Data processing apparatus

By designing multiple data processing components and writeable configuration memory in the data processing device, the high separation and adjustable correlation between different domains are achieved, the problem of difficult to meet high availability requirements in the prior art is solved, and the high availability of the system in the event of failure and the security of different applications is achieved.

CN120124062APending Publication Date: 2025-06-10INFINEON TECHNOLOGIES AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411786989.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-08
Filing Date
2024-12-06
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

When existing data processing equipment meets the operational security and data security requirements of different domains, it is difficult to effectively separate the cross-coupling of different domains, resulting in the system being unable to meet the high availability requirements when there is a failure.

Method used

A data processing device is designed, including a plurality of data processing components and a writeable configuration memory. The data processing component exchanges synchronization information in pairs at a preset synchronization point, and configures the memory to store whether the synchronization information needs to be exchanged for each reset type so that the data processing component continues or stops processing without the synchronization information exchange.

Benefits of technology

Through this design, high separation and adjustable correlation between different domains are achieved, ensuring that the system can still meet high availability requirements in the event of failure and meet operational safety and data security requirements in different applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124062A_ABST
    Figure CN120124062A_ABST
Patent Text Reader

Abstract

According to one embodiment, a data processing device is described having a plurality of data processing components which are designed to exchange respective synchronization information in pairs with one another at predetermined synchronization points, and a writable configuration memory, the writable configuration memory is designed to store, for each reset type of a plurality of reset types, whether respective synchronization information needs to be exchanged for all synchronization points, so that respective pairs of data processing components allow their processing to continue beyond the synchronization points. The data processing means are designed to continue or not continue the processing of the data processing means beyond a synchronization point in the absence of a synchronization information exchange depending on the content of the configuration memory.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments generally relate to data processing devices. Background Art

[0002] Data processing devices for critical applications, such as control devices for vehicles, usually have high requirements for operational safety and possibly also data security. However, since the cost of providing measures to ensure a high level of operational safety and / or data security for all participating data processing components would be too high, typically such measures are only provided for those data processing components whose operational safety and possibly data security are required for the operational safety and, if necessary, data security of the overall system. However, in this case, a certain separation is desired between the data processing components provided with such measures and those not provided with such measures, so as not to compromise the operational safety and, if necessary, data security of the overall system. However, the data processing components should cooperate reliably with respect to the given requirements for operational safety and data security for a given application scenario. Summary of the Invention

[0003] According to one embodiment, there is provided a data processing device having: a plurality of data processing components configured to: pairwise exchange respective synchronization information with each other at preset synchronization points; and a writable configuration memory configured to: store, for each of a plurality of reset types, whether it is necessary to exchange the respective synchronization information for all synchronization points so that the corresponding pairs of data processing components are allowed to continue their processing beyond the synchronization points. The data processing components are configured to: continue or not continue the processing of the data processing components beyond the synchronization points based on the content of the configuration memory in the absence of synchronization information exchange. Brief Description of the Drawings

[0004] The drawings do not reflect actual size ratios and are intended to illustrate the principles of different embodiments. Various embodiments are described below with reference to the following drawings.

[0005] Figure 1 Shows a data processing device.

[0006] Figure 2 Shows an example of an early start-up phase according to one embodiment.

[0007] Figure 3 Illustrates the scalability of the correlation between two data processing device domains.

[0008] Figure 4 Shows a data processing device according to one embodiment. Detailed Description

[0009] The following detailed description refers to the accompanying drawings, which show details and embodiments. The embodiments are described in detail so that those skilled in the art can implement the present invention. Other embodiments are also feasible, and the embodiments can be changed in terms of structure, logic, and electricity without departing from the subject matter of the present invention. Different embodiments are not necessarily mutually exclusive, but different embodiments can be combined with each other so that new embodiments are formed. In the scope of this specification, the terms "connect", "couple", and "interface" are used to describe direct connections and indirect connections, direct or indirect couplings, and direct or indirect interfaces.

[0010] Figure 1 shows a data processing device 100.

