Processing systems, related integrated circuits, devices and methods

By separating the fault collection and error management circuits and combining combinational logic operations and hardware address protection, the problem of low efficiency in error signal management in the processing system is solved, achieving error management with smaller area and higher security, and adapting to the needs of complex multi-core systems.

CN115221084BActive Publication Date: 2025-10-28STMICROELECTRONICS APPL GMBH +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210400090.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-04
Filing Date
2022-04-15
Publication Date
2025-10-28
Estimated Expiration
2042-04-15

AI Technical Summary

Technical Problem

As the complexity of processing system functions increases, existing fault collection and error management circuits are inefficient in terms of area, unable to effectively manage large numbers of error signals, and have complex wiring in multi-core systems, making it difficult to meet safety requirements.

Method used

It employs separate fault collection and error management circuits, including multiple error combination circuits and error management circuits. It generates combinational error signals through combinational logic operations and manages access permissions using software instructions and hardware address protection circuits, supporting virtual machine and multi-tasking environments.

Benefits of technology

It reduces the area and wiring complexity of fault collection and error management circuits, improves system security and flexibility, and adapts to the needs of multi-tasking and virtualized environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115221084B_ABST
    Figure CN115221084B_ABST
Patent Text Reader

Abstract

Various embodiments of this disclosure relate to processing systems, related integrated circuits, devices, and methods. One processing system includes a security monitoring circuit configured to generate error signals by monitoring microprocessor operation, memory controllers, and / or resources. The system also includes fault collection subcircuits, each including one or more error combination circuits. Each error combination circuit includes a first programmable register and is configured to receive a subset of error signals, determine whether an error signal is asserted, and store error state data identifying asserted error signals in the first register. Each error combination circuit is configured to read enable data from the first register and generate a combined error signal. An error management circuit includes a second programmable register and is configured to receive the combined error signal, read routing data from the second register, and generate an error signal for each microprocessor.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of Italian patent application No. 102021000009683, filed on April 16, 2021, which is incorporated herein by reference. Technical Field

[0003] The embodiments of this disclosure relate to error management within processing systems such as microcontrollers. Background Technology

[0004] Figure 1 A typical electronic system, such as the electronic system of a vehicle, is shown, including multiple processing systems 10, such as embedded systems or integrated circuits, for example, field programmable gate arrays (FPGAs), digital signal processors (DSPs), or microcontrollers (e.g., dedicated to the automotive market).

[0005] For example, in Figure 1 The diagram illustrates three processing systems 101, 102, and 103 connected via a suitable communication system 20. For example, the communication system may include a vehicle control bus (such as a Controller Area Network (CAN) bus) and a possible multimedia bus (such as a Media-Oriented System Transport (MOST) bus) connected to the vehicle control bus via a gateway. Typically, the processing systems 10 are located at different locations within the vehicle and may include, for example, an engine control unit, a transmission control unit (TCU), an anti-lock braking system (ABS), a body control module (BCM), and / or a navigation and / or multimedia audio system. Thus, one or more of the processing systems 10 may also implement real-time control and adjustment functions. These processing systems are typically identified as electronic control units (ECUs).

[0006] Figure 2 It shows what can be used as Figure 1 A block diagram of an exemplary digital processing system 10, such as a microcontroller, for any of the processing systems in the processing system 10.

[0007] In the considered example, the processing system 10 includes a microprocessor 102, typically a central processing unit (CPU), which is programmed via software instructions. Typically, the software executed by the microprocessor 102 is stored in a non-volatile program memory 104, such as flash memory or EEPROM. Therefore, the memory 104 is configured to store the firmware of the processing unit 102, which includes software instructions to be executed by the microprocessor 102. Typically, the non-volatile memory 104 can also be used to store other data, such as configuration data, for example, calibration data.

[0008] The microprocessor 102 is also typically associated with volatile memory 104b, such as random access memory (RAM). For example, memory 104b can be used to store temporary data.

[0009] like Figure 2 As shown, communication with memory 104 and / or 104b is typically performed via one or more memory controllers 100. One or more memory controllers 100 may be integrated into microprocessor 102 or connected to microprocessor 102 via a communication channel such as the system bus of processing system 10. Similarly, memory 104 and / or 104b may be integrated with microprocessor 102 in a single integrated circuit, or memory 104 and / or 104b may be in the form of a separate integrated circuit and connected to microprocessor 102, for example, via traces on a printed circuit board.

[0010] In the example under consideration, the microprocessor 102 may have been associated with one or more (hardware) resources / peripherals 106, which are selected from the group consisting of:

[0011] - One or more communication interfaces IF, for example, for exchanging data via communication system 20, such as Universal Asynchronous Receiver / Transmitter (UART), Serial Peripheral Interface Bus (SPI), Internal Integrated Circuit (I) 2 C) Controller Area Network (CAN) bus, and / or Ethernet interface, and / or debug interface; and / or

[0012] - One or more analog-to-digital converters (AD) and / or digital-to-analog converters (DA); and / or

[0013] - One or more dedicated digital components (DCs), such as hardware timers and / or counters, or cryptographic coprocessors; and / or

[0014] - One or more analog components AC, such as comparators, sensors (such as temperature sensors), etc.; and / or

[0015] - One or more mixed-signal components (MSCs), such as PWM (Pulse Width Modulation) drivers.

[0016] Typically, the dedicated digital component (DC) may also correspond to an FPGA integrated within the processing system 10. For example, in this case, the memory 104 may also include programming data for such an FPGA.

[0017] Therefore, the digital processing system 10 can support different functions. For example, the behavior of the microprocessor 102 is determined by firmware (e.g., software instructions to be executed by the microprocessor 102 of the microcontroller 10) stored in the memory 104. Thus, by installing different firmware, the same hardware (microcontroller) can be used for different applications.

[0018] In this regard, future generations of this processing system 10 (e.g., microcontrollers for automotive applications) are expected to exhibit increased complexity, primarily due to the increasing number of requested functions (new protocols, new features, etc.) and stricter constraints on execution conditions (e.g., lower power consumption, higher computing power and speed, etc.).

[0019] For example, more sophisticated multi-core processing systems have recently been proposed. Such multi-core processing systems can be used for (parallel) execution. Figure 1 Several processing systems 10 are shown in the processing system 10, such as several ECUs of a vehicle.

[0020] Figure 3 An example of a multi-core processing system 10 is shown. Specifically, in the considered example, the processing system 10 includes multiple (n) processing cores 1021...102 connected to a (on-chip) communication system 114. n For example, in the case of a real-time control system, the processing core 1021...102 n It can be ARM Core. Typically, the communication system 114 may include one or more bus systems, such as those based on the Advanced Scalable Interface (AXI) bus architecture and / or Network on Chip (NoC).

[0021] For example, as illustrated in the example of processing core 1021, each processing core 102 may include a microprocessor 1020 and a communication interface 1022 configured to manage communication between the microprocessor 1020 and the communication system 114. Typically, interface 1022 is a master interface, configured to forward a given (read or write) request from the microprocessor 1020 to the communication system 114, and to forward an optional response from the communication system 114 to the microprocessor 1020. However, communication interface 1022 may also include slave interfaces. For example, in this way, the first microprocessor 1020 may send a request to the second microprocessor 1020 (via the communication interface 1022 of the first microprocessor, the communication system 114, and the communication interface 1022 of the second microprocessor).

[0022] Typically, each processing core has 1021...102 n It may also include other local resources, such as one or more local memories 1026, typically identified as tightly coupled memory (TCM).

[0023] As mentioned before, typically, processing cores 1021...102 n It is configured to exchange data with non-volatile memory 104 or volatile memory 104b. In the multi-core processing system 10, these memories are typically system memory (i.e., memory for processing cores 1021...102). n (Shared). However, as mentioned before, each processing core has 1021...102... n It may include one or more additional local memories 1026.

[0024] For example, such as Figure 3 As shown, the processing system 10 may include one or more memory controllers 100 configured to connect at least one non-volatile memory 104 and at least one volatile memory 104b to the communication system 114. As previously mentioned, one or more of the memories 104 or 104b may be integrated into the integrated circuit of the processing system 10 or externally connected to the integrated circuit. For example, the processing system 10 may include:

[0025] - A first volatile memory 104b, integrated in the integrated circuit of the processing system 10 and connected to the communication system 114 via a first memory controller 100, and

[0026] - The second volatile memory 104b is located externally relative to the integrated circuit of the processing system 10 and is connected to the communication system 114 via the second memory controller 100.

