Method and checking unit for checking data in a memory cell of a system on a chip
Through the integrated monitoring unit in the SoC, error correction code and address management are independently performed, memory data verification and error correction problems in the vehicle field are solved, efficient error recognition and correction are achieved, and ISO 26262 and ASIL D standards are met.
Patent Information
- Application Number
- CN202010869910.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-27
- Filing Date
- 2020-08-26
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-08-26
AI Technical Summary
The prior art is difficult to meet the memory data verification and error correction requirements in the vehicle field, especially under the ISO 26262 and ASIL D standards, the use of 8-bit error correction codes in traditional DRAM modules is not sufficient to meet the high security requirements.
A monitoring unit is designed to be modularly integrated in the SoC to activate or disable the monitoring unit to independently perform the introduction of error correction codes, address shift management, data verification and correction. The monitoring unit ensures that data can be correctly addressed and verified when data is accessed by independently registering error correction codes in the storage unit and managing address shifts.
It realizes identification and correction of more than 99% of errors in the vehicle field, meets the high safety requirements of ISO 26262 and ASIL D standards, ensuring that the SoC continues to operate normally without shutting down in the event of error.
Smart Images

Figure CN112445644B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for checking data in a storage unit of a system-on-chip (SoC), and also relates to a monitoring unit, a computing unit, and a computer program for performing this method. Background Art
[0002] A system-on-chip (SoC) is an integrated circuit (IC) in which multiple functions of a corresponding system are integrated on a single chip (die). Such an SoC can have an externally connected main memory (e.g., DRAM (Dynamic Random Access Memory)) and a processor unit (processor system part, PS). Such a processor unit can include a suitable processor or processor core, or a multi-core processor. A multi-core processor includes multiple (at least two) processor cores. Processor cores mostly include an arithmetic logic unit (ALU), which represents the actual electronic computing unit for implementing tasks, programs, calculation instructions, etc., and also includes a local memory or buffer memory. The local buffer memory can be configured as a so-called cache memory. For example, this cache memory can include a so-called level-1 cache, and optionally a level-2 cache. The level-1 cache is mostly a smaller but faster memory. The level-2 cache is mostly larger than the level-1 cache, but often has a smaller bandwidth and worse latency than the level-1 cache.
[0003] It has proven to be appropriate to integrate such an SoC into a control device, especially into a control device of a (motor) vehicle, such as into a motor control device or a driving assistance control device. Due to safety regulations (especially in the vehicle field), it is often required to check data, for example, to check the data in the internal and external main memories of the SoC. Such safety regulations are, for example, pre-specified by the standard ISO 26262, especially by the so-called Automotive Safety Integrity Level (ASIL), which is the safety requirement level for safety-related systems in motor vehicles detailed by ISO 26262.
[0004] A corresponding memory check can be carried out, for example, by means of a so-called Error Correcting Code (ECC). If data in the main memory of the SoC is used, for example, to implement safety-critical functions of a vehicle, such as a driver assistance system up to autonomous and fully autonomous driving, the system must not simply be switched off in the event of an error, but must continue to operate normally. For example, the required redundancy of the main memory can be ensured by means of a corresponding error correction method (ECC). Summary of the Invention
[0005] According to the present invention, a method for checking data in (internal or external) storage units of a system-on-chip (SoC), a monitoring unit, a computing unit, and a computer program for performing the method are proposed. Advantageous configurations are the subject of the subsequent description.
[0006] The storage unit can in particular be the main memory or working memory of the SoC, in particular an external DRAM (Dynamic Random Access Memory) or a memory integrated in the SoC, which external DRAM can be connected to the SoC via a corresponding interface. In addition, the SoC includes a processor unit having a buffer memory or cache memory.
[0007] In the system-on-chip, a monitoring unit or monitoring module is implemented, which can be activated or deactivated by the system-on-chip. The monitoring unit is in particular configured as a hardware unit or as a hardware module, which hardware unit can in particular be modularly incorporated into the SoC and can be connected to the components of the SoC, for example configured as a so-called IP core (intellectual property core, reusable, prefabricated functional block of chip design).
[0008] For example, the monitoring unit can be activated or deactivated by setting corresponding bits, for example, by bits in an entry of a storage page (Page Table Entry, PTE) of a Memory Management Unit (MMU).
[0009] If the monitoring unit is activated, the monitoring unit stores an error correction code (ECC) for performing an error correction method in the storage unit. Here, for a predefined number of data blocks of the storage unit, data blocks with their respective error correction codes are stored respectively. If the monitoring unit is deactivated, the monitoring unit correspondingly does not store the error correction code.
