Safe electrification method, system, chip and electronic device

By combining multiple configurations of microcontrollers, one-time programmable memory, and electrically erasable read-only memory, the safety and reliability issues of power-on configuration of automotive-grade chips are solved, and safe and reliable startup of system-on-a-chip is achieved.

CN114356410BActive Publication Date: 2026-02-03SMARTSENS TECH (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111014195.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-31
Publication Date
2026-02-03
Estimated Expiration
2041-08-31

AI Technical Summary

Technical Problem

In the existing technology, automotive-grade chips rely on one-time programmable memory to perform power-on configuration, which has problems such as poor safety, weak stability and insufficient reliability. In particular, when the memory fails, the chip cannot start normally, resulting in safety risks.

Method used

A safe power-up method combining a microcontroller, a one-time programmable memory, and an electrically erasable read-only memory is adopted. By configuring the chip registers multiple times, the register configuration can still be successfully completed even if any one of them fails, thus achieving safe and reliable power-up of the system-on-a-chip.

Benefits of technology

It ensures the safety and reliability of the system-on-a-chip throughout the entire process from power-on to normal operation, meets the high requirements of automotive-grade chips, and avoids safety hazards caused by configuration command errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114356410B_ABST
    Figure CN114356410B_ABST
Patent Text Reader

Abstract

The application provides a secure power-on method and system of a system-on-chip, a chip and an electronic device. The secure power-on method specifically comprises: triggering a read-only memory in a microcontroller to configure a chip register in a case where a one-time programmable memory cannot configure the chip register; triggering an electrically erasable read-only memory to configure the chip register in a case where the microcontroller cannot normally start; and triggering the system-on-chip to perform a reset start and enter a normal working state in a case where the electrically erasable read-only memory cannot configure the chip register. Through the technical scheme provided in the application, the microcontroller, the one-time programmable memory and the electrically erasable read-only memory are simultaneously used to control the power-on process of the system-on-chip, especially the register configuration link in the power-on process, thereby guaranteeing the safety and reliability of the whole power-on process of the system-on-chip.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of chip power-on configuration, and particularly discloses a safe power-on method, a system, a chip, an electronic device and a readable storage medium. BACKGROUND

[0002] With the rapid development of integrated circuit technology, the circuit functions in the chip are becoming more and more complex, and the functions integrated in a single chip are becoming more and more numerous. In order to adapt to the needs of the complexity of the chip system, the chip design has developed from a single large-scale integrated circuit to a multi-functional IP integrated system. Among them, the system on chip (SOC) chip has become the main solution to replace the traditional integrated circuit and has become an inevitable trend of the development of current microelectronic chip technology.

[0003] The system on chip usually integrates a processor, a register, a memory and various interface control modules, and various functional modules are combined together according to a certain connection relationship to form a complex system on chip. According to different use scenarios and specification standards, the system on chip can be divided into consumer-grade chips, industrial-grade chips, automotive-grade chips and military-grade chips. According to the classification of specification standards, the requirements of the automotive-grade chip are only second to the military-grade chip, and it needs to face variable and harsh environments in application, and puts forward very high requirements on safety, reliability and stability.

[0004] In the prior art, the automotive-grade chip usually uses a one-time programmable memory to store the default configuration information of the chip: in the process of power-on startup of the automotive-grade chip, the chip can automatically read data information from the one-time programmable memory and configure the chip to enter a normal working state. However, when the one-time programmable memory is wrong or cannot work normally, the automotive-grade chip will face the dilemma of configuration instruction error or even unable to start normally, which will cause the user to face the risk of reduced user experience and even safety risk. Therefore, it is urgent to propose a more secure, stable and reliable power-on method to realize the safe power-on and power-on configuration of the automotive-grade chip. SUMMARY

[0005] In order to solve the problems of poor safety, weak stability and insufficient reliability caused by the fact that the system on chip in the prior art only relies on the one-time programmable memory to perform the power-on configuration process, the present application provides a safe power-on method, a system, a chip, an electronic device and a readable storage medium of a system on chip.

[0006] In a first aspect of the present application, a safe power-on method of a system on chip is provided, wherein the system on chip includes a microcontroller, a chip register, a one-time programmable memory and an electrically erasable read-only memory.

