Reset abnormality monitoring device, method, chip and circuit

By introducing an on-chip system-level reset monitoring module into the smart chip, dynamically monitoring reset requests and directly performing a system-level power-on reset when an exception occurs, the problem that traditional monitoring methods cannot adapt to reset management in different scenarios is solved, thereby improving the reliability and security of the chip.

CN120578560BActive Publication Date: 2025-09-26江苏云途半导体有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511080815.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-09-26
Estimated Expiration
2045-08-04

AI Technical Summary

Technical Problem

In the existing technology, smart chips have difficulty adapting to the differentiated needs of different application scenarios when facing reset management, resulting in abnormal reset requests not being processed in a timely manner, causing cascading failures or failure of safety mechanisms, and traditional monitoring methods are unable to finely analyze reset request anomalies.

Method used

An on-chip system-level reset monitoring module is introduced to dynamically monitor reset requests through a counter and pre-scaling module. Configuration information is distributed in a one-to-one or non-one-to-one manner. A system-level power-on reset is performed directly after an anomaly is detected, bypassing the reset management module to ensure that the system is restored to a safe state.

Benefits of technology

It implements dynamic monitoring of reset requests and exception handling, improves chip reliability and security, adapts to high-security requirements in different scenarios, avoids dead loops and cascading failures, and ensures rapid system recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120578560B_ABST
    Figure CN120578560B_ABST
Patent Text Reader

Abstract

The present invention relates to a reset anomaly monitoring device, method, chip, and circuit, comprising: a system-on-chip (SoC) determining configuration information based on the number of occurrences and the number of exception requests, as well as changes thereto; updating the configuration information and writing it into a register configuration module when the configuration information changes; and a reset monitoring module monitoring reset requests from various on-chip submodules of the SoC based on the updated configuration information. The present invention utilizes the computing resources of the SoC to analyze SoC-level reset signal anomaly data, dynamically monitoring the reset status and request anomalies of each reset source, and, upon detecting an anomaly, bypassing the reset management module to directly initiate a system-level power-on reset, returning the entire system-level reset signal to a power-on initialization state, thereby restoring the system to a safe state and enabling normal operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of smart chips, and in particular relates to a reset abnormality monitoring device, method, chip and circuit. Background Art

[0002] With the rapid development of the Internet of Things, artificial intelligence, and 5G technologies, modern chip design is undergoing a fundamental shift from simple computing units to intelligent terminals. In traditional chip architectures, functional modules typically utilize fixed logic circuits and static resource allocations, making them difficult to adapt to the dynamic demands of changing application scenarios. The new generation of intelligent chips achieves breakthroughs through three key technological innovations: first, the integration of reconfigurable computing arrays at the hardware level, allowing for dynamic adjustment of computing resource allocation based on workload; second, the introduction of embedded neural network accelerators, enabling localized machine learning capabilities; and finally, on-chip sensor networks enabling real-time self-awareness of operating status. This architectural shift enables a single chip to autonomously complete a closed-loop process from environmental perception to decision execution. A typical example is the on-chip fault prediction system in Tesla's Dojo chip, which reduces error detection latency from milliseconds to microseconds. The security protection system of intelligent chips demonstrates a depth of defense. By embedding monitoring units in critical paths such as memory controllers and bus arbiters, a protection network covering the entire data access, transmission, and processing process is constructed. Precise responses are achieved, using online machine learning algorithms to analyze abnormal patterns. This intelligent trend is driving reset management systems from passive response to proactive prevention.

[0003] In terms of application scenarios, smart chips are also showing a trend of deep scenario integration. With the in-depth application of smart chips in critical infrastructure, autonomous driving, financial payments, and other fields, traditional general-purpose security solutions are no longer able to meet scenario-specific needs. Especially in real-time-critical scenarios such as industrial control, chips must complete the entire process from fault detection to safe recovery within 200 microseconds. This places high demands on reset management with millisecond-level response and nanometer-level precision. Current mainstream solutions still rely on static threshold monitoring, which is difficult to adapt to the differentiated security requirements of different application scenarios.

