Controlling a fault-tolerant system with two semiconductor assemblies
The method employs two interchangeable semiconductor assemblies with a redundant data processing device to ensure uninterrupted operation and high availability in fault-tolerant systems, addressing space and spare part management challenges.
Patent Information
- Application Number
- PCT/EP2025/068055
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-09-24
- Filing Date
- 2025-06-26
- Publication Date
- 2026-02-05
AI Technical Summary
Existing fault-tolerant systems require multiple semiconductor assemblies for uninterrupted operation, leading to space and spare part management challenges, and conventional dual modular redundancy does not ensure continuous operation if another fault occurs during repair.
A method utilizing two interchangeable semiconductor assemblies, each with two independently operable data processing devices, allows a two-out-of-three configuration for fault-tolerant systems, incorporating a fourth device for redundancy to ensure uninterrupted operation and efficient repair.
Enables uninterrupted operation and high availability with reduced space and spare parts, maintaining system reliability and safety even during repairs, while minimizing energy consumption and spare parts inventory.
Smart Images

Figure EP2025068055_05022026_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Control of a fault-tolerant system with two semiconductor assemblies
[0003] The invention relates to a method for controlling a fault-tolerant system, a control system for carrying out the method, a computer program and a computer-readable medium.
[0004] In safety-critical systems, such as traffic control systems or emergency management systems, fault-tolerant control systems with high availability and high reliability are required. To provide safe and highly available control systems, it is already known to have three independent control tasks performed on separately arranged semiconductor modules and then compare the results obtained from each. Based on this comparison, in the event of a failure in one of the three data processing devices, the fault can be detected, and a correction can be made based on a majority decision. The control of the safety-critical system then takes place using a majority decision based on the concurring results of the three data processing devices.Such a configuration of three data processing devices for controlling a fault-tolerant system is already known as a two-of-three configuration in accordance with the standard IEC 61508 or in English usage under the name "triple modular redundancy".
[0005] Furthermore, in the event of a fault, one of the three separate semiconductor modules can be replaced. Meanwhile, the system is controlled without interruption using the two remaining functioning data processing devices, based on a two-of-two configuration as defined by IEC 61508. This configuration is known as "dual modular redundancy." While this configuration allows for fault detection, it does not enable fault-tolerant continued operation of the system.
[0006] In the event of a failure, a two-out-of-two configuration is currently used as a first step. Therefore, a repair and / or replacement of a faulty or defective semiconductor assembly from the three separate semiconductor assemblies mentioned is generally required promptly after the failure is detected. If another fault or defect occurs in one of the remaining semiconductor assemblies from the three separate assemblies during this initial failure, the system availability will be insufficient. To prevent this, a rapid replacement of a failed or defective semiconductor assembly must be ensured. This is typically achieved by maintaining a sufficient number of spare components. These spare components may need to be regularly inspected for their condition to prevent one defective semiconductor assembly from being replaced by another.Furthermore, three separate semiconductor assemblies require more space. While it is already known to integrate several independent data processing devices on a single semiconductor assembly and / or a single-chip system, three independent data processing devices on separate semiconductor assemblies are currently required for fault-tolerant system control and the previously described majority decision. Reducing the number of available semiconductor assemblies therefore leads to a dilemma in the event of a failure, as a functioning, undamaged data processing device might be affected by replacing a semiconductor assembly containing two data processing devices. In this case, uninterrupted operation during a repair of the fault-tolerant system would no longer be possible, even based on a two-of-two configuration according to IEC 61508.
[0007] The object of the invention is to realize a fault-tolerant system with high availability based on two interchangeable semiconductor assemblies. In particular, this should enable uninterrupted operation of the system during a repair process.
[0008] This problem is solved by a method having the features of claim 1.
[0009] Furthermore, the invention is based on the objective of providing a control device for carrying out the method according to the invention.
[0010] This problem is solved by a control device having the features of the subordinate claim.
[0011] Furthermore, the invention is based on the objectives of providing a computer program and a computer-readable medium. These objectives are achieved by a computer program with the features of the dependent computer program claim and by a computer-readable medium with the features of dependent claim 15.
