High-performance bus transmission security guarantee method and system

By setting up a monitoring counter and error reporting mechanism in the bus safety unit, the problem of bus transmission errors caused by transient register failure is solved, and the reliability and flexibility of high-performance bus transmission are improved, which is suitable for embedded chip design.

CN120743604AActive Publication Date: 2025-10-03江苏云途半导体有限公司
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511194597.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-10-03
Estimated Expiration
2045-08-26

AI Technical Summary

Technical Problem

During existing high-performance bus transmissions, abnormal flips caused by transient register failures cannot be detected in a timely manner, resulting in bus transmission errors and potentially serious consequences. Existing technologies lack a combined software and hardware solution based on abnormality detection.

Method used

By setting a monitoring counter in the bus safety unit to detect the transmission duration and determine timeout or loss errors, and combining the error reporting mechanism to report to the operating system, system-level response and slave port reconfiguration are performed to achieve transparent detection and correction of transient register failures.

Benefits of technology

It improves the reliability and flexibility of bus transmission, provides a layered error handling mechanism, adapts to different functional safety requirements, reduces additional software and hardware overhead, and improves chip performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120743604A_ABST
    Figure CN120743604A_ABST
Patent Text Reader

Abstract

The invention relates to a high-performance bus transmission security guarantee method and system. The high-performance bus transmission security guarantee system comprises a bus security unit, a host, a slave and a bus matrix group formed by a plurality of bus matrixes, the bus security unit is connected between the host and the slave; the bus security unit performs error monitoring by using a transmission duration counting module; comparing the decoded slave port number with a pre-configured slave port number to determine whether a slave port error occurs; and when an error occurs, processing the error of the operating system layer or the bus controller layer. The device can independently act on the bus and a bus matrix group mechanism thereof, can discover loss or overtime errors in a bus transmission process caused by transient failure of the register or abnormal overturning of the register in a transparent manner of the bus, the host and the slave, and can be independently mounted for use or integrated with the bus for use; and the method has high flexibility and less extra software and hardware overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of intelligent chips, and in particular relates to a high-performance bus transmission security guarantee method and system. Background Art

[0002] In high-performance chip bus systems, transmission security is a multi-layered, comprehensive protection system that requires collaborative design across three dimensions: protocol, hardware, and system. In bus arbitration and bus matrix group transmission scenarios, existing security approaches primarily rely on static protection mechanisms, while cutting-edge technologies are dedicated to building dynamic, intelligent security systems. At the protocol level, traditional bus security relies primarily on fixed encryption algorithms and static access control. Bus transmission data is typically encrypted using standard algorithms such as AES, complemented by CRC checksums to ensure data integrity. Basic access control is also implemented through master device ID whitelists. Hardware-level security technology is evolving towards dynamic and intelligent capabilities. Dynamic encryption technology, through key rotation and post-quantum cryptography, effectively enhances the encryption system's attack resistance. Establishing a hardware chain of trust is crucial. PUF-based device authentication and TEE security domain isolation provide a hardware-level trust foundation for bus transmission. Programmable monitoring units embedded in the bus matrix can analyze transmission behavior patterns in real time and identify abnormal traffic using machine learning algorithms, enabling a shift from passive to active protection. The application of these technologies significantly enhances the security baseline of bus systems. System-level security requires a balanced balance between performance and security. A security weight factor is introduced into the bus arbitration strategy, incorporating the device security level into the arbitration priority calculation to ensure low-latency transmission of critical security transactions. At the same time, dynamic address space remapping and labeled routing mechanisms enable flexible configuration and secure isolation of transmission paths.

