Fault-tolerant data processing system.
Abstract
The system exhibits groups (TMR) of computer units (SRU) which supply and process identical binary data signals, and one logical decision unit (voter) each which votes on the data signals of the group (TMR). In this arrangement, a plurality of groups (TMR) having at least three computer units (SRU) supplying or processing data signals are connected to one another via data channels (K1, K2, K3) and the voters of one group are connected to the voters of other groups via data or signal lines. Each computer unit (SRU) supplying or processing data signals can exhibit at least one voter for the decision on the freedom from errors of input and/or output signals. Each computer unit (SRU) supplying or processing data signals suitably contains one sequence voter for the decision on the correct sequence of the signals to be processed. <IMAGE>

Term
Term ended
Projected expiry passed 7 May 2007, 19.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
9 claims: 2 independent, 7 dependent
- c-de-00011. providing fault tolerant data processing system with a group of same binary data signals and processing computer units and at least one logical decision unit (Voter), which is voted on by the data signals of the group, characterized in that a plurality of groups with at least three, supplying data signals or processing computing units together is connected via data channels, and the Voter that a group associated with the previous voters other groups via data or signal lines.
- c-de-00044. A fault tolerant data processing system according to one of claims 1, 2 or 3, characterized in that the between groups exchanged signals are serially transferable and one computer unit to a group with at least one each computer unit to another group is connected via bidirektionald data or signal lines.
Independent claims2
68 paragraphs, as filed
The invention relates to providing a fault tolerant data processing system with a group of same binary data signals and processing computer units and at least one logical decision unit (Voter), which is voted on by the data signals of the group.
The fault tolerant data processing systems are, for example, US Patent No. 4,375,683 refer to. In this known forming a so-called tripelmodulare redundancy is used, whereby each three computers are connected to a common logical decision unit. Such circuit arrangements are primarily of achieving a higher system reliability in unpredictable hardware failures. In this known device, the decision logic unit operates on the basis of a majority vote, and the system can also be operated even further useful if a computer unit of the three combined to form a group units emits an incorrect signal. The decision logic unit forms at two identical signals, which differ from a third signal, a majority decision in favor of the like signals and this majority result is further processed in the data processing.
In particular, for the process in complex data processing systems in which non-periodic and indeterministic events to be processed and an event-driven system to be created, there are major problems with the synchronization of the individual units of data processing system. To produce a global time base in all data processing units, a considerable synchronization and communication overhead would be necessary, which would use up to half of the available computing power. In the known device according to US Patent 4,375,683 a networking to more complex data processing systems is not readily possible and the applicability of the basic principles set forth in U.S. Patent No. 4,375,683 of tripelmodularen redundancy is limited to relatively simple cyclic running and easily synced events , Applications, the nature of which is cyclical in nature, for example, where ters to an engine as a function of Leistungspa in controlling the fuel supply. For process control systems that detect inherently decentralized events, wi s example for railway signaling systems, a high degree of decentralized data processing is additionally provided. Especially in such applications, it is particularly advantageous to provide a design of fault tolerant data processing system with which substantially reduces the cabling required for communication between the individual computer units or groups and at the same time a high level of system reliability is maintained. The invention is further from it, even with non-periodic and indeterministic events a high degree of reliability and fault tolerance to ensure.
To achieve this object, the invention consists essentially in the fact that a plurality of groups with at least three, supplying data signals or processing computing unit is connected via data channels and that the voter a group associated with the previous voters of other groups on data or signal lines. The fact that a substantial or even complete crosslinking of the individual computer units of the groups and the groups to each other is provided to synchronize the external synchronization effort and thus the proportion of the communication can be substantially reduced on with the measure, the voters of a group with the previous voters to join other groups on data or signal lines, even in complex and networked systems a high degree of fault tolerance is achieved. This type of connection makes it possible in a global time base to dispense and synchronizations, for instance by means of a relative time basis, for example, by exclusive measurement of time differences to make.
