Chip with check function and chip starting method

CN117130670BActive Publication Date: 2026-09-25CRM ICBG (WUXI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210556919.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-20
Publication Date
2026-09-25
Estimated Expiration
2042-05-20

AI Technical Summary

Technical Problem

[0005]鉴于以上所述现有技术的缺点,本发明的目的在于提供一种具有校验功能的芯片及芯片启动方法,用于解决现有技术中由于电源不稳定导致的配置字无法正常加载使得微处理器无法正常工作的问题

Benefits of technology

[0025]1)本发明通过判断累计标志位及当前标志位,提高配置字的加载几率,避免因编译失误而产生校验失误从而使微处理器陷入无限死循环。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117130670B_ABST
    Figure CN117130670B_ABST
Patent Text Reader

Abstract

The application provides a chip with a check function and a chip starting method, which performs power-on or reset; adds a safe control word, performs work based on the safe control word, until an oscillator and power-on are stable, updates a data part, and generates a check part corresponding to the data part; verifies and checks the control word, and performs self-checking on the data part and the check part of each configuration word, adds corresponding cumulative flag bits and current flag bits for each configuration word according to the self-checking condition; performs a check operation on the cumulative flag bits and the current flag bits, when the check passes, replaces the safe control word with the read data part; when the check does not pass, ignores the read data part; if the cumulative flag bits of the configuration word are all valid, reads a main program and executes the main program, otherwise, performs a watchdog reset, and re-performs power-on or reset. The loading probability of the configuration word is improved, and a check failure caused by a compiling failure is avoided, so that a microprocessor is prevented from falling into an infinite dead loop state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of semiconductor technology, and in particular to a chip with verification function and a chip startup method. Background Technology

[0002] During the power-on process of microprocessor-based products, due to varying power-on times and power instability, the loading of configuration control words stored in non-volatile media (such as flash memory) can sometimes result in scrambled values ​​being loaded during periods of power instability. This can cause the microprocessor system to fail to boot normally, or even lead to a collective failure of configuration loading due to power instability, resulting in inaccuracies in the collective accuracy of certain analog control components within some microprocessor chips. Therefore, finding a method to resolve power-on configuration chaos and collective loading failures caused by power instability is crucial. Traditionally, the configuration word loading process during power-on of microprocessor-based integrated circuits mainly employs two methods:

[0003] Method 1: One approach involves directly reading the configuration word information to initialize various analog modules after power-on reset and the watchdog timer reaches the required count. This includes oscillator frequency adjustment parameters and LDO (low dropout regulator) adjustment parameters. Once the system master clock reaches the required count, the microprocessor begins reading the program and executing it. However, during power-on, the circuit cannot determine whether the configuration word is loaded correctly. Incorrect configuration word loading can easily lead to an abnormal, chaotic state, and even after power-on and power-off, the circuit will exhibit the same abnormal state, failing to function normally.

[0004] Method 2: An improved version of the above method is to calculate a checksum obtained from all configuration words before reading the configuration word information. If the configuration word self-test fails, the configuration word is repeatedly loaded until it is loaded correctly. Only then is the system master clock started to count and execute the microprocessor program. This method effectively reduces the probability of the chip becoming disordered due to configuration word loading errors caused by unstable power supply in Method 1. However, it also introduces a new problem: if the configuration word self-test fails during power-on, the chip will be trapped in an infinite loop of configuration word self-test, which will also prevent the microprocessor from running normally. Summary of the Invention

[0005] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide a chip with a verification function and a chip startup method, so as to solve the problem in the prior art that the configuration word cannot be loaded normally due to unstable power supply, which causes the microprocessor to malfunction.

[0006] To achieve the above and other related objectives, the present invention provides a chip boot method with verification function, the chip boot method with verification function comprising at least:

[0007] 1) Power on or reset the device, and the oscillator will start counting.

