ASIL accuracy

Last updated

ASIL accuracy describes the maximum possible deviation of a measurement in a system in which a single point fault occurred before some diagnostic detects this fault. This concept applies to automotive systems designed under the ISO-26262 methodology for automotive functional safety, which defines Automotive Safety Integrity Levels (ASILs) to classify risks.

While accuracy refers to a single measurement, ASIL accuracy considers variation in the primary measurement being assessed as well as variation in the diagnostic measurement or measurements used to detect single point faults.

How to calculate

To detect single point faults, two measurements can be compared. Measurement-comparison-drawing.png
To detect single point faults, two measurements can be compared.
Illustration of overlapping measurements with different accuracy, and correspondingly chosen fault detection limit. Circles-showing-accuracy-drawing.png
Illustration of overlapping measurements with different accuracy, and correspondingly chosen fault detection limit.
Illustration of how to calculate ASIL accuracy given the fault detection limit VLIM and the diagnostic accuracy V2. Accuracy-drift-and-ASIL-accuracy.png
Illustration of how to calculate ASIL accuracy given the fault detection limit VLIM and the diagnostic accuracy V2.

A conceptually simple implementation incorporates a fully redundant measurement. A fault in the primary measurement can be detected by comparing the primary and diagnostic measurements, and signaling a fault if the difference is outside the expected operating range. If the two measurements are truly independent and uncorrelated, in normal operation they can be at opposite ends of their operating ranges. If the primary measurement has an accuracy V1, and if the redundant diagnostic measurement has an accuracy V2, then the fault detection limit should be set to at least VLIM=V1+V2 to avoid false positives. The system shall flag a fault if the difference between V1 and V2 is greater than VLIM. The fault detection limit, however, should not be confused with ASIL accuracy. Consider the case of a single point fault in which the primary measurement drifts to an incorrect value. ASIL accuracy describes the maximum such drift before the fault is flagged. If the diagnostic measurement V2 is at the maximum of its operating range, the primary measurement can drift VLIM further before the fault is raised. The maximum possible drift in the primary measurement V1, then, is V2+VLIM, and so the ASIL accuracy VASIL=V2+VLIM.



Related Research Articles

Multimeter Electronic measuring instrument that combines several measurement functions in one unit

A multimeter or a multitester, also known as a VOM (volt-ohm-milliammeter), is an electronic measuring instrument that combines several measurement functions in one unit. A typical multimeter can measure voltage, current, and resistance. Analog multimeters use a microammeter with a moving pointer to display readings. Digital multimeters have a numeric display, and may also show a graphical bar representing the measured value. Digital multimeters are now far more common due to their lower cost and greater precision, but analog multimeters are still preferable in some cases, for example when monitoring a rapidly varying value.

A Doppler radar is a specialized radar that uses the Doppler effect to produce velocity data about objects at a distance. It does this by bouncing a microwave signal off a desired target and analyzing how the object's motion has altered the frequency of the returned signal. This variation gives direct and highly accurate measurements of the radial component of a target's velocity relative to the radar. Doppler radars are used in aviation, sounding satellites, Major League Baseball's StatCast system, meteorology, radar guns, radiology and healthcare, and bistatic radar.

Indium phosphide chemical compound

Indium phosphide (InP) is a binary semiconductor composed of indium and phosphorus. It has a face-centered cubic ("zincblende") crystal structure, identical to that of GaAs and most of the III-V semiconductors.

Linear variable differential transformer LVDT

The linear variable differential transformer (LVDT) is a type of electrical transformer used for measuring linear displacement (position). A counterpart to this device that is used for measuring rotary displacement is called a rotary variable differential transformer (RVDT).

A rotary variable differential transformer (RVDT) is a type of electrical transformer used for measuring angular displacement.

Receiver autonomous integrity monitoring (RAIM) is a technology developed to assess the integrity of global positioning system (GPS) signals in a GPS receiver system. It is of special importance in safety-critical GPS applications, such as in aviation or marine navigation.

Failure mode and effects analysis is the process of reviewing as many components, assemblies, and subsystems as possible to identify potential failure modes in a system and their causes and effects. For each component, the failure modes and their resulting effects on the rest of the system are recorded in a specific FMEA worksheet. There are numerous variations of such worksheets. An FMEA can be a qualitative analysis, but may be put on a quantitative basis when mathematical failure rate models are combined with a statistical failure mode ratio database. It was one of the first highly structured, systematic techniques for failure analysis. It was developed by reliability engineers in the late 1950s to study problems that might arise from malfunctions of military systems. An FMEA is often the first step of a system reliability study.

