A hardware watchdog circuit and MCU-based control system
By constructing a hardware watchdog circuit using discrete components such as a boost module, an inverting module, and a reset signal output module, the high cost of hardware watchdog circuits is solved, resulting in cost reduction and simplified production complexity.
Patent Information
- Application Number
- CN202610982123.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-02
- Publication Date
- 2026-08-25
AI Technical Summary
Existing hardware watchdog circuits have a high overall cost, and the watchdog function needs to be additionally disabled during MCU programming or upgrades, which increases production complexity and field maintenance costs.
By employing a watchdog boost module, an inverting module, and a reset signal output module, a hardware watchdog circuit is constructed using discrete components to replace the expensive watchdog chip, thereby enabling the monitoring and reset of the MCU.
It reduces the overall cost of the hardware watchdog circuit, simplifies the production and field upgrade process, and avoids the need to disable the watchdog function during programming or upgrades.
Smart Images

Figure CN122632710A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of watchdog circuit technology, and more specifically, to a hardware watchdog circuit and an MCU-based control system. Background Technology
[0002] Microcontrollers (MCUs), as core control components, are widely used in various products such as home appliances, industrial control, automotive electronics, smart wearable devices, and IoT terminals. MCUs execute pre-programmed code stored in their internal memory to control various peripheral devices and handle data interaction. However, in actual operation, MCUs face several factors that can lead to malfunctions. For example, fluctuations in mains voltage can increase power ripple, affecting the timing margin of the MCU's internal digital logic circuits; electromagnetic interference in the environment can couple into the MCU through power or signal lines, causing unexpected register data flips; and untested edge cases in the program design can trigger unpredictable logic jumps under specific runtime conditions. When these factors occur, the MCU's program counter may jump to an incorrect instruction address, the program may get stuck in an infinite loop, or even the MCU's internal bus arbitration logic may malfunction—all situations collectively referred to as system crashes or program crashes.
[0003] If the MCU crashes or the program malfunctions, the control tasks it was supposed to perform will be interrupted. Therefore, an effective monitoring mechanism must be used to reset the MCU in a timely manner when it malfunctions, restoring it to a known initial state and restarting program execution. This monitoring mechanism is called a watchdog timer.
[0004] Currently, watchdog timers generally fall into two categories: software watchdogs and hardware watchdogs. For hardware watchdogs, the mainstream implementation method is to use dedicated watchdog chips. These chips integrate precise timers, voltage reference sources, and reset output driver circuits, offering advantages such as high timing accuracy, wide operating temperature range, and low power consumption. However, the cost of these chips is relatively high, resulting in a higher overall cost for the watchdog circuit. Summary of the Invention
[0005] The purpose of this disclosure is to provide a hardware watchdog circuit and an MCU-based control system to solve the problem of high overall cost of watchdog circuits in the prior art.
[0006] To achieve the above objectives, the technical solutions adopted in the embodiments of this disclosure are as follows: On one hand, embodiments of this disclosure provide a hardware watchdog circuit, the hardware watchdog circuit comprising: The dog-feeding boost module has its input connected to the dog-feeding signal pin of the MCU to receive the dog-feeding signal output by the MCU, and its output connected to the control terminal of the inverting module. The inverter module's output is connected to the control terminal of the reset signal output module. A reset signal output module, the output of which is connected to the reset pin of the MCU; wherein, When the MCU is powered on, the dog feed boost module outputs a low level, and the inverting module controls the reset signal output module to reset, and then keeps the reset pin at a high level so that the MCU can start normally or enter the software programming state. When the MCU starts normally and outputs the watchdog signal, the watchdog boost module boosts the watchdog signal and outputs a high-voltage control signal. The inverter module responds to the high-voltage control signal to control the reset signal output module to keep the reset pin at a high level. When the MCU malfunction causes the watchdog signal to be lost, the high voltage control signal of the watchdog boost module disappears, and the inverting module controls the reset signal output module to output a reset pulse to the reset pin to reset the MCU.
[0007] Optionally, the dog-feeding booster module includes: The push-pull unit has its control terminal connected to the dog-feeding signal pin; A voltage multiplier unit, connected to the push-pull unit, is used to multiply the dog-feeding signal to generate the high-voltage control signal; The voltage divider unit is connected between the output terminal of the voltage multiplier unit and the control terminal of the inverting module.
[0008] Optionally, the push-pull unit includes a P-type switch, a first N-type switch, a first resistor, and a second resistor. The control terminals of the P-type switch and the first N-type switch are both connected to the dog feed signal pin. The first terminal of the P-type switch is connected to the power supply. The second terminal of the P-type switch, the first resistor, the second resistor, and the first terminal of the first N-type switch are connected in sequence. The second terminal of the first N-type switch is grounded. The voltage multiplier unit is connected at the midpoint between the first resistor and the second resistor.
[0009] Optionally, the voltage multiplier unit includes a first capacitor, a second capacitor, and a diode assembly. One end of the first capacitor is connected to the push-pull unit, and the other end of the first capacitor is connected to the diode assembly and one end of the second capacitor. The other end of the second capacitor is connected to the diode assembly, and the diode assembly is also connected to the voltage divider unit and the power supply. The two switching transistors in the push-pull unit are alternately turned on under the pulse drive of the dog-feeding signal, causing the first capacitor and the second capacitor to charge and discharge sequentially, thereby multiplying the voltage of the dog-feeding signal.
