A pure hardware hierarchical control system architecture
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-16
- Publication Date
- 2026-08-14
AI Technical Summary
1. 安全风险极高:软件管控架构存在大量不可避免的代码漏洞,容易被黑客利用植入病毒、后门,导致数据泄露、算力被劫持、系统被篡改、执行器失控等灾难性后果;现有硬件辅助方案多作为软件管控的补充,未能从根本上摆脱对软件的依赖,无法实现物理级别的安全防护
1. 极致的物理硬件安全:本发明通过纯硬件固化的组合逻辑电路实现,所有控制逻辑永久不可编程、电路永久固化,无任何可执行代码存储单元,系统全生命周期无任何可编程逻辑参与,从物理层面有效阻断了软件漏洞攻击路径、病毒感染、后门植入的问题,实现了全链路硬件级安全防护,规避了软件中心模式下的黑客攻击、数据泄露、系统劫持、执行器失控等核心安全风险。
Abstract
Description
Technical Field
[0001] This invention relates to the field of electronic system control technology, and in particular to a pure hardware hierarchical control system architecture, which is suitable for application scenarios with high safety, high reliability, and low power consumption requirements, such as six-axis industrial collaborative robots, full-size humanoid robots, intelligent vehicle drive-by-wire chassis, and large-scale intelligent computing centers. Background Technology
[0002] With the rapid development of electronic information technology, fields such as industrial automation, artificial intelligence, and intelligent equipment have placed extreme demands on the security, reliability, and low power consumption of electronic systems. Traditional electronic systems generally adopt a hybrid management architecture of "central processing unit + operating system + application software." Although performance has continuously improved over decades of development, the following fundamental technical defects remain insurmountable: 1. Extremely high security risks: Software control architecture has a large number of unavoidable code vulnerabilities, which can be easily exploited by hackers to implant viruses and backdoors, leading to catastrophic consequences such as data leakage, hijacking of computing power, system tampering, and malfunction of actuators; existing hardware-assisted solutions are mostly used as a supplement to software control, failing to fundamentally get rid of the dependence on software and unable to achieve physical-level security protection.
[0003] 2. High maintenance costs: Software systems inevitably have program defects, requiring frequent patch updates and version upgrades, making long-term unattended operation impossible; large-scale intelligent computing centers, industrial production lines, and other scenarios require a large number of professional maintenance personnel, resulting in high annual maintenance costs and huge investments in human resources and time.
[0004] 3. Serious energy waste: The operation of the software management architecture depends on the continuous online operation of the central processing unit, memory and operating system. Even in the idle state without tasks, a large number of circuits need to be powered. At the same time, the response delay of software scheduling makes it impossible for computing units and actuators to achieve real-time and accurate power control. The overall energy utilization efficiency of the entire industry is low, and there is serious energy waste throughout the year.
[0005] 4. Poor operational stability: The software system has inherent problems such as memory leaks, process deadlocks, and system crashes, resulting in a short mean time between failures (MTBF). After an anomaly occurs, manual intervention is required to restore normal operation, which seriously affects the continuity of business operations such as industrial production and large-scale model inference.
