Electronic device mounted on vehicle, method of operating the electronic device, and storage device

By designing a storage controller in a vehicle electronic device to provide startup code according to the ECU security level, the problems of resource waste and difficult to meet ASIL requirements are solved, and resource conservation and multi-user performance improvement are achieved.

CN119953292APending Publication Date: 2025-05-09SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411470427.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-08
Filing Date
2024-10-21
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

As the number of electronic control units (ECUs) on the vehicle increases, the number of corresponding individual storage controllers also increases, resulting in waste of resources and difficulty in meeting the automotive safety integrity level (ASIL) requirements of each ECU.

Method used

An electronic device is designed in which the storage controller provides corresponding startup codes to multiple ECUs according to the security level of each ECU, reduces the number of storage controllers through a shared storage structure, improves multi-user performance, and ensures that each ECU complies with appropriate ASIL.

Benefits of technology

The shared storage structure reduces resource consumption of multiple storage controllers, improves multi-user performance for multiple ECUs, and ensures that each ECU meets the appropriate level of automotive safety integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119953292A_ABST
    Figure CN119953292A_ABST
Patent Text Reader

Abstract

An electronic device mounted on a vehicle, a method of operating the electronic device, and a storage device are provided, the method including confirming, by a storage controller, a security level corresponding to each of a plurality of electronic control units (ECUs), and providing, by the storage controller, boot codes respectively corresponding to the plurality of ECUs and stored in the first non-volatile memory to each ECU based on the security level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The inventive concept relates to an electronic device mounted on a vehicle, and more particularly, to an electronic device including a storage controller configured to provide a boot code to an electronic control unit (ECU), a method of operating the electronic device, and a storage device. Background Art

[0002] Vehicles developed in recent years are basically equipped with various electronic control units (ECUs). As the number of ECUs mounted on vehicles increases, the number of individual memory controllers corresponding to the respective ECUs also increases. Summary of the invention

[0003] The inventive concept provides an electronic device having the following structure: wherein a storage controller provides corresponding boot codes to multiple electronic control units ECU according to the security level of each ECU to improve multi-user performance for multiple ECUs, and the inventive concept provides a method for operating the electronic device.

[0004] The technical objectives of the inventive concept are not limited to the above-mentioned technical objectives, and other technical objectives not mentioned will be clearly understood by those of ordinary skill in the art from the following description.

[0005] According to one aspect of the inventive concept, a method for operating an electronic device is provided, wherein the electronic device is installed on a vehicle and includes a plurality of electronic control units (ECUs), the method comprising: confirming, by a storage controller, a security level corresponding to each of the plurality of ECUs; and providing, by the storage controller, a startup code to the plurality of ECUs based on the confirmed security level, the startup codes respectively corresponding to the plurality of ECUs and stored in a first non-volatile memory.

[0006] According to another aspect of the inventive concept, an electronic device installed on a vehicle is provided, the electronic device comprising a plurality of ECUs and a storage device shared by the plurality of ECUs, wherein the storage device comprises: a first non-volatile memory, the first non-volatile memory storing startup codes for the plurality of ECUs; and a storage controller, the storage controller being configured to: confirm a security level corresponding to each ECU in the plurality of ECUs, and provide each ECU with a corresponding startup code from the startup codes stored in the first non-volatile memory based on the confirmed security level.

[0007] According to another aspect of the inventive concept, a storage device is provided, which includes: a first non-volatile memory, wherein the first non-volatile memory stores startup codes of multiple ECUs; and a storage controller, wherein the storage controller is configured to: confirm a security level corresponding to each ECU in the multiple ECUs, and provide each ECU with a corresponding startup code among the startup codes stored in the first non-volatile memory based on the confirmed security level. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Embodiments of the inventive concept will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0009] Figure 1 is a block diagram of an electronic device according to at least one embodiment;

[0010] Figure 2A is a block diagram illustrating an electronic device installed on a vehicle according to at least one embodiment;

[0011] Figure 2B is a block diagram showing an electronic device mounted on a vehicle according to a comparative example;

[0012] Figure 3 is a flowchart of a method of operating an electronic device installed in a vehicle according to at least one embodiment;

[0013] Figure 4A and Figure 4B is a diagram for describing a startup code according to at least one embodiment;

[0014] Figure 5A and Figure 5B is a flowchart of a method of operating an electronic device according to at least one embodiment; and

[0015] Fig. 6A , Figure 6B and Figure 6C is a flowchart of a method of operating an electronic device according to at least one embodiment. DETAILED DESCRIPTION

[0016] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. In the accompanying drawings, the same reference numerals are used to denote the same elements, and repeated descriptions thereof will be omitted.

[0017] Although the terms "first", "second", "third", etc. may be used herein to describe various elements, components, regions, layers and / or sections, these elements, components, regions, layers and / or sections should not be limited by these terms. These terms are only used to distinguish one element, component, region, layer or section from another element, component, region, layer or section. Therefore, the first element, first component, first region, first layer or first section discussed below may be referred to as the second element, second component, second region, second layer or second section without departing from the scope of the present disclosure.

