Chip, chip startup method, controller and terminal device
By setting up an isolation module within the chip to control access to the central processing unit and hardware resources, and dividing the chip into multiple control function areas, the problems of increased vehicle cost and network load caused by the increase in the number of electronic control units are solved, achieving cost reduction and network optimization.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- CHIPSEA TECH SHENZHEN CO LTD
- Filing Date
- 2025-08-26
- Publication Date
- 2026-04-23
AI Technical Summary
As automotive electrical functions become more sophisticated and the number of electronic control units increases, problems arise such as higher vehicle costs, more communication cabling, and increased load on in-vehicle networks.
By setting a first isolation module between the central processing unit and the bus, and a second isolation module between the hardware resources and the bus, these modules are used to control the access of the central processing unit and the legitimate access objects of the hardware resources, so as to divide multiple control function areas within the same chip and reduce the number of electronic control units.
This reduces the number of electronic control units in the car, lowers costs and communication wiring, and reduces the load on the vehicle network.
Smart Images

Figure CN2025117114_23042026_PF_FP_ABST
Abstract
Description
Chips, chip boot methods, controllers, and terminal devices
[0001] This application claims priority to Chinese Patent Application No. 202411462382.X, filed on October 18, 2024, entitled "Chip, Chip Startup Method, Controller and Terminal Device", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of integrated circuit technology, specifically to a chip, a chip startup method, a controller, and a terminal device. Background Technology
[0003] Currently, the Electronic Control Unit (ECU) is the core of an automotive electronic control system. It is responsible for receiving and processing signals from sensors and precisely controlling various components of the vehicle based on these signals. As automobiles rapidly develop and acquire increasingly sophisticated electrical functions, the number of ECUs in vehicles is also increasing. For example, in traditional vehicles, there are engine ECUs, transmission ECUs, powertrain ECUs, brake ECUs, anti-lock braking systems (ABS) ECUs, body control ECUs, and suspension control ECUs; further additions may include battery management ECUs, autonomous driving ECUs, and vehicle safety ECUs.
[0004] However, the significantly increased number of electronic control units has brought enormous challenges to the traditional distributed electronic and electrical architecture, resulting in increased vehicle costs, more communication cabling between electronic control units, and increased load on the vehicle network. Technical solutions
[0005] In view of the above problems, embodiments of this application provide a chip, a chip startup method, a controller, and a terminal device to solve the above technical problems.
[0006] In a first aspect, embodiments of this application provide a chip, comprising: at least one central processing unit (CPU); multiple hardware resources, including at least one memory, at least one physical input interface, at least one physical output interface, or at least one physical communication interface, wherein the at least one hardware resource has multiple resource regions; a bus connecting the CPU and the hardware resources, such that the CPU can access the hardware resources via the bus; at least one first isolation module and multiple second isolation modules, each first isolation module being connected between the CPU and the bus, and each second isolation module being connected between a hardware resource and the bus; wherein each first isolation module is configured to control the hardware resources and / or resource regions of the corresponding hardware resources that the CPU can actively access, and each second isolation module is configured to control the legal access objects of the corresponding hardware resources and / or resource regions of the hardware resources.
[0007] Secondly, embodiments of this application also provide a chip boot method, comprising: configuring each first isolation module and each second isolation module in response to system power-on, such that each first isolation module controls the hardware resources and / or resource areas of the corresponding central processing unit that can be actively accessed, and each second isolation module controls the legal access objects of the corresponding hardware resources and / or resource areas of the hardware resources; controlling each central processing unit to load a program, and during program execution, each central processing unit accesses the corresponding hardware resources under the control of the first isolation module and the second isolation module.
[0008] Thirdly, embodiments of this application also provide a controller, including the chip described in the first aspect.
[0009] Fourthly, embodiments of this application also provide a terminal device, including the controller described in the third aspect.
[0010] This application establishes a first isolation module between the central processing unit (CPU) and the bus, and a second isolation module between the hardware resources and the bus. The first isolation module controls the hardware resources that the corresponding CPU can actively access, and the second isolation module controls the legal access objects of the corresponding hardware resources. Through the first and second isolation modules, multiple CPUs and multiple hardware resources can be divided into multiple control function areas within the same chip. This allows each control function area to perform the function of a traditional electronic control unit (ECU) (such as window control, headlight control, engine control, etc.). Compared to the phenomenon that traditional ECU chips can only perform a single control function, this application helps to reduce the number of ECUs in a car, thereby avoiding the problems of increased car costs, increased communication wiring between ECUs, and increased load on the vehicle network caused by the increased number of ECUs.
[0011] These or other aspects of this application will become more apparent in the following description of the embodiments. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 shows a schematic diagram of an electronic control unit in the related technology.
[0014] Figure 2 shows a schematic diagram of a chip in an embodiment of this application.
[0015] Figure 3 shows another schematic diagram of the chip in an embodiment of this application.
[0016] Figure 4 shows another schematic diagram of the chip in an embodiment of this application.
