Your browser does not support JavaScript! Skip to main content
Free 30-day trial DO-178C Handbook RapiCoupling Preview DO-178C Multicore Training Multicore Resources
Rapita Systems
 

Industry leading verification solutions

View All

Software Verification with RVS

RapiTest - Functional testing RapiCover - Coverage analysis RapiTime - Timing analysis RapiTask - RTOS scheduling visualization RapiCoverZero - Zero-footprint coverage analysis RapiTimeZero - Zero-footprint timing analysis RapiTaskZero - Zero-footprint scheduling analysis RVS Qualification Kits - Tool qualification for DO-178C RapiCouplingPreview - DCCC analysis

Multicore Verification with MACH178

MACH178 Core Pack - Getting started MACH178 Platform Pack - Platform evaluation MACH178 Resource Pack - Interference verification MACH178 Qualification Pack- Tool qualification

Product-related services

Tool Integration Training Consultancy Support

Other Solutions

RTBx - The ultimate data logging solution Sim68020 - Motorola 68020 Simulation

Using Our Solutions

RVS Development roadmap Product life cycle policy RVS Assurance issue policy

Latest from Rapita HQ

Latest news

Text: Whats New in RVS 3.25. Image: Double decker commercial airliner taking off from a runway with an overlay of code RVS 3.25 brings improved zero-footprint analysis to more platforms
Rapita Systems Collaborates with Wind River to Break the Multicore Certification Barrier
MACH178 Rapita Systems Launches Next Generation of MACH178 for Multicore
RVS 3.24 accelerates multicore software verification
View News

Latest from the Rapita blog

Introduction to Data Coupling and Control Coupling for DO-178C
The Evolution of DO-178 and ED-12 Standards
Retro gaming with the Sim68020
RVS gets a new timing analysis engine
View Blog

Latest discovery pages

Processor How to achieve multicore DO-178C certification with Rapita Systems
Plane How to achieve DO-178C certification with Rapita Systems
Military Drone Certifying Unmanned Aircraft Systems
control_tower DO-278A Guidance: Introduction to RTCA DO-278 approval
View Discovery pages

Upcoming events

DASC 2026
2026-09-13
DO-178C Multicore Virtual Training
2026-09-29
HISC 2026
2026-10-13
Supporting Multicore Interference Analysis using Branch Traces
2026-11-24
View Events

Technical resources for industry professionals

Latest White papers

Mitigation of interference in multicore processors for A(M)C 20-193
Sysgo WP
Developing DO-178C and ED-12C-certifiable multicore software
DO178C Handbook
Efficient Verification Through the DO-178C Life Cycle
View White papers

Latest Videos

Supporting Multicore Interference Analysis using Branch Traces
Multicore Avionics (Aerospace Innovations)
AMACC Rev B & Multicore Certification: Key considerations for software verification in US defense programs
Certification-Ready Rust: GNAT Pro & RVS for Avionics Standards
View Videos

Latest Case studies

Case Study Front Cover
Multicore timing analysis support for ECSS-E-ST-40C R&D with MACH178
GMV case study front cover
GMV verify ISO26262 automotive software with RVS
Kappa: Verifying Airborne Video Systems for Air-to-Air Refueling using RVS
View Case studies

Other Resources

 Webinars

 Brochures

 Product briefs

 Technical notes

 Research projects

 Flyers

 Multicore resources

Discover Rapita

About us

The company menu

  • Customers
  • Partners & Distributors
  • Research projects
  • Contact us
  • Careers
  • Working at Rapita
  • Subscribe to newsletter

Industries

  Civil Aviation (DO-178C)   Military & Defense   Automotive (ISO 26262)   Space

Standards

  DO-178C   A(M)C 20-193

US office


info@rapitasystems.com Rapita Systems, Inc., 41131 Vincenti Ct., Novi, MI 48375, USA

UK office

+44 (0)1904 413945
info@rapitasystems.com Rapita Systems Ltd., Atlas House, Osbaldwick Link Road, York, YO10 3JB, UK

Spain office

+34 93 351 02 05
info@rapitasystems.com Rapita Systems S.L., Parc UPC, Edificio K2M, c/ Jordi Girona, 1-3, Barcelona 08034, Spain
Back to Top

Chaining two 16 bit timers together in STM32f4

2013-12-10

If, like us, you need to measure times with high accuracy over a relatively long period of time, timers with 32-bit accuracy are probably the way to go. Although the STM32F4 only offers two 32 bit timers, it is also possible to chain two 16 bit timers together to obtain 32 bit accuracy.

In the STM32F4 you can configure either TIM9 or TIM12 to act as the most significant word (MSW) of a 32-bit timer, which can be connected to another timer, which acts as the least significant word (LSW). The ST documentation refers to this as a "Synchronization circuit to control the timer with external signals and to interconnect several timers".

