August 13, 2023
Article
Functional Safety on Zynq UltraScale+ MPSoC enables developers to build reliable, fault-tolerant embedded systems for applications where system failure can have serious consequences. Automotive, industrial automation, motor control, avionics, and other safety-critical applications require robust mechanisms to detect faults, mitigate errors, and maintain system availability.
iWave’s Functional Safety solution leverages the safety capabilities available in AMD Zynq UltraScale+ MPSoC devices and development tools. The solution combines soft-error mitigation, redundancy, processor lockstep operation, and hardware isolation techniques to help developers address functional safety requirements and accelerate system development.
Safety-critical systems must continue to operate reliably even when hardware or software faults occur. Depending on the application, the system may need to meet defined Safety Integrity Levels (SIL) or Automotive Safety Integrity Levels (ASIL).
A functional safety architecture typically addresses:
Zynq UltraScale+ MPSoC devices provide several hardware and programmable-logic capabilities that can be combined to implement these mechanisms.
The UltraScale+ Soft Error Mitigation (SEM) IP helps detect and correct Single Event Upsets (SEUs) affecting the FPGA configuration memory.
SEUs can occur when environmental radiation causes a change in the configuration memory of an FPGA. In safety-critical systems, such errors need to be detected and managed to prevent them from affecting system operation.
The SEM solution continuously monitors the configuration memory and provides mechanisms for detecting and correcting correctable configuration errors. This provides an additional layer of protection for FPGA-based safety-critical designs.
Triple Modular Redundancy (TMR) is a fault-tolerance technique that uses multiple redundant processing elements to reduce the impact of individual faults.
The TMR MicroBlaze subsystem implements three redundant MicroBlaze processor instances along with associated memories, I/O, and critical logic. Their outputs are compared and majority voting is used to determine the valid result.
This architecture helps maintain system functionality when a soft error affects one of the redundant processing elements.
Xilinx MicroBlaze technology has been certified by SGS TÜV Saar for IEC 61508:2010 up to SIL 4 and ISO 26262:2011 up to ASIL D, providing a foundation for developing safety-oriented FPGA applications.
Safety-critical and non-safety functions may need to operate within the same device without interfering with each other.
The Isolation Design Flow (IDF) enables designers to separate safety-related functions from non-safety functions within the programmable logic. This approach can also help manage fault propagation when redundant functions are implemented on the same device.
The isolation methodology is integrated into the AMD/Xilinx Vivado design environment and provides a structured approach to developing isolated safety functions.
Zynq UltraScale+ MPSoC devices include dual Arm Cortex-R5 real-time processor cores that can operate in LockStep mode.
In this configuration, both processor cores execute the same instructions, allowing their operation to be compared for fault detection. If a discrepancy occurs between the cores, the system can identify a potential fault and initiate an appropriate response.
This dual-core redundancy makes Cortex-R5 LockStep suitable for applications requiring enhanced fault detection and real-time safety monitoring.
The Zynq UltraScale+ MPSoC RPU has been certified by exida against IEC 61508 requirements up to SIL 3 with HFT 1 and ISO 26262 requirements up to ASIL C.
Zynq UltraScale+ MPSoC integrates multiple processing subsystems, including the Application Processing Unit (APU), Real-Time Processing Unit (RPU), Platform Management Unit (PMU), Configuration Security Unit (CSU), and programmable-logic-based processing elements.
The Xilinx Memory Protection Unit (XMPU) and Xilinx Peripheral Protection Unit (XPPU) can be used to restrict access to protected memory regions and peripherals.
This allows safety-critical processing functions to be isolated from other processing domains, helping prevent unintended access and reducing the potential impact of faults.
iWave combines the functional safety capabilities of Zynq UltraScale+ MPSoC with its FPGA, embedded hardware, and software development expertise to provide application-ready safety solutions.
The solution includes:
These capabilities help developers reduce design complexity and accelerate the development of safety-critical embedded products.
The solution can be applied to embedded systems where reliability, fault tolerance, and safety are critical.
Key application areas include:
Functional Safety on Zynq UltraScale+ MPSoC combines hardware-based fault detection, redundancy, isolation, and real-time processing capabilities to address the requirements of safety-critical embedded systems.
With SEM, TMR, Cortex-R5 LockStep, Isolation Design Flow, XMPU, and XPPU capabilities, developers can create architectures designed to improve fault tolerance and system reliability.
iWave supports customers with Zynq UltraScale+ MPSoC-based System on Modules, SBCs, reference designs, FPGA development, embedded software, and customization services for safety-critical applications.
For more information, visit www.iwave-global.com or contact mktg@iwave-global.com
We appreciate you contacting iWave.
Our representative will get in touch with you soon!