A highly flexible, secure, and redundant PHY architecture and communication node for TTP networks

By introducing components such as dual communication channels, digital isolators, and differential transceivers into the TTP network, and combining them with hardware transmission enable logic, the problems of insufficient resource utilization, inflexible matching design, and imperfect security control in the TTP network are solved, thereby improving system redundancy and enhancing reliability.

CN122372598APending Publication Date: 2026-07-10SHANGHAI CIVIL AVIATION POWER SYSTEM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI CIVIL AVIATION POWER SYSTEM CO LTD
Filing Date
2026-06-09
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

The existing TTP network suffers from insufficient utilization of controller channel resources, inflexible matching design, imperfect security control, and insufficient transient protection, resulting in low system redundancy, poor reliability, and inconvenient maintenance.

Method used

Design a highly flexible, safe, and redundant PHY architecture, including dual communication channels, digital isolators, differential transceivers, channel selection switches, terminal matching branches, and transient protection circuits. Hardware transmit enable logic ensures isolation of faulty nodes and environmental adaptability, thereby improving system redundancy and reliability.

Benefits of technology

Without adding external interfaces and cables, it improves network redundancy, enhances communication link reliability, simplifies maintenance, improves system-level fault safety, and adapts to complex electromagnetic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372598A_ABST
    Figure CN122372598A_ABST
Patent Text Reader

Abstract

This application provides a highly flexible, secure, and redundant PHY architecture and communication node for TTP networks. The architecture sets up two internal isolated transceiver branches within the same external TTP differential bus port: the first and second communication channels of the TTP protocol controller are respectively connected to a digital isolator and a differential transceiver to form two differential signal pairs, and then a channel selection switch selects only one of them to connect to the external bus port; the termination matching branch and transient protection circuit are located on the common side of the channel selection switch or on the external port side, allowing the two internal channels to share the same termination matching network and protection network. Hardware transmit enable logic generates a differential transceiver transmit enable signal based on reset, watchdog timer, power-on, host transmit enable, TTP transmit enable, and channel selection status, preventing transmission from the unselected channel or the channel in a fault state. This application achieves channel-level redundancy without adding external interfaces and cables.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of avionics and communication technology, and in particular to a highly flexible, secure, and redundant PHY architecture and communication node for TTP networks. Background Technology

[0002] Time-triggered protocols (TTPs) are deterministic real-time communication protocols widely used in fields with extremely high security and real-time requirements, such as aviation and aerospace. In aviation power networks, TTPs are primarily used to transmit critical power conversion control and load management commands; therefore, data reliability is paramount. To avoid these issues, Dual-Web (dual networks) are typically used for redundancy backup.

[0003] In existing technologies, a single TTP protocol controller typically has only two communication channels. In the Dual-Web architecture, in order to save on the number of airborne device interfaces, reduce cable weight and maintenance complexity, only one channel of each controller is generally used, leaving the other channel idle and wasted. This results in a waste of controller chip resources and limits the system's redundancy and expansion capabilities.

[0004] The design of the existing TTP node physical layer also presents the following problems: Outdated isolation methods: The network transformers used in aviation Ethernet are commonly employed for isolation, resulting in large size and relatively low reliability. Inflexible matching design: Terminal matching resistors are often placed at the end of the bus, leading to redundant wiring between the node access point and the actual matching point, which can easily cause signal reflection, and the matching effect is limited by the physical layout. For modular, standardized devices, manual adjustment is required when used at network locations (end or middle), making maintenance inconvenient. Inadequate safety control: PHY transmit enable control typically relies solely on the TTP protocol's own CTS signal, without rapid, hard-wired-level linkage and isolation with the host's global fail-safe states (e.g., reset, watchdog timeout), posing a risk of faulty nodes interfering with the bus. Lack of protection: There is a lack of dedicated, layered protection circuits for complex airborne electromagnetic environments (lightning strikes, surges, etc.).

[0005] Therefore, there is an urgent need for a TTP network PHY architecture that can fully utilize controller resources, improve system redundancy, enhance reliability, simplify maintenance, and integrate comprehensive security protection. Summary of the Invention

[0006] This application provides a highly flexible, secure, and redundant PHY architecture and communication node for TTP networks, which addresses problems in the prior art such as insufficient utilization of controller channel resources, inflexible matching design, imperfect security control, and insufficient transient protection.

