SFFS779 December 2024 TMS320F28P550SJ
The standardized E-GAS monitoring concept [6] for engine management systems, generated by the German VDA working group E-Gas-Arbeitskreis, is an example of a well-trusted safety-architecture that can be used for applications other than engine management systems, provided the architecture fits the purpose of the new application in terms of diagnosis feasibility, environment constraints, time constraints, robustness, and so forth [7]. For more information, see Figure 4-4.
The TMS320F28P55x MCU device family supports heterogeneous asymmetric architecture and the functional safety features of the device lend to an E-GAS concept implementation at system-level, as indicated in Figure 4-5. In the first level (Level 1), the functions required for the system mission are computed. Second level (Level 2) checks the correct formation in first level based on a selected set of parameters. Third level (Level 3) implements an additional external monitoring element for correctly carrying out the mission in the first level and monitoring in the second level. The exact functional safety implementation and the modules used for realizing Level 1, Level 2, and the external monitoring device for realizing Level 3 are left to the system designer. Though Figure 4-5 indicates CLA implementing Level 1 and CPU(28x) implementing Level 2 of the EGAS monitoring concept, both processing units are capable of implementing either Level 1 or Level 2. The application can determine the partitioning based on the system requirements.