The invention provides a trusted redundant fault-tolerant computer 
system which aims at satisfying the requirement for high safety and high reliability of systems in 
safety control fields. The trusted redundant fault-tolerant computer 
system is capable of blocking the operation of illegal programs of malicious codes, viruses and the like, protecting the 
system and core applications from being destroyed, protecting important information from being revealed, stolen, tampered and ruined, and shielding faults by means of a failure switching function to enable the system to work normally when faults of the system occur. The trusted redundant fault-tolerant computer system is based on a trusted 
cryptography module (TCM) safety 
chip, and a dual-computer redundant hot standby method and a compact 
peripheral component interconnect (CPCI) 
bus framework are used. Two trusted computer subsystems are configured in a 
computer case, each of the trusted computer subsystems is composed of a trusted computer main module (including a TCM and a flash disk), a power source module, a flash disk expansion module and an interface expansion module, and the failure switching between the two subsystems is achieved through a 
heartbeat server and a failure switching module.