Bus error handling method
The method addresses the challenge of managing bus errors by storing and using transaction characteristics to direct interrupts in electronic systems, enabling targeted error handling and improving system reliability.
Patent Information
- Application Number
- FR2023015216
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Existing methods struggle to effectively identify and manage the causes of bus errors during write access transactions in electronic systems, often leading to unnecessary system resets and user experience degradation.
A method for managing bus errors involves storing first and second characteristics of write transactions and associated errors, generating interrupts with these characteristics, and using a management unit to direct these interrupts to the appropriate processing unit, allowing for targeted error handling and reporting.
This approach enables more precise identification and handling of bus errors, allowing operating systems to implement targeted repair actions instead of complete system resets, and facilitates the creation of error reports for certifications.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for managing bus errors Technical field
[0001] The present description relates generally to bus error management methods as well as to microcontrollers implementing these methods. Prior art
[0002] Many electronic systems use processing units (CPU, Central Processing Unit in English) generating write access transactions to functional units (IP, Intellectual Property core in English). Errors can occur during the implementation of these transactions. Summary of the invention
[0003] There is a need to improve the identification of error causes following a write access transaction.
[0004] One embodiment overcomes all or part of the drawbacks of the known methods.
[0005] One embodiment provides a method for handling bus errors, in which one or more first characteristics of a first write transaction to a functional unit and passing through a gateway are stored, and in which in the presence of a bus error sent by the functional unit: - one or more second characteristics linked to said error are stored; - the gateway generates a first interrupt which it transmits with said first and second characteristics to a management unit; and - the management unit generates at least one second interrupt to a processing unit based on the first and / or second characteristics.
[0006] One embodiment provides a microcontroller comprising at least one control unit, a gateway, a functional unit, and a management unit; the microcontroller being configured to: - store one or more first characteristics of a first write transaction to the functional unit and passing through the gateway; and - that in the presence of a bus error sent by the functional unit: the gateway generates a first interrupt which it transmits with said first and second characteristics to a management unit; and the management unit generates at least one second interrupt to a processing unit based on the first and / or second characteristics.
[0007] According to one embodiment, the processing unit executes several operating systems and the second interrupt is intended for one of these operating systems according to the first and / or second characteristics.
[0008] According to one embodiment, the second interruption is intended for one of several processing units depending on the first and / or second characteristics.
[0009] According to one embodiment, the first characteristics are stored in the gateway.
[0010] According to one embodiment, the second characteristics are stored in the gateway.
[0011] According to one embodiment, the management unit stores the first and second characteristics.
[0012] According to one embodiment, the management unit stores the first and second characteristics after the transmission of the first interrupt transaction and the first and second characteristics by the gateway.
[0013] According to one embodiment, the first and second characteristics are stored in one or more registers of the management unit.
[0014] According to one embodiment, the first characteristic(s) comprise a level of access restriction.
[0015] According to one embodiment, the second characteristic(s) comprise a level of addressing mode restriction.
[0016] According to one embodiment, the second characteristic(s) comprise an address.
[0017] According to one embodiment, the second characteristic(s) comprise an identifier.
[0018] According to one embodiment, one of the registers is configured to store a value representative of the presence of a transmission of the first interrupt transaction.
[0019] According to one embodiment, one of the registers is configured to store the first characteristic(s) as well as the second characteristic(s).
[0020] According to one embodiment, one of the registers is configured to store an address linked to the first write access transaction.
[0021] According to one embodiment, the management unit stores the first and second characteristics in registers having a similar access restriction level to the first characteristics.
[0022] According to one embodiment, the management unit transmits said second interrupt transaction to the processing unit having an access restriction level similar to the access restriction level associated with the first characteristic(s).
[0023] According to one embodiment, following the transmission of the second interrupt transaction, the processing unit having received said second interrupt transaction performs an action among a reconfiguration of the functional unit, a reinitialization of the first or second transaction, a reinitialization of the microcontroller, and a writing of an error report. Brief description of the drawings
[0024] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:
[0025] [Fig.l] represents, very schematically and in the form of blocks, an example of a microcontroller of the type to which the described embodiments apply;
[0026] [Fig.2] represents an example of a bus error management method;
[0027] [Fig.3] shows another example of a bus error handling method;
[0028] [Fig.4] represents a method of bus error management according to a mode of realization; and
[0029] [Fig.5] represents a bus error management method according to another embodiment. Description of the embodiments
[0030] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.
[0031] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed.
[0032] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.
[0033] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.
[0034] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.
[0035] [Fig. 1] represents, very schematically and in the form of blocks, an example of a microcontroller 100 of the type to which the described embodiments apply. The microcontroller 100 is for example a microprocessor.
