NTB in vehicles

The system addresses the challenge of connecting independent PCIe domains by using a PCIe switch with ATUs for direct memory transactions and redundant switches, enhancing communication efficiency and safety in motor vehicles.

DE102024206403A1Pending Publication Date: 2026-01-08ZF FRIEDRICHSHAFEN AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102024206403
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-08
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Existing PCIe architectures do not inherently support the connection of two independent PCI domains, limiting communication and scalability in motor vehicle environments.

Method used

A system comprising a PCIe switch connected to system-on-a-chips (SoCs) with address translation units (ATUs) for translating address spaces and enabling direct memory transactions between SoCs without CPU intervention, utilizing shared components like buffers and doorbell registers, and supporting redundant switches for fault tolerance and security features.

Benefits of technology

Enables efficient, scalable, and secure communication between independent PCIe domains with reduced latency and increased throughput, ensuring uninterrupted operation and enhanced safety through redundancy and security mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A system (20; 30; 40; 50; 60) for enabling non-transparent bridging, hereinafter referred to as NTB, in a motor vehicle environment, comprising the following: at least one PCIe switch (5), a first system-on-a-chip (3), hereinafter referred to as SoC 1, connected to the PCIe switch, and a second system-on-a-chip (4), hereinafter referred to as SoC 2, connected to the PCIe switch; wherein the PCIe switch contains hardware components for a buffer; where SoC 1 contains the following: a PCIe interface and a memory containing the following: a memory window shared with SoC 2, and a PCIe base address register containing a base address of a cache in the PCIe switch and a base address of a memory window of the SoC 2; where SoC 2 contains the following: a PCIe interface and a memory containing the following: a memory window shared with SoC 1, and a PCIe base address register containing a base address of a cache in the PCIe switch and a base address of a memory window of the SoC 1; to enable communication between SoC 1 and SoC 2; and further comprising a first address translation unit, hereinafter referred to as ATU 1, which is assigned to SoC 1, and a second address translation unit, hereinafter referred to as ATU 2, which is assigned to SoC 2, for translating address spaces between SoC 1, SoC 2 and the PCIe switch, such that ATU 1 and ATU 2 enable memory transaction packets to flow between SoC 1 and SoC 2, in particular without CPU intervention.
Need to check novelty before this filing date? Find Prior Art

Description

AREA OF REVELATION

[0001] The present invention relates to a system and a method for enabling non-transparent bridging (NTB) in a motor vehicle environment. BACKGROUND

[0002] NVIDIA, “NVIDIA DRIVE OS 5.1 Linux SDK - Non-Transparent Bridging and PCIe Interface Communication,” NVIDIA, 2024. [Online]. Available at: https: / / docs.nvidia.com / drive / drive os 5.1.6.1 L / nvvib docs / index.html#paqe / DRIVE OS Linux SDK Development Guide / System%20Programming / sys components non transparent bridging.html, describes a PCI Express architecture model (PCIe architecture model) that supports a single root complex, where all devices connected to it, including the endpoints (EPs), share a common address space.

[0003] However, in many scenarios there is a need to connect two independent PCI domains, which the standard PCIe model does not inherently support. SUMMARY

[0004] Accordingly, the present invention solves the problem of connecting two or more independent PCIe domains in a motor vehicle environment.

