EP3274835A1 - Verfahren und vorrichtung zur fehlerfeststellung bei einem prozessor, der ein sicherheitsrelevantes programm ausführt - Google Patents
Verfahren und vorrichtung zur fehlerfeststellung bei einem prozessor, der ein sicherheitsrelevantes programm ausführtInfo
- Publication number
- EP3274835A1 EP3274835A1 EP16723320.4A EP16723320A EP3274835A1 EP 3274835 A1 EP3274835 A1 EP 3274835A1 EP 16723320 A EP16723320 A EP 16723320A EP 3274835 A1 EP3274835 A1 EP 3274835A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- processor
- output values
- program
- safety
- test program
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/22—Detection or location of defective computer hardware by testing during standby operation or during idle time, e.g. start-up testing
- G06F11/2205—Detection or location of defective computer hardware by testing during standby operation or during idle time, e.g. start-up testing using arrangements specific to the hardware being tested
- G06F11/2236—Detection or location of defective computer hardware by testing during standby operation or during idle time, e.g. start-up testing using arrangements specific to the hardware being tested to test CPU or processors
Definitions
- the invention relates to a method for error detection in a processor that executes a security-related program and a related device.
- error detection in the arithmetic unit of the processor in particular a CPU - Central Processing Unit - is in many areas of technology with safety-relevant orientation, such as railway signaling, vehicle construction, traffic control and monitoring, industrial plant and medical technology, required or at least desirable.
- the correct execution of the security-related program that is, the software that runs on the processor, sets the correct execution of the machine code of the processor vo ⁇ out.
- An error in a machine code instruction generates data processing errors or program execution errors. This can cause significant distortions of the program result.
- redundant design is common.
- processor functions can be simulated. According to a known method, the object code, that is, the binary representation of the processor instructions, is analyzed byte by byte until these bytes can be uniquely mapped to a processor instruction. Then the ser ⁇ processor command is applied to associated, emulated processor components.
- the method is based on the emulation of the processor main memory, and application of the emulated Prozes ⁇ sorbetatione to associated, also emulated Listeorkom- components.
- An emulation is the ability of a program to simulate the operation of a processor with software means. These software tools, which are also called emulators, load the object code, that is, the program of the processor in a working ⁇ store, in order to subsequently, starting with a defined position, byte by byte to interpret this object code. The command structures obtained from this interpretation are then applied to the likewise emulated processor components, in particular registers, memory cells, input / output modules and subcomponents. In this way, processor functions can be simulated, whereby faulty processor instructions can be identified.
- a disadvantage of this known method is, in addition to the considerable expense above all, that results from the byte-by-byte interpretation of the executed object code low performance.
- the invention has for its object to provide a method and apparatus of the generic type, which allow a highly secure and early detection of a processor-related error.
- the object is achieved in that the processor carries out a test program in computing pauses of the safety-relevant program whose output values are compared by means of an external device with expected values, wherein mismatch triggers an error response.
- the object is achieved according to claim 7 also by a device in which it is provided that the processor is connected to an external device having a memory and a comparator, the comparator for comparison of output values of one in computing pauses the .srele- vanten Program in the processor running test program is formed with stored in the memory expectation values and means for triggering an error response in case of disagreement of the output values with the expected values.
- the test program runs in the pauses or waiting loops of the safety-related program on the processor and generates output values, which are tested by the external Ge ⁇ advised to expectation. If the output values do not match the expected values, the external device triggers a shutdown or blockage of the faulty processor.
- the external device can be constructed relatively simple, namely essentially with fuse-reliable memory modules and
- test program can according to the requirements of the
- the evaluation by the external device, ie, the avoidance of a self-test by means of the processor is dage ⁇ gen indispensable because a faulty processor can also lead to a false negative test result.
- the test program determines decimal places of an irrational number as output values by means of a trickle algorithm. Through the trickle algorithm can the irrational number, for example ⁇ , decimal places are calculated for decimal places without having stored the already calculated values.
- the test program calculates Minim ⁇ least one decimal in ei ⁇ ner computing break the security program and continues to calculate the after ⁇ following decimals with each new computation break.
- test program with the expiration of the safety-related program is so closely interlaced or intertwined that the test program can be scheduled, can also be determined by the external device, whether the safety-related program was virtually displaced in its course.
- Ausga ⁇ ben deliberately false decimal error response can be initiated directly and from the safety-related program.
- the number of output values of the test program by means of the external device is compared with the number of output values to be expected in the pause of the safety-relevant program, wherein mismatch triggers an error response.
- the output values must agree not only with their value, for example the digit of the decimal place, but also with regard to the number of output values calculated in a certain time with expected values, which results in a further increase in safety.
- test program is determined according to a sequence of output values corresponding to a test reset and generate a next series of output values. After a useful large number of output values within a sequence, in particular digits of an irrational number according to claim 2, the program strigpro- resets and starts the next sequence of output ⁇ values corresponding to the test plan.
- Each new sequence may, for example, refer to the calculation of a certain number of decimal places of another irrational number. In this way, the repetition of output values in the same sequence and thus the possibility that processor errors remain undetected, quasi excluded.
- the test program is according to claim 6 so he ⁇ represents that the largest possible number of different machine-code instructions of the processor is activated.