[0008] 2) Add a secure control word to each configuration word, wherein the secure control word only includes the data portion;

[0009] 3) Operate based on the security control word until the oscillator and power-on are stable, then add a number of check control words, each of the configuration words updates the data part, and generates a check part corresponding to the data part;

[0010] 4) Verify the check control words for each configuration word. When all the check control words match the corresponding reservation value, perform a self-check on the data part and the verification part of each configuration word. Add the corresponding cumulative flag bit and current flag bit to each configuration word according to the self-check results. When any check control word does not match the reservation value, if the time for reading the current check control word has not expired, return to step 3) to re-add the check control word. If the time for reading the current check control word has expired, perform a watchdog reset.

[0011] 5) Read the data portion, cumulative flag bit, and current flag bit of each configuration word, and perform a verification operation on the cumulative flag bit and the current flag bit. If the verification passes, replace the secure control word with the read data portion; if the verification fails, ignore the read data portion.

[0012] 6) When the cumulative flags of all configuration words are valid, read the main program and execute the main program; when the cumulative flag of any configuration word is invalid, perform a watchdog reset and return to step 1).

[0013] Optionally, between step 5) and step 6), a step of determining whether to enter the test mode is included. If the test mode is entered, a self-test is performed; otherwise, step 6) is executed to run the main program.

[0014] Optionally, the number of inspection control words is a natural number greater than or equal to 1, wherein the reservation value is equal to the number of inspection control words.

[0015] Optionally, the secure control word is the middle value of the range of values ​​for the data portion.

[0016] Optionally, the verification portion is set to have the same length as the data portion.

[0017] Optionally, when the verification part is equal to the value after bitwise inversion of the data part, the current flag bit is valid and the cumulative flag bit is valid;

[0018] When the verification part is not equal to the value after bitwise inversion of the data part, the current flag bit is invalid. If it is the first self-test, the cumulative flag bit is invalid. If it is not the first self-test and the current flag bit has not been detected as valid before, the cumulative flag bit is invalid. If it is not the first self-test and the current flag bit has been detected as valid at least once before, the cumulative flag bit is valid.

[0019] Optionally, the verification operation includes: if the cumulative flag is invalid or the current flag is invalid, the verification fails and the data portion of the configuration word read at the current time is ignored; if the cumulative flag is valid and the current flag is valid, the verification passes and the data portion of the configuration word read at the current time is replaced with a secure control word.

[0020] This invention proposes a chip with a verification function, wherein the chip with the verification function is an architecture of a microprocessor or a digital signal processor, and is used to implement the chip startup method with the verification function.

[0021] Optionally, the chip with verification function further includes a storage medium for setting the configuration word.

[0022] Optionally, the storage medium is a non-volatile storage medium.

[0023] Optionally, the storage medium is disposed inside or outside the chip with verification function.

[0024] As described above, the chip with verification function and the chip startup method of the present invention have the following beneficial effects:

[0025] 1) This invention improves the loading probability of configuration words by judging the cumulative flag bit and the current flag bit, and avoids verification errors caused by compilation errors, which would cause the microprocessor to fall into an infinite loop.

[0026] 2) This invention queries the validity of the cumulative flag bit through the program to find out the specific configuration word that is loading abnormally, and recompiles or resets the watchdog for the abnormal configuration word to trigger the reloading operation of the configuration word, thereby further improving the loading probability of the microprocessor's configuration word. Attached Figure Description

[0027] Figure 1 The diagram shown is a functional flowchart of the chip startup method with verification function according to the present invention.

[0028] Figure 2The diagram shown is a schematic of the configuration word data structure of the present invention.

[0029] Component designation explanation

[0030] Steps S1 to S8 Detailed Implementation

[0031] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention.

[0032] Please see Figure 1 and Figure 2 It should be noted that the illustrations provided in this embodiment are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0033] Example 1

[0034] like Figure 1 and Figure 2 As shown, this embodiment provides a chip boot method with verification function, which includes at least:

[0035] S1: As Figure 1 As shown, upon power-on or reset, the oscillator starts counting. It should be noted that the oscillator provides a clock signal to the circuit, which performs data processing operations based on this clock signal.