[0007] In a first aspect, this application provides a highly flexible, secure, and redundant PHY architecture for TTP networks, comprising: The TTP protocol controller has a first communication channel and a second communication channel; The first isolated transceiver branch is connected to the first communication channel and includes a first digital isolator and a first differential transceiver, wherein the first differential transceiver outputs a first differential signal pair; The second isolated transceiver branch, connected to the second communication channel, includes a second digital isolator and a second differential transceiver, wherein the second differential transceiver outputs a second differential signal pair; The channel selection switch has a first input terminal connected to the first differential signal pair, a second input terminal connected to the second differential signal pair, and a common terminal connected to the same external TTP differential bus port. According to the channel selection signal, it will only connect one of the first differential signal pair or the second differential signal pair to the external TTP differential bus port in both directions. The terminal matching branch is connected between the two differential lines of the common terminal of the channel selection switch, and includes a terminal matching resistor and a controllable switch connected in series therewith. The controllable switch connects or disconnects the terminal matching resistor according to the location identification information of the communication node. A transient protection circuit is installed on the external TTP differential bus port side or the common terminal side of the channel selection switch to provide common-mode and differential-mode transient protection for the two differential lines. The hardware transmit enable logic is used to generate transmit enable signals for the first differential transceiver and the second differential transceiver based on the reset release signal, watchdog valid signal, power valid signal, host transmit enable signal, TTP transmit enable signal of the corresponding communication channel, and the channel selection signal, respectively. When any fault signal is invalid or the corresponding communication channel is not selected, the corresponding differential transceiver is prohibited from transmitting.

[0008] Preferably, the first digital isolator and the second digital isolator are respectively disposed between the TTP protocol controller and the corresponding differential transceiver. The first differential transceiver and the second differential transceiver are powered by an isolation power supply, so that the controller-side ground is electrically isolated from the bus-side ground.

[0009] Preferably, the channel selection switch is a double-pole double-throw analog switch, a solid-state relay array, or a dual-channel differential analog switch; when one differential signal pair is selected, the other unselected differential signal pair is disconnected from the external TTP differential bus port.

[0010] Preferably, the location identification information comes from non-volatile memory, backplane encoding, machine position identification pins, connector keys, DIP switches, or remote configuration data; when the location identification information indicates that the communication node is at the end of the bus, the terminal matching resistor is connected, and when the location identification information indicates that the communication node is in the middle of the bus, the terminal matching resistor is disconnected.

[0011] Preferably, the transient protection circuit includes: A high-energy discharge stage, located close to the external TTP differential bus port, includes a gas discharge tube for discharging high-energy surges. A fast clamping stage, located close to the differential transceiver side, includes a line-to-line bidirectional transient suppression diode and / or a line-pair protective ground common-mode transient suppression diode.

[0012] Preferably, the hardware transmit enable logic generates the transmit enable signal according to the following logic: DE0 = RST_OK&WDG_OK&PWR_OK&HOST_TXEN&CTS0&CH0_SEL; DE1 = RST_OK&WDG_OK&PWR_OK&HOST_TXEN&CTS1&CH1_SEL; Among them, RST_OK is the reset release valid signal, WDG_OK is the watchdog valid signal, PWR_OK is the isolation power supply or bus side power supply valid signal, and HOST_TXEN is the host transmit enable signal; CTS0 and CTS1 respectively send TTP enable signals for the first and second communication channels; CH0_SEL and CH1_SEL are the status signals for the first and second communication channels being selected, respectively. When either condition is invalid, the corresponding enable signal is prohibited from being sent.

[0013] Preferably, in any of the following states: reset not released, watchdog timer invalid, host not initialized, power valid signal invalid, channel selection signal illegal, or the selected communication channel cannot be uniquely determined, the hardware transmit enable logic sets the transmit enable signals of both the first differential transceiver and the second differential transceiver to invalid.

[0014] Preferably, the resistance of the terminal matching resistor is 120Ω, or it is set according to the characteristic impedance of the external TTP differential bus port; the controllable switch is a back-to-back MOSFET, a PhotoMOS solid-state relay, a bidirectional analog switch, a miniature relay, or a controllable terminal switch integrated inside the differential transceiver.

