Configurable Safety Master Microcontroller Unit for SoC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems on a chip (SoCs) that incorporate safety subsystems face increased costs and power consumption due to the inclusion of unused safety subsystems, even in applications where safety subsystems are not required.
Innovation Solution
A SoC design that includes a configurable safety master microcontroller unit, allowing the same processing resources to be configured as either a safety domain or a general-purpose processing domain, with isolation circuitry to manage the level of isolation between the domains based on the configured mode.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated safety subsystem is added to the SoC, then functional safety is improved, but system cost and power consumption increase
Solution Approach 1:
The second processor is designed to serve dual purposes: it can function as a general-purpose processing unit when the safety subsystem is not needed, and as a safety master when safety functions are required. This multi-functionality eliminates the need for separate dedicated safety hardware, thereby reducing power consumption while maintaining safety capabilities when needed.
Solution Approach 2:
The system dynamically reconfigures the second processor's function based on operational requirements. Through configuration modes that can be switched between, the system adapts the processor's role from general-purpose to safety-critical, allowing the same hardware to serve different functions without requiring permanent dedicated safety infrastructure.
2Reliability
If a dedicated safety subsystem is added to the SoC, then functional safety is improved, but system cost increases
Solution Approach 1:
The second processor is designed to serve dual purposes: it can function as a general-purpose processing unit when the safety subsystem is not needed, and as a safety master when safety functions are required. This multi-functionality eliminates the need for separate dedicated safety hardware, thereby reducing system cost while maintaining safety capabilities when needed.
Solution Approach 2:
The patent merges the safety master functionality with the second processor's processing capabilities. Instead of having completely separate dedicated safety hardware, the system combines safety functions with general-purpose processing resources, reducing overall system complexity and cost while maintaining safety integrity through isolation mechanisms.
3Reliability
If isolation circuitry is added between domains, then functional safety is improved, but device complexity increases
Solution Approach 1:
The isolation mechanism applies local quality by providing isolation only where needed - specifically between the first processor's general-purpose domain and the second processor's safety domain. The isolation circuitry is strategically placed to provide targeted protection without requiring complete system-wide isolation, thereby reducing overall device complexity.
4Reliability
If processing resources are dedicated to safety functions only, then functional safety is improved, but adaptability decreases
Solution Approach 1:
The system dynamically reconfigures the second processor's function based on operational requirements. Through configuration modes that can be switched between, the system adapts the processor's role from general-purpose to safety-critical, allowing the same hardware to serve different functions without requiring permanent dedicated safety infrastructure.
Solution Approach 2:
The second processor is designed to serve dual purposes: it can function as a general-purpose processing unit when the safety subsystem is not needed, and as a safety master when safety functions are required. This multi-functionality eliminates the need for separate dedicated safety hardware, thereby reducing power consumption while maintaining safety capabilities when needed.
Data Source
AI summary
An example system, e.g., a system on a chip (SoC), includes first and second domains having first and second processors, respectively. The second processor is part of a processing subsystem in the second domain. The first processor provides an instruction to the second processor, which executes the instruction to configure the processing subsystem to operate in a mode specified by the instruction. In response to the processing subsystem being configured to operate in the specified mode, isolation circuitry of the system is configured to provide a level of isolation between the first domain and the second domain based on the specified mode.


