IP Library Granted Patent US 12,468,596
Granted Patent B2
US 12,468,596 · App. 18/639,573 · Granted Nov 11, 2025

Temporal buffering of integrity comparison data

Inventors: Eric N. Anderson (Marion, IA); Matthew P. Corbett (Mount Vernon, IA); Jason R. Owen (Marion, IA); Russ D. Uthe (Ely, IA)
Assignee: Rockwell Collins, Inc.
G06F11/079G06F11/0721G06F11/1608G06F11/1629
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,596
App. No.
18/639,573
Granted
Nov 11, 2025
Kind
B2
Abstract

A system-on-chip may include application processing cores which execute safety critical applications and an integrity application. The system-on-chip may also include integrity processing cores which execute an integrity monitor. The integrity monitor may compare integrity application outputs and integrity monitor outputs to detect if the processing cores have experienced a common mode fault. The integrity processing cores may perform temporal monitoring to accommodate time-asynchronization's between the application processing cores and the integrity processing cores.

Claims (41)

1 . A system-on-chip comprising:

one or more application processing cores with a first instruction set architecture, wherein the one or more application processing cores are configured to execute an integrity application and one or more safety critical applications, wherein the integrity application is configured to generate one or more integrity application outputs;

one or more integrity processing cores with a second instruction set architecture, wherein the first instruction set architecture and the second instruction set architecture are different, wherein the one or more integrity processing cores are configured to execute an integrity monitor, wherein the integrity monitor is configured to generate one or more integrity monitor outputs, wherein the integrity monitor is configured to compare the one or more integrity application outputs and the one or more integrity monitor outputs to detect one of a valid-compare or a mis-compare; and

an integrity memory;

wherein the one or more application processing cores and the one or more integrity processing cores are asynchronized, wherein the integrity memory is configured to provide temporal buffering between the one or more integrity application outputs and the one or more integrity monitor outputs when the integrity monitor compares the one or more integrity application outputs and the one or more integrity monitor outputs.

2 . The system-on-chip of claim 1 , wherein the integrity memory maintains a strike counter, wherein the integrity monitor causes the strike counter to increment one or more strikes when the integrity monitor detects the mis-compare.

3 . The system-on-chip of claim 2 , wherein the integrity monitor causes the strike counter to decrement one or more strikes when the integrity monitor detects the valid-compare.

4 . The system-on-chip of claim 3 , wherein the integrity monitor causes the strike counter to increment more strikes for the mis-compare than decrementing strikes for the valid-compare.

5 . The system-on-chip of claim 3 , wherein the integrity monitor causes the strike counter to decrement to zero when the integrity monitor detects the valid-compare.

6 . The system-on-chip of claim 2 , wherein the integrity monitor is configured to increment the strike counter up to a strike counter threshold; wherein the integrity monitor detects a fault at the strike counter threshold.

7 . The system-on-chip of claim 1 , wherein the integrity memory maintains an integrity application output buffer and an integrity monitor output buffer; wherein the integrity memory is configured to provide temporal buffering by the integrity application output buffer and the integrity monitor output buffer; wherein the integrity memory is configured to store the one or more integrity application outputs and the one or more integrity monitor outputs in the integrity application output buffer and the integrity monitor output buffer, respectively; wherein the integrity monitor is configured to compare the one or more integrity application outputs stored in the integrity application output buffer and the one or more integrity monitor outputs stored in the integrity monitor output buffer to detect one of the valid-compare or the mis-compare.

8 . The system-on-chip of claim 7 , wherein the integrity monitor detects the valid-compare when at least one of the one or more integrity application outputs in the integrity application output buffer match at least one of the one or more integrity monitor outputs in the integrity monitor output buffer;

wherein the integrity monitor detects the mis-compare when none of the one or more integrity application outputs in the integrity application output buffer match the one or more integrity monitor outputs in the integrity monitor output buffer.

9 . The system-on-chip of claim 1 , wherein at least one of:

the one or more application processing cores comprise a dual lockstep pair of the one or more application processing cores; or

the one or more integrity processing cores comprise a dual lockstep pair of the one or more integrity processing cores.