[0006] Although some solutions using hardware circuits for local control have emerged in the existing technology, they are all supplements to software management and have not fundamentally eliminated the dependence on software and programmable logic devices. Vulnerabilities of programmable logic still exist, and a complete self-closed-loop full life cycle management system has not been formed. It is impossible to achieve true pure hardware operation without software, nor can it solve the aforementioned core technical defects at the same time. Summary of the Invention
[0007] Purpose of the invention The purpose of this invention is to overcome the above-mentioned shortcomings of the prior art and provide a pure hardware hierarchical management and control system architecture. All control logic is implemented by non-programmable native hardware circuits. No software, firmware, or programmable logic code participates in the internal control throughout the entire system life cycle. It can achieve self-operation throughout the entire life cycle without manual intervention, effectively blocking software vulnerability attack paths at the physical level. At the same time, it achieves extreme energy saving, ultra-high reliability, and extremely low operation and maintenance costs, and is completely decoupled from the computing core and actuator. Technical solution
[0008] To achieve the above objectives, the present invention adopts the following technical solution: A pure hardware hierarchical control system architecture includes at least two levels of physically electrically isolated, independently powered pure hardware timing control units. Each higher-level timing control unit has unique and irreversible control authority over its lower-level counterparts. Each level of the pure hardware timing control unit is an independent hardware functional module with a built-in, permanently fixed linear execution timing state machine. The execution steps of this linear execution timing state machine are fixed once during manufacturing and cannot be skipped or have additional steps inserted during normal operation. It is used to independently complete the entire lifecycle control of the corresponding level, including power-on, self-test, operation, power-off, and anomaly handling, responding only to higher-level control commands. The system employs a hardware-based, irreversible, unidirectional control command transmission mechanism between its various levels of pure hardware timing control units. This mechanism allows only the upper level to transmit control commands to the lower level and the lower level to send back status data to the upper level. The hardware layer completely blocks the reverse control path from the lower level to the upper level. Throughout the system's entire lifecycle, there is no multi-master control arbitration mechanism, and only one highest-level pure hardware timing control unit exists at any given time. All control logic is implemented entirely by non-programmable native combinational logic gates and hardware timing state machines. Throughout the system's entire lifecycle, no executable program, firmware, or programmable logic code participates in the generation and execution of the internal control logic.
[0009] Furthermore, the pure hardware timing control unit adopts a three-level architecture arranged from bottom to top: chip level, module level, and system level. Each level is connected through a one-way isolation channel, and logically, the upper level has unique and irreversible control authority over the lower level.
[0010] Furthermore, irreversible unidirectional signal transmission at the physical layer is achieved between the upper and lower levels through unidirectional optocouplers, unidirectional bus transceivers, or physical layer unidirectional conduction circuits. Only the upper level is allowed to send control commands to the lower level, and the lower level is allowed to send status data back to the upper level.
[0011] Furthermore, each unit has an independent power domain, full hardware reset, and one-time permission lockout function, enabling closed-loop management throughout the entire lifecycle.
[0012] Furthermore, the system-level timing control unit has a built-in hardware atomic jump addressing circuit, which adopts single-clock-cycle hardware atomic jump addressing. If the addressing fails, a hardware fuzzy search is triggered as a fallback, with no software involvement throughout the process. Beneficial effects
[0013] Compared with the prior art, the present invention has the following significant and substantial beneficial effects: 1. Ultimate Physical Hardware Security: This invention is implemented through purely hardware-based combinational logic circuits. All control logic is permanently non-programmable and the circuits are permanently fixed. There are no executable code storage units, and no programmable logic participates in the entire system lifecycle. This effectively blocks software vulnerability attack paths, virus infection, and backdoor implantation at the physical level, achieving full-link hardware-level security protection and avoiding core security risks such as hacker attacks, data leaks, system hijacking, and actuator malfunctions in the software-centric model.
[0014] 2. Fully unattended self-operation: This invention automatically completes the entire process of power-on, self-test, operation, power-off, and anomaly handling through the permanent hardware-fixed full lifecycle timing logic. It does not require manual operation and maintenance such as daily patch updates and version upgrades. Only annual hardware inspection is required, which can achieve long-term unattended self-operation and solve the pain point of traditional software architecture requiring continuous manual supervision.
[0015] 3. Significant energy-saving effect: This invention uses multi-level hardware targeted power control and hierarchical hibernation technology to keep only the instruction monitoring circuit with the lowest power consumption running in the idle state, while all other functional circuits are completely powered off, which significantly reduces the standby power consumption of the system. The measured standby power consumption is reduced by more than 98% compared with the traditional software management architecture, which greatly improves the overall energy utilization efficiency.
[0016] 4. Extremely high operational stability: This invention adopts pure hardware self-closed-loop control logic, avoiding common defects of traditional software architecture, and significantly improving the system's mean time between failures (MTBF). Actual measured MTBF is more than two orders of magnitude higher than that of traditional software architecture, ensuring long-term continuous and stable operation of the system.
[0017] 5. Extremely fast operation response and anomaly recovery: All control processes are executed directly by hardware logic, without any software scheduling delay or operating system overhead. The system can wake up from deep standby and start executing tasks in microseconds. All anomalies in the entire system are automatically handled through hardware full reset without manual intervention. The anomaly recovery speed is several orders of magnitude faster than traditional software architecture.
