SWRA825 January 2025 IWR6843 , LP87745-Q1
From a safety architecture, one key consideration is to consider the IEC 61496 requirements. While IEC TS 61496-5 mandates a type 3 ESPE, IEC 61496-1 defines a type 3 with the following wording:
“In cases where a single fault which does not cause a failure to danger of the RPD is not detected, the occurrence of a further fault internal to the RPD shall not cause a failure to danger.”
There are multiple ways to architect a sensor that fulfills this, some of which include:
Since the first option with physical redundancy of the sensing element is equivalent to the previously called “co-located bistatic” option, it is not covered in this paper.
The other 2 options that highlight and leverage redundancy and multi-channel at the sensor level and take advantage of monitoring and fault injection are discussed in the upcoming sections.
Note that certain aspects of the device-level safety mechanisms that are described in the safety manual – which as of time of writing of this white paper is under NDA – are not explicated here either.