Is using one FCCU pin enough for ASIL D?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Is using one FCCU pin enough for ASIL D?

Jump to solution
769 Views
haythemLtifi
Contributor II

hello , 

I was wondering if using one FCCU pin is enough for the ASIL D or i have to use both?

I found this table in one of the presentation so i belive one pin is enough.

haythemLtifi_0-1777974700032.png

Also in case of the S32K3 MCU , does it support one FCCU pin or it has to be in pair bi stable ?

i found this in the application note AN14068 page 25 but its not clear to me :

FCCU monitoring by pair (bi-stable protocol)

When connected to the S32K3 MCU FCCU_ERR0 and FCCU_ERR1 pins, the FCCU1 and FCCU2 input

pins must be configured by pair to work in bi-stable protocol by default. This configuration cannot be changed

because the S32K3 only supports this protocol. The FCCU pins' polarity and the SBC reaction upon a fault can

be changed nonetheless.

The default settings for FCCU pins are configured as below:

• FCCU1 = 0 or FCCU2 = 1 is considered as a fault (can be reversed using FCCU12_FLT_POL bits)

• When a fault occurs, the impact can be configured on RSTB, FS0B, and LIMP0 (using FCCU12_[RSTB/

FS0B/LIMP0]_IMPACT)

 

thank you

 

 

0 Kudos
Reply
1 Solution
704 Views
danielmartynek
NXP TechSupport
NXP TechSupport

Hello @haythemLtifi,

S32K3xx is a SEooC, therefore ASIL‑D applies to the complete system, not just the MCU.
ASIL‑D is possible with a single FCCU EOUT signal; however, this introduces a latent fault scenario on the safety path (e.g. the pin stuck at “no fault” due to a short to GND or VDD, depending on polarity).
Referring to the FMEDA (SM3.FCCU_MON), the justification assumes a high diagnostic coverage (~99%). This requires external monitoring, typically implemented by the SBC (e.g. FS26). When both FCCU EOUT signals are used and monitored in a bi‑stable (or fault‑toggle) configuration, the SBC can achieve the required diagnostic coverage. as it detects stuck‑at and line faults structurally. In contrast, when using a single FCCU signal, additional independent mechanisms are required to reach the same level of coverage.

Regards,

Daniel

 

 

View solution in original post

0 Kudos
Reply
1 Reply
705 Views
danielmartynek
NXP TechSupport
NXP TechSupport

Hello @haythemLtifi,

S32K3xx is a SEooC, therefore ASIL‑D applies to the complete system, not just the MCU.
ASIL‑D is possible with a single FCCU EOUT signal; however, this introduces a latent fault scenario on the safety path (e.g. the pin stuck at “no fault” due to a short to GND or VDD, depending on polarity).
Referring to the FMEDA (SM3.FCCU_MON), the justification assumes a high diagnostic coverage (~99%). This requires external monitoring, typically implemented by the SBC (e.g. FS26). When both FCCU EOUT signals are used and monitored in a bi‑stable (or fault‑toggle) configuration, the SBC can achieve the required diagnostic coverage. as it detects stuck‑at and line faults structurally. In contrast, when using a single FCCU signal, additional independent mechanisms are required to reach the same level of coverage.

Regards,

Daniel

 

 

