Fault-tolerant failsafe computer system using COTS components
First Claim
1. A system comprising:
- a safety relevant component that generates a data packet in response to receiving a request to perform a task and that communicates the data packet;
a first fail-safe chassis (FSC) that;
continuously generates a first chassis health signal;
determines whether the data packet is valid; and
selectively determines whether to de-assert the first chassis health signal based on the determination;
a second FSC that;
continuously generates a second chassis health signal;
determines whether a copy of the data packet is valid; and
selectively determines whether to de-assert the second chassis health signal based on the determination; and
a safety relay box module that determines whether to instruct the first FSC to operate in a predetermined mode based on the first chassis health signal and the second chassis health signal.
8 Assignments
0 Petitions
Accused Products
Abstract
A system includes a safety relevant component that generates a data packet in response to receiving a request to perform a task and that communicates the data packet. The system further includes a first fail-safe chassis (FSC) that continuously generates a first chassis health signal, that determines whether the data packet is valid, and that selectively determines whether to de-assert the first chassis health signal based on the determination. The system also includes a second FSC that continuously generates a second chassis health signal, that determines whether a copy of the data packet is valid, and that selectively determines whether to de-assert the second chassis health signal based on the determination. The system further includes a safety relay box module that determines whether to instruct the first FSC to operate in a predetermined mode based on the first chassis health signal and the second chassis health signal.
3 Citations
20 Claims
-
1. A system comprising:
-
a safety relevant component that generates a data packet in response to receiving a request to perform a task and that communicates the data packet; a first fail-safe chassis (FSC) that; continuously generates a first chassis health signal; determines whether the data packet is valid; and selectively determines whether to de-assert the first chassis health signal based on the determination; a second FSC that; continuously generates a second chassis health signal; determines whether a copy of the data packet is valid; and selectively determines whether to de-assert the second chassis health signal based on the determination; and a safety relay box module that determines whether to instruct the first FSC to operate in a predetermined mode based on the first chassis health signal and the second chassis health signal. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A method comprising:
-
generating a data packet in response to receiving a request to perform a task; communicating the data packet; continuously generating a first chassis health signal; determining whether the data packet is valid; selectively determining whether to de-assert the first health chassis signal based on the determination; continuously generating a second chassis health signal; determining whether a copy of the data packet is valid; selectively determining whether to de-assert the second health chassis signal based on the determination; and determining whether to instruct a first FSC to operate in a predetermined mode based on the first chassis health signal and the second chassis health signal. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification