Facility for monitoring an error status of operating system domains of a hypervisor system
The monitoring device for hypervisor systems addresses cascading failures by tracking and sharing fault status information, ensuring proper operation and compliance with ASIL levels, thereby preventing system malfunctions.
Patent Information
- Application Number
- DE112022008124
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-12-28
- Publication Date
- 2025-10-23
AI Technical Summary
Cascading failures occur in operating system domains due to physical or logical faults, leading to improper operation and violation of functional safety requirements, particularly in systems requiring high ASIL levels.
A monitoring device for hypervisor systems that tracks and shares fault status information across multiple operating system domains, using a hypervisor with a fault status monitoring manager to allocate resources and manage domain operations, ensuring proper operation and compliance with ASIL levels.
Prevents cascading failures by enabling accurate monitoring and management of fault states, allowing each operating system to operate according to its original specification and ensuring functional safety requirements are met, particularly for systems with higher ASIL levels.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
AREA OF TECHNOLOGY
[0001] The present disclosure relates to a monitoring device for monitoring the error status of operating system domains of a hypervisor system. More precisely, it relates to a monitoring device for monitoring the error status of operating system domains of a hypervisor system, which can prevent a problem in which, due to physical or logical errors in some operating systems running on the hypervisor, it cannot operate correctly, causing cascading errors in the remaining operating system domains running on the hypervisor in connection with the operating system domain while system requirements are being met. GENERAL STATE OF THE ART
[0002] In general, hypervisor software is software that transforms a single computer hardware into multiple virtual computer hardware, and the design and development of hypervisor software requires a high level of technology similar to that used in the creation of general-purpose operating system software, such as Windows and Linux.
[0003] Hypervisors were used to assist with computing operations without interrupting banking services during an operating system update or impacting the hardware efficiency of the cloud data center.
[0004] Hypervisors are expected to be used on various high-tech devices, such as future vehicles, drones, and robots. Operating systems running on known hypervisors have typically been general-purpose operating systems, such as Linux. Given its application in various areas of real-time systems, such as motor vehicles, drones, and robots, operating systems running on hypervisors are expected to include an operating system that guarantees real-time functionality and operational safety. Furthermore, control / application software that ensures operational safety will run on this operating system.
[0005] These hypervisors use computer hardware efficiently to run multiple operating systems simultaneously, and they are operated by allocating hardware resources to each operating system according to its given specification.
[0006] Meanwhile, among hardware resources, input / output devices such as networks, touchscreens, and mice, which are often used by multiple operating systems on a hypervisor, can malfunction and consume more resources than the hardware resources already allocated according to the respective specification.
[0007] For example, in a situation where hardware resources are used excessively, the hardware resources already allocated on a hypervisor according to the respective specification for each operating system may be insufficient, which can result in operating system malfunctions.
[0008] Since devices such as motor vehicles, drones and robots that will be used in the future will use a real-time operating system, if there are not enough hardware resources available, a real-time operating system will not be able to provide regular services, causing malfunctions in the systems of cars, drones and robots.
[0009] Such problems are discussed in detail using examples, with reference to Fig. 1 and Fig. 2 as described below.
[0010] Fig. 1 is a structure diagram in which control / application software (e.g., AutoSAR) is run on a general-purpose operating system (such as Linux), whereas Fig. 2. This example illustrates a structure in which control / application software (such as AutoSAR) is used. Fig. 1 is separated and configured on the hypervisor using a method for automotive safety integrity level decomposition (ASIL decomposition) into functional safety according to ISO26262.
[0011] With reference to Fig. 1 could replace the conventional system in Fig. 1. Due to the high complexity of a general-purpose operating system (such as Linux), these cannot be defined as higher levels of ASIL. Referring to Fig. 2. It is implemented by structurally decomposing it into AutoSAR (QM: Quality Assurance), which requires ASIL assessment, and AutoSAR(ASIL), which requires ASIL assessment, by implementing a procedure for ASIL decomposition into control / application software (e.g., AutoSAR) from Fig. 1 is applied. Here, the operating system is run with higher levels of ASIL applied, and AutoSAR(QM) is run on a general-purpose operating system.
