Fault Collection Circuit for Selective Target Reset

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrated circuits, such as system-on-a-chip (SoC), face challenges in distinguishing between faults in safety and non-safety targets, leading to indiscriminate system resets that affect system availability and reliability, particularly in critical applications like automotive systems.

Innovation Solution

Implementing fault collection and control circuits (FCCC) with network interface units (NIUs) and timeout logic to differentiate between safety and non-safety targets, employing fence, drain, and dummy responder logic to isolate and reset only non-safety targets, thereby preventing system-wide resets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the SoC is reset when a fault is detected (traditional approach), then the fault is remedied, but the system availability deteriorates due to indiscriminate resets affecting both safety and non-safety targets

Engineering Contradiction:
Improvefault remediationVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the target into safety targets and non-safety targets, enabling differentiated fault handling. The FCCC identifies which target type experienced the fault and applies appropriate recovery actions: system-wide reset for safety targets, selective reset for non-safety targets only, thereby resolving the contradiction between reliable fault remediation and maintaining system availability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing different recovery strategies for different target types. Safety targets receive full system reset while non-safety targets receive selective reset without affecting safety-critical components. This localized approach to fault recovery maintains system availability while ensuring reliable remediation of the specific fault

Inventive Principle:
Principle #3Local quality

2Reliability

If the SoC is reset to remedy a fault, then the fault is cleared, but the complexity of the recovery process increases due to need to distinguish between safety and non-safety targets

Engineering Contradiction:
Improvefault clearanceVSAvoidrecovery process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism (FCCC with timeout logic and target identification circuitry) that automatically distinguishes between safety and non-safety targets and selects the appropriate recovery action. This intermediary handles the complexity of differentiation, providing simple automated recovery processes without requiring complex manual intervention or judgment

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If timeout logic is implemented to detect faults, then fault detection capability is improved, but the device complexity increases due to additional timeout circuits and logic

Engineering Contradiction:
Improvefault detection capabilityVSAvoidtimeout circuit complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The timeout logic is designed with multi-functionality, serving both as a fault detection mechanism and as part of the target identification system. The same timeout circuitry that detects faults also contributes to identifying whether the fault originated from a safety or non-safety target, thereby improving fault detection capability without proportionally increasing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4575793A1Method and system to identify and recover from faults in non-safety targets and safety targets
Publication Date: 2025.06.25 NXP USA INC
  • EP4575793A1 patent drawingFigure 1
  • EP4575793A1 patent drawingFigure 2
  • EP4575793A1 patent drawingFigure 3

AI summary

A method and system to increase system availability during a fault of a non-safety target is disclosed. A fault signal is received indicative of a response to a request from an initiator not being received from one of a safety target and non-safety target within a response time. Based on the response not being received from the non-safety target, only the non-safety target is reset to increase the system availability rather than also resetting safety targets. Because a target did not respond to the request, a dummy responder further sends to the initiator a response to the request to prevent the initiator from entering into a hang state.