System Descriptions: Fail-safe
To prevent improper operation, the multiplex control system has a fail-safe function. In the fail-safe mode, the output signal is stopped when any part of the system malfunctions (for example, a faulty control unit or communication line).
Each control unit has a hardware fail-safe function that stops the output signal when there is any CPU malfunction, and a software fail-safe function that ignores the signal from the malfunctioning control unit and allows part of the system with no defect to operate normally.