Euf Aut t3871
Euf Aut t3871
Company Public – NXP, the NXP logo, and NXP secure connections for a smarter world are trademarks of NXP
B.V. All other product or service names are the property of their respective owners. © 2019 NXP B.V.
Agenda
• Introduction
• ISO 26262:2018 Edition 2
• Functional Safety @ NXP
• Example of a System Safety Solution:
Power Inverter Module (PIM)
COMPANY PUBLIC 1
Global Megatrends
Safe and Secure Mobility - More than tripling the semi value per car
COMPANY PUBLIC 2
Automated SENSE THINK ACT
Cellular
Evolving Vehicle Connectivity Connectivity
WiFi, BT, GNSS, NFC Domain
Architecture Controller
Smart Car Access
V2X
Sensor Fusion
ADAS & Highly Radar & Planning
Automated Driving Domain
Camera Controller
Lidar
Network Gateway
Motion & Pressure
Engine Steering
Powertrain & Powertrain
Powertrain
Transmission Airbag
Speed Domain
Domain Brake Suspension
Vehicle Dynamics Controller
Controller Battery Cell Management
Ultrasonic
Audio
Infotainment and Cockpit
eCockpit eCockpit
In-Vehicle Touch Displays Domain
Domain
Controller
Controller Amplifiers
Experience Voice Recognition
COMPANY PUBLIC 3
Requirements for a Safe System
Cyber Security
Functional Safety Zero accidents due to
Zero accidents due to system hacks
system failures
Vehicle Safety
Zero accidents due to
human error
Device Reliability
Zero accidents due
to device defects
COMPANY PUBLIC 4
Why Safety Is Important
Standardization – consolidating
platforms and harmonizing systems
COMPANY PUBLIC 5
Safety and Security Are Closely Linked
>25
Vehicle hacks
published since 2015 Why hacking? Why is it possible? Why now?
COMPANY PUBLIC 6
ISO 26262: 2018 Edition 2
COMPANY PUBLIC 7
What is Functional Safety?
PUBLIC 8
Quantify a Risk: Automotive Safety Integrity Level
COMPANY PUBLIC 9
Automotive Functional Safety Standards
• Indicator of industry maturity
COMPANY PUBLIC 10
ISO 26262: 2018 - What’s New Compared to Edition 1
ISO 26262 Deliverables
IP Management New
2018 Edition 2
Safety Analysis- DFA Improved
Confirmation Improved
Measures
COMPANY PUBLIC 11
Functional Safety @ NXP
COMPANY PUBLIC 12
NXP BCAM7 Process Development
Automotive
IATF 16949 ISO 26262
SPICE
Templates
Policies Roles & Resp. Procedures Tools
Checklists
COMPANY PUBLIC 13
ISO 26262 : 2018 – NXP Tailoring
Roles Functional Safety
Development Types
Project Functional Safety Safety Element out of Context
Manager (SEooC)
- QM or ASILx
- Safety analysis (FTA, DFA, FMEDA)
- Confirmation review Safety Analysis
- Impact Analysis - Functional Safety design assessment
- CR Impact Analysis
- Assessment plan - Safety concept
(Requirements
& Architecture)
- Safety Case
- Safety Manual
- Functional Safety Release assessment
- Safety plan - Confirmation review Safety case
- SW tool criteria Evaluation
- Verification Plan (inc. safety)
- Confirmation review Safety Plan
- CR technical safety concept
COMPANY PUBLIC 15
Functional Safety Competence Management
Standard
Trainign Library
E-Learning courses
COMPANY PUBLIC 16
System Safety Solution
Example of Power Inverter Module
COMPANY PUBLIC 17
Key Growth Areas of Automotive
Electronic Systems
30% Automotive Systems Growth 17-22
25%
The car is evolving to a sophisticated
electronic system that
20% senses, thinks, connects,
and acts and is ‘always on’
15%
Internal combustion engines are
replaced or complemented by
10%
electric propulsion
5%
0%
Motor control
(HV inverters)
48 V eMachine
(BSG, ISG, HVAC)
DC/DC voltage
domain converter
On-board charger
AC/DC converter
System perspective
IP perspective
HW IP SW IP
Safety Analysis Safety Design Safety
(SEooC) (SEooC)
Verification
COMPANY PUBLIC 20
System Safety Enablement
FS65
Smart, flexible
Fail-safe SBCs
Leadership ASIL-D
Certified MCUs
Integrated Isolated HV
IGBT gate driver
Traction Motor
Inverter Systems
COMPANY PUBLIC 22
Functional Safety ISO 26262 - 2018 Applies NXP
Part 1: Vocabulary
Part 2: Management of Functional Safety
Part 3: Concept Phase
Part 4: Product development at system level
Part 5: Product development at HW level
Part 6: Product development at SW level
Part 7: Production and operation
Part 8: Supporting processes
Part 9: Automotive Safety Integrity Level
(ASIL) oriented and safety oriented
analyses
Part 10: Guideline on ISO 26262
Part 11: Guideline for Semiconductors
COMPANY PUBLIC 23
Item, HaRa and Safety Goals
Assumptions:
• Powertrain inverteur HighVoltage (>350V)
• No clutch between Electrical motor and Vehicle
Wheels
• Gas and Brake Pedals command from driver to
VCU
• Inverter Torque request from VCU
• 3 phases Motor up to 80kW
COMPANY PUBLIC 25
Extract of Functional Block Safety Requirements
− Define FR and FSR
− Decompose Functional Safety Requirement
− Documentation
COMPANY PUBLIC 26
Extract of Technical Safety Concept
− Technical requirements
− Technical safety requirements
− Diagnostic & reaction
− Documentation
COMPANY PUBLIC 27
System Failure Matrix & System Safety Mechanism
HW / SW requirements SW requirements
for Safety Mechanism for Safety manager
COMPANY PUBLIC 28
NXP Safety Enablement Deliverables
HW Safety Architecture
• NXP System Safety Concept
documentation (FSC, TSC architecture)
• NXP System Failure matrix
• NXP Prepared System FMEDA
(with IC system FMs)
• NXP SDK SW
(with system safety mechanism)
SW Safety Architecture
• NXP ICs datasheet
• NXP ICs Safety manuel
• NXP ICs Safety analysis report
• NXP ICs Assessment report
• NXP ICs expert support
COMPANY PUBLIC 29
SafeAssure Program
SafeAssure Community
COMPANY PUBLIC 30
NXP’s Safe Assure Program
Functional Safety Standards
• Launched SafeAssure initiative in September
2011 focusing on NXP’s functional safety Automotive Industrial
solutions ISO 26262 IEC 61508
Safety
Support
Safety
Process
• 100+ Products being developed to target ISO
26262:
▪ Aug 2012 AMP HW – Leopard (MPC564xL) 32-bit MCU –
Certified by Exida
▪ 2013 AMP SW – First release of Safety MCAL (sMCAL)
NXP Quality Foundation
▪ 2014 AAA HW – Analog – PowerSBC
COMPANY PUBLIC 31
SAFEASSURE
SafeAssureCOMMUNITIES
Community
Customer Support for Functional Safety
Customer support for Functional Safety
Self Sufficient
Community users find answers to their questions an safety documentation requests
COMPANY PUBLIC 32
nxp.com/SafeAssure
COMPANY PUBLIC 33
COMPANY PUBLIC 34