Bus error management method

By storing write transaction characteristics and associating error characteristics, interrupt transmission is generated to the management unit, the problem of poor bus error management in the prior art is solved, effective identification and management of bus errors is realized, and remediation behavior and error reporting of the operating system are supported.

CN120196483APending Publication Date: 2025-06-24STMICROELECTRONICS INT NV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411865118.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-12-10
Filing Date
2024-12-18
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify and manage bus errors caused by the central processor during write access transactions.

Method used

By storing the characteristics of the write transaction and associating the error characteristics when a bus error occurs, the bridge generates an interrupt and transmits the characteristics to the management unit. The management unit generates an interrupt of the processing unit based on the characteristics so that the operating system can handle the error.

Benefits of technology

It realizes effective identification and management of bus errors caused by write access transactions, allows the operating system to perform remediation behavior without having to completely reset the microcontroller, and can generate error reports to meet authentication requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120196483A_ABST
    Figure CN120196483A_ABST
Patent Text Reader

Abstract

The present specification relates to a bus error management method in which one or more first characteristics of a first write transaction intended for a functional unit and transmitted through a bridge are stored, and in which when there is a bus error transmitted by the functional unit: one or more second characteristics associated with the error are stored; the bridge generates a first interrupt that transmits the first interrupt to the management unit together with the first characteristic and the second characteristic; and the management unit generates at least one second interrupt intended for the processing unit as a function of the first characteristic and / or the second characteristic.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - reference to related applications

[0002] This application claims the priority benefit of French Patent Application No. FR2315216, titled "Procédé de gestion d'erreurs de bus", filed on December 22, 2023. Technical field

[0003] The present disclosure generally relates to methods for bus error management and microcontrollers implementing these methods. Background art

[0004] Many electronic systems use a central processing unit (CPU) that generates write access transactions for functional units (Ips, intellectual property cores). Errors may occur during the implementation of these transactions. Summary of the invention

[0005] There is a need to improve the identification of the causes of errors resulting from write access transactions.

[0006] Embodiments overcome all or some of the drawbacks of known methods.

[0007] Embodiments provide a method for bus error management,

[0008] wherein one or more first characteristics of a first write transaction intended for a functional unit and transmitted through a bridge are stored,

[0009] and wherein when there is a bus error sent by the functional unit:

[0010] one or more second characteristics associated with the error are stored;

[0011] the bridge generates a first interrupt and transmits the first interrupt together with the first and second characteristics to a management unit; and

[0012] the management unit generates at least one second interrupt intended for a processing unit based on the first and / or second characteristics.

[0013] Embodiments provide a microcontroller comprising at least one control unit, a bridge, a functional unit, and a management unit; the microcontroller is configured to:

[0014] store one or more first characteristics of a first write transaction intended for a functional unit and transmitted through a bridge; and

[0015] such that when there is a bus error sent by the functional unit:

[0016] The bridge generates a first interrupt and transmits the first interrupt, together with the first characteristic and the second characteristic, to the management unit; and

[0017] The management unit generates at least one second interrupt for the processing unit according to the first characteristic and / or the second characteristic.

[0018] According to an embodiment, the processing unit executes multiple operating systems, and the second interrupt is for one of these operating systems according to the first characteristic and / or the second characteristic.

[0019] According to an embodiment, the second interrupt is for one of the multiple processing units according to the first characteristic and / or the second characteristic.

[0020] According to an embodiment, the first characteristic is stored in the bridge.

[0021] According to an embodiment, the second characteristic is stored in the bridge.

[0022] According to an embodiment, the management unit stores the first characteristic and the second characteristic.

[0023] According to an embodiment, after the bridge transmits the first interrupt transaction and transmits the first characteristic and the second characteristic, the management unit stores the first characteristic and the second characteristic.

[0024] According to an embodiment, the first characteristic and the second characteristic are stored in one or more registers of the management unit.

[0025] According to an embodiment, the (one or more) first characteristics include an access restriction level.

[0026] According to an embodiment, the (one or more) second characteristics include an addressing mode restriction level.

[0027] According to an embodiment, the (one or more) second characteristics include an address.