[0012] In the structure of Fig. 2. It was difficult to apply a procedure for ASIL decomposition because there is no device in a hypervisor that can prevent cascading errors between AutoSAR(QM) and AutoSAR(ASIL). State of the art patent specification Korean patent application Publication No. 10-2021-0127427 (published on October 22, 2021, title: Method and Apparatus for CPU Virtualization in Multicore Embedded System) Korean patent application Publication No. 10-2021-0154769 (published on December 21, 2021, title: Micro Kernel-based Extensible Hypervisor) Korean patent application Publication No. 10-2019-0029977 (published on March 21, 2019, title: A Control System for Device and Process for Operating the Control System) Korean patent application Publication No. 10-2015-0090439 (published on August 6, 2015, title: Method for Scheduling a Task In Hypervisor for Many-core Systems) SUMMARY
[0013] One technical problem addressed by the present disclosure is to solve the problems where cascading errors occur in the rest of the operating system domains running on a hypervisor in connection with the corresponding operating systems, due to physical or logical errors in some operating system domains, making it difficult to operate them while meeting system requirements.
[0014] Furthermore, a technical problem of the present disclosure is to solve problems such as cascading failures, where each operating system cannot be operated correctly according to its original specification on the hypervisor, and the rest of the operating system domains, especially operating systems with higher levels of ASIL and higher levels of control / application software, cannot be operated correctly while meeting functional safety requirements.
[0015] There are various communication channels (such as back-end device drivers and front-end device drivers) between operating system domains on a hypervisor, enabling interdependent operations between operating systems. A more specific technical problem addressed in this disclosure is to prevent the effects of errors on all related operating system domains when cascading errors occur between them.
[0016] A monitoring device for monitoring the error status of operating system domains of the hypervisor system according to the present disclosure for solving these technical problems consists of running multiple operating systems in a virtual machine environment by allocating underlying resources to use system resources of the physical hardware layer and the operating system layer, which represents several different types of operating systems and control / application software; and running the multiple operating systems in a virtual machine environment that has functions to report the status of cascading errors for each of the multiple operating system domains corresponding to multiple operating systems, which comprise the operating system layers.and including a hypervisor that configures a manager to monitor a failure status and that has a function to monitor the failure status, wherein the hypervisor captures the failure status through each of several operating system domains via interfaces and shares it with the several operating system domains.
[0017] In a monitoring device for monitoring an error status of operating system domains in a hypervisor system according to the present disclosure, the system resources include one or more of central processing unit resources, microcontroller unit resources, and memory resources.
[0018] In a monitoring device for monitoring an error status of operating system domains in a hypervisor system according to the present disclosure, the administrator for monitoring an error status, which represents the hypervisor, continuously tracks the state, such as a normal / malfunction state, of the associated operating system domains via an interface by which the hypervisor collects the state information of a certain operating system domain for sharing, and reports the event signals throughout the entire system when an error occurs in the operating system domain of the hypervisor system and delivers these reported event signals to a user.
[0019] In a monitoring device for monitoring an error status of operating system domains in a hypervisor system according to the present disclosure, the operating system layer is characterized in that it includes an operating system with one or more ASIL levels, control / application software with one or more ASIL levels, and one or more general-purpose operating systems.
[0020] In a monitoring device for monitoring the error status of operating system domains in a hypervisor system according to the present disclosure, the manager for monitoring errors is characterized in that it registers assigned operating system domains and manages the assignment operations by means of an identification that is given to operating system domains on the hypervisor.
