Method and apparatus for implementing security diagnostics
By implementing the hardware security diagnostic engine (HSDE) circuit system in the processor, identifying and using idle modules for diagnostic tests, the problems of diagnostic test delay and inefficiency in the prior art are solved, and efficient and safe running time diagnosis is achieved.
Patent Information
- Application Number
- CN202411528812.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-14
- Filing Date
- 2024-10-30
- Publication Date
- 2025-05-16
AI Technical Summary
Existing processors have problems with latency, power consumption, and complexity when performing diagnostic tests during runtime, especially inefficient in determining active and idle modules.
Design a hardware security diagnostic engine (HSDE) circuit system to avoid multi-layer data traversal across the OSI model by identifying the signal chain used by the application and running diagnostic tests when the module is idle.
Implement time, cost and power efficient application context-aware diagnostic tests to ensure safe and execute at runtime, reducing software complexity and latency.
Smart Images

Figure CN120012172A_ABST
Abstract
Description
Technical Field
[0001] The present description relates generally to processors and, more particularly, to methods and apparatus for implementing security diagnostics. Background Art
[0002] The architecture of a processor can be described as a group of modules. In this architecture, the processor performs operations by sending electrical signals to one or more modules in the group. A given processor may include a variety of modules. For example, the modules may differ in cost, complexity, performance, functionality, and other characteristics. Some industries may use diagnostic tests to evaluate whether a processor meets performance and / or safety standards. In general, diagnostic tests include providing inputs to a sequence of modules and comparing the outputs of the sequence with expected values. Summary of the invention
[0003] For methods and devices for implementing security diagnostics, an example device includes an interface circuit system and a diagnostic circuit system, wherein the diagnostic circuit system is configured to: determine a set of signal chains that can be used by an application, the signal chains in the set including an ordered sequence of one or more circuit modules; identify a first signal chain used by the application from the set; and run a diagnostic test on the first signal chain in response to determining that a circuit module in the first signal chain is idle. BRIEF DESCRIPTION OF THE DRAWINGS
[0004] Figure 1 is a block diagram of an example environment including a processor and an application.
[0005] Figure 2 for Figure 1 A block diagram of an example implementation of a Hardware Safety Diagnostics Engine.
[0006] Figure 3A for Figure 1 A block diagram of an example implementation of a system timer for .
[0007] Figure 3B for Figure 2 208.
[0008] Figure 4 is a block diagram of an example implementation of a signal chain.
[0009] Figure 5 To indicate that you can use Figure 1 A flowchart of example operations executed, instantiated, and / or performed by an example programmable circuit system implementation of a hardware security diagnostic engine.
[0010] Figure 6A flowchart representing example machine readable instructions and / or example operations that may be executed, instantiated, and / or performed using an example programmable circuit system to diagnose a selected signal chain, such as in conjunction with Figure 5 Discussed.
[0011] Figure 7 To contain is structured to execute, instantiate and / or perform Figure 5 and 6 Example machine readable instructions and / or example operations to implement Figure 2 A block diagram of an example processing platform of a programmable circuit system of an HSDE circuit system.
[0012] The same reference numbers or other reference designators are used in the drawings to indicate the same or similar features (functionally and / or structurally). DETAILED DESCRIPTION
[0013] The drawings are not necessarily to scale. In general, the same reference numerals in one or more of the drawings and the specification refer to the same or similar parts. Although the drawings show regions with clear lines and boundaries, some or all of these lines and / or boundaries may be idealized. In practice, boundaries and / or lines may be unobservable, mixed, and / or irregular.
[0014] Diagnostic tests for processors are often implemented in software. For example, an application may contain machine-readable instructions (e.g., code) that provide input values to a processor, request output values, and compare the outputs to expected values. The execution of these software-driven tests requires data to traverse multiple layers of the Open Systems Interconnection (OSI) model. This data traversal adds latency, which adversely affects the performance of the application while the test is running. This latency can become a compounding issue when diagnostic tests are performed during both the boot-up period (e.g., the period when the device is turned on and connected to the system) and run-time (e.g., the period when the processor is executing the application).
[0015] To perform software-based diagnostics at run time, the application implementing the test can request to know which modules the processor is currently utilizing and which modules are currently idle. Implementing this type of logic may: increase the complexity of the software, increase the size of the code base, increase the duration of the test cycle, and increase the power consumption of the processor.
[0016] In some instances, an application running a test software-based diagnostic may not be able to determine which modules are active and which modules are idle during runtime. In such instances, software-based diagnostic tests may blindly test all modules in the processor for safety, since it is unclear which modules are being used at runtime. These diagnostic tests are inefficient and can introduce additional latency by testing unused modules.
[0017] The example methods, devices, and systems described herein implement a technique for performing diagnostic tests that are application context-aware, time, cost, and power efficient, software agnostic, help ensure safety, and can be performed at run time. An example hardware safety diagnostic engine (HSDE) circuit system is a hardware module implemented within a processor according to the teachings of the present disclosure. The example HSDE circuit system identifies which diagnostic tests may be useful at run time based on the modules present in the processor. The HSDE circuit system also keeps track of which modules are utilized by the application during run time. If within a user-defined test window, the HSDE identifies a collection of modules that: a) can be analyzed using diagnostic tests and b) were previously used by the application but are currently idle, then the HSDE circuit system will initiate diagnostic tests. If time permits, the HSDE circuit system can complete the diagnostic tests and provide the results to the application. Alternatively, if a time-critical application is interrupted to reclaim one of the modules before the diagnostic test is completed, the HSDE circuit system can abandon the previous test and initiate a new diagnostic test for other modules that are currently idle. Alternatively, if the application requests access to the module but is willing to wait for a period of time, the HSDE circuitry may complete the current diagnostic test before returning control of the module to the application.
[0018] Advantageously, the example HSDE can implement diagnostic tests in hardware and does not require assistance or coordination from a software program. Thus, by avoiding data traversal across multiple layers of the OSI model, the HSDE exhibits less latency, power consumption, and complexity than software-based diagnostic tests.
[0019] Figure 1 1 is a block diagram of an example environment 100 including an example processor 102. The example processor 102 includes an example application 104, an example system timer circuitry 106, an example HSDE circuitry 108, an example analog-to-digital converter (ADC) 110A, an example digital-to-analog converter (DAC) 110B, an example programmable gain amplifier (PGA) 110C, an example comparator (COMP) 110D, and an example reference voltage (VREF) circuitry 112. The ADC 110A, DAC 110B, PGA 110C, and COMP 110D may be collectively referred to as an example module 110. Although Figure 1 Processor 102 is depicted as including HSDE 108, module 110, and VREF circuitry 112, but in some examples, one or more of these elements may be partially or completely external to processor 102. For example, in some examples, HSDE 108, module 110, and VREF circuitry 112 may be separate from and coupled to processor 102.
[0020] Figure 1 The example processor 102 performs operations based on the application 104. The processor 102 can be implemented by any form of programmable circuit system. Examples of programmable circuit systems include, but are not limited to, programmable microprocessors, field programmable gate arrays (FPGAs) that can instantiate instructions, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), XPUs, or microcontrollers and integrated circuits, such as application-specific integrated circuits (ASICs). In some examples, the processor 102 may not only include a processor, for example, the processor 102 may include multiple processing cores.
[0021] Figure 1 The example application 104 represents machine readable instructions that cause one or more of the modules 110 within the processor 102 to perform operations in a logical sequence. The application 104 can implement any type of program and provide any kind of functionality. As used herein, the period during which the application 104 causes the modules 110 to perform operations can be referred to as a runtime. In some examples, the machine readable instructions that implement the application 104 are stored in the same device that implements the processor 102. In other examples, the machine readable instructions are stored separately from the device that implements the processor 102. Figure 1 The example environment 100 includes one example of application 104. In other examples, a different number of applications communicate to cause processor 102 to perform operations.
[0022] The example system timer circuitry 106 generates a series of clock signals that can be utilized globally throughout the processor 102. Figure 1 In the example of HSDE circuit system 108 and module 110, one or more of the global clock signals can be used to coordinate and / or synchronize operations. Any type of oscillator or other clock generation circuit can be used to implement the system timer circuit system 106. Figure 2 System timer circuitry 106 is discussed further. In some examples, the global clock signals may be collectively referred to as a global time bus.
