Vehicle-mounted Ethernet chip initialization storage unit fault protection system and method and storage medium

By designing pre- and post-stage initialization units during the initialization process of on-board chips, and using reread instructions, redundant backups and verification and correction measures, the failure problem in traditional technology that fails to effectively protect the chip initialization process is solved, functionally safe chip initialization is achieved, and initialization time is shortened.

CN119917347APending Publication Date: 2025-05-02KUNGAO XINXIN MICROELECTRONICS (JIANGSU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510061826.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The prior art fails to fully consider memory internal errors or transient errors during the initialization of the on-board chip, resulting in the inability to effectively protect the chip's failures during the initialization process and cannot meet the requirements of functional safety specifications such as ISO26262.

Method used

By designing a system that includes pre- and post-stage initialization units, the hardware initialization controller and memory can be used to achieve rapid chip startup, and three measures: reread instructions, redundant backups and verification and correction are used to provide protection for hardware permanent errors and transient errors.

Benefits of technology

It realizes fault protection during the initialization process of the chip, meets the functional safety requirements of the on-board Ethernet chip, ensures the normal start-up of the chip, and shortens the initialization time to the millisecond level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119917347A_ABST
    Figure CN119917347A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle-mounted Ethernet chip initialization storage unit fault protection method and device and a storage medium, at least one preceding-stage initialization unit and at least one post-stage initialization unit are configured, the post-stage initialization unit comprises a post-stage controller and a post-stage storage unit, the post-stage storage unit is divided into a region A and a region B, the area A is used for backing up initialization configuration of a preceding-stage memory, and the area B is used for storing general initialization configuration of a chip; through a hardware initialization method before a BootLoader stage and in combination with characteristics of different memories and a configuration effective stage, initialization configuration is reasonably distributed into the corresponding memories, and the chip starting time is shortened to a millisecond level; functional safety design of instruction rereading, redundant backup and verification correction is added, and the functional safety requirement of the vehicle-mounted chip is met. Moreover, due to the adoption of the method for realizing initialization by hardware, the modification of upper software is avoided, only the content of the hardware initialization memory needs to be configured and modified, and certain flexibility is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle-mounted chips, and in particular to a protection system, method and storage medium for a vehicle-mounted Ethernet chip initialization storage unit failure. Background Art

[0002] As the in-vehicle information system becomes more and more complex, the network transmission bandwidth is growing exponentially. Traditional communication buses such as CAN are being gradually replaced by high-bandwidth Ethernet. Similarly, the development of in-vehicle Ethernet must also comply with functional safety specifications such as ISO26262, one of which is the requirement for chip initialization. Chip initialization is the process of configuring the function-related registers in the chip after the chip is reset so that the chip can work normally. There are two ways to implement this process: software or hardware. The software method is to operate the chip registers through the CPU executing the instructions in the compiler program, which is highly flexible but time-consuming; the hardware method is to read the instructions from the memory where the configuration instructions are stored through the control unit to operate the chip registers, which is less flexible but time-consuming. The specific implementation of chip initialization is usually selected according to the actual application scenario.

[0003] In the field of automotive chips, in order to meet the chip startup time requirements, various links in the chip startup process will be optimized, but most of them are optimized in the BOOT stage, and the optimization of this stage will lead to large changes in the overall architecture, complex solutions, and more overhead; some consider using hardware configuration before BOOT to speed up initialization, but traditional hardware initialization solutions only consider improving the configuration speed and do not fully consider possible faults, such as errors in the internal storage value of the memory or transient errors during the reading process. The ISO26262 specification requires protection processing for possible faults to reduce the impact of the consequences of the faults. The design of automotive safety functions is to reduce the occurrence rate of faults and increase the fault coverage rate, so a hardware initialization startup solution that meets functional safety and design specifications is needed to ensure the smooth execution of chip startup and meet the chip startup time requirements in the automotive field. Summary of the invention

[0004] In order to solve the above problems of the existing technical solutions, the present invention provides a functional safety technology for initializing an in-vehicle Ethernet chip. More specifically, it realizes fast chip startup through a hardware initialization controller and a memory, achieving a total initialization time of milliseconds; at the same time, hardware permanent error and transient error protection are provided through three measures of rereading instructions, redundant backup and verification correction to meet the functional safety requirements of the in-vehicle Ethernet chip and solve the above technical problems.

