A Testing Method and Device for the Security Mechanism of a Hyper-Heterogeneous Chip for ADAS
By executing the MCU fault injection program under the LINUX system and combining the MCU real-time operating system to conduct security mechanism testing, the problem of incomplete security assessment of super heterogeneous chips in real application scenarios is solved, and the stability and reliability of the chip are improved.
Patent Information
- Application Number
- CN202410151332.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-02
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-02-02
AI Technical Summary
The existing super heterogeneous chip fault injection test methods cannot fully simulate the real application scenarios of multi-system and multi-functional operation at the same time, resulting in insufficient comprehensive chip functional safety assessment.
While the LINUX system algorithm application is running, the MCU fault injection program is executed to realize dynamic injection of the fault, and traversal testing of the security mechanism is carried out in conjunction with the MCU real-time operating system.
It realizes the simulation of failures in real application scenarios of super heterogeneous chips, improves the availability, recovery and stability of the chip in various abnormal situations, discovers potential security problems and vulnerabilities, and improves the stability and reliability of the chip in diverse scenarios.
Smart Images

Figure CN118245296B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent driving, and particularly relates to a method and device for testing a security mechanism of a superheterogeneous chip for ADAS. Background Art
[0002] In the field of intelligent driving, with the application of deep learning, chips are required to provide higher computing power than traditional chips, and also to offer lower power consumption and better integration. As a processor widely used in the ADAS system (Advanced Driver Assistance System), the superheterogeneous chip Super SOC plays a crucial role in the application process of ADAS and autonomous vehicles (AV). Superheterogeneous chips are generally developed based on heterogeneous and scalable architectures, and by invoking computing units with different performances and structures (CPUs, GPUs, various dedicated chips, etc.) to meet different computing needs and achieve optimal computing. The advantage of multi-core heterogeneity is that each core gives full play to its processing efficiency, and together with dedicated hardware accelerators for specific tasks, the best balance among performance, power consumption and cost can be achieved. Since the vehicle control system must be highly safe and reliable, in addition to using high-performance cores such as NPUs, GPUs, and DSPs to quickly process specific tasks, the superheterogeneous chips applied to the intelligent driving system also have a kernel that can ensure the security of computing tasks and has high real-time performance to process some more general instructions. Moreover, while the relevant peripheral interfaces interact with external information, they can also ensure the security of data at the ports and on the channels. The chip security island is such a physical environment that can provide a software security task execution. The functional safety island is mainly designed according to the requirements of the ISO26262 standard, aiming to prevent chip and system failures caused by random hardware failures, and further prevent personal and vehicle safety accidents.
[0003] The superheterogeneous chip integrates various different chip cores. This integrated chip design can fully integrate chip resources and further improve data computing efficiency. And since the chips are made compatible with each other at the beginning of the design, the logical optimization of the internal function division and interaction unified construction can significantly reduce various constraints of each other's functions and interactions compared with the single-chip function scheme. And on many design schematics, certain resources can be shared among the chips, and the integrated single chip can further reduce costs. In addition, for the design of the autonomous driving system, about (80%-90%) of the lightweight scenarios + about 10% of the challenging scenarios + about 10% of the extreme scenarios require high performance to calculate traditional and deep learning algorithms with the industry-leading power / performance ratio, and these can be fully covered by different chip cores of the superheterogeneous, thus significantly reducing complexity and system scale.
[0004] Hyper-heterogeneous chips are used in various perception and general computing tasks in autonomous driving systems. Their high-quality computing power, operating performance, complete compatibility, and rich I / O interfaces can reduce the complexity of system development. The on-board intelligent computing platform is the "brain" of the autonomous driving car. It is mainly responsible for completing the recognition and fusion tasks of the perception link and the entire decision-making link. It needs to process massive data and perform complex logical operations. In order to meet the high computing power requirements, the current on-board intelligent computing platform integrates multiple SoCs, and each SoC integrates multiple types of computing units (such as CPU, GPU, FPGA, ASIC, etc.). In the application, it is necessary to have the capabilities of multi-sensor fusion, positioning, path planning, decision control, wireless communication, and high-speed communication. Usually, multiple cameras, millimeter-wave radars, lidars, and IMUs are required to complete functions including image recognition and data processing. The heterogeneous distributed hardware architecture of the computing platform is classified in a hyper-heterogeneous way, and the optimal engine solution is adopted for the characteristics of each task to ensure the most extreme flexibility and programmability while achieving the most extreme performance.
