Verification control method of vehicle-gauge-level SoC (System on Chip) chip and related equipment
By setting up a verification module in the AMBA bus protocol of automotive-grade SoC chips, end-to-end detection of data transmission is solved, and the problem that traditional protocols cannot effectively detect and restore data transmission errors is improved, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202510234081.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-27
AI Technical Summary
The traditional AMBA bus protocol cannot effectively detect and recover errors in data transmission in automotive-grade SoC chips, resulting in possible errors in operations and causing serious security problems.
The verification module is respectively set up in the master and slave devices to conduct end-to-end detection of data transmission, generate verification values and attach them to the data to achieve single point failure verification on the bus.
Through the end-to-end verification mechanism, the security and reliability of the functional safety bus are improved, and errors in data transmission can be effectively detected and recovered to prevent incorrect operations.
Smart Images

Figure CN120216252A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of integrated circuit design verification, and in particular to a verification control method and related devices for automotive-grade SoC chips. Background Art
[0002] With the rapid development of automotive electronics technology, automotive-grade SoC chips are increasingly widely used in automotive control systems. Automotive-grade SoC chips need to operate stably for a long time in a harsh environment, so extremely high requirements are put forward for the reliability and security of data transmission.
[0003] Although the traditional AMBA bus protocol has been widely used in consumer-grade SoC chips, in automotive-grade applications, its functional safety mechanism has obvious deficiencies. Especially when facing single-point failures (such as ionizing radiation, lightning strikes, electrostatic charges, etc.), the traditional AMBA bus cannot effectively detect and recover errors in data transmission, which may lead to misoperations in the chip, thus triggering serious safety problems. Therefore, how to implement single-point failure verification on the bus in automotive-grade SoC chips has become an urgent problem to be solved in the current technology. Summary of the Invention
[0004] The embodiments of the present application provide a verification control method for automotive-grade SoC chips. Based on the original commercial AMBA protocol circuit design, by respectively setting verification modules in the master device and the slave device for end-to-end detection of data transmission, single-point failure verification on the bus can be achieved, so that the system can perform further safety processing to improve the safety and reliability of the functional safety bus.
[0005] To achieve the above object, the first aspect of the embodiments of the present application provides a verification control device for automotive-grade SoC chips, including: a functional safety bus connected to multiple master devices and slave devices for realizing data transmission; a master device end verification module provided in each of the master devices; a slave device end verification module provided in each of the slave devices; wherein, when the master device initiates a write operation, the master device end verification module is used to verify the write data sent to the slave device, generate a verification value and append it to the write data; the slave device end verification module is used to receive the write data and the verification value from the master device, and verify the write data based on the verification value; when the master device initiates a read operation, the slave device end verification module is used to verify the read data sent to the master device, generate a verification value and append it to the read data; the master device end verification module is used to receive the read data and the verification value from the slave device, and verify the read data based on the verification value.
[0006] In some embodiments, the master device - side verification module includes: a first injection self - test unit configured to perform error injection based on the read data during power - on self - test to calculate an injected ECC check value; a first verification comparison module configured to compare the injected ECC check value with the additional ECC check value in the read data to obtain a verification comparison result; a first error recovery unit configured to, when the verification comparison result indicates a 1 - bit error, recover the 1 - bit error data and send an error status signal to the corresponding master device, and when the verification comparison result indicates a multi - bit error, send an interrupt status signal corresponding to the multi - bit error to the master device.
[0007] In some embodiments, the slave device - side verification module includes: a second injection self - test unit configured to perform error injection based on the write data during power - on self - test to calculate an injected ECC check value; a second verification comparison module configured to compare the injected ECC check value with the additional ECC check value in the write data to obtain a verification comparison result; a second error recovery unit configured to, when the verification comparison result indicates a 1 - bit error, recover the 1 - bit error data and send an error status signal to the corresponding master device, and when the verification comparison result indicates a multi - bit error, send an interrupt status signal corresponding to the multi - bit error to the master device.
[0008] In some embodiments, the check value includes an ECC check value, an address parity check value, and a control signal parity check value. The master device - side verification module includes a first check calculation unit configured to: calculate an ECC check value for the write data to generate a corresponding ECC check value; calculate an address parity check value for the address information of the write data to generate a corresponding address parity check value; calculate a control signal parity check value for the control signal of the write data to generate a corresponding control signal parity check value.
[0009] In some embodiments, the master device - side verification module includes a second check calculation unit configured to: calculate an ECC check value for the read data to generate a corresponding ECC check value; calculate an address parity check value for the address information of the read data to generate a corresponding address parity check value; calculate a control signal parity check value for the control signal of the read data to generate a corresponding control signal parity check value.
[0010] To achieve the above object, a second aspect of the embodiments of the present application provides a verification control method for an automotive-grade SoC chip. The method is applied to the verification control device of the automotive-grade SoC chip described in any item of the first aspect. The method includes: when the master device initiates a write operation, verifying the write data sent to the slave device through the master device-side verification module, generating a verification value and attaching it to the write data, receiving the write data and the verification value from the master device through the slave device-side verification module, and verifying the write data based on the verification value; when the master device initiates a read operation, verifying the read data sent to the master device through the slave device-side verification module, generating a verification value and attaching it to the read data, receiving the read data and the verification value from the slave device through the master device-side verification module, and verifying the read data based on the verification value.
[0011] In some embodiments, the verifying the write data based on the verification value includes: injecting errors based on the write data during power-on self-test to calculate an injected ECC verification value; comparing the injected ECC verification value with the ECC verification value attached to the write data to obtain a verification comparison result; in the case where the verification comparison result is a 1-bit error, recovering the 1-bit error data and sending an error status signal to the corresponding master device; in the case where the verification comparison result is a multi-bit error, sending an interrupt status signal corresponding to the multi-bit error to the master device.
