BRM1553ERL

Home > BRM1553ERL

Space Grade, High Reliability MIL-STD-1553 IP Core

chip ERL 1553

Designed from ground up for use in space applications, Sital’s BRM1553ERL IP core offers a uniquely compact, robust and reliable BC, RT, MT solution for any FPGA and ASIC. The core implements special features for rapidly mitigating against single event upsets that commonly occur in space applications.

The core implements features including Hamming-Code, watchdog timers and logic to reset all state-machines following every MIL-STD-1553 message.

Selected by NASA for use in satellites and other spacecraft, the BRM1553ERL ensures a successful and robust implementation of MIL-STD-1553 for any space or other high-reliability application.

This core is available in multiple configurations. The BRM553ERL option includes memory, and is register and memory structure compatible with DDC’s® Enhanced Mini-ACE®, Micro-ACE® and Total-ACE®. Alternatively, the core is also available with “simple-system” back-end configuration (BRD1553ERL-FE). This version includes no memory and can operate without a processor or software.

There’s also the BRD1553ERL-SnS version, which incorporates Sital’s Safe and Secure (SnS) functionality. Sital’s SnS can detect instances of “snooping” (impersonation) and also detecting and locating open and short circuit electrical faults in cables, connectors couplers, terminators or LRUs.

 

BRM1553ERL Space Grade MIL-STD-1553 IP Core: BC, RT, And Monitor For FPGA And ASIC With Single Event Upset Mitigation

Sital’s BRM1553ERL IP Core resets every internal state machine the moment a new MIL-STD-1553 message appears on the bus. Pure logic does that work, with no processor, no software, and no wait for a system-level reset. The design choice sets a hard ceiling on how long a radiation-induced fault can affect the terminal: one message period.

The BRM1553ERL is a space-grade, high-reliability MIL-STD-1553 IP Core for FPGA and ASIC, supporting Bus Controller (BC), Remote Terminal (RT), and Monitor (MT) operation. Hamming code, watchdog timers, and the per-message reset work together against the single-event upsets that occur routinely in orbit. NASA selected Sital’s MIL-STD-1553 IP for space equipment communication after a competitive evaluation, and the BRM1553ERL is the variant Sital built for satellites and other spacecraft.

TL;DR Quick Answers

BRM1553ERL Space Grade, High Reliability MIL-STD-1553 IP Core

The BRM1553ERL is Sital Technology’s MIL-STD-1553 IP Core for space and other extreme-reliability applications.

  • What it is: A MIL-STD-1553B Notice 2 protocol core, delivered as vendor-independent VHDL for any FPGA or ASIC.
  • Modes: Bus Controller, Remote Terminal, and Monitor, individually or in any combination.
  • What makes it space grade: Hamming code on stored data, watchdog timers on internal logic, and a full state-machine reset triggered by every new MIL-STD-1553 message. Corruption from a single event upset stays bound to one message period, and nothing in the recovery path depends on a processor or software.
  • Flight heritage: Selected by NASA for use in satellites and spacecraft.
  • Footprint: Very small FPGA area utilization. A Front-End RT consumes roughly 764 to 1,036 4-LUTs, depending on device family.
  • Interfaces: Front-End, which needs no memory and no processor, or DDC® Enhanced Mini-ACE® compatible.
  • Certifiability: DO-254 and DO-178 up to and including DAL A, with artifacts available through Sital’s certification partners.

“ERL” stands for Extended Reliability Logic.

Top Takeaways

  1. State-Machine Lockup Is The Real Space Risk In A 1553 Terminal. MIL-STD-1553 already handles a flipped data bit. It has no answer for a controller that stops responding.
  2. The BRM1553ERL Ties Recovery Time To Bus Traffic Rather Than Software. Every new MIL-STD-1553 message resets all internal state machines in pure logic, so an upset cannot survive into the following message.
  3. NASA Selected Sital’s MIL-STD-1553 IP For Space Equipment Communication. The BRM1553ERL carries that lineage into radiation environments.
  4. Small Area Matters More On A Rad-Hard FPGA Than Anywhere Else. Rad-hard fabric is scarce and expensive, so a compact core leaves a budget for the rest of the design.
  5. Vendor-Independent VHDL Removes Single-Source Risk. On programs with 15-year procurement horizons, an IP Core you instantiate in the FPGA of your choice changes the obsolescence picture entirely.

