
STM8AF safety architecture
UM1915
12/43
UM1915 Rev 3
In this document any claim and computation in terms of safety metrics is done on the
activity safety scope represented by the SEooC block diagram reported in
The budget of the PMHF given to the SEooC must be (if possible) lower than 10% of the
overall PMHF budget of the safety goal, and therefore (for ASILB) the budget for the
STM8AF is 10% * 100 FIT = 10 FIT.
3.3.2 The
assumed
target
time intervals (FTTI and MPFDI)
As illustrated in
ISO 26262-1:2001 - Figure 4 - Fault reaction time and fault tolerant time
interval
, a system must be able to detect faults and move to safe state before a fault can
become a system level hazard.
In ISO 26262-1, the fault tolerant time interval (FTTI) is defined as the time span in which a
fault (or faults), can be present in a system before a hazardous event occurs.
Moreover, according to ISO 26262-1:2011, the multiple-point fault detection interval
(MPFDI) is the time span to detect multiple-point fault before it can contribute to a
multiple-point failure.
From a system point of view, the STM8AF MCU is a safety-related element, to which a
portion of the FTTI system budget is associated. As shown in
, the portion of FTTI
assigned to a SEooC (in this case the STM8AF) strongly depends on the application.
Figure 3. STM8AF FTTI allocation and cycle time
In this document, according to ISO 26262-10, 9.2.3.3 d) it is assumed that any
implemented safety mechanisms related to the STM8AF completes its functions in less
than the assigned FTTI budget time reported in
.
This value must be considered as a reference, and can be changed by the
MCU/system integrator according to its needs.
It is worth noting that, according to ISO 26262-5, 7.4.3.3, a single point fault must be
detected within the FTTI budget allocated to the component.
In this document, in accordance with ISO 26262-.5:2011, 6.4.8 – Note 1, it is assumed that
the MPFDI is equal to or lower than the item “power-up to power-down” cycle (i.e. one
driving cycle),
6\VWHPOHYHO)77,
0&8GHWHFWLRQ
):UHDFWLRQ
6:UHDFWLRQ
$FWXDWRUUHDFWLRQ
0LFURFRQWUROOHUGXW\
(QGXVHUGXW\
«
069
0LFURFRQWUROOHU)77,
7LPHIRUUHDFWLRQHJ6\VWHPUHVHW
7LPH