Space Grade, High Reliability MIL-STD-1553 IP Core
Designed from ground up for use in space applications, Sital’s BRM1553ERL IP core offers a uniquely compact, robust and reliable BC, RT, MT solution for any FPGA and ASIC. The core implements special features for rapidly mitigating against single event upsets that commonly occur in space applications.
The core implements features including Hamming-Code, watchdog timers and logic to reset all state-machines following every MIL-STD-1553 message.
Selected by NASA for use in satellites and other spacecraft, the BRM1553ERL ensures a successful and robust implementation of MIL-STD-1553 for any space or other high-reliability application.
This core is available in multiple configurations. The BRM553ERL option includes memory, and is register and memory structure compatible with DDC’s® Enhanced Mini-ACE®, Micro-ACE® and Total-ACE®. Alternatively, the core is also available with “simple-system” back-end configuration (BRD1553ERL-FE). This version includes no memory and can operate without a processor or software.
There’s also the BRD1553ERL-SnS version, which incorporates Sital’s Safe and Secure (SnS) functionality. Sital’s SnS can detect instances of “snooping” (impersonation) and also detecting and locating open and short circuit electrical faults in cables, connectors couplers, terminators or LRUs.
Sital’s BRM1553ERL IP Core resets every internal state machine the moment a new MIL-STD-1553 message appears on the bus. Pure logic does that work, with no processor, no software, and no wait for a system-level reset. The design choice sets a hard ceiling on how long a radiation-induced fault can affect the terminal: one message period.
The BRM1553ERL is a space-grade, high-reliability MIL-STD-1553 IP Core for FPGA and ASIC, supporting Bus Controller (BC), Remote Terminal (RT), and Monitor (MT) operation. Hamming code, watchdog timers, and the per-message reset work together against the single-event upsets that occur routinely in orbit. NASA selected Sital’s MIL-STD-1553 IP for space equipment communication after a competitive evaluation, and the BRM1553ERL is the variant Sital built for satellites and other spacecraft.
The BRM1553ERL is Sital Technology’s MIL-STD-1553 IP Core for space and other extreme-reliability applications.
“ERL” stands for Extended Reliability Logic.
Sital supplies the BRM1553ERL as a vendor- and technology-independent VHDL, delivered as an EDIF netlist targeted to your chosen device family, memory configuration, and clock frequency. It runs in any FPGA with sufficient LUTs, and Sital supports ASIC implementation on consultation.
In orbit, charged particles pass through the FPGA fabric and deposit charge in sensitive nodes. The result is a single event upset, a bit flip caused by one ionizing particle strike. MIL-STD-1553 already defends the data path with Manchester encoding and parity, so a corrupted word gets caught and retried. Protocol logic is the harder case. When an upset drives a sequencer into an undefined state, the terminal can stop participating in the bus altogether, and no technician is standing by in orbit to power-cycle it.
That distinction shaped the whole design. Sital’s engineers assumed upsets would happen and built the core to recover from them quickly and predictably, rather than trying to prevent every one.
Four mechanisms work together:
One point of clarification, because it comes up in nearly every evaluation call. The BRM1553ERL is protocol logic, and it does not replace a radiation-hardened or radiation-tolerant FPGA. You instantiate it inside the rad-hard device you have already selected, so that the protocol layer behaves predictably when the fabric takes a hit.
Sital offers the core as BRM1553ERL-BC, BRM1553ERL-RT, BRM1553ERL-MT, or any combination. Synthesis options let you compile in only the modes your design requires.
Two back-end interfaces are available:
A third option, BRM1553ERL-SnS, adds Sital’s patented “SnS” (Safe and Secure) technology. “SnS” detects impersonation on the bus. It also detects and locates open and short circuit faults in bus and stub wires, connectors, couplers, terminators, and LRUs.
Sital’s MIL-STD-1553 IP Cores require very little FPGA space. For a Remote Terminal, published reference figures range from approximately 764 to 1,036 4-LUTs in the Front-End configuration, and approximately 3,100 to 3,950 in the DDC® compatible configuration, depending on vendor and family. These numbers are approximate and vary with core configuration. On rad-hard devices, where fabric is both limited and costly, that difference drives real design decisions.