[0012] Advantageous further training courses are each the subject of dependent sub-claims.
[0013] The inventive method for controlling a fault-tolerant system provides that parameters for controlling the system are determined by means of three data processing devices distributed across two single-chip systems.
[0014] In this context, a single-chip system (SCS) is understood to be an electronic system arranged on a common semiconductor substrate. In this case, at least two independently implemented integrated circuits are arranged on the common semiconductor substrate. Advantageously, each of the two SCS comprises two integrated circuits configured as a data processing device. In particular, the two data processing devices of a SCS are implemented independently of each other. The data processing device may be, for example, a microcontroller, a processor, or another programmable hardware component. The data processing device is advantageously configured to read, receive, store, write, transmit, and / or manage data.In the preferred application, the data processing device includes a semiconductor memory for storing data. Preferably, each of the data processing devices is configured to control the fault-tolerant system. Instead of the three data processing devices distributed across two single-chip systems, two semiconductor assemblies can be provided, each comprising two separately implemented and independently operable data processing devices. Of these four data processing devices, at least three can be used to carry out the method according to the invention. While single-chip systems with, for example, two independent data processing devices each offer improved efficiency in specific applications,However, the present invention can also be implemented in an alternative way using the two aforementioned semiconductor assemblies, each comprising two separate and independently operable data processing devices. Furthermore, the method according to the invention provides that matching parameters are determined based on a comparison of the respective defined parameters. The system is then controlled based on these matching parameters. In this way, a two-out-of-three configuration as defined in IEC 61508 can be implemented cost-effectively with only two interchangeable semiconductor assemblies. This two-out-of-three configuration is therefore referred to in English as "triple modular redundancy." This allows for the implementation of a fail-safe and highly fault-tolerant system based on two interchangeable semiconductor assemblies. The system can thus be operated in an energy-efficient manner.Advantages of single-chip systems, such as high availability, low electrical power consumption, low failure risk, cost-effective manufacturing, compact arrangement, and high reliability, can be exploited in the control of the system.
[0015] An advantageous embodiment provides for a fourth data processing direction, which is located on one of the two semiconductor assemblies and / or one of the two single-chip systems. In the event of a failure of one of the three operational data processing devices, this fourth direction takes over the control function of the failing device. This enables the provision of a fault-tolerant system with particularly high availability. Compared to conventional two-out-of-three configurations, the system can continue to operate in a two-out-of-three configuration even if one data processing device fails.A majority decision, in which at least two of the three defined parameters must agree to ensure fail-safe system control, can be quickly implemented even if one of the three operational data processing devices fails. Furthermore, this avoids relying solely on two data processing devices for system control. The fourth data processing device also allows for maintaining a high level of reliability, even until the faulty device is replaced. In the preferred application, the number of spare parts required by the operator can be minimized.If one of the operational data processing devices fails, the fourth data processing device can cost-effectively replace it without requiring the replacement of an entire semiconductor assembly. Furthermore, the aforementioned two-out-of-three configuration can be maintained. Depending on the timing of a failure or defect, it may even be possible to forgo replacing the defective data processing device altogether. This is particularly relevant if the remaining data processing devices have a sufficiently long lifespan and a sufficiently low probability of failure. Alternatively, a defective single-chip system or semiconductor assembly can be repaired.During the repair, which is usually quick to complete, the system reverts to a two-of-two configuration because the entire semiconductor assembly or single-chip system is replaced, each of which inextricably incorporates two data processing devices. Due to the short repair time, the risk of another failure during this period is negligible. After the repair and / or replacement of the faulty semiconductor assembly, all four units are operational again, and the system can resume operation in a two-of-three configuration with an additional data processing device as a hot spare.
[0016] In the event of a failure, the fourth data processing device can be used to take over the operation of a defective data processing device. This allows for safe and continued high availability of control even though a primary data processing device is no longer available for system operation. Therefore, in the event of a further failure, safe and highly available control of the system, preferably in a two-out-of-three configuration, is still possible. Thus, only a third failure would lead to an interruption of control operation. Additionally, this approach enables repair without interrupting safe operation using only two physically replaceable units (semiconductor assemblies).
