Course Introduction
AUTOSAR (Automotive Open System Architecture) improves the management of complex automotive electrical and electronic architectures by enhancing the reusability and interchangeability of software modules between OEMs and suppliers. Today AUTOSAR has been applied to the vast majority of automotive ECUs, and AUTOSAR standard specifications also include descriptions related to functional safety. AUTOSAR itself does not provide a complete safety solution. Projects still need to comply with ISO 26262 to achieve the desired safety level design, but AUTOSAR provides functional safety measures and mechanisms to support the realization of necessary functional safety of the system.
Training Benefits
- Understand the relationship between AUTOSAR and automotive functional safety
- Understand AUTOSAR general functional safety mechanisms
Target Participants
- Automotive electrical and electronic system engineers, software and hardware engineers
Course Outline
- Explanation of E2E safety mechanisms: CRC algorithm explanation
- Difference between Alive Counter and Sequence Counter
- Methods to ensure that ASIL A, B, C, D level signals meet corresponding ASIL level failure detection in transmission paths
- Related requirements for CRC and Counter length
- Recommendations given by AUTOSAR for transmitting signals of different safety levels based on CAN, CAN-FD and automotive Ethernet
- E2E profile
- Requirements of AUTOSAR for adding and removing E2E at different layers, corresponding to application layer, RTE and Communication module
- Methods for RTE to ensure data transmission reaches corresponding ASIL level
- Explanation of WDGM module safety mechanisms: three major safety mechanisms of WDGM
- Usage scenarios, diagnosable failures and implementation examples of Alive Supervision
- Usage scenarios, diagnosable failures and implementation examples of Deadline Supervision
- Usage scenarios, diagnosable failures and implementation examples of Logical Supervision
- Explanation of OS safety mechanisms
- Stack overflow checking methods, two common implementation methods and pros and cons of OS stack overflow checking
- Methods, scenarios and pros and cons of implementing MPU, examples of implementing MPU, relationship between MPU and OS Application
- How user permission code calls privileged code
- How Task1 protects its stack from accidental access by Task2
- Ways to prevent OS crashes caused by application code erroneously calling or passing wrong parameters
- Explanation of three major Timing Protection safety mechanisms
- Principle, scenarios and detectable failures of Execution Time monitoring safety mechanism implementation
- Principle, scenarios and detectable failures of Blocking Time monitoring safety mechanism implementation
- Principle, scenarios and detectable failures of Inter-arrival Rate monitoring safety mechanism implementation
- Functions enhanced in current MCU hardware kernels that can help OS better implement safety mechanisms