Dual timing circuit

Through the dual-time circuit monitoring of the start-up and run time of the processor, and using hardware and software control to assert the reset signal, the monitoring complexity and reliability problems in the prior art are solved, and high reliability monitoring of computing devices is achieved and authentication costs are reduced.

CN120371613APending Publication Date: 2025-07-25THE BOEING CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510098616.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-23
Filing Date
2025-01-22
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The prior art is difficult to simultaneously monitor the startup and runtime operation of computing devices, and discrete ICs and CPLD/FPGAs have reliability problems and increased design complexity under high safety-critical functional requirements.

Method used

The dual timing circuit is adopted, including a startup circuit configured with a first timeout duration and an operating circuit configured with a second timeout duration, respectively, the boot loading of the processor and the software running time are monitored, the reset signal is asserted through hardware and software control, and the timeout time is configured through the serial interface, and the reset indicator signal is stored in conjunction with the latch.

Benefits of technology

It realizes high reliability monitoring of computing devices, reduces design complexity and certification costs, adapts to various system timeout requirements, provides redundancy and flexibility, and meets key applications with design assurance level A.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005253545980000011
    Figure HDA0005253545980000011
  • Figure HDA0005253545980000021
    Figure HDA0005253545980000021
  • Figure HDA0005253545980000031
    Figure HDA0005253545980000031
Patent Text Reader

Abstract

A dual timing circuit is configured to reset a processor when a fault is detected. The dual timing circuit includes a start-up circuit configured with a first timeout duration. The boot-up circuit is operable to assert the reset signal in response to the processor failing to complete the boot load for a first timeout duration after power-on. The dual timing circuit also includes an operating circuit configured with a second timeout duration. The operation circuit is operable to assert the reset signal in response to failing to receive the strobe signal from the processor for a second timeout duration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to providing fault correction for a computing system. More specifically, the present disclosure relates to monitoring and correcting startup and runtime operations of processors and microcontrollers. Background Art

[0002] Generally, the processors of computing devices are vulnerable to errors that may occur at any time during the startup and use of the computing devices. Some of these devices run applications that perform highly critical or key mission functions. For example, computing devices that run applications for monitoring heavy machinery (such as fleet vehicles) or other computing devices require a high level of safety certification (i.e., Design Assurance Level (DAL) A or B certification). These machines can use internal or external monitoring circuits to monitor the progress of device startup (or restart) and software application runtime to ensure that the processor operates without faults.

[0003] External monitoring circuits are superior to internal solutions. Compared with external solutions, internal monitoring circuits are less able to reliably monitor and correct faults caused during the bootloader process. Existing external solutions employ single timing integrated circuits (ICs) or field programmable gate arrays and / or complex programmable logic devices (FPGA / CPLD).

[0004] A single discrete IC can help monitor startup (hardware) or runtime operations (software), but not both simultaneously. Since the two have quite different timeout requirements, a single discrete IC will not be sufficient. Another problem is that when a fault occurs during startup or during runtime, the discrete IC cannot store the reset source (i.e., the cause of the fault). In addition, the discrete IC has discrete settable input pins for timeout, so two units using the same discrete IC have two problems. The first problem is that these inputs need to be configured from the microcontroller / processor, and such an implementation requires a high number of pins dedicated to the operation. The second problem is that there are reliability issues with such an implementation.

[0005] Using CPLD / FPGA can achieve dual timing for startup and runtime monitoring. However, CPLD / FPGA fails to meet the high safety critical function requirements for some computing devices (e.g., heavy machinery such as fleet vehicles; Design Assurance Level A (DAL A)). This results in conducting DAL A DO-178 / DO-254 certification, increasing design complexity, and potentially leading to a longer product development cycle and higher qualification costs. Summary of the Invention

[0006] One aspect of the present disclosure provides a dual-timing circuit configured to reset a processor upon detecting a fault. The dual-timing circuit includes a startup circuit configured with a first timeout duration. The startup circuit is operable to assert a reset signal in response to the processor failing to complete a bootload within the first timeout duration after power-on. The dual-timing circuit further includes an operation circuit configured with a second timeout duration. The operation circuit is operable to assert a reset signal in response to failing to receive a strobe signal from the processor within the second timeout duration.

[0007] According to some aspects of the present disclosure, the startup circuit is hardware-controlled.

[0008] According to some aspects of the present disclosure, the operation circuit is software-controlled.

