Redundant Server Lockstep Control for Failed Part Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In redundant systems implementing lockstep operations, it is challenging to restore the system to a duplexed operation by simply falling back a failed part, as existing methods fail to maintain synchronization and redundancy effectively.
Innovation Solution
A redundant system control method that involves separating the failed redundant server, preparing for restoration to a duplexed operation, and resuming a lockstep operation from initialization processing using synchronous reset, allowing the system to recover with a configuration that has fallen back the failed part.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the failed system is separated and only the normal system continues operation, then system reliability is maintained, but redundancy is lost and the system will stop if another failure occurs
Solution Approach 1:
The system dynamically switches between lockstep operation mode (both systems operating identically) and degraded operation mode (only normal system operating). This dynamic adaptation allows the system to maintain reliability during failures while preserving redundancy for future failures, resolving the contradiction between reliability and adaptability.
Solution Approach 2:
The system changes its operational parameters by transitioning from synchronous lockstep mode to asynchronous degraded mode. In degraded mode, the normal system can operate independently while the failed system remains part of the configuration, allowing redundancy to be preserved without compromising reliability.
2Ease of repair
If the failed system and normal system perform different operations, then the failed part can be separated, but in a lockstep operation system it is unlikely that the two systems perform different operations
Solution Approach 1:
The system segments the operational modes into distinct phases: lockstep mode for normal operation and degraded mode for failure handling. This segmentation allows the system to separate the failed part logically while maintaining the lockstep constraint during normal operation, resolving the contradiction between ease of repair and ease of operation.
Solution Approach 2:
The system dynamically transitions between operational modes based on system state. During lockstep operation, both systems perform identical operations. Upon failure detection, the system transitions to degraded mode where the normal system operates independently, enabling failed part separation while respecting lockstep constraints during normal operation.
3Adaptability or versatility
If the system restores to duplexed operation by falling back a failed part, then redundancy is restored, but maintaining synchronization in lockstep systems is challenging
Solution Approach 1:
The system performs preliminary actions by maintaining configuration information about both lockstep and degraded modes. When failure occurs, the system has pre-prepared the transition path to degraded mode and can restore to duplexed operation by falling back the failed part without complex real-time synchronization challenges, as the restoration follows a predetermined procedure.
Data Source
AI summary
The redundant system includes a redundant server of a first system and a redundant server of a second system. The redundant servers of the first system and the second system operate in lockstep. When a failure occurs in the redundant server of the second system, the redundant server of the first system separates the redundant server of the second system in which the failure has occurred and continues the operation, and then prepares for restoration to a duplexed operation with a configuration in which the failed part is fallen back. When the preparation is completed, both redundant servers of the first system and the second system start a lockstep operation from initialization processing by synchronous reset, and resume the duplexed operation with the configuration in which the failed part is fallen back.


