Security monitoring of system on chip
By introducing the primary domain and security domain into the system-on-chip (SoC) of the vehicle control system and using the PMIC to directly detect and process the errors of SoCs, the increased cost and complexity of intermediate MCUs in existing systems is solved, achieving higher security and reliability.
Patent Information
- Application Number
- CN202380071333.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-10-18
- Filing Date
- 2023-10-19
- Publication Date
- 2025-05-16
AI Technical Summary
In existing vehicle control systems, communication middleware (such as MCU) between the system-on-chip (SoC) and the electronic control unit (ECU) exists, resulting in increased system cost and complexity.
Reliance on intermediate MCUs is reduced by introducing primary and security domains into SoCs and supplying power to these domains with power management integrated circuits (PMICs) directly detecting errors associated with SoCs and indicating errors to ECUs through multibus or PMICs.
Reduces the cost and complexity of the vehicle control system, while improving the security and reliability of the system, reducing the impact of middleware through direct communication.
Smart Images

Figure CN120019364A_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to U.S. Patent Application No. 18 / 489,809, filed on October 18, 2023, which claims the benefit of and priority to U.S. Provisional Application No. 63 / 380,083, filed on October 19, 2022, both of which are assigned to the assignee of the present application and are hereby expressly incorporated herein by reference in their entirety as if fully set forth below and for all applicable purposes. Background Art Technical Field
[0003] Certain aspects of the present disclosure relate generally to electronic components and, more particularly, to safety monitoring in vehicle control systems.
[0004] Related technologies
[0005] In the past few years, automobiles have been transformed from self-propelled mechanical vehicles to powerful and complex electromechanical systems, which include a large number of sensors and processors that control many functions, features and operations of vehicles. The vehicle may be equipped with a vehicle control system, which may be configured to collect and use information from various systems and sensors of the vehicle to automate all or part of the operation of the vehicle. For example, an advanced driver assistance system (ADAS) can automate, adapt or enhance the operation of the vehicle. ADAS can use information collected from sensors (e.g., accelerometers, radars, lidars, geospatial positioning, etc.) to automatically detect potential road hazards, and assume all or part of the control of the operation of the vehicle (e.g., braking, steering, etc.) to avoid the detected danger. Features and functions commonly associated with ADAS include adaptive cruise control, automatic lane detection, lane departure warning, automatic steering, automatic braking and automatic collision avoidance. The vehicle monitors errors associated with the control system, and the vehicle can notify the operator of such errors, shut down certain systems, or operate in a degraded state in response to detecting certain errors. Summary of the invention
[0006] The systems, methods, and devices of the present disclosure each have several aspects, no single aspect of which is solely responsible for its desired characteristics. Without limiting the scope of the present disclosure as expressed by the claims that follow, some features will now be briefly discussed. After considering this discussion, and particularly after reading the section entitled "Detailed Description," one will understand how the features of the present disclosure provide the advantages described herein.
[0007] Certain aspects of the present disclosure provide a method for operating a vehicle. The method generally includes detecting an error associated with a system on a chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with one or more ECUs. The method also includes indicating an error to one or more ECUs via at least one of a first bus, a second bus, or a power management integrated circuit (PMIC) in response to detecting an error, wherein the PMIC is configured to supply power to the primary domain or the security domain. The method also includes performing one or more actions in response to detecting an error.
[0008] Certain aspects of the present disclosure provide a device for operating a vehicle. The device generally includes a SoC and a PMIC. The SoC has a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more ECUs, and wherein the security domain is coupled to a second bus for communicating with one or more ECUs. The PMIC is configured to supply power to the primary domain or the security domain. At least one of the SoC or the PMIC is configured to detect an error associated with the SoC, indicate an error to one or more ECUs via at least one of the first bus, the second bus, or the PMIC in response to detecting an error, and perform one or more actions in response to detecting an error.
[0009] Certain aspects of the present disclosure provide an apparatus for operating a vehicle. The apparatus generally includes: a component for detecting an error associated with a SoC having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more ECUs, and wherein the security domain is coupled to a second bus for communicating with one or more ECUs. A component for indicating an error to one or more ECUs via at least one of a first bus, a second bus, or a PMIC in response to detecting an error, wherein the PMIC is configured to supply power to the primary domain or the security domain. And a component for performing one or more actions in response to detecting an error.
[0010] Certain aspects of the present disclosure provide a non-transitory computer-readable medium including computer-executable instructions that, when executed by one or more processors of a processing system, cause the processing system to: detect an error associated with a SoC having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more ECUs, and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; indicate the error to the one or more ECUs via at least one of the first bus, the second bus, or a PMIC in response to detecting the error, wherein the PMIC is configured to supply power to the primary domain or the security domain; and perform one or more actions in response to detecting the error.
[0011] To achieve the aforementioned and related purposes, one or more aspects include the features fully described below and particularly pointed out in the claims. The following description and the accompanying drawings set forth in detail certain exemplary features of the one or more aspects. However, these features indicate only some of the various ways in which the principles of the various aspects can be employed. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to be able to understand in detail the manner in which the above-mentioned features of the present disclosure are achieved, a more specific description briefly summarized above may be obtained by reference to various aspects, some of which are illustrated in the accompanying drawings. It should be noted, however, that the accompanying drawings illustrate only certain aspects of the present disclosure and therefore should not be considered as limiting its scope, as the description may allow for other equally effective aspects.
[0013] Figure 1 is a diagram of an example vehicle having a vehicle control system in which aspects of the present disclosure may be practiced.
[0014] Figure 2 is a block diagram of example components and interconnections in a SoC in which aspects of the present disclosure may be practiced.
[0015] Figure 3 is a block diagram of an example SoC-based electronic control unit (ECU) in communication with one or more other ECUs according to certain aspects of the present disclosure.
[0016] Figure 4 is a flow diagram depicting example operations for detecting and reporting errors associated with a SoC, in accordance with certain aspects of the present disclosure.
[0017] To facilitate understanding, identical reference numerals have been used, where possible, to designate identical elements that are common to the figures. It is contemplated that elements disclosed in one aspect may be beneficially utilized on other aspects without specific recitation. DETAILED DESCRIPTION
[0018] Certain aspects of the present disclosure relate to methods and apparatus for safety monitoring of vehicle control systems.
[0019] Some vehicles are equipped with multiple features for safety, navigation, entertainment, etc., such as advanced driver assistance systems (ADAS), autonomous driving (AD), and / or in-vehicle infotainment (IVI). Some vehicles are able to sense other vehicles and / or objects on the road and / or communicate with other vehicles and / or objects on the road, which allows for improved predictive safety features and AD. IVI is no longer just for entertainment purposes, and can ideally work closely with safety features (including ADAS), especially when some vehicles are equipped with AD capabilities. As the automotive industry transitions to AD vehicles, ADAS merges with IVI. Merging ADAS and IVI will improve driving safety and improve the overall driving experience. In other words, as the driving experience becomes autonomous, the demand for both passenger safety and entertainment increases.
[0020] In some vehicle control systems, a system on chip (SoC) can be used to control ADAS, AD and / or IVI. In some cases, a microcontroller unit (MCU) can be used to communicate between the SoC and the electronic control unit (ECU) in the vehicle control system. For example, the SoC may have been added to a vehicle control system including an MCU and an ECU to provide certain ADAS, AD and / or IVI features. In some cases, the MCU can perform a safety monitoring function relative to the SoC. For example, the MCU can monitor errors occurring at the SoC and notify the ECU when an error is detected. When the SoC becomes unresponsive or suspends operation, the MCU can act as a watchdog timer for the SoC. The MCU can monitor dedicated functional safety (FuSa) errors and warning signals from the SoC. The MCU can monitor catastrophic error signals (e.g., extreme thermal excursions) from the SoC. The MCU can monitor functional safety error signals from a power management integrated circuit (PMIC) that provides power to the SoC. The MCU can monitor certain other functional signals from the SoC and / or the PMIC.
[0021] Various aspects of the present disclosure provide methods and apparatus for safety monitoring of a vehicle control system using a SoC. For example, the SoC may have multiple buses for communicating with an ECU, wherein the bus may provide a redundant interface to communicate with the ECU. For some aspects, the bus may carry a heartbeat signal or a challenge-response to the ECU to indicate whether the SoC is unresponsive or suspended. In some aspects, a PMIC that supplies power to the SoC may monitor error signals from the SoC, and the PMIC may notify the ECU when an error is detected. In response to detecting the error, the PMIC may shut down the SoC, or may otherwise output a control signal that causes the SoC to be shut down.