The process processing can proceed because he selected networking for a simple priority-driven process. A system-wide time base can be omitted here for the synchronization of the process processing and also there is no need for a time frame for the Druchführung processes. The connection of the individual, providing data signals or processing computer units to each other can be formed by serial point-to-point connections as crosslinking.
The necessarily and inevitably occurring timing imprecision in the transmission of messages on these compounds can be controlled by an appropriate decision logic. Advantageously, the training is hiebei taken so that each data signals delivered or processing computer unit comprises at least one voter to rule on the correctness of input and / or output signals, the resulting above all in non-cyclical procedures and elimination of a global time base problems with the order of the individual messages can thereby be controlled effectively, that each data signals delivered or processing computer unit includes a Sequenzvoter to decide on the correct sequence of signals to be processed.
For the formation of a clear decision on the input or output signals data signals supplying or manufacturing computer units are in each group at least three, are provided so that a clear majority formation is possible. In the case of Sequenzvoter fault tolerance can be increased, that whenever any individual computer units of a group results in different sequences, it is assumed that it essentially is simultaneous events and therefore a priority or an order of the messages also on the basis a random order, which must, however, be chosen uniformly for the subsequent operations can be continued here. In addition to the error detection and the tripelmodularen redundancy also other forms of redundancy in a fault tolerant data processing system for non-periodic event-driven systems desirable whereby in addition to an active redundancy, wherein a plurality of data signals supplying or manufacturing computer units are simultaneously involved in the fulfillment of the same problem, also a passive redundancy can be provided, in which a redundant data signals delivered or processing computing unit only then switched on when it is intended to replace a failed during operation, data signals delivered or processing computer unit.
The main advantage of cross-linking according to the invention is that the transmission of data or signals or messages can be carried in series between individual groups, so that the line loss is inherently substantially reduced. The possibility of serial transmission is due primarily to the existence of Sequenzvoters which an optionally occurred to change the order of the individual signals or messages in turn corrected with non-periodic indeterministic events. The compounds or links between the individual computer units are bidirectional, so that a complete meshing and a complete replacement of the processes in the individual groups of the fault tolerant data processing system is taking place today. The crosslinking can hiebei be made in the form of a cascade or even branches or merges included (convergences and divergences). Additionally, it is within the fault tolerant data processing system of the present invention possible to provide data signals supplying or manufacturing computer units having data inputs for sensor signals or input or output processors, whereby the fault tolerant data processing system, a fault tolerance to the sensor signals or faulty sensor signals is achieved. The inputs and / or outputs of the groups are hiebei advantageously connected peripheral processors, which are responsible for the further process control.
To view a complete communication via the correctness both what the completeness and correctness of the input or output signals are concerned, as well as to the correct sequence of signals to ensure the crosslinking is advantageously carried out so that the signals from the voter for input signals the Sequenzvotern be forwarded. The Sequenzvoter hiebei decide the order of the input signals and the input signals are passed in the sequence in this order of the processing system and then put the Ausgangsvoter available earnings. The internal logic of the decision units or voter for the input or output signals is hiebei designed so that the input and / or Ausgangsvoter forward the signals at a predetermined based on the total number of channels with majority advantage. For a clear decision an odd number of data signals supplied or processing units of each group is hiebei required and the decision logic in the case of redundancy tripelmodularer a two-by-three-reaching its decision. In the case of a link größerern number of data signals supplied or manufac- turing units per group, an appropriately sensitive condition for the accuracy of the signal processing are placed, whereby the fault tolerance although decreasing, but the reliability is increased.
The inventive fault tolerant data processing system is also suitable for connecting single-channel peripheral devices, except for the maintenance of forgiveness on interactive channel peripheral devices, the arrangement is such that the connection of these devices, an interface is provided that a voter for voting on the signals of a group contains, which are to be forwarded to the peripheral device, and multiplies the supplied by the peripheral device of the group signals corresponding to the number of units of the group.