[0005] Accordingly, the following will be provided: - a system for enabling non-transparent bridging, hereinafter referred to as NTB, in an automotive environment, comprising: at least one PCIe switch, a first system-on-a-chip, hereinafter referred to as SoC 1, connected to the PCIe switch, and a second system-on-a-chip, hereinafter referred to as SoC 2, connected to the PCIe switch; wherein the PCIe switch includes hardware components for a buffer; wherein SoC 1 includes a PCIe interface and memory, comprising a memory window shared with SoC 2, and a PCIe base address register, comprising a base address of a buffer in the PCIe switch and a base address of a memory window of SoC 2;wherein SoC 2 includes a PCIe interface and memory comprising a memory window shared with SoC 1 and a PCIe base address register containing a base address of a buffer in the PCIe switch and a base address of a memory window of SoC 1; to enable communication between SoC 1 and SoC 2; and further comprising a first address translation unit, hereinafter referred to as ATU 1, associated with SoC 1, and a second address translation unit, hereinafter referred to as ATU 2, associated with SoC 2, for translating the address spaces between SoC 1, SoC 2, and the PCIe switch, such that ATU 1 and ATU 2 enable memory transaction packets to flow between SoC 1 and SoC 2, in particular without CPU intervention; and; - A method for enabling non-transparent bridging (NTB) in an automotive environment, comprising: providing a first system-on-a-chip (SoC1) and a second system-on-a-chip (SoC2), each with a PCIe interface; connecting SoC1 and SoC2 by means of a PCIe switch configured for NTB; translating address spaces between SoC1, SoC2, and / or the PCIe switch using address translation units (ATUs) in the PCIe switch; communicating between SoC1 and SoC2 using a set of shared components, including buffers, memory windows, and, in particular, doorbell registers; and configuring the ATU to allow direct memory transaction packets to be transferred between SoC1 and SoC2.

[0006] A sensor, also known as a detector, transducer, or probe, is a technical component capable of qualitatively or quantitatively detecting certain physical or chemical properties or conditions of its environment, such as temperature, humidity, pressure, velocity, brightness, acceleration, pH value, ionic strength, electrochemical potential, and / or the material composition of its surroundings. These parameters are detected using physical or chemical effects and converted into processable electrical signals as sensor data.

[0007] Vehicle sensors can be mounted on or attached to a vehicle. Vehicle sensors include optical sensors such as cameras, LiDAR, radar, time-of-flight (TOF) sensors, and other sensor technologies such as acoustic sensors.

[0008] ADAS stands for Advanced Driver Assistance Systems. These are technologies designed to enhance vehicle safety and improve driving comfort by providing the driver with assistance and automated features. ADAS encompasses a wide range of systems and functionalities, including collision avoidance, adaptive cruise control, lane keeping assist, automatic emergency braking, blind spot monitoring, parking assistance, and traffic sign recognition. These systems utilize various sensors, cameras, radar, lidar, and other advanced technologies to detect and respond to surrounding traffic, road conditions, and potential hazards, thereby reducing the risk of accidents and improving the overall driving experience.

[0009] A non-transparent bridge (NTB) is a component or mechanism in a computer architecture that enables communication between two or more PCIe domains or PCIe switch partitions. Unlike transparent bridges, which pass PCIe transactions transparently, NTBs intercept and handle transactions, thus enabling communication between separate PCI domains with potentially different address spaces.

[0010] An NTB, or non-transparent coupling, comprises multiple PCI functions, each defined by a Type 0 PCI head, coupled by a bridging function. These Type 0 PCI functions are commonly referred to as non-transparent endpoints (NT EPs). Each partition can have at most one NT EP, which limits the number of NTBs that can be configured in a system.

[0011] In a domain architecture, vehicle functions are grouped into centralized domains, each managed by a dedicated electronic control unit (ECU) or domain control unit. These domains typically correspond to specific vehicle subsystems such as powertrain, chassis, body, and infotainment. Each domain has its own dedicated communication network, enabling ECUs within the domain to communicate with each other. This architecture is characterized by point-to-point communication between ECUs and relies on a centralized gateway for communication between domains.

[0012] Domain architectures can have a hierarchical structure, with higher-level ECUs coordinating and controlling lower-level ECUs within the same domain.

[0013] In a zone architecture, vehicle functions are organized into zones or partitions based on physical proximity. Each zone contains multiple ECUs responsible for managing various functions within that zone. Zone architectures are equipped with a shared communication backbone that connects all ECUs in the vehicle. This backbone enables peer-to-peer communication between ECUs across different zones, eliminating the need for a centralized gateway. Zone architectures tend to have a flat network structure, with ECUs communicating directly with each other without hierarchical control.