[0021] According to the present disclosure, there is an effect of resolving a situation in which some operating system domains running on the hypervisor cause errors, resulting in cascading errors where each operating system cannot operate properly according to its original specification on the hypervisor, leading to a problem where the rest of the operating systems, especially operating systems with higher levels of ASIL, cannot operate properly while meeting functional safety requirements.
[0022] Additionally, the error status information shared by a hypervisor across operating system domains has a fundamental effect of preventing cascading error problems in operating system domains running on the hypervisor, by enabling it to know the error status of an individual operating system in the software architecture for ASIL decomposition.
[0023] Additionally, there is an effect of resolving problems such as a cascading failure, where each of the operating systems on a hypervisor cannot operate correctly according to its original specification because some operating system domains running on a hypervisor cause failures, and a situation where the rest of the operating system domains, especially operating systems with higher levels of ASIL and control / application software with higher levels of ASIL, cannot operate correctly while meeting functional safety requirements. [BRIEF DESCRIPTION OF THE DRAWINGS] Fig. Figure 1 is a structural diagram of the control / application software (e.g. AutoSAR) running on a general-purpose operating system (e.g. Linux), in accordance with the state of the art. Fig. Figure 2 is a diagram illustrating a structure in which the control / application software (e.g., AutoSAR) is composed of Fig. 1 is separated by means of a method for decomposing the safety level for the integrity of motor vehicles according to ISO 26262: Functional safety standard. Fig. Figure 3 is a diagram illustrating a device for monitoring the error status of operating system domains on a hypervisor system according to an embodiment of the present disclosure. Fig. Figure 4 is a diagram illustrating, by way of example, the configuration of a hypervisor according to an embodiment of the present disclosure. Fig. Figure 5 is a diagram illustrating an example of a system architecture in which a device driver domain is isolated from operating system domains according to an embodiment of the present disclosure. Fig. Figure 6 is a diagram illustrating an example of a system architecture in which a device driver domain is integrated into an operating system domain according to an embodiment of the present disclosure. [DESCRIPTION OF PREFERRED VERSIONS]
[0024] It is understood that the specific structural or functional description of embodiments of the present invention disclosed in this document serves only for illustration and is not intended to limit the scope of the concept according to the invention, but can be embodied in many different forms and may not be limited to the embodiments set forth in this document.
[0025] The embodiments according to the concept of the present invention can undergo various modifications and take on different forms, so that the embodiments are illustrated in the drawings and described in detail in this document. It is understood, however, that the embodiments according to the concepts of the present invention are not intended to be limited to the specific forms disclosed, but rather that all modifications, equivalents, or alternatives that fall within the nature and scope of the invention are included.
[0026] Unless otherwise defined, all terms, including technical and / or scientific terms used in this document, have the same meaning as generally understood by a person skilled in the art in the field to which this invention belongs. These terms, such as commonly used predefined expressions, have the same meaning as in the related prior art and are not to be interpreted as ideal or ambiguous unless expressly defined otherwise in this description.
[0027] Following a description of the basic principles of the present disclosure, the embodiments of the present disclosure will be described in detail below.
[0028] When a Hypervisor 30 efficiently uses computer hardware to run multiple operating systems simultaneously, the Hypervisor 30 is operated in accordance with its specifications given for each operating system.
[0029] If a fault occurs in a specific operating system domain among multiple operating system domains, other operating systems running in conjunction with that specific operating system domain may not operate correctly in accordance with their specifications due to cascading faults.
[0030] Since devices such as vehicles, drones and robots that will be used in the future will use a real-time operating system, if a cascading fault occurs, the real-time operating system will be unable to provide normal service, resulting in faults in the systems of cars, drones and robots.
[0031] To correct such cascading errors, a procedure for applying ASIL decomposition on a hypervisor is explained as follows.
[0032] In the prior art, there was previously no method to prevent cascading errors due to the lack of an interface and a function that mutually shares status information with multiple operating systems running on a hypervisor 30.
