System-level fault and anomaly detection and management method and device of vehicle-mounted Ethernet chip and storage medium

A system-level fault detection and management framework for vehicle Ethernet chips addresses the lack of robust fault detection in vehicle chip designs by integrating fault detection units and a security island, ensuring high diagnostic coverage and rapid response to faults.

CN120321095APending Publication Date: 2025-07-15KUNGAO XINXIN MICROELECTRONICS (JIANGSU) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510530102.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The prior art is difficult to effectively meet the functional safety requirements of automotive chips, especially the requirements for failure efficiency and fault diagnosis coverage under different ASIL levels, resulting in increased chip design costs and inflexible fault response.

Method used

The system-level fault detection and management framework of the on-board Ethernet chip is adopted. By setting up a fault detection unit in each functional module, fault information is gathered to the safety island for classified management, and independent external power supply and clock, the built-in watchdog module is used for real-time monitoring and fault response, and flexible fault handling is used by a state machine.

Benefits of technology

It improves fault response speed and flexibility, reduces the processing pressure of upper-layer software, enhances the reliability and abnormal diagnosis coverage of the chip, and reduces chip costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321095A_ABST
    Figure CN120321095A_ABST
Patent Text Reader

Abstract

The invention discloses a system-level fault and anomaly detection and management method and device for a vehicle-mounted Ethernet chip and a storage medium, and the method comprises the following steps: configuring a function safety management framework of the vehicle-mounted Ethernet chip, setting a fault detection unit according to a possible fault in each function module of the vehicle-mounted Ethernet chip, and setting a fault detection unit according to the fault in each function module of the vehicle-mounted Ethernet chip; the fault detection units gather fault information to a safety island in the vehicle-mounted Ethernet chip through a safety bus, and the safety island classifies faults and makes different responses to different faults. The invention provides a chip-level functional safety management framework, more specifically, fault detection units are added to all functional modules in a chip, all faults are uniformly integrated into a safety island in the chip for classified management, different types of faults are processed differently, and the safety of the chip is improved. And a fault response is made when basic functions of the chip are ensured as much as possible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of functional safety of in-vehicle Ethernet chips, and in particular to a method, device and storage medium for system-level fault, anomaly detection and management of in-vehicle Ethernet chips. Background Art

[0002] With the development of the automotive industry, more and more semiconductor chips are used in automobiles, and the safety and reliability of the chips affect the safety of the entire vehicle. Based on this, the concept of functional safety has been put forward, and the functional safety requirements and design guidelines for semiconductor products are defined in Part 11 of the second edition of ISO-26262. Different ASIL safety levels are defined in ISO-26262, and requirements for failure rates and fault diagnosis coverage are required under different ASIL levels. With the continuous expansion of the scale of in-vehicle chips, in order to meet the functional safety requirements of in-vehicle chips, it is usually necessary to use a combination of multiple safety mechanisms to meet the failure rate index at the chip level. Therefore, a general safety architecture is needed to guide the design of the chip, classify the faults of the chip, and make fault responses as much as possible while ensuring the basic functions of the chip. Summary of the Invention

[0003] In order to solve the above problems of the existing technical solutions, the present invention provides a chip-level functional safety management framework. More specifically, a fault detection unit is added to each functional module inside the chip, and all faults are uniformly integrated into the safety island inside the chip for classification management. Different responses are made for different types of faults, and fault responses are made as much as possible while ensuring the basic functions of the chip to solve the above technical problems.

[0004] In order to achieve the above object, the present invention adopts the following technical solutions: A method for system-level fault, anomaly detection and management of an in-vehicle Ethernet chip, comprising the following steps:

[0005] Configure the functional safety management framework of the in-vehicle Ethernet chip. In each functional module of the in-vehicle Ethernet chip, a fault detection unit is set according to the possible faults. Each fault detection unit converges the fault information to the safety island inside the in-vehicle Ethernet chip through a safety bus, and the safety island classifies the faults and makes different responses to different faults.

[0006] Further, the safety island uses an independent power supply and clock set outside the in-vehicle Ethernet chip to avoid the failure of the safety island caused by the power supply or clock failure inside the chip.

[0007] Furthermore, a safety island external monitoring module is configured and arranged outside the on-board Ethernet chip; the safety island has a built-in watchdog module, which regularly sends pulse signals to the safety island monitoring module outside the chip. If the safety island external monitoring module does not receive the pulse signal within the specified time, the chip's safety island is considered to be invalid.

