Storage device
By using multiple erase unit areas and storage controllers in the storage device, data is stored according to the automobile security level, the problems of hardware equipment interference and emergency data collection in the automotive electronic system are solved, and the security and data collection efficiency of autonomous vehicles are improved.
Patent Information
- Application Number
- CN202411335754.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-20
- Filing Date
- 2024-09-24
- Publication Date
- 2025-06-20
AI Technical Summary
In automotive electronic systems, interference may occur between hardware devices, resulting in reduced user safety and it is difficult for the prior art to effectively collect emergency data from autonomous vehicles.
A storage device is provided that includes a plurality of erase unit areas and a storage controller to determine the storage location according to the automotive security level of the data, prevent interference, and effectively collect emergency data.
It improves the safety of autonomous vehicles, prevents interference between hardware equipment, and effectively collects emergency data, enhancing the safety and reliability of vehicle systems.
Smart Images

Figure CN120179153A_ABST
Abstract
Description
[0001] Cross - reference to related applications
[0002] This application claims priority to Korean Patent Application No. 10 - 2023 - 0186493, filed with the Korean Intellectual Property Office on December 20, 2023, the contents of which are incorporated herein by reference in their entirety. Technical Field
[0003] Example embodiments relate to a storage device, and more particularly, to a storage device that can store data of an autonomous vehicle. Background Art
[0004] Recently, in the automotive industry, various devices or systems have been developed to provide driving convenience to users. As an example, automotive electronic systems can use semiconductor integrated circuits to provide autonomous driving or various user experiences. The automotive electronic system can provide convenience in driving a vehicle through the semiconductor integrated circuit, or can provide various infotainment through the semiconductor integrated circuit.
[0005] When an error occurs in an automotive electronic system, the error may cause safety problems in the automotive electronic system. That is, the error may lead to a reduction in user safety. Therefore, the ISO 26262 standard defines the Automotive Safety Integrity Level (ASIL) for various hardware devices or Intellectual Property (IP) blocks used in automotive electronic systems. The hardware devices or IP blocks can operate or communicate with each other according to their automotive safety levels defined in the ISO 26262 standard. However, in some cases, interference (i.e., unexpected communication) may occur between the hardware devices or IP blocks, which may lead to a reduction in driver safety. Summary of the Invention
[0006] One aspect is to provide a storage device that can prevent interference (e.g., unintentional communication) between hardware devices of an autonomous vehicle and can improve the safety of the autonomous vehicle based on the security level of data generated by the hardware devices.
[0007] Another aspect is to provide a storage device that can effectively collect emergency data of an autonomous vehicle.
[0008] In accordance with one aspect of one or more example embodiments, a storage device is provided, comprising: a memory device having a plurality of erase unit regions, the plurality of erase unit regions including a first erase unit region and a second erase unit region, the second erase unit region having a second bit density higher than a first bit density of the first erase unit region; and a storage controller configured to receive a write command from a first electronic control unit among a plurality of electronic control units, the write command including a tag indicating a hazard, store the data in the first erase unit region based on an automotive safety level of data received together with the write command being greater than or equal to a threshold level, and store the data in the second erase unit region based on the automotive safety level of the data being lower than the threshold level; and move the data received together with the write command and stored in the first erase unit region to the second erase unit region based on a hazard termination signal received from the first electronic control unit.
[0009] In accordance with another aspect of one or more exemplary embodiments, a storage device is provided, comprising: a memory device including a plurality of erase unit regions; and a storage controller configured to receive a write command and data from a first electronic control unit among a plurality of electronic control units, obtain an automotive safety level of a vehicle function that generated the write command from a tag included in the write command, and control the memory device to store the data in the plurality of erase unit regions depending on the automotive safety level of the vehicle function, wherein the storage controller controls the memory device to store multiple pieces of the data having different automotive safety levels in different erase unit regions of the plurality of erase unit regions.
[0010] In accordance with yet another aspect of one or more example embodiments, a storage device is provided, comprising: a memory device; and a storage controller configured to control the memory device. The storage controller includes a grouping manager configured to obtain a logical address included in a read command from a first electronic control unit among a plurality of electronic control units, and obtain an automotive safety level included in a tag of the read command; an access manager configured to determine whether a first automotive safety level included in the tag is greater than or equal to a second automotive safety level of data previously written to the memory device by the first electronic control unit; and a flash translation layer (FTL) configured to determine whether the first automotive safety level is greater than or equal to a third automotive safety level of data stored in the logical address based on the first automotive safety level being greater than or equal to the second automotive safety level, and perform a read operation on the logical address based on the first automotive safety level being greater than the third automotive safety level. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The above and other aspects will be more clearly understood from the following detailed description in conjunction with the accompanying drawings, in which:
[0012] Figure 1 is a diagram showing an autonomous vehicle according to an example embodiment;
[0013] Figure 2 is a diagram showing an example of the safety level of an autonomous vehicle according to some embodiments;
[0014] Figure 3 is a diagram showing a vehicle system according to an example embodiment;
[0015] Figure 4 is a diagram showing a storage device according to an example embodiment;
[0016] Figure 5 is a diagram showing the interaction between an electronic control device and a storage device according to an example embodiment;
[0017] Figure 6A and Figure 6B is a diagram showing the structure of a command including tags according to some example embodiments;
[0018] Figure 7 is a diagram showing a storage device according to an example embodiment;
[0019] Figure 8A is a diagram showing an access management table according to an example embodiment;
[0020] Figure 8B is a diagram showing a mapping table according to an example embodiment;
[0021] Figure 9 is a flowchart showing the operation of a storage device according to an example embodiment;
[0022] Figure 10 is a flowchart showing the operation of a storage device according to an example embodiment;
[0023] Figure 11 is a diagram showing a storage device according to an example embodiment;
[0024] Figure 12 is a diagram showing the interaction between components in a vehicle system according to an example embodiment;
[0025] Figure 13 is a diagram showing a storage device according to an example embodiment;
[0026] Figure 14 is a diagram showing a storage device according to an example embodiment;
[0027] Figure 15is a diagram showing a vehicle system according to an exemplary embodiment; and
[0028] Figure 16 is a diagram showing an access management table according to an exemplary embodiment. DETAILED DESCRIPTION
[0029] Hereinafter, various embodiments will be described with reference to the accompanying drawings. As used in this specification, the phrase "at least one of A, B, or C" includes within its scope "only A", "only B", "only C", "A and B", "B and C", "A and C", and "A, B, and C".
[0030] Figure 1 is a diagram showing an autonomous vehicle according to an exemplary embodiment.
[0031] Referring to Figure 1 , vehicle 10 may include a plurality of electronic control units (ECUs) 110, 120, 130, 140, and 150 (described in more detail below), a storage device 200, a plurality of sensors 310, 320, 330, 340, 351, and 352, a plurality of actuators 410, 420, 430, and 440, an advanced driver assistance system (ADAS) 500, and an infotainment system (INFOTAINMENT) 600.
[0032] Each of the plurality of electronic control units (ECUs) 110 - 150 may be electrically, mechanically, and communicatively connected to at least one of the plurality of sensors 310 - 352 and at least one of the plurality of actuators 410 - 440 disposed in vehicle 10, and may control the operation of at least one device based on a function execution command. For example, the electronic control units 110 - 150 may sense the internal and external conditions of vehicle 10 using the sensors 310 - 352 directly or indirectly connected thereto, and may drive vehicle 10 by controlling the actuators 410 - 440 directly or indirectly connected thereto according to the sensing results.
[0033] The storage device 200 may store data obtained from the plurality of electronic control units (ECUs) 110 - 150, and may provide the stored data to the plurality of electronic control units 110 - 150. For example, the plurality of electronic control units 110 - 150 may provide data generated by the sensors 310 - 352 and reprocessed data to the storage device 200. The plurality of electronic control units 110 - 150 may obtain the data stored in the storage device 200, may determine whether to use the actuators 410 - 440 to perform a function based on the obtained data, and may control one or more of the actuators 410 - 440 to perform the function.
[0034] The sensors 310-352 may include various sensors, such as for example an image sensor, a position sensor, a speed sensor, a pressure sensor, an inertial sensor, and / or a temperature sensor. The actuators 410-440 may include various actuators, such as for example a throttle actuator, a fuel injection device actuator, a brake actuator, a transmission actuator, a steering actuator, a suspension actuator, a window actuator, and / or a wiper actuator.
