Core Processor with Control Flow Attack Detection and Redundant Branch Processor

By introducing the main core processor and redundant branch processor architecture into the pipeline processor architecture, the high power consumption and low efficiency problems of injecting code detection in the prior art are solved, and more efficient safe detection and power consumption reduction are achieved.

CN118541672BActive Publication Date: 2025-05-27CEREMORPHIC INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202280076518.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-09-26
Filing Date
2022-09-25
Publication Date
2025-05-27
Estimated Expiration
2042-09-25

AI Technical Summary

Technical Problem

The prior art detects and prevents the execution of code injection into pipeline processor architectures, and results in high power consumption and low computing efficiency.

Method used

Using the architecture of the main core processor and redundant branch processor, the main core processor handles memory access, calculation, and address arithmetic, while the redundant branch processor only executes branch initialization instructions, conditional or unconditional branch instructions and iterative variable instructions. Both output branch status to the fault detector, which is used to compare and generate fault detection outputs.

Benefits of technology

By reducing the functional complexity of redundant branch processors, power consumption is reduced while effectively detecting and preventing the execution of injected code, improving computing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118541672B_ABST
    Figure CN118541672B_ABST
Patent Text Reader

Abstract

A safety processor with fault detection has a core thread that executes together with a redundant branch processor thread. In one configuration, the core thread operates on a full-function core processor configured to execute a full instruction set, and the redundant branch processor thread contains only initialization instructions and flow control instructions such as branch instructions, and operates on a redundant branch processor configured to execute a subset of the full instruction set, particularly branch control variable initialization and branch instructions, thereby greatly simplifying the redundant branch processor architecture. Fault conditions are detected by comparing the history of branch taken / not taken and branch targets, or comparison of program counter activity of the core thread and the redundant branch processor thread.
Need to check novelty before this filing date? Find Prior Art

Description

Field of the Invention

[0001] The present invention relates to a thread - safe processor. More particularly, the present invention relates to an architecture for detecting an intrusion into an executed program in single - threaded and multi - threaded applications. Background of the Invention

[0003] Pipeline processors are well - known in the field of computer architecture. Each level in a series of pipeline stages performs an operation and forwards the result to the next level.

[0004] A common security problem in computer architecture is the "code injection" problem, where a malicious entity replaces executable code with code that performs unwanted operations, which is typically part of a security vulnerability. Malicious code injection can be performed, for example, through a buffer overflow, where an input contains a long data string of executable code and the program that processes the data string does not truncate or check the data length, causing a data buffer overflow in the memory adjacent to the executable code space, resulting in the execution of malicious code from the executable code space. Many other malicious techniques can be used to perform code injection attacks.

[0005] One prior - art approach is to replicate the processor and compare the results, as well as compare the results of executing the same code. However, the computational and hardware overhead required to detect and prevent the execution of unwanted injected code in these prior - art systems leads to excessive power consumption and low computational efficiency.

[0006] There is a desire to provide an improved system and method for detecting the execution of injected code in a pipeline processor architecture.

[0007] Objectives of the Invention

[0008] A first objective of the present invention is a secure pipeline processor, including a main core processor and a redundant branch processor. The main core processor processes memory access, calculations, and address arithmetic for memory - addressing instructions. The redundant branch processor only executes branch initialization instructions, conditional or unconditional branch instructions, and iteration variable instructions. The main core processor and the redundant branch processor output branch states to a fault detector for comparison and generation of a fault - detection output.

[0009] A second objective of the present invention is a secure pipeline processor, including a main core pipeline processor and a redundant branch pipeline processor. The main core pipeline processes memory access, calculations, and address arithmetic for memory - addressing instructions. The redundant branch processor only processes branch initialization instructions, conditional or unconditional branch instructions, NOP instructions, and iteration variable instructions. The main core processor and the redundant branch processor output branch states to a fault detector for comparison and generation of a fault - detection output.

[0010] A third object of the present invention is a secure multi-threaded processor that executes a plurality of threads including a first thread and a second thread. The first thread is a core program, and the second thread is a redundant branch processor program. The core program of the first thread includes memory access instructions, computing instructions, and address arithmetic instructions for memory addressing instructions. The redundant branch processor program (or redundant branch processor thread) includes branch initialization instructions, conditional or unconditional branch instructions, and iteration variable instructions. The multi-threaded processor outputs a list of branch states from the first thread and the second thread to a fault detector, and the branch states include at least one of branch taken / not taken, branch direction, and branch target.

