A processor start flow control method and system

CN122044675BActive Publication Date: 2026-08-11JUDI (SHANGHAI) TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-20
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

然而,在常规处理器启动控制方案中,受启动代码固化、启动地址固定、硬件逻辑不可重构等因素限制,现有方案普遍存在启动流程无法调整、缺陷难以修复、异常场景无法兼容及重新投片成本高昂等问题,难以在不修改原有启动程序的前提下灵活切换指令执行地址与引导路径

Benefits of technology

[0015]本申请提供的处理器启动流程控制方法及系统,通过在目标芯片中的处理器处于启动状态的情况下,接收处理器发送的用于从原始启动存储器获取处理器的后续指令执行位置信息的读取请求。根据目标芯片的硬件配置状态,生成与读取请求对应的执行位置选择控制信号,执行位置选择控制信号用于确定是否需要切换后续指令执行位置。在执行位置选择控制信号表征需要切换后续指令执行位置的情况下,获取备用后续指令执行位置信息,并将备用后续指令执行位置信息发送至处理器,以使处理器根据备用后续指令执行位置信息执行后续指令跳转,以规避原始启动存储器故障、硬件配置异常导致的启动中断或启动失败问题,无需对故障芯片进行整体废弃或重新投片,可通过切换后续指令执行位置实现启动流程的正常推进,同时可灵活适配不同硬件配置场景下的启动需求,从而提升处理器启动流程的灵活可调性、降低芯片修复与重投片成本、提高量产良率与交付稳定性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122044675B_ABST
    Figure CN122044675B_ABST
Patent Text Reader

Abstract

This application provides a processor boot process control method and system. The method includes: when the processor in the target chip is in a boot state, receiving a read request sent by the processor, the read request being used to obtain the subsequent instruction execution location information of the processor from the original boot memory; generating an execution location selection control signal corresponding to the read request based on the hardware configuration state of the target chip, the execution location selection control signal being used to determine whether it is necessary to switch the subsequent instruction execution location; if the execution location selection control signal indicates that it is necessary to switch the subsequent instruction execution location, obtaining backup subsequent instruction execution location information; and sending the backup subsequent instruction execution location information to the processor, so that the processor executes the subsequent instruction jump according to the backup subsequent instruction execution location information. This method can improve the flexibility and adjustability of the processor boot process, reduce chip repair and re-wafer production costs, and improve mass production yield and delivery stability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of integrated circuit technology, and more specifically, to a processor startup process control method and system. Background Technology

[0002] Currently, integrated circuit chips have become the core computing carriers of electronic devices and embedded systems. Processor boot control, as a crucial step in chip power-on initialization and system booting, directly determines chip boot reliability, functional compatibility, and mass production stability, significantly impacting chip development costs, delivery cycles, and product yield. Current processor boot process control often employs a method of burning fixed boot code into a built-in boot read-only memory (Boot ROM). Once the chip is fabricated, the boot program cannot be modified, relying on the fixed program to complete processor booting and initialization. However, conventional processor boot control schemes are limited by factors such as fixed boot code, fixed boot addresses, and non-reconfigurable hardware logic. Existing solutions generally suffer from problems such as unadjustable boot processes, difficulty in repairing defects, incompatibility with abnormal scenarios, and high costs associated with re-fabrication. They also struggle to flexibly switch instruction execution addresses and boot paths without modifying the original boot program. This increases chip development risks and mass production costs, negatively impacts product delivery cycles and reliability, and limits the application capabilities of integrated circuit chips in multi-configuration, highly compatible, and rapidly iterating scenarios, failing to meet the core requirements of modern chip design for low cost, high flexibility, and high reliability.

[0003] Therefore, improving the flexibility and adjustability of the processor boot process, reducing the cost of chip repair and re-casting, and improving mass production yield and delivery stability are urgent technical problems that need to be solved. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a processor boot process control method and system to improve the flexibility and adjustability of the processor boot process, reduce the cost of chip repair and re-casting, and improve mass production yield and delivery stability.

[0005] In a first aspect, this application provides a processor boot process control method, including: When the processor in the target chip is in the boot state, a read request sent by the processor is received. The read request is used to obtain the subsequent instruction execution location information of the processor from the original boot memory. Based on the hardware configuration status of the target chip, an execution position selection control signal corresponding to the read request is generated. The execution position selection control signal is used to determine whether it is necessary to switch the execution position of subsequent instructions. The hardware configuration status includes at least one of the following: the one-time programmable memory cell status of the target chip, and the state of the input / output pins of the target chip latched at startup. When the execution position selection control signal indicates that the execution position of the subsequent instruction needs to be switched, information on the alternative execution position of the subsequent instruction is obtained. The backup subsequent instruction execution location information is sent to the processor so that the processor executes the subsequent instruction jump according to the backup subsequent instruction execution location information.

[0006] Optionally, when the execution position selection control signal indicates that the execution position of the subsequent instruction needs to be switched, obtaining the backup execution position information of the subsequent instruction includes: Receive the original subsequent instruction execution location information returned by the original boot memory according to the read request; The backup subsequent instruction execution location information is obtained from a target source, wherein the target source includes at least one of the following: a fixed address constant, address data generated by decoding the one-time programmable memory unit, or a set of address data selected from multiple address setting tables; Based on the execution position selection control signal, the data selection circuit selects the backup subsequent instruction execution position information as the address information to be sent from the original subsequent instruction execution position information and the backup subsequent instruction execution position information.

[0007] Optionally, when the execution position selection control signal indicates that the execution position of the subsequent instruction needs to be switched, obtaining the backup execution position information of the subsequent instruction includes: According to the execution location selection control signal, the target address of the read request is redirected from the original boot memory to the backup address source through the access path selection mechanism, and the read request is sent to the backup address source. The backup address source includes at least one of the following: another memory region inside the target chip, the address space mapped by the one-time programmable memory cell, and external memory. Receive the backup address source returning the backup subsequent instruction execution location information based on the read request.

[0008] Optionally, generating an execution location selection control signal corresponding to the read request based on the hardware configuration status of the target chip includes: Obtain configuration mode indication information, which is derived from at least one of the following: the pre-stored value of the one-time programmable memory cell, the specific position of the input / output pin in the latched state at startup, and the hardwired bonding option of the target chip; The state of the one-time programmable memory cell is read to obtain a first state value, and the state of the input / output pin latched at startup is read to obtain a second state value; The current configuration mode is determined based on the configuration mode indication information. The configuration mode includes using the one-time programmable memory unit alone, using the input / output pin alone, or using both the one-time programmable memory unit and the input / output pin simultaneously. When the configuration mode is to use the one-time programmable storage unit alone and the first state value is programmed, an execution position selection control signal is generated to indicate that the execution position of subsequent instructions needs to be switched. When the configuration mode is to use the input / output pins alone and the second state value is not at the default level, an execution position selection control signal is generated to indicate that the execution position of subsequent instructions needs to be switched. When the configuration mode is to use the one-time programmable memory unit and the input / output pins simultaneously and the first state value is a programmed state or the second state value is a non-default level, an execution position selection control signal is generated to indicate that the execution position of subsequent instructions needs to be switched. Otherwise, the execution location selection control signal for generating the representation does not require switching the execution location of subsequent instructions.

[0009] Optionally, before obtaining the configuration mode indication information, the method further includes: Obtain a historical startup result sequence, which includes records of whether each startup successfully executed subsequent instruction jumps during multiple consecutive startup processes; Pattern analysis is performed on the historical startup result sequence to identify the number of consecutive failed startups and the number of consecutive successful startups in the historical startup result sequence; When the number of consecutive failed startups reaches a first preset threshold, the current configuration mode is set to use the one-time programmable storage unit and the input / output pins simultaneously, and the first state value and the second state value are logically XORed as the determination basis. When the logical XOR result is valid, the execution position selection control signal representing the need to switch is generated. When the number of consecutive successful startups reaches the second preset threshold, the current configuration mode is set to use the one-time programmable storage unit alone, and the first status value is used as the determination criterion. When the number of consecutive failed startups does not reach the first preset threshold and the number of consecutive successful startups does not reach the second preset threshold, the configuration mode determined by the configuration mode indication information remains unchanged.

