Control methods for clustered hot standby redundancy systems and trains
By automatically switching between primary and backup systems based on device attributes and command operation status, the problem of low availability of redundant systems during initial operation or primary system failure is solved, and high availability of clustered hot standby redundant systems is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CRRC QINGDAO SIFANG CO LTD
- Filing Date
- 2024-11-15
- Publication Date
- 2026-07-03
AI Technical Summary
When the redundant system is just starting up or when the primary system fails, the backup system cannot automatically upgrade to the primary system, resulting in low availability of the redundant system.
Based on the device attributes and command operation status of the target device, the system automatically performs primary and backup system switching, including determining the priority or command operation status of the device in the clustered hot standby redundancy system, and performing primary and backup switching according to the priority or command operation status.
This enables the clustered hot standby redundant system to automatically switch between primary and backup systems when the redundant system just starts running or when the primary system fails, thus improving system availability.
Smart Images

Figure CN119705564B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the fields of vehicle control technology and communication, and more specifically, to a control method for a clustered hot standby redundancy system and a train. Background Technology
[0002] Trains typically employ redundant systems, consisting of a primary system and multiple backup systems. In the event of a primary system malfunction, one backup system's operating status is changed to that of the primary system, allowing it to continue operating. However, manual intervention is required to reset the primary system's status when the redundant system is first operational or when the primary system fails. Without manual intervention, none of the backup systems can acquire primary system access.
[0003] In realizing the present invention, the inventors discovered that the related technology has at least the following problems: when the redundant system starts running or when the main system fails, the backup system cannot automatically upgrade to the main system, resulting in low availability of the redundant system. Summary of the Invention
[0004] In view of this, this disclosure provides a control method and train for a clustered hot standby redundancy system.
[0005] One aspect of this disclosure provides a control method for a clustered hot standby redundancy system, comprising: determining the priority of the target system to which the target device belongs or the instruction operation status of the target device in the clustered hot standby redundancy system according to the device attributes of the target device, wherein the target system includes multiple devices, the clustered hot standby redundancy system includes multiple systems, the multiple systems are classified into a master system and a hot standby system, the master system is used to manage the communication data of the train, and the hot standby system is used to back up the communication data; and performing master-slave switching of the target system according to the priority or instruction operation status.
[0006] According to embodiments of this disclosure, device attributes include master devices and slave devices; determining the priority or instruction execution status of the target system to which the target device belongs in the cluster system based on the device attributes of the target device includes: determining the priority of the target system to which the target device belongs in the cluster system in response to the device attribute of the target device being a master device; or determining the instruction execution status of the target device in response to the device attribute of the target device being a slave device.
[0007] According to embodiments of this disclosure, performing a master-slave switchover on the system to which the target device belongs, based on priority or instruction running status, includes: responding to the target device's device attribute being a master device, performing a master-slave switchover on the target system according to the priority and operating status of each system in the clustered hot standby redundancy system; or responding to the target device's device attribute being a slave device, performing a master-slave switchover on the target system according to the instruction running status of the target device.
[0008] According to embodiments of this disclosure, in response to the target device's device attribute being a slave device, performing a master-slave switchover of the target system based on the target device's instruction operating state includes: in response to the target device's device attribute being a slave device, detecting the operating state of the master device in the target system through the target device's operating data to obtain a first detection result of the master device; in response to the first detection result indicating an abnormality in the master device's operating state, adjusting the master device's instruction operating state to switch the target system's system state to a hot standby system state, and controlling the instruction state to control communication of the target system in a clustered hot standby redundant system.
[0009] According to embodiments of this disclosure, in response to the device attribute of the target device being a master device, performing master-slave switching of the target system based on the priority and operating status of each system in the clustered hot standby redundancy system includes: in response to the device attribute of the target device being a master device, determining the system status of the target system; and performing master-slave switching of the target system based on the system status of the target system and the priority and operating status of each system in the clustered hot standby redundancy system.
[0010] According to embodiments of this disclosure, the system state includes an initialization state, a main system state, and a hot standby system state. The initialization state is the state in which the system in a clustered hot standby redundant system has completed file configuration.
[0011] According to embodiments of this disclosure, the primary / standby switchover of the target system based on the system state of the target system and the priorities and operating states of each system in the clustered hot standby redundancy system includes: in response to the target system being in an initialization state or a hot standby system state, performing a primary / standby switchover of the target system based on the priority of the target system and the operating states of each system in the clustered hot standby redundancy system; in response to the target system being in a primary system state and operating state being abnormal, switching the target system's system state to a hot standby system state; and in response to the target system's operating time in the primary system state not meeting a time threshold and the existence of a system in the clustered hot standby redundancy system meeting a first preset condition, switching the target system's system state to a hot standby system state, wherein the first preset condition is that the system state is in a primary system state, the priority meets a first preset threshold, and the operating state is normal.
[0012] According to an embodiment of this disclosure, in response to the target system's system state being a master system state and its operating state being abnormal, switching the target system's system state to a hot standby system state includes: in response to the target system's system state being a master system state, detecting the operating state of the slave device in the target system through the master system's operating data to obtain a second detection result of the master device; and in response to the second detection result indicating that the slave device's operating state is abnormal, switching the target system's system state to a hot standby system state.
[0013] According to embodiments of this disclosure, in response to the target system being in an initialization state or a hot standby system, the primary / standby switchover of the target system, based on the priority of the target system and the operating status of each system in the clustered hot standby redundancy system, includes: in response to the target system being in an initialization state and the existence of a primary system in the clustered hot standby redundancy system with a normal operating status, comparing the priority of the target system with the priority of the primary system to obtain a comparison result; performing a primary / standby switchover of the target system based on the comparison result; in response to the target system being in an initialization state and the existence of a primary system in the clustered hot standby redundancy system with an operating time meeting a time threshold, switching the target system's system state to a hot standby system state; in response to the target system being in a hot standby system state and the systems in the clustered hot standby redundancy system other than the target system meeting a second preset condition, switching the target system's system state to a primary system state, the second preset condition including priority meeting a second threshold or an abnormal operating status.
[0014] Another aspect of this disclosure provides a train equipped with a clustered hot standby redundancy system controlled by performing any of the methods described above, the clustered hot standby redundancy system being used to manage the train's communication data.
