Tool/software:
Hello and thank you for your support.
We're working on a power management ECU for the automotive industry, it has to be certified according to the Functional Safety - Road Vehicles standard ISO-26262. following the safety analysis, we have software requirements that will be allocated ASIL-D integrity level (SIL3).
We are considering the use of the TMS320 family of controllers, reviewing its functional safety capability and certification we can see the following statement mentioned.
– Systematic capability up to ASIL D and SIL 3
– Hardware capability up to ASIL B and SIL 2
So to be able to assign ASIL-D software requirements to the controller, we are considering the use of two controllers, one acts as a main controller, and another smaller one acting as a checker controller, both will be integrated according to the safety manual to achieve ASIL-B hardware quantitative rating, and independence among the two will be ensured, effectively performing a decomposition on the probabilistic quantitative side of the analysis, while the systematic side is certified by TI.
I would like to get your opinion on that approach, I have not previously used controllers that make that distinction between the systematic and probabilistic ASIL rating, also if different approaches are recommended I would be happy to hear it.
Thank you.