Bus access method in integrated circuits, integrated circuits, and electronic devices
The bus access method in integrated circuits controls access requests based on safety levels to prevent malfunctions in lower-safety domains from affecting higher-safety domains, ensuring operational integrity.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- XG TECHNOLOGIES PTE LTD
- Filing Date
- 2025-09-16
- Publication Date
- 2026-05-15
AI Technical Summary
A malfunction in a hardware unit in a lower-safety functional safety level domain can cause access requests to disrupt the normal operation of hardware units in a higher-safety functional safety level domain, compromising the security requirements of the higher-safety domain.
A bus access method that includes generating an access request, determining identification information, reading configuration information, and controlling the transmission of the request based on the safety levels of the involved domains to prevent disruptions.
The method effectively guarantees the normal operation of hardware units in higher-safety domains by controlling access requests, ensuring the safety requirements of these domains are met even in the presence of malfunctions in lower-safety domains.
Smart Images

Figure 2026079714000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of integrated circuits, and particularly to a bus access method in an integrated circuit, an integrated circuit, and an electronic device.
Background Art
[0002] A system on chip (SoC), also called an integrated circuit, can include a plurality of hardware units, and different functions can be realized by these plurality of hardware units. Due to different requirements for the safety of different functions, the integrated circuit can be divided into at least one functional safety level domain. Here, each functional safety level domain includes at least one hardware unit, and different functional safety level domains correspond to different safety levels, and this safety level represents the height of the requirement for the safety of the functions realized by each hardware unit in the corresponding functional safety level domain. The higher the safety level of the functional safety level domain, the higher the requirement for the safety of the functions realized by each hardware unit in this functional safety level domain. On the other hand, the lower the safety level of the functional safety level domain, the lower the requirement for the safety of the functions realized by each hardware unit in this functional safety level domain.
[0003] The hardware units in different functional safety level domains can access each other via a bus, thereby realizing communication between the corresponding functional safety level domains.
Summary of the Invention
Problems to be Solved by the Invention
[0004] If a hardware unit in a lower-safety functional security domain malfunctions, that unit can still transmit access requests to hardware units in a higher-safety functional security domain via the bus. This access request can prevent the hardware unit in the higher-safety functional security domain from functioning correctly, potentially compromising the security requirements of the higher-safety functional security domain.
[0005] This disclosure provides a bus access method for an integrated circuit, an integrated circuit, and an electronic device that can solve the problem described above, specifically addressing the issue where a malfunction in a hardware unit in a functional safety level domain with a lower safety level can prevent a hardware unit in a functional safety level domain with a higher safety level from operating normally. [Means for solving the problem]
[0006] A bus access method in an integrated circuit according to a first aspect of this disclosure includes the steps of: generating a first access request by a first hardware unit in a first functional safety level domain; determining first identification information of the first hardware unit based on the first access request; reading first configuration information from a register corresponding to a second hardware unit in a second functional safety level domain, wherein the first configuration information includes second identification information of a target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain; determining the authority of the first hardware unit to access the second hardware unit based on the first and second identification information; and controlling the transmission of the first access request from the bus to the second hardware unit based on the authority of the first hardware unit to access the second hardware unit.
[0007] An integrated circuit according to a second aspect of this disclosure includes a controller, a first hardware unit corresponding to a first functional safety level domain, a second hardware unit corresponding to a second functional safety level domain, and a register storing first configuration information corresponding to the second hardware unit, wherein the first configuration information includes second identification information of a target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain, the first hardware unit generates a first access request, the controller determines the first identification information of the first hardware unit based on the first access request, the controller further reads the first configuration information from the register, the controller further determines the authority of the first hardware unit to access the second hardware unit based on the first and second identification information, and the controller further controls the transmission of the first access request from the bus to the second hardware unit based on the authority of the first hardware unit to access the second hardware unit.
[0008] A computer-readable storage medium according to a third aspect of this disclosure stores a computer program for executing a bus access method in an integrated circuit according to a first aspect.
[0009] An electronic device according to a fourth aspect of this disclosure includes a processor and a memory for storing instructions that the processor can execute, and the processor reads and executes instructions that it can execute from the memory to realize a bus access method in an integrated circuit according to a first aspect, or the electronic device includes an integrated circuit according to a second aspect.
[0010] A fifth aspect of this disclosure provides a computer program product, wherein when instructions in the computer program product are executed by a processor, the bus access method for an integrated circuit according to the first aspect is executed. [Effects of the Invention]
[0011] According to the bus access method for integrated circuits described herein, when a first hardware unit in a first functional safety level domain transmits a first access request to a second hardware unit in a second functional safety level domain via a bus, the transmission of the first access request via the bus can be controlled based on the safety levels of the first and second functional safety level domains. If an abnormality occurs in a hardware unit in the functional safety level domain with a lower safety level among the first and second functional safety level domains, the transmission of the first access request from the bus to the hardware unit in the functional safety level domain with a higher safety level can be controlled. Therefore, by performing corresponding control on the first access request transmitted when an abnormality occurs in a hardware unit in the functional safety level domain with a lower safety level, the normal operation of the hardware unit in the functional safety level domain with a higher safety level can be effectively guaranteed, thereby guaranteeing the safety requirements of the functional safety level domain with a higher safety level. [Brief explanation of the drawing]
[0012] [Figure 1] This is a schematic diagram of the architecture of an integrated circuit relating to one exemplary embodiment of the present disclosure. [Figure 2] This is a schematic diagram of the architecture of an integrated circuit relating to another exemplary embodiment of the present disclosure. [Figure 3] This is a schematic diagram of the architecture of an integrated circuit relating to yet another exemplary embodiment of the present disclosure. [Figure 4] This is a schematic flowchart of a bus access method according to one exemplary embodiment of the present disclosure. [Figure 5] This is a schematic flowchart of a bus access method relating to another exemplary embodiment of the present disclosure. [Figure 6] This is a schematic flowchart of a bus access method relating to yet another exemplary embodiment of the present disclosure. [Figure 7]This is a schematic flowchart of a bus access method relating to yet another exemplary embodiment of the present disclosure. [Figure 8] This is a schematic diagram of the structure of an electronic device according to an exemplary embodiment of the present disclosure. [Modes for carrying out the invention]
[0013] Hereinafter, exemplary embodiments of this disclosure will be described in detail with reference to the drawings for the purpose of interpreting this disclosure. The embodiments described are only a selection of embodiments of this disclosure, not all embodiments, and this disclosure is not limited to exemplary embodiments.
[0014] The relative settings of the components and steps described in these embodiments, the numerical expressions and figures, do not limit the scope of this disclosure unless specifically described otherwise.
[0015] (Summary of the application) A system on a chip (SoC), also known as an integrated circuit, can contain multiple hardware units that can perform different functions. Depending on the safety requirements of these different functions, an integrated circuit can be divided into at least one functional safety level domain, where each functional safety level domain contains at least one hardware unit, and different functional safety level domains correspond to different safety levels, which represent the level of safety requirements for the functions performed by each hardware unit in the corresponding functional safety level domain. For example, the higher the safety level of a functional safety level domain, the higher the safety requirements for the functions performed by each hardware unit in that functional safety level domain; conversely, the lower the safety level of a functional safety level domain, the lower the safety requirements for the functions performed by each hardware unit in that functional safety level domain.
[0016] In some cases, hardware units contained within an integrated circuit can implement vehicle-related functions, and functional safety level domains can be divided for this integrated circuit based on road vehicle functional safety standards (e.g., ISO 26262). The safety levels of the functional safety level domains can include Quality Management (QM) levels and Automotive Safely Integrity Levels (ASIL), where the QM level is lower than the ASIL level, and each ASIL level can include ASIL-A, ASIL-B, ASIL-C, and ASIL-D in order from lowest to highest.
