Protection device and method for matching register, equipment, device, vehicle, medium and product
Through the mirror register and comparison module in the configuration register protection device, the security problems caused by the bit flip or tampering of the configuration register are solved, and resource conservation and stability improvement are achieved.
Patent Information
- Application Number
- CN202510092327.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-08-19
AI Technical Summary
In the controller system, bit flip or tampering of the configuration registers leads to security problems. The existing readback verification method consumes large resources of the main control chip, complex software design, and high cost.
The configuration register protection device is adopted, including a first mirror register and a comparison module. By comparing the target configuration data with the first configuration data, the abnormal status of the configuration register is determined, and processed in the abnormal situation to avoid security problems.
It reduces the communication resource consumption of the main control unit, simplifies software design, improves the stability and security of the system, and reduces implementation costs.
Smart Images

Figure CN120508415A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of configuration registers, and more specifically, to a configuration register protection device, a protection method, an electronic device, an electronic device, a vehicle, a computer-readable storage medium, and a computer program product. Background Art
[0002] In controller systems, peripheral devices have numerous hardware resources, and the main control unit must configure these devices. If these configurations are bit-flipped or tampered with during controller operation, this can lead to security issues. The main control unit can periodically read back the values in the configuration registers and then compare them with the expected values within the main control unit to check for bit-flips or changes in the configuration information.
[0003] However, in the related art, the read-back verification method consumes a lot of communication resources of the main control chip, and the software design is complex and the implementation cost is high. Summary of the Invention
[0004] The present application provides a protection device, a protection method, an electronic device, an electronic device, a vehicle, a computer-readable storage medium, and a computer program product for a configuration register.
[0005] An embodiment of the present application provides a protection device for a configuration register, wherein the configuration register is configured to store target configuration data, and the protection device includes:
[0006] a first mirror register, wherein the first mirror register is configured to store first configuration data, where the first configuration data is determined according to the target configuration data;
[0007] A comparison module is configured to determine an abnormal state of the configuration register according to the first configuration data and the target configuration data.
[0008] In this way, in the protection device, protection method, electronic device, electronic device, vehicle, computer-readable storage medium and computer program product of the configuration register in the embodiments of the present application, by comparing the target configuration data stored in the configuration register with the first configuration data determined based on the target configuration data, the abnormal state of the configuration register can be determined, so that when there is an abnormality in the target configuration data stored in the configuration register, the abnormality of the configuration register can be processed in a timely manner to avoid safety problems caused by the abnormality of the configuration data.
[0009] In some embodiments, the protection device further comprises:
[0010] an inverter configured to invert the target configuration data to obtain the first configuration data; and invert the first configuration data to obtain second configuration data;
[0011] The comparison module is further configured to determine an abnormal state of the configuration register according to the second configuration data and the target configuration data.
[0012] In some embodiments, the protection device further comprises:
[0013] A second mirror register, wherein the second mirror register is configured to store third configuration data, and the third configuration data is determined based on the target configuration data; when it is determined that the configuration register may be in an abnormal state, the third configuration data is used to determine an abnormal register with an abnormality, and the abnormal register includes the configuration register and the first mirror register.
[0014] In some embodiments, when it is determined that an exception occurs in the exception register, the third configuration data is used to determine new configuration data, and the new configuration data is used to write into the exception register.
[0015] In some embodiments, the protection device further comprises:
[0016] A data management module is configured to determine the first configuration data according to the target configuration data, and write the first configuration data into the first mirror register.
[0017] An embodiment of the present application provides a method for protecting a configuration register. The method is based on the protection device of any of the above embodiments, and the method includes:
[0018] determining first configuration data according to the target configuration data stored in the configuration register;
[0019] An abnormal state of the configuration register is determined based on the first configuration data and the stored target configuration data.
[0020] In some embodiments, determining the first configuration data according to the target configuration data stored in the configuration register includes:
[0021] The target configuration data is inverted to determine the first configuration data.
[0022] In some embodiments, determining the abnormal state of the configuration register according to the first configuration data and the stored target configuration data includes:
[0023] Inverting the first configuration data to obtain second configuration data;
[0024] The second configuration data is compared with the target configuration data to determine an abnormal state of the configuration register.
[0025] In some embodiments, comparing the second configuration data with the target configuration data to determine the abnormal state of the configuration register includes:
[0026] When the second configuration data is different from the target configuration data, it is determined that an abnormality may exist in the configuration register.
[0027] In some embodiments, the protection method further comprises:
[0028] determining third configuration data according to the target configuration data stored in the configuration register;
[0029] In the case that the configuration register may be abnormal, the actual abnormal state of the configuration register is determined according to the third configuration data and the target configuration data.
