Watchdog Timer
Independent vs Windowed watchdog.
A watchdog timer is a hardware safety mechanism built into microcontrollers that automatically resets the system if the main program fails to service it within a defined time window. The fundamental premise is simple: a working program will always reach the watchdog refresh instruction periodically, but a crashed, hung, or looping program will not. When the watchdog counter expires without being refreshed, the hardware forces a system reset, restoring normal operation without human intervention. This makes watchdog timers indispensable in embedded systems that must operate unattended.
Core Concept of Watchdog Timer
A watchdog timer works on the principle of a countdown counter. The counter is loaded with a preset value at startup and begins counting down. The software must periodically write a specific unlock sequence (called feeding or refreshing the watchdog) before the counter reaches zero. If the counter reaches zero, the hardware interprets this as a system fault and generates a reset. The key design philosophy is that a healthy program always executes the feed instruction on time, so a missing feed is a reliable indicator of a fault.
There are two main types found in most microcontrollers. The Independent Watchdog Timer (IWDT) is clocked from a dedicated internal RC oscillator (LSI) that is completely separate from the main system clock. This makes IWDT capable of detecting even main clock failures, because it keeps running regardless of the CPU clock state. The Window Watchdog Timer (WWDT) is clocked from the APB bus and introduces the concept of an upper and lower boundary window for the refresh operation.
The WWDT adds an additional constraint: the watchdog must NOT be refreshed too early. If the program refreshes before the counter has counted down to the upper window boundary, a reset is generated just as it would be for a late refresh. This forces the programmer to ensure that the watchdog is fed only within a narrow time window, which detects not just hang conditions but also unintended timing errors where the program is executing too fast, possibly due to a bug or incorrect clock configuration.
Mathematical Expression
For the IWDT in STM32 as a representative example, the timeout period is determined by the LSI clock frequency, a prescaler, and the reload register value. The timeout formula gives the maximum time the software has to refresh the watchdog. If the selected timeout is too short, the system will reset even when software is running correctly. If too long, a real fault will go undetected for too long before recovery. Choosing the right timeout is a practical design decision based on the worst-case execution time of the main loop.
The IWDT timeout period is: T_IWDT = (Prescaler x (Reload + 1)) / f_LSI. The LSI frequency is approximately 40 kHz (varies between 30 kHz and 60 kHz across temperature and voltage, so always use worst-case values). The prescaler is a power of two from 4 to 256. For WWDT, the timeout is: T_WWDT = (4096 x 2^WDGTB x (T - 63)) / f_PCLK, where T is the 7-bit counter value and WDGTB is the prescaler selection.
Practical Understanding
In practice, watchdog placement in code must be deliberate. A common mistake is placing the feed instruction inside an interrupt service routine rather than the main loop. If the main loop hangs but interrupts continue to fire, the watchdog gets fed from the ISR and never triggers, making it useless. The feed must be placed in the critical execution path that validates overall system health.
The IWDT is typically enabled in hardware through option bytes (fuse bits) so that it starts running before the bootloader even executes, and software cannot disable it. This is the highest level of protection. The WWDT must be enabled by software and can be disabled before it is started, making it less tamper-proof but more flexible for debug sessions where halting the CPU would otherwise cause constant resets.
Many microcontrollers provide a watchdog reset flag in the reset status register. At startup, software can check this flag to determine whether the last reset was caused by a watchdog timeout. This is useful for fault logging, telemetry, and recovery logic in embedded applications.
Given:
LSI frequency f_LSI = 40 kHz
IWDT Prescaler = 32
Reload Register value = 999
Why this formula applies:
IWDT counter is clocked by LSI divided by prescaler.
Each tick decrements the reload counter.
When counter reaches 0, reset fires.
Formula:
T_IWDT = (Prescaler x (Reload + 1)) / f_LSI
Substitution:
T_IWDT = (32 x (999 + 1)) / 40,000
T_IWDT = (32 x 1000) / 40,000
Calculation:
T_IWDT = 32,000 / 40,000
Final Answer:
IWDT Timeout = 0.8 seconds
Software must feed the watchdog within every 800 ms.Exam Tip: IWDT uses LSI (independent RC, ~40 kHz) and cannot be stopped once enabled via option bytes. WWDT uses APB clock and resets if fed too early or too late. These differences are a common MCQ topic in GATE ES paper.
- IWDT: clocked by LSI (~40 kHz), independent of CPU clock, starts from option bytes, cannot be disabled by software.
- WWDT: clocked by APB clock, requires software enable, fires on both early refresh (before W register value) and late refresh (counter expired).
- Both watchdogs generate a system reset and set a status flag that the application can read on next startup to detect recovery.
- Watchdog feed must be placed in the main execution path, not inside ISRs, to correctly validate full program flow.
- Timeout selection should be based on worst-case main loop execution time including maximum interrupt latency.
Quick Revision
- Watchdog resets the system if software fails to feed it within the timeout period, protecting against hang or crash.
- IWDT timeout: T = (Prescaler x (Reload + 1)) / f_LSI. Uses LSI (~40 kHz) independent of main clock.
- WWDT adds an upper window: feeding too early triggers reset, not just feeding too late.
- IWDT is enabled via option bytes and cannot be stopped; WWDT is software-enabled.
- Watchdog reset flag in status register allows firmware to detect and log watchdog-caused resets.
- Exam trap: never place watchdog feed only inside ISR; the main loop could still hang silently.
Watchdog Timer Practice
Test your knowledge on this topic!