[0005] In order to achieve the above-mentioned object, the present invention adopts the following technical scheme: a protection method for a failure of an initialization storage unit of an in-vehicle Ethernet chip, configured to include at least one front-stage initialization unit, including a front-stage controller and a front-stage memory; configured to include at least one rear-stage initialization unit, including a rear-stage controller and a rear-stage storage unit, the rear-stage storage unit is divided into two areas, area A and area B, area A is used to back up the initialization configuration of the front-stage memory, and area B is used to store the general initialization configuration of the chip;

[0006] The following steps are involved:

[0007] S1, the chip is powered on and reset is released, and the front-end controller starts initialization;

[0008] S2, the front-stage controller obtains the starting address and hardware circuit adjustment parameters, reads the content from the front-stage memory according to the starting address, obtains the check code according to the instruction format and uses the check algorithm to check it; if the check result is correctable or does not need to be corrected, the correct instruction after correction or unchanged is executed, otherwise the current instruction is marked as an error instruction sequence. Correction is performed to cover the correctable permanent errors in the storage unit; the check algorithm can use the ECC check algorithm or other algorithms with error correction function;

[0009] S3, after the current initialization configuration process is finished, the error instruction sequence that cannot be corrected during the initialization process is statistically recorded, and the next process of initializing the storage unit is started; the front-stage controller transmits the enable signal and the initialization result to the back-stage initialization unit;

[0010] S4, the post-stage controller receives the enable signal and initialization result from the pre-stage controller of the pre-stage initialization unit, analyzes the initialization result to determine whether an uncorrectable fault occurs during the execution of the pre-stage initialization, and if so, reads instructions from area A, and selects execution according to the erroneous configuration instruction sequence, rather than executing all the backup configurations, to reduce redundant processing time, and then executes from area B after execution; if not, directly starts from area B to execute the chip initialization configuration.

[0011] Further, it includes one or all of the following two: In S2, if the error is not uncorrectable after verification, the initialization instruction is executed, otherwise, the re-read instruction flow is entered. The permanent error that cannot be corrected in the previous initialization unit is covered by redundant backup.

[0012] Furthermore, in S3, after the initialization instruction is executed, the read address will jump to the next target address to read the new instruction, and then the address will be judged; if the address does not reach the maximum value, it will return to the parsing verification and correction stage; if the address reaches the maximum value, the current initialization configuration process will be ended, the error instruction sequence in the initialization process will be statistically recorded, and the next process of initializing the storage unit will be started.

[0013] Furthermore, the internal instruction format of the subsequent storage unit includes a check tag, and the subsequent controller will also execute a check correction process and reread instructions to cover the fault type.

[0014] Furthermore, in S2, the process of rereading the instruction is that the address remains unchanged, the front-stage controller re-reads the instruction, and executes the analysis and verification process, and then makes a correction and verification result judgment. If it can be corrected, the corrected initialization instruction is executed. If it fails and is less than the maximum number threshold, the process will return to the starting point of the reread instruction and re-instruct; this is repeated. When the maximum threshold is reached and the correction and verification are still unsuccessful, the reread process will exit, the initialization instruction will be executed and the current instruction will be marked as wrong.

[0015] Furthermore, the front-stage controller starts its initialization operation after receiving the reset release signal of the power-on circuit, and sends the configuration result to the configured central processor and the back-stage controller after the operation is completed; the back-stage controller starts the initialization operation after receiving the processing result of the front-stage controller, and sends the configuration result to the central processor after the operation is completed; the central processor simultaneously reads the initialization result of each Ethernet functional unit to determine whether the initialization of the on-board Ethernet chip is completed.