[0015] Another aspect of this disclosure provides a control device for a clustered hot standby redundancy system, comprising: a first determining module, configured to determine the priority of the target system to which the target device belongs in the clustered hot standby redundancy system or the instruction operation status of the target device according to the device attributes of the target device, wherein the target system includes multiple devices, the clustered hot standby redundancy system includes multiple systems, the multiple systems are classified into a master system and a hot standby system, the master system is used to manage the communication data of the train, and the hot standby system is used to back up the communication data; and a master-standby switching module, configured to perform master-standby switching of the target system according to the priority or instruction operation status.
[0016] Another aspect of this disclosure provides an electronic device comprising:
[0017] One or more processors;
[0018] Memory, used to store one or more programs.
[0019] When the one or more programs are executed by the one or more processors, the one or more processors implement the method described above.
[0020] Another aspect of this disclosure provides a computer-readable storage medium storing computer-executable instructions that, when executed, are used to implement the method described above.
[0021] Another aspect of this disclosure provides a computer program product including computer-executable instructions that, when executed, are used to implement the method described above.
[0022] According to embodiments of this disclosure, the priority or command operation status of the target system to which the target device belongs in the clustered hot standby redundancy system is determined based on the device attributes of the target device; then, the target system is switched from primary to standby based on the priority or command operation status. Even when the redundant system has just started running or when the primary system fails, each system in the clustered hot standby redundancy system can automatically switch from primary to standby, resulting in high availability of the clustered hot standby redundancy system. Attached Figure Description
[0023] The above and other objects, features and advantages of this disclosure will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0024] Figure 1 This schematically illustrates a system architecture diagram of a control method applicable to a clustered hot standby redundant system according to embodiments of the present disclosure.
[0025] Figure 2 A flowchart illustrating a control method for a clustered hot standby redundancy system according to an embodiment of the present disclosure is shown schematically.
[0026] Figure 3A A flowchart illustrating a control method for a clustered hot standby redundancy system according to an embodiment of the present disclosure is shown schematically.
[0027] Figure 3B A flowchart illustrating a control method for a clustered hot standby redundancy system according to another embodiment of the present disclosure is shown schematically.
[0028] Figure 4 This schematically illustrates a flowchart of a process for switching a target system to a master / slave state based on the instruction execution state of the target device, in response to the device attribute of the target device being a slave device, according to an embodiment of the present disclosure.
[0029] Figure 5 This illustration schematically shows a scenario in which, in response to the device attribute of the target device being the master device, the target system is switched over to a master device based on the priority and operating status of each system in the clustered hot standby redundancy system, according to an embodiment of the present disclosure.
[0030] Figure 6 A block diagram of the control apparatus for a clustered hot standby redundancy system according to an embodiment of the present disclosure is shown schematically.
[0031] Figure 7A block diagram of an electronic device suitable for implementing the control method of the clustered hot standby redundant system described above, according to an embodiment of the present disclosure, is shown schematically. Detailed Implementation
[0032] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0033] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0034] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0035] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0036] In the embodiments disclosed herein, the collection, updating, analysis, processing, use, transmission, provision, disclosure, and storage of data (e.g., including but not limited to user personal information) comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. In particular, necessary measures have been taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.
[0037] In the embodiments disclosed herein, user authorization or consent is obtained before acquiring or collecting user personal information.
[0038] When the train activation terminal receives a driver key command or is manually set up, it typically operates in primary system mode. However, when the redundant system first starts operating or when the primary system malfunctions, manual intervention is required to reset the primary system's status. Without manual intervention, the backup system cannot obtain primary system operating privileges. The backup system cannot automatically upgrade to the primary system, resulting in low availability for the redundant system.
[0039] The embodiments of this disclosure provide a control method for a clustered hot standby redundancy system, including: determining the priority of the target system to which the target device belongs in the clustered hot standby redundancy system or the instruction operation status of the target device according to the device attributes of the target device. The target system includes multiple devices, and the clustered hot standby redundancy system includes multiple systems. The multiple systems are classified into a master system and a hot standby system. The master system is used to manage the communication data of the train, and the hot standby system is used to back up the communication data. The master system is switched to standby according to the priority or instruction operation status.
[0040] Figure 1 The diagram illustrates a system architecture of a control method for a clustered hot standby redundant system according to an embodiment of the present disclosure.
[0041] It is important to note that Figure 1 The examples shown are merely examples of system architectures that can be applied to the embodiments of this disclosure, in order to help those skilled in the art understand the technical content of this disclosure, but do not mean that the embodiments of this disclosure cannot be used in other devices, systems, environments or scenarios.
[0042] like Figure 1 As shown, the system architecture 100 according to this embodiment may include a clustered hot standby redundancy system 101, a train 102, a network 103, and a server 104. The network 103 serves as a medium for providing communication links between the clustered hot standby redundancy system 101, the train 102, and the server 104. The network 103 may include various connection types, such as wired and / or wireless communication links, etc.
[0043] Users can use the clustered hot standby redundancy system 101 and train 102 to interact with the server 104 via network 103 to receive or send messages, etc.
[0044] The clustered hot standby redundancy system 101 may include multiple systems, which are classified as master systems and hot standby systems. The master system is used to manage the train's communication data, and the hot standby system is used to back up the communication data. Communication between the multiple systems in the clustered hot standby redundancy system is coupled. Each system includes multiple devices, which are classified as master devices and slave devices. Master devices are used to output control commands to other systems in the clustered hot standby redundancy system, while slave devices are used to output control commands to master devices but do not output control commands to other systems in the clustered hot standby redundancy system.
[0045] Train 102 can be equipped with a clustered hot standby redundancy system 101.
[0046] Server 104 can be a server that provides various services, such as an operation management server that supports the operation commands selected by users using the clustered hot standby redundancy system 101 and train 102 (this is just an example). The operation management server can analyze and process data such as received user operation requests.
[0047] It should be noted that the control method of the clustered hot standby redundancy system provided in this embodiment can generally be executed by server 104. Correspondingly, the control device of the clustered hot standby redundancy system provided in this embodiment can generally be located in server 104. The control method of the clustered hot standby redundancy system provided in this embodiment can also be executed by a server or server cluster that is different from server 104 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 104. Correspondingly, the control device of the clustered hot standby redundancy system provided in this embodiment can also be located in a server or server cluster that is different from server 104 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 104. Alternatively, the control method of the clustered hot standby redundancy system provided in this embodiment can also be executed by the first terminal device 101, the second terminal device 102, or the third terminal device 103, or it can be executed by other terminal devices that are different from the first terminal device 101, the second terminal device 102, or the third terminal device 103. Accordingly, the control device of the clustered hot standby redundancy system provided in this embodiment can also be set in the first terminal device 101, the second terminal device 102 or the third terminal device 103, or in other terminal devices different from the first terminal device 101, the second terminal device 102 or the third terminal device 103.
