Vehicle chip and protection method thereof
By introducing an inter-core communication mechanism into the vehicle chip, the second core generates a power-off command when the first core fails to suspend, and controls the first core to execute the power-off process, solving the problem of file system corruption caused by suspend failure, and achieving effective protection of the file system.
Patent Information
- Application Number
- CN202311546966.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2043-11-17
AI Technical Summary
In vehicle chips, the file system may be damaged when suspended, and the prior art lacks an effective protection mechanism.
Through inter-core communication, after the second core detects that the first core fails to suspend, it generates and sends a first power-off command to control the first core to perform the power-off process to avoid direct power-off operation.
It effectively protects the file system of the vehicle chip, avoids file system corruption when suspending fails, and improves the system stability and user experience.
Smart Images

Figure CN117573404B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to chip technology, and in particular to a vehicle chip and a protection method thereof. Background Art
[0002] The STR (Suspend to Ram) function means that all the working state data before the system enters STR is stored in the memory. In the STR state, the power supply continues to supply power to the most necessary devices such as the memory to ensure that data is not lost, while other devices are turned off. At this time, the system power consumption is extremely low. Once the system is awakened, it immediately reads data from the memory and restores to the working state before STR. The read and write speed of the memory is extremely fast, so we feel that the time spent entering and leaving the STR state is only a few seconds.
[0003] With the development of intelligent and electrified vehicles, STR functions are gradually being applied in real vehicles, for example, in vehicle HPC (High performance computer) and other products. HPC products are generally developed and designed based on heterogeneous SOC (System on Chip). Figure 1 , which is a schematic diagram of the structure of a heterogeneous SOC, the SOC 10 includes two cores, an A core 101 and an M core 102. In a normal STR process, the M core 102 sends a suspend-to-memory instruction to the A core 101, and the A core 101 performs the STR function based on the instruction of the M core 102. Then, when the A core 101 completes the STR function, the M core 102 performs a power-off process, that is, shuts off the power supply of related modules and only retains the power supply of necessary modules. Summary of the invention
[0004] The embodiment of the present invention provides a vehicle chip and a protection method thereof, which can protect the file system of the chip from damage.
[0005] A method for protecting a vehicle chip according to an embodiment of the present invention, the vehicle chip includes: a first core and a second core, and the method includes: the first core receives a suspend instruction from the second core; the first core executes a suspend process based on the suspend instruction; when the suspend fails, the first core sends an indication of the suspend failure to the second core; the first core receives a first shutdown power-off instruction generated by the second core based on the indication of the suspend failure; the first core executes the shutdown power-off process based on the first shutdown power-off instruction.
[0006] The method further includes: when the first core is suspended successfully, setting a preset flag bit in the static random access memory to a specific value to send an indication of successful suspension to the second core.
[0007] The method further includes: when the first core fails to suspend, executing a process of restoring the running state to restore the state to the running state; the first core sends an indication of the running state to the second core; and when the second core receives the indication of the running state and does not detect that the preset flag bit is the specific value within a timeout period, it determines that the first core has failed to suspend and generates the first shutdown power-off instruction.
[0008] The method further includes: after the first core is successfully suspended or shut down and powered off, the second core executes a shutdown and power-off process.
[0009] Among them, after the first core is successfully suspended, the method also includes: the first core receives a recovery instruction from the second core, the recovery instruction instructs the first core to recover to a running state; the first core obtains status information of at least one peripheral device related to the first core based on the recovery instruction; the first core sends the obtained status information to the second core; the first core receives a second shutdown and power-off instruction from the second core, the second shutdown and power-off instruction is generated by the second core when it detects a peripheral fault based on the status information; and the first core executes a shutdown and power-off process based on the second shutdown and power-off instruction.
[0010] The method further includes: after the first core executes the shutdown and power-off process, the first core executes a restart process based on a restart instruction, where the restart instruction is generated by the second core when a wake-up source is detected and sent to the first core.
[0011] The method further includes: when the second core detects a fault in the peripheral device based on the status information, and when a condition for the first core to re-enter the suspended state is met, sending the second shutdown power-off instruction to the first core.
[0012] The first core and the second core interact with each other through inter-core communication, and the first core is an A core and the second core is an M core.