[0007] The safe power-on method comprises the following steps:

[0008] In the case of receiving the power-on instruction, the one-time programmable memory configures the chip register for the first time;

[0009] In the case that the one-time programmable memory completes the configuration of the chip register, the system-level chip implements the first reset start and the initialization of the microcontroller;

[0010] The microcontroller triggers the one-time programmable memory to configure the chip register for the second time; and / or

[0011] The microcontroller triggers the electrically erasable read-only memory to configure the chip register for the third time;

[0012] In the case that the electrically erasable read-only memory completes the configuration of the chip register, the system-level chip implements the second reset start and enters the normal working state;

[0013] Wherein:

[0014] In the case that the one-time programmable memory cannot configure the chip register, the read-only memory in the microcontroller is triggered to configure the chip register.

[0015] In a possible implementation of the first aspect, in the case that the microcontroller cannot start normally, the electrically erasable read-only memory is triggered to configure the chip register;

[0016] In the case that the electrically erasable read-only memory cannot configure the chip register, the system-level chip is reset for the second time and enters the normal working state.

[0017] In a possible implementation of the first aspect, the power-on operation is performed on the system-level chip to realize the sending of the power-on instruction to trigger the one-time programmable memory.

[0018] In a possible implementation of the first aspect, the microcontroller triggers the one-time programmable memory to configure the chip register for the second time by writing the first switch register;

[0019] The microcontroller triggers the electrically erasable read-only memory to configure the chip register for the third time by writing the second switch register.

[0020] In a possible implementation of the first aspect, in the process of configuring the chip register by any one of the one-time programmable memory, the electrically erasable read-only memory and the read-only memory in the microcontroller, the configuration information for configuring the chip register comprises the working instruction of the system-level chip.

[0021] In a possible implementation of the first aspect, in the process of configuring the chip register by any one of the one-time programmable memory, the electrically erasable read-only memory and the read-only memory in the microcontroller, the current configuration information for configuring the chip register completely covers the historical configuration information of the chip register.

[0022] In a possible implementation of the first aspect, when the one-time programmable memory fails to configure the chip register, the safe power-on method further includes:

[0023] The system-level chip is configured by the read-only memory in the microcontroller to implement the first reset start and the initialization of the microcontroller.

[0024] The microcontroller triggers the electrically erasable read-only memory to configure the chip register for the third time.

[0025] When the electrically erasable read-only memory completes the configuration of the chip register, the system-level chip implements the second reset start and enters the normal working state.

[0026] In a possible implementation of the first aspect, the read-only memory in the microcontroller modifies the data of the read-only memory by means of an engineering change command to configure the chip register.

[0027] In a possible implementation of the first aspect, when the one-time programmable memory completes the configuration of the chip register and the microcontroller fails to start normally, the safe power-on method further includes:

[0028] The one-time programmable memory triggers the electrically erasable read-only memory to configure the chip register for the third time.

[0029] When the electrically erasable read-only memory completes the configuration of the chip register, the system-level chip implements the second reset start and enters the normal working state.

[0030] In a possible implementation of the first aspect, the one-time programmable memory triggers the electrically erasable read-only memory to configure the chip register by writing a third switch register, the third switch register being associated with the working state of the electrically erasable read-only memory.

[0031] In a possible implementation of the first aspect, when the electrically erasable read-only memory fails to configure the chip register and the microcontroller triggers the one-time programmable memory to configure the chip register for the second time, the safe power-on method further includes:

[0032] The system-level chip implements second reset starting and entering a normal working state according to configuration information of the one-time programmable memory on the chip register.

[0033] The second aspect of the present application provides a safe power-on system of a system-level chip, applied to the safe power-on method provided in the first aspect.

[0034] The safe power-on system comprises:

[0035] The first judging unit is configured to judge whether the one-time programmable memory can configure the chip register, and trigger the read-only memory in the microcontroller to configure the chip register in the case that the one-time programmable memory cannot configure the chip register.

[0036] The second judging unit is configured to judge whether the microcontroller can start normally, and trigger the electrically erasable read-only memory to configure the chip register in the case that the microcontroller cannot start normally.

[0037] The third judging unit is configured to judge whether the electrically erasable read-only memory can configure the chip register, and the system-level chip implements second reset starting and enters a normal working state through the microcontroller in the case that the electrically erasable read-only memory cannot configure the chip register.

[0038] In a possible implementation of the second aspect, the safe power-on system comprises a chip and an electrically erasable read-only memory, and the microcontroller, the chip register and the one-time programmable memory are integrated on the system-level chip.