An essential advantage of the system linking the invention can be seen in the possible serial connection between the individual groups or units, this interconnection can be made with a low line expenses. For with this type of connection necessarily resulting transit time differences, the fault tolerance is ensured by the fact that decisions can be made about the order of the individual signals or messages within the same network.
The following example is the principle of a highly reliable, fault-tolerant real-time system, which was designed for use in fail-safe controls, such as in railway signal boxes, described. This system is hereinafter referred VOTRICS (Voting Triple Modular Computing System).
In the drawings Figure l is a general illustration of a VOTRICS system, Figure 2 cascading VOTRICS -.. Node, Figure 3 shows the convergence of VOTRICS -.. Node, Figure 4 is a divergence of VOTRICS -. Node, Figure 5 shows the time blur in the transmission of a message triad between two cascaded VOTRICS -.. systems, Figure 6 shows the interaction of Voterfunktionen in a computer unit, Figure 7 voting links between adjacent VOTRICS -. computer units and 8 is a virtual duplication of voting links through the use of redundancy in the time domain ,
A VOTRICS network consists of any network of one or more VOTRICS - nodes, each of these nodes constitutes an autonomous fault tolerant subsystem. In the minimum configuration is a VOTRICS - nodes of three independent computer units of the same configuration - called Smallest Replaceable Units (SRU) - through serial bidirectional Voting - loose links VL are fully meshed with each other. Each SRU is connected by one or more serial input and output channels IC, OC with the environment. Fig. L shows the most general arrangement of such a system consisting of SRU (al) ... SRU (at), which cooperate in active redundancy and SRU (pl) ... SRU (pn) in passive redundancy (Standby).
the use of active redundancy required controls - Due to the required time behavior is in real-time systems for failsafe.
A prerequisite for the successful use of active redundancy is an efficient voting mechanism, which allows the results and the behavior of working in active redundancy calculator constantly and vegleichen each other in real time conditions. To continue working in the event of discovered by voting mechanism mismatch results or the conduct still right, so to be able to tolerate the error (error-masking), at least 2N + l independently determined results are necessary. When using parallel, active redundancy (simultaneous determination of the results, one per computer) so at least three computers are required to tolerate errors.
The usual in literature term for this form of redundancy is "Triple Modular Redundancy (TMR)". For the sake of simplicity only is on a TMR at the nearby Overview Description Parameters of VOTRICS - entered configuration with active redundancy. In many of the mentioned in the literature fault tolerant systems special voting hardware is used. If this voting hardware running easy, so it deteriorates by the mean time between failures (MTBF) of the TMR system. The outcome of the voting hardware has a total failure. There are also solutions with redundant hardware Voting known (see, for example:. AL Hopkins Jr., FTMP - A Highly Reliable Fault-Tolerant Multi- processor for Aircraft, Proc of the IEEE, Vol 66 No. lo pp l22l - l239, l978 Oct. ). While these provide a relatively better reliability, require Allerding a significant hardware overhead.
In the present VOTRICS therefore the voting function is allocated to the individual computer units (SRU's) of the system. Advantageously, this can be done by Softwarevoter in each computer unit. The architecture described in the successful eden allows any combination of SRU's in active and / or passive redundancy, so it can be flexibly adapted to each required reliability and availability.
VOTRICS differs in some fundamental points very significantly from other fault-tolerant computer systems with a similar objective:<ul><li>l) no global time base (not tight synchronization of the clocks of all the SRU's)</li><li>2) indeterministic first in - first out (FIFO) - Scheduling</li><li>3) no 'broadcast' - communication between the SRU's.</li></ul>
The establishment of a global (absolute) time base with sufficient granularity in the millisecond range in all SRU's a distributed Systmes requires additional synchronization and communication expenses. The applied in a known system Interactive convergence algorithm caused depending on the number of employed SRU's and the clock drift an additional expense which verbruacht at about l2-l5 SRU's l00% of the available computing power. (See for example: C. Krishna & K. Shin, synchronization and fault masking in Redundant Real-Time Systems, Dig of Pap l4th Int Symp on Fault-Tolerant Computing, pp l52-l57, l984 and L...... Lamport & PM Melliar-Smith, Synchronizing Clocks in the Presence of Faults, Journal of the ACM, Vol 32 No l, pp. 52 - 78, Jan l985). Time measurements are performed in VOTRICS only using a relative time basis - time differences will be exclusively measured, ie the inevitable drift of the hardware timer can not affect.