[0027] For example, processing system 10 may include one or more resources 106, such as one or more communication interfaces or coprocessors (e.g., cryptographic coprocessors). Resources 106 are typically connected to communication system 114 via corresponding communication interfaces 1062. Generally, communication interfaces 1062 include at least one slave interface. For example, processing core 102 can send a request to resource 106 and the resource returns given data. Typically, one or more communication interfaces 1062 may also include corresponding master interfaces. For example, such master interfaces are used when resources must initiate communication to exchange data with another circuit (such as resource 106 or processing core 102) connected to communication system 114 via (read and / or write) requests. For example, for this purpose, communication system 114 may actually include an Advanced Microcontroller Bus Architecture (AMBA) High Performance Bus (AHB) and an Advanced Peripheral Bus (APB) for connecting resources / peripheral devices 106 to the AMBA AHB bus.

[0028] Typically, such a processing system 10 also includes one or more direct memory access (DMA) controllers 110. For example, as Figure 3 As shown, the DMA controller 110 can be used to exchange data directly with memory (e.g., memory 104b) based on requests received from resource 106. For example, the communication interface IF can thus read data directly from memory 104b and transfer that data (via the DMA controller 110) without exchanging other data with processor 102. Typically, the DMA controller 110 can communicate with one or more memories via communication system 114 or via one or more dedicated communication channels.

[0029] In this regard, regardless of the complexity of the processing system 10 (e.g., regarding the number of processing cores 102 or the number and type of resources 106), a typical processing system 10 also includes fault collection and error management circuitry 120.

[0030] For example, a possible embodiment of the fault collection and error management circuit 120 is disclosed for this purpose by reference to European patent application number EP 3 534261A1, which is incorporated herein by reference.

[0031] Specifically, such as Figure 4 As shown, at least one of circuits 102, 104, and 106 can generate one or more error signals ERR1, ..., ERR. m For example, such an error signal ERR may be generated by at least one of the following:

[0032] - Memory 104 supports error detection and / or correction functions. When the data read from memory 104 contains errors and / or when the data cannot be written to memory, memory 104 generates an error signal ERR1.

[0033] - Processing core 102 is configured to generate an error signal ERR2 in response to hardware and / or software failures; and

[0034] - The communication interface is configured to generate an error signal ERR3, which corresponds to a hard error signal indicating a hardware fault and / or a soft error signal indicating a data transmission error.

[0035] Additionally, one or more error signals may be generated by monitoring the power supply voltage of the processing system 10 (e.g., to detect overvoltage and / or undervoltage conditions), the clock signal of the processing system 10 (e.g., to detect whether the clock frequency is out of range), and / or the temperature of the processing system 10 (e.g., to detect whether the current operating temperature is out of range).

[0036] In the example considered, various error signals ERR1, ..., ERRm Provided to the fault collection and error management circuit 120. Responding to error signals ERR1, ..., ERR m The fault collection and error management circuit 120 can perform various operations.

[0037] For example, the fault collection and error management circuit 120 can be configured to generate at least one of the following:

[0038] - Interrupt signal IRQ is provided to processing core 102;

[0039] - The reset request signal RST is provided to the reset management circuit of the processing system 10;

[0040] - Signal ET is provided to terminal EP of processing system 10, for example, to notify external circuitry of an error signal; and

[0041] - Signal SET is used to set the output level of one or more safety-critical terminals SCP of the processing system 10.

[0042] Specifically, due to errors, the circuitry of processing system 10 may malfunction, potentially generating incorrect signals at the pins / pads of processing system 10. Therefore, some pins / pads in processing system 10a may be safety-critical pins / pads, i.e., pins / pads that may generate critical conditions when driven incorrectly. For example, in Figure 4 The diagram schematically shows a first safety-critical pin SCP1 driven by the processing core 102 and a second safety-critical pin SCP2 driven by a resource / peripheral device 106 such as a communication interface or a PWM half-bridge driver.

[0043] Typically, each input / output pin / pad of processing system 10 is associated with a corresponding driver circuit I / O, which is configured to drive the corresponding pin / pad based on signals received from the corresponding block (e.g., processing system 102 and hardware resource 106). Typically, dedicated logic, such as one or more multiplexers, may also be arranged between the driver circuit 10 and the block of processing system 10a to allow for configuration of pin mappings.

[0044] Therefore, according to the disclosure in document EP 3 534 261A1, the driver circuit I / O of the safety-critical pin / pad SCP can be configured to set the output level of the corresponding pin to a given safety state in response to the signal SET. The output level (such as a high-impedance state or a given logic level (high or low)) may depend on the specific application requirements. Preferably, this "safety state" conforms to the ISO 2626 specification.

[0045] Figure 5 Possible implementations of the fault collection and error management circuit 120 are shown.

[0046] In the considered example, the fault collection and error management circuitry 120 includes a register 1200. Specifically, in the considered example, register 1200 includes one or more error bits EB for storing the values ​​of error signals ERR. For example, considering the exemplary case of three error signals ERR1…ERR3, register 1200 may include a corresponding number of error bits EB.

[0047] In the considered example, the fault collection and error management circuitry 120 includes an internal response circuitry 1202. Specifically, the internal response circuitry 1202 can be configured to generate an interrupt signal IRQ and / or a reset request signal RST based on the contents of the error bit EB in register 1200. The error bit EB is purely optional, and the external response circuitry 1202 can also directly generate the interrupt signal IRQ and / or the reset request signal RST based on one or more error signals.

[0048] Similarly, the fault collection and error management circuit 120 includes an external response circuit 1204. Specifically, the external response circuit 1204 can be configured to generate an error trigger signal ET and / or a signal SET based on the contents of the error bit EB in the register 1200. Furthermore, the error bit EB is purely optional, and the external response circuit 1204 can also directly generate the signal ET and / or the signal SET based on one or more error signals ERR.

[0049] Generally, the behavior of the response circuits 1202 and / or 1204 can also be programmable, for example, by setting one or more configuration bits in register 1200. For example, in the considered example, register 1200 includes:

[0050] - The corresponding interrupt enable bit IE for each error signal in error signals ERR1...ERR3, that is, when the corresponding interrupt enable bit IE of the asserted error signal ERR is also asserted, the interrupt signal IRQ is asserted.

[0051] - The corresponding error trigger enable bit ETE for each error signal in the error signals ERR1......ERR3, that is, the error trigger signal ET is asserted when the corresponding error trigger enable bit ETE of the asserted error signal ERR is also asserted.

[0052] Similarly, register 1200 may include a corresponding reset enable bit for the reset request signal REQ and / or a corresponding enable bit for the security signal SET.

[0053] To simplify data exchange between processing unit 102 and register 1200, register 1200 can be directly addressed by processing unit 102, which is... Figure 3 The diagram schematically shows that the fault collection and error management circuit 120 is connected to the communication system 114.

[0054] As previously mentioned, the fault collection and error management circuit 120 can receive a significant number of error signals (ERRs) from different circuits in the processing system. This is particularly suitable for complex multi-core processing systems 10. For example, in the context of automotive applications, multiple functions such as braking, airbag control, and powertrain can be integrated into the same processing system. However, in this case, the safety requirements specified in ISO 26262 must also be met.

[0055] Usually, such as Figure 6 As shown, the hardware error signal ERR is generated by a dedicated safety monitoring circuit SM. For example, such a safety monitoring circuit may include combinational and / or sequential logic circuits that monitor the operation of a given circuit. Typically, such a safety monitoring circuit SM may also include analog components, for example, to detect out-of-range conditions of analog signals, such as internal power supply voltages or signals indicating the operating temperature of the processing system or specific circuitry of the processing system.

[0056] For example, Figure 6 A security monitor circuit SM configured to monitor one or more signals of memory 104 is shown. 104 A security monitor circuit SM configured to monitor one or more signals of the core processing core 102. 102 and a security monitor circuit SM configured to monitor one or more signals of resource / peripheral device 106. 106 Typically, safety monitoring circuitry can also be integrated into the corresponding circuitry.

[0057] Therefore, typically, each safety monitoring circuit SM monitors one or more signals generated and / or supplied to the associated circuit, and determines whether the behavior of one or more signals is normal or indicates an error. Generally, the operation performed by a given safety monitoring circuit SM depends on the associated circuit and may include, for example:

[0058] - Combinatorial analysis, for example, determining whether signal levels are consistent by combining signals from related circuits;

[0059] - Sequential analysis, for example, by comparing the time evolution of one or more signals with one or more reference signals;

[0060] - Analysis of one or more analog signals, for example, by comparing the values ​​of the analog signals with one or more reference values; or

[0061] - The combination of the above analyses can enable more complex analysis of abnormal behavior.

[0062] For example, as mentioned earlier, the security monitoring circuit SM104 can correspond to the error detection circuit of the memory 104, which calculates (via combinational logic operations and optional sequential logic operations) an error correction code for data read from the memory, and compares the calculated error correction code with the error correction code read from the memory (via combinational logic operations). Conversely, the security monitoring circuit SM 102 It may include a watchdog timer, which is configured to generate an error signal when the relevant processing core does not reset the watchdog timer within a given time period.

