Cross-domain access methods, devices, equipment, and media

The cross-domain access method addresses abnormalities in high safety level domains by detecting and recovering from bus issues, ensuring normal operation and functional safety in in-vehicle chips.

JP7830584B2Active Publication Date: 2026-03-16BEIJING HORIZON INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-09-24
Publication Date
2026-03-16

AI Technical Summary

Technical Problem

In in-vehicle chips, frequent cross-domain access between high and low safety level domains can lead to abnormalities in the high safety level domain when the low safety level domain bus is abnormal, compromising the normal operation of the high safety level domain.

Method used

A cross-domain access method that includes transmitting an access request, detecting the bus transmission state, generating an interrupt signal based on the bus state, and performing error processing to recover access, ensuring normal operation and functional safety.

Benefits of technology

Guarantees normal completion of access requests without causing abnormalities in the high safety level domain by detecting and recovering from bus abnormalities, thereby enhancing functional safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007830584000001
    Figure 0007830584000001
  • Figure 0007830584000002
    Figure 0007830584000002
  • Figure 0007830584000003
    Figure 0007830584000003
Patent Text Reader

Abstract

To provide a cross-domain access method, a device, an apparatus, and media.SOLUTION: A method includes the steps of: transmitting an access request from a first component having a first security level to a second component having a second security level; detecting a bus transmission status of the second component; generating an interrupt signal based on the bus transmission status, and treating a preset result, when the bus transmission status is a preset status, as an access result corresponding to the access request transmitted by the second component; and executing abnormality processing corresponding to the interrupt signal to recover access of the first component to the second component.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of semiconductor technology, and particularly to a cross-domain access method, apparatus, device, and medium.

Background Art

[0002] In fields such as autonomous driving and driving assistance, functional safety is an element that must be considered in in-vehicle chips. Each function in an in-vehicle chip is usually classified into different functional safety levels according to the risk of vehicle operation. For example, it is the Automotive Safety Integrity Level (abbreviated as ASIL), and according to the functional safety levels of various functions, various functions are attributed to different functional safety domains. Here, the functions of the high safety level domain (also called the high safety level domain system) ensure the normal and safe operation of the vehicle. In actual applications, the functions of the high safety level domain need to access the related data of the functions of the low safety level domain (also called the low safety level domain system), that is, cross-domain access needs to be performed. In the related technology, due to the frequent cross-domain access between the high safety level domain and the low safety level domain, if the bus of the low safety level domain is abnormal (for example, hung up), there is a high possibility that abnormalities will also occur in the bus of the high safety level domain, components for starting cross-domain access, etc., which easily causes abnormalities in the high safety level domain system.

Summary of the Invention

Problems to be Solved by the Invention

[0003] <0000The embodiments of this disclosure provide cross-domain access methods, apparatus, devices, and media to solve technical problems such as the tendency for abnormalities in the low-security domain system to easily cause abnormalities in the high-security domain system. By doing so, it is possible to ensure the normal operation of the high-security domain system and avoid abnormalities in the high-security domain system when the bus of the low-security domain system is abnormal. [Means for solving the problem]

[0004] A cross-domain access method according to a first aspect of the present disclosure includes the steps of: transmitting an access request from a first component having a first security level to a second component having a second security level; detecting the transmission state of the bus of the second component; generating an interrupt signal based on the transmission state of the bus, and if the transmission state of the bus is in a preset state, setting the preset result as the access result corresponding to the access request transmitted by the second component; and performing error processing corresponding to the interrupt signal to recover the first component's access to the second component.

[0005] A cross-domain access device according to a second aspect of the present disclosure includes: a transmission module for transmitting an access request from a first component having a first security level to a second component having a second security level; a first detection module for detecting the transmission state of the bus of the second component; a first response module for generating an interrupt signal based on the abnormality of the bus transmission state and setting a preset result, if the bus transmission state is in a preset state, to be the access result corresponding to the access request transmitted by the second component; and a processing module for performing abnormality processing corresponding to the interrupt signal to recover the first component's access to the second component.

[0006] A computer-readable storage medium according to a third aspect of the present disclosure stores a computer program for performing the cross-domain access method described in any one of the above embodiments of the present disclosure.

[0007] An electronic device according to a fourth aspect of the present disclosure comprises a processor and a memory for storing instructions that the processor can execute, wherein the processor reads the executable instructions from the memory and executes the executable instructions to realize the cross-domain access method described in any one of the above embodiments of the present disclosure.

[0008] A computer program product according to a fifth aspect of the present disclosure executes a cross-domain access method according to any one of the above embodiments of the present disclosure when instructions therein are executed by a processor. [Effects of the Invention]

[0009] According to the cross-domain access method, apparatus, device, and medium of the above embodiment of this disclosure, when performing cross-domain access, an access request from a first component at a first safety level is transmitted to a second component at a second safety level, the transmission state of the bus of the second component can be detected, an interrupt signal is generated based on the bus transmission state, the preset result when the bus transmission state is in a preset state is used as the access result corresponding to the access request, the access request from the first component at the first safety level is guaranteed to be completed normally without causing an abnormality due to an abnormality in the bus transmission state of the second component, and the corresponding abnormality processing can be performed, and the functional safety of the first component can be effectively guaranteed by recovering the cross-domain access of the first component to the second component. [Brief explanation of the drawing]

[0010] [Figure 1] This is one example application scenario of the cross-domain access method described herein. [Figure 2] This is a schematic flowchart of a cross-domain access method according to an exemplary embodiment of the present disclosure. [Figure 3] This is a schematic flowchart of a cross-domain access method relating to another exemplary embodiment of the present disclosure. [Figure 4] This is a schematic flowchart of a cross-domain access method relating to yet another exemplary embodiment of the present disclosure. [Figure 5] This is a schematic flowchart of a cross-domain access method relating to yet another exemplary embodiment of the present disclosure. [Figure 6] This is a schematic flowchart of a cross-domain access method relating to yet another exemplary embodiment of the present disclosure. [Figure 7] This is a block diagram of a flowchart of cross-domain access according to an exemplary embodiment of the present disclosure. [Figure 8] This is a schematic diagram of the structure of a cross-domain access device according to an exemplary embodiment of the present disclosure. [Figure 9] This is a schematic diagram of the structure of a cross-domain access device according to another exemplary embodiment of the present disclosure. [Figure 10] This is a schematic diagram of the structure of a cross-domain access device according to yet another exemplary embodiment of the present disclosure. [Figure 11] This is a schematic diagram of the structure of a cross-domain access device according to yet another exemplary embodiment of the present disclosure. [Figure 12] This is a schematic diagram of the structure of a cross-domain access device according to yet another exemplary embodiment of the present disclosure. [Figure 13] This is a schematic diagram of the structure of the first subcomponent according to an exemplary embodiment of the present disclosure. [Figure 14] This is a schematic diagram of the structure of a first subcomponent relating to another exemplary embodiment of the present disclosure. [Figure 15] This is a structural diagram of an electronic device according to an embodiment of the present disclosure. [Modes for carrying out the invention]

[0011] Hereinafter, in order to interpret the present disclosure, exemplary embodiments of the present disclosure will be described in detail while referring to the drawings. Further, the described embodiments are only some embodiments of the present disclosure, not all embodiments, and the present disclosure is not limited to the exemplary embodiments.