[0013] A vehicle chip according to an embodiment of the present invention comprises: a heterogeneous first core and a second core, wherein the first core is used to: receive a suspend instruction from the second core; execute a suspend process based on the suspend instruction; when the suspend fails, transmit an indication of the suspend failure to the second core; receive a first shutdown and power-off instruction from the second core; execute a shutdown and power-off process based on the first shutdown and power-off instruction; the second core is used to: send the suspend instruction to the first core; and generate the first shutdown and power-off instruction based on the indication of the suspend failure and send it to the first core.
[0014] Among them, the first core is also used to: after successful suspension, receive a recovery instruction from the second core, the recovery instruction is used to instruct the first core to recover from the suspended state to the running state; based on the recovery instruction, obtain the status information of at least one peripheral related to the first core; send the obtained status information to the second core; receive a second shutdown and power-off instruction from the second core; and execute the shutdown and power-off process based on the second shutdown and power-off instruction; the second core is also used to: send the recovery instruction to the first core; receive the status information returned by the first core; and when the status information shows that there is a fault in the peripheral, generate the second shutdown and power-off instruction and send it to the first core.
[0015] Beneficial effects of the embodiments of the present invention:
[0016] In an embodiment of the present invention, the second core obtains the status of the first core, and thus controls the first core to execute shutdown and power off when the first core fails to suspend, thereby avoiding power-off operations when the first core is in operation, thereby avoiding damage to the file system of the vehicle chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Other details and advantages of the present invention will become apparent from the detailed description provided below. It should be understood that the following drawings are merely illustrative and thus cannot be considered as limiting the present invention, and the following will be described in detail with reference to the drawings, wherein:
[0018] Figure 1 is a schematic structural diagram of an embodiment of a vehicle chip of the present invention;
[0019] Figure 2 is a schematic structural diagram of another embodiment of a vehicle chip of the present invention;
[0020] Figure 3 is a flow chart of an embodiment of a method for protecting a vehicle chip of the present invention;
[0021] Figure 4 is a flow chart of another embodiment of a method for protecting a vehicle chip of the present invention;
[0022] Figure 5A is a flow chart of another embodiment of a method for protecting a vehicle chip of the present invention;
[0023] Figure 5B is a flow chart of another embodiment of the vehicle chip protection method of the present invention; and
[0024] Figure 6It is a flow chart of another embodiment of the vehicle chip protection method of the present invention. DETAILED DESCRIPTION
[0025] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention clearer and more understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the present invention and are not intended to limit the present invention.
[0026] In the description of the present invention, it is to be understood that the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. Moreover, the terms "first", "second", etc. are applicable to distinguishing similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein.
[0027] like Figure 1 As shown, it is a schematic diagram of an embodiment of a structure of a vehicle chip. The vehicle chip may be, for example, a SOC (system on chip), such as a heterogeneous SOC. The A core 101 in the vehicle chip has a STR (suspend to memory) function, and can enter a suspended state or wake up from a suspended state under the control of the M core 102. In various application scenarios of the vehicle, the A core 101 may frequently switch back and forth between the suspended state and the running state, but the A core 101 is not always able to suspend successfully, and it is inevitable that the suspension fails. When the M core 102 sends a suspend instruction to the A core 101, regardless of whether the A core 101 is successfully suspended, the M core will perform a power-on operation.
[0028] Specifically, the A core 101 and the M core 102 will transmit the indication of successful suspension through the preset flag bit in the SRAM (Static Random Access Memory). When the A core 101 is successfully suspended, it sets the value of the preset flag bit to a specific value. When the M core 102 detects that the value of the preset flag bit is a specific value, it performs a power-on operation. However, when the M core does not detect that the value of the preset flag bit is a specific value within the timeout period, it will perform a power-on operation regardless of the current state of the A core 101; at this time, the A core 101 may be in a suspended state, but an error occurred when writing the preset flag bit, resulting in the failure to successfully write the preset flag bit to a specific value, or the A core 101 may fail to suspend and is in a running state at this time. If the power-on operation is performed when the A core is in a running state, it may cause damage to the file system of the vehicle chip, etc., affect the stability of the entire vehicle, and cause a poor user experience. Therefore, there is currently a lack of a protection mechanism for failure to suspend.
