Electrical and logical isolation for system on a chip

CN115190994BActive Publication Date: 2026-09-22TEXAS INSTRUMENTS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180017405.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-18
Filing Date
2021-01-04
Publication Date
2026-09-22
Estimated Expiration
2041-01-04

AI Technical Summary

Technical Problem

虽然两个不同功能单元的电路可以在相同的电源电压下操作,但它们都在其上实施的IC的布置可能要求一个功能单元能够在电源仍然施加到另一个功能单元时断电

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115190994B_ABST
    Figure CN115190994B_ABST
Patent Text Reader

Abstract

In described examples, a SoC (200) includes at least two voltage domains (201, 202) interconnected with a communication bus (203). Detection logic (122, 236, 230) in a first voltage domain (201) determines when a voltage error occurs in a second voltage domain (202) and isolates communication (205) via the communication bus when a voltage error or timing error is detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to providing logical and electrical isolation protection for the safety of a system-on-a-chip with a high-performance interface in the event of a power failure. Background Technology

[0002] In many modern integrated circuits (ICs) configured as System-on-Chip (SoCs), the circuitry for different functional units can be implemented in different power domains. There are several reasons for implementing different power domains. For example, some functional units may have different operating voltage requirements than other functional units; in this case, circuitry with different operating voltage requirements relative to other circuitry can be implemented in a separate power domain.

[0003] Another reason for implementing different circuits in different power domains may be due to energy-saving requirements. Although the circuits of two different functional units can operate at the same power supply voltage, the arrangement of ICs on which they are implemented may require one functional unit to be able to shut down while power is still being applied to the other functional unit.

[0004] Although an IC can implement various functional units in different power domains, many of these functional units can interface with functional units in other power domains. Communication may occur between functional units in two different power domains when both are receiving power. Communication between two functional units can be disabled when one of the power domains is de-energized. Summary of the Invention

[0005] In the described example, a SoC includes at least two voltage domains interconnected with a communication bus. Detection logic in the first voltage domain determines when a voltage error occurs in the second voltage domain and isolates communication via the communication bus when a voltage fault or timing error is detected. Attached Figure Description

[0006] Figure 1 and Figure 2 This is a block diagram of an example SoC that includes multiple voltage domains with security isolation logic between the domains.

[0007] Figure 3 This is a block diagram of an example system including an integrated circuit with isolation logic between voltage domains.

[0008] Figure 4 This is a flowchart of the operation of an example SoC device with multiple voltage domains. Detailed Implementation

[0009] In the accompanying drawings, the same elements are represented by the same reference numerals to maintain consistency.

[0010] In integrated circuits designed for security applications, multiple voltage domains are implemented to provide isolation between functional units in the event of a failure in one domain. One or more voltage domains are identified as high-priority domains, and steps are taken to isolate these high-priority domains so that functional devices within the high-priority domains can continue to operate when another voltage domain in the same integrated circuit fails. Meeting this requirement in integrated circuits with multiple high-performance interfaces that communicate between the high-priority domains and the faulty regions of the integrated circuit is highly challenging.

[0011] By combining hardware and software responses to power supply failures or timing errors, some examples provide logical and electrical isolation for integrated circuits with one or more high-performance interfaces that communicate between a high-priority voltage domain of the integrated circuit and another voltage domain.

[0012] Some examples provide components of both hardware and software that operate in response to voltage source failures to achieve robust logic and electrical isolation between voltage domains, where the interface between voltage domains is not fault-tolerant.

[0013] Example automotive SoC in December 2019: Texas Instruments Inc.'s SPRSP50 "DRA829V Jacinto" TM A more detailed description is provided in "Automotive Processors Silicon Revision 1.0", which is incorporated herein by reference. Based on Jacinto 64-bit architecture TM The 7DRA829V automotive processor offers advanced system integration to reduce system costs for automotive applications such as gateways, vehicle computing, and body domain controllers. Integrated diagnostics and functional safety features are designed for ASIL-B / C certification / requirements. The integrated microcontroller (MCU) island eliminates the need for an external system MCU. The device features a Gigabit Ethernet switch and PCIe hub, supporting network use cases requiring high data bandwidth. Up to four The subsystem manages low-level, time-critical processing tasks, enabling... Unhindered by applications. The dual-core cluster configuration facilitates multi-operating system applications with minimal need for software management programs.

