Reducing Steps to Achieve Safety Certification
|
|
|
- Amberly Hudson
- 10 years ago
- Views:
Transcription
1 Reducing Steps to Achieve Safety Certification WP White Paper This white paper describes the successful steps in achieving certification for an FPGA implementation of an application certified for functional safety. Safety is a critical system requirement in developing machinery that must comply with worldwide established standards such as the IEC basic functional safety standard. Altera s pre-qualified Functional Safety Data Package shortens development and certification time and reduces certification risks in safety-critical industrial applications. Introduction How to Start Many application developers have concerns about incorporating functional safety. Project managers and members of the validation team are confronted with a new and unknown field of safety certification. The concerns are typically caused by the fact that a certifying body, external auditor, gets involved with the project team. Authority over process and quality no longer lies only within the company s responsibility; it is supervised externally. Safety projects require an increased amount of process and documentation. Fortunately, not all process steps have to be re-invented or created from scratch. By using prequalified tools or applying predefined techniques and measures, it becomes much easier to achieve safety certification. Documentation plays an important role, and international standards require a stricter level of following defined rules in a project. Therefore, it helps to rely on an already-qualified set of documents, processes, and methods. To simplify and speed up the certification process, Altera worked with TÜV Rheinland and obtained qualification for Altera FPGA devices, IP, the FPGA design flow, and development tools. This qualification means that Altera tools, methodologies, and devices are sufficiently free of systematic errors and can be used in safety-critical applications. The main intent of functional safety is to prevent the risk of injury or death as a result of random, systematic, or common-cause failures in safety-relevant systems. So-called random failures are caused by a malfunction of the safety system s parts or components in contrast to systematic failures that are a result of a wrong or inadequate specification of a safety function. A common cause failure is the simultaneous malfunction of several parts of the safety device caused by a single reason, like a single power rail powering multiple components on a board. Typically the goal for product development is to get a low probability of failures during operation, or in other words, to achieve a high level of quality and reliability. Functional safety defines qualitative measures for this quality and reliability and makes it even harder for the product definition and development to achieve them. 101 Innovation Drive San Jose, CA All rights reserved. ALTERA, ARRIA, CYCLONE, HARDCOPY, MAX, MEGACORE, NIOS, QUARTUS and STRATIX words and logos are trademarks of and registered in the U.S. Patent and Trademark Office and in other countries. All other words and logos identified as trademarks or service marks are the property of their respective holders as described at Altera warrants performance of its semiconductor products to current specifications in accordance with Altera's standard warranty, but reserves the right to make changes to any products and services at any time without notice. Altera assumes no responsibility or liability arising out of the application or use of any information, product, or service described herein except as expressly agreed to in writing by Altera. Altera customers are advised to obtain the latest version of device specifications before relying on any published information and before placing orders for products or services. ISO 9001:2008 Registered Feedback Subscribe
2 Page 2 How to Start The first question to investigate before starting a safety project within your organization or company is: Which procedures are already established and available and can be reused to build the foundation for a functional safety project? Many companies apply management tools to achieve a high level of process quality, and by that, high product quality and reliability. For example, the ISO 9000 family of international standards (ISO 9000 ff.) defines the means and measures for quality management (QM) systems that are typically summarized in a QM manual. This manual provides a description of the applied methods for the daily workflow. As compliance to this quality standard is usually audited by an external certification body, it is ensured that these processes follow worldwide recognized requirements. One of the eight pillars of ISO 9000 ff. is the description, implementation of, and compliance to company-specific procedures. The standard requires a process-oriented approach within a certified organization. Maintaining well-defined processes helps in repeatedly achieving high-quality results. The procedures are typically traceable and continuously improved. Quality Management System An organization s QM systems can help start a safety-relevant project because responsibilities within the company are already clearly defined, and the procedures for handling documents are very well understood. Documents are reviewed and contain all the relevant information to assure process and product quality. The following list describes a set of attributes that should be included in each document or can be obtained by a corresponding document list to guarantee clear document identification and relevance based on the International Electrotechnical Commission s IEC 61508: Functional Safety of Electrical/Electronic/ Programmable Electronic Safety-related Systems standard, clause 5 and annex A: Document author (with description of the function within the project) Document version number Document date Document history Reference documents File location within a dedicated storage system Unambiguous and standardized document naming Clear assignment to certain project steps To avoid errors and missing or wrong product features, all the documents are reviewed and the reviews are documented in a review report. In addition, all specified requirements have to be traceable throughout the entire project to ensure that all requirements will be implemented, tested, and validated. Companies even need to document later modifications of requirements in order to understand the changes months or years later. Similar to functional safety projects, ISO 9000 ff. requires internal audits on a regular basis to ensure compliance to QM system and to identify improvements. All these measures help guarantee a high level of quality not only in standard projects, but also in safety-relevant projects. They are a critical prerequisite of all safety-relevant work. Reducing Steps to Achieve Safety Certification
3 How to Start Page 3 Project Preparation As quality standards are usually state-of-the-art, they constitute a base to start a safety project. The following topics summarize the main features of a QM system: Definition of responsibilities within a company or project team Description of available and applied processes Management and handling of process-accompanying documents Clear and repeatable procedures These aspects are described in more detail in clause 6 of IEC 61508: Safety is not just about writing high-quality C- or (V) HDL-code and assembling printed circuit boards. Safety is an overall design philosophy applied to all phases a product undergoes during its lifetime. The following sections will focus on additional aspects associated with functional safety. Functional Safety According to IEC 61508:2010 The second edition (edition 2) of the international standard IEC 61508:2010 published in 2010 includes several modifications and enhancements which have led to a state-ofthe-art standard that validates a reliable level of product quality for functional safety. The standard consists of seven parts: General requirements Requirements for electrical/electronic/programmable electronic safety-related systems Software requirements Definitions and abbreviations Examples of methods for the determination of safety integrity levels Guidelines on the application of IEC and IEC Overview of techniques and measures Figure 1 shows how IEC 61508:2010 with its seven parts is mapped into a more refined process that guides the user through the lifecycle of a safety application. Reducing Steps to Achieve Safety Certification
