Documente Academic
Documente Profesional
Documente Cultură
exida Contacts
Singapore +65 6222 5160 Canada +1 403 475 1943
Shanghai +86 21 5171 7250 United Kingdom +44 2476 456 195
Hong Kong +852 2633 7727 Netherlands +31 318 414 505
Germany +49 89 4900 0547 Australia / NZL +64 3 472 7707
USA +1 215 453 1720 Mexico +52 55 5611 9858
Switzerland +41 22 364 14 34 South Africa +27 31 267 1564
exida
Copyright exida LLC ® 2000-2012
Once upon a time…
Electronics???
Adaptive Headlights
Pre-Crash System
Automatic Steering
Backup Camera
Infrared Night Vision
Steering Lock
Traction Control System
Anti-Blocking System
Corner Brake Control
Adaptive Cruise Control
Automatic Collision Notification Automated Parking System Automatic Gearbox Control Airbag
Electronic Stability Program Tire Pressure Monitoring Reverse Sensors Lane Departure Warning
Deflation Detection System Emergency Brake Assistance Traffic Sign Recognition
Adaptive Headlights
Pre-Crash System
Automatic Steering
Backup Camera
Infrared Night Vision
Steering Lock
Traction Control System
“Actively” function Anti-Blocking System
to achieve Corner Brake Control
Safe State
Adaptive Cruise Control
Automatic Collision Notification Automated Parking System Automatic Gearbox Control Airbag
Electronic Stability Program Tire Pressure Monitoring Reverse Sensors Lane Departure Warning
Deflation Detection System Emergency Brake Assistance Traffic Sign Recognition
Functional Safety
BECAUSE…
BECAUSE…
IEC 61508
Functional Safety for E/E/PES Safety Related Systems
IEC 61508
Functional Safety for E/E/PES Safety Related Systems
IEC 61508
Functional Safety for E/E/PES Safety Related Systems
IEC 61508
Functional Safety for E/E/PES Safety Related Systems
ISO 13849-1
Machine Safety
ISO 25119
Tractors…
Control of
Avoid Systematic Faults
Systematic Failures
Control of
Random Failures
Control of
Avoid Systematic Faults
Systematic Failures
Control of
Random Failures
Approach
concept phase
Concept
Functional
of Functional
Safety
3.7
3.8
Concept
Safety
product development
4 Product Development
Other Driver External
System
Technologies Controllability Measures
Planning of (and Usability)
7.4 Hard- Soft-
Production 5 6
ware ware
Planning of Operation,
7.5
Service and Decom.
4.11 Release for SOP
after SOP
7.4 Production
Back to appropriate
lifecycle phase
Operation, Service
7.5
and Decommissioning
Exida
Templates
Vocabulary
6
5.6.7 Verification of SW safety requirements ...........................................................59
Production and Operation ........................................................................................ 61
Template
7 Supporting Processes .............................................................................................. 66
7.1 Interfaces within distributed development ..................................................................66
7.2 Specification and management of safety requirements .............................................69
7.3 Copyright exida LLC
Configuration management .......................................................................................70 ® 2000-2012
7.4 Change management ................................................................................................70
Management of Functional Safety
Safety Case
A clear,
comprehensive and defensible argument
that a system is acceptably safe to operate
in a particular context.
(Tim Kelly / Rob Weawer University of York)
Concept
Safety Alert
Change Control
Change Control Recall
Board
Board
Stop
Modification Proposal
Safety Criticality Decide on lifecycle Update Safety Case
Affected Modules re-entry point & Probability Model
Modifications
Version Control Update Regression
Test Suite
Module Test
Productization
Integration Test
Configuration Control
Legend New
System Test release
Database entries
yellow: new
green: update existing
Exida Documents
yellow: new
green: update existing
Regression testing
Modified product - hardware & software
User documentation incl.
changed product safety properties
Associated development & test doc.
Release history
Modification
Process
Moderation Always
with OEM
Functionality to
meet
SAFETY GOAL…
ASIL D ASIL D
Vehicle speed ASIL D Lock Sequence
Vehicle Speed ASIL D ASIL D Steering Column
SG1
Server Lock
Technical Safety
INTEGRITY Concept
System Design
HW Design SW Design
HSI
HW Level Development
Single point ≥ 90 % ≥ 97 % ≥ 99 %
faults metric + ++ ++
Latent faults ≥ 60 % ≥ 80 % ≥ 90 %
metric + + ++
5.9 Random
ASIL Random hardware failure target values
Voter
I/O I/O
µC1
ALU ALU
RAM RAM
I/O I/O
Reg Reg
µC2
I/O Flash I/O
2x SW Development,
Communication, Testing, Focus Mainly on
PCB Space, Justification, Application
Supply voltage,
SW Level Development
System Validation
Sc
4
E/E System-Design E/E System Integration
art
ope
of P
of P
Verification
pe
art
Sco
during Design
4
es
Verification
has
nP
during Design
tP
has
Tes
es
Sc
6
ope
art
Software Architecture Test Software Integration
of P
of P
pe
art
Sco
6
Verification
during Design
Test
Software
Software Unit Test
Implementation
Production
Operation
Supporting Processes
Safety Analyses
SCA
FTA
H&R FMEA
FMEA
SWCA HAZAN
FMEDA
H&R: Hazard & Risk
SCA: System Criticality
FTA: Fault Tree
FMEA: Failure Mode Effect
FMEDA: FMEA with Diagnostics
SWCA: SW-Criticality
HAZAN: Hazard Analysis
SafetyCaseDB
Requirements and Safety Case Management and ISO 26262
knowledgebase
SILCal FMEDA
Component FMEA with integrated Failure Mode Database
SILCap
Safety Criticality Analysis, System FMEA and S/W-HAZOP
Tool-Based Design
Support
Guideline
Copyright exida LLC ® 2000-2012
ISO 26262: If you did it well…
– Traceability: – Documentation:
Structured Process Model All activities planned
Documents linked Execution documented in SC
Evidence for Everything Inspected - Archived
Understandable for external For a life-time (15year?)
EXIDA SCOPE
Functional SERVICES
INDUSTRIES
Safety Tools CUSTOMERS
Process
Industry End Users
Cyber Training Equipment
Automotive
Security Manufacturer
Consultancy Machine
Industry Car
Manufacturer
Reliability Certification Power
Industry System
Integrators
Alarm Reference Rail
Management Materials