VLDB 2026 Research / reviewers in the wild / expert
Andreas Steininger
dblp:09/5562
· DBLP profile ↗
72ranked-venue papers
6as first author
13since 2021 · last 2024
0000-0002-3847-1647ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 59 · 6 first-author · 13 since 2021Software engineering, systems software and programming languages · 9 · 2 since 2021Security and privacy · 5Applied, interdisciplinary, general and emerging computing · 4Artificial intelligence and machine learning · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | An Autonomous Clock Frequency Supervision CircuitabstractAn important class of attacks is based on manip-ulating the victim's hardware clock to gain control over the system. We propose a circuit that can be added to an IP module to detect and hence mitigate such attacks. It employs a ring oscillator as a tamper-proof internal time reference. We embed this oscillator into a complete circuit whose design carefully takes metastability issues at the boundary between supervised clock and reference clock into account. Furthermore, we analyze the attainable accuracy considering the frequency ratio between these clocks, as well as ring oscillator frequency tolerances. Finally, we give guidelines to parameterize our circuit for given requirements and present a demo implementation as a proof of concept. Clemens Scharwitzl, Andreas Steininger |
DDECS | 2 |
| 2024 | SBanTEM: A Novel Methodology for Sparse Band Tensors as Soft-Error Mitigation in Sparse Convolutional Neural NetworksabstractOver the last two decades, Convolutional Neural Networks (CNNs) have become common in a wide variety of tasks, including safety-critical ones such as autonomous driving, leading to optimizations such as Sparse Convolutional Neural Networks (SparseCNNs). Scaling technologica nodes has led to an exponential increase in transient faults affecting the systems, generating critical soft errors. We introduce SBanTEM a novel methodology for employing sparse band tensors as soft-error mitigation in SparseCNNs. SBanTEM includes a novel mitigation technique, employing band tensors, as they do not require using indices for storing data. We employ progressive reduction of the bandwidth of the selected tensors, allowing the network to train in-between successive prunings, and compensat accuracy loss. Additionally, we implement a Genetic Algorithm (GA) to optimally select the tensors bandwidths in the network. We analyze the resilience of many state-of-the-art CNNs on multiple datasets, showin that resilience is much lower for SparseCNNs, and using SBanTEM makes them as resilient as standard CNNs. SBanTEM’s code and result is available at github.com/Alexei95/SBanTEM to boost reproducibility and reusability of the implementation. Alessio Colucci, Andreas Steininger, Muhammad Shafique 0001 |
IOLTS | 2 |
| 2024 | EISFINN: On the Role of Efficient Importance Sampling in Fault Injection Campaigns for Neural Network Robustness Analysis
Alessio Colucci, Andreas Steininger, Muhammad Shafique 0001 |
IOLTS | 2 |
| 2023 | Towards Resilient Quasi Delay Insensitive Conditional Control ElementsabstractThe causal behavior of Quasi Delay-Insensitive (QDI) circuits may get compromised under the effects of single event transients (SETs). To address the issue, the research community already made efforts in different directions, like with modular redundancy, or shortening the data accepting windows of buffer templates. Nevertheless, in non-modular techniques, the focus remains towards the buffers and combinational logic. Most of the time the conditional control elements, namely Multiplexer and De-multiplexer, are not explicitly addressed. However, for the event-driven behavior these elements are also realized with a storage element called Muller C-element (MCE), so in principle these elements also require special consideration to improve the overall fault tolerance of the circuit. In this article we first analyze the error contribution of these elements during single event transient (SET) strikes and then present a hardening technique to mitigate these effects. The focus is to utilize the inherent fault-tolerance properties of QDI circuits. For better coverage of scenarios we test our technique with two different target circuits, an 8-bit Arithmetic Logic Unit (ALU) circuit designed in a simple linear fashion and a 16-bit iterative multiplier. The analysis includes the state-of-the-art buffer template with one of its SET hardened derivatives named$\Delta$. The findings suggest 40% improvement in tolerance towards SETs with$\Delta_{-}E$, our proposed template with resilient conditional control elements. Zaheer Tabassam, Andreas Steininger |
DSD | 2 |
| 2023 | SET Effects on Quasi Delay Insensitive and Synchronous CircuitsabstractDue to their unbounded data accepting windows asynchronous circuits seem to be more susceptible to environmental effects than their synchronous counterparts with their strict data latching protocol. The technology advancement makes single event transients (SETs) more of a concern towards reliable operation.To better understand the properties of the mentioned classes we present their behaviour under the influence of SETs in a more detailed view that helps to visualize their unseen characteristics. For comparison we propose a way of fault injection where the length of a fault pulse is not fixed, calculated based on maximum gate delay, but related to the circuit's computation steps instead.The analysis concludes that asynchronous quasi delay-insensitive (QDI) circuits show better resilience against SETs due to two main reasons: (1) if realized with a 4-phase handshake protocol they are 95 to 97% resilient to negative fault pulses (2) the susceptibility of a circuit is largely unchanged for increasing fault length because of the causality underlying the QDI principle.Our analysis provides insights leading towards more resilient QDI circuits: if we only make a circuit or specific gates better resist "1" faults, we are fully resilient towards the single event transient (SET)s because "0" faults are already filtered out by its inherent behaviour. This is also beneficial for area efficiency; as asynchronous circuits often require already double or more area and computation time compared to synchronous circuits, adding extra SET mitigation with double-up or other buffer redundant techniques tends to result in painful overheads. Being able to focus the protection to "1" faults, as indicated by our analysis, can hence yield important savings. Zaheer Tabassam, Andreas Steininger |
ETS | 2 |
| 2023 | The Hidden Behavior of a D-LatchabstractFor clock and data transitions in close temporal proximity, synchronous memory elements potentially enter metastability, which leads to unintended output behavior. Although respective analyses in literature have already derived suitable explanations, almost all of them modeled the control (clock) signal transition with negligible rise/fall time. In modern circuits this assumption is, however, not reasonable any more. In fact, due to a finite slope, intermediate clock signal values have to be considered during a large share of the storage process, while their concrete impact is not yet sufficiently explored. In this paper we thus use static and dynamic considerations to thoroughly investigate the behavior of a latch for arbitrary analog control, data and output values, i.e., during the storage process. Basic circuit considerations allow us to derive a unified model which identifies the latch as a Schmitt Trigger with vastly varying hysteresis. We verify the correctness of our predictions by comparison to analog SPICE simulations. Finally we are able to generalize our findings and thus provide explanations for yet unexplained behavior reported in literature. Jürgen Maier 0002, Andreas Steininger, Robert Najvirt |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2022 | On SAT-Based Model Checking of Speed-Independent CircuitsabstractFormal verification plays an important role in the quality assurance of digital circuits. Apart from the now standard equivalence checking between design steps, functional correctness can be proven with model checking. In one approach, a Boolean satisfiability (SAT) problem describing the circuit’s implementation and expected properties is generated for each of a bounded number of time steps and fed to a SAT solver. In synchronous circuits, the time steps correspond to cycles of the global clock. The execution of asynchronous, specifically speed-independent (SI) circuits, however, relies on local handshakes instead of a global time reference. This absence of a global clock requires a different approach for choosing time steps for the SAT problem.This paper presents how bounded, SAT-based model checking can be used on SI asynchronous circuits. We aim to give a general and accessible introduction to this topic, highlight the inherent computational complexity and show that setting up a basic model checker for SI circuits is possible with quite simple means, without any reliance on (expensive) commercial tools. For our reference implementation used in the provided examples we use the open source Z3 solver. Florian Huemer, Robert Najvirt, Andreas Steininger |
DDECS | 3 |