[0017] Figure 1 is a schematic diagram of the architecture of an integrated circuit according to one exemplary embodiment of the present disclosure.
[0018] As shown in FIG. 1, the integrated circuit can include a first hardware unit 11 and a second hardware unit 12. The first hardware unit 11 can implement a first function (for example, the function of displaying information on the display panel of a vehicle), and the second hardware unit 12 can implement a second function (for example, the function of braking a vehicle emergently). Based on the requirements for the safety of the first function and the second function, the functional safety level domain of the integrated circuit is divided. If the requirements for the safety of the first function and the second function are different, the integrated circuit can be divided into a first functional safety level domain 13 and a second functional safety level domain 14. The hardware units in the first functional safety level domain 13 include the first hardware unit 11, and the hardware units in the second functional safety level domain 14 include the second hardware unit 12. The safety levels of the first functional safety level domain 13 and the second functional safety level domain 14 may be the same or different. The safety level of the first functional safety level domain 13 matches the requirements for the safety of the first function, and the safety level of the second functional safety level domain 14 matches the requirements for the safety of the second function. Hereinafter, for the convenience of description, it is exemplarily described that the safety levels of different functional safety level domains are different.
[0019] The hardware units in different functional safety level domains can access each other via a bus to realize communication between the corresponding functional safety level domains. As shown in FIG. 1, the first hardware unit 11 and the second hardware unit 12 can access each other via a bus 15 to realize communication between the first functional safety level domain 13 and the second functional safety level domain 14.
[0020] However, according to the above architecture, when hardware units in functional safety level domains with different safety levels access each other, if a failure occurs in a hardware unit in a certain functional safety level domain, it will not cause a failure in other hardware units in this functional safety level domain. Instead, this failure may cause a failure in the bus and further cause a failure in hardware units in another functional safety level domain that shares the bus. In particular, if a failure occurs in a hardware unit in a functional safety level domain with a low safety level, it can cause a failure in a hardware unit in a functional safety level domain with a high safety level, spreading the failure. For example, if the safety level of the first functional safety level domain 13 is lower than that of the second functional safety level domain 14, and the first hardware unit 11 accesses the second hardware unit 12, when a failure occurs in the first hardware unit 11, for example, if the first hardware unit 11 cannot respond to the access request of the second hardware unit 12 for a long time, and the first hardware unit 11 hangs, the second hardware unit 12 will also hang.
[0021] Embodiments of the present disclosure provide a bus access device and a bus access method in an integrated circuit to solve the above technical problems.
[0022] The device includes a controller, a first hardware unit corresponding to a first functional safety level domain, a second hardware unit corresponding to a second functional safety level domain, and a register storing first configuration information corresponding to the second hardware unit, wherein the first configuration information includes second identification information of a target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain, the first hardware unit generates a first access request, the controller determines the first identification information of the first hardware unit based on the first access request, the controller further reads the first configuration information from the register, the controller further determines the authority of the first hardware unit to access the second hardware unit based on the first and second identification information, and the controller further controls the transmission of the first access request from the bus to the second hardware unit based on the authority of the first hardware unit to access the second hardware unit.
[0023] The method includes the steps of: generating a first access request by a first hardware unit in a first functional safety level domain; determining first identification information for the first hardware unit based on the first access request; reading first configuration information from a register corresponding to a second hardware unit in a second functional safety level domain, wherein the first configuration information includes second identification information for a target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain; determining the authority of the first hardware unit to access the second hardware unit based on the first and second identification information (i.e., the height relationship between the safety level of the first functional safety level domain where the first hardware unit resides and the safety level of the second functional safety level domain where the second hardware unit resides); and controlling the transmission of the first access request from the bus to the second hardware unit based on this authority (i.e., controlling the transmission of the first access request from the bus to the second hardware unit based on the height relationship between the safety level of the first functional safety level domain and the safety level in the second functional safety level domain). If an abnormality occurs in a hardware unit in a lower-safety functional safety level domain within the first or second functional safety level domain, the first access request can be controlled to be transmitted from the bus to a hardware unit in a higher-safety functional safety level domain. By performing corresponding control on the first access request transmitted when an abnormality occurs in a hardware unit in a lower-safety functional safety level domain, the normal operation of the hardware unit in the higher-safety functional safety level domain can be effectively guaranteed, thereby ensuring the safety requirements of the higher-safety functional safety level domain.
[0024] The bus access device and bus access method described herein will be explained in detail below with reference to the drawings.
[0025] (An example system) Figure 2 is a schematic diagram of the architecture of an integrated circuit according to another exemplary embodiment of the present disclosure.
[0026] As shown in Figure 2, an integrated circuit can contain N functional safety level domains, for example, a first functional safety level domain 21, a second functional safety level domain 22, ..., an Nth functional safety level domain 2n. Each functional safety level domain contains at least one hardware unit, and the hardware unit contained in the first functional safety level domain 21 is called the first hardware unit, the hardware unit contained in the second functional safety level domain 22 is called the second hardware unit, ..., the hardware unit contained in the Nth functional safety level domain 2n is called the Nth hardware unit. The first functional safety level domain 21 can contain first hardware units 211, first hardware units 212 to 21n, the second functional safety level domain 22 can contain second hardware units 221, first hardware units 222 to 22n, ..., the Nth functional safety level domain 2n can contain Nth hardware units 2n1, Nth hardware units 2n2 to 2nn.
[0027] Hardware units in each functional safety level domain can access each other via bus 201 to enable communication between corresponding functional safety level domains. Here, a hardware unit can initiate access to other hardware units as a master, and a hardware unit can also be accessed by other hardware units as a slave. A hardware unit includes a master interface and a slave interface, and is connected to bus 201 via the master interface and the slave interface, respectively. A hardware unit acting as a master can transmit access requests to bus 201 via the master interface and to the slave interface of a hardware unit acting as a slave via bus 201.
[0028] As shown in Figure 2, the integrated circuit further includes at least one controller, which can control access requests transmitted between each hardware unit. This at least one controller corresponds to a hardware unit, where each hardware unit corresponds to at least one controller group, and each controller group includes at least one controller. The controller group corresponding to a first hardware unit is called the first controller group, the controller group corresponding to a second hardware unit is called the second controller group, and so on. As shown in Figure 2, the first hardware units 211 to 21n correspond to the first controller groups 2111 to 21n1, respectively, the second hardware units 221 to 22n correspond to the second controller groups 2211 to 22n1, respectively, ..., the nth hardware unit 2n1 to 2nn correspond to the nth controller groups 2n11 to 2nn1, respectively.
[0029] In some embodiments, a controller group can control the transmission of access requests on bus 201 based on at least one processing mechanism. This at least one processing mechanism is intended to avoid influencing hardware units in a lower functional safety level domain with hardware units in a higher functional safety level domain. Here, a controller in the controller group corresponds to a processing mechanism, different controllers correspond to different processing mechanisms, and a controller controls the transmission of access requests on bus 201 based on its corresponding processing mechanism.
[0030] The mechanism type of the processing mechanism corresponds to different stages in which an access request is transmitted on bus 201. Here, the stage in which the access request is transmitted from the master to bus 201 corresponds to the first mechanism type, and the stage in which the access request is transmitted from bus 201 to the slave corresponds to the second mechanism type. Based on the mechanism type of the processing mechanism, the controllers can be divided into controllers on different sides. Here, the controller corresponding to the processing mechanism of the first mechanism type is the master-side controller, and the controller corresponding to the processing mechanism of the second mechanism type is the slave-side controller.