[0011] The data processing device 100 has a plurality of data processing components 101, which are associated with different (operational safety - data security) domains 102. The domains differ in that corresponding requirements in terms of operational safety (Safety) and data security (Security) are associated with the domains, and these requirements are at least partially different between the domains 102. For example, the data processing device 100 is an electronic control unit (ECU, Electronic Control Unit) of a vehicle, and for one of the domains 102, a specific ASIL (Automotive Safety Integrity Level) or CAL (Cyber Security Assurance Level) is required, such as ASIL-D for a passenger safety-critical function, while for another domain in the domains 102, it is a "QM" (Quality Management) domain, and only low operational safety and data security requirements exist for the QM domain. However, the data processing device 100 can also be different types of data processing devices 100 with different domains, and these different domains have corresponding (at least partially different) operational safety and data security requirements, such as a microcontroller for another application, a SoC (System on Chip) for any application, etc.

[0012] Therefore, each domain 102 provides a specific function, and the domain should do so while meeting specific operational safety and data security requirements, that is, requirements given by corresponding specifications and / or standards such as ISO26262, ISO21434, or IATF61508. Here, each domain 102 is a combination of hardware and software, that is, the data processing components 101 belonging to the corresponding domain 102 execute specific software, such as firmware, an operating system (OS), or corresponding OS components and one or more application programs (or application program components).

[0013] To meet the corresponding operational safety and / or data security requirements for a single domain 102, various mechanisms (redundant processing, such as lockstep, error correction mechanisms (EDC (Error Detection and Correction), etc.)) are typically provided.

[0014] However, if the requirements of the two domains 102 are different, the two domains 102 need to be separated so that the domain that only meets the lower requirements regarding operational safety and / or data security does not negatively impact the operational safety and / or data security of the other domain (e.g., because there is an insecure communication channel between the domains, or because due to the correlation of the first domain with the second domain, the first domain would be paralyzed by a successful attack on the second domain), such that the operational safety and / or data security requirements of the other domain are no longer met.

[0015] Therefore, difficulties arise when cross - coupling (in English: cross - coupling) is required between the domains 102. This is complicated by the fact that for some domains 102 (i.e., for the functions they provide), a high availability (in English: availability) is required even if the other domain 102 fails. For example, if due to the failure of the domain 102 responsible for secure communication (e.g., encryption), it is not possible to have (in the sense of data security) secure communication between the domain 102 that calculates the steering signal and the corresponding actuator, the steering of the autonomous vehicle should still function. If there is no cross - coupling, corresponding measures can be set for each domain such that the corresponding operational safety and / or data security requirements are met. Therefore, it is desirable to reduce cross - coupling, that is, to keep the domains 102 separated from each other as much as possible.

[0016] If the new data - processing device 100 is started, this initial state is particularly important: the initial state serves as a trust basis (“root of trust”, “root of integrity”) for subsequent software components in this process. This is especially important if critical tasks (e.g., operation - safety - critical tasks in a vehicle) should be executed.

[0017] If the domains 102 have corresponding data - security and operation - security mechanisms (such as lock - step and error - correction), etc., then if the cross - coupling with other domains 102 that do not have such measures (due to lower requirements for them) is kept low enough as described above, the operation and data security of the corresponding domains 102 can be maintained. Therefore, in the early startup phase (i.e., the “pre - operating - system phase” (or “pre - OS phase”), that is, the phase after startup or reset until software, typically operating - system components, are loaded), it is already desirable to selectively prevent or reduce cross - coupling between the domains. Of course, it should be noted here that: specific measures such as error - correction mechanisms have not been established (i.e., have not come into play) in the early startup phase. Therefore, there are special cases in the early startup phase for which special, dedicated handling methods are desired to meet different operational safety and / or data security requirements.

[0018] The data processing device 100 can enter a pre-OS boot state not only after being powered on (power-on reset (PORST)), but also after a software reset, as it can typically be performed in response to an error (e.g., executed multiple times during the operation of a vehicle control loop). According to various embodiments, these two cases are differentiated, as will be explained in more detail below, because for example, it is not necessary to check the integrity of the program code every time a software reset occurs (e.g., because the previous check results are still valid).

