Flexible allocation of processors for safety-critical and non-critical applications

By creating isolated paths using redundant switch networks or programmable logic on the same chip, processors and resources are dynamically allocated, solving the problem of inflexible hardware design in existing technologies and achieving flexible resource allocation and cost-effectiveness in safety-critical systems.

CN122439149APending Publication Date: 2026-07-21ADVANCED MICRO DEVICES INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ADVANCED MICRO DEVICES INC
Filing Date
2024-06-11
Publication Date
2026-07-21

Smart Images

  • Figure CN122439149A_ABST
    Figure CN122439149A_ABST
Patent Text Reader

Abstract

Apparatuses and methods for partitioning components of a safety-critical system are provided. A processing apparatus includes a resource including a memory, a host processor, and a plurality of processors connected to the resource via a shared lane of a network and configured to execute an application based on instructions from the host processor. Each processor of the plurality of processors is assigned to one criticality domain level of a plurality of criticality domain levels, and an isolated lane is created between the plurality of processors and the plurality of resources via the shared lane based on which of the processors is assigned to one or more criticality domain levels of the plurality of criticality domain levels to access one or more resources of the plurality of resources. The application is executed using the network. For example, the isolated lane is created by disabling one or more switches. Alternatively, the isolated lane is created via programmable logic.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications This application claims priority to pending U.S. nonprovisional patent application No. 18 / 543,627, filed December 18, 2023, entitled “Flexible Allocation of Processors for Safety-Critical and Non-Critical Applications,” the entire contents of which are incorporated herein by reference. Background Technology

[0002] Safety-critical systems, typically comprising multiple processors, are used in various industries, such as the automotive, medical, and railroad sectors. In the automotive industry, current vehicle processing systems are complex and include many different components (e.g., processors) for managing or controlling various functions within the vehicle, such as audio, video, climate control, engine management, etc. Attached Figure Description

[0003] A more detailed understanding can be obtained from the following description, which is given by way of example in conjunction with the accompanying drawings: Figure 1 It is a block diagram of an exemplary computing device that can implement one or more features of this disclosure; Figure 2 Based on the block diagram of the example device, additional details involving the performance of processing tasks on the auxiliary processing device are illustrated. Figure 3 It is a block diagram of an exemplary computing device that can implement one or more features of this disclosure; Figure 4 This is a block diagram illustrating an example audio component in a motor vehicle; Figure 5A This is a diagram illustrating the network configuration of a shared switch network; Figure 5B This is a diagram illustrating a redundant switch network in which the features of this disclosure can be implemented; Figure 6 This is an example of additional details. Figure 5B The example diagram shown in the figure; Figure 7 This is a diagram illustrating another example of a redundant switch network in which the features of this disclosure can be implemented; Figure 8 This is a flowchart illustrating an example method for allocating critical and non-critical components of a motor vehicle processing system according to the features of this disclosure; and Figure 9 It is a table that shows a list of components according to the example, which includes their shareability with key and non-key domains and their assignability to key and non-key domains. Detailed Implementation

[0004] Examples of different types of audio functions in motor vehicles include multimedia playback, active noise cancellation (eliminating sounds such as wind and tire noise while allowing the driver to hear sounds such as horns and car horns), voice user interface (allowing users to interact with the system via voice commands), hands-free calling, and sound generation.

[0005] Some audio features, such as hands-free calling and sound generation, have safety-critical requirements. For example, safety-critical requirements for hands-free calling include the ability to make automated emergency calls (e.g., in the event of an accident), driver alerts for electric vehicles, and external pedestrian alerts. Additionally, safety-critical requirements for sound generation include driver alerts (e.g., sounds that alert the driver to various situations such as objects, people, other vehicles, attention, and lane changes) and external pedestrian alerts (e.g., for electric vehicles that produce less noise than internal combustion engine vehicles).

[0006] Compared to non-critical processors in safety-critical systems (e.g., safety-critical systems for motor vehicles), critical processors benefit from having dedicated critical resources (e.g., memory, memory interfaces, and input / output (I / O) devices) separate from non-critical resources to ensure quality of service in the event of a failure in one part of the system (e.g., during an emergency). That is, for safety-critical systems and applications, it is important to separate (e.g., isolate) the subsystems used to perform safety-critical applications from other subsystems to ensure Freedom of Interference (FFI) (i.e., "no cascading failure between two or more components that could lead to a breach of safety requirements"). However, for system designers and application developers, it is challenging to anticipate how to partition effective hardware resources for safety-critical workloads versus non-critical workloads. Furthermore, as safety workload requirements evolve, fixed partitioning of hardware cannot flexibly meet these evolving requirements.

[0007] The FFI principle can be achieved by physically separating critical and non-critical resources onto separate chips. However, placing critical and non-critical resources onto separate chips is not cost-effective.

[0008] Some conventional technologies place critical and non-critical components on the same chip, but physically separate them, and use a single shared network switch for communication between critical and non-critical processors (e.g., digital signal processors (DSPs)) and critical and non-critical resources (e.g., memory, memory interfaces, I / O devices, or other resources). In other words, while placing critical and non-critical components on the same chip reduces costs, conventional architectures are not flexible (e.g., not hardware-flexible), especially when the mapping of hardware requirements does not tightly match the application workload requirements. For example, if additional critical functions are added in the future, and additional DSPs are needed to perform these additional critical functions, conventional architectures are limited to a fixed number of critical components on the device.

[0009] Features of this disclosure include devices and methods for assigning (e.g., allocating) dedicated critical resources (e.g., memory, memory interfaces, and I / O devices) on the same chip along with non-critical resources while maintaining the quality of service of critical resources and providing application developers with flexibility in managing workloads and performance (e.g., allowing application developers to reallocate DSPs from non-critical domains of processing devices (e.g., audio coprocessors (ACP)) to critical domains).

