
UM1915 Rev 3 9/43
UM1915 STM8AF safety architecture
42
3 STM8AF safety architecture
This section describes the safety architecture to implement when using STM8AF
microcontrollers for automotive applications.
3.1 Introduction
The STM8AF microcontroller described in this document is a Safety element out of context
(SEooC), that is, a safety element that can be used in different safety applications.
The aim of this section is to define the context of the analysis in terms of assumptions with
respect to reference safety requirements as also assumptions with respect to the design
external to that SEooC.
As a consequence of the SEooC approach, the goal is not to provide an exhaustive hazard
and risk analysis of the system around the microcontroller, but rather to list the
system-related information (such as the application-related assumptions for dangerousness
factors, frequency of failures and diagnostic coverage already guaranteed by the
application) that have been considered during the following steps of the analysis.
3.1.1 Definition of the SEooC
The automotive industry develops generic elements for different applications and for
different customers. These generic elements can be developed concurrently and by
different companies in different tiers of the supply chain, as a distributed development.
Assumptions are made both on the requirements (including safety requirements) on the
element at higher levels of design and also on the design external to the element.
In a safety context, these elements can be developed as a “Safety Element out of Context”
(SEooC), as described in ISO 26262-10, Clause 9.
According to ISO 26262, a “safety element out of context (SEooC)” is a safety-related
element that is not developed for a specific item, i.e. in the context of a particular vehicle. A
SEooC can be a system, an array of systems, a subsystem, a software component or a
hardware component.
This document considers the STM8AF as a SEooC to whom an ASIL
capability is
required, up to and including ASILB, i.e. it can be used in ASILA and ASILB
environments.
3.2 STM8AF as a SEooC
The STM8AF is a general purpose RISC microcontroller, suitable for embedded
applications and, in particular, for safety related applications.
For a detailed description of the STM8AF functionality refer to the reference manuals,
available on www.st.com.
In this document, the SEooC is identified as the STM8AF microcontroller (MCU),
referenced as a functional block inserted in a system defined by Figure 1. The
MCU acts as
the processing unit of the system, i.e. acquiring field data from sensors,
processing
them according to the implemented algorithm, and taking decisions that bring to specific
commands to external actuators. The MCU is connected directly or indirectly to
sensors
and actuators through communication buses.