Bus error handling method
The described method and architecture in microcontrollers address the issue of incomplete error handling by storing transaction and error characteristics to generate targeted interrupts, enabling effective error management and system recovery.
Patent Information
- Application Number
- FR2023015216
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Existing bus error handling methods in microcontrollers fail to provide adequate identification of error causes, leading to unnecessary complete resets of the system and lack of targeted remedial actions due to insufficient information being transmitted to the appropriate operating systems.
A method and microcontroller architecture that stores characteristics of write transactions and associated bus errors, generating targeted interrupts to the appropriate processing units or operating systems based on these characteristics, allowing for informed remedial actions without complete system resets.
Enables targeted error handling and reporting, facilitating system recovery and compliance with security certifications by ensuring relevant operating systems receive necessary error information.
Smart Images

Figure 00000015_0000 
Figure 00000016_0000 
Figure 00000017_0000
Abstract
Description
Title of the invention: Bus error management method technical field
[0001] This description relates in general to bus error management methods and microcontrollers implementing these methods. Previous technique
[0002] Many electronic systems use central processing units (CPUs) that generate write access transactions destined for intellectual property cores (IPs). Errors can occur during the implementation of these transactions. Summary of the invention
[0003] There is a need to improve the identification of the causes of error following a write access transaction.
[0004] An embodiment overcomes all or part of the disadvantages of known processes.
[0005] One embodiment provides a method for managing bus errors, in which one or more first characteristics of a first write transaction destined for a functional unit and passing through a gateway are stored, and in which in the presence of a bus error sent by the functional unit: - one or more second characteristics related to said error are stored; - the gateway generates a first interrupt which it transmits, along with said first and second characteristics, to a management unit; and - the management unit generates at least one second interrupt destined for a processing unit based on the first and / or second characteristics.
[0006] One embodiment provides a microcontroller comprising at least one control unit, one gateway, one functional unit, and one management unit; the microcontroller being configured to: - to store one or more initial characteristics of an initial write transaction destined for the functional unit and passing through the gateway; and - that in the presence of a bus error sent by the functional unit: The gateway generates a first interrupt which it transmits, along with said first and second characteristics, to a management unit; and The management unit generates at least one second interrupt destined for a processing unit based on the first and / or second characteristics.
[0007] According to one embodiment, the processing unit executes several operating systems and the second interrupt is intended for one of these operating systems depending on the first and / or second characteristics.
[0008] According to one embodiment, the second interrupt is intended for one of several processing units depending on the first and / or second characteristics.
[0009] According to one embodiment, the first characteristics are stored in the gateway.
[0010] According to one embodiment, the second characteristics are stored in the gateway.
[0011] According to one embodiment, the management unit stores the first and second characteristics.
[0012] According to one embodiment, the management unit stores the first and second characteristics after the transmission of the first interrupt transaction and the first and second characteristics by the gateway.
[0013] According to one embodiment, the first and second characteristics are stored in one or more registers of the management unit.
[0014] According to one embodiment, the first feature(s) include an access restriction level.
[0015] According to one embodiment, the second feature(s) include a level of addressing mode restriction.
[0016] According to one embodiment, the second feature(s) include an address.
[0017] According to one embodiment, the second feature(s) include an identifier.
[0018] According to one embodiment, one of the registers is configured to store a value representative of the presence of a transmission of the first interrupt transaction.
[0019] According to one embodiment, one of the registers is configured to store the first characteristic(s) as well as the second characteristic(s).
[0020] According to one embodiment, one of the registers is configured to store an address related to the first write access transaction.
[0021] According to one embodiment, the management unit stores the first and second characteristic(s) in registers having a level of access restriction similar to the first characteristic(s).
[0022] According to one embodiment, the management unit transmits said second interrupt transaction to the processing unit having an access restriction level similar to the access restriction level associated with the first characteristic(s).
