Method for isolating a defective computer in a fault-tolerant multiprocessor system
4 claims: 4 independent, 0 dependent
- 1Method for isolating a computer identified as defective by non-defective computers in a computer system with at least three computers (R1, R2, R3 in Fig. 4), in which the at least three computers exchange data with one another via a system-internal communication network (KV12, KV13, KV23) and output results they have calculated to a common in/output channel (EAK) independent of the system-internal communication network, with the following steps:a) an isolation command is communicated to the defective computer,b) it is tested whether the defective computer is outputting results to the common in/output channel (EAK),c) if the defective computer is still outputting results to the common in/output channel (EAK) after a predetermined period of time after the isolation command, the non-defective computers also receive isolation commands,characterised in that the isolation command is designed as a shut-down command, wherein at least one of the non-defective computers communicates (102) the shut-down command to the defective computer and at least one of the non-defective computers tests whether the defective computer is outputting (102) results to the common in/output channel (EAK) and at least one of the non-defective computers gives the shut-down command to the non-defective computers if the defective computer is still outputting (104) results to the in/output channel (EAK) after a predetermined period of time after the shut-down command. Procédé pour l'isolation d'un calculateur identifié comme défectueux par des calculateurs non défectueux dans un système de calculateurs avec au moins trois calculateurs (C1, C2, C3 sur la figure 4), dans lequel les trois calculateurs au moins interchangent des données sur un réseau de communication interne au système (LC12, LC13, LC23) et produisent des résultats calculés par ces derniers sur un canal commun d'entrée/sortie (CES) indépendant du réseau de communication interne au système, avec les étapes suivantes : a) une commande d'isolation est transmise au calculateur défectueux,b) on vérifie si le calculateur défectueux produit des résultats sur le canal commun d'entrée/sortie (CES),c) si le calculateur défectueux produit encore des résultats sur le canal commun d'entrée/sortie (CES) après un intervalle de temps prédéfini, les calculateurs non défectueux obtiennent également les commandes d'isolation, caractérisé en ce que la commande d'isolation est réalisée en tant commande d'arrêt, dans lequel au moins l'un des calculateurs non défectueux transmet (102) au calculateur défectueux la commande d'arrêt et au moins l'un des calculateurs non défectueux vérifie si le calculateur défectueux produit (102) des résultats sur le canal commun d'entrée/sortie (CES), et au moins l'un des calculateurs non défectueux donne la commande d'arrêt aux calculateurs non défectueux, si le calculateur défectueux produit (104) toujours des résultats sur le canal commun d'entrée/sortie (CES) après un intervalle de temps prédéfini, suite à la commande d'arrêt. Verfahren zur Isolation eines als defekt identifizierten Rechners durch nicht defekte Rechner in einem Rechnersystem mit mindestens drei Rechnern (R1, R2, R3 in Fig. 4), bei dem die mindestens drei Rechner über ein systeminternes Kommunikationsnetz (KV12, KV13, KV23) miteinander Daten austauschen und von ihnen berechnete Ergebnisse an einen gemeinsamen, vom systeminternen Kommunikationsnetz unabhängigen Ein-/Ausgabekanal (EAK) ausgeben, mit folgenden Schritten: a) dem defekten Rechner wird ein Isolationskommando übermittelt,b) es wird überprüft, ob der defekte Rechner Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt,c) falls der defekte Rechner nach einer vorbestimmten Zeitspanne nach dem Isolationskommando noch immer Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt, erhalten die nicht defekten Rechner ebenfalls Isolationskommandos, dadurch gekennzeichnet, dass das Isolationskommando als Herunterfahrkommando ausgeführt wird, wobei wenigstens einer der nicht defekten Rechner dem defekten Rechner das Herunterfahrkommando übermittelt (102) und wenigstens einer der nicht defekten Rechner überprüft, ob der defekte Rechner Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt (102), und wenigstens einer der nicht defekten Rechner den nicht defekten Rechnern das Herunterfahrkommando gibt, falls der defekte Rechner nach einer vorbestimmten Zeitspanne nach dem Herunterfahrkommando noch immer Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt (104).