[0014] Figure 1This is a block diagram of an example SoC 100 including multiple voltage domains 101, 102, with safety isolation logic 105 between these domains. SoC 100 is a simplified example illustrating the use of safety isolation logic between voltage domains, which can be applied to more complex SoCs with multiple voltage domains, such as the Jacinto series automotive processors. Voltage domain 102 is a voltage isolated from voltage domain 101, such that a failure of the voltage source in voltage domain 102 will not jeopardize the operation of fault detection logic on voltage domain 101. In some examples, voltage domain 101 may still receive voltage from the voltage source in voltage domain 102 for power failure and / or fault detection, but voltage isolation is still maintained.

[0015] Communication bus 103 is coupled between communication interface 104 in primary domain 102 and communication interface 125 in security domain 101. Security isolation logic 105 includes a set of transmission gates, as shown in 106, arranged such that each signal line of communication bus 103 can be isolated in response to a control signal provided by memory-mapped register (MMR) 127. In this example, only three signal lines are illustrated to provide communication in each direction between MCU island domain 101 and primary domain 102. However, communication bus 103 may include dozens or hundreds of independent signal lines providing information between voltage domain 101 and voltage domain 102.

[0016] In the main voltage domain 102 and the MCU island voltage domain 101, there may be several different sections of a communication bus 103 coupled between various logic and processing modules. In this example, logic module 107 in voltage domain 101 is a crossbar module coupled to different sections of the communication bus 103 to allow dynamic routing of information through the various sections of the communication bus 103. Logic module 108 in voltage domain 102 is a processing unit that processes data received on the communication bus 103 from other parts of the main domain 102 (such as logic unit 109). Each signal line of the communication bus 103 is equipped with a transmission gate (such as 106) to allow complete isolation between the processing logic in the MCU island voltage domain 101 and the processing logic in the main domain 102 in the event of a failure in the main domain 102. In a first operating mode, the communication bus 103 is completely transparent and provides data communication in a normal manner. In a second operating mode, the communication bus 103 is placed in an isolation mode to prevent the transmission of erroneous data via the communication bus 103. In this way, the processing logic located in the voltage domain 101 of the MCU island can continue to operate in order to help restore the operation of the SOC 100 or even restart the main domain 102 after the fault condition is corrected.

[0017] The MCU island voltage domain 101 includes a secure MCU 110, a Device Management and Security Controller (DMSC) 111, and a Power and Sleep Controller (PSC) 112. The PSC 112 manages system power-on / off, clock-on / off, and reset transitions. The PSC's clock gating feature can be used for energy saving. Many PSC operations are transparent to the software executing in the processor within the main domain 102, such as power-on and hard reset operations. The PSC provides an interface to control several important power, clock, and reset operations.

[0018] In this example, the Device Management and Security Control (DMSC) 111 attempts to address potential issues during the operation of complex SoCs by acting as a consistent component across a range of SoC devices, serving as a centralized SoC power, security, and device management controller. The DMSC 111 supports complex interactions between operating systems on heterogeneous SoCs for common features and provides consistency in SoC feature authorization across all operating systems for complex SoC features. The DMSC 111 provides centralized knowledge of system state. In practice, it is a microcontroller that runs security and authentication software that serves the remaining operating systems / software running on the various other processors on the SoC 100.

[0019] The DMSC 111 controls the power management of the SoC 100 and is responsible for removing the device from reset and enforcing clock and reset rules. The DMSC power management function is essential for bringing the SoC 100 into low-power modes (such as "deep sleep" mode) and can sense wake-up events to bring the SoC 100 back online and active.

[0020] The DMSC security management software manages the central security resources of the SoC 100. This security subsystem provides application programming interfaces (APIs) to other software entities to leverage these features in a controlled and secure manner. The security management software is subdivided into several modules, such as: firewall management; ISC management; power-on authentication; SA2UL context management (for encryption and authentication); encryption APIs (for accessing common SA2UL functions such as PKA and RNG); security key management; and secure debugging.

[0021] The DMSC Software Resource Management (RM) (subsystem) manages SoC shared resources. The RM manages access to and configuration of shared resources among SoC 100 processing entities. The RM provides a set of interfaces through which SoC processing entities can allocate and freely access shared resources, such as: core database; IRQ management; ring accelerator management; UDMA-P management; PSI-L management; non-secure agent management; and communication with the DMSC.

