPMENT. Efficiency, reliability and safety of modern lithium ion batteries for electric vehicle drives strongly depend on the

More information

Original operating instructions Safety relay with relay outputs with and without delay G1502S / / 2016

Original operating instructions Safety relay with relay outputs with and without delay G1502S / / 2016 Original operating instructions Safety relay with relay outputs with and without delay UK G50S 803638 / 00 0 / 06 Contents Preliminary note...4. Symbols used...4 Safety instructions...5 3 Items supplied...6

More information

88 Dugald Campbell. Making Industrial Systems Safer Meeting the IEC standards

88 Dugald Campbell. Making Industrial Systems Safer Meeting the IEC standards 88 Dugald Campbell Making Industrial Systems Safer Meeting the IEC 60730 standards Introduction With the introduction of the International Electrotechnical Commission s IEC 60730 standards series, household

More information

ISO meets AUTOSAR - First Lessons Learned Dr. Günther Heling

ISO meets AUTOSAR - First Lessons Learned Dr. Günther Heling ISO 26262 meets AUTOSAR - First Lessons Learned Dr. Günther Heling Agenda 1. ISO 26262 and AUTOSAR Two Basic Contradictions Top-Down vs. Reuse Concentration vs. Distribution 2. Approach Mixed ASIL System

More information

Software Verification and Validation (VIMMD052) Introduction. Istvan Majzik Budapest University of Technology and Economics

Software Verification and Validation (VIMMD052) Introduction. Istvan Majzik Budapest University of Technology and Economics Software Verification and Validation (VIMMD052) Introduction Istvan Majzik majzik@mit.bme.hu Budapest University of Technology and Economics Dept. of Measurement and Information s Budapest University of

More information

Functional Safety simulation using SaberRD

Functional Safety simulation using SaberRD Functional Safety simulation using SaberRD April 7, 2016 Michael McDermott/Thomas Hedges Electrical Simulation and Analysis Megatrends drive our technology portfolio Safe Green Connected - Active Safety

More information

Autoranging True RMS Multimeter User Manual

Autoranging True RMS Multimeter User Manual Autoranging True RMS Multimeter User Manual Please read this manual before switching the unit on. Important safety information inside. Contents Page 1. Safety Information... 4 2. Safety Symbols... 5 3.

More information

Hiperface DSL Combined with Safety

Hiperface DSL Combined with Safety International TÜV Rheinland Symposium in China Functional Safety in Industrial Applications 18 19 October 2011, Shanghai - China Hiperface DSL Combined with Safety 1 Safety Implementation Hiperface DSL

More information

Industrial Embedded Systems - Design for Harsh Environment - Dr. Alexander Walsch

Industrial Embedded Systems - Design for Harsh Environment - Dr. Alexander Walsch Industrial Embedded Systems - Design for Harsh Environment - Dr. Alexander Walsch alexander.walsch@ge.com WS 2011/12 Technical University Munich (TUM) Introduction - Our Backgrounds O&G Energy Sensor systems

More information

Institutionen för systemteknik

Institutionen för systemteknik Institutionen för systemteknik Department of Electrical Engineering Examensarbete Automated Fault Tree Generation from Requirement Structures Examensarbete utfört i Fordonssystem vid Tekniska högskolan

More information

New developments about PL and SIL. Present harmonised versions, background and changes.

New developments about PL and SIL. Present harmonised versions, background and changes. Safety evevt 2017 Functional safety New developments about PL and SIL. Present harmonised versions, background and changes. siemens.com ISO/ TC 199 and IEC/ TC 44 joint working group 1 - Merging project

More information

Using Fault Injection to Verify an AUTOSAR Application According to the ISO 26262

Using Fault Injection to Verify an AUTOSAR Application According to the ISO 26262 Using Fault Injection to Verify an AUTOSAR Application According to the ISO 26262 Ludovic Pintard, Michel Leeman, Abdelillah Ymlahi-Ouazzani, Jean-Charles Fabre, Karama Kanoun, Matthieu Roy To cite this

More information

aentron Energy System 1 to 900 Vdc

aentron Energy System 1 to 900 Vdc aentron Energy System 1 to 900 Vdc The aentron lithium-ion energy system enables the realisation of a modular and scalable lithium-ion battery solution. The management of large lithium-ion batteries systems

More information

Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation

Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation Safety and Reliability of Software-Controlled Systems Part 14: Fault mitigation Prof. Dr.-Ing. Stefan Kowalewski Chair Informatik 11, Embedded Software Laboratory RWTH Aachen University Summer Semester