[0008] Furthermore, the fault detection unit converts the fault information into a standard data stream and sends it to the fault collection interface module in the safety island. The safety bus uses ECC for end-to-end protection. The safety island responds to the faults occurring in the chip in real time through the fault collection interface module, fault judgment module, and fault response module set up inside it.

[0009] Furthermore, the safety island is also provided with a monitoring module for detecting the fault information transmitted by the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to determine whether the safety island is in a normal working state. If the safety island is considered abnormal, the entire safety island is reset and reported to the external monitoring module of the safety island.

[0010] Furthermore, the fault collection interface module collects all fault information, classifies the faults, and sends them to the fault judgment module for unified processing;

[0011] The fault judgment module has a built-in state machine, which has four states: configuration, normal, warning, and error. The state machine is in the normal state by default;

[0012] When the upper-layer software configuration enters the instruction, the state machine jumps to the configuration state. In this state, the safety island will not respond to fault information. Therefore, a timer will be started when entering this state. When the set time is reached, the state machine automatically exits the configuration state and returns to the normal state to avoid being in the configuration state for a long time and unable to respond to faults;

[0013] When the state machine is in the normal state, if the fault collection interface module receives a common level fault, the state machine will jump to the warning state. In this state, the next level fault response module will be notified to handle the fault. When entering the warning state, a timer will be started. If the fault still exists after the specified time, the state machine will jump to the error state.

[0014] When the state machine is in the warning state, if the fault collection interface module receives a fault of a serious level, the state machine will jump to the error state and handle the fault of the serious level first;

[0015] When the state machine is in the normal state, if the fault collection interface module receives a fault of a severe level, the state machine directly jumps to the error state, in which the fault response module responds according to the configuration;

[0016] When the state machine is in a warning state or an error state, if the state is released, it jumps back to the normal state.

[0017] The fault judgment module and the fault response module have two levels of fault status and can configure two levels of fault handling methods for the same fault source, which improves the flexibility of fault handling. Some faults can be handed over to hardware for processing through configuration, which improves the fault response speed and reduces the pressure on the upper-level software.

[0018] The present invention also provides a system-level fault and anomaly detection and management device for an in-vehicle Ethernet chip, comprising:

[0019] A plurality of fault detection units are respectively arranged in each functional module of the vehicle Ethernet chip, and are used for collecting fault information to a safety island inside the vehicle Ethernet chip through a safety bus according to possible faults;

[0020] The safety island is used to classify faults and make different responses to different faults. A programmable hardware fault handling module is provided in the safety island to respond to faults in a timely manner and reduce the pressure of upper-layer software processing. The safety island uses an independent power supply and clock outside the on-board Ethernet chip to avoid the failure of the safety island due to power supply or clock failure inside the chip.

[0021] Furthermore, the fault detection unit converts the fault information into a standard data stream and sends it to the fault collection interface module in the safety island. The safety bus uses ECC for end-to-end protection. The safety island responds to the faults occurring in the chip in real time through the fault collection interface module, fault judgment module and fault response module set up inside it. The safety island is also provided with a monitoring module for detecting the fault information transmitted by the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to determine whether the safety island is in a normal working state. If the safety island is considered abnormal, the entire safety island is reset and reported to the external monitoring module of the safety island.

[0022] Furthermore, the fault collection interface module collects all fault information, classifies the faults, and sends them to the fault judgment module for unified processing;

[0023] The fault judgment module has a built-in state machine, which has four states: configuration, normal, warning, and error. The state machine is in the normal state by default;

[0024] When the upper-layer software configuration enters the instruction, the state machine jumps to the configuration state. In this state, the safe island does not respond to fault information. Therefore, a timer is started when entering this state. When the set time is reached, the state machine automatically exits the configuration state and returns to the normal state, avoiding being in the configuration state for a long time and being unable to respond to faults.

[0025] When the state machine is in the normal state, if the fault collection interface module receives a fault of normal level, the state machine jumps to the warning state. In this state, the subsequent fault response module is notified to handle the fault. At the same time as entering the warning state, a timer is also started. If the fault still exists after the specified time, the state machine jumps to the error state.