[0003] Bus transmission anomalies can have serious knock-on effects on chips and entire computing systems. Their consequences can be analyzed from three perspectives: functionality, performance, and reliability. At the functional level, transmission errors can lead to critical data loss or instruction execution errors. For example, data anomalies on the memory access bus can cause the processor to read incorrect instructions or operands, potentially crashing the application at best and triggering system-level deadlocks at worst. In safety-critical applications such as autonomous driving and medical devices, such anomalies can directly endanger human life. Deadlocks or livelocks caused by bus contention can disable the multi-core coordination mechanisms of the entire chip, stalling multiple processing units due to resource contention. This systemic paralysis often requires a hardware reset to recover. From a performance perspective, bus anomalies can significantly increase system latency and reduce throughput. When the bus matrix detects a transmission error, it typically needs to initiate a retransmission mechanism or wait for an arbitration timeout. These recovery operations incur additional clock cycle overhead. In cache coherence protocols, bus transaction anomalies can trigger unnecessary cache line invalidations, significantly increasing the latency of subsequent memory accesses. For systems with stringent real-time requirements, such as 5G baseband or industrial control, this latency fluctuation can directly lead to the system failing to meet timing constraints and causing task timeouts. More seriously, certain bus errors can be erroneously propagated and amplified. For example, a single erroneous DMA transfer can corrupt a large memory area, consuming significant computing resources for subsequent error correction. Regarding reliability, the long-term accumulation of bus transmission anomalies accelerates system aging and shortens chip lifespan. Constant bus contention and retransmissions place related circuits under high load, increasing power consumption and heat, and thus impacting transistor stability. Certain physical layer anomalies, such as signal integrity degradation, can trigger metal migration, causing permanent damage to bus lines. In safety-critical scenarios, hidden bus errors that go undetected can remain dormant for extended periods, ultimately erupting at critical moments. This "silent failure" mode poses a significant threat to system reliability. Furthermore, maliciously crafted bus anomalies can be exploited as a gateway for hardware attacks. Through carefully crafted error injection, security measures can be bypassed, encryption keys stolen, or critical configuration registers tampered with.

[0004] In the traditional high-performance bus transmission process, when the master port initiates a transmission, the selected slave port address will be sent from the master port, and the combinational logic will decode it into a one-hot code type bit selection signal as the slave port selection signal, and the slave port selection signal will be sent to the bus matrix. The bus matrix caches the slave port selection signal and the remaining transmission signals sent by the master port, and after arbitration and delay, it selects the corresponding slave port and completes the transmission according to the slave port selection signal. In this process, if the register that caches the slave port selection signal has a transient failure and causes an abnormal flip, it will directly cause the bus transmission to be sent to the wrong slave port without triggering any alarm, resulting in abnormal data being retrieved or written, causing serious consequences. The existing technology for the security protection of high-performance buses is an independent solution based on the software level or the hardware level. In addition, the hardware level solution is mostly based on hardware redundancy rather than from the perspective of abnormality detection. Based on the above problems, the present invention can start from the perspective of the bus transmission mechanism itself, based on the specific exception type and its source discovery, and combine the transmission error discovery and resolution at the software and hardware levels, and independently act on the bus and its bus matrix group mechanism. It can transparently discover the loss or timeout errors in the bus transmission process caused by transient failures caused by registers and their abnormal flips through the bus, host, and slave. It can be used independently or mounted on the bus, has high flexibility and less additional software and hardware overhead, and is suitable for embedded chip design scenarios that require a high degree of software and hardware resource integration to improve chip performance. Summary of the Invention

[0005] In order to solve the above problems in the prior art, the present invention proposes a high-performance bus transmission security guarantee method and system, the method comprising: Step S1: sending address information to the bus safety unit and the bus matrix group; Step S2: the decoding circuit decodes the address information into a slave port and matrix selection signal, sends it to the bus matrix group to select the corresponding bus matrix and slave port, and sends it to the encoding circuit; Step S3: The encoding circuit encodes the selection signal and sends it to the bus matrix group; the bus matrix group performs bit splicing on the encoded selection signal and the address signal sent from the master port; Step S4: Transmitting based on the selected slave port and bus matrix; performing bit splitting on the bit-spliced ​​signal to obtain an encoded selection signal, and sending it together with its own slave port number to the decoding circuit; and sending the address signal obtained by bit splitting to the slave; Step S5: The decoding circuit decodes the encoded selection signal and compares it with the pre-configured slave port number to determine whether the slave port is consistent. If not, the process proceeds to the next step. Otherwise, the transmission is determined to be completed normally, and the slave responds with a received signal to the monitoring counter corresponding to the slave port. The monitoring counter compares the monitoring counter with the timeout threshold. If the timeout exceeds the threshold, a transmission timeout error is reported and the monitoring counter is cleared. If the received signal is not received, the counting is continued until the loss threshold is reached, and a transmission loss error is reported. Step S6: Send an error report to the operating system and / or send a bus error to the bus controller based on the error information; the operating system updates the number of timeout errors and / or the number of lost errors based on the error report and the executable type involved, and triggers a system-level error response and / or reconfigures the address range and slave port mapping relationship based on the number of timeout errors and / or the number of lost errors of the slave port; the bus controller resets the bus matrix in response to the bus error reset enable.

[0006] Furthermore, a monitoring counter is set for each slave port in the transmission duration counting module in the bus safety unit; when the master port initiates transmission, in response to a counting trigger signal from the host, the monitoring counter corresponding to the slave port in the bus safety unit starts counting, and the transmission duration is used to check whether there is a transmission timeout error or a transmission loss error.

