Reset Protection Circuit for Lock-Step Reset Deassertion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In systems with stringent safety goals, synchronizing the deassertion of reset signals between primary and shadow logic blocks is challenging, especially in large systems with high fanout and varying semiconductor processes, temperature, and supply voltage, which can lead to lock-step operation failures.

Innovation Solution

The implementation of a reset protector block using flip-flops to synchronize the deassertion of reset signals, ensuring that shadow logic blocks come out of reset precisely n clock cycles after primary logic blocks, and the use of a logical OR gate to suppress transient errors, maintaining lock-step operation and detecting stuck-at faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If primary and shadow reset signal trees are used with large fanout, then functional safety coverage is improved, but synchronization precision of reset deassertion deteriorates

Engineering Contradiction:
Improvefunctional safety coverageVSAvoidsynchronization precision of reset deassertion
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system divides the reset signal distribution into separate primary and shadow reset signal trees, each serving independent logic blocks. This segmentation allows independent optimization of each tree while maintaining overall functional safety through comparison of results.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A reset protection block is introduced as an intermediary component that receives reset signals from both primary and shadow trees, compares their deassertion timing, and generates control signals to ensure proper synchronization. This mediator resolves the timing mismatch caused by large fanout variations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If reset signal fanout is increased to cover more logic blocks, then system coverage is improved, but reset timing synchronization deteriorates

Engineering Contradiction:
Improvenumber of covered logic blocksVSAvoidreset timing skew
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The reset protection block monitors the deassertion timing of both primary and shadow reset signals and provides feedback control. When timing skew is detected, the system can adjust timing through the flip-flop synchronization mechanism to maintain proper lock-step operation across all covered logic blocks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary synchronization of reset deassertion through the reset protection block before the actual lock-step operation begins. The flip-flops are configured to advance or delay signals proactively, ensuring that when reset deassertion occurs, all logic blocks are properly synchronized regardless of fanout variations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If lock-step operation is maintained with strict timing requirements, then functional safety is improved, but system complexity increases

Engineering Contradiction:
Improvefunctional safetyVSAvoidreset signal synchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The reset protection block serves as a dedicated intermediary that handles the complex timing synchronization tasks, isolating the complexity from the main functional logic. This block contains the flip-flops and comparison logic needed for lock-step verification, keeping the overall system manageable despite strict timing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11181957B1Reset protection scheme for functional safety applications
Publication Date: 2021.11.23 ARM LTD
  • US11181957B1 patent drawing
  • US11181957B1 patent drawing
  • US11181957B1 patent drawing

AI summary

An improved apparatus and method for the protection of reset in systems with stringent safety goals that employ primary and shadow logic blocks with a lock-step checker to achieve functional safety, including those systems having very large fanout of primary and shadow reset signal trees. The disclosed apparatus and method support assertion of reset that is asynchronous to the system clock and deassertion of reset that is synchronous to the system clock. Shadow logic blocks have reset deasserted a fixed number of clock cycles after their respective primary logic blocks, thereby avoiding the requirement to synchronize the primary and shadow reset signal trees at each of their end points to ensure lock-step operation between the primary and shadow logic blocks.