[0010] Optionally, the diode assembly includes a first diode, a second diode, a third diode, and a fourth diode. The anode of the first diode is connected to a power supply. The cathode of the first diode is connected to the other end of the first capacitor and the anode of the second diode. The cathode of the second diode is connected to the anode of the third diode. The cathode of the third diode is connected to the other end of the second capacitor and the anode of the fourth diode. The cathode of the fourth diode serves as the output terminal of the voltage multiplier unit and is connected to the voltage divider unit.
[0011] Optionally, the voltage divider unit includes a third resistor and a fourth resistor. One end of the third resistor and the fourth resistor connected in series is connected to the voltage multiplier unit, and the other end is grounded. The intermediate node between the third resistor and the fourth resistor is connected to the control terminal of the inverting module.
[0012] Optionally, the dog-feeding boost module further includes a fifth resistor, one end of which is connected to the control terminal of the push-pull unit, and the other end of which is grounded.
[0013] Optionally, the inverting module includes a sixth resistor and a second N-type switch. The control terminal of the second N-type switch is connected to the output terminal of the dog-feeding boost module. The first terminal of the second N-type switch is connected to the power supply through the sixth resistor, and the second terminal of the second N-type switch is grounded. The first terminal of the second N-type switch is also connected to the control terminal of the reset signal output module.
[0014] Optionally, the reset signal output module includes a third N-type switch, a seventh resistor, an eighth resistor, a ninth resistor, and a third capacitor. The control terminal of the third N-type switch is connected to one end of the third capacitor, the seventh resistor, and the eighth resistor, respectively. The other ends of the third capacitor and the seventh resistor are connected to the inverting module. The eighth resistor is grounded. The first end of the third N-type switch is connected to the power supply through the ninth resistor, and the first end of the third N-type switch is also connected to the reset pin of the MCU. The second end of the third N-type switch is grounded.
[0015] On the other hand, embodiments of this disclosure also provide an MCU-based control system, which includes the aforementioned hardware watchdog circuit.
[0016] Compared with the prior art, this disclosure has the following beneficial effects: By utilizing the watchdog boost module, inverting module, and reset signal output module provided in this disclosure, a watchdog circuit can be constructed using discrete components, replacing the traditional watchdog chip. This eliminates the need for expensive chips in the hardware watchdog circuit, significantly reducing overall costs. Furthermore, since the hardware watchdog circuit requires no additional operations during production programming and field upgrades, it eliminates the need to disable the watchdog reset function during software programming, thus significantly reducing production complexity and field maintenance costs.
[0017] To make the above-mentioned objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of this disclosure and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 A schematic diagram of a hardware watchdog circuit provided in an embodiment of this disclosure.
[0020] Figure 2 A circuit diagram of a hardware watchdog circuit provided in an embodiment of this disclosure.
[0021] Figure 3 This is another schematic diagram of a hardware watchdog circuit provided in an embodiment of the present disclosure.
[0022] Figure 4 This is a circuit diagram of the dog-feeding boost module provided in an embodiment of the present disclosure.
[0023] Figure 5 This is a circuit diagram of an inverting module provided in an embodiment of the present disclosure.
[0024] Figure 6 This is a circuit diagram of a reset signal output module provided in an embodiment of the present disclosure.
[0025] In the picture: 110 - Dog feed boost module; 111 - Push-pull unit; 112 - Voltage multiplier unit; 113 - Voltage divider unit; 120 - Inverting module; 130 - Reset signal output module; Q1 - P-type switch; Q2 - First N-type switch; Q3 - Second N-type switch; Q4 - Third N-type switch; R1 - First resistor; R2 - Second resistor; R3 - Third resistor; R4 - Fourth resistor; R5 - Fifth resistor; R6 - Sixth resistor; R7 - Seventh resistor; R8 - Eighth resistor; R9 - Ninth resistor; C1 - First capacitor; C2 - Second capacitor; C3 - Third capacitor; D1 - First diode; D2 - Second diode; D3 - Third diode; D4 - Fourth diode. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. The components of the embodiments of this disclosure described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0027] Therefore, the following detailed description of the embodiments of this disclosure provided in the accompanying drawings is not intended to limit the scope of the claimed disclosure, but merely to illustrate selected embodiments of the disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without inventive effort are within the scope of protection of this disclosure.
[0028] In the description of this disclosure, the terms "first," "second," etc., are used for descriptive purposes only to distinguish similar components in different locations, and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. The term "connection" should be interpreted broadly; for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection, an electrical connection, or a signal connection; it can be a direct connection or an indirect connection through an intermediate medium. Those skilled in the art can understand the specific meaning of the above terms in this disclosure according to the specific circumstances. The term "power supply" or "power supply voltage" refers to the DC voltage source that supplies power to the MCU and the hardware watchdog circuit of this disclosure. In typical applications, this power supply voltage is usually 3.3V or 5V, but this disclosure is not limited to these voltage values, and other suitable DC power supply voltages are also applicable. The term "ground" or "grounded" refers to the reference zero potential point in the circuit, i.e., the negative terminal or common terminal of the power supply.
[0029] The technical solution of this disclosure will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0030] As described in the background section, if an MCU crashes or its program malfunctions, the control tasks it was supposed to perform will be interrupted. For example, in washing machine control, the water level sensor signal may not be read in time, causing the inlet valve to remain open for an extended period and overflow; in industrial temperature controllers, this may cause the heating element to remain continuously powered and malfunction, posing a safety hazard; in automotive electronic modules, this may prevent the transmission of critical communication messages, affecting the coordination of the entire vehicle network. Therefore, a watchdog-based monitoring mechanism is needed to promptly reset the MCU when it malfunctions, restoring it to a known initial state and restarting program execution.
