Chips and chip-based data access methods, storage media and electronic devices
Patent Information
- Application Number
- JP2026035739
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-07
- Filing Date
- 2026-03-06
- Publication Date
- 2026-09-17
AI Technical Summary
【0010】 本開示の上記実施例に係るチップおよびチップに基づくデータアクセス方法、記憶媒体、電子機器並びにプログラム製品によれば、第1チップドメインは、分離回路に対して第2チップドメインへのデータアクセス要求を発起することでき、分離回路は、データアクセス要求に基づいて第2チップドメインの記憶空間に対してメモリアクセス操作を実行し、第2チップドメインによるメモリアクセス操作に対する実際フィードバック状態に基づいて、第1チップドメインにデータアクセス要求の要求実行結果を返すことにより、第1チップドメインによる第2チップドメインへのデータアクセスを完了する。即ち、本開示の実施例では、高機能安全レベルの第1チップドメインは、分離回路により低機能安全レベルの第2チップドメインの記憶空間に対してデータアクセスを行うことができ、それにより高機能安全レベルの第1チップドメインは、低機能安全レベルの第2チップドメインの記憶空間を柔軟に使用することができ、低機能安全レベルの第2チップドメインの記憶空間を高機能安全レベルの第1チップドメインの拡張記憶空間として機能させることができる。これにより、追加のチップ面積オーバーヘッド無しで、高機能安全レベルの第1チップドメインの記憶空間を拡大させて、高機能安全レベルの第1チップドメインがプログラムを円滑に実行することにより、プログラム実行の円滑さとチップ面積オーバーヘッドとを両立させることができる。また、分離回路は、第1チップドメインと第2チップドメインとを効果的に分離させて、第1チップドメインと第2チップドメインとの直接通信を回避し、これにより、第2チップドメインの機能安全異常(例えば、予期せぬ電断、プログラム暴走、悪意あるエラー注入など)が第1チップドメインの正常的動作に影響を与えることを防ぐことができる。
Smart Images

Figure 2026148545000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to driving technology, and in particular to a chip, a chip-based data access method, a storage medium, and an electronic device.
Background Art
[0002] In the field of driving technology, chips have a very wide range of applications. The chip may be, for example, an intelligent driving chip, and a plurality of chip domains may exist in the chip.
[0003] If the storage space of a chip domain is too small, the chip domain cannot smoothly execute programs; if the storage space of a chip domain is too large, additional area overhead will be incurred. How to balance the smoothness of program execution and chip area overhead is a technical issue that deserves attention from those skilled in the art.
Summary of the Invention
Problem to be Solved by the Invention
[0004] In order to solve the above technical problem, the present disclosure provides a chip, a chip-based data access method, a storage medium, and an electronic device.
Means for Solving the Problem
[0005] A chip according to one aspect of an embodiment of the present disclosure includes a first chip domain, a second chip domain, and an isolation circuit, a functional safety level of the first chip domain is higher than a functional safety level of the second chip domain, the first chip domain generates a data access request to the second chip domain, The isolation circuit performs a memory access operation on the storage space of the second chip domain based on the data access request, and returns the request execution result of the data access request to the first chip domain based on the actual feedback state of the second chip domain to the memory access operation, thereby causing the storage space of the second chip domain to function as an extended storage space of the first chip domain.
[0006] A data access method based on a chip according to another embodiment of the embodiments of the present disclosure, wherein the chip includes a first chip domain, a second chip domain, and an isolation circuit. The functional safety level of the first chip domain is higher than that of the second chip domain. The aforementioned data access method is: The first chip domain generates a data access request to the second chip domain, The isolation circuit includes the steps of: performing a memory access operation on the storage space of the second chip domain based on the data access request; and returning the request execution result of the data access request to the first chip domain based on the actual feedback state of the second chip domain to the memory access operation, thereby causing the storage space of the second chip domain to function as an extended storage space of the first chip domain.
[0007] A computer-readable storage medium according to yet another embodiment of the embodiments of the present disclosure stores a computer program, and the computer program is executed by a processor to realize the above-mentioned chip-based data access method.
[0008] Electronic devices relating to yet another embodiment of the embodiments of this disclosure are: Processor and The processor includes a memory for storing executable instructions, The processor reads and executes the executable instructions from the memory, thereby realizing the data access method based on the chip described above.
[0009] A computer program product according to yet another embodiment of the embodiments of the present disclosure stores processor-executable instructions, and when the processor executes the executable instructions, the processor is caused to perform steps in the data access method based on the chip. [Effects of the Invention]
[0010] According to the chip and data access method, storage medium, electronic device, and program product based on the above embodiment of the present disclosure, the first chip domain can initiate a data access request to the second chip domain from an isolation circuit, the isolation circuit performs a memory access operation on the storage space of the second chip domain based on the data access request, and completes the data access to the second chip domain by the first chip domain by returning the request execution result of the data access request to the first chip domain based on the actual feedback state to the memory access operation by the second chip domain. That is, in the embodiment of the present disclosure, the first chip domain with a high level of safety can perform data access to the storage space of the second chip domain with a low level of safety via the isolation circuit, thereby allowing the first chip domain with a high level of safety to flexibly use the storage space of the second chip domain with a low level of safety, and allowing the storage space of the second chip domain with a low level of safety to function as an extended storage space for the first chip domain with a high level of safety. This expands the memory space of the first chip domain with high functionality and safety level without additional chip area overhead, enabling smooth program execution and minimizing chip area overhead. Furthermore, the isolation circuit effectively separates the first and second chip domains, avoiding direct communication between them. This prevents functional safety anomalies in the second chip domain (e.g., unexpected power outages, program malfunctions, malicious error injection, etc.) from affecting the normal operation of the first chip domain. [Brief explanation of the drawing]
[0011] [Figure 1] This is a first schematic diagram of a chip relating to some exemplary embodiments of the present disclosure. [Figure 2] This is a second schematic diagram of a chip relating to some exemplary embodiments of the present disclosure. [Figure 3]This is a third schematic diagram of a chip relating to some exemplary embodiments of the present disclosure. [Figure 4] This is a first flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 5] This is a second flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 6] This is a third flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 7] This is a fourth flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 8] This is a fifth flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 9] This is a sixth flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 10] This is a seventh flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 11] This is an eighth flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 12] This is a ninth flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 13] This is a tenth flowchart of a chip-based data access method relating to some exemplary embodiments of the present disclosure. [Figure 14] These are schematic diagrams of electronic devices relating to some exemplary embodiments of the present disclosure. [Modes for carrying out the invention]
[0012] Hereinafter, to describe the present disclosure, exemplary embodiments of the present disclosure will be described in detail with reference to the drawings. The described embodiments are merely some embodiments of the present disclosure, not all embodiments, and the present disclosure is not limited to the exemplary embodiments.
[0013] Unless specifically stated otherwise, the relative arrangement of components and steps, mathematical formulas and numerical values described in these embodiments do not limit the scope of the present disclosure.
[0014] [Summary of the Application] A chip may include at least two subsystems. Each subsystem among the at least two subsystems may include a processor, a memory, a peripheral module, and the like. The processor may be, for example, a Central Processing Unit (CPU). The memory may be, for example, Double Data Rate Synchronous Dynamic Random Access Memory (DDR), Static Random Access Memory (SRAM), or the like.
[0015] Furthermore, each subsystem among the at least two subsystems may have a corresponding functional safety level. A single subsystem may be configured as one chip domain, or a plurality of subsystems with the same functional safety level may be configured as one chip domain, whereby a plurality of chip domains may exist in the chip.
[0016] In the process of implementing the present disclosure, the inventor has found that if the storage space of a chip domain is too small, the chip domain cannot smoothly execute programs; if the storage space of the chip domain is too large, additional chip area overhead is incurred. Therefore, it is necessary to take some measures to balance the smoothness of program execution and chip area overhead.
[0017] [Example System] Automotive functional safety standards define Automotive Safety Integration Levels (ASIL), which consist of five functional safety levels: Quality Management (QM), ASIL-A, ASIL-B, ASIL-C, and ASIL-D. Here, the QM level is lower than ASIL-A, ASIL-A is lower than ASIL-B, ASIL-B is lower than ASIL-C, and ASIL-C is lower than ASIL-D.
[0018] In the embodiments of this disclosure, the storage space of the low-security chip domain can function as an extended storage space for the high-security chip domain by having the high-security chip domain access the storage space of the low-security chip domain. This expands the storage space of the high-security chip domain without additional chip area overhead, allowing the high-security chip domain to execute programs smoothly and thus achieving both smooth program execution and reduced chip area overhead.
