FPGA Fault Injection and Fault Location Methods, Devices, Equipment, and Storage Media
Through Tile-level resource coordinate conversion technology, fault injection and fault positioning of different models of SRAM type FPGAs are achieved, which solves the problem of insufficient universality in the existing technology and improves the applicability and effectiveness of the test.
Patent Information
- Application Number
- CN202210674247.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-14
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-06-14
AI Technical Summary
The existing fault injection and fault positioning technologies are mainly aimed at single model SRAM FPGAs, which are poor in versatility and are difficult to adapt to different models of SRAM FPGAs.
Through the general Tile-level resource coordinate conversion method, the Tile-level coordinates of the resources in the user's design are obtained, and the characteristic parameters of the FPGA are used to convert them into frame address and start bit offset, so as to realize fault injection and fault positioning of different models of SRAM FPGAs.
The versatility of fault injection and fault positioning is improved, making it suitable for different models of SRAM FPGAs. Through automatic backward push-sensitive user design, it helps designers evaluate the reliability of FPGA design and provides a basis for subsequent reinforcement measures.
Smart Images

Figure CN115080318B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of integrated circuits, and particularly relates to a fault injection and fault location method, device, equipment, and storage medium for SRAM-based FPGAs. Background Art
[0002] Due to its characteristics such as reconfigurability, rich resources, and short development cycle, SRAM-based FPGAs are increasingly widely used in the aerospace field. However, due to the characteristics of the FPGA's own structure, it is very easy to be hit by high-energy charged particles in the space radiation environment, resulting in single event upset (SEU), which in turn causes the function of the SRAM-based FPGA to be abnormal, and may even damage the hardware circuit seriously in severe cases. Especially with the continuous reduction of the transistor feature size, the SEU effect will become more obvious. Therefore, how to evaluate the impact of the SEU effect on SRAM-based FPGAs is particularly important. Currently, there are two mainstream evaluation methods, irradiation test and fault injection. The irradiation test uses high-energy particles to simulate the irradiation source, which can more realistically reflect the space radiation environment, but it is often costly and the injection position is uncontrollable, providing limited help for subsequent reinforcement of SRAM-based FPGAs. Through the fault injection technology, the configuration bitstream in the FPGA is artificially flipped, which is more convenient, inexpensive, and can better control the injection position, greatly saving the test time. Combined with the fault location technology, it can provide a reference for subsequent fault repair and reinforcement. However, the existing fault injection and fault location technologies often only target a single model of FPGA, with poor versatility. It is necessary to find a general fault injection and fault location system and method to adapt to most SRAM-based FPGAs. Summary of the Invention
[0003] In order to overcome the deficiencies in the prior art, the inventors have conducted intensive research and provided a fault injection and fault location method for SRAM-based FPGAs. Through a general Tile-level resource coordinate conversion method, the fault injection and fault location are applicable to different models of SRAM-based FPGAs, greatly improving the versatility. And according to the result information after fault injection, the sensitive user design can be automatically deduced, which is convenient for designers to evaluate the reliability of the FPGA design and provide a basis for subsequent reinforcement measures, thus completing the present invention.
[0004] The technical solutions provided by the present invention are as follows:
[0005] In a first aspect, a fault injection and fault location method for SRAM-based FPGAs includes:
[0006] Obtaining the Tile-level coordinates of the resources in the FPGA used by the user design;
[0007] Set the characteristic parameters of the FPGA, and use the characteristic parameters of the FPGA to convert the Tile-level coordinates of the resources into the corresponding frame address and start-bit offset;
[0008] Perform bit-by-bit flip injection on the configuration bits of the used resources, and record the data output by the FPGA after each configuration bit is injected;
[0009] Determine whether the currently injected configuration bit will cause the FPGA function to be abnormal according to the data output by the FPGA. If the currently injected configuration bit will cause the FPGA function to be abnormal, reverse-deduce all the Tile-level resource coordinates that are in error due to fault injection according to the frame address and start-bit offset corresponding to the configuration bit, and then reverse-deduce the user design corresponding to the resources.
[0010] Further, the Tile-level coordinates of the resources used in the user design are obtained by parsing the NCD file: After synthesizing and mapping the user design in the ISE tool of AMD Xilinx, the NCD file is obtained. This file contains the coordinate information of all the resources used in the current user design. Then, by running the ncd2xdl command, the NCD file is converted into a readable XDL file, and parsing this file can obtain the Tile-level coordinates of the resources used in the user design.