[0036] The microcontroller 100 comprises a non-volatile memory 104 (NVM), for example of the phase change type, capable of communicating, via a communication bus 114, with a non-volatile memory interface 106 (NVM INTERFACE) configured to write or read data in and from the non-volatile memory 104.
[0037] The microcontroller 100 further comprises, for example, one or more processing units 110 (CPU) comprising one or more processors under control of instructions stored in an instruction memory 112 (INSTR MEM). The one or more processing units 110 comprise one or more operating systems (OS).
[0038] The instruction memory 112 is for example a volatile memory of the random access type (Random Access Memory, RAM). The processing unit 110 and the memory 112 communicate, for example, via a system bus 140 (data, address and control). The memory 104 is connected to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 further comprises an input / output interface 108 (FO interface) connected to the system bus 140 to communicate with the outside.
[0039] The microcontroller 100 can integrate other circuits implementing other functions or functional units (for example, one or more volatile and / or non-volatile memories, direct memory accesses (DMA, Direct Access Memory in English) or other processing units, symbolized by a block 116 (IP) in [Fig.l]. Among these other circuits, the microcontroller 100 comprises for example a read-only or static memory 118 (ROM).
[0040] The processing unit(s) 110 as well as the blocks 104, 106, 108, 112, 114, 116, 118, are for example used in environments having different access restriction levels (NS, SEC). In one example, the resources evolving in the SEC environment have access to the resources of the SEC or NS level while the resources evolving in the SEC environment have access to the resources of the NS level but not of the NS level. In one example, an application defined to have the SEC access restriction level has more rights than an application having the NS access restriction level. The SEC, NS access restriction levels are for example implemented with the TrustZone protocol of the ARM® CORTEX-M architecture.
[0041] In certain cases, the different blocks 104, 106, 108, 110, 112, 114, 116, 118, of [Fig.l] operate with different clock signal domains or under different protocols such as AXI, AHB or APB of the ARM® architecture. It is then necessary to implement one or more gateways 160, 162, 164, 166, 168 (bridge in English) for example between the processing unit(s) 110 and the block 116, or one of the blocks 118, 112, 108, or 106. These gateways ensure the transition from one operating mode, for example a bus protocol or a clock frequency domain, to another operating mode.
[0042] The processing unit(s) 110 generate and send write access transactions to one or more of the different blocks 104, 106, 108, 112, 114, 116, 118 through the bus 140 and for example by transiting through one of the gateways. When passing through the gateway, the write access request transaction (Write bufferable access in English) is for example temporarily stored in the respective gateway. In one example, if the write access is not successful, a bus error is generated for example by the block receiving the write access transaction.
[0043] [Fig.2] represents an example of a bus error handling method.
[0044] In the example shown, the processing unit 110 comprises for example two operating systems 214 (SEC OS) and 212 (NS OS). The SEC OS operating system has a higher level of access rights restriction (secure, SEC) than that of the NS OS operating system (non-secure, NS).
[0045] In a first step 230 (NS Write Bufferable Access), a write access transaction is generated by the operating system 212 for example to block 116. In this example, this transaction is implemented in an NS environment.
[0046] In a second step 232 (Access buffered), this transaction passes through the respective gateway (Bridge AHB2AHB) 160,162,164,166,168. In the example shown, the gateway adapts the transaction which is in AHB bus protocol to the same AHB protocol having for example a different clock signal domain, for example a different frequency. In this step, the transaction is buffered, i.e. temporarily stored, by the gateway. After this buffering or as soon as the first step 230 is finished, the processing unit 110 carries out for example other tasks which no longer have any link with the gateway.
[0047] In a third step 234 (NS Write access), the transaction is implemented from the gateway to, for example, block 116.
[0048] In response, in a fourth step 236 (Bus error), if the write access transaction fails, a bus error is sent from block 116 to gateway 160.
[0049] In a fifth step 240 (IRQ), upon receipt of this error, the gateway generates, in other words raises, an interrupt (IRQ, Interupt ReQuest in English) to the default operating system 214 SEC OS and not to the operating system having the NS environment of the initial transaction. This is for example due to the fact that the bus error may be due to an attack and that by default the interrupts are directed to the operating system 214. This interruption may be software or hardware. The interruption materializes for example by the change of a bit or a byte of a register. The operating system NS OS, initiator of the initial transaction, does not receive the bus error and cannot therefore implement any repair action or targeted action. The fact that the processing unit 110 has, following the write access request transaction, carried out other tasks which are no longer linked to the gateway 160, implies that none of the operating systems 214 SEC OS or 212 NS OS will receive the bus error.The 214 SEC OS operating system having no information other than the interrupt raised by the gateway, which could correspond to an attack, it will implement for example a complete reset of the microcontroller 100 which is damaging for the user experience for example.