[0028] According to an embodiment, the (one or more) second characteristics include an identifier.

[0029] According to an embodiment, one of the registers is configured to store a value indicating the transmission of the first interrupt transaction.

[0030] According to an embodiment, one of the registers is configured to store the (one or more) first characteristics and the (one or more) second characteristics.

[0031] According to an embodiment, one of the registers is configured to store the address associated with the first write access transaction.

[0032] According to an embodiment, the management unit stores the first characteristic and the second characteristic in a register having an access restriction level similar to the (one or more) first characteristics.

[0033] According to an embodiment, the management unit transmits the second interrupt transaction to a processing unit having an access restriction level similar to the access restriction level associated with the (one or more) first characteristics.

[0034] According to an embodiment, as a result of the transmission of the second interrupt transaction, the processing unit that has received the second interrupt transaction performs an action among the following: reconfiguring a functional unit, resetting a first transaction or a second transaction, resetting a microcontroller, and writing an error report. Description of the Drawings

[0035] The above-described features and advantages and other features and advantages will be described in detail with reference to the accompanying drawings in the remainder of the disclosure of specific embodiments given by way of illustration and not limitation, in which:

[0036] Figure 1 An example of a type of microcontroller to which the embodiments are applicable is shown very schematically and in block diagram form;

[0037] Figure 2 An example of a bus error management method is shown;

[0038] Figure 3 Another example of a bus error management method is shown;

[0039] Figure 4 A bus error management method according to one embodiment is shown; and

[0040] Figure 5 A bus error management method according to another embodiment is shown. Detailed Description of the Embodiments

[0041] Identical features in the various figures are denoted by the same reference numerals. In particular, structural and / or functional features common among the various embodiments may have the same reference numerals and may be deployed with the same structure, dimensions, and material properties.

[0042] For clarity, only those steps and elements that contribute to an understanding of the embodiments are shown and described in detail.

[0043] Unless otherwise stated, when referring to two elements connected together, this means a direct connection without any intermediate element other than a conductor, and when referring to two elements coupled together, this means that the two elements may be connected or they may be coupled via one or more other elements.

[0044] In the following description, when referring to absolute position determiners (such as "front", "back", "top", "bottom", "left", "right", etc.), or relative position determiners (such as "top", "bottom", "upper", "lower", etc.), or orientation determiners (such as "horizontal", "vertical", etc.), unless otherwise specified, they all refer to the orientation of the accompanying drawings.

[0045] Unless otherwise specified, the expressions "about", "approximate", "substantially", and "about" mean plus or minus 10%, preferably plus or minus 5%.

[0046] Figure 1 An example of a microcontroller 100 of the type to which the embodiments are applicable is shown very schematically and in the form of a block diagram. The microcontroller 100 is, for example, a microprocessor.

[0047] The microcontroller 100 includes, for example, a non-volatile memory 104 (NVM) of the phase change type, which is capable of communicating via a communication bus 114 with a non-volatile memory interface 106 (NVM interface), and the non-volatile memory interface 106 is configured to write data to or read data from the non-volatile memory 104.

[0048] The microcontroller 100 further includes, for example, one or more processing units 110 (CPUs), and the one or more processing units 110 include one or more processors controlled by instructions stored in an instruction memory 112 (INSTR MEM). The one or more processing units 110 include one or more operating systems (OS).

[0049] The instruction memory 112 is, for example, a volatile memory of the random access (RAM) type. The processing unit 110 and the memory 112 communicate, for example, via a system (data, address, and control) bus 140. The memory 104 is coupled to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 further includes an input / output interface 108 (I / O interface) coupled to the system bus 140 for external communication.

[0050] The microcontroller 100 may integrally implement other circuits for other functions or functional units (for example, one or more volatile and / or non-volatile memories, direct memory access (DMA), or other processing units), which are represented by block 116 (IP) in Figure 1 Among these other circuits, the microcontroller 100 includes, for example, a read-only or static memory 118 (ROM).