[0036] Specifically, as one implementation of the present invention, before executing step S1, the method further includes: allocating space for the configuration word and setting a number of reservation values ​​for comparison operations, such as... Figure 1As shown. It needs further explanation that the configuration word (also called the device configuration word, or DCW) is a special program storage unit inside a chip (here referring to a microprocessor or digital signal processor) that uses a Complex Instruction Set Computer (CISC) or Reduced Instruction Set Computer (RISC) architecture. It is freely configurable by the user and used to define performance options for some functional circuit units of the chip. The reservation value setting is used to compare with the check control word. The specific functional flow is detailed in the following steps. The "several quantities" refers to a natural number greater than or equal to 1, meaning the number of reservation values ​​is a natural number greater than or equal to 1. Specifically, as an example, such as... Figure 2 As shown, the number of inspection control words is a natural number greater than or equal to 1, that is... Figure 2 In this context, n is a natural number greater than or equal to 1, where the reservation value is equal to the number of check control words. It should be noted that the number of check control words should consider factors such as storage space size, chip operating speed, and environmental security, and is not limited to this embodiment. S2: As... Figure 1 As shown, a secure control word is added to each configuration word, where the secure control word only includes the data portion. It should be noted that, as an example, ... Figure 2 As shown, before the oscillator stabilizes, each configuration word only includes a data portion, omitting the check portion, cumulative flag bit, and current flag bit. Specifically, as an example, such as... Figure 2 As shown, the secure control word is the midpoint of the value range of the data portion. If the data portion occupies 4 bits of space, then the value range of the data portion is [0000, FFFF], and the secure control word is selected from the midpoint of this value range. It should be noted that the data portion setting of the secure configuration word should consider actual usage scenarios, such as storage space, the number of configuration words, and the functional requirements of the chip. It can also be obtained through simulation experiments (e.g., mixed-signal simulation experiments), and is not limited to this embodiment.

[0037] S3: As Figure 1 As shown, each configuration word operates based on the security control word until the oscillator and power-on stabilize. Then, a number of check control words are added, and each configuration word updates the data portion, generating a check portion corresponding to the data portion. Specifically, as an example, such as... Figure 1 As shown, before the oscillator and power-on stabilization, each configuration word operates as a safety control word; after the oscillator and power-on stabilization, the number and data structure of the added check control words are as follows. Figure 2 As shown, the data portion is automatically updated, and the specific values ​​of the updated data portion conform to randomness; the verification portion is set to have the same length as the data portion. It should be noted that the number of check control words should be set according to factors such as storage space, the number of configuration words, and the functional requirements of the chip, and is not limited to this embodiment.

[0038] S4: As Figure 1 As shown, the check control words for each configuration word are verified. When all the check control words match the corresponding reservation values, a self-check is performed on the data and verification parts of each configuration word. Based on the self-check results, a corresponding cumulative flag and a current flag are added to each configuration word. When any check control word does not match the reservation value, if the time for reading the current check control word has not expired, the process returns to step S3 to re-add the check control word; if the time for reading the current check control word has expired, the watchdog timer is reset. Specifically, as an example, such as... Figure 1 and Figure 2 As shown, when the verification part is equal to the bitwise inverted value of the data part, the current flag bit is valid, and the cumulative flag bit is valid; when the verification part is not equal to the bitwise inverted value of the data part, the current flag bit is invalid. If this is the first self-test, the cumulative flag bit is invalid; if this is not the first self-test and the current flag bit has not been detected as valid before, the cumulative flag bit is invalid; if this is not the first self-test and the current flag bit has been detected as valid at least once before, the cumulative flag bit is valid. It should be noted that the validity status of the current flag bit is based on, but is not limited to, the verification part being equal to the bitwise inverted value of the data part. A cyclic redundancy check mechanism can also be used. The specific setting should consider the actual usage scenario and is not limited to this embodiment.

[0039] S5: As Figure 1 and Figure 2 As shown, the data portion, cumulative flag, and current flag of each configuration word are read. A verification operation is performed on the cumulative flag and the current flag. If the verification passes, the read data portion replaces the secure control word; if the verification fails, the read data portion is ignored. Specifically, as an example, such as... Figure 1 As shown, the verification operation includes: when the cumulative flag is invalid or the current flag is invalid, the verification fails and the data portion of the configuration word read at the current time is ignored; when the cumulative flag is valid and the current flag is valid, the verification passes and the data portion of the configuration word read at the current time is replaced with a secure control word.

