Data processing device
The data processing device addresses the challenge of ensuring operational safety and data security by allowing data processing components to exchange synchronization information and configure their processing based on a writable memory, thereby reducing costs and maintaining system reliability.
Patent Information
- Application Number
- JP2024213953
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-12-06
- Publication Date
- 2025-06-19
AI Technical Summary
Data processing devices in critical applications face challenges in ensuring operational safety and data security for all components, as providing comprehensive safety and security measures across all components is prohibitively costly. This necessitates a method to separate components with and without these measures while maintaining system reliability and safety.
A data processing device with multiple components that exchange synchronization information in pairs at predetermined points, utilizing a writable configuration memory to determine if synchronization information exchange is necessary for all synchronization points, allowing each pair of components to decide whether to continue processing beyond the synchronization point based on the configuration memory's content.
This approach enables the data processing device to maintain operational safety and data security while reducing costs by allowing components to continue processing based on configured requirements, ensuring reliable operation even in early start phases where error correction mechanisms are not yet available.
Smart Images

Figure 2025092497000001_ABST
Abstract
Description
Technical Field
[0001] Embodiments generally relate to data processing devices.
Background Art
[0002] Data processing devices used in critical applications, such as control devices for vehicles, generally have high requirements for operational safety and, in some cases, data security. However, providing means to ensure high operational safety and / or data security for all data processing components involved can be prohibitively costly. Therefore, such means are generally provided only for the data processing components that are necessary for the operational safety of the overall system and, in some cases, data security. However, in this case, it is desirable to separate, to some extent, between the data processing components provided with such means and those not provided with such means, so that the operational safety of the entire system and, in some cases, data security are not impaired. Nevertheless, the data processing components should cooperate reliably with respect to the given requirements for operational safety and data security for a given use case.
[0003] According to one embodiment, there is provided a data processing device having a plurality of data processing components configured to exchange their respective synchronization information in pairs at predetermined synchronization points, and a writable configuration memory configured to store, for each of a plurality of reset types, whether the exchange of each synchronization information is necessary for all of the synchronization points, whereby each pair of data processing components is provided with a data processing device that is permitted to continue its processing beyond the synchronization point. The data processing component is configured to further continue or not continue its processing beyond the synchronization point according to the content of the configuration memory when the exchange of synchronization information is not performed.
[0004] The actual sizes are not reproduced in the drawings, which should be used to illustrate the basic concepts of various different embodiments. The following describes various different embodiments in relation to the following drawings.
Brief Description of the Drawings
[0005]
Figure 1
Figure 2
Figure 3
Figure 4
Embodiments for Carrying Out the Invention
[0006] The following detailed description relates to the accompanying drawings that illustrate details and examples. These examples are described in detail so that those skilled in the art can implement the present invention. Other embodiments are also contemplated, and the examples can be changed in terms of structure, logic, and electrical aspects without departing from the subject matter of the present invention. The various different embodiments do not necessarily exclude each other, and the various different embodiments can be combined with each other, thereby obtaining new embodiments. Within the framework of this specification, the terms "joined", "connected", and "coupled" are used to represent both direct and indirect joining, direct or indirect connection, and direct or indirect coupling.
[0007] FIG. 1 shows a data processing device 100.
[0008] The data processing device 100 has a plurality of data processing components 101 associated with various different (operational safety and data security) domains 102, and these data processing components 101 differ in that respective requirements regarding operational safety and data security are associated therewith, and these requirements are at least partially different between domains 102. For example, the data processing device 100 is an electronic control unit (ECU, which stands for Electronic Control Unit in English) of a vehicle, and for one of the plurality of domains 102, a specific ASIL (Automotive Safety Integrity Level) or CAL (Cybersecurity Assurance Level), for example, ASIL-D for a function critical to passenger safety, is required, whereas for another one of the domains 102, it is a "QM" (Quality Management) domain with few operational safety requirements and data security requirements. However, the data processing device 100 may be another type of data processing device 100 having various different domains with respective (at least partially different) operational safety requirements and data security requirements, for example, a microcontroller for another use, a SoC (System on Chip) for any use, etc.