[0009] According to some aspects of the present disclosure, the dual-timing circuit is further configured to assert a single reset signal to the processor in response to the startup circuit or the operation circuit asserting a reset signal.

[0010] According to some aspects of the present disclosure, the dual-timing circuit further includes a first memory element configured to store a reset indicator signal indicating the source of the reset signal asserted by the startup circuit. The dual-timing circuit further includes a second memory element configured to store a reset indicator signal indicating the source of the reset signal asserted by the operation circuit.

[0011] According to some aspects of the present disclosure, the processor is configured to disable the startup circuit after the bootload is completed and the operation circuit is properly configured.

[0012] According to some aspects of the present disclosure, the strobe signal from the processor is shared by the operation circuit and the startup circuit.

[0013] According to some aspects of the present disclosure, the dual-timing circuit further includes a serial interface. The second timeout duration is configured through the serial interface.

[0014] According to some aspects of the present disclosure, the strobe signal is operably connected to the operation circuit and the startup circuit.

[0015] Another aspect of the present disclosure provides a method for resetting a processor upon detecting a fault. The method includes asserting, by a startup circuit configured with a first timeout duration, a reset signal in response to the processor failing to complete a bootload during the first timeout period. The method further includes asserting, by an operation circuit configured with a second timeout duration, a reset signal in response to failing to receive a strobe signal from the processor within the second timeout duration.

[0016] According to some aspects of the present disclosure, the method further includes disabling the startup circuit in response to the processor completing a bootload within the first timeout duration.

[0017] According to some aspects of the present disclosure, the method further includes enabling the operation circuit in response to a boot load completed by the processor within a first timeout duration.

[0018] According to some aspects of the present disclosure, the method further includes configuring the operation circuit in response to a boot load performed by the processor.

[0019] According to some aspects of the present disclosure, the method further includes, in response to not receiving a strobe signal from the processor within a second timeout duration, writing a reset indicator signal indicating the source of a reset signal asserted by the operation circuit to a second memory element.

[0020] According to some aspects of the present disclosure, the method further includes, in response to the processor failing to complete a boot load within a first timeout duration, writing a reset indicator signal indicating the source of a reset signal asserted by a startup circuit.

[0021] According to some aspects of the present disclosure, the method further includes storing an indication of a reset signal asserted by the startup circuit in a first memory element and storing an indication of a reset signal asserted by the operation circuit in a second memory element.

[0022] According to some aspects of the present disclosure, the method further includes asserting a single reset signal to the processor in response to starting or asserting a reset.

[0023] According to some aspects of the present disclosure, the method further includes configuring the second timeout duration through a serial interface.

[0024] According to some aspects, the startup circuit can be reconfigured for a longer duration than the operation circuit. In the event of a failure of the operation circuit, the startup circuit can be used as a second layer of protection.

[0025] Another aspect of the present disclosure provides a method implemented by a dual timing circuit. The method includes asserting a reset signal to the processor in response to one of a plurality of timers expiring before a boot load or runtime completion. A first timer of the plurality of timers is configured to start upon a boot load of the processor. A second timer of the plurality of timers is configured to start in response to a successful boot load.

[0026] According to some aspects of the present disclosure, the method further includes writing an indication of the source of a reset signal asserted by a first circuit associated with the first timer to a first memory element and writing an indication of the source of a reset signal asserted by a second circuit associated with the second timer to a second memory element.

[0027] According to some aspects, the processor can read the first memory element and the second memory element after completing a boot load operation.

[0028] According to some aspects, the processor may clear the reset indicator signals stored at the first memory element and the second memory element.

[0029] According to some aspects, during power-on, the processor clears the first memory element and the second memory element before boot loading.

[0030] According to some aspects, if the power rail used to power the processor is not within the nominal range, the processor may be reset.

[0031] The features, functions, and advantages that have been discussed may be implemented independently in various aspects or may be combined in other aspects, and further details thereof can be seen with reference to the following description and the drawings. Brief Description of the Drawings

[0032] After thus generally describing the variations of the present disclosure, reference will now be made to the drawings, which are not necessarily drawn to scale, and in which:

[0033] Figure 1 is a block diagram of a dual timing circuit coupled to a processor according to an exemplary aspect of the present disclosure.

[0034] Figure 2 is a timing diagram of a startup circuit according to an exemplary aspect of the present disclosure.