More information

A tool based estimation computation method of MCU random failure rate &functional safety metrics

A tool based estimation computation method of MCU random failure rate &functional safety metrics A tool based estimation computation method of MCU random failure rate &functional safety metrics Yogitech / Texas Instruments Riccardo Mariani YOGITECH, CTO Hoiman Low TI Safety MCU, FSCAE July / 2015

More information

V&V: Model-based testing

V&V: Model-based testing V&V: Model-based testing Systems Engineering BSc Course Budapest University of Technology and Economics Department of Measurement and Information Systems Traceability Platform-based systems design Verification

More information

Original operating instructions Safety relay with relay outputs G1501S / / 2016

Original operating instructions Safety relay with relay outputs G1501S / / 2016 Original operating instructions Safety relay with relay outputs G50S UK 8023637 / 00 02 / 206 Contents Preliminary note...4. Symbols used...4 2 Safety instructions...5 3 Items supplied...6 4 Functions

More information

Integrated Assessment of AutomotiveSPICE 3.0, Functional Safety ISO 26262, Cybersecurity SAE J3061

Integrated Assessment of AutomotiveSPICE 3.0, Functional Safety ISO 26262, Cybersecurity SAE J3061 Integrated Assessment of AutomotiveSPICE 3.0, Functional Safety ISO 26262, Cybersecurity SAE J3061 Christian Kreiner Institute of Technical Informatics TUGraz Richard Messnarz ISCN GesmbH The AQU project

More information

Battery Stack Management Makes another Leap Forward

Battery Stack Management Makes another Leap Forward Battery Stack Management Makes another Leap Forward By Greg Zimmer Sr. Product Marketing Engineer, Signal Conditioning Products Linear Technology Corp. Any doubts about the viability of electric vehicles

More information

SysML Modeling Guide for Target System

SysML Modeling Guide for Target System SysML Modeling Guide for Target System /4 Table of Contents Scope...4 2 Overview of D-Case and SysML Modeling Guide...4 2. Background and Purpose...4 2.2 Target System of Modeling Guide...5 2.3 Constitution

More information

Automating Best Practices to Improve Design Quality

Automating Best Practices to Improve Design Quality Automating Best Practices to Improve Design Quality Adam Whitmill, Senior Application Engineer 2015 The MathWorks, Inc. 1 Growing Complexity of Embedded Systems Emergency Braking Body Control Module Voice

More information

How Microcontrollers help GPUs in Autonomous Drive

How Microcontrollers help GPUs in Autonomous Drive How Microcontrollers help GPUs in Autonomous Drive GTC 2017 Munich, 2017-10-12 Hans Adlkofer, VP Automotive System department Outline 1 Main Safety concepts 2 Sensor Fusion architecture and functionalities

More information

Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist

Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist Riccardo Mariani, Intel Fellow, IOTG SEG, Chief Functional Safety Technologist Internet of Things Group 2 Internet of Things Group 3 Autonomous systems: computing platform Intelligent eyes Vision. Intelligent

More information

DUAL PLATE D630 Installation and Maintenance en / a

DUAL PLATE D630 Installation and Maintenance en / a Installation and Maintenance 5185 en 2014.04 / a Table des matières 1. General instructions... 3 1.1. Identity card... 3 1.2. General presentation... 3 1.2.1. Of the product... 3 1.2.2. Of the mean...

More information

Requirements-driven Verification Methodology for Standards Compliance Serrie-justine Chapman (TVS)

Requirements-driven Verification Methodology for Standards Compliance Serrie-justine Chapman (TVS) Requirements-driven Verification Methodology for Standards Compliance Serrie-justine Chapman (TVS) in collaboration with Test and Verification Solutions Ltd Infineon Technologies UK ARTEMIS CRYSTAL project

More information

Safe Automotive software architecture (SAFE)

Safe Automotive software architecture (SAFE) Contract number: ITEA2 10039 Safe Automotive software architecture (SAFE) ITEA Roadmap application domains: Major: Services, Systems & Software Creation Minor: Society ITEA Roadmap technology categories:

More information

SOFTWARE QUALITY. MADE IN GERMANY.