[0019] [Example Circuit] Figure 1 is a schematic diagram of the structure of a chip according to some exemplary embodiments of the present disclosure. The chip shown in Figure 1 may be an intelligent operation chip. The chip shown in Figure 1 may include a first chip domain 1, a second chip domain 3, and an isolation circuit 5. The functional safety level of the first chip domain 1 is higher than that of the second chip domain 3, and the first chip domain 1 generates data access requests to the second chip domain 3. The isolation circuit 5 performs a memory access operation on the storage space of the second chip domain 3 based on the data access request, and returns the result of the data access request to the first chip domain 1 based on the actual feedback state to the memory access operation by the second chip domain 3, thereby causing the storage space of the second chip domain 3 to function as an extended storage space of the first chip domain 1.
[0020] Selectively, the first chip domain 1 and the second chip domain 3 can be any two chip domains with different functional safety levels in the chip (it is necessary to ensure that the functional safety level of the first chip domain 1 is higher than that of the second chip domain 3). For example, the first chip domain 1 could be a chip domain with a functional safety level of ASIL-D, and the second chip domain 3 could be a chip domain with a functional safety level of ASIL-A, ASIL-B, or ASIL-C. Alternatively, for example, the first chip domain 1 could be a chip domain with a functional safety level of ASIL-C, and the second chip domain 3 could be a chip domain with a functional safety level of ASIL-A or ASIL-B.
[0021] Selectively, the isolation circuit 5 is a circuit that assists in enabling data access to the memory space of the second chip domain 3 by the first chip domain 1, and can be a circuit for separating the first chip domain 1 and the second chip domain 3. The isolation circuit 5 can be electrically connected to the first chip domain 1 and the second chip domain 3. The memory space of the second chip domain 3 can be the memory space within the memory contained in the second chip domain 3. The memory contained in the second chip domain 3 can be, for example, DDR.
[0022] The first chip domain 1 generates data access requests to the second chip domain 3, which may include, but are not limited to, read requests and write requests. The first chip domain 1 can transmit data access requests to the isolation circuit 5.
[0023] The isolation circuit 5 can acquire data access requests from the first chip domain 1 and perform memory access operations on the storage space of the second chip domain 3 based on the data access requests. If the data access request is a read request, the memory access operation that the isolation circuit 5 performs on the storage space of the second chip domain 3 is a read operation, that is, it can read the data corresponding to the read request (i.e., the data requested by the read request) from the storage space of the second chip domain 3. The data to be read corresponding to a read request may include, but is not limited to, feature map data, weight data, etc. If the data access request is a write request, the memory access operation that the isolation circuit 5 performs on the storage space of the second chip domain 3 is a write operation, that is, it can write the data to be written corresponding to the write request (i.e., the data to be written as instructed by the write request) to the storage space of the second chip domain 3. The data to be written corresponding to a write request may include, but is not limited to, feature map data, weight data, etc.
[0024] The isolation circuit 5 can determine the actual feedback state for memory access operations performed by the second chip domain 3. The actual feedback state can indicate whether or not the second chip domain 3 returned actual access feedback for the memory access operation. If the memory access operation is a read operation, the actual access feedback is read feedback, and this read feedback can be read data corresponding to the read request, or feedback information indicating a read failure. If the memory access operation is a write operation, the actual access feedback is write feedback, and this write feedback can be feedback information indicating a write success, or feedback information indicating a write failure.
[0025] The isolation circuit 5 can further return the request execution result of a data access request to the first chip domain 1 based on the actual feedback state. If the actual feedback state indicates that the second chip domain 3 has already returned actual access feedback, the isolation circuit 5 can return the actual access feedback to the first chip domain 1 as the request execution result of the data access request. If the actual feedback state indicates that the second chip domain 3 has not returned actual access feedback, the isolation circuit 5 can generate simulated access feedback corresponding to the data access request and return that simulated access feedback to the first chip domain 1 as the request execution result of the data access request. Note that the simulated access feedback is not the actual access feedback returned by the second chip domain 3, but rather access feedback intended to simulate actual access feedback. If the data access request is a read request, the simulated access feedback can be a simulated read feedback indicating a read failure, and if the data access request is a write request, the simulated access feedback can be a simulated write feedback indicating a write failure.
[0026] In the embodiments of this disclosure, the first chip domain 1 initiates a data access request to the second chip domain 3 via the isolation circuit 5. Based on the data access request, the isolation circuit 5 performs a memory access operation on the storage space of the second chip domain 3 and returns the result of the data access request to the first chip domain 1 based on the actual feedback state to the memory access operation by the second chip domain 3, thereby completing the data access of the first chip domain 1 to the second chip domain 3. That is, in the embodiments of this disclosure, the first chip domain 1, which is at a high level of safety, can access data on the storage space of the second chip domain 3, which is at a low level of safety, via the isolation circuit 5. This allows the first chip domain 1, at a high level of safety, to flexibly use the storage space of the second chip domain 3, which is at a low level of safety, to function as an extended storage space for the first chip domain 1, at a high level of safety. This expands the memory space of the first chip domain 1 with a high level of safety without additional chip area overhead, and allows the first chip domain 1 with a high level of safety to execute programs smoothly, thus providing an advantage in balancing smooth program execution with chip area overhead. Furthermore, the isolation circuit 5 effectively isolates the first chip domain 1 and the second chip domain 3, avoiding direct communication between them. This prevents functional safety anomalies in the second chip domain 3 (e.g., unexpected power outage, program runaway, malicious error injection, etc.) from affecting the normal operation of the first chip domain 1.
[0027] In some selective examples, as shown in Figure 2, the isolation circuit 5 includes a first isolation sub-circuit 51 and a second isolation sub-circuit 53, and the second isolation sub-circuit 53 may include an isolation module 531, a first buffer 533, and a second buffer 535.
[0028] The isolation circuit 5 performs a memory access operation on the storage space of the second chip domain 3 based on the data access request, and returns the request execution result of the data access request to the first chip domain 1 based on the actual feedback state to the memory access operation by the second chip domain 3. The first separation subcircuit 51 caches the target content in the first buffer 533 based on the data access request, The isolation module 531 performs a memory access operation on one memory area of the memory space based on the target content in the first buffer 533, and in response to obtaining actual access feedback of the memory access operation that occurred in the memory area by the second chip domain 3, caches the actual access feedback in the second buffer 535. The first separation subcircuit 51 may include determining the actual feedback state for memory access operations that occurred in the storage area by the second chip domain 3 based on the cache state of the actual access feedback of the second buffer 535, and returning the request execution result of the data access request to the first chip domain 1 based on the actual feedback state corresponding to the storage area.
[0029] Selectively, the first isolation subcircuit 51 can be a subcircuit in the isolation circuit 5 that communicates with the first chip domain 1 and detects functional safety anomalies in the first chip domain 1 and the second chip domain 3. The second isolation subcircuit 53 can be a subcircuit in the isolation circuit 5 that communicates with the first isolation subcircuit 51 and the second chip domain 3 and controls reading and writing to the second chip domain 3. The first buffer 533 and the second buffer 535 are data buffers in the second isolation subcircuit 53, and the first buffer 533 and the second buffer 535 can be, for example, first-in, first-out (FIFO) buffers. The isolation module 531 can be a subcircuit in the second isolation subcircuit 53 that communicates with the second chip domain 3, the first buffer 533 and the second buffer 535 and controls reading and writing to the second chip domain 3. The isolation module 531 is electrically connected to the second chip domain 3, the first buffer 533, and the second buffer 535. The first buffer 533 and the second buffer 535 are also electrically connected to the first isolation subcircuit 51, and the first isolation subcircuit 51 can also be electrically connected to the first chip domain 1.
[0030] The first isolation subcircuit 51 can acquire data access requests from the first chip domain 1 and cache target content in the first buffer 533 based on those data access requests. If the data access request is a read request, the first isolation subcircuit 51 can cache the read request as target content in the first buffer 533. If the data access request is a write request, the first isolation subcircuit 51 can acquire the write data corresponding to the write request and cache the write request and the corresponding write data as target content in the first buffer 533.
[0031] The isolation module 531 can perform a memory access operation on one memory area in the memory space based on the target content in the first buffer 533. If the data access request is a read request, the read request may carry a read address, and as described in the paragraph above, if the data access request is a read request, the read request may function as the target content, and correspondingly the target content may contain a read address, thereby enabling the isolation module 531 to obtain the read address from the target content and perform a read operation on the memory area in the memory space corresponding to the read address. If the data access request is a write request, the write request can carry a write address, and as described in the paragraph above, if the data access request is a write request, the write request and the write data corresponding to the write request can function as target content, and correspondingly, the target content can include a write address and write data, thereby enabling the isolation module 531 to obtain the write address and write data from the target content and perform a write operation on the memory area corresponding to the write address in the memory space, that is, to write the write data to the memory area corresponding to the write address.