[0012] In some embodiments, the verifying the read data based on the verification value includes: injecting errors based on the read data during power-on self-test to calculate an injected ECC verification value; comparing the injected ECC verification value with the ECC verification value attached to the read data to obtain a verification comparison result; in the case where the verification comparison result is a 1-bit error, recovering the 1-bit error data and sending an error status signal to the corresponding master device; in the case where the verification comparison result is a multi-bit error, sending an interrupt status signal corresponding to the multi-bit error to the master device.
[0013] To achieve the above object, a third aspect of the embodiments of the present application provides an electronic device, including: at least one processor; at least one memory for storing at least one program; when at least one of the programs is executed by at least one of the processors, implementing the verification control method for the automotive-grade SoC chip described in any item of the second aspect.
[0014] To achieve the above object, a fourth aspect of the embodiments of the present application provides a computer-readable storage medium storing computer-executable instructions for executing the verification control method of the automotive-grade SoC chip as described in any one of the second aspect.
[0015] The embodiments of the present application provide a verification control method for an automotive-grade SoC chip and related devices, which at least include the following beneficial effects: In the present application, the functional safety bus is implemented based on the AMBA protocol and connects multiple master devices and slave devices; the master device-side verification module is provided in each master device and may include a power-on self-test unit, an ECC calculation unit, and an error recovery unit; the slave device-side verification module is provided in each slave device and may also include a power-on self-test unit, an ECC calculation unit, and an error recovery unit; wherein, when the master device initiates a write operation, the master device-side verification module can be used to calculate the ECC check value, address parity check value, and control signal parity check value for the write data, address, and control signal, and attach the check value to the write data; the slave device-side verification module can be used to receive the write data and the check value, verify the data integrity through the check value, and recover the data when detecting a 1-bit error and trigger an interrupt when detecting a multi-bit error; when the master device initiates a read operation, the slave device-side verification module can be used to calculate the check value for the read data, address, and control signal and attach it to the read data; the master device-side verification module can be used to receive the read data and the check value, verify the data integrity through the check value, and recover the data when detecting a 1-bit error and trigger an interrupt when detecting a multi-bit error; it can be understood that in the present application, by adding end-to-end verification on the basis of the AMBA bus protocol, single-point failure verification on the bus can be achieved, and the following further security processing can be performed. For example, after calibration errors occur, as many verification errors as possible are performed on the verification results according to the verification feedback results, the original operation instruction is restored, and when the algorithm determines that the original operation instruction cannot be restored, the bus error status is fed back to the CPU or outside the chip to effectively improve the security and reliability of the functional safety bus. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 Schematic diagram of a verification control device for an automotive-grade SoC chip provided by an embodiment of the present application;
[0017] Figure 2 Schematic diagram of the master device-side verification module in the verification control device for an automotive-grade SoC chip provided by an embodiment of the present application;
[0018] Figure 3 Schematic diagram of the slave device-side verification module in the verification control device for an automotive-grade SoC chip provided by an embodiment of the present application;
[0019] Figure 4In the verification control device of the automotive-grade SoC chip provided by an embodiment of the present application, the timing diagram of the bus verification data and results;
[0020] Figure 5 The method flow chart of the verification control method of the automotive-grade SoC chip provided by an embodiment of the present application;
[0021] Figure 6 In the verification control method of the automotive-grade SoC chip provided by an embodiment of the present application, the method flow chart for verifying the write data based on the verification value;
[0022] Figure 7 In the verification control method of the automotive-grade SoC chip provided by an embodiment of the present application, the method flow chart for verifying the read data based on the verification value;
[0023] Figure 8 In the verification control method of the automotive-grade SoC chip provided by an embodiment of the present application, the schematic diagram of the process for performing a safety bus self-check process;
[0024] Figure 9 The structural schematic diagram of the electronic device provided by an embodiment of the present application. Detailed implementation manners
[0025] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0026] In some embodiments, although the functional modules are divided in the system schematic diagram and the logical order is shown in the flow chart, in some cases, the steps shown or described can be executed in a different order from the module division in the system or the order in the flow chart. Terms such as first and second in the description, claims and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.
[0027] In addition, unless otherwise clearly specified and limited, the term "connected / linked" should be understood in a broad sense. For example, it can be a fixed connection or a movable connection, or a detachable connection or an inseparable connection, or an integral connection; it can be a mechanical connection, an electrical connection or can communicate with each other; it can be directly connected or indirectly connected through an intermediate medium.
[0028] In the description of the embodiments of the present application, the descriptions referring to terms such as "one embodiment / implementation", "another embodiment / implementation", "certain embodiments / implementations", "in the above embodiments / implementations", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiments or examples are included in at least two embodiments or implementations disclosed in the present application. In the disclosure of the present application, the schematic expressions of the above terms do not necessarily refer to the same embodiment or implementation. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in an order different from that in the flowchart.
[0029] With the rapid development of automotive electronic technology, automotive-grade SoC chips are increasingly widely used in automotive control systems. Automotive-grade SoC chips need to operate stably for a long time in a harsh environment, so extremely high requirements are put forward for the reliability and security of data transmission. Although the traditional AMBA bus protocol has been widely used in consumer-grade SoC chips, in automotive-grade applications, its functional safety mechanism has obvious deficiencies. Especially when facing single-point failures (such as ionizing radiation, lightning strikes, electrostatic charges, etc.), the traditional AMBA bus cannot effectively detect and recover errors in data transmission, which may lead to misoperations in the chip, thus triggering serious safety problems. Therefore, how to implement single-point failure verification on the bus in automotive-grade SoC chips has become an urgent problem to be solved in the current technology.
[0030] Based on this, the embodiments of the present application provide a verification control method for automotive-grade SoC chips, which can, on the basis of the original commercial AMBA protocol circuit design, realize end-to-end detection of data transmission by respectively setting verification modules in the master device and the slave device, so as to implement single-point failure verification on the bus, and further enable the system to perform further safety processing to improve the safety and reliability of the functional safety bus.
[0031] The following further illustrates the embodiments of the present application with reference to the accompanying drawings.