[0031] The basic working principle of a watchdog timer is as follows: During normal system operation, the MCU periodically sends a specific signal (feed signal) to the watchdog circuit to indicate that the MCU is in normal operating condition. If the MCU crashes for some reason and can no longer send the feed signal, the watchdog circuit will determine that the MCU has malfunctioned. At this time, the watchdog circuit will actively output a reset pulse to the MCU's reset pin, forcing the MCU to perform a hardware reset, thereby attempting to restore the system to normal operating condition.
[0032] Currently, watchdog timers include software watchdogs and hardware watchdogs. Software watchdogs are typically implemented using an independent timer within the MCU, which has the advantage of not requiring additional external components. However, software watchdogs also depend on the normal operation of the MCU. When the MCU experiences certain serious hardware failures (such as the clock oscillator stopping or the power supply voltage dropping below the logic threshold), the software watchdog itself may fail to function, thus losing its monitoring role. Therefore, in applications with high reliability requirements, hardware watchdogs are usually chosen, that is, using independent hardware circuitry to implement the watchdog function.
[0033] The mainstream approach to implementing a hardware watchdog timer is to use a dedicated watchdog chip. These chips integrate a precision timer, voltage reference, and reset output driver circuit, offering advantages such as high timing accuracy, wide operating temperature range, and low power consumption. However, they also come with a higher cost.
[0034] In addition to cost issues, the manufacturing or repair of MCUs requires programming code into their internal memory or performing firmware upgrades via the communication interface without disassembling the product casing. During these programming or upgrade processes, the MCU operates in a special mode where it does not run the user's main program and therefore does not generate a normal watchdog signal. If the watchdog circuit is already active and starting to time, it will send a reset signal upon timeout, forcing the MCU to reset. This MCU reset will then interrupt the ongoing programming or upgrade operation. Therefore, additional measures are needed to disable the watchdog function, such as temporarily disconnecting the power supply to the watchdog circuit or adding a dedicated shielding circuit, increasing the complexity of the production process.
[0035] In view of this, in order to solve the above problems, this disclosure provides a hardware watchdog circuit, please refer to... Figure 1 and Figure 2 The hardware watchdog circuit mainly includes three functional modules: a watchdog boost module 110, an inverting module 120, and a reset signal output module 130. The input of the watchdog boost module 110 is connected to the watchdog signal pin of the MCU to receive the watchdog signal output by the MCU, and its output is connected to the control terminal of the inverting module 120. The output of the inverting module 120 is connected to the control terminal of the reset signal output module 130. The output of the reset signal output module 130 is used to connect to the reset pin of the MCU.
[0036] When the MCU powers on, the watchdog boost module 110 outputs a low level. After the inverting module 120 controls the reset signal output module 130 to reset, the reset pin remains at a high level to enable the MCU to start normally or enter the software programming state. When the MCU starts normally and outputs a watchdog signal, the watchdog boost module 110 boosts the watchdog signal and outputs a high-voltage control signal. The inverting module 120 responds to the high-voltage control signal and controls the reset signal output module 130 to keep the reset pin at a high level. When the MCU malfunctions and causes the watchdog signal to be lost, the high-voltage control signal of the watchdog boost module 110 disappears, and the inverting module 120 controls the reset signal output module 130 to output a reset pulse to the reset pin to reset the MCU.
[0037] Understandably, the hardware watchdog circuit provided in this disclosure achieves the effect of building a watchdog circuit with discrete components, replacing the watchdog chip, through the feed boost module 110, the inverting module 120, and the reset signal output module 130. This eliminates the need for expensive chips in the hardware watchdog circuit, significantly reducing the overall cost. Furthermore, since the hardware watchdog circuit requires no additional operations during production programming and field upgrades, eliminating the need to disable the watchdog reset function during software programming, it significantly reduces production complexity and field maintenance costs.
[0038] The following provides a detailed description of each functional module provided in this disclosure. It should be noted that in the following description, VCC refers to the power supply voltage of the entire system. Using 3.3V as an example, it can be understood that the circuit operates on the same principle when VCC is 5V or other voltage values; only the voltage values of the relevant nodes will change proportionally. MCU_WDI represents the MCU's watchdog signal pin, and MCU_RST represents the MCU's reset pin. Furthermore, for ease of description of the circuit's operating principle, Figure 2 The diagram shows voltage markings for several key nodes, including points A, B, C, D, E, F, and G. Changes in the voltage at these nodes reflect the state transitions of the circuit at different operating stages.
[0039] As one implementation method, please refer to Figure 3 The dog-feeding boost module 110 includes a push-pull unit 111, a voltage multiplier unit 112, and a voltage divider unit 113. The control terminal of the push-pull unit 111 is connected to the dog-feeding signal pin. The voltage multiplier unit 112 is connected to the push-pull unit 111 and is used to multiply the dog-feeding signal to generate a high-voltage control signal. The voltage divider unit 113 is connected between the output terminal of the voltage multiplier unit 112 and the control terminal of the inverting module 120.
[0040] For example, please refer to Figure 4 The push-pull unit 111 consists of a P-type switch Q1, a first N-type switch Q2, a first resistor R1, and a second resistor R2. The control terminals of both the P-type switch Q1 and the first N-type switch Q2 are connected to the watchdog signal pin MCU_WDI. The first terminal of the P-type switch Q1 is connected to the power supply. The second terminal of the P-type switch Q1, the first resistor R1, the second resistor R2, and the first terminal of the first N-type switch Q2 are connected in sequence. The second terminal of the first N-type switch Q2 is grounded. The voltage multiplier unit 112 is connected at the midpoint between the first resistor R1 and the second resistor R2.