[0012] It should be noted that the relative settings of the components and steps described in these embodiments, the numerical expressions and numerical values, do not limit the scope of the present disclosure unless specifically described.

[0013] [Summary of the Present Disclosure] In the process of realizing the present disclosure, the inventor has discovered that in the fields of autonomous driving, driving assistance, etc., functional safety is an element that must be considered in in-vehicle chips. Each function in an in-vehicle chip is usually classified into different functional safety levels according to the risks of vehicle operation, for example, the Automotive Safety Integrity Level (abbreviated as ASIL), and according to the functional safety levels of various functions, various functions are assigned to different functional safety domains. Here, the functions of the high safety level domain (also called the system of the high safety level domain) ensure the normal and safe operation of the vehicle. In actual applications, the functions of the high safety level domain need to access the related data of the functions of the low safety level domain (also called the system of the low safety level domain), that is, cross-domain access needs to be performed. In the related technology, due to the frequent cross-domain access between the high safety level domain and the low safety level domain, if the bus of the low safety level domain is abnormal (for example, hung up), there is a high possibility that the bus of the high safety level domain, components for starting cross-domain access, etc. will also have abnormalities, which easily causes abnormalities in the system of the high safety level domain.

[0014] [Exemplary Summary] FIG. 1 is an exemplary application scenario of a cross-domain access method according to the present disclosure.

[0015] As shown in Figure 1, in automotive chips for fields such as autonomous driving and driver assistance, components in the high-safety domain (i.e., high-safety domain components) typically need cross-domain access to components in the low-safety domain (i.e., low-safety domain components). High-safety domain components may include, for example, processors, DMA (Direct Memory Access) controllers, ETH (Ethernet), XSPI (eXpanded Serial Peripheral Interface) and other related components that have cross-domain access capabilities in the high-safety domain. Low-safety domain components may include processors, DMA controllers and other related components in the low-safety domain. By utilizing the cross-domain access method of this disclosure, an isolation component is provided between the high-safety domain component and the low-safety domain component, and this isolation component can be implemented using at least one of software or hardware. The isolation component is connected to the high-safety domain module and the low-safety domain module, or the isolation component may consist of two parts, one of which is provided in the high-safety domain component and the other in the low-safety domain component. The isolated component transmits an access request from a high-security-level domain component (i.e., the first component at the first security level) to a second component at the second security level (i.e., the low-security-level domain component), detects the transmission state of the second component's bus, generates an interrupt signal based on the bus transmission state, and if the bus transmission state is in a preset state, sets the preset result as the access result corresponding to the access request transmitted by the second component. The first component then performs error processing corresponding to the interrupt signal to recover the first component's access to the second component.When the transmission of the bus of the second component is in a preset state (for example, abnormal), in order to ensure that the access request of the first component is normally responded as the access result corresponding to the access request of the preset result, the current cross-domain access can be normally completed, and no abnormality occurs due to the inability to obtain the response of the second component. Thereby, the normal operation of the first component can be guaranteed, which helps the first component to perform subsequent corresponding abnormality processing, timely recover the cross-domain access of the first component to the second component, thereby effectively guarantee the functional safety of the first component, and further improve the safety of vehicle driving.

[0016] The cross-domain access method of the present disclosure is not limited to the above fields or scenes of autonomous driving and driving assistance, and can also be applied to other fields or scenes of cross-domain access that need to meet any other different functional safety requirements.

[0017] [Exemplary Method] FIG. 2 is a schematic diagram of a flowchart of a cross-domain access method according to an exemplary embodiment of the present disclosure. This embodiment can be applied to electronic devices, specifically, for example, an in-vehicle computing platform. As shown in FIG. 2, it includes the following steps 201 to step 204.

[0018] In step 201, an access request of a first component at a first safety level is transmitted to a second component at a second safety level.

[0019] In several selectable embodiments, the first safety level is higher than the second safety level. For example, the first safety level may be ASIL D and the second safety level may be one of ASIL QM (Quality Management), ASIL A, ASIL B, or ASIL C; or the first safety level may be ASIL C and the second safety level may be ASIL QM, ASIL A, or ASIL B; or the first safety level may be ASIL B and the second safety level may be ASIL QM, ASIL A, etc.

[0020] In several selectable embodiments, the first component may include components in a domain corresponding to a first safety level (also called the first safety level domain). The first component may include, for example, one or more of the processor, DMA controller, and other related components (e.g., registers, memory, etc.) in the first safety level domain. Similarly, the second component may include components in a domain corresponding to a second safety level (i.e., the second safety level domain).

[0021] In several selectable embodiments, an access request to the first component can be initiated by a component in the first component that has cross-domain access capabilities, such as a processor, DMA controller, ETH, or XSPI.

[0022] In several selectable embodiments, an isolation component is provided between the first and second components to transmit access requests from the first component to the second component. This isolation component can be implemented using software, hardware, or a combination of software and hardware. For example, to ensure real-time performance, this isolation component can be implemented using hardware.

[0023] In several selectable embodiments, the isolated component may include a first part (also called a first subcomponent) located on the first component side and a second part (also called a second subcomponent) located on the second component side. Communication between the first part and the second part is conducted by a predetermined communication protocol. The communication protocol can be any implementable bus protocol, such as the AXI (Advanced eXtensible Interface) protocol or the APB (Advanced Peripheral Bus) protocol. The first part may be included in the first component as a part of the first component, or it may be a part connected to the first component independently of the first component, or it may include a hardware part connected to the first component independently of the first component and a software part executed by the processor in the first component. The second part may be included in the second component as a part of the second component, or it may be a part connected to the second component independently of the second component. The relationship between the first part and the first component, and the relationship between the second part and the second component, can be set according to actual requirements and are not limited to the embodiments of this disclosure. Cross-domain access is achieved by the first part sending an access request to the first component to the second part, and the second part sending this access request to a component in the second component, for example, by sending this access request to a processor, memory, etc., in the second component.

[0024] In step 202, the transmission status of the bus of the second component is detected.

[0025] In several selectable embodiments, the bus transmission state can include two states: normal and abnormal. The bus transmission state of the second component is determined to be abnormal if, for some reason, the second component is unable to successfully transmit the access results corresponding to the access request of the first component. For example, the bus transmission state of the second component is determined to be abnormal if the bus of the second component is unable to successfully transmit data due to a hang-up of the second component's bus, the second component not starting or failing to start, or various other reasons.