[0063] Therefore, in response to the determination of abnormal behavior, the safety monitoring circuit SM can assert the corresponding error signal ERR, which will notify the fault collection system 120 of the error signal.

[0064] However, when the functionality of the processing system 10 is increased, for example, regarding the number and / or characteristics of the processing and handling 102 and / or resources, the number n of error signals ERR also increases. Therefore, this solution may be quite inefficient in terms of area, for example, because the area of ​​the fault collection and management circuitry 120 increases proportionally to the number n of error signals ERR to be managed. Summary of the Invention

[0065] In view of the above, the purpose of the various embodiments of this disclosure is to provide a solution for managing error signals within a processing system.

[0066] According to one or more embodiments, one or more of the above-described objectives are achieved by means of a processing system having the features specifically set forth in the following claims. Furthermore, the embodiments relate to a related integrated circuit, device, and method.

[0067] The claims are an integral part of the technical teachings of the disclosure provided herein.

[0068] As previously mentioned, various embodiments of this disclosure relate to a processing system. The processing system includes a plurality of microprocessors programmable via software instructions, a memory controller configured to read software instructions from non-volatile memory, at least one resource / peripheral device, and a communication system connecting the processing core to the memory controller and one or more resources.

[0069] In various embodiments, multiple safety monitoring circuits are configured to generate multiple error signals by monitoring the operation of a microprocessor, a memory controller, and / or one or more resources. Therefore, a fault collection and error management circuit is configured to receive multiple error signals from the multiple safety monitoring circuits and generate one or more reaction signals based on the multiple error signals.

[0070] Specifically, in various embodiments, the fault collection and error management circuitry includes multiple fault collection sub-circuits and error management circuitry.

[0071] In various embodiments, each fault collection subcircuit includes one or more error combination circuits, wherein each error combination circuit includes a first register programmable via software instructions executable by a microprocessor. For example, each first register may be connected to a communication system and has been associated with a corresponding physical address, wherein the first register can be programmed by sending a write request including the corresponding physical address to the communication system.

[0072] In various embodiments, each error combination circuit is configured to receive a subset of error signals, determine whether one or more of the received error signals are asserted, and, in response to determining that one or more of the received error signals are asserted, store error status data in a first register, wherein the error status data identifies the asserted one or more error signals. In various embodiments, each error combination circuit is also configured to read enable data from the first register, wherein the enable data specifies for each error signal whether a combined error signal should be asserted when the corresponding error signal is asserted, and generates a combined error signal based on the error status data and the enable data; that is, asserting the combined error signal when an error signal is asserted, and the corresponding enable data specifies that the combined error signal should be asserted. Thus, in various embodiments, the microprocessor can be programmed to specify which errors should be signaled via the combined error signal, and can read the error status data to determine which error is asserted (or which errors are asserted).

[0073] In various embodiments, the error management circuitry includes a second register programmable via software instructions executed by a microprocessor. For example, the second register may also be connected to a communication system and associated with a corresponding physical address, wherein the second register can be programmed by sending a write request to the communication system including the corresponding physical address.

[0074] In various embodiments, the error management circuitry is configured to receive combined error signals from the error combination circuitry, read routing data from a second register, wherein the routing data specifies for each combined error signal and each microprocessor whether an error should be signaled to the corresponding microprocessor when the corresponding combined error signal is asserted, and generates a corresponding signal, such as an interrupt signal or an exception signal, for each microprocessor to signal the error based on the combined error signal and the routing data; that is, when the combined error signal is asserted, the signal is asserted, and the routing data specifies for the corresponding combined error signal that an error should be signaled to the microprocessor. Therefore, in various embodiments, the microprocessor can be programmed with the routing data to specify which combined error signals should be signaled to each microprocessor.

[0075] Specifically, this solution is particularly useful for processing systems configured to execute a hypervisor and one or more virtual machines. In fact, the routing data stored in the second register and the enable data associated with the first set of error signals can be programmed by the hypervisor, while the enable data associated with the corresponding set of error signals can be programmed by each virtual machine.

[0076] For example, to control access to the first and second registers, the processing system may include one or more hardware address protection circuits configured to selectively forward write requests generated by the microprocessor to the second register or the first register of an error combination circuit based on virtual address translation data and / or access permission data. For example, in various embodiments, a corresponding hardware address protection circuit, such as a memory management unit or a memory protection unit, is associated with each microprocessor. In this case, the management program may be configured to at least partially program the virtual address translation data and / or access permission data for each microprocessor.

[0077] For example, in the case of virtual machines, each microprocessor may have been associated with a register for storing the virtual machine ID, and hardware address protection circuitry can be configured to use virtual address translation data and / or access permissions based on the virtual machine ID stored in that register. Therefore, in this scenario, the hypervisor can be configured to associate each virtual machine with a corresponding virtual machine ID, program corresponding virtual address translation data and / or access permission data (which restricts access to a first register and a second register) for each virtual machine ID, determine for each microprocessor whether a virtual machine should be executed, program the corresponding virtual machine ID into the register associated with the microprocessor, and start the corresponding virtual machine on the microprocessor.

[0078] Typically, the fault collection subcircuit can therefore receive system error signals, error signals related to a specific microprocessor or virtual machine, or shared resources. Thus, error signals can be assigned in different ways depending on whether the processing system is a custom or general-purpose system.

[0079] For example, one or more fault collection subcircuits may be associated with a supervisor, i.e., the processing system is configured to allow access to the fault collection subcircuit only via a microprocessor executing the supervisor. For example, the fault collection subcircuit may include one or more error combination circuits configured to receive system error signals and / or error signals generated by one or more safety monitoring circuits configured to monitor the operation of shared memory and / or shared resources.

[0080] Additionally or alternatively, each microprocessor (or virtual machine) may be associated with a corresponding fault collection subcircuit, which includes one or more error combination circuits configured to receive error signals generated by one or more security monitoring circuits configured to monitor the operation of the corresponding microprocessor (or one or more microprocessors configured to execute a virtual machine). In various embodiments, these error combination circuits may also receive error signals generated by one or more security monitoring circuits configured to monitor the operation of resources and / or memory regions associated with the corresponding microprocessor (or virtual machine) (already during the hardware design phase).

[0081] Therefore, in this configuration, each microprocessor (or each microprocessor executing a given virtual machine) can program the first register of the corresponding fault collection subcircuit. For example, the hypervisor can be configured to program virtual address translation data and / or access permission data such that each microprocessor (or each microprocessor executing a given virtual machine) can access the first register of one or more error combination circuits of the fault collection subcircuit associated with the microprocessor (or virtual machine). Furthermore, the hypervisor can configure routing data stored in a second register to forward combined error signals to one or more associated microprocessors. For example, the hypervisor can be configured to program routing data stored in a second register to forward combined error signals generated by one or more error combination circuits of the fault collection subcircuit associated with the microprocessor (or virtual machine) to the corresponding microprocessor (or one or more microprocessors configured to execute the virtual machine). Attached Figure Description

[0082] Embodiments of the present disclosure will now be described with reference to the accompanying drawings, which are provided by way of non-limiting example only, and in which:

[0083] Figure 1 An example of an electronic system including multiple processing systems is shown;

[0084] Figure 2 and Figure 3 An example of a processing system is shown;

[0085] Figure 4 An example of a processing system including fault collection and error management circuitry is shown;

[0086] Figure 5 It shows Figure 4 An example of a fault collection and error management circuit;

[0087] Figure 6 An example of the connection between multiple safety monitoring circuits and fault collection and error management circuits is shown;

[0088] Figure 7 An embodiment of a processing system including fault collection circuitry and error management circuitry is shown;

[0089] Figure 8 An example of software executed by a processing system is shown, wherein the software is divided into an operating system and applications;

[0090] Figure 9 An example of software executed by a processing system is shown, wherein the software is divided into a hypervisor and multiple virtual machines;

[0091] Figure 10 It shows Figure 7 Examples of fault collection circuits and error management circuits;

[0092] Figure 11 Shown for Figure 10 An embodiment of a programmable error signal processing circuit for a fault collection circuit;

[0093] Figure 12 It shows the result of Figure 10 An example of the configuration data used by the error management circuit; and

[0094] Figure 13 It shows the result of Figure 10 An example of a signal generated by an error management circuit. Detailed Implementation

[0095] In the following description, numerous specific details are set forth to provide a thorough understanding of the embodiments. Embodiments may be implemented without one or more of these specific details or using other methods, components, materials, etc. In other instances, well-known structures, materials, or operations have not been shown or described in detail so as not to obscure aspects of the embodiments.

