Chip, data access method based on chip, storage medium and electronic equipment

By introducing a first chip domain with a high functional safety level and a second chip domain with a low functional safety level into the chip, and using an isolation circuit to make the storage space of the second chip domain an extended storage space of the first chip domain, the problems of insufficient chip storage space and area overhead are solved, and efficient storage expansion and functional safety isolation are achieved.

CN120197235APending Publication Date: 2025-06-24CHENGDU HORIZON JOURNEY TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510272763.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the field of driving technology, if the storage space in the chip domain is too small, it cannot run the program smoothly; if it is too large, it will bring additional area overhead. How to take into account the smoothness of the program running and the area overhead of the chip is a technical challenge.

Method used

By introducing the first chip domain and the second chip domain into the chip, the functional safety level of the first chip domain is higher than that of the second chip domain, and the isolation circuit is used to make the storage space of the second chip domain an extended storage space of the first chip domain, thereby expanding the storage space without increasing the chip area.

Benefits of technology

It realizes that the storage space of the chip domain with high functional safety level is expanded without increasing the chip area, so that it can run programs smoothly, and at the same time, effectively isolate the two chip domains, avoiding the impact of abnormal functional safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197235A_ABST
    Figure CN120197235A_ABST
Patent Text Reader

Abstract

The invention discloses a chip, a data access method based on the chip, a storage medium and electronic equipment. The chip comprises a first chip domain and a second chip domain, the functional security level of the first chip domain is higher than that of the second chip domain, and the first chip domain is used for generating a data access request for the second chip domain; the isolation circuit is used for executing memory access operation on the storage space of the second chip domain based on the data memory access request, and returning a request execution result of the data memory access request to the first chip domain based on an actual feedback state of the second chip domain on the memory access operation, the storage space of the second chip domain is used as the extended storage space of the first chip domain. According to the embodiment of the invention, the storage space of the first chip domain with the high function security level can be expanded on the premise of not bringing extra area overhead of the chip, so that the first chip domain with the high function security level can smoothly run the program, and the program running fluency and the area overhead of the chip can be considered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to driving technologies, and in particular, to a chip, a data access method based on the chip, a storage medium, and an electronic device. Background Art

[0002] In the field of driving technologies, chips are widely used. For example, the chip can be an intelligent driving chip, and there can be several chip domains in the chip.

[0003] It should be noted that if the storage space of the chip domain is too small, the chip domain cannot run the program smoothly. If the storage space of the chip domain is too large, it will bring additional area overhead. How to balance the program running smoothness and the chip area overhead is a technical problem worthy of attention for those skilled in the art. Summary of the Invention

[0004] To solve the above technical problems, the present disclosure provides a chip, a data access method based on the chip, a storage medium, and an electronic device.

[0005] According to one aspect of the embodiments of the present disclosure, a chip is provided, including:

[0006] A first chip domain and a second chip domain, where the functional safety level of the first chip domain is higher than that of the second chip domain, and the first chip domain is used to generate a data access request for the second chip domain;

[0007] An isolation circuit, where the isolation circuit is used to perform an access operation on the storage space of the second chip domain based on the data access request, and return a request execution result of the data access request to the first chip domain based on an actual feedback status of the second chip domain for the access operation, so that the storage space of the second chip domain serves as an extended storage space of the first chip domain.

[0008] According to another aspect of the embodiments of the present disclosure, a data access method based on a chip is provided. The chip includes: a first chip domain, a second chip domain, and an isolation circuit, where the functional safety level of the first chip domain is higher than that of the second chip domain;

[0009] The data access method includes:

[0010] Generating, by the first chip domain, a data access request for the second chip domain;

[0011] The isolation circuit performs the following operations to make the storage space of the second chip domain serve as the extended storage space of the first chip domain: perform a memory access operation on the storage space of the second chip domain based on the data memory access request, and return the request execution result of the data memory access request to the first chip domain based on the actual feedback status of the second chip domain for the memory access operation.

[0012] According to another aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium storing a computer program for executing the above chip-based data memory access method.

[0013] According to another aspect of the embodiments of the present disclosure, there is provided an electronic device, which includes:

[0014] a processor;

[0015] a memory for storing executable instructions of the processor;

[0016] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the above chip-based data memory access method.

[0017] According to another aspect of the embodiments of the present disclosure, there is provided a computer program product, when the instructions in the computer program product are executed by a processor, the above chip-based data memory access method is executed.

[0018] Based on the chip, the data access method based on the chip, the storage medium, the electronic device, and the program product provided in the above embodiments of the present disclosure, the first chip domain can initiate a data access request for the second chip domain to the isolation circuit. The isolation circuit can perform a memory access operation on the storage space of the second chip domain based on the data access request, and return the request execution result of the data access request to the first chip domain based on the actual feedback status of the second chip domain for the memory access operation, thereby completing the data access of the first chip domain to the second chip domain. That is, in the embodiments of the present disclosure, the first chip domain with a high functional safety level can perform data access on the storage space of the second chip domain with a low functional safety level via the isolation circuit. Then, the first chip domain with a high functional safety level can flexibly use the storage space of the second chip domain with a low functional safety level, so that the storage space of the second chip domain with a low functional safety level serves as an extended storage space for the first chip domain with a high functional safety level. In this way, without incurring additional chip area overhead, the storage space of the first chip domain with a high functional safety level can be expanded, enabling the first chip domain with a high functional safety level to run programs smoothly, which is beneficial to balancing the program running fluency and the chip area overhead. In addition, the isolation circuit can effectively isolate the first chip domain and the second chip domain, avoiding direct communication between the first chip domain and the second chip domain, and thus facilitating the prevention of the functional safety anomalies (such as unexpected power-off, program runaway, malicious error injection, etc.) of the second chip domain from affecting the normal operation of the first chip domain. Description of the Drawings

[0019] Figure 1 It is a schematic structural diagram of a chip provided by some exemplary embodiments of the present disclosure.

[0020] Figure 2 It is a second schematic structural diagram of a chip provided by some exemplary embodiments of the present disclosure.

[0021] Figure 3 It is a third schematic structural diagram of a chip provided by some exemplary embodiments of the present disclosure.

[0022] Figure 4 It is a first schematic flowchart of a data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0023] Figure 5 It is a second schematic flowchart of a data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0024] Figure 6 It is a third schematic flowchart of a data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0025] Figure 7It is the fourth flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0026] Figure 8 It is the fifth flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0027] Figure 9 It is the sixth flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0028] Figure 10 It is the seventh flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0029] Figure 11 It is the eighth flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0030] Figure 12 It is the ninth flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0031] Figure 13 It is the tenth flowchart diagram of the data access method based on a chip provided by some exemplary embodiments of the present disclosure.

[0032] Figure 14 It is the structural diagram of an electronic device provided by some exemplary embodiments of the present disclosure. Detailed implementation manners

[0033] To explain the present disclosure, the exemplary embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. It should be understood that the present disclosure is not limited by the exemplary embodiments.

[0034] It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions, and numerical values set forth in these embodiments do not limit the scope of the present disclosure.

[0035] Application Overview

[0036] The chip may include at least two subsystems. Each of the at least two subsystems may include a processor, a memory, a peripheral module, etc. The processor may be, for example, a Central Processing Unit (CPU). The memory may be, for example, a Double Data Rate Synchronous Dynamic Random Access Memory (DDR), a Static Random Access Memory (SRAM), etc.

[0037] It should be noted that each of the at least two subsystems may have a corresponding functional safety level. A single subsystem may be regarded as a chip domain, or several subsystems with the same functional safety level may form a chip domain. In this way, there may be several chip domains in the chip.

[0038] In the process of implementing the present disclosure, the inventors found that if the storage space of a chip domain is too small, the chip domain cannot run the program smoothly. If the storage space of the chip domain is too large, it will bring additional chip area overhead. Therefore, it is necessary to take certain measures to balance the program running smoothness and the chip area overhead.

[0039] Exemplary System

[0040] The Road Vehicle Functional Safety Standard defines the Automotive Safety Integration Level (ASIL), which involves the following five functional safety levels: Quality Management (QM), ASIL-A, ASIL-B, ASIL-C, and ASIL-D; among them, the level of QM is lower than that of ASIL-A, the level of ASIL-A is lower than that of ASIL-B, the level of ASIL-B is lower than that of ASIL-C, and the level of ASIL-C is lower than that of ASIL-D.

[0041] In the embodiments of the present disclosure, a chip domain with a high functional safety level may perform data access to the storage space of a chip domain with a low functional safety level, so that the storage space of the chip domain with a low functional safety level serves as an extended storage space for the chip domain with a high functional safety level. In this way, without bringing additional chip area overhead, the storage space of the chip domain with a high functional safety level can be expanded, enabling the chip domain with a high functional safety level to run the program smoothly, which is beneficial to balancing the program running smoothness and the chip area overhead.