[0022] The methods and apparatus for safety monitoring described herein provide various advantages. The methods and apparatus described herein can reduce the cost and complexity of vehicle control systems, for example, by eliminating an intermediate MCU between a SoC-based control system and an ECU.
[0023] Example Vehicle Control System
[0024] Figure 1 1 is a block diagram of an example vehicle 100 including a vehicle control system 102 and various sensors suitable for controlling certain systems such as ADAS, AD and / or IVI. Vehicle 100 may refer to a component that carries or transports something (e.g., people and / or goods). In some aspects, vehicle 100 may represent a motor vehicle, such as a car, a van, a truck, a semi-trailer, a motorcycle, a light motorcycle, a moped, an electric bicycle, etc. Vehicle 100 may be a mass-produced road vehicle with a safety-related system including one or more electrical and / or electronic systems, as further described herein. Vehicle 100 may be propelled using an internal combustion engine, an electric motor, or a hybrid propulsion system (e.g., a combination of an engine and an electric motor). In some cases, vehicle 100 may have one or more electrical and / or electronic systems that comply with certain functional safety standards (such as ISO 26262 provided by the International Organization for Standardization (ISO)).
[0025] The vehicle 100 may include a vehicle control system 102, which may include one or more computing devices having a SOC (e.g., one or more ECUs), as described herein with respect to Figure 2 and Figure 3 The vehicle control system 102 may be coupled to various vehicle systems and subsystems, such as an environmental system 104 (e.g., an air conditioning and / or heating system), a navigation system 106, a communication and / or infotainment system 108, a power control system 110, a powertrain control system 112, a driver assistance and / or autonomous driving control system 114, and / or various sensors 116. Each vehicle system or subsystem may communicate with one or more other systems (and / or subsystems) via one or more communication links, which may include wired communication links (e.g., a controller area network (CAN) protocol compatible bus, a universal serial bus (USB) connection, an Ethernet connection, a universal asynchronous receiver-transmitter (UART), etc.) and / or wireless communication links (e.g., link, Link, ZigBee Link, link, etc.).
[0026] The vehicle control system 102 may perform certain operations associated with any of the vehicle systems and subsystems. For example, the vehicle control system 102 may control or initiate a power-on and / or shutdown sequence for any of the vehicle systems and subsystems. The vehicle control system 102 may monitor errors associated with any of the vehicle systems and subsystems, and in some cases, the vehicle control system 102 may store errors for vehicle diagnostics. In response to any errors detected, the vehicle control system 102 may perform certain actions, such as shutting down the affected system or transmitting some affected operations to be performed at a different vehicle system. The vehicle control system 102 may monitor the power level supplied to any of the vehicle systems and subsystems, and ensure that the supplied power level meets the operating specifications of any of the vehicle systems and subsystems.
[0027] The environmental system 104 can control cooling and / or heating systems associated with the vehicle 100. For example, the vehicle 100 can have an air conditioning system, a heating system, heated or cooled seats, and / or a heated steering wheel, and the environmental system 104 can adjust the temperature according to user (or default) settings for the corresponding cooling and / or heating components. The navigation system 106 can show the location of the vehicle on a map and provide navigation information, such as directions to a destination, via a display and / or speakers (neither shown).
[0028] The communication and / or infotainment system 108 may allow the user to access various information (e.g., navigation information, interior or exterior environment information, ADAS information, etc.), applications, and / or entertainment or media content, such as music and / or video. The communication and / or infotainment system 108 may allow the user to update or access settings associated with various systems (such as the environment system 104, the navigation system 106, the ADAS, vehicle settings, etc.). The communication and / or infotainment system 108 may allow the user and / or vehicle 100 to communicate wirelessly via an integrated modem of the vehicle or via a user's wireless communication device (e.g., a smart phone or tablet).
[0029] The power control system 110 can control the output power to move components of the vehicle, such as an internal combustion engine (e.g., adjusting air-fuel ratio, boost pressure, valve timing, etc.), an electric power system (e.g., controlling regenerative braking, battery power output, battery charging, battery cooling, etc.), and / or a hybrid power system (e.g., controlling regenerative braking, switching between battery power and engine power, battery charging, battery cooling, etc.). The powertrain control system 112 can control various components of the vehicle 100 that deliver power to the drive wheels. For example, the powertrain control system 112 can control shifting in an automatic transmission. For a four-wheel drive vehicle, the powertrain control system 112 can control the ratio of power applied to the front drive wheels and the rear drive wheels.
[0030] The driver assistance and / or autonomous driving control system 114 may control various driver assistance features and functions, such as adaptive cruise control, automatic lane detection, lane departure warning, automatic steering, automatic braking, and automatic collision avoidance. The driver assistance and / or autonomous driving control system 114 may control autonomous driving at various levels of automation, such as any of Society of Automotive Engineers (SAE) levels 1 to 5.
[0031] The various sensors 116 coupled to the vehicle control system 102 may include a speedometer, a wheel speed sensor, a torque meter, a turbine speed sensor, a variable reluctance sensor, a sonar system, a radar system, an air-fuel ratio meter, a water-in-fuel sensor, an oxygen sensor, a crankshaft position sensor, a curb detector, a temperature sensor, a Hall effect sensor, a manifold absolute pressure sensor, various fluid sensors (e.g., an engine coolant sensor, a transmission fluid sensor, etc.), a tire pressure monitoring sensor, a mass air flow sensor, a speed sensor, a blind spot monitoring sensor, a parking sensor, a camera, a microphone, an accelerometer, a compass, a global navigation satellite system (GNSS) receiver (e.g., a global positioning system (GPS) receiver or a Galileo receiver), and other similar sensors for monitoring physical or environmental conditions in and around the vehicle.
[0032] The foregoing systems are presented as examples only, and the vehicle may include one or more additional systems that are not shown for clarity. Additional systems may include systems related to additional other functions of the vehicle systems, including instrumentation, air bags, cruise control, other engine systems, stability control parking systems, tire pressure monitoring, anti-lock brakes, active suspension, battery charge and / or management, and various other systems.
[0033] Example System-on-Chip
[0034] As used herein, the term "system on chip" (SoC) generally refers to an integrated electronic device including one or more integrated circuit (IC) dies (e.g., chiplets) that combines multiple electronic components (e.g., processors and / or memory) on a single substrate or in a single package. A single SoC may contain circuits for digital, analog, mixed-signal, and / or radio frequency functions. A single SoC may also include any number of general-purpose and / or specialized processors (digital signal processors, modem processors, video processors, etc.), storage blocks (e.g., ROM, RAM, DRAM, flash memory, etc.), and resources (e.g., timers, voltage regulators, oscillators, etc.). The SoC may also include software for controlling the integrated resources and processors and for controlling peripheral devices.
[0035] Figure 2 2 is a block diagram of example components and interconnections in a SoC 200 suitable for implementing various aspects of the present disclosure. The SoC 200 may include multiple processing domains including, for example, at least one primary domain 202a and at least one security domain 202b (also referred to as a "safe island (SAIL)"). In the case of multiple primary (or security) domains, the primary (or security) domains may be similar to each other. For ease of description and illustration, the remainder of the present disclosure may refer to the primary domain 202a and the security domain 202b, but the reader should understand that there may be more than one primary domain and / or more than one security domain.
[0036] The primary domain 202a may be configured to support (or be able to perform) vehicle operations (e.g., driver assistance and / or autonomous driving operations, features, etc.) up to a specific automotive safety integrity level (ASIL), and the safety domain 202b may be configured to support (or be able to perform) vehicle operations up to a lower, the same, or a higher ASIL than the primary domain 202a. For example, the primary domain 202a may be configured to support (or be able to perform) vehicle operations up to ASIL B, and the safety domain 202b may be configured to support vehicle operations up to ASIL D. In some cases, the primary domain 202a may be configured to support (or be able to perform) vehicle operations up to ASIL A, B, C, or D, and the safety domain 202b may be configured to support vehicle operations up to a different ASIL than the primary domain 202a. In some cases, the primary domain 202a and the safety domain 202b may be configured to support (or be able to perform) vehicle operations at the same ASIL (e.g., ASIL D). The primary domain 202a and the safety domain 202b may be configured to support (or be capable of performing) vehicle operations at different ASILs.