[0096] Throughout this specification, references to "an embodiment" or "one embodiment" mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment. Therefore, the phrases "in one embodiment" or "in one embodiment" appearing in various places throughout the specification do not necessarily refer to the same embodiment. Furthermore, a particular feature, structure, or characteristic may be combined in any suitable manner in one or more embodiments.

[0097] The headings provided herein are for convenience only and do not explain the scope or meaning of the embodiments.

[0098] In the following Figures 7 to 13 In each part, reference has been made Figures 1 to 6 The parts, elements, or components described are indicated by the same reference numerals previously used in this figure; the descriptions of these previously described elements will not be repeated below to avoid making this specific embodiment cumbersome.

[0099] Figure 7 An embodiment of the processing system 10a according to the present description is shown.

[0100] In the considered embodiment, the underlying architecture of the processing system 10a corresponds to... Figures 1 to 6 The processing system described herein, and the corresponding description applies in its entirety. Therefore, also in this context, the processing system 10a, such as an integrated circuit, includes:

[0101] - Communication system 114, such as bus or NoC;

[0102] -At least one processing core 102a, such as processing core 102 a1 102 an Each processing core includes at least one microprocessor 1020 and at least one communication interface 1022, the at least one communication interface 1022 being configured to connect the microprocessor 1020 to the communication system 114.

[0103] - At least one memory controller 100 is configured to be connected to (internal or external) non-volatile memory 104 and / or volatile memory 104b;

[0104] - Optional other circuitry, such as one or more resource / peripheral devices 106 and / or DMA controller 110.

[0105] As mentioned earlier, it may be necessary to manage a significant number of error signals ERR within the processing system 10a, such as error signals ERR1, ..., ERR2. mSpecifically, such an error signal ERR is generated by a security monitoring circuit SM, which analyzes the behavior of related circuitry such as processing core 102, memory controller 100, or resource / peripheral device 106. Typically, multiple security monitoring circuits SM can be associated with the same circuitry and monitor different potential errors, such as one or more security monitoring circuits monitoring different memory ranges of memory 104 or 104b. Typically, such security monitoring circuits SM are located near or even integrated into the related circuitry.

[0106] In this context, the inventors have observed that forwarding various error signals ERR from the safety monitoring circuit SM (which is distributed within the processing system) to the centralized fault collection and error management circuit 120 can be quite inefficient. Indeed, on the one hand, the fault collection and error management circuit 120 must support a corresponding number of error signals, which increases its size. On the other hand, each error signal ERR must be provided to its corresponding input via a corresponding trace to the fault collection and error management circuit 120, which can involve complex wiring within the processing system.

[0107] Therefore, in order to reduce the number of inputs to the fault collection and error management circuitry and the wiring within the processing system, the processing system may include a fault collection and management circuitry, which is divided into two circuits:

[0108] - Fault collection circuit 30, including multiple error combination circuits 320; and

[0109] - Fault management circuit 34.

[0110] For example, various error combination circuits 320, such as error combination circuits 3201, ..., 320 p Each error combination circuit 320 is configured to generate a combined error signal CES by combining multiple error signals ERR via combinational logic operations (e.g., via a logical OR operation). Thus, in this case, combined error signals such as CES1, ..., CES... p Each combined error signal CES can be provided to a corresponding input of the error management circuit 34. Therefore, the error combination circuit 320 can be located near the corresponding safety monitoring circuit SM.

[0111] While this solution reduces the size of the fault collection and error management circuitry and the wiring issues of the error signal ERR, it introduces other problems.

[0112] For example, based on the combinational logic operation used within such an error combination circuit 320, when one (or more) of the received error signals ERR are fixed to a given logic level, for example, when set high in the case of a logical OR operation, the combinational error signal CES generated by the error combination circuit 320 can be fixed to a given logic level. For example, it can be asserted that a given error signal ERR is fixed either because the corresponding safety monitor circuit SM has detected an error, or because the safety monitor circuit SM itself has malfunctioned. However, this implies that triggering in another error signal ERR managed by the same error combination circuit 320 may be masked, potentially reducing overall safety coverage.

[0113] Furthermore, the error management circuit 34 is no longer able to distinguish the error signal ERR that has been combined into the corresponding combined error signal CES. Therefore, in order to distinguish the error again, the safety monitoring circuit SM and / or the fault collection sub-circuit 32 must include a register for storing the error status, wherein the register is readable, for example, by means of software instructions executed on the processing core 102.

[0114] Furthermore, adding and integrating new safety monitors (SMs) that may also have different error triggering characteristics using simple logic gates may require modification of the error management circuitry 34. This modification may not be desirable, for example, because the error management circuitry 34 may be an already tested IP design.

[0115] The inventors also observed that, in addition to these problems, modern processing systems have shifted towards the concept of software tasks, where processing system 10a can execute several software tasks, for example, by executing tasks 102a sequentially on the same processing core and / or executing tasks in parallel on multiple processing cores 102a. However, such tasks may perform completely different operations. Therefore, from a security and / or safety perspective, each task should only be granted access permissions.

[0116] Typically, each processing core 102a can access other circuitry by sending a read or write request (REQ) to the communication system 114 via a corresponding interface 1022. This request includes a physical address associated with a target circuitry such as a memory controller, resource 106, or even another processing core 102a. Therefore, the processing system 10 can manage access permissions by transmitting such requests to the communication system 114 via software and / or hardware control.

[0117] For example, such as Figure 8 As shown, this access permission is typically achieved by separating software tasks into tasks of the operating system (OS) and tasks of the application (APP) executed by the OS.

[0118] Specifically, in software protection mechanisms, all read and write requests from an application (APP) must go through the operating system (OS) to determine whether the application can send a request to a given target address.

[0119] Conversely, in hardware address protection, each processing core 102a (or, in the case where processing core 102a includes multiple microprocessors, or even each microprocessor 1020) includes or is associated with hardware address protection circuitry 1028 (see also...). Figure 7 The hardware address protection circuit 1028 manages the forwarding of read or write requests generated by the processing core 102 to the communication system 114, such as the forwarding of read or write requests generated by the corresponding microprocessor 1020 to the communication interface 1022.

[0120] Specifically, the memory management unit (MMU) for a Virtual Memory System Architecture (VMSA), such as an ARM AArch64 architecture, allows the configuration of one or more translation tables (TTBs) via the operating system (OS). Specifically, the translation tables allow mapping a given virtual address to a corresponding physical address or another virtual address. Specifically, this mapping of the virtual address (VA) of communication system 114 (possibly via various translation tables for different exception levels) to the physical address (PA) is implemented directly within the hardware MMU of processing core 102a or microprocessor 1020. Therefore, the access permissions of a given software task can be controlled by defining the mapping from the virtual address range used by the software task executed by microprocessor 1020 to the actual physical address range of communication system 114; for example, the MMU can be configured as follows:

[0121] - When the request received by the microprocessor 1020 includes a virtual address specified in the translation table, the virtual address is translated into the corresponding physical address and the modified request is forwarded to the communication system 114; or

[0122] - If the request received by the microprocessor 1020 includes a virtual address that is not specified in the translation table, the request is rejected.

[0123] Conversely, memory protection units (MPUs) used in protected memory system architectures (PMSA), such as the ARM AArch32 architecture with PMSA, do not perform address translation. Specifically, instead of defining a mapping from virtual addresses to physical addresses, the MPU allows the direct specification, for example, of the physical addresses / address ranges accessible by the software tasks executed by the microprocessor 1020 via one or more access permission tables. For instance, the MPU can be configured as follows:

[0124] - When the request received by microprocessor 1020 includes a physical address specified in the access permission table, the request is forwarded to communication system 114; or

[0125] - If the request received by the microprocessor 1020 includes a physical address not specified in the access permission table, the request is rejected.

[0126] and, Figure 9 This illustrates a recently proposed implementation of virtualization, where the hypervisor HYP is executed by the processing system 10a. Specifically, the hypervisor HYP essentially corresponds to a specific software layer that allows the configuration of multiple (k) virtual machines VM1, ..., VM2. k Each virtual machine (VM) can execute corresponding software tasks, such as the corresponding operating system (OS) and one or more corresponding applications (APPs).

[0127] Therefore, when using the VMSA architecture, each virtual machine VM1...VM k It may already be associated with a corresponding virtual address range, the so-called Intermediate Physical Address (IPA). Similarly, when using the PMSA architecture, each virtual machine VM1...VM k It may already be associated with a corresponding physical address range. For example, such virtual machine translation tables or access permission tables are typically implemented in exception level EL2. For example, in ARM architecture, the selection of a current rule based on one or more virtual machine translation tables or one or more access permission tables can be performed according to the following:

[0128] - A virtual machine ID (VMID) value that identifies the virtual machine currently being executed by the given microprocessor 1020, where the VMID is typically set by the hypervisor HYP; and

[0129] - Value Address Space ID (ASID) identifies a given software task (e.g., a specific application) or group of software tasks (e.g., tasks of the operating system), where the ASID is typically set by the operating system OS.

