2. IEC61508 ISO WD IEC6150 SIL( Safety Integrity Level ) ISO WD2626 ASIL( Automotive Safety Integrity Level ) SIL/ASIL (tolerable risk) (Residu

Similar documents
2015/12/24 1

untitled

(1 ) (2 ) Table 1. Details of each bar group sheared simultaneously (major shearing unit). 208

PowerPoint

202

IEC :2014 (ed. 4) の概要 (ed. 2)


untitled

ユーザーズマニュアル

2

Microsoft Word - PCM TL-Ed.4.4(特定電気用品適合性検査申込のご案内)


ユーザーズマニュアル

2 236

A Nutritional Study of Anemia in Pregnancy Hematologic Characteristics in Pregnancy (Part 1) Keizo Shiraki, Fumiko Hisaoka Department of Nutrition, Sc


[2] , [3] 2. 2 [4] 2. 3 BABOK BABOK(Business Analysis Body of Knowledge) BABOK IIBA(International Institute of Business Analysis) BABOK 7





Appropriate Disaster Preparedness Education in Classrooms According to Students Grade, from Kindergarten through High School Contrivance of an Educati

国際社会文化研究所紀要 14号☆/目次

32 東和知財研究第 5 巻第 2 号 ( 通巻第 7 号 ) Journal of Towa Institute of Intellectual Property Vol.5, No.1 33 発明の単一性の要件 シフト補正の制限の審査基準改訂のご紹介 東和国際特許事務所 加藤 弁理士 2013

Studies of Foot Form for Footwear Design (Part 9) : Characteristics of the Foot Form of Young and Elder Women Based on their Sizes of Ball Joint Girth

SPSS

1..FEM FEM 3. 4.

46

総研大文化科学研究第 11 号 (2015)

Bull. of Nippon Sport Sci. Univ. 47 (1) Devising musical expression in teaching methods for elementary music An attempt at shared teaching

GPGPU

untitled

Web Web Web Web Web, i


<95DB8C9288E397C389C88A E696E6462>



Chapter

JIS Z 9001:1998JIS Z 9002:1998 ISO/IEC 17025ISO/IEC Guide 25

untitled

24_ChenGuang_final.indd

Core Ethics Vol. a


大学論集第42号本文.indb


Development of Induction and Exhaust Systems for Third-Era Honda Formula One Engines Induction and exhaust systems determine the amount of air intake

22SPC4報告書

JIS A 5308 a1 moll moll moll (JP) REAGENT CHEMICALS ninth edition ACS SPECIFICATIONS Replication Duplicate standardiz

alternating current component and two transient components. Both transient components are direct currents at starting of the motor and are sinusoidal

高信頼RTミドルウエアの開発

,,,,., C Java,,.,,.,., ,,.,, i

- 1 -

, PDD ASD p.,.,..,..,.,..,.,..,.,.,.,, 146

日本国憲法における「社会福祉」

06’ÓŠ¹/ŒØŒì

EU RMap

28 Docker Design and Implementation of Program Evaluation System Using Docker Virtualized Environment

PC_14ZY6_BFT150A_US_ indd

_念3)医療2009_夏.indd

Page 1 of 6 B (The World of Mathematics) November 20, 2006 Final Exam 2006 Division: ID#: Name: 1. p, q, r (Let p, q, r are propositions. ) (10pts) (a

浜松医科大学紀要


137. Tenancy specific information (a) Amount of deposit paid. (insert amount of deposit paid; in the case of a joint tenancy it should be the total am

FAX-760CLT


How to read the marks and remarks used in this parts book. Section 1 : Explanation of Code Use In MRK Column OO : Interchangeable between the new part


How to read the marks and remarks used in this parts book. Section 1 : Explanation of Code Use In MRK Column OO : Interchangeable between the new part

1 1 tf-idf tf-idf i

I N S T R U M E N T A T I O N & E L E C T R I C A L E Q U I P M E N T Pressure-resistant gasket type retreat method effective bulk compressibility Fro

How to read the marks and remarks used in this parts book. Section 1 : Explanation of Code Use In MRK Column OO : Interchangeable between the new part

