Managing a ring buffer-like memory

A data structure with a header and section fields manages ring buffer memory in vehicle event data systems, addressing power failure challenges by ensuring data integrity and simplifying recovery on flash storage media.

DE102023213338A1Pending Publication Date: 2025-07-03ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE102023213338
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing vehicle event data acquisition systems face challenges in preserving the state of a ring buffer memory during power failures without redundant storage, particularly when using storage media that do not allow multiple overwrites, such as NOR flash storage.

Method used

A data structure with a header containing control variables and section fields is implemented to manage a ring buffer, allowing for the detection of successfully erased blocks and ensuring the validity of data structures, even across power outages, using a flash memory storage medium.

Benefits of technology

The solution enables cost-effective preservation and restoration of the ring buffer state without additional storage, ensuring data integrity and simplifying the recovery process by using fixed, predefined values in the header fields.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Data structure for managing at least one ring buffer for a physical storage medium, in particular for a flash memory storage medium, wherein the data structure has a header and at least one section for storing management data, characterized in that the header has at least one field for a control variable and at least one field per section.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a data structure for managing a ring buffer-type memory, corresponding methods for managing it, as well as computer programs, machine-readable storage media and devices. State of the art

[0002] Modern vehicle control units are complex, interconnected systems. For analysis and improvement purposes, control units can be equipped with an event data recording system. In some cases, such event data recording systems are required by law or standards.

[0003] Vehicle event data acquisition systems typically have the following framework conditions: Log-structured write pattern: Event data acquisition systems typically append new event records, retain a set of older records, and overwrite or delete older or obsolete records. This results in a "circular buffer" write pattern. In-place updates, i.e., changes to previously written records, are not a typical data change scenario.

[0004] Small write operations: For the purposes of the present invention, it is assumed that the size of the data to be written at once is on the order of a few hundred bytes at most. This is not the case for all automotive data acquisition systems.

[0005] The ECU hardware on which the event data acquisition system is implemented can experience a power failure at any time without warning, for example, due to an accident involving a power interruption. While some ECUs have a power reserve (e.g., through capacitors in the ECU) to remain operational for at least a limited period of time and with at least a limited range of functions in the event of a power loss, e.g., due to an accident, the ECU may be busy with tasks that have a higher priority (e.g., airbag deployment) than data recording.

[0006] Under these conditions, the challenge now is to preserve or restore the state of the memory of the event data acquisition system, especially in the case of a "ring buffer-like" memory behavior, the position of the logical start and end of the ring buffer.

[0007] A classic approach to preserve or restore the state of the memory is to create redundant storage, for example on a second storage medium Disclosure of the invention

[0008] The object of the present invention is therefore to create a data structure that enables the preservation or recovery of the state of a memory of an event data acquisition system without the need for a second storage medium. This can be used to cost-effectively manufacture a correspondingly equipped vehicle control unit.

[0009] The challenges therefore lie in the following points.

[0010] Maintaining information about which blocks were successfully erased across firing cycles and power outages.

[0011] Particularly when using storage media whose technology does not allow multiple overwriting, such as NOR flash storage media, it is important to retain information about which bytes in which blocks a write operation was initiated on, even across firing cycles and power outages. This does not necessarily mean that the bytes were successfully written, but only that an attempt was made to write to a byte. The information about the attempt alone is sufficient to know that a second write attempt cannot be made for that byte without first erasing the byte.

[0012] Detecting blocks that have not been properly erased. Such blocks must not be read or written under any circumstances without first erasing the block.

[0013] Against this background, the present invention provides a data structure (block) for managing a ring buffer for a physical storage medium. Furthermore, the data structure comprises a header and at least one section (a multiple of 6 bytes) for storing management data.

[0014] The data structure according to the present invention is characterized in that the header has at least one field for a control variable (Erase Timestamp) and at least one field per section.

[0015] The physical storage medium can be a flash memory storage medium, such as a NAND or NOR flash storage medium.

[0016] The advantage of the data structure according to the present invention is that the validity, fill level and writable nature of the data structure can be easily determined based on the fields in the header of the data structure.

