Testing hybrid security system

By detecting criteria and performing tests in different states of the ECU, the problem of safety application test interference during the rapid recovery of hybrid safety ECU is solved, ensuring the rapid recovery and safety of the vehicle, and improving the driving experience.

CN120476386APending Publication Date: 2025-08-12QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380090207.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-01-10
Filing Date
2023-12-29
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, during the rapid recovery or boot process of the vehicle key after the hybrid safety ECU is opened, the testing and initialization of the safety application may interfere with the rapid recovery delay of non-safe applications, affecting the driving experience and safety.

Method used

Provided is a method and device to enable rapid recovery of safe and non-safe applications by performing tests when the ECU is in different states to detect that the criteria are met, ensuring that BIST is performed when the vehicle is not in use or when powered off, storing the test results, and checking the next time the power is on, achieving rapid recovery of safe and non-safe applications.

Benefits of technology

Achieve rapid recovery or boot time after the vehicle key is turned on while ensuring operational integrity of safe and non-safe applications, improving driving experience and safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120476386A_ABST
    Figure CN120476386A_ABST
Patent Text Reader

Abstract

Aspects of the present disclosure provide techniques and apparatus for testing a hybrid safety system, such as a system included in a vehicle. An example method of operating a vehicle includes: operating an electronic control unit (ECU) in a first state; detecting that one or more criteria are satisfied to perform a test associated with the ECU; and when the ECU is in a second state different from the first state, performing the test associated with the ECU in response to detecting that the one or more criteria are satisfied.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of and priority to U.S. patent application No. 18 / 152,222, filed on January 10, 2023, which is hereby incorporated by reference in its entirety. Background Art Technical Field

[0003] Certain aspects of the present disclosure relate generally to electronic components and, more particularly, to a system on a chip (SoC) with hybrid security functionality.

[0004] Related technologies

[0005] Over the past few years, automobiles have been transformed from self-propelled mechanical vehicles into powerful and complex electromechanical systems that include a large number of sensors and processors that control many functions, features, and operations of the vehicle. The vehicle may be equipped with a vehicle control system that may be configured to collect and use information from various systems and sensors of the vehicle to automate all or part of the operation of the vehicle. For example, an advanced driver assistance system (ADAS) may automate, adapt, or enhance the operation of the vehicle. ADAS may use information collected from sensors (e.g., accelerometers, radars, lidars, geospatial positioning, etc.) to automatically detect potential road hazards and assume control of all or part of the operation of the vehicle (e.g., braking, steering, etc.) to avoid detected hazards. Features and functions typically associated with ADAS include adaptive cruise control, automatic lane detection, lane departure warning, automatic steering, automatic braking, and automatic collision avoidance. Summary of the Invention

[0006] The systems, methods, and devices of the present disclosure each have several aspects, no single aspect of which is solely responsible for its desirable properties. Without limiting the scope of the present disclosure as expressed by the claims that follow, some features will now be briefly discussed. After considering this discussion, and particularly after reading the section entitled "Detailed Description," one will understand how the features of the present disclosure provide the advantages described herein.

[0007] Certain aspects of the present disclosure provide a method of operating a vehicle. The method generally includes: operating an electronic control unit (ECU) in a first state; detecting satisfaction of one or more criteria for executing a test associated with the ECU; and, when the ECU is in a second state different from the first state, executing the test associated with the ECU in response to detecting satisfaction of the one or more criteria.

[0008] Certain aspects of the present disclosure provide an apparatus for operating a vehicle. The apparatus generally includes an ECU. The ECU is configured to operate in a first state, detect satisfaction of one or more criteria to execute a test associated with the ECU, and, when the ECU is in a second state different from the first state, execute the test associated with the ECU in response to detecting satisfaction of the one or more criteria.

[0009] Certain aspects of the present disclosure provide an apparatus for operating a vehicle. The apparatus generally includes: means for operating an ECU in a first state; means for detecting that one or more criteria are satisfied to execute a test associated with the ECU; and means for executing the test associated with the ECU in response to detecting that the one or more criteria are satisfied when the ECU is in a second state different from the first state.

[0010] Certain aspects of the present disclosure provide a computer-readable medium having stored thereon instructions for causing an electronic control unit (ECU) to operate in a first state; detecting satisfaction of one or more criteria to perform a test associated with the ECU; and performing the test associated with the ECU in response to detecting satisfaction of the one or more criteria when the ECU is in a second state different from the first state.

[0011] To achieve the foregoing and related ends, one or more aspects include the features fully described below and particularly pointed out in the claims. The following description and the accompanying drawings set forth in detail certain illustrative features of these one or more aspects. However, these features are indicative of only some of the various ways in which the principles of the various aspects can be employed. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order that the manner in which the above-mentioned features of the present disclosure are understood in detail, a more particular description, briefly summarized above, may be obtained by reference to various aspects, some of which are illustrated in the accompanying drawings. It should be noted, however, that the drawings illustrate only certain aspects of the present disclosure and are therefore not to be considered limiting of its scope, as the description may admit to other equally effective aspects.

[0013] Figure 1 is a diagram of an example vehicle with a vehicle control system.

[0014] Figure 2 is a block diagram of example components and interconnections in a system on a chip (SoC).

[0015] Figure 3 is a block diagram of an example SoC-based electronic control unit (ECU) in communication with one or more other ECUs.

[0016] Figure 4is an example timeline illustrating opportunistic execution of tests in a test state associated with an ECU.

[0017] Figure 5 is a flow chart depicting example operations for testing an ECU.

[0018] To facilitate understanding, identical reference numerals have been used, where possible, to designate identical elements that are common to the figures. It is contemplated that elements disclosed in one aspect may be beneficially utilized on other aspects without specific recitation. DETAILED DESCRIPTION

[0019] Certain aspects of the present disclosure relate to methods and apparatus for performing tests associated with a system on a chip (SoC).

[0020] Some vehicles are equipped with multiple features for safety, navigation, entertainment, etc., such as advanced driver assistance systems (ADAS), autonomous driving (AD) and / or in-vehicle infotainment (IVI). Some vehicles are able to sense other vehicles and / or objects on the road and / or communicate with other vehicles and / or objects on the road, which allows for improved predictive safety features and AD. IVI is no longer just for entertainment purposes and can ideally work closely with safety features (including ADAS), especially when some vehicles are equipped with AD capabilities. As the automotive industry transitions to AD vehicles, ADAS is merged with IVI. Merging ADAS and IVI will improve driving safety and improve the overall driving experience. In other words, as the driving experience becomes autonomous, the demand for both passenger safety and entertainment increases.

[0021] Safety systems (e.g., certain ADAS and / or AD systems) may perform built-in self-test (BIST) to ensure the operational integrity of certain electrical components, such as memory, processors, control logic, power management circuits, voltage regulators, and the like. ADAS and / or AD systems offer overall improved driver and passenger safety, but malfunction of these systems could potentially harm passengers or bystanders. For example, BIST may be performed at system power-up to check the structural integrity of flip-flops, gates, and memory cells. Safety and automotive SoCs may initiate and perform such BIST at system power-down, system power-up, or a combination of both. SoC safety mechanisms (e.g., memory error detection circuitry) can be tested for correct operation during system boot time using techniques such as fault injection. Such testing can increase overall boot time, particularly as SoCs increase in complexity and / or functionality. More safety subsystems within the SoC may require testing to verify the operation of the safety subsystems and mechanisms during system boot and initialization. Safety hardware can be tested and checked before running safety applications to ensure the absence of random hardware failures that could impact safety operations. Measures for detecting such faults are designed according to a specific Automotive Safety Integrity Level (ASIL), for example, according to functional safety standards such as ISO 26262 provided by the International Organization for Standardization (ISO).

[0022] Automotive computing architectures are becoming increasingly centralized into multi-function SoC architectures. For example, certain safety features (e.g., ADAS and / or AD) and certain non-safety features (e.g., IVI) may be merged into a single centralized electronic control unit (ECU), such as the one described herein with respect to Figure 2 A centralized ECU can have safety applications and non-safety applications coexisting on the same ECU hardware and software platform. Such a centralized ECU can be called a hybrid safety ECU or SoC.