[0048] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of clustered hot standby redundant systems, trains, and servers can be included.
[0049] Figure 2 A flowchart illustrating a control method for a clustered hot standby redundancy system according to an embodiment of the present disclosure is shown.
[0050] like Figure 2 As shown, the method includes operations S210~S220.
[0051] In operation S210, the priority of the target system to which the target device belongs or the command operation status of the target device is determined according to the device attributes of the target device.
[0052] When operating S220, the target system is switched from primary to backup based on priority or instruction running status.
[0053] According to embodiments of this disclosure, the target system includes multiple devices, and the clustered hot standby redundancy system includes multiple systems, which are classified into a main system and a hot standby system. The main system is used to manage the communication data of the train, and the hot standby system is used to back up the communication data.
[0054] According to embodiments of this disclosure, the communication data may be data from sensors in the train, data from controllers, communication transmission data, etc.
[0055] Device attributes can be determined by the role of the target device within the target system. For example, the target device may be used to transmit data or output commands to other systems in a clustered hot standby redundant system. Or, the target device may be used to transmit data or output commands to other devices within the target system.
[0056] Device attributes can also be determined by the functions of the target device. For example, the target device may have data transmission capabilities, or it may have detection capabilities. There are no restrictions on this function.
[0057] Device attributes can also be determined by the user permissions of the target device. For example, the user permissions of the target device may be those of train maintenance personnel or train drivers.
[0058] According to embodiments of this disclosure, priority characterizes the level at which a system can be classified as a master system in a clustered hot standby redundancy system. For example, a clustered hot standby redundancy system may have systems A, B, and C. The priorities of the three systems, from highest to lowest, are: system C, system B, and system A. Then, if system C does not experience any anomalies, it can switch to become the master system to manage train communication data. If system C does not experience any anomalies, system B, which also does not experience any anomalies, will switch to become the master system to ensure the continuity of train communication data management.
[0059] According to embodiments of this disclosure, the instruction execution state is the state in which the target device outputs instructions to other devices within the target system. For example, the instruction execution state can be an instruction output state or an instruction output prohibited state.
[0060] When the target device's command execution state is either in output command state or output command prohibited state, it can detect whether there is an anomaly in the target system. If so, the system classification of the target system is adjusted; otherwise, the system classification of the target system is maintained. The system classification can be primary system or hot standby system.
[0061] It should be noted that the device attributes of the target device are roughly divided into two categories. One category requires determining the priority of the target system to which the target device belongs in the clustered hot standby redundancy system, and the other category requires determining the command execution status of the target device. The master-slave switching logic differs between the two types of device attributes.
[0062] For example, to determine the priority of the target system to which the target device belongs in a clustered hot standby redundancy system, the operating status of the master and slave devices in the target system can be used to determine whether there are any anomalies in the target system. Then, based on the priorities of each system in the clustered hot standby redundancy system, and following the principle of normal systems having high priority, the systems in the clustered hot standby redundancy system are switched over from master to standby.
[0063] For example, to determine the command execution status of the target device, one can also determine whether there is an anomaly in the target system based on the execution status of the master and slave devices in the target system. If the target system is the master system and an anomaly exists, the target system is downgraded to a hot standby system; if the target system is the master system and no anomaly exists, the target system remains the master system. If the target system is a hot standby system, the system classification is maintained, and then it is determined whether there is anomaly in the master and slave devices of the target system, and a master-slave switchover is performed on the target device.
[0064] According to embodiments of this disclosure, the priority or instruction operating status of the target system to which the target device belongs in the clustered hot standby redundancy system is determined based on the device attributes of the target device; based on the priority or instruction operating status, the target system is switched from primary to standby, so that even when the redundant system has just started running or when the primary system fails, each system in the clustered hot standby redundancy system can automatically switch from primary to standby, and the clustered hot standby redundancy system has high availability.
[0065] According to embodiments of this disclosure, device attributes include master devices and slave devices; determining the priority or instruction execution status of the target system to which the target device belongs in the cluster system based on the device attributes of the target device includes: determining the priority of the target system to which the target device belongs in the cluster system in response to the device attribute of the target device being a master device; or determining the instruction execution status of the target device in response to the device attribute of the target device being a slave device.
[0066] According to embodiments of this disclosure, performing a master-slave switchover on the system to which the target device belongs, based on priority or instruction running status, includes: responding to the target device's device attribute being a master device, performing a master-slave switchover on the target system according to the priority and operating status of each system in the clustered hot standby redundancy system; or responding to the target device's device attribute being a slave device, performing a master-slave switchover on the target system according to the instruction running status of the target device.
[0067] According to embodiments of this disclosure, the master device is used to output commands to other systems in a clustered hot standby redundancy system. The slave device is used to output commands to other devices within the target system, but not to other systems in the clustered hot standby redundancy system.
[0068] According to embodiments of this disclosure, the master / slave switching logic differs for systems with different priorities.
[0069] For example, if a high-priority target system is functioning correctly and there are no anomalies, it can remain the primary system. If a low-priority target system is functioning correctly, but other systems in the clustered hot standby redundancy system are experiencing anomalies, the target system can be switched from the hot standby system to become the primary system.
[0070] According to embodiments of this disclosure, slave devices in different instruction execution states have different master / slave switching logic.
[0071] For example, if the slave device is in a command execution state where command output is prohibited, it can detect whether there is an abnormality in the master device, and determine whether the slave device should adjust the command execution state, thereby completing the master-slave switchover of the target system.
[0072] Figure 3A A flowchart illustrating a control method for a clustered hot standby redundancy system according to an embodiment of the present disclosure is shown.
[0073] like Figure 3A As shown, the method includes operations S310~S320.
[0074] When operating S310, in response to the target device's device attribute being a master device, the priority of the target system to which the target device belongs in the cluster system is determined.
[0075] When operating the S320, the target system is switched from primary to backup based on the priority and operating status of each system in the clustered hot standby redundancy system.
[0076] Figure 3B A flowchart illustrating a control method for a clustered hot standby redundancy system according to another embodiment of the present disclosure is shown.
[0077] like Figure 3B As shown, the method includes operations S330~S340.
[0078] In operation S330, in response to the target device's device attribute being a slave device, the command execution status of the target device is determined.
[0079] When operating S340, the target system is switched from primary to backup based on the target device's command and operating status.
