2. Can be considered ranked as “+” if only one safety function is implemented and the presence of non-safety-
related software is excluded.
3. Must be considered ranked as “++” if Application software is executed on RAM.
The above-described safety mechanism or conditions of use are conceived with different levels of abstraction
depending on their nature: the more a safety mechanism is implemented as application-independent, the wider is
its possible use on a large range of
End user
applications.
The safety analysis highlights two major partitions inside the
MCU
:
•
System-critical
MCU
modules
Every
End user
application is affected, from safety point of view, by a failure on these modules. Because
they are used by every
End user
application, related methods or safety mechanism are mainly conceived to
be application-independent. The system-critical modules on
Device
are: CPU, RCC, PWR, bus matrix and
interconnect, and Flash memory and RAM (including their interfaces).
•
Peripheral modules
Such modules could be not used by the end-user application, or they could be used for non-safety related
tasks. Related safety methods are therefore implemented mainly at application level, as
Application software
solutions or architectural solutions.
UM2305
Conditions of use
UM2305
-
Rev 10
page 90/110