[0018] Further, a functional block that processes at least one function or operation (including a functional block described using terms such as "unit" and / or "controller") may be implemented in a processing circuit system such as hardware, software, and / or a combination of hardware and software. For example, more specifically, the processing circuit system may include, but is not limited to, a central processing unit (CPU), an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable gate array (FPGA), a system-on-chip (SoC), a programmable logic unit, a microprocessor, an application-specific integrated circuit (ASIC), etc. The processing circuit system may additionally include electrical components such as at least one of a transistor, a resistor, a capacitor, etc., and / or an electronic circuit including the components.

[0019] Figure 1 is a block diagram of an electronic device according to at least one embodiment.

[0020] The electronic device 10 may be mounted on a vehicle, and may include an electronic control unit (ECU) 100 and a storage device 200. The storage device 200 may include a storage controller 210 and a non-volatile memory (NVM) 220. Also, according to at least one embodiment, the ECU 100 may include an ECU controller 110 and an ECU memory 120. The ECU memory 120 may function as a buffer memory for temporarily storing data to be transmitted to and / or transmitted from the storage device 200.

[0021] ECU 100 is an electronic control device including processing circuitry configured to control the overall operation of a vehicle. In at least one embodiment, ECU 100 may collect and process measurement information from sensors to perform various functions or control vehicle systems.

[0022] For example, ECU 100 may correspond to, but is not limited to, an engine control unit, a transmission control unit, a brake control unit, an airbag control unit, a fuel control unit, an entertainment system control unit, a driving assistance system control unit, an energy management unit, a vehicle safety system control unit, etc.

[0023] The engine control unit is an ECU configured to control, improve and / or optimize the operation of the vehicle's engine, and may control, for example, fuel injection, gas flow, ignition timing, exhaust treatment and other engine elements. The transmission control unit is an ECU configured to manage and control the vehicle's transmission, and may control, for example, gear shifting, torque converter clutch control, etc. The brake control unit is configured to control the brake system, such as managing the pressure distribution required for stable braking and safety functions (e.g., anti-lock brake system (ABS) or electric power steering (ESP)). The airbag control unit is configured to trigger the airbag in the event of an accident and analyze information from sensors in the vehicle to trigger the airbag at an appropriate time point according to the intensity or direction of the accident. The fuel control unit is configured to control the fuel supply and fuel mixture ratio to improve and / or optimize fuel economy and reduce exhaust gas. The entertainment system control unit is configured to manage, for example, audio, video and navigation systems in the vehicle. The driving assistance system control unit is used as a driving assistance system in an autonomous vehicle, and may be configured to detect the surrounding environment and control the vehicle through radar, cameras, sensors, etc. Energy management devices are configured to manage batteries and control energy flow in hybrid and / or electric vehicles. Vehicle safety system control units are configured to improve vehicle safety and can detect driving environments through radar, cameras, sensors, etc.; and provide warnings to the driver and / or automatically perform safety procedures, such as reducing vehicle speed and / or shutting down the engine.

[0024] In other words, the ECU 100 may be an electronic control device dedicated to performing one or more specific functions of the vehicle.

[0025] ECU 100 may be (and / or include) processing circuitry, and thus may be implemented in software, hardware, and / or a combination of hardware and software. Moreover, in at least one embodiment, ECU 100 may be implemented as a plurality of different ECUs (e.g., Figure 2A 1 ECU 100_1 , 2 ECU 100_2 , and 3 ECU 100_3 ), and each ECU (eg, Figure 2A The first ECU 100_1 or the second ECU 100_2 or the third ECU 100_3) may be dedicated to performing a specific function.

[0026] The storage device 200 may include a storage medium for storing data according to a request from the ECU 100. As an example, the storage device 200 may include at least one of a solid state drive (SSD), an embedded memory, and a removable external memory. When the storage device 200 is an SSD, the storage device 200 may be a device that complies with the non-volatile memory express (NVMe) standard. When the storage device 200 is an embedded memory or an external memory, the storage device 200 may be a device that complies with the universal flash storage (UFS) standard or the embedded multi-media card (eMMC) standard. The ECU 100 and the storage device 200 may generate and transmit data packets according to the standard protocols adopted by them, respectively.

[0027] When the NVM 220 of the storage device 200 includes a flash memory, the flash memory may include a 2D NAND memory array or a 3D (or vertically stacked) NAND (VNAND) memory array. In another example, the storage device 200 may include various other types of non-volatile memory. For example, the storage device 200 may include a magnetic random-access memory (MRAM), a spin-transfer torque MRAM, a conductive bridging RAM (CBRAM), a ferroelectric RAM (FeRAM), a phase RAM (PRAM), a resistive RAM, and / or various other types of memory.