[0010] Each stored error correction code is suitably used to perform an error correction method on the data in the associated number of data blocks. With such an error correction code, it is suitably possible to perform a check on the data in the associated data block and, in the case of an identified error, it is furthermore suitably possible to perform a correction of the erroneous data.
[0011] The monitoring unit in particular uses a partial capacity of the storage unit in order to store in the storage unit itself the following code: With the aid of this code, it is possible to perform a check on the data stored in the storage unit. In addition to the data, the error correction code (ECC) is thus suitably stored separately in the storage unit, in particular in a separate address area.
[0012] If access is to be made to the data in the storage unit, the monitoring unit addresses the corresponding data and the associated error correction code. Before the corresponding access, the monitoring unit checks the addressed data with the aid of the addressed error correction code and, if necessary, corrects the addressed data.
[0013] By inserting a data block with an error correction code, in particular an address shift can occur between the desired physical memory address and the actual physical memory address, at the desired physical memory address the memory management unit expects data, and at the actual physical memory address the data is actually stored in the storage unit.
[0014] Suitably, the monitoring unit manages the address shift. If access is to be made to certain data, the monitoring unit suitably mediates the access such that the desired data is addressed with the correct, actual physical memory address. In addition, the monitoring unit also addresses the error correction code belonging to the data or the corresponding data block such that the data together with its addressing is also checked and, if necessary, corrected.
[0015] Within the scope of the present invention, it is thus proposed a monitoring unit which can be integrated modularly into an SoC and can be activated and deactivated flexibly. The monitoring unit independently introduces the error correction code required for the monitoring of the data into the storage unit of the SoC and manages the resulting address shift. In the case of a data access, the monitoring unit automatically and transparently mediates and is responsible for correctly addressing and checking the desired data.
[0016] If the monitoring unit is activated, the monitoring unit in particular autonomously and independently performs its functions (in particular the introduction of error correction codes, the management of address shifts, the checking and correction of data), such that it is particularly suitable that no or at least hardly any adaptation of the SoC or the components of the SoC is required, in particular adaptation of a buffer or cache memory, a Memory Management Unit (MMU), a control unit of the main memory (DRAM Controller) or a connection system (Interconnect) for networking or connecting the individual SoC components. In particular, it is particularly suitable that no or hardly any adaptation of the software of the Memory Management Unit (MMU) is required. In particular, compatibility, modularity and flexible retrofitting can thus be achieved.
[0017] In particular, the monitoring unit can be flexibly implemented at a suitable location in the SoC. The SoC type can in particular be retrofitted with a modular monitoring unit in a simple manner, where in particular no or at least hardly any change to the components of the SoC is necessary. In particular, in order to implement the monitoring unit, it is not necessary to modify the storage units of the SoC, in particular the buffer memory. The monitoring unit can be retrofitted in the SoC type, for example, within the scope of a Design-Update. In addition, the monitoring unit can be flexibly switched on and off as required. For example, if high security is not required, the monitoring unit can be switched off so as to maintain compatibility with the previous design of the SoC.
[0018] The monitoring unit respectively sets data blocks with error correction codes for each corresponding number of data blocks, where the error correction codes are for the respectively assigned data blocks. For example, the individual data blocks with error correction codes can be aggregated into complete storage pages, such that after a corresponding number of storage pages with data there are storage pages each with the assigned error correction code. The corresponding storage pages with error correction codes (ECC pages) can be suitably placed in the storage unit. For example, all ECC pages can be placed at the start or the end of the storage unit. If the storage pages are all placed together at the end of the storage unit, preferably no address shift occurs between the desired physical address and the actual physical address. However, if data blocks and the assigned error correction codes are stored in the same storage page (DRAM page), access is faster.
[0019] The number of data blocks each having an error correction code after it is suitably pre-given according to the burst size of the SoC. In the process of a so-called burst, data blocks of a data unit smaller than a bundle whose transmission is not interrupted are transmitted. The burst size (i.e., the size of the data blocks transmitted as a bundle whose transmission is not interrupted) is in particular of a uniform specification, for example, unified by the so-called JEDEC (Joint Electron Device Engineering Council) Solid State Technology Association of the semiconductor standardization organization (abbreviation: JEDEC).
[0020] In a memory cell such as a conventional DRAM, a burst size of 256 bits, 512 bits or 1024 bits is mostly set, which in particular corresponds to the content of the cache line in the SoC. In a conventional DRAM module with an error correction code, for example, 64 + 8 bits can be set, that is, a 64-bit data block with an 8-bit error correction code, which corresponds to 512 + 64 bits in the case of an 8-fold burst, for example. However, such a DRAM module is not particularly suitable for safety-critical functions used in vehicles because, in particular, according to ISO 26262 and ASIL (Automotive Safety Integrity Level) D, the high safety requirements in the vehicle field can mostly not be met with an 8-bit error correction code.
