
SpaceWire RMAP target + initiator engine — key-authorized, CRC-8 integrity-checked remote memory access, ASIL-B lockstep. It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
spacewire_rmap is a SpaceWire RMAP (Remote Memory Access Protocol, ECSS-E-ST-50-52C) target and initiator engine: it lets one SpaceWire node read, write, or read-modify-write the memory or register space of another node without running software on the remote end.
SpaceWire RMAP ECSS-E-ST-50-52C target + initiator (external SpaceWire link, ECSS-E-ST-50-12C, via the catalog spacewire codec); ISO 26262 ASIL-B SEooC (SPFM 91.40%, LFM 88.52%, PMHF 1.23×10⁻⁸/h)
ASIL-B target (SEooC) · SPFM 91.40% · LFM 88.52% · Informational — not gated
Informational FMEDA — this IP is reported but NOT gated. The SPFM/LFM figures above are engineering estimates from a model that is not held to the ASIL metric gates (QM, safety-by-composition, a vendor-core overlay, or a pre-sign-off Technology Preview, depending on the IP). They are not a certification claim and must not be relied on as one. See the safety manual for this IP’s exact status, assumptions of use, and any open items.
ISO 26262-5 FMEDA method (transferable evidence for the ECSS-Q-ST-60 / radiation case) · FMEDA available · Safety Manual included
| Offset | Register | Description |
|---|---|---|
0x00 | CTRL | 0x04 STATUS 0x08 LADDR 0x0C KEY 0x10 MEMBASE |
0x14 | INI_CMD | 0x18 INI_DAT 0x1C IER 0x20 ISR(W1C) 0x24 ERR(W1C) 0x28 INI_STAT [5]ini_busy [6]ini_done [10:7]last_status3… |
// Minimal instantiation
spacewire_rmap #(
.ADDR_W(6)
) u_spacewire_rmap (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Typically deployed in avionics, defense, and space systems built to the ARINC, MIL-STD, and CCSDS standards.
Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.
circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space