Below is an example using TIM3 as the master (to count the lower 16 bits) and TIM9 as the slave (to count the upper 16 bits):

/* enable the timer peripherals: */
RCC->APB1ENR |= RCC_APB1Periph_TIM3;
RCC->APB2ENR |= RCC_APB2Periph_TIM9;
/* Master - TIM3 counts the lower 16 bits */
/* TIM3 should use the clock as its input by default.*/
TIM3->PSC = 0x0000; /* no prescaler. */
/* set clock division to zero: */
TIM3->CR1 &= (uint16_t)(~TIM_CR1_CKD);
TIM3->CR1 |= TIM_CKD_DIV1;
TIM3->CR2 |= 0x20; /* MMS (6:4) */
/* slave - TIM9 counter the upper 16 bits */
TIM9->PSC = 0x0000;
/* set clock division to zero: */
TIM9->CR1 &= (uint16_t)(~TIM_CR1_CKD);
TIM9->CR1 |= TIM_CKD_DIV1;
TIM9->SMCR |= (TIM_TS_ITR1 | TIM_SlaveMode_External1);
/* enable the two counters: */
TIM9->CR1 |= TIM_CR1_CEN;
TIM3->CR1 |= TIM_CR1_CEN;

In the example you can see that both timers need to have their prescaler set to zero and their clock division set to zero. The timer capturing the lower 16 bits (TIM3 in this case) needs to be configured in Master Mode (TIM3_CR2:MMS = 010, master is used as a prescaler for the slave). The timer capturing the high 16 bits (TIM9 in our example) needs to have the following configuration set:

  • The Trigger Selection needs to be set to TIM3 (001) so that the output from TIM3 acts as the input to TIM9
    TIM9_SMCR:TS = 001
    
  • The Slave Mode Selection needs to be set to External Clock Mode 1 (111) - Rising edges of the selected trigger (TRGI) clock the counter. So the input causes a counter increment.
    TIM9_SMCR:SMS = 111
    

The one challenge that this approach introduces is the risk of the LSW wrapping around between reading one 16-bit register and the other one (it doesn't matter what order they occur in). For example, if the timers have the following values

TIM9 (msw) TIM3 (lsw)
0x0100 0xffff

If we read TIM9, then the clock increments before we read TIM3, we'll get a value that's about 216 ticks too low. If we read the registers in the other way, the resulting value is about 216 ticks too high. The following (rather simplistic) approach can handle rollover

lsw_1 = TIM3_CNT;
msw_1 = TIM9_CNT;
lsw_2 = TIM3_CNT;
/* has TIM3 rolled over between its first and second reading? */
if (lsw_2 < lsw_1) {
/* rollover has happened. lsw_2 is read post-rollover. 
* Not sure whether msw_1 was read pre- or post-rollover */
ret.s.lsw = lsw_2;
ret.s.msw = TIM9_CNT; /* re-read MSW to be sure we've got it post-rollover */
} else {
/* a rollover didn't occur between reading lsw_1 and lsw_2. We can use msw_1 safely */
ret.s.lsw = lsw_2;
ret.s.msw = msw_1;
}

So with a bit of simple setup, and a little pain when it comes to reading the result, you effectively have two more 32 bit timers on the STM32. Have fun.

DO-178C webinars

DO178C webinars

White papers


Mitigation of interference in multicore processors for A(M)C 20-193
Sysgo WP
Developing DO-178C and ED-12C-certifiable multicore software
DO178C Handbook
Efficient Verification Through the DO-178C Life Cycle

A Commercial Solution for Safety-Critical Multicore Timing Analysis

Related blog posts

How to use the System Clock to extract timing data from a TriCore timer

.
2013-09-11

Using I/O ports on the STM32 F4 Discovery

.
2013-01-15

Hardware acceleration features that make real-time hard – pipelined architectures

.
2012-11-28

On-target verification - if it's so difficult, why do it?

.
2012-08-17

Pagination

  • First page « First
  • Previous page ‹ Previous
  • Page 1
  • Page 2
  • Current page 3
  • Page 4
  • Next page Next ›
  • Last page Last »
  • Solutions
    • Rapita Verification Suite
    • RapiTest
    • RapiCover
    • RapiTime
    • RapiTask
    • MACH178
  • Latest
  • Latest menu

    • News
    • Blog
    • Events
    • Videos
  • Success Stories
  • Success Stories Menu

    • Airbus Defence & Space
    • BAE Systems
    • Cobham
    • Collins Aerospace
    • Leonardo
  • Downloads
  • Downloads menu

    • Brochures
    • Webinars
    • White Papers
    • Case Studies
    • Product briefs
    • Technical notes
    • Software licensing
  • Company
  • Company menu

    • About Rapita
    • Careers
    • Customers
    • Industries
    • Locations
    • Partners
    • Research projects
    • Contact
  • Discover
    • Multicore Timing Analysis
    • Worst Case Execution Time
    • WCET Tools
    • Code coverage for Ada, C & C++
    • MC/DC Coverage
    • Verifying additional code for DO-178C
    • Data Coupling & Control Coupling
    • DO-178C
    • AC 20-193 and AMC 20-193
    • Certifying eVTOL
    • Certifying UAS

All materials © Rapita Systems Ltd. 2026 - All rights reserved | Privacy information | Trademark notice Subscribe to our newsletter