System on chip and vehicle comprising same

By designing a physically isolated FSI subsystem in the system on chip, the insufficient logical independence caused by resource sharing between FSI and ADAS system is solved, and higher system stability and reliability are achieved.

WO2025130435A1PCT designated stage expired Publication Date: 2025-06-26NIO SMART TECHNOLOGY (SHENZHEN) CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/131184
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-20
Filing Date
2024-11-11
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

In the existing ADAS chip design, the functional safety island (FSI) is logically independent from the ADAS system, but due to resource sharing, it cannot be completely isolated, resulting in the FSI being affected by ADAS system abnormalities and cannot be monitored normally.

Method used

By designing a physically isolated FSI subsystem in the system-on-chip, using completely independent hardware modules and asynchronous serial ports to communicate, avoid resource sharing, thereby realizing physical isolation between FSI and functional modules.

Benefits of technology

It effectively improves the stability and reliability of SoC, prevents FSI from stagnating due to ADAS system abnormalities, and ensures the independence and reliability of functional safety monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024131184_26062025_PF_FP_ABST
    Figure CN2024131184_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a system on a chip (SoC) and a vehicle comprising same. The SoC comprises a functional module subsystem and an FSI subsystem. The functional module subsystem comprises a functional module internal bus, a functional module processor, a functional module memory, and a functional module path interface. The functional module processor, the functional module memory, and the functional module path interface are separately communicatively connected to the functional module internal bus. The FSI subsystem comprises an FSI internal bus, an FSI processor, an FSI memory, and an FSI path interface. The FSI processor, the FSI memory, and the FSI path interface are separately communicatively connected to the FSI internal bus, and the FSI path interface is configured to communicate with the functional module path interface to form a communication link. According to the SoC provided by embodiments of the present application, an FSI is designed by means of physical isolation, so that the FSI is completely isolated from the functional module of the SoC, thereby avoiding the problem of mutual influence between the FSI and the functional module in a mainstream design, and effectively improving the stability and reliability of the SoC.
Need to check novelty before this filing date? Find Prior Art

Description

System on chip and vehicle including the same

[0001] This application claims priority to Chinese patent application 202311763711.X, filed on December 20, 2023, entitled “System on a Chip and Vehicle Including the Same,” the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of electronics, and in particular to a system on a chip and a vehicle including the same. Background Art

[0003] With the advancement of semiconductor technology, traditional microcontroller units (MCUs) can no longer fully meet the needs of smart terminals, giving rise to the System on Chip (SoC). With its high performance, low power consumption, and high flexibility, SoCs enable complete electronic systems to be implemented on a single chip.

[0004] With the rapid development of autonomous driving technology, the functions and complexity of Advanced Driving Assistance System (ADAS) chips are becoming increasingly higher, and vehicle functional safety is also placing higher demands on the system-on-chip of ADAS modules.

[0005] In the current mainstream ADAS chip design scheme, in addition to meeting the necessary software and hardware requirements for autonomous driving, a system function monitoring module is usually added. This system function monitoring module is relatively independent and is used to monitor whether the functions of the entire ADAS system are operating normally. This system function monitoring module is called the Functional Safety Island (FSI).

[0006] To ensure that the FSI's monitoring functions are not interfered with by the ADAS system, the FSI must be as logically independent from the ADAS system as possible. However, due to factors such as SoC design integration and software design complexity, the current mainstream design scheme reuses some SoC system resources and peripherals (such as bus systems, memory, mailboxes, etc.) with the ADAS system, resulting in incomplete isolation of power supply and reset functions. Under this design, the FSI and ADAS system are only logically independent. Consequently, when an ADAS system experiences an anomaly, there is a chance that the FSI's functions will be affected. For example, if the ADAS system experiences a bus freeze or memory system anomaly, since these resources are shared with the FSI, the FSI may also freeze due to the impact, resulting in the inability to complete the ADAS system monitoring function.

[0007] Summary of the Invention

[0008] An embodiment of the present application provides a system-on-chip and a vehicle including the same. By designing the FSI (also known as a "functional safety island" or "functional safety monitoring module") using physical isolation, the FSI is completely isolated from the functional modules of the SoC (also known as the "system-on-chip"), thereby avoiding the problem of mutual influence between the FSI and the functional modules in mainstream designs and effectively improving the stability and reliability of the SoC.

