EP0902369B1

Method for isolating a defective computer in a fault-tolerant multiprocessor system

Abstract

This record has no abstract on file.

EP0902369B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 28 August 2018, 8.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

4 claims: 4 independent, 0 dependent

  1. 1
    Method for isolating a computer identified as defective by non-defective computers in a computer system with at least three computers (R1, R2, R3 in Fig. 4), in which the at least three computers exchange data with one another via a system-internal communication network (KV12, KV13, KV23) and output results they have calculated to a common in/output channel (EAK) independent of the system-internal communication network, with the following steps:a) an isolation command is communicated to the defective computer,b) it is tested whether the defective computer is outputting results to the common in/output channel (EAK),c) if the defective computer is still outputting results to the common in/output channel (EAK) after a predetermined period of time after the isolation command, the non-defective computers also receive isolation commands,characterised in that the isolation command is designed as a shut-down command, wherein at least one of the non-defective computers communicates (102) the shut-down command to the defective computer and at least one of the non-defective computers tests whether the defective computer is outputting (102) results to the common in/output channel (EAK) and at least one of the non-defective computers gives the shut-down command to the non-defective computers if the defective computer is still outputting (104) results to the in/output channel (EAK) after a predetermined period of time after the shut-down command. Procédé pour l'isolation d'un calculateur identifié comme défectueux par des calculateurs non défectueux dans un système de calculateurs avec au moins trois calculateurs (C1, C2, C3 sur la figure 4), dans lequel les trois calculateurs au moins interchangent des données sur un réseau de communication interne au système (LC12, LC13, LC23) et produisent des résultats calculés par ces derniers sur un canal commun d'entrée/sortie (CES) indépendant du réseau de communication interne au système, avec les étapes suivantes : a) une commande d'isolation est transmise au calculateur défectueux,b) on vérifie si le calculateur défectueux produit des résultats sur le canal commun d'entrée/sortie (CES),c) si le calculateur défectueux produit encore des résultats sur le canal commun d'entrée/sortie (CES) après un intervalle de temps prédéfini, les calculateurs non défectueux obtiennent également les commandes d'isolation,    caractérisé en ce que la commande d'isolation est réalisée en tant commande d'arrêt, dans lequel au moins l'un des calculateurs non défectueux transmet (102) au calculateur défectueux la commande d'arrêt et au moins l'un des calculateurs non défectueux vérifie si le calculateur défectueux produit (102) des résultats sur le canal commun d'entrée/sortie (CES), et au moins l'un des calculateurs non défectueux donne la commande d'arrêt aux calculateurs non défectueux, si le calculateur défectueux produit (104) toujours des résultats sur le canal commun d'entrée/sortie (CES) après un intervalle de temps prédéfini, suite à la commande d'arrêt. Verfahren zur Isolation eines als defekt identifizierten Rechners durch nicht defekte Rechner in einem Rechnersystem mit mindestens drei Rechnern (R1, R2, R3 in Fig. 4), bei dem die mindestens drei Rechner über ein systeminternes Kommunikationsnetz (KV12, KV13, KV23) miteinander Daten austauschen und von ihnen berechnete Ergebnisse an einen gemeinsamen, vom systeminternen Kommunikationsnetz unabhängigen Ein-/Ausgabekanal (EAK) ausgeben, mit folgenden Schritten: a) dem defekten Rechner wird ein Isolationskommando übermittelt,b) es wird überprüft, ob der defekte Rechner Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt,c) falls der defekte Rechner nach einer vorbestimmten Zeitspanne nach dem Isolationskommando noch immer Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt, erhalten die nicht defekten Rechner ebenfalls Isolationskommandos,    dadurch gekennzeichnet,   dass das Isolationskommando als Herunterfahrkommando ausgeführt wird, wobei wenigstens einer der nicht defekten Rechner dem defekten Rechner das Herunterfahrkommando übermittelt (102) und wenigstens einer der nicht defekten Rechner überprüft, ob der defekte Rechner Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt (102), und wenigstens einer der nicht defekten Rechner den nicht defekten Rechnern das Herunterfahrkommando gibt, falls der defekte Rechner nach einer vorbestimmten Zeitspanne nach dem Herunterfahrkommando noch immer Ergebnisse an den gemeinsamen Ein-/Ausgabekanal (EAK) ausgibt (104).
  2. 2