[0014] An example of a zone definition according to physical spatial proximity in a vehicle could be as follows: front zone, left zone, right zone, rear zone.

[0015] The front zone covers the area in front of the vehicle and is relevant for collision avoidance and dynamic speed and distance control. Sensors connected to a front zone ECU can be forward-facing optical sensors such as lidar, radar, and cameras.

[0016] The left (right) zone covers the area on the left (right) side of the vehicle and is relevant for lane keeping assist and blind spot detection systems. Sensors connected to a left (right) zone ECU can be left-side optical sensors.

[0017] The rear zone covers the area behind the vehicle and is relevant for parking assistance, rear collision avoidance, and rear cross-traffic alert systems. Sensors connected to a rear zone ECU can be rear-facing optical sensors and ultrasonic sensors for detecting objects approaching the vehicle from behind and providing a view of the area behind the vehicle to assist with parking maneuvers and safe reversing.

[0018] Computer program products typically comprise a sequence of instructions that, when the program is loaded, instruct the hardware to execute a specific procedure that leads to a particular result.

[0019] To solve the problem of the invention, non-transparent bridges (NTBs) are used. NTBs enable communication between devices located in different switch partitions, essentially facilitating communication between domains. With an NTB in place, both hosts and endpoints can initiate transactions to hosts and / or endpoints located in another switch partition.

[0020] When there is a need to connect independent PCI domains or switch partitions, NTBs have the effect of allowing devices in one partition to communicate with devices in another.

[0021] Essentially, NTBs provide a mechanism to overcome the limitations of the single root and shared address space of a conventional PCIe architecture, enabling more flexible and scalable coupling between independent PCIe domains.

[0022] Each ATU is responsible for performing address translations between different address spaces within the switch to enable communication between the SoCs. It facilitates data exchange between the SoCs by translating addresses so that the correct data can be sent to the respective destinations.

[0023] Advantageous embodiments are described in the further dependent claims and in the description with reference to the figures of the drawing.

[0024] The benefit of allowing memory transaction packets to flow between SoC 1 and SoC 2 without CPU intervention is to achieve higher throughput and lower latency in data transfer. By bypassing the CPU, data can be transferred directly between the two SoCs, reducing instruction processing time and maximizing system efficiency.

[0025] According to a preferred embodiment of the invention, the memory further comprises a doorbell register for sending interrupt requests to SoC 2 and the PCIe base address register of SoC 1 contains a base address of a doorbell of SoC 2, wherein the memory of SoC 2 further comprises a doorbell register for sending interrupt requests to SoC 1 and the PCIe base address register of SoC 2 contains a base address of a doorbell of SoC 1.

[0026] Such a system optimizes the use of memory components by utilizing doorbell registers for interrupt signaling between SoC 1 and SoC 2. Instead of continuously reading the memory, which can be inefficient and resource-intensive, the memory components are only accessed when an interrupt signal is received. This approach minimizes unnecessary memory accesses and improves the efficiency and performance of the overall system.

[0027] According to a preferred embodiment of the invention, the system further comprises a system containing at least one first PCIe switch and one second PCIe switch, each having hardware components for a buffer, wherein the PCIe switches are further configured to implement data security features by controlling access to specific memory areas.

[0028] Having multiple switches can create redundancy in the network architecture. If one switch fails, the other switch can continue to operate, ensuring uninterrupted data access.

[0029] Two or more switches enable network segmentation, dividing the network into separate zones or domains. This segmentation can isolate sensitive data or critical systems from less secure or non-essential components, reducing the attack surface and limiting the impact of security breaches.

