SoC Fault Detection via Trusted Resource Monitor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In system on chip (SoC) architectures where IP cores communicate exclusively via messages, faulty control messages from one IP core can inadvertently cause failures in other IP cores, leading to potential system-wide failures.
Innovation Solution
Implementing a trusted resource monitor (TRM) that checks and forwards control messages from non-privileged IP cores, ensuring only authorized messages are sent to the technology-dependent interface of other IP cores, and using error-correcting codes to safeguard the privileged subsystem, including the network on chip and network interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If IP cores communicate exclusively via messages without intermediary checking, then communication efficiency is improved, but system reliability deteriorates as faulty messages can propagate and cause failures in other IP cores
Solution Approach 1:
The patent introduces a Trusted Resource Monitor (TRM) as an intermediary component that checks control messages before they are processed by IP cores. The TRM validates messages from non-privileged IP cores and forwards only authorized messages to the technology-dependent interface, preventing faulty messages from propagating while maintaining communication efficiency.
2Reliability
If control messages are checked by a third IP core before forwarding, then message validity is improved, but device complexity increases due to the additional checking mechanism
Solution Approach 1:
The TRM serves as a dedicated intermediary that centralizes the message checking function. Rather than adding checking logic to each IP core (which would increase overall complexity), the patent introduces a single specialized TRM component that handles validation for all IP cores, thus improving message validity while minimizing the increase in device complexity.
Solution Approach 2:
The TRM is designed as a universal checking mechanism that handles control messages from multiple different IP cores through a single interface. This multi-functional approach allows the same checking logic to be applied across all IP cores, reducing the need for duplicate validation logic and thereby limiting the increase in device complexity.
3Reliability
If the TRM forwards messages only from authorized senders, then security is improved, but communication speed deteriorates due to additional authorization checks
Solution Approach 1:
The authorization checking function is integrated into the TRM's message forwarding process, performing validation in advance before messages reach the IP cores. By pre-establishing authorization rules and checking them at the TRM level, the system ensures security without requiring additional speed-critical checks at the receiving IP cores.
Solution Approach 2:
The TRM acts as a security gateway that filters and validates messages before they enter the IP core processing pipeline. This intermediary position allows authorization checks to be performed once at the network level rather than repeatedly at each IP core, minimizing the impact on communication speed while maintaining security.
4Reliability
If error-correcting codes are used to safeguard the privileged subsystem, then reliability is improved, but use of energy increases due to additional error correction processing
Solution Approach 1:
Error-correcting codes are applied selectively to the privileged subsystem (TRM, network on chip, and network interfaces) rather than to the entire SoC system. This localized application of error correction focuses computational resources and energy consumption only on the critical components that require highest reliability, thereby improving privileged subsystem reliability while minimizing overall energy increase.
Data Source
AI summary
The invention relates to a method for fault identification in a System-on-Chip (SoC) consisting of a number of IP cores, wherein each IP core is a fault containment unit, and where the IP cores communicate with one another by means of messages via a Network-on-Chip, and wherein an excellent IP core provides a TRM (Trusted Resource Monitor), wherein a faulty control message which is sent from one non-privileged IP core to another non-privileged IP core is identified and projected by an (independent) fault container unit, as a result of which this faulty control message cannot cause any failure of the message receiver.