[0039] The electrically erasable read-only memory is in communication connection with the microcontroller, the chip register and the one-time programmable memory.

[0040] The third aspect of the present application provides a system-level chip, which executes a chip power-on process according to the safe power-on method provided in the first aspect.

[0041] The fourth aspect of the present application provides an electronic device, comprising:

[0042] The memory is configured to store a processing program.

[0043] The processor is configured to execute the processing program to implement the safe power-on method provided in the first aspect.

[0044] The fifth aspect of the present application provides a readable storage medium, which stores a processing program, and the processing program is executed by a processor to implement the safe power-on method provided in the first aspect.

[0045] Compared with the prior art, the application has the following beneficial effects:

[0046] By using the microcontroller, the one-time programmable memory and the electrically erasable read-only memory simultaneously, the power-on process of the system-on-chip and especially the register configuration link in the power-on process are controlled. Regardless of any fault, the register configuration in the power-on process of the system-on-chip can be smoothly performed, and the safety and reliability of the whole process from power-on to the normal working state of the system-on-chip are ensured. BRIEF DESCRIPTION OF DRAWINGS

[0047] Other features, objects and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments with reference to the attached drawings:

[0048] Figure 1 According to the embodiment of the application, a flowchart of a safe power-on method for a system-on-chip is shown;

[0049] Figure 2 According to the embodiment of the application, a flowchart of obtaining a power-on instruction for a system-on-chip is shown;

[0050] Figure 3 According to the embodiment of the application, a flowchart of a safe power-on method for a system-on-chip is shown when the one-time programmable memory cannot configure the chip register and the read-only memory in the microcontroller completes the configuration of the chip register;

[0051] Figure 4 According to the embodiment of the application, a flowchart of a safe power-on method for a system-on-chip is shown when the one-time programmable memory completes the configuration of the chip register and the microcontroller cannot be normally started;

[0052] Figure 5 According to the embodiment of the application, a flowchart of a safe power-on method for a system-on-chip is shown;

[0053] Figure 6 According to the embodiment of the application, a structural diagram of a system-on-chip with a safe power-on system is shown. DETAILED DESCRIPTION

[0054] The present application will be described in detail below with reference to specific embodiments. The following embodiments will help those skilled in the art to further understand the present application, but do not limit the present application in any form. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present application. These all belong to the protection scope of the present application.

[0055] As used herein, the term "includes" and its variants are meant to be open-ended and mean "comprising." The term "or" means "and / or" unless expressly stated otherwise. The term "based on" means "based, at least in part, on." The terms "one example embodiment" and "an embodiment" mean "at least one example embodiment." The term "another embodiment" means "at least one additional embodiment." The terms "a first," "a second," etc. can refer to different or the same objects. Other explicitly and implicitly recited definitions can also be found below.

[0056] In order to solve the problem that the system on chip in the prior art relies on the one-time programmable memory to perform the power-on configuration process only, when the one-time programmable memory fails, the system on chip cannot be started normally, and then it is difficult to meet the safety, reliability and stability required by the automotive-grade chip. The present application proposes a safe power-on method, system, chip, electronic device and readable storage medium of a system on chip. The microcontroller, one-time programmable memory and electrically erasable read-only memory are used at the same time to control the power-on process of the system on chip, especially the register configuration link in the power-on process. No matter which one fails, it can ensure that the register configuration of the system on chip in the power-on process can be smoothly implemented, and then the safety and reliability of the whole process from power-on to the system on chip entering the normal working state smoothly are ensured.

[0057] Specifically, in some embodiments of the present application, a safe power-on method of a system on chip is proposed. It can be understood that in the above-mentioned embodiments, the system on chip (safe power-on system) can include a microcontroller, a chip register, a one-time programmable memory and an electrically erasable read-only memory.

[0058] In the system on chip involved in the present application, specifically: the microcontroller can be integrated with a central processing unit, a random access memory, a read-only memory, a timing counter and a variety of input and output interfaces to form a chip-level computer, providing different combinations of control for different application occasions, and playing a core leading role in the system on chip involved in the present application.

[0059] The chip register can be composed of flip-flops, gate circuits and other electronic components, and has the functions of receiving data, storing data and outputting data, and is used to realize the specific application functions of the system-on-chip, such as general-purpose registers that can be used to store operands, addresses of operands or intermediate structures, instruction registers that can be used to store the instructions currently being executed, and the like. It can be understood that, for the chip register, it can only receive data when it receives the "store instruction"; similarly, it can only output data when it receives the "read instruction". In the system-on-chip involved in the embodiment, the number of chip registers, the types of chip registers corresponding to the chip registers, and the specific functions to be realized by the chip registers are not limited.

