The root of the safe/secure-boot chain — the one instruction stream a CV32E40S core fetches before anything else in the system exists to check it. It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
boot_rom is an integrity-checked, single-cycle instruction ROM that sits at the reset-fetch address of an OpenHW CV32E40S core (rv32/rv32_lockstep), which has no internal boot ROM of its own — it is the first code the core ever executes, and so the root of the SoC’s safe-boot chain.
rvalid/out-of-range): a stuck-at that would mis-grant or silently suppress the OBI error response raises err_code 9instr_rvalidpar_o plus per-byte instr_rchk_o parity — for an independent, end-to-end response check at the fetch consumerinj_data_xor/inj_chk_xor/inj_raddr_xor/inj_ctrl_xor, tied 0 in mission mode) exercise every diagnostic path; verified by a 7-test directed testbench (SBE correction, DBE, out-of-range, read-mux fault, OBI control fault)ISO 26262 ASIL-B SEooC (pre-sign-off engineering FMEDA: SPFM 99.40%, LFM 100.00%, PMHF 5.65×10⁻¹⁰/h); OBI-lite instruction-slave interface (CV32E40S-compatible subset)
ASIL-B target (SEooC) · SPFM 99.40% · LFM 100.00% · Informational — not gated
Informational FMEDA — this IP is reported but NOT gated. The SPFM/LFM figures above are engineering estimates from a model that is not held to the ASIL metric gates (QM, safety-by-composition, a vendor-core overlay, or a pre-sign-off Technology Preview, depending on the IP). They are not a certification claim and must not be relied on as one. See the safety manual for this IP’s exact status, assumptions of use, and any open items.
ISO 26262:2018 · FMEDA available · Safety Manual included
See datasheet for full register reference.
// Minimal instantiation
boot_rom #(
.ADDR_W(6)
) u_boot_rom (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Typically deployed in RISC-V SoCs that need a safety-grade core, boot, memory, debug, and interrupt platform.
Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.
circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space