[0004] Furthermore, with the advancement of chip manufacturing technology, on-chip intelligence has ushered in new development opportunities. Advanced process technologies below 5nm enable the integration of over 80 billion transistors on a single chip, providing the hardware foundation for the deployment of embedded AI engines. Untimely abnormal reset requests can lead to cascading failures. For example, jitter in the reset signal from the image processing module of an autonomous driving chip caused the control system to misjudge within 300ms, ultimately triggering unnecessary emergency braking. More seriously, certain maliciously constructed reset attacks can defeat the protection mechanisms of the secure enclave. In a typical system-on-chip architecture, the typical system-level reset process is as follows: When a system reset is required, each submodule of the system issues a system reset request signal. The reset request signal is sent to the reset management module, which then responds to the reset request signal and sends a system reset signal. After the system reset process, the reset signal is removed, indicating that the system reset is complete and the system resumes operation. This chip design approach presents many potential issues. If the reset management module does not properly respond to the system reset request, the system will not be able to enter the reset process, affecting normal operation. If the reset signal is not properly removed after the system reset process, the system will remain in the reset state and will not function properly. If an exception occurs in the reset management module and the system reset process is not completed, the system will enter an abnormal state. If the reset request signal is not removed normally after the system reset process, the system reset will be triggered multiple times, causing the system to fall into an infinite loop. In the prior art, the exception handling of the on-chip system submodule is often a single hardware-level reset request handling based on the reset management module. It fails to finely analyze the situation where the reset request exception occurs, and to perform targeted compensatory handling of the reset request exception. It also fails to combine with the application scenario to provide an embedded vertical integration processing mechanism. Based on the above problems, the present invention can use the computing resources of the on-chip system to perform on-chip system-level reset signal exception data analysis, to dynamically monitor the reset state and request exceptions of each reset source, and after detecting the exception, bypass the reset management module and directly set a system-level power-on reset, and reset the entire system-level reset signal to the power-on initialization state, so that the system is restored to a safe state and can work normally; perform targeted compensatory handling of reset request exceptions, and combine with the application scenario to provide an embedded vertical integration processing mechanism. Summary of the Invention

[0005] In order to solve the above problems in the prior art, the present invention proposes a reset abnormality monitoring device, method, chip and circuit, wherein the device comprises: an on-chip system including an on-chip sub-module and an on-chip storage module, a reset monitoring module and a reset management module;

[0006] The system on chip determines the number of reset requests issued by each submodule in the most recent time interval and the number of abnormal requests associated with the reset request, and determines to write configuration information into the register configuration module based on the number of occurrences and the number of abnormal requests and their changes;

[0007] The reset management module generates a system-level reset signal based on the submodule reset request and sends it to the on-chip system and reset monitoring module synchronously;

[0008] The reset monitoring module is connected between the reset management module and the on-chip system to monitor the system-level reset signal; it includes a register configuration module, a pre-scaling module, a reset generation module, a reset input distributor and a monitoring channel composed of multiple counters;

[0009] The register configuration module performs control enable of the counter, error injection enable of the pre-scaling module, and preload configuration of the reset input distributor; and the preload configuration module is set to receive the configuration information of the on-chip storage module to configure the counter, reset input distributor, and pre-scaling module;

[0010] The reset input distributor distributes the reset signal to the monitoring channel for submodule reset request monitoring in a one-to-one or non-one-to-one manner based on the distribution configuration information of the configuration information;

[0011] The counter uses the system-level power-on reset as its reset source; it counts using the monitoring channel function clock; it stops counting and clears the counter when it detects the rising edge of the monitored reset signal when it is released; when the counter value reaches the preset upper threshold, does not reach the preset lower threshold when it is cleared, or the reset signal is still high when the counter is cleared, it sends a system-level power-on reset request to the reset generation module; after receiving the reset request, the reset generation module asserts the system-level power-on reset signal to the on-chip system;

[0012] The prescaler module is used to provide the functional clock of the counter channel and perform injection testing on the reset monitoring module.

[0013] Furthermore, the reset monitoring module uses a normally open low-frequency clock, which is the clock signal of each module in the reset monitoring module, ensuring that the reset monitoring module will not fail due to clock loss.

[0014] Furthermore, the one-to-one distribution method includes the following steps:

[0015] Step SA1: Obtain the number of monitoring channels N and the number of submodules M;

[0016] Step SA2: The system on chip determines a target submodule; the target submodule is a submodule that needs to be reset monitored; specifically, the system on chip determines the number of reset requests issued by each submodule in the most recent time interval, and the number of abnormal requests in which the associated reset request is abnormal, and determines an abnormality index based on the number of occurrences and / or the number of abnormal requests; the abnormality index is positively correlated with the number of occurrences and / or the number of abnormal requests, and the top M target submodules with the highest abnormality index are selected as the determined target submodules;

[0017] Step SA3: The distribution configuration information is one-to-one distribution configuration information; each target submodule corresponds to a monitoring channel, and is written into the register configuration module as distribution configuration information.

