A single-configuration frame-level fault detection and refresh method for Zynq chips

The Zynq chip's internal processor performs single-configuration frame-level fault detection and refresh, which solves the problem of frequent soft errors in the spatial environment of SRAM FPGA, and achieves efficient fault repair and resource conservation.

CN114924917BActive Publication Date: 2025-08-08ZHEJIANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210160929.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-22
Publication Date
2025-08-08
Estimated Expiration
2042-02-22

AI Technical Summary

Technical Problem

Existing SRAM-type FPGAs are susceptible to single-particle effects in the spatial environment, resulting in frequent soft errors. The existing refresh solutions have time redundancy or hardware resource utilization problems, which affects their on-orbit reliability.

Method used

The internal processor of the Zynq chip uses a single-configuration frame-level fault detection and refresh. Through frame-by-frame comparison and dynamic reconfiguration, error bits are located and repaired to avoid the time overhead of global refresh and hardware resource occupation.

Benefits of technology

It improves the reliability of SRAM-type FPGAs in space applications, reduces detection time and hardware resource consumption, and is suitable for space tasks of complex tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114924917B_ABST
    Figure CN114924917B_ABST
Patent Text Reader

Abstract

The present invention discloses a single configuration frame-level fault detection and refresh method for Zynq chips. The method reads back the data in the Zynq chip configuration memory frame by frame and compares it with the pre-parsed original configuration data to locate the flipped bits in the single configuration frame. Then, by leveraging the advantage of heterogeneous processors that can be dynamically reconfigured through software, the method implements configuration frame-level fault repair, thereby effectively repairing the erroneous bits.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the application of SRAM type FPGA chips in the aerospace field, and in particular to a method for performing fault detection and refresh repair on the SRAM type FPGA according to a single configuration frame. Background Art

[0002] The space environment poses numerous challenges to electronic systems. As a natural radiation environment, it is teeming with ionizing radiation particles in the form of high-energy neutrons, heavy ions, and protons. These particles originate from sources such as the Earth's capture zone, galactic cosmic rays, and solar cosmic rays. They are highly penetrating and difficult to fully shield against. SRAM-based FPGAs (Field Programmable Gate Arrays) are highly susceptible to the radiation effects of these particles, causing memory state upsets. The most significant of these is the single-event effect (SEU). A single-event effect (SEU) occurs when high-energy charged particles strike sensitive points in microelectronic devices. Ionization generates a large number of electron-hole pairs. Under the influence of the electric field, when sufficient electron-hole pairs are absorbed by the device's source and drain, a transient current pulse is generated, causing a change in the circuit's logic state and resulting in a single-event upset (SEU). In severe cases, this can even lead to positive feedback current, resulting in permanent single-event damage, gate punch-through, and burnout, seriously damaging the device.

[0003] Single-event effects (SEEs) can be categorized into two main categories, namely, correctable "soft errors" and uncorrectable "hard errors," depending on the degree of damage they cause to devices. For integrated circuits using bulk CMOS processes, hard errors are less likely to occur because they require a significant charge to deposit within the device. Soft errors, which can be corrected by power cycling or reconfiguration, primarily include single-event upsets (SEEs), single-event functional terminations (SEEs), and single-event transient disturbances (SEEs). As process scaling becomes increasingly severe, SEE-induced soft errors have become a key factor affecting the reliability of circuits in space environments at nanometer process nodes. Among these, SEE-induced soft errors are particularly severe. For example, my country's Fengyun-1 and AB satellites experienced attitude control computer failure due to heavy ion bombardment in space, resulting in only 39 and 165 days of normal operation, respectively. The Magellan Venus probe, launched by the United States in 1990, also lost contact with Earth due to SEEs. Reliability issues have severely limited the application of SRAM-based FPGAs in space. Designing system-level fault-tolerance solutions to ensure the on-orbit reliability of SRAM-based FPGAs and improve their SEE tolerance has become a key research focus.