[0026] When the state machine is in the warning state, if the fault collection interface module receives a fault of critical level, the state machine jumps to the error state to give priority to handling the critical-level fault.

[0027] When the state machine is in the normal state, if the fault collection interface module receives a fault of critical level, the state machine directly jumps to the error state, and in this state, the fault response module makes a response according to the configuration.

[0028] When the state machine is in the warning state or the error state, if the state is cleared, it jumps back to the normal state.

[0029] Through two levels of fault states, the fault judgment module and the fault response module can configure two levels of fault handling methods for the same fault source, improving the flexibility of fault handling. Some faults can be handed over to the hardware for processing through configuration, improving the fault response speed and reducing the pressure on the upper-layer software.

[0030] The present invention also provides a computer-readable storage medium containing a computer program. When the computer program is executed by one or more processors, the system-level fault, anomaly detection, and management method of the in-vehicle Ethernet chip described in any one of the above is implemented.

[0031] The present invention proposes a system-level functional safety management framework, and based on this framework, a method and device for fault, anomaly detection and management are implemented. The modular design is adopted, which facilitates the adjustment of chip design and reduces the chip cost increased to meet the requirements of functional safety anomaly diagnosis coverage. The present invention provides a functional safety management framework for in-vehicle Ethernet chips to classify and respond to faults within the chips. Through modular design, it is convenient to adjust the chip design and reduce the chip cost increased to meet the requirements of functional safety anomaly coverage. In each functional module of the chip, fault detection units need to be added according to the possible faults that may occur, and some additional fault detection units need to be added according to the requirements of functional safety levels. Each fault detection unit converges the fault information to the safety island inside the chip through the safety bus. The safety island classifies the faults and makes different responses to different faults. There is a programmable hardware fault processing module in the safety island, which can respond in a timely manner when a fault occurs, reducing the pressure on the upper-layer software processing.

[0032] The safety island uses independent power and clock, which are provided from outside the chip, to avoid the failure of the safety island caused by power or clock faults inside the chip. The safety island is built-in with a watchdog module that periodically sends pulse signals to the detection module outside the chip. If the detection module outside the chip does not receive the pulse signal within the specified time, it is considered that the safety island of the chip has failed. Through this hierarchical protection method, the reliability of chip operation is improved, which is convenient to meet the requirements of functional safety for anomaly coverage.

[0033] The fault, anomaly detection and management device of the present invention includes a hardware-implemented fault response module, which can configure the response methods of different faults through upper-layer software. While ensuring the flexibility of the fault response method, it improves the fault response speed and reduces the pressure on the upper-layer software processing.

[0034] The present invention places most of the modules related to fault response inside the safety island of the chip. The safety island uses independent clock and power provided from outside the chip to ensure that the fault response path is not interfered by anomalies or faults of other modules inside the chip. The watchdog is used to periodically send pulse signals to the monitoring module outside the chip, and the method of foreground error injection test plus background real-time monitoring is used to ensure the correctness of the function of the fault response path, ensuring that if there are anomalies in the fault response path, they can be detected by the external monitoring module in a timely manner. This hierarchical protection method can improve the anomaly diagnosis coverage of the chip. Brief Description of the Drawings

[0035] Figure 1 It is a schematic diagram of a system-level fault, anomaly detection and management device for an in-vehicle Ethernet chip of the present invention;

[0036] Figure 2This is a schematic diagram of the operation process of the safety island of the present invention. Detailed implementation manners

[0037] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0038] A system-level fault, anomaly detection and management method for a vehicle-mounted Ethernet chip includes the following steps:

[0039] Configure the functional safety management framework of the vehicle-mounted Ethernet chip. In each functional module of the vehicle-mounted Ethernet chip, set up a fault detection unit according to the possible faults. Each fault detection unit converges the fault information to the safety island inside the vehicle-mounted Ethernet chip through a safety bus. The safety island classifies the faults and makes different responses to different faults.

[0040] The safety island uses independent power supply and clock set outside the vehicle-mounted Ethernet chip to avoid the failure of the safety island caused by the power supply or clock failure inside the chip.

[0041] Configure an external monitoring module for the safety island, which is set outside the vehicle-mounted Ethernet chip; the safety island is built-in with a watchdog module, which regularly sends a pulse signal to the external monitoring module of the safety island. If the external monitoring module of the safety island does not receive the pulse signal within the specified time, it is considered that the safety island of the chip fails. Through this hierarchical protection method, the reliability of the chip operation is improved, which is convenient to meet the requirements of functional safety for the anomaly coverage rate.