[0080] According to embodiments of this disclosure, in response to the target device's device attribute being a slave device, performing a master-slave switchover of the target system based on the target device's instruction operating state includes: in response to the target device's device attribute being a slave device, detecting the operating state of the master device in the target system through the target device's operating data to obtain a first detection result of the master device; in response to the first detection result indicating an abnormality in the master device's operating state, adjusting the master device's instruction operating state to switch the target system's system state to a hot standby system state, and controlling the instruction state to control communication of the target system in a clustered hot standby redundant system.
[0081] According to embodiments of this disclosure, when the master device is functioning normally, the master device has output control commands to communicate with the clustered hot standby redundant system, and the slave device maintains the state of outputting control commands to the target system.
[0082] According to embodiments of this disclosure, in the event of a malfunction of the master device, the master device does not have the ability to output control commands to the clustered hot standby redundant system, and the slave device switches to a state where it is prohibited from outputting control commands to the target system.
[0083] According to embodiments of this disclosure, the slave device can detect the operational status of the master device. The operational status may include health status and vital signs.
[0084] For example, health status could refer to the storage function status of the master device. The master and slave devices each generate a random number and send it to each other. Both devices then perform calculations using fixed formulas on the generated and received random numbers, including addition, subtraction, multiplication, division, AND, OR, and NOT operations. The calculation result for the received random number must be sent back. The two devices compare their respective calculation results with the other's. If the results match, the other device is considered to be in normal health; otherwise, it is considered abnormal. This allows for mutual health checks between master and slave devices.
[0085] For example, a life signal can be a communication signal. A normal life signal has a regular, periodic pattern.
[0086] According to embodiments of this disclosure, in response to the target device's device attribute being a slave device, the operating status of the master device in the target system is detected through the target device's operating data, resulting in a first detection result for the master device. This enables mutual health detection between the master and slave devices, thus perfecting the functionality of the clustered hot standby redundancy system. In response to the first detection result indicating an abnormality in the master device's operating status, the master device's command operating status is adjusted to automatically switch the target system's system state to a hot standby state, achieving efficient master-standby switching.
[0087] Figure 4The illustration schematically shows a flowchart of a process for switching between primary and backup systems in response to the target device's device attribute being a slave device, according to an embodiment of the present disclosure, based on the target device's instruction operating state.
[0088] like Figure 4 As shown, the method includes operations S410~S440.
[0089] In operation S410, in response to the target device's device attribute being a slave device, the operating status of the master device in the target system is detected through the target device's operating data, and the first detection result of the master device is obtained.
[0090] In operation S420, determine whether the first detection result indicates an abnormality in the working status of the main equipment. If yes, execute operation S430; otherwise, execute operation S440.
[0091] When operating S430, adjust the master device's command operation state to prohibit outputting control commands to other systems in the clustered hot standby redundant system; switch the slave device to a state that prohibits outputting control commands to other devices in the target system.
[0092] When operating S440, maintain the command execution state of the master device outputting control commands to other systems in the clustered hot standby redundant system, and maintain the state of the slave device outputting control commands to other devices in the target system.
[0093] According to embodiments of this disclosure, the system state includes an initialization state, a main system state, and a hot standby system state. The initialization state is the state in which the system in a clustered hot standby redundant system has completed file configuration.
[0094] According to embodiments of this disclosure, the initialization state is the system startup phase, and no priority is configured.
[0095] According to embodiments of this disclosure, the main system state, i.e., the target system, is the main system, and the hot standby system state, i.e., the target system is the hot standby system.
[0096] According to embodiments of this disclosure, in response to the device attribute of the target device being a master device, performing master-slave switching of the target system based on the priority and operating status of each system in the clustered hot standby redundancy system includes: in response to the device attribute of the target device being a master device, determining the system status of the target system; and performing master-slave switching of the target system based on the system status of the target system and the priority and operating status of each system in the clustered hot standby redundancy system.
[0097] According to embodiments of this disclosure, whether the clustered hot standby redundancy system has a higher priority than the target system and is in normal working condition directly affects whether the target system performs a primary / standby switchover.
[0098] For example, if the target system is in the initialization state, based on the priorities of each system in the clustered hot standby redundancy system, the system with the highest priority can be promoted to the master system, and the remaining systems can be hot standby systems. If the target system is the highest priority system, it will be the master system; otherwise, it will be a hot standby system.
[0099] For example, if the target system is the master system and is running normally, and there is no system in the initialization state with a higher priority than the target system, then the target system remains the master system.
[0100] For example, if the target system is in the primary system but its operating status is abnormal, the system with normal operating status and high priority should be promoted to the primary system, and the target system should be demoted to a hot standby system.
[0101] For example, if the target system is in hot standby mode and is operating normally, and there is a system in the main system mode and is operating abnormally, then the target system, which has the second-highest priority after the original main system, will be promoted to the main system.
[0102] According to embodiments of this disclosure, the primary / standby switchover of the target system based on the system state of the target system and the priorities and operating states of each system in the clustered hot standby redundancy system includes: in response to the target system being in an initialization state or a hot standby system state, performing a primary / standby switchover of the target system based on the priority of the target system and the operating states of each system in the clustered hot standby redundancy system; in response to the target system being in a primary system state and operating state being abnormal, switching the target system's system state to a hot standby system state; and in response to the target system's operating time in the primary system state not meeting a time threshold and the existence of a system in the clustered hot standby redundancy system meeting a first preset condition, switching the target system's system state to a hot standby system state, wherein the first preset condition is that the system state is in a primary system state, the priority meets a first preset threshold, and the operating state is normal.
[0103] According to embodiments of this disclosure, the time threshold can be the time during which the system has been running stably. For example, if the system is typically in a stable state for 30 minutes, it is considered to be running stably. When the primary system is stable, it is not recommended to perform a primary-to-standby switchover on the stable primary system, as this is detrimental to the stable management and communication data of the clustered hot standby redundant system.
[0104] According to embodiments of this disclosure, the first preset threshold can be any priority higher than the target system priority.
[0105] According to embodiments of this disclosure, different primary / standby switching logics exist for different system states of the target system.
[0106] According to the embodiments of this disclosure, the target system is in an initialization state or a hot standby system state. It is necessary to determine whether there is any abnormality in the working state of the main system in the existing clustered hot standby redundancy system in order to further determine whether the target system should perform a master-slave switchover.