[0023] Non-safety applications on a hybrid safety ECU can be expected to resume or boot very quickly (e.g., on the order of a few hundred milliseconds) after the user performs a vehicle key-on action. For example, the ECU can quickly resume operation of smartphone integration and features (e.g., Android Auto and / or Apple CarPlay), vehicle comfort controls and displays, etc. Very fast boot and resume latency (e.g., less than 1 or 2 seconds) can be achieved by resuming from a suspended state (e.g., suspending to random access memory (RAM)), where the context is saved after the first complete boot cycle and then a fast resume from RAM is performed.

[0024] Safety applications on a hybrid safety ECU can be expected to recover or boot within a specified time after the user performs the vehicle key-on action. Certain safety applications (e.g., a rearview camera display) may be specified (by regulation or industry standards) to be available to the driver for a certain duration (e.g., two seconds) from the time the vehicle key is turned on. For example, in the United States, Federal Motor Vehicle Safety Standard (FMVSS) No. 111: Rearview Mirror Visibility Requirements specifies that the rearview image be displayed within two seconds after the vehicle's direction selector is placed in reverse. In some cases, ADAS and / or AD applications supporting autonomous driving may respond within two seconds. Because ADAS and / or AD systems may undergo BIST and other safety checks at power-up or initialization, such tests can interfere with the fast boot and recovery latency of the hybrid safety ECU.

[0025] Various aspects of the present disclosure provide methods and apparatus for performing tests associated with a SoC (such as a hybrid safety ECU). For example, the SoC may perform certain tests (e.g., BIST and check BIST operations) periodically (e.g., every 24 hours or after a certain number of actions (e.g., key-on actions) have been performed). For example, the SoC may perform tests when the vehicle is not in use or in response to the vehicle being turned off, and the SoC may store the test results in memory for review at the next key-on action. The SoC may resume from a suspended state (e.g., suspend to RAM state) to achieve fast boot times for both secure and non-secure applications. It should be understood that the methods and apparatus described herein for performing tests associated with a hybrid safety ECU are merely examples of a test framework. Various aspects of the present disclosure may be further designed and / or implemented under the guidance of the original equipment manufacturer (such as when and how often certain tests (including BIST) will be performed) based on certain system safety concepts and / or objectives of the manufacturer.

[0026] The methods and apparatus described herein for performing tests associated with a SoC provide various advantages. The methods and apparatus described herein can achieve fast recovery or boot times and ensure operational integrity of hardware and / or software running secure and non-secure applications.

[0027] Example Vehicle Control System

[0028] Figure 11 is a block diagram of an example vehicle 100 including a vehicle control system 102 and various sensors suitable for controlling certain systems such as ADAS, AD and / or IVI. Vehicle 100 may refer to a component that carries or transports something (e.g., people or goods). In some aspects, vehicle 100 may represent a motor vehicle, such as a car, van, truck, semi-trailer truck, motorcycle, moped, electric bicycle, etc. Vehicle 100 may be a mass-produced road vehicle with a safety-related system including one or more electrical and / or electronic systems, as further described herein. Vehicle 100 may be propelled using an internal combustion engine, an electric motor, or a hybrid propulsion system (e.g., a combination of an engine and an electric motor). In some cases, vehicle 100 may have one or more electrical and / or electronic systems that comply with certain functional safety standards (such as ISO 26262 provided by the International Organization for Standardization (ISO)).

[0029] The vehicle control system 102 may include one or more computing devices having a SoC (eg, one or more ECUs), as described herein with respect to Figure 2 and Figure 3 The vehicle control system 102 may be coupled to various vehicle systems and subsystems, such as an environmental system 104 (e.g., an air conditioning and / or heating system), a navigation system 106, a communication and / or infotainment system 108, a power control system 110, a powertrain control system 112, a driver assistance and / or autonomous driving control system 114, and / or various sensors 116. Each of the vehicle systems and sensors 102-116 may communicate with one or more other systems via one or more communication links, which may include wired communication links (e.g., a controller area network (CAN) protocol-compatible bus, a universal serial bus (USB) connection, an Ethernet connection, a universal asynchronous receiver-transmitter (UART), etc.) and / or wireless communication links (e.g., link, link, link, link, etc.).

[0030] The vehicle control system 102 can perform certain operations associated with any of the vehicle systems and subsystems. For example, the vehicle control system 102 can control or initiate a power-on and / or shutdown sequence for any of the vehicle systems and subsystems. The vehicle control system 102 can monitor errors associated with any of the vehicle systems and subsystems, and in some cases, the vehicle control system 102 can store the errors for vehicle diagnostics. In response to any detected errors, the vehicle control system 102 can perform certain actions, such as shutting down the affected system or transferring some of the affected operations to be performed at a different vehicle system. The vehicle control system 102 can monitor the power level supplied to any of the vehicle systems and subsystems and ensure that the supplied power level meets the operating specifications of any of the vehicle systems and subsystems.

[0031] The environmental system 104 can control the cooling and / or heating systems associated with the vehicle 100. For example, the vehicle 100 may have an air conditioning system, a heating system, heated or cooled seats, and / or a heated steering wheel; and the environmental system 104 can adjust the temperature according to the user (or default) settings of the corresponding cooling and / or heating components. The navigation system 106 can show the location of the vehicle on a map and provide navigation information, such as directions to a destination, via a display (not shown).

[0032] The communication and / or infotainment system 108 may allow the user to access various information (e.g., navigation information, interior or exterior environment information, ADAS information, etc.), applications, and / or entertainment or media content, such as music and / or videos. The communication and / or infotainment system 108 may allow the user to update or access settings associated with various systems (e.g., the environment system 104, the navigation system 106, ADAS, vehicle settings, etc.). The communication and / or infotainment system 108 may allow the user and / or vehicle 100 to communicate wirelessly via the vehicle's integrated modem or via the user's wireless communication device (e.g., a smartphone or tablet).

[0033] The power control system 110 can control the output power to move components of the vehicle, such as the internal combustion engine (e.g., adjusting the air-fuel ratio, boost pressure, valve timing, etc.), the electric power system (e.g., controlling regenerative braking, battery power output, battery charging, and / or battery cooling, etc.), and / or the hybrid power system (e.g., controlling regenerative braking, switching between battery power and engine power, battery charging, battery cooling, etc.). The powertrain control system 112 can control various components of the vehicle 100 that deliver power to the drive wheels. For example, the powertrain control system 112 can control gear shifting in an automatic transmission. For a four-wheel drive vehicle, the powertrain control system 112 can control the ratio of power applied to the front and rear drive wheels.

[0034] The driver assistance and / or autonomous driving control system 114 may control various driver assistance features and functions, such as adaptive cruise control, automatic lane detection, lane departure warning, automatic steering, automatic braking, and automatic collision avoidance. The driver assistance and / or autonomous driving control system 114 may control autonomous driving at various levels of automation, such as any of Society of Automotive Engineers (SAE) levels 1 to 5.

[0035] The various sensors 116 coupled to the vehicle control system 102 may include any of the following: a vehicle's speedometer, wheel speed sensors, torque meters, turbine speed sensors, variable reluctance sensors, sonar systems, radar systems, air-fuel ratio meters, water-in-fuel sensors, oxygen sensors, crankshaft position sensors, curb detectors, temperature sensors, Hall effect sensors, manifold absolute pressure sensors, various fluid sensors (e.g., engine coolant sensors, transmission fluid sensors, etc.), tire pressure monitoring sensors, mass air flow sensors, speed sensors, blind spot monitoring sensors, parking sensors, cameras, microphones, accelerometers, compasses, global navigation satellite system (GNSS) receivers (e.g., global positioning system (GPS) receivers or Galileo receivers), and other similar sensors for monitoring physical or environmental conditions in and around the vehicle.

[0036] The foregoing systems are presented as examples only, and the vehicle may include one or more additional systems that are not illustrated for clarity. Additional systems may include systems related to additional other functions of the vehicle systems, including instrumentation, air bags, cruise control, other engine systems, stability control parking systems, tire pressure monitoring, anti-lock brakes, active suspension, battery charge and / or management, and various other systems.

[0037] Example System-on-Chip

[0038] The term "system on a chip" (SOC) is used herein to refer to a single integrated circuit (IC) chip that includes multiple resources and / or processors integrated on a single substrate or in a single package. A single SoC may include circuits for digital, analog, mixed-signal, and radio frequency functions. A single SOC may also include any number of general-purpose and / or specialized processors (digital signal processors, modem processors, video processors, etc.), memory blocks (e.g., ROM, RAM, flash memory, etc.), and resources (e.g., timers, voltage regulators, oscillators, etc.). The SoC may also include software for controlling the integrated resources and processors and for controlling peripheral devices.

[0039] Figure 2 is a block diagram of example components and interconnects in a system on a chip (SoC) 200 suitable for implementing various aspects of the present disclosure. The SoC 200 may include multiple processing domains including, for example, a primary domain 202a and a safety domain 202b (also referred to as a "safety island (SAIL)"). The primary domain 202a may be configured to support (or be capable of performing) vehicle operations (e.g., driver assistance and / or autonomous driving operations, features, etc.) up to a particular automotive safety integrity level (ASIL), and the safety domain 202b may be configured to support (or be capable of performing) vehicle operations up to a lower, the same, or a higher ASIL than the primary domain 202a. For example, the primary domain 202a may be configured to support (or be capable of performing) vehicle operations up to ASIL B, and the safety domain 202b may be configured to support vehicle operations up to ASIL D. In some cases, the primary domain 202a may be configured to support (or be capable of performing) vehicle operations up to ASIL A, ASIL B, ASIL C, or ASIL D, and the safety domain 202b may be configured to support vehicle operations up to an ASIL different from that of the primary domain 202a. In some cases, the primary domain 202a and the safety domain 202b may be configured to support (or be capable of performing) vehicle operations at the same ASIL (e.g., ASIL D). The primary domain 202a and the safety domain 202b may be configured to support (or be capable of performing) vehicle operations at different ASILs.

[0040] ASILs can be defined in specific safety standards, such as ISO 26262. For example, ASILs can provide a risk classification scheme for certain electrical and electronic systems in road vehicles. ISO 26262 provides four ASILs, including ASIL A, ASIL B, ASIL C, and ASIL D. ASIL D is the highest classification and corresponds to the highest level of safety measures for avoiding unreasonable residual risks, while ASIL A is the lowest classification and corresponds to the lowest level of safety measures.

[0041] In some aspects, the SoC 200 may be included in a computing device (eg, an ECU) in a vehicle control system. The SoC 200 may control the vehicle control system. Figure 1 For example, SoC 200 may be configured to control an ADAS / AD system, such as that described herein with respect to Figure 1 The driver assistance and / or autonomous driving control system 114 described herein. In certain aspects, the SoC 200 can communicate with other ECUs in the vehicle control system, such as those described herein with respect to Figure 3 For example, the primary domain 202a may control environmental systems, infotainment systems, and driver assistance features up to a certain ASIL; and the safety domain 202b may control driver assistance features up to a certain ASIL, which may generally be higher than the primary domain 202a.

[0042] The primary domain 202a and / or the secure domain 202b may include multiple heterogeneous processors 204a-204c (collectively, processors 204), such as a central processing unit (CPU) 204a, a signal processor or other specialized processor 204b (e.g., a digital signal processor, an image signal processor, a neural network signal processor, a computer vision processor, a graphics processing unit (GPU), etc.), and / or an application processor 204c. Each processor 204 may include one or more cores, and each processor / core may perform operations independently of the other processors / cores. Each processor 204 may be part of a subsystem (not shown) that includes one or more processors, caches, etc. configured to handle certain types of tasks or computations. It should be noted that the primary domain 202a and / or the secure domain 202b may include additional processors (not shown) or may include fewer processors (not shown). The primary domain 202a and / or the secure domain 202b may include other processors (e.g., a graphics processing unit, a vision processing unit, etc.) in addition to or in place of those illustrated.

[0043] The primary domain 202a and / or the secure domain 202b may include system components and resources 206 for performing certain specialized operations, such as analog-to-digital conversion and / or wireless data transmission. The system components and resources 206 may include components such as voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, system controllers, access ports, timers, and other similar components for supporting the processors and software clients running on the SoC 200. The system components and resources 206 may include circuitry for interfacing with peripheral devices, such as cameras, electronic displays, wireless communication devices, external memory chips, and the like.

[0044] The primary domain 202a and / or the secure domain 202b may also include a power management controller 208, a memory controller 210 (e.g., a dynamic random access memory (DRAM) memory controller and / or a non-volatile memory controller), a sensor controller 212, and / or a driver assistance controller 214. The primary domain 202a and / or the secure domain 202b may also include an input / output (IO) module (not shown) for communicating with resources external to the SoC (such as clocks and voltage regulators), each of which may be shared by two or more of the internal SoC components. For example, the IO module may include a general purpose IO (GPIO) interface. In some aspects, each of the primary domain 202a and the secure domain 202b may have a separate clock to facilitate independent operability.

[0045] The processor 204 of the master domain 202a can be interconnected to the system components and resources 206, the power management controller 208, the memory controller 210, the sensor controller 212, the driver assistance controller 214, other system components and / or the security domain 202b via an interconnect / bus module 216, which can include a reconfigurable logic gate array and / or implement a bus architecture (e.g., CoreConnect, Advanced Microcontroller Bus Architecture (AMBA), etc.). Communication can be provided by a high-level interconnect such as a high-performance network on chip (NoC).

[0046] The interconnect / bus module 216 may include or provide a bus mastering system that is configured to grant an SoC component (e.g., a processor, a peripheral device, etc.) exclusive control of the bus (e.g., to transfer data) for a set duration, number of operations, number of bytes, etc. In some aspects, the bus module 216 may include a direct memory access (DMA) controller (not shown) that enables a component connected to the bus module 216 to operate as a master and initiate memory transactions. The bus module 216 may implement an arbitration scheme to prevent multiple masters from attempting to drive the bus simultaneously.

[0047] The power management controller 208 may manage power supplied to the primary domain 202a from the PMIC 218, which may represent one or more PMICs. Power management may be separate and independent between the primary domain 202a and the secure domain 202b.

[0048] The memory controller 210 may be a dedicated hardware module configured to manage data flow to and from the memory 220. The memory controller 210 may include logic components for interfacing with the memory 220, such as selecting a row and column corresponding to a memory location in a cell array of the memory 220, reading or writing data to a memory location, etc. The memory 220 may be an on-chip component of the SoC 200 (e.g., on a substrate, die, integrated chip, etc.), or alternatively (as shown) an off-chip component.

[0049] The sensor controller 212 may manage sensor data received from various sensors 222, such as the sensor 116. The sensor controller 212 may include circuitry for interfacing with the sensors 222. For example, the sensor controller 212 may receive sensor data from a tire pressure monitoring system and / or a radar sensor for adaptive cruise control.

[0050] The driver assistance controller 214 may control certain driver assistance functions via the driver assistance module 224 (e.g., one or more actuators, relays, switches, etc.). For example, the driver assistance controller 214 may control adaptive cruise control by controlling actuators coupled to the engine and / or braking system. In some cases, the driver assistance controller 214 may perform automatic steering by controlling actuators attached to the steering system. It should be understood that the driver assistance controller 214 is merely an example, and that the primary domain 202a and / or the safety domain 202b may include controllers that interface with the autonomous driving components in addition to or in place of the driver assistance controller 214.

[0051] SoC 200 may also include additional hardware and / or software components suitable for collecting sensor data from sensors, including speakers, user interface elements (e.g., input buttons, touch screen display, etc.), microphone arrays, sensors for monitoring physical conditions (e.g., position, direction, motion, orientation, vibration, pressure, temperature, etc.), cameras, compasses, GPS receivers, communication circuits (e.g., Wireless Local Area Network (WLAN), Long Term Evolution (LTE), Fifth Generation New Radio (5G NR), etc.) and other well-known components of modern electronic devices (e.g., accelerometers, etc.).

[0052] Each of the processing domains can operate independently of the other domains. In some cases, each of the processing domains can be coupled to separate and independent external resources, such as PMICs, memories, sensors, and driver assistance modules. Specific external resources can be designed based on the ASIL corresponding to the specific ASIL associated with the primary domain 202a and / or safety domain 202b to which the external resources are coupled. For example, the PMIC 218 can have the same ASIL as the primary domain 202a, and the PMIC that provides power to the safety domain 202b can have the same ASIL as the safety domain 202b. The safety domain 202b can include the same or different processing resources and components as the primary domain 202a, as described herein with respect to the primary domain 202a. For example, the safety domain 202b can include a processor 204, system components and resources 206, a power management controller 208, a memory controller 210, a sensor controller 212, and a driver assistance controller 214. The safety domain 202 b may be coupled to certain external resources 226 , which may represent, for example, a PMIC, memory, sensors, and / or driver assistance modules, as described herein with respect to the primary domain 202 a .