4 Page 4 How to Start Figure 1. Safety Lifecycle According to IEC : Concept 2 Overall Scope Definiton 3 Hazard and Risk Analysis 4 Overall Safety Requirements 5 Overall Safety Requirements Allocation Overall Planning 6 Overall Operation and 7 Overall Safety 8 Maintenance Planning Validation Planning Overall Installation and Commissioning Planning 9 10 System Safety Requirements Specification Safety-Related Systems 11 Other Risk Reduction Measures Specification and Realization Realization 12 Overall Installation and Commissioning 13 Overall Safety Validation 14 Overall Operation, Maintenance, and Repair 15 Overall Modification and Retrofit 16 Decommissioning or Disposal Edition 2 of this international standard covers among other new topics FPGA, ASIC, and CPLD technologies. These components play an important role in today s product development. Because FPGAs are increasingly replacing electronic components typically used for industrial applications, standards like the IEC have to support these evolving technology trends if they want to keep their relevance. This is achieved through regular updates to the specification. Reducing Steps to Achieve Safety Certification
5 Project Phases Page 5 Product Safety Lifecycle Project Phases Safety as an overall philosophy and requirement includes the complete product lifecycle from its beginning to the very end when the product is retired. In other words, it has to be deeply embedded in planning the system. Safety must be included in the design methodology of safe equipment early on and cannot just be considered as an afterthought. This is in contrast to typically standardized development processes that tend to cover the design, implementation, and verification of a product only. Safety considerations do not end until the decommissioning of a product. IEC 61508:2010 describes the entire lifecycle of functional safety equipment, starting from first concept description and ending at the decommissioning of a product (Figure 1). At first glance it seems that functional safety simply just introduces a significant amount of additional work at no value. If the concept and specification phase receives the required attention, then projects become much more predictable and achieve a higher level of quality. Investing in early phases of the project immediately brings an increase in productivity for the following work. Referring to Figure 1, the functional safety lifecycle contains 16 cohering steps. As the process looks fairly complex, a segmentation into four main project phases helps structure the lifecycle model more clearly (Figure 2). Figure 2. Main Project Phases Concept and Project Startup Overall Planning of Operation, Maintenance, Validation, Installation, and Commissioning Realization Hardware and Software Development Product Usage, Modification, and Decommissioning Each of these project phases will be discussed in more detail in the following sections. This white paper mainly focuses on functional safety with FPGA applications, and as such, the readily available support from Altera for the different project phases is described together with the individual project phases. Reducing Steps to Achieve Safety Certification
6 Page 6 Project Phases V-Model The V-Model (Figure 3) is commonly used in a huge variety of projects. It is a successor of the waterfall model (Figure 4) which defines a sequential design process. Compared to the waterfall model, the V-Model offers enhanced feedback and monitoring possibilities and separates the process of product specification from test, verification, validation, and integration. It describes a set of steps to be done during a project life cycle and begins with the decomposition of requirements and the clear definition of all necessary system specifications. In parallel each of these decomposition steps are accompanied by a corresponding verification step. The point of intersection of these two paths is the creation of hardware and software. Figure 3. V-Model Simplified System Design Includes Validation, Verification, and Test More Detailed View More Global View System Design Quality Monitoring Supervises Keeping of Requirements Quality Monitoring Realization Hardware and Software Development Figure 4. Waterfall Model Requirements Waterfall Model Design Implementation Verification Maintenance Reducing Steps to Achieve Safety Certification
7 Project Phases Page 7 Two main aspects have to be considered when following the V-Model. It has to follow the IEC 61508:2010 lifecycle requirements, and each step of the V-Model requires particular documents to be attached as a precondition (input) as well as a result (output) after a successful completion of the step. The TÜV-qualified Functional Safety Data Package (FSDP) from Altera contains a detailed document to guide the user in drafting a process structure. It supplies a development FPGA V-Model that can be reused, and the internal FPGA development process can adapt easily to this model to comply with the safety requirements. This FPGA V-Model is approved according to IEC 61508:2010 and comes with a detailed description of the input and output documentation recommended for each step. Each of these FPGA V-Model steps contains a detailed description of the step itself, the verification methods to be applied, and the tools to be used. This detailed documentation reduces the time the project team has to invest in a safety-centric FPGA development process significantly, and if Altera s recommendation is adopted as is, then no time has to be invested in this critical project phase. Configuration Management Concept A configuration management has to be installed to guarantee traceability and reproducibility for any kind of project. It defines a set of tools that are used within the project. Functional safety also requires that these tools be capable of fulfilling functional safety requirements and qualified for use in safety projects. It is of great value if a tool vendor like Altera qualifies its tool chain for use in functional safety projects. IEC :2010 highly recommends the use of certified tools for software design and development. If this certification is not available from the tool s vendor, it will be very difficult for the user to independently verify the tools needed for the project. Only a tool manufacturer has all the detailed information and knowledge necessary to perform a reliable tool qualification. Altera has already certified Quartus II development software version 9.0 SP2 together with TÜV for use in safety-relevant projects. This certification includes a list of detailed recommendations on how to use the tool, tool flow, intellectual property (IP), and silicon data. In addition, the package includes certification checklists and references the detailed FPGA documentation. Normally the draft specification of a functional safety concept is the most important part of the entire safety-relevant project. Having a well-defined concept determines the overall success of a project. The safety concept is also the very first step in the certification process as the certifying body should approve this concept before the project can progress to the next phase. Reviewing the concepts with the assessor at a later stage might require significant changes to the system s safety concepts, and implementation work may have to be revisited. Once the concept is approved, there are only very few possibilities to change, add, or remove safety-relevant features. This safety concept clearly defines the content of a project. Reducing Steps to Achieve Safety Certification