What The BRM1553ERL Is, And Why Space Changes The Problem

Sital supplies the BRM1553ERL as a vendor- and technology-independent VHDL, delivered as an EDIF netlist targeted to your chosen device family, memory configuration, and clock frequency. It runs in any FPGA with sufficient LUTs, and Sital supports ASIC implementation on consultation.

In orbit, charged particles pass through the FPGA fabric and deposit charge in sensitive nodes. The result is a single event upset, a bit flip caused by one ionizing particle strike. MIL-STD-1553 already defends the data path with Manchester encoding and parity, so a corrupted word gets caught and retried. Protocol logic is the harder case. When an upset drives a sequencer into an undefined state, the terminal can stop participating in the bus altogether, and no technician is standing by in orbit to power-cycle it.

That distinction shaped the whole design. Sital’s engineers assumed upsets would happen and built the core to recover from them quickly and predictably, rather than trying to prevent every one.

How The BRM1553ERL Mitigates Single Event Upsets

Four mechanisms work together:

  • Hamming code protection. The core applies error detection and correction to stored data, so it corrects a flipped bit instead of passing it into the message stream.
  • Watchdog timers. Internal timers catch logic that has stalled and force recovery, rather than waiting on a system-level reset that may be seconds away.
  • Per-message state-machine reset. Pure logic resets all internal state machines whenever a new MIL-STD-1553 message is detected on the bus. This mechanism matters most. Bus traffic sets your recovery latency, processor intervention plays no part, and a corrupted state cannot carry into the next message.
  • Recovery from unknown states. During verification, the core recovers from any ‘X’ state injected into its logic as soon as a new message appears on the bus. Engineers can observe that behavior directly in simulation.

One point of clarification, because it comes up in nearly every evaluation call. The BRM1553ERL is protocol logic, and it does not replace a radiation-hardened or radiation-tolerant FPGA. You instantiate it inside the rad-hard device you have already selected, so that the protocol layer behaves predictably when the fabric takes a hit.

Configurations, Back-End Interfaces, And FPGA Area

Sital offers the core as BRM1553ERL-BC, BRM1553ERL-RT, BRM1553ERL-MT, or any combination. Synthesis options let you compile in only the modes your design requires.

Two back-end interfaces are available:

  • Front-End. No memory, no processor, no software required. This configuration suits protocol translators, simple remote terminals, and systems carrying modest message volume. Removing the CPU also removes its software from your reliability and certification analysis.
  • DDC® Enhanced Mini-ACE® compatible. The core arranges messages in a predefined memory and register structure compatible with DDC®’s Enhanced Mini-ACE®, Micro-ACE®, and Total-ACE®. Teams migrating away from single-source components can keep their existing driver code.

A third option, BRM1553ERL-SnS, adds Sital’s patented “SnS” (Safe and Secure) technology. “SnS” detects impersonation on the bus. It also detects and locates open and short circuit faults in bus and stub wires, connectors, couplers, terminators, and LRUs.

Sital’s MIL-STD-1553 IP Cores require very little FPGA space. For a Remote Terminal, published reference figures range from approximately 764 to 1,036 4-LUTs in the Front-End configuration, and approximately 3,100 to 3,950 in the DDC® compatible configuration, depending on vendor and family. These numbers are approximate and vary with core configuration. On rad-hard devices, where fabric is both limited and costly, that difference drives real design decisions.

The Manchester decoder operates at any even clock frequency from 12 MHz up, selected by the user. Fewer clock sources and clock domains on the board mean less EMI/RFI to manage, and the decoder’s filtering algorithms are built for harsh environments.