SOFTWARE QUALITY. MADE IN GERMANY. UPCOMING IMPACT OF THE SECOND EDITION OF THE ISO 26262 MGIGroup, 11.07.2017 SOFTWARE QUALITY. MADE IN GERMANY. SOLUTIONS FOR INTEGRATED QUALITY ASSURANCE OF EMBEDDED SOFTWARE MOTIVATION Release ISO 26262:2011

More information

Virtual Hardware ECU How to Significantly Increase Your Testing Throughput!

Virtual Hardware ECU How to Significantly Increase Your Testing Throughput! Virtual Hardware ECU How to Significantly Increase Your Testing Throughput! Elektrobit Tech Day Jason Niatas Synopsys Inc. July 27, 2017 2017 Synopsys, Inc. 1 Agenda Automotive electronic evolution and

More information

Functional Safety Architectural Challenges for Autonomous Drive

Functional Safety Architectural Challenges for Autonomous Drive Functional Safety Architectural Challenges for Autonomous Drive Ritesh Tyagi: August 2018 Topics Market Forces Functional Safety Overview Deeper Look Fail-Safe vs Fail-Operational Architectural Considerations

More information

Setpoint Isolators. Technical Manual. HA Issue Parker SSD Drives, a division of Parker Hannifin Ltd. WARRANTY

Setpoint Isolators. Technical Manual. HA Issue Parker SSD Drives, a division of Parker Hannifin Ltd. WARRANTY Technical Manual HA09 Issue 008 Parker SSD Drives, a division of Parker Hannifin Ltd. All rights strictly reserved. No part of this document may be stored in a retrieval system, or transmitted in any form

More information

New ARMv8-R technology for real-time control in safetyrelated

New ARMv8-R technology for real-time control in safetyrelated New ARMv8-R technology for real-time control in safetyrelated applications James Scobie Product manager ARM Technical Symposium China: Automotive, Industrial & Functional Safety October 31 st 2016 November

More information

Entwicklung zuverlässiger Software-Systeme, Stuttgart 30.Juni 2011

Entwicklung zuverlässiger Software-Systeme, Stuttgart 30.Juni 2011 Entwicklung zuverlässiger Software-Systeme, Stuttgart 30.Juni 2011 Tools and Methods for Validation and Verification as requested by ISO26262 1 Introduction ISO26262 ISO 26262 is the adaptation of IEC

More information

Software Architecture. Definition of Software Architecture. The importance of software architecture. Contents of a good architectural model

Software Architecture. Definition of Software Architecture. The importance of software architecture. Contents of a good architectural model Software Architecture Definition of Software Architecture Software architecture is process of designing g the global organization of a software system, including: Dividing software into subsystems. Deciding

More information

Introduction: Transient Voltage Suppressors (TVS) for Automotive Electronic Protection. SM8/5Z Series APPLICATION NOTE

Introduction: Transient Voltage Suppressors (TVS) for Automotive Electronic Protection. SM8/5Z Series APPLICATION NOTE Introduction: Because of the benefits from the booming development of automotive electronics, cars are integrating more and more sophisticated electronics into their systems. For example, entertainment

More information

S-14 S-14. Compact Digital Multimeter. Compact Digital Multimeter

S-14 S-14. Compact Digital Multimeter. Compact Digital Multimeter S-14 Compact Digital Multimeter S-14 Compact Digital Multimeter SAFETY INFORMATION The following safety information must be observed to insure maximum personal safety during the operation at this meter

More information

Redundant Power Supplies. Keep Machines Up When Power Goes Down

Redundant Power Supplies. Keep Machines Up When Power Goes Down Redundant Power Supplies Keep Machines Up When Power Goes Down When your operation is critical, you need power you can count on. Redundant Power Systems are ideal for any equipment where the highest attainable

More information

DEPENDABLE PROCESSOR DESIGN

DEPENDABLE PROCESSOR DESIGN DEPENDABLE PROCESSOR DESIGN Matteo Carminati Politecnico di Milano - October 31st, 2012 Partially inspired by P. Harrod (ARM) presentation at the Test Spring School 2012 - Annecy (France) OUTLINE What?

More information

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility

European Conference on Nanoelectronics and Embedded Systems for Electric Mobility European Conference on Nanoelectronics and Embedded Systems for Electric Mobility ecocity emotion 24-25 th September 2014, Erlangen, Germany Scalable Functional Safety Architecture for Electric Mobility

More information

Driver Assistance Pushes New Flash Functionalities

Driver Assistance Pushes New Flash Functionalities Driver Assistance Pushes New Flash Functionalities Anil Gupta Technical Executive Winbond Electronics Corporation Santa Clara, CA 1 Automotive and ADAS terminology ECC use to increase reliability of Flash

More information

C-DIAS Analog Input Module CAI 086 For eight, ±10V voltage inputs

C-DIAS Analog Input Module CAI 086 For eight, ±10V voltage inputs C-DIAS ANALOG INPUT MODULE CAI 086 C-DIAS Analog Input Module CAI 086 For eight, ±10V voltage inputs This analog input module is used for the input of voltage values in the range of ±100mV / ±1.0V and10v.