[0018] 6. Universal compatibility across all scenarios: The pure hardware control logic of this invention is completely decoupled from the computing core and actuator. It connects to the computing chip and servo driver only through a standard hardware interface. No modification is required to any code of the computing core and actuator. It can directly interface with any native inference chip, general computing chip, and industrial actuator to achieve plug-and-play. It can be widely adapted to all electronic system fields with high security, high reliability, and low power consumption requirements, such as industrial robots, humanoid robots, smart cars, intelligent computing centers, edge computing, and aerospace.
[0019] 7. Extremely low hardware implementation cost: The pure hardware control circuit structure of this invention is simple, occupies a very small chip area, and can be directly embedded into existing computing chips and driver chips without the need for additional independent control chips. It has extremely high industrial applicability and cost advantages. Attached Figure Description
[0020] This embodiment has no accompanying drawings, which is hereby noted. Detailed Implementation
[0021] This specific embodiment fully discloses the feasible implementation scheme of the present invention, and all contents completely cover all the technical features of claims 1-10. Those skilled in the art can fully implement the present invention without creative effort by following the contents described in this specification, thus satisfying the full disclosure requirement stipulated in Article 26, Paragraph 3 of the Patent Law.
[0022] Core Main Implementation Example: Six-Axis Industrial Collaborative Robot Scenario This embodiment uses a six-axis industrial collaborative robot as the core application scenario, and is not intended to limit the scope of protection of this invention. This invention can be adapted to all electronic system scenarios that require high safety, high reliability, and low power consumption.
[0023] The pure hardware hierarchical control system architecture described in this embodiment constructs a pure hardware timing control architecture for a six-axis industrial collaborative robot with three levels of physical and electrical isolation and a unique and irreversible control authority from the logical superior to the subordinate. All control logic is implemented by non-programmable native combinational logic gates and hardware timing state machines. No executable programs, firmware, or programmable logic code participate in the internal control process throughout the entire system lifecycle. The robot's main controller is only used for task issuance and status monitoring and does not intervene in any joint execution or safety control internal control process. The failure of the main controller or program crash will not affect the normal operation of this system. After the robot completes a cold start, it can achieve fully unattended autonomous operation without any human intervention.
[0024] I. System Overall Architecture and Hardware Implementation of the Three-Level Timing Control Unit This system employs a three-tiered, bottom-up, pure hardware timing control unit structure: joint-level (chip-level), arm-body-level (module-level), and system-level, forming a complete self-closed-loop control system. Internally, the system uses a hardware-fixed, irreversible, unidirectional control command transmission mechanism. Throughout its lifecycle, there is no multi-master control arbitration mechanism; at any given time, only the system-level timing control unit—the highest-level control unit—exists. Each timing control unit is an independent physical hardware entity, electrically isolated, and independently completes the full lifecycle control logic for its corresponding level, including power-on, self-test, operation, power-off, and anomaly handling, without any executable code storage unit.
[0025] In this embodiment, all hardware circuits are implemented using dedicated integrated circuits, and all control logic is permanently fixed through hardware circuit wiring. There are no programmable logic units that can be modified, ensuring that the control logic cannot be tampered with or bypassed.
[0026] 1. Joint-level timing control unit (single joint full lifecycle control, corresponding to the chip-level of claim 2) This unit corresponds to the full lifecycle management of a robot's single-joint servo motor. Each of the robot's six joints is equipped with an independent joint-level timing control unit. Hardware-wise, it is packaged within the same bare die as the corresponding joint's servo drive chip. Electrically, it is completely independent of the motor drive core and encoder sampling core, forming a secure control isolation domain within the chip. This unit only has command forwarding, task execution, and pure motion control functions, and does not have any external input parsing or global addressing capabilities. Command forwarding simply transmits the commands issued by the superior to the drive core without any modification or parsing. Pure motion control only covers the timing control of motor start / stop and acceleration / deceleration, and does not include any form of data processing or path planning functions.