[0021] The monitoring unit can be implemented to select the size of the data blocks for the error correction code in the process of this method, so that the safety requirements in the vehicle field are also met, in particular, the requirements according to ISO 26262 and ASIL D. Suitably, the monitoring unit can be implemented to identify more than 99% of all existing errors, in particular, also address errors and errors in the signal path, and thus in particular identify errors in the cache, memory management unit and memory protection unit (Memory Management Unit MMU and Memory Protection Unit MPU), main memory control unit (DRAM Controller), bus interface and monitoring logic devices (Snoop-Logiken) for preventing conflicts between the memory and cache contents. Particularly suitably, the monitoring unit can be implemented to correct so many errors that uncorrectable errors are sufficiently unlikely.
[0022] For example, through the monitoring unit, a data transfer of 512 + 128 bits can be achieved in the storage unit, where a data block of 128 bits is set for the associated error correction code on a data block of 512 bits. With such a 128-bit error correction code, for example, a conventional, commercially available DRAM can be used as the storage unit, enabling error detection and error correction as required by ISO 26262 and ASIL to be achieved.
[0023] Advantageously, if the monitoring unit is active, for addressing data, the monitoring unit translates the desired physical address into the actual physical address. As described above, by inserting data blocks with error correction codes, an address shift may occur in the storage unit. For a SoC (especially the memory management unit MMU), in particular, only the original physical address of the data before the address shift is known, and not the actual physical address that is valid after the address shift. As described above, the monitoring unit manages the address shift and translates the desired physical address into the actual physical address during its process. Therefore, appropriately, there is no need to change the SoC and its software, and nevertheless, the compatibility of the monitoring unit can be ensured. Advantageously, if the monitoring unit is not active, the monitoring unit does not translate the address.
[0024] Preferably, the memory management unit (MMU) of the SoC transmits the desired physical address to the monitoring unit. The MMU is appropriately configured to manage the data in the storage unit. In the case where the processor unit of the SoC has an access expectation for certain data in the storage unit, the memory management unit conventionally retrieves the desired data from the storage unit according to the physical address. However, since these physical addresses are no longer necessarily correct after the address shift, the memory management unit preferably transmits the access expectation and thus the physical address to the monitoring unit within the scope of this method.
[0025] Preferably, according to a predetermined number of data blocks, according to the size of the data blocks, and according to the physical memory address of the error correction code, the desired physical address is translated into the actual physical address by the monitoring unit, and data blocks with the associated error correction codes are respectively stored for the predetermined number of data blocks. Appropriately according to the corresponding relationship, the monitoring unit inserts an additional storage area into the physical address space of the storage unit for the error correction code.
[0026] According to a particularly advantageous embodiment, the following predetermined number of data blocks is a power of two: data blocks with the associated error correction codes are respectively stored for the data blocks. For N data blocks, therefore, preferably N = 2 n, where n is a natural number. Appropriately, the sizes of the error correction code ECC are fractional powers of two (Zweierpotenzbruchteil) of 512 bits, particularly preferably 64 bits, 128 bits or 256 bits. For example, in the case of data transmission of 512 + 64 bits (that is, a 64-bit ECC data block is provided for each 512-bit data block), after N = 8 data pages, there can be one page with an error correction code ECC each. In the case of 512 + 128 bits, for example, after N = 4 data pages, there can be one ECC page each. The pages for the error correction code can be appropriately placed in the storage unit, for example, all at the start of the storage unit, or all at the end of the storage unit.
[0027] It is also conceivable that the number N of the following data blocks is selected as N = 2 n - 1: One ECC data block is stored for each of the said data blocks. In this case, compared with N = 2 n , appropriately, a simpler translation of the physical address into the actual address is obtained, but for this purpose, the storage location of the ECC pages is not utilized as fully as in the case of N = 2 n .
[0028] The error correction code ECC can also appropriately not be a complete fractional power of two of the cache line. This situation is particularly suitable in combination with N ≠ 2 n .
[0029] Advantageously, the monitoring unit is connected between the primary buffer memory or cache memory (L1 cache) and the secondary buffer memory or cache memory (L2 cache) of the system on a chip. In addition, the monitoring unit is preferably connected between the memory management unit MMU and the secondary buffer memory. Here, in addition to checking the main memory, the monitoring unit is particularly arranged to ensure other components, such as the tertiary buffer memory (L3 cache), the control unit of the main memory (DRAM Controller) and the corresponding wiring.