[0011] A fourth object of the present invention is a fault detector for a secure processor. The fault detector receives branch states that include at least one of branch taken / not taken, branch direction, and branch target from a first processor and a second processor. The fault detector sequentially compares the branch states and generates a fault when the offsets in branch taken / not taken, branch direction, or branch target do not match each other.

[0012] A fifth object of the present invention is a method for generating a redundant branch program from a core program. The method includes identifying an execution loop that includes initialization instructions, iteration instructions, and branch instructions. The method generates a redundant branch program by identifying new iteration variables from the initialization instructions and generating a program that includes initialization instructions using the new iteration variables, iteration instructions using the new iteration variables, and branch instructions using the iteration variables.

[0013] A sixth object of the present invention is a method for generating a redundant branch program from a core program. The method includes identifying an execution loop that includes initialization instructions, iteration instructions, and branch instructions. The method generates a redundant branch program by identifying new iteration variables from the initialization instructions and generating a program that includes initialization instructions using the new iteration variables, iteration instructions using the new iteration variables, and branch instructions using the iteration variables, and replacing other instructions with NOP instructions to keep the number of instructions in the redundant branch program the same as the number of instructions in the core program. Summary of the Invention

[0015] In a first example of the present invention, the security processor includes a core processor and a redundant branch processor. Each of the core processor and the redundant branch processor includes a plurality of pipeline stages, and the pipeline stages include: an address fetch stage and a decode stage. The address fetch stage is used to generate a program address, and the decode stage is used to decode an instruction from a program access into individual operation actions and pass non-multiplication instructions to the ALU of the first execution stage. The first execution stage receives the decoded multiplication instructions and performs multiplier operations, and decodes non-multiplication instructions for use by the second execution stage in cycles when multiplier operations are not performed. The second execution stage includes an arithmetic logic unit (ALU) that sends the result to the load / store stage. The load / store stage reads and writes results from / to the register file or external memory. Data intended for the register file is processed by the write-back stage. The core processor executes control instructions, data instructions, and a subset of control instructions, which is called branch control instructions. The branch control instructions include at least one of initialization instructions, branch arithmetic instructions associated with branch instructions, no-operation (NOP) instructions, and branch instructions. The core processor executes the main program, which includes control instructions, branch control instructions, and data instructions for performing the required operations, while the redundant branch processor only executes branch control instructions, which include at least one of branch iteration variable initialization, conditional and unconditional branch instructions, and associated iteration variable modification instructions (such as incrementing or decrementing of variables associated with conditional branch instructions). The core processor and the redundant branch processor output branch status information, which includes at least one of branch taken / not taken, branch direction, and / or branch target address. The fault detector sequentially compares the branch status information from the core processor and the redundant branch processor, and generates a fault detection output when the comparison of the branch status information fails. The comparison can check for a match in branch taken / not taken, branch direction, or offset value of the branch target. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 Shows a block diagram of a dual-way fully redundant error detection processor.

[0018] Figure 2 Shows a block diagram of a first example of the present invention using a main core pipeline processor thread and a redundant branch processor thread, which executes instructions determined based on an inspection of the instructions of the main core pipeline processor.

[0019] Figure 3A and Figure 3B Shows example MIPS instructions for the core processor thread and the redundant branch processor thread.

[0020] Figure 4A and Figure 4BShows another example of MIPS instructions for core processor threads and redundant branch processor threads.

[0021] Figure 5A and Figure 5B Shows a block diagram of a fault detector.

[0022] Figure 6 Displays a flowchart for generating redundant branch processor threads from a core thread.

[0023] Figure 7 Shows a block diagram of a multithreaded variant of the present invention.

[0024] Detailed Description of the Invention

[0025] Figure 1 Shows an example of a fully redundant fault detection pipelined processor, which includes identical processing blocks 101A and 101B. The processing blocks 101A and 101B each execute the same program and have the same stages. In checking processor 101A, program instructions are stored in instruction memory 116A, and these instructions are fetched by fetch stage 104A using program counter 105A, and alternatively, previously retrieved instructions can be recovered from instruction cache 107A instead of instruction memory 116A. Fetch stage 104A passes the retrieved instructions to decode stage 106A, which converts the retrieved opcode into specific operations to be executed by decode-execute stage 108A and execute stage 110A. Load / store stage 112A processes instructions that require register access, while write-back stage 114A writes the modified data back to the associated register file 118A. In the fully redundant fault detection mode, two identical processors are required, and they are shown as pipelined processors 101A and 101B. The two processors execute the same instructions, and system 100 detects mismatches between the two processors and asserts fault detection 126 based on the mismatches. For low-power or high-density processors, typically, it is sufficient to detect a fault, which causes the system to reinitialize upon detection of the fault and re-establish safe program execution. Figure 1 The example system doubles the power consumption and system complexity as the cost of performing fault detection, so this is unacceptable for this fault detection function.

