Verification method, system and equipment for fault injection of FPGA (Field Programmable Gate Array) and medium

By injecting and verifying faults in preset simulation tools, the problems of high resource consumption and performance degradation in FPGA fault tolerance design are solved, and efficient and accurate fault tolerance capability verification is achieved in nuclear power plant systems to meet reliability requirements.

CN120449788APending Publication Date: 2025-08-08STATE NUCLEAR POWER AUTOMATION SYST ENGCO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510605012.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing FPGA fault-tolerant design has high resource consumption and reduced performance, which cannot meet the reliability requirements of nuclear power plant systems, lacks general fault injection verification methods, and is difficult to use flexibly in different application scenarios.

Method used

Provides a fault injection verification method for FPGAs. By obtaining fault injection information and target nodes, fault injection is performed in preset simulation tools, generating simulation results and verifying the fault tolerance of FPGAs, including automated scripting language control fault injection and simulation tools to simulate soft errors.

Benefits of technology

Efficiently and accurately verify the fault tolerance of FPGA in high-safety applications such as nuclear power plants, ensure the stability of the design and anti-interference performance, and meet the reliability requirements of nuclear power plant systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120449788A_ABST
    Figure CN120449788A_ABST
Patent Text Reader

Abstract

The invention provides a verification method, system and device for fault injection of an FPGA and a medium, the FPGA is applied to a nuclear power station system, and the verification method comprises the following steps: obtaining fault injection information and a target node in the FPGA; based on the fault injection information, performing fault injection on the target node in a preset simulation tool to obtain a simulation result; and based on the simulation result, verifying the FPGA to obtain a verification result. According to the method and the device, the fault injection is performed on the target node in the FPGA in the preset simulation tool through the fault injection information to obtain the simulation result, so that the verification result of the FPGA is obtained, the fault-tolerant capability of the FPGA in high-security applications such as a nuclear power station is efficiently and accurately verified, the method and the device can be flexibly used in different application scenes, and the reliability of the FPGA is improved. And the stability and the anti-interference performance of the design are tested in the preset simulation tool, so that the performance and the stability of the fault-tolerant design of the FPGA can be ensured, and the reliability requirement of a nuclear power station system is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of FPGA technology, and in particular to a method, system, device, and medium for verifying fault injection of an FPGA. Background Art

[0002] As nuclear power plants face increasing safety and reliability requirements, traditional analog and microprocessor-based software control systems are increasingly unable to meet the high reliability demands of complex operating conditions. As an alternative, field-programmable gate arrays (FPGAs) have gained widespread attention and application in nuclear power plant safety automation systems due to their parallel processing capabilities and flexible hardware logic configuration. However, the reduced feature size and core voltage of FPGAs make them sensitive to soft errors such as single-event upsets (SEUs), especially in high-radiation environments. This can lead to data errors and reduced system reliability.

[0003] Existing FPGA fault-tolerant designs typically use technologies such as triple modular redundancy (TMR) and Hamming coding. Although these methods can resist soft errors to a certain extent, they are often accompanied by problems such as high resource consumption and performance degradation. They also lack universal fault injection verification methods, making them difficult to flexibly use in different application scenarios. They cannot guarantee the performance and stability of FPGA fault-tolerant designs and cannot meet the reliability requirements of nuclear power plant systems. Summary of the Invention

[0004] The technical problem to be solved by the present disclosure is to overcome the defects of the prior art FPGA fault-tolerant design that adopts triple modular redundancy, Hamming coding and other technologies, which result in high resource consumption, performance degradation, inability to ensure the stability of the FPGA fault-tolerant design, and inability to meet the reliability requirements of nuclear power plant systems. A method, system, device and medium for verifying FPGA fault injection are provided.

[0005] The present disclosure solves the above technical problems through the following technical solutions:

[0006] The present disclosure provides a method for verifying fault injection of an FPGA, wherein the FPGA is applied to a nuclear power plant system. The verification method includes:

[0007] Obtain fault injection information and target nodes in FPGA;

[0008] Based on the fault injection information, injecting a fault into the target node in a preset simulation tool to obtain a simulation result;

[0009] Based on the simulation results, the FPGA is verified to obtain a verification result.

[0010] Optionally, the fault injection information includes at least one of a fault type, a fault injection time, a fault duration, a fault interval, and a number of fault injections.

[0011] Optionally, the fault type includes at least one of a single event upset and a multiple event upset.

[0012] Optionally, the step of obtaining fault injection information and a target node in the FPGA includes:

[0013] The netlist file corresponding to the FPGA is parsed to obtain the target node.

[0014] Optionally, the target node includes at least one of a status register and a logic unit.