[0050] [Fig. 3] shows another example of a bus error handling method. The example of [Fig. 3] is similar to that of the figure except that instead of having one processing unit implementing two operating systems under different environments, the microcontroller 100 includes two processing units 312 (CPU1) and 314 (CPU2) which implement operating system 212 and operating system 214 respectively. In one example, the processing unit 110 includes two regions containing processing units 312 and 314 respectively.
[0051] In the illustrated example, the write access transaction of step 230 is generated by the operating system 212 under NS environment. Steps 232, 234 and 236 are then similar to those of the example of [Fig.2].
[0052] After step 236, in a step 340 (IRQ), upon receipt of the bus error, the gateway 160 generates by default an interrupt (IRQ) to the operating system 214 SEC OS of the processing unit 314 and not to the operating system 212 NS which nevertheless has the same NS environment as that of the initial transaction.
[0053] Furthermore, the operating system 212 NS OS, initiator of the initial transaction, does not receive the bus error and thus cannot implement any repair action or targeted action. For the same reasons as the example in [Fig.2], neither of the operating systems 214 SEC OS nor 212 NS OS will receive the bus error. Since the operating system 214 SEC OS has no information other than the interrupt raised by the gateway, it will implement, for example, a complete reset of the microcontroller 100.
[0054] To overcome these drawbacks, the described embodiments provide a method for managing bus errors, in which one or more first characteristics of a first write transaction (write bufferable access) to the functional unit 116 and passing through the gateway 160, are stored, and in which in the presence of a bus error sent by the functional unit 116: - one or more second characteristics linked to said error are stored; - the gateway generates a first interrupt which it transmits with said first and second characteristics to a management unit; and - the management unit generates at least one second interrupt to the processing unit (110, 312, 314) as a function of the first and / or second characteristics.
[0055] The operating system initiating the initial transaction can thus have access to information relating to the bus error and can thus implement repair actions or targeted actions without having to completely reset the microcontroller.
[0056] Storing the first and second characteristics makes it possible to create an error report for the implementation of certifications such as the SESIP (Security Evaluation Standard for loT Platforms) certification.
[0057] The operating system that issued the initial write access transaction, whether it is of NS or SEC access restriction level, may receive the second interrupt linked to this transaction.
[0058] Finally, an advantage of such a method is that it is possible to retain existing gateways without having to develop new ones.
[0059] [Fig.4] shows a bus error management method according to one embodiment. The processing unit 110 of [Fig.4] is similar to that of [Fig.2].
[0060] In a first step 410 (NS Write Bufferable Access), a write access transaction is generated by the operating system 212 to, for example, block 116. In this example, this transaction is implemented in an NS environment. In the example shown, N write access transactions are generated, for example successively, by the operating system 212 to, for example, block 116 or other blocks and transiting respectively for each write access transaction through N gateways (Bridge 0 AHB2AHB, Bridge 1 AHB2AHB,..., Bridge N AHB2AHB).
[0061] In a second step 412 (Access buffered + store information on the access (SEC / NS + debug info)), this transaction passes through a respective gateway (Bridge 0 AHB2AHB) 160, 162, 164, 166, 168. In the example shown, the gateway adapts the transaction which is in AHB bus protocol to the same AHB protocol having for example a different clock signal domain, for example a different frequency. In this step, the transaction is buffered, i.e. temporarily stored, by the gateway. After this buffering or at the end of the first step 410, the processing unit 110 performs, for example, other tasks that are no longer linked to the gateway. During this step, one or more first characteristics of the write transaction, in other words write access, are stored, for example in the gateway. These first characteristics are, for example, representative of the level of access restriction (NS / SEC) linked to the transaction environment. The first characteristics may also include information useful for error resolution (debug in English).
[0062] In a third step similar to step 234, the write access transaction is implemented from the respective gateway to, for example, block 116.
[0063] In response, in a fourth step similar to step 236 (Bus error), if the write access transaction fails, a bus error possibly accompanied by one or more second characteristics is sent from block 116 to the respective gateway. In this step, one or more second characteristics related to this error are stored for example in the respective gateway. These second characteristics include for example an addressing mode restriction level (unpriv, Priv), an address or even an identifier of master or slave functions.
[0064] In a fifth step 416, 420, 430 (NS / SEC, and debug information), after receiving the respective bus error, each gateway generates an interrupt 418 IRQ(0), 422 IRQ(1)... 432 IRQ (N) which it transmits, for example with the first and second characteristics, to a management unit 440. The management unit 440 is for example a smart bridge system (SBS).