[0018] Furthermore, based on the increase in the usage time of the system on chip and / or the need for the minimum security requirement scenario, a non-one-to-one distribution method is adopted, including a one-to-many, many-to-one, and / or many-to-many method; specifically, the following steps are included:

[0019] Step SB1: Obtain the number of monitoring channels N and the number of submodules M;

[0020] Step SB2: The system on chip determines the number of occurrences of reset requests issued by each submodule m in the recent time interval and the number of abnormal requests in which the associated reset request is abnormal. Determine the abnormality index ; Determine the abnormality index based on the number of occurrences and / or the number of abnormal requests, so that the submodule with a higher abnormality index is allocated a greater number of monitoring channels; ;

[0021] Step SB3: Set corresponding monitoring channels for the submodules according to the number of allocated monitoring channels, and write the distribution configuration information into the register configuration module.

[0022] Furthermore, the step SB2 includes: setting ; Use the residual value method to allocate the number of monitoring channels for the submodules ;in: is a floor symbol; if there are remaining unallocated monitoring channels, the remaining monitoring channels are shared among the sub-modules to which the monitoring channels are not allocated.

[0023] Furthermore, the step SB2 includes: based on the number of occurrences and / or the number of abnormal requests Determine the abnormality index ;set up Differentiation anomaly index; where: and is the weight coefficient, and ; Cluster the values ​​of the anomaly index to obtain two clusters; evenly distribute the monitoring channels among each submodule in the cluster with the larger mean; and share the remaining monitoring channels among the submodules in the cluster with the smaller mean.

[0024] A reset anomaly monitoring method is characterized in that the reset anomaly monitoring method performs reset monitoring of an on-chip submodule based on the above-mentioned reset anomaly monitoring device; specifically comprising the following steps:

[0025] The on-chip system determines the number of reset requests issued by each submodule in the most recent time interval and the number of abnormal requests in which the associated reset request is abnormal, periodically determines configuration information based on the number of occurrences and the number of abnormal requests, and their changes. When the configuration information changes, the configuration information is updated, written into the register configuration module, and simultaneously updated into the initial value preload module of the on-chip storage module;

[0026] The reset monitoring module monitors reset requests of various on-chip sub-modules of the system-on-chip based on the updated configuration information.

[0027] A reset abnormality monitoring digital logic comprises the above reset abnormality monitoring device.

[0028] A reset abnormality monitoring chip comprises the above reset abnormality monitoring device.

[0029] A reset abnormality monitoring circuit comprises the above reset abnormality monitoring device.

[0030] The beneficial effects of the present invention include:

[0031] (1) It acts independently on the system on chip and introduces a dedicated monitoring mechanism and monitoring circuit into the system on chip. It can use the computing resources of the system on chip to analyze the abnormal data of the reset signal at the system level on chip, and dynamically monitor the abnormal reset status and request of each reset source. After detecting the abnormality, it bypasses the reset management module and directly sets a system-level power-on reset to reset the entire system level to the power-on initialization state, so that the system can be restored to a safe state and can work normally.

[0032] (2) Through the introduction of a monitoring mechanism, system-level reset exception processing is carried out. At the same time, reset exception analysis based on time series characteristics is carried out through the on-chip system. Based on the number of occurrences and / or the number of system-level power-on reset request exception requests, the distribution configuration information is dynamically determined to quickly adapt to the real-time use of the on-chip system. Reset exception processing is carried out by combining software and hardware to form an integrated vertical exception handling mechanism, which improves the efficiency of the use of software and hardware resources. It is suitable for embedded chips with high security requirements and can improve the reliability of the chip in a compatible manner without affecting the on-chip system. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application, but do not constitute an improper limitation of the present invention. In the drawings:

[0034] Figure 1 This is a structural diagram of the reset abnormality monitoring device provided by the present invention.

[0035] Figure 2 This is a structural diagram of the reset monitoring module provided by the present invention.

[0036] Figure 3 This is a structural diagram of the reset state monitoring counter module provided by the present invention.

[0037] Figure 4 This is a structural diagram of the reset generation module provided by the present invention. DETAILED DESCRIPTION

[0038] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. The exemplary embodiments and descriptions are only used to explain the present invention but are not intended to limit the present invention.