[0037] ASIL can be defined in a specific safety standard, such as ISO 26262. For example, ASIL can provide a risk classification scheme for certain electrical and electronic systems of road vehicles. ISO 26262 provides four ASILs, including ASIL A, ASIL B, ASIL C, and ASIL D. ASIL D is the highest classification and corresponds to the highest level of safety measures for avoiding unreasonable residual risks, and ASIL A is the lowest classification and corresponds to the lowest level of safety measures.
[0038] In some aspects, SoC 200 may be included in a computing device (eg, an ECU) in a vehicle control system. SoC 200 may control the Figure 1 For example, SoC 200 may be configured to control an ADAS / AD system, such as the one described herein with respect to Figure 1 The driver assistance and / or autonomous driving control system 114 described herein. In certain aspects, the SoC 200 may communicate with other ECUs in the vehicle control system, and the SoC 200 and / or the PMIC 218 may report errors associated with the SoC 200 to the other ECUs, as described herein with respect to Figure 3 For example, the primary domain 202a may control environmental systems, infotainment systems, and driver assistance features up to a certain ASIL, and the safety domain 202b may control driver assistance features up to a certain ASIL (which may generally be higher than the primary domain 202a).
[0039] The primary domain 202a and / or the secure domain 202b may include a plurality of heterogeneous processors 204a-c (collectively referred to herein as "processors 204"), such as a central processing unit (CPU) 204a, a signal processor 204b (e.g., a digital signal processor, an image signal processor, a neural network signal processor, etc.), and / or an application processor 204c. Each processor 204 may include one or more cores, and each processor / core may perform operations independently of other processors / cores. Each processor 204 may be part of a subsystem (not shown) that includes one or more processors, caches, etc. configured to handle certain types of tasks or calculations. It should be noted that the primary domain 202a and / or the secure domain 202b may include additional processors (not shown) or may include fewer processors (not shown). The primary domain 202a and / or the secure domain 202b may include other processors (e.g., a graphics processing unit (GPU), a visual processing unit, etc.) in addition to or in place of those illustrated.
[0040] The primary domain 202a and / or the secure domain 202b may include system components and resources 206 for performing certain specialized operations, such as analog-to-digital conversion and / or wireless data transmission. The system components and resources 206 may include components such as voltage regulators, oscillators, phase-locked loops (PLLs), modems, peripheral bridges, data controllers, system controllers, access ports, timers, and other similar components for supporting processors and software clients running on the SoC 200. The system components and resources 206 may include circuits for interfacing with peripheral devices such as cameras, electronic displays, wireless communication devices, external memory chips, and the like.
[0041] The primary domain 202a and / or the secure domain 202b may also include a power management controller 208, a memory controller 210 (e.g., a dynamic random access memory (DRAM) memory controller and / or a non-volatile memory controller), a sensor controller 212, and / or a driver assistance controller 214. The primary domain 202a and / or the secure domain 202b may also include an input / output (IO) module (not shown) for communicating with resources external to the SoC (such as clocks and voltage regulators), each of which may be shared by two or more of the internal SoC components. For example, the IO module may include a general purpose IO (GPIO) interface. In some aspects, each of the primary domain 202a and the secure domain 202b may have a separate clock and power supply to facilitate independent operability.
[0042] The processor 204 of the main domain 202a can be interconnected to the system components and resources 206, the power management controller 208, the memory controller 210, the sensor controller 212, the driver assistance controller 214, other system components and / or the security domain 202b via the interconnect / bus module 216, which can include a reconfigurable logic gate array and / or implement a bus architecture (e.g., CoreConnect, Advanced Microcontroller Bus Architecture (AMBA), etc.). Communication can be provided by an advanced interconnect such as a high-performance network on chip (NoC).
[0043] The interconnect / bus module 216 may include or provide a bus master system that is configured to grant a SoC component (e.g., a processor, a peripheral device, etc.) exclusive control of a bus (e.g., to transfer data) for a set duration, number of operations, number of bytes, etc. In some aspects, the interconnect / bus module 216 may include a direct memory access (DMA) controller (not shown) that enables a component connected to the interconnect / bus module 216 to operate as a master component and initiate memory transactions. The interconnect / bus module 216 may implement an arbitration scheme to prevent multiple master components from attempting to drive the bus simultaneously.
[0044] The power management controller 208 may manage power supplied to the primary domain 202a from the PMIC 218, which may represent one or more PMICs. In some cases, the power management controller 208 may report errors associated with the primary domain 202a and / or the security domain 202b to the PMIC 218, as further described herein. Power management and error monitoring controls may be separate and independent between the primary domain 202a and the security domain 202b.
[0045] The memory controller 210 may be a dedicated hardware module configured to manage data flow to and from the memory 220. The memory controller 210 may include logic components for interfacing with the memory 220, such as selecting rows and columns corresponding to memory locations in a cell array of the memory 220, reading or writing data to memory locations, etc. The memory 220 may be an on-chip component of the SoC 200 (e.g., on a substrate, die, integrated chip, etc.), or alternatively (as shown) an off-chip component.
[0046] The sensor controller 212 may manage sensor data received from various sensors 222, such as the sensor 116. The sensor controller 212 may include circuitry for interfacing with the sensors 222. For example, the sensor controller 212 may receive sensor data from a tire pressure monitoring system and / or a radar sensor for adaptive cruise control.
[0047] The driver assistance controller 214 may control certain driver assistance functions via a driver assistance module 224 (e.g., one or more actuators, relays, switches, etc.). For example, the driver assistance controller 214 may control adaptive cruise control by controlling actuators coupled to the engine and / or braking system. In some cases, the driver assistance controller 214 may perform automatic steering by controlling actuators attached to the steering system. It should be understood that the driver assistance controller 214 is merely an example, and in addition to or in place of the driver assistance controller 214, the primary domain 202a and / or the safety domain 202b may include a controller that interfaces with the autonomous driving component.
[0048] SoC 200 may also include additional hardware and / or software components suitable for collecting sensor data from sensors, including speakers, user interface elements (e.g., input buttons, touch screen displays, etc.), microphone arrays, sensors for monitoring physical conditions (e.g., position, direction, motion, orientation, vibration, pressure, temperature, etc.), cameras, compasses, GPS receivers, communication circuits (e.g., Wireless Local Area Network (WLAN), Long Term Evolution (LTE), Fifth Generation New Radio (5G NR), etc.) and other well-known components of modern electronic devices (e.g., accelerometers, etc.).
[0049] Each processing domain in the processing domain can operate independently of other domains. In some cases, each processing domain in the processing domain can be coupled to a separate and independent external resource, such as a PMIC, a memory, a sensor, and a driver assistance module. Specific external resources can be designed according to the ASIL corresponding to the specific ASIL associated with the main domain 202a and / or the safety domain 202b to which the external resource is coupled. For example, the PMIC 218 can have the same ASIL as the main domain 202a, and the PMIC that provides power to the safety domain 202b can have the same ASIL as the safety domain 202b. The safety domain 202b may include the same or different processing resources and components as the main domain 202a, as described herein with respect to the main domain 202a. For example, the safety domain 202b may include a processor 204, system components and resources 206, a power management controller 208, a memory controller 210, a sensor controller 212, and a driver assistance controller 214. The safety domain 202 b may be coupled to certain external resources 226 , which may represent, for example, a PMIC, memory, sensors, and / or a driver assistance module, as described herein with respect to the primary domain 202 a .
[0050] In addition to the SoC 200 discussed above, the various aspects may also be implemented in a variety of computing systems that may include a single processor, multiple processors, a multi-core processor, or any combination thereof. The various aspects described herein may also be implemented in a system that employs more than one SoC. For example, an SoC-based ECU may include multiple SoCs (e.g., SoC 200) configured to monitor the safety of a vehicle control system (e.g., vehicle control system 102). In these examples, each of the multiple SoCs may include a different number of primary domains and / or security domains.
