Chip, method and device for isolating safety island and storage medium
By setting up a bus gasket module and an asynchronous bridge control module in the bus system between the security island and the main domain, the security asynchronous bridge module is controlled to enter the refresh mode using the refresh signal, which solves the impact of the main domain reset operation on the security island and realizes data security and normal operation isolation.
Patent Information
- Application Number
- CN202510578736.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-08-19
AI Technical Summary
When the prior art performs reset operations in the main domain, it is impossible to ensure the high-speed bus performance of the secure island while preventing its data security and normal operation.
By setting up a bus gasket module, an asynchronous bridge control module and a safety asynchronous bridge module between the security island and the main domain, the security asynchronous bridge module is used to make the security asynchronous bridge module enter the refresh mode by using the reset request signal and the refresh signal, turning off the reset control unit and the clock control unit, and preventing data interaction.
Effectively isolate the data interaction between the security island and the main domain, protect the data security and normal operation of the security island, and avoid the impact of the main domain operations on it.
Smart Images

Figure CN120509060A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of chip technology, and in particular to a chip, method, device and storage medium for isolating a security island. Background Art
[0002] Currently, the chip technology field involves chips with relatively high safety requirements. For example, in-vehicle chips used in autonomous driving often integrate two independent domains: a safety island and a main domain, forming a system-on-a-chip (SoC). To ensure independence, the safety island and the main domain have independent power supplies, clocks, and resets. To ensure communication performance between the safety island and the main domain, they are connected not only by high-speed peripherals but also by high-speed buses. For example, the Advanced Microcontroller Bus Architecture (AMBA) and AXI (Advanced eXtensible Interface) are used to connect the two domains. As a domain with a relatively high security level, isolating the safety island is a common method to protect it, preventing errors in the main domain from affecting it.
[0003] In related technologies, when the main domain needs to be reset, in order to isolate the safety island, the safety island is controlled to perform the reset operation together with the main domain; or the high-speed bus between the safety island and the main domain is removed, that is, only the peripheral protocol is used for transmission.
[0004] However, the above method cannot ensure that the safety island has high-speed bus performance while also ensuring that the reset operation of the main domain will not affect the security of the data in the safety island and normal operation. Summary of the Invention
[0005] The present invention provides a chip, method, device, and storage medium for isolating a security island. These chips can put the security island into refresh mode when the primary domain is reset, preventing the security island from interacting with the primary domain and ensuring data security and normal operation. The technical solution is as follows:
[0006] According to a first aspect of an embodiment of the present application, a chip for isolating a security island is provided, including:
[0007] An electrically connected safety island and a main domain; the safety island comprises a bus gasket module, an asynchronous bridge control module and a safety asynchronous bridge module which are electrically connected in sequence; the main domain comprises a main asynchronous bridge module; the main asynchronous bridge module is electrically connected to the safety asynchronous bridge module;
[0008] The main domain is used to pull high the reset request signal;
[0009] The bus gasket module is configured to pull up a refresh signal in response to the reset request signal;
[0010] The safety asynchronous bridge module is used to enter the first refresh mode in response to the refresh signal being pulled high, and to turn off the reset control unit and the clock control unit; the reset control unit and the clock control unit are arranged inside the safety asynchronous bridge module; the reset control unit is used to control the opening and closing of the reset unit of the safety asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safety asynchronous bridge module.
[0011] In a possible implementation, when the master domain passively needs to be reset, the master domain is configured to pull up the reset request signal when detecting that a fault occurs on the chip;
[0012] The bus gasket module is configured to pull up the refresh signal in response to the reset request signal;
[0013] The safety asynchronous bridge module is configured to enter a first refresh mode in response to the refresh signal and turn off the reset control unit and the clock control unit;
[0014] The safety asynchronous bridge module is further used to pull up the trigger confirmation signal;
[0015] The master domain is further configured to perform a reset operation in response to the trigger confirmation signal;
[0016] The master domain is further configured to pull up a status signal; the status signal indicates that the master domain has completed reset release;
[0017] The secure asynchronous bridge module is further configured to exit the first refresh mode in response to the status signal;
[0018] The bus gasket module is further used to pull down the refresh signal;
[0019] The safety asynchronous bridge module is further configured to turn on the reset control unit and the clock control unit in response to the refresh signal being pulled low.
[0020] In a possible implementation, when the master domain actively performs a reset operation, the master domain is configured to actively pull up the reset request signal.
[0021] In a possible implementation, when it is necessary to shut down the bus between the safety island and the main domain, the safety island is configured to send a shutdown signal to the main domain;
[0022] The master domain is further configured to shut down the second clock unit of the master asynchronous bridge module in response to the shutdown signal;
[0023] The primary domain is further configured to send a feedback signal to the safety island;
[0024] The safety island is further configured to send a first trigger signal to the bus gasket module in response to the feedback signal;
[0025] The bus gasket module is further configured to pull up the refresh signal in response to the first trigger signal;
[0026] The asynchronous bridge control module is further configured to enter the first refresh mode in response to the refresh signal and turn off the reset control unit and the clock control unit.
[0027] In a possible implementation, the safety island is further configured to send the shutdown signal to the main domain in a non-bus manner.
