Communication Node for Critical Systems Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication nodes in fault-tolerant computer systems face challenges in preventing the transmission of arbitrary application data to real-time networks, especially when faulty, which can compromise safety-critical applications by sending incorrect or generated data.

Innovation Solution

A communication node design comprising two end systems and a switch with a commander, monitor, and comparator part, synchronized through local clocks and protocol data, ensures that only identical critical application data from both hosts is forwarded to the real-time network, utilizing an interception function to prevent faulty transmissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a communication node is used to forward critical application data from computation hosts to real-time network, then data transmission is enabled, but the risk of transmitting arbitrary or incorrect data increases when the communication node becomes faulty

Engineering Contradiction:
Improvedata transmission reliabilityVSAvoidtransmission of arbitrary data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The communication node is segmented into multiple independent functional units: commander part, monitor part, and comparator part. Each part processes data independently and the comparator validates data integrity by comparing outputs, preventing arbitrary data transmission even when one component fails.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The comparator part acts as an intermediary between the commander/monitor parts and the real-time network. It validates data from computation hosts before forwarding to the network, serving as a mediator that blocks arbitrary or incorrect data from reaching the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If protection mechanisms are implemented to prevent faulty data transmission, then data integrity is improved, but the device complexity increases due to multiple end systems and switch components

Engineering Contradiction:
Improvedata integrityVSAvoidcommunication node structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitor part and comparator part can be integrated into a single integrated part, reducing device complexity while maintaining the protective functionality. This merging combines validation and monitoring functions into one unified component.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Different parts of the communication node have specialized functions: the commander part handles primary data processing, the monitor part handles validation, and the comparator part handles final verification. This local specialization of quality allows each component to be optimized for its specific task, making the overall system more manageable despite the multiple components.

Inventive Principle:
Principle #3Local quality

3Productivity

If the communication node forwards data from computation hosts to the real-time network, then productivity is maintained, but the risk of harmful factors increases when computation hosts are faulty

Engineering Contradiction:
Improvedata forwarding capabilityVSAvoidfaulty data from computation hosts
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The communication node implements preliminary validation through the monitor and comparator parts before data is forwarded to the real-time network. This preliminary anti-action detects and blocks faulty or arbitrary data from computation hosts before they can contaminate the network, maintaining productivity while preventing harmful factors.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11366726B2Communication node for critical systems
Publication Date: 2022.06.21 TTTECH COMPUTERTECHNIK AG
  • US11366726B2 patent drawing
  • US11366726B2 patent drawing
  • US11366726B2 patent drawing

AI summary

A communication node (NODE) for connecting a fault-tolerant computer (FTC) to a real-time network (NET), wherein the node receives critical application data (HCAD1, HCAD2) from computation hosts (HOST) of the fault-tolerant computer, and the node is configured to forward the critical application data as node critical application data (NCAD) to the NET. The node includes at least a first end system (ES1), a second end system (ES2) and a switch (SW), and the switch includes at least a commander part (COM), a monitor part (MON) and a comperator part (COMP). The MON and the COMP may be integrated into an integrated part (MONC). The ES1 connects to the computation hosts or a subset thereof, and the ES2 connects to the computation hosts or a subset thereof. The ES1 connects to the COM, and the ES2 connects to the MON. The computation hosts or a subset thereof provide first host critical application data (HCAD1) to the ES1, and the computation hosts or a subset thereof provide second host critical application data (HCAD2) to the ES2. The ES1 is configured to forward the HCAD1 as first end system critical application data (ESCAD1) to the COM and the ES2 is configured to forward the HCAD2 as second end system critical application data (ESCAD2) to the MON. The COM is configured to forward the ESCAD1 as commander critical application data (CCAD) to the COMP at a pre-configured commander forwarding point in time (TCOM), and the MON is configured to forward the ESCAD2 as monitor critical application data (MCAD) to the COMP at a pre-configured monitor forwarding point in time (TMON). If the MON and the COMP are not integrated into an integrated part, then the COMP is configured to forward either the CCAD or the MCAD as node critical application data (NCAD), if and only if, the CCAD and the MCAD are identical and the COMP starts to receive the CCAD and the MCAD within an interval of configured length (SYNC-1). Alternatively, if the MON and the COMP are integrated into an integrated part (MONC), then the COM is configured to forward the ESCAD1 as NCAD to the NET. The switch includes an interception function (INTERCEPT) which is configured to (i) preempt an ongoing transmission of NCAD and/or (ii) prevent the transmission of NCAD, and the COMP is configured to activate the interception function if and only if the CCAD and the MCAD are not identical or the COMP does not start to receive the CCAD and the MCAD within SYNC-1.