with
G ¼
P 00 k 1 ; l; Dt
m
i
P 0 k 2 ; Dt
m
i
P 0 k; t rb m
ð
Þ if T P
i \t beg m
P 0 ðk; Dt
0 m
i
if T P
i ! t beg m
8
> > <
> > :
The total time needed to perform a recovery with depth m is
T P
m ¼ T þ d 1 þ ðm þ 1Þ T þ d
0
ð
ÞþmðT þ dÞ
ð 10:17Þ
where d′ is the time needed to create a new RP and to compare the content of the
new and former RP (d′ ( d if checksums are used).
The recovery times (Eq. 10.3) are determined as follows:
T beg m ¼ T þ d i þ mðT þ d
0 Þ
ð 10:18Þ
T rb m ¼ T þ d
0 þ mðT þ dÞ
Denote Dt
0 m
n
the time difference between the termination of recovery step
m and i:
Dt
0 m
n
¼ T P
m À T P
i
The probability of successful recovery with depth m in the case of a latent
malfunction with latency period l is
P k m ðlÞ ¼ 1 À a k
ð
ÞP 00 k 1 ; l; T; t beg m ðlÞ
À
Á
P 0 k 2 ; t beg m ðlÞ
À
Á
P 0 k; t rb m
ð
ÞÀ
X mÀ1
i¼l þ 2
P k i ðlÞG
ð10:19Þ
with m = 2, …, N and
t begmðlÞ ¼ t begm þ l T þ d
ð
Þ
ð10:20Þ
The probability of successful recovery with depth m is determined in case of a
latent malfunction from Eq. 10.7.
The probability of a system restart in case of non-latent and latent malfunctions
and the mean time of successful termination are found as in the case of linear
recovery from Eqs. 10.4, 10.8, 10.9, respectively.
10.5 Modified Linear Recovery
161
Précédent

- 174/315

Suivant