[0051] Example Security Monitoring for SoC
[0052] Figure 3 is a block diagram of an example SoC-based ECU 300a communicating with one or more other ECUs 300b, for example, for safety monitoring. In this example, the ECU 300a and other ECUs 300b may operate in a vehicle control system and / or any vehicle system or subsystem, as described herein with respect to Figure 1 ECU 300a may perform some vehicle control operations (e.g., infotainment, environment, ADAS, etc.), and other ECU 300b may perform some vehicle control operations (e.g., system-wide control, engine control, powertrain control, other ADAS features, etc.). As an example, ECU 300a may be an ADAS ECU. ECU 300a may include SoC 200 and corresponding external resources, as described herein with respect to Figure 2 In some aspects, the other ECU 300b may include a SoC-based ECU, such as SoC 200 and corresponding external resources, as described herein with respect to Figure 2 As described.
[0053] The primary domain 202a may operate independently of the security domain 202b using independent external resources. For example, the primary domain 202a may receive power from the primary domain PMIC 218a, and the security domain 202b may receive power from a security domain PMIC 218b that is different from the primary domain PMIC 218a and may provide independent power. Such a power architecture may allow the primary domain 202a to operate even when the security domain 202b is shut down or in a low power state, or vice versa. In some cases, the security domain 202b may be operable to monitor errors of the primary domain 202a.
[0054] Any of the main domain 202a, the safety domain 202b, the main domain PMIC 218a, and / or the safety domain PMIC 218b may perform self-error detection, wherein a component may detect an error occurring at the component. For example, the main domain 202a may detect an error occurring at the main domain 202a. These components may also perform redundant error detection as further described herein, wherein a component may detect an error occurring at another component. For example, the safety domain 202b may detect an error occurring at the main domain 202a, or vice versa. The safety domain 202b may monitor errors of the safety subsystem of the main domain 202a. The ECU 300a may use a redundant error propagation scheme, wherein any error detected within the safety subsystem is routed to the main domain 202a and the safety domain 202b. For example, the safety domain PMIC 218b may notify the main domain 202a of the occurrence of an error associated with the safety domain 202b or the occurrence of an error within the safety domain PMIC 218b.
[0055] The primary domain 202a may communicate with the security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b. Any of the security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b may monitor errors associated with the primary domain 202a. Errors associated with the primary domain 202a may include errors occurring at the primary domain 202a or at any of the external resources associated with the primary domain 202a (e.g., PMIC, memory, sensor, driver assistance module, etc.). In some cases, the primary domain 202a may notify the security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b of the occurrence of an error associated with the primary domain 202a.
[0056] In some cases, the security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b can detect errors associated with the primary domain 202a. The security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b can detect whether the primary domain 202a has suspended operation or is unresponsive. For example, the security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b can detect that the primary domain 202a has stopped outputting a watchdog timer or is unresponsive to a challenge in a challenge-response exchange with the primary domain 202a. The watchdog timer, heartbeat, and / or challenge-response operation can be implemented between the primary domain 202a and any one of the security domain 202b, the primary domain PMIC 218a, and / or the security domain PMIC 218b to ensure that the primary domain 202a is detected to be suspended, suspended, or unresponsive. As an example, the secure domain 202b may request the primary domain 202a to perform a calculation and provide the result to the secure domain 202b. If the primary domain 202a provides an erroneous result or is unresponsive, the secure domain 202b may detect that an error occurred at the primary domain 202a.
[0057] The security domain 202b may communicate with the main domain 202a, the security domain 202b and / or the security domain PMIC 218b. Any of the main domain 202a and the security domain PMIC 218b may monitor errors associated with the security domain 202b. Errors associated with the security domain 202b may include errors occurring at the security domain 202b or at any one of the external resources associated with the security domain 202b. In some cases, the security domain 202b may notify the main domain 202a and / or the security domain PMIC 218b of the occurrence of errors associated with the security domain 202b (e.g., so that the ECU 300b can take appropriate actions as a response). In some cases, the main domain 202a and / or the security domain PMIC 218b may detect errors associated with the security domain 202b, for example, based on a watchdog operation and / or a challenge-response operation.
[0058] The primary domain 202a and the safety domain 202b may communicate with other ECUs 300b via separate buses 330a, 330b (collectively referred to herein as "buses 330"). The bus 330 may include a wired communication link (e.g., a CAN bus, a USB connection, an Ethernet connection, etc.) and / or a wireless communication link (e.g., link, link, link, Link, etc.). The bus 330 may provide a redundant communication path to other ECUs 300b. Error information associated with the SoC 200 may be propagated from the primary domain 202a to other ECUs 300b via the first bus 330a, wherein the error information associated with the SoC 200 may include an error occurring at the primary domain 202a, the security domain 202b, or at any one of the external resources associated with the primary domain 202a and / or the security domain 202b. Error information associated with the SoC 200 may be propagated from the security domain 202b to other ECUs 300b via the second bus 330b.
[0059] In some cases, the primary domain 202a and / or the security domain 202b may notify the other ECUs 300b of the occurrence of an error associated with the primary domain and / or the security domain 202b via the bus 330. In some cases, the other ECUs 300b may detect the error associated with the primary domain 202a and / or the security domain 202b via the bus 330, for example, based on a watchdog operation and / or a challenge-response operation.
[0060] The primary domain PMIC and / or the safety domain PMIC 218b may communicate with other ECUs 300b via communication links 332a, 332b (collectively referred to herein as "communication links 332") such as a bus or one or more input / output (I / O) interfaces (e.g., I / O pins). The safety domain PMIC 218b may communicate with the primary domain PMIC 218a. Power-on and / or shutdown sequencing signals may be received from other ECUs 300b at the primary domain PMIC 218a and / or the safety domain PMIC 218b. The primary domain PMIC 218a and / or the safety domain PMIC 218b may obtain power-on instructions and / or shutdown instructions from other ECUs 300b. In some cases, the primary domain PMIC 218a and / or the safety domain PMIC 218b may receive instructions from other ECUs 300b to perform a rapid shutdown, for example, due to a sudden power outage from an external power source. Such an indication may be routed to a dedicated control pin of the primary domain PMIC 218a and / or the safety domain PMIC 218b. Input supply monitoring to the PMICs 218a, 218b may be performed externally by an ASIL rated pre-regulator or some other entity (e.g., other ECUs 300b). The input supply to the PMICs 218a, 218b may be ensured to be within the specifications associated with the PMICs 218a, 218b.
[0061] In some cases, the secure domain PMIC 218b may instruct the primary domain PMIC 218a to power on or off the primary domain 202a in response to an instruction. The primary domain PMIC 218a and the secure domain PMIC 218b may also power on or off the primary domain 202a and / or the secure domain 202b in response to an instruction.
[0062] The safety domain PMIC 218b may receive an indication of an error associated with the SoC 200 from the primary domain 202a, the safety domain 202b, and / or the primary domain PMIC 218a. The safety domain PMIC 218b may notify other ECUs 300b of the occurrence of an error associated with the primary domain 202a, the primary domain PMIC 218a, and / or the safety domain 202b via a communication link 332b. In some cases, other ECUs 300b may detect the occurrence of an error associated with the primary domain 202a, the primary domain PMIC 218a, and / or the safety domain 202b via a communication link 332b, for example, based on a watchdog operation and / or a challenge-response operation.
[0063] In response to detecting an error associated with the main domain 202a and / or the safety domain 202b, the other ECU 300b may be notified of the error by any one of the main domain 202a, the safety domain 202b and / or the safety domain PMIC 218b. Other ECU 300b may take corrective action based on the error. For example, other ECU 300b may instruct SoC 200 to shut down any one of the main domain 202a and the safety domain 202b, and other ECU 300b may operate the vehicle without the operation performed by ECU 300a or taking over all or some of the operations performed by ECU 300a. In response to detecting an error, other ECU 300b may operate according to a specific security strategy designed by, for example, an original equipment manufacturer (OEM) of the vehicle. In some aspects, when SoC 200 is unresponsive to a command, ECU 300b may drive the shutdown of SoC 200 by transmitting a powerful shutdown (power-off) command to the main domain PMIC 218a and / or the safety domain PMIC 218b.
[0064] If the SoC 200 has a functional safety error or warning, the SoC 200 may notify the safety domain PMIC 218b of the error via at least one error pin (e.g., at least one pin of a general purpose IO (GPIO)) routed from the SoC 200 to the safety domain PMIC 218b. The error pin is capable of conveying errors very quickly without software intervention. In some aspects, in addition to the error pin or as an alternative to the error pin, a communication bus may be used to communicate more detailed functional safety error or warning information. In response to detecting such an error, the SoC 200 may instruct the main domain PMIC 218a and / or the safety domain PMIC 218b to shut down the SoC 200. In response to detecting such an error, the SoC 200 may notify other ECUs 300 of a functional safety error or warning associated with the SoC 200 via any one of the buses 330. In some aspects, the main domain PMIC 218a and / or the safety domain PMIC 218b may also notify the ECU 300 of the functional safety error and the subsequent action of shutting down the SoC 200.