[0030] From a safety perspective, various useful features can be implemented to improve ASIL certification at the system level, such as failover capability coupled with fault propagation functionality, for a redundantly configured system-on-a-chip (SoC). This could be achieved through periodic functional tests between the SoC and the non-transparent bridge (NTB). These functionalities could enable features such as monitoring and watchdog mechanisms.

[0031] Monitoring mechanisms continuously observe the system's behavior and performance parameters, enabling early detection of potential problems or deviations from expected behavior. Watchdog mechanisms act as safety devices, automatically triggering corrective actions or system reconfiguration in the event of detected anomalies or errors, thus ensuring continuous, safe system operation.

[0032] Failover capability ensures that the system continues to function reliably even in the event of a failure. This is complemented by a fault handover functionality that seamlessly transfers operations to a redundant SoC configuration in the event of a primary system failure. By performing cyclical functionality checks between the SoC and the NTB, the system can continuously assess its own operational status and immediately respond to any detected anomalies or faults.

[0033] The implementation of data security features aimed at controlling access to specific storage areas can include various mechanisms to protect the confidentiality, integrity, and availability of data, such as ACLs, encryption, integrity checks, or the like.

[0034] Access control lists (ACLs) are configured in PCIe switches to determine which devices or components are allowed to access specific memory areas. Access is granted only to authorized units with the necessary credentials or permissions, thus preventing unauthorized access attempts.

[0035] Encryption mechanisms are supported by the PCIe switches to encrypt data stored in the cache. Accessing encrypted storage requires decryption keys, which are provided only to authorized entities. This ensures that even in the event of unauthorized access, the data remains protected and unreadable.

[0036] Integrity verification mechanisms are used to ensure that data stored in memory areas remains unchanged and free from falsification. Techniques such as checksums or digital signatures are used to detect any unauthorized modifications of data.

[0037] According to a preferred embodiment of the invention, the system further comprises a PCIe switch configured to perform cyclic functional tests between SoC 1 and SoC 2 to monitor system integrity.

[0038] Functionality tests can be performed at regular key points in the PCIe Link Training and Conditioning Machine (PCIe-LTSSM) or in a cycle-time operating mode. Correctable and non-correctable faults can be collected using the PCIe Advanced Fault Reporting Mechanism (PCIe-AER Mechanism), and heuristics can be used to estimate link degradation / failure. For each fault, a corrective action can be defined to increase the overall Safety Integrity Level (ASIL) of the automotive system. Some faults may be correctable through corrective actions, while others may be non-correctable and require a system reset, which involves resetting the system to a known state to clear all faults and resume normal operation.

[0039] Corrective measures can include dynamically reconfiguring system parameters or resources to bypass faulty components or reroute data paths. Alternatively, redundant components or subsystems can be activated to take over the functionality of faulty ones, ensuring uninterrupted operation.

[0040] Along with the usual PCIe errors, such as incorrectly configured TLPs, CRC checks, etc., reciprocal and cyclical communication between the SoCs enables a higher level of abstraction for error correction—at least higher than PCIe itself—allowing it to detect and potentially correct more errors. This communication can be implemented similarly to how watchdogs work in hardware systems, with an observer continuously awaiting a signal from a sender. In our case, one SoC would be the sender and the other the observer. If the signal from the sender does not arrive within a certain timeframe, an error can be triggered (this would be similar to the Wikipedia description of a single-stage watchdog).Depending on the necessary requirements for functional safety, a more complex behavior could be used to determine the existence of the other system, such as the use of multi-stage timeouts (similar to multi-stage watchdogs), window timeouts (similar to window watchdogs), or even including a permanently increasing value in the signal to prevent errors due to stuck and to minimize false positive detections.

[0041] According to a preferred embodiment of the invention, the system further comprises a third system on a chip (SoC 3) which includes a PCIe interface and a memory containing a memory window shared with SoC 2 and a PCIe base address register containing a base address of a buffer in the PCIe switch and a base address of a memory window of SoC 2, such that communication between SoC 1 and SoC 3 is blocked and communication between SoC 3 and SoC 2 is enabled.