[0028] In a possible implementation, when the master domain needs to be powered off, the master domain is further configured to shut down the second clock unit of the master asynchronous bridge module;
[0029] The main domain is further configured to send a power-off notification signal to the safety island;
[0030] The safety island is further configured to send a second trigger signal to the bus gasket module in response to the power-off notification signal;
[0031] The bus gasket module is further configured to pull up the refresh signal in response to the second trigger signal;
[0032] The asynchronous bridge control module is further configured to enter the first refresh mode in response to the refresh signal and turn off the reset control unit and the clock control unit;
[0033] The safety island is also used to control the power isolation module to enter the power isolation mode; the power isolation module is arranged inside the safety island.
[0034] In a possible implementation, the system further includes a peripheral device; the peripheral device is electrically connected to the security island and the main domain respectively;
[0035] The power isolation module is used to isolate all signals transmitted from the main domain to the safety island;
[0036] The safety island is also used to pull up the power-off signal;
[0037] The peripheral device is configured to control the main domain to power off in response to the power-off signal.
[0038] In a possible implementation, the bus gasket module is further configured to, after pulling up the refresh signal, pull up a preset signal if a signal requesting access to the main domain from the safety island is received.
[0039] In a possible implementation, the safety island is further configured to send a second trigger signal to the bus gasket module;
[0040] The bus gasket module is further configured to enter a second refresh mode in response to the second trigger signal, and pull up a preset signal if a signal requesting access to the main domain is received.
[0041] According to a second aspect of an embodiment of the present application, a method for isolating a safety island is provided, comprising:
[0042] Pull high the reset request signal;
[0043] In response to the reset request signal, pulling up a refresh signal;
[0044] In response to the refresh signal being pulled high, the first refresh mode is entered, and the reset control unit and the clock control unit are turned off; the reset control unit and the clock control unit are arranged inside the asynchronous bridge control module; the reset control unit is used to control the opening and closing of the reset unit of the safety asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safety asynchronous bridge module.
[0045] According to the third aspect of an embodiment of the present application, a computer device is provided, which includes a processor and a memory, wherein the memory is used to store at least one program, and the at least one program is loaded by the processor and executes the method of isolating a safety island.
[0046] According to the fourth aspect of an embodiment of the present application, a computer-readable storage medium is provided, in which at least one program is stored. The at least one program is loaded and executed by a processor to implement the method of isolating a safety island.
[0047] In an embodiment of the present application, an embodiment of the present application provides a method for isolating a safety island, including an electrically connected safety island and a main domain; the safety island includes a bus gasket module, an asynchronous bridge control module and a safety asynchronous bridge module electrically connected in sequence; the main domain includes a main asynchronous bridge module; the main asynchronous bridge module is electrically connected to the safety asynchronous bridge module; the main domain pulls up a reset request signal; the bus gasket module pulls up a refresh signal in response to the reset request signal; the safety asynchronous bridge module enters a first refresh mode in response to the pulled-up refresh signal, and turns off the reset control unit and the clock control unit; the reset control unit and the clock control unit are arranged inside the asynchronous bridge control module; the reset control unit is used to control the opening and closing of the reset unit of the safety asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safety asynchronous bridge module. The above technical solution sets up a bus gasket module. When the main domain needs to perform a reset operation, the bus gasket module pulls up the refresh signal, and the asynchronous bridge control module enters the refresh mode in response to the refresh signal, turns off the clock control unit and the reset control unit, and also turns off the safety asynchronous bridge module, thereby preventing the safety asynchronous bridge module from interacting with the main asynchronous bridge module, and further preventing data interaction between the safety island and the main domain, thus avoiding the reset operation of the main domain from polluting the data of the safety island and affecting the normal operation of other parts of the safety island. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0049] Figure 1 is a schematic diagram of an implementation environment provided according to an embodiment of the present application;
[0050] Figure 2 1 is a schematic structural diagram of a chip for isolating a safety island according to an embodiment of the present application;
[0051] Figure 3 This is a first exemplary structural diagram of a chip for isolating a safety island according to an embodiment of the present application;
[0052] Figure 4 2 is a schematic diagram of a second exemplary structure of a chip for isolating a safety island according to an embodiment of the present application;
[0053] Figure 5 3 is a schematic diagram of a third exemplary structure of a chip for isolating a safety island according to an embodiment of the present application;
[0054] Figure 61 is a flow chart of a method for isolating a safety island according to an embodiment of the present application;
[0055] Figure 7 is a schematic structural diagram of a terminal provided according to an embodiment of the present application;
[0056] Figure 8 It is a structural diagram of a server provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0057] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0058] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different drawings represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with this application.
[0059] In this application, the terms "first," "second," and the like are used to distinguish identical or similar items having substantially the same role and function. It should be understood that "first," "second," and "nth" do not have a logical or temporal dependency, nor do they limit the quantity or execution order. It should also be understood that although the following description uses the terms "first," "second," and the like to describe various elements, these elements should not be limited by these terms.
[0060] These terms are simply used to distinguish one element from another. For example, without departing from the scope of various examples, a first action can be referred to as a second action, and similarly, a second action can also be referred to as a first action. Both the first action and the second action can be actions, and in some cases, can be separate and different actions.