[0015] Preferably, the differential transceiver is an RS-485 differential transceiver or an RS-422 differential transceiver that meets the TTP target communication rate, propagation delay and temperature rating requirements.

[0016] Secondly, this application also provides a communication node suitable for TTP networks, including a main processor, a TTP protocol controller, a configuration identification circuit, a power monitoring circuit, an external TTP connector, and the aforementioned highly flexible and secure redundant PHY architecture for TTP networks; when the main processor performs channel switching, it first cancels the host transmit enable signal or invalidates the transmit enable signals of both differential transceivers through the hardware transmit enable logic, and only restores the transmit enable signal of the backup channel when the backup channel completes resynchronization or communication stack recovery, the reset release signal is valid, the watchdog valid signal is valid, the power valid signal is valid, the host transmit enable signal is valid, the TTP transmit enable signal of the backup channel is valid and the backup channel is selected.

[0017] The highly flexible, secure, and redundant PHY architecture and communication node for TTP networks provided in this application have the following advantages: Enhanced redundancy: By fully utilizing the first and second communication channels of the TTP controller, network redundancy is extended from the network level to the channel level within the node without adding external interfaces and cables, thereby improving the reliability of communication links.

[0018] Enhanced Reliability: Digital isolators and isolated power supplies are installed between the controller logic side and the bus side, reducing the size and reliability constraints imposed by discrete components such as network transformers and improving the integration of PHY circuits. Rapid and Secure Isolation: The hardware transmit enable logic simultaneously incorporates reset, watchdog, power enable, host transmit enable, TTP transmit enable, and channel strobe status, ensuring that unselected channels or abnormal nodes cannot drive the external TTP bus, enhancing system-level fault safety.

[0019] Good maintainability and versatility: The terminal matching branch is located on the common side of the channel selection switch and can be automatically switched according to the configuration or machine position identification information, allowing the same hardware module to adapt to the end or middle position of the bus, reducing manual adjustments on site. Strong environmental adaptability: A high-energy discharge stage and a fast clamping stage are provided on the external port side, which can be designed and verified according to the requirements of airborne lightning strike induced transient, surge and electrostatic tests, ensuring that the PHY can work normally in complex electromagnetic environments. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is an overall block diagram of a highly flexible, secure, and redundant PHY architecture for TTP networks provided in an embodiment of this application. Figure 2 This is a schematic diagram of the isolated transceiver signal chain topology provided in an embodiment of this application; Figure 3 This is a schematic diagram of the differential gating topology of the channel selection switch provided in the embodiments of this application; Figure 4 This is a schematic diagram of a common terminal matching and transient protection circuit provided in an embodiment of this application; Figure 5 This is a schematic diagram of the transmit enable hardware interlock logic provided in an embodiment of this application; Figure 6 This is a schematic diagram of the channel security switching process provided in an embodiment of this application. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0023] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein.

[0024] like Figure 1 As shown, the PHY architecture of this application embodiment couples two internal communication channels within an external TTP differential bus port. CH0 and CH1 are two communication channels of the TTP protocol controller, wherein CH0 is connected to a first digital isolator and a first differential transceiver to form a first differential signal pair TTPH_0 / TTPL_0, and CH1 is connected to a second digital isolator and a second differential transceiver in sequence to form a second differential signal pair TTPH_1 / TTPL_1.

[0025] The two differential signal pairs are connected to the two sets of input terminals of the channel selector switch, respectively. The common terminal of the channel selector switch is connected to the same external TTP differential bus port TTPH / TTPL. The channel selector switch connects only one differential signal pair according to CH_SEL, and the unselected pair is disconnected from the external port.

[0026] The terminal matching branch and transient protection circuit are both located on the common side or external port side of the channel selection switch, so that the selected CH0 and CH1 share the same terminal matching network and the same protection network. The hardware transmit enable logic also generates transmit enable signals for each differential transceiver based on the fail-safe state and the channel selection state.

[0027] For example, refer to Figure 1 A complete embodiment of this application is applied to the TTP communication module of an airborne power management unit. In this embodiment, the TTP protocol controller is a controller with dual communication channels; in other embodiments, two independent TTP protocol controllers may provide the first communication channel and the second communication channel respectively.

