Clock Domain Crossing Synchronizer With Immediate Fault Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional clock domain synchronizers face challenges in detecting failures promptly, leading to potential safety issues in systems like automotive SoCs, where asynchronous clock domains can result in metastable states and faults that may go undetected, compromising system reliability and safety.

Innovation Solution

A synchronizer circuit with a primary and secondary synchronizer stage, along with detection and fault output stages, utilizing serially-coupled flip-flops and Triple-Voting Flip-flops in critical stages to detect both logic high and low faults, providing a fault output signal for corrective action, and adjustable flip-flop stages based on Mean Time Between Failure (MTBF) values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional two flip-flop synchronizer is used, then the circuit area and latency are minimized, but the ability to detect faults immediately is lost, compromising system reliability

Engineering Contradiction:
Improvefault detection capabilityVSAvoidsynchronizer structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The synchronizer is divided into two independent paths: a primary synchronizer path (flip-flops B1, B2) that provides the synchronized output signal, and a secondary detection path (flip-flops C1, C2) that monitors for faults. This segmentation allows the detection function to be added without significantly increasing overall complexity, as each path operates independently with its own flip-flop sequence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The detection path is created as a copy of the primary synchronizer path, using the same two-stage flip-flop structure. The secondary flip-flops C1 and C2 replicate the synchronization logic of B1 and B2, allowing the system to monitor for faults by comparing expected vs. actual behavior without requiring entirely new detection circuitry.

Inventive Principle:
Principle #26Copying

2Reliability

If additional synchronizer stages are added to improve fault detection, then reliability increases, but latency and circuit area increase

Engineering Contradiction:
Improvefault detection capabilityVSAvoidsynchronization latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The detection function is segmented into a separate parallel path rather than being integrated into the main synchronizer chain. This allows the detection flip-flops to operate simultaneously with the primary synchronizer, adding fault detection capability without increasing the critical path latency of the main signal transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The fault detection mechanism operates periodically in sync with the clock domains, using the same clock cycles as the primary synchronizer. The detection path samples signals at the same intervals as the main synchronizer, ensuring that fault detection does not introduce additional timing delays beyond the inherent synchronization period.

Inventive Principle:
Principle #19Periodic action

3Object-affected harmful factors

If a conventional synchronizer is used, then the circuit area is minimized, but safety issues may arise from undetected metastable states and faults

Engineering Contradiction:
Improveundetected faultsVSAvoiddetection circuitry
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The secondary detection path acts as an intermediary monitoring system that observes the synchronization process without interfering with the primary signal path. The detection flip-flops C1 and C2 serve as intermediaries that capture and report fault conditions while allowing the main synchronizer to continue its normal operation independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The detection path provides feedback about the health and status of the synchronization process. By monitoring the outputs of the primary synchronizer and comparing them against expected behavior, the system generates feedback signals that indicate when faults or metastable states occur, enabling timely corrective action.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10924091B2Immediate fail detect clock domain crossing synchronizer
Publication Date: 2021.02.16 STMICROELECTRONICS INT NV
  • US10924091B2 patent drawing
  • US10924091B2 patent drawing
  • US10924091B2 patent drawing

AI summary

A synchronizer circuit includes a first synchronizer having a first input for receiving a signal associated with a first clock signal, a second input for receiving a second clock signal, and an output for providing a synchronizer circuit output signal; a second synchronizer having a first input for receiving the signal associated with the first clock signal, a second input for receiving the second clock signal, and an output; a detection stage having a first input coupled to the output of the first synchronizer and to the output of the second synchronizer, a second input for receiving the second clock signal, and an output; and a fault output stage having a first input coupled to the detection stage, a second input for receiving the second clock signal, and an output for providing a fault output signal.