Managing a ring buffer-like memory
A data structure with an erase counter and log entries addresses the challenge of managing ring buffers on unreliable storage media by ensuring data integrity and preventing erroneous operations in automotive control units.
Patent Information
- Application Number
- DE102023213337
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-03
AI Technical Summary
Existing event data acquisition systems in automotive control units face challenges in managing multiple ring buffers on unreliable physical storage media, particularly flash memory, due to issues with data integrity and robustness across power outages and ignition cycles, leading to incorrect data interpretation and erroneous operations.
A data structure and method for managing ring buffers with an erase counter, CRC value, and log entries to ensure data integrity by maintaining the logical start and end of the buffer, and restoring the state of the buffer after power failures, using a logical memory model that includes a log to track changes and ensure valid data storage.
Ensures robust and fail-safe management of ring buffers across power outages and ignition cycles, preventing incorrect data interpretation and erroneous operations by maintaining data integrity and ensuring valid data storage.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The present invention relates to a data structure for managing ring memory, corresponding methods for managing and computer programs, machine readable storage media and devices.Prior ArtModern vehicle controllers are complex interconnected systems. While much effort is being expended in developing such systems according to high quality standards, failures are not excluded. This requires data acquisition in the event that the system goes somewhat obliquely, so that all the required information is available for analysis and product improvement. In some cases, such event data acquisition systems are legally or equitably prescribed according to automotive standards.Event data acquisition systems in the automotive sector are typically characterized by the following properties:These systems are typically designed as a dominant design driver at low hardware cost per unit. As a result, the physical storage medium used to store the data is selected mainly due to the low price point, which implies limited hardware properties of the storage medium, in particular in terms of robustness and reliability. The necessary robustness must then be built up in the software.Event data acquisition systems typically hang up new event data at the end, store a series of legacy records, and eventually overwrite or delete even legacy data. This results in a ring memory type write pattern. Updates of already written data, on the other hand, are not a typical data change scenario.Depending on the application, several of these "ring memories" can be kept in parallel for different types of data, different storage intervals, etc.Disclosure of the InventionThe problem underlying this invention is to provide other software layers with a memory model that makes it possible to manage multiple ring memories in a robust and fail-safe manner despite an unreliable physical storage medium.The logical memory model provides a series of ring memories (engl. Ring Buffer).• Each ring memory comprises a number of physically adjacent blocks of the physical storage medium. All the blocks of all the ring memories have the same size, since this size depends on the hardware of the physical storage medium. A block in a ring memory is either deleted or used.• A block may be used to store a fixed number of records.• The data sets are stored in so-called slots. The number of slots per block is fixed for each ring memory. In other words, all slots of a ring memory consist of the same number of bytes. If the size of a slot is not a multiple of the block size, then unused bytes (so-called waste bytes) occur at the end of each block of the ring memory.• Each ring memory has an erase counter which indicates the number of times the ring memory has already been erased, i.e. the number of times the last memory slot has already been written to and has been started again at the first memory slot.Against this background, the present invention provides a data structure for managing at least one ring memory for a physical storage medium, in particular for a flash memory storage medium, wherein the at least one ring memory has a specific number of blocks and each block from a specific number of slots, wherein the ring memory has an erase counter, wherein the data structure has an entry for each of the at least one ring memories, wherein the entry has an identification value of the respective ring memory, a value for the erase counter of the ring memory, a value for the last erased block of the respective ring memory, a value for the last used block of the ring memory, a value for the last used slot in the last used block.According to an embodiment of the data structure according to the present invention, the entry of the data structure further comprises a value for the integrity of the entry.This value may be a CRC valueAccording to an embodiment of the data structure according to the present invention, the data structure itself comprises a ring memory-like structure, but is not itself part of the ring memory managed by it.Although the implementation of a circular buffer structure is simple, the challenge is to manage, maintain, and restore the state of the circular buffers, particularly the location of the logical beginning and end of the circular buffer.If the start and end of a circular buffer are incorrectly initialized at the start of the controller (which typically coincides with the start of the vehicle), the contents of the circular buffer are incorrectly interpreted: valid data is lost, invalid data is incorrectly read as valid data, and further writes may be erroneously performed without intermediate erasure, since the physical storage medium requires overwriting already written bytes.More specifically, the challenge is: 1. securing the information on which blocks the ring memories have been successfully cleared and over ignition cycles and power dropouts. 