[0041] In this embodiment, the P-type switch Q1 and the first N-type switch Q2 can be transistors, MOSFETs, or other types of switches, and this disclosure does not impose any limitations on them. Taking both the P-type switch Q1 and the first N-type switch Q2 as MOSFETs as an example, the source of the P-type switch Q1 is connected to the power supply VCC, and the drain is connected to one end of the first resistor R1. The other end of the first resistor R1 is connected to one end of the second resistor R2, and this connection node serves as the output node (i.e., point A) of the push-pull unit 111, which is connected to the subsequent voltage multiplier unit 112. The other end of the second resistor R2 is connected to the drain of the first N-type switch Q2. The source of the first N-type switch Q2 is grounded. The gates of both the P-type switch Q1 and the first N-type switch Q2 are connected to the MCU's watchdog signal pin MCU_WDI.
[0042] Meanwhile, in order to ensure that the push-pull unit 111 can be in a certain state when the MCU_WDI pin is in a high-impedance state, the dog-feed boost module 110 also includes a fifth resistor R5. One end of the fifth resistor R5 is connected to the control terminal of the push-pull unit 111, that is, one end of the fifth resistor R5 is connected to the MCU_WDI pin, and the other end of the fifth resistor R5 is grounded. The resistance value of the fifth resistor R5 needs to take into account both power consumption and pull-down capability.
[0043] In one implementation, the voltage multiplier unit 112 consists of a first capacitor C1, a second capacitor C2, and a diode assembly. One end of the first capacitor C1 is connected to the push-pull unit 111, and the other end of the first capacitor C1 is connected to the diode assembly and one end of the second capacitor C2, respectively. The other end of the second capacitor C2 is connected to the diode assembly, and the diode assembly is also connected to the voltage divider unit 113 and the power supply. The two switching transistors in the push-pull unit 111 are alternately turned on under the pulse drive of the watchdog signal, causing the first capacitor C1 and the second capacitor C2 to charge and discharge sequentially, thereby multiplying the voltage of the watchdog signal.
[0044] Specifically, one end of the first capacitor C1 (i.e. Figure 4 The left end of the first capacitor C1 is connected to the output node of the push-pull unit 111, which is the middle node between the first resistor R1 and the second resistor R2. The other end of the first capacitor C1 (i.e. Figure 4 The right end of the first capacitor C1 is connected to point B. The diode assembly includes a first diode D1, a second diode D2, a third diode D3, and a fourth diode D4. The connection of the four diodes forms a two-stage charge pump structure.
[0045] In this configuration, the anode of the first diode D1 is connected to the power supply VCC, and the cathode of the first diode D1 is connected to point B. The anode of the second diode D2 is connected to point B, and the cathode of the second diode D2 is connected to point C. The anode of the third diode D3 is connected to point C, and the cathode of the third diode D3 is connected to point D. The anode of the fourth diode D4 is connected to point D, and the cathode of the fourth diode D4 is connected to the voltage divider unit 113.
[0046] Of course, in practical applications, the voltage multiplier unit 112 may also include more components, such as capacitor C5, one end of which is connected to point C and the other end is grounded.
[0047] In one implementation, the voltage divider unit 113 is composed of a third resistor R3 and a fourth resistor R4. One end of the third resistor R3 and the fourth resistor R4 connected in series is connected to the voltage multiplier unit 112, and the other end is grounded. The intermediate node between the third resistor R3 and the fourth resistor R4 is connected to the control terminal of the inverting module 120.
[0048] In this design, the intermediate node between the third resistor R3 and the fourth resistor R4 is point F. The voltage divider unit 113 may also include other components, such as capacitor C6, which is connected between point F and ground. The capacitance value of capacitor C6 can be selected based on the required filtering time constant.
[0049] As one implementation method, please refer to Figure 5 The inverting module 120 includes a sixth resistor R6 and a second N-type switch Q3. The control terminal of the second N-type switch Q3 is connected to the output terminal of the dog-feeding boost module 110. The first terminal of the second N-type switch Q3 is connected to the power supply VCC through the sixth resistor R6, and the second terminal of the second N-type switch Q3 is grounded. The first terminal of the second N-type switch Q3 is also connected to the control terminal of the reset signal output module 130.
[0050] For example, when the second N-type switch Q3 is an NMOS transistor, the gate (i.e., the control terminal) of the second N-type switch Q3 is connected to point F. The drain (i.e., the first terminal) of the second N-type switch Q3 is connected to the power supply VCC through the sixth resistor R6, and the source (i.e., the second terminal) of the second N-type switch Q3 is grounded.
[0051] As one implementation method, please refer to Figure 6The reset signal output module 130 includes a third N-type switch Q4, a seventh resistor R7, an eighth resistor R8, a ninth resistor R9, and a third capacitor C3. The control terminal of the third N-type switch Q4 is connected to one end of the third capacitor C3, the seventh resistor R7, and the eighth resistor R8, respectively. The other end of the third capacitor C3 and the seventh resistor R7 is connected to the inverting module 120. The eighth resistor R8 is grounded. The first end of the third N-type switch Q4 is connected to the power supply through the ninth resistor R9, and the first end of the third N-type switch Q4 is also connected to the reset pin of the MCU. The second end of the third N-type switch Q4 is grounded.
