A Safety Cutting Method and Device Based on Eigenvalue Virtual Fuse

By adopting a safe cutting method of characteristic value virtual fuse on the safe digital output board, the problems of high hardware circuit dependence and maintenance costs in the prior art are solved, and efficient and safe fault holding and cutting processing are achieved.

CN114398196BActive Publication Date: 2025-06-17CASCO SIGNAL LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111551843.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-17
Publication Date
2025-06-17
Estimated Expiration
2041-12-17

AI Technical Summary

Technical Problem

The existing safe digital output boards have problems such as hardware circuit dependence in the fault maintenance design, requiring special inspection circuits, increasing maintenance costs and time, and mistouching will expand the detection range.

Method used

A safe cut-off method based on characteristic value virtual fuse is adopted, and redundant code values ​​are generated through dual-channel software and hardware self-test, and safe cut-off is achieved through GPIO settings and shift register string conversion in a timing interrupt.

Benefits of technology

The requirements for fault preservation are realized, while reducing hardware circuit dependence, reducing maintenance costs and time, and avoiding unnecessary detection caused by mistouch.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114398196B_ABST
    Figure CN114398196B_ABST
Patent Text Reader

Abstract

The present invention relates to a safety cut-off method and device based on eigenvalue virtual fuses. The method includes: S1, each of the dual-channel software performs self-check; S2, the eigenvalue of the self-check result of the software is stored in the non-volatile storage area exclusive to the software; Step S3, each of the dual-channel hardware performs self-check; Step S4, the eigenvalue of the self-check result of the hardware is stored in the non-volatile storage area exclusive to the hardware; Step S5, perform a read-write ability self-check on the non-volatile storage area used; Step S6, the eigenvalue of the self-check result of the non-volatile storage area is stored in the memory area; Step S7, all the self-check result eigenvalues of the software and hardware are interacted through the data channel between the dual channels and stored in the non-volatile storage area of the other party; Step S8, these eigenvalues are combined into a redundant code value with unique correctness through a fusion algorithm, etc. Compared with the prior art, the present invention has the advantages of not only meeting the requirements of fault retention, but also being safe, efficient and extremely simplified in design, etc.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a safety digital quantity output type board card, in particular to a safety cutting method and device based on a characteristic value virtual fuse. Background Art

[0002] Currently, there is a fault retention design on the safety digital output board, the purpose of which is to prevent the faulty board from resuming work without completely locating and solving the problem. The method of achieving fault retention is mainly to disconnect the output power supply by outputting a fuse instruction through software to blow the hardware fuse. Although this method can achieve a good fault retention effect, the fuse instruction of blowing the hard fuse may be falsely triggered, and it may not be caused by the fault of the board itself. Moreover, the method of blowing the hard fuse also brings inconvenience to on-site maintenance (fuses and corresponding detection equipment must be always available), which is not friendly to scenarios that require short-term repairs. In summary, the prior art has the following obvious disadvantages:

[0003] 1. It is necessary to design a hardware circuit to implement the hardware fuse blowing function.

[0004] 2. A special detection circuit needs to be designed for the fuse's fusing capacity.

[0005] 3. Spare parts and testing equipment are required, which increases maintenance costs.

[0006] 4. Replacing the fuse will increase maintenance time.

[0007] 5. False touch will expand the detection range unnecessarily. Summary of the invention

[0008] The purpose of the present invention is to overcome the defects of the above-mentioned prior art and provide a safe cutting method and device based on a characteristic value virtual fuse, which not only meets the requirements of fault retention, but is also safe, efficient and extremely simplified in design.