[0042] Exemplary Circuit

[0043] Figure 1 It is a schematic structural diagram of a chip provided by some exemplary embodiments of the present disclosure. Figure 1 The chip shown may be an intelligent driving chip. Figure 1 The chip shown may include:

[0044] A first chip domain 1 and a second chip domain 3, where the functional safety level of the first chip domain 1 is higher than that of the second chip domain 3, and the first chip domain 1 is used to generate a data access request for the second chip domain 3;

[0045] An isolation circuit 5, which is used to perform a memory access operation on the storage space of the second chip domain 3 based on the data access request, and return the request execution result of the data access request to the first chip domain 1 based on the actual feedback status of the second chip domain 3 on the memory access operation, so that the storage space of the second chip domain 3 serves as an extended storage space of the first chip domain 1.

[0046] Optionally, the first chip domain 1 and the second chip domain 3 may be any two chip domains with different functional safety levels in the chip (it is necessary to ensure that the functional safety level of the first chip domain 1 is higher than that of the second chip domain 3). For example, the first chip domain 1 may be a chip domain with a functional safety level of ASIL-D, and the second chip domain 3 may be a chip domain with a functional safety level of ASIL-A, ASIL-B, or ASIL-C. For another example, the first chip domain 1 may be a chip domain with a functional safety level of ASIL-C, and the second chip domain 3 may be a chip domain with a functional safety level of ASIL-A or ASIL-B.

[0047] Optionally, the isolation circuit 5 may be a circuit in the chip used to assist in implementing the data access of the first chip domain 1 to the storage space of the second chip domain 3, and is a circuit used to isolate the first chip domain 1 and the second chip domain 3. The isolation circuit 5 may be electrically connected to the first chip domain 1 and the second chip domain 3 respectively. The storage space of the second chip domain 3 may refer to the storage space in the memory included in the second chip domain 3. The memory included in the second chip domain 3 may be, for example, DDR.

[0048] The first chip domain 1 may generate a data access request for the second chip domain 3, and the data access request may include, but is not limited to, a read request, a write request, etc. The first chip domain 1 may send the data access request to the isolation circuit 5.

[0049] The isolation circuit 5 can obtain a data access request from the first chip domain 1 and perform an access operation on the storage space of the second chip domain 3 based on the data access request. If the data access request is a read request, the access operation performed by the isolation circuit 5 on the storage space of the second chip domain 3 can be a read operation, that is, reading the read data corresponding to the read request (i.e., the requested data of the read request) from the storage space of the second chip domain 3. The read data corresponding to the read request can include, but is not limited to, feature map data, weight data, etc. If the data access request is a write request, the access operation performed by the isolation circuit 5 on the storage space of the second chip domain 3 can be a write operation, that is, writing the write data corresponding to the write request (i.e., the data to be written indicated by the write request) into the storage space of the second chip domain 3. The write data corresponding to the write request can include, but is not limited to, feature map data, weight data, etc.

[0050] The isolation circuit 5 can determine the actual feedback status of the second chip domain 3 for the access operation. The actual feedback status can indicate whether the second chip domain 3 returns an actual access feedback for the access operation. If the access operation is a read operation, the actual access feedback can be a read feedback, and the read feedback can be the read data corresponding to the read request, or feedback information indicating a read failure. If the access operation is a write operation, the actual access feedback can be a write feedback, and the write feedback can be feedback information indicating a write success, or feedback information indicating a write failure.

[0051] The isolation circuit 5 can also return the request execution result of the data access request to the first chip domain 1 based on the actual feedback status. If the actual feedback status indicates that the second chip domain 3 has returned an actual access feedback, the isolation circuit 5 can return the actual access feedback as the request execution result of the data access request to the first chip domain 1. If the actual feedback status indicates that the second chip domain 3 has not returned an actual access feedback, the isolation circuit 5 can generate an analog access feedback corresponding to the data access request and return the analog access feedback as the request execution result of the data access request to the first chip domain 1. It should be noted that the analog access feedback is not the actual access feedback returned by the second chip domain 3, but an access feedback used to simulate the actual access feedback. If the data access request is a read request, the analog access feedback can be an analog read feedback indicating a read failure. If the data access request is a write request, the analog access feedback can be an analog write feedback indicating a write failure.

[0052] In an embodiment of the present disclosure, the first chip domain 1 may initiate a data access request for the second chip domain 3 to the isolation circuit 5. The isolation circuit 5 may perform an access operation on the storage space of the second chip domain 3 based on the data access request, and return the request execution result of the data access request to the first chip domain 1 based on the actual feedback status of the second chip domain 3 on the access operation, thereby completing the data access of the first chip domain 1 to the second chip domain 3. That is, in the embodiment of the present disclosure, the first chip domain 1 with a high functional safety level may perform data access to the storage space of the second chip domain 3 with a low functional safety level via the isolation circuit 5. Then, the first chip domain 1 with a high functional safety level can flexibly use the storage space of the second chip domain 3 with a low functional safety level, so that the storage space of the second chip domain 3 with a low functional safety level serves as an extended storage space for the first chip domain 1 with a high functional safety level. In this way, without incurring additional chip area overhead, the storage space of the first chip domain 1 with a high functional safety level can be expanded, enabling the first chip domain 1 with a high functional safety level to run programs smoothly, which is beneficial to taking into account both the program running smoothness and the chip area overhead. In addition, the isolation circuit 5 can effectively isolate the first chip domain 1 and the second chip domain 3, avoiding direct communication between the first chip domain 1 and the second chip domain 3, and thus being beneficial to preventing the functional safety exception (such as unexpected power-off, program runaway, malicious error injection, etc.) of the second chip domain 3 from affecting the normal operation of the first chip domain 1.

[0053] In some alternative examples, as Figure 2 shown, the isolation circuit 5 may include a first isolation sub-circuit 51 and a second isolation sub-circuit 53, and the second isolation sub-circuit 53 may include an isolation module 531, a first buffer 533, and a second buffer 535;

[0054] The isolation circuit 5 is configured to perform an access operation on the storage space of the second chip domain 3 based on the data access request, and return the request execution result of the data access request to the first chip domain 1 based on the actual feedback status of the second chip domain 3 on the access operation, and may include:

[0055] The first isolation sub-circuit 51 is configured to cache the target content in the first buffer 533 based on the data access request;

[0056] The isolation module 531 is configured to perform an access operation on a storage area of the storage space based on the target content in the first buffer 533; in response to obtaining the actual access feedback of the access operation of the second chip domain 3 on the storage area, cache the actual access feedback in the second buffer 535;

[0057] The first isolation circuit 51 is configured to determine the actual feedback status of the access operation of the second chip domain 3 to the storage area based on the cache status of the actual memory access feedback of the second buffer 535, and return the request execution result of the data memory access request to the first chip domain 1 based on the actual feedback status corresponding to the storage area.

[0058] Optionally, the first isolation circuit 51 may be a sub-circuit in the isolation circuit 5 that is used to communicate with the first chip domain 10 and detect functional safety exceptions for the first chip domain 1 and the second chip domain 3. The second isolation circuit 53 may be a sub-circuit in the isolation circuit 5 that is used to communicate with the first isolation circuit 51 and the second chip domain 3 respectively, and perform read / write control on the second chip domain 3. The first buffer 533 and the second buffer 535 may be data buffers in the second isolation circuit 53. The first buffer 533 and the second buffer 535 may be, for example, a first-in-first-out (FIFO) buffer respectively. The isolation module 531 may be a sub-circuit in the second isolation circuit 53 that is used to communicate with the second chip domain 3, the first buffer 533 and the second buffer 535 respectively, and perform read / write control on the second chip domain 3. The isolation module 531 may be electrically connected to the second chip domain 3, the first buffer 533 and the second buffer 535 respectively. The first buffer 533 and the second buffer 535 may also be electrically connected to the first isolation circuit 51 respectively. The first isolation circuit 51 may also be electrically connected to the first chip domain 1.

[0059] The first isolation circuit 51 can obtain the data memory access request from the first chip domain 1, and based on the data memory access request, cache the target content in the first buffer 533. If the data memory access request is a read request, the first isolation circuit 51 can use the read request as the target content and cache it in the first buffer 533. If the data memory access request is a write request, the first isolation circuit 51 can obtain the write data corresponding to the write request, and use the write request and the write data corresponding to the write request as the target content and cache it in the first buffer 533.

[0060] The isolation module 531 may perform a memory access operation on a storage area of the storage space based on the target content in the first buffer 533. If the data memory access request is a read request, the read request may carry a read address. As introduced in the previous paragraph, if the data memory access request is a read request, the read request may be used as the target content. Correspondingly, the target content may include the read address. Then, the isolation module 531 may obtain the read address from the target content and perform a read operation on the storage area corresponding to the read address in the storage space. If the data memory access request is a write request, the write request may carry a write address. As introduced in the previous paragraph, if the data memory access request is a write request, the write request and the write data corresponding to the write request may be used as the target content. Correspondingly, the target content may include the write address and the write data. Then, the isolation module 531 may obtain the write address and the write data from the target content and perform a write operation on the storage area corresponding to the write address in the storage space, that is, write the write data into the storage area corresponding to the write address.