[0030] Preferably, the monitoring unit includes a code unit that creates an error correction code for a pre-given number of data blocks. In addition, the monitoring unit appropriately includes a main unit that is in a data transmission connection with the code unit. The main unit is particularly set up for addressing, reading, monitoring, correcting and forwarding data in or from the storage unit. Preferably, the code unit creates an error correction code with reference to the desired physical address of the corresponding data block. Thus, through the error correction code, not only can the incorrect data be identified, but also the incorrect addressing of the correct data can be appropriately identified.
[0031] Preferably, the code unit is connected between the primary buffer memory and the secondary buffer memory. Alternatively, the code unit may preferably also be connected between the processor unit of the system-on-chip and the primary buffer memory. In this case, the error correction code may suitably be generated and evaluated between the bus master and the primary cache. Thus, in particular, the primary cache and the memory management unit MMU can also be ensured, such that additional safeguarding of these components is preferably not required. Suitably, the main unit of the monitoring unit is connected between the primary buffer memory and the secondary buffer memory in this case and is connected corresponding to the code unit.
[0032] Preferably, the monitoring unit has a buffer memory. The monitoring unit thus suitably has its own internal buffer memory or cache. Via the internal buffer memory, the monitoring unit can suitably access the error correction code quickly. The internal buffer memory in particular includes N ECCs in each cache line, and these ECCs together result in a block size that is suitably 512 bits, and these bits are transferred from the secondary cache of the SoC to the storage unit per Burst, or vice versa.
[0033] Alternatively or additionally, the monitoring unit preferably uses a part of the buffer memory of the system-on-chip, in particular a part of the primary buffer memory. The monitoring unit can in particular be constructed more simply in this case. The ECC is then in particular a component of the primary cache line.
[0034] Particularly advantageously, the system-on-chip is used in a vehicle, in particular in a control device of the vehicle, such as in a driver assistance control device. In particular, the SoC can be set up to implement safety-critical functions of the vehicle, such as from driver assistance systems up to autonomous and fully autonomous driving. By means of the monitoring unit and the checking of the data according to the present method, safety regulations in the field of motor vehicles can suitably be met, in particular the regulations according to ISO 26262 and the automotive safety integrity level (ASIL). In particular, it can be ensured that in the event of an error, the SoC does not shut down but continues to operate normally.
[0035] The monitoring unit according to the invention is in particular set up in terms of program technology and / or in terms of hardware technology to carry out the method according to the invention; or the monitoring unit according to the invention has: means for carrying out the method according to the invention, in particular means for generating an error correction code for data to be stored in a storage unit, means for storing the error correction code in the storage unit, means for outputting the data requested from the storage unit, and means for carrying out an error correction method on the data requested from the storage unit based on the error correction code.
[0036] The computing unit (in particular a system-on-chip) according to the invention has a monitoring unit according to the invention that can be activated and deactivated (in particular by means of storage entries such as page table entries). The computing unit furthermore has an (internal) storage unit and / or an interface for connecting an (external) storage unit.
[0037] It is also advantageous to implement the method according to the invention in the form of a computer program or a computer program product having program code for performing all method steps, because this results in particularly low costs, especially if the control device used for the implementation is also used for other tasks and is thus already present. Suitable data carriers for providing the computer program are in particular magnetic, optical and electrical memories such as, for example, hard disks, flash memories, EEPROMs, DVDs and many more. Downloading the program via a computer network (Internet, Intranet, etc.) is also possible.
[0038] Other advantages and configurations of the invention result from this description and the attached drawings. Description of the Drawings
[0039] The invention is schematically illustrated on the basis of embodiments in the drawings and is described below with reference to the drawings.
[0040] Figure 1 A system-on-chip is schematically illustrated that is set up to execute a preferred embodiment of the method according to the invention.
[0041] Figure 2 A system-on-chip is schematically illustrated that is set up to execute a preferred embodiment of the method according to the invention. Detailed Description
[0042] In Figure 1 a system-on-chip SoC is schematically illustrated and the system-on-chip SoC is designated by 100. The system-on-chip SoC is set up to execute a preferred embodiment of the method according to the invention. The SoC 100 is used, for example, in a control device of a vehicle, for example for implementing safety-critical vehicle functions (for example during autonomous driving).
