??? 05/28/08 09:34 Read: times |
#155215 - Irrespective.... Responding to: ???'s previous message |
I proposed a watchdog circuit that runs a relay to allow the changeover. Why would this not be a reasonable solution? Nevertheless, you need to understand the possible ways your controller could fail - otherwise how do you formulate a solution? As I mentioned, the controller could fail in a number of ways - not necessarily due to the microcontroller getting upset or dying but nevertheless the controller fails to control the temperature and may even fail in a way that might cause a dangerous condition. The 'usual' method is to perform a FMEA to identify failure points and to formulate the method of handling such failures. How do you think they design aeroplanes? |