[0065] In some cases, if the SoC 200 has a functional safety (FuSa) error or warning, the SoC 200 may notify the primary domain PMIC 218a of the error via an error pin routed from the SoC 200 to at least two primary domain PMICs 218a. Since the primary domain 202a may use two or more PMICs, the primary PMIC and the auxiliary PMIC may be used for error monitoring. ASIL decomposition may be applied to achieve the highest ASIL for error reporting from the SoC 200 to the primary domain PMIC 218a via the error pin. The SoC 200 may request the primary domain PMIC 218a and the safety domain PMIC 218b to shut down the SoC 200.
[0066] FuSa errors or warnings may include errors that may jeopardize the safety of future operations at a component (such as the main domain 202a or the safety domain 202b). The safety system of SoC 200 may monitor FuSa errors and / or FuSa warnings. FuSa errors may include electrical and / or electronic faults detected by hardware or software safety mechanisms that cause uncorrectable errors within the safety system of SoC 200. The detected errors may cause failures and / or violate specific safety goals. FuSa warnings may include electrical and / or electronic faults detected by hardware or software safety mechanisms within the safety system of SoC 200. The detected faults associated with FuSa warnings may be correctable faults or uncorrectable faults. Correctable faults associated with FuSa warnings may be detected, reported, and corrected by the safety system of the vehicle (e.g., other ECUs 300b) and / or SoC 200. For example, a correctable fault may be a memory error handled by an error correction code, such as a 1-bit error. Uncorrectable faults associated with FuSa warnings may be known faults that may be handled by the safety policy of the OEM. For example, in response to detecting an uncorrectable fault, the security policy may provide for notification of a warning, such as a SoC temperature excursion warning (e.g., triggered by an on-die temperature of the SoC exceeding a warning threshold but not exceeding an error threshold) or a SoC voltage excursion warning (e.g., triggered by an on-die voltage of the SoC exceeding a warning threshold but not exceeding an error threshold). In some aspects, a FuSa error or warning may include a systemic fault associated with software or hardware, such as a software bug or a hardware design bug.
[0067] For example, a functional safety error or warning may include a miscalculation or faulty determination performed at the primary domain 202a and / or the safety domain 202b, a corrupted or faulty memory coupled to the primary domain 202a and / or the safety domain 202b (e.g., due to a memory bit being flipped), or the primary domain 202a and / or the safety domain 202b being unable to communicate with a sensor and / or control device (e.g., an actuator, relay, switch, etc.). As another example, a functional safety error may include a fault occurring at a sensor (e.g., data used for measurement is corrupted) or a control device (e.g., an actuator is stuck or a relay is inoperable).
[0068] The security domain 202b can perform a watchdog operation and / or a challenge-response operation on the primary domain 202a to detect whether the primary domain 202a is suspended or suspended in operation or unresponsive. In response to detecting such an error, the security domain 202b can notify other ECUs 300b of an error associated with the primary domain 202a. In some cases, the security domain 202b can indicate to the primary domain PMIC 218a to shut down the primary domain 202a, and the security domain 202b can continue to operate without the primary domain 202a. The security domain 202b can be functionally isolated from the primary domain 202a to allow the security domain 202b to operate independently of the primary domain 202a. The secure domain PMIC 218b and / or other ECUs 300b may perform watchdog operations and / or challenge-response operations for the primary domain 202a and / or the secure domain 202b to detect whether the primary domain 202a and / or the secure domain 202b suspends operations or is hung or unresponsive in operation.
[0069] If the primary domain PMIC 218a has a functional safety error or warning, the primary domain PMIC 218a may notify the safety domain 202b and / or the safety domain PMIC 218b, for example, via at least one error pin routed from the primary domain PMIC 218a to the safety domain 202b, the safety domain PMIC 218b, and / or the ECU 300b. In addition to or in lieu of the error pin (e.g., via a communication interface from the PMIC 218b), the communication of the functional safety error or warning from the primary domain PMIC 218b to the safety domain 202b, the safety domain PMIC 218b, and / or the ECU 300b may be performed via one or more communication bus interfaces (e.g., a serial peripheral interface (SPI), a UART, an inter-integrated circuit (IIC)). 2 C) etc.) occurs. In response to detecting such an error, the primary domain PMIC 218a may drive the shutdown of the primary domain 202a. The SoC level shutdown may be performed with the security domain PMIC 218b driving the shutdown of the security domain 202b. In some aspects, the security domain 202b may continue to operate without the primary domain 202a to provide a degraded operating mode. For some aspects, the security domain 202b may request the security domain PMIC 218b to shut down the security domain 202b.
[0070] If the safety domain PMIC 218b has a functional safety error or warning, the safety domain PMIC 218b may notify the primary domain 202a via at least one error pin routed from the safety domain PMIC 218b to the primary domain 202a. In some aspects, in addition to or as an alternative to the error pin, the communication of the functional safety error or warning from the safety domain PMIC 218b to the primary domain 202a may be via a communication bus interface (e.g., SPI, UART, I2C, etc.). 2C, etc.) occurs. Similarly, in some aspects, a suitable communication interface can relay an error in the safety domain PMIC 218b to the ECU 300b. In response to detecting such an error, the primary domain 202a can notify the other ECUs 300b of the error via the first bus 330a. The primary domain 202a can instruct the primary domain PMIC 218a to shut down the primary domain 202a. The safety domain PMIC 218b can shut down the safety domain 202b. In some cases, the primary domain 202a can instruct the safety domain PMIC 218b to shut down the safety domain 202b.
[0071] If the main domain 202a has a functional safety error or warning, the main domain 202a can notify the error to the safety domain PMIC 218b via the error pin routed from the SoC 200 to the safety domain PMIC 218b. In response to detecting such an error, the safety domain PMIC 218b can instruct the main domain PMIC 218a to shut down the main domain 202a, and in some cases, the safety domain PMIC 218b can notify the error to other ECUs 300b via the communication link 332b. In response to detecting such an error, the SoC 200 can instruct the main domain PMIC 218a to shut down the main domain 202a. In response to detecting such an error, the safety domain 202b can notify the error to other ECUs 300b via the second bus 330b. In some cases, the safety domain 202b can instruct the main domain PMIC 218a to shut down the main domain 202a, and the safety domain 202b can continue to operate when the main domain 202a is inoperable. In some cases, the secure domain 202b may continue to operate without transmitting a shutdown instruction to the master domain PMIC 218a.
[0072] If the safety domain 202b has a functional safety error or warning, the safety domain 202b can notify the safety domain PMIC 218b via an error pin routed from the SoC 200 to the safety domain PMIC 218b. In response to detecting such an error, the safety domain 202b can instruct the main domain 202a to shut down. In response to detecting such an error, the main domain 202a can notify the other ECUs 300b of the error associated with the safety domain 202b. The safety domain 202b can instruct the safety domain PMIC 218b to shut down the safety domain 202b. In some cases, the main domain 202a may not be able to continue to operate if the safety domain 202b is inoperable.
[0073] The SoC 200 may be configured to communicate with other ECUs 300b via at least one of the first bus 330a, the second bus 330b, the primary domain PMIC 218a, and / or the safety domain PMIC 218b without a vehicle interface processor (e.g., a microcontroller unit (MCU), also referred to as a "safety MCU" or an external safety monitor) coupled between the safety domain 202b (or PMIC 218) and other ECUs 300b. A direct communication link between the SoC 200 (and PMIC 218) and other ECUs 300b may reduce the complexity and cost associated with the ECU 300a. In certain aspects, for example, in situations where one or more of the buses 330 (and / or one or more of the communication links 332) cannot be used for communication, or when certain safety subsystems within the SoC 200 or PMIC218 detect a functional safety error, a direct communication link between the SoC 200 and the other ECUs 300b may provide a redundant communication path, thereby allowing the SoC 200 and the other ECUs 300b to communicate with each other.
