Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
100% found this document useful (1 vote)
114 views24 pages

ISO 26262 Webinar

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1/ 24

Live Webinar

Introduction to ISO 26262 for Functional Safety Critical Projects


Speaker-: Mr. Martin Heininger

Leading technology company award by Deloitte in Fast50 India 2012 program


Embitel is rated as one of the top 21 innovators in India by NASSCOM
Juror’s Distinction Award for Innovation in Manthan 2008
Nominated for Best UK Entrant in 2009 by UKTI

An ISO 9001:2008 certified company 

Confidential
About the Speaker
 15 years of industry experience and has worked as a Lead
and Project Consultant for Functional Safety projects.

 Functional Safety Seminars (IEC 61508, ISO26262,


RTCA DO 178B)

 Functional Safety Consulting

 Functional Safety on Verification activities

 Consulting on Strategic Technical Project Management

Confidential
Contents
 ISO 26262 Overview
 ISO 26262 First Steps
 ASIL Determination
 ISO 26262 Life Cycle Work Products
 Methods for Software Unit Implementation
 Embitel-Heicon Collaboration

Confidential
ISO 26262 Overview
 ISO 26262 is the adaption of IEC 61508 to comply with needs specific to
road vehicles
 Safety-related systems that include electrical and/or electronic (E/E)
systems
 Series production passenger cars (up to 3500kg max. vehicle mass)
 ISO 26262 addresses possible hazards caused by malfunctions behavior
of E/E safety-related systems and their interactions
 ISO 26262 does not apply to hazards related to electrical shock, fire,
smoke, heat, radiation, toxicity, flammability, reactivity, corrosion etc.

Confidential
ISO 26262 Overview

2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
(Safety Lifecycle, Hazard
Analysis, Risk Assessment , Repair
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

Confidential
ISO 26262 First steps

Hazard analysis and


risk assessment
Concept Phase

Specification and management of

Derive ASIL Level


Specification of Safety Goals

Specification of System
safety requirements

safety requirements
Product development

Hardware safety Software safety Architecture


requirements requirements

Confidential
ASIL Determination

Exposure Controllability Severity ASIL


E0 to E4 C0 to C3 S0 to S3 A to D

Class
E0 E1 E2 E3 E4
Incredible Very low probability Low probability Medium probability High probability

(Probability of exposure regarding operational situations)

Class
C0 C1 C2 C3
Controllable in general Simply controllable Normally controllable Difficult to control or uncontrollable

Class
S0 S1 S2 S3
No injuries Light and moderate injuries Severe and life-threatining Life-threatening injuries (survival
injuries (survival probable) uncertain), fatal injuries

Confidential
ASIL Determination

Severity class Probability Controllability class


class C1 C2 C3
E1 QM QM QM

S1 E2 QM QM QM
E3 QM QM A
E4 QM A B
E1 QM QM QM

S2 E2 QM QM A
E3 QM QM B
E4 A B C
E1 QM QM A

S3 E2 QM A B
E3 A B C
E4 B C D

ISO 26262-3
Note: The class QM (Quality Management) denotes no requirement to comply
with ISO 26262

Confidential
Content
 ISO 26262 Overview
 ISO 26262 First Steps
 ASIL Determination
 ISO 26262 Life Cycle Work Products
 Methods for Software Unit Implementation
 Embitel-Heicon Collaboration

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

ISO 26262 Work Products – Functional Safety Mngt.


Work Products Hazard analysis and
Functional Safety Management

risk assessment
 Organizational-specific rules and processes for functional safety
 Evidence of competence
 Evidence of quality management
 Functional safety assessment plan
 Evidence of field monitoring

ISO/FDIS 26262-2

10

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,

ISO 26262 Work Products – Concept Phase


Safety Analysis

Work Products Hazard analysis and


risk assessment
 Impact Analysis (Development of new Product or Modification of
existing Product)
Concept Phase

 Hazard analysis and risk assessment


 Safety goals
 Functional safety concept (Requirements)
 Verification (Review) report

ISO 26262-3

11

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes

ISO 26262 Work Products – Production


(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

Work Products
Hazard analysis and
 Safety-related content of risk
theassessment
production plan
 Safety-related content of the production control plan
Production, Maintenance

 Control measure report


 Assessment report for capability of the production process
 Safety-related content of the maintenance plan
 Repair instructions
 Safety-related content of the information made available to the user
 Instructions regarding field observations
 Safety related content of the instructions for decommissioning

ISO 26262-7

12

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes

ISO 26262 Work Products – Supporting Fkt.