8 Page 8 Preparation of Quality Measures An example may illustrate this issue in more detail. The hardware fault tolerance (HFT) defines the minimum number of faults that can cause a complete drop through of the entire safety function. For example in a dual-channel architecture, a dangerous fault of one component does not destroy the entire safety function because the second channel still keeps the safety function working. In this case, the system has a HFT of one. The HFT has a significant influence on the achievable Safety Integrity Level 3 (SIL 3) of a safety product and is a major architecture decision. A HFT of 1 can be realized, for example, by two different redundant channels that can move the equipment under control (EUC) into a safe state in case of emergency. If one channel fails, the system can still rely on the remaining second channel. This is a fundamental design decision and has to be described clearly and early on in the safety concept. Later on in a project, it cannot be as easily changed. Besides normal project management aspects which are already part of the project plan, the following aspects have to be considered in the safety concept: Overall description of the system and its main parts System boundaries, usage, and mission profile Definition of the safety functions that will be implemented Interfaces to the system Analysis of risks that have to be reduced by safety functions Evaluation of the necessary SIL for risk reduction Additional standards that need to be followed depending on the range of use Description on how to achieve the required SIL Architecture principles Depending on the kind of product, this list may not be complete yet. As each safety system is adapted to particular functional safety needs, it requires different topics to be described in the safety concept document. It is obvious that the safety concept requires a good level of accuracy and knowledge of all requirements, and an early involvement of the certifying body is required to identify gaps early. Fundamental issues in a safety concept can be detected before the implementation starts. Altera s FSDP offers detailed information about the applications and safety functions that can be realized in an FPGA platform. This information contributes further to the simplification of the concept phase and speeds up the overall planning process. Preparation of Quality Measures In addition to the V-Model in Figure 3 that highlights all specification and design steps, it is important to note that each of these steps requires a related method to ensure the overall quality. To extend this model toward functional safety, the international standard IEC 61508:2010 defines in more detail which techniques and measures should be applied to guarantee a successful implementation of a functional safety project. Reducing Steps to Achieve Safety Certification
9 Preparation of Quality Measures Page 9 Techniques and Measures Parts 2, 3, and 7 of IEC 61508:2010 provide detailed lists of techniques and measures. Depending on the desired SIL, a certain set of methods has to be applied to a particular extent. From the beginning of the project on, it has to be determined and documented which techniques and measures will be used. An example is table F.2 in part 2 of IEC 61508:2010. This table in combination with part 7 of the standard defines which technique or measures have to be applied if a certain SIL has to be realized. In the design phase a script-based procedure is recommended if SIL 2 is desired. The same method is highly recommended for SIL 3 applications because SIL 3 requires a higher level of applied techniques and measures compare to SIL 2. The Quartus II tool command language (Tcl) flow is the suggested tool for this purpose. Altera provides detailed information on how to fulfill the needs of IEC 61508:2010 with its list of techniques and measures that prevent the introduction of faults during design and development. With Altera s FSDP, the selection of measures and techniques is already done, well documented, and ready to be used by the development team. This helps in understanding the application of methods, especially when realizing the very first safety-related FPGA project. In addition, these methods are also clearly linked to tools that implement them. In order not to forget any of the required documents and design steps, Altera s FSDP provides detailed checklists which help the development teams ensure that for all lifecycle phases the necessary input and output documents are available. In addition, a set of lifecycle actions are defined to verify that all phases are performed completely. As these checklists are already qualified by TÜV, no additional work is necessary to show how it will be guaranteed that the development V-Model of Altera s FSDP is used correctly. Safety Demand Modes Safety functions are categorized into two classes: Low-demand mode of operation and high-demand mode of operation. Low-demand mode of operation refers to safety functions with a demand frequency of less than one time per year to set the EUC in a safe state. Therefore, the characteristic safety key value for this class of safety functions is called probability of dangerous failure on demand (PFD) and describes the risk that a safety function fails in the moment it is triggered. High-demand mode of operation refers to safety functions used more than once a year or that are permanently used to set a EUC in a safe state as part of normal equipment operation. In this case, the safety key value is called average frequency of dangerous failure per hour (PFH) and describes the probability a safety function fails during one hour operating time. As an example, the PFH value has to be located within the range of 10 7 /h and 10 8 /h to achieve SIL 3. In both cases (PFD, PFH), the remaining probability of failure for a safety-relevant product has to be calculated (Figure 5). Reducing Steps to Achieve Safety Certification
10 Page 10 Realization Figure 5. Different Types of Failure Rates s Failure Rate s The hardware determines this probability value, and international standards provide detailed information on failure probabilities of electronic components and publish λ- values. With semiconductor devices like microcontrollers or FPGAs, the situation is more complex as the number of transistors and the internal structure of the chip has to be very well-known to support an overall calculation of the λ values. This detailed information about the internal structure of a semiconductor device is usually difficult to retrieve. Altera offers its customers an annual reliability report with detailed information on the λvalue in failure in time (FIT) of each type of available devices. Altera provides an application note that explains how the data in the reliability report has to be applied to the IEC certification. Providing this information as part of the qualified data package saves a significant amount of time and effort in the project documentation phase and later on during product certification. Realization The realization project phase covers hardware and software development as well as the diagnostic function. Hardware and Software To model and implement safety-relevant electronic systems, it is possible and desirable to combine self-developed Verilog HDL or VHDL modules with off-theshelf, complex intellectual property (IP) functions like the Nios II processor, which in the Altera case already has been qualified for use in safety-relevant designs. In cases where the processor is used together with the functional safety part of the system, all relevant requirements of the IEC 61508:2010 standard have to be applied. Part 2 of IEC 61508:2010 covers hardware aspects of functional safety and part 3 deals with software-related topics. Finally, part 7 provides an overview of the techniques and measures mentioned in part 2 and 3. Software for functional safety demands a consideration of the entire software lifecycle as well. Part 3 of IEC 61508:2010 includes all steps of the software lifecycle in detail. It also outlines the requirements for the specification, validation, design, and development of software as well as software modifications and verification. Reducing Steps to Achieve Safety Certification