[0061] Here, at least one refers to one or more than one. For example, at least one action can be one action, two actions, three actions, or any other action that is an integer greater than or equal to one. And multiple refers to two or more than two. For example, multiple actions can be two actions, three actions, or any other action that is an integer greater than or equal to two.
[0062] Figure 1 10 is a schematic diagram of an implementation environment provided according to an embodiment of the present application, which may include a terminal 101 and a server 102.
[0063] Terminal 101 is provided with a chip that includes a main domain and a safety island. For example, terminal 101 may be a vehicle-mounted terminal with a chip, used in the field of autonomous driving, thereby ensuring the safety of autonomous driving by protecting the data security of the safety island.
[0064] The server 102 may be a single server, a server cluster consisting of multiple servers, or a cloud processing center.
[0065] The terminal 101 is connected to the server 102 via a wired or wireless network.
[0066] In some embodiments, the wireless network or wired network uses standard communication technologies and / or protocols. The network is typically the Internet, but can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or any combination of a virtual private network. In some embodiments, technologies and / or formats including Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above-mentioned data communication technologies.
[0067] In related technologies, in some scenarios, the primary domain may need to be reset actively or passively. When the primary domain needs to be reset, in order to isolate the safety island, the control safety island is reset together with the primary domain; or the high-speed bus between the safety island and the primary domain is removed, that is, only peripheral protocol transmission is used. However, the above methods cannot guarantee the safety island has high-speed bus performance while also ensuring that the reset of the primary domain will not affect the safety and normal operation of the safety island. In addition, in other scenarios, the primary domain may need to perform operations such as power down. If the main domain and the safety island are powered down together, the normal operation of the safety island will be affected.
[0068] In order to solve the above technical problems, an embodiment of the present application provides a chip for isolating the safety island 201, including the safety island 201 and the main domain 202 electrically connected through a bus; when the main domain 202 needs to perform a reset operation or power-off operation, the safety island 201 enters a refresh mode, so that there is no data interaction between the safety island 201 and the main domain 202, thereby achieving protection of the data of the safety island 201.
[0069] Data exchange between the safety island 201 and the main domain 202 is performed via a bus. Optionally, the safety island 201 includes a safety asynchronous bridge module 2013, and the main domain 202 includes a master asynchronous bridge module 2021. Both the master asynchronous bridge module 2021 and the safety asynchronous bridge module 2013 are provided on the bus. Thus, the master asynchronous bridge module 2021 and the safety asynchronous bridge module 2013 exchange data, thereby enabling data exchange between the safety island 201 and the main domain 202. It is understood that if data exchange between the master asynchronous bridge module 2021 and the safety asynchronous bridge module 2013 is blocked, data exchange between the safety island 201 and the main domain 202 is also blocked. Therefore, when the main domain 202 needs to perform some operations, but these operations may affect the security of the data in the safety island 201, the data interaction between the safety island 201 and the main domain 202 can be prevented by preventing the data interaction between the safety asynchronous bridge module 2013 and the main asynchronous bridge module 2021, and then the main domain 202 can be allowed to perform some operations. In this way, the impact of the operations performed by the main domain 202 on the data in the safety island 201 can be isolated, thereby ensuring the security of the data in the safety island 201 and normal operation.
[0070] Figure 2 This is a schematic diagram of the structure of a chip 200 for isolating a safety island 201 according to an embodiment of the present application. The device includes: an electrically connected safety island 201 and a main domain 202; the safety island 201 includes a bus shim module 2011, an asynchronous bridge control module 2012, and a safety asynchronous bridge module 2013, which are electrically connected in sequence; the main domain 202 includes a main asynchronous bridge module 2021; and the main asynchronous bridge module 2021 is electrically connected to the safety asynchronous bridge module 2013. Both the safety island 201 and the main domain 202 exist in the form of hardware.
[0071] Figure 3 This is a first example structural diagram of a chip for isolating a safety island 201 provided according to an embodiment of the present application.
[0072] The following combination Figure 3 An example description is given of a chip that isolates the safety island 201 .
[0073] In some embodiments, the bus shim module 2011 is set on the bus, and when the security island 201 needs to access the main domain 202, the relevant data flow needs to pass through the bus shim module 2011. The bus shim module 2011 exists in the form of hardware. It should be noted that the main domain 202 includes multiple first application modules, and the security island 201 also includes multiple second application modules. Data can be exchanged between multiple first application modules, and data can also be exchanged between multiple second application modules. Some first application modules can also exchange data with some second application modules. When some first application modules are blocked from exchanging data with some second application modules, it does not affect the data exchange between other first application modules and other second application modules. That is, after the data exchange between the security island 201 and the main domain 202 is blocked, the security island 201 can still operate normally.
[0074] In some embodiments, the chip includes a main domain 202 and a security island 201. The chip also includes a first top-level application, so that the operation of the main domain 202 and the security island 201 can be controlled by the first top-level application. The first top-level application can also be understood as software.
[0075] In some embodiments, the master domain 202 is configured to pull a reset request signal high; the bus shim module 2011 is configured to pull a refresh signal high in response to the reset request signal; the secure asynchronous bridge module 2013 is configured to enter a first refresh mode in response to the pulled refresh signal and disable the reset control unit 20122 and the clock control unit 20121; the reset control unit 20122 and the clock control unit 20121 are disposed within the asynchronous bridge control module 2012; the reset control unit 20122 is configured to control the activation and deactivation of the reset unit 20132 of the secure asynchronous bridge module 2013; and the clock control unit 20121 is configured to control the activation and deactivation of the first clock unit 20131 of the secure asynchronous bridge module 2013. Pulling the reset request signal high activates the reset request signal, while pulling the reset request signal low deactivates the reset request signal. Optionally, the asynchronous bridge control module 2012 first disables the clock control unit 20121 and then the reset control unit 20122.
