
In some circumstances, it is desirable to ensure the system continues to operate even if there is an internal failure. An aircraft navigation system should be able to operate even if an internal dc-dc regulator fails, for example.
Not everything within some systems benefits by being fault tolerant.
For example, a failure of a cabin reading light over a passenger seat is not critical to the safe operation of the aircraft, thus is likely not created to be fault tolerant. One criterion to determine what should be fault tolerant is the criticality of the function the system provides.
This also applies to specific subsystems within a system allowing some elements to be created fault tolerant and others within the system not. [Read more…]