[0040] S6: As Figure 1As shown, when all the cumulative flags of all configuration words are valid, preparation time is reserved for loading each configuration word; when not all the cumulative flags of all configuration words are valid, if the time to read all configuration words has not timed out, the process returns to step S4; if the time to read all configuration words timed out, a watchdog reset is performed. It should be noted that checking whether the cumulative flags of all configuration words are valid is an operation process within the hardware environment.

[0041] S7: Specifically, as an example, such as Figure 1 As shown, the steps for determining whether to enter test mode are as follows: If test mode is entered, a self-test is performed, i.e., the chip's test mode, and the main program startup is not executed; if test mode is not entered, the next step is performed. It should be noted that the chip's test mode may not be set, depending on the actual usage scenario, and is not limited to this embodiment.

[0042] S8: As Figure 1 As shown, a reset and release are performed, and the cumulative flag bits of all configuration words are checked. If the cumulative flag bits of all configuration words are valid, the main program is read and executed. If the cumulative flag bit of any configuration word is invalid, a watchdog reset is performed, and the process returns to step S1. It should be noted that checking the cumulative flag bits of all configuration words in step S8 is a software environment operation, fundamentally different from checking the validity of the cumulative flag bits of all configuration words in step S6. It should also be noted that after the watchdog reset, all configuration words operate with safe control words. After the oscillator and power-on stabilization, each configuration word will eventually complete the operation verified in step S5, thus avoiding verification errors caused by compilation errors that could lead to an infinite loop in the microprocessor and affect the normal startup of the main program, greatly increasing the probability of successful configuration word loading. By querying the validity of the cumulative flag bits, the specific configuration word that failed to load is identified, and the abnormal configuration word is recompiled or a watchdog reset is performed to trigger a reloading operation, further improving the probability of successful configuration word loading by the microprocessor.

[0043] Example 2

[0044] This embodiment provides a chip with verification function to implement the chip startup method with verification function provided in Embodiment 1. The chip with verification function is configured as a microprocessor or a digital signal processor. Specifically, as an example, the architecture of the chip with verification function includes, but is not limited to, a microprocessor or a digital signal processor. Any chip capable of implementing the chip startup method with verification function provided in Embodiment 1 is applicable, and will not be elaborated upon here.

[0045] Specifically, as an example, the chip with verification function further includes a storage medium used to set the configuration word. More specifically, the storage medium is located inside or outside the chip with verification function, taking into account specific usage scenarios such as storage space size, number of configuration words, and functional requirements of the chip. The storage medium is a non-volatile storage medium. Non-volatile memory (NVM) integrates the advantages of Dynamic Random Access Memory (DRAM), flash memory, intelligent system controller, and supercapacitor module. It retains the low latency and unlimited read / write cycles of DRAM, and has the long-term data storage capability of flash memory. Furthermore, the intelligent system controller ensures that the updated data portion conforms to randomness, and the supercapacitor guarantees the goal of non-volatile composite memory. Therefore, NVM can effectively ensure the successful implementation of the chip startup method with verification function in Embodiment 1. It should be noted that the storage medium includes, but is not limited to, non-volatile storage media. Any storage medium that can improve the effectiveness of the chip startup method with verification function is applicable and is not limited to this embodiment.

[0046] In summary, the present invention provides a chip with verification function and a chip startup method, which involves powering on or resetting the chip, and starting an oscillator to count. A secure control word is added to each configuration word, wherein the secure control word only includes the data portion. Operation is performed based on the secure control word until the oscillator and power-on are stable. Then, a number of check control words are added, and for each configuration word, the data portion is updated, generating a verification portion corresponding to the data portion. The check control words of each configuration word are verified. When all the check control words match the corresponding preset value, a self-test is performed on the data portion and verification portion of each configuration word. Based on the self-test results, a corresponding cumulative flag bit and a current flag bit are added to each configuration word. When any of the check control words does not match the reserved value, if the time for reading the current check control word has not expired, the check control word is re-added; if the time for reading the current check control word has expired, the watchdog timer is reset. The system reads the data portion, cumulative flag, and current flag of each configuration word, and performs verification on the cumulative flag and current flag. If the verification passes, the read data portion replaces the safe control word; if the verification fails, the read data portion is ignored. When the cumulative flags of all configuration words are valid, the main program is read and executed. When the cumulative flag of any configuration word is invalid, the watchdog timer is reset, and a power-on or reset operation is performed. By judging the cumulative flag and current flag, the loading probability of configuration words is improved, avoiding verification errors caused by compilation errors that could lead to an infinite loop in the microprocessor. By querying the validity of the cumulative flag, the system identifies the specific configuration word that is loading abnormally, and recompiles or resets the abnormal configuration word, triggering a reloading operation for that configuration word, thereby improving the loading probability of configuration words in the microprocessor. Therefore, this invention effectively overcomes the various shortcomings of the prior art and has high industrial application value.