[0010] Optionally, the step of reading the state latched by the input / output pin at startup to obtain the second state value includes: When receiving a read request from the processor, the state of the input / output pins is continuously sampled within a sliding sampling window to obtain a sequence of sampled values; Calculate the arithmetic mean of all sampled values ​​in the sampled value sequence, and compare the arithmetic mean with a preset reference level threshold to obtain the level decision result; Calculate the variance of the sampled values ​​in the sampled value sequence, and compare the variance with a preset jitter tolerance threshold to obtain a stability decision result; When the stability decision result indicates that the variance of change is less than the preset jitter tolerance threshold, the level decision result is taken as the second state value; When the stability decision result indicates that the variance of change is greater than or equal to the jitter tolerance threshold, the historical average level value is obtained, and the historical average level value is weighted and averaged with the arithmetic mean of the current sample, and then compared with the reference level threshold. The result of the re-comparison is used as the second state value, and the historical average level value is updated with the recalculated weighted average value.

[0011] Optionally, obtaining the backup subsequent instruction execution location information includes: Read the encrypted address ciphertext from the one-time programmable memory unit, and extract the decryption key fragment from the state latched by the input / output pin at startup; The decryption key fragment is concatenated with the key base value stored in the one-time programmable storage unit to obtain the complete decryption key; The complete decryption key is used to perform a decryption operation on the ciphertext of the address to obtain the decrypted plaintext of the address. The decrypted plaintext address is used as the backup execution location information for subsequent instructions.

[0012] Optionally, after sending the backup subsequent instruction execution location information to the processor, the method further includes: After the processor starts executing instructions according to the backup subsequent instruction execution location information, an instruction execution timer is started, and the actual execution time required for the processor to execute a preset number of instructions is recorded; The expected execution time range of the preset number of instructions is read from the one-time programmable memory unit, and the actual execution time is compared with the expected execution time range; When the actual execution time exceeds the expected execution time range, it is determined to be an execution abnormality, triggering a safe reset of the processor, and the abnormal event is recorded in the non-erasable area of ​​the one-time programmable memory unit; When the actual execution time falls within the expected execution time range, the execution is considered normal, and the processor is allowed to continue execution.

[0013] Optionally, the method further includes: Before the processor issues the read request, a random number is generated by a hardware random source and the random number is sent as a challenge value to an external authentication device through the input / output pin. The input / output pins receive the response value returned by the external authentication device, which is calculated by the external authentication device based on the challenge value and the internal key. Read the desired response value from the one-time programmable memory unit and compare the received response value with the desired response value; When the response value matches the expected response value, the execution location selection control signal can be generated subsequently based on the hardware configuration status. When the response value is inconsistent with the expected response value, the execution position selection control signal is forcibly generated to indicate that there is no need to switch the execution position of subsequent instructions, and the one-time programmable memory unit is locked so that it is subsequently unreadable.

[0014] Secondly, this application provides a processor startup process control system, which includes a processor and a computer-readable storage medium. The computer-readable storage medium stores machine-executable instructions. When the machine-executable instructions are executed by a computer, the processor startup process control system implements the aforementioned processor startup process control method.

[0015] The processor boot process control method and system provided in this application, when the processor in the target chip is in a boot state, receives a read request from the processor to obtain the execution location information of subsequent instructions from the original boot memory. Based on the hardware configuration of the target chip, an execution location selection control signal corresponding to the read request is generated. This signal determines whether a switch to the execution location of subsequent instructions is needed. If the execution location selection control signal indicates a need to switch the execution location, backup execution location information is obtained and sent to the processor. This allows the processor to execute subsequent instructions based on the backup execution location information, thus avoiding boot interruptions or failures caused by original boot memory failures or hardware configuration anomalies. This eliminates the need for complete discarding or re-wafering of the faulty chip. The boot process can proceed normally by switching the execution location of subsequent instructions. Furthermore, it can flexibly adapt to boot requirements under different hardware configuration scenarios, thereby improving the flexibility and adjustability of the processor boot process, reducing chip repair and re-wafering costs, and improving mass production yield and delivery stability. Attached Figure Description

[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0017] Figure 1 A flowchart illustrating a processor startup process control method provided in an embodiment of this application; Figure 2 This is a schematic diagram of the structure of a processor startup process control system provided in an embodiment of this application.

[0018] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0019] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] Figure 1This is a flowchart illustrating a processor startup process control method provided in an embodiment of this application. It should be understood that in other embodiments, the order of some steps in the processor startup process control method of this embodiment can be shared according to actual needs, or some steps can be omitted or maintained. Figure 1 As shown, the method may include the following steps: Step S110: When the processor in the target chip is in the boot state, receive a read request sent by the processor. The read request is used to obtain the subsequent instruction execution location information of the processor from the original boot memory.

[0021] The processor boot state refers to the moment when the processor, after being released from the reset state, begins executing instructions located at its reset vector address. A read request is a bus transaction initiated by the processor in the early stages of boot, the purpose of which is to load a data word from a specific address in the raw boot memory. This data word could be, for example, the address of the code that the processor will next jump to execute.

[0022] The processor core contains a program counter register. When the reset signal fails, the value of this program counter register can be forcibly loaded by hardware to a predefined reset vector address, which, for example, can be a 32-bit address. The processor core can then execute instruction fetches starting from this address. This address can store jump instructions or a pointer to the actual startup code.

[0023] To obtain the pointer, the processor core's bus interface unit can automatically initiate a read transaction. This read transaction may include, for example, a transaction identifier, an opcode, a target address, and a length field. For instance, the transaction identifier may be a five- to eight-bit value used to match requests and responses in out-of-order systems; the opcode may be a multi-bit binary code used to indicate that this transaction is a read operation; the target address is equal to the location of the pointer stored in the original boot memory, and for instance, the target address may be a thirty-two-bit address value; the length field may be a two- or three-bit code used to indicate the width of the data to be read.

[0024] Bus transactions are broadcast via a bus conforming to the Advanced Microcontroller Bus Architecture (AMIC) protocol. A boot control circuit is connected to the same bus as a bus slave device. This boot control circuit internally contains address monitoring logic. This address monitoring logic consists of an address comparator and an address mask register. The address mask register stores an address range mask, which, exemplarily, can be a 32-bit wide value, where the high-order bits are all one and the low-order bits are all zero, used to define the address space of the raw boot memory.

[0025] The address comparator compares the target address on the bus with the masked address range. When the address comparator detects that the target address falls within the range defined by the address range mask, and the opcode on the bus matches the read opcode, the address monitoring logic generates a capture pulse. This capture pulse triggers the request register group to latch relevant information about the current bus transaction, including the latched target address value, transaction identifier, and opcode. After latching is complete, the start control circuit internally generates a request valid flag, indicating that the read request issued by the processor has been successfully received and captured.

[0026] Step S120: Based on the hardware configuration state of the target chip, generate an execution position selection control signal corresponding to the read request. The execution position selection control signal is used to determine whether it is necessary to switch the execution position of subsequent instructions. The hardware configuration state includes at least one of the following: the one-time programmable memory cell state of the target chip, and the state of the input / output pins of the target chip latched at startup.

[0027] Hardware configuration status refers to the configuration information of a chip that is determined at the physical level or at startup and cannot or is difficult to modify dynamically through software. The status of a one-time programmable memory cell reflects the permanent setting of non-volatile memory bits within the chip. The state of input / output pins latched at startup reflects the temporary configuration provided by external circuitry through pin levels at startup. Execution location selection control signals, for example, can be binary digital signals used to select from multiple possible sources of subsequent instruction execution locations.

[0028] The configuration status acquisition network reads data from multiple physical sources in parallel. For one-time programmable memory cell states, the configuration status acquisition network includes a one-time programmable memory cell read controller. This controller executes the following sequence: First, it sends a precharge command to the control interface of the one-time programmable memory cell array, charging the bit lines to a preset level. Then, it sends a read enable command while simultaneously sending the address signal of the target memory cell to the array's decoder via the address bus. Exemplarily, the address signal of the target memory cell can be a combination of row and column addresses with a width of eight to twelve bits. The decoder selects a specific word line, activating the memory cell in that row. Each memory cell includes a floating-gate transistor whose threshold voltage varies depending on whether it is programmed. The selected memory cell outputs its data to a sensitive amplifier via the bit line. The sensitive amplifier amplifies the small current or voltage difference on the bit line into a full-swing digital logic level. This digital level is stabilized by an output latch and used as a first state value. Exemplarily, this first state value can be a single-bit logic level.