[0032] The isolation module 531 can also monitor whether or not it has obtained actual access feedback for memory access operations that occurred in the storage area of the second chip domain 3. If it obtains actual access feedback for memory access operations that occurred in the storage area of the second chip domain 3, the isolation module 531 can cache the actual access feedback in the second buffer 535. If it has not obtained actual access feedback for memory access operations that occurred in the storage area of the second chip domain 3, the isolation module 531 does not perform the operation to cache the actual access feedback in the second buffer 535.
[0033] The first isolation subcircuit 51 determines the cache state of the actual access feedback by the second buffer 535, and based on this, can determine the actual feedback state (also called the "actual feedback state corresponding to the memory area") for memory access operations that occurred in the memory area of the second chip domain 3. The cache state of the actual access feedback by the second buffer 535 can indicate whether or not the second buffer 535 has cached the actual access feedback. If the second buffer 535 has cached the actual access feedback, the actual feedback state corresponding to the memory area can indicate that the second chip domain 3 has already returned actual access feedback for the memory access operation. If the second buffer 535 has not cached the actual access feedback, the actual feedback state corresponding to the memory area can indicate that the second chip domain 3 has not returned actual access feedback for the memory access operation. Based on the actual feedback state corresponding to the memory area, the first isolation subcircuit 51 can return the request execution result of the data access request to the first chip domain 1.
[0034] In the embodiments of this disclosure, the first isolation subcircuit 51, the isolation module 531, the first buffer 533, and the second buffer 535 work together to perform a corresponding memory access operation on the corresponding storage area of the storage space Furthermore, the first isolation subcircuit 51, isolation module 531, first buffer 533, and second buffer 535 effectively isolate the first chip domain 1 and the second chip domain 3, preventing a functional safety anomaly in the second chip domain 3 from affecting the normal operation of the first chip domain 1.
[0035] In some selective examples, as shown in Figure 3, the first isolation subcircuit 51 may include a detection module 511 and a result return module 513.
[0036] The first isolation subcircuit 51 returns the request execution result of the data access request to the first chip domain 1 based on the actual feedback state corresponding to the memory area. The detection module 511 determines the first functional safety detection result of the second chip domain 3 based on the actual feedback state corresponding to the memory area, The result return module 513 may include returning the request execution result of the data access request to the first chip domain 1 based on the first functional safety detection result.
[0037] Selectively, the detection module 511 may be a subcircuit in the first isolation subcircuit 51 for detecting functional safety anomalies in the first chip domain 1 and the second chip domain 3. The result return module 513 may be a subcircuit in the first isolation subcircuit 51 for returning the request execution result of a data access request to the first chip domain 1. The result return module 513 may be electrically connected to the detection module 511 and also electrically connected to the first chip domain 1.
[0038] Selectively, the detection module 511 can determine a first functional safety detection result for the second chip domain 3 using a predetermined detection strategy based on the actual feedback state corresponding to the memory area. The predetermined detection strategy may include, but is not limited to, a redundant backup detection strategy or a timeout detection strategy. The first functional safety detection result for the second chip domain 3 can indicate whether or not a functional safety anomaly exists in the second chip domain 3.
[0039] The following describes a redundant backup detection strategy.
[0040] When a redundant backup detection strategy is adopted, the number of second isolation subcircuits 53 is at least two, for example, as shown in Figure 3 (indicated by the two "×2"s in Figure 3). Since each of the at least two second isolation subcircuits 53 contains one isolation module 531, there are at least two isolation modules 531 in total for at least two second isolation subcircuits 53. Furthermore, each of the at least two isolation modules 531 corresponds to one memory area (the memory area corresponding to each isolation module 531 is the memory area in which the isolation module 531 performs memory access operations), so that at least two isolation modules 531 can correspond to at least two memory areas, and there is a one-to-one relationship between at least two memory areas and at least two isolation modules 531.
[0041] Correspondingly, the detection module 511 determines the first functional safety detection result of the second chip domain 3 based on the actual feedback state corresponding to the memory area. The detection module 511 may, in response to at least two actual feedback states corresponding to at least two memory areas all indicating that the second chip domain 3 has already returned actual access feedback, determine a first matching degree between at least two actual access feedbacks corresponding to at least two actual feedback states, and determine a first functional safety detection result for the second chip domain 3 based on the first matching degree.
[0042] Furthermore, in response to a data access request, each of the at least two memory areas can correspond to one actual feedback state, thereby enabling a one-to-one correspondence between the at least two memory areas and at least two actual feedback states.
[0043] Selectively, as shown in Figure 3, the detection module 511 includes a first detection unit 5111, which is a detection unit for executing a redundant backup detection strategy within the detection module 511. If at least two actual feedback states both indicate that the second chip domain 3 has already returned an actual access feedback, then a first degree of agreement can be determined between at least two actual access feedbacks that correspond one-to-one with the at least two actual feedback states. For any two actual access feedbacks among the at least two actual access feedbacks, the first detection unit 5111 can determine whether these two actual access feedbacks are identical. If they are identical, the first detection unit 5111 can determine that the first degree of agreement between these two actual access feedbacks is 1. If they are not identical, the first detection unit 5111 can determine that the first degree of agreement between these two actual access feedbacks is 0. According to the above scheme, the first detection unit 5111 can obtain at least one first degree of agreement. The first detection unit 5111 can determine a first functional safety detection result for the second chip domain 3 based on at least one first matching degree. For example, if at least one of the first matching degrees is 1, the first functional safety detection result can indicate that there is no functional safety anomaly in the second chip domain 3. If at least some of the first matching degrees are 0, the first functional safety detection result can indicate that there is a functional safety anomaly in the second chip domain 3.
[0044] Theoretically, if the second chip domain 3 can operate normally, at least two actual access feedbacks corresponding one-to-one with at least two memory areas will match. From this perspective, a first degree of agreement between at least two actual access feedbacks can be determined to clarify whether or not at least two actual access feedbacks actually match. If at least two actual access feedbacks actually match, it means that the actual situation matches the theoretical situation, and thus it can be determined that there is no functional safety anomaly in the second chip domain 3. If at least two actual access feedbacks do not actually match, it means that the actual situation does not match the theoretical situation, and thus it can be determined that there is a functional safety anomaly in the second chip domain 3. Therefore, by employing a redundant backup detection strategy, the first functional safety detection result for the second chip domain 3 can be determined efficiently and reliably.
[0045] The following describes timeout detection strategies.
[0046] When a timeout detection strategy is employed, the detection module 511 starts executing a timing operation in response to the first isolation subcircuit 51 receiving a data access request.
[0047] The detection module 511 determines the first functional safety detection result of the second chip domain 3 based on the actual feedback state corresponding to the memory area. The detection module 511 includes determining a second degree of agreement between the actual feedback state and the expected feedback state corresponding to the memory area, and determining a first functional safety detection result for the second chip domain 3 based on the second degree of agreement. Here, the expected feedback state indicates that the second chip domain 3 has already returned actual access feedback before the timing duration of the timing operation reaches a preset duration.
[0048] Selectively, as shown in Figure 3, the detection module 511 includes a second detection unit 5113, which is a detection unit for executing a timeout detection strategy within the detection module 511, and the second detection unit 5113 may have a timing function. The first isolation subcircuit 51 further includes a setting module 514, which can set a preset time length for the second detection unit 5113, and the preset time length may be the maximum time length required for the first chip domain 1 to perform one data access to the second chip domain 3 via the isolation circuit 5, which is preset by experience.
[0049] The second detection unit 5113 can start executing a timing operation in response to the first isolation subcircuit 51 receiving a data access request from the first chip domain 1. The second detection unit 5113 can determine whether the second chip domain 3 has returned actual access feedback before the timing duration of the timing operation reaches a preset duration. If the actual feedback state corresponding to the memory area indicates that the second chip domain 3 has already returned actual access feedback before the timing duration of the timing operation reaches a preset duration, the second detection unit 5113 can determine that the second degree of agreement between the actual feedback state corresponding to the memory area and the expected feedback state is 1. In this case, the first functional safety detection result for the second chip domain 3 can indicate that there is no functional safety anomaly in the second chip domain 3. If the actual feedback state corresponding to the memory area indicates that the second chip domain 3 has not returned actual access feedback before the timing duration of the timing operation reaches a preset duration, the second detection unit 5113 can determine that the second degree of agreement between the actual feedback state and the expected feedback state corresponding to the memory area is 0. In this case, the first functional safety detection result for the second chip domain 3 indicates that a functional safety anomaly exists in the second chip domain 3.