[0029] On this basis, in the embodiment of the present invention, when the M core 102 detects that the A core 101 fails to suspend, it does not directly pull the power, but controls the A core 101 to execute the shutdown process to avoid the problem of file system damage caused by direct power pulling. That is to say, the embodiment of the present invention introduces a protection mechanism for suspension failure. In addition, when the A core 101 fails to suspend, it will switch back to the running state, and send the indication of the running state to the M core 102, so that the M core 102 can accurately judge whether the A core 101 is suspended successfully based on the indication of the running state and the value of the preset flag bit. In addition, for the recovery process after suspension, the embodiment of the present invention further collects the status of the peripherals in the A core 101 and provides it to the M core 102; when the M core 102 recognizes that the peripheral has a fault based on the status of the peripheral, it controls the M core to execute the shutdown process, thereby optimizing the problem of the decline of the whole vehicle function caused by the peripheral problem. That is to say, for suspension recovery, this embodiment also provides an additional protection mechanism to enable the system to operate normally and improve the user experience.
[0030] Combine the following Figures 2 to 6 The embodiments of the present invention are described in detail.
[0031] like Figure 2 FIG. 2 is a schematic diagram of the structure of an embodiment of a vehicle chip of the present invention. The vehicle chip may include: a first core (eg, an A core) 20 and a second core (eg, an M core) 30 .
[0032] The first core 20 and the second core 30 may be developed and designed based on different Autosar (Automotive Open System Architecture) platforms.
[0033] The first core 20 and the second core 30 may exchange data via an inter-core communication method such as an IPCF (inter-processor communication Framework) 40 .
[0034] As shown in the figure, the first core 20 includes: SPMC (slave power manager client, power management slave device) 201, SM (State machine Manager, state machine management module) 202, EM (Execution Manager, execution management module) 203 and other modules 204. Among them, other modules 204 include, for example: operating system kernel, various APP modules running on the first core 20, etc. The second core 30 includes: PM (Power Master, power management master device) 301. Among them, PM301 is the master device of SPMC201, which is used to control SPMC201 to perform power-related management functions. SM202 is responsible for setting the state of the first core 20 to control the first core to switch between different states. Among them, the state of the first core may include, for example: suspended state (also known as sleep state), shutdown state, standby state and running state, etc. EM203 is responsible for executing corresponding operations based on the state set by SM202 to make the first core 20 enter the corresponding state. For example, EM203 can control the components in other modules 204 to stop working, restart, save running data to memory, and so on.
[0035] like Figure 3 FIG. 1 is a flow chart of an embodiment of a method for protecting a vehicle chip of the present invention, which includes the following steps:
[0036] Step S30 : the first core 20 receives the suspend instruction from the second core 30 .
[0037] When the suspend state is satisfied, the second core 30 sends a suspend instruction to the first core 20 to instruct the first core 20 to enter the suspend state. For example, when there is no network communication in the vehicle chip, the second core 30 can control the first core 20 to suspend. The network communication can be, for example, CAN network communication. When the CAN interface of the vehicle chip does not send or receive signals, it can be regarded as no CAN network communication. The network communication is only a trigger source for entering the suspend state or a wake-up source for recovering from the suspend state, and is not a limitation of the embodiments of the present invention.
[0038] Step S32: the first core 20 executes the suspend process based on the suspend instruction.
[0039] The first core 20 may first switch to the transient state based on the suspend instruction, and then switch from the transient state to the suspended state. For those skilled in the art, the processing flow of the transient state and the processing flow of the suspended state are both familiar, and will not be described in detail here.
[0040] Step S34 : when the suspend fails, the first core 20 transmits an indication of the suspend failure to the second core 30 .
[0041] There are many ways for the first core 20 to transmit the indication of suspension failure, which are described below by way of example. In one way, when the suspension fails, the first core 20 will be restored to the running state (running), and the first core 20 can send an indication of the running state to the second core 30 to notify the first core 20 that it is in the running state. When the second core 30 receives the indication of the running state, it can be regarded as the suspension failure of the first core 20.