[0027] The core hardware circuit modules integrated in this unit are as follows, which fully implement all the technical requirements of the corresponding level: • Fixed-step linear execution timing state machine: The hardware circuit is permanently fixed and cannot be modified throughout the entire operation. During normal operation, steps cannot be skipped and no extra steps can be inserted. The timing process of a single joint throughout its entire life cycle is fixed. After the process is completed, it automatically returns to the standby state and executes in a loop. Any abnormality will trigger the reset and restart process of this level. • Independent power enable control and targeted power control circuit: It has an independent power control pin, which can control the power-on and power-off of the corresponding joint drive core individually; in the idle state, only the instruction listening circuit with the lowest power consumption is kept in standby mode, and all other functional circuits are completely powered off and the clock is turned off; the instruction listening circuit is composed only of an edge detection trigger and a hardware comparator, and only has the functions of instruction reception and wake-up trigger, without any data processing capabilities. • Hardware full reset circuit: All abnormalities affecting the normal operation of the joint (overcurrent, overvoltage, encoder failure) will trigger a hardware full reset at this level. The reset covers all functional circuits within the joint. After the reset, the fixed timing process will be automatically re-executed. There is no abnormal data or state retention that will affect the subsequent operation of the system. Except for hardware counter values used only for statistical purposes, and these counter values do not participate in any control logic of the system. • One-time hardware access lock circuit: Constructed with a one-time programmable fuse circuit, after the joint is powered on and initialized, the fuse is automatically triggered to blow, completing the one-time hardware access lock; after locking, no external signal or physical operation within the normal operating range can modify the control logic and configuration parameters of this unit. This lock state cannot be released or bypassed within the normal operating range of the system. • Hardware firewall for joint drive input: The filtering rules are permanently fixed through hardware circuitry and connected in series with the data path of the motor drive core. Only compliant pulse signals that meet the preset format and range are allowed to pass through, filtering all illegal input data and physically blocking the risk of motor runaway caused by abnormal commands.
[0028] 2. Arm-body level timing control unit (multi-joint cluster control, corresponding to the module level of claim 2) This unit manages the entire lifecycle of the robot's six-joint arm motion cluster. Each robot is equipped with an independent arm-level timing control unit, which is a separate hardware control board connected to the six joint-level units via the robot's internal backplane hardware bus. Electrically, it is completely independent of all joint drive chips, forming an arm-level safety control domain. This unit only has command forwarding, task splitting and scheduling, and multi-joint synchronous control functions. It does not have any external input parsing or global arbitrary address data addressing capabilities. Command forwarding simply transmits the commands issued by the entire robot to the corresponding joint-level unit without any modification or parsing. It has no right to send any control signals to the upper level that could change the upper level's operating state, nor does it have the right to modify any configuration parameters of the upper-level timing control unit.
[0029] The core hardware circuit modules integrated in this unit are as follows, which fully implement all the technical requirements of the corresponding level: • Fixed-step linear execution sequential state machine: It is completely derived from the whole machine-level sequential logic, only the task execution stage is adapted to six-joint synchronous scheduling. The hardware circuit is permanently fixed and cannot be modified throughout the entire operation. During normal operation, it is not possible to skip steps or insert extra steps. If an abnormality is triggered, the current level will be reset and restarted. After the process is completed, it will automatically return to the standby state. • Irreversible one-way command transmission and reception hardware circuit: Physically, only downlink command reception and uplink data transmission are allowed, completely blocking the reverse control path from the lower level to the upper level; an irreversible one-way command transmission mechanism between the upper and lower levels is constructed, which can only receive control commands and motion tasks issued by the whole machine level, and can only transmit joint operation results, status signals and heartbeat signals back to the whole machine level. • Independent power domain and zoned power control circuit: It adopts an independent switching power supply module with independent power enable control, which can control the power-on and power-off of each joint-level unit in the arm body separately; in the idle state, only the lowest power consumption instruction listening circuit is kept in standby mode, and all other circuits are completely powered off and the clock is turned off; the instruction listening circuit is composed only of edge detection triggers and hardware comparators, and only has the functions of instruction reception and wake-up trigger, without any data processing capabilities. • Hardware full reset and hot-swappable fault-tolerant circuit: An abnormal trigger results in a full reset at this level, while also possessing hardware-level fault isolation and hot-swappable control capabilities. It can automatically isolate faulty joints through hardware logic, supporting hot-swappable replacement without stopping the system or affecting the normal operation of other joints; the reset covers all functional circuits within the arm module, and after the reset, it automatically re-executes the fixed timing process, leaving no abnormal data or state retention that affects the subsequent operation of the system; except for hardware counter values used only for statistical purposes, and these counter values do not participate in any system control logic; • One-time hardware access lock circuit: Constructed using a one-time programmable fuse circuit, the fuse is automatically triggered to blow immediately after the module is powered on and initialized, completing the one-time hardware access lock; after locking, the control logic and configuration parameters cannot be modified, bypassed, or released. • Module-level targeted energy-saving control circuit: Monitors the load of each joint in real time at fixed intervals, and precisely controls the power supply and clock status of each joint through hardware logic to achieve instant power-off and hibernation of joints without tasks. • Multi-joint hardware synchronization circuit: realizes hardware-level clock synchronization of six joints, ensuring the timing consistency of multi-axis linkage of the robot; • Cooling and power supply coordinated control circuit: Based on the real-time temperature and power consumption data of the arm, the hardware-fixed logic coordinates the power supply of the module and the speed of the matching cooling fan to achieve optimal energy consumption matching.