10 . The system-on-chip of claim 1 , wherein at least one of:

the one or more application processing cores comprise triple-modular redundancy with three of the one or more application processing cores; or

the one or more integrity processing cores comprise triple modular redundancy with three of the one or more integrity processing cores.

11 . The system-on-chip of claim 1 , wherein the one or more safety critical applications do not include application specific independent integrity checks capable of detection of a common mode failure.

12 . The system-on-chip of claim 1 , comprising one or more communication interfaces, wherein the one or more communication interfaces are configured to provide one or more inputs to the one or more application processing cores and the one or more integrity processing cores.

13 . The system-on-chip of claim 12 , wherein the one or more inputs comprise at least one of air data, position, altitude, attitude, engine data, flight controls, fire warning, cabin pressure, engine thrust, exhaust gas temperature, speed, angle of attack, pitch angle, flight path angle, acceleration, or rate of descent.

14 . The system-on-chip of claim 12 , wherein the integrity application comprises a set of commands, wherein the set of commands use the one or more inputs to exercise the first instruction set architecture used by the one or more safety critical applications.

15 . The system-on-chip of claim 1 , wherein the one or more integrity application outputs and the one or more integrity monitor outputs comprise a direct data output or a computed signature of the direct data output.

16 . The system-on-chip of claim 1 , wherein the integrity monitor is configured to compare the one or more integrity application outputs and the one or more integrity application outputs to detect one of the valid-compare or the mis-compare by one of an exact match or a tolerance match.

17 . The system-on-chip of claim 1 , wherein the integrity monitor is configured to reset the one or more application processing cores and the one or more integrity processing cores upon detecting a fault.

18 . A system-on-chip comprising:

one or more application processing cores with a first instruction set architecture, wherein the one or more application processing cores are configured to execute an integrity application and one or more safety critical applications, wherein the integrity application is configured to generate one or more integrity application outputs, wherein the one or more safety critical applications do not include application specific independent integrity checks capable of detection of a common mode failure;

one or more integrity processing cores with a second instruction set architecture, wherein the first instruction set architecture and the second instruction set architecture are different, wherein the one or more integrity processing cores are configured to execute an integrity monitor, wherein the integrity monitor is configured to generate one or more integrity monitor outputs, wherein the integrity monitor is configured to compare the one or more integrity application outputs and the one or more integrity monitor outputs to detect one of a valid-compare or a mis-compare;

an integrity memory; and

one or more communication interfaces, wherein the one or more communication interfaces are configured to provide one or more inputs to the one or more application processing cores and the one or more integrity processing cores; wherein the integrity application comprises a set of commands, wherein the set of commands use the one or more inputs to exercise the first instruction set architecture used by the one or more safety critical applications;

wherein the one or more application processing cores and the one or more integrity processing cores are asynchronized, wherein the integrity memory is configured to provide temporal buffering between the one or more integrity application outputs and the one or more integrity monitor outputs when the integrity monitor compares the one or more integrity application outputs and the one or more integrity monitor outputs; wherein the integrity memory maintains a strike counter, wherein the integrity monitor causes the strike counter to increment one or more strikes when the integrity monitor detects the mis-compare.

19 . A system-on-chip comprising:

one or more application processing cores with a first instruction set architecture, wherein the one or more application processing cores are configured to execute an integrity application and one or more safety critical applications, wherein the integrity application is configured to generate one or more integrity application outputs, wherein the one or more safety critical applications do not include application specific independent integrity checks capable of detection of a common mode failure;

one or more integrity processing cores with a second instruction set architecture, wherein the first instruction set architecture and the second instruction set architecture are different, wherein the one or more integrity processing cores are configured to execute an integrity monitor, wherein the integrity monitor is configured to generate one or more integrity monitor outputs, wherein the integrity monitor is configured to compare the one or more integrity application outputs and the one or more integrity monitor outputs to detect one of a valid-compare or a mis-compare;