Advanced driver-assistance systems

Advanced driver-assistance systems (ADAS), are electronic systems that help the vehicle driver while driving or during parking. When designed with a safe human-machine interface, they are intended to increase car safety and more generally road safety. ADAS systems use electronic technology such as microcontroller units (MCU), electronic control units (ECU), and power semiconductor devices.

Current transformer current transformer

A current transformer (CT) is a type of transformer that is used to reduce or multiply an alternating current (AC). It produces a current in its secondary which is proportional to the current in its primary.

Redundancy (engineering) Duplication of critical components to increase reliability of a system

In engineering, redundancy is the duplication of critical components or functions of a system with the intention of increasing reliability of the system, usually in the form of a backup or fail-safe, or to improve actual system performance, such as in the case of GNSS receivers, or multi-threaded computer processing.

Load cell

load cell is a type of transducer, specifically a force transducer. It converts a force such as tension, compression, pressure, or torque into an electrical signal that can be measured and standardized. As the force applied to the load cell increases, the electrical signal changes proportionally. The most common types of load cell used are hydraulic, pneumatic, and strain gauge.

Fault tolerance is the property that enables a system to continue operating properly in the event of the failure of some of its components. If its operating quality decreases at all, the decrease is proportional to the severity of the failure, as compared to a naively designed system, in which even a small failure can cause total breakdown. Fault tolerance is particularly sought after in high-availability or life-critical systems. The ability of maintaining functionality when portions of a system break down is referred to as graceful degradation.

Condition monitoring is the process of monitoring a parameter of condition in machinery, in order to identify a significant change which is indicative of a developing fault. It is a major component of predictive maintenance. The use of condition monitoring allows maintenance to be scheduled, or other actions to be taken to prevent consequential damages and avoid its consequences. Condition monitoring has a unique benefit in that conditions that would shorten normal lifespan can be addressed before they develop into a major failure. Condition monitoring techniques are normally used on rotating equipment, auxiliary systems and other machinery, while periodic inspection using non-destructive testing (NDT) techniques and fit for service (FFS) evaluation are used for static plant equipment such as steam boilers, piping and heat exchangers.

In the automotive industry, brake-by-wire technology is the ability to control brakes through electrical means. It can be designed to supplement ordinary service brakes or it can be a standalone brake system.

Gas detector

A gas detector is a device that detects the presence of gases in an area, often as part of a safety system. This type of equipment is used to detect a gas leak or other emissions and can interface with a control system so a process can be automatically shut down. A gas detector can sound an alarm to operators in the area where the leak is occurring, giving them the opportunity to leave. This type of device is important because there are many gases that can be harmful to organic life, such as humans or animals.

An optical power meter (OPM) is a device used measure the power in an optical signal. The term usually refers to a device for testing average power in fiber optic systems. Other general purpose light power measuring devices are usually called radiometers, photometers, laser power meters, light meters or lux meters.

ISO 26262, titled "Road vehicles – Functional safety", is an international standard for functional safety of electrical and/or electronic systems in production automobiles defined by the International Organization for Standardization (ISO) in 2011.

Automotive Safety Integrity Level (ASIL) is a risk classification scheme defined by the ISO 26262 - Functional Safety for Road Vehicles standard. This is an adaptation of the Safety Integrity Level used in IEC 61508 for the automotive industry. This classification helps defining the safety requirements necessary to be in line with the ISO 26262 standard. The ASIL is established by performing a risk analysis of a potential hazard by looking at the Severity, Exposure and Controllability of the vehicle operating scenario. The safety goal for that hazard in turn carries the ASIL requirements.

Qorivva is a line of Power ISA 2.03-based microcontrollers from Freescale built around one or more PowerPC e200 cores. Within this line are a number of products specifically targeted for functional safety applications. The hardware-based fault detection and correction features found within this line include dual cores that may run in lock-step, full-path ECC, automated self-testing of memory and logic, peripheral redundancy, and monitor/checker cores.

While almost every weighing scale uses the same basic principle, industrial weighing scales are designed to do a lot more. They handle heavier loads, often in different conditions, both environmental and physical.

References