[0023] According to one embodiment, following the transmission of the second interrupt transaction, the processing unit that received said second interrupt transaction performs one of the following actions: a reconfiguration of the functional unit, a reset of the first or second transaction, a reset of the microcontroller, and the writing of an error report. Brief description of the drawings
[0024] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the accompanying figures, among which:
[0025] [Fig.1] represents, in a very schematic way and in block form, an example of a microcontroller of the type to which the described embodiments apply;
[0026] [Fig.2] represents an example of a bus error handling method;
[0027] [Fig.3] represents another example of a bus error handling method;
[0028] Figure 4 represents a bus error management method according to a mode of realization; and
[0029] [Fig.5] represents a bus error management method according to another embodiment. Description of the implementation methods
[0030] The same elements have been designated by the same reference numerals in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.
[0031] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been represented and are detailed.
[0032] Unless otherwise specified, when referring to two elements connected together, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") together, this means that these two elements can be connected or linked through one or more other elements.
[0033] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made, unless otherwise specified, to the orientation of the figures.
[0034] Unless otherwise specified, the expressions "approximately", "roughly", and "in the order of" mean within 10%, preferably within 5%.
[0035] Figure 1 represents, in a very schematic and block-like fashion, an example of a microcontroller 100 of the type to which the described embodiments apply. The microcontroller 100 is, for example, a microprocessor.
[0036] The microcontroller 100 includes a non-volatile memory 104 (NVM), for example of the phase-change type, capable of communicating, via a communication bus 114, with a non-volatile memory interface 106 (NVM INTERFACE) configured to write or read data into and from the non-volatile memory 104.
[0037] The microcontroller 100 further comprises, for example, one or more processing units 110 (CPUs) comprising one or more processors under instruction control stored in an instruction memory 112 (INSTR MEM). The processing unit(s) 110 comprise one or more operating systems (OS).
[0038] The instruction memory 112 is, for example, a volatile random access memory (RAM). The processing unit 110 and the memory 112 communicate, for example, via a system bus 140 (data, address, and control bus). The memory 104 is connected to the system bus 140 via the non-volatile memory interface 106 and via the bus 114. The device 100 further includes an input / output interface 108 (FO interface) connected to the system bus 140 for external communication.
[0039] The microcontroller 100 can integrate other circuits implementing other functions or functional units (for example, one or more volatile and / or non-volatile memories, direct memory access (DMA, Direct Access Memory) or other processing units, symbolized by a block 116 (IP) in [Fig.1]. Among these other circuits, the microcontroller 100 includes, for example, a read-only or static memory 118 (ROM).
[0040] The processing unit(s) 110, as well as blocks 104, 106, 108, 112, 114, 116, and 118, are used, for example, in environments with different access restriction levels (NS, SEC). In one example, resources operating in the SEC environment have access to resources at either the SEC or NS level, while resources operating in the SEC environment have access to resources at the NS level but not at the NS level. In one example, an application defined to have the SEC access restriction level has more privileges than an application with the NS access restriction level. The SEC and NS access restriction levels are implemented, for example, with the TrustZone protocol of the ARM® CORTEX-M architecture.
[0041] In some cases, the various blocks 104, 106, 108, 110, 112, 114, 116, 118 of [Fig. 1] operate with different clock signal domains or under different protocols such as AXI, AHB, or APB of the ARM® architecture. It is then necessary to implement one or more gateways 160, 162, 164, 166, 168 (bridge (in English) for example between processing unit(s) 110 and block 116, or one of blocks 118, 112, 108, or 106. These gateways ensure the transition from one operating mode, for example a bus protocol or a clock frequency domain, to another operating mode.
[0042] The processing unit(s) 110 generate and send write access transactions to one or more of the different blocks 104, 106, 108, 112, 114, 116, 118 via bus 140, for example, by passing through one of the gateways. During transit through the gateway, the write access request transaction (Write Bufferable Access) is, for example, temporarily stored in the respective gateway. In an example, if the write access fails, a bus error is generated, for example, by the block receiving the write access transaction.
[0043] Figure 2 represents an example of a bus error handling method.
