Control of a fault-tolerant system with two semiconductor assemblies

A control system with two semiconductor modules and a standby device ensures uninterrupted operation and high availability by enabling a two-of-three fault-tolerant configuration, addressing space and complexity issues in existing systems.

DE102024209152A1Pending Publication Date: 2026-02-05SIEMENS MOBILITY GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE102024209152
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-30
Filing Date
2024-09-24
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing fault-tolerant systems require multiple semiconductor modules for redundancy, leading to increased space requirements and complexity, and fail to ensure uninterrupted operation during repairs or failures, especially when a second fault occurs.

Method used

Implement a control system using two semiconductor modules, each with two independent data processing devices, and a fourth device in a standby mode to take over tasks in case of failure, allowing a two-of-three configuration for fault-tolerant operation with reduced components and space.

Benefits of technology

Enables uninterrupted, highly available, and reliable operation even with a single failure, reducing the need for spare parts and space, while maintaining high reliability and safety standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method (100a, 100b) for controlling a fault-tolerant system (10), in which parameters for controlling the system (10) are determined (102) by means of three data processing devices (18, 20, 22) distributed across two single-chip systems (12, 14). Based on a comparison of the respective determined parameters (102), matching parameters are then identified (104). Furthermore, the system (10) is controlled based on the matching parameters (106).
Need to check novelty before this filing date? Find Prior Art

Description

The invention relates to a method for controlling a fault-tolerant system, to a control system for carrying out the method, to a computer program and to a computer-readable medium.In a safety-critical system, such as, for example, in a traffic guidance system or an emergency management system, fault-tolerant control systems with high availability and high reliability are required. In order to be able to provide safe and highly available control systems, it is already known to have three mutually independent semiconductor modules arranged separately perform the same control tasks and then to compare the respectively determined results. On the basis of the comparison, in the event of a fault in one of the three data processing devices, both this fault can be detected and a correction of this fault can be carried out on the basis of a majority decision. The safety-critical system is then controlled with the aid of a majority decision on the basis of matching results of the three data processing devices. Such a configuration of three data processing devices for controlling a fault-tolerant system is already known as a two-of-three configuration in the sense of the IEC 61508 standard or in English usage under the designation "triple modular redundancy".Furthermore, in the event of a fault, a defective one of the three separate semiconductor assemblies can be replaced. Meanwhile, the system is controlled uninterruptedly on the basis of a two-by-two configuration in the sense of the IEC 61508 by means of the two remaining fault-free data processing devices. This configuration is known in English as "dual modular redundancy". In this configuration, a fault can be detected, but in the event of a fault, fault-tolerant continued operation of the system is not possible.In the event of a fault, a two-of-two configuration has been provided first. In principle, therefore, repair and / or replacement of a defective or defective semiconductor assembly of the three separate semiconductor assemblies mentioned is required promptly after the fault case has been detected. If a further fault or defect occurs on one of the remaining semiconductor assemblies of the three separate semiconductor assemblies during the fault case mentioned, the system is not sufficiently available. To prevent this, a rapid replacement of a failed or defective semiconductor device must be provided. This is usually made possible by virtue of the fact that a sufficient number of replacement components are stored. Under certain circumstances, these replacement components must regularly be checked for their state so that a defective semiconductor assembly is not replaced by a further defective semiconductor assembly. Furthermore, there is an increased space requirement in the case of three separate semiconductor assemblies. It is indeed already known to integrate a plurality of data processing devices independent of one another on a semiconductor module and / or a system on chip. However, for fault-tolerant control of the system and the majority decision explained above, three data processing devices independent of one another are required on separate semiconductor modules. A reduction in the number of held semiconductor modules therefore led to a dilemma in the event of a fault, since a lack-free intact data processing device may be affected by a replacement of a semiconductor module provided with two data processing devices. In this case, uninterrupted continued operation during a repair operation of the fault-tolerant system would then no longer be possible even on the basis of a two-of-two configuration according to IEC 61508.It is an object of the invention to realize a fault-tolerant system with a high availability on the basis of two replaceable semiconductor modules. In particular, this is intended to enable uninterrupted continued operation of the system during a repair operation.This object is achieved by a method having the features of claim 1.Furthermore, the object of the invention is to provide a control device for carrying out the method according to the invention.This object is achieved by a control device having the features of the subordinate present claim.Furthermore, the invention is based