[0042] The fault detection unit converts the fault information into a standard data stream and sends it to the fault collection interface module inside the safety island. The safety bus uses ecc for end-to-end protection; inside the safety island, the fault collection interface module, fault judgment module, and fault response module set inside it respond to the faults occurring in the chip in real time.

[0043] The safety island is also provided with a monitoring module, which is used to detect the fault information transmitted from the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to judge whether the safety island is in a normal working state. If it is considered that the safety island is abnormal, the entire safety island is reset and reported to the external monitoring module of the safety island.

[0044] Such as Figure 1As shown, the fault, abnormality detection and management of the present invention are implemented in an Ethernet chip, and the Ethernet chip includes functional modules for realizing the main functions of the chip, including but not limited to Ethernet data processing unit, processor unit, storage unit, interface unit, bus unit, power management unit, clock management unit, etc. In order to realize fault detection, it is necessary to add a fault detection unit in each functional module. Since different functional modules realize different functions, the possible faults are also different, so it is necessary to design different fault detection units for the types of possible faults. All fault units convert fault information into standard data streams and send them to the fault collection interface module in the safety island. The safety bus adopts ECC for end-to-end protection. The safety island can respond to the faults occurring in the chip in real time through the fault collection interface module, fault judgment module and fault response module. The safety island monitoring module detects the fault information transmitted by the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to judge whether the safety island is in a normal working state. If the safety island is considered abnormal, the entire safety island will be reset and reported to the monitoring module outside the chip. The error injection module is used to inject errors into the functional modules of the chip during the chip self-check stage to detect whether the entire fault response path is functioning normally. The watchdog module periodically sends a pulse signal to the chip's external detection module. If the external detection module does not receive the pulse signal within the specified time, it is considered that the safety island module has failed.

[0045] Taking the clock management unit as an example, the clock management unit is used to provide a clock with a specified frequency for the chip. Therefore, when the clock frequency is inaccurate, it will affect the normal operation of the chip. Therefore, a frequency detection module is required to detect the fault of inaccurate frequency of the clock management module. The frequency detection module is implemented using two counters and a comparator. Counter A counts using the clock output by the clock management unit, and counter B counts using the secure clock provided externally to the chip. The two counters start counting at the same time and stop counting simultaneously when the value of counter B reaches the specified value. Since the clock frequency of counter B is known, the expected count value of counter A during this period can be calculated. The comparator compares the count value of counter A with the expected value. If the difference between the two is within the tolerable error range, it is considered that the clock output by the clock management module is accurate; otherwise, it is considered that the clock frequency output by the clock management module is inaccurate, and the frequency detection module reports the fault to the secure island. After the fault collection interface module in the secure island collects the fault signal output by the frequency detection module, it notifies the fault judgment module in the secure island; the fault judgment module jumps the state machine to the error state according to the configuration and notifies the fault response module to handle the fault; after the fault response module switches the chip's clock to the reference clock, it resets the PLL in the clock management unit. After the PLL relocks, it switches the chip's clock to the clock output by the PLL. At the same time, the fault response module also reports the fault to the external monitoring module of the secure island.

[0046] Taking the power management unit as an example, the power management unit provides power with various voltages for the chip. Therefore, when the voltage output by the power module is unstable, it will affect the normal operation of the chip. To detect the fault of the power management unit, a voltage detection module is required. The voltage detection module incorporates an ADC detection circuit and a comparator. The ADC detection circuit detects the output voltage of the power management unit in real time, and the comparator compares the ADC detection value with the expected value. If the error between the two exceeds the set threshold, it is considered that the power management module has a fault and the fault is reported to the secure island. Depending on the configuration, the secure island can choose to turn off the abnormal power output of the power management unit and report the fault to the external monitoring module of the secure island.