[0076] In one example, after the asynchronous bridge control module 2012 turns on the reset control unit 20122, the reset control unit 20122 is in the turned-on state. Alternatively, if the reset control unit 20122 pulls the reset signal high, the reset unit 20132 performs a reset operation in response to the reset signal. After the reset control unit 20122 pulls the reset signal low, i.e., after the reset release operation is completed, the reset of the safety asynchronous bridge module 2013 is achieved. Alternatively, after the asynchronous bridge control module 2012 turns off the reset control unit 20122, the reset control unit 20122 is in the turned-off state.
[0077] In one example, after the asynchronous bridge control module 2012 turns on the clock control unit 20121, the clock control unit 20121 is in the on state. Optionally, if the clock control unit 20121 pulls up the clock signal, the first clock unit 20131 operates normally, and the secure asynchronous bridge module 2013 also operates normally. This means that the secure asynchronous bridge exchanges data with the master asynchronous bridge module 2021. Optionally, after the asynchronous bridge control module 2012 turns off the clock control unit 20121, because the clock control unit 20121 cannot send a clock signal to the first clock unit 20131, the first clock unit 20131 is turned off, and the secure asynchronous bridge module 2013 is also turned off. This means that the secure asynchronous bridge module 2013 cannot exchange data with the master asynchronous bridge module 2021, thereby preventing data exchange between the secure island 201 and the primary domain 202. This, in turn, isolates the secure island 201 and protects the data within the secure island 201. Optionally, the asynchronous bridge control module 2012 first turns on the reset control unit 20122 , and then turns on the clock control unit 20121 after completing the reset release operation.
[0078] In one example, the master asynchronous bridge module 2021 is provided with a second clock unit 20211. The master domain 202 controls the opening and closing of the master asynchronous bridge module 2021 by controlling the opening and closing of the second clock unit 20211, thereby controlling the data interaction with the safety island 201.
[0079] In one example, the bus shim module 2011 is further configured to, after raising the refresh signal, raise a preset signal, i.e., return a preset signal, if it receives a signal from the security island 201 requesting access to the main domain 202, to prevent the security island 201 from accessing the unsecure main domain 202 and thereby contaminating the data in the security island 201. The preset signal can be implemented in various forms, for example, any one of 0x0, 0xFFFF, and 0xDEADBEAF.
[0080] In some embodiments, when the main domain 202 needs to be reset passively, the main domain 202 is used to pull up the reset request signal when a chip fault is detected; the bus gasket module 2011 is used to pull up the refresh signal in response to the reset request signal; the safe asynchronous bridge module 2013 is used to enter the first refresh mode in response to the refresh signal, and turn off the reset control unit 20122 and the clock control unit 20121; the safe asynchronous bridge module 2013 is also used to pull up the trigger confirmation signal; the main domain 202 is also used to perform a reset operation in response to the trigger confirmation signal; the main domain 202 is also used to pull up the status signal; the status signal indicates that the main domain 202 has completed the reset release; the safe asynchronous bridge module 2013 is also used to exit the first refresh mode in response to the status signal; the bus gasket module 2011 is also used to pull down the refresh signal; the safe asynchronous bridge module 2013 is also used to turn on the reset control unit 20122 and the clock control unit 20121 in response to the pulled-down refresh signal.
[0081] In one example, a detection module is provided in master domain 202 to detect whether a chip failure has occurred. If a chip failure is detected, master domain 202 proactively pulls a reset request signal high, indicating that the chip failure requires a reset. Alternatively, if the detection module does not detect a chip failure, master domain 202 does not pull the reset request signal high, indicating that the reset request signal remains inactive. Chip failures can occur in various ways, such as when a chip acquires erroneous data.
[0082] In some embodiments, when the master domain 202 actively performs a reset operation, the master domain 202 is configured to actively pull a reset request signal high. The master domain 202 may actively perform a reset operation in various scenarios. For example, when the master domain 202 obtains erroneous data, the master domain 202 actively performs a reset operation, i.e., the master domain 202 actively pulls a reset request signal high.
[0083] Combined with the above analysis, it can be seen that whether in the scenario where the main domain 202 needs to actively perform a reset operation or in the scenario where the main domain 202 needs to passively perform a reset operation, the bus between the safety island 201 and the main domain 202 is in a clean state, thereby ensuring the security of the data in the safety island 201.
[0084] Figure 4 This is a second example structural diagram of a chip for isolating a safety island 201 provided according to an embodiment of the present application.
[0085] The following combination Figure 4 An example description is given of a chip that isolates the safety island 201 .