[0035] Figure 3 is a timing diagram of an operation circuit according to an exemplary aspect of the present disclosure.

[0036] Figure 4 is a flowchart of a method for facilitating automatic correction of a transient fault according to an exemplary aspect of the present disclosure.

[0037] Figure 5 is a flowchart of a method for facilitating automatic correction of a transient fault according to an exemplary aspect of the present disclosure.

[0038] Figure 6 is a flowchart of a method for facilitating automatic correction of a transient fault according to an exemplary aspect of the present disclosure.

[0039] Figure 7 is a flowchart of a method for facilitating automatic correction of a transient fault according to an exemplary aspect of the present disclosure.

[0040] Figure 8 is a circuit diagram of a dual timing circuit according to an exemplary aspect of the present disclosure.

[0041] Figure 9A flowchart of a method for facilitating automatic correction of temporary faults according to an exemplary aspect of the present disclosure. Detailed implementation

[0042] The present disclosure provides a scalable dual-timing circuit that can be used for critical applications that achieve Design Assurance Level A, thereby reducing the need for DO-254 certification. The dual-timing circuit provides enhanced reliability (due to lower component count and use of discrete ICs), reduced design complexity (compared to ASIC / FPGA methods), and the ability to store reset sources. The dual-timing circuit provides a discrete-based implementation that allows the circuit to operate without programmable devices. For example, no timing capacitors are required to set timeout values. Additionally, the reset time setting changes throughout different stages of monitoring without incurring any additional cost to the program.

[0043] The disclosed dual-timing circuit has a wide range of applications because most computing devices can be configured to include external circuits for monitoring (especially computing devices with higher criticality or failure impact). Additionally, as a flexible yet still low-cost solution, the present disclosure can be easily adapted to support various system timeout requirements, whether it is an architecture based on a single central processing unit (CPU) or an architecture based on multiple central processing units (CPUs).

[0044] Figure 1 A block diagram of a dual-timing circuit 100 coupled to a processor 110 according to an exemplary aspect. The dual-timing circuit 100 includes a dual-timer 101 and a latch 112.

[0045] The processor 110 is connected to an operation circuit 113 and a start circuit 111 (both located within the dual-timer 101) via a strobe signal 120. The processor 110 is also communicatively coupled to the operation circuit 113 via a serial interface 125. The start circuit 111 and the operation circuit 113 are coupled to the processor 110 via a reset signal 121. The processor 110 is also coupled to the latch 112 via a reset indicator signal 123. The reset indicator signal 123 can be received at the latch 112 by the operation circuit 113 and / or the start circuit 111. The processor is coupled to the start circuit 111 via a disable signal 124.

[0046] For example, the processor 110 can be a microprocessor or a microcontroller.

[0047] The startup circuit 111 (for startup sequence monitoring) is mainly hardware-controlled and is configured with the following capabilities upon power-on: it can be disabled by software (if needed) once the startup process is successfully completed. The startup circuit 111 can provide startup timeout monitoring support in case of startup failure without any dependence on software. Since software is not required, a wide range of timeout values can be selected as the startup time by means of pull-up / pull-down resistors. For example, the startup time can be set to ten seconds. The startup timer is configured to count down to zero.

[0048] The operation circuit 113 (for software runtime monitoring) is mainly software-controlled. The operation timer for the operation circuit 113 can be configured upon successful completion of startup. The operation timer is configured to count down to zero. The configuration (i.e., setting) of the operation circuit 113 can be implemented through the serial interface 125, which protects against single-event bit flips that may potentially lead to incorrect timeout settings and hinder system functionality. The operation circuit 113 also meets higher-resolution timeout requirements for runtime monitoring (compared to the startup circuit). For example, compared to the ten-second startup timer, the operation timer can be set to ten milliseconds.

[0049] According to application requirements, the startup circuit 111 and the operation circuit 113 can operate together or one at a time, thus providing redundancy and robust monitoring for critical applications. Due to the built-in redundancy, the dual-timer circuit 100 provides additional reliability and security during operation. In addition, different from previous circuit architectures, since the startup circuit 111 is mainly hardware-controlled, it does not rely on software to implement hardware functions.