[0032] Refer to Figure 1 , Figure 1Schematic diagram of the verification control device for the automotive-grade SoC chip provided by an embodiment of the present application; To achieve the above object, a first aspect of the embodiments of the present application provides a verification control device for an automotive-grade SoC chip, including: A functional safety bus, connecting multiple master devices and slave devices, for realizing data transmission; A master device-side verification module, provided in each master device; A slave device-side verification module, provided in each slave device; Wherein, when the master device initiates a write operation, the master device-side verification module is used to verify the write data sent to the slave device, generate a verification value and append it to the write data; The slave device-side verification module is used to receive the write data and the verification value from the master device, and verify the write data based on the verification value; When the master device initiates a read operation, the slave device-side verification module is used to verify the read data sent to the master device, generate a verification value and append it to the read data; The master device-side verification module is used to receive the read data and the verification value from the slave device, and verify the read data based on the verification value.
[0033] As Figure 1 shown, Figure 1 It shows a schematic diagram of the verification control device for the automotive-grade SoC chip provided by the embodiment of the present application. The device mainly includes a functional safety bus, a master device-side verification module (E2E_M) and a slave device-side verification module (E2E_S).
[0034] The following is a detailed explanation of Figure 1 each part in
[0035] Functional safety bus: The functional safety bus is the core part of the entire verification control device, used to connect multiple master devices and slave devices to realize data transmission. This bus not only supports the traditional AMBA protocol, but also adds an end-to-end verification mechanism to ensure the reliability and security of data transmission. The design of the functional safety bus meets the functional safety requirements of automotive-grade chips, and can effectively detect and correct errors in data transmission, improving the overall reliability of the system.
[0036] Master device-side verification module (E2E_M): The master device-side verification module is provided in each master device and is responsible for verifying the data sent to the slave device. When the master device (such as CPU0 or CPU1) initiates a write operation, the E2E_M module verifies the write data, generates a verification value (such as ECC check value, address parity check value and control signal parity check value), and appends the verification value to the write data, so that the write data can be verified by the slave device-side verification module during transmission, ensuring the integrity and correctness of the data; When the master device initiates a read operation, the E2E_M module receives the read data and the verification value from the slave device, and verifies the read data based on the verification value. If the verification passes, the master device can continue to process the data; If the verification fails, the E2E_M module will trigger the corresponding error handling mechanism, such as a retransmission request or sending an error signal to the slave device.
[0037] Slave - side verification module (E2E_S): The slave - side verification module is set in each slave device and is responsible for verifying the received data. When a slave device receives write data and a verification value from the master device, the E2E_S module verifies the write data based on the verification value. If the verification passes, the write data will be correctly written into the storage unit of the slave device; if the verification fails, the E2E_S module will trigger corresponding error - handling mechanisms, such as re - transmission requests or sending error signals to the master device. When the slave device initiates a read operation, the E2E_S module verifies the read data, generates a verification value, and attaches the verification value to the read data so that the read data can be verified by the master - side verification module during transmission, ensuring the integrity and correctness of the data.
[0038] In some embodiments, the patent of this application is the original commercial bus. E2E_M and E2E_S modules are respectively added to the MASTER side and the SLAVE side. By using the E2E_M and E2E_S modules, signals such as data, address, control lines, and operation time uploaded on the bus can be monitored in real - time, and the error status can be reported to the CPU in real - time or output outside the chip.
[0039] It can be understood that when the MASTER side corresponding to the master - side verification module initiates a write operation by the master device (such as a CPU), it calculates the verification value for the data, address, and control bus; when reading, it calculates the verification value for the address and control bus, calculates the verification value of the read data, and compares it with the verification value returned by the SLAVE side corresponding to the slave - side verification module. When the two verification values are different, the data is corrected as much as possible; when the SLAVE side receives a write from the MASTER, it calculates the verification value for the write data, address, and control bus and compares it with the MASTER result. When they are inconsistent, it also corrects as much as possible. When reading, it calculates and compares the verification value for the address and control bus, and calculates the verification value for the returned data; the MASTER side is mainly connected to the master device (common master devices in the SOC include CPU, DMA, DSP, etc.), and the SLAVE side can be set on the bus and external devices (there are many common slave devices in the SOC, such as UART, CAN, etc.).
[0040] In addition, when the SoC is integrated and developed, those skilled in the art can integrate the functional - safety verification modules of the MASTER side (E2E_M) and the SLAVE side (E2E_S) based on the content of this application according to the AMAB protocol interface, and then a secure bus with functional safety for the on - chip bus of the entire chip can be realized.
[0041] In some embodiments, Figure 1Several specific master devices and slave devices are shown: The master devices include CPU0 and CPU1, and each CPU is connected to an E2E_M module. The slave devices include:
[0042] MEM: A memory device, connected to an E2E_S module;
[0043] ROM / RAM: Read-only memory and random access memory, connected to an E2E_S module;
[0044] Peripherals1: Includes peripherals such as UART, SPI, I2C, GPIO, Timer, CAN, etc., connected to an E2E_S module;
[0045] Peripherals2: Includes peripherals such as CTE, RF, etc., connected to an E2E_S module;
[0046] Among them, when CPU0 or CPU1 initiates a write operation, the E2E_M module verifies the write data, can generate a check value and append it to the write data. The write data and the check value are transmitted to the corresponding slave device (such as MEM, ROM / RAM, Peripherals1 or Peripherals2) through the functional safety bus. The E2E_S module of the slave device receives the write data and the check value, and verifies the write data based on the check value. If the verification passes, the write data is correctly written into the slave device; if the verification fails, the E2E_S module triggers an error handling mechanism.
[0047] When CPU0 or CPU1 initiates a read operation, the E2E_M module generates a read request and sends it to the corresponding slave device. The E2E_S module of the slave device receives the read request, reads the data and generates a check value, appends the check value to the read data. The read data and the check value are transmitted back to the master device through the functional safety bus. The E2E_M module of the master device receives the read data and the check value, and verifies the read data based on the check value. If the verification passes, the master device continues to process the data; if the verification fails, the E2E_M module triggers an error handling mechanism.