[0052] Taking the third N-type switch Q4 as an NMOS as an example, the gate (i.e., the control terminal) of the third N-type switch Q4 is connected to point G, the source (i.e., the second terminal) of the third N-type switch Q4 is grounded, and the drain (i.e., the first terminal) of the third N-type switch Q4 is connected to the power supply VCC through the ninth resistor R9. At the same time, this drain is connected to the MCU's reset pin MCU_RST. One end of the seventh resistor R7 is connected to point G, and the other end of the seventh resistor R7 is connected to the drain of the second N-type switch Q3. One end of the eighth resistor R8 is connected to point G, and the other end of the eighth resistor R8 is grounded. One end of the third capacitor C3 is connected to point G, and the other end of the third capacitor C3 is connected to the drain of the second N-type switch Q3.
[0053] The working principle of the hardware watchdog circuit of this disclosure embodiment will be described in detail below, in conjunction with the circuit's operation process: Regarding the circuit operation before the MCU reaches normal operating status after power-on, when the system power supply VCC starts to power on, VCC gradually rises from 0V to a stable voltage of 3.3V. During the power-on process, the MCU's internal power management circuit and clock circuit require a certain amount of time to stabilize. Therefore, all general-purpose input / output pins of the MCU (including the MCU_WDI pin) are in an uninitialized state initially. This state may be a high-level output, a low-level output, or a high-impedance state, depending on the design of the MCU's internal power-on reset logic and whether the pin is affected by internal pull-up or pull-down resistors during power-on. Furthermore, the hardware watchdog circuit provided in this disclosure can operate correctly regardless of the initial state of the MCU_WDI pin during the power-on phase.
[0054] Once VCC stabilizes, since the MCU has not yet entered its normal operating program, no regular watchdog pulse signal will be generated on the MCU_WDI pin. In this case, the gates of the P-type switch Q1 and the first N-type switch Q2 in the push-pull unit 111 are both connected to the MCU_WDI pin. If the MCU_WDI pin is high (e.g., 3.3V), the first N-type switch Q2 is turned on, while the P-type switch Q1 is turned off. At this time, the output node of the push-pull unit 111 (i.e., point A) is connected to ground through the second resistor R2 and the turned-on first N-type switch Q2, so the voltage at this node is close to 0V. If the MCU_WDI pin is low (e.g., 0V), the P-type switch Q1 is turned on, while the first N-type switch Q2 is turned off. At this time, the output node of the push-pull unit 111 is connected to the power supply VCC through the first resistor R1 and the turned-on P-type switch Q1, so the voltage at this node is close to 3.3V. If the MCU_WDI pin is in a high-impedance state, the potential of the MCU_WDI pin is pulled down to near 0V due to the pull-down effect of the fifth resistor R5. At this time, the P-type switch Q1 is turned on, and the output node of the push-pull unit 111 also presents a high level close to 3.3V.
[0055] However, regardless of whether the output node of push-pull unit 111 is high or low, for voltage doubler unit 112, during this stage, since the MCU is not yet running normally and no pulse signal is generated on the MCU_WDI pin, the output node of push-pull unit 111 remains at a fixed level, either close to 0V or close to 3.3V, without alternating between high and low levels. Voltage doubler unit 112 is essentially a charge pump, and its operation requires a continuous clock excitation signal. When the output node of push-pull unit 111 remains at a fixed level, the voltage across the first capacitor C1 does not change after the initial transient process ends. Therefore, the voltage at point B is fixed at a level determined by the power supply VCC through the first diode D1 and the equivalent load. By appropriately selecting the conduction characteristics of the first diode D1 and the second diode D2, as well as the resistance values of the relevant resistors, the voltage at point B is limited to a low value. Simultaneously, the voltage across the second capacitor C2 is not boosted, so the voltage at point E is essentially equal to the remaining value of the power supply voltage VCC after the series voltage drop through the first diode D1, the second diode D2, the third diode D3, and the fourth diode D4. Each diode has a forward voltage drop of approximately 0.6V to 0.7V, and the series voltage drop of the four diodes is approximately 2.4V to 2.8V. Therefore, the voltage at point E is approximately 3.3V minus 2.4V to 2.8V, or approximately 0.5V to 0.9V. After this voltage is divided by the third resistor R3 and the fourth resistor R4, the voltage at point F is approximately 0.5V. For a typical NMOS transistor, its turn-on threshold voltage is usually between 1V and 2V, which is much lower than the turn-on threshold voltage of the second N-type switch Q3. Therefore, the second N-type switch Q3 is in a completely off state.
[0056] When the second N-type switch Q3 is off, the voltage at point G, the output of the inverter module 120, is determined by the voltage division of the sixth resistor R6 and the eighth resistor R8. Under transient conditions, because the second N-type switch Q3 is off, there is no low-impedance path from Q3 to ground at point G. Therefore, the voltage at point G is determined by the sixth resistor R6, the eighth resistor R8, and the third capacitor C3. The resistance of the sixth resistor R6 is much smaller than that of the eighth resistor R8. For example, the resistance of the eighth resistor R8 is more than five times that of the sixth resistor R6. For instance, if the resistance of the eighth resistor R8 is 51KΩ and the resistance of the sixth resistor R6 is 10KΩ, the voltage at point G is higher than that of the third N-type switch Q4, causing Q4 to conduct. The MCU's reset pin then receives the reset signal MCU_RST.
[0057] Under static conditions, the third capacitor C3 is essentially open-circuited. The voltage at point G is the voltage obtained by dividing the power supply VCC through the sixth resistor R6, the seventh resistor R7, and the eighth resistor R8. The resistance of the seventh resistor R7 is much greater than that of the eighth resistor R8. For example, the resistance of the seventh resistor R7 is 10 times that of the eighth resistor R8. Therefore, the voltage at point G is low, the third N-type switch Q4 is turned off, and the MCU_RST voltage is equal to VCC, maintaining a high level. The MCU can start normally or enter the programming software state normally.
