Power & Clock Supervision
Supervise the ground your safety concept stands on: rails inside their windows, a time base you can trust, and an argument that says how you know.
- Chapters
- 14
- Chapters
- Failure families
- 6
- Failure families
- Evidence levels
- 5
- Evidence levels
- Review questions
- 10
- Review questions
- 01The Silent Assumptions
- 02The Power Tree
- 03Inside a Safety PMIC
- 04Voltage Supervision
- 05Sequencing & Power-Good
Why it pays for itself
Make the silent assumptions supervised assumptions
Every safety mechanism in your concept depends on rails inside their characterized window and a time base consistent with the timing design. This guide turns those dependencies into stated requirements, monitors with justified thresholds, and reactions with deadlines.
Independence you argue, not independence you buy
A second part number is not an independence claim. The reference, clock, supply, die and configuration bridges between a monitor and what it monitors are walked one by one, together with the environmental and systematic couplings that never appear on a schematic.
The budget and the evidence, written down
Detection latency, filter time, reaction time and margin become four explicit numbers per supervised fault class, the supply-loss reaction gets an energy budget, and every inherited coverage claim gets its assumptions of use tracked to closure.
What you’ll be able to do
Write Rail Requirements a Monitor Can Enforce
Turn nominal voltages into masks with windows, permitted excursions, detection deadlines and specified reactions, defined at the load pins rather than at the regulator output.
Select and Justify a Supervision Platform
Compare an integrated safety PMIC, a system basis chip and a discrete supervisor on the monitoring, reaction and self-test functions they actually document, and trace the integration obligations that come with them.
Design Escalation That Converges
Grade reactions per fault class, give software one bounded window where its verdict is still worth something, route around it where it is not, and use counters and latched states so escalation never becomes a reset loop.
Defend an Independence Claim
Walk the reference, clock, supply, die and configuration bridges between a monitor and what it monitors, then handle the environmental and systematic couplings that no netlist shows.
Produce a Written Supervision Timing Budget
Decompose sensing latency, filter time, reaction time and margin against the allocated interval, and budget the stored energy that a supply-loss reaction has to run on.
Turn Coverage Claims Into Evidence
Schedule monitor self-tests at the interval your latent-fault analysis assumes, run a board-level injection campaign that measures times rather than outcomes, and close every assumption of use before inheriting a supplier coverage number.
Chapter by chapter
- 01
The Silent Assumptions
Take any safety mechanism from anywhere else in the stack and ask what it needs in order to work: supply conditions inside the characterized limits and a time base consistent with the timing design. The six physical failure families that move that ground, and the vocabulary that keeps the later argument honest.
- The operating envelope
- Six failure families
- When an excursion becomes a hazard
- The supervision fabric
- 02
The Power Tree
From a battery post that swings between cranking and load dump to a core rail that must hold a few percent. How each stage fails loudly and, more dangerously, quietly, and why a usable rail requirement is a mask in the voltage-time plane rather than a nominal number.
- Stage-by-stage failure modes
- Loud versus quiet faults
- The rail mask
- Requirements at the load pins
- 03
Inside a Safety PMIC
What separates a safety power-management device from an ordinary regulator is not better regulation but documented monitoring, reaction and self-test functions. The regulating plane and the judging plane, the start-up state machine, the pins that carry the verdict off the die, and how to choose between integrated and discrete supervision.
- Two planes and a wall
- Trust state machine
- The pins that carry the verdict
- PMIC, SBC or discrete
- 04
Voltage Supervision
A threshold is only as good as the reference behind it, which is why an independently referenced monitor exists at all. Windows rather than lines, the error budget that turns a clean threshold into a band, and the hysteresis and deglitch settings that buy calm with detection time.
- The shared-reference problem
- Windows, not lines
- Threshold error budget
- Deglitch versus latency
- 05
Sequencing & Power-Good
Rails must arrive in order, and something must define ready. The choice between releasing reset on a measured power-good chain and releasing it on a timer is a safety decision disguised as a convenience, and power-down brings constraints of its own.