[0026] By Figure 1The instructions executed by a processor are divided into two categories - control flow instructions, such as conditional or unconditional branch instructions (including associated branch iteration variable initialization and modification instructions), and data instructions, such as instructions related to memory access, computation, and address arithmetic for memory addressing. Analysis of the instructions for various benchmarks reveals that control flow instructions such as branch instructions represent 2% to 20% of the executed instructions from various benchmarks, and in typical applications, branch instructions on average represent 5% to 10% of the executed instructions. It is desired to provide an architecture that provides the security of a fully redundant architecture such as Figure 1 while saving power by leveraging an execution architecture with a low percentage of branch instructions.

[0027] Figure 2 An example secure processor 200 with branch attack detection is shown. In Figure 2 the present invention, the core processor 201A executes all instructions (control instructions, branch control instructions, and data instructions), while the redundant branch processor 201B executes a program derived from the program executed by the core processor 201A, but the branch control instructions are present, and the data instructions are replaced with NOP (no operation) instructions of the same program length, or removed and collapsed, and the branch targets are adjusted accordingly. The fault detection 224 compares the branch status information generated by the two processors, which should match each other, or have a fixed offset from each other, and if a difference is detected, a fault detection output 226 is generated. The execution of a branch instruction (conditional or unconditional) results in an updated status register associated with the branch. The status flags for arithmetic operations in the status register can be "equal", "greater than", "less than", "zero", "overflow", and various other well-known examples used in conditional branch instructions. A branch can be an absolute branch (to a specific address) or a relative branch (incrementing an offset from the current address to identify a new location of program execution), as shown respectively in Figure 3A / Figure 4A and Figure 3B / Figure 4Bas shown by "Label1 (Label 1)" and "Label 2 (Label 2)" in. When a branch is taken, this may cause a program counter offset value or an absolute value to be applied to the program counter to generate a new branch target address (also referred to as a "branch target"), at which the execution of the program will continue, and the branch direction can be forward or backward in the program memory. In the present invention, an example for comparing branch actions in a core processor and a redundant branch processor is generally referred to as "branch status" information, which may include one or more of branch taken / not taken, branch direction, or branch target address 211A / 211B provided by the decode stage 206A / 206B or 208A / 208B, or the program counter value 213A / 213B, which may be provided by the fetch stage 204A / 204B. The fault detector 224 may use any combination of these inputs to detect faults by detecting differences in branch status information between the redundant branch program and the core program.

[0028] In different processor embodiments of the present invention, the main core pipeline processor 201A includes Figure 1all of the processing elements as in any of the processors 101A, 101B, 101C, and the redundant branch pipeline processor 201B has stage elements of reduced complexity, where the pipelined decode stage 206B, decode execution stage 208B, execution stage 210B, load / store stage 212B, and write-back stage 214B only process the specific branch control instructions described previously, such as branch iteration variable related instructions (iteration variable initialization and modification), conditional and unconditional branch instructions, and NOP instructions, while the corresponding core pipeline processor 201A is configured to process all instructions, including the full set of control instructions and data instructions. In a first example of unequal processor embodiments, where the redundant branch processor has reduced functionality, power savings are achieved through the reduced complexity of the redundant branch processor 201B compared to the core processor 201A. In this first example of unequal processor embodiments, the main core processor 201A executes a full-function program, while the redundant branch processor executes a modified version of the full-function program, where NOP instructions replace non-initialized and non-branch instructions (instructions not associated with loop branches, loop initializations, and loop variable modifications), and generates a list of branch status information for use by a fault detector that compares the sequence of branch status information between the core processor and the redundant branch processor. In this first example, the corresponding programs of the core processor and the redundant branch processor can be executed synchronously (so that branches and program counters can be compared instantaneously), or the two programs can be executed asynchronously or at different speeds, leaving a branch history for comparison in order to detect a fault condition when there is a difference in branch status information between the two processes. In a second example of unequal processor embodiments, the NOP instructions of the modified version of the full-function program are removed, so that the redundant branch processor only executes loop variable initialization, loop variable modification, and conditional or unconditional branch instructions, creating a branch status that can include at least one of branch taken / not taken, branch direction, branch target, forming a branch target trace for use by a fault detector to compare with the main core processor.