[0007] Furthermore, the monitoring threshold is configurable. After the bus security unit is enabled, the operating system writes the monitoring threshold into the register in the transmission duration counting module; the monitoring threshold includes a timeout threshold and a loss threshold, which are used to monitor transmission duration errors and transmission loss errors, respectively; the loss threshold is greater than the timeout threshold.

[0008] Furthermore, when the master port initiates transmission through the bus, the selected slave port number will be encoded and sent to the slave port through the bus; when the slave port receives the transmitted data, it decodes the encoded slave port number and checks it with its own preset number to determine whether a slave port error occurs in the transmission.

[0009] Furthermore, the transfer request comes from the operating system or originates from the application layer.

[0010] Furthermore, the operating system triggers a system-level error response and / or reconfigures the mapping relationship between the address range and the slave port based on the number of timeout errors and / or loss errors of the slave port; and reconfigures the corresponding relationship between the slave port and the slave machine based on the reconfiguration operation; The specific steps include: Step S11: The host determines the execution type of the transmission request; the execution type includes time-sensitive, loss-sensitive, reliability-sensitive or other types; Step S12: upon receiving the error report, the operating system updates the number of timeout errors and / or the number of lost errors of the slave port based on the executable type. Specifically, the operating system obtains the executable corresponding to the transmission request and its corresponding executable type based on the master port number, address information, and / or slave port number of the transmission error; updates the number of timeout errors and / or the number of lost errors based on the executable type and the error type; pre-sets a correspondence table between the executable type, the error type, and the update method for the number of timeout errors and / or the number of lost errors, obtains the update method by querying the correspondence table, and updates the number of timeout errors and / or the number of lost errors based on the obtained update method. Step S13: Determine whether the timeout error and / or loss error exceeds the tolerance threshold, if so, proceed to the next step; Step S14: triggering a system-level error response and / or reconfiguring the mapping relationship between the address and the slave port based on the number of timeout errors and / or loss errors of the slave port; and reconfiguring the corresponding relationship between the slave port and the slave device based on the reconfiguration operation; The reconfiguration of the address and slave port mapping relationship based on the number of timeout errors and / or loss errors of the slave port is specifically as follows: obtaining the address range involved in the slave port with the largest number of timeout errors and / or loss errors and the first mapping relationship of the slave port; obtaining the address range involved in the slave port with the smallest number of timeout errors and / or loss errors and the second mapping relationship of the slave port; and exchanging the first mapping relationship and the second mapping relationship for reconfiguration.

[0011] A high-performance bus transmission security assurance system is used to implement the above-mentioned high-performance bus transmission security assurance method; the system includes a bus security unit, a host, a slave, and a bus matrix group consisting of multiple bus matrices; The bus safety unit is connected between the host and the slave; the bus safety unit includes a transmission time counting module, an address decoding circuit, an address mapping management circuit, an encoding circuit, a decoding circuit, an error reporting module and a register; The bus security unit sends the address information from the bus to the address decoding circuit to cooperate with the address mapping management circuit for decoding, and sends the matrix / slave port selection signal obtained by decoding to the bus matrix group and the encoding circuit; The encoding circuit encodes the matrix / slave port selection signal to obtain an encoded port selection signal and sends it to the bus matrix group; The decoding circuit receives the encoded port selection signal and the current slave port selection signal from the bus matrix group, compares the decoded slave port number with the pre-configured slave port number to determine whether the slave port is consistent, and if not, determines that a slave port error has occurred; and sends error information to the error reporting module and register when an error occurs; The register receives and stores configuration information of the bus safety unit and records error information after the bus safety unit detects an error; The transmission duration counting module includes a plurality of monitoring counters, each of which corresponds to a master port and / or a slave port; The bus matrix group is used to perform bus matrix and slave port selection based on a matrix / slave port selection signal, and perform data transmission based on the selected slave port.

[0012] A high-performance bus transmission security assurance digital logic is provided, wherein the high-performance bus transmission security assurance digital logic is used to implement the above-mentioned high-performance bus transmission security assurance method.

[0013] A high-performance bus transmission security assurance chip is used to implement the above-mentioned high-performance bus transmission security assurance method.

[0014] A high-performance bus transmission security assurance circuit is used to implement the above-mentioned high-performance bus transmission security assurance method.