In VOTRICS the scheduling process is not performed in a fixed, periodic pattern, but according to a simple FIFO priority-controlled method. All actions are performed on the basis of (stochastic) external and internal events. By eliminating the coupling of scheduling on a system-wide time base, it is necessary, using appropriate synchronization action to coordinate scheduling activities among working in active redundancy SRU's.
Both VOTRICS node and the computer units SRU within a node are by serial point - networked connections - to - point. An alternative would be computer links via redundant "broadcast buses". The point - to - point connections, however, give a simple method to limit the error propagation, since only two units SRU may be affected by a link failure.
Only by these assumptions is achieved with respect to the application a high level of generality and transparency of the fault tolerance mechanisms. For example, based the well-known in the systems SIFT and August 300 applied synchronization method (see: CB vine, "SIFT: System Design and Implementation"..., Dig of Pap l0th Int Symposium on Fault Tolerant Computing, Kyoto, Japan, pp 75 - 77, Oct-3 l, l980 and J. Wensley, "Industrial Control system does Things in three for Safety", Electronics, Jan l983) on a simple, periodic linked to a global time base scheduling method. The advantage of the relative simplicity of such a synchronization algorithm can be fully there only flourish where applications inherently cyclical in nature (such as controlling the fuel supply to an engine as a function of performance parameters). For process control, the stochastic are inherently (railway signaling systems belong to this group) the use of periodic systems is inappropriate as non-periodic processes can be mapped difficulties on the cyclic operation of the operating system.
In Figs. 2, 3 and 4 networking options of VOTRICS be - nodes shown.
Each VOTRICS - node forms a fault tolerant subsystem itself. A key objective of this approach is the ability to build a plurality of such sub-systems, a distributed computer network. For this purpose it is necessary VOTRICS - to interconnect nodes. The coupling of two VOTRICS - node is carried out by three point-to-point connections (paired each of two adjacent SRU's). In this way can be produced any network topology by cascading and branching.
As shown in Fig. 2, the node TMR are (n, x) (node x of the plane n) and the node (TMR n + l, y) (node y of the level n + l) via the channels Kl, K2 and K3 connected in cascade. Within each node, the three computer units SRU (l, 2,3) are fully meshed with each other.
In Fig. 3, the convergence is illustrated in a VOTRICS arrangement. The outputs of the node are TMR (n, x) - ie node X of the plane n - to the respective inputs of node TMR (n + l, y) or TMR (n + l, z) - these are the node y or for the level n + l - connected.
As is apparent from Fig 4, a divergence is possible in a similar manner. In the example shown and TMR (n, y) to the inputs of the node (TMR n + l, z) are the outputs of the TMR node (x, n), respectively.
All communication and synchronization in a VOTRICS network is exclusively using "CHILL-News" (See:... CCITT Recommendation z.200, "CCITT High Level Language CHILL" Yellow Book, Vol VI, Fasc VI.8 Geneva l98l). This applies both to the interprocess communication within a SRU, and more broadly, the 'Inter-SRU communications'.
This type of Nachrichtenynchronisation corresponds to the principle of event control, which all actions can be triggered by application processes solely through messages. Here there are generally only two sources that can interfere with events in the course of an application process from the outside: messages that are received from a neighbor SRU coming on an input channel (IC) and the passage of time monitoring what by the operating system in Timeout messages are converted.