[0035] The advanced driver assistance system (ADAS) 500 may include devices for enhancing driver safety and convenience. The ADAS 500 may use data obtained from one or more of the plurality of sensors 310-352 (e.g., from sensors 351 and 352) to sense a dangerous situation. The ADAS 500 may control one or more of the plurality of electronic control units 110-150 depending on the sensed dangerous situation to provide an adaptive cruise control function, a lane departure warning function, a lane keeping assist function, a collision avoidance function including an automatic emergency braking function, and / or a blind spot monitoring function, etc.
[0036] The infotainment system 600 may improve the driving experience of a vehicle driver by providing audio, video, navigation, and / or communication functions.
[0037] The vehicle 10 may be electrically, mechanically, and communicatively connected to the plurality of electronic control units 110-150, and may further include a connection control device for performing communication with the plurality of electronic control units 110-150 respectively.
[0038] The connection control device may communicate with a server via wireless communication. The wireless communication between the connection control device and the server may include various wireless communication methods, such as global system for mobile communications (GSM), code division multiple access (CDMA), wideband code division multiple access (WCDMA), universal mobile telecommunications system (UMTS), time division multiple access (TDMA), and / or long term evolution (LTE). In some embodiments, the connection control device may include a Wi-Fi module and a wireless broadband module.
[0039] As the autonomous driving technology of the vehicle 10 is developed, the vehicle 10 may have dozens or more sensors 310 to 352 and dozens or more actuators 410 to 440, and the vehicle functions become more complex. When individually controlling multiple vehicle functions using each electronic control unit, networking between vehicle functions may become difficult, and introducing new vehicle functions may become difficult.
[0040] To enhance the networking and scalability among vehicle functions, multiple sensors 310-352 and multiple actuators 410-440 can be grouped into multiple regions depending on their positions in the vehicle 10, and an electronic control unit for each region can be introduced.
[0041] In Figure 1 In the illustrated example, multiple electronic control units 110-150 can include a first electronic control unit (ECU1) 110 connected to the sensors 310 and actuators 410 disposed on the right front side of the vehicle 10, a second electronic control unit (ECU2) 120 connected to the sensors 320 and actuators 420 disposed on the left front side of the vehicle 10, a third electronic control unit (ECU3) 130 connected to the sensors 330 and actuators 430 disposed on the right rear side of the vehicle 10, a fourth electronic control unit (ECU4) 140 connected to the sensors 340 and actuators 440 disposed on the left rear side of the vehicle 10, and a central electronic control unit (central ECU) 150 for controlling the multiple electronic control units (ECU1-ECU4) 110-140.
[0042] Each of the electronic control units (ECUs) 110-150 can execute multiple vehicle functions. For example, each of the vehicle functions can be implemented as software such as an application, or implemented by hardware such as firmware. In each of the electronic control units 110-150, multiple vehicle functions can be networked, vehicle functions can be updated, and / or new vehicle functions can be introduced.
[0043] The storage device 200 can be shared by the multiple electronic control units 110-150. Since the data of the multiple electronic control units 110-150 can be easily shared, the networking among vehicle functions and the scalability of vehicle functions can be further enhanced.
[0044] Depending on the safety level required for the vehicle function, an automotive safety level can be assigned to the vehicle function. Examples of automotive safety levels can include Automotive Safety Integrity Level (ASIL). For example, among various vehicle functions, the braking function that requires a high safety level can be assigned the ASIL D level as the highest level, and the rear lighting function can be assigned the ASIL A level as a relatively low level.
[0045] The ISO 26262 standard requires ensuring that there is no interference among vehicle functions with different automotive safety levels. This requirement can be referred to as Freedom From Interference (FFI).
[0046] Among multiple electronic control units (ECUs) 110 - 150, multiple vehicle functions with different automotive safety levels can generate data, and the generated data can be stored in a storage device 200. When the storage device 200 is shared by multiple electronic control units 110 - 150, unintentional interference may occur between different vehicle functions.
[0047] Specifically, when a vehicle function with a relatively low level accesses data stored in the storage device 200 that is generated by a vehicle function with a relatively high level, or when a vehicle function with a relatively low level changes data stored in the storage device 200 that is generated by a vehicle function with a relatively high level due to interference in the storage device 200, or when data from a vehicle function with a relatively low level causes interference to data stored in the storage device 200 that is generated by a vehicle function with a relatively high level, the safety of the vehicle may be adversely affected.
[0048] As a first example of a specific vehicle function changing the data of another vehicle function stored in the storage device 200, the specific vehicle function can directly change the data by providing a write command to the storage device 200 for the logical address assigned to the data. As a second example, when a specific vehicle function accesses an area around the physical area where data is stored in the storage device 200, the data may be damaged due to read interference and programming interference caused by the physical characteristics of the storage device 200.
[0049] According to an exemplary embodiment, the storage device 200 can meet the Freedom from Interference (FFI) requirement and can improve vehicle safety by preventing a specific vehicle function from unintentionally accessing, changing, or interfering with the data of another vehicle function.
[0050] Figure 2 is a diagram showing an example of the safety levels of an autonomous vehicle according to some embodiments.
[0051] Reference Figure 2 , the Automotive Safety Integrity Level (ASIL) can be determined according to the levels of S1 - S3, E1 - E4, and C1 - C3. The levels S1, S2, and S3 can indicate the severity of potential disasters or hazards during vehicle operation. S1 can indicate a level indicating mild and moderate injuries, S2 can indicate a level indicating survivable and life - threatening injuries (survivable), and S3 can indicate a level indicating life - threatening injuries (survivability is unspecified) or fatal injuries.
[0052] Levels E1, E2, E3, and E4 can indicate the levels of exposure to risks and disasters. E1 can indicate a very low level of exposure to risks and disasters, E2 can indicate a low level of exposure to risks and disasters, E3 can indicate a medium level of exposure to risks and disasters, and E4 can indicate an extremely high level of exposure to risks and disasters.
[0053] Levels C1, C2, and C3 can indicate the levels of disaster controllability. C1 can indicate a level of simple controllability, C2 can indicate a level of normal controllability, and C3 can indicate a level of uncontrollability or possible difficulty in control.
[0054] Automotive Safety Integrity Level (ASIL) can be divided into levels QM, A, B, C, and D. Level QM can indicate a level that is not related to the functional safety of the vehicle. Levels A, B, C, and D can indicate higher levels in the order of A, B, C, and D, where A is the lowest level and D is the highest level. The higher the ASIL, the higher the level of danger caused by a failure may be. In other words, the higher the ASIL, the higher the safety requirements may be.
[0055] Hereinafter, example embodiments will be described based on the Automotive Safety Integrity Level (ASIL) defined by the ISO 26262 standard, but the example embodiments are not limited thereto. For example, in the example embodiments, the safety levels defined by the IEC 61508 standard, the integrated functional safety standard for the safety of general electronic devices, or the functional safety standards for various other industries (railway, port, aviation, communication, etc.) can be used and / or applied together.
[0056] Figure 3 It is a diagram showing a vehicle system according to an example embodiment.
[0057] The vehicle system 11 may include a plurality of electronic control units (ECUs) 110, 120, 130, 140, and 150, a storage device 200, a plurality of sensors 311, 312, 321, 322, 331, 332, 341, and 342, and a plurality of actuators 411, 412, 421, 422, 431, 432, 441, and 442.
[0058] The plurality of electronic control units (ECUs) 10 - 150 may correspond to the plurality of electronic control units (ECUs) 110 - 150 described with reference to Figure 1 That is, the first to fourth electronic control units (ECU1 - ECU4) 110 - 140 may control the sensors and actuators provided in different areas of the vehicle, and the central electronic control unit (Central ECU) 150 may control the first to fourth electronic control units (ECU1 - ECU4) 110 - 140.
[0059] The first electronic control unit (ECU1) 110 can control sensors 311 and 312 and actuators 411 and 412, the second electronic control unit (ECU2) 120 can control sensors 321 and 322 and actuators 421 and 422, the third electronic control unit (ECU3) 130 can control sensors 331 and 332 and actuators 431 and 432, and the fourth electronic control unit (ECU4) 140 can control sensors 341, 342 and actuators 441 and 442.
[0060] Sensors 311 - 342 can generate various types of data, and the data can be used to control various vehicle functions. For example, for controlling the braking function, sensor 311 can sense a position and can generate position data.
[0061] The importance of the data generated from sensors 311 - 342 can vary depending on the safety level of the vehicle function for which the data is used. For example, the data generated for controlling a braking function with an ASIL D level can be managed as more important data than the data used for controlling a vehicle function in vehicle system 11 with a level lower than the ASIL D level, and the data generated for controlling a braking function with an ASIL D level can be managed so as not to be changed by a vehicle function with a lower level.
