EP0757315A2

Fail-fast, fail-functional, fault-tolerant multiprocessor system

Abstract

A multiprocessor system includes a number of sub-processor systems, each substantially identically constructed, and each comprising a central processing unit (CPU), and at least one I/O device, interconnected by routing apparatus that also interconnects the sub-processor systems. A CPU of any one of the sub-processor systems may communicate, through the routing elements, with any I/O device of the system, or with any CPU of the system. Communications between I/O devices and CPUs is by packetized messages. Interrupts from I/O devices are communicated from the I/O devices to the CPUs (or from one CPU to another CPU) as message packets. CPUs and I/O devices may write to, or read from, memory of a CPU of the system. Memory protection is provided by an access validation method maintained by each CPU in which CPUs and/or I/O devices are provided with a validation to read/write memory of that CPU, without which memory access is denied.

EP0757315A2, drawing sheet 1
Sheet 1 of 31

Term

Term ended

Projected expiry passed 6 June 2016, 10.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

1 claim: 1 independent, 0 dependent

  1. 1
    A central processor unit, comprising:a memory for storing instructions and data;a pair of processors operating in lock-step synchronism with each other to execute each instruction of an instruction stream and to periodically write identical N-bit data words comprising first and second portions to the memory at substantially the same moment in time;first and second interface elements communicating the N-bit data words from corresponding ones of the pair of processors to the memory such that the first portion of the N-bit data word from a one of the pair of processors is written to the memory by the first interface unit together with the second portion of the N-bit data from the second interface element;the first interface unit including means for receiving comparing the second portion of the N-bit data word from the second interface unit with the second portion of the N-bit data word received from the corresponding one of the pair of processors to assert an error signal is a miscompare is detected;and the second interface unit including means for receiving comparing the first portion of the N-bit data word from the first interface unit with the first portion of the N-bit data word received from the corresponding one of the pair of processors to assert an error signal is a miscompare is detected.