The expiry of CHILL application is not interrupt driven; Interrupts are handled by the operating system and are used only to process the serial communication between SRU's.
Fig. 5 shows the timing imprecision in the transmission of a message between two triad cascaded VOTRICS systems. The communication between adjacent nodes VOTRICS via 'news triads': three identical messages are exchanged between the three pairs of two adjacent SRU VOTRICS nodes on the three interconnections. Due to the different processing times in the SRU's the sending and receiving VOTRICS node and also by possible differences in the transmission times (serial transmission method), the news of a triad hit with a temporal blur a at the receiver processes.
In this example, the node TMR (n, x) send (from FIG. 2) existing three computer units SRU (n, x, l) SRU (n, x, 2) and SRU (n, x, 3) on the channels Kl, K2, K3, the output message OM (n, x, l), OM (n, x, 2) and OM (n, x, 3) is made. The max. Output blur Uamax (n, x) is given in this case by the time interval of the output messages OM (n, x, l) and OM (n, x, 2). Due to different transmission times TUEL, TUe2, TUe3 the transmission sharpness Utue (n, x - n + l, y) in the present example TUe2 minus TUEL. The maximum rate of input blur with a message Triad arrives at the destination node, results from Uemax (n + l, y) = Vomax (n, x) + Utue (n, x n + l, y). Despite temporal blur proviso that the recipient on each input channel of a triad normally (no transmission errors) arrives the same sequence of messages. If multiple input channels connected to each SRU (convergence, see Fig. 4) so it no longer applies to the sum received from these channels messages. By the timing imprecision in the transmission of messages triads on different channels, there is overhaul operations, which leads to that the data received from each SRU VOTRICS a system message sequences are unequal. Would such a resulting sequence of messages unaltered to the application processes, so this would a different behavior of the application processes of the individual SRU's caused, the TMR system would no longer be synchronized.
The synchronization algorithm used in VOTRICS to solve this problem based on the principle of a distributed 'Sequence voting' on the information passed on through einzelenen SRU's a TMR system to the application processes sequence of input messages, which will be described in a later section.
The time behavior of the application processes is controlled by time-out messages. Since the clocks are not synchronized, and run the application processes with significant time blurs in three computer units, the result of time-out message is not necessarily identical in all three units. But you can look at the generated by the operating system timeout messages as an additional input channel and therefore identical timeout messages to the application processes to all computer units will be sent.
In the following 6 the interaction of Voterfunktionen is now with reference to FIG. Set forth in a computer unit SRU.
When distributed Voting (a data record, etc. as a message) is from three independent previous voters (a voter per SRU) together about an object matched. During the voting process, each sends the current object wrapped in a voting message to its two neighbors. Each voter compares his own object with the other two and then applies for an independent 2of3 decision. Normally, this result is passed, an error occurs, the output is suppressed and the error to a central error processing process.
The voter can be used for many different tasks, the following basic functions are performed by each voter: misrecognition error masking and synchronization.
Depending on the task of Voters these functions have different weight.
Depending on whether multiple logical news sources to be voted at the same one or a distinction between sequence Voting and Input / Output voting. In each computer unit SRU an Input / Output Voter IOV forming means Voting Links VL with its neighboring previous voters a Voter triad exists. This voter now has to vote on all incoming or outgoing messages triads a VOTRICS node. The source of incoming messages triads are the input channels ICl ... ICn and the timeout handler TOH of Operating Systems. The outgoing messages that are developed by the application processor AP, leave the VOTRICS node via the output channels OCl ... OCm after being detected by the input-output Votertriade correct.
Due to the transmission blur in the input channels and the non-synchronized system clock, the input message sequences are generated by the input / output previous voters, in each SRU different, even though the set of messages in each sequence are the same. All Input Messages triads, which were assumed to be correct during Input voting are, therefore redirected to the sequence Voter SV, where a uniform sequence of messages is prepared and is then passed to the application process.