The Manchester decoder operates at any even clock frequency from 12 MHz up, selected by the user. Fewer clock sources and clock domains on the board mean less EMI/RFI to manage, and the decoder’s filtering algorithms are built for harsh environments.
Sital publishes what it has tested rather than what it has claimed:
The core ships with a user’s manual, sample VHDL that instantiates it, a synthesis script, a gate-level model for the target technology, a transceiver model, a 1553 bus-tester model that generates messages and checks replies, a top-level test bench, and a simulation script. Sital assembles that package because integration schedule, not protocol capability, is usually the binding constraint on a space program.
The BRM1553ERL sits inside a broader family of DataBus communication solutions from Sital Technology, covering MIL-STD-1553, EBR-1553 at 10 Mbps, ARINC-429, ARINC-825, and CAN bus across IP Cores, components, boards, and testers.
“Space customers never ask us whether an upset will happen. It will. They ask how long the terminal stays off the bus afterward. We designed the BRM1553ERL so the answer is one message, in logic, with no processor in the recovery path. In verification, it came back from every ‘X’ state we injected the moment the next message arrived.”
— Sital Technology Team
Seven references that engineers evaluating a space-grade 1553 IP Core typically need next.
NASA’s Electronic Parts and Packaging program publishes the test and analysis methodology its Radiation Effects and Analysis Group uses to evaluate FPGA SEU data, including guidance on test structures and mitigation evaluation. Read it to establish what “SEU tested” should actually mean on your program.
Source: NASA NEPP — Field Programmable Gate Array (FPGA) Single Event Effect (SEE) Radiation Testing
NOAA explains how it monitors and forecasts the solar activity that drives upset rates, and how satellite operators act on those forecasts to protect spacecraft. Use it to frame your environment assumptions before setting design margin.
Source: NOAA NESDIS — Safeguarding Satellites: How NOAA Monitors Space Weather To Prevent Disruptions
FAA Advisory Circular 20-152A describes an acceptable means of showing compliance for the electronic hardware aspects of airborne systems, and adds objectives covering the use of COTS intellectual property inside a DO-254 program. Read it early if DAL A is in scope. Note also that the AC states outright that it does not address single-event effects, which leaves that documentation to you.
Source: FAA — AC 20-152A, Development Assurance For Airborne Electronic Hardware
The National Academies walks through the three-step process of identifying, evaluating, and mitigating a single-event effects threat, and puts real numbers on what device-level testing costs. Useful context when you build a radiation case for a program review.
Source: National Academies — Current State Of Single-Event Effects Hardness Assurance And Infrastructure
IEEE’s LEO Satellites and Systems initiative published a full workshop on radiation effects and testing for satellites, with sessions from NASA GSFC, NASA JPL, ESA, and CERN covering mitigation strategies and heavy-ion test practice. The recorded sessions are free.
Source: IEEE LEO SatS — Radiation Effects On Satellites And Space Systems Workshop
The Berkeley Accelerator Space Effects facility at Lawrence Berkeley National Laboratory supplies heavy ion, proton, and neutron beams for radiation effects testing, and hosted the first single event effects tests ever conducted, in 1979. Relevant when your program requires device-level or board-level SEE data.
Source: Lawrence Berkeley National Laboratory — Berkeley Accelerator Space Effects (BASE) Facility
USML Category XV governs spacecraft and related articles under ITAR. This final rule documents the most recent revision to what falls under that control. Review it alongside any supply chain, sourcing, or international collaboration decision.
Three figures that frame why space-grade 1553 design decisions carry the weight they do.
A record 296 launches deployed 4,434 satellites during that single year. Each of them carries a communication architecture that has to work unattended.
Constellation economics has changed the calculus we see in customer conversations. Teams no longer qualify one bus interface for one flagship spacecraft. They qualify a design they intend to replicate dozens or hundreds of times, which turns protocol-layer robustness into a multiplier across the whole program.
