Automotive Microprocessor Chip Architecture Based on RISC-V Instruction Set Architecture
By adopting a chip architecture based on the RISC-V instruction set architecture in automotive microprocessor chips, combining the TEE technology of RISC-V CPU and the HSM hardware security module, the problem of difficulty in achieving independent control and security in the existing chip architecture is solved, and the chip is fully autonomous controllable and high security is achieved.
Patent Information
- Application Number
- CN202210766299.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-30
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-06-30
AI Technical Summary
The existing chip architectures are rarely designed independently, and it is difficult to achieve fully autonomous and controllable functions. Especially in automotive microprocessor chips, security and autonomy are urgently needed.
The automotive microprocessor chip architecture is adopted based on the RISC-V instruction set architecture, including CPU module, bus, peripheral interface, PMC program storage controller module, LMC local storage controller module, and HSM hardware security module. The secure execution environment and hardware security boundaries are built through the RISC-V CPU's TEE technology and the HSM hardware security module, and the dual-layer memory isolation access protection of software security + hardware security is realized.
It realizes the complete autonomous and controllable function of the chip. Through the open-source and customizable RISC-V instruction set and hardware security module, the security and autonomy of the chip are improved, and are suitable for application fields such as gasoline engine controllers and body domain controllers.
Smart Images

Figure CN115098164B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of chip architectures, and particularly relates to a vehicle microprocessor chip architecture based on the RISC-V instruction set architecture. Background Art
[0002] There are few self-designed types of existing chip architectures. Today, with the rising global economic competition, higher requirements are put forward for the security of chips that play a core role in the control field; therefore, a chip architecture that can achieve complete self-control is particularly important. Summary of the Invention
[0003] The technical problem to be solved by the present invention is: to provide a vehicle microprocessor chip architecture based on the RISC-V instruction set architecture, which is used to make the chip achieve complete self-control.
[0004] The technical solution adopted by the present invention to solve the above technical problem is: a vehicle microprocessor chip architecture based on the RISC-V instruction set architecture, including a CPU module, a bus, a peripheral interface, a PMC program storage controller module, an LMC local storage controller module, and an HSM hardware security module; the bus includes a high-performance system bus AHB and a peripheral bus APB; the high-performance system bus AHB is used to connect high-speed modules inside the chip, including a Master interface and a Slave interface, and the bus carries ECC data; the peripheral bus APB is used to connect low-speed peripheral interfaces and configuration signals of transmission interfaces, including a Master interface and a Slave interface, and the bus carries ECC data; the PMC program storage controller module is used to support a DMA function interface, HSM encryption, and ECC error correction functions, and at the same time has a built-in MBIST function for configuring shielded failure modules; the HSM hardware security module is used to protect channel security and startup security, support DMA, and has a built-in true / false random number generator and a post-quantum encryption engine; when the chip is in different working modes, part of the modules are turned off by means of power island isolation; the chip uses 3 PLLs to implement the entire chip's clock structure; the chip adopts a two-stage reset system.
[0005] According to the above solution, the peripheral interface includes CAN, SPI, MCS, Ethernet, SENT, I2C, LIN, UART, GPIO, CTE, WDT, HSM, ADC, Osillator, and CRG.
[0006] According to the above solution, the Master interface of the high-performance system bus AHB includes CPU0, CPU1, CPU2, DMA, and HSM_DMA; the Slave interface includes CPU0 slave port, CPU1 slave port, PMC, LMC, AHB2APB bridge, RGMII, and HSM communication module.
[0007] According to the above solution, the Master interface of the peripheral bus APB includes the AHB2APB bridge and DMA; the Slave interface includes I2C, UART, CAN, SENT, LIN, SPI, MSC, CTE, HSM, WDT, SAR-ADC, DS-ADC, CRG, Monitor.
[0008] According to the above solution, for the PMC program storage controller module, the eflash of the chip is divided into two areas to improve the reliability of the system; the PMC program storage controller module uses two groups of logics to independently control each eflash storage area; each area has an independent ECC check module to ensure data security; each area has an independent data buffer to improve the read and write speed of the eflash.
[0009] According to the above solution, for the HSM hardware security module, the CPU module adopts the RISC-V architecture to control the configuration of the HSM hardware security module and participate in operations; DMA is used to assist the communication between the processor AHB bus and the system AHB bus without the participation of the CPU module to reduce the occupancy of the CPU module; it supports post-quantum encryption algorithms to improve security.
[0010] According to the above solution, according to the application scenario, all the modules of the chip are divided into different power domains, including always_on, Powerdomain0 and Powerdomain1; always_on includes the part of the CPU module that needs to connect to the always_on clock and Sys_pll0; Powerdomain0 includes all other digital parts and is used to start through the internal wake-up mechanism of the CPU module; Powerdomain1 is the analog power domain, including D-S ADC and SAR-ADC, and is used to start through the configuration after the CPU module is started.
