Verification IP is not safety-rated. These are testbench components — no ASIL target, no FMEDA, no IP-XACT, no safety-mechanism interface. They exist to help you verify a design, not to carry a safety argument. The safety soft-IP catalog is over here.
A Verification IP (VIP) is a reusable model of one side of a protocol, used to exercise and check a design that implements the other side. If you are building an AXI slave, the VIP is the master that talks to it: it drives legal traffic, watches what comes back, and says so when the design breaks the specification.
It is verification collateral, not silicon. A VIP is never synthesised into your chip — it exists only inside the simulation.
The terms get used interchangeably and they are not the same thing.
A BFM (Bus Functional Model) drives and samples signals: it turns a call like WRITE_BURST(addr, len) into legal wiggles on the bus. That is the stimulus half.
A VIP is the BFM plus the judgement: the protocol checker that knows the rules, the monitor that watches without interfering, and the far-end model that responds. A BFM can drive an illegal transaction quite happily. A VIP tells you that it did.
141 protocol VIPs across 16 groups, of which 70 ship with real, tested collateral today and the rest are scoped. The shipping set is 218 SystemVerilog files covering 59 protocols:
| Component | Files |
|---|---|
| Protocol checkers | 153 |
| Files carrying SystemVerilog assertions | 109 |
| Monitors | 63 |
| Delivered as a UVM agent (driver + monitor + sequencer) | 3 |
| Delivered as a task-based SystemVerilog BFM | 67 |
The UVM agents are APB5 / APB4 / APB3 / APB2, OBI (Open Bus Interface), TileLink (TL-UL). Everything else is a task-based SystemVerilog BFM, callable from a plain Verilog testbench with no methodology library required — which is deliberate: most of the designs these are used against are small enough that a UVM environment costs more than it returns.
Two limits, stated here rather than discovered after you download something.
No functional coverage models. The VIP deliverable contains 0 covergroups. Coverage closure is your verification plan’s job, not something these ship an opinion about. (This repository does contain 76 files with covergroups across 48 UVM environments — but those verify our own safety IP and are not part of any VIP product.)
Not safety-rated. No ASIL, no FMEDA, no IP-XACT, no safety manual. That distinction matters and it is not hedging: the safety soft-IP in this catalog carries measured diagnostic coverage and a gated ISO 26262 verdict. The VIPs are verification tools used while integrating it. Only one of those two things is a safety claim.
These are written from the public protocol specifications, not derived from this catalog’s own RTL. That is the point of using one: a VIP built out of the design it is meant to check inherits the design’s misreadings of the spec, agrees with them, and passes. An independent second source disagrees instead.
This VIP is scoped but not yet built — tell us your timeline and we will reorder the wave.
Verification IP is testbench collateral and is deliberately not safety-rated: no ASIL target, no FMEDA, and no IP-XACT descriptor. It carries no functional-safety claim.
circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space