[0107] According to the embodiments of this disclosure, the target system's system state is the master system state. It is necessary to first determine whether the master system's operating state is abnormal. If abnormal, the target system's system state is switched to a hot standby system state. If no abnormality exists, it is necessary to further determine whether the target system's operating time in the master system state meets a time threshold. If so, the target system's system state remains the master system state. If not, it is necessary to determine whether there is a system in the clustered hot standby redundancy system that meets a first preset condition. If such a system exists, the target system's system state is switched to a hot standby system state; otherwise, the target system's system state remains the master system state.
[0108] According to embodiments of this disclosure, in response to the target system's system state being in a master system state and its operational state being abnormal, the target system's system state is switched to a hot standby system state. Even if the master system fails, communication data can continue to be managed, ensuring the continuous operation of the clustered hot standby redundancy system. Furthermore, in response to the target system's operating time in the master system state not meeting a time threshold and the existence of a system in the clustered hot standby redundancy system meeting a first preset condition, the target system's system state is switched to a hot standby system state. This ensures that, when the master system is stable, a master-slave switchover is not performed, facilitating the stable management of communication data by the clustered hot standby redundancy system.
[0109] According to an embodiment of this disclosure, in response to the target system's system state being a master system state and its operating state being abnormal, switching the target system's system state to a hot standby system state includes: in response to the target system's system state being a master system state, detecting the operating state of the slave device in the target system through the master system's operating data to obtain a second detection result of the master device; and in response to the second detection result indicating that the slave device's operating state is abnormal, switching the target system's system state to a hot standby system state.
[0110] According to embodiments of this disclosure, the master device of a clustered hot standby redundancy system can detect the operating status of slave devices.
[0111] According to embodiments of this disclosure, if the device is malfunctioning, the target system is also in an malfunctioning state.
[0112] According to embodiments of this disclosure, by detecting the slave devices of the master system, the backup function of the master system is ensured to operate normally, thus maintaining the integrity of the security architecture of the clustered hot standby redundant system.
[0113] According to embodiments of this disclosure, in response to the target system being in an initialization state or a hot standby system, the primary / standby switchover of the target system, based on the priority of the target system and the operating status of each system in the clustered hot standby redundancy system, includes: in response to the target system being in an initialization state and the existence of a primary system in the clustered hot standby redundancy system with a normal operating status, comparing the priority of the target system with the priority of the primary system to obtain a comparison result; performing a primary / standby switchover of the target system based on the comparison result; in response to the target system being in an initialization state and the existence of a primary system in the clustered hot standby redundancy system with an operating time meeting a time threshold, switching the target system's system state to a hot standby system state; in response to the target system being in a hot standby system state and the systems in the clustered hot standby redundancy system other than the target system meeting a second preset condition, switching the target system's system state to a primary system state, the second preset condition including priority meeting a second threshold or an abnormal operating status.
[0114] According to embodiments of this disclosure, the initialization state refers to the process of establishing a network connection and configuring files. In cases where network connectivity is lost, a lower-priority system may initially act as the primary system. If the target system is in the initialization state, its priority can be compared with that of the primary system to obtain a comparison result; based on the comparison result, a primary / backup switch can be performed on the target system. If the comparison result indicates that the target system's priority is higher than that of the primary system, the target system's state can be switched to the primary system state.
[0115] This disclosure takes into account the situation where a clustered hot standby redundant system is in the startup state and there are network disconnections between the systems, so that the lower priority system is first used as the master system. By comparing the priorities between the systems, the master system can be determined in an orderly manner.
[0116] According to embodiments of this disclosure, after a high-priority primary system failure is recovered, a hot standby system can be maintained to ensure the stable operation of the clustered hot standby redundancy system. Specifically, when the target system is in its initial state, if a primary system exists in the clustered hot standby redundancy system whose runtime meets a time threshold, the target system's state is switched to hot standby mode.
[0117] This disclosure considers maintaining the hot standby system after a high-priority primary system failure, so as not to cause instability in the operation of the clustered hot standby redundant system due to the primary / standby switchover process.
[0118] According to embodiments of this disclosure, the second preset threshold can be any priority lower than the target system priority.
[0119] In a clustered hot standby redundancy system, there are systems that are operating normally and have a higher priority than the target system. The target system maintains the hot standby system.
[0120] In a clustered hot standby redundant system, if there is no system in normal operating condition or with a higher priority than the target system, the target system will switch to the master system.
[0121] Figure 5 This illustration schematically depicts a scenario where, in response to the device attribute of the target device being the master device, a master-slave switch is performed on the target system according to the priority and operating status of each system in the clustered hot standby redundancy system, based on an embodiment of this disclosure.
[0122] When the target system to which the master device belongs is in the initialization state 502, and there is a master system 505 in the clustered hot standby redundancy system that is in normal working state and the priority of the target system is lower than that of the master system 506, the system state 501 of the target system is switched to the hot standby system state 503.
[0123] When the system state 501 of the target system to which the main device belongs is in the initialization state 502, and there is a main system 507 in the clustered hot standby redundant system whose running time meets the time threshold, the system state 501 of the target system is switched to the hot standby system state 503.
[0124] When the system state 501 of the target system to which the main device belongs is in hot standby state 503, and the system 508 in the clustered hot standby redundancy system meets the second preset condition other than the target system, the system state 501 of the target system is switched to the main system state 504.
[0125] When the target system to which the main device belongs is in system state 501 as main system state 504, and the running time of the main system state does not meet the time threshold 509, and there is a system 510 in the clustered hot standby redundant system that meets the first preset condition, the target system's system state 501 is switched to hot standby system state 503.
[0126] When the target system to which the master device belongs is in system state 501 as master system state 504, and the slave device of the target system is in abnormal operating state 511, the target system's system state 501 is switched to hot standby system state 503.
[0127] Each system is prioritized, and at system startup, the highest-priority system automatically switches to master. In the event of a master system failure, the second-highest-priority slave system automatically switches to master. If two masters exist, the lower-priority master system degrades to slave. This master-slave redundancy switching method improves automation and system availability compared to the first method. However, during the recovery of a high-priority master system, a master-slave switch occurs, causing instability in system control command output and low system reliability.
[0128] Based on the automatic switching capability of the clustered hot standby redundant system, the master-slave switching logic adds diagnostics on the health status of each cluster slave device, enabling the master system to have complete system functions and maximizing the reliability and stability of the system operation.
[0129] A clustered hot standby redundancy system comprises multiple communication-coupled systems. In a clustered hot standby redundancy system, only one system acts as the master system, while the others serve as hot standby systems.