[0033] In other words, according to the relevant state of the art, if a fault occurs in one operating system among several operating systems on a hypervisor, other operating systems remain unaware of it. This leads to greater challenges when such a problem is associated with software that requires ASIL rating.
[0034] In the present revelation, these problems can be solved in the following ways.
[0035] For example, future Hypervisor 30 will need to support ASIL-rated operating systems in response to the proliferation of autonomous driving devices, such as future vehicles, drones, and robots. Therefore, it is necessary to ensure that multiple operating systems run on Hypervisor 30 in accordance with their conventional specifications.
[0036] The present disclosure provides a function and interface of the hypervisor 30 that enables the hypervisor to receive or determine the status of multiple operating systems and to share the status information, such as normal operation or errors, with multiple operating systems. Furthermore, it provides a mechanism for managing cascading errors by sharing an error status monitoring device.
[0037] Preferred embodiments of the present disclosure are described in detail below in conjunction with the accompanying drawings.
[0038] Fig. Figure 3 is a diagram illustrating a monitoring device for monitoring the error status of operating system domains in a hypervisor system according to an embodiment of the present disclosure. Fig. Figure 4 is a diagram illustrating the configuration of a hypervisor according to an embodiment of the present disclosure.
[0039] With reference to Fig. 3 and Fig. 4. A monitoring device for monitoring an error status of operating system domains in a hypervisor system according to an embodiment of the present disclosure can be configured to include a physical hardware layer 10, an operating system layer 20 and a hypervisor 30.
[0040] The physical hardware layer 10 is an element that represents a physical device in which a monitoring device for monitoring the error status of operating system domains in a hypervisor system according to one embodiment of the present disclosure is implemented. For example, the physical device that configures the physical hardware layer 10 may include a central processing unit or a microcontroller unit, a storage device, including a dynamic random-access storage device, and input and output devices. These input and output devices may, among other things, include storage devices, output devices such as a network device and a touch panel, input devices such as a keyboard and a mouse, serial input and output devices, and the like.
[0041] Operating system layer 20 represents several different types of operating systems and control / application software. For example, the multiple operating systems that represent operating system layer 20 can be configured to include general-purpose operating systems with one or more ASIL levels, such as Windows, Unix, and the like, and control / application software can be configured to include software with one or more ASIL levels.
[0042] The hypervisor 30 is an element that enables multiple operating systems to run in a virtual machine environment by allocating underlying resources to use system resources of the physical hardware layer 10 for each of several operating system domains corresponding to multiple operating systems, which represent the operating system layer 20.
[0043] Additionally, Hypervisor 30 has a function for reporting the status of cascading errors for each of several operating system domains corresponding to multiple operating systems representing operating system layer 20; allows the multiple operating systems to be run in a virtual machine environment; and has a function for monitoring the error state.
[0044] Additionally, Hypervisor 30 detects an error state for each operating system domain via an interface and shares this information with the multiple operating system domains. For example, Hypervisor 30 can detect an error state by communicating with operating system layer 20 via interfaces and monitoring using a watchdog. Examples of interfaces include shared memory, device driver software, and Hypercall.
[0045] For example, system resources that the hypervisor 30 allocates for each of the multiple operating system domains may include one or more CPU resources, MCU resources, and memory resources.
[0046] Referring to the example from Fig. 4 The hypervisor 30 can be configured to include a resource allocator 32, a domain manager 34, an access control 36 and an error status monitor.
[0047] Resource allocator 32 allocates system hardware resources, such as CPU and memory, to each domain.
[0048] The domain manager 34 schedules domains in a time-sharing operation according to the amount of resources allocated by the resource allocator 32, and manages a context switching operation during scheduling.
[0049] Access control 36 controls access between objects, such as domains, hardware system resources, and data.
[0050] The administrator for monitoring an error status 38 monitors status information of each of the domains, device drivers and control / application software and shares it with all operating systems.
[0051] For example, the administrator can be configured to monitor for error status 38, register mapped operating system domains using an identification given to operating system domains on the hypervisor 30, and manage mapping operations.