[0130] Typically, because a given microprocessor 1020 is not necessarily explicitly associated with a given corresponding virtual machine, a VMID value is usually required. For example, multiple virtual machines can be executed (via a time-based scheduling scheme) on the same processing core 102a, or a given virtual machine can be executed by multiple microprocessors 1020 (in parallel or sequentially). Essentially, when the hypervisor HYP switches from one virtual machine to another, the virtual machine 1020 can set the corresponding VMID of the given microprocessor 1020.

[0131] Therefore, the hypervisor HYP can assign access permissions for a given physical address range to each virtual machine (VM) by configuring one or more translation tables of the MMU or one or more access permission tables of the MPU. Similarly, other master interfaces (e.g., DMA controller 110 or resource 106) can also send read or write requests to the communication system 114 via the System Memory Management Unit (SMMU) or System Memory Protection Unit (SMPU). Therefore, furthermore, in this case, the hypervisor HYP can assign access permissions for a given physical address range to each master interface by configuring one or more translation tables of the SMMU or one or more access permission tables of the SMPU. For example, a given resource 106 and / or a given address range managed by the memory controller 100 can be explicitly assigned to a given virtual machine (VM) or the hypervisor HYP. For example, the hypervisor HYP can configure the processing system 10a such that a given resource 106 (e.g., a communication interface) can only be accessed by a first virtual machine and not by a second virtual machine.

[0132] However, as mentioned above, when the fault collection sub-circuit 32 is used, the detailed information about the error signal ERR that has triggered the given combined error signal CES is actually stored in the register of the corresponding safety monitoring circuit or the corresponding error combination circuit 320.

[0133] However, it is generally not possible to prevent access to individual bits of the register associated with a given physical address via the protection circuit 1028. Therefore, the only way to restrict access to these error bits and the corresponding register bits for a given virtual machine is to block access from all virtual machines and allow access only to the hypervisor HYP, thus providing the corresponding error information to the virtual machine VM associated with the circuit that has generated the error signal.

[0134] However, this means that a significant delay may be introduced between the moment when the security monitor circuit SM signals an error to the microprocessor 1020 via the interrupt IRQ and the moment when the corresponding virtual machine VM actually receives the information that the error was signaled.

[0135] To address the aforementioned issues, in various embodiments of the present invention, the fault acquisition circuit 30 and the fault management circuit 34 are configured in a specific manner, thereby simplifying the management of the error signal ERR, particularly in the context of, for example, a multi-core processing system 10a for executing multiple (k) virtual machines VMs.

[0136] Specifically, if Figure 10As shown, in various embodiments, the fault acquisition circuit 30 includes multiple fault acquisition sub-circuits 32, hereinafter also referred to as a combined error manager (CEM) circuit. For example, in the considered embodiment, the fault acquisition circuit 30 includes p fault acquisition sub-circuits 321, ..., 32. p .

[0137] Specifically, as described in more detail below, the number p of the fault collection sub-circuits 32 corresponds to or is greater than:

[0138] - The number of microprocessors 1020 in the processing system 10a, for example, in the case where each processing core 102a includes a single microprocessor 1020, is n; or

[0139] - The number k of virtual machines (VMs) configured to run in parallel on the processing system 10a.

[0140] In fact, this allows each virtual machine VM or each microprocessor 1020 to be associated with a corresponding fault collection subcircuit 32.

[0141] In various embodiments, the processing system 10a may include additional fault collection subcircuit 32 associated with the management program HYP.

[0142] In various embodiments, the processing system 10a may also include additional fault collection subcircuit 32 that can manage system errors not specifically associated with a particular virtual machine VM or processing core 102a, such as errors associated with monitored clock signals, power supply voltages, temperatures, etc.

[0143] In various embodiments, each fault collection subcircuit / CEM circuit 32 includes one or more programmable error combination circuits 320, for example, a plurality (q) of error combination circuits 320 for the fault collection subcircuit 321. 1,1 320 1,q Specifically, each error combination circuit 320 is configured to generate a corresponding combination error signal CES. For example, error combination circuit 320 1,1 320 1,q Combined error signal CES 1,1 ...CES 1,q Specifically, in various embodiments, each error combination circuit 320 generates a corresponding combined error signal CES based on the received error signal ERR and the first configuration data set. In various embodiments, the programmable error combination circuits 320 may be distributed within the processing system 102a, for example, near the safety monitoring circuit SM that generates the corresponding error signal.

[0144] like Figure 10 As shown, in various embodiments, each error combination circuit 320 receives a given number (s) of error signals, such as error signals ERR1, ..., ERR2. s Typically, the number of error signals ERR, s, can be different for a given fault collection sub-circuit 32 and / or different for different fault collection sub-circuits 32.

[0145] Specifically, as previously mentioned, in various embodiments, the corresponding fault collection subcircuit 32 may be associated with each virtual machine VM or each microprocessor 1020. Thus, in various embodiments, the error signal ERR subcircuit 32 provided for a given fault collection includes an error signal ERR that may be of interest to the corresponding virtual machine VM or microprocessor 1020.

[0146] For example, in various embodiments, a fault collection subcircuit 32 may be explicitly associated with each microprocessor 1020, wherein each subcircuit 32 includes one or more error combination circuits 320 configured to collect errors 102 associated with the corresponding microprocessor, such as by monitoring the corresponding microprocessor 1020 (see example...). Figure 6 Safety monitoring circuit SM in 102 Errors generated by monitoring predetermined memory ranges in memory 104 and / or 104b assigned to microprocessor 1020 (see, for example) Figure 6 Safety monitoring circuit SM in 104 Errors generated by monitoring various components (such as memory 1026, protection unit 1028, and / or interface 1022) in the processing core 102a. In practice, this is usually sufficient because each microprocessor 1020 executes only the corresponding virtual machine (VM) at a given time, and multiple microprocessors 1020 can also be assigned to the same virtual machine; that is, each microprocessor 1020 is explicitly associated with a corresponding virtual machine at a given time.

[0147] Regarding other resources / peripherals 106, these resources can be explicitly assigned to a given microprocessor 1020, or the assignment can be programmable, for example, by specifying access permissions as described with respect to protection unit 1028.

[0148] Therefore, in cases where a custom processing system 10a has been assigned a predetermined resource 106 to a virtual machine VM, the error signals related to the resource 106 received by each fault collection sub-circuit 32 may also be different.

[0149] In contrast, in the case of the general-purpose processing system 10a, various solutions can be adopted.

[0150] In the first solution, error signals generated for one or more resources 106 are managed by the fault collection subcircuit 32 assigned to the management program HYP, thereby performing global management of error signals related to (shared) resources 106.

[0151] In the second solution, each fault collection sub-circuit 32 associated with the microprocessor 1020 can receive an error signal ERR generated for a given resource 106, thereby allowing each microprocessor 1020 to monitor the error signal of the given resource individually.

[0152] In the third solution, one or more additional fault collection subcircuits 32 may be associated with one or more resources 106. For example, assuming that the fault collection subcircuit 32 monitors a given number of resources 106, such as communication interfaces or communication channels of the same resources, the additional fault collection subcircuit 32 may include a corresponding error combination circuit 320 for each resource, and thus the corresponding error combination circuit 320 may be assigned (via appropriate programming) to the corresponding virtual machine VM / microprocessor 1020.

[0153] Typically, the above schemes can also be combined in any suitable manner. For example, a low-speed communication interface (e.g., UART) can be managed via a hypervisor, while a high-speed communication interface (e.g., CAN or Ethernet) may be associated with a corresponding error combination circuit 320 of the additional fault collection subcircuit 32, which can then be assigned to a virtual machine VM or microprocessor 1020 (via appropriate programming of access permissions).

[0154] As previously mentioned, the processing system 10a may also include one or more other fault collection sub-circuits 32, such as:

[0155] - Fault collection subcircuit 32 is configured to manage error signals that the management program HYP may be interested in (e.g., it may only receive a reduced set of error signals); and / or

[0156] - Fault collection subcircuit 32 is configured to collect system errors, i.e., errors common to all virtual machines (VMs).

[0157] Typically, the number s of error signals of the error combination circuit 320 and the number q of error combination circuits 320 of the fault collection sub-circuit 32 are defined during the hardware design phase of the processing system 10a.

[0158] Therefore, in each embodiment, each error combination circuit 320 receives the corresponding error signals ERR1, ..., ERR. s The set is used to generate the corresponding combined error signal CES. For example... Figure 10 As shown, the combined error signal of the fault collection subcircuit 32 is provided to the error management circuit 34. Therefore, in the considered embodiment, the error management circuit receives the combined error signal 321 (identified as CES) from the fault collection subcircuit. 1,1 To CES 1,q ), combined error signals from fault collection sub-circuit 322 (simply labeled CES2), etc.