[0009] According to one aspect of the present application, a system on chip is provided, which includes a functional module subsystem and an FSI subsystem; wherein the functional module subsystem includes: a functional module internal bus; a functional module processor, the functional module processor is communicatively connected to the functional module internal bus; a functional module memory, the functional module memory is communicatively connected to the functional module internal bus; and a functional module path interface, the functional module path interface is communicatively connected to the functional module internal bus; wherein the FSI subsystem includes: an FSI internal bus; an FSI processor, the FSI processor is communicatively connected to the FSI internal bus; an FSI memory, the FSI memory is communicatively connected to the FSI internal bus; and an FSI path interface, the FSI path interface is communicatively connected to the FSI internal bus, and the FSI path interface is configured to communicate with the functional module path interface to form a communication link.

[0010] In some embodiments of the present application, optionally, the communication link is based on any one of the following communication protocols: UART, SPI, I2C.

[0011] In some embodiments of the present application, optionally, the FSI subsystem and the functional module subsystem can achieve startup state synchronization through the communication link.

[0012] In some embodiments of the present application, optionally, the FSI subsystem can query the operating status of the functional module subsystem through the communication link.

[0013] In some embodiments of the present application, optionally, when an abnormality occurs in the functional module subsystem, the FSI subsystem can query the cause of the abnormality in the functional module subsystem through the communication link.

[0014] In some embodiments of the present application, optionally, when the functional module subsystem is in a suspended state, the FSI subsystem can obtain a timeout reply through the communication link.

[0015] In some embodiments of the present application, optionally, the FSI subsystem further includes an FSI interrupt controller, the FSI interrupt controller being communicatively connected to the FSI processor; and

[0016] The functional module subsystem is configured to send a hardware signal of an abnormal interrupt to the FSI interrupt controller in an interrupt manner when an abnormal interrupt occurs.

[0017] In some embodiments of the present application, optionally, the functional module subsystem and the FSI subsystem each have an independent power control switch and reset switch.

[0018] In some embodiments of the present application, optionally, the functional module subsystem is an ADAS module subsystem.

[0019] According to another aspect of the present application, a vehicle is provided, comprising any one of the system-on-chips described above.

[0020] In the FSI design, the present embodiment utilizes completely independent hardware modules (CPU, memory, etc.) and uses asynchronous serial ports for communication between the FSI and the functional modules. This configuration prevents the sharing of system resources and peripherals between the FSI and the functional modules, thereby achieving physical isolation between the FSI and the functional modules. This addresses shortcomings in current designs and effectively improves system stability and reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The above and other objects and advantages of the present application will become more fully apparent from the following detailed description taken in conjunction with the accompanying drawings, wherein the same or similar elements are denoted by the same reference numerals.

[0022] FIG1 shows a schematic structural diagram of a system on a chip according to an embodiment of the present application; and

[0023] FIG2 shows a schematic diagram of a vehicle according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] For brevity and illustrative purposes, the principles of the present application are described herein primarily with reference to exemplary embodiments thereof. However, those skilled in the art will readily recognize that the same principles are equally applicable to all types of system-on-chips and vehicles including the same, and that the same or similar principles may be implemented therein, without departing from the true spirit and scope of the present application.

[0025] A system on chip (SoC) 100 according to an embodiment of the present application will be described below with reference to FIG. 1 .

[0026] FIG1 is a schematic diagram illustrating the structure of a system-on-chip (SoC) 100 according to one embodiment of the present application. As shown in FIG1 , SoC 100 may include a functional module subsystem 120 and an FSI subsystem 110. Functional module subsystem 120 is a subsystem corresponding to the primary functional modules in SoC 100. Because the functional modules in SoC 100 can operate as independent subsystems, the functional modules in SoC 100 are referred to herein as "functional module subsystem 120."

[0027] In order to ensure the normal operation of the main functions of the system on chip 100, the system on chip 100 usually has high requirements for the security level of the functional module subsystem 120. Therefore, an FSI is added inside the system on chip 100 to monitor the safe operation of the functional module subsystem 120. In the embodiment of the present application, the FSI in the system on chip 100 can also operate as an independent subsystem. Therefore, the FSI in the system on chip 100 is referred to as "FSI subsystem 110" in this article. Through the monitoring of the functional module subsystem 120 by the FSI subsystem 110, the FSI subsystem 110 can monitor whether the entire functional module subsystem 120 is operating normally, and when an abnormality occurs in the software and hardware of the functional module subsystem 120, the abnormality is recorded and reported, and an attempt is made to recover the abnormality.