[0022] The DMSC 111 is a "black box" relative to other processing entities (ARM / DSP) on the SoC. Communication with the DMSC 111 uses a predefined request-response protocol, which provides access to various services offered by the DMSC 111. The actual messaging hardware block varies from SoC to SoC, but typical examples include a "proxy on the message manager" and a "security proxy on the ring accelerator." These communication mechanisms are standardized and protected by the DMSC software prior to operation.

[0023] The main domain 102 includes at least one processor and associated memory, peripheral devices, and interface circuitry to execute software program instructions in order to provide the intended functionality of the SoC 100, such as for automotive or industrial applications.

[0024] The MCU island voltage domain 101 also includes VDD_MCU power monitoring circuit 121 and VDD_MAIN power monitoring circuit 122, which are connected to the respective voltage sources VDD_MCU and VDD_MAIN via voltage terminals 131 and 132, respectively. VDD_MCU is the operating voltage provided to the MCU island voltage domain 101 and is used by various processing logics 110, 111, etc., located within the MCU island voltage domain 101. VDD_MAIN is the operating voltage provided to the main voltage domain 102 and is used by various processing logics, memory, etc., located within the main voltage domain 102. VDD_MCU and VDD_MAIN are provided by independent power supplies, which may be derived from system power supplies such as those provided by automotive or manufacturing systems.

[0025] The VDD_MCU power supply monitoring circuit 121 monitors the VDD_MCU under low or high voltage conditions. The VCC_MCU power supply is a robust power supply that may include backup capabilities (e.g., battery backup) to maintain the operation of the MCU's safe island voltage domain under adverse conditions. The VDD_MAIN power supply monitoring circuit 122 monitors the VDD_MAIN under low or high voltage conditions. Voltage anomalies detected in the VDD_MAIN generate events, which are sent to the de-glitcher circuit 123 to filter out brief transient voltage anomalies, and then sent to the error signaling module (ESM) 124.

[0026] Communication interface 125 includes timeout logic for monitoring transactions occurring on communication bus 103. If a given transaction takes too long and times out, a timeout error signal is activated to ESM 124. In this example, communication bus 103 is an asynchronous interface between security island domain 101 and master domain 102. The asynchronous communication bus 103 interface naturally supports bus unlocking to achieve the required logical and electrical isolation. Reset signal 126 responds to security MCU 110 and can be activated when master domain 102 is reset to clear communication interface 125.

[0027] ESM 124 aggregates safety-related events and / or errors throughout the SoC 100 into a single location. It can send low-priority and high-priority interrupt signals to the safety MCU 110 and DMSC 111 to handle safety events and / or manipulate I / O error pins to signal an error to external hardware. ESM 124 receives voltage error signals from the VDD_MCU power monitoring circuitry 121 and the VDD_MAIN power monitoring circuitry 122, as well as timeout error signals from the timeout logic in interface 125, and sends alerts to the DMSC 111 and the core safety MCU 110.

[0028] The safety software running in the core safety MCU 110 allows for programmable responses in the event of a detected fault. Software code and operations are provided to ensure robustness in responding to detected faults. For example, a fault in the voltage level reported by a voltage monitor will trigger an interrupt, which in turn will cause the safety kernel in the MCU to execute a service routine. This service routine will begin and check various voltage monitors to identify one or more voltage domains experiencing one or more faults. At this point, the same software can check the further status of timeout circuitry and then activate it in response to any MCU master request, ignoring / blocking potentially corrupted arriving data from the MAIN domain, in which case, operation in auto-acknowledgment mode is initiated, where this is a hypothetical fault.

[0029] In various examples, the software code running in the MCU core can be either security software code developed by the SOC manufacturer and provided by the vendor, or user-provided security software code implemented by the SOC reseller or user. Vendor-provided security software code is transparent to the customer.

[0030] The security software comprises program instructions executed by the security MCU 110 and DMSC 111. In some examples, the security software is stored in a read-only memory accessible to the respective processors 110 and 111. In some examples, there may be a portion of the security software that can be installed or updated during operation of the SOC 100.