[0159] For example, Figure 10 In error combination circuit 32 01,1 The example illustrates a possible embodiment of the error combination circuit 320. Specifically, in the considered embodiment, the error combination circuit 320 includes:

[0160] -For each error signal ERR1, ..., ERR s The corresponding programmable error signal processing circuit 3200, namely, error signal processing circuits 32001, ..., 3200. s Each programmable error signal processing circuit 3200 generates a processed corresponding error signal ERR', namely, processed error signals ERR'1, ..., ERR'. s ;

[0161] - Combinational logic circuit 3202, configured to assert a corresponding combined error signal CES when at least one of the processed error signals ERR' is asserted, such as asserting one or more logic OR gates when both the processed error signal ERR' and the combined error signal CES are asserted via a logic high level; and

[0162] Register 3204 is configured to store configuration data for programming the programmable error signal processing circuit 3200.

[0163] For example, in Figure 10 In this system, register 3204 (via a corresponding communication interface) is connected to communication system 114 and can therefore be accessed via software instructions executed by microprocessor 1020.

[0164] Figure 11 Possible embodiments of a general-purpose programmable error signal processing circuit 3200i (which can be used in any circuit of circuit 3200) and register 3204 are shown.

[0165] Typically, the programmable error signal processing circuit 3200i receives the error signal ERR. i And provides a processed error signal ERR' based on the configuration data stored in register 3204. iSpecifically, in the considered embodiment, register 3204 includes two bits for each error signal processing circuit 3200i:

[0166] - Error status bit STATUS; and

[0167] - Enable bit ENABLE.

[0168] Specifically, in the considered embodiment, the enable bit ENABLE in register 3204 can be written by sending a request REQ via communication system 114. Conversely, when the corresponding error signal ERR is received... i When asserted, the error status bit STATUS is asserted and can be deasserted by sending a request REQ via communication system 114. For example, the error status bit STATUS can be implemented using a set-reset flip-flop, where the error signal ERR... i The corresponding bit of the request REQ received via communication system 114 is connected to the reset input; that is, the STATUS bit can be implemented using a so-called write-1-clear register.

[0169] In the considered embodiment, the error status bit STATUS and the enable bit ENABLE are provided to a logic gate 3208, such as an AND gate, which is configured to assert the processed error signal ERR' when both the error status bit STATUS and the enable bit ENABLE are asserted. i .

[0170] Optionally, the programmable error signal processing circuit 3200i may also include a synchronization circuit 3206 arranged between the input of the error signal ERRi and the status bit register STATUS. For example, such a synchronization circuit 3206 can be used to normalize the characteristics of the input flip-flops connected to the error combination circuit 320. For example, such a synchronization circuit 3206 may include a clock synchronization stage for decoupling the clock used by the corresponding safety monitoring circuit SM from the clock used by the error combination circuit 320. For example, such a clock synchronization stage can be implemented using multiple cascaded flip-flops, wherein these flip-flops use the clock signal of the error combination circuit 320, which preferably corresponds to the clock signal used by the error management circuit 34. Typically, the synchronization circuit 3206 can also perform other operations based on the characteristics of the received error signal ERR, such as inverting logic levels. Thus, by using the synchronization circuit 3206 and the status bit register STATUS, the characteristics of the combined error signal CES provided to the error management circuit 34 may be consistent.

[0171] Therefore, when the given error signal ERR of the error combination circuit 320 is asserted, the corresponding error status bit STATUS is also asserted. Moreover, when the corresponding enable bit ENABLE is asserted, the processed corresponding error signal ERR' is also asserted, thereby also asserting the combined error signal CES of the error combination circuit 320 via the combinational logic circuit 3202.

[0172] Therefore, by programming the ENABLE bit of register 3204, microprocessor 1020 can specify which errors should be signaled via the corresponding combined error signal CES. For example, in various embodiments, the ENABLE bit is asserted by default. Conversely, by reading the STATUS bit of register 3204, microprocessor 1020 can determine which error signals ERR were triggered, and thus use these error signals ERR to determine which error signal ERR is asserted and assert the combined error signal CES.

[0173] For example, because the ENABLE bit can be used to individually enable or disable each error trigger, processing core 102a can disable the error signal ERR of any security monitoring circuit SM that malfunctions and causes the error signal ERR to always be asserted. For example, in a complex clock tree architecture, different clock monitoring circuits SM can be inserted on various branches of the clock tree. The number of clock monitoring circuits can be large enough to facilitate the combination of the corresponding error signals ERR via one or more error combination circuits 320, thereby generating one or more combined error signals CES. For example, in various embodiments, clock monitoring circuits (such as PLLs that generate clock signals) specifically associated with a given microprocessor 1020, provided only to the corresponding microprocessor 1020, can be provided to the fault collection subcircuit 32 associated with the corresponding microprocessor 1020. Conversely, error signals generated by clock monitoring circuits that monitor a shared clock signal (provided directly or indirectly to several microprocessors 1020, memory controller 100, and / or resources 106) can be provided to one or more error combination circuits 320 that can be managed, for example, by a hypervisor HYP.

[0174] If a clock monitor circuit is defective and its error signal ERR is fixed at 1, the software may decide to disable the corresponding enable bit ENABLE so that the combined error signal CES is not fixed at 1.

[0175] Typically, in various embodiments, one or more of the enable bits ENABLE may always be asserted (and are not programmable), or the corresponding enable bit ENABLE and the corresponding logic gate 3208 may be omitted; that is, the processed error signal ERR' may correspond to the error status bit STATUS. For example, in this case, a safety-critical error may always be signaled. For example, this might be the case where the fault collection subcircuit 32 manages system errors.

[0176] In various embodiments, the (programmable) enable register bit ENABLE of a given register 3204 is protected by one or more parity bits. Therefore, a request sent by microprocessor 1020 includes not only the enable register bit ENABLE, but also one or more corresponding parity bits.

[0177] Therefore, in various embodiments, the error combination circuit 320 is configured to, for example, in response to a given event (e.g., in response to receiving a request REQ) and / or periodically, calculate one or more parity bits for storage in the ENABLE bit of register 3204, and compare one or more calculated parity bits with one or more parity bits received with the request. The parity scheme is set at design time; for example, it may be one parity bit protecting 8 register bits, one parity bit protecting 16 register bits, or one parity bit protecting 32 register bits. Furthermore, parity can be calculated on either an even or odd scheme. For example, when using an odd parity scheme, the parity bit can be set to 1 when the number of bits set to 1 is even. Given the default value of the ENABLE bit in register 3204, the corresponding reset value of the parity bit is set accordingly.

[0178] As previously mentioned, one or more parity bits can be calculated in response to a given event and / or periodically. For example, in various embodiments, the error combination circuit 320 is configured to calculate the parity bits when a write request REQ is received, and the calculated or received parity bits are stored in other registers. Moreover, the error combination circuit 320 is configured to recalculate the parity bits periodically (e.g., in each clock cycle) and compare the calculated parity bits with the stored parity bits.

[0179] In the event of a mismatch in parity check data, the error combination circuit 320 can assert an error signal, which can be provided to:

[0180] - The error signal processing circuit 3200 of the error combination circuit 320 itself; or

[0181] -Another fault collection sub-circuit 32 for collecting parity error signals is the error signal processing circuit 3200.

[0182] For example, since such parity errors are safety-critical, a dedicated error combination circuit 320 may be particularly suitable. Therefore, in this case, the error signal associated with the parity error may not be masked via the ENABLE bit.

[0183] Therefore, by using multiple fault collection subcircuits 32, each virtual machine VM (which may be executed on multiple microprocessors) or each microprocessor 1020 can be associated with a corresponding fault collection subcircuit 32. For example, for this purpose, the hardware address protection circuitry 1028 (such as an MMU or MPU) of each microprocessor 1020 can be programmed to allow access to register 3204 of the fault collection subcircuit 32 associated with the microprocessor 1020 or to the virtual machine VM executed by the microprocessor 1020. Thus, the microprocessor 1020 can send a read or write request REQ to register 3204 of the corresponding subcircuit 32 so that:

[0184] - Set the corresponding enable bit to ENABLE;

[0185] - Read or clear the corresponding status bit STATUS.

[0186] Therefore, the microprocessor 1020 can determine which errors are signaled via one or more combined error signals CES, and can read the status bit STATUS to determine which error was signaled.