[0028] In some embodiments, the system-on-chip (SoC) 100 can be used in a vehicle 200 (see FIG1 ). Accordingly, the functional module subsystem 120 can be an ADAS module (ADAS Module) subsystem for implementing autonomous driving functions. In the system-on-chip (SoC) 100, the ADAS module can be an independently operated subsystem and is therefore referred to as an "ADAS module subsystem" in this document. As an example, the ADAS module subsystem can have all the system resources required by a traditional ADAS system-on-chip as well as the SoC design implementation functions.

[0029] In the embodiment shown in FIG1 , the functional module subsystem 120 may include a functional module internal bus 121, a functional module processor 122, a functional module memory 123, and a functional module path interface 124. The functional module processor 122, the functional module memory 123, and the functional module path interface 124 may be communicatively connected to the functional module internal bus 121, so that the aforementioned units may communicate with each other via the functional module internal bus 121.

[0030] As shown in Figure 1, the functional module processor 122 is a central processing unit (CPU) dedicated to the functional module subsystem 120, which is used to implement the main functions of the system on chip (SoC) 100. The functional module memory 123 is a memory dedicated to the functional module subsystem 120. As an example, the type of the functional module memory 123 can be selected according to the system requirements and characteristics of the functional module subsystem 120. For example, in an example where the functional module subsystem 120 is an ADAS module subsystem, the functional module memory 123 can be a non-volatile memory with a storage capacity of about tens of gigabytes (G). In addition, in the functional module subsystem 120, the functional module path interface 124 is used to implement communication between the functional module subsystem 120 and the FSI subsystem 110.

[0031] In some embodiments, the functional module subsystem 120 may further include other peripherals. For example, if the functional module subsystem 120 is an ADAS module subsystem, the functional module subsystem 120 may further include a graphics processing unit (GPU) 125 and other devices 126 that participate in implementing the autonomous driving function. As shown in FIG1 , the GPU 125 and other devices 126 are communicatively connected to the functional module internal bus 121 to enable communication with other related units within the functional module subsystem 120 (e.g., the functional module processor 122, the functional module memory 123, and the functional module path interface 124) via the functional module internal bus 121.

[0032] As shown in FIG1 , the functional module subsystem 120 may further include a functional module interrupt controller 127 , wherein the functional module interrupt controller 127 is communicatively connected to the functional module processor 122 for transmitting interrupt information associated with the processing process to the functional module processor 122 while the functional module subsystem 120 is performing its functions.

[0033] In the embodiment shown in FIG1 , the FSI subsystem 110 includes an FSI internal bus 111, an FSI processor 112, an FSI memory 113, and an FSI path interface 114. The FSI processor 112, the FSI memory 113, and the FSI path interface 114 can be communicatively connected to the FSI internal bus 111, so that the above-mentioned units can communicate with each other through the FSI internal bus 111.

[0034] As shown in FIG1 , the FSI processor 112 is a dedicated CPU for the FSI subsystem 110. Accordingly, the FSI subsystem 110 can use an independent CPU to run an independent software system. As can be seen from FIG1 , the functional safety island (FSI) in the embodiment of the present application can be an independently running subsystem that uses a separate CPU (i.e., the FSI processor 112) and a memory system (i.e., the FSI memory 113), and integrates the minimum set of peripherals required for the operation of the subsystem.

[0035] The FSI memory 113 is a dedicated memory for the FSI subsystem 110. For example, the type of the FSI memory 113 can be selected based on the system requirements and characteristics of the FSI subsystem 110. Considering that the FSI subsystem 110 is used to perform monitoring functions, a memory with high access speed and high reliability can be selected as the FSI memory 113. For example, the FSI memory 113 can be a static random-access memory (SRAM) or an on-chip tightly coupled memory (TCM).

[0036] In an embodiment of the present application, FSI subsystem 110 and functional module subsystem 120 each have a dedicated internal bus, CPU and memory. That is to say, FSI internal bus 111, FSI processor 112 and FSI memory 113 are only used by FSI subsystem 110, and are not shared with functional module subsystem 120. To a certain extent, FSI internal bus 111, FSI processor 112 and FSI memory 113 are isolated from functional module subsystem 120 respectively. Functional module internal bus 121, functional module processor 122 and functional module memory 123 are only used by functional module subsystem 120, and are not shared with FSI subsystem 110. To a certain extent, functional module internal bus 121, functional module processor 122 and functional module memory 123 are isolated from FSI subsystem 110 respectively.