[0028] According to some embodiments, the ECU controller 110 and the ECU memory 120 may be implemented as separate semiconductor chips. Alternatively, according to some embodiments, the ECU controller 110 and the ECU memory 120 may be integrated on the same semiconductor chip. According to at least one embodiment, the ECU controller 110 may be any one of a plurality of modules included in an application processor, and the application processor may be implemented as a system on chip (SoC). Moreover, the ECU memory 120 may be an embedded memory provided in the application processor, or a non-volatile memory and / or memory module provided outside the application processor.

[0029] The ECU controller 110 may manage an operation of storing data (eg, write data) of the buffer 121 in the NVM 220 and / or an operation of storing data (eg, read data) of the NVM 220 in the buffer 121 .

[0030] The storage controller 210 may include an ECU interface 211, a memory interface 212, and a central processing unit (CPU) 213. The storage controller 210 may also include a flash translation layer (FTL) 214, a packet manager 215, a buffer memory 216, an error correction code (ECC) engine 217, and / or an advanced encryption standard (AES) engine 218. The storage controller 210 may also include a working memory (not shown) loaded with the FTL 214, and when the CPU 213 runs the FTL 214, operations for programming data to and reading data from the non-volatile memory may be controlled.

[0031] The ECU interface 211 is configured to send and receive data packets to and from the ECU 100. Data packets sent from the ECU 100 to the ECU interface 211 may include commands or data to be programmed to the NVM 220, and data packets sent from the ECU interface 211 to the ECU 100 may include responses to commands or data read from the NVM 220. The memory interface 212 may send data to be programmed to the NVM 220 to the NVM 220, or may receive data read from the NVM 220. The memory interface 212 may be implemented to comply with a standard protocol such as Toggle or ONFI.

[0032] The FTL 214 is configured to perform various functions such as address mapping, wear leveling, and garbage collection. The address mapping operation is an operation for converting a logical address received from the ECU 100 into a physical address for storing data in the NVM 220. Wear leveling is a technique for preventing (and / or reducing) excessive degradation of a specific block by allowing the blocks in the NVM 220 to be used uniformly, and can be implemented, for example, by a firmware technique for balancing the erase counts of physical blocks. Garbage collection is a technique for ensuring available capacity in the NVM 220 by copying valid data of an old block to a new block and then erasing the old block.

[0033] The packet manager 215 is configured to generate a packet according to a protocol of an interface negotiated with the ECU 100, or may parse various information derived from a packet received from the ECU 100. Also, the buffer memory 216 may temporarily store data to be programmed to the NVM 220 or data to be read from the NVM 220. The buffer memory 216 may be a component provided in the memory controller 210, but may also be provided outside the memory controller 210.

[0034] The ECC engine 217 is configured to detect and correct errors regarding read data read from the NVM 220. For example, the ECC engine 217 may generate parity bits regarding write data to be written to the NVM 220, and such parity bits may be stored together with the write data in the NVM 220. When reading data from the NVM 220, the ECC engine 217 may correct errors of the read data using the parity bits read from the NVM 220 together with the read data, and output the error-corrected read data.

[0035] The AES engine 218 is configured to perform at least one of an encryption operation and a decryption operation on data input to the storage controller 210 using, for example, a symmetric key algorithm.

[0036] According to at least one embodiment, when the electronic device 10 includes multiple ECUs, the storage controller 210 can check the security level corresponding to each of the multiple ECUs, and provide a startup code corresponding to the corresponding ECU to the corresponding ECU based on the security level, so that the corresponding ECU can comply with the appropriate automotive safety integrity level (ASIL) and improve multi-user performance.

[0037] Here, ASIL may refer to a risk classification system related to a functional safety standard for vehicles specified in the international standard ISO 26262. Also, the boot code may refer to a code that causes the ECU 100 to start a boot process. For example, when power is applied to the ECU 100, the ECU 100 may run the boot code to start the boot process. Also, the boot code may run a boot loader so that the boot loader loads and runs an operating system image.

[0038] Next, we will refer to Figure 2A and Figure 3 5 , the method of operating the electronic device 10 is described in more detail.

[0039] Figure 2A is a block diagram illustrating an electronic device mounted on a vehicle according to at least one embodiment. Figure 2Bis a block diagram showing an electronic device installed in a vehicle according to a comparative example. Figure 1 A description is given, and repeated descriptions may be omitted.

[0040] refer to Figure 2A , the electronic device 10 mounted on the vehicle may include a first ECU 100_1 , a second ECU 100_2 , a third ECU 100_3 , a storage device 200 , and an external storage device 500 . The storage device 200 may include a storage controller 210 , a first NVM 221 , and a second NVM 223 .

[0041] Here, the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3 may each perform a specific function of the vehicle and may perform functions different from each other. Therefore, the startup code of the first ECU 100_1, the startup code of the second ECU 100_2, and the startup code of the third ECU 100_3 may be different from each other.

