Clock monitor message synchronization between main domain safety monitor and safety island
The synchronization mechanism for the safety island and main domain safety monitor addresses the issue of unsynchronized message handling, ensuring reliable communication and preventing system crashes, thus maintaining ASIL-D integrity in SoC operations.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- QUALCOMM INC
- Filing Date
- 2024-10-28
- Publication Date
- 2026-05-07
AI Technical Summary
There is a lack of effective message synchronization between a main domain safety monitor and a safety island, leading to potential system crashes due to the discard of clock monitor messages when the safety island mailbox is not ready, which compromises the safety requirements of system-on-a-chip (SoC) operations, particularly in automotive systems rated for high ASIL-D integrity levels.
Implementing a synchronization mechanism that includes initiating a safety island booting procedure, determining the readiness of the safety island mailbox, waiting for it to be ready by using the iofunc_attr_unlock API and sm_block_for_sail_mb function, and transmitting the clock monitor message only when the mailbox is ready, thereby ensuring synchronized communication.
This approach prevents system crashes by ensuring reliable message synchronization between the main domain safety monitor and the safety island, maintaining the integrity of SoC operations and adhering to ASIL-D safety standards.
Smart Images

Figure CN2024127616_07052026_PF_FP_ABST
Abstract
Description
CLOCK MONITOR MESSAGE SYNCHRONIZATION BETWEEN MAIN DOMAIN SAFETY MONITOR AND SAFETY ISLAND
[0001] FIELD OF THE DISCLOSURE
[0002] Aspects of the present disclosure generally relate to computing devices, and more particularly to a method to improve clock monitor message synchronization between a main domain safety monitor and a safety island.BACKGROUND
[0003] Functional safety is an aspect of computer systems design, particularly in automotive, aerospace, industrial automation, and medical device contexts. Functional safety includes implementing mechanisms to increase the likelihood that a system behaves predictably and safely in the presence of faults. Functional safety standards provide frameworks for the development, validation, and verification of safety systems. These standards include rigorous risk assessment, hazard analysis, and the use of redundant and diverse design techniques to mitigate potential hazards. Strategies for implementing functional safety involve built-in self-tests (BISTs) , safety integrity levels (SILs) , fail-safe and fail-operational modes, architectures including safety islands, and comprehensive safety case documentation to demonstrate that safety specifications are satisfied throughout the product lifecycle.
[0004] In the automotive industry, vehicles are rated via an Automotive Safety Integrity Level (ASIL) rating system. ASIL ratings, ranging from ASIL-Ato ASIL-D, categorize the severity of potential hazards and the rigor specified to mitigate the hazards. ASIL-Arepresents the lowest safety integrity level and is awarded to systems implementing fewer safety measures, while ASIL-D signifies the highest safety integrity level and is awarded to systems implementing more stringent safety protocols. These ratings guide automotive development, validation, and verification processes to increase the likelihood that automotive systems can operate safely, even in the presence of faults. The ASIL framework encompasses risk assessment, hazard analysis, and the implementation of redundant and diverse safety mechanisms to prevent or mitigate failures. Deploying safety islands, which may monitor clock frequencies for subsystems operating outside the safety island, is one technique for ensuring safety specifications are satisfied.SUMMARY
[0005] In aspects of the present disclosure, a method for synchronizing communications between a safety island and a main domain safety monitor includes initiating a safety island booting procedure including loading data stored in memory outside the safety island. The method also includes determining whether a safety island mailbox is ready, after initiating the booting procedure. The method further includes waiting for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready. The method still further includes transmitting a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0006] Other aspects of the present disclosure are directed to an apparatus. The apparatus has one or more memories and one or more processors coupled to the memory. The processor (s) is configured to initiate a safety island booting procedure including loading data stored in memory outside the safety island. The processor (s) is also further configured to determine whether a safety island mailbox is ready, after initiating the booting procedure. The processor (s) is further configured to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready. The processor (s) is still further configured to transmit a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0007] In other aspects of the present disclosure, a non-transitory computer-readable medium with program code recorded thereon is disclosed. The program code is executed by a processor and includes program code to initiate a safety island booting procedure including loading data stored in memory outside the safety island. The program code also includes program code to determine whether a safety island mailbox is ready, after initiating the booting procedure. The program code further includes program code to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready. The program code still further includes program code to transmit a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0008] Additional features and advantages of the disclosure will be described below. It should be appreciated by those skilled in the art that this disclosure may be readily utilized as a basis for modifying or designing other structures for carrying out the same purposes of the present disclosure. It should also be realized by those skilled in the art that such equivalent constructions do not depart from the teachings of the disclosure as set forth in the appended claims. The novel features, which are believed to be characteristic of the disclosure, both as to its organization and method of operation, together with further objects and advantages, will be better understood from the following description when considered in connection with the accompanying figures. It is to be expressly understood, however, that each of the figures is provided for the purpose of illustration and description only and is not intended as a definition of the limits of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The features, nature, and advantages of the present disclosure will become more apparent from the detailed description set forth below when taken in conjunction with the drawings in which like reference characters identify correspondingly throughout.
[0010] FIGURE 1 illustrates an example implementation of a system-on-a-chip (SoC) , including a safety island, in accordance with various aspects of the present disclosure.
[0011] FIGURE 2 illustrates an example of an automobile including systems that may be adapted, configured, or operated, in accordance with various aspects of the present disclosure.
[0012] FIGURE 3 is a block diagram illustrating an Automotive Safety Integrity Level (ASIL) data path.
[0013] FIGURE 4 is a timing diagram illustrating static random access memory (SRAM) boot up processing and safety island clock monitoring.
