
UM1915 Rev 3
13/43
UM1915
STM8AF safety architecture
42
3.4
Electrical specifications and environment limits
The user must not exceed the electrical specification and the environmental limits defined
in the list below, as reported in STM8AF datasheets, to guarantee its own safety integrity:
•
absolute maximum rating
•
operating conditions.
Due to the large number of STM8AF products, the related user manuals/datasheets are
not listed in this document; the user is responsible to carefully check the above reported
limits in the technical documentation on the related part number available on
www.st.com.
3.5 Systematic
safety
integrity
Due to known device limitations for STM8AF automotive MCUs, the user must follow the
errata sheets available on
www.st.com
to avoid the introduction of systematic failures.
3.6 Safety
mechanisms/measures
This section lists all the safety mechanisms/measures (hardware, software and application
level) considered in the safety analysis of the microcontrollers of the STM8AF Series.
According to ISO 26262-1,
“…a safety mechanism is a technical solution implemented by
Electrical/Electronic (E/E) functions or elements, or by other technologies, to detect faults
or control failures in order to achieve or maintain a safe state
”.
It is expected that users are familiar with the STM8AF architecture, and that this document
is used in conjunction with the related device datasheet, user manual and reference
information. Therefore, in order to avoid any mistake and reduce the amount of information
to be shown, no functional details are included in this document.
Note that the part numbers of the STM8AF Series represent different combinations of
peripherals (for instance, some of them are not equipped with CAN peripheral). To reduce
the number of documents and avoid information-less repetitions, the current safety manual
addresses the overall possible peripherals available in the targeted part numbers. Users
have to select which peripherals are really available on their devices, and discard the
meaningless recommendations accordingly.
The implementation guidelines reported in the following section are for reference only. Read
the following definitions:
•
end user:
the final user of STM8AF, in charge of integrating the MCU in a real
application (for example an electronic control board)
•
application software
: the actual software running on the STM8AF, used to
implement the safety function.
3.6.1 STM8AF
core
Periodical core self-test software - CPU_SM_0
Permanent faults affecting the CPU are addressed through a dedicated software test
executing a sequence of instructions and data transfers.
The software test is built around well-known techniques already addressed by ISO
26262-5, D.2.3.1 (“
Self-test by software: limited number of patterns (one channel)
”). The