Validation, Certifiability, And Flight Heritage

Sital publishes what it has tested rather than what it has claimed:

  • Compliance: MIL-STD-1553B Notice 2 at 1 Mbps, connecting to any transceiver-transformer pair through 10 pins and standard FPGA pads.
  • Third-party validation: An independent laboratory ran the core through the full MIL-STD-1553B Notice 2 RT validation test, to a plan derived from MIL-HDBK-1553A.
  • Verification environment: Sital developed the core using a random-generation engine, code coverage, and assertion tools, and verified all MIL-STD-1553B functions and performance requirements.
  • Certifiability: Available with DO-254 artifacts up to and including DAL A, and DO-178 for software drivers, through Sital’s certification partners Logicircuit and ConsuNova.
  • Heritage: NASA chose Sital’s MIL-STD-1553 IP for space equipment communication after evaluating it against competing products.

The core ships with a user’s manual, sample VHDL that instantiates it, a synthesis script, a gate-level model for the target technology, a transceiver model, a 1553 bus-tester model that generates messages and checks replies, a top-level test bench, and a simulation script. Sital assembles that package because integration schedule, not protocol capability, is usually the binding constraint on a space program.

The BRM1553ERL sits inside a broader family of DataBus communication solutions from Sital Technology, covering MIL-STD-1553, EBR-1553 at 10 Mbps, ARINC-429, ARINC-825, and CAN bus across IP Cores, components, boards, and testers.

“Space customers never ask us whether an upset will happen. It will. They ask how long the terminal stays off the bus afterward. We designed the BRM1553ERL so the answer is one message, in logic, with no processor in the recovery path. In verification, it came back from every ‘X’ state we injected the moment the next message arrived.” 

— Sital Technology Team

Essential Resources On BRM1553ERL Space Grade, High Reliability MIL-STD-1553 IP Core

Seven references that engineers evaluating a space-grade 1553 IP Core typically need next.

Understand Exactly How Single Event Effects Behave In FPGA Logic

NASA’s Electronic Parts and Packaging program publishes the test and analysis methodology its Radiation Effects and Analysis Group uses to evaluate FPGA SEU data, including guidance on test structures and mitigation evaluation. Read it to establish what “SEU tested” should actually mean on your program. 

Source: NASA NEPP — Field Programmable Gate Array (FPGA) Single Event Effect (SEE) Radiation Testing

Quantify The Radiation Environment Your Terminal Will Fly Through

NOAA explains how it monitors and forecasts the solar activity that drives upset rates, and how satellite operators act on those forecasts to protect spacecraft. Use it to frame your environment assumptions before setting design margin. 

Source: NOAA NESDIS — Safeguarding Satellites: How NOAA Monitors Space Weather To Prevent Disruptions

Know The Certification Ground Rules Before You Write A Single Requirement

FAA Advisory Circular 20-152A describes an acceptable means of showing compliance for the electronic hardware aspects of airborne systems, and adds objectives covering the use of COTS intellectual property inside a DO-254 program. Read it early if DAL A is in scope. Note also that the AC states outright that it does not address single-event effects, which leaves that documentation to you. 

Source: FAA — AC 20-152A, Development Assurance For Airborne Electronic Hardware

See Where Single-Event Hardness Assurance Practice Stands Today

The National Academies walks through the three-step process of identifying, evaluating, and mitigating a single-event effects threat, and puts real numbers on what device-level testing costs. Useful context when you build a radiation case for a program review. 

Source: National Academies — Current State Of Single-Event Effects Hardness Assurance And Infrastructure

Go Deeper On Radiation Effects With The Engineering Community

IEEE’s LEO Satellites and Systems initiative published a full workshop on radiation effects and testing for satellites, with sessions from NASA GSFC, NASA JPL, ESA, and CERN covering mitigation strategies and heavy-ion test practice. The recorded sessions are free. 