[0065] In the example shown, the management unit comprises registers 450 (B 1ER), 452 (BISR), 454 (BICR), 456 (BESR) and 458 (BEADDR) dedicated to the storage of the characteristics among the first and second which follow a write access transaction of access restriction level NS and different registers 442 (SBIER), 444 (SBISR), 446 (SBICR), 447 (SBESR) and 448 (SBEADDR) dedicated to the storage of the characteristics which follow a write access transaction of access restriction level SEC. In other words, if the NS / SEC access restriction level of the operating system, or the environment, which generated the transaction in step 410 is of type NS then the first and second characteristics transmitted by the respective gateway are stored in the management unit 440 in the registers associated with this same NS access restriction level, and likewise for the SEC level.
[0066] In a sixth step after the fifth step, the management unit 440 generates at least one second interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) to destination of the processing unit 110 as a function of the first and / or second characteristics stored in one or more of the gateways and / or in the management unit 440.
[0067] If the interrupt, generated by one of the gateways and stored for example by means of a flag raised in one of the registers of the management unit 440, is initially linked to a transaction having an access restriction level NS then the second interrupt SBS_IRQ_NS is sent from the management unit 440 to the operating system 212. If the interrupt is initially linked to a transaction having an access restriction level SEC then the second interrupt SBS_IRQ_SEC is sent from the management unit 440 to the operating system 214.
[0068] This second interrupt may contain, for example, the NS / SEC access restriction level of the initial transaction but also the second characteristics linked to the corresponding bus error.
[0069] The register 450 is for example read-only and write-only in the case where the access restriction level is NS. In one example, certain bits or bytes of the register 450 are written by software to activate or deactivate the second SBS_IRQ_NS interrupt. A value of 0 means that this second SBS_IRQ_NS interrupt is deactivated and that, in this case, the second interrupt will not be returned to the level of the processing unit concerned when a first interrupt has been initiated by a gateway. A value of 1 means that the second SBS_IRQ_NS interrupt is active and in this case the interrupt will be returned to the level of the processing unit concerned when an interrupt has been initiated by a gateway.
[0070] The register 452 is for example read-only access in the case where the access restriction level is of type NS. In one example, a bit or byte of the register 452 is dedicated to storing the flag linked to the raising of the second SBS_IRQ_NS interrupt. A value of 1 indicates for example that the SBS_IRQ_NS interrupt is sent to the processing unit concerned. A value of the flag of 0 indicates for example that the SBS_IRQ_NS interrupt is not sent to the processing unit concerned.
[0071] Register 454 is for example write-only access in the case where the access restriction level is NS. In one example, a value of 1 clears the interrupt-related flag stored in register 452 and also clears registers 456 and 458. In one example, writing 0 has no effect.
[0072] The register 456 is for example read-only access in the case where the access restriction level is NS. It stores the characteristics associated with the transaction requesting write access of NS access restriction. This register is for example valid only when the respective gateway has generated an associated interrupt to NS access restriction, i.e. when a flag is raised. In one example, some bits or bytes of register 456 are dedicated to storing the identifier of the gateway that transmitted the interrupt. Some bits or bytes of register 456 are, for example, dedicated to storing the addressing mode restriction level (unpriv, Priv) of the functional unit or gateway or operating system that issued the transaction. Some bits or bytes of register 456 are, for example, dedicated to storing the identifier of the master / slave element or functional unit.
[0073] The register 458 is for example read-only access in the case where the access restriction level is NS. This register 458 is for example written by hardware when a gateway raises an error. It is for example reset by software via the register 454. It stores for example the address of the write access request transaction having the access restriction level NS which generated the bus error.
[0074] Registers 442, 444, 446, 447, and 448 are similar to registers 450, 452, 454, 456, and 458, respectively, except that the criteria of the access restriction level parameters NS are replaced by the access restriction level SEC.
[0075] The processing unit or the operating system receiving the second interruption may, for example, use the first and second characteristics stored in the corresponding gateway or in the registers of the management unit 440 or in the second interruptions to supply an error report and / or implement specific actions. These actions are, for example, the reconfiguration of the functional block 116 having generated the bus error or restarting the initial transaction or even reinitializing all or part of the microcontroller.
[0076] [Fig.5] represents a bus error management method according to another embodiment.
[0077] The method of [Fig.5] is similar to that of [Fig.4] except that, in step 410 of [Fig.5], the write access transaction is issued by an operating system similar to operating system 214 which is of access restriction level SEC or by an operating system similar to operating system 212 which is of access restriction level NS.