[0023] Figure 1The example HSDE circuit system 108 runs diagnostic tests on modules 110 according to the teachings of the present disclosure. To do so, the HSDE circuit system 108 identifies a signal chain that is ready for diagnostic testing, provides a value in a control input signal to the first module in the signal chain, and obtains a value from a data signal output from the last module in the signal chain. As used herein, a signal chain refers to an ordered sequence of one or more modules 110 whose performance can be analyzed using a diagnostic test. Figure 4 Signal chains are discussed further. In some examples, HSDE circuitry may be referred to as diagnostic circuitry.
[0024] After providing the value in the control input signal, the HSDE circuit system 108 compares the value from the obtained data signal to the expected value. If the obtained data value matches the expected value, then the HSDE circuit system 108 notifies the application that the signal chain passed the diagnostic test. Alternatively, if the obtained data value does not match the expected value, then the HSDE circuit system 108 notifies the application that the signal chain failed the diagnostic test. In some instances, the HSDE circuit system 108 instructs the application to abort a set of operations. The HSDE circuit system 108 may provide an abort instruction in instances where the signal chain failed the diagnostic test and the failure indicates a safety issue. Figure 2 The HSDE circuitry 108 is discussed further.
[0025] Figure 1 The modules 110 are circuit components within the processor 102. The circuit components of the modules 110 may be reusable circuit components, such as peripheral components, RF transmit or receive components, analog modules, digital modules, and / or software modules. During runtime, some modules (e.g., ADC 110A and PGA 110C) may perform operations based on input signals provided by the application 104, while different modules (e.g., DAC 110B and COMP 110D) may simultaneously perform operations based on control input signals from the HSDE circuit system 108. The processor 102 may implement any number of modules. For example, Figure 1 Four modules 110 are shown. Figure 1 The example also depicts a module 110 that performs analog functions. In some examples, the module 110 includes circuits that execute machine-readable instructions to implement digital logic. These modules may be referred to as intellectual property (IP) cores.
[0026] exist Figure 1 In the example of , a given module (eg, ADC 110A) receives control input signals from HSDE circuitry 108 and outputs data signals to HSDE circuitry 108, as discussed above. The corresponding module 110 also provides enable signals, idle signals, and activation request signals to HSDE circuitry 108.
[0027] The enable signal generated by the module provides a binary indication of when the module is performing an operation for application 104. For example, a high supply voltage in the enable signal of ADC 110A may indicate that ADC 110A is currently being used by application 104, while a low supply voltage in the enable signal may indicate that ADC 110A is not currently being used by application 104.
[0028] exist Figure 1 In the example of , the idle signal generated by the module is the inverse of the enable signal. Figure 1 The idle signal of ADC 110A provides a binary indication of when the module is not performing operations for application 104. For example, a high supply voltage in the idle signal of ADC 110A may indicate that ADC 110A is not currently being used by application 104, while a low supply voltage in the idle signal may indicate that ADC 110A is being used by application 104 (e.g., busy). In instances where processor 102 communicates with multiple applications, the idle signal may provide a binary indication of when the corresponding module is not performing operations for any of the multiple applications. In some instances, the enable signal line and the idle signal line for each module 110 may be combined into a single line. In these instances, the combined single line may indicate whether the corresponding module is performing operations for application 104.
[0029] Figure 1 The example VREF circuit system 112 generates a reference voltage that can be used by one or more of the modules 110 to perform operations. The VREF circuit system 112 can generate any number of reference signals at any voltage. Figure 1 In the example of FIG. 1 , VREF circuitry 112 provides three different reference voltages to ADC 110A, DAC 110B, and COMP 110D. In other examples, VREF circuitry 112 may provide different values and / or be connected to different modules in module 110 .
[0030] Example environment 100 illustrates how application 104 may initiate execution of a function and receive updates about the safety and performance of the function throughout runtime. Advantageously, HSDE circuitry 108 implements diagnostic tests independently of application 104 or any other software program. Thus, the decision to run a diagnostic test and subsequent cycles during which modules in the signal chain are unavailable to other applications occur in example processor 102 with less latency than software-based diagnostic tests where data traverses multiple OSI layers to perform similar functions.
[0031] Figure 2 For performing diagnostic tests Figure 1108. A block diagram of an example implementation of the HSDE circuit system 108. Figure 2 The HSDE circuit system 108 may be instantiated (e.g., an instance of, causing to exist for any length of time, implementation, implementation, etc.) by (i) an application specific integrated circuit (ASIC) and / or (ii) a field programmable gate array (FPGA) structured and / or configured to perform operations. It should be understood that Figure 2 Some or all of the circuitry may thus be instantiated at the same or different times. Figure 2 Some or all of the circuitry of may be instantiated, for example, in one or more threads that execute in parallel on hardware and / or serially on hardware. Figure 2 The example HSDE circuit system 108 includes an example control circuit system 202, an example decoder circuit system 204, an example look-up table (LUT) 205, an example module availability register 206, an example rate determiner circuit system 208, an example diagnostic cycle register 210, an example strategy register 212, an example comparison circuit system 214 and an example abort register 216.
[0032] Figure 2 The control circuit system 202 of the example determines when to perform diagnostic tests, initiates testing of the signal chain, determines when to stop testing, and determines what information should be reported to the application 104. To do so, the control circuit system 202 receives an idle signal from the module 110, receives an activation request signal from the module 110, receives internal signals from the decoder circuit 204 and the rate determiner circuit system 208, and accesses data stored in the strategy register 212 and the abort register 216. The control circuit system 202 also outputs control input signals to the module 110 and configures the comparison circuit system 214 to perform operations. In some examples, the control circuit system 202 implements a state machine to manage the relationship between multiple input signals and output signals. In some examples, the control circuit system 202 is instantiated by a programmable circuit system configured to perform operations, such as those performed by Figure 5 and 6 One or more flowcharts represent operations.
[0033] If signal chains are defined, then control circuitry 202 may only consider signal chains used for diagnostic testing. Figure 2 The example decoder circuit system 204 defines a signal chain according to the teachings of the present disclosure. As used herein, a defined signal chain refers to a signal chain that has been used at least once by the application 104 during runtime.
[0034] To determine which signal chains should be qualified, decoder circuitry 204 first uses LUT 205 and module availability register 206 to determine which signal chains can be qualified. Figure 1100. LUT 205 refers to a data structure in the memory of HSDE circuit system 108 that contains a collection (e.g., a list) of signal chains. HSDE 108 can be configured to maintain the list of signal chains in a dynamic manner at run time based on the use of modules 110 in application 104. That is, LUT 205 stores a plurality of entries, where each entry is a different ordered sequence of modules that can be tested on the device. LUT 205 can be implemented as a predetermined static data structure that includes signal chains with modules that are not implemented in processor 102. In the examples described herein, application 104 runs on processor 102 and is therefore limited to using signal chains where the reference module is in Figure 1 100 (eg, implemented in or connected to processor 102).
[0035] Figure 2 The instance module availability register 206 refers to a data structure in memory that describes Figure 1 The decoder circuitry 204 uses the module availability register 206 to remove signal chains containing modules that are not in the processor 102 from qualifying consideration.
[0036] For example, suppose Figure 1 The environment 100 only includes ADCs, DACs, and comparators. In this example, the decoder circuit system 204 may identify the signal chains [ADC+DAC] and [DAC+COMP] within the LUT 205 as potential candidates for qualification. Because the ADC produces digital outputs and the comparator accepts analog inputs, the LUT 205 does not include the [ADC+COMP] signal chain. Therefore, this ordered sequence of modules is not operational, will not be used by the application 104, and does not need to be tested. If the environment 100 then integrates a PGA, the decoder circuit system 204 will consider the signal chains [ADC+DAC], [DAC+COMP], and [ADC+DAC+PGA] as candidates for qualification. However, the LUT 205 may contain all of the aforementioned signal chains as well as use Figure 1 205, regardless of whether the environment 100 ever integrates a PGA. Therefore, the decoder circuit system 204 can use the module availability register 206 to determine which entries within the LUT 205 should currently be considered for qualification. In some examples, the decoder circuit system 204 evaluates the module availability register 206 once per boot cycle to check for the addition or removal of modules from the environment 100.