[0061] The isolation module 531 may also monitor whether an actual memory access feedback of the memory access operation on the storage area by the second chip domain 3 is obtained. If the actual memory access feedback of the memory access operation on the storage area by the second chip domain 3 is obtained, the isolation module 531 may cache the actual memory access feedback in the second buffer 535. If the actual memory access feedback of the memory access operation on the storage area by the second chip domain 3 is not obtained, the isolation module 531 will not perform the operation of caching the actual memory access feedback in the second buffer 535.

[0062] The first isolation sub-circuit 51 may determine the caching state of the actual memory access feedback in the second buffer 535 and accordingly determine the actual feedback state of the access operation on the storage area by the second chip domain 3 (which may also be referred to as the actual feedback state corresponding to the storage area). The caching state of the actual memory access feedback in the second buffer 535 may indicate whether the second buffer 535 caches the actual memory access feedback. If the second buffer 535 caches the actual memory access feedback, the actual feedback state corresponding to the storage area may indicate that the second chip domain 3 has returned the actual memory access feedback for the memory access operation. If the second buffer 535 does not cache the actual memory access feedback, the actual feedback state corresponding to the storage area may indicate that the second chip domain 3 has not returned the actual memory access feedback for the memory access operation. Based on the actual feedback state corresponding to the storage area, the first isolation sub-circuit 51 may return the request execution result of the data memory access request to the first chip domain 1.

[0063] In an embodiment of the present disclosure, through the collaborative work of the first isolation sub-circuit 51, the isolation module 531, the first buffer 533, and the second buffer 535, it is possible to perform corresponding memory access operations on the corresponding storage area of the storage space of the second chip domain 3 with a low functional safety level based on the data memory access request initiated by the first chip domain 1 with a high functional safety level, and return the corresponding request execution result to the first chip domain 1 with a high functional safety level, thereby completing the data memory access of the first chip domain 1 with a high functional safety level to the storage space of the second chip domain 3 with a low functional safety level. In this way, the storage space of the second chip domain 3 with a low functional safety level can be used as an extended storage space of the first chip domain 1 with a high functional safety level, so that without bringing additional chip area overhead, the storage space of the first chip domain 1 with a high functional safety level can be expanded, enabling the first chip domain 1 with a high functional safety level to run programs smoothly, which is beneficial to balancing the program running fluency and the chip area overhead. In addition, the first isolation sub-circuit 51, the isolation module 531, the first buffer 533, and the second buffer 535 can effectively isolate the first chip domain 1 and the second chip domain 3, which is conducive to preventing the functional safety exception of the second chip domain 3 from affecting the normal operation of the first chip domain 1.

[0064] In some optional examples, such as Figure 3 shown, the first isolation sub-circuit 51 may include a detection module 511 and a result return module 513;

[0065] The first isolation sub-circuit 51 is configured to return the request execution result of the data memory access request to the first chip domain 1 based on the actual feedback status corresponding to the storage area, and may include:

[0066] The detection module 511 is configured to determine the first functional safety detection result of the second chip domain 3 based on the actual feedback status corresponding to the storage area;

[0067] The result return module 513 is configured to return the request execution result of the data memory access request to the first chip domain 1 based on the first functional safety detection result.

[0068] Optionally, the detection module 511 may be a sub-circuit in the first isolation sub-circuit 51 for detecting functional safety exceptions between the first chip domain 1 and the second chip domain 3. The result return module 513 may be a sub-circuit in the first isolation sub-circuit 51 for returning the request execution result of the data memory access request to the first chip domain 1. The result return module 513 may be electrically connected to the detection module 511, and the result return module 513 may also be electrically connected to the first chip domain 1.

[0069] Optionally, the detection module 511 may determine the first functional safety detection result of the second chip domain 3 based on the actual feedback status corresponding to the storage area, using a predetermined detection strategy. The predetermined detection strategy may include, but is not limited to, a redundant backup detection strategy, a timeout detection strategy, etc. The first functional safety detection result of the second chip domain 3 may indicate whether there is a functional safety anomaly in the second chip domain 3.

[0070] The redundant backup detection strategy will be introduced first below.

[0071] When adopting the redundant backup detection strategy, the number of the second isolation sub-circuits 53 may be at least two, for example, Figure 3 the two shown (reflected by the two "×2" in Figure 3 . Each of the at least two second isolation sub-circuits 53 includes an isolation module 531, so there are at least two isolation modules 531 in total among the at least two second isolation sub-circuits 53. In addition, each of the at least two isolation modules 531 corresponds to a storage area (the storage area corresponding to each isolation module 531 refers to the storage area where the isolation module 531 performs a memory access operation), so the at least two isolation modules 531 may correspond to at least two storage areas, and there may be a one-to-one correspondence between the at least two storage areas and the at least two isolation modules 531.

[0072] Correspondingly, the detection module 511 for determining the first functional safety detection result of the second chip domain 3 based on the actual feedback status corresponding to the storage area may include:

[0073] The detection module 511 is configured to, in response to the at least two actual feedback statuses corresponding to the at least two storage areas both indicating that the second chip domain 3 has returned an actual memory access feedback, determine a first matching degree between the at least two actual memory access feedbacks corresponding to the at least two actual feedback statuses; and based on the first matching degree, determine the first functional safety detection result of the second chip domain 3.

[0074] It should be noted that for a data memory access request, each of the at least two storage areas may correspond to an actual feedback status, so the at least two storage areas may be in one-to-one correspondence with the at least two actual feedback statuses.

[0075] Optionally, as Figure 3As shown, the detection module 511 may include a first detection unit 5111. The first detection unit 511 may be the detection unit in the detection module 511 for running the redundant backup detection strategy. If at least two actual feedback states both characterize that the second chip domain 3 has returned the actual memory access feedback, the first matching degree between at least two actual memory access feedbacks corresponding one by one to the at least two actual feedback states may be determined. For any two of the at least two actual memory access feedbacks, the first detection unit 5111 may determine whether these two actual memory access feedbacks are the same. If they are the same, the first detection unit 5111 may determine that the first matching degree between these two actual memory access feedbacks is 1. If they are not the same, the first detection unit 5111 may determine that the first matching degree between these two actual memory access feedbacks is 0. In the above manner, the first detection unit 5111 may obtain at least one first matching degree. The first detection unit 5111 may determine the first functional safety detection result of the second chip domain 3 based on the at least one first matching degree. For example, if at least one first matching degree is 1, the first functional safety detection result may characterize that there is no functional safety anomaly in the second chip domain 3. If at least some of the at least one first matching degrees are 0, the first functional safety detection result may characterize that there is a functional safety anomaly in the second chip domain 3.

[0076] It should be noted that theoretically, if the second chip domain 3 can work properly, at least two actual memory access feedbacks corresponding one by one to at least two storage areas are consistent. In view of this, the first matching degree between at least two actual memory access feedbacks may be determined to clarify whether at least two actual memory access feedbacks are actually consistent. If at least two actual memory access feedbacks are actually consistent, it means that the actual situation is consistent with the theoretical situation. Then, it can be determined that there is no functional safety anomaly in the second chip domain 3. If at least two actual memory access feedbacks are actually inconsistent, it means that the actual situation is inconsistent with the theoretical situation. Then, it can be determined that there is a functional safety anomaly in the second chip domain 3. Therefore, by adopting the redundant backup detection strategy, the first functional safety detection result of the second chip domain 3 can be determined efficiently and reliably.

[0077] The timeout detection strategy will be introduced below.

[0078] When adopting the timeout detection strategy, the detection module 511 is further configured to start a timing operation in response to the first isolation circuit 51 obtaining a data memory access request;

[0079] The detection module 511 is configured to determine the first functional safety detection result of the second chip domain 3 based on the actual feedback state corresponding to the storage area, and may include:

[0080] The detection module 511 is used to determine a second matching degree between the actual feedback status corresponding to the storage area and the expected feedback status; based on the second matching degree, determine a first functional safety detection result of the second chip domain 3;

[0081] Wherein, the expected feedback status indicates that before the elapsed time of the timing operation reaches a preset duration, the second chip domain 3 has returned an actual memory access feedback.

[0082] Optionally, as Figure 3 shown, the detection module 511 may include a second detection unit 5113. The second detection unit 5113 may be a detection unit in the detection module 511 for running a timeout detection policy, and the second detection unit 5113 may have a timing function. The first isolation circuit 51 may further include a configuration module 514. The configuration module 514 may configure a preset duration in the second detection unit 5113. The preset duration may be preset according to experience and is the maximum duration required for the first chip domain 1 to perform a data memory access on the second chip domain 3 via the isolation circuit 5.