[0037] In an embodiment of the present application, the FSI subsystem 110 may further include a timer 115. As shown in FIG1 , the timer 115 is communicatively connected to the FSI internal bus 111, thereby enabling communication with other related units within the FSI subsystem 110 (e.g., the FSI processor 112, the FSI memory 113, and the FSI path interface 114) via the FSI internal bus 111. In some embodiments of the present application, each peripheral unit in the FSI subsystem 110 may be interconnected by being communicatively connected to the FSI internal bus 111.

[0038] As shown in Figure 1, the FSI subsystem 110 may also include an FSI interrupt controller 116, wherein the FSI interrupt controller 116 is communicatively connected to the FSI processor 112. The functional module subsystem 120 may be configured to, in the event of an abnormal interrupt, send an abnormal interrupt hardware signal to the FSI interrupt controller 116 in an interrupt mode via the abnormal interrupt hardware path 140. Accordingly, the FSI interrupt controller 116 may be configured to, in the event of an abnormal interrupt, receive an abnormal interrupt signal via the abnormal interrupt hardware path 140, transmit the abnormal interrupt signal to the FSI processor 112. In an embodiment of the present application, when the functional module subsystem 120 generates an abnormal interrupt, the SoC 100 may generate a physical abnormal signal as an external interrupt of the FSI subsystem 110, notify the FSI subsystem 110 in an interrupt mode, thereby improving abnormal perception and processing efficiency. In some embodiments, the FSI processor 112 may perform a coarse-grained judgment based on the received hardware signal of the abnormal interrupt, and determine the cause of the abnormal interrupt based on this.

[0039] In the embodiment shown in Figure 1, the FSI path interface 114 is communicatively connected to the functional module path interface 124 to form a communication link 130 for realizing communication between the FSI subsystem 110 and the functional module subsystem 120. In the embodiment of the present application, the communication link 130 can be configured as a low-speed path as the main way for the FSI subsystem 110 and the functional module subsystem 120 to interact. In some embodiments, the communication link 130 between the FSI path interface 114 and the functional module path interface 124 can be based on any of the following communication protocols: Universal Asynchronous Receiver / Transmitter (UART), Serial Peripheral Interface (SPI), and Inter-Integrated Circuit (I2C). In other embodiments, the communication link 130 can be based on other communication interface protocols.

[0040] Based on the communication link 130 between the FSI subsystem 110 and the functional module subsystem 120, a corresponding interaction protocol between the FSI subsystem 110 and the functional module subsystem 120 can be implemented through software. As an example, the interaction protocol may include related functions such as startup status synchronization, system operation status query, and abnormality cause query.

[0041] The SoC 100 of the embodiment of the present application can use a low-speed path communication method (for example, using a communication protocol such as UART, SPI, I2C, etc.) between the FSI subsystem 110 and the functional module subsystem 120, without causing abnormal interference between the two subsystems. As an example, when an abnormality occurs in the functional module subsystem 120, the FSI subsystem 110 can query through a protocol based on a low-speed path (for example, a communication protocol such as UART, SPI, I2C, etc.). Accordingly, even if the functional module subsystem 120 is in a suspended state, the FSI subsystem 110 will receive a timeout response, and the local operation of the FSI subsystem 110 will not be caused by the communication abnormality.

[0042] In some embodiments, the FSI subsystem 110 and the functional module subsystem 120 can synchronize their startup states via the communication link 130. For example, when either the FSI subsystem 110 or the functional module subsystem 120 is started, it can send a signal to the other subsystem via the communication link 130, causing the other subsystem to start synchronously.

[0043] In some embodiments, the FSI subsystem 110 can query the operating status of the functional module subsystem 120 through the communication link 130. For example, when the functional module subsystem 120 is in an operating state, the FSI subsystem 110 can periodically send a query signal to the functional module subsystem 120 through the communication link 130. Accordingly, the functional module subsystem 120 can respond to the FSI subsystem 110 in response to the received query signal.