[0074] Figure 4 4 is a flow chart depicting example operations 400 for operating a vehicle (eg, vehicle 100). Operations 400 may be performed, for example, by a SoC (eg, SoC 200) or an SoC-based ECU (eg, Figure 3 The SoC-based ECU 300a) is executed, hereinafter referred to as "SoC / ECU".
[0075] Operations 400 may optionally begin at block 402, where the SoC / ECU may detect an error (or fault) associated with a SoC (e.g., SoC 200) having a primary domain (e.g., primary domain 202a) and a security domain (e.g., security domain 202b). For example, the primary domain, the security domain, and / or any PMIC may detect an error. The primary domain may be coupled to a first bus (e.g., first bus 330a) for communicating with one or more ECUs (e.g., other ECUs 300b), and the security domain may be coupled to a second bus (e.g., second bus 330b) for communicating with one or more ECUs.
[0076] At block 404, the SoC / ECU may indicate the error to one or more ECUs via at least one of the first bus, the second bus, or a PMIC (e.g., PMIC 218a, 218b) in response to detecting the error. The PMIC may be configured to supply power to the primary domain or the safety domain. As an example, the SoC / ECU may indicate the error via the first bus in response to the error being associated with the safety domain, and the SoC / ECU may indicate the error via the second bus in response to the error being associated with the primary domain.
[0077] At block 406, the SoC / ECU may perform one or more actions in response to detecting the error. For example, the SoC / ECU may shut down a component that encountered the error (e.g., the primary domain 202a). In some cases, the SoC / ECU may allow a component to operate in a degraded or sub-operational state. For example, assuming there is an error associated with an environmental system controlled by the primary domain 202a, the SoC / ECU may allow the primary domain 202a to continue to perform other operations without the environmental system. For some aspects, the SoC / ECU may transfer operations associated with the affected component to another component. For example, the SoC / ECU may allow the safety domain 202b to perform some of the affected operations performed by the primary domain 202a.
[0078] If the error includes a functional safety error or warning associated with the SoC, the SoC / ECU may shut down the SoC at block 406. The SoC / ECU may output an indication of the error from the SoC to the PMIC. To indicate the error, the SoC / ECU may indicate the error to one or more ECUs via the PMIC in response to the PMIC obtaining an indication of the error from the SoC. The PMIC may communicate with one or more ECUs, and the PMIC may be coupled to a primary domain of the SoC or a security domain of the SoC. To shut down the SoC, the SoC / ECU may output an indication to shut down the SoC to a first PMIC (e.g., primary domain PMIC 218a) and a second PMIC (e.g., security domain PMIC 218b). The first PMIC may be coupled to the primary domain of the SoC, the second PMIC may be coupled to the security domain of the SoC, and the PMIC includes at least one of the first PMIC or the second PMIC. The SoC / ECU may power off the SoC via the first PMIC and the second PMIC in response to the indication to shut down the SoC.
[0079] In certain aspects, when the error includes a functional safety error or warning associated with the SoC, the SoC / ECU may cause the SoC to be restarted via the first PMIC and the second PMIC. The restart may include a complete power cycle, safety initialization, and self-test of the SoC (including the primary and safety domains, and the associated PMICs) before the SoC is again operationalized to perform safety functions. In this way, after safely shutting down the SoC, for example, in the case where the error is not permanent in nature and disappears after the restart, the SoC can be restarted.
[0080] In some cases, the error may include the SoC being unresponsive or the SoC suspending operation or hanging in operation. In such cases, to detect the error, the SoC / ECU may use the security domain of the SoC to detect that the error occurred at the primary domain of the SoC, for example, using a watchdog operation and / or a challenge-response operation. In some aspects, a PMIC (e.g., security domain PMIC 218b) may be coupled to the security domain; and to detect the error, the SoC / ECU may use the PMIC to detect that the error occurred at the security domain of the SoC, for example, using a watchdog operation and / or a challenge-response operation.
[0081] In some aspects, the error may include a functional safety error or warning associated with a first PMIC (e.g., a primary domain PMIC 218a or a secure domain PMIC 218b). In the case where the first PMIC supplies power to the primary domain, the SoC / ECU may output an indication of an error at the first PMIC to the secure domain of the SoC or from the first PMIC to the second PMIC (e.g., secure domain PMIC 218b). The first PMIC may be coupled to the primary domain of the SoC, the second PMIC may be coupled to the secure domain of the SoC, and the PMIC includes at least one of the first PMIC or the second PMIC. In order to perform one or more actions, the SoC / ECU may shut down at least the primary domain of the SoC. In some cases, the SoC / ECU may operate the secure domain of the SoC while shutting down the primary domain of the SoC. In the case where the first PMIC supplies power to the secure domain, the SoC / ECU may output an indication of an error at the first PMIC from the first PMIC to the primary domain of the SoC or one or more ECUs. The first PMIC may be coupled to the secure domain of the SoC. In order to perform one or more actions, the SoC / ECU may shut down the SoC.
[0082] For certain aspects, the error may include a functional safety error associated with a primary domain of the SoC. The SoC / ECU may indicate the error via a second bus coupled to the security domain of the SoC. The SoC / ECU may output an indication of the error from the SoC to a PMIC (e.g., primary domain PMIC218a). The PMIC may be coupled to the primary domain of the SoC. To perform one or more actions, the SoC / ECU may shut down at least the primary domain of the SoC in response to obtaining an indication of an error at the PMIC. In some cases, the SoC / ECU may operate the security domain of the SoC while shutting down the primary domain of the SoC.
[0083] In some aspects, the error may include the primary domain of the SoC being unresponsive or the primary domain suspending operation or hanging in operation. To detect the error, the SoC / ECU may use the security domain of the SoC to detect that the error occurred at the primary domain of the SoC. To indicate the error to one or more ECUs, the SoC / ECU may indicate the error to one or more ECUs via a second bus coupled to the security domain of the SoC. To perform one or more actions, the SoC / ECU may shut down at least the primary domain of the SoC. In some cases, the SoC / ECU may operate the security domain of the SoC while shutting down the primary domain of the SoC.
[0084] For certain aspects, the error may include a functional safety error associated with a security domain of the SoC. To indicate the error, the SoC / ECU may indicate the error to one or more ECUs via a first bus coupled to a primary domain of the SoC. In some cases, the SoC / ECU may indicate from the security domain of the SoC to the primary domain of the SoC to shut down the SoC, and the SoC / ECU may shut down the SoC at block 406.
[0085] The various operations of the above methods may be performed by any suitable component capable of performing the corresponding functions. The component may include various hardware and / or software components and / or modules, including but not limited to circuits, application specific integrated circuits (ASICs), or processors. For example, components for detecting, components for indicating, components for executing, components for using, components for closing, components for powering off, components for outputting, and / or components for operating may include a SoC (e.g., SoC200), a primary domain of the SoC (e.g., primary domain 202a), a security domain of the SoC (e.g., security domain 202b), one or more PMICs (e.g., primary domain PMIC 218a and / or security domain PMIC 218b), a bus coupled to the primary domain and / or security domain (e.g., bus 330), and / or a communication link coupled to the PMIC (e.g., communication link 332).
[0086] Example aspects
[0087] Specific implementation examples are described in the following numbered aspects:
[0088] Aspect 1: A method for operating a vehicle, the method comprising: detecting an error associated with a system on a chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; in response to detecting the error, indicating the error to the one or more ECUs via at least one of the first bus, the second bus, or a power management integrated circuit (PMIC), wherein the PMIC is configured to supply power to the primary domain or the security domain; and performing one or more actions in response to detecting the error.
[0089] Aspect 2: The method according to aspect 1, wherein indicating the error comprises: indicating the error via the first bus in response to the error being associated with the security domain; and indicating the error via the second bus in response to the error being associated with the primary domain.
[0090] Aspect 3: The method according to aspect 1 or 2, wherein: the error comprises a functional safety error associated with the SoC; and performing the one or more actions comprises shutting down the SoC or restarting the SoC.
[0091] Aspect 4: According to the method of Aspect 3, the method also includes: outputting an indication of the error from the SoC to the PMIC, wherein the PMIC is coupled to the primary domain of the SoC or the security domain of the SoC, and wherein indicating the error includes indicating the error to the one or more ECUs via the PMIC in response to the PMIC obtaining the indication of the error from the SoC, wherein the PMIC communicates with the one or more ECUs.