[0015] The beneficial effects of the present invention include: (1) It acts independently on the bus and its bus matrix group mechanism, and detects loss or timeout errors in bus transmission caused by transient failure of registers or abnormal flipping through the bus, host, and slave in a transparent manner. It can be mounted and used independently or integrated with the bus, with high flexibility and low additional software and hardware overhead; (2) The hardware-level errors found are reported to the operating system and bus controller layer through error reporting, thereby providing a layered error handling mechanism, and then supporting the bus transmission error analysis at the operating system level. Based on the analysis results, the operating system layer and application layer executors are provided with the opportunity to trigger system-level error response and / or reconfigure from the port. By reconfiguring the chip mapping logic, a better bus routing method is provided for important executors that are time-sensitive, loss-sensitive, and reliability-sensitive. Without replacing the hardware body, the chip reliability is improved, a strong guarantee for bus transmission is provided, and it can adapt to different functional safety requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application, but do not constitute an improper limitation of the present invention. In the drawings: Figure 1 Schematic diagram of the high-performance bus transmission security assurance method provided by the present invention.

[0017] Figure 2This is a structural diagram of the high-performance bus transmission security assurance system provided by the present invention.

[0018] Figure 3 This is a schematic diagram of the bus matrix structure provided by the present invention.

[0019] Figure 4 This is a structural diagram of the error reporting module provided by the present invention. DETAILED DESCRIPTION

[0020] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. The exemplary embodiments and descriptions are only used to explain the present invention but are not intended to limit the present invention.

[0021] The present invention proposes a high-performance bus transmission security guarantee method, as shown in the attached Figure 1 As shown, the method includes: Step S1: Sending address information from the master port; specifically: the host sends the address information to the bus security unit, and sends it to the bus matrix group through the master port; Preferably, a monitoring counter is set for each slave port in a transmission duration counting module in the bus safety unit; when the master port initiates transmission, in response to a count trigger signal from the host, the monitoring counter corresponding to the slave port in the bus safety unit starts counting, and checks whether there is a bus transmission timeout or loss based on the transmission duration; the monitoring threshold is configurable, and the operating system writes the monitoring threshold into a register, and after the bus safety unit is enabled, the monitoring threshold in the register is written into the transmission duration counting module; Preferably, the monitoring threshold includes a timeout threshold and a loss threshold, which are used to count the transmission duration and transmission loss respectively; the loss threshold is greater than the timeout threshold; the setting of the monitoring threshold is related to the security requirements of the chip. When the chip requires higher security, the timeout threshold and loss threshold are set to lower values; otherwise, relatively loose settings can be made; Alternative: Setting monitoring thresholds for each slave port based on the type of slave device to which the slave port is mapped. Differentiated monitoring threshold settings can be used when different slave types have different security requirements or time sensitivities, but such settings incur more on-chip resource overhead. Preferably, a system-level error response and / or reconfiguration of the address range and slave port mapping relationship is triggered based on the number of timeout errors and / or loss errors of the slave port; and the corresponding relationship between the slave port and the slave device is reconfigured based on the reconfiguration information; the specific reconfiguration timing may be on a periodic basis, before the master port sends address information, after receiving an error report, when the bus matrix group is idle, etc. The specific steps include: Step S11: The host determines the execution type of the transmission request; the execution type includes time-sensitive, loss-sensitive, reliability-sensitive, and other types; Preferably: the transmission request comes from an operating system or originates from an application layer; Preferably, the types of executables include: user process / thread, kernel thread, interrupt handler, interrupt handler, DMA controller, system call, hardware accelerator; generally, the type of user process is set to general type, considering that time-sensitive and loss-sensitive events in the application will initiate transmission requests in the form of other executable types. Therefore, even for executables with higher security requirements such as vehicle control, no special considerations are required; other types of executables also have similar problems, which will not be elaborated here; of course, the executable type can be refined in one step according to the security requirements; thus, differentiated executable types are set for executables at the application layer to provide differentiated security protection; Step S12: When the operating system receives the error report, it updates the number of timeout errors and / or loss errors of the slave port based on the execution body type; Step S13: Determine whether the timeout error and / or loss error exceeds the tolerance threshold, if so, proceed to the next step; Preferably, the tolerance threshold is a preset value; the tolerance threshold can be set to a larger value and can be further set in conjunction with other operating system monitoring data; since the mapping relationship between the address range and the slave port is relatively fixed after configuration, and for time-sensitive and timeout-sensitive types of executors, their bus routing method can be regarded as logically fixed, remapping can break this inherent logical limitation to achieve security; Step S14: triggering a system-level error response and / or reconfiguring the mapping relationship between the address and the slave port based on the number of timeout errors and / or loss errors of the slave port; and reconfiguring the corresponding relationship between the slave port and the slave device based on the reconfiguration information; Preferably: information that the error condition has exceeded the tolerance is sent to an operating system, such as a system-level error management unit in the operating system, and a system interrupt or system reset, a module-level reset of the slave port, or a reconfiguration of the slave port is generated based on the number of timeout errors and / or loss errors of the slave port; The reconfiguration of the address and slave port mapping relationship based on the number of timeout errors and / or loss errors of the slave port is specifically as follows: obtaining a first mapping relationship between the address range involved in the slave port with the largest number of timeout errors and / or loss errors and the slave port; obtaining a second mapping relationship between the address range involved in the slave port with the smallest number of timeout errors and / or loss errors and the slave port; exchanging the mapping relationships between the two for reconfiguration; that is, establishing a mapping relationship between the address range in the first mapping relationship and the slave port in the second mapping relationship, and establishing a mapping relationship between the address range in the second mapping relationship and the slave port in the first mapping relationship; this reconfiguration method is suitable for situations where the tolerance level is low but the reconfiguration effort is small, and the configuration overhead and configuration time required for reconfiguration are short; The above is a case where the timeout error count and the loss error count are reconfigured separately. Since some loss error counts are caused by timeout errors, the two can be comprehensively considered by weighted summation and a unified exchange based on the weighted sum count can be performed. Preferably: reconfiguring the mapping relationship and the corresponding relationship by supporting dynamic remapping of registers of the interconnect bus that supports software programmable address decoding, dynamic redirection of the MMU / IOMMU of the CPU or IO device that supports virtual address translation, and PCIeBAR reconfiguration that supports dynamic address allocation of PCIe devices; The dynamic remapping through registers is specifically as follows: determining a configuration register for controlling address mapping in the bus matrix; writing a command to the control register to release the binding between the old address range and the slave port; writing a base address and address range of the new address range to realize dynamic configuration of the address range to the slave port; Preferably: after the reconfiguration is completed, a synchronization barrier is triggered and a test access is performed to verify whether the new mapping is effective.