[0026] In several selectable embodiments, the transmission status of the second component's bus can be detected by detecting a timeout situation in which the second component returns a transmission completion confirmation signal. For example, timing is started from the time the access request is transmitted to the second component, and it is detected whether or not a transmission completion confirmation signal returned from the second component has been received. If the confirmation signal is received within a preset time, it indicates that the transmission status of the second component's bus is normal. If the confirmation signal is not received within a preset time, it indicates that the confirmation signal from the second component has timed out, and it is determined that the transmission status of the second component's bus is abnormal.

[0027] In several selectable embodiments, the first part of the isolated component can detect a timeout situation in which the second part returns a confirmation signal indicating that transmission is complete. The second component communicates with the second part, which is responsible for transmitting data transmitted by the bus of the second component to the first part and for transmitting a confirmation signal to the first part after transmission is complete. If the transmission status of the bus of the second component is abnormal, the second part cannot transmit a confirmation signal to the first part, and the transmission status of the bus of the second component can be determined by the first part detecting the timeout situation of the confirmation signal.

[0028] In step 203, an interrupt signal is generated based on the bus transmission state, and the preset result when the bus transmission state is a preset state is used as the access result corresponding to the access request transmitted by the second component.

[0029] In several selectable embodiments, an interrupt signal is generated when it is detected that the transmission state of the bus of the second component is in a preset state, and the preset result when the bus transmission state is in a preset state can be set to the access result corresponding to the access request transmitted by the second component. The preset state can be determined by a preset detection rule. The preset detection rule may include, for example, whether or not a protocol signal from the second component was received within a preset time, and the protocol signal may be, for example, an acknowledgment signal that a transmission has been completed.

[0030] In several selectable embodiments, the bus transmission state is set to an abnormal state, meaning that the second component's bus transmission state is abnormal, and the second component cannot transmit the access result corresponding to the access request due to the bus abnormality. To avoid an abnormality occurring in the first component, an interrupt signal is generated, and the preset state of abnormal bus transmission state is set to the access result corresponding to the access request transmitted by the second component, meaning that in order for the access request to be answered and the current access to be completed successfully, the preset state is sent back to the component that initiated the access request in the first component as the access result transmitted by the second component, for example, to the processor that initiated the access request in the first component, so that the processor receives the access result corresponding to the access request and completes the current cross-domain access.

[0031] In several selectable embodiments, a single access request can correspond to one or more access results, specifically determined by the data address and transmission protocol accessed by the access request. For example, if the access request accesses many data addresses, the second component may need to transmit multiple times. Each time a transmission is completed, the second component sends a transmission completion confirmation signal, and the first component obtains the access result of one transmission. After the second component has completed multiple transmissions, the first component can obtain the final access result corresponding to the access request. In this process, if any of the transmission completion confirmation signals time out, the transmission state of the second component's bus can be determined to be a preset state (i.e., abnormal). The preset result is returned to the component initiating the access request in the first component as the access result for this transmission. If the next transmission completion confirmation signal is detected and times out, the preset result becomes the access result for this next transmission, and so on, until the cross-domain access corresponding to the access request is completed until the access result corresponding to each of the multiple transmissions is obtained.

[0032] In several selectable embodiments, an interrupt signal is used to cause a processor in a first component to respond to the interrupt and perform abnormal processing corresponding to the interrupt signal.

[0033] In several selectable embodiments, an interrupt signal is generated by the isolation component described above, which transmits the interrupt signal to a fault handling module (or error handling module), which notifies the processor in the first module to perform abnormal processing corresponding to the interrupt signal. The fault handling module may be an independent module outside the first and second safety level domains, or it may be a module within the first safety level domain, and is not specifically limited.

[0034] In step 204, error handling corresponding to the interrupt signal is performed to recover the first component's access to the second component.

[0035] In some optional embodiments, the error handling may include, for example, waiting for the current cross-domain access corresponding to the access request above to complete, prohibiting new cross-domain access, restarting the second component or the second security level domain to recover the transmission state of the second component's bus so that the second component can transmit normally, thereby recovering the first component's cross-domain access to the second component.

[0036] In several selectable embodiments, error handling can be implemented by a processor in the first component.

[0037] The cross-domain access method according to this embodiment, when performing cross-domain access, transmits an access request of the first safety level to the second component of the second safety level, then detects the transmission state of the second component's bus. When it is detected that the transmission state of the second component's bus is in a preset state, an interrupt signal is generated. The preset result when the bus transmission state is in a preset state is set as the access result corresponding to the access request. This ensures that the access request of the first component of the first safety level is completed normally without any abnormalities occurring due to the abnormal transmission state of the second component's bus, and by performing the corresponding abnormality processing, the cross-domain access of the first component to the second component can be recovered, thereby effectively guaranteeing the functional safety of the first component.

[0038] Figure 3 is a schematic flowchart of a cross-domain access method relating to another exemplary embodiment of the present disclosure.

[0039] In some selectable embodiments, step 201, which transmits a request for access to a first component at a first security level to a second component at a second security level, includes the following steps 2011 to 2012.

[0040] In step 2011, the access isolation status of the first component accessing the second component is checked.

[0041] In several selectable embodiments, the access isolation state can be determined by a recorded access isolation state value, for example, representing two states with two different state values, and the specific access isolation state is determined by the currently recorded state value. Exemplaryly, a state value of 1 indicates that the access isolation state is in the first state, and a state value of 0 indicates that the access isolation state is in the second state. The specific state value can be set according to the actual requirements and is not limited to the above representation of 1 and 0. The first state is an isolation state, indicating that new cross-domain access is prohibited. The second state is not an isolation state, indicating that cross-domain access is permitted.

[0042] In several selectable embodiments, the access isolation state can be stored in an access isolation state register. Each time an interrupt signal is generated, the access isolation state is entered, and the access isolation state register enters a first state. Each time a cross-domain access is recovered, the isolation state is released, and the access isolation state register enters a second state.

[0043] In several selectable embodiments, the access isolation state can be maintained by a first component, specifically by the processor of the first component. The processor updates the access isolation state to a first state in response to an interrupt signal, prohibiting new cross-domain access. After the processor restarts the second component and the bus transmission state of the second component becomes normal through recovery, the access isolation state is updated to a second state. When a check is performed before a new cross-domain access, the check allows the new cross-domain access to occur.

[0044] In several selectable embodiments, step 2011 can be performed by a first component. Specifically, it can be performed by a target component (e.g., a processor or DMA controller) that is attempting to initiate cross-domain access in the first component.

[0045] In step 2012, in response to the access isolation state being the second state, the access request is transmitted to the second component.

[0046] In some selectable embodiments, an access isolation state being in the second state indicates that the system is not currently isolated and that cross-domain access to the second component is possible. Only in this case can access requests be transmitted to the second component to ensure cross-domain access is achieved.

[0047] In several selectable embodiments, in response to the access isolation state being a second state, the target component that needs to initiate cross-domain access in the first component transmits an access request to the second component, or the target component transmits an access request to the isolation component, and the isolation component transmits an access request to the second component.

[0048] In some of the selectable embodiments, the method of the embodiment of the present disclosure further includes the following step 301.