[0014] FIGURE 5 is a timing diagram illustrating double data rate (DDR) synchronous dynamic random access memory (SDRAM) boot up processing and resulting safety island clock monitoring issues.
[0015] FIGURE 6 is a timing diagram illustrating double data rate (DDR) synchronous dynamic random access memory (SDRAM) boot up processing and safety island clock monitoring, in accordance with various aspects of the present disclosure.
[0016] FIGURE 7 is a flow chart illustrating an example process performed, for example, by a computing device, in accordance with various aspects of the present disclosure.
[0017] FIGURE 8 is a block diagram illustrating a design workstation used for circuit, layout, and logic design of message synchronization components, in accordance with various aspects of the present disclosure.DETAILED DESCRIPTION
[0018] The detailed description set forth below, in connection with the appended drawings, is intended as a description of various configurations and is not intended to represent the only configurations in which the concepts described may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of the various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form in order to avoid obscuring such concepts.
[0019] Based on the teachings, one skilled in the art should appreciate that the scope of the disclosure is intended to cover any aspect of the disclosure, whether implemented independently of or combined with any other aspect of the disclosure. For example, an apparatus may be implemented or a method may be practiced using any number of the aspects set forth. In addition, the scope of the disclosure is intended to cover such an apparatus or method practiced using other structure, functionality, or structure and functionality in addition to or other than the various aspects of the disclosure set forth. It should be understood that any aspect of the disclosure disclosed may be embodied by one or more elements of a claim.
[0020] The word “exemplary” is used to mean “serving as an example, instance, or illustration. ” Any aspect described as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects.
[0021] Although particular aspects are described, many variations and permutations of these aspects fall within the scope of the disclosure. Although some benefits and advantages of the preferred aspects are mentioned, the scope of the disclosure is not intended to be limited to particular benefits, uses or objectives. Rather, aspects of the disclosure are intended to be broadly applicable to different technologies, system configurations, networks, and protocols, some of which are illustrated by way of example in the figures and in the following description of the preferred aspects. The detailed description and drawings are merely illustrative of the disclosure rather than limiting, the scope of the disclosure being defined by the appended claims and equivalents thereof.
[0022] Several aspects of functional safety management will now be presented with reference to various apparatuses and techniques. These apparatuses and techniques will be described in the following detailed description and illustrated in the accompanying drawings by various blocks, modules, components, circuits, steps, processes, algorithms, and / or the like (collectively referred to as “elements” ) . These elements may be implemented using hardware, software, or combinations thereof. Whether such elements are implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system.
[0023] As described, automotive systems executing safety critical applications or functions are rated via an Automotive Safety Integrity Level (ASIL) rating system. The ASILs may be defined in a specific safety standard, such as international organization for standardization (ISO) 26262. For example, the ASILs may provide a risk classification scheme for certain electrical and electronic systems of road vehicles. ISO 26262 provides four ASILs, including ASIL-A, ASIL-B, ASIL-C, and ASIL-D. ASIL-D is the highest classification and corresponds to the highest level of safety measures for avoiding an unreasonable residual risk, and ASIL-Ais the lowest classification and corresponds to the lowest level of safety measures. ASIL ratings, ranging from ASIL-A(lowest) to ASIL-D (highest) , categorize the severity of potential hazards and the rigor specified to mitigate the hazards.
[0024] Development of advanced driver assistance systems (ADASs) and automated driving systems (ADSs) , as well as associated safety and mission critical applications in the automotive industry, have prompted many safety critical applications to specify ASIL-D safety ratings. As a result, vehicle and chip manufacturers have developed conventional approaches to develop and manufacture ASIL-D hardware. In one approach, a system-on-a-chip (SoC) and memory elements include several components along an inline data path. The components are each individually designed and manufactured to satisfy ASIL specifications (e.g., ASIL-D or ASIL-C specifications) , enabling the entire data path to reach ASIL-D or ASIL-C status.
[0025] Implementing safety islands is one technique for ensuring safety specifications are satisfied. A safety island may be an ASIL-D certified region, whereas other components of an SoC may be lower level certified (e.g., ASIL-B) . The safety island may include isolated memory, peripherals, and processors to ensure a higher level of reliability. Main domain subsystems (e.g., a graphics processing unit (GPU) , camera, and / or temperature sensor) may employ components in the safety island to improve the reliability of the subsystems. For example, a subsystem may rely on components of the safety island to monitor a clock frequency in the subsystem to avoid jitter, which may cause a system crash.
[0026] The size of static random access memory (SRAM) in the safety island is small. In some cases, to load a safety island boot image, services running in kernel mode may need more memory than an amount of memory available in the SRAM. Therefore, the safety island may boot from main domain (MD) double data rate (DDR) memory to overcome the SRAM limitation. In the case of safety island boot image loading from DDR memory, the safety island hypervisor (e.g., virtual machine monitor) waits for the DDR memory to be ready before loading the safety island boot image. The wait time for loading from DDR memory may be long (e.g., over 100 milliseconds (ms) ) , introducing unwanted latency, for example, while waiting for a safety island mailbox to be created.
[0027] In order to enlist the safety island to monitor a clock frequency for a subsystem, a main domain safety monitor (SM) assumes the safety island mailbox will be ready before sending a first clock monitor message to the safety domain mailbox. The safety monitor directly discards the message without waiting or resending when the mailbox is not ready. Thus, there is a lack of control for message synchronization between the main domain safety monitor and the safety island. Moreover, a message discard causes the subsystem to fail to enable the clock monitor thereby compromising the safety requirements of the SoC. Some subsystems may trigger an SoC crash as a fail-safe reaction.