[0005] The development and integration of these functions, as well as the increasing computing power of chips, the increasing complexity of software and hardware technologies, and the increasing risks of systematic failures and random hardware failures will further strengthen the requirements for system security. Taking the TDA4 platform as an example, the platform supports multiple isolation domains: wake-up domain, MCU domain, and main domain. The wake-up domain is an isolation domain that manages security and operating status, and uses a high-performance client-server messaging scheme to manage all security configurations. This domain supports boot management, encryption acceleration, trusted execution environment, secure storage, and real-time encryption. This domain can also enable low-power operating modes and security precautions during power conversion. The MCU domain is an isolated chip within the chip for device management, which works under dedicated power, clock, and reset to enable the MCU to run continuously independent of the main domain, including the period when the rest of the SoC is kept in reset or powered off. The MCU domain integrates general-purpose microcontrollers and communication peripherals, such as SPI and CAN, to support safety-critical communications. If the main domain fails, the MCU domain can pass this information to the system and take appropriate measures. The main domain includes computing clusters, accelerator clusters, and high-speed I / O clusters integrated in a shared address space. The SoC infrastructure forms a secure interconnect structure consisting of multiple crossbar switches.
[0006] Taking the TDA4 of TI Company as an example of the heterogeneous chip, the application processor is divided into two independent domains: the main domain and the MCU domain. The main domain provides high-performance computing cores such as MPU and GPU, multimedia and vision hardware accelerators (including DSP), and necessary peripherals; the MCU domain is an independent domain for implementing security functions. The MCU domain provides a secure partition and has sufficient hardware diagnostic functions to achieve random fault integrity of ASIL-D / SIL-3.
[0007] The functional safety requirements at the hardware foundation level of the chip mainly refer to the microcontroller module, storage module, power supply module, clock module, etc. The test of the functional safety mechanism is carried out by injecting faults and monitoring in real time. Software fault injection mainly achieves the purpose of fault injection by modifying the register or memory cell value, generally through software compilation-time injection and software runtime injection. Software compilation-time injection means injecting software faults into the program source code before the program of the system under test is loaded and executed to simulate the software and hardware faults of the system under test. Runtime fault injection refers to injecting faults into the system under test in a specific way after the software in the system under test runs. Runtime fault injection technology requires certain triggering conditions, and only when the conditions are met can the injection of faults be executed. Common triggering methods include timer timeout and interrupt / exception.
[0008] The security mechanism test of the heterogeneous chip is carried out by means of software fault injection. The fault injection test generally runs on the MCU security island. Fault injection is performed by modifying the register or memory in the MCU-side application software, usually before the chip computing function is loaded and run. The existing implementation methods of heterogeneous chip fault injection run isolatedly on the security island MCU chip, mainly used for power-on self-check of the chip and verification of the chip functional safety mechanism under static conditions, and cannot simulate the real application scenarios where multiple systems and multiple functions of the heterogeneous chip run simultaneously, and the evaluation of the chip functional safety is not comprehensive enough.
[0009] Based on this technical background, the present invention studies a method and device for testing the security mechanism of a heterogeneous chip for ADAS. Summary of the Invention
[0010] Aiming at the deficiencies of the existing technology, the present invention proposes a method and device for testing the security mechanism of a heterogeneous chip for ADAS. This method executes the MCU fault injection program while the LINUX system algorithm application program is running, realizes dynamic injection of faults, and realizes the purpose of testing the security mechanism by injecting faults in the real application scenarios of the heterogeneous chip.
[0011] To achieve the above object, the first aspect of the present invention provides a method for testing the security mechanism of a heterogeneous chip for ADAS, including:
[0012] Run the LINUX system and the MCU real-time operating system simultaneously in the heterogeneous chip;
[0013] Execute the MCU fault injection program in the MCU real-time operating system to perform a traversal test on the security mechanism of the heterogeneous chip.
