ASIL B Compliant IC Segmentation for Automotive Safety
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Designing and manufacturing integrated circuits that implement Automotive Safety Integrity Level B (ASIL B)-compliant automotive safety-related functions is resource-intensive, and existing solutions fail to provide an affordable and effective means to meet the requirements set by standards like ISO 26262 and the German Association of the Automotive Industry's reference document.
Innovation Solution
An automotive internal combustion engine electronic control unit is designed with a dedicated integrated circuit (U-Chip) performing Quality Managed-compliant functions and a microcontroller (µC) performing ASIL B-compliant monitoring, where the U-Chip includes a diagnosis function to detect failures and the µC monitors the diagnosis function's operability, ensuring ASIL B compliance and mitigating overvoltage propagation through embedded safety-related load drivers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If integrated circuits are designed and manufactured with Quality Managed criteria, then manufacturing cost is reduced, but ASIL B safety compliance cannot be achieved
Solution Approach 1:
The system is divided into two separate integrated circuits: a first integrated circuit implementing the safety-related function with reduced safety measures, and a second integrated circuit implementing the monitoring function with full ASIL B compliance. This segmentation allows each circuit to be optimized for its specific purpose, reducing overall system cost while maintaining safety requirements.
Solution Approach 2:
A monitoring function is introduced as an intermediary mechanism that independently verifies the correct operation of the safety-related function. This monitoring circuit acts as a mediator that detects failures in the primary function without requiring the primary circuit itself to be fully ASIL B compliant, thus reducing manufacturing costs while maintaining safety compliance.
2Device complexity
If a single integrated circuit implements both safety-related functions and diagnosis functions, then device complexity is reduced, but diagnosability and safety monitoring capability deteriorate
Solution Approach 1:
The diagnosis function is extracted from the safety-related function and implemented in a separate second integrated circuit. This segmentation enables independent verification of the first circuit's operation, significantly improving diagnosability while the modular architecture keeps overall system complexity manageable.
Solution Approach 2:
The second integrated circuit continuously monitors the operation of the first integrated circuit and provides feedback about its correct operation. This feedback mechanism enhances the system's ability to detect and diagnose failures, ensuring high diagnosability while maintaining clear functional separation between the two circuits.
3Device complexity
If safety monitoring functions are integrated into the same circuit as safety-related functions, then device complexity is reduced, but the risk of system failures increases
Solution Approach 1:
The system separates safety-related functions and safety monitoring functions into different integrated circuits. This physical separation ensures that a failure in the monitoring circuit cannot directly cause a failure in the safety-related function, and vice versa, thereby reducing system failure risk while maintaining manageable complexity through modular design.
Solution Approach 2:
The second integrated circuit serves as an independent intermediary that monitors the first circuit without being part of its operational path. This independent monitoring architecture reduces the risk of cascading failures while the modular structure keeps overall system complexity controlled.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An automotive internal combustion engine electronic control unit required to perform safety-related functions with a predetermined automotive safety integrity level; wherein the automotive internal combustion engine electronic control unit comprises a microcontroller and an integrated circuit distinct from, and communicating with the microcontroller; in which the microcontroller is designed to perform one or more safety-related functions with the same automotive safety integrity level as the one required to the automotive engine electronic control unit; in which the integrated circuit is designed to perform one or more safety-related functions with an automotive safety integrity level lower than the one of the microcontroller; in which the integrated circuit is further designed to perform, for each performed safety-related function, a corresponding diagnosis function designed to detect failures in the performance of the safety-related function; and in which the microcontroller is designed to perform, for each performed diagnosis function, a corresponding monitoring function designed to monitor the performance of the corresponding diagnosis function by the integrated circuit to detect failures that may compromise the diagnostic capability of the diagnosis function.