[0028] For example, refer to Figure 2 The controller and digital isolation are as follows: Channels 0 (CH0) and 1 (CH1) of the TTP controller (U1) are enabled. The transmit lines (TXD0, TXD1), receive lines (RXD0, RXD1), and hardware flow control lines (CTS0, CTS1) in each channel are connected to two high-speed digital isolators (U2, U3), respectively. The digital isolators can be magnetically coupled, capacitively coupled, or optically coupled, preferably devices that meet the requirements of TTP target rate, propagation delay, and common-mode transient immunity.

[0029] Taking channel 0 as an example, the connection in the transmitting direction is as follows: U1's TXD0 is connected to the input terminal of the U2 controller, and the output terminal of the U2 bus is connected to the DI0 data input terminal of the differential transceiver U4. The connection in the receiving direction is as follows: after the external differential bus is received by U4, a single-ended receive signal is output by RO0, RO0 is connected to the input terminal of the U2 bus, and the output terminal of the U2 controller is connected to the RXD0 of U1. CTS0 or other transmit enable signals are transmitted after isolation by U2 according to their signal direction.

[0030] The power supply design is as follows: the controller side (VDD1, GND1) of U2 and U3 is powered by the controller-side power supply; the bus side (VDD2, GND2) is powered by the isolated power supply generated by the isolated DC-DC module. The ground (GND2) of this isolated power supply serves as the "bus ground" or "communication ground," electrically isolated from the controller's "digital ground." Channel selection control signals, terminal switching control signals, and transmit permission signals that need to cross the isolation boundary can all be transmitted through the corresponding isolators to avoid violating the isolation boundary.

[0031] For example, refer to Figure 3 The differential conversion and channel selection specifically involve the bus-side outputs of two digital isolators, U2 and U3, driving two high-speed RS-485 or RS-422 differential transceivers (U4 and U5), respectively. The differential transceivers should meet the TTP target communication rate, propagation delay, transceiver enable / disable time, temperature rating, and electromagnetic compatibility requirements, and can be selected based on system speed and environmental rating.

[0032] Taking channel 0 as an example, the connection relationship is as follows: The bus-side output terminal B of U2 corresponds to the TXD0 signal and is connected to the DI data input terminal of U4. The differential signal pair output by U4 is TTPH_0 (in-phase) and TTPL_0 (out-of-phase).

[0033] Similarly, the channel 1 signals TXD1, RXD1, and CTS1 on the TTP controller U1 are isolated by U3 and driven or received by U5 to form the second differential signal TTPH_1 (in-phase) and TTPL_1 (out-of-phase). The two differential signal pairs (TTPH_0 / TTPL_0, TTPH_1 / TTPL_1) are used as inputs to a double-pole double-throw (DPDT) analog switch (U6), such as the ADG1636. This is a low on-resistance (<1Ω) high-bandwidth switch.

[0034] The channel selection logic is as follows: Pins A1 and A2 of switch U6 are connected to TTPH_0 and TTPH_1 respectively, with the common terminal A connected to the TTPH of the external port; pins B1 and B2 are connected to TTPL_0 and TTPL_1 respectively, with the common terminal B connected to the TTPL of the external port. The address selection pin S of U6 is controlled by the host (U7, such as PowerPC, ARM processor, or FPGA) general-purpose I / O pin GPIO_CH_SEL via isolator (U8). When S is low, A is connected to A1 and B is connected to B1, i.e., CH0 is selected; when S is high, A is connected to A2 and B is connected to B2, i.e., CH1 is selected. Unselected differential signal pairs are disconnected from the external port. Channel switching should be coordinated with transmit enable interlocking and protection wait time to avoid two channels driving the external differential bus simultaneously.

[0035] For example, refer to Figure 4 Controllable termination matching refers to connecting a termination matching branch between the common output terminals TTPH and TTPL of analog switch U6. This branch consists of a termination matching resistor R_term and a controllable switch connected in series with it. R_term can be a 120Ω precision resistor, or it can be set according to the characteristic impedance of the external TTP differential bus port. Because the termination matching branch is located on the common terminal side of U6, CH0 and CH1 share a single termination matching network when selected.

[0036] The control implementation can be as follows: the control terminal of the controllable switch receives the host GPIO_TERM_EN signal through the isolator (U9), causing R_term to connect or disconnect the two differential lines. The controllable switch preferably uses a back-to-back MOSFET, a PhotoMOS solid-state relay, a bidirectional analog switch, a miniature relay, or a controllable termination switch integrated within the differential transceiver. When using a back-to-back MOSFET, the two MOSFETs are connected in series, either source-connected or drain-connected, to suppress the formation of a unidirectional conduction path by a single MOSFET body diode in the off state.

[0037] The adaptive logic is as follows: During the U7 power-on initialization phase, the host reads the device location identification information. This location identification information can come from onboard non-volatile memory, backplane coded resistors, device identification pins, connector keys, DIP switches, remote configuration data, or configuration data sent from the host computer. For example, code "0x01" represents a bus end node, and code "0x02" represents a bus middle node. If the identification result indicates that the communication node is at the end of the bus, the host sets GPIO_TERM_EN to valid, allowing R_term to connect to the bus; if the identification result indicates that the communication node is in the middle of the bus, GPIO_TERM_EN is invalidated, causing R_term to disconnect. If the identification result is conflicting or invalid, the system can either default to disconnecting the terminating resistor or, according to the security policy, maintain the most recent valid configuration and report the configuration anomaly.

[0038] For example, refer to Figure 4 After the matching network comes a two-stage protection circuit.

[0039] First stage (differential mode high energy discharge): A gas discharge tube GDT1 is connected in parallel between TTPH and TTPL, with its two main electrodes connected to TTPH and TTPL respectively; the intermediate electrode or reference terminal is connected to the chassis protective ground (PE). The DC breakdown voltage of GDT1 is selected to be higher than the normal operating voltage of the bus and to meet the surge discharge requirements, in order to discharge the high-energy transient current generated by lightning strike induction or surge.

[0040] The second stage (differential / common-mode fast clamping): After GDT1, near the channel selection switch or differential transceiver side, a bidirectional transient voltage suppressor diode (TVS1) is connected in parallel. Its clamping voltage is lower than the maximum withstand voltage of subsequent devices, used for fast response and clamping residual overvoltage. Common-mode protection can be achieved by connecting two transient voltage suppressor diodes in series across TTPH and TTPL, with the midpoint of the series connection connected to PE, or by placing low-capacitance TVS devices between the lines and PE to clamp common-mode overvoltage of any differential line to PE. The parasitic capacitance of the protection devices should be selected according to the TTP target rate to avoid excessive distortion of the differential signal edges.

[0041] The above protection combination can be selected and verified according to the airborne environmental test requirements such as DO-160G Section 22 (lightning-induced transient sensitivity) and Section 25 (electrostatic discharge). In cases of low lightning strike level or limited space, the GDT can be omitted and only the bidirectional TVS between lines and the common-mode TVS between lines and the protective ground can be used to simplify the protection.

[0042] Example reference Figure 5 The hardware fail-safe logic of this application is implemented by a small programmable logic device (CPLD) (U11) or discrete logic gates to generate transmit enable signals (DE0, DE1) for transceivers U4 and U5. Figure 5 The input signal area, logic processing area, and output area are all expanded according to six types of input conditions.

[0043] The input signals include: RST_OK: Reset signal is valid and can be obtained by converting an external hardwired reset signal to an effective level.

[0044] WDG_OK: Watchdog valid signal, which can be output by the independent watchdog chip U12; this signal becomes invalid when the host fails to feed the watchdog through the GPIO_WDI pin within the specified time.

[0045] PWR_OK: Valid signal for isolated power supply or bus-side power supply, which can be provided by power monitoring circuitry or undervoltage detection circuitry.

[0046] HOST_TXEN: A transmit enable signal (active high) actively output by host U7 based on application logic (such as system health status).

[0047] CTS0, CTS1: TTP transmit enable signals (active high) from two channels of the TTP controller, respectively.

[0048] CH0_SEL and CH1_SEL: These represent the status signals of the channel selection switch that currently select only CH0 or CH1, respectively. They can be obtained by decoding GPIO_CH_SEL or by the feedback contact or status detection circuit of the channel selection switch.

[0049] Logical implementation: Implement the following Boolean equations in CPLD U11: DE0 = RST_OK&WDG_OK&PWR_OK&HOST_TXEN&CTS0&CH0_SEL DE1 = RST_OK&WDG_OK&PWR_OK&HOST_TXEN&CTS1&CH1_SEL This logic means that six conditions must be met simultaneously for the transmitter of the corresponding channel to be enabled: reset, watchdog timer enabled, power supply enabled, host transmission allowed, TTP protocol layer transmission allowed, and the corresponding channel selected. Any anomaly (such as CPU reset, program crash triggering the watchdog timer, abnormal isolation power supply or bus-side power supply, software-activated disablement, TTP protocol layer disallowing transmission, or invalid CH_SEL state) will immediately disable the transmitter of the corresponding channel (DE=0, entering receive or high-impedance state). When the channel selection state cannot uniquely determine the currently selected channel, both DE0 and DE1 remain invalid to prevent faulty nodes or unselected channels from interfering with bus communication at the hardware level.

[0050] For example, a simplified design can be adopted in cost-sensitive or space-constrained applications: Isolation: Capacitively coupled digital isolators, magnetically coupled digital isolators, or high-speed optocouplers can be used, but the requirements for TTP target rate, propagation delay, lifetime, and common-mode transient immunity must be met.

[0051] Control logic: The above transmit enable interlock logic can be implemented using CPLD, FPGA, gate array, security monitoring chip, or multi-input AND gate chip with inverter, without being limited to a single CPLD device.

[0052] Matching resistor control: Manual DIP switches, self-locking switches, or jumper caps can be used instead of automatic controllable switches. Instructions should be marked on the device casing indicating that the appropriate switch needs to be connected when the device is installed at the "end of the bus".

[0053] Protection circuit: It can be simplified to set a low capacitance TVS between the line pairs and PE for basic common mode protection, and set a bidirectional TVS between the lines for differential mode protection, omitting GDT. It is suitable for occasions with relatively mild electromagnetic environment or low lightning strike level.

[0054] For example, such as Figure 6As shown, based on the aforementioned hardware, the software within the host (U7) needs to execute the following process, including runtime channel security switching steps S1 to S9. Figure 6 The process markers in the code correspond one-to-one: Figure 6 Steps S1 to S9 correspond to the following: S1 Detects the current channel communication quality and determines whether the current channel meets the switching conditions; S2 Cancels HOST_TXEN or forces DE0 and DE1 to be invalid; S3 Waits for a first protection time not less than the sum of the differential transceiver transmission prohibition time, the channel selection switch opening time, and the bus signal stabilization time; S4 Changes CH_SEL to switch the channel selection switch to the backup channel; S5 Waits for the channel selection switch conduction establishment time and the external differential line stabilization time; S6 Enables the backup channel receive link and performs resynchronization, reconfiguration, or communication stack recovery; S7 Determines whether all six conditions—RST_OK, WDG_OK, PWR_OK, HOST_TXEN, backup channel CTSi, and backup channel CHi_SEL—are valid; S8 Restores backup channel transmission enable when all six conditions are valid; S9 Records the switching event and reports an alarm.

[0055] Power-on initialization: a. Read the device location identifier code in the NVM (or detect the physical signal for device identification).

[0056] b. Set the GPIO_TERM_EN pin state according to the identifier code to control the terminating resistor.

[0057] c. Initialize the GPIO_CH_SEL pin, CH0 is selected by default.

[0058] d. Initialize the TTP controller and driver.

[0059] e. Start the watchdog timer.

[0060] Operational monitoring and switchover: a. Periodically (or during an interrupt service routine) "feed" the watchdog.

[0061] b. Monitor your own health status and network management information in real time.

[0062] c. If software diagnostics or hardware feedback, such as transceiver error flags, frame loss counts, synchronization loss counts, and network management status, detects that the communication quality of the currently active channel (e.g., CH0) is deteriorating, a safe handover will be performed, provided it complies with the TTP network management policy. i. Record and notify of the current channel anomaly; or use application layer protocols or network management mechanisms to record and notify.

[0063] ii. Cancel HOST_TXEN, or force DE0 and DE1 to be invalid by hardware-sent enable logic, so that both differential transceivers enter receive or high-impedance state.

