SPRUJC6A December 2024 – July 2025 AM2752-Q1 , AM2754-Q1
The Automotive Safety Integrity Level (ASIL) or Safety Integrity Level (SIL) rating is determined by how OptiFlash is used in the SoC.
ASIL-D/SIL-3 can be obtained by duplicating the OptiFlash, supplying the same inputs to both copies, and comparing all the outputs for consistency (including RAM controls). If any output between the two copies do not match, an error has occurred. It is expected that both copies see the same external TAG memory contents. The RAM controls should be checked for consistency in this configuration.
There are cases that may require the safety version of the OptiFlash to be delayed by one cycle, so delaying all inputs to the safety copy and creating a delayed version of the outputs of the primary OptiFlash before comparing outputs.
Each R5F subsystem (R5FSS) in the device implements two instances of the RL2_OF modules that can run in lockstep. RL2 instances run in sync with the R5F CPU lockstep mode of operation, to detect faults that may result in unsafe operating conditions. The CCM-RL2_OF detects faults and signals them to the SOC error signaling module. Figure RL2_OF Lockstep Implementation shows the safety lockstep implementation of the RL2_OF modules.
Figure 12-195 RL2_OF Lockstep
ImplementationInput Handling:
Identical inputs are provided to both RL2_OF module copies CCM-RL2_OF compares all outputs from both copies, including:
Error Detection:
CCMR compare error is triggered if outputs from the two copies mismatch
To prevent common mode failures:
During lockstep mode, outputs are clamped to inactive safe values