15.11.2012 Views

Integrated and Modular Systems for Commercial ... - Nonstop Systems

Integrated and Modular Systems for Commercial ... - Nonstop Systems

Integrated and Modular Systems for Commercial ... - Nonstop Systems

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Redundancy<br />

• Attributes:<br />

� <strong>for</strong>m (physical, temporal, per<strong>for</strong>mance, data,<br />

analytical)<br />

� similarity/diversity*<br />

� level of replication<br />

� physical distribution within a/c<br />

� allocation along end-to-end path<br />

� configuration (grouping & interconnects)<br />

� redundancy management concept (static, dynamic)<br />

- more resources that required <strong>for</strong> fault-free single-thread operation -<br />

* Notes:<br />

- dissimilarity’s power is based on assumption that it makes simultaneous common-mode (generic) faults extremely improbable<br />

- dissimilarity does not reduce the probability of simultaneous r<strong>and</strong>om faults<br />

- dissimilarity provides little advantage against common-mode environmental faults (EMI, temp/vibe, power)<br />

- dissimilarity allows shift away from proving absence of generic faults, to demonstrating ability to survive them (cert. level!)<br />

- dissimilarity of design drives source of faults back to (common) requirements <strong>and</strong> system architecture<br />

- dissimilarity is fault avoidance tool, as long as independence is not compromised when fixing ambiguities or divergence<br />

37<br />

©1995-1997 F.M.G. Dörenberg

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!