[0083] In response to the first isolation circuit 51 obtaining a data memory access request from the first chip domain 1, the second detection unit 5113 may start performing a timing operation. The second detection unit 5113 may determine whether the second chip domain 3 returns an actual memory access feedback before the elapsed time of the timing operation reaches the preset duration. If the actual feedback status corresponding to the storage area indicates that the second chip domain 3 has returned an actual memory access feedback before the elapsed time of the timing operation reaches the preset duration, the second detection unit 5113 may determine that the second matching degree between the actual feedback status corresponding to the storage area and the expected feedback status is 1. In this case, the first functional safety detection result of the second chip domain 3 may indicate that there is no functional safety anomaly in the second chip domain 3. If the actual feedback status corresponding to the storage area indicates that the second chip domain 3 has not returned an actual memory access feedback before the elapsed time of the timing operation reaches the preset duration, the second detection unit 5113 may determine that the second matching degree between the actual feedback status corresponding to the storage area and the expected feedback status is 0. In this case, the first functional safety detection result of the second chip domain 3 may indicate that there is a functional safety anomaly in the second chip domain 3.

[0084] It should be noted that theoretically, if the second chip domain 3 can operate normally, the second chip domain 3 will return an actual memory access feedback before the elapsed time of the timing operation reaches the preset time. In view of this, the second matching degree between the actual feedback state and the expected feedback state corresponding to the storage area can be determined to clarify whether the second chip domain 3 actually returns an actual memory access feedback before the elapsed time of the timing operation reaches the preset time. If the second chip domain 3 actually returns an actual memory access feedback before the elapsed time of the timing operation reaches the preset time, it means that the actual situation is consistent with the theoretical situation. Then, it can be determined that there is no functional safety anomaly in the second chip domain 3. If the second chip domain 3 does not actually return an actual memory access feedback before the elapsed time of the timing operation reaches the preset time, it means that the actual situation is inconsistent with the theoretical situation. Then, it can be determined that there is a functional safety anomaly in the second chip domain 3. Therefore, by adopting the timeout detection strategy, the first functional safety detection result of the second chip domain 3 can be determined efficiently and reliably.

[0085] Optionally, the redundant backup detection strategy and the timeout detection strategy can be used in combination. For example, if all the first matching degrees are 1 and the second matching degree is 1, the first functional safety detection result can indicate that there is no functional safety anomaly in the second chip domain 3. If some of the first matching degrees are 0 among all the first matching degrees, and / or the second matching degree is 0, the first functional safety detection result can indicate that there is a functional safety anomaly in the second chip domain 3.

[0086] Regardless of the method used to determine the first functional safety detection result of the second chip domain 3, the result return module 513 can return the request execution result of the data access request to the first chip domain 1 based on the first functional safety detection result.

[0087] In some alternative embodiments of the present disclosure, the result return module 513 is used to return the request execution result of the data access request to the first chip domain 1 based on the first functional safety detection result, which may include:

[0088] The result return module 513 is used to, in response to the first functional safety detection result indicating that there is no functional safety anomaly in the second chip domain 3, determine the target actual memory access feedback based on the actual feedback state corresponding to the storage area, and return the target actual memory access feedback as the request execution result of the data access request to the first chip domain 1.

[0089] Taking the case where the number of the second isolation sub-circuits 53 is at least two as an example, if the first functional safety test result indicates that there is no functional safety anomaly in the second chip domain 3, this indicates that at least two actual feedback states corresponding to at least two storage areas both indicate that the second chip domain has returned actual memory access feedback, then, an actual memory access feedback can be randomly selected from at least two actual memory access feedbacks corresponding to at least two actual feedback states as the target actual memory access feedback. The result return module 513 can return the target actual memory access feedback to the first chip domain 1 as the request execution result of the data memory access request. In this way, the first chip domain 1 can obtain the actual memory access feedback of the second chip domain 3 on the memory access operation, and the first chip domain 1 can make a decision on the operation to be performed next based on this. For example, if the actual memory access feedback is feedback information indicating a read failure or a write failure, the first chip domain 1 can initiate the data memory access request that was initiated last time again. If the actual memory access feedback is feedback information indicating a write success or a read success, the first chip domain 1 can initiate a new data memory access request.

[0090] In some other optional implementations of the present disclosure, the result returning module 513 is used to return the request execution result of the data access request to the first chip domain 1 based on the first functional safety test result, which may include:

[0091] The result returning module 513 is used to generate simulated memory access feedback corresponding to the data memory access request in response to the first functional safety test result indicating that the second chip domain 3 has a functional safety anomaly, and return the simulated memory access feedback as the request execution result of the data memory access request to the first chip domain 1.

[0092] Optionally, the simulated memory access feedback is not the actual memory access feedback returned by the second chip domain 3, but is a memory access feedback used to simulate the actual memory access feedback. If the data memory access request is a read request, the simulated memory access feedback may be a simulated read feedback representing a read failure. If the data memory access request is a write request, the simulated memory access feedback may be a simulated write feedback representing a write failure.

[0093] Since the result return module 513 returns the simulated memory access feedback as the request execution result of the data memory access request to the first chip domain 1, the first chip domain 1 can obtain the simulated memory access feedback, and based on this, the first chip domain 1 can make a decision on the operations to be performed next. For example, it can decide whether to initiate again the data memory access request that has been initiated last time or initiate a new data memory access request. In this way, even if due to the functional safety exception of the second chip domain 3, the second chip domain 3 fails to return the actual memory access feedback for the memory access operation, or the actual memory access feedback returned by the second chip domain 3 for the memory access operation is abnormal (such as the case where the first matching degree is 0 in the above text), the result return module 513 can also generate the simulated memory access feedback by itself and return it to the first chip domain 1, which is beneficial to avoid the lack of memory access feedback, complete the entire data memory access process, and prevent the first chip domain 1 from remaining in a waiting state for a long time due to the failure to obtain the memory access feedback.

[0094] In the embodiments of the present disclosure, the detection module 511 can efficiently and reliably determine whether there is a functional safety exception in the second chip domain 3 based on the actual feedback status corresponding to the storage area. The result return module 513 can accordingly return the corresponding request execution result to the first chip domain 1. In this way, regardless of whether there is a functional safety exception in the second chip domain 3, the entire data memory access process can be normally implemented.

[0095] In some optional examples, as Figure 3 shown, the first isolation circuit 51 may further include a first reading module 515 and a first counter 517;

[0096] The first counter 517 is used to record the first quantity of the actual memory access feedbacks respectively cached by at least two second buffer memories 535 in at least two second isolation circuits 53;

[0097] Before the detection module 511 determines the first matching degree between the two actual memory access feedbacks corresponding to at least two actual feedback statuses, the first reading module 515 is used to, in response to determining that at least two second buffer memories 535 all meet the preset reading conditions based on the first quantity of the actual memory access feedbacks respectively cached by at least two second buffer memories 535, perform data reading on at least two second buffer memories 535 respectively, so as to obtain the two actual memory access feedbacks corresponding to at least two actual feedback statuses respectively.

[0098] Optionally, the first counter 517 may include at least two counters, and each counter in the at least two counters is used to record the first quantity of the actual memory access feedbacks cached by one second buffer memory 535 in at least two second buffer memories 535.

[0099] Optionally, the preset reading condition may be that the buffer memory is in a non-empty state (that is, there is content available for reading in the buffer memory).

[0100] When adopting the redundant backup detection strategy, before the detection module 511 determines the first matching degree between two actual memory access feedbacks corresponding to at least two actual feedback states, the first reading module 515 may determine whether the first quantity of the actual memory access feedbacks cached in each of the at least two second buffers 535 recorded by the first counter 517 is 0. If the first quantity of the actual memory access feedbacks cached in each of the at least two second buffers 535 is not 0, it means that there are actual memory access feedbacks available for reading in each of the at least two second buffers 535, and it can be determined that the at least two second buffers 535 all meet the preset reading conditions. Then, the first reading module 515 may respectively send read enable signals to the at least two second buffers 535, and the at least two second buffers 535 may respectively respond to the received read enable signals and return the actual memory access feedbacks cached in themselves to the first reading module 515. At this time, the first quantity of the cached actual memory access feedbacks recorded by the first counter 517 may all be decreased by 1 based on the current value. In this way, the first reading module 515 can obtain two actual memory access feedbacks corresponding to at least two actual feedback states through data reading for determining the first matching degree. If the first quantity of the actual memory access feedbacks cached in some of the at least two second buffers 535 is 0, it means that there are no actual memory access feedbacks available for reading in these second buffers 535, and it can be determined that the at least two second buffers 535 do not meet the preset reading conditions, and a period of time may be waited. After a period of time, if the at least two second buffers 535 all meet the preset reading conditions, at least two actual memory access feedbacks corresponding to at least two actual feedback states can be obtained through data reading of the at least two second buffers 535 for determining the first matching degree.