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-2360385%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EIs%20using%20one%20FCCU%20pin%20enough%20for%20ASIL%20D%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2360385%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3Ehello%20%2C%26nbsp%3B%3C%2FP%3E%3CP%3EI%20was%20wondering%20if%20using%20one%20FCCU%20pin%20is%20enough%20for%20the%20ASIL%20D%20or%20i%20have%20to%20use%20both%3F%3C%2FP%3E%3CP%3EI%20found%20this%20table%20in%20one%20of%20the%20presentation%20so%20i%20belive%20one%20pin%20is%20enough.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22haythemLtifi_0-1777974700032.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22haythemLtifi_0-1777974700032.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F384325iD2072D0E7FF35D32%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22haythemLtifi_0-1777974700032.png%22%20alt%3D%22haythemLtifi_0-1777974700032.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EAlso%20in%20case%20of%20the%20S32K3%20MCU%20%2C%20does%20it%20support%20one%20FCCU%20pin%20or%20it%20has%20to%20be%20in%20pair%20bi%20stable%20%3F%3C%2FP%3E%3CP%3Ei%20found%20this%20in%20the%20application%20note%20AN14068%20page%2025%20but%20its%20not%20clear%20to%20me%20%3A%3C%2FP%3E%3CP%3EFCCU%20monitoring%20by%20pair%20(bi-stable%20protocol)%3C%2FP%3E%3CP%3EWhen%20connected%20to%20the%20S32K3%20MCU%20FCCU_ERR0%20and%20FCCU_ERR1%20pins%2C%20the%20FCCU1%20and%20FCCU2%20input%3C%2FP%3E%3CP%3Epins%20must%20be%20configured%20by%20pair%20to%20work%20in%20bi-stable%20protocol%20by%20default.%20This%20configuration%20cannot%20be%20changed%3C%2FP%3E%3CP%3Ebecause%20the%20S32K3%20only%20supports%20this%20protocol.%20The%20FCCU%20pins'%20polarity%20and%20the%20SBC%20reaction%20upon%20a%20fault%20can%3C%2FP%3E%3CP%3Ebe%20changed%20nonetheless.%3C%2FP%3E%3CP%3EThe%20default%20settings%20for%20FCCU%20pins%20are%20configured%20as%20below%3A%3C%2FP%3E%3CP%3E%E2%80%A2%20FCCU1%20%3D%200%20or%20FCCU2%20%3D%201%20is%20considered%20as%20a%20fault%20(can%20be%20reversed%20using%20FCCU12_FLT_POL%20bits)%3C%2FP%3E%3CP%3E%E2%80%A2%20When%20a%20fault%20occurs%2C%20the%20impact%20can%20be%20configured%20on%20RSTB%2C%20FS0B%2C%20and%20LIMP0%20(using%20FCCU12_%5BRSTB%2F%3C%2FP%3E%3CP%3EFS0B%2FLIMP0%5D_IMPACT)%3C%2FP%3E%3CBR%20%2F%3E%3CP%3Ethank%20you%3C%2FP%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2360887%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20Is%20using%20one%20FCCU%20pin%20enough%20for%20ASIL%20D%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2360887%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F258585%22%20target%3D%22_blank%22%3E%40haythemLtifi%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3ES32K3xx%20is%20a%20SEooC%2C%20therefore%20ASIL%E2%80%91D%20applies%20to%20the%20complete%20system%2C%20not%20just%20the%20MCU.%3CBR%20%2F%3EASIL%E2%80%91D%20is%20possible%20with%20a%20single%20FCCU%20EOUT%20signal%3B%20however%2C%20this%20introduces%20a%20latent%20fault%20scenario%20on%20the%20safety%20path%20(e.g.%20the%20pin%20stuck%20at%20%E2%80%9Cno%20fault%E2%80%9D%20due%20to%20a%20short%20to%20GND%20or%20VDD%2C%20depending%20on%20polarity).%3CBR%20%2F%3EReferring%20to%20the%20FMEDA%20(SM3.FCCU_MON)%2C%20the%20justification%20assumes%20a%20high%20diagnostic%20coverage%20(~99%25).%20This%20requires%20external%20monitoring%2C%20typically%20implemented%20by%20the%20SBC%20(e.g.%20FS26).%20When%20both%20FCCU%20EOUT%20signals%20are%20used%20and%20monitored%20in%20a%20bi%E2%80%91stable%20(or%20fault%E2%80%91toggle)%20configuration%2C%20the%20SBC%20can%20achieve%20the%20required%20diagnostic%20coverage.%20as%20it%20detects%20stuck%E2%80%91at%20and%20line%20faults%20structurally.%20In%20contrast%2C%20when%20using%20a%20single%20FCCU%20signal%2C%20additional%20independent%20mechanisms%20are%20required%20to%20reach%20the%20same%20level%20of%20coverage.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3ERegards%2C%3C%2FP%3E%0A%3CP%3EDaniel%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E