[0015] Optionally, the simulation result includes waveform data of the FPGA, and the verification result includes a fault masking result;

[0016] The step of verifying the FPGA based on the simulation result to obtain a verification result includes:

[0017] Based on the waveform data, determining whether the FPGA masks the fault corresponding to the fault injection information to obtain the fault masking result;

[0018] and / or,

[0019] The simulation result includes an output result of the FPGA, and the verification result includes the number of errors;

[0020] The step of injecting a fault into the target node in a preset simulation tool based on the fault injection information to obtain a simulation result includes:

[0021] Based on the fault injection information, injecting a fault into the target node in a preset simulation tool, and setting assertions to obtain the output result;

[0022] The step of verifying the FPGA based on the simulation result to obtain a verification result includes:

[0023] In response to the output result satisfying a preset condition, the errors triggered by the assertion are counted to obtain the number of errors.

[0024] The present disclosure further provides a system for verifying fault injection of an FPGA, wherein the FPGA is applied to a nuclear power plant system, and the verification system comprises:

[0025] Fault information acquisition module, used to obtain fault injection information;

[0026] A target node acquisition module is used to obtain the target node in the FPGA;

[0027] A fault injection module, configured to inject a fault into the target node in a preset simulation tool based on the fault injection information to obtain a simulation result;

[0028] A verification module is used to verify the FPGA based on the simulation result to obtain a verification result.

[0029] Optionally, the fault injection information includes at least one of a fault type, a fault injection time, a fault duration, a fault interval, and a number of fault injections.

[0030] Optionally, the fault type includes at least one of a single event upset and a multiple event upset.

[0031] Optionally, the target node acquisition module is further configured to parse a netlist file corresponding to the FPGA to obtain the target node.

[0032] Optionally, the target node includes at least one of a status register and a logic unit.

[0033] Optionally, the simulation result includes waveform data of the FPGA, and the verification result includes a fault masking result;

[0034] The verification module includes:

[0035] a fault masking determination unit, configured to determine, based on the waveform data, whether the FPGA masks the fault corresponding to the fault injection information, so as to obtain the fault masking result;

[0036] and / or,

[0037] The simulation result includes an output result of the FPGA, and the verification result includes the number of errors;

[0038] The fault injection module is further configured to perform fault injection on the target node in a preset simulation tool based on the fault injection information, and set assertions to obtain the output result;

[0039] The verification module includes:

[0040] An error counting unit is configured to count the errors triggered by the assertion in response to the output result satisfying a preset condition, so as to obtain the number of errors.

[0041] The present disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and used to run on the processor, wherein the processor implements the above-mentioned FPGA fault injection verification method when executing the computer program.

[0042] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the above-mentioned FPGA fault injection verification method is implemented.

[0043] The present disclosure also provides a computer program product, including a computer program, which implements the above-mentioned FPGA fault injection verification method when executed by a processor.

[0044] On the basis of conforming to the common sense in this field, the above-mentioned preferred conditions can be arbitrarily combined to obtain the preferred embodiments of the present disclosure.

[0045] The positive progress of this disclosure is:

[0046] The present disclosure uses fault injection information to inject faults into target nodes in an FPGA in a preset simulation tool to obtain simulation results, and then obtain FPGA verification results. This overcomes the defects of high resource consumption and performance degradation in existing technologies, and efficiently and accurately verifies the fault tolerance capabilities of FPGAs in high-security applications such as nuclear power plants. It can be flexibly used in different application scenarios. The interference of soft errors on FPGA circuits is simulated through fault injection information, and the stability and anti-interference performance of the design are tested in the preset simulation tool. This can ensure the performance and stability of the FPGA fault-tolerant design and meet the reliability requirements of the nuclear power plant system. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a flow chart of a method for verifying fault injection in an FPGA according to embodiment 1 of the present disclosure;

[0048] Figure 2 This is a schematic diagram of the first module of the FPGA fault injection verification system according to Embodiment 2 of the present disclosure;

[0049] Figure 3 This is a schematic diagram of the second module of the FPGA fault injection verification system according to Embodiment 2 of the present disclosure;

[0050] Figure 4 This is a schematic diagram of the architecture of the FPGA fault injection verification system according to Embodiment 2 of the present disclosure;

[0051] Figure 5 This is a structural diagram of an electronic device according to embodiment 3 of the present disclosure. DETAILED DESCRIPTION

[0052] The present disclosure is further illustrated below by way of examples, but the present disclosure is not limited to the scope of the examples.