[0009] Accordingly, each domain 102 provides a specific function, and here, this should be done such that specific operational safety requirements and data security requirements are met by each domain 102, as exemplified by respective specifications and / or standards, for example, ISO26262, ISO21434, or IATF61508. Each domain 102 is here a combination of hardware and software, that is, specific software, for example, firmware, an operating system (OS), or respective OS components, and one or more applications (or application components) are executed by the data processing components 101 belonging to each domain 102.
[0010] To meet the respective operational safety requirements and / or data security requirements for each individual domain 102, generally, various different mechanisms (redundant processing, e.g., lockstep, error correction mechanisms (such as EDC (Error detection and correction), etc.)) are available.
[0011] However, if the requirements of two domains 102 are different, separation of the two domains 102 is necessary, and as a result, a domain that meets only fewer requirements regarding operational safety requirements and / or data security requirements (for example, because there is an unprotected communication channel between domains, or because the first domain depends on the second domain, and an attack on the second domain is successful, causing the first domain to be disabled) can have an adverse impact on the operational safety and / or data security of another domain, such that the operational safety requirements and / or data security requirements of another domain are no longer met.
[0012] Therefore, difficulties arise when cross-coupling between domains 102 is required. This is complicated by the fact that high availability is required for many domains 102 (i.e., for the functions provided by them), even when another domain 102 fails. For example, the steering of an autonomous vehicle should function even if secure communication (in the sense of data security) between the domain 102 that calculates the steering signal and each actuator is currently impossible because the domain 102 responsible for secure communication (e.g., encryption) has failed. In the absence of cross-coupling, respective means can be provided for each individual domain, thereby meeting the respective operational safety requirements and / or data security requirements. Correspondingly, it may be desirable to reduce cross-coupling, i.e., to keep the domains 102 separated from each other as much as possible.
[0013] When the data processing apparatus 100 is newly started, this initial state becomes particularly important. That is, this initial state functions as a trust base ('Root of Trust', 'Root of Integrity') for subsequent software components in the process. This is particularly important when performing critical tasks (for example, tasks critical to the operational safety in a vehicle).
[0014] When the domain 102 has respective mechanisms (lockstep and error correction, etc.) for data security and operational safety, as described above, if the cross-coupling to another domain 102 without these means is kept sufficiently low (due to fewer requirements), the operational safety and data security of each domain 102 can be maintained sufficiently low. Thus, selectively preventing or reducing cross-coupling between domains is desirable in the already early start phase (i.e., the 'pre-operating system phase' (or 'pre-OS phase')), that is, the phase until the loading after the start or reset of software, generally the operating system component. However, it should be noted here that in the early start phase, a predetermined means, for example, an error correction mechanism, is not yet provided (i.e., not yet ready to function). Therefore, in the early start phase, there are special situations where a special dedicated approach is desirable to meet various different operational safety requirements and / or data security requirements.
[0015] The data processing device 100 may enter the pre-OS boot state not only after being switched on (Power-On-Reset (PORST)), but also after a software reset that can often be executed, for example, as a response to an error (e.g., multiple times during the vehicle control cycle). According to various different embodiments, these two cases are distinguished as will be described in more detail below. This is because, for example, during each software reset, there is no need to check the integrity of the program code (e.g., because the previous test results are still valid).
[0016] According to various different embodiments, an approach is provided that enables error handling during the early start phase, thereby fulfilling certain availability requirements. For example, by the control device, at least in a reduced form until the next reset (e.g., when the QM domain to which the encryption task is delegated fails), it is guaranteed that critical functions for passenger safety (e.g., steering without communication encryption) can be provided. However, depending on the application in which the data processing device 100 is used, there may be various different operational safety requirements and / or data security requirements (e.g., encryption is critical for many applications, while in another application, its failure is tolerated for basic functions (e.g., steering) that should be guaranteed). Therefore, according to various different embodiments, it is specified that for each type of reset (e.g., power-on reset or software reset), it is possible to configure which domain 102 is critical and which domain 102 is not. This is manifested in the fact that it is possible to configure whether a domain 102 has to wait for synchronization with another domain 102 before proceeding with its respective processing (e.g., starting with the loading of its own operating system).