[0019] According to different embodiments, a processing method is provided that enables handling errors in the early startup phase to meet specific availability requirements, such as ensuring that the control device can provide passenger safety-critical functions in at least a simplified form (e.g., steering without encrypted communication) until the next reset (e.g., if the QM domain that delegates the encryption task fails). However, due to different operational safety and / or data security requirements depending on the application using the data processing device 100 (e.g., for some applications, encryption is critical, while in other applications, the failure of encryption is tolerable in favor of the basic functions that should be ensured (e.g., steering)), according to different embodiments, it is proposed that for each type of reset (e.g., power-on reset or software reset), it can be configured which domains 102 are critical and which are not. This is manifested in the fact that it is configurable whether a domain 102 must wait for synchronization with another domain 102 before proceeding in its corresponding processing (e.g., starting to load its operating system).

[0020] Figure 2 An example of the early startup phase according to one embodiment is shown.

[0021] In the example, there are two domains, where the first processor 201 belongs to the first domain and the second processor 202 belongs to the second domain. For example, the first processor 201 provides specific "host" functions, and the second processor 202 provides (data) security functions available to the first processor 201 (e.g., encryption of control signals).

[0022] The early startup phase begins with a reset, which can be a power-on reset or also a software reset. The two processors 201, 202 then operate according to the firmware 203 of the data processing device 100 (the firmware is stored in a non-volatile memory of the data processing device 100, which is, for example, one of the components 101).

[0023] The early startup phase ends with the loading of software 204 (operating system component or application).

[0024] At a specific synchronization point (defined in the firmware 203), synchronization 205 occurs between the two processors 201, 202, that is, communication for synchronizing the two processors 201, 202 occurs respectively. According to different embodiments, it is proposed that for each reset type (for example, power-on reset and software reset), it can be configured which part (for example, none, part, or all) of the synchronization point defined (in the firmware 203) must be respected so that the two processors are allowed to continue their processing. If the synchronization point is defined as blocking in this sense for a specific type of reset, then in each early startup phase according to the reset type, before the two processors 201, 202 are allowed to continue their respective processing, the two processors 201, 202 must have reached the synchronization point (that is, the corresponding phase of the corresponding processing of the processors) (that is, the corresponding synchronization 205 has occurred).

[0025] The processing method for synchronization is designed such that on the one hand, a separation related to the reset type of the two processors 201, 202 is provided or can be provided (for the above reasons), but the timing requirements of the corresponding reset type can also be complied with, and finally a consistent state of the data processing device 100 is reached at the end of the early startup phase. Due to the adjustable correlation (and thus coupling) of the two domains (here the two processors 201, 202), it is feasible to avoid restrictions on availability (if this is reasonable from the perspective of operational safety and data security).

[0026] For synchronization 205, for example, one or more registers (English Mailbox) for data exchange are set for each processor 201, 202, and write access or read-only access can be performed on the registers according to the communication direction. When the corresponding processor 201, 202 has reached the corresponding processing phase, the corresponding processor 201, 202 writes synchronization information to the register allocated to it, and the other processor 201, 202 can read it to check whether the processor 201, 202 has reached a specific synchronization point. In this way, a protected one-way communication path between domains can be achieved, thus realizing a high degree of separation between the two domains.

[0027] For example, it can be illustrated in the non-volatile memory of the data processing device 100 (e.g., an area of the flash memory of the data processing device 100) (e.g., by a user instruction, where the user can be, for example, the manufacturer of a vehicle using the data processing device 100): which of multiple configuration options should be followed to achieve an adjustable correlation between two domains. The configuration options / adjustable variants are irrevocably confirmed for the user via the control flow of the firmware. The configuration options can be set individually for each of multiple reset types (i.e., confirmed by correspondingly writing to the non-volatile memory). Setting the correlation, i.e., setting which synchronization points are blocked (after a reset of the corresponding reset type), achieves setting the sensitivity of one domain to the failure of another domain.

