The Startup Problem in Fault-Tolerant Time-Triggered Communication

The Startup Problem in Fault-Tolerant Time-Triggered Communication
复制标题

容错时间触发通信中的启动问题

DOI:
10.1109/dsn.2006.69
复制
发表时间:
2006
期刊:
International Conference on Dependable Systems and Networks (DSN'06)
影响因子:
--
通讯作者:
H. Kopetz
H. Kopetz
中科院分区:
--
文献类型:
--
作者:
W. Steiner;H. Kopetz

文献摘要

被引文献

相似文献

容错时间触发通信依赖于本地时钟的同步。启动问题是在系统通电后达到足够程度的同步的问题。这个问题的复杂程度自然取决于系统假设。本文中的系统假设是通过与汽车和航空行业合作伙伴的合作编写的。我们提出了一种通用的安全关键系统启动策略,从抽象的角度讨论了启动问题的解决方案。从这个抽象的角度出发,我们推导并分析了一种新的启动算法,该算法用于TTP/C研究衍生协议(LTTP)。我们还分析了FlexRay启动算法,并讨论了它在存在简单故障时的行为。分析是通过使用SAL模型检查器进行详尽的故障模拟来完成的。虽然LTTP被发现可以容忍一个节点的任意故障,但FlexRay的启动很容易受到简单故障模式的影响
Fault-tolerant time-triggered communication relies on the synchronization of local clocks. The startup problem is the problem of reaching a sufficient degree of synchronization after power-on of the system. The complexity of this problem naturally depends on the system assumptions. The system assumptions in this paper were compiled from cooperation with partners in the automotive and aeronautic industry. We present a general startup strategy for safety-critical systems that discusses the solution to the startup problem from an abstract point of view. From this abstract view we derive and analyze a new startup algorithm that is used in a TTP/C research derivative protocol (LTTP). We also analyze the FlexRay startup algorithm and discuss its behavior in presence of simple failures. The analyses were done by exhaustive fault simulation using the SAL model checker. While LTTP was found to tolerate the arbitrary failure of one node, the FlexRay startup shows to be vulnerable to simple failure modes