Electronic Components Datasheet Search |
|
AN4266 Datasheet(PDF) 10 Page - STMicroelectronics |
|
AN4266 Datasheet(HTML) 10 Page - STMicroelectronics |
10 / 76 page General information AN4266 10/76 Doc ID 024283 Rev 2 Defining these states as safe for the MCU means that the overall system must react safely to the SPC56xL70xx being in, and entering, any of these states. For the ‘Completely unpowered’ and ‘Reset’ states the addition of a pullup or pulldown resistor on relevant signals may be necessary. If an ‘Explicit indication of internal error’ occurs on FCCU_F[0:1], the application must not depend on the MCU for continued operation. This also means that the system must be able to remain in a safe state without any additional actions from the MCU. Mandatory: The system must transition to a safe state when there is an indication of an error. Depending on the configuration the system may disable, or reset, the SPC56xL70xx as a reaction to the error signal. If a system continuously switches between a standard operating state and the reset state, without any device shutdown, the system is not considered to be in a Safe state. Mandatory: The application must identify and signal such switching as a failure condition. 2.3 Failure indication time The SPC56xL70xx failure indication time must be taken into consideration when determining application safety strategies, because it must be less than the FTTI. Failure indication time has three components, two of which are influenced by configuration settings: recognition time + internal processing time + indication time. Each component of failure indication time is described as follows: ● Recognition time is the maximum of the recognition time of all involved safety mechanisms. The three mechanisms with the longest time are: –ADC(a) recognition time is the most demanding HW test in terms of timing. The self-test requires the ADC conversion to complete a full test. A single full test takes at least 70 µs(b). – Recognition time related to the FMPLL loss of clock: it depends on how the FMPLL is configured, but is approximately 20 µs. – Diagnostic cycle time of software self-tests. This time depends closely on the software implementation. ● Internal processing time lasts maximum 10 RC clock cycles (RC is the internal safe clock with nominal frequency of 16 MHz). ● Indication time, the time to notify an observer about the failure, depends on indication protocol configured in the Fault Collection and Control Unit (FCCU): – Dual Rail protocol and time switching protocol: FCCU configured as “fast switching mode”: indication delay is maximum 64 µs. As soon as FCCU receives a fault signal, FCCU reports the failure to the outside world via output pin (if properly configured). 0 = FCCU configured as “slow switching mode”: an indication delay could occur. The maximum delay is equal to period of the error out signal. This parameter shall be configured equal to its minimum which is 128 µs. a. ADC recognition time shall be used only if ADC is used by the safety function. b. This value takes into account the steps needed to run the three ADC hardware self-tests. |
Similar Part No. - AN4266 |
|
Similar Description - AN4266 |
|
|
Link URL |
Privacy Policy |
ALLDATASHEET.COM |
Does ALLDATASHEET help your business so far? [ DONATE ] |
About Alldatasheet | Advertisement | Datasheet Upload | Contact us | Privacy Policy | Link Exchange | Manufacturer List All Rights Reserved©Alldatasheet.com |
Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
Family Site : ic2ic.com |
icmetro.com |