[0101] In the embodiments of the present disclosure, through the settings of the first reading module 515 and the first counter 517, it is possible to monitor the situation that there are actual memory access feedbacks available for reading in each of the at least two second buffers 535, and perform data reading only in this case. In this way, at least two actual memory access feedbacks can be successfully read for determining the first matching degree, which is beneficial to avoiding resource consumption and power consumption caused by data reading in other cases except this case.

[0102] In some optional examples, the first isolation circuit 51 is further configured to determine the first functional safety detection result of the second chip domain 3 based on the actual feedback state corresponding to the storage area; and in response to the first functional safety detection result indicating that there is a functional safety exception in the second chip domain 3, perform the first target exception handling operation.

[0103] Optionally, for the specific manner in which the first isolation sub-circuit 51 determines the first functional safety detection result of the second chip domain 3 based on the actual feedback status corresponding to the storage area, refer to the relevant introduction in the foregoing text and will not be elaborated here. If the first functional safety detection result indicates that there is a functional safety anomaly in the second chip domain 3, the first isolation sub-circuit 51 may perform a first target anomaly handling operation, and the first target anomaly handling operation may be an anomaly handling operation for preventing the functional safety anomaly of the second chip domain 3 from affecting the normal operation of the first chip domain 1.

[0104] In some alternative embodiments of the present disclosure, the first isolation sub-circuit 51 for performing the first target anomaly handling operation may include:

[0105] The first isolation sub-circuit 51 is configured to send a first interrupt signal to the first chip domain 1, so that in response to obtaining the first interrupt signal, the first chip domain 1 controls the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 to be reset.

[0106] Optionally, a reset line may be provided between the first chip domain 1 and the second chip domain 3, a reset line may be provided between the first chip domain 1 and the isolation module 531, a reset line may be provided between the first chip domain 1 and the first buffer 533, and a reset line may also be provided between the first chip domain 1 and the second buffer 535. The first chip domain 1 may respectively send reset signals to the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 via these reset lines, so that the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 perform reset operations in response to the received reset signals. Alternatively, the first chip domain 1 may write reset instructions for the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 respectively in the configuration module 514, and the first isolation sub-circuit 51 may transmit the reset instructions written in the configuration module 514 to the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 respectively, so that the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 perform reset operations in response to the received reset instructions.

[0107] In this embodiment, the first isolation sub-circuit 51 can send a first interrupt signal to the first chip domain 1, enabling the first chip domain 1 to sense the functional safety exception of the second chip domain 3. As a result, the first chip domain 1 can promptly control the reset of the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535. On the one hand, this can restore the second chip domain 3 to its normal operating state to prevent the functional safety exception of the second chip domain 3 from affecting the normal operation of the first chip domain 1. On the other hand, it can clear the data cached in the second isolation sub-circuit 53 (such as the target content cached in the first buffer 533, the data access feedback cached in the second buffer 535, and the second quantity recorded by the second counter 5313 in the following text) to avoid the impact of this data on subsequent data accesses.

[0108] In some other alternative embodiments of the present disclosure, the first isolation sub-circuit 51 is configured to perform a first target exception handling operation, including:

[0109] The first isolation sub-circuit 51 is configured to disconnect the communication link between the first isolation sub-circuit 51 and the first buffer 533, and disconnect the communication link between the first isolation sub-circuit 51 and the second buffer 535.

[0110] Optionally, the communication link between the first isolation sub-circuit 51 and the first buffer 533 may refer to the bus connecting the first isolation sub-circuit 51 and the first buffer 533. By placing this bus in an open circuit state, the communication link between the first isolation sub-circuit 51 and the first buffer 533 can be disconnected. The method of disconnecting the communication link between the first isolation sub-circuit 51 and the second buffer 535 is similar and will not be elaborated here. Specifically, when implementing, the positions where a "×" symbol is separately drawn between the first isolation sub-circuit 51 and the second isolation sub-circuit 53 in Figure 3 shall all be placed in an open circuit state.

[0111] In the embodiments of the present disclosure, by disconnecting the communication link between the first isolation sub-circuit 51 and the first buffer 533, and disconnecting the communication link between the first isolation sub-circuit 51 and the second buffer 535, it is beneficial to cut off the communication link between the first chip domain 1 and the second chip domain 3, and prevent the functional safety exception of the second chip domain 3 from affecting the normal operation of the first chip domain 1.

[0112] In some alternative examples, as Figure 3 shown, the isolation module 531 may include a second reading module 5311 and a second counter 5313;

[0113] The second counter 5313 is configured to record the second quantity of the target content already cached in the first buffer 533;

[0114] Before the isolation module 531 performs a memory access operation on a storage area of the storage space based on the target content in the first buffer 533, the second reading module 5311 is configured to determine that the first buffer 533 meets a preset reading condition in response to a second quantity of the target content cached in the first buffer 533, read data from the first buffer 533, and obtain the target content in the first buffer 533.

[0115] Optionally, the preset reading condition may be that the buffer is in a non-empty state (i.e., there is content available for reading in the buffer).

[0116] Before the isolation module 531 performs a memory access operation on a storage area of the storage space based on the target content in the first buffer 533, the second reading module 5311 may determine whether the second quantity of the target content cached in the first buffer 533 recorded by the second counter 5313 is 0. If the second quantity of the target content cached in the first buffer 533 is not 0, it indicates that there is target content available for reading in the first buffer 533, and it can be determined that the first buffer 533 meets the preset reading condition. Then, the second reading module 5311 may send a read enable signal to the first buffer 533, and the first buffer 533 may respond to the received read enable signal and return the target content cached in itself to the second reading module 5311. In this way, the second reading module 5311 can obtain the target content through data reading for subsequent memory access operations. If the second quantity of the target content cached in the first buffer 533 is 0, it indicates that there is no target content available for reading in the first buffer 533, and it can be determined that the first buffer 533 does not meet the preset reading condition, and it may wait for a period of time. After a period of time, if the first buffer 533 meets the preset reading condition, the target content in the first buffer 533 can be obtained through data reading of the first buffer 533 for subsequent memory access operations.

[0117] In the embodiments of the present disclosure, through the settings of the second reading module 5311 and the second counter 5313, the situation where there is target content available for reading in the first buffer 533 can be monitored, and data reading is performed only in this situation. In this way, the target content can be successfully read for subsequent memory access operations, which helps to avoid resource consumption and power consumption caused by data reading in other situations except this situation.

[0118] In some alternative examples, the isolation circuit 5 is further configured to perform a first target exception handling operation in response to obtaining an actual memory access feedback from the second chip domain 3, and the actual memory access feedback and the data memory access request meet a preset non-correlation condition.

[0119] Optionally, the condition that the actual memory access feedback and the data memory access request meet the preset non - associated condition can be understood as follows: the actual memory access feedback is not returned for the memory access operation corresponding to the data memory access request by the second chip domain 3, but is spontaneously initiated by the second chip domain 3. The preset non - associated condition can be: different carrying states of the request ID. For example, the carrying state of the request ID in the data memory access request is: carrying the request ID, and the specific request ID carried is ID1, and the carrying state of the request ID in the actual memory access feedback is: not carrying the request ID, or carrying the request ID and the carried request ID is ID2 (which is different from any ID1 carried in the data memory access request), then it can be determined that the actual memory access feedback and the data memory access request meet the preset non - associated condition.

[0120] Optionally, as Figure 3 shown, the detection module 511 may include a third detection unit 5115. The third detection unit 5115 may be the detection unit in the detection module 511 for making judgments related to the preset non - associated condition. If the isolation circuit 5 obtains the actual memory access feedback from the second chip domain 3, and the third detection unit 5115 determines that the actual memory access feedback and the data memory access request meet the preset non - associated condition, this indicates that the first chip domain 1 did not initiate the data memory access request, but the second chip domain 3 gave a feedback, which is obviously abnormal. Therefore, the third detection unit 5115 may determine that there is a functional safety exception in the second chip domain 3. At this time, the third detection unit 5115 may perform the first target exception handling operation. The type of the first target exception handling operation can refer to the relevant introduction in the above text and will not be elaborated here. In this way, it is beneficial to restore the second chip domain 3 to the normal working state, avoid the functional safety exception of the second chip domain 3 from affecting the normal operation of the first chip domain 1, and is also beneficial to empty the data cached in the second isolation sub - circuit 53 to avoid these data from affecting subsequent data memory access, and is also beneficial to cut off the communication link between the first chip domain 1 and the second chip domain 3 to further avoid the functional safety exception of the second chip domain 3 from affecting the normal operation of the first chip domain 1.

[0121] In some optional examples, the isolation circuit 5 is also used to record the third quantity of the data memory access requests in execution; determine the numerical relationship between the third quantity of the data memory access requests in execution and the preset quantity; based on the numerical relationship, determine the second functional safety detection result of the first chip domain 1; and in response to the second functional safety detection result indicating that there is a functional safety exception in the first chip domain 1, perform the second target exception handling operation.