[0028] According to aspects of the present disclosure, the safety monitor may call two functions to enable synchronization with the safety island. The safety monitor may call an iofunc_attr_unlock application program interface (API) and a sm_block_for_sail_mb block function to wait for the safety island mailbox to be ready. The two functions control clock monitor message synchronization between the main domain safety monitor and the safety island.
[0029] The iofunc_attr_unlock API unlocks other safety monitor resource manager threads to process messages from other subsystems while awaiting the safety island mailbox to be created. The sm_block_for_sail_mb function periodically checks the mailbox. More specifically, the sm_block_for_sail_mb function creates a timer, and sets the timer to periodically trigger a timer pulse (e.g., every 25 ms) until the main domain receives a safety island mailbox ready notification interrupt.
[0030] FIGURE 1 illustrates an example implementation of a system-on-a-chip (SoC) 100, which may include a central processing unit (CPU) 102 or a multi-core CPU configured for message synchronization operations. Variables (e.g., neural signals and synaptic weights) , system parameters associated with a computational device (e.g., neural network with weights) , delays, frequency bin information, and task information may be stored in a memory block associated with a neural processing unit (NPU) 108, in a memory block associated with a CPU 102, in a memory block associated with a graphics processing unit (GPU) 104, in a memory block associated with a digital signal processor (DSP) 106, in a memory block 118, or may be distributed across multiple blocks. Instructions executed at the CPU 102 may be loaded from a program memory associated with the CPU 102 or may be loaded from a memory block 118.
[0031] The SoC 100 may also include additional processing blocks tailored to specific functions, such as a GPU 104, a DSP 106, a connectivity block 110, which may include fifth generation (5G) connectivity, fourth generation long term evolution (4G LTE) connectivity, Wi-Fi connectivity, USB connectivity, Bluetooth connectivity, and the like, and a multimedia processor 112 that may, for example, detect and recognize gestures. In one implementation, the NPU 108 is implemented in the CPU 102, DSP 106, and / or GPU 104. The SoC 100 may also include a sensor processor 114, image signal processors (ISPs) 116, and / or navigation module 120, which may include a global positioning system.
[0032] The SoC 100 may also include a safety island 130. Although shown as part of the SoC 100, the safety island 130 may be a separate SoC. In some aspects, the safety island is ASIL-D certified, whereas other components of the SoC 100 are ASIL-B certified. The safety island 130 may include enhanced error management support, as well as isolated memory, peripherals, and processors. The safety island 130 may work independently from or in lockstep with the rest of the SoC 100.
[0033] The SoC 100 may be based on any architecture, such as a complex instruction set (CISC) architecture, an ARM, RISC-V (RISC-five) , or any reduced instruction set computing (RISC) architecture. In aspects of the present disclosure, the instructions loaded into the CPU 102 may include code to initiate a safety island booting procedure including loading data stored in memory outside the safety island. In aspects of the present disclosure, the instructions loaded into the CPU 102 may include code to determine whether a safety island mailbox is ready, after initiating the booting procedure. In aspects of the present disclosure, the instructions loaded into the CPU 102 may include code to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready. In aspects of the present disclosure, the instructions loaded into the CPU 102 may include code to transmit a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0034] According to aspects of the present disclosure, an apparatus includes a synchronization mechanism. The apparatus may include means for initiating, means for determining, means for waiting, means for transmitting, means for unlocking, means for checking, means for blocking, means for initializing, means for configuring, and means for receiving.
[0035] For example, the means for initiating, means for determining, means for waiting, means for transmitting, means for unlocking, means for checking, means for blocking, means for initializing, means for configuring, and means for receiving may be any of the CPU 102, GPU 104, DSP 106, NPU 108, safety island 130, central controller 220, CPU cluster 302, computation engines 308, main domain (MD) critical subsystem, MD safety monitor, mailbox interprocess communications resource manager, and / or SoC 100.
[0036] FIGURE 2 illustrates an example of an automobile including systems that may be adapted, configured, or operated in accordance with various aspects of this disclosure. The automobile 200 may be equipped with multiple imaging or sensing devices including, for example, cameras 202, 204, 206, 208, 212, 214, and sensors 216, 218. The automobile 200 may include sensors such as tire pressure or braking sensors as the sensors 216, 218. The automobile 200 may also include one or more antennas 210 for radio frequency reception, wireless communication and / or radio navigation using a position location system, such as a global positioning system (GPS) . A central controller 220 may be coupled to each of the cameras 202, 204, 206, 208, 212, 214, sensors 216, 218 and antennas 210. The central controller 220 may configure and manage automated systems and / or driver assistance systems. In some implementations, the central controller 220 may be configured to operate as an engine control unit that manages the operation and performance of the engine, motor, motors, or other power systems in the automobile 200. In some instances, the central controller 220 may include an SoC, such as the SoC 100.
[0037] Robust data communication links are specified to support the large number of cameras deployed within the automobile 200. In some examples, 20-30 cameras may be deployed to support automation and driver assistance systems. Each camera may be capable of generating data at a rate of between 1-10 gigabits per second (GBps) resulting in aggregate data rates of up to 300 GBps.
[0038] FIGURE 3 is a block diagram illustrating an automotive data path 300. As shown, the data path 300 includes a CPU cluster 302. Although a single CPU cluster 302 is depicted for ease of explanation, the present disclosure is not so limited. The CPU cluster 302 includes a set of CPU cores 304 that work concurrently or in parallel to perform computational tasks via workloads distributed across the set of CPU cores 304. The set of CPU cores 304 are respectively interconnected such that each core may perform a portion of a task. Portions of a task may be assigned to each core of the CPU cores 304 by a scheduler (not illustrated) hosted by the CPU cluster 302. The CPU cluster 302 is coupled to an SoC interconnect 306.