[0017] According to an embodiment of the data structure according to the present invention, the at least one field can assume only two valid values; including either a value representing the "deleted" state or a value representing the control variable of the header.

[0018] The advantage of this embodiment is that the validity of the data structure can be determined in a simple way.

[0019] According to one embodiment of the data structure according to the present invention, the header has at least one field for a status indication (Full State Flag).

[0020] The at least one field can indicate whether the data structure contains a data record that is suitable for restoring the managed ring buffer.

[0021] The advantage of this embodiment is that the usability of the data structure for restoring the managed ring buffer can be determined in a simple manner.

[0022] According to one embodiment of the data structure according to the present invention, the header has a fixed size.

[0023] According to one embodiment of the data structure according to the present invention, the data structure has a fixed size.

[0024] Fixed, predefined values have the advantage that there is no dynamic information—that is, no information that changes the data structure extensively during the system's runtime—and therefore no need to be stored and restored. This leads to a simplification of the data structure.

[0025] According to one embodiment of the data structure according to the present invention, the first of the at least one section is designed to accommodate a complete representation of the managed ring buffers.

[0026] The advantage of this implementation is that the managed ring buffer can be completely restored using a single data structure. This simplifies the recovery of the managed ring buffer.

[0027] Another aspect of the present invention is a method for deleting a data structure according to the present invention. The method comprises the following steps. Delete the entire data structure and then

[0028] Updating the data structure header.

[0029] The advantage of this aspect of the present invention is that the success of an erasure operation on an inherently unreliable physical storage medium can be easily verified.

[0030] Since, in case the update of the header of the data structure resulted in a valid date in the header, it can be assumed that the deletion procedure was successful.

[0031] Accordingly, the data structure is then prepared to receive new data.

[0032] If the header update has not occurred, i.e., the date in the header is either missing or inconsistent, i.e., not as expected, the data structure is considered invalid. This case also covers the subcase where the deletion of the data structure was completed successfully, but the header update failed. An invalid data structure is not ready to accept new data.

[0033] An invalid data structure can be prepared for re-incorporation of data by attempting to delete it again.

[0034] According to one embodiment of the method according to the present invention, in the step of updating the header is updated with an erasure timestamp (Erase Timestamp).

[0035] The advantage of this embodiment is that by updating the header with a timestamp of deletion, the validity of the data structure or the data in the data structure can be easily checked.

[0036] In this case, a deletion timestamp can be understood as a counter that is incremented each time a block is successfully deleted. The value of the current deletion timestamp can be stored in the control unit's RAM, meaning it is not mandatory to store the value in a non-volatile manner on the physical storage medium.

[0037] The timestamp of deletion plays a particular role when the data structure according to the present invention is integrated into a data structure system which, for example, consists of a plurality of data structures according to the present invention.

[0038] A fixed memory size, e.g., one byte, can be used for the deletion timestamps. If the control unit is running for a sufficiently long time, the deletion timestamp counter will overflow. The following boundary conditions apply to the overflow: 1. The overflow should occur long before the maximum unsigned integer value for the length of the deletion timestamp is reached (e.g., 255 or 0xFF for a byte). A deletion timestamp with the value 0xFF would be indistinguishable from a deleted data structure without a header. The Hamming distance between the largest valid deletion timestamp and the maximum unsigned integer for the counter length should be at least 1, but can be larger. 2. To simulate a strictly increasing sequence, a "<" relationship ("truly less" relationship) must exist on the deletion timestamps that works across overflows. According to this "<" relationship, a smaller integer value can represent the larger logical value, e.g., the integer value 0 after an overflow relative to the integer value 255. If the largest valid deletion timestamp is too small, a "<" relationship cannot work according to the present invention.