an integrity memory; and

one or more communication interfaces, wherein the one or more communication interfaces are configured to provide one or more inputs to the one or more application processing cores and the one or more integrity processing cores; wherein the integrity application comprises a set of commands, wherein the set of commands use the one or more inputs to exercise the first instruction set architecture used by the one or more safety critical applications;

wherein the one or more application processing cores and the one or more integrity processing cores are asynchronized, wherein the integrity memory is configured to provide temporal buffering between the one or more integrity application outputs and the one or more integrity monitor outputs when the integrity monitor compares the one or more integrity application outputs and the one or more integrity monitor outputs; wherein the integrity memory maintains an integrity application output buffer and an integrity monitor output buffer; wherein the integrity memory is configured to provide temporal buffering by the integrity application output buffer and the integrity monitor output buffer;

wherein the integrity memory is configured to store the one or more integrity application outputs and the one or more integrity monitor outputs in the integrity application output buffer and the integrity monitor output buffer, respectively; wherein the integrity monitor is configured to compare the one or more integrity application outputs stored in the integrity application output buffer and the one or more integrity monitor outputs stored in the integrity monitor output buffer to detect one of the valid-compare or the mis-compare.

20 . The system-on-chip of claim 19 , wherein the integrity monitor detects the valid-compare when at least one of the one or more integrity application outputs in the integrity application output buffer match at least one of the one or more integrity monitor outputs in the integrity monitor output buffer;