[0011] Further, the Tile-level coordinates of the resources used in the user design are obtained by executing a tcl command: In the vivado tool of AMD Xilinx, the get_tiles command is executed to obtain the Tile-level coordinates of the resources used in the user design.
[0012] Further, in the step of setting the characteristic parameters of the FPGA and using the characteristic parameters of the FPGA to convert the Tile-level coordinates of the resources into the corresponding frame address and start-bit offset, the frame address includes five parts: block flag, upper and lower half-region flag bits, row address, main address, and secondary address. The frame address is determined in the following way:
[0013] Step S201: Set the characteristic parameters of the FPGA. The characteristic parameters include frame_length, res_length, bottom_rows, res_num, and res_num_bottom. Among them, frame_length represents the length of the configuration frame in this type of FPGA, and its value is the total number of configuration bits in a configuration frame; res_length represents the length of a certain resource in this type of FPGA, and its value is the total number of configuration bits occupied by a certain resource in a configuration frame; bottom_rows represents the number of rows in the lower half area of this type of FPGA; res_num represents the total number of resources in a configuration frame of this type of FPGA; res_num_bottom is the product of res_num and bottom_rows, representing the total number of resources in a column in the lower half area.
[0014] Step S202: Determine the value of the block flag: The block flag value of the on-chip programmable logic resources of the FPGA except for the content of the BRAM is 001, and the block flag values of other resources are all 000.
[0015] Step S203: The formula for determining the upper and lower half area flag bits is:
[0016]
[0017] Among them, Top / Bottom bit represents the upper and lower half area flag bit, Y represents the ordinate of the resource, and Top / Bottom bit being 0 means the resource is in the upper half area, and being 1 means the resource is in the lower half area.
[0018] Step S204: The formula for determining the row address is:
[0019]
[0020] Among them, row address represents the row address, and Y represents the ordinate of the resource.
[0021] Step S205: The formula for determining the main address is:
[0022] majoraddress = X
[0023] Among them, majoraddress represents the main address, and X represents the abscissa of the resource.
[0024] Step S206: The formula for determining the secondary address is:
[0025] minoraddress = 0
[0026] Among them, minor address represents the secondary address. Since each type of resource consists of multiple secondary addresses, when performing fault injection, all secondary addresses of the resource will be traversed for injection. The above formula represents the initial value of the secondary address;
[0027] The starting bit offset is determined by the following formula:
[0028]
[0029] Among them, offset represents the starting bit offset, Y % res_num represents how many resources the target resource is offset in a configuration frame, and α represents a special bit.
[0030] Further, in the step of performing bit-by-bit flipping injection on the configuration bits of the used resources and recording the data output by the FPGA after each configuration bit injection, the data format output by the FPGA is D + flag + DUT value + Goldenvalue. Among them, D is a fixed starting bit with a length of 1 byte. After D is recognized, the subsequent data is valid data; the flag field has a length of 1 byte, and its valid bits are the lowest two bits, which respectively represent the finish signals of the DUT circuit and the Golden circuit when they finish running. The finish signal being 1 indicates that the circuit has finished running, and being 0 indicates that it has not finished running; the lengths of the DUT value and Goldenvalue fields are both n bytes, and n is set manually;
[0031] Among them, the DUT circuit is the module to be tested, corresponding to all resources used in the user design; the Golden circuit is a redundant design of the DUT circuit. During fault injection, only the DUT circuit is injected. After each injection of 1 configuration bit, the DUT circuit and the Golden circuit output DUT value and Goldenvalue respectively.
[0032] Further, the step of determining whether the currently injected configuration bit will cause the FPGA function to be abnormal according to the data output by the FPGA is implemented in the following way:
[0033] Identify the starting bit D. After D is recognized, the data is valid data, and continue to identify the subsequent fields; otherwise, the data is invalid and stop identifying;
[0034] Identify the flag field. The finish signal of the Golden circuit is always 1. The lower two bits of the flag field can only have two values: 01 and 11. 01 indicates that the DUT circuit fails to finish running due to fault injection, and the currently injected configuration bit is the sensitive bit; if the value is 11, it is also necessary to compare whether the DUT value and the GoldenValue are the same to determine whether the DUT circuit has an error;
[0035] When the lowest two bits of the flag are 11, if the values of the DUT value and the GoldenValue are not equal, it is considered that the fault injection causes an error in the operation result of the DUT circuit. The currently injected configuration bit is a sensitive bit, which will cause the FPGA function to be abnormal.