[0047] As Figure 2 shown, the fault collection interface module collects all fault information, classifies the faults, and sends them to the fault judgment module for unified processing;

[0048] The fault judgment module incorporates a state machine. The state machine has four states: configuration, normal, warning, and error. The state machine is default in the normal state;

[0049] When the upper-layer software configuration enters the instruction, the state machine jumps to the configuration state. In this state, the safety island will not respond to fault information. Therefore, a timer will be started when entering this state. When the set time is reached, the state machine automatically exits the configuration state and returns to the normal state to avoid being in the configuration state for a long time and unable to respond to faults;

[0050] When the state machine is in the normal state, if the fault collection interface module receives a common level fault, the state machine will jump to the warning state. In this state, the next level fault response module will be notified to handle the fault. When entering the warning state, a timer will be started. If the fault still exists after the specified time, the state machine will jump to the error state.

[0051] When the state machine is in the warning state, if the fault collection interface module receives a fault of a serious level, the state machine will jump to the error state and handle the fault of the serious level first;

[0052] When the state machine is in the normal state, if the fault collection interface module receives a fault of a severe level, the state machine directly jumps to the error state, in which the fault response module responds according to the configuration;

[0053] When the state machine is in a warning state or an error state, if the state is released, the jump will be to the normal state.

[0054] The fault judgment module and the fault response module have two levels of fault status and can configure two levels of fault handling methods for the same fault source, which improves the flexibility of fault handling. Some faults can be handed over to hardware for processing through configuration, which improves the fault response speed and reduces the pressure on the upper-level software.

[0055] The fault, anomaly detection and management device of the present invention adopts a modular design, and the safety island can be reused between different chip designs. For possible faults in different modules in the chip, only the corresponding fault detection unit needs to be designed to conveniently access the fault, anomaly detection and management framework of the present invention.

[0056] like Figure 1 and Figure 2 As shown, the present invention also provides a system-level fault and anomaly detection and management device for an in-vehicle Ethernet chip, comprising:

[0057] A plurality of fault detection units are respectively arranged in each functional module of the vehicle Ethernet chip, and are used for collecting fault information to a safety island inside the vehicle Ethernet chip through a safety bus according to possible faults;

[0058] A safety island is used to classify faults and make different responses to different faults. A programmable hardware fault handling module is provided inside the safety island to respond to faults in a timely manner and reduce the pressure on upper-layer software processing. The safety island uses an independent power supply and clock set outside the in-vehicle Ethernet chip to avoid the failure of the safety island caused by power supply or clock faults inside the chip.

[0059] The fault detection unit converts the fault information into a standard data stream and sends it to the fault collection interface module inside the safety island. The safety bus uses ecc for end-to-end protection. Inside the safety island, the fault collection interface module, fault judgment module, and fault response module set inside it respond to the faults occurring in the chip in real time. The safety island also has a monitoring module, which is used to detect the fault information transmitted from the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to judge whether the safety island is in a normal working state. If it is considered that the safety island is abnormal, the entire safety island is reset and reported to the external monitoring module of the safety island.

[0060] The fault collection interface module collects all fault information, classifies the faults, and sends them to the fault judgment module for unified processing;

[0061] The fault judgment module has a state machine built in. The state machine has 4 states: configuration, normal, warning, and error. The state machine defaults to the normal state;

[0062] When the upper-layer software configuration enters an instruction, the state machine will jump to the configuration state. In this state, the safety island will not respond to fault information. Therefore, a timer is started when entering this state. When the set time is reached, the state machine will automatically exit the configuration state and return to the normal state to avoid being unable to respond to faults for a long time in the configuration state;

[0063] When the state machine is in the normal state, if the fault collection interface module receives a fault of ordinary level, the state machine will jump to the warning state. In this state, it will notify the subsequent fault response module to process the fault. A timer is also started when entering the warning state. If the fault still exists after the specified time, the state machine will jump to the error state;

[0064] When the state machine is in the warning state, if the fault collection interface module receives a fault of severe level, the state machine will jump to the error state to give priority to processing the fault of severe level;

[0065] When the state machine is in the normal state, if the fault collection interface module receives a fault of severe level, the state machine will directly jump to the error state. In this state, the fault response module will make a response according to the configuration;

[0066] When the state machine is in the warning state or the error state, if the state is lifted, it will jump back to the normal state.

[0067] Through two levels of fault states, the fault judgment module and the fault response module can configure two levels of fault handling methods for the same fault source, improving the flexibility of fault handling. Some faults can be configured to be handled by hardware, which improves the fault response speed and reduces the pressure on the upper-layer software.

