Asynchronous Fault Interface for SoC Safety-Critical Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional fault handling systems in safety-relevant integrated circuits face challenges with high-frequency synchronous interfaces that increase backend routing complexity and timing constraints, particularly in systems-on-a-chip (SoCs) with multiple processor cores and safety-critical applications, where fault information needs to be efficiently communicated across distributed resources.

Innovation Solution

Implementing an asynchronous fault interface that uses handshaking signals instead of clock-synchronized communication, filtering out false faults, and reducing clock signal routing, while adapting synchronous fault signals to asynchronous interfaces for efficient fault information transfer between local and central fault collection units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If synchronous fault interface signals are used for fault communication, then fault detection reliability is improved, but backend routing complexity and timing constraints increase

Engineering Contradiction:
Improvefault detection reliabilityVSAvoidbackend routing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An asynchronous fault interface circuit is introduced as an intermediary component between the synchronous fault signal source and the fault collection unit. This circuit includes an edge detector that captures fault signals on the rising edge of a clock, a flip-flop that stores the fault indication and domain identifier, and an asynchronous interface that transfers these values without requiring synchronized clock routing. This intermediary structure maintains fault detection reliability while eliminating the need for complex synchronous routing across the SoC.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If synchronous fault interface signals are used for fault communication, then fault detection reliability is improved, but timing constraints become more stringent

Engineering Contradiction:
Improvefault detection reliabilityVSAvoidtiming constraints
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The asynchronous fault interface circuit acts as a mediator that decouples the timing requirements between fault signal generation and fault collection. The edge detector captures faults on the rising edge of a local clock, and the flip-flop stores the fault information asynchronously. The interface then transfers fault indications and domain identifiers without requiring tight timing synchronization with the central fault collection unit, thereby relaxing timing constraints while maintaining reliable fault detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If clock signal routing is extended across the SoC for fault interface, then synchronous communication is maintained, but routing complexity and cost increase

Engineering Contradiction:
Improvesynchronous communicationVSAvoidrouting complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The asynchronous fault interface circuit serves as an intermediary that performs synchronous-to-asynchronous conversion locally. The edge detector and flip-flop use a local clock for reliable edge detection and storage, but the subsequent transfer of fault indications and domain identifiers occurs through an asynchronous interface. This eliminates the need to route high-frequency clock signals across the entire SoC to the central fault collection unit, reducing routing complexity and cost while maintaining ease of operation through reliable local sampling.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If asynchronous fault interface is implemented, then routing complexity is reduced, but fault signal filtering capability must be enhanced

Engineering Contradiction:
Improverouting complexityVSAvoidfalse fault filtering
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The edge detector performs preliminary action by capturing fault signals only on the rising edge of the clock cycle, which inherently filters out glitches and false signals that do not align with the clock edge. The flip-flop then stores this edge-detected fault indication, providing an additional layer of filtering. This preliminary edge detection and storage mechanism ensures that only valid, clock-synchronized fault signals are transferred through the asynchronous interface, maintaining reliability while reducing routing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12493509B2Fault interface architecture in safety-relevant systems
Publication Date: 2025.12.09 NXP USA INC
  • US12493509B2 patent drawing
  • US12493509B2 patent drawing
  • US12493509B2 patent drawing

AI summary

A method for handling faults in an integrated circuit system includes receiving fault interface signals from safety-critical logic and generating a fault request indicating a fault and a domain identifier based on the fault interface signals. The fault interface signals include a fault signal and a fault domain identifier signal. In an embodiment of the method, the fault interface signals include synchronous signals received from the safety-critical logic using a synchronous interface and the synchronous signals include a fault clock signal. In an embodiment of the method, generating the fault request includes asserting the fault request in response to the fault signal having a first asserted signal level and maintaining assertion of the fault request until a fault acknowledgement is received from a fault collection and control circuit.