on the object of specifying a computer program and a computer-readable medium.These objects are achieved by a computer program having the features of the subordinate claim 15 and by a computer-readable medium having the features of the subordinate claim 15.Advantageous refinements are the subject matter of dependent dependent claims in each case.The method according to the invention for controlling a fault-tolerant system provides that parameters for controlling the system are determined in each case by means of three data processing devices distributed over two single-chip systems.In the present context, a single-chip system is to be understood as meaning an electronic system which is arranged on a common semiconductor substrate. In the present case, at least two integrated circuits which are embodied independently of one another are arranged on the common semiconductor substrate. Each of the two system units on a chip expediently has two integrated circuits in each case, which are designed as a data processing device. In particular, two data processing devices of a system on a chip are designed independently of one another. The data processing device can be, for example, a microcontroller, a processor or another programmable hardware component. The data processing device is expediently configured to read in, receive, store, write, transmit and / or manage data. In the preferred application, the data processing device has a semiconductor memory for the purpose of storing data. Preferably, each of the data processing devices is configured to control the fault tolerant system. Instead of the three data processing devices distributed over two single-chip systems, two semiconductor modules can be provided, each of which has two data processing devices which are embodied separately and can be operated independently of one another. Of these four data processing devices, at least three can be used to carry out the method according to the invention. Single-chip systems each having, by way of example, two independent data processing devices offer improved properties in terms of efficiency in the individual application. Nevertheless, the present invention can also be carried out in an alternative manner with the two semiconductor assemblies mentioned, which each have two data processing devices which are separate and can be operated independently of one another.Furthermore, the method according to the invention provides that matching parameters are determined on the basis of a comparison of the respectively determined parameters. The system is then controlled based on the matching parameters. In this way, a two-of-three configuration in the sense of the standard IEC 61508 can be implemented with only two replaceable semiconductor assemblies at low cost. The mentioned two-of-three configuration is therefore referred to in English as "triple modular redundancy". This enables a fail-safe and highly fault-tolerant system to be realized on the basis of two replaceable semiconductor modules. The system can thereby be operated energy-efficiently. Advantages of single-chip systems, such as high availability, low electrical power, low risk of failure, low-cost production, a compact arrangement and high reliability, can be exploited in the control of the system.An advantageous embodiment variant provides that a fourth data processing device is provided, which is arranged on one of the two semiconductor modules and / or one of the two single-chip systems and by means of which, in the event of a fault in one of the three mentioned operation-guiding data processing devices, a control task of the defective ones of the three operation-guiding data processing devices is taken over. As a result, a fault-tolerant system with a particularly high availability can be provided. In comparison with previously customary two-of-three configurations, the system can continue to be operated in a two-of-three configuration despite failure of a data processing device. A majority decision in which at least two of three of the determined parameters must match to enable fail-safe control of the system can be provided quickly even in the event of failure of one of the three operational data processing devices. Furthermore, it can be avoided in this way that the control of the system is realized solely on the basis of only two data processing devices. The fourth data processing device further makes it possible to maintain high reliability up to a replacement of the defective data processing device. In the preferred application, a number of spare parts to be kept available by an operator can be kept small. If one of the operation-performing data processing devices fails, the fourth data processing device can replace this defective data processing device in a cost-effective manner without the need to replace an entire semiconductor module. Further, the above two-out-of-three configuration can be further maintained. Depending on a time of failure or occurrence of failure, it may even be considered to omit replacement of the defective data processing apparatus. In particular, this may be the case when a life expectancy of the remaining data processing devices is sufficiently high and a failure probability is sufficiently low. Alternatively, repair of a defective system-on-chip or a defective semiconductor package may be performed. During repair, which is usually quick to carry out, the system falls back to a two-by-two configuration, since during the repair process an entire semiconductor assembly or an entire system on chip is replaced, which each has two data processing devices in an inextricable manner. Due to a shortness of a period of the repair process, a risk of a further error within this period can be neglected. Once repair has been carried out and / or after replacement of the defective semiconductor assembly has been carried out, all four units are ready again and the system can be operated again in a two-of-three configuration with an additional data processing device as a hot spare.In the event of a fault, the fourth data processing device can be used to assume operation of