[0037] Decoder circuitry 204 defines only some of the signal chains from a subset of LUT 205 entries identified using module availability register 206. Specifically, decoder circuitry 204 tracks which modules have been enabled by application 104 (e.g., which modules have been utilized by application 104, as indicated by a high supply voltage in an enable signal) at least once. Decoder circuitry 204 defines signal chains in which each module in an ordered sequence has been enabled at least once. This definition is beneficial because signal chains that have been used at least once by application 104 are likely to be used again by application 104. Therefore, the performance and safety of the signal chains should be analyzed using diagnostic tests. In some examples, decoder circuitry 204 is instantiated by programmable circuitry configured to perform operations, such as those performed by Figure 5 and 6 One or more flowcharts represent operations.
[0038] In some applications, providing control circuit system 202 with unfettered authority to identify defined signal chains ready for testing and initiate diagnostic testing may result in inefficient use of computing resources (e.g., module 110). Figure 2 An example rate determiner circuit system 208 provides a diagnostic trigger signal that limits the functionality of control circuit system 202. In some examples, a high supply voltage in the diagnostic trigger signal enables control circuit system 202 to identify the signal chain and initiate diagnostic testing, while a low supply voltage in the diagnostic trigger signal prevents control circuit system 202 from performing these operations. In some examples, rate determiner circuit system 208 is instantiated by programmable circuit system configured to perform operations such as those performed by Figure 5 and 6 One or more flowcharts represent operations.
[0039] The example rate determiner circuitry 208 generates diagnostic triggers using both the global clock signal from the system timer circuitry 106 and the diagnostic period register 210. The example diagnostic period register 210 stores configuration data that informs the rate determiner circuitry 208 of the frequency at which the diagnostic trigger signal should switch between the high supply voltage and the low supply voltage (e.g., the frequency at which the control circuitry 202 switches between enabled and disabled). Advantageously, the frequency information stored in the diagnostic period register 210 can be set by a user and / or application 104. Thus, the user and / or application 104 can balance the utilization of the module 110 between diagnostic testing and run-time performance by changing the frequency at which the control circuitry 202 is enabled. In combination Figure 3B Rate determiner circuitry 208 is discussed further.
[0040] In the examples described herein, the diagnostic trigger signal alternates between enabled and disabled states as described above. In these examples, the control circuit system 202 may initiate any number of diagnostic tests when enabled, but stop performing the tests when disabled. In other examples, a pulse in the diagnostic trigger may indicate that the control circuit system 202 is allowed to perform n diagnostic tests, where n is any positive integer. In this example, the control circuit system 202 cannot perform the (n+1)th diagnostic test until the rate determiner circuit system 208 provides another pulse in the diagnostic trigger signal.
[0041] When enabled, the control circuit system 202 further limits the testing of the defined signal chain to the signal chain that is currently idle for each module of the defined signal chain. To initiate a diagnostic test, the control circuit system 202 provides the value in the control input signal to the first module in the signal chain, as described above in conjunction with Figure 1 The modules in the signal chain are not idle during the diagnostic test. In fact, the modules in the signal chain are performing operations so that the last module in the ordered sequence can provide the value in the data signal back to the control circuit system 202.
[0042] In some examples, a module in a signal chain sends a value in an activation request signal to control circuitry 202 while the signal chain is running a diagnostic test. The value informs control circuitry 202 that application 104 will want to reclaim the module for run-time operations. In these examples, control circuitry 202 determines whether to return access to the module to application 104 before or after receiving an output value in a data signal from the last module in the ordered sequence.
[0043] If control circuitry 202 returns access to application 104 before receiving the output value, then application 104 has immediate access to use the requested module in the execution of the time-sensitive runtime operation. However, if access is returned to application 104 before receiving the output value, then the diagnostic test cannot be completed. In these instances, control circuitry 202 may later restart the diagnostic test on the signal chain (e.g., once all modules in the signal chain are idle again).
[0044] Alternatively, if control circuitry 202 returns access to the module after receiving the output value, comparison circuitry 214 can use the output value to complete the diagnostic test and produce a pass / fail result. However, if control circuitry 202 returns access to the module after receiving the output value, there is a lag period between the time when application 104 first requests the module and the time when application 104 can use the module for runtime operations. In some examples, the lag period can prevent application 104 from performing certain time-sensitive runtime operations.
[0045] The control circuit system 202 uses Figure 2 The instance policy register 212 of the processor 104 determines whether to return access to a module to the application 104 before or after an output value has been received from the signal link. The policy register 202 refers to a portion of a binary value for each module in the memory storage environment 100 (e.g., module 110 and any external modules connected to the processor 102). The binary value for a given module describes whether the application 104 wants to access the module as soon as possible or is willing to wait for a lag period (e.g., so that diagnostic tests involving the module can be completed). For example, a "True" value stored in the policy register 212 associated with ADC 110A means that the application 104 wants to access ADC 110A as soon as possible if it reclaims ADC 110A via an activation signal. In other instances, a "True" value means that the application 104 is willing to wait to access ADC 110A until the ADC 110A is used (e.g., Figure 1 DAC] or [ADC+DAC+PGA] in the example of [ADC+DAC] has been completed. Therefore, when control circuit system 202 receives the value in the activation request from a given module, if policy register 202 indicates that application 104 wants to access the module as soon as possible, then control circuit system 202 stops the diagnostic test before receiving the output value. Similarly, if policy register 212 indicates that application 104 will wait for a hysteresis period, then control circuit system 202 provides access after receiving the output value.
[0046] Figure 2 The example comparison circuit system 214 receives the data signal from the module 110. Therefore, if the diagnostic test on the defined signal chain is not interrupted by the application 104 requesting to access the module as soon as possible, the comparison circuit system 214 receives the output value from the last module in the ordered sequence of the defined signal chain. The comparison circuit system 214 then compares the output value with the expected value. In some examples, the LUT 205 includes one expected value per signal chain. In other examples, the expected values corresponding to the possible signal chains are stored elsewhere in the memory of the environment 100.
[0047] If the output value matches the expected value or is within a threshold range of the expected value, then the comparison circuit system 214 provides a result of "pass" to the application 104. In the examples herein, the foregoing result can be referred to as qualifying that the signal chain passes the diagnostic test. Alternatively, if the output value is outside the threshold range centered on the expected value, then the comparison circuit system 214 provides a result of "fail" to the application 104. In the examples herein, the foregoing result can be referred to as qualifying that the signal chain fails the diagnostic test.
[0048] If the defined signal chain fails the diagnostic test, then the comparison circuit system 214 may additionally provide an abort instruction to the application 104. As used herein, an abort instruction refers to a signal that forces the application 104 to stop performing one or more runtime operations. In some examples, if the failure of the defined signal chain indicates a safety issue, then the comparison circuit system 214 provides an abort instruction. For example, some failures may indicate that if the runtime operation continues, one or more of the modules 110 may be damaged. Additionally or alternatively, some failures may indicate that one or more of the modules 110 are producing unexpected outputs, which may cause the application 104 to produce unsafe results if the application 104 relies on the unexpected outputs at runtime.
[0049] Figure 2 An example of an abort register 216 is an amount of memory that indicates which failed diagnostic tests should generate an abort instruction. The abort register may contain one binary value per signal chain in LUT 205. In some examples, a "true" value in an abort register 216 associated with a given signal chain (e.g., [ADC+DAC]) indicates that an abort instruction should be provided to application 104 if the signal chain fails a diagnostic test. In some examples, comparison circuitry 214 is instantiated by programmable circuitry configured to perform operations such as those specified by Figure 5 and 6 One or more flowcharts represent operations.
[0050] Figure 3A for Figure 1 A block diagram of an example implementation of a system timer for . Figure 3A The system timer circuit system 106 is shown to generate global clock signals at various frequencies. For example, a signal with index zero transmits a pulse once every microsecond. That is, a signal with index zero has a frequency of 1 Mega Hertz (MHz). A signal with index one transmits a pulse once every two microseconds (e.g., a frequency of 500 kilo Hertz (kHz)). Figure 3A In the example of , the global time bus includes 48 signals, where the signal with index n transmits pulses at half the frequency of the signal with index (n-1). Therefore, the system timer circuit system 106 generates a signal at index 47 with a frequency of approximately 7.1e-15 Hz (e.g., approximately one pulse every 4.46 years). In other examples, the system timer circuit system 106 generates a different number of clock signals and / or generates clock signals with different frequencies.
