Skip to main content
arthiJan
Associate
November 13, 2018
Solved

Code Isolation for Functional Safety

  • November 13, 2018
  • 18 replies
  • 4961 views

HI,

  I am considering the use of STM32F0 device for my project. How do I isolate the safety related code(for functional safety)  from the general code, so that a f/w update on the general code doesn't affect the safety related code? Are there any hardware provisions on the STM32 devices to help me isolate these sections? Or are there any software means to isolate the two?

This topic has been closed for replies.
Best answer by Chris1

The concept is that the MPU is configured to allow your safety-related code to access the RAM and peripherals that it needs and other code is not permitted to access those resources.  

This makes a strong argument that the non-safety code is independent from (and cannot affect) the safety-related code.

Access to flash memory could also be controlled, but if your application treats flash as read-only memory, that would probably not be very beneficial.  

Ideally, an RTOS manages the MPU, changing the accessible regions when switching tasks (FreeRTOS and SafeRTOS have that ability, among others).

18 replies

Tesla DeLorean
Guru
November 13, 2018

Look in the reference and data manuals and check the granularity of the flash write protection afforded.

Review the ARM Cortex-M0 manuals to understand it's capabilities and protections.

Tips, Buy me a coffee, or three.. PayPal Venmo (See Profile) Up vote any posts that you find helpful, it shows what's working..
Chris1
Associate II
November 13, 2018

Consider using a device that has an MPU (Memory Protection Unit) such as one of the STM32L4 or perhaps L5 families. The MPU allows you to restrict access to various regions of memory.

AvaTar
Senior III
November 14, 2018

I agree. That's the way we did it usually (on Infineon and Cypress M3/M4 MCUs, though).

Pavel A.
November 13, 2018

Take ​two F0s. One for general code, another for safety stuff :)

-- pa

arthiJan
arthiJanAuthor
Associate
November 14, 2018

​Thanks. I am going to have to go that route, if I don't find a decent solution. I am trying to stick to one microcontroller, because of cost and real estate.