[0062] According to an example embodiment, the storage device 200 can include a plurality of erase unit regions, the plurality of erase unit regions including memory cells that can be erased simultaneously, and can store multiple pieces of data with different automotive safety levels in different erase unit regions.
[0063] According to an example embodiment, when data is separately stored in different erase unit regions depending on the automotive safety level, when accessing data with a relatively low automotive safety level, problems of damaging data with a relatively high automotive safety level due to read interference and program interference can be prevented.
[0064] According to an example embodiment, the storage device 200 can obtain the automotive safety level of a vehicle function attempting to access data from an electronic control unit, and can selectively permit access to the data depending on the obtained automotive safety level. When access to data is selectively permitted depending on the automotive safety level, a vehicle function with a relatively low automotive safety level can be prevented from accessing data with a relatively high automotive safety level.
[0065] Figure 4 is a diagram showing a storage device according to an example embodiment.
[0066] The storage device 200 may include a storage controller 210 and a memory device 220. The storage device 200 may include a storage medium for storing data in response to a request from an electronic control unit (ECU) 100. The electronic control unit (ECU) 100 may correspond to any of the multiple electronic control units (ECUs) 110-150 described with reference to Figure 1 and Figure 3 .
[0067] In some embodiments, the storage device 200 may include at least one of a solid state drive (SSD), an embedded memory, or a removable external memory. When the storage device 200 is implemented as an SSD, the storage device 200 may comply with the Non-Volatile Memory Express (NVMe) standard.
[0068] In an embodiment, when the memory device 220 of the storage device 200 includes a flash memory, the flash memory may include a 2D NAND memory array or a 3D (or vertical) NAND (VNAND) memory array. In some embodiments, the storage device 200 may include various other types of non-volatile memories. For example, in some embodiments, the storage device 200 may be implemented as a magnetic RAM (MRAM), a spin transfer torque MRAM, a conductive bridge RAM (CBRAM), a ferroelectric RAM (FeRAM), a phase RAM (PRAM), and / or a resistive memory (resistive RAM) and / or various other types of memories.
[0069] In some embodiments, the memory device 220 may include multiple memory dies DIE. Each of the multiple memory dies DIE may include multiple memory blocks, and each of the multiple memory blocks may include multiple memory cells. In a memory die DIE, an erase operation may be performed on a memory block unit.
[0070] In some embodiments, the multiple memory dies DIE may be connected to the storage controller 210 through multiple channels CH and multiple paths W. In some embodiments, the memory dies DIE connected to a channel CH may sequentially perform command and data communication through the channel CH. In some embodiments, the memory dies DIE may each receive a command and may perform command operations simultaneously and in parallel.
[0071] The storage controller 210 may include a host interface (I / F) 211, a memory interface (I / F) 212, a processor 213, a buffer memory 214, and a packet manager 215. In some embodiments, the storage controller 210 may include an access manager 216, a flash translation layer (FTL) 217, and a command analyzer 218.
[0072] In some embodiments, the storage controller 210 may include a working memory into which the FTL 217 is loaded, and write and read operations of data on the non-volatile memory may be controlled by the processor 213 by executing the FTL 217.
[0073] The host interface (I / F) 211 may send packets to and receive packets from the electronic control unit (ECU) 100. Packets sent from the electronic control unit 100 to the host interface 211 may include commands or data to be written to the memory device 220, and packets sent from the host interface 211 to the electronic control unit 100 may include responses to the commands or data read from the memory device 220.
[0074] The memory interface (I / F) 212 may send data to be written to the memory device 220, or may receive data read from the memory device 220. In some embodiments, the memory interface 212 may be implemented to conform to a standard protocol such as Toggle or ONFI.
[0075] The FTL 217 may perform several vehicle functions, such as address mapping, wear leveling, and / or garbage collection. The address mapping operation may be a function of changing a logical address received from the host to a physical address for actually storing data in the memory device 220. Wear leveling may be a function of preventing excessive degradation of a specific block by ensuring that blocks in the memory device 220 are used evenly, and may be implemented by firmware techniques such as balancing the erase counts of physical blocks. Garbage collection may be a function of ensuring available capacity in the memory device 220 by copying valid data of a block to a new block and erasing the existing block.
[0076] To utilize the parallel processing performance of the memory die DIE, the FTL 217 may configure memory blocks included in each of the memory die DIEs as super memory blocks. Memory blocks included in the super memory block may control the parallel operation of the memory blocks included in the super memory block. For example, in some embodiments, data may be programmed in parallel in each page of the memory blocks. In some embodiments, the memory blocks may be erased in parallel. Hereinafter, similar to the storage area provided by the super memory block, a storage area that may be erased simultaneously under the control of the FTL 217 may be referred to as an erase unit area.
[0077] The buffer memory 214 can temporarily store data to be written to the memory device 220, data to be read from the memory device 220, and / or metadata such as mapping data. In some embodiments, the buffer memory 214 can be a component provided in the storage controller 210. In some embodiments, the buffer memory 214 can be provided outside the storage controller 210.
[0078] In some embodiments, the packet manager 215 can generate packets according to the protocol of the interface with the electronic control unit 100. In some embodiments, the packet manager 215 can parse various information from the packets received from the electronic control unit 100.
[0079] According to an exemplary embodiment, the electronic control unit 100 can provide a write command or a read command to the storage device 200, and the write command or the read command includes a tag indicating the automotive safety level of the vehicle function for which the write operation or the read operation is to be performed. When the packet manager 215 receives the write command or the read command, the packet manager 215 can obtain the automotive safety level of the vehicle function from the tag included in the command.
[0080] The access manager 216 can selectively allow access to data depending on the automotive safety level of the vehicle function. For example, the access manager 216 can control the vehicle function not to access data having an automotive safety level higher than its automotive safety level depending on the automotive safety level included in the read command.
[0081] The flash translation layer (FTL) 217 can determine the automotive safety level of the data received from the vehicle function based on the automotive safety level of the vehicle function, and can separately store multiple pieces of data having different automotive safety levels in different erase unit areas. In some embodiments, the FTL 217 can store the automotive safety level of the data stored in each logical address, and can control the vehicle function not to access data having an automotive safety level higher than its automotive safety level.
[0082] In the exemplary embodiment, the buffer memory 214 can separately store the data to be written to the memory device 200 or the data to be read from the memory device 200 in different areas depending on the automotive safety level.
[0083] The command analyzer 218 can dynamically adjust the size of the buffer area depending on the automotive safety level included in the buffer memory 214 by analyzing the write command received from the electronic control unit 100.
[0084] Figure 5 FIG. is a diagram showing the interaction between an electronic control device and a storage device according to an exemplary embodiment.
[0085] Figure 5 The electronic control unit (ECU) 100 and the storage device 200 in Figure 4 may correspond to the electronic control unit (ECU) 100 and the storage device 200 described with reference to
[0086] In operation S11, a vehicle function having a determined automotive safety level in the electronic control unit 100 may generate data to be stored in the storage device 200. For example, the vehicle function generating data may include the electronic control unit 100 executing the vehicle function to obtain data from a sensor connected to the electronic control unit 100 or to process the data obtained from the sensor.
[0087] In operation S12, the electronic control unit 100 may provide a query to identify whether the storage device 200 supports command processing depending on the automotive safety level. In operation S13, the storage device 200 may provide a response to the query to the electronic control unit 100. For example, the storage device 200 may provide a response indicating support for command processing depending on the automotive safety level.
[0088] In operation S14, the electronic control unit 100 may insert a tag indicating the automotive safety level of the vehicle function into a write command for storing the generated data in the storage device 200. In operation S15, the electronic control unit 100 may provide the generated data and the write command into which the tag is inserted to the storage device 200.
[0089] In operation S16, the storage device 200 may update the automotive safety level that can be accessed by the electronic control unit 100. For example, the storage device 200 may store the automotive safety level requested by the electronic control unit 100 in an access management table and may control the access of the electronic control unit 100 by referring to the access management table.
[0090] In operation S17, the storage device 200 may store the data received from the electronic control unit 100 and may store the automotive safety level included in the tag as the automotive safety level of the data.
[0091] According to an example embodiment, the storage device 200 may use the automotive safety level of the data to control the access made by the electronic control unit 100. In some embodiments, the storage device 200 may store multiple pieces of data having different automotive safety levels in different erase unit areas depending on the automotive safety level of the data.
[0092] Figure 6A and Figure 6B are diagrams showing the structure of a command including a tag according to some example embodiments.
[0093] The command can be included in a packet provided from an electronic control unit (ECU) 100 to a storage device 200. The command can have a structure defined between the electronic control unit 100 and the storage device 200. For example, the command can include a plurality of double words (Dwords). In some embodiments, the indication of each bit of the Dword can be predefined.
[0094] Figure 6A is a diagram showing the structure of the command CMD. The command CMD can include a plurality of Dwords, Dword0 to Dword15. In Figure 6A the example in, bits [7:0] of Dword0 can indicate the type of operation code (i.e., command). For example, the value of bits [7:0] of Dword0 can indicate whether the command CMD is a read command, a write command, or another command. Bits [b:a] can refer to the bits from bit a to bit b.
[0095] Bits [31:0] of Dword1 can indicate the namespace identifier (NSID) to be accessed from the storage device 200. The storage device 200 can divide the physical storage space provided by the memory device into a plurality of logical storage spaces, and can provide the spaces to external entities, and each of the logical storage spaces can be referred to as a namespace. In an example embodiment, the storage device 200 can provide different namespaces for each of the electronic control units (ECUs) 100. The electronic control unit 100 can include the NSID of the namespace provided to it in bits [31:0] of Dword1.
[0096] According to an example embodiment, one or more bits indicating a label in the command CMD can be predetermined, and the label indicates the automotive safety level of a vehicle function. For example, the bits of Dword11 can be used to define a direct send command, and bits [15:8] of Dword11 can correspond to an instruction type (DTYPE) field that can indicate that the data is part of a set of related data. The DTYPE field can be predetermined to include a label indicating the automotive safety level.
[0097] Figure 6B shows the relationship between the value of the data bits included in the DTYPE field and the automotive safety level indicated by the value of the data bits. For example, the value '0x03' of the DTYPE field can indicate the ASIL QM level, '0x13' can indicate the ASIL A level, '0x23' can indicate the ASIL B level, '0x33' can indicate the ASIL C level, and '0x43' can indicate the ASIL D level. '0x53' can be reserved for other ASIL levels.
[0098] Referring to Figure 4The described packet manager 215 can determine the type of a command by analyzing the operation code field of the command included in the packet, can determine from which electronic control unit the command is received by analyzing the NSID field, and can determine the automotive safety level of the vehicle function for which data is desired to be accessed by analyzing the DTYPE field. The storage controller 210 can process access requests from vehicle functions having various automotive safety levels based on the result of the command analysis by the packet manager 215.
[0099] However, the command structure, the positions of the bits corresponding to the tags in the command structure, and the automotive safety levels according to the values of the tags are not limited to Figure 6A and Figure 6B the examples in
[0100] Below, with reference to Figure 7 、 Figure 8A and Figure 8B a method for processing a write command to a storage device according to an exemplary embodiment will be described in detail.
[0101] Figure 7 is a diagram showing a storage device according to an exemplary embodiment.
[0102] Figure 7 The storage device 200 in Figure 4 can correspond to the storage device 200 described with reference to
[0103] The memory device 220 may include a plurality of erase unit regions, including for example a first erase unit region ER1 and a second erase unit region ER2. The erase unit regions may include a plurality of memory blocks BLK. The memory blocks BLK included in the erase unit regions may be configured to be erased simultaneously and may be memory blocks included in different memory dies.
[0104] The number of memory blocks included in the erase unit regions is not limited to any specific example. In an exemplary embodiment, the memory blocks included in the erase unit regions may be obtained from the entirety of the memory dies DIE of the memory device 220, or may be obtained from the memory dies DIE connected to the channel CH, or may be obtained from the memory dies DIE individually selected from each of the channels CH.
[0105] The storage controller 210 can receive a write command WCMD and data DATA, and the packet manager 215 can analyze the write command WCMD. For example, the packet manager 215 can obtain the NSID of the namespace provided to the electronic control unit and the tag Tag indicating the automotive safety level of the vehicle function by analyzing the write command WCMD. The packet manager 215 can obtain the logical address LBA corresponding to the data DATA from the write command WCMD.
[0106] According to an exemplary embodiment, the FTL 217 may determine a physical address of a region in the memory device 220 where data DATA can be stored based on a tag Tag and a logical address LBA obtained from the packet manager 215. Specifically, the FTL 217 may store multiple pieces of data having different tags Tag in different erase unit regions.
[0107] In Figure 7 the example shown, data having a first automotive safety level may be stored in a first erase unit region ER1, and data having a second automotive safety level may be stored in a second erase unit region ER2. As referred to Figure 2 above, when the automotive safety level includes five levels (e.g., QM, A, B, C, and D), each of the automotive safety levels may be separately stored in five different erase unit regions.
[0108] Due to the physical structure of the memory device 220, when a read operation is performed on a page of a specific memory block, a read interference phenomenon may occur, in which data stored in other pages adjacent to the page degrades.
[0109] When the storage device 200 stores data in the erase unit region regardless of the automotive safety level, interference may occur between multiple pieces of data having different automotive safety levels due to the read interference phenomenon. For example, when multiple pieces of data having different automotive safety levels are stored in adjacent pages, data having a relatively high automotive safety level may be damaged due to accessing data having a relatively low automotive safety level. For example, when data related to a braking function is damaged due to continuous reading of data related to a rear lighting function, a great danger may occur to the vehicle driver.
[0110] According to an exemplary embodiment, data having different automotive safety levels may be separately stored in different erase unit regions, thereby preventing interference caused by read interference between multiple pieces of data having different automotive safety levels. Therefore, the safety of the vehicle system including the storage device 200 can be improved.
[0111] In an exemplary embodiment, the FTL 217 may determine a physical address such that data having a relatively high automotive safety level can be stored in an erase unit region having a relatively high durability. For example, whenever an erase operation is performed, stress may be applied to the memory cells of the memory device 220, and the erase unit region may have a durability determined by the number of program / erase (P / E) cycles (i.e., the number of erase operations).
[0112] The FTL 217 can determine a physical address to store data with a relatively high automotive safety level in an erase unit region having a relatively small number of erasures among multiple erase unit regions. Accordingly, the storage device 200 can prevent damage to data with a relatively high automotive safety level.
[0113] The storage controller 210 can complete the write command WCMD operation by buffering the received data DATA in the buffer memory 214 and storing the buffered data in an erase unit region. In an exemplary embodiment, the buffer memory 214 can include a plurality of buffer regions, including for example a first buffer region 241 and a second buffer region 242, for separately storing multiple pieces of data having different automotive safety levels. For example, the buffer memory 214 can include a metadata buffer for storing metadata such as mapping data, and an input / output data buffer for storing input / output data input to or output from the electronic control unit 100. The plurality of buffer regions 241 and 242 can be included in the input / output data buffer.
[0114] When multiple pieces of data having different automotive safety levels are separately stored in the buffer memory 214, interference between the multiple pieces of data having different automotive safety levels can be further prevented.
[0115] In some embodiments, the sizes of the plurality of buffer regions 241 and 242 can be fixed. However, in an exemplary embodiment, the sizes of the plurality of buffer regions 241 and 242 can be dynamically adjusted. For example, the command analyzer 218 can analyze the automotive safety level indicated by a tag included in each of the write commands received from the electronic control unit 100, the size of the data received together with each of the write commands, and / or can analyze the access frequency of the automotive safety level. In some embodiments, the command analyzer 218 can adjust the sizes of the plurality of buffer regions 241 and 242 based on the data size and access frequency for each automotive safety level. The storage controller 210 can use the access manager 216 and the FTL 217 to prevent vehicle functions having a relatively low automotive safety level from accessing data having a relatively high automotive safety level.
[0116] The access manager 216 can obtain the NSID and the tag Tag included in the write command WCMD from the packet manager 215. A namespace can be provided for each electronic control unit, and the access manager 216 can determine the electronic control unit that provides the write command WCMD based on the NSID.
[0117] According to an example embodiment, the access manager 216 may collect, for each of the electronic control units, automotive safety level information of vehicle functions that provide write commands to the storage device 200. The access manager 216 may determine data access permissions of the electronic control units by referring to the automotive safety level information for each of the electronic control units.
[0118] The FTL 217 may obtain a logical address LBA included in the write command WCMD, and a physical address and a tag Tag mapped to the logical address LBA as mapping data. In some embodiments, the FTL 217 may prevent vehicle functions with a relatively low automotive safety level from accessing data with a relatively high automotive safety level by referring to the tag Tag mapped to the logical address LBA.