[0030] In some embodiments, the second configuration data is stored in a first mirror register, and determining the actual abnormal state of the configuration register based on the third configuration data and the target configuration data includes:
[0031] Inverting the third configuration data to obtain fourth configuration data;
[0032] When the fourth configuration data and the target configuration data are different, determining that an abnormality actually exists in the configuration register;
[0033] When the fourth configuration data is identical to the target configuration data, it is determined that there is no abnormality in the configuration register and there is an abnormality in the first mirror register.
[0034] In some embodiments, the protection method further comprises:
[0035] When it is determined that the configuration register is truly abnormal, new target configuration data is determined according to the third configuration data and written into the configuration register.
[0036] In some embodiments, determining the third configuration data according to the target configuration data stored in the configuration register includes:
[0037] inverting the target configuration data to obtain the third configuration data;
[0038] The determining new target configuration data according to the third configuration data and writing the new target configuration data into the configuration register includes:
[0039] The third configuration data is inverted to determine new target configuration data, and written into the configuration register.
[0040] An embodiment of the present application provides an electronic device, which includes a configuration register and a protection device as described in any of the above embodiments.
[0041] An embodiment of the present application provides an electronic device, which includes one or more processors and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the steps of the method in any of the above embodiments are implemented.
[0042] An embodiment of the present application provides a vehicle, which includes the electronic device or the electronic device according to the above embodiment.
[0043] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the steps of the method of any of the above embodiments are implemented.
[0044] An embodiment of the present application provides a computer program product, including a computer program, which implements the steps of any of the above embodiments when the computer program is executed by a processor.
[0045] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become obvious from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0047] Figure 1 is a schematic diagram of an electronic device and an external configuration source according to certain embodiments of the present application;
[0048] Figure 2 is a flowchart of a protection method according to certain embodiments of the present application;
[0049] Figure 3 is a schematic diagram of a related art protection device and an external configuration source;
[0050] Figure 4 This is a schematic diagram of certain embodiments of the present application applied to an intelligent driving domain controller system;
[0051] Figure 5 is a flowchart of a protection method according to certain embodiments of the present application;
[0052] Figure 6is a flowchart of a protection method according to certain embodiments of the present application;
[0053] Figure 7 is a flowchart of a protection method according to certain embodiments of the present application;
[0054] Figure 8 is a flowchart of a protection method according to certain embodiments of the present application;
[0055] Figure 9 is a flowchart of a protection method according to certain embodiments of the present application;
[0056] Figure 10 is a flowchart of a protection method according to certain embodiments of the present application;
[0057] Figure 11 It is a flowchart of the protection method of certain embodiments of the present application. DETAILED DESCRIPTION
[0058] The embodiments of the present application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application and are not to be construed as limiting the present application.
[0059] In controller systems, peripheral devices have numerous hardware resources, and the main control unit must configure these devices. If these configurations are bit-flipped or tampered with during controller operation, this can lead to security issues. The main control unit can periodically read back the values in the configuration registers and then compare them with the expected values within the main control unit to check for bit-flips or changes in the configuration information.
[0060] However, in the related art, the read-back verification method consumes a lot of communication resources of the main control chip, and the software design is complex and the implementation cost is high.
[0061] Based on the above issues to be resolved, please refer to Figure 1 In an embodiment of the present application, a protection device 10 for a configuration register 20 is provided. The configuration register 20 is configured to store target configuration data. The protection device 10 includes a first mirror register 11 and a comparison module 12. The first mirror register 11 is configured to store first configuration data, which is determined based on the target configuration data. The comparison module 12 is configured to determine an abnormal state of the configuration register 20 based on the first configuration data and the target configuration data.
[0062] See also Figure 2The embodiment of the present application provides a method for protecting a configuration register 20. The protection method is based on the protection device 10 of any of the above embodiments. The protection method includes:
[0063] 01: Determine first configuration data according to target configuration data stored in the configuration register 20;
[0064] 02: Determine the abnormal state of the configuration register 20 according to the first configuration data and the stored target configuration data.
[0065] An embodiment of the present application provides an electronic device comprising one or more processors and a memory, wherein the memory stores a computer program that can be executed by the processor. The processor can be configured to: determine first configuration data based on target configuration data stored in a configuration register 20; and determine an abnormal state of the configuration register 20 based on the first configuration data and the stored target configuration data.
[0066] The present application provides a configuration register 20 protection device 10, which includes a first determination module and a second determination module. The first determination module can be used to determine first configuration data based on target configuration data stored in the configuration register 20; the second determination module can be used to determine an abnormal state of the configuration register 20 based on the first configuration data and the stored target configuration data.
