Home Knowledge Base Functional Safety (ISO 26262)

Functional Safety (ISO 26262) is the systematic approach to ensuring that electronic systems in safety-critical applications (automotive, medical, industrial) continue to operate correctly or fail safely in the presence of hardware faults — requiring chip designers to implement fault detection, diagnostic coverage, and redundancy mechanisms at the silicon level, with automotive ICs needing to meet specific ASIL (Automotive Safety Integrity Level) ratings that dictate maximum allowable failure rates of 10-100 FIT (Failures In Time, per billion hours).

ASIL Levels

ASILRisk LevelExampleSPFM TargetLFM TargetRandom HW Metric
QMNo safety requirementInfotainment
ASIL ALowRear lights
ASIL BMediumInstrument cluster≥ 90%≥ 60%< 100 FIT
ASIL CHighAirbag controller≥ 97%≥ 80%< 100 FIT
ASIL DHighestSteering, braking, ADAS≥ 99%≥ 90%< 10 FIT

FMEDA (Failure Mode Effects and Diagnostic Analysis)

Hardware Safety Mechanisms

MechanismWhat It ProtectsDiagnostic Coverage
ECC (SECDED)Memory (SRAM, cache)99%+ for single-bit, detected multi-bit
Lockstep CPUProcessor logic99%+ (dual redundant execution)
Watchdog timerSoftware hang60-90% (detects non-response)
CRC on busesData transfer99%+ for data corruption
Memory BISTSRAM array95%+ stuck-at fault detection
Logic BISTRandom logic80-95% stuck-at fault detection
ParityRegister files, FIFOs99%+ single-bit
Voltage/temp monitorsSupply and thermal90%+ for out-of-spec operation

Lockstep Architecture

Safety Analysis Flow

1. Concept phase: Define safety goals and ASIL decomposition. 2. Design phase: Add safety mechanisms (ECC, lockstep, BIST). 3. FMEDA: Quantify failure rates and diagnostic coverage. 4. Fault injection: Simulate faults in RTL → verify detection by safety mechanisms. 5. Verification: Formal + simulation coverage of safety properties. 6. Documentation: Safety manual, FMEDA report, dependent failure analysis.

Functional safety is the gating requirement for semiconductor products entering automotive and safety-critical markets — as autonomous driving and ADAS push chip complexity to billions of transistors, achieving ASIL-D compliance demands that safety be architected into the silicon from day one, with failure detection mechanisms consuming 15-30% of die area and representing a fundamental design constraint alongside performance and power.

functional safetyiso 26262asilsafety critical chipautomotive safetyfmeda

Related Topics

Explore 500+ Semiconductor & AI Topics

From EUV lithography to CUDA optimization — search the full knowledge base or chat with our AI assistant.