[0187] For example, one or more resources 106 or memory regions in memory 104 or 104b may also be associated with each virtual machine (VM). Thus, in various embodiments, the microprocessor 1020 executing a given virtual machine may be programmed to enable the corresponding fault collection subcircuit 32 to forward errors generated by one or more resources 106 associated with the corresponding virtual machine (VM) and / or errors generated by the memory controller 100 for the address range associated with the corresponding virtual machine (VM) via one or more corresponding combined error signals CES.

[0188] Therefore, in various embodiments, the error management circuit 34 is configured to generate internal response signals (e.g., signals IRQ and optionally RST) and optional external responses (e.g., signals ET and / or SET) based on the combined error signal CES and the second configuration data set. For example, in various embodiments, the error management circuit 34 is configured to generate at least one of the following for each microprocessor 1020:

[0189] - Interrupt request signal IRQ;

[0190] -System error interrupt request signal SEI; and

[0191] - Virtual System Error Interruption Request Signal (VSEI).

[0192] To allow a virtual machine (VM) to handle its own errors, the errors of the circuitry associated with a given VM should generate an internal response provided to one or more microprocessors 1020 executing the VM. This is achieved, on one hand, by programming the register 3204 of the corresponding fault collection sub-circuit 32 in a suitable manner. On the other hand, the error management circuit 34 should correctly forward the combined error signal CES generated by the given fault collection circuit 32 to the respective microprocessor 1020 or the microprocessor executing the corresponding VM. Furthermore, in various embodiments, one or more of the combined error signals CES may also be related to system errors.

[0193] Therefore, such as Figure 12 As shown, in various embodiments, the error management circuit 34 includes one or more registers 340 for storing corresponding configuration data CD for each combined error signal CES, the corresponding configuration data CD including:

[0194] - Routing data RD that identifies which microprocessor(s) 1020 should forward the corresponding combined error signal CES to; and

[0195] - Optional selection data SD indicates which internal response signal should be set, such as not setting any signal, or setting one of the signals IRQ, SEI, and VSEI.

[0196] Typically, when each microprocessor 1020 is associated with a given fault collection sub-circuit 32, routing data RD for the corresponding combined error signal CES can also be fixed.

[0197] However, for example, when each virtual machine (VM) is associated with a corresponding fault collection subcircuit 32 and / or when multiple microprocessors 1020 execute the same VM, the routing data RD can also be programmable to selectively forward the corresponding combined error signal CES to one or more microprocessors 1020 assigned to the VM. For example, in various embodiments, register 340 can be connected to communication system 114 via a corresponding communication interface and thus can be programmed via software instructions executed by the microprocessor 1020. In various embodiments, register 340 can only be programmed via a hypervisor HYP, which determines which VM is executed on a given microprocessor 1020.

[0198] For example, in various embodiments, the routing data RD includes corresponding bits, such as bits CPU1, CPU2, etc., for each microprocessor 1020 of the processing system 10a, which allow enabling the corresponding combined error signal CES to be forwarded to one or more microprocessors 1020. For example, this allows setting all flags for the combined error signal CES provided by the fault collection subcircuit 34 that handles system errors.

[0199] Therefore, in the considered embodiment, the hypervisor HYP can program the routing data RD to forward a given combined error signal CES to any microprocessor 1020 (or multiple microprocessors), without necessarily forwarding it to the corresponding microprocessor 1020 or the virtual machine VM for which the error has already been generated. For example, such that, for instance, if the microprocessor 1020 executing the virtual machine does not comply with ASIL-D, one or more combined error signals CES can be forwarded to, for example, another microprocessor 1020 implementing a redundant CPU and / or an ASIL-D compliant microprocessor, which may be internal (e.g., via an interrupt signal IRQ or another exception signal) or external (e.g., via a signal ET) relative to the processing system 10a.

[0200] As mentioned earlier, the selection data SD can be used to specify which internal response signal should be set. For example, in various embodiments, register 340 includes two bits, which are encoded using the following:

[0201] - "00": No signals IRQ, SEI, and VSEI were asserted.

[0202] - "01": The IRQ signal is asserted;

[0203] - "10": The signal SEI is asserted; and

[0204] - "11": Signal VSEI is asserted.

[0205] Therefore, in various embodiments, one or more corresponding internal response signals IRQ, SEI and / or VSEI are generated for each microprocessor 1020 of the processing system 10a.

[0206] For example, Figure 13 An embodiment is shown in which the processing system 10a includes three processing cores 102a1, 102a2 and 102a3, wherein each processing core 102a includes two microprocessors 1020, that is, the processing system 10a includes six microprocessors 10201, ... 10206.

[0207] Specifically, in the considered embodiments, each microprocessor 1020 includes:

[0208] - The first terminal INT is used to receive and process the core interrupt request signal IRQ;

[0209] - The second terminal SEI is used to receive the system error interrupt request signal SEI; and

[0210] - The third terminal, VSEI, is used to receive virtual system error interrupt request signals.

[0211] Therefore, in the considered embodiment, the error management circuit 34 is configured to generate six processing core interrupt request signals IRQ (IRQ1, ..., IRQ6), six system error interrupt request signals SEI (SEI1, ..., SEI6), and six virtual system error interrupt request signals VSEI (VSEI1, ..., VSEI6), wherein these signals are based on the fault collection subcircuits 321, ..., 32 p Received combined error signals CES1, ..., CES p And, for example, configuration data CD stored in register 340 is asserted.

[0212] Specifically, while the corresponding System Error Interrupt Request Signal (SEI) and Virtual System Error Interrupt Request Signal (VSEI) are directly provided to each microprocessor 1020, Interrupt Request Signals (IRQs) are indirectly provided to the microprocessor 1020. Specifically, in the considered embodiments, each processing core 102a includes a Generic Interrupt Controller (GIC) interface configured to receive all Interrupt Request Signals (IRQs) and selectively forward a first Interrupt Request Signal (IRQ) to terminal INT of a first microprocessor 1020 of processing core 102a and selectively forward a second Interrupt Request Signal (IRQ) to terminal INT of a second microprocessor 1020 of processing core 102a. In various embodiments, additional routing data for forwarding processing core Interrupt Request Signals (IRQs) via the CIG is programmable, preferably programmable via a hypervisor (HYP).

[0213] Therefore, in various embodiments, the error signal ERR associated with the circuitry assigned to a given virtual machine VM (or microprocessor 1020) is reported to the error combination circuitry 320VM of the fault collection subcircuit 32 associated with the virtual machine (or microprocessor 1020). By configuring the hardware address protection circuitry 1028 of the virtual machine VM (or microprocessor 1020), the corresponding register 3204 is accessible only by that virtual machine VM (or microprocessor 1020). Based on the configuration of register 3204, the error is reported to the error management circuitry 34 via the corresponding combined error signal CES. For example, the response of the error management circuitry 34 can be pre-programmed via the hypervisor HYP, for example, to assert an interrupt signal assigned to the microprocessor 1020 of the virtual machine VM. Then, in response to the interrupt, the microprocessor 1020 can read the contents of the status bits of the corresponding fault collection subcircuit 32 to determine which error signal was indeed set.

[0214] The above scenario can occur simultaneously in another virtual machine, and because the software-operated registers are assigned to different fault collection subcircuits 32 associated with different virtual machines, both will be able to manage their own errors without interfering with each other.

[0215] Of course, without prejudice to the principles of the invention, the details of the construction and embodiments may vary considerably from what is described and illustrated herein purely by way of example, without departing from the scope of the invention as defined by the appended claims.

Claims

1. A processing system, comprising: Multiple microprocessors, programmable via software instructions; A memory controller is configured to read the software instructions from non-volatile memory; resource; A communication system connects the microprocessor to the memory controller and the resources; Multiple safety monitoring circuits are configured to generate multiple error signals by monitoring the operation of the microprocessor, the memory controller, and / or the resources; The fault collection and error management circuitry is configured as follows: Receive the plurality of error signals from the plurality of safety monitoring circuits; as well as One or more reaction signals are generated based on the plurality of error signals; The fault collection and error management circuitry includes: Multiple fault collection subcircuits, each including one or more error combination circuits, wherein each error combination circuit includes a first register, the first register being programmable via a first software instruction executed by a corresponding microprocessor, and configured to: Receive a subset of the error signals; Determine whether one or more of the received error signals are asserted; In response to determining that one or more of the received error signals are asserted, error state data is stored in the first register, the error state data identifying the asserted one or more error signals; Read enable data from the first register, the enable data specifying for each error signal whether a combined error signal should be asserted when the corresponding error signal is asserted; and The combined error signal is generated based on the error status data and the activation data; and The error management circuit includes a second register, which can be programmed via a second software instruction executed by the corresponding microprocessor and is configured to: Receive the combined error signal from the error combination circuit; Routing data is read from the second register, which specifies whether an error should be signaled to each microprocessor when the corresponding combined error signal is asserted, for each combined error signal and each microprocessor; and Based on the combined error signal and the routing data, a corresponding signal is generated for each microprocessor to signal the error.

