Scalable AXI4 Transaction Monitoring for Mixed-Criticality SoCs: From Phase-Level Precision to ID-Level Efficiency
By Chaoqun Liang 1, Thomas Benz 2,3, Alessandro Ottaviano 4, Michael Rogenmoser 2, Luca Benini 1, 2, Angelo Garofalo 1, 2, Davide Rossi 1
1 Department of Electrical, Electronic, and Information Engineering (DEI), University of Bologna, Bologna, Italy
2 Integrated Systems Laboratory (IIS), ETH Zurich, Switzerland
3 lowRISC C.I.C., Cambridge, United Kingdom
4 Tenstorrent USA, Inc., Santa Clara, California

Abstract
Mixed-criticality Systems-on-Chip (SoCs) with on-chip interconnects based on the AXI4 open standard protocol lack a protocol-level timeout mechanism, exposing systems to deadlocks and missed real-time deadlines when subordinate devices or managers fail or stall due to hardware faults, radiation-induced upsets, or software errors. This work presents a configurable hardware intellectual property (IP), non-intrusive in fault-free operation, that detects AXI4 protocol violations and timing faults at runtime and restores interconnect liveness through a cut-and- drain isolation mechanism. To address the fundamental trade-off between monitoring granularity and area cost, we introduce three designs at decreasing monitoring granularity: Phase-Level Track-ing (PLT), which provides cycle-accurate fault localization across individual protocol phases; Channel-Level Tracking (CLT), which coalesces per-phase monitors into channel-level supervision; and ID-Level Tracking (ILT), which achieves sub-linear area scaling by monitoring only per-ID transaction boundaries. Synthesized in GlobalFoundries 12 nm technology, CLT reduces area by 36.7% relative to PLT while preserving worst-case detection bounds at a minimal detection latency overhead, whereas ILT achieves an 89.2% area reduction suitable for tightly constrained deployments at the cost of a 3.7x higher median detection latency with coarser fault localization. Fault injection campaigns on a RISC-V SoC across 1.2 million scenarios confirm that no fault manifesting as an AXI4 protocol or liveness violation escaped detection, with observed detection latencies consistently bounded by theoretical worst-case predictions.
Index Terms—Transaction monitoring, AXI4 interconnect, mixed-criticality SoC, fault detection and recovery, deadlock prevention, hardware IP, functional safety.
To read the full article, click here
Related Semiconductor IP
- AMBA AXI4 Interconnect Verification IP
- AMBA AXI4 Verification IP
- AMBA AXI4 Verification IP
- AMBA AXI4 Synthesizable Transactor
- AMBA AXI4 Assertion IP
Related Articles
- IMS: Intelligent Hardware Monitoring System for Secure SoCs
- System-Level Isolation for Mixed-Criticality RISC-V SoCs: A "World" Reality Check
- A Centralized Performance Monitoring Architecture for Heterogeneous Multicore SoCs
- Runtime Energy Monitoring for RISC-V Soft-Cores
Latest Articles
- Scalable AXI4 Transaction Monitoring for Mixed-Criticality SoCs: From Phase-Level Precision to ID-Level Efficiency
- Hardware-managed heterogeneous high-bandwidth memory and flash in LLM inference systems
- LACE: Large Language Model Aided Multi-Agent Framework for Agile RISC-V Instruction Extension
- A Process-Aware Hybrid Si/IGO Monolithic-3D 6T SRAM with BEOL Pass-Gates for the 2nm Node
- Automated Estimation of MBIST Area and Test Time in Heterogeneous Memory IPs via Stacked Ensemble Framework