[0036] In a second aspect, a fault injection and fault location device for SRAM-based FPGAs includes:
[0037] A fault injection module, configured to obtain the Tile-level coordinates of the programmable logic resources used in the user design, convert the Tile-level coordinates into corresponding frame addresses and start bit offsets using the characteristic parameters of the FPGA, and perform bit-by-bit flip injection on the configuration bits of the used resources;
[0038] A fault location module, configured to record the data output by the FPGA after bit-by-bit flip injection, determine whether the currently injected configuration bit will cause the FPGA function to be abnormal according to the data output by the FPGA. If the currently injected configuration bit will cause the FPGA function to be abnormal, reverse-deduce all the Tile-level resource coordinates that are in error due to fault injection according to the frame address and start bit offset corresponding to the configuration bit, and then determine the user design corresponding to the resources;
[0039] A communication module, configured to implement data transmission between the fault injection module, the fault location module and the FPGA chip under test.
[0040] In a third aspect, a fault injection and fault location device for SRAM-based FPGAs includes:
[0041] One or more processors;
[0042] A storage device, configured to store one or more programs,
[0043] When the one or more programs are executed by the one or more processors, the one or more processors implement the fault injection and fault location method for SRAM-based FPGAs described in the first aspect.
[0044] In a fourth aspect, a readable storage medium stores a computer program, and when the program is executed by a processor, it implements the fault injection and fault location method for SRAM-based FPGAs described in the first aspect.
[0045] According to the fault injection and fault location method, device, equipment, and storage medium for SRAM-based FPGAs provided by the present invention, the following beneficial effects are achieved:
[0046] The present invention uses a general Tile-level resource coordinate conversion method to make fault injection and fault location applicable to different models of SRAM-based FPGAs, greatly improving the versatility. Moreover, based on the result information after fault injection, the sensitive user design can be automatically deduced, facilitating the designers to evaluate the reliability of the FPGA design and providing a basis for subsequent strengthening measures. Brief Description of the Drawings
[0047] Figure 1 is a flowchart of a fault injection and fault location method for SRAM-based FPGAs in the present invention;
[0048] Figure 2 is a schematic diagram of the conversion of CLB resource coordinates in the present invention;
[0049] Figure 3 is the FPGA return string format;
[0050] Figure 4 is a structural block diagram of the connection between the fault injection and fault location device and the FPGA;
[0051] Figure 5 is the fault location diagram of four circuits. (a) is the fault location diagram of the AES circuit, (b) is the fault location diagram of the AES_TMR circuit, (c) is the fault location diagram of the FFT circuit, and (d) is the fault location diagram of the FFT_TMR circuit. Detailed Description of the Embodiments
[0052] The present invention will be described in detail below, and its features and advantages will become clearer and more definite with these descriptions.
[0053] Here, the special term "exemplary" means "serving as an example, embodiment, or illustration". Any embodiment described as "exemplary" here does not have to be construed as superior to or better than other embodiments. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.
[0054] According to the first aspect of the present invention, a fault injection and fault location method for SRAM-based FPGAs is provided, as Figure 1 shown, including the following steps:
[0055] Step S1, obtaining the Tile-level coordinates of the programmable logic resources (hereinafter referred to as "resources") in the FPGA used by the user design.
[0056] In Xilinx FPGAs, programmable logic resources are hierarchically divided into three levels from coarser to finer: Tile, Site, and BEL. The resources on the chip are organized in this repetitive hierarchical relationship. Through research, the inventor determined that Tile-level information is easier to obtain and more convenient for fault injection compared to the other two levels of information.
[0057] In this step, the Tile-level coordinates of the resources used in the user design in the FPGA are obtained by parsing the NCD file or by executing a tcl command; specifically:
[0058] Obtaining by parsing the NCD file means that after synthesizing and mapping the user design in the ISE tool of AMD Xilinx, the NCD file is obtained. This file contains the coordinate information of all resources used in the current user design. Then, by running the ncd2xdl command, the NCD file is converted into a readable XDL file, and parsing this file can obtain the Tile-level coordinates of the resources used in the user design.
[0059] Obtaining by executing the tcl command means that in the vivado tool of AMD Xilinx, the get_tiles command is executed to obtain the Tile-level coordinates of the resources used in the user design.
[0060] Step S2: Set the characteristic parameters of the FPGA, and use the characteristic parameters of the FPGA to convert the Tile-level coordinates of the resources into corresponding frame addresses and starting bit offsets to complete the coordinate conversion.
