Memory Subsystem Panic Modes for Incremental Fault Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional memory sub-systems in automotive applications face challenges in handling failures, particularly in automotive SSDs, due to limited debugging capabilities and varying SMBUS capabilities across different platforms, which hinder effective fault analysis and compliance with Functional Safety (FuSA) standards.
Innovation Solution
A memory controller incrementally transitions the memory sub-system into different panic handling modes to recover from failures, including panic, read-only, write protect, and diagnostic modes, while maintaining functionality to satisfy host requests and ensuring FuSA compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the memory sub-system completely disables the system in case of failure, then safety and fault isolation are improved, but system availability and productivity deteriorate
Solution Approach 1:
The system is segmented into different operational modes (deployed mode, panic handling modes including read-only mode, diagnostic mode, and crippled mode). When failure occurs, the system transitions to appropriate panic handling modes that isolate the failure while maintaining limited functionality. This segmentation allows the system to maintain safety by isolating faults while preserving productivity through continued operation in degraded modes.
Solution Approach 2:
The system dynamically transitions between different operational states based on failure conditions. The controller can incrementally transition through different panic handling modes (from read-only to diagnostic to crippled mode) depending on the severity and type of failure. This dynamic adaptation allows the system to maintain optimal safety levels while preserving maximum possible productivity for each failure scenario.
2Reliability
If the memory sub-system enters panic mode immediately upon failure, then fault isolation is improved, but debugging capability and recovery opportunity deteriorate
Solution Approach 1:
The panic handling process is segmented into multiple incremental modes rather than a single immediate panic state. The system first attempts less restrictive modes (read-only mode, diagnostic mode) before transitioning to more restrictive modes (crippled mode). This segmentation preserves debugging capabilities in earlier modes while still providing fault isolation, allowing engineers to analyze failures without immediately crippling the system.
Solution Approach 2:
The system performs preliminary diagnostic actions and attempts recovery in less restrictive modes before entering full panic mode. By incrementally transitioning through different panic handling modes, the system preserves debugging capabilities and recovery opportunities that would be lost if full panic mode were entered immediately. This preliminary action allows for fault analysis and potential recovery while maintaining safety.
3Stability of the object's composition
If the memory sub-system restricts all operations in panic mode, then system stability is improved, but functionality and host request satisfaction deteriorate
Solution Approach 1:
The operational restrictions are segmented and applied differently across multiple panic handling modes. Read-only mode allows read operations while restricting writes, diagnostic mode allows specific diagnostic operations, and crippled mode applies more comprehensive restrictions. This segmented approach maintains system stability by applying appropriate restrictions while preserving necessary functionality for each failure scenario, allowing the system to remain adaptable to different operational requirements.
Solution Approach 2:
Different levels of operational restriction are applied locally to different modes rather than uniformly to all panic states. Each panic handling mode has tailored restrictions that match the specific failure condition and recovery needs. This local quality approach ensures system stability through appropriate restrictions while maintaining functionality where safe and necessary, optimizing the balance between stability and adaptability for each scenario.
Data Source
AI summary
Aspects of the present disclosure configure a system component, such as memory sub-system controller, to transition a state of a memory sub-system into different panic handling modes. The controller detects failure of a memory sub-system and determines that self-recovery from the failure of the memory sub-system is unavailable. The controller, in response to determining that self-recovery from the failure of the memory sub-system is unavailable, incrementally transitions a state of the memory sub-system to different panic handling modes and returns the memory sub-system to a deployed mode from one of the different panic handling modes in response to successfully recovering the memory sub-system.


