High Integrity Computer Processing Module with Software Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional high integrity computer processing modules require expensive custom circuitry for instruction level lock-step processing, making it difficult to implement with modern microprocessors that have embedded memory controllers and input/output support, and impose design constraints on software applications.
Innovation Solution
A method for a computer processing module that detects and manages differences in output data across processing lanes, configures applications for high or normal integrity, and uses Time Management, Critical Regions Management, and data Input/Output Management units to ensure synchronization and fault containment, allowing the same software to run on both high and normal integrity modules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional instruction level lock-step processing is implemented, then high integrity is achieved, but device complexity and cost increase due to expensive custom circuitry
Solution Approach 1:
The patent uses software copying instead of hardware duplication. Identical software instances are executed on multiple general-purpose microprocessors, and their outputs are compared to detect faults. This eliminates the need for expensive custom circuitry while maintaining high integrity through software-based redundancy and comparison.
Solution Approach 2:
The patent replaces the mechanical/hardware-based lock-step processing with a software-based solution. Instead of using specialized hardware circuits to enforce synchronous execution, the system uses software configuration and management units to coordinate execution and detect faults, thereby reducing hardware complexity.
2Reliability
If instruction level lock-step processing is implemented, then high integrity is achieved, but adaptability decreases due to constraints on software applications
Solution Approach 1:
The patent introduces dynamic configuration capabilities where software applications can be selectively configured as high-integrity or normal-integrity based on their requirements. The system dynamically activates or deactivates management units and redundancy mechanisms for different applications, allowing flexibility while maintaining high integrity where needed.
Solution Approach 2:
The patent segments the system into multiple processing lanes, each capable of running independent software instances. Different applications can be assigned to different integrity levels and processing configurations, allowing some applications to use full high-integrity processing while others use normal processing, thereby increasing overall system adaptability.
3Speed
If high-speed microprocessors with embedded memory controllers and multiple PLLs are used, then processing speed is improved, but implementation difficulty increases for conventional high integrity designs
Solution Approach 1:
The patent makes the high-integrity system universal by designing it to work with standard general-purpose microprocessors that already have embedded memory controllers and multiple PLLs. The software-based approach allows these multi-functional processors to be used without requiring specialized hardware modifications, thereby easing implementation while maintaining high speed capability.
Data Source
AI summary
A method of providing high integrity checking for an N-lane computer processing module (Module), N being an integer greater than equal to two. The method comprises the steps of: detecting, by a data Output Management unit (OM), when any of the N processing lanes sends different output data; configuring each Hosted Application as either normal or high integrity; for the Hosted Applications configured as high integrity, running an identical version of the software source code targeted for similar or dissimilar microprocessors on all N processing lanes, and activating a Time Management Unit, Critical Regions Management Unit, data Input Management Unit and data Output Management Unit for each of the N processing lanes; and for the Hosted Applications configured as normal integrity, running a copy of the software on one of the N processing lanes, and not activating the Time Management Unit, Critical Regions Management Unit, Input Management Unit and Output Management Unit for the one activated processing lane while that Hosted Application is running.