[0004] System-level fault tolerance is divided into hardware redundancy technology and configuration refresh technology. Hardware redundancy sacrifices the complexity of hardware space in exchange for high fault tolerance, resulting in extensive hardware area and power consumption overhead, and is not very applicable to complex circuits and low-power systems. Configuration refresh technology is based on the principle of dynamic reconfiguration. When the FPGA is working normally, the flip bit is rewritten to achieve SEU repair. Depending on the triggering method, it can be divided into blind refresh and readback refresh. Blind refresh ignores the occurrence of SEU and the failure of circuit function, and only performs a memory rewrite at a specific time. Although the execution speed is fast, continuous data writing will cause bandwidth waste. Readback refresh continuously reads back the data in the configuration memory and compares it with the original data. When an error is detected, the error location is reported and rewritten in time. The repair speed is fast, but the implementation method is complex. Refresh control methods can be categorized as external, internal, and internal processor refresh. External refresh typically requires an external antifuse FPGA or microprocessor as a refresh controller, increasing system power consumption due to the addition of an additional device. Internal refresh utilizes the FPGA's internal resources to implement the refresh controller, resulting in a higher refresh rate. However, the refresh controller itself is also susceptible to radiation damage, requiring robustness measures such as triple-module redundancy, which reduces the logic resources reserved for user designs. However, with the development of heterogeneous processors such as Zynq, an internal processor-based refresh solution for FPGA fault detection and repair has become an important solution. Internal refresh is directly controlled by the internal processor, eliminating the need to occupy FPGA logic resources. Configuration data can be stored in the processor's on-chip memory, reducing reliance on external memory. Furthermore, since the refresh controller is physically closer to the configuration memory, a higher refresh rate can be achieved. However, existing refresh solutions based on internal controllers typically perform refreshes at the configuration file granularity, resulting in time redundancy. The present invention proposes a refresh solution based on a single configuration frame. This solution effectively reduces refresh time by performing single-frame fixed-point refreshes on certain error points. Summary of the Invention

[0005] Targeting on-orbit applications of the Zynq series of heterogeneous processors, this paper proposes a method for detecting and refreshing single configuration frames in SRAM-based FPGAs using an internal processor. By reading back data from the SRAM FPGA configuration memory frame by frame and comparing it with the pre-parsed original configuration data, flipped bits in the single configuration frame are located. Subsequently, leveraging the heterogeneous processor's dynamic software reconfiguration capabilities, fault repair is achieved at the configuration frame level, effectively repairing the erroneous bits. This method overcomes the shortcomings of SRAM-based FPGAs in their ability to withstand spatial single-event upsets, providing a simple, efficient, and reliable design approach for SRAM-based FPGAs that requires no FPGA logic resources.

[0006] The specific implementation method of the present invention is as follows:

[0007] A single-configuration frame-level fault detection and refresh method for a Zynq chip includes the following steps:

[0008] (1) After the test circuit board equipped with the Zynq chip is powered on, the various parts of the system are initialized and the addresses of the sensitive frames to be detected that are pre-stored in the non-volatile memory are loaded into the on-chip memory of the Zynq chip to avoid the time overhead caused by frequent access to the non-volatile memory during subsequent readback detection;

[0009] (2) The Zynq chip receives the start-up readback command sent by the ground control station, and then initializes the configuration of the PCAP interface, including the initialization and self-test of the DevCfg interface:

[0010] When the self-test passes, a test pass signal is issued, and the subsequent readback operation can be performed at this time; if the start readback instruction contains a configuration frame address, the configuration frame data corresponding to the address is read back from the configuration memory, and then jump to step (3); if the configuration frame address is not included, jump to step (4); the configuration frame address is the sensitive frame address to be detected in step (1);

[0011] Otherwise, a configuration interface initialization failure signal is sent to the ground control station;

[0012] (3) Read the original configuration data corresponding to the configuration frame address from the non-volatile memory and compare it bit by bit with the data read back from the configuration memory. If the comparison is wrong, return the address comparison error information to the ground measurement and control station; at the same time, calculate the global CRC check value in the last cycle of the readback and compare it with the original check value. If the CRC check is wrong, load the original configuration file from the non-volatile memory and perform a global refresh; otherwise, refresh the configuration frame data corresponding to the error frame address by a single frame and enter step (5);

[0013] (4) First, obtain the pre-stored configuration frame address from the on-chip memory of the Zynq chip, read back the configuration memory according to the address, and jump to step (3); after the current address is read back, continue to increment to the next address in the on-chip memory until all addresses are tested, and return the test completion instruction to the ground control station;

[0014] (5) According to the current configuration frame address, the configuration frame data corresponding to the address is read from the non-volatile memory and saved to the on-chip memory. The current configuration frame data is filled with a blank frame. Then, after the configuration frame data, blank frame and configuration instruction packet are correctly organized, they are transmitted to the configuration memory through the PCAP interface to complete the single configuration frame refresh.