[0086] In some embodiments, when it is necessary to shut down the bus between the safety island 201 and the main domain 202, the safety island 201 is used to send a shutdown signal to the main domain 202; the main domain 202 is also used to shut down the second clock unit 20211 of the main asynchronous bridge module 2021 in response to the shutdown signal; the main domain 202 is also used to send a feedback signal to the safety island 201; the safety island 201 is also used to send a first trigger signal to the bus gasket module 2011 in response to the feedback signal; the bus gasket module 2011 pulls up the refresh signal in response to the first trigger signal; the asynchronous bridge control module 2012 is also used to enter the first refresh mode in response to the refresh signal, and shut down the reset control unit 20122 and the clock control unit 20121.
[0087] In one example, when the bus between the safety island 201 and the main domain 202 needs to be shut down and the safety island 201 and the main domain 202 do not need to perform a global reset operation, the first top-level application determines that there is no communication between the safety island 201 and the main domain 202. The global reset operation can be understood as requiring a reset operation for the safety island 201 but not for the main domain 202.
[0088] In one example, the safety island 201 is provided with a second top-level application. The main domain 202 is provided with a third top-level application. The safety island 201 sends a shutdown signal to the main domain 202 via a non-bus method. In response to the shutdown signal, the third top-level application turns off the second clock unit 20211 of the main asynchronous bridge. After completing the shutdown operation, the third top-level application sends a feedback signal to the software of the safety island 201. In response to the feedback signal, the second top-level application sends a refresh signal to the bus gasket module 2011. The bus gasket module 2011 pulls up the refresh signal in response to the first trigger signal. The asynchronous bridge control module 2012 enters the refresh mode in response to the refresh signal, and turns off the clock control unit 20121 and the reset control unit 20122. Among them, the non-bus method can be implemented in various forms. For example, a serial peripheral interface (SPI). In this scenario, the data of the safety island 201 will not be affected by the main domain 202, and the safety island 201 can continue to operate normally. In addition, since the bus between the safety island 201 and the main domain 202 is closed, the asynchronous bridge control module 2012 of the safety island 201 does not need to exit the refresh mode, which can ensure that there is no data interaction between the safety island 201 and the main domain 202.
[0089] Figure 5 This is a third example structural diagram of a chip for isolating a safety island 201 provided according to an embodiment of the present application.
[0090] The following combination Figure 5 An example description is given of a chip that isolates the safety island 201 .
[0091] In some embodiments, when the main domain 202 needs to be powered off, the main domain 202 is also used to turn off the second clock unit 20211 of the main asynchronous bridge module 2021; the main domain 202 is also used to send a power-off notification signal to the safety island 201; the safety island 201 is also used to send a second trigger signal to the bus gasket module 2011 in response to the power-off notification signal; the bus gasket module 2011 pulls up the refresh signal in response to the second trigger signal; the asynchronous bridge control module 2012 is also used to enter the first refresh mode in response to the refresh signal, and turn off the reset control unit 20122 and the clock control unit 20121; the safety island 201 is also used to control the power isolation module 2014 to enter the power isolation mode; the power isolation module 2014 is arranged inside the safety island 201.
[0092] In one example, when the main domain 202 needs to be powered off, but the safety island 201 still needs to operate normally, it is necessary to ensure that the power off of the main domain 202 does not affect the normal operation of the safety island 201. To solve this problem, an embodiment of the present application controls the power isolation module 2014 to enter the working mode. Specifically, the main domain 202 processes most of the first application modules that need to be shut down according to the power-off process, and then shuts down the second clock unit 20211 of the main asynchronous bridge module 2021. The third top-level application sends a power-off notification signal to the main domain 202. In response to the power-off notification signal, the second top-level application sends a first trigger signal to the bus gasket module 2011. In response to the first trigger signal, the bus gasket module 2011 pulls up the refresh signal. In response to the refresh signal, the asynchronous bridge control module 2012 enters the refresh mode and shuts down the clock control unit 20121 and the reset control unit 20122.
[0093] In some embodiments, peripheral devices are also included; the peripheral devices are electrically connected to the safety island 201 and the main domain 202 respectively; the power isolation module 2014 is used to isolate all signals transmitted from the main domain 202 to the safety island 201; the safety island 201 is also used to pull up the power-off signal; the peripheral device is used to control the power-off of the main domain 202 in response to the power-off signal. Among them, the peripheral device is independent of the chip of the isolated safety island 201 involved in this application, and can be implemented in various forms. For example, the peripheral device is implemented based on a power management chip (Management Integrated Circuit Chip, PMIC).
[0094] In some embodiments, the security island 201 is also used to send a second trigger signal to the bus gasket module 2011; the bus gasket module 2011 is also used to enter the second refresh mode in response to the second trigger signal, and if a signal requesting access to the main domain 202 is received, the preset signal is pulled high.
[0095] In one example, the security island 201 sends a second trigger signal to the bus shim module 2011 through the second top-level application. In this scenario, the bus shim module 2011 enters the second refresh mode. The second refresh mode can be understood as not requiring the refresh signal to be pulled high, thereby eliminating the need for the asynchronous bridge control module 2012 to enter the first refresh mode. Since the data flow needs to pass through the bus shim module 2011 when the security island 201 and the main domain 202 are interacting with each other, and after the bus shim module 2011 enters the second refresh mode, the bus shim module 2011 prevents the data flow from accessing the main domain 202. Therefore, after the bus shim module 2011 enters the second refresh mode, it prevents the security island 201 and the main domain 202 from interacting with each other, thereby ensuring the security of the data in the security island 201.
