40 Time-Triggered Communication
For active diagnosis, the diagnostic subsystem decides on an action to recover
from a fault. After a transient fault, a suitable action is a reset of the affected node
with a subsequent restoration of the state (cf. Section 3.6.4). After a permanent fault,
the services can be migrated to suitable spare nodes. Restrictions on the migration of
services result from the types of nodes (e.g., deployed processing cores, performance,
memory) and the management of physical inputs and outputs. In particular, inputs
and outputs introduce a strong coupling between application service and specific
nodes [92].
For decision making in active and passive diagnosis, different types of analy-
sis technologies are available, such as solutions ...