Forum Discussion
Altera_Forum
Honored Contributor
16 years agoYou're assumptions about processor failure mechanisms won't convince a safety auditor, I think. You can also imagine many kinds of failure that are undetectable by a watchdog circuit.
But I assume, that hardware redundancy (using separate FPGAs) is necessary, if the device operation can't be supervized otherwise.