More information

UNISONIC TECHNOLOGIES CO., LTD

UNISONIC TECHNOLOGIES CO., LTD UNISONIC TECHNOLOGIES CO., LTD MICROPROCESSOR IC DESCRIPTION The UTC UTC812 is a microprocessor (µp) reset circuit designed to monitor the power supplies in µp and digital systems. The UTC UTC812 has push-pull

More information

BRIO. Application note BRIO Extension & Ethernet redundancy. EN50155 Basic Remote I/O module P DOC BRIO 101E V01

BRIO. Application note BRIO Extension & Ethernet redundancy. EN50155 Basic Remote I/O module P DOC BRIO 101E V01 BRIO EN50155 Basic Remote I/O module Application note BRIO Extension & Ethernet redundancy P DOC BRIO 101E V01 This page is intentionally left blank Introduction BRIO is an Ethernet-based decentralized-remote

More information

Hardware-Software Codesign. 1. Introduction

Hardware-Software Codesign. 1. Introduction Hardware-Software Codesign 1. Introduction Lothar Thiele 1-1 Contents What is an Embedded System? Levels of Abstraction in Electronic System Design Typical Design Flow of Hardware-Software Systems 1-2

More information

ISO Compliant Automatic Requirements-Based Testing for TargetLink

ISO Compliant Automatic Requirements-Based Testing for TargetLink ISO 26262 Compliant Automatic Requirements-Based Testing for TargetLink Dr. Udo Brockmeyer CEO BTC Embedded Systems AG An der Schmiede 4, 26135 Oldenburg, Germany udo.brockmeyer@btc-es.de Adrian Valea

More information

A general-purpose industrial input/output

A general-purpose industrial input/output A general-purpose industrial input/output Iono MKR is a versatile and compact IO module compatible with all the Arduino MKR boards. All the power of the Arduino platform, combined with WiFi, BLE, GSM,

More information

Control unit SG-EFS 104/4L. EN Operating instructions. Innovative by tradition. Version SG-EFS 104/4L AC/DC 24 V

Control unit SG-EFS 104/4L. EN Operating instructions. Innovative by tradition. Version SG-EFS 104/4L AC/DC 24 V Innovative by tradition. Control unit SG-EFS 104/4L EN Operating instructions Version 2 1004128 SG-EFS 104/4L AC/DC 24 V Original instructions Mayser GmbH & Co. KG Örlinger Straße 1 3 89073 Ulm GERMANY

More information

Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO standard

Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO standard Fault-Injection testing and code coverage measurement using Virtual Prototypes on the context of the ISO 26262 standard NMI Automotive Electronics Systems 2013 Event Victor Reyes Technical Marketing System

More information

IsoLoop Isolated CAN Evaluation Board

IsoLoop Isolated CAN Evaluation Board IsoLoop Isolated CAN Evaluation Board Board No.: IL41050-01 About This Evaluation Board This Evaluation Board provides a complete isolated CAN node using the revolutionary IL41050TA-3E isolated transceiver.

More information

Foundation Fieldbus Safety Instrumented System (FF SIS) FF-SIS Meeting. Hannover. April 21, 2004

Foundation Fieldbus Safety Instrumented System (FF SIS) FF-SIS Meeting. Hannover. April 21, 2004 Foundation Fieldbus Safety Instrumented System (FF SIS) FF-SIS Meeting Hannover April 21, 2004 1 Foundation Fieldbus Safety Instrumented System (FF SIS) Principles of Safety Related Bus-System and Protocols

More information

Hardware-Software Codesign. 1. Introduction

Hardware-Software Codesign. 1. Introduction Hardware-Software Codesign 1. Introduction Lothar Thiele 1-1 Contents What is an Embedded System? Levels of Abstraction in Electronic System Design Typical Design Flow of Hardware-Software Systems 1-2

More information

Drives Motors and PLCs

Drives Motors and PLCs Drives Motors and PLCs WHAT YOU WILL LEARN: The electrical drives and other rotating equipment connected to motors like pumps, fans, blowers, compressors etc. consumes about 65% of the total electrical

More information

Pluto AS-i. Safety PLC. Approvals: Control of: Features:

Pluto AS-i. Safety PLC. Approvals: Control of: Features: Safety PLC Pluto AS-i Approvals: TÜV Rheinland Control of: Safety products in dynamic and static circuits as well as in AS-i networks Electrically controlled actuators such as contactors, valves, motors

More information

REGULATED DC POWER SUPPLIES.