[0130] The system includes multiple devices, which are divided into master devices and slave devices. Only the master devices can output control commands to other systems in the clustered hot standby redundancy system, while the slave devices participate in the master system's external control functions.
[0131] For example, both System 1 and System 2 execute input commands. Only the master system outputs control commands to other systems in the clustered hot standby redundancy system, while the hot standby system does not output control commands to other systems in the clustered hot standby redundancy system.
[0132] In a clustered hot standby redundancy system, each system automatically generates a priority for switching to the master system after power-on.
[0133] During communication between and within systems, the master devices of each system perform life signal monitoring and normal operation status monitoring, while the master devices and slave devices within a system perform health status monitoring of each other.
[0134] The implementation of the health status monitoring function includes the detection of the controller's data storage functions such as addition, subtraction, multiplication, division, AND, OR, NOT, communication, instructions and addresses.
[0135] The main system can assess its own health status and the vital signs and operational status of the hot standby system, while the hot standby system assesses its own health status and the normal operational status of the original main system.
[0136] When a clustered hot standby redundant system has multiple master systems, only the highest priority master system does not switch over, while the other systems switch over to the hot standby system.
[0137] For example, in a clustered hot standby redundancy system, after initial power-on, each system starts up. The master device of each system is set to the startup state and simultaneously reads the configuration file from the storage unit, which specifies the system's priority. The slave devices of each system are set to a state where outputting control commands is prohibited, and the master device generates regularly changing digital signals (health signals) at fixed intervals. The master and slave devices perform mutual health status monitoring, which is implemented as follows:
[0138] The master and slave devices each generate a random number and send it to the other. Both devices then perform calculations on the generated and received random numbers according to a fixed formula, including addition, subtraction, multiplication, division, AND, OR, and NOT operations. The calculation result for the received random number must be sent back. The two devices compare their respective calculation results with the other's. If the results match, the other device is considered to be in normal health; otherwise, it is considered abnormal.
[0139] In a clustered hot standby redundancy system, each system receives calculation results from other systems and determines its operational status based on life signals and normal operating status signals. The method for determining normal life signals is whether their changes exhibit a periodic pattern. The method for determining normal operating status is based on specific data offset states transmitted by other systems.
[0140] After successfully reading the configuration file, the master device in each cluster sets itself to the initialization state.
[0141] For example, when the target device is the primary device and the target system it belongs to is a high-priority system, primary / backup switching can be performed according to different system states.
[0142] First, while the target system is in an initialization state, perform the following operations:
[0143] If all systems in the clustered hot standby redundant system are in hot standby mode and the target system's life signals are normal, the target system is promoted to master system. If other systems are in initialization mode, the target system is promoted to master system. If other systems are in hot standby mode, the target system is promoted to master system. If other systems are in master system mode, the target system becomes a hot standby system.
[0144] Second, if the target system is in hot standby mode, perform the following operations:
[0145] If other systems detect abnormal life signals while the target system's life signals are normal, the target system is promoted to the primary system. If other systems detect abnormal operating states while the target system's life signals are normal, the target system is promoted to the primary system. If other systems are detected to be in hot standby mode, the target system is promoted to the primary system.
[0146] Third, when the target system is in master system status, the following operations are performed: If other systems are detected as master systems, the target system remains the master system. If the health status of slave devices in the target system is abnormal, but the life signals and operating status of other systems are normal, the target system is downgraded to a hot standby system. If the target system's life signals are abnormal, the target system is downgraded to a hot standby system.
[0147] For example, when the target device is the primary device and the target system it belongs to is a low-priority system, primary / backup switching can be performed according to different system states.
[0148] First, when the target system is in the initialization state, the following operations are performed: if any abnormal life signals are detected in other systems in the clustered hot standby redundancy system besides the target system, the target system is promoted to the master system; if other systems are in the initialization state, the target system is used as a hot standby system; if other systems are in the hot standby system state, the target system is promoted to the master system; if other systems are in the master system state, the target system is used as a hot standby system.
[0149] Second, when the target system is in hot standby mode, the following operations are performed: if other systems detect abnormal life signals and the target system's life signals are normal, the target system becomes the primary system; if other systems detect abnormal normal operating conditions and the target system's life signals are normal, the target system becomes the primary system; if other systems detect that they are in hot standby mode, the target system becomes the hot standby system.
[0150] Third, when the target system is in the master system state, perform the following operations: if other systems are in the master system state, the target system is set up as a hot standby system; if the target system is found to have abnormal equipment health status, while other systems have normal life signals and operating status, the target system is downgraded to a hot standby system; if other systems are in the hot standby system state, the target system is set up as the master system.
[0151] For example, if the target device is a slave device and is in a state where it is prohibited from outputting control commands to other devices in the target system, the following operations are performed: the health status of the master device in the target system is detected to be normal, the working status is set to normal, and the target device is upgraded to a state where it can output control commands to other devices in the target system.
[0152] The target device is a slave device. When the target device is in the output command state, it performs the following operations: detects that the health status of the master device of the target system is abnormal, sets the working status to abnormal, and sets the target device to a state that prohibits outputting control commands to other devices in the target system; and performs a power-off reset on the master device to make the target system a hot standby system or keep it as such.
[0153] This invention offers the following advantages: It enables hot standby redundancy in systems with multiple devices participating in control. The master-slave switching logic incorporates diagnostics of the health status of slave devices within each system, ensuring the master system retains full functionality. Master devices within each system can degrade to hot standby based on the health status of slave devices, while slave devices can issue their cluster's normal operating status based on the master device's health status, thus forming a secure architecture for the clustered hot standby redundancy system. Upon recovery from a high-priority master system failure, it automatically switches to hot standby, maintaining the original master system state to ensure system stability.
[0154] A train equipped with a clustered hot standby redundancy system controlled by performing any of the methods described above, the clustered hot standby redundancy system being used to manage the train's communication data.
[0155] A clustered hot standby redundancy system can include multiple systems, categorized as master systems and hot standby systems. The master system manages train communication data, while the hot standby system backs up communication data. Communication between the multiple systems in a clustered hot standby redundancy system is coupled. Each system includes multiple devices, categorized as master devices and slave devices. Master devices output control commands to other systems in the clustered hot standby redundancy system, while slave devices output control commands to the master devices but do not output control commands to other systems in the clustered hot standby redundancy system.
[0156] In a clustered hot standby redundancy system, during communication between or within systems, the master devices of each system perform vital sign monitoring and normal operation status monitoring, while the master devices and slave devices within the system perform health status monitoring of each other.