[0031] Here, the hardware unit transmits the access request to the corresponding master controller via the master interface, and this master controller can transmit the access request to bus 201. The access request is then transmitted to the slave controller via bus 201, and this slave controller can transmit the access request to the slave interface of the corresponding hardware unit.
[0032] In some examples, at least one processing mechanism may include one or more of the following: a firewall mechanism, a bandwidth limiting (BW_Limit) mechanism, a hang detection mechanism, and a hang protection mechanism. Here, the bandwidth limiting mechanism and the hang detection mechanism are processing mechanisms of the first mechanism type, and the firewall mechanism and the hang protection mechanism are processing mechanisms of the second mechanism type.
[0033] Figure 3 is a schematic diagram of the architecture of an integrated circuit according to yet another exemplary embodiment of the present disclosure.
[0034] In some embodiments, when a controller group is configured to control the transmission of access requests on bus 201 based on a firewall mechanism, a bandwidth limiting mechanism, a hang detection mechanism, and a hang protection mechanism, as shown in Figure 3, on the architecture shown in Figure 2, a first controller group 2111 corresponds to a first hardware unit 211 and a second controller group 2211 corresponds to a second hardware unit 221, and each controller group 2111 and 2211 each contain four controllers, which can be hardware modules, such as a firewall module, a bandwidth limiting module, a hang detection module, and a hang protection module. Here, the firewall module corresponds to a firewall mechanism, the bandwidth limiting module corresponds to a bandwidth limiting mechanism, the hang detection module corresponds to a hang detection mechanism, and the hang protection module corresponds to a hang protection mechanism. The bandwidth limiting module and the hang detection module are master-side controllers, and the firewall module and the hang protection module are slave-side controllers.
[0035] Figure 3 illustrates only the connection relationships between the hardware units and the corresponding controllers within the controller group, and between each controller within the controller group; the embodiments of this disclosure are not limited thereto. For example, to a master controller, the master may be connected to bus 201 in the order of hang detection module and bandwidth limiting module, and to a slave controller, the slave may be connected to bus 201 in the order of firewall module and hang protection module.
[0036] As shown in Figure 2, the integrated circuit further includes a register 202, which can pre-store configuration information for the hardware unit. The configuration information for the hardware unit may include non-modifiable configuration information or modifiable configuration information. Here, the modifiable configuration information may include configuration information related to safety levels, and for example, the configuration information related to safety levels can be flexibly changed based on a change in the safety level of the functional safety level domain corresponding to the hardware unit.
[0037] In some examples, the configuration information of a hardware unit may include first configuration information, which may include identification information of a target hardware unit, and the safety level of the functional safety level domain corresponding to the target hardware unit is higher than the safety level of the functional safety level domain corresponding to this hardware unit. Exemplarily, the identification information of a target hardware unit may be an identifier (ID).
[0038] In some examples, the configuration information of a hardware unit may further include second configuration information, which may include authorization information for the target hardware unit to access an address space, where the address space corresponds to this hardware unit.
[0039] In some embodiments, when hardware units in different functional safety level domains access each other, a controller group corresponding to a hardware unit can read first and second configuration information corresponding to the hardware unit from the corresponding register 202, determine access rights between hardware units based on this configuration information, and control the transmission of access requests over the bus based on the determined rights. Since the first and second configuration information are related to safety levels, the above determination of access rights is equivalent to determining access rights between hardware units based on safety levels, and controlling the transmission of access requests over the bus based on the determined rights is equivalent to controlling the transmission of access requests over the bus based on safety levels. If a malfunction occurs in a hardware unit in a low-safety level functional safety level domain, a malfunction may occur in the bus, and the transmission of the first access request from the bus to a hardware unit in a high-safety level functional safety level domain can be controlled. Therefore, by performing corresponding control on the first access request transmitted when a malfunction occurs in a hardware unit in a low-safety level functional safety level domain, the normal operation of the hardware unit in the high-safety level functional safety level domain can be effectively guaranteed, thereby guaranteeing the safety requirements of the high-safety level functional safety level domain.
[0040] (Example method) Figure 4 is a schematic flowchart of a bus access method according to one exemplary embodiment of the present disclosure. This embodiment can be applied to an electronic device, which may include an integrated circuit as shown in Figures 2 and 3. In this embodiment, the bus access method in an integrated circuit will be described using the access process between a first hardware unit 211 in a first functional safety level domain 21 and a second hardware unit 221 in a second functional safety level domain 22 as an example. This bus access method in an integrated circuit can be applied to access between any hardware units in any functional safety level domain in the integrated circuit shown in Figures 2 and 3.
[0041] As shown in Figure 4, the bus access method includes the following steps 41 to 45.
[0042] In step 41, the first hardware unit in the first functional safety level domain generates the first access request.
[0043] If the first hardware unit 211 needs to access the second hardware unit 221, the first hardware unit 211 generates a first access request as the master.
[0044] In some examples, this first access request may include instructions to the second hardware unit 221 and data to the second hardware unit 221.
[0045] In some cases, the first access request may carry the identification information of the first hardware unit 211 (hereafter, the identification information of the first hardware unit 211 will be abbreviated as "first identification information").
[0046] In some examples, this first access request may carry further information about the object for which access is being requested. For example, this information may include the identification information of the second hardware unit 221 (hereafter referred to as the "third identification information"), the address of the requested access, and so on.
[0047] The first hardware unit 211 transmits the first access request to the second hardware unit 221. For example, the first access request is transmitted from the master interface of the first hardware unit 211 to the master controller of the first controller group 2111 corresponding to the first hardware unit 211, from this master controller to the bus 201, from the bus 201 to the slave controller of the second controller group 2211 corresponding to the second hardware unit 221, and from this slave controller to the slave interface of the second hardware unit 221.
[0048] Steps 42 to 44 can be performed by a controller with authentication functionality, either the master controller of the first controller group 2111 or the slave controller of the second controller group 2211. For example, a firewall module in the slave controller of the second controller group 2211 has authentication functionality, and the firewall module corresponding to the second hardware unit 221 can authenticate the first access request. In the following embodiment, the authentication of the first access request by the firewall module corresponding to the second hardware unit 221 will be described as an example.
[0049] In step 42, the first identification information of the first hardware unit is determined based on the first access request.
[0050] For example, if the first access request carries the first identification information of the first hardware unit 211, the firewall module corresponding to the second hardware unit 221 can determine the first identification information from this first access request.
[0051] In step 43, the first configuration information corresponding to the second hardware unit in the second functional safety level domain is read from the register.
[0052] For example, if the first access request carries the third identification information of the second hardware unit 221, the firewall module corresponding to the second hardware unit 221 can determine the third identification information from this first access request. The firewall module corresponding to the second hardware unit 221 can read the configuration information corresponding to all hardware units in the integrated circuit from register 202, where the configuration information corresponding to each hardware unit has an index relationship with the corresponding hardware unit. For example, this index relationship may be an index relationship between the identification information and configuration information of a hardware unit. Based on this index relationship, the firewall module corresponding to the second hardware unit 221 can determine the configuration information corresponding to the second hardware unit 221 from the configuration information corresponding to all hardware units. Furthermore, the firewall module corresponding to the second hardware unit 221 can determine the first configuration information corresponding to the second hardware unit 221 from the configuration information corresponding to the second hardware unit 221.
[0053] Here, the first configuration information includes the second identification information of the target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain 22. In other words, the target hardware unit has the authority to access the second hardware unit 221. Hardware units whose safety level in the functional safety level domain is lower than or equal to the safety level in the second functional safety level domain 22 do not have the authority to access the second hardware unit 221. As can be seen from this, the access rights between each hardware unit can represent the height relationship between the safety levels of the functional safety level domains corresponding to each hardware unit.