[0031] In response to a detected voltage fault or timeout error, MMR 127 activates isolation control line 128 in the presence of a safety MCU 110 to isolate MCU island 101 from the main domain 102 via interrupt communication bus 103. When activated, isolation control line 128 disconnects all transmission gates 106 to prevent erroneous or unstable signals generated by fault logic in main domain 102 from being transmitted to MCU island 101 via communication bus 103. In this way, safety MCU 110 and DMSC 111 can continue to operate correctly and attempt to resume processing in main domain 102.

[0032] Once the error condition has been corrected, the safety MCU 110 disables the isolation control signal 128 via MMR 127, thereby allowing the communication bus 103 to resume normal communication between the MCU domain 101 and the master domain 102.

[0033] In this example, the fault detection logic within voltage domain 101 includes power monitoring circuits 121 and 122, ESM module 124, safety MCU 110, DMSC 111, and MMR 127, which operate autonomously through a combination of hardware and software responses to power supply failures or timing errors. In this way, the operation of SoC 100 can typically recover rapidly after the fault condition is resolved. In other examples, the fault detection logic within voltage domain 101 may include additional or different types of hardware and software capabilities for resolving power supply failures or timing errors.

[0034] Figure 2 This is a block diagram of an example SOC 200 including multiple voltage domains 201, 202, with security isolation logic 205 between these domains. SOC 200 is a simplified example illustrating the use of security isolation logic between voltage domains, which can be applied to more complex SOCs with multiple voltage domains, such as the Jacinto family of automotive processors.

[0035] SoC 200 is similar to SoC 100 ( Figure 1 And includes security MCU 110, DMSC 111, PSC 112, ESM 124, etc., such as for... Figure 1More detailed description. In this example, the communication bus 203 is a high-performance fully synchronous interface, which naturally does not support bus lock release. The security isolation logic 205 includes a set of transmission gates 206 arranged such that each signal line of the communication bus 203 can be isolated in response to a control signal provided by the MMR 227. In this example, only three signal lines are illustrated to provide communication in each direction between the MCU island domain 201 and the main domain 202. However, the communication bus 203 may include dozens or hundreds of individual signal lines providing information between the voltage domains 201 and 202.

[0036] Communication interface 225 in MCU island 201 provides a fully synchronous interface for communication transactions between MCU island 201 and the main domain 202. In this example, transactions on synchronous communication interface 225 operate according to defined time periods, therefore no built-in timeout detection logic is required, as in asynchronous communication interface 125 (see...). Figure 1 The above is provided in [reference to previous section]. However, in the event of an error in the primary domain 202, the transaction may not receive an acknowledgment, and the bus or a portion of the bus may be locked. Therefore, a separate timeout logic 236 is provided, which includes timing circuitry coupled to various control lines within the communication bus 203, configured to detect when an expected acknowledgment for a transaction is not received. When a lost acknowledgment is detected, the timeout logic 236 sends a timeout error event notification to the ESM 124.

[0037] In this example SoC 200, a hardware-implemented override finite state machine (FSM) 230 is coupled to the ESM 124 to receive error events upon detection. The override FSM 230 is configured to immediately respond to voltage anomalies in the main domain 202 detected by the power monitoring circuitry 122 or timeout events in the communication bus 203 detected by the timeout logic 236. When an error event is detected, the override FSM 230 activates control signals coupled to override logic (ovr-log) 231, 232, 233, 234 to send appropriate reset or deactivation signals to the crossbar switch module 107, communication interface 225, timeout logic 236, and isolation logic 205 to immediately isolate the MCU island 201 from the faulty main domain 202.

[0038] In response to a detected voltage fault or timeout error, MMR 227 activates isolation control line 228 in the safety MCU 110, causing safety isolation logic 205 to isolate MCU island 201 from the main domain 202 via interrupt communication bus 203. When activated, isolation control line 228 disconnects all transmission gates 206 to prevent erroneous or unstable signals generated by fault logic in the main domain 202 from being sent to MCU island 201 via communication bus 203. In this way, safety MCU 110 and DMSC 111 can continue to operate correctly and attempt to resume processing in the main domain 102.

[0039] In this way, the Supercontrol FSM 230 provides a fault detection and response mechanism based on redundant hardware. In some such examples, the software executed by the safety MCU 110 and DMSC 111 is configured to respond to certain error events, while the Supercontrol FSM 230 is configured to respond immediately to certain error events. In some cases, the type of response can be defined when designing the SoC 200. In other cases, the type of response can be flexible and can be selected based on the application being executed by the SoC 200.

