分享

Fusa_005_Safety Analysis_Dependent Failure Initiat...

 ZHAOHUI 2019-10-10
From  the last two sharing about dependent failures,we have known what is the dependent failure and why we need to perform dependentfailure analysis. Today,  I gona to talkabout Dependent failure Initialtors(DFI).
1- Dependent Failure Initiator
Same like other failures which could violate the safety goals or higher safetyrequirements, the dependent failure initiators are either random hardware faults or systematic faults. 
The picture below shows thetypical sources of dependent failure initiator in detail.


In 4.7.5.1of ISO 26262-2018 : Part 11, the dependent failure initialors are classifiedinto 7 classifications:
  • DFI ofshared resources

  • DFI singlephysical root cause

  • DFI environmentalfaults

  • DFI developmentfaults

  • DFI manufacturingfaults

  • DFI installationfaults

  • DFI service faults

The part 11also provides some examples of dependent failure initiators and their commonlyused safety mechanisms including the safety mechanisms to provent DFI fromviolating the safety goals and prevent DFI occurrence during operation. 
Eventhough the examples are mainly for the semiconductors, they are still worth forreference. Let's look at them in detail.

1.1  DFI of Shared Resources

For thedependent failure initiator of shared resources, the potential causes could be:

  • Shared inputs

  • Communication

  • Shared other resource

They arehighlighted with red cycles in the picture below:


 The examples of dependent failure initiators of shared resources and their safety mechanisms are given in the table below:


1.2  DFI of single physical root cause

 The potentialsources of the DFI with single physical root cause are shown in the picturebelow with red cycles.


The examples of dependent failure initiators of single physical root cause and their safety mechanisms are given in the table below:


1.3 DFI of environmental faults

The potentialsources of the DFI of environmental faults are shown in the picture below withred cycles.


The examples of dependent failure initiators of environmental faults and their safety mechanisms are given in the table below:


1.4 DFI of development faults

The potentialsources of the DFI of development faults are shown in the picture below withred cycles.


The examples of dependent failure initiators of development faults and their safety mechanisms are given in the table below: 


1.5 DFI of manufacturing faults

The potentialsources of the DFI of manufacturing faults are shown in the picture below withred cycles.


The examples of dependent failure initiators of manufactureing faults and their safety mechanisms are given in the table below:


1.6 DFI of installation faults

The potentialsources of the DFI of installation faults are shown in the picture below withred cycles.


The examples of dependent failure initiators of installation faults and their safety mechanisms are given in the table below:


1.7 DFI of service faults

The potentialsources of the DFI of service faults are also mainly systematic coupling faults. 

Servicein automotive typically happens by replacement of the whole ECUs or sensormodules. Thus the DFI of service faults mainly due to systemactic coupling. Since it is too difficult to replace or to fix, the semiconductor components aretypically not serviced.
Actually,in order to help the users to have a better understanding of the dependent failure, and to correctly perform the depenedent failure analysis, more descriptions of dependentfailure are  provided in detail in thenew edition of ISO 26262 than the first version:
  • In Part 9

  • Describeshow to identify, analyse and mitigate or reduce dependent failures
  • Dependantfailure initiators are defined in Annex C
  • In Part 11

  • Examples of dependent failures to consider

  • Anexample workflow

  • Amicrocontroller and analogue example in Annex B

  • How to Verificationof the mitigation measures

If you read though all of the parts related to dependent failure in Part 9 and Part 11, you will have a better understanding of it.

2-  Reference

[1] ISO 26262-9: 2018 Automotive safety integrity level (ASIL)-orented and safety-oriented analyses

[2] ISO 26262-11: 2018 Guidelines on application of ISO 26262 to semiconductors

[3] Improvements in Functional Safety of Automotive Semiconductors and IP through ISO 26262:2018 Part 11

3-  About 功能安全沙龙

功能安全沙龙 is used as  an Wechart Public Account for the technical sharing platform on following topics :

  • ISO 26262
  • SOTIF/ ISO 21448
  • Cyber-security/J3061 or ISO-21434
  • Powertrain Control of PHEV and EV
  • ADAS or ADS or AD vehicles

    本站是提供个人知识管理的网络存储空间,所有内容均由用户发布,不代表本站观点。请注意甄别内容中的联系方式、诱导购买等信息,谨防诈骗。如发现有害或侵权内容,请点击一键举报。
    转藏 分享 献花(0

    0条评论

    发表

    请遵守用户 评论公约

    类似文章 更多