[0014] The second aspect of the present invention provides a security mechanism testing device for an ultra-heterogeneous chip for ADAS, including:
[0015] A system operation module for running the LINUX system and the MCU real-time operating system simultaneously in the heterogeneous chip;
[0016] A traversal test module for executing the MCU fault injection program in the MCU real-time operating system to perform a traversal test on the security mechanism of the heterogeneous chip.
[0017] The technical effects of the present invention include:
[0018] (1) The security mechanism testing method for the ultra-heterogeneous chip for ADAS proposed by the present invention executes the MCU fault injection program while the LINUX system algorithm application program is running, realizing dynamic injection of faults and achieving the purpose of simulating the injection of faults in the real application scenario of the ultra-heterogeneous chip for security mechanism testing.
[0019] (2) The security mechanism testing method for the ultra-heterogeneous chip for ADAS proposed by the present invention makes full use of the resources of the ultra-heterogeneous chip, runs data processing and algorithm programs on the relevant cores of the computing unit, and runs the fault injection program on the MCU security island, which can realize dynamic injection of faults in the application scenario. At the same time, by dynamically injecting faults and performing a traversal verification on the security mechanism, the availability, recoverability and stability of the chip under various abnormal conditions are tested to evaluate its security mechanism design.
[0020] (3) The security mechanism testing method for the ultra-heterogeneous chip for ADAS proposed by the present invention can discover hidden security problems or vulnerabilities in the chip by performing MCU fault injection in different application scenarios, improving the stability and reliability of the chip under various application scenarios.
[0021] (4) The security mechanism testing method for the ultra-heterogeneous chip for ADAS proposed by the present invention can explore more scenarios by running different application programs, expose more potential problems, provide a diversified and operable fault injection platform, and achieve the effect of dynamic injection of faults in the ultra-heterogeneous chip.
[0022] (5) The security mechanism testing method for the ultra-heterogeneous chip for ADAS proposed by the present invention can perform a traversal test on all ECC storage units according to the storage unit type and different address blocks. Description of the Drawings
[0023] The above and other objects, features, and advantages of the present invention will become more apparent by describing the exemplary embodiments of the present invention in more detail with reference to the accompanying drawings, in which, in the exemplary embodiments of the present invention, the same reference numerals generally represent the same components.
[0024] Figure 1 It is a schematic flow diagram of a security mechanism testing method for an ultra - heterogeneous chip for ADAS proposed by the present invention.
[0025] Figure 2 It is a schematic diagram of a fault injection operation architecture in a specific embodiment of a security mechanism testing method for an ultra - heterogeneous chip for ADAS proposed by the present invention.
[0026] Explanation of reference numerals:
[0027] ROM - Read - Only Memory, SBL - Secondary Bootloader, MCU start - Micro - Control Unit start, MCU app - Micro - Control Unit program running, Fault Inject - Fault injection, Fault Delete - Fault deletion, Linux start - Linux start, Linux app - Linux program running. Specific embodiments
[0028] The preferred embodiments of the present invention will be described in more detail below. Although the preferred embodiments of the present invention are described below, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein.
[0029] In the present invention, unless otherwise stated, the directional terms such as "upper, lower" generally refer to the upper and lower in the normal use state of the device, and "inner, outer" refer to the inside and outside relative to the contour of the device. In addition, the terms "first, second, third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, the features defined with "first, second, third" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality" means two or more unless otherwise specifically defined.
[0030] The present invention provides a security mechanism testing method for an ultra - heterogeneous chip for ADAS, as Figure 1 shown, including:
[0031] Simultaneously running the LINUX system and the MCU real - time operating system in the heterogeneous chip;
[0032] Execute the MCU fault injection program in the MCU real-time operating system to traverse and test the security mechanisms of heterogeneous chips.
[0033] In the present invention, while the LINUX system algorithm application program is running, the MCU fault injection program is executed, realizing dynamic fault injection and achieving the purpose of simulating the injection of faults in the real application scenario of the super heterogeneous chip to test the security mechanism.
[0034] In the present invention, simultaneously running the LINUX system and the MCU real-time operating system in the heterogeneous chip may include:
[0035] After the heterogeneous chip is powered on, run the ROM program, and load the secondary bootloader through the ROM;
[0036] Load the LINUX system and the MCU real-time operating system through the secondary bootloader;
[0037] Simultaneously run the LINUX system and the MCU real-time operating system.
[0038] According to the present invention, executing the MCU fault injection program in the MCU real-time operating system includes:
[0039] During the operation of LINUX, perform fault injection in the MCU real-time operating system by configuring registers and / or memory.
[0040] According to the present invention, before performing fault injection by configuring registers and / or memory, the following are also carried out:
[0041] Perform hardware initialization and fault management module initialization on the MCU real-time operating system in sequence;
[0042] Configure the management enable, interrupt priority, and fault output pin enable for the fault management module in sequence.
[0043] Preferably, the fault management module is used to summarize and monitor the security events or errors generated by the diagnosis of the entire device;
[0044] The configuration of management enable is to enable the management function of the fault management module;
[0045] The configuration of interrupt priority is to specify an event as a high-priority or low-priority interrupt;
[0046] The configuration of fault output pin enable is to configure the fault output pin as valid.
[0047] In the present invention, by making full use of the resources of the superheterogeneous chip, the data processing and algorithm programs are run on the relevant cores of the computing unit, and the fault injection program is run on the MCU security island, so that dynamic fault injection can be realized in the application scenario. At the same time, by dynamically injecting faults and traversing and verifying the security mechanism, the availability, recoverability and stability of the chip under various abnormal conditions are tested to evaluate the design of its security mechanism.
[0048] In the present invention, by performing MCU fault injection in different application scenarios, hidden security problems or vulnerabilities in the chip can be discovered, and the stability and reliability of the chip in various application scenarios can be improved.
[0049] Preferably, the fault injection by configuring registers and / or memory includes:
[0050] Fault injection is performed on a certain memory by sequentially configuring misconfigured memory, misconfigured address, flipped bit and misconfigured type in the register and / or memory.
[0051] According to the present invention, the traversal test of the security mechanism of the heterogeneous chip includes:
[0052] Performing fault injection on a certain memory in the MCU fault injection program;
[0053] Testing and evaluating the security mechanism of the memory by monitoring the fault output pin;
[0054] Testing and evaluating the security mechanisms of the remaining memories of the heterogeneous chip.
[0055] In the present invention, the fault injection can be ECC fault injection.
[0056] Preferably, before the fault injection, the following is also performed:
[0057] Enabling the ECC function;
[0058] The traversal test of the security mechanism of the heterogeneous chip is to perform a traversal test on all ECC storage units in the heterogeneous chip and all random memories in each ECC storage unit.
[0059] In the present invention, by running different application programs to explore more scenarios, more potential problems can be exposed, a diversified and operable fault injection platform is provided, and the effect of dynamic fault injection of the superheterogeneous chip is realized.
[0060] In the present invention, all ECC storage units can be traversed and tested according to the storage unit type and different address blocks.
[0061] In the present invention, for a heterogeneous chip, due to the multi-core heterogeneous architecture, there are certain differences in its corresponding applications due to different system requirements. And because of the integration of multiple cores, its applications are more complex than those of single-core and multi-core homogeneous processors. Taking the multi-core heterogeneous chip TDA4 of TI as an example, TDA4 captures the data input by the camera through the camera serial interface and then sends it to the vision processing hardware engine to convert the raw data. Various analysis and deep learning algorithms, such as object classification algorithms and available space detection algorithms, are run on the on-chip C7x DSP, MMA, and ARM Cortex-A72 cores of the processor. The MCU domain acts as an inspector for each step, regularly verifying and monitoring the data being processed. To improve the functionality and system reliability, the memories in many device modules and subsystems are protected by error-correcting code ECC. ECC performs single error correction (SEC) and double error correction (DED), reports the detected errors through ESM, corrects single-bit errors, and detects double-bit errors. The implementation process of fault injection is illustrated by taking the ECC fault injection test as an example.
[0062] The present invention will be described in more detail through specific embodiments below.