[0053] In the embodiments of the present disclosure, prefixes such as "first" and "second" are used only to distinguish different description objects, and have no limiting effect on the position, order, priority, quantity or content of the described objects. In the embodiments of the present disclosure, the use of prefixes such as ordinal numbers to distinguish description objects does not constitute a limitation on the described objects. For the statement of the described objects, please refer to the description in the context of the claims or embodiments, and no unnecessary limitations should be constituted due to the use of such prefixes. In addition, in the description of this embodiment, unless otherwise specified, the meaning of "plurality" is two or more.

[0054] Example 1

[0055] This embodiment provides a method for verifying fault injection of an FPGA, where the FPGA is applied to a nuclear power plant system. Figure 1 As shown, the verification method includes:

[0056] S11, obtaining fault injection information and target nodes in FPGA;

[0057] S12. Based on the fault injection information, inject a fault into the target node in a preset simulation tool to obtain a simulation result;

[0058] S13. Based on the simulation results, verify the FPGA to obtain a verification result.

[0059] Specifically, automated operations are implemented using a scripting language. The fault-tolerance verification objectives and parameters, known as fault injection information, are set based on the characteristics of the FPGA design and the specific requirements of the nuclear power application. Different nuclear power plants have different parameter requirements. By studying the design criteria of nuclear power plants and anticipating potential faults, the fault injection information is generated.

[0060] Automated control technology based on scripting languages such as TCL (Tool Command Language) is used to generate fault injection instructions and import them into the FPGA simulation environment. The preset simulation tool is the simulation environment or simulator.

[0061] Based on TCL scripts, the simulator directly modifies the internal logic state of the FPGA. During the fault generation process, key sensitive nodes are automatically identified and corresponding injection scripts are generated to simulate soft errors. Soft error simulation is achieved by fixing the state values of key sensitive nodes through commands such as "force -freeze." The "force -freeze" command can be used to control the fault's validity within a specific time period, simulating various scenarios such as single faults and frequent faults. Key sensitive nodes are the target nodes. For example, using the "force -freeze" command as an injection method, a specific bit is fixed to "0" or "1" for a specific time period, simulating the impact of soft errors on FPGA circuits.

[0062] Load the simulation model of the FPGA design into a pre-defined simulation tool, such as NuSIM, to observe circuit behavior in real time after fault injection. Build a simulation test bench, defining input stimulus signals and output monitoring signals to simulate the operating conditions of the FPGA design in a real application.

[0063] Execute the generated fault injection script in the pre-set simulation tool to inject soft errors into the target nodes according to the specified fault parameters. The script sequentially injects faults into the simulation model based on the specified time and nodes. For example, the "force-freeze" command can be used to set a bit in a target node to a fixed value and maintain that state for a specified period of time.

[0064] After fault injection, the FPGA design is run in a pre-set simulation tool to analyze the impact of fault injection on the FPGA system's performance and functionality, thereby verifying the reliability of the fault-tolerant design. The script is run using the simulation model of the FPGA design to evaluate the impact of fault injection on circuit operation. During the simulation process, the simulation tool generates simulation results based on the injected fault information. The FPGA is then verified based on these simulation results to obtain a verification result.

[0065] In this solution, fault injection information is used to inject faults into target nodes in the FPGA in a preset simulation tool to obtain simulation results, and then obtain FPGA verification results. This overcomes the defects of high resource consumption and performance degradation in existing technologies, and efficiently and accurately verifies the fault tolerance capabilities of FPGAs in high-security applications such as nuclear power plants. It can be flexibly used in different application scenarios. The interference of soft errors on FPGA circuits is simulated through fault injection information, and the stability and anti-interference performance of the design are tested in the preset simulation tool. This can ensure the performance and stability of the FPGA fault-tolerant design and meet the reliability requirements of the nuclear power plant system.

[0066] In an implementable solution, the fault injection information includes at least one of the fault type, the fault injection time, the fault duration, the fault interval duration, and the number of fault injections.

[0067] Specifically, configure detailed test parameters, including the duration of the fault injection, the duration between faults, and the number of injections, so that the subsequent automated script can generate control commands accordingly. Import these configured parameters into the script to ensure that they can be used during script execution, thereby automatically controlling the fault injection process. This script can be written in TCL or Python (a computer programming language) to facilitate recognition and execution by the pre-defined simulation tool.

[0068] In this solution, by configuring fault injection information including at least one of the fault type, fault injection time, fault duration, fault interval duration, and number of fault injections, subsequent automated scripts can generate control commands based on this information, thereby achieving automated control of the fault injection process.

[0069] In one implementation, the fault type includes at least one of a single event upset and a multiple event upset.