[0009] The purpose of the present invention can be achieved by the following technical solutions:

[0010] According to a first aspect of the present invention, a safe cutting method based on a characteristic value virtual fuse is provided, the method comprising the following steps:

[0011] Step S1, dual-channel software self-checks respectively;

[0012] Step S2, the characteristic value of the self-test result of the software is stored in a non-volatile storage area dedicated to the software;

[0013] Step S3, dual-channel hardware self-checks respectively;

[0014] Step S4, the characteristic value of the hardware self-test result is stored in a non-volatile storage area dedicated to the hardware;

[0015] Step S5, performing a self-check of the read and write capabilities of the non-volatile storage area used;

[0016] Step S6, the characteristic value of the self-test result of the non-volatile storage area is stored in the memory area;

[0017] Step S7, exchanging all hardware and software self-test result characteristic values ​​through the data channel between the two channels, and storing them in the non-volatile storage area of ​​the other party;

[0018] Step S8, combining these feature values ​​into a redundant code value with unique correctness through a fusion algorithm;

[0019] Step S9, in the dual-channel timing interruption, the GPIO is set in time-sharing according to each bit value of the respective redundant code;

[0020] Step S10, the GPIO timing output is sent to the shift register and the shift signal of the channel is triggered at the same time;

[0021] Step S11, the redundant code information after serial-to-parallel conversion by the shift register is compared with the value comparator, and if the preset state is consistent with the redundant code information, it is output, and if it is inconsistent, it is not output.

[0022] As a preferred technical solution, the step S1, the dual-channel software self-checks each of the following specifically: each channel performs an online self-check of the software according to the original software self-check logic, and reflects the self-check result on the software characteristic value.

[0023] As a preferred technical solution, the self-check fault information of the software and the fault information detected during operation are fed back to a software-specific non-volatile storage area that can be written by the software.

[0024] As a preferred technical solution, the step S3, the dual-channel hardware self-check is specifically: each channel performs an online hardware self-check according to the original hardware self-check logic, and reflects the self-check result on the hardware characteristic value.

[0025] As a preferred technical solution, the hardware's self-check fault information and the fault information detected during operation are fed back to a hardware-specific non-volatile storage area that can be written by software.

[0026] As a preferred technical solution, the step S5 of performing a self-check on the read / write capability of the non-volatile storage area used is specifically as follows:

[0027] The non-volatile storage area used is tested for read and write of all 0s, all 1s, and random values.

[0028] As an optimal technical solution, the read-write detection includes a temporary storage area and an exclusive area for characteristic values. The temporary storage area is detected first, and then the exclusive area is detected. The characteristic value must be transferred when the corresponding area is self-checked, so as to ensure that the characteristic value remains unchanged before and after the exclusive area self-check.

[0029] As a preferred technical solution, the method mutually checks and stores fault information through dual CPU channels.

[0030] As a preferred technical solution, the method's software and hardware failures can be effectively cut off from output in a timely manner through feature value coding.

[0031] According to a second aspect of the present invention, there is provided a safety cut-off device based on a characteristic value virtual fuse, the device comprising:

[0032] Software self-check module, used for self-check of dual-channel software;

[0033] A software self-test result storage module is used to store the characteristic value of the software's self-test result in a non-volatile storage area dedicated to the software;

[0034] Hardware self-test module, used for dual-channel hardware self-test;

[0035] A hardware self-test result storage module is used to store the characteristic value of the hardware self-test result in a hardware-specific non-volatile storage area;

[0036] A read / write capability self-check module is used to perform a read / write capability self-check on the non-volatile storage area used;

[0037] A storage module for storing self-test results is used to store the characteristic value of the self-test result of the non-volatile storage area into the memory area;

[0038] The interaction module is used to exchange all the characteristic values ​​of the self-test results of software and hardware through the data channel between the two channels, and store them in the non-volatile storage area of ​​the other party;

[0039] A redundant code generation module, used to combine these characteristic values ​​into a redundant code value with unique correctness through a fusion algorithm;

[0040] The GPIO setting module is used to set the GPIO in a timed interrupt of a dual channel according to the value of each bit of the respective redundant code;

[0041] The shift register serial-to-parallel module is used to send the GPIO timing output to the shift register and trigger the shift signal of the channel at the same time;

[0042] The comparison module is used to compare the redundant code information after the serial-to-parallel conversion by the shift register with the numerical comparator. If the preset state is consistent with the redundant code information, it is output, and if it is inconsistent, it is not output.