Voter have the task of detecting error conditions and if possible to mask, but can not perform a system-wide measures, such as stopping the own SRU, etc. Recovery. For this purpose an 'Error Monitoring Process' (EMP) is introduced, which receives reported all identified by the previous voters errors (also masked).
The connections between VOTRICS node (triads serial data channels) are mostly exposed to the interference of the environment due to the possible large distances. Per input channel triad (IC), there is, therefore, an input / output Voter- triad which you vote on the signals received on this IC. It is voted on both the accuracy of the order as well as on the content and time accuracy of the signals. The resulting signal sequence of this voting will be forwarded to the Sequence-Voter, which is explained later. It is the object of the input / output Voters to detect errors in the input signal triad, and mask.
In VOTRICS can start one or more of each other independently running time monitoring of each application process. After draining of such a specified timeout by himself when starting the timeout message, the process by the operating system.
It is usually also happen that a time-out in an SRU expires and in the other two are not (or vice versa). Although not fault situation, it is not desirable to handle such situations in the Sequence Voter (the sequence Voter would by special treatment of the timeout message to much more complex). The timeout signals are therefore passed to the Input / Output-Voter, which then ensures that only full timeout messages triads are forwarded to the Sequence-Voter triad.
The input / output Votertriade you vote via all signals, leaving the VOTRICS node. The purpose of the output Votens is the detection of errors in neighboring units, the error masking and providing the output triad with a single identifier. The sequence of the signals leaving the Votrics node in the same sequence, as prepared by the application process.
Although each specific input / output Vote is conducted only over three redundant objects (in most cases signal triads), have the input / output Voter process the sequences of such triads correctly. This leads to some constraints: -The Triads a logical channel (eg, an input channel) must be issued in the same order as they arrived. As a triplizierter channel generates three identical signal sequences, a uniform series is set in the signal triads. -The Result is transmitted in the signals from different logical channels, is arbitrary. -A Faulty triad must not affect the processing of other triads in the same voter.
Triads of different logical channels, should be processed and transmitted in parallel during consecutive triads have to be transferred sequentially on a single logical channel.
Because of the constraints under which arrive signal triads in a VOTRICS nodes can each affect the triads in various ways, namely by -Triadenüberlappung On a single logical channel: If the time interval between the arrival of triads is less than the time uncertainty within the three signals of the triad, then it can happen, for example, that the signal at the "own" input channel of the voter arrives later than one or both voting signals a subsequent triad (the Inptsignale receiving the Nachbarvoter and pass). In case of a "defective" triad, ie a triad with a bad or no signal, much more complex situations may arise. -Kanalüberlappung: The input / output voter must triads from a plurality of logical input channels to process (physical of at least one input channel and a time-out handler). The signals of these triads may arrive in any order.
The Input / Output Voter must therefore be capable of any combination of Triads - to process and channel overlap.
Now, the all Voter types describes underlying voting algorithm.
The basic principle of applied here distributed voting is that each voter back the contents of a message received from him Input message by sending 'Voting News' to its partners. An output of the voting outcome (z. B. in the case of the IOV submission to the Sequence-Voter) takes place solely on the basis of a majority decision 2of3 (Commitment).
Due to the inevitable temporal blur arrival of input messages will appear in the rule that a voter one or both Voting News obtained before private Imputnachricht. After the arrival of the first message of a new commitments of Voter time monitored (Voterzeitkonstante) waits for the rest, the commitment related news. Even after receiving the first of the two missing messages he compares them with each other in content and procedure is followed according to the following rules:<ul><li>Case l) When news ident, then commitment and expenditure of the voting result.</li><li>Case 2) When news nich ident, then start second timeout TO '(TO = TO'). Time Monitored Awaiting third input message.</li><li>Case 2a) In zeitgerechtem arrival of the third message within the timeout period TO when Message 3 identical with message and Message l 2 is false, then 2of3 majority decision and issue above.</li><li>Case 2b) In zeitgerechtem arrival of the third message within the second timeout TO 'when Message 3 identical to message 2 and message l is false, then 2of3 majority decision and issue above.</li><li>Case 2c) If not arrive the same message pairs within the timeout TO or TO ', then majority decision and not issue a voting result.</li></ul>
This voting algorithm refers to a respective message triad. A voter can vote simultaneously over a plurality of triads to search for triad or channel overlap, but the sequence of commitments must on each logical channel corresponding to the input sequence of this logical channel.
