2014 2Q Exida TI Safety Webinar
2014 2Q Exida TI Safety Webinar
2014 2Q Exida TI Safety Webinar
e ida 1
Topics
• exida
• Overview of functional safety standards for industrial
and automotive systems
• Steps to certification
• Services provided by exida
• Texas Instruments
• Hercules MCU family and safety features overview
• Hercules MCU for IEC 61508, ISO 26262 and other
functional safety standards
e ida 2
exida Capabilities
Assessment and
Certification
Lifecycle Services
Knowledge Base
Specification 44%
Specification 44%
Design &
Changes after
Implementation
Commissioning
15%
21%
ISA
Operation & Installation & Commissioning
S84
Maintenance
15%
6%
HSE
PES
DIN V 19250
DINV VDE0801
EWICS
IEC61508
e ida Copyright exida 2000-2014
The continuing need today . . .
Overall Scope
2 Definition What should it do?
Hazard & Risk
3 Analysis
Overall Safety
4 Requirements
Safety Requirements
5 Allocation
Planning
Validation
Installation &
6 Maintenance 7 Planning 8 Commissioning
Planning
9 E/E/PES
Realization
10 Technology
Realization
11 Facilities
Realization
REALIZATION
Phase
Overall Installation
12 & Commissioning How will it do it?
Overall Safety
13 Validation
The system
architecture
drawing(s)
document the
relevant sub-
systems and
their
relationship.
The function(s)
of each sub-
system is fully
described.
e ida Chapter 8, “Functional Safety, An IEC 61508 Compliant Development Process,” exida, 2010.
Copyright exida 2000-2014
Project Milestones
• Product and process review
• Product reliability and failure mode
analysis
• Requirements fulfillment and
traceability
• Final audit and assessment report
Integration testing
Software (components,
E/E/PE system architecture subsystems and
architecture programmable
electronics)
Software Integration
system design testing (module)
Module Module
design testing
Output
Verification Coding
Audit Lists
Evidence
Functional Cyber-Security
• Achilles Level 1-2
• ISA Secure Levels 1 – 3
Functional Safety Certification
• IEC 61508
• IEC 61511
• IEC 62061 / ISO 13849
• IEC / ISO 26262
• EN 50271
• Other Functional Safety
• Texas Instruments
• Hercules MCU family and safety features overview
• Hercules MCU for IEC 61508, ISO 26262 and other
functional safety standards
26
Hercules™ MCU: End Equipment
Aerospace & Railway Industrial
Motor Control
Automotive
Industrial
Automation / PLC
Solar Power
Oxygen Anesthesia
Concentrators
Chassis / Domain Control
Active Suspension Electric Power Steering Respirators
Medical
27
TI Hercules MCU Platform
TM
RM
• 100MHz to 330MHz
Industrial and Medical
Safety MCUs • 384KB to 4MB Flash
• -40 to 105°C Operation
• ENET, USB, CAN & UART
• Developed to Safety Standards
• IEC 61508 SIL-3
• Cortex-R – up to 550 DMIPs
Hercules™ TMS570
MCU • 80MHz to 300MHz
28
Applying Functional Safety Standards
Config Management
Random Failures
Change Management
Diagnostics
V&V
Architectural Metric Hercules
Personnel Competence
Architecture
Failure Rate
Certification (FMEDA)
Cortex™R
Flash
w/ MPU
CPU
ARM®
optimized to reduce w/ ECC OSC PLL PBIST/LBIST memory test
RAM
probability of common ARM® w/ ECC POR ESM
cause failure Cortex™R Flash
Error Signaling
w/ MPU EEPROM w/ ECC CRC RTI/DWWD Module w/ External
Error Pin
Lockstep CPU & Calibration Memory Interface
Compare Module for
Lockstep Interrupt JTAG Debug
Fault Detection External Memory
Fault Detection Embedded Trace On-Chip Clock and
DMA
Voltage Monitoring
Enhanced System Bus and lockstep Vectored Interrupt Module
ECC or Parity on Protected Bus and
select Peripheral, lockstep Interrupt
Dual Manager
DMA and Interrupt
Dual High-end
controller RAMS
Serial Network ADC Timers
IO Loop Back, ADC
Interfaces Interfaces Cores Available Self Test, …
Parity or CRC in Serial
Available
and Network
Communication GIO Dual ADC Cores with
Peripherals shared channels
30
Hercules TMS570LS and RM4x Architecture
Concept Assessment Random
31
SafeTI™ Hitex Safety Kit Random
On Board Display
Kit Overview
q Fault injection and reaction
monitoring via GUI
ControlCard Interface q MCU Diagnostic features
profiling
q SafeTI Software Framework +
Hercules™ MCU
SafeRTOS included
32
Hercules Safety Documents Random
NDA
NDA
– Safety Report
Summary of compliance to IEC 61508 and/or ISO 26262
33
Hercules Safety Documents Random
Safety Manual
34
SafeTI™ Hardware Development Process Systematic
Certification
TI’s hardware functional safety
development process has been certified
for:
Ø IEC 61508 SIL-3
Ø ISO 26262 ASIL-D
35
HerculesTM and SafeTITM Systematic
36
SafeTI™ Compiler Qualification Kit Systematic
• Includes:
• Qualification Support Tool (model-based)
• Process specific documentation:
• Tool Classification Report
• Tool Qualification Plan
TI
ARM
Compiler
• Tool Qualification Report
• Tool Safety Manual
• ACE SuperTestTM qualification suite
• TI compiler validation test cases
• Test Automation Unit (TAU)
• 24hrs of Validas consulting services Approved by
• TÜV Nord assessment report
IEC 61508
ISO 26262
37
Typical Usage of Hercules MCU per Functional
Safety Standard*
Specific Diagnostic
Functional Safety
Typical Hercules MCU Usage Requirements per
Standard
Standard
IEC 61508 Single MCU for SIL1 - SIL 3, Dual MCU for SIL 4 No
ISO 26262
Single Hercules MCU ASIL A to D No
Automotive
EN 50129 Examples provided,
Single MCU for SIL1 - SIL 3, Dual MCU for SIL 4
Railway not requirements
ISO 22201
Single MCU for SIL1 - SIL 2, Dual MCU for SIL 3 Yes
Elevator
IEC 61511
Single MCU for SIL1 - SIL 3, Dual MCU for SIL 4 No
Process Safety
IEC 61800
Single Hercules MCU for SIL1 - SIL 3 No
Motor Drive
IEC 62061
Single Hercules MCU for SIL1 -SIL 3 No
Machine Safety
ISO 13849 Single MCU for Cat B, 1, 2 from PL a to PLe
No
Machine Safety Single MCU + Safety Companion for PL d/e CAT3/4
IEC 60730
Single MCU for Class A – C, Dual MCU for some Class C Yes
White Goods
* Items shown are typical examples. Achieved safety integrity level is the responsibility of the system developer.
38
Project Flowchart
✓ ✓
✓ ✓
✓
✓ HerculesTM MCU data available through SafeTITM design package
Contact Information:
Chris O’Brien:[email protected]
Hoiman Low: [email protected]
e ida 40