[0042] Moreover, the security level may be different for each ECU, and the following description will be given under the assumption that the security level of the first ECU 100_1 is the first level, the security level of the second ECU 100_2 is the second level, and the security level of the third ECU 100_3 is the third level. Moreover, the description will be given under the assumption that the higher the security level of the ECU, the more relevant the function of the corresponding ECU is to the safety of the passengers of the vehicle. Moreover, the number of ECUs included in the electronic device 10 is not limited to three, and according to the security level, a plurality of ECUs may each correspond to one of the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3. Moreover, the number of security levels is not limited to three, and in some cases, there may be two security levels, or four or more security levels.

[0043] The storage controller 210 may check the security levels corresponding to a plurality of ECUs (e.g., the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3, respectively), and provide corresponding (or respective) boot codes (e.g., BC_Mode1, BC_Mode2, and BC_Mode3 stored in the first NVM 221 and corresponding to the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3, respectively) to the plurality of ECUs based on the security levels. The number of storage controllers 210 included in the storage device 200 is not limited to one, and a plurality of storage controllers may provide boot codes to the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3, respectively. Moreover, the number of first NVMs 221 for storing the boot codes BC_Mode1, BC_Mode2, and BC_Mode3 corresponding to the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3, respectively, is not limited to one, and a plurality of first NVMs 221 may be provided.

[0044] In other words, the at least one storage controller 210 may provide the boot codes of all ECUs in the vehicle stored in the at least one first NVM 221 to each ECU based on the security level of each ECU.

[0045] Meanwhile, a structure in which boot codes of all ECUs in a vehicle are stored in at least one first NVM 221 and one storage controller 210 provides boot codes from at least one first NVM 221 to each ECU may be referred to as a shared storage structure for a vehicle.

[0046] Here, according to some embodiments, the storage controller 210 may include a plurality of storage controllers.

[0047] According to at least one embodiment, one storage controller 210 may provide boot codes of all ECUs in the vehicle stored in at least one first NVM 221 to each ECU based on the security level of each ECU.

[0048] In other words, according to at least one embodiment, a storage controller 210 included in the electronic device 10 having a shared storage structure for a vehicle can provide the boot codes of all ECUs in the vehicle stored in at least one first NVM 221 to each ECU based on the security level of each ECU. Figure 3 6 describe in detail a method in which the storage controller 210 provides the boot codes of all ECUs in the vehicle stored in at least one first NVM 221 to each ECU based on the security level of each ECU.

[0049] Further references Figure 2B According to the comparative example, the electronic device 20 installed on the vehicle may include a first ECU 300_1, a second ECU 300_2, a third ECU 300_3, a first storage controller 410_1 corresponding to the first ECU 300_1, a second storage controller 410_2 corresponding to the second ECU 300_2, a third storage controller 410_3 corresponding to the third ECU 300_3, a first NVM 420_1 corresponding to the first ECU 300_1, a second NVM 420_2 corresponding to the second ECU 300_2, and a third NVM 420_3 corresponding to the third ECU 300_3.

[0050] In the electronic device 20 mounted on a vehicle according to the comparative example, each storage controller corresponding to each ECU independently provides a boot code to the corresponding ECU regardless of the security level of the corresponding ECU. Figure 2B , the first storage controller 410_1 provides the boot code BC1 stored in the first NVM 420_1 to the first ECU 300_1, the second storage controller 410_2 provides the boot code BC2 stored in the second NVM 420_2 to the second ECU 300_2, and the third storage controller 410_3 provides the boot code BC3 stored in the third NVM 420_3 to the third ECU 300_3.

[0051] Compared to a case where one storage controller provides a boot code to multiple ECUs, in the comparative example, since the storage controller corresponding to each ECU provides the boot code stored in each of the NVMs to each ECU, resources (e.g., power consumption or occupied space of the multiple storage controllers) may be wasted. Moreover, in the comparative example, since the storage controller corresponding to each ECU independently provides the boot code to the corresponding ECU regardless of the safety level of the corresponding ECU, each storage controller may not comply with the ASIL suitable for the corresponding ECU.

[0052] Return to reference Figure 2A , a storage controller 210 included in the electronic device 10 having a shared storage structure for a vehicle can provide the boot code of all ECUs in the vehicle stored in at least one first NVM 221 to each ECU based on the security level of each ECU. As a result, according to the inventive concept, the storage controller 210 can provide the boot code corresponding to each of the multiple ECUs based on the security level, so that each ECU complies with the appropriate ASIL. Moreover, according to the inventive concept, by reducing the resources used for multiple storage controllers (for example, the power consumption or occupied space of the multiple storage controllers) through the shared storage structure for the vehicle, the multi-user performance for the multiple ECUs can be improved.

[0053] Figure 3 is a flow chart of a method for operating an electronic device installed in a vehicle according to at least one embodiment. In detail, Figure 3 It is used to describe the operation Figure 1 and Figure 2A 10. In the following, reference will be made to Figure 1 and Figure 2A A description is given, and duplicate descriptions will be omitted.

[0054] refer to Figure 3 , the method S100 of operating the electronic device 10 may include operations S110 and S120.

[0055] In operation S110 , the storage controller 210 may query security levels respectively corresponding to a plurality of ECUs.