[0039] It has therefore proven advantageous if the number of valid deletion timestamps is at least twice as large as the number of data structures in the data structure system. 3. The number of valid erasure timestamps should be a prime number. This ensures that the bit patterns of the erasure timestamps assigned to a data structure over time vary significantly. This helps in cases where unstable bytes yield false values that appear to be valid erasure timestamps because they differ by only a few bits. The number of valid erasure timestamps must never be a multiple of the number of data structures. Using a prime number ensures this. n 0 1 2 3 ... 97 Block 0 0 32 64 96 ... 0 Block 1 1 33 65 0 ... 1 Block 2 2 34 66 1 ... 2 ... ... ... ... ... ... ... Block 30 30 62 94 31 ... 30 Block 31 31 63 95 32 ... 31

[0040] The table above shows the deletion timestamps using the example of 32 blocks, a deletion timestamp size of one byte and 97 deletion timestamps in the range 0 to 96.

[0041] The columns represent the number of deletions. The first column after the blocks shows the possible initial state.

[0042] Provided that the number of valid erasure timestamps is at least twice the number of blocks, a “<” relation is used to compare two erasure timestamps a and b as follows (π denotes the number of valid erasure timestamps; e.g., π = 97): a"<"b={a <b,|a−b|<π2a≥b, sonst

[0043] The table above clearly shows that the values repeat starting with the 98th entry (π = 97). This makes it clear that it makes sense to choose a prime number for n, since at π = 96 or 97, it takes several overflows before a block would legally receive the same erase timestamp again. This makes it very unlikely that corrupted bits will be mistakenly interpreted as correct values because they happen to match.

[0044] In conjunction with the requirement for continuous values between neighboring blocks, such a misinterpretation is even more unlikely.

[0045] For π = 123, there would be 123 overflows. For π = 128 (i.e., not a prime number and also a multiple of the block number of 32), there would be only 5 overflows.

[0046] The following table lists some example results of the "<" relation for π = 97. The "<" relation compares the difference between the deletion timestamps a and b for both scenarios, with and without overflow. The "<" relation corresponds to the relation given above with the smaller difference between the deletion timestamps. a b a "<" b 0 1 true 0 47 true 0 48 incorrect 0 96 incorrect 48 96 incorrect 49 96 true

[0047] For example, in the case of an overflow at value 97, the value 3 could be identical to the value 100. Consequently, (90 "<" 3) is true because the difference between 90 and 100 (with overflow) is smaller than the difference between 3 and 90 (without overflow).

[0048] Another aspect of the present invention is a method for adding a datum to a data structure according to the present invention. The method comprises the following steps.

[0049] Updating the header of the data structure and then appending the date to at least one section of the data structure.

[0050] The advantage of this aspect of the present invention is that it can easily trace any attempt to add a datum to the data structure on an inherently unreliable physical storage medium.

[0051] For this reason, the header of the data structure is first updated. This update indicates that an attempt to add the data has at least begun.

[0052] Updating the header cannot be used to indicate the successful addition of the date. This would have to be ensured by additional methods, possibly by higher-level software layers, and is outside the scope of the present invention.

[0053] The corresponding area of the data structure is then locked for further addition attempts, regardless of whether the addition procedure was actually carried out successfully.

[0054] Furthermore, by updating the header of the data structure, the position of the logical end of the memory area of the present data structure can be determined.

[0055] To document attempts to write data to specific parts of the data structure, the portion of the block remaining after the header can be divided into a number of sections. The number of sections can be statically configured; at least one section must be present. The sections can be of the same size. For example, a block can be divided into 32 equal sections. The more blocks provided, the more detailed the documentation of write attempts and the smaller the waste can be. Conversely, the header becomes larger, and write time may increase.

[0056] For each section, there may be a corresponding field in the header, the so-called section marker. This field can be one byte in size. After the data structure has been erased, all section markers carry a value indicating the "erased" state, for example, the value 0xFF. Before any byte in a section is written, the section containing that byte must be "activated" by writing the block's erasure timestamp to the corresponding section marker. Since the logical memory model only allows data to be appended to the end of the data structure's memory area, the sections of a block can only be activated in ascending order.