a defective data processing device. This allows a safe and still highly available control to be provided, even though an operation-guiding data processing device is no longer available for the operation of the system. In the event of a further fault, therefore, a safe and highly available control of a system, preferably in a two-of-three configuration, is still possible. Thus, only a third error would lead to an interruption of the operation in the control. In addition, in the present manner, repair without interrupting safe operation can be provided with only two physically exchangeable units (semiconductor modules).A further advantageous refinement provides that the fourth data processing device arranged on one of the two single-chip systems is operated in a standby operating state. Starting from the standby operating state, the fourth data processing device can be used at any time and with a transfer time which is at most short for the purpose of controlling the system. In the event of a fault in one of the three operational data processing devices, control tasks of the defective data processing device can be quickly and reliably performed by the fourth data processing device. Preferably, in the fault case mentioned, the fourth data processing device can perform control tasks of the defective data processing device without an operational interruption of the system.In an advantageous embodiment variant, the fourth data processing device is operated in a passive standby operating state. In the present context, the passive standby operating state is to be understood as an operating state in which the data processing device, without itself carrying out control tasks, is kept up-to-date by means of a background update for the purpose of controlling the system. In this way, the relevant data processing device is predominantly brought into agreement with the operation-carrying data processing devices during normal operation without a fault in the standby operating state. Preferably, in the passive operating state, a correspondence of the fourth data processing device with the operation-guiding data processing devices is achieved, which is at least 80% and preferably at least 90%. This makes it possible to process the fourth data processing device in the event of a fault with little time in such a way that it can be used quickly as an operating data processing device.In a further advantageous embodiment, a memory content of the fourth data processing device is synchronized with at least a part of the memory contents of the three operation-carrying data processing devices in the passive standby operating state. For this purpose, known methods relating to a memory check and / or extensions of these known methods are suitable, for example. The fourth data processing device can thereby be prepared for assuming control tasks at low cost during normal operation. As a result, low energy consumption of the fourth data processing device in the passive standby operating state can be achieved. Furthermore, a significant deterioration of a failure probability of the fourth data processing device due to the passive standby operating state can be counteracted.Expediently, in the event of a fault, a transfer time is provided for the fourth data processing device operated in the passive standby operating state. During this transfer time, the memory contents of the fourth data processing device are preferably completely synchronized with the memory contents of the three operational data processing devices without any shortage. The fourth data processing device can be used quickly and reliably in this way for the purpose of assuming control tasks of the defective data processing device. The fourth data processing device can thus be used as an operating data processing device at low cost instead of the defective data processing device. In the preferred application, in this way, in particular also in the event of a fault in an operation-carrying data processing device, uninterrupted and still highly available operation of the system is made possible.In an alternative advantageous embodiment variant, the fourth data processing device is operated in an active standby operating state.In the present context, an active standby operating state is to be understood as meaning an operating state in which the data processing device concerned carries out the same control tasks as the three operation-carrying data processing devices. However, during normal operation of the system, the parameters determined by means of the data processing device concerned are ignored in the comparison of the parameters for transmitting matches. In this way, a complete synchronization of the data processing device concerned with the three operational data processing devices can be achieved. In particular, a memory content of the relevant data processing device can always be completely synchronized with the memory contents of the operation-guiding data processing devices. Control tasks of a defective data processing device can therefore be taken over directly by the defective data processing device. Furthermore, during normal operation of the system, a majority decision can be made for the purpose of controlling the system without any possible parity arising. With the aid of the active standby operating state, in the preferred application, even a short transition time can be dispensed with.In the event of a fault in one of the three operational data processing devices, a system on chip of the two system on chip having the defective data processing device is preferably replaced by a non-defective system on chip during operation of the system. As a result, a safety-critical application can also be controlled without interruption using two hardware modules. A high availability of the system can thus be provided at low cost. Even in the event of a failure of an operation-guiding data processing device, the system can continue to be operated with a high level of availability. Furthermore, a high safety requirement level can be achieved in a cost-effective manner.Particularly preferably, during a replacement