Professional Documents
Culture Documents
08 Fuhrman
08 Fuhrman
Tom Fuhrman
General Motors R&D
IFIP Workshop
June 25-27, 2010
Automotive Challenges and Goals
Driver Challenges Goals
Energy • Rising cost of petroleum fuels • Reduce fuel consumption
• Non-renewability of fossil fuels • Zero dependency on fossil
• Increasing gov’t regulations for fuels
fuel economy
SBZA-R
US-R RCTCW-R
F-SRR-R R-SRR-R
F-LRR F-CAM
F-SRR-L R-SRR-L
US-L
RCTCW-L
SBZA-L
Where does failure diagnosis fit in?
OEMs
Suppliers
Technical Services
Concept phase
Hazard analysis
3-6 and risk assessment
3-7
Functional safety
concept Most diagnostic
requirements
4 Product development:
Product development
system level
7-4 Production
After SOP
Back to appropriate
lifecycle phase
Operation, service
7-5 and
decommissioning
ISO 26262 Process Overview
3-4 Item definition
Initiation of the
3-5 safety lifecycle
Concept phase
Hazard analysis
3-6 and risk assessment
Functional safety
3-7 concept
4 Product development:
Product development
system level
7-4 Production
After SOP
Back to appropriate
lifecycle phase
Operation, service
7-5 and
decommissioning
ISO 26262 Concept Phase
System
Requirements
Functional Safety
Concept
System
Requirement Functional
Safety
Requirement
ISO 26262 Hazard Analysis and Determination of
ASIL (Automotive Safety Integrity Level)
S0 S1 S2 S3
No injuries Light and Severe and life- Life-threatening injuries
moderate threatening injuries (survival uncertain), fatal
injuries (survival probable) injuries
E0 E1 E2 E3 E4
Incredible Very low Low Medium Probability High Probability
probability probability
C0 C1 C2 C3
Controllable Simply Normally controllable Difficult to control or
in general controllable uncontrollable
ISO 26262 Hazard Analysis and Determination of
ASIL (Automotive Safety Integrity Level)
C1 C2 C3
E1 QM QM QM
E2 QM QM QM
S1
E3 QM QM ASIL A
E4 QM ASIL A ASIL B
E1 QM QM QM
E2 QM QM ASIL A
S2
E3 QM ASIL A ASIL B
E4 ASIL A ASIL B ASIL C
E1 QM QM ASIL A
E2 QM ASIL A ASIL B
S3
E3 ASIL A ASIL B ASIL C
E4 ASIL B ASIL C ASIL D
ISO 26262 Identification of Safety Goals
Fault Y
Hazard B Safety Goal N
ASIL C
Through hazard Fault Y Per analysis results, Fault Y
analysis, ASIL and is implicated for both
potential source faults Goals M and N but since
Goal N is associated with a
are determined and Fault Z higher ASIL (C), safety
Safety Goals are mechanisms to cover for
identified. Fault Y must satisfy ASIL C
failure rate targets.
ISO 26262 Process Overview
3-4 Item definition
Initiation of the
3-5 safety lifecycle
Concept phase
Hazard analysis
3-6 and risk assessment
Functional safety
3-7 concept
4 Product development:
Product development
system level
7-4 Production
After SOP
Back to appropriate
lifecycle phase
Operation, service
7-5 and
decommissioning
ISO 26262 System Level
Technical Safety
Concept
Technical
Safety
Requirement
ISO 26262 Process Overview
3-4 Item definition
Initiation of the
3-5 safety lifecycle
Concept phase
Hazard analysis
3-6 and risk assessment
Functional safety
3-7 concept
4 Product development:
Product development
system level
7-4 Production
After SOP
Back to appropriate
lifecycle phase
Operation, service
7-5 and
decommissioning
ISO 26262 Hardware Design
Residual
Covered Fault
PE SM
2-
DP
Dual
Dual Point Point
Fault Fault
ISO 26262 Hardware Design: Fault Model
ISO 26262 Hardware Design: Fault Model
ISO 26262 Hardware Design: Diagnostic Coverage
Metrics 1st Order
Safety Mechanism
2nd Order
Safety Mechanism
Primary Safety Safety
Evaluates level of diagnostic coverage Element Mechanism 1 Mechanism 2
(PE) (SM1) (SM2)
and safe faults vs. undetected faults
Single Point Latent Failure
Failure Metric Metric
Based on safety goal ASIL
Dual Point
Single Point
Faults
& Residual
Single Faults Latent
Point Failure
Failure = Metric =
Metric All
Faults
Concept phase
Hazard analysis
3-6 and risk assessment
Functional safety
3-7 concept
4 Product development:
Product development
system level
7-4 Production
After SOP
Back to appropriate
lifecycle phase
Operation, service
7-5 and
decommissioning
ISO 26262 Software Design
Radar
ECU 1
Camera EPS
ECU 2
Lidar EBCM
ECU 1
Camera EPS
ECU 2
Lidar EBCM
¶ Questions?