[0051] Figure 3B for Figure 210 is a block diagram of an example implementation of a rate determiner circuit system 208 of FIG. Rate determiner circuit system 208 includes multiplexer circuit system to select a signal from the global timing bus to act as a rate determiner signal (e.g., to provide a pulse to enable or disable control circuit system 202). Multiplexer circuit system determines which signal to pass to control circuit system 202 based on diagnostic period register 210. The passed signal may indicate the periodicity with which diagnostic tests will be performed when module 110 is idle. For example, a faster diagnostic rate may be used to comply with a higher safety level. Figure 3A and 3B In the example of , the diagnostic cycle register 210 includes four bits and can therefore indicate a selection between one of 16 possible inputs. Therefore, the multiplexer circuit system of this example is connected to a subset of signals available on the global time bus (e.g., signals within a frequency range between a pulse once every four milliseconds and a pulse once every hour), and a signal from the subset is provided to the control circuit system 202 to implement the diagnostic test. In other examples, the multiplexer circuit system 3B can be connected to different subsets of signals from the global time bus and / or to different numbers of signals from the global time bus. Similarly, in other examples, the diagnostic cycle register 210 can include any number of bits.
[0052] Figure 4 is a block diagram of an example implementation of a signal chain. Figure 4 Example configurations 402, 404, and 406 are included. In order to obtain an output value from the last module that defines a signal chain, the modules 110 must be connected to each other in a specific configuration (e.g., in an ordered sequence) to properly implement the signal chain. Therefore, the example control circuit system 202 uses control input signals to provide both: a) input values for the first module in the ordered sequence, and b) instructions as to where a given module in the chain should transmit an output value.
[0053] For example, configuration 402 shows Figure 110A . The control circuit system 202 in the HSDE circuit system 108 selects the output of the DAC 110B as the input of the ADC 110A. The DAC 110B and the ADC 110A both operate on different reference voltages from the VREF circuit system 112 to avoid common cause errors. The control circuit system 202 provides a known value as an input word to the DAC 110B and instructs the DAC 110B to provide an analog output to the ADC 110A. The HSDE circuit system 108 also instructs the ADC 110A to provide its converted digital output to the HSDE circuit system 108 so that the comparison circuit system 214 can check the value using the threshold window to declare a diagnostic pass / fail result.
[0054] Example configuration 404 shows how the components within processor 102 would be connected to each other to test the signal chain [DAC+COMP]. To implement configuration 404, control circuitry 202 in HSDE circuitry 108 selects the output of DAC 110B as the input of COMP 110D. Control circuitry 202 also provides a known reference input from VREF circuitry 112 as another input to COMP 110D. Control circuitry 202 provides an input word to DAC 110B so that the output voltage can trigger a change in the output of COMP 110D. The output of HSDE circuitry 108 checks the output of COMP 110D to declare a diagnostic pass / fail result.
[0055] Example configuration 406 shows how the components within processor 102 will be connected to each other to test the signal chain [DAC+PGA+ADC]. To implement configuration 406, HSDE circuit system 108 selects the output of DAC 110B as the input of PGA 110C. DAC 110B and ADC 110A both operate on different reference voltages from VREF circuit system 112 to avoid common cause errors. Control circuit system 202 sets the input of DAC 110B to a known value. Control circuit system 202 then compares the output of ADC 110A with the DAC 110B input word adjusted by the gain setting of PGA 110C.
[0056] Although Figure 2 The implementation is shown in Figure 1 HSDE circuit system 108 is an example of a Figure 2 One or more of the elements, processes and / or devices shown in the drawings may be combined, divided, rearranged, omitted, eliminated and / or implemented in any other manner. Figure 2The control circuit system 202, decoder circuit system 204, LUT 205, module availability register 206, rate determiner circuit system 208, diagnostic cycle register 210, strategy register 212, comparison circuit system 214, and abort register 216 may be implemented by hardware alone or by hardware in combination with software and / or firmware. Thus, for example, Figure 2 Any of the control circuitry 202, decoder circuitry 204, LUT 205, module availability register 206, rate determiner circuitry 208, diagnostic cycle register 210, strategy register 212, comparison circuitry 214, and abort register 216 may be implemented by programmable circuitry in combination with machine-readable instructions (e.g., firmware or software), processor circuitry, one or more analog circuits, one or more digital circuits, one or more logic circuits, one or more programmable processors, one or more programmable microcontrollers, one or more graphics processing units (GPUs), one or more digital signal processors (DSPs), one or more ASICs, one or more programmable logic devices (PLDs), and / or one or more field programmable logic devices (FPLDs) such as FPGAs. Still further, the example HSDE circuitry 108 may include, in addition to Figure 2 In addition to or in place of one or more of the components, processes and / or devices shown Figure 2 One or more of the one or more elements, processes and / or devices shown, and / or may include more than one of any or all of the shown elements, processes and devices.
[0057] Figure 5 and 6 The diagram shows that the programmable circuit system can be executed to implement and / or instantiate Figure 2 One or more flow charts of example operations of the HSDE circuit system. Example operations may be performed by a programmable circuit system (e.g., as described below in conjunction with Figure 7 The example programmable circuit system platform 700 discussed herein may be executed by the programmable circuit system 712 shown in the example programmable circuit system platform 700, and / or may be one or more functions or one or more parts of functions to be performed by the example programmable circuit system (e.g., FPGA). In some examples, the machine-readable instructions cause operations, tasks, etc. to be performed and / or executed in an automated manner in the real world. As used herein, "automatically" means without human intervention.
[0058] In addition, although the reference Figure 5 and 6One or more flowcharts shown in the example program are described, but many other methods of implementing the example HSDE circuit system may be used alternatively. For example, the execution order of the blocks of one or more flowcharts may be changed, and / or some of the blocks described may be changed, eliminated, or combined. Additionally or alternatively, any or all of the blocks of the flowchart may be implemented by one or more hardware circuits (e.g., processor circuit systems, discrete and / or integrated analog and / or digital circuit systems, FPGAs, ASICs, comparators, operational amplifiers (op-amps), logic circuits, etc.) that are structured to perform corresponding operations without executing software or firmware. The programmable circuit system may be distributed in different network locations and / or locally in one or more hardware devices (e.g., single-core processors (e.g., single-core CPUs), multi-core processors (e.g., multi-core CPUs, XPUs, etc.)). For example, the programmable circuit system may be a CPU and / or FPGA located in the same package (e.g., the same integrated circuit (IC) package or in two or more separate housings), one or more processors in a single machine, multiple processors distributed across multiple servers in a server rack, multiple processors distributed across one or more server racks, etc., and / or any combination of one or more thereof.
[0059] Figure 5 To indicate that you can use Figure 1 Flowchart of example operations performed, instantiated, and / or performed by an example programmable circuitry implementation of the HSDE circuitry 108. Figure 1 When the testable instance environment 100 is (block 502), Figure 5 205 using module availability registers 206 to identify which signal chains in LUT 205 contain only modules implemented in environment 100 (e.g., implemented within or connected to processor 102). In some examples, decoder circuitry 204 implements block 502 once per boot cycle to identify whether any modules are connected to processor 102 when the processor is powered off.
[0060] The example decoder circuitry 204 continuously identifies signal chains enabled by the application 104. (Block 504). Identifying a signal chain at block 504 may be referred to as defining a signal chain. For example, the decoder circuitry 204 defines the signal chain in response to determining that the enable signal indicates that each module in the signal chain has been utilized at least once by the application 104 during runtime. In some examples, the decoder circuitry 204 implements block 504 continuously and in parallel with the implementation of blocks 506-516. Thus, the decoder circuitry 204 may define a second signal chain while the control circuitry 202 is running a diagnostic test on a previously defined first signal chain.
[0061] The control circuit system 202 determines whether the diagnostic trigger signal has enabled the test. (Block 506). In some examples, a high supply voltage in the diagnostic trigger signal indicates that the control circuit system 202 is enabled and permitted to perform diagnostic tests. Similarly, in these examples, a low supply voltage in the diagnostic trigger signal indicates that the control circuit system 202 is disabled and prevented from performing diagnostic tests. The diagnostic trigger signal switches between enabling and disabling the control circuit system 202 at a frequency based on the diagnostic cycle register 210. Subsequently, the value stored in the diagnostic cycle register 210 can be determined by the user and / or the application 104.
