Method for Efuse programming of a microcontroller
The SEB image simplifies efuse programming for MCUs by configuring efuse states at startup, eliminating the need for specialized tools and reducing errors, thus enhancing programming efficiency and reliability.
Patent Information
- Application Number
- DE102023004843
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-11-25
- Publication Date
- 2025-11-06
- Estimated Expiration
- 2043-11-25
AI Technical Summary
Existing efuse programming methods for microcontroller units (MCUs) are complex, require specialized hardware and software tools, and pose a risk of hardware destruction due to irreversible programming errors.
A self-efuse burning (SEB) image is created and transmitted to the MCU, allowing efuse programming without specialized tools, ensuring reversible programming and error-free operation by configuring the efuse states at startup.
Efuse programming is simplified, reduces manual errors, and enables efficient, error-free configuration of MCUs, even in distributed systems like vehicles or IoT devices, with minimal additional effort and cost.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for Efuse programming of a microcontroller with at least one Efuse according to the preamble of claim 1.
[0002] Electronic fuses (EFUSEs) on a microchip enable a one-time state change (programming), for example, from a conductive state (corresponding to a logic zero) to a non-conductive state (corresponding to a logic one), preferably by applying a suitable current that destroys the conductive material. This programming is irreversible. Therefore, a state change from zero to one is possible, but not from one to zero.
[0003] For example, efuses can be used to create uniquely programmable memory modules that can also be part of a larger microchip, particularly an efuse MCU (microcontroller unit). Typically, an efuse comprises a multitude of individual trace elements whose state can be changed independently of one another. The current state of an efuse can thus be described as a bit pattern with a width corresponding to the number of individual trace elements it contains. A desired state can be programmed into an efuse if no bit position represents the desired state with a zero, while the current state represents a one.
[0004] Document US 2014 / 0253221 A1 describes a method for efuse programming of programmable efuses embedded on a chip substrate, which can be programmed after the chip has been manufactured and placed on the market. An on-die fuse controller includes a sequencer that uses a fuse state machine to control the programming of efuse modules. The sequencer is controlled via interfaces using pseudocode. The fuse state machine manages the power supply and timing of the read and write operations.
[0005] Programming Efuse devices (that is, changing the state of certain built-in efuses) typically requires special software and hardware tools provided by the manufacturer of such memory chips or microchips. These tools might include special configuration files and / or firmware images for a microcontroller, or a special cable, particularly a Joint Test Action Group (JTAG) cable, to connect the microcontroller to a programming computer running the special programming software. Efuse MCUs typically require special, proprietary JTAG cables and / or other JTAG devices provided by the Efuse MCU manufacturer, which must be connected between the Efuse MCU and the programming computer.
[0006] For example, document CN 108665934 A discloses such tools and a method for programming efuses. After the programming information for several efuse units connected to a digital logic controller (DLC) is continuously inputted into an information input interface of the DLC, the DLC controls the multiple efuse units to be automatically programmed according to the programming information. A clock cycle is provided between the programming of each pair of adjacent efuse units. The timing requirement for programming the efuse units is met without reserving programming time for unprogrammed bits, thereby significantly reducing the programming time of the multiple efuse units and improving programming efficiency.
[0007] The process of programming an Efuse is complex and typically involves several steps, requires specialized technical knowledge, and carries the risk of damaging the memory chip or microchip being programmed. Furthermore, subsequent programming, especially of embedded Efuse MCUs such as those integrated into vehicle control units, is complicated by the need for special cables or other hardware tools.
[0008] Therefore, there is a need for an improved method for Efuse programming of Efuse MCUs.
[0009] The invention is based on the objective of specifying such a method.
[0010] The problem is solved according to the invention by a method having the features of claim 1.
[0011] Advantageous embodiments of the invention are the subject of the dependent claims.
[0012] Efuse MCUs are programmed by transferring a memory image containing executable instructions, known as an MCU image, into the MCU's programmable memory. This process is called flashing or flash programming. Unlike Efuse programming, this process can be performed without special (i.e., MCU-specific) hardware or software tools and is typically reversible (depending on the type of programmable memory used by the MCU).
