The ROM Bank entry has only one bit indicating duplication with voter (bit set
to 1) or linear (bit set to 0), as the simulator features only two memory modules. All
banks have fixed addresses in the memory space, with ROM bank 1 starting at
address 0 and bank 2 continuing adjacent to bank 1. At system boot up, the
processor starts executing code from address 0, which means that bank 0 must
always be populated with at least a single ROM module. The same applies for the
memory banks. Every bank has its own unique address, with all memory banks
being adjacent in the address space.
The power management area reflects the power status of the hardware components. For every component (RAM, Devices, etc.), the power can be enabled or
disabled. If the power is disabled, the device is ideally also physically isolated, for
fault containment.
The power settings for every device (one bit per device in the register syndrome
power configuration) are as follows: 0 = Power Off; 1 = Power On. Note that the
power and memory bank configuration are tightly connected. A memory chip
module can only be used in one of the memory configurations if it is powered on.
The combination of those three areas: fault, configuration, and power management determines the state and configuration of the system and every component.
However, the syndrome is only capable to signal faults but gives no details about
the fault type (malfunction, permanent fault). Therefore, additional diagnosis routines are required to distinguish the fault type. In case of a permanent fault, software
support is required to reconfigure the system, and the software can replicate the
syndrome in software to keep the current system state or to track changes.
Without doubt, the syndrome is one the most critical parts of the system. For
reliability purposes, we suggest using internal three copies of the three syndrome
registers connected to a voter. Without this replication, a bit flip in the faults area of
the syndrome would lead to wrongly initiated fault processing, or even worse,
undetected faults, whereas a bit flip in the configuration area would likely end up in
a catastrophic failure.
The same applies for misbehaving software. If an undetected fault affects the
software in a way that the processor accidentally writes a value in the configuration
section, the result could be a dead system. To prevent this, a special access pattern
is used, which we explain later in this chapter.
7.3.1 Access and Location of the Syndrome
Triplication of the syndrome registers involves more complexity in terms of logic.
In addition, the voters are vulnerable as well (unless we have triplicated voters as
well). Low-level hardening could be used for the syndrome registers and voters to
decrease the complexity but this would need an adapted manufacturing process and
would therefore result in much higher costs.
92
7 Testing, Checking, and Hardware Syndrome
to 1) or linear (bit set to 0), as the simulator features only two memory modules. All
banks have fixed addresses in the memory space, with ROM bank 1 starting at
address 0 and bank 2 continuing adjacent to bank 1. At system boot up, the
processor starts executing code from address 0, which means that bank 0 must
always be populated with at least a single ROM module. The same applies for the
memory banks. Every bank has its own unique address, with all memory banks
being adjacent in the address space.
The power management area reflects the power status of the hardware components. For every component (RAM, Devices, etc.), the power can be enabled or
disabled. If the power is disabled, the device is ideally also physically isolated, for
fault containment.
The power settings for every device (one bit per device in the register syndrome
power configuration) are as follows: 0 = Power Off; 1 = Power On. Note that the
power and memory bank configuration are tightly connected. A memory chip
module can only be used in one of the memory configurations if it is powered on.
The combination of those three areas: fault, configuration, and power management determines the state and configuration of the system and every component.
However, the syndrome is only capable to signal faults but gives no details about
the fault type (malfunction, permanent fault). Therefore, additional diagnosis routines are required to distinguish the fault type. In case of a permanent fault, software
support is required to reconfigure the system, and the software can replicate the
syndrome in software to keep the current system state or to track changes.
Without doubt, the syndrome is one the most critical parts of the system. For
reliability purposes, we suggest using internal three copies of the three syndrome
registers connected to a voter. Without this replication, a bit flip in the faults area of
the syndrome would lead to wrongly initiated fault processing, or even worse,
undetected faults, whereas a bit flip in the configuration area would likely end up in
a catastrophic failure.
The same applies for misbehaving software. If an undetected fault affects the
software in a way that the processor accidentally writes a value in the configuration
section, the result could be a dead system. To prevent this, a special access pattern
is used, which we explain later in this chapter.
7.3.1 Access and Location of the Syndrome
Triplication of the syndrome registers involves more complexity in terms of logic.
In addition, the voters are vulnerable as well (unless we have triplicated voters as
well). Low-level hardening could be used for the syndrome registers and voters to
decrease the complexity but this would need an adapted manufacturing process and
would therefore result in much higher costs.
92
7 Testing, Checking, and Hardware Syndrome