[0060] It can be understood that, in order to adapt to the needs of different customers and different functions, a plurality of registers can be provided in the system-on-chip to set various implementation functions or parameters of the system-on-chip, and different registers need to be configured according to different needs after the system-on-chip is powered on, and such a process is referred to as initialization configuration of the chip register. The one-time programmable memory and the electrically erasable read-only memory can serve the initialization configuration of the chip register, and the one-time programmable memory and the electrically erasable read-only memory both store pre-burned register configuration information in the interior, and the register configuration information can include the configuration of the chip normal working instruction and the like. For example, when the system-on-chip is applied to an image sensor, the above-mentioned register configuration information can include a pixel exposure mode, a readout mode, a selection of an exposure mode, and the like, to configure the correct chip working state. It can be understood that the one-time programmable memory and the electrically erasable read-only memory both belong to read-only memories, and the stored configuration information will not disappear due to power-off of the chip; the difference between the two is that the one-time programmable memory can only be burned once, and the configuration information cannot be changed and cleared again after the burning is completed, while the electrically erasable read-only memory supports multiple burnings to realize on-demand updating of the configuration information.

[0061] Based on the understanding of the composition structure of the system-on-chip, the safe power-on method applied to the system-on-chip will be described below.

[0062] Specifically, Figure 1 According to the embodiment of the present application, a flowchart of a safe power-on method is shown:

[0063] Step 100: In the case of receiving a power-on instruction, the one-time programmable memory configures the chip register. The generation and acquisition of the power-on instruction will be described below.

[0064] It can be understood that, in the case of receiving the power-on instruction, it is indicated that the current system-on-chip is in the power-on process, the chip register can be configured for the first time by the one-time programmable memory, and the configuration information can cover the configuration of the chip normal working instruction and the like.

[0065] Step 200: In the case that the one-time programmable memory completes the configuration of the chip register, the system-on-chip implements the first reset start and the initialization of the microcontroller.

[0066] It can be understood that, in the above step 200, after the chip register is configured by the one-time programmable memory, the first reset of the system-on-chip is implemented, that is, the first reset start; at the same time, the initialization of the microcontroller is implemented. The initialization operation of the microcontroller can include the initialization of global variables and / or static variables, the initialization of the stack, and the initialization of the library function, and the like, which are not limited herein.

[0067] Step 300: The microcontroller triggers the one-time programmable memory to configure the chip register for the second time.

[0068] Step 400: The microcontroller triggers the electrically erasable read-only memory to configure the chip register for the third time.

[0069] It can be understood that, in an embodiment, in the above steps 300 to 400, after the initialization of the microcontroller is completed, the register configuration of the chip register is performed by sequentially triggering the one-time programmable memory and the electrically erasable read-only memory, and the configuration information can cover the configuration of the chip normal working instruction and the like. The configuration items of the one-time programmable memory and the electrically erasable read-only memory for the chip register can be the same or different. The specific explanation of the configuration content will be described later. In other embodiments, only step 300 can be performed to trigger the one-time programmable memory to configure the chip register for the second time, and only step 400 can be performed to trigger the electrically erasable read-only memory to configure the chip register for the third time, which can be set according to actual needs. The possible cases of the corresponding specific working mode will be specifically described in the subsequent steps.

[0070] Step 500: In the case that the electrically erasable read-only memory completes the configuration of the chip register, the system-on-chip implements the second reset start and enters the normal working state.

[0071] It can be understood that, after the electrically erasable read-only memory completes the configuration of the chip register, the system-on-chip is reset again, that is, the second reset start. The reset here refers to the configuration of the system-on-chip normal working state information which is modified, and in this state, the system-on-chip completes the entire power-on process and can carry out normal work.

[0072] It can be understood that the above steps 100 to steps 500 introduce the basic power-on process of the system-on-chip, and the specific implementation of some steps will be further described below:

[0073] Further, in some possible implementations of the above steps 100 to steps 500, before step 100 is implemented, Figure 2 A flowchart for obtaining a power-on instruction is shown, which can be applied to the above step 100. As shown in FIG. 2, it specifically includes:

[0074] Step 001: Perform a power-on start operation on the system-on-chip. It can be understood that when the state of the system-on-chip changes from the sleep state to the power-on state, a series of initialization operations need to be performed, including but not limited to testing the memory, importing basic configuration data to the memory, initializing the register, initializing various hardware, etc. These operations can be collectively considered as the power-on reset operation of the system-on-chip, which will not be described here.