[0010] Features of this disclosure include assigning processors (e.g., digital signal processors (DSPs)) of processing devices (e.g., ACPs) to critical domain levels of a safety-critical system. For example, a safety-critical system may include two critical domain levels (e.g., critical and non-critical domains), and the processor is assigned as a critical processor or a non-critical processor. Features of this disclosure can be implemented for safety-critical systems having any number of critical domain levels (e.g., three or more levels, each defining different levels of criticality from the most critical to the least critical), and the processor is assigned to different critical domain levels. However, for simplicity, this document uses two critical domain levels to describe an example.

[0011] When using two critical domain levels, resources are assigned as critical and non-critical resources. Processors assigned as critical processors are allowed to access critical resources but not non-critical resources, and processors assigned as non-critical processors are allowed to access non-critical resources but not critical resources, except for limited shared memory resources.

[0012] Processing devices (e.g., ACP) include interconnect networks that include connection paths (e.g., separate, non-shared paths) between each of multiple processors and multiple resources (e.g., memory, memory interfaces, storage devices, I / O devices, or other resources) throughout a shared connection path.

[0013] Based on which processor among multiple processors is assigned to one or more critical domain levels among multiple critical domain levels to access one or more resources among multiple resources, isolated paths are created between multiple processors and multiple resources via shared paths. Isolated paths are dynamically created at startup or runtime, such that one or more individual paths in the interconnect network are isolated from one or more other individual paths in the interconnect network.

[0014] In one example, the interconnection network is a redundant switch network comprising multiple redundant switches, and one or more redundant switches in the network are disabled by disabling one or more redundant switches in the network by determining which of the assigned critical processors (or which of the processors assigned to one or more critical domain levels, such as one or more levels at or above a critical domain threshold) is accessing one or more resources.

[0015] Alternatively, at startup or runtime, isolated paths to the interconnect network are created (i.e., configured) via programmable logic to suit a particular application. Programmable logic may include one or more programmable logic devices (PLDs) configured to perform logical functions. Examples of such programmable logic include simple programmable logic devices (SPLDs) (e.g., programmable array logic (PAL), programmable logic array (PLA), or other types of array logic), complex programmable logic devices (CPLDs), and field-programmable gate arrays (FPGAs). Programmable logic can be programmed, for example, using a processor (e.g., a DSP, a host processor), a programmable logic controller (PLC), or another processing device.

[0016] A portion (component) of programmable logic can be used for safety-critical configurations, while another portion (other components) of programmable logic can be designated for non-critical configurations. The reconfigured logic can be designed to include only network connectivity or a complete subsystem comprising multiple sub-components such as memory, memory controller, one or more processors (e.g., digital signal processors (DSPs)), and input / output (I / O) channels, which together constitute a complete audio processing system for critical or non-critical audio.

[0017] The configuration of the interconnected network can be unlocked until the system undergoes a complete configuration sequence at startup. Alternatively, a separate "root of trust" in a critical domain can manage configuration resources through a secure, dedicated interface with exclusive write access, allowing the system to be reconfigured via a soft reboot or through software-managed dynamic reconfiguration.

[0018] For fixed-domain processors (e.g., DSPs that are essentially in a critical or non-critical domain), portions of the interconnect network can be individually merged into a single interconnect network that connects to components within the same fixed domain.

[0019] A processing device is provided for allocating components of a safety-critical system. The processing device includes multiple resources, including memory and a host processor. The multiple processors are connected to the multiple resources via a shared path of a network and are configured to execute applications based on instructions from the host processor. Isolation paths are created between the multiple processors and the multiple resources via the shared path, based on which processor is assigned to one or more critical domain levels to access one or more of the multiple resources.

[0020] A method for allocating components of a safety-critical system includes: assigning each of a plurality of processors to a critical domain level of a plurality of critical domain levels by a host processor, the plurality of processors executing an application based on instructions from the host processor; creating an isolated path between the plurality of processors and the plurality of resources via a shared path of a network connecting the plurality of processors to the plurality of resources, based on which of the plurality of processors is assigned to one or more critical domain levels of the plurality of critical domain levels to access one or more of the plurality of resources; and having the plurality of processors use the network to execute the application.

[0021] A non-transitory computer-readable medium includes instructions for causing a computer to perform a method for allocating components of a safety-critical system, the instructions including: assigning each of a plurality of processors to a critical domain level of a plurality of critical domain levels by a host processor, the plurality of processors executing an application based on instructions from the host processor; creating an isolated path between the plurality of processors and the plurality of resources based on which of the plurality of processors is assigned to one or more critical domain levels of the plurality of critical domain levels to access one or more of the plurality of resources; and having the plurality of processors use the network to execute the application.

[0022] Figure 1This is a block diagram of an exemplary computing device 100 that can implement one or more features of this disclosure. In various examples, computing device 100 is, but is not limited to, a computing device, computer, gaming device, handheld device, set-top box, television, mobile phone, tablet computer, or other computing device, such as a safety-critical system (e.g., a safety-critical system for a motor vehicle). For example, as described in the examples provided herein, computing device 100 may be a computing device in a motor vehicle and may include a coprocessor (e.g., an audio coprocessor (ACP)) or other processing device including multiple processors (e.g., a DSP), each processor being configured to perform a function (e.g., an audio function) (e.g., a safety-critical system for a motor vehicle having two or more critical domain levels).

[0023] Device 100 includes, but is not limited to, one or more processors 102, memory 104, one or more auxiliary devices 106, and storage device 108. It may be a bus, a combination of buses, and / or an interconnection network 112 of any other communication components that communicatively links the processor 102, memory 104, auxiliary devices 106, and storage device 108.

[0024] In some of the examples described herein, interconnect network 112 is configured only to efficiently route data and control signals between fixed resources (e.g., memory and storage devices) of a subsystem and the processor. For example, as described herein, isolated paths to the interconnect network are created by the host processor (e.g., CPU) (e.g., dynamically at startup or runtime) by disabling one or more redundant switches in the redundant switches of the interconnect network based on resource and processor criticality levels.