[0067] Specifically, in the control system, the main control unit needs to configure other electronic devices 100 so that they can respond to and cooperate with the control of the main control unit. Figure 3 In related technologies, complex controller systems, such as intelligent driving domain controller systems, have a large number of peripheral hardware resources, and the main control unit needs to configure and operate many external devices. For example, it is necessary to configure the deserializer used to receive camera video data, the serializer used to send video data, the power management IC (PMIC), and the IMU (Inertial Measurement Unit) module.
[0068] The configurations of these external devices are often safety-related. That is, if this configuration information experiences bit flips or tampering during controller operation, it could lead to hazardous events. Therefore, it is crucial to consider how to detect or prevent these anomalies. To address this issue, a common strategy currently involves the main control unit periodically reading back the configuration data in safety-related configuration registers. This data is then compared with the expected configuration values within the main control unit to check for bit flips or changes in the configuration registers. This readback verification requires the main control unit to utilize its own resources. Consequently, this periodic readback verification during runtime consumes significant communication resources of the main control unit, complicates software design, and increases implementation costs.
[0069] In the embodiments of the present application, both the protection device 10 and the configuration register 20 may be provided within the electronic device 100. The target configuration data within the configuration register 20 is the configuration data written by the external configuration source 200 into the configuration register 20 within the electronic device 100 in order to configure the electronic device 100. By integrating all protection devices 10 within the electronic device 100, the protection strategy design for the safety-related configuration register 20 can be completed without the external configuration source 200 (main control unit) consuming additional resources or design costs. This makes the electronic device 100 more flexible to adapt and can better support the control system in meeting safety requirements.
[0070] Among them, the external configuration source 200 can be any main control unit, such as: SoC (System on Chip), MCU (Microcontroller Unit), FPGA (Field Programmable Gate Array), etc. The electronic device 100 can be any device that needs to be configured in the controller system, such as: serializer, deserializer, IMU module, PMIC, etc. It should be noted that those skilled in the art should understand that the above-mentioned external configuration source 200 can be equivalently replaced by other main control devices, and the above-mentioned electronic device 100 can be equivalently replaced by other configuration devices, and this is not an exhaustive list.
[0071] The external configuration source 200 writes target configuration data into the configuration register 20 of the electronic device 100. Assuming that the target configuration data stored in the configuration register 20 is security-related configuration data, any abnormalities such as bit flipping or data corruption caused by interference during device operation will cause abnormal operation of the electronic device 100. Therefore, it is necessary to verify the target configuration data to determine the abnormal state of the configuration register 20, thereby achieving security protection for the configuration register 20.
[0072] In one embodiment, see Figure 4 In the intelligent driving domain controller system, MCU, SOC and other devices serve as the core computing units of the system, and their peripheral electronic devices 100 need to be configured to ensure the normal operation of the intelligent driving domain controller system. Among them, the MCU can configure the PMIC through the SPI (Serial Peripheral Interface), and write the target configuration data into the configuration register 20 in the PMIC so that it can power the main control chip. The SOC configures the power timing management chip through the I2C bus (INTER IC BUS), and needs to write the target configuration data into the configuration register 20 of the power timing management chip so that it can manage the power supply timing of the SOC. In addition, the SOC also needs to configure the deserializer used to process the video data of the camera module, and write the target configuration data into the register inside the deserializer through the I2C bus to ensure that the deserializer can correctly deserialize the video data and input it into the SOC.
[0073] Whether the configuration data of the aforementioned devices that need to be configured is correctly configured will affect the normal operation of the entire control system and the normal implementation of the control system's functions. Therefore, implementing the configuration register 20 protection method of the present embodiment in the PMIC chip, power timing management chip, and deserializer chip can effectively deal with abnormal faults such as corruption, bit flipping, and tampering of the value in the configuration register 20, greatly improving the stability of system operation and effectively avoiding the risks caused by system failure.
[0074] In some embodiments, the protection device 10 further includes a data management module 13 , which is configured to determine first configuration data according to the target configuration data and write the first configuration data into the first mirror register 11 .
[0075] The data management module 13 is used to perform operations such as collecting configuration data comparison and verification results of the configuration register 20, writing to the mirror register, and rewriting the configuration register 20.
[0076] After the external configuration source 200 writes the target configuration data into the configuration register 20, the data management module 13 in the protection device 10 determines the first configuration data based on the target configuration data and writes the first configuration data into the first mirror register 11. In other words, the first configuration data stored in the first mirror register 11 is determined based on the target configuration data. Therefore, it is possible to determine whether the target configuration data is abnormal based on the target configuration data and the first configuration data, thereby determining the abnormal state of the configuration register 20.