[0096] It should be noted that: when the chip of the isolated safety island 201 provided in the above embodiment executes the corresponding steps, it only uses the division of the above functional modules as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0097] An embodiment of the present application includes an electrically connected safety island and a main domain; the safety island includes a bus gasket module, an asynchronous bridge control module and a safety asynchronous bridge module that are electrically connected in sequence; the main domain includes a main asynchronous bridge module; the main asynchronous bridge module is electrically connected to the safety asynchronous bridge module; the main domain pulls up a reset request signal; the bus gasket module pulls up a refresh signal in response to the reset request signal; the safety asynchronous bridge module enters a first refresh mode in response to the pulled-up refresh signal, and turns off the reset control unit and the clock control unit; the reset control unit and the clock control unit are arranged inside the asynchronous bridge control module; the reset control unit is used to control the opening and closing of the reset unit of the safety asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safety asynchronous bridge module. The above technical solution sets up a bus gasket module. When the main domain needs to perform a reset operation, the bus gasket module pulls up the refresh signal, and the asynchronous bridge control module enters the refresh mode in response to the refresh signal, turns off the clock control unit and the reset control unit, and also turns off the safety asynchronous bridge module, thereby preventing the safety asynchronous bridge module from interacting with the main asynchronous bridge module, and further preventing data interaction between the safety island and the main domain, thus avoiding the reset operation of the main domain from polluting the data of the safety island and affecting the normal operation of other parts of the safety island.
[0098] Figure 6 FIG. 1 is a flow chart of a method for isolating a safety island according to an embodiment of the present application. Figure 6 As shown, in the embodiment of the present application, the application is described as an example of a terminal with a chip. The method includes the following steps:
[0099] In step 601, the terminal pulls high a reset request signal;
[0100] In step 602, the terminal responds to the reset request signal by pulling up the refresh signal;
[0101] In step 603, the terminal enters a first refresh mode in response to the refresh signal being pulled high, and turns off the reset control unit and the clock control unit.
[0102] Among them, the reset control unit and the clock control unit are arranged inside the asynchronous bridge control module; the reset control unit is used to control the opening and closing of the reset unit of the safe asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safe asynchronous bridge module.
[0103] In some embodiments, when the main domain needs to be reset passively, the main domain is used to pull up the reset request signal when a chip failure is detected; the bus gasket module is used to pull up the refresh signal in response to the reset request signal; the safety asynchronous bridge module is used to enter the first refresh mode in response to the refresh signal, and turn off the reset control unit and the clock control unit; the safety asynchronous bridge module is also used to pull up the trigger confirmation signal; the main domain is also used to perform a reset operation in response to the trigger confirmation signal; the main domain is also used to pull up the status signal; the status signal indicates that the main domain has completed the reset release; the safety asynchronous bridge module is also used to exit the first refresh mode in response to the status signal; the bus gasket module is also used to pull down the refresh signal; the safety asynchronous bridge module is also used to turn on the reset control unit and the clock control unit in response to the pulled-down refresh signal.
[0104] In some embodiments, when the master domain actively performs a reset operation, the master domain is configured to actively pull up a reset request signal.
[0105] In some embodiments, when it is necessary to shut down the bus between the safety island and the main domain, the safety island is configured to send a shutdown signal to the main domain;
[0106] The master domain is further configured to shut down the second clock unit of the master asynchronous bridge module in response to a shutdown signal;
[0107] The main domain is also used to send feedback signals to the safety island;
[0108] The safety island is further configured to send a first trigger signal to the bus gasket module in response to the feedback signal;
[0109] The bus gasket module is further configured to pull up the refresh signal in response to the first trigger signal;
[0110] The asynchronous bridge control module is further configured to enter a first refresh mode in response to a refresh signal and turn off the reset control unit and the clock control unit.
[0111] In some embodiments, the safety island is further used to send a shutdown signal to the main domain in a non-bus manner.
[0112] In some embodiments, when the master domain needs to be powered off, the master domain is further configured to shut down the second clock unit of the master asynchronous bridge module;
[0113] The main domain is also used to send power failure notification signals to the safety island;
[0114] The safety island is further configured to send a second trigger signal to the bus gasket module in response to the power-off notification signal;
[0115] The bus gasket module is further configured to pull up the refresh signal in response to the second trigger signal;
[0116] The asynchronous bridge control module is further configured to enter a first refresh mode in response to a refresh signal and turn off the reset control unit and the clock control unit;
[0117] The safety island is also used to control the power isolation module to enter the power isolation mode; the power isolation module is arranged inside the safety island.
[0118] In some embodiments, a peripheral device is further included; the peripheral device is electrically connected to the security island and the main domain respectively;
[0119] Power isolation module, used to isolate all signals transmitted from the main domain to the safety island;
[0120] Safety island, also used to pull up the power-off signal;
[0121] The peripheral device is used for controlling the main domain to power off in response to the power-off signal.
[0122] In some embodiments, the bus gasket module is further configured to pull up a preset signal if a safety island request to access the main domain signal is received after the refresh signal is pulled up.
[0123] In some embodiments, the safety island is also used to send a second trigger signal to the bus gasket module; the bus gasket module is also used to enter the second refresh mode in response to the second trigger signal, and if a request to access the main domain signal is received, the preset signal is pulled high.