[0070] Specifically, nuclear power plant applications often require testing the impact of soft errors on plant systems. Based on design requirements, different types of fault injection are automatically generated, including single-event upsets (SEUs) and multiple-event upsets (MEUs). This allows for simulating a variety of soft error scenarios without changing the hardware structure. For example, an SEU can inject a single bit upset, while an MEU simulates multiple bit upsets simultaneously.

[0071] In this solution, by simulating soft errors such as single-event upsets and multiple-event upsets in real environments, accurate soft error scenarios are generated through scripted fault injection, allowing the design to verify in advance the possible faults that may occur in actual high-radiation environments.

[0072] In one feasible solution, step S11 includes:

[0073] Parse the netlist file corresponding to the FPGA to obtain the target node.

[0074] Specifically, TCL is used to read the netlist file, traverse the nodes in the netlist, and mark the key sensitive nodes, i.e., the target nodes. This replaces manual line-by-line inspection, saving over 90% of time and improving efficiency. It covers all potentially sensitive nodes, eliminating omissions. When design changes occur, simply re-parse the netlist to update the list of key sensitive nodes.

[0075] Nodes in the netlist can be prioritized based on their functional importance and sensitivity to ensure that highly sensitive and high-risk nodes are tested first.

[0076] Based on the test objectives, such as maximizing fault coverage or verifying specific functional modules, select a certain number of nodes from the high-priority nodes as target nodes. Record the target node locations in the script so that they can be directly called in subsequent injection steps. First, sort the priority nodes in descending order of functional importance and sensitivity. Then, determine the number of nodes to be injected based on test resources. Finally, record the node locations in the script. Test resources, such as simulation time, should be used. The number of nodes, such as 30% of all high-priority nodes, is just an example and can be adjusted based on actual conditions.

[0077] In this solution, automated target node identification eliminates the complex process of manual point selection, which not only improves verification efficiency but also ensures the consistency and comprehensiveness of the test and reduces the risk of human error.

[0078] In one implementable solution, the target node includes at least one of a status register and a logic unit.

[0079] In this scheme, by acquiring target nodes such as status registers and logic units, which are extremely sensitive in a soft error environment, the validity and comprehensiveness of the target nodes are guaranteed.

[0080] In one feasible solution, the simulation result includes waveform data of the FPGA, and the verification result includes a fault masking result;

[0081] Step S13 includes:

[0082] Based on the waveform data, it is determined whether the FPGA masks the fault corresponding to the fault injection information to obtain a fault masking result.

[0083] Specifically, the preset simulation tool automatically records the circuit's waveform data during fault injection for subsequent analysis. This waveform data includes the circuit's output response after the fault is injected, making it easy to observe the fault's impact on circuit behavior, such as sudden changes in output signals or incorrect transitions in status registers. By comparing the waveform changes before and after the fault, it is possible to determine whether the fault has been effectively shielded.

[0084] For nodes designed with fault tolerance such as triple modular redundancy, it is possible to detect whether the error is successfully masked. If it cannot be masked, it will be recorded as a failure.

[0085] After each fault injection, a waveform file can be generated to facilitate observation of the operation of the FPGA design after the fault injection. The playback function is also supported to help designers deeply analyze the actual impact of each fault.

[0086] By calling the waveform file generated by the simulator, the waveform changes of each fault node can be recorded and output in a visual form. Designers can replay the waveform at a specific time point to intuitively understand the impact of the fault and support design improvements.

[0087] In this solution, by analyzing the waveform data and obtaining the fault shielding results, it is possible to determine whether the fault is effectively shielded, and effectively verify the impact of the fault on the behavior of the FPGA circuit.

[0088] In one embodiment, the simulation result includes an output result of the FPGA, and the verification result includes a number of errors;

[0089] Step S12 includes:

[0090] Based on the fault injection information, the fault is injected into the target node in the preset simulation tool and assertions are set to obtain the output results;

[0091] Step S13 includes:

[0092] In response to the output result satisfying the preset condition, the errors triggered by the assertion are counted to obtain the number of errors.

[0093] Specifically, configure self-check assertions in the simulation testbench to detect unexpected output behavior during the simulation. For example, you can set an assertion in the status register. If an undefined state is detected in the status register, an error is logged. The default condition is that the output result is not the expected result.

[0094] Embed pre-set assertion logic into simulation scripts, enabling real-time verification of circuit outputs during simulation. If an anomaly is detected, error counting is automatically triggered. Multiple assertion modes are supported, such as simple logic assertions and counter overflow assertions, to monitor whether faults are detected and handled. Embed assertion logic into simulation scripts.

[0095] During simulation, the number of assertion failures or errors after fault injection is recorded in real time to generate an error count. This error count facilitates quantitative analysis of the impact of fault injection on the FPGA and helps evaluate the effectiveness of the FPGA's fault-tolerant design. The error count is output to a report file as part of the analysis report, allowing designers to assess the quality of the fault-tolerant design. Error counts can be recorded in various ways, such as by time period or fault type, facilitating subsequent statistical analysis.