[0016] Further, the front-stage controller is an EFUSE controller, and the front-stage memory is an EFUSE memory; the rear-stage controller is a ROM controller, and the rear-stage storage unit is a ROM storage unit, and the ROM storage unit is divided into two areas, area A and area B, area A is used to back up the initialization configuration of the EFUSE memory, and area B is used to store the general initialization configuration of the chip;

[0017] The present invention also provides a protection device for a vehicle-mounted Ethernet chip initialization storage unit failure, comprising:

[0018] The front-stage initialization unit includes an EFUSE controller and an EFUSE memory; the EFUSE controller transmits an enable signal and an initialization result to the rear-stage initialization unit;

[0019] A post-stage initialization unit, including a ROM controller and a ROM storage unit, wherein the ROM storage unit is divided into two areas, area A and area B, area A is used to back up the initialization configuration of the EFUSE memory, and area B is used to store the general initialization configuration of the chip;

[0020] The system bus is used to connect the front-stage initialization unit, the rear-stage initialization unit, and the target chip functional unit, namely, the Ethernet functional unit; the system bus provides data interaction function between modules;

[0021] The EFUSE memory and the ROM storage unit respectively store different initialization instruction configurations of specific structures; the EFUSE controller and the ROM controller are respectively used to access the EFUSE memory and the ROM storage unit to obtain the instruction configuration, and send the configuration to the target chip function unit, i.e., the Ethernet function unit, through the system bus;

[0022] The power-on circuit is responsible for managing functions such as power supply and reset release;

[0023] Ethernet functional unit, responsible for implementing Ethernet functions such as parsing, forwarding, mirroring, etc., with built-in register module; specifically, it obtains instructions from the system bus to change the parameter values ​​of the internal register module to change the working characteristics, such as parsing the four-layer message protocol, etc.;

[0024] The central processing unit is used to access and collect initialization results and execute software operations.

[0025] Furthermore, the EFUSE controller starts its initialization operation after receiving the reset release signal of the power-on circuit, and sends the configuration result to the central processing unit and the ROM controller after the operation is completed; the ROM controller starts the initialization operation after receiving the EFUSE processing result, and sends the configuration result to the central processing unit after the operation is completed; the central processing unit reads the initialization result of each Ethernet functional unit to determine whether the initialization of the vehicle Ethernet chip is completed.

[0026] The present invention also provides a computer-readable storage medium containing a computer program, which, when executed by one or more processors, implements any of the above-mentioned methods for protecting the vehicle Ethernet chip from initialization storage unit failure.

[0027] The present invention designs a hardware initialization method before the BootLoader stage by deeply analyzing the chip initialization process, and combines the characteristics of different memories and the configuration effectiveness stage to reasonably allocate the initialization configuration to the corresponding memory, shortening the chip startup time to milliseconds. In addition, since the method of hardware initialization is adopted, the upper-layer software modification is avoided, and the required configuration only needs to modify the content of the hardware initialization memory, which provides a certain degree of flexibility.

[0028] In addition, combined with the design specifications of vehicle-mounted chips, the three specific measures of rereading instructions, redundant backup and verification correction as mentioned above are designed to cover transient and permanent faults in vehicle-mounted fault scenarios, meet the functional safety requirements of vehicle-mounted chips, and ensure the normal startup of the chip. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 A schematic diagram of the format of initialization instructions for a method for protecting a vehicle-mounted Ethernet chip from initialization storage unit failure according to the present invention;

[0030] Figure 2 A schematic diagram of a protection device for a vehicle-mounted Ethernet chip initialization storage unit failure according to the present invention;

[0031] Figure 3 This is a schematic diagram of the EFUSE initialization configuration process of the present invention;

[0032] Figure 4 It is a schematic diagram of the ROM initialization configuration flow of the present invention. DETAILED DESCRIPTION

[0033] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0034] like Figure 1 As shown, the specific instruction format stored in the initialization storage unit (EFUSE memory and ROM storage unit) of the present invention is shown, which consists of five parts: key code, operation code, address, data and check code, which represent the operation to be performed by the current instruction. The check code is calculated by splicing the first four parts by the check algorithm.

[0035] like Figure 2-4 As shown, a protection method for a vehicle Ethernet chip initialization storage unit failure is described, and a front-stage initialization unit and a rear-stage initialization unit are used as examples for description. The working principles of multiple front-stage initialization units and multiple rear-stage initialization units are similar and will not be repeated. The front-stage controller is an EFUSE controller, the front-stage memory is an EFUSE memory, the rear-stage controller is a ROM controller, and the rear-stage storage unit is a ROM storage unit. The principles of using other applicable controllers and corresponding storage units are similar and will not be repeated.