[0039] The SoC interconnect 306 links various upstream components, such as the CPU cluster 302 and cache (not illustrated) to various downstream components. Additionally, the SoC interconnect 306 facilitates on-chip communications and transaction handling between the upstream components and downstream components on the data path 300. The SoC interconnect 306 is coupled to computation engines 308. The computation engines 308 represent one or more logic structures on the data path 300 that are downstream from the SoC interconnect 306.
[0040] The computation engines 308 may include functionally complex, area intensive logic structures on the path to dynamic random access memory (DRAM) in an SoC. For example, the computation engines 308 may include compression engines, encryption engines, a last-level cache, and other computational or memory structures. Compression engines apply compression techniques to reduce the data footprint of data packets transmitted on the data path 300, thus reducing bandwidth specified to transmit the data packets. Encryption engines implement cryptographic techniques to encrypt data packets. A last-level cache serves as high-capacity, low-latency memory storage for upstream components such as the CPU cluster 302. The computation engines 308 are coupled to a memory controller 310.
[0041] The memory controller 310 manages data flow between DRAM 312 and upstream components on the data path 300, such as the CPU cluster 302. The memory controller 310 coordinates memory access requests from the upstream components to reduce memory bandwidth and latency. The DRAM 312, coupled to the memory controller 310, serves as the primary volatile storage for the data path 300, providing memory space for stored information. While smaller data packets and data packets specifying low access latency may be stored in a cache within the data path 300, larger data packets and data packets specifying higher access latency may instead by stored in the DRAM 312 by the memory controller 310.
[0042] In FIGURE 3, each of the components in the data path 300 may be rated as conforming to the highest safety integrity level, e.g., ASIL-D. For instance, ASIL-D may specify strict path protection across complex structures, such as the computation engines 308, memory controller 310, and DRAM 312. Similarly, other safety levels, such as ASIL-C, may also be associated with components in the data path 300, such as subsystems in the main domain.
[0043] Main domain subsystems (e.g., a graphics processing unit (GPU) , camera, and / or temperature sensor) may employ components in a safety island to improve the reliability of the subsystems. For example, a subsystem may rely on components of the safety island to monitor a clock frequency in the subsystem to avoid jitter, which may cause a system crash. It would be desirable to ensure message synchronization between the safety island and main domain subsystems in order to reduce or prevent system crashes.
[0044] The size of static random access memory (SRAM) in the safety island is small. In some cases, to load a safety island boot image, services running in kernel mode may need more memory than an amount of memory available in the SRAM. Therefore, the safety island may boot from main domain (MD) double data rate (DDR) memory to overcome the SRAM limitation. For a DDR boot, the service manually enables an imageLoadToDDR option and can then custom configure the DDR address and size desired to access the memory that is outside the safety island.
[0045] In the case of safety island boot image loading from DDR memory, the safety island hypervisor (e.g., virtual machine monitor) waits for the DDR memory to be ready before loading the safety island boot image. The safety island boot image initializes the safety island and enables execution of the safety island functions. The wait time for loading from DDR memory may be long (e.g., over 100 millisecond) , introducing unwanted latency. After the DDR memory is ready, the safety island boot image is loaded and then the safety island creates and initializes a safety island mailbox.
[0046] Once the mailbox is created, the safety island initiates a handshake mechanism with a main domain safety monitor to establish communications. After the above steps are performed, the main domain safety monitor can transmit the clock monitor requests from subsystems to the safety island via the mailbox. The latency caused by image loading from DDR memory affects the main domain safety monitor’s ability to send the clock monitor request to the safety island.
[0047] In order to enlist the safety island to monitor a clock frequency for a subsystem, a main domain safety monitor (SM) assumes the safety island mailbox will be ready before sending a first clock monitor message to the safety domain mailbox. The safety monitor directly discards the message without waiting or resending when the mailbox is not ready. Thus, there is a lack of control for message synchronization between the main domain safety monitor and the safety island. Moreover, a message discard causes the subsystem to fail to enable the clock monitor thereby compromising the safety requirements of the SoC. Some subsystems may trigger SoC crash as a fail-safe reaction.
[0048] FIGURE 4 is a timing diagram illustrating static random access memory (SRAM) boot up processing and safety island clock monitoring. As seen in the example of FIGURE 4, at time 1, a safety island (SAIL) loads a safety island boot image in an executable and linkable format (ELF) from SRAM. At times 2 and 3, a mailbox interprocess communication (IPC) resource manager (e.g., QCMI) provides access to the DDR memory for the safety island and transmits a DDR ready notification to the safety island. Once the DDR memory is ready, the safety island creates mailboxes, at time 6. In parallel, a main domain (MD) critical subsystem (e.g., a GPU) registers as a client of the MD safety monitor (SM) and receives a success or error indication, at times 4 and 5.
[0049] At time 7, the safety island informs the MD safety monitor that the mailbox is ready. At time 8, the MD critical subsystem transmits a clock monitor request to the MD safety monitor. At times 9 and 10, the MD safety monitor checks whether a mailbox is ready and transmits the clock monitor message to the safety island mailbox because the mailbox is ready. At times 11, 12, and 13, the safety island successfully enables the clock monitoring for the MD critical subsystem and returns an acknowledgment (ACK) message to the MD critical subsystem via the MD safety monitor. Because the safety monitor and the safety island are synchronized, the clock monitoring is successfully started.