[0022] The dynamic redirection through MMU / IOMMU is specifically as follows: updating the page table of MMU / IOMMU, mapping the virtual address to a new address range to correspond to a different slave port, and refreshing the TLB to invalidate the old address range translation cache; The dynamic address allocation through PCIe device is specifically as follows: shutting down the device response and disabling the device through PCI configuration space; modifying the BAR register, writing the base address of the new address range to point to the new slave port address; and reallocating the address space; The reconfiguration of the correspondence between the slave port and the slave device based on the reconfiguration information specifically includes: sending a global abort signal through the bus arbiter to clear all uncompleted transfer requests associated with the slave port; modifying the control register of the slave port in the bus matrix to point to the new address range; and resetting the slave device involved in the reconfiguration operation.

[0023] The restarting of the bus matrix group specifically includes: partially restarting the bus matrix group to re-enable and reconfigure the relevant part of the bus matrix; Step S2: The decoding circuit decodes the address information into a one-hot code as a slave port and matrix selection signal; the slave port and matrix selection signal is sent to the bus matrix group to select the corresponding bus matrix and slave port, and is sent to the encoding circuit at the same time; Preferably: before entering step S2, the host sends a transmission start signal to the corresponding monitoring counter; Preferably: the one-hot code uses an N-bit binary number to represent N different states, where only one bit is 1 and the rest are 0, for bit-port selection; Step S3: The encoding circuit encodes the slave port and matrix selection signal and sends it to the bus matrix group; the bus matrix group performs bit splicing on the encoded slave port and / or matrix signal and the address signal sent from the master port; Preferably: each slave port is assigned a binary code unique to both the matrix number and the slave port number according to the selected encoding type; Step S4: The bus matrix group selects the bus matrix and slave port based on the slave port and matrix selection signals received from the decoding circuit; simultaneously, the received encoded slave port and / or matrix signals and address signals are bit-spliced ​​to obtain the encoded matrix and / or slave port selection signals, which are sent to the decoding circuit together with the bus matrix group's own slave port number (i.e., the current slave port number); and the address signal obtained by bit-splicing is sent to the slave device; Preferably: after the bus matrix group is enabled, the slave port number information is obtained and the slave port is pre-configured; while performing bit splitting, the selected slave port obtains the pre-configured slave port number information and sends it to the decoding circuit; Preferably: reading the slave port number information from the bus controller; Preferably: when the slave port receives a transmission signal from the bus matrix, a bit splitting operation is triggered on the received bit-spliced ​​signal to split it into an address signal and an encoded slave port selection signal; Step S5: Determine whether a slave port abnormality occurs; if so, proceed to the next step; otherwise, determine that the transmission is completed normally; The determining whether a slave port abnormality occurs is specifically as follows: receiving a preconfigured slave port number sent by the slave port, decoding the received encoded slave port / matrix selection signal by a decoding circuit, comparing the decoded slave port number with the preconfigured slave port number to determine whether the slave ports are consistent, and if they are inconsistent, determining that a slave port error occurs; Preferably, when the master port initiates transmission via the bus, the selected slave port numbers are encoded and sent to the slave port via the bus; when the slave port receives the transmitted data, it decodes the encoded slave port number and checks it with its own preset number to determine whether a slave port error occurs in the transmission; Preferably, when the transmission from the slave port is completed normally, the slave device responds with a received signal to the monitoring counter corresponding to the slave port, compares the value of the monitoring counter with the timeout threshold based on the received signal, and reports a transmission timeout error if the timeout threshold is exceeded; and clears the monitoring counter at the same time; and if the slave port does not receive a signal, the monitoring counter of the master port cannot be cleared due to the lack of signal, and the monitoring counter keeps counting until the loss threshold is reached, and reports a transmission loss error; Step S6: the error management module and the register receive the reported error information; the register records the error information; the error management module sends an error report to the operating system and / or sends a bus error to the bus controller based on the information in the register; Preferably: the error information includes the master port number, address information and slave port number where the transmission error occurs; Preferably: the error management module sends an error report when a reporting condition is met; the reporting condition is that a sending cycle requirement is met, a register is full, and error report enabling information is received; Preferably, the error management module sends an error report to the operating system by initiating an interrupt request; the operating system performs error processing by analyzing the error report; the bus controller re-enables the bus matrix in response to the bus error to reset the bus matrix; further, a counter threshold is set in the bus controller, and the bus controller is re-enabled when the number of timeout errors and / or loss times reaches the counter threshold; The operating system analyzes the error report to perform error processing, specifically: recording the number of timeout errors and / or loss errors corresponding to each slave port in the operating system; upon receiving the error report, updating the recorded number of timeout errors and / or loss errors corresponding to the slave port