REGULATED DC POWER SUPPLIES. REGULATED DC POWER SUPPLIES. PRODUCT CATALOG 2011 PRODUCT CATALOG 2011 DelTA elektronika Table of contents: SM-series SM6000-Series 2 SM3300-Series 4 SM3000-Series 6 SM1500-Series 8 SM800-Series 10 ES-series

More information

VDE Testing and Certification Institute

VDE Testing and Certification Institute Test Report Report No.... : 223766-AS6-1 File No.... : 5007383-4970-0007/223766 Date of issue... : 2016-04-28 Laboratory... : Testing and Certification Institute Address... : Merianstrasse 28 63069 Offenbach/Main;

More information

INTRODUCTION. Mechanical Considerations APPLICATION NOTE Z86E21 THERMAL PRINTER CONTROLLER ZILOG

INTRODUCTION. Mechanical Considerations APPLICATION NOTE Z86E21 THERMAL PRINTER CONTROLLER ZILOG ZILOG DESIGNING A LOW-COST THERMAL PRINTER USING THE Z86E21 TO CONTROL THE OPERATING CURRENT ON LOW-COST THERMAL PRINTERS PROVIDES DESIGN FLEXIBILITY AND HELPS SAFEGUARD PERFORMANCE. INTRODUCTION Compact

More information

FSO Webnair FSO Safety Functions Module. ABB Group February 11, 2015 Slide 1

FSO Webnair FSO Safety Functions Module. ABB Group February 11, 2015 Slide 1 FSO Webnair FSO Safety Functions Module February 11, 2015 Slide 1 Competence Requirements for ABB Commissioner / Service Engineer of ACS880 Drives with FSO The integrated Safety Function Module (FSO; option

More information

Designing and Analysing Power Electronics Systems Using Simscape and SimPowerSystems

Designing and Analysing Power Electronics Systems Using Simscape and SimPowerSystems Designing and Analysing Power Electronics Systems Using Simscape and SimPowerSystems Gernot Schraberger Industry Manager, Europe Industrial Automation & Machinery, Energy Production MathWorks 2012 The

More information

SINUMERIK Safety Integrated. Possible Encoder Connections

SINUMERIK Safety Integrated. Possible Encoder Connections SINUMERIK Safety Integrated Possible Encoder Connections siemens.de/safety 1-encoder Safety Servomotor / spindle motor / torque motor SMI DQI 1FW motors 1FW motors 1FW motors Motor with analog interface

More information

SPC584Cx, SPC58ECx. 32-bit Power Architecture microcontroller for automotive ASIL-B applications. Features

SPC584Cx, SPC58ECx. 32-bit Power Architecture microcontroller for automotive ASIL-B applications. Features 32-bit Power Architecture microcontroller for automotive ASIL-B applications Data brief Features etqfp64 (10 x 10 x 1.0 mm) etqfp144 (20 x 20 x 1.0 mm) AEC-Q100 qualified FPBGA292 (17 x 17 x 1.8 mm) High

More information

STM32 F0 Value Line. Entry-level MCUs

STM32 F0 Value Line. Entry-level MCUs STM32 F0 Value Line Entry-level MCUs Key Messages 2 STM32 F0: Is the Cortex -M0 core generated with ST s STM32 DNA, for cost sensitive designs. The STM32 F0 is benefiting of STM32 DNA, providing the essential

More information

±15kV ESD-Protected, Single/Dual/Octal, CMOS Switch Debouncers

±15kV ESD-Protected, Single/Dual/Octal, CMOS Switch Debouncers 19-477; Rev 1; 1/99 ±15k ESD-Protected, Single/Dual/Octal, General Description The are single, dual, and octal switch debouncers that provide clean interfacing of mechanical switches to digital systems.