[0056] According to some embodiments, safety levels respectively corresponding to a plurality of ECUs may be predetermined according to ASIL.

[0057] According to the function of the ECU, the ASIL corresponding to each of the plurality of ECUs may correspond to one of ASIL A, ASIL B, ASIL C, and ASIL D. Here, ASIL A may represent the lowest requirement, and ASIL D may represent the highest requirement.

[0058] During design, multiple ECUs may be required to meet one of ASIL A, ASIL B, ASIL C, and ASIL D, and / or the safety level of the ECU may be predetermined according to the ASIL. For example, the safety level of the ECU corresponding to ASIL A may be determined as the first level, the safety level of the ECU corresponding to ASIL B or ASIL C may be determined as the second level, and the safety level of the ECU corresponding to ASIL D may be determined as the third level. Alternatively, the safety level of the ECU corresponding to ASIL A may be determined as the first level, the safety level of the ECU corresponding to ASIL B may be determined as the second level, the safety level of the ECU corresponding to ASIL C may be determined as the third level, and the safety level of the ECU corresponding to ASIL D may be determined as the fourth level.

[0059] In operation S120, the storage controller 210 may provide boot codes respectively corresponding to the plurality of ECUs and stored in the first NVM to each ECU based on the security level. A detailed description thereof will be given later with reference to FIG.

[0060] Meanwhile, the boot code may refer to a code that causes the corresponding ECU (e.g., ECU 100 and / or the first ECU 100_1 to the third ECU 100_3) to start a boot process. For example, when power is applied to the ECU 100, the ECU 100 may run the boot code to start the boot process. Moreover, the boot code may run a boot loader so that the mobile loader loads and runs an operating system image. The boot code will be described in detail with reference to FIG. 4.

[0061] Figure 4A and Figure 4B is a diagram for describing a startup code according to at least one embodiment. In detail, Figure 4A is a diagram for describing the startup code according to the overall startup, and Figure 4B is a diagram for describing the startup code for subsequent startup. Figure 1 2 and 3 , and duplicate descriptions will be omitted.

[0062] In a shared storage structure for a vehicle, at least one first NVM 221 may store boot codes of all ECUs in the vehicle, and at least one storage controller 210 may provide the boot codes stored in at least one first NVM 221 to corresponding ECUs, respectively.

[0063] refer to Figure 4A and Figure 4B According to at least one embodiment, the startup code may include driver data Driver, dynamic-link library (DLL) data DLL, application data App, kernel data Kernel, header data Header, etc.

[0064] Here, the driver data Driver may be data related to a driver, which is a software component that manages and controls the interaction between hardware and an operating system (OS), the DLL data DLL may be data related to a library of code and data that can be shared by multiple programs, the application data App may be data related to a program that performs a specific function, the kernel data Kernel may be data related to a kernel that manages and controls hardware components used to run programs, and the header data Header may be data related to a header file that allows multiple codes to share the same declarations and structures.

[0065] For example, the method of starting the ECU may include a full start and / or a subsequent start.

[0066] A full boot means that the ECU is completely shut down and then restarted, and may include a process in which the ECU is completely restarted from its initial state and all hardware and software components of the ECU are initialized. For example, a full boot may be performed when the ECU is restarted after a complete power loss or complete shutdown of the ECU.

[0067] refer to Figure 4A The storage controller 210 can provide the ECU controller 110 with the boot code of the ECU (e.g., ECU100 and / or the first ECU100_1 to the third ECU100_3) stored in the first NVM 221, and the ECU controller 110 can run the boot loader based on the boot code to load the OS image into the ECU memory 120 and run the OS image.

[0068] According to some embodiments, the boot code provided by the storage controller 210 to the ECU controller 110 during full boot may include driver data Driver, DLL data DLL, application data App, kernel data Kernel, header data Header, etc.

[0069] Subsequent startup refers to starting the ECU again after the ECU has been started at least once, and may include a process of executing a new operation and / or a process of applying an update while maintaining a previous state and configuration of the ECU.

[0070] refer to Figure 4B The storage controller 210 can provide the startup code of the ECU (e.g., ECU100 and / or the first ECU100_1 to the third ECU100_3) stored in the first NVM (e.g., NVM220 and / or the first NVM221) to the ECU controller 110, and the ECU controller 110 can run the boot loader based on the startup code to restart the configuration, data or operation of the previous state on the ECU memory 120.

[0071] According to some embodiments, the boot code provided by the memory controller 210 to the ECU controller 110 during a subsequent boot may include kernel data Kernel.

[0072] Figure 5A and Figure 5B is a flow chart of a method for operating an electronic device according to at least one embodiment. In detail, Figure 5A and Figure 5B is used to describe in more detail Figure 3 Flow chart of an example of operation S110. Figures 1 to 4B A description is given, and duplicate descriptions will be omitted.

[0073] refer to Figure 5Aand Figure 5B , Figure 3 Operation S110 may include operation S110a or operation S110b.