| 2022 | AµFLIPS: An Asynchronous Microprocessor With FLexIbly-timed Pipeline StagesabstractAµFLIPS is an asynchronous microprocessor with novel pipeline register organization to resolve data and control hazards using synchronous hazard resolving schemes. Existing works claim that mechanisms for handling data and control hazards in synchronous systems are not directly applicable to asynchronous pipelined processors, because of distributed control nature of the latter. As a result of that, most asynchronous equivalents of MIPS propose novel hazard resolution methods, adding an overhead in terms of performance and complexity. In this work, we build a counter narrative by proposing a novel pipelined register organization that maintains synchrony with a flexible clock generator instead of the rigid clock, which also allow us to utilize the synchronous hazard resolving methods. Our simulation results – using Balsa – suggest 20.8% improvement in execution time as compared to one of the existing asynchronous processors. Zaheer Tabassam, Syed Rameez Naqvi, Andreas Steininger |
DDECS | 3 |
| 2022 | Towards Resilient QDI Pipeline ImplementationsabstractQDI circuits are robust towards timing issues, but this elasticity makes them vulnerable in value-domain fault scenarios because data-accepting windows are flexibly defined by the handshakes, and during these windows any data transition gets latched, even those originating from single event transients. As a solution, locking the data-accepting windows after the first transition contributes to robustness, but still needs consideration. We examine WCHB variants called Interlocking-WCHB and Input/Output-Interlocking-WCHB in this respect. To highlight the relevant error triggering conditions, we chose two target circuits to investigate the behavior in detail: FIFO and pipelined multiplier. Based on the experimental results we investigate the observed errors to understand the main cause of their generation and propagation. We highlight the problematic scenarios and propose modifications in buffer styles that resolve most of these while minimizing the area overhead to 50%. Zaheer Tabassam, Andreas Steininger |
DSD | 2 |
| 2022 | enpheeph: A Fault Injection Framework for Spiking and Compressed Deep Neural NetworksabstractResearch on Deep Neural Networks (DNNs) has focused on improving performance and accuracy for real-world deployments, leading to new models, such as Spiking Neural Networks (SNNs), and optimization techniques, e.g., quantization and pruning for compressed networks. However, the deployment of these innovative models and optimization techniques introduces possible reliability issues, which is a pillar for DNNs to be widely used in safety-critical applications, e.g., autonomous driving. Moreover, scaling technology nodes have the associated risk of multiple faults happening at the same time, a possibility not addressed in state-of-the-art resiliency analyses. Towards better reliability analysis for DNNs, we present enpheeph, a Fault Injection Framework for Spiking and Compressed DNNs. The enpheeph framework enables optimized execution on specialized hardware devices, e.g., GPUs, while providing complete customizability to investigate different fault models, emulating various reliability constraints and use-cases. Hence, the faults can be executed on SNNs as well as compressed networks with minimal-to-none modifications to the underlying code, a feat that is not achievable by other state-of-the-art tools. To evaluate our enpheeph framework, we analyze the resiliency of different DNN and SNN models, with different compression techniques. By injecting a random and increasing number of faults, we show that DNNs can show a reduction in accuracy with a fault rate as low as$7\times 10^{-7}$faults per parameter, with an accuracy drop higher than 40%. Run-time overhead when executing enpheeph is less than 20% of the baseline execution time when executing 100 000 faults concurrently, at least 10× lower than state-of-the-art frameworks, making enpheeph future-proof for complex fault injection scenarios. We release the source code of our enpheeph framework under an open-source license at https://github.com/Alexei95/enpheeph. Alessio Colucci, Andreas Steininger, Muhammad Shafique 0001 |
IROS | 2 |
| 2022 | Simulation-Based Approaches for Comprehensive Schmitt-Trigger AnalysesabstractSchmitt-Triggers (S/Ts) are often utilized to clean noisy analog signals at intermediate voltage values in digital circuits. However, they are vulnerable to metastability, which may cause the same undesired non-digital output behavior that was supposed to be removed in the first place. To enable an efficient characterization of static and dynamic metastability properties of S/Ts (e.g., the metastable voltages, the resolution time constants and the overall total resolution times), this work introduces multiple simulation approaches based on control theory, AC, DC and transient analyses. The accuracy and runtime of all methods are compared and discussed by applying them to an analytically describable idealized circuit model as well as three common circuit implementations. Altogether, this work represents a comprehensive resource for investigating the metastable behavior in S/Ts. Even more, the proposed methods are applicable beyond the S/T, enabling an efficient characterization of static and dynamic metastable behavior in general circuits as well. Jürgen Maier 0002, Christian Hartl-Nesic, Andreas Steininger |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2021 | Analysis of State Corruption caused by Permanent Faults in WCHB-based Quasi Delay-Insensitive PipelinesabstractQuasi delay-insensitive asynchronous circuits have the appealing property of stopping further operation in case of a permanent fault. This fail-stop behavior makes them attractive for on-line repair: after removal of the permanent fault, the circuit can, ideally, continue operating without the need for state recovery. However, it has been shown that in certain cases the state may get corrupted before the operation actually stops.In this paper we use the example of a weak-conditioned half-buffer template to investigate more closely which situations can lead to such state corruption. We explore implementation variants like double completion detection to mitigate that undesired effect. Based on extensive gate-level simulation experiments we quantify the probability for state corruption seen in the different circuits and identify the relevant dependences. As it turns out, the proposed extensions can reduce, but not completely eliminate, the risk of state corruption. At the same time detection of illegal code words promises to have great potential for countermeasures. Raghda El Shehaby, Andreas Steininger |
DDECS | 2 |
| 2021 | An Automated Setup for Large-Scale Simulation-Based Fault-Injection Experiments on Asynchronous Digital CircuitsabstractExperimental fault injection is an essential tool in the assessment and verification of fault-tolerance properties. Often, in these experiments it is impossible to reasonably cover the huge parameter space spanned by target state and fault parameters, and compromises or restrictions must be made. This is even more pronounced for asynchronous circuits where a convenient discretization of time through a synchronous clock is not possible. In this paper we present a fault-injection toolset that allows for a very efficient injection and data processing, thus bringing studies with many billions of meaningful injections into asynchronous targets within reach. The key ingredients of our solution are an auto-setup feature capable of optimizing parameter values, seamless distribution of the simulation load to many host computers, and efficient arrangement of the important settings and readings in a database. We will use the example of a comparative study of different asynchronous pipeline styles to motivate the need for such an approach and illustrate its benefits. Patrick Behal, Florian Huemer, Robert Najvirt, Andreas Steininger |
DSD | 4 |
| 2020 | Merging Redundant Crystal Oscillators into a Fault-Tolerant ClockabstractHaving a precise and stable clock that is still fault tolerant is a fundamental prerequisite in safety critical real-time systems. However, combining redundant independent clock sources to form a single clock supply is non-trivial, even if only a single clock output is desired. Often there is a need for having redundant clock outputs - like for the replicated nodes within a TMR architecture - that fail independently but still stay tightly synchronized. This problem is even harder to solve.In this paper we present solutions for the latter. We elaborate a solution for producing tightly synchronized clock outputs in a fault-tolerant fashion. This approach extends an existing, ring-oscillator like distributed clock generation scheme by augmenting each of its constituent nodes with a stable clock reference. We illustrate in theory and by simulation experiments that the four clock outputs of our circuit do not share a single point of failure, have small and bounded skew, remain stabilized to one crystal source during normal operation, do not propagate glitches from one failed clock to a correct one, and only exhibit slightly extended clock cycles during a short stabilization period after a component failure. Wolfgang Duer, Andreas Steininger |
DDECS | 2 |
| 2020 | On the Effects of Permanent Faults in QDI Circuits - A Quantitative PerspectiveabstractWith their event-driven nature, quasi-delay-insensitive (QDI) asynchronous circuits offer a compelling fail-stop behavior along with an inherent 100 % permanent fault detection coverage. In fact, permanent faults break the handshake, pushing the circuit into deadlock. In this paper we give quantitative results for the relative occurrence of the different effects that can manifest in a QDI circuit due to permanent faults. We study in which and how many cases the state of the circuit gets corrupted before reaching the deadlock. This behavior diagnosis enables us to identify the cases in which the circuit can go back to operating normally if a (self-) repair process were to take place. This investigation is conducted through extensive fault injection experiments in a chosen circuit simulation. Stuck-at faults are injected on a gate-level VHDL model of the circuit, with a wide coverage of parameters. Raghda El Shehaby, Andreas Steininger |
