摘要

IEC 61508-2010 puts special limits on the on-chip redundancy of one single chip, for example the safety integrity level (SIL) is limited up to SIL 3. About this, however, there are no specific explanations. Based on the safety-critical system of on-chip redundancy for a typical programmable logic device (FPGA), this paper proves that the highest SIL is 3; analyses the factors that may impact the safety integrity of redundancy system, and furthermore, provides reasonable solutions. The results show that the use of 1oo2 channel redundancy scheme can effectively improve the safety integrity level of the on-chip redundancy.

全文