[0044] In the example shown, the processing unit 110 includes, for example, two operating systems 214 (SEC OS) and 212 (NS OS). The SEC OS operating system has a higher level of access rights restriction (secure, SEC) than the NS OS operating system (non-secure, NS).
[0045] In a first step 230 (NS Write Bufferable Access), a write access transaction is generated by the operating system 212 for example block 116. In this example, this transaction is implemented in an NS environment.
[0046] In a second step 232 (Buffered Access), this transaction passes through the respective gateway (AHB2AHB Bridge) 160, 162, 164, 166, 168. In the example shown, the gateway adapts the transaction, which is in AHB bus protocol, to the same AHB protocol having, for example, a different clock signal domain, for example, a different frequency. In this step, the transaction is buffered, that is, temporarily stored, by the gateway. After this buffering, or as soon as the first step 230 is completed, the processing unit 110 performs, for example, other tasks that are no longer related to the gateway.
[0047] In a third step 234 (NS Write access), the transaction is implemented from the gateway to, for example, block 116.
[0048] In response, in a fourth step 236 (Bus error), if the write access transaction fails, a bus error is sent from block 116 to gateway 160.
[0049] In a fifth step 240 (IRQ), upon receiving this error, the gateway generates, in other words raises, an interrupt (IRQ, Interupt ReQuest) to the default 214 SEC OS operating system and not to the operating system with the NS environment of the initial transaction. This This is due, for example, to the fact that the bus error may be caused by an attack, and that by default interrupts are directed to operating system 214. This interrupt can be software or hardware-based. The interrupt manifests itself, for example, as a change in a bit or a byte of a register. The NS OS operating system, which initiated the original transaction, does not receive the bus error and therefore cannot implement any repair or targeted action. The fact that the processing unit 110, following the write access request transaction, has performed other tasks unrelated to the gateway 160, means that neither the 214 SEC OS nor the 212 NS OS operating systems will receive the bus error.Since the 214 SEC OS operating system has no information other than the interrupt raised by the gateway, which could correspond to an attack, it will implement, for example, a complete reset of microcontroller 100, which is detrimental to the user experience, for example.
[0050] Figure 3 represents another example of a bus error handling method. The example in Figure 3 is similar to that in Figure 1 except that instead of having one processing unit implementing two operating systems under different environments, the microcontroller 100 comprises two processing units 312 (CPU1) and 314 (CPU2) which implement operating systems 212 and 214 respectively. In one example, the processing unit 110 comprises two regions containing processing units 312 and 314 respectively.
[0051] In the illustrated example, the write access transaction in step 230 is generated by the operating system 212 under NS environment. Steps 232, 234 and 236 are then similar to those in the example in [Fig.2].
[0052] After step 236, in a step 340 (IRQ), upon receiving the bus error, gateway 160 generates by default an interrupt (IRQ) to the 214 SEC OS operating system of the processing unit 314 and not to the 212 NS operating system which nevertheless has the same NS environment as that of the initial transaction.
[0053] Furthermore, the 212 NS OS operating system, which initiated the initial transaction, does not receive the bus error and therefore cannot implement any repair or targeted action. For the same reasons as in [Fig. 2], neither the 214 SEC OS nor the 212 NS OS operating systems will receive the bus error. Since the 214 SEC OS operating system has no information other than the interrupt raised by the gateway, it will, for example, perform a complete reset of microcontroller 100.
[0054] To overcome these drawbacks, the described embodiments provide a bus error handling method, in which one or more first Characteristics of a first write bufferable access transaction destined for functional unit 116 and passing through gateway 160 are stored, and in which, in the presence of a bus error sent by functional unit 116: - one or more secondary features related to said error are stored; - the gateway generates a first interrupt which it transmits, along with said first and second characteristics, to a management unit; and - the management unit generates at least one second interrupt to the processing unit (110, 312, 314) depending on the first and / or second characteristics.
