ABSTRACT

Safe computers are mainly constructed using several subsystems and complex diagnostic procedures. They consist at least of two independent sub-systems (channels), where self tests and cross-checking of the channels is used to detect failures, also safety relevant ones. Not each failure can be detected, even with the best diagnostics. This also holds for safety critical failures.