[0017] Figure 5 shows a schematic diagram of the functional area division of a chip in an embodiment of this application.
[0018] Figure 6 shows another functional area division diagram of the chip in an embodiment of this application.
[0019] Figure 7 shows another functional area division diagram of the chip in an embodiment of this application.
[0020] Figure 8 shows another functional area division diagram of the chip in an embodiment of this application.
[0021] Figure 9 shows another schematic diagram of the chip in an embodiment of this application.
[0022] Figure 10 shows another schematic diagram of the chip in an embodiment of this application.
[0023] Figure 11 shows another schematic diagram of the chip in an embodiment of this application.
[0024] Figure 12 shows another schematic diagram of the chip in an embodiment of this application.
[0025] Figure 13 shows another schematic diagram of the chip in an embodiment of this application.
[0026] Figure 14 shows a schematic flowchart of a chip startup method in an embodiment of this application.
[0027] The system comprises: 10 central processing unit, 20 hardware resources, 30 bus, 40 first isolation module, 41 first resource configuration unit, 42 first access monitoring unit, 50 second isolation module, 51 second resource configuration unit, 52 second access monitoring unit, 60 hardware acceleration module, 70 third isolation module, 80 security module, 90 fourth isolation module, 100 DMA controller, and 110 fifth isolation module.
[0028] Implementation methods of this application
[0029] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.
[0030] To enable those skilled in the art to better understand the solutions of this application, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0031] In the embodiments of this application, it should be noted that, in this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.
[0032] Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0033] In the description of the embodiments of this application, the words "example" or "for example" are used to indicate exemplification, illustration, or description. Any embodiment or design described as "example" or "for example" in the embodiments of this application is not to be construed as being more preferred or having more advantages than another embodiment or design. The use of the words "example" or "for example" is intended to present relative concepts in a clear manner.
[0034] Furthermore, in the embodiments of this application, "multiple" refers to two or more. Therefore, in the embodiments of this application, "multiple" can also be understood as "at least two". "At least one" can be understood as one or more, such as one, two, or more. For example, including at least one means including one, two, or more, and is not limited to which ones are included. For example, including at least one of A, B, and C, then it could include A, B, C, A and B, A and C, B and C, or A and B and C.
[0035] It should be noted that in the embodiments of this application, "and / or" describes the relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. In addition, the character " / ", unless otherwise specified, generally indicates that the associated objects before and after it are in an "or" relationship.
[0036] It should be noted that in the embodiments of this application, "connection" can be understood as electrical connection. The connection between two electrical components can be a direct or indirect connection between the two electrical components. For example, the connection between A and B can be a direct connection between A and B, or an indirect connection between A and B through one or more other electrical components.
[0037] Currently, electronic control units (ECUs) are distributed throughout various parts of a vehicle. They collect sensor data, analyze and process this data, and ultimately output actions to achieve specific control functions, such as motor control, window control, door control, headlight control, and battery management. Referring to Figure 1, which illustrates a schematic diagram of an ECU in related technologies, the ECU includes an MCU chip, input hardware components, output hardware components, and communication hardware components. The input hardware components process the sensor signals and send them to the MCU chip. After analyzing and processing the data, the MCU chip outputs control signals to the corresponding execution units via the output hardware components, causing them to perform the corresponding actions. The communication hardware components are responsible for communication between the MCU chip and the communication network.
[0038] However, as automobiles have developed rapidly and become equipped with increasingly sophisticated electrical functions, the number of electronic control units (ECUs) in automobiles has increased dramatically. This significant increase in the number of ECUs has brought enormous challenges to the traditional distributed electronic and electrical architecture, resulting in increased automobile costs, more communication cabling between ECUs, and increased load on the vehicle network.
[0039] Therefore, this application provides a chip, a chip startup method, a controller, and a terminal device, which are described in detail below.
[0040] First, referring to Figure 2, Figure 2 shows a schematic diagram of a chip in an embodiment of this application. The chip may be, but is not limited to, an MCU (Microcontroller Unit) chip, a SOC (System on Chip) chip, or a SIP (System in Package) chip. The chip includes at least one central processing unit 10, multiple hardware resources 20, a bus 30, at least one first isolation module 40, and multiple second isolation modules 50.
[0041] Specifically, the Central Processing Unit (CPU) 10 is the control core of the chip for information processing and program execution. For example, the CPU 10 can perform arithmetic operations, logical operations, and control flow operations. In some embodiments of this application, the chip may include multiple CPUs 10. Each CPU 10 can run software programs that perform corresponding single functions (such as engine, window control, door control, headlight control, autonomous driving, etc.), so that multiple CPUs 10 can respectively implement arithmetic operations, logical operations, and control flow operations for different single functions.
[0042] In some embodiments of this application, the chip may include a central processing unit 10, which can run different single-function software programs in a time-sharing manner. For example, a central processing unit 10 may run a window control software program for a period of time and a door control software program for another period of time, so that a single central processing unit 10 can perform arithmetic operations, logical operations and control flow operations for different single functions respectively.