[0042] Since the switch forwards every memory access transaction, it is an advantageous place to implement security features, if desired. This functionality would be similar to a firewall concept—allowing or blocking access to specific memory areas, perhaps even depending on the originating interface. For example, due to system architecture decisions, SoC 1 might need to communicate with SoC 3, but not necessarily with SoC 2. From a security perspective, it might be beneficial to block communication between SoC 1 and SoC 2.

[0043] According to a preferred embodiment of the invention, the system is further configured to support a zone architecture for vehicle on-board communication.

[0044] A zone architecture for vehicle onboard communication can include various aspects such as segmentation, where the PCIe switch divides the vehicle's network into distinct zones or segments, each serving specific functions or subsystems within the vehicle; communication channels, where the switch provides communication channels between different zones, enabling data exchange between subsystems while maintaining isolation and security; routing and switching, where the switch enables the routing and switching of data packets between zones based on predefined rules, ensuring efficient data flow while preventing unauthorized access; and security mechanisms that prevent unauthorized access from one zone to another. These can include encryption, authentication, access control, and intrusion detection systems.

[0045] According to a preferred embodiment of the invention, the system is further configured to support lane keeping ADAS functions.

[0046] The integration of lane-keeping ADAS functions contributes to increased road safety by assisting the driver in keeping the vehicle in its lane, thereby reducing the likelihood of accidents due to unintentional lane departure.

[0047] According to a preferred embodiment of the invention, the system is further configured to support ADAS functions for automatic emergency braking.

[0048] The support of ADAS functions for automatic emergency braking significantly reduces the risk of collisions by providing rapid, autonomous braking in response to potential obstacles, thereby increasing passenger safety.

[0049] According to a preferred embodiment of the invention, SoC 1 is connected to a first vehicle sensor and SoC 2 is connected to a second vehicle sensor.

[0050] Connecting SoC 1 to a first vehicle sensor and SoC 2 to a second vehicle sensor enables a zone architecture and / or parallel processing of sensor data, which can lead to faster response times for safety-critical functions.

[0051] According to a preferred embodiment of the invention, SoC 1 and SoC 2 are connected to the same vehicle sensor.

[0052] Having multiple SoCs connected to the same switch can create redundancy in the network architecture. If one SoC fails, the other SoC can continue operating, ensuring uninterrupted data access. This redundancy improves fault tolerance and resilience against single points of failure.

[0053] A computer program product according to a method of an embodiment of the invention performs the steps of a method as described above when the computer program product runs on a computer, in particular on a vehicle on-board computer. When the program in question is used on a computer, the computer program product produces an effect that specifically enables devices in one partition to communicate with devices in another. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] The present invention is described in more detail below with reference to the exemplary embodiments shown in the schematic figures of the drawings; these show: Fig. 1 a schematic block diagram of an embodiment of the invention; Fig. 2 a schematic block diagram of an embodiment of the invention; Fig. 3 a schematic block diagram of an embodiment of the invention; Fig. 4 a schematic block diagram of an embodiment of the invention; Fig. 5 a schematic block diagram of an embodiment of the invention; and Fig. 6 a schematic block diagram of an embodiment of the invention.

[0055] The accompanying drawings are intended to provide a deeper understanding of the embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain the principles and concepts of the invention. Other embodiments and many of the aforementioned advantages become apparent from the drawings. The elements of the drawings are not necessarily shown to scale in relation to one another.