2. safeguarding the information about which slots of which blocks have already been used and that over ignition cycles and power failures. In the present case, "used" can be understood to mean that a writing operation has been attempted. This does not necessarily mean that the corresponding bytes have been successfully written. However, even if only the attempt was made to write a byte, the byte must not be rewritten without first deleting its block. Therefore, after a failed write operation, the next call must write "attach new record" to a new slot. 3. Provided that the data structure for managing the ring memories and the ring memories themselves are stored on the same physical storage medium.The present invention does not provide a solution to ensure the validity of the records stored in the ring memories. In an application system incorporating the present invention, this problem would be overcome by higher-level software layers.Based on the data structure described above, the invention provides the following methods for solving the addressed challenges.For the management of a ring storage system comprising at least one ring storage, the present invention provides a data structure according to the present invention per ring storage of the ring storage system. The data structures together form the so-called log (log) of the ring storage system.When the state of a ring memory of the managed ring memory system is changed, a log entry is attached to the end of the log. By means of these log entries, the present invention provides a method for restoring all ring memories of the ring memory system in that the method reads out the log in the reverse sequence from the last log entry and restores the ring memories of the ring memory system as a function of the read-out data.A change in the state of the ring memory system can be made by carrying out an erase operation. In the case of a clearing process in a ring memory of the ring memory system, a log entry to the log takes place after a clearing process on a block of a ring memory of the ring memory system.This log entry documents that the erase operation was successful and the controller was still functioning, so that the controller could still write the log entry. If the log entry is missing or inconsistent, then block is not deemed deleted. In this case, the block must be deleted again before records can be written to the block.Thus, the log entry allows the ring storage system to restore the ring storage to its logical start and prevents the system from writing a record to the block even though the block has not been securely deleted.In this method, it may happen that although the one block in the ring memory of the ring memory system successfully deletes it, the corresponding log entry is not successfully written by an error.For example, the ring memory could be used in a control device of the automotive sector and the control device fails due to a fault or accident.In such a case, the block is erroneously assumed not to be erased and is again erased without cause. Such behavior is acceptable and we balanced by the advantages otherwise associated with the invention.A change of the state of the ring storage system can be made by writing a data record into a slot of a block of the ring storage of the ring storage system. In such a case, a new log entry is added to the log before the record is written to the slot of the block of the ring memory.This log entry documents that the logical end of the ring memory has been changed and possibly the attempt has been made to write a record to the slot. The log entry allows the system to restore the logical end of the ring memory and prevents the system from rewriting a record in the slot without clearing the block in which the slot resides therebetween.A change in the state of the ring storage system can be made by deleting a block of the ring storage of the ring storage system. In such a case, a new log entry is appended to the log after the first block of the ring memory has been successfully deleted. This log entry documents that the ring memory clear counter has been incremented. With this log entry, the system can restore the ring memory clear counter.Note that the controller may crash between the block erase and the log entry write. There are two alternative ways to deal with this case: a. The system may in this case lose the information that the clear counter has been incremented. This is okay because the clear counter does not need to be 100% accurate in such an extremely unlikely error situation. b. The log entry via the incremental clear counter can be combined with the log entry appended to the log anyway after the block has been deleted (see above). As described above, the system would re-delete the block if no log entry about the deletion is found, and in this case, it also repeats the log entry, including incrementing the deletion counter.The above-described methods log these to changes of state of a ring memory. In the event that, for example, after a restart, the state of a ring memory is to be restored, the backup of the contents of the ring memory at the time of the state change would also be necessary. However, if all the contents of a ring memory or even the entire ring memory system were backed up each time a state change occurs, this would require a large amount of storage space. Therefore, the present invention proposes to save the entire contents of a ring memory or of the ring memory system only at certain selected times. Between these times, the storage of the difference from the previous storage state, and therefore exactly the change in content, would be effected with the change in state.The times at which a complete content of a ring memory or of the ring memory system should be saved can be defined in various ways. In practice, it appears to save full state when a new block is started in the ring memory in which the log is stored. In this way, the state of a ring memory or ring memory system can always be restored from a single block of the protocol.A further aspect of the present invention is a computer program which is set up to carry out all the steps of the method according to the present invention.A further aspect of the present invention is a machine-readable storage medium on