[0036] A front-stage initialization unit is configured, including an EFUSE controller and an EFUSE memory; a rear-stage initialization unit is configured, including a ROM controller and a ROM storage unit, wherein the ROM storage unit is divided into two areas, area A and area B, area A is used to back up the EFUSE initialization configuration, and area B is used to store the general initialization configuration of the chip;

[0037] The following steps are involved:

[0038] S1, the chip is powered on and reset is released, and the EFUSE controller starts initialization;

[0039] S2, the EFUSE controller obtains the starting address and hardware circuit calibration parameters, reads the content from the EFUSE memory according to the starting address, obtains the check code according to the instruction format and uses the check algorithm to check and correct it; if the check result is correctable or does not need to be corrected, the correct instruction after correction or unchanged is executed, otherwise the current instruction is marked as an error instruction sequence. Correction is performed to cover the correctable permanent errors in the storage unit; the check algorithm can use the ECC check algorithm or other algorithms with error correction function;

[0040] S3, after the current initialization configuration process is finished, the error instruction sequence in the initialization process is statistically recorded, and the next process of initializing the storage unit is started; the EFUSE controller transmits the enable signal and the initialization result to the subsequent initialization unit;

[0041] S4, the ROM controller receives the enable signal and initialization result from the EFUSE controller of the previous initialization unit, analyzes the initialization result to determine whether an uncorrectable fault occurs during the execution of the previous initialization. If so, it reads instructions from area A and selects to execute according to the configuration instruction sequence with the error, rather than executing all the backup configurations to reduce the time consumption of redundant processing. After execution, it executes from area B; if not, it directly executes the chip initialization configuration from area B. The redundancy backup is used to cover the permanent uncorrectable errors inside the previous initialization unit.

[0042] In S2, if the verification is passed, the initialization instruction is executed, otherwise, the re-read instruction process is entered. The re-read instruction process is that the address remains unchanged, the EFUSE controller re-reads the instruction, and executes the parsing, verification and correction process, and then performs the verification result judgment. If the verification and correction pass, the initialization instruction is executed. If it fails and is less than the maximum number of times, the process will return to the starting point of the re-read instruction and re-instruct; this is repeated. When the maximum threshold is reached and the verification still fails, the re-read process will be exited, the initialization instruction will be executed, and the current instruction will be marked as an error.

[0043] In S3, after the initialization instruction is executed, the read address will jump to the next target address to read the new instruction, and then the address will be judged; if the address does not reach the maximum value, it will return to the parsing and verification stage; if the address reaches the maximum value, the current initialization configuration process will be ended, the error instruction sequence in the initialization process will be statistically recorded, and the next process of initializing the storage unit will be started.

[0044] The internal instruction format of the ROM storage unit includes a verification tag, and the ROM controller will also execute a verification process and reread instructions to cover the fault type.

[0045] The EFUSE controller starts its initialization operation after receiving the reset release signal of the power-on circuit, and sends the configuration result to the configured central processor and ROM controller after the operation is completed; the ROM controller starts the initialization operation after receiving the EFUSE processing result, and sends the configuration result to the central processor after the operation is completed; the central processor simultaneously reads the initialization result of each Ethernet functional unit to determine whether the initialization of the vehicle Ethernet chip is completed.

[0046] The present invention also provides a protection device for a vehicle-mounted Ethernet chip initialization storage unit failure, comprising:

[0047] The front-stage initialization unit includes an EFUSE controller and an EFUSE memory; the EFUSE controller transmits an enable signal and an initialization result to the rear-stage initialization unit;

[0048] A post-stage initialization unit, including a ROM controller and a ROM storage unit, wherein the ROM storage unit is divided into two areas, area A and area B, area A is used to back up the EFUSE initialization configuration, and area B is used to store the general initialization configuration of the chip;

[0049] The system bus is used to connect the front-stage initialization unit, the rear-stage initialization unit and the target chip functional unit (i.e., the Ethernet functional unit); the system bus provides data interaction function between modules;

[0050] The EFUSE memory and the ROM storage unit respectively store different initialization instruction configurations of specific structures; the EFUSE controller and the ROM controller are respectively used to access the EFUSE memory and the ROM storage unit to obtain the instruction configuration, and send the configuration to the target chip function unit (i.e., the Ethernet function unit) through the system bus;

[0051] The power-on circuit is responsible for managing functions such as power supply and reset release;

[0052] Ethernet functional unit, responsible for implementing Ethernet functions, with built-in register module, which will change working characteristics according to register configuration;

[0053] The central processing unit is used to access and collect initialization results and execute software operations.

