1
About this document
1.1
Purpose and scope
This document describes how to use Arm
®
Cortex
®
‑
M4 -based STM32L4 and Series
devices (further also referred to as
Device
(s)) in the context of a safety
‑
related system, specifying the
user's responsibilities for installation and operation, in order to reach the desired safety integrity level.
It is useful to system designers willing to evaluate the safety of their solution embedding one or more
Device(s)
.
For terms used, refer to the glossary at the end of the document.
Note:
Arm is a registered trademark of Arm Limited (or its subsidiaries) in the US and/or elsewhere.
1.2
Normative references
This document is written in compliance with the IEC 61508 international norm for functional safety of electrical,
electronic and programmable electronic safety-related systems, version IEC 61508:1-7 © IEC:2010.
The other functional safety standards considered in this manual are:
•
ISO 13849-1:2015, ISO13849-2:2012
•
IEC 62061:2005+AMD1:2012+AMD2:2015
•
IEC 61800-5-2:2016
The following table maps the document content with respect to the IEC 61508-2 Annex D requirements.
Table 1.
Document sections versus IEC 61508-2 Annex D safety requirements
Safety requirement
Section number
D2.1 a) a functional specification of the functions capable of being performed
D2.1 b) identification of the hardware and/or software configuration of the
Compliant item
D2.1 c) constraints on the use of
Compliant item
or assumptions on which analysis of the behavior or
failure rates of the item are based
D2.2 a) the failure modes of
Compliant item
due to random hardware failures, that result in a failure of
the function and that are not detected by diagnostics internal to
Compliant item
;
D2.2 b) for every failure mode in a), an estimated failure rate;
D2.2 c) the failure modes of
Compliant item
due to random hardware failures, that result in a failure of
the function and that are detected by diagnostics internal to
Compliant item
;
D2.2 d) the failure modes of the diagnostics, internal to
Compliant item
due to random hardware failures,
that result in a failure of the diagnostics to detect failures of the function;
D2.2 e) for every failure mode in c) and d), the estimated failure rate;
D2.2 f) for every failure mode in c) that is detected by diagnostics internal to
Compliant item
, the
diagnostic test interval;
D2.2 g) for every failure mode in c) the outputs of
Compliant item
initiated by the internal diagnostics;
D2.2 h) any periodic proof test and/or maintenance requirements;
D2.2 i) for those failure modes, in respect of a specified function, that are capable of being detected by
external diagnostics, sufficient information must be provided to facilitate the development of an external
diagnostics capability.
D2.2 j) the hardware fault tolerance;
D2.2 k) the classification as type A or type B of that part of
Compliant item
that provides the function (see
7.4.4.1.2 and 7.4.4.1.3);
UM2305
About this document
UM2305
-
Rev 10
page 2/110