11 Realization Page 11 Altera provides additional benefit when using a Nios II processor by pointing out different items that are of relevance depending on the desired SIL. These items deal with topics such as the usage of interrupts, Quartus II software and the Nios Integrated Development Environment (IDE) versions, and variants of assembler, compiler, and linker tools. Diagnostic Coverage It is impossible to develop a safety-relevant product that is guaranteed to be 100% free of errors. The important point is to detect as many errors as possible and to move the EUC into a safe state in case of failures. Possible failures are subdivided in two classes. The first type of error does not cause a dangerous situation (λ s ) and the second type of error leads to a non-safe or dangerous state (λ d ). In addition, these failure rates are subclassified into detectable (λ sd and λ dd ) or undetectable (λ su and λ du ) failure classes as explained in Figure 5. If it is possible to detect a failure, the EUC is brought into a safe state to mitigate the risk of the cause of failure. The most important aspect to consider for the reliability of a safety function is the fraction of failures that can be detected or do not lead into a dangerous state in relation to all possible failures. IEC :2010 defines the safe failure fraction (SFF) of a device with the following equation and the λ values of Figure 5: λ + s λ dd SFF = λ + s λ + dd λ du It is obvious that the SFF value will get a higher value with a reduced number of undetected dangerous failures (λ du ) in a safety-relevant design. Part 2 of IEC 61508:2010 differentiates two types of elements that are used for safety systems. Elements are regarded as type A if, for example, the failure modes are defined well and the element behavior under fault conditions is entirely known. If a safety system is only built up out of type A elements, it is treated as a type A system. In other cases or if one element of a safety system does not fulfill type A requirements, the entire system is considered type B. Type B systems contain at least one component with unknown failure modes or an unpredictable failure behavior. Depending on the type of the safety system and its hardware fault tolerance, the SFF together with the PFD or PFH value have a significant influence on the SIL that can be achieved. FPGA designs are considered mainly type B as they are based on complex semiconductor devices. As a result of this, it is required that the SFF be in the range of 90% to 99% to achieve SIL 3 with a dual-channel architecture. One of the best techniques to increase the safe failure fraction is to raise the amount of diagnostic coverage within the design. This can either be achieved through additional diagnostic software or redundant hardware with monitoring capability. A benefit of using FPGA technology is that diagnostic features can be implemented on a hardware level. This saves the effort of writing additional software code and is less timeconsuming and impactful to the system performance than software-based diagnostics. FPGAs can easily provide resources and capabilities in the logic array such that no extra electrical components or devices are required. Reducing Steps to Achieve Safety Certification
12 Page 12 Conclusion Altera s FSDP comes with IP cores that provide fundamental diagnostic functions. A clock checker diagnostic IP core can be used for monitoring the frequency and presence of a clock signal against a stable reference clock. The single-event upset (SEU) diagnostic IP core offers the possibility to identify SEUs in the FPGA to alert the system. The SEU core also provides functionality to test the diagnostic IP and the system response to an alert through means of inserting errors. And a cyclic redundancy check (CRC) diagnostic IP core can be used to calculate and check CRC values across a communication link. Dedicated software algorithms for the Nios II processor to run diagnostic functions on memory, registers, and other processor parts have to be implemented in the same way as for stand-alone microcontrollers. Conclusion More effort may be necessary compared to most standard projects for the first functional safety project. However, a high level of reusability in subsequent projects can be expected because of the detailed processes, measures, and techniques provided by the functional safety standards. A profound examination of existing tools, quality measures, and resources will bring additional benefits and simplification to establishing a new application development process for safety projects within the company. FPGAs offer design flexibility and are well supported in terms of functional safety through Altera s upfront investment in providing methods, qualified tools, and devices together with qualified IP and diagnostic IP. As the V-Model is the key to the entire functional safety project, it is important to spend a good amount of time on this part of the project. Being able to reuse proven methodologies and a validated V-Model for FPGAs provided by Altera can help during this phase of the project. The clear definition and understanding of the planned system and the reuse of prequalified technology will lead to a successful project very quickly. Altera s FSDP helps project managers and development teams meet the requirements for a safety project and save a significant amount of project planning and development time. It offers significant benefits for developing safety-relevant applications up to SIL 3 designs that conform to the latest IEC 61508:2010 standard. Reducing Steps to Achieve Safety Certification
13 Further Information Page 13 Further Information Acknowledgements TÜV-Qualified FPGAs for Functional Safety Designs: White Paper: Developing Functional Safety Systems with TÜV-Qualified FPGAs: White Paper: A Validated Methodology for Designing Safe Industrial Systems on a Chip Altera Design Software: Quartus II Handbook Version 9.0: Quartus II Software Device Support Release Notes: ISO 9000 ff.: Altera Reliability Report: Functional Safety and IEC Document Revision History Table 1. Document Revision History Roland Rauch, Functional Safety Engineer, Engineering Office, Rauch Christoph Fritsch, Senior Manager Strategic Marketing, Industrial and Automotive Business Unit, Jason Chiang, Senior Technical Marketing Manager, Industrial and Automotive Business Unit, Adam Titley, Design Engineer MTS, Embedded Solutions, Table 1 shows the revision history for this document. Date Version Changes 1.0 Initial release. Reducing Steps to Achieve Safety Certification
Hardware safety integrity Guideline
Hardware safety integrity Comments on this report are gratefully received by Johan Hedberg at SP Swedish National Testing and Research Institute mailto:[email protected] Quoting of this report is allowed
Using Altera MAX Series as Microcontroller I/O Expanders
2014.09.22 Using Altera MAX Series as Microcontroller I/O Expanders AN-265 Subscribe Many microcontroller and microprocessor chips limit the available I/O ports and pins to conserve pin counts and reduce
IEC 61508 Functional Safety Assessment. Project: K-TEK Corporation AT100, AT100S, AT200 Magnetostrictive Level Transmitter.
61508 SIL 3 CAPABLE IEC 61508 Functional Safety Assessment Project: K-TEK Corporation AT100, AT100S, AT200 Magnetostrictive Level Transmitter Customer: K-TEK Corporation Prairieville, LA USA Contract No.:
Version: 1.0 Latest Edition: 2006-08-24. Guideline
Management of Comments on this report are gratefully received by Johan Hedberg at SP Swedish National Testing and Research Institute mailto:[email protected] Quoting of this report is allowed but please
Value Paper Author: Edgar C. Ramirez. Diverse redundancy used in SIS technology to achieve higher safety integrity
Value Paper Author: Edgar C. Ramirez Diverse redundancy used in SIS technology to achieve higher safety integrity Diverse redundancy used in SIS technology to achieve higher safety integrity Abstract SIS
White Paper FPGA Performance Benchmarking Methodology
White Paper Introduction This paper presents a rigorous methodology for benchmarking the capabilities of an FPGA family. The goal of benchmarking is to compare the results for one FPGA family versus another
Is your current safety system compliant to today's safety standard?