[0061] The smallest configurable unit of Xilinx FPGA is called a frame. The two-dimensional logic plane composed of configuration frames corresponds to various resources inside the FPGA. Modifying the composition of the configuration frames can complete the programming of the FPGA. For example, in the Virtex-7 series FPGA, one frame consists of 101 words, each word consists of 4 bytes, for a total of 3232 bits, and each frame can be addressed by a unique 32-bit frame address. The composition of the frame address mainly includes five parts: block flag (Blocktype), upper / lower half region flag bit (Top / Bottom flag bit), row address, major address, and minor address. To convert the Tile-level coordinates into corresponding frame addresses and bit offsets in the frame, it is necessary to analyze the organization method of the FPGA chip, such as Figure 2As shown, the FPGA of model XC7VX330T is divided into two half-areas, Top and Bottom. Among them, Top has 5 rows, Bottom has 2 rows, and the length of each row is the width of one frame, that is, 3232 bits. The length of the CLB is 64 bits. Therefore, each row contains 50 CLBs and an additional 32 bits, and these 32 bits are located in the exact middle of one frame and are used to configure the clock routing resources. Here, take the CLB resource CLB_X4Y149 with the horizontal and vertical coordinates of 4 and 149 in the figure as an example to calculate the 5 components of the frame address and the starting bit offset respectively. The coordinate transformation of other resources is similar. The frame address and the starting bit offset are obtained through the following steps:
[0062] Step S201: Set the characteristic parameters of the FPGA (XC7VX330T). The characteristic parameters include frame_length, res_length, bottom_rows, res_num, res_num_bottom. Among them, frame_length represents the length of the configuration frame in this model of FPGA, and its value is the total number of configuration bits in one configuration frame, and its value is equal to 3232; res_length represents the length of a certain resource in this model of FPGA, and its value is the total number of configuration bits occupied by a certain resource in one configuration frame. For the CLB resource, its value is equal to 64; bottom_rows represents the number of rows in the lower half-area of this model of FPGA, and its value is equal to 2; res_num represents the total number of resources in one configuration frame of this model of FPGA, and its value is equal to 50; res_num_bottom is the product of res_num and bottom_rows, representing the total number of resources in one column of the lower half-area, and its value is equal to 100;
[0063] Step S202: Determine the value of the block flag. The on-chip programmable logic resources of the FPGA include CLB, BRAM, DSP, IOB, etc. The block flag value of the content of BRAM except for that is 001, and the block flag values of other resources are all 000;
[0064] Step S203: The formula for determining the upper and lower half-area flag bits is:
[0065]
[0066] Among them, Top / Bottom bit represents the upper and lower half-area flag bit, Y represents the vertical coordinate of the resource. When Top / Bottombit is 0, it means that the resource is located in the upper half-area, and when it is 1, it means that the resource is located in the lower half-area. The vertical coordinate of CLB_X4Y149 is 149, which is greater than the value 100 of res_num_bottom. Therefore, the value of its upper and lower half-area flag bit is 0.
[0067] Step S204: The formula for determining the row address is:
[0068]
[0069] Among them, row address represents the row address, Y represents the vertical coordinate of the resource. For the upper half area, for each increase in the total number of resources in one configuration frame based on the total number of resources in one column of the lower half area, the value of the row address will increase by 1. For the lower half area, for each decrease in the total number of resources in one configuration frame based on the total number of resources in one column of the lower half area, the value of the row address will increase by 1. Substituting the relevant parameters, the row address value of CLB_X4Y149 can be obtained as 0.
[0070] Step S205: The formula for determining the major address is:
[0071] major address = X (3)
[0072] Among them, major address represents the major address, and X represents the horizontal coordinate of the resource. The major address of each column is fixed, and the value of the horizontal coordinate of the resource is the value of the major address. The horizontal coordinate of CLB_X4Y149 is 4, so its major address is 4.
[0073] Step S206: The formula for determining the minor address is:
[0074] minor address = 0(4)
[0075] Among them, minor address represents the minor address. Since each type of resource is composed of multiple minor addresses, when performing fault injection, the present invention will traverse all minor addresses of the resource for injection. The above formula represents the initial value of the minor address. For CLB resources, the range of its minor address values is from 0 to 35.