[0053] In addition to the SoC 200 discussed above, various aspects may be implemented in a wide variety of computing systems that may include a single processor, multiple processors, multi-core processors, or any combination thereof.

[0054] Example testing hybrid safety system

[0055] Figure 3 is a block diagram of an example SoC-based ECU 300a in communication with one or more other ECUs 300b. In this example, the ECU 300a and the other ECUs 300b may operate in a vehicle control system and / or any vehicle system or subsystem as described herein with respect to Figure 1 As described. ECU 300a may perform some vehicle control operations (e.g., infotainment, environment, ADAS, etc.); and other ECU 300b may perform some vehicle control operations (e.g., full system control, engine control, powertrain control, other ADAS features, etc.). For example, ECU 300a may be a hybrid safety ECU, such as having a primary domain 202a and a safety domain 202b. ECU 300a may include SoC 200 and corresponding external resources (not shown), as described herein with respect to Figure 2 In some aspects, the other ECU 300b may include a SoC-based ECU, such as SoC 200 and corresponding external resources, as described herein with respect to Figure 2 described.

[0056] The primary domain 202a may have a non-safety subsystem 330 that executes a non-safety application (app) 332 (e.g., an IVI application such as climate control). In some cases, the primary domain 202a may have a safety subsystem 334a that executes another non-safety application 336 (e.g., an IVI application such as an audio system) and a safety application 338 (e.g., an ADAS application such as blind spot monitoring). The safety domain 202b may have safety subsystems 340a, 340b (collectively referred to as safety subsystems 340), wherein the first safety subsystem 340a may execute a first safety application 342 (e.g., an ADAS application such as an adaptive cruise control system), and the second safety subsystem 340b may execute a second safety application 344 (e.g., an ADAS application such as lane departure warning and / or correction) and a non-safety application 346 (e.g., an IVI application such as smartphone integration). It should be understood that subsystems 330, 334, 340 are merely examples of hybrid safety systems where one or more specific domains of an ECU may be responsible for executing both safety and non-safety applications. Figure 3 Other subsystem architectures distributed across the primary domain 202a and / or the secure domain 202b may be used in addition to or in place of those illustrated in FIG.

[0057] In some cases, the safety subsystem and corresponding safety applications may perform safety-critical (e.g., life-critical) functions or features, where a failure or malfunction associated with the safety subsystem and / or safety application may result in a violation of a safety goal, death or serious injury to a person (e.g., a driver, operator, or passenger), loss of or serious damage to property, or environmental harm. The safety goals may include top-level safety standards or requirements that are the result of a hazard analysis and risk assessment at the vehicle level.

[0058] In certain aspects, the ECU 300a may include a test module 348 that performs tests on any of the various subsystems 330, 334, and 340. Faults in electrical or electronic components may occur for a variety of reasons. The tests described herein may allow for timely (and proactive) detection of such faults by safety mechanisms, allowing the driver to be alerted so as not to rely on ADAS features or systems that have been detected to be malfunctioning, or for the system to enter another safe state to avoid danger. For example, the test module 348 may perform a BIST on any of the various subsystems 330, 334, and 340. The test module 348 may perform a BIST on any of the various electrical components (not shown) of the subsystems 330, 334, and 340 (such as memory (e.g., memory controller 210 and / or memory 220), processor (e.g., processor 204), control logic, power management circuitry (e.g., power management controller 208 and / or PMIC 218), voltage regulators, etc.). The test module 348 may also perform tests on any of the various software components or modules (such as testing certain software applications (ADAS applications), algorithms (e.g., common calculations), other software components (e.g., device drivers, operating systems, etc.) to ensure correct operation. The test module 348 may perform tests to verify the operational integrity of the BIST, for example, by injecting faults into the BIST. For example, the test module 348 may confirm that the BIST is operating correctly by injecting known failures and / or known successes into the BIST and verifying that the failures or successes are output or reported.

[0059] In various aspects, the test module 348 may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device (PLD), discrete logic components (e.g., gate or transistor logic components), discrete hardware components (e.g., comparators, digital-to-analog converters, multiplexers, etc.), or any combination thereof designed to perform the functions associated with executing the tests described herein. In some aspects, the test module 348 may be integrated with another component, such as the processor 204, the power management controller 208, the memory controller 210, the sensor controller 212, and / or the driver assistance controller. In some aspects, the test module 348 may include computer-executable code that, when executed by a processor, causes the processor to perform the tests described herein. In some aspects, the test module 348 may represent one or more circuits, circuit packages, circuit boards, and / or software modules or packages. The test module 348 may represent multiple hardware and / or software components included in the ECU 300a.

[0060] To ensure fast booting in response to a key-on action (or another action), the ECU 300a can be resumed from a suspended state (e.g., suspended to RAM (STR) state) of the non-safety applications 332, 338 and / or the safety application 336 on the hybrid safety ECU. Resuming from the suspended state can allow the ECU 300a to resume within an expected duration (e.g., a few hundred milliseconds) from the key-on action. Resuming from the suspended state can achieve fast resume or boot time, and performing the tests described herein can ensure the operational integrity of the hardware and / or software running the safety and non-safety applications.

[0061] When the vehicle is in a specific test state, the ECU 300a can opportunistically perform tests (e.g., BIST for logic, memory, and / or other electrical components) at certain times. For example, the test state may include when the vehicle is not in use, when the vehicle is stationary (or not moving or parked), when the vehicle is powered off (turned off or transitioned to a suspended state in response to a key-off action), when the vehicle is in a shut-off state, when the vehicle is being refueled or recharged, or at a certain time of day (e.g., at certain times when the vehicle is not moving, such as when parked at home at night or at work during the day).

[0062] Opportunistic testing enables the proper initialization of both safety and non-safety contexts (including hardware and software) to be executed on the same vehicle ECU following a vehicle key-on event or while the vehicle is operationally enabled for driving. Opportunistic testing enables low-latency restoration of system context stored in memory while ensuring that functional safety-related checks and initialization are performed to detect (random) hardware or software failures in the system. In some cases, whenever the vehicle or ECU 300a is powered down or transitioning to a suspended state, the ECU 300a may perform tests (e.g., BIST) during a context preservation phase. The ECU 300a can ensure that the vehicle is in a test state by waiting for a certain period of time after the driver performs a key-off action. After initiating a test sequence during power-down, the ECU 300a can achieve a point of no return. For example, the ECU 300a may avoid responding to a key-on action while executing the BIST, or wait until the BIST is complete to trigger vehicle power-on.

[0063] When the vehicle is in a test state, the ECU 300a may execute a test in response to meeting certain criteria (such as the expiration of a timer and / or the matching of a counter with a threshold), wherein the timer and / or counter may be reset when the test is executed. For example, the timer may be restarted when the test is executed, and the counter may be set to an initial value (e.g., zero) when the test is executed. In some cases, the ECU 300a may execute the test periodically (e.g., every time interval, such as a multi-point fault detection interval (MPFDI)). The timer interval or duration may be, for example, 24 hours, or may be configured by the safety expectations of the vehicle's original equipment manufacturer (OEM). The timer interval or duration may be referred to as the MPFDI. The ECU 300a (or other ECU 300b) may track the last test execution cycle performed via a timer and / or counter set relative to the last test performed. In some aspects, the ECU 300a may ensure that the vehicle is in a test state, such as by waiting for an additional time interval (e.g., 1 to 2 seconds) before initiating the test. The ECU 300a may wait a dwell counter or timer for a time interval (eg, 1 to 2 seconds or a configurable duration) to ensure that the driver does not perform an immediate key-on (after key-off).