[0122] Optionally, as Figure 3As shown, the detection module 511 may include a fourth detection unit 5117. The fourth detection unit 5117 may be a detection unit in the detection module 511 for detecting functional safety anomalies in the first chip domain 1. The fourth detection unit 5117 may record the number of data access requests during actual execution (i.e., the third number). The data access requests during execution may be understood as: data access requests that the first chip domain 1 has sent to the isolation circuit 5 but for which the first chip domain 1 has not yet received the request execution results from the isolation circuit 5. Additionally, the configuration module 514 may configure a preset number in the fourth detection unit 5117. The preset number may be the maximum number of data access requests during execution supported by the isolation circuit 5. The fourth detection unit 5117 may also determine the numerical relationship between the third number of data access requests during execution and the preset number. The numerical relationship between the third number of data access requests during execution and the preset number may be the magnitude relationship between the third number of data access requests during execution and the preset number. If the numerical relationship between the third number of data access requests during execution and the preset number indicates that the third number of data access requests during execution is greater than the preset number, this means that the number of data access requests during actual execution has exceeded the maximum number supported by the isolation circuit 5, which is obviously abnormal. Therefore, the second functional safety detection result may indicate that there is a functional safety anomaly in the first chip domain 1. If the numerical relationship between the third number of data access requests during execution and the preset number indicates that the third number of data access requests during execution is less than or equal to the preset number, this means that the number of data access requests during actual execution has not exceeded the maximum number supported by the isolation circuit 5. Therefore, the second functional safety detection result may indicate that there is no functional safety anomaly in the first chip domain 1. If the second functional safety detection result indicates that there is a functional safety anomaly in the first chip domain 1, the fourth detection unit 5117 may perform a second target anomaly handling operation. The second target anomaly handling operation may be a repair operation for the functional safety anomaly of the second chip domain 3.

[0123] In some alternative embodiments of the present disclosure, the isolation circuit 5 for performing the second target anomaly handling operation may include:

[0124] The isolation circuit 5 is used to send a second interrupt signal to the first chip domain 1 so that the first chip domain 1 performs a reset operation in response to obtaining the second interrupt signal.

[0125] If the second functional safety detection result indicates that there is a functional safety anomaly in the first chip domain 1, the fourth detection unit 5117 may send a second interrupt signal to the first chip domain 1 so that, through the second interrupt signal, the first chip domain 1 senses its own functional safety anomaly, thereby enabling the first chip domain 1 to promptly restore itself to the normal operating state through a reset operation.

[0126] Of course, the type of the second target exception handling operation is not limited to this, and any other operation that can help restore the first chip domain 1 to the normal operating state is feasible. For example, the isolation circuit 5 can issue an alarm signal to prompt manual repair of the exception in the first chip domain 1.

[0127] In some alternative examples, the first chip domain 1 can be a chip domain with a functional safety level of ASIL-D, and the second chip domain 3 can be a chip domain with a functional safety level of ASIL-A, ASIL-B, or ASIL-C. In this case, the first chip domain 1 can also be referred to as the ASIL-D domain, and the second chip domain 3 can also be referred to as the other domain. Additionally, the isolation circuit 5 can be referred to as the bdiso_dp IP, the first isolation sub-circuit 51 can be referred to as the bdiso_dp_s, and the sub-circuit composed of two asynchronous modules (see Figure 3 , and the asynchronous modules can be used to implement cross-asynchrony) in the first buffer 533, the second buffer 535, and the second isolation sub-circuit 53 can be referred to as the bdiso_dp_async, and the isolation module 531 can be referred to as the bdiso_dp_m. The number of the second isolation sub-circuits 53 can be two.

[0128] If the ASIL-D domain needs to write to the other domain, the ASIL-D domain can initiate a write request and write data to the isolation circuit 5 via the bus. After receiving the write request and write data, the bdiso_dp_s stores them in the two first buffers 533 in the two second isolation sub-circuits 53. The first detection unit 5111 starts timing, and the fourth detection unit 5117 starts counting. The bdiso_dp_m reads the two first buffers 533 respectively and sends the read data (including the write request and write data) to two different storage areas of the DDR in the other domain for storage. After receiving the write feedback from the other domain, the bdiso_dp_m stores them in the two second buffers 535 in the two second isolation sub-circuits 53 respectively. When the first reading module 515 in the bdiso_dp_s finds that both of the two second buffers 535 are not empty, it reads the two second buffers 535 respectively and compares the two reading results (equivalent to determining the first matching degree) as described above. If the comparison passes (for example, the first matching degree is 1), the data (specifically, the request execution result) is returned to the ASIL-D domain; otherwise, an interrupt is reported. If no feedback is received within the specified time duration, it is determined that the other domain has hung.

[0129] If the ASIL-D domain needs to read other domains, the ASIL-D domain can initiate a read request to the isolation circuit 5 via the bus. After receiving the read request, bdiso_dp_s stores it in two first buffers 533 in the two second isolation sub-circuits 53. The first detection unit 5111 starts timing, and the fourth detection unit 5117 starts counting. Bdiso_dp_m reads the two first buffers 533 respectively and sends the read data (including the read request) to the other domain. After receiving two read feedbacks from the DDR in the other domain, bdiso_dp_m stores them in two second buffers 535 in the two second isolation sub-circuits 53 respectively. When the first reading module 515 in bdiso_dp_s finds that both second buffers 535 are not empty, it reads the two second buffers 535 respectively and compares the two reading results (equivalent to determining the first matching degree in the above text). If the comparison passes (for example, the first matching degree is 1), the data (i.e., the request execution result) is returned to the ASIL-D domain; otherwise, an interrupt is reported. If no feedback is received within the specified time, it is considered that the other domain has crashed.

[0130] Optionally, the bdiso_dp IP can report an interrupt in the following scenarios: a. The number of outstanding commands issued by the ASIL-D domain exceeds the set value (equivalent to the third quantity of data memory access requests in execution in the above text being greater than the preset quantity); b. The other domain does not give feedback within the specified clock (equivalent to the second chip domain 3 not returning the actual memory access feedback before the timing duration of the timing operation in the above text reaches the preset duration); c. The comparison of the read data or write feedback given by the other domain fails (equivalent to at least two actual memory access feedbacks being actually inconsistent in the above text); d. The ASIL-D domain does not issue a command, but the other domain gives feedback (equivalent to the actual memory access feedback and the data memory access request meeting the preset non-correlation condition in the above text).

[0131] Optionally, when the CPU in the ASIL-D domain receives the interrupt reported by the bdiso_dp IP, it can intervene through software to reset the other domain or perform other operations that can restore it to the normal working state. At the same time, it can also reset bdiso_dp_async and bdiso_dp_m to clear the data cached in the bdiso_dp IP.

[0132] Optionally, as Figure 3As shown, the first isolation sub-circuit 51 may further include some handshaking modules for handshaking communication between the first isolation sub-circuit 51 and the first chip domain 1. Based on the handshaking communication between the first isolation sub-circuit 51 and the first chip domain 1, the first isolation sub-circuit 51 may send a signal R1 to the first chip domain 1. The signal R1 may indicate whether new target content can be written into the first buffer 533. The first chip domain 1 may return a signal R2 to the first isolation sub-circuit 51. The signal R2 may indicate that the signal R1 has been received. Based on the handshaking communication between the first isolation sub-circuit 51 and the first chip domain 1, the first chip domain 1 may send a signal R3 to the first isolation sub-circuit 51. The signal R3 may indicate whether the first chip domain 1 can receive a new request execution result. The first isolation sub-circuit 51 may return a signal R4 to the first chip domain 1. The signal R4 may indicate that the signal R3 has been received.

[0133] Similarly, as Figure 3 shown, the isolation module 531 may further include some handshaking modules for handshaking communication between the isolation module 531 and the second chip domain 3. Based on the handshaking communication between the isolation module 531 and the second chip domain 3, the second chip domain 3 may send a signal R5 to the isolation module 531. The signal R5 may indicate whether the second chip domain 3 can support a new memory access operation. The isolation module 531 may, in response to receiving the signal R5, return a signal R6 to the second chip domain 3. The signal R6 may indicate that the signal R5 has been received. Based on the handshaking communication between the isolation module 531 and the second chip domain 3, the isolation module 531 may send a signal R7 to the second chip domain 3. The signal R7 may indicate whether new data memory access feedback has been written into the second buffer 535. The second chip domain 3 may, in response to receiving the signal R7, return a signal R8 to the isolation module 531. The signal R8 may indicate that the signal R7 has been received.