[0017] A further advantageous embodiment provides that the fourth data processing device, arranged on one of the two single-chip systems, operates in a standby state. From this standby state, the fourth data processing device can be used to control the system at any time with a minimal transfer time. In the event of a failure of one of the three primary data processing devices, the control tasks of the faulty device can be quickly and reliably taken over by the fourth data processing device. Preferably, in the aforementioned failure scenario, the fourth data processing device can assume the control tasks of the faulty device without interrupting system operation. In an advantageous embodiment, the fourth data processing device operates in a passive standby state.In this context, the passive standby operating state is understood to be an operating state in which the data processing device, without itself performing control tasks, is kept up-to-date by means of a background update for the purpose of controlling the system. In this way, during normal operation without errors, the data processing device in question is largely synchronized with the active data processing devices in the standby operating state. Preferably, in the passive operating state, the fourth data processing device achieves a synchronization with the active data processing devices of at least 80% and preferably at least 90%.This makes it possible to prepare the fourth data processing device in the event of a failure with minimal time expenditure so that it can be quickly used as an operational data processing device.
[0018] In a further advantageous embodiment, the memory contents of the fourth data processing device are synchronized with at least a portion of the memory contents of the three operating data processing devices while in passive standby mode. Known methods for memory checks and / or extensions of these known methods are suitable for this purpose. This allows the fourth data processing device to be prepared for taking over control tasks during normal operation in a cost-effective manner. As a result, low energy consumption of the fourth data processing device in passive standby mode can be achieved. Furthermore, a significant increase in the failure probability of the fourth data processing device due to passive standby mode can be counteracted.
[0019] Advantageously, in the event of a failure, a transfer period is provided for the fourth data processing device, which operates in passive standby mode. During this transfer period, the memory contents of the fourth data processing device are preferably fully synchronized with the memory contents of the three functioning data processing devices. In this way, the fourth data processing device can be quickly and reliably deployed to take over control tasks from the faulty data processing device. The fourth data processing device can thus be used as the primary data processing device in place of the faulty data processing device in a cost-effective manner.In the preferred application case, this ensures uninterrupted and highly available operation of the system, particularly in the event of a failure of the operating data processing device.
[0020] In an alternative advantageous embodiment, the fourth data processing device is operated in an active standby operating state.
[0021] In this context, an active standby operating state is understood to mean an operating state in which the affected data processing device performs the same control tasks as the three operating data processing devices. However, during normal system operation, the parameters determined by the affected data processing device are disregarded when comparing parameters for transmitting matches. In this way, complete synchronization of the affected data processing device with the three operating data processing devices can be achieved. In particular, the memory contents of the affected data processing device can always be fully synchronized with the memory contents of the operating data processing devices.Control tasks of a defective data processing device can therefore be directly taken over by the defective data processing device itself. Furthermore, a majority decision for system control can be made during normal system operation without creating any potential parity. In the preferred application, even a short transition period can be dispensed with using the active standby operating state.
[0022] Preferably, in the event of a failure of one of the three operational data processing devices, the defective single-chip system of the two single-chip systems is replaced by a non-defective single-chip system during system operation. This allows a safety-critical application to continue to be controlled without interruption using only two hardware modules. High system availability can thus be provided cost-effectively. Even in the event of a failure of an operational data processing device, the system can continue to operate with high availability. Furthermore, a high level of safety can be achieved cost-effectively. Particularly preferably, during the replacement of the defective single-chip system by a non-defective one-chip system, the system is controlled solely by the two data processing devices of the remaining single-chip system of the two single-chip systems.This allows the system to continue operating reliably and safely even when a semiconductor assembly is replaced, which, instead of the single-chip system, may have two separate data processing devices. Using the two data processing devices of the remaining single-chip system, the system's control can continue based on a two-of-two configuration as defined in IEC 61508. Such a two-of-two configuration is therefore referred to as "double modular redundancy." This allows a fault to be detected by comparing the two parameters determined by the two remaining data processing devices. However, unlike in a two-of-three configuration, this fault cannot be corrected or tolerated by majority vote in the two-of-two configuration.After replacing the defective single-chip system with the non-defective one, one of the two data processing devices of the new non-defective single-chip system can be quickly and cost-effectively prepared for system control. For example, the memory contents of the two operating data processing devices can be synchronized with the memory contents of one of the two newly added data processing devices. Once the non-defective operation of the newly added data processing device has been sufficiently ensured, it can assume the same control tasks as the operating data processing devices. Subsequently, to restore a two-out-of-three configuration as defined in IEC 61508, the newly added data processing device can be included in a majority vote.The remaining newly added data processing device of the flawless single-chip system is advantageously then operated in one of the previously described standby operating modes.