[0064] Since the ECU 300a can resume from the suspended state after performing the test, the ECU 300a can store the test results (e.g., BIST pass or fail) in a non-volatile memory (e.g., memory 220) or provide the test results to another ECU 300b. The ECU 300a can store the test results before transitioning to the suspended state. The ECU 300a can save the BIST status (e.g., pass or fail) and detailed BIST test results in memory for ECU 300a to retrieve during context restoration (e.g., during the next power-on cycle of the ECU 300a). Subsequently, during the next key-on (power-on) cycle, the ECU 300a can check the test results to ensure that there are no faults (such as transient or permanent faults detected by the BIST test). If an error is detected during the test, the ECU 300a can perform any of a variety of actions. In some cases, the ECU 300a may treat the detected error as a permanent error and not perform additional testing. In some cases, the ECU 300a may perform additional testing while the vehicle is still in a test state (e.g., stationary, unused, or powered off) or in a subsequent test state. If an error is detected, the ECU 300a may rerun the BIST to confirm the validity of the test results. The additional testing can ensure that the detected fault is not transient in nature, but rather a permanent fault. Since the fault was detected in the test state, upon resuming from the suspend state, if the vehicle discovers a fault based on the saved BIST test data, the vehicle may perform BIST testing to eliminate the permanent fault. In this case, the vehicle may not offer the flexibility or option to postpone such testing further until the power-off phase, as this could be dangerous.

[0065] In certain aspects, upon detecting a fault, ECU 300a may prevent the vehicle from booting, operating, or executing certain features or applications, such as ADAS, AD, or other applications, upon the next key-on activation (e.g., power-on). In some cases, ECU 300a may notify other ECUs 300b that a fault has been detected at ECU 300a and that ECU 300a will prevent the vehicle from operating or executing certain features due to the fault. Other ECUs 300b may perform any of a variety of actions, such as those configured by the OEM. Other ECUs 300b may determine a response to the detected fault based on the OEM's safety policy. For example, other ECUs 300b may display an error indication to a user or operator, or other ECUs 300b may take over execution of some of the features previously executed by ECU 300a. In certain cases, upon detecting a fault, ECU 300a (and / or other ECUs 300b) may notify an entity, such as the OEM or a vehicle maintenance service, of the fault. For example, upon detecting a permanent fault, ECU 300a (and / or other ECUs 300b) may notify the OEM via a wireless communication network (e.g., cellular communication). The OEM may initiate and perform remote safety diagnostics for any potential recovery procedures. The OEM may perform remote diagnostics for possible recovery procedures.

[0066] If an error or fault (e.g., an uncorrectable error or fault) is detected during vehicle runtime (e.g., outside of a test state, while the vehicle is moving), the ECU 300a (and / or the other ECUs 300b) may undergo specific actions based on the OEM's safety policy, including shutting down, resetting, or transitioning to a safe state, such as a semi-operational state in which the ECU 300a performs limited tasks (e.g., refraining from performing any safety functions due to the fault or fault). The ECU 300a (and / or the other ECUs 300b) may, for example, perform minimal risk operations based on the system safety concept designed by the OEM. In this case, since the error may be permanent, the ECU 300a may not be allowed to enter a suspended state (e.g., STR) and / or resume from a suspended state, and instead, the ECU 300a may undergo a reset or transition to a safe or semi-operational state. In the event that a reboot or BIST cycle is to be performed in response to the detected fault, the ECU 300a may transition to a context save or restore process. Performing a full system boot (rather than resuming from a suspend state) and safe initialization (including BIST) after a fault is detected allows verification of whether the fault is permanent or resolved due to a reboot.

[0067] In response to detecting an error or fault during vehicle operation, the ECU 300a may perform certain tests (e.g., BIST) during the next test state without waiting for a timer to expire and / or a counter to reach a threshold. The ECU 300a may be allowed to enter a suspended state (e.g., STR) if the test passes (e.g., successfully undergoes the test without any failures). If the test has any failures or detects any faults or errors, the ECU 300a may perform any of the various actions described previously herein with respect to detecting an error or fault.

[0068] When resuming from a suspended state (e.g., STR), the ECU 300a may perform any of certain safety checks before executing any safety applications (e.g., ADAS or AD features). The ECU 300a may perform a safety recovery process (e.g., performing certain safety checks) to achieve proper safety initialization and reconfiguration of the SoC 200 when restoring the safety and non-safety contexts from memory. Until the safety checks are completed and successful, the ECU 300a may remain in a suspended state or operate in a semi-operational state (e.g., running non-safety applications in the primary domain 202a), and the ECU 300a may be prevented from executing any safety applications (e.g., safety applications 336a, 336b). The ECU 300a may check the correct operation of certain safety computing subsystems, safety interfaces, and / or safety communication channels. The ECU 300a may evaluate the results of tests (e.g., BIST) performed in the test state as described herein.

[0069] The secure computing subsystem may execute a set of (randomized) challenge-response computational problems (e.g., computations) to ensure that the secure computing subsystem can read data or instructions from memory and perform computations. The secure computing subsystem may, for example, check the correct operation of error correction codes (ECCs) associated with memory (e.g., corresponding memory 220 of secure domain 202b) via fault injection. The secure computing subsystem may include any of the processors associated with secure domain 202b, such as corresponding processor 204, an application processor, a neural network signal processor (NSP), a GPU, a computer vision processor (CVP), and the like.

[0070] ECU 300a can output and receive test signals or patterns on any of the safety interfaces, for example, via loopback. The safety interface can include any of the communication interfaces associated with security domain 202b, such as a peripheral component interconnect (PCI) bus, a PCI Express (PCIe) bus, an Ethernet interface, a CAN bus, a serial peripheral interface (SPI) bus, a serial communication bus (e.g., an inter-integrated circuit (I2C) bus or USB), a UART, etc. The safety interface can facilitate communication between ECU 300a and peripheral components (such as PMIC 218, memory 220, sensors 222, and / or driver assistance module 224).

[0071] The ECU 300a may check any of the secure communication channels. For example, the ECU 300a may transmit a test signal or pattern on any of the secure communication channels to ensure error-free communication, such as handshaking and / or erroneous communication. The secure communication channels may include communication channels between the primary domain 202a and the secure domain 202b and / or between the ECU 300a and other ECUs 300b.

[0072] In certain aspects, the safety check performed upon resuming from a suspend state may include verifying that opportunistic tests (e.g., BIST for hardware and / or software) performed during a test state (e.g., BIST) have been executed (within the correct time window) and / or enabled to be executed at the next test interval. The safety check may include fault injection testing of ECC logic components. The safety check may include executing periodic tests associated with a safety test library (STL) in any of the safety subsystems (e.g., application processor, GPU, NSP, CVP, or security domain).

[0073] Upon successful completion of the safety check (eg, without any faults or errors being detected), the ECU 300a may be released from the suspended state and may be allowed to initiate execution of either safety application 336a, 336b.

[0074] Figure 4An example timeline 400 for opportunistically performing tests in a test state associated with an ECU (e.g., ECU 300a) is illustrated. At opportunity 402, a key-on action may be performed, wherein the key-on action may trigger a vehicle (e.g., vehicle 100) and a corresponding ECU (e.g., ECU 300a) to perform a full boot sequence, for example, including performing any of the tests described herein, such as a BIST and / or a BIST integrity check (e.g., checking whether the BIST is operating as expected). For example, the full boot sequence may be performed for the first time at a manufacturing facility. The full boot sequence may be performed in a first time period 404. The key-on action may include any action that triggers vehicle power on or resume from a suspend state, for example, via a remote start signal, a power button, or an ignition lock pin.

[0075] At time 406, the full boot sequence can be completed, and the vehicle can perform safety and non-safety functions in a second time period 408. For example, the vehicle can perform ADAS and / or AD functions using the safety domain 202b, and the vehicle can perform IVI functions via the primary domain 202a. During the second time period 408, the vehicle and corresponding ECUs can be operating in a normal state (e.g., when the vehicle is fully operational and performing safety and non-safety functions).

[0076] At time 410, a key-off action may be performed, wherein the key-off action may trigger the vehicle and corresponding ECU to transition to a suspended state (e.g., STR) during a third time period 412. The vehicle may store secure and non-secure contexts in memory (e.g., memory 220 and / or corresponding memory associated with secure domain 202b). In some aspects, ECU 300a may store results from the test performed during the first complete boot sequence during the first time period 404. At time 414, the vehicle may be effectively shut down in the suspended state. The key-off action may include any action that triggers the vehicle to power down or transition to the suspended state, such as via an automatic power-off cycle, a power button, or an ignition lock pin.