More information

SPC58NE84E7, SPC58NE84C3

SPC58NE84E7, SPC58NE84C3 SPC58NE84E7, SPC58NE84C3 32-bit Power Architecture microcontroller for automotive ASIL-D applications Data brief - preliminary data Features LFBGA292 (17 x 17 x 1.7 mm) elqfp176 (24 x 24 x 1.4 mm) Two

More information

Introduction to Control Systems Design

Introduction to Control Systems Design Experiment One Introduction to Control Systems Design Control Systems Laboratory Dr. Zaer Abo Hammour Dr. Zaer Abo Hammour Control Systems Laboratory 1.1 Control System Design The design of control systems

More information

Is this presentation suited for you?

Is this presentation suited for you? bus protection Is this presentation suited for you? 2 Where do you stand with bus protection? Beginner? I am not familiar with this subject. I am in the discovery phase and would like an overview and a

More information

Instruction book IQAN-LSL. Publ no HY /UK Edition 0301

Instruction book IQAN-LSL. Publ no HY /UK Edition 0301 Instruction book IQAN-LSL Publ no HY17-8367/UK Edition 0301 Contents 1 Introduction......................................................2 2 Precautions.......................................................3

More information

MANUFACTURING TECHNICAL INSTRUCTIONS - SAFETY. Subject: Control Reliability for Machinery & Equipment

MANUFACTURING TECHNICAL INSTRUCTIONS - SAFETY. Subject: Control Reliability for Machinery & Equipment DAIMLERCHRYSLER MANUFACTURING TECHNICAL INSTRUCTIONS - SAFETY Subject: Control Reliability for Machinery & Equipment ISSUE DATE: January 3, 2005 EFFECTIVE DATE: January 31, 2005 REVIEW DATE. June 26, 2007

More information

Workpackage WP2.5 Platform System Architecture. Frank Badstübner Ralf Ködel Wilhelm Maurer Martin Kunert F. Giesemann, G. Paya Vaya, H.

Workpackage WP2.5 Platform System Architecture. Frank Badstübner Ralf Ködel Wilhelm Maurer Martin Kunert F. Giesemann, G. Paya Vaya, H. Guidelines for application Deliverable n. D25.6 Guidelines for application Sub Project SP2 ADAS development platform Workpackage WP2.5 Platform System Architecture Tasks T2.5.4 Guidelines for applications

More information

TwinSAFE Scalable Safety Solutions. Dr. Guido Beckmann Technology Marketing

TwinSAFE Scalable Safety Solutions. Dr. Guido Beckmann Technology Marketing TwinSAFE Scalable Safety Solutions Dr. Guido Beckmann Technology Marketing TwinSAFE Integration of Functional Safety From Safety Relais Logic From Safety Relais Logic to Modern Safety Concepts Advantages

More information

SAFETY MANUAL SIL Switch Amplifier

SAFETY MANUAL SIL Switch Amplifier PROCESS AUTOMATION SAFETY MANUAL SIL Switch Amplifier KCD2-SOT-(Ex)*(.LB)(.SP), KCD2-ST-(Ex)*(.LB)(.SP) ISO9001 2 With regard to the supply of products, the current issue of the following document is applicable:

More information

Safety and Security for Automotive using Microkernel Technology

Safety and Security for Automotive using Microkernel Technology Informationstag "Das Automobil als IT-Sicherheitsfall" Berlin, 11.05.2012 Safety and Security for Automotive using Microkernel Technology Dr.-Ing. Matthias Gerlach OpenSynergy TwoBirds withonestone Safety

More information

SINAMICS SINAMICS G120. Frequency inverter with Control Units CU240E-2 CU240E-2 DP CU240E-2 F CU240E-2 DP-F. Function Manual Safety Integrated 07/2010

SINAMICS SINAMICS G120. Frequency inverter with Control Units CU240E-2 CU240E-2 DP CU240E-2 F CU240E-2 DP-F. Function Manual Safety Integrated 07/2010 SINAMICS G120 Frequency inverter with Control Units CU240E-2 CU240E-2 DP CU240E-2 F CU240E-2 DP-F Function Manual Safety Integrated 07/2010 SINAMICS Answers for industry. Safety Integrated Function Manual,

More information

FUNCTIONAL SAFETY FOR INDUSTRIAL AUTOMATION

FUNCTIONAL SAFETY FOR INDUSTRIAL AUTOMATION FUNCTIONAL SAFETY FOR INDUSTRIAL AUTOMATION 2017.11 The term Functional Safety has become a topic of great interest. Functional Safety generally means that malfunctions of the operating systems or applications

More information