[0029] In a single-processor variant of the present invention where the redundant branch program and the core program are executed separately on a single processor, in order to pre-compute a list of branch status information, the single processor can first execute the redundant branch process, or periodically execute the redundant branch process. The pre-computed branch status information can be loaded into a list of 512 such as Figure 5B and then the single processor can thereafter switch to the execution of the core process, which generates a list of core processor branch status information that is loaded into Figure 5BIn 510, and each newly arrived branch status information entry is verified against the corresponding sequence in 512. In this way, the entire sequence or a part of the sequence of branch status information can be pre-computed or computed periodically, for example in a subroutine by subroutine, thread by thread manner.

[0030] In the balanced processor embodiment of the present invention, the main core pipeline processor 201A and the redundant branch processor 201B have the same functions, and in the first example of the present invention, the redundant branch processor program has NOP instructions to replace all instructions except for loop variable initialization, loop variable modification, and loop branch instructions, which are required to generate a branch status that matches the branch status of the main core pipeline processor, as described for different processor embodiments. In this first example of the balanced processor embodiment, power savings are achieved by the execution of NOP instructions compared to the unmodified instructions of the core processor program, and the fault detector can perform a comparison of the branch status (branch taken / not taken, branch direction, and branch target address) to detect a fault and assert a fault output. In the second example of the balanced processor embodiment, the NOP instructions of the first example are removed, leaving only the initialization and loop branch instructions, and the fault detector compares branch taken / not taken, branch direction, and branch target between the core processor and the redundant branch processor.

[0031] Figure 3A and Figure 3B shows an example instruction for a multiply-accumulate operation called "saxpy", which is an acronym for "Sum of A*X Plus Y". In the example shown, the initialization step 302 includes the initialization of a loop variable in register 2, which is used as a counter for the number of branches taken. Register 2 is used for indirect addressing (addressing through register content), where register 3 plus an offset of 0 points to x(i), and register 3 plus an offset of 4000 points to y(i). Register 4 is a loop variable increment counter, which is set to 100 in this example, and is used to accumulate 100 values of a*x(i)+y(i). The x(i) array starts at position 0, and the y(i) array starts at position 4000. Register 5 is the constant "a" used in the saxpy operation, and as shown, the saxpy operation is performed in loop 306 and terminates when register 2 (loop iteration variable i) reaches 100. Figure 3A The operation of Figure 3BShows an example instruction executed by the redundant branch processor 201B, where the redundant branch processor only performs loop initialization at step 308, and loop 310 counts the number of iterations, thereby creating a branch status list that should match the branch status list generated by the core processor.

[0032] Figure 4A Shows Figure 3A of the core processor thread. Figure 4B Shows a redundant branch processor thread, which is derived from the Figure 4A core processor thread by initializing the branch counter register 6 and replacing other commands that are not loop branches with no-operation (nop) instructions. In an example operation, the core processor 201A in the figure and the redundant branch processor 201B in the figure each execute one instruction per clock cycle and are timed together. However, the decode stage 206B, decode / execute stage 208B, execute stage 210B, load / store stage 212B, and write-back stage 214B only need to support the Figure 4B initialization of a simplified instruction set and a subset of the branch instructions, while the core processor 201A has full capabilities and supports all instructions of the instruction set. In another example operation, the core processor 201A in the figure and the redundant branch processor 201B in the figure execute asynchronously or at different speeds, and maintain records of the branch status for each of the core processor 201A and the redundant branch processor 201B, such as branch taken / not taken, branch direction, and branch target, and compare the records of the branch status to detect faults.

[0033] In an example of the present invention, where Figure 4A and Figure 4B instructions are executed on the corresponding core processor 201A and redundant branch processor 201B at one instruction per clock cycle, the program counters of the core processor 201A and the redundant branch processor 201B will track each other with a fixed offset, and the fixed offset is equal to the difference in memory locations. If there is corruption in the program memory of the core processor 201A, the branch status histories of the two processors will differ, resulting in the assertion of the fault detection output 226. Fault detection can cause the reset of the system, a fault report, or other actions to restore the correct operation of the processor and identify the cause of the fault.