In the following the sequence votes will be described. The object of the Sequence-Voter triad is the coordinated forwarding of a single input message string to the application processes each SRU. Each Sequence Voter receives generated by IOV message consequences and unites them in coordination with its neighbors arrangements acceptable to all three Sequence previous voters resulting message string. The properly lined up signals in each computer unit (SRU) identical are then passed on to the application processes to synchronize their processes.
The sequence-Voter also performs such other voter error masking. Recognizes a sequence voter but an error, so this represents a critical situation in any case. With very high probability the voter, originating the message in question is defective. Is this a bug in the SRU own, so this is halted in the wake of the 'Error Monitoring Process'.
A separate problem is the communication about the voting links. Via these channels the matching Voter each communicate a triad together. The by a voter to be processed messages are 'packaged' in voting messages and sent to the two neighbors of the same voter triad. Both physically and logically form the voting links, the only connections between the SRU's a VOTRICS system. To achieve maximum INDEPENDENCE of individual error behavior of the SRU's a VOTRICS system must be prevented from neighboring SRU ex-'s about the Voting Links errors or can import.
That brought by Leslie Lamport example of 'the lying PM' (see above article in Journal of the ACM, Vol 32 No l, pp. 52 - 78, Jan. l985) can be transmitted directly to the problem of Votens. By distorting the communication with the two Nachbarvotern could deceive her two neighbors and give two votes when votes in the absence of appropriate measures a SRU. As a result, the synchronicity of the TMR system could be lost or left in the worst case of different output by Outputvoter the system which means a violation of the fail-safe principle.
Another error event which harm in particular the effectiveness of VOTRICS system (especially the timing here), is the failure of a Voting Links. here is no countermeasure is set, the time behavior of the system deteriorates markedly in this case and the input blur the Input Message triad is the Vote fully in the Commitment blur.
The method described below solves both problems by the use of redundancy in the time domain in the transmission to the Voting Links. In the communication level, an additional mechanism is inserted, which ensures that voting messages via two different paths to reach Destination-SRU (Fig. 7). This measure resulted in a virtual doubling every Voting links (Fig. 8).
From an earlier of SRUK necessary for a full voting process messages triad namely Input message IIIk, Voting News VMik and VMjk is now, as shown in Fig. 7, a quintuple namely Input message IIIk, Voting News VMik and VMjk and in addition to the other computer unit SRUj or SRUi transmitted virtual voting News VMik' and VMjk'. No errors, applies VMik = VMik' = VMjk'.
From Figure 8, the resulting arrangement of the Voting links for the computer unit SRUK be seen. The Voter this unit therefore receives its aforementioned voting messages from the input channel ick and the voting links VLjk of the computer unit SRUj and VLIK of the computer unit SRUi and from the additional virtual Voting Links VLjk' of the computer unit SRUj over SRUi and VLIK of the computer unit SRUi over SRUj.
Lügt example SRUi so VMij applies = VMik. VMij is of SRUj to SRUK forwarded (VMik) VMik of SRUK to SRUj (VMij'); both SRUj and SRUK can find each other independently verify the conditions (VMij-VMij) or (VMik VMik') that SRUi lying. In both cases the condition is not satisfied.
The algorithm as it has been described, however, has a defect that a voting message could be distorted by the neighbor SRU from duplicating. To prevent an SRU can lie undetected when duplicating and forwarding a message voting, another protection mechanism is introduced.