[0011] According to the above solution, the chip clock system includes SysPLL0, SysPLL1 and CTEPLL; SysPLL0 provides two interfaces, which are used for the system main clock and the input of all peripheral modules respectively; SysPLL1 provides two interfaces, which are used for the RGMII module clock and the HSM module clock respectively; CTEPLL is a dedicated PLL for CTE; the chip reset system includes the first-level reset and the second-level reset; the first-level reset is that the chip pin chip_rst_n resets the system PLL, and after the PLL is stable, cpu_rst_n is generated to reset the CPU module; the second-level reset is that the peripherals and the system bus are reset by the CPU software configuration.
[0012] The beneficial effects of the present invention are:
[0013] 1. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture of the present invention selects the RISC-V instruction set architecture, whose instruction set is completely open-source and customizable. While achieving differentiated design, it realizes the function of complete self-control of the chip.
[0014] 2. This architecture of the present invention constructs a secure execution environment and secure storage through the TEE technology of the RISC-V CPU, and builds a hardware-based security boundary through the independent CPU and storage unit of the HSM, realizing double-layer memory isolation access protection of software security + hardware security.
[0015] 3. Based on the development practice and functional requirements of autonomous vehicle controllers, the present invention adopts a bus-based and function modular design method for application fields such as gasoline engine controllers, body domain controllers, power domain controllers, and gateway controllers, which is convenient for function trimming and applicable to low-cost vehicle models. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is the principle block diagram of an embodiment of the present invention.
[0017] Figure 2 is the PMC program storage controller module diagram of an embodiment of the present invention.
[0018] Figure 3 is the HSM hardware security module diagram of an embodiment of the present invention.
[0019] Figure 4 is the power island isolation diagram of an embodiment of the present invention.
[0020] Figure 5 is the clock system diagram of an embodiment of the present invention.
[0021] Figure 6 is the reset system diagram of an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] The present invention will be further described in detail below with reference to the drawings and specific embodiments.
[0023] See Figure 1 , the embodiments of the present invention include a CPU core, a bus, and peripheral interfaces (CAN, SPI, MCS, Ethernet, SENT, I2C, LIN, UART, GPIO, CTE, WDT, HSM, ADC, Osillator, CRG, etc.).
[0024] The high-performance system bus AHB (Advanced High Performance Bus) is used to connect high-speed modules within the chip. The Master interface and Slave interface it contains are as follows in the table, and the bus carries ECC data:
[0025]
[0026] The peripheral bus APB (Advanced Peripheral Bus) is used for the connection of low-speed peripheral interfaces and the transmission of interface configuration signals. The Master interface and Slave interface it contains are as follows in the table, and the bus carries ECC data:
[0027]
[0028]
[0029] 1) CPU module:
[0030] The CPU adopts a 3-core heterogeneous architecture with the RISC-V instruction set, supports dual-core lockstep, and CPU1 serves as the checker core.
[0031] The instruction set supported by the CPU can be customized according to performance requirements.
[0032] Icache / Dcache and ILM / DLM instruction tightly coupled memories can be built into the core, which can improve the real-time performance of the processor and reduce power consumption
[0033] 2) PMC program storage controller module
[0034] See Figure 2 , the PMC can support the DMA function interface, support HSM encryption, support the ECC error correction function, and at the same time has a built-in MBIST function and can configure and shield faulty modules.
[0035] To improve the reliability of the system, the chip divides the eflash into two regions. The PMC uses two groups of logics to independently control each eflash storage region. Each region has an independent ECC check module to ensure data security. Each region has an independent data buffer buffer to improve the read and write speed of the eflash.
[0036] 3) HSM hardware security module
[0037] See Figure 3 , the HSM, as a hardware security coprocessor system, is used to protect channel security and startup security, supports DMA, supports built-in true / false random number generators, and supports post-quantum encryption engines.
[0038] The CPU also adopts the RISC-V architecture, which is used to control the HSM encryption system configuration and participate in operations;
[0039] The DMA is used for communication between the coprocessor AHB bus and the system AHB bus. Without the participation of the CPU, it can reduce the occupancy of the main CPU;
[0040] The encryption algorithm supports post-quantum encryption algorithms, which can improve security.
[0041] 3. Power island isolation
[0042] When the chip is in different working modes, the power island isolation method is adopted to turn off some modules. According to the application scenario, all the modules of the chip are divided into different power domains, such as Figure 4 shown as:
[0043] All the modules are divided into 3 powermain in total, including:
[0044] always_on: It contains the part of the CPU that needs to connect to the always_on clock and Sys_pll0;
[0045] Powerdomain0: All other digital parts are included, and it can be started through the internal wake-up mechanism of the CPU.
[0046] Powerdomain1: The analog power domain, which contains D-S ADC and SAR-ADC, and is started through the configuration after the CPU is started.
[0047] 4. Chip clock reset system
[0048] 1) Clock system, see Figure 5 .
[0049] The chip clock system uses 3 PLLs to implement the clock structure of the entire chip.