[0050] Theoretically, if the second chip domain 3 is operating normally, it will return actual access feedback before the timing duration of the timing operation reaches a preset duration. From this perspective, by determining the second degree of agreement between the actual feedback state and the expected feedback state corresponding to the memory area, it is possible to clarify whether the second chip domain 3 actually returned actual access feedback before the timing duration of the timing operation reached a preset duration. If the second chip domain 3 actually returned actual access feedback before the timing duration of the timing operation reached a preset duration, it means that the actual situation matches the theoretical situation, and thus it can be determined that there is no functional safety anomaly in the second chip domain 3. If the second chip domain 3 did not actually return actual access feedback before the timing duration of the timing operation reached a preset duration, it means that the actual situation does not match the theoretical situation, and thus it can be determined that there is a functional safety anomaly in the second chip domain 3. Therefore, by adopting a timeout detection strategy, the first functional safety detection result of the second chip domain 3 can be determined efficiently and reliably.
[0051] Selectively, the redundant backup detection strategy and the timeout detection strategy can be used in combination. For example, if all first-order matches are 1 and the second-order match is 1, the first functional safety detection result can indicate that there are no functional safety anomalies in the second chip domain 3. If some of the first-order matches are 0 and / or the second-order match is 0, the first functional safety detection result can indicate that there are functional safety anomalies in the second chip domain 3.
[0052] Regardless of the method used to determine the first functional safety detection result of the second chip domain 3, the result return module 513 can return the request execution result of the data access request to the first chip domain 1 based on the first functional safety detection result.
[0053] In some selective embodiments of this disclosure, the result return module 513 returns the request execution result of the data access request to the first chip domain 1 based on the first functional safety detection result. The result return module 513 may, in response to the first functional safety detection result indicating that no functional safety anomalies exist in the second chip domain 3, determine the target actual access feedback based on the actual feedback state corresponding to the memory area, and return that target actual access feedback to the first chip domain 1 as the request execution result of the data access request.
[0054] Taking the case where there are at least two second separation subcircuits 53 as an example, if the first functional safety detection result indicates that there are no functional safety anomalies in the second chip domain 3, it means that at least two actual feedback states corresponding to at least two memory areas all indicate that the second chip domain has already returned actual access feedback. This allows one actual access feedback to be randomly selected as the target actual access feedback from at least two actual access feedbacks corresponding to at least two actual feedback states. The result return module 513 can return the target actual access feedback to the first chip domain 1 as the request execution result of the data access request. This allows the first chip domain 1 to obtain actual access feedback for the memory access operation by the second chip domain 3, and based on this, the first chip domain 1 can determine the next operation to be performed. For example, if the actual access feedback is feedback information indicating a read failure or write failure, the first chip domain 1 can reinvoke the data access request that was previously initiated. If the actual access feedback is feedback information indicating a write success or read success, the first chip domain 1 can invoke a new data access request.
[0055] In some other selective embodiments of this disclosure, the result return module 513 returns the request execution result of the data access request to the first chip domain 1 based on the first functional safety detection result. The result return module 513 may, in response to the first functional safety detection result indicating the presence of a functional safety anomaly in the second chip domain 3, generate a simulated access feedback corresponding to the data access request and return the simulated access feedback to the first chip domain 1 as the request execution result of the data access request.
[0056] Selectively, the simulated access feedback is not the actual access feedback returned by the second chip domain 3, but rather access feedback intended to simulate the actual access feedback. If the data access request is a read request, the simulated access feedback can be a simulated read feedback indicating a read failure. If the data access request is a write request, the simulated access feedback can be a simulated write feedback indicating a write failure.
[0057] Since the result return module 513 returns simulated access feedback to the first chip domain 1 as the result of executing a data access request, the first chip domain 1 can obtain simulated access feedback and, based on this, can decide what operation to perform next, for example, whether to reinitiate a data access request that was previously initiated or to initiate a new data access request. As a result, even if the second chip domain 3 fails to return actual access feedback for a memory access operation due to a functional safety anomaly in the second chip domain 3, or if there is an anomaly in the actual access feedback returned by the second chip domain 3 for a memory access operation (for example, if the first degree of agreement is 0), the result return module 513 can generate simulated access feedback itself and return it to the first chip domain 1, thereby preventing the loss of access feedback, complementing the entire data access flow, and preventing the first chip domain 1 from remaining in a waiting state for a long period of time without being able to obtain access feedback.
[0058] In the embodiments of this disclosure, the detection module 511 can efficiently and reliably determine whether a functional safety anomaly exists in the second chip domain 3 based on the actual feedback state corresponding to the memory area, and the result return module 513 can return a request execution result corresponding to the first chip domain 1 based on this, thereby enabling the entire data access flow to be executed normally regardless of whether a functional safety anomaly exists in the second chip domain 3.
[0059] In some selective examples, as shown in Figure 3, the first isolation subcircuit 51 may further include a first readout module 515 and a first counter 517.
[0060] The first counter 517 records a first number of actual access feedbacks already cached by at least two of the two second buffers 535 of the at least two second isolation subcircuits 53.
[0061] Before the detection module 511 determines a first degree of agreement between two actual access feedbacks corresponding to at least two actual feedback states, the first read module 515, in response to determining that at least two second buffers 535 all satisfy a preset read condition based on a first number of actual access feedbacks already cached by at least two second buffers 535, performs a data read from at least two second buffers 535 to obtain two actual access feedbacks corresponding to at least two actual feedback states.
[0062] Selectively, the first counter 517 may include at least two counters, each of which records a first number of actual access feedbacks already cached by one of the at least two second buffers 535.
[0063] Selectively, a pre-configured read condition can be that the buffer is non-empty (i.e., that there is readable content in the buffer).
[0064] When employing a redundant backup detection strategy, the first read module 515 can determine whether the first number of actual access feedbacks already cached by the at least two second buffers 535, recorded by the first counter 517, is zero, before the detection module 511 determines the first degree of agreement between the two actual access feedbacks corresponding to at least two actual feedback states. If the first number of actual access feedbacks already cached by at least two second buffers 535 is not zero, it indicates that there are readable actual access feedbacks in at least two second buffers 535, and it can be determined that at least two second buffers 535 satisfy the preset read conditions. As a result, the first read module 515 can send read enable signals to at least two second buffers 535, and at least two second buffers 535, in response to the received read enable signals, return the actual access feedbacks they have cached to the first read module 515. At this time, the first number of actual access feedbacks already cached, recorded by the first counter 517, can each be reduced by 1 from its current value. As a result, the first read module 515 can obtain two actual access feedbacks corresponding to at least two actual feedback states by reading the data and use them to determine the first degree of match. If at least two of the second buffers 535 have a first number of actual access feedback already cached by some of the second buffers 535 being 0, it indicates that there is no readable actual access feedback in those some of the second buffers 535, and it can be determined that at least two of the second buffers 535 do not satisfy the preset read conditions, and a wait period can be established. After the established period, if at least two of the second buffers 535 both satisfy the preset read conditions, at least two actual access feedbacks corresponding to at least two actual feedback states can be obtained by reading data from at least two of the second buffers 535, and these can be used to determine the first degree of match.
[0065] In the embodiments of this disclosure, the installation of the first read module 515 and the first counter 517 allows monitoring of the presence of readable actual access feedback in at least two second buffers 535, and enables data reading only in such situations to successfully read at least two actual access feedbacks for use in determining the first degree of match, thereby avoiding resource consumption and power consumption caused by performing data reading in other situations.
[0066] In some selective examples, the first isolation subcircuit 51 further determines a first functional safety detection result for the second chip domain 3 based on the actual feedback state corresponding to the memory area, and performs a first target anomaly handling operation in response to the first functional safety detection result indicating the presence of a functional safety anomaly in the second chip domain 3.
[0067] The specific method by which the first isolation subcircuit 51 selectively determines the first functional safety detection result of the second chip domain 3 based on the actual feedback state corresponding to the memory area can be found in the related introduction above, and will not be explained here. If the first functional safety detection result indicates that a functional safety anomaly exists in the second chip domain 3, the first isolation subcircuit 51 executes a first target anomaly processing operation, which is an anomaly processing operation to prevent the functional safety anomaly in the second chip domain 3 from affecting the normal operation of the first chip domain 1.
