
UM1915 Rev 3
25/43
UM1915
STM8AF safety architecture
42
testing of the arbitration mechanisms between peripherals. This method, based on the
periodical execution of software-based tests is executed at least once per DTI.
Note that the implementation of this safety method is overlapped by already planned
methods for the configuration register checks for the STM8AF peripherals (e.g.
CAN_SM_0
).
Implementation of all such methods is equivalent to the implementation of BUS_SM_0.
Information redundancy in intra-chip data exchanges - BUS_SM_1
Both permanent and transient faults affecting the intra-chip connection features are
addressed by information redundancy techniques implemented on the messages
exchanged inside the MCU.
Note that the implementation of this safety method is overlapped by already planned
methods related to information redundancy for the STM8AF peripherals (e.g.
CAN_SM_2
).
Implementation of all such methods is equivalent to the implementation of BUS_SM_1.
3.6.16 Supply
voltage
system
Periodical read-back of configuration registers - VSUP_SM_0
This diagnostic measure, typically referred to as “Read back periodic by software of
configuration registers”, executes a periodical check of the configuration registers of the
Power control logic respect to their expected values, previously stored in RAM and
adequately updated after each configuration change. It mainly addresses transient faults
affecting the configuration registers, detecting bit flips. The registers test is executed at
least once per DTI.
Supply voltage monitoring - VSUP_SM_1
It is required to detect early the under- and over-voltage conditions that are potential
sources of failure at MCU level. The power supply values close to the operating limits
reported in device datasheet are considered at the same level as hardware faults and lead
to similar recovery actions by the application software.
The usage of an external monitoring power supply device outside the MCU can ensure the
protection against potential common cause failures.
Warning:
To reduce the risk of an over-voltage condition, it is highly
recommended that end users respect the absolute
maximum ratings for voltage (see
Independent watchdog - VSUP_SM_2
The independent watchdog is fed directly by V
DD
; therefore, major failures in the 1.8 V
supply for digital logic (core/peripherals) do not affect its behavior but may lead to a
violation of the IWDG window for the key value writing by the application software, leading
to a system reset.