[0034] Figure 5A and Figure 5B Show corresponding example fault detectors for the synchronous and asynchronous operations of processors 201A and 201B. Figure 5A Shows for Figure 4A and Figure 4BA program counter-based failure detector for a core thread and a redundant thread, where the two threads are executed in parallel on corresponding core and redundant processors, such that the two processors maintain a fixed offset between the program counters 205A and 205B of the corresponding core and redundant branch processors. A minimal branch state history is required, and an offset comparator 502 compares the two program counter inputs 205A and 205B, optionally with a pre-programmed expected offset 504, and generates a failure output 506 when the difference between the two program counters exceeds the offset plus a threshold for accounting for asynchronous instruction execution (e.g., one or two instructions).

[0035] In the case where the core thread and the redundant branch thread operate asynchronously or at different times but have the same branch characteristics (e.g., having different lengths of Figure 3A the core processor thread of Figure 3B and the redundant branch processor thread of Figure 5B illustrates an example failure detector, where the list of branch state history, for example, comes from the core processor 201A executing Figure 3A a program and the redundant branch processor 201B executing Figure 3B a program, where the branch state history may include at least one of taken / not taken, branch direction, and associated target address fields, which are stored as sequential list entries, and the core processor and the redundant branch processor maintain their respective branch state history lists 510 and 512. A table comparator 514 makes a sequential entry-by-entry comparison of the decisions made by the core processor and the redundant branch processor, and generates a failure detection output 516 when different branch results are detected.

[0036] The present invention can be implemented in many different ways. Figure 2 Illustrates a core processor 201A configured to operate simultaneously and a redundant branch processor 201B with reduced capabilities, achieving power savings by reducing the complexity of the redundant branch processor 201B. The redundant branch processor 201B only needs to support register initialization and branch control logic in each pipeline stage. In another example, the present invention can also be implemented with a redundant branch processor 201B of equal capabilities, because NOP (no operation or nop) instructions consume less power than the original instructions replaced by Figure 4B the nop instructions due to reduced internal activity.

[0037] In another example of the present invention for a single pipeline processor, Figure 7illustrates a multi-threaded processor in which a core thread and a redundant branch thread can operate as independent threads in a single processor 700, and in one example, operate as sequential threads 1 (T1) and 2 (T2) on a single processor 700 with multi-threading capabilities, such as the sequence T1 T2 T1 T2...... described in U.S. Patent 7,761,688, which is incorporated herein by reference in its entirety. In the case where the multi-threaded processor executes each corresponding instruction of the core thread (T1) and the redundant branch thread (T2) and replaces non-branch-related instructions with NOP instructions for the redundant branch thread, instruction count balancing such as that shown in Figure 4B is performed for Figure 4A so that divergence of the program counter as shown in Figure 5A or divergence of the branch state as shown in Figure 5B can be executed, such as branch taken / not taken, branch direction, and branch target address comparison, because the two threads will track each other's program counters and execution-level results for each corresponding thread. In this case, the single processor outputs a thread identifier (thread_id) accompanied by the branch state for use by the multiplexer 703, and the multiplexer 703 outputs a first thread branch state (T1BrSt 705) and a second thread branch state (T2 BrSt 707), which are input to the fault detector 706 (e.g., Figure 5B the fault detector with corresponding inputs 208A and 208B). Figure 7 The example shown is Figure 2 a single-processor variant, and the C suffix on the reference numerals indicates similar operations. The thread generator 702 generates a thread_id 702, which is used to select a specific register file associated with the thread by thread_id, as well as the program counter 712. The fault detector 706 operates as a Figure 5B thread detector, however, the branch state inputs to Figure 5B 510 and 512 are separate branch state values applied to each corresponding table 510 and 512 according to the thread_id. For example, in the case where the thread_id alternates between T1 T2 T1 T2......, the branch state (BS) 213 is output as the corresponding sequence BS1 BS2 BS3 BS4......, and the thread_id is used to place BS1 and BS3 as sequential entries related to T1, and place BS2 and BS4 as sequential entries related to T2. Alternatively, the threads can execute asynchronously, e.g., at different times, in which case Figure 5BThe fault detector can be used to compare a later-executed thread with an earlier-executed thread, which is most suitable for iterative threads with a fixed number of iterations and less suitable for branches that depend on tests that may vary over time. In this example, the core thread T1 can generate list 510, while the redundant branch thread T2 can generate list 512 for use by the fault detector, which compares the sequence of entries in the two lists to detect a fault condition. In another example of the present invention, the processor only periodically executes the core thread and the redundant branch thread for fault detection, and executes the core thread alone at other times.