[0054] The EFUSE controller starts its initialization operation after receiving the reset release signal of the power-on circuit, and sends the configuration result to the central processing unit and the ROM controller after the operation is completed; the ROM controller starts the initialization operation after receiving the EFUSE processing result, and sends the configuration result to the central processing unit after the operation is completed; the central processing unit also reads the initialization results of each Ethernet functional unit to determine whether the initialization of the vehicle Ethernet chip is completed.

[0055] Specifically, attached Figure 2 The chip structure diagram of the hardware initialization solution of the present invention is shown, which includes a power-on circuit responsible for managing power supply and reset release functions; two initialization storage units (such as EFUSE storage unit and ROM storage unit) respectively storing different initialization instruction configurations of specific structures; two storage unit controllers (such as EFUSE controller and ROM controller) for accessing the corresponding storage unit to obtain instruction configurations, and sending the configurations to the target chip function unit through the system bus ( Figure 2 Examples are Ethernet function unit A, Ethernet function unit B, Ethernet function unit C, or fewer or more required chip modules); Ethernet function unit, responsible for implementing various Ethernet functions, with built-in register module, which will change the working characteristics according to the register configuration; system bus provides data interaction function between modules; central processing unit, used to access and collect initialization results and execute software operations. Among them, the EFUSE controller receives the reset release signal of the power-on circuit to start its initialization operation, and sends the configuration result to the central processing unit and ROM controller after the operation is completed; the ROM controller starts the initialization operation after receiving the EFUSE processing result, and sends the configuration result to the central processing unit after the operation is completed; the central processing unit will also read the initialization results of each Ethernet function unit to determine whether the initialization of the vehicle Ethernet chip is completed.

[0056] Attached Figure 3 The initialization configuration process based on EFUSE is described in detail. First, the chip is powered on and reset and released, and the EFUSE controller starts initialization, obtains the starting address and hardware circuit calibration parameters, etc., and then reads the content from the EFUSE memory according to the starting address, obtains the check code according to the instruction format, and uses a correctable check algorithm to check it. If it is judged that no correction is required or can be corrected, the unchanged or corrected initialization instruction is executed, otherwise it enters the reread instruction process. The reread instruction process is that the address remains unchanged, the EFUSE controller re-reads the instruction, and executes the parsing and correction check process, and then the check result is judged again. If the check passes, the corrected initialization instruction is executed. If it does not pass and is less than the maximum number of times, the process will return to the starting point of the reread instruction and re-instruct. Repeatedly, when the maximum threshold is reached and the check still fails, the reread process will be exited, the initialization instruction will be executed, and the current instruction will be marked as an error. After the initialization instruction is executed, the read address will jump to the next target address to read the new instruction, and then the address judgment will be performed. If the address does not reach the maximum value, it will return to the parsing correction and verification stage. Otherwise, it will end the current initialization configuration process, statistically record the error instruction sequence during the initialization process, and start the next process of initializing the storage unit.

[0057] Attached Figure 4Describe the initialization configuration process based on ROM storage units. The ROM initialization storage unit is divided into two areas, area A is used to back up the EFUSE initialization configuration, and area B is used to store the general initialization configuration of the chip. The ROM controller receives the enable signal and initialization result from the previous initialization unit, parses the initialization result to determine whether an uncorrectable fault occurs during the execution of the previous initialization. If so, it reads instructions from area A and selects to execute according to the erroneous configuration instruction sequence, rather than executing all the backup configurations, to reduce the time-consuming redundant processing. After execution, it executes from area B; if not, it directly executes the chip initialization configuration from area B. Internal instruction format of ROM storage unit and attached Figure 1 The ROM controller will also execute the verification process and reread instructions to cover the fault type, which will not be repeated here.