[0025] In other examples described herein, interconnect network 112 includes programmable logic, such as, for example, an SPLD, CPLD, or FPGA. For example, as described herein, isolated paths to the interconnect network are created (e.g., dynamically at startup time or runtime) by configuring or reconfiguring the programmable logic of the interconnect network based on resource and processor criticality levels and / or to suit a particular application.

[0026] In various alternatives, processor 102 includes a central processing unit (CPU), a graphics processing unit (GPU), a CPU and GPU located on the same chip, or one or more processor cores, wherein each processor core may be a CPU, GPU, or neural processor. In various alternatives, at least a portion of memory 104 is located on the same chip as one or more of processors 102, such as on the same chip or in an interpolator arrangement, and / or at least a portion of memory 104 is located separately from processor 102. Memory 104 includes volatile or non-volatile memory, such as random access memory (RAM), dynamic RAM, or cache.

[0027] Storage device 108 includes fixed or removable storage devices, such as, but not limited to, hard disk drives, solid-state drives, optical disk drives, or flash drives. Auxiliary device 106 is, for example, a coprocessor (e.g., ACP, such as...). Figure 3 The auxiliary processor 114 includes, but is not limited to, one or more auxiliary processors 114 (e.g., DSPs) and / or one or more input / output (“IO”) devices. The auxiliary processor 114 includes, but is not limited to, processing units capable of executing instructions, such as central processing units, DSPs, graphics processing units, parallel processing units capable of performing computational shader operations in single-instruction multiple-data format, multimedia accelerators such as video encoding or decoding accelerators, or any other processor. Any auxiliary processor 114 can be implemented as a programmable processor that executes instructions, a fixed-function processor that processes data according to fixed hardware circuitry, a combination thereof, or any other type of processor. In some examples, the auxiliary processor 114 includes an accelerated processing device (“APD”). Additionally, while processor 102 and auxiliary processor 114 are... Figure 1 The processor 102 and the auxiliary processor 114 are shown separately, but in some examples, the processor 102 and the auxiliary processor 114 may be on the same chip.

[0028] As described in more detail herein, each auxiliary processor 114 is, for example, a digital signal processor (DSP) configured to perform functions (e.g., audio functions) in a safety-critical system of a motor vehicle. For example, each auxiliary processor 114 is an ACP (such as...) Figure 3 The DSPs in the ACP 300 shown herein include local instruction fetch memory (e.g., IRAM 140) and local data RAM (DRAM 142), including cache memory (e.g., L1 cache). Each DSP is configured to transfer data (e.g., via a DMA controller).

[0029] One or more I / O devices 118 include one or more input devices, such as a keyboard, keypad, touchscreen, touchpad, detector, microphone, accelerometer, gyroscope, biometric scanner, or network connection (e.g., a wireless LAN card for transmitting and / or receiving wireless IEEE 802 signals), and / or one or more output devices, such as a display, speaker, digital serial audio interface (e.g., an I2S interface or a time division multiplexing (TDM) interface), printer, haptic feedback device, one or more lights, antenna, or network connection (e.g., a wireless LAN card for transmitting and / or receiving wireless IEEE 802 signals).

[0030] Figure 2 This is a block diagram of the device, illustrating additional details related to performing processing tasks on auxiliary device 106 according to one example. Processor 102 maintains one or more control logic modules in system memory 104 for execution by processor 102. The control logic modules include operating system 120, driver 122, and application program 126, and may optionally include other modules not shown. These control logic modules control various aspects of the operation of processor 102 and auxiliary device 106. For example, operating system 120 communicates directly with the hardware and provides an interface to the hardware for other software executing on processor 102. Driver 122 controls the operation of auxiliary device 106 by providing, for example, an application programming interface (“API”) to software executing on processor 102 (e.g., application 126) to access various functionalities of auxiliary device 106.

[0031] Auxiliary device 106 is, for example, a coprocessor (e.g., ACP) that executes commands received from the host processor (e.g., processor 102) and programs for selected functions via command processor 136, such as operations for performing critical and non-critical functions in a safety-critical system (e.g., a safety-critical system for a motor vehicle). For example, each auxiliary processor 114 is a DSP in the ACP, configured to perform audio functions of the motor vehicle in a safety-critical or non-critical domain. Each auxiliary processor 114 (e.g., DSP) includes local DRAM 142 and accesses resources 115 including shared memory 117.

[0032] Figure 3 This is a block diagram of an example ACP 300 that can implement one or more features of this disclosure. The ACP 300 is merely an auxiliary processing device (e.g., Figure 1 and Figure 2 An example of auxiliary device 106 shown is illustrated. The features of this disclosure can be implemented with any type of auxiliary processing device in a computing device for a safety-critical system (e.g., a safety-critical system for a motor vehicle). Figure 3In the configuration shown, critical and non-critical domains are merged into ACP 300. As shown, ACP 300 includes interconnection network 320.

[0033] In some examples described herein, interconnect network 320 is a combined network of critical and non-critical redundant switches configured to efficiently route data and control signals between fixed resources (e.g., memory and storage devices) and processors in a subsystem using multiple redundant switches. For example, as described below... Figure 6 and Figure 7 In more detail, processors (e.g., DSP 302) are assigned critical and non-critical processors, and isolation paths are created by the host processor (e.g., CPU) by selecting redundant switches to be disabled (isolated) based on which critical DSP is determined to target an identified resource (e.g., an identified portion of memory).

[0034] Alternatively, the interconnect network 320 includes programmable logic. Examples of programmable logic may include an SPLD, CPLD, or FPGA. For example, isolated paths to the interconnect network 320 can be created (e.g., dynamically at startup or runtime) by configuring or reconfiguring the programmable logic of the interconnect network based on resource and processor criticality levels and / or to suit a particular application. The programmable logic can be programmed, for example, using any of a DSP 302, a host processor (e.g., CPU 102), a programmable logic controller (PLC 322), or another processing device.