[0043] Understandably, the number of central processing units 10 can be set according to actual needs, such as 2, 4, 8, 10, 16, etc., and this application does not make a specific limitation.
[0044] Multiple hardware resources 20 include at least one memory, at least one physical input interface, at least one physical output interface, or at least one physical communication interface to ensure the normal operation of the central processing unit 10. For example, at least one memory may include non-volatile memory (NVM) to store software program data loaded by the central processing unit 10; for another example, at least one memory may include random access memory (RAM) to store data generated during the operation of the central processing unit 10; for yet another example, at least one physical input interface may include a general purpose input / output (GPIO), a SENT sensor interface, an Ethernet bus interface, a CAN bus interface, etc., so that the central processing unit 10 can receive input data (e.g., sensor data) through the physical input interface; for yet another example, at least one physical output interface may include a general purpose input / output (GPIO), a motor control interface, an Ethernet bus interface, a CAN bus interface, etc., so that the central processing unit 10 can send control signals to the execution object through the physical output interface; for yet another example, at least one physical communication interface may include a serial peripheral interface (SPI), a FlexRAY communication interface, etc., so that the central processing unit 10 can interact with other devices (e.g., other electronic control units, vehicle controllers, etc.).
[0045] It should be noted that at least one hardware resource 20 has multiple resource regions. A resource region is a subset of all resources of the hardware resource 20. For example, taking one of the hardware resources 20 as memory, multiple resource regions refer to multiple memory partitions. For instance, the memory partitions can be divided according to memory address into 0x0000 0000~0x0000 1FFF, 0x1000 0000~0x1FFF, etc. Multiple storage partitions, such as FFFF, correspond to multiple resource areas of the memory. For example, taking a hardware resource 20 as a physical input interface, the multiple channels of the physical input interface are divided into multiple groups according to a certain number (e.g., two), and each group of a certain number of channels corresponds to a resource area. Similarly, taking a hardware resource 20 as a physical output interface, the multiple channels of the physical output interface are divided into multiple groups according to a certain number (e.g., three), and each group of a certain number of channels corresponds to a resource area. Likewise, taking a hardware resource 20 as a physical communication interface, the multiple channels of the physical communication interface are divided into multiple groups according to a certain number (e.g., four), and each group of a certain number of channels corresponds to a resource area.
[0046] Bus 30 serves as a shared information channel between multiple central processing units 10 and multiple hardware resources 20 within the chip, facilitating data transmission and communication between the central processing units 10 and the hardware resources 20. Exemplarily, the structure of bus 30 can be, but is not limited to, star, linear, tree, ring, mesh, and fully connected types. Bus 30 can be, but is not limited to, one or more of the following: on-chip bus, advanced eXtensible interface, and advanced high-performance bus.
[0047] Each first isolation module 40 is connected between a central processing unit 10 and a bus 30. Each first isolation module 40 is configured to control the hardware resources 20 and / or resource areas of the corresponding hardware resources 20 that the corresponding central processing unit 10 can actively access. For example, in Figure 2, first isolation module a is connected between central processing unit a and bus 30. First isolation module a can control central processing unit a to actively access memory a or a portion of memory a's storage partitions. At the same time, first isolation module a can control central processing unit a to actively access physical input interface a, physical output interface a, physical communication interface a, or a portion of the channels of physical input interface a, physical output interface a, and physical communication interface a. First isolation module b is connected between central processing unit b and bus 30. First isolation module b can control central processing unit b to actively access memory b or a portion of memory b's storage partitions. First isolation module b can control central processing unit b to actively access memory b or a portion of memory b's storage partitions. At the same time, first isolation module b can control central processing unit b to actively access physical input interface b, physical output interface b, physical communication interface b, or a portion of the channels of physical input interface b, physical output interface b, and physical communication interface b.
[0048] Each second isolation module 50 is connected between a hardware resource 20 and the bus 30. Each second isolation module 50 is configured to control the legal access objects of the corresponding hardware resource 20 and / or the resource area of the hardware resource 20. For example, in Figure 2, second isolation module a1 is connected between memory a and the bus 30. Second isolation module a1 can control the legal access objects of memory a or a certain storage partition of memory a, including the central processing unit a; second isolation module a2 is connected between physical input interface a and the bus 30. Second isolation module a2 can control the legal access objects of physical input interface a or certain channels of physical input interface a, including the central processing unit a; second isolation module b1 is connected between memory b and the bus 30. Second isolation module b1 can control the legal access objects of memory b or a certain storage partition of memory b, including the central processing unit b; second isolation module b2 is connected between physical input interface b and the bus 30. Second isolation module b2 can control the legal access objects of physical input interface b or certain channels of physical input interface b, including the central processing unit b. The second isolation modules a3, a4, b3, and b4 are similar and will not be described in detail here.
[0049] As can be seen, this application utilizes the first isolation module 40 to control the hardware resources 20 that the corresponding central processing unit 10 can actively access, and utilizes the second isolation module 50 to control the legitimate access objects of the corresponding hardware resources 20. Through the first isolation module 40 and the second isolation module 50, multiple central processing units 10 and multiple hardware resources 20 can be divided into multiple control function areas within the same chip, thereby enabling each control function area to realize the function of an electronic control unit (such as window control, headlight control, engine control, etc.). Compared with the phenomenon that traditional electronic control unit chips can only realize a single function, this application is beneficial to reducing the number of electronic control units in automobiles, thereby avoiding the problems of increased automobile costs, increased communication wiring between electronic control units, and increased vehicle network load caused by the increase in the number of electronic control units.
[0050] In some embodiments of this application, at least one second isolation module 50 is configured to control the legitimate access objects of the resource areas of the corresponding hardware resource 20; wherein, under the control of multiple first isolation modules 40 and multiple second isolation modules 50, at least two central processing units 10 can access different resource areas of the same hardware resource 20.
[0051] For example, referring to Figure 3, which shows another schematic diagram of the chip in an embodiment of this application, the memory a has a storage area a1 and a storage area a2. The first isolation module a can control the central processing unit a to actively access the memory a, the first isolation module b can control the central processing unit b to actively access the memory a, the second isolation module a1 can control the legal access objects of storage area a1 to include the central processing unit a, and the second isolation module a1 can control the legal access objects of storage area a2 to include the central processing unit b. Therefore, under the control of the first isolation module a, the first isolation module b, and the second isolation module a2, the central processing unit a and the central processing unit b can respectively access the storage area a1 and the storage area a2 of the memory a. Similarly, under the control of the first isolation module a, the first isolation module b, and the second isolation module a2, the central processing unit a and the central processing unit b can respectively access the input channel a1 and the input channel a2 of the physical input interface a.
[0052] As can be seen, in the above embodiments, the multiple hardware resources 20 only include a single memory and a physical input interface. However, the multiple storage areas of the single memory are allocated to different processors under the control of the second isolation module 50, and the multiple channels of the single physical input interface are allocated to different processors under the control of the second isolation module 50. Therefore, under the control of the multiple first isolation modules 40 and the multiple second isolation modules 50, the multiple central processing units 10 can also be divided into multiple control function areas with a single memory and a single physical input interface. Thus, while reducing the number of electronic control units in the car, the number of chip hardware resources 20 and the number of second isolation modules 50 can be further reduced, ultimately achieving the goal of reducing chip area and manufacturing cost.
[0053] In some embodiments of this application, each second isolation module 50 is configured to control the legitimate access objects of the resource area of the corresponding hardware resource 20; wherein, under the control of multiple first isolation modules 40 and multiple second isolation modules 50, multiple central processing units 10 can access different resource areas of the same hardware resource 20.
[0054] For example, referring to Figure 4, which shows another schematic diagram of the chip in an embodiment of this application, the plurality of central processing units 10 include central processing units a to n, memory a has storage areas a1, storage areas a2... storage areas an, physical input interface a has input channels a1, input channels a2... input channels an, physical output interface a has output channels a1, output channels a2... output channels an, and physical communication interface a has communication channels a1, communication channels a2... communication channels an.
[0055] The second isolation module a1 can control the access of storage areas a1, a2, ..., an to central processing units a through n. The second isolation module a2 allocates input channels a1, a2, ..., an to central processing units a through n. The second isolation module a3 allocates output channels a1, a2, ..., an to central processing units a through n. The second isolation module a4 allocates communication channels a1, a2, ..., an to central processing units a through n. Therefore, under the control of multiple first isolation modules 40 and multiple second isolation modules 50, central processing units a through n can access different resource areas of memory a, physical input interface a, physical output interface a, and physical communication interface a respectively. This allows for the division of multiple control functional areas with a single memory, a single physical input interface, a single physical output interface, and a single physical communication interface, ultimately contributing to further reductions in chip area and manufacturing costs.
[0056] In some embodiments of this application, at least two central processing units 10 independently run different software programs, and the hardware resources 20 accessible to at least two central processing units 10 and / or the resource regions of the hardware resources 20 are different from each other.
[0057] For example, referring to Figure 5, Figure 5 shows a schematic diagram of the functional area division of a chip in an embodiment of this application. After the chip is powered on and initialized, the domain management machine (Domain Management) The Distributed Machine (DMM) allocates memory a, physical input interface a, physical output interface a, and physical communication interface a to central processing unit a, and allocates memory b, physical input interface b, physical output interface b, and physical communication interface b to central processing unit b, by configuring first isolation module a, first isolation module b, second isolation modules a1 to a4, and second isolation modules b1 to b4. This allows central processing unit a and central processing unit b to run different domain applications. When central processing unit a and central processing unit b are running different domain applications, central processing unit a can only use the allocated memory a, physical input interface a, physical output interface a, and physical communication interface a, while central processing unit b can only use the allocated memory b, physical input interface b, physical output interface b, and physical communication interface b. This ultimately forms functional area a and functional area b, which can implement different control functions. For example, functional area a can implement window control function, and functional area b can implement door control function. Ultimately, this achieves the goal of dividing multiple central processing units 10 and multiple hardware resources 20 into multiple control functional areas within the same chip.
[0058] For example, referring to Figure 6, which shows another functional area division diagram of the chip in this embodiment, after the chip is powered on and initialized, the domain management machine configures the first isolation module a, the first isolation module b, the second isolation modules a1 to a4, and the second isolation modules b3 to b4 to allocate the storage area a1 of the memory a, the input channel a1 of the physical input interface a, the physical output interface a, and the physical communication interface a to the central processing unit a, and allocates the storage area a2 of the memory a, the input channel a2 of the physical input interface a, the physical output interface b, and the physical communication interface b to the central processing unit b, so that the central processing unit a and the central processing unit b can achieve the same result. b runs different domain applications respectively. When CPU a and CPU b run different domain applications, CPU a can only use the storage area a1 of the allocated memory a, the input channel a1 of the physical input interface a, the physical output interface a, and the physical communication interface a, while CPU b can only use the storage area a2 of the allocated memory a, the input channel a2 of the physical input interface a, the physical output interface b, and the physical communication interface b. This ultimately forms functional area a and functional area b, thus achieving the goal of dividing multiple CPUs 10 and multiple hardware resources 20 into multiple control functional areas within the same chip.
[0059] In some embodiments of this application, at least one central processing unit 10 runs a first software program in a first time period and a second software program in a second time period; and the hardware resources 20 and / or the resource regions of the hardware resources 20 accessible to the at least one central processing unit 10 in the first time period and the second time period are different.
[0060] For example, referring to Figure 7 (only a portion of the central processing unit 10 and hardware components are shown), Figure 7 shows another schematic diagram of the chip in an embodiment of this application. After the chip is powered on and initialized, the domain management machine, by configuring the first isolation module a, the first isolation module b, the second isolation modules a1 to a4, and the second isolation modules b1 to b4, allocates the memory a, physical input interface a, physical output interface a, and physical communication interface a to the central processing unit a in the first time period, and allocates the memory b, physical input interface b, physical output interface b, and physical communication interface b to the central processing unit a in the second time period. This allows the central processing unit a to run a first software program in the first time period and a second software program in the second time period, ultimately forming a functional area a corresponding to the first time period and a functional area b corresponding to the second time period. This allows the central processing unit a to be divided into two functional areas a and b, achieving the purpose of time-division multiplexing of the central processing unit a by the two functional areas a and b.
[0061] In some embodiments of this application, at least two central processing units 10 run a first software program in a first time period and a second software program in a second time period; and at least two central processing units 10 have access to the same hardware resources 20 and / or the resource areas of the hardware resources 20 in the first or second time period.
[0062] For example, referring to Figure 8, which shows another functional area division diagram of the chip in this embodiment, after the chip is powered on and initialized, the domain management machine allocates memory a, physical input interface a, physical output interface a, and physical communication interface a to central processing unit a and central processing unit b in a first time period by configuring the first isolation module a, the first isolation module b, the second isolation modules a1 to a4, and the second isolation modules b1 to b4. This allows central processing unit a and central processing unit b to run a first software program (e.g., a computer program stored in memory a) in the first time period. In the second time period, memory b, physical input interface b, physical output interface b, and physical communication interface b are allocated to central processing unit a and central processing unit b. This allows central processing unit a and central processing unit b to run a second software program (e.g., a computer program stored in memory b) in the second time period. This ultimately forms functional area a corresponding to the first time period and functional area b corresponding to the second time period. Central processing unit a and central processing unit b are simultaneously time-division multiplexed to functional area a and functional area b, achieving the purpose of time-division multiplexing multiple processing cores in two functional areas a and functional area b.
[0063] It should be noted that the functional area division of the chip in Figures 5 to 8 above is only an exemplary embodiment and should not be construed as a limitation on the claims of this application. Those skilled in the art can adjust the functional area division according to actual needs in conjunction with the content of this application. For example, in the first time period, physical output interface a and physical output interface b can be allocated to central processing unit a simultaneously.
[0064] In some embodiments of this application, referring to FIG9, FIG9 shows another schematic diagram of the chip in an embodiment of this application, wherein the first isolation module 40 includes a first resource configuration unit 41 and a first access monitoring unit 42; the first resource configuration unit 41 is used to store the first legal access address of the corresponding central processing unit 10; the first access monitoring unit 42 is used to determine whether the access address corresponding to each access request of the central processing unit 10 is legal based on the first legal access address stored in the first resource configuration unit 41.
[0065] Specifically, the first resource configuration unit 41 can store the first valid access address of the corresponding central processing unit 10. The first valid access address is the address of the hardware resource 20 that the central processing unit 10 can access, such as the address space of the memory, or the physical channel of the physical input interface, physical output interface, physical communication interface, etc. For example, the first resource configuration unit 41 may include, but is not limited to, registers, non-volatile memory, etc., to store the first valid access address of the central processing unit 10.
[0066] The first access monitoring unit 42 can determine whether the access address corresponding to each access request of the central processing unit 10 is valid based on the first valid access address stored in the first resource configuration unit 41. For example, in Figure 9, the storage area a1 of memory a is the first valid access address of the central processing unit a. When the central processing unit a sends a data read / write request to the storage area b2 of memory a, the first access monitoring unit a determines that the data read / write request is an illegal access and reports the exception. In the end, the purpose of controlling the corresponding hardware resources 20 and / or resource areas of hardware resources 20 that the central processing unit 10 can actively access through the first isolation module 40 is achieved.
[0067] In some embodiments of this application, referring to FIG10, FIG10 shows another schematic diagram of the chip in an embodiment of this application, wherein the second isolation module 50 includes a second resource configuration unit 51 and a second access monitoring unit 52; the second resource configuration unit 51 is used to store the corresponding hardware resources and / or the legal access codes that are allowed to be accessed for each resource area of the hardware resources; the second access monitoring unit 52 is used to determine whether each access request transmitted via the bus 30 is legal based on the legal access codes stored in the second resource configuration unit 51.
[0068] Specifically, the second resource configuration unit 51 can store the corresponding hardware resources and / or the legal access codes that are allowed to be accessed for each resource area of the hardware resources. The legal access codes are the codes that are allowed to be accessed by the hardware resources 20. For example, the legal access codes may be, but are not limited to, the unique virtual machine ID (VMID) corresponding to each functional area, the unique thread ID (threadID) corresponding to the virtual machine, the CPU ID (coreID) of the virtual machine or thread running on the corresponding CPU 10, or the direct memory access ID (masterID) of the direct memory access controller (DMA) started by the virtual machine or thread, etc.
[0069] The second access monitoring unit 52 can determine whether each access request transmitted via the bus 30 is legitimate based on the legitimate access codes stored in the second resource configuration unit 51. For example, in Figure 10, the second access monitoring unit a1 identifies fields such as virtual machine ID, thread ID, coreID, and masterID based on the access attribute control fields on the bus 30. By comparing the legitimate access codes of the second resource configuration unit a1, if it is found that the access originates from the central processing unit b, the access is determined to be illegal and an exception is reported. Ultimately, this achieves the purpose of controlling the legitimate access objects of the corresponding hardware resource 20 and / or the resource area of the hardware resource 20 through the second isolation module 50.
[0070] As an example, taking a memory with an address space (0x0000 0000~0xFFFF FFFF, a total of 4G space) as an example, the following shows an allocation diagram of the second resource allocation unit 51 in an embodiment of this application:
[0071] As can be seen from Figure 1, the legal access codes corresponding to the address space 0x0000 0000~0x0000 1FFF are VMID 0, coreID 0 and 1, and masterID 0, 1, 2 and 3. The legal access codes corresponding to the address space 0x1000 0000~0x1FFF FFFF are VMID 1, coreID 1, masterID 1, 2 and 3. And so on, ultimately enabling the second access monitoring unit 52 to determine whether each access request transmitted via bus 30 is legal based on the legal access codes stored in the second resource configuration unit 51.
[0072] In some embodiments of this application, referring to FIG11, FIG11 shows another schematic diagram of a chip in an embodiment of this application, wherein the chip further includes a hardware acceleration module 60 and a third isolation module 70, the third isolation module 70 being connected between the hardware acceleration module 60 and the bus 30; the third isolation module 70 is configured to control the legitimate access objects of the hardware acceleration module 60.
[0073] It should be noted that the hardware acceleration module 60 can improve the system's data processing capabilities to support complex data processing algorithms. For example, the hardware acceleration module 60 can be, but is not limited to, a DSP (Digital Signal Processor) system or a small MCU system. Taking a DSP system as an example, after the analog-to-digital converter acquires a signal, the digital signal converted by the analog-to-digital converter is processed by the DSP system, and the processed result is stored in local storage or system storage. Meanwhile, since the third isolation module 70 can control the legitimate access objects of the hardware acceleration module 60, the hardware acceleration module 60 can be protected by the third isolation module 70, preventing unauthorized access by the central processing unit 10 that does not require hardware acceleration, thereby interrupting or affecting the hardware acceleration process of other legitimate central processing units 10.
[0074] In some embodiments of this application, referring to FIG11, the chip further includes a security module 80 and a fourth isolation module 90, wherein the fourth isolation module 90 is connected between the security module 80 and the bus 30; the fourth isolation module 90 is configured to control the legitimate access objects of the security module 80.
[0075] It should be noted that the security module 80 has a hardware cryptographic algorithm engine that supports encryption algorithms such as symmetric cryptography, asymmetric cryptography, and hash algorithms. This cryptographic algorithm engine is directly connected to the main system's bus 30, thus ensuring the security of data transmission and storage. Simultaneously, since the fourth isolation module 90 can control the legitimate access objects of the security module 80, the hardware acceleration module 60 can be protected by the fourth isolation module 90, thereby preventing unauthorized access to the security module 80.
