Dual-Chip Functional Safety Isolation for Flexible Non-Safety Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing functional safety systems face challenges in separating non-safety and safety units on a single processor, leading to difficulties in modifying the non-safety unit without interfering with the safety unit, which is necessary for maintaining high reliability and flexibility.
Innovation Solution
The implementation of a functional safety system using two semiconductor chips with independently operating timers and space domain separation hardware, allowing for time and space domain separation of software execution, enabling self-diagnosis and mutual diagnosis to ensure separation and independence between safety and non-safety units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If the safety unit and non-safety unit are implemented on a single processor, then the number of components is reduced, but the reliability and flexibility of modifying the non-safety unit deteriorates due to interference between operations
Solution Approach 1:
The patent divides the processor into separate execution environments: a first execution environment for the safety unit and a second execution environment for the non-safety unit. This segmentation allows both units to coexist on a single processor while maintaining operational independence, thus reducing component quantity without compromising reliability.
Solution Approach 2:
The patent introduces an intermediary mechanism (separation hardware and monitoring processes) that mediates between the safety unit and non-safety unit. This intermediary ensures that operations in one environment do not interfere with the other, maintaining reliability while allowing integration on a single processor.
2Quantity of substance
If the safety unit and non-safety unit are implemented on a single processor, then the number of components is reduced, but the flexibility of modifying the non-safety unit deteriorates due to interference between operations
Solution Approach 1:
By segmenting the processor into distinct execution environments with separate memory spaces and resource access controls, the non-safety unit can be modified independently without affecting the safety unit, thus improving flexibility while maintaining integration.
Solution Approach 2:
The patent applies local quality by giving different access permissions and resource allocations to different execution environments. The non-safety unit environment is configured to allow modifications while the safety unit environment maintains strict controls, enabling flexibility where needed without compromising safety.
3Quantity of substance
If separation between non-safety unit and safety unit is not sufficiently ensured, then the number of components is reduced, but the ability to freely modify the non-safety unit deteriorates
Solution Approach 1:
The separation hardware and monitoring processes act as intermediaries that enforce strict boundaries between the safety and non-safety units. This intermediary layer ensures that modifications to the non-safety unit cannot affect the safety unit, making modifications easier and safer.
Solution Approach 2:
The patent extracts the safety unit into a separate execution environment with isolated memory and resource access. This extraction allows the non-safety unit to be freely modified in its own environment without risk of interfering with the safety unit, improving ease of operation.
4Reliability
If strict separation between safety unit and non-safety unit is implemented, then the reliability is improved, but the number of components increases
Solution Approach 1:
The patent merges the safety unit and non-safety unit onto a single processor by creating virtual execution environments. This combining approach maintains strict separation and reliability through environmental isolation while reducing the total number of physical components compared to using separate processors.
Data Source
AI summary
In a semiconductor device according to the related art, unfortunately, a non-safety unit mounted on the same device as a safety unit is modified with low flexibility. According to one embodiment, a first semiconductor chip and a second semiconductor chip each have space domain separation hardware for limiting access to hardware resources in a functional safety system. Safety unit software and space domain and time domain separation software are executed in a time sharing manner. Based on a timer installed on the semiconductor chip, the space domain and time domain separation software performs separation for intermittently executing the safety unit software in a predetermined cycle, self-diagnosis for examining an operation of the safety unit software, and mutual diagnosis made between the first semiconductor chip and the second semiconductor chip to mutually diagnose the operation of the space domain and time domain separation software for performing the separation and the self-diagnosis.