[0119] Figure 8A FIG. is a diagram showing an access management table according to an example embodiment. Figure 8B FIG. is a diagram showing a mapping table according to an example embodiment.
[0120] As described with reference to Figure 7 The access manager 216 described above may store the automotive safety level of vehicle functions that will provide write commands to the storage device 200 in each of the plurality of electronic control units 110-140, as described with reference to Figure 3 above.
[0121] Figure 8A FIG. shows an access management table indicating the automotive safety level for each NSID. In the example of Figure 8A , a namespace may be provided for each electronic control unit (ECU1-ECU4), and there may be a one-to-one correspondence between the electronic control unit and the NSID. The access manager 216 may update the access management table based on the NSID and the tag Tag included in the write command WCMD.
[0122] For example, when an ASIL B level tag has been received together with the first NSID, and an ASIL D level tag has been received together with the first NSID, the automotive safety level corresponding to the first NSID in the access management table may be saved as the ASIL B level and the ASIL D level. The automotive safety level corresponding to the first NSID may indicate that vehicle functions in the first electronic control unit 110 that store data in the storage device 200 may have the ASIL B level and the ASIL D level.
[0123] According to an example embodiment, when a read command is received, the access manager 216 may determine whether to allow the read operation by referring to the NSID and the tag included in the read command and the NSID and the automotive safety level stored in the access management table.
[0124] The example embodiments are not limited to examples where the electronic control unit and the NSID can have a one-to-one correspondence. For example, multiple namespaces can be provided for the electronic control unit. Even when multiple namespaces are provided for the electronic control unit, the access manager 216 can generate an access management table indicating the automotive safety level for each of the multiple NSIDs.
[0125] Reference Figure 8B , the mapping table can represent the mapping relationship between the logical address, the physical address, and the label. For example, when the write command can include a label indicating the first logical address LBA1 and the ASIL A level, the FTL 217 can determine the first physical address PPN1, which is the physical address of the area in the memory device 220 where the data corresponding to the first logical address LBA1 is stored. In some embodiments, the FTL 217 can store the mapping relationship between the first logical address LBA1 and the first physical address PPN1 in the mapping table, and can store the ASIL A level information as the automotive safety level corresponding to the first logical address LBA1 in the mapping table.
[0126] According to the example embodiments, by adding a label indicating the automotive safety level to the mapping table indicating the mapping relationship between the logical address and the physical address, another table indicating the mapping relationship between the logical address and the label can be not added, and the automotive safety level for each logical address can be stored. For example, in the example embodiments, the label indicating the automotive safety level can be composed of 1 byte or less of data. Therefore, the capacity burden of the buffer memory 214 storing the automotive safety level for each logical address can be reduced.
[0127] In the example embodiments, the mapping table can be stored in the memory device 220, and even when the storage device 200 is not powered on, the mapping table can be retained in the memory device 220. In some embodiments, when the storage device 200 is started, at least a part of the mapping table stored in the memory device 220 can be loaded into the buffer memory 214 and can be referred to.
[0128] The mapping table can be managed by the namespace. For example, the memory device 220 can store multiple mapping tables, each corresponding to a namespace. When a namespace is generated, a mapping table can be generated, and when a namespace is deleted, the mapping table corresponding to the deleted namespace can be removed. For example, when a delete command in the namespace management command is received from the electronic control unit 100, or when a namespace is deleted in response to a secure erase command, the mapping table can be deleted from the memory device 220.
[0129] According to an exemplary embodiment, when a read command is received, the FTL 217 may determine whether to allow a read operation by comparing the logical address and tag included in the read command with the logical address and automotive safety level stored in the mapping table.
[0130] In the following description, reference Figure 9 is made to the method of processing a read command using the access manager 216 and the FTL 217 in detail.
[0131] Figure 9 is a flowchart showing the operation of a storage device according to an exemplary embodiment.
[0132] The storage device may correspond to the storage device 200 described with reference Figure 1 to FIGS. 8.
[0133] In operation S21, the host interface 211 may receive a read command from the electronic control unit. The read command may include an NSID, a tag, and a logical address, similar to the write command WCMD described with reference Figure 7 In operation S22, the packet manager 215 may obtain the NSID, the tag, and the logical address by analyzing the read command.
[0134] In operation S23, the access manager 216 may determine whether the automotive safety level indicated in the tag is equal to or higher than the automotive safety level of the NSID. The automotive safety level of the NSID may be obtained by referring to the access management table.
[0135] When the automotive safety level indicated in the tag is higher than the automotive safety level of the NSID (\"Yes\" in operation S23), the automotive safety level of the vehicle function that generates the read command may be higher than the automotive safety level of the data that has been written in the NSID so far. For example, when the automotive safety level of the NSID in the access management table is ASIL B level and ASIL D level, when the automotive safety level indicated in the tag is equal to or higher than the ASIL B level, it may be determined as \"Yes\" in operation S23. In this case, operation S24 may be performed to determine whether the automotive safety level indicated in the tag is equal to or higher than the automotive safety level of the logical address.
[0136] When the vehicle safety level indicated in the tag is lower than the vehicle safety level of the NSID ( "No" in operation S23), the vehicle safety level of the vehicle function that generates the read command may be lower than the vehicle safety level of the data that has been written in the NSID so far. Therefore, in operation S26, the storage controller 210 may provide an error response to the electronic control unit. In some embodiments, the storage controller 210 may block (or otherwise prevent) the vehicle function from accessing the data and may provide an error response to the electronic control unit. For example, when the vehicle safety level of the NSID is ASIL B level and ASIL D level, and the vehicle safety level indicated in the tag is ASIL A level or lower, operation S23 may be determined as "No".
[0137] When the vehicle safety level indicated in the tag is the vehicle safety level of the logical address or higher ( "Yes" in operation S24), the vehicle safety level of the vehicle function that generates the read command may be high enough to access the data corresponding to the logical address, such that in operation S25, the storage controller 210 may perform a read operation on the logical address.
[0138] When the vehicle safety level indicated in the tag is lower than the vehicle safety level of the logical address ( "No" in operation S24), the storage controller 210 may provide an error response to the electronic control unit in operation S26. In some embodiments, the storage controller 210 may block (or otherwise prevent) the vehicle function from accessing the data and may provide an error response to the electronic control unit. For example, when the vehicle safety level indicated in the tag is ASIL C level and the vehicle safety level of the NSID is ASIL B level and ASIL D level, the access may be determined based on the logical address. For example, access to data with ASIL B level may be allowed, but access to data with ASIL D level may be blocked. The storage controller 210 may control access to the data by comparing the vehicle safety level indicated in the tag with the vehicle safety level of the logical address.
[0139] According to an exemplary embodiment, the storage device may prevent a vehicle function with a relatively low vehicle safety level from obtaining data with a relatively high vehicle safety level, such that the safety of the vehicle system may be improved.
[0140] As in the above operation S23, when the vehicle safety level included in the read command received from the electronic control unit is lower than the vehicle safety level that has been written by the electronic control unit, the storage device may preemptively block the read operation before searching the mapping table. Therefore, the computational burden of the storage device 200 for controlling access may be improved.
[0141] According to the reference Figures 7 to 9In the described example embodiment, the storage device 200 may update the access management table in response to a write command from the electronic control unit, and may control the read operation by referring to the updated access management table in response to a read command from the electronic control unit.
[0142] However, the example embodiment is not limited to an access management table that only controls read operations. For example, in some embodiments, a write command may be processed by referring to the access management table. In the following description, the operation of processing a write command for a storage device according to an example embodiment is described in detail. Figure 10 The operation of processing a write command for a storage device according to an example embodiment is described in detail.
[0143] Figure 10 FIG. is a flowchart showing the operation of a storage device according to an example embodiment.
[0144] In operation S31, the host interface 211 may receive a write command and data from the electronic control unit.
[0145] In operation S32, the access manager 216 may determine whether an access table has been generated for the storage device 200. For example, in the first startup of the storage device 200, an access table may not have been generated.
[0146] When the access table has not been generated (No in operation S32), the access manager 216 may generate an access table in operation S33. When the access table has been generated (Yes in operation S32), the access manager 216 may skip operation S33 and proceed to operation S34.
[0147] In operation S34, the packet manager 215 may obtain the NSID, tag, and logical address by analyzing the write command received from the host interface 211. The logical address may refer to the logical address of the data.