[0035] ACP 300 is, for example, part of an Accelerated Processing Unit (APU) located on the same chip. ACP 300 is connected to the APU (e.g., via a system bus (e.g., interconnect 112, but...). Figure 3 (Not shown in the image) Other processors and memories connected to the APU. The ACP 300 integrates the DSP with associated routing and bridging, direct memory access (DMA), interrupt support infrastructure, and I / O interfaces.

[0036] The ACP 300 includes multiple DSPs 302, each with local DRAM 142. Figure 3 The total number of DSPs shown in the figure Figure 3 The number of DSPs shown in each field is merely an example. The features of this disclosure can be implemented for ACPs with any total number of DSPs and any number of DSPs in each field.

[0037] Each of resource 304, shared memory 117, shared external device 306, and external device 308 can be accessed by DSP 302 (before the redundant switch is disabled) to perform the vehicle's audio functions. Figure 3 The quantity and type of resources shown are merely examples. The features of this disclosure can be implemented using any quantity and type of resources used to perform audio functions of a motor vehicle.

[0038] Data processed by each DSP 302 from memory (e.g., system memory 102, shared memory 117) enters and leaves the block via a system interface (not shown). A direct memory access controller (DMAC) 310 utilizes a 128-bit interface and multiple concurrent accesses to stream data and code memory from system memory 108. Access to system memory 108 undergoes address translation specified by a mapping table located in shared memory 117.

[0039] Figure 4 This is a block diagram illustrating an example audio component in a motor vehicle.

[0040] A car's speakers are used to generate sounds for critical functions, such as driver alarms, and sounds for non-critical functions, such as stereo music. However, a car has a fixed array of speakers. Therefore, even while generating sounds for non-critical functions, it is crucial that sounds for critical functions are generated at one or more speakers (and heard by the driver).

[0041] like Figure 4 As illustrated in the example, audio signals from different non-critical domain sources (e.g., streaming audio, Bluetooth audio, radio, multi-channel audio) 402 are selected via source selector 416, upmixed by upmixer 404, and mixed by audio mixer 406. Audio signals from different safety-critical domain sources (e.g., siren / warning unit 410 for generating an internal alarm to the driver or an external alarm to pedestrians, acoustic vehicle alarm system (AVAS) unit 412 for generating an engine sound alarm to pedestrians in an electric vehicle, and emergency call (eCall) unit 414 for generating an emergency call, such as in the event of a collision) are also provided to audio mixer 406, which mixes and provides the audio signals from the different non-critical domain sources 402 and safety-critical sources for processing (e.g., equalization (EQ), compression such as using dynamic range compression (DRC), gain processing, delay, etc.) and provides them to speaker 408, which generates sound from the processed signals. Figure 4 The data generated by each component in the ACP 300 is mapped to the corresponding different DSP 302.

[0042] Audio signals from different non-critical domain sources 402 and safety-critical domain sources 410, 412, 414 are generated at speaker 408, such that sounds from critical domain sources 410, 412, 414 (e.g., driver alarm sounding) will still be generated (and heard by the driver), while sounds from non-critical domain source 402 (e.g., music from the radio) are also being generated at speaker 408.

[0043] Audio mixer 406, audible alarm source (e.g., hardware such as a processor and memory for generating the alarm) 410, AVAS source (hardware for generating engine sound alarms) 412, and eCall source (e.g., hardware for generating emergency telephone calls) 414 are all safety-critical components used to perform safety-critical applications. Therefore, to ensure FFI and maintain quality of service in the event of a failure in one part of the system, these critical components and their resources are separated from non-critical components and resources. However, as mentioned above, placing critical and non-critical resources on separate chips is neither cost-effective nor flexible. Furthermore, mailbox interface 312 and cross-domain time-division multiplexing (TDM) interface 313 (in... Figure 3 (In the example shown) it is used to send data and information between non-critical domains and safety-critical domains. However, if a component in a non-critical domain is disabled (e.g., due to a crash), the data and information sent via these components will not affect the operability of the components in the safety-critical domain.

[0044] Therefore, the features of this disclosure provide dedicated critical resources (e.g., memory and I / O devices) on the same chip as non-critical resources, while maintaining the quality of service for critical resources and providing application developers with the flexibility to manage workloads and performance.

[0045] As described above, in some examples, the interconnection network of processing devices (e.g., subsystems of safety-critical systems in motor vehicles) is a redundant switch network configured to efficiently route data and control signals between the subsystem's fixed resources (e.g., memory and storage devices) and the processor using multiple redundant switches.

[0046] Figure 5A and Figure 5B This is a diagram illustrating the difference between the configuration of a redundant switch network 504 with shared network switches (i.e., without redundant switches) and the configuration of a switch network 514 using redundant switches (i.e., a redundant switch network), wherein the features of this disclosure can be implemented. Figure 5A This is a diagram illustrating the network configuration of a shared switch network. Figure 5B This is a diagram illustrating a redundant switch network 514 in which the features of this disclosure can be implemented. The redundant switch network 514 is... Figure 3The example shown is a combination of critical and non-critical redundant switch networks 320.

[0047] To simplify the explanation, Figure 5A The number of DSPs 512, the number of redundant network switches 516, and the single resource 518 (e.g., memory, memory interface, I / O device) shown are merely examples. The features of this disclosure can be implemented using any number of DSPs, any number of redundant network switches, and any number of resources.

[0048] Figure 5A and Figure 5B The DSPs 502 and 512 shown are merely examples of one type of processor. The features of this disclosure can be implemented with any type of processor configured to initiate transactions over a network (e.g., requests to access memory) and receive data from resources (e.g., received requested data from memory).

[0049] Figure 5A The shared network switch 506 and Figure 5B The redundant network switch 516 in the diagram can be any type of network logical switch (e.g., a multiplexer).