[0048] Through the above design, the check control device of the in-vehicle grade SoC chip in the embodiments of the present application can effectively improve the reliability and security of data transmission, and meet the strict functional safety requirements of in-vehicle grade chips.
[0049] In some embodiments, the functional safety bus in the present application is implemented based on the AMBA protocol and connects multiple master devices and slave devices. The master device - side verification module is provided in each master device and may include a power - on self - test unit, an ECC calculation unit, and an error recovery unit. The slave device - side verification module is provided in each slave device and may also include a power - on self - test unit, an ECC calculation unit, and an error recovery unit. Among them, when the master device initiates a write operation, the master device - side verification module can be used to calculate the ECC check value, address parity check value, and control signal parity check value for the write data, address, and control signal, and append the check value to the write data. The slave device - side verification module can be used to receive the write data and the check value, verify the data integrity through the check value, and recover the data when a 1 - bit error is detected, and trigger an interruption when a multi - bit error is detected. When the master device initiates a read operation, the slave device - side verification module can be used to calculate the check value for the read data, address, and control signal and append it to the read data. The master device - side verification module can be used to receive the read data and the check value, verify the data integrity through the check value, and recover the data when a 1 - bit error is detected, and trigger an interruption when a multi - bit error is detected. It can be understood that by adding end - to - end verification on the basis of the AMBA bus protocol, the present application can achieve single - point failure verification on the bus and can perform the following further security processes. For example, after calibration errors occur, perform as many verification errors as possible on the verification results according to the verification feedback results, recover the original operation instruction, and when the algorithm determines that the original operation instruction cannot be recovered, feedback the bus error status to the CPU or outside the chip, so as to effectively improve the security and reliability of the functional safety bus.
[0050] It is worth noting that since the present application has implemented an efficient on - chip bus of the SoC chip that meets the functional safety ASIL B automotive - grade requirements based on the existing mature AMBA bus protocol, there is no need to add excessive resources, and the implementation is simple. It can reuse the original AMBA bus resources in the SoC chip, add appropriate control logic and inspection logic, make full use of the existing on - chip logic resources, and achieve an efficient on - chip bus that meets the functional safety ASIL B automotive - grade requirements by adding end - to - end checks, inspections, and corrections of data, addresses, and controls on the bus. The present application proposes a mechanism that uses the AMBA protocol, makes full use of the existing SoC on - chip bus resources, and realizes an efficient on - chip safety bus protocol by adding mechanisms for checking, inspecting, and correcting data, addresses, and controls on the bus, and applies the entire bus protocol to automotive - grade products.
[0051] Reference Figure 2 , Figure 2In the verification control device of the automotive-grade SoC chip provided by an embodiment of the present application, it is a schematic diagram of the master device end verification module; in some embodiments, the master device end verification module includes: a first injection self-check unit, which is used to perform error injection based on the read data during power-on self-check to calculate the injected ECC check value; a first verification comparison module, which is used to compare the injected ECC check value with the additional ECC check value in the read data to obtain a verification comparison result; a first error recovery unit, which is used to recover the data with 1-bit error and send an error status signal to the corresponding master device when the verification comparison result is a 1-bit error, and send an interrupt status signal corresponding to the multi-bit error to the master device when the verification comparison result is a multi-bit error.
[0052] In some embodiments, the check value includes an ECC check value, an address parity check value, and a control signal parity check value. The master device end verification module includes a first verification calculation unit, which is used to: calculate the ECC check value for the write data to generate the corresponding ECC check value; calculate the parity check value for the address information of the write data to generate the corresponding address parity check value; calculate the parity check value for the control signal of the write data to generate the corresponding control signal parity check value.
[0053] It can be understood that as Figure 2 shown, the master device end verification module is mainly used to verify the data sent by the master device, generate a check value, and verify the received data. This module includes the following main parts:
[0054] Error injection self-check unit: used to perform error injection based on the read data during power-on self-check to calculate the injected ECC check value;
[0055] Verification comparison module: used to compare the injected ECC check value with the additional ECC check value in the read data to obtain a verification comparison result;
[0056] Error recovery unit: used to recover the data with 1-bit error and send an error status signal to the corresponding master device when the verification comparison result is a 1-bit error; send an interrupt status signal corresponding to the multi-bit error to the master device when the verification comparison result is a multi-bit error;
[0057] Verification calculation unit: used to calculate the ECC check value and parity check value for the write data, address information, and control signal;
[0058] In some embodiments, during power-on self-test, the error injection self-test unit performs error injection based on the read data to calculate the injected ECC check value. By simulating error injection, the self-test function of the E2E_M module is verified to ensure that the module can correctly detect and handle errors before normal operation. Figure 2 The "error injection, E2E module self-test" part in Figure 2 is the error injection self-test unit.
[0059] In some embodiments, the verification comparison module compares the injected ECC check value with the additional ECC check value in the read data to obtain the verification comparison result. By comparing the calculated ECC check value with the received ECC check value, it is determined whether an error occurs during data transmission. Figure 2 The "comparing the calculated value of the current data with the ECC value transmitted on the bus" part in Figure 2 is the verification comparison module.
[0060] In some embodiments, when the verification comparison result is a 1-bit error, the error recovery unit recovers the 1-bit error data and sends an error status signal to the corresponding master device. When the verification comparison result is a multi-bit error, an interrupt status signal corresponding to the multi-bit error is sent to the master device. It can be understood that by ensuring the reliability of data transmission, the correctable 1-bit error is recovered, and the uncorrectable multi-bit error is interrupted. Figure 2 The "error recovery" part in Figure 2 is the error recovery unit.
