Iso 26262
Iso 26262
Iso 26262
exida Contacts
Singapore
Shanghai
Hong Kong
Germany
USA
Switzerland
Canada
United Kingdom
Netherlands
Australia / NZL
Mexico
South Africa
On the Agenda
ISO 26262 and the Challenges
exida Expertise
exida
Copyright exida LLC 2000-2012
Reverse
Lane Departure Warning
Sensors
Deflation Detection Emergency Brake Assistance
Traffic Sign Recognition
System
Copyright exida LLC 2000-2012
Fatalities
Fatalities decreasing
decreasing too
too Slow
Slow in
in
Europe
Europe
Fatalities
Fatalities stable
stable but
but too
too High
High in
in US
US
Copyright exida LLC 2000-2012
Actively
Actively
function
function
to
to achieve
achieve
Safe
Safe State
State
Reverse
Lane Departure Warning
Sensors
Emergency Brake Assistance
Traffic Sign Recognition
Copyright exida LLC 2000-2012
What is?
Functional Safety
ISO 26262: Absence of unreasonable risk due to
hazards caused by malfunctioning behavior of E/E
systems
IEC 61508: Part of the overall safety related to the
equipment under control (EUC) that depends on the
correct functioning of the safety-related system
Functional
FunctionalSafety
Safetyfor
forE/E/PES
E/E/PESSafety
SafetyRelated
RelatedSystems
Systems
Functional
FunctionalSafety
Safetyfor
forE/E/PES
E/E/PESSafety
SafetyRelated
RelatedSystems
Systems
Why
Why not
not ideal
ideal
for
for
Automotive
Automotive
Industry
Industry ??
Copyright exida LLC 2000-2012
Functional
FunctionalSafety
Safetyfor
forE/E/PES
E/E/PESSafety
SafetyRelated
RelatedSystems
Systems
Why
Why not
not Ideal
Ideal
for
for
Automotive
Automotive
Industry
Industry ??
Copyright exida LLC 2000-2012
Functional
FunctionalSafety
Safetyfor
forE/E/PES
E/E/PESSafety
SafetyRelated
RelatedSystems
Systems
IEC
IEC 61511
61511 IEC
62061
IEC
61513
IEC
62061
IEC
61513
Process
Process
Industry
Industry
Machinery
Machinery
ISO
ISO
13849-1
13849-1
Nuclear
Nuclear
Machine
Machine
Safety
Safety
ISO
ISO
26262
26262
Road
RoadVehicles
Vehicles
ISO
ISO
25119
25119
Tractors
Tractors
ISO
ISO 26262
26262 is
is State
State of
of the
the Art
Art For
For
Automotive
Automotive
Developed
Developed with
with OEM
OEM
Copyright exida LLC 2000-2012
Control
Control of
of Failures
Failures
Avoid
AvoidSystematic
Systematic
Faults
Faults
Control
Controlof
of
Systematic
SystematicFailures
Failures
Control
Controlof
of
Random
RandomFailures
Failures
Process
ProcessMethods
Methods-Organization
Organization
Before
BeforeDelivery
Delivery
Technical
TechnicalSafety
Safety
Measures
Measures
In
InOperation
Operation
Control
Control of
of Failures
Failures
Avoid
AvoidSystematic
Systematic
Faults
Faults
Control
Controlof
of
Systematic
SystematicFailures
Failures
Control
Controlof
of
Random
RandomFailures
Failures
Process
ProcessMethods
Methods-Organization
Organization
Before
BeforeDelivery
Delivery
Implement
Implement
Correctly
Correctly
Technical
TechnicalSafety
Safety
Measures
Measures
In
InOperation
Operation
Detect
Detect and
and
React
React
2.4 2.6
Risk
Risk Based
Based
Approach
Approach
3.5
Item definition
3.6
3.7
3.7
3.8
Concept
Functional
of Functional
Safety
Concept
Safety
Product Development
System
7.4
7.5
Planning of Operation,
Service and Decom.
after SOP
product
development
concept phase
Planning of
Production
Hardware
Other
Technologies
Software
4.11
7.4
Production
Operation, Service
Supporting Processes
Copyright exida LLC 2000-2012
Driver
Controllability
(and Usability)
External
Measures
Back to appropriate
lifecycle phase
Work Products
>
> 100
100
Work
Work
Products
Products
Exida
Templat
es
Copyright exida LLC 2000-2012
Vocabulary is important
English is not English
English American - KorEnglish GerEnglish
Singlish
English is not ISO/IEC
Validation Verification Confirmation
Fault Failure Error
Different Standard Different Terminology
Safety Requirement in ISO 26262 vs IEC
61511
Exida
Template
Copyright exida LLC 2000-2012
AA clear,
clear,
comprehensive
comprehensive and
and defensible
defensible
argument
argument
that
that aa system
system is
is acceptably
acceptably safe
safe to
to
operate
operate
in
in aa particular
particular context.
context.
(Tim
(TimKelly
Kelly/ /Rob
RobWeawer
Weawer
University
of
York)
of York)
Copyright exida University
LLC 2000-2012
Concept Phase
Prevent
Prevent use
use by
by
OEM Defines Item > ESCL
unauthorized
unauthorized
person
Initiation of Safety Lifecycle
person by
by
mechanical
mechanical lock
lock
Hazard Analyses and Risk Assessment
Concept Phase
OEM Defines Item > ESCL
Initiation of Safety Lifecycle > New
Hazard Analyses and Risk Assessment
Functional Safety Concept
Exida
Exida
Modificatio
Modificatio
nn Process
Process
Copyright exida LLC 2000-2012
Concept Phase
OEM Defines Item > ESCL
Initiation of safety Lifecycle > New
Hazard Analyses and Risk Assessment
Functional Safety Concept
What
What Can
Can Go
Go Wrong?