[0077] In this way, in the protection device 10, protection method, electronic device, vehicle, computer-readable storage medium and computer program product of the configuration register 20 in the embodiments of the present application, by comparing the target configuration data stored in the configuration register 20 with the first configuration data determined based on the target configuration data, the abnormal state of the configuration register 20 can be determined, so that when there is an abnormality in the target configuration data stored in the configuration register 20, the abnormality of the configuration register 20 can be processed in time to avoid safety problems caused by the abnormality of the configuration data.
[0078] In some embodiments, the protection device 10 also includes an inverter 14, which is configured to invert the target configuration data to obtain first configuration data; and invert the first configuration data to obtain second configuration data; the comparison module 12 is also configured to determine the abnormal state of the configuration register 20 based on the second configuration data and the target configuration data.
[0079] See also Figure 5 In some embodiments, step 01, determining first configuration data according to target configuration data stored in the configuration register 20, includes:
[0080] 011: Invert the target configuration data to determine the first configuration data.
[0081] In some embodiments, the processor may be configured to invert the target configuration data to determine the first configuration data.
[0082] In some embodiments, the first determination module includes a first determination submodule. The first determination submodule can be configured to invert the target configuration data to determine the first configuration data.
[0083] See also Figure 6 In some embodiments, step 02, determining an abnormal state of the configuration register 20 according to the first configuration data and the stored target configuration data, includes:
[0084] 021: Invert the first configuration data to obtain the second configuration data;
[0085] 022 : Compare the second configuration data with the target configuration data to determine the abnormal state of the configuration register 20 .
[0086] In some embodiments, the processor may be configured to: invert the first configuration data to obtain second configuration data; and compare the second configuration data with the target configuration data to determine the abnormal state of the configuration register 20 .
[0087] In some embodiments, the second determination module includes a second determination submodule and a third determination submodule. The first determination submodule may be configured to invert the first configuration data to obtain the second configuration data, and the second determination submodule may be configured to compare the second configuration data with the target configuration data to determine whether the configuration register 20 is in an abnormal state.
[0088] Specifically, the protection device 10 further includes an inverter 14. When the external configuration source 200 writes target configuration data into the configuration register 20, the data management module 13 of the protection device 10 inverts the target configuration data through the inverter 14 to obtain first configuration data, and writes the first configuration data into the first mirror register 11.
[0089] Because the first configuration data stored in the first mirror register 11 is obtained by inverting the target configuration data, it cannot be directly compared with the target configuration data. Therefore, when determining the abnormal state of the configuration register 20 based on the first configuration data and the target configuration data, it is necessary to invert the first configuration data before comparing them.
[0090] That is, the first configuration data is inverted to obtain the second configuration data. The second configuration data is compared with the target configuration data to determine the abnormal state of the configuration register 20, so as to determine whether the configuration register 20 is abnormal.
[0091] When comparing the second configuration data with the target configuration data, the comparison may be performed bit by bit to ensure that there is no anomaly in the target configuration data.
[0092] In this way, the inverter 14 is added to the writing of the first mirror register 11 in the protection device 10, which can avoid common cause failures of configuration data bit abnormalities during equipment operation to a certain extent and improve the abnormality diagnosis coverage.
[0093] It should be noted that in the protection device 10 of the embodiment of the present application, in addition to providing the inverter 14, other similar algorithms or verification methods can also be used to improve the diagnostic coverage of abnormality diagnosis. For example, parity check bits can be added to the configuration register 20 and the first mirror register 11, the operating status of the control system can be monitored by a timer, and a check code can be generated by multinomial division and appended to the end of the configuration data for verification.
[0094] See also Figure 7 In some embodiments, step 022, comparing the second configuration data with the target configuration data to determine the abnormal state of the configuration register 20, includes:
[0095] 0221: When the second configuration data and the target configuration data are different, it is determined that there may be an abnormality in the configuration register 20.
[0096] In some embodiments, the processor may be configured to determine that an abnormality may exist in the configuration register 20 when the second configuration data and the target configuration data are different.
[0097] In some embodiments, the third determining submodule includes a first determining unit. The first determining unit is configured to determine that an abnormality may exist in the configuration register 20 when the second configuration data is different from the target configuration data.
[0098] Specifically, by comparing the second configuration data with the target configuration data, it can be determined whether the target configuration data is the same as the second configuration. If the target configuration data and the second configuration data are different, then there may be an abnormality in the configuration register 20, resulting in a change in the target configuration information stored therein.
[0099] In one embodiment, after the external configuration source 200 completes configuration of the configuration register 20, the electronic device 100, through the data management module 13, inverts the target configuration data in the configuration register 20 and writes the inverted data to the first mirror register 11. The comparison module 12 is configured to compare the value in the target configuration register 20 with the inverted value in the first mirror configuration register 20 to see if they are consistent. If the comparison result is inconsistent, it can be determined that the target configuration data in the configuration register 20 may have undergone an abnormal change.
