SIFT - DESIGN AND ANALYSIS OF A FAULT-TOLERANT COMPUTER FOR AIRCRAFT CONTROL

被引:201
作者
WENSLEY, JH
LAMPORT, L
GOLDBERG, J
GREEN, MW
LEVITT, KN
MELLIARSMITH, PM
SHOSTAK, RE
WEINSTOCK, CB
机构
[1] SRI International, Menlo Park
关键词
D O I
10.1109/PROC.1978.11114
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
SIFT (Software Implemented Fault Tolerance) is an ultrareliable computer for critical aircraft control applications that achieves fault tolerance by the replication of tasks among processing units. The main processing units are off-the-shelf minicomputers, with standard microcomputers serving as the interface to the I/O system. Fault isolation is achieved by using a specially designed redundant bus system to interconnect the processing units. Error detection and analysis and system reconfiguration are performed by software. Iterative tasks are redundantly executed, and the results of each iteration are voted upon before being used. Thus, any single failure in a processing unit or bus can be tolerated with triplication of tasks, and subsequent failures can be tolerated after reconfiguration. Independent execution by separate processors means that the processors need only be loosely synchronized, and a novel fault-tolerant synchronization method is described. The SIFT software is highly structured and is formally specified using the SRI-developed SPECIAL language. The correctness of SIFT is to be proved using a hierarchy of formal models. A Markov model is used both to analyze the reliability of the system and to serve as the formal requirement for the SIFT design. Axioms are given to characterize the high-level behavior of the system, from which a correctness statement has been proved. An engineering test version of SIFT is currently being built. Copyright © 1978 by The Institute of Electrical and Electronics Engineers, Inc.
引用
收藏
页码:1240 / 1255
页数:16
相关论文
共 12 条
  • [1] Floyd Robert W., 1967, P S APPL MATH, V19, P19, DOI DOI 10.1090/PSAPM/019/0235771
  • [2] MELLIARSMITH PM, 1977, PERMISSIBLE PROCESSO
  • [3] MURRAY ND, 1977, INTEGRITY ELECTRONIC
  • [4] PEASE M, UNPUBLISHED
  • [5] Randell B., 1975, IEEE T SOFTWARE ENG, VSE-1, P220, DOI DOI 10.1109/TSE.1975.6312842
  • [6] RATNER RS, 1973, CR132253 NASA SRI IN, V2
  • [7] ROBINSON L, 1976, CURRENT TRENDS PROCE, V1
  • [8] ROBINSON L, 1977, CSL46 SRI INT TECHN
  • [9] SHOSTAK RE, 1977, 14TH P IEEE COMP SOC
  • [10] Wensley J. H., 1976, 2nd International Conference on Software Engineering, P458