[0038] Figure 6 An example method for generating redundant branch processor-executable code (or program) for execution in a redundant branch processor such as Figure 2 201B is shown. Step 602 identifies the core program iteration loop, such as Figure 4A 406, and allocates 604 memory for the redundant branch processor code that matches the number of Figure 4A instructions. Step 606 identifies the core program loop initialization, such as Figure 4A instruction 403, and copies it to the corresponding location in the code space, and in step 610, identifies the unused registers for initialization and copies the corresponding branch instructions to the corresponding locations in the redundant branch processor code, with an offset that matches the offset in the core program, and adjusts the redundant branch processor code branch instructions to use the free registers of step 610. In the optional step 614, other instructions are saved as NOP (no operation), thus creating Figure 4A the redundant branch processor program from Figure 4B the core processor program. Alternatively, the NOP instructions of step 614 are not executed, and the conditional branch follows the iteration variable modification, as Figure 3B shown.

[0039] Many aspects of the present invention are possible.

[0040] In a first aspect of the present invention, a fault detection pipelined processor includes a multi-threaded pipelined processor and a fault detector;

[0041] The multi-threaded pipelined processor is configured to execute control instructions and data instructions and output the branch status from branch instructions to the fault detector;

[0042] The multi-threaded pipelined processor is configured to execute at least two program threads on different instruction cycles, at least one thread being an executable program thread and at least one thread being a redundant branch program thread;

[0043] The executable program thread has control instructions, data instructions, and branch control instructions, and the branch control instructions are a subset of the control instructions;

[0044] The redundant branch thread only has branch control instructions;

[0045] The fault detector compares the branch states between the executable program thread and the redundant branch thread, and asserts a fault detection output when the branch state of the executable program does not match the branch state of the redundant branch thread.

[0046] In a second aspect of the present invention, the fault detection pipeline processor of the first aspect has branch control instructions, which include at least one of a branch variable initialization instruction, a branch variable modification instruction, and a branch instruction.

[0047] In a third aspect of the present invention, for the fault detection pipeline processor of the first aspect, the branch state includes at least one of branch taken / not taken, branch direction, and branch target.

[0048] In a fourth aspect of the present invention, the fault detection pipeline processor of the first aspect has a fault detector, which includes a comparison of branch state lists for corresponding entries of the executable program thread and the redundant branch thread.

[0049] In a fifth aspect of the present invention, the fault detection pipeline processor of the fourth aspect has a branch state list generated by the redundant branch thread before the execution of the executable program thread.

[0050] In a sixth aspect of the present invention, the fault detection pipeline processor of the fourth aspect has a branch state list, which includes a first branch state list generated by the executable program thread and a second branch state list generated by the redundant branch thread.

[0051] In a seventh aspect of the present invention, the fault detection pipeline processor of the first aspect has a redundant branch thread derived from the executable program thread by replacing instructions that are not branch control instructions with no-operation (NOP) instructions.

[0052] In an eighth aspect of the present invention, the fault detection pipeline processor of the first aspect has a redundant branch thread derived from the executable program thread by removing instructions that are not branch control instructions while retaining the branch target address.

[0053] In a ninth aspect of the present invention, the processor includes:

[0054] A pipeline processor configured to execute a plurality of executable program threads, and the pipeline processor outputs thread identifiers and branch state information of at least a first executable thread and a second executable thread;

[0055] The first executable thread, which is associated with a first unique thread identifier, includes data instructions, control instructions, and branch control instructions, where the branch control instructions are a subset of the control instructions;

[0056] The second executable thread, which is associated with a second unique thread identifier, includes only branch control instructions;

[0057] A fault detector that receives branch status information from a pipeline processor, where the branch status information is accompanied by a thread identifier associated with the first executable thread and a thread identifier associated with the second executable thread;

[0058] The fault detector compares the branch status information associated with the first thread identifier and the branch status information associated with the second thread identifier, and asserts a fault condition when the comparison does not match.

[0059] In a tenth aspect of the present invention, the fault detection pipeline processor of the ninth aspect has branch control instructions that include iteration variable initialization instructions, iteration variable modification instructions, and branch instructions.

[0060] In an eleventh aspect of the present invention, the fault detection pipeline processor of the ninth aspect has a branch status that includes at least one of branch taken / not taken, branch direction, and branch target.

[0061] In a twelfth aspect of the present invention, the fault detection pipeline processor of the ninth aspect has a fault detector comparison that includes a comparison of branch status lists of corresponding entries of an executable program thread and a redundant branch thread.

[0062] In a thirteenth aspect of the present invention, the fault detection pipeline processor of the twelfth aspect has a branch status list generated by the redundant branch thread before the execution of the executable program thread.