ICCD | 2 |
| 2019 | International Symposium on Design and Diagnostics of Electronic Circuits and SystemsabstractThe paper is a contribution to the 50th anniversary celebration of the International Test Conference (ITC) and its Global Test Forum (GTF), which honors the geographic breadth of the test community and highlights the global reach of ITC during the past 50 years. It covers the past, present, and future of the International Symposium on Design and Diagnostics of Electronic Circuits and Systems (DDECS), a symposium which belongs to prominent test technology related events initiated and supported by the ITC. Zoran Stamenkovic, Alberto Bosio, György Cserey, Ondrej Novák, Witold A. Pleskacz, Lukás Sekanina, Andreas Steininger, Goran Stojanovic, Viera Stopjaková |
ITC | 7 |
| 2018 | Using a Duplex Time-to-Digital Converter for Metastability Characterization of an FPGAabstractIn view of the increasing number of clock domains found in modern ASICs, the precise characterization of metastability at their boundaries becomes crucial. In some cases, the conventional approach does not provide a sufficient level of detail information. As an alternative approach, the use of a time-to-digital converter based on a tapped delay line has been proposed. In this paper we extend the latter by an additional tapped delay line thus allowing to further refine the concept. We present the underlying concept, its implementation, as well as experimental measurements on an FPGA platform that reveals significant variations in the metastable behavior of different FPGA boards of the same type. Florian Huemer, Thomas Polzer, Andreas Steininger |
DDECS | 3 |
| 2017 | A Critical Charge Model for Estimating the SET and SEU Sensitivity: A Muller C-Element Case StudyabstractThis paper presents a critical charge model for estimating the SET and SEU robustness. The proposed model has been derived by analytic fitting of SPICE results, using a Muller C-element designed in 65 and 130 nm bulk CMOS technologies as the target device. The critical charge is expressed in terms of the size of C-element, size of load inverter, supply voltage and temperature, for constant timing parameters of the SET/SEU current pulse. The proposed model could be utilized to calculate the critical charge causing a SET, for both analyzed technologies, with the accuracy comparable to SPICE simulations. The critical charge for SEU was higher than for SET, but the dependencies obtained for SET response were qualitatively similar to those for SEU. This implies that the proposed critical charge model may be applicable for optimizing the SET/SEU robustness evaluation of the circuits involving the Muller C-element. Moreover, the model may also serve as a basis for evaluating the SET/SEU robustness of other standard cells and other technologies, and thus also for analysis of the SET/SEU robustness of complex circuits. Marko S. Andjelkovic, Milos Krstic, Rolf Kraemer, Varadan Savulimedu Veeravalli, Andreas Steininger |
ATS | 5 |
| 2017 | Measuring metastability using a time-to-digital converterabstractIn view of the numerous clock domain crossings found in modern systems-on-chip and multicore architectures precise metastability characterization is a fundamental task. We propose a conceptually novel approach for the experimental assessment of upset rate over resolution time that is usually employed to extract the relevant characteristics. Our method is based on connecting a time-to-digital converter to the output of the flip flop under test, rather than using a phase shifted clock, as conventionally done. We present the details of an FPGA implementation of our approach and show its feasibility through an experimental evaluation, whose results favorably match those obtained by the conventional method. The benefits of the novel scheme are the ability to perform a calibration for the delay steps, a speed-up of the measurement process, and the availability of a more comprehensive and ordered measurement data set. Thomas Polzer, Florian Huemer, Andreas Steininger |
DDECS | 3 |
| 2017 | Setup for an Experimental Study of Radiation Effects in 65nm CMOSabstractPhysical radiation experiments are a vital means for calibrating simulation models targeted to studying the impact of ionizing particles on VLSI circuits. However, their conduction requires special care and a very specific setup. In this paper we give an overview of such an experimental setup, and highlight some specific details. Beyond showing the context overarching the objectives of the experiments, the envisioned radiation sources, as well as design and architecture of a specific target ASIC, we will put specific emphasis on the communication infrastructure, namely an FPGA that controls the data exchange between some preprocessing infrastructure located on the target ASIC on one side and the host PC running the data analysis on the other. Finally, the physical arrangement comprising carrier PCB for the target ASIC, and cabling, which need to adhere specific requirements, will receive some attention as well. Bernhard Fritz, Andreas Steininger, Václav Simek, Varadan Savulimedu Veeravalli |
DSD | 2 |
| 2016 | A general approach for comparing metastable behavior of digital CMOS gatesabstractIn digital CMOS essentially all sequential function blocks may get metastable in one way or another, when provided with marginal inputs. Most often the result is a delayed reaction at the output, which, in a synchronous design, potentially violates the timing assumptions. Therefore metastable behavior is often characterized by the Mean Time Between Upset (MTBU), which reflects the expected interval between such violations on a statistical base. However, not all designs are synchronous - there are even sequential elements specifically intended for use in context with elastic timing, such as the mutual exclusion element or the Muller C-element. For these a characterization via MTBU is not useful; but on the other hand there seem to be no reasonable alternatives. Therefore in this paper we propose the use of the delay graph (over the relevant quantity that causes metastability when becoming marginal) for this purpose. We elaborate its correspondence with the usual MTBU graph and the metastability parameters, namely tau and T0. As a proof of concept we apply our strategy to a set of sequential elements, like D-latch, RS-latch, Muller C-element and mutex and discuss the differences we identified. Thomas Polzer, Andreas Steininger |
DDECS | 2 |
| 2016 | Does Cascading Schmitt-Trigger Stages Improve the Metastable Behavior?abstractSchmitt-Trigger stages are the method of choice for robust discretization of input voltages with excessive transition times or significant noise. However, they may suffer from metastability. Based on the experience that the cascading of flip-flop stages yields a dramatic improvement of their overall metastability hardness, in this paper we elaborate on the question whether the cascading of Schmitt-Trigger stages can obtain a similar gain. We perform a theoretic analysis that is backed up by an existing metastability model for a single Schmitt-Trigger stage and elaborate some claims about the behavior of a Schmitt-Trigger cascade. These claims suggest that the occurrence of metastability is indeed reduced from the first stage to the second which suggests an improvement. On the downside, however, it becomes clear that metastability can still not be completely ruled out, and in some cases the behavior of the cascade may be less beneficial for a given application, e.g. by introducing seemingly acausal transitions. We validate our findings by extensive HSPICE simulations in which we directly cover our most important claims. Andreas Steininger, Robert Najvirt, Jürgen Maier 0002 |
DSD | 1 |
| 2016 | Design and Physical Implementation of a Target ASIC for SET ExperimentsabstractWe present design aims and implementation results of a digital ASIC that is dedicated as a target for radiation experiments. Accordingly, it carries different target circuit blocks whose purpose is to study susceptibility to radiation as well as propagation of radiation effects. On-chip measurement infrastructure is mainly comprised of counters that record single event transients in various nodes of the target blocks. As it competes with the target blocks for chip area, it must be kept as small as possible, in spite of the need of being tolerant to particle hits in itself, which cannot be avoided in some types of radiation experiments. We sketch our respective solutions and present the resulting area distribution of the final ASIC layout for an industrial 65nm bulk CMOS process. We also show how we optimized the layout for the purpose of our experiments and present all relevant implementation details. Varadan Savulimedu Veeravalli, Andreas Steininger |
DSD | 2 |
| 2016 | Study of a delayed single-event effect in the Muller C-elementabstractWe study the behavior of the Muller C-element, a fundamental building block in asynchronous design, under SETs. Beyond the expected reactions to the injected SETs - namely immediate state flip or pulse at the output - we also observed an new kind of behavior for the Muller C-element, namely a delayed state flip. In this paper we give a closer analysis of this effect and identify its enabling conditions. Varadan Savulimedu Veeravalli, Andreas Steininger |