[0056] In the figures of the drawings, identical, functionally identical and similarly acting elements, features and components - unless otherwise specified - are each provided with the same reference symbols. DETAILED DESCRIPTION

[0057] Fig. Figure 1 shows a block diagram of a method according to one aspect of the invention, comprising steps S1-S5. In S1, both systems on a single chip (SoC1 and SoC2) are provided with a PCIe interface. In S2, SoC1 and SoC2 are connected by a PCIe switch configured for NTB. In S3, address spaces of SoC1, SoC2, and / or the PCIe are translated between SoC1, SoC2, and / or the PCIe switch using ATUs in the PCIe switch. In S4, communication between SoC1 and SoC2 is enabled through the use of shared components, including buffers, memory windows, and doorbell registers. In S5, the ATUs are configured to allow direct memory transaction packets to be transferred between SoC1 and SoC2.

[0058] Fig. Figure 2 shows an architecture according to an embodiment of the invention for enabling a non-transparent bridge (NTB). The system 20 comprises a first SoC 3 and a second SoC 4, which are connected via the PCIe switch 5.

[0059] Fig. Figure 3 shows a system 30, which is similar to the system 20. Fig. 2, which includes a third SoC 6 and a second PCIe switch 7. PCIe switches 7 and 5 are connected to each other, while the third SoC 6 is only connected to PCIe switch 7.

[0060] Fig. Figure 4 shows a system 40 for lane-keeping ADAS functions of the vehicle with A-SIL decomposition, comprising forward-facing optical sensors 1, 2, a first SoC 3, a second SoC 4, and actuators 14, here steering actuators. Optical sensor 1 is connected to SoC 3, and sensor 2 is connected to SoC 4. The system's tasks are lane detection 11, lane keeping 12, and actuator message transmission 13. SoC 3 and 4 are connected via a PCIe switch (not shown).

[0061] Fig. Figure 5 shows a system 50 for distributing data from optical sensors to a SoC to enable high ASIL-relevant vehicle steering functions. The system comprises an optical sensor 1, a first SoC 3, and a second SoC 4, which is redundant to SoC 3. SoC 3 and SoC 4 are connected via a PCIe switch 5. Both SoC 3 and 4 are connected to an actuator.

[0062] Fig.Figure 6 shows a system 60 for automatic emergency braking. In this embodiment, a physical zone architecture is used, with sensors 1 in the rear section of the vehicle 9 connected to the first SoC 3, and sensors 2 and 8 in the front section of the vehicle 9 connected to the second SoC 4. A third SoC 6, which serves as the computing platform, is located in a central zone. The functions of SoC 3 and 4 are sensor preprocessing, applying preconfigured functions and filters—relieving SoC 6 of these tasks. SoC 6 then collects the sensor data from SoC 3 and 4 and can proceed with its emergency braking algorithm. The PCIe switch 5 receives input data from SoC 3 and 4 and provides output data that is transmitted to SoC 6. REFERENCE MARK LIST S1-S5 Steps of the procedure 1 sensor 2 Sensor 3 first SoC 4 second SoC 5 PCIe switches 6 third SoC 7 PCIe switch 8 Sensor 9 vehicles 11 Lane Detection 12 Keeping in lane 13 Actuator message transmission 14 Actuator 20 System 30 System 40 System 50 System 60 System QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited non-patent literature

[0000] NVIDIA, “NVIDIA DRIVE OS 5.1 Linux SDK - Non-Transparent Bridging and PCIe Interface Communication,” NVIDIA, 2024

[0002] https: / / docs.nvidia.com / drive / drive os 5.1.6.1 L / nvvib docs / index.html#paqe / DRIVE OS Linux SDK Development Guide / System%20Programming / sys components non transparent bridging.html

[0002]