[0023] Advantageously, a defective one of the three operational data processing devices is identified by the fact that the parameter determined by the defective data processing device differs from the parameter determined by any two of the other three operational data processing devices. This allows the defective data processing device to be identified reliably and quickly. A targeted replacement of a defective semiconductor assembly with a single-chip system or, for example, two separate, independent data processing devices is thus reliably possible. Preferably, the parameters for controlling the system are determined concurrently by the three operational data processing devices distributed across the two single-chip systems.Concurrent processing, as used here, is to be understood in the context of computer science, where tasks, calculations, instructions, and / or commands are executed at least partially during a common time interval. This allows parameters intended for control to be determined quickly using various data processing devices. Furthermore, it enables flexible and fast-responding control for systems with preferably low latency.
[0024] The inventive method can be carried out using the control system according to the invention.
[0025] The control system according to the invention comprises two single-chip systems, each containing two data processing devices. This enables the provision of a highly available control system that uses only two replaceable semiconductor components. Furthermore, a two-out-of-three configuration according to IEC 61508 is achievable with only two replaceable semiconductor assemblies. This allows for the provision of a compact and space-saving control system. Advantageously, the need for a large number of separate semiconductor assemblies to meet high safety requirements can be avoided. Moreover, this approach minimizes the need for spare parts inventory for the operator of the control system. In addition, an energy-efficient control system can be provided.
[0026] An advantageous embodiment of the control system provides that each of the two single-chip systems has two data processing devices implemented as integrated circuits, which are independent of each other. The independent implementation of the integrated circuits of the data processing devices means that a predetermined level of safety, as defined by standards EN 50129, IEC 61508, or IEC 61511, is achieved. This ensures that if one data processing device integrated on a single-chip system fails, the other data processing device can continue to operate. In this way, the transmission of a fault or defect to a functioning integrated data processing device can be prevented with a high degree of probability. The control system can thus meet stringent safety requirements.Preferably, a maximum safety requirement level 4 according to EN 50129 can be achieved in this way.
[0027] Furthermore, the invention provides a computer program which, when executed, causes the control system according to the invention to carry out the method according to the invention.
[0028] Furthermore, a computer-readable medium is provided according to the invention. This medium contains instructions which cause the control system according to the invention to carry out the method according to the invention.
[0029] The computer-readable medium is preferably a CD-ROM, a DVD, a USB or flash memory device, or a non-physical medium such as a data stream and / or a digital carrier signal.
[0030] The properties, features, and advantages of the invention described above, as well as the manner in which these are achieved, are explained in more detail in the following description of exemplary embodiments of the invention and related variations, in conjunction with the figures. Where appropriate, the same reference numerals are used in the figures for the same or corresponding elements of the invention. The exemplary embodiments and related variations serve to illustrate the invention and do not limit the invention to the combinations of features specified therein, including functional features. Furthermore, all features specified in the exemplary embodiments can be considered in isolation and combined appropriately with the features of any claim. The figures described below are not to scale and are schematic representations.
[0031] They show:
[0032] FIG 1 illustrates an example of the method according to the invention using a schematic flowchart;
[0033] FIG 2 illustrates a second example of the method according to the invention using a schematic flowchart; FIG 3 shows an embodiment of the control device according to the invention and a further illustration of the method according to the invention.