[0068] The present invention also provides a computer-readable storage medium containing a computer program, which, when executed by one or more processors, implements the system-level fault, anomaly detection, and management method of the in-vehicle Ethernet chip described in any one of the above.

[0069] The present invention proposes a system-level functional safety management framework, and based on this framework, implements a fault, anomaly detection, and management method and device. It adopts a modular design, which is convenient for adjusting the chip design and reduces the chip cost increased to meet the requirements of functional safety anomaly diagnosis coverage. The present invention provides a functional safety management framework for an in-vehicle Ethernet chip to classify and handle faults within the chip and respond to them. Through modular design, it is convenient to adjust the chip design and reduces the chip cost increased to meet the requirements of functional safety anomaly coverage. In each functional module of the chip, it is necessary to add a fault detection unit according to the possible faults that may occur, and add some additional fault detection units according to the requirements of the functional safety level. Each fault detection unit converges the fault information to the safety island inside the chip through a safety bus. The safety island classifies the faults inside and makes different responses to different faults. There is a programmable hardware fault handling module in the safety island, which can respond in a timely manner when a fault occurs, reducing the pressure on the upper-layer software for processing.

[0070] The safety island uses independent power and clock, which are provided from outside the chip, to avoid the failure of the safety island caused by power or clock faults inside the chip. The safety island is built with a watchdog module that periodically sends pulse signals to the detection module outside the chip. If the detection module outside the chip does not receive a pulse signal within the specified time, it is considered that the safety island of the chip has failed. Through this hierarchical protection method, the reliability of the chip operation is improved, which is convenient for meeting the requirements of functional safety for anomaly coverage.

[0071] The fault, anomaly detection, and management device of the present invention includes a hardware-implemented fault response module, which can configure the response methods of different faults through the upper-layer software. While ensuring the flexibility of the fault response method, it improves the fault response speed and reduces the pressure on the upper-layer software for processing.

[0072] In the present invention, most of the modules related to fault response are placed inside the security island within the chip. The security island uses an independent clock and power supply provided externally to the chip, ensuring that the fault response path is not interfered by abnormalities or faults in other internal modules of the chip. The watchdog is used to periodically send pulse signals to the external monitoring module of the chip, and the method of foreground error injection test plus background real-time monitoring is used to ensure the correctness of the function of the fault response path, ensuring that if any abnormality occurs in the fault response path, it can be detected by the external monitoring module in a timely manner. This method of hierarchical protection can improve the abnormal diagnosis coverage rate of the chip.

[0073] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, making equivalent substitutions or changes should be covered within the protection scope of the present invention.

Claims

1. A system-level fault, anomaly detection and management method for in-vehicle Ethernet chips, characterized in that The following steps are involved: Configure the functional safety management framework of the vehicle Ethernet chip. In each functional module of the vehicle Ethernet chip, a fault detection unit is set according to the possible faults. Each fault detection unit aggregates the fault information to the safety island inside the vehicle Ethernet chip through the safety bus. The safety island classifies the faults and makes different responses to different faults.

2. The system-level fault, anomaly detection and management method for an in-vehicle Ethernet chip according to claim 1, characterized in that The safety island uses an independent power supply and clock arranged outside the vehicle Ethernet chip to avoid failure of the safety island due to power supply or clock failure inside the chip.

3. The system-level fault, anomaly detection and management method for the in-vehicle Ethernet chip according to claim 2, characterized in that, A safety island external monitoring module is configured and arranged outside the vehicle-mounted Ethernet chip; the safety island has a built-in watchdog module, which regularly sends pulse signals to the safety island monitoring module outside the chip. If the safety island external monitoring module does not receive the pulse signal within the specified time, the chip's safety island is considered to be invalid.

4. The method for system-level fault, anomaly detection and management of an in-vehicle Ethernet chip according to any one of claims 1-3, characterized in that, The fault detection unit converts the fault information into a standard data stream and sends it to the fault collection interface module in the safety island. The safety bus uses ECC for end-to-end protection. The safety island responds to the faults occurring in the chip in real time through the fault collection interface module, fault judgment module and fault response module set up inside it.

5. The system-level fault, anomaly detection and management method of the in-vehicle Ethernet chip according to claim 4, characterized in that, The safety island is also equipped with a monitoring module, which is used to detect the fault information transmitted by the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to determine whether the safety island is in a normal working state. If the safety island is considered abnormal, the entire safety island will be reset and reported to the external monitoring module of the safety island.