[0054] In step 44, the authority of the first hardware unit to access the second hardware unit is determined based on the first and second identification information.
[0055] The firewall module corresponding to the second hardware unit 221 can determine the authority of the first hardware unit 211 to access the second hardware unit 221 based on the first and second identification information, that is, it can determine the height relationship between the security level of the first functional security level domain 21 corresponding to the first hardware unit 211 and the security level of the second functional security level domain 22 corresponding to the second hardware unit 221.
[0056] For example, if the first hardware unit 211 has the authority to access the second hardware unit 221, it can be determined that the security level of the first functional security level domain 21 is higher than the security level of the second functional security level domain 22. If the first hardware unit 211 does not have the authority to access the second hardware unit 221, it can be determined that the security level of the first functional security level domain 21 is lower than or equal to the security level of the second functional security level domain 22.
[0057] In some examples, the firewall module corresponding to the second hardware unit 221 can write the permission for the first hardware unit 211 to access the second hardware unit 221 to register 202, and the controllers in the first controller group 2111 and the second controller group 2211 can read the permission for the first hardware unit 211 to access the second hardware unit 221 from register 202.
[0058] In some examples, the firewall module corresponding to the second hardware unit 221 can transmit to the controllers in the first controller group 2111 and the second controller group 2211 the authority for the first hardware unit 211 to access the second hardware unit 221.
[0059] In step 45, the transmission of the first access request from the bus to the second hardware unit is controlled based on the first hardware unit's authority to access the second hardware unit.
[0060] For example, based on the fact that the first hardware unit 211 has the authority to access the second hardware unit 221, that is, based on the fact that the security level of the first functional security level domain 21 corresponding to the first hardware unit 211 is higher than the security level of the second functional security level domain 22 corresponding to the second hardware unit 221, the transmission of the first access request from the bus 201 to the second hardware unit 221 by the master controller in the first controller group 2111 and the slave controller in the second controller group 2211 can be controlled to avoid the second hardware unit 221 affecting the first hardware unit 211.
[0061] Based on the fact that the first hardware unit 211 has no access rights to access the second hardware unit 221, that is, based on the fact that the safety level of the first functional safety level domain 21 corresponding to the first hardware unit 211 is less than or equal to the safety level of the second functional safety level domain 22 corresponding to the second hardware unit 221, the master controller in the first controller group 2111 and the slave controller in the second controller group 2211 control the transmission of the first access request from the bus 201 to the second hardware unit 221, thereby avoiding any impact of the first hardware unit 211 on the second hardware unit 221.
[0062] In the bus access method for an integrated circuit according to the embodiment of this disclosure, when a first hardware unit 211 in a first functional safety level domain 21 accesses a second hardware unit 221 in a second functional safety level domain 22, at least one controller among the master-side controller in the first controller group 2111 corresponding to the first hardware unit 211 and the slave-side controller in the second controller group 2211 corresponding to the second hardware unit 221 controls the transmission of a first access request from the bus 201 to the second hardware unit 221 based on the authority of the first hardware unit 211 to access the second hardware unit 221, that is, based on the height relationship between the safety level of the first functional safety level domain 21 corresponding to the first hardware unit 211 and the safety level of the second functional safety level domain 22 corresponding to the second hardware unit 221. This prevents an abnormality in the bus 201 when an abnormality occurs in a hardware unit in a functional safety level domain with a low safety level from affecting hardware units in a functional safety level domain with a high safety level, thereby guaranteeing the safety requirements of the functional safety level domain with a high safety level.
[0063] Figure 5 is a schematic flowchart of a bus access method according to another exemplary embodiment of the present disclosure.
[0064] In some embodiments, as shown in Figure 5, step 44 may include steps 441 to 442 in the embodiment shown in Figure 4.
[0065] In step 441, the inclusion relationship between the second identification information and the first identification information is determined.
[0066] The inclusion relationship between the second identification information and the first identification information includes cases where the first identification information is included in the second identification information, and cases where the first identification information is not included in the second identification information.
[0067] For example, if the target hardware unit corresponding to the second hardware unit 221 includes the first hardware units 211 to 21n, then the first configuration information corresponding to the second hardware unit 221 includes the second identification information 211 to 21n corresponding to the first hardware units 211 to 21n. In that case, the inclusion relationship between the second identification information and the first identification information can be determined as the first identification information being contained within the second identification information.
[0068] For example, if the target hardware unit corresponding to the second hardware unit 221 does not include the first hardware units 211 to 21n, then the first configuration information corresponding to the second hardware unit 221 does not include the second identification information corresponding to the first hardware units 211 to 21n. In that case, the inclusion relationship between the second identification information and the first identification information can be determined to be that the first identification information is not included in the second identification information.
[0069] In step 442, the authority of the first hardware unit to access the second hardware unit is determined based on the inclusion relationship.
[0070] If the inclusion relationship is such that the first identification information is contained within the second identification information, it can be determined that the first hardware unit 211 has the right to access the second hardware unit 221. If the inclusion relationship is such that the first identification information is not contained within the second identification information, it can be determined that the first hardware unit 211 does not have the right to access the second hardware unit 221.
[0071] In the bus access method for an integrated circuit according to the embodiment of this disclosure, the authority of the first hardware unit 211 to access the second hardware unit 221 can be quickly determined by determining the inclusion relationship between the first identification information of the first hardware unit 211 and the second identification information of the target hardware unit corresponding to the second hardware unit 221, thereby improving the efficiency of controlling the transmission of the first access request from the bus 201 to the second hardware unit 221.
[0072] Figure 6 is a schematic flowchart of a bus access method according to yet another exemplary embodiment of the present disclosure.
[0073] In some embodiments, as shown in Figure 6, step 442 may include steps 4421 to 4424 in the embodiment shown in Figure 5.
[0074] In step 4421, if the inclusion relationship is that the first identification information is contained within the second identification information, the second configuration information corresponding to the second hardware unit is read from the register.
[0075] If the inclusion relationship is such that the first identification information is contained within the second identification information, then it can be determined that the first hardware unit 211 has the authority to access the second hardware unit 221.
[0076] To facilitate the management of the accessible space of the second hardware unit 221, for example, to facilitate the rapid and accurate writing / reading of data to the accessible space of the second hardware unit 221, the accessible space of the second hardware unit 221 can be divided into at least one subspace, and the authority of the target hardware unit corresponding to the second hardware unit 221 to access this at least one subspace can be restricted. This allows for the pre-configuration of second configuration information for the second hardware unit 221, which includes authorization information for the target hardware unit corresponding to the second hardware unit 221 to access the address field. Here, the address field corresponds to the second hardware unit 221 and includes the addresses of each subspace in the accessible space of the second hardware unit 221; in some cases, the address field may also be called an address range.
[0077] In some examples, authorization information may include the authorization of the target hardware unit to access each address in the address space, for example, whether the target hardware unit has authorization to access an address, and if so, it can access the type of access to that address (e.g., write access, read access, etc.).
[0078] In some examples, the firewall module corresponding to the second hardware unit 221 can read the configuration information corresponding to the second hardware unit 221 from register 202, and then determine the second configuration information corresponding to the second hardware unit 221 from the configuration information corresponding to the second hardware unit 221.
[0079] In step 4422, the authorization information for the target hardware unit to access the address space is determined from the second configuration information.
[0080] The firewall module corresponding to the second hardware unit 221 can determine the authority of each target hardware unit to access the address space of the second hardware unit 221 based on the contents included in the second configuration information corresponding to the second hardware unit 221.
[0081] In step 4423, based on the authorization information, the first hardware unit determines the authorization to access each address in the address space.