[0043] According to a third aspect of the present invention, there is provided an electronic device, including a memory and a processor, wherein a computer program is stored on the memory, and when the processor executes the program, the method described above is implemented.

[0044] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described above is implemented.

[0045] Compared with the prior art, the present invention has the following advantages:

[0046] 1. The present invention designs a safety output cut-off method based on eigenvalue-based virtual fuses.

[0047] 2. The present invention reduces the dependence on hardware circuits and can be implemented with simple shift registers and numerical comparators.

[0048] 3. The present invention does not require real hardware fuses, reducing maintenance costs.

[0049] 4. For software and hardware failures of the present invention, the output can be cut off in a timely and effective manner through eigenvalue coding, achieving the purpose of fail-safe response.

[0050] 5. For the present invention, software and hardware cut-off processing can occur simultaneously, without waiting for a cut-off instruction from software to hardware and then making the software enter a non-output state.

[0051] 6. For the present invention, fault retention does not need to be achieved through permanent physical cut-off. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 It is a schematic diagram of the system module structure;

[0053] Figure 2 It is a flowchart of the method of the present invention;

[0054] Figure 3 It is a schematic diagram of the functional modules of the device of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] As Figure 2 shown, the specific implementation steps of the method of the present invention are as follows.

[0057] Step 1: Each channel performs online software self-checking according to the original software self-checking logic, and reflects the self-checking result on the software characteristic value.

[0058] Step 2: The characteristic value of the software self-checking result is stored in the non-volatile storage area dedicated to the software.

[0059] Step 3: Each channel performs online hardware self-checking according to the original hardware self-checking logic, and reflects the self-checking result on the hardware characteristic value.

[0060] Step 4: The characteristic value of the hardware self-checking result is stored in the non-volatile storage area dedicated to the hardware.

[0061] Step 5: Perform read and write detection of all 0s, all 1s, and random values on the non-volatile storage area used. This detection involves the temporary storage area and the dedicated area of the characteristic value. First, detect the temporary storage area, and then detect the dedicated area. The characteristic value needs to be transferred during the self-checking in the corresponding area to ensure that the characteristic value remains unchanged before and after the self-checking in the dedicated area.

[0062] Step 6: The characteristic value of the self-checking result of the non-volatile storage area is stored in the memory area.

[0063] Step 7: Interact all software and hardware self-checking result characteristic values through the data channel between the two channels and store them in the non-volatile storage area of the other party.

[0064] Step 8: Use a fusion algorithm to form a redundant code value with unique correctness from these characteristic values.

[0065] Step 9: In the periodic interrupt of the two channels, set the GPIO according to each bit value of the respective redundant code at different times.

[0066] Step 10: While the GPIO periodically outputs to the shift register, trigger the shift signal of this channel for the channel.

[0067] Step 11: After the serial-parallel conversion by the shift register, compare the redundant code information with the numerical comparator. If the preset state is consistent with the redundant code information, output; otherwise, do not output.

[0068] The present invention has the following characteristics:

[0069] I. Centralized collection and recording of fault detection information:

[0070] 1. Hardware fault information, the self-checking fault information of the hardware, and the fault information detected during operation are all fed back to a non-volatile memory area that can be written by the software.

[0071] 2. Software fault information, the self-checking fault information of the software, and the fault information detected during operation are all fed back to a non-volatile memory area that can be written by the software.

[0072] II. Validity Processing and Storage Method for Fault Information Recording:

[0073] 1. Characterize the fault information eigenvalues to prevent single-bit flipping.

[0074] 2. Dual CPU channels are required for mutual verification and storage of fault information.

[0075] III. Method for Effectively Reflecting Fault Information:

[0076] 1. Check the storage validity of the non-volatile storage area.

[0077] 2. Effectively fuse the characteristic values of software and hardware fault states into a redundant code.

