{"title":"系统结构对多微处理器控制系统安全性和可靠性的影响","authors":"R. C. Milnor, R. Washington","doi":"10.1109/VTC.1984.1623281","DOIUrl":null,"url":null,"abstract":"Surface Transportation Systems are progressively making more use of microprocessors in vital control system applications. We have examined three types of control system architecture: duplex, triplex and dual duplex. Expressions are derived for the rate of occurrence at the system level of total failures, unsafe failures and service interruptions. We find that the duplex system has the lowest rate of occurrence of unsafe failures and of failures requiring maintenance action. Either a triplex or dual-duplex system provides orders-of-magnitude better freedom from service interruption than a duplex system, which must shut down whenever one channel fails. Sample implementations are shown for each architecture. It is shown that a duplex system can be easily expanded to a dual-duplex system and that this may be the preferable route in many cases.","PeriodicalId":178210,"journal":{"name":"34th IEEE Vehicular Technology Conference","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1984-05-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Effects of system architecture on safety and reliability of multiple microprocessor control systems\",\"authors\":\"R. C. Milnor, R. Washington\",\"doi\":\"10.1109/VTC.1984.1623281\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Surface Transportation Systems are progressively making more use of microprocessors in vital control system applications. We have examined three types of control system architecture: duplex, triplex and dual duplex. Expressions are derived for the rate of occurrence at the system level of total failures, unsafe failures and service interruptions. We find that the duplex system has the lowest rate of occurrence of unsafe failures and of failures requiring maintenance action. Either a triplex or dual-duplex system provides orders-of-magnitude better freedom from service interruption than a duplex system, which must shut down whenever one channel fails. Sample implementations are shown for each architecture. It is shown that a duplex system can be easily expanded to a dual-duplex system and that this may be the preferable route in many cases.\",\"PeriodicalId\":178210,\"journal\":{\"name\":\"34th IEEE Vehicular Technology Conference\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1984-05-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"34th IEEE Vehicular Technology Conference\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/VTC.1984.1623281\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"34th IEEE Vehicular Technology Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/VTC.1984.1623281","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Effects of system architecture on safety and reliability of multiple microprocessor control systems
Surface Transportation Systems are progressively making more use of microprocessors in vital control system applications. We have examined three types of control system architecture: duplex, triplex and dual duplex. Expressions are derived for the rate of occurrence at the system level of total failures, unsafe failures and service interruptions. We find that the duplex system has the lowest rate of occurrence of unsafe failures and of failures requiring maintenance action. Either a triplex or dual-duplex system provides orders-of-magnitude better freedom from service interruption than a duplex system, which must shut down whenever one channel fails. Sample implementations are shown for each architecture. It is shown that a duplex system can be easily expanded to a dual-duplex system and that this may be the preferable route in many cases.