[0049] In step 301, in response to the access isolation state being the first state, access to the second component is stopped.

[0050] In several selectable embodiments, the access isolation state is a first state, representing that the system is currently isolated and prohibits cross-domain access, thus halting access to the second component.

[0051] In several selectable embodiments, a target component attempting to initiate cross-domain access to the first component stops transmitting an access request to the second component, i.e., does not perform cross-domain access to the second component, in response to the access isolation state being in the first state.

[0052] This embodiment effectively avoids triggering new cross-domain access in the event of a bus failure on the second component by checking the access isolation status before initiating cross-domain access. This achieves access isolation between the first and second components, ensuring that all cross-domain access initiated after a bus failure on the second component is prohibited, thereby helping to ensure the normal operation of the first component and preventing the first component from becoming abnormal due to the influence of the second component.

[0053] Figure 4 is a schematic flowchart of a cross-domain access method relating to yet another exemplary embodiment of the present disclosure.

[0054] In some selectable embodiments, step 2012, in response to the access isolation state being a second state, transmits an access request to a second component, which includes the following steps 20121 to 20122.

[0055] In step 20121, in response to the access isolation state being the second state, the first total count is recorded, which is the sum of the number of times the access isolation state was in the first state and the number of times the de-isolated state was in the first state.

[0056] In several selectable embodiments, an access isolation state being in state 1 means that the system is isolated and new cross-domain access is prohibited. A return to state 1 after the isolation state is lifted means that the isolation is removed and new cross-domain access is permitted.

[0057] In several selectable embodiments, the access isolation state is released by switching the access isolation state from a first state to a second state. The access isolation state is restored by switching the access isolation state from a second state to a first state. The first total count is the sum of the number of times the access isolation state is switched from a second state to a first state and the number of times the access isolation state is switched from a first state to a second state.

[0058] In several selectable embodiments, isolation is achieved by switching the de-isolated state from a second state to a first state. Isolation is achieved by switching the de-isolated state from a first state to a second state. The first total number is the sum of the number of times the de-isolated state is switched from a first state to a second state and the number of times the de-isolated state is switched from a second state to a first state.

[0059] In several selectable embodiments, when power is supplied to the first and second safety level domains and operation begins, the total count is initialized, for example, to a preset value (e.g., 0). In subsequent operations, each time the access isolation state becomes the first state, 1 is added to the total count, and each time the isolation release state becomes the first state, 1 is added to that count as well, thereby allowing the total count to be maintained in real time. Each time cross-domain access occurs, in response to the access isolation state being the second state, the total count at that time (referred to as the first total count) is recorded.

[0060] In several selectable embodiments, the first total count can be obtained by a counter and a register. For example, a counter is connected to a component that generates an interrupt signal, and each time an interrupt signal is generated, the interrupt signal triggers the counter and counts once. The counter is connected to a register representing the de-isolation state (also called the de-isolation state register), and each time the de-isolation state register is updated to a first state, the counter is triggered and counts once. Similarly, the counter can record the total count in real time, and the total count of the counter can be stored in a count register. The register can be read to record the first total count before transmitting an access request to a second component.

[0061] In step 20122, the access request is transmitted to the second component.

[0062] The transmission of the access request in step 20122 can be specifically described in the previously mentioned examples, so we will omit the explanation here.

[0063] After transmitting the access request in step 20122 to the second component, the process further includes steps 401 to 404.

[0064] In step 401, it is detected whether the access corresponding to the access request has been completed.

[0065] In several selectable embodiments, the detection of access completion can be achieved by the number of access results that the access request needs to transmit by the second component. For example, if the access request is transmitted four times by the second component, i.e., the first component obtains four access results for the four transmissions and constitutes the target access result corresponding to the access request, then it can be determined whether or not the access has been completed based on the number of access results obtained so far.

[0066] In several selectable embodiments, even if the bus transmission of the second component is abnormal, the first component can obtain the access result of the preset result, and therefore the access result(s) obtained when the access of the first component is completed may include at least one of the preset result and the access result actually transmitted by the second component.

[0067] In step 402, in response to the termination of access, the access result corresponding to the access request is obtained, and a second total count is recorded, which is the sum of the number of times the access isolation state reached the first state and the number of times the isolation release state reached the first state.

[0068] In several selectable embodiments, upon completion of access, the first component may obtain the one or more transmitted access results corresponding to the access request, at which point it records again the sum of the number of times the access isolation state was in state 1 and the number of times the isolation release state was in state 1 (i.e., the second total count). If no abnormalities occur in the transmission state of the second component's bus during this access process, the second total count will match (i.e., be identical to) the first total count mentioned above. If an abnormality occurs in the transmission state of the second component's bus, the total count will change as the number of times the access isolation state was in state 1 increases, and the second total count will be different from the first total count.

[0069] In some selectable embodiments, if the first total count is the sum of the number of times the access isolation state switched from state 2 to state 1 and the number of times the access isolation state switched from state 1 to state 2, then the second total count is also the sum of the number of times the access isolation state switched from state 2 to state 1 and the number of times the access isolation state switched from state 1 to state 2.

[0070] In some selectable embodiments, if the first total count is the sum of the number of times the de-isolated state switched from the first state to the second state and the number of times the de-isolated state switched from the second state to the first state, then the second total count is also the sum of the number of times the de-isolated state switched from the first state to the second state and the number of times the de-isolated state switched from the second state to the first state.

[0071] In step 403, the availability status of the access results corresponding to the access request is determined based on the first total count and the second total count.

[0072] Here, the available state can include two states: available and unavailable.

[0073] In several selectable embodiments, if the total number of first and second access attempts are the same, it can be determined that no abnormalities occurred on the bus of the second component during the current access process. In this case, the access results obtained by the first component are all actual access results transmitted by the second component. Conversely, if the numbers are different, it can be determined that the access results include preset results and are not used. This allows for the determination of the available state of access results corresponding to access requests.

[0074] In step 404, processing is performed on the access result to determine if it is available.

[0075] Here, the step of processing the access result in accordance with its available state is as follows: if the access result is available, the access result is used in subsequent business logic processing; if the access result is unavailable, the access result is not used in subsequent business logic processing. The subsequent business logic processing can be set according to the specific function of the first security level domain, and is not specifically limited to, for example, business logic processing for control functions or business logic processing for policy determination functions.

[0076] Furthermore, steps 401 and 202 described above have no dependency on their execution order and can be executed simultaneously or sequentially; there are no restrictions on the execution order.

[0077] This embodiment helps to accurately determine whether an anomaly occurred in the bus of the second component during the cross-domain access process, thereby effectively determining the availability of the access results. By proactively sensing whether the cross-domain access was successful, accurate and reliable access results can be provided to subsequent business logic processing, thereby guaranteeing the reliability of the subsequent business logic.