Is your current safety system compliant to today's safety standard? Abstract It is estimated that about 66% of the Programmable Electronic Systems (PES) running in the process industry were installed before
A Safety Methodology for ADAS Designs in FPGAs
A Safety Methodology for ADAS Designs in FPGAs WP-01204-1.0 White Paper This white paper discusses the use of Altera FPGAs in safety-critical Advanced Driver Assistance Systems (ADAS). It looks at the
SAFETY MANUAL SIL Switch Amplifier
PROCESS AUTOMATION SAFETY MANUAL SIL Switch Amplifier KCD2-SR-(Ex)*(.LB)(.SP), HiC282* ISO9001 2 With regard to the supply of products, the current issue of the following document is applicable: The General
ELECTROTECHNIQUE IEC INTERNATIONALE 61508-3 INTERNATIONAL ELECTROTECHNICAL
61508-3 ª IEC: 1997 1 Version 12.0 05/12/97 COMMISSION CEI ELECTROTECHNIQUE IEC INTERNATIONALE 61508-3 INTERNATIONAL ELECTROTECHNICAL COMMISSION Functional safety of electrical/electronic/ programmable
White Paper 40-nm FPGAs and the Defense Electronic Design Organization
White Paper 40-nm FPGAs and the Defense Electronic Design Organization Introduction With Altera s introduction of 40-nm FPGAs, the design domains of military electronics that can be addressed with programmable
IEC 61508 Overview Report
IEC 61508 Overview Report A Summary of the IEC 61508 Standard for Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems exida Sellersville, PA 18960, USA +1-215-453-1720
IEC 61508 Functional Safety Assessment. ASCO Numatics Scherpenzeel, The Netherlands
IEC 61508 Functional Safety Assessment Project: Series 327 Solenoid Valves Customer: ASCO Numatics Scherpenzeel, The Netherlands Contract No.: Q09/04-59 Report No.: ASC 09-04-59 R003 V1 R3 61508 Assessment
Selecting Sensors for Safety Instrumented Systems per IEC 61511 (ISA 84.00.01 2004)
Selecting Sensors for Safety Instrumented Systems per IEC 61511 (ISA 84.00.01 2004) Dale Perry Worldwide Pressure Marketing Manager Emerson Process Management Rosemount Division Chanhassen, MN 55317 USA
Quartus II Software and Device Support Release Notes Version 15.0
2015.05.04 Quartus II Software and Device Support Release Notes Version 15.0 RN-01080-15.0.0 Subscribe This document provides late-breaking information about the Altera Quartus II software release version
SAFETY MANUAL SIL RELAY MODULE
PROCESS AUTOMATION SAFETY MANUAL SIL RELAY MODULE KFD0-RSH-1.4S.PS2 ISO9001 3 With regard to the supply of products, the current issue of the following document is applicable: The General Terms of Delivery
Applying the Benefits of Network on a Chip Architecture to FPGA System Design
Applying the Benefits of on a Chip Architecture to FPGA System Design WP-01149-1.1 White Paper This document describes the advantages of network on a chip (NoC) architecture in Altera FPGA system design.
Vetting Smart Instruments for the Nuclear Industry
TS Lockhart, Director of Engineering Moore Industries-International, Inc. Vetting Smart Instruments for the Nuclear Industry Moore Industries-International, Inc. is a world leader in the design and manufacture
USB-Blaster Download Cable User Guide
USB-Blaster Download Cable User Guide Subscribe UG-USB81204 101 Innovation Drive San Jose, CA 95134 www.altera.com TOC-2 Contents Introduction to USB-Blaster Download Cable...1-1 USB-Blaster Revision...1-1
How to Upgrade SPICE-Compliant Processes for Functional Safety
How to Upgrade SPICE-Compliant Processes for Functional Safety Dr. Erwin Petry KUGLER MAAG CIE GmbH Leibnizstraße 11 70806 Kornwestheim Germany Mobile: +49 173 67 87 337 Tel: +49 7154-1796-222 Fax: +49
Final Element Architecture Comparison
Final Element Architecture Comparison 2oo2 with diagnostics: Lower False Trip Rate and High Safety Project: Safety Cycling Systems Architecture Review Customer: Safety Cycling Systems, L.L.C. 1018 Laurel
Effective Compliance. Selecting Solenoid Valves for Safety Systems. A White Paper From ASCO Valve, Inc. by David Park and George Wahlers
Effective Compliance with IEC 61508 When Selecting Solenoid Valves for Safety Systems by David Park and George Wahlers A White Paper From ASCO Valve, Inc. Introduction Regulatory modifications in 2010
Engineering Change Order (ECO) Support in Programmable Logic Design
White Paper Engineering Change Order (ECO) Support in Programmable Logic Design A major benefit of programmable logic is that it accommodates changes to the system specification late in the design cycle.
University of Paderborn Software Engineering Group II-25. Dr. Holger Giese. University of Paderborn Software Engineering Group. External facilities
II.2 Life Cycle and Safety Safety Life Cycle: The necessary activities involving safety-related systems, occurring during a period of time that starts at the concept phase of a project and finishes when
1. Overview of Nios II Embedded Development
January 2014 NII52001-13.1.0 1. Overview o Nios II Embedded Development NII52001-13.1.0 The Nios II Sotware Developer s Handbook provides the basic inormation needed to develop embedded sotware or the
White Paper Understanding Metastability in FPGAs
White Paper Understanding Metastability in FPGAs This white paper describes metastability in FPGAs, why it happens, and how it can cause design failures. It explains how metastability MTBF is calculated,
White Paper Utilizing Leveling Techniques in DDR3 SDRAM Memory Interfaces
White Paper Introduction The DDR3 SDRAM memory architectures support higher bandwidths with bus rates of 600 Mbps to 1.6 Gbps (300 to 800 MHz), 1.5V operation for lower power, and higher densities of 2
Guidelines. Safety Integrity Level - SIL - Valves and valve actuators. March 2009. Valves
Valves Guidelines Safety Integrity Level - SIL - Valves and valve actuators March 2009 VDMA German Engineering Federation Valves Manufacturers Association Chairman: Prof.-Dr.-Ing. Heinfried Hoffmann Managing
Altera Error Message Register Unloader IP Core User Guide
2015.06.12 Altera Error Message Register Unloader IP Core User Guide UG-01162 Subscribe The Error Message Register (EMR) Unloader IP core (altera unloader) reads and stores data from the hardened error
Failure Modes, Effects and Diagnostic Analysis
Failure Modes, Effects and Diagnostic Analysis Project: Plant-STOP 9475 Company: R. STAHL Schaltgeräte GmbH Waldenburg Germany Contract No.: STAHL 13/04-027 Report No.: STAHL 13/04-027 R024 Version V1,
PROFINET IRT: Getting Started with The Siemens CPU 315 PLC
PROFINET IRT: Getting Started with The Siemens CPU 315 PLC AN-674 Application Note This document shows how to demonstrate a working design using the PROFINET isochronous real-time (IRT) device firmware.