[0134] In summary, by adopting the embodiments of the present disclosure, the storage space of a chip domain with a low functional safety level can be used as the extended storage space of a chip domain with a high functional safety level, which has high flexibility. It is beneficial to expand the storage space of the chip domain with a high functional safety level without bringing additional chip area overhead, enabling the chip domain with a high functional safety level to run programs smoothly, saving costs, and is particularly suitable for scenarios where the memory size of the chip domain with a high functional safety level is limited. Additionally, when a functional safety exception occurs in the chip domain with a low functional safety level, it can be effectively isolated by the bdiso_dp IP, ensuring the normal and reliable operation of the chip domain with a high functional safety level. Moreover, the chip domain with a high functional safety level can perceive the functional safety exception of the chip domain with a low functional safety level.

[0135] Exemplary Method

[0136] Figure 4It is a schematic flowchart of a chip-based data access method provided by some exemplary embodiments of the present disclosure. Figure 4 In the method shown, the chip may include a first chip domain, a second chip domain, and an isolation circuit, and the functional safety level of the first chip domain is higher than that of the second chip domain. Figure 4 The method shown may include:

[0137] Step 410, generating a data access request for the second chip domain through the first chip domain;

[0138] Step 420, performing the following operations through the isolation circuit to make the storage space of the second chip domain serve as an extended storage space of the first chip domain: based on the data access request, performing an access operation on the storage space of the second chip domain, and based on the actual feedback status of the second chip domain on the access operation, returning the request execution result of the data access request to the first chip domain.

[0139] In some optional examples, the isolation circuit includes: a second isolation sub-circuit, and the second isolation sub-circuit includes: a first buffer and a second buffer;

[0140] As Figure 5 shown, based on the data access request, performing an access operation on the storage space of the second chip domain, and based on the actual feedback status of the second chip domain on the access operation, returning the request execution result of the data access request to the first chip domain may include:

[0141] Step 510, caching the target content in the first buffer based on the data access request;

[0142] Step 520, performing an access operation on a storage area of the storage space based on the target content in the first buffer;

[0143] Step 530, in response to obtaining the actual access feedback of the second chip domain on the access operation of the storage area, caching the actual access feedback in the second buffer;

[0144] Step 540, determining the actual feedback status of the access operation of the second chip domain on the storage area based on the caching status of the actual access feedback in the second buffer;

[0145] Step 550, returning the request execution result of the data access request to the first chip domain based on the actual feedback status corresponding to the storage area.

[0146] In some optional examples, as Figure 6 shown, step 550 includes:

[0147] Step 610, determining the first functional safety detection result of the second chip domain based on the actual feedback status corresponding to the storage area;

[0148] Step 620: Based on the first functional safety detection result, return the request execution result of the data memory access request to the first chip domain.

[0149] In some alternative examples, the number of the second isolation sub-circuits is at least two, and the at least two second isolation sub-circuits correspond to at least two storage areas;

[0150] Step 610 includes:

[0151] In response to that at least two actual feedback states corresponding to the at least two storage areas both indicate that the second chip domain has returned an actual memory access feedback, determine a first matching degree between at least two actual memory access feedbacks corresponding to the at least two actual feedback states;

[0152] Based on the first matching degree, determine the first functional safety detection result of the second chip domain.

[0153] In some alternative examples, as Figure 7 shown, the method provided by the embodiments of the present disclosure may further include:

[0154] Step 710: Record a first quantity of the actual memory access feedbacks respectively cached by at least two second buffers in the at least two second isolation sub-circuits;

[0155] Step 720: In response to determining that the at least two second buffers all meet a preset reading condition based on the first quantity of the actual memory access feedbacks respectively cached by the at least two second buffers, perform data reading on the at least two second buffers respectively, so as to obtain two actual memory access feedbacks corresponding to at least two actual feedback states respectively.

[0156] Optionally, step 720 may be executed before step 610.

[0157] In some alternative examples, as Figure 8 shown, the method provided by the embodiments of the present disclosure may further include:

[0158] Step 810: In response to the isolation circuit obtaining a data memory access request, start performing a timing operation;

[0159] Step 610 includes:

[0160] Step 820: Determine a second matching degree between the actual feedback state corresponding to the storage area and the expected feedback state; wherein, the expected feedback state indicates that the second chip domain has returned an actual memory access feedback before the timing duration of the timing operation reaches a preset duration;

[0161] Step 830: Based on the second matching degree, determine the first functional safety detection result of the second chip domain.

[0162] In some alternative examples, step 620 includes:

[0163] In response to the first functional safety detection result indicating that there is no functional safety anomaly in the second chip domain, based on the actual feedback status corresponding to the storage area, determine the target actual memory access feedback, and return the target actual memory access feedback as the request execution result of the data memory access request to the first chip domain;

[0164] Or,

[0165] The result return module is configured to, in response to the first functional safety detection result indicating that there is a functional safety anomaly in the second chip domain, generate an analog memory access feedback corresponding to the data memory access request, and return the analog memory access feedback as the request execution result of the data memory access request to the first chip domain.

[0166] In some alternative examples, as Figure 9 shown, the method provided by the embodiments of the present disclosure may further include:

[0167] Step 910, determine the first functional safety detection result of the second chip domain based on the actual feedback status corresponding to the storage area;

[0168] Step 920, in response to the first functional safety detection result indicating that there is a functional safety anomaly in the second chip domain, perform a first target anomaly handling operation through an isolation circuit.

[0169] In some alternative examples, performing the first target anomaly handling operation through an isolation circuit includes:

[0170] Send a first interrupt signal to the first chip domain through the isolation circuit, so that in response to obtaining the first interrupt signal, the first chip domain controls the second chip domain, and resets the isolation module, the first buffer, and the second buffer in the second isolation circuit;

[0171] And / or,

[0172] Disconnect the communication link between the first isolation circuit and the first buffer in the isolation circuit, and disconnect the communication link between the first isolation circuit and the second buffer.

[0173] In some alternative examples, as Figure 10 shown, the method provided by the embodiments of the present disclosure may further include:

[0174] Step 1010, record the second quantity of the target content cached in the first buffer;

[0175] Step 1020, in response to determining that the first buffer meets the preset reading condition based on the second quantity of the target content cached in the first buffer, perform data reading on the first buffer to obtain the target content in the first buffer.

[0176] Optionally, step 1020 may be executed before step 520.

[0177] In some alternative examples, such as Figure 11 as shown, the method provided by the embodiments of the present disclosure may further include:

[0178] Step 1110, in response to the isolation circuit obtaining the actual memory access feedback from the second chip domain, determining whether the actual memory access feedback and the data memory access request meet a preset non - correlation condition; in response to the actual memory access feedback and the data memory access request meeting the preset non - correlation condition, proceeding to step 1120;

[0179] Step 1120, performing a first target exception handling operation through the isolation circuit.

[0180] In some alternative examples, such as Figure 12 as shown, the method provided by the embodiments of the present disclosure may further include:

[0181] Step 1210, recording the third quantity of the data memory access requests being executed;

[0182] Step 1220, determining the numerical relationship between the third quantity of the data memory access requests being executed and a preset quantity;

[0183] Step 1230, determining the second functional safety detection result of the first chip domain based on the numerical relationship;

[0184] Step 1240, in response to the second functional safety detection result indicating that there is a functional safety exception in the first chip domain, performing a second target exception handling operation through the isolation circuit.

[0185] In some alternative examples, performing the second target exception handling operation through the isolation circuit includes:

[0186] Sending a second interrupt signal to the first chip domain through the isolation circuit, so that the first chip domain performs a reset operation in response to obtaining the second interrupt signal.

[0187] In some alternative examples, such as Figure 13As shown, when the isolation circuit is in an idle state (i.e., there is no memory access task being executed or pending execution in the isolation circuit), the first chip domain can initiate a data memory access request to the isolation circuit to start data transmission between the first chip domain and the isolation circuit. The isolation circuit can detect whether there is a functional safety exception in the second chip domain. If there is a functional safety exception in the second chip domain, the isolation circuit can generate an analog memory access feedback corresponding to the data memory access request and return the analog memory access feedback as the request execution result of the data memory access request to the first chip domain. Additionally, the isolation circuit can also report an interruption to the first chip domain. At this time, the CPU in the first chip domain can perform exception repair on the second chip domain through software control (such as controlling the second chip domain to reset), and can also Figure 3 all the positions where the symbol "×" is separately drawn between the first isolation sub-circuit 51 and the second isolation sub-circuit 53 in Figure 3 are placed in an open circuit state (at this time, it can be considered that the isolation circuit is in the fence state). After the functional safety exception in the second chip domain is successfully resolved, the isolation circuit can exit the fence state, that is, Figure 3 the positions where the symbol "×" is separately drawn between the first isolation sub-circuit 51 and the second isolation sub-circuit 53 in Figure 3 can all be restored to a conducting state.

[0188] In the method of the present disclosure, various optional embodiments, optional implementations, and optional examples disclosed in the above exemplary circuit part can be flexibly selected and combined as needed to achieve corresponding functions and effects, and the present disclosure does not list them one by one.

