Skip to main content
The AURIX Toolchain Ecosystem in India: TESSY + SafeTpack + UAD3+/UDE for Complete Development, featured image

The AURIX Toolchain Ecosystem in India: TESSY + SafeTpack + UAD3+/UDE for Complete Development

GSAS Engineering · · 5 min read

The AURIX Toolchain Ecosystem in India: TESSY + SafeTpack + UAD3+/UDE for Complete Development

Infineon’s AURIX TC3xx is the dominant microcontroller platform for safety-critical automotive electronics in India. Powertrain ECUs, electric vehicle battery management systems, ADAS domain controllers, steering assist modules, and braking systems, across OEMs and Tier-1 suppliers in Bengaluru, Pune, and Chennai, the AURIX is the silicon at the center of the design.

But the silicon is only the foundation. Building a safety-certified product on AURIX requires a development toolchain that covers three distinct engineering disciplines: dynamic testing with structural code coverage, hardware safety self-test, and multi-core debug with deep trace capture. Each discipline has its own standards requirements, its own workflow, and its own failure modes.

Hitex, as an Infineon AURIX Preferred Design House, provides tools that address all three: TESSY for automated unit and integration testing, SafeTpack for ISO 26262-certified safety self-test libraries, and UAD3+ with UDE for multi-core debug and trace. Together, they form a coherent AURIX development ecosystem where the tools are designed to work with the same silicon, the same safety standards, and the same engineering workflows.

TESSY: Verification at the Unit Level

ISO 26262 Part 6 requires structural coverage measurement at the unit level. For ASIL C and D, the required metric is MC/DC (Modified Condition/Decision Coverage). Achieving MC/DC on embedded C code running on AURIX TriCore requires a testing tool that understands the target compiler’s calling conventions, memory layout, and optimization behavior.

TESSY automates the unit testing workflow: interface analysis, test driver generation, stub creation, test execution, and coverage measurement. It compiles test harnesses against the same toolchain used for the production build (HighTec, TASKING, or GCC for TriCore), ensuring that coverage results reflect the actual compiled code, not a host-compiled approximation.

For AURIX projects, TESSY’s ability to run tests on the actual target hardware (via a debug connection) or on a host simulation is particularly valuable. Early in development, when hardware is scarce, host-based testing provides rapid feedback. Later, target-based testing validates the code against the real silicon, including hardware-dependent behavior like register access patterns and interrupt timing.

The Classification Tree Editor provides systematic test design that satisfies ISO 26262 Part 6 Table 10, while ReqIF import/export connects TESSY to the requirements management tool (IBM DOORS, Polarion, codebeamer) for the bidirectional traceability that assessors expect.

SafeTpack: Hardware Diagnostic Coverage

While TESSY verifies that the software is correct, SafeTpack verifies that the hardware is healthy. ISO 26262 Part 5 requires diagnostic mechanisms that detect single-point faults and latent faults in the processing unit, memory, clock system, and peripherals. For ASIL D, the diagnostic coverage targets are demanding: 99% for single-point faults, 90% for latent faults.

SafeTpack provides the runtime safety mechanisms to meet these targets on AURIX TC2xx and TC3xx: LBIST management for CPU logic verification at startup, program flow monitoring for execution path integrity during runtime, SFR cyclic control for register corruption detection, and comprehensive startup and runtime diagnostic tests for RAM, flash, clock, and peripherals.

The library ships as source code with Elektrobit tresos plugins for AUTOSAR integration, or it integrates directly into bare-metal and RTOS-based architectures. Certified to ISO 26262 ASIL A through ASIL D, SafeTpack comes with a pre-certified safety case that reduces the qualification effort from months to weeks.

The relationship between TESSY and SafeTpack is complementary: TESSY tests the application software for functional correctness, while SafeTpack monitors the underlying hardware for integrity. Both are needed for a complete safety case. An application that passes all unit tests but runs on corrupted hardware is not safe. Hardware that passes all self-tests but executes incorrect software is equally unsafe.

UAD3+ and UDE: Debug and Trace for Multi-Core AURIX

The AURIX TC3xx family includes devices with up to six TriCore CPUs. Debugging multi-core TriCore requires a probe that can access all cores simultaneously, capture deep execution traces at full target speed, and present the results in a way that makes cross-core interactions visible.

The UAD3+ provides this capability: simultaneous debug of up to 8 cores, 4 GB of onboard trace memory, and 500 MHz / 3.125 Gbit/s serial trace bandwidth via the Aurora interface. Paired with UDE (Universal Debug Engine), the UAD3+ provides synchronized start/stop across all TriCore CPUs, per-core breakpoints, cross-core memory inspection, and RTOS-aware task views for AUTOSAR OS, FreeRTOS, PXROS, and SafeRTOS.

For AURIX-based ECU development, the deep trace buffer is not a luxury, it is a debugging necessity. Timing-dependent bugs in multi-core systems often manifest only under specific load conditions. Capturing seconds of continuous execution trace means engineers can reproduce the bug once and analyze it offline, rather than repeatedly triggering a transient fault while hoping the shallow trace buffer was recording at the right moment.

UDE also supports in-system flash programming (PFLASH, DFLASH, and external QSPI flash) and scripted test automation via command line, enabling automated regression testing from CI/CD pipelines.

The Integration Advantage

Using TESSY, SafeTpack, and UAD3+/UDE from a single vendor ecosystem provides practical benefits beyond individual tool capabilities:

Consistent AURIX expertise. Hitex, as an Infineon Preferred Design House, designs all three tools with deep knowledge of the AURIX architecture, TriCore instruction set, MCDS trace system, safety management unit, and peripheral register models. The tools are validated against the same silicon errata and safety manual revisions.

Unified safety qualification. Each tool comes with an ISO 26262 Tool Qualification Support Package. Using tools from the same vendor simplifies the qualification narrative: the assessor reviews a coherent toolchain rather than a patchwork of independently qualified tools from different vendors with different qualification methodologies.

Workflow coherence. TESSY test results feed into the safety case alongside SafeTpack diagnostic coverage evidence. UAD3+/UDE trace data supports both functional debugging and safety analysis (verifying that program flow monitoring detects injected faults, for example). The tools share a common understanding of the AURIX memory map, register definitions, and debug infrastructure.

Building the Ecosystem in India

Indian automotive teams building AURIX-based ECUs face a specific challenge: sourcing, licensing, and integrating tools from European vendors through local channels with INR invoicing and responsive technical support. Global procurement cycles that take weeks in Germany can take months when routed through indirect channels in India.

GSAS Micro Systems addresses this directly. As India’s authorized Hitex partner, GSAS provides the complete Hitex tool portfolio, TESSY, SafeTpack, UAD3+, and UDE, with INR invoicing, local procurement, and application engineering from safety engineers based in Bengaluru, Hyderabad, Chennai, Pune, Mumbai, and Delhi NCR.

Our team helps with the full deployment lifecycle: initial tool evaluation on your AURIX target, CI/CD pipeline integration for TESSY, SafeTpack integration into your BSP, UDE/UAD3+ debug environment setup, and ongoing technical support as your project moves from development through safety assessment to production release.

Whether you are starting a new AURIX-based ECU project or strengthening the toolchain on an existing one, GSAS provides a single point of contact for the complete Hitex ecosystem in India.

Request a Hitex toolchain evaluation →

Interested in Hitex tools?

Talk to our application engineers for personalized tool recommendations.

Stay in the Loop

Get monthly compliance updates, product insights, and engineering best practices delivered to your inbox.