[0063] Embodiment 1
[0064] This embodiment provides a test method for the security mechanism of a heterogeneous chip for ADAS. The specific process is as follows:
[0065] As Figure 2 shown, after the chip is powered on, the ROM program runs. The ROM loads the secondary bootloader SBL. The secondary bootloader SBL loads the MCU RTOS and the LINUX system and runs the two systems simultaneously. The code related to fault injection is implemented in the MCU RTOS, and the algorithm application program runs in the LINUX system. While the LINUX is running, faults are injected in the MCU RTOS by modifying registers and memory.
[0066] In this embodiment, after the MCU is started, hardware initialization is first performed to initialize the fault management module. The fault management module aggregates safety-related events or errors generated from the diagnosis of the entire device to a location that can be monitored internally or externally. It allows events to be designated as high-priority or low-priority interrupts and can also directly operate the I / O error pin to signal to external hardware (such as an external monitor) that an error has occurred. By configuring the interrupt priority, for example, for ECC fault injection, a single-bit fault injection event can be configured as a low-priority event, and a double-bit injection as a high-priority event. Configure the fault output pin enable. When a fault is injected and the safety mechanism is triggered, the fault output pin can output a low level. By monitoring the level status of the output pin, it can be monitored whether the safety mechanism takes effect. Before performing ECC fault injection, the ECC function needs to be enabled, then configure the error injection address in software, configure the error flip bit, and configure the error injection type as a single-bit error or a double-bit error. After the configuration is completed, error injection is performed. The result of the error injection triggers an error interrupt, and the level of the fault output pin is pulled low, completing the entire fault injection process.
[0067] Inside the chip, due to the multi-core heterogeneous design framework, not only to ensure the operation efficiency of each core itself, but also to improve the data exchange between cores, there are multiple memory media and controllers in the chip. Each Memory plays an important role in the system. For example, TDA4 is also configured with multiple memory media and controllers such as MSMC (Multicore Shared Memory Controller), OCMC (On Chip Memory Controller), TCM (Tightly-Coupled Memory), and Cache. To ensure the safety mechanism of these storage units takes effect, this embodiment performs a traversal test on all storage units. In software, all ECC storage units are traversed, and each RAMID in the ECC storage unit is traversed and tested.
[0068] Embodiment 2
[0069] As Figure 1 shown, this embodiment provides a safety mechanism test method for a super heterogeneous chip for ADAS, including:
[0070] Run the LINUX system and the MCU real-time operating system simultaneously in the heterogeneous chip;
[0071] Execute the MCU fault injection program in the MCU real-time operating system to perform a traversal test on the safety mechanism of the heterogeneous chip;
[0072] In this embodiment, running the LINUX system and the MCU real-time operating system simultaneously in the heterogeneous chip includes:
[0073] After the heterogeneous chip is powered on, run the ROM program and load the secondary boot program through the ROM;
[0074] Load the LINUX system and the MCU real-time operating system through the secondary boot program;
[0075] Run the LINUX system and the MCU real-time operating system simultaneously;
[0076] Execute the MCU fault injection program in the MCU real-time operating system, including:
[0077] During the operation of LINUX, perform fault injection in the MCU real-time operating system by configuring registers and / or memory;
[0078] In this embodiment, before performing fault injection by configuring registers and / or memory, the following operations are also carried out:
[0079] Perform hardware initialization and fault management module initialization on the MCU real-time operating system in sequence;
[0080] Configure the fault management module in sequence for management enabling, interrupt priority, and fault output pin enabling;
[0081] In this embodiment, the fault management module is used to summarize and monitor security events or errors generated by the diagnosis of the entire device;
[0082] The configuration of management enabling is to enable the management function of the fault management module;
[0083] The configuration of interrupt priority is to specify an event as a high-priority or low-priority interrupt;
[0084] The configuration of fault output pin enabling is to configure the fault output pin as valid;
[0085] In this embodiment, performing fault injection by configuring registers and / or memory includes:
[0086] Perform fault injection on a certain memory by sequentially configuring mis-injected memory, mis-injected address, flipped bit, and mis-injected type in the register and / or memory;
[0087] Performing a traversal test on the security mechanism of the heterogeneous chip includes:
[0088] Perform fault injection on a certain memory in the MCU fault injection program;
[0089] Test and evaluate the security mechanism of this memory by monitoring the fault output pin;
[0090] Test and evaluate the security mechanisms of the remaining memories of the heterogeneous chip;
[0091] In this embodiment, the fault injection is ECC fault injection;
[0092] Configure the single-bit fault injection event as a low-priority event and the double-bit injection as a high-priority event;
[0093] Configure the fault output pin to be active low;
[0094] Configure the mis-injection type as single-bit error or double-bit error;
[0095] In this embodiment, before the ECC fault injection, the following is also performed:
[0096] Enable the ECC function;
[0097] The traversal test of the security mechanism of the heterogeneous chip is to perform a traversal test on all ECC storage units in the heterogeneous chip and all random access memories in each ECC storage unit.
