Dual Fault Detection for Protected Task Processing Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Processing systems in safety-critical applications face challenges in detecting and recovering from transient and permanent faults, particularly in processing logic that transforms data, which conventional error correction mechanisms like ECC and parity bit checks cannot address, necessitating a robust fault detection system to meet stringent safety standards like ASIL B or D of ISO 26262.

Innovation Solution

A processing system with dual fault detection units operating in mission and test modes, comparing duplicate processed outputs to identify faults, and a method for periodic testing of these units to ensure their functionality, enabling concurrent fault detection and reduced intrusive testing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional error correction mechanisms (ECC and parity bit checks) are used, then memory and data path faults can be detected, but processing logic faults cannot be protected against

Engineering Contradiction:
Improvefault detection capabilityVSAvoidapplicability to different fault types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the processing system into multiple processing elements (at least two) that can independently execute the same task. This segmentation allows the system to compare results from different processing elements to detect faults in processing logic, extending protection beyond what conventional ECC and parity bit checks can provide for memory and data paths alone.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copying by having multiple processing elements execute identical tasks and compare their outputs. This copying approach enables fault detection in processing logic by comparing results, whereas conventional ECC and parity bit checks only copy/check data without validating the processing logic itself.

Inventive Principle:
Principle #26Copying

2Reliability

If rigorous development practices, code auditing and testing protocols are implemented, then software safety goals are achieved, but hardware fault detection remains insufficient

Engineering Contradiction:
Improvesoftware safetyVSAvoiddevelopment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the hardware system to automatically detect its own faults through built-in comparison mechanisms. Multiple processing elements independently execute tasks and compare results, allowing the system to self-diagnose processing logic faults without requiring external testing or complex development protocols for hardware validation.

Inventive Principle:
Principle #25Self-service

3Reliability

If processing systems meet stringent safety standards (ASIL B or D), then safety-critical requirements are satisfied, but fault detection capabilities are still limited for processing logic

Engineering Contradiction:
Improvesafety standard complianceVSAvoidprocessing logic fault detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses feedback by implementing a comparison mechanism where outputs from multiple processing elements are fed back and compared. This feedback loop enables the system to detect discrepancies indicating processing logic faults, providing the enhanced fault detection capability needed to meet stringent ASIL safety standards for processing logic where conventional methods fall short.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250377990A1Processing System Configured to Process Protected Tasks
Publication Date: 2025.12.11 IMAGINATION TECH LTD
  • US20250377990A1 patent drawing
  • US20250377990A1 patent drawing
  • US20250377990A1 patent drawing

AI summary

Processing logic of a processing system processes protected tasks first and second times to generate first and second processed outputs. A first fault detection unit compares the first and second processed outputs for a respective protected task and generates a first signal indicative of whether they match. A second fault detection unit compares the first and second processed outputs for the respective protected task and generates a second signal indicative of whether they match. The processing system is operable in a first protected mode in which the first fault detection unit and the second fault detection unit operate, concurrently, in respective mission modes, and the first signal and the second signal for the respective protected task are provided to a fault assessment unit for comparison in order to assess whether a fault existed at the first fault detection unit and/or the second fault detection unit when generating the first and second signals.