wherein the integrity monitor detects the mis-compare when none of the one or more integrity application outputs in the integrity application output buffer match the one or more integrity monitor outputs in the integrity monitor output buffer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2024
From: ANDERSON, ERIC N.; CORBETT, MATTHEW P.; OWEN, JASON R.; UTHE, RUSS D.
To: ROCKWELL COLLINS, INC.
Reel/Frame 067155/0881 →
Continuity (1)
Related Publication 20250328408A1 · Oct 23, 2025
References Cited (74)
US 4245344A · Richter · 1981 [cited by applicant]
US 4254492A · McDermott, III · 1981 [cited by applicant]
US 4328583A · Stodola · 1982 [cited by applicant]
US 4342112A · Stodola · 1982 [cited by applicant]
US 4371754A · De et al. · 1983 [cited by applicant]
US 4750181A · McDonald et al. · 1988 [cited by applicant]
US 5170401A · Mohr · 1992 [cited by applicant]
US 5355090A · Pajowski et al. · 1994 [cited by applicant]
US 6002970A · Abdelnour et al. · 1999 [cited by applicant]
US 6883121B1 · Jensen et al. · 2005 [cited by applicant]
US 6895582B1 · Greve · 2005 [cited by applicant]
US 6948091B2 · Bartels et al. · 2005 [cited by applicant]
US 7027880B2 · Izzo et al. · 2006 [cited by applicant]
US 7320064B2 · Ramos et al. · 2008 [cited by applicant]
US 7392426B2 · Wolfe et al. · 2008 [cited by applicant]
US 7565586B2 · Thompson · 2009 [cited by applicant]
US 7679403B2 · Erstad · 2010 [cited by applicant]
US 7809863B2 · Beutler et al. · 2010 [cited by applicant]
US 7852235B1 · Johnson et al. · 2010 [cited by applicant]
US 8015390B1 · Corcoran et al. · 2011 [cited by applicant]
US 8301867B1 · Mazuk et al. · 2012 [cited by applicant]
US 8743020B1 · Mazuk et al. · 2014 [cited by applicant]
US 9137038B1 · Mazuk et al. · 2015 [cited by applicant]
US 9256486B2 · Saito · 2016 [cited by applicant]
US 9454418B1 · Kovalan et al. · 2016 [cited by applicant]
US 9552271B1 · Fetta et al. · 2017 [cited by applicant]
US 9714081B1 · Hall, III et al. · 2017 [cited by applicant]
US 9891978B1 · Fejfar et al. · 2018 [cited by applicant]
US 9964937B2 · Koh · 2018 [cited by applicant]
US 9973515B1 · Corbett et al. · 2018 [cited by applicant]
US 10114777B1 · Owen et al. · 2018 [cited by applicant]
US 10144529B1 · Fetta et al. · 2018 [cited by applicant]
US 10242179B1 · Corbett et al. · 2019 [cited by applicant]
US 10345801B2 · Dehaas et al. · 2019 [cited by applicant]
US 10372901B1 · Marek · 2019 [cited by applicant]
US 10447588B1 · Fannin et al. · 2019 [cited by applicant]
US 10452446B1 · Bloom et al. · 2019 [cited by applicant]
US 10454656B1 · Nelson et al. · 2019 [cited by applicant]
US 10466702B1 · Bloom et al. · 2019 [cited by applicant]
US 10541944B1 · Nelson et al. · 2020 [cited by applicant]
US 10579469B2 · Geng et al. · 2020 [cited by applicant]
US 10719356B1 · Corbett et al. · 2020 [cited by applicant]
US 10771194B2 · Tune et al. · 2020 [cited by applicant]
US 10901865B2 · Bryant et al. · 2021 [cited by applicant]
US 10909006B2 · Ainsworth et al. · 2021 [cited by applicant]
US 10970154B2 · Grimm · 2021 [cited by applicant]
US 11003196B2 · Li et al. · 2021 [cited by applicant]
US 11029706B2 · Li et al. · 2021 [cited by applicant]
US 11181957B1 · Prasadh et al. · 2021 [cited by applicant]
US 11200312B1 · Greve et al. · 2021 [cited by applicant]
US 11224094B1 · Corbett et al. · 2022 [cited by applicant]
US 11243504B2 · Wrobel et al. · 2022 [cited by applicant]
US 11263073B2 · Boettcher et al. · 2022 [cited by applicant]
US 11372981B2 · Bean et al. · 2022 [cited by applicant]
US 11494256B2 · Meriac et al. · 2022 [cited by applicant]
US 11556113B2 · Izzo et al. · 2023 [cited by applicant]
US 11586497B1 · Geist · 2023 [cited by examiner]
US 11591092B2 · Horner · 2023 [cited by applicant]
US 11780603B2 · Hooker · 2023 [cited by applicant]
US 20060236168A1 · Wolfe et al. · 2006 [cited by applicant]
US 20070220367A1 · Smith et al. · 2007 [cited by applicant]
US 20080005706A1 · Sharma · 2008 [cited by examiner]
US 20190114243A1 · Santoni · 2019 [cited by examiner]
US 20200089559A1 · Ainsworth et al. · 2020 [cited by applicant]
US 20200145251A1 · Hass · 2020 [cited by examiner]
US 20210064234A1 · Zhang et al. · 2021 [cited by applicant]
US 20210373898A1 · Selwan · 2021 [cited by examiner]
US 20230356730A1 · Schmidt · 2023 [cited by applicant]
US 20240231900A1 · Kamaraj · 2024 [cited by examiner]
H. D. Doran and T. Lang, “Dynamic Lockstep Processors for Applications with Functional Safety Relevance,” 2021 26th IEEE International Conference on Emerging Technologies and Factory Automation (ETFA ), Vasteras, Sweden… [cited by examiner]
Y. C. Yeh, “Triple-triple redundant 777 primary flight computer,” 1996 IEEE Aerospace Applications Conference. Proceedings, Aspen, CO, USA, 1996, pp. 293-307 vol. 1 (Year: 1996). [cited by examiner]
Sim et al.; A Dual Lockstep Processor System-on-a-Chip for Fast Error Recovery in Safety-Critical Applications; 2020; IEEE (Year: 2020). [cited by examiner]
Jeffrey Voas et al. “Reducing Uncertainty About Common-Mode Failures”, Published Jan. 1, 1997; retrieved; Feb. 26, 2024; https://apps.dtic.mil/sti/pdfs/ADA465215.pdf. [cited by applicant]
Steven L. Hogan, “Effective Fault Management Guidelines”, published Jun. 5, 2009; retrieved on Feb. 26, 2024; https://aerospace.org/sites/default/files/maiw/TOR-2009(8591)-14.pdf. [cited by applicant]