- 2Method according to claim 1, characterised in that the non-defective computers no longer exchange (204) data with the defective computer after it has received the shut-down command. Procédé selon la revendication 1, caractérisé en ce que les calculateurs non défectueux, après que le calculateur défectueux a obtenu la commande d'arrêt, n'échangent (204) plus de données avec ce dernier. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass die nicht defekten Rechner, nachdem der defekte Rechner das Herunterfahrkommando erhalten hat, keine Daten mehr mit diesem austauschen (204).
- 3Mehrrechnersytem, umfassend a) mindestens drei Rechner (R1, R2, R3),b) ein systeminternes Kommunikationsnetz (V1, V2, V3 in Fig. 3;KV12, KV13, KV23 in Fig. 4) zum Austausch von Daten zwischen den Rechnern,c) Rechnerschnittstellen (EA1, EA2, EA3), über die die Rechner von ihnen berechnete Ergebnisse an einen gemeinsamen Ein-/Ausgabekanal (EAK) ausgeben,d) und Identifikationsmittel (IM;IM1, IM2, IM3) zum Identifizieren eines defekten Rechners, dadurch gekennzeichnet,e) dass Kommandomittel (KM;KM1, KM2, KM3) vorhanden sind, die über das systeminterne Kommunikationsnetz (V1, V2, V3;KV12, KV13, KV23) an einen als defekt identifizierten Rechner ein Herunterfahrkommando übermitteln,f) dass Prüfmittel (PM;PM1, PM2, PM3) vorhanden sind, die überprüfen, ob der von den Identifikationsmitteln (IM;IM1, IM2, IM3) als defekt identifizierte Rechner Ergebnisse an den gemeinsamen Ein/Ausgabekanal ausgibt, und die veranlassen, dass den nicht defekten Rechnern ein Herunterfahrkommando übermittelt wird, falls der defekte Rechner nach einer vorbestimmten Zeitspanne, die mit der Übermittlung des Herunterfahrkommandos an den defekten Rechner beginnt, noch immer Ergebnisse an den gemeinsamen Ein/Ausgabekanal (EAK) ausgibt. Multicomputer system, comprising a) at least three computers (R1, R2, R3),b) a system-internal communication network (V1, V2, V3 in Fig. 3;KV12, KV13, KV23 in Fig. 4) for exchanging data between the computers,c) computer interfaces (EA1, EA2, EA3) via which the computers output results they have calculated to a common in/output channel (EAK),d) and identification means (IM;IM1, IM2, IM3) for identifying a defective computer, characterised in thate) there are command means (KM;KM1, KM2, KM3) which communicate a shut-down command to a computer identified as defective via the system-internal communication network (V1, V2, V3;KV12, KV13, KV23),f) there are testing means (PM;PM1, PM2, PM3) which test whether the computer identified by the identification means (IM;IM1, IM2, IM3) as defective is outputting results to the common in/output channel and which cause a shut-down command to be communicated to the non-defective computers if the defective computer is still outputting results to the common in/output channel (EAK) after a predetermined period of time, which begins with the communication of the shut-down command to the defective computer. Système multi-calculateurs, comprenant a) au moins trois calculateurs (C1, C2, c3),b) un réseau de communication interne au système (L1, L2, L3 sur la figure 3 ;LC12, LC13, LC23 sur la figure 4) pour l'échange de données entre les calculateurs,c) les interfaces du calculateur (ES1, ES2, ES3), sur lesquelles les calculateurs produisent des résultats calculés par ces derniers sur un canal commun d'entrée/sortie (CES),d) et des dispositifs d'identification (DI ;DI1, DI2, DI3) pour identifier un calculateur défectueux, caractérisé en ce que,e) que les dispositifs de commande (DC ;DC1, DC2, DC3) sont présents, qui transmettent une commande d'arrêt à un calculateur identifié comme défectueux sur le réseau de communication interne au système (L1, L2, L3 ;LC12, LC13, LC23),f) les dispositifs de vérification (DV ;DV1, DV2, DV3) sont présents, qui vérifient si le calculateur identifié comme défectueux par les dispositifs d'identification (DI ;DI1, DI2, DI3) produit des résultats sur un canal commun d'entrée/sortie, et qui provoquent la transmission d'une commande d'arrêt aux calculateurs non défectueux, si le calculateur défectueux, après un intervalle de temps prédéfini, qui commence avec la transmission de la commande d'arrêt au calculateur défectueux, produit toujours des résultats sur le canal commun d'entrée/sortie (CES).