[0015] In the above technical solution, further, the CRC check in step (3) is implemented by integrating a global_CRC circuit in the designed circuit.

[0016] Furthermore, the PCAP interface is set to include initializing the DevCfg interface, enabling the PCAP interface, and setting the register mode for controlling the PCAP interface to the PCAP mode.

[0017] Furthermore, the data read back from the configuration memory includes a blank frame and a target data frame. The blank frame data needs to be removed before it can be used for comparison.

[0018] Furthermore, the single-frame refresh is: according to the configuration frame address, a configuration instruction packet of the refresh process is automatically organized; the configuration instruction packet consists of three parts, including sending a refresh configuration command, sending refresh data and terminating the refresh process, and the sending refresh configuration command includes a synchronization word and a correct device ID; the loading of the configuration frame data adopts an interrupt loading method. Before enabling the PCAP interface for transmission, it is necessary to clear the interrupt bit first, then enable the interrupt, wait for the transmission to be completed, clear the interrupt bit again and disable the interrupt; during the single-frame refresh process, two frames of data need to be written to the configuration memory, namely the target configuration frame data and a frame of filling frame.

[0019] Furthermore, the non-volatile memory is used to store the configuration frame address to be read back for detection, and the configuration frame data corresponding to the configuration frame address; the configuration frame data is obtained by parsing the configuration bitstream file and the debugging bitstream file to obtain data corresponding to the configuration frame address.

[0020] Furthermore, the configuration frame address is a sensitive frame directly related to the designed circuit function obtained by parsing the .ebd and .ebc files.

[0021] Compared with the prior art, the advantages of the present invention are:

[0022] (1) Supporting single configuration frame granularity, compared with global refresh or module-level refresh, it has short time overhead and high efficiency, thus greatly improving the reliability of SRAM-based FPGAs in space applications;

[0023] (2) Using the processor's internal interface as the configuration interface not only avoids the occupation of logic resources, but also prevents the refresher from failing when it is affected by SEU;

[0024] In addition, since the internal configuration interface is physically close to the configuration memory, a higher configuration speed can be achieved;

[0025] (3) Compared with global readback detection, the detection range of the present invention is only for sensitive frames in the designed circuit, which can eliminate the influence of blank configuration frames, thereby effectively narrowing the detection range; (4) There is no need to interrupt the currently running program during the refresh process of a single configuration frame, which is of great significance for certain satellites with complex missions. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 It is a schematic diagram of the system structure provided by the present invention;

[0027] Figure 2 It is the command sequence of the single configuration frame readback process;

[0028] Figure 3 This is the flow of the single configuration frame refresh process. DETAILED DESCRIPTION

[0029] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments:

[0030] Figure 1 This is a schematic diagram of the system structure provided by the present invention. A single-configuration frame-level fault detection and refresh method for a Zynq chip of the present invention can be implemented based on the following fault detection and refresh system. The fault detection and refresh system includes the following modules: a main processor module, a readback module, a fault detection module, and a single-configuration frame refresh module. The main processor module further includes an instruction receiving and processing module, a status return module, and a global reload module. The specific implementation method is as follows:

[0031] (1) After the test circuit board equipped with the Zynq chip is powered on, the main processor module completes the initialization of various parts of the system and loads the sensitive frame addresses to be detected that are pre-stored in the non-volatile memory into the on-chip memory of the Zynq chip to avoid the time overhead caused by frequent access to the non-volatile memory during subsequent readback detection;

[0032] (2) The main processor module enters the ready state and waits for instructions from the ground control station. Only after receiving the start readback instruction, it starts to perform the readback verification operation of the configuration frame on the configuration memory of the Zynq chip.

[0033] (3) After the main processor module receives the start readback instruction, the readback module will first initialize the configuration of the PCAP interface, mainly including the initialization and self-test of the DevCfg interface:

[0034] When the self-test passes, a test pass signal is issued, and the subsequent readback operation can be performed at this time; if the start readback instruction contains a configuration frame address, then jump to step (5); if it does not contain a configuration frame address, then jump to step (6); the configuration frame address is the sensitive frame address to be detected in step (1);

[0035] Otherwise, the readback module sends a configuration interface initialization failure signal to the ground measurement and control station;

[0036] (4) If the start readback instruction contains the configuration frame address, the readback module reads the configuration frame data corresponding to the address from the configuration memory and inputs it to the fault detection module;

