Dual-Chip Functional Safety Isolation for Flexible Non-Safety Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing functional safety systems face challenges in separating non-safety and safety units on a single processor, leading to difficulties in modifying the non-safety unit without interfering with the safety unit, which is necessary for maintaining high reliability and flexibility.

Innovation Solution

The implementation of a functional safety system using two semiconductor chips with independently operating timers and space domain separation hardware, allowing for time and space domain separation of software execution, enabling self-diagnosis and mutual diagnosis to ensure separation and independence between safety and non-safety units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If the safety unit and non-safety unit are implemented on a single processor, then the number of components is reduced, but the reliability and flexibility of modifying the non-safety unit deteriorates due to interference between operations

Engineering Contradiction:
Improvenumber of componentsVSAvoidreliability of safety unit
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent divides the processor into separate execution environments: a first execution environment for the safety unit and a second execution environment for the non-safety unit. This segmentation allows both units to coexist on a single processor while maintaining operational independence, thus reducing component quantity without compromising reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (separation hardware and monitoring processes) that mediates between the safety unit and non-safety unit. This intermediary ensures that operations in one environment do not interfere with the other, maintaining reliability while allowing integration on a single processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If the safety unit and non-safety unit are implemented on a single processor, then the number of components is reduced, but the flexibility of modifying the non-safety unit deteriorates due to interference between operations

Engineering Contradiction:
Improvenumber of componentsVSAvoidflexibility of modifying non-safety unit
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

By segmenting the processor into distinct execution environments with separate memory spaces and resource access controls, the non-safety unit can be modified independently without affecting the safety unit, thus improving flexibility while maintaining integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by giving different access permissions and resource allocations to different execution environments. The non-safety unit environment is configured to allow modifications while the safety unit environment maintains strict controls, enabling flexibility where needed without compromising safety.

Inventive Principle:
Principle #3Local quality

3Quantity of substance

If separation between non-safety unit and safety unit is not sufficiently ensured, then the number of components is reduced, but the ability to freely modify the non-safety unit deteriorates

Engineering Contradiction:
Improvenumber of componentsVSAvoidease of modifying non-safety unit
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The separation hardware and monitoring processes act as intermediaries that enforce strict boundaries between the safety and non-safety units. This intermediary layer ensures that modifications to the non-safety unit cannot affect the safety unit, making modifications easier and safer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the safety unit into a separate execution environment with isolated memory and resource access. This extraction allows the non-safety unit to be freely modified in its own environment without risk of interfering with the safety unit, improving ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If strict separation between safety unit and non-safety unit is implemented, then the reliability is improved, but the number of components increases

Engineering Contradiction:
Improvereliability of safety unitVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the safety unit and non-safety unit onto a single processor by creating virtual execution environments. This combining approach maintains strict separation and reliability through environmental isolation while reducing the total number of physical components compared to using separate processors.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11449361B2Functional safety system, safety control method for the functional safety system, and functional safety program
Publication Date: 2022.09.20 RENESAS ELECTRONICS CORP
  • US11449361B2 patent drawing
  • US11449361B2 patent drawing
  • US11449361B2 patent drawing

AI summary

In a semiconductor device according to the related art, unfortunately, a non-safety unit mounted on the same device as a safety unit is modified with low flexibility. According to one embodiment, a first semiconductor chip and a second semiconductor chip each have space domain separation hardware for limiting access to hardware resources in a functional safety system. Safety unit software and space domain and time domain separation software are executed in a time sharing manner. Based on a timer installed on the semiconductor chip, the space domain and time domain separation software performs separation for intermittently executing the safety unit software in a predetermined cycle, self-diagnosis for examining an operation of the safety unit software, and mutual diagnosis made between the first semiconductor chip and the second semiconductor chip to mutually diagnose the operation of the space domain and time domain separation software for performing the separation and the self-diagnosis.