This page was machine-translated and may differ from the original. View original
"Functional safety is now an essential step in automotive semiconductor development"
Level 3 autonomous driving requires 2,000 semiconductors per vehicle
Automotive industry must comply with ISO 26262
Safety verification process added to vehicle semiconductor manufacturing
The automotive semiconductor market size continues to grow. According to market research firm IHS, the automotive semiconductor market size in 2018 was a total of 32.3 billion dollars, or about 39 trillion won in our currency. This is an increase of about 18.5% from 27.2 billion dollars in 2017.
The automotive semiconductor market is expected to grow at an average annual rate of 12.5% for the five years until 2021, reaching a market size of approximately $58.5 billion in 2023. In addition, the average growth rate of the automotive semiconductor market is expected to be more than twice that of the overall semiconductor market (6.1%).
According to the Korea Industrial Technology Assessment and Management Institute, by 2022, when autonomous vehicles at level 3 or higher are fully commercialized, a single vehicle will require about 2,000 semiconductors. This is a seven-fold increase from 2010, when there were about 300 semiconductors.
Most of the functions of automotive semiconductors are related to operation and safety. In addition, the perfection and safety of automotive electrical components are directly related to the safety of drivers and pedestrians. ISO 26262, also known as the automotive functional safety international standard, is an automotive functional safety international standard established by ISO to prevent accidents caused by errors in electrical and electronic systems installed in automobiles.
ISO 26262 defines the process model, required activities, tangible and intangible evidence, and methods used in development and production, and is a standard that everyone, from semiconductor companies to automobile manufacturers, must follow. To comply, automakers are requiring automotive semiconductors installed in their vehicles to have a certain level of certification.

Automotive semiconductor developers must now go through an additional development process called 'Safety Verification' in addition to 'Functional Verification'. We met with Kim Jae-yoon, Manager of Mentor and Siemens Business, and asked him about safety verification that must be kept in mind when developing automotive semiconductors.
Q. In order to manufacture automotive semiconductors, you must comply with ISO26262. What are the difficulties that automotive semiconductor manufacturers face in this process?
A. For those working in companies that develop automotive semiconductors, the functional verification field is very familiar. However, the safety verification field is a completely new field and is different from the existing functional verification. There are major difficulties in the unfamiliarity of the new field and the time required to achieve the time to market.
Q. Then, what are the characteristics of safety verification that are different from functional verification?
A. ISO 26262, which was established as a standard for safety verification or functional safety, divides failures that may occur in a system into two types. There are two types of faults: systematic fault and random fault.
Systematic faults refer to errors such as incomplete specifications, insufficient inputs, or mistakes made during the design implementation process. The goal of the traditional functional verification phase is to discover these failures and implement the design functionally perfectly.
On the other hand, random faults refer to defects that can occur within a design due to external factors such as EMI, temperature, etc. In the field of safety verification, the focus is on how much safety of a design can be secured due to external factors.
Q. How are the safety levels of automotive semiconductors divided? Also, should functional safety according to the safety level be provided independently for each chip?
A. Automotive semiconductors are managed by assigning a grade called ASIL. ASIL stands for 'Automotive Safety Integration Level' and ranges from A to D. ASIL D is the grade required for chips that must ensure the highest level of safety. As the grade increases, the effort and difficulty required to implement the design doubles.
ISO 26262 proposes a methodology called ASIL decomposition as a way to achieve a certain level of ASIL rating. Even if the rating required for a specific chip is ASIL D, it allows the safety-critical parts to be distributed to other chips with the same safety goal through a kind of partitioning, thereby lowering the ASIL rating required for a specific chip and allowing room to achieve it quickly.
Q. Once the safety mechanism of the automotive semiconductor is fully functionally verified, random hardware tests are performed. It is impossible to test for all defects, so what are your ideas on this?
A. It is impossible to comprehensively test for all possible faults, errors, etc.
Design stability verification is conducted in the form of a fault campaign. This fault campaign is a form of modeling failures or faults that may occur due to external influences and verifying how the design behaves when such failures actually occur in the design.
A technique called fault injection is used to inject faults into the design and observe the response. Basically, fault injection is performed on all nets and ports in the design.
However, in the case of SoC-level chip design, there are hundreds of millions of nets and ports. It is almost impossible to conduct a fault campaign on all of these. However, the important thing here is that the parts that need to be verified for safety through fault injection are parts that are directly related to safety.
Mentor provides optimization techniques for safety-related fault lists. It provides a lot of support to optimize and minimize faults that can really affect safety, so that you can meet the delivery deadline within the desired time.
Q. Does Mentor have a unique methodology that accelerates functional safety verification of automotive semiconductors?
A. The mentor proposes a methodology called closed loop. Typically, safety verification goes through three stages: ‘safety analysis → safety design → safety verification.’
Among these, the part that takes the most time and effort is safety verification. It is no exaggeration to say that most of the development time is spent here. If any design problems occur during the safety verification process, the safety analysis stage must be returned to and the loop must be repeated from the beginning to the end.
Ironically, safety verification, which is the last step, takes the most time, which inevitably increases the time to market exponentially. Mentor provides a way to measure the level of safety expected from the design, starting from the safety analysis stage.
Q. What is the Mentor Safe IC solution? And for which engineer roles is it particularly useful?
A. Mentor Safe IC is a brand that brings together all of Mentor’s solutions that can be used for functional safety. I can say that it is a useful solution for everyone who is interested in functional safety, who is planning, safety managers who are in charge of overall safety-related projects, designers who actually reinforce the design, and verification engineers who perform safety verification in addition to functional verification.
