IP Library Granted Patent US 7,613,948
Granted Patent B2
US 7,613,948 · App. 12/033,408 · Granted Nov 3, 2009

Cache coherency during resynchronization of self-correcting computer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,613,948
App. No.
12/033,408
Granted
Nov 3, 2009
Kind
B2
Abstract

A fault-tolerant computer uses multiple commercial processors operating synchronously, i.e., in lock-step. In an exemplary embodiment, redundancy logic isolates the outputs of the processors from other computer components, so that the other components see only majority vote outputs of the processors. Processor resynchronization, initiated at predetermined time, milestones, and/or in response to processor faults, protects the computer from single event upsets. During resynchronization, processor state data is flushed and an instance of these data in accordance with processor majority vote is stored. Processor caches are flushed to update computer memory with more recent data stored in the caches. The caches are invalidated and disabled, and snooping is disabled. A controller is notified that snooping has been disabled. In response to the notification, the controller performs a hardware reset of the processors. The processors are loaded with the stored state data, and snooping and caches are enabled.

Claims (35)

1. The method of operating a fault-tolerant computer system with at least three processors, comprising steps of:

flushing out internal processor state data from processors of the plurality of processors;

determining an instance of the flushed out internal processor state data in accordance with processor majority vote;

storing the instance;

invalidating and disabling caches of the processors of the plurality of processors;

disabling snooping;

holding each processor of the plurality of processors with the instance;

enabling snooping;

enabling the caches of the processors of the plurality of processors; and

synchronously operating all processors of the at least three processors in parallel while determining processor majority vote of processor output signals;

wherein the step of enabling snooping is performed after initialization of the memory management units of the at least three processors following the step of holding.

2. The method of claim 1 , further comprising: flushing out the caches of the processors of the plurality of processors between the step of flushing out internal processor state data from processors of the plurality of processors and the step of invalidating.

3. The method of claim 1 , wherein the step of flushing out internal processor state data is performed at predetermined times.

4. The method of claim 1 , wherein the step of flushing out internal processor state data is performed at predetermined milestones.

5. The method of claim 1 , wherein the step of flushing out internal processor state data is performed at predetermined milestones of at least one software application executed by the computer system.

6. The method of claim 1 , wherein the step of flushing out internal processor state data is performed in response to a single event upset in at least one processor of the plurality of processors.

7. The method of claim 1 , wherein the step of flushing out internal processor state data is performed at predetermined intervals, further comprising:

shortening at least one of the intervals in response to an error in at least one processor of the plurality of processors.

8. The method of claim 1 , wherein the step of flushing out internal processor state data is performed in response to loss of synchronization of a first processor of the plurality of processors with respect to at least a second processor and a third processor of the plurality of processors.

9. The method of claim 1 , wherein the instance does not include data stored in the caches of the processors of the plurality of processors.

10. The method of claim 1 , wherein the instance includes all internal processor state data other than cache data stored in the caches of the processors of the plurality of processors.

11. A method of using a fault-tolerant computer system comprising at least three processors operating synchronously in parallel, wherein each processorr of the at least three processors comprise a memory management unit (MMU), the method comprising:

operating the at least three processors with enabled snooping by external devices;

step for processor resynchronization of the at least three processors; and

step for preventing snooping by the external devices while the at least three processors are coming out of reset caused by the step for processor resynchronization,

wherein the step fro preventing is performed until initialization of the memory management units of the at least three processors.

12. The method of claim 11 , wherein the step for processor resynchronization is performed after the step of operating.

13. The method of claim 11 , wherein the step for processor resynchronization is performed in response to a single event upset in the at least three processors.

14. The method of claim 11 , wherein the step for processor resynchronization is performed at predetermined times.

15. The method of claim 11 , wherein the step for processor resynchronization is performed at predetermined milestones.

16. A method of operating a fault-tolerant computer system comprising a plurality of processors operating in lock-step, the method comprising:

resynchronizing the processors;

preventing bus transactions while the processors of the plurality of processors are coming out of reset caused by the step of resynchronizing;

wherein the step of preventing comprises bypassing snooping, and

the step of preventing is performed at least until initialization of memory management units (MMUs) of the processors.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded May 24, 2019
From: EAST WEST BANK
To: MAXWELL TECHNOLOGIES, INC.
Reel/Frame 051441/0005 →
SECURITY AGREEMENT Recorded Aug 2, 2016
From: DATA DEVICE CORPORATION
To: CREDIT SUISSE AG, AS ADMINISTRATIVE AGENT
Reel/Frame 039537/0075 →
RELEASE OF SECURITY INTEREST Recorded Jun 23, 2016
From: GOLUB CAPITAL MARKETS LLC, FORMERLY KNOWN AS GCI CAPITAL MARKETS LLC, AS COLLATERAL AGENT
To: DATA DEVICE CORPORATION
Reel/Frame 038997/0516 →
SECURITY INTEREST Recorded May 19, 2016
From: DATA DEVICE CORPORATION
To: GCI CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 038652/0062 →
PATENT ASSIGNMENT Recorded May 4, 2016
From: MAXWELL TECHNOLOGIES, INC.
To: DATA DEVICE CORPORATION
Reel/Frame 038608/0509 →
RELEASE OF SECURITY INTEREST Recorded Apr 14, 2016
From: EAST WEST BANK
To: MAXWELL TECHNOLOGIES, INC.
Reel/Frame 038288/0495 →
ASSIGNEE CHANGE OF ADDRESS Recorded Feb 18, 2016
From: MAXWELL TECHNOLOGIES, INC.
To: MAXWELL TECHNOLOGIES, INC.
Reel/Frame 037856/0901 →
SECURITY INTEREST Recorded Jul 6, 2015
From: MAXWELL TECHNOLOGIES, INC.
To: EAST WEST BANK
Reel/Frame 036064/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2009
From: CONRAD, MARK S.; HILLMAN, ROBERT A.
To: MAXWELL TECHNOLOGIES, INC.
Reel/Frame 022360/0897 →