[0050] exist Figure 5A In the configuration shown, if a transaction from a DSP in a non-critical domain (e.g., one of DSPs 502) to a shared resource 508 (e.g., a shared portion of memory) fails to complete due to one or more components in the non-critical domain being disabled or inoperable, the incomplete transaction may negatively impact transactions from critical domain DSPs (e.g., non-critical DSP 502). For example, as... Figure 5A As shown, the first one in DSP 502 shares the same network switch 506. Using Figure 5A In the shared network configuration shown, if a transaction initiated by a non-critical DSP 2 or a non-critical DSP 3 cannot be completed (e.g., the requested data is not returned to DSP 2 or a non-critical DSP 3 due to power loss or program failure to the shared network switch 506), the transaction of the critical DSP 1 via the shared network switch 506 will also be negatively affected.

[0051] In other words, because critical and non-critical DSPs and resources are not separated (i.e., each of DSPs 502 shares the same path between the shared network switch 506 and the shared memory 508), transactions from non-critical DSP 1 to shared memory 508 may remain incomplete on the shared memory arbitrator due to, for example, a program fault or power loss. Therefore, if critical DSP 1 later accesses the same shared memory 508, the arbitrator or interconnect network may block the critical DSP 1's transaction due to the incomplete previous transaction, and critical DSP 1 will therefore be unable to proceed.

[0052] Therefore, critical and non-critical components should be separated from each other. However, as mentioned above, placing critical and non-critical resources on separate chips is not cost-effective. Furthermore, physically separating critical and non-critical resources makes the hardware inflexible, especially when the mapping of hardware requirements does not closely match the application workload requirements.

[0053] Figure 5B This is a diagram illustrating a technique for creating isolated paths using redundant network switch 516 according to the features of this disclosure. Although the redundant switch 516 in network 514 uses additional routing and area (e.g., additional silicon), the additional area is relatively small (e.g., the additional area in the network is less than 1% of the ACP area). Additionally, as per [reference to...] Figure 6 In more detail, by disabling (e.g., isolating) selected redundant network switches (e.g., switch 516), critical and non-critical components can be placed on the same chip while ensuring the quality of service for critical resources and providing application developers with greater flexibility to manage workloads and performance.

[0054] Figure 6 This is an example of additional details. Figure 5B The example diagram shown is in [the image]. Figure 5B and Figure 6 In the example shown, DSP1 and DSP2 are assigned as critical DSPs, and DSP3 is assigned as a non-critical DSP.

[0055] During the cold start time (i.e., before the audio application begins execution), one or more DSPs 512 are assigned as critical processors by the host processor (e.g., processor 102, such as CPU), one or more DSPs 512 are assigned as non-critical processors by the host processor, and one or more of the redundant network switches 516 are selected by the host processor to be disabled (separated) based on which critical DSP is determined to be targeting an identified resource (e.g., an identified portion of memory).

[0056] (For example, by the application developer) it is determined which DSP will be assigned as a critical DSP and which DSP will be assigned as a non-critical DSP to suit a particular application or use case. It is also (for example, by the application developer) determined which resource (for example, a portion of memory) will be assigned as a target critical portion of memory (accessible by the assigned critical DSP) to suit a particular application or use case.

[0057] For example, refer to Figure 6 During cold start, DSP 1 and DSP 2 (e.g., application-specific) are assigned as critical processors, and DSP 3 (e.g., application-specific) is assigned as a non-critical processor. Additionally, resource 518 (e.g., a portion of memory identified) (e.g., application-specific) is assigned as a target critical portion of memory accessible by critical DSP 1 and critical DSP 2. That is, critical DSP 1 and critical DSP 2 can access the target portion of memory 518, while DSP 3 cannot access the target portion of memory 518.

[0058] The host processor selects and disables redundant network switches 516(1), 516(2), and 516(3) based on resource 518, which is designated as a target for critical DSP 1 and critical DSP 2. That is, by disabling switches 516(1), 516(2), and 516(3), isolated paths are dynamically created between DSP 1 and resource 518, and between DSP 2 and resource 518. This prevents (isolates) requests to access data from critical memory portion 518 from being sent along path portion 604.

[0059] However, the remaining redundant network switches (i.e., switches other than 516(1), 516(2), and 516(3)) are not disabled. Therefore, requests to access data from the critical memory section 518 are not blocked (allowed) along path sections 602(1)-602(4). Because the path between each DSP 512 and the critical memory section 518 is separated and the selected redundant network switches are disabled, critical DSP 1 can access the critical memory section 518 along path sections 602(1)-602(3), and critical DSP 2 can access the critical memory section 518 along path sections 602(4) and 602(3). That is, individual paths (including path sections 602(1)-602(3)) and individual paths (including path sections 602(4) and 602(3)) become isolated from other paths. Therefore, critical components (e.g., critical DSP 1, critical DSP 2, and critical memory section 518) and non-critical components (e.g., non-critical DSP 1 and non-critical memory section 518) Figure 6(Not shown in the diagram) can be placed on the same chip while ensuring quality of service. Furthermore, it provides application developers with greater flexibility in managing workloads and performance. For example, if additional critical functions are added in the future and require additional DSPs to perform these functions, the features of this disclosure allow application developers the additional flexibility to reassign the DSP from non-critical domains of the ACP 300 to critical domains.

[0060] In relation to Figure 6 In the described example, the DSP is assigned as a critical or non-critical processor, and redundant network switches are locked during cold start via a hardware lock-in mechanism (e.g., Figure 3 The locking mechanism 318 in the hardware is selected and disabled, and this hardware locking mechanism cannot be changed by software.

[0061] Figure 7 This is a diagram illustrating another example of a redundant switch network 714 in which features of this disclosure can be implemented. The redundant switch network 714 is... Figure 3 Another example of a combination of critical and non-critical redundant switch networks 320 is shown.

[0062] exist Figure 7 In the example shown, DSP1 and DSP2 are assigned as non-critical DSPs, and DSP3 is assigned as a critical DSP.