[0055] The operating system initiating the initial transaction can thus have access to information relating to the bus error and can thus implement remedial or targeted actions without having to completely reset the microcontroller.
[0056] Storing the first and second characteristics makes it possible to create an error report for the implementation of certifications such as the SESIP (Security Evaluation Standard for loT Platforms) certification.
[0057] The operating system that issued the initial write access transaction, whether it is of NS or SEC access restriction level, will be able to receive the second interrupt related to that transaction.
[0058] Finally, an advantage of such a process is that it is possible to retain existing gateways without having to develop new ones.
[0059] Figure 4 represents a bus error management method according to one embodiment. The processing unit 110 of Figure 4 is similar to that of Figure 2.
[0060] In a first step 410 (NS Write Bufferable Access), a write access transaction is generated by the operating system 212 for, for example, block 116. In this example, this transaction is implemented in an NS environment. In the example shown, N write access transactions are generated, for example successively, by the operating system 212 for, for example, block 116 or other blocks, and transiting respectively through N gateways (Bridge 0 AHB2AHB, Bridge 1 AHB2AHB,..., Bridge N AHB2AHB).
[0061] In a second step 412 (Access buffered + store information on the access (SEC / NS + debug info)), this transaction passes through a gateway (Bridge 0 AHB2AHB) respective 160, 162, 164, 166, 168. In the example shown, the gateway adapts the transaction, which is in AHB bus protocol, to the same AHB protocol having, for example, a different clock signal domain, for example, a different frequency. In this step, the transaction is buffered, that is to say- This information is temporarily stored by the gateway. After this buffering, or as soon as the first step 410 is completed, the processing unit 110 performs other tasks that are no longer related to the gateway. During this step, one or more initial characteristics of the write transaction, or write access, are stored, for example, in the gateway. These initial characteristics may represent, for example, the access restriction level (NS / SEC) associated with the transaction environment. The initial characteristics may also include information useful for error resolution (debugging).
[0062] In a third step similar to step 234, the write access transaction is implemented from the respective gateway to, for example, block 116.
[0063] In response, in a fourth step similar to step 236 (Bus error), if the write access transaction fails, a bus error, possibly accompanied by one or more secondary features, is sent from block 116 to the respective gateway. In this step, one or more secondary features related to this error are stored, for example, in the respective gateway. These secondary features include, for example, an addressing mode restriction level (unpriv, Priv), an address, or a master or slave function identifier.
[0064] In a fifth step 416, 420, 430 (NS / SEC, and debug information), after receiving the respective bus error, each gateway generates an interrupt 418 IRQ(0), 422 IRQ(1)... 432 IRQ(N) which it transmits, for example with the first and second characteristics, to a management unit 440. The management unit 440 is for example a Smart Bridge System (SBS).
[0065] In the example shown, the management unit includes registers 450 (B 1ER), 452 (BISR), 454 (BICR), 456 (BESR) and 458 (BEADDR) dedicated to storing the characteristics of the first and second following an NS access restriction level write access transaction and different registers 442 (SBIER), 444 (SBISR), 446 (SBICR), 447 (SBESR) and 448 (SBEADDR) dedicated to storing the characteristics following a SEC access restriction level write access transaction. In other words, if the NS / SEC access restriction level of the operating system, or environment, that generated the transaction in step 410 is of type NS, then the first and second characteristics transmitted by the respective gateway are stored in management unit 440 in the registers associated with that same NS access restriction level, and similarly for the SEC level.
[0066] In a sixth step subsequent to the fifth step, the management unit 440 generates at least a second interrupt (SBS_IRQ_NS, SBS_IRQ_SEC) at destination of the processing unit 110 based on the first and / or second characteristics stored in one or more of the gateways and / or in the management unit 440.
[0067] If the interrupt, generated by one of the gateways and stored, for example, via a flag raised in one of the registers of the management unit 440, is initially linked to a transaction having an access restriction level of NS, then the second interrupt SBS_IRQ_NS is sent from the management unit 440 to the operating system 212. If the interrupt is initially linked to a transaction having an access restriction level of SEC, then the second interrupt SBS_IRQ_SEC is sent from the management unit 440 to the operating system 214.