[0076] Step S207: The formula for determining the starting bit offset is:
[0077]
[0078] Among them, offset represents the starting bit offset, Y % res_num represents how many resources the target resource is offset in one configuration frame. Multiplying the result by the length of the resource can obtain the starting bit of the bit offset. α represents a special bit. In some resources, there are some special configuration bits. For example, in CLB resources, there are 32 bits used to configure the clock. Substituting the relevant parameters, Y % res_num obtains the number of CLBs offset in one frame by taking the remainder of the Y coordinate value with respect to res_num (50), and then multiplying by 64 can obtain the starting bit value of the bit offset of CLB_X4Y149 as 3168. The injection length is the length of the CLB resource, which is 64. Therefore, the range of the configured bits injected in one frame is from 3168 to 3231.
[0079] Through the above process, the 32-bit frame address of CLB_X4Y149 can be obtained, which is [000 (block) - 0 (top) - 00000 (row) - 0000000100 (major) - 0000000 (minor)]. The starting bit offset is 3168, and then inversion injection can be performed.
[0080] Step S3: Use a tcl script to perform bit-by-bit inversion injection on the configuration bits of the resources used, and record the data output by the FPGA after each configuration bit is injected.
[0081] After obtaining the frame addresses and starting bit offsets of all resources, fault injection can begin. The present invention uses bit-by-bit inversion for injection, that is, only 1 configuration bit in the configuration frame is inverted each time. And after each injection is completed, the configuration bit will be restored to avoid affecting subsequent injections.
[0082] The SRAM-based FPGA chip for implementing fault injection and fault location testing generally includes an interface (such as a JTAG interface), a device under test (abbreviated as DUT circuit), a redundant module (abbreviated as Golden circuit), and a serial port circuit. The DUT circuit corresponds to all resources used in the user design. The Golden circuit is an exact copy of the DUT circuit (the redundant design of the DUT circuit). During fault injection, the tcl script is used to control the interface on the FPGA to inject into the DUT circuit. After each injection of 1 configuration bit, the data of the DUT circuit and the Golden circuit will be output through the serial port circuit. Through subsequent result analysis, the configuration bits that are likely to cause data mismatch between the DUT circuit and the Golden circuit are determined.
[0083] Step S4: Determine whether the currently injected configuration bit will cause the FPGA function to be abnormal according to the data output by the FPGA. If the currently injected configuration bit causes the FPGA function to be abnormal, reverse-deduce all the Tile-level resource coordinates that are in error due to fault injection according to the frame address and starting bit offset corresponding to the configuration bit, and then reverse-deduce the user design corresponding to the resource.
[0084] After fault injection, fault location is to determine which resources are sensitive. The specific method is as follows:
[0085] S4.1: After each injection of 1 configuration bit, the FPGA will output the results in the DUT circuit and the Golden circuit through the serial port circuit for comparison through the serial port. This requires specifying a communication protocol, and specifying the string format returned by the FPGA as Figure 3 as shown below. The following is the meaning of each field.
[0086] (i) D is the fixed starting bit, with a length of 1 byte. After D is recognized, the subsequent data is valid data.
[0087] (ii) The flag field has a length of 1 byte, and its valid bits are the lowest two bits, which respectively represent the finish signals of the DUT and the Golden circuit running to completion. A finish signal of 1 indicates that the circuit has finished running, and 0 indicates that it has not. Since fault injection is only performed on the DUT and not on the Golden, the finish signal of the Golden circuit is always 1. Therefore, there are only two possible values for the lowest two bits of the flag field: 01 and 11. 01 means that the DUT circuit failed to finish running due to fault injection, and the currently injected configuration bit is the sensitive bit (which can easily cause abnormal FPGA functionality). If the value is 11, it is also necessary to compare whether the DUT value and the GoldenValue are equal to determine whether the DUT circuit has an error.
[0088] (iii) The DUT value and Golden value fields both have a length of n bytes, where n is set manually. When the lowest two bits of the flag are 11, if the values of the two are not equal, it is considered that the fault injection has caused an error in the operation result of the DUT circuit, and the currently injected configuration bit is the sensitive bit.
[0089] Therefore, by parsing the string returned by the FPGA, it can be known whether the currently injected configuration bit will cause an error in the DUT circuit. The frame addresses and starting bit offsets corresponding to all these configuration bits will be recorded in the result file (resultfile).
[0090] S4.2 After obtaining the result file, the Tile-level coordinates corresponding to the frame address and starting bit offset can be inferred through the inverse process of Formula 1-5. These sensitive Tile-level coordinates will be stored in the sensitive tile file (sensitive tile file), and the user design corresponding to the resource can be deduced from the Tile-level coordinates.