6. The system-level fault, anomaly detection and management method of the in-vehicle Ethernet chip according to claim 5, characterized in that, The fault collection interface module collects all fault information, classifies the faults, and sends them to the fault judgment module for unified processing; The fault judgment module has a built-in state machine, which has four states: configuration, normal, warning, and error. The state machine is in the normal state by default; When the upper-layer software configuration enters the instruction, the state machine jumps to the configuration state. In this state, the safety island will not respond to fault information. Therefore, a timer will be started when entering this state. When the set time is reached, the state machine automatically exits the configuration state and returns to the normal state to avoid being in the configuration state for a long time and unable to respond to faults; When the state machine is in the normal state, if the fault collection interface module receives a common level fault, the state machine will jump to the warning state. In this state, the next level fault response module will be notified to handle the fault. When entering the warning state, a timer will be started. If the fault still exists after the specified time, the state machine will jump to the error state. When the state machine is in the warning state, if the fault collection interface module receives a fault of a serious level, the state machine will jump to the error state and handle the fault of the serious level first; When the state machine is in the normal state, if the fault collection interface module receives a fault of a severe level, the state machine directly jumps to the error state, in which the fault response module responds according to the configuration; When the state machine is in a warning state or an error state, if the state is released, the jump will be to the normal state.

7. A system-level fault, anomaly detection, and management device for an in-vehicle Ethernet chip, characterized in that, include: A plurality of fault detection units are respectively arranged in each functional module of the vehicle Ethernet chip, and are used for collecting fault information to a safety island inside the vehicle Ethernet chip through a safety bus according to possible faults; The safety island is used to classify faults and make different responses to different faults. A programmable hardware fault handling module is provided in the safety island to respond to faults in a timely manner and reduce the pressure of upper-layer software processing. The safety island uses an independent power supply and clock outside the on-board Ethernet chip to avoid the failure of the safety island due to power supply or clock failure inside the chip.

8. The system-level fault, anomaly detection and management device of the in-vehicle Ethernet chip according to claim 7, characterized in that, The fault detection unit converts the fault information into a standard data stream and sends it to the fault collection interface module in the safety island. The safety bus uses ECC for end-to-end protection; the safety island responds to the faults occurring in the chip in real time through the fault collection interface module, fault judgment module and fault response module set up inside it; the safety island is also provided with a monitoring module for detecting the fault information transmitted by the fault detection unit at the entrance of the safety island and the response made by the fault response module at the exit, so as to determine whether the safety island is in a normal working state. If the safety island is considered abnormal, the entire safety island is reset and reported to the external monitoring module of the safety island.

9. The system-level fault, anomaly detection, and management device for an in-vehicle Ethernet chip according to claim 8, wherein, The fault collection interface module collects all fault information, classifies the faults, and sends them to the fault judgment module for unified processing; The fault judgment module has a built-in state machine, which has four states: configuration, normal, warning, and error. The state machine is in the normal state by default; When the upper-layer software configuration enters the instruction, the state machine jumps to the configuration state. In this state, the safety island will not respond to fault information. Therefore, a timer will be started when entering this state. When the set time is reached, the state machine automatically exits the configuration state and returns to the normal state to avoid being in the configuration state for a long time and unable to respond to faults; When the state machine is in the normal state, if the fault collection interface module receives a common level fault, the state machine will jump to the warning state. In this state, the next level fault response module will be notified to handle the fault. When entering the warning state, a timer will be started. If the fault still exists after the specified time, the state machine will jump to the error state. When the state machine is in the warning state, if the fault collection interface module receives a fault of a serious level, the state machine will jump to the error state and handle the fault of the serious level first; When the state machine is in the normal state, if the fault collection interface module receives a fault of a severe level, the state machine directly jumps to the error state, in which the fault response module responds according to the configuration; When the state machine is in a warning state or an error state, if the state is released, the jump will be to the normal state.

10. A computer-readable storage medium containing a computer program, characterized in that, When the computer program is executed by one or more processors, the system-level fault, anomaly detection and management method for the vehicle Ethernet chip according to any one of claims 1 to 6 is implemented.

Citation Information

Cited By

  • Function safety hardware fault management system and method

    CN120722878A