[0068] This second interrupt can contain, for example, the NS / SEC access restriction level of the initial transaction but also the second characteristics related to the corresponding bus error.
[0069] Register 450, for example, has read and write access only when the access restriction level is NS. In one example, certain bits or bytes of register 450 are written in software to enable or disable the second interrupt SBS_IRQ_NS. A value of 0 means that this second interrupt SBS_IRQ_NS is disabled and, in this case, the second interrupt will not be reported to the relevant processing unit when a first interrupt has been initiated by a gateway. A value of 1 means that the second interrupt SBS_IRQ_NS is enabled and, in this case, the interrupt will be reported to the relevant processing unit when an interrupt has been initiated by a gateway.
[0070] Register 452, for example, is read-only when the access restriction level is of type NS. In one example, a bit or byte of register 452 is dedicated to storing the flag associated with the raising of the second interrupt, SBS_IRQ_NS. A value of 1 indicates, for example, that the SBS_IRQ_NS interrupt has been raised to the relevant processing unit. A flag value of 0 indicates, for example, that the SBS_IRQ_NS interrupt has not been raised to the relevant processing unit.
[0071] Register 454, for example, is write-only when the access restriction level is NS. In one example, a value of 1 clears the interrupt flag stored in register 452 and also clears registers 456 and 458. In another example, writing 0 has no effect.
[0072] Register 456, for example, is read-only when the access restriction level is NS. It stores the characteristics associated with the transaction requesting write access with NS access restriction. This register is, for example, valid only when the respective gateway has generated an associated interrupt. This relates to NS access restriction, that is, when a flag is raised. For example, certain bits or bytes of register 456 are dedicated to storing the identifier of the gateway that transmitted the interrupt. Other bits or bytes of register 456 are dedicated to storing the addressing mode restriction level (unpriv, priv) of the functional unit, gateway, or operating system that initiated the transaction. Finally, some bits or bytes of register 456 are dedicated to storing the identifier of the master / slave element or the functional unit.
[0073] Register 458, for example, is read-only when the access restriction level is NS. This register 458 is, for example, written to in hardware when a gateway raises an error. It is, for example, reset in software via register 454. It stores, for example, the address of the write access request transaction with the NS access restriction level that generated the bus error.
[0074] Registers 442, 444, 446, 447, and 448 are similar respectively to registers 450, 452, 454, 456, and 458 except that the criteria of the NS access restriction level parameters are replaced by the SEC access restriction level.
[0075] The processing unit or the operating system receiving the second interrupt may, for example, use the first and second characteristics stored in the corresponding gateway or in the registers of the management unit 440 or in the second interrupts to populate an error report and / or implement specific actions. These actions include, for example, reconfiguring the function block 116 that generated the bus error, restarting the initial transaction, or resetting all or part of the microcontroller.
[0076] Figure [Fig. 5] represents a bus error management method according to another embodiment.
[0077] The process of [Fig.5] is similar to that of [Fig.4] except that, in step 410 of [Fig.5], the write access transaction is issued by an operating system similar to operating system 214 which is of access restriction level SEC or by an operating system similar to operating system 212 which is of access restriction level NS.
[0078] In the sixth step, the second interrupt generated by the management unit 440 (SBS_IRQ_NS,SBS_IRQ_SEC) is either directed to the operating system 212 of the processing unit 312, or to the operating system 214 of the processing unit 314 depending on the first and / or second characteristics stored in one or more of the gateways and / or in the management unit 440.
[0079] Various embodiments and variations have been described. A person skilled in the art will understand that certain features of these various embodiments and Variants could be combined, and other variants will appear to the person in the trade. In particular, other types of registers can be implemented in the 440 management unit to store other types of features that could help in troubleshooting bus errors.