[0075] Step 002: In the case that the system-on-chip is in the power-on start state, the sending of the power-on instruction is implemented to trigger the one-time programmable memory. It can be understood that during the power-on start process of the microprocessor, for example, the level changes from low to high, thereby triggering the corresponding control module to generate the corresponding power-on instruction to trigger the one-time programmable memory.

[0076] Further, in some possible implementations of the above steps 300 to steps 400, the microcontroller can trigger the one-time programmable memory and the electrically erasable read-only memory by writing specific registers, so that the one-time programmable memory and the electrically erasable read-only memory configure the chip registers.

[0077] Specifically, for example, the one-time programmable memory can correspond to a first switch register, and the first switch register is related to the working state of the one-time programmable memory. When the first switch register detects that it receives a write instruction, it controls the one-time programmable memory to start configuring the chip registers according to the configuration information burned by itself through signal transmission. Similarly, the electrically erasable read-only memory can also be corresponded to a second switch register in the same way. The microcontroller can control the configuration process of the one-time programmable memory and the electrically erasable read-only memory through the specific registers such as the first switch register and the second switch register.

[0078] It is understandable that, in steps 300 to 400 above, in one embodiment, the microcontroller sequentially controls the one-time programmable memory and the electrically erasable read-only memory to configure the chip registers. This is because, during the chip register configuration process, the current configuration information configured for the chip registers completely overwrites the historical configuration information of the chip registers. In other words, the chip configuration information executed by the electrically erasable read-only memory later will overwrite the configuration information of the one-time programmable memory previously. Since the configuration information programmed into the one-time programmable memory is fixed and cannot be changed, it is impossible to update it in a timely manner when the system-on-a-chip has new configuration requirements. At this time, the characteristic of the electrically erasable read-only memory that allows modification of the programmed information can be utilized to program new configuration information that meets the requirements of the system-on-a-chip, thereby achieving support for the configuration update requirements of the system-on-a-chip.

[0079] Furthermore, in the above possible implementations, the electrically erasable read-only memory (ERM) can be fabricated on an external programmable gate array (FPGA). Users can choose whether to enable the ERM configuration operation based on actual needs. For example, for some system-on-a-chip (SoC), the configuration information currently burned into the one-time programmable memory (IPM) is sufficient for normal use, meaning the programming and rewriting functions supported by the ERM are not required. In this case, the ERM can be shut down. In the aforementioned safe power-on method, step 400 only needs to be skipped, and the SoC can directly perform a second reset and enter normal operating mode.

[0080] As can be seen from the foregoing embodiments, the one-time programmable memory (IPM), the electrically erasable read-only memory (ERM), and the read-only memory in the microcontroller can all perform configuration operations on the chip registers. When the IPM, ERM, and microcontroller are all in normal working condition, the entire safe power-on process for the system-on-a-chip (SoC) can be achieved by following steps 100 to 500. Even when any one of the IPM, ERM, or microcontroller malfunctions and cannot sequentially execute steps 100 to 500, the technical solution provided in this application can still achieve the entire safe power-on process for the SoC. The following will specifically describe this technical solution in application scenarios where the IPM, ERM, and microcontroller malfunction and cannot perform their functions.

[0081] In some other possible embodiments of this application, Figure 3 This diagram illustrates a safe power-up process for a system-on-a-chip (SoC) where chip registers cannot be configured in a one-time programmable memory. The process includes:

[0082] In step 1100, the system-on-a-chip configures the chip registers through the read-only memory in the microcontroller, thereby achieving the first reset and startup and the initialization of the microcontroller. Referring to the descriptions of steps 001 to 002 above, since the read-only memory in the microcontroller has already completed the chip register configuration operation before determining whether the one-time programmable memory can perform the register configuration task, the system-on-a-chip can directly execute the corresponding reset and startup operation at this point.

[0083] In step 1200, the microcontroller triggers the electrically erasable read-only memory to configure the chip registers. It is understood that the specific implementation of the triggering operation in step 1200 is consistent with the triggering operation implementation in the aforementioned steps 300 or 400, and will not be repeated here.