[0189] For the beneficial technical effects corresponding to the exemplary embodiments of the present method, reference can be made to the corresponding beneficial technical effects in the above exemplary circuit part, which will not be elaborated here.

[0190] Exemplary Electronic Device

[0191] Figure 14 The block diagram of an electronic device according to an embodiment of the present disclosure is illustrated. The electronic device 1400 includes one or more processors 1410 and a memory 1420.

[0192] The processor 1410 can be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and can control other components in the electronic device 1400 to perform desired functions.

[0193] The memory 1420 may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 1410 may run the one or more computer program instructions to implement the methods of the various embodiments of the present disclosure described above and / or other desired functions.

[0194] In one example, the electronic device 1400 may further include: an input device 1430 and an output device 1440, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0195] The input device 1430 may further include, for example, a keyboard, a mouse, etc.

[0196] The output device 1440 may output various information to the outside, which may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0197] Of course, for simplicity, Figure 14 only some of the components related to the present disclosure in the electronic device 1400 are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, according to specific application scenarios, the electronic device 1400 may further include any other appropriate components.

[0198] Exemplary Computer Program Product and Computer Readable Storage Medium

[0199] In addition to the above methods and devices, the embodiments of the present disclosure may also be a computer program product, which includes computer program instructions that, when run by a processor, cause the processor to execute the steps in the methods according to the various embodiments of the present disclosure described in the "Exemplary Methods" section above of this specification.

[0200] The computer program product may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0201] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the methods according to various embodiments of the present disclosure described in the "Exemplary Methods" section above of this specification.

[0202] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0203] The basic principles of the present disclosure have been described above in connection with specific embodiments. However, the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. The above-described specific details are only for the purpose of illustration and easy understanding, and are not limitations. The above details do not limit the present disclosure to necessarily implement with the above specific details.

[0204] Those skilled in the art can make various changes and modifications to the present disclosure without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present disclosure and their equivalent technologies, the present disclosure is also intended to include these changes and modifications.

Claims

1. A chip, comprising: a first chip domain and a second chip domain, the functional safety level of the first chip domain being higher than the functional safety level of the second chip domain, and the first chip domain being used to generate a data access request to the second chip domain; An isolation circuit is used to perform a memory access operation on the storage space of the second chip domain based on the data memory access request, and return a request execution result of the data memory access request to the first chip domain based on an actual feedback status of the memory access operation by the second chip domain, so that the storage space of the second chip domain serves as an extended storage space of the first chip domain.

2. The chip according to claim 1, wherein: The isolation circuit comprises: a first isolation sub-circuit and a second isolation sub-circuit, and the second isolation sub-circuit comprises: an isolation module, a first buffer and a second buffer; The isolation circuit is used to perform a memory access operation on the storage space of the second chip domain based on the data memory access request, and return a request execution result of the data memory access request to the first chip domain based on an actual feedback status of the memory access operation by the second chip domain, including: The first isolation subcircuit is used to cache target content in the first buffer based on the data access request; The isolation module is used to perform a memory access operation on a storage area of ​​the storage space based on the target content in the first buffer; in response to obtaining actual memory access feedback of the memory access operation on the storage area by the second chip domain, cache the actual memory access feedback in the second buffer; The first isolation sub-circuit is used to determine the actual feedback status of the access operation performed by the second chip domain on the storage area based on the cache status of the second cache feedback on the actual memory access; and return the request execution result of the data memory access request to the first chip domain based on the actual feedback status corresponding to the storage area.

3. The chip according to claim 2, wherein: The first isolation subcircuit includes: a detection module and a result return module; The first isolation sub-circuit is used to return the request execution result of the data access request to the first chip domain based on the actual feedback state corresponding to the storage area, including: The detection module is used to determine a first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the storage area; The result returning module is used to return a request execution result of the data access request to the first chip domain based on the first functional safety test result.

4. The chip according to claim 3, wherein: The number of the second isolation sub-circuits is at least two, and at least two isolation modules in at least two of the second isolation sub-circuits correspond to at least two storage areas; The detection module is used to determine a first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the storage area, including: The detection module is used for determining a first matching degree between at least two actual memory access feedbacks corresponding to at least two actual feedback states in response to at least two actual feedback states corresponding to at least two storage areas both indicating that the second chip domain has returned the actual memory access feedback; Based on the first matching degree, a first functional safety test result of the second chip domain is determined.

5. The chip according to claim 4, wherein: The first isolation subcircuit further includes: a first reading module and a first counter; The first counter is used to record a first number of the actual memory access feedbacks cached by at least two of the second buffers in at least two of the second isolation sub-circuits; Before the detection module determines a first matching degree between two actual memory access feedbacks corresponding to at least two actual feedback states, the first reading module is used to determine that at least two second caches satisfy a preset reading condition in response to a first number of the actual memory access feedbacks cached by each of the at least two second caches, and to read data from the at least two second caches respectively to obtain two actual memory access feedbacks corresponding to the at least two actual feedback states respectively.

6. The chip according to claim 3, wherein: The detection module is also used for starting to execute a timing operation in response to the first isolation sub-circuit acquiring the data memory access request; The detection module is used to determine a first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the storage area, including: The detection module is used to determine a second matching degree between the actual feedback state and the expected feedback state corresponding to the storage area; based on the second matching degree, determine a first functional safety detection result of the second chip domain; The expected feedback state indicates that the second chip domain has returned the actual memory access feedback before the timing duration of the timing operation reaches a preset duration.

7. The chip according to claim 3, wherein: The result returning module is used to return the request execution result of the data access request to the first chip domain based on the first functional safety test result, including: The result returning module is used for determining target actual memory access feedback based on the actual feedback state corresponding to the storage area in response to the first functional safety test result indicating that the second chip domain does not have a functional safety anomaly, and returning the target actual memory access feedback as a request execution result of the data memory access request to the first chip domain; or, The result returning module is used to generate simulated memory access feedback corresponding to the data memory access request in response to the first functional safety test result indicating that the second chip domain has a functional safety anomaly, and return the simulated memory access feedback as a request execution result of the data memory access request to the first chip domain.

8. The chip according to claim 2, wherein: The first isolation sub-circuit is also used to determine a first functional safety test result of the second chip domain based on the actual feedback state corresponding to the storage area; and perform a first target exception handling operation in response to the first functional safety test result indicating that the second chip domain has a functional safety abnormality.

9. The chip according to claim 8, wherein: The first isolation sub-circuit is used to perform a first target exception handling operation, including: The first isolation subcircuit is used to send a first interrupt signal to the first chip domain, so that the first chip domain controls the second chip domain, the isolation module, the first buffer, and resets the second buffer in response to obtaining the first interrupt signal; and / or, The first isolation sub-circuit is used to perform a first target exception handling operation, including: The first isolation sub-circuit is used to disconnect the communication link between the first isolation sub-circuit and the first buffer, and to disconnect the communication link between the first isolation sub-circuit and the second buffer.

10. The chip according to claim 2, wherein: The isolation module includes: a second reading module and a second counter; The second counter is used to record a second amount of the target content cached by the first cache; Before the isolation module performs a memory access operation on a storage area of ​​the storage space based on the target content in the first cache, the second reading module is used to determine that the first cache meets a preset reading condition in response to a second amount of the target content cached in the first cache, and read data from the first cache to obtain the target content in the first cache.

11. The chip according to claim 1, wherein: The isolation circuit is further configured to execute a first target exception handling operation in response to obtaining actual memory access feedback from the second chip domain, and the actual memory access feedback and the data memory access request satisfy a preset unrelated condition.

12. The chip according to claim 1, wherein: The isolation circuit is further used to record a third number of the data access memory requests being executed; determine a numerical relationship between the third number of the data access memory requests being executed and a preset number; Based on the numerical relationship, a second functional safety test result of the first chip domain is determined; in response to the second functional safety test result indicating that the first chip domain has a functional safety abnormality, a second target abnormality handling operation is performed.

13. The chip according to claim 12, wherein: The isolation circuit is used to perform a second target exception handling operation, including: The isolation circuit is used to send a second interrupt signal to the first chip domain, so that the first chip domain performs a reset operation in response to obtaining the second interrupt signal.

14. A data access method based on a chip, the chip comprising: A first chip domain, a second chip domain and an isolation circuit, wherein a functional safety level of the first chip domain is higher than a functional safety level of the second chip domain; The data access method comprises: generating, by the first chip domain, a data memory access request to the second chip domain; The following operations are performed through the isolation circuit to make the storage space of the second chip domain serve as the extended storage space of the first chip domain: based on the data memory access request, a memory access operation is performed on the storage space of the second chip domain, and based on the actual feedback status of the memory access operation by the second chip domain, a request execution result of the data memory access request is returned to the first chip domain.

15. A computer-readable storage medium storing a computer program, wherein the computer program is used to execute the method according to claim 14.

16. An electronic device, comprising: processor; a memory for storing instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method of claim 14.