[0050] The strobe signal 120 is a common strobe shared by the operation circuit 113 and the startup circuit 111. The processor 110 is configured to send the strobe signal 120 (or hold-active signal) to the dual timer 101 to restart the startup timer or the operation timer. Receiving the strobe signal 120 indicates that the processor 110 is operating normally. On the contrary, if the strobe signal 120 is not received, it is assumed that the processor 110 is not operating properly. The strobe signal 120 is only activated after the dual timer 101 is fully configured. Having a common strobe signal 120 gives the flexibility to operate the two timers jointly or disable one timer. This feature also provides redundancy for the architecture.

[0051] The serial interface 125 coupled to the operation circuit 113 is used to configure the operation timer 113. The configuration of the serial interface 125 helps reduce the burden on the processor / controller because it only needs to be set once. The serial interface 125 also helps to easily implement changes in timeout requirements, which is a common scenario during the development phase.

[0052] The latch 112 is a single-bit memory latch. The latch 112 includes an enable latch 112A and an operation latch 112B. The latch includes simple digital circuitry where the output can be set to logic 1 or logic 0 by an input signal. The latch 112 stores the state of the received signal even after the input is removed. The latch receives a reset indicator signal 123 from the enable circuit 111 or the operation circuit 113. The reset indicator signal 123 is a signal that indicates to the latch 112 the source of the reset (i.e., the fault). The latch 112 records which one (if any) of the enable circuit 111 or the operation circuit 113 is the source of the reset. The purpose of the latch 112 is to store the reset source for later debugging or logging of the processor 110. The processor 110 can perform a memory reset to clear the reset indicator signal 123 stored at the latch 112. Performing the memory reset enables a new reset indicator signal 123 to be stored at the latch 112.

[0053] Figure 2 is a timing diagram of the enable circuit 111 according to an exemplary aspect. During power-on 209 at time T = 0 ms, the single-bit memory latch 112, including the enable latch signal 205 and the operation latch signal 206, is in an unknown state. At T = 20 ms, the power-on latch reset (RST) signal 204 causes the enable latch signal 205 and the operation latch signal 206 to output to a logic low state. At T = 50 ms, when all circuit power rails are within the specified range, the reset signal 121 and the secondary power good signal 207 are set to logic high. The secondary power good signal 207 is configured to keep the processor 110 in reset until the power rails are stable. At T = 100 ms, the enable circuit signal 202 is set low. In the case where the enable sequence 2 fails (i.e., the dual timer 101 does not receive the strobe signal 120 before the enable timer reaches zero), the enable circuit 111 asserts the reset signal 121, and the enable latch signal 205 is set to logic high. Once the enable is successfully completed, the operation timer is configured via the application software through the serial interface 125.

[0054] Figure 3 is a timing diagram of the operation circuit 113 according to an exemplary aspect. At time T = 0, the enable latch signal 205 and the operation latch signal 206 are reset to an unknown state. Once the operation circuit 113 is programmed (the enable timer is enabled and configured, for example, timeout = 10 ms), the operation circuit 113 begins monitoring the strobe signal 120 for a high-to-low transition.

[0055] If no transition is observed before the operation timer reaches zero, the operation circuit 113 activates the reset signal 121. A low pulse from the operation circuit signal 203 triggers and sets its operation latch signal 206 output to logic high. At reset, the processor 110 can read the states of the startup latch 112A and the operation latch 112B via the reset indicator signal 123 to identify the source of the reset. After determining the source of the reset, the processor 110 can reset the latch 112 (operation latch 112B, startup latch 112A) to logic low.

[0056] Figure 4 A flowchart of a method for resetting a processor upon detecting a fault is shown. The method includes the startup circuit 111 configured with a first timeout duration asserting the reset signal 121 (410) in response to the processor 110 failing to complete a boot load within the first timeout duration. The method further includes the operation circuit 113 configured with a second timeout duration asserting the reset signal 121 (420) in response to failing to receive the strobe signal 120 from the processor 110 within the second timeout duration. The first timeout duration can be a startup timer. The second timeout duration can be an operation timer.

[0057] In some examples, the method includes disabling the startup circuit 111 in response to the processor 110 completing a boot load within the first timeout duration.

[0058] In some examples, the method includes enabling the operation circuit 113 in response to the processor 110 completing a boot load within the first timeout duration. Enabling the operation circuit 113 can also include configuring the operation circuit 113.

[0059] In some examples, the method includes configuring the operation circuit 113 in response to a boot load of the processor 110. After the boot load is completed and the operation circuit 113 is correctly configured, the configuration of the operation circuit 113 is executed.