[0076] In some embodiments of this application, referring to FIG11, the chip further includes a DMA controller 100 and a fifth isolation module 110. The fifth isolation module 110 is connected between the DMA controller 100 and the bus 30. The fifth isolation module 110 is configured to control the hardware resources 20 and / or the resource areas of the hardware resources 20 that the DMA controller 100 can actively access.
[0077] It should be noted that the DMA (Direct Memory Access) controller 100 is a controller that can directly control the exchange of data information between I / O devices and memory without the intervention of the central processing unit 10. Since the fifth isolation module 110 can control the hardware resources and / or resource areas of the hardware resources that the DMA controller 100 can actively access, for example, the fifth isolation module 110 can control the memory a that the DMA controller 100 can actively access, but cannot actively access the memory b, the fifth isolation module 110 can also prevent the DMA controller 100 from illegally accessing the corresponding hardware resources.
[0078] As an example, referring to FIG12, FIG12 shows another schematic diagram of the chip in an embodiment of the present application, wherein the hardware acceleration module 60 includes a heterogeneous processor, a hardware acceleration unit, an eFPGA, a local bus, and a storage unit. The third isolation module 70 is connected between the local bus and the bus 30, thereby realizing the protection of the hardware acceleration module 60. The security module 80 includes a hardware encryption algorithm engine, an inter-core access unit, a local bus, a security processor, a storage unit, etc. The fourth isolation module 90 is connected between the hardware encryption algorithm engine, the inter-core access unit, and the bus 30, thereby realizing the isolation protection of the security module 80.
[0079] It should be noted that the above description of the chip is intended to clearly illustrate the implementation and verification process of this application. Those skilled in the art can make equivalent modifications or further designs under the guidance of this application. For example, referring to Figure 13, which shows another schematic diagram of the chip in an embodiment of this application, the chip may also include a calibration module. The calibration module can calibrate various parameters of the chip before it leaves the factory, thereby ensuring the accuracy of the chip parameters. Simultaneously, since the sixth isolation module is connected between the calibration module and the bus 30, the sixth isolation module can achieve isolation protection for the calibration module, preventing unauthorized access to the calibration module.
[0080] To better implement the chip in the embodiments of this application, based on the chip in this application, this application also provides a chip startup method. The chip startup method uses the chip as described in any of the above embodiments. Referring to FIG14, FIG14 shows a schematic flowchart of a chip startup method in an embodiment of this application, wherein the chip startup method includes:
[0081] Step S1401: In response to system power-on configuration, each first isolation module 40 and each second isolation module 50 are configured such that each first isolation module 40 controls the hardware resources and / or resource areas of the corresponding central processing unit 10 that can be actively accessed, and each second isolation module 40 controls the legal access objects of the corresponding hardware resource 20 and / or resource areas of the hardware resource 20.
[0082] Step S1402: Control each central processing unit 10 to load a program. During program execution, each central processing unit 10 accesses the corresponding hardware resource 20 under the control of the first isolation module 40 and the second isolation module 50.
[0083] Since the chip startup method of this application uses the chip of any of the above embodiments, after the chip is started, each central processing unit 10 can load different control programs and realize the functions of multiple traditional electronic control units (such as window control, headlight control, engine control, etc.) under the control of multiple first isolation modules 40 and multiple second isolation modules 50. Compared with the phenomenon that the chip of traditional electronic control unit can only realize a single function, this application is beneficial to reducing the number of electronic control units in the car, thereby avoiding the problems of increased car cost, increased communication wiring between electronic control units and increased vehicle network load caused by the increase in the number of electronic control units.
[0084] To better implement the chips in the embodiments of this application, this application also provides a controller based on the chips in the embodiments described above. The controller includes the chips as described in any of the above embodiments. For example, taking the application of the controller in the automotive field, the controller of this application can have control functions for any number of components such as an engine controller (ECU), transmission controller (TCU), brake controller (BCM), air conditioning controller (HVAC), body controller (BCM), airbag controller (SBC), drive controller (DCU), and driver assistance system controller. It is understood that the controller of this application can also be applied to other fields, such as drones, industrial robots, and robotic vacuum cleaners. Since the automotive controller of this application includes the chips of the above embodiments, it possesses all the beneficial effects of the chips in the above embodiments, which will not be repeated here.
[0085] To better implement the controller in the embodiments of this application, this application also provides a terminal device based on the controller in the embodiments described above. The terminal device may, for example, be, but is not limited to, a car, a drone, an industrial robot, a robotic vacuum cleaner, etc. The car may be, but is not limited to, an internal combustion engine car, an electric car, a natural gas car, etc. Internal combustion engine cars include gasoline cars and diesel cars; electric cars include pure electric cars and hybrid electric cars; natural gas cars include compressed natural gas (CNG) cars, liquefied natural gas (LNG) cars, and liquefied petroleum gas (LPG) cars, etc.