[0098] The security mechanism test method for the ultra-heterogeneous chip for ADAS in this embodiment executes the MCU fault injection program while the LINUX system algorithm application program is running, realizes the dynamic injection of faults, and realizes the purpose of testing the security mechanism by injecting faults in the real application scenario of the simulated ultra-heterogeneous chip.
[0099] The embodiments of the present invention have been described above. The above description is exemplary and not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments.
Claims
1. A test method for the security mechanism of a hyper - heterogeneous chip for ADAS, characterized in that, including: running the LINUX system and the MCU real-time operating system simultaneously in the heterogeneous chip; executing an MCU fault injection program in the MCU real-time operating system to perform a traversal test on the security mechanism of the heterogeneous chip; executing the MCU fault injection program in the MCU real-time operating system includes: during the operation of LINUX, performing fault injection in the MCU real-time operating system by configuring registers and / or memory; before performing fault injection by configuring registers and / or memory, further performing: performing hardware initialization and fault management module initialization on the MCU real-time operating system in sequence; configuring the fault management module in sequence for management enabling, interrupt priority, and fault output pin enabling; the fault management module is used to summarize and monitor security events or errors generated by the diagnosis of the entire device; the configuration of the management enabling is to enable the management function of the fault management module; the configuration of the interrupt priority is to designate an event as a high-priority or low-priority interrupt; the configuration of the fault output pin enabling is to configure the fault output pin as valid.
2. The method according to claim 1, characterized in that, performing fault injection by configuring registers and / or memory includes: performing fault injection on a certain memory by sequentially configuring mis-injected memory, mis-injected address, flip bits, and mis-injected type in the register and / or memory.
3. The method according to claim 2, characterized in that, performing a traversal test on the security mechanism of the heterogeneous chip includes: performing fault injection on a certain memory in the MCU fault injection program; testing and evaluating the security mechanism of this memory by monitoring the fault output pin; testing and evaluating the security mechanisms of the remaining memories of the heterogeneous chip.
4. The method according to claim 3, wherein the fault injection is ECC fault injection; before ECC fault injection, further performing: enabling the ECC function; performing a traversal test on the security mechanism of the heterogeneous chip is to perform a traversal test on all ECC storage units in the heterogeneous chip and all random memories in each ECC storage unit.
5. A test device for the security mechanism of a superheterogeneous chip for ADAS, characterized in that, including: a system operation module, used to run the LINUX system and the MCU real-time operating system simultaneously in the heterogeneous chip; a traversal test module, used to execute an MCU fault injection program in the MCU real-time operating system to perform a traversal test on the security mechanism of the heterogeneous chip; executing the MCU fault injection program in the MCU real-time operating system includes: during the operation of LINUX, performing fault injection in the MCU real-time operating system by configuring registers and / or memory; before performing fault injection by configuring registers and / or memory, further performing: performing hardware initialization and fault management module initialization on the MCU real-time operating system in sequence; configuring the fault management module in sequence for management enabling, interrupt priority, and fault output pin enabling; the fault management module is used to summarize and monitor security events or errors generated by the diagnosis of the entire device; the configuration of the management enabling is to enable the management function of the fault management module; the configuration of the interrupt priority is to designate an event as a high-priority or low-priority interrupt; The configuration of enabling the fault output pin is to configure the fault output pin as valid.
Citation Information
Patent Citations
QNX BSP starting verification method and QNX BSP starting verification module
CN112231710A
Virtual machine security monitoring processing method and device, equipment and medium
CN116643842A
Dynamically reconfigurable field self-test capability for automotive systems
CN116724298A