[0100] It is understandable that since the abnormal state is determined by comparing the first configuration data stored in first mirror register 11 with the target configuration data stored in configuration register 20, it is also possible that an abnormality in first mirror register 11 has caused a change in the first configuration data, resulting in the second configuration data being different from the target configuration data. Therefore, based on the second configuration data and the target configuration data, it can only be determined that there may be an abnormality in configuration register 20. Further determination is required to determine the actual abnormality in configuration register 20.
[0101] In this way, since the second configuration data is different from the target configuration data, it can be determined that the configuration register 20 may be abnormal, thereby achieving a preliminary determination of the abnormal state of the configuration register 20.
[0102] In some embodiments, the protection device 10 also includes a second mirror register 15, which is configured to store third configuration data, and the third configuration data is determined based on the target configuration data; when it is determined that the configuration register 20 may be in an abnormal state, the third configuration data is used to determine an abnormal register with an abnormality, and the abnormal register includes the configuration register 20 and the first mirror register 11.
[0103] See also Figure 8 In some embodiments, the protection method further comprises:
[0104] 03: Determine third configuration data according to the target configuration data stored in the configuration register 20;
[0105] 04: In the case that the configuration register 20 may be abnormal, the actual abnormal state of the configuration register 20 is determined according to the third configuration data and the target configuration data.
[0106] In some embodiments, the processor may be configured to determine third configuration data based on target configuration data stored in the configuration register 20; and when the configuration register 20 may be abnormal, determine the actual abnormal state of the configuration register 20 based on the third configuration data and the target configuration data.
[0107] In some embodiments, the configuration register 20 protection device 10 further includes a third determination module and a fourth determination module. The third determination module may be configured to determine the third configuration data based on the target configuration data stored in the configuration register 20; and the fourth determination module may be configured to determine the actual abnormal state of the configuration register 20 based on the third configuration data and the target configuration data when the configuration register 20 may be abnormal.
[0108] Specifically, the second mirror register 15 stores third configuration data. The third configuration data is determined based on the target configuration data. When the external configuration source 200 writes the target configuration data into the configuration register 20, the data management module 13 processes the target configuration data to obtain first and third configuration data, respectively. The first configuration data is then written into the first mirror register 11, and the third configuration data is written into the second mirror register 15. The third configuration data in the second mirror register 15 allows for further determination of the true nature of any abnormality in the configuration register 20, should it be considered to be present.
[0109] As described above, when the second configuration data differs from the target configuration data, an abnormality may exist in the first mirror register 11 or the configuration register 20. In this case, it is necessary to determine whether the abnormal change occurred in the target configuration data in the configuration register 20 or in the first configuration data in the first mirror configuration register 20. Based on the third configuration data and the target configuration data, it is possible to further determine whether the target configuration data is truly abnormal, thereby determining the true nature of the abnormal state of the configuration register 20. For example, when writing to the second mirror register 15, if the target configuration data is directly written as the third configuration data into the second mirror register 15, then during verification, the third configuration data can be directly compared with the target configuration data to determine the authenticity of the abnormality in the configuration register 20. For another example, when writing to the second mirror register 15, if the target configuration data is processed to obtain the third configuration data and then written to the second mirror register 15, then during verification, it is necessary to inversely process the third configuration data and then compare it with the target configuration data to determine the authenticity of the abnormality in the configuration register 20.
[0110] In one embodiment, in electronic device 100, a first mirror register 11 and a second mirror register 15 are provided for each configuration register 20. That is, if electronic device 100 includes two configuration registers 20, two first mirror registers 11 and two second mirror registers 15 are required. These two additional mirror registers enable configuration data comparison and verification, as well as target configuration data rewriting. This facilitates anomaly detection and automatic error correction for security-related configuration data during operation. This eliminates the need for an external configuration source 200 to detect data readback anomalies, as is often the case in related technologies, and enhances automatic error correction capabilities.
[0111] In this way, by setting the second mirror register 15 and according to the second configuration data and the target configuration data therein, it can be determined whether the configuration register 20 is actually abnormal.
[0112] See also Figure 9 In some embodiments, the second configuration data is stored in the first mirror register 11, and the third configuration data is obtained by inverting the target configuration data. Step 04, determining the actual abnormal state of the configuration register 20 based on the third configuration data and the target configuration data, includes:
[0113] 041: invert the third configuration data to obtain fourth configuration data;
[0114] 042: When the fourth configuration data and the target configuration data are different, it is determined that an abnormality actually exists in the configuration register 20;
[0115] 043: When the fourth configuration data and the target configuration data are identical, it is determined that the configuration register 20 has no abnormality, but the first mirror register 11 has an abnormality.