[0078] In some selectable embodiments, the step of determining the available state of access results corresponding to access requests based on the first total count and the second total count of step 403 includes the following steps:

[0079] In other words, this is a step in which, in response to the second total count being the same as the first total count, the available state is determined to be available, and in response to the second total count being different from the first total count, the available state is determined to be unavailable.

[0080] Here, the fact that the second total count is the same as the first total count indicates that no abnormalities occurred in the bus of the second component during this cross-domain access process. Therefore, since all access results obtained by the first component are actual access results transmitted by the second component, the available state of the access results is confirmed to be available. Conversely, if the access results were not available, the available state of the access results would be confirmed to be unavailable.

[0081] Figure 5 is a schematic flowchart of a cross-domain access method relating to yet another exemplary embodiment of the present disclosure.

[0082] In some selectable embodiments, step 202 for detecting the transmission state of the bus of the second component includes the following steps 2021 to 2022.

[0083] In step 2021, the second component detects a timeout condition in which it returns a signal confirming the completion of transmission.

[0084] Here, the second component responds to the access request by returning transmission data, and the number of transmissions by the second component may be one or more depending on the differences in the access content of the access request. Each time the transmission of data is completed, it returns a confirmation signal that the transmission is complete. If there is a problem with the bus of the second component, it will not be able to return the confirmation signal, and the apparatus of the embodiment of this disclosure can detect the transmission status of the bus of the second component by detecting a timeout condition in which the second component returns the confirmation signal that the transmission is complete. The confirmation signal may be any implementable representation and can be set by the transmission protocol, and is not limited to the embodiment of this disclosure.

[0085] In step 2022, in response to the timeout condition being a timeout, it is determined that the transmission state of the bus of the second component is abnormal.

[0086] Here, a timeout state for the acknowledgment signal indicates that the second component is unable to properly return the acknowledgment signal, thus confirming that the transmission state of the second component's bus is abnormal (i.e., in a preset state).

[0087] This embodiment enables effective detection of the transmission status of the second component's bus by detecting a timeout state in which the second component returns a confirmation signal of transmission completion. This helps to proactively and promptly detect abnormalities in the second component's bus, thereby enabling timely handling of the corresponding abnormality and facilitating rapid recovery of cross-domain access.

[0088] In some of the selectable embodiments, the embodiments of the present disclosure further include the following step 501.

[0089] In step 501, in response to receiving a transmission completion confirmation signal from the second component within the preset time, the data transmitted from the second component is used as the access result corresponding to the access request.

[0090] Here, when the first component receives a confirmation signal from the second component indicating that the transmission has been successfully completed within the preset time, the second component can use the data it transmitted as the access result for the single transmission corresponding to the access request. This access result can then be sent back to the target component that initiated the access request in the first component. If the access is not completed, the first component continues to receive data and waits for a confirmation signal indicating that the next transmission has been completed. If the access result for the next transmission is obtained, or if the confirmation signal times out, the preset result is used as the access result for the current transmission. The process continues similarly until all access results corresponding to the access requests have been obtained.

[0091] In this embodiment, if the second component can return an acknowledgment signal within a preset time, the data transmitted from the second component can be returned to the target component in the first component as the access result of this transmission, thereby obtaining the actual access result. If all access results are transmitted by the second component, they are used in the processing of subsequent business logic, ensuring the realization of the corresponding functional safety function of the vehicle.

[0092] Figure 6 is a schematic flowchart of a cross-domain access method relating to yet another exemplary embodiment of the present disclosure.

[0093] In some selectable embodiments, step 204, which performs error handling in response to an interrupt signal, includes the following steps 2041 to 2043.

[0094] In step 2041, access isolation is performed between the first and second components based on the interrupt signal.

[0095] In several selectable embodiments, access isolation is implemented between the first and second components, i.e., new cross-domain access from the first component to the second component is prohibited.

[0096] In several selectable embodiments, access isolation between the first and second components can be achieved by setting the access isolation state to a first state. Before performing subsequent cross-domain access, the access isolation state can be checked first. If the access isolation state is the first state, the new cross-domain access can be stopped. If the access isolation state is the second state, the new cross-domain access can be performed and the access request can be transmitted to the second component, or the isolation component can transmit the access request to the second component. For specific examples, please refer to the embodiments described above.

[0097] In several selectable embodiments, the access isolation state can be stored using an access isolation state register. For example, setting the access isolation state register to 1 indicates that the access isolation state has entered the first state, and setting the access isolation state register to 0 indicates that the access isolation state has entered the second state. The specific state value of the access isolation state register can be set according to the actual requirements and is not limited to the aforementioned 1 and 0. For example, the first state may be represented by 11 and the second state by 00, and is not specifically limited.

[0098] In step 2042, the second component is restarted to restore the transmission state of the second component's bus to a normal state.

[0099] In several selectable embodiments, the processor in the first component can be controlled to restart the second component, which in turn restores the bus transmission state of the second component to a normal state.

[0100] In some selectable embodiments, the second component can be restarted by further restarting the second safety level domain.

[0101] In several selectable embodiments, after restarting the second component, the second component returns to its default state through a reset, and initializing the second component restores it to a normal operating state, thereby recovering the second component's bus to a normal state.

[0102] In step 2043, the access isolation between the first component and the second component is removed, and access from the first component to the second component is recovered.

[0103] Here, after the transmission state of the bus of the second component is recovered to a normal state, the access isolation between the first and second components can be released, and cross-domain access of the first component to the second component can be recovered.

[0104] In several selectable embodiments, the de-isolation state can be maintained in real time, and the de-isolation state can include a first state and a second state, where the de-isolation state being the first state indicates that the isolation has been lifted and new cross-domain access is possible, and the de-isolation state being the second state indicates that the isolation has not been lifted and new cross-domain access is prohibited.

[0105] In several selectable embodiments, the deisolated state can be maintained by a deisolated state register. For example, setting the deisolated state register to 1 indicates that the deisolated state is in a first state (i.e., the isolation has been released), and setting the deisolated state register to 0 indicates that the deisolated state is in a second state (i.e., the isolation has not been released or the isolation has been restored). The specific representations of the first and second states of the deisolated state are not limited to 1 and 0 as described above, but can be set according to the specific requirements and are not limited to the embodiments of this disclosure.

[0106] In some optional embodiments, the process may further include: checking whether the cross-domain access corresponding to the current access request has been completed before releasing the access isolation between the first and second components; releasing the access isolation between the first and second components in response to the completion of access; and waiting for access to be completed before releasing the access isolation between the first and second components in response to incomplete access. That is, releasing the access isolation between the first and second components requires ensuring that the bus path for cross-domain access at that time is idle (completing ongoing cross-domain access and prohibiting new cross-domain access). The presence of incomplete transmissions on the bus may cause abnormalities in the transmission protocol, which in turn may cause abnormalities in the first component.

[0107] This embodiment effectively prevents all new cross-domain access in abnormal conditions on the second component's bus by performing access isolation based on interrupt signals. Furthermore, by restarting the second component and recovering the transmission state of the second component's bus to a normal state, it helps to recover cross-domain access from the first component to the second component in a timely manner, thereby ensuring the normal operation of the vehicle's functions.