[0040] For example, when designing the SoC 300, the amount of time delay introduced by the de-interference unit 123 can be defined. Similarly, the duration for which the timeout logic 236 is active can be defined. Additional power monitoring circuitry for different supply voltages may be included. The timeout logic 236 may be configured with two or more timeout period detectors. In this case, the ESM module 124 can be configured to route event notifications for short timeout events to the security core 110 for software response, while routing longer timeout events to the overriding FSM 230. In another example, if the timeout logic 236 provides this capability, the application can specify the timeout length by programmatically configuring the timeout logic 236.

[0041] Once the software-managed error condition has been corrected, the safety MCU 110 disables the isolation control signal 228 via MMR 227, thereby allowing the communication bus 203 to resume normal communication between the MCU domain 201 and the master domain 202. Similarly, once the FSM-managed error condition has been corrected, the overdrive FSM 230 disables the isolation control signal 234, thereby allowing the communication bus 203 to resume normal communication between the MCU domain 201 and the master domain 202.

[0042] In this example, the fault detection logic within voltage domain 201 includes power monitoring circuits 121 and 122, ESM module 124, safety MCU 110, DMSC 111, MMR 127, overriding FSM 230, overriding logic 231, 232, and 233, and timeout logic 236. These operate autonomously through a combination of hardware and software responses to power supply failures or timing errors. In this way, the operation of SoC 100 can typically recover rapidly after the fault condition is resolved. In other examples, the fault detection logic within voltage domain 101 may include additional or different types of hardware and software capabilities for resolving power supply failures or timing errors.

[0043] System Example

[0044] Figure 3 This is a block diagram of an example system 340 including an integrated circuit SoC 300, which has isolation logic 305 between voltage domains 301 and 302. Power supply 341 provides the VDD_MCU voltage to voltage domain 301 via voltage terminal 331. Power supply 342 provides the VDD_MAIN voltage to voltage domain 302 via voltage terminal 332. External modules 343 and 344 represent one or more peripheral modules included in system 340 and provide various processing and / or interface functions for the system, such as in automotive applications, industrial applications, etc.

[0045] SoC 300 is similar to Figure 1 SoC 100 or Figure 2 An example of SoC 2. Voltage domain 301 (VD1) includes processing unit 1 351, which includes a security MCU, DMSC, ESM, PSC, overdrive FSM, etc., such as Figure 2 As described in more detail below. Voltage domain 301 receives the operating voltage from power supply PS1 341.

[0046] Voltage domain VD2 302 includes one or more processing units 308, 309 that receive operating voltage from power supply PS2 342. Processing units 308, 309 communicate with processing unit 351 via one or more communication buses 303, such as for communication bus 103 (…). Figure 1 ) or communication bus 203 ( Figure 2 (More detailed description follows.) Isolation logic 305 is controlled by processing unit 351 to provide isolation between voltage domain 301 and voltage domain 302 when a voltage anomaly is detected on VDD_MAIN or a timing error is detected on communication bus 303, as per [reference to...]. Figure 1 and Figure 2 More detailed description.

[0047] In this example, the software executed by the safety MCU and DMSC in processing unit 351 is configured to respond to certain error events, while the overclocking FSM in voltage domain 301 is configured to respond immediately to certain error events. In some cases, the type of response can be defined when designing the SoC 300. In other cases, the type of response can be flexible and can be selected based on the application being executed by the SoC 300.

[0048] For example (reference) Figure 2 When designing the SoC 300, the amount of time delay introduced by the de-interference unit 123 can be defined. Similarly, the activation duration of the timeout logic 236 can be defined. Additional power monitoring circuitry for different supply voltages may be included. The timeout logic 236 may be configured with two or more timeout cycle detectors. In this case, the ESM module 124 can be configured to route event notifications for short timeout events to the security core 110 for software response, while routing longer timeout events to the overriding FSM 230. In another example, the application can specify the timeout length by programmatically configuring the timeout logic 236.

[0049] Once the software-managed error condition has been corrected, the safety MCU disables the isolation control signal 328 of the MMR in voltage domain 301, thereby allowing the communication bus 303 to resume normal communication between MCU domain 301 and master domain 302. Similarly, once the FSM-managed error condition has been corrected, the overclocked FSM disables the isolation control signal 328, thereby allowing the communication bus 303 to resume normal communication between MCU domain 301 and master domain 302.

