Multi-channel Control Switchover Logic for Microprocessor Fault Tolerance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic control systems in multi-channel configurations face challenges in seamlessly transitioning control between primary and backup microprocessors, particularly in scenarios involving failures or health issues, which can lead to unintended control conflicts and faults.

Innovation Solution

A method and configuration that allow primary and backup microprocessors to assess control states and take appropriate actions, including 'take/keep control' and 'give-up control' actions, using channel-in-control signals and health signals to prevent simultaneous control attempts and ensure fault-tolerant operation, with redundant logic systems to prevent single-point failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If primary and backup microprocessors operate independently without coordinated control logic, then each microprocessor can function autonomously, but control conflicts and simultaneous control attempts may occur leading to system faults

Engineering Contradiction:
Improveautonomous operation capabilityVSAvoidcontrol conflict prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The control logic evaluates multiple conditions before allowing a microprocessor to assume control, including checking whether the other microprocessor is already in control. This preliminary evaluation prevents simultaneous control attempts by ensuring that control transition only occurs when the target microprocessor is not currently controlling the device, thereby resolving the contradiction between autonomous operation and conflict prevention

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If simple failover logic is used for control transition, then the control system is easy to implement, but it cannot handle complex failure scenarios such as simultaneous failures or unrecoverable errors

Engineering Contradiction:
Improvecontrol logic simplicityVSAvoidfault tolerance capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The control logic is segmented into multiple independent condition evaluations, each handling a specific failure scenario. The system evaluates conditions such as primary controller failure, backup controller failure, simultaneous failures, and unrecoverable errors separately. This segmentation allows the relatively simple control logic to systematically handle complex failure scenarios by breaking them down into discrete, manageable decision points, thereby resolving the contradiction between simplicity and fault tolerance

Inventive Principle:
Principle #1Segmentation

3Reliability

If the system waits for primary controller recovery before failover, then normal operation is maintained, but control is lost during extended failure periods

Engineering Contradiction:
Improvenormal operation maintenanceVSAvoidcontrol unavailability duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The control logic dynamically adjusts the failover decision based on the recovery status of the primary controller. The system continuously evaluates whether the primary controller has recovered and whether the backup controller is available. This dynamic evaluation allows the system to maintain normal operation with the primary controller when possible, while seamlessly transitioning to backup control when the primary controller fails to recover, thereby resolving the contradiction between maintaining normal operation and preventing control loss

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10747186B2Multi-channel control switchover logic
Publication Date: 2020.08.18 HAMILTON SUNDSTRAND CORP
  • US10747186B2 patent drawing
  • US10747186B2 patent drawing
  • US10747186B2 patent drawing

AI summary

A multi-channel control system includes at least a primary control microprocessor and a back-up control microprocessor operable to control a device. The primary control microprocessor and the back-up control microprocessor assert control over a controlled device according to a locally stored method of controlling a back-up microprocessor assumption of control of a device.