[0116] In some embodiments, the processor may be configured to determine that the configuration register 20 has no abnormality and the first mirror register 11 has an abnormality when the third configuration data and the target configuration data are the same.
[0117] In some embodiments, the fourth determination module includes a fourth determination submodule, a fifth determination submodule, and a sixth determination submodule. The fourth determination submodule may be configured to invert the third configuration data to obtain fourth configuration data; the fifth determination submodule may be configured to determine that an abnormality actually exists in the configuration register 20 when the fourth configuration data and the target configuration data are different; and the sixth determination submodule may be configured to determine that an abnormality does not exist in the configuration register 20 but exists in the first mirror register 11 when the fourth configuration data and the target configuration data are the same.
[0118] Specifically, the third configuration data may be obtained by inverting the target configuration data. When determining the abnormal state of the configuration register 20 based on the third configuration data and the target configuration data, the third configuration data also needs to be inverted before being compared with the target configuration data.
[0119] When writing the target configuration data, the data management module 13 of the protection device 10 may invert the target configuration data through the inverter 14 , obtain the third configuration data, and write the obtained data into the second mirror register 15 .
[0120] When determining the abnormal state of the configuration register 20 according to the third configuration data and the target configuration data, the inverter 14 inverts the third configuration data to obtain the fourth configuration data. The comparator compares the fourth configuration data with the target configuration data to determine the abnormal state of the configuration register 20.
[0121] In the case that the fourth configuration data is different from the target configuration data, the target configuration data is different from the configuration data stored in the two mirror registers, and it can be determined that there is a real abnormality in the configuration register 20.
[0122] If the fourth configuration data and the target configuration data are identical, the target configuration data is different from the configuration data stored in the first mirror register 11 and is consistent with the configuration data stored in the second mirror register 15. This indicates that an abnormality exists in the first mirror register 11. In other words, it can be determined that there is no abnormality in the configuration register 20, but an abnormality exists in the first mirror register 11.
[0123] It should be noted that the implementation of the embodiments of the present application is based on the assumption that the probability of simultaneous failure of configuration register 20, first mirror register 11, and second mirror register 15 is either impossible or acceptably low. Because the configuration data stored in configuration register 20, first mirror register 11, and second mirror register 15 are mutually inverted values, the probability of common-cause failure of configuration register 20 and first mirror register 11, or configuration register 20 and second mirror register 15, is significantly reduced. Therefore, the probability of simultaneous failure of both registers is very low.
[0124] In this way, by inverting the third configuration data to obtain the fourth configuration data, and comparing the fourth configuration data with the target configuration data, the actual abnormal state of the configuration register 20 can be determined to further determine the abnormal state of the configuration register 20.
[0125] In some embodiments, when it is determined that an exception occurs in the exception register, the third configuration data is used to determine new configuration data, and the new configuration data is used to write into the exception register.
[0126] See also Figure 10 In some embodiments, the protection method further comprises:
[0127] 05: When it is determined that the configuration register 20 is truly abnormal, new target configuration data is determined according to the third configuration data and written into the configuration register 20 .
[0128] In some embodiments, the processor may be configured to determine new target configuration data based on the third configuration data and write the new target configuration data into the configuration register 20 when determining that the configuration register 20 is truly abnormal.
[0129] In some embodiments, the configuration register 20 protection device 10 further includes a fifth determination module. The fifth determination module is configured to determine new target configuration data based on the third configuration data and write the new target configuration data into the configuration register 20 when determining that the configuration register 20 is truly abnormal.
[0130] Specifically, if it is determined that configuration register 20 truly has an abnormality, since third configuration data has already been obtained based on the target configuration data and stored in second configuration register 20, it can be assumed that the third configuration data stored in second mirror register 15 can be processed to obtain the original correct target configuration data. Therefore, data management module 13 can determine new target configuration data based on the third configuration data and write the new target configuration data into configuration register 20. Alternatively, if it is determined that first mirror register 11 truly has an abnormality, new first configuration data can be determined based on the third configuration data and written into first mirror register 11.
[0131] Understandably, when the electronic device 100 has multiple configuration registers 20, after detecting an abnormality in a configuration register 20 through comparison and verification, the abnormal configuration register 20 can be located. After determining that the abnormal configuration register 20 exists, the target device can rewrite the configuration register 20. After the target configuration data is rewritten, the protection device 10 can enter the next protection cycle.
[0132] In this way, the entire abnormality detection and automatic error correction protection process is completely completed by the protection device 10 in the electronic device 100, and no reconfiguration or any other operations are required by the external configuration source 200, saving computing resources and costs in the main control unit as the external configuration source 200.