04_奥田順也.indd

1. Database&Logic Word/Excel/PPT/PDF&Web Ultimate Dictionary 4. Jukkou&Rewrite 5. Convenience&Safety 6. Chinese&Korean 7. Support&Consultation 8

1 UD Fig. 1 Concept of UD tourist information system. 1 ()KDDI UD 7) ) UD c 2010 Information Processing S

スライド 1

How to read the marks and remarks used in this parts book. Section 1 : Explanation of Code Use In MRK Column OO : Interchangeable between the new part

橡自動車~1.PDF


01_舘野.indd

<8ED089EF8B D312D30914F95742E696E6464>

利隆塑料

論文9.indd

Vol. 42 No MUC-6 6) 90% 2) MUC-6 MET-1 7),8) 7 90% 1 MUC IREX-NE 9) 10),11) 1) MUCMET 12) IREX-NE 13) ARPA 1987 MUC 1992 TREC IREX-N




クイックスタートガイド [SC-06D]

20 Method for Recognizing Expression Considering Fuzzy Based on Optical Flow

Web-ATMによる店舗向けトータルATMサービス

10-渡部芳栄.indd

:

untitled



IPSJ SIG Technical Report Vol.2014-EIP-63 No /2/21 1,a) Wi-Fi Probe Request MAC MAC Probe Request MAC A dynamic ads control based on tra

Microsoft Word - j201drills27.doc

年次大会原稿最終.PDF

_Y05…X…`…‘…“†[…h…•

04_学術.indd

評論・社会科学 98号(P)☆/1.鰺坂

Transcription:

Consideration of requirement of decomposition for a safety related system NEC IEC61508 ISO 26262 We considered the concept of system decomposition paying attention to the decomposition concept of the system which includes software in individual application standard ISO 26262 of functional safety standard IEC61508 In order to divide a safety related system and to deliver the requirements for safety into each subsystems/components, such independency is made into requirements, but under the present circumstances, it is insufficient in view of bilaterally supervising. This research considers the attribute of decomposition and is examining the attribute. As a result, the conclusion that the independency and the diagnostic coverage of the divided subsystem/component were important for system decomposition was reached. And it proposes making independency and the diagnostic coverage into a matrix, and considering it as the attribute of system decomposition. 1. B IEC61508 C ( B.1) ISO SC3/TC22/WG16 2005 2007 (ISO WD26262) ( ) 1

2. IEC61508 ISO WD26262 4 IEC6150 SIL( Safety Integrity Level ) ISO WD2626 ASIL( Automotive Safety Integrity Level ) SIL/ASIL (tolerable risk) (Residual Risk) ISO WD26262 Decomposition ASIL D ASIL C ASIL A ASIL D C+A ASIL B ASIL A C B+A ASIL A ASIL A ISO26262 1 Decomposition ISO WD26262 Decomposition IEC61508 ISO26262 1. 2. 3. 4. 5. 6. A IEC61508/ISO26262 7. B 2

1. Decomposition ISO WD26262 (Diagnostic coverage) ( ) ( ) ( IC ) ( ) ( ) ( ) CCF( Common cause failure) CCF ( ) 2 (Safety State) Safety State (Latent failure) ABS/VSA IEC61508 6 FT 3 3

CCF 3 S f d CCF CCF f d CCF S f d CCF CCF ( ) CCF (i) ( ) S CCF f d 3 FT FT 4 S fud fd dud 4 FT fd dud fud S fd dud fud 4

2. CPU OS API IO 5 OS 5 IO Safety Concept (Safety state) IO 5

OS API OS FT 6 S h O OS f d 6 FT h OS o f d S S = f + O + f * d A ASIL OS ASIL-D 10-8 h o 10-7 h * d 10-7 ASIL C Decomposition 3. Decomposition WD26262-5 6

Decomposition ASIL CCF ASIL ASIL 1 1 None Low Medium High None ( < 60%) ASIL A ASIL B Low (>=60%) ASIL A ASIL B ASIL C Medium (>=90%) ASIL A ASIL B ASIL C ASIL D High (>=99%) ASIL B ASIL C ASIL D ASIL D ASIL D Medium High High Medium 4. ASIL Decomposition 1 Decomposition 5. ISO WD26262 07 CD(Committee Draft) ASIL Decomposition 2006 10 MISRA Decomposition 6 ISO TC22/SC3/WG16 7