[0013] The invention is based on the finding that the Efuse programming of an Efuse MCU can be simplified and improved by flashing a special MCU image to the MCU in a conventional manner. This special MCU image, hereinafter referred to as the Self-Efuse-Burning (SEB) image, is designed such that, upon startup of the MCU, it programs certain efuses configured in the SEB image (for example, switching from a conducting to a non-conducting state).
[0014] By hard-configuring Efuse programming within the SEB image, potential errors, such as those arising from incorrect operation of a special software tool provided by the Efuse MCU manufacturer for Efuse programming, are avoided. Such an SEB image can be deployed particularly easily, for example, via the internet or a database. Furthermore, the need for special hardware tools for Efuse programming is eliminated; instead, the hardware tools typically available for transferring any MCU image to an MCU are sufficient.
[0015] According to the invention, the application of such a SEB image provides for generating an SEB image in which the programming of the intended efuses is executed, and transferring this SEB image to an efuse MCU.
[0016] The Efuse MCU, now loaded with the SEB image, is then started. Due to the SEB image's unique configuration, this does not involve a normal operating system startup. Instead, the Efuuses intended for programming are programmed (for example, changed from a conducting to a non-conducting state). This process can take several seconds.
[0017] The Efuse MCU will then be restarted. During this restart, it will detect that the Efuse programming process has already been completed, and then the operating system will start.
[0018] Following this, an MCU image containing standard production code (i.e., an MCU image designed and configured for productive operation of the Efuse MCU) is transferred (flashed) to the Efuse MCU in the conventional manner. The Efuse MCU is then ready for operational use (for example, in a vehicle's control unit).
[0019] In a method for programming an Efuse MCU comprising at least one Efuse, a Self-Efuse Burning Image (SEB) is created, provided, and transferred to the Efuse MCU. This SEB is configured for programming at least one of the Efues. For each Efuse to be programmed, the SEB contains program instructions such that the current programming state (i.e., the assignment of all line states of the elements of a programmable Efuse, which can be encoded as bit values) is captured. Furthermore, the SEB contains instructions such that if the current programming state deviates from the intended value, it is overwritten with a predetermined bit pattern (hereinafter referred to as the value) assigned to the respective Efuse to be programmed.
[0020] One advantage of the method is that Efuse programming is reduced to the transfer of an MCU image, which, although specially designed (namely as an SEB image), can be transferred in a conventional way without the aid of special software or hardware tools.
[0021] Another advantage is that manual errors in Efuse programming are avoided by transferring a pre-built SEB image (which can be verified independently of the target hardware of the Efuse MCU) without further manual interaction. Methods and tools for verifying MCU images are known that enable very good test coverage and test precision. In particular, errors in the creation of SEB images, which can be readily detected with such methods, do not lead to hardware loss due to irreversible incorrect programming of an Efuse MCU.
[0022] In one embodiment of the method, the SEB image includes program instructions such that safety- and / or reliability-critical efuses are programmed and tested first, before further efuses are programmed. This prevents a critical state of the efuse MCU from being reached if efuse programming is aborted. Furthermore, this ensures that interdependent steps of efuse programming are executed correctly. Such a dependency can be defined, for example, by checking the value of a first efuse before modifying a second efuse, and blocking the modification (reprogramming) of the second efuse if the value of the first efuse does not permit this change.
[0023] In one embodiment of the method, the SEB image includes program instructions such that, after all efuses to be programmed have been programmed, an operating system is started.
[0024] The booted operating system allows a user to interact with the Efuse MCU with at least one modified Efuse, for example, to query values or debug programs. Furthermore, the booted operating system can be configured for flashing an MCU image. This makes it particularly easy to verify the correctness of the Efuse programming and to establish a state ready for operation, especially automatically.
[0025] In one embodiment of the method, the SEB image is transferred to the Efuse MCU via a JTAG connection. Such a JTAG connection can, for example, include a JTAG adapter and / or other JTAG devices and / or JTAG cables. These types of JTAG connections are particularly easy to establish and widely available.
[0026] In one embodiment of the method, the JTAG connection used to transmit the SEB image is taken from a set of JTAG connections that are configured to transmit at least one production image (which is intended for the operational use of the Efuse MCU). This enables Efuse programming without the need for additional special hardware or software.