[0108] In some selectable embodiments, step 2041 of providing access isolation to the first and second components based on an interrupt signal includes the following steps:

[0109] In other words, the step is to set the access isolation state, in which the first component accesses the second component based on an interrupt signal, to the first state.

[0110] In some of the selectable embodiments, the access isolation state can be described in the previously mentioned embodiments and will not be explained here.

[0111] Step 2043, which removes the access isolation between the first component and the second component, includes the following steps:

[0112] In other words, the step is to set the de-isolated state to the first state, and / or the access isolation state to the second state.

[0113] In several selectable embodiments, access isolation can be achieved by at least one of the following: setting the isolation state to a first state and setting the access isolation state to a second state.

[0114] In some selectable embodiments, the first total number and the second total number described above can be obtained by setting the access isolation state to the first state and resulting in one isolation, and by setting the isolation release state to the first state and resulting in one isolation release.

[0115] This embodiment helps to enable timely cross-domain access from the first component to the second component by maintaining the de-isolation state in real time, thereby enabling the first component to recover to a normal, functionally safe state in a timely manner.

[0116] In several selectable embodiments, Figure 7 is a block diagram of a flowchart of cross-domain access according to an exemplary embodiment of the present disclosure. As shown in Figure 7, after the first component initiates cross-domain access, it detects a bus timeout (i.e., detects whether the acknowledgment signal that the second component returns to confirm transmission completion is a timeout). If no (N), it performs the access successfully, i.e., the second component returns the transmitted access result successfully. If yes (Y), it triggers an interrupt, sets an interrupt signal indicating a timeout has occurred, and stops the cross-domain access (i.e., prohibits further cross-domain access) with the preset result as the access result. After the interrupt signal is set, the first component transitions to the interrupt handling flow based on the interrupt signal, waits for the current cross-domain access to complete, prohibits new cross-domain access, restarts the second safety level domain to recover the transmission state of the second component's bus to a normal state, checks the current cross-domain access isolation state, i.e., checks the access isolation state, and if it is in the first state, releases the access isolation, recovers the cross-domain access path, and after releasing the access isolation, the access isolation state becomes the second state so that the first component can perform a new cross-domain access.

[0117] Each of the embodiments described herein may be implemented individually or in any combination in a non-contradictory manner, and may be specifically configured according to actual requirements, and is not limited herein.

[0118] Any cross-domain access method relating to the embodiments of this disclosure can be executed by any device having appropriate data processing capabilities, including but not limited to terminal devices and servers. Alternatively, any cross-domain access method relating to the embodiments of this disclosure can be executed by a processor, for example, by calling a corresponding instruction stored in memory, thereby executing any cross-domain access method referred to in the embodiments of this disclosure. Further explanation is omitted below.

[0119] [Example device] Figure 8 is a schematic diagram of the structure of a cross-domain access device according to an exemplary embodiment of the present disclosure. The device of this embodiment is used to implement an embodiment of the corresponding cross-domain access method of the present disclosure, and the device shown in Figure 8 comprises a transmission module 61, a first detection module 62, a first response module 63, and a processing module 64.

[0120] The transmission module 61 transmits an access request from the first component with a first security level to the second component with a second security level.

[0121] The first detection module 62 detects the transmission status of the bus of the second component.

[0122] The first response module 63 generates an interrupt signal based on the bus transmission state, and if the bus transmission state is in a preset state, the preset result is used as the access result corresponding to the access request transmitted by the second component.

[0123] The processing module 64 performs error handling in response to the interrupt signal to recover the first component's access to the second component.

[0124] Figure 9 is a schematic diagram of the structure of a cross-domain access device according to another exemplary embodiment of the present disclosure.

[0125] In some selectable embodiments, as shown in Figure 9, the transmission module 61 comprises a first inspection unit 611, a transmission unit 612, and a processing unit 613.

[0126] The first inspection unit 611 checks for access isolation status, which indicates that the first component is accessing the second component.

[0127] The transmission unit 612 transmits the access request to the second component in response to the access isolation state being the second state.

[0128] The processing unit 613 stops accessing the second component in response to the access isolation state being the first state.

[0129] In some selectable embodiments, as shown in Figure 9, the apparatus of the embodiment of the present disclosure further comprises a first recording module 65, a second detection module 66, a second recording module 67, a confirmation module 68, and an access result processing module 69.

[0130] The first recording module 65 records the first total count in response to the access isolation state being in the second state. The first total count is the sum of the number of times the access isolation state was in the first state and the number of times the de-isolated state was in the first state.

[0131] The second detection module 66 transmits the access request to the second component and then detects whether the access corresponding to the access request has been completed.

[0132] The second recording module 67, in response to the completion of the access, obtains the access result corresponding to the access request and records the second total count. The second total count is the sum of the number of times the access isolation state returned to the first state and the number of times the isolation release state returned to the first state.

[0133] The confirmation module 68 determines the available state of the access results corresponding to the access request based on the first total count and the second total count.

[0134] The access result processing module 69 performs processing on the access result that corresponds to the available state.

[0135] In several selectable embodiments, the determination module 68 specifically determines the available state as available in response to the second total count being the same as the first total count, and determines the available state as unavailable in response to the second total count being different from the first total count.

[0136] Figure 10 is a schematic diagram of the structure of a cross-domain access device according to yet another exemplary embodiment of the present disclosure.

[0137] In some selectable embodiments, as shown in Figure 10, the first detection module 62 includes a detection unit 621 for detecting a timeout condition in which the second component returns a signal confirming the completion of transmission, and a third confirmation unit 622 for determining that the transmission state of the second component's bus is abnormal in response to the timeout condition being a timeout.

[0138] In some selectable embodiments, as shown in Figure 10, the first detection module 62 further comprises a fourth confirmation unit 623 for determining the data transmitted by the second component as an access result corresponding to an access request, in response to receiving a transmission completion confirmation signal returned from the second component within a preset time.

[0139] Figure 11 is a schematic diagram of the structure of a cross-domain access device according to yet another exemplary embodiment of the present disclosure.

[0140] In some selectable embodiments, as shown in Figure 11, the processing module 64 comprises an isolation unit 641, a control unit 642, and an isolation release unit 643.

[0141] The isolation unit 641 performs access isolation between the first and second components based on the interrupt signal.

[0142] The control unit 642 restarts the second component to restore the transmission state of the second component's bus to a normal state.

[0143] The deisolation unit 643 releases the access isolation between the first component and the second component, thereby restoring the first component's access to the second component.

[0144] In several selectable embodiments, the isolation unit 641 specifically brings the access isolation state to a first state based on an interrupt signal, where the first component accesses the second component.

[0145] The de-isolation unit 643 specifically sets the de-isolation state to a first state and / or the access isolation state to a second state.