[0084] Step 1300: After the electrically erasable read-only memory completes the configuration of the chip registers, the system-on-a-chip performs a second reset and boots up, and enters normal working state.

[0085] It is understood that, in the above embodiments, when the one-time programmable memory malfunctions or fails, it is only necessary to change the layout corresponding to the read-only memory in the microcontroller and re-execute the tape-out. The read-only memory in the microcontroller is used to replace the one-time programmable memory for register configuration after power-on. After configuration, the chip is reset and the microcontroller is initialized. The process of changing the layout corresponding to the read-only memory can be implemented through Engineering Change Order (ECO). Those skilled in the art can modify the data of the read-only memory through ECO to configure the chip registers, which will not be elaborated here.

[0086] It is understood that, in the above embodiments, the judgment conditions for determining whether the one-time programmable memory has malfunctioned or failed are not limited. It can be a method of observing whether the chip register has completed the relevant configuration within a preset period, which can be achieved by external detection equipment, or other feasible methods. Those skilled in the art can choose appropriate judgment conditions to make judgments according to actual needs.

[0087] In some other possible embodiments of this application, Figure 4 This diagram illustrates a safe power-up process for a system-on-a-chip (SoC) when the one-time programmable memory has completed configuring the chip registers and the microcontroller fails to boot normally. The process includes:

[0088] Step 2100: The one-time programmable memory triggers the electrically erasable read-only memory to perform the third configuration of the chip registers. It is understood that step 2100 can be executed following step 100. The specific implementation of the triggering operation in step 2100 is the same as the triggering operation in steps 300 or 400, and will not be repeated here.

[0089] Step 2200: After the electrically erasable read-only memory completes the configuration of the chip registers, the system-on-a-chip performs a reset and boots up and enters normal working state.

[0090] Understandably, when a microcontroller malfunctions or fails, it cannot release the clock signal or perform initialization operations. In this state, after the one-time programmable memory is powered on and configured, the electrically erasable read-only memory (EROM) register configuration operation can be triggered directly. After the EROM register configuration is completed, the system-on-a-chip (SoC) skips the reset and startup phase and directly enters the normal working state.

[0091] It is understood that, in the above embodiments, the judgment conditions for determining whether the microcontroller has malfunctioned or failed are not limited. It can be to observe whether the microcontroller is always in an unresponsive state within a preset period. This can be done by external detection equipment, internal system detection equipment, or other feasible methods. Those skilled in the art can choose appropriate judgment conditions according to actual needs.

[0092] Specifically, the one-time programmable memory triggers the electrically erasable read-only memory to configure the chip register by writing to the third switch register. For example, the electrically erasable read-only memory can correspond to the third switch register, which is related to the working state of the electrically erasable read-only memory. When the third switch register detects that it has received a write command, it controls the electrically erasable read-only memory to start configuring the chip register according to the configuration information it has burned in through signal transmission.

[0093] In some other possible embodiments of this application, when the electrically erasable read-only memory (EROM) cannot configure chip registers, for example, when the EROM on a programmable gate array is in a turned-off state, a secure power-up method for a system-on-a-chip may include:

[0094] The system-on-a-chip (SoC) performs a reset and boots up and enters normal operating mode based on the configuration information of the chip registers in the one-time programmable memory.

[0095] Understandably, during the power-on process, the microcontroller will determine whether the electrically erasable read-only memory (EROM) has been successfully triggered. If the EROM is off or in other situations, skipping these updates and optimizations may result in a poor user experience when using the functions, but it will not affect the normal reset, startup, and normal operation of the system-on-a-chip. Therefore, the step of configuring the chip registers with the EROM can be skipped directly, without affecting the stability of the entire safe power-on process of the system-on-a-chip.

[0096] Specifically, Figure 5 This diagram illustrates a complete safe power-up process for a system-on-a-chip (SoC), covering the subsequent configuration process when any one of the one-time programmable memory (IPM), electrically erasable read-only memory (ERM), or microcontroller fails or malfunctions. It demonstrates that by simultaneously using the microcontroller, IPM, and ERM, the power-up process of the SoC, particularly the register configuration stage, is controlled. Regardless of the failure of any one of these components, the register configuration during the power-up process can be successfully performed, effectively ensuring the safety and reliability of the SoC from power-up to successful entry into normal operating conditions, meeting the relevant specifications for automotive-grade chips.