[0034] FIG 1 illustrates a first example of a method 100a for controlling a fault-tolerant system 10. The fault-tolerant system 10 relates, for example, to a traffic control system or an emergency management system, such as a smoke extraction system.
[0035] The example of method 100a described here provides that 10 parameters are determined for controlling the system. These parameters are determined by means of three data processing devices 18, 20, 22 in an operational state. These three data processing devices 18, 20, 22 are distributed across two single-chip systems 12, 14. An embodiment of a control device 26 for carrying out method 100a is explained in more detail in connection with FIG. 3.
[0036] Based on a comparison of the 102 parameters determined by the three operating data processing devices 18, 20, 22, matching parameters are identified 104. In a preferred embodiment, the parameters are determined concurrently by the three data processing devices 18, 20, 22 102. This provides a fast and reliable method 100a for controlling the system 10. High fault tolerance of the system 10 is achieved by determining whether all three data processing devices 18, 20, 22 determined the same parameters 102. If this is the case, it is assumed that all three data processing devices 18, 20, 22 are fault-free.However, if one of the defined parameters (102) deviates from the other defined parameters (102), it is assumed that the deviating parameter is defective. This error can then be either corrected or tolerated by majority vote. System 10 is then controlled based on the matching parameters (106).
[0037] Furthermore, a fourth data processing device 24 is provided. In the event of a failure F of one of the three aforementioned operational data processing devices 18, 20, 22, this fourth data processing device 24 is intended to take over control tasks of the defective of the three operational data processing devices 18, 20, 22 108. In the example of method 100a described here, the fourth data processing device 24, arranged on one of the two aforementioned single-chip systems 12, 14, is operated in a passive standby operating state for this purpose 110. In the passive standby operating state 110, a memory content of the fourth data processing device 24 is synchronized with the memory contents of the three operational data processing devices 18, 20, 22 by means of a background update 114.In this way, the memory contents of the fourth data processing device 24 can be aligned with the memory contents of the operating data processing devices 18, 20, 22 such that this alignment is at least 80%. The fourth data processing device 24 can thus be made available with minimal time expenditure to take over the control tasks 108 of a defective one of the three operating data processing devices 18, 20, 22.
[0038] In the event of an error F, a short transfer time is initially provided 116. During this transfer time 116, the memory contents of the fourth data processing device 24 are fully synchronized with the memory contents of error-free data processing devices of the three operational data processing devices 18, 20, 22 114. Furthermore, during this transfer time 116, the system 10 is controlled by means of two error-free data processing devices of the three operational data processing devices 18, 20, 22 in a redundant two-of-two configuration 106. In this redundant configuration, an error F can be detected by comparing the parameters 102 determined by the two remaining data processing devices 18, 20, 22. However, in this case, error correction cannot be carried out based on a majority decision.Should another error occur during the aforementioned transfer time 116, this would mean an interruption of the operation of system 10. However, such an accumulation of errors within a short time is unlikely. Moreover, the transfer time 116 is already kept short by means of the passive operating state 110, since in this way a predominant part of the memory contents of the operating data processing devices 18, 20, 22 is synchronized with the memory contents of the fourth data processing device 24 114. As soon as the memory contents of the fourth data processing device 24 are fully synchronized with the memory contents of the error-free data processing devices of the three operating data processing devices 18, 20, 22 114, the control tasks of the defective of the three operating data processing devices 18, 20, 22 are taken over by means of the fourth data processing device 24 108.Preferably, 24 parameters for controlling the system 10 are then determined using the fourth data processing device. These 102 parameters determined using the fourth data processing device are then included in the comparison to identify 104 matching parameters. 102 parameters determined by a defective data processing device (18, 20, 22) are disregarded in the aforementioned comparison. This allows the system 10 to continue to be controlled in a two-out-of-three configuration as defined in IEC 61508, despite a defective data processing device. This also makes it possible to provide a high fault tolerance, where a further fault is both detected and either corrected or tolerated by majority vote.