[0061] In some embodiments, the verification calculation unit is used to calculate the ECC check value for the write data to generate the corresponding ECC check value, calculate the parity check value for the address information of the write data to generate the corresponding address parity check value, and calculate the parity check value for the control signal of the write data to generate the corresponding control signal parity check value, so as to generate various check values to ensure the integrity and correctness during data transmission. Figure 2 The "calculating the ECC check value" part in Figure 2 corresponds to the calculation of the ECC check value for the write data, the "calculating the parity check value of the address" part corresponds to the calculation of the parity check value of the address information, and the "calculating the parity check value of the control bus and monitoring whether an operation times out" part corresponds to the calculation of the parity check value of the control signal.
[0062] It should be noted that as Figure 2As shown, rdatain is the read data input signal for receiving read data from the slave device; data1 is the write data input signal for receiving write data from the master device; wdatain is the write data input signal for receiving write data from the master device; address in is the address input signal for receiving address information from the master device; data2 is the control signal input signal for receiving control signals from the master device; rdataout is the read data output signal, which outputs the read data after passing the verification; onebiterror is the 1-bit error signal indicating that a 1-bit error has been detected; fatalerror is the multi-bit error signal indicating that a multi-bit error has been detected; data_ecc_parityin is the ECC check value output signal of the write data; addr_ecc_parityin is the parity check value output signal of the address information; ctr l_ecc_parityin is the parity check value output signal of the control signal; Time_out_err int is the timeout error signal indicating that an operation has timed out.
[0063] It can be understood that in the write operation process, the master device can send write data, address information, and control signals to the E2E_M module through the data1, address in, and data2 signals. The E2E_M module calculates the ECC check value of the write data, the parity check value of the address information, the parity check value of the control bus, and monitors whether an operation times out. The calculated check values are attached to the write data through the data_ecc_parityin, addr_ecc_parityin, and ctr l_ecc_parityin signals, and then the write data with the attached check values is transmitted to the slave device through the functional safety bus. Through the above design, the master device-side verification module can effectively verify the write data, generate check values, and verify the received read data to ensure the reliability and security of data transmission.
[0064] Reference Figure 3 , Figure 3In the verification control device of the in-vehicle grade SoC chip provided by an embodiment of the present application, it is a schematic diagram of the slave device end verification module; in some embodiments, the slave device end verification module includes: a second injection self-check unit, which is used to perform error injection based on the write data during power-on self-check to calculate the injected ECC check value; a second verification comparison module, which is used to compare the injected ECC check value with the ECC check value appended in the write data to obtain a verification comparison result; a second error recovery unit, which is used to recover the 1-bit error data and send an error status signal to the corresponding master device when the verification comparison result is a 1-bit error, and send an interrupt status signal corresponding to the multi-bit error to the master device when the verification comparison result is a multi-bit error.
[0065] In some embodiments, the master device end verification module includes a second verification calculation unit, and the second verification calculation unit is used to: calculate the ECC check value for the read data to generate the corresponding ECC check value; calculate the parity check value for the address information of the read data to generate the corresponding address parity check value; calculate the parity check value for the control signal of the read data to generate the corresponding control signal parity check value.
[0066] It can be understood that, as Figure 3 shown, the slave device end verification module is mainly used to verify the received data, generate a check value, and append the check value to the data and return it to the master device. This module includes the following main parts:
[0067] The second injection self-check unit: used to perform error injection based on the write data during power-on self-check to calculate the injected ECC check value;
[0068] The second verification comparison module: used to compare the injected ECC check value with the ECC check value appended in the write data to obtain a verification comparison result;
[0069] The second error recovery unit: used to recover the 1-bit error data and send an error status signal to the corresponding master device when the verification comparison result is a 1-bit error; send an interrupt status signal corresponding to the multi-bit error to the master device when the verification comparison result is a multi-bit error;
[0070] The second verification calculation unit: used to calculate the ECC check value and the parity check value for the read data, address information, and control signal.
[0071] In some embodiments, during power-on self-test, the second injection self-test unit performs error injection based on the write data to calculate the injected ECC check value. By simulating error injection, it verifies the self-test function of the slave device-side verification module to ensure that the module can correctly detect and handle errors before normal operation. Figure 3 The "error injection, E2E module self-verification" part in Figure 3 is the second injection self-test unit.
[0072] In some embodiments, the second verification comparison module compares the injected ECC check value with the ECC check value appended to the write data to obtain the verification comparison result. By comparing the calculated ECC check value with the received ECC check value, it determines whether an error occurs during data transmission. Figure 3 The "comparing the calculated value of the current data with the ECC value transmitted on the bus" part in Figure 3 is the second verification comparison module.
[0073] In some embodiments, when the verification comparison result indicates a 1-bit error, the second error recovery unit recovers the 1-bit error data and sends an error status signal to the corresponding master device. When the verification comparison result indicates a multi-bit error, it sends an interrupt status signal corresponding to the multi-bit error to the master device to ensure the reliability of data transmission. It recovers the correctable 1-bit error and performs interrupt processing on the uncorrectable multi-bit error. Figure 3 The "error recovery" part in Figure 3 is the second error recovery unit.
[0074] In some embodiments, the second verification calculation unit calculates the ECC check value for the read data to generate the corresponding ECC check value, calculates the parity check value for the address information of the read data to generate the corresponding address parity check value, and calculates the parity check value for the control signal of the read data to generate the corresponding control signal parity check value to generate various check values to ensure the integrity and correctness during data transmission. Figure 3 The "calculating the ECC check value" part in Figure 3 corresponds to the calculation of the ECC check value for the read data, the "calculating the parity check value of the address" part corresponds to the calculation of the parity check value for the address information, and the "calculating the parity check value of the control bus and monitoring whether an operation times out" part corresponds to the calculation of the parity check value for the control signal.