[0063] During the cold start time (i.e., before the audio application begins execution), DSP 1 and DSP 2 are designated as non-critical processors, and DSP 3 is designated as a critical processor. Additionally, resource 518 (e.g., a portion of memory identification) is assigned as a target critical portion of memory accessible by the critical DSP 3. That is, the critical DSP 3 is determined to be able to access the target portion of memory 518, while DSP 1 and DSP 2 are determined to be unable to access the target portion of memory 518.

[0064] Based on resource 518, which is designated as a critical resource to be targeted by critical DSP 3, redundant network switches 716(1)-716(4) are selected and disabled. This prevents (isolating) requests to access data from critical memory section 518 from being sent along path section 704.

[0065] However, the remaining redundant network switches (i.e., switches other than 716(1)-716(4)) are not disabled. Therefore, requests to access data from the critical memory section 518 are not blocked (i.e., allowed) along path sections 702(1)-702(3). Because the path between each DSP 512 and the critical memory section 518 is separated and the selected redundant network switches 716(1)-716(4) are disabled, the critical DSP 3 can access the critical memory section 518 along path sections 702(1)-702(3). Therefore, critical components (e.g., critical DSP 3 and critical memory section 518) and non-critical components (e.g., non-critical DSP 1, non-critical DSP 2 and non-critical memory section 518) are not blocked (i.e., allowed). Figure 6 (Not shown in the image) can be placed on the same chip while ensuring quality of service. Furthermore, by assigning processors (e.g., DSPs) as critical or non-critical based on which critical processor is identified as targeting the identified critical resource, and by disabling selected redundant network switches, application developers gain greater flexibility in managing workloads and performance.

[0066] Alternatively, instead of using redundant switches in the interconnection network (such as...) Figure 6 and Figure 7 As shown, the interconnect network includes programmable logic, such as, for example, SPLD, CPLD, or FPGA. In this example, isolated paths to the interconnect network are dynamically created by configuring (or reconfiguring) the programmable logic of the interconnect network at startup or runtime based on resource and processor criticality levels and / or to suit specific applications. A portion (component) of the programmable logic can be used for safety-critical configurations, while another portion (other components) of the programmable logic can be designated for non-critical configurations.

[0067] Figure 8 This is a flowchart illustrating an example method 800 for allocating critical and non-critical components of a motor vehicle according to the features of this disclosure. Each of the tasks and functions described below with respect to method 500 is performed, for example, on an auxiliary device (e.g., auxiliary device 106, ACP 300).

[0068] As shown in box 802, method 800 includes assigning a processor (e.g., a digital signal processor (DSP)) of a processing device (e.g., an audio coprocessor (ACP)) to one of a plurality of critical domain levels. For example, as described above regarding Figure 6As described in the example, DSP1 and DSP2 are assigned as critical DSPs by the host processor (e.g., processor 102, such as a CPU), and DSP3 is assigned as a non-critical DSP by the host processor. Additionally, resource 518 (e.g., a portion of memory identified) is assigned by the host processor as a target critical portion of memory accessible by critical DSP1 and critical DSP2 to suit a specific application to be executed. (E.g., by the application developer) It is determined which DSP will be assigned as a critical DSP and which will be assigned as a non-critical DSP to suit a specific application or use case. It is also (e.g., by the application developer) determined which resource (e.g., a portion of memory) will be assigned as a target critical portion of memory (accessible by the assigned critical DSP) to suit a specific application or use case.

[0069] For example, when using two critical domain levels (critical domain level and non-critical domain level), each processor is assigned as either a critical processor or a non-critical processor, and resources are assigned as critical resources and non-critical resources. Processors assigned as critical processors are allowed to access critical resources but not non-critical resources, and processors assigned as non-critical processors are allowed to access non-critical resources but not critical resources (except for limited shared memory resources).

[0070] When more than two criticality domain levels are used (e.g., each level defines different criticality levels from the most critical to the least critical), processors and resources are assigned to different criticality domain levels (e.g., each processor and each resource is assigned to one of the criticality domain levels).

[0071] As shown in box 804, method 800 includes creating isolated paths for interconnecting networks based on assigned criticality. For example, at box 804, isolated paths for interconnecting networks are created by having a host processor select one or more redundant switches (e.g., switch 516) from a plurality of redundant switches in a network (e.g., network 514) to be disabled (isolated), and by having the host processor disable the selected one or more switches.

[0072] When using two critical domain levels (critical domain level and non-critical domain level), one or more redundant switches in a redundant switch are selected and disabled based on which processor in the processor is assigned as the critical processor and therefore determined to target identified critical resources (e.g., identified critical portions of memory). For example, refer to Figure 6When using two critical domain levels, redundant switches 516(1), 516(2), and 516(3) are selected to be disabled because DSP 1 and DSP 2 are designated as critical processors and therefore can access critical resource 518. However, DSP 3 is assigned as a non-critical processor and cannot access critical resource 518. Therefore, redundant switches 516(1), 516(2), and 516(3) are selected to be disabled, making In other words, disabling 516(1), 516(2) and 516(3) enables critical DSP 1 to access critical resource 518 via the path (i.e., via path portions 602(2) and 602(3)) and enables critical DSP 2 to access critical resource 518 via the path (i.e., via path portions 602(4) and 602(3)) while preventing DSP 3 from accessing critical resource 518.

[0073] Therefore, transactions from non-critical DSP 3 to critical resource 518 cannot be performed, and thus, incomplete transactions between non-critical DSP 3 and critical resource 518 will not occur (e.g., due to program failure or power loss), and any transactions from critical DSP 1 or critical DSP 2 will not be blocked due to such incomplete previous transactions.

[0074] When using more than two criticality domain levels (e.g., each level defines different criticality levels from the most critical to the least critical), one or more redundant switches among the redundant switches to be disabled are selected based on which processor (e.g., DSP) is assigned to one or more criticality domain levels. For example, one or more redundant switches among the redundant switches to be disabled are selected based on which processor (e.g., DSP) is assigned to one or more levels at or above a criticality domain threshold (e.g., high criticality and medium criticality levels are at or above the criticality domain threshold and have access to critical resources, while low criticality levels are below the criticality domain threshold and do not have access to critical resources).

