Basic Single-Microcontroller Monitoring Concept for Safety Critical Systems

2007-01-1488

04/16/2007

Event
SAE World Congress & Exhibition
Authors Abstract
Content
Electronic Control Units of safety critical systems require constant monitoring of the hardware to be able to bring the system to a safe state if any hardware defects or malfunctions are detected. This monitoring includes memory checking, peripheral checking as well as checking the main processor core. However, checking the processor core is difficult because it cannot be guaranteed that the error will be properly detected if the monitor function is running on a processing system which is malfunctioning. To circumvent this issue, several previously presented monitoring concepts (e.g. SAE#2006-01-0840) employ a second external microprocessor to communicate with the main processor to check its integrity. The addition of a second microcontroller and the associated support circuitry that is required adds to the overall costs of the ECU, increases the size and creates significant system complexity.
Meta TagsDetails
DOI
https://doi.org/10.4271/2007-01-1488
Pages
10
Citation
Schneider, R., Kalhammer, M., Eberhard, D., and Brewerton, S., "Basic Single-Microcontroller Monitoring Concept for Safety Critical Systems," SAE Technical Paper 2007-01-1488, 2007, https://doi.org/10.4271/2007-01-1488.
Additional Details
Publisher
Published
Apr 16, 2007
Product Code
2007-01-1488
Content Type
Technical Paper
Language
English