Certification Report of the STT25S Temperature Transmitter
Certification Report of the STT25S Temperature Transmitter Revision No.: 1.2 Date: Report Number: Product: Customer: Order Number: Authority: Responsible: 2009-Jul-10 SAS-135/2006T STT25S Temperature Transmitter
Providing Battery-Free, FPGA-Based RAID Cache Solutions
Providing Battery-Free, FPGA-Based RAID Cache Solutions WP-01141-1.0 White Paper RAID adapter cards are critical data-center subsystem components that ensure data storage and recovery during power outages.
1. Overview of Nios II Embedded Development
May 2011 NII52001-11.0.0 1. Overview o Nios II Embedded Development NII52001-11.0.0 The Nios II Sotware Developer s Handbook provides the basic inormation needed to develop embedded sotware or the Altera
SAFETY MANUAL SIL SMART Transmitter Power Supply
PROCESS AUTOMATION SAFETY MANUAL SIL SMART Transmitter Power Supply KFD2-STC4-(Ex)*, KFD2-STV4-(Ex)*, KFD2-CR4-(Ex)* ISO9001 2 3 With regard to the supply of products, the current issue of the following
Nios II Software Developer s Handbook
Nios II Software Developer s Handbook Nios II Software Developer s Handbook 101 Innovation Drive San Jose, CA 95134 www.altera.com NII5V2-13.1 2014 Altera Corporation. All rights reserved. ALTERA, ARRIA,
Quartus II Software Design Series : Foundation. Digitale Signalverarbeitung mit FPGA. Digitale Signalverarbeitung mit FPGA (DSF) Quartus II 1
(DSF) Quartus II Stand: Mai 2007 Jens Onno Krah Cologne University of Applied Sciences www.fh-koeln.de [email protected] Quartus II 1 Quartus II Software Design Series : Foundation 2007 Altera
SIL manual. Structure. Structure
With regard to the supply of products, the current issue of the following document is applicable: The General Terms of Delivery for Products and Services of the Electrical Industry, published by the Central
Viewpoint on ISA TR84.0.02 Simplified Methods and Fault Tree Analysis Angela E. Summers, Ph.D., P.E., President
Viewpoint on ISA TR84.0.0 Simplified Methods and Fault Tree Analysis Angela E. Summers, Ph.D., P.E., President Presented at Interkama, Dusseldorf, Germany, October 1999, Published in ISA Transactions,
Machineontwerp volgens IEC 62061
Machineontwerp volgens IEC 62061 Insert Photo Here Safety solution Architect Safety Local Business Leader Benelux. Stephen Podevyn Safety Solution Seminar Agenda deel 1 1. Richtlijnen en normen 2. Safety
Controlling Risks Safety Lifecycle
Controlling Risks Safety Lifecycle Objective Introduce the concept of a safety lifecycle and the applicability and context in safety systems. Lifecycle Management A risk based management plan for a system
IBM Rational Rhapsody
IBM Rational Rhapsody IBM Rational Rhapsody Reference Workflow Guide Version 1.9 License Agreement No part of this publication may be reproduced, transmitted, stored in a retrieval system, nor translated
PowerPlay Power Analysis & Optimization Technology
Quartus II Software Questions & Answers Following are the most frequently asked questions about the new features in Altera s Quartus II design software. PowerPlay Power Analysis & Optimization Technology
Quartus II Software Download and Installation Quick Start Guide
Quartus II Software Download and Installation Quick Start Guide 2013 Altera Corporation. All rights reserved. ALTERA, ARRIA, CYCLONE, HARDCOPY, MAX, MEGACORE, NIOS, QUARTUS and STRATIX words and logos
SAFETY LIFECYCLE WORKBOOK FOR THE PROCESS INDUSTRY SECTOR
SAFETY LIFECYCLE WORKBOOK FOR THE PROCESS INDUSTRY SECTOR SAFETY LIFECYCLE WORKBOOK FOR THE PROCESS INDUSTRY SECTOR The information and any recommendations that may be provided herein are not intended
SOFTWARE DEVELOPMENT STANDARD FOR SPACECRAFT
SOFTWARE DEVELOPMENT STANDARD FOR SPACECRAFT Mar 31, 2014 Japan Aerospace Exploration Agency This is an English translation of JERG-2-610. Whenever there is anything ambiguous in this document, the original
13. Publishing Component Information to Embedded Software
February 2011 NII52018-10.1.0 13. Publishing Component Information to Embedded Software NII52018-10.1.0 This document describes how to publish SOPC Builder component information for embedded software tools.
Using the Altera Serial Flash Loader Megafunction with the Quartus II Software
Using the Altera Flash Loader Megafunction with the Quartus II Software AN-370 Subscribe The Altera Flash Loader megafunction IP core is an in-system programming (ISP) solution for Altera serial configuration
White Paper Using the Intel Flash Memory-Based EPC4, EPC8 & EPC16 Devices
White Paper Introduction Altera enhanced configuration devices provide single-device, advanced configuration solutions for high-density Altera FPGAs. The core of an enhanced configuration device is divided
White Paper Military Productivity Factors in Large FPGA Designs
White Paper Introduction Changes in technology and requirements are leading to FPGAs playing larger roles in defense electronics designs, and consequently are creating both opportunities and risks. The
Understanding Safety Integrity Levels (SIL) and its Effects for Field Instruments
Understanding Safety Integrity Levels (SIL) and its Effects for Field Instruments Introduction The Industrial process industry is experiencing a dynamic growth in Functional Process Safety applications.
FUNCTIONAL SAFETY CERTIFICATE
FUNCTIONAL SAFETY CERTIFICATE This is to certify that the hardware safety integrity of the Valvetop ESD Valve Controller manufactured by TopWorx Inc. 3300 Fern Valley Road Louisville Kentucky 40213 USA
Frequently Asked Questions
Frequently Asked Questions The exida Certification Program Functional Safety (SIL) Cyber-Security V2 R3 June 14, 2012 exida Sellersville, PA 18960, USA, +1-215-453-1720 Munich, Germany, +49 89 4900 0547
TÜ V Rheinland Industrie Service
TÜ V Rheinland Industrie Service Business Area: Automation / Functional Safety Contact Minsung Lee +82-2-860-9969 mailto : [email protected] Sales Account Manager for Functional Safety Fax +82-2-860-9862
Using the Agilent 3070 Tester for In-System Programming in Altera CPLDs
Using the Agilent 3070 Tester for In-System Programming in Altera CPLDs AN-628-1.0 Application Note This application note describes how to use the Agilent 3070 test system to achieve faster programming
Safety Manual BT50(T) Safety relay / Expansion relay
Safety Manual BT50(T) Safety relay / Expansion relay ABB Jokab Safety Varlabergsvägen 11, SE-434 39, Sweden www.abb.com/jokabsafety Read and understand this document Please read and understand this document
ISO 26262:2011 Functional Safety Assessment Report. Texas Instruments Richardson, TX USA. Project: TDA2X ADAS SoC. Customer:
ISO 26262:2011 Functional Safety Report Project: TDA2X ADAS SoC Customer: Texas Instruments Richardson, TX USA Contract No.: Q13/09-037 Report No.: TI 13-09-037 R002 Version V1, Revision R1, January 23,
CONSOLIDATED VERSION IEC 62304. Medical device software Software life cycle processes. colour inside. Edition 1.1 2015-06
IEC 62304 CONSOLIDATED VERSION Edition 1.1 2015-06 colour inside Medical device software life cycle processes INTERNATIONAL ELECTROTECHNICAL COMMISSION ICS 11.040 ISBN 978-2-8322-2765-7 Warning! Make sure
ISO 26262 Introduction
ISO 26262 Introduction Prof. Christian Madritsch 2012 Table of Contents Structure of ISO 26262 Management of Functional Safety Product Development System Level Product Development Hardware Level Product
USB-Blaster II Download Cable User Guide
USB-Blaster II Download Cable User Guide Subscribe UG-01150 101 Innovation Drive San Jose, CA 95134 www.altera.com TOC-2 Contents Setting Up the USB-Blaster II Download Cable...1-1 Supported Devices and
White Paper Streaming Multichannel Uncompressed Video in the Broadcast Environment
White Paper Multichannel Uncompressed in the Broadcast Environment Designing video equipment for streaming multiple uncompressed video signals is a new challenge, especially with the demand for high-definition
MAX II ISP Update with I/O Control & Register Data Retention
MAX II ISP Update with I/O Control & Register Data Retention March 2006, ver 1.0 Application Note 410 Introduction MAX II devices support the real-time in-system mability (ISP) feature that allows you
December 2002, ver. 1.0 Application Note 285. This document describes the Excalibur web server demonstration design and includes the following topics:
Excalibur Web Server Demonstration December 2002, ver. 1.0 Application Note 285 Introduction This document describes the Excalibur web server demonstration design and includes the following topics: Design
GAM900/GAM900S. Acceleration precisely measured and safely monitored
GAM900/GAM900S Acceleration precisely measured and safely monitored The benefits at a glance: Less sensors more safety Minimum size, maximum performance Extremely reliable and robust IP 67 protection thanks
Safety Integrated. SIMATIC Safety Matrix. The Management Tool for all Phases of the Safety Lifecycle. Brochure September 2010. Answers for industry.
SIMATIC Safety Matrix The Management Tool for all Phases of the Safety Lifecycle Brochure September 2010 Safety Integrated Answers for industry. Functional safety and Safety Lifecycle Management Hazard
FMEDA and Proven-in-use Assessment. Pepperl+Fuchs GmbH Mannheim Germany
FMEDA and Proven-in-use Assessment Project: Inductive NAMUR sensors Customer: Pepperl+Fuchs GmbH Mannheim Germany Contract No.: P+F 03/11-10 Report No.: P+F 03/11-10 R015 Version V1, Revision R1.1, July
When COTS is not SOUP Commercial Off-the-Shelf Software in Medical Systems. Chris Hobbs, Senior Developer, Safe Systems
When COTS is not SOUP Commercial Off-the-Shelf Software in Medical Systems Chris Hobbs, Senior Developer, Safe Systems 2 Audience and Assumptions Who will benefit from this presentation? Software designers
15. Introduction to ALTMEMPHY IP
15. Introduction to ALTMEMPHY IP Noember 2012 EMI_RM_013-1.2 EMI_RM_013-1.2 The Altera DDR,, and DDR3 SDRAM Controllers with ALTMEMPHY IP proide simplified interfaces to industry-standard DDR,, and DDR3
Altera SoC Embedded Design Suite User Guide
Altera SoC Embedded Design Suite User Guide Subscribe ug-1137 101 Innovation Drive San Jose, CA 95134 www.altera.com TOC-2 Contents Introduction to SoC Embedded Design Suite... 1-1 Overview... 1-1 Linux
SAFETY MANUAL SIL SWITCH AMPLIFIER
PROCESS AUTOMATION SAFETY MANUAL SIL SWITCH AMPLIFIER KF**-SR2-(Ex)*(.LB), KFD2-SR2-(Ex)2.2S ISO9001 2 With regard to the supply of products, the current issue of the following document is applicable:
VON BRAUN LABS. Issue #1 WE PROVIDE COMPLETE SOLUTIONS ULTRA LOW POWER STATE MACHINE SOLUTIONS VON BRAUN LABS. State Machine Technology
VON BRAUN LABS WE PROVIDE COMPLETE SOLUTIONS WWW.VONBRAUNLABS.COM Issue #1 VON BRAUN LABS WE PROVIDE COMPLETE SOLUTIONS ULTRA LOW POWER STATE MACHINE SOLUTIONS State Machine Technology IoT Solutions Learn
FPGAs for High-Performance DSP Applications
White Paper FPGAs for High-Performance DSP Applications This white paper compares the performance of DSP applications in Altera FPGAs with popular DSP processors as well as competitive FPGA offerings.
Functional Safety Management of the development process of safety related programmable electronic systems at Jaquet Technology Group
Functional Safety Management of the development process of safety related programmable electronic systems at Jaquet Technology Group Document type: Certification Report Client: Jaquet Technology Group
Using the On-Chip Signal Quality Monitoring Circuitry (EyeQ) Feature in Stratix IV Transceivers
Using the On-Chip Signal Quality Monitoring Circuitry (EyeQ) Feature in Stratix IV Transceivers AN-605-1.2 Application Note This application note describes how to use the on-chip signal quality monitoring
Implementation of ANSI/AAMI/IEC 62304 Medical Device Software Lifecycle Processes.