[0062] If the diagnostic trigger signal has disabled the test (block 506: No), the control circuit system 202 determines whether the processor 102 has been turned off. (block 508). If the processor 102 has been turned off (block 508: Yes), the example operation 500 ends. Alternatively, if the processor 102 is still on (block 508: No), the control circuit system 202 waits for a period of time before control returns to block 506 (block 510).
[0063] Rate determiner circuitry 208 changes the value of the diagnostic trigger signal independently of the state of control circuitry 202. Thus, if the diagnostic trigger signal changes to disabled during execution of blocks 512 through 516, control proceeds directly to block 510 rather than following the sequence described below. That is, in response to being disabled by the diagnostic trigger signal, control circuitry 202 may cease performing any operations of the diagnostic test and wait for re-enabling before continuing.
[0064] If the diagnostic trigger signal has enabled the test (block 506: yes), then the control circuit system 202 selects a defined signal chain. (block 512). The control circuit system 202 may select a defined signal chain from the set using any suitable technique. In some instances, the control circuit system 202 selects the defined signal chain using round robin scheduling. In other instances, the control circuit system 202 selects the signal chain based on a priority scheme (e.g., based on the amount of time the signal chain has been defined without completing the diagnostic test, based on the number of operations in the corresponding diagnostic test, etc.). The control circuit system 202 may be configured to select the signal chain in response to determining that the signal chain is the only signal chain that is currently idle. In some instances, the control circuit system 202 may select the defined signal chain even if the signal chain has completed the diagnostic test earlier in the runtime.
[0065] The control circuit system 202 checks whether all modules in the selected signal chain are currently idle. (Block 514). If one or more of the modules in the selected signal chain are not currently idle (Block 514: No), control returns to block 512, in which the control circuit system 202 selects another defined signal chain. In this example, the control circuit system 202 skips the selected signal chain because at least one module is performing operations for the application and therefore cannot participate in the diagnostic test. In addition, skipping the first defined signal chain enables the control circuit system 202 to test the second defined signal chain while waiting for the application to complete using one or more modules in the first signal chain.
[0066] If all modules in the selected signal chain are currently idle (block 514: yes), then the control circuit system 202 and the comparison circuit system 214 diagnose the selected signal chain. (block 516). The control circuit system 202 and the comparison circuit system 214 may diagnose the selected signal chain by running diagnostic tests. Figure 6 Block 516 is discussed further.
[0067] Figure 5 The flowchart of 500 describes an example operation performed with reference to a single application 104. In some examples, the HSDE circuitry 108 runs diagnostic tests while multiple applications utilize the module 110 in an interleaved manner (e.g., in a multi-threaded usage scenario). In these examples, the decoder circuitry 204 may maintain a separate list of defined signal chains at block 504 for each application running on the processor 102. Similarly, in this example, the module 110 is idle only if it is not utilized by any of the applications running on the processor 102. Therefore, the frequency with which the control circuitry 202 may perform diagnostic tests at block 516 may depend on the number of applications running simultaneously.
[0068] In some examples, the qualification of signals by decoder circuitry 204 is application specific, allowing HSDE circuitry 108 to limit diagnostic testing to signal chains that are actively used. This limitation is advantageous because signal chains that can theoretically be implemented have fewer potential safety risks than signal chains that are actively used at run time.
[0069] In some examples, execution of the application 104 is stopped and execution of another application is started before the processor 102 is powered off at block 508. In these examples, the decoder circuitry 204 may create a new set of defined signal chains at block 504 based on the other application that has started executing. By doing so, the HSDE circuitry 108 may prevent testing of defined signals from the application 104 after execution of the application 104 has stopped.
[0070] Figure 6 A flowchart representing example machine readable instructions and / or example operations that may be executed, instantiated, and / or performed using an example programmable circuit system to diagnose a selected signal chain, such as in conjunction with Figure 5 Specifically, Figure 6 The flow chart is Figure 5 An example implementation of block 516 of .
[0071] exist Figure 2 When the example control circuit system 202 initializes the diagnostic test (block 602), the execution of block 516 begins. To initialize the diagnostic test, the control circuit system 202 provides the value in the control input signal to the first module in the ordered sequence of the signal chain. Figure 4 Examples of these input values are discussed.After initializing the diagnostic test, control circuitry 202 implements blocks 604 and 616 simultaneously (eg, in parallel with each other).
[0072] Control circuitry 202 determines whether the modules in the signal chain have completed operations forming the diagnostic test. (Block 604) If operations are still in progress (Block 604: No), control circuitry 202 waits for a period of time before control returns to block 604 (Block 606).
[0073] Alternatively, if the module has completed operations forming the diagnostic test (block 604: yes), then the comparison circuitry 214 compares the output of the signal chain to the expected value. (block 608). The comparison may produce a result of "pass" or "fail" depending on whether the output value is within a threshold range of the expected value (e.g., whether the output value is within the expected value ± the threshold).
[0074] Comparison circuitry 214 reports the comparison result to application 104. (Block 610). Comparison circuitry 214 then determines whether the result indicates a safety issue (Block 612). To perform the determination of block 612, comparison circuitry 214 checks abort register 216 when the signal chain fails the diagnostic test.
[0075] If the results of the diagnostic test do not indicate a safety issue (block 612: NO), control returns to Figure 5 Alternatively, if the result of the diagnostic test indicates a safety issue (block 612: yes), then the comparison circuitry 214 provides an abort instruction to the application program (block 614). In some examples, the abort instruction forces the application program 104 to stop executing one or more runtime operations. Control returns to the Figure 5 Frame 510.
[0076] In parallel with block 604, control circuitry 202 determines whether application 104 has requested access to a module in the signal chain. (Block 616). To do so, control circuitry 202 may continuously monitor an activation request signal provided by module 110 while control circuitry 202 is enabled. If application 104 has not requested access to any of the modules in the signal chain (block 616: No), control circuitry 202 waits for a period of time before control returns to block 616 (block 618).
[0077] Alternatively, if the application 104 has requested access to a module in the signal chain (block 616: yes), the control circuit system 202 determines whether the application 104 will wait for the diagnostic test to complete. (block 620). The control circuit system 202 performs the determination by checking the policy register 212 to identify the module-specific policy of the application. In the instance where the application 104 simultaneously requests multiple modules from the signal chain at block 616, if none of the policies corresponding to the requested modules in the policy register 212 indicate that the application 104 needs the module as soon as possible, then the application 104 will only wait for the diagnostic test to complete.
[0078] If the application 104 will wait for the diagnostic test to complete (block 620: YES), control returns to block 604 where the control circuit system 202 determines whether the operations forming the diagnostic test have completed. Alternatively, if the application 104 will not wait for the diagnostic test to complete (block 620: NO), control returns to Figure 5 By returning to wait for diagnostic trigger (block 510) when the application 104 will not wait for the diagnostic test to complete (block 620: No), the HSDE circuitry 108 relinquishes control of the modules in the signal chain and returns access to the application 104.
[0079] The control circuitry 202 performs blocks 604-614 in parallel with and independently of blocks 616-620. Thus, in some examples, the operations of blocks 616-620 may be controlled to return to block 510 (thereby stopping the diagnostic testing) before the diagnostic testing is completed. Advantageously, the example operations 500 enable: a) the application 104 to use the module 110 to perform runtime operations whenever needed, and b) the HSDE circuitry 108 to perform diagnostic testing independently of the application 104 during the transition period.
[0080] Figure 7 is structured to be executed and / or instantiated Figure 5 and 6 Example machine readable instructions and / or example operations to implement Figure 2The programmable circuit system platform 700 is a block diagram of an example of a HSDE circuit system. The programmable circuit system platform 700 can be, for example, a server, a personal computer, a workstation, a self-learning machine (e.g., a neural network), a mobile device (e.g., a mobile phone, a smart phone, such as an iPad TM tablet computer), personal digital assistant (PDA), Internet appliance, DVD player, CD player, digital video recorder, Blu-ray player, game console, personal video recorder, set-top box, headsets (e.g., augmented reality (AR) headsets, virtual reality (VR) headsets, etc.) or other wearable devices, or any other type of computing and / or electronic device.