Source: IEEE LEO SatS — Radiation Effects On Satellites And Space Systems Workshop

Find A Facility That Can Beam-Test Your Integrated Design

The Berkeley Accelerator Space Effects facility at Lawrence Berkeley National Laboratory supplies heavy ion, proton, and neutron beams for radiation effects testing, and hosted the first single event effects tests ever conducted, in 1979. Relevant when your program requires device-level or board-level SEE data. 

Source: Lawrence Berkeley National Laboratory — Berkeley Accelerator Space Effects (BASE) Facility

Confirm The Export Control Status Of Your Spacecraft Electronics

USML Category XV governs spacecraft and related articles under ITAR. This final rule documents the most recent revision to what falls under that control. Review it alongside any supply chain, sourcing, or international collaboration decision. 

Source: Federal Register — International Traffic In Arms Regulations: Revision Of U.S. Munitions List Category XV

Supporting Statistics

Three figures that frame why space-grade 1553 design decisions carry the weight they do.

14,266 Operational Satellites Were In Orbit At The End Of 2025

A record 296 launches deployed 4,434 satellites during that single year. Each of them carries a communication architecture that has to work unattended.

Constellation economics has changed the calculus we see in customer conversations. Teams no longer qualify one bus interface for one flagship spacecraft. They qualify a design they intend to replicate dozens or hundreds of times, which turns protocol-layer robustness into a multiplier across the whole program. 

Source: Satellite Industry Association — 29th Annual State Of The Satellite Industry Report

The Global Space Economy Reached A Record $613 Billion In 2024

Growth ran 7.8% year over year, with the commercial sector accounting for 78% of the total and government budgets the remaining 22%.

Watch the commercial share. Commercial programs move faster and carry less schedule slack than traditional government builds. That is why our customers ask about integration deliverables, meaning test benches, bus tester models, and simulation scripts, as often as they ask about protocol features. 

Source: Space Foundation — The Space Report 2025 Q2

NASA Planned About $74 Billion In Major Project Investment For Fiscal Year 2025

Four of 18 major projects in development recorded cost growth over the year, and together they reported more than $500 million in overruns.

Cost growth in space programs concentrates in rework and late discovery. In 25+ years of supplying 1553 IP, we have found that the failures which hurt schedules are rarely exotic. They are integration problems found after board spin, once the cost of a change has already multiplied. Choosing protocol logic with third-party validation behind it removes one of those variables early. 

Source: U.S. Government Accountability Office — NASA: Assessments Of Major Projects

Final Thoughts And Opinion

MIL-STD-1553 in space is a different engineering problem than MIL-STD-1553 on an aircraft. Teams that treat the two as one problem make the mistake we see most often.

Three observations from supplying this core:

  • Radiation tolerance often gets specified at the device level and stops there. A team selects a rad-hard FPGA, marks the requirement closed, and never asks separately how the protocol logic inside it behaves when a bit flips. The FPGA vendor’s LET and TID numbers say nothing about whether your 1553 sequencer recovers.
  • Recovery time is the specification that should be written down and seldom is. “Tolerates SEUs” states an aspiration. “Recovers protocol operation within one message period, in logic, without processor intervention” states a requirement.
  • The area budget decides more designs than feature lists do. On rad-hard fabric, a core that consumes a few thousand LUTs instead of tens of thousands changes what else fits on the die.

Our opinion, stated plainly. For space applications, the most useful thing a 1553 IP Core can offer is a bounded, provable answer to one question: what happens after the upset? Sital built the BRM1553ERL on that principle, and we would encourage any program to press hard on it, in our core or anyone else’s.

Frequently Asked Questions

What Makes The BRM1553ERL A Space Grade MIL-STD-1553 IP Core?

The core implements protocol logic designed to recover from radiation-induced faults. Hamming code protects stored data, watchdog timers catch stalled logic, and pure logic resets every internal state machine when a new MIL-STD-1553 message is detected. An upset therefore stays bound to one message period, and no processor or software sits in the recovery path.