[0042] In another way, when the first core 20 is suspended successfully, it will set the preset flag bit stored in the SRAM to a specific value to indicate that the suspension is successful. Then, as long as the second core 30 does not detect that the preset flag bit is set to the specific value within the timeout period, it can be regarded as a suspension failure. The timeout period should be set at least long enough for the first core 20 to be successfully suspended.
[0043] In another embodiment, the second core 30 can combine the above two to accurately determine whether the suspension fails. For example, after sending the suspension indication, the second core 30 receives an indication that the first core 20 is in a running state, and within the timeout period, it is not detected that the preset flag bit is set to a specific value, then the second core 30 considers that the suspension fails.
[0044] Step S36 : the first core 20 receives the first shutdown power-off instruction from the second core 30 .
[0045] When confirming that the first core 20 fails to suspend, the second core 30 generates a first shutdown power-off instruction and sends it to the first core 20 .
[0046] Step S38: the first core 20 executes a shutdown process based on the first shutdown instruction.
[0047] The shutdown and power-off process is familiar to those skilled in the art and will not be described in detail here.
[0048] After the first core completes the shutdown and power-off process, it can indicate the completion of the shutdown and power-off by writing another specific value in the SRAM. When the second core 30 finds that the other specific value is written in the SRAM, it can perform the power-off operation.
[0049] In this embodiment, when the suspension fails, the second core 30 does not directly perform a power-off operation, but controls the first core 20 to perform a power-off operation through a power-off instruction, thereby protecting the file system of the vehicle chip. In addition, when the suspension fails, by obtaining the status of the first core 20 and feeding it back to the second core 30, the second core 30 can more accurately determine whether the first core 20 fails to suspend by combining the status information of the first core 20.
[0050] like Figure 4 , which is a flow chart of an embodiment of a vehicle chip protection method of the present invention. Figure 4 The invention relates to a process of recovering from the suspended state to the running state after the first core 20 is successfully suspended, and a mechanism for detecting whether a peripheral device has a fault is added in this process, and when a fault is detected in the peripheral device, the first core 20 is controlled to shut down and restart, or the first core 20 is shut down and powered off when it enters the suspended state next time, so as to repair the fault in the peripheral device. In other words, Figure 4 The embodiments may further provide a protection mechanism for the vehicle chip to improve performance.
[0051] like Figure 4 As shown, the method flow includes the following steps:
[0052] Step S40: the first core is in a suspended state.
[0053] For example, Figure 3 In the process, the first core 20 successfully enters the suspended state based on the suspend instruction of the second core 30.
[0054] Step S41: the first core 20 receives a resume instruction (or a wake-up instruction) from the second core 20, where the resume instruction is used to instruct the first core 20 to resume from a suspended state to a running state.
[0055] When there is a valid wake-up source, the second core 30 may generate a recovery instruction and send it to the first core 20. The wake-up source may be, for example, a CAN communication interface of a vehicle chip.
[0056] Step S42: the first core 20 obtains status information of at least one peripheral device related to the first core 20 based on the recovery instruction.
[0057] The first core 20 may obtain the status information of the peripheral device by reading the file content in the operating system (such as Linux). The status information of the peripheral device may be information indicating whether the peripheral device has a fault. The peripheral device may be, for example, a PFE (Package Forwarding Engine).
[0058] Step S43 : the first core 20 sends the acquired status information to the second core 30 .
[0059] Step S44: The second core 30 determines whether the peripheral device has a fault based on the received status information.
[0060] Step S45 : when a peripheral device fails, the second core 30 generates a shutdown command and sends it to the first core 20 .
[0061] Step S46: the first core 20 executes a shutdown process based on the second shutdown instruction.
[0062] In some embodiments, in step S44, the second core 30 may first save the acquired state information, and after the first core 20 is restored to the running mode, determine whether the peripheral device is faulty, because the shutdown and power-off process of the first core 20 should start from the running state. In some embodiments, in step S44, when the second core 30 determines that the peripheral device is faulty, it does not immediately instruct the first core 30 to execute the shutdown and power-off process, but when the suspend trigger condition is met again, controls the first core 20 to execute the shutdown and power-off process instead of the suspend process, because the faulty peripheral device may not affect the operation currently required to be executed by the first core 20, and the repair of the peripheral device can be left for the next time the suspend state is entered.