[0051] One or more processing units 110 and blocks 104, 106, 108, 112, 114, 116, 118 are for example used in environments with different access restriction levels (NS, SEC). In an example, resources operating in a SEC environment can access resources of level SEC or NS, while resources operating in an NS environment can access resources of level NS but not resources of level SEC. In an example, an application qualified with an access restriction level of SEC has more permissions than an application with an access restriction level of NS. The access restriction levels SEC, NS are implemented for example by the TrustZone protocol of the ARM® CORTEX-M architecture.

[0052] In some cases, Figure 1 the different blocks 104, 106, 108, 110, 112, 114, 116, 118 operate using different clock signal domains or under different protocols (such as AXI, AHB or APB of the ARM® architecture). Then one or more bridges (160, 162, 164, 166, 168) need to be implemented for example between one or more of the processing units 110 and block 116 or blocks 118, 112, 108 or 106. These bridges ensure the transition from one operating mode (for example, bus protocol or clock frequency domain) to another.

[0053] One or more processing units 110 generate write access transactions and send the write access transactions to one or more different blocks 104, 106, 108, 112, 114, 116, 118 through bus 140 and for example via one of the bridges. During passing through the bridge, the write access request transaction (write bufferable access) is temporarily stored in the corresponding bridge for example. In an example, if the write access is unsuccessful, a bus error is generated for example by the block receiving the write access transaction.

[0054] Figure 2 An example of a bus error management method is shown.

[0055] In the example shown, the processing unit 110 includes for example two operating systems 214 (SEC OS) and 212 (NS OS). The access permission restriction level (secure, SEC) of the operating system SEC OS is higher than the access permission restriction level (non-secure, NS) of the operating system NS OS.

[0056] During a first step 230 (NS write bufferable access), the operating system 212 generates a write access transaction for example for block 116. In this example, this transaction is implemented in the NS environment.

[0057] In the second step 232 (access buffered), this transaction is transmitted through the corresponding bridges (bridge AHB2AHB) 160, 162, 164, 166, 168. In the example shown, the bridge adapts the transaction in the AHB bus protocol to the same AHB protocol with, for example, different clock signal domains (e.g., having different frequencies). In this step, the transaction is buffered by the bridge, i.e., temporarily stored. After this buffering, or from the end of the first step 230 onwards, the processing unit 110, for example, performs other tasks that are no longer related to the bridge.

[0058] In the third step 234 (NS write access), the transaction is implemented from the bridge to, for example, block 116.

[0059] In response, in the fourth step 236 (bus error), if the write access transaction fails, a bus error is sent from block 116 to bridge 160.

[0060] In the fifth step 240 (IRQ), when the error is received, the bridge generates (i.e., causes) an interruption (IRQ, Interrupt ReQuest), which is intended for the default operating system 214 SEC OS, rather than for the operating system of the NS environment with the initial transaction. For example, this is because the bus error may be due to an attack and the fact that the interruption is by default directed to the operating system 214. The interruption can be software or hardware. For example, the interruption is implemented by changing the bits or bytes of a register. The operating system NS OS that has initiated the initial transaction does not receive the bus error and thus cannot implement any remedial or targeted actions. The fact that the processing unit 110 has performed other tasks that are no longer related to the bridge 160 due to the write access request transaction means that neither the operating system 214 SEC OS nor 212 NS OS will receive the bus error. The operating system 214 SEC OS has no other information except the interruption caused by the bridge (which may correspond to an attack), and it will implement, for example, a full reset of the microcontroller 100, which is, for example, harmful to the user experience.

[0061] Figure 3 Another example of a bus error management method is shown. Figure 3 The example is similar to the example in the drawings, except that the microcontroller 100 includes two processing units 312 (CPU1) and 314 (CPU2) that respectively implement the operating systems 212 and 214, rather than one processing unit with two operating systems implemented in different environments. In the example, the processing unit 110 includes two regions that respectively contain the processing units 312 and 314.

[0062] In the example shown, the write access transaction of step 230 is generated by the operating system 212 in the NS environment. Steps 232, 234, and 236 are similar to those of Figure 2 the same.

[0063] After step 236, in step 340 (IRQ), when a bus error is received, the bridge 160 by default generates an interrupt (IRQ) that is intended for the operating system 214 SEC OS of the processing unit 314, rather than for the operating system 212 NS with the same NS environment as the initial transaction.

