SoC Failover via Hypervisor Domain Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for providing backup or failover support for critical and safety-sensitive tasks in computer-assisted or autonomous driving vehicles are costly and complex, requiring fully redundant hardware components and infrastructure for switching output devices.

Innovation Solution

A system-on-chip (SoC) with a hypervisor partitioning cores into operational and failover domains, using a main operating system for primary functions and a secondary operating system with reduced capabilities to take over in case of failure, allowing for re-assignment of devices from the operational domain to the failover domain to execute a backup version of critical tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fully redundant hardware components (second CPU and/or second GPU) are provisioned for failover support, then system reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvefailover supportVSAvoidhardware redundancy
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the primary and backup operating systems onto a single CPU/GPU hardware platform. The hypervisor consolidates hardware resource management, allowing both OS instances to share the same physical components rather than requiring separate redundant hardware. This merging approach maintains failover capability while eliminating the need for duplicate hardware infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single CPU/GPU platform is designed to universally support both primary and backup operating system instances. The hardware resources (CPU cores, GPU units, memory) are multi-functional, capable of serving either the primary OS or the backup OS depending on operational needs. This universality allows one hardware platform to fulfill multiple roles without requiring specialized redundant components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If secondary redundant hardware component and switching infrastructure are provisioned, then failover capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvefailover capabilityVSAvoidswitching infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hypervisor acts as an intermediary layer between the hardware resources and the operating systems. It manages resource allocation and switching dynamically, eliminating the need for complex physical switching infrastructure. When failover is required, the hypervisor reallocates hardware resources to the backup OS instance through software-based resource management rather than requiring physical switch reconfiguration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical/physical switching infrastructure with a software-based resource management system. Instead of physically switching hardware connections through complex switching infrastructure, the hypervisor uses virtualization and software-controlled resource allocation to achieve failover. This substitution of mechanical systems with software-based solutions reduces physical complexity while maintaining failover capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11449396B2Failover support within a SoC via standby domain
Publication Date: 2022.09.20 INTEL CORP
  • US11449396B2 patent drawing
  • US11449396B2 patent drawing
  • US11449396B2 patent drawing

AI summary

In various embodiments, an apparatus includes a system-on-chip (SoC) to be disposed in a vehicle having a plurality of cores; a hypervisor arranged to partition the cores into at least two domains, an operational domain and a failover domain; a first operating system (OS) arranged to manage execution of at least a first application in the operational domain to provide a first plurality of functions for the vehicle; a second OS arranged to manage execution of at least a second application in the failover domain to provide a second plurality of functions for the vehicle, on occurrence of a failure of the first application. The second functions comprise a subset of the first functions or less embellished versions of some of the first functions, and the second OS has less capabilities than the first OS. Other embodiments, including storage media and methods, are also described and claimed.