[0075] It should be noted that Figure 3Description of Input and Output Signals: wdatain is the write data input signal for receiving write data from the master device; address in is the address input signal for receiving address information from the master device; data1 is the control signal input signal for receiving control signals from the master device; rdatain is the read data input signal for receiving read data from the master device; wdataout is the write data output signal, which outputs the write data after passing the verification; onebiterror is the 1-bit error signal indicating that a 1-bit error is detected; fatalerror is the multi-bit error signal indicating that multi-bit errors are detected; data_ecc_parityout is the ECC check value output signal of the write data; addr_ecc_parityout is the parity check value output signal of the address information; ctrl_ecc_parityout is the parity check value output signal of the control signal; Time_out_err_int is the timeout error signal indicating that an operation has timed out.
[0076] It can be understood that in the read operation process, the slave device sends the read data to the slave device - side verification module through the rdatain signal. The slave device - side verification module performs self - check by error injection, calculates the injected ECC check value, compares the injected ECC check value with the additional ECC check value in the read data to obtain the verification comparison result. Further, if the verification comparison result is a 1 - bit error, the slave device - side verification module recovers the data with a 1 - bit error through the "error recovery" part and sends the error status signal to the master device through the onebiterror signal. If the verification comparison result is multi - bit errors, the slave device - side verification module sends the interrupt status signal corresponding to the multi - bit errors to the master device through the fatalerror signal. The read data after passing the verification is output to the slave device through the wdataout signal to ensure the reliability and security of data transmission.
[0077] In some embodiments, the MASTER side (E2E_M) of this patent is internally composed of the following eight major parts: error injection self - check module, ECC calculation module, result comparison module, error recovery module, verification result status generation module, write data ECC value calculation module, address parity check value calculation module, and control signal parity check value calculation module.
[0078] Among them, the function of the error injection self-check module is to perform self-check on the functional safety function of the bus after the chip is powered on. After the chip power-on is completed, it is necessary to confirm that the security mechanism functions of all internal buses are normal. Therefore, this module is required. After the CPU enables this module, it will generate a 1-bit error or multi-bit error on the bus, so that subsequent functional modules can perform error checking and recover the data with 1-bit error. The self-check result will be sent to the CPU to complete the power-on self-check function of the bus. Only after the power-on self-check is completed correctly will the SoC chip enter the normal working state;
[0079] Furthermore, the ECC calculation and result comparison module is responsible for performing real-time ECC algorithm calculation on the data on the bus and comparing the calculated ECC result with the ECC check data transmitted simultaneously on the bus. If the comparison is consistent, it means no error has occurred. If the comparison is inconsistent, when it is a 1-bit error, the error recovery module will recover the error data through an algorithm and return the recovered data to the bus to enable the system to continue working. For a 1-bit error, the data can be 100% recovered, but at the same time, the status of the 1-bit error will be notified to the CPU. When there are more than 1-bit data errors, since the data cannot be recovered through the algorithm, a fatal_error interrupt signal will be generated and sent to the CPU, and this error status will be transmitted to the outside of the chip through a dedicated PAD port for further processing by the system;
[0080] Furthermore, the check result status generation module generates corresponding error indication signals according to the system settings when onebit_error and fatal_error occur, and outputs them to the corresponding functional modules;
[0081] Furthermore, the write data ECC value calculation module, address parity check value calculation module, and control signal parity check value calculation module are responsible for calculating the check values of the write data (wdata), address (address), and bus control signals sent from the MASTER end in real time. The calculated check values will be sent to the SLAVE end along with the current bus operation. After receiving the bus operation, the SLAVE end calculates the check values of the received data, address, and control signals by the E2E_S according to the algorithm and compares them with the check values sent from the MASTER end. According to the calculation results, the check result status generation module in the E2E_S generates corresponding statuses, thereby realizing the complete verification of one transmission.
[0082] Reference Figure 4 , Figure 4In the verification control device of the automotive-grade SoC chip provided by an embodiment of the present application, the timing diagram of bus verification data and results. Among them, HTRANS, HADDR, HBURST, HWDTA, HREADY, and HRDATA in the figure are protocol signals specified by the AHB bus protocol of the original AMAB. HAUSER, HWUSER, HRUSER, onebit_error, and fatal_error are relevant signals added during the implementation of the present application. The function safety timely detection of the standard AMBA bus is realized by these added signals, so that the current bus meets the functional safety ASIL B automotive-grade requirements; through this timing diagram, it can be seen that processes such as error injection and ECC self-check are all self-checks of the functions that need to meet the ISO26262 functional part before the chip starts to enter normal operation. The self-check includes normal function when the function is correct, and when the function is incorrect, the corresponding module can discover, detect, and report the error; the ECC self-check includes error injection and normal function detection. The purpose of error injection is to inject known errors into E2E_M and E2E_S to see if they can be detected, and the normal function detection is to verify whether the functions of E2E_M and E2E_S are correct when they are working properly.
[0083] Among them, while these signals "HTRANS, HADDR, HBURST, HWDTA, HREADY, HRDATA are protocol signals specified by the AHB bus protocol of the original AMAB" are transmitted on the bus, they will be provided to E2E_M and E2E_S for calculation. "HAUSER, HWUSER, HRUSER, onebit_error, fatal_error" are relevant signals added during the implementation of the present application. Among "HAUSER, HWUSER, HRUSER", they are the parity check values of the address and control, the ECC value of the write data, and the ECC value of the read data respectively. These signals are transmission signals added by the present application based on the AMBA protocol, and are input or output signals generated by the E2E_M and E2E_S of the present application, used to complete the functions of the present application.
[0084] It can be understood that after an error occurs between the MASTER and the SLAVE, both the MASTER and the SLAVE will generate their own onebit_error and fatal_error signals. Such signals are connected to different interrupt numbers of the CPU through the circuit. When different modules detect errors, it will cause the CPU to generate different interrupts. The data transmission process between the master device and the slave device through the real-time verification and error recovery mechanism ensures the reliability and security of data transmission and meets the strict functional safety requirements of automotive-grade chips.