[0097] In some embodiments of this application, a system-on-a-chip (SoC) safe power-on system is also provided, applied to the safe power-on method involved in the above embodiments, wherein... Figure 6 A schematic diagram of a system-on-a-chip (SoC) equipped with a safe power-on system is shown, including a microcontroller 010, a chip register 020, a one-time programmable memory 030, and an electrically erasable read-only memory 040.

[0098] like Figure 6 As shown, this type of safe power-on system includes:

[0099] The first judgment unit 031 is used to determine whether the one-time programmable memory 030 can configure the chip register 020, and if the one-time programmable memory 030 cannot configure the chip register, it triggers the read-only memory in the microcontroller 010 to configure the chip register. The function of the first judgment unit 031 can be implemented using a detection device external to the system-on-a-chip.

[0100] The second judgment unit 011 is used to determine whether the microcontroller 010 can start normally, and if the microcontroller 010 cannot start normally, it triggers the electrically erasable read-only memory 040 to configure the chip register 020. The function of the second judgment unit 011 can be implemented by means of detection equipment outside the system-on-a-chip, or by detection equipment inside the system-on-a-chip.

[0101] The third judgment unit 041 is used to determine whether the electrically erasable read-only memory 040 can configure the chip register 020. If the electrically erasable read-only memory 040 cannot configure the chip register, the system-on-a-chip (SoC) is reset and booted up via the microcontroller, entering normal operating mode. The electrically erasable read-only memory may be in a disabled state when it cannot configure the chip register. In some embodiments of this application, the function of the third judgment unit 041 can be achieved by judging the state of the electrically erasable read-only memory.

[0102] It is understood that the various functional modules in the above-mentioned safe power-on system perform the same steps and procedures as the safe power-on method in the aforementioned embodiments, and will not be described in detail here.

[0103] In one embodiment, the safe power-on system includes a chip and an electrically erasable read-only memory (EROM). The microcontroller, the chip registers, and the one-time programmable memory are all integrated on the chip. The EROM can be integrated on a field-programmable gate array (FPGA) external to the chip. The EROM is communicatively connected to the microcontroller, the chip registers, and the one-time programmable memory. Here, the chip and the EROM can be considered as collectively constituting a system-on-a-chip (SoC).

[0104] In some embodiments of this application, a system-on-a-chip (SoC) is also provided. This SoC executes the chip power-up process according to the safe power-up method provided in the foregoing embodiments, and can meet the relevant requirements for automotive-grade chips.

[0105] In some embodiments of this application, an electronic device is also provided. This electronic device includes a memory and a processor, wherein the memory stores a processing program, and the processor executes the processing program according to instructions. When the processor executes the processing program, the safe power-on method described in the foregoing embodiments is implemented. For example, the aforementioned electronic device may be an in-vehicle device, including an in-vehicle image sensor, or other devices.

[0106] The technical solutions proposed in this application relate to methods, apparatus, systems, chips, electronic devices, computer-readable storage media, and / or computer program products. The computer program product may include computer-readable program instructions for performing various aspects of this disclosure.

[0107] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination thereof. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0108] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.

[0109] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, etc., and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.

[0110] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0111] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0112] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0114] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or technical improvements to the embodiments in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

Claims

1. A secure power-on method for a system-on-a-chip, the system-on-a-chip comprising a microcontroller, chip registers, a one-time programmable memory, and an electrically erasable read-only memory; Its features are, The safe power-on method includes: Upon receiving a power-on command, the one-time programmable memory performs the first configuration of the chip registers; When the one-time programmable memory completes the configuration of the chip registers, the system-on-a-chip performs its first reset and startup, as well as the initialization of the microcontroller. The microcontroller triggers the one-time programmable memory to configure the chip registers a second time; and / or, the microcontroller triggers the electrically erasable read-only memory to configure the chip registers a third time; When the electrically erasable read-only memory completes the configuration of the chip registers, the system-on-a-chip performs a second reset and boots up, and enters normal operating mode. in: If the one-time programmable memory cannot configure the chip register, the read-only memory in the microcontroller is triggered to configure the chip register; In the event that the microcontroller fails to start normally, the one-time programmable memory can trigger the electrically erasable read-only memory to configure the chip registers; If the electrically erasable read-only memory cannot configure the chip registers, the microcontroller can directly perform the second reset and start up to enter normal working state.