ETS | 2 |
| 2016 | A new coding scheme for fault tolerant 4-phase delay-insensitive codesabstractDelay-insensitive (DI) codes are usually prone to transient faults occurring during an ongoing transmission. For most DI code words even a single transient can turn an incomplete transmission into a complete code word, which is different from the originally sent one. In this paper we therefore propose a novel two-step data encoding scheme that combines DI and error detecting codes. Our solution exploits the inherent fault resilience of DI codes to achieve a low coding overhead. For analyzing this fault resilience we use methods from graph theory. In contrast to existing approaches we carefully avoid the introduction of timing assumptions to mask faults. The presented coding scheme is generic and can, in principle, be used with any 4-phase DI code. We show how to apply it to m-of-n codes and analyze the resulting coding efficiency. Florian Huemer, Jakob Lechner, Andreas Steininger |
ICCD | 3 |
| 2015 | Containment of Metastable Voltages in FPGAsabstractThe significant PVT variations seen with modern technologies make synchronous design inefficient. Asynchronous design with its flexible timing is a promising alternative, but prototyping is difficult on the available FPGA platforms which are clock centric and do not provide the required functional primitives like mutual exclusion or Muller C-elements. The solutions proposed in the literature work nicely in principle, but cannot safely handle metastability issues that are inevitable at interfaces even in asynchronous designs. In this paper we propose a reliable implementation of a Schmitt-trigger, which allows to safely convert potential intermediate voltage levels that result from metastability into late transitions that can be reliably handled in the asynchronous domain. Beyond the actual circuit we also discuss the associated routing constraints to make the circuit work properly in spite of the uncertain routing within FPGAs. Furthermore we propose a procedure for an "in situ reliability assessment" of the specific Schmitt-trigger element under consideration, which also applies to metastability containment with high-or low-threshold inverters only. Our proof of concept is based on experimental results for both Xilinx and Altera FPGA platforms. Robert Najvirt, Thomas Polzer, Florian Beck, Andreas Steininger |
DDECS | 4 |
| 2015 | Measuring the Distribution of Metastable Upsets over TimeabstractAs modern ASICs comprise an increasing number of independently clocked subsystems that need to interact, the accurate reliability assessment of synchronizers becomes crucial. Traditionally the reliability of a synchronizer is characterized by the mean time between upsets (MTBU), and the relevant flip-flop parameters are specified in a way to support MTBU calculation. In this paper we claim that actually a deeper insight into the distribution of upsets over time is needed in order to make a reasonable prediction in the range of the high reliability values that are generally targeted. We present a measurement concept that appropriately extends state-of-the-art approaches so as to allow for an experimental assessment of the upset distribution over time. In this way the distribution function can be studied, and in particular the probability of upsets with low temporal distance -- which is the relevant one for high reliability -- can be identified. We implement our concept on three different FPGA platforms and present the selected results. The distribution function we obtain indicates that the assumption of a uniform or standard normal distribution, which one might be tempted to imply for lack of better information, is definitely not generally useful. Thomas Polzer, Andreas Steininger |
DSD | 2 |
| 2015 | Enhanced Metastability Characterization Based on AC AnalysisabstractThe common way of characterizing the metastability properties of a circuit is by its metastability resolution constant τ and the aperture window. This approach is based on a model that represents the storage cell as a pair of crosscoupled inverters, each of which is, in turn, modeled by a constant-gain amplifier with a first-order low-pass filter at the output. The former reflects the inverter's signal regeneration capability, while the latter approximates its dynamic behavior. In this simple model there is no natural way of expressing, e.g., the load dependence of tau, therefore each change of the element's load capacitance requires a full recalibration. In this paper we propose decomposing the inverter into its constituent transistors and using their small-signal equivalent circuits for modeling. Metastability characterization is now based on a Spice AC analysis which yields a higher-order dynamic model of the circuit. Once the relevant parameters are known for a given element, the load dependence of tau can be expressed analytically, thus elegantly avoiding recalibration. We compare our approach with the extended nose short simulation (ENSS) method from literature and show that the results deviate by no more than 1-2%. Thomas Polzer, Andreas Steininger |
DSD | 2 |
| 2015 | Reliable and Continuous Measurement of SET Pulse WidthsabstractGaining better insights into propagation and masking of radiation induced faults at some point requires the conduction of physical experiments. In our attempt to design a target ASIC for such experiments we elaborated an on-chip infrastructure that allows recording the pulse width of radiation induced voltage transients. Its unique properties are the ability to record more than one of these measurement values before having to be read out, and to be radiation tolerant. By careful circuit design and an unconventional redundancy architecture we obtained an infrastructure that provides the required features while being extremely area efficient. We motivate and present our proposed circuit architecture and evaluate it by means of a fault dictionary as well as simulation results. Varadan Savulimedu Veeravalli, Andreas Steininger |
DSD | 2 |
| 2015 | Methods for analysing and improving the fault resilience of delay-insensitive codesabstractDelay-insensitive (DI) codes are usually prone to transient faults occurring during an ongoing transmission. For most DI codewords even a single transient can turn an incomplete transmission into a complete codeword, which is different from the originally sent codeword. Unless further redundant information is provided, the receiver has no means to detect such a transmission fault. In this paper we therefore propose two methods to systematically increase redundancy, either by i) building resilient subcodes, or by ii) using a two-step data encoding where error detecting codes are appropriately combined with delay-insensitive codes. In contrast to existing approaches we carefully avoid the introduction of timing assumptions to mask faults. Both methods are generic and can be used for any 4-phase DI code. In this paper we apply them to m-of-n codes, Berger and Zero-Sum codes and thoroughly analyse the efficiency of the resulting coding schemes. Jakob Lechner, Andreas Steininger, Florian Huemer |
ICCD | 2 |
| 2015 | A composable real-time architecture for replicated railway applications
Stefan Resch, Andreas Steininger, Christoph Scherrer |
J. Syst. Archit. | 2 |
| 2014 | A tree arbiter cell for high speed resource sharing in asynchronous environmentsabstractWe present a novel tree arbiter cell that allows a pipelined processing of asynchronous requests. In this way it can achieve significantly lower delay in the critical case of frequent requests coming from different clients. We elaborate the necessary extension to facilitate a cascaded use of this cell in a tree-like fashion, and we show by theoretical analysis that in this configuration our cell provides better fairness than the standard approach. We implement our approach and quantitatively compare its performance properties with related work in a gatelevel simulation. In our sample asynchronous Networks-on-Chip application our new cell proves to increase the throughput of three different designs available in literature by approximately 61.28%, 69.24%, and 186.85% respectively. Syed Rameez Naqvi, Andreas Steininger |
DATE | 2 |
| 2014 | Online test vector insertion: A concurrent built-in self-testing (CBIST) approach for asynchronous logicabstractComplementing concurrent checking with online testing is crucial for preventing fault accumulation in fault-tolerant systems with long mission times. While implementing a non-intrusive online test is cumbersome in a synchronous environment, this task becomes even more challenging in asynchronous designs. The latter receive increasing attention, mainly due to their elastic timing behaviour; however the issues related with their testing remain a key obstacle for their wide adoption. In this paper we present a novel approach for testing of asynchronous circuits that leverages the redundancy present in the conventional 4-phase protocol for implementing a fully transparent and fully concurrent test procedure. The key idea is to use the protocol's unproductive NULL phase for processing test vectors, thus effectively interleaving the incoming 4-phase data stream with a test data stream in a 2-phase fashion. We present implementation templates for the fundamental building blocks required and give a proof-of-concept by an example application that also serves as a platform for evaluating the overheads of our solution which turn out to be moderate. Jürgen Maier 0002, Andreas Steininger |