[0068] In some selective embodiments of the present disclosure, the first isolation subcircuit 51 performs a first target abnormality processing operation. The first isolation subcircuit 51 may send a first interrupt signal to the first chip domain 1, and in response to the first chip domain 1 receiving the first interrupt signal, it may control the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 to reset.
[0069] Selectively, reset lines may be provided between the first chip domain 1 and the second chip domain 3, between the first chip domain 1 and the isolation module 531, between the first chip domain 1 and the first buffer 533, and between the first chip domain 1 and the second buffer 535. The first chip domain 1 can transmit reset signals to the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 via these reset lines, thereby causing the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 to perform reset operations in response to the received reset signals. Alternatively, the first chip domain 1 can write reset commands to the setting module 514 for the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535, respectively. The first isolation subcircuit 51 can then transmit the reset commands written to the setting module 514 to the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535, respectively. As a result, the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 perform reset operations in response to the received reset commands.
[0070] In this embodiment, the first isolation subcircuit 51 transmits a first interrupt signal to the first chip domain 1, causing the first chip domain 1 to detect a functional safety anomaly in the second chip domain 3. This controls the first chip domain 1 to reset the second chip domain 3, the isolation module 531, the first buffer 533, and the second buffer 535 in a timely manner. On the one hand, this restores the second chip domain 3 to a normal operating state, preventing the functional safety anomaly in the second chip domain 3 from affecting the normal operation of the first chip domain 1. On the other hand, it clears the data cached in the second isolation subcircuit 53 (for example, target content cached in the first buffer 533, actual access feedback cached in the second buffer 535, and the second number recorded by the second counter 5313 described later), preventing this data from affecting subsequent data access.
[0071] In some other selective embodiments of the present disclosure, the first isolation subcircuit 51 performs a first target abnormality processing operation. The first separation subcircuit 51 includes disconnecting the communication link between the first separation subcircuit 51 and the first buffer 533, and disconnecting the communication link between the first separation subcircuit 51 and the second buffer 535.
[0072] Selectively, the communication link between the first separation subcircuit 51 and the first buffer 533 can be a bus connecting the first separation subcircuit 51 and the first buffer 533, and the communication link between the first separation subcircuit 51 and the first buffer 533 can be disconnected by disconnecting this bus. The method for disconnecting the communication link between the first separation subcircuit 51 and the second buffer 535 is the same as described above, so its explanation is omitted here. In actual implementation, any position in Figure 3 where the symbol "×" is drawn individually between the first separation subcircuit 51 and the second separation subcircuit 53 can be disconnected.
[0073] In the embodiments of this disclosure, by disconnecting the communication link between the first isolation subcircuit 51 and the first buffer 533, and by disconnecting the communication link between the first isolation subcircuit 51 and the second buffer 535, the communication link between the first chip domain 1 and the second chip domain 3 can be interrupted, thereby preventing a functional safety abnormality in the second chip domain 3 from affecting the normal operation of the first chip domain 1.
[0074] In some selective examples, as shown in Figure 3, the isolation module 531 may include a second read module 5311 and a second counter 5313.
[0075] The second counter 5313 records the second number of target content already cached by the first buffer 533.
[0076] Before the isolation module 531 performs a memory access operation on one of the memory areas in the memory space based on the target content in the first buffer 533, the second read module 5311, in response to determining that the first buffer 533 satisfies a pre-configured read condition based on a second number of target contents already cached by the first buffer 533, performs a data read from the first buffer 533 to obtain the target content in the first buffer 533.
[0077] Selectively, a pre-configured read condition can be that the buffer is non-empty (i.e., that there is readable content in the buffer).
[0078] Before the isolation module 531 performs a memory access operation on one of the memory areas in the memory space based on the target content in the first buffer 533, the second read module 5311 can determine whether the second number of target content already cached by the first buffer 533, recorded by the second counter 5313, is zero. If the second number of target content already cached by the first buffer 533 is not zero, it indicates that there is readable target content in the first buffer 533, and the second read module 5311 can determine that the first buffer 533 satisfies the preset read condition. As a result, the second read module 5311 can send a read enable signal to the first buffer 533, and the first buffer 533, in response to the received read enable signal, returns the target content it has cached to the second read module 5311. This allows the second read module 5311 to obtain the target content by reading the data and use it for subsequent memory access operations. If the second number of target content already cached by the first buffer 533 is 0, it indicates that there is no target content available to read from the first buffer 533. It is determined that the first buffer 533 does not meet the pre-set read conditions, and the system can wait for a certain period of time. After the period, when the first buffer 533 meets the pre-set read conditions, the target content in the first buffer 533 can be obtained by reading data from the first buffer 533 and used for subsequent memory access operations.
[0079] In the embodiments of this disclosure, the installation of the second read module 5311 and the second counter 5313 monitors whether there is readable target content in the first buffer 533, and performs data reading only when such content exists. This allows the target content to be successfully read and used for subsequent memory access operations, while avoiding resource consumption and power consumption caused by performing data reading in other situations.
[0080] In some selective examples, the isolation circuit 5 further obtains actual access feedback from the second chip domain 3 and performs a first target anomaly handling operation in response to the actual access feedback and the data access request satisfying pre-set irrelevant conditions.
[0081] Selectively, if the actual access feedback and the data access request satisfy a pre-configured irrelevance condition, it can be understood that the actual access feedback was not returned in response to a memory access operation corresponding to a data access request by the second chip domain 3, but rather initiated spontaneously by the second chip domain 3. The pre-configured irrelevance condition is that the carrying state of the request ID is different. For example, if the carrying state of the request ID in the data access request is that the request ID is carried, and the carried request ID is specifically ID1, and the carrying state of the request ID in the actual access feedback is that the request ID is not carried, or the request ID is carried but the carried request ID is ID2 (different from ID1 carried during any data access request), then it can be determined that the actual access feedback and the data access request satisfy a pre-configured irrelevance condition.
[0082] Selectively, as shown in Figure 3, the detection module 511 may include a third detection unit 5115, which is a detection unit for making decisions regarding irrelevant conditions pre-set within the detection module 511. When the isolation circuit 5 obtains actual access feedback from the second chip domain 3 and the third detection unit 5115 determines that the actual access feedback and the data access request satisfy pre-set irrelevant conditions, it means that the first chip domain 1 has not initiated a data access request, but the second chip domain 3 has issued feedback, which is clearly not normal. Therefore, the third detection unit 5115 determines that a functional safety anomaly exists in the second chip domain 3, and at this time, the third detection unit 5115 can execute a first target anomaly processing operation. The types of first target anomaly processing operations can be found in the related introduction above, and their explanation is omitted here. This allows the second chip domain 3 to be restored to a normal operating state, preventing a functional safety anomaly in the second chip domain 3 from affecting the normal operation of the first chip domain 1, clearing the data cached in the second isolation subcircuit 53 to prevent this data from affecting subsequent data access, and further preventing a functional safety anomaly in the second chip domain 3 from affecting the normal operation of the first chip domain 1 by disconnecting the communication link between the first chip domain 1 and the second chip domain 3.
[0083] In some selective examples, the isolation circuit 5 further records a third number of data access requests in progress, determines a numerical relationship between the third number of data access requests in progress and a preset number, determines a second functional safety detection result for the first chip domain 1 based on the numerical relationship, and performs a second target anomaly processing operation in response to the second functional safety detection result indicating the presence of a functional safety anomaly in the first chip domain 1.
[0084] Selectively, as shown in Figure 3, the detection module 511 may include a fourth detection unit 5117, which is a detection unit for detecting functional safety anomalies in the first chip domain 1 within the detection module 511. The fourth detection unit 5117 may record the number of data access requests that are actually being executed (i.e., the third number). An executed data access request can be understood as a data access request that the first chip domain 1 has already initiated with the isolation circuit 5, but for which the first chip domain 1 has not yet received a request execution result from the isolation circuit 5. The setting module 514 may also set a preset number for the fourth detection unit 5117, which may be the maximum number of executed data access requests that the isolation circuit 5 supports. The fourth detection unit 5117 may further determine the numerical relationship between the third number of executed data access requests and the preset number, which may be the magnitude relationship between the third number of executed data access requests and the preset number. If the numerical relationship between the third number of data access requests in progress and the preset number indicates that the third number of data access requests in progress is greater than the preset number, it means that the actual number of data access requests in progress has already exceeded the maximum number that the isolation circuit 5 can support. This is clearly abnormal, and therefore the second functional safety detection result can indicate that a functional safety anomaly exists in the first chip domain 1. If the numerical relationship between the third number of data access requests in progress and the preset number indicates that the third number of data access requests in progress is less than or equal to the preset number, it means that the actual number of data access requests in progress has not exceeded the maximum number that the isolation circuit 5 can support. Therefore, the second functional safety detection result can indicate that there is no functional safety anomaly in the first chip domain 1. If the second functional safety detection result indicates that a functional safety anomaly exists in the first chip domain 1, the fourth detection unit 5117 can perform a second target anomaly processing operation, which can be a remediation operation for the functional safety anomaly in the first chip domain 1.