[0096] Analyze the error counts recorded during the simulation process, count the fault frequency of each node, and determine the nodes most susceptible to failures in order to further optimize the fault-tolerant design.

[0097] In this solution, assertion checking can quickly identify potential defects in the FPGA design, improving verification efficiency. Error counts facilitate quantitative analysis of the impact of fault injection on the FPGA, thereby evaluating the effectiveness of the fault-tolerant design. During the verification process, assertion checking and error counting record the impact of each fault in real time, quickly identifying potential design flaws and providing detailed data for further optimization of the fault-tolerant design.

[0098] In addition, after the initial test, it is possible to analyze whether the injected faults are comprehensive enough. If it is found that sensitive nodes are missed or insufficiently covered, the injected nodes can be automatically adjusted to obtain better fault coverage.

[0099] By analyzing the simulation results, we can identify potential fault areas that were not triggered, and increase the frequency of fault injection in these areas in subsequent tests. In addition, we can dynamically adjust the injection intensity and timing based on the characteristics of the FPGA design to ensure maximum test coverage.

[0100] In FPGA design, finite state machines (FSMs) are often used in control sections and are extremely sensitive to soft errors. The fault tolerance of FSMs can be tested to ensure they maintain a safe state even when a fault occurs.

[0101] Using fault-tolerant encoding methods such as one-hot encoding and gray coding, you can inject faults through scripts and test the finite state machine's response behavior in a pre-defined simulation tool. This allows you to automatically perform state transition analysis to verify whether the finite state machine can recover to a valid state after an error occurs, thus preventing the system from crashing or entering an unknown state.

[0102] Based on the simulation results, determine whether the injected faults cover all key and sensitive nodes. If any nodes are not tested or the fault is not triggered, you can add more injected nodes or adjust the injection timing.

[0103] If the verification results show that certain fault types do not achieve the expected effect, the type, intensity and frequency of fault injection can be readjusted and a new injection script can be generated for re-verification.

[0104] Continuously optimize the injection script and parameter configuration based on the verification results to ensure that the verification process covers all possible failure scenarios and achieves the best fault-tolerant design results.

[0105] The error information and performance parameters recorded during the simulation process can be integrated to generate an analysis report after fault injection, providing a basis for further optimization of FPGA fault-tolerant design.

[0106] It can automatically extract waveform data, assertion records, error count results, and performance evaluation results from preset simulation tools, summarize them, and generate a comprehensive analysis report.

[0107] The analysis report includes fault coverage, which is the proportion of faults detected after fault injection. Fault coverage = actual measured faults / actual injected faults. High fault coverage indicates strong fault detection and shielding capabilities of the design.

[0108] FPGA designs have resource consumption, timing delays, error type distribution, etc. under different fault scenarios. The analysis report after fault injection also includes error distribution, resource utilization and timing performance evaluation, providing designers with intuitive performance data, enabling designers to efficiently optimize and improve the FPGA's fault-tolerant design, ensuring that the fault-tolerant design does not significantly affect the overall performance while improving the anti-interference capability.

[0109] Summarize the overall fault-tolerance performance of FPGA designs during fault injection, including the types of errors that are successfully masked and the causes of errors that cannot be masked, providing data support for improving fault-tolerant designs.

[0110] The final analysis report can be presented in the form of charts and data tables, allowing designers to quickly understand the fault tolerance effect and design flaws. The analysis report can quantify the actual effect of the fault tolerance design, ensuring that it meets the high reliability requirements in critical application scenarios such as nuclear power plants.

[0111] The overall idea of this embodiment is to simulate and test the FPGA design through automated fault injection technology, thereby analyzing the effectiveness of the fault-tolerant design. The entire process is automated through script control, ensuring the consistency and repeatability of the test, and can efficiently and accurately simulate the impact or interference of soft errors on the FPGA circuit, and analyze and verify the effectiveness of its fault-tolerant design. The verification process is simplified through scripted operations, which improves the reliability and anti-interference ability of FPGA designs in high-security application scenarios such as nuclear power plants. This method provides a low-cost, high-coverage verification method for fault-tolerant design, which is particularly suitable for high-security application environments such as nuclear power plants, and has important application value in the future development of fault-tolerant technology for nuclear power plant systems.