of the deficient one-chip system with a deficiency-free one-chip system, a control of the system is realized solely by means of two data processing devices of the remaining one-chip system of the two one-chip systems. As a result, the system can also be continued to operate in a sufficiently reliable and reliable manner during the replacement of a semiconductor module, which can have two separate data processing devices instead of the system on chip in an alternative manner. With the aid of the two data processing devices of the remaining system on a chip, the control of the system on the basis of a two-of-two configuration can continue to be operated in the sense of the IEC 61508. Such a two-of-two configuration is therefore referred to in English as "double modular redundancy". As a result, an error can be detected with the aid of a comparison of the two parameters determined by means of the two other data processing devices. In contrast, this error in the two-of-two configuration cannot be either corrected or tolerated by a majority decision as in the case of a two-of-three configuration. After the defective one-chip system has been replaced by the defective one-chip system, one of the two data processing devices of the new defective one-chip system can be prepared quickly and economically for the purpose of controlling the system. By way of example, a storage content of the two operational computing devices may be synchronized with a storage content of one of the two newly-to-join computing devices. After sufficient guarantee of a deficiency-free operation of the newly added data processing device, the latter can assume the same control tasks as the operation-guiding data processing devices. Then, for the purpose of restoring a two-of-three configuration in the sense of the IEC 61508, the newly added data processing device can be included in a vote concerning the majority decision. The remaining newly added data processing device of the deficiency-free system-on-chip is then advantageously operated in one of the previously described standby operating modes.Conveniently, a defective one of the three operational data processing devices is identified in that the parameter determined by the defective data processing device is different from parameters determined by two remaining ones of the three operational data processing devices. The defective data processing device can thereby be identified reliably and quickly. Targeted replacement of a defective semiconductor assembly with a system on chip or, for example, two separate independent data processing devices is thereby possible in a reliable manner.Preferably, the parameters for controlling the system are each determined concurrently by means of the three operational data processing devices distributed over the two single-chip systems. Concurrent determination is to be understood in the present case in the sense of informatives, wherein tasks, calculations, instructions and / or commands are executed at least partially during a common time interval. Parameters provided for control can thereby be determined within a short time by means of different data processing devices. Furthermore, a flexible and fast responding controller may be provided for systems with preferably low latencies.The method according to the invention can be carried out by means of the control system according to the invention.The control system according to the invention comprises two system-on-chip, each comprising two data processing devices. In this way, a highly available control system can be provided which has only two replaceable semiconductor components. Furthermore, a two-of-three configuration according to IEC 61508 can thereby be realized with only two replaceable semiconductor modules. This makes it possible to provide a compact and space-saving control system. A plurality of separate semiconductor assemblies for the purpose of satisfying a high safety requirement level may advantageously be dispensed with. Furthermore, a stock supply of spare parts can be kept small for an operator of the control system in this way. Moreover, a power saving control system can be provided.An advantageous embodiment variant of the control system provides that each of the two system-on-chip has in each case two data processing devices embodied as integrated circuits, which are embodied independently of one another. The fact that the integrated circuits of the data processing device are each designed independently is to be understood as meaning that a predetermined safety level is reached in the sense of the standard EN 50129, IEC 61508 or IEC 61511. This makes it possible to ensure that, in the case of a defective data processing device integrated on a system-on-chip, a remaining data processing device can continue to be operated. Thus, a carry of an error or a defect to a non-defective integrated data processing device can be prevented with high probability. The control system can thus meet stringent safety requirements. Preferably, a highest security requirement level 4 according to EN 50129 can be reached in this way.Furthermore, the invention provides a computer program which, when executed, causes the control system according to the invention to carry out the method according to the invention.Moreover, according to the invention, a computer-readable medium is provided. This includes instructions which cause the control system according to the invention to carry out the method according to the invention.Conveniently, the computer readable medium is a CD-ROM, DVD, USB or flash memory, or a non-tangible medium such as a data stream and / or a digital carrier signal.The above-described properties, features and advantages of the invention and the manner in which these are achieved are explained in more detail in conjunction with the figures in the following description of exemplary embodiments of the invention and associated variations. Where appropriate, the same reference numerals are used in the figures to refer to the same or corresponding elements of the invention. The exemplary embodiments and associated variations