[0058] The present invention designs a hardware initialization method before the BootLoader stage by deeply analyzing the chip initialization process, and combines the characteristics of different memories and the configuration effectiveness stage to reasonably allocate the initialization configuration to the corresponding memory, shortening the chip startup time to milliseconds. And because the method of initialization is implemented in hardware, the upper-level software modification is avoided, and the required configuration only needs to modify the content of the hardware initialization memory, which provides a certain degree of flexibility. At the same time, combined with the design specifications of the vehicle-mounted chip, the above three reread instructions, redundant backup and verification correction measures are designed to cover fault scenarios, meet the functional safety requirements of the vehicle-mounted chip, and ensure the normal startup of the chip.

[0059] The two-level initialization storage unit of the present invention can expand the cascade startup sequence of multiple initialization storage units. The present invention is not limited to the initialization storage unit combination of EFUSE and ROM, and other storage device combinations are also possible, such as EFUSE and FLASH, ROM and RAM, etc.

[0060] The functional safety protection concept of the present invention can be implemented not only in ASIC circuits, but also in other integrated circuits such as FPGA or CPLD.

[0061] The check algorithm of the present invention exemplifies the ECC algorithm, but may also be other check algorithms with correction functions.

[0062] The present invention also provides a computer-readable storage medium containing a computer program, which, when executed by one or more processors, implements any of the above-mentioned methods for protecting the vehicle Ethernet chip from initialization storage unit failure.

[0063] The present invention designs a hardware initialization method before the BootLoader stage by deeply analyzing the chip initialization process, and combines the characteristics of different memories and the configuration effectiveness stage to reasonably allocate the initialization configuration to the corresponding memory, shortening the chip startup time to milliseconds. In addition, since the method of hardware initialization is adopted, the upper-layer software modification is avoided, and the required configuration only needs to modify the content of the hardware initialization memory, which provides a certain degree of flexibility.

[0064] In addition, combined with the design specifications of automotive chips, three measures are designed to cover fault scenarios, meet the functional safety requirements of automotive chips, and ensure the normal startup of the chip.

[0065] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.

Claims

1. A protection method for initialization storage unit failure of an in-vehicle Ethernet chip, characterized in that: The configuration includes at least one front-stage initialization unit, including a front-stage controller and a front-stage memory; the configuration includes at least one rear-stage initialization unit, including a rear-stage controller and a rear-stage storage unit, wherein the rear-stage storage unit is divided into two areas, area A and area B, area A is used to back up the initialization configuration of the front-stage memory, and area B is used to store the general initialization configuration of the chip; The following steps are involved: S1, the chip is powered on and reset is released, and the front-end controller starts initialization; S2, the front-stage controller obtains the starting address and hardware circuit adjustment parameters, reads the content from the front-stage memory according to the starting address, obtains the check code according to the instruction format and uses the check algorithm to check it; S3, after the current initialization configuration process is finished, the error instruction sequence in the initialization process is statistically recorded, and the next process of initializing the storage unit is started; the front-stage controller transmits the enable signal and the initialization result to the back-stage initialization unit; S4, the post-stage controller receives the enable signal and initialization result from the pre-stage controller of the pre-stage initialization unit, analyzes the initialization result to determine whether an uncorrectable fault occurs during the execution of the pre-stage initialization, and if so, reads instructions from area A, and selects execution according to the erroneous configuration instruction sequence, rather than executing all the backup configurations, to reduce redundant processing time, and then executes from area B after execution; if not, directly starts from area B to execute the chip initialization configuration.

2. The protection method for initialization storage unit failure of an in-vehicle Ethernet chip according to claim 1, characterized in that: Includes one or both of the following: In S2, if the verification passes, the initialization instruction is executed, otherwise, the reread instruction process is entered; In S4, a redundant backup is used to cover the permanent error that cannot be corrected inside the previous initialization unit.

