Shared SPI Bus Arbiter for Fault-Tolerant Master Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional fault-tolerant process control systems fail when a single random hardware failure in a master process controller prevents the remaining healthy controller from accessing the SPI bus, leading to downtime, and require fully redundant SPI buses, increasing costs.

Innovation Solution

Implementing a shared SPI bus with dedicated bus switches controlled by an arbiter block, allowing only one master process controller to access the bus at a time, ensuring continued system functionality and reducing redundant bus requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional fault-tolerant process control system uses separate SPI buses for each master controller, then system reliability is improved through redundancy, but device complexity and cost increase due to requiring fully redundant SPI buses

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges two separate SPI buses into a single shared SPI bus that is time-multiplexed between two master controllers. Instead of having fully redundant separate buses, the system combines the communication resources into one shared infrastructure, reducing overall complexity while maintaining fault tolerance through arbitration-based access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces dynamic arbitration logic that dynamically assigns bus access rights to different master controllers based on operational needs and fault status. The arbiter block dynamically switches between masters, allowing the system to adapt to failures and maintain reliability without requiring static redundant pathways for every controller.

Inventive Principle:
Principle #15Dynamics

2Reliability

If a single random hardware failure in a master process controller occurs, then the healthy controller should continue operation, but the healthy controller is prevented from accessing the SPI bus in conventional systems

Engineering Contradiction:
Improvefault toleranceVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an arbiter block as an intermediary component that mediates access to the shared SPI bus between multiple master controllers. This arbiter ensures that when one master fails, the healthy master can still access the bus through the arbitration mechanism, preventing single points of failure from blocking system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The arbitration logic incorporates feedback mechanisms that monitor the status of master controllers and dynamically adjust bus access rights. When a failure is detected, the feedback signal triggers the arbiter to grant access to the healthy controller, ensuring continuous operation and maintaining productivity despite hardware failures.

Inventive Principle:
Principle #23Feedback

3Reliability

If fully redundant SPI buses are implemented in conventional systems, then fault tolerance is achieved, but system cost increases

Engineering Contradiction:
Improvefault toleranceVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes the single SPI bus universal by designing it to serve multiple master controllers through time-multiplexed access. The same physical bus infrastructure is shared across different controllers at different time intervals, eliminating the need for dedicated redundant buses for each controller and significantly reducing system cost while maintaining fault tolerance capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of permanently allocating redundant bus resources for each controller, the system discards the concept of dedicated redundancy and recovers resources by time-multiplexing a single bus across multiple controllers. The bus is recovered and reused for different masters at different times, reducing the total quantity of communication resources needed.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentEP3416061B1Multiple master process controllers using a shared serial peripheral bus
Publication Date: 2021.01.13 HONEYWELL INTERNATIONAL INC
  • EP3416061B1 patent drawingFigure 1
  • EP3416061B1 patent drawingFigure 2

AI summary

A fault-tolerant process control system 200 includes a first and second master process controller 110, 110' each including a first and second serial communication engine 117, 117'. A first bus switch 211 couples the first serial communication engine to a shared SPI bus 235 and a second bus switch 212 couples the second communication engine to shared SPI bus. The shared SPI bus transmits SPI signals received from the first serial communication engine when the first bus switch 211 is enabled to a first target device 120, and transmits SPI signals received from the second serial communication engine when the second bus switch 212 is enabled to a second target device 120'. An arbiter block 225 receives a select control signal from the master process controllers and is coupled to both the first and second bus switch for single bus switch selection so that only one master process controller is granted access to the shared SPI bus.