[0017] FIG. 2 shows an example of the early start phase according to one embodiment.
[0018] In this embodiment, there are two domains. The first domain belongs to the first processor 201, and the second domain belongs to the second processor 202. For example, the first processor 201 provides a specific "host" function, and the second processor 202 provides a (data) security function (e.g., encryption of control signals) that can be used by the first processor 201.
[0019] The early start phase starts with a reset, which may be a power-on reset or a software reset. In this case, the two processors 201, 202 operate according to the firmware 203 of the data processing device 100 (stored in the non-volatile memory of the data processing device 100, which is, for example, one of the components 101).
[0020] The early start phase ends with the loading of software 204 (an operating system component or an application).
[0021] At specific synchronization points (which are defined in the firmware 203), a synchronization 205 is performed between the two processors 201, 202, that is, one communication each for the synchronization of the two processors 201, 202. According to various different embodiments, for each reset type (for example, power-on reset and software reset), it is specified that it should be configurable which part of the synchronization points defined (in the firmware 203) is emphasized (for example, no part is emphasized, some or all are emphasized), whereby the two processors are permitted to proceed with their processing. For a specific type of reset, if the synchronization points are defined as a blocked state in this sense, in each early start phase after this type of reset, the two processors 201, 202 must reach these synchronization points (and thus each step of their respective processing) before the two processors 201, 202 are permitted to continue their respective processing (that is, the corresponding synchronization 205 is performed).
[0022] The way for synchronization can, on the one hand, (for the reasons mentioned above) provide or be able to provide a separation of the two processors 201, 202 that depends on the reset type, and can also comply with the timing requirements of each reset type, and is ultimately configured to achieve a consistent state of the data processing device 100 at the end of the early start phase. The configurable dependencies (and thus couplings) of the two domains (here the two processors 201, 202) can avoid restrictions on availability (if recognized as correct from the perspective of operational safety and data security).
[0023] For the synchronization 205, for example, for each of the processors 201, 202, one or more registers (mailboxes in English) for data exchange are provided, and only write access or read access can be performed on this register according to the communication direction. Each of the processors 201, 202 writes synchronization information to the register assigned to itself when it reaches its respective processing step, and the other processor 201, 202 can read this register to check whether the processor 201, 202 has reached a specific synchronization point. Thereby, a unidirectional communication path protected between domains, and thus a high degree of separation of the two domains can be achieved.
[0024] The configurable dependencies between the two domains are achieved, for example, by being able to enter in the non-volatile memory of the data processing device 100 (for example, an area of the flash memory of the data processing device 100) which of a plurality of configuration options (for example, which may be the manufacturer of the vehicle in which the data processing device 100 is used, for example, by the user) should be adhered to. The configuration options / configurable variants are defined as unchangeable for the user via the firmware control flow. The configuration options can be set individually for each of the plurality of reset types (that is, determined by writing correspondingly to the non-volatile memory). By setting the dependencies, that is, setting which synchronization points are in the blocked state (after the reset of each reset type), it becomes possible to set the sensitivity of the domain to the failure of another domain.
[0025] Table 1 shows examples of possible settings for each of the following reset types · “Cold PORST” (CPORST): Cold power-on reset, that is, also called cold start or cold start reset, the power-on reset when power supply to the data processing device 100 starts · "Warm PORST" (WPORST): A power-on reset triggered via a pin of the data processing device 100, also known as warm power-on reset, i.e., warm start or warm start reset. · "SysRST": A software reset triggered by the operating system. · "AppRST": A software reset triggered by an application.
