PlatformsFaststream SiliconFaststream RadioFaststream VisionConnected EdgeFaststream SecureMobility & Rail
ProductsSemiconductor IPWireless & RANEdge & GatewaysTracking & IdentificationSoftware & FrameworksConnected Systems
TechnologyRTL to GDSIIVerification methodologyDFT and silicon testLow-power designMixed-signal integrationDesign enablement5G protocol stackWireless and RF architectureBaseband and low PHYForward error correctionControl and data planeHigh-speed interfacesFirmware and bootSilicon root of trustSoftware-defined vehicleAutomotive OTAFunctional safety
AIAI Engineering ServicesEdge AI & Embedded MLComputer Vision EngineeringSensor Fusion & PerceptionAI Silicon & AccelerationMLOps for DevicesAI Visual InspectionPredictive MaintenanceDriver MonitoringVideo Analytics & Safety
SolutionsSemiconductorIndustrial AIConnected ProductsAsset TrackingAutomotive & MobilitySmart InfrastructureSecure IdentityWireless & SatelliteSmart WashroomsFuel ManagementSmart BuildingsWorker SafetyEnergy MonitoringSmart AgricultureSmart CityAutonomous PlatformsAssembly AutomationLiDAR Rail SafetyHardware Wallet
IndustriesSemiconductorTelecommunicationsIndustrial & ManufacturingAutomotive & MobilityTransportation & RailAerospace & DefenceHealthcare & MedicalEnergy & UtilitiesOil & GasRetailConsumer ElectronicsMedia & EntertainmentSmart Infrastructure & IoT
ServicesSystem Integration overviewASIC & SoC DesignFPGA DesignFPGA-to-ASIC ConversionAnalog, Mixed-Signal & RFHardware & High-Speed PCBEmbedded SoftwareCloud, OTA & Device ManagementManufacturing TransitionHow we engage
InsightCase StudiesKnowledge CenterWhite PapersGlossaryNewsletterResources & Support
CompanyAbout FaststreamEngineering ExcellenceLeadership & OrganisationHow We EngageQuality & ComplianceStandards & EcosystemPartners & EcosystemTrust CentreLocations & DeliveryNewsroom & MediaCareers
ContactStart a projectHow we engage
Talk to an engineer
SAFETY

Functional Safety and Reliability

Functional safety is an argument, supported by evidence, that a system's residual risk is acceptable. The engineering is in the evidence: hazard analysis that genuinely constrains the design, diagnostic coverage that is measured rather than asserted, and a qualification programme sized to the service life the product will actually have.

ISO 26262ASILFMEDADiagnostic coverageQualification
How a safety argument is assembled
01Hazard analysisintegrity level02Safety goalstraced requirements03Decompositionwith independence04Safety mechanismsper failure mode05FMEDAdiagnostic coverage06Fault injectionverify the detectors07Qualificationenvironmental,standard08Safety manualassumptions of useA safe component used outside its stated assumptions is not safe.
THE ARGUMENT

How a safety case is assembled.

01

Hazard analysis and risk assessment

What can go wrong, how severely, how often, and how detectable. This produces the integrity level, and it has to influence the architecture rather than describe it after the fact.

02

Safety goals and requirements

Each hazard traced to a requirement, and each requirement traced to a design element and a verification activity. Traceability is the deliverable as much as the design is.

03

Architectural decomposition

Where a lower integrity level plus independence achieves the same goal as a higher one — legitimate and valuable, provided the independence is real and demonstrable.

04

Safety mechanisms

Error detection and correction, lockstep, watchdogs, redundant paths, plausibility checks, built-in self-test. Each chosen against a specific failure mode rather than added generically.

05

FMEDA

Failure modes, effects and diagnostic analysis: quantified failure rates and the fraction each mechanism actually detects. This is where diagnostic coverage becomes a number instead of a claim.

06

Verification and validation

Fault injection, fault campaign coverage, and verification of the safety mechanisms themselves — because an undetected failure in a detector is worse than not having one.

07

Qualification

Environmental, reliability and, where required, standard-specific qualification appropriate to the market and the service life.

08

Safety manual

What the integrator must do for the safety argument to hold in their system. A safe component used outside its assumptions is not safe.

STANDARDS

Which framework applies where.

Capability described here is engineering capability against these frameworks. Certifications held are confirmed at enquiry rather than claimed generically.

Functional safety and qualification frameworks
FrameworkDomainWhat it governs
ISO 26262AutomotiveFunctional safety lifecycle and ASIL integrity levels A to D
IEC 61508IndustrialFunctional safety and SIL integrity levels 1 to 4
AEC-Q100AutomotiveQualification of integrated circuits for automotive use
IEC 62304MedicalSoftware lifecycle for medical device software
DO-254 / DO-178CAirborneHardware and software design assurance
IEC 61511ProcessSafety instrumented systems in process industries
EN 50128 / 50129RailSoftware and system safety for railway applications
LONG LIFECYCLE

Reliability over a decade.

A product with a fifteen-year service life faces problems a consumer product never does. Components go end of life. Toolchains stop installing. The engineers who designed it leave. A vulnerability is discovered in a protocol stack that was current at design time.

So the reliability programme includes obsolescence monitoring rather than discovery at reorder, second sources qualified before they are needed, change control that keeps qualification valid through a substitution, archive discipline covering design data and toolchains, and a security maintenance path that remains defensible for the whole life — not just at launch.

None of this is glamorous, and all of it is cheaper designed in than retrofitted. A part that cannot be updated in year eight is a product that ends in year eight.

WHERE THIS APPLIES

Industries this serves.

COMMON QUESTIONS

What engineers ask about this.

01

What is ASIL decomposition?

Achieving a safety goal with elements of lower integrity level plus demonstrated independence, rather than requiring every element to meet the highest level. It is legitimate and valuable, provided the independence is real and can be shown rather than asserted.

02

What is FMEDA for?

Failure modes, effects and diagnostic analysis quantifies failure rates and the fraction each safety mechanism actually detects. It is what turns diagnostic coverage from a claim into a number that a safety case can rest on.

03

What is a safety manual?

The document telling an integrator what they must do for the safety argument to hold in their system — assumptions of use, required external measures and configuration constraints. A safe component used outside its assumptions is not safe.

04

Does Faststream hold safety certifications?

Capability is described here against these frameworks. Which certifications are currently held is confirmed at enquiry rather than claimed generically on a website, because certification status changes and an out-of-date claim is worse than none.

KEEP READING

Related work.

BUILD WITH FASTSTREAM

Bring us the difficult part.

Tell us the specification, the constraint and the deadline. Programmes that cross silicon, radio, embedded and AI are where Faststream is strongest.