ISO 26262
Functional Safety Management in the Autonomous Car industry and the
- verview of the required safety
lifecycle
TÜV SÜD America PSES San Diego Chapter Meeting Sep. 12, 2017
TÜV SÜD AG Slide 1
ISO 26262 Functional Safety Management in the Autonomous Car - - PowerPoint PPT Presentation
ISO 26262 Functional Safety Management in the Autonomous Car industry and the overview of the required safety lifecycle TV SD America PSES San Diego Chapter Meeting Sep. 12, 2017 TV SD AG Slide 1 Functional Safety Expert: Peter
TÜV SÜD AG Slide 1
Background:
Royal Navy
Processes, Tools +Config, Python, Perl.
Software, Safety shutdown systems
PLC/Instrumentation Logic controls/Safety shutdown systems, risk assessment/analysis
300mm Projects
ISO 13849 & IEC 62061, IEC 61800-5-2, IEC 61508, System Test and logic design, IEC 61010).
25.09.2017
Homologation
components and processes regarding means of functional safety
ECE 13 and ECE 79
railway, infrastructure and automation
systems (µC, SW Tools)
ISO 26262 …
Knowledge transfer Knowledge transfer
TÜV SÜD Rail GmbH Folie 4 18.01.2017
TÜV SÜD Rail GmbH Folie 5 18.01.2017
6
TÜV SÜD Rail GmbH Folie 6 18.01.2017
TÜV SÜD AG Slide 7
IEC 61508 Functional safety of electrical/electronic/ programmable electronic safety related systems ISO/IEC 15504 SPICE/Automotive SPICE ISO/IEC 12207 Software lifecycle process IEC 62304 Software for medical devices ISO 13849 IEC 62061 Safety of machines EN 50271 EN 50402 Functional safety of gas warning systems
IEC 61511 Safety instrumented systems for the process industry sector EN 50126 EN 50128 EN 50129 ISO 26262 Functional safety “road vehicles” ARP 4761 ARP 4754 RTCA/DO 178C RTCA/DO 254 ...
IEC 60880 Nuclear power– control technology, Software aspects IEC 61513 TÜV SÜD AG Slide 7
TÜV SÜD AG Slide 8
TÜV SÜD AG Slide 9
TÜV SÜD AG Slide 10
TÜV SÜD AG Slide 11
(Process for Certification)
Legally binding Application of, e.g., EU directives and ECE regulations (Europe), FMVSS (USA)
Recommended Application of IEC, ISO, EN or DIN standards (“State of the art”)
TÜV SÜD AG Slide 12
Unintended deceleration Unintended acceleration Unintended loss of acceleration Unintended loss
Unintended vehicle movement
(safety functions, e.g., pinch protection)
High Voltage Explosion
Fire
13
source: siemens.com
TÜV SÜD Rail GmbH Folie 13 18.01.2017
14
source: wikipedia.com
TÜV SÜD Rail GmbH Folie 14 18.01.2017
15
Adaptive Cruise Control Adaptive Front Lighting Airbag Control Engine Control Wiper Control Night Vision Driver Alertness Monitoring Instrument Cluster Automatic Breaking Electric Power Steering Electronic Throttle Control Electronic Valve Timing Idle Stop/Start Cylinder De-activation Active Vibration Control OBDII Remote Keyless Entry Blindspot Detection Lane Departure Warning Transmission Control Seat Position Control Electronic Stability Control Active Yaw Control Parking System Antilock Braking Tire Pressure Monitoring Regenerative Braking Hill-Hold Control Active Suspension Active Exhaust Noise Suppression Security System Navigation System Digital Turn Signals Electronic Toll Collection Lane Correction Battery Management Entertainment System DSRC Cabin Environment Controls Voice/Data Communications Active Cabin Noise Suppression Interior Lighting Event Data Recorder Accident Recorder
TÜV SÜD Rail GmbH Folie 15 18.01.2017
16
TÜV SÜD AG Slide 17
TÜV SÜD AG Slide 18
TÜV SÜD Rail GmbH Folie 20 18.01.2017
Distributed Development Safety Requirements Configuration Management Change Management Verification Documentation Software Tools Qualification of Software Qualification of Hardware Proven in Use Argument
TÜV SÜD Rail GmbH Folie 23 18.01.2017
requirements throughout supply chain */
responsibility to monitor and maintain functional safety after release for production*/
ISO 26262-6 and supporting processes of ISO 26262-8*/
supplier-related requirements, e.g.: supplier selection and functional safety assessment, development interface agreement (DIA)*/
specific, but impacts corporate level. ISO 26262 requires to install a Safety Culture in the organization.*/“
TÜV SÜD Rail GmbH Folie 24 18.01.2017
Slide 25
Corporate Quality Manual, Corporate Project Management Manual Modification Procedure Safety Plan, Validation Plan
Safety Goals Technical Safety
HW Requirements Specification Instructions for use SW Requirements Specification SW State machine diagram Technical Safety Concept SW & HW Architecture Descr. HW Design documentation SW Detailed Architecture SW Detailed Design SW Source Code
Functional Safety
Confirmation Reviews Conformance & Audit reports
Integration Test Spec.& Report
System Test
Block-level FMEDA SPF Metric, LF Metric Calculation, PMHF Component FMEDA HW Test Spec.& Report SW Test Spec.& Report FTA Vehicle&Item Level Test Spec. & Report
System Safety Requirements SW safety Requirements HW safety Requirements SW Module HW Block method, function HW Component Hazards and risks Source code section Functional failure modes Component failure modes Coding rules and restrictions Validation test case and result Integration test case and result SW qualifi. Test case and result Module test case and result SW static analysis result
26
ISO 26262-5; Figure C.1 — Fault classification of safety-related hardware elements of an item
ISO 26262-5; Figure C.1 — Fault classification of safety- related hardware elements of an item
TÜV SÜD Rail GmbH Folie 30 18.01.2017
TÜV SÜD Rail GmbH Folie 32 18.01.2017
TÜV SÜD Rail GmbH Folie 34 18.01.2017
35
ASIL A,B,C ASIL D ASIL A,B ASIL C,D
for TI2 with TD1 Determine confidence in measures for prevention and detection of malfuctions Determine maximally required ASIL Qualify SW tool, or methods & processes (”workflow” for the SW tool) Determine possibility that an error is introduced or not detected by tool
17-09-25 Slide 36 TÜV SÜD Automotive Functional Safety & Security
TÜV SÜD Automotive Department Tel: 213-784-5234 mailto:pspence@tuvam.com http://www.tuev-sued.de http://www.tuev-sued.de/rail/training