[0047] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.

Claims

1. A chip boot method with verification function, characterized in that, The chip startup method with verification function includes at least the following: Allocate space for the configuration word and set a number of reservation values ​​for comparison operations; the reservation values ​​are set to be compared with the check control word; wherein, the number of reservation values ​​is a natural number greater than or equal to 1; 1) Power on or reset the oscillator to start counting; 2) Add a secure control word to each configuration word, wherein the secure control word only includes the data portion; 3) Operate based on the security control word until the oscillator and power-on are stable, then add a number of check control words, each of the configuration words updates the data part, and generates a check part corresponding to the data part; 4) Verify the check control words for each configuration word. When all the check control words match the corresponding reservation value, perform a self-check on the data part and the verification part of each configuration word. Add the corresponding cumulative flag bit and current flag bit to each configuration word according to the self-check results. When any check control word does not match the reservation value, if the time for reading the current check control word has not expired, return to step 3) to re-add the check control word. If the time for reading the current check control word has expired, perform a watchdog reset. 5) Read the data portion, cumulative flag bit, and current flag bit of each configuration word, and perform a verification operation on the cumulative flag bit and the current flag bit. If the verification passes, replace the secure control word with the read data portion; if the verification fails, ignore the read data portion. 6) When the cumulative flags of all configuration words are valid, read the main program and execute the main program; when the cumulative flag of any configuration word is invalid, perform a watchdog reset and return to step 1).

2. The chip startup method with verification function according to claim 1, characterized in that: Between step 5) and step 6), there is also a step to determine whether to enter the test mode. If the test mode is entered, a self-test is performed; otherwise, step 6) is executed to run the main program.

3. The chip startup method with verification function according to claim 1, characterized in that: The number of inspection control words is a natural number greater than or equal to 1, wherein the reservation value is equal to the number of inspection control words.

4. The chip startup method with verification function according to claim 1, characterized in that: The secure control word is the midpoint of the value range of the data portion.

5. The chip boot method with verification function according to claim 1, characterized in that: The verification section is set to have the same length as the data section.

6. The chip boot method with verification function according to claim 1, characterized in that: When the verification part is equal to the value after bitwise inversion of the data part, the current flag bit is valid and the cumulative flag bit is valid. When the verification part is not equal to the value after bitwise inversion of the data part, the current flag bit is invalid. If it is the first self-test, the cumulative flag bit is invalid. If it is not the first self-test and the current flag bit has not been detected as valid before, the cumulative flag bit is invalid. If it is not the first self-test and the current flag bit has been detected as valid at least once before, the cumulative flag bit is valid.

7. The chip boot method with verification function according to claim 1, characterized in that: The verification operation includes: if the cumulative flag is invalid or the current flag is invalid, the verification fails and the data portion of the configuration word read at the current time is ignored; if the cumulative flag is valid and the current flag is valid, the verification passes and the data portion of the configuration word read at the current time is replaced with a secure control word.

8. A chip with verification function, characterized in that: The chip with verification function is configured as a microprocessor or digital signal processor, and is used to implement the chip startup method with verification function as described in any one of claims 1 to 7.

9. The chip with verification function according to claim 8, characterized in that: The chip with verification function also includes a storage medium, which is used to set the configuration word.

10. The chip with verification function according to claim 9, characterized in that: The storage medium is a non-volatile storage medium.

Citation Information

Patent Citations

  • MCU electrification starting method with configuration word self-inspection function and self-inspection method

    CN104123167A

  • Code protection method and device for flash region in chip

    CN107657153A