What Does ERL Stand For?

Extended Reliability Logic. The designation marks the variant of Sital’s MIL-STD-1553 IP Core family built for space and other extreme-reliability applications, as distinct from the BRM1553D flagship core used on airborne and ground platforms.

Does The BRM1553ERL Replace A Radiation-Hardened FPGA?

No, and this is the most common misunderstanding we encounter. You instantiate the BRM1553ERL inside the radiation-hardened or radiation-tolerant device you have already selected. Device-level hardening and protocol-level recovery solve different halves of the same problem.

Can The Core Be Implemented In An ASIC As Well As An FPGA?

Yes. Sital supplies it as a vendor- and technology-independent VHDL, delivered as an EDIF netlist targeted to your device family, memory configuration, and clock frequency. Supported FPGA families span Microchip/Actel, AMD/Xilinx, Altera, Lattice, and QuickLogic. Sital supports ASIC implementation on consultation.

How Much FPGA Area Does The BRM1553ERL Use?

For a Remote Terminal, reference figures run approximately 764 to 1,036 4-LUTs in the Front-End configuration, and approximately 3,100 to 3,950 in the DDC® compatible configuration, depending on vendor and family. Figures are approximate and vary with the BC, RT, and Monitor combination selected.

Does It Support Bus Controllers, Remote Terminal, And Monitor Modes?

Yes, individually or in any combination, with either the Front-End or the DDC® Enhanced Mini-ACE® compatible back-end interface. Synthesis compiling options let you include only the modes your design needs, which keeps logic resources to a minimum.

What Certification Support Is Available?

DO-254 artifacts up to and including DAL A for the hardware, and DO-178 up to and including DAL A for software drivers, supplied through Sital’s certification partners Logicircuit and ConsuNova. Sital’s DO-254 certification partnership announcement explains how the certification data package works for licensed IP Cores.

Has The BRM1553ERL Been Used In Flight Programs?

NASA selected Sital’s MIL-STD-1553 IP for space equipment communication after evaluating it against competing products, and the BRM1553ERL is the variant intended for satellites and spacecraft. Sital’s published customer base across the space sector includes NASA, ESA, IAI, and Orbital Sciences Corporation. Confirm the current approved scope for named client references before publication.

Put The BRM1553ERL To Work On Your Space Program

Send us the device family, the modes you need, and the radiation environment you are designing for, and our engineers will tell you what the BRM1553ERL looks like in your FPGA or ASIC. Talk To An Expert, or request an Evaluation to get hardware samples and start integration this quarter.

  • MIL-STD-1553 Intellectual Property for FPGAs
  • Suitable for any High-Reliability MIL-STD-1553 BC, RT, MT implementation
  • Includes features to mitigate against single event upsets: Hamming code, watchdog timers and logic to reset all internal state-machines following every MIL-STD-1553 message.
  • Very small FPGA area utilization
  • Supports any even MHz multiple clock frequency
  • Two possible back-end interfaces available:
    • Front-End – for simple implementations, no memory, does not require a processor or software
    • DDC® compatible – for more complex applications
  • Provided with full verification environment
  • Passed full validation testing by 3rd party
  • Based on vendor and technology independent VHDL code

Select products for quote:

ensure a successful and robust implementation of MIL-STD-1553 for any space or other high-reliability application

for Free Evaluation and hardware Samples

safe illustration

Safe and Secure DataBus Solutions

Sital’s cutting-edge, innovative “SnS” Technology is designed for IP Core’s physical layer. Our solutions offer unprecedented cyber security and DataBus fault finder capabilities.

 

We supply our products with DO-254 and DO-178 certifiability, including DAL A. Our partners: Logicircuit and ConsuNova provide the DO-254 and DO-178 artifacts. Through enhanced physical layer monitoring, the patented “SnS” analyzes all DataBus messages and provides 2 unique capabilities.

2026©All rights reserved
Contact us on Whatsapp