[0157] Figure 6 A block diagram of the control apparatus for a clustered hot standby redundancy system according to an embodiment of the present disclosure is shown schematically.
[0158] like Figure 6 As shown, the control device 600 of the clustered hot standby redundancy system includes a determination module 610 and a primary / standby switching module 620.
[0159] The determining module 610 is used to determine the priority of the target system to which the target device belongs in the clustered hot standby redundancy system or the instruction operation status of the target device based on the device attributes of the target device. The target system includes multiple devices, and the clustered hot standby redundancy system includes multiple systems. The multiple systems are classified into a master system and a hot standby system. The master system is used to manage the communication data of the train, and the hot standby system is used to back up the communication data. In one embodiment, the determining module 610 can be used to perform the operation S210 described above, which will not be repeated here.
[0160] The primary / standby switching module 620 is used to perform primary / standby switching on the target system according to priority or instruction running status. In one embodiment, the primary / standby switching module 620 can be used to execute the operation S220 described above, which will not be repeated here.
[0161] According to embodiments of this disclosure, the determining module 610 includes a first determining submodule or a second determining submodule. The determining submodule is used to determine the priority of the target system to which the target device belongs within the cluster system in response to the target device's device attribute being a master device. Alternatively, the second determining submodule is used to determine the instruction execution status of the target device in response to the target device's device attribute being a slave device.
[0162] According to embodiments of this disclosure, the master / standby switching module 620 includes a first master / standby switching submodule or a second master / standby switching submodule. The first master / standby switching submodule is used to perform master / standby switching on the target system based on the priority and operating status of each system in the clustered hot standby redundancy system, in response to the target device's device attribute being a master device. Alternatively, the second master / standby switching submodule is used to perform master / standby switching on the target system based on the target device's instruction operating status, in response to the target device's device attribute being a slave device.
[0163] According to embodiments of this disclosure, the second master-slave switching submodule includes a detection unit and an adjustment unit. The detection unit, in response to the target device's device attribute being a slave device, detects the operating status of the master device in the target system using the target device's operating data to obtain a first detection result for the master device. The adjustment unit, in response to the first detection result indicating an abnormality in the master device's operating status, adjusts the master device's command operating status to switch the target system's system state to a hot standby system state. The control command state is used to control communication within the clustered hot standby redundant system.
[0164] According to embodiments of this disclosure, the first primary / standby switching submodule includes a first determining unit and a primary / standby switching unit. The first determining unit is used to determine the system state of the target system in response to the target device's device attribute being a primary device. The primary / standby switching unit is used to perform primary / standby switching on the target system based on the system state of the target system and the priority and operating status of each system in the clustered hot standby redundancy system.
[0165] According to embodiments of this disclosure, the system state includes an initialization state, a main system state, and a hot standby system state. The initialization state is the state in which the system in a clustered hot standby redundant system has completed file configuration.
[0166] According to embodiments of this disclosure, the primary / standby switching unit includes a first primary / standby switching subunit, a second primary / standby switching subunit, and a third primary / standby switching subunit. The first primary / standby switching subunit is used to perform a primary / standby switch for the target system in response to the target system's system state being either an initialization state or a hot standby system state, based on the target system's priority and the operating status of each system in the clustered hot standby redundancy system. The second primary / standby switching subunit is used to switch the target system's system state to a hot standby system state in response to the target system's system state being a primary system state and its operating status being abnormal. The third primary / standby switching subunit is used to switch the target system's system state to a hot standby system state in response to the target system's operating time in the primary system state not meeting a time threshold and the existence of a system in the clustered hot standby redundancy system meeting a first preset condition. The first preset condition is that the system state is a primary system state, the priority meets a first preset threshold, and the operating status is normal.
[0167] According to an embodiment of this disclosure, in response to the target system's system state being a master system state and its operating state being abnormal, switching the target system's system state to a hot standby system state includes: in response to the target system's system state being a master system state, detecting the operating state of the slave device in the target system through the master system's operating data to obtain a second detection result of the master device; and in response to the second detection result indicating that the slave device's operating state is abnormal, switching the target system's system state to a hot standby system state.
[0168] According to embodiments of this disclosure, in response to the target system being in an initialization state or a hot standby system, the primary / standby switchover of the target system, based on the priority of the target system and the operating status of each system in the clustered hot standby redundancy system, includes: in response to the target system being in an initialization state and the existence of a primary system in the clustered hot standby redundancy system with a normal operating status, comparing the priority of the target system with the priority of the primary system to obtain a comparison result; performing a primary / standby switchover of the target system based on the comparison result; in response to the target system being in an initialization state and the existence of a primary system in the clustered hot standby redundancy system with an operating time meeting a time threshold, switching the target system's system state to a hot standby system state; in response to the target system being in a hot standby system state and the systems in the clustered hot standby redundancy system other than the target system meeting a second preset condition, switching the target system's system state to a primary system state, the second preset condition including priority meeting a second threshold or an abnormal operating status.
[0169] Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure, or at least part of the functions of any one or more of them, can be implemented in one module. Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be implemented by dividing them into multiple modules. Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be at least partially implemented as hardware circuitry, such as a Field-Programmable Gate Array (FPGA), a Programmable Logic Array (PLA), a System-on-Chip, a System-on-a-Substrate, a System-on-Package, an Application-Specific Integrated Circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be at least partially implemented as computer program modules, which, when run, can perform corresponding functions.
[0170] For example, any plurality of the determining module 610 and the primary / standby switching module 620 can be combined into one module / unit / subunit, or any one of the modules / units / subunits can be split into multiple modules / units / subunits. Alternatively, at least part of the functionality of one or more of these modules / units / subunits can be combined with at least part of the functionality of other modules / units / subunits and implemented in one module / unit / subunit. According to embodiments of this disclosure, at least one of the determining module 610 and the primary / standby switching module 620 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the determining module 610 and the primary / standby switching module 620 can be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.
[0171] It should be noted that the control device part of the clustered hot standby redundancy system in the embodiments of this disclosure corresponds to the control method part of the clustered hot standby redundancy system in the embodiments of this disclosure. For a detailed description of the control device part of the clustered hot standby redundancy system, please refer to the control method part of the clustered hot standby redundancy system, which will not be repeated here.
[0172] Figure 7 A block diagram of an electronic device suitable for implementing the control method of the clustered hot standby redundant system described above, according to an embodiment of the present disclosure, is shown schematically.
