and
MTTF mf ¼
1
ð1 þ kÞk pf 1
ð16:2Þ
Figure 16.1 illustrates that impact of malfunctions k assumes 100 here, while in
reliability the malfunction rate is in the order of 5 higher than the ratio of permanent
faults.
Permanent fault is assumed at rate 10
−5 , k as above = 100.
Assuming that redundancy in the system is introduced for detection of fault
denoted as d, and recovery denoted as r, we claim that implemented checking
process and recovery process reduce impact of malfunction on the processor
reliability.
Clear a share of tolerable malfunction (success of detection and recovery) should
be taken into account; we denote a and it stands for success of malfunction
toleration.
P mft ¼ e
À 1¼d þ r
ð
Þ1 þ ak
ð
Þ k pf 1
ð16:3Þ
and
MTTF 2 ¼
1
1 þ d þ r
ð
Þ1 þ ak
ð
Þk pf 1
ð16:4Þ
Redundancy for checking (detection) d varies in various hardware schemes, and the
maximum redundancy to provide checking is 100%, or d = 1, when duplication of
the hardware is used to compare outputs.
Maximum power of fault detection is a privilege of duplication. Assuming the
same coefficient k of malfunction/permanent fault ratio, resulting reliability with the
implementation of fault tolerance proposed for ERRIC is shown in Fig. 16.2.
Fig. 16.1 Probability of system operation in the presence of malfunctions
216
16 ERRIC Reliability
MTTF mf ¼
1
ð1 þ kÞk pf 1
ð16:2Þ
Figure 16.1 illustrates that impact of malfunctions k assumes 100 here, while in
reliability the malfunction rate is in the order of 5 higher than the ratio of permanent
faults.
Permanent fault is assumed at rate 10
−5 , k as above = 100.
Assuming that redundancy in the system is introduced for detection of fault
denoted as d, and recovery denoted as r, we claim that implemented checking
process and recovery process reduce impact of malfunction on the processor
reliability.
Clear a share of tolerable malfunction (success of detection and recovery) should
be taken into account; we denote a and it stands for success of malfunction
toleration.
P mft ¼ e
À 1¼d þ r
ð
Þ1 þ ak
ð
Þ k pf 1
ð16:3Þ
and
MTTF 2 ¼
1
1 þ d þ r
ð
Þ1 þ ak
ð
Þk pf 1
ð16:4Þ
Redundancy for checking (detection) d varies in various hardware schemes, and the
maximum redundancy to provide checking is 100%, or d = 1, when duplication of
the hardware is used to compare outputs.
Maximum power of fault detection is a privilege of duplication. Assuming the
same coefficient k of malfunction/permanent fault ratio, resulting reliability with the
implementation of fault tolerance proposed for ERRIC is shown in Fig. 16.2.
Fig. 16.1 Probability of system operation in the presence of malfunctions
216
16 ERRIC Reliability
