Asynchronous Fault Interface for SoC Safety-Critical Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional fault handling systems in safety-relevant integrated circuits face challenges with high-frequency synchronous interfaces that increase backend routing complexity and timing constraints, particularly in systems-on-a-chip (SoCs) with multiple processor cores and safety-critical applications, where fault information needs to be efficiently communicated across distributed resources.
Innovation Solution
Implementing an asynchronous fault interface that uses handshaking signals instead of clock-synchronized communication, filtering out false faults, and reducing clock signal routing, while adapting synchronous fault signals to asynchronous interfaces for efficient fault information transfer between local and central fault collection units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If synchronous fault interface signals are used for fault communication, then fault detection reliability is improved, but backend routing complexity and timing constraints increase
Solution Approach 1:
An asynchronous fault interface circuit is introduced as an intermediary component between the synchronous fault signal source and the fault collection unit. This circuit includes an edge detector that captures fault signals on the rising edge of a clock, a flip-flop that stores the fault indication and domain identifier, and an asynchronous interface that transfers these values without requiring synchronized clock routing. This intermediary structure maintains fault detection reliability while eliminating the need for complex synchronous routing across the SoC.
2Reliability
If synchronous fault interface signals are used for fault communication, then fault detection reliability is improved, but timing constraints become more stringent
Solution Approach 1:
The asynchronous fault interface circuit acts as a mediator that decouples the timing requirements between fault signal generation and fault collection. The edge detector captures faults on the rising edge of a local clock, and the flip-flop stores the fault information asynchronously. The interface then transfers fault indications and domain identifiers without requiring tight timing synchronization with the central fault collection unit, thereby relaxing timing constraints while maintaining reliable fault detection.
3Ease of operation
If clock signal routing is extended across the SoC for fault interface, then synchronous communication is maintained, but routing complexity and cost increase
Solution Approach 1:
The asynchronous fault interface circuit serves as an intermediary that performs synchronous-to-asynchronous conversion locally. The edge detector and flip-flop use a local clock for reliable edge detection and storage, but the subsequent transfer of fault indications and domain identifiers occurs through an asynchronous interface. This eliminates the need to route high-frequency clock signals across the entire SoC to the central fault collection unit, reducing routing complexity and cost while maintaining ease of operation through reliable local sampling.
4Device complexity
If asynchronous fault interface is implemented, then routing complexity is reduced, but fault signal filtering capability must be enhanced
Solution Approach 1:
The edge detector performs preliminary action by capturing fault signals only on the rising edge of the clock cycle, which inherently filters out glitches and false signals that do not align with the clock edge. The flip-flop then stores this edge-detected fault indication, providing an additional layer of filtering. This preliminary edge detection and storage mechanism ensures that only valid, clock-synchronized fault signals are transferred through the asynchronous interface, maintaining reliability while reducing routing complexity.
Data Source
AI summary
A method for handling faults in an integrated circuit system includes receiving fault interface signals from safety-critical logic and generating a fault request indicating a fault and a domain identifier based on the fault interface signals. The fault interface signals include a fault signal and a fault domain identifier signal. In an embodiment of the method, the fault interface signals include synchronous signals received from the safety-critical logic using a synchronous interface and the synchronous signals include a fault clock signal. In an embodiment of the method, generating the fault request includes asserting the fault request in response to the fault signal having a first asserted signal level and maintaining assertion of the fault request until a fault acknowledgement is received from a fault collection and control circuit.