[0037] (5) The fault detection module reads the original configuration data corresponding to the configuration frame address from the non-volatile memory and compares it bit by bit with the readback data output by the readback module. If the comparison fails, the address check error information is returned to the ground measurement and control station. At the same time, the global CRC check value is calculated in the last cycle of the readback and compared with the original check value. If the CRC check error occurs, the main processor loads the original configuration file from the non-volatile memory and performs a global refresh; otherwise, the configuration frame data corresponding to the error frame address is sent to the single configuration frame refresh module for single frame refresh, and then enters step (7);

[0038] (6) The readback module first obtains the pre-stored configuration frame address from the on-chip memory of the Zynq chip, reads back the configuration memory according to the address, and jumps to step (5); after the current address is read back, it continues to increment to the next address in the on-chip memory until all addresses are tested, and returns a test completion instruction to the ground control station;

[0039] (7) The single configuration frame refresh module reads the configuration frame data corresponding to the current configuration frame address from the non-volatile memory, saves it to the specified address of the on-chip memory, and fills the current configuration frame data with a blank frame. Then, after correctly organizing the configuration frame data, blank frame and configuration instruction packet, it transmits them to the configuration memory through the PCAP interface to complete the single configuration frame repair.

[0040] In the single-configuration frame-level fault detection and refresh method for Zynq chips, the main processor module includes an instruction receiving and processing module for receiving control instructions from a ground control station; a status return module for returning status information to the ground control station; and a global reload module for immediately performing a global bitstream refresh after a global CRC check error occurs.

[0041] In the single configuration frame level fault detection and refresh method for the Zynq chip, the CRC check in step (5) is implemented by integrating a global_CRC circuit in the design circuit. In the last cycle of the readback, the CRC check value of the global configuration frame is automatically calculated. If the check fails, a CRC check error is thrown to the main processor module.

[0042] In the aforementioned single-configuration-frame-level fault detection and refresh method for Zynq chips, the readback module automatically organizes the readback instruction packet for the readback process based on the configuration frame address. This readback instruction packet consists of three parts: sending the readback configuration command (packet header), receiving the readback data, and terminating the readback sequence (packet trailer). Before starting readback via the PCAP interface, the PCAP interface mode must be correctly set, including initializing the DevCfg interface, enabling the PCAP interface, and setting the register mode for controlling the PCAP interface to PCAP mode.

[0043] For the above-mentioned readback process, after enabling the PCAP interface, the PCAP clock needs to be set correctly. Before setting the clock, the SLCR register must be unlocked first, and then the SLCR register must be locked after the setting is completed. After the readback process is started, the DMA transfer will be called first, and the readback instruction packet will be transmitted to the packet processor through the PCAP interface. The packet processor will first wait for a synchronization word to synchronize the configuration control logic and the configuration interface. If the packet header in the data packet is valid, the readback instruction packet will be written to the specified configuration register for processing. When the DMA DONE signal is pulled high, it marks the end of the sending process. The data obtained by reading back consists of two parts, a blank frame and the target configuration frame data. The blank frame needs to be discarded. After all data transmission is completed, the packet processor receives a desynchronization command and no longer continues to receive data from the configuration interface.

[0044] In the above-mentioned single configuration frame-level fault detection and refresh method for Zynq chips, the single configuration frame refresh module can automatically organize the configuration instruction packet of the refresh process according to the configuration frame address. The configuration instruction packet consists of three parts, including sending the refresh configuration command, sending the refresh data, and terminating the refresh process. First, in addition to passing the synchronization word to the data packet processor, it is also necessary to transmit the correct device ID to it. The loading of the configuration frame data adopts the interrupt loading method. Before enabling the PCAP interface for transmission, it is necessary to clear the interrupt bit first, then enable the interrupt, wait for the transmission to be completed, and then clear the interrupt bit again and disable the interrupt. It should be noted that the refresh process also needs to write two frames of data to the configuration memory, namely the target configuration frame data and a frame of fill frame.

[0045] In the single-configuration-frame fault detection and refresh method for Zynq chips, the non-volatile memory is used to store the configuration frame address to be read back for testing, as well as the configuration frame data corresponding to the configuration frame address. The configuration frame data is obtained by parsing the configuration bitstream file and the debug bitstream file, obtaining a one-to-one correspondence with the configuration frame address.