[0060] In some examples, the method includes, in response to failing to receive the strobe signal 120 from the processor 110 within the second timeout duration, writing a reset indicator signal 123 indicating the source of the reset signal asserted by the operation circuit 113 to a second memory element. The second memory element can be the operation latch 112B.

[0061] In some examples, the method includes, in response to the processor 110 failing to complete a boot load within the first timeout duration, writing a reset indicator signal 123 indicating the source of the reset signal 121 asserted by the operation circuit 113 to a first memory element. The first memory element can be the startup latch 112A.

[0062] In some examples, the method includes storing an indication of the reset signal 121 asserted by the startup circuit 111 via a first memory element and storing an indication of the reset signal 121 asserted by the operation circuit 113 via a second memory element.

[0063] In some examples, the method includes asserting a single reset signal to the processor in response to the startup circuit 111 or the operation circuit 113 asserting the reset signal 121.

[0064] In some examples, the method includes configuring a second timeout duration via a serial interface.

[0065] Now turning to Figure 5 , Figure 5 FIG. shows a flowchart of a method for monitoring and power-on resetting a processor upon detection of a hardware or software fault in accordance with aspects of the present disclosure.

[0066] The process starts with power-on resets 501, 511, and 521 of the startup circuit 111, the processor 110, and the operation circuit 113, respectively. When the power-on reset 501 is initiated at the startup circuit 111, the hardwired (hardware) startup circuit 111 is activated and the startup timer is reset 502. The startup circuit 111 starts a countdown 503 based on a configured countdown time. For example, the startup timer can be configured for 5 seconds. At the processor 110, a bootloader sequence 512 (system controller unit [SCU] bootloader) then begins.

[0067] While the bootloader 512 is in progress, the startup timer is configured to count down simultaneously. If the bootloader 512 is not completed before the startup timer expires (ends), a bootloader error is indicated. If a bootloader error occurs, the startup circuit 111 writes the source of the error to the startup latch 112A at 505 and asserts a reset signal 506 to the processor 110. Once the signal is received at the processor 110, the processor 110 restarts the power-on reset 511.

[0068] If the bootloader 512 sequence ends before the startup circuit 111 expires, the bootloader is successfully completed. Upon completion of the bootloader, the software application starts executing at 513 and the latch 112 is read by the processor 110 at 514. The latch is then reset at 515. On the other hand, the reading of the latch 514 should only be completed after the startup strobe signal 120. On the other hand, the reading of the latch should only be completed before the startup strobe signal 120.

[0069] The processor enables and configures the operation circuit 113 to reset the operation timer 522. If the operation circuit 113 is not configured correctly, the process is repeated at 501, 511, and 521 during power-on reset. The startup circuit 111 is automatically activated during any power-on reset 501, 511, 521. The operation circuit 113 is automatically disabled during any power-on reset.

[0070] Upon successful enabling and configuration of the 516 operation timer, the processor 110 disables the startup circuit 111 at 507. Additionally, or alternatively, the processor 110 can disable the operation of the startup circuit 111 at 507 via three discrete general-purpose input / output (GPIO) to hold the startup circuit 111 in a disabled configuration. Additionally, or alternatively, the startup circuit 111 has a connection via a dual in-line package (DIP) switch to disable the startup circuit 111.

[0071] Upon successful enabling and configuration of the 516 operation circuit 113, the processor 110 outputs a strobe signal 517 (i.e., a hold active signal) to the operation circuit 113, which indicates that the application is operating normally. Additionally, or alternatively, the strobe signal 517 can be initiated before sending the disable 507 to the startup circuit 111. In another aspect, the strobe signal 517 can be initiated only after the operation circuit 113 is fully configured.

[0072] As long as the strobe signal 120 is received at the operation circuit 113 before the operation timer expires 524, it is assumed that the application is running normally. If the strobe signal 120 is not received before the operation timer has expired 524, it is determined that there is a fault in the application run time. In response to the detected fault, the operation circuit 113 writes the source of the error to the latch 112B at 525 and asserts a reset signal 526 to the processor 110. The processor 110 reads the latch at 518 and resets the latch 112 at 519. Then, the processor 110 performs another power-on reset 501, 511, 521.

[0073] Figure 6 A flowchart of a method for monitoring and power-on resetting the processor 110 upon detection of a hardware fault in accordance with aspects of the present disclosure is shown.