[0133] See also Figure 11 In some embodiments, step 03, determining the third configuration data according to the target configuration data stored in the configuration register 20, includes:
[0134] 031: invert the target configuration data to obtain the third configuration data;
[0135] Step 06, determining new target configuration data based on the third configuration data and writing the new target configuration data into the configuration register 20, includes:
[0136] 061: Invert the third configuration data, determine new target configuration data, and write it into configuration register 20.
[0137] In some embodiments, the processor may be configured to invert the target configuration data to obtain third configuration data; invert the third configuration data to determine new target configuration data, and write the new target configuration data into the configuration register 20 .
[0138] In some embodiments, the third determination module includes a seventh determination submodule, and the eighth determination module includes a sixth determination submodule. The seventh determination submodule may be configured to invert the target configuration data to obtain the third configuration data, and the eighth determination submodule may be configured to invert the third configuration data to determine the new target configuration data and write it into the configuration register 20.
[0139] Specifically, when the third configuration data is obtained by inverting the target configuration data, the third configuration data can be inverted to determine the new target configuration data, which is written into the configuration register 20 as the correct configuration data to achieve automatic correction of the configuration data in the configuration register 20.
[0140] Thus, when the target configuration data is inverted to obtain the third configuration data, the original target configuration data can be obtained by inverting the third configuration data. The target configuration data is written into the configuration register 20 as the new target configuration data to achieve automatic correction of the configuration data.
[0141] In one embodiment, based on the protection method of the embodiment of the present application, the abnormality detection process for the target configuration data stored in the configuration register 20 includes: the external configuration source 200 writes the target configuration data into the configuration register 20 .
[0142] After the configuration register 20 is written, the electronic device 100 inverts the target configuration data in the configuration register 20 through the data management module 13 and writes the inverted data into the first mirror register 11 and the second mirror register 15 respectively.
[0143] During operation, the electronic device 100 periodically compares the target configuration data in the configuration register 20 with the second configuration data obtained by inverting the first configuration data in the first mirror register 11 through a comparator, and inputs the comparison result into the data management module 13. The comparison and verification period can be set according to actual needs.
[0144] The data management module 13 in the electronic device 100 determines whether the target configuration data in the configuration register 20 is consistent with the second configuration data obtained by inverting the first configuration data in the first mirror register 11 .
[0145] If the check result is consistent, it can be determined that there is no abnormality in the configuration data stored in the configuration register 20 and the first mirror register 11. At this time, the next detection cycle can be entered to continue comparing the target configuration data in the configuration register 20 with the second configuration data to see if they are consistent.
[0146] If the check result is inconsistent, it is determined that the value in the configuration register 20 or the first mirror register 11 has changed abnormally and is inconsistent with the expected value. However, it is not possible to determine which of the two has caused the abnormality. Therefore, it is necessary to further compare and verify the target configuration data with the third configuration data stored in the second mirror register 15.
[0147] The electronic device 100 compares the target configuration data in the configuration register 20 with the fourth configuration data obtained by inverting the third configuration data in the second mirror register 15 through the data management module 13 to determine whether the values of the two are consistent.
[0148] If the check result is consistent, it can be determined that the value in the first mirror register 11 has changed, and the electronic device 100 needs to rewrite the correct value. Therefore, the electronic device 100 inverts the target configuration data in the configuration register 20 to obtain new first configuration data, and rewrites it into the first mirror register 11 under the register write instruction of the data management module 13. After the rewriting is completed, the next detection cycle begins, and the value in the configuration register 20 is compared with the second configuration data obtained by inverting the first configuration data stored in the first mirror register 11 to see if they are consistent.
[0149] If the check result is inconsistent, it can be determined that the value in the configuration register 20 has changed abnormally and needs to be rewritten to the correct value. Therefore, the electronic device 100 inverts the third configuration data in the second mirror register 15 through the data management module 13, and then writes it to the configuration register 20 under the register write instruction of the data management module 13. At this point, the electronic device 100 completes the entire process from abnormality detection to abnormality location and then automatic abnormality recovery.
[0150] An embodiment of the present application provides an electronic device 100 , which includes a configuration register 20 and a protection device 10 according to any of the above embodiments.
[0151] An embodiment of the present application provides a vehicle, which includes the electronic device according to the above embodiment, or the electronic device 100 according to the above embodiment.
[0152] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the steps of the method of any of the above embodiments are implemented.
[0153] An embodiment of the present application provides a computer program product, including a computer program, which implements the steps of any of the above embodiments when the computer program is executed by a processor.