[0148] In operation S35, the access manager 216 may identify whether the update of the access table has been completed.
[0149] When updating the firmware of the electronic control unit 100, the vehicle functions provided by the electronic control unit 100 may change, and the automotive safety level for each vehicle function may change. Until the firmware of the electronic control unit 100 is updated, the automotive safety level of the electronic control unit 100 may be fixed for each vehicle function.
[0150] For example, after updating the firmware of the electronic control unit 100, the access manager 216 may update the automotive safety level that can be accessed by the electronic control unit 100 in the access table for a determined period of time, and when the determined period of time has passed, the update of the access table may be terminated, and the access table that has completed the update may be used to determine whether to allow a write operation.
[0151] When the update of the access table is not completed (No in operation S35), the access manager 216 can update the access table in operation S36 using the vehicle safety level accessible by the electronic control unit 100.
[0152] When the update of the access table is completed (Yes in operation S35), the access manager 216 can determine in operation S37 whether the vehicle safety level of the tag included in the write command is equal to or higher than the vehicle safety level of the NSID by referring to the access table, thereby determining whether to allow the write operation of the data.
[0153] When the vehicle safety level of the tag is equal to or higher than the vehicle safety level of the NSID (Yes in operation S37), the storage controller 210 can perform operation S38.
[0154] When the vehicle safety level of the tag is less than the vehicle safety level of the NSID (No in operation S37), the storage controller 210 can output an error response to the electronic control unit in operation S40.
[0155] In operation S38, the FTL 217 can determine whether to allow the write operation of the data by determining whether the vehicle safety level of the tag is equal to or higher than the vehicle safety level of the logical address. The vehicle safety level of the logical address can be determined by referring to the mapping table and finding the vehicle safety level corresponding to the logical address included in the write command.
[0156] When the vehicle safety level of the tag is equal to or higher than the vehicle safety level of the logical address (Yes in operation S38), in operation S39 the FTL 217 can allow the write operation of the data. In other words, when the vehicle safety level of the vehicle for writing data to the logical address in the electronic control unit is higher than the vehicle safety level of the data currently written to the logical address, the FTL 217 will allow the update of the data at the logical address. The FTL 217 can map the logical address to another physical address, can store the data in the area indicated by the physical address in the memory device 220, and can update the logical address, physical address, and the vehicle safety level indicated by the tag in the mapping table.
[0157] When the vehicle safety level of the tag is less than the vehicle safety level of the logical address (No in operation S38), in operation S40, the storage controller 210 can provide an error response to the electronic control unit. In some embodiments, when the vehicle safety level of the vehicle function is lower than the vehicle safety level of the data currently written to the logical address, the storage controller 210 can block the write operation and provide an error response to protect the previously written data.
[0158] According to an example embodiment, a storage device may prevent a vehicle function with a relatively low automotive safety level from directly changing data with a relatively high automotive safety level or causing programming interference to the data, so that the safety of the vehicle system can be improved.
[0159] Reference Figures 7 to 10 The storage device described according to the example embodiment may store data with the same automotive safety level without distinguishing erasure unit regions, but the example embodiment is not limited thereto. For example, data with the same automotive safety level may be separately stored in multiple erasure unit regions according to additional criteria.
[0160] Figure 11 is a diagram showing a storage device according to an example embodiment.
[0161] Figure 11 The storage device 200 in Figure 11 The storage device 200 in Figure 7 may correspond to the storage device 200 described in the reference
[0162] Even when multiple pieces of data have the same automotive safety level, the storage device 200 may separately store the multiple pieces of data in different erasure unit regions depending on the access frequency of the data. For example, the FTL 217 may determine the automotive safety level of the data according to the tag included in the write command, and may determine the access frequency of the data according to the logical address included in the write command. The FTL 217 may collect the access frequencies by logical address, may classify data with an access frequency equal to or higher than a standard value as hot data, may classify data with an access frequency lower than the standard value as cold data, and may separately store the hot data and the cold data in different erasure unit regions.
[0163] The memory device 220 may include multiple erasure unit regions, including, for example, a first erasure unit region ER1, a second erasure unit region ER2, a third erasure unit region ER3, and a fourth erasure unit region ER4. As described in the reference Figure 7 Data with a first automotive safety level may be buffered in the first buffer region 241, and data with a second automotive safety level may be buffered in the second buffer region 242. In the example embodiment, among the multiple pieces of data buffered in the first buffer region 241, the hot data may be stored in the first erasure unit region ER1, and the cold data may be stored in the second erasure unit region ER2. In some embodiments, among the multiple pieces of data buffered in the second buffer region 242, the hot data may be stored in the third erasure unit region ER3, and the cold data may be stored in the fourth erasure unit region ER4.
[0164] As described in the referenceFigure 7 As described, in some embodiments, the sizes of the first buffer region 241 and the second buffer region 242 may be fixed. In some embodiments, the sizes of the first buffer region 241 and the second buffer region 242 may be dynamically adjusted by the command analyzer 218 for each automotive safety level based on the received data size and access frequency.
[0165] Figure 11 An example is shown in which multiple pieces of data with different automotive safety levels and multiple pieces of data with the same automotive safety level are separately stored in different erasure unit regions depending on the access frequency, but the example embodiments are not limited thereto. For example, in some embodiments, data with the same automotive safety level may be separately stored according to the lifetime (i.e., update frequency).
[0166] When the storage device 200 is applied to a vehicle system, the storage device 200 may be exposed to various and rapidly changing environments. For example, the storage device 200 may be exposed to various temperature conditions depending on the position of the vehicle, or may be exposed to dangerous conditions such as vehicle collisions and fires, or the power supply may become unstable.
[0167] When the data generated by the electronic control unit in a dangerous situation is not normally stored in the storage device 200, it may be difficult to normally control the vehicle system. In particular, when the data with a relatively high automotive safety level is damaged, an accident may occur due to a malfunction of the vehicle system. In addition, after removing the dangerous situation, it may be difficult to perform a hazard analysis using the data stored in the storage device 200.
[0168] According to an example embodiment, the storage device 200 may effectively protect the data with a relatively high automotive safety level by processing the data received from the electronic control unit based on the external conditions of the vehicle. In the following description, reference will be made to Figures 12 to 14 The operations of the vehicle system and the storage device according to the example embodiment will be described in detail.
[0169] Figure 12 is a diagram showing the interaction of a vehicle system according to an example embodiment.
[0170] The vehicle system may include an electronic control unit (ECU) 100, a storage device 200, and an advanced driver assistance system (ADAS) 500. The electronic control unit 100, the storage device 200, and the ADAS 500 may correspond to the components with the same reference numerals described in Figure 1 and Figure 3 description.
[0171] In operation S41, the ADAS 500 may sense a dangerous situation. For example, the ADAS 500 may be based on data from a referenceFigure 1 The data obtained by the described sensors 351 and 352 is used to sense dangerous situations. For example, the ADAS 500 can use a position sensor to sense a dangerous situation where the distance to surrounding objects is shorter than a standard value, or can use a temperature sensor to sense a dangerous situation where the temperature of the vehicle is higher than a standard value.
[0172] In operation S42, the ADAS 500 can provide a danger signal notifying of a dangerous situation to the electronic control unit 100. The electronic control unit 100 can correspond to at least one of the multiple electronic control units (ECUs) 110 - 150 described with reference to Figure 1 and Figure 3 The ADAS 500 can provide a danger signal to the electronic control unit related to the dangerous situation among the multiple electronic control units 110 - 150. For example, when sensing a danger of a frontal collision, the ADAS 500 can provide a danger signal to the first electronic control unit 110 and the second electronic control unit 120 associated with the sensors and actuators provided at the front of the vehicle.
[0173] In operation S43, whenever a write command is generated in response to a danger signal, the electronic control unit 100 can insert a label indicating the vehicle safety level and the danger into the write command. For example, one or more flag bits indicating danger can be added to the label, as described with reference to Figure 6A and one or more flag bits can indicate danger by being determined as a certain value (such as "1").
[0174] In operation S44, the electronic control unit 100 can provide the write command and data added with one or more flag bits to the storage device 200.
[0175] In operation S45, the storage device 200 can perform operations according to the dangerous situation in response to the sensing signal. For example, in an exemplary embodiment, the storage device 200 can store the data received from the electronic control unit 100 in a first erase unit area or a second erase unit area with different levels of bit density depending on the vehicle safety level of the data. For example, when the vehicle safety level of the received data is equal to or higher than a threshold level, the storage device 200 can store the data in the first erase unit area with a relatively low bit density. The operation S45 will be described later with reference to Figure 13 described.