[0050] Figure 4 This is a flowchart illustrating the operation of an example SoC device with multiple voltage domains. In the described example, the SoC has two voltage domains, such as... Figure 1 and Figure 2 As illustrated in the diagrams for SoC 100 and 200, in this case, there is a main voltage domain and a safety island voltage domain. In other examples, there may be more than two voltage domains monitored and controlled by a single safety island voltage domain. In this example, the safety island voltage domain includes the microcontroller (such as...) Figure 1 The security MCU 110 is configured to execute security software in response to detected fault conditions.

[0051] At 400, in some examples, the response type is defined when designing the SoC. In other cases, the response type can be flexible and can be selected based on the application the SoC is executing. For example, when designing the SoC, the amount of time delay introduced by a de-interference unit on the voltage monitoring circuitry can be defined. Similarly, the duration for which timeout logic is active on the communication bus can be defined. Additional power monitoring circuitry for different supply voltages may be included. The timeout logic on the communication bus can be configured with two or more timeout period detectors. In this case, the error signaling module can be configured to route event notifications for short timeout events to the security core for a software response, while routing longer timeout events to the overriding FSM for an immediate hardware response. In another example, if the timeout logic provides this capability, the application can specify the timeout length by programmatically configuring the communication bus timeout logic.

[0052] At 402, each voltage domain is powered by a separate voltage source (VDD). The VDD_MCU power supply coupled to the safety island voltage domain is a robust power supply that may include backup capabilities (e.g., battery backup) to maintain the operation of the MCU safety island voltage domain under adverse conditions. VDD_MAIN is the operating voltage provided to the main voltage domain and is used by the various processing logic, memory, etc., located within the main voltage domain.

[0053] At 404, communication between logic modules located in separate voltage domains is provided by a communication bus (such as communication bus 103, see...). Figure 1 To accommodate this. Provides, for example, logic 105 (see...) Figure 1 Safety isolation logic, such as ), is used to allow electrical isolation of the communication bus in response to the detection of an error.

[0054] At position 406, fault detection logic in the safety island voltage domain monitors various conditions affecting the operation of the main voltage domain. This fault detection logic can include hardware-based fault detection logic and software-based fault detection logic (e.g., a safety MCU running a suite of safety software). In this example, the voltage source monitoring circuitry monitors low or high voltage conditions in VDD_MAIN. Voltage anomalies detected in VDD_MAIN generate events, which are sent to a de-interference circuitry to filter out brief transient voltage anomalies, and then to an error signaling module.

[0055] The communication bus interface in the safety island voltage domain includes timeout logic for monitoring transactions occurring on the communication bus. If a given transaction takes too long and times out, a timeout error signal is activated and sent to the error signaling module.

[0056] Other types of error detection logic can be included in the safety island voltage domain to detect various types of abnormal behavior, such as temperature, pressure, etc.

[0057] At 408, the safety MCU receives an error signal from the detection logic. Safety software running within the safety MCU allows for a programmable response in the event of a detected fault. The software code and operations are provided to ensure robustness in responding to detected faults. For example, a fault in the voltage level reported by a voltage monitor will trigger an interrupt, which in turn causes the safety MCU to execute a service routine. This routine will begin and check various voltage monitors to identify one or more voltage domains experiencing one or more faults. At this point, the same software can check the further status of the timeout circuit and then activate it in response to any MCU master request, ignoring / blocking potentially corrupted arriving data from the MAIN domain, in which case, operation in auto-acknowledgment mode is initiated, in which case it is a hypothetical fault.

[0058] In various examples, the software code running in the secure MCU can be either supplier-provided secure software code developed by the SOC manufacturer, or user-provided secure software code implemented by the SOC distributor or user. Supplier-provided secure software code is transparent to the customer.

[0059] Security software consists of program instructions executed by the security MCU. In some examples, the security software is stored in read-only memory accessible to the security MCU. In some examples, there may be a portion of the security software that can be installed or updated during SOC operation.

[0060] At 410, some detected faults may require handling via dedicated hardware to provide a rapid and fail-safe response. In this case, a device such as the FSM 230 (see [link to hardware]) might be necessary. Figure 2 Hardware logic such as can be operated to override the control signal output provided by the safety MCU in order to immediately isolate the main voltage domain from the safety island voltage domain.