[0028] Table 1 shows examples of possible settings for each of the following reset types

[0029] · "Cold PORST" (CPORST): Cold power-on reset, i.e., the power-on reset when starting to supply power to the data processing device 100, also known as cold start or cold start reset

[0030] · "Warm PORST" (WPORST): Warm power-on reset, i.e., the power-on reset triggered via the pins of the data processing device 100, also known as warm start or warm start reset

[0031] · "SysRST": Software reset triggered by the operating system

[0032] · "AppRST": Software reset triggered by an application

[0033]

[0034] Table 1

[0035] Here, the configuration area in the non-volatile memory for selecting the configuration options for each reset type includes 12 bits (0 - 11), where three bits are set for each reset type, and the bits implement: confirming one of the following three configuration options, where in this example the configuration (i.e., each 3-bit configuration word) also indicates: in what order the domains continue their processing after the end of the early start phase:

[0036] · "Foreground" (bit combination 100): All synchronization points are blocked (i.e., in this example, "Foreground" implies "blocked"); after the end of the early start phase ("enforced sequencing"), the domains follow the defined order (e.g., in the firmware 203). For example, the second processor 202 first starts to execute the user-defined program code (e.g., establishing secure communication for the first processor 201)

[0037] · "Background Critical Blocking" (bit combination 010): A synchronization point defined as critical in (firmware 203) is blocking, and domains can continue in any order at the end of the early startup phase, as derived from the run time of the program code (firmware) executed by the domain ("natural sequencing").

[0038] · "Background Unblocked" (bit combination 001): No synchronization point is blocking, and domains can continue in any order at the end of the early startup phase, as derived from the run time of the program code (firmware) executed by the domain

[0039] Any other bit combination other than these three bit combinations is invalid and results in an error state.

[0040] Critical synchronization points are generally divided into two categories: the startup and synchronization events of shared (i.e., cross - domain) hardware functions (i.e., communication between running program codes). Examples of shared hardware functions can be, for example, the non - volatile memory of a data processing device, because, for example, further processing is not possible if the non - volatile memory does not work. In contrast, synchronization with a random number generator, for example, may be non - critical because random numbers can be omitted (e.g., by sacrificing a certain degree of data security tolerable for the current application). Here, the non - volatile memory and the random number generator are examples of components shared by multiple (other) domains. The setting regarding whether synchronization with such (e.g., shared) components is mandatory (i.e., blocking) enables: certain (reset - type - related) error handling of the component in the early startup phase.

[0041] Figure 3 The above - mentioned setting options of "blocking", "critical blocking", and "unblocked" for synchronization points and the above - mentioned setting options for the sequencing after the early startup phase illustrate the scalability of the correlation between two domains.

[0042] The setting on the left (marked by dotted lines), i.e., unblocked, natural sequencing, ensures that: even if an error occurs in another domain, the error - free domain can complete the early startup phase. That is to say: it ensures the execution of the next software phase (e.g., bootloader, application, operating system startup) in the error - free domain. This implies that: the handling of the error domain can be flexibly designed in the said software phase (from ignoring the error to emergency operation mode). In this setting, two aspects can be problematic: i. The system's response time to potentially critical events is delayed (by "moving" from the early startup phase to a subsequent phase), ii. The detection heuristic regarding random / intentionally introduced errors is reduced.

[0043] The middle (dashed-line marked) setting, i.e., critical blocking, forced sorting of PORST, and natural sorting of SW reset (i.e., a mixed setting of sorting), is implemented to perform early error handling on shared components (i.e., components that are critical in the sense of executing two domains), and to start the defined order of subsequent software components in the case of PORST, while the overall system does not completely fail due to the failure of one domain during software reset. For example, therefore, during software reset in a vehicle (performed by a vehicle controller), a mode with limited functionality (but maintaining important driving functions) can be implemented. The right (solid-line bordered) setting enables maximum possible error detection, which comes at the cost of reduced availability and is thus generally not a good compromise in terms of application.

[0044] In summary, according to different embodiments, a data processing device as shown in Figure 4 is provided.

[0045] Figure 4 FIG. shows a data processing device 400 according to one embodiment.

[0046] The data processing device 400 has a plurality of data processing components 401, which are designed (e.g., by the firmware of the data processing device) to exchange corresponding synchronization information pairwise with each other at (each pair, if necessary separately) preset synchronization points (i.e., for example, each synchronization point is defined for a corresponding pair of data processing components).

[0047] The data processing device 400 also has a configurable (by the user) configuration memory 402 (e.g., one or more configuration registers), which is designed to store, for each of a plurality of reset types (as (memory) content), whether it is necessary to exchange corresponding synchronization information for all synchronization points so that the corresponding pair of data processing components is allowed (or not allowed) to continue their processing beyond the synchronization point.