[0029] For the state latched by the input / output pins during startup, the chip's reset logic includes a startup latch register. On the rising edge of the first clock cycle after reset release, this register samples the output of the input buffer for a specific input / output pin. Exemplarily, the number of such pins can be four, eight, or sixteen. Each pin's input buffer includes a Schmitt trigger to filter out some noise. The sampled high or low level is directly stored in the corresponding bit of the register. The contents of this register are mapped to a specific address space by the address decoding circuit during startup. A configuration state acquisition network obtains the entire register value by reading this mapped address, denoted as the pin latch vector. Exemplarily, this pin latch vector can be an eight-bit or sixteen-bit wide value. A specific bit is extracted from this pin latch vector according to a predefined bit index value, serving as the second state value. Exemplarily, this second state value can be a single-bit logic level. A decision logic circuit, a combinational logic network composed of basic logic gates, receives the first and second state values ​​as inputs.

[0030] This combinational logic network contains lookup tables or hard-coded decision rules. These rules can be expressed, for example, as follows: when condition one, condition two, or condition three is met, the output control signal is logic one; otherwise, it is logic zero. Condition one is defined as a first state value equal to logic one, condition two is defined as a second state value equal to logic one, and condition three is defined as a specific one-time programmable memory cell flag bit equal to logic one. The control signal output by this decision logic circuit is the execution position selection control signal.

[0031] Step S121: Obtain configuration mode indication information, which is derived from at least one of the following: the pre-stored value of the one-time programmable memory cell, the specific position of the input / output pin in the latched state at startup, and the hard-wired bonding option of the target chip.

[0032] Configuration mode indication information is used to indicate which configuration mode the chip should currently follow to interpret the hardware configuration status. Different sources provide mode settings with different priorities or for different scenarios.

[0033] The configuration mode selection module internally implements a priority arbiter. This arbiter first checks a specific validity flag bit in the one-time programmable memory array. This validity flag bit is read in the same way as the first status value, via the one-time programmable memory read controller. If the validity flag bit is logic one, it indicates that the manufacturer has written valid mode configuration data into the one-time programmable memory.

[0034] The arbiter then reads a multi-bit pre-stored value from a specific one-time programmable memory address. Exemplarily, this multi-bit pre-stored value can be two, three, or four bits wide, with the bit width determining the number of configurable modes. The arbiter outputs this multi-bit pre-stored value as the final configuration mode indication information. If the validity flag is logic zero, the arbiter then checks the pin mode enable flag in another one-time programmable memory. If the pin mode enable flag is logic one, the arbiter reads a specific combination of bits from the start-up latch register. Exemplarily, this specific combination of bits can consist of the latched states of two input / output pins at startup, corresponding to the low and high bits of the mode selection bits, respectively, forming a two-bit value.

[0035] The arbiter outputs this specific pin combination as a configuration mode indication. If the pin mode enable flag is also logic zero, the arbiter ultimately employs the hardwire bonding option. The hardwire bonding option is determined during chip design via metal layer programming. For example, the chip has a two-bit hardwire node, where each bit is directly connected to power or ground, thus being fixed to logic one or logic zero. The arbiter reads the level of this node as the hardwire value and outputs it as the configuration mode indication.

[0036] Step S122: Read the state of the one-time programmable memory cell to obtain the first state value, and read the state of the input / output pin latched at startup to obtain the second state value.

[0037] The state acquisition module performs parallel read operations to obtain the raw hardware configuration data. For a one-time programmable memory cell, the state acquisition module initiates a read sequence via a state machine. This sequence first writes a read command to the control register of the one-time programmable memory cell, and then writes the target address. Subsequently, the state machine waits for a preset read delay, which is equal to the sum of the word line setup time, bit line discharge time, and sensitive amplifier settling time of the one-time programmable memory cell. After the delay, the state machine reads the data output register of the one-time programmable memory cell to obtain a multi-bit wide data vector. For example, the width of this data output register can be thirty-two bits or sixty-four bits.

[0038] Since the first state value may only occupy one bit, the state acquisition module includes a bit extractor. The bit extractor extracts a specific bit from the data vector based on a fixed bit index value, latches it, and uses it as the first state value. For input / output pin states, the state acquisition module directly reads the startup configuration register. Each bit in this register corresponds to the input / output pin latched at startup. Similarly, the state acquisition module extracts a specific bit from the startup configuration register based on a fixed bit index value and uses it as the second state value. Both of these state values ​​are single-bit digital logic signals, which are simultaneously fed into the subsequent decision logic circuit.

[0039] Step S1221: When receiving a read request sent by the processor, continuously sample the state of the input / output pin within the sliding sampling window to obtain a sequence of sampled values.

[0040] The states of input / output pins may rapidly change during startup due to signal reflections, power supply ripple, or electromagnetic interference on the circuit board. To improve read reliability, the input / output pin sampling module in the startup control circuit implements a sliding window oversampling mechanism. This module internally contains a high-frequency sampling clock generator, which generates a sampling clock with a frequency much higher than the system clock by multiplying the chip's system clock using a phase-locked loop.

[0041] When the capture request logic in step S110 generates a capture enable signal, this enable signal triggers the sampling module to start operating. The target pin of the sampling module is a specific input / output pin that provides a second state value. The sampling module initiates a continuous sampling process on this pin. The sampling module maintains a shift register with a length denoted as the sampling window width, which can be, for example, sixteen. At the rising edge of each sampling clock cycle, the sampling module samples the current level of the input / output pin to obtain a binary bit, shifts this new bit into the most significant bit of the shift register, while the other bits in the shift register are shifted to the least significant bit, and the least significant bit is shifted out and discarded.

[0042] This process repeats in each sampling clock cycle, thus forming a sampling window that slides forward over time. In the first sampling clock cycle after the capture enable signal is active, the shift register contains only the initial values ​​from the reset. After a number of sampling clock cycles equal to the width of the sampling window, the shift register is completely filled, storing the results of the most recent consecutive samples; this binary number is the sample value sequence. The most significant bit of the sample value sequence represents the latest sample value, and the least significant bit represents the earliest sample value.

[0043] Step S1222: Calculate the arithmetic mean of all sampled values ​​in the sampled value sequence, and compare the arithmetic mean with the preset reference level threshold to obtain the level decision result.

[0044] The sampling module contains a numerical analysis unit that performs mathematical processing on the sampled value sequence in the shift register. First, the numerical analysis unit calculates the arithmetic mean of all bits in the sequence. The calculation process involves iterating through each bit of the shift register and summing the values ​​of each bit using an accumulator to obtain the total.

[0045] Then, a divider circuit is used to divide the sum by the sampling window width. Since the sampling window width is a power of two, this division can be achieved through a right shift operation. Therefore, the arithmetic mean is equal to the sum shifted right by the number of bits corresponding to the sampling window width. Next, the numerical analysis unit compares the calculated arithmetic mean with a preset reference level threshold. The value of the reference level threshold is stored in a register. A comparator circuit determines whether the arithmetic mean is greater than the reference level threshold.

[0046] If the arithmetic mean is greater than the reference level threshold, the comparator outputs logic 1, indicating that the pin was at a high level for the majority of the time within the sampling window, therefore the current pin state is determined to be high. If the arithmetic mean is less than the reference level threshold, the comparator outputs logic 0, determining a low level. If the arithmetic mean is equal to the reference level threshold, the result can be the previous result, or a default low level can be determined. The output of this comparator is the filtered level determination result.

[0047] Step S1223: Calculate the variance of the sampled values ​​in the sampled value sequence, and compare the variance with the preset jitter tolerance threshold to obtain the stability judgment result.

[0048] To further evaluate the stability of the pin states, the numerical analysis unit also calculates the variance of the sampled value sequence. Variance measures how much each sampled value in the sequence deviates from the mean.

[0049] Specifically, the numerical analysis unit has already obtained the arithmetic mean. Then, for each bit in the shift register, the difference between it and the arithmetic mean is calculated. Since each bit can only be zero or one, and the arithmetic mean is a fraction between zero and one, the difference can be negative or positive. Next, the square of each difference is calculated. Because the squaring operation eliminates the sign, all squared terms are non-negative. Then, the numerical analysis unit sums all the squared terms to obtain the sum of squares. Finally, the variance is equal to the sum of squares divided by the sampling window width. This calculation process can be implemented using shifting and addition.

[0050] The calculated variance is fed into a comparator circuit and compared with a preset jitter tolerance threshold. The jitter tolerance threshold value is pre-stored in a register. The comparator determines whether the variance is less than the jitter tolerance threshold. If the variance is less than the jitter tolerance threshold, it indicates that the sampled value sequence is very concentrated with minimal variation, and the pin signal is stable. In this case, the comparator outputs logic one as the stability decision result. If the variance is greater than or equal to the jitter tolerance threshold, it indicates that the sampled value sequence is dispersed, and the pin experiences severe jitter; the stability decision result is logic zero.

[0051] Step S1224: When the stability decision result indicates that the variance of the change is less than the preset jitter tolerance threshold, the level decision result is used as the second state value.

[0052] The outputs of steps S1222 and S1223, namely the level decision result and the stability decision result, are sent to the selection logic circuit. This selection logic circuit checks the value of the stability decision result. If the stability decision result is logic one, it indicates that the pin state is stable and reliable, and the selection logic circuit will directly output the level decision result as the final second state value. This value will be used by the logic in steps S124, S125, S126, etc.

[0053] Step S1225: When the stability decision result indicates that the variance of the change is not less than the preset jitter tolerance threshold, the historical average level value is obtained, and the historical average level value is weighted and averaged with the arithmetic mean of the current sample, and then compared with the reference level threshold. The result of the re-comparison is used as the second state value, and the historical average level value is updated with the recalculated weighted average value.

[0054] If the stability decision result is logic zero, it indicates that the pin state is unstable and jitter exists. In this case, the selection logic circuit switches to a weighted average filtering method. The sampling module internally maintains a historical average level value register, which stores the weighted result of the average level value calculated in previous startup processes. The initial value can be set to the default level, such as the level value of zero corresponding to logic zero.

[0055] When the stability decision result is logic zero, the weighted average calculator is activated. This calculator reads historical average level values ​​and performs a weighted average on the arithmetic mean obtained in the current calculation. The specific calculation method for the weighted average is as follows: the new average level value equals the historical average level value multiplied by a first weighting coefficient, plus the current arithmetic mean multiplied by a second weighting coefficient, where the sum of the first and second weighting coefficients is one. For example, the first weighting coefficient can be 0.7, and the second weighting coefficient can be 0.3.

[0056] After calculating the new average level value, it is compared with a reference level threshold. If the new average level value is greater than the reference level threshold, the result of the recomparison is logic one; otherwise, it is logic zero. This recomparison result is output as the final second state value. Simultaneously, the value in the historical average level value register is updated with the recalculated weighted average value for use in subsequent startup processes. This mechanism can smooth the current decision result using historical information when there is jitter in the pin signal, improving the continuity of decision-making.

[0057] Step S123: Determine the current configuration mode based on the configuration mode indication information. The configuration mode includes using the one-time programmable memory unit alone, using the input / output pin alone, or using the one-time programmable memory unit and the input / output pin simultaneously.

[0058] The mode decoder receives the configuration mode indication information output in step S121. This mode decoder is a multi-input address decoder circuit. Its input is the configuration mode indication information, which may, for example, be a two-bit binary number.

[0059] The mode decoder internally hard-coded the mapping relationship from input encoding to output mode enable signals. For example, when the configuration mode indication information is equal to the binary number "01", the decoder's "One-Time Programmable Memory Unit Only Mode" output is set to logic high, and the other outputs are logic low; when the configuration mode indication information is equal to the binary number "10", the "Input / Output Pin Only Mode" output is set to logic high; when the configuration mode indication information is equal to the binary number "11", the "Simultaneous Use Mode" output is set to logic high; and when the configuration mode indication information is equal to the binary number "00", all outputs are logic low, corresponding to an invalid or default no-switching mode.

[0060] The output of the mode decoder is a mutually exclusive single-bit enable signal, of which only one signal is asserted in the current startup process, thus explicitly indicating the configuration mode to be used by subsequent decision logic.

[0061] Step S124: When the configuration mode is to use the one-time programmable memory unit alone and the first state value is the programmed state, generate the execution position selection control signal that indicates the need to switch the execution position of subsequent instructions.

[0062] The two inputs of the first AND gate logic circuit are connected to the output of the "one-time programmable memory cell mode" and the output of the first comparator, respectively. The first comparator is used to determine whether the first state value is equal to the logical definition of the "programmed state".

[0063] In a typical implementation of a one-time programmable memory cell, an unprogrammed memory bit outputs logic zero upon reading, while a memory bit programmed with high voltage outputs logic one. Therefore, the first comparator is hardwired to check if the first state value is equal to logic one. If the first state value is equal to logic one, the first comparator outputs a logic high level. At this time, both inputs of the first AND gate logic circuit are at logic high levels, and its output is driven to a logic high level. This output level is the execution position selection control signal, indicating that the execution position of subsequent instructions needs to be switched. If the first state value is equal to logic zero, the first comparator outputs a logic low level, the first AND gate logic circuit outputs a logic low level, and the execution position selection control signal is set to logic zero, indicating that no switching is needed.

[0064] Step S125: When the configuration mode is to use the input / output pin alone and the second state value is not at the default level, generate the execution position selection control signal that indicates the need to switch the execution position of subsequent instructions.

[0065] The two inputs of the second AND gate logic circuit are connected to the output of the "input-only pin mode" and the output of the second comparator, respectively. The second comparator is used to determine whether the second state value is equal to the "non-default level". The default level can be specified, for example, by the chip's datasheet and determined by pull-down or pull-up resistors in external circuitry. In this embodiment, the default level is designed to be logic zero.

[0066] Therefore, the second comparator is implemented to check if the second state value is equal to logic one. If the second state value is equal to logic one, the second comparator outputs a logic high level. At this time, both inputs of the second AND gate logic circuit are at logic high levels, and its output is driven to a logic high level, that is, the execution position selection control signal is set to logic one, indicating that a switch is needed. If the second state value is equal to logic zero, the execution position selection control signal is set to logic zero.

[0067] Step S126: When the configuration mode uses both the one-time programmable memory cell and the input / output pin and the first state value is the programmed state or the second state value is a non-default level, generate the execution position selection control signal that indicates the need to switch the execution position of subsequent instructions.

[0068] The two inputs of an OR gate logic circuit are connected to the outputs of a first comparator and a second comparator, respectively. The first comparator indicates whether a first state value is logic 1, and the second comparator indicates whether a second state value is logic 1. The OR gate logic circuit performs a logical OR operation; its output is logic high as long as at least one of the two inputs is logic high.

[0069] The two inputs of the third AND gate logic circuit are connected to the output of the "simultaneous use mode" and the output of the aforementioned OR gate logic circuit, respectively. Therefore, when the "simultaneous use mode" output is logic high, if either the first or second state value is logic one, the OR gate outputs logic high, which in turn causes the third AND gate to output logic high, ultimately setting the execution position selection control signal to logic one. Only when both the first and second state values ​​are logic zero is the execution position selection control signal set to logic zero, thus implementing the "switch if any condition is met" decision logic.

[0070] Step S127: Otherwise, the generation of the representation does not require switching the execution location selection control signal of the subsequent instruction execution location.

[0071] This step covers all situations not explicitly captured by steps S124, S125, and S126. These situations include: the configuration mode is "one-time programmable memory cell mode only" but the first state value is logic zero; the configuration mode is "input / output pin mode only" but the second state value is logic zero; the configuration mode is "simultaneous use mode" but both the first and second state values ​​are logic zero; and the configuration mode indication information points to an undefined code, causing the output terminals of "one-time programmable memory cell mode only", "input / output pin mode only", and "simultaneous use mode" to all be logic zero.

[0072] In all the above cases, the logic circuit responsible for ultimately generating the execution location selection control signal, such as a flip-flop with an enable input or a tri-state gate, will set its output to logic zero. This logic zero signal indicates that there is no need to switch the execution location of subsequent instructions, and the processor will continue execution at the original address read from the original boot memory.

[0073] Step S130: If the control signal at the execution position indicates that the execution position of the subsequent instruction needs to be switched, obtain the information of the backup execution position of the subsequent instruction.

[0074] When the execution location selection control signal is logic one, it indicates that the execution location of the processor's subsequent instructions needs to be switched. At this time, the start control circuit initiates the backup address acquisition process. The backup subsequent instruction execution location information can come from multiple possible internal or external sources, such as fixed address constants, addresses stored in one-time programmable memory cells, or entries in an address table selected by an external pin. There are two main ways to acquire this information, as described in steps S131-A to S133-A and steps S131-B to S135-B, respectively.

[0075] Step S131-A: Receive the original subsequent instruction execution location information returned by the original boot memory according to the read request.

