HARDWARE SECURITY

RTL Anti-Tampering DesignLesson 11 / 16

RTL Anti-Tampering Design Lesson 11: Reset, Clocks, CDC and Lifecycle

Reset release is not one simultaneous instant across the chip. If permission crosses a clock domain or precedes startup checks, it may be used while the system appears to be booting.

3 min read

Reset release is not one simultaneous instant across the chip. If permission crosses a clock domain or precedes startup checks, it may be used while the system appears to be booting.

Lesson 11: Reset, Clocks, CDC and Lifecycle

Startup is a gated sequence

A hospital backup-power transfer makes the point: lights can be on before every ward has passed its checks. A controller waits for stable power, self-tests, and then enables selected outlets. A chip must likewise distinguish stable power, reset release, valid OTP/lifecycle data, ROM checks, and CPU fetch enable. These are separate events. The analogy only conveys staged readiness; it does not model asynchronous reset networks, metastability, or fused lifecycle states.

List reset assertion and deassertion in each domain. Asynchronous assertion can clear state promptly; deassertion is commonly synchronized to each destination clock to avoid recovery/removal violations. OpenTitan’s public lifecycle-controller theory describes waiting for OTP sensing, decoding and broadcasting lifecycle, then checking straps/ROM after stabilization. That is a design-specific document, not a timing guarantee for every product. Lifecycle controller.

A one-bit ready pulse sampled directly across domains may be missed. Synchronizing each bit of a multi-bit lifecycle bus independently can instead produce a combination that never existed because bits arrive on different cycles. Transfer data with a handshake or stable encoding, and authorize using reset state synchronized locally. For split reset groups, examine transactions and FIFO clearing while the producer is awake but the consumer is not. A CDC report is structural evidence; it does not prove lifecycle policy.

Counterexample: ROM check is complete in clk_sys, but clk_dbg has not yet observed synchronized check_done. If permission arrives first, the destination accepts debug too early. Assert at the actual debug-accept boundary, not only on the reset controller’s eventual state. The SVA below is a harness proposal, not compiled; every debug_accept requires stable lifecycle and a completed check.

Acceptance boundary

Test reset release order, pause or speed each domain, inject one-cycle cross-domain requests, repeat reset, and cover each lifecycle value. Positive controls must show that an authorized startup eventually becomes usable; safety checks must show no acceptance before prerequisites hold. An edge model cannot replace CDC/RDC analysis, reset-tree timing, power-ramp testing, or analog brownout validation.

Offline interactive lab

RTL / SVA review direction

These are property sketches: define the harness transaction, reset and oracle, then confirm sampling boundaries before binding to the design. They have not been compiled or proven.

assert property (@(posedge clk_dbg) disable iff (!rst_dbg_n)
  debug_accept |-> reference_lifecycle_stable_sync && reference_rom_check_done_sync);

cover property (@(posedge clk_dbg) disable iff (!rst_dbg_n)
  debug_accept && reference_lifecycle_stable_sync && reference_rom_check_done_sync);

reference_* signals belong to an oracle independent of the DUT. A synchronized flag only says the destination observed a state; it does not prove correct CDC or a legal source lifecycle.

This snippet does not prove CDC, timing, side-channel, or physical injection behavior; each requires its own tool evidence or measurement.

Check your reasoning

  1. Recognition — Which startup events must the design treat separately? Reasoning: Reset release, valid lifecycle data, ROM check completion, and CPU or debug acceptance are distinct events; one ready bit cannot stand in for all of them.
  2. Contrast — Why synchronize reset deassertion locally, but use a handshake for a multi-bit lifecycle value? Reasoning: A local reset synchronizer controls release timing in that domain. A handshake or stable encoded transfer preserves the relationship among multiple data bits.
  3. Scenario — On a common teaching timeline, permission reaches the destination first. Source check_done completes later and has not yet been observed through synchronization in clk_dbg. What should debug_accept do? Reasoning: It must remain low until the destination domain has observed the prerequisite. A weak policy that accepts the early permission is the counterexample.
  4. Failure diagnosis — What can happen if each bit of a lifecycle bus crosses through its own synchronizer? Reasoning: Different bits can arrive on different cycles, producing a combination that the source never sent. Use a coherent transfer protocol or a safely held encoding.
  5. Design risk / transfer — A producer restarts while a consumer and its FIFO remain active. What must the review establish? Reasoning: Define which reset groups may restart independently, how in-flight entries are invalidated or drained, and which transactions remain authorized. CDC/RDC structure alone does not prove that policy.

References

OpenTitan Lifecycle Controller

MY ACADEMY · LESSON FILM

Lesson video

The film explains this lesson’s data path. After a section, return to the interactive exercise and change the input or fault conditions. The animation presents a teaching model; it does not replace RTL simulation.

Diagram scope
Teaching model · Not RTL simulation or silicon testing
Common teaching timeline; not cycle-index comparison, metastability probability or STA

Download MP4 · Captions VTT

Narration uses a synthetic voice. Both the interaction and animation have model boundaries; interpret results using this lesson’s sources and validation scope.

Wrap-up: take this lesson into a design review

Threat model and assumptions

During startup, debug permission and ROM check_done cross different clock domains. After the destination reset releases, permission may arrive before check_done is synchronized there.

Why the design fails

The destination accepts debug permission before synchronized check_done; reset-release ordering and clock phase can let that path arrive first.

Defenses

Synchronize reset release in each domain, handshake lifecycle/check status, and check stable conditions at acceptance.

Validation and checks to perform

Cross phase/state enumeration, CDC/RDC structural checks, timing and positive startup controls; no RTL/formal/STA has run for this lesson.

Limits and unverified claims

An edge model does not represent metastability probability, analog power, the actual reset tree or physical lifecycle fuses.

Try a changed assumption

Change destination frequency and add a CDC FIFO. Define which reset groups may restart independently and the minimum evidence required at acceptance.

This wrap-up summarizes the lesson’s teaching cases, references and experiment scope. Checks not reported as completed remain future work.

Thanks for reading.

Take the concept with you, not just the terminology.

#RTL#Fault Injection#Hardware Security