[0064] In addition, the operating system 212 NS OS that has initiated the initial transaction does not receive the bus error and thus cannot implement any remedial or targeted actions. For the same reason as in the Figure 2 example, neither the operating system 214 SEC OS nor 212 NSOS will receive the bus error. The operating system 214 SEC OS has no other information except the interrupt caused by the bridge, and it will, for example, implement a full reset of the microcontroller 100.

[0065] To overcome these drawbacks, the described embodiments provide a bus error management method in which one or more first characteristics intended for the functional unit 116 are stored and a first write transaction (write bufferable access) passing through the bridge 160 is transmitted,

[0066] and in which when there is a bus error sent by the functional unit 116:

[0067] one or more second characteristics associated with the error are stored;

[0068] the bridge generates a first interrupt and transmits the first interrupt together with the first and second characteristics to the management unit; and

[0069] the management unit generates at least one second interrupt intended for the processing unit (110, 312, 314) based on the first and / or second characteristics.

[0070] Thus, the operating system that has initiated the initial transaction can access information related to the bus error and can thus implement remedial or targeted actions without having to fully reset the microcontroller.

[0071] The fact of storing the first and second characteristics enables the generation of error reports for the implementation of certifications such as SESIP (Security Evaluation Standard for Internet of Things Platforms) certification.

[0072] The operating system that issues the initial write access transaction (regardless of whether it has an access restriction level of NS or SEC) will be able to receive the second interrupt associated with that transaction.

[0073] Finally, an advantage of this method is that existing bridges can be retained without having to develop new ones.

[0074] Figure 4 A bus error management method according to an embodiment is shown. Figure 4 The processing unit 110 of Figure 2 is similar to the processing unit of

[0075] In a first step 410 (NS write buffered access), a write access transaction is generated, for example, by the operating system 212 for block 116. In this example, this transaction is implemented in the NS environment. In the example shown, the operating system 212 generates N write access transactions, for example, for block 116 or other blocks, successively, and each write access transaction is transmitted through N bridges (bridge 0 AHB2AHB, bridge 1 AHB2AHB,..., bridge N AHB2AHB) respectively.

[0076] In a second step 412 (access buffered + store information about the access (SEC / NS + debug information)), this transaction is transmitted through the corresponding bridges (bridge 0 AHB2AHB) 160, 162, 164, 166, 168. In the example shown, the bridge adapts the transaction in the AHB bus protocol to the same AHB protocol with, for example, different clock signal domains (e.g., different frequencies). In this step, the transaction is buffered by the bridge, that is, temporarily stored. After this buffering, or from the end of the first step 410, the processing unit 110 performs other tasks that are no longer related to the bridge, for example. During this step, one or more first characteristics of the write transaction (in other words, the write access) are stored in, for example, the bridge. These first characteristics represent, for example, the access restriction level (NS / SEC) associated with the transaction environment. The first characteristics may also include information useful for debugging.

[0077] In a third step similar to step 234, a write access transaction is implemented from the corresponding bridge to, for example, block 116.

[0078] In response, in a fourth step similar to step 236 (bus error), if the write access transaction fails, a bus error that may be accompanied by one or more second characteristics is sent from block 116 to the corresponding bridge. During this step, one or more second characteristics related to this error are stored in, for example, the corresponding bridge. These second characteristics include, for example, the addressing mode restriction level (unpriv, Priv), the address, or the identifier of the master or slave function.

[0079] In the fifth steps 416, 420, 430 (NS / SEC and debug information), after receiving the corresponding bus error, each bridge generates interrupts 418 IRQ(0), 422 IRQ(1),..., 432 IRQ(N), and transmits them, together with, for example, the first characteristic and the second characteristic, to the management unit 440. The management unit 440 is, for example, an intelligent bridge system (SBS).

