Adapting the FMEA for Safety Critical Design Processes
Functional safety standards (ISO 26262, IEC 61508) require a safety life cycle which demands additional design and engineering tasks to be managed. This paper addresses how the existing FMEAs have to be extended and refocused to address and overview signal paths throughout the system. The safety standards require to classify signals with a SIL (Safety Integrity Level) and the higher the SIL the more parallel controls and checks must assure that the signal is correctly calculated, used, and monitored. This paper illustrates this extension of the FMEA using the FMEA to investigate the effect of false sensor signals resulting out of failures in software monitoring functions and false failure reactions on system level resulting out of either false sensor signals or failures within the diagnostic software. AS a complementary activity to the FMEDA a FMEA method is introduced that allows an analysis during the development process that is performed prior to the “in-use” FMEDA.
KeywordsFunctional safety FMEA signals extended safety design process
Unable to display preview. Download preview PDF.
- 1.IEC 61508 (1998)Google Scholar
- 2.ISO 26262, Road vehicles — Functional safetyGoogle Scholar
- 3.Spork, G.: Establishment of a Performance Driven Improvement Program. In: Proceedings of the EuroSPI 2007 Conference (2007)Google Scholar
- 4.Volker, B., Richard, M.: Improving the Software-Development for multiple Projects by applying a Platform Strategy for Mechatronic Systems. In: Proceedings of the EuroSPI 2009 Conference (2009)Google Scholar