← All IP · the catalog
Avionics, Space & Mil-Std Networking

ECSS-CAN Onboard Bus Controller

ECSS-E-ST-50-15C spacecraft CAN overlay — dual-bus redundancy, CANopen frame-integrity plausibility…

Request this IP →Browse the catalog
ASIL-B
target
93.20%
SPFM
88.36%
LFM
Informational
FMEDA
3.6K
gates
1.0.0
version
Interfaces at a glance

Block diagram

ecss_can35 portsapb_slave8 signalsrxa_*4 signalsrxb_*4 signalstx_*6 signalsfi_*7 signalsclkrst_ninterruptecss_irqsafety / statuserr_clear · err_valid · err_code
Place-and-route snapshot

Physical implementation

ECSS-CAN Onboard Bus Controller routed place-and-route layout on the Nangate45 PDK
A real synthesis and place-and-route pass on this RTL, routed on the open Nangate45 / FreePDK45 PDK — evidence the block closes physically, not just in simulation. Target-PDK timing, area, and power sign-off figures are shared under NDA.
The deliverable

What you’re licensing

ECSS-E-ST-50-15C spacecraft CAN overlay — dual-bus redundancy, CANopen frame-integrity plausibility… It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:

Synthesizable RTL
Portable, vendor-neutral SystemVerilog that drops onto your existing SoC fabric — no foundry or EDA-tool lock-in.
Per-IP FMEDA report
SPFM / LFM / PMHF computed against the ASIL target per ISO 26262-5 — the quantitative analysis your assessor asks for.
Safety manual
Assumptions of use, the safety mechanisms and their diagnostic coverage — written to drop straight into your safety case.
IP-XACT + integration docs
A machine-readable descriptor plus register and integration documentation for fast, low-risk bring-up.
Self-checking testbench
A self-checking testbench and a one-command build, so you can reproduce every claim on day one.

What it is

ecss_can is an ECSS-E-ST-50-15C “CANbus extension protocol” layer — the European spacecraft onboard-bus standard — delivered as synthesizable SystemVerilog soft-IP with an APB4-lite control interface and built-in ISO 26262 (ASIL-B) / space-grade safety instrumentation.

Key Features

Standards & Compliance

ECSS-E-ST-50-15C (Spacecraft CANbus extension protocol), CANopen (CiA 301), CAN 2.0B / CAN-FD (via can_fd/can_xl); ISO 26262 ASIL-B SEooC (SPFM 93.20%, LFM 88.36%, PMHF 4.60×10⁻⁹/h)

Functional Safety

ASIL-B target (SEooC) · SPFM 93.20% · LFM 88.36% · Informational — not gated

Informational FMEDA — this IP is reported but NOT gated. The SPFM/LFM figures above are engineering estimates from a model that is not held to the ASIL metric gates (QM, safety-by-composition, a vendor-core overlay, or a pre-sign-off Technology Preview, depending on the IP). They are not a certification claim and must not be relied on as one. See the safety manual for this IP’s exact status, assumptions of use, and any open items.

ISO 26262-5 FMEDA method (transferable evidence for the ECSS-Q-ST-60 / radiation case) · FMEDA available · Safety Manual included

Register Map

OffsetRegisterDescription
0x00CTRL[0]=EN [1]=REDUN_EN [2]=TIME_MASTER [3]=TIME_SLAVE [4]=HB_EN
0x04NODECFG[6:0]=NODE_ID [15:8]=HB_PERIOD(x256 cyc)
0x08STATUS(RO) [0]=ACTIVE_BUS(0=A,1=B) [1]=A_ALIVE [2]=B_ALIVE [3]=SYNC_OK [4]=HB_OK [7:5]=fsm_state
0x0CTIME_VALtime-master: write the 32-bit onboard time to distribute
0x10TIME_PULSEtime-master: write 1 -> emit a TIME message carrying TIME_VAL

…5 more registers — see datasheet for the full table.

Getting Started

// Minimal instantiation
ecss_can #(
 .ADDR_W(6)
) u_ecss_can (
 .clk (clk),
 .rst_n (rst_n),
 // APB4
 .p_paddr (paddr),
 .p_psel (psel),
 .p_penable (penable),
 .p_pwrite (pwrite),
 .p_pwdata (pwdata),
 .p_prdata (prdata),
 .p_pready (pready),
 // Safety
 .err_clear (1'b0),
 .err_valid (err_valid),
 .err_code (err_code)
);

Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.

Applications

Where it fits

Typically deployed in avionics, defense, and space systems built to the ARINC, MIL-STD, and CCSDS standards.

The case

Why license it, not build it

Skip 12–18 months
The FMEDA and the safety case are already generated. You integrate a finished safety element — you don’t stand up a safety-IP program to originate one.
One vendor, one safety story
Every block in the catalog shares the same safety architecture, fault-reaction model, and FMEDA methodology — so subsystems roll up cleanly.
Verified, not vapor
The RTL builds and passes today; the safety metrics come from analysis and fault injection against real RTL, not a datasheet promise.

Interested in ECSS-CAN Onboard Bus Controller?

Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.

Talk to us →See related IP

Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.

circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space