Clock Domain Crossing Synchronizer With Immediate Fault Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional clock domain synchronizers face challenges in detecting failures promptly, leading to potential safety issues in systems like automotive SoCs, where asynchronous clock domains can result in metastable states and faults that may go undetected, compromising system reliability and safety.
Innovation Solution
A synchronizer circuit with a primary and secondary synchronizer stage, along with detection and fault output stages, utilizing serially-coupled flip-flops and Triple-Voting Flip-flops in critical stages to detect both logic high and low faults, providing a fault output signal for corrective action, and adjustable flip-flop stages based on Mean Time Between Failure (MTBF) values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional two flip-flop synchronizer is used, then the circuit area and latency are minimized, but the ability to detect faults immediately is lost, compromising system reliability
Solution Approach 1:
The synchronizer is divided into two independent paths: a primary synchronizer path (flip-flops B1, B2) that provides the synchronized output signal, and a secondary detection path (flip-flops C1, C2) that monitors for faults. This segmentation allows the detection function to be added without significantly increasing overall complexity, as each path operates independently with its own flip-flop sequence.
Solution Approach 2:
The detection path is created as a copy of the primary synchronizer path, using the same two-stage flip-flop structure. The secondary flip-flops C1 and C2 replicate the synchronization logic of B1 and B2, allowing the system to monitor for faults by comparing expected vs. actual behavior without requiring entirely new detection circuitry.
2Reliability
If additional synchronizer stages are added to improve fault detection, then reliability increases, but latency and circuit area increase
Solution Approach 1:
The detection function is segmented into a separate parallel path rather than being integrated into the main synchronizer chain. This allows the detection flip-flops to operate simultaneously with the primary synchronizer, adding fault detection capability without increasing the critical path latency of the main signal transmission.
Solution Approach 2:
The fault detection mechanism operates periodically in sync with the clock domains, using the same clock cycles as the primary synchronizer. The detection path samples signals at the same intervals as the main synchronizer, ensuring that fault detection does not introduce additional timing delays beyond the inherent synchronization period.
3Object-affected harmful factors
If a conventional synchronizer is used, then the circuit area is minimized, but safety issues may arise from undetected metastable states and faults
Solution Approach 1:
The secondary detection path acts as an intermediary monitoring system that observes the synchronization process without interfering with the primary signal path. The detection flip-flops C1 and C2 serve as intermediaries that capture and report fault conditions while allowing the main synchronizer to continue its normal operation independently.
Solution Approach 2:
The detection path provides feedback about the health and status of the synchronization process. By monitoring the outputs of the primary synchronizer and comparing them against expected behavior, the system generates feedback signals that indicate when faults or metastable states occur, enabling timely corrective action.
Data Source
AI summary
A synchronizer circuit includes a first synchronizer having a first input for receiving a signal associated with a first clock signal, a second input for receiving a second clock signal, and an output for providing a synchronizer circuit output signal; a second synchronizer having a first input for receiving the signal associated with the first clock signal, a second input for receiving the second clock signal, and an output; a detection stage having a first input coupled to the output of the first synchronizer and to the output of the second synchronizer, a second input for receiving the second clock signal, and an output; and a fault output stage having a first input coupled to the detection stage, a second input for receiving the second clock signal, and an output for providing a fault output signal.