[0080] Finally, the practical implementation of the described embodiments and variants is within the grasp of a person skilled in the art, based on the functional specifications given above. In particular, with regard to the NS / SEC access restriction level, a person skilled in the art can implement the storage in the gateway(s) or in the management unit 440 of other characteristics such as a priv / unpriv addressing restriction level of the operating system that issued the initial transaction. In one example, the gateway(s) could be integrated into the management unit so as to facilitate the storage and transmission of the characteristics of write access transactions, as well as characteristics related to bus errors.
Claims
Demands
1. A bus error handling method, wherein one or more first features of a first write transaction (410) destined for a functional unit (116) and passing through a gateway (160,162,164,166,168) are stored, and wherein in the presence of a bus error sent by the functional unit (116): - one or more second features related to said error are stored; - the gateway (160,162,164,166,168) generates a first interrupt (416,420,422,430) which it transmits with said first and second features to a management unit (440); and - the management unit (440) generates at least one second interrupt (SBS_IRQ_NS,SBS_IRQ_SEC) to a processing unit (110,312,314) depending on the first and / or second characteristics.
2. A method according to claim 1, wherein the processing unit runs several operating systems (212,214) and the second interrupt is directed to one of these operating systems according to the first and / or second characteristics.
3. Method according to claim 2, wherein the second interruption is intended for one of several processing units (312,314) depending on the first and / or second characteristics.
4. A method according to any one of claims 1 to 3, wherein the first features are stored in the gateway (160,162,164,166,168).
5. Method according to any one of claims 1 to 4, wherein the second features are stored in the gateway (160,162,164,166,168).
6. A method according to any one of claims 1 to 5, wherein the management unit (440) stores the first and second features.
7. A method according to claim 6, wherein the management unit (440) stores the first and second characteristics after the transmission of the first interrupt transaction (416,420,422,430) and the first and second characteristics by the gateway.
8. Method according to claim 6 or 7, wherein the first and second characteristics are stored in one or more registers of the management unit (440).
9. A method according to any one of claims 1 to 8, wherein the first feature(s) include an access restriction level (NS, SEC).
10. A method according to any one of claims 1 to 9, wherein the second feature(s) include an addressing mode restriction level (unpriv, Priv).
11. A method according to any one of claims 1 to 10, wherein the second feature or features comprise an address.
12. A method according to any one of claims 1 to 11, wherein the second feature or features comprise an identifier.
13. A method according to any one of claims 8 or 9 to 12 in their dependence on claim 8, wherein one of the registers is configured to store a value representative of the presence of a transmission of the first interrupt transaction (416,420,422,430).
14. A method according to any one of claims 8 or 9 to 13 in their dependence on claim 8, wherein one of the registers is configured to store the first feature(s) as well as the second feature(s).
15. A method according to any one of claims 8 or 9 to 14 in their dependence on claim 8, wherein one of the registers is configured to store an address related to the first write access transaction (410).
16. A method according to any one of claims 9 to 15 in their dependence on claim 8, wherein the management unit (440) stores the first and second feature(s) in registers having an access restriction level (NS, SEC) similar to the first feature(s).
17. A method or microcontroller according to any one of claims 9 to 16 in their dependence on claim 8, wherein the management unit (440) transmits said second transaction interrupt (SBS_IRQ_NS,SBS_IRQ_SEC) to the processing unit (110, 312, 314) having an access restriction level (NS, SEC) similar to the access restriction level (NS, SEC) associated with the first characteristic(s).
18. A method according to any one of claims 1 to 17, wherein, following the transmission of the second interrupt transaction (SBS_IRQ_NS,SBS_IRQ_SEC), the processing unit (110,312,314) having received said second interrupt transaction performs one action among a reconfiguration of the functional unit (116), a reset of the first or second transaction, a reset of the microcontroller (100), and a writing of an error report.
19. Microcontroller comprising at least one bus, one functional unit (116), one gateway (160,162,164,166,168), one management unit (440) and one processing unit (110,312,314), and configured to implement the method according to any one of claims 1 to 18.