[0092] Aspect 5: A method according to Aspect 3 or 4, wherein shutting down the SoC comprises: outputting an indication to shut down the SoC to a first PMIC and a second PMIC, wherein the first PMIC is coupled to the main domain of the SoC, wherein the second PMIC is coupled to the security domain of the SoC, and wherein the PMIC comprises at least one of the first PMIC or the second PMIC; and powering off the SoC via the first PMIC and the second PMIC in response to the indication to shut down the SoC.
[0093] Aspect 6: The method according to any one of aspects 1 to 5, wherein the error includes the SoC being unresponsive or the SoC suspending operation.
[0094] Aspect 7: The method according to aspect 6, wherein detecting the error comprises using the secure domain of the SoC to detect that the error occurs at the primary domain of the SoC.
[0095] Aspect 8: The method of aspect 6, wherein the PMIC is coupled to the security domain, and wherein detecting the error comprises using the PMIC to detect that the error occurs at the security domain of the SoC.
[0096] Aspect 9: The method of any one of aspects 1 to 8, wherein the error comprises a functional safety error associated with the first PMIC.
[0097] Aspect 10: The method according to Aspect 9 further includes: outputting an indication of the error at the first PMIC to the security domain of the SoC or from the first PMIC to the second PMIC, wherein the first PMIC is coupled to the main domain of the SoC, wherein the second PMIC is coupled to the security domain of the SoC, wherein the PMIC includes at least one of the first PMIC or the second PMIC, and wherein performing the one or more actions includes at least shutting down the main domain of the SoC.
[0098] Aspect 11: The method according to aspect 10, wherein performing the one or more actions includes operating the security domain of the SoC while shutting down the primary domain of the SoC.
[0099] Aspect 12: According to the method of Aspect 9, the method also includes: outputting an indication of the error at the first PMIC from the first PMIC to the main domain of the SoC or the one or more ECUs, wherein the first PMIC is coupled to the security domain of the SoC, and wherein performing the one or more actions includes shutting down the SoC.
[0100] Aspect 13: The method according to any one of aspects 1 to 12, wherein the error comprises a functional safety error associated with the primary domain of the SoC.
[0101] Aspect 14: The method of aspect 13, wherein indicating the error comprises indicating the error via the second bus coupled to the security domain of the SoC.
[0102] Aspect 15: The method according to Aspect 13 or 14, the method further comprising: outputting an indication of the error from the SoC to the PMIC, wherein the PMIC is coupled to the main domain of the SoC, wherein performing the one or more actions includes shutting down at least the main domain of the SoC in response to obtaining the indication of the error at the PMIC.
[0103] Aspect 16: The method according to aspect 15, wherein performing the one or more actions includes operating the secure domain of the SoC while shutting down the primary domain of the SoC.
[0104] Aspect 17: The method according to any one of aspects 1 to 16, wherein the error includes the primary domain of the SoC becoming unresponsive or suspending operation.
[0105] Aspect 18: A method according to Aspect 17, wherein: detecting the error includes using the security domain of the SoC to detect that the error occurs at the primary domain of the SoC; and indicating the error to the one or more ECUs includes indicating the error to the one or more ECUs via the second bus coupled to the security domain of the SoC.
[0106] Aspect 19: The method of aspect 18, wherein performing the one or more actions comprises shutting down at least the primary domain of the SoC.
[0107] Aspect 20: The method according to aspect 19, wherein performing the one or more actions includes operating the secure domain of the SoC while shutting down the primary domain of the SoC.
[0108] Aspect 21: The method according to any one of aspects 1 to 20, wherein the error comprises a functional safety error associated with the security domain of the SoC.
[0109] Aspect 22: The method according to aspect 21, wherein indicating the error comprises indicating the error to the one or more ECUs via the first bus coupled to the primary domain of the SoC.
[0110] Aspect 23: The method according to Aspect 21 or 22 further comprises: instructing the primary domain of the SoC from the security domain of the SoC to shut down the SoC, wherein performing the one or more actions comprises shutting down the SoC.
[0111] Aspect 24: An apparatus for operating a vehicle, the apparatus comprising: a system on a chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; and a power management integrated circuit (PMIC), the power management integrated circuit (PMIC) being configured to supply power to the primary domain or the security domain, wherein at least one of the SoC or the PMIC is configured to: detect an error associated with the SoC, indicate the error to the one or more ECUs via at least one of the first bus, the second bus, or the PMIC in response to detecting the error, and perform one or more actions in response to detecting the error.
[0112] Aspect 25: An apparatus according to Aspect 24, wherein, in order to indicate the error: the primary domain is configured to indicate the error via the first bus in response to the error being associated with the security domain; and the security domain is configured to indicate the error via the second bus in response to the error being associated with the primary domain.
[0113] Aspect 26: The apparatus of aspect 24 or 25, wherein: the error comprises a functional safety error associated with the SoC; and to perform the one or more actions, the PMIC is configured to shut down the SoC.
[0114] Aspect 27: An apparatus according to any one of Aspects 24 to 26, wherein the SoC is configured to communicate with the one or more ECUs via at least one of the first bus, the second bus, or the PMIC without coupling a vehicle interface processor between the security domain and the one or more ECUs.
[0115] Aspect 28: An apparatus according to any one of Aspects 24 to 27, wherein the primary domain is configured to support at least up to Automotive Safety Integrity Level (ASIL) B, and wherein the safety domain is configured to support up to ASIL D.
[0116] Aspect 29: A device comprising: a memory comprising computer-executable instructions; and one or more processors configured to execute the computer-executable instructions and cause the device to perform a method according to any one of Aspects 1 to 23.
[0117] Aspect 30: An apparatus comprising means for performing the method according to any one of aspects 1 to 23.
[0118] Aspect 31: A non-transitory computer-readable medium comprising computer-executable instructions, which, when executed by one or more processors of a processing system, cause the processing system to perform the method according to any one of aspects 1 to 23.
[0119] Aspect 32: A computer program product embodied on a computer-readable storage medium, the computer program product comprising code for executing the method according to any one of aspects 1 to 23.
[0120] Aspect 33: A non-transitory computer-readable medium, comprising computer-executable instructions that, when executed by one or more processors of a processing system, cause the processing system to: detect an error associated with a system on a chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; in response to detecting the error, indicate the error to the one or more ECUs via at least one of the first bus, the second bus, or a power management integrated circuit (PMIC), wherein the PMIC is configured to supply power to the primary domain or the security domain; and perform one or more actions in response to detecting the error.
[0121] Aspect 34: An apparatus for operating a vehicle, the apparatus comprising: a component for detecting an error associated with a system on a chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; a component for indicating the error to the one or more ECUs via at least one of the first bus, the second bus, or a power management integrated circuit (PMIC) in response to detecting the error, wherein the PMIC is configured to supply power to the primary domain or the security domain; and a component for performing one or more actions in response to detecting the error.
[0122] Additional considerations
[0123] Within this disclosure, the word "exemplary" is used to mean "serving as an example, instance, or illustration." Any specific implementation or aspect described herein as "exemplary" is not necessarily to be construed as superior or superior to other aspects of the disclosure. Likewise, the term "aspect" does not require that all aspects of the disclosure include the discussed features, advantages, or modes of operation. The term "coupled" is used herein to refer to a direct or indirect coupling between two objects. For example, if object A physically contacts object B, and object B contacts object C, objects A and C may still be considered to be coupled to each other, even though objects A and C are not in direct physical contact with each other. For example, a first object may be coupled to a second object, even though the first object has never been in direct physical contact with the second object. The term "circuit" is used broadly and is intended to include hardware implementations of both electronic devices and conductors that, when connected and configured, enable the functions described in this disclosure to be performed without limitation to the type of electronic circuit.
[0124] The apparatuses and methods described in the detailed description are illustrated in the drawings by various blocks, modules, components, circuits, steps, processes, algorithms, etc. (collectively referred to as “elements”). These elements may be implemented using, for example, hardware.
[0125] One or more of the components, steps, features, and / or functions illustrated herein may be rearranged and / or combined into a single component, step, feature, or function, or embodied in several components, steps, or functions. Additional elements, components, steps, and / or functions may also be added without departing from the features disclosed herein. The devices, equipment, and / or components illustrated herein may be configured to perform one or more of the methods, features, or steps described herein.