[0057] The section markers can be used for further consistency checks: 1. A section marker can have only two valid values: a value indicating the "deleted" state, for example, 0xFF, and the erasure timestamp of the data structure. If any other value is found in a section marker, the corresponding section is considered invalid. 2. There must be a sequence of 0 or more section markers containing the block's erasure timestamp, followed by a sequence of 0 or more section markers containing the value 0xFF. Any other combination will invalidate the entire block.

[0058] The table below contains some example headers to illustrate the section markers. Timestamp of deletion Sec. 0 Section 1 Section 2 Section 3 0 0 0 0 0 All sections activated 11 11 255 255 255 1. Section activated 22 255 255 255 255 No section activated 33 255 33 33 33 Section 0 is invalid 44 255 255 199 255 Section 2 is invalid

[0059] The data structure of the present invention solves, among other things, the task of restoring the managed ring buffers. The steps required for such a restoration are described below.

[0060] When the vehicle control unit boots up (e.g., during vehicle ignition), the state of the managed ring buffers must first be restored before the ring buffers can be used. To restore the state, the headers of all data structures in the data structure system must be read and interpreted. In this context, the following information must be extracted. 1. The block number of the first block used. This indicates the logical beginning of the circular buffer. This is the block that, of all blocks with at least one activated section, has the smallest erasure timestamp according to the above "<" relation. 2. The block number and section that indicate the logical end of the circular buffer. Of all blocks that have at least one active section, this is the block with the largest erasure timestamp, according to the "<" relation. 3. The current value of the deletion timestamp, which is stored in memory for use in the next deletion operation. 5. A list of block numbers that are considered invalid. These blocks must be erased before they can be used.

[0061] A further aspect of the present invention is a computer program which is arranged to carry out all steps of the method according to the present invention claims.

[0062] Another aspect of the present invention is a machine-readable storage medium on which the computer program according to the present invention is stored.

[0063] A further aspect of the present invention is an electronic control unit configured to carry out all steps of the method according to the present invention.

[0064] Embodiments of the invention are explained in more detail below with reference to the accompanying drawings. In the drawings: Fig. 1 a block diagram of a vehicle control unit; Fig. 2 a block diagram of a logical memory model; Fig. 3 is a block diagram of an embodiment of a data structure according to the present invention; Fig. 4 is a flowchart of an embodiment of the method for deleting the data structure according to one aspect of the present invention; Fig. 5 is a flowchart of an embodiment of the method for adding a date to the data structure according to one aspect of the present invention;

[0065] Fig. 1 shows a block diagram of a vehicle control unit 10.

[0066] The block diagram shows only a part of the typical components of a vehicle control unit 10.

[0067] The diagram shows a physical storage medium 11 on which the data structure according to the present invention can be stored. The physical storage medium 11 can be a storage medium 11 using flash memory technology, e.g., a NOR flash storage medium.

[0068] The storage medium 11 is connected to a computing unit 12 which is suitable, for example, for carrying out the methods according to the present invention.

[0069] The physical storage medium 11 can be organized into fixed-size blocks. The block size can be, for example, 4 KB.

[0070] The physical storage medium 11 can be configured such that it can only be erased block by block. Block-by-block erasure can result in all bytes of the block being assigned a value that represents the "erased" state. Such a value can be 255 or 0xFF.

[0071] The physical storage medium 11 can be written to byte by byte. A write operation only sets the desired bits from 1 to 0. The 1 bits in the data to be written are already 1 from the last erasure. Resetting a bit from 0 to 1 is only possible by erasing the entire block.

[0072] The order of changes to a given byte must be strictly delete -> write -> delete. Adding additional 0 bits to a byte, i.e., first writing 0xFE and then writing 0xFC to the same location, is not allowed without first erasing the entire block.

[0073] The physical storage medium 11 can be read byte by byte.

[0074] A write or delete operation may fail. It cannot be assumed that the state of the affected bytes or block will actually be as expected after such an operation.

[0075] In particular, the power supply may fail, and a write or erase operation may only be partially completed. Furthermore, it is unpredictable whether a particular operation will fail or succeed (even under certain conditions). Therefore, every write or erase operation must be considered potentially failing.