Automotive industry must comply with ISO 26262
Safety verification process added to vehicle semiconductor manufacturing
The automotive semiconductor market size continues to grow. According to market research firm IHS, the automotive semiconductor market size in 2018 was a total of 32.3 billion dollars, or about 39 trillion won in our currency. This is an increase of about 18.5% from 27.2 billion dollars in 2017.
The automotive semiconductor market is expected to grow at an average annual rate of 12.5% for the five years until 2021, reaching a market size of approximately $58.5 billion in 2023. In addition, the average growth rate of the automotive semiconductor market is expected to be more than twice that of the overall semiconductor market (6.1%).
According to the Korea Industrial Technology Assessment and Management Institute, by 2022, when autonomous vehicles at level 3 or higher are fully commercialized, a single vehicle will require about 2,000 semiconductors. This is a seven-fold increase from 2010, when there were about 300 semiconductors.
Most of the functions of automotive semiconductors are related to operation and safety. In addition, the perfection and safety of automotive electrical components are directly related to the safety of drivers and pedestrians. ISO 26262, also known as the automotive functional safety international standard, is an automotive functional safety international standard established by ISO to prevent accidents caused by errors in electrical and electronic systems installed in automobiles.
ISO 26262 defines the process model, required activities, tangible and intangible evidence, and methods used in development and production, and is a standard that everyone, from semiconductor companies to automobile manufacturers, must follow. To comply, automakers are requiring automotive semiconductors installed in their vehicles to have a certain level of certification.
▲ Mentor, Siemens Business Manager Kim Jae-yoon [Photo = Reporter Lee Su-min]
Automotive semiconductor developers must now go through an additional development process called 'Safety Verification' in addition to 'Functional Verification'. We met with Kim Jae-yoon, Manager of Mentor and Siemens Business, and asked him about safety verification that must be kept in mind when developing automotive semiconductors.
Q. In order to manufacture automotive semiconductors, you must comply with ISO26262. What are the difficulties that automotive semiconductor manufacturers face in this process?
A. For those working in companies that develop automotive semiconductors, the functional verification field is very familiar. However, the safety verification field is a completely new field and is different from the existing functional verification. There are major difficulties in the unfamiliarity of the new field and the time required to achieve the time to market.
Q. Then, what are the characteristics of safety verification that are different from functional verification?
A. ISO 26262, which was established as a standard for safety verification or functional safety, divides failures that may occur in a system into two types. There are two types of faults: systematic fault and random fault.
Systematic faults refer to errors such as incomplete specifications, insufficient inputs, or mistakes made during the design implementation process. The goal of the traditional functional verification phase is to discover these failures and implement the design functionally perfectly.
On the other hand, random faults refer to defects that can occur within a design due to external factors such as EMI, temperature, etc. In the field of safety verification, the focus is on how much safety of a design can be secured due to external factors.
Q. How are the safety levels of automotive semiconductors divided? Also, should functional safety according to the safety level be provided independently for each chip?
A. Automotive semiconductors are managed by assigning a grade called ASIL. ASIL stands for 'Automotive Safety Integration Level' and ranges from A to D. ASIL D is the grade required for chips that must ensure the highest level of safety. As the grade increases, the effort and difficulty required to implement the design doubles.
ISO 26262 proposes a methodology called ASIL decomposition as a way to achieve a certain level of ASIL rating. Even if the rating required for a specific chip is ASIL D, it allows the safety-critical parts to be distributed to other chips with the same safety goal through a kind of partitioning, thereby lowering the ASIL rating required for a specific chip and allowing room to achieve it quickly.
Q. Once the safety mechanism of the automotive semiconductor is fully functionally verified, random hardware tests are performed. It is impossible to test for all defects, so what are your ideas on this?
A. It is impossible to comprehensively test for all possible faults, errors, etc.
Design stability verification is conducted in the form of a fault campaign. This fault campaign is a form of modeling failures or faults that may occur due to external influences and verifying how the design behaves when such failures actually occur in the design.
A technique called fault injection is used to inject faults into the design and observe the response. Basically, fault injection is performed on all nets and ports in the design.
However, in the case of SoC-level chip design, there are hundreds of millions of nets and ports. It is almost impossible to conduct a fault campaign on all of these. However, the important thing here is that the parts that need to be verified for safety through fault injection are parts that are directly related to safety.
Mentor provides optimization techniques for safety-related fault lists. It provides a lot of support to optimize and minimize faults that can really affect safety, so that you can meet the delivery deadline within the desired time.
Q. Does Mentor have a unique methodology that accelerates functional safety verification of automotive semiconductors?
A. The mentor proposes a methodology called closed loop. Typically, safety verification goes through three stages: ‘safety analysis → safety design → safety verification.’
Among these, the part that takes the most time and effort is safety verification. It is no exaggeration to say that most of the development time is spent here. If any design problems occur during the safety verification process, the safety analysis stage must be returned to and the loop must be repeated from the beginning to the end.
Ironically, safety verification, which is the last step, takes the most time, which inevitably increases the time to market exponentially. Mentor provides a way to measure the level of safety expected from the design, starting from the safety analysis stage.
Q. What is the Mentor Safe IC solution? And for which engineer roles is it particularly useful?
A. Mentor Safe IC is a brand that brings together all of Mentor’s solutions that can be used for functional safety. I can say that it is a useful solution for everyone who is interested in functional safety, who is planning, safety managers who are in charge of overall safety-related projects, designers who actually reinforce the design, and verification engineers who perform safety verification in addition to functional verification.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