[0039] In a preferred embodiment of the example of method 100a described herein, a defective data processing device and an associated defective single-chip system of the two single-chip systems 12, 14 are identified 120. For this purpose, it is determined by which of the three operating data processing devices 18, 20, 22 the parameter deviating from the other two parameters was determined 102. The affected of the three operating data processing devices 18, 20, 22 is identified as the defective data processing device 120. In this context, a single-chip system of the two single-chip systems 12, 14, which includes the defective data processing device, is also identified as defective 120. Subsequently, it is provided that the defective single-chip system of the two single-chip systems 12, 14 is replaced by a non-defective single-chip system. 118.During the replacement 118 of the defective single-chip system, in a preferred embodiment, the control of system 10 is implemented solely by means of the two remaining non-defective data processing devices of the non-defective single-chip system 12, 14. Therefore, during the replacement 118 of the defective single-chip system, system 10 is operated in the redundant two-of-two configuration previously described in connection with the handover time 116. Once the defective single-chip system has been replaced by the non-defective single-chip system 118, one of the two data processing devices integrated on the non-defective single-chip system can be integrated into the control of system 10. This can be achieved, for example, by synchronizing memory contents 114.Once these memory contents are fully synchronized with the fault-free and operational data processing devices of the operational fault-free single-chip system 114, control tasks are taken over by means of this data processing device 108. Preferably, the second integrated data processing device of the newly added fault-free single-chip system is also placed in the previously described passive standby operating state 110.
[0040] FIG 2 illustrates a second example of a method 100b for controlling the aforementioned system 10 using a schematic flowchart.
[0041] In contrast to the example of method 100a described in connection with FIG 1, in the second example of method 100b described here, the fourth data processing device 24 is operated in an active standby operating state 112. In this active standby operating state 112, the same control tasks are performed concurrently by the fourth data processing device 24 as are performed by the three operating data processing devices 18, 20, 22. However, the parameters 102 determined by the fourth data processing device 24 are disregarded when comparing them for the purpose of identifying 104 matching parameters. This easily avoids a problematic parity situation when determining a majority decision.The active standby operating state 112 enables the fourth data processing device 24 to be integrated into the control of the system 10 immediately after the detection of a fault F. With the active standby operating state 112, the fourth data processing device 24 is able to take over control tasks 108 of a defective data processing device immediately after the detection of a fault 108. This eliminates the need for a transfer time, such as that provided for in connection with the passive standby operating state 110, thus saving effort. Therefore, uninterrupted control of the system 10 can be achieved in a particularly reliable manner using the active standby operating state 112.
[0042] FIG 3 shows a schematic representation of an embodiment of a control device 26. The control device 26 is, by way of example, part of the fault-tolerant system 10, which is not shown in detail. Furthermore, FIG 3 illustrates by way of example that the fault-tolerant system 10 is controlled by means of the embodiment of the control device 26 106.
[0043] The exemplary embodiment of the control device 26 comprises two single-chip systems 12, 14 for controlling the system 10. Each of the single-chip systems 12, 14 in turn comprises two integrated data processing devices 18, 20, 22, 24. The control of the fault-tolerant system 10 is thus implemented with high reliability using two interchangeable semiconductor modules. In particular, a cost-effective two-out-of-three configuration for controlling the system 10 can be implemented using the two single-chip systems 12, 14, requiring only two interchangeable semiconductor modules.
[0044] In a preferred embodiment of the control device 26, each of the two single-chip systems 12, 14 comprises two data processing devices 18, 20, 22, 24 implemented as independent integrated circuits. A first single-chip system 12 of the two single-chip systems 12, 14, by way of example, comprises two data processing devices 18, 20 implemented as integrated circuits. Furthermore, a second single-chip system 14 of the two single-chip systems 12, 14, by way of example, comprises two further data processing devices 22, 24 implemented as integrated circuits. If a defect is detected in one of the data processing devices 18, 20, 22, 24, the effects on the function of other data processing devices 18, 20, 22, 24 can be avoided due to the independent and separate design of the integrated circuits on the respective single-chip system 12, 14.The distribution of operational data processing devices 18, 20, 22 on the two single-chip systems 12, 14, which are configured to control the system 10 106, can be chosen arbitrarily.