[0112] In this embodiment, fault injection information is used to inject faults into target nodes in the FPGA in a preset simulation tool to obtain simulation results, and then obtain FPGA verification results. This overcomes the defects of high resource consumption and performance degradation in the existing technology, and efficiently and accurately verifies the fault tolerance capability of the FPGA in high-security applications such as nuclear power plants. The embodiment can be flexibly used in different application scenarios. The interference of soft errors on the FPGA circuit is simulated through fault injection information, and the stability and anti-interference performance of the design are tested in the preset simulation tool. This can ensure the performance and stability of the FPGA fault-tolerant design and meet the reliability requirements of the nuclear power plant system.

[0113] Example 2

[0114] Corresponding to the aforementioned FPGA fault injection verification method embodiment, the present disclosure also provides an FPGA fault injection verification system embodiment.

[0115] FPGA is used in nuclear power plant systems, such as Figure 2 As shown, the verification system includes:

[0116] Fault information acquisition module 1, used to obtain fault injection information;

[0117] Target node acquisition module 2, used to acquire the target node in the FPGA;

[0118] The fault injection module 3 is used to inject faults into the target node in a preset simulation tool based on the fault injection information to obtain simulation results;

[0119] The verification module 4 is used to verify the FPGA based on the simulation result to obtain a verification result.

[0120] In an implementable solution, the fault injection information includes at least one of the fault type, the fault injection time, the fault duration, the fault interval duration, and the number of fault injections.

[0121] In one implementation, the fault type includes at least one of a single event upset and a multiple event upset.

[0122] In an implementable solution, the target node acquisition module 2 is further configured to parse the netlist file corresponding to the FPGA to obtain the target node.

[0123] In one implementable solution, the target node includes at least one of a status register and a logic unit.

[0124] In one feasible solution, the simulation result includes waveform data of the FPGA, and the verification result includes a fault masking result;

[0125] like Figure 3 As shown, the verification module 4 includes:

[0126] The fault masking determination unit 41 is configured to determine whether the FPGA masks the fault corresponding to the fault injection information based on the waveform data, so as to obtain a fault masking result.

[0127] In one embodiment, the simulation result includes an output result of the FPGA, and the verification result includes a number of errors;

[0128] The fault injection module 3 is further configured to inject faults into the target node in a preset simulation tool based on the fault injection information and set assertions to obtain output results;

[0129] Verification module 4 includes:

[0130] The error counting unit 42 is configured to count errors triggered by assertions in response to the output result satisfying a preset condition to obtain the number of errors.

[0131] In addition, each module in the FPGA fault injection verification system can be set or adjusted according to the actual situation, such as Figure 4 FIG. 1 is a schematic diagram of the architecture of a fault injection verification system for FPGA.

[0132] The fault information acquisition module is re-divided into a fault injection control module and a fault injection generation module. The fault injection control module is the core control unit of the entire system, responsible for managing and triggering the fault injection process in the FPGA design. This module implements automated operations through a scripting language, selecting the timing, type, and location of fault injection based on predetermined parameters and design requirements. The fault injection control module uses automated control technology based on scripting languages such as TCL to generate fault injection instructions and import them into the simulation environment of the target FPGA. Commands such as "force -freeze" are used to freeze the state values of key sensitive nodes to achieve soft error simulation. In addition, this module can automatically analyze the netlist structure and identify key nodes in the design, thereby selecting the most sensitive nodes for fault injection.

[0133] The fault injection generation module automatically generates different types of fault injections based on design requirements, including single-event upsets and multiple-event upsets. This module can simulate a variety of soft error scenarios without changing the hardware structure. Based on TCL scripts, this module directly modifies the internal logic states of the FPGA through the simulator. During fault generation, the module automatically identifies sensitive nodes (such as status registers and logic cells) and generates corresponding injection scripts to simulate these soft errors. The "force-freeze" command can be used to control the validity of faults for a specific time period, simulating a variety of scenarios, including single faults and frequent faults.

[0134] The fault mask determination unit has been restructured into a simulation and synthesis module. This module runs the FPGA design in a post-fault simulation environment, analyzing its impact on FPGA system performance and functionality, thereby verifying the reliability of the fault-tolerant design. During the simulation and synthesis phase, the system runs scripts using a simulation model of the FPGA design to evaluate the impact of the fault injection on circuit operation, including resource utilization and timing performance. During the simulation process, the simulation tool generates detailed waveforms based on the injected fault information for subsequent analysis.

[0135] The Fault Injection Module has been restructured into the Automatic Assertion Generation Module. This module generates assertions during simulation to detect whether faults have triggered unusual behavior. Assertion detection can quickly identify potential design flaws and improve verification efficiency. This module embeds pre-set assertion logic into simulation scripts, enabling real-time verification during simulation to ensure that circuit outputs meet expectations. The Automatic Assertion Generation Module supports multiple assertion modes, such as simple logic assertions and counter overflow assertions, allowing for monitoring whether faults have been detected and addressed.