[0085] In some selective embodiments of this disclosure, the isolation circuit 5 performs a second target abnormality processing operation. The isolation circuit 5 may send a second interrupt signal to the first chip domain 1, and the first chip domain 1 may perform a reset operation in response to receiving the second interrupt signal.
[0086] If the second functional safety detection result indicates that a functional safety anomaly exists in the first chip domain 1, the fourth detection unit 5117 sends a second interrupt signal to the first chip domain 1. The second interrupt signal causes the first chip domain 1 to sense its own functional safety anomaly, and a timely reset operation restores the first chip domain 1 to a normal operating state.
[0087] Of course, the types of second target anomaly handling operations are not limited to these; other operations that help restore the first chip domain 1 to a normal operating state are also possible. For example, the isolation circuit 5 can issue a warning signal to alert the user to artificially repair the anomaly in the first chip domain 1.
[0088] In some selective examples, the first chip domain 1 may be a chip domain with a functional safety level of ASIL-D, and the second chip domain 3 may be a chip domain with a functional safety level of ASIL-A, ASIL-B, or ASIL-C, in which case the first chip domain 1 may also be called the ASIL-D domain, and the second chip domain 3 may also be called the other domain. Furthermore, the isolation circuit 5 may be called bdiso_dp IP, the first isolation sub-circuit 51 may be called bdiso_dp_s, the sub-circuit consisting of the first buffer 533, the second buffer 535, and two asynchronous modules in the second isolation sub-circuit 53 (see Figure 3, the asynchronous modules are for achieving cross-asynchronous operation) may be called bdiso_dp_async, and the isolation module 531 may be called bdiso_dp_m. The number of second isolation sub-circuits 53 may be two.
[0089] When the ASIL-D domain needs to write to the other domain, the ASIL-D domain initiates a write request and write data to the isolation circuit 5 via the bus. bdiso_dp_s receives the write request and write data and stores them in the two first buffers 533 in the two second isolation subcircuits 53, respectively. The first detection unit 5111 starts timing, and the fourth detection unit 5117 starts counting. bdiso_dp_m reads from the two first buffers 533, respectively, and transmits the read data (including the write request and write data) to two different storage areas of the DDR in the other domain for storage. After receiving write feedback from the other domain, bdiso_dp_m stores it in the two second buffers 535 in the two second isolation subcircuits 53. The first read module 515 in bdiso_dp_s reads from both second buffers 535 and compares the two read results when it finds that both second buffers 535 are non-empty (corresponding to the determination of the first match degree described above). If the comparison is successful (for example, if the first match degree is 1), the data (specifically, the request execution result) is returned to the ASIL-D domain; otherwise (if unsuccessful), an interrupt is reported. If no feedback is received within the specified time length, it is determined that the other domain has hung up.
[0090] When the ASIL-D domain needs to read data from the other domain, the ASIL-D domain initiates a read request to the isolation circuit 5 via the bus. bdiso_dp_s receives the read request and stores it in the two first buffers 533 in the two second isolation subcircuits 53, respectively. The first detection unit 5111 starts timing, and the fourth detection unit 5117 starts counting. bdiso_dp_m reads the data from the two first buffers 533 and sends the read data (including the read request) to the other domain. bdiso_dp_m receives two read feedbacks from the DDR in the other domain and stores them in the two second buffers 535 in the two second isolation subcircuits 53. The first read module 515 in bdiso_dp_s reads from both second buffers 535 and compares the two read results when it finds that both second buffers 535 are non-empty (corresponding to the determination of the first match degree above). If the comparison is successful (for example, if the first match degree is 1), it returns the data (i.e., the request execution result) to the ASIL-D domain; otherwise (if it fails), it broadcasts an interrupt. If no feedback is received within the specified time length, it is determined that the other domain has hung up.
[0091] Selectively, the bdiso_dp IP can announce an interrupt in scenarios such as: a) when the number of outstanding instructions initiated by the ASIL-D domain exceeds a set value (corresponding to the third number of data access requests in execution being greater than a preset number); b) when the other domain fails to provide feedback within a given clock cycle (corresponding to the second chip domain failing to provide actual access feedback before the timing duration of the timing operation reaches a preset duration); c) when the comparison of read data or write feedback issued by the other domain fails (corresponding to at least two of the actual access feedbacks not actually matching); and d) when the ASIL-D domain has not initiated an instruction, but the other domain has provided feedback (corresponding to the actual access feedback and data access request satisfying a preset unrelated condition).
[0092] Selectively, after the CPU in the ASIL-D domain receives an interrupt announced by the bdiso_dp IP, software intervention can be performed to reset the other domain or restore it to another normal operating state, and at the same time, bdiso_dp_async and bdiso_dp_m can also be reset to clear the data cached by the bdiso_dp IP.
[0093] Selectively, as shown in Figure 3, the first isolation subcircuit 51 may further include several handshake modules used for handshake communication between the first isolation subcircuit 51 and the first chip domain 1. Based on the handshake communication between the first isolation subcircuit 51 and the first chip domain 1, the first isolation subcircuit 51 may send a signal R1 to the first chip domain 1 indicating whether or not it is possible to write new target content to the first buffer 533, and the first chip domain 1 may return a signal R2 to the first isolation subcircuit 51 indicating that it has received signal R1. Based on the handshake communication between the first isolation subcircuit 51 and the first chip domain 1, the first chip domain 1 may send a signal R3 to the first isolation subcircuit 51 indicating whether or not it is possible to receive a new request execution result, and the first isolation subcircuit 51 may return a signal R4 to the first chip domain 1 indicating that it has received signal R3.
[0094] Similarly, as shown in Figure 3, the isolation module 531 may further include several handshake modules used for handshake communication between the isolation module 531 and the second chip domain 3. Based on the handshake communication between the isolation module 531 and the second chip domain 3, the second chip domain 3 may send a signal R5 to the isolation module 531 indicating whether the second chip domain 3 is able to support a new memory access operation, and in response to receiving the signal R5, the isolation module 531 may return a signal R6 to the second chip domain 3 indicating that it has received the signal R5. Based on the handshake communication between the isolation module 531 and the second chip domain 3, the isolation module 531 may send a signal R7 to the second chip domain 3 indicating whether a new actual access feedback has been written to the second buffer 535, and in response to receiving the signal R7, the second chip domain 3 may return a signal R8 to the isolation module 531 indicating that it has received the signal R7.
[0095] Based on the above, according to the embodiments of this disclosure, the memory space of a low-function-safety level chip domain can be made to function as an extended memory space of a high-function-safety level chip domain, providing high flexibility and expanding the memory space of the high-function-safety level chip domain without additional chip area overhead. This allows the high-function-safety level chip domain to execute programs smoothly, reduce costs, and is particularly suitable for scenarios where the memory size of the high-function-safety level chip domain is limited. Furthermore, if a functional safety anomaly occurs in the low-function-safety level chip domain, it is effectively isolated by the bdiso_dp IP, ensuring the normal and reliable operation of the high-function-safety level chip domain, and the high-function-safety level chip domain can detect the functional safety anomaly in the low-function-safety level chip domain.
[0096] [Example Method] Figure 4 is a flowchart of a chip-based data access method according to some exemplary embodiments of the present disclosure. In the method shown in Figure 4, the chip may include a first chip domain, a second chip domain, and isolation circuits, wherein the functional safety level of the first chip domain is higher than that of the second chip domain. The method shown in Figure 4 may include the following steps 410 to 420.
[0097] In step 410, the first chip domain generates a data access request to the second chip domain.
[0098] In step 420, the isolation circuit performs a memory access operation on the storage space of the second chip domain based on the data access request, and returns the result of the data access request to the first chip domain based on the actual feedback state to the memory access operation by the second chip domain, thereby making the storage space of the second chip domain function as an extended storage space of the first chip domain.
[0099] In some selective examples, the isolation circuit includes a second isolation subcircuit, and the second isolation subcircuit includes a first buffer and a second buffer.