[0077] At time 416, a key-on action may be performed, wherein the key-on action may trigger the vehicle and corresponding ECU to resume from a suspended state, thereby allowing a fast boot time (e.g., less than 1 to 2 seconds) in a fourth time period 418. At time 420, the ECU (e.g., ECU 300a) may perform the steps described herein with respect to Figure 3 The ECU may refrain from executing safety functions until the safety checks are completed, such as in the fifth time period 422. Upon completion of the safety checks, the vehicle may execute safety and non-safety functions.

[0078] At timing 424, a key-off action may be performed, which may trigger the vehicle and corresponding ECU to transition to a suspended state (e.g., STR). The ECU (e.g., ECU 300a) may determine that the duration since the last BIST (performed at timing 402) is greater than the MPFDI (e.g., 24 hours), and in response to this determination, the ECU may perform a BIST during a sixth time period 426 while the ECU is in a test state (e.g., when the vehicle is not moving). Performing a BIST in a test state allows the vehicle to quickly recover from the suspended state. If an error or fault is detected, the vehicle may perform the test again to determine whether the error or fault is persistent or temporary. In some cases, the ECU may wait an additional duration (e.g., 1 to 2 seconds) to ensure the vehicle is in the test state. In some cases, the ECU may wait until a certain time of day to perform the BIST, such as after 12:00 AM or 1:00 AM, when the vehicle is most likely not moving. The ECU may store the test results associated with the BIST in memory. At opportunity 428 , the vehicle may be effectively shut down in the suspended state.

[0079] At time 430, a key-on action may be performed, wherein the key-on action may trigger the vehicle and the corresponding ECU to resume from the suspended state in a seventh time period 432. The ECU may restore the secure and non-secure contexts from memory. The ECU may check the test results stored in memory to verify that no faults or errors were detected in the sixth time period, as described herein. At time 434, the ECU may perform certain security checks in an eighth time period 436, as described herein with respect to Figure 3 As described, and upon completion of the safety check, the ECU may perform safety functions.

[0080] Figure 5 1 is a flow chart depicting example operations 500 for operating a vehicle (e.g., vehicle 100). Operations 500 may be performed by a SoC (e.g., SoC 200) or a SoC-based ECU (e.g., Figure 3 ECU 300a) executes.

[0081] Operation 500 may optionally begin at block 502, where the vehicle may operate an electronic control unit (ECU) in a first state. For example, the ECU may operate in a normal state, as described herein with respect to Figure 4 A normal state may include when the vehicle or ECU is fully operational and performing safety and non-safety functions.

[0082] At block 504, the ECU may detect that one or more criteria are met to perform a test associated with the ECU. For example, the ECU may opportunistically perform a test without interrupting the boot sequence of the ECU, as described herein with respect to Figure 3 and Figure 4 described.

[0083] At block 506, while the ECU is in a second state different from the first state, the ECU may, in response to detecting that one or more criteria are satisfied, perform a test associated with the ECU. The test may include a BIST or, for example, testing whether the BIST is operating as expected via fault injection. To perform the test, the ECU may execute a BIST associated with one or more electrical components or one or more software components of the ECU. For example, the one or more electrical components may include at least one of a memory (e.g., memory 220), a processor (e.g., any of processors 204), a control logic component (e.g., memory controller 210 or sensor controller 212), a power management circuit (e.g., PMIC 218), or a voltage regulator (e.g., a voltage regulator in PMIC 218).

[0084] The second state may include a test state, for example, as described herein with respect to Figure 3 and Figure 4 The second state may include when the vehicle or ECU is powered off (e.g., a key-off action may trigger a transition to the second state), when the vehicle or ECU is in a suspended state (e.g., STR), when the vehicle or ECU is not in use for a certain duration, when the vehicle or ECU is in a low power mode, when the vehicle or ECU is immobile for a certain duration, when the vehicle is being refueled or recharged, or any combination thereof.

[0085] In some aspects, the ECU may determine when to perform a test based on, for example, one or more criteria. The one or more criteria may include the vehicle or ECU being powered off, the vehicle or ECU being in a suspended state, or the vehicle or ECU being in a low-power mode. In some aspects, the one or more criteria may be relative to the last time a test was performed. The one or more criteria may be satisfied when a timer (e.g., MPFDI) expires or when a counter reaches a threshold. The ECU may restart a timer or reset a counter in response to performing a test associated with the ECU.

[0086] For certain aspects, the ECU may store results (e.g., pass or fail) associated with the test in a memory (e.g., memory 220). The ECU may examine the stored results in response to obtaining an instruction to resume the ECU from a suspended state. The instruction to resume the ECU may include the following: Figure 3 and Figure 4 The ECU may perform one or more actions in response to the check results.

[0087] In certain aspects, the ECU may perform any of certain security checks in response to resuming from a suspended state. The ECU may perform one or more security checks associated with the ECU while the ECU is in a suspended state and is blocked from executing secure applications. The security checks may include checks as described herein with respect to Figure 3 Certain secure computing subsystems, secure interfaces, and / or secure communication channels are described. The ECU may be allowed to resume from a suspended state in response to (successfully) completing one or more security checks.

[0088] For certain aspects, the ECU may perform any of a variety of actions in response to detecting an error or failure from a test. The ECU may determine that the result indicates an error associated with the ECU. The ECU may perform a subsequent test (e.g., a BIST) in response to determining that the result indicates an error. The ECU may store the results of the subsequent test in memory. The ECU may provide an indication that the result indicates an error associated with the ECU to one or more other ECUs (e.g., other ECU 300b) or an entity (e.g., an OEM), and may prevent the ECU from booting or resuming from a suspended state.

[0089] In certain aspects, the ECU may detect an error while in the first state and perform any of a variety of actions. For example, the ECU may detect an error associated with the ECU while the ECU is operating in the first state. In response to detecting the error, the ECU may be reset or shut down (or perform specific actions depending on the OEM). The ECU may detect an indication to power off the vehicle, and the ECU may perform another test associated with the ECU in response to detecting the error and in response to detecting the indication to power off the vehicle. The ECU may be allowed to enter a suspended state if the other test passes. If the other test fails, the ECU may provide an indication of the error associated with the ECU to one or more other ECUs or entities, and if the other test fails, the ECU may be prevented from booting or resuming from a suspended state.

[0090] For certain aspects, the ECU may be resumed from a suspended state, for example, to enable a fast boot sequence. For example, the ECU may be operated in a suspended state, where the suspended state includes a suspend to memory (e.g., random access memory (RAM) or other types of memory such as non-volatile memory, general-purpose flash memory, embedded multimedia card (eMMC), PCIe, Ethernet-based storage drive, etc.) state.

[0091] In some aspects, the ECU may perform a hybrid safety function including safety functions and non-safety functions, for example, as described herein with respect to Figure 2 and Figure 3 For example, causing the ECU to operate in the first state may include performing safety operations (eg, ADAS and / or AD) and non-safety operations (eg, IVI) via the ECU.

[0092] The various operations of the methods described above may be performed by any suitable component capable of performing the corresponding functions. The component may include various hardware and / or software components and / or modules, including but not limited to circuits, application-specific integrated circuits (ASICs), or processors. For example, components for operating, components for detecting, components for executing, components for storing, components for checking, components for allowing, components for resetting, components for providing, and components for preventing may include a SoC (e.g., SoC 200), a primary domain of the SoC (e.g., primary domain 202a), a security domain of the SoC (e.g., security domain 202b), and a memory (e.g., memory 220).

[0093] Example aspects

[0094] Specific implementation examples are described in the following numbered aspects:

[0095] Aspect 1: A method for operating a vehicle, the method comprising: operating an electronic control unit (ECU) in a first state; detecting that one or more criteria are satisfied to perform a test associated with the ECU; and when the ECU is in a second state different from the first state, performing the test associated with the ECU in response to detecting that the one or more criteria are satisfied.

[0096] Aspect 2: The method of aspect 1, wherein performing the test comprises performing a built-in self-test (BIST) associated with one or more electrical components or one or more software components of the ECU.

[0097] Aspect 3: The method of aspect 2, wherein the one or more electrical components include at least one of a memory, a processor, a control logic unit, a power management circuit, or a voltage regulator.

[0098] Aspect 4: A method according to any one of Aspects 1 to 3, wherein the second state includes: the vehicle or the ECU is powered off, the vehicle or the ECU is in a suspended state, the vehicle or the ECU is not used for a certain duration, the vehicle or the ECU is in a low power mode, or a combination thereof.

[0099] Aspect 5: A method according to any one of Aspects 1 to 4, wherein the one or more criteria include: the vehicle or the ECU transitioning to power off, the vehicle or the ECU transitioning to a suspended state, or the vehicle or the ECU transitioning to a low power mode.

[0100] Aspect 6: The method according to any one of aspects 1 to 5, wherein the one or more criteria are relative to the time when the test was last performed.

[0101] Aspect 7: A method according to any one of Aspects 1 to 6, wherein: the one or more criteria are met when a timer expires or when a counter reaches a threshold; and the method further includes restarting the timer or resetting the counter in response to performing the test associated with the ECU.

[0102] Aspect 8: According to the method described in any one of Aspects 1 to 7, the method also includes: storing the results associated with the test in a memory; checking the stored results in response to obtaining an indication to resume the ECU from a suspended state; and performing one or more actions in response to checking the results.

[0103] Aspect 9: A method according to Aspect 8, wherein performing the one or more actions includes: performing one or more security checks associated with the ECU when the ECU is in the suspended state and is prevented from executing security applications; and allowing the ECU to resume from the suspended state in response to completing the one or more security checks.

[0104] Aspect 10: The method according to aspect 8 or 9 further includes: determining that the result indicates an error associated with the ECU; performing a subsequent test in response to determining that the result indicates the error; and storing the result of the subsequent test in the memory.

[0105] Aspect 11: A method according to any one of aspects 8 to 10, wherein performing the one or more actions includes: providing an indication to one or more other ECUs or entities that the result indicates an error associated with the ECU; and preventing the ECU from booting.

[0106] Aspect 12: According to the method described in any one of Aspects 8 to 11, the method further includes: detecting an error associated with the ECU while the ECU is operating in the first state; resetting or shutting down the ECU in response to detecting the error; detecting an indication for powering off the vehicle; performing another test associated with the ECU in response to detecting the error and in response to detecting the indication for powering off the vehicle; allowing the ECU to enter the suspended state if the another test passes; providing an indication of the error associated with the ECU to one or more other ECUs or entities if the another test fails; and preventing the ECU from booting if the another test fails.

[0107] Aspect 13: The method according to any one of aspects 8 to 12, further comprising causing the ECU to operate in the suspended state, wherein the suspended state comprises a suspend to memory state.

[0108] Aspect 14: The method according to any one of aspects 1 to 13, wherein causing the ECU to operate in the first state includes performing a safety operation and a non-safety operation via the ECU.

[0109] Aspect 15: A device for operating a vehicle, the device comprising: an electronic control unit (ECU), the electronic control unit (ECU) being configured to: operate in a first state, detect that one or more criteria are satisfied to perform a test associated with the ECU, and when the ECU is in a second state different from the first state, perform the test associated with the ECU in response to detecting that the one or more criteria are satisfied.

[0110] Aspect 16: The apparatus of aspect 15, wherein to perform the test, the ECU is configured to perform a built-in self test (BIST) associated with one or more electrical components or one or more software components of the ECU.

[0111] Aspect 17: The apparatus of aspect 16, wherein the one or more electrical components include at least one of a memory, a processor, a control logic unit, a power management circuit, or a voltage regulator.

[0112] Aspect 18: An apparatus according to any one of Aspects 15 to 17, wherein the second state includes: the vehicle or the ECU is powered off, the vehicle or the ECU is in a suspended state, the vehicle or the ECU is not used for a certain duration, the vehicle or the ECU is in a low power mode, or a combination thereof.

[0113] Aspect 19: An apparatus according to any one of Aspects 15 to 18, wherein the one or more criteria include: the vehicle or the ECU transitioning to power off, the vehicle or the ECU transitioning to a suspended state, or the vehicle or the ECU transitioning to a low power mode.

[0114] Aspect 20: The apparatus of any one of aspects 15 to 19, wherein the one or more criteria are relative to the time when the test was last performed.

[0115] Aspect 21: An apparatus according to any one of Aspects 15 to 20, wherein: the one or more criteria are met when a timer expires or when a counter reaches a threshold; and the ECU is further configured to restart the timer or reset the counter in response to performing the test associated with the ECU.

[0116] Aspect 22: An apparatus according to any one of Aspects 15 to 21, wherein the ECU is further configured to: store results associated with the test in a memory, check the stored results in response to obtaining an indication to resume the ECU from a suspended state, and perform one or more actions in response to checking the results.

[0117] Aspect 23: An apparatus according to Aspect 22, wherein, in order to perform the one or more actions, the ECU is configured to: perform one or more security checks associated with the ECU when the ECU is in the suspended state and is prevented from executing security applications, and allow the ECU to resume from the suspended state in response to completing the one or more security checks.

[0118] Aspect 24: An apparatus according to Aspect 22 or 23, wherein the ECU is further configured to: determine that the result indicates an error associated with the ECU, perform a subsequent test in response to determining that the result indicates the error, and store the result of the subsequent test in the memory.

[0119] Aspect 25: An apparatus according to any one of Aspects 22 to 24, wherein, in order to perform the one or more actions, the ECU is further configured to: provide an indication of the result indicating an error associated with the ECU to one or more other ECUs or entities, and prevent the ECU from booting.

[0120] Aspect 26: An apparatus according to any one of Aspects 22 to 25, wherein the ECU is further configured to: detect an error associated with the ECU while the ECU is operating in the first state, reset or shut down the ECU in response to detecting the error, detect an indication for powering off the vehicle, perform another test associated with the ECU in response to detecting the error and in response to detecting the indication for powering off the vehicle, allow the ECU to enter the suspended state if the another test passes, provide an indication of the error associated with the ECU to one or more other ECUs or entities if the another test fails, and prevent the ECU from booting if the another test fails.

[0121] Aspect 27: The apparatus according to any one of aspects 22 to 26, wherein the ECU is further configured to operate in the suspended state, wherein the suspended state includes a suspend to memory state.

[0122] Aspect 28: The apparatus according to any one of aspects 15 to 27, wherein in order for the ECU to operate in the first state, the ECU is configured to perform a safety operation and a non-safety operation.

[0123] Aspect 29: A device for operating a vehicle, the device comprising: a component for operating an electronic control unit (ECU) in a first state; a component for detecting that one or more criteria are satisfied to perform a test associated with the ECU; and a component for performing the test associated with the ECU in response to detecting that the one or more criteria are satisfied when the ECU is in a second state different from the first state.

[0124] Aspect 30: An apparatus comprising: a memory comprising computer-executable instructions; and one or more processors configured to execute the computer-executable instructions and cause the apparatus to perform a method according to any one of Aspects 1 to 14.

[0125] Aspect 31: An apparatus comprising means for performing the method according to any one of aspects 1 to 14.

[0126] Aspect 32: A non-transitory computer-readable medium comprising computer-executable instructions that, when executed by one or more processors of a processing system, cause the processing system to perform the method of any one of aspects 1 to 14.

[0127] Aspect 33: A computer program product embodied on a computer-readable storage medium, the computer program product comprising code for executing the method according to any one of aspects 1 to 14.

[0128] Additional Notes

[0129] Within this disclosure, the word “exemplary” is used to mean “serving as an example, instance, or illustration.” Any specific implementation or aspect described herein as “exemplary” is not necessarily to be construed as preferred or superior to other aspects of the disclosure. Likewise, the term “aspect” does not require that all aspects of the disclosure include the feature, advantage, or mode of operation discussed. The term “coupled” is used herein to refer to a direct or indirect coupling between two objects. For example, if object A physically contacts object B, and object B contacts object C, objects A and C may still be considered to be coupled to each other, even though objects A and C are not in direct physical contact with each other. For example, a first object may be coupled to a second object even though the first object has never been in direct physical contact with the second object. The term “circuit” is used broadly and is intended to include hardware implementations of electronic devices and conductors that, when connected and configured, enable the functions described in this disclosure to be performed, without limitation to the type of electronic circuitry.

[0130] The apparatuses and methods described in the detailed description are illustrated in the drawings by various blocks, modules, components, circuits, steps, processes, algorithms, etc. (collectively referred to as "elements"), which may be implemented using, for example, hardware.