[0058] Therefore, during the stage when the MCU is powered on but has not yet started normally, the hardware watchdog circuit disclosed herein keeps the MCU_RST pin at a high level, allowing the MCU to start freely. Once the MCU starts, whether it enters the normal user program running mode or the dedicated programming or upgrade mode, it will not be interfered with by the watchdog circuit. This ensures that programming or upgrade operations can be performed normally without any additional shielding circuits or manual operation during the MCU software programming or upgrade process.
[0059] When the MCU starts normally or after the software programming is completed and it outputs a watchdog timer signal, its control program enters the main loop. In the main loop, the watchdog timer signal causes the MCU_WDI pin to output a pulse waveform at a fixed frequency. The frequency of this pulse waveform needs to be determined based on the system's watchdog timeout requirements. Generally, the higher the frequency of the watchdog timer pulse, the more energy the watchdog circuit needs to maintain its active state, but at the same time, the faster the circuit responds to the loss of the watchdog timer signal. In a typical application scenario, the frequency of the watchdog timer pulse is chosen to be 1kHz, meaning a level transition occurs every 1ms.
[0060] When a pulse signal appears on the MCU_WDI pin, the push-pull unit 111 begins normal operation. The function of the push-pull unit 111 is to buffer and amplify the signal on the MCU_WDI pin, while simultaneously generating a push-pull output signal with stronger driving capability. Specifically, when the MCU_WDI signal is high, the first N-type switch Q2 is turned on, and the output node of the push-pull unit 111 is pulled low to a level close to 0V. When the MCU_WDI signal is low, the P-type switch Q1 is turned on, and the output node of the push-pull unit 111 is pulled high to a level close to 3.3V. Therefore, the output node of the push-pull unit 111 generates a square wave signal with a stronger driving capability and opposite phase to the MCU_WDI signal. The amplitude of this square wave signal is from 0V to 3.3V, and its frequency is the same as the MCU_WDI signal.
[0061] The square wave signal output from this push-pull unit serves as the excitation source for the voltage multiplier unit 112. The voltage multiplier unit 112 operates as a charge pump. When the output node of the push-pull unit 111 transitions from a high level to a low level, the voltage at the left end of the first capacitor C1 transitions from 0V to 3.3V. Since the voltage across the first capacitor C1 cannot change abruptly, the voltage at its right end (point B) will also transition accordingly. Before the transition, the voltage at point B is clamped by the first diode D1 at the power supply VCC minus the forward voltage drop of the first diode D1, approximately 3.3V - 0.6V = 2.7V. When the voltage at the left end of the first capacitor C1 transitions to 3.3V, the voltage at point B transitions to 2.7V + 3.3V = 6V. Similarly, point D also transitions to a higher voltage.
[0062] For example, when point D jumps to a voltage of 3 times its rated voltage, its voltage is approximately 9V. After being divided by the third resistor R3 and the fourth resistor R4, the voltage at point F is approximately 3V. This voltage is sufficient to fully turn on the NMOS transistor. Capacitor C6 is connected in parallel between point F and ground. Its function is to filter out ripple and interference on the voltage at point F, so that point F obtains a smooth and stable DC voltage.
[0063] When the voltage at point F rises to a level sufficient to turn on the second N-type switch Q3, Q3 turns on, and its drain is pulled low to near ground. At this time, the voltage at point G is determined by the voltage division of resistors R6, R7, and R8, and is pulled low. This low level acts on the gate of the third N-type switch Q4, turning it off. After Q4 turns off, the MCU_RST pin is pulled up to the power supply VCC through resistor R9 and remains high. The MCU continues to operate normally and will not be reset.
[0064] As can be seen, during normal MCU operation, the watchdog boost module 110 continuously generates a high-voltage control signal, which is inverted to a low level by the inverting module 120. The reset signal output module 130 maintains the MCU_RST pin at a high level under low-level control. The entire circuit forms a stable closed loop, with the MCU continuously outputting the watchdog signal and the circuit remaining in a non-reset state.
[0065] When the MCU crashes or the program malfunctions for some reason, its program execution flow is interrupted, and the watchdog signal is no longer generated. The MCU_WDI pin may remain at a high level, a low level, or be in an indeterminate state; there will no longer be alternating pulse signals on the MCU_WDI pin.
[0066] In this situation, the output node of push-pull unit 111 is fixed at a certain level, voltage multiplier unit 112 loses its excitation source, and the first capacitor C1 and the second capacitor C2 are no longer alternately charged and discharged, so the voltage at point D begins to drop. The voltage drop at point D is not instantaneous, but rather gradually discharged through the fourth resistor R4 and the equivalent load in the subsequent circuit. The rate of voltage drop at point D depends on the resistance values of the third resistor R3 and the fourth resistor R4, as well as the capacitance value of capacitor C6. This time constant determines the watchdog timeout time, i.e., the delay time between the loss of the watchdog signal and the generation of a reset pulse by the circuit.
[0067] When the voltage at point F decreases below the turn-on threshold of the second N-type switch Q3 as the voltage at point D decreases, Q3 transitions from the on state to the off state. This transition is a positive feedback process because as Q3 begins to turn off, the voltage at point G begins to rise, which further reduces the gate-source voltage of Q3, accelerating its turn-off process.