Claims

[1] System (20; 30; 40; 50; 60) for enabling non-transparent bridging, hereinafter referred to as NTB, in a motor vehicle environment, comprising the following: at least one PCIe switch (5), a first system-on-a-chip (3), hereinafter referred to as SoC 1, connected to the PCIe switch, and a second system-on-a-chip (4), hereinafter referred to as SoC 2, connected to the PCIe switch; wherein the PCIe switch contains hardware components for a buffer; where SoC 1 contains the following: a PCIe interface and a memory containing the following: a memory window shared with SoC 2, and a PCIe base address register containing a base address of a cache in the PCIe switch and a base address of a memory window of the SoC 2; where SoC 2 contains the following: a PCIe interface and a memory containing the following: a memory window shared with SoC 1, and a PCIe base address register containing a base address of a cache in the PCIe switch and a base address of a memory window of the SoC 1; to enable communication between SoC 1 and SoC 2; and further comprising a first address translation unit, hereinafter referred to as ATU 1, which is assigned to SoC 1, and a second address translation unit, hereinafter referred to as ATU 2, which is assigned to SoC 2, for translating address spaces between SoC 1, SoC 2 and the PCIe switch, such that ATU 1 and ATU 2 enable memory transaction packets to flow between SoC 1 and SoC 2, in particular without CPU intervention. [2] System (20; 30; 40; 50; 60) according to claim 1, wherein the memory of SoC 1 (3) further includes a doorbell register for sending interrupt requests to SoC 2 (4) and the PCIe base address register of SoC 1 contains a base address of a doorbell of SoC 2; and wherein the memory of SoC 2 further includes a doorbell register for sending interrupt requests to SoC 1 and the PCIe base address register of SoC 2 contains a base address of a doorbell of SoC 1. [3] System (30) according to any of the preceding claims, wherein the system includes at least a first PCIe switch (5) and a second PCIe switch (7), each comprising hardware components for a buffer, wherein the PCIe switches are further configured to implement data security features by controlling access to specific memory areas. [4] System (20; 30; 40; 50; 60) according to any of the preceding claims, wherein the PCIe switch (5; 7) is further configured to perform cyclic functional tests between SoC 1 (3) and SoC 2 (4) to monitor system integrity. [5] System (30; 60) according to one of the preceding claims, further comprising a third system on a chip (6), hereinafter referred to as SoC 3, comprising: a PCIe interface (5; 7) and a memory containing the following: a memory window shared with SoC 2, and a PCIe base address register that contains a base address of a cache in the PCIe switch and a base address of a memory- window of SoC 2; such that communication between SoC 1 and SoC 3 is blocked. [6] System (20; 30; 40; 50; 60) according to any of the preceding claims, further configured to support a zone architecture for vehicle on-board communication. [7] System (20; 30; 40; 50; 60) according to any of the preceding claims, in particular according to claim 6, which is further configured to support lane keeping ADAS functions. [8] System (20; 30; 40; 50; 60) according to any of the preceding claims, in particular according to claim 6 or 7, which is further configured to support ADAS functions for automatic emergency braking. [9] System (40; 60b) according to one of the preceding claims, wherein SoC 1 (3) is connected to a first vehicle sensor (1) and SoC 2 (4) is connected to a second vehicle sensor (2). [10] System (50) according to any of the preceding claims, wherein SoC 1 (3) and SoC 2 (4) are connected to the same vehicle sensor (1). [11] Method for enabling non-transparent bridging (NTB) in a motor vehicle environment, comprising the following: - Provisioning (S1) of a first system on a chip (SoC1) and a second system on a chip (SoC2), each with a PCIe interface; - Connecting (S2) SoC1 and SoC2 through a PCIe switch configured for NTB; - Translation (S3) of address spaces between SoC1, SoC2 and / or the PCIe switch using address translation units (ATUs) in the PCIe switch; - Communication (S4) between SoC1 and SoC2 using a group of shared components that include caches, memory windows, and, in particular, Doorbell registers; and - Configure (S5) the ATU to allow direct storage transaction packets to be transferred between SoC1 and SoC2. [12] Computer program product comprising instructions which, when the program is executed by a computer, cause the computer to perform the method according to claim 11.

Citation Information

Patent Citations

  • Data transmission method and device

    CN117909098A

  • Memory protection unit

    EP2983088A1

  • CN000117909098A