[0046] In the single configuration frame level fault detection and refresh method for the Zynq chip, the configuration frame address stored in the non-volatile memory is a sensitive frame directly related to the design circuit function obtained by parsing the .ebd and .ebc files.

Claims

1. A single-configuration frame-level fault detection and refresh method for Zynq chips, characterized in that: The following steps are involved: (1) After the test circuit board equipped with the Zynq chip is powered on, the various parts of the system are initialized, and the addresses of the sensitive frames to be detected that are pre-stored in the non-volatile memory are loaded into the on-chip memory of the Zynq chip; (2) The Zynq chip receives the start-up readback command sent by the ground control station, and then initializes the configuration of the PCAP interface, including the initialization and self-test of the DevCfg interface: When the self-test passes, a test pass signal is issued, and the subsequent readback operation can be performed at this time; if the start readback instruction contains a configuration frame address, the configuration frame data corresponding to the address is read back from the configuration memory, and then jump to step (3); if the configuration frame address is not included, jump to step (4); the configuration frame address is the sensitive frame address to be detected in step (1); Otherwise, a configuration interface initialization failure signal is sent to the ground control station; (3) Reading the original configuration data corresponding to the configuration frame address from the non-volatile memory and performing a bit-by-bit comparison with the data read back from the configuration memory; if the comparison fails, returning address comparison error information to the ground measurement and control station; at the same time, calculating the global CRC check value in the last cycle of the readback and comparing it with the original check value; if the CRC check fails, loading the original configuration file from the non-volatile memory and performing a global refresh; Otherwise, refresh the configuration frame data corresponding to the error frame address in a single frame and proceed to step (5); (4) First, obtain the pre-stored configuration frame address from the on-chip memory of the Zynq chip, read back the configuration memory according to the address, and jump to step (3); after the current address is read back, continue to increment to the next address in the on-chip memory until all addresses are tested, and return the test completion instruction to the ground control station; (5) According to the current configuration frame address, the configuration frame data corresponding to the address is read from the non-volatile memory and saved to the on-chip memory. The current configuration frame data is filled with a blank frame. Then, after the configuration frame data, blank frame and configuration instruction packet are correctly organized, they are transmitted to the configuration memory through the PCAP interface to complete the single configuration frame refresh.

2. A single-configuration frame-level fault detection and refresh method for a Zynq chip according to claim 1, characterized in that: The CRC check in step (3) is implemented by integrating a global_CRC circuit in the designed circuit.

3. A single-configuration frame-level fault detection and refresh method for a Zynq chip according to claim 1, characterized in that: The PCAP interface is set to include initializing the DevCfg interface, enabling the PCAP interface, and setting the register mode for controlling the PCAP interface to the PCAP mode.

4. A single-configuration frame-level fault detection and refresh method for a Zynq chip according to claim 1, characterized in that: The data read back from the configuration memory includes a blank frame and a target frame. The blank frame data needs to be removed before it can be used for comparison.

5. The single-configuration frame-level fault detection and refresh method for a Zynq chip according to claim 1, characterized in that: The single-frame refresh is as follows: according to the configuration frame address, a configuration instruction packet of the refresh process is automatically organized; the configuration instruction packet consists of three parts, including sending a refresh configuration command, sending refresh data, and terminating the refresh process. The sending refresh configuration command needs to include a synchronization word and a correct device ID; the configuration frame data is loaded using an interrupt loading method. Before enabling the PCAP interface for transmission, the interrupt bit needs to be cleared first, then the interrupt is enabled. After the transmission is completed, the interrupt bit is cleared again and the interrupt is disabled; during the single-frame refresh process, two frames of data need to be written to the configuration memory, namely the target configuration frame data and a fill frame.

6. A single-configuration frame-level fault detection and refresh method for a Zynq chip according to claim 1, characterized in that: The non-volatile memory is used to store the configuration frame address to be read back for detection, and the configuration frame data corresponding to the configuration frame address; the configuration frame data is obtained by parsing the configuration bitstream file and the debugging bitstream file to obtain data corresponding to the configuration frame address.

7. The single-configuration frame-level fault detection and refresh method for a Zynq chip according to claim 1, characterized in that: The configuration frame address is a sensitive frame directly related to the design circuit function obtained by parsing the .ebd and .ebc files.

Citation Information

Patent Citations

  • On-orbit SRAM type FPGA fault detection and restoration method based on configuration frame

    CN104579313A

  • Processing device with self-scrubbing logic

    US9274895B1