[0068] When the second N-type switch Q3 is turned off, the voltage at point G is no longer pulled down to ground. One end of the seventh resistor R7 is connected to point G, and the other end is connected to the power supply VCC, so the voltage at point G begins to rise. Simultaneously, the third capacitor C3 is connected between point G and the power supply VCC. During the rise of the voltage at point G, the third capacitor C3 is charged through the sixth resistor R6. Since the voltage across the third capacitor C3 cannot change abruptly, the rise of the voltage at point G is delayed by the third capacitor C3, and its rise time is determined by the product of the seventh resistor R7 and the third capacitor C3.
[0069] During the rise of the voltage at point G, when the voltage reaches the turn-on threshold of the third N-type switch Q4, Q4 begins to conduct. As the voltage at point G continues to rise, the conduction level of the third N-type switch Q4 gradually increases, and its drain voltage (i.e., the MCU_RST pin) is gradually pulled low. When the voltage at point G rises high enough, the third N-type switch Q4 is fully turned on, and the MCU_RST pin is pulled low to near ground level.
[0070] However, the voltage at point G does not remain at the high level that turns on the third N-type switch Q4 indefinitely. Once the third capacitor C3 has fully charged, the voltage at point G reaches its steady-state value. In this disclosure, the eighth resistor R8 is connected between point G and ground, and its resistance value is chosen such that the steady-state voltage at point G is lower than the turn-on threshold of the third N-type switch Q4. Specifically, when the second N-type switch Q3 is turned off, the steady-state voltage at point G is determined by the voltage division of the sixth resistor R6, the seventh resistor R7, and the eighth resistor R8. By setting the resistance values of the sixth resistor R6, the seventh resistor R7, and the eighth resistor R8, the steady-state voltage at point G is made lower than the turn-on threshold of the third N-type switch Q4.
[0071] In this disclosure, a pulse is generated during the charging transient process of the third capacitor C3, rather than relying on the steady-state voltage to control the conduction state of the third N-type switch Q4. Specifically, when the second N-type switch Q3 is suddenly turned off, the voltage at point G rises from near 0V. Due to the charging delay of the third capacitor C3, the voltage at point G does not immediately rise to the steady-state value, but undergoes a rising process. During this rising process, the voltage at point G passes through the conduction threshold voltage range of the third N-type switch Q4, thereby generating a brief low-level pulse at the drain of the third N-type switch Q4. When the voltage at point G continues to rise and eventually stabilizes at a level higher than the conduction threshold of the third N-type switch Q4, the third N-type switch Q4 remains on, the MCU_RST pin remains low, and the MCU remains in a reset state.
[0072] As can be seen, the generation of the reset signal is essentially a transient process. By appropriately selecting the parameters of the eighth resistor R8 and the third capacitor C3, the width of the reset pulse can be controlled to meet the reset requirements of the MCU. Generally speaking, the required reset pulse width for the MCU is between tens of microseconds and milliseconds.
[0073] In summary, the state changes of the hardware watchdog circuit provided in this embodiment throughout the entire operating cycle can be summarized as follows: During the initial power-on phase, the watchdog boost module 110 does not generate a high-voltage control signal, the inverting module 120 outputs a high level, and the reset signal output module 130 generates a power-on reset pulse to keep the MCU_RST pin high, allowing the MCU to start normally. This achieves the effect of naturally disabling the watchdog function when programming or upgrading the MCU software.
[0074] During normal operation, the MCU continuously outputs a watchdog signal, the watchdog boost module 110 generates a high-voltage control signal, the inverting module 120 outputs a low level, and the reset signal output module 130 keeps the MCU_RST pin at a high level, so the MCU is running normally.
[0075] During the fault reset phase, the MCU loses the watchdog signal, the high voltage control signal of the watchdog boost module 110 disappears, the inverting module 120 outputs a brief high-level pulse, the reset signal output module 130 converts the pulse into a reset pulse and outputs it to the MCU_RST pin, and the MCU is reset.
[0076] Based on the above implementation, this disclosure also provides an MCU-based control system, which includes an MCU and the hardware watchdog circuit described above. The MCU's feed signal pin is connected to the input of the feed boost module 110 of the hardware watchdog circuit, and the MCU's reset pin is connected to the output of the reset signal output module 130 of the hardware watchdog circuit. Under normal operating conditions, the MCU periodically sends a feed signal to the hardware watchdog circuit. The hardware watchdog circuit does not trigger a reset when the feed signal is normal. When an MCU malfunction causes the feed signal to be lost, the hardware watchdog circuit sends a reset pulse to the MCU's reset pin, causing the MCU to restart. This control system can be applied to various applications requiring high reliability and low cost, including but not limited to home appliance control boards, industrial control modules, intelligent sensor nodes, and power management units.
[0077] In summary, this disclosure provides a hardware watchdog circuit and an MCU-based control system. The hardware watchdog circuit includes a watchdog boost module, an inverting module, and a reset signal output module. The input of the watchdog boost module is connected to the watchdog signal pin of the MCU to receive the watchdog signal output by the MCU, and its output is connected to the control terminal of the inverting module. The output of the inverting module is connected to the control terminal of the reset signal output module. The output of the reset signal output module is used to connect to the reset pin of the MCU. When the MCU is powered on, the watchdog boost module outputs a low level. After the inverting module controls the reset signal output module to reset, it keeps the reset pin at a high level to enable the MCU to start normally or enter the software programming state. When the MCU starts normally and outputs the watchdog signal, the watchdog boost module boosts the watchdog signal and outputs a high-voltage control signal. The inverting module responds to the high-voltage control signal to control the reset signal output module to keep the reset pin at a high level. When the MCU fails and the watchdog signal is lost, the high-voltage control signal of the watchdog boost module disappears, and the inverting module controls the reset signal output module to output a reset pulse to the reset pin to reset the MCU. By utilizing the watchdog boost module, inverting module, and reset signal output module provided in this disclosure, a watchdog circuit can be constructed using discrete components, replacing the traditional watchdog chip. This eliminates the need for expensive chips in the hardware watchdog circuit, significantly reducing overall costs. Furthermore, since the hardware watchdog circuit requires no additional operations during production programming and field upgrades, it eliminates the need to disable the watchdog reset function during software programming, thus significantly reducing production complexity and field maintenance costs.
