Selective IO Terminal Safe-Stating for SoC Fault Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional system-on-chip (SoC) fault-handling mechanisms respond aggressively to faults by disabling all input/output terminals, impacting non-faulty applications and reducing system availability.
Innovation Solution
A method and apparatus for selectively disabling only the IO terminals associated with faulty applications, using a fault collection and reaction system that includes terminal controllers, processor cores, and memory to store terminal masks, allowing non-faulty terminals to remain operational.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all IO terminals are disabled upon fault detection, then system safety is improved, but system availability deteriorates
Solution Approach 1:
The patent segments the IO terminals into application-specific groups, where each application has its own dedicated set of terminals. When a fault occurs in one application, only the terminals associated with that specific application are disabled, while terminals for other applications remain operational. This segmentation allows selective isolation of faulty components without affecting the entire system.
Solution Approach 2:
The patent implements local quality by applying different safety responses to different parts of the system based on their association with faulty applications. Terminal controllers examine terminal masks to determine which terminals belong to which applications, and selectively disable only those terminals that are locally associated with the faulty application, rather than applying a uniform disable-all policy.
2Object-affected harmful factors
If all IO terminals are disabled upon fault detection, then fault propagation is prevented, but device availability deteriorates
Solution Approach 1:
The patent segments terminals into application-specific groups using terminal masks, where each mask defines which terminals are associated with which application. This segmentation enables selective disabling of only those terminals that could propagate the fault, while leaving terminals for unrelated applications unaffected and operational.
Solution Approach 2:
The patent extracts and isolates the faulty application's terminal associations from the rest of the system. By identifying and separating the terminals that belong to the faulty application through terminal masks, the system can remove (disable) only those specific terminals that would propagate the fault, while maintaining operation of all other terminals.
3Reliability
If traditional fault handling disables all terminals, then safety mechanisms are strengthened, but application independence deteriorates
Solution Approach 1:
The patent segments the terminal control mechanism into application-specific units using terminal masks. Each application has its own mask that defines its terminal associations, enabling independent control of terminals for each application. This allows one application's fault to be handled independently without affecting the terminal control of other applications.
Solution Approach 2:
The patent applies local quality by making terminal controllers aware of application-specific terminal associations through terminal masks. Each terminal controller can determine whether its controlled terminal belongs to a faulty application and respond accordingly, providing localized safety responses that preserve application independence rather than applying a system-wide disable policy.
Data Source
AI summary
A system-on-chip (SoC) may include a plurality of terminals and a plurality of terminal controllers. Each terminal controller is configured to selectively disable a terminal. An SoC be configured to execute at least one application. An SoC may include a memory configured to store a plurality of terminal masks. Each terminal mask identifies a subset of the plurality of terminals to be disabled. An SoC may include a fault collection and reaction system configured to transmit, to the plurality of terminal controllers, a fault indication signal in response to an error in a corresponding application. Each terminal controller is further configured to determine, based on a fault indication signal and a value in a terminal mask, whether the terminal corresponding to the terminal controller is to be disabled, and when the terminal corresponding to the terminal controller is to be disabled, disable the terminal.