Source: Satellite Industry Association — 29th Annual State Of The Satellite Industry Report
Growth ran 7.8% year over year, with the commercial sector accounting for 78% of the total and government budgets the remaining 22%.
Watch the commercial share. Commercial programs move faster and carry less schedule slack than traditional government builds. That is why our customers ask about integration deliverables, meaning test benches, bus tester models, and simulation scripts, as often as they ask about protocol features.
Source: Space Foundation — The Space Report 2025 Q2
Four of 18 major projects in development recorded cost growth over the year, and together they reported more than $500 million in overruns.
Cost growth in space programs concentrates in rework and late discovery. In 25+ years of supplying 1553 IP, we have found that the failures which hurt schedules are rarely exotic. They are integration problems found after board spin, once the cost of a change has already multiplied. Choosing protocol logic with third-party validation behind it removes one of those variables early.
Source: U.S. Government Accountability Office — NASA: Assessments Of Major Projects
MIL-STD-1553 in space is a different engineering problem than MIL-STD-1553 on an aircraft. Teams that treat the two as one problem make the mistake we see most often.
Three observations from supplying this core:
Our opinion, stated plainly. For space applications, the most useful thing a 1553 IP Core can offer is a bounded, provable answer to one question: what happens after the upset? Sital built the BRM1553ERL on that principle, and we would encourage any program to press hard on it, in our core or anyone else’s.
The core implements protocol logic designed to recover from radiation-induced faults. Hamming code protects stored data, watchdog timers catch stalled logic, and pure logic resets every internal state machine when a new MIL-STD-1553 message is detected. An upset therefore stays bound to one message period, and no processor or software sits in the recovery path.
Extended Reliability Logic. The designation marks the variant of Sital’s MIL-STD-1553 IP Core family built for space and other extreme-reliability applications, as distinct from the BRM1553D flagship core used on airborne and ground platforms.
No, and this is the most common misunderstanding we encounter. You instantiate the BRM1553ERL inside the radiation-hardened or radiation-tolerant device you have already selected. Device-level hardening and protocol-level recovery solve different halves of the same problem.
Yes. Sital supplies it as a vendor- and technology-independent VHDL, delivered as an EDIF netlist targeted to your device family, memory configuration, and clock frequency. Supported FPGA families span Microchip/Actel, AMD/Xilinx, Altera, Lattice, and QuickLogic. Sital supports ASIC implementation on consultation.
For a Remote Terminal, reference figures run approximately 764 to 1,036 4-LUTs in the Front-End configuration, and approximately 3,100 to 3,950 in the DDC® compatible configuration, depending on vendor and family. Figures are approximate and vary with the BC, RT, and Monitor combination selected.
Yes, individually or in any combination, with either the Front-End or the DDC® Enhanced Mini-ACE® compatible back-end interface. Synthesis compiling options let you include only the modes your design needs, which keeps logic resources to a minimum.
DO-254 artifacts up to and including DAL A for the hardware, and DO-178 up to and including DAL A for software drivers, supplied through Sital’s certification partners Logicircuit and ConsuNova. Sital’s DO-254 certification partnership announcement explains how the certification data package works for licensed IP Cores.
NASA selected Sital’s MIL-STD-1553 IP for space equipment communication after evaluating it against competing products, and the BRM1553ERL is the variant intended for satellites and spacecraft. Sital’s published customer base across the space sector includes NASA, ESA, IAI, and Orbital Sciences Corporation. Confirm the current approved scope for named client references before publication.
Send us the device family, the modes you need, and the radiation environment you are designing for, and our engineers will tell you what the BRM1553ERL looks like in your FPGA or ASIC. Talk To An Expert, or request an Evaluation to get hardware samples and start integration this quarter.
Sital’s cutting-edge, innovative “SnS” Technology is designed for IP Core’s physical layer. Our solutions offer unprecedented cyber security and DataBus fault finder capabilities.
We supply our products with DO-254 and DO-178 certifiability, including DAL A. Our partners: Logicircuit and ConsuNova provide the DO-254 and DO-178 artifacts. Through enhanced physical layer monitoring, the patented “SnS” analyzes all DataBus messages and provides 2 unique capabilities.