[0081] The programmable circuit system platform 700 of the illustrated example includes a programmable circuit system 712. The programmable circuit system 712 of the illustrated example is hardware. For example, the programmable circuit system 712 may be implemented by one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers from any desired family or manufacturer. The programmable circuit system 712 may be implemented by one or more semiconductor-based (e.g., silicon-based) devices. In some examples, the programmable circuit system 712 may include more than one processor. In this example, the programmable circuit system 712 implements the system timer circuit system 106, the module 110, the control circuit system 202, the decoder circuit system 204, the rate determiner circuit system 208, the comparison circuit system 214, and more generally, the processor 102. In some examples, the HSDE 108 and the circuit systems 202, 204, 208, and 214 may be separate from and coupled to the programmable circuit system 712. In these examples, HSDE 108 may include any of the circuitry attributed to programmable circuitry 712, such as one or more integrated circuits, logic circuits, FPGAs, microprocessors, CPUs, GPUs, DSPs, and / or microcontrollers.
[0082] The programmable circuit system 712 of the illustrated example includes a local memory 713 (e.g., cache, registers, etc.). The programmable circuit system 712 of the illustrated example communicates with a main memory 714, 716 including a volatile memory 714 and a non-volatile memory 716 via a bus 718. The volatile memory 714 may be comprised of a synchronous dynamic random access memory (SDRAM), a dynamic random access memory (DRAM), Dynamic Random Access Memory 206, a diagnostic cycle register 210, a policy register 212, and an abort register 216.
[0083] The programmable circuit system platform 700 of the illustrated example also includes an interface circuit system 720. The interface circuit system 720 can be implemented by hardware according to any type of interface standard, such as an Ethernet interface, a universal serial bus (USB) interface, interface, a near field communication (NFC) interface, a peripheral component interconnect (PCI) interface, and / or a peripheral component interconnect express (PCIe) interface.
[0084] In the example shown, one or more input devices 722 are connected to the interface circuitry 720. The one or more input devices 722 permit a user (e.g., a human user, a machine user, etc.) to enter data and / or commands into the programmable circuitry 712. The one or more input devices 722 may be implemented by, for example, an audio sensor, a microphone, a camera (still or video), a keyboard, buttons, a mouse, a touch screen, a track pad, a trackball, an isochronous device, and / or a speech recognition system.
[0085] One or more output devices 724 are also connected to the interface circuit system 720 of the illustrated example. The one or more output devices 724 may be implemented, for example, by a display device (e.g., a light emitting diode (LED), an organic light emitting diode (OLED), a liquid crystal display (LCD), a cathode ray tube (CRT) display, an in-place switch (IPS) display, a touch screen, etc.), a tactile output device, a printer, and / or a speaker. Therefore, the interface circuit system 720 of the illustrated example typically includes a graphics driver card, a graphics driver chip, and / or a graphics processor circuit system such as a GPU.
[0086] The interface circuitry 720 of the illustrated example also includes communication devices, such as transmitters, receivers, transceivers, modems, residential gateways, wireless access points, and / or network interfaces to facilitate the exchange of data with external machines (e.g., any kind of computing device) over the network 726. Communications may occur over, for example, an Ethernet connection, a digital subscriber line (DSL) connection, a telephone line connection, a coaxial cable system, a satellite system, a line-of-sight wireless system, a line-of-sight wireless system, a cellular telephone system, an optical connection, and the like.
[0087] The programmable circuit system platform 700 of the illustrated example also includes one or more mass storage disks or devices 728 to store firmware, software and / or data. Examples of such mass storage disks or devices 728 include magnetic storage devices (e.g., floppy disks, drives, HDDs, etc.), optical storage devices (e.g., Blu-ray disks, CDs, DVDs, etc.), RAID systems, and / or solid-state storage disks or devices, such as flash memory devices and / or SSDs.
[0088] Machine-readable instructions 732 that may implement application 104 may be stored in mass storage device 728, in volatile memory 714, in nonvolatile memory 716, and / or on at least one non-transitory computer-readable storage medium, such as a removable CD or DVD.
[0089] The example application 104 may be implemented using executable instructions (e.g., computer-readable and / or machine-readable instructions) forming an executable program. The program may be embodied in instructions (e.g., software and / or firmware) stored on one or more non-transitory computer-readable and / or machine-readable storage media, such as cache memory, magnetic storage devices or disks (e.g., floppy disks, hard disk drives (HDDs), etc.), optical storage devices or optical disks (e.g., Blu-ray disks, compact disks (CDs), digital versatile disks (DVDs), etc.), redundant arrays of independent disks (RAID), registers, ROM, solid-state drives (SSDs), SSD memory, non-volatile memory (e.g., electrically erasable programmable read-only memory (EEPROM), flash memory, etc.), volatile memory (e.g., any type of random access memory (RAM), etc.), and / or any other storage devices or storage disks. The instructions of the non-transitory computer-readable and / or machine-readable media may be programmed and / or executed by programmable circuitry located in one or more hardware devices, but the entire program and / or portions thereof may alternatively be executed and / or instantiated and / or embodied in dedicated hardware by one or more hardware devices other than the programmable circuitry. The machine-readable instructions may be distributed across multiple hardware devices and / or executed by two or more hardware devices (e.g., a server and a client hardware device). For example, a client hardware device may be implemented by an endpoint client hardware device (e.g., a hardware device associated with a human and / or machine user) or an intermediate client hardware device gateway (e.g., a radio access network (RAN)) that may facilitate communication between a server and an endpoint client hardware device. Similarly, a non-transitory computer-readable storage medium may include one or more media.
[0090] The machine-readable instructions described herein may be stored in one or more of a compressed format, an encrypted format, a segmented format, a compiled format, an executable format, a packaged format, etc. The machine-readable instructions described herein may be stored as data (e.g., computer-readable data, machine-readable data, one or more bits (e.g., one or more computer-readable bits, one or more machine-readable bits, etc.), a bit stream (e.g., a computer-readable bit stream, a machine-readable bit stream, etc.), etc.) or a data structure (e.g., one or more portions of instructions, code, a representation of code, etc.) that can be used to create, manufacture, and / or generate machine-executable instructions. For example, the machine-readable instructions may be segmented and stored on one or more storage devices, disks, and / or computing devices (e.g., servers) located in the same or different locations (e.g., in the cloud, an edge device, etc.) of a network or collection of networks. The machine-readable instructions may require one or more of installation, modification, adaptation, update, combination, supplementation, configuration, decryption, decompression, decapsulation, distribution, reassignment, compilation, etc., in order to make them directly readable, interpretable, and / or executable by a computing device and / or other machine. For example, machine-readable instructions may be stored in multiple portions that are individually compressed, encrypted, and / or stored on separate computing devices, wherein the portions, when decrypted, decompressed, and / or combined, form a set of computer-executable and / or machine-executable instructions that implement one or more functions and / or operations that may together form a program such as described herein.
[0091] In another example, the machine-readable instructions may be stored in a state in which they can be read by the programmable circuit system, but a library (e.g., a dynamic link library (DLL)), a software development kit (SDK), an application programming interface (API), etc., may need to be added in order to execute the machine-readable instructions on a particular computing device or another device. In another example, the machine-readable instructions and / or one or more corresponding programs may need to be configured (e.g., stored settings, data inputs, recorded network addresses, etc.) before they can be executed in whole or in part. Therefore, as used herein, machine-readable, computer-readable, and / or machine-readable media may include instructions and / or one or more programs, regardless of the specific format or state of the machine-readable instructions and / or one or more programs.
[0092] The machine-readable instructions described herein may be represented by any past, present, or future instruction language, scripting language, programming language, etc. For example, the machine-readable instructions may be represented using any of the following languages: C, C++, Java, C#, Perl, Python, JavaScript, HyperText Markup Language (HTML), Structured Query Language (SQL), Swift, etc.