[0039] A dedicated monitoring mechanism and monitoring circuit are introduced into the SoC. This mechanism can utilize the SoC's computing resources to analyze abnormal data of the SoC-level reset signal. This allows for dynamic monitoring of the reset status and request anomalies of each reset source. Upon detecting an anomaly, the system bypasses the reset management module and directly initiates a system-level power-on reset (por_reset), returning the entire system-level reset signal to the power-on initialization state, restoring the system to a safe state and enabling normal operation.

[0040] The present invention complements the monitoring mechanism for the reset process in the system-on-chip architecture and provides a verification method for error injection for this function, which can improve the functional safety level of the system, ensure that the system operates in a relatively safe state, and ensure that the system-level reset signal process can be triggered normally;

[0041] The present invention proposes a reset abnormality monitoring method and device, as shown in the attached Figure 1 As shown, the device includes: an on-chip sub-module, a reset monitoring module, a reset management module, and an on-chip storage module; wherein: the on-chip sub-module and the on-chip storage module both belong to the on-chip system;

[0042] The system-on-chip determines the number of reset requests issued by each submodule in a recent time interval and the number of abnormal requests in which the associated reset request is abnormal; determines configuration information based on the number of occurrences and the number of abnormal requests, as well as changes therein, and writes the configuration information into a register configuration module and / or an initial value preloading module; the configuration information is used as a preload initial value so that the register configuration module performs preload configuration of a reset state monitoring counter, a prescaler module, and a reset input distributor;

[0043] Preferably, while writing configuration information to the register configuration module, the system-on-chip determines if the configuration information requires long-term configuration or typical configuration information for special occasions. This configuration information is then simultaneously written to the initial value preload module located in the flash memory for long-term storage. In this manner, if the system-on-chip experiences a power cycle (power off and on again), all register configurations and the configurations in the chip's conventional circuits will return to their initial values. However, due to the flash memory's ability to retain data even after a power off, the internally stored configuration will remain unchanged. Upon powering the system back on, the initial value preload module will begin operating and preload the saved configuration into the register configuration module as the initial configuration value. By leveraging the flash memory's ability to retain data after a power off, the initial value preload module can reload the configuration into the register configuration module upon powering back on, providing preloaded configurations for the reset status monitoring counter, prescaler module, and reset input distributor. This allows the reset monitoring module to begin operating earlier during the system-on-chip power-up process, allowing monitoring of related reset processes during the system-on-chip power-up process when necessary.

[0044] Preferably: the system on chip periodically determines the configuration information, and when the configuration information changes, updates the configuration information so that the reset monitoring module loads and uses the updated configuration information;

[0045] The on-chip storage module includes an initial value preloading module for storing preloaded initial values ​​for reset monitoring; preferably, the on-chip storage module is a FLASH storage module;

[0046] The on-chip submodule generates a reset request corresponding to each submodule during operation;

[0047] The reset management module generates a system-level reset signal based on the reset request and sends it to the system on chip and the reset monitoring module synchronously;

[0048] As attached Figure 2 As shown, the reset monitoring module is connected between the reset management module and the system on chip, and is used to monitor the system-level reset signal generated by the system on chip; it includes a register configuration module, a pre-scaling module, a reset generation module, a reset input distributor, and an independent monitoring channel composed of multiple reset state monitoring counters; the reset monitoring module supports the use of multiple monitoring channels to manage different reset sources / reset signals, and supports the use of error injection function to functionally test its own monitoring function;

[0049] The reset monitoring module uses a normally open low-frequency clock, which is the clock signal of each module in the reset monitoring module, and is used to ensure that the reset monitoring module will not fail due to clock loss;

[0050] The register configuration module is used to control and enable the reset state monitoring counter and the error injection of the pre-scaling module, as well as preload configuration of the reset input distributor; the preload configuration module is set to receive the configuration information of the on-chip storage module through the initial value preload module when the system is powered on to configure the reset state monitoring counter, the reset input distributor, and the pre-scaling module;

[0051] The reset input distributor is used to distribute the input multiple monitored reset signals to the respective monitoring channels of the multiple reset state monitoring counters based on the distribution configuration information sent by the register configuration module; specifically: one-to-one distribution or non-one-to-one distribution;

[0052] The one-to-one distribution method includes the following steps:

[0053] Step SA1: Set the number of monitoring channels to be less than or equal to the number of submodules. In this case, the number of submodules is scalable. During the initial setting, the number of monitoring channels N can be equal to the number of submodules, and this state is entered as the number of submodules increases.