[0043] SoC 100 here includes a processor unit 110 configured as a multi-core processor and a storage unit 120, in particular a first-level buffer memory or cache memory 121 (L1 cache), a second-level buffer memory or cache memory 122 (L2 cache), and a main memory or working memory 123 configured as a DRAM (Dynamic Random Access Memory). As outlined by the dashed line, an external working memory 123 may also be involved, which is connected to the SoC via a corresponding interface.
[0044] A Memory Management Unit (MMU) 130 is provided to mediate between the processor unit 110 and the storage units 122, 123. To address data blocks of the memory components or storage units 122, 123, the processor unit 110 only knows virtual addresses or logical addresses, in particular, but does not know the following physical addresses: with which the memory components are controlled. The memory management unit MMU 130 is especially used to translate logical addresses into physical addresses.
[0045] In particular, the memory management unit 130 allows the processor unit 110 to always address the memory starting from, for example, address 0 without knowing the actual physical address. Since the memory management unit 130 is usually reconfigured when the task changes, each individual task can especially use the same starting address. This also suitably applies to data. In addition, the memory management unit 130 especially decouples the storage areas of tasks from each other. In particular, each task can only see "its" memory here. However, the storage area can also be shared by multiple tasks, such as the code of a library or data for exchange.
[0046] To determine the physical address from the logical address, the memory management unit 130 especially uses a table with the required data. The table is suitably located in the corresponding storage unit, especially in the main memory DRAM 123. A part of the table can be cached in the buffer memory 131 (the so-called Translation Lookaside Buffer (TLB)). The operation of the memory management unit 130 is thus greatly accelerated. The address conversion can be performed in pages of a fixed size (e.g., 4k bytes). For each such page, there is a Page Table Entry (PTE), which may also contain other information in addition to the physical address of the page in the memory, such as whether the page is to be cached, whether there is write protection, etc.
[0047] The primary buffer memory 121 typically stores 512 bits in a cache line. Code is mostly read into the processor unit 110 in chunks (e.g., also 512 bits) and then decoded for out-of-order execution. Data access to this can vary strongly. Signal processing instructions can be processed in parallel, for example up to 1024 bits, while individual bytes or even individual bits can also be manipulated. There is logic means in the form of a selection unit 111 (“byte / word selection”) so that only a small part of the cache line can be read or written.
[0048] To check the data in the memory units of the SoC, there is a monitoring unit 140 which is set up (especially in terms of program technology and / or hardware technology) to execute a preferred embodiment of the method according to the invention.
[0049] Advantageously, the monitoring unit 140 is modularly constructed and can be implemented at a suitable location in the SoC 100 such that especially no or at least hardly any changes or adaptations to the remaining components of the SoC 100 are necessary. In particular, it is not necessary to modify the memory units 121, 121, 123. Furthermore, the monitoring unit 140 performs its functions autonomously and independently such that especially no or at least hardly any adaptation of the software of the memory management unit 130 is necessary.
[0050] As shown in Figure 1 the monitoring unit 140 can advantageously be connected between the primary buffer memory 121 and the secondary buffer memory 122.
[0051] The monitoring unit 140 can be activated or deactivated by the SoC 100, for example by setting the corresponding bit in an entry (page table entry, PTE) of a memory page of the memory management unit 130.
[0052] If the monitoring unit 140 is activated, the monitoring unit 140 stores an error correcting code (ECC) for performing an error correction method in the memory unit (especially the main memory 123). For a pre-given number of data blocks of the memory unit 123, the data blocks with the associated error correcting code ECC are stored respectively.
[0053] If data in the memory unit 123 is to be accessed, the corresponding data and the associated error correcting code are addressed by the monitoring unit 140. Before the corresponding access, the monitoring unit 140 checks the addressed data with the addressed error correcting code and corrects the addressed data if necessary.
[0054] The monitoring unit 140 can, for example, have a main unit 141, a code unit 142, and its own buffer memory 143 (ECC cache). The code unit 142 is arranged to create an error correction code, in particular with reference to the physical address transmitted by the memory management unit 130 for the corresponding data block, such that in addition to the data with errors it is also possible to suitably identify incorrect addressing of correct data. The main unit 141 is in particular arranged to address, read, monitor, correct, and forward data. In particular, the main unit can insert additional write or read operations in order to load ECC data into the ECC cache 143 or to clear ECC data from the ECC cache 143. Suitably, this occurs if there are no requests from the L1 cache 121 and access to the main memory 120 is possible without conflicts. Another task of the unit 141 is to translate addresses, as described below.
[0055] With the aid of the buffer memory or ECC cache 143, the monitoring unit 140 can access the error correction code quickly. The ECC cache 143 contains in particular N ECCs in each cache line, and these N ECCs together result in a block size of, for example, 512 bits, which bits are then transferred in a burst from or to the secondary cache 122 or to the DRAM 123.
[0056] By inserting data blocks with error correction codes, in particular an address shift can occur such that the actual physical address in the storage unit 120 is different from the physical address transmitted or expected by the memory management unit 130 for the respective data or data block. For the memory management unit 130, in particular only the original physical address is also known in addition. The monitoring unit 140 manages the address shift and translates the desired physical address into the actual physical address.
[0057] Preferably, according to a pre-given number N of data blocks, according to the memory address or position of the error correction code, and according to the size G of the data block, the desired physical address is translated into the actual physical address, and data blocks with the respective error correction codes are stored for the pre-given number N of data blocks. Particularly advantageously, the pre-given number N of data blocks is a power of two, so that N = 2 n , where n is a natural number, and data blocks with the respective error correction codes are stored for the data blocks.
[0058] If in this case for the number N = 2 n a data block with an error correction code is arranged directly after each of the N data blocks, and if each data block has a size G in bytes, then in particular the following relationships result (each commented with C):
[0059] A BLOCK =(APHYS &(-N*G))+((A PHYS &(-N*G))>>ld(N)
[0060] A off = A PHYS &((-N*G)-1)
[0061] A DATA = A PHYS +((A PHYS &(-N*G))>>ld(N))
[0062] A ECC = A BLOCK +N*G+A off >>ld(N)
[0063] Wherein:
[0064] N: The number of ECCs associated with the cache line
[0065] = The number of data blocks as follows: After which an ECC block follows
[0066] G: The size of the data block in bytes
[0067] A PHYS : The expected physical address, especially the expected physical address of the memory management unit 130
[0068] A DATA : The actual physical address of the data belonging to A in the storage unit PHYS in the storage unit
[0069] A ECC : The address of the error correction code ECC belonging to A PHYS
[0070] A BLOCK : Auxiliary value, especially the address of the N + 1 page data block
[0071] A off : Auxiliary value, especially the offset within the N + 1 page data block
[0072] Id(x): Logarithmic binary.
[0073] The monitoring unit 140 appropriately inserts additional storage areas into the physical address space of the storage unit for the error correction code according to these relationships. The storage unit is, for example, the main memory 123 or the L2 cache 122. In particular, only for the first data area does A DATA = A PHYSThe address relationship. Due to the additional ECC data block, all other data areas are especially placed in the storage unit, so that A applies to these data areas DATA >A PHYS .
[0074] If the monitoring unit 140 is not activated, especially if the corresponding bit in the PTE of the MMU 130 is not activated, then especially no address translation is performed, that is to say A applies DATA =A PHYS .
[0075] Especially, the monitoring unit 140 can be activated and deactivated page by page, so that individual data pages are protected while other data pages are not. If not all of the data pages belonging before the ECC page are protected by the monitoring unit 140, this especially results in only using a part of the ECC page and wasting storage locations. Thus, it is appropriate to ensure that all of the data pages belonging before the ECC page are protected by the monitoring unit 140, or to ensure that all of the data pages belonging before the ECC page are not protected. If all of the data pages belonging before the ECC page are not protected, then the ECC page is appropriately completely free. In the case of the activated monitoring unit 140, the monitoring unit then does not have to be used for the address translation from A PHYS to A DATA either. In the case of the deactivated monitoring unit 140, however, this free ECC page can appropriately be used by the MMU 130 within the unprotected storage area.
[0076] The size G of each data block can especially also include multiple pages, appropriately including a power of two. A very large G may result in that only the area with all ECCs is still at the end of the storage unit, and the addresses of the data before this can be delivered 1:1 without translation.
[0077] However, appropriately, G is not chosen to be much larger than the storage page in order to achieve a high location of the data in the storage unit. If the data and the associated ECC and each DRAM page (different from the storage page of the MMU) match, this greatly accelerates the access. If such a high location and such an accelerated access are not necessary, then it may be appropriate to choose G so large as to obtain as large a 1:1 data area as possible.
[0078] If a specific data is to be accessed, the processor unit 110 transmits a corresponding query with the corresponding virtual address to the memory management unit 130. The memory management unit 130 then translates these virtual addresses into corresponding physical addresses and forwards the corresponding query to the monitoring unit 140. The monitoring unit 140 in turn translates the (expected) physical address into an actual physical address and addresses the corresponding data and the associated error correction code according to the actual physical address. The correspondingly verified and, if necessary, corrected data is then forwarded by the monitoring unit 140 to the level 1 buffer memory 121.
