Isolated safety region of a system on a chip
In various examples, an integrated circuit includes first and second portions. The first portion includes a timer that starts when the first portion transmits at least one error signal to the second portion. The timer may reset when data corresponding to at least one fault has been cleared from the first portion. The first portion transmits a timeout error signal when the timer indicates at least a predetermined amount of time has elapsed. The second portion receives the at least one error signal and the timeout error signal when the timeout error signal has been sent. The second portion may notify an external system after the timeout error signal is received.
1 . A system on a chip (“SoC”) comprising:
one or more first hardware components associated with performing one or more functional safety operations; and
one or more second hardware components associated with performing one or more control operations, the one or more first hardware components being electrically isolated on the SoC from the one or more second hardware components such that the one or more first hardware components are capable of achieving a higher safety integrity level than the one or more second hardware components.
2 . The SoC of claim 1 , wherein the one or more second hardware components are to operate at an Automotive Safety Integrity Level (“ASIL”) B or lower as defined by an International Organization for Standardization (“ISO”) 26262 Functional Safety Standard.
3 . The SoC of claim 1 , wherein the one or more first hardware components are to operate at an ASIL-D as defined by the ISO 26262 Functional Safety Standard.
4 . The SoC of claim 1 , wherein the one or more control operations are to at least partially implement a level of driving autonomy within a range extending from Level 2 to Level 5 as defined by Society of Automotive Engineers (“SAE”).
5 . The SoC of claim 1 , wherein performance of the one or more functional safety operations is to help transition a machine to a safe state in response to at least one fault that originated from performance of the one or more control operations.
6 . The SoC of claim 1 , wherein data is to be stored in a first memory address in the one or more second hardware components, and
the one or more functional safety operations are to determine a second memory address in the one or more second hardware components in which to store an error detection code obtained for the data.
7 . The SoC of claim 1 , wherein the one or more first hardware components are electrically isolated from the one or more second hardware components such that an outage occurring in the one or more second hardware components does not affect the one or more first hardware components.
8 . The SoC of claim 1 , wherein the one or more first hardware components are connected by one or more first electrical conductors to at least one power supply, and the one or more second hardware components are connected by one or more second electrical conductors to the at least one power supply.
9 . A system comprising:
a first hardware component to perform one or more control operations associated with a machine; and
a second hardware component external to and electrically isolated from the first hardware component, the second hardware component to perform one or more safety-related operations associated with the machine, wherein the second hardware component is capable of satisfying a higher safety level than the first hardware component based at least on the second hardware component being external from the first hardware component.
10 . The system of claim 9 , wherein the system is comprised in a system on a chip (“SoC”).
11 . The system of claim 9 , wherein the system is comprised in an autonomous or semi-autonomous vehicle.
12 . The system of claim 9 , wherein the first hardware component is to operate at an Automotive Safety Integrity Level (“ASIL”) B or lower as defined by an International Organization for Standardization (“ISO”) 26262 Functional Safety Standard, and
the second hardware component is to operate at an ASIL-D as defined by the ISO 26262 Functional Safety Standard.
13 . The system of claim 9 , wherein the second hardware component is to transition the machine to a safe state in response to at least one fault received from the first hardware component.
14 . The system of claim 9 , wherein data is to be stored in a first memory address in the first hardware component, and
the second hardware component is to determine a second memory address in the first hardware component in which to store an error detection code obtained for the data.
15 . The system of claim 9 , wherein the first hardware component is connected by a first electrical conductor to a power supply, and the second hardware component is connected by a different second electrical conductor to the power supply.
16 . A method comprising:
performing one or more first operations of a first type using first processing circuitry capable of achieving a first safety integrity level; and
performing one or more second operations of a second type using second processing circuitry capable of achieving a second safety integrity level higher than the first safety integrity level, wherein the second safety integrity level is achievable due to the second processing circuitry being isolated electrically from the first processing circuitry.
17 . The method of claim 16 , wherein the first processing circuitry and the second processing circuitry are components of a system on a chip (“SoC”).
18 . The method of claim 16 , wherein the one or more first operations are to be performed by an autonomous or semi-autonomous vehicle.
19 . The method of claim 16 , wherein the first safety integrity level is Automotive Safety Integrity Level (“ASIL”) B or lower as defined by an International Organization for Standardization (“ISO”) 26262 Functional Safety Standard, and
the second safety integrity level is ASIL-D as defined by the ISO 26262 Functional Safety Standard.
20 . The method of claim 16 , wherein the one or more second operations comprise transitioning a machine comprising the first processing circuitry and the second processing circuitry to a safe state.
21 . The method of claim 16 , further comprising:
storing data in a first memory address of the first processing circuitry;
using the second processing circuitry to determine an error detection code based at least in part on at least one of the data and the first memory address; and
using the second processing circuitry to determine a second memory address of the first processing circuitry in which to store the error detection code.