[0091] S4.3 After locating the Tile-level coordinates, using the minor address in the frame address, a more fine-grained sensitive resource can be located. Taking the CLB as an example, it consists of two Site-level resources, Slices, which can be distinguished by the minor address. After that, the coordinates of the sensitive Slices will be saved in the sensitive site file.
[0092] Mapping sensitive Site-level resources to the user design can be accomplished through a tcl script. The core commands are as follows. The user design corresponding to the Site-level resources is obtained through the get_cells command, where the coordinates of the Site-level resources are a list extracted from the previous sensitive site file.
[0093] According to a second aspect of the present invention, there is provided a fault injection and fault location device for an SRAM-based FPGA, comprising:
[0094] A fault injection module for obtaining the Tile-level coordinates of the programmable logic resources used in the FPGA of the user design, converting the Tile-level coordinates into corresponding frame addresses and start bit offsets using the characteristic parameters of the FPGA, and injecting bit-by-bit flips into the configuration bits of the used resources;
[0095] A fault location module for recording the data output by the FPGA after bit-by-bit flip injection, determining whether the currently injected configuration bit will cause the FPGA function to be abnormal based on the data output by the FPGA. If the currently injected configuration bit will cause the FPGA function to be abnormal, then the Tile-level resource coordinates that are in error due to fault injection are deduced based on the frame address and start bit offset corresponding to the configuration bit, and thus the user design corresponding to the resources is determined;
[0096] A communication module for implementing data transmission between the fault injection module, the fault location module, and the FPGA chip to be tested.
[0097] In a third aspect, a fault injection and fault location device for an SRAM-based FPGA comprises:
[0098] One or more processors;
[0099] A storage device for storing one or more programs,
[0100] When the one or more programs are executed by the one or more processors, the one or more processors implement a fault injection and fault location method for an SRAM-based FPGA according to the first aspect.
[0101] In a fourth aspect, a readable storage medium stores a computer program, and when the program is executed by a processor, it implements a fault injection and fault location method for an SRAM-based FPGA according to the first aspect.
[0102] Those skilled in the art can clearly understand that for the sake of convenience and brevity of description, the specific working processes of the above-described device and equipment can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0103] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer storage media and communication media, where the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage media can be any available medium accessible by a general-purpose or special-purpose computer, including: USB flash drives, external hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media that can store program codes.
[0104] Embodiment
[0105] The fault injection and fault location device for SRAM-based FPGAs provided in the present invention is centralized in the host computer and developed using Qt, including a fault injection module, a fault location module, and a communication module, as shown in Figure 4 . The fault injection module is responsible for parsing the Tile-level coordinates of the resources used and controlling the fault injection process. The fault location module is responsible for locating the error bit positions to specific resources to facilitate subsequent strengthening by the user. The communication module implements two functions. First, it controls the JTAG interface in the FPGA through the FT4232H chip for fault injection. Second, it parses the data read back from the serial port circuit for fault location.
[0106] The FPGA chip includes a JTAG interface, a DUT circuit, a Golden circuit, and a serial port circuit. Among them, the DUT circuit corresponds to all the resources used in the user design. The Golden circuit is an exact copy of the DUT. During fault injection, the DUT is injected through the JTAG interface. After each injection of 1 configuration bit, the results of the DUT and the Golden are uploaded to the host computer through the serial port circuit, and the results are compared in the host computer for final fault location.
[0107] The hardware part is implemented on the Virtex-7 development board XC7VX330T. The FT4232H is used to connect the development board and the host computer. The system clock is 200 MHz, and the serial port baud rate is 115200 bit / s. Four circuits, namely AES, FFT, and AES_TMR and FFT_TMR after triple modular redundancy of them, are selected as experimental circuits for fault injection and fault location. Synthesis and implementation are carried out in Xilinx Vivado, and the resource usage is shown in Table 1.
[0108] Table 1 Resource Usage
[0109]
[0110] According to the fault injection process in the present invention, fault injection is performed on four types of circuits respectively. The total number of injected bits, sensitive bits, and sensitivity rates are shown in Table 2. After the fault location process for the sensitive bits, the proportion of sensitive resources in each circuit is shown in Table 3. The experimental data shows that the sensitive bits and sensitive resources of the triple modular design are significantly less than those of the original design. Through this device, fault injection and location can be effectively performed on the test circuit, and the sensitivity of the circuit after triple modular reinforcement can be evaluated.
