Nova Patents
AT407582B

Fault-tolerant distributed computer system

Abstract

Method for ensuring the fail-silent property in the time domain of remote communication computers (111, . . . 114) of a fault-tolerant distributed computer system, in which a plurality of remote computers are connected via a distributor unit (101, 102), each remote computer has an independent communications controller unit with the corresponding connections to the communication channels (121), and the access to the communication channels occurs by a cyclical time-division multiple access method. The at least one distributor unit makes sure, by virtue of the correct sending behavior of the remote computer that is known a priori by it, that a remote computer can only send to the other remote computers within its statically assigned time slice.

AT407582B, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 13 August 2019, 7.1 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

7 claims: 7 independent, 0 dependent

  1. 1
    Method for enforcing the fail-silent property in the time domain of node computers of a fault-tolerant distributed computer system in which a large number of node computers are connected via one or more distribution units and where each node computer has an autonomous communication control unit with the appropriate connections to the communication channels and where access is available takes place on the communication channels according to a cyclical time slice procedure, characterized in that a central distribution unit, on the basis of the regular transmission behavior of the node computers known to it a priori, forces a node computer to be able to send to the other node computers only within its statically assigned time slice. 1. Methode zur Erzwingung der Fail-silent Eigenschaft im Zeitbereich von Knotenrechnern eines fehlertoleranten verteilten Computersystems, in dem eine Vielzahl von Knotenrechnern über einen oder mehrere Verteilereinheiten verbunden sind und wo jeder Knotenrechner über eine autonome Kommunikationskontrolleinheit mit den entsprechenden Anschlüssen an die Kommunikationskanäle verfügt und wo der Zugriff auf die Kommunikationskanäle entsprechend einem zyklischen Zeitscheibenverfahren erfolgt, dadurch gekennzeichnet, daß eine zentrale Verteilereinheit aufgrund des ihr a priori bekannt regulären Sendeverhaltens der Knotenrechner erzwingt, daß ein Knotenrechner nur innerhalb seiner statisch zugewiesenen Zeitscheibe an die anderen Knotenrechner zu senden vermag.
  2. 2
    Method according to Claim 1, characterized in that the central distribution unit changes from the unsynchronized state, in which all input ports can be received, to the synchronized state after receiving a correct initialization message, in which received via an input port only during the time slice statically assigned to this input port can be. 2. Methode nach Anspruch 1 dadurch gekennzeichnet, daß die zentrale Verteilereinheit vom Zustand unsynchronisiert, in dem über alle Eingangsports empfangen werden kann, nach dem Empfang einer korrekten Initialierungsnachricht in den Zustand synchronisiert wechselt, in dem über einen Eingangsport nur während der diesem Eingangsport statisch zugewiesenen Zeitscheibe empfangen werden kann.
  3. 3
    Methode nach den Ansprüchen 1 oder 2 dadurch gekennzeichnet, daß eine zentrale Verteilereinheit vom Zustand synchronisiert in den Zustand unsynchronisiert wechselt, wenn an keinem ihrer Eingangports innerhalb eines a priori vorgegebenen Zeitintervalls dfaUit-i eine korrekte Initialisierungsnachricht empfangen wird. 3rd Method according to Claims 1 or 2, characterized in that a central distribution unit changes from the synchronized state to the unsynchronized state if at none of its input ports within an a priori predetermined time interval dfaUit-i a correct initialization message is received.
  4. 4
    Methode nach einem oder mehreren der Ansprüche 1 bis 3 dadurch gekennzeichnet, daß die zentrale Verteilereinheit vom Zustand synchronisiert in den Zustand unsynchronisiert wechselt, wenn an keinem ihrer Eingangports innerhalb eines a priori vorgegebenen Zeitintervalls dfaUit-2 eine Nachricht, die den Codierungsvorschiften des gewählten Codierungssystems entspricht, empfangen wird. 4th Method according to one or more of Claims 1 to 3, characterized in that the central distribution unit changes from the synchronized state to the unsynchronized state if d at none of its input ports within an a priori predetermined time intervalfaUit-2 a message is received that complies with the coding rules of the selected coding system.
  5. 5
    Method according to one or more of Claims 1 to 4, characterized in that a powerful central distribution unit stores the content of initialization messages 5. Methode nach einem oder mehreren der Ansprüche 1 bis 4 dadurch gekennzeichnet, daß eine leistungsfähige zentrale Verteilereinheit den Inhalt von Initialisierungsnachrichten AT 407 582 B auswertet, um eine zusätzliche Fehlererkennung durchzuführen. AT 407 582 B evaluates in order to carry out an additional error detection.
  6. 6
    Methode nach einem oder mehreren der Ansprüche 1 bis 5 dadurch gekennzeichnet, daß die zentrale Verteilereinheit nach Power-up den Zustand ''unsynchronisieif' einnimmt. 6th Method according to one or more of Claims 1 to 5, characterized in that the central distribution unit assumes the "unsynchronized" state after power-up.
  7. 7
    Verteilereinheit mit integriertem Guardian zur Erzwingung der Fail-silent Eigenschaft im Zeitbereich von Knoten rechnern eines fehlertoleranten verteilten Computersystems, in dem eine Vielzahl von Knotenrechnern über einen oder mehrere Verteilereinheiten verbunden sind und wo jeder Knotenrechner über eine autonome Kommunikationskontrolleinheit mit den entsprechenden Anschlüssen an die Kommunikationskanäle verfügt und wo der Zugriff auf die Kommunikationskanäle entsprechend einem zyklischen Zeitscheibenverfahren erfolgt, dadurch gekennzeichnet, daß die zentrale Verteilereinheit aufgrund des ihr a priori bekannten reguläre Sendeverhaltens der Knotenrechner erzwingt, daß ein Knotenrechner nur innerhalb seiner statisch zugewiesenen Zeitscheibe an die anderen Knotenrechner zu senden vermag und wo die Verteilereinheit eine oder mehrere der in Ansprüchen 2 bis 6 beschriebenen Methoden realisiert. 7th Distribution unit with integrated guardian for enforcing the fail-silent property in the time domain of node computers of a fault-tolerant distributed computer system, in which a large number of node computers are connected via one or more distribution units and where each node computer has an autonomous communication control unit with the corresponding connections to the communication channels and where the communication channels are accessed according to a cyclical time-slice method, characterized in that the central distribution unit is based on enforces the regular transmission behavior of the node computers known a priori, that a node computer is only able to send to the other node computers within its statically assigned time slice and where the distribution unit implements one or more of the methods described in claims 2 to 6.