[0061] At 412, in response to a detected fault condition, the fault domain is isolated from the safety island voltage domain. In some examples, this includes placing the communication bus in an isolation mode to prevent the transmission of erroneous data via the communication bus. In this way, the processing logic located in the safety island voltage domain can continue to run to help restore SOC operation.

[0062] At 414, once it is determined that one or more fault conditions have been corrected, the safety MCU can attempt to restart or reboot the processing logic in the main voltage domain.

[0063] In this way, SoC operation can typically be quickly restored after a fault condition is resolved. In other examples, fault detection logic within the safe voltage domain may include additional or different types of hardware and software capabilities for resolving power supply failures or timing errors.

[0064] Other embodiments

[0065] In the described example, two voltage domains are illustrated for clarity. In other examples, in response to the detection of voltage or timing errors, there may be several additional voltage domains that can be isolated from the safety island voltage domain.

[0066] In the described example, a single primary domain voltage source is illustrated. In another example, there might be several different voltage domain sources, all monitored by a voltage monitor located on a common safety island voltage domain.

[0067] In the described example, the fault detection logic monitors the primary domain voltage level and communication bus timing. In other examples, additional or different conditions can be monitored by safety software and / or overclocking safety FSMs to provide protection against other types of fault conditions. For example, temperature, pressure, vibration, etc., may be important for monitoring in various operating environments.

[0068] The term "coupled" is used throughout this specification. This term can encompass connections, communication, or signal paths that achieve a functional relationship consistent with this specification. For example, if device A generates a signal to control device B to perform an action, in the first example, device A is coupled to device B; or in the second example, if the intervening component C substantially does not alter the functional relationship between device A and device B, device A is coupled to device B via the intervening component C, such that control signals generated by device B via device A are controlled by device A.

[0069] Modifications to the described embodiments are possible within the scope of the claims, and other embodiments are also possible.

Claims

1. An integrated circuit, comprising: A first voltage domain, which includes a first logic module coupled to a first communication interface; A second voltage domain includes a second logic module coupled to a second communication interface, wherein the second voltage domain is voltage isolated from the first voltage domain. An isolation circuit coupled between the first communication interface and the second communication interface, the isolation circuit being operable to allow communication between the first communication interface and the second communication interface in a first operating mode, and operable to isolate the first communication interface from the second communication interface in a second operating mode. as well as Fault detection logic, located within the first voltage domain, wherein: The fault detection logic is coupled to the isolation circuit; The fault detection logic includes a voltage detection circuit coupled to a voltage terminal in the second voltage domain; The fault detection logic is operable to control the operation mode of the isolation circuit by detecting that the voltage level on the voltage terminal exceeds the tolerance, and when the voltage on the voltage terminal in the second voltage domain exceeds the tolerance, placing the isolation circuit in the second operation mode. The fault detection logic includes a security processor configured to execute security software to control the operating mode of the isolation circuit; and The fault detection logic includes a super-control finite state machine, i.e., a super-control FSM, which is configured to detect fault conditions in the second voltage domain and is operable to super-control the safety processor to control the operating mode of the isolation circuit.

2. The integrated circuit of claim 1, wherein the fault detection logic includes timing logic coupled to the first communication interface, the timing logic being operable to detect a communication timeout fault, wherein the fault detection logic is operable to place the isolation circuit in the second operating mode in response to a communication timeout fault.

3. The integrated circuit of claim 1, wherein the fault detection logic includes timing logic coupled to the first communication interface, the timing logic being operable to detect a communication timeout fault, wherein the overclocking FSM is operable to place the isolation circuit in the second operating mode in response to the communication timeout fault.

4. The integrated circuit according to claim 1, wherein the fault detection logic comprises: A power monitoring circuit, operable to detect whether the voltage level at the voltage terminal exceeds a tolerance, and The interference removal logic is coupled to the power monitoring circuit and is operable to cause the isolation circuit to be placed in the second operating mode when the voltage on the voltage terminal in the second voltage domain exceeds the tolerance for a specified amount of time.

5. The integrated circuit of claim 1, wherein the fault detection logic includes a memory-mapped register coupled to the isolation circuit and operable to cause the isolation circuit to be placed in the first operating mode or the second operating mode.

