Other Parts Discussed in Thread: TIDA-00548
We are developing a system according to IEC 61508 SIL 3. We are using a single TMS570LS0914 with a TPS65381a. Is there any recommendations on how to interface an safety related analog signal (range 0 to 10V) to a Hercules mcu?
The following schematic is from TIDA-00548. The problem with this design is that if R18 failed short, the input voltage will be directly connected to the mcu pin and will probably damage the mcu.
How is this interface considered acceptable? Is it because the shorted resistor failure probability is too small to be considered or is it because reading V_iso in TIDA-00548 isn't safety related? Or is it because an overvoltage on one of the mcu pins and damaging the mcu will cause the TPS65381a to kick and guarantee a fail safe state?