[0044] In some embodiments, when an exception occurs in the functional module subsystem 120, the FSI subsystem 110 can query the cause of the exception in the functional module subsystem 120 through the communication link 130. As described above, when an abnormal interrupt occurs in the functional module subsystem 120, an abnormal interrupt signal can be transmitted via the abnormal interrupt hardware path 140. In contrast, the situation where the abnormal signal is transmitted via the communication link 130 corresponds to a situation where the abnormality occurring in the functional module subsystem 120 is not so serious (for example, the functional module subsystem 120 does not have an abnormal interrupt). For example, the FSI subsystem 110 can receive an abnormal signal of a timeout reply via the communication link 130, which corresponds to the functional module subsystem 120 being in a suspended abnormal state.

[0045] In an embodiment of the present application, the functional module subsystem 120 and the FSI subsystem 110 each have independent power control switches and reset switches. As shown in FIG1 , the functional module subsystem 120 is provided with a functional module power control switch 128 and a functional module reset switch 129. The functional module power control switch 128 can independently control the power on and off of the functional module subsystem 120, and the functional module reset switch 129 can independently control the reset of the functional module subsystem 120. Since the functional module subsystem 120 has independent power control and system reset implementations, if an abnormality occurs during the operation of the functional module subsystem 120, the SoC 100 can restore system functions by partially resetting the functional module subsystem 120 without resetting the entire SoC 100 and the FSI subsystem 110.

[0046] Since the FSI subsystem 110 has independent power control and system reset implementation, the FSI subsystem 110 can be regarded as a sub-SoC system integrated within the SoC 100. As shown in Figure 1, the FSI subsystem 110 is provided with an FSI power control switch 118 and an FSI reset switch 119, wherein the FSI power control switch 118 can independently control the power on and off of the FSI subsystem 110, and the FSI reset switch 119 can independently control the reset of the FSI subsystem 110. The embodiment of the present application configures the FSI subsystem 110 to have an independent CPU and content, so that the FSI subsystem 110 is physically isolated from the functional module subsystem 120, thereby enabling independent power control and system reset.

[0047] In an embodiment of the present application, the entire system on chip 100 can be divided into two parts, one of which is a functional module subsystem 120 for completing the main functions of the SoC, and the other is an FSI subsystem 110 for monitoring the operating status of the functional module subsystem 120. The implementation of the functional module subsystem 120 and the FSI subsystem 110 of the embodiment of the present application is not only functionally independent of each other, but also isolated in the use of physical resources. That is to say, in an embodiment of the present application, the functional module subsystem 120 and the FSI subsystem 110 can operate independently as separate systems, and during the operation of each subsystem, they can be unaffected by each other.

[0048] The FSI subsystem 110 of the embodiment of the present application has necessary peripherals such as an independent CPU (i.e., FSI processor 112), memory (i.e., FSI memory 113), timer 115, FSI path interface 114, FSI interrupt controller 116, wherein the peripheral resources such as memory, timer 115, FSI path interface 114 and CPU can be connected through FSI internal bus 111. In addition, information exchange can be carried out between the FSI subsystem 110 and the functional module subsystem 120 through a low-speed path (e.g., based on communication protocols such as UART, SPI, I2C). In an embodiment of the present application, although the FSI subsystem 110 and the functional module subsystem 120 are integrated into the SoC 100 together, there is no resource sharing between the two, and they are physically independent of each other, thus similar to two independent SoC subsystems. In addition, in some embodiments, the FSI subsystem 110 and the functional module subsystem 120 both have independent power control domains and can be reset independently, so that the abnormalities of the two independent subsystems themselves will not be transmitted and affected by each other.

[0049] In the example where functional module subsystem 120 is an ADAS module subsystem, SoC 100 may be divided into two parts: an ADAS module subsystem for implementing autonomous driving functions and an FSI subsystem 110 for monitoring the operating status of the ADAS module subsystem. The ADAS module subsystem and FSI subsystem 110 are independent of each other during operation. In other embodiments, functional module subsystem 120 may also be a functional module subsystem for implementing other functions.

[0050] In the ADAS chip design, embodiments of the present application utilize physical isolation to design a functional safety monitoring module (i.e., FSI subsystem 110) that is completely isolated from the autonomous driving main function module (i.e., the ADAS module subsystem). The functional safety monitoring module and the autonomous driving main function module can communicate via a low-speed path (e.g., based on a communication protocol such as UART, SPI, or I2C), avoiding the sharing of buses, memory, and other SoC on-chip resources between the two modules. This reduces the functional safety monitoring module's dependence on other modules in the system-on-chip 100 and ensures complete independence from the autonomous driving main function module. This avoids the mutual influence between the two modules found in mainstream designs and prevents stability failures in the functional safety monitoring module caused by failures in the autonomous driving main function module, thereby effectively improving the stability and reliability of the system-on-chip 100.