[0080] In the example shown, the management unit includes registers 450 (BIER), 452 (BISR), 454 (BICR), 456 (BESR), and 458 (BEADDR) dedicated to storing the characteristics among the first and second characteristics of write access transactions that follow the access restriction level NS, and different registers 442 (SBIER), 444 (SBISR), 446 (SBICR), 447 (SBESR), and 448 (SBEADDR) dedicated to storing the characteristics of write access transactions that follow the access restriction level SEC. In other words, if the access restriction level NS / SEC of the operating system or environment that has generated the transaction at step 410 is of the NS type, then the first and second characteristics transmitted by the corresponding bridge are stored in the registers in the management unit 440 associated with the same access restriction level NS, and the same applies to the level SEC.

[0081] In the sixth step after the fifth step, the management unit 440 generates at least one second interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) intended for the processing unit 110 based on the first and / or second characteristics stored in one or more bridges and / or stored in the management unit 440.

[0082] If the interrupt (generated by one of the bridges and stored, for example, via a flag in one of the registers of the management unit 440) is initially associated with a transaction having an access restriction level NS, then the second interrupt SBS_IRQ_NS is sent from the management unit 440 to the operating system 212. If the interrupt is initially associated with a transaction having an access restriction level SEC, then the second interrupt SBS_IRQ_SEC is sent from the management unit 440 to the operating system 214.

[0083] This second interrupt may include, for example, the access restriction level NS / SEC of the initial transaction, but may also include the second characteristic associated with the corresponding bus error.

[0084] For example, when the access restriction level is NS, register 450 is read-only and write-only. In the example, certain bits or bytes of register 450 are written by software means to enable or disable the second interrupt SBS_IRQ_NS. A value of 0 indicates that the second interrupt SBS_IRQ_NS is disabled, and in this case, when the first interrupt has been initiated by the bridge, the second interrupt will not reach the relevant processing unit. A value of 1 indicates that the second interrupt SBS_IRQ_NS is active, and in this case, when the interrupt has been initiated by the bridge, the interrupt will be transmitted all the way to the relevant processing unit.

[0085] For example, when the access restriction level is of the NS type, register 452 is read-only. In the example, the bits or bytes of register 452 are dedicated to storing the flag associated with causing the second interrupt SBS_IRQ_NS. For example, a value of 1 indicates that the interrupt SBS_IRQ_NS has been transmitted all the way to the relevant processing unit. For example, a flag value of 0 indicates that the interrupt SBS_IRQ_NS has not reached the relevant processing unit.

[0086] For example, when the access restriction level is NS, register 454 is write-only. In the example, a value of 1 clears the flag associated with the interrupt stored in register 452, and also clears registers 456 and 458. In the example, writing 0 has no effect.

[0087] For example, when the access restriction level is NS, register 456 is read-only. It stores the characteristics associated with the write access request transaction with access restriction NS. For example, this register is only valid when the corresponding bridge has generated an interrupt associated with access restriction NS (i.e., when the flag is caused). In the example, certain bits or bytes of register 456 are dedicated to storing the identifier of the bridge that has transmitted the interrupt. For example, certain bits or bytes of register 456 are dedicated to storing the addressing mode restriction level (unpriv, Priv) of the functional unit, or the bridge, or the operating system that has issued the transaction. For example, certain bits or bytes of register 456 are dedicated to storing the identifier of the master / slave element or the functional unit.

[0088] For example, when the access restriction level is NS, register 458 is read-only. This register 458 is written by hardware means, for example, when the bridge causes an error. For example, it is reset by software means via register 454. For example, it stores the address of the write access request transaction with access restriction level NS for which a bus error has been generated.

[0089] Registers 442, 444, 446, 447, and 448 are similar to registers 450, 452, 454, 456, and 458 respectively, except that the criteria for the parameters of the access restriction level NS are replaced by the access restriction level SEC.

[0090] The processing unit or operating system that receives the second interrupt can, for example, use the first and second characteristics stored in the corresponding bridge, or in the registers of the management unit 440, or in the second interrupt, to feed error reports and / or implement specific behaviors. These behaviors are, for example, reconfiguring the functional block 116 that has generated a bus error or restarting the initial transaction, or also resetting all or part of the microcontroller.

[0091] Figure 5 A bus error management method according to another embodiment is shown.

[0092] Figure 5 The method of Figure 4 is similar to the method of Figure 5 except that, at step 410 of

[0093] the write access transaction is transmitted by an operating system with access restriction level SEC similar to the operating system 214, or by an operating system with access restriction level NS similar to the operating system 212.

