ECSS-E-ST-50-12C §10 wormhole crossbar router for multi-node SpaceWire networks, ASIL-B. It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
spw_router is a SpaceWire (ECSS-E-ST-50-12C §10) N-port routing switch, delivered as synthesizable SystemVerilog with an APB4 configuration slave and a rad-tolerant / ASIL-B safety overlay.
make cdc IP=spw\_router reports zero crossings) — the per-port DS recovered-clock crossing lives in each spacewire link instance, not the switch fabricECSS-E-ST-50-12C §10 (SpaceWire); ECSS-Q-ST-60-02C device assurance + ECSS-Q-ST-60-13 radiation (TID/SEE); ISO 26262 ASIL-B SEooC (SPFM 90.75%, LFM 90.00%, PMHF 1.78×10⁻⁸/h)
ASIL-B (SEooC) · SPFM 90.75% · LFM 90.00% · PASS
ISO 26262-5 FMEDA method (transferable evidence for the ECSS-Q-ST-60 / radiation case) · FMEDA available · Safety Manual included
See datasheet for full register reference.
// Minimal instantiation
spw_router #(
.ADDR_W(6)
) u_spw_router (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Typically deployed in avionics, defense, and space systems built to the ARINC, MIL-STD, and CCSDS standards.
Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.
circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space