[0074] refer to Figure 1 and Figure 5A , operation S110a may include operations S111a and S113a.

[0075] In operation S111a, the storage controller 210 may receive a startup request for the ECU 100. For example, when power is applied to the ECU 100, the ECU controller 110 may provide the storage controller 210 with the startup request for the ECU 100.

[0076] In operation S113a, the storage controller 210 may query the safety level of the ECU 100 included in the received start request in response to receiving the start request. Thereafter, the method may proceed to operation S120. According to some embodiments, the safety level of the ECU 100 may be predetermined according to the ASIL.

[0077] refer to Figure 2A and Figure 5B , operation S110b may include operations S111b and S113b.

[0078] In operation S111b, the storage controller 210 may receive a boot code of the ECU stored in the first NVM 221. For example, in response to a boot request for the first ECU 100_1, the storage controller 210 may receive a boot code BC_Mode1 stored in the first NVM 221 corresponding to the first ECU 100_1.

[0079] In operation S113b, the storage controller 210 may query the security level of the ECU included in the received boot code in response to receiving the boot code. Thereafter, the method may proceed to operation S120. For example, the storage controller 210 may query the security level of the first ECU 100_1, which is included in the boot code BC_Mode1 and corresponds to the first ECU 100_1.

[0080] According to some embodiments, the safety level of the first ECU 100_1 may be predetermined according to the ASIL.

[0081] Fig. 6A , Figure 6B and Figure 6C is a flow chart of a method for operating an electronic device according to at least one embodiment. In detail, Fig. 6A , Figure 6B and Figure 6C is used to describe in more detail Figure 3 Flow chart of an example of operation S120. Figure 1 A description is given up to FIG. 5 , and duplicate descriptions will be omitted.

[0082] refer to Fig. 6A , Figure 6B and Figure 6C , Figure 3 Operation S120 may include operation S120a, operation S120b, or operation S120c.

[0083] According to at least one embodiment, at least one storage controller 210 included in the electronic device 10 having a shared storage structure for a vehicle can provide the boot code of all ECUs in the vehicle stored in at least one first NVM 221 to each ECU based on the security level of each ECU. The following description will be given under the assumption that the security level of the first ECU 100_1 is the first level, the security level of the second ECU 100_2 is the second level, and the security level of the third ECU 100_3 is the third level. Moreover, the description will be given under the assumption that the higher the security level of the ECU, the more relevant the function of the corresponding ECU is to the safety of the passengers of the vehicle. Moreover, as described above, the number and security level of the ECUs included in the electronic device 10 are not limited to three, and according to the security level, the plurality of ECUs may each correspond to one of the first ECU 100_1, the second ECU 100_2, and the third ECU 100_3.

[0084] refer to Figure 2A and Fig. 6A In operation S120a, when the security level of the first ECU 100_1 is the first level, the storage controller 210 may provide the first boot code BC_Mode1 stored in the first NVM 221 and corresponding to the first ECU 100_1 to the first ECU 100_1.

[0085] For example, since the security level of the first ECU 100_1 is the first level (the lowest level thereof), the storage controller 210 may provide the first boot code BC_Mode1 stored in the first NVM 221 and corresponding to the first ECU 100_1 without comparison.

[0086] refer to Figure 2A and Figure 6B , operation S120b may include operations S121b and S123b.

[0087] In operation S121b, when the security level of the second ECU 100_2 is the second level, the storage controller 210 may compare the second boot code BC_Mode2 stored in the first NVM 221 and corresponding to the second ECU 100_2 with the third boot code VBC_Mode2 stored in the second NVM 223. Here, the third boot code VBC_Mode2 stored in the second NVM 223 may correspond to the second ECU 100_2.

[0088] For example, the second NVM 223 isolated from the first NVM 221 may store an additional boot code corresponding to the corresponding ECU for comparison with the boot code of the ECU stored in the first NVM 221 .

[0089] According to some embodiments, when the security level of the second ECU 100_2 is the second level, the storage controller 210 may compare the second boot code BC_Mode2 stored in the first NVM 221 and corresponding to the second ECU 100_2 with the third boot code VBC_Mode2 stored in the second NVM 223. For example, a method for verifying the data integrity of the second boot code BC_Mode2 by comparing the second boot code BC_Mode2 with the third boot code VBC_Mode2 may include a checksum method, a cyclic redundancy check (CRC) method, etc., and through such a verification method, falsification or alteration of data may be confirmed. Alternatively, in order to compare the second boot code BC_Mode2 with the third boot code VBC_Mode2, a signature of the second boot code BC_Mode2 and a signature of the third boot code VBC_Mode2 may be generated and stored by using a hash value of the second boot code BC_Mode2 and a hash value of the third boot code VBC_Mode2 during booting, and then data integrity and data falsification or alteration may be confirmed by comparing the signature of the second boot code BC_Mode2 with the signature of the third boot code VBC_Mode2. Moreover, the method of comparing the second boot code BC_Mode2 and the third boot code VBC_Mode2 is not limited to signature comparison using checksum, CRC, and hash value, and various other methods may be used.

