SFFSAY3 January   2026 F29H850DM , F29H850TU , F29H859TU-Q1 , F29P329SM-Q1 , F29P589DM-Q1 , F29P589DU-Q1 , TMCS1123 , TMCS1123-Q1 , TPS650362-Q1 , TPS650364-Q1 , TPS650365-Q1 , TPS650366-Q1

 

  1.   1
  2.   Abstract
  3.   Trademarks
  4. 1Introduction
    1. 1.1 Background
    2. 1.2 HW/SW FuSa Analysis Process
      1. 1.2.1 Item Definition
      2. 1.2.2 Functional Safety Goal
      3. 1.2.3 Functional Safety Concept
      4. 1.2.4 Technical Safety Concept
      5. 1.2.5 HW/SW Safety Requirement
      6. 1.2.6 Dependent‑failure Analysis
    3. 1.3 TI Collaterals
      1. 1.3.1 TI Components Category
      2. 1.3.2 FuSa Collaterals for Safety MCU
  5. 2FuSa Concepts of OBC System
    1. 2.1 Item Definition
      1. 2.1.1 Item Functions
      2. 2.1.2 System Boundaries
      3. 2.1.3 External Interfaces
      4. 2.1.4 Operation Modes
    2. 2.2 Functional Safety Goal
    3. 2.3 Functional Safety Concept
    4. 2.4 Technical Safety Concept
    5. 2.5 HW/SW Safety Requirement
    6. 2.6 Dependent‑Failure Analysis
  6. 3FuSa Components of OBC System
    1. 3.1 Components Overview
    2. 3.2 Microcontroller
      1. 3.2.1 CPU
      2. 3.2.2 ADC Sample
      3. 3.2.3 PWM Generation
      4. 3.2.4 CMPSS
      5. 3.2.5 Data Transmission
      6. 3.2.6 Fault Signal Monitor and Safe State Control
    3. 3.3 Power Management IC
      1. 3.3.1 MCU Monitor
      2. 3.3.2 Shutdown Sequence
      3. 3.3.3 Power Supply
    4. 3.4 System Basis Chips
      1. 3.4.1 CAN Communication
      2. 3.4.2 Supply Voltage Rail Monitoring
      3. 3.4.3 SPI/Processor Communication
      4. 3.4.4 Device Internal EEPROM
    5. 3.5 Power Supply and Supervisor
    6. 3.6 Gate Driver
    7. 3.7 Voltage Sensor
    8. 3.8 Current Sensor
    9. 3.9 Temperature Sensor
  7. 4Summary
  8. 5References

Item Definition

The first step in FuSa design is the item definition. The item is the top‑level vehicle function or subsystem that will be the subject of functional‑safety analysis. The objectives of item definition are:

  • Define and describe the item, its dependencies on, and interaction with the environment and other items.

  • Support an adequate understanding of the item so that the activities in subsequent phases can be performed.

This step incorporates hazard analysis and risk assessment (HARA), a systematic methodology that transforms identified functional hazards into quantified Automotive Safety Integrity Levels (ASILs) and corresponding safety goals. The HARA process establishes clear traceability to the item definition while providing a risk-based foundation for all subsequent safety activities. The primary objectives of HARA include:

  • Identify all potential hazardous events that could result from the item.

  • Rigorous risk assessment through detailed analysis of each hazard's severity, exposure probability, and controllability factors.

  • Assignment of appropriate ASIL classifications based on the assessment results.

Hazard identification can be carried out using techniques such as Failure Modes and Effects Analysis (FMEA), Hazard and Operability studies (HAZOP), or lessons learned from past quality problems. Each identified hazardous event is then evaluated for Severity (S), Exposure (E) and Controllability (C) and assigned an ASIL. The appropriate ASIL for each event can be derived from the matrix shown in Table 1-3.

Table 1-3 ASIL Ratings According to ISO 26262
SeverityExposureControllability
C1 (Simple)C2 (Normal)C3 (Difficult, uncontrollable)
S1 (Light and moderate injuries)E1 (Very low)QMQMQM
E2 (Low)QMQMQM
E3 (Medium)QMQMA
E4 (High)QMAB
S2 (Severe and life-threatening injuries – survival probable)E1 (Very low)QMQMQM
E2 (Low)QMQMA
E3 (Medium)QMAB
E4 (High)ABC
S3 (Life threatening injuries – fatal injuries)E1 (Very low)QMQMA
E2 (Low)QMAB
E3 (Medium)ABC
E4 (High)BCD