Table 1
[0026] The configuration area in the non-volatile memory for selecting configuration options for each reset type contains 12 bits (0 to 11), with 3 bits provided for each reset type. These bits enable the determination of one of the following three configuration options. The configuration (i.e., the 3-bit configuration word for each) also represents the order in which the domain resumes its processing after the early start phase in this embodiment. · "Foreground" (bit combination 100): All synchronization points are in a blocked state (i.e., "foreground" means "in a blocked state" in this embodiment), and the domain adheres to the order (the "enforced sequencing") defined (e.g., in the firmware 203) after the end of the early start phase. For example, the second processor 202 first starts executing the program code defined by the user (e.g., to configure secure communication for the first processor 201). · "Background Critical Block State" (bit combination 010): The synchronization points defined as critical (in firmware 203) are in a block state, and the domains can continue in any order at the end of the early start phase as if caused by the execution time of the program code (firmware) executed by them ("natural sequencing" in English). · "Background Non-Block State" (bit combination 001): There are no synchronization points in a block state, and the domains can continue in any order at the end of the early start phase as if caused by the execution time of the program code (firmware) executed by themselves.
[0027] Any bit combination other than these three bit combinations is invalid and results in an error state.
[0028] Critical synchronization points generally fall into two classes, namely, the start of hardware functions commonly (i.e., cross-domain) used and synchronization events (i.e., communication between program codes in execution). One example of a commonly used hardware function may be, for example, the non-volatile memory of a data processing device. This is because further processing may be impossible, for example, if the non-volatile memory does not function. In contrast, synchronization with a random number generator may not be critical in some cases. This is because random numbers can be omitted (for example, by omitting a certain degree of data security acceptable for the use of the present invention). The non-volatile memory and the random number generator are here examples of components commonly used by multiple (different) domains. By setting whether synchronization with such (for example, commonly used) components is essential (i.e., in a block state) or not, specific (depending on the reset type) error handling of these components becomes possible in the early start phase.
[0029] Figure 3 shows the scalability of dependencies between two domains using the above configurability for the synchronization points "block state", "critical block state", and "non-block state", and the order after the early start phase.
[0030] For the setting on the left (marked by a dashed line), i.e., in the non-block state, what is guaranteed by the natural order is that even if an error occurs in another domain, the error-free domain can complete the early start phase. That is, in the error-free domain, it is guaranteed that the execution of the next software level (e.g., bootloader, application, OS startup) is achieved. What this means is that the processing of the domain with an error (from ignoring the error to the emergency mode) can be flexibly configured at this software level. In such a setting, there are two aspects that can be problematic. That is, i. the system response time for potentially critical events is delayed (by the "shift" from the early start phase to the subsequent phase), ii. the detection / heuristic regarding randomized / intentionally introduced errors is reduced.
[0031] The middle (marked with a dashed line) setting, i.e., the critical block for PORST, the forced order, and the natural order for SW reset (i.e., the mixed setting for the order), enables early error handling (i.e., critically in the sense of the execution of two domains) for commonly used components, and in the case of PORST, a defined sequence for starting subsequent software components, and in this case, in software reset, the entire system is not made completely dysfunctional due to domain failures. For example, during software reset (by vehicle control), in a vehicle, a mode with restricted functionality (but with important driving functions maintained) can be implemented. The right (continuously enclosed) setting enables maximum error detection, which is obtained with a decrease in availability and is thus often not a good compromise in applications.
[0032] In summary, according to various different embodiments, a data processing device as shown in FIG. 4 is provided.
[0033] FIG. 4 shows a data processing device 400 according to one embodiment.
[0034] The data processing device 400 has a plurality of data processing components 401, and these data processing components 401 are configured to exchange their respective synchronization information at pre-set synchronization points (for each pair, and in some cases individually) with each other in pairs (e.g., by the firmware of the data processing device). That is, each synchronization point is defined, for example, for each pair of data processing components.
[0035] The data processing apparatus 400 further includes a writable configuration memory 402 (e.g., one or more configuration registers) by a user, and the configuration memory 402 is configured to store, as (memory) contents for each of the plurality of reset types, whether the exchange of respective synchronization information is necessary for all synchronization points, whereby each pair of data processing components is permitted (or not permitted) to continue its processing beyond its synchronization point.