[0045] Although the invention has been further illustrated and described in detail by the preferred embodiments and their variations, the invention is not limited by the disclosed examples and other variations can be derived by the person skilled in the art without leaving the scope of protection of the invention.
[0046] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.
Claims
Patent claims 1. Method (100a, 100b) for controlling a fault-tolerant system (10), in which - parameters for controlling the system (10) are determined by means of three data processing devices (18, 20, 22) distributed across two single-chip systems (12, 14) (102); - matching parameters are determined based on a comparison of the respective determined (102) parameters (104); - the system (10) is controlled on the basis of the matching parameters (106).
2. Method (100a, 100b) according to claim 1, in which a fourth data processing device (24) is provided, which is arranged on one of the two single-chip systems (12, 14) and by means of which, in the event of a fault (F) of one of the three said operational data processing devices (18, 20, 22), a control task of the defective of the three operational data processing devices (18, 20, 22) is taken over (108).
3. Method (100a, 100b) according to claim 1 or 2, wherein the fourth data processing device (24) arranged on one of the two single-chip systems (12, 14) is operated in a standby operating state (110, 112).
4. Method (100a) according to claim 3, wherein the fourth data processing device (24) is operated in a passive standby operating state (110).
5. Method (100a) according to claim 4, in which a memory content of the fourth data processing device (24) in the passive standby operating state (110) is synchronized with at least a part of the memory contents of the three operating data processing devices (18, 20, 22) (114).
6. Method (100a) according to claim 4 or 5, wherein in the event of a fault (F) a transfer time (116) is provided for the fourth data processing device (24) operated in the passive standby operating state (110), during which the memory content of the fourth data processing device (24) is transferred with memory contents flawless data processing devices of the three operating data processing devices (18, 20, 22) are fully synchronized (114).
7. Method (100b) according to claim 3, wherein the fourth data processing device (24) is operated in an active standby operating state (112).
8. Method (100a, 100b) according to one of the preceding claims, wherein in the event of a fault (F) of one of the three operating data processing devices (18, 20, 22) a single-chip system comprising the defective data processing device of the two single-chip systems (12, 14) is replaced by a fault-free single-chip system during operation of the system (10) (118).
9. Method (100a, 100b) according to claim 8, in which, while the defective single-chip system is replaced by the non-defective single-chip system (118), the control of the system (10) is realized solely by means of two data processing devices of the remaining single-chip system of the two single-chip systems (12, 14).
10. Method (100a, 100b) according to one of the preceding claims, wherein a defective one of the three operating data processing devices (18, 20, 22) is identified (120) by the fact that the parameter (102) determined by means of the defective one of the three operating data processing devices (18, 20, 22) differs from the parameter (102) determined by means of two other one of the three operating data processing devices (18, 20, 22).
11. Method (100a, 100b) according to one of the preceding claims, in which the parameters for controlling the system (10) are determined concurrently by means of the three data processing devices (18, 20, 22) distributed on the two single-chip systems (12, 14) (102).
12. Control device (26) which is configured to carry out the method (100a, 100b) according to one of the preceding claims, comprising two single-chip systems (12, 14) which each comprise two data processing devices (18, 20, 22, 24).
13. Control device (26) according to claim 12, characterized in that each of the two single-chip systems (12, 14) has two data processing devices (18, 20, 22, 24) designed as integrated circuits, which are implemented independently of each other.
14. Computer program which, upon execution, causes the control device (26) according to claim 12 or 13 to perform the method (100a, 100b) according to any one of claims 1 to 11.
15. Computer-readable medium comprising instructions which cause the control device (26) according to claim 12 or 13 to perform the method (100a, 100b) according to any one of claims 1 to 11.
Citation Information
Patent Citations
Providing fault-tolerance by comparing addresses and data from redundant processors running in lock-step
US20020152420A1
Data availability in a constrained deployment of a high-availability system in the presence of pending faults
US20210089376A1