[0131] One or more of the components, steps, features, and / or functions illustrated herein may be rearranged and / or combined into a single component, step, feature, or function, or embodied in several components, steps, or functions. Additional elements, components, steps, and / or functions may also be added without departing from the features disclosed herein. The apparatus, devices, and / or components illustrated herein may be configured to perform one or more of the methods, features, or steps described herein.

[0132] It should be understood that the specific order or hierarchy of steps in the disclosed methods is an illustration of exemplary processes. It should be understood that the specific order or hierarchy of steps in these methods may be rearranged based on design preferences. The accompanying method claims present elements of the various steps in a sample order and are not intended to be limited to the specific order or hierarchy presented unless expressly stated herein.

[0133] The foregoing description is provided to enable any person skilled in the art to practice various aspects described herein. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects. Therefore, the claims are not intended to be limited to the various aspects shown herein, but to meet the full scope consistent with the text of the claims, wherein unless explicitly stated otherwise, reference to an element in the singular is not intended to mean "one and only one", but "one or more". Unless otherwise specified, the term "some" refers to one or more. The phrase "at least one" mentioned in the project list refers to any combination of those projects, including single members. For example, "at least one of the following: a, b or c" is intended to at least encompass: a, b, c, ab, ac, bc and abc, and any combination with the multiple of the same element (for example, aa, aaa, aab, aac, abb, acc, bb, bbb, bbc, cc and ccc or any other order of a, b and c). All structural and functional equivalents to the elements of the various aspects described throughout this disclosure that are or later become known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be covered by the claims. In addition, nothing disclosed herein is intended to be dedicated to the public regardless of whether such disclosure is explicitly recited in the claims. No claim element should be construed under 35 U.S.C. §112(f) unless the element is explicitly recited using the phrase “means for” or, in the case of a method claim, the phrase “step for.”

[0134] It is to be understood that the claims are not limited to the precise configuration and components illustrated above. Various modifications, changes and variations may be made in the arrangement, operation and details of the methods and apparatus described above without departing from the scope of the claims.

Claims

1. A method of operating a vehicle, the method comprising: causing an electronic control unit (ECU) to operate in a first state; detecting satisfaction of one or more criteria to execute a test associated with the ECU; as well as The test associated with the ECU is performed in response to detecting that the one or more criteria are satisfied while the ECU is in a second state different from the first state. 2 . The method of claim 1 , wherein performing the test comprises performing a built-in self-test (BIST) associated with one or more electrical components or one or more software components of the ECU. 3 . The method of claim 2 , wherein the one or more electrical components include at least one of a memory, a processor, a control logic unit, a power management circuit, or a voltage regulator.

4. The method of claim 1 , wherein the second state comprises: The vehicle or the ECU is powered off, The vehicle or the ECU is in a suspended state, The vehicle or the ECU has not been used for a certain duration, The vehicle or the ECU is in low power mode, or A combination of them.

5. The method of claim 1 , wherein the one or more criteria include: The vehicle or the ECU transitions to power off, The vehicle or the ECU transitions to a suspended state, or The vehicle or the ECU transitions to a low power mode. The method of claim 1 , wherein the one or more criteria are relative to a time when the test was last performed.

7. The method according to claim 1, wherein: The one or more criteria are satisfied when a timer expires or when a counter reaches a threshold; and The method further includes restarting the timer or resetting the counter in response to executing the test associated with the ECU.

8. The method according to claim 1, further comprising: storing results associated with the test in a memory; checking the stored result in response to obtaining an instruction to resume the ECU from a suspended state; as well as One or more actions are performed in response to examining the results.

9. The method of claim 8, wherein performing the one or more actions comprises: performing one or more security checks associated with the ECU while the ECU is in the suspended state and is blocked from executing secure applications; as well as The ECU is allowed to resume from the suspended state in response to completing the one or more safety checks.

10. The method according to claim 8, further comprising: determining that the result indicates an error associated with the ECU; performing subsequent testing in response to determining that the result indicates the error; as well as The results of the subsequent test are stored in the memory.

11. The method of claim 8, wherein performing the one or more actions comprises: providing an indication to one or more other ECUs or entities that the result indicates an error associated with the ECU; as well as Prevent the ECU from booting.

12. The method according to claim 8, further comprising: detecting an error associated with the ECU while the ECU is operating in the first state; resetting or shutting down the ECU in response to detecting the error; detecting an indication to power off the vehicle; performing another test associated with the ECU in response to detecting the error and in response to detecting the indication to power off the vehicle; allowing the ECU to enter the suspended state if the another test passes; providing an indication of the error associated with the ECU to one or more other ECUs or entities if the further test fails; as well as The ECU is prevented from booting if the further test fails. 13 . The method of claim 8 , further comprising causing the ECU to operate in the suspend state, wherein the suspend state comprises a suspend to memory state.

14. The method of claim 1, wherein causing the ECU to operate in the first state comprises executing a safety operation and a non-safety operation via the ECU.

15. A device for operating a vehicle, the device comprising: An electronic control unit (ECU), the electronic control unit (ECU) being configured to: In the first state, detecting that one or more criteria are satisfied to execute a test associated with the ECU, and The test associated with the ECU is performed in response to detecting that the one or more criteria are satisfied while the ECU is in a second state different from the first state. 16 . The apparatus of claim 15 , wherein to perform the test, the ECU is configured to execute a built-in self test (BIST) associated with one or more electrical components or one or more software components of the ECU.

17. The apparatus of claim 16, wherein the one or more electrical components include at least one of a memory, a processor, control logic, a power management circuit, or a voltage regulator.

18. The apparatus of claim 15, wherein the second state comprises: The vehicle or the ECU is powered off, The vehicle or the ECU is in a suspended state, The vehicle or the ECU has not been used for a certain duration, The vehicle or the ECU is in low power mode, or A combination of them.

19. The apparatus of claim 15, wherein the one or more criteria include: The vehicle or the ECU transitions to power off, The vehicle or the ECU transitions to a suspended state, or The vehicle or the ECU transitions to a low power mode.

20. The apparatus of claim 15, wherein the one or more criteria are relative to a time when the test was last performed.

21. The apparatus of claim 15, wherein: The one or more criteria are satisfied when a timer expires or when a counter reaches a threshold; and The ECU is further configured to restart the timer or reset the counter in response to executing the test associated with the ECU.

22. The apparatus according to claim 15, wherein the ECU is further configured to: storing results associated with the test in a memory, checking the stored result in response to obtaining an instruction to resume the ECU from a suspended state, and One or more actions are performed in response to examining the results.

23. The apparatus of claim 22, wherein to perform the one or more actions, the ECU is configured to: performing one or more security checks associated with the ECU while the ECU is in the suspended state and is prevented from executing secure applications, and The ECU is allowed to resume from the suspended state in response to completing the one or more safety checks.

24. The apparatus according to claim 22, wherein the ECU is further configured to: determining that the result indicates an error associated with the ECU, performing subsequent testing in response to determining that the result indicates the error, and The results of the subsequent test are stored in the memory.

25. The apparatus of claim 22, wherein to perform the one or more actions, the ECU is further configured to: providing an indication that the result is indicative of an error associated with the ECU to one or more other ECUs or entities, and Prevent the ECU from booting.

26. The apparatus of claim 22, wherein the ECU is further configured to: detecting an error associated with the ECU while the ECU is operating in the first state, resetting or shutting down the ECU in response to detecting the error, detecting an indication to power off the vehicle, performing another test associated with the ECU in response to detecting the error and in response to detecting the indication to power off the vehicle, allowing the ECU to enter the suspended state if the other test passes, providing an indication of said error associated with said ECU to one or more other ECUs or entities if said further test fails, and The ECU is prevented from booting if the further test fails. 27 . The apparatus of claim 22 , wherein the ECU is further configured to operate in the suspend state, wherein the suspend state comprises a suspend to memory state.

28. The apparatus of claim 15, wherein in order for the ECU to operate in the first state, the ECU is configured to perform a safety operation and a non-safety operation.

29. A device for operating a vehicle, the device comprising: a component for causing an electronic control unit (ECU) to operate in a first state; means for detecting that one or more criteria are satisfied for executing a test associated with said ECU; as well as Means for performing the test associated with the ECU in response to detecting that the one or more criteria are satisfied when the ECU is in a second state different from the first state.