Invention Grant
- Patent Title: Fault-tolerant system architecture for the control of a physical system, in particular a machine or a motor vehicle
-
Application No.: US15440449Application Date: 2017-02-23
-
Publication No.: US10324797B2Publication Date: 2019-06-18
- Inventor: Hermann Kopetz
- Applicant: FTS COMPUTERTECHNIK GMBH
- Applicant Address: AT Vienna
- Assignee: TTTech Auto AG
- Current Assignee: TTTech Auto AG
- Current Assignee Address: AT Vienna
- Agency: Eversheds Sutherland (US) LLP
- Priority: ATA50142/2016 20160226
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F11/14 ; H04L12/24 ; H04L29/08 ; G05B19/04 ; G06F11/20 ; G06F11/16 ; G06F11/18

Abstract:
A fault-tolerant distributed real-time computer system for controlling a physical system, in particular a machine or a motor vehicle, wherein the components of the computer system have access to a global time of known precision, and wherein the node computers and intelligent sensors and the intelligent actuators exchange time-triggered messages and event-triggered messages periodically via the distributor units, and wherein the functions of the user software are contained in real-time software components—RTSC—and the periodic time-triggered data transfer between the RTSC is specified by a time-triggered data flow diagram, and wherein the assignment of the RTSC to a TTVM of a node computer and specific parameters of the TTVM are contained in active local allocation plans for each RTSC, and wherein the time plans for the time-triggered communication in this distributor unit are contained in active local allocation plans for each distributor unit, and wherein a global allocation plan consists of the totality of the local allocation plans, which are adapted to one another, of all RTSC and all distributor units of the user software, and wherein a monitor component periodically receives a copy of messages of the node computers to define the present operating state of the node computers, and wherein after the permanent failure of one or more RTSC, the monitor component activates a passive global allocation plan which specifies the allocation of the RTSC and the data supply thereof on newly installed TTVMs to the still functional node computers, and wherein the RTSC arrive at the newly configured TTVMs for execution at the provided periodic restart point in time in accordance with the selected passive global allocation plan.
Public/Granted literature
Information query