[0079] The access to the data can be a read access or can also be a write access. The data can in particular be data values, such as measurement values or control values, or can also be code to be executed. The level 1 buffer memory 121 includes, for example, an instruction cache (L1I-cache) for data in the form of executable code and a data cache (L1D-cache) for data in the form of data values.
[0080] The read access to the code can run as follows, for example:
[0081] The processor unit 110 fills the prefetch buffer by accessing the level 1 instruction cache (L1I cache). Since the processor unit 110 and the L1I cache are before the monitoring unit 140, they are not safeguarded together by the monitoring unit and suitably include their own security-enhancing measures, such as lockstep for the processor unit 110 and cyclic redundancy check (CRC) for the L1I cache.
[0082] In the case of a cache hit in the L1I cache, the access ends here and the corresponding data in the L1I cache is accessed. Simultaneously with the L1I access, the MMU 130 determines the physical memory address and passes the physical memory address to the monitoring unit 140 in the case of a cache miss in the L1I cache.
[0083] The monitoring unit 140 converts the expected physical address into an actual physical address and passes the read access to the level 2 cache 122. At the same time, the monitoring unit 140 searches for the associated error correction code ECC in the ECC cache 143.
[0084] In the case of a cache hit, the monitoring unit 140 verifies the data in the level 2 cache 122 and, if necessary, forwards the data to the L1I cache in a corrected manner. In the case of a cache miss, the monitoring unit 140 initiates additional level 2 cache read accesses for the data and N - 1 other ECCs and performs verification / correction when they arrive.
[0085] A read access to a data value can in particular operate similarly to a code read access, where in particular the L1 data cache (L1D cache) is used. Different from the L1I cache, which is safeguarded, for example, by means of a cyclic redundancy check CRC, the safeguarding for the L1D cache can in particular use an error correction code ECC so that data written that has not yet landed in the main memory 123 can be corrected if necessary. In addition, the access can include different word widths (1 bit, 8 bits, 16 bits, 32 bits, 64 bits, 128 bits, 256 bits), which the L1D cache can handle.
[0086] A write access to a data value can in particular operate as follows:
[0087] The processor unit 110 writes data with a corresponding word width (for example 1 bit, 8 bits, 16 bits, 32 bits, 64 bits, 128 bits) into the L1 data cache. In the case of an L1D cache hit, the process appropriately ends here. The cache line is in particular marked as "dirty", indicating that the cache block has been changed.
[0088] Using the L1D access, the MMU 130 determines the physical memory address and passes the physical memory address to the monitoring unit 140 in the case of an L1D cache miss. The monitoring unit 140 converts the desired physical address into the actual physical address and the associated ECC address.
[0089] First, similar to the description of the read access above, the monitoring unit 140 obtains data and / or ECC from the L2 cache 122. In particular, the monitoring unit 140 can first write additional L1D cache lines and / or ECC cache lines here. Alternatively, the corresponding L1D cache lines and / or ECC cache lines can also have been written prophylactically and not just at this point. The cache line can be overwritten with data at another address after the write.
[0090] The desired cache line is obtained, especially in the L1 cache 121, and the associated cache line with ECC is obtained in the ECC cache 143. Now, after the data is available, the data cache line is modified according to the write expectations of the processor unit 110U, and the associated ECC in the corresponding ECC cache line is recalculated. The two cache lines are appropriately marked as "dirty" to indicate that they have been changed.
[0091] The ECC cache 143 especially has the following size: the size can be between 5% and 10% of the size of the L1 cache 121. Since only ECC is stored in the ECC cache 143 especially without storing the data itself, the ECC cache 143 can especially be one Nth of the L1 cache 121. Since the ECC cache 143 stores N ECCs in each cache line in addition, cache misses are less likely compared to in the L1 cache 121. The location of the ECC is especially N times the location of the associated data. Thus, the possibility that the ECC is at a smaller and faster cache level than the associated data increases. The additional latency caused by ECC cache misses is therefore on average less than the latency of the data, so the miss rate of the ECC cache 143 is allowed to be greater than the miss rate of the L1 cache 121.
[0092] Alternatively, it is also conceivable that the monitoring unit 140 does not have its own buffer memory 143, but uses a part of the buffer memory of the SoC 100, as will be described subsequently with respect to Figure 2 as set forth.
[0093] Figure 2 A corresponding system-on-chip is schematically shown, where in Figure 1 and Figure 2 the same reference numerals indicate the same or functionally equivalent elements.
[0094] As shown in Figure 2 in this case, the monitoring unit 140 only includes the main unit 141 and the code unit 142. In the manner outlined by reference numeral 144, the monitoring unit 140 uses a part of the level-1 buffer memory 121 as a cache.