3. The protection method for the vehicle Ethernet chip initialization storage unit failure according to claim 2 is characterized in that: In S3, after the initialization instruction is executed, the read address will jump to the next target address to read the new instruction, and then the address will be judged; if the address does not reach the maximum value, it will return to the parsing and verification stage; if the address reaches the maximum value, the current initialization configuration process will be ended, the error instruction sequence in the initialization process will be statistically recorded, and the next process of initializing the storage unit will be started.

4. The protection method for initialization storage unit failure of the vehicle Ethernet chip according to claim 3 is characterized in that: The internal instruction format of the post-stage storage unit includes a verification tag, and the post-stage controller will also execute a verification process and re-read instructions to cover the fault type.

5. The protection method for the vehicle Ethernet chip initialization storage unit failure according to any one of claims 1 to 4, characterized in that: In S2, the instruction rereading process is that the address remains unchanged, the front-stage controller re-reads the instruction, and executes the parsing and verification process, and then makes another verification result judgment. If the verification passes, the initialization instruction is executed. If it fails and is less than the maximum number of times, the process returns to the starting point of the reread instruction and executes again; this is repeated. When the maximum threshold is reached and the verification still fails, the rereading process will be exited, the initialization instruction will be executed and the current instruction will be marked as an error.

6. The protection method for initialization storage unit failure of the vehicle Ethernet chip according to claim 5, characterized in that: The front-stage controller starts its initialization operation after receiving the reset release signal of the power-on circuit, and sends the configuration result to the configured central processor and the back-stage controller after the operation is completed; the back-stage controller starts the initialization operation after receiving the processing result of the front-stage controller, and sends the configuration result to the central processor after the operation is completed; the central processor simultaneously reads the initialization result of each Ethernet functional unit to determine whether the initialization of the vehicle Ethernet chip is completed.

7. The protection method for initialization storage unit failure of an in-vehicle Ethernet chip according to claim 1, characterized in that: The front-stage controller is an EFUSE controller, and the front-stage memory is an EFUSE memory; the rear-stage controller is a ROM controller, and the rear-stage storage unit is a ROM storage unit. The ROM storage unit is divided into two areas, area A and area B. Area A is used to back up the initialization configuration of the EFUSE memory, and area B is used to store the general initialization configuration of the chip.

8. A protection device for a vehicle Ethernet chip initialization storage unit failure, characterized in that: include: A front-stage initialization unit, including an EFUSE controller and an EFUSE memory; The EFUSE controller transmits the enable signal and the initialization result to the subsequent initialization unit; A post-stage initialization unit, including a ROM controller and a ROM storage unit, wherein the ROM storage unit is divided into two areas, area A and area B, area A is used to back up the initialization configuration of the EFUSE memory, and area B is used to store the general initialization configuration of the chip; The system bus is used to connect the front-stage initialization unit, the rear-stage initialization unit, and the target chip functional unit, namely, the Ethernet functional unit; the system bus provides data interaction function between modules; The EFUSE memory and the ROM storage unit respectively store different initialization instruction configurations of specific structures; the EFUSE controller and the ROM controller are respectively used to access the EFUSE memory and the ROM storage unit to obtain the instruction configuration, and send the configuration to the target chip function unit, i.e., the Ethernet function unit, through the system bus; The power-on circuit is responsible for managing functions such as power supply and reset release; The Ethernet function unit is responsible for realizing the Ethernet function, and has a built-in register module; specifically, it obtains instructions from the system bus to change the parameter values ​​of the internal register module to change the working characteristics; The central processing unit is used to access and collect initialization results and execute software operations.

9. The protection device for initialization storage unit failure of the vehicle Ethernet chip according to claim 8, characterized in that: The EFUSE controller starts its initialization operation after receiving the reset release signal of the power-on circuit, and sends the configuration result to the central processing unit and the ROM controller after the operation is completed; the ROM controller starts the initialization operation after receiving the EFUSE processing result, and sends the configuration result to the central processing unit after the operation is completed; the central processing unit reads the initialization result of each Ethernet functional unit to determine whether the initialization of the vehicle Ethernet chip is completed.

10. A computer-readable storage medium containing a computer program, characterized in that: When the computer program is executed by one or more processors, the protection method for the failure of the initialization storage unit of the vehicle Ethernet chip as described in any one of claims 1 to 7 is implemented.