olo_ft_sync¶
Status Information¶
VHDL Source: olo_ft_sync
Description¶
This component is a TMR-hardened synchronizer for asynchronous input signals (external inputs, status signals of hard IP without a clock). A single-event upset (SEU) on any flip-flop of the synchronizer does not change the output.
It is the fault-tolerant counterpart of olo_intf_sync with the same interface and the same behavior. Like olo_intf_sync, it synchronizes each bit separately: it is meant for individual bits, not for multi-bit values that must be consistent (use the olo_ft_cc\<...>_ clock crossings for signals that come from a known clock domain, e.g. olo_ft_cc_bits or olo_ft_cc_status).
Generics¶
| Name | Type | Default | Description |
|---|---|---|---|
| Width_g | positive | 1 | Number of bits to synchronize |
| RstLevel_g | std_logic | '0' | Reset state of the synchronizer registers |
| SyncStages_g | positive | 2 | Number of synchronization stages. Range: 2 ... 4 |
Interfaces¶
| Name | In/Out | Length | Default | Description |
|---|---|---|---|---|
| Clk | in | 1 | - | Clock |
| Rst | in | 1 | '0' | Reset input (high-active, synchronous to Clk) |
| DataAsync | in | Width_g | - | Asynchronous input signals |
| DataSync | out | Width_g | - | Synchronized output signals |
Architecture¶
For each bit, the design triplicates the synchronizer chain of olo_intf_sync and combines the three outputs with a majority voter:
DataAsync[i] --+--> Reg0_A --> RegN_A(..) --.
| \
+--> Reg0_B --> RegN_B(..) ----+--> Voter --> DataSync[i]
| /
+--> Reg0_C --> RegN_C(..) --'
An upset in one chain is shifted out after SyncStages_g clock cycles and masked by the voter in the meantime.
Limitations¶
- The three chains sample the asynchronous input independently. Around a change of the input, the chains may resolve the new value one clock cycle apart; the voted output follows the second chain. An upset of one of the two agreeing chains in exactly this cycle is not masked. This is inherent to the synchronization of an asynchronous signal with TMR (see the analysis in [1]).
- TMR masks one upset per bit and clock cycle. Two upsets in different chains of the same bit within SyncStages_g clock cycles are not masked.
- The voters are not triplicated. The design targets upsets of storage elements (SEU), not single-event transients in combinational logic.
Synthesis Attributes¶
syn_radhardlevel = "none"at the architecture level prevents tools like Synplify (Microchip Libero) from triplicating the already-triplicated registers.- All synchronizer attributes of olo_intf_sync (
async_reg,dont_merge,preserve,syn_preserve,syn_keep,shreg_extract,syn_srlstyle) plusdont_touchon every copy prevent the synthesis tool from merging the three chains (which would defeat the TMR).
Constraints¶
The same constraints as for olo_intf_sync apply: the path from the input to the first synchronizer stage (Reg0)
must be shorter than one clock period (set_max_delay -datapath_only).
The register names match olo_intf_sync, so in AMD Vivado its scoped constraint file can be used for inputs that
come from device pins: read_xdc -ref olo_ft_sync <path>/src/intf/tcl/olo_intf_sync.tcl. For signals that come from
hard IP inside the device (e.g. transceiver status), constrain the paths to Reg0 manually.
References¶
[1] Y. Li, B. Nelson, and M. Wirthlin, "Synchronization Techniques for Crossing Multiple Clock Domains in FPGA-Based TMR Circuits," IEEE Transactions on Nuclear Science, vol. 57, no. 6, pp. 3506-3514, Dec. 2010. DOI: 10.1109/TNS.2010.2086075