[0036] The data processing component 401 is configured to further continue or not continue its processing beyond the synchronization point when the exchange of synchronization information is not performed according to the content of the configuration memory.
[0037] According to various different embodiments, the synchronization points that must be emphasized by data processing components (such as processors, memories, control circuits, etc.) are configurable, which enables compliance with the requirements regarding the operational safety and / or data security of each application case.
[0038] Hereinafter, various different examples will be shown.
[0039] Example 1 is the data processing apparatus 400 as described in relation to FIG. 4.
[0040] Example 2 is the data processing apparatus described in Example 1, and the configuration memory is configured to store, for each of the plurality of reset types, whether the exchange of respective synchronization information is necessary for all synchronization points or only for a preset portion of the synchronization points, whereby each pair of data processing components is permitted to continue its processing beyond the synchronization point.
[0041] Example 3 is the data processing apparatus described in Example 2. When it is stored in the configuration memory that the exchange of respective synchronization information is necessary only for a preset part of the synchronization points, even when the respective synchronization information is not exchanged, each data processing component is configured to continue its processing after reaching the synchronization point after reset. Thus, each pair of data processing components is permitted to continue its processing beyond the synchronization point, and the reached synchronization point does not belong to the preset part.
[0042] Example 4 is the data processing apparatus described in Example 2 or 3, and is a data processing apparatus having firmware that determines to which preset part of the synchronization points each synchronization point belongs.
[0043] Example 5 is the data processing apparatus described in any one of Examples 1 to 4, and the configuration memory is configured to store for each of a plurality of reset types whether the exchange of respective synchronization information is necessary for all of the synchronization points or not necessary for any of the synchronization points. Thus, each pair of data processing components is permitted to continue its processing beyond the synchronization point.
[0044] Example 6 is the data processing apparatus described in Example 5. When it is stored in the configuration memory that the exchange of respective synchronization information is not necessary for any of the synchronization points, even when the respective synchronization information is not exchanged, each data processing component is configured to continue its processing after reaching the synchronization point after reset. Thus, each pair of data processing components is permitted to continue its processing beyond the synchronization point.
[0045] Example 7 is the data processing apparatus described in any one of Examples 1 to 6, and the plurality of reset types include a cold start reset, a warm start reset, and / or a software reset.
[0046] Example 8 is a data processing apparatus according to any one of Examples 1 to 7, and the content of the configuration memory is at least partially different for different reset types.
[0047] Example 9 is a data processing apparatus according to any one of Examples 1 to 8, and after one of the synchronization points or after another preset synchronization point, whether the order in which the data processing components continue their processing must follow a preset order or is permitted to be performed as determined by their respective processing durations is stored for each reset type of a plurality of reset types in the configuration memory, and the data processing components are configured to continue their processing according to the content of the configuration memory after the synchronization point or another synchronization point.
[0048] Example 10 is the data processing apparatus according to Example 9, and the synchronization point or another synchronization point is a synchronization point at the end of the pre-operating system phase of the data processing apparatus.
[0049] Example 11 is the data processing apparatus according to Example 9 or 10, and the processing after the synchronization point or another preset synchronization point includes loading an operating system component or an application.
[0050] Example 12 is a data processing apparatus according to any one of Examples 1 to 11, and at least a part of the data processing components is a processor.
[0051] Example 13 is a data processing apparatus according to any one of Examples 1 to 12, and the data processing components are at least partially provided with various different means for generating operational safety and / or data security.
[0052] Embodiment 14 is a data processing apparatus according to any one of Embodiments 1 to 13, and the data processing components are configured to exchange synchronization information via one or more synchronous memories that they write to and read from themselves.
[0053] Embodiment 15 is a data processing apparatus according to Embodiment 14, and for each pair of data processing components, a first synchronous memory and a second synchronous memory are provided. The first synchronous memory can be written only by the first data processing component of the pair, and the second synchronous memory can be written only by the second data processing component of the pair.