[0093] As mentioned above, the example application 104 may be implemented using executable instructions (e.g., computer-readable and / or machine-readable instructions) stored on one or more non-transitory computer-readable and / or machine-readable media. As used herein, the terms non-transitory computer-readable media, non-transitory computer-readable storage media, non-transitory machine-readable media, and / or non-transitory machine-readable storage media are expressly defined to include any type of computer-readable storage device and / or storage disk, and to exclude propagating signals and to exclude transmission media. Examples of such non-transitory computer-readable media, non-transitory computer-readable storage media, non-transitory machine-readable media, and / or non-transitory machine-readable storage media include optical storage devices, magnetic storage devices, HDDs, flash memory, read-only memory (ROM), CDs, DVDs, caches, any type of RAM, registers, and / or any other storage device or storage disk where information is stored for any duration (e.g., for an extended period of time, permanently, temporarily, temporarily buffered, and / or cached information). As used herein, the terms "non-transitory computer-readable storage device" and "non-transitory machine-readable storage device" are defined to include any physical (mechanical, magnetic, and / or electrical) hardware to retain information over a period of time, but exclude propagating signals and exclude transmission media. Examples of non-transitory computer-readable storage devices and non-transitory machine-readable storage devices include any type of random access memory, any type of read-only memory, solid-state memory, flash memory, optical disks, magnetic disks, disk drives, and / or redundant arrays of independent disks (RAID) systems. As used herein, the term "device" refers to a physical structure, such as a mechanical and / or electrical device, hardware, and / or circuit system, which may or may not be configured by computer-readable instructions, machine-readable instructions, etc., and / or is manufactured to execute computer-readable instructions, machine-readable instructions, etc.
[0094] "Include" and "comprising" (and all forms and tenses thereof) are used herein as open-ended terms. Thus, whenever a claim employs any form of "include" or "comprising" (e.g., comprises, includes, comprising, including, having, etc.) as a preamble or in any type of claim recitation, it should be understood that additional elements, terms, etc. may be present without exceeding the scope of the corresponding claim or recitation. As used herein, when the phrase "at least" is used as a transitional term, such as in the preamble of a claim, it is open in the same manner as the terms "include" and "comprising" are open. For example, the term "and / or" when used in the form of, for example, A, B, and / or C, refers to any combination or subset of A, B, C, such as (1) only A, (2) only B, (3) only C, (4) A and B, (5) A and C, (6) B and C, or (7) A and B and C. As used herein in the context of describing structures, components, items, objects, and / or things, the phrase “at least one of A and B” is intended to refer to embodiments that include any of the following: (1) at least one A; (2) at least one B; or (3) at least one A and at least one B. Similarly, as used herein in the context of describing structures, components, items, objects, and / or things, the phrase “at least one of A or B” is intended to refer to embodiments that include any of the following: (1) at least one A; (2) at least one B; or (3) at least one A and at least one B. As used herein in the context of describing the performance or execution of a process, instruction, action, activity, etc., the phrase “at least one of A and B” is intended to refer to embodiments that include any of the following: (1) at least one A; (2) at least one B; or (3) at least one A and at least one B. Similarly, as used herein in the context of describing the performance or execution of a process, instruction, action, activity, etc., the phrase "at least one of A or B" is intended to refer to an embodiment that includes any of the following: (1) at least one A; (2) at least one B; or (3) at least one A and at least one B.
[0095] As used herein, singular references (e.g., "a", "an", "first", "second", etc.) do not exclude the plural. As used herein, the term "a" or "an" object refers to one or more of the objects described. The terms "a" (or "an"), "one or more" and "at least one" are used interchangeably herein. Furthermore, although listed separately, multiple components, elements or actions may be implemented by, for example, the same entity or object. In addition, although individual features may be included in different instances or claims, these features may be combined, and the inclusion in different instances or claims does not imply that the combination of features is not feasible and / or advantageous.
[0096] As used herein, unless otherwise indicated, connection references (e.g., attached, coupled, connected, and joined) may include intermediate components between elements referenced by the connection reference and / or relative movement between those elements. Thus, connection references do not necessarily infer that two elements are directly connected and / or in fixed relation to each other. As used herein, stating that any part is "in contact with" another part is defined to mean that there are no intermediate parts between the two parts.
[0097] Unless otherwise specifically stated, descriptors such as "first", "second", "third", etc. are used herein without imposing or otherwise indicating a priority in a list, a physical order, a meaning of arrangement, and / or ordering in any way, but are only used as labels and / or arbitrary names to distinguish elements to facilitate understanding of the described examples. In some examples, the descriptor "first" may be used to refer to an element in a specific embodiment, while the same element may be referred to in the technical solution by different descriptors such as "second" or "third". In this case, it should be understood that these descriptors are only used to clearly identify those elements within the context of the discussion (e.g., within the claims), where the elements may, for example, share the same name in other ways.
[0098] As used herein, "substantially" and "approximately" modify the subject matter / values thereof to recognize the potential for variations that occur in real-world applications. For example, as will be understood by one of ordinary skill in the art, "substantially" and "approximately" may modify dimensions that may not be exact due to manufacturing tolerances and / or other real-world imperfections. For example, unless otherwise specified herein, "substantially" and "approximately" may indicate that these dimensions may be within a tolerance range of + / - 10%.
[0099] As used herein, "substantially real time" means occurring in a near instantaneous manner, recognizing that there may be real-world delays in computing time, transmission, etc. Thus, unless otherwise specified, "substantially real time" means real time + 1 second.
[0100] As used herein, the phrase "communicate" (including variations thereof) encompasses direct communication and / or indirect communication through one or more intermediate components, and does not require direct physical (e.g., wired) communication and / or continuous communication, but also includes selective communication at periodic intervals, predetermined intervals, non-periodic intervals and / or one-time events.
[0101] As used herein, "programmable circuitry" is defined to include the following: (i) one or more special-purpose circuits (e.g., application-specific circuits (ASICs)) that are structured to perform one or more specific operations and include one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors); and / or (ii) one or more general-purpose semiconductor-based circuits that can be programmed with instructions to perform one or more specific functions and / or one or more operations and include one or more semiconductor-based logic devices (e.g., electrical hardware implemented by one or more transistors). Examples of programmable circuit systems include a programmable microprocessor, such as a central processor unit (CPU), which can execute a first instruction to perform one or more operations and / or functions; a field programmable gate array (FPGA), which can be programmed with a second instruction so that the configuration and / or structure of the FPGA can instantiate one or more operations and / or functions corresponding to the first instruction; a graphics processor unit (GPU), which can execute a first instruction to perform one or more operations and / or functions; a digital signal processor (DSP), which can execute a first instruction to perform one or more operations and / or functions; an XPU; a network processing unit (NPU); one or more microcontrollers, which can execute a first instruction to perform one or more operations and / or functions; and / or an integrated circuit, such as an application specific integrated circuit (ASIC). For example, the XPU may be implemented by a heterogeneous computing system that includes multiple types of programmable circuit systems (e.g., one or more FPGAs, one or more CPUs, one or more GPUs, one or more NPUs, one or more DSPs, etc., and / or any one or more combinations thereof) and orchestration technologies (e.g., one or more application programming interfaces (APIs)) that can distribute one or more computing tasks to any one or more programmable circuit systems among the multiple types of programmable circuit systems that are suitable and can be used to perform the one or more computing tasks.
[0102] As used herein, an integrated circuit / circuitry is defined as one or more semiconductor packages containing one or more circuit elements, such as transistors, capacitors, inductors, resistors, current paths, diodes, etc. For example, an integrated circuit may be implemented as one or more of an ASIC, an FPGA, a chip, a microchip, a programmable circuitry, a semiconductor substrate coupling multiple circuit elements, a system-on-chip (SoC), etc.
[0103] In this description, the term "coupled" may encompass connections, communications, or signal paths that enable a functional relationship consistent with this specification. For example, if device A generates a signal to control device B to perform an action, then: (a) in a first instance, device A is coupled to device B through a direct connection; or (b) in a second instance, device A is coupled to device B through an intermediate component C, provided that the intermediate component C does not change the functional relationship between device A and device B, so that device B is controlled by device A via the control signal generated by device A.
[0104] A device "configured to" perform a task or function may be configured (e.g., programmed and / or hardwired) to perform the function when manufactured by a manufacturer, and / or may be configurable (or reconfigurable) by a user after manufacture to perform the function and / or other additional or alternative functions. Configuration may be through firmware and / or software programming of the device, through the construction and / or layout of the device's hardware components and interconnections, or a combination thereof.