[0076] While the boot control circuit processes the read request, the request is also sent to the primary boot memory. The primary boot memory, such as the external serial peripheral interface flash memory, returns the read data after a delay period. This data is the original subsequent instruction execution location information, storing the processor's default jump target address. The boot control circuit internally includes a data receive buffer that captures the read response data returned from the primary boot memory on the bus, including the returned data value and the corresponding transaction identifier. By matching the transaction identifier, the boot control circuit can associate the returned data value with the previously captured read request, thereby obtaining the original subsequent instruction execution location information.

[0077] Step S132-A: Obtain the execution location information of the backup subsequent instruction from the target source, which includes at least one of the following: fixed address constant, address data generated by decoding the one-time programmable memory unit, and one set of address data selected from multiple address setting tables.

[0078] In parallel with acquiring the original address, the startup control circuit obtains a backup address from a preset target source. The fixed address constant can be a set of 32-bit binary values ​​hardwired within the chip, which directly serves as the backup location information for subsequent instruction execution. Address data generated by decoding a one-time programmable memory cell refers to reading the values ​​of multiple storage bits from the one-time programmable memory cell array; these values ​​are combined to form a complete address.

[0079] For example, thirty-two consecutive storage bits can be allocated in a one-time programmable memory unit, with each storage bit storing one bit of the address. After being read by the one-time programmable memory unit read controller, these bits are concatenated to form a thirty-two-bit address value. Selecting one set of address data from multiple address setting tables means that the chip internally contains a register group that stores multiple predefined address values. For example, four sets of addresses can be stored, each set being thirty-two bits. A selection logic selects one set of addresses from these four sets based on specific combinations of the latched states of input / output pins at startup. For example, the states of two pins can be combined to form a two-bit selection signal. This selection is used as backup location information for subsequent instruction execution.

[0080] Step S133-A: Based on the execution position selection control signal, the data selection circuit selects the backup subsequent instruction execution position information as the address information to be sent from the original subsequent instruction execution position information and the backup subsequent instruction execution position information.

[0081] The data selection circuit is a 2-to-1 multiplexer. Its two data inputs are connected to the original subsequent instruction execution location information and the alternate subsequent instruction execution location information, respectively. Its selection control terminal is connected to the execution location selection control signal. Since the execution location selection control signal is currently logic 1, indicating a switch is required, the multiplexer passes the alternate subsequent instruction execution location information to its output. This output is the address information to be sent, ready to be sent to the processor.

[0082] Step S131-B: Based on the execution location selection control signal, the target address of the read request is redirected from the original boot memory to the backup address source through the access path selection mechanism, and the read request is sent to the backup address source, which includes at least one of the following: another memory region inside the target chip, the address space mapped by the one-time programmable memory cell, and external memory.

[0083] Steps S131-A to S133-A describe a method where data is received from the original memory and then replaced. The implementation in this application embodiment changes the access path directly during the request phase.

[0084] When the execution location selection control signal is logic one, the access path selection mechanism is activated. This mechanism may include address remapping logic. When the address monitoring logic captures a read request from the processor, the target address of this read request originally points to the original boot memory. The address remapping logic intercepts this request and does not forward it to the bus interface of the original boot memory. Instead, according to a preset remapping rule, it converts the target address into the corresponding address from the alternative address source. For example, if the alternative address source is another memory region inside the chip, such as internal static random access memory (SRAM), the address remapping logic can replace the high-order part of the original address with the base address of the internal SRAM to form a new target address. Then, the boot control circuit sends the modified read request to the corresponding bus interface, which is connected to the alternative address source.

[0085] Step S132-B: Receive the backup address source's backup subsequent instruction execution location information returned according to the read request.

[0086] Upon receiving the redirected read request, the backup address source performs a memory read operation and returns the read data. The data receive buffer of the startup control circuit captures this returned data, which serves as the location information for subsequent instruction execution. Unlike step S133-A, in this mode, the processor issues only one request, and the startup control circuit internally redirects the request to a different physical target. The response data received by the processor comes directly from the backup address source.

[0087] Step S140: Send the backup subsequent instruction execution location information to the processor so that the processor executes the subsequent instruction jump according to the backup subsequent instruction execution location information.

[0088] After obtaining the location information for the backup subsequent instructions, whether selected by the data selection circuit or received directly, the startup control circuit needs to return this address information to the processor. The startup control circuit constructs a read response transaction, which includes a transaction identifier matching the original read request and the location information for the backup subsequent instructions as response data.

[0089] The response transaction is sent back to the processor via the bus. Upon receiving the response, the processor's bus interface unit extracts the data value and loads it into the processor's program counter register. When the processor continues executing the next instruction, the new address value in the program counter register causes the processor to jump to the address indicated by the standby instruction execution location information to begin fetching and executing the instruction, thus completing the switch of the subsequent instruction execution location.

[0090] The method provided in this application, when the processor in the target chip is in a boot state, receives a read request from the processor to obtain the execution location information of subsequent instructions from the original boot memory. Based on the hardware configuration of the target chip, an execution location selection control signal corresponding to the read request is generated. This signal determines whether a switch to the execution location of subsequent instructions is needed. If the execution location selection control signal indicates a need to switch, backup execution location information is obtained and sent to the processor. This allows the processor to execute subsequent instructions based on the backup execution location information, thus avoiding boot interruptions or failures caused by original boot memory failures or hardware configuration anomalies. This eliminates the need for complete discarding or re-wafering of the faulty chip. The boot process can proceed normally by switching the execution location of subsequent instructions. Furthermore, it can flexibly adapt to boot requirements under different hardware configuration scenarios, thereby improving the flexibility and adjustability of the processor boot process, reducing chip repair and re-wafering costs, and improving mass production yield and delivery stability.

[0091] Step S210: Obtain the historical startup result sequence, which contains records of whether each startup successfully executed subsequent instructions during multiple consecutive startup processes.

[0092] The chip internally maintains a non-volatile boot log area. This non-volatile boot log area can be a rewritable memory area partitioned within a one-time programmable memory cell, or a separate block of flash memory or electrically erasable programmable read-only memory. Each time the chip completes a full boot process, whether it successfully executes subsequent instructions and jumps to the main application, or triggers an exception and causes a system reset due to jumping to an incorrect address, the boot control circuit writes a record to this log area. This record is a single-bit flag, with logic 1 indicating a successful boot and logic 0 indicating a boot failure.

[0093] The above records are stored sequentially in consecutive addresses within the log area, forming a sequence that grows over time. At the start of this startup process, the historical analysis module reads sequentially from the beginning address of this non-volatile log area until it reaches the last stored record. These record values ​​are then stored sequentially in an internal shift register, forming a historical startup result sequence. The length of this sequence is variable; for example, it can store the results of the sixteen most recent startups. Each element in the sequence is a binary success or failure flag.

[0094] Step S220: Perform pattern analysis on the historical startup result sequence to identify the number of consecutive failed startups and the number of consecutive successful startups in the historical startup result sequence.

[0095] The history analysis module iterates through and analyzes the sequence stored in the shift register. Internally, this module contains a finite state machine to identify the longest consecutive success and failure patterns. The state machine backtracks from the end of the sequence, i.e., the most recently started record. The history analysis module initializes two counters: a consecutive failure counter and a consecutive success counter, both initially set to zero.

[0096] The state machine enters a backtracking loop, checking each element in the sequence. If the currently checked element has a value of zero, representing a failure, the state machine increments the consecutive failure counter by one and resets the consecutive success counter to zero. Then, the state machine moves the backtracking pointer forward one position to continue checking earlier records. If the checked element has a value of one, representing a success, the state machine increments the consecutive success counter by one and resets the consecutive failure counter to zero. The state machine repeats this process until one of the following two cases is encountered: the first case is that the backtracking pointer has moved to before the beginning of the sequence, meaning all records have been checked; the second case is that an element opposite to the currently accumulating pattern is checked, such as encountering a success record while accumulating consecutive failures, or encountering a failure record while accumulating consecutive successes. At this point, the accumulation process stops, and the consecutive failure counter or consecutive success counter stores the number of consecutive failures or consecutive successes obtained from the most recent start backtracking. The analysis module uses these two count values ​​as output signals.

[0097] Step S230: When the number of consecutive failed startups reaches the first preset threshold, the current configuration mode is set to use the one-time programmable memory unit and the input / output pin at the same time, and the first state value and the second state value are logically XORed as the judgment basis. When the logical XOR result is valid, the execution position selection control signal representing the need to switch is generated.