[0050] FIGURE 5 is a timing diagram illustrating double data rate (DDR) synchronous dynamic random access memory (SDRAM) boot up processing and resulting safety island clock monitoring issues. As seen in the example of FIGURE 5, at time 1, the safety island (SAIL) waits for the DDR memory to be ready. At times 2 and 3, the QCMI provides access to the DDR memory for the safety island DDR memory and transmits a ready notification to the safety island. Once the DDR is ready, the safety island loads the safety island boot image (SAIL ELF) from the DDR memory, at time 6. In parallel, a main domain (MD) critical subsystem (e.g., a GPU) registers as a client of the main domain (MD) safety monitor (SM) and receives a success or error indication, at times 4 and 5.
[0051] At time 7, the MD critical subsystem transmits a clock monitor request to the MD safety monitor. At times 8 and 9, the MD safety monitor checks whether a mailbox is ready and returns an error message to the MD critical subsystem because the mailbox is not yet ready. At time 10, the MD critical subsystem waits for an ACK timeout, and aborts the process.
[0052] The safety island creates the mailbox, at time 11, and informs the MD safety monitor, at time 12. A critical subsystem crash causes the kernel to crash, at time 13, because the mailbox was not ready when the clock monitor request was sent at time 7. That is, the safety monitor and the safety island are not synchronized due to the DDR load time, causing a system crash.
[0053] According to aspects of the present disclosure, the safety monitor may call two functions to enable synchronization with the safety island. The safety monitor may call an iofunc_attr_unlock application program interface (API) and a sm_block_for_sail_mb block function to wait for the safety island mailbox to be ready. The two functions control clock monitor message synchronization between the main domain safety monitor and the safety island. The iofunc_attr_unlock API may be a QNX API from BLACKBERRY Limited, in some implementations.
[0054] The iofunc_attr_unlock API unlocks other safety monitor resource manager threads to process messages from other subsystems while awaiting the safety island mailbox to be created. The sm_block_for_sail_mb function periodically checks the mailbox. More specifically, the sm_block_for_sail_mb function creates a timer, and sets the timer to periodically trigger a timer pulse (e.g., every 25 ms) until the main domain receives a safety island mailbox ready notification interrupt.
[0055] The iofunc_attr_unlock may be called before the sm_process_clock_monitor call. The iofunc_attr_unlock kernel call may be provided by the main domain and allows other threads in the safety monitor resource manager to process messages, preventing the sm_block_for_sail_mb call from blocking execution of other threads.
[0056] The sm_block_for_sail_mb in the sm_process_clock_monitor call consists of the following three parts:
[0057] Call API (osal_config_timer_ev) creates and initiates the timer node.
[0058] Call API (osal_set_timer) configures the timer pulse trigger cycle.
[0059] Call API (osal_ev_receive_block) checks the mailbox status when the timer pulse arrives and then sends the clock monitor message to the safety island when the mailbox is ready.
[0060] FIGURE 6 is a timing diagram illustrating double data rate (DDR) synchronous dynamic random access memory (SDRAM) boot up processing and safety island clock monitoring, in accordance with various aspects of the present disclosure. As seen in the example of FIGURE 6, at time 1, the safety island (SAIL) waits for the DDR memory to be ready. At times 2 and 3, the QCMI provides access to the DDR memory for the safety island and transmits a ready notification to the safety island. The DDR memory is outside the safety island and may be off-chip memory. Once the DDR is ready, the safety island loads the safety island boot image (SAIL ELF) from the DDR memory, at time 6. In parallel, a main domain (MD) critical subsystem (e.g., a GPU) registers as a client of the MD safety monitor (SM) and receives a success or error indication, at times 4 and 5.
[0061] At time 7, the MD critical subsystem transmits a clock monitor request to the MD safety monitor. At time 8, the MD safety monitor calls the iofunc_attr_unlock API to unlock other safety monitor resource manager (RM) threads.
[0062] At time 9, the MD safety monitor calls the sm_block_for_sail_mb function, including checking whether the safety island mailbox is ready. If not ready, at time 10, the MD safety monitor creates a timer and starts a loop. Within the loop, at time 11, the MD safety monitor configures the timing pulse cycle, and at time 12, the MD safety monitor waits for the pulse. At time 13, the MD safety monitor checks whether the mailbox is ready in response to receiving a timing pulse.
[0063] At time 14, the safety island creates the safety island mailbox. The loop ends once the mailbox is ready. For example, at time 15, the MD safety monitor receives the mailbox ready notification. Then, when the MD safety monitor confirms the mailbox is ready, at time 16, the MD safety monitor sends the clock monitor message to the safety island through the mailbox, at time 17. At time 18, the clock monitoring is successfully enabled. At times 19 and 20, the safety island and the MD safety monitor transmit ACK messages to the MD critical subsystem.
[0064] Thus, using the iofunc_attr_unlock and sm_block_for_sail_mb calls to block the message sending until the main domain receives the mailbox ready notification interrupt from the safety island synchronizes the safety island and the main domain. More specifically, the solution avoids main domain safety monitor and safety island clock monitor message synchronization issues resulting from safety island boot images loaded from the DDR memory.
[0065] FIGURE 7 is a flow chart illustrating an example process 700 performed, for example, by a computing device, in accordance with various aspects of the present disclosure.
[0066] In some aspects, the process 700 may include initiating a safety island booting procedure including loading data stored in memory outside the safety island (block 702) . In some aspects, the method includes unlocking additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready. The memory may be DDR memory.
[0067] In some aspects, the process 700 may include determining whether a safety island mailbox is ready, after initiating the booting procedure (block 704) .