[0063] In addition, after the second core 30 controls the first core 20 to execute the shutdown and power-off process, the second core 30 can further determine whether it is necessary to immediately restart the first core 20. For example, when there is still a valid wake-up source, the first core 20 can be immediately restarted. If there is no valid wake-up source, the second core 30 can execute the shutdown and power-off process.
[0064] In this embodiment, during the process of recovering from the suspended state to the running state, the system performance can be optimized by detecting whether there is a fault in the peripheral device and repairing it if there is a fault.
[0065] Combine the following Figure 5A , 5B and Figure 6 The above process is further explained in detail.
[0066] like Figure 5A and 5B , which is a flow chart of an embodiment of the vehicle chip protection method of the present invention, respectively shows the flow chart when the suspension is successful and when it fails.
[0067] like Figure 5AAs shown, when the suspend trigger condition is met, PM301 sends a suspend instruction to SPMC201, and SPMC201 further sends the suspend instruction to SM202 (step S501). After receiving the suspend instruction, SM202, together with EM203 and other modules 204, first executes the transient process (step S502), and then executes the suspend process (step S503), so as to successfully suspend the first core. After the first core is successfully suspended, other modules 204 will write specific values in SRAM to indicate that the suspension is successful (step S5041).
[0068] like Figure 5B As shown, when the suspension process of step S503 fails, the first core is controlled to resume the running state (step S5042). After the first core is restored to the running state, the indication of the running state is fed back to PM301 through SM202 and SPMC201 (step S505). When PM301 receives the indication of the running state and does not detect that a specific value is written to the SRAM within the timeout period, PM301 considers that the suspension has failed, generates a shutdown power-off instruction, and sends it to SM202 via SPMC201 (step S506). SM202 executes the shutdown power-off process based on the shutdown power-off instruction, such as setting the state machine to enter the shutdown state, and performing the shutdown power-off operation through EM203. In this embodiment, when the suspension fails, PM301 will not directly perform the power-on operation, but will control the first core to execute the shutdown power-off process to avoid damage to the file system due to power failure in the running state.
[0069] like Figure 6 FIG. 1 is a flow chart of a method for protecting a vehicle chip according to an embodiment of the present invention, showing a specific process of restoring the first core from a suspended state to a running state. Figure 6 As shown, when PM301 detects that the wake-up condition is met, for example, when there is a valid wake-up source, a recovery instruction (or wake-up instruction) is generated and sent to other modules 204 (step S601). When other modules 204 detect the recovery instruction, they collect and save the status information of the peripherals (step S602), send the status information to PM301 (step S603), and perform related operations of the recovery operation process (step S604), and when the operation state is restored, send the indication of the operation state to PM301 (step S603). After receiving the status information, PM301 saves the status information (step S503), and after receiving the indication that the first core has been restored to the operation state (step S605), it determines whether the peripheral has a fault based on the status information of the peripheral (step S607). If there is a fault, the first core can be controlled to execute the shutdown and power-off process (steps S608 and S609).
[0070] Specifically, PM301 can modify the variable value of the variable manager in other modules 204 to a predetermined value, and the operating system kernel in other modules 204 executes the recovery process when detecting that the variable of the variable manager is the predetermined value. Different from the ordinary recovery process, the recovery process of this embodiment at least includes: collecting and saving the state information of the peripherals.
[0071] In addition, after controlling the first core to shut down and power off, if there is still a wake-up source, PM301 immediately controls the first core to restart, that is, executes the boot process. If there is no wake-up source, PM301 can control the second core to execute the shutdown and power-off process.
[0072] In addition, when it is determined in step S506 that a peripheral failure exists, PM301 may not control the first core to immediately perform the shutdown and power-off process, but instead control the first core to execute the shutdown and power-off process instead of the suspension process when the suspension trigger condition is met again.
[0073] It should be noted that the above description is only for example and not for limitation of the present invention. In other embodiments of the present invention, the method may have more, fewer or different steps, and the order, inclusion and function of each step may be different from that described and illustrated. For example, generally multiple steps can be combined into a single step, and a single step can also be divided into multiple steps. For those of ordinary skill in the art, without paying creative work, the sequential changes of each step are also within the scope of protection of the present invention.