[0154] In the description of this specification, the reference terms "one embodiment," "some embodiments," "illustrative embodiments," "example," "specific example," or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the exemplary expressions of the above terms do not necessarily refer to the same embodiment or example. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification, as well as features of different embodiments or examples, unless they are mutually inconsistent.
[0155] Furthermore, the term "connection" should be interpreted broadly. For example, it can include fixed connection, detachable connection, or integral connection; it can include direct connection, indirect connection through an intermediate medium, and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in this application based on the specific circumstances.
[0156] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.
[0157] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed in a different order than shown or discussed, including performing functions in a substantially simultaneous manner or in a reverse order depending on the functions involved, as should be understood by those skilled in the art to which the embodiments of the present application pertain.
[0158] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.
Claims
1. A protection device for a configuration register, characterized in that: The configuration register is configured to store target configuration data, and the protection device includes: a first mirror register, wherein the first mirror register is configured to store first configuration data, where the first configuration data is determined according to the target configuration data; A comparison module is configured to determine an abnormal state of the configuration register according to the first configuration data and the target configuration data.
2. The protection device according to claim 1, characterized in that The protection device further comprises: an inverter configured to invert the target configuration data to obtain the first configuration data; and invert the first configuration data to obtain second configuration data; The comparison module is further configured to compare the second configuration data with the target configuration data.
3. The protection device according to claim 1, characterized in that: The protection device further comprises: A second mirror register, wherein the second mirror register is configured to store third configuration data, and the third configuration data is determined based on the target configuration data; when it is determined that the configuration register may be in an abnormal state, the third configuration data is used to determine an abnormal register with an abnormality, and the abnormal register includes the configuration register and the first mirror register.
4. The protection device according to claim 3, characterized in that: In the case where it is determined that an exception occurs in the exception register, the third configuration data is used to determine new configuration data, and the new configuration data is used to write into the exception register.
5. The protection device according to claim 1, characterized in that: The protection device further comprises: A data management module is configured to determine the first configuration data according to the target configuration data, and write the first configuration data into the first mirror register.
6. A method for protecting a configuration register, characterized in that: The protection method is based on the protection device according to any one of claims 1 to 5, and the protection method includes: determining first configuration data according to the target configuration data stored in the configuration register; An abnormal state of the configuration register is determined based on the first configuration data and the stored target configuration data.
7. The protection method according to claim 6, characterized in that: The determining the first configuration data according to the target configuration data stored in the configuration register includes: The target configuration data is inverted to determine the first configuration data.
8. The protection method according to claim 6, characterized in that: The determining, according to the first configuration data and the stored target configuration data, an abnormal state of the configuration register includes: Inverting the first configuration data to obtain second configuration data; The second configuration data is compared with the target configuration data to determine an abnormal state of the configuration register.
9. The protection method according to claim 8, characterized in that: The comparing the second configuration data with the target configuration data to determine the abnormal state of the configuration register includes: When the second configuration data is different from the target configuration data, it is determined that an abnormality may exist in the configuration register.
10. The protection method according to claim 9, characterized in that: The protection method further comprises: determining third configuration data according to the target configuration data stored in the configuration register; In the case that the configuration register may be abnormal, the actual abnormal state of the configuration register is determined according to the third configuration data and the target configuration data.
11. The protection method according to claim 10, characterized in that: The second configuration data is stored in a first mirror register, and determining the actual abnormal state of the configuration register according to the third configuration data and the target configuration data includes: Inverting the third configuration data to obtain fourth configuration data; When the fourth configuration data and the target configuration data are different, determining that an abnormality actually exists in the configuration register; When the fourth configuration data is identical to the target configuration data, it is determined that there is no abnormality in the configuration register and there is an abnormality in the first mirror register.
12. The protection method according to claim 10, characterized in that: The protection method further comprises: When it is determined that the configuration register is truly abnormal, new target configuration data is determined according to the third configuration data and written into the configuration register.
13. The protection method according to claim 10, characterized in that: The determining the third configuration data according to the target configuration data stored in the configuration register includes: inverting the target configuration data to obtain the third configuration data; The determining new target configuration data according to the third configuration data and writing the new target configuration data into the configuration register includes: The third configuration data is inverted to determine new target configuration data, and written into the configuration register.
14. An electronic device, characterized in that: The electronic device comprises a configuration register and a protection device according to any one of claims 1 to 5.
15. An electronic device, characterized in that: The electronic device includes one or more processors and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the steps of the method according to any one of claims 6 to 13 are implemented.
16. A vehicle, characterized in that: The vehicle comprises the electronic device according to claim 14 or the electronic apparatus according to claim 15 .
17. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 6 to 13 are implemented.
18. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 6 to 13 are implemented.