[0085] Reference Figure 5 , Figure 5The method flow chart of the verification control method for the automotive-grade SoC chip provided by an embodiment of the present application; To achieve the above object, the second aspect of the embodiments of the present application provides a verification control method for an automotive-grade SoC chip, and the method is applied to the verification control device of the automotive-grade SoC chip in any item of the first aspect. The method includes the following steps:
[0086] Step S510, when the master device initiates a write operation, the write data sent to the slave device is verified by the master device-side verification module, a verification value is generated and appended to the write data, the write data and the verification value from the master device are received by the slave device-side verification module, and the write data is verified based on the verification value;
[0087] Step S520, when the master device initiates a read operation, the read data sent to the master device is verified by the slave device-side verification module, a verification value is generated and appended to the read data, the read data and the verification value from the slave device are received by the master device-side verification module, and the read data is verified based on the verification value.
[0088] Reference Figure 6 , Figure 6 In the verification control method for the automotive-grade SoC chip provided by an embodiment of the present application, the method flow chart for verifying and validating the write data based on the verification value; In some embodiments, for verifying and validating the write data based on the verification value, the method includes the following steps:
[0089] Step S610, error injection is performed based on the write data during power-on self-test to calculate the injected ECC verification value;
[0090] Step S620, comparing the injected ECC verification value with the ECC verification value appended in the write data to obtain a verification comparison result;
[0091] Step S630, in the case where the verification comparison result is a 1-bit error, the data with a 1-bit error is recovered, and an error status signal is sent to the corresponding master device;
[0092] Step S640, in the case where the verification comparison result is a multi-bit error, an interrupt status signal corresponding to the multi-bit error is sent to the master device.
[0093] Reference Figure 7 , Figure 7 In the verification control method for the automotive-grade SoC chip provided by an embodiment of the present application, the method flow chart for verifying and validating the read data based on the verification value; In some embodiments, for verifying and validating the read data based on the verification value, the method includes the following steps:
[0094] Step S710, error injection is performed based on the read data during power-on self-test to calculate the injected ECC verification value;
[0095] Step S720: Compare the injected ECC check value with the ECC check value appended to the read data to obtain a check comparison result;
[0096] Step S730: In the case where the check comparison result is a 1-bit error, recover the 1-bit error data and send an error status signal to the corresponding master device;
[0097] Step S740: In the case where the check comparison result is a multi-bit error, send an interrupt status signal corresponding to the multi-bit error to the master device.
[0098] Reference Figure 8 , Figure 8 is a schematic flow diagram of the self-check process of the safety bus in the check control method of the automotive-grade SoC chip provided by an embodiment of the present application; it can be understood that after the chip is powered on, the present application can first determine whether the SoC has completed initialization. If the initialization is not completed, the system will wait for the initialization to complete. Once the SoC initialization is completed, the CPU will set the on-chip bus to enter the self-check mode to ensure the functional safety of the bus;
[0099] Further, in the self-check mode, the error injection self-check module corresponding to the bus interface starts to work, actively generates errors to test the error detection and processing capabilities of the system; subsequently, the ECC (Error-Correcting Code) calculation and comparison module inside E2E starts to perform ECC calculation on the data on the bus and compare it with the preset ECC check value to detect whether there are errors;
[0100] Further, if the injected error is detected, it indicates that the error detection function of the system is normal; at this time, the system will generate an interrupt signal with a self-check success status to notify the CPU that the self-check is successful; after receiving this signal, the CPU will set to exit the bus self-check mode, make the bus enter the normal working state, and start processing normal read and write operations;
[0101] Further, if the injected error is not detected, it indicates that there may be a problem with the error detection function of the system; at this time, the system will generate an interrupt signal with a self-check failure status to notify the CPU that the self-check fails; after receiving this signal, the SoC will enter the safe state and report the self-check failure status to the system where the chip is located, so that the system can take further measures to ensure the security and reliability of the system;
[0102] Through the above self-check process, the automotive-grade SoC chip can automatically detect the functional safety of the bus after power-on, ensure that the error detection and processing functions of the bus are normal before formal operation, thereby improving the reliability and security of the system.
[0103] In summary, the present application can utilize the existing commercial AMBA protocol circuits. Based on the original design of the commercial AMBA protocol circuits, a secure end-to-end detection and verification circuit and a power-on self-test circuit for the bus are added, enabling the original AMBA protocol bus to meet the requirements of automotive-grade functional safety. This design meets the automotive-grade requirements of functional safety ASI LB for the original commercial AMBA bus protocol at a minimal cost.
[0104] Reference Figure 9 , Figure 9 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the verification control method of the automotive-grade SoC chip according to any one of the above embodiments. For example, it executes the method steps S510 to S520 in Figure 5 above, Figure 6 the method steps S610 to S640 in Figure 7 above,
[0105] The electronic device 900 according to an embodiment of the present application includes one or more processors 910 and a memory 920. Figure 9 The case of one processor 910 and one memory 920 is taken as an example in
[0106] The processor 910 and the memory 920 can be connected through a bus or other means. Figure 9 The case of being connected through a bus is taken as an example in
[0107] As a non-transitory computer-readable storage medium, the memory 920 can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory 920 can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 920 may optionally include a memory 920 remotely provided relative to the processor 910. These remote memories can be connected to the electronic device 900 through a network. At the same time, examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0108] In some embodiments, when the processor executes the computer program, it executes the verification control method of the automotive-grade SoC chip according to any one of the above embodiments at a preset interval.
[0109] Those skilled in the art can understand. Figure 9The device structure shown does not constitute a limitation on the electronic device 900, and it may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0110] In Figure 9 In the illustrated electronic device 900, the processor 910 may be used to call the verification control method of the automotive-grade SoC chip stored in the memory 920, thereby implementing the verification control method of the automotive-grade SoC chip.
[0111] Based on the hardware structure of the above-mentioned electronic device 900, various embodiments of the verification control device for the automotive-grade SoC chip of the present application are proposed. At the same time, the non-transitory software programs and instructions required to implement the verification control method of the automotive-grade SoC chip in the above embodiments are stored in the memory. When executed by the processor, the verification control method of the automotive-grade SoC chip in the above embodiments is executed.
