Integrated Microprocessor Memory Protection for Safety Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing microprocessor systems for safety-critical applications in motor vehicles are complex, expensive, and prone to undesired mutual influences between main and monitoring programs, which compromises reliability and increases costs due to the use of multiple complete microprocessor systems and separate components.

Innovation Solution

An integrated microprocessor system with at least two modules, each containing a processor core and a memory protection unit, where separate address areas are assigned to each program to prevent unauthorized memory access, allowing for independent processing and operation with a common operating system, reducing costs and enhancing reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two complete microprocessor systems are used for main and monitoring programs, then reliability and separation of programs are improved, but device complexity and cost increase

Engineering Contradiction:
Improveprogram separation reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines two previously separate microprocessor systems into a single integrated system. The main processor and monitoring processor share common components including read-only memory, read-write memory, and bus systems, while maintaining separate processing functions. This merging reduces device complexity and cost while preserving the reliability benefits of program separation through hardware-enforced memory protection boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated system segments the memory space into distinct address areas for main programs and monitoring programs. The memory protection unit divides the shared read-write memory into separate accessible regions for each processor, ensuring that the monitoring program can only access its designated memory segment. This segmentation maintains program separation reliability while allowing physical integration.

Inventive Principle:
Principle #1Segmentation

2Reliability

If two complete microprocessor systems are used, then program independence is improved, but cost and chip area increase

Engineering Contradiction:
Improveprogram independenceVSAvoidchip area
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the memory subsystems of two separate microprocessor systems into shared common memory resources. Both the main processor and monitoring processor access the same physical memory chips through separate bus interfaces, eliminating the need for duplicate memory components. This significantly reduces chip area and component quantity while maintaining program independence through logical memory segmentation enforced by the memory protection unit.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared read-write memory serves multiple functions simultaneously: it stores data for both main programs and monitoring programs, and provides separate accessible regions for each processor. The memory protection unit enables this universal memory resource to function independently for both processors by enforcing address-based access control, reducing the total quantity of memory components needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If separate memory systems are used for each processor, then unauthorized access is prevented, but device complexity and cost increase

Engineering Contradiction:
Improvememory access securityVSAvoidmemory system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a memory protection unit as an intermediary component between the main processor and the shared read-write memory. This intermediary intercepts memory access requests, checks whether the accessing processor is authorized to access the target address area, and blocks unauthorized accesses. This single intermediary component provides security for both processors sharing common memory, reducing complexity compared to implementing separate memory systems with individual protection mechanisms for each processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2193408B1Integrated microprocessor system for safety-critical control systems
Publication Date: 2011.02.02 CONTINENTAL TEVES AG & CO OHG
  • EP2193408B1 patent drawingFigure 1
  • EP2193408B1 patent drawingFigure 2

AI summary

Integrated microprocessor system (1) for safety-critical control systems, comprising at least two microprocessor system modules (2,3) each comprising at least one processor core (21,31), a read/write memory (22,32) and a memory protection unit (23,33), and a read-only memory (4) which is jointly assigned to the processor cores (21,31) of the microprocessor system modules (2,3), wherein each of the microprocessor system modules (2,3) executes a main program and a monitoring program which comprise, in particular, a plurality of subprograms, and the respective memory protection unit (23,33) assigns a separate address area (A, B) of the read/write memory (22,32) to the main program and to the monitoring program, wherein the memory protection unit (23,33) detects unauthorized operations by one of the programs for accessing the separate address area (A, B) of another program.