Wrong?
>
> Steering
Steering locks
locks when
when
driving
driving
Concept Phase
OEM Defines Item > ESCL
Initiation of safety Lifecycle > New
Hazard Analyses and Risk Assessment
Functional Safety Concept
SAFETY
SAFETY GOAL
GOAL
Avoid
Avoid aa
Dangerous
Dangerous
Situation
Situation
SG
No.
SG1
HRA Reg
ESCL_001
Safety Goal
Unintended locking of
ESCL while vehicle is
moving shall be avoided
ASIL
Safe
State
Unlocked
ESCL
Concept Phase
OEM Defines Item > ESCL
Initiation of safety Lifecycle > New
Hazard Analyses and Risk Assessment
Functional Safety Concept
How
How Risky
Risky is
is that?
that?
>
> Need
Need ASILD
ASILD
Consequence Likelihood
Moderation
Moderation
Always
Always with
with
OEM
OEM
Concept Phase
OEM Defines Item > ESCL
Initiation of safety Lifecycle > New
Hazard Analyses and Risk Assessment > ASILD
Functional Safety Concept
Functionality
Functionality
to
to meet
meet
SAFETY
SAFETY GOAL
GOAL
Concept Phase
OEM Defines Item > ESCL
Initiation of safety Lifecycle > New
Hazard Analyses and Risk Assessment > ASILD
Functional Safety Concept
Unlock
Unlock Steering
Steering Column
Column when
when Vehicle
Vehicle
is
is moving
moving
ASIL
ASIL D
D
Vehicle
VehicleSpeed
Speed
Server
Server
Vehicle speed
ASIL D
ASIL
ASIL D
D
SG1
SG1
Lock Sequence
ASIL D
ASIL
ASIL D
D
Steering
Steering
Column
ColumnLock
Lock
Concept Phase
Functional
Functional
Safety
Safety Concept
Concept
Product Development
Technical
Technical
Safety
Safety Concept
Concept
INTEGRITY
INTEGRITY
System
System Design
Design
HW
Design
SW
Design
HS
I
HW Level
Development
ASIL B
ASIL C
ASIL D
Single point
faults metric
90 %
+
97 %
++
99 %
++
Latent faults
metric
60 %
+
80 %
+
90 %
++
5.9
5.9 Random
Random
ASIL
C1
I/O
C
2
I/O
2x
2x SW
SW Development,
Development,
Communication,
Communication,
Testing,
Testing,
PCB
PCB Space,
Space,
Justification,
Justification,Supply
Supply
voltage,
voltage,
Copyright exida LLC 2000-2012
Voter
ALU
RAM
Reg
ALU
RAM
Reg
Flash
I/O
I/O
I/O
Focus
Focus Mainly
Mainly
on
on Application
Application
SW Level
Development
E/E System-Design
Verification
during Design
Software Validation
Software Safety
Requirements
Software Safety
Validation
Verification
during Design
Software Architecture
and Design
Test
Software Integration
and Test
Verification
during Design
Software
Implementation
Test
Software Unit Test
Producti
on
Operati
on
Supporting Processes
Supporting Processes
Interfaces within Distributed Developments
(DIA)
Specification and Management Other
of
Parts
Other
Parts
reference
Requirements
reference
Supporting
Supporting
Configuration Management
Processes
Processes
Change Management
Verification
Documentation
Confidence of Use in SW Tools
Qualification of HW/SW Components
Proven in Use Arguments
Copyright exida LLC 2000-2012
Safety
Analyses
Safety Analyses
Decomposition ASIL Tailoring
Criteria for Coexistence
Dependent Failure Analysis
Safety Analyses
SCA
H&R
FMEA
FTA
FMEA
FMED
A
SWCA
HAZA
N
Guideline
Copyright exida LLC 2000-2012
Documentation:
Traceability:
Consistency
Consistency
On the Agenda
ISO 26262 and the Challenges
exida Expertise
Who we are
Founded in 1999 by experts from
Manufacturers, End Users, Engineering
Companies and TV SD
Today: LARGEST Functional Safety and Cyber
Security consultancy and certification body
worldwide
What we do
EXIDA SCOPE
SERVICE
Function
S
Tools
al Safety
Cyber
Security
Reliability
Training
Consulta
ncy
Certificat
ion
INDUSTRI
CUSTOME
ES
Process
RS
Industry End Users
Automoti Equipmen
t
ve
Manufact
Machine urer
Industry
Alarm
Manageme
Power
nt
Referenc
Industry
Copyright exida LLC 2000-2012
e
Car
Manufact
urer
Tools
Tools
ICs
ICs
IEC/ISO knowledgebase
per exida
development
phase:
Document templates
Copyright
LLC 2000-2012
exida Certifications
exida Certification S.A.
Clean separation from the exida Consulting business
English language based assessment and certification
system
International alternative to TV
Open exida Certification Scheme
IEC 61508 and ISO 26262 compliant using exida Safety
Case methodology (SafetyCaseDB) and audits
Assessment Process and Requirements Publicly
available