IEC61508 ( JIS C 0508) ISO WD26262-3 Concept (Working draft) 1 ISO WD26262-4 System (Working draft) 1 ISO WD26262-5 Hardware (Working draft) 1 ISO WD26262-6 Software (Working draft) 1 1 ISO WD26262 2006 12 MISRA Safety Analysis Guidelines (MISRA SA)Draft Ver.13J 2 2 MISRA SA Ver.13J 2006 6 8

A IEC61508 SIL Safety Integrity Level) SIL SIL 4 SIL IEC61508 5 IEC61508 SIL ASIL (Automotive Safety Integrity Level) ASIL SIL (A~D) SIL ASIL SIL1~3 A.1 ASIL 2007 IEC61508 WD26262 (tolerable risk) A.1 (Residual Risk) (ASIL) (ASIL) Lower than tolerable A.1. 9

ASIL SIL ( ) A 1 B 2 or 3 C 3 or 2 D 3 A.1 ASIL 1. ( ) (Random mode failure) ( ) (Systematic failure) 2. Hazard ( ) (Usability) ( ) (Hazard) IO (Systematic failure) 1. ( ) ( ) ( ) Hazard ( ) 2. ( ) ( ) ( ) ( ) OS ( ) ( ) 3. ( ) ( ) SIL/ASIL 10

IEC61508 A.2 1 2 3 4 5 9 10 11 6 7 8 E/E/PES E/E/PES 12 13 14 16 15 A.2 IEC61508 IEC61508 ISO WD26262 SIL/ASIL A.3,A.4 A.2 IEC61508 Safety integrity level High demand or continuous mode of operation (Probability of a dangerous failure per hour) 4 10-9 to < 10-8 3 10-8 to < 10-7 2 10-7 to < 10-6 1 10-6 to < 10-5 NOTE See notes 3 to 9 below for details on interpreting this table. 11

A.4 ISO WD26262 ASIL Level Random HW failure target values D < 10-8 /h C < 10-7 /h B No requirement( 10-6 ) A No requirement 10-5 12

B 2 IEC61508 IEC61508 Part1 Annex A Table A.1 Software safety requirements specification ) Table A.1 Software safety requirements specification (see 7.2) Technique/Measure Ref SIL1 SIL2 SIL3 SIL4 1 Computer-aided specification tools B.2.4 R R HR HR 2a Semi-formal methods Table B.7 R R HR HR 2b Formal methods including for example, CCS, C.2.4 CSP, HOL, LOTOS, OBJ, temporal logic, --- R R HR VDM and Z a) The software safety requirements specification will always require a description of the problem in natural language and any necessary mathematical notation that reflects the application. b) The table reflects additional requirements for specifying the software safety requirements clearly and precisely. c) Appropriate techniques/measures shall be selected according to the safety integrity level. Alternate or equivalent techniques/measures are indicated by a letter following the number. Only one of the alternate or equivalent techniques/measures has to be satisfied. 13

Table A.4 Software design and development: detailed design (see 7.4.5 and 7.4.6) (This includes software system design, software module design and coding) Technique/Measure Ref SIL1 SIL2 SIL3 SIL4 1a Structured methods including for example, C.2.1 JSD, MASCOT, SADT and Yourdon HR HR HR HR 1b Semi-formal methods Table B.7 R HR HR HR 1c Formal methods including for example, CCS, C.2.4 --- R R HR CSP, HOL, LOTOS, OBJ, temporal logic, VDM and Z 2 Computer-aided design tools B.3.5 R R HR HR 3 Defensive programming C.2.5 --- R HR HR 4 Modular approach Table B.9 HR HR HR HR 5 Design and coding standards Table B.1 R HR HR HR 6 Structured programming C.2.7 HR HR HR HR 7 Use of trusted/verified software modules and components (if available) C.2.10 C.4.5 R HR HR HR Appropriate techniques/measures shall be selected according to the safety integrity level. Alternate or equivalent techniques/measures are indicated by a letter following the number. Only one of the alternate or equivalent techniques/measures has to be satisfied. 14