[0136] The error counting unit has been restructured into an error counter module. This module records the number of errors that occur during simulation, enabling quantitative analysis of the impact of fault injection on the FPGA and evaluating the effectiveness of fault-tolerant designs. The error counter module records the number of assertion failures or errors in real time during simulation and outputs this information to a report file. The error counter module supports multiple recording methods, such as by time period and fault type, to facilitate subsequent statistical analysis.

[0137] The FPGA fault injection verification system also includes an analysis and reporting module, a script parsing and automatic scheduling module, a fault injection effect optimization module, a state machine fault tolerance verification module, and a simulation waveform generation and playback module.

[0138] The analysis and reporting module is the system's output unit, responsible for integrating error information and performance parameters recorded during the simulation process to generate a post-fault injection analysis report, providing a basis for further optimization of the FPGA's fault-tolerant design. This module automatically extracts waveform data, assertion records, and error counts from the simulation tool to generate a comprehensive analysis report. The report includes information on resource consumption, timing delays, and error type distribution for the FPGA design under different fault scenarios. The analysis report can be presented in the form of charts and statistical data, allowing designers to quickly understand the fault-tolerant effect and design flaws.

[0139] The script parsing and automated scheduling module parses user-entered parameters and script commands, schedules other modules based on different testing requirements, and flexibly adjusts the fault injection process. This module parses user-entered TCL or Python scripts, identifies parameter settings, and converts them into control signals for each module. It also schedules the entire system's fault injection process, including fault generation, simulation startup, and assertion checking, achieving full process automation.

[0140] After preliminary testing, the fault injection optimization module analyzes whether the injected faults are comprehensive enough. If sensitive nodes are missed or coverage is insufficient, the system automatically adjusts the injection nodes for better fault coverage. By analyzing simulation results, the module identifies potential fault areas that have not been triggered and increases the frequency of fault injection in these areas in subsequent testing. Furthermore, the module dynamically adjusts the injection intensity and timing based on the characteristics of the FPGA design to ensure maximum test coverage.

[0141] In FPGA design, finite state machines are often used in control systems and are extremely sensitive to soft errors. The State Machine Fault Tolerance Verification module is specifically designed to test the fault tolerance of state machines, ensuring they can maintain a safe state in the event of a fault. This module utilizes fault-tolerant encoding methods such as one-hot encoding and gray coding, injects faults via scripts, and then tests the state machine's response in a simulation environment. This module automatically performs state transition analysis to verify that the state machine can recover to a valid state after an error occurs, thereby preventing the system from crashing or entering an undefined state.

[0142] After each fault injection, the simulation waveform generation and playback module generates a waveform file, making it easy to observe the FPGA design's operation after the fault is injected. It also supports playback, helping designers deeply analyze the actual impact of each fault. This module uses the waveform files generated by the simulator to record the waveform changes at each fault node and output them in a visual format. Designers can replay waveforms at specific points in time to intuitively understand the fault's impact and support design improvements.

[0143] In this embodiment, fault injection information is used to inject faults into target nodes in the FPGA in a preset simulation tool to obtain simulation results, and then obtain FPGA verification results. This overcomes the defects of high resource consumption and performance degradation in the existing technology, and efficiently and accurately verifies the fault tolerance capability of the FPGA in high-security applications such as nuclear power plants. The embodiment can be flexibly used in different application scenarios. The interference of soft errors on the FPGA circuit is simulated through fault injection information, and the stability and anti-interference performance of the design are tested in the preset simulation tool. This can ensure the performance and stability of the FPGA fault-tolerant design and meet the reliability requirements of the nuclear power plant system.

[0144] Since the system embodiments generally correspond to the method embodiments, reference will be made to the description of the method embodiments for relevant details. The system embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components of the units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the disclosed solution.

[0145] Example 3

[0146] Figure 5 This is a structural schematic diagram of an electronic device showing an example embodiment of the present disclosure. The electronic device includes a memory, a processor, and a computer program stored in the memory and configured to run on the processor. When the processor executes the computer program, the FPGA fault injection verification method described in any of the above embodiments is implemented. Figure 5 The electronic device 90 shown is only an example and should not limit the functionality and scope of use of the embodiments of the present disclosure.

[0147] like Figure 5 As shown, the electronic device 90 may be a general-purpose computing device, such as a server device. Components of the electronic device 90 may include, but are not limited to, the at least one processor 91, the at least one memory 92, and a bus 93 connecting different system components (including the memory 92 and the processor 91).

[0148] The bus 93 includes a data bus, an address bus, and a control bus.