- 4Mehrrechnersystem nach Anspruch 3, dadurch gekennzeichnet, doss das systeminterne Kommunikationsnetz (V1, V2, V3;KV12, KV13, KV23) so ausgelegt ist, dass die Rechner untereinander vollständig durch voneinander physikalisch unabhängige Leitungen vermascht sind. Multicomputer system according to claim 3, characterised in that the system-internal communication network (V1, V2, V3;KV12, KV13, KV23) is designed in such a way that the computers are fully meshed among one another by lines which are physically independent of one another. Système multi-calculateurs selon la revendication 3, caractérisé en ce que le réseau de communication interne au système (L1, L2, L3 ;LC12, LC13, LC23) est étudié de sorte que les calculateurs soient maillés les uns avec les autres totalement par des liaisons indépendantes physiquement les unes des autres.
Independent claims4
20 paragraphs, as filed
The invention relates to a method for isolating an identified as defective Computer in a fault tolerant multiprocessor system according to the preamble of claim 1. The invention further relates to a fault-tolerant Multicomputer system according to the preamble of claim 3rd
Fault-tolerant multiprocessor systems - mostly 2-of-3 computer systems Are used to control especially those processes where particularly high demands in terms of security and availability the controller are provided. Examples of such processes include the Assurance of railway infrastructure for railway or monitoring Nuclear power plants. A computer system is called fault tolerant if even in the presence of a limited number of hardware and / or Software errors, the system still works. From such Data processing equipment can also request that they rest with the required for process control devices according to the "fail-safe" principle cooperate. This means that even with a total loss the data processing system of the process under any circumstances in a dangerous condition may pass.
A method according to the preamble of claim 1 is known from WO-A1-9203787 known, a hardware comparator arrangement provided is that a shutdown of a defective computer of a multicomputer system causes. If a defective computer does not shut down, causing the flawless computer switching off the Mehrrechnersystms.
EP-B1-0 246 218 is not isolation, but before a Isolation necessary identification of a faulty computer in a redundant data processing system described. The known Data processing system consists of several computer nodes, which in turn More than computer systems - preferably as a 2-of-3 computer systems - are executed. The nodes are over serial point-to-point connections interconnected. The computers within each node are also fully meshed with each other. The a Majority decision required reconciliation of each of the Computers within a node supplied results ( "Voting") will not performed centrally, but distributed to the individual computers.
Furthermore, from DE-A1-41 35 640 a 2-from-3-computer system known in the computer also has its own control bus to each other can exchange data. The computers communicate with the process a thereof independent I / O data bus. If a computer is defective is identified, cause there the two non-defective computers that The data port is blocked to the I / O bus. Depending on the nature of the defect, it may however happen that the non-defective computers such engagement in the data port of the defective computer fails. It is then possible that the defective computer continues to output erroneous data to the I / O bus. If another computer is broken and also errored data output to the I / O bus, so these data could match by chance. A receiver could these two results then because of their maintain compliance for properly, so they accept and pursue tax acts that result in a non-safe state could.
Finally, from DE-C2-32 08 573 a selection device for a Three computer system is known in which an identified as defective computer via a relay switch from I / O channel is irreversibly separated. Of the defective computer can there - as well as in the multiprocessor system according to the abovementioned WO-A1-9203787 - after restarting again not without Intervention of an operator can be integrated into the system. These Solution is relatively expensive since the relay switch dedicated to each Computer system needs to be developed. Further, control lines for provide control of the relay switch.
It is therefore an object of the invention to provide a method by which Help an identified defective computers in a multiprocessor system effectively taking into account the "fail-safe" principle of not the may be defective computers isolated. The process should under no Circumstances lead to unsafe process conditions. In addition to the Method does not use additional hardware such as relay switch require.
The invention solves this problem by the teaching specified in claim. 1 Since the invention of the defective computer is prompted shut down, a subsequent re-integration of the computer - unless a reboot is successful - even without the intervention of an operator possible. System security is ensured by the fact that not Shutdown defective computer even if the defective computer the Shutdown command has not complied with successfully. namely, if the defective computer to spite shutdown commands further results outputs the input / output channel, then only by a shutdown of the non-defective computers are reliably prevented it up to the aforementioned random match results from two defective computers and thereby comes to an unsafe condition.
