Functional safety and security fundamentals of the Infineon TC387QP on KCU GEN2
Infineon classifies the AURIX TC387QP as ISO 26262-compliant with ASIL-D/SIL-3 support. This article explains how KCU GEN2 can use its lockstep, ECC, and security hardware; component capability does not certify the complete controller as ASIL-D.
Quick Facts
Summary
Infineon AURIX TC387QP is the main processor used in selected KCU GEN2 hardware variants. Infineon’s published product data lists four 300 MHz TriCore cores, including two lockstep cores, and classifies the component as ISO 26262-compliant with ASIL-D/SIL-3 support.
These are MCU component capabilities. They do not certify KCU GEN2, a customer ECU, or a vehicle system as ASIL-D. Final system ASIL depends on the Item Definition, HARA, Safety Goals, hardware and software safety architecture, verification results, and the Safety Case.
Component capability versus system responsibility
| Level | Supported statement | What cannot be inferred |
|---|---|---|
| MCU component | Infineon’s published ISO 26262 classification, ASIL-D/SIL-3 support, lockstep, and memory-protection capabilities. | That KCU GEN2 is an ASIL-D-certified controller. |
| Controller platform | The MCU mechanisms can support monitoring, fault response, partitioning, and diagnostics. | That every hardware revision or software configuration has the same safety integrity. |
| Customer system | Engineering, analysis, integration, and verification can follow project Safety Goals. | Product certification without HARA, verification evidence, and a Safety Case. |
Key TC387QP hardware capabilities
- Processing cores: Four 300 MHz TriCore cores; Infineon’s product data lists two lockstep cores.
- Functional-safety mechanisms: Lockstep, ECC, memory protection, monitoring, and watchdog mechanisms can form part of a safety architecture.
- Security hardware: Can support protected key storage, cryptographic services, and a secure-boot architecture; the exact capability depends on the derivative, licensed software, and project configuration.
- Memory: Infineon lists 10 MB of program memory and 1,376 KB of SRAM, including cache.
- Automotive communications: The MCU provides CAN, LIN, and other automotive peripherals; the interfaces exposed by a KCU depend on the hardware revision and schematic.
Applying the MCU in a KCU GEN2 program
The TC387QP mechanisms can support the following engineering activities, but each item must be designed and verified under the project’s safety plan:
- Run safety-related monitoring or control functions on lockstep cores.
- Isolate safety-related and QM functions with the MPU, OS Applications, and access-control configuration.
- Build fault-detection and reaction strategies around ECC, watchdogs, and clock or voltage monitors.
- Use security hardware for secure boot, key management, SecOC, or ISO 15118 PnC.
- Trace diagnostic events, fault reactions, degraded modes, and test evidence to safety requirements.
Required project inputs
| Input | Purpose |
|---|---|
| Item Definition and HARA | Derive Safety Goals and ASIL without assuming ASIL-D in advance. |
| Technical Safety Concept | Define hardware and software safety mechanisms, fault-tolerant time intervals, and safe states. |
| MCU Safety Manual and integration constraints | Confirm manufacturer assumptions, diagnostic coverage, startup tests, and conditions of use. |
| Software partition and resource plan | Define core, memory, peripheral, timing, and permission boundaries. |
| Verification plan and Safety Case | Connect safety requirements, implementation, tests, and residual risk with auditable evidence. |
| Cybersecurity Concept | Use TARA to define assets, threats, key lifecycle, and secure-update requirements. |
KopherBit support scope
Under a project contract and safety plan, KopherBit can provide KCU GEN2 platform integration, AUTOSAR Classic software, bootloader, diagnostics, and functional-safety engineering support. Potential work products include safety requirements, partition design, safety mechanisms, verification specifications, and traceability data. The actual delivery scope is agreed at project kickoff.
FAQ
Does the TC387QP support ISO 26262 ASIL-D?
Infineon’s public product data classifies the TC387QP as ISO 26262-compliant and lists ASIL-D/SIL-3 support. This is an MCU component capability; selecting the device does not automatically make KCU GEN2 or the vehicle system an ASIL-D-certified product.
Does lockstep make an application safe by itself?
No. Lockstep can help detect certain processor faults, but it must be combined with the Safety Manual, defined fault reactions, independent monitoring, appropriate software design, test coverage, and system-level verification.
How does security hardware differ from a software cryptography library?
Security hardware can provide clearer key isolation, hardware acceleration, and a root of trust. Actual security still depends on the key lifecycle, access control, boot chain, update process, and the overall threat analysis.
How much boot time does secure boot add?
The impact depends on image size, signature algorithm, hardware acceleration, storage interface, and verification strategy. It should be measured on the target hardware rather than promised as a fixed number.
Is the TC387QP suitable for AUTOSAR Adaptive?
The TC387QP is primarily used for AUTOSAR Classic-style real-time control. Programs that require a POSIX, Linux, or QNX Adaptive platform typically evaluate a higher-performance SoC and integrate it with Classic ECUs over interfaces such as SOME/IP.
Manufacturer sources
Need a production VCU platform?
Explore KopherBit Vehicle Control Unit platforms and engineering services for commercial EV programs.