- the test program is so complicated that a large amount of different machine code commands to calculate the
- Output values must contribute.
- the output values are not randomly computable for a long time from stored, repeated or arbitrarily generated values, so that randomly correct output is nearly impossible.
Landscapes
- Engineering & Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Quality & Reliability (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Test And Diagnosis Of Digital Computers (AREA)
- Debugging And Monitoring (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102015209530.4A DE102015209530A1 (de) | 2015-05-22 | 2015-05-22 | Verfahren und Vorrichtung zur Fehlerfeststellung bei einem Prozessor, der ein sicherheitsrelevantes Programm ausführt |
| PCT/EP2016/060452 WO2016188736A1 (de) | 2015-05-22 | 2016-05-10 | Verfahren und vorrichtung zur fehlerfeststellung bei einem prozessor, der ein sicherheitsrelevantes programm ausführt |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3274835A1 true EP3274835A1 (de) | 2018-01-31 |
Family
ID=56014976
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP16723320.4A Withdrawn EP3274835A1 (de) | 2015-05-22 | 2016-05-10 | Verfahren und vorrichtung zur fehlerfeststellung bei einem prozessor, der ein sicherheitsrelevantes programm ausführt |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP3274835A1 (de) |
| DE (1) | DE102015209530A1 (de) |
| WO (1) | WO2016188736A1 (de) |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8799713B2 (en) * | 2011-03-01 | 2014-08-05 | Texas Instruments Incorporated | Interruptible non-destructive run-time built-in self-test for field testing |
-
2015
- 2015-05-22 DE DE102015209530.4A patent/DE102015209530A1/de not_active Withdrawn
-
2016
- 2016-05-10 EP EP16723320.4A patent/EP3274835A1/de not_active Withdrawn
- 2016-05-10 WO PCT/EP2016/060452 patent/WO2016188736A1/de not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| DE102015209530A1 (de) | 2016-11-24 |
| WO2016188736A1 (de) | 2016-12-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE60309928T2 (de) | Verfahren zur erhöhung der sicherheitsintegritätsstufe eines kontrollsystems | |
| DE69831732T2 (de) | Verfahren und gerät zum korrigieren von fehlern in einem rechnersystem | |
| EP3841438B1 (de) | Automatisierungssystem zur überwachung eines sicherheitskritischen prozesses | |
| EP3770766B1 (de) | Verfahren zum testen eines systems | |
| EP2852896A2 (de) | Anordnung mit einem mikroprozessorsystem | |
| DE102009050161A1 (de) | Verfahren und Vorrichtung zum Testen eines Systems mit zumindest einer Mehrzahl von parallel ausführbaren Softwareeinheiten | |
| WO2005045665A1 (de) | Verfahren und vorrichtung zur operandenverarbeitung in einer prozessoreinheit | |
| EP3349082B1 (de) | System zur abschaltbaren simulation von anlagen oder maschinen innerhalb von speicherprogrammierbaren steuerungen | |
| WO2010049339A1 (de) | Vorrichtung und verfahren zur generierung redundanter, aber unterschiedlicher maschinencodes aus einem quellcode zur verifizierung für ein sicherheitskritisches system | |
| DE112013006981T5 (de) | Steuersystem Prüfmittel | |
| EP3274835A1 (de) | Verfahren und vorrichtung zur fehlerfeststellung bei einem prozessor, der ein sicherheitsrelevantes programm ausführt | |
| WO2017080793A2 (de) | Verfahren zum betrieb eines mehrkernprozessors | |
| DE102022208087A1 (de) | Verfahren zum Überprüfen einer Verarbeitung von Nutzdaten | |
| DE102009047724A1 (de) | Verfahren zur Programmlaufkontrolle | |
| EP3841439B1 (de) | Automatisierungssystem zur überwachung eines sicherheitskritischen prozesses | |
| DE102021132235A1 (de) | Verfahren zur Simulation eines Steuergeräts auf einem Computer auf der Grundlage des AUTOSAR-Standards und Computer dafür | |
| EP3314412B1 (de) | Verfahren zum debugging von softwarekomponenten in einem verteilten zeitgesteuerten echtzeitsystem | |
| WO2016206847A1 (de) | Verfahren und vorrichtung zum absichern einer programmzählerstruktur eines prozessorsystems und zum überwachen der behandlung einer unterbrechungsanfrage | |
| EP2653850B1 (de) | Verfahren und IT-System zum Durchführen von Gesamtfahrzeugtests | |
| DE102007028721A1 (de) | Verfahren und Vorrichtung zur Verifizierung von Funktionsabläufen in einem Steuergerät | |
| DE102022117470A1 (de) | Verfahren zum Charakterisieren von Testergebnissen | |
| EP2869143B1 (de) | Emulationssystem zur Simulation eines technischen Systems | |
| EP4092535B1 (de) | Verfahren zum testen von steuergeräten | |
| DE19805819B4 (de) | Verfahren zur Überwachung von integrierten Schaltkreisen | |
| DE102022127868A1 (de) | Verfahren zum Durchführen einer Simulation |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20171025 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: SIEMENS MOBILITY GMBH |
|
| 17Q | First examination report despatched |
Effective date: 20190214 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20190725 |