7.1 Hardware-Checking Process
Consider a sequence of tests and programs denoted as T and P in Fig. 7.1. The
initial test T is executed before a task execution and guarantees the hardware
consistency and integrity, i.e., it confirms that there is no hardware fault at that time
in the system.
However, if a permanent fault happens, for example, a “stuck bit”, the effect of
the fault is basically permanent. When a permanent fault occurs immediately after
the first test or during the program execution, it might be in principle invisible for
an arbitrary long time (latent period).
Therefore, a second sequential test is required right after the program execution
to guarantee that no permanent fault occurred since the last test. For periodic tasks
which are often used in control systems, we slightly adapt this scheme as shown in
Fig. 7.2.
But what happens if a malfunction occurs during the execution of program P?
The effect of the malfunction might not last until P finishes and T, therefore, cannot
detect the fault, leaving the malfunction undetected at all.
Malfunctions can be detected by double execution of the same program with
comparison C of the result and the result state space. Figure 7.3 illustrates this
scenario.
It is important to note that for periodic tasks, the persistent state of the program,
i.e., the program state which is used in the next computation as input data must also
be compared, as malfunctions might affect data which is no longer used in the
current computation but in the next.
Fig. 7.1 Ensuring of hardware integrity through program execution
Fig. 7.2 Regular sequence of program with test of hardware integrity to detect permanent faults
Fig. 7.3 Ensuring the hardware integrity to detect malfunction faults
72
7 Testing, Checking, and Hardware Syndrome
Consider a sequence of tests and programs denoted as T and P in Fig. 7.1. The
initial test T is executed before a task execution and guarantees the hardware
consistency and integrity, i.e., it confirms that there is no hardware fault at that time
in the system.
However, if a permanent fault happens, for example, a “stuck bit”, the effect of
the fault is basically permanent. When a permanent fault occurs immediately after
the first test or during the program execution, it might be in principle invisible for
an arbitrary long time (latent period).
Therefore, a second sequential test is required right after the program execution
to guarantee that no permanent fault occurred since the last test. For periodic tasks
which are often used in control systems, we slightly adapt this scheme as shown in
Fig. 7.2.
But what happens if a malfunction occurs during the execution of program P?
The effect of the malfunction might not last until P finishes and T, therefore, cannot
detect the fault, leaving the malfunction undetected at all.
Malfunctions can be detected by double execution of the same program with
comparison C of the result and the result state space. Figure 7.3 illustrates this
scenario.
It is important to note that for periodic tasks, the persistent state of the program,
i.e., the program state which is used in the next computation as input data must also
be compared, as malfunctions might affect data which is no longer used in the
current computation but in the next.
Fig. 7.1 Ensuring of hardware integrity through program execution
Fig. 7.2 Regular sequence of program with test of hardware integrity to detect permanent faults
Fig. 7.3 Ensuring the hardware integrity to detect malfunction faults
72
7 Testing, Checking, and Hardware Syndrome