based on the master port number, address information and / or slave port number and error type of the error transmitted in the error report; The updating of the recorded number of timeout errors and / or loss errors corresponding to the slave port is specifically as follows: obtaining the execution body corresponding to the transmission request and its corresponding execution body type based on the master port number, address information and / or slave port number of the transmission error; updating the number of timeout errors and / or loss errors based on the execution body type and error type; The updating of the number of timeout errors and / or the number of lost errors based on the execution body type and the error type is specifically as follows: presetting a correspondence table between the execution body type, the error type and the updating method of the number of timeout errors and / or the number of lost errors, obtaining the updating method by querying the correspondence table, and updating based on the obtained updating method; an example of the correspondence table is shown in the following table; Table 1: Correspondence between execution body type, error type and update method of timeout error number and / or loss error number; Of course, the update granularity can be configured based on the chip aging, usage frequency, and usage scenarios; the example above is a unit update granularity; The present invention proposes a high-performance bus transmission security method and system, the system is used to implement the above method steps; as shown in the attached Figure 2 As shown, the high-performance bus transmission security system includes a bus security unit, a host, a slave and a bus matrix group consisting of multiple bus matrices; The bus safety unit is connected between the host and the slave; the bus safety unit includes a transmission time counting module, an address decoding circuit, an address mapping management circuit, an encoding circuit, a decoding circuit, an error reporting module and a register; Preferably, the bus safety unit is integrated into a bus integrity checker for use, or is used as an independent module in the form of a bus safety unit and connected between the host and the slave by being mounted beside the bus port; The bus security unit sends the address information from the bus to the address decoding circuit to cooperate with the address mapping management circuit for decoding, and sends the matrix / slave port selection signal obtained by decoding to the bus matrix group and the encoding circuit; The encoding circuit encodes the matrix / slave port selection signal to obtain an encoded port selection signal and sends it to the bus matrix group; The decoding circuit receives the encoded port selection signal and the current slave port selection signal from the bus matrix group, compares the decoded slave port number with the pre-configured slave port number to determine whether the slave port is consistent, and if not, determines that a slave port error has occurred; and sends error information to the error reporting module and register when an error occurs; The transmission duration counting module includes multiple monitoring counters, each of which corresponds to a master port and / or a slave port; it is used to count the transmission duration when receiving a counting trigger signal (transmission start signal) sent by the host, and stop counting when receiving a receipt signal (transmission delivery signal) sent by the slave; when a timeout or loss occurs, it sends a timeout or loss error to the error reporting module and register; The bus matrix group is used to select a bus matrix and a slave port based on a matrix / slave port selection signal, and to perform data transmission based on the selected slave port; The register receives and stores configuration information of the bus safety unit and records error information after the bus safety unit detects an error; Preferably, an address mapping management module is used to manage address mapping, and based on the reconfiguration information, management is provided for specific address mapping of the bus matrix; when reconfiguration of the address range and slave port mapping relationship is triggered, configuration information in the address mapping management module is modified based on the reconfiguration information, and address decoding and connection allocation between the bus slave ports and submodules are performed according to the configuration information of the address mapping management module; As attached Figure 3 As shown, each bus matrix in the bus matrix group includes multiple master ports and multiple slave ports, which are connected through the bus matrix group; the bus matrix group also includes a bit splicing module, a bus buffer / interaction module, and a bit splitting module; when the master port initiates transmission, the received encoded matrix / slave port selection signal and the address signal are bit-spliced; the spliced ​​signal is sent to the bus matrix and sent to the selected slave port through the bus buffer / interaction module; after receiving the spliced ​​signal, the slave port performs bit splitting on the received address signal to split it into the address signal and the encoded matrix / slave port selection signal, and decodes the encoded matrix / slave port selection signal based on the slave port number preconfigured for the slave port to obtain the encoded slave port matrix / slave port selection signal for slave port error judgment; Preferred: handling conflicts or caching data through bus cache / interaction modules, and concurrent management of multiple masters and multiple slaves; As attached Figure 4 As shown, the error reporting module receives error information and each error reporting enabling information, and sends the error report to the operating system or the bus error to the bus controller based on each error reporting enabling information; Preferably, the error reporting enabling information is from a bus controller or an operating system; A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language, including assembly or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple collaborative files (e.g., files storing one or more modules, subroutines, or code portions). A computer program can be deployed to execute on one computer or on multiple computers located at one site or distributed across multiple sites and interconnected by a communication network.