[0075] The host processor (e.g., CPU) then disables one or more of the selected redundant network switches based on this selection. For example, when using two critical domain levels, redundant switches 516(1), 516(2), and 516(3) are disabled (e.g., isolated). The isolation paths of the interconnect network are created, for example, via a set of redundant physical switches whose connectivity is configurable (e.g., at startup or runtime), thereby providing flexibility to assign each processor in the processor to mutually exclusive safety-critical or non-critical domains. The interconnect network includes redundant switches between processors and shared resources (e.g., shared on-chip memory and memory interfaces to external memory). The configuration of the interconnect network is managed in software at startup, such that one or more DSPs and their associated resources (e.g., memory, memory interfaces, accelerators) are assigned to safety-critical or non-critical domains, and unused connections are closed (e.g., isolated) via a hardware lockout mechanism 318 that cannot be changed by software.

[0076] Alternatively, as described above, isolated paths to the interconnect network can be dynamically created through programmable logic that configures (or reconfigures) the interconnect network at startup or runtime based on resource and processor criticality levels and / or to suit specific applications. A portion (component) of the programmable logic can be used for safety-critical configurations, while another portion (other components) can be designated for non-critical configurations. The reconfigured logic can be targeted to include network connectivity or entire subsystems (e.g., ACP).

[0077] As shown in box 806, method 800 includes multiple processors of an auxiliary processing device using a network to execute an application. For example, ACP 300 executes an audio application in a car via DSP 512. During the execution of the application, key DSP 1 and key DSP 2, identified as having access to target portions of memory 518, are used to perform key functions by accessing key portions of memory 518.

[0078] The connectivity of redundant physical switches, and optionally programmable logic, is dynamically configurable at startup or runtime. For example, at startup, the system can dynamically configure the switches (or alternatively, programmable logic) to suit a specific application based on detected hardware (e.g., processors and resources), settings (e.g., assigned criticality or other settings), and / or conditions. At runtime: After the startup process is complete, the system can dynamically configure the switches (or alternatively, programmable logic) based on changes that occur while the system is running (e.g., changes to assigned criticality). Because the connectivity (or alternatively, programmable logic) of redundant physical switches is dynamically configurable (e.g., at startup or runtime), it provides the flexibility to assign each processor in the processor set to mutually exclusive security-critical or non-critical domains.

[0079] The configuration of the interconnected network can be unlocked until the system undergoes a complete configuration sequence at startup. Alternatively, a separate "root of trust" in a critical domain can manage configuration resources through a secure, dedicated interface with exclusive write access, allowing the system to be reconfigured via a soft reboot or through software-managed dynamic reconfiguration.

[0080] For fixed-domain processors (e.g., DSPs that are essentially in a critical or non-critical domain), portions of the interconnect network can be individually merged into a single interconnect network that connects to components within the same fixed domain.

[0081] Non-critical domain components of the ACP are allowed to send and receive transactions with memory and processors (e.g., compute units or processor cores) and other non-critical components within the ACP via the system hub and shared memory network (SMN) interface. The functionality of non-critical domains is assumed to depend on the functionality of the processor, architecture, and / or system memory. Non-critical domain ACP components do not lose power in the event of power loss (e.g., system state S0 power), but their functionality may be affected by power supply component failure if power loss is sudden (e.g., not through normal system state transitions). After the initial cold start configuration and loading are complete, non-critical domain components are prevented from accessing critical domain components.

[0082] Critical domain components are isolated from the system hub and SMN interface, as well as from any other internal paths to the processor, architecture, and system memory, and from all non-critical domain ACP components. It is assumed that critical domain ACP components need to remain functional in the event of partial or complete failure or crash of the processor, architecture, and / or system memory. Critical domain components also continue to function in the event of S0 power loss. After enabling domain isolation following the initial cold-start configuration via the system hub and SMN interface, the only permissible internal communication path between critical and non-critical domains is through a shared SRAM bank assigned as a shared domain, and through specially designated ACP internal error management registers and interrupts. Register access paths are shared between critical and non-critical domains.

[0083] Shared-domain SRAM memory allows access from two domains, but is designed so that a failed or pending transaction on one domain does not interfere with transactions on the other. System firmware designers must be aware that domain failures can corrupt data in shared-domain SRAM memory. Code and data that affect DSP execution (e.g., stack, pointers, etc.) should not be placed in shared-domain SRAM memory. A limited number of SRAM memory units are typically assigned as shared domains. Typical intended use cases include sending audio data streams and messages between critical and non-critical domains.

[0084] During cold start, domain partitioning is disabled to allow chip-level and security processor (e.g., Platform Security Processor (PSP)) initialization for each component. Domain partitioning is enabled by a stateful, one-time register bit switch, which can be set by any DSP but is cleared by the security processor via its isolated sideband interface or by a cold reset. This bit is read-only for x86 domains. Domain assignments are configured before domain partitioning is enabled and are subsequently locked. In a typical use case, the ACP driver messages the ACP upon completion of its initialization and then enables domain partitioning.

[0085] Figure 9 This is a table showing a list of ACP components according to an example, including their shareability with critical and non-critical domains and their assignability to critical and non-critical domains. Figure 9 As shown in the example, some SRAM memory (i.e., domain-shared SRAM memory) are domain-shareable, while other SRAM memory (i.e., standard shared SRAM memory) and other components are not domain-shareable. Figure 9 The example also lists components that are domain-assignable (e.g., can be assigned to two domains) and components that are domain-unassignable (e.g., assigned to a critical domain but not a non-critical domain, or assigned to a non-critical domain but not a critical domain). Figure 9 The domain shareability and domain assignability of the components shown are merely examples. Features of this disclosure can also be used with… Figure 9 The domain shareability and domain assignability of the different components shown are implemented.

