In-field Core Failover for Multicore Processor Reliability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern processors lack a mechanism for in-field core failover, leading to potential system failures due to unaddressed post-manufacturing failures in multicore processors, where active cores can fail due to design marginalities, random defects, or other failure modes, and existing support is limited to enabling entire spare components, resulting in reduced reliability and increased costs.
Innovation Solution
The implementation of architectural and micro-architectural capabilities that allow for in-field core failover, enabling fully qualified and functional spare cores to be activated in the field to replace faulty cores, thereby maintaining system functionality without additional power or area costs, using mechanisms such as a power control unit and configuration registers to manage core activation and deactivation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If spare cores are included in multicore processors, then reliability is improved through potential failover capability, but device complexity increases due to additional cores and configuration management
Solution Approach 1:
The processor is segmented into active cores and spare cores, with each core being an independent functional unit. This segmentation allows the spare core to be activated independently when a failure occurs in an active core, providing reliability improvement without requiring complete system redesign.
Solution Approach 2:
A power control unit acts as an intermediary between the processor cores and the power management system. This intermediary component manages the activation and deactivation of cores, handling the complexity of configuration changes and providing a simplified interface for reliability management.
2Reliability
If in-field core failover capability is implemented, then reliability is improved through fault tolerance, but ease of manufacture deteriorates due to additional architectural capabilities
Solution Approach 1:
Spare cores are pre-configured and prepared during manufacturing, with their operational status controlled by configuration registers. This preliminary preparation allows the processor to be manufactured with failover capability built-in, while the actual activation of spares is deferred to field operation when needed.
Solution Approach 2:
The operational state of processor cores is controlled by changing parameters in configuration registers, specifically the cores on mask register and preferred cores register. This parameter-based control allows flexible activation of failover capability without requiring physical manufacturing changes.
3Reliability
If functional spares are activated to replace faulty cores, then reliability is improved through core substitution, but loss of time occurs during the failover process
Solution Approach 1:
Spare cores are pre-positioned and ready for activation before any failure occurs. The power control unit and configuration registers are pre-configured to enable rapid switching, eliminating the need for complex real-time decisions or extensive reconfiguration during the failover process.
Solution Approach 2:
The processor configuration is made dynamic through the power control unit, which can change the operational state of cores in real-time based on failure conditions. This dynamic reconfiguration allows the system to adapt to failures while maintaining high availability.
Data Source
AI summary
A multicore processor may include multiple processing cores that were previously designated as active cores and at least one processing core that was previously designated as a functional spare. The processor may include an interface to receive, during operation of the processor in an end-user environment, a request to change the designation of at least one of the processing cores. The processor may be to store, into a desired cores configuration data structure in response to the request, data representing a bitmask that reflects the requested change, and to execute a reset sequence. During the reset sequence, the processor may activate, dependent on the bitmask, a processing core previously designated as a functional spare, or may deactivate, dependent on the bitmask, a processing core previously designated as an active core. The processor may include a predetermined maximum number of active cores and a predetermined minimum number of functional spares.