DDECS | 2 |
| 2014 | Exploring the state dependent SET sensitivity of asynchronous logic - The muller-pipeline exampleabstractAsynchronous circuits exhibit considerable advantages over their synchronous counterparts, like lower dynamic power and inherent variation tolerance, which makes them increasingly interesting. Their fault-tolerance behavior, however, is not yet fully explored. In particular, temporal masking, as seen with synchronous circuits, seems to be completely non-existent in asynchronous logic. Instead, there seem to be other masking mechanisms in the control structure that establish an extra barrier for transient fault propagation. In this paper we will explore these masking mechanisms in a qualitative as well as quantitative manner. To this end we first analyze the behavior of a Muller C-element, one fundamental building block in asynchronous designs. In a next step we evaluate the behavior of a chain of these elements, forming a so-called Muller pipeline, the basic control structure of many asynchronous designs, under transient faults. To validate our theoretical findings we inject radiation induced single event transients (SETs) in an extensive simulation campaign. The results show that the SET susceptibility of the Muller pipeline is indeed state dependent. This knowledge can be leveraged to improve, e.g., the radiation hardness of asynchronous circuits by preferring the more robust states in their design wherever possible. Andreas Steininger, Varadan Savulimedu Veeravalli, Dan Alexandrescu, Enrico Costenaro, Lorena Anghel |
ICCD | 1 |
| 2014 | Rigorously modeling self-stabilizing fault-tolerant circuits: An ultra-robust clocking scheme for systems-on-chipabstractWe present the first implementation of a distributed clock generation scheme for Systems-on-Chip that recovers from an unbounded number of arbitrary transient faults despite a large number of arbitrary permanent faults. We devise self-stabilizing hardware building blocks and a hybrid synchronous/asynchronous state machine enabling metastability-free transitions of the algorithm's states. We provide a comprehensive modeling approach that permits to prove, given correctness of the constructed low-level building blocks, the high-level properties of the synchronization algorithm (which have been established in a more abstract model). We believe this approach to be of interest in its own right, since this is the first technique permitting to mathematically verify, at manageable complexity, high-level properties of a fault-prone system in terms of its very basic components. We evaluate a prototype implementation, which has been designed in VHDL, using the Petrify tool in conjunction with some extensions, and synthesized for an Altera Cyclone FPGA. Danny Dolev, Matthias Függer, Markus Posch, Ulrich Schmid 0001, Andreas Steininger, Christoph Lenzen 0001 |
J. Comput. Syst. Sci. | 5 |
| 2014 | Runtime verification of microcontroller binary code
Thomas Reinbacher, Jörg Brauer, Martin Horauer, Andreas Steininger, Stefan Kowalewski |
Sci. Comput. Program. | 4 |
| 2013 | A Multi-Credit Flow Control scheme for asynchronous NoCsabstractCredit schemes are used to establish flow control in NoCs without blocking the communication channel. In traditional implementations one credit is transmitted per data flit, so the credit channel conveys as many messages as the data channel. Our proposed multi-credit scheme transmits credits in bundles of M, yielding one credit transmission per M flits. This saves transitions on the credit channel and promises a slower, more energy efficient implementation. We investigate requirements, options and benefits of this approach; first in theory, and then in a concrete application example, in which we propose a specifically beneficial implementation. Our study confirms that, with a negligible increase in area, our scheme can reduce dynamic energy as well as bandwidth requirements for the credit channel. Syed Rameez Naqvi, Robert Najvirt, Andreas Steininger |
DDECS | 3 |
| 2013 | Digital Late-Transition Metastability Simulation ModelabstractAs modern systems-on-chip contain increasingly more clock domain crossings, the associated metastability effects become much more pronounced. To maintain the reliability of the design, efficient means for metastability analysis become mandatory. We propose an approach that allows simulation of late transitions, the most dominant effect of metastability in modern VLSI chips. While this approach is purely digital and hence very fast, it allows a precise treatment in the time domain. These properties make it attractive for modeling even complex circuit structures. The core of our approach is a timing model that carefully maps the relative times of setting the latch opaque and the arrival of new data at the input to the appropriate data-input/output delay. Unlike with existing models this mapping is not simply linear and hence restricted to a very narrow scope, it rather works for arbitrary inter-arrival times between data and enable. We systematically elaborate an analytic description of this input/output delay and illustrate how the respective model parameters can be derived from an initial circuit simulation, either automatically or with manual support. Once calibrated, the model allows fast and precise simulation, which we illustrate in a case study. Thomas Polzer, Andreas Steininger |
DSD | 2 |
| 2012 | Designing FlexRay-based automotive architectures: A holistic OEM approachabstractFlexRay is likely to become the de-facto standard for upcoming in-vehicle communication. Efficient scheduling of the static and dynamic segment of the communication cycle in combination with the determination of more than 60 parameters that are part of the FlexRay protocol is a challenging task. This paper provides a formal analysis for interdependencies between the parameters as well as a scheduling approach for the static and dynamic segment. Experimental results give evidence of a significant interdependency between the subtasks such that a holistic scheduling approach becomes mandatory to provide high-quality FlexRay schedules. As a solution, this work introduces a complete functional FlexRay scheduling approach that takes parameter selection, allocation of messages to the static and dynamic segment, and concurrent scheduling into account. A real-world case study from the automotive domain gives evidence of efficiency and applicability of the proposed approach. Paul Milbredt, Michael Glaß, Martin Lukasiewycz, Andreas Steininger, Jürgen Teich |
DATE | 4 |
| 2012 | Radiation-tolerant combinational gates - an implementation based comparisonabstractAs newer CMOS technologies are known to be more susceptible to particle hits, radiation tolerance is receiving increased attention. Several techniques for attaining this property are available in the literature already. However, virtually all of the publications refer to an inverter circuit, and the related robustness assessments (if any) are hard to compare, since important characteristics, such as technology or fault model, differ. In this paper we fill this gap by applying the available concepts to combinational gates, in particular an XOR gate, using the same concrete technology and sizing as well as the same fault model. By means of extensive analog simulations we verify and finally tune their robustness to the same level. On this foundation we can then make a comparison of the respective overheads and problems, such that it becomes relatively easy to distinguish efficient solutions from problematic ones. Varadan Savulimedu Veeravalli, Andreas Steininger |
DDECS | 2 |
| 2012 | Protecting an Asynchronous NoC against Transient Channel FaultsabstractConsidering the increasing rates of transient faults predicted for future technology nodes, we investigate options for protecting the communication channels within an NoC from those. Our target is an asynchronous NoC, as its data-driven activity emanates from a more energy aware communication concept. We compare different redundancy schemes with the aim of providing a reliable communication service where error detection and correction is transparent to the higher system levels, and we also propose a new scheme. Our comparison is supported by results from simulation and synthesis. While all solutions are designed to withstand at least one transient fault, they largely differ in their area and delay penalty as well as potential extra coverage that some of them offer. Syed Rameez Naqvi, Varadan Savulimedu Veeravalli, Andreas Steininger |
DSD | 3 |
| 2012 | Architecture and Design Analysis of a Digital Single-Event Transient/Upset Measurement ChipabstractThis paper presents the architecture and a detailed design analysis of a digital measurement chip which facilitates long-term irradiation experiments of basic asynchronous circuits. It combines radiation targets like Muller C-elements and elastic pipelines as well as standard combinational gates and flip-fops with an elaborate on-chip measurement infrastructure. Major architectural challenges result from the fact that the latter must operate reliably under the same radiation conditions the target circuits are exposed to, without wasting precious die area for a rad-hard design. A measurement architecture based on multiple non-rad-hard counters is used, which we show to be resilient against double faults, as well as many triple and even higher-multiplicity faults. The analysis is done by means of comprehensive fault injection experiments, which are based on detailed Spice models of the circuits in conjunction with a standard double-exponential current injection model for single-event transients. We also provide probabilistic calculations of the sustainable particle flow rates, based on the results of a detailed area analysis in conjunction with experimentally determined cross section data for the ASIC implementation technology used. The results confirm that the overall architecture indeed supports significant target hit rates, without exceeding the resilience bound of the measurement infrastructure. Varadan Savulimedu Veeravalli, Thomas Polzer, Andreas Steininger, Ulrich Schmid 0001 |