[0082] The firewall module corresponding to the second hardware unit 221 can determine the authorization information corresponding to the first hardware unit 211 from the authorization information corresponding to each target hardware unit, and based on the authorization information corresponding to the first hardware unit 211, it can determine the authorization for the first hardware unit 211 to access each address in the address space corresponding to the second hardware unit 221.
[0083] For example, the address range corresponding to the second hardware unit 221 includes addresses 2a, 2b, and 2c, and the second configuration information corresponding to the second hardware unit 221 includes authorization information corresponding to the first hardware unit 211, which may include that the first hardware unit 211 has the authority to access address 2a and that the first hardware unit 211 does not have the authority to access addresses 2b and 2c. Based on this authorization information, the firewall module corresponding to the second hardware unit 221 can determine whether the first hardware unit 211 has the authority to access addresses 2a, 2b, and 2c.
[0084] In step 4424, the first hardware unit determines its authority to access the second hardware unit based on its authority to access each address in the address space.
[0085] The authority of the first hardware unit 211 to access the second hardware unit 221 is to have the authority to access the second hardware unit 221 and to have the authority to access at least one address in the address field corresponding to the second hardware unit 221, but not to have the authority to access any other addresses in the address field.
[0086] In the bus access method for an integrated circuit according to the embodiment of this disclosure, by pre-setting second configuration information in the hardware unit, it is possible to more accurately and precisely manage the accessible space of each hardware unit by effectively restricting the accessible space that the master permits access to when the hardware unit is a slave.
[0087] Figure 7 is a schematic flowchart of a bus access method relating to yet another exemplary embodiment of the present disclosure.
[0088] In some embodiments, as shown in Figure 7, step 45 above may include steps 451 to 453 in the embodiment shown in Figure 4.
[0089] In step 451, a processing mechanism is determined for transmitting the first access request from the bus to the second hardware unit, based on the first hardware unit's authority to access the second hardware unit.
[0090] Each processing mechanism is primarily used to prevent hardware units in lower-safety functional safety level domains from affecting hardware units in higher-safety functional safety level domains, and in particular to prevent an abnormality in a hardware unit in a lower-safety functional safety level domain from affecting hardware units in a higher-safety functional safety level domain. This allows for the determination of a processing mechanism to control the transmission of the first access request based on the authority of the first hardware unit 211 to access the second hardware unit 221, that is, based on the safety level relationship between the first functional safety level domain 21 and the second functional safety level domain 22.
[0091] Here, in response to the fact that the first hardware unit 211 does not have the authority to access the second hardware unit 221, that is, in response to the fact that the safety level of the first functional safety level domain 21 is less than or equal to the safety level of the second functional safety level domain 22, a first processing mechanism is determined to transmit the first access request from the bus 201 to the second hardware unit 221, thereby avoiding any impact of the first hardware unit 211 on the second hardware unit 221.
[0092] In some examples, this first processing mechanism may include one or more of the firewall mechanism and the bandwidth limiting mechanism.
[0093] In response to the fact that the first hardware unit 211 has the authority to access the second hardware unit 221, that is, in response to the fact that the security level of the first functional security level domain 21 is higher than the security level of the second functional security level domain 22, a second processing mechanism is determined to transmit the first access request from the bus 201 to the second hardware unit 221, thereby preventing the second hardware unit 221 from affecting the first hardware unit 211.
[0094] In some examples, this second processing mechanism may include one or more of the hang detection mechanism and the hang protection mechanism.
[0095] In step 452, based on the processing mechanism, the target controller that controls the transmission of the first access request over the bus is determined.
[0096] The mechanism type corresponding to the processing mechanism can be determined. For example, if the processing mechanism is a firewall mechanism, it can be determined that the firewall mechanism corresponds to the second mechanism type. Similarly, if the processing mechanism is a bandwidth limiting mechanism, it can be determined that the bandwidth limiting mechanism corresponds to the first mechanism type.
[0097] Based on the mechanism type corresponding to the processing mechanism, it is possible to determine the target controller that controls the transmission of the first access request via the bus 201, that is, the target controller for controlling the transmission of the first access request via the bus 201. Here, based on the first mechanism type corresponding to the processing mechanism, it can be determined that the target controller is a controller for executing this processing mechanism in the first controller group 2111 corresponding to the first hardware unit 211, and based on the second mechanism type corresponding to the processing mechanism, it can be determined that the target controller is a controller for executing this processing mechanism in the second controller group 2211 corresponding to the second hardware unit 221.
[0098] In some examples, based on a first processing mechanism, a first controller can be determined as a target controller that controls the transmission of a first access request over the bus. Here, based on the first processing mechanism, a corresponding mechanism type can be determined, and based on the mechanism type corresponding to the first processing mechanism, a target controller for executing this first processing mechanism can be determined.
[0099] For example, if the first processing mechanism includes a firewall mechanism and a bandwidth limiting mechanism, it can be determined that the first controller corresponding to the firewall mechanism is a firewall module corresponding to the second hardware unit 221, and the first controller corresponding to the bandwidth limiting mechanism is a bandwidth limiting module corresponding to the first hardware unit 211.
[0100] In some examples, based on a second processing mechanism, a second controller can be determined as a target controller that controls the transmission of the first access request over the bus. Here, based on the second processing mechanism, a corresponding mechanism type can be determined, and based on the mechanism type corresponding to the second processing mechanism, a target controller for executing this second processing mechanism can be determined.
[0101] For example, if the second processing mechanism includes a hang detection mechanism and a hang protection mechanism, it can be determined that the second controller corresponding to the hang detection mechanism is a hang detection module corresponding to the first hardware unit 211, and the second controller corresponding to the hang protection mechanism is a hang protection module corresponding to the second hardware unit 221.
[0102] Step 453 controls the transmission of the first access request from the bus to the hardware unit corresponding to the target controller.
[0103] The target controller controls the transmission of the first access request from bus 201 to the hardware unit corresponding to this target controller, based on the corresponding processing mechanism.
[0104] For example, if the target controller is a bandwidth limiting module corresponding to the first hardware unit 211, the hardware unit corresponding to the target controller is the second hardware unit 221; if the target controller is a hang detection module corresponding to the first hardware unit 211, the hardware unit corresponding to the target controller is the second hardware unit 221; if the target controller is a firewall module corresponding to the second hardware unit 221, the hardware unit corresponding to the target controller is the second hardware unit 221; and if the target controller is a hang protection module corresponding to the second hardware unit 221, the hardware unit corresponding to the target controller is the first hardware unit 211.
[0105] In the bus access method for an integrated circuit according to the embodiment of this disclosure, the processing mechanism necessary to control the transmission of the first access request can be accurately determined based on the authority of the first hardware unit 211 to access the second hardware unit 221, and furthermore, the target controller that needs to execute this processing mechanism can be accurately determined, and the transmission of the first access request can be controlled by the target controller. As a result, in order to effectively avoid the impact of hardware units in a functional safety level domain with a lower safety level on hardware units in a functional safety level domain with a higher safety level, non-target controllers other than the target controller are not involved in the control of the transmission of the first access request, so that non-target controllers do not interfere with the transmission of the first access request, and such power consumption can also be reduced.
[0106] The following describes how the target controller controls the transmission of the first access request from the bus to the hardware unit corresponding to the target controller, based on the corresponding processing mechanism.
[0107] In some embodiments, the processing mechanism is a first processing mechanism (e.g., a firewall mechanism), and the target controller is a firewall module corresponding to the second hardware unit 221.
[0108] A method for controlling the transmission of the first access request from bus 201 to the hardware unit corresponding to the target controller may include interrupting the transmission of the first access request from the bus to the hardware unit corresponding to the first controller.