(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

Work Products – Distributed Development Work Products – Config Managmt


 Supplier selection report  Configuration Management Plan
Hazard analysis and
 Development interface agreement
 Supplier’s project plan risk assessment
 Safety assessment report
 Supply agreement
Product Development

Work Products – Change Management Work Products - Documentation Process


 Change management plan  Document management plan
 Change request  Documentation guideline requirements
 Impact analysis and change request plan
 Change report ISO 26262-8

Work Products – Tool Qualification


 Software tool criteria evaluation report
 Software tool qualification report

13

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

ISO 26262 Work Products – ASIL and


8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

safety oriented analysis


Hazard analysis and
Work Products risk assessment
ASIL and safety-oriented analysis

 Update of the corresponding Documentation due to Requirements


decomposition with respect to ASIL tailoring
 Analysis of dependent failures
 Safety analysis

ISO 26262-9

14

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
(Safety Lifecycle, Hazard
Analysis, Risk Assessment , Repair
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes

Embedded System/Software Life Cycle


(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

Technical Safety Validation and


Requirements Integration Testing

System Design

Details see Slide 16

Software safety (HW)/Software


requirements Integration Testing

Software architectural
design

Software unit design Software unit testing

Embedded Software

Details see Slide 17


15

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
(Safety Lifecycle, Hazard
Analysis, Risk Assessment , Repair
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

ISO 26262 Work Products – System Level


9. ASIL-oriented and safety-oriented Analysis
Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

ü Project Plan
ü Safety Plan
Validation and Integration Testing

Technical Safety Requirements ü Validation plan

ü Technical safety requirements ü Validation report


specification ü Item integration and testing plan(s)
ü System verification report ü Integration testing specification(s)
ü Integration testing report(s)
ü Functional safety assessment report

System Design
ü Technical safety concept
ü System design specification
ü Hardware-software interface
specification (HSI)
ü Specification of requirements for
production, operation service and
decommissioning

16 ISO 26262-4

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis

ISO 26262 Work Products – Software Level


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

Software safety requirements


ü Software safety requirements (HW)/Software Integration Testing
specification ü Software verification plan
Software architectural design ü Hardware-software interface ü Software verification specification
ü Software architectural design specification ü Software verification report
specification ü Software verification Report
ü Safety analysis report
ü Dependent failure analysis report
ü Software verification Report Software unit testing
Software unit design
ü Software verification plan
ü Software unit design specification
ü Software verification specification
ü Software verification report
ü Software verification report

Embedded Software

17 ISO 26262-6

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
(Safety Lifecycle, Hazard
Analysis, Risk Assessment , Repair
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,

Embedded System/Hardware Life Cycle


Safety Analysis

Technical Safety Validation and


Requirements Integration Testing

System Design

Hardware safety Hardware Integration


requirements Testing

Hardware design

Hardware

Details see Slide 19

18

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes
(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

ISO 26262 Work Products – Hardware Level

Hardware safety requirements


ü Hardware safety requirements
specification
Hardware design Hardware Integration Testing
ü Hardware-software interface
ü Hardware design specification ü Hardware integration test report
specification
ü Hardware Safety analysis report ü Hardware safety requirement
ü Hardware design verification verification Report
Report
ü Analysis of architecture to cope
with random hardware failures

Hardware

19 ISO 26262-5

Confidential
Content
 ISO 26262 Overview
 ISO 26262 First Steps
 ASIL Determination
 ISO 26262 Life Cycle Work Products
 Software Unit Implementation Methods
 Embitel-Heicon Collaboration

20

Confidential
2. Functional Safety Management

4. System 7.
3. Concept Production,
Phase Maintenance
, Repair
(Safety Lifecycle, Hazard
Analysis, Risk Assessment
Functional Safety concept)

5. Hardware 6. Software

8. Supporting Processes

Software Unit Implementation Methods


(Config.Manag, Change Manag, Verification, Documentation, Qualification of SW Tools)

9. ASIL-oriented and safety-oriented Analysis


Requirements decomposition with respect to ASIL tailoring, Criteria for coexistence of elements, Analysis of dependent failure,
Safety Analysis

Methods ASIL A ASIL B ASIL C ASIL D

One entry and one exit point in subprograms and ++ ++ ++ ++


functions
No dynamic objects or variables, or else online test + ++ ++ ++
during their creation
Initialization of variables ++ ++ ++ ++
No multiple use of variable names + ++ ++ ++
Avoid global variables or else justify their usage + + ++ ++
Limited use of pointers o + + ++
No implicit type conversions + ++ ++ ++
No hidden data flow or control flow + ++ ++ ++
No unconditional jumps ++ ++ ++ ++
No recursions + + ++ ++

21 ISO 26262-6

Confidential
HEICON
Our Collaboration & Services

ISO 26262 Consultancy

Functional Safety Validation & Verification

ISO 26262 Tool Qualifications

Automotive Software & Hardware development

22

Confidential
Q&A
International Presence
embitel – A Partner For You

Please Send Additional queries to:

e.seminar@embitel.com

You might also like