[0024] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0025] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0026] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0027] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0028] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A high-performance bus transmission security guarantee method, characterized in that: Include: Step S1: sending address information to the bus safety unit and the bus matrix group; Step S2: the decoding circuit decodes the address information into a slave port and matrix selection signal, sends it to the bus matrix group to select the corresponding bus matrix and slave port, and sends it to the encoding circuit; Step S3: the encoding circuit encodes the selection signal and sends it to the bus matrix group; The bus matrix group performs bit splicing on the coded selection signal and the address signal sent from the master port; Step S4: Transmitting based on the selected slave port and bus matrix; performing bit splitting on the bit-spliced ​​signal to obtain an encoded selection signal, and sending it together with its own slave port number to the decoding circuit; and sending the address signal obtained by bit splitting to the slave; Step S5: The decoding circuit decodes the encoded selection signal and compares it with the pre-configured slave port number to determine whether the slave port is consistent. If not, the process proceeds to the next step. Otherwise, the transmission is determined to be completed normally, and the slave responds with a received signal to the monitoring counter corresponding to the slave port. The monitoring counter compares the monitoring counter with the timeout threshold. If the timeout exceeds the threshold, a transmission timeout error is reported and the monitoring counter is cleared. If the received signal is not received, the counting is continued until the loss threshold is reached, and a transmission loss error is reported. Step S6: Sending an error report to the operating system and / or sending a bus error to the bus controller based on the error information; The operating system updates the number of timeout errors and / or the number of lost errors based on the error report and the executable type involved, and triggers a system-level error response and / or reconfigures the address range and slave port mapping relationship based on the number of timeout errors and / or the number of lost errors of the slave port; The bus controller performs a bus matrix reset in response to the bus error reset enable.

2. The high-performance bus transmission security guarantee method according to claim 1, characterized in that: A monitoring counter is set for each slave port in the transmission duration counting module in the bus safety unit. When the master port initiates transmission, in response to a counting trigger signal from the host, the monitoring counter corresponding to the slave port in the bus safety unit starts counting, and checks whether there is a transmission timeout error or a transmission loss error based on the transmission duration.

3. The high-performance bus transmission security guarantee method according to claim 2, characterized in that: The monitoring threshold is configurable. After the bus security unit is enabled, the operating system writes the monitoring threshold into the register in the transmission duration counting module. The monitoring threshold includes a timeout threshold and a loss threshold, which are used to monitor transmission duration errors and transmission loss errors respectively. The loss threshold is greater than the timeout threshold.