Implementation of ANSI/AAMI/IEC 62304 Medical Device Software Lifecycle Processes.. www.pharmout.net Page 1 of 15 Version-02 1. Scope 1.1. Purpose This paper reviews the implementation of the ANSI/AAMI/IEC
Agile Project Execution
ebook Agile Project Execution The future of Industrial Process Automation projects v1.4 EMK(VDS)-TR-EB-01 APEX ebook Table of Contents Intro Agile Project Execution Page 2. Chapter 1 Conventional Project
functional Safety UL Functional Safety Mark
functional Safety UL Functional Safety Mark Program UL Functional Safety Mark Program With the advent and evolution of functional safety standards in North America and Europe, UL is now offering a UL Functional
MXa SIL Guidance and Certification
MXa SIL Guidance and Certification SIL 3 capable for critical applications Experience In Motion Functional Safety in Plants Safety and instrumentation engineers demand that a functional safety system s
PABIAC Safety-related Control Systems Workshop
Health and and Safety Executive PABIAC Safety-related Control Systems Workshop KEY STANDARDS FOR ELECTRICAL & FUNCTIONAL SAFETY OF PAPERMAKING MACHINES: APPLICATION & USE Steve Frost HM Principal Electrical
Digital Systems Design! Lecture 1 - Introduction!!
ECE 3401! Digital Systems Design! Lecture 1 - Introduction!! Course Basics Classes: Tu/Th 11-12:15, ITE 127 Instructor Mohammad Tehranipoor Office hours: T 1-2pm, or upon appointments @ ITE 441 Email:
ModelSim-Altera Software Simulation User Guide
ModelSim-Altera Software Simulation User Guide ModelSim-Altera Software Simulation User Guide 101 Innovation Drive San Jose, CA 95134 www.altera.com UG-01102-2.0 Document last updated for Altera Complete
ISO 9001:2000 Gap Analysis Checklist
ISO 9001:2000 Gap Analysis Checklist Type: Assessor: ISO 9001 REQUIREMENTS STATUS ACTION/COMMENTS 4 Quality Management System 4.1 General Requirements Processes needed for the quality management system
Version: 1.0 Last Edited: 2005-10-27. Guideline
Process hazard and risk Comments on this report are gratefully received by Johan Hedberg at SP Swedish National Testing and Research Institute mailto:[email protected] -1- Summary This report will try
NEOXEN MODUS METHODOLOGY
NEOXEN MODUS METHODOLOGY RELEASE 5.0.0.1 INTRODUCTION TO QA & SOFTWARE TESTING GUIDE D O C U M E N T A T I O N L I C E N S E This documentation, as well as the software described in it, is furnished under
Frequently Asked Questions
Frequently Asked Questions The exida 61508 Certification Program V1 R8 October 19, 2007 exida Geneva, Switzerland Sellersville, PA 18960, USA, +1-215-453-1720 Munich, Germany, +49 89 4900 0547 1 Exida
SOFTWARE-IMPLEMENTED SAFETY LOGIC Angela E. Summers, Ph.D., P.E., President, SIS-TECH Solutions, LP
SOFTWARE-IMPLEMENTED SAFETY LOGIC Angela E. Summers, Ph.D., P.E., President, SIS-TECH Solutions, LP Software-Implemented Safety Logic, Loss Prevention Symposium, American Institute of Chemical Engineers,
A methodology For the achievement of Target SIL
A methodology For the achievement of Target SIL Contents 1.0 Methodology... 3 1.1 SIL Achievement - A Definition... 4 1.2 Responsibilities... 6 1.3 Identification of Hazards and SIL Determination... 8
MAX 10 Clocking and PLL User Guide
MAX 10 Clocking and PLL User Guide Subscribe UG-M10CLKPLL 2015.11.02 101 Innovation Drive San Jose, CA 95134 www.altera.com TOC-2 Contents MAX 10 Clocking and PLL Overview... 1-1 Clock Networks Overview...
FUNCTIONAL SAFETY INDUSTRIAL
FUNCTIONAL SAFETY INDUSTRIAL TRAINING AND PERSONAL QUALIFICATION PUBLIC TRAININGS, IN - HOUSE SEMINARS, PERSONAL CERTIFICATES, WEBINARS IEC 61508 ISO 13849 IEC 62061 IEC 61511 ISO 25119 IEC 60730 IEC 60335
Design of automatic testing tool for railway signalling systems software safety assessment
Risk Analysis VI 513 Design of automatic testing tool for railway signalling systems software safety assessment J.-G. Hwang 1, H.-J. Jo 1 & H.-S. Kim 2 1 Train Control Research Team, Korea Railroad Research
Software Production. Industrialized integration and validation of TargetLink models for series production
PAGE 24 EB AUTOMOTIVE Industrialized integration and validation of TargetLink models for series production Continuous Software Production The complexity of software systems in vehicles is increasing at
WHITEPAPER: SOFTWARE APPS AS MEDICAL DEVICES THE REGULATORY LANDSCAPE
WHITEPAPER: SOFTWARE APPS AS MEDICAL DEVICES THE REGULATORY LANDSCAPE White paper produced by Maetrics For more information, please contact global sales +1 610 458 9312 +1 877 623 8742 [email protected]
Medical Device Software Standards for Safety and Regulatory Compliance
Medical Device Software Standards for Safety and Regulatory Compliance Sherman Eagles +1 612-865-0107 [email protected] www.softwarecpr.com Assuring safe software SAFE All hazards have been addressed
SAFETY LIFE-CYCLE HOW TO IMPLEMENT A
AS SEEN IN THE SUMMER 2007 ISSUE OF... HOW TO IMPLEMENT A SAFETY LIFE-CYCLE A SAFER PLANT, DECREASED ENGINEERING, OPERATION AND MAINTENANCE COSTS, AND INCREASED PROCESS UP-TIME ARE ALL ACHIEVABLE WITH
Basic Fundamentals Of Safety Instrumented Systems
September 2005 DVC6000 SIS Training Course 1 Basic Fundamentals Of Safety Instrumented Systems Overview Definitions of basic terms Basics of safety and layers of protection Basics of Safety Instrumented