[0146] In several selectable embodiments, Figure 12 is a schematic diagram of the structure of a cross-domain access device according to yet another exemplary embodiment of the present disclosure. As shown in Figure 12, the device of the embodiment of the present disclosure may include a hardware isolation component and a software portion that runs on a first component in a first security level domain. The isolation component comprises a first subcomponent located in a first security level domain and a second subcomponent located in a second security level domain, with communication between the first and second subcomponents via a bus protocol. The first subcomponent is connected to the first component, and the second subcomponent is connected to the second component. Communication between the first subcomponent and the first module and between the second subcomponent and the second module is also via a bus protocol. The software portion may be executed by a processor in the first component. The software portion may first check the current access isolation state before the first component initiates a cross-domain access request, and in response to the access isolation state being in a second state, transmit the access request to the first subcomponent in the isolation component. The first subcomponent transmits an access request to the second subcomponent, and the second subcomponent transmits an access request to the second subcomponent. If the access isolation state is the first state, access to the second component is stopped. The software part also sends an access request to the first subcomponent, which checks the current access isolation state. If it is the second state, the first subcomponent transmits an access request to the second subcomponent. If it is the first state, the first subcomponent stops access.

[0147] The first subcomponent may be responsible for recording in real time the sum (total count) of the number of times the access isolation state has been in state 1 and the number of times the isolation release state has been in state 1. If the access isolation state is in state 2, the software part may obtain and record the first total count from the first subcomponent before transmitting the access request to the first subcomponent (see the embodiment described above), and after transmitting the access request to the second component, record the second total count in response to detecting the completion of the access corresponding to this access request, and determine the available state of the access result. Alternatively, the first subcomponent may record the first total count before transmitting the access request to the second subcomponent, and after transmitting the access request to the second component, record the second total count in response to detecting the completion of the access corresponding to this access request, determine the available state of the access result, and return the available state to the software part of the first component so that the software part can perform the corresponding processing on the access result based on the available state.

[0148] The first subcomponent transmits an access request to the second subcomponent, then detects a timeout state in which the second subcomponent returns a confirmation signal indicating transmission completion. In response to the timeout state, the first subcomponent determines that the transmission state of the second component's bus is abnormal, triggers an interrupt, sets an interrupt signal, returns the preset result as the access result to the software part of the first component, the interrupt signal triggers the software part to enter the interrupt processing flow, performs the corresponding abnormality processing, and recovers the first component's cross-domain access to the second component. Specific abnormality processing can be found in the previously described embodiment and is omitted here.

[0149] In several selectable embodiments, Figure 13 is a schematic diagram of the structure of a first subcomponent according to an exemplary embodiment of the present disclosure. As shown in Figure 13, the first subcomponent may include a total count counter and a total count register, the total count counter being used to count the total count, and the total count register being used to store the total count, thereby making it easier for the processor of the first component to read the total count. The first subcomponent may further include a timer and a comparator, the timer being used to start timing after transmitting an access request to a second subcomponent, and the comparator being used to compare the timer time to a preset time (i.e., a preset time length), and outputting an interrupt signal (e.g., a high-level signal) in response to the timer time exceeding the preset time. The interrupt signal triggers the total count counter to increment by 1, and the total count register stores the total count of the total count counter. The first subcomponent may further include an access isolation state register and an isolation release state register. The access isolation state register stores the access isolation state. The isolation release state register stores the isolation release state. Both the isolation release state and the interrupt signal can trigger the count of the total count counter, enabling accurate real-time recording of the total count. The access isolation state register and the isolation release state register can be controlled and maintained by the processor in the first component. The first component can access the total count register to read the first total count before cross-domain access and the second total count after access is complete. The interrupt signal can further be transmitted to the fault handling module, which notifies the software portion of the first component that it has entered the interrupt handling flow.

[0150] In several selectable embodiments, the first subcomponent may further include a first count register and a second count register, used to record a first total count and a second total count, respectively. The first and second count registers are connected to a comparator that can compare the first and second total counts and output the comparison result. The software portion of the first component can read the comparison result and determine the available state of the access result. The first and second count registers can be controlled by the first component to write the first and second total counts, respectively.

[0151] In several selectable embodiments, Figure 14 is a schematic diagram of the structure of a first subcomponent according to another exemplary embodiment of the present disclosure. As shown in Figure 14, the first subcomponent further includes a controller for controlling other related components. For example, when the first subcomponent checks the access isolation state and the access isolation state is a second state, the controller reads the access isolation state register to confirm the access isolation state when the first component transmits an access request to the second subcomponent. Alternatively, for example, before the first subcomponent transmits an access request to the second subcomponent, the controller reads the total count register to obtain the first total count and writes it to the first count register, and after the access is complete, the controller reads the total count register to obtain the second total count and writes it to the second count register, and controls the operation of the comparator to compare the first total count and the second total count to obtain a comparison result. The first subcomponent may further include available state registers for storing the comparison result between the first total count and the second total count as available states of the access result. The first component can read the available state registers to determine the available state of the access result.

[0152] In several selectable embodiments, the signal transmission between the first subcomponent and the second subcomponent crosses the clock domain, allowing for cross-clock synchronization in the second subcomponent, thereby achieving synchronization between the second subcomponent and the first subcomponent.

[0153] In actual applications, the specific implementation method of the first subcomponent can be determined by the actual requirements and is not limited to the implementation methods shown in Figures 13 and 14 above.

[0154] Beneficial technical effects corresponding to exemplary embodiments of this apparatus can be found by referring to the corresponding beneficial technical effects of the exemplary method portion described above, and are therefore omitted from this explanation.

[0155] [Example electronic device] Figure 15 is a structural diagram of an electronic device according to an embodiment of the present disclosure, which comprises at least one processor 11 and memory 12.

[0156] The processor 11 can be a central processing unit (CPU) or another type of processing unit having data processing and / or instruction execution functions, and can control other components of the electronic device 10 to perform desired functions.

[0157] Memory 12 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored in the computer-readable storage media, and the processor 11 can implement the methods of each embodiment of the present disclosure and / or other desired functions by executing one or more computer program instructions.

[0158] In one example, the electronic device 10 may further include input devices 13 and output devices 14 connected to each other via a bus system and / or other forms of connection mechanisms (not shown).

[0159] The input device 13 may further include, for example, a keyboard, a mouse, or the like.

[0160] The output device 14 can output various types of information to the outside. This output device 14 may include, for example, a display, a speaker, a printer, a communication network, and remote output devices connected thereto.

[0161] For simplicity, Figure 15 shows only some of the components of the electronic device 10 relevant to this disclosure, omitting components such as buses and input / output interfaces. The electronic device 10 may further include any other appropriate components depending on the specific application.

[0162] In several selectable embodiments, embodiments of the present disclosure provide electronic equipment comprising a cross-domain access device according to any of the above embodiments.

[0163] [Examples of computer program products and computer-readable storage media] Embodiments of this disclosure may further provide computer program products, including computer program instructions, in addition to the methods and apparatus described above. When the computer program instructions are executed by a processor, the processor is caused to perform the steps in the methods of each type of embodiment of this disclosure described in the “Exemplary Methods” portion above.