[0063] In a fourteenth aspect of the present invention, the branch status list of the fault detection pipeline processor of the twelfth aspect of the present invention includes a first branch status list generated by the executable program thread and a second branch status list generated by the redundant branch thread.

[0064] In a fifteenth aspect of the present invention, the processor of the ninth aspect, where a redundant branch thread is derived from the executable program thread by replacing instructions that are not branch control instructions with no-operation (NOP) instructions.

[0065] In a sixteenth aspect of the present invention, the processor of the ninth aspect has a redundant branch thread derived from an executable program thread by removing instructions that are not branch control instructions, thereby reducing the number of instructions in the redundant branch thread while preserving the branch target addresses of the redundant branch thread.

[0066] In a seventeenth aspect of the present invention, a fault detection pipeline processor is configured for multithreaded operation. The pipeline processor includes a plurality of sequential stages, and at least one stage operates on branch instructions to generate a branch state that includes at least one of a branch direction, whether the branch is taken / not taken, and a branch target;

[0067] The plurality of execution threads include:

[0068] A first thread having an associated first thread_id and execution instructions that include control instructions, branch control instructions that are a subset of the control instructions, and data instructions;

[0069] A second thread having an associated second thread_id and execution instructions that include only control instructions;

[0070] The branch control instructions include at least one of a conditional branch instruction, an unconditional branch instruction, a no-operation (NOP) instruction, a branch variable initialization instruction, and a branch variable modification instruction associated with a conditional branch instruction;

[0071] A fault detector that receives the branch state from the pipeline processor, the branch state being accompanied by the associated first thread_id and second thread_id;

[0072] The fault detector compares the branch states of the first thread_id and the second thread_id to generate a match, and when no match is found, the fault detector asserts a fault output.

[0073] In an eighteenth aspect of the present invention, the fault detection pipeline processor of the seventeenth aspect has execution control instructions that include instructions from a reduced instruction set computer (RISC) instruction set.

[0074] In a nineteenth aspect of the present invention, the fault detection pipeline processor of the seventeenth aspect has data instructions that include arithmetic operation instructions.

[0075] In a twentieth aspect of the present invention, the fault detection pipeline processor of the seventeenth aspect causes the fault detector to generate a list of branch states by executing the second thread before comparing the branch state with the first thread.

Claims

1. A fault detection pipelined processor, comprising a core processor and a redundant branch processor; The core processor is configured to execute control instructions and branch control instructions, where the branch control instructions are a subset of the control instructions, and the branch control instructions include at least one of a variable initialization instruction, a branch instruction, a variable arithmetic instruction associated with the branch instruction, and a no operation (NOP) instruction; The core processor is further configured to execute control instructions and data instructions. The core processor sequentially includes a fetch stage, a decode stage, a decode-execute stage, an execute stage, a load-store stage, and a write-back stage. The fetch stage is coupled to the decode stage, the decode stage is coupled to the decode-execute stage, the decode-execute stage is coupled to the execute stage, the execute stage is coupled to the load-store stage, and the load-store stage is coupled to the write-back stage; The redundant branch processor is configured to only execute branch control instructions. The redundant branch processor sequentially includes a fetch stage, a decode stage, a decode-execute stage, an execute stage, a load-store stage, and a write-back stage. The fetch stage is coupled to the decode stage, the decode stage is coupled to the decode-execute stage, the decode-execute stage is coupled to the execute stage, the execute stage is coupled to the load-store stage, and the load-store stage is coupled to the write-back stage; A fault detector that receives a branch status value from the core processor and a branch status value from the redundant branch processor, where the branch status value includes at least one of a branch target, a branch direction, and whether the branch is taken / not taken; When the branch status including at least one of the branch target, branch direction, or whether the branch is taken / not taken of the core processor does not match the branch status including at least one of the branch target, branch direction, or whether the branch is taken / not taken of the redundant branch processor, the fault detector asserts an output; Wherein, the core processor and the redundant branch processor are configured to operate simultaneously during a first time interval and are configured to operate separately during a second time interval.

2. The fault detection pipelined processor according to claim 1, Wherein, The branch instruction includes at least a conditional branch instruction or an unconditional branch instruction.

3. The fault detection pipelined processor according to claim 1, Wherein, The execution of control instructions and data instructions includes instructions from a reduced instruction set computer (RISC) instruction set.

4. The fault detection pipelined processor according to claim 1, Wherein, The data instruction includes an arithmetic operation instruction.

5. The fault detection pipelined processor according to claim 4, Wherein, The arithmetic operation instruction includes an addition instruction and a multiplication instruction.