[0109] For example, the first access request is transmitted from bus 201 to a firewall module corresponding to the second hardware unit 221, which blocks the first access request, preventing it from being transmitted to the second hardware unit 221.
[0110] In some cases, the firewall module corresponding to the second hardware unit 221 can generate response information (e.g., a response error) based on the first access request, and the first hardware unit 211 can determine, based on this response information, that it does not have permission to access the second hardware unit 221.
[0111] In some examples, the firewall module corresponding to the second hardware unit 221 can process data corresponding to the first access request based on the request type corresponding to the first access request. Here, if the request type corresponding to the first access request is a data read request, the firewall module can generate a pre-configured number (for example, zero (0)), and if the request type corresponding to the first access request is a data write request, the firewall module can discard the write data corresponding to the first access request.
[0112] In some examples, the firewall module corresponding to the second hardware unit 221 can generate an interrupt signal in response to the first access request, which instructs the first hardware unit 211 to block access to the second hardware unit 221. In this case, a record of the blocking of access from the first hardware unit 211 to the second hardware unit 221 can be written to register 202, which can be queried and processed in ways such as deletion or blocking.
[0113] The bus access method in the integrated circuit according to the embodiment of this disclosure effectively restricts access from hardware units in a lower functional safety level domain to hardware units in a higher functional safety level domain by blocking access requests transmitted from hardware units in a lower functional safety level domain to hardware units in a higher functional safety level domain. Therefore, even if a malfunction occurs in a hardware unit in a lower functional safety level domain, the hardware unit in a higher functional safety level domain can still operate normally.
[0114] In some embodiments, the processing mechanism is a first processing mechanism (e.g., a bandwidth limiting mechanism), and the target controller is a bandwidth limiting module corresponding to the first hardware unit 211.
[0115] In that case, the method for controlling the transmission of the first access request from the bus to the hardware unit corresponding to the target controller may include determining a first bandwidth threshold corresponding to the first hardware unit 211 based on the safety level of the first functional safety level domain 21, and controlling the transmission of the first access request from the bus 201 to the hardware unit corresponding to the first controller based on the first bandwidth threshold.
[0116] Register 202 can be pre-configured with a correspondence between each safety level and a bandwidth threshold, where the bandwidth threshold represents the maximum bus bandwidth available when each hardware module accesses the bus in the functional safety level domain of the corresponding safety level. The bandwidth limiting module corresponding to the first hardware unit 211 can read this correspondence from register 202 and determine the first bandwidth threshold corresponding to the first hardware unit 211 based on the safety level of the first functional safety level domain 21. Subsequently, the bandwidth limiting module corresponding to the first hardware unit 211 can determine the bus bandwidth currently used by the first hardware unit 211 (e.g., the first bandwidth).
[0117] In some cases, bandwidth thresholds corresponding to different safety levels can be determined based on the safety level and bus bandwidth. For example, a higher safety level corresponds to a higher proportion of bus bandwidth, and a lower safety level corresponds to a lower proportion of bus bandwidth. Thus, the bandwidth threshold corresponding to a safety level is the product of this proportion of bus bandwidth and the bus bandwidth. Note that if the bus bandwidth is constant, a higher safety level corresponds to a higher bandwidth threshold, and a lower safety level corresponds to a lower bandwidth threshold.
[0118] Furthermore, the higher the safety level, the higher the corresponding bandwidth threshold, that is, ensuring that hardware units in high-safety functional level domains can use more bus bandwidth. Conversely, the lower the safety level, the lower the corresponding bandwidth threshold, that is, preventing hardware units in low-safety functional level domains from occupying excessive bus bandwidth, leaving hardware units in high-safety functional level domains to use more bus bandwidth.
[0119] In some examples, the bandwidth limiting module can determine the bus transmission bandwidth corresponding to access requests transmitted by the first hardware unit 211 within a predetermined unit time. Here, the first hardware unit 211 can determine the bus transmission bandwidth corresponding to the read channel and the write channel, respectively, within a predetermined unit time, and calculate the sum of the bus transmission bandwidths corresponding to the read channel and the write channel, respectively. By calculating the ratio of the bus transmission bandwidth corresponding to access requests transmitted by the first hardware unit 211 within a predetermined unit time to the predetermined unit time, the first bandwidth corresponding to the first hardware unit 211 can be obtained.
[0120] The bandwidth limiting module controls the transmission of the first access request from bus 201 to the hardware unit corresponding to the first controller, based on the first bandwidth and the first bandwidth threshold. Here, the first controller is the bandwidth limiting module, and the hardware unit corresponding to the bandwidth limiting module is the second hardware unit 221.
[0121] Here, if the first bandwidth is less than the first bandwidth threshold, the bandwidth limiting module does not limit the transmission of the first access request. If the first bandwidth is greater than or equal to the first bandwidth threshold, the bandwidth limiting module limits the transmission of the first access request, for example, by blocking the transmission of the first access request to bus 201 or by reducing the number of first access requests transmitted to bus 201 within a unit time, thereby reducing the bus bandwidth occupancy of the first hardware unit 211.
[0122] In the bus access method for an integrated circuit according to the embodiments of this disclosure, different bandwidth thresholds are assigned to different safety levels, and the bus bandwidth occupied by access requests transmitted by hardware units is controlled so as not to exceed the corresponding bandwidth thresholds. This effectively limits the bus bandwidth occupied by hardware units in lower safety level functional safety level domains, reducing their occupation of bus bandwidth in lower safety level functional safety level domains and ensuring that hardware units in higher safety level functional safety level domains can use more bus bandwidth.
[0123] In some embodiments, the processing mechanism is a second processing mechanism (e.g., a hang detection mechanism), and the target controller is a hang detection module corresponding to the first hardware unit 211.
[0124] Furthermore, the method for controlling the transmission of the first access request from bus 201 to the hardware unit corresponding to the target controller may include determining the target access request for which the response timeout occurs in the first access request, generating an interrupt signal corresponding to the target access request to instruct the interrupt processing of the target access request, and controlling the transmission of the first access request from bus 201 to the hardware unit corresponding to the second controller based on the interrupt signal.
[0125] The hang detection module corresponding to the first hardware unit 211 can read a time threshold from register 202 and monitor each first access request based on this time threshold. If response information for the first access request from the second hardware unit 221 is detected within this time threshold, this first access request is an access request with a normal response. If no response information for the first access request from the second hardware unit 221 is detected within this time threshold, this first access request is a target access request for a response timeout.
[0126] The hang detection module can count unresponsive first access requests using a counter. Here, the first hardware unit generates one first access request and adds 1 to the counter value. After one first access request is responded to, 1 is subtracted from the counter value. If the counter value is 0, it means there are currently no unresponsive first access requests. If the counter value is not 0, it means there are currently no unresponsive first access requests. When the time threshold is reached, if the counter value is not 0, there are unresponsive first access requests, and these unresponsive first access requests become the target access requests.
[0127] In some cases, the hang detection module can determine the first access request corresponding to the same second hardware unit 221 and perform timeout monitoring for the first access request corresponding to the same second hardware unit 221.
[0128] Here, the hang detection module can perform independent timeout monitoring for each first access request, the hang detection module creates a corresponding timer for each first access request, and if the hang detection module cannot detect a response from the second hardware unit 221 to the corresponding first access request before the timer reaches a time threshold, it determines that this first access request has timed out and sets this first access request as the target access request.