6. The integrated circuit according to claim 1, wherein: The isolation circuit includes a set of signal lines coupled between the first communication interface and the second communication interface; and Each of the set of signal lines includes a corresponding transmission gate operable to allow or disable communication via the corresponding signal line.

7. A method for logic and electrical isolation protection, the method comprising: The first voltage source supplies power to the first voltage domain of the system-on-a-chip integrated circuit, i.e., the SoC. The second voltage source supplies power to the second voltage domain of the SoC; Communication is performed between the first logic module in the first voltage domain and the second logic module in the second voltage domain via a communication bus; By detecting whether a communication timeout fault occurs between the first logic module and the second logic module, the detection logic located in the first voltage domain detects whether a fault occurs in the second voltage domain. as well as Based on whether the fault occurs in the second voltage domain, determine whether to disable communication between the first voltage domain and the second voltage domain. Wherein, the fault is the first fault; and The method further includes: The occurrence of a second fault is detected by executing software on a safety processor located in the first voltage domain. Based on whether the second fault occurs, determine whether to disable communication between the first voltage domain and the second voltage domain, and The control signals generated by the supercontrol finite state machine are supercontrolled by the control signals provided by the safety processor, so as to electrically isolate the first voltage domain from the second voltage domain.

8. The method according to claim 7, further comprising: The occurrence of a second fault is detected by checking whether the voltage source level in the second voltage domain exceeds the tolerance.

9. The method of claim 7, further comprising, in response to detecting that either the first fault or the second fault has occurred, restarting the processing logic in the second voltage domain of the SoC under the control of the security processor.

10. A system for logic and electrical isolation protection, comprising: System-on-a-chip (SoC) is an integrated circuit. A first power source, which is coupled to a first voltage domain of the SoC; A second power source, which is coupled to a second voltage domain of the SoC; as well as The SoC includes: A first logic module in the first voltage domain, the first logic module being coupled to a first communication interface; A second logic module in the second voltage domain, the second logic module being coupled to a second communication interface, wherein the second voltage domain is voltage isolated from the first voltage domain; An isolation circuit coupled between the first communication interface and the second communication interface, the isolation circuit being operable to allow communication between the first and second communication interfaces in a first operating mode, and operable to isolate the first and second communication interfaces in a second operating mode; and The fault detection logic is located within the first voltage domain, wherein: The fault detection logic is coupled to the isolation circuit. The fault detection logic includes a security processor configured to execute security software operable to control the operating mode of the isolation circuit, and The fault detection logic includes a super-control finite state machine, i.e., a super-control FSM, which is configured to detect fault conditions in the second voltage domain and is operable to super-control the safety processor to control the operating mode of the isolation circuit.

11. The system of claim 10, wherein the fault detection logic includes a voltage detection circuit coupled to a voltage terminal in the second voltage domain, the fault detection logic being operable to detect a voltage level exceeding a tolerance on the voltage terminal, wherein when the voltage at the voltage terminal in the second voltage domain exceeds the tolerance, the fault detection logic is operable to place the isolation circuit in the second operating mode.

12. The system of claim 10, wherein the fault detection logic includes timing logic coupled to the first communication interface, the timing logic being operable to detect a communication timeout fault, wherein the fault detection logic is operable to place the isolation circuit in the second operating mode in response to the communication timeout fault.

13. The system of claim 10, wherein the fault detection logic includes timing logic coupled to the first communication interface, the timing logic being operable to detect a communication timeout fault, wherein the overclocking FSM is operable to place the isolation circuit in the second operating mode in response to the communication timeout fault.

14. The system of claim 13, wherein the fault detection logic includes a voltage detection circuit coupled to a voltage terminal in the second voltage domain, the fault detection logic being operable to detect that the voltage level on the voltage terminal exceeds a tolerance, wherein when the voltage on the voltage terminal exceeds a tolerance, the fault detection logic is operable to place the isolation circuit in the second operating mode.

15. The system according to claim 10, wherein: The isolation circuit includes a set of signal lines coupled between the first communication interface and the second communication interface; and Each of the set of signal lines includes a corresponding transmission gate operable to allow or disable communication via the corresponding signal line.

Citation Information

Patent Citations

  • Methods for detecting an imminent power failure in time to protect local design state

    CN110546590A