serve to explain the invention and do not restrict the invention to the combinations of features specified therein, nor with respect to functional features. In addition, all features indicated in the exemplary embodiments can be considered in isolation and combined in a suitable manner with the features of any claim. The figures described in the following context are schematic representations which are not true to scale.The following are shown: FIG. 1 shows an illustration of an example of the method according to the invention on the basis of a schematic flow diagram; FIG. 2 shows an illustration of a second example of the method according to the invention on the basis of a schematic flow diagram; FIG. 3 shows an exemplary embodiment of the control device according to the invention and a further illustration of the method according to the invention.FIG. 1 illustrates a first example of a method 100 afor controlling a fault tolerant system 10.The example of method 100 adescribed here provides that parameters are determined 102 for controlling system 10. These parameters are determined 102 by means of three data processing devices 18, 20, 22 in an operating state. These three data processing devices 18, 20, 22 are distributed between two single-chip systems 12, 14. An exemplary embodiment of a control device 26 for carrying out method 100 ais explained in more detail in conjunction with FIG. 3.On the basis of a comparison of the 102 parameters determined in each case by means of the three operation-carrying data processing devices 18, 20, 22, matching parameters are determined 104 in the present case. In a preferred embodiment variant, it is provided that the parameters are determined in a concurrent manner 102 by means of the three data processing devices 18, 20, 22. This allows a quick and reliable method 100 ato be provided for controlling the system 10. A high fault tolerance of the system 10 is achieved by detecting, on the basis of a determination 104 of a match of the determined 102 parameters, whether the same parameters have been determined 102 by all three data processing devices 18, 20, 22. If this is the case, it is assumed that all three data processing devices 18, 20, 22 are free of defects. However, if one of the determined 102parameters deviates from the other of the determined parameters 102, it is assumed that the deviating parameter is a deficient parameter. This error can then be either corrected or tolerated by a majority decision. The system 10 is then controlled 106 based on the matching parameters.Furthermore, a fourth data processing device 24 is provided. In the event of a fault F of one of the three previously mentioned operation-guiding data processing devices 18, 20, 22, this fourth data processing device 24 is provided to take over 108 control tasks of the defective ones of the three operation-guiding data processing devices 18, 20, 22.In the example of the method 100 adescribed here, the fourth data processing device 24 arranged on one of the two aforementioned single-chip systems 12, 14 is operated 110 in a passive standby operating state for this purpose. In the passive standby operating state 110, a storage content of the fourth data processing device 24 is synchronized 114 with storage contents of the operating three data processing devices 18, 20, 22 by means of a background update. In this way, a storage content of the fourth data processing device 24 can be matched with the storage contents of the operation-guiding data processing devices 18, 20, 22 such that this match is at least 80%. The fourth data processing device 24 can thereby be kept ready with little time for assuming the control tasks 108 of a deficient one of the three operation-carrying data processing devices 18, 20, 22.In the event of a fault F, a short transfer time is first provided 116. During this handover time 116, the storage content of the fourth computing device 24 is completely synchronized 114 with storage contents of non-defective computing devices of the three operational computing devices 18, 20, 22. Furthermore, during this handover time 116, the system 10 is controlled 106 by means of two non-defective data processing devices of the three operational data processing devices 18, 20, 22 in a redundant two-of-two configuration. In this redundant configuration, a fault case F can be detected with the aid of a comparison of the parameters 102 determined in each case by means of the two remaining data processing devices 18, 20, 22. However, in this case, error correction cannot be made further on the basis of a majority decision. Should a further fault therefore occur during the aforementioned transfer time 116, this would mean an interruption of the operation of the system 10. However, such fault accumulation is unlikely within a short time. Moreover, the transfer time 116 is already kept small with the aid of the passive operating state 110, since in this way a predominant part of the storage contents of the operation-guiding data processing devices 18, 20, 22 is synchronized 114 with the storage contents of the fourth data processing device 24. As soon as the memory contents of the fourth data processing device 24 are completely synchronized 114 with the memory contents of non-defective data processing devices of the three operational data processing devices 18, 20, 22, the control tasks of the defective ones of the three operational data processing devices 18, 20, 22 are taken over 108 by means of the fourth data processing device 24.Parameters for controlling the system 10 are then preferably determined 102 by means of the fourth data processing device 24. These 102 parameters determined by means of the fourth data processing device 24 are then included in the comparison with the determination 104 of matching parameters. 