[0129] Alternatively, the hang detection module can perform timeout monitoring on a holistic basis for first access requests corresponding to the same channel type, where the channel type of the data channel between the first hardware unit 211 and the second hardware unit 221 can include write channels, read channels, and auxiliary channels (AC). It can monitor first access requests corresponding to write channels holistically, and first access requests corresponding to read channels holistically. When monitoring first access requests holistically, a timer is created corresponding to the corresponding channel. This timer starts counting when the counter value is first not zero, and resumes counting after detecting that any first access request on this channel has been responded to. If the hang detection module fails to detect that any first access request on the corresponding channel has been responded to before the timer reaches a time threshold, it determines that the first access request on this channel has timed out and sets this first access request as the target access request. The hang detection module performs independent timeout monitoring for each first access request corresponding to an auxiliary channel, which is not described here.
[0130] In some examples, the hang detection module can perform timeout monitoring on a collectively for first access requests corresponding to the same channel type, where first access requests corresponding to the same channel type may include first access requests corresponding to different second hardware units 221.
[0131] Here, the first access requests corresponding to the write channel can be monitored as a whole, the first access requests corresponding to the read channel can be monitored as a whole, and the first access requests corresponding to the auxiliary channel can be monitored as a whole. When monitoring the first access requests as a whole, a timer is created corresponding to the corresponding channel, and this timer starts counting when the counter value is first not 0, and after detecting that any first access request on this channel has been responded to, this timer resumes counting. If the hang detection module cannot detect that any first access request on the corresponding channel has been responded to before the timer reaches the time threshold, it is determined that the first access request corresponding to this channel has timed out, and this first access request is set as the target access request.
[0132] When the hang detection module determines that a target access request exists, it can determine that the first hardware unit 211 is in a hang state. Subsequently, the hang detection module corresponding to the first hardware unit 211 interrupts the target access request based on the interrupt signal, blocking the first hardware unit 211 from accessing the second hardware unit 221.
[0133] In some cases, the hang detection module can write a record that generates an interrupt signal to register 202, and other hardware units can avoid accessing the hung first hardware unit 211 by reading the corresponding record from register 202 when accessing the first hardware unit 211.
[0134] In the bus access method for an integrated circuit according to the embodiment of this disclosure, by detecting the target access request of the response timeout in the first access request, it is determined whether or not the first hardware unit 211 is in a hung state. If it is determined that the first hardware unit 211 is in a hung state, an alarm is issued, such as generating an interrupt signal or writing a record of the generated interrupt signal to register 202. When a hardware unit in a functional safety level domain with a high safety level needs to access this first hardware unit 211, it is determined that this first hardware unit 211 is in a hung state and subsequently avoids accessing this first hardware unit 211, thereby avoiding the impact on itself from accessing the first hardware unit 211.
[0135] In some embodiments, the processing mechanism is a second processing mechanism (e.g., a hang protection mechanism), and the target controller is a hang protection module corresponding to the second hardware unit 221.
[0136] Furthermore, the method for controlling the transmission of the first access request from bus 201 to the hardware unit corresponding to the target controller may include determining the target access request for which the response timeout in the first access request occurred, generating response information for the target access request, and controlling the transmission of the first access request from bus 201 to the hardware unit corresponding to the second controller based on the response information.
[0137] The hang protection module corresponding to the second hardware unit 221 performs timeout monitoring for the first access request corresponding to the same channel type.
[0138] In some cases, the hang protection module can perform timeout monitoring for each first access request according to the transmission order of each first access request, and after monitoring the first target access request, it can determine that all first access requests whose transmission order falls after this first target access request are target access requests.
[0139] In some cases, the hang protection module, in the process of determining the target access request, monitors corresponding items in the first access request using a monitoring policy corresponding to the request type and determines the error type that causes a response timeout.
[0140] For example, monitoring for a read command request in the first access request may include whether the handshake for each command channel was successful, whether the handshake for the last read data signal (RLAST) corresponding to each command was successful, and whether the number of successfully transmitted read data (RDATA) matches the requirements of the current command.
[0141] For example, monitoring for an instruction read request in the first access request may include whether the handshake for each instruction channel was successful, whether the write response signal (BRESP) handshake for each instruction was successful, and whether the number of successfully transmitted write data (WDATA) matches the requirements of the current instruction.
[0142] In some cases, the hang protection module can write information corresponding to the initial target access request (e.g., request type, error type, etc.) to register 202.
[0143] In some cases, the hang protection module can determine the appropriate response mechanism based on the request type and error type corresponding to the target access request, and generate response information based on this response mechanism.
[0144] For example, for a read command request in the first access request, the corresponding response mechanism can be determined based on the error type corresponding to the read command request. The response mechanism may include constructing a Read Address Ready (ARREADY) signal to complete the reception of the corresponding command, constructing a Read Data Read / Valid Read Data (RVALID) signal for the under-transmitted data and returning a Read Data Read of all 0s, constructing a Last Data Signal / Read Response (RRESP) signal and returning a response error, discarding the over-transmitted read data, and discarding any over-transmitted signals downstream and recording the corresponding record.
[0145] For example, for a write command request in the first access request, the corresponding response mechanism can be determined based on the error type corresponding to the write command request. The response mechanism may include constructing a write address ready signal (AWREADY) to complete the reception of the corresponding command, constructing a write address ready signal to complete the reception of the write data and discarding the write data, constructing a write response valid signal (BVALID) / write response signal for the forgotten write data and returning a response error, constructing a write response valid signal / write response signal and returning a response error, and discarding any over-transmitted signals downstream and making the corresponding record.
[0146] In some cases, information about the first target access request can be read from register 202, and the request type of the first target access request can be determined based on this information. Other target access requests corresponding to the same channel type as the first target access request will correspond to the same request type as the first target access request, so the request types of other target access requests can be quickly determined based on the request type of the first target access request. For target access requests other than the first one, the response mechanism can be determined based on the request type, and response information can be generated based on the response mechanism.
[0147] For example, for target access requests other than the first one, where the request type is a read command request, the response mechanism may include constructing a read address ready signal to complete the reception of the data and returning all zeros for the read data and a response error.
[0148] For example, for target access requests other than the first one, where the request type is a write command request, the response mechanism may include configuring a write address ready signal to complete the reception of data, discarding all received write data, and returning a response error.
[0149] The hardware unit corresponding to the hang protection module is the first hardware unit 211. The hang protection module controls the transmission of response information from the bus 201 to the first hardware unit 211. When the second hardware unit 221 is in a hang state, the hang protection module sends the response information configured by the hang protection module to the first hardware unit 211, thereby terminating the first hardware unit 211's access to the second hardware unit 221 and preventing the first hardware unit 211 from hanging.
[0150] In the bus access method for an integrated circuit according to an embodiment of the present disclosure, after determining the response timeout for an access request from a hardware unit in a lower safety level functional safety level domain to a hardware unit in a higher safety level functional safety level domain, response information is constructed and transmitted to the hardware unit in the higher safety level functional safety level domain to terminate the current access, and as a result the hardware unit in the lower safety level functional safety level domain is in a hung state, the hardware unit in the higher safety level functional safety level domain can still respond and can still operate normally.
[0151] (Example electronic device) Figure 8 is a schematic diagram of the structure of an electronic device according to an exemplary embodiment of the present disclosure.
[0152] As shown in Figure 8, the electronic device includes an integrated circuit 81, which may be the integrated circuit shown in Figure 2 or Figure 3. The integrated circuit 81 includes at least one processor 811 and memory 812.
[0153] The processor 811 may be a central processing unit (CPU) or another form of processing unit having data processing and / or instruction execution functions, and may control other components in an electronic device to perform desired functions.
[0154] The memory 812 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disks, flash memory, etc. The computer-readable storage media may store one or more computer program instructions, and the processor 811 may execute one or more computer program instructions to realize the desired functions of the electronic device, that is, the bus access methods and / or other desired functions of each embodiment of the present disclosure.