[0030] 3. System-wide timing control unit (the highest-level control unit in the entire system, corresponding to the system level in claim 2) This unit is the highest-level pure hardware timing control unit in the entire robot system. It corresponds to the global control of the entire robot. Hardware-wise, it is an independent system-level hardware main control module, installed in the robot control cabinet, and connected to the arm-level unit through a fiber optic hardware bus. Electrically, it is completely independent of the robot main controller and all joint drive modules. It is the only unit in the entire system with external input parsing, arbitrary address data addressing, and global safety protection functions.
[0031] The core hardware circuit modules integrated in this unit are as follows, which fully implement all global technical requirements: • Fixed-step linear execution timing state machine: Implemented using dedicated integrated circuits, the hardware circuit is permanently fixed and cannot be modified throughout the entire operation. During normal operation, it is not possible to skip steps or insert additional steps. It fixes the linear execution timing of the entire life cycle of the robot. Any abnormality will trigger the corresponding level or even the global reset and restart process. After the process is completed, it automatically returns to the deep standby state and executes in a loop. • Global irreversible unidirectional command bus control circuit: It is the command initiator of the entire system. It can only send control commands and motion tasks to the lower-level arm and joint units, and supports sending broadcast commands to the lower level at the same time. It only receives the running results and status signals returned by the lower level, and builds an irreversible unidirectional control command transmission mechanism that is fixed in the hardware of the entire system. There is no multi-master control arbitration mechanism throughout the entire life cycle of the system. • Global independent power domain and partitioned sleep management circuit: It adopts dual independent redundant power modules with independent power enable control, which can globally manage the power status of all lower-level units; in deep standby mode, only the lowest power stateless wake-up device, the hardware status real-time feedback interface, and the multi-joint hardware synchronization interface are kept running, while all other functional circuits are completely powered off and the clock is turned off; the stateless wake-up device is composed of only edge detection triggers and hardware comparators, and only has the functions of instruction reception and wake-up triggering, without any data processing capabilities; • Global hardware full reset circuit: It can trigger a hardware full reset at the corresponding level or even globally according to the level of the anomaly. After the reset, no abnormal data or state is left that will affect the subsequent operation of the system. Except for hardware counter values used only for statistical purposes, and these counter values do not participate in any system control logic. • One-time global hardware permission lock-up circuit: Constructed with multiple sets of one-time programmable fuse circuits, after the system is powered on and initialized, the system immediately and automatically locks up all levels of permissions, and synchronously triggers the fuses of all lower-level units to blow; after locking up, no external signal or physical operation within the normal operating range can modify the control logic and configuration parameters of the timing control units at all levels. This lock-up state cannot be released or bypassed. • Hardware atomic jump addressing circuit: Arbitrary address data addressing is performed by hardware atomic jump method completed in a single clock cycle. When addressing fails, an approximate matching fuzzy search mechanism based on hardware comparator circuit is automatically triggered as a fallback, with no software involvement throughout the process. • Three-tiered pure hardware firewall circuit: Complete end-to-end hardware security protection is achieved. The three firewalls are connected in series on the system data path. They are all constructed using hardware comparators and fixed rule logic gate circuits. The filtering rules are permanently fixed through hardware circuits without any software involvement. They are: external input firewall (connected in series with the external data input interface of the whole machine-level timing control unit, filtering all external data entering the system, as the first line of defense of the system), joint driver input firewall (composed of the corresponding firewalls of all joint-level units in the whole system, filtering all data entering the driver core, as the second line of defense of the system), and system output firewall (connected in series with the external data output interface of the whole machine-level timing control unit, filtering all output data leaving the system, as the third line of defense of the system). • Bus status hardware verification