ISO26262 Part 5 Hardware Development (E)- Clause 8 Example of SPFM and LFM in HW Architectural

 

 

SG- Safety Goal

uese Severity , Exposure , Controllability to get the ASIL level

image-blog-qac-iso-26262

SM - Safety Mechanism

Components Redundency

 

 

Can be Detected in circuit

 

 

Can be Perceived by driver

 

 

 

 

REF:https://www.quint-safety.com/assets/pdf/publications/QUINT-SAFETY_Whitepaper_Impact-ASIL-C_20200224.pdf

As noted in §5, it is required to implement safety measures to prevent the violation of all safety goals rated ASIL A or higher. However, no detection or mitigation measure can prevent 100% of the safety goal violations. The gap in diagnostic coverage and failures in the detection and mitigation measures still lead to the safety goal violation.

After applying detection and mitigation to a single point fault, the remaining failure rate leading to safety goal violation is called the residual fault. Since it has the same effect (but less often) than the signal point fault, the rates are added together when calculating the Single Point Fault Metric (SPFM).

Independent multiple point faults do not immediately lead to safety goal violations. However, without detection, these faults could persist indefinitely, and thus their failure rates are assigned 100% to the latent fault metric. After applying detection and mitigation to a multiple point fault, only the remaining (undetected or unmitigated) failure rate is assigned to the latent fault metric.

 

Single Point Fault Metric

 

 

ASIL B

ASIL C

ASIL D

Single point faults metric

> 90 %

> 97 %

> 99 %

 

Latent (Multiple Point) Fault Metric

 

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值