[0068] In some aspects, the process 700 may include waiting for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready (block 706) . In some aspects, waiting comprises repeatedly: checking for a mailbox status in response to arrival of a timer pulse; and blocking the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready. Waiting for the safety island mailbox to be ready may also include initializing a timer node; and configuring a timer pulse trigger cycle for the timer node.
[0069] In some aspects, the process 700 may include transmitting a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready (block 708) .
[0070] FIGURE 8 is a block diagram illustrating a design workstation 800 used for circuit, layout, and logic design of a semiconductor component, such as the safety island , disclosed above. The design workstation 800 includes a hard disk 801 containing operating system software, support files, and design software such as Cadence or OrCAD. The design workstation 800 also includes a display 802 to facilitate design of a circuit 810 or a semiconductor component 812, such as the safety mechanism. A storage medium 804 is provided for tangibly storing the design of the circuit 810 or the semiconductor component 812 (e.g., the safety island ) . The design of the circuit 810 or the semiconductor component 812 may be stored on the storage medium 804 in a file format such as GDSII or GERBER. The storage medium 804 may be a CD-ROM, DVD, hard disk, flash memory, or other appropriate device. Furthermore, the design workstation 800 includes a drive apparatus 803 for accepting input from or writing output to the storage medium 804.
[0071] Data recorded on the storage medium 804 may specify logic circuit configurations, pattern data for photolithography masks, or mask pattern data for serial write tools such as electron beam lithography. The data may further include logic verification data such as timing diagrams or net circuits associated with logic simulations. Providing data on the storage medium 804 facilitates the design of the circuit 810 or the semiconductor component 812 by decreasing the number of processes for designing semiconductor wafers.
[0072] Example Aspects
[0073] Aspect 1: A method of synchronizing communications between a safety island and a main domain safety monitor, comprising: initiating a safety island booting procedure including loading data stored in memory outside the safety island; determining whether a safety island mailbox is ready, after initiating the booting procedure; waiting for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready; and transmitting a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0074] Aspect 2: The method of Aspect 1, further comprising unlocking additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready.
[0075] Aspect 3: The method of Aspect 1 or 2, in which waiting for the safety island mailbox to be ready comprises repeatedly: checking for a mailbox status in response to arrival of a timer pulse; and blocking the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready.
[0076] Aspect 4: The method of any of the preceding Aspects, in which waiting for the safety island mailbox to be ready further comprises: initializing a timer node; and configuring a timer pulse trigger cycle for the timer node.
[0077] Aspect 5: The method of any of the preceding Aspects, in which the timer pulse trigger cycle comprises one timer pulse every 25 milliseconds (ms) .
[0078] Aspect 6: The method of any of the preceding Aspects, in which the memory comprises double data rate (DDR) synchronous dynamic random access memory (SDRAM) .
[0079] Aspect 7: The method of any of the preceding Aspects, further comprising receiving a clock monitor request from a main domain subsystem before determining whether the safety island mailbox is ready.
[0080] Aspect 8: An apparatus for synchronizing communications between a safety island and a main domain safety monitor, comprising: at least one memory; and at least one processor coupled to the at least one memory, the at least one processor configured: to initiate a safety island booting procedure including loading data stored in memory outside the safety island; to determine whether a safety island mailbox is ready, after initiating the booting procedure; to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready; and to transmit a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0081] Aspect 9: The apparatus of Aspect 8, in which the at least one processor is further configured to unlock additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready.
[0082] Aspect 10: The apparatus of Aspect 8-9, in which the at least one processor is further configured: to check for a mailbox status in response to arrival of a timer pulse; and to block the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready.
[0083] Aspect 11: The apparatus of any of the Aspects 8-10, in which the at least one processor is further configured: to initialize a timer node; and to configure a timer pulse trigger cycle for the timer node.
[0084] Aspect 12: The apparatus of any of the Aspects 8-11, in which the timer pulse trigger cycle comprises one timer pulse every 25 milliseconds (ms) .
[0085] Aspect 13: The apparatus of any of the Aspects 8-12, in which the memory comprises double data rate (DDR) synchronous dynamic random access memory (SDRAM) .
[0086] Aspect 14: The apparatus of any of the Aspects 8-13, in which the at least one processor is further configured to receive a clock monitor request from a main domain subsystem before determining whether the safety island mailbox is ready.
[0087] Aspect 15: A non-transitory computer-readable medium having program code recorded thereon, the program code executed by a processor and comprising: program code to initiate a safety island booting procedure including loading data stored in memory outside the safety island; program code to determine whether a safety island mailbox is ready, after initiating the booting procedure; program code to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready; and program code to transmit a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.
[0088] Aspect 16: The non-transitory computer-readable medium of Aspect 15, in which the program code comprises unlocking additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready.
[0089] Aspect 17: The non-transitory computer-readable medium of Aspect 15-16, in which the program code comprises: program code check for a mailbox status in response to arrival of a timer pulse; and program code to block the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready.
[0090] Aspect 18: The non-transitory computer-readable medium of any of the Aspects 15-17, in which the program code comprises: program code to initialize a timer node; and program code to configure a timer pulse trigger cycle for the timer node.
[0091] Aspect 19: The non-transitory computer-readable medium of any of the Aspects 15-18, in which the timer pulse trigger cycle comprises one timer pulse every 25 milliseconds (ms) .
[0092] Aspect 20: The non-transitory computer-readable medium of any of the Aspects 15-19, in which the memory comprises double data rate (DDR) synchronous dynamic random access memory (SDRAM) .
[0093] The various operations of methods described above may be performed by any suitable means capable of performing the corresponding functions. The means may include various hardware and / or software component (s) and / or module (s) , including, but not limited to, a circuit, an application specific integrated circuit (ASIC) , or processor. Generally, where there are operations illustrated in the figures, those operations may have corresponding counterpart means-plus-function components with similar numbering.