DSD | 3 |
| 2011 | Past Time LTL Runtime Verification for Microcontroller Binary Code
Thomas Reinbacher, Jörg Brauer, Martin Horauer, Andreas Steininger, Stefan Kowalewski |
FMICS | 4 |
| 2011 | Automated Test-Trace Inspection for Microcontroller Binary Code
Thomas Reinbacher, Jörg Brauer, Daniel Schachinger, Andreas Steininger, Stefan Kowalewski |
RV | 4 |
| 2010 | A deterministic approach for hardware fault injection in asynchronous QDI logicabstractThis paper presents a new approach for hardware based fault injection in Quasi Delay Insensitive (QDI) asynchronous circuits. Configurable saboteurs are placed at points of interest in the circuit and allow to inject various types of faults on an arbitrary number of signals. These saboteurs not only redefine the logic value of a faulty signal but also the exact moment of the fault occurrence. In asynchronous logic, signal events rather than time are used to trigger on a circuit's state. Our concept allows to precisely control the order of concurrent signal events. It can be shown that the fault sensitivity highly depends on that event ordering. Thereby a deterministic and reproducible investigation of QDI circuits in the presence of transient and permanent faults in hardware is obtained. The work is evaluated by fault injection experiments on different circuits. Werner Friesenbichler, Thomas Panhofer, Andreas Steininger |
DDECS | 3 |
| 2010 | Enhancing pipelined processor architectures with fast autonomous recovery of transient faultsabstractRecent technology trends have made radiation-induced soft errors a growing threat to the reliability of microprocessors, a problem previously only known to the aerospace industry. Therefore, the ability to handle higher soft error rates in modern processor architectures is essential in order to allow further technology scaling. This paper presents an efficient fault-tolerance method for pipeline-based processors using temporal redundancy. Instructions are executed twice at each pipeline stage, which allows the detection of transient faults. Once a fault is detected the execution is stopped immediately and recovery is implicitly performed within the pipeline stages. Due to this fast reaction the fault is contained at its origin and no expensive rollback operation is required later on. Marcus Jeitler, Jakob Lechner, Andreas Steininger |
DDECS | 3 |
| 2009 | Remote measurement of local oscillator drifts in FlexRay networksabstractDistributed systems, especially time-triggered ones, are implementing clock synchronization algorithms to provide and maintain a common view of time among the different nodes. Such architectures heavily rely on the nodes' local oscillators to remain within given accuracy bounds. However, measuring the oscillator frequencies (e.g., for maintenance or diagnosis) is usually difficult to perform since it requires physical access to each single node and may interfere with the running application. Moreover, clock synchronization features tend to mask clock deviations. In this work, we propose a non-intrusive method for remote measurement of the individual oscillator drifts within a distributed system. Our approach is based on a tester that sends carefully aligned messages to stimulate the clock synchronization service and records the resulting bus traffic for an analysis of the nodes' synchronization behavior. This tester needs access to the communication bus only. We focus our work to FlexRay and validate our approach by experiments. Eric Armengaud, Andreas Steininger |
DATE | 2 |
| 2009 | On the role of the power supply as an entry for common cause faults - An experimental analysisabstractThe principle of duplication and comparison has proven very efficient for error detection in processor cores, since it can be applied as a generic solution for making virtually any type of core fail safe. A weakness of this approach, however, is the potential for common cause faults: Faults affecting both cores in the same way will escape detection. Shared resources and signals are especially prone to such effects. In practice the efforts for providing a redundant power source are often prohibitive, thus rendering the power supply such a shared resource. While a complete failure of the supply voltage can be relatively easily accommodated in a fail safe system, short pulses can have subtle consequences and are therefore much more dangerous. In this paper we will perform an experimental study of the potential of such power supply induced faults to create common cause effects. For this purpose we first study their effects on the operation of a processor core. In particular we will show that, when applied with the most adverse parameters, they tend to cause timing violations in the critical path. In two instances of the same core there is therefore a non-negligible risk of common cause effects. We will quantitatively assess this risk through fault injection experiments into an FPGA based dual core design. Peter Tummeltshammer, Andreas Steininger |
DDECS | 2 |
| 2009 | Soft Error Tolerant Asynchronous Circuits Based on Dual Redundant Four State LogicabstractThe continuing downscaling of integrated circuits makes modern devices more susceptible to soft errors. This paper investigates the possibility of using Four-State Logic (FSL) to improve the fault tolerance of digital circuits. FSL is a possible implementation of asynchronous Quasi Delay Insensitive (QDI) logic using a more efficient encoding and handshake protocol. The behavior of asynchronous circuits designed with FSL when subjected to transient faults is analyzed. We present methods based on dual redundancy that allow to detect as well as correct soft errors autonomously. The concept is demonstrated by fault injection experiments. Werner Friesenbichler, Andreas Steininger |
DSD | 2 |
| 2009 | On the Risk of Fault Coupling over the Chip SubstrateabstractDuplication and comparison has proven to be an efficient method for error detection. Based on this generic principle dual core processor architectures with output comparison are being proposed for safety critical applications. Placing two instances of the same (arbitrary) processor on one die yields a very cost efficient "single chip" implementation of this principle. At the same time, however, the physical coupling of the two replica creates the potential for certain types of faults to affect both cores in the same way, such that the mutual checking will fail. The key question here is how this type of coverage leakage relates to other imperfections of the duplication and comparison approach that would also be found using two cores on separate dies (such as coupling over a common power supply or clock). In this paper we analyze several of the relevant physical coupling mechanisms and elaborate a model to decompose the genesis of a common cause fault into several steps. We present an experimental study showing that a very tight local and temporal coincidence of the fault effect in both replica is a crucial prerequisite for a common cause fault. Based on this quantitative input we can conclude from our decomposition model that the risk of common cause faults is low for physical coupling mechanisms with relatively slow propagation speed, such as thermal and mechanical effects. The role of asymmetry for mitigating common cause faults is discussed in the light of these findings. Peter Tummeltshammer, Andreas Steininger |
DSD | 2 |
| 2009 | Power supply induced common cause faults-experimental assessment of potential countermeasuresabstractFault-tolerant architectures based on physical replication of components are vulnerable to faults that cause the same effect in all replica. Short outages in a power supply shared by all replica are a prominent example for such common cause faults. For systems in which the provision of a replicated power supply would cause prohibitive efforts the identification of reliable countermeasures against these effects is vital to maintain the required dependability level. In this paper we propose several of such countermeasures, namely parity protection, voltage monitoring and time diversity of the replica. We perform extensive fault injection experiments on three fault-tolerant dual core processor designs, one FPGA based and two commercial ASICs. These experiments provide evidence for the vulnerability of a completely unprotected dual core solution, while time diversity and voltage monitoring in combination with increased timing margins turn out particularly effective for eliminating common cause effects. Peter Tummeltshammer, Andreas Steininger |
DSN | 2 |
| 2009 | A Metastability-Free Multi-synchronous Communication Scheme for SoCs
Thomas Polzer, Thomas Handl, Andreas Steininger |
SSS | 3 |