[0054] Step SA2: The system on chip determines a target submodule; the target submodule is a submodule that needs to be reset monitored; specifically, the system on chip determines the number of reset requests issued by each submodule in the most recent time interval, and the number of abnormal requests in which the associated reset request is abnormal, and determines an abnormality index based on the number of occurrences and / or the number of abnormal requests; the abnormality index is positively correlated with the number of occurrences and / or the number of abnormal requests, and the top M target submodules with the highest abnormality index are selected as the determined target submodules;

[0055] Step SA3: The distribution configuration information is one-to-one distribution configuration information; each target submodule corresponds to a monitoring channel, and is written into the register configuration module as distribution configuration information;

[0056] As the SoC usage time increases or as the minimum security requirement is met, a non-one-to-one distribution method may be used; including one-to-many and / or many-to-one distribution methods; including the following steps:

[0057] Step SB1: Obtain the current number of monitoring channels N and the number of submodules M;

[0058] Step SB2: The system on chip determines the number of occurrences of reset requests issued by each submodule m in the recent time interval and the number of abnormal requests in which the associated reset request is abnormal. Determine the abnormality index ; Determine the abnormality index based on the number of occurrences and / or the number of abnormal requests, so that the submodule with a higher abnormality index is allocated a greater number of monitoring channels; ;

[0059] Preferred: Setting ;

[0060] Optimal: The number of monitoring channels allocated to the submodule by the residual value method is ;in: is the downward rounding symbol; if there are any remaining unassigned monitoring channels, they are first assigned to the submodules that have not been assigned monitoring channels; if there are still remaining, they are assigned in descending order of abnormality index; each submodule is assigned a monitoring channel until there are no remaining channels;

[0061] Replaceable: The number of monitoring channels allocated to the submodule is , then allocate one monitoring channel to each submodule in descending order of anomaly index; if there are any remaining monitoring channels, share them among the submodules that have not been allocated monitoring channels (the number of allocated monitoring channels is small); this allocation method can be selected when there is no significant difference between the number of submodule reset request occurrences and / or the number of system-level power-on reset request exceptions; if there is a significant difference, the following replacement method can be used;

[0062] Alternative: Based on the number of occurrences and / or the number of exception requests Determine the abnormality index ;set up So that there are obvious differences between the abnormal indices; among them: and is the weight coefficient, and Cluster the anomaly index to obtain two clusters; evenly distribute the monitoring channels among each submodule in the cluster with the larger mean; and share the remaining monitoring channels among the submodules in the cluster with the smaller mean.

[0063] Step SB3: Set corresponding monitoring channels for the submodules according to the number of allocated monitoring channels, and write the distribution configuration information into the register configuration module; through one-to-many distribution and / or many-to-one distribution, multiple reset signals are time-shared on one monitoring channel to save resources; through many-to-one distribution, multiple monitoring channels are used to simultaneously monitor one reset signal to achieve lockstep and redundant monitoring;

[0064] Alternatively, a reset input distributor is configured to distribute the input multiple monitored reset signals to the respective monitoring channels of the multiple reset state monitoring counters based on the distribution configuration information sent by the register configuration module. Specifically, the number of reset requests issued by each submodule in the most recent time interval and the number of abnormal requests in which the associated reset requests are abnormal are determined, and the distribution configuration information is determined based on changes in the number of occurrences and / or the number of abnormal requests. The distribution configuration information is written into the reset input distributor via the register configuration module, and the reset input distributor distributes the input multiple monitored reset signals to the corresponding monitoring channels of the multiple reset state monitoring counters according to the distribution configuration information. In this manner, the resources in the system-on-chip can be fully utilized for periodic reset monitoring control, and the monitoring and control can be adjusted according to the usage of the system-on-chip without having to change the hardware system.