102 parameters determined on the basis of a deficient one of the three operational data processing devices 18, 20, 22 are ignored in this respect in the mentioned comparison. As a result, despite a defective data processing device, the system 10 can continue to be controlled 106 in a two-of-three configuration in the sense of the IEC 61508. This further makes it possible to provide a high error tolerance in which a further error is both detected and either corrected or tolerated with the aid of the majority decision.In a preferred embodiment variant of the example of method 100 adescribed here, a defective data processing device and an associated defective one-chip system of the two one-chip systems 12, 14 are identified 120. For this purpose, it is determined by which of the three operational data processing devices 18, 20, 22 the parameter deviating from the remaining two parameters was determined 102. The affected one of the three operational data processing devices 18, 20, 22 is identified 120 as a defective data processing device. In this case, one-chip system of the two one-chip systems 12, 14 having the defective data processing apparatus is also identified 120 as defective. It is then provided that the deficient one-chip system of the two one-chip systems 12, 14 is replaced 118 by a deficient one-chip system. During replacement 118 of the deficient system-on-chip, in a preferred embodiment, control of system 10 is realized solely from the two remaining deficient data processing devices of the deficient system-on-chip of the two systems-on-chip 12, 14. Thus, during the replacement 118 of the deficient system-on-chip, the system 10 operates as previously described in connection with the handoff time 116. Once the deficient system-on-chip is replaced 118 by the deficient system-on-chip, one of the two computing devices integrated on the deficient system-on-chip may be incorporated into the controller of the system 10. By way of example, this can be realized by synchronizing 114 memory contents. As soon as these memory contents are completely synchronized 114 with the fault-free and operation-leading data processing devices of the operation-leading fault-free system, control tasks are taken over 108 by means of this data processing device. Preferably, the second integrated data processing device of the newly added lack-free system-on-chip is also placed in the passive standby operating state 110 described above.FIG. 2 illustrates a second example of a method 100 bfor controlling the aforementioned system 10 on the basis of a schematic flow diagram.In contrast to the example of method 100 adescribed in connection with FIG. 1, fourth data processing device 24 is operated 112 in an active standby operating state in the second example of method 100 bdescribed herein. In the active standby operating state 112, the same control tasks as are carried out by the three operation-carrying data processing devices 18, 20, 22 are carried out concurrently by means of the fourth data processing device 24. However, the 102 parameters determined by means of the fourth data processing device 24 are not taken into account in the comparison for the purpose of determining 104 matching parameters. As a result, a problematic parity state can be avoided in a simple manner when determining a majority decision. The active standby operating state 112 makes it possible to include the fourth data processing device 24 in the control of the system 10 immediately after a fault case F is detected. With the aid of the active standby operating state 112, the fourth data processing device 24 is able to take over 108 control tasks 108 of a deficient data processing device immediately after a detection of a deficient state. A transfer time, as is provided by way of example in connection with the passive standby operating state 110, can thereby be dispensed with in a cost-effective manner. Therefore, with the aid of the active standby operating state 112, uninterrupted control of the system 10 can be realized in a particularly reliable manner.FIG. 3 shows an exemplary embodiment of a control device 26 in a schematic illustration. The control device 26 is part of the fault-tolerant system 10, not shown in detail, by way of example, FIG. 3 furthermore illustrates by way of example that the fault-tolerant system 10 is controlled 106 by means of the exemplary embodiment of the control device 26.The exemplary embodiment of the control device 26 has two system-on-chip 12, 14 for controlling the system 10. Each of the system-on-chip 12, 14 in turn has two integrated data processing devices 18, 20, 22, 24, respectively. The control of the fault-tolerant system 10 is thereby realized with the aid of two replaceable semiconductor modules with a high level of reliability. In particular, the two single-chip systems 12, 14 can be used to realize a two-of-three configuration for controlling the system 10 with only two replaceable semiconductor assemblies in a cost-effective manner.In a preferred embodiment of the control device 26, each of the two system-on-chip 12, 14 has two data processing devices 18, 20, 22, 24 each, which are designed as independent integrated circuits. A first system on chip 12 of the two systems on chip 12, 14 has, for example, two data processing devices 18, 20 embodied as integrated circuits. Furthermore, a second system 14 of the two systems 12, 14 on a single chip has, by way of example, two further data processing devices 22, 24 embodied as integrated circuits. If a lack of one of the data processing devices 18, 20, 22, 24 is detected, then, due to an independent and separate embodiment of the integrated circuits on the respective system on chip 12, 14, effects on a function of remaining data processing devices 18, 20, 22, 24 can be avoided. A distribution of operation-guiding data processing devices 18, 20, 22 on the two single-chip systems 12, 14 which are configured to control 106 the system 10 can be selected as desired.Although the invention has been illustrated and described in more detail by the preferred exemplary embodiments and their variations, the invention is not restricted by the disclosed examples and other variations can be derived therefrom by the person skilled in the art without departing from the scope of protection of the invention.Regardless of the grammatical sex of a certain term, individuals with male, female or other sex identity are included.

