
DESCRIPTION AND OPERATION
SECURITY FUNCTIONS
2 - 4
I-E96-213A
®
SECURITY FUNCTIONS
The hardware and software handle a variety of module security
functions that detect normal failures.
Hardware Module Security Functions
The hardware checks for illegal addresses, and monitors the
Machine Fault Timer and the slave expander bus clock.
The hardware detects illegal addresses in and above the MFC's
boundary of 16 megabytes. If the processor sources an illegal
address, the address decoding hardware detects it and gener-
ates a Bus Error. The front panel LEDs illuminate with the
error message.
The processor periodically resets the Machine Fault Timer
(MFT). If the timer is not reset, it expires. When this happens,
the MFC stops immediately and the Status LED turns solid
red.
The hardware also monitors the free running slave expander
bus clock. If a timeout occurs, the hardware generates an
interrupt or halt depending upon whether the MFC is a pri-
mary or backup.
Internal Software Security Functions
Two functions are handled by the internal software: Module
Diagnostics and Module Status Check.
Module diagnostics are done when the MFC is powered up. If a
problem is detected, the error is displayed on the front panel
LEDs and the module stops immediately.
As a background idle task, the Module Status Check con-
stantly verifies ROM and NVM checksums. If there is a discrep-
ancy in any ROM checksum, the front panel LEDs display the
error and the module stops immediately. If a discrepancy is
found in any NVM checksum (nonfatal NVM error), the module
continues to operate and the status LED flashes green. An
NVM error during the start-up generates an error and causes
LED to light red.
Control Software Security
The control software is responsible for Local I/O problems,
remote I/O problems, station problems, and redundancy
errors.