[0100] As shown in Figure 5, the step of performing a memory access operation on the storage space of the second chip domain based on a data access request, and returning the request execution result of the data access request to the first chip domain based on the actual feedback state of the memory access operation by the second chip domain, is as follows: Step 510 caches the target content in a first buffer based on the data access request, Step 520, which performs a memory access operation on one memory region of the memory space based on the target content in the first buffer, Step 530, in response to obtaining actual access feedback for a memory access operation that occurred in the memory area of the second chip domain, caches the actual access feedback in the second buffer. Step 540 determines the actual feedback state for memory access operations that occurred in the storage area by the second chip domain, based on the cache state of the actual access feedback by the second buffer. The process includes step 550, which returns the request execution result of a data access request to the first chip domain based on the actual feedback state corresponding to the memory area.
[0101] In some selective examples, as shown in Figure 6, step 550 is performed. Step 610 determines the first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the memory area, The process includes step 620, which returns the request execution result of a data access request to the first chip domain based on the first functional safety detection result.
[0102] In some selective examples, the number of second isolation subcircuits is at least two, and the at least two second isolation subcircuits correspond to at least two memory areas.
[0103] Step 610 is, A step of determining a first degree of agreement between at least two actual access feedbacks corresponding to at least two actual feedback states, in response to the fact that at least two actual feedback states corresponding to at least two memory regions both indicate that the second chip domain has already returned actual access feedback, The process includes the step of determining a first functional safety detection result for a second chip domain based on a first degree of agreement.
[0104] In some selective examples, as shown in Figure 7, the methods relating to embodiments of the present disclosure are Step 710 records a first number of actual access feedbacks already cached by at least two second buffers in at least two second isolation subcircuits, The further step 720 includes, in response to determining that at least two second buffers satisfy a preset read condition based on a first number of actual access feedbacks already cached by at least two second buffers, performing a data read to at least two second buffers to obtain at least two actual access feedbacks corresponding to at least two actual feedback states.
[0105] Selectively, step 720 may be performed before step 610.
[0106] In some selective examples, as shown in Figure 8, the methods relating to embodiments of the present disclosure are The further step 810 includes initiating a timing operation in response to the isolation circuit receiving a data access request.
[0107] Step 610 is, Step 820 determines a second degree of agreement between the actual feedback state corresponding to the memory area and the expected feedback state, which indicates that the second chip domain has already returned actual access feedback before the timing duration of the timing operation reaches a preset duration. The procedure includes step 830, which determines the first functional safety detection result for the second chip domain based on the second degree of agreement.
[0108] In some selective examples, step 620 is: In response to the first functional safety detection result indicating that no functional safety anomalies exist in the second chip domain, the target actual access feedback is determined based on the actual feedback state corresponding to the memory area, and the target actual access feedback is returned to the first chip domain as the request execution result of the data access request. or The process includes the steps of generating simulated access feedback corresponding to a data access request in response to a first functional safety detection result indicating the presence of a functional safety anomaly in a second chip domain, and returning the simulated access feedback to the first chip domain as the request execution result of the data access request.
[0109] In some selective examples, as shown in Figure 9, the methods relating to embodiments of the present disclosure are Step 910 determines the first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the memory area, The procedure further includes step 920, in response to the first functional safety detection result indicating the presence of a functional safety anomaly in the second chip domain, by performing a first target anomaly handling operation using an isolation circuit.
[0110] In some selective examples, the step of performing a first target anomaly handling operation by an isolation circuit is: The isolation circuit transmits a first interrupt signal to the first chip domain, and in response to the first chip domain receiving the first interrupt signal, controls the second chip domain, the isolation module in the second isolation subcircuit, the first buffer, and the second buffer to reset. and / or, The procedure includes the steps of disconnecting the communication link between the first isolation subcircuit and the first buffer in the isolation circuit, and disconnecting the communication link between the first isolation subcircuit and the second buffer.
[0111] In some selective examples, as shown in Figure 10, the methods relating to embodiments of the present disclosure are Step 1010 records a second number of target content already cached by the first buffer, The process further includes step 1020, which, in response to determining that the first buffer satisfies a pre-configured read condition based on a second number of target contents already cached by the first buffer, performs a data read from the first buffer to obtain the target content of the first buffer.
[0112] Selectively, step 1020 may be performed before step 520.
[0113] In some selective examples, as shown in Figure 11, the method according to the embodiments of the present disclosure further includes step 1110 and step 1120.
[0114] In step 1110, in response to the isolation circuit receiving actual access feedback from the second chip domain, it is determined whether the actual access feedback and the data access request satisfy a pre-defined irrelevance condition. If the actual access feedback and the data access request satisfy the pre-defined irrelevance condition, the process proceeds to step 1120.
[0115] In step 1120, the isolation circuit performs the first target abnormality handling operation.
[0116] In some selective examples, as shown in Figure 12, the methods relating to embodiments of the present disclosure are Step 1210 records a third number of data access requests currently in progress, Step 1220 determines the numerical relationship between a third number of data access requests currently in progress and a preset number, Step 1230 determines the second functional safety detection result of the first chip domain based on numerical relationships, The procedure further includes step 1240, in response to the second functional safety detection result indicating the presence of a functional safety anomaly in the first chip domain, by performing a second target anomaly handling operation using an isolation circuit.
[0117] In some selective examples, the step of performing a second target anomaly handling operation by an isolation circuit is: The procedure includes the steps of sending a second interrupt signal to the first chip domain via an isolation circuit, and the first chip domain performing a reset operation in response to receiving the second interrupt signal.
[0118] In some selective examples, as shown in Figure 13, the first chip domain can initiate a data access request to the isolation circuit and start data transmission between the first chip domain and the isolation circuit if the isolation circuit is idle (i.e., the isolation circuit has no access tasks running or waiting). The isolation circuit can detect whether or not a functional safety anomaly exists in the second chip domain. If a functional safety anomaly exists in the second chip domain, the isolation circuit can generate a simulated access feedback corresponding to the data access request and return the simulated access feedback to the first chip domain as the result of executing the data access request. Furthermore, the isolation circuit can notify the first chip domain of an interrupt, at which point the CPU in the first chip domain can perform anomaly repair on the second chip domain (for example, by controlling the reset of the second chip domain) using a software control method, and can also disconnect the positions where the symbol "×" is drawn individually between the first isolation sub-circuit 51 and the second isolation sub-circuit 53 in Figure 3 (at which point the isolation circuit is considered to be in a fenced state). After the functional safety anomaly in the second chip domain is successfully resolved, the isolation circuit can exit the fenced state, meaning that any location where the symbol "×" is drawn independently between the first isolation subcircuit 51 and the second isolation subcircuit 53 in Figure 3 can be restored to a passage state.
[0119] In the methods of this disclosure, the various selective embodiments, selective forms, and selective examples disclosed in the exemplary circuit portions described above can all be flexibly selected and combined as needed to achieve the corresponding functions and effects; therefore, they are not listed one by one in this disclosure.
[0120] The beneficial technical effects corresponding to the exemplary embodiments of this method can be found by referring to the corresponding beneficial technical effects of the exemplary circuit portion described above; therefore, their explanation is omitted here.
[0121] [Example electronic device] Figure 14 shows a block diagram of an electronic device according to an embodiment of the present disclosure. The electronic device 1400 includes one or more processors 1410 and memory 1420.
[0122] The processor 1410 may be a central processing unit (CPU) or another form of processing unit having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 1400 to perform desired functions.
[0123] The memory 1420 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. The computer-readable storage media may store one or more computer program instructions. The processor 1410 can implement the methods and / or other desired functions of each embodiment of the present disclosure described above by executing one or more computer program instructions.
[0124] As an example, the electronic device 1400 may further include input devices 1430 and output devices 1440 connected to each other via a bus system and / or other forms of connection mechanisms (not shown).
[0125] This input device 1430 may include, for example, a keyboard, a mouse, or the like.
[0126] This output device 1440 can output various types of information to an external source. This output device 1440 may include, for example, a display, speaker, printer, communication network, and remote output devices connected thereto.
[0127] For simplicity, Figure 14 shows only some of the components of the electronic device 1400 relevant to this disclosure, omitting components such as buses and input / output interfaces. Beyond this, the electronic device 1400 may further include any other appropriate components depending on the specific application.
[0128] [Examples of computer program products and computer-readable storage media] Embodiments of this disclosure can provide a computer program product that includes computer program instructions in addition to the methods and apparatus described above. When these computer program instructions are executed by a processor, the processor can be caused to perform the steps in the methods of the various embodiments of this disclosure described in the “Exemplary Methods” section above.