6. The fault detection pipelined processor according to claim 1, Wherein, The core processor performs a summation operation of a*x(i)+y(i), where i is a loop iteration variable, a is a constant, and x(i) and y(i) are loaded arrays.

7. The fault detection pipelined processor according to claim 1, Wherein, The fault detector includes a core processor branch table and a redundant branch processor branch table, and each core processor branch table and redundant branch processor branch table is a circular queue of storage locations containing a sequence of branch status values.

8. The fault detection pipelined processor according to claim 1, wherein, the fault detector includes a table containing a list of branch status values, and the list of branch status values includes at least one of the following: branch taken / not taken, branch direction, and / or list of branch target locations.

9. The fault detection pipelined processor according to claim 8, wherein, the list of branch status values is calculated by the redundant branch processor before the core processor executes the program.

10. A method for generating an executable redundant branch processor thread from a core processor thread, the core processor thread having at least data instructions and control instructions, the control instructions including a subset of branch control instructions, the branch control instructions including at least one of a branch control variable initialization instruction, a branch control variable modification instruction, and a branch instruction, the method comprises: identifying the execution branch control in the core processor thread; identifying the branch control initialization value for the execution branch control in the core processor thread; identifying the execution branch control in the core processor thread and inserting branch control initialization at the corresponding position in the executable redundant branch processor thread; identifying the branch control conditional branch in the core processor thread and inserting the corresponding conditional branch instruction at the corresponding position in the executable redundant branch processor thread; identifying the executable instructions in the execution branch control of the core processor thread that are not branch control instructions and inserting no-operation (NOP) instructions at the corresponding positions in the executable redundant branch processor thread; wherein the core processor thread performs an a*x(i)+y(i) summation operation, where i is a loop iteration variable, a is a constant, and x(i) and y(i) are loaded arrays.

11. The method according to claim 10, wherein, the redundant branch processor thread has a branch target, and the branch target has a fixed offset from the corresponding branch target of the core processor thread.

12. The method according to claim 10, wherein, the control instructions and the data instructions are reduced instruction set computer (RISC) instructions.

13. A method for generating an executable redundant branch processor thread from a core processor thread, the core processor thread having at least branch control instructions and data instructions, the method comprises: identifying the execution loop in the core processor thread; identifying the initialization value for the execution loop in the core processor thread; identifying the execution loop variable initialization in the core processor thread and inserting the execution loop variable initialization at the corresponding position in the executable redundant branch processor thread; identifying the execution loop variable modification in the core processor thread and inserting the execution loop variable modification at the corresponding position in the executable redundant branch processor thread; Create a fault detection table containing a list of branch status values, the list of branch status values including at least one of branch adopted / not adopted, branch direction, and / or list of branch target locations, and the list of branch status values being calculated by the redundant branch processor before the core processor executes a program.

14. A fault detection pipelined processor, comprising: A core processor configured to execute control instructions and data instructions, the control instructions including a subset of branch control instructions, the branch control instructions including at least one of a no operation (NOP) instruction, a branch control variable initialization instruction, a branch control variable modification instruction, a conditional branch instruction, and an unconditional branch instruction; The core processor generates a branch status including at least one of branch adopted / not adopted, branch direction, and branch target; A redundant branch processor configured to execute only branch control instructions, the redundant branch processor generating a branch status including at least one of branch adopted / not adopted, branch direction, and branch target; A fault detector that compares the branch status from the core processor and the branch status from the redundant branch processor; When the corresponding branch statuses from the core processor and the redundant branch processor are not the same value, the fault detector asserts a fault output; wherein, before the core processor executes to generate a list of branch statuses, the redundant branch processor generates a list of branch statuses.

15. The fault detection pipelined processor according to claim 14, wherein, The fault detector stores the branch statuses from the core processor and the redundant branch processor in a list.

16. The fault detection pipelined processor according to claim 14, wherein, The core processor is configured to execute reduced instruction set (RISC) instructions.

17. The fault detection pipelined processor according to claim 14, wherein, The branch control instructions of the redundant branch processor are unconditional branches.

18. The fault detection pipelined processor according to claim 14, wherein, The branch control instructions of the redundant branch processor are iteration variable initialization, iteration variable modification, and conditional branches.

Citation Information

Patent Citations

  • Multiple thread in-order issue in-order completion DSP and micro-controller

    US7761688B1

  • Firmware mechanism for correcting soft errors

    CN101539875A

  • Fault detection and fallback method for dual-mode redundant pipeline

    CN105260256A