3.4 Error Handling
85
3.4.1 Single Event Upset Handling
A common technique to increase tolerance to SEE is to create custom cells (i.e. flipflops and latches) that have been improved by altering or adding extra components
(resistors, transistors etc.) to mitigate the effect of the injected charge. The use of
custom cells comes with an increase in size and power consumption, in addition
to the extra work needed to design test and qualify them. The SAMPA design uses
standard cells and as such need to mitigate the effect of SEEs through design instead.
SEUs are caused by charged particles traversing a device, injecting charge along
the way and potentially causing a register’s value to change to the opposite value. A
common technique to protect devices against SEUs is by employing Triple-Modular
Redundancy (TMR), which is essentially the use of a two-out-of-three voting concept
at a low level [24]. As the information is stored in multiple locations and, provided
that a hit only affects one node, the upset will not propagate and the correct data
can be recovered. Accumulation of errors can be prevented by making sure that the
register is refreshed periodically or automatically when an error is detected. Most of
the operationally important registers in the design have been protected through TMR
to avoid functional upsets in the device that would require the device to be reset.
There are about 125 000 flip-flops in total in the second prototype design, including
the extra TMR registers. The amount of registers (excluding extra TMR flip-flops)
is about 55 000, of which 20 700 (38 %) are not protected by TMR.
The exceptions are:
Internal data path The number of registers in the data path between the ADC and
the buffer memory amount to about 17 700 registers or about 1/3 of the design.
SEUs in the data is deemed to be acceptable, so TMR is not enabled for these
registers to save area.
Daisy chained data path The number of registers on the data path from the daisychained input to the buffer memory amounts to 109 registers. These are not protected for timing reasons and as the header-data is already protected through
SECDED.
Test structures Registers in the test structures, i.e. the ring oscillator, LFSR generator, JTAG, and some other test infrastructure, are not protected since they are
kept in reset by TMR protected configuration registers during normal operation.
The test structures contain 138 registers.
Memory BIST The memory Built-In Self-Test is not protected as it is kept in reset
by an external pin that is pulled low. It contains about 2700 registers.
Figure 3.22a shows the schematic drawing of a normal TMR register and
Fig. 3.22b shows the schematic for a TMR protected synchronizer. The TSMC library
has a custom component for the majority voter which reduces the additional area
needed for a TMR register compared to a non-TMR register.
85
3.4.1 Single Event Upset Handling
A common technique to increase tolerance to SEE is to create custom cells (i.e. flipflops and latches) that have been improved by altering or adding extra components
(resistors, transistors etc.) to mitigate the effect of the injected charge. The use of
custom cells comes with an increase in size and power consumption, in addition
to the extra work needed to design test and qualify them. The SAMPA design uses
standard cells and as such need to mitigate the effect of SEEs through design instead.
SEUs are caused by charged particles traversing a device, injecting charge along
the way and potentially causing a register’s value to change to the opposite value. A
common technique to protect devices against SEUs is by employing Triple-Modular
Redundancy (TMR), which is essentially the use of a two-out-of-three voting concept
at a low level [24]. As the information is stored in multiple locations and, provided
that a hit only affects one node, the upset will not propagate and the correct data
can be recovered. Accumulation of errors can be prevented by making sure that the
register is refreshed periodically or automatically when an error is detected. Most of
the operationally important registers in the design have been protected through TMR
to avoid functional upsets in the device that would require the device to be reset.
There are about 125 000 flip-flops in total in the second prototype design, including
the extra TMR registers. The amount of registers (excluding extra TMR flip-flops)
is about 55 000, of which 20 700 (38 %) are not protected by TMR.
The exceptions are:
Internal data path The number of registers in the data path between the ADC and
the buffer memory amount to about 17 700 registers or about 1/3 of the design.
SEUs in the data is deemed to be acceptable, so TMR is not enabled for these
registers to save area.
Daisy chained data path The number of registers on the data path from the daisychained input to the buffer memory amounts to 109 registers. These are not protected for timing reasons and as the header-data is already protected through
SECDED.
Test structures Registers in the test structures, i.e. the ring oscillator, LFSR generator, JTAG, and some other test infrastructure, are not protected since they are
kept in reset by TMR protected configuration registers during normal operation.
The test structures contain 138 registers.
Memory BIST The memory Built-In Self-Test is not protected as it is kept in reset
by an external pin that is pulled low. It contains about 2700 registers.
Figure 3.22a shows the schematic drawing of a normal TMR register and
Fig. 3.22b shows the schematic for a TMR protected synchronizer. The TSMC library
has a custom component for the majority voter which reduces the additional area
needed for a TMR register compared to a non-TMR register.
