Dissimilar Processor Self-Checking Network for Common-Mode Fault Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Self-checking processors are susceptible to common-mode faults that go undetected due to their complex hardware design, as both processors output identical incorrect data, requiring additional verification that increases performance demand and power consumption.
Innovation Solution
A self-checking network with two dissimilar processor pairs on a system-on-a-chip (SOC) device, including a command processor and a monitor processor, along with lockstep circuits and cross-side comparison logic, to detect faults common to both processors without increasing performance demand on the command processor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a self-checking processor uses two similar processors to detect faults, then faults can be detected when outputs differ, but common-mode faults affecting both processors similarly remain undetected
Solution Approach 1:
The patent introduces a dissimilar processor pair (second processor with different architecture or implementation) alongside the similar processor pair. This asymmetric configuration enables detection of common-mode faults by comparing outputs between the dissimilar processors, which would produce different expected outputs for the same input, thereby resolving the limitation of symmetric self-checking processors.
Solution Approach 2:
The patent divides the fault detection system into multiple independent processor pairs: a first similar processor pair for detecting random faults and a second dissimilar processor pair for detecting common-mode faults. This segmentation allows each pair to specialize in detecting specific fault types, improving overall reliability without requiring a single complex processor configuration to handle all fault types.
2Reliability
If an additional dissimilar processor is added to detect common-mode faults, then fault detection improves, but performance demand on similar processors increases
Solution Approach 1:
The dissimilar processor pair performs self-verification by comparing its own outputs against each other independently of the similar processor pair. This self-service mechanism allows the dissimilar processors to detect common-mode faults without requiring the similar processors to execute additional verification code, thereby improving reliability without increasing performance demand on the similar processors.
Solution Approach 2:
The dissimilar processor pair acts as an intermediary verification layer that independently monitors for common-mode faults. By introducing this intermediate verification mechanism, the system can detect faults without requiring the primary similar processors to perform additional self-verification, thus maintaining their performance while improving overall system reliability.
3Reliability
If additional verification processing is implemented on command processors, then fault detection improves, but power consumption increases
Solution Approach 1:
The patent segments the verification function across separate processor pairs: the similar processor pair handles random fault detection while the dissimilar processor pair handles common-mode fault detection. This segmentation allows verification to be distributed rather than concentrated on the command processors, reducing their power consumption while maintaining comprehensive fault detection capability.
Solution Approach 2:
The dissimilar processor pair performs verification of common-mode faults independently through self-comparison, eliminating the need for command processors to execute additional verification code. This self-service approach reduces the computational burden and power consumption of the command processors while improving overall verification accuracy.
Data Source
AI summary
A self-checking network is provided, comprising a first command processor configured to execute a performance function and a second command processor configured to execute the performance function, coupled to the first command processor. The self-checking network also comprises a first monitor processor configured to execute a monitor function that is coupled to the first command processor and a second monitor processor configured to execute the monitor function that is coupled to the second command processor. The first and second command processors compare outputs, the first and second monitor processors compare outputs, and the first monitor processor determines whether an output of the first command processor exceeds a first selected limit.