[0086] The above are merely preferred embodiments of this application and are not intended to limit this application in any way. Although this application has disclosed preferred embodiments as above, it is not intended to limit this application. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the technical solution of this application. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of this application without departing from the scope of the technical solution of this application shall still fall within the scope of the technical solution of this application.
Claims
1. A chip, characterized in that, include: At least one central processing unit; Multiple hardware resources, including at least one memory, at least one physical input interface, at least one physical output interface or at least one physical communication interface, and at least one of the hardware resources having multiple resource areas; A bus, the bus connecting the central processing unit and the hardware resources, so that the central processing unit can access the hardware resources through the bus; At least one first isolation module and a plurality of second isolation modules, each first isolation module being connected between a central processing unit and the bus, and each second isolation module being connected between a hardware resource and the bus; Each of the first isolation modules is configured to control the hardware resources and / or resource areas of the corresponding central processing unit that can be actively accessed, and each of the second isolation modules is configured to control the legitimate access objects of the corresponding hardware resources and / or resource areas of the hardware resources.
2. The chip as described in claim 1, characterized in that, At least one of the second isolation modules is configured to control the legitimate access objects of the resource area corresponding to the hardware resource; Under the control of multiple first isolation modules and multiple second isolation modules, at least two central processing units can access different resource regions of the same hardware resource.
3. The chip as described in claim 2, characterized in that, Each of the hardware resources has multiple resource regions, and each of the second isolation modules is configured to control the legal access objects of the resource regions of the corresponding hardware resource; Under the control of multiple first isolation modules and multiple second isolation modules, multiple central processing units can access different resource regions of the same hardware resource.
4. The chip as described in claim 2 or 3, characterized in that, At least two of the central processing units (CPUs) independently run different software programs, and the hardware resources accessible to at least two of the CPUs and / or the resource regions of the hardware resources are different from each other.
5. The chip as described in claim 2 or 3, characterized in that, At least one of the central processing units runs a first software program in a first time period and a second software program in a second time period; Furthermore, at least one of the central processing units has different access to the hardware resources and / or the resource regions of the hardware resources in the first time period and the second time period.
6. The chip as described in claim 2 or 3, characterized in that, At least two of the central processing units run a first software program in a first time period and a second software program in a second time period; Furthermore, at least two of the central processing units have access to the same hardware resources during the first time period or the second time period, and / or the resource areas of the hardware resources are the same.
7. The chip as described in claim 1, characterized in that, The first isolation module includes a first resource configuration unit and a first access monitoring unit; The first resource configuration unit is used to store the first legal access address of the corresponding central processing unit; The first access monitoring unit is used to determine whether the access address corresponding to each access request of the central processing unit is valid based on the first valid access address stored in the first resource configuration unit.
8. The chip as described in claim 1, characterized in that, The second isolation module includes a second resource configuration unit and a second access monitoring unit; The second resource configuration unit is used to store the corresponding hardware resource and / or the legal access codes that are allowed to be accessed for each resource area of the hardware resource; The second access monitoring unit is used to determine whether each access request transmitted via the bus is legitimate based on the legitimate access code stored in the second resource configuration unit.
9. The chip as described in claim 8, characterized in that, The valid access code includes at least one of the following: virtual machine ID, thread ID, central processing unit ID, or direct memory access ID.
10. The chip as described in claim 1, characterized in that, The chip also includes a hardware acceleration module and a third isolation module, wherein the third isolation module is connected between the hardware acceleration module and the bus; The third isolation module is configured to control the legitimate access objects of the hardware acceleration module.
11. The chip as described in claim 1, characterized in that, The chip also includes a security module and a fourth isolation module, the fourth isolation module being connected between the security module and the bus; The fourth isolation module is configured to control the legitimate access objects of the security module.
12. The chip as described in claim 1, characterized in that, The chip also includes a DMA controller and a fifth isolation module; The fifth isolation module is connected between the DMA controller and the bus, and the fifth isolation module is configured to control the hardware resources and / or resource areas of the hardware resources that the DMA controller can actively access.
13. A chip boot method, characterized in that, include: In response to system power-on configuration, each first isolation module and each second isolation module are configured such that each first isolation module controls the hardware resources and / or resource areas of the corresponding central processing unit that can be actively accessed, and each second isolation module controls the legal access objects of the corresponding hardware resources and / or resource areas of the hardware resources. Each central processing unit (CPU) is controlled to load a program, and during the program's execution, each CPU accesses corresponding hardware resources under the control of the first isolation module and the second isolation module.
14. A controller, characterized in that, Includes the chip as described in any one of claims 1 to 12.
15. A terminal device, characterized in that, Includes the controller as described in claim 14.
Citation Information
Patent Citations
Techniques for configuring processor to function as multiple, separate processors
CN112445611A
Domain control vehicle-mounted network communication architecture based on virtualization layer
CN114629773A
System on chip, construction method thereof and vehicle
CN116560830A
System and method of limiting access of processors to hardware resources
US20220035953A1
Multi-Partition, Multi-Domain System-on-Chip JTAG Debug Control Architecture and Method
US20240019494A1