Safety-instrumented RISC-V PLIC — level-sensitive source routing, priority/threshold arbitration and claim/complete… It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
Synthesizable RTL
Portable, vendor-neutral SystemVerilog that drops onto your existing SoC fabric — no foundry or EDA-tool lock-in.
Per-IP FMEDA report
SPFM / LFM / PMHF computed against the ASIL target per ISO 26262-5 — the quantitative analysis your assessor asks for.
Safety manual
Assumptions of use, the safety mechanisms and their diagnostic coverage — written to drop straight into your safety case.
IP-XACT + integration docs
A machine-readable descriptor plus register and integration documentation for fast, low-risk bring-up.
Self-checking testbench
A self-checking testbench and a one-command build, so you can reproduce every claim on day one.
What it is
A RISC-V Platform-Level Interrupt Controller (PLIC) delivered as synthesizable SystemVerilog soft-IP.
Key Features
Level-sensitive interrupt routing: NSRC sources (v0.1 hard-capped at 8 — PRIORITY is one fixed 32-bit, 4-bit/source register) to a single hart context’s ext_irq_o → mip.MEIP; priority 0 unconditionally disables a source
ENABLE bitmap + THRESHOLD gating (only priority > threshold sources are eligible); CLAIM read atomically returns and clears the highest-priority eligible source id (lowest id breaks ties), COMPLETE ack re-pends a still-asserted level source
TMR-voted pending latch: three keep’d rails (pend_r0/r1/r2) load every cycle and are voted 2-of-3 by voter_2oo3, masking a single-rail upset while pend_disagree flags the latent fault
Independent eligibility-OR recompute (any_elig_redund) cross-checks ext_irq_o every cycle; either mismatch reports err_code 9 (lockstep) so a missed interrupt can never go silent
Per-source even parity over the interrupt-routing vector table — one bit per 4-bit priority nibble, one over ENABLE, one over THRESHOLD — recomputed and compared every cycle → err_code 1; prio_fi_i is a dedicated DFT injection hook (tie 0 in mission mode)
APB4 slave configuration/claim plane, fully separate from the irq_src_i interrupt-source data plane; 8-bit address decode over PRIORITY/PENDING/ENABLE/THRESHOLD/CLAIM
The claim-ID arbitration compare is the one disclosed, fail-loud residual single point
Standards & Compliance
RISC-V Platform-Level Interrupt Controller (PLIC) specification; ISO 26262 ASIL-B SEooC
Functional Safety
ASIL-B (SEooC) · SPFM 95.39% · LFM 99.00% · PASS
ISO 26262:2018 · FMEDA available · Safety Manual included
Register Map
Offset
Register
Description
0x00
PRIORITY
4 bits/source packed (0 = source disabled)
0x04
PENDING
[NSRC-1:0] RO
0x08
ENABLE
[NSRC-1:0]
0x0C
THRESHOLD
[3:0] (only priority > threshold can interrupt)
0x10
CLAIM
read = claim id (clears pending); write = complete
Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Applications
Where it fits
Typically deployed in the safety backbone of an ASIL SoC — error detection, redundancy, and the fault-reaction path that takes the system to a safe state.
The case
Why license it, not build it
Skip 12–18 months
The FMEDA and the safety case are already generated. You integrate a finished safety element — you don’t stand up a safety-IP program to originate one.
One vendor, one safety story
Every block in the catalog shares the same safety architecture, fault-reaction model, and FMEDA methodology — so subsystems roll up cleanly.
Verified, not vapor
The RTL builds and passes today; the safety metrics come from analysis and fault injection against real RTL, not a datasheet promise.
Interested in RISC-V PLIC (Platform-Level Interrupt Controller)?
Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.