IP Library Granted Patent US 12,630,191
Granted Patent B2
US 12,630,191 · App. 18/668,534 · Granted May 19, 2026

Isolated safety region of a system on a chip

Inventors: Padam Patt Krishnani (Bangalore, IN); Avinash J V (Bangalore, IN); Shraddha Manohar Gondkar (San Jose, CA); Sowmya Satya Venkata Naga Siva Sai Bindu Mandapati (Atchutapuram, IN)
Assignee: NVIDIA CORPORATION
B60W60/0016B60W50/0205B60W50/0225G06F11/0739G06F11/0757G06F11/0772G06F11/0793G07C5/008
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,630,191
App. No.
18/668,534
Granted
May 19, 2026
Kind
B2
Abstract

In various examples, an integrated circuit includes first and second portions. The first portion includes a timer that starts when the first portion transmits at least one error signal to the second portion. The timer may reset when data corresponding to at least one fault has been cleared from the first portion. The first portion transmits a timeout error signal when the timer indicates at least a predetermined amount of time has elapsed. The second portion receives the at least one error signal and the timeout error signal when the timeout error signal has been sent. The second portion may notify an external system after the timeout error signal is received.

Claims (34)

1 . A system on a chip (“SoC”) comprising:

one or more first hardware components associated with performing one or more functional safety operations; and

one or more second hardware components associated with performing one or more control operations, the one or more first hardware components being electrically isolated on the SoC from the one or more second hardware components such that the one or more first hardware components are capable of achieving a higher safety integrity level than the one or more second hardware components.

2 . The SoC of claim 1 , wherein the one or more second hardware components are to operate at an Automotive Safety Integrity Level (“ASIL”) B or lower as defined by an International Organization for Standardization (“ISO”) 26262 Functional Safety Standard.

3 . The SoC of claim 1 , wherein the one or more first hardware components are to operate at an ASIL-D as defined by the ISO 26262 Functional Safety Standard.

4 . The SoC of claim 1 , wherein the one or more control operations are to at least partially implement a level of driving autonomy within a range extending from Level 2 to Level 5 as defined by Society of Automotive Engineers (“SAE”).

5 . The SoC of claim 1 , wherein performance of the one or more functional safety operations is to help transition a machine to a safe state in response to at least one fault that originated from performance of the one or more control operations.

6 . The SoC of claim 1 , wherein data is to be stored in a first memory address in the one or more second hardware components, and

the one or more functional safety operations are to determine a second memory address in the one or more second hardware components in which to store an error detection code obtained for the data.

7 . The SoC of claim 1 , wherein the one or more first hardware components are electrically isolated from the one or more second hardware components such that an outage occurring in the one or more second hardware components does not affect the one or more first hardware components.

8 . The SoC of claim 1 , wherein the one or more first hardware components are connected by one or more first electrical conductors to at least one power supply, and the one or more second hardware components are connected by one or more second electrical conductors to the at least one power supply.

9 . A system comprising:

a first hardware component to perform one or more control operations associated with a machine; and

a second hardware component external to and electrically isolated from the first hardware component, the second hardware component to perform one or more safety-related operations associated with the machine, wherein the second hardware component is capable of satisfying a higher safety level than the first hardware component based at least on the second hardware component being external from the first hardware component.

10 . The system of claim 9 , wherein the system is comprised in a system on a chip (“SoC”).

11 . The system of claim 9 , wherein the system is comprised in an autonomous or semi-autonomous vehicle.

12 . The system of claim 9 , wherein the first hardware component is to operate at an Automotive Safety Integrity Level (“ASIL”) B or lower as defined by an International Organization for Standardization (“ISO”) 26262 Functional Safety Standard, and

the second hardware component is to operate at an ASIL-D as defined by the ISO 26262 Functional Safety Standard.

13 . The system of claim 9 , wherein the second hardware component is to transition the machine to a safe state in response to at least one fault received from the first hardware component.

14 . The system of claim 9 , wherein data is to be stored in a first memory address in the first hardware component, and

the second hardware component is to determine a second memory address in the first hardware component in which to store an error detection code obtained for the data.

15 . The system of claim 9 , wherein the first hardware component is connected by a first electrical conductor to a power supply, and the second hardware component is connected by a different second electrical conductor to the power supply.

16 . A method comprising:

performing one or more first operations of a first type using first processing circuitry capable of achieving a first safety integrity level; and

performing one or more second operations of a second type using second processing circuitry capable of achieving a second safety integrity level higher than the first safety integrity level, wherein the second safety integrity level is achievable due to the second processing circuitry being isolated electrically from the first processing circuitry.

17 . The method of claim 16 , wherein the first processing circuitry and the second processing circuitry are components of a system on a chip (“SoC”).

18 . The method of claim 16 , wherein the one or more first operations are to be performed by an autonomous or semi-autonomous vehicle.

19 . The method of claim 16 , wherein the first safety integrity level is Automotive Safety Integrity Level (“ASIL”) B or lower as defined by an International Organization for Standardization (“ISO”) 26262 Functional Safety Standard, and

the second safety integrity level is ASIL-D as defined by the ISO 26262 Functional Safety Standard.