[0074] Upon power-on reset 601, the start timer is activated 602. The processor 110 begins the bootloader sequence 603. If the bootloader sequence is completed within the time period before the timer expires 604, the processor 110 executes the software application 608. The processor 110 reads 609 the latch 112 and resets 610 the latch 112. The processor 110 then configures 611 the operation timer. If the operation timer is not configured before the start timer expires, the start circuit 111 writes the source of the reset to the latch 112 (i.e., the operation circuit 113) and asserts the reset 605. Configuring the operation circuit 113 may include enabling and setting the operation timer. If a strobe signal 120 is received at the operation circuit 113, it is assumed that the operation circuit has been successfully configured 612. If the strobe signal 120 is not received, the start circuit asserts the reset 605.

[0075] Figure 7 A flowchart showing a method for monitoring and power resetting the processor 110 upon detection of a software fault in accordance with aspects of the present disclosure is shown. When the operation timer is correctly configured 701, the processor 110 may disable 702 or reconfigure the start timer. The processor 110 then sends a keep-alive or strobe signal 703 to the operation circuit 113, which indicates that the application runtime is operational. If the operation timer expires before receiving the keep-alive signal 704, the operation circuit 113 writes the source of the reset to the latch 112 and asserts a reset command 705 to the processor 110.

[0076] Figure 8 A circuit diagram of a dual-timing circuit 100 according to an exemplary aspect is shown. The circuit includes a processor 110, an external dual-timer 101, a latch 112, and a power-on latch reset 801.

[0077] The processor 110 is connected to the operation circuit 113 and the start circuit 111 (both located within the dual-timer 101) via the strobe signal 120. The processor 110 is also communicatively coupled to the operation circuit 113 via a serial interface 125. The start circuit 111 and the operation circuit 113 are coupled to the processor 110 via a reset signal 121. The processor 110 is also coupled to the latch 112 via a reset indicator signal 123. The reset indicator signal 123 may be received at the latch 112 by the operation circuit 113 and / or the start circuit 111.

[0078] The processor 110 is configured to disable the start circuit 111 using a disable signal 124.

[0079] In some examples, the operation timer may be configured by the processor using GPIO 806.

[0080] In some examples, the operation circuit 113 can be enabled or disabled by an external enable-disable circuit 803.

[0081] In some examples, AND logic 802 is used to combine the power good signal 207, the startup reset signal 121a, and the operation reset signal 121b to output a reset signal 121 to the processor 110.

[0082] In some examples, the startup reset indicator signal 123a and the operation reset indicator signal 123b are coupled to each of the startup circuit 111 and the operation circuit 113.

[0083] In some examples, the power-on latch reset 801 is coupled to the startup circuit 111 and the operation circuit 113. The power-on latch reset 801 is configured to reset the startup latch 112A and the operation latch 112B.

[0084] Figure 9 A flowchart of a method for resetting the processor 110 upon detection of a fault in accordance with aspects of the present disclosure is shown. The method includes asserting a reset signal 121 to the processor 110 (910) in response to one of a plurality of timers 111, 113 expiring before completion of a boot load or run time. A first timer 111 of the plurality of timers is configured to start during a boot load of the processor 110 (920). A second timer 113 of the plurality of timers is configured to start in response to a successful boot load (930).

[0085] In some examples, the method includes writing an indication of a source of the reset signal 121 asserted by a first circuit 111 associated with the first timer 111 to a first memory element 112A, and writing an indication of a source of the reset signal 121 asserted by a second circuit 113 associated with the second timer 113 to a second memory element 112B.

[0086] Of course, the present disclosure may be implemented in other ways than those specifically set forth herein without departing from the basic characteristics thereof. This embodiment should be considered illustrative in all respects and not restrictive, and all changes within the meaning and equivalence range of the appended claims are intended to be included therein.

[0087] Furthermore, the present disclosure includes examples in accordance with the following clauses:

[0088] Clause 1. A method for resetting a processor (110) upon detection of a fault, the method comprising:

[0089] A startup circuit (111) configured with a first timeout duration asserts a reset signal (121) in response to the processor (110) failing to complete a boot load within the first timeout duration; and

[0090] An operation circuit (113) configured with a second timeout duration asserts the reset signal (121) in response to failing to receive a strobe signal (120) from the processor (110) within the second timeout duration.

[0091] Clause 2. The method according to clause 1, further comprising disabling the startup circuit (111) in response to the processor (110) completing the boot load within the first timeout duration.