[0076] Failed write or delete operations can leave the bytes that were the subject of the operation in an undefined and unstable state. Bytes that were not the subject of the operation are unaffected.

[0077] The only way to determine whether a write or erase operation to the physical storage medium was successful or not is to check the return status of the physical storage medium after the operation is complete. Write or erase operations with an unknown return status must be considered failed. In particular, reading back the written bytes and comparing them with the original source is not a reliable way to determine whether a write operation was successful or not. Likewise, comparing its contents to 0xFF is not a reliable way to determine whether a block was successfully erased or not.

[0078] With a storage medium 11 as shown above, erasure operations are slow. For example, an erasure operation may take 0.2 seconds. This means that the erasure of a block is likely to be interrupted by a power failure.

[0079] The computing unit 12 also has access to a working memory 13 in which process-specific data is stored. In the illustration, the computing unit 11 and the working memory 13 are shown as separate blocks. It is conceivable that the working memory 13 is integrated into the computing unit 12. Not all data stored in the working memory is also stored in the data structure 11 and would initially be lost in the event of a power failure of the control unit 10. All relevant data for resuming the processes according to the present invention can be restored from the data stored in the storage medium 11.

[0080] Fig. 2 shows a block diagram of a logical memory model of a data structure system 20 comprising a data structure 21, 22, 23, 24, 25 to n according to the present invention.

[0081] The data structure system 20 is suitable for offering the overlying layers in a software system a logical memory model that behaves like a ring buffer.

[0082] The present invention makes it possible to offer a robust and fail-safe storage model on an inherently unreliable storage medium 11.

[0083] The Fig. The memory model shown in Figure 2 can, in one embodiment, offer the following functions (primitives) to the overlying software layers. Initialize

[0084] Restores the state of the managed ring buffer, specifically the position of the logical start and end of the ring buffer. Query available bytes

[0085] Reports how many bytes can still be appended to the block. Attach

[0086] Appends the data to the logical end of the circular buffer. The amount of data must not exceed the available storage space at the end of the block. Start new block

[0087] Moves the logical end of the ring buffer to the beginning of the next block. If the next block is not ready, e.g., has not yet been deleted, it is first prepared, e.g., deleted. If the previous logical end of the ring buffer was in the last block of the memory area of the physical storage medium 11 assigned to the data structure system, the logical end ("next block") becomes the first block of the memory area of the physical storage medium assigned to the data structure system. Delete next block

[0088] Deletes the block at the logical beginning of the ring buffer and sets the logical beginning to the beginning of the next block. If the previous logical beginning of the ring buffer was in the last block of the memory area of the physical storage medium 11 assigned to the data structure system, the logical beginning ("next block") becomes the first block of the memory area of the physical storage medium assigned to the data structure system. To read

[0089] Returns the desired number of bytes stored at a specific position between the logical start and end of the circular buffer. Clean up

[0090] Deletes the blocks identified as valid. If there are no such blocks, nothing is done. The set of blocks considered invalid is internal information stored in memory and may not be visible to other software layers.

[0091] The data structure system 20 consists of a number of n blocks 21, 22, 23, 24, 24, 25 to n, which are located in an area of the physical storage medium 11 assigned to the data structure system 20. The assigned area can be a contiguous area in the physical storage medium. It is conceivable that the blocks of the data structure system 20 represent blocks of the physical storage medium 11 in the same order. Each block represents a data structure 21, 22, 23, 24, 24, 25 according to the present invention.

[0092] Blocks 21 and n are shown without any padding. This indicates that these blocks 21, n are marked as erased. This may mean that all bytes assigned to the respective block 21, n have the value 0xFF.

[0093] Blocks 22, 23, and 24 are shown with hatched fill. This indicates that these blocks are marked as occupied. Changing the data stored in these blocks or appending data is not possible.

[0094] Block 25 is represented by a dotted line. This indicates that the current logical end of the ring buffer is located in this block. Changing the data stored in this block is not possible. When the "Append" function is called, the data to be appended is appended to this block – provided the block still has sufficient storage space (see above).

