INTERACTIVE CONSISTENCY AND ITS IMPACT ON THE DESIGN IN TMR SYSTEMS
S.G. Frison, John H. Wensley · 2005
It is well known that in a TMR system it is not possible to guarantee correct operation in situations where correctly functioning processors can legitimately have diffeiing results and where one faulty procesbor carries out a pattern of activity that confuses the two correctly functioning processors. The paper analyzes this general problem as it applies to certain design issues that arise in building a fault tolerant TMR system. The issues addressed are synchronization, the processing of analog data, and the handling of interrupts. It is shown that certain simplistic solutions that have been applied in the past fail to provide a guarantee of complete coverage of faults. Approaches are described that, while not guaranteeing absolute fault tolerance, can be shown to provide fault tolerance except against an extremely unlikely pattern of behavior of a faulty processor.