4. The high-performance bus transmission security guarantee method according to claim 3, characterized in that: When the master port initiates a transmission through the bus, the selected slave port number will be encoded and sent to the slave port through the bus; when the slave port receives the transmitted data, it decodes the encoded slave port number and checks it with its own preset number to determine whether a slave port error occurs in the transmission.

5. The high-performance bus transmission security guarantee method according to claim 4, characterized in that: Transfer requests come from the operating system or originate from the application layer.

6. The high-performance bus transmission security guarantee method according to claim 5, characterized in that: The operating system triggers a system-level error response and / or reconfigures the mapping relationship between the address range and the slave port based on the number of timeout errors and / or loss errors of the slave port; and reconfigures the corresponding relationship between the slave port and the slave machine based on the reconfiguration operation; The specific steps include: Step S11: The host determines the execution type of the transmission request; the execution type includes time-sensitive, loss-sensitive, reliability-sensitive or other types; Step S12: When the operating system receives the error report, it updates the number of timeout errors and / or loss errors of the slave port based on the execution body type; Specifically, the process includes: obtaining the execution body corresponding to the transmission request and its corresponding execution body type based on the main port number, address information and / or slave port number of the transmission error; updating the number of timeout errors and / or loss errors based on the execution body type and error type; Presetting a correspondence table between the execution body type, error type, and timeout error count and / or loss error count update method, obtaining the update method by querying the correspondence table, and updating the timeout error count and / or loss error count based on the obtained update method; Step S13: Determine whether the timeout error and / or loss error exceeds the tolerance threshold, if so, proceed to the next step; Step S14: triggering a system-level error response and / or reconfiguring the address and slave port mapping relationship based on the number of timeout errors and / or loss errors of the slave port; and reconfiguring the correspondence between the slave port and the slave machine based on the reconfiguration operation; The reconfiguration of the address and slave port mapping relationship based on the number of timeout errors and / or loss errors of the slave port specifically comprises: obtaining a first mapping relationship between the address range involved in the slave port with the largest number of timeout errors and / or loss errors and the slave port; obtaining a second mapping relationship between the address range involved in the slave port with the smallest number of timeout errors and / or loss errors and the slave port; The first mapping relationship and the second mapping relationship are exchanged for reconfiguration.

7. A high-performance bus transmission security system, characterized in that: The high-performance bus transmission security assurance system is used to implement the high-performance bus transmission security assurance method according to any one of claims 1 to 6; the system includes a bus security unit, a master, a slave, and a bus matrix group consisting of a plurality of bus matrices; The bus safety unit is connected between the host and the slave; the bus safety unit includes a transmission time counting module, an address decoding circuit, an address mapping management circuit, an encoding circuit, a decoding circuit, an error reporting module and a register; The bus security unit sends the address information from the bus to the address decoding circuit, cooperates with the address mapping management circuit to decode, and sends the matrix / slave port selection signal obtained by decoding to the bus matrix group and the encoding circuit; The encoding circuit encodes the matrix / slave port selection signal to obtain an encoded port selection signal and sends it to the bus matrix group; The decoding circuit receives the encoded port selection signal and the current slave port selection signal from the bus matrix group, compares the decoded slave port number with the pre-configured slave port number to determine whether the slave ports are consistent, and if not, determines that a slave port error occurs; And send error information to the error reporting module and register when an error occurs; The register receives and stores configuration information of the bus safety unit and records error information after the bus safety unit detects an error; The transmission duration counting module includes a plurality of monitoring counters, each of which corresponds to a master port and / or a slave port; The bus matrix group is used to perform bus matrix and slave port selection based on a matrix / slave port selection signal, and perform data transmission based on the selected slave port.

8. A high-performance bus transmission security digital logic, characterized in that: The high-performance bus transmission security assurance digital logic is used to implement the high-performance bus transmission security assurance method described in any one of claims 1-6.

9. A high-performance bus transmission security chip, characterized in that: The high-performance bus transmission security assurance chip is used to implement the high-performance bus transmission security assurance method described in any one of claims 1 to 6.

10. A high-performance bus transmission security circuit, characterized in that: The high-performance bus transmission security assurance circuit is used to implement the high-performance bus transmission security assurance method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for initializing a secure bus in a master-slave system

    CN115333892A

  • Integrated circuit bus system, data processing method and programmable logic unit

    CN120353741A

  • Bus system with fault detection function

    DE102021200411A1