What does widening a frame's CRC from 16 to 32 bits actually buy, and what does it leave untouched?
answer
- width is the generator's degree
- two quantities: burst window, residual
- residual is roughly two to the minus r
- multiply by the corrupted-frame rate first
- covers one hop's covered bytes only
basics
~20 sIt buys exactly two things: guaranteed detection of bursts up to 32 bits instead of 16, and a residual escape rate for unstructured corruption falling from about 1 in 65,536 to about 1 in 4.3 billion. It fixes nothing outside the covered bytes.
solid answer
~50 sWidth is the generator's degree `r`, and it sets two quantities. The **guaranteed burst length** is `r`, so 16 becomes 32. The **residual probability** that an unstructured error pattern divides the generator anyway is about `2^-r`, so roughly `1/65,536` becomes roughly `1/4,294,967,296`. Turn that into a rate before deciding: multiply the frame rate by the fraction of frames corrupted by the fraction that escapes. A bus pushing 10,000 frames a second with one frame in 100,000 corrupted sees about 0.1 corrupt frames a second; at 16 bits that is one undetected frame roughly every 7.6 days, at 32 bits roughly one every 1,360 years. What width does not touch: bytes outside the covered region, corruption already present when the sender computed the field, corruption introduced after the receiver verified it, deliberate modification, and the frame-length ceiling above which a generator's two-bit separation guarantee lapses.
go deeper
Take away the direction and the scope: more check bits means better odds of spotting damage, and the field only ever speaks about the bytes it is defined to cover on one link.
State the two quantities width sets — guaranteed burst length equals the generator's degree, and the residual is about two to the minus that degree — and be able to turn the residual into a rate.
Do the budget out loud: frames per second times corrupted fraction times residual gives a mean time between undetected frames. Then name the failures width does not touch, above all corruption outside the covered region or outside this hop.
The lead-level call is where to spend: two extra bytes per frame is cheap, but coverage gaps between hops, excluded header fields and a generator used beyond its characterised frame length dominate the real undetected-error rate.
## The two quantities a width sets The width of a check field is the degree `r` of its generator, and `r` controls exactly two things that matter operationally. - **Guaranteed burst length.** Every burst spanning at most `r` consecutive bit positions is detected outright. Doubling the width doubles the window. - **Residual escape probability.** For corruption that is not one of the guaranteed classes — a wide burst, scattered heavy damage — the pattern escapes only if it happens to be a multiple of the generator, which for an unstructured pattern happens with probability about `2^-r`. At 16 bits that residual is `1/65,536`, about 1.5 in 100,000. At 32 bits it is `1/4,294,967,296`, roughly 1 in 4.3 billion. Both numbers are conditional on a frame *already being corrupted*, which is the step engineers most often skip. ## Working the budget The decision-shaped quantity is a **rate of undetected corrupt frames**, and it takes three inputs: 1. Frames per second on the link. 2. The fraction of frames that arrive corrupted at all. 3. The residual, about `2^-r`. Take a bus carrying 10,000 frames a second with one frame in 100,000 corrupted. That is 0.1 corrupt frames a second reaching the check. | Check width | Residual | Undetected frames per second | Mean time between them | | --- | --- | --- | --- | | 16 bits | 1 / 65,536 | about 1.5e-6 | about 7.6 days | | 32 bits | 1 / 4,294,967,296 | about 2.3e-11 | about 1,360 years | The second row costs two extra bytes per frame. That is why the wider field is usually an easy call — and also why arguing about it is rarely where the real risk sits. ## What the extra bits do not touch The residual is the probability that **corruption in the covered bytes on this hop** slips through. Everything outside that sentence is unaffected by width: - **Bytes outside the covered region.** Header fields the specification excludes are unprotected at 16 bits and equally unprotected at 32. - **Corruption that predates the computation.** If the payload was already wrong in the sender's memory when the division ran, the field faithfully certifies wrong bytes. The check protects a wire, not a pipeline. - **Corruption after verification.** A frame copied into a buffer, held, then forwarded is unprotected in between, and a store-and-forward hop that recomputes its own check will happily re-bless bytes it damaged internally. - **Deliberate modification.** The construction is public and linear, so an attacker recomputes or patches the field at any width. - **Systematic faults.** A stuck driver, a framing slip that duplicates or drops a whole frame, or a sender emitting a stale-but-well-formed frame all produce internally consistent frames. A check field cannot see any of them. ## The frame-length ceiling One subtlety separates people who have specified a link from people who have only read about one. A generator's guarantees for **isolated multi-bit errors** — two flips far apart, three flips scattered — hold only up to a maximum data length; beyond it the separation the polynomial provides degrades. Published, analysed generators are therefore characterised as a table of (data length, guaranteed separation) rather than a single claim. The practical consequence is that **choosing a wider field and choosing a well-characterised polynomial are different decisions**. A 32-bit generator used far outside its characterised length can offer weaker isolated-error protection than a 16-bit one used inside its own, even though its burst window and residual are better. ## Where the remaining risk usually lives After the arithmetic above, the dominant risk in a real deployment is almost never the residual: - Gaps in coverage between hops, where each hop verifies and recomputes rather than carrying one end-to-end check. - Bytes deliberately excluded from the covered region and then quietly relied upon. - Two implementations disagreeing about parameterisation, so one side's field is meaningless to the other. - The check being cited as protection against an adversary it was never designed for. Widen the field — it is cheap — then go and look at that list, because that is where the undetected corruption actually comes from.
- Why must the residual be multiplied by the corrupted-frame rate rather than quoted on its own?Because the residual is conditional on a frame already being corrupted. On a quiet link almost no frames reach that condition, so the undetected rate is tiny at any width; on a noisy one it can matter at 16 bits. The residual alone names no rate at all.
- Two links use the same 32-bit generator, but one carries frames ten times longer. Are they equally protected?Not for isolated multi-bit errors. A generator's guaranteed separation between scattered flips holds only up to a characterised data length, and the longer frames may sit beyond it. The burst window and the residual are unchanged; the multi-bit separation guarantee is not.
- Each hop on a path verifies the check and recomputes its own. Does that give end-to-end protection?No. It protects each wire, with a gap at every hop where the frame sits in memory unprotected and is then re-blessed by a freshly computed field. Corruption inside a relay is invisible downstream, which is the argument for an additional end-to-end check.
saying these in an interview costs you the question
- Quotes the residual without the corrupted-frame rate
- Says a wider field makes undetected corruption impossible
- Thinks width reduces how often frames get corrupted
- Assumes a per-hop check protects a whole path
- Ignores that guarantees hold only over the covered bytes
- Treats generator width and generator choice as one decision