[0094] Multiple embodiments and variant embodiments have been described. Those skilled in the art will understand that certain features of these multiple embodiments and variant embodiments can be combined, and those skilled in the art will think of other variant embodiments. In particular, other types of registers can be implemented in the management unit 440 to store other types of characteristics that can help solve problems associated with bus errors.

[0095] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variant embodiments is within the capabilities of those skilled in the art. In particular, with regard to the access restriction levels NS / SEC, those skilled in the art will be able to implement the storage of other characteristics (such as the addressing restriction levels priv / unpriv of the operating system that has issued the initial transaction) in the (one or more) bridges or in the management unit 440. In an example, the (one or more) bridges can be integrated into the management unit to facilitate the storage and transmission of the characteristics of the write access transaction, as well as the storage and transmission of the characteristics associated with the bus error.

[0096] A bus error management method may include: storing one or more first characteristics of a first write transaction (410) intended for a functional unit (116) and transmitted through a bridge (160, 162, 164, 166, 168); and when there is a bus error sent by the functional unit (116): storing one or more second characteristics associated with the error; generating, by the bridge (160, 162, 164, 166, 168), a first interrupt (416, 420, 422, 430) and transmitting the first interrupt, together with the first characteristics and the second characteristics, to a management unit (440); and generating, by the management unit (440), at least one second interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) intended for a processing unit (110, 312, 314) according to the (one or more) first characteristics and / or the second characteristics.

[0097] A microcontroller (100) may include at least one control unit (110, 312, 314), bridges (160, 162, 164, 166, 168), a functional unit (116), and a management unit (440); the microcontroller (100) is configured to: store one or more first characteristics of a first write transaction (410) intended for the functional unit (116) and transmitted through the bridges (160, 162, 164, 166, 168); and when there is a bus error sent by the functional unit (116): the bridge generates a first interrupt (416, 420, 422, 430) and transmits the first interrupt, together with the first characteristics and the second characteristics, to the management unit (440); and the management unit generates at least one second interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) intended for the processing unit (110, 312, 314) according to the (one or more) first characteristics and / or the second characteristics.

[0098] The processing unit may execute multiple operating systems (212, 214), and the second interrupt may be intended for one of these operating systems according to the (one or more) first characteristics and / or the second characteristics.

[0099] The second interrupt may be intended for one of multiple processing units (312, 314) according to the (one or more) first characteristics and / or the second characteristics.

[0100] The (one or more) first characteristics may be stored in the bridge (160, 162, 164, 166, 168).

[0101] The (one or more) second characteristics may be stored in the bridge (160, 162, 164, 166, 168).

[0102] The management unit (440) may store one or more first characteristics and second characteristics.

[0103] The management unit (440) may store one or more first characteristics and second characteristics after the first interrupt transaction (416, 420, 422, 430) is transmitted by the bridge and one or more first characteristics and second characteristics are transmitted.

[0104] One or more first characteristics and second characteristics may be stored in one or more registers of the management unit (440).

[0105] One or more first characteristics may include access restriction levels (NS, SEC).

[0106] One or more second characteristics may include addressing mode restriction levels (unpriv, Priv).

[0107] One or more second characteristics may include an address.

[0108] One or more second characteristics may include an identifier.

[0109] One of the registers may be configured to store a value representing the transmission of the first interrupt transaction (416, 420, 422, 430).

[0110] One of the registers may be configured to store one or more first characteristics and one or more second characteristics.

[0111] One of the registers may be configured to store the address associated with the first write access transaction (410).

[0112] The management unit (440) may store one or more first characteristics and second characteristics in a register having an access restriction level (NS, SEC) similar to that of one or more first characteristics.

[0113] The management unit (440) may transmit the second interrupt transaction (SBS_IRQ_NS, SBS_IRQ_SEC) to a processing unit (110, 312, 314) having an access restriction level (NS, SEC) similar to the access restriction level (NS, SEC) associated with one or more first characteristics.