[0065] The step of determining the distribution configuration information based on the change in the number of occurrences and / or the number of abnormal requests specifically includes the following steps:

[0066] Step SC1: Get the log information of the latest T time intervals and get the number of occurrences of submodule m in each time interval t and / or the number of abnormal requests for system-level power-on reset requests ; Where: t = 1 ~ T;

[0067] Preferably: T is a preset value; T=2~10;

[0068] Step SC2: Determine an abnormality index based on the number of occurrences and / or the number of abnormal requests, so that it can reflect the number of occurrences and the number of abnormal requests for abnormal system-level power-on reset requests, and at the same time, the ones with higher recent occurrences, more complex changes, and more unpredictable results have higher abnormality indexes; specifically, calculate the abnormality index based on the following formulas (1), (2), and (3); wherein: is the time decay coefficient, for example: ;

[0069] (1);

[0070] (2);

[0071] (3);

[0072] Step SC3: Based on the abnormality index, monitoring channels are allocated to the submodules, so that the submodules with higher abnormality index are allocated more monitoring channels, and vice versa. Specifically, for the mth submodule, if , then allocate If an independent monitoring channel , then the monitoring channel is shared with other sub-modules, and the remaining monitoring channels that are allocated independent monitoring channels are set as shared channels; , then no monitoring channel is allocated; is the zero-crossing residual;

[0073] Preferably: in the case where multiple submodules share a channel, the channels are shared by the multiple submodules in a random or time slice rotation manner; obviously, the number of shared monitoring channels is one or more;

[0074] After the reset monitoring module is enabled, the register configuration module configures the monitoring threshold of the reset monitoring module; wherein: the configuration information includes the upper limit of the monitoring threshold, the lower limit of the monitoring threshold, and the reset number threshold; at the same time, when the system on chip is powered on again after being powered off, the initial value preloading module will start the reset monitoring module according to the previously saved configuration information and begin to monitor the reset process;

[0075] Preferably: the upper limit of the monitoring threshold, the lower limit of the monitoring threshold, and the reset times threshold are used to monitor all counters;

[0076] The pre-scaling module is used to perform injection testing on the reset monitoring module; specifically: the pre-scaling module is used to perform injection testing on the functional clock reset monitoring module that provides the counter channel; including: in response to the error injection test enable from the APB bus, sending an error injection enable signal through the register configuration module to enable the reset monitoring module to enter the error injection mode; the pre-scaling module reduces the frequency division ratio of the channel clock to trigger a system-level power-on reset; the pre-scaling module further divides the normally open low-frequency clock external to the module to provide counting points for each channel of the counter as the low-frequency functional clock of the channel to save hardware resources, and at the same time, the frequency division ratio can be adjusted to achieve functional testing of each channel using error injection; the frequency division ratio is adjusted to achieve functional testing of the reset monitoring module using error injection;

[0077] Further: the pre-scaling module is used to provide the channel function clock to the reset channel and support error injection testing;

[0078] The pre-scaling module reduces the frequency division ratio of the channel clock to trigger a system-level power-on reset, and further divides the low-frequency clock to provide counting points for each monitoring channel to save hardware resources. At the same time, the frequency division ratio is adjusted to implement functional testing of the monitoring module using error injection; specifically: the pre-scaling module reduces the frequency division ratio of the channel clock to trigger a system-level power-on reset when the reset process is normal and the configuration information is unchanged, thereby verifying the reliability of the reset monitoring module; for example: under a certain configuration information setting, it is necessary to monitor the reset process for 5ms before a system-level power-on reset is generated. If there is no reset, If there is an error caused by external interference, the reset process will remain normal and this reset will never be triggered, making it impossible to test the module function. When the error injection enable is turned on, the frequency division ratio of the channel clock sent to the channel will be lowered, and the channel clock of the channel will become faster. Therefore, if the configuration information does not change, the time to trigger the system-level power-on reset will become 100us. Therefore, after the error injection is turned on, since the normal reset process requires 300us under this threshold, the system-level power-on reset will be triggered after the reset of the channel reaches 100us, thereby completing the reset monitoring module's verification of the reliability of the channel monitoring;

[0079] As attached Figure 3 The reset state monitoring counter module includes multiple monitoring channels, each monitoring channel is constructed based on a counter, and clock control is performed based on the normally open low-frequency clock after division output by the pre-scaling module as a counting point; the reset state monitoring counter receives the reset signal from the reset input distributor; and receives the upper monitoring threshold, lower monitoring threshold, and reset number threshold signals from the register configuration module;