[0098] The dynamic configuration adjustment logic receives the consecutive failure count output by the historical analysis module. This adjustment logic internally includes a first numerical comparator circuit. The two inputs of this first numerical comparator are connected to the consecutive failure count signal and a register storing a first preset threshold, respectively. The first preset threshold can be set via hardwiring during chip design.

[0099] The first numerical comparator checks whether the number of consecutive failures is greater than or equal to a first preset threshold. If the condition is met, it indicates that multiple consecutive startup failures have occurred, meaning the current configuration mode or decision logic cannot adapt to a harsh environment or incorrect configuration. At this time, the mode overriding logic is triggered. This logic ignores the configuration mode obtained by decoding the configuration mode indication information in step S123 and forces the current valid configuration mode to be set to the "simultaneous use of one-time programmable memory units and input / output pins" mode. In addition, it can also force a change in the determination criteria, no longer using the "logical OR" operation described in step S126, but switching to an XOR logic gate. The two inputs of this XOR logic gate are still the first state value and the second state value. The output of the XOR logic gate is logic one when the first state value and the second state value are different, and logic zero when they are the same.

[0100] Therefore, the new criterion is: the execution location selection control signal is set to logic one only when the first state value and the second state value are inconsistent, indicating that a switch is required. This XOR decision method can provide a definite decision when two configuration sources contradict each other, avoiding incorrect judgments caused by both being faulty or subject to the same interference simultaneously.

[0101] Step S240: When the number of consecutive successful startups reaches the second preset threshold, the current configuration mode is set to use the one-time programmable storage unit alone, and the first state value is used as the basis for the determination.

[0102] The dynamic configuration adjustment logic also receives the consecutive success count output by the historical analysis module. This adjustment logic internally includes a second numerical comparator circuit. The two inputs of this second numerical comparator are connected to the consecutive success count signal and a register storing a second preset threshold, respectively. The second preset threshold can also be set via hard-wiring. The second numerical comparator checks whether the consecutive success count is greater than or equal to the second preset threshold. If the condition is met, it indicates that multiple consecutive successful starts have occurred, suggesting that the current hardware configuration and external environment are very stable and reliable. To maximize system determinism and security and eliminate uncertainties that may be introduced by external input / output pins, the mode override logic is triggered. This logic forces the current effective configuration mode to be set to "single use of one-time programmable memory cell" mode and forces the decision criterion to be simplified to directly using the first state value. At this time, the value of the execution position selection control signal is directly equal to the first state value. If the first state value is logic one, i.e., the programmed state, then the execution position selection control signal is logic one, indicating that a switch is needed; if the first state value is logic zero, then the execution position selection control signal is logic zero. This mode makes the startup decision entirely determined by the state of the unchangeable one-time programmable memory cell inside the chip.

[0103] Step S250: When the number of consecutive failed startups does not reach the first preset threshold and the number of consecutive successful startups does not reach the second preset threshold, the configuration mode determined by the configuration mode indication information remains unchanged.

[0104] If the number of consecutive failures is less than a first preset threshold and the number of consecutive successes is less than a second preset threshold, it means that the system's startup history is in an intermediate state, exhibiting neither a severe failure mode nor meeting the standard for stable success. In this case, the mode overriding logic will not be triggered. The startup control circuit will operate entirely according to the normal process described in steps S121, S122, S123, S124, S125, S126, and S127, that is, it will use the original configuration mode determined by the configuration mode indication information and the corresponding decision logic.

[0105] The method provided in this application acquires a historical boot result sequence, analyzes the boot success and failure records in the sequence, and identifies the number of consecutive boot failures and the number of consecutive boot successes. When the number of consecutive boot failures reaches a preset standard, the boot control logic is adjusted to adopt a dual-configuration source determination method to ensure that the subsequent boot process can proceed normally; when the number of consecutive boot successes reaches a preset standard, it switches to a single-configuration source determination method to reduce external interference factors and ensure the stability of the boot process. Through this dynamic adjustment method, abnormal interruption problems in the boot process are effectively avoided, the reliability of the boot process is improved, and no additional hardware cost is required. It balances boot efficiency and stability, ensuring that the processor can complete the boot process stably and efficiently, thereby ensuring the accuracy and continuity of subsequent instruction execution.

[0106] Step S310: Read the encrypted address ciphertext from the one-time programmable memory unit, and extract the decryption key fragment from the state latched by the input / output pin at startup.

[0107] To enhance the security of the startup process, the backup subsequent instruction execution location information can be stored in encrypted form. Steps S310 to S340 describe a secure implementation method for obtaining the backup address. The startup control circuit internally includes a decryption module.

[0108] The decryption module first sends a request to the one-time programmable memory read controller to read the encrypted address ciphertext stored within a specific address range. For example, this address ciphertext can be 32-bit or 64-bit wide ciphertext data. Simultaneously, the decryption module reads the value from the start-up latch register, the contents of which are derived from the latched state of the input / output pins at startup. The decryption module extracts the decryption key fragment from specific bits of this register according to a predetermined key fragment distribution rule. For example, the lowest four bits of the register can be specified as the key fragment, or every other bit can be extracted to form the key fragment.

[0109] Step S320: Concatenate the decryption key fragment with the key base value stored in the one-time programmable storage unit to obtain the complete decryption key.

[0110] In addition to storing the ciphertext address, the one-time programmable memory unit can also store a key base value. The decryption module sends a request to the one-time programmable memory unit read controller to read the key base value. For example, the key base value can be data with a width of 32 bits or 56 bits. The decryption module performs a concatenation operation between the decryption key fragment extracted in step S310 and the key base value. For example, the key fragment can be appended before the most significant bit of the key base value, or appended after the least significant bit, or mixed according to a preset bit interleaving rule, etc.

[0111] The concatenated decryption key has a predetermined total bit width, such as 64 bits. This complete decryption key will be used for subsequent decryption operations.

[0112] Step S330: Use the complete decryption key to perform a decryption operation on the ciphertext of the address to obtain the decrypted plaintext address.

[0113] The decryption module contains a decryption algorithm engine, which, for example, can implement the Advanced Encryption Standard (AES) algorithm. The decryption algorithm engine receives the complete decryption key and the ciphertext address as input. Based on a preset decryption mode, such as electronic codebook mode or cipher block chaining mode, the decryption algorithm engine performs multiple rounds of decryption operations. Taking the AES algorithm as an example, the decryption operation may include the following steps: First, a round key addition operation is performed, XORing the ciphertext address with the subkey from the last round. Then, an inverse byte substitution operation is performed, replacing each byte with its corresponding value using the inverse S-box. Next, a reverse row shift operation is performed, cyclically shifting the rows in the state matrix in reverse according to a specific rule. Then, an inverse column mixing operation is performed, inversely multiplying each column with a fixed polynomial. These steps are repeated multiple times until the first round of inverse column mixing is completed. Finally, another inverse byte substitution, inverse row shift, and round key addition operation are performed, outputting the decrypted plaintext address. This plaintext address is the original, unencrypted backup location information for subsequent instruction execution.

[0114] Step S340: Use the decrypted plaintext address as the backup execution location information for subsequent instructions.

[0115] The plaintext address output by the decryption algorithm engine is latched into a spare address register as the final spare address for subsequent instruction execution. This information is then sent to the processor via step S140, enabling the processor to jump to the decrypted address to execute instructions.

[0116] The method provided in this application stores the backup subsequent instruction execution location information in encrypted form in a one-time programmable memory unit. Simultaneously, the decryption key is split into a key base value and key fragments, which are stored separately. The key base value is stored in the one-time programmable memory unit, and the key fragments are extracted from the input / output pin states latched during startup. This distributed storage of the decryption key significantly improves the security of the startup process and effectively prevents the illegal theft or tampering of backup address information. The complete decryption key is then combined using specific concatenation rules, and the address ciphertext is decrypted using encryption algorithms such as Advanced Encryption Standards (AES), ensuring the reliability and security of the decryption process and accurately obtaining the backup subsequent instruction execution location information. The entire process requires no additional hardware cost. While ensuring the security of the startup process, it ensures that the processor can successfully obtain the backup execution location when needed and proceed with the startup process normally, avoiding startup failures caused by address information leakage or tampering. This further improves the stability, security, and reliability of processor startup, while simplifying the implementation process of secure encryption and decryption, balancing security and execution efficiency.

[0117] Step S410: After the processor starts executing instructions according to the backup subsequent instruction execution location information, start the instruction execution timer and record the actual execution time required for the processor to execute the preset number of instructions.

