Other Parts Discussed in Thread: TMS570LC4357, HALCOGEN, TPS65381A-Q1, AMIC110
Hello,
I am going to develop an industrial drive with Functional Safety functions (such as STO, SS1, SS2, SOS, SLS, ...) according to the following standards and safety levels:
- IEC 61508 (generic functional safety standard) -> SIL3 level
- IEC 61800-5-2 (industrial drive safety standard) -> SIL3 level
- IEC 62061 (machinery) -> SIL3 level
- ISO 13849-1 (machinery) -> PLd level
Here some questions:
- If using only one Hercules MCU for each drive is sufficient for our SIL3 target (e.g. max SIL and PL, DC diagnostic coverage, redundance ...). I've read that the Hercules architecture is 1oo1D (the safety system is not redundant) so will it imply that the MCU has DC>99%?
- Which versions among the Hercules MCU family are totally certified and provided with user documentation?
- I know that TI offers tools for the validation, but which tools we need for the assessment. Have you some more detailed information or a practical example?
- Regarding the application level (the code written by us) is it validated using the tools provided by TI or do we need some external unit test (like Polyspace, Cantata, LDRA, ecc)?
- Do you have experience if someone has already succeeded to implement a IEC61508/SIL3-compliant product with only one Hercules MCU?
- We tried the Demo Kit for Compiler Qualification, but we saw there is the Hercules SafeTI Compiler Qualification Kit (that is free of charge). Which are the differences affecting the certification process?
Many Thanks,
Fax