[0051] Next, a vehicle 200 according to an embodiment of the present application will be described with reference to FIG. 2 .

[0052] FIG2 shows a schematic diagram of a vehicle 200 according to one embodiment of the present application. As shown in FIG2 , vehicle 200 may include any control system 110 according to any of the embodiments of the present application described above. Vehicle 200 as referred to herein may represent any suitable vehicle having a drive system consisting of at least a battery, a power conversion device, and a drive motor, such as a hybrid electric vehicle, an electric vehicle, a plug-in hybrid electric vehicle, and the like. A hybrid electric vehicle is a vehicle that has two or more power sources, such as a gasoline-powered and an electric vehicle.

[0053] The relevant user personal information that may be involved in the various embodiments of this application is strictly in accordance with the requirements of laws and regulations, following the principles of legality, legitimacy and necessity, and based on the reasonable purposes of business scenarios, to process the personal information that users actively provide during the use of products / services or generated due to the use of products / services, as well as the personal information obtained with the user's authorization.

[0054] The personal information processed by the Applicant will vary depending on the specific product / service scenario and will be based on the specific scenario in which the user uses the product / service. This may involve the user's account information, device information, driving information, vehicle information, or other related information. The Applicant will treat the user's personal information and its processing with a high degree of diligence.

[0055] The Applicant attaches great importance to the security of user personal information and has taken reasonable and feasible security measures that comply with industry standards to protect user information and prevent personal information from being accessed, disclosed, used, modified, damaged or lost without authorization.

[0056] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Those skilled in the art can think of other feasible changes or replacements based on the technical scope disclosed in this application, and such changes or replacements are all included in the scope of protection of the present application. In the absence of conflict, the embodiments of the present application and the features in the embodiments can also be combined with each other. The scope of protection of the present application shall be based on the description of the claims.

Claims

1. A system on chip, characterized in that: The system on chip comprises: Functional module subsystem, wherein the functional module subsystem comprises: Internal bus of functional modules; a function module processor, the function module processor being communicatively connected to the function module internal bus; a function module memory, the function module memory being communicatively connected to the function module internal bus; and a functional module access interface, the functional module access interface being communicatively connected to the functional module internal bus; and FSI subsystem, wherein the FSI subsystem comprises: FSI internal bus; an FSI processor, the FSI processor being communicatively connected to the FSI internal bus; An FSI memory communicatively coupled to the FSI internal bus; and The FSI pathway interface is communicatively connected to the FSI internal bus, and the FSI pathway interface is configured to communicate with the functional module pathway interface to form a communication link.

2. The system on chip according to claim 1, characterized in that: The communication link is based on any one of the following communication protocols: UART, SPI, I2C.

3. The system on chip according to claim 1 or 2, characterized in that: The FSI subsystem and the functional module subsystem can achieve startup state synchronization through the communication link.

4. The system on chip according to claim 1 or 2, characterized in that: The FSI subsystem can query the operating status of the functional module subsystem through the communication link.

5. The system on chip according to claim 4, characterized in that: In the event that an abnormality occurs in the functional module subsystem, the FSI subsystem can query the cause of the abnormality in the functional module subsystem through the communication link.

6. The system on chip according to claim 4, characterized in that: When the functional module subsystem is in a suspended state, the FSI subsystem can obtain a timeout reply through the communication link.

7. The system on chip according to claim 1, characterized in that: The FSI subsystem further includes an FSI interrupt controller communicatively coupled to the FSI processor; and The functional module subsystem is configured to send a hardware signal of an abnormal interrupt to the FSI interrupt controller in an interrupt mode when an abnormal interrupt occurs.

8. The system on chip according to claim 1, wherein: The functional module subsystem and the FSI subsystem each have an independent power control switch and a reset switch.

9. The system on chip according to claim 1, characterized in that: The functional module subsystem is an ADAS module subsystem.

10. A vehicle, characterized in that: The vehicle comprises the system on chip according to any one of claims 1-9.

Citation Information

Patent Citations

  • Functional security system and method for functional security system

    CN116501527A

  • System on chip and vehicle comprising same

    CN117951075A

  • Flexible interface

    US20160216327A1

  • Method for operating a robot device

    WO2023241910A1