[0027] In one embodiment of the method, the SEB image is provided by a cloud and / or by one or more databases. The cloud can, for example, include servers configured for downloading data (e.g., using the File Transfer Protocol, FTP, or a similar protocol) and / or for sending data (e.g., using an email protocol). This enables Efuse programming independent of physical access to an Efuse MCU.
[0028] This embodiment is particularly advantageous when a large number of physically distributed MCUs (for example, in vehicles or Internet of Things (IoT) devices) are to be modified by Efuse programming. In particular, it also enables maintenance of such devices, the effort of which increases only sublinearly with the number of installations.
[0029] In one embodiment of the method, an Efuse MCU located in a vehicle and / or equipped for direct or indirect communication with a vehicle is Efuse-programmed, that is: the values of its at least one Efuse are changed.
[0030] This implementation allows various service providers (such as workshops or dealers) to perform configurations based on Efuses settings without requiring these service providers to be equipped with special hardware or software tools. This makes maintenance, updates, and / or upgrades particularly easy and cost-effective.
[0031] Exemplary embodiments of the invention are explained in more detail below with reference to drawings.
[0032] This shows: Fig. 1 schematically an Efuse MCU as well as Fig. 2 schematically shows a flowchart for Efuse programming of an Efuse MCU.
[0033] Corresponding parts are marked with the same reference symbols in all figures.
[0034] Fig. Figure 1 schematically shows an Efuse-MCU 1 comprising an MCU Image PI, SI and at least one, typically several Efuses, of which only an example of a first Efuse 2.1 is shown here.
[0035] The MCU image can be configured as a production image (PI) and include production code (i.e., firmware program code configured for the operational use of the Efuse MCU 1). Alternatively, the MCU image can be configured as an SEB image (SI) and include program code configured for programming at least one Efuse 2.1.
[0036] Such MCU images PI, SI can be stored locally (for example, via a Fig. 1 desktop computer (not shown) that can be connected to the Efuse-MCU 1, but also via a database DB and / or via one or more servers operated in a Cloud C.
[0037] The first Efuse 2.1 is represented purely schematically as an ordered set of bits B (in this case, 64 bits) that can be selected (addressed) individually or in bit groups BG of, for example, two, three, or ten bits B for Efuse programming. The division into bit groups BG and their technical meaning (semantics) can be different for each Efuse without altering the Efuse programming process, and is shown here only schematically and as an example.
[0038] Fig. Figure 2 schematically shows a program flowchart illustrating the Efuse programming of the Efuse-MCU 1. It starts from point S0, where an SEB image SI for the Efuse-MCU 1 has been provided.
[0039] Starting from point S0, the first step loads and starts S1 bootstrap code. In the subsequent second step, S2, a flash firmware is loaded. The provided SEB image SI is then loaded using the flash firmware. For illustrative purposes and to clarify the Efuse programming process, it is assumed that the SEB image SI is configured to modify (reprogram) the state of four Efuses 2.1 to 2.4. The first Efuse, 2.1, configures special settings of the Efuse MCU 1, particularly those relevant to security and / or reliability. The other Efuses, 2.2 to 2.4, encode further settings, such as the chip configuration of the Efuse MCU 1 or a hash value.
[0040] Following the second step S2, a first decision E1 checks whether the value intended for the first (safety- and / or reliability-critical) Efuse 2.1 has already been set (programmed). If the intended value has not yet been set, the intended value is programmed in the subsequent first Efuse programming step P1. This step can program multiple bits B and / or bit groups BG of the first Efuse 2.1. The first Efuse programming step P1 is repeated until all intended bits B and / or bit groups BG of the first Efuse 2.1 have been programmed.
[0041] If the first decision (E1) determines that the value intended for the first Efuse 2.1 is already set, the subsequent third step (S3) tests the provided SEB image and / or the modified Efuse configuration of the Efuse MCU 1. Following this, a fourth step (S4) initiates a pre-start sequence, which may include one or more program instructions that prepare the Efuse MCU 1 for Efuse programming of the subsequent Efuses 2.2 to 2.4.