[0050] SysPLL0 provides two interfaces, which are used for the system main clock and the input of all peripheral modules respectively;
[0051] SysPLL0 provides two interfaces, which are used for the RGMII module clock and the HSM module clock respectively;
[0052] CTEPLL is a dedicated PLL for CTE.
[0053] 2) Reset system
[0054] The chip adopts a two-level reset system, see Figure 6 .
[0055] First-level reset: The chip pin chip_rst_n resets the system PLL. After the PLL is stable, cpu_rst_n is generated to reset the CPU core module;
[0056] Second-level reset: The peripherals and the system bus are reset by the CPU software to configure the system.
[0057] The above embodiments are only used to illustrate the design concept and features of the present invention, and the purpose is to enable those skilled in the art to understand the content of the present invention and implement it accordingly. The protection scope of the present invention is not limited to the above embodiments. Therefore, all equivalent changes or modifications made according to the principles and design ideas disclosed by the present invention are within the protection scope of the present invention.
Claims
1. An automotive microprocessor chip architecture based on the RISC-V instruction set architecture, characterized in that: It includes a CPU module, a bus, a peripheral interface, a PMC program storage controller module, an LMC local storage controller module, and an HSM hardware security module; The bus includes a high-performance system bus AHB and a peripheral bus APB; the high-performance system bus AHB is used to connect high-speed modules within the chip, including a Master interface and a Slave interface. The Master interface includes a CPU core and DMA, and the Slave interface includes PMC and LMC. The bus carries ECC data; the peripheral bus APB is used to connect low-speed peripheral interfaces and transmit configuration signals of the transmission interface, and the bus carries ECC data; The PMC program storage controller module is divided into two independent areas, supports large-capacity flash storage, and improves the reliability of the system; it supports a DMA functional interface, HSM encryption, and ECC error correction functions, and also has a built-in MBIST function for configuring and shielding failed modules; The HSM hardware security module is used to protect channel security and startup security, supports DMA, and has a built-in true / false random number generator and a post-quantum encryption engine; When the chip is in different working modes, some modules are turned off using the power island isolation method; The chip uses 3 PLLs to implement the entire chip's clock structure; the chip adopts a two-level reset system.
2. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, wherein: The peripheral interface includes CAN, SPI, MCS, Ethernet, SENT, I2C, LIN, UART, GPIO, CTE, WDT, HSM, ADC, Osillator, and CRG.
3. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, wherein: The Master interface of the high-performance system bus AHB includes CPU0, CPU1, CPU2, DMA, and HSM_DMA; the Slave interface includes a CPU0 slave port, a CPU1 slave port, PMC, LMC, an AHB2APB bridge, RGMII, and an HSM communication module.
4. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, wherein: The Master interface of the peripheral bus APB includes an AHB2APB bridge and DMA; the Slave interface includes I2C, UART, CAN, SENT, LIN, SPI, MSC, CTE, HSM, WDT, SAR-ADC, DS-ADC, CRG, Monitor.
5. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, characterized in that: For the PMC program storage controller module, the eflash of the chip is divided into two areas to improve the reliability of the system; the PMC program storage controller module uses two sets of logic to independently control each eflash storage area; each area has an independent ECC check module to ensure data security; each area has an independent data buffer to improve the read / write speed of the eflash.
6. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, wherein: For the HSM (Hardware Security Module), the CPU module adopts the RISC-V architecture, which is used to control the configuration of the HSM hardware security module and participate in operations; the DMA is used to assist the communication between the processor AHB bus and the system AHB bus without the participation of the CPU module, aiming to reduce the occupancy of the CPU module; it supports post-quantum encryption algorithms to enhance security.
7. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, characterized in that: According to the application scenario, all modules of the chip are divided into different power domains, including always_on, Powerdomain0, and Powerdomain1; always_on includes the part in the CPU module that needs to be connected to the always_on clock and Sys_pll0; Powerdomain0 includes all other digital parts and is started through the internal wake-up mechanism of the CPU module; Powerdomain1 is the analog power domain, including D-S ADC and SAR-ADC, and is started through the configuration after the CPU module is started.
8. The vehicle microprocessor chip architecture based on the RISC-V instruction set architecture according to claim 1, characterized in that: The chip clock system includes SysPLL0, SysPLL1, and CTEPLL; SysPLL0 provides two interfaces, which are respectively used for the system main clock and the input of all peripheral modules; SysPLL1 provides two interfaces, which are respectively used for the RGMII module clock and the HSM module clock; CTEPLL is a dedicated PLL for CTE; The chip reset system includes a first-level reset and a second-level reset; The first-level reset is that the chip pin chip_rst_n resets the system PLL, and after the PLL is stable, cpu_rst_n is generated to reset the CPU module; The second-level reset is that the peripherals and the system bus are reset by the CPU software configuration reset system.
Citation Information
Patent Citations
System-on-chip (SOC) chip architecture
CN113836081A
Systems and methods for safe and reliable autonomous vehicles
US20190258251A1