- Why order is a requirement
- Chain versus timer
- Power-down is a sequence too
- Who supervises the sequencer
- 06
Reset & Escalation
Reset treated as an actuator the supervision subsystem fires, not an event that happens to the system. Who is allowed to pull it, how graded escalation gives software one bounded window of agency, why the best error pins toggle instead of sitting at a level, and how an escalation policy is made to converge.
- Reset as an actuator
- Graded escalation
- Proof of life over levels
- Counters, latches and reset storms
- 07
Watchdogs
Voltage monitors judge the platform; watchdogs judge the program running on it. The window that convicts early service as well as late, the question-answer protocol that makes service depend on the supervised control flow, what each tier honestly buys, and whose clock the watchdog is counting.
- The closed window
- Question and answer
- Three tiers, honest claims
- Service discipline
- 08
Clock Supervision
A broken time base can only be compared with another timing reference, which reproduces the reference-independence problem in the time domain. Crystal loss, drift, loss of lock and glitches, the counting monitor and the toggle that ruins it, and how to react when every timed reaction depends on the suspect clock.
- Clock failure physics
- The counting monitor
- Reacting without a trusted clock
- Where the recursion stops
- 09
The Independence Argument
The chapter where the word independent earns its keep or is exposed as decoration. Adding a monitor reduces risk only for the faults it detects in time, so the bridges between a function and its judge are hunted one by one, including the environmental and systematic couplings no schematic shows.
- A monitor is a correlation claim
- Five common-cause bridges
- What each placement can claim
- A dependent failure walk
- 10
FTTI & the Supervision Timing Budget
Every credited detection and reaction path has a worst-case timing contribution, and this is the arithmetic. Where the fault tolerant time interval is spent, why the deglitch filter is squeezed from three sides, and why a reaction during supply loss spends stored energy as well as milliseconds.
- The budget shape
- Three-way squeeze on the filter
- Hold-up energy
- Four numbers to write down
- 11
Latent Faults & Monitor Self-Test
On a healthy system a correct monitor output and a dead monitor output look identical, so the fault sits latent until the day the rail genuinely sags. What the standard calls this, why the test interval matters as much as the coverage, and the trap hiding in always-powered ECUs that sleep instead of powering down.
- The two-hit problem
- Latent fault metric and intervals
- The self-test toolbox
- Test the reaction, not just the sensor
- 12
Demonstrating Diagnostic Coverage
A coverage figure is a claim with a supply chain: the vendor produced it, the safety manual publishes it wrapped in assumptions of use, and the integrator inherits it only under those conditions. The evidence stack from analysis to end-to-end test, and the board-level injection campaign nobody can run for you.
- Where a coverage number comes from
- The evidence stack
- The injection matrix
- Do not claim past the mechanism
- 13
Into the FMEDA & Safety Case
Where the circuits become rows, claims and evidence, and where unread safety manuals go to invalidate otherwise excellent designs. The assumptions-of-use matrix that turns each supplier condition into a tracked requirement, supervision appearing twice in the FMEDA, and the claims a safety case makes about all of it.
- The paper trail end to end
- Assumptions-of-use tracking
- Supervision as FMEDA rows
- The honest empty cell
- 14
Worked Example, Patterns & Pitfalls
Two faults run end to end against the clock in a hypothetical teaching architecture, then the whole page folded into the patterns worth stealing, the pitfalls that keep recurring, and a ten-question review checklist for a supervision concept.
- Two faults, end to end
- Six patterns worth stealing
- Six recurring pitfalls
- A review checklist
Who this guide is for
- Hardware and system engineers designing ECU power and clock supervision
- Safety engineers who must justify diagnostic coverage claimed for supervision circuits
- Integrators consuming a PMIC or MCU safety manual and its assumptions of use
- FMEDA and dependent failure analysis practitioners working on the supervision subsystem
- Software leads who own watchdog service, escalation policy and start-up diagnostics
Frequently Asked Questions
Common questions about Power & Clock Supervision
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.