[0042] In a second decision, E2, it is checked whether the value intended for the second Efuse 2.2 has already been set (programmed). If the intended value has not yet been set, the intended value is programmed in the subsequent second Efuse programming step, P2. This step can program multiple bits B and / or bit groups BG of the second Efuse 2.2. The second Efuse programming step, P2, is repeated until all intended bits B and / or bit groups BG of the second Efuse 2.2 have been programmed.
[0043] If the second decision E2 determines that the value intended for the second Efuse 2.2 is already set, a subsequent third decision E3 checks whether the value intended for the third Efuse 2.3 is already set (programmed). If the intended value is not yet set, the intended value is programmed in the subsequent third Efuse programming step P3. This step can program multiple bits B and / or bit groups BG of the third Efuse 2.3. The third Efuse programming step P3 is repeated until all intended bits B and / or bit groups BG of the third Efuse 2.3 have been programmed.
[0044] If the third decision E3 determines that the value intended for the third Efuse 2.3 is already set, a subsequent fourth decision E4 checks whether the value intended for the fourth Efuse 2.4 is already set (programmed). If the intended value is not yet set, the intended value is programmed in the subsequent fourth Efuse programming step P4. This step can program multiple bits B and / or bit groups BG of the fourth Efuse 2.4. The fourth Efuse programming step P4 is repeated until all intended bits B and / or bit groups BG of the fourth Efuse 2.4 have been programmed.
[0045] If all Efuses 2.1 to 2.4 intended for Efuse programming in the SEB image have been programmed to their designated values, the operating system of the Efuse MCU 1 is started in a fifth step S5.
[0046] Following this, further steps can be taken, in Fig. In two steps, which are not described in detail, interaction with the now running Efuse-MCU 1 is carried out in the usual way (for example, to query values or to debug), and a production firmware is flashed onto the Efuse-MCU 1 as a production image PI in the usual way.
[0047] The in Fig. The schematically depicted process thus enables the execution of Efuse programming using only such means and steps as are also required for conventional programming (flashing firmware onto an MCU). Reference symbol list 1 Efuse MCU 2.1 to 2.4 first to fourth efuse B Bit BG Bitgruppe C Cloud DB database E1 to E4 first to fourth decision P1 to P4 first to fourth Efuse programming step PI MCU Image, Production Image S0 starting point S1 to S5 first to fifth step SI MCU Image, Self-Efuse Burning (SEB) Image
Claims
[1] Method for Efuse programming of an Efuse MCU (1) comprising at least one Efuse (2.1 to 2.4), characterized by , that a Self-Efuse-Burning (SEB) Image (SI) configured for Efuse programming of at least one of the Efuses (2.1 to 2.4) is created and transferred to the Efuse MCU (1), wherein the SEB Image (SI) includes program instructions for each of the Efuses (2.1 to 2.4) to be programmed, with which an Efuse (2.1 to 2.4) to be programmed is programmed to a predetermined value associated with it, if that predetermined value has not already been set. [2] Method according to claim 1, characterized by , that the SEB Image (SI) includes program instructions such that safety- and / or reliability-critical efuses (2.1) are programmed and tested first, before further efuses (2.2 to 2.4) are programmed. [3] Method according to any one of the preceding claims, characterized by, that the SEB Image (SI) contains program instructions such that, after all the efuses to be programmed (2.1 to 2.4) have been programmed, an operating system is started. [4] Method according to any one of the preceding claims, characterized by , that the SEB Image (SI) is transferred to the Efuse MCU (1) via a Joint Test Action Group (JTAG) connection. [5] Method according to claim 4, characterized by , that the JTAG connection used to transfer the SEB image (SI) to the Efuse-MCU (1) is taken from a set of JTAG connections that are set up to transfer at least one production image (PI) to the Efuse-MCU (1). [6] Method according to any one of the preceding claims, characterized by that the SEB Image (SI) is provided by a cloud (C) and / or by one or more databases (DB). [7] Method according to any one of the preceding claims, characterized by, that an Efuse MCU (1) located in a vehicle and / or intended for communication with a vehicle is Efuse-programmed.
Citation Information
Patent Citations
On-Die Programmable Fuses
US20140253221A1