Hello,
My name is Vitalij. I represent a small group of electronics engineers from Riga.
At the moment we are redesigning / upgrading data acquisition and control system for fire alarm applications. The problem is so that the system must meet requirements of the SIL2 standard (SIL2 - Safety Integrity Level 2). What are main requirements regarding hardware and firmware design? The system consists of different I/O modules that are interconnected via RS485. In general optocouplers are used for inputs and relays - for outputs. What are additional requirements for I/O? Perhaps self-test or something else…?
All modules feature isolated power supply and isolated RS485 interface. At the moment data integrity is ensured by CRC16.
We took a look on several SIL2 compliant devices. They use 2 MCUs to increase system reliability. Is this option required for SIL2? If yes, how can this be implemented?
Texas Instruments provides dedicated TMS570LS Family. "The Hercules TMS570LS Safety MCU family enables customers to easily develop safety-critical products for transportation applications. Developed to meet the requirements of the ISO 26262 ASIL-D and IEC 61508 SIL-3 safety standards and qualified to the AEC-Q100 automotive specification this ARM® Cortex™-R4F based family offers several options of performance, memory and connectivity. Dual core lockstep CPU architecture, hardware BIST, MPU, ECC and on-chip clock and voltage monitoring are some of the key functional safety features available to meet the needs of automotive, railway and aerospace applications"
Can we rely on this family of microcontrollers to meet all SIL2 requirements? Or is single MCU also acceptable?
Additional peripheral modules of the MCU are onboard memories: FRAM or optionally microSD card. FRAM is more preferable for us because ease of use.
I will be waiting for your response.
Best regards,
Vitalij