[0094] As used, the term “determining” encompasses a wide variety of actions. For example, “determining” may include calculating, computing, processing, deriving, investigating, looking up (e.g., looking up in a table, a database, or another data structure) , ascertaining and the like. Additionally, “determining” may include receiving (e.g., receiving information) , accessing (e.g., accessing data in a memory) and the like. Furthermore, “determining” may include resolving, selecting, choosing, establishing, and the like.
[0095] As used, a phrase referring to “at least one of” a list of items refers to any combination of those items, including single members. As an example, “at least one of: a, b, or c” is intended to cover: a, b, c, a-b, a-c, b-c, and a-b-c.
[0096] The various illustrative logical blocks, modules and circuits described in connection with the present disclosure may be implemented or performed with a general-purpose processor, a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , a field programmable gate array signal (FPGA) or other programmable logic device (PLD) , discrete gate or transistor logic, discrete hardware components or any combination thereof designed to perform the functions described. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any commercially available processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration.
[0097] The steps of a method or algorithm described in connection with the present disclosure may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module may reside in any form of storage medium that is known in the art. Some examples of storage media that may be used include random access memory (RAM) , read-only memory (ROM) , flash memory, erasable programmable read-only memory (EPROM) , electrically erasable programmable read-only memory (EEPROM) , registers, a hard disk, a removable disk, a CD-ROM and so forth. A software module may comprise a single instruction, or many instructions, and may be distributed over several different code segments, among different programs, and across multiple storage media. A storage medium may be coupled to a processor such that the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium may be integral to the processor.
[0098] The methods disclosed comprise one or more steps or actions for achieving the described method. The method steps and / or actions may be interchanged with one another without departing from the scope of the claims. In other words, unless a specific order of steps or actions is specified, the order and / or use of specific steps and / or actions may be modified without departing from the scope of the claims.
[0099] The functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in hardware, an example hardware configuration may comprise a processing system in a device. The processing system may be implemented with a bus architecture. The bus may include any number of interconnecting buses and bridges depending on the specific application of the processing system and the overall design constraints. The bus may link together various circuits including a processor, machine-readable media, and a bus interface. The bus interface may be used to connect a network adapter, among other things, to the processing system via the bus. The network adapter may be used to implement signal processing functions. For certain aspects, a user interface (e.g., keypad, display, mouse, joystick, etc. ) may also be connected to the bus. The bus may also link various other circuits such as timing sources, peripherals, voltage regulators, power management circuits, and the like, which are well known in the art, and therefore, will not be described any further.
[0100] The processor may be responsible for managing the bus and general processing, including the execution of software stored on the machine-readable media. The processor may be implemented with one or more general-purpose and / or special-purpose processors. Examples include microprocessors, microcontrollers, DSP processors, and other circuitry that can execute software. Software shall be construed broadly to mean instructions, data, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. Machine-readable media may include, by way of example, random access memory (RAM) , flash memory, read-only memory (ROM) , programmable read-only memory (PROM) , erasable programmable read-only memory (EPROM) , electrically erasable programmable Read-only memory (EEPROM) , registers, magnetic disks, optical disks, hard drives, or any other suitable storage medium, or any combination thereof. The machine-readable media may be embodied in a computer-program product. The computer-program product may comprise packaging materials.
[0101] In a hardware implementation, the machine-readable media may be part of the processing system separate from the processor. However, as those skilled in the art will readily appreciate, the machine-readable media, or any portion thereof, may be external to the processing system. By way of example, the machine-readable media may include a transmission line, a carrier wave modulated by data, and / or a computer product separate from the device, all which may be accessed by the processor through the bus interface. Alternatively, or in addition, the machine-readable media, or any portion thereof, may be integrated into the processor, such as the case may be with cache and / or general register files. Although the various components discussed may be described as having a specific location, such as a local component, they may also be configured in various ways, such as certain components being configured as part of a distributed computing system.
[0102] The processing system may be configured as a general-purpose processing system with one or more microprocessors providing the processor functionality and external memory providing at least a portion of the machine-readable media, all linked together with other supporting circuitry through an external bus architecture. Alternatively, the processing system may comprise one or more neuromorphic processors for implementing the neuron models and models of neural systems described. As another alternative, the processing system may be implemented with an application specific integrated circuit (ASIC) with the processor, the bus interface, the user interface, supporting circuitry, and at least a portion of the machine-readable media integrated into a single chip, or with one or more field programmable gate arrays (FPGAs) , programmable logic devices (PLDs) , controllers, state machines, gated logic, discrete hardware components, or any other suitable circuitry, or any combination of circuits that can perform the various functionality described throughout this disclosure. Those skilled in the art will recognize how best to implement the described functionality for the processing system depending on the particular application and the overall design constraints imposed on the overall system.
[0103] The machine-readable media may comprise a number of software modules. The software modules include instructions that, when executed by the processor, cause the processing system to perform various functions. The software modules may include a transmission module and a receiving module. Each software module may reside in a single storage device or be distributed across multiple storage devices. By way of example, a software module may be loaded into RAM from a hard drive when a triggering event occurs. During execution of the software module, the processor may load some of the instructions into cache to increase access speed. One or more cache lines may then be loaded into a general register file for execution by the processor. When referring to the functionality of a software module below, it will be understood that such functionality is implemented by the processor when executing instructions from that software module. Furthermore, it should be appreciated that aspects of the present disclosure result in improvements to the functioning of the processor, computer, machine, or other system implementing such aspects.