[0074] The technical solution of the present invention, in essence or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor or a microcontroller to perform all or part of the steps of the method described in each embodiment of the present invention.
[0075] Those skilled in the art will appreciate that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed.
[0076] Although the present invention has been disclosed as above with preferred embodiments, the present invention is not limited thereto. Any changes and modifications made by any person skilled in the art without departing from the spirit and scope of the present invention should be included in the protection scope of the present invention, and therefore the protection scope of the present invention should be subject to the scope defined by the claims.
Claims
1. A method for protecting a vehicle chip, wherein the vehicle chip include: The first core and the second core are characterized in that the method comprises: The first core receives a suspend instruction from the second core; The first core executes a suspension process based on the suspension instruction; When the first core fails to suspend, sending an indication of the suspension failure to the second core; The first core receives a first shutdown power-off instruction generated by the second core based on the indication of the suspend failure; The first core executes a shutdown and power-off process based on the first shutdown and power-off instruction; After the first core is successfully suspended, the method further includes: The first core receives a recovery instruction from the second core, the recovery instruction instructing to recover the first core to a running state; The first core acquires, based on the recovery instruction, state information of at least one peripheral device related to the first core; The first core sends the acquired status information to the second core; The first core receives a second shutdown power-down instruction from the second core, where the second shutdown power-down instruction is generated when the second core detects a failure of a peripheral device based on the status information; and The first core executes a shutdown and power-off process based on the second shutdown and power-off instruction.
2. The vehicle chip protection method according to claim 1, It is characterized in that The method further comprises: When the first core is suspended successfully, the preset flag bit in the static random access memory is set to a specific value to send an indication of successful suspension to the second core.
3. The vehicle chip protection method as claimed in claim 2, It is characterized in that The method further comprises: When the first core fails to suspend, the first core executes a process of restoring the running state to restore the state to the running state; The first core sends the indication of the operating status to the second core; and When the second core receives the indication of the running status and fails to detect that the preset flag bit is the specific value within a timeout period, it determines that the first core has failed to suspend and generates the first shutdown power-off instruction.
4. The vehicle chip protection method as claimed in claim 2, It is characterized in that The method further comprises: After the first core is successfully suspended or shut down and powered off, the second core executes a shutdown and power-off process.
5. The vehicle chip protection method according to claim 1, It is characterized in that The method further comprises: After executing the shutdown and power-off process, the first core executes a restart process based on a restart instruction, where the restart instruction is generated by the second core when detecting the presence of a wake-up source and sent to the first core.
6. The vehicle chip protection method according to claim 1, It is characterized in that The method further comprises: When the second core detects a failure in the peripheral device based on the status information, and when a condition for the first core to enter the suspended state again is met, the second core sends the second shutdown power-off instruction to the first core.
7. The vehicle chip protection method as claimed in claim 1, It is characterized in that The first core and the second core interact with each other through inter-core communication, and the first core is an A core and the second core is an M core.
8. A vehicle chip, include: The heterogeneous first core and the second core are characterized in that The first core is used for: receiving a suspend instruction from the second core; Based on the suspend instruction, executing the suspend process; When the suspend fails, transmitting an indication of the suspend failure to the second core; receiving a first shutdown and power-off instruction from the second core; Based on the first shutdown and power-off instruction, executing the shutdown and power-off process; The second core is used for: sending the suspend instruction to the first core; and Based on the indication of the suspend failure, generating the first shutdown power-off instruction and sending it to the first core; The first core is further used for: After the suspension is successful, receiving a resume instruction from the second core, the resume instruction is used to instruct the first core to resume from the suspended state to the running state; Based on the recovery instruction, obtaining status information of at least one peripheral device related to the first core; sending the acquired status information to the second core; receiving a second shutdown power-off instruction from the second core; and Based on the second shutdown and power-off instruction, executing the shutdown and power-off process; The second core is further used for: sending the recovery instruction to the first core; receiving the status information returned by the first core; and When the status information shows that a peripheral device has a fault, the second shutdown power-off instruction is generated and sent to the first core.
Citation Information
Patent Citations
Memory monitor
CN109690496A
Chip control method and chip
CN115756622A