Claims

Method (100a, 100b) for controlling a fault-tolerant system (10), in which - parameters for controlling the system (10) are determined (102) in each case by means of three data processing devices (18, 20, 22) distributed over two single-chip systems (12, 14); - parameters which correspond to one another are determined (104) on the basis of a comparison of the parameters which are determined in each case (102); - the system (10) is controlled (106) on the basis of the parameters which correspond to one another.Method (100a, 100b) according to Claim 1, in which a fourth data processing device (24) is provided, which is arranged on one of the two single-chip systems (12, 14) and by means of which, in the event of a fault (F) in one of the three said operation-guiding data processing devices (18, 20, 22), a control task of the defective ones of the three operation-guiding data processing devices (18, 20, 22) is taken over (108).Method (100a, 100b) according to claim 1 or 2, wherein the fourth data processing device (24) arranged on one of the two single-chip systems (12, 14) is operated (110, 112) in a standby operating state.Method (100a) according to claim 3, wherein the fourth data processing device (24) is operated (110) in a passive standby operating state.The method (100a) of claim 4, wherein a storage content of the fourth data processing device (24) is synchronized (114) with at least a portion of the storage contents of the three operational data processing devices (18, 20, 22) in the passive standby operating state (110).Method (100a) according to Claim 4 or 5, in which, in the event of a fault (F), a transfer time is provided (116) for the fourth data processing device (24) operated in the passive standby operating state (110), during which the memory content of the fourth data processing device (24) is completely synchronized (114) with memory contents of non-defective data processing devices of the three operation-carrying data processing devices (18, 20, 22).Method (100b) according to claim 3, wherein the fourth data processing device (24) is operated (112) in an active standby operating state.Method (100a, 100b) according to one of the preceding claims, in which, in the event of a fault (F) in one of the three operation-carrying data processing devices (18, 20, 22), a system on chip of the two system on chip (12, 14), which system has the faulty data processing device, is replaced (118) by a faulty system on chip during operation of the system (10).Method (100a, 100b) according to claim 8, wherein, while the deficient one-chip system is replaced (118) by the deficient one-chip system, the control of the system (10) is realized solely by means of two data processing devices of the remaining one-chip system of the two one-chip systems (12, 14).The method (100a, 100b) of any preceding claim, wherein a deficient one of the three operational data processing devices (18, 20, 22) is identified (120) in that the parameter determined (102) by the deficient one of the three operational data processing devices (18, 20, 22) is different from parameters determined (102) by two remaining ones of the three operational data processing devices (18, 20, 22).Method (100a, 100b) according to one of the preceding claims, in which the parameters for controlling the system (10) are each determined (102) in a concurrent manner by means of the three data processing devices (18, 20, 22) distributed on the two single-chip systems (12, 14).Control device (26) which is configured to carry out the method (100a, 100b) according to one of the preceding claims, having two system-on-chip (12, 14) which each have two data processing devices (18, 20, 22, 24).Control device (26) according to Claim 12, characterized in that each of the two system-on-chip (12, 14) has two data processing devices (18, 20, 22, 24) which are embodied as integrated circuits and are embodied independently of one another.A computer program which, when executed, causes the control device (26) according to claim 12 or 13 to perform the method (100a, 100b) according to any one of claims 1 to 11.A computer readable medium comprising instructions that cause the control device (26) of claim 12 or 13 to perform the method (100a, 100b) of any one of claims 1 to 11.