The task of the defective computer a shutdown command to forward is taken by the non-defective computers. The non Check defective computer even if the defective computer results to the common I / O channel outputs. Further, the drive is not defective Computer itself down if the defective computer after a predetermined period of time after the shutdown command still Results to the common I / O channel outputs. This involves the Computer system in a safe state, because it is - as in safe Computer systems usual - provided that a safe output always must involve two computers. A single computer alone can Under no circumstances effectively in the process to be controlled intervention. Additional hardware devices - like the Multicomputer system according to the above-mentioned WO-A1-9203787 - are unnecessary.
In an advantageous embodiment according to claim 2 do not represent the defective computer on the exchange of data with the defective computer, after it has received the shutdown command. This is the defective computer signaled again that it all the output to adjust common I / O channel and shut down.
The invention is described with reference to embodiments and the Drawings in detail. Show it:<sl><li>Fig. 1: A representation of the method according to claim 1 in the form of a flow chart,</li><li>Fig. 2: A representation of the method according to claim 3 in the form of a flow chart,</li><li>Fig. 3: A schematic representation of one embodiment of a Multicomputer system according to the invention of claim 4,</li><li>Fig. 4: A schematic representation of another embodiment a multi-computer system according to the invention of claim 4.</li></sl>
Fig. Figure 1 illustrates the inventive method 100 according to claim 1 in the form of of a flow chart. A multi-computer system in which the method 100 may be advantageously applied, Fig. 4. This multi-computer system consists in this example of three computers R1, R2, R3, via a system internal communication network are intermeshed, ie each Computer can have its own communication link with each Replacing other computer data. Thus, between the computers R1 and R2 communication connection KV12, between the computers R2 and R3 communication connection KV23 and between the computers R1 and R3 communication connection KV13. The exchange of data between the multicomputer system, and the process to be controlled via a common, independent of the system-internal communication network I / O channel EAK.
In a first step 101, by the inventive method 100 a defective computer identified. In general, this identification is performed characterized in that the three computers R1, R2, R3 via the intrinsic Communication network, the calculated results of them with each other change. If all the results agree with each other, so it goes System assumes that no host is defective. however soft the result a computer of the results of the other two computers from, so is this result as flawed and therefore the corresponding computer as defective viewed. Because of the complete meshing of the computer each other is always a clear allocation of results ensured so that the defective computer can be clearly identified. A particularly advantageous method for error identification is already in the cited patent EP-B1-0 246 218 describes, on to this Reference is made.
In a second step 102, in accordance with the invention to be defective identified computer a shutdown command received. This Command can, for example, by external command means are, as in the description of the invention Multicomputer system is described in detail below. Especially then However, if the error ID decentralized, ie distributed to all computers, is performed, it is advisable, broken this command not to Computers or start from one of the non-defective computers allow. Under shutdown is understood here that the computer be concerned Application program, as well as its operating system with all Interface drivers properly terminated. Such proper Termination includes, for example conducting diagnostics and Storing data on a non-volatile carriers. After this Shutdown, the computer will not back more, either through the I / O channel still on the system internal communication network. If no errors were detected and it allows the security concept, will the computer then rebooted. This typically includes extensive hardware testing a with.
In a next step 103 it is checked whether the detected as defective computer continue outputting results to the common I / O channel. This amounts to a review of whether the defective computer the Shutdown command is actually complied with. As already mentioned, a computer can after shutdown no issues to the common I / O channel make more. yet Can such demonstrate expenditures, then it can be assumed that the defect such is severe, that a shutdown was no longer possible. If he makes computer output to the input / output channel, can the I / O channel be even detected. Again, it is again possible, this task by external test equipment or defective of not the carry computers even allow.
If it is found during this check that the broken computer to a predetermined period still issues to the common input / output channel makes, so go the non-defective computers in one step 104 down to. This shutdown will of external test equipment are caused or of the non-defective computers themselves. By Shutdown is, as explained above, the system to a safe state over because the defective computer can alone make any expenditure on the side of expenditure receiving recipient an effect could unfold. That task must always - in the case of a 2-of-3 computer system - Correspond at least two results.