[0149] The memory 92 may include a volatile memory, such as a random access memory (RAM) 921 and / or a cache memory 922 , and may further include a read-only memory (ROM) 923 .

[0150] The memory 92 may also include a program tool 925 (or utility) having a set (at least one) of program modules 924, such program modules 924 including but not limited to: an operating system, one or more application programs, other program modules and program data, each of which or some combination may include an implementation of a network environment.

[0151] The processor 91 executes various functional applications and data processing by running the computer program stored in the memory 92, such as the FPGA fault injection verification method provided in any of the above embodiments.

[0152] The electronic device 90 can also communicate with one or more external devices 94 (e.g., a keyboard, pointing device, etc.). This communication can occur via an input / output (I / O) interface 95. Furthermore, the electronic device 90 can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 96. As shown, the network adapter 96 communicates with other modules of the electronic device 90 via a bus 93. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 90, including but not limited to microcode, device drivers, redundant processors, external disk drive arrays, RAID (RAID) systems, tape drives, and data backup storage systems.

[0153] It should be noted that although several units / modules or sub-units / modules of the electronic device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more units / modules described above can be embodied in one unit / module. Conversely, the features and functions of one unit / module described above can be further divided and embodied by multiple units / modules.

[0154] Example 4

[0155] An embodiment of the present disclosure further provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the method for verifying fault injection of an FPGA provided in any of the above embodiments is implemented.

[0156] The readable storage medium may include, but is not limited to, a portable disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0157] Example 5

[0158] An embodiment of the present disclosure further provides a computer program product, including a computer program, which, when executed by a processor, implements any of the above-mentioned methods for verifying fault injection in an FPGA.

[0159] The program code for executing the computer program product of the present disclosure may be written in any combination of one or more programming languages, and the program code may be executed entirely on the user device, partially on the user device, as a standalone software package, partially on the user device and partially on a remote device, or entirely on the remote device.

[0160] While specific embodiments of the present disclosure have been described above, those skilled in the art will appreciate that these are merely illustrative and that the scope of protection of the present disclosure is defined by the appended claims. Those skilled in the art may make various changes or modifications to these embodiments without departing from the principles and essence of the present disclosure, and such changes and modifications are intended to fall within the scope of protection of the present disclosure.

Claims

1. A method for verifying fault injection of FPGA, characterized in that: The FPGA is applied to a nuclear power plant system, and the verification method includes: Obtain fault injection information and target nodes in FPGA; Based on the fault injection information, injecting a fault into the target node in a preset simulation tool to obtain a simulation result; Based on the simulation results, the FPGA is verified to obtain a verification result.

2. The FPGA fault injection verification method according to claim 1, wherein: The fault injection information includes at least one of a fault type, a fault injection time, a fault duration, a fault interval, and a number of fault injection times.

3. The FPGA fault injection verification method according to claim 2, wherein: The fault type includes at least one of a single event upset and a multiple event upset.

4. The FPGA fault injection verification method according to claim 1, wherein: The step of obtaining fault injection information and a target node in the FPGA includes: The netlist file corresponding to the FPGA is parsed to obtain the target node.

5. The FPGA fault injection verification method according to claim 1, wherein: The target node includes at least one of a status register and a logic unit.

6. The FPGA fault injection verification method according to any one of claims 1 to 5, characterized in that: The simulation result includes waveform data of the FPGA, and the verification result includes a fault masking result; The step of verifying the FPGA based on the simulation result to obtain a verification result includes: Based on the waveform data, determining whether the FPGA masks the fault corresponding to the fault injection information to obtain the fault masking result; and / or, The simulation result includes an output result of the FPGA, and the verification result includes the number of errors; The step of injecting a fault into the target node in a preset simulation tool based on the fault injection information to obtain a simulation result includes: Based on the fault injection information, injecting a fault into the target node in a preset simulation tool, and setting an assertion to obtain the output result; The step of verifying the FPGA based on the simulation result to obtain a verification result includes: In response to the output result satisfying a preset condition, the errors triggered by the assertion are counted to obtain the number of errors.

7. A fault injection verification system for FPGA, characterized in that: The FPGA is applied to a nuclear power plant system, and the verification system includes: Fault information acquisition module, used to obtain fault injection information; A target node acquisition module is used to obtain the target node in the FPGA; A fault injection module, configured to inject a fault into the target node in a preset simulation tool based on the fault injection information to obtain a simulation result; A verification module is used to verify the FPGA based on the simulation result to obtain a verification result.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and configured to run on the processor, wherein: When the processor executes the computer program, the FPGA fault injection verification method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the FPGA fault injection verification method according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method for verifying fault injection in an FPGA according to any one of claims 1 to 6 is implemented.