[0126] It should be understood that the specific order or hierarchy of steps in the disclosed methods is an illustration of an exemplary process. It should be understood that the specific order or hierarchy of steps in these methods can be rearranged based on design preferences. The attached method claims provide elements of various steps in an example order, but are not intended to be limited to the specific order or hierarchy provided unless explicitly stated herein.
[0127] The preceding description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects. Therefore, the claims are not intended to be limited to the various aspects shown herein, but to conform to the full range consistent with the text of the claims, wherein unless explicitly stated otherwise, the reference to the element in the singular form is not intended to mean "one and only one", but "one or more". Unless otherwise explicitly stated, the term "some" refers to one or more. The phrase "at least one" mentioned in the list of items refers to any combination of those items, including a single member. For example, "at least one of the following: a, b or c" is intended to at least cover: a, b, c, ab, ac, bc and abc, and any combination with multiples of the same element (e.g., aa, aaa, aab, aac, abb, acc, bb, bbb, bbc, cc and ccc or any other order of a, b and c). All structural and functional equivalents to the elements of the various aspects described throughout this disclosure that are or later become known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be covered by the claims. In addition, nothing disclosed herein is intended to be dedicated to the public regardless of whether such disclosure is explicitly recited in the claims. No claim element should be interpreted under the provisions of 35 U.S.C. §112(f) unless the element is explicitly recited using the phrase "means for..." or, in the case of a method claim, the phrase "step for..." is used to recite the element.
[0128] It is to be understood that the claims are not limited to the precise configuration and components illustrated above. Various modifications, changes and variations may be made in the arrangement, operation and details of the methods and apparatus described above without departing from the scope of the claims.
Claims
1. A method of operating a vehicle, the method comprising: detecting errors associated with a system on chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; indicating the error to the one or more ECUs via at least one of the first bus, the second bus, or a power management integrated circuit (PMIC) in response to detecting the error, wherein the PMIC is configured to supply power to the primary domain or the security domain; as well as One or more actions are performed in response to detecting the error.
2. The method of claim 1 , wherein indicating the error comprises: indicating the error via the first bus in response to the error being associated with the security domain; as well as The error is indicated via the second bus in response to the error being associated with the primary domain.
3. The method according to claim 1, wherein: The error comprises a functional safety error associated with the SoC; and Performing the one or more actions includes shutting down the SoC or restarting the SoC.
4. The method according to claim 3, further comprising: An indication of the error is output from the SoC to the PMIC, wherein the PMIC is coupled to the primary domain of the SoC or the security domain of the SoC, and wherein indicating the error comprises indicating the error to the one or more ECUs via the PMIC in response to the PMIC obtaining the indication of the error from the SoC, wherein the PMIC communicates with the one or more ECUs.
5. The method of claim 3, wherein shutting down the SoC comprises: outputting an indication to shut down the SoC to a first PMIC and a second PMIC, wherein the first PMIC is coupled to the primary domain of the SoC, wherein the second PMIC is coupled to the secure domain of the SoC, and wherein the PMIC includes at least one of the first PMIC or the second PMIC; as well as The SoC is powered off via the first PMIC and the second PMIC in response to the instruction to shut down the SoC. The method of claim 1 , wherein the error comprises the SoC being unresponsive or the SoC suspending operation. 7 . The method of claim 6 , wherein detecting the error comprises using the secure domain of the SoC to detect that the error occurs at the primary domain of the SoC. 8 . The method of claim 6 , wherein the PMIC is coupled to the security domain, and wherein detecting the error comprises using the PMIC to detect that the error occurs at the security domain of the SoC.
9. The method of claim 1, wherein the error comprises a functional safety error associated with the first PMIC.
10. The method according to claim 9, further comprising: Outputting an indication of the error at the first PMIC to the secure domain of the SoC or from the first PMIC to a second PMIC, wherein the first PMIC is coupled to the primary domain of the SoC, wherein the second PMIC is coupled to the secure domain of the SoC, wherein the PMICs include at least one of the first PMIC or the second PMIC, and wherein performing the one or more actions includes shutting down at least the primary domain of the SoC. 11 . The method of claim 10 , wherein performing the one or more actions comprises operating the secure domain of the SoC while shutting down the primary domain of the SoC.
12. The method according to claim 9, further comprising: An indication of the error at the first PMIC is output from the first PMIC to the primary domain of the SoC or the one or more ECUs, wherein the first PMIC is coupled to the safety domain of the SoC, and wherein performing the one or more actions includes shutting down the SoC.
13. The method of claim 1, wherein the error comprises a functional safety error associated with the primary domain of the SoC. 14 . The method of claim 13 , wherein indicating the error comprises indicating the error via the second bus coupled to the security domain of the SoC.
15. The method according to claim 13, further comprising: An indication of the error is output from the SoC to the PMIC, wherein the PMIC is coupled to the primary domain of the SoC, wherein performing the one or more actions includes shutting down at least the primary domain of the SoC in response to obtaining the indication of the error at the PMIC. 16 . The method of claim 15 , wherein performing the one or more actions comprises operating the secure domain of the SoC while shutting down the primary domain of the SoC.
17. The method of claim 1, wherein the error comprises the primary domain of the SoC becoming unresponsive or suspending operation.
18. The method of claim 17, wherein: Detecting the error includes using the secure domain of the SoC to detect that the error occurs at the primary domain of the SoC; and Indicating the error to the one or more ECUs includes indicating the error to the one or more ECUs via the second bus coupled to the security domain of the SoC.
19. The method of claim 18, wherein performing the one or more actions comprises shutting down at least the primary domain of the SoC.
20. The method of claim 19, wherein performing the one or more actions comprises operating the secure domain of the SoC while shutting down the primary domain of the SoC.
21. The method of claim 1, wherein the error comprises a functional safety error associated with the security domain of the SoC.
22. The method of claim 21, wherein indicating the error comprises indicating the error to the one or more ECUs via the first bus coupled to the primary domain of the SoC.
23. The method according to claim 21, further comprising: Instructing, from the secure domain of the SoC to the primary domain of the SoC, to shut down the SoC, wherein performing the one or more actions includes shutting down the SoC.
24. A device for operating a vehicle, the device comprising: A system on chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; as well as a power management integrated circuit (PMIC) configured to supply power to the primary domain or the secure domain, wherein at least one of the SoC or the PMIC is configured to: detecting errors associated with the SoC, indicating the error to the one or more ECUs via at least one of the first bus, the second bus, or the PMIC in response to detecting the error, and One or more actions are performed in response to detecting the error.
25. The apparatus of claim 24, wherein to indicate an error: The master domain is configured to indicate the error via the first bus in response to the error being associated with the security domain; and The secure domain is configured to indicate the error via the second bus in response to the error being associated with the primary domain.
26. The apparatus of claim 24, wherein: The error comprises a functional safety error associated with the SoC; and To perform the one or more actions, the PMIC is configured to shut down the SoC.
27. The apparatus of claim 24, wherein the SoC is configured to communicate with the one or more ECUs via at least one of the first bus, the second bus, or the PMIC without a vehicle interface processor coupled between the security domain and the one or more ECUs.
28. The apparatus of claim 24, wherein the primary domain is configured to support at least up to Automotive Safety Integrity Level (ASIL) B, and wherein the safety domain is configured to support up to ASIL D.
29. A non-transitory computer readable medium comprising computer executable instructions that, when executed by one or more processors of a processing system, cause the processing system to: detecting errors associated with a system on chip (SoC) having a primary domain and a security domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the security domain is coupled to a second bus for communicating with the one or more ECUs; indicating the error to the one or more ECUs via at least one of the first bus, the second bus, or a power management integrated circuit (PMIC) in response to detecting the error, wherein the PMIC is configured to supply power to the primary domain or the security domain; as well as One or more actions are performed in response to detecting the error.
30. A device for operating a vehicle, the device comprising: Components for detecting errors associated with a system on a chip (SoC) having a primary domain and a secure domain, wherein the primary domain is coupled to a first bus for communicating with one or more electronic control units (ECUs), and wherein the secure domain is coupled to a second bus for communicating with the one or more ECUs; means for indicating the error to the one or more ECUs via at least one of the first bus, the second bus, or a power management integrated circuit (PMIC) in response to detecting the error, wherein the PMIC is configured to supply power to the primary domain or the secure domain; as well as Means for performing one or more actions in response to detecting the error.