2. The safe power-on method as described in claim 1, characterized in that, A power-on startup operation is performed on the system-on-a-chip to issue the power-on command, thereby triggering the one-time programmable memory.

3. The safe power-on method as described in claim 1, characterized in that, The microcontroller triggers the one-time programmable memory to perform the second configuration of the chip register by writing to the first switch register; The microcontroller triggers the electrically erasable read-only memory to perform the third configuration of the chip registers by writing to the second switch register.

4. The safe power-on method as described in claim 1, characterized in that, During the process of configuring the chip register by any of the one-time programmable memory, the electrically erasable read-only memory, and the read-only memory in the microcontroller, the configuration information for configuring the chip register includes the operating instructions of the system-on-a-chip.

5. The safe power-on method as described in claim 1, characterized in that, During the configuration of the chip register by any of the one-time programmable memory, the electrically erasable read-only memory, and the read-only memory in the microcontroller, the current configuration information for configuring the chip register completely overwrites the historical configuration information of the chip register.

6. The safe power-on method according to any one of claims 1 to 5, characterized in that, When the chip registers cannot be configured in the one-time programmable memory, the safe power-on method includes: The system-on-a-chip configures the chip registers through the read-only memory in the microcontroller to achieve the first reset startup and the initialization of the microcontroller; The microcontroller triggers the electrically erasable read-only memory to perform the third configuration of the chip registers; Once the electrically erasable read-only memory has completed configuring the chip registers, the system-on-a-chip performs the second reset and boots up, then enters normal operating mode.

7. The safe power-on method as described in claim 6, characterized in that, The read-only memory in the microcontroller can be modified via engineering change commands to configure the chip registers.

8. The safe power-on method according to any one of claims 1 to 5, characterized in that, When the one-time programmable memory has completed configuring the chip registers, and the microcontroller fails to start normally, the safe power-on method includes: The one-time programmable memory triggers the electrically erasable read-only memory to perform the third configuration of the chip register; Once the electrically erasable read-only memory has completed configuring the chip registers, the system-on-a-chip performs the second reset and boots up, then enters normal operating mode.

9. The safe power-on method as described in claim 8, characterized in that, The one-time programmable memory triggers the electrically erasable read-only memory to configure the chip register by writing to the third switch register, and the third switch register is associated with the operating state of the electrically erasable read-only memory.

10. The safe power-on method according to any one of claims 1 to 5, characterized in that, When the electrically erasable read-only memory cannot configure the chip registers, and the microcontroller triggers the one-time programmable memory to perform the second configuration of the chip registers, the safe power-on method includes: The system-on-a-chip (SoC) performs the second reset and boots up to normal operation based on the configuration information of the chip registers provided by the one-time programmable memory.

11. A system-on-a-chip secure power-on system, comprising a microcontroller, chip registers, a one-time programmable memory, and an electrically erasable read-only memory; Its features are, The safe power-on system, used in any one of claims 1 to 10, comprises: The first determination unit is used to determine whether the one-time programmable memory can configure the chip register, and if the one-time programmable memory cannot configure the chip register, it triggers the read-only memory in the microcontroller to configure the chip register; The second judgment unit is used to determine whether the microcontroller can start normally, and if the microcontroller cannot start normally, it triggers the electrically erasable read-only memory to configure the chip register; The third judgment unit is used to determine whether the electrically erasable read-only memory can configure the chip register, and if the electrically erasable read-only memory cannot configure the chip register, the system-on-a-chip implements the second reset startup through the microcontroller and enters the normal working state.

12. The safe power-on system as described in claim 11, characterized in that, The safe power-on system includes a chip and an electrically erasable read-only memory, wherein the microcontroller, the chip register, and the one-time programmable memory are all integrated on the chip; The electrically erasable read-only memory is communicatively connected to the microcontroller, the chip register, and the one-time programmable memory.

13. A system-on-a-chip, characterized in that, The system-on-a-chip executes the chip power-up process according to the safe power-up method as described in any one of claims 1 to 10.

14. An electronic device, characterized in that, include: The memory is used to store the processing program; A processor that, when executing the processing program, implements the safe power-on method as described in any one of claims 1 to 10.

15. A readable storage medium, characterized in that, The readable storage medium stores a processing program that, when executed by a processor, implements the safe power-on method as described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • A power up detection system for a memory device

    CN104303235A

  • Soc chip and bus access control method

    CN111295645A