[0114] As a result of the transmission of the second interrupt transaction (SBS_IRQ_NS, SBS_IRQ_SEC), the processing unit (110, 312, 314) that has received the second interrupt transaction may perform actions among the following: reconfigure the functional unit (116), reset the first transaction or the second transaction, reset the microcontroller (100), and write an error report.

[0115] The various embodiments described above may be combined to provide further embodiments. All U.S. patents, U.S. patent application publications, U.S. patent applications, foreign patents, foreign patent applications, and non-patent publications cited in this specification and / or listed in the Application Data Sheet are hereby incorporated by reference in their entirety. Aspects of the embodiments may be modified as necessary to employ concepts of multiple patents, applications, and publications to provide yet further embodiments. If multiple patents, applications, and publications conflict with the present disclosure, the present disclosure controls.

[0116] Based on the foregoing detailed description, these and other changes may be made to the embodiments. In general, in the following claims, the terms used should not be construed as limiting the claims to the specific embodiments disclosed in the specification and the claims, but should be construed to include all possible embodiments and the full scope of equivalents to which these claims are entitled. Thus, the claims are not limited by the disclosure.

Claims

1. A bus error management method, comprising: storing one or more first characteristics of a first write transaction intended for the functional unit and transmitted through the bridge; And when there is a bus error signaled by the functional unit: storing one or more second characteristics associated with the error; generating a first interrupt by the bridge, the bridge transmitting the first interrupt along with the first characteristic and the second characteristic to the management unit; as well as At least one second interrupt intended for the processing unit is generated by the management unit depending on at least one of the first characteristic or the second characteristic.

2. A microcontroller, comprising at least one control unit, a bridge, a function unit and a management unit; the microcontroller is configured to: storing one or more first characteristics of a first write transaction intended for the functional unit and transmitted through the bridge; and When there is a bus error signaled by the functional unit: The bridge generates a first interrupt, transmits the first interrupt together with the first characteristic and the second characteristic to the management unit; and The management unit generates at least one second interrupt intended for the processing unit depending on at least one of the first characteristic or the second characteristic.

3. The method of claim 1, wherein the processing unit executes a plurality of operating systems, and the second interrupt is intended for one of the plurality of operating systems according to at least one of the first characteristic or the second characteristic. 4 . The method of claim 1 , wherein the second interrupt is intended for a processing unit among the plurality of processing units according to at least one of the first characteristic or the second characteristic. The method of claim 1 , wherein the first characteristic is stored in the bridge. The method of claim 1 , wherein the second characteristic is stored in the bridge. The method according to claim 1 , wherein the management unit stores the first characteristic and the second characteristic. 8 . The method of claim 7 , wherein after the first interrupt transaction is transmitted by the bridge and the first characteristic and the second characteristic are transmitted, the management unit stores the first characteristic and the second characteristic.

9. The method of claim 7, wherein the first characteristic and the second characteristic are stored in one or more registers of the management unit.

10. The method of claim 1, wherein the first characteristic comprises an access restriction level. The method of claim 1 , wherein the second characteristic comprises an addressing mode restriction level.

12. The method of claim 1, wherein the second characteristic comprises an address. The method of claim 1 , wherein the second characteristic comprises an identifier.

14. The method of claim 9, wherein one of the registers is configured to store a value indicating the presence of a transfer of the first interrupt transaction.

15. The method of claim 9, wherein one of the registers is configured to store a first characteristic and a second characteristic.

16. The method of claim 9, wherein one of the registers is configured to store an address associated with a first write access transaction.

17. The method of claim 9, wherein the management unit stores the first characteristic and the second characteristic in a register having an access restriction level similar to an access restriction level associated with the first characteristic.

18. The method of claim 9, wherein the management unit transmits the second interrupt transaction to a processing unit having an access restriction level similar to an access restriction level associated with the first characteristic.

19. The method according to claim 1, wherein: As a result of the transmission of the second interrupt transaction, the processing unit that has received the second interrupt transaction performs actions including at least one of: reconfiguring the functional unit, resetting the first transaction or resetting the second transaction, resetting the microcontroller, or writing an error report.

Citation Information

Patent Citations

  • Interlocking H-shaped paving stone - has square centre and irregular hexagonal ends with chamfered wearing surface on concrete body

    FR2315216A7