[0080] The counter is reset by a system-level power-on reset; when the reset signal distributed by the reset input distributor is counted and monitored, the counting is started by using an asynchronous setting and synchronous release method; the counting is stopped and the counter is cleared when the rising edge of the monitored reset signal is detected; when the counter count value reaches the preset upper threshold value or does not reach the preset lower threshold value when clearing, or the reset request signal is still high when the counter is cleared, a power-on reset request is sent to the reset generation module; and the reset generation module generates a system-level power-on reset; this indicates that a reset anomaly has been detected; wherein: the counter count value reaches the preset upper threshold value, indicating that a reset timeout event has occurred in the monitored reset channel; the counter count value does not reach the preset lower threshold value when clearing. If the reset request signal is still high when the counter is cleared, it indicates that the reset request signal has not been removed normally. Under normal circumstances, the reset request signal will be removed after the reset is completed. The monitoring module introduces a higher priority system-level power-on reset to perform a power-on reset (por_reset) to ensure that the system enters a safe state and avoids the system falling into an infinite loop of regular resets. The on-chip system accumulates and stores the number of times the reset request is abnormal and the sub-module that caused the abnormality for analysis, thereby obtaining dynamically updated distribution configuration information. Obviously, this record is based on time.

[0081] Preferably, each channel is associated with a reset count recording module for monitoring the number of resets within a preset time length. When the number of resets exceeds the reset count threshold, a power-on reset request is sent to the reset generation module to invoke a system-level power-on reset. The system on chip increases the number of abnormal requests corresponding to the submodule m based on the occurrence of the request. ;

[0082] Optimum: To ensure that each channel can work normally, all asynchronous signals such as clearing / setting / starting the counter will be processed across clock domains to ensure that no glitches are generated;

[0083] As attached Figure 4 As shown in the figure, after receiving the reset request from each channel, the reset generation module sets a system-level power-on reset signal (por_reset) to the on-chip system, and automatically removes the system-level power-on reset signal after one normally open low-frequency clock cycle;

[0084] Preferably, a dual-backup register is used to set the power-on reset signal to avoid abnormal power-on reset signals caused by abnormal flipping of registers due to transient failures; specifically, after receiving a power-on reset request sent by the monitoring channel, it is synchronized to two functional registers. When the outputs of the two functional registers are both 1, the system-level power-on reset signal is set; when one functional register is flipped to 1 due to transient failure, the system-level power-on reset is not set;

[0085] Because system-level power-on resets have a significant impact, the reset generation module uses a dual signal backup method to avoid unexpected system-level power-on reset signals due to environmental influences. The power-on reset request generated by each channel is simultaneously sent to the synchronous set terminals of two registers. Subsequently, in the next clock cycle, the outputs of both registers are pulled high. The two high outputs remain high after passing through the AND gate and are sent to the reset generation module as a system-level power-on reset. If only one register briefly flips due to external interference, causing the output to be high, while the output of the other register is low, the output after passing through the AND gate remains low, and no abnormal system-level power-on reset occurs.

[0086] Based on the same inventive concept, the present invention provides a reset anomaly monitoring method, which performs reset monitoring of an on-chip submodule based on the above reset anomaly monitoring device; specifically, the method comprises the following steps:

[0087] The system on chip determines the number of reset requests issued by each submodule in the most recent time interval and the number of abnormal requests associated with the reset request, periodically determines configuration information based on the number of occurrences and the number of abnormal requests and their changes, and updates the configuration information and writes it into the register configuration module when the configuration information changes;

[0088] The reset monitoring module monitors reset requests of various on-chip sub-modules of the system-on-chip based on the updated configuration information.

[0089] A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language, including assembly or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple collaborative files (e.g., files storing one or more modules, subroutines, or code portions). A computer program can be deployed to execute on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communication network.

[0090] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0091] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0092] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0093] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A reset abnormality monitoring device, characterized in that: It includes: a system on chip including an on-chip sub-module and an on-chip storage module, a reset monitoring module and a reset management module; The system on chip determines the number of reset requests issued by each submodule in the most recent time interval and the number of abnormal requests associated with the reset request, and determines to write configuration information into the register configuration module based on the number of occurrences and the number of abnormal requests and their changes; The reset management module generates a system-level reset signal based on the submodule reset request and sends it to the on-chip system and reset monitoring module synchronously; The reset monitoring module is connected between the reset management module and the on-chip system to monitor the system-level reset signal; it includes a register configuration module, a pre-scaling module, a reset generation module, a reset input distributor and a monitoring channel composed of multiple counters; The register configuration module performs control enable of the counter, error injection enable of the pre-scaling module, and preload configuration of the reset input distributor; and the preload configuration module is set to receive the configuration information of the on-chip storage module to configure the counter, reset input distributor, and pre-scaling module; The reset input distributor distributes the reset signal to the monitoring channel for submodule reset request monitoring in a one-to-one or non-one-to-one manner based on the distribution configuration information of the configuration information; The counter is reset by the system-level power-on reset; it counts using the monitoring channel function clock; it stops counting and clears the counter when it detects the rising edge of the monitored reset signal. When the counter value reaches the preset upper threshold value, does not reach the preset lower threshold value when cleared, or the reset signal is still high when the counter is cleared, a system-level power-on reset request is sent to the reset generation module; after receiving the reset generation module, the system-level power-on reset signal is asserted to the on-chip system; The prescaler module is used to provide the functional clock of the counter channel and perform injection testing on the reset monitoring module.