[0064] iii. Wait for a protection time no less than the sum of the differential transceiver transmission disable time, the channel selection switch open time, and the bus signal stabilization time; then change GPIO_CH_SEL to switch U6 to the standby channel (CH1).

[0065] iv. Waiting for the channel selection switch to activate and for the external differential line to stabilize.

[0066] v. Re-enable the receive link of the backup channel and perform resynchronization, reconfiguration, or communication stack recovery based on the TTP controller state.

[0067] vi. Backup channel transmit enable is restored only when all six conditions—RST_OK, WDG_OK, PWR_OK, HOST_TXEN, backup channel CTSi, and backup channel CHi_SEL—are valid, and the backup channel has completed resynchronization or the communication stack has recovered. Through this process, the two differential transceivers will not simultaneously drive the same external differential bus during the handover.

[0068] Fail-safe response: When WDG_OK becomes invalid due to software failure, RST_OK becomes invalid, PWR_OK becomes invalid, HOST_TXEN becomes invalid, CTS becomes invalid, or CH_SEL becomes illegal, the hardware transmit enable logic immediately disables the transmit enable of the corresponding channel or two channels; this fault-safe response does not rely on the host software to execute periodically, and can isolate the faulty node from the external TTP bus at the hardware level.

[0069] As can be seen from the detailed embodiments above, this application combines hardware circuit design with software control logic to form a complete PHY solution from TTP controller pins to external connectors. Specifically, the dual-isolation transceiver tributary selection under a single external port, common-end terminal matching, common-end transient protection, and hardware transmit enable interlocking couple the PHY with the system's fail-safe architecture, making it suitable for TTP network applications with high security requirements.

[0070] This application also provides a communication node suitable for TTP networks, including a main processor, a TTP protocol controller, a configuration identification circuit, a power monitoring circuit, an external TTP connector, and the aforementioned highly flexible, secure, and redundant PHY architecture for TTP networks. The main processor configures the TTP protocol controller via a local bus and controls the channel selection switch and terminal matching branch via isolated control signals; the configuration identification circuit provides machine or bus position identification information; the power monitoring circuit sends enable logic to the hardware to provide the isolated power supply or bus-side power status and generates a PWR_OK signal; during channel switching, the main processor first cancels HOST_TXEN or forces DE0 and DE1 to invalidate via hardware enable logic, and after the protection time, channel switching time, and backup channel synchronization recovery are completed, it restores the backup channel transmission enable according to six valid conditions.

[0071] When the communication node is installed in the end slot of the bus, the configuration identification circuit outputs the end identifier, and the main processor or hardware sends the terminal switching control logic other than the enable logic to the terminal matching resistor; when the communication node is installed in the middle slot, the terminal matching resistor is disconnected.

[0072] When the main processor is reset, the watchdog timeout occurs, the power supply valid signal is invalid, the TTP protocol controller does not allow transmission, the host transmit enable signal is invalid, the channel selection signal is illegal, or the selected communication channel cannot be uniquely determined, the communication node remains in receive state or high impedance state and does not send signals to the external TTP bus.

[0073] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A highly flexible, secure, and redundant PHY architecture for TTP networks, characterized in that, include: The TTP protocol controller has a first communication channel and a second communication channel; The first isolated transceiver branch is connected to the first communication channel and includes a first digital isolator and a first differential transceiver, wherein the first differential transceiver outputs a first differential signal pair; The second isolated transceiver branch, connected to the second communication channel, includes a second digital isolator and a second differential transceiver, wherein the second differential transceiver outputs a second differential signal pair; The channel selection switch has a first input terminal connected to the first differential signal pair, a second input terminal connected to the second differential signal pair, and a common terminal connected to the same external TTP differential bus port. According to the channel selection signal, it will only connect one of the first differential signal pair or the second differential signal pair to the external TTP differential bus port in both directions. The terminal matching branch is connected between the two differential lines of the common terminal of the channel selection switch, and includes a terminal matching resistor and a controllable switch connected in series therewith. The controllable switch connects or disconnects the terminal matching resistor according to the location identification information of the communication node. A transient protection circuit is installed on the external TTP differential bus port side or the common terminal side of the channel selection switch to provide common-mode and differential-mode transient protection for the two differential lines. The hardware transmit enable logic is used to generate transmit enable signals for the first differential transceiver and the second differential transceiver based on the reset release signal, watchdog valid signal, power valid signal, host transmit enable signal, TTP transmit enable signal of the corresponding communication channel, and the channel selection signal, respectively. When any fault signal is invalid or the corresponding communication channel is not selected, the corresponding differential transceiver is prohibited from transmitting.

2. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The first digital isolator and the second digital isolator are respectively disposed between the TTP protocol controller and the corresponding differential transceiver. The first differential transceiver and the second differential transceiver are powered by an isolation power supply, so that the controller-side ground is electrically isolated from the bus-side ground.

3. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The channel selection switch is a double-pole double-throw analog switch, a solid-state relay array, or a dual-channel differential analog switch; when one differential signal pair is selected, the other unselected differential signal pair is disconnected from the external TTP differential bus port.

4. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The location identification information comes from non-volatile memory, backplane encoding, machine position identification pins, connector keys, DIP switches, or remote configuration data; when the location identification information indicates that the communication node is at the end of the bus, the terminal matching resistor is connected; when the location identification information indicates that the communication node is in the middle of the bus, the terminal matching resistor is disconnected.

5. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The transient protection circuit includes: A high-energy discharge stage, located close to the external TTP differential bus port, includes a gas discharge tube for discharging high-energy surges. A fast clamping stage, located close to the differential transceiver side, includes a line-to-line bidirectional transient suppression diode and / or a line-pair protective ground common-mode transient suppression diode.

6. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The hardware transmit enable logic generates a transmit enable signal according to the following logic: DE0 = RST_OK & WDG_OK & PWR_OK & HOST_TXEN & CTS0 & CH0_SEL; DE1 = RST_OK & WDG_OK & PWR_OK & HOST_TXEN & CTS1 & CH1_SEL; Among them, RST_OK is the reset release valid signal, WDG_OK is the watchdog valid signal, PWR_OK is the isolation power supply or bus side power supply valid signal, and HOST_TXEN is the host transmit enable signal; CTS0 and CTS1 respectively send TTP enable signals for the first and second communication channels; CH0_SEL and CH1_SEL are the status signals for the first and second communication channels being selected, respectively. When either condition is invalid, the corresponding enable signal is prohibited from being sent.

7. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 6, characterized in that, In any of the following states: reset not released, watchdog timer invalid, host not initialized, power valid signal invalid, channel selection signal illegal, or the selected communication channel cannot be uniquely determined, the hardware transmit enable logic will set the transmit enable signals of both the first differential transceiver and the second differential transceiver to invalid.

8. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The resistance of the terminal matching resistor is 120Ω, or it can be set according to the characteristic impedance of the external TTP differential bus port; the controllable switch is a back-to-back MOSFET, a PhotoMOS solid-state relay, a bidirectional analog switch, a miniature relay, or a controllable terminal switch integrated inside the differential transceiver.

9. The highly flexible, secure, and redundant PHY architecture for TTP networks according to claim 1, characterized in that, The differential transceiver is an RS-485 differential transceiver or an RS-422 differential transceiver that meets the TTP target communication rate, propagation delay and temperature rating requirements.

10. A communication node suitable for TTP networks, characterized in that, It includes a main processor, a TTP protocol controller, a configuration identification circuit, a power monitoring circuit, an external TTP connector, and a highly flexible, secure, redundant PHY architecture for TTP networks as described in any one of claims 1 to 9; The power monitoring circuit is used to send an enable logic to the hardware to provide a power valid signal. When the main processor performs channel switching, it first cancels the host transmit enable signal or invalidates the transmit enable signals of the two differential transceivers by sending the enable logic through the hardware. After waiting for a protection time of not less than the sum of the differential transceiver transmit disable time, the channel selection switch open time, and the bus signal stabilization time, it changes the channel selection signal. Then it waits for the channel selection switch conduction establishment time and the external differential line stabilization time. Only when the backup channel completes resynchronization or communication stack recovery, the reset release signal is valid, the watchdog valid signal is valid, the power valid signal is valid, the host transmit enable signal is valid, the backup channel's TTP transmit enable signal is valid, and the backup channel is selected, does it restore the backup channel's transmit enable signal.