IP Library Granted Patent US 10,397,081
Granted Patent B2
US 10,397,081 · App. 15/188,029 · Granted Aug 27, 2019

Distributed real-time computer system and method for forcing fail-silent behavior of a distributed real-time computer system

Inventors: Stefan Poledna (Klosterneuburg, AT); Hermann Kopetz (Baden, AT)
Assignee: TTTech Auto AG
H04L43/0847G05B9/03G06F11/0709G06F11/1629H04L1/20H04L1/22H04L41/0659H04L67/10B60T2270/40G05B2219/24181G05B2219/24187G05B2219/24189
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,397,081
App. No.
15/188,029
Granted
Aug 27, 2019
Kind
B2
Abstract

The invention relates to a method for forcing fail-silent behavior of a periodically functioning, distributed real-time computer system, which real-time computer system comprises at least two redundant NSCFCUs. At the beginning of a frame, the at least two redundant NSCFCUs ( 110, 111 ) are supplied with the same input data, wherein each of the redundant NSCFCUs calculates a result, preferably by means of a deterministic algorithm, particularly from the input data, and wherein this result is packed into a CSDP with an end-to-end signature, and wherein the CSDPs of the NSCFCUs ( 110, 111 ) are transmitted to an SCFCU ( 130 ), and wherein the SCFCU ( 130 ) checks whether the bit patterns of the received CSDPs are identical, and, if disparity of the bit patterns is found, prevents further transmission of the CSDPs, particularly those CSDPs in which disparity was found. Furthermore, the invention relates to a periodically functioning, distributed real-time computer system.

Claims (21)

1. A method for forcing fail-silent behavior of a periodically functioning distributed real-time computer system, which can be connected with one or more sensor(s) ( 101 , 102 , 103 ), the real-time computer system comprises at least two redundant NSCFCUs (non-self-checking fault-containment units), the method comprising:

making available a global time by the distributed real-time computer system, which global time establishes a beginning of a frame;

supplying the at least two redundant NSCFCUs ( 110 , 111 ) with the same input data by the sensor(s) at the beginning of the frame;

calculating by each of the at least two redundant NSCFCUs a result by a deterministic algorithm from the input data by the sensor(s);

packing the result into a CSDP (closed signed data packet) with an end-to-end signature;

transmitting the CSDPs of the at least two redundant NSCFCUs ( 110 , 111 ) to an SCFCU (self-checking fault-containment unit) ( 130 ) at a tick of the global time that has been established a priori; and

checking by the SCFCU ( 130 ) whether bit patterns of the received CSDPs are identical, and, if a disparity of the bit patterns is found, preventing further transmission of the CSDPs in which the disparity was found.

2. The method of claim 1 , wherein the SCFCU ( 130 ) prevents further transmission of the other CSDP in the event that a CSDP is not received by one of the at least two redundant NSCFCUs ( 110 , 111 ).

3. The method of claim 1 , wherein the SCFCU ( 130 ) transmits a release signal to a transceiver ( 140 ) in the failure-free case by way of a control line ( 170 ), and, in the event of failure, shuts off or does not transmit the release signal, so that further transmission of the CSDPs to subsequent components by way of a communication channel ( 165 ) is prevented.

4. The method of claim 1 , wherein in the event of failure of the SCFCU ( 130 ), further transmission of the CSDPs to the subsequent components is prevented.

5. The method of claim 3 , wherein in the event of failure of the SCFCU ( 130 ) and thereby of the release signal on the control line ( 170 ), the transceiver ( 140 ) prevents further transmission of the CSDPs to the subsequent components by way of the communication channel ( 165 ) and transmission of the CSDPs to the subsequent components is prevented.

6. The method of claim 3 , wherein a time-controlled message relay unit ( 120 ) delays output of the CSDPs to the transceiver ( 140 ) until the SCFCU ( 130 ) has completed the comparison of the redundant CSDPs.

7. The method of claim 1 , wherein the SCFCU ( 130 ) transmits failure messages to a monitor component by way of a communication channel ( 167 ).

8. A periodically functioning distributed real-time computer system, which can be connected with one or more sensor(s) ( 101 , 102 , 103 ), the system comprising:

a global time is made available by the distributed real-time computer system, which global time establishes the beginning of a frame, wherein in order to force fail-silent behavior, the real-time computer system comprises at least two redundant NSCFCUs ( 110 , 111 ) and an SCFCU ( 130 ), wherein each sensor ( 101 , 102 , 103 ) is connected with each of the at least two redundant NSCFCUs ( 110 , 111 ) by way of at least one communication channel ( 150 ) in each instance, wherein the at least two redundant NSCFCUs ( 110 , 111 ), which are supplied with the same input data by the sensor(s) at the beginning of the frame, are set up for calculating a result, in each instance, by a deterministic algorithm, packing the result into a CSDP (closed signed data packet) with an end-to-end signature, wherein the SCFCU ( 130 ) is set up for receiving the CSDPs of the at least two redundant NSCFCUs ( 110 , 111 ) based on the same input data, and for checking whether the bit patterns of the received CSDPs are identical, and the SCFCU ( 130 ) is furthermore set up for preventing further transmission of the CSDPs if a disparity of the bit patterns was found of those CSDPs in which the disparity was found.

9. The real-time computer system of claim 8 , further comprising a distributor unit ( 120 ), wherein at least one of the of the at least two redundant NSCFCUs ( 110 ) is connected with the distributor unit ( 120 ) by way of a communication channel ( 160 ), and at least one of the at least two redundant NSCFCUs ( 111 ) is connected with the distributor unit ( 120 ) by way of a further communication channel ( 162 ).

10. The real-time computer system of claim 9 , further comprising a transceiver ( 140 ), wherein the distributor unit ( 120 ) is connected with the transceiver ( 140 ) by way of a communication channel ( 163 ), and with the SCFCU ( 130 ) by way of a communication channel ( 161 ), and wherein a control line ( 170 ) leads from the SCFCU ( 130 ) to the transceiver ( 140 ).

11. The real-time computer system of claim 9 , wherein a protocol converter ( 119 ) is disposed in a communication channel ( 160 ), which connects the at least one of the at least two redundant NSCFCUs ( 110 ) with the distributor unit ( 120 ).

12. The real-time computer system of claim 10 , wherein a protocol converter ( 119 ) is disposed in the communication channel ( 163 ), which connects the distributor unit ( 120 ) with the transceiver ( 140 ).

13. The real-time computer system of claim 8 , wherein the at least two redundant NSCFCUs ( 110 , 111 ) are combined in a physical unit ( 115 ).

14. The real-time computer system of claim 8 , wherein the distributor unit ( 120 ), the SCFCU ( 130 ), and the protocol converter ( 119 ) are combined in a physical unit ( 135 ).

Assignments (4)
CHANGE OF NAME Recorded Aug 4, 2026
From: TTTECH AUTO AG
To: TRUSTMOTION AUSTRIA GMBH
Reel/Frame 075519/0943 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2019
From: TTTECH COMPUTERTECHNIK AG
To: TTTECH AUTO AG
Reel/Frame 049021/0787 →
MERGER Recorded Sep 14, 2018
From: FTS COMPUTERTECHNIK GMBH
To: TTTECH COMPUTERTECHNIK AG
Reel/Frame 047648/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2016
From: POLEDNA, STEFAN; KOPETZ, HERMANN
To: FTS COMPUTERTECHNIK GMBH
Reel/Frame 039268/0273 →
Priority Claims (1)
AT 50528/2015 · Jun 23, 2015 · national
Continuity (1)
Related Publication 20160380858A1 · Dec 29, 2016