2. The processing system of claim 1, wherein the second register and the first register of each error combination circuit are connected to the communication system and have been associated with one or more corresponding physical addresses, and wherein each of the first register and the second register is programmable by sending a write request to the communication system including the corresponding physical address.

3. The processing system of claim 2, comprising one or more hardware address protection circuits configured to selectively forward the write request generated by the corresponding microprocessor to the second register and the first register of the corresponding error combination circuit, based on virtual address translation data and / or access permission data.

4. The processing system of claim 3, wherein the processing system is configured to execute a hypervisor and one or more virtual machines, and wherein the hypervisor is configured to program virtual address translation data and / or access permission data for each microprocessor and / or virtual machine.

5. The processing system of claim 4, wherein each microprocessor has been associated with a register for storing a virtual machine identifier (ID), wherein the corresponding hardware address protection circuitry is configured to use virtual address translation data and / or access permission data based on the virtual machine ID stored in the register associated with each microprocessor, and wherein the hypervisor is configured to: Associate each virtual machine with its corresponding virtual machine ID; Program corresponding virtual address translation data and / or access permission data for each virtual machine ID; For each microprocessor, determine whether the corresponding virtual machine should be executed; as well as In response to determining that the corresponding virtual machine should be executed on one of the microprocessors, the corresponding virtual machine ID is programmed into the register associated with the selected microprocessor, and the corresponding virtual machine is started on the selected microprocessor.

6. The processing system of claim 4, wherein the processing system is configured to allow access only to the routing data stored in the second register via the microprocessor executing the management program.

7. The processing system of claim 4, wherein the plurality of fault collection subcircuits includes fault collection subcircuits associated with the management program, wherein the processing system is configured to allow access only via the microprocessor executing the management program to the first register of the one or more error combination circuits of the fault collection subcircuit associated with the management program.

8. The processing system of claim 7, wherein the one or more error combination circuits of the fault collection subcircuit associated with the management program are configured to receive system error signals and / or error signals generated by one or more safety monitoring circuits, the one or more safety monitoring circuits being configured to monitor the operation of one or more first resources.

9. The processing system of claim 1, wherein the plurality of fault collection subcircuits includes a corresponding fault collection subcircuit for each microprocessor, the corresponding fault collection subcircuit including the one or more corresponding error combination circuits, the one or more corresponding error combination circuits being configured to receive the error signal generated by one or more safety monitoring circuits, the one or more safety monitoring circuits being configured to monitor the operation of the corresponding microprocessor.

10. The processing system of claim 9, wherein one or more error combination circuits of the error combination circuits of the corresponding fault collection sub-circuit associated with the corresponding microprocessor are configured to receive the error signal generated by the one or more safety monitoring circuits, the one or more safety monitoring circuits being configured to monitor the operation of one or more second resource and / or memory regions associated with the corresponding microprocessor.

11. The processing system according to claim 9, wherein: The processing system is configured to execute a hypervisor and one or more virtual machines, wherein the hypervisor is configured to program virtual address translation data and / or access permission data for each microprocessor and / or virtual machine; and The management program is configured to program the virtual address translation data and / or access permission data such that each microprocessor can access the first register of the one or more error combination circuits of the fault collection sub-circuit associated with each microprocessor.

12. The processing system according to claim 9, wherein: The processing system is configured to execute a hypervisor and one or more virtual machines, wherein the hypervisor is configured to program virtual address translation data and / or access permission data for each microprocessor and / or virtual machine; and The management program is configured to program the routing data stored in the second register to forward the combined error signal generated by one or more error combination circuits of the corresponding fault collection subcircuit associated with each microprocessor to each microprocessor.

13. The processing system of claim 1, wherein the processing system is disposed on an integrated circuit.

14. An apparatus comprising: Another communication system; as well as Multiple processing systems are connected via the other communication system, wherein each processing system comprises: Multiple microprocessors, programmable via software instructions; A memory controller is configured to read the software instructions from non-volatile memory; resource; A communication system connects the microprocessor to the memory controller and the resources; Multiple safety monitoring circuits are configured to generate multiple error signals by monitoring the operation of the microprocessor, the memory controller, and / or the resources; The fault collection and error management circuitry is configured as follows: Receive the plurality of error signals from the plurality of safety monitoring circuits; and One or more reaction signals are generated based on the plurality of error signals; The fault collection and error management circuitry includes: Multiple fault collection sub-circuits, each fault collection sub-circuit including one or more error combination circuits, wherein each error combination circuit includes a first register, the first register being programmable and configured via a first software instruction executed by a corresponding microprocessor to: Receive a subset of the error signals; Determine whether one or more of the received error signals are asserted; In response to determining that one or more of the received error signals are asserted, error state data is stored in the first register, the error state data identifying the asserted one or more error signals; Enable data is read from the first register, the enable data specifying for each error signal whether the combined error signal should be asserted when the corresponding error signal is asserted; and The combined error signal is generated based on the error status data and the activation data; and The error management circuit includes a second register, which can be programmed by a second software instruction executed by the corresponding microprocessor and is configured to: Receive the combined error signal from the error combination circuit; Routing data is read from the second register, the routing data specifying for each combined error signal and each microprocessor whether an error signal should be sent to each microprocessor when the corresponding combined error signal is asserted; and Based on the combined error signal and the routing data, a corresponding signal is generated for each microprocessor to notify of the error.

15. The device of claim 14, wherein the device is a vehicle.

16. A method of operating a processing system, the processing system comprising: Multiple microprocessors, programmable via software instructions; A memory controller is configured to read the software instructions from non-volatile memory; resource; A communication system connects the microprocessor to the memory controller and the resources; Multiple safety monitoring circuits are configured to generate multiple error signals by monitoring the operation of the microprocessor, the memory controller, and / or the resources; a fault collection and error management circuit includes multiple fault collection sub-circuits, each fault collection sub-circuit including one or more error combination circuits, each error combination circuit including a first register programmable via a first software instruction executed by a corresponding microprocessor, and the fault collection and error management circuit includes an error management circuit, the error management circuit including a second register programmable via a second software instruction executed by the corresponding microprocessor, the method comprising: Enable data will be programmed into one or more of the first registers in the first registers of the one or more error combination circuits; The routing data is programmed into the second register of the error management circuit; The fault collection and error management circuit receives the multiple error signals from the multiple safety monitoring circuits; Based on the multiple error signals, one or more reaction signals are generated by the fault collection and error management circuit. A subset of the error signal is received through each error combination circuit; Each error combination circuit determines whether one or more of the received error signals are asserted. In response to determining that one or more of the received error signals are asserted, error state data is stored in the first register through each error combination circuit, the error state data identifying the asserted one or more error signals; The enable data is read from the first register by each error combination circuit, the enable data specifying whether the combined error signal should be asserted when the corresponding error signal is asserted for each error signal; Based on the error status data and the activation data, the combined error signal is generated by each error combination circuit; The combined error signal is received from the error combination circuit through the error management circuit; The routing data is read from the second register via the error management circuit. This routing data specifies, for each combined error signal and each microprocessor, whether an error should be signaled to each microprocessor when the corresponding combined error signal is asserted. Based on the combined error signal and the routing data, the error management circuit generates a corresponding signal for each microprocessor to notify the error.

17. The method of claim 16, wherein the second register and the first register of each error combination circuit are connected to the communication system and have been associated with one or more corresponding physical addresses, the method further comprising: Each of the first and second registers is programmed by sending a write request, including the corresponding physical address, to the communication system.

18. The method of claim 17, wherein the processing system includes one or more hardware address protection circuits, and the method further includes: Based on virtual address translation data and / or access permission data, the write request generated by the corresponding microprocessor is selectively forwarded to the second register and the first register of the corresponding error combination circuit via one or more hardware address protection circuits.

19. The method of claim 16, wherein the plurality of fault collection subcircuits includes a corresponding fault collection subcircuit for each microprocessor, the corresponding fault collection subcircuit including the one or more corresponding error combination circuits, and the method further includes: Each corresponding fault collection subcircuit receives the error signal generated by one or more safety monitoring circuits configured to monitor the operation of the corresponding microprocessor.

20. The method of claim 19, further comprising: The error signal generated by the one or more safety monitoring circuits is received through one or more error combination circuits in the error combination circuits of the corresponding fault collection sub-circuit associated with the corresponding microprocessor; as well as The operation of one or more second resources and / or memory regions associated with the corresponding microprocessor is monitored by the one or more security monitoring circuits.

Citation Information

Patent Citations

  • Processing system, related integrated circuit and method

    EP3534261A1

  • Method and apparatus for processing error information and injecting errors in a processor system

    CN101008916A

  • Processing System, Related Integrated Circuit and Method

    US20190272210A1