| 2009 | Is Asynchronous Logic More Robust Than Synchronous Logic?abstractWith clock rates beyond 1 GHz, the model of a system wide synchronous clock is becoming difficult to maintain; therefore, asynchronous design styles are increasingly receiving attention. While the traditional synchronous design style is well-proven and backed up by a rich field experience, comparatively little is known about the properties of asynchronous circuits in practical application. In the face of increased transient fault rates, robustness is a crucial property, and from a conceptual view, the so-called ldquodelay-insensitiverdquo asynchronous design approaches promise to be more robust than synchronous ones, since their operation does not depend on tight timing margins, and data are two-rail coded. A practical assessment of asynchronous designs in fault-injection (FI) studies, however, can rarely be found, and there is a lack of adequate methods and tools in this particular domain. Therefore, the objective of this work is 1) to provide a common approach for efficient and accurate FI in synchronous and in asynchronous designs, and 2) to experimentally compare the robustness of both synchronous and asynchronous designs. To this end, a synchronous 16-bit processor as well as its asynchronous (delay insensitive) equivalent are subjected to signal flips and delay faults. The results of over 489 million experiments are summarized and discussed, and a detailed discussion on the specific properties of the chosen asynchronous design style is given. Babak Rahbaran, Andreas Steininger |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2009 | Safely Stimulating the Clock Synchronization Algorithm in Time-Triggered Systems - a Combined Formal & Experimental ApproachabstractDeterministic replay is used during testing to reproduce a scenario and drive the system under test to a given state. In this work, we replay ana prioridefined bus traffic to influence the clock synchronization mechanism. Beyond testing this distributed mechanism itself, our aim is to draw conclusions on the nodes' bus receiver operation. Since these replay activities are part of a transparent online test procedure, it is important to ensure that they do not represent a threat for proper system operation. We show this for TTP/C by means of a generic formal proof, while for the case of FlexRay we formally prove that the system precision can be bounded according to the replay operation applied. Experimental results confirm and illustrate our approach. Matthias Függer, Eric Armengaud, Andreas Steininger |
IEEE Trans. Ind. Informatics | 3 |
| 2008 | Mapping a Fault-Tolerant Distributed Algorithm to Systems on ChipabstractSystems on chip (SoC) have much in common with traditional (networked) distributed systems in that they consist of largely independent components with dedicated communication interfaces. Therefore the adoption of classic distributed algorithms for SoCs suggests itself. The implementation complexity of these algorithms, however, significantly depends on the underlying failure models. In traditional software-based solutions this is normally not an issue, such that the most unconstrained, namely the Byzantine, failure model is often applied here. Our case study of a hardware implemented tick synchronization algorithm shows, however, that in an SoC-implementation substantial hardware savings can result from restricting the failure model to benign failures (omissions, crashes). On the downside, it turns out that such restricted failure models have a fairly poor coverage with respect to the hardware faults occurring in practice, and that additional measures to enforce these restrictions may entail an implementation overhead that outweighs the gain obtained in the implementation of a simpler algorithm. As a remedy we investigate the potential of failure transformation in this context and show that this technique may indeed yield an optimized overall solution. Gottfried Fuchs, Matthias Függer, Ulrich Schmid 0001, Andreas Steininger |
DSD | 4 |
| 2008 | Automated generation of explicit connectors for component based hardware/software interaction in embedded real-time systemsabstractThe complexity of today's embedded real-time systems is continuously growing with high demands on dependability, resource-efficiency, and reusability. Two solution approaches address these needs: First, in the component based software engineering (CBSE) paradigm, software is decomposed into self-contained components with explicit interactions and context dependencies. Connectors represent the abstraction of interactions between these components. Second, components can be shifted from software to reconfigurable hardware, typically field programmable gate arrays (FPGAs), in order to meet real-time constraints. This paper proposes a component-based concept to support efficient hardware/software co-design: A hardware component together with the hardware/software connector can seamlessly replace a software component with the same functionality, while the particularities of the alternative interaction are encapsulated in the component connector. Our approach provides for tools that can generate all necessary interaction mechanisms between hardware and software components. A proof-of-concept application demonstrates the advantages of our concept: Rapid change and comparison of different partitioning decisions due to automated and faultless generation of the hardware/software connectors. Wolfgang Forster, Christof Kutschera, Andreas Steininger, Karl M. Göschka |
IPDPS | 3 |
| 2008 | Towards a Systematic Test for Embedded Automotive Communication SystemsabstractThe introduction of computer-controlled intelligent safety and comfort features has turned cars into complex distributed computing systems. In such a system the proper operation of the communication backbone as well as the proper interaction of components from different vendors must be ensured for all configurations and operating conditions. This system-level test goes far beyond the (isolated) test of single components and represents a substantial problem, that seems to be still largely unsolved, although its solution is crucial for maintaining the consumers' trust in modern automotive electronics. In this paper we concentrate on the test of distributed systems based on FlexRay, the protocol that is envisioned as the communication backbone for future automotive systems. The cornerstones of our approach are a decomposition of the system into layers and mechanisms, and a versatile strategy for monitoring and stimulation under various conditions. Our concept can be adapted to diverse needs ranging from an early debugging with full access to the system, over non-intrusive online testing during interoperability tests, to maintenance testing that is restricted to a remote access only. We give detailed discussions of the requirements and present our solutions for the various issues involved. Selected use cases demonstrate the usefulness of the taken approach. Eric Armengaud, Andreas Steininger, Martin Horauer |
IEEE Trans. Ind. Informatics | 2 |
| 2007 | Hardware implementation of an SAD based stereo vision algorithmabstractThis paper presents the hardware implementation of a stereo vision core algorithm, that runs in real-time and is targeted at automotive applications. The algorithm is based on the sum of absolute differences (SAD) and computes the disparity map using 320 times 240 input images with a maximum disparity of 100 pixels. The hardware operates at a frequency of 65 MHz and achieves a frame rate of 425 fps by calculating the data highly parallel and pipelined. Thus an implemented and basically optimized software solution, running on an Intel Pentium 4 with 3 GHz clock frequency is 166 times outperformed. Kristian Ambrosch, Wilfried Kubinger, Martin Humenberger, Andreas Steininger |
CVPR | 4 |
| 2007 | The effect of quartz drift on convergence-average based clock synchronizationabstractThe aim of this work is to study how the temporal behavior of time-triggered distributed systems is influenced by a drift of their underlying quartz. More especially, we focus on convergence-average clock synchronization used e.g. for TTP/C and FlexRay. We show that, for a fault free system in a stable environment, the global time converges to an interval spanned by the accuracies of the physical clocks independently of the system history. Although this result seems quite intuitive, it is not self-evident, given the complex behavior of distributed clock synchronization. Moreover, this proof allows to derive diagnosis information about the underlying quartz and is the enabler of remote system test. Eric Armengaud, Andreas Steininger, Alexander Hanzlik |
ETFA | 2 |
| 2007 | A Fail-Silent Reconfigurable Superscalar ProcessorabstractWe propose a reconfigurable superscalar processor with two modes of operation: In safety mode the two pipelines run in lock step, executing the same instruction sequence, thus allowing to detect hardware failures. In performance mode different instruction streams are executed in parallel, just like in a standard superscalar processor. Considering that many embedded applications comprise a mixture of safety-critical and non safety-critical functions, the ability to dynamically switch between the two modes allows an efficient utilization of the duplicated pipeline. To complement the error detection enabled by the duplicated pipeline, non-duplicated components such as the register file are secured by parity. A systematic failure analysis shows that the proposed implementation can indeed detect all single faults in safety mode and that the ability to switch modes does not compromise the fail safe property. These encouraging results are finally confirmed by extensive fault injection experiments. Thomas Kottke, Andreas Steininger |
PRDC | 2 |