[0078] In the sixth step, the second interrupt generated by the management unit 440 (SBS_IRQ_NS, SBS_IRQ_SEC) is either intended for the operating system 212 of the processing unit 312, or intended for the operating system 214 of the processing unit 314 depending on the first and / or second characteristics stored in one or more of the gateways and / or in the management unit 440.
[0079] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variants could be combined, and other variants will occur to those skilled in the art. In particular, other types of registers may be implemented in the management unit 440 to store other types of characteristics that could assist in troubleshooting bus errors.
[0080] Finally, the practical implementation of the embodiments and variants described is within the reach of the person skilled in the art from the functional indications given above. In particular, with regard to the NS / SEC access restriction level, the person skilled in the art may implement the storage in the gateway(s) or in the management unit 440 of other characteristics such as a priv / unpriv addressing restriction level of the operating system having issued the initial transaction. In one example, the gateway(s) may be integrated into the management unit so as to facilitate the storage and transmission of the characteristics of the write access transactions but also of the characteristics linked to bus errors.
Claims
Claims
1. A method for managing bus errors, in which one or more first characteristics of a first write transaction (410) to a functional unit (116) and passing through a gateway (160,162,164,166,168) are stored, and in which in the presence of a bus error sent by the functional unit (116): - one or more second characteristics related to said error are stored; - the gateway (160,162,164,166,168) generates a first interrupt (416,420,422,430) which it transmits with said first and second characteristics to a management unit (440); and - the management unit (440) generates at least one second interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) intended for a processing unit (110, 312, 314) as a function of the first and / or second characteristics.
2. The method of claim 1, wherein the processing unit executes multiple operating systems (212,214) and the second interrupt is directed to one of those operating systems based on the first and / or second characteristics.
3. The method of claim 2, wherein the second interrupt is intended for one of several processing units (312,314) based on the first and / or second characteristics.
4. A method according to any one of claims 1 to 3, wherein the first characteristics are stored in the gateway (160,162,164,166,168).
5. A method according to any one of claims 1 to 4, wherein the second characteristics are stored in the gateway (160,162,164,166,168).
6. A method according to any one of claims 1 to 5, wherein the management unit (440) stores the first and second characteristics.
7. The method of claim 6, wherein the management unit (440) stores the first and second characteristics after the transmission of the first interrupt transaction (416,420,422,430) and the first and second characteristics by the gateway.
8. Method according to claim 6 or 7, in which the first and second characteristics are stored in one or more registers of the management unit (440).
9. A method according to any one of claims 1 to 8, wherein the first characteristic(s) comprise an access restriction level (NS, SEC).
10. A method according to any one of claims 1 to 9, wherein the second characteristic(s) comprises an addressing mode restriction level (unpriv, Priv).
11. A method according to any one of claims 1 to 10, wherein the second characteristic(s) comprises an address.
12. A method according to any one of claims 1 to 11, wherein the second characteristic(s) comprises an identifier.
13. A method according to any one of claims 8 or 9 to 12 as dependent on claim 8, wherein one of the registers is configured to store a value representative of the presence of a transmission of the first interrupt transaction (416,420,422,430).
14. A method according to any one of claims 8 or 9 to 13 as dependent on claim 8, wherein one of the registers is configured to store the first characteristic(s) as well as the second characteristic(s).
15. A method according to any one of claims 8 or 9 to 14 as dependent on claim 8, wherein one of the registers is configured to store an address related to the first write access transaction (410).
16. Method according to any one of claims 9 to 15 in their dependence on claim 8, in which the management unit (440) stores the first and second characteristics in registers having an access restriction level (NS, SEC) similar to the first characteristics.
17. Method or microcontroller according to any one of claims 9 to 16 in their dependence on claim 8, in which the management unit (440) transmits said second transaction interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) to the processing unit (110, 312, 314) having an access restriction level (NS, SEC) similar to the access restriction level (NS, SEC) associated with the first characteristic(s).
18. Method according to any one of claims 1 to 17, wherein, following the transmission of the second interrupt transaction (SBS_IRQ_NS, SBS_IRQ_SEC), the processing unit (110, 312, 314) having received said second interrupt transaction performs one of a reconfiguration of the functional unit (116), a reset of the first or second transaction, a reset of the microcontroller (100), and a writing of an error report.
19. Microcontroller comprising at least one bus, a functional unit (116), a gateway (160,162,164,166,168), a management unit (440) and a processing unit (110,312,314), and configured so as to implement the method according to any one of claims 1 to 18.
Citation Information
Patent Citations
Information processing apparatus and fault processing method for information processing apparatus
EP2713273A2