[0095] Blocks 21, 22, 23, 24, 24, 25 may have a predetermined size. The blocks may occupy 11 consecutive storage locations on the physical storage medium.

[0096] Fig. Figure 3 shows a block diagram of an embodiment of a data structure according to the present invention.

[0097] Fig. 3 shows on the left a data structure system 20 as in Fig. 2 explained.

[0098] In the middle shows Fig. 3 shows a detailed view of block 25; representative of the other data blocks 21, 22, 23, 24 to n of the illustrated data structure system 20. Block 25 has a structure according to the data structure of the present invention. Block 25 has a header 251 and at least one section 252a, 252b, 252c to 252n.

[0099] Right shows Fig.3 shows a detailed view of header 251 of block 25 of data structure system 20. Header 251 includes at least one field 2511 for a control variable and at least one field 2513a, 2513b to 2513n for each section 252a, 252b, 252c to 252n of data structure 25 according to the present invention. Furthermore, the illustrated header includes at least one field 2512 for a status indication.

[0100] Fig. 4 shows a flowchart of an embodiment of the method for deleting the data structure according to one aspect of the present invention.

[0101] In step 401 the entire data structure is deleted and only then is the header of the data structure updated in step 402.

[0102] The method can be implemented in such a way that the data structure is represented by a memory block of the physical storage medium. In the case of a flash memory storage medium, particularly a NOR flash storage medium, erasure occurs by filling all bytes of the memory block to the value 0xFF, i.e., with ones ("1").

[0103] With a flash memory storage medium, this process can take a comparatively long time, for example, up to 0.2 seconds.

[0104] Only when the physical storage medium indicates the completion of the deletion process is step 402 executed, in which the header 251 of the data structure 25 is updated. The header 251 is updated by filling at least one field for a control variable with the current value of a timestamp for the deletion.

[0105] Fig.5 shows a flowchart of an embodiment of the method for adding a date to the data structure according to one aspect of the present invention.

[0106] In step 501, the header of the data structure is updated and only then, in step 502, data to be appended is appended to the at least one section of the data structure 25.

[0107] Updating the header 251 of the data structure 25 is only necessary if a new section needs to be “activated” for appending.

[0108] If the remaining space in the current section to be written is sufficient, the data to be appended can be appended at the position of the logical end of the ring buffer-like memory without having to “activate” a new section.

[0109] In both cases, the logical end of the ring buffer is moved to the end of the appended data.

Claims

[1] Data structure for managing at least one ring buffer for a physical storage medium, in particular for a flash memory storage medium, wherein the data structure has a header and at least one section for storing management data, characterized by that the header has at least one field for a control variable and at least one field for each section. [2] The data structure of claim 1, wherein the at least one field can only take two valid values, either a value representing the value 0 or a value representing the control variable of the header. [3] Data structure according to claim 1 or 2, wherein the header has at least one field for a status indication. [4] Data structure according to one of the preceding claims, wherein the header has a fixed size. [5] Data structure according to one of the preceding claims, wherein the data structure has a fixed size. [6] Data structure according to one of the preceding claims, wherein the first of the at least one section is designed to receive a complete representation of the managed ring buffers. [7] A method for deleting a data structure according to any one of claims 1 to 6, comprising the steps of: a. Delete the entire data structure and then b. Updating the header of the data structure. [8] The method of claim 7, wherein in the step of updating the header is updated with a timestamp of deletion. [9] A method for adding a date to a data structure according to any one of claims 1 to 6, comprising the steps of: a. Updating the header of the data structure and then b. Appending the date to at least one section of the data structure. [10] Method according to claim 9, wherein in the step of updating the header is updated as a function of the control variable of the header, in particular wherein the field of the header corresponding to the section is updated as a function of the control variable, in particular with the control variable. [11] Computer program which is arranged to carry out all the steps of a method according to one of the preceding claims. [12] A machine-readable storage medium on which the computer program according to claim 11 is stored. [13] Electronic control unit which is arranged to carry out all steps of a method according to one of claims 1 to 10.