[0129] A computer program product can be created using any combination of one or more programming languages to produce program code for performing the operations of the embodiments of this disclosure, and such programming languages may include object-oriented programming languages such as Java and C++, and may further include general procedural programming languages such as the C language or similar programming languages. The program code may be executed as follows: it may be executed entirely on a user computing device, partially on a user device, as a standalone software package, partially on a user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0130] Furthermore, embodiments of the present disclosure may also provide a computer-readable storage medium in which computer program instructions are stored. When the computer program instructions are executed by a processor, the processor can be made to perform the steps in the methods of the various embodiments of the present disclosure described in the “Exemplary Methods” section of this specification.
[0131] Any combination of one or more types of readable media can be used as a computer-readable storage medium. A readable medium can be a readable signal medium or a readable storage medium. A readable storage medium may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any combination thereof. More specific examples (non-exclusive list) of readable storage media include electrical connections with one or more wires, portable disks, hard drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.
[0132] While the basic principles of this disclosure have been explained above with reference to specific examples, the advantages, merits, and effects mentioned in this disclosure are illustrative and not limiting, and various examples of this disclosure do not necessarily possess these advantages, merits, and effects. Furthermore, the specific details of the above disclosure are for illustrative and easy-to-understand purposes only and are not limiting, and the above details do not necessarily restrict this disclosure to being realized by the above specific details.
[0133] The above description is provided for illustrative and illustrative purposes only. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. While several exemplary embodiments and examples have been described above, those skilled in the art will be able to recognize certain variations, modifications, changes, additions, and subcombinations thereof.
Claims
1. It includes a first chip domain, a second chip domain, and an isolation circuit. The functional safety level of the first chip domain is higher than the functional safety level of the second chip domain. The first chip domain generates a data access request to the second chip domain, The separation circuit is characterized by performing a memory access operation on the storage space of the second chip domain based on the data access request, and returning the request execution result of the data access request to the first chip domain based on the actual feedback state of the second chip domain to the memory access operation, thereby causing the storage space of the second chip domain to function as an extended storage space of the first chip domain.
2. The separation circuit includes a first separation subcircuit and a second separation subcircuit. The aforementioned second isolation subcircuit includes an isolation module, a first buffer, and a second buffer. The separation circuit performs a memory access operation on the storage space of the second chip domain based on the data access request, and returns the request execution result of the data access request to the first chip domain based on the actual feedback state of the second chip domain to the memory access operation. The first isolation subcircuit caches the target content in the first buffer based on the data access request, The isolation module performs a memory access operation on one of the memory areas in the memory space based on the target content of the first buffer, and in response to the second chip domain obtaining actual access feedback of the memory access operation that occurred in the memory area, caches the actual access feedback in the second buffer. The chip according to claim 1, wherein the first isolation subcircuit determines the actual feedback state for the memory access operation that occurred in the storage area by the second chip domain based on the cache state of the actual access feedback by the second buffer, and returns the request execution result of the data access request to the first chip domain based on the actual feedback state corresponding to the storage area.
3. The first isolation subcircuit includes a detection module and a result return module, The first isolation subcircuit returns the request execution result of the data access request to the first chip domain based on the actual feedback state corresponding to the memory area. The detection module determines the first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the memory area, The chip according to claim 2, wherein the result return module returns the request execution result of the data access request to the first chip domain based on the first functional safety detection result.
4. The number of the second isolation subcircuits is at least two, and at least two of the isolation modules in the at least two of the second isolation subcircuits correspond to at least two of the memory areas. The detection module determines the first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the memory area. The chip according to claim 3, wherein the detection module determines a first degree of agreement between at least two of the actual access feedbacks corresponding to at least two of the actual feedback states, in response to at least two of the actual feedback states corresponding to at least two of the memory areas all indicating that the second chip domain has already returned the actual access feedback, and determines a first functional safety detection result for the second chip domain based on the first degree of agreement.
5. The first isolation subcircuit further includes a first readout module and a first counter, The first counter records the first number of actual access feedbacks already cached by at least two of the second buffers in at least two of the second isolation subcircuits, The chip according to claim 4, wherein the first read module performs data reads to at least two of the second buffers in response to determining that at least two of the second buffers satisfy a preset read condition, based on a first number of actual access feedbacks already cached by each of the at least two of the second buffers, before the detection module determines a first degree of agreement between at least two of the actual access feedbacks corresponding to at least two of the actual feedback states, to obtain at least two of the actual access feedbacks corresponding to at least two of the actual feedback states.
6. The detection module further initiates a timing operation in response to the first isolation subcircuit acquiring the data access request. The detection module determines the first functional safety detection result of the second chip domain based on the actual feedback state corresponding to the memory area. The detection module includes determining a second degree of agreement between the actual feedback state and the expected feedback state corresponding to the memory area, and determining a first functional safety detection result for the second chip domain based on the second degree of agreement. The chip according to claim 3, characterized in that the expected feedback state indicates that the second chip domain has already returned the actual access feedback before the timing duration of the timing operation reaches a preset duration.
7. The result return module returns the request execution result of the data access request to the first chip domain based on the first functional safety detection result. The result return module, in response to the first functional safety detection result indicating that no functional safety anomalies exist in the second chip domain, determines the target actual access feedback based on the actual feedback state corresponding to the memory area, and returns the target actual access feedback to the first chip domain as the request execution result of the data access request. or The chip according to claim 3, wherein the result return module includes generating a simulated access feedback corresponding to the data access request in response to the first functional safety detection result indicating the presence of a functional safety anomaly in the second chip domain, and returning the simulated access feedback to the first chip domain as the request execution result of the data access request.
8. The chip according to claim 2, further comprising: the first isolation subcircuit determining a first functional safety detection result for the second chip domain based on the actual feedback state corresponding to the memory area, and executing a first target anomaly processing operation in response to the first functional safety detection result indicating the presence of a functional safety anomaly in the second chip domain.
9. The first isolation subcircuit performs the first target abnormality processing operation. The first isolation subcircuit includes transmitting a first interrupt signal to the first chip domain and controlling the first chip domain to reset the second chip domain, the isolation module, the first buffer, and the second buffer in response to receiving the first interrupt signal. and / or, The first isolation subcircuit performs the first target abnormality processing operation. The chip according to claim 8, characterized in that the first isolation subcircuit includes disconnecting the communication link between the first isolation subcircuit and the first buffer, and disconnecting the communication link between the first isolation subcircuit and the second buffer.
10. The isolation module includes a second read module and a second counter, The chip according to claim 2, wherein the second counter records a second number of the target content already cached by the first buffer, and the second read module performs a data read from the first buffer to obtain the target content of the first buffer, in response to determining that the first buffer satisfies a preset read condition based on the second number of the target content already cached by the first buffer, before the isolation module performs a memory access operation to one of the storage areas of the storage space based on the target content of the first buffer.
11. The chip according to claim 1, further comprising: the isolation circuit acquiring actual access feedback from the second chip domain, and executing a first target abnormality processing operation in response to the actual access feedback and the data access request satisfying a preset irrelevance condition.
12. The separation circuit further records a third number of data access requests in progress, determines a numerical relationship between the third number of data access requests in progress and a preset number, determines a second functional safety detection result for the first chip domain based on the numerical relationship, and performs a second target abnormality processing operation in response to the second functional safety detection result indicating the presence of a functional safety abnormality in the first chip domain.
13. The separation circuit performs the second target abnormality processing operation. The chip according to claim 12, wherein the isolation circuit includes transmitting a second interrupt signal to the first chip domain, and the first chip domain performs a reset operation in response to receiving the second interrupt signal.
14. A chip-based data access method, The chip includes a first chip domain, a second chip domain, and an isolation circuit. The functional safety level of the first chip domain is higher than the functional safety level of the second chip domain. The aforementioned data access method is: The first chip domain generates a data access request to the second chip domain, A chip-based data access method characterized by comprising the steps of: the isolation circuit performing a memory access operation on the storage space of the second chip domain based on the data access request; and, based on the actual feedback state of the second chip domain to the memory access operation, performing an operation to return the request execution result of the data access request to the first chip domain, thereby causing the storage space of the second chip domain to function as an extended storage space of the first chip domain.
15. A computer-readable storage medium on which computer programs are stored, A computer-readable storage medium characterized in that the data access method described in claim 14 is realized when the computer program is executed by a processor.
16. An electronic device comprising a processor and a memory for storing instructions that the processor can execute, The electronic device is characterized in that the processor reads and executes the executable instructions from the memory to realize the data access method described in claim 14.