[0173] Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0174] like Figure 7 As shown, an electronic device 700 according to an embodiment of the present disclosure includes a processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage portion 708 into a random access memory (RAM) 703. The processor 701 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 701 may also include onboard memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0175] RAM 703 stores various programs and data required for the operation of electronic device 700. Processor 701, ROM 702, and RAM 703 are interconnected via bus 704. Processor 701 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 702 and / or RAM 703. It should be noted that the programs may also be stored in one or more memories other than ROM 702 and RAM 703. Processor 701 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.
[0176] According to embodiments of this disclosure, the electronic device 700 may further include an input / output (I / O) interface 705, which is also connected to a bus 704. The electronic device 700 may also include one or more of the following components connected to the input / output (I / O) interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the input / output (I / O) interface 705 as needed. A removable medium 711, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 710 as needed so that computer programs read from it can be installed into the storage section 708 as needed.
[0177] According to embodiments of this disclosure, the method flow according to embodiments of this disclosure can be implemented as a computer software program. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable storage medium, the computer program containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via communication section 709, and / or installed from removable medium 711. When the computer program is executed by processor 701, it performs the functions defined in the system of embodiments of this disclosure. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0178] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0179] According to embodiments of this disclosure, the computer-readable storage medium can be a non-volatile computer-readable storage medium. Examples include, but are not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0180] For example, according to embodiments of this disclosure, a computer-readable storage medium may include the ROM 702 and / or RAM 703 described above and / or one or more memories other than ROM 702 and RAM 703.
[0181] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods provided in the embodiments of this disclosure. When the computer program product is run on an electronic device, the program code enables the electronic device to implement the control method of the clustered hot standby redundancy system provided in the embodiments of this disclosure.
[0182] When the computer program is executed by the processor 701, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0183] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 709, and / or installed from a removable medium 711. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0184] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0185] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions. Those skilled in the art will understand that the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways, even if such combinations are not explicitly described in the present disclosure. In particular, the features described in the various embodiments of this disclosure may be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0186] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.
Claims
1. A control method for a clustered hot standby redundancy system, comprising: Based on the device attributes of the target device, determine the priority of the target system to which the target device belongs in the clustered hot standby redundancy system or the instruction operation status of the target device. The target system includes multiple devices, and the clustered hot standby redundancy system includes multiple systems. The multiple systems are classified into a main system and a hot standby system. The main system is used to manage the communication data of the train, and the hot standby system is used to back up the communication data. Based on the priority or the instruction execution status, the target system is switched from primary to backup. The device attributes include master device and slave device. In response to the target device's device attribute being the slave device, the instruction execution status of the target device is determined. The step of performing a primary / standby switchover of the system to which the target device belongs based on the priority or the instruction running state includes: In response to the target device's device attribute being the slave device, the operating status of the master device in the target system is detected through the target device's operating data to obtain the first detection result of the master device; In response to the first detection result indicating an abnormality in the working state of the master device, the instruction operation state of the master device is adjusted to switch the system state of the target system to a hot standby system state. The instruction operation state of the master device is used to control the communication of the target system in the clustered hot standby redundancy system.
2. The method according to claim 1, wherein determining the priority or instruction execution status of the target system to which the target device belongs in the cluster system based on the device attributes of the target device includes: In response to the target device's device attribute being the master device, the priority of the target system to which the target device belongs in the cluster system is determined.
3. The method of claim 2, wherein, The step of performing a primary / standby switchover of the system to which the target device belongs based on the priority or the instruction running state includes: In response to the target device's device attribute being the master device, the target system is switched over to master / standby mode according to the priority and operating status of each system in the clustered hot standby redundancy system.
4. The method of claim 3, wherein, The device attribute responding to the target device is the master device, and the master-slave switchover of the target system according to the priority and operating status of each system in the clustered hot standby redundancy system includes: In response to the target device's device attribute being the master device, the system state of the target system is determined; Based on the system status of the target system and the priority and operating status of each system in the clustered hot standby redundancy system, a primary / standby switchover is performed on the target system.
5. The method of claim 4, wherein, The system status includes the initialization status, the main system status, and the hot standby system status. The initialization status is the status in which the system in the clustered hot standby redundancy system has completed file configuration.
6. The method of claim 5, wherein, The step of performing primary / standby switchover on the target system based on the system state of the target system and the priority and operating status of each system in the clustered hot standby redundancy system includes: In response to the target system's system state being either the initialization state or the hot standby system state, a primary / standby switchover is performed on the target system based on the target system's priority and the operating status of each system in the clustered hot standby redundancy system. In response to the target system's system state being the main system state and the operating state being abnormal, the target system's system state is switched to the hot standby system state. In response to the target system's running time in the main system state not meeting the time threshold and the existence of a system in the clustered hot standby redundancy system that meets the first preset condition, the system state of the target system is switched to the hot standby system state. The first preset condition is that the system state is the main system state, the priority meets the first preset threshold, and the working running state is normal.
7. The method of claim 6, wherein, The step of switching the system state of the target system to the hot standby system state in response to the target system's system state being the main system state and its operating state being abnormal includes: In response to the system state of the target system being the master system state, the working status of the slave device in the target system is detected through the operating data of the master system, and a second detection result of the master device is obtained; In response to the second detection result indicating that the working state of the slave device is abnormal, the system state of the target system is switched to the hot standby system state.
8. The method of claim 6, wherein, The response to the system state of the target system being either the initialization state or the hot standby system, and the primary / standby switchover of the target system based on the priority of the target system and the operating status of each system in the clustered hot standby redundancy system, includes: In response to the target system being in the initialization state and the presence of a normal operating master system in the clustered hot standby redundancy system, the priority of the target system is compared with the priority of the master system to obtain a comparison result. Based on the comparison results, perform a primary / backup switchover on the target system; In response to the target system being in the initialization state and the presence of a master system in the clustered hot standby redundancy system whose running time meets the time threshold, the target system is switched to the hot standby system state. In response to the target system's system state being the hot standby system state and the systems in the clustered hot standby redundancy system other than the target system meeting a second preset condition, the target system's system state is switched to the master system state. The second preset condition includes the priority meeting a second threshold or the operating state being abnormal.
9. A train equipped with a clustered hot standby redundancy system controlled by performing the method as described in any one of claims 1 to 8, the clustered hot standby redundancy system being used to manage the communication data of the train.
Citation Information
Patent Citations
Redundant system switching method, device and equipment, medium and vehicle
CN118466160A
Control system
JP2011039702A