    Method according to claim 1, characterised in that the non-defective computers no longer exchange (204) data with the defective computer after it has received the shut-down command. Procédé selon la revendication 1, caractérisé en ce que les calculateurs non défectueux, après que le calculateur défectueux a obtenu la commande d'arrêt, n'échangent (204) plus de données avec ce dernier. Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass die nicht defekten Rechner, nachdem der defekte Rechner das Herunterfahrkommando erhalten hat, keine Daten mehr mit diesem austauschen (204).
  3. 3
    Mehrrechnersytem, umfassend a) mindestens drei Rechner (R1, R2, R3),b) ein systeminternes Kommunikationsnetz (V1, V2, V3 in Fig. 3;KV12, KV13, KV23 in Fig. 4) zum Austausch von Daten zwischen den Rechnern,c) Rechnerschnittstellen (EA1, EA2, EA3), über die die Rechner von ihnen berechnete Ergebnisse an einen gemeinsamen Ein-/Ausgabekanal (EAK) ausgeben,d) und Identifikationsmittel (IM;IM1, IM2, IM3) zum Identifizieren eines defekten Rechners, dadurch gekennzeichnet,e) dass Kommandomittel (KM;KM1, KM2, KM3) vorhanden sind, die über das systeminterne Kommunikationsnetz (V1, V2, V3;KV12, KV13, KV23) an einen als defekt identifizierten Rechner ein Herunterfahrkommando übermitteln,f) dass Prüfmittel (PM;PM1, PM2, PM3) vorhanden sind, die überprüfen, ob der von den Identifikationsmitteln (IM;IM1, IM2, IM3) als defekt identifizierte Rechner Ergebnisse an den gemeinsamen Ein/Ausgabekanal ausgibt, und die veranlassen, dass den nicht defekten Rechnern ein Herunterfahrkommando übermittelt wird, falls der defekte Rechner nach einer vorbestimmten Zeitspanne, die mit der Übermittlung des Herunterfahrkommandos an den defekten Rechner beginnt, noch immer Ergebnisse an den gemeinsamen Ein/Ausgabekanal (EAK) ausgibt. Multicomputer system, comprising a) at least three computers (R1, R2, R3),b) a system-internal communication network (V1, V2, V3 in Fig. 3;KV12, KV13, KV23 in Fig. 4) for exchanging data between the computers,c) computer interfaces (EA1, EA2, EA3) via which the computers output results they have calculated to a common in/output channel (EAK),d) and identification means (IM;IM1, IM2, IM3) for identifying a defective computer, characterised in thate) there are command means (KM;KM1, KM2, KM3) which communicate a shut-down command to a computer identified as defective via the system-internal communication network (V1, V2, V3;KV12, KV13, KV23),f) there are testing means (PM;PM1, PM2, PM3) which test whether the computer identified by the identification means (IM;IM1, IM2, IM3) as defective is outputting results to the common in/output channel and which cause a shut-down command to be communicated to the non-defective computers if the defective computer is still outputting results to the common in/output channel (EAK) after a predetermined period of time, which begins with the communication of the shut-down command to the defective computer. Système multi-calculateurs, comprenant a) au moins trois calculateurs (C1, C2, c3),b) un réseau de communication interne au système (L1, L2, L3 sur la figure 3 ;LC12, LC13, LC23 sur la figure 4) pour l'échange de données entre les calculateurs,c) les interfaces du calculateur (ES1, ES2, ES3), sur lesquelles les calculateurs produisent des résultats calculés par ces derniers sur un canal commun d'entrée/sortie (CES),d) et des dispositifs d'identification (DI ;DI1, DI2, DI3) pour identifier un calculateur défectueux,    caractérisé en ce que,e) que les dispositifs de commande (DC ;DC1, DC2, DC3) sont présents, qui transmettent une commande d'arrêt à un calculateur identifié comme défectueux sur le réseau de communication interne au système (L1, L2, L3 ;LC12, LC13, LC23),f) les dispositifs de vérification (DV ;DV1, DV2, DV3) sont présents, qui vérifient si le calculateur identifié comme défectueux par les dispositifs d'identification (DI ;DI1, DI2, DI3) produit des résultats sur un canal commun d'entrée/sortie, et qui provoquent la transmission d'une commande d'arrêt aux calculateurs non défectueux, si le calculateur défectueux, après un intervalle de temps prédéfini, qui commence avec la transmission de la commande d'arrêt au calculateur défectueux, produit toujours des résultats sur le canal commun d'entrée/sortie (CES).
  4. 4
    Mehrrechnersystem nach Anspruch 3, dadurch gekennzeichnet, doss das systeminterne Kommunikationsnetz (V1, V2, V3;KV12, KV13, KV23) so ausgelegt ist, dass die Rechner untereinander vollständig durch voneinander physikalisch unabhängige Leitungen vermascht sind. Multicomputer system according to claim 3, characterised in that the system-internal communication network (V1, V2, V3;KV12, KV13, KV23) is designed in such a way that the computers are fully meshed among one another by lines which are physically independent of one another. Système multi-calculateurs selon la revendication 3, caractérisé en ce que le réseau de communication interne au système (L1, L2, L3 ;LC12, LC13, LC23) est étudié de sorte que les calculateurs soient maillés les uns avec les autres totalement par des liaisons indépendantes physiquement les unes des autres.