[0090] In operation S123b, the storage controller 210 may provide the second boot code BC_Mode2 to the second ECU 100_2 based on a result of comparing the third boot code VBC_Mode2 with the second boot code BC_Mode2.

[0091] For example, the storage controller 210 may determine whether a boot process or a boot operation of the second ECU 100_2 may be normally performed based on a difference between the second boot code BC_Mode2 and the third boot code VBC_Mode2.

[0092] When determining that the boot process or boot operation of the second ECU 100_2 is to be normally performed, the storage controller 210 may provide the second boot code BC_Mode2 to the second ECU 100_2.

[0093] refer to Figure 2A and Figure 6C , operation S120c may include operations S121c and S123c.

[0094] In operation S121c, when the security level of the third ECU 100_3 is the third level, the storage controller 210 may compare the fourth boot code BC_Mode3 stored in the first NVM 221 and corresponding to the third ECU 100_3 with the fifth boot code VBC_Mode3 stored in the external storage device 500. Here, the fifth boot code VBC_Mode3 stored in the external storage device 500 may correspond to the third ECU 100_3.

[0095] For example, the external storage device 500 isolated from the first NVM 221 may store an additional boot code corresponding to the corresponding ECU for comparison with the boot code of the ECU stored in the first NVM 221 .

[0096] According to some embodiments, when the security level of the third ECU 100_3 is the third level, the storage controller 210 may compare the fourth boot code BC_Mode3 stored in the first NVM 221 and corresponding to the third ECU 100_3 with the fifth boot code VBC_Mode3 stored in the external storage device 500. For example, a method of verifying the data integrity of the fourth boot code BC_Mode3 by comparing the fourth boot code BC_Mode3 with the fifth boot code VBC_Mode3 may include a checksum method, a cyclic redundancy check (CRC) method, etc.; and, through such a verification method, falsification or alteration of data may be confirmed. Alternatively, in order to compare the fourth boot code BC_Mode3 with the fifth boot code VBC_Mode3, a signature of the fourth boot code BC_Mode3 and a signature of the fifth boot code VBC_Mode3 may be generated and stored by using a hash value of the fourth boot code BC_Mode3 and a hash value of the fifth boot code VBC_Mode3 during booting, and then the data integrity and falsification or alteration of data may be confirmed by comparing the signature of the fourth boot code BC_Mode3 with the signature of the fifth boot code VBC_Mode3. Also, the method of comparing the fourth boot code BC_Mode3 with the fifth boot code VBC_Mode3 is not limited to signature comparison using checksum, CRC, and hash value, and various other methods may be employed.

[0097] In operation S123c, the storage controller 210 may provide the fourth boot code BC_Mode3 to the third ECU 100_3 based on a result of comparing the fifth boot code VBC_Mode3 with the fourth boot code BC_Mode3.

[0098] For example, the storage controller 210 may determine whether the boot process or boot operation of the third ECU 100_3 may be normally performed based on the difference between the fifth boot code VBC_Mode3 and the fourth boot code BC_Mode3.

[0099] When it is determined that the boot process or boot operation of the third ECU 100_3 is to be normally performed, the storage controller 210 may provide the fourth boot code BC_Mode3 to the third ECU 100_3.

[0100] According to the inventive concept, the storage controller 210 can provide boot codes corresponding to multiple ECUs respectively to each ECU based on the safety level, so that each ECU complies with the appropriate ASIL. In addition, according to the inventive concept, the resources used for multiple storage controllers (e.g., power consumption or occupied space of multiple storage controllers) are reduced through a shared storage structure for a vehicle, and the multi-user performance for multiple ECUs can be improved.

[0101] While the inventive concept has been particularly shown and described with reference to embodiments thereof, it will be understood that various changes in form and details may be made therein without departing from the technical spirit and scope of the appended claims.

Claims

1. A method for operating an electronic device, the electronic device being mounted on a vehicle and comprising a plurality of electronic control units ECU, the method comprising: confirming, by the storage controller, a security level corresponding to each of the plurality of ECUs; as well as The storage controller provides the plurality of ECUs with boot codes based on the confirmed security level, and the boot codes correspond to the plurality of ECUs respectively and are stored in the first nonvolatile memory.

2. The method according to claim 1, wherein: The providing the startup code to the plurality of ECUs comprises: when the security level of a first ECU among the plurality of ECUs is the first level, The storage controller provides a first startup code to the first ECU, The first startup code is stored in the first non-volatile memory and corresponds to the first ECU.

3. The method according to claim 1, wherein: The providing the startup code to the plurality of ECUs comprises: when the security level of a second ECU among the plurality of ECUs is the second level, comparing, by the storage controller, a second boot code stored in the first nonvolatile memory and corresponding to the second ECU, with a third boot code stored in the second nonvolatile memory; and The second boot code is provided to the second ECU by the memory controller based on a result of comparing the second boot code with the third boot code.