[0105] As used herein, the terms "terminal", "node", "interconnection", "pin" and "lead" are used interchangeably. Unless specifically stated to the contrary, these terms are generally used to refer to the interconnections between device elements, circuit elements, integrated circuits, devices or other electronic devices or semiconductor components or their ends.
[0106] A circuit or device described herein as including certain components may actually be adapted to be coupled to those components to form the described circuit system or device. For example, a structure described as including one or more semiconductor elements (e.g., transistors), one or more passive elements (e.g., resistors, capacitors, and / or inductors), and / or one or more sources (e.g., voltage sources and / or current sources) may actually include only semiconductor elements within a single physical device (e.g., a semiconductor die and / or an integrated circuit (IC) package), and may be adapted to be coupled to at least some of the passive elements and / or sources to form the described structure at the time of manufacture or after manufacture, for example, by an end user and / or a third party.
[0107] The circuits described herein can be reconfigured to include replaced components to provide functions that are at least partially similar to the functions available before the component replacement. Unless otherwise stated, components shown as resistors generally represent any one or more elements that are coupled in series and / or in parallel to provide the impedance amount represented by the resistor shown. For example, a resistor or capacitor shown and described as a single component in this article may actually be a plurality of resistors or capacitors coupled in parallel between the same nodes, respectively. For example, a resistor or capacitor shown and described as a single component in this article may actually be a plurality of resistors or capacitors coupled in series between two nodes that are the same as a single resistor or capacitor, respectively. Although some elements of the described examples are included in the integrated circuit and other elements are outside the integrated circuit, in other example embodiments, additional or fewer features may be incorporated into the integrated circuit. In addition, some or all of the features shown as being outside the integrated circuit may be included in the integrated circuit, and / or some features shown as being inside the integrated circuit may be incorporated outside the integrated circuit. As used herein, the term "integrated circuit" means one or more circuits that are: (i) incorporated in / on a semiconductor substrate; (ii) incorporated in a single semiconductor package; (iii) incorporated into the same module; and / or (iv) incorporated in / on the same printed circuit board.
[0108] Modifications are possible in the described embodiments and other embodiments are possible within the scope of the claims.
[0109] From the foregoing it should be appreciated that example systems, apparatus, articles, and methods that implement security diagnostics have been described. The described systems, apparatus, articles, and methods improve the efficiency of using a computing device by implementing a hardware security diagnostic engine to perform diagnostic tests that are application context aware, time, cost, and power efficient, software agnostic, help ensure security, and can be executed at runtime. The described systems, apparatus, articles, and methods thus relate to one or more improvements in the operation of a machine, such as a computer or other electronic and / or mechanical device.
Claims
1. A device for implementing safety diagnosis, the device comprising: an interface circuit system coupled to the plurality of circuit modules; and A diagnostic circuit system configured to: determining a set of signal chains usable by the programmable circuit system, wherein a first signal chain in the set of signal chains includes one or more circuit modules of the plurality of circuit modules; identifying the first signal chain used by the programmable circuitry; as well as A diagnostic test is run on the first signal chain via the interface circuitry in response to determining that the one or more circuit modules in the first signal chain are idle.
2. The apparatus of claim 1 , wherein to run the diagnostic test, the diagnostic circuitry is configured to: providing an input to a first circuit module in the first signal chain; Obtaining an output from the last circuit block in the first signal chain; and The output is compared to an expected value. 3 . The apparatus of claim 1 , wherein the diagnostic circuitry is configured to identify the first signal chain in response to receiving a pulse in a trigger signal.
4. The apparatus according to claim 1, wherein: The circuit module is a first circuit module; and The diagnostic circuit system is configured to: accessing a list of signal chains, the list comprising signal chains describing separation of a second circuit module from the device; and The set of signal chains usable by the programmable circuitry is determined by identifying signal chains within the list that do not include the second circuit module.
5. The apparatus of claim 1, wherein: The first signal chain includes a first circuit module; and The diagnostic circuit system is configured to: receiving a request from the programmable circuit system to access the first circuit module while running the diagnostic test; and After the diagnostic test is completed, the programmable circuitry is provided with access to the first circuit module.
6. The apparatus of claim 5, wherein the diagnostic circuitry is configured to: determining, based on a policy register in a memory, that the programmable circuit system will wait to access the first circuit module until the diagnostic test is complete; and Access to the first circuit module is provided based on the determination.
7. The apparatus of claim 1, wherein: The first signal chain includes a first circuit module; and The diagnostic circuit system is configured to: receiving a request from the programmable circuit system to access the first circuit module while running the diagnostic test; and Prior to completion of the diagnostic test, the programmable circuitry is provided access to the first circuit module.
8. A device for implementing safety diagnosis, the device comprising: Programmable circuit system; a plurality of circuit modules; and A diagnostic circuit system configured to: determining a set of signal chains usable by the programmable circuit system, wherein a first signal chain in the set of signal chains includes one or more circuit modules of the plurality of circuit modules; identifying the first signal chain used by the programmable circuitry; running a diagnostic test on the first signal chain in response to determining that the one or more circuit modules in the first signal chain are idle; as well as Results of the diagnostic test are provided to the programmable circuitry. 9 . The apparatus of claim 8 , wherein the diagnostic circuitry is configured to identify the first signal chain in response to receiving a pulse in a trigger signal.
10. The apparatus of claim 8, wherein: The plurality of circuit modules are a first plurality of circuit modules; The apparatus further includes a memory to store a list of signal chains, the list including signal chains describing a second plurality of circuit modules separate from the apparatus; and To determine the set of signal chains usable by the programmable circuitry, the diagnostic circuitry is configured to identify signal chains within the list that do not include the second plurality of circuit modules.
11. The apparatus of claim 8, wherein the plurality of circuit modules comprises one or more of an analog-to-digital converter (ADC), a digital-to-analog converter (DAC), a programmable gain amplifier, and a comparator.
12. The apparatus of claim 8, wherein the plurality of circuit modules comprise intellectual property (IP) cores that execute machine-readable instructions.
13. The apparatus of claim 8, wherein: The first signal chain includes a first circuit module; and The diagnostic circuit system is configured to: receiving a request from the programmable circuit system to access the first circuit module while running the diagnostic test; and After the diagnostic test is completed, the programmable circuitry is provided with access to the first circuit module.
14. The apparatus of claim 13, wherein the diagnostic circuitry is configured to: determining, based on a policy register in a memory, that the programmable circuit system will wait to access the first circuit module until the diagnostic test is complete; and Access to the first circuit module is provided based on the determination.
15. The apparatus of claim 8, wherein: The first signal chain includes a first circuit module; and The diagnostic circuit system is configured to: receiving a request from the programmable circuit system to access the first circuit module while running the diagnostic test; and Prior to completion of the diagnostic test, the programmable circuitry is provided access to the first circuit module.
16. The device of claim 8, wherein the diagnostic circuitry is configured to run the diagnostic test on the first signal chain while other circuit modules in the device implement instructions from the programmable circuitry.
17. A method for implementing safety diagnosis, the method comprising: determining, using the diagnostic circuitry, a set of signal chains that can be used by the programmable circuitry, wherein a first signal chain in the set of signal chains includes one or more circuit modules; identifying, using the diagnostic circuitry, the first signal chain used by the programmable circuitry; and A diagnostic test is run on the first signal chain utilizing the diagnostic circuitry and in response to determining that the one or more circuit modules in the first signal chain are idle.
18. The method of claim 17, further comprising identifying the first signal chain in response to receiving a pulse in a trigger signal.
19. The method of claim 17, wherein: The circuit module is a first circuit module; and The method further comprises: accessing a list of signal chains, the list including signal chains describing separation of a second circuit module from the diagnostic circuitry; and The set of signal chains usable by the programmable circuitry is determined by identifying signal chains within the list that do not include the second circuit module.
20. The method of claim 17, wherein: The first signal chain includes a first circuit module; and The method further comprises: receiving a request from the programmable circuit system to access the first circuit module while running the diagnostic test; determining, based on a policy register in a memory, that the programmable circuit system will wait to access the first circuit module until the diagnostic test is complete; as well as Based on the determination, control of the first circuit module is provided to the programmable circuitry after the diagnostic test is completed.