[0052] For example, in one embodiment of the present disclosure, where the hardware system resources are CPU resources, a manager for monitoring an error state 38, representing the hypervisor 30, is used to accurately identify the status (such as error) of each operating system and communicates its status to operating systems in order to determine, for allocated operating system domains, whether or not to continue the allocation operations. Since it is guaranteed that an operating system domain will operate according to its original specification when running on a hypervisor 30, the service can, in turn, guarantee stable operation for ASIL-certified operating systems.
[0053] Fig. Figure 5 is a diagram illustrating an example of a system architecture in which a device driver domain is isolated from an operating system domain. Fig. Figure 6 is a diagram illustrating an example of a system architecture in which a device driver domain is integrated into an operating system domain. One embodiment of the present disclosure can be commonly applied to system architectures that are in Fig. 5 and Fig. 6 are illustrated, and can be applied.
[0054] As detailed above, according to the present disclosure, there is an effect of resolving a situation in which some operating system domains running on the hypervisor cause errors, resulting in cascading errors where each operating system cannot operate on the hypervisor according to its original specification, leading to a problem where the remaining operating systems, especially those with higher ASIL levels, cannot operate properly while meeting functional safety requirements.
[0055] Additionally, there is an effect to fundamentally avoid cascading errors in operating system domains running on the hypervisor, as an error state of a single operating system in the software architecture for ASIL decomposition using the error state information shared by the hypervisor with the operating system domains.
[0056] Furthermore, there is an effect of resolving a situation where some operating system domains running on the hypervisor cause errors, resulting in cascading errors where each operating system cannot operate on the hypervisor according to its original specification, leading to a problem where the remaining operating systems, especially operating systems with higher ASIL levels and control / application software with higher ASIL levels, cannot operate properly while meeting functional safety requirements. [DESCRIPTION OF THE REFERENCE MARKS IN THE DRAWINGS] 10 Physical Hardware Layer 20 Operating system layer 30 Hypervisor 32 resource allocators 34 domain administrators 36 Access control 38 administrators to monitor an error status QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] KR 10-2021-0127427
[0012] KR 10-2021-0154769
[0012] KR 10-2019-0029977
[0012] KR 10-2015-0090439
[0012]
Claims
[1] Monitoring device for monitoring the error status of operating system domains of a hypervisor system, comprising: a physical hardware layer; an operating system layer that represents several different types of operating systems and control / application software; and a hypervisor that allocates underlying resources to use system resources of the physical hardware layer to run multiple operating systems in a virtual machine environment, reports a cascading failure status of each of the multiple operating system domains corresponding to multiple operating systems, which represents the operating system layer, and to run the multiple operating systems in a virtual machine environment, and represents a manager for monitoring a failure status with a function for monitoring a failure status, the hypervisor captures the error status through interfaces across multiple operating system domains and shares this information with the multiple operating system domains. [2] Monitoring device according to claim 1, wherein the system resources include one or more of central processing unit resources, microcontroller unit resources and storage resources. [3] Monitoring device according to claim 1, wherein the administrator, for monitoring an error status representing the hypervisor, continuously monitors the state, such as a normal / malfunction state, of the associated operating system domains via an interface by which the hypervisor captures the state information of a certain operating system domain for sharing, tracks, and reports the event signals throughout the entire system when an error occurs in the operating system domain of the hypervisor system and delivers these reported event signals to a user. [4] Monitoring device according to claim 1, wherein the operating system layer includes an operating system with one or more ASIL levels, control / application software with one or more ASIL levels and one or more universal operating systems. [5] Monitoring device according to claim 1, wherein the administrator registers operating system domains assigned to monitor an error status and manages the assignment processes by means of an identification that is given to operating system domains on the hypervisor.
Citation Information
Patent Citations
10-2019-0029977
10-2015-0090439
10-2021-0154769
10-2021-0127427