[0054] Particularly, although the present invention has been shown and described in connection with specific embodiments, those skilled in the art will understand that numerous changes can be made to the configuration and details without departing from the essence and scope of the present invention as defined by the following claims. Therefore, the scope of the present invention is determined by the appended claims, and it is intended to include all changes that fall within the semantic or equivalent scope of the claims.
Description of Reference Numerals
[0055] 100 Data processing apparatus 101 Data processing component 102 Domain 201, 202 Processor 203 Firmware 204 Software 205 Synchronization 400 Data processing apparatus 401 Data processing component 402 Configuration memory
Claims
1. A data processing device, comprising: a plurality of data processing components configured to exchange respective synchronization information with each other in pairs at a predetermined synchronization point; a writeable configuration memory configured to store, for each of a plurality of reset types, whether or not an exchange of each of the synchronization information is required for all of the synchronization points; whereby each said pair of data processing components is permitted to continue its processing beyond said synchronization point; said data processing component being configured to, if no exchange of synchronization information occurs, continue or not continue its processing further beyond a synchronization point according to the contents of said configuration memory; Data processing device.
2. said configuration memory being configured to store for each of a plurality of reset types whether the respective exchange of said synchronization information is required for all of said synchronization points or only for a pre-defined portion of said synchronization points, whereby each pair of data processing components is permitted to continue their processing beyond said synchronization points; 2. The data processing device according to claim 1.
3. said data processing components are configured to continue their processing after a reset and after reaching a synchronization point even if said respective synchronization information has not been exchanged, if it is stored in said configuration memory that said exchange of respective synchronization information is necessary only for a predefined part of said synchronization point, whereby each pair of data processing components is allowed to continue their processing beyond said synchronization point and said reached synchronization point does not belong to a predefined part; 3. The data processing device according to claim 2.
4. the data processing device having firmware that defines which synchronization points belong to the predefined portion of synchronization points; 4. The data processing device according to claim 2 or 3.
5. said configuration memory being configured to store for each of a plurality of reset types whether an exchange of said respective synchronization information is required for all of said synchronization points or for none of said synchronization points, thereby permitting each pair of data processing components to continue their processing beyond a synchronization point; 5. A data processing device according to any one of claims 1 to 4.
6. if it is stored in said configuration memory that the exchange of the respective synchronization information is not required for any of said synchronization points, said data processing components are configured to continue their processing after resetting and reaching a synchronization point even if the respective synchronization information has not been exchanged, thereby allowing each said pair of data processing components to continue their processing beyond said synchronization point; 6. The data processing device according to claim 5.
7. The reset types include a cold start reset, a warm start reset, and / or a software reset.
7. A data processing device according to any one of claims 1 to 6.
8. the contents of the configuration memory are, at least in part, different for different reset types; A data processing device according to any one of claims 1 to 7.
9. the configuration memory is further configured to store for each of a plurality of reset types whether an order in which the data processing component continues its processing after one of the synchronization points or after another one of the preset synchronization points must follow a preset order or is allowed to be performed as caused by a respective processing duration, and the data processing component is configured to continue its processing after the synchronization point or the other one of the synchronization points according to the contents of the configuration memory.
9. A data processing device according to any one of claims 1 to 8.
10. the synchronization point or the other synchronization point is a synchronization point at the end of a pre-operating system phase of the data processing device; 10. The data processing apparatus according to claim 9.
11. the processing after the synchronization point or the other predetermined synchronization point includes loading an operating system component or an application; 11. A data processing device according to claim 9 or 10.
12. At least some of the data processing components are processors. A data processing device according to any one of claims 1 to 11.
13. said data processing component being at least partially equipped with different means for generating operational safety and / or data security, 13. A data processing device according to any one of claims 1 to 12.
14. the data processing components are configured to exchange the synchronization information via one or more synchronization memories to which the data processing components write and read; A data processing device according to any one of claims 1 to 13.
15. for each pair of said data processing components, a first synchronous memory and a second synchronous memory are provided, said first synchronous memory being writable only by a first data processing component of said pair, and said second synchronous memory being writable only by a second data processing component of said pair; 15. A data processing apparatus according to claim 14.