2. The reset abnormality monitoring device according to claim 1, characterized in that: The reset monitoring module uses a normally open low-frequency clock, which is the clock signal of each module in the reset monitoring module, ensuring that the reset monitoring module will not fail due to clock loss.

3. The reset abnormality monitoring device according to claim 2, characterized in that: The one-to-one distribution method includes the following steps: Step SA1: Obtain the number of monitoring channels N and the number of submodules M; Step SA2: The system on chip determines a target submodule; the target submodule is a submodule that needs to be reset monitored; specifically, the system on chip determines the number of reset requests issued by each submodule in the most recent time interval, and the number of abnormal requests in which the associated reset request is abnormal, and determines an abnormality index based on the number of occurrences and / or the number of abnormal requests; the abnormality index is positively correlated with the number of occurrences and / or the number of abnormal requests, and the top M target submodules with the highest abnormality index are selected as the determined target submodules; Step SA3: The distribution configuration information is one-to-one distribution configuration information; each target submodule corresponds to a monitoring channel, and is written into the register configuration module as distribution configuration information.

4. The reset abnormality monitoring device according to claim 2, characterized in that: Based on the increasing usage time of the SoC and / or the need for minimum security requirements, a non-one-to-one distribution method is adopted, including one-to-many, many-to-one, and / or many-to-many methods. The specific steps include: Step SB1: Obtain the number of monitoring channels N and the number of submodules M; Step SB2: The system on chip determines the number of occurrences of reset requests issued by each submodule m in the recent time interval and the number of abnormal requests in which the associated reset request is abnormal. Determine the abnormality index ; Determine an abnormality index based on the number of occurrences and / or the number of abnormal requests, so that a submodule with a higher abnormality index is allocated a greater number of monitoring channels; ; Step SB3: Set corresponding monitoring channels for the submodules according to the number of allocated monitoring channels, and write the distribution configuration information into the register configuration module.

5. The reset abnormality monitoring device according to claim 3, characterized in that: Step SB2 includes: setting ; Use the residual value method to allocate the number of monitoring channels for the submodules ;in: is a floor symbol; if there are remaining unallocated monitoring channels, the remaining monitoring channels are shared among the sub-modules to which the monitoring channels are not allocated.

6. The reset abnormality monitoring device according to claim 3, characterized in that: Step SB2 includes: based on the number of occurrences and / or the number of abnormal requests Determine the abnormality index ;set up Differentiation anomaly index; where: and is the weight coefficient, and ; Cluster the values ​​of the anomaly index to obtain two clusters; evenly distribute the monitoring channels among each submodule in the cluster with the larger mean; and share the remaining monitoring channels among the submodules in the cluster with the smaller mean.

7. A reset abnormality monitoring method, characterized in that: The reset abnormality monitoring method is based on the reset abnormality monitoring device according to any one of claims 1 to 6, and performs reset monitoring of an on-chip submodule; specifically comprising the following steps: The on-chip system determines the number of reset requests issued by each submodule in the most recent time interval and the number of abnormal requests in which the associated reset request is abnormal, periodically determines configuration information based on the number of occurrences and the number of abnormal requests, and their changes. When the configuration information changes, the configuration information is updated, written into the register configuration module, and simultaneously updated into the initial value preload module of the on-chip storage module; The reset monitoring module monitors reset requests of various on-chip sub-modules of the system-on-chip based on the updated configuration information.

8. A reset abnormality monitoring chip, characterized in that: The reset abnormality monitoring chip includes the reset abnormality monitoring device according to any one of claims 1 to 6.

9. A reset abnormality monitoring circuit, characterized in that: The reset abnormality monitoring circuit includes the reset abnormality monitoring device according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Board card firmware abnormity monitoring and core data exporting method of multi-core SoC

    CN115373997A

  • Network node anomaly monitoring method and device, vehicle, equipment and medium

    CN119135506A