and exception handling unit: Real-time sampling of the entire system bus signals, hardware-level verification of the integrity and legality of bus data, automatic determination of exception type and level, and triggering the corresponding level of hardware full reset operation; • Multi-hardware parallel autonomous underlying security architecture unit: realizes electrical isolation and independent operation of each hardware unit in the whole system, and prevents single point failure from spreading to the entire system; • Hardware grouping and clustering scheduling unit: Based on the motion task requirements, the hardware-fixed logic automatically groups and schedules different joint clusters to achieve distributed execution of tasks; • Full hardware system physical control console: integrates all hardware control buttons and status indicator lights, used only for initial system power-on and emergency physical operations. After shutdown, it is completely disconnected from the system and does not affect the unattended operation of the system. • External compliant access hardware adapter interface: It adopts standard hardware interface and unidirectional isolation circuit to realize compliant and secure access with robot teach pendant and external programmable controller. It only transmits compliant data and has no ability to modify any control logic. • Real-time hardware status feedback interface: Constructed using a unidirectional data transmission circuit, it is only used to unidirectionally transmit system operating status data to the robot's main controller. There is no downlink control data channel, completely blocking the influence path of external software on the system control logic.
[0032] II. Fixed timing implementation of timing control units at all levels All timing control units at all levels in this system employ a fixed-step linear execution timing sequence permanently fixed in hardware circuits. No software is involved in the entire process control; all processes are executed automatically by the hardware circuits. During normal operation, skipping steps or inserting extra steps is not allowed. Any abnormality triggers a full hardware reset at the corresponding level. After the process is completed, it automatically returns to standby mode for cyclical execution. In this embodiment, the timing logic of the three-level units is completely homogeneous; only the task execution stage adapts to the functions of the corresponding level, ensuring the consistency of timing across the entire system.
[0033] The complete, fixed timing sequence of the whole-machine level timing control unit includes the following fixed, non-skipping execution states: initialization state, self-test state, low-power wait state, bus monitoring state, idle determination state, periodic lightweight monitoring state, sleep handshake state, atomic shutdown state, temperature adaptive pre-synchronization state, wake-up state, task execution state, cross-checking state, and protection reset state. The jump logic of all states is permanently fixed through hardware circuits. The state transition can only be executed in the fixed order, with no reverse jump permission. During normal operation, it cannot be modified or any additional states can be inserted.
[0034] Extended Example 1: Full-size humanoid robot scenario In this embodiment, the system is applied to the electronic and electrical architecture of a full-size bipedal humanoid robot. It adopts a three-level pure hardware timing control architecture at the joint level, limb level, and whole-machine level. The upper level has unique and irreversible control authority over the lower level. All control logic is 100% permanently fixed by pure hardware circuits. No software, firmware, or programmable logic code participates in the internal control throughout the entire system lifecycle.
[0035] • The overall timing control unit is the highest control unit of the robot. It is independent of the robot's main AI brain on-chip system and is physically and electrically isolated. It is the only highest control entity in the entire system. The main AI brain can only issue task instructions and cannot modify the control logic. Even if the main AI system crashes, the program runs out of control, or the algorithm goes out of control, it will not affect the normal operation of this system at all. • The limb-level timing control unit corresponds to five limb modules: left arm, right arm, left leg, right leg, head, and torso. It is an independent hardware control board, which corresponds to the multi-joint cluster control of each limb. It only receives control commands from the whole-machine level unit and has no right to control the upper-level unit in reverse. • The joint-level timing control unit corresponds to the servo joints of more than 20 degrees of freedom of the robot's whole body. Each joint drive chip has a built-in independent control unit, which is packaged in the same bare die as the drive core. It is electrically isolated and only receives control commands from the corresponding limb-level unit to achieve full life cycle control of a single joint.