[0111] Table 2 Sensitive Bit Conditions
[0112]
[0113] Table 3 Proportion of Sensitive Resources
[0114]
[0115]
[0116] The sensitive resources in the four types of circuits are graphically displayed in the fault location software as Figure 5 shown. Among them, the red squares are sensitive resources. Through the graphical display, the distribution of sensitive resources can be intuitively seen, providing a reference for subsequent further reinforcement. And the proportion of sensitive resources in the statistical chart also conforms to Table 3, indicating the effectiveness of fault location.
[0117] The present invention has been described in detail above in combination with specific embodiments and exemplary examples. However, these descriptions should not be construed as limitations on the present invention. Those skilled in the art understand that without departing from the spirit and scope of the present invention, various equivalent substitutions, modifications, or improvements can be made to the technical solutions of the present invention and their implementation manners, and these all fall within the scope of the present invention. The protection scope of the present invention is subject to the appended claims.
[0118] The content not detailedly described in the specification of the present invention belongs to the well-known technology of those skilled in the art.
Claims
1. A fault injection and fault location method for SRAM-based FPGAs, characterized in that Including: Obtaining the Tile-level coordinates of the resources used in the FPGA for the user design; Setting the characteristic parameters of the FPGA, and using the characteristic parameters of the FPGA to convert the Tile-level coordinates of the resources into corresponding frame addresses and starting bit offsets; the characteristic parameters include frame_length, res_length, bottom_rows, res_num, res_num_bottom; where frame_length represents the length of the configuration frame in the corresponding model FPGA, and its value is the total number of configuration bits in a configuration frame; res_length represents the length of a certain resource in this model FPGA, and its value is the total number of configuration bits occupied by a certain resource in a configuration frame; bottom_rows represents the number of rows in the lower half area of this model FPGA; res_num represents the total number of resources in a configuration frame of this model FPGA; res_num_bottom is the product of res_num and bottom_rows, representing the total number of resources in a column in the lower half area; Performing bit-by-bit flip injection on the configuration bits of the used resources, and recording the data output by the FPGA after each configuration bit is injected; Determining whether the currently injected configuration bit will cause the FPGA function to be abnormal according to the data output by the FPGA. If the currently injected configuration bit will cause the FPGA function to be abnormal, then inversely deduce the Tile-level resource coordinates of all errors caused by fault injection according to the frame address and starting bit offset corresponding to the configuration bit, and further inversely deduce the user design corresponding to the resources.
2. The method for fault injection and fault location for SRAM-based FPGAs according to claim 1, characterized in that The obtaining of the Tile-level coordinates of the resources used in the FPGA for the user design is obtained by parsing the NCD file: After synthesizing and mapping the user design in the ISE tool of AMD Xilinx, the NCD file is obtained. This file contains the coordinate information of all resources used in the current user design. Then, by running the ncd2xdl command, the NCD file is converted into a readable XDL file, and parsing this file to obtain the Tile-level coordinates of the resources used in the user design.
3. The method for fault injection and fault location for SRAM-based FPGAs according to claim 1, characterized in that, The obtaining of the Tile-level coordinates of the resources used in the FPGA for the user design is obtained by executing the tcl command: In the vivado tool of AMD Xilinx, the get_tiles command is executed to obtain the Tile-level coordinates of the resources used in the user design.
4. The fault injection and fault location method for SRAM-based FPGA according to claim 1, characterized in that In the step of setting the characteristic parameters of the FPGA and using the characteristic parameters of the FPGA to convert the Tile-level coordinates of the resources into corresponding frame addresses and starting bit offsets, the frame address includes five parts: block flag, upper and lower half area flag bit, row address, main address, and secondary address. The frame address is determined in the following way: Setting the characteristic parameters of the FPGA; Determining the value of the block flag: The block flag value of the on-chip programmable logic resources of the FPGA except for the content of the BRAM is 001, and the block flag values of other resources are all 000; The formula for determining the upper and lower half area flag bit is: Among them, the Top / Bottom bit represents the upper and lower half area flag bits, Y represents the ordinate of the resource. When the Top / Bottom bit is 0, it means the resource is in the upper half area, and when it is 1, it means the resource is in the lower half area; The formula for determining the row address is: Among them, row address represents the row address, and Y represents the ordinate of the resource; The formula for determining the major address is: major address = X Among them, major address represents the major address, and X represents the abscissa of the resource; The formula for determining the minor address is: minor address = 0 Among them, minor address represents the minor address. Since each type of resource is composed of multiple minor addresses, when performing fault injection, all minor addresses of the resource will be traversed for injection. minor address = 0 represents the initial value of the minor address.
