| поискавой системы для электроныых деталей |
|
AN4475 датащи(PDF) 14 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
AN4475 датащи(HTML) 14 Page - STMicroelectronics |
|
14 / 26 page ![]() DocID026216 Rev 1 15/27 AN4475 Functional safety requirements for application software 26 2.10.2 Additional mechanisms The two analog-to-digital converter macro-cells share the same digital interface. To increase the diagnostic coverage against failures impacting this common logic, some additional counter measures can be developed. For example: • Oversampling; • Plausibility check. Suggested: [covers: SW_OVERSAMPLING_AN_INPUT] the analog inputs are acquired redundantly in time. [end] Rationale: to increase the diagnostic coverage. Implementation hint: the sampling rate is significantly higher than the Nyquist Frequency related to the input signal. The acquired values are compared by software in order to verify the correlation. In case of fault, the acquired values are not correlated with themselves. Against random faults, at least three consecutive analog values are acquired for each analog input. 2.11 Temperature sensor SPC563Mxx devices are equipped with a temperature sensor in order to monitor the device temperature. This temperature sensor generates a voltage that increases linearly with temperature and that can be read by software using the on-board eQADC module, so the read value can be used with the band-gap voltage and constants stored in flash memory during factory test to calculate device junction temperature. Suggested: the temperature sensor output voltage is read by software and the corresponding temperature is compared with the upper limit of the operating range. In case an over-temperature fault is detected, the device is set to a safe state. This check runs once per FTTI. Rationale: to detect over-temperature faults. Implementation hint: to set the proper operating range threshold, the temperature sensor accuracy of 10° C and the maximum operating junction temperature of 150 °C (see device data sheet,Chapter Appendix B: Document references) are considered. Note: External temperature sensor could be used to check internal temperature sensor output. 2.12 Software Watchdog Timer (SWT) Suggested: [covers: HW_INT_SWT] SWT module is used to implement control flow monitoring function. The SWT is clocked by oscillator clock. These specific software countermeasures can run once after the Power-On Reset (POR) before the safety function starts. [end] However, other control flow monitoring approaches that do not use the SWT may also be used. SPC563Mxx devices provide the hardware support (SWT) to implement both control flow monitoring and temporal flow monitoring methods. Rationale: to detect a defective program sequence. Implementation hint: SWT can be enabled asserting the bit SWT_MCR[WEN] and the configuration registers can be hard-locked asserting the bit SWT_MCR[HLK]. The timeout register (SWT_TO) must contain a 32-bit value that represents a timeout less than the FTTI. Before the safety function is executed, software must verify that the SWT is enabled |
|
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |