Contact us

在新窗口打开 在新窗口打开

功能安全技术

东芝公司提供的微处理器具有经过优化的故障紧密监督系统,以此确保功能安全。并且荣获了授权认证机构颁发的IEC61508 SIL3技术报告1。这些微控制器提供更安全、更具成本效益的解决方案。

东芝公司SIL3技术

这是东芝公司SIL3技术的外形综述图。

优化了的故障紧密监督系统,执行内核A与一套硬件检查器紧密配合工作,每一个检查器包含一个比较器和一个自我诊断设备。通过这种方式,能够自动进行比较和自我诊断。与传统双核配置相比,新配置减少了硬件的数量和软件的大小。

低成本故障安全和带故障运行系统提案

开车时如果控制引擎的MCU出现故障
竞争者的微控制器 东芝公司的紧密耦合微控制器
一对一单核 不能实施故障安全功能(需要从微控制器)
不能实施故障安全功能
(需要从微控制器)
在不稳定巡航的条件下安全地停止汽车(故障安全)
在不稳定巡航的条件下安全地停止汽车
(故障安全)
二中选一双核 在不稳定巡航的条件下安全地停止汽车(故障安全)

在不稳定巡航的条件下安全地停止汽车
(故障安全)

将汽车保持在稳定巡航的状态下(带故障运行和容错系统)

将汽车保持在稳定巡航的状态下
(带故障运行和容错系统)

东芝公司的单核微控制器支持故障安全功能,传统上需要执行双内核才能达到这个目的。另外,东芝公司的双核微控制器支持故障运行和容错系统。

Toshiba Functional Safety Package

Toshiba offers a support environment not only from a system perspective but also from a customer perspective.

This figure shows the diagram of functional safety package.

Feature 1: Support from a device perspective

Toshiba's functional safety technology is based on an optimized tightly coupled fault supervisor, which observes and directs the operation of not only the CPU but also its peripherals. The functional safety alarm output at the interface between an MCU and a power supply IC can be monitored to enhance automotive functional safety from a system perspective.

Example of Functional Safety Block for an Automotive MCU (including the interface between the MCU and the power supply IC)

This is a example of functional safety block for an automotive MCU.

Features of the Functional Safety Block
  • Monitors all the peripheral blocks, the CPU, buses and memories used by application software except a few communication control blocks
  • Incorporates an fRNET block that handles alarms from all the monitor functions
  • Sends alarm signals from all the monitor functions directly from fRNET to the external world without involving the CPU
  • Self-diagnosis function of fRNET to protect its alarm-handling function

*1 Fault diagnosis circuit from Yogitech that monitors memories
*2 Fault diagnosis circuit from Yogitech that monitors the on-chip CPU buses
*3 Fault diagnosis circuit from Yogitech that monitors the entire CPU
*4 Fault diagnosis circuit developed by Toshiba
*5 Fault diagnosis circuit from Yogitech that collects all alarm and fault information and manages fault handling

Feature 2: Fault Injection (Under Development)

The Full-ICE MCU emulator provides a fault injection test environment that can directly be connected to a customer's hardware evaluation environment. It is easy to learn and yet allows flexible fault injection testing.

This figure shows the diagram of fault injection system development flow.

Feature 3: Functional Safety IP Library

The Functional Safety IP Library is a software library designed to detect faults in an automotive MCU. It has been created using a software development process certified by TÜV-SÜD.

The Functional Safety IP Library helps its users reduce development time.

This figure shows software library offerings.

Reduction in the time required to create a safety mechanism
  • Performs requirements analysis and verification on the fault diagnosis section of an MCU
  • Identifies application-specific interfaces (APIs) to enable quick feedback to a system design
  • Guarantees that the fault coverage required by ASIL D is met

This figure shows reduction in the time required to create a safety mechanism.

Reduction in the time required to meet accountability requirements
  • A set of documents necessary to achieve accountability is pre-packaged.

This figure shows reduction in the time required to meet accountability requirements.

什么是功能安全?

以铁路和公路的交叉口为例,如何确保安全呢?
  • 立交桥:本身便可以阻止危险的发生(本质安全型)
  • 铁路交叉口:通过使用安全系统阻止危险的发生(功能安全型)
为实现功能安全,在设计时必须实施一系列阻止故障发生的措施。
  • 确定性故障:硬件和软件的设计是否能消除功能缺陷?
  • 随机硬件故障:硬件设计时,是否考虑到了磨损和偶发故障?
电子控制系统的国际标准
  • 适用于所有行业的基本功能安全标准: IEC61508 (第二版:2010年4月发行)
    范围:原子能设备、铁路、处理设施(工厂)、工业机器、汽车等等。
  • 适用于汽车电气/电子系统的IEC61508:ISO 26262(2011年11月15日实施)

* ARM,Cortex和Thumb是ARM Limited公司在欧盟和其他国家使用的商标或注册商标。

* 本文中涉及到的系统和产品名称可能是相关公司或组织的商标或注册商标。

联系方式

如您需查询,请点击其中任何一个链接

技术方面的问题
购买、样片和IC可靠性的相关咨询
·Before creating and producing designs and using, customers must also refer to and comply with the latest versions of all relevant TOSHIBA information and the instructions for the application that Product will be used with or for.