[0118] After the processor successfully jumps to the address indicated by the standby subsequent instruction execution location information and begins instruction execution, the startup control circuit can activate a security monitoring mechanism. This security monitoring mechanism includes an instruction execution timer. This timer can be implemented by a high-precision counter driven by the chip's system clock.

[0119] When the processor program counter is loaded into a spare address and completes its first fetch, a trigger signal is generated, which starts a timer. Simultaneously, a preset instruction count counter is also started. This counter monitors the state of the processor's instruction retirement bus or execution unit, incrementing its value each time the processor successfully executes and retires an instruction. When the number of retired instructions reaches a preset value (e.g., one hundred or one thousand instructions), the timer stops, and its current count is latched. This count, multiplied by the system clock cycle, represents the actual execution time required for the processor to complete the preset number of instructions.

[0120] Step S420: Read the expected execution time range of the preset number of instructions from the one-time programmable memory unit, and compare the actual execution time with the expected execution time range.

[0121] During the chip design or manufacturing phase, the time range required for a processor to execute a specific number of instructions under normal conditions can be obtained through analysis or testing. This expected execution time range is pre-programmed into a one-time programmable memory cell.

[0122] For example, the expected execution time range may include a lower threshold and an upper threshold, stored in two separate one-time programmable memory addresses. The startup control circuit reads these two thresholds and compares them with the actual execution time measured in step S410.

[0123] Step S430: When the actual execution time exceeds the expected execution time range, it is determined to be an execution abnormality, triggering a safe reset of the processor, and the abnormal event is recorded in the non-erasable area of ​​the one-time programmable memory unit.

[0124] The comparator determines whether the actual execution time is less than the lower threshold or greater than the upper threshold. If the actual execution time exceeds the range defined by the lower and upper thresholds, it indicates that the processor's instruction execution speed is abnormal, which may mean that the processor has been injected with malicious code, its clock frequency has been tampered with, or its instruction cache has been corrupted. At this time, the security monitoring logic generates an exception flag and sends a reset request to the processor's reset controller, triggering a security reset operation to allow the chip to re-enter the startup state.

[0125] Simultaneously, the exception event logging module is activated. This module writes information about the current exception event, such as the exception type code and timestamp, into a specially designated non-erasable area within a one-time programmable storage unit. This area is locked after being written, and no subsequent operation can modify or erase the record, thus forming an undeniable security audit log.

[0126] Step S440: When the actual execution time falls within the expected execution time range, it is determined that the execution is normal, and the processor is allowed to continue execution.

[0127] If the actual execution time is greater than or equal to the lower threshold and less than or equal to the upper threshold, it indicates that the processor's instruction execution speed is normal. In this case, the security monitoring logic does not generate an exception flag, does not interfere with the processor's operation, and allows the processor to continue executing subsequent instructions until the complete boot process is completed and the main application is entered.

[0128] The method provided in this application starts an instruction execution timer after the processor executes a backup subsequent instruction, records the actual execution time of the processor executing a preset number of instructions in real time, and reads a preset expected execution time range from a one-time programmable memory unit. The actual execution time is then precisely compared with the expected time range to determine whether the processor instruction execution is normal. When the actual execution time exceeds the expected range, it is determined to be an execution anomaly, immediately triggering a processor safety reset, and the anomaly event is recorded in the non-erasable area of ​​the one-time programmable memory unit, forming an immutable security audit log to prevent the anomaly from escalating. When the actual execution time falls within the expected range, it is determined to be normal execution, allowing the processor to continue executing subsequent instructions. This method achieves real-time security monitoring of the processor instruction execution status through a simple and efficient time comparison mechanism, without the need for additional complex hardware. It can promptly detect instruction execution anomalies, prevent fault propagation, and provide a basis for subsequent fault investigation through non-erasable anomaly records. It also ensures the stability and security of processor startup and instruction execution, balancing monitoring efficiency and system reliability, effectively reducing fault investigation costs, and improving the security and controllability of chip operation.

[0129] Step S510: Before the processor issues the read request, a random number is generated by a hardware random source and sent as a challenge value to an external authentication device through the input / output pin.

[0130] To authenticate the external environment before the startup process begins, the chip can perform a two-way authentication step. Before the processor issues a read request for information on the execution location of subsequent instructions, the startup control circuitry initiates the authentication process. The chip internally includes a hardware random number generator that generates truly random numbers based on physical entropy sources such as circuit thermal noise or oscillator jitter. This random number, serving as a challenge value, is sent via output pins configured for output mode, according to a serial or parallel communication protocol, to an external authentication device, such as a dedicated security chip or cryptographic coprocessor.

[0131] Step S520: Receive the response value returned by the external authentication device through the input / output pin. The response value is calculated by the external authentication device based on the challenge value and the internal key.

[0132] Upon receiving the challenge value, the external authentication device uses its internally stored key to perform a preset encryption or hash operation on the challenge value, generating a response value. This response value is returned to the chip via input / output pins. After sending the challenge value, the chip's input / output pins switch to input mode, receive the response value, and store it in internal registers.

[0133] Step S530: Read the desired response value from the one-time programmable storage unit and compare the received response value with the desired response value.

[0134] During the chip manufacturing stage, one or more sets of correct response values ​​are pre-calculated based on the internal key of the external authentication device and a preset algorithm, and then burned into the chip's one-time programmable memory. The start control circuit reads the expected response value and compares it bit by bit with the actual response value received in step S520.

[0135] Step S540: When the response value matches the expected response value, the subsequent generation of the execution location selection control signal is allowed based on the hardware configuration status.

[0136] If the received response value is exactly the same as the expected response value read from the one-time programmable memory unit, it indicates that the external authentication device is legitimate and the current hardware environment of the chip is trustworthy. At this time, the authentication logic outputs an authentication pass flag, allowing the startup process to continue, that is, allowing the execution of step S120 and subsequent steps, and normally generating the execution position selection control signal.

[0137] Step S550: When the response value is inconsistent with the expected response value, the execution location selection control signal is forcibly generated to indicate that the execution location of subsequent instructions does not need to be switched, and the one-time programmable memory unit is locked so that it is subsequently unreadable.

[0138] If the received response value is inconsistent with the expected response value, it indicates that the external authentication device is illegal or does not exist, and the chip may be in an environment under attack. At this time, the authentication logic outputs an authentication failure flag. This flag forcibly overrides the output of the decision logic circuit in step S120, forcibly setting the execution position selection control signal to logic zero, that is, indicating that there is no need to switch the execution position of subsequent instructions.

[0139] Furthermore, the chip's internal access control logic is activated, cutting off all subsequent read paths to the one-time programmable memory cell. Any attempt to read the one-time programmable memory cell will return all zeros or trigger a bus error. This prevents attackers from exploiting an unauthorized environment to induce the chip to boot from an insecure alternate address and prevents attackers from reading sensitive information stored in the one-time programmable memory cell.

[0140] The method provided in this application generates a random challenge value using the chip's internal hardware random source before the processor issues a read request and sends it to an external authentication device. It then receives a response value generated by the external authentication device using its internal key and compares this response value with a pre-programmed expected response value to verify the legitimacy of the external device and the operating environment. Only when authentication is successful can the subsequent execution location selection control signal generation process proceed normally, ensuring the orderly progress of the startup process. If authentication fails, the instruction execution location is forcibly locked, preventing switching, and the read access of the one-time programmable memory unit is blocked. This intercepts unauthorized external device access and malicious emulation attacks at the source, eliminating the security risk of the chip starting from a backup address in an untrusted environment. It also prevents the unauthorized reading and theft of internal encryption keys and address data, thereby comprehensively strengthening the chip's identity verification capabilities and security protection level during the startup phase, ensuring that the chip only completes normal startup and operation in a legitimate and trusted hardware environment.

[0141] Figure 2 This is a schematic diagram of a processor startup process control system provided in an embodiment of this application. Figure 2 As shown, the processor 110 can be used in the processor startup process control system and to perform the functions in this invention.

[0142] The processor boot process control system can be a general-purpose server or a special-purpose server; both can be used to implement the processor boot process control method of this invention. Although only one server is shown in this invention, for convenience, the functions described in this invention can be implemented in a distributed manner on multiple similar platforms to balance the processing load.

[0143] For example, a processor boot process control system may include a network port 100 connected to a network, one or more processors 110 for executing program instructions, a communication bus 140, and various forms of storage media 130, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the processor boot process control system may also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The method of the present invention can be implemented according to these program instructions. The processor boot process control system also includes an input / output (I / O) interface 120 between the computer and other input / output devices.