[0176] In operation S46, the ADAS 500 can sense that the dangerous situation has ended. For example, the ADAS 500 can sense that the dangerous situation has ended based on the data obtained from the sensors.
[0177] In operation S47, the ADAS 500 may provide a danger termination signal notifying the electronic control unit 100 that the dangerous situation has ended.
[0178] In operation S48, the electronic control unit 100 may provide a termination signal notifying the storage device 200 that the dangerous situation has ended. After the dangerous situation has ended, whenever a write command is generated, the electronic control unit 100 may reset one or more flag bits included in the tag of the write command to a value such as "0".
[0179] In operation S49, the storage device 200 may perform an operation in response to the termination signal according to the termination of the dangerous situation. For example, in an exemplary embodiment, when the dangerous situation ends, the storage device 200 may move the data stored in the first erase unit area during the dangerous situation to a second erase unit area with a relatively high bit density. The operation S49 will be described later with reference to Figure 14 Describe operation S49.
[0180] In an exemplary embodiment, the dangerous situation of the storage device 200 and the operations after the termination of the dangerous situation may be individually controlled depending on each of the plurality of electronic control units.
[0181] For example, when a danger signal is provided from the ADAS 500 to the first electronic control unit 110 and the second electronic control unit 120, and the storage device 200 receives write commands including tags indicating danger only from the first electronic control unit 110 and the second electronic control unit 120, the storage device 200 may perform operation S45 on the data received from the first electronic control unit 110 and the second electronic control unit 120. However, in some embodiments, the data received from the third electronic control unit and the fourth electronic control unit 130 - 140 in the same time period may be stored in an erase unit area with the same bit density regardless of the vehicle safety level.
[0182] Figure 13 Is a diagram showing a storage device according to an exemplary embodiment.
[0183] Figure 13 The storage device 200 in may correspond to the storage device 200 described with reference to Figure 7 The storage device 200 may store data in erase unit areas with different levels of bit density depending on the vehicle safety level in the dangerous situation.
[0184] The memory device 220 may have an erase unit region that has different bit densities depending on the number of data bits that can be stored in the memory cells. For example, the memory device 220 may include an erase unit region having single-level cell (SLC) memory blocks for storing 1-bit data in the memory cells, an erase unit region having multi-level cell (MLC) memory blocks for storing 2-bit data in the memory cells, an erase unit region having triple-level cell (TLC) memory blocks for storing 3-bit data in the memory cells, and an erase unit region having quad-level cell (QLC) memory blocks for storing 4-bit data in the memory cells.
[0185] Figure 13 A first region LBD including erase unit regions ER1 and ER2 having a relatively low bit density and a second region HBD including erase unit regions ER3 and ER4 having a relatively high bit density are shown. For example, the erase unit regions of the first region LBD may include SLC memory blocks, and the erase unit regions of the second region HBD may include TLC memory blocks or QLC memory blocks.
[0186] According to an example embodiment, the storage controller 210 may store data of an automotive safety level having a threshold level equal to or higher in a hazardous situation in the erase unit regions ER1 and ER2 having a relatively low bit density. For example, the storage controller 210 may store data of an automotive safety level of ASIL D level or higher in the erase unit regions ER1 and ER2 including SLC memory blocks.
[0187] The storage controller 210 may store data of an automotive safety level less than the ASIL D level in the erase unit regions ER3 and ER4 including TLC memory blocks. As referred to Figure 7 above, when the automotive safety levels less than the ASIL D level include QM, A, B, and C, the data may be stored in four different erase unit regions depending on the automotive safety level.
[0188] In the erase unit region having a relatively low bit density, since the voltage margin between the threshold voltage states indicating the data is relatively large, the data can be programmed quickly and the data can be read quickly and accurately.
[0189] As referred to Figure 7As described above, the buffer memory 214 may include a plurality of buffer areas 241 and 242 for separately storing multiple pieces of data with different automotive safety levels. In an example embodiment, when a write command including a tag indicating danger is received, the command analyzer 218 may dynamically change the sizes of the plurality of buffer areas 241 and 242. For example, when the command analyzer 218 receives a write command including a tag indicating danger, the command analyzer 218 may further increase the size of the first buffer area 241 storing data with a relatively high automotive safety level compared to the size of the second buffer area 242 storing data with a relatively low automotive safety level.
[0190] According to an example embodiment, the storage controller 210 may quickly and securely store data generated in a vehicle function with a relatively high automotive safety level in a dangerous situation, thereby preventing data loss. According to an example embodiment, the storage controller 210 may accurately read the data such that a malfunction of a vehicle function with a relatively high automotive safety level can be prevented in a dangerous situation, and the safety of the vehicle system can be improved.
[0191] In an example embodiment, the storage controller 210 may mirror the same data in the erase unit areas ER1 and ER2. In other words, the second erase unit area ER2 may store a copy of the data stored in the first erase unit area ER1. In an example embodiment, the storage controller 210 may protect data from being damaged by mirroring data with a relatively high automotive safety level.
[0192] Figure 14 is a diagram showing a storage device according to an example embodiment.
[0193] Figure 14 The storage device 200 in Figure 13 may correspond to the storage device 200 described with reference to
[0194] In Figure 14 the example, the storage controller 210 may copy the data stored in the first erase unit area and the second erase unit areas ER1 and ER2 to the third erase unit area and the fourth erase unit areas ER3 and ER4, and may control the memory device 220 to perform an erase operation on the first erase unit area and the second erase unit areas ER1 and ER2.
[0195] According to an exemplary embodiment, when the dangerous situation ends, the storage device 200 may move the data stored in the first erasure unit region ER1 and the second erasure unit region ER2 to the third erasure unit region ER3 and the fourth erasure unit region ER4, thereby providing storage in the second region LBD having a relatively low bit density.
[0196] In an exemplary embodiment, when the dangerous situation terminates, the electronic control unit 100 may provide the data stored in the storage device 200 during the dangerous situation to an external server, thereby allowing the external server to perform a dangerous analysis of the vehicle system. For example, the data stored in the storage device 200 during the dangerous situation may be used for dangerous analysis for the same purpose as the data stored in the event data recorder (EDR).
[0197] Referring to Figures 1 to 14 The storage device according to the exemplary embodiment described may be applied to a vehicle system having a single root input / output virtualization (SR-IOV) architecture. In the following description, an example of a vehicle system having an SR-IOV architecture will be described with reference to Figure 15 an example of a vehicle system having an SR-IOV architecture will be described.
[0198] Figure 15 FIG. is a diagram showing a vehicle system according to an exemplary embodiment.
[0199] The vehicle system 12 may include a plurality of electronic control units (ECUs) 1110, 1120, and 1130, a storage device 1200, a network structure switch 1000, a plurality of sensors 1311, 1312, 1321, 1322, 1331, and 1332, and a plurality of actuators 1411, 1412, 1421, 1422, 1431, and 1432.
[0200] The plurality of electronic control units 1110-1130 may be similar to the plurality of electronic control units 110-140 described with reference to Figure 3 For example, at least one sensor and at least one actuator may be connected to each of the plurality of electronic control units 1110-1130, and the plurality of electronic control units 1110-1130 may use the data obtained from at least one sensor to control at least one actuator.
[0201] The storage device 1200 may be similar to the storage device 200 described with reference to Figure 3 and Figure 4 The storage device 1200 may include a storage controller 1210 and a memory device 1220.
[0202] A fabric switch 1000 can support communication between multiple electronic control units 1110 - 1130 and a storage device 1200. The storage device 1200 can be shared by multiple electronic control units 1110 - 1130.
[0203] When multiple physical or virtual devices share an input / output device, the SR - IOV architecture can provide multiple virtual devices for ease of management and performance improvement. For example, when the storage device 1200 is configured as an SR - IOV - enabled endpoint device, the storage device 1200 can provide one or more physical functions PF corresponding to input / output ports, and the physical function PF can provide multiple virtual functions VF1 - VF3. The physical function PF can be managed by the fabric switch 1000, and each of the multiple virtual functions VF can be assigned to multiple electronic control units 1110 - 1130.
[0204] The multiple virtual functions VF1 - VF3 can provide independent storage spaces for multiple electronic control units 1110 - 1130. For example, the storage controller 1210 can configure the storage space provided by the memory device 1220 into multiple namespaces NS1 - NS3, and can provide the multiple namespaces NS1 - NS3 to the multiple virtual functions VF1 - VF3. For example, the memory device 1220 can include multiple erase unit regions ER, each of the erase unit regions ER can include memory blocks BLK that can be accessed in parallel, and the logical storage space provided by the multiple erase unit regions ER can include multiple namespaces NS1 - NS3.
