MooN Voting for Redundant Computing Instance Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing railroad automation systems face challenges in maintaining operational reliability and safety during error detection, leading to train delays due to hardware requirements and unreliable error detection methods, which result in system reinitialization and disruption.

Innovation Solution

A method utilizing an MooN voting system to execute application programs redundantly, comparing results, excluding minority results, generating a state copy, and reintegrating affected computing instances after reinitialization to maintain process continuity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application programs are executed redundantly in multiple computing instances with MooN voting, then error detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveerror detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the computing workload into multiple independent computing instances (N instances), each executing the same application program separately. This segmentation allows the voting mechanism to compare results from independent executions, improving error detection while keeping each individual instance relatively simple.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computing instances serve multiple functions: they execute application programs normally during regular operation, participate in voting for error detection, and can be dynamically excluded or reintegrated based on error detection results. This multi-functionality reduces the need for separate dedicated error detection hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If computing instances are excluded and reinitialized upon error detection, then operational reliability is improved, but system downtime increases

Engineering Contradiction:
Improveoperational reliabilityVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates a state copy (snapshot) of the computing instance before exclusion. This preliminary action preserves the instance's state, allowing it to be quickly restored and reintegrated without full reinitialization, thereby reducing system downtime while maintaining reliability through error isolation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of destroying or fully reinitializing the affected computing instance, the system creates a copy of its state and uses this copy for restoration. This copying approach enables faster recovery compared to complete reinitialization, reducing the time loss while still ensuring operational reliability through the exclusion and reintegration process.

Inventive Principle:
Principle #26Copying

3Reliability

If all computing instances are reinitialized upon error detection, then system safety is improved, but productivity decreases

Engineering Contradiction:
Improvesystem safetyVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the affected computing instance from the system upon error detection, excluding it from further voting and operation. The remaining N-1 instances continue to operate and process requests normally. This selective extraction maintains system safety by isolating the error while preserving productivity through continued operation of the unaffected instances.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system ensures continuous operation by having the remaining computing instances continue to execute application programs and process requests without interruption. The excluded instance is restored in the background, and once synchronized, is reintegrated to resume full system capacity. This maintains productivity throughout the error handling process.

Inventive Principle:
Principle #20Continuity of useful action

4Reliability

If redundant execution and voting are implemented, then error detection reliability is improved, but hardware requirements and cost increase

Engineering Contradiction:
Improveerror detection reliabilityVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system merges the error detection function with the normal computation function by having the same computing instances perform both tasks. The voting mechanism utilizes the existing computational results from redundant executions rather than requiring separate dedicated error detection hardware, thereby reducing overall hardware requirements while maintaining error detection reliability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12443473B2Method for performing a technical process in regular operation and repair operation
Publication Date: 2025.10.14 SIEMENS MOBILITY GMBH
  • US12443473B2 patent drawing
  • US12443473B2 patent drawing
  • US12443473B2 patent drawing

AI summary

A method for performing a technical process in which application programs are executed redundantly in a plurality N of computing instances and, on the basis of an MooN system, wherein M is at least two and N is at least three, a comparison of the plurality N of results of the redundant execution of the application programs is performed in a voting. When a minority of the results is different from a majority of the results with identical content, the minority is excluded during the performance of the technical process, is repaired with a state copy of one of the intact computing instances and reintegrated into the process. There is also described a computer program product and a provisioning apparatus.