Functional safety for system-on-chip arrangements
A sensor data input chiplet obtains sensor data from a sensor system. A central chiplet executes a functional safety program to dynamically compare and verify output of workloads being executed by a set of workload processing chiplets, where the workloads are executed across the set of workload processing chiplets based on the sensor data.
1 . A computing system, comprising:
a sensor data input chiplet to obtain sensor data from a sensor system;
a set of workload processing chiplets; and
a first central chiplet comprising a shared memory including a functional safety (FuSa) program that causes one or more processors of the first central chiplet to:
dynamically compare and verify output of workloads executed by the set of workload processing chiplets, the workloads being executed across the set of workload processing chiplets based on the sensor data;
a first system-on-chip (SoC) that includes the first central chiplet; and
a second SoC that includes a second central chiplet, the first SoC and the second SoC being communicatively coupled by an interconnect;
wherein the FuSa program is further included in the second central chiplet of the second SoC, the FuSa program included in the second central chiplet of the second SoC causes one or more processors of the second SoC to:
monitor the shared memory of the first central chiplet of the first SoC to dynamically determine whether the first SoC is functioning within nominal operating parameters.
2 . The computing system of claim 1 , wherein the sensor data input chiplet, the first central chiplet, and the set of workload processing chiplets communicate over a performance network comprising a plurality of network hubs, and wherein the FuSa program monitors communications through the plurality of network hubs between the sensor data input chiplet, the first central chiplet, and the one or more workload processing chiplets.
3 . The computing system of claim 2 , wherein the FuSa program monitors communications through the plurality of network hubs using a set of FuSa accounting hubs that communicate over a high-reliability FuSa network.
4 . The computing system of claim 3 , wherein the first central chiplet comprises a dedicated FuSa CPU executing the FuSa program to (i) communicate over the performance network via a performance network-on-chip (NoC), and (ii) communicate over the high-reliability FuSa network via a FuSa NoC.
5 . The computing system of claim 4 , wherein the set of workload processing chiplets transmit (i) processed data to a cache memory of the first central chiplet over the performance network, and (ii) a first error correction code (ECC) along the high-reliability FuSa network to the first central chiplet based on the processed data.
6 . The computing system of claim 5 , wherein upon receiving the processed data, the first central chiplet generates a second ECC using the processed data, and wherein the FuSa CPU performs a functional safety call in the first central chiplet to verify that the first ECC and the second ECC match to ensure that the processed data was transmitted correctly.
7 . The computing system of claim 1 , wherein the computing system is included on a vehicle, and wherein the workloads comprise inference tasks based on the sensor data for autonomously operating the vehicle.
8 . The computing system of claim 1 , wherein the workloads are executed by the set of workload processing chiplets in independent pipelines, and wherein the FuSa program dynamically compares and verifies output of the independent pipelines by executing a set of FuSa workloads in a FuSa pipeline.
9 . The computing system of claim 1 , wherein the FuSa program in the second central chiplet of the second SoC further causes the one or more processors of the second SoC to:
in response to determining that the first SoC is not functioning within nominal operating parameters, cause a second set of workload processing chiplets of the second SoC to take over execution of the workloads.
10 . The computing system of claim 1 , wherein determining that the first SoC is not operating within nominal operating parameters corresponds to one or more of the first SoC overheating, a power surge, or an error in the first SoC.
11 . The computing system of claim 9 , wherein for each respective sensor data item generated by each respective sensor data component of the sensor system, the first SoC generates a cipher associated with the respective sensor data component at which the respective sensor data item originates, and transmits the cipher to the second SoC.
12 . The computing system of claim 11 , wherein, upon determining that the first SoC is not functioning within the nominal operating parameters, the second SoC decrypts the cipher to verify the respective sensor data item to take over execution of the workloads.
13 . A non-transitory computer readable medium storing instructions that, when executed by one or more processors of a computing system, cause the computing system to:
obtain, by a sensor data input chiplet of the computing system, sensor data from a sensor system;
on a first central chiplet of a first system-on-chip (SoC) of the computing system, execute a functional safety program (FuSa) to dynamically compare and verify output of workloads executed by a set of workload processing chiplets, the workloads being executed across the set of workload processing chiplets based on the sensor data; and
on a second central chiplet of a second SoC of the computing system on which the FuSa program is included, monitor a shared memory of the first central chiplet of the first SoC to dynamically determine whether the first SoC is functioning within nominal operating parameters.
14 . The non-transitory computer readable medium of claim 13 , wherein the sensor data input chiplet, the first central chiplet, and the set of workload processing chiplets communicate over a performance network comprising a plurality of network hubs, and wherein the FuSa program monitors communications through the plurality of network hubs between the sensor data input chiplet, the first central chiplet, and the one or more workload processing chiplets.
15 . The non-transitory computer readable medium of claim 14 , wherein the FuSa program monitors communications through the plurality of network hubs using a set of FuSa accounting hubs that communicate over a high-reliability FuSa network.
16 . The non-transitory computer readable medium of claim 15 , wherein the first central chiplet comprises a dedicated FuSa CPU executing the FuSa program to (i) communicate over the performance network via a performance network-on-chip (NoC), and (ii) communicate over the high-reliability FuSa network via a FuSa NoC.
17 . The non-transitory computer readable medium of claim 16 , wherein the set of workload processing chiplets transmit (i) processed data to a cache memory of the first central chiplet over the performance network, and (ii) a first error correction code (ECC) along the high-reliability FuSa network to the first central chiplet based on the processed data.
18 . A computer-implemented method of implementing functional safety on a computing system, the method being performed by one or more processors and comprising:
obtaining, by a sensor data input chiplet of the computing system, sensor data from a sensor system;
on a first central chiplet of a first system-on-chip (SoC) of the computing system, executing a functional safety (FuSa) program to dynamically compare and verify output of workloads executed by a set of workload processing chiplets, the workloads being executed across the set of workload processing chiplets based on the sensor data; and
on a second central chiplet of a second SoC of the computing system on which the FuSa program is included, monitoring a shared memory of the first central chiplet of the first SoC to dynamically determine whether the first SoC is functioning within nominal operating parameters.