| 2006 | Solving the Fundamental Problem of Digital Design - A Systematic Review of Design MethodsabstractDuring the last decade various asynchronous circuit structures and design methods have been proposed that seem to be quite different. In essence, however, all these methods contribute to solving the same fundamental design problem in one way or another. In this paper we use a simple communication model to figure out what this fundamental design problem actually is and to highlight its roots. We show how each of the related sub-problems can be conceptually solved in the time domain and in the information domain. Having this model in mind we finally develop a common framework to classify the most popular asynchronous design methods and figure out which sub-problem they actually solve and in which respect they differ from each other Martin Delvai, Andreas Steininger |
DSD | 2 |
| 2006 | A Reconfigurable Generic Dual-Core ArchitectureabstractIn this paper we propose a generic frame for the implementation of a dual-core processor with two modes of operation. One is the safety mode that allows to run the two cores in lock step in a classical master/checker fashion. A clock delay of 1.5 clock cycles between master and checker establishes the temporal redundancy to minimize the potential for common mode faults. The second operation mode allows a parallel execution of different instruction streams on the two cores in a multiprocessor fashion. The possibility to dynamically switch between the two modes allows for an efficient utilization of the duplicated core. We propose an implementation of such a generic frame that can be applied in conjunction with virtually any standard processor core. Also we perform a systematic failure analysis for the safety mode and the mode switching procedure. Experimental fault injection confirms that our reconfigurable architecture indeed provides the same fail safe properties as the classical master/checker architecture Thomas Kottke, Andreas Steininger |
DSN | 2 |
| 2006 | Automatic Parameter Identi cation in FlexRay based Automotive Communication NetworksabstractTime-triggered architectures are being introduced in safety-critical automotive systems ("X-by-wire") to cope with the growing complexity and the high safety demands. One of their merits is to provide a static operation schedule, thus largely reducing the complexity of (otherwise input-dependent) execution flow. This, however, comes for the price of increased configuration complexity: the FlexRay protocol that implements the time-triggered paradigm on the communication level requires several tens of configuration parameters. The product of their possible settings spans a space of more than 10M48(theoretical) configurations. This does not represent a problem as long as the configuration is known and fault-free. However, in many cases - ranging from debugging over conformance testing to maintenance - an identification of the configuration is desirable, but turns out extremely burdensome. This paper presents a systematic approach that facilitates parameter identification in such complex systems. Experimental results illustrate the usefulness of our approach and explore its limitations. Eric Armengaud, Andreas Steininger, Martin Horauer |
ETFA | 2 |
| 2005 | Efficient stimulus generation for testing embedded distributed systems the FlexRay exampleabstractEmbedded electronic communication systems play a vital role in the future development of automotive systems. For successful application developments new test and diagnosis solutions for these distributed systems are required. This paper presents solutions for the stimulus generation of test systems based on a remote test under the stringent constraints of the automotive industry. We elaborate a flexible and accurate method that enables a systematic and comprehensive test of data link layer related communication services. Furthermore, we discuss how this solution can be applied for various different test purposes (e.g. for verification, robustness, interoperability or maintenance tests) and demonstrate its application by use of an example that varies one fundamental protocol parameter of FlexRay Eric Armengaud, Andreas Steininger, Martin Horauer |
ETFA | 2 |
| 2005 | A structured approach for the systematic test of embedded automotive communication systemsabstractWe present a systematic test strategy for the communication subsystem of a distributed automotive system. Key points are (1) system decomposition into layers and services and (2) integration of fault injection and monitoring within this framework Eric Armengaud, Florian Rothensteiner, Andreas Steininger, Roman Pallierer, Martin Horauer, Martin Zauner |
ITC | 3 |
| 2003 | Processor Support for Temporal Predictability - The SPEAR Design ExampleabstractThe demand for predictable timing behavior is characteristic for real-time applications. Experience has shown that this property cannot be achieved by software alone but rather requires support from the processor. This situation is analyzed and mapped to a design rationale for SPEAR (Scalable Processor for Embedded Applications in Real-time Environments), a processor that has been designed to meet the specific temporal demands of real-time systems. At the hardware level, SPEAR guarantees interrupt response with minimum temporal jitter and minimum delay. Furthermore, the processor provides an instruction set that only has constant-time instructions. At the software level, SPEAR supports the implementation of temporally predictable code according to the single-path programming paradigm. Altogether, these features support writing of code with minimal jitter and provide the basis for exact temporal predictability. Experimental results show that SPEAR indeed exhibits the anticipated highly predictable timing behavior. Martin Delvai, Wolfgang Huber, Peter P. Puschner, Andreas Steininger |
ECRTS | 4 |
| 2003 | Dealing with dormant faults in an embedded fault-tolerant computer systemabstractAccumulation of dormant faults is a potential threat in a fault tolerant system, especially because most often fault tolerance is based on the single-fault assumption. We investigate this threat by the example of an automotive steer-by-wire application based on the Time-Triggered Architecture (TTA). By means of a Markov model we illustrate that the effect of fault dormancy can degrade the MTTF of a system by several orders of magnitude. We study potential remedies, of which transparent online testing proves to be the most powerful one, while taking a hot spare offline temporarily to test it provides a more feasible solution, though with tight constraints regarding the test duration. Christoph Scherrer, Andreas Steininger |
IEEE Trans. Reliab. | 2 |
| 2003 | A transparent online memory test for simultaneous detection of functional faults and soft errors in memoriesabstractThe Transparent Online Memory Test (TOMT) introduced here has been specifically developed for online testing of word-oriented memories with parity or Hamming protection. Careful interleaving of a word-oriented and a bit-oriented test facilitates a fault coverage and a test duration comparable to the widely used March C- algorithm. Unlike similar methods TOMT actively exercises all bit cells in memory within one test period. Hence it not only detects soft errors but also functional faults and reliably prevents fault accumulation. Different variants of the basic TOMT algorithm are investigated in terms of fault coverage and test time. A prototype implementation for SRAM is introduced which-integrated into a standard processor/memory interface-autonomously performs the transparent online memory test. The trade-offs in terms of hardware overhead and memory access delay caused by this system integration are explored. Karl Thaller, Andreas Steininger |
IEEE Trans. Reliab. | 2 |
| 2002 | Using Offline and Online BIST to Improve System Dependability - The TTPC-C ExampleabstractFault-tolerant distributed real-time systems are facing many new challenges. Although many techniques provide effective masking of node failures on the architectural level, several trends are aggravating the reliability demands on the node level. Starting with a brief presentation of the fault tolerance properties of the time-triggered architecture TTA the corresponding support by the time-triggered protocol controller (TTPC-C) is discussed. We propose a strategy for improving these properties with respect to the anticipated new fault scenarios. It turns out that the application of BIST during node startup and before node reintegration improves system fault tolerance. Additionally a combined strategy of online BIST and error correction can efficiently protect memory. We illustrate the implementation of the proposed mechanisms. Our implementation experiences on an FPGA platform show that the involved overheads are moderate. Andreas Steininger, Johann Vilanek |
ICCD | 1 |
| 2002 | Identifying Efficient Combinations of Error Detection Mechanisms Based on Results of Fault Injection ExperimentsabstractWe introduce novel performance ratings for error detection mechanisms. Given a proper setup of the fault injection experiments, these ratings can be directly computed from raw readout data. They allow the evaluation of the overall performance of arbitrary combinations of mechanisms without the need for further experiments. With this means we can determine a minimal subset of mechanisms that still provides the required performance. Andreas Steininger, Christoph Scherrer |
IEEE Trans. Computers | 1 |
| 2000 | Testing and built-in self-test - A survey
Andreas Steininger |
J. Syst. Archit. | 1 |
| 1991 | Towards an optimal combination of error detection mechanisms
Andreas Steininger, Herbert F. Schweinzer |
Microprocessing and Microprogramming | 1 |