SFFSAY3 January 2026 F29H850TU , F29H859TU-Q1 , TMCS1123 , TMCS1123-Q1 , TPS650362-Q1 , TPS650365-Q1
After the FuSa goal has been established, the next phase is to develop the FSC. The system block diagram is shown in Figure 2-5, which is one level deeper than the block diagram in item definition. The objective is to define sub-functional elements and interconnections on preliminary architecture diagrams.
Figure 2-5 FSR Level System Block
DiagramTo simplify the analysis, SG2 is chosen as an example. Figure 2-6 is the one level deeper block diagram related to SG2, and related sub-functional elements and interactions are defined in Table 2-9.
Figure 2-6 FSR Level System Block Diagram
of SG2| Element ID | Element Name | Description |
|---|---|---|
| E1 | DC output current measurement circuit | Measure the OBC output current for both constant current control and overcurrent protection. |
| E2 | AC input current measurement circuit | Measure the OBC input current for AC current control and overcurrent protection. |
| E3 | Microcontroller circuit | Executes the charger control algorithm, monitors sensor data, generates PWM signals, and communicates with the vehicle’s BMS/VCU. |
| E4 | Gate driver circuit | Provide the required voltage and high‑current drive signals of the power switches. |
| E5 | TPLD circuit | Programmable logic device that features power switches switching off sequence with combinational logic. |
| E6 | CAN transceiver circuit | Exchange status and diagnostic information with the BMS/VCU. |
| E7 | PMIC circuit | Provide the power supply to key devices and voltage monitoring for key voltage rails. This also provides an external watchdog and error pin monitor for MCU. |
| E8 | Temperature measurement circuit | Monitors the power switches junction temperature, transformer temperature and the ambient temperature of the converter. |
FTA is performed to generate FSRs of SG2. FTA analysis is structured by three steps. The first step is to create the fault tree with SG2 violation as top event, then the second step is to derive each potential malfunction of the defined sub-functional element that leads to top events occur, then the third step is to use logic gates to represent the relationships between events.
Following the above steps, the FTA tree is illustrated in Figure 2-7. Critical failure paths must be identified for cut set analysis. If SPF directly violates the FuSa goal, FSR must be designed; if SPF does not directly violate the FuSa goal, it is necessary to determine whether the dual-point failure system is acceptable and to analyze the independence of dual-point failures.
For the FTA analysis of the SG, in FSR level it can be terminated at the component, while more detailed analysis must be carried out at the TSR level. As shown in Figure 2-7, If there is abnormal current sensing, or a control malfunction, or a power supply issue, SG2 is violated. Then it can be broken down into different components.
Figure 2-7 The FTA Tree Example of
SG2Cut set is a logical analysis to determine sets of combinations of gate/events which causes the top gate condition to fail.
Each FSR must be assigned to the logical block that is responsible for the implementation. Where an FSR spans more than one block, all relevant subsystems must be listed. Table 2-10 lists the concise set of FSRs that underpin the goal Avoid vehicle fire due to DC bus overcurrent.
| SG2: Avoid vehicle fire due to DC bus overcurrent. | |||||
|---|---|---|---|---|---|
| ID | FSR | Safe state | Allocation | ASIL | Traced to |
| FSR 2.1 | DC‑bus current sensing system shall perform accurate current measurement. | Assert the OC flag to MCU. | E1 and SW | B | GT4 |
| FSR 2.2 | TCAN shall perform correct communication between OBC and VCU. | Transmit OC status to VCU. | E6 and SW | B | GT6 |
| FSR 2.3 | MCU shall perform correct control scheme. | Switch to emergency operation mode. | E3 and SW | B | GT7 |
| FSR 2.4 | Gate drivers shall drive the power switches correctly. | Disable power switches. | E4 | B | GT8 |
| FSR 2.5 | Bias supply shall provide reliable voltage to key components. | Provide reliable voltage rail. | E7 | B | GT3 |