20 . The method of claim 16 , wherein the one or more second operations comprise transitioning a machine comprising the first processing circuitry and the second processing circuitry to a safe state.

21 . The method of claim 16 , further comprising:

storing data in a first memory address of the first processing circuitry;

using the second processing circuitry to determine an error detection code based at least in part on at least one of the data and the first memory address; and

using the second processing circuitry to determine a second memory address of the first processing circuitry in which to store the error detection code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2024
From: KRISHNANI, PADAM PATT; J V, AVINASH; GONDKAR, SHRADDHA MANOHAR; MANDAPATI, SOWMYA SATYA VENKATA NAGA SIVA SAI BINDU
To: NVIDIA CORPORATION
Reel/Frame 067462/0358 →
Priority Claims (1)
IN 202111034493 · Jul 30, 2021 · national
Continuity (2)
Continuation 17477225 · Sep 16, 2021
Related Publication 20240300537A1 · Sep 12, 2024
References Cited (48)
US 8138623B2 · Rofougaran · 2012 [cited by applicant]
US 8520400B2 · Rofougaran · 2013 [cited by applicant]
US 8649240B2 · McCombs · 2014 [cited by applicant]
US 9118310B1 · Ganusov et al. · 2015 [cited by applicant]
US 9158319B2 · Gowda et al. · 2015 [cited by applicant]
US 9891978B1 · Fejfar · 2018 [cited by examiner]
US 10014041B1 · Khare et al. · 2018 [cited by applicant]
US 10140615B2 · Carpenter et al. · 2018 [cited by applicant]
US 10324521B2 · Nishijima et al. · 2019 [cited by applicant]
US 10885698B2 · Muthler et al. · 2021 [cited by applicant]
US 11003618B1 · Constantinides et al. · 2021 [cited by applicant]
US 11061453B1 · Ruiz et al. · 2021 [cited by applicant]
US 11204857B2 · Woo · 2021 [cited by applicant]
US 11217323B1 · Sharma et al. · 2022 [cited by applicant]
US 11650585B1 · Aschbacher et al. · 2023 [cited by applicant]
US 20070055421A1 · Bauerle et al. · 2007 [cited by applicant]
US 20140040695A1 · Iwasaki · 2014 [cited by applicant]
US 20150112730A1 · Binion et al. · 2015 [cited by applicant]
US 20150212952A1 · Wegner · 2015 [cited by examiner]
US 20160092306A1 · Benedict et al. · 2016 [cited by applicant]
US 20180050704A1 · Bao et al. · 2018 [cited by applicant]
US 20190205489A1 · de Lescure et al. · 2019 [cited by applicant]
US 20190235943A1 · Gordani · 2019 [cited by applicant]
US 20190243736A1 · Lee · 2019 [cited by applicant]
US 20190258251A1 · Ditty et al. · 2019 [cited by applicant]
US 20190265703A1 · Hicok · 2019 [cited by examiner]
US 20190324422A1 · Capodanno et al. · 2019 [cited by applicant]
US 20200104204A1 · Nautiyal et al. · 2020 [cited by applicant]
US 20200264924A1 · Park et al. · 2020 [cited by applicant]
US 20210089453A1 · Hayakawa et al. · 2021 [cited by applicant]
US 20210119780A1 · Hassan et al. · 2021 [cited by applicant]
US 20210208189A1 · Flores et al. · 2021 [cited by applicant]
US 20210237752A1 · Ewert · 2021 [cited by applicant]
US 20210331686A1 · Beyers et al. · 2021 [cited by applicant]
US 20220126864A1 · Moustafa et al. · 2022 [cited by applicant]
US 20220227379A1 · Robinson et al. · 2022 [cited by applicant]
DE 102011075182A1 · 2011 [cited by applicant]
DE 102019102573A1 · 2019 [cited by applicant]
WO 2018193449A1 · 2018 [cited by applicant]
WO 2019094843A1 · 2019 [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2022/038405, mailed Oct. 28, 2022, filed Jul. 26, 2022, 12 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/US2022/038404, mailed Jan. 11, 2023, filed Jul. 26, 2022, 22 pages. [cited by applicant]
Society of Automotive Engineers On-Road Automated Vehicle Standards Committee, “Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles,” Standard No. J3016-201609, issued Jan… [cited by applicant]
Society of Automotive Engineers On-Road Automated Vehicle Standards Committee, “Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles,” Standard No. J3016-201806, issued Jan… [cited by applicant]
Cao, Dong, “Application of Logic Relation Based on Security in PLC Programming,” China Molybdenum Industry, vol. 40 No. 6, Dec. 2016, 3 Pages. [cited by applicant]
Office Action for Chinese Application No. 202210868989.2, mailed Jul. 23, 2025, 26 pages. [cited by applicant]
Office Action for Chinese Application No. 202210868989.2, mailed Dec. 8, 2025, 21 pages. [cited by applicant]
Office Action for Chinese Application No. 202210868989.2, mailed Feb. 26, 2026, 21 pages. [cited by applicant]