5. The method for fault injection and fault location for SRAM-based FPGA according to claim 4, wherein The starting bit offset is determined by the following formula: Among them, offset represents the starting bit offset, Y % res_num represents how many resources the target resource is offset in a configuration frame, and α represents a special bit.
6. The fault injection and fault location method for SRAM-based FPGAs according to claim 1, characterized in that In the step of performing bit-by-bit flip injection on the configuration bits of the used resources and recording the data output by the FPGA after each configuration bit injection, the data format output by the FPGA is D + flag + DUT value + Golden value. Among them, D is a fixed starting bit with a length of 1 byte. After D is recognized, the subsequent data is valid data; the flag field has a length of 1 byte, and its valid bits are the lowest two bits, which respectively represent the finish signals of the DUT circuit and the Golden circuit when they finish running. When the finish signal is 1, it means the circuit has finished running, and when it is 0, it means it has not finished running; the lengths of the DUT value and Golden value fields are both n bytes, and n is set manually; Among them, the DUT circuit is the module to be tested, corresponding to all resources used in the user design; the Golden circuit is a redundant design of the DUT circuit. During fault injection, only the DUT circuit is injected. After each injection of 1 configuration bit, the DUT circuit and the Golden circuit respectively output DUT value and Golden value.
7. The method for fault injection and fault location for SRAM-based FPGAs according to claim 6, characterized in that, The step of determining whether the currently injected configuration bit will cause the FPGA function to be abnormal according to the data output by the FPGA is implemented in the following way: Identify the starting bit D. After D is recognized, the data is valid data, and continue to identify the subsequent fields; otherwise, the data is invalid and stop identifying; Identify the flag field. The finish signal of the Golden circuit is always 1. The lower two bits of the flag field can only have two values: 01 and 11. 01 means that the DUT circuit fails to finish running due to fault injection, and the currently injected configuration bit is the sensitive bit; if the value is 11, it is also necessary to compare whether the DUT value and the Golden Value are consistent to determine whether the DUT circuit has an error; When the lowest two bits of the flag are 11, if the values of the DUT value and the Golden Value are not equal, it is considered that the fault injection causes an error in the operation result of the DUT circuit. The currently injected configuration bit is a sensitive bit, which may cause abnormal functions of the FPGA.
8. A fault injection and fault location device for SRAM-based FPGAs, characterized in that, Including: A fault injection module, configured to obtain the Tile-level coordinates of the programmable logic resources in the FPGA used in the user design, convert the Tile-level coordinates into corresponding frame addresses and start bit offsets by using the characteristic parameters of the FPGA, and perform bit-by-bit flip injection on the configuration bits of the used resources; the characteristic parameters include frame_length, res_length, bottom_rows, res_num, res_num_bottom; where frame_length represents the length of the configuration frame in the corresponding model FPGA, and its value is the total number of configuration bits in a configuration frame; res_length represents the length of a certain resource in the model FPGA, and its value is the total number of configuration bits occupied by a certain resource in a configuration frame; bottom_rows represents the number of rows in the lower half area of the model FPGA; res_num represents the total number of resources in a configuration frame of the model FPGA; res_num_bottom is the product of res_num and bottom_rows, representing the total number of resources in a column in the lower half area. A fault location module, configured to record the data output by the FPGA after the bit-by-bit flip injection, determine whether the currently injected configuration bit will cause abnormal functions of the FPGA according to the data output by the FPGA. If the currently injected configuration bit will cause abnormal functions of the FPGA, reverse deduce the Tile-level resource coordinates of all the faulty ones due to the fault injection according to the frame address and start bit offset corresponding to the configuration bit, and then determine the user design corresponding to the resources. A communication module, configured to implement data transmission between the fault injection module, the fault location module and the FPGA chip under test.
9. A fault injection and fault location device for SRAM-based FPGAs, characterized in that, Including: One or more processors; A storage device, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement a fault injection and fault location method for SRAM-based FPGAs according to any one of claims 1 to 7.
10. A readable storage medium, characterized in that, On which a computer program is stored, and when the program is executed by a processor, it implements a fault injection and fault location method for SRAM-based FPGAs according to any one of claims 1 to 7.
Citation Information
Patent Citations
System and method for positioning FPGA chip sensitive area
CN101916306A
SRAM (Static Random Access Memory)-type FPGA (Field-Programmable Gate Array) fault injection method and device
CN106124970A