[0048] The data processing component 401 is designed to continue or not continue the processing of the data processing component beyond the synchronization point according to the content of the configuration memory in the absence of the exchange of synchronization information.

[0049] According to different embodiments, the synchronization points that must be taken into account by the data processing components (processors, memories, control circuits, etc.) are configurable. This enables adaptation to the requirements of operational safety and / or data security regarding the corresponding application scenarios.

[0050] Different embodiments are described below.

[0051] Embodiment 1 is the data processing device 400 as described with reference to Figure 4 as described.

[0052] Embodiment 2 is the data processing device according to Embodiment 1, wherein the configuration memory is designed to store, for each of a plurality of reset types: whether it is necessary to exchange the corresponding synchronization information for all synchronization points or only for a preset part of the synchronization points, so that the corresponding pairs of data processing components are allowed to continue their processing beyond the synchronization point.

[0053] Embodiment 3 is the data processing device according to Embodiment 2, wherein the data processing component is designed to: if it is stored in the configuration memory that it is only necessary to exchange the corresponding synchronization information for a preset part of the synchronization points, so that the corresponding pairs of data processing components are allowed to continue their processing beyond the synchronization point, and the reached synchronization point does not belong to the preset part, then even if the corresponding synchronization information is not exchanged, the processing of the data processing component is continued after the reached synchronization point after the reset.

[0054] Embodiment 4 is the data processing device according to Embodiment 2 or 3, having firmware that defines which synchronization points belong to the preset part of the synchronization points.

[0055] Embodiment 5 is the data processing device according to any one of Embodiments 1 to 4, wherein the configuration memory is designed to store, for each of a plurality of reset types: whether it is necessary to exchange the corresponding synchronization information for all synchronization points or for any synchronization point, so that the corresponding pairs of data processing components are allowed to continue their processing beyond the synchronization point.

[0056] Embodiment 6 is the data processing device according to Embodiment 5, wherein the data processing component is designed to: if it is stored in the configuration memory that it is not necessary to exchange the corresponding synchronization information for any synchronization point, so that the corresponding pairs of data processing components are allowed to continue their processing beyond the synchronization point, then even if the corresponding synchronization information is not exchanged, the processing of the data processing component is continued after the reached synchronization point after the reset.

[0057] Embodiment 7 is the data processing device according to any one of Embodiments 1 to 6, wherein the plurality of reset types include a cold start reset, a warm start reset, and / or a software reset.

[0058] Embodiment 8 is the data processing device according to any one of Embodiments 1 to 7, wherein the content of the configuration memory is at least partially different for different reset types among the reset types.

[0059] Embodiment 9 is a data processing device according to any one of Embodiments 1 to 8, wherein the configured memory is further designed to: for each of a plurality of reset types, store: the sorting according to which the data processing component continues its processing after one of the synchronization points or after another preset synchronization point must follow or allow the implementation of a preset sorting as obtained by the corresponding processing duration, and the data processing component is designed to: continue its processing after the synchronization point or after another synchronization point according to the content of the configured memory.

[0060] Embodiment 10 is a data processing device according to Embodiment 9, wherein the synchronization point or another synchronization point is the synchronization point at the end of the pre - operating system phase of the data processing device.

[0061] Embodiment 11 is a data processing device according to Embodiment 9 or 10, wherein the processing after the synchronization point or another preset synchronization point includes loading an operating system component or an application.

[0062] Embodiment 12 is a data processing device according to any one of Embodiments 1 to 11, wherein at least a part of the data processing components is a processor.

[0063] Embodiment 13 is a data processing device according to any one of Embodiments 1 to 12, wherein the data processing components are at least partly equipped with different measures for establishing operational security and / or data security.

[0064] Embodiment 14 is a data processing device according to any one of Embodiments 1 to 13, wherein the data processing component is designed to: exchange synchronization information via one or more synchronization memories written to and read from by the data processing component.

[0065] Embodiment 15 is a data processing device according to Embodiment 14, wherein a first synchronization memory and a second synchronization memory are provided for each pair of data processing components, wherein the first synchronization memory can only be written to by the first data processing component of the pair, and the second synchronization memory can only be written to by the second data processing component of the pair.