[0124] It should be noted that the chip for isolating the safety island provided in the above embodiments and the method embodiment for isolating the safety island belong to the same concept. The specific implementation process is detailed in the chip embodiment and will not be repeated here.
[0125] In an embodiment of the present application, a bus gasket module is provided. When the main domain needs to perform a reset operation, the bus gasket module pulls up the refresh signal, and the asynchronous bridge control module enters the refresh mode in response to the refresh signal, turns off the clock control unit and the reset control unit, that is, turns off the safety asynchronous bridge module, thereby preventing the safety asynchronous bridge module from interacting with the main asynchronous bridge module, and further preventing data interaction between the safety island and the main domain, thereby avoiding the reset operation of the main domain from polluting the data of the safety island and affecting the normal operation of other parts of the safety island.
[0126] An embodiment of the present application further provides a computer device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and the processor implements the above method when executing the computer program.
[0127] Taking computer equipment as the terminal as an example, Figure 7 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present application, see Figure 7 Terminal 700 may be a smartphone, tablet computer, MP3 player (Moving Picture Experts Group Audio Layer III), MP4 player (Moving Picture Experts Group Audio Layer IV), laptop computer, or desktop computer. Terminal 700 may also be referred to as user equipment, portable terminal, laptop terminal, desktop terminal, or other similar names.
[0128] Typically, the terminal 700 includes a processor 701 and a memory 702 .
[0129] The processor 701 may include one or more processing cores, such as a 4-core processor, a 5-core processor, etc. The processor 701 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 701 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 701 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 701 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0130] The memory 702 may include one or more computer-readable storage media, which may be non-transitory. The memory 702 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 702 is used to store at least one program code, which is used to be executed by the processor 701 to implement the process for terminal execution in the above method provided in the method embodiment of the present application.
[0131] In some embodiments, terminal 700 may also optionally include a peripheral device interface 703 and at least one peripheral device. Processor 701, memory 702, and peripheral device interface 703 may be connected via a bus or signal lines. Each peripheral device may be connected to peripheral device interface 703 via a bus, signal lines, or circuit boards. Specifically, the peripheral device may include at least one of a display screen 704, a camera assembly 705, an audio circuit 706, and a power supply 707.
[0132] The peripheral device interface 703 can be used to connect at least one I / O (Input / Output)-related peripheral device to the processor 701 and the memory 702. In some embodiments, the processor 701, the memory 702, and the peripheral device interface 703 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 701, the memory 702, and the peripheral device interface 703 can be implemented on separate chips or circuit boards, which is not limited in this embodiment of the present application.
[0133] Display screen 704 is used to display a user interface (UI). This UI may include graphics, text, icons, videos, or any combination thereof. If display screen 704 is a touchscreen display, it is also capable of collecting touch signals on or above the surface of display screen 704. These touch signals can be input as control signals to processor 701 for processing. Display screen 704 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be a single display screen 704, located on the front panel of terminal 700. In other embodiments, there may be at least two display screens 704, located on different surfaces of terminal 700 or in a foldable design. In still other embodiments, display screen 704 may be a flexible display screen, located on a curved or foldable surface of terminal 700. Display screen 704 can also be configured as a non-rectangular, irregular shape, also known as a special-shaped screen. Display screen 704 can be made of materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).
[0134] The camera assembly 705 is used to capture images or videos. In some embodiments, the camera assembly 705 includes a front camera and a rear camera. Typically, the front camera is arranged on the front panel of the terminal, and the rear camera is arranged on the back of the terminal. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth of field camera, a wide-angle camera, and a telephoto camera, so as to realize the fusion of the main camera and the depth of field camera to realize the background blur function, the fusion of the main camera and the wide-angle camera to realize panoramic shooting and VR (Virtual Reality) shooting function or other fusion shooting functions. In some embodiments, the camera assembly 705 may also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm light flash and a cold light flash, which can be used for light compensation at different color temperatures.
[0135] The audio circuit 706 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, and convert the sound waves into electrical signals to be input into the processor 701 for processing. For the purpose of stereo sound collection or noise reduction, there can be multiple microphones, which are respectively arranged at different parts of the terminal 700. The microphone can also be an array microphone or an omnidirectional collection microphone. The speaker is used to convert the electrical signal from the processor 701 into sound waves. The speaker can be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio circuit 706 may also include a headphone jack.
[0136] Power supply 707 is used to power various components in terminal 700. Power supply 707 can be AC power, DC power, a disposable battery, or a rechargeable battery. When power supply 707 includes a rechargeable battery, the rechargeable battery can support wired charging or wireless charging. The rechargeable battery can also be used to support fast charging technology.
[0137] Those skilled in the art will understand that Figure 7 The structure shown in the figure does not constitute a limitation on the terminal 700, and the terminal 700 may include more or fewer components than shown in the figure, or combine certain components, or adopt a different component arrangement.
[0138] Taking the computer device as a server as an example, Figure 8 This is a structural diagram of a server provided in an embodiment of the present application. The server 800 may have relatively large differences due to different configurations or performances, and may include one or more processors (Central Processing Units, CPU) 801 and one or more memories 802, wherein the one or more memories 802 store at least one computer program, and the at least one computer program is loaded and executed by the one or more processors 801 to implement the above-mentioned method of isolating the safety island. Of course, the server 800 may also have components such as a wired or wireless network interface, a keyboard, and an input and output interface for input and output. The server 800 may also include other components for realizing device functions, which will not be described here.