Each SRU protects the voting messages produced by it with an individual, unique signature. The encoding function encode (VMnx) for all n = i, j, k different. In addition, each SRU knows only their own Codiergalorithmus. For example, ENCODEi (Vmix) only SRUi known. The decoding functions decoden (VMnx) for n = i, j, k all three SRU's are known.
Each voting message is provided from the source SRU with their individual signature. When duplicating the neighbor SRU no signature is applied. The tourist-SRU can apply to any known decoding algorithm and thus make sure that the message has suffered on the way through the neighboring SRU damage.
Example: SRUi produced VMij and VMik. Before being sent to SRU j or SRUK the signature is applied specifically for VMij: "ENCODEi (VMij)" and for VMik: "ENCODEi (VMik)". SRUj duplicated VMij and sends (without own signature apply VMik to SRUK further, simultaneously leads SRUj but also the decoding functions for your own message from (DECODEi (VMij)) SRUK receives VMik and VMik' and performs the decoding function DECODE:. (VMik) and DECODE (VMik') from; also SRUK still produces a VMij (though without own signature) and sends them where they received, with DECODE (VMij') is decoded and compared with the decrypted also VMij to SRUj.
Also, the time behavior of the system with a failed voting link is improved, that the Eingangssunschärfe no longer enters into this situation when voting in the Commitment blur. But you have to take twice the number of Voting Messages (4 instead of 2 per SRU and Commitment) and the overhead of signature encoding and decoding in purchasing.
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| DE19742918A1 | Cited by | Germany | Search report |
| EP0905623A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0905623A2 | Cited by | European Patent Office (EPO) | Search report |
| EP1148396A1 | Cited by | European Patent Office (EPO) | Search report |
| US9575859B2 | Cited by | United States of America | Applicant |
| US6574744B1 | Cited by | United States of America | Applicant |
| US5754757A | Cited by | United States of America | Search report |
| WO2013123543A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP1205834A2 | Cited by | European Patent Office (EPO) | Search report |
| EP1205834A3 | Cited by | European Patent Office (EPO) | Search report |
| DE19831720A1 | Cited by | Germany | Search report |
| WO0182010A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US4392199A | Cites | United States of America | Search report |
6 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 128686 | Austria | – | |
| 128686 | Austria | A | |
| 128686 | – | – | – |
| AT19860001286 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| EP0246218A2This record | European Patent Office (EPO) | A2 | |
| EP0246218A3 | European Patent Office (EPO) | A3 | |
| EP0246218B1 | European Patent Office (EPO) | B1 | |
| AT93332T | Austria | T | |
| DE3787045D1 | Germany | D1 | |
| ES2044975T3 | Spain | T3 |
41 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Se: european patent has lapsedLapsedEUG | EUG | EP | |
| Nl: ceased due to reaching the maximum lifetime of a patentCeasedNLV7 | NLV7 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| European patent in force as of 2002-01-01IF02 | IF02 | GB | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Se: european patent in force in swedenEAL | EAL | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Fr: translation filedET | ET | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Corresponds to:REF | REF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Designated contracting statesAK | AK | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0246218
- Publication, DOCDB
- 0246218
- Publication, EPODOC
- EP0246218
- Application
- 87890089
- Application, DOCDB
- 87890089
- Application, EPODOC
- EP19870890089
Titles6
- German
- Fehlertolerantes Datenverarbeitungssystem.
- English
- Fault-tolerant data processing system.
- French
- Système de traitement de données à tolérance de fautes.
- German
- Fehlertolerantes Datenverarbeitungssystem
- English
- Fault-tolerant data processing system
- French
- Système de traitement de données à tolérance de fautes
Classification
- CPC, 6
- G06F11/182
- G06F11/1443
- G06F11/16
- G06F11/1687
- G06F11/187
- G06F2201/83
- IPC, 2
- G06F11 16
- G06F11 18
Designated states1
- Contracting states, 1
- Sweden