[0086] It should be understood that many variations are possible based on the disclosure herein. Although the features and elements described above are described in specific combinations, each feature or element may be used alone without other features and elements, or in various combinations with or without other features or elements.

[0087] The provided methods can be implemented in general-purpose computers, processors, or processor cores. Suitable processors, for example, include general-purpose processors, special-purpose processors, conventional processors, digital signal processors (DSPs), multiple microprocessors, one or more microprocessors associated with a DSP core, controllers, microcontrollers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), any other type of integrated circuit (IC), and / or state machines. Such processors can be manufactured by configuring the manufacturing process using the results of hardware description language (HDL) instructions and other intermediate data, including netlists (such instructions capable of being stored on a computer-readable medium). The results of such processing can be masks, which are then used in semiconductor manufacturing processes to manufacture processors that implement aspects of the implementation scheme.

[0088] The methods or flowcharts provided herein can be implemented in a computer program, software, or firmware incorporated in a non-transitory computer-readable storage medium for execution by a general-purpose computer or processor. Examples of non-transitory computer-readable storage media include read-only memory (ROM), random access memory (RAM), registers, cache memory, semiconductor memory devices, magnetic media (such as internal hard disks and removable disks), magneto-optical media and optical media (such as CD-ROM disks), and digital multifunction disks (DVDs).

[0089] ***

Claims

1. A processing device for distributing components of a safety-critical system, the processing device comprising: Multiple resources, including memory; Host processor; as well as Multiple processors, connected to the multiple resources via a shared path of a network, and configured to execute applications based on instructions from the host processor. Based on which of the plurality of processors is assigned to one or more critical domain levels to access one or more of the plurality of resources, an isolation path is created between the plurality of processors and the plurality of resources via the shared path.

2. The processing apparatus according to claim 1, wherein The network includes a separate path between each of the plurality of processors and the resource via multiple redundant switches, and The host processor is configured to create the isolated path by disabling one or more of the multiple redundant switches, thereby isolating one or more individual paths from one or more other individual paths.

3. The processing apparatus according to claim 2, wherein the host processor is configured to: At the application's startup or runtime, each of the plurality of processors is assigned to one of the critical domain levels; and At the application's startup or runtime, select one or more redundant switches to be disabled.

4. The processing apparatus of claim 1, wherein the processing apparatus is an audio coprocessor configured to perform audio applications for motor vehicles.

5. The processing apparatus of claim 1, wherein one or more of the processors are digital signal processors configured to perform audio functions in a motor vehicle.

6. The processing apparatus of claim 1, wherein the network includes a plurality of separate paths between each of the plurality of processors and the plurality of resources, and the isolated paths are created such that one or more of the separate paths are isolated from one or more other separate paths.

7. The processing apparatus of claim 1, wherein the network includes programmable logic; and The isolated pathways in the network are created by configuring or reconfiguring the programmable logic.

8. The processing apparatus of claim 7, wherein the isolation pathway is dynamically created at the application startup or runtime via the programmable logic based on which of the plurality of processors is assigned to the one or more critical domain levels.

9. The processing apparatus of claim 1, wherein each of the plurality of processors designated as critical processors and each of the plurality of processors designated as non-critical processors are on the same chip.

10. The processing apparatus of claim 1, wherein the safety-critical system is a system of a motor vehicle.

11. The processing apparatus according to claim 1, wherein, The multiple critical domain levels include non-critical domain levels and critical domain levels, and The host processor is configured as follows: Each of the plurality of processors is assigned as a critical processor or a non-critical processor, and The isolation pathway is created based on which of the processors is assigned as the critical processor.

12. The processing apparatus according to claim 1, wherein The multiple critical domain levels include three or more critical domain levels, and The host processor is configured to create the isolation path based on which processor is assigned to one or more levels at or above a criticality domain threshold.

13. A method for allocating components of a safety-critical system, the method comprising: The host processor assigns each of a plurality of processors to a critical domain level among a plurality of critical domain levels, the plurality of processors executing the application based on instructions from the host processor; Based on which of the plurality of processors is assigned to one or more of the plurality of critical domain levels to access one or more of the plurality of resources, an isolated path is created between the plurality of processors and the plurality of resources via a shared path of a network connecting the plurality of processors to the plurality of resources; as well as The application is executed by the plurality of processors using the network.

14. The method according to claim 13, further comprising: At the application's startup or runtime, each of the plurality of processors is assigned to the critical domain level; as well as The host processor creates the isolated path by selecting one or more redundant switches from a plurality of redundant switches in the network to be disabled at the application's startup or runtime.

15. The method of claim 14, further comprising creating the isolated path by disabling the one or more redundant switches, such that one or more individual paths of the network are isolated from one or more other individual paths of the network.

16. The method of claim 13, wherein the network includes programmable logic, and the method further includes creating the isolated path by reconfiguring the programmable logic.

17. The method of claim 16, further comprising creating the isolated path by dynamically configuring the programmable logic at the application's startup time or runtime.

18. The method according to claim 13, wherein, The multiple critical domain levels include non-critical domain levels and critical domain levels, and The method includes: Each of the plurality of processors is assigned as a critical processor or a non-critical processor, and The isolation pathway is created based on which of the processors is assigned as the critical processor.

19. The method of claim 13, wherein the plurality of key domain levels comprises three or more key domain levels, and The method includes creating the isolation pathway based on which processor among the processors is assigned to one or more levels at or above a criticality domain threshold.

20. A non-transitory computer-readable medium having instructions thereon for causing a computer to perform a method for allocating components of a safety-critical system, the instructions comprising: The host processor assigns each of a plurality of processors to a critical domain level among a plurality of critical domain levels, the plurality of processors executing the application based on instructions from the host processor; Based on which of the plurality of processors is assigned to one or more of the plurality of critical domain levels to access one or more of the plurality of resources, an isolated path is created between the plurality of processors and the plurality of resources via a shared path of a network connecting the plurality of processors to the plurality of resources; as well as The application is executed by the plurality of processors using the network.