[0139] An embodiment of the present application further provides a computer-readable storage medium, the computer-readable storage medium including a stored computer program, wherein when the computer program is executed, the device containing the computer-readable storage medium is controlled to execute the above method. Optionally, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc (CD-ROM), a magnetic tape, a floppy disk, an optical data storage device, or the like.
[0140] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
[0141] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A chip for isolating a safety island, characterized in that: include: An electrically connected safety island and a main domain; the safety island comprises a bus gasket module, an asynchronous bridge control module and a safety asynchronous bridge module electrically connected in sequence; The master domain includes a master asynchronous bridge module; The main asynchronous bridge module is electrically connected to the safety asynchronous bridge module; The main domain is used to pull high the reset request signal; The bus gasket module is configured to pull up a refresh signal in response to the reset request signal; The safety asynchronous bridge module is used to enter the first refresh mode in response to the refresh signal being pulled high, and to turn off the reset control unit and the clock control unit; the reset control unit and the clock control unit are arranged inside the asynchronous bridge control module; the reset control unit is used to control the opening and closing of the reset unit of the safety asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safety asynchronous bridge module.
2. The chip according to claim 1, characterized in that When the master domain passively needs to be reset, the master domain is configured to pull up the reset request signal when detecting that a fault has occurred in the chip; The bus gasket module is configured to pull up the refresh signal in response to the reset request signal; The safety asynchronous bridge module is configured to enter a first refresh mode in response to the refresh signal and turn off the reset control unit and the clock control unit; The safety asynchronous bridge module is further used to pull up the trigger confirmation signal; The master domain is further configured to perform a reset operation in response to the trigger confirmation signal; The master domain is further configured to pull up a status signal; the status signal indicates that the master domain has completed reset release; The secure asynchronous bridge module is further configured to exit the first refresh mode in response to the status signal; The bus gasket module is further used to pull down the refresh signal; The safety asynchronous bridge module is further configured to turn on the reset control unit and the clock control unit in response to the refresh signal being pulled low.
3. The chip according to claim 1, characterized in that When the master domain actively performs a reset operation, the master domain is configured to actively pull up the reset request signal.
4. The chip according to claim 1, characterized in that When the bus between the safety island and the main domain needs to be closed, the safety island is used to send a closing signal to the main domain; The master domain is further configured to shut down the second clock unit of the master asynchronous bridge module in response to the shutdown signal; The primary domain is further configured to send a feedback signal to the safety island; The safety island is further configured to send a first trigger signal to the bus gasket module in response to the feedback signal; The bus gasket module is further configured to pull up the refresh signal in response to the first trigger signal; The asynchronous bridge control module is further configured to enter the first refresh mode in response to the refresh signal and turn off the reset control unit and the clock control unit.
5. The chip according to claim 4, characterized in that The safety island is further configured to send the shutdown signal to the main domain in a non-bus manner.
6. The chip according to claim 1, characterized in that When the main domain needs to be powered off, the main domain is further configured to shut down the second clock unit of the main asynchronous bridge module; The main domain is further configured to send a power-off notification signal to the safety island; The safety island is further configured to send a second trigger signal to the bus gasket module in response to the power-off notification signal; The bus gasket module is further configured to pull up the refresh signal in response to the second trigger signal; The asynchronous bridge control module is further configured to enter the first refresh mode in response to the refresh signal and turn off the reset control unit and the clock control unit; The safety island is also used to control the power isolation module to enter the power isolation mode; the power isolation module is arranged inside the safety island.
7. The chip according to claim 6, characterized in that Also included are peripheral devices; the peripheral devices are electrically connected to the safety island and the main domain respectively; The power isolation module is used to isolate all signals transmitted from the main domain to the safety island; The safety island is also used to pull up the power-off signal; The peripheral device is configured to control the main domain to power off in response to the power-off signal.
8. The chip according to claim 1, characterized in that The bus gasket module is further configured to, after pulling up the refresh signal, pull up a preset signal if a signal requesting access to the main domain from the safety island is received.
9. The chip according to claim 1, characterized in that The safety island is further configured to send a third trigger signal to the bus gasket module; The bus gasket module is further configured to enter a second refresh mode in response to the third trigger signal, and pull up a preset signal if a signal requesting access to the main domain is received.
10. A method for isolating a safety island, characterized in that: include: Pull high the reset request signal; In response to the reset request signal, pulling up a refresh signal; In response to the refresh signal being pulled high, the first refresh mode is entered, and the reset control unit and the clock control unit are turned off; the reset control unit and the clock control unit are arranged inside the safety asynchronous bridge module; the reset control unit is used to control the opening and closing of the reset unit of the safety asynchronous bridge module; the clock control unit is used to control the opening and closing of the first clock unit of the safety asynchronous bridge module.
11. A computer device, characterized in that: The computer device includes a processor and a memory, the memory is used to store at least one program, and the at least one program is loaded by the processor and executed by the method for isolating a safety island as described in claim 10.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores at least one program, which is loaded and executed by a processor to implement the method for isolating a safety island as described in claim 10.