[0092] Clause 3. The method according to clause 1, further comprising enabling the operation circuit (113) in response to the processor (110) completing the boot load within the first timeout duration.

[0093] Clause 4. The method according to clause 1, further comprising configuring the operation circuit (113) in response to the boot load of the processor (110).

[0094] Clause 5. The method according to clause 1, further comprising, in response to failing to receive a strobe signal (120) from the processor (110) within the second timeout duration, writing a reset indicator signal (123) indicating the source of the reset signal (121) asserted by the operation circuit (113) to a second memory element (112B).

[0095] Clause 6. The method according to clause 1, further comprising, in response to the processor (110) failing to complete the boot load within the first timeout duration, writing a reset indicator signal (123) indicating the source of the reset signal (121) asserted by the startup circuit (111).

[0096] Clause 7. The method according to clause 1, further comprising:

[0097] Storing an indication of the reset signal (121) asserted by the startup circuit (111) in a first memory element (112A); and

[0098] Storing an indication of the reset signal (121) asserted by the operation circuit (113) in a second memory element (112B).

[0099] Clause 8. The method according to clause 1, further comprising asserting a single reset signal (121) to the processor (110) in response to the startup circuit (111) or the operation circuit (113) asserting a reset.

[0100] Clause 9. The method according to Clause 1 further includes configuring the second timeout duration via a serial interface.

[0101] Clause 10. A method implemented by a dual timing circuit, the method including:

[0102] Asserting a reset signal (121) to a processor (110) in response to one of a plurality of timers expiring before boot loading or run time completion;

[0103] wherein a first timer of the plurality of timers is configured to start at boot loading of the processor (110); and

[0104] wherein a second timer of the plurality of timers is configured to start in response to successful boot loading.

[0105] Clause 11. The method according to Clause 10 further includes:

[0106] Writing an indication of a source of the reset signal (121) asserted by a first circuit (111) associated with the first timer to a first memory element (112A); and

[0107] Writing an indication of a source of the reset signal (121) asserted by a second circuit (113) associated with the second timer to a second memory element (112B).

Claims

1. A dual-timing circuit (100) configured to reset a processor (110) upon detection of a fault, the dual-timing circuit comprising: A startup circuit (111) configured with a first timeout duration, wherein the startup circuit (110) is operable to assert a reset signal (121) in response to the processor (110) failing to complete a boot load within the first timeout duration after power-on; and An operation circuit (113) configured with a second timeout duration, wherein the operation circuit (113) is operable to assert the reset signal (121) in response to failing to receive a strobe signal (120) from the processor (110) within the second timeout duration.

2. The dual-timing circuit (100) according to claim 1, wherein the startup circuit (111) is hardware-controlled.

3. The dual-timing circuit (100) according to claim 1, wherein the operation circuit (113) is software-controlled.

4. The dual-timing circuit (100) according to claim 1, further configured to assert a single reset signal (121) to the processor (110) in response to the startup circuit (111) or the operation circuit (113) asserting the reset signal (121).

5. The dual-timing circuit (100) according to claim 1, further comprising: A first memory element (112A) configured to store a reset indicator signal (123) indicating the source of the reset signal (121) asserted by the startup circuit (111); and A second memory element (112B) configured to store the reset indicator signal (123) indicating the source of the reset signal (121) asserted by the operation circuit (113).

6. The dual-timing circuit (100) according to claim 1, wherein the processor (110) is configured to disable the startup circuit (111) after the boot load is completed and the operation circuit (113) is correctly configured.

7. The dual timing circuit (100) according to claim 1, wherein, The strobe signal (120) from the processor (110) is shared by the operation circuit (113) and the startup circuit (111).

8. The dual timing circuit (100) according to claim 1 further includes a serial interface (125), wherein, The second timeout duration is configured to be set via the serial interface (125).

9. The dual-timing circuit (100) according to claim 1, wherein the strobe signal (120) is configured to be operably provided to both the operation circuit (113) and the startup circuit (111).

10. A method for resetting a processor (110) upon detection of a fault, the method comprising: Asserting a reset signal (121) by a startup circuit (111) configured with a first timeout duration in response to the processor (110) failing to complete a boot load within a first timeout duration; and An operation circuit (113) configured with a second timeout duration asserts the reset signal (121) in response to not receiving the strobe signal (120) from the processor (110) within the second timeout duration.