4. The method according to claim 1, wherein: The providing the startup code to the plurality of ECUs comprises: when the security level of a third ECU among the plurality of ECUs is the third level, comparing, by the storage controller, a fourth startup code stored in the first nonvolatile memory and corresponding to the third ECU, with a fifth startup code stored in an external storage device; and The fourth startup code is provided to the third ECU by the memory controller based on a result of comparing the fourth startup code with the fifth startup code.

5. The method according to claim 1, wherein: A security level corresponding to each of the plurality of ECUs is predetermined based on a vehicle safety integrity level.

6. The method according to claim 1, wherein: The confirming of the security level by the storage controller includes: receiving, by the storage controller, a request to start an ECU among the plurality of ECUs, and The storage controller confirms a security level of the one ECU included in the activation request.

7. The method according to claim 1, wherein: The confirming of the security level by the storage controller includes: receiving, by the storage controller, a boot code of one of the plurality of ECUs, and The security level of the one ECU included in the received boot code is confirmed by the storage controller based on the boot code stored in the first nonvolatile memory.

8. An electronic device mounted on a vehicle, the electronic device comprising: Multiple electronic control units ECU; as well as a storage device, the storage device being shared by the plurality of ECUs, Wherein, the storage device comprises a first non-volatile memory storing startup codes for the plurality of ECUs; as well as A storage controller, wherein the storage controller is configured to: A security level corresponding to each of the plurality of ECUs is confirmed, and a corresponding boot code among the boot codes stored in the first nonvolatile memory is provided to each ECU based on the confirmed security level.

9. The electronic device according to claim 8, wherein: The storage controller is configured to, when a security level of a first ECU among the plurality of ECUs is a first level, A first boot code corresponding to the first ECU among the boot codes stored in the first nonvolatile memory is provided to the first ECU as the corresponding boot code.

10. The electronic device according to claim 8, wherein: The storage controller is configured to, when a security level of a second ECU among the plurality of ECUs is a second level, comparing a second startup code corresponding to the second ECU among the startup codes stored in the first nonvolatile memory with a third startup code stored in the second nonvolatile memory, and Based on a result of comparing the second startup code with the third startup code, the second startup code is provided to the second ECU as the corresponding startup code.

11. The electronic device according to claim 8, wherein: The storage controller is configured to, when a security level of a third ECU among the plurality of ECUs is a third level, comparing a fourth startup code corresponding to the third ECU among the startup codes stored in the first nonvolatile memory with a fifth startup code stored in an external storage device, and Based on a result of comparing the fourth startup code with the fifth startup code, the fourth startup code is provided to the third ECU as the corresponding startup code.

12. The electronic device according to claim 8, wherein: A security level corresponding to each of the plurality of ECUs is predetermined based on a vehicle safety integrity level.

13. The electronic device according to claim 8, wherein: The storage controller is configured to: receiving a start request for one of the plurality of ECUs, and A security level of the one ECU included in the activation request is confirmed.

14. The electronic device according to claim 8, wherein: The storage controller is configured to: receiving a startup code corresponding to one of the plurality of ECUs, and A security level of the one ECU included in the received boot code is confirmed based on the boot code stored in the first nonvolatile memory.

15. A storage device, comprising: A first non-volatile memory storing startup codes of a plurality of electronic control units ECU; as well as A storage controller, wherein the storage controller is configured to: confirming a security level respectively corresponding to each of the plurality of ECUs, and A corresponding boot code among the boot codes stored in the first nonvolatile memory is provided to each ECU based on the confirmed security level.

16. The storage device according to claim 15, wherein: The storage controller is configured to, when the security level of a first ECU among the plurality of ECUs is the first level, A first boot code corresponding to the first ECU among the boot codes stored in the first nonvolatile memory is provided to the first ECU as the corresponding boot code.

17. The storage device according to claim 15, wherein: The storage controller is configured to, when a security level of a second ECU among the plurality of ECUs is a second level, comparing a second startup code corresponding to the second ECU among the startup codes stored in the first nonvolatile memory with a third startup code stored in the second nonvolatile memory, and Based on a result of comparing the second startup code with the third startup code, the second startup code is provided to the second ECU as the corresponding startup code.

18. The storage device according to claim 15, wherein: The storage controller is configured to, when a security level of a third ECU among the plurality of ECUs is a third level, comparing a fourth startup code corresponding to the third ECU among the startup codes stored in the first nonvolatile memory with a fifth startup code stored in an external storage device, and Based on a result of comparing the fourth startup code with the fifth startup code, the fourth startup code is provided to the third ECU as the corresponding startup code.

19. The storage device according to claim 15, wherein: A security level corresponding to each of the plurality of ECUs is predetermined based on a vehicle safety integrity level.

20. The storage device according to claim 15, wherein: The storage controller is configured to: receiving a startup code corresponding to one of the plurality of ECUs, and A security level of the one ECU included in the received boot code is confirmed based on the boot code stored in the first nonvolatile memory.