×

Selective disablement in fail-operational, fail-safe multi-computer control system

  • US 4,270,168 A
  • Filed: 08/31/1978
  • Issued: 05/26/1981
  • Est. Priority Date: 08/31/1978
  • Status: Expired due to Term
First Claim
Patent Images

1. A selective disablement, fail-operational, and fail-safe multi-computer process control system, comprising:

  • a plurality of computer systems;

    a data connection between each computer and at least one other one of said computers;

    each of said computer system comprising;

    a plurality of outputs for controlling related functions of said process;

    a plurality of inputs providing data manifestations related to the control of said process;

    a data link connected to said data connection for providing data communication with another of said computer systems;

    a disable connection between it and said another computer system; and

    program controlled means for providing a plurality of self tests including bit by bit tests of at least a portion of the memory related to an important portion of said process and providing a test fault manifestation in response to any of said self tests failing, reading in of data from said inputs and calculating results manifestations, receiving calculation result manifestations across said data link from said another computer system, comparing the calculation result manifestations of both computer systems and, in response to comparison thereof, providing said calculation result manifestation to said outputs, or alternatively providing an error manifestation if the two calculation result manifestations do not compare, disabling said computer system in response to one or more of said self test fault manifestations, providing a manifestation over said data link to indicate to said another computer system the fact of said computer system being disabled, registering the fact of said another computer system being disabled if provided thereto over said data link, by-passing the portion of said program for comparing calculations with said another computer system in response to a registered manifestation indicating that said another computer system has disabled itself, and forcing a disabled status in said computer system and said another computer system via said disable connection in response to said error manifestation concurrently with the absence of a registered manifestation indicating that said another computer system has disabled itself, whereby, if one computer system senses disagreement with another nondisabled computer system, such one computer system will disable itself and such another computer system.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×