Non-Lockstep High Integrity Processing via Transaction Replay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional high integrity processing systems require expensive custom circuitry for lockstep operation between microprocessors, which is not feasible due to increased component integration and variability in processing time, especially in critical applications like aircraft, where fault detection and isolation are paramount.

Innovation Solution

A method for synchronization and integrity checking in high integrity processing systems using redundant processing lanes that operate in a non-lockstep configuration, where transactions are compared for matching across processors to ensure data integrity without requiring identical processing times, allowing for dissimilar processors and reducing the need for lockstep operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If lockstep operation between microprocessors is implemented, then processing synchronization and integrity are improved, but device complexity and cost increase due to expensive custom circuitry

Engineering Contradiction:
Improveprocessing integrityVSAvoidcircuitry complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a buffer to store and replay transactions from one processing lane to another, creating a virtual copy of the processing sequence without requiring identical hardware execution. This allows integrity checking through transaction comparison while avoiding complex lockstep circuitry

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The buffer acts as an intermediary component that mediates between the two processing lanes. It stores transactions and enables comparison without requiring direct synchronized execution, simplifying the system architecture while maintaining integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If lockstep operation is used, then fault detection capability is improved, but processing speed deteriorates due to variability in processing time

Engineering Contradiction:
Improvefault detection capabilityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The buffer stores transactions in advance, allowing the system to replay and compare them later without requiring real-time synchronized execution. This decouples fault detection from processing speed constraints

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system allows processing lanes to operate at different speeds dynamically, using the buffer to accommodate timing variations. This enables modern microprocessors with variable execution times to maintain integrity without lockstep constraints

Inventive Principle:
Principle #15Dynamics

3Reliability

If custom circuitry is implemented for lockstep processing, then processing synchronization is improved, but manufacturing cost increases

Engineering Contradiction:
Improvesynchronization accuracyVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Instead of custom circuitry, the patent uses software-based transaction copying and replay through a buffer. This approach achieves synchronization using standard microprocessors, significantly reducing manufacturing costs

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/custom hardware lockstep circuitry with a software-based transaction buffer system. This substitution uses standard digital logic and memory resources instead of specialized custom circuitry

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9170907B2Method of providing high integrity processing
Publication Date: 2015.10.27 GE AVIATION SYSTEMS LLC
  • US9170907B2 patent drawing
  • US9170907B2 patent drawing
  • US9170907B2 patent drawing

AI summary

A method of providing synchronization and integrity checking in a high integrity processing system having at least two redundant processing lanes, with each lane having an application processor, with the application processors running the same application software in a non-lockstep configuration, and outputting transactions requiring access to an addressable space.