for both: malfunctions and permanent hardware faults. If it is possible to prove that
the software state was not affected by the fault or the recovery was successful, then
the processing is resumed.
According to Table 4.1, a system is fault tolerant if it completely implements
GAFT, i.e., all steps of GAFT. Every individual step can of course be implemented
in various ways with different properties. Thus, fault-tolerant systems may differ in
the following:
– GAFT steps execution time,
– Used redundancy types, and
– Tolerated fault types.
Table 4.1 enables the comparison, classification, and analysis of various solutions for fault-tolerant computer system implementations.
Note also that reliability, power consumption, cost, and maintenance as
requirements are usually predefined in the development of safety-critical, embedded, and RT systems.
It is therefore important to define the level of required redundancy, dependent on
the application, as a basis to design the system as “as reliable as possible” system
which is usually much too expensive to develop. GAFT and redundancy
Table 4.1 Template for the analysis of GAFT implementations
Step
Description
Redundancy types
HW
(I)
HW
(S)
HW
(T)
SW
(I)
SW
(S)
SW
(T)
0
PERIODICALLY DO Create
recovery point END
A
IF error is detected THEN
B
Determine the fault type
C
IF fault is permanent THEN
D
Locate faulty element
E
Reconfigure hardware
END
F
IF hardware has been
reconfigured OR software is
affected
G
Locate faulty software states
H
Recover software
I
IF hardware has been
reconfigured THEN
J
Reconfigure software
END
END
K
CONTINUE
4.1 The Generalized Algorithm of Fault Tolerance
29
Précédent

- 44/315

Suivant