[0066] Although the present invention has been shown and described mainly with reference to specific embodiments, those skilled in the art should understand that: various changes in design and details can be made to the present invention without departing from the spirit and scope of the present invention as defined by the subsequent claims. Therefore, the scope of the present invention is determined by the appended claims and is intended to cover all changes falling within the literal meaning or the equivalent scope of the claims.

[0067] List of reference numerals

[0068] 100 Data processing device

[0069] 101 Data processing component

[0070] 102 field

[0071] 201, 202 processors

[0072] 203 firmware

[0073] 204 software

[0074] 205 synchronization

[0075] 400 data processing device

[0076] 401 data processing component

[0077] 402 configuration memory

Claims

1. A data processing device comprising: A plurality of data processing components, the plurality of data processing components being designed to: exchange corresponding synchronization information with each other in pairs at a preset synchronization point, and a writable configuration memory, the writable configuration memory being designed to: store, for each of a plurality of reset types, whether corresponding synchronization information needs to be exchanged for all synchronization points, so that the corresponding pairs of data processing components are allowed to continue their processing beyond the synchronization point; The data processing component is designed to continue or not continue processing of the data processing component beyond a synchronization point in the absence of an exchange of synchronization information, depending on the content of the configuration memory.

2. A data processing device according to claim 1, wherein the configuration memory is designed to: store, for each of the multiple reset types: whether corresponding synchronization information needs to be exchanged for all synchronization points or only for a preset part of the synchronization points, so that the data processing components of the corresponding pairs are allowed to continue their processing beyond the synchronization point.

3. A data processing device according to claim 2, wherein the data processing components are designed to: if it is stored in the configuration memory that only a preset part for the synchronization point needs to exchange corresponding synchronization information so that the data processing components of the corresponding pair are allowed to continue their processing beyond the synchronization point, and the synchronization point reached does not belong to the preset part, then even if the corresponding synchronization information is not exchanged, the processing of the data processing components is continued after the synchronization point reached after resetting.

4. A data processing device according to claim 2 or 3, having firmware defining which synchronization points belong to the preset part of synchronization points.

5. A data processing device according to any one of claims 1 to 4, wherein the configuration memory is designed to store, for each of the multiple reset types: whether it is necessary for all synchronization points or not for any synchronization point to exchange corresponding synchronization information so that the data processing components of the corresponding pairs are allowed to continue their processing beyond the synchronization point.

6. A data processing device according to claim 5, wherein the data processing components are designed to: if it is stored in the configuration memory that no corresponding synchronization information needs to be exchanged for any synchronization point so that the data processing components of the corresponding pair are allowed to continue their processing beyond the synchronization point, then even if the corresponding synchronization information is not exchanged, the processing of the data processing components is continued after the synchronization point reached after a reset. 7 . The data processing device according to claim 1 , wherein the plurality of reset types include a cold start reset, a warm start reset and / or a software reset.

8. The data processing device according to any one of claims 1 to 7, wherein the content of the configuration memory is at least partially different for different ones of the reset types.

9. A data processing device according to any one of claims 1 to 8, wherein the configuration memory is also designed to: store, for each of the multiple reset types: the order in which the data processing component continues its processing after one of the synchronization points or after another preset synchronization point must follow or allow the preset order obtained by the corresponding processing duration to be achieved, and the data processing component is designed to: continue its processing after the synchronization point or after another synchronization point according to the content of the configuration memory.

10. A data processing device according to claim 9, wherein the synchronization point or the further synchronization point is a synchronization point at the end of a pre-operating system phase of the data processing device.

11. The data processing device according to claim 9 or 10, wherein the processing after the synchronization point or the further preset synchronization point comprises loading an operating system component or an application.

12. The data processing apparatus according to any one of claims 1 to 11, wherein at least a part of the data processing components is a processor. 13 . The data processing device according to claim 1 , wherein the data processing components are at least partially equipped with different measures for establishing operational safety and / or data security.

14. The data processing device according to claim 1, wherein the data processing components are designed to exchange the synchronization information via one or more synchronization memories which are written to and read from by the data processing components.

15. The data processing device according to claim 14, wherein a first synchronous memory and a second synchronous memory are provided for each pair of the data processing components, wherein the first synchronous memory can only be written by the first data processing component of the pair, and the second synchronous memory can only be written by the second data processing component of the pair.