skip to content

What does widening a frame's CRC from 16 to 32 bits actually buy, and what does it leave untouched?

level: seniorimportance: nice to knowfreq 30%

answer

  1. width is the generator's degree
  2. two quantities: burst window, residual
  3. residual is roughly two to the minus r
  4. multiply by the corrupted-frame rate first
  5. covers one hop's covered bytes only

basics

~20 s

It buys exactly two things: guaranteed detection of bursts up to 32 bits instead of 16, and a residual escape rate for unstructured corruption falling from about 1 in 65,536 to about 1 in 4.3 billion. It fixes nothing outside the covered bytes.

solid answer

~50 s

Width is the generator's degree `r`, and it sets two quantities. The **guaranteed burst length** is `r`, so 16 becomes 32. The **residual probability** that an unstructured error pattern divides the generator anyway is about `2^-r`, so roughly `1/65,536` becomes roughly `1/4,294,967,296`. Turn that into a rate before deciding: multiply the frame rate by the fraction of frames corrupted by the fraction that escapes. A bus pushing 10,000 frames a second with one frame in 100,000 corrupted sees about 0.1 corrupt frames a second; at 16 bits that is one undetected frame roughly every 7.6 days, at 32 bits roughly one every 1,360 years. What width does not touch: bytes outside the covered region, corruption already present when the sender computed the field, corruption introduced after the receiver verified it, deliberate modification, and the frame-length ceiling above which a generator's two-bit separation guarantee lapses.

go deeper

for a junior

Take away the direction and the scope: more check bits means better odds of spotting damage, and the field only ever speaks about the bytes it is defined to cover on one link.

for a middle

State the two quantities width sets — guaranteed burst length equals the generator's degree, and the residual is about two to the minus that degree — and be able to turn the residual into a rate.

for a senior

Do the budget out loud: frames per second times corrupted fraction times residual gives a mean time between undetected frames. Then name the failures width does not touch, above all corruption outside the covered region or outside this hop.

for a principal

The lead-level call is where to spend: two extra bytes per frame is cheap, but coverage gaps between hops, excluded header fields and a generator used beyond its characterised frame length dominate the real undetected-error rate.

## The two quantities a width sets The width of a check field is the degree `r` of its generator, and `r` controls exactly two things that matter operationally. - **Guaranteed burst length.** Every burst spanning at most `r` consecutive bit positions is detected outright. Doubling the width doubles the window. - **Residual escape probability.** For corruption that is not one of the guaranteed classes — a wide burst, scattered heavy damage — the pattern escapes only if it happens to be a multiple of the generator, which for an unstructured pattern happens with probability about `2^-r`. At 16 bits that residual is `1/65,536`, about 1.5 in 100,000. At 32 bits it is `1/4,294,967,296`, roughly 1 in 4.3 billion. Both numbers are conditional on a frame *already being corrupted*, which is the step engineers most often skip. ## Working the budget The decision-shaped quantity is a **rate of undetected corrupt frames**, and it takes three inputs: 1. Frames per second on the link. 2. The fraction of frames that arrive corrupted at all. 3. The residual, about `2^-r`. Take a bus carrying 10,000 frames a second with one frame in 100,000 corrupted. That is 0.1 corrupt frames a second reaching the check. | Check width | Residual | Undetected frames per second | Mean time between them | | --- | --- | --- | --- | | 16 bits | 1 / 65,536 | about 1.5e-6 | about 7.6 days | | 32 bits | 1 / 4,294,967,296 | about 2.3e-11 | about 1,360 years | The second row costs two extra bytes per frame. That is why the wider field is usually an easy call — and also why arguing about it is rarely where the real risk sits. ## What the extra bits do not touch The residual is the probability that **corruption in the covered bytes on this hop** slips through. Everything outside that sentence is unaffected by width: - **Bytes outside the covered region.** Header fields the specification excludes are unprotected at 16 bits and equally unprotected at 32. - **Corruption that predates the computation.** If the payload was already wrong in the sender's memory when the division ran, the field faithfully certifies wrong bytes. The check protects a wire, not a pipeline. - **Corruption after verification.** A frame copied into a buffer, held, then forwarded is unprotected in between, and a store-and-forward hop that recomputes its own check will happily re-bless bytes it damaged internally. - **Deliberate modification.** The construction is public and linear, so an attacker recomputes or patches the field at any width. - **Systematic faults.** A stuck driver, a framing slip that duplicates or drops a whole frame, or a sender emitting a stale-but-well-formed frame all produce internally consistent frames. A check field cannot see any of them. ## The frame-length ceiling One subtlety separates people who have specified a link from people who have only read about one. A generator's guarantees for **isolated multi-bit errors** — two flips far apart, three flips scattered — hold only up to a maximum data length; beyond it the separation the polynomial provides degrades. Published, analysed generators are therefore characterised as a table of (data length, guaranteed separation) rather than a single claim. The practical consequence is that **choosing a wider field and choosing a well-characterised polynomial are different decisions**. A 32-bit generator used far outside its characterised length can offer weaker isolated-error protection than a 16-bit one used inside its own, even though its burst window and residual are better. ## Where the remaining risk usually lives After the arithmetic above, the dominant risk in a real deployment is almost never the residual: - Gaps in coverage between hops, where each hop verifies and recomputes rather than carrying one end-to-end check. - Bytes deliberately excluded from the covered region and then quietly relied upon. - Two implementations disagreeing about parameterisation, so one side's field is meaningless to the other. - The check being cited as protection against an adversary it was never designed for. Widen the field — it is cheap — then go and look at that list, because that is where the undetected corruption actually comes from.

  • Why must the residual be multiplied by the corrupted-frame rate rather than quoted on its own?
    Because the residual is conditional on a frame already being corrupted. On a quiet link almost no frames reach that condition, so the undetected rate is tiny at any width; on a noisy one it can matter at 16 bits. The residual alone names no rate at all.
  • Two links use the same 32-bit generator, but one carries frames ten times longer. Are they equally protected?
    Not for isolated multi-bit errors. A generator's guaranteed separation between scattered flips holds only up to a characterised data length, and the longer frames may sit beyond it. The burst window and the residual are unchanged; the multi-bit separation guarantee is not.
  • Each hop on a path verifies the check and recomputes its own. Does that give end-to-end protection?
    No. It protects each wire, with a gap at every hop where the frame sits in memory unprotected and is then re-blessed by a freshly computed field. Corruption inside a relay is invisible downstream, which is the argument for an additional end-to-end check.

saying these in an interview costs you the question

  • Quotes the residual without the corrupted-frame rate
  • Says a wider field makes undetected corruption impossible
  • Thinks width reduces how often frames get corrupted
  • Assumes a per-hop check protects a whole path
  • Ignores that guarantees hold only over the covered bytes
  • Treats generator width and generator choice as one decision