[0036] This system is completely decoupled from the main artificial intelligence system of the humanoid robot, effectively preventing the risk of abnormal robot actions caused by uncontrolled artificial intelligence algorithms and malicious code tampering at the physical level. In emergency scenarios such as collisions and falls, microsecond-level emergency shutdown can be achieved through hardware full reset. At the same time, through hierarchical targeted power control technology, the robot's standby power consumption is reduced by more than 90%, significantly improving battery life. After the robot is powered on, it can achieve long-term unattended operation without human intervention, perfectly meeting the core requirements of high safety and high reliability for humanoid robots used in home companionship and industrial operations.
[0037] Extended Example 2: Intelligent Vehicle Scenarios In this embodiment, the system is applied to the drive-by-wire chassis and the vehicle's electronic and electrical architecture of an intelligent vehicle. It adopts a three-level pure hardware timing control architecture: domain controller level, zone level, and vehicle level. Each level has unique and irreversible control authority over its subordinate levels. All control logic is permanently fixed in pure hardware circuitry without any software involvement. The vehicle-level timing control unit is the highest control unit, corresponding to the global control of the vehicle's power, steering, and braking. The zone-level timing control unit corresponds to the zone-level control of the power domain, chassis domain, and intelligent driving domain. The domain controller-level timing control unit corresponds to the full lifecycle control of a single domain controller chip. The system is completely decoupled from the system on the vehicle's main chip. System crashes or program failures on the main chip do not affect the normal operation of the system. In abnormal scenarios such as collisions or loss of control, rapid emergency response can be achieved through a full hardware reset. Simultaneously, hierarchical hibernation control reduces the vehicle's standby power consumption by more than 90%, perfectly meeting the high safety and high reliability requirements of intelligent vehicles.
[0038] Extended Example 3: Large-Scale Intelligent Computing Center Scenario In this embodiment, the system is applied to the global management of a large-scale intelligent computing center. It employs a three-tiered pure hardware timing control architecture: chip-level, module-level, and system-level. Each level has unique and irreversible control authority over its subordinate levels. All control logic is implemented entirely in hardware circuitry, with no software or firmware involved throughout its entire lifecycle. The system-level timing control unit is the highest-level control unit of the intelligent computing center, independent of the center's scheduling platform. The module-level timing control unit corresponds to the management of a single rack's computing power cluster. The chip-level timing control unit corresponds to the full lifecycle management of a single AI inference chip. The system effectively blocks security risks such as software vulnerabilities, hacker attacks, and backdoor implantation at the physical level. Simultaneously, through tiered hibernation management, it reduces the intelligent computing center's standby power consumption by over 98%, enabling long-term unattended operation without manual maintenance. This perfectly meets the core requirements of large-scale intelligent computing centers for high security, low power consumption, and high reliability.
Claims
1. A pure hardware hierarchical control system architecture, characterized in that, include: The system consists of at least two levels of physically electrically isolated, independently powered pure hardware timing control units, with each higher-level timing control unit having unique and irreversible control authority over the lower-level timing control units. Each level of the pure hardware timing control unit is an independent hardware functional module with a built-in linear execution timing state machine that is permanently fixed in hardware. The execution steps of the linear execution timing state machine are fixed once during manufacturing. During normal operation, no steps can be skipped or additional steps can be inserted. It is used to respond only to the control instructions of the superior level and independently complete the full life cycle control logic of the corresponding level, including power-on, self-test, operation, power-off, and abnormal handling. The pure hardware timing control units at each level communicate with each other through an irreversible one-way control command transmission mechanism that is fixed in hardware. Only the upper level is allowed to transmit control commands to the lower level and the lower level is allowed to send status data back to the upper level. The hardware completely blocks the reverse control path from the lower level to the upper level. There is no multi-master control arbitration mechanism throughout the entire system lifecycle; at any given time, only one top-level pure hardware timing control unit exists. All control logic is implemented entirely by non-programmable native combinational logic gates and hardware sequential state machines. No executable programs, firmware, or programmable logic code participate in the generation and execution of internal control logic throughout the entire system lifecycle.
2. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, The pure hardware timing control unit adopts a three-level architecture arranged from bottom to top, namely: Chip-level timing control unit, corresponding to the full life cycle control of a single computing chip or a single actuator module, is encapsulated in the same physical entity as the corresponding controlled object or connected through a dedicated hardwire, and is electrically completely isolated from the controlled object, only receiving control instructions from the upper-level module-level timing control unit; The module-level timing control unit corresponds to the full lifecycle control of a subsystem composed of multiple chip-level units. It is an independent hardware control board and is connected to all the chip-level timing control units under its jurisdiction through a backplane hardware bus. It only receives control commands from the upper-level system-level timing control unit. The system-level timing control unit is the highest-level pure hardware timing control unit in the entire system. It is an independent hardware master control module and is connected to all module-level timing control units through a fiber optic hardware bus or a dedicated parallel bus.
3. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, The hardware circuit implementation of the irreversible unidirectional control command transmission mechanism is as follows: The upper-level timing control unit can only send control commands and calculation tasks to the lower level, and supports sending broadcast commands to the lower level at the same time. The lower-level timing control unit can only transmit calculation results, running status signals and heartbeat signals back to the upper level, and has no right to send any control signals to the upper level that can change the running status of the upper level. Irreversible unidirectional signal transmission is achieved between upper and lower levels through unidirectional optocouplers, unidirectional bus transceivers, or physical layer unidirectional conduction circuits, with no reverse electrical path at the hardware level.
4. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, All of the aforementioned pure hardware timing control units have independent power domain control pins, which can individually control the power-on and power-off of the corresponding level. In the idle state, the pure hardware timing control units at each level retain power to only the instruction listening circuit with the lowest power consumption, while all other functional circuits are completely powered off and the clock is turned off. The instruction monitoring circuit consists only of an edge detection trigger and a hardware comparator, and only has the functions of instruction reception and wake-up triggering, but does not have any data processing capabilities.
5. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, All of the aforementioned pure hardware timing control units have corresponding levels of hardware full reset circuits; The hardware full reset covers all functional circuits at the corresponding level. After the reset, the fixed timing process at the corresponding level is automatically re-executed, and no abnormal data or state is left that affects the subsequent operation of the system. This excludes hardware counter values used solely for statistical purposes, and these counter values do not participate in any system control logic.
6. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, All of the aforementioned pure hardware timing control units have a built-in one-time hardware permission lock-off circuit. After the corresponding level is powered on and initialized, a one-time hardware permission lock is automatically triggered immediately. Once locked, no external signal or physical operation within the normal operating range can modify the control logic and configuration parameters of the timing control unit. This lock state cannot be released or bypassed within the normal operating range of the system.
7. The pure hardware hierarchical control system architecture according to claim 2, characterized in that, The system-level timing control unit has a built-in hardware atomic jump addressing circuit, which uses a hardware atomic jump method completed in a single clock cycle to perform arbitrary address data addressing; When addressing fails, an approximate matching fuzzy search mechanism based on hardware comparator circuits is automatically triggered as a fallback. The matching rules are permanently fixed through hardware circuits, with no software involvement throughout the process.
8. The pure hardware hierarchical control system architecture according to claim 2, characterized in that, The linear execution timing state machines of the chip-level, module-level, and system-level timing control units adopt completely homogeneous fixed-step linear execution timing, with only the task execution stage adapting to the functional boundaries of the corresponding level, ensuring the timing consistency of the entire system.
9. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, The linear execution sequential state machine includes the following fixed, non-skippable execution states: The system includes initialization state, self-test state, low-power wait state, bus monitoring state, idle determination state, periodic lightweight monitoring state, sleep handshake state, atomic shutdown state, temperature adaptive pre-synchronization state, wake-up state, task execution state, cross-checking state, and protection reset state. The transition logic for all states is permanently fixed by the hardware circuit. The state transition can only be executed in the fixed order, and there is no reverse transition permission. During normal operation, no additional states can be modified or inserted.
10. The pure hardware hierarchical control system architecture according to claim 1, characterized in that, The system architecture is completely decoupled from the computing core, and connects to the computing chip only through a standard hardware interface. No modification is required to the computing core code, and it can directly interface with any native inference chip, general computing chip or servo actuator.