If on the other hand found in this test 103 that the defective computer after a predetermined period of time no issues to the common makes I / O channel more, so go the non-defective computers in the of conventional 2-of-3 computer systems known manner with their Computing activity continued. The predetermined time period should be at least as long as be like a broken computer needs to shut down. Otherwise could shut down the non-defective computers, although the defective Computer is shutting down successfully and thus a dangerous condition not may occur.
Another embodiment of the method according to Claim 3 is shown in Fig. 2. Steps 201 and 202 correspond to the Steps 101 to 102. In addition to the steps shown in Fig. 1 is here However, provided that, in a step 204, the non-defective computers of from the data exchange with the defective computer via the Setting the internal system communications network. This is the defective Computer again signaled that it is no longer as an equal calculator is recognized in the system and should therefore shut down. The non defective computers can exchange data in each case after the Setting the transmission of the shutdown commands 202 or, as in shown Fig. 2, in step 203, do this depends on whether the defective Calculator adjusts on its own data exchange. The additional Step 204 reduces the likelihood that the defective computer not shutting down and therefore to a shutdown and the not defective computer in step 207 comes.
An embodiment of an inventive multi-computer system is in shown FIG. 3. The multiprocessor system includes three computer R1, R2, R3, the via input / output ports EA1, EA2, EA3 with a common input / output channel EAK are connected. According to the invention are further provided Identification means IM for identifying defective computers and Command means KM to issue shutdown commands. This means are connected to the computer via a system internal communication network, comprising the compounds V1, V2 and V3. In this way, the Identification means IM and the command means KM with the computers R1, R2, R3 communicate. In addition, test equipment PM are present, both with the I / O channel EWC as well as with the three computers R1, R2, R3 are connected. These agents have the task of reviewing whether the of the identification means as defective recognized calculator results to the common I / O channel outputs. If the test equipment to determine that the defective computer after a predetermined period still cause outputting results to the common input / output channel, the test means that the non-defective computers shut down and thus a safe state is achieved.
In the embodiment shown in Fig. 4, the Identification means IM, the command means KM and test equipment not PM externally arranged, but divided among the three computers. Preferably is it in this means IM1 ... IM3, KM1 KM3 ... and PM1 PM3 to ... Software modules, which take over the corresponding functions.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| DE4135640A | Cites | Germany |
| WO9203787A | Cites | World Intellectual Property Organization (WIPO) |
8 members in 4 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19740136 | Germany | A | |
| 19740136 | Germany | A | |
| 19740136 | Germany | – | |
| 19740136 | – | – | – |
| DE1997140136 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP0902369A2 | European Patent Office (EPO) | A2 | |
| DE19740136A1 | Germany | A1 | |
| EP0902369A3 | European Patent Office (EPO) | A3 | |
| EP0902369B1This record | European Patent Office (EPO) | B1 | |
| AT230132T | Austria | T | |
| ATE230132T1 | Austria | T1 | |
| DE59806695D1 | Germany | D1 | |
| ES2185131T3 | Spain | T3 |
50 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| ExpiryMK07 | MK07 | AT | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Patent ceasedCeasedPL | PL | CH | |
| Be: lapsedLapsedBERE | BERE | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fr: translation filedET | ET | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| Corresponds to:REF | REF | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designation fees paidAT BE CH DE DK ES FI FR GB IT LI NL PT SEAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0902369
- Publication, DOCDB
- 0902369
- Publication, EPODOC
- EP0902369
- Application
- 98440187
- Application, DOCDB
- 98440187
- Application, EPODOC
- EP19980440187
Titles3
- German
- Verfahren zur Isolation eines defekten Rechners in einem fehlertoleranten Mehrrechnersystem
- English
- Method for isolating a defective computer in a fault-tolerant multiprocessor system
- French
- Méthode pour l'isolation d'un ordinateur défectueux dans un système à multiprocesseur à tolérance de fautes
Classification
- CPC, 3
- G06F11/181
- G06F11/0796
- G06F11/182
- IPC, 4
- G06F11 00
- G06F11 16
- G06F11 18
- G06F15 16
Designated states14
- Contracting states, 14
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Italy
- Liechtenstein
- Netherlands (Kingdom of the)
- Portugal
- Sweden
