Communication Node for Critical Systems Data Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication nodes in fault-tolerant computer systems face challenges in preventing the transmission of arbitrary application data to real-time networks, especially when faulty, which can compromise safety-critical applications by sending incorrect or generated data.
Innovation Solution
A communication node design comprising two end systems and a switch with a commander, monitor, and comparator part, synchronized through local clocks and protocol data, ensures that only identical critical application data from both hosts is forwarded to the real-time network, utilizing an interception function to prevent faulty transmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a communication node is used to forward critical application data from computation hosts to real-time network, then data transmission is enabled, but the risk of transmitting arbitrary or incorrect data increases when the communication node becomes faulty
Solution Approach 1:
The communication node is segmented into multiple independent functional units: commander part, monitor part, and comparator part. Each part processes data independently and the comparator validates data integrity by comparing outputs, preventing arbitrary data transmission even when one component fails.
Solution Approach 2:
The comparator part acts as an intermediary between the commander/monitor parts and the real-time network. It validates data from computation hosts before forwarding to the network, serving as a mediator that blocks arbitrary or incorrect data from reaching the network.
2Reliability
If protection mechanisms are implemented to prevent faulty data transmission, then data integrity is improved, but the device complexity increases due to multiple end systems and switch components
Solution Approach 1:
The monitor part and comparator part can be integrated into a single integrated part, reducing device complexity while maintaining the protective functionality. This merging combines validation and monitoring functions into one unified component.
Solution Approach 2:
Different parts of the communication node have specialized functions: the commander part handles primary data processing, the monitor part handles validation, and the comparator part handles final verification. This local specialization of quality allows each component to be optimized for its specific task, making the overall system more manageable despite the multiple components.
3Productivity
If the communication node forwards data from computation hosts to the real-time network, then productivity is maintained, but the risk of harmful factors increases when computation hosts are faulty
Solution Approach 1:
The communication node implements preliminary validation through the monitor and comparator parts before data is forwarded to the real-time network. This preliminary anti-action detects and blocks faulty or arbitrary data from computation hosts before they can contaminate the network, maintaining productivity while preventing harmful factors.
Data Source
AI summary
A communication node (NODE) for connecting a fault-tolerant computer (FTC) to a real-time network (NET), wherein the node receives critical application data (HCAD1, HCAD2) from computation hosts (HOST) of the fault-tolerant computer, and the node is configured to forward the critical application data as node critical application data (NCAD) to the NET. The node includes at least a first end system (ES1), a second end system (ES2) and a switch (SW), and the switch includes at least a commander part (COM), a monitor part (MON) and a comperator part (COMP). The MON and the COMP may be integrated into an integrated part (MONC). The ES1 connects to the computation hosts or a subset thereof, and the ES2 connects to the computation hosts or a subset thereof. The ES1 connects to the COM, and the ES2 connects to the MON. The computation hosts or a subset thereof provide first host critical application data (HCAD1) to the ES1, and the computation hosts or a subset thereof provide second host critical application data (HCAD2) to the ES2. The ES1 is configured to forward the HCAD1 as first end system critical application data (ESCAD1) to the COM and the ES2 is configured to forward the HCAD2 as second end system critical application data (ESCAD2) to the MON. The COM is configured to forward the ESCAD1 as commander critical application data (CCAD) to the COMP at a pre-configured commander forwarding point in time (TCOM), and the MON is configured to forward the ESCAD2 as monitor critical application data (MCAD) to the COMP at a pre-configured monitor forwarding point in time (TMON). If the MON and the COMP are not integrated into an integrated part, then the COMP is configured to forward either the CCAD or the MCAD as node critical application data (NCAD), if and only if, the CCAD and the MCAD are identical and the COMP starts to receive the CCAD and the MCAD within an interval of configured length (SYNC-1). Alternatively, if the MON and the COMP are integrated into an integrated part (MONC), then the COM is configured to forward the ESCAD1 as NCAD to the NET. The switch includes an interception function (INTERCEPT) which is configured to (i) preempt an ongoing transmission of NCAD and/or (ii) prevent the transmission of NCAD, and the COMP is configured to activate the interception function if and only if the CCAD and the MCAD are not identical or the COMP does not start to receive the CCAD and the MCAD within SYNC-1.


