Browse Publications Technical Papers 2013-01-0185
2013-04-08

A New Approach to Input and Output Monitoring for Microcontrollers Supporting Functional Safety 2013-01-0185

It is very common that a microcontroller is used in a safety relevant system to acquire data from sensors, process the data and then control actuators. With the shrink of technology every few years it becomes ever more common to use digital serial interfaces and high speed PWM links for both inputs and outputs. The microcontroller vendors have responded to the need for functional safety in the CPU cores by lock-stepping them and adding ECC to buses and memories. They are also implementing highly flexible and complex timer peripherals to be able to automate much of the real-time processing of the digital signals. However these timers are becoming significantly large, and many have their own embedded sequence engines or microkernels, which although powerful, often lack the rigorous diagnostic mechanisms required to reach ASILD. Currently the only solution is to use an application level measure to detect timer failures, but the large quantity of signals can lead to a substantial CPU load just for the monitoring tasks. This paper describes how a new I/O Monitoring peripheral can be used to ‘lockstep’ digital input and output signals, using two redundant or diverse timer peripherals. It will outline the problems, the current state of the art, and the proposed new solution, together with some typical use-cases of braking, electrical power steering and airbag.

SAE MOBILUS

Subscribers can view annotate, and download all of SAE's content. Learn More »

Access SAE MOBILUS »

Members save up to 16% off list price.
Login to see discount.
We also recommend:
TECHNICAL PAPER

Development and Comparison of Monitoring Functions for Electric Vehicles

2013-01-0176

View Details

TECHNICAL PAPER

Authentication and Secure Communication for In-Vehicle Networks

2005-01-1533

View Details

TECHNICAL PAPER

Open-Interface Definitions for Automotive Systems1 Application to a Brake by Wire System

2002-01-0267

View Details

X