[0155] As an example, the electronic devices may further include input devices 82 and output devices 83 that are connected to each other by a bus system and / or other forms of connection mechanisms (not shown).
[0156] For simplicity, Figure 8 shows only some of the components relating to this disclosure in this electronic device, omitting components such as buses and input / output interfaces. The electronic device may further include any other appropriate components depending on the specific application.
[0157] (Examples of computer program products and computer-readable storage media) Embodiments of this disclosure further provide computer program products, including computer program instructions, in addition to the methods and apparatus described above. When the computer program instructions are executed by the processor, the processor is caused to perform the steps in the bus access methods of each embodiment of this disclosure described in the “Exemplary Methods” portion above.
[0158] A computer program product can be created using any combination of one or more programming languages to produce program code for performing the operations of the embodiments of this disclosure, and such programming languages may include object-oriented programming languages such as Java and C++, and may also include general procedural programming languages such as the C language or similar programming languages. The program code may be executed as follows: it may be executed entirely on a user computing device, partially on a user device, as a standalone software package, partially on a user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0159] Furthermore, embodiments of the present disclosure further provide a computer-readable storage medium in which computer program instructions are stored. When the computer program instructions are executed by a processor, the processor is caused to perform the steps in the bus access method of each embodiment of the present disclosure described in the “Exemplary Methods” portion above.
[0160] Any combination of one or more types of readable media can be used as a computer-readable storage medium. A readable medium can be a readable signal medium or a readable storage medium. A readable storage medium may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any combination thereof. More specific examples (non-exclusive list) of readable storage media include electrical connections with one or more wires, portable disks, hard drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0161] While the basic principles of this disclosure have been explained above with reference to specific examples, the advantages, merits, and effects mentioned in this disclosure are illustrative and not limiting, and various examples of this disclosure do not necessarily possess these advantages, merits, and effects. Furthermore, the specific details of the above disclosure are for illustrative and easy-to-understand purposes only and are not limiting, and the above details do not necessarily restrict this disclosure to being realized by the above specific details.
[0162] The above description is provided for illustrative and illustrative purposes only. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. While several exemplary embodiments and examples have been described above, those skilled in the art will be able to recognize certain variations, modifications, changes, additions, and subcombinations thereof.
Claims
1. A bus access method in an integrated circuit, wherein each step is performed by an integrated circuit, A step of generating a first access request by a first hardware unit in the first functional safety level domain, The steps include determining first identification information of the first hardware unit based on the first access request, A step of reading first configuration information from a register corresponding to a second hardware unit in a second functional safety level domain, wherein the first configuration information includes second identification information of a target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain. A step of determining the authority of the first hardware unit to access the second hardware unit based on the first identification information and the second identification information, A bus access method in an integrated circuit, characterized by comprising the step of controlling the transmission of the first access request from the bus to the second hardware unit based on the first hardware unit's authority to access the second hardware unit.
2. The step of determining the authority of the first hardware unit to access the second hardware unit based on the first identification information and the second identification information is: A step of determining the inclusion relationship between the second identification information and the first identification information, A bus access method in an integrated circuit according to claim 1, comprising the step of determining the authority of the first hardware unit to access the second hardware unit based on the inclusion relationship.
3. The step of determining the authority of the first hardware unit to access the second hardware unit based on the aforementioned inclusion relationship is: If the inclusion relationship indicates that the first identification information is contained within the second identification information, the steps are to read the second configuration information corresponding to the second hardware unit from the register, The steps include determining the authorization information for the target hardware unit to access the address area corresponding to the second hardware unit from the second configuration information, The steps include determining the authority of the first hardware unit to access each address in the address area based on the authority information, A bus access method in an integrated circuit according to claim 2, comprising the step of determining the authority of the first hardware unit to access the second hardware unit based on the authority of the first hardware unit to access each address in the address area.
4. The step of controlling the transmission of the first access request from the bus to the second hardware unit based on the first hardware unit's authority to access the second hardware unit is: The steps include determining a processing mechanism for transmitting the first access request from the bus to the second hardware unit based on the first hardware unit's authority to access the second hardware unit, The steps include determining a target controller that controls the transmission of the first access request via the bus based on the processing mechanism, A bus access method in an integrated circuit according to any one of claims 1 to 3, comprising the step of controlling the transmission of the first access request from the bus to a hardware unit corresponding to the target controller.
5. The step of determining a processing mechanism for transmitting the first access request from the bus to the second hardware unit based on the first hardware unit's authority to access the second hardware unit is: The first step of determining a first processing mechanism that transmits the first access request from the bus to the second hardware unit in response to the first hardware unit not having the authority to access the second hardware unit. Alternatively, the bus access method in an integrated circuit according to claim 4, comprising the step of determining a second processing mechanism for transmitting the first access request from the bus to the second hardware unit in response to the first hardware unit having the right to access the second hardware unit.
6. The step of determining a target controller that controls the transmission of the first access request via the bus based on the processing mechanism is: A step of determining the first controller as a target controller that controls the transmission of the first access request via the bus, based on the first processing mechanism. Alternatively, the bus access method in an integrated circuit according to claim 5, comprising the step of determining, based on the second processing mechanism, that the second controller is a target controller that controls the transmission of the first access request over the bus.
7. The step of controlling the transmission of the first access request from the bus to the hardware unit corresponding to the target controller is: A bus access method in an integrated circuit according to claim 6, characterized by including the step of blocking the transmission of the first access request from the bus to a hardware unit corresponding to the first controller.
8. The step of controlling the transmission of the first access request from the bus to the hardware unit corresponding to the target controller is: The steps include determining a first bandwidth threshold corresponding to the first hardware unit 211 based on the safety level of the first functional safety level domain, A bus access method in an integrated circuit according to claim 6, comprising the step of controlling the transmission of the first access request from the bus to a hardware unit corresponding to the first controller based on the first bandwidth threshold.
9. The step of controlling the transmission of the first access request from the bus to the hardware unit corresponding to the target controller is: The steps include determining the target access request for the response timeout in the first access request, The steps include generating an interrupt signal corresponding to the aforementioned target access request, A bus access method in an integrated circuit according to claim 6, comprising the step of controlling the transmission of the first access request from the bus to a hardware unit corresponding to the second controller based on the interrupt signal.
10. The step of controlling the transmission of the first access request from the bus to the hardware unit corresponding to the target controller is: The steps include determining the target access request for the response timeout in the first access request, The steps include generating response information for the aforementioned target access request, A bus access method in an integrated circuit according to claim 6, comprising the step of controlling the transmission of the first access request from the bus to a hardware unit corresponding to the second controller based on the response information.
11. Controller and A first hardware unit corresponding to the first functional safety level domain, A second hardware unit corresponding to the second functional safety level domain, A register in which first configuration information corresponding to the second hardware unit is stored, The first configuration information includes second identification information of a target hardware unit whose safety level in the functional safety level domain is higher than the safety level in the second functional safety level domain. The first hardware unit generates a first access request, The controller determines the first identification information of the first hardware unit based on the first access request. The controller further reads the first configuration information from the register, The controller further determines, based on the first and second identification information, whether the first hardware unit has the authority to access the second hardware unit. The integrated circuit is further characterized in that the controller controls the transmission of the first access request from the bus to the second hardware unit based on the first hardware unit's authority to access the second hardware unit.
12. A computer-readable storage medium characterized by storing a computer program for executing a bus access method in an integrated circuit according to any one of claims 1 to 3.
13. An electronic device comprising a processor and a memory for storing instructions that the processor can execute, The processor reads and executes the executable instructions from the memory, thereby realizing the bus access method in the integrated circuit according to any one of claims 1 to 3. Or, An electronic device comprising the integrated circuit described in claim 11.