[0205] The access command provided to the storage device 1200 can include a virtual function identifier. The storage controller 1210 can determine the virtual function for which the access command is provided.
[0206] As referenced Figure 3 As described, each of the multiple electronic control units 1110 - 1130 can execute functions with various automotive safety levels, such that the data provided to the storage device 1200 from the multiple electronic control units 1110 - 1130 can have various automotive safety levels.
[0207] According to an example embodiment, the storage device 1200 can prevent interference (such as read interference) between multiple pieces of data with different automotive safety levels by storing multiple pieces of data with different automotive safety levels in different erase unit regions ER. In the example embodiment, when the data of different virtual functions has the same safety level, the data can be stored in the same erase unit region ER.
[0208] According to an example embodiment, the storage device 1200 may configure an access management table for each virtual function and may perform an access management operation.
[0209] Figure 16 FIG. is a diagram showing an access management table according to an example embodiment.
[0210] Referring to Figure 16 , the access management table may indicate a vehicle safety level for each of the virtual functions VF1-VF3.
[0211] As described with reference to Figure 15 , a virtual function may be provided for each of the electronic control units, and there may be a one-to-one correspondence between the electronic control units and the virtual function identifiers (VFIDs).
[0212] According to an example embodiment, the access management table may be updated based on the VFID and the tag included in the write command. According to an example embodiment, the storage controller 210 may control a read operation or a write operation by referring to the VFID and the tag included in the read command or the write command and the access management table.
[0213] According to the foregoing example embodiment, the storage device may separately store data in different erase unit regions depending on the security level of the data generated from the hardware devices of the autonomous vehicle, so that physical interference of the data can be excluded and the security of the autonomous vehicle can be improved.
[0214] According to the foregoing example embodiment, the storage device may store data having a relatively high security level among multiple pieces of data generated during a dangerous period of the autonomous vehicle in a memory region having a relatively low cell bit density, so that the dangerous data can be stored quickly and securely, and the stored data can be provided as data for dangerous analysis for the same purpose as the data from the event data recorder (EDR).
[0215] Although various example embodiments have been shown and described above, those skilled in the art will understand that modifications and variations can be made without departing from the scope of the example embodiments defined by the appended claims.
Claims
1. A storage device, comprising: A memory device having a plurality of erase unit regions, the plurality of erase unit regions comprising a first erase unit region and a second erase unit region, the second erase unit region having a second bit density higher than a first bit density of the first erase unit region; as well as Storage controller, configured as: receiving a write command including a tag indicating a hazard from a first electronic control unit of the plurality of electronic control units, storing the data in the first erase unit area based on a vehicle safety level of the data received with the write command being greater than or equal to a threshold level, and storing the data in the second erase unit area based on the vehicle safety level of the data being lower than the threshold level, and The data received together with the write command and stored in the first erase unit area is moved to the second erase unit area based on receipt of a hazard termination signal from the first electronic control unit.
2. The storage device according to claim 1, wherein: The storage controller is configured to mirror the data stored in the first erase unit area to a third erase unit area among the plurality of erase unit areas before receiving the hazard termination signal.
3. The storage device according to claim 1, wherein: The storage controller is configured to store data received from a second electronic control unit among the plurality of electronic control units in a different area of the plurality of erase unit areas depending on a vehicle safety level before receiving the hazard termination signal, and The different regions have the same bit density.
4. The storage device according to claim 1, wherein: The first erase unit area includes a single-level cell (SLC) memory block, the second erase unit area includes a triple-level cell (TLC) memory block, and the threshold level is configured as an automotive safety integrity level (ASIL) D level.
5. A storage device, comprising: A memory device including a plurality of erase unit regions; as well as Storage controller, configured as: receiving a write command and data from a first electronic control unit of the plurality of electronic control units, obtaining, from a tag included in the write command, a vehicle safety level of a vehicle function that generated the write command, and controlling the memory device to store the data in the plurality of erase unit areas depending on the vehicle safety level of the vehicle function, The storage controller controls the memory device to store the plurality of data having different automobile safety levels in different erasure unit areas of the plurality of erasure unit areas.
6. The storage device according to claim 5, wherein: The storage controller stores an access management table indicating a vehicle security level of a vehicle function accessing the storage device for each of the multiple electronic control units, and updates the vehicle security level of the vehicle function indicated by the tag in the access management table to the vehicle security level for the first electronic control unit.
7. The storage device according to claim 6, wherein: The storage controller is configured to receive a read command from the first electronic control unit, obtain a vehicle security level indicated by a tag included in the read command, compare the vehicle security level indicated by the tag included in the read command with the vehicle security level for the first electronic control unit stored in the access management table, and selectively allow a read operation to be performed based on the comparison result.
8. The storage device according to claim 5, wherein: The storage controller is configured to store a mapping table indicating a mapping of logical addresses used in the plurality of electronic control units and physical addresses of the memory device and a vehicle safety level, and is configured to update the mapping of the logical addresses, physical addresses and the vehicle safety level indicated in the tag included in the write command in the mapping table.
9. The storage device according to claim 8, wherein: The storage controller is configured to receive a read command from one of the multiple electronic control units, obtain a tag indicating a vehicle safety level and a logical address from the read command, compare the vehicle safety level indicated by the tag from the read command with the vehicle safety level of the logical address stored in the mapping table, and selectively allow a read operation to be performed based on the comparison result.
10. The storage device according to claim 5, wherein: The storage controller is configured to classify the received data into hot data and cold data depending on the access frequency of the data, and control the memory device to store the hot data and the cold data among a plurality of pieces of the data having the same automobile safety level in different erase unit areas among the plurality of erase unit areas.
11. The storage device according to claim 5, wherein: The storage controller is configured to assign data received from different electronic control units among the plurality of electronic control units to different namespaces, and control the memory device to store a plurality of pieces of the data having the same vehicle safety level in the same erase unit area regardless of the namespace to which the data is assigned.
12. The storage device according to claim 5, wherein: Each of the plurality of erase unit areas includes a memory block that is accessible simultaneously.
13. The storage device according to claim 5, wherein: The automotive safety level is configured as an Automotive Safety Integrity Level ASIL.
14. A storage device comprising: Memory devices; as well as a memory controller configured to control the memory device, Wherein, the storage controller comprises: a packet manager configured to obtain a logical address included in a read command from a first electronic control unit among the plurality of electronic control units, and obtain a vehicle security level included in a tag of the read command; an access manager configured to determine whether a first vehicle security level included in the tag is greater than or equal to a second vehicle security level of data that has been previously written to the memory device by the first electronic control unit; and A flash translation layer FTL is configured to determine whether the first vehicle security level is greater than or equal to a third vehicle security level of data stored in the logical address based on the first vehicle security level being greater than or equal to the second vehicle security level, and to perform a read operation on the logical address based on the first vehicle security level being greater than the third vehicle security level.
15. The storage device according to claim 14, wherein: The access manager is configured to receive write commands from the plurality of electronic control units and update an access management table indicating a vehicle security level that has been written for each of the plurality of electronic control units based on a tag included in each of the write commands.
16. The storage device according to claim 15, wherein: The access manager is configured to: terminating the updating of the access management table based on a time period elapsed after the firmware of one of the plurality of electronic control units is updated, determining, based on the access management table, whether the fourth vehicle security level is greater than a fifth vehicle security level of data that has been previously written into the memory device by the second electronic control unit based on obtaining a fourth vehicle security level included in a write command received from a second electronic control unit among the plurality of electronic control units, and Based on the fourth vehicle safety level being less than or equal to the fifth vehicle safety level, an error response to the write command is output.
17. The storage device according to claim 15, in, The storage controller provides different namespaces for the multiple electronic control units respectively, and The access manager updates the access management table based on a namespace identifier NSID included in the read command.
18. The storage device according to claim 17, in, The storage controller provides different virtual functions to the plurality of electronic control units respectively, and The access manager updates the access management table based on a virtual function identifier VFID included in the read command.
19. The storage device according to claim 14, wherein: The access manager is configured to output an error response to the read command based on the first vehicle security level being less than the second vehicle security level.
20. The storage device according to claim 14, wherein: The FTL is configured to output an error response to the read command based on the first vehicle safety level being less than the third vehicle safety level.