| CPC H04L 12/40 (2013.01) [G05D 1/0077 (2013.01); H04L 2012/40273 (2013.01)] | 20 Claims | 

| 
               1. A method implemented in a safety-critical system to enable continued safe operations with failed components, the method comprising: 
            monitoring at least three components of the safety-critical system for output communicated over a system bus, the at least three components configured to produce the output indicative of a same event independently from the other components by using different input information than the other components; 
                comparing the outputs of the at least three components to determine whether each of the outputs indicates occurrence of the same event; 
                responsive to determining that a different output of one component does not indicate the occurrence of the same event as the outputs of the other components that do indicate the occurrence of the same event, identifying the one component as having failed; and 
                using the outputs of the other components to continue the safe operations of the safety-critical system without using the different output of the failed component. 
               |