[0144] For ease of explanation, only one processor is described in the processor startup process control system. However, it should be noted that the processor startup process control system of the present invention may also include multiple processors, and therefore the steps executed by one processor as described in the present invention may also be executed jointly by multiple processors or individually. For example, if the processor of the processor startup process control system executes steps A and B, it should be understood that steps A and B may also be executed jointly by two different processors or individually by one processor. For example, the first processor executes step A, the second processor executes step B, or the first processor and the second processor jointly execute steps A and B.

[0145] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any inventive effort.

[0146] Finally, it should be noted that the above-disclosed embodiments are merely preferred embodiments of the present invention and are only used to illustrate the technical solutions of the present invention, not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A processor startup process control method, characterized in that, include: When the processor in the target chip is in the boot state, a read request sent by the processor is received. The read request is used to obtain the subsequent instruction execution location information of the processor from the original boot memory. Based on the hardware configuration status of the target chip, an execution position selection control signal corresponding to the read request is generated. The execution position selection control signal is used to determine whether it is necessary to switch the execution position of subsequent instructions. The hardware configuration status includes at least one of the following: the one-time programmable memory cell status of the target chip, and the state of the input / output pins of the target chip latched at startup. When the execution position selection control signal indicates that the execution position of the subsequent instruction needs to be switched, information on the alternative execution position of the subsequent instruction is obtained. The backup subsequent instruction execution location information is sent to the processor, so that the processor executes the subsequent instruction jump according to the backup subsequent instruction execution location information; The step of generating an execution location selection control signal corresponding to the read request based on the hardware configuration status of the target chip includes: Obtain configuration mode indication information, which is derived from at least one of the following: the pre-stored value of the one-time programmable memory cell, the specific position of the input / output pin in the latched state at startup, and the hardwired bonding option of the target chip; The state of the one-time programmable memory cell is read to obtain a first state value, and the state of the input / output pin latched at startup is read to obtain a second state value; The current configuration mode is determined based on the configuration mode indication information. The configuration mode includes using the one-time programmable memory unit alone, using the input / output pin alone, or using both the one-time programmable memory unit and the input / output pin simultaneously. When the configuration mode is to use the one-time programmable storage unit alone and the first state value is programmed, an execution position selection control signal is generated to indicate that the execution position of subsequent instructions needs to be switched. When the configuration mode is to use the input / output pins alone and the second state value is not at the default level, an execution position selection control signal is generated to indicate that the execution position of subsequent instructions needs to be switched. When the configuration mode is to use the one-time programmable memory unit and the input / output pins simultaneously and the first state value is a programmed state or the second state value is a non-default level, an execution position selection control signal is generated to indicate that the execution position of subsequent instructions needs to be switched. Otherwise, the execution location selection control signal for generating the representation does not require switching the execution location of subsequent instructions.

2. The processor startup process control method according to claim 1, characterized in that, When the control signal at the execution position selection indicates that the execution position of the subsequent instruction needs to be switched, obtaining the backup execution position information for the subsequent instruction includes: Receive the original subsequent instruction execution location information returned by the original boot memory according to the read request; The backup subsequent instruction execution location information is obtained from a target source, wherein the target source includes at least one of the following: a fixed address constant, address data generated by decoding the one-time programmable memory unit, or a set of address data selected from multiple address setting tables; Based on the execution position selection control signal, the data selection circuit selects the backup subsequent instruction execution position information as the address information to be sent from the original subsequent instruction execution position information and the backup subsequent instruction execution position information.

3. The processor startup process control method according to claim 1, characterized in that, When the control signal at the execution position selection indicates that the execution position of the subsequent instruction needs to be switched, obtaining the backup execution position information for the subsequent instruction includes: According to the execution location selection control signal, the target address of the read request is redirected from the original boot memory to the backup address source through the access path selection mechanism, and the read request is sent to the backup address source. The backup address source includes at least one of the following: another memory region inside the target chip, the address space mapped by the one-time programmable memory cell, and external memory. Receive the backup address source returning the backup subsequent instruction execution location information based on the read request.

4. The processor startup process control method according to claim 1, characterized in that, Before obtaining the configuration mode indication information, the process also includes: Obtain a historical startup result sequence, which includes records of whether each startup successfully executed subsequent instruction jumps during multiple consecutive startup processes; Pattern analysis is performed on the historical startup result sequence to identify the number of consecutive failed startups and the number of consecutive successful startups in the historical startup result sequence; When the number of consecutive failed startups reaches a first preset threshold, the current configuration mode is set to use the one-time programmable storage unit and the input / output pins simultaneously, and the first state value and the second state value are logically XORed as the determination basis. When the logical XOR result is valid, the execution position selection control signal representing the need to switch is generated. When the number of consecutive successful startups reaches the second preset threshold, the current configuration mode is set to use the one-time programmable storage unit alone, and the first status value is used as the determination criterion. When the number of consecutive failed startups does not reach the first preset threshold and the number of consecutive successful startups does not reach the second preset threshold, the configuration mode determined by the configuration mode indication information remains unchanged.

5. The processor startup process control method according to claim 4, characterized in that, The process of reading the state of the input / output pins latched at startup to obtain the second state value includes: When receiving a read request from the processor, the state of the input / output pins is continuously sampled within a sliding sampling window to obtain a sequence of sampled values; Calculate the arithmetic mean of all sampled values ​​in the sampled value sequence, and compare the arithmetic mean with a preset reference level threshold to obtain the level decision result; Calculate the variance of the sampled values ​​in the sampled value sequence, and compare the variance with a preset jitter tolerance threshold to obtain a stability decision result; When the stability decision result indicates that the variance of change is less than the preset jitter tolerance threshold, the level decision result is taken as the second state value; When the stability decision result indicates that the variance of change is greater than or equal to the jitter tolerance threshold, the historical average level value is obtained, and the historical average level value is weighted and averaged with the arithmetic mean of the current sample, and then compared with the preset reference level threshold. The result of the re-comparison is used as the second state value, and the historical average level value is updated with the recalculated weighted average value.

6. The processor startup process control method according to claim 1, characterized in that, The step of obtaining the location information for executing backup subsequent instructions includes: Read the encrypted address ciphertext from the one-time programmable memory unit, and extract the decryption key fragment from the state latched by the input / output pin at startup; The decryption key fragment is concatenated with the key base value stored in the one-time programmable storage unit to obtain the complete decryption key; The complete decryption key is used to perform a decryption operation on the ciphertext of the address to obtain the decrypted plaintext of the address. The decrypted plaintext address is used as the backup execution location information for subsequent instructions.

7. The processor startup process control method according to claim 1, characterized in that, After sending the backup subsequent instruction execution location information to the processor, the method further includes: After the processor starts executing instructions according to the backup subsequent instruction execution location information, an instruction execution timer is started, and the actual execution time required for the processor to execute a preset number of instructions is recorded; The expected execution time range of the preset number of instructions is read from the one-time programmable memory unit, and the actual execution time is compared with the expected execution time range; When the actual execution time exceeds the expected execution time range, it is determined to be an execution abnormality, triggering a safe reset of the processor, and the abnormal event is recorded in the non-erasable area of ​​the one-time programmable memory unit; When the actual execution time falls within the expected execution time range, the execution is considered normal, and the processor is allowed to continue execution.

8. The processor startup process control method according to claim 1, characterized in that, The method further includes: Before the processor issues the read request, a random number is generated by a hardware random source and the random number is sent as a challenge value to an external authentication device via an input / output pin. The input / output pins receive the response value returned by the external authentication device, which is calculated by the external authentication device based on the challenge value and the internal key. Read the desired response value from the one-time programmable memory unit and compare the received response value with the desired response value; When the response value matches the expected response value, the execution location selection control signal can be generated subsequently based on the hardware configuration status. When the response value is inconsistent with the expected response value, the execution position selection control signal is forcibly generated to indicate that there is no need to switch the execution position of subsequent instructions, and the one-time programmable memory unit is locked so that it is subsequently unreadable.

9. A processor startup process control system, characterized in that, The method includes a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores machine-executable instructions, which, when executed by a computer, implement the processor startup process control method of any one of claims 1-8.

Citation Information

Patent Citations

  • Starting method, device and system for central processing unit

    CN114003299A

  • Device and method for defending control flow attack, processor, equipment and storage medium

    CN114266082A