which the computer program according to the present invention is stored.A further aspect of the present invention is an electronic control unit which is configured to carry out all the steps of the method according to the present invention.Embodiments of the invention are explained in more detail below with reference to the attached drawings. In the drawings, there are shown: FIG. 1 is a block diagram of a vehicle controller; FIG. 2 is a schematic diagram of the logical memory model; FIG. 3 is a flow chart of a method for restoring a ring memory; FIG. 4 is a flow diagram of a method for clearing an entry in a ring memory; FIG. 5 is a flow diagram of a method for adding an entry to a ring memory.FIG. 1 shows a block diagram of a vehicle control device 10.The block diagram represents only a part of the typical constituent elements of a vehicle control device 10.The diagram shows a physical storage medium 11 on which the data structure according to the present invention may be stored. The physical storage medium 11 may be a storage medium 11 of flash memory technology, for example a NOR flash storage medium.The storage medium 11 is connected to a computing unit 12 which is suitable, for example, for carrying out the methods according to the present invention.The physical storage medium 11 may be organized into fixed-size blocks. The block size may be, for example, 4 Kb.The physical storage medium 11 may be configured such that it can be deleted only block by block. In this case, a block-by-block erasure can result in all bytes of the block being occupied with a value which represents the state "erased". Such a value may be 255 or 0×FF.The physical storage medium 11 can be written byte by byte. In this case, a write operation sets only the desired bits from 1 to 0. The 1-bits in the data to be written are already 1 from the last erase. Resetting a bit from 0 to 1 is possible only by deleting the entire block.The order of changes to a particular byte must be strictly erase → write → erase. Adding more 0-bits to a byte, i.e. first writing 0×FE and then writing 0×FC to the same location, is not allowed without intermediate erasure of the entire block.The physical storage medium 11 can be read byte by byte.A write or erase operation may fail. It cannot be assumed that after such a process, the state of the bytes or block concerned is actually as expected.In particular, the power supply may fail and a write or erase operation may be only partially completed. In addition, it is unpredictable whether a particular operation fails or is successful (even under certain conditions). Each write or erase operation must therefore be considered potentially failing.Failed write or erase operations may leave the bytes that were the subject of the operation in an undefined and unstable state. Bytes that were not the subject of the process are unaffected thereby.The only way to decide whether or not a write or erase operation to the physical storage medium was successful is to check the return status of the physical storage medium after completion of the operation. Writes or erases with unknown return status must be considered as failed. In particular, there is no reliable way to decide whether or not a write was successful, read back the written bytes and compare them to the original source. Also, it is not a reliable way to decide whether or not a block has been successfully deleted by comparing its content with 0×FF.In a storage medium 11 as shown above, erase operations are slow. A clear operation may take 0.2 seconds, for example. That is, it is likely that the erase operation of a block is interrupted by a power failure.The arithmetic unit 12 also has access to a working memory 13 in which method-specific data are stored. In the illustration, the arithmetic unit 11 and the working memory 13 are shown as separate blocks. It is conceivable that the working memory 13 is integrated into the computing unit 12. Not all data stored in the working memory are also stored in the data structure 11 and would be lost in the event of a failure of the power supply of the control unit 10. All relevant data for resuming the methods according to the present invention can be restored from the data stored in the storage medium 11.FIG. 2 shows a schematic representation of the logical memory model using the example of four ring memories (ring buffers). Ring buffer 0 has six blocks and provides three slots in each block. Ring buffer 1 has four blocks and provides one slot in each block. Ring buffer 2 has seven blocks and provides two slots in each block. Ring buffer 3 has three blocks, but none of them is currently used because its logical beginning (logical start) and end (logical end) both point to block 2.As seen in Figure 2, each ring memory has its own relative block numbering starting with block 0.The system maintains the state of each ring memory in main memory. The state of each ring memory comprises: 1. logical start: The block number of the first used block 2. logical end: The block number of the last used block and the slot number of the last used slot in this block 3. clear counterIf the block number of the logical beginning of a ring memory corresponds to the block number of the logical end, the ring memory is considered to be empty. That is, the ring memory contains only erased blocks, shown at ring buffer 3.In order to distinguish an empty ring memory from a fully used ring memory (wherein the block numbers of logical start and end would also be the same), it is provided according to the invention that not all blocks of a ring memory are used simultaneously. That is, each ring memory must have at least one erased block at any time.In the example shown, the ring buffer 1 would first have to delete block 2 before it can use block 1. Similarly, ring buffer 0 is able to store one record in slot 2 of block 5, then it must delete block 1 before being able to store another record.According to one embodiment, a ring memory system includes 32 ring memories, with up to 256 blocks per ring memory, up to 8 slots per block, a maximum clear counter of 65,536, and an eight-bit CRC. A log entry may be as shown in Table 1. In this case, a log entry may be stored in 6 bytes.Since a single log entry covers the full state of a ring buffer, a "delta" and the "total state" of all ring buffers are structurally identical. The entire state of all ring buffers is simply a concatenation of log entries, one for each ring buffer.0...1all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all allClear counters13442all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all alllast erased block23all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all allThe latter is the more recently used343...Most recently used040...Ring Memory Identifier25all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all all allCRC of bytes 0.. 