[0164] Computer program products can be created using one or any combination of programming languages ​​to produce program code for performing the operations of the embodiments of this disclosure, including object-oriented programming languages ​​such as Java and C++, and traditional procedural programming languages ​​such as the C language or similar programming languages. The program code can be executed as follows: it may be executed entirely on a user computing device, partially on a user device, as a standalone software package, partially on a user computing device and partially on a remote computing device, or entirely on a remote computing device or a server.

[0165] Furthermore, embodiments of the present disclosure further provide a computer-readable storage medium storing computer program instructions. When the computer program instructions are executed by a processor, the processor is caused to perform the steps in the methods of each type of embodiment of the present disclosure described in the “Exemplary Methods” portion above.

[0166] Any combination of one or more readable media can be used as a computer-readable storage medium. A readable medium can be a readable signal medium or a readable storage medium. A readable storage medium may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any combination thereof. More specific examples (non-exclusive list) of readable storage media include electrical connections with one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0167] While the basic principles of this disclosure have been explained above with reference to specific examples, the advantages, merits, and effects mentioned in this disclosure are merely illustrative and not limiting, and these advantages, merits, and effects are not necessarily present in every example of this disclosure. Furthermore, the specific details of the above disclosure are merely illustrative and easy-to-understand effects and are not limiting, and the above details do not necessarily limit this disclosure to being realized by the above specific details.

[0168] Those skilled in the art can make various modifications and alterations to this disclosure without departing from the spirit and scope of the present application. Thus, if such modifications and alterations of the present application fall within the claims of this disclosure and the equivalent art thereto, this disclosure also includes such modifications and alterations.

Claims

1. A cross-domain access method in which each step is performed by a cross-domain access device, A step of transmitting an access request from a first component with a first security level to a second component with a second security level, The steps include detecting the transmission state of the bus of the second component, The steps include: generating an interrupt signal based on the transmission state of the bus, and setting the preset result when the transmission state of the bus is in a preset state as the access result corresponding to the access request transmitted by the second component; The step includes performing error processing corresponding to the interrupt signal to recover the first component's access to the second component, The step of performing error processing corresponding to the interrupt signal to recover the first component's access to the second component is: The steps include: performing access isolation between the first component and the second component based on the interrupt signal; The steps include restarting the second component to restore the transmission state of the bus of the second component to a normal state, A cross-domain access method characterized by comprising the step of releasing the access isolation between the first component and the second component to recover the first component's access to the second component.

2. The step of performing access isolation between the first component and the second component based on the interrupt signal is: The process includes the step of setting the first component to a first state of access isolation, where the first component accesses the second component based on the interrupt signal, The step of removing the access isolation between the first component and the second component is: The cross-domain access method according to claim 1, characterized by including the step of setting the de-isolation state to a first state and / or setting the access isolation state to a second state.

3. The step of transmitting an access request from a first component with a first security level to a second component with a second security level is: The steps include checking the access isolation state of the first component accessing the second component, The step of transmitting the access request to the second component in response to the access isolation state being a second state, The aforementioned cross-domain access method is: The cross-domain access method according to claim 1, further comprising the step of stopping access to the second component in response to the access isolation state being a first state.

4. Before transmitting the access request to the second component, The process further includes recording a first total number of times, which is the sum of the number of times the access isolation state has been in the first state and the number of times the isolation release state has been in the first state, in response to the access isolation state being in the second state. After transmitting the access request to the second component, A step of detecting whether the access corresponding to the aforementioned access request has been completed, Steps include: obtaining the access result corresponding to the access request in response to the completion of access, recording a second total count which is the sum of the number of times the access isolation state entered a first state and the number of times the isolation release state entered a first state; A step of determining the availability status of the access result corresponding to the access request based on the first total number and the second total number, The cross-domain access method according to claim 3, further comprising the step of performing processing on the access result corresponding to the available state.

5. The step of determining the availability status of the access result corresponding to the access request based on the first total number and the second total number is as follows: In response to the second total number being the same as the first total number, the step of determining that the available state is available, The cross-domain access method according to claim 4, comprising the step of determining that the available state is unavailable in response that the second total number is different from the first total number.

6. The step of detecting the transmission state of the bus of the second component is: The steps include detecting a timeout condition in which the second component returns a signal confirming the completion of transmission, A cross-domain access method according to any one of claims 1 to 5, comprising the step of determining that the transmission state of the bus of the second component is abnormal in response to the timeout state being a timeout.

7. The aforementioned cross-domain access method is: The cross-domain access method according to claim 6, further comprising the step of making the data transmitted from the second component an access result corresponding to the access request in response to receiving a transmission completion confirmation signal returned from the second component within a preset time.

8. A cross-domain access device, A transmission module for transmitting an access request from a first component with a first security level to a second component with a second security level, A first detection module for detecting the transmission state of the bus of the second component, A first response module generates an interrupt signal based on the transmission state of the bus, and sets the preset result when the transmission state of the bus is in a preset state as the access result corresponding to the access request transmitted by the second component, The system includes a processing module for performing abnormal processing corresponding to the interrupt signal to recover the first component's access to the second component, The aforementioned processing module is An isolation unit for performing access isolation between the first component and the second component based on the interrupt signal, A control unit for restarting the second component and recovering the transmission state of the bus of the second component to a normal state, A cross-domain access device comprising: an isolation release unit for releasing the access isolation between the first component and the second component and recovering the first component's access to the second component.

9. The aforementioned transmission module is A first inspection unit for checking the access isolation state of the first component accessing the second component, A transmission unit for transmitting the access request to the second component in response to the access isolation state being a second state, The cross-domain access device according to claim 8, further comprising a processing unit for stopping access to the second component in response to the access isolation state being a first state.

10. The first detection module is, A detection unit for detecting a timeout condition in which the second component returns a signal confirming the completion of transmission, The cross-domain access device according to claim 8 or 9, further comprising: a third determination unit for determining that the transmission state of the bus of the second component is abnormal in response to the timeout state being a timeout.

11. The first detection module is, The cross-domain access device according to claim 10, further comprising a fourth confirmation unit for determining the data transmitted by the second component as an access result corresponding to the access request, in response to receiving a transmission completion confirmation signal returned from the second component within a preset time.

12. A computer-readable storage medium, A computer-readable storage medium characterized by storing a computer program for executing the cross-domain access method described in claim 1.

13. It is an electronic device, Processor and The processor comprises a memory for storing executable instructions, The processor realizes the cross-domain access method described in claim 1 by reading the executable instruction from the memory and executing the executable instruction, or An electronic device characterized by comprising the cross-domain access device described in claim 8.

Citation Information

Patent Citations

  • Separate reset method for bus connecting system

    JP1993342145A

  • Access interruption circuit, semiconductor integrated circuit, and access interruption method

    JP2016206891A

  • Safety node in interconnect data buses

    US20150355989A1