[0112] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions for executing the above-mentioned verification control method of the automotive-grade SoC chip, which can cause the above one or more processors to execute the verification control method of the automotive-grade SoC chip in any of the above embodiments. For example, execute the method steps S510 to step S520 described above Figure 5 in, Figure 6 the method steps S610 to step S640 in, Figure 7 the method steps S710 to step S740 in.
[0113] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network nodes. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0114] Those of ordinary skill in the art will understand that all or some of the steps and systems disclosed in the above methods can be implemented as software, firmware, hardware, and their appropriate combinations. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer-readable storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer-readable storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer-readable storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory, or other memory technologies, CD-ROM, digital versatile disks (DVDs), or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0115] The above is a specific description of the preferred embodiments of the present application. However, the present application is not limited to the above embodiments. Those skilled in the art can make various equivalent deformations or substitutions without departing from the spirit of the present application, and these equivalent deformations or substitutions are all included within the scope defined by the claims of the present application.
Claims
1. A verification control device for an automotive-grade SoC chip, characterized in that: include: Functional safety bus, connecting multiple master devices and slave devices for data transmission; A master device-side verification module is provided in each of the master devices; A slave device-side verification module, arranged in each of the slave devices; in, When the master device initiates a write operation, the master device-side verification module is used to verify the write data sent to the slave device, generate a verification value and attach it to the write data; the slave device-side verification module is used to receive the write data and the verification value from the master device, and verify the write data based on the verification value; When the master device initiates a read operation, the slave device-side verification module is used to verify the read data sent to the master device, generate a verification value and attach it to the read data; the master device-side verification module is used to receive the read data and the verification value from the slave device, and verify the read data based on the verification value.
2. The verification control device for the automotive-grade SoC chip according to claim 1, characterized in that: The master device end verification module comprises: A first injection self-check unit, the first injection self-check unit is used to perform error injection based on the read data during power-on self-check to calculate an injected ECC check value; A first inspection and comparison module, wherein the first inspection and comparison module is used to compare the injected ECC inspection value with the ECC check value attached to the read data to obtain an inspection and comparison result; A first error recovery unit, wherein the first error recovery unit is used to recover 1-bit error data when the check and comparison result is a 1-bit error and send an error status signal to the corresponding master device; and when the check and comparison result is a multi-bit error, send an interrupt status signal corresponding to the multi-bit error to the master device.
3. The verification control device for the automotive-grade SoC chip according to claim 1, characterized in that: The slave device verification module includes: A second injection self-check unit, the second injection self-check unit is used to perform error injection based on the write data during power-on self-check to calculate an injected ECC check value; A second inspection and comparison module, the second inspection and comparison module is used to compare the injected ECC inspection value with the ECC check value attached to the write data to obtain an inspection and comparison result; A second error recovery unit, wherein the second error recovery unit is used to recover 1-bit error data when the check and comparison result is a 1-bit error, and send an error status signal to the corresponding master device; and when the check and comparison result is a multi-bit error, send an interrupt status signal corresponding to the multi-bit error to the master device.
4. The verification control device for an automotive-grade SoC chip according to any one of claims 1 to 3, characterized in that: The check value includes an ECC check value, an address parity check value and a control signal parity check value, and the master device-side check module includes a first check calculation unit, and the first check calculation unit is used to: Performing ECC check value calculation on the write data to generate a corresponding ECC check value; Performing parity check value calculation on the address information of the write data to generate a corresponding address parity check value; A parity check value is calculated for the control signal of the write data to generate a corresponding parity check value of the control signal.
5. The verification control device for the automotive-grade SoC chip according to claim 4, characterized in that: The master device-side verification module includes a second verification calculation unit, and the second verification calculation unit is used to: Performing ECC check value calculation on the read data to generate a corresponding ECC check value; Performing parity check value calculation on the address information of the read data to generate a corresponding address parity check value; A parity check value is calculated for the control signal of the read data to generate a corresponding parity check value of the control signal.
6. A verification control method for an automotive-grade SoC chip, characterized in that: The method is applied to the verification control device of the automotive-grade SoC chip according to any one of claims 1 to 5, and the method comprises: When the master device initiates a write operation, the master device-side verification module verifies the write data sent to the slave device, generates a verification value and attaches it to the write data, receives the write data and the verification value from the master device through the slave device-side verification module, and verifies the write data based on the verification value; When the master device initiates a read operation, the read data sent to the master device is verified by the slave device-side verification module, a verification value is generated and attached to the read data, the read data and the verification value are received from the slave device by the master device-side verification module, and the read data is verified based on the verification value.
7. The verification control method of the automotive-grade SoC chip according to claim 6 is characterized in that: The verifying and verifying the write data based on the verification value includes: Performing error injection based on the write data during power-on self-test to calculate an injected ECC check value; Comparing the injected ECC check value with the ECC check value attached to the write data to obtain a check comparison result; When the check and comparison result is a 1-bit error, the 1-bit erroneous data is restored and an error status signal is sent to the corresponding master device; When the check and comparison result is a multi-bit error, an interrupt status signal corresponding to the multi-bit error is sent to the master device.
8. The verification control method of the automotive-grade SoC chip according to claim 6, characterized in that: The verifying and verifying the read data based on the verification value includes: Performing error injection based on the read data during power-on self-test to calculate an injected ECC check value; Comparing the injected ECC check value with the ECC check value attached to the read data to obtain a check comparison result; When the check and comparison result is a 1-bit error, the 1-bit erroneous data is restored and an error status signal is sent to the corresponding master device; When the check and comparison result is a multi-bit error, an interrupt status signal corresponding to the multi-bit error is sent to the master device.
9. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When at least one of the programs is executed by at least one of the processors, the verification control method for the automotive-grade SoC chip as described in any one of claims 6 to 8 is implemented.
10. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the verification control method for an automotive-grade SoC chip as described in any one of claims 6 to 8.
Citation Information
Cited By
Error injection and verification method and device and storage medium
CN121037242A