[0095] In addition, in this case, the code unit 142 is connected between the processor unit 110 and the level-1 buffer memory 121, especially between the selection unit 111 and the L1 cache 121.
[0096] In this case, ECC is generated and evaluated by code unit 142 between the bus master and the L1 cache 121. In this case, the master unit 141 in particular takes over the storage and reading of ECC in separate address areas.
[0097] In this case, the signal path can also be protected against the master unit 141, in particular the L1 cache 121 and the MMU 130, so that a separate safeguard for the L1 cache 121 is no longer necessary.
Claims
1. A method for verifying data in a storage unit (120) of a system on a chip (100), wherein in the system on a chip (100), a monitoring unit (140) is implemented, and the monitoring unit (140) can be activated or deactivated by the system on a chip (100), wherein, if the monitoring unit (140) is activated, the monitoring unit (140) stores error correction codes for performing an error correction method in the storage unit (120), such that data blocks with their respective error correction codes are stored for a pre - given number of data blocks of the storage unit (120), wherein, if data in the storage unit (120) is to be accessed, the monitoring unit (140) addresses the corresponding data and the associated error correction codes, and before the corresponding access, checks the addressed data with the addressed error correction codes and corrects the addressed data if necessary, wherein the monitoring unit (140) is connected between a primary buffer memory (121) and a secondary buffer memory (122) of the system on a chip (100).
2. The method according to claim 1, wherein, in order to address the data, the monitoring unit (140) translates a desired physical address into an actual physical address.
3. The method according to claim 2, wherein, a memory management unit (130) of the system on a chip (100) transmits the desired physical address to the monitoring unit (140).
4. The method according to claim 2 or 3, wherein, according to the pre - given number of data blocks, according to the physical memory address of the error correction code and according to the size of the data block, the desired physical address is translated into the actual physical address, and data blocks with their respective error correction codes are stored for the pre - given number of data blocks.
5. The method according to any one of claims 1 to 3, wherein, the pre - given number of the following data blocks is a power of two: for the data blocks, data blocks with their respective error correction codes are stored respectively.
6. The method according to any one of the above claims, wherein, the monitoring unit (140) is also connected between the memory management unit (130) and the secondary buffer memory (122).
7. The method according to any one of claims 1 to 3, wherein, the monitoring unit (140) includes a code unit (142), and the code unit (142) creates the error correction codes for the pre - given number of data blocks.
8. The method according to claim 7, wherein, the code unit (142) creates the error correction codes with reference to the physical address of the corresponding data block.
9. The method according to claim 7, wherein, the code unit (142) is connected between the primary buffer memory (121) and the secondary buffer memory (122), or between a processor unit (110) of the system on a chip (100) and the primary buffer memory (121).
10. The method according to any one of claims 1 to 3, wherein, The monitoring unit (140) further has a buffer memory (143) and / or uses a part of the buffer memory of the system-on-chip (100).
11. The method according to claim 10, wherein, when the monitoring unit (140) uses a part of the buffer memory of the system-on-chip (100), the monitoring unit (140) uses a part of the primary buffer memory (121).
12. The method according to any one of claims 1 to 3, wherein, the system-on-chip (100) is used in a vehicle.
13. A monitoring unit (140) configured to perform all method steps of the method according to any one of claims 1 to 12.
14. A computing unit (100) having an activatable and deactivatable monitoring unit (140) for checking data in a storage unit (120), wherein the monitoring unit (140) has: - means for generating an error correction code for data to be stored in the storage unit (120), - means for storing the error correction code in the storage unit (120), - means for outputting requested data from the storage unit (120), - means for performing an error correction method on the requested data from the storage unit (120) based on the error correction code, wherein, the monitoring unit (140) is connected between the primary buffer memory (121) and the secondary buffer memory (122) of the computing unit (100).
15. The computing unit (100) according to claim 14, wherein, the computing unit (100) is a system-on-chip.
16. The computing unit (100) according to claim 14, wherein, the monitoring unit (140) is activatable and deactivatable by a storage entry.
17. The computing unit (100) according to any one of claims 14 to 16, configured to perform all method steps of the method according to any one of claims 1 to 12.
18. A computer program product comprising a computer program which, when executed on a computing unit (140), causes the computing unit (140) to perform all method steps of the method according to any one of claims 1 to 12.
19. A machine-readable storage medium having stored thereon a computer program which, when executed on a computing unit (140), causes the computing unit (140) to perform all method steps of the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Memory system performing error correction of address mapping table and method of controlling same
CN108073470A
Memory module having error correction logic
US20150278017A1