448The above table illustrates an example of a serialized log entry with example values of the state of the ring memory 2 in Figure. 2FIG. 3 shows a flow diagram of a method 100 for restoring a ring memory according to the present invention.The method 100 comprises the step of reading 101 the values of a data structure according to the present invention. The data structure is part of a log entry of a log relating to the ring memory provided for restoration. The log entries are read 101 in particular in the reverse sequence to their creation.In detail, this may be implemented as follows.To restore the state of the ring memories of a ring memory system, the system reads and interprets the log entries from the last, i.e., latest, log entry. The system thereby carries out the following steps: 1. setting the restored ring memory identifier 2. setting a pointer to the last protocol entry 3. if this protocol entry completely consists of a value which identifies a deleted block, for example consists only of OxFF bytes, ignoring the protocol entry and continuing the method at step 10. reading the CRC value of the data structure of the protocol entry 5. checking the CRC value 6. in the case of a failed check of the CRC value, continuing the method at step 10. reading the ring memory identifier of the data structure of the protocol entry 8. if the read ring memory identifier corresponds to the restored ring memory identifier from step 1, That is, the state of the ring memory is already restored, continuing the method to step 10.9. copying the contents of the data structure of the log entry to the state of the ring memory to be restored. 10. If all ring memories of the ring memory system are successfully restored, end the method. Otherwise, if there are further log entries, the method continues to step 3.The hardware and storage infrastructure of the physical storage medium typically read the data in larger blocks. For example, the time required to read a single byte from the physical storage medium may be the same as the time required to read 120 bytes. In this case, the present invention contemplates reading as many bytes as possible from the physical storage medium without increasing the read time.FIG. 4 shows a flow diagram of a method 200 for clearing an entry in a ring memory. The ring memory comprises a block.The method comprises the steps of:Erase 201 the block of the ring memory and thereafterAdding 202 a log entry into a log, the log being associated with the ring memory, the log entry comprising a data structure according to the present invention.Within the scope of the present invention, it is assumed that the protocol always comprises the complete state of a ring memory or a ring memory system. Thus, the system can be initialized only from the last block of the protocol. Thus, older blocks of the log used can be deleted as soon as the entire state of the ring memory or ring memory system has been successfully written to the last block of the log.FIG. 5 shows a flow diagram of a method 300 for adding an entry to a ring memory. The ring memory comprises a block.The method comprises the steps of:adding 301 a log entry into a log, the log being associated with the ring memory, the log entry comprising one according to the present invention, and thereafter writing 302 a record in the slot of the block of the ring memory
Claims
A data structure for managing a ring memory for a physical storage medium, in particular for a flash memory storage medium, wherein the ring memory comprises a certain number of blocks and each block of a certain number of slots, wherein the ring memory comprises an erase counter, wherein the data structure comprises an identification value ring memory, a value for the erase counter of the ring memory, a value for the last erased block of the ring memory, a value for the last used block of the ring memory and a value for the last used slot in the last used block.Data structure according to claim 1, wherein the data structure has a value for the integrity of the entry, in particular a CRC value.The data structure according to claim 1 or 2, wherein the data structure itself comprises a ring memory-like structure, but is not itself part of the ring memory managed by it.Method (100) for restoring a ring memory, wherein the method restores the ring memory by reading (101) the values of the data structure, in particular in the reverse order from the last protocol entry, depending on a protocol consisting of at least one protocol entry, wherein the protocol entry comprises a data structure according to one of Claims 1 to 3.A method (200) for deleting an entry in a ring memory, the ring memory comprising a block, comprising the steps of: deleting the block of the ring memory and then adding a log entry to a log, the log being associated with the ring memory, the log entry comprising a data structure according to any one of claims 1 to 3.A method (300) of adding an entry to a ring memory, the ring memory comprising a block, the block comprising a slot, comprising the steps of: adding a log entry to a log, the log being associated with the ring memory, the log entry comprising a data structure according to any one of claims 1 to 3, and thereafter writing a record to the slot of the block of the ring memory.Computer program which is configured to carry out all the steps of a method (100, 200, 300) according to one of the preceding claims.A machine readable storage medium having stored thereon the computer program according to claim 7.Electronic control unit which is configured to carry out all the steps of a method according to one of Claims 1 to 6.