[0078] The above description is merely a preferred embodiment of this disclosure and is not intended to limit this disclosure. Various modifications and variations can be made to this disclosure by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
[0079] It will be apparent to those skilled in the art that this disclosure is not limited to the details of the exemplary embodiments described above, and that this disclosure can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of this disclosure is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within this disclosure. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A hardware watchdog circuit, characterized in that, The hardware watchdog circuit includes: The dog-feeding boost module has its input connected to the dog-feeding signal pin of the MCU to receive the dog-feeding signal output by the MCU, and its output connected to the control terminal of the inverting module. The inverter module's output is connected to the control terminal of the reset signal output module. A reset signal output module, the output of which is connected to the reset pin of the MCU; wherein, When the MCU is powered on, the dog feed boost module outputs a low level, and the inverting module controls the reset signal output module to reset, and then keeps the reset pin at a high level so that the MCU can start normally or enter the software programming state. When the MCU starts normally and outputs the watchdog signal, the watchdog boost module boosts the watchdog signal and outputs a high-voltage control signal. The inverter module responds to the high-voltage control signal to control the reset signal output module to keep the reset pin at a high level. When the MCU malfunction causes the watchdog signal to be lost, the high voltage control signal of the watchdog boost module disappears, and the inverting module controls the reset signal output module to output a reset pulse to the reset pin to reset the MCU.
2. The hardware watchdog circuit according to claim 1, characterized in that, The dog-feeding booster module includes: The push-pull unit has its control terminal connected to the dog-feeding signal pin; A voltage multiplier unit, connected to the push-pull unit, is used to multiply the dog-feeding signal to generate the high-voltage control signal; The voltage divider unit is connected between the output terminal of the voltage multiplier unit and the control terminal of the inverting module.
3. The hardware watchdog circuit according to claim 2, characterized in that, The push-pull unit includes a P-type switch, a first N-type switch, a first resistor, and a second resistor. The control terminals of the P-type switch and the first N-type switch are both connected to the dog feed signal pin. The first terminal of the P-type switch is connected to the power supply. The second terminal of the P-type switch, the first resistor, the second resistor, and the first terminal of the first N-type switch are connected in sequence. The second terminal of the first N-type switch is grounded. The voltage multiplier unit is connected at the midpoint between the first resistor and the second resistor.
4. The hardware watchdog circuit according to claim 2, characterized in that, The voltage multiplier unit includes a first capacitor, a second capacitor, and a diode assembly. One end of the first capacitor is connected to the push-pull unit, and the other end of the first capacitor is connected to both the diode assembly and one end of the second capacitor. The other end of the second capacitor is connected to the diode assembly. The diode assembly is also connected to the voltage divider unit and a power supply. The two switching transistors in the push-pull unit are alternately turned on under the pulse drive of the dog-feeding signal, causing the first capacitor and the second capacitor to charge and discharge sequentially, thereby multiplying the voltage of the dog-feeding signal.
5. The hardware watchdog circuit according to claim 4, characterized in that, The diode assembly includes a first diode, a second diode, a third diode, and a fourth diode. The anode of the first diode is connected to a power supply. The cathode of the first diode is connected to the other end of the first capacitor and the anode of the second diode. The cathode of the second diode is connected to the anode of the third diode. The cathode of the third diode is connected to the other end of the second capacitor and the anode of the fourth diode. The cathode of the fourth diode serves as the output terminal of the voltage multiplier unit and is connected to the voltage divider unit.
6. The hardware watchdog circuit according to claim 2, characterized in that, The voltage divider unit includes a third resistor and a fourth resistor. One end of the third resistor and the fourth resistor connected in series is connected to the voltage multiplier unit, and the other end is grounded. The midpoint between the third resistor and the fourth resistor is connected to the control terminal of the inverting module.
7. The hardware watchdog circuit according to claim 2, characterized in that, The dog-feeding boost module also includes a fifth resistor, one end of which is connected to the control terminal of the push-pull unit, and the other end of which is grounded.
8. The hardware watchdog circuit according to claim 1, characterized in that, The inverting module includes a sixth resistor and a second N-type switch. The control terminal of the second N-type switch is connected to the output terminal of the dog-feeding boost module. The first terminal of the second N-type switch is connected to the power supply through the sixth resistor, and the second terminal of the second N-type switch is grounded. The first terminal of the second N-type switch is also connected to the control terminal of the reset signal output module.
9. The hardware watchdog circuit according to claim 1, characterized in that, The reset signal output module includes a third N-type switch, a seventh resistor, an eighth resistor, a ninth resistor, and a third capacitor. The control terminal of the third N-type switch is connected to one end of the third capacitor, the seventh resistor, and the eighth resistor, respectively. The other ends of the third capacitor and the seventh resistor are connected to the inverting module. The eighth resistor is grounded. The first end of the third N-type switch is connected to the power supply through the ninth resistor, and the first end of the third N-type switch is also connected to the reset pin of the MCU. The second end of the third N-type switch is grounded.
10. A MCU-based control system, characterized in that, The MCU-based control system includes a hardware watchdog circuit as described in any one of claims 1 to 9.