olo_ft_cc_simple¶
Status Information¶
VHDL Source: olo_ft_cc_simple
Description¶
This component is a TMR-hardened clock crossing for transferring single values from one clock domain to another (completely asynchronous clocks). A single-event upset (SEU) on any flip-flop of the crossing is masked: it neither corrupts the transferred data nor produces a spurious or lost Out_Valid pulse.
It is the fault-tolerant counterpart of olo_base_cc_simple with the same interface and the same behavior. In both clock domains the valid samples are marked with a Valid signal according to the AXI-S specification but back-pressure (Ready) is not handled.
For the entity to work correctly, the data-rate must be significantly lower ((3+SyncStages_g) x lower) than the slower clock frequency. This is the same requirement as for olo_base_cc_simple.
This block follows the general clock-crossing principles. Read through them for more information.
Generics¶
| Name | Type | Default | Description |
|---|---|---|---|
| Width_g | positive | 1 | Width of the data-signal to clock-cross |
| SyncStages_g | positive | 2 | Number of synchronization stages. Range: 2 ... 4 |
Interfaces¶
| Name | In/Out | Length | Default | Description |
|---|---|---|---|---|
| In_Clk | in | 1 | - | Source clock |
| In_RstIn | in | 1 | '0' | Reset input (high-active, synchronous to In_Clk) |
| In_RstOut | out | 1 | N/A | Reset output (see clock-crossing principles, synchronous to In_Clk) |
| In_Data | in | Width_g | - | Input data (synchronous to In_Clk) |
| In_Valid | in | 1 | - | AXI4-Stream handshaking signal for In_Data |
| Out_Clk | in | 1 | - | Destination clock |
| Out_RstIn | in | 1 | '0' | Reset input (high-active, synchronous to Out_Clk) |
| Out_RstOut | out | 1 | N/A | Reset output (see clock-crossing principles, synchronous to Out_Clk) |
| Out_Data | out | Width_g | N/A | Output data (synchronous to Out_Clk) |
| Out_Valid | out | 1 | N/A | AXI4-Stream handshaking signal for Out_Data |
Architecture¶
The architecture follows olo_base_cc_simple: In_Data is latched when In_Valid is asserted, the valid pulse is clock-crossed, and in the output clock domain the latched data is sampled when the valid pulse arrives. A specific clock crossing for the data is not required because the latched data is guaranteed to be stable while the valid pulse crosses.
Every storage element of the data and valid paths is triplicated (copies A, B and C) and followed by a majority voter:
In_Clk domain : Out_Clk domain
:
In_Valid --+--> olo_ft_private_cc_toggle --> VldOutI --+--> OutValid[A,B,C] --> vote --> Out_Valid
| : |
| load : | load
v : v
In_Data -----> DataLatchIn[A] ----------:-----> Out_Data_Sig[A] --+
+---> DataLatchIn[B] ----------:-----> Out_Data_Sig[B] --+--> vote --> Out_Data
+---> DataLatchIn[C] ----------:-----> Out_Data_Sig[C] --+
(hold: voted value) : (hold: voted value)
In_RstIn / Out_RstIn --> olo_ft_cc_reset --> In_RstOut / Out_RstOut
- Data latch (In_Clk): three copies load In_Data on In_Valid. Otherwise every copy reloads the voted value.
- Valid crossing: In_Valid is crossed by olo_ft_private_cc_toggle: a triplicated toggle register, an olo_ft_cc_bits TMR synchronizer and a triplicated edge detector. It produces exactly one single-cycle pulse per input pulse.
- Output registers (Out_Clk): each copy of the output data samples its own copy of the data latch (A from A, B from B, C from C) when the valid pulse arrives, so there is no logic on the asynchronous data path. Otherwise every copy reloads the voted value. Out_Valid is a triplicated register followed by a voter.
- Reset crossing: olo_ft_cc_reset.
The latency in clock cycles is identical to olo_base_cc_simple.
Fault Tolerance¶
Protection Concept¶
| State | Clock domain | Protection |
|---|---|---|
| Data latch | In_Clk | Three copies, voted hold (an upset copy is repaired at the next edge) |
| Valid toggle | In_Clk | Three copies, next value computed from the voted value |
| Valid synchronizer | both | olo_ft_cc_bits: three chains with voter |
| Valid edge detector | Out_Clk | Three copies with voter |
| Out_Valid register | Out_Clk | Three copies with voter |
| Output data register | Out_Clk | Three copies, voted hold (an upset copy is repaired at the next edge) |
| Reset crossing | both | olo_ft_cc_reset |
The hold path of every register uses the voted value instead of the register's own value. An upset copy is therefore repaired at the next clock edge and upsets cannot accumulate while a value is held for a long time. With a plain triplication (each copy holding its own value), an upset in copy A followed much later by an upset in copy B of the same bit would defeat the voter.
The valid pulse is crossed with the toggle synchronizer olo_ft_private_cc_toggle (like in olo_base_cc_pulse and olo_ft_cc_pulse), using the reset crossing of this entity. The toggle synchronizer works for any clock ratio, supports 2 to 4 sync stages and produces a single-cycle output pulse, so the timing behavior of olo_base_cc_simple is retained. Because a toggle is a level, the three synchronizer chains of olo_ft_cc_bits may see a toggle one clock cycle apart, but the voted toggle still changes exactly once per input pulse. A single upset can at most delay the change until the last of the three chains sees the toggle, which is within the worst-case latency of a non-hardened synchronizer, but it never produces a second change. The underlying analysis of TMR synchronizers is given in [1].
Limitations¶
- TMR masks one upset per register and clock cycle. Two upsets in different copies of the same register within one clock cycle are not masked.
- The voters and the combinational logic are not triplicated. The design targets upsets of storage elements (SEU), not single-event transients in combinational logic. This is the same fault model as for the other olo_ft_cc\<...>_ entities.
- The reset crossing olo_ft_cc_reset protects its acknowledge paths with TMR. Its request-path registers rely on vendor TMR (see its documentation). An upset there leads to a spurious reset of both clock domains (visible on In_RstOut / Out_RstOut), not to silently corrupted data.
Synthesis Attributes¶
syn_radhardlevel = "none"at the architecture level prevents tools like Synplify (Microchip Libero) from triplicating the already-triplicated registers.dont_touch,dont_merge,preserve,syn_preserveandsyn_keepon all TMR copies prevent the synthesis tool from merging the copies (they have identical inputs and would otherwise be optimized into one register).
The entity requires roughly three times the flip-flops of olo_base_cc_simple (six registers of Width_g bits for the data) plus one voter per bit.
Constraints¶
The same constraints as for olo_base_cc_simple apply, see clock-crossing principles.
Note that the scoped constraints for automatic constraining in AMD Vivado are only provided for the olo_base clock crossings. Constrain the clock crossings of olo_ft entities manually.
References¶
[1] Y. Li, B. Nelson, and M. Wirthlin, "Synchronization Techniques for Crossing Multiple Clock Domains in FPGA-Based TMR Circuits," IEEE Transactions on Nuclear Science, vol. 57, no. 6, pp. 3506-3514, Dec. 2010. DOI: 10.1109/TNS.2010.2086075