[0104] If implemented in software, the functions may be stored or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A storage medium may be any available medium that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Additionally, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL) , or wireless technologies such as infrared (IR) , radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. Disk and disc, as used, include compact disc (CD) , laser disc, optical disc, digital versatile disc (DVD) , floppy disk, and disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Thus, in some aspects, computer-readable media may comprise non-transitory computer-readable media (e.g., tangible media) . In addition, for other aspects computer-readable media may comprise transitory computer-readable media (e.g., a signal) . Combinations of the above should also be included within the scope of computer-readable media.
[0105] Thus, certain aspects may comprise a computer program product for performing the operations presented. For example, such a computer program product may comprise a computer-readable medium having instructions stored (and / or encoded) thereon, the instructions being executable by one or more processors to perform the operations described. For certain aspects, the computer program product may include packaging material.
[0106] Further, it should be appreciated that modules and / or other appropriate means for performing the methods and techniques described can be downloaded and / or otherwise obtained by a user terminal and / or base station as applicable. For example, such a device can be coupled to a server to facilitate the transfer of means for performing the methods described. Alternatively, various methods described can be provided via storage means (e.g., RAM, ROM, a physical storage medium such as a compact disc (CD) or floppy disk, etc. ) , such that a user terminal and / or base station can obtain the various methods upon coupling or providing the storage means to the device. Moreover, any other suitable technique for providing the methods and techniques described to a device can be utilized.
[0107] It is to be understood that the claims are not limited to the precise configuration and components illustrated above. Various modifications, changes, and variations may be made in the arrangement, operation, and details of the methods and apparatus described above without departing from the scope of the claims.
Claims
1.A method of synchronizing communications between a safety island and a main domain safety monitor, comprising:initiating a safety island booting procedure including loading data stored in memory outside the safety island;determining whether a safety island mailbox is ready, after initiating the booting procedure;waiting for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready; andtransmitting a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.2.The method of claim 1, further comprising unlocking additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready.3.The method of claim 1, in which waiting for the safety island mailbox to be ready comprises repeatedly:checking for a mailbox status in response to arrival of a timer pulse; andblocking the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready.4.The method of claim 3, in which waiting for the safety island mailbox to be ready further comprises:initializing a timer node; andconfiguring a timer pulse trigger cycle for the timer node.5.The method of claim 4, in which the timer pulse trigger cycle comprises one timer pulse every 25 milliseconds (ms) .6.The method of claim 1, in which the memory comprises double data rate (DDR) synchronous dynamic random access memory (SDRAM) .7.The method of claim 1, further comprising receiving a clock monitor request from a main domain subsystem before determining whether the safety island mailbox is ready.8.An apparatus for synchronizing communications between a safety island and a main domain safety monitor, comprising:at least one memory; andat least one processor coupled to the at least one memory, the at least one processor configured:to initiate a safety island booting procedure including loading data stored in memory outside the safety island;to determine whether a safety island mailbox is ready, after initiating the booting procedure;to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready; andto transmit a clock monitor message from the safety monitor to the safety island in response to determining the safety island mailbox is ready after waiting for the safety island mailbox to be ready.9.The apparatus of claim 8, in which the at least one processor is further configured to unlock additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready.10.The apparatus of claim 8, in which the at least one processor is further configured to repeatedly:check for a mailbox status in response to arrival of a timer pulse; andblock the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready.11.The apparatus of claim 10, in which the at least one processor is further configured:to initialize a timer node; andto configure a timer pulse trigger cycle for the timer node.12.The apparatus of claim 11, in which the timer pulse trigger cycle comprises one timer pulse every 25 milliseconds (ms) .13.The apparatus of claim 8, in which the memory outside the safety island comprises double data rate (DDR) synchronous dynamic random access memory (SDRAM) .14.The apparatus of claim 8, in which the at least one processor is further configured to receive a clock monitor request from a main domain subsystem before determining whether the safety island mailbox is ready.15.A non-transitory computer-readable medium having program code recorded thereon, the program code executed by a processor and comprising:program code to initiate a safety island booting procedure including loading data stored in memory outside a safety island;program code to determine whether a safety island mailbox is ready, after initiating the booting procedure;program code to wait for the safety island mailbox to be ready in response to determining the safety island mailbox is not ready; andprogram code to transmit a clock monitor message from a safety monitor to the safety island in response to determining the safety island mailbox is ready.16.The non-transitory computer-readable medium of claim 15, in which the program code comprises unlocking additional safety monitor resource manager threads to process messages from other subsystems, prior to determining whether the safety island mailbox is ready.17.The non-transitory computer-readable medium of claim 15, in which the program code comprises program code to repeatedly:check for a mailbox status in response to arrival of a timer pulse; andblock the transmitting of the clock monitor message until the mailbox status indicates the safety island mailbox is ready.18.The non-transitory computer-readable medium of claim 17, in which the program code comprises:program code to initialize a timer node; andprogram code to configure a timer pulse trigger cycle for the timer node.19.The non-transitory computer-readable medium of claim 18, in which the timer pulse trigger cycle comprises one timer pulse every 25 milliseconds (ms) .20.The non-transitory computer-readable medium of claim 15, in which the memory comprises double data rate (DDR) synchronous dynamic random access memory (SDRAM) .
Citation Information
Patent Citations
Master controller clock reset processing method and device and corresponding automobile
CN104898491A
Vehicle-mounted operating system security detection method and device based on virtualization technology
CN117818511A
Vehicle-mounted MCU starting method and system
CN118306332A
Functional safety clocking framework for real time systems
US20190052277A1
Display driver integrated circuit, system-on-chip, and display system including the system-on-chip
US20240185801A1