当前位置:首页 > 报告详情

29.d2s4-6-Nuclei Automotive RV Summit 20230821.pdf

上传人: 张** 编号:155403 2024-02-15 14页 2.62MB

1、Confidential 2023 Nuclei.All Rights Reserved.Confidential 2023 Nuclei.All Rights Reserved.2023-8-212Functional Safety-ISO 26262ASIL comes from Functional Safety,ISO 26262Absence of unacceptable risk due to hazards casue by malfunctioning behaviour of E/E(electrical/electronic)systems.Root causes for

2、 malfunctioning behaviour:Systematic errors(during specification,development,manufacturing,)Random hardware faults(during operation in the field)Foreseeable operational errors and misuse(during operation)Original from Mentor&NXPConfidential 2023 Nuclei.All Rights Reserved.2023-8-213ASIL DASIL CASIL

3、B(ASIL A)SPFM 99%97%90%60%not normativeLFM 90%80%60%n/aASIL LevelRandom hardware failure target values*)D 10-8 h-1 (10 FIT)C 10-7 h-1 (100 FIT)(B)10-7 h-1 (100 FIT)(A)10-6 h-1 (1000 FIT)not normative*Target values from ISO 26262-5Quantitative ASIL effect on IP designDetect/Control failureEffective s

4、afety mechanism to handle transient&permanent faultsVerification of safety mechansim to achieve target values from ISO 26262-5Confidential 2023 Nuclei.All Rights Reserved.2023-8-214Safety Mechanisms on CPU IP designMasterCoreShadowCoreCMPThe Dual-core lockstep cores executing the same code,then thei

5、r outputs and key internal states are compared every cycle;Any mismatch will generate a fault by the comparison unitDual-Core LockstepImplementing error correction code(ECC)on ILM,DLM,I/D-Cache with enhanced address and multi-bit error coverageSTLProviding STL(software test library)SRAM ECCRead/Writ

6、e CtrlECC GeneratorSRAMECC Check CorrectImplementing error detection code(EDC)on critical DFF.Selective coverage of architectural,pipeline or all DFF.DFF Parity/EDCComb logicParity/EDC GeneratorDFFs Parity/EDC CheckImplementing error detection code(EDC)on core boundary IOIO Parity/EDCOutput logicPar

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了ISO 26262标准下的功能安全(Functional Safety)以及与之相关的汽车安全完整性级别(ASIL)。ASIL是指由于电气/电子(E/E)系统的故障行为引起的危害的不接受风险。文章详细解释了导致系统故障行为的根本原因,包括系统错误(在规范、开发、制造等过程中)、随机硬件故障(在现场运行过程中)和可预见的操作错误和误用(在运行过程中)。 ISO 26262-5中提出了对随机硬件故障的目标值,ASIL D级别的目标值是小于10^-8 h^-1(10 FIT),ASIL C级别是小于10^-7 h^-1(100 FIT),ASIL B和A级别则分别为小于10^-7 h^-1(100 FIT)和小于10^-6 h^-1(1000 FIT)。 文章还详细描述了如何在CPU IP设计中实现功能性安全机制,例如双核心锁步、错误检测和校正代码(ECC)、软件测试库(STL)等。此外,还提到了如何通过ISO 26262 compliant半导体开发过程、失效分析、故障注入验证、系统集成和测试等步骤来实现ASIL B和D级别的CPU IP产品认证。 总之,本文深入探讨了ISO 26262标准下的功能安全及其在汽车电子系统中的应用,关键数据和概念,以及如何在CPU IP设计中实现这些安全机制。
"ISO 26262中的ASIL是什么意思?" "如何确保E/E系统的功能安全?" "NA900处理器如何实现功能安全?"
客服
商务合作
小程序
服务号
折叠