[0078] 3. The software sets the GPIO according to the redundant code in the periodic interrupt.

[0079] 4. The GPIO output converts the redundant code from serial to parallel through a shift register and gives it to a numerical comparator to control the final output.

[0080] IV. The non-volatile storage area ensures that the previous information is not lost after restart, achieving fault retention.

[0081] The above is the introduction of the method embodiment. The following further illustrates the solution of the present invention through the device embodiment.

[0082] As Figure 3 shown, the safety cut-off device of the present invention based on eigenvalue virtual fuses includes:

[0083] A software self-checking module 100 for self-checking each of the two channels of software;

[0084] A software self-checking result storage module 200 for storing the eigenvalue of the software self-checking result into the non-volatile storage area exclusive to the software;

[0085] A hardware self-checking module 300 for self-checking each of the two channels of hardware;

[0086] A hardware self-checking result storage module 400 for storing the eigenvalue of the hardware self-checking result into the non-volatile storage area exclusive to the hardware;

[0087] A read / write ability self-checking module 500 for performing a read / write ability self-check on the non-volatile storage area used;

[0088] A storage self-checking result storage module 600 for storing the eigenvalue of the self-checking result of the non-volatile storage area into the memory area;

[0089] An interaction module 700 for interacting all software and hardware self-checking result eigenvalues through the data channels between the two channels and storing them into the non-volatile storage area of the other party;

[0090] The redundant code generation module 800 is used to form a redundant code value with unique correctness by fusing algorithms for these eigenvalue values;

[0091] The GPIO setting module 900 is used to set the GPIO time-divisionally according to each bit value of the respective redundant code in the dual-channel timing interrupt;

[0092] The shift register serial-to-parallel conversion module 1000 is used to trigger the shift signal of this channel for the channel while the GPIO outputs to the shift register regularly;

[0093] The comparison module 1100 is used to compare the redundant code information after the serial-to-parallel conversion by the shift register with the numerical comparator. If the preset state is consistent with the redundant code information, it outputs; otherwise, it does not output.

[0094] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described modules can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0095] The electronic device of the present invention includes a central processing unit (CPU), which can execute various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) or computer program instructions loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The CPU, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.

[0096] Multiple components in the device are connected to the I / O interface, including: an input unit, such as a keyboard, a mouse, etc.; an output unit, such as various types of displays, speakers, etc.; a storage unit, such as a magnetic disk, an optical disc, etc.; and a communication unit, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit allows the device to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0097] The processing unit executes the various methods and processes described above, such as methods S1 to S11. For example, in some embodiments, methods S1 to S11 may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed onto the device via the ROM and / or the communication unit. When the computer program is loaded into the RAM and executed by the CPU, one or more steps of methods S1 to S11 described above may be executed. Alternatively, in other embodiments, the CPU may be configured to execute methods S1 to S11 by any other suitable means (e.g., by means of firmware).

[0098] The functions described above herein may be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on a chip (SOC), complex programmable logic devices (CPLD), and the like.

[0099] The program code for implementing the methods of the present invention may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, a special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.

[0100] In the context of the present invention, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0101] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A safety cut-off method based on eigenvalue virtual fuses, characterized in that, The method comprises the following steps: Step S1, dual-channel software self-checks respectively; Step S2, the characteristic value of the self-test result of the software is stored in a non-volatile storage area dedicated to the software; Step S3, dual-channel hardware self-checks respectively; Step S4, the characteristic value of the hardware self-test result is stored in a non-volatile storage area dedicated to the hardware; Step S5, performing a self-check of the read and write capabilities of the non-volatile storage area used; Step S6, the characteristic value of the self-test result of the non-volatile storage area is stored in the memory area; Step S7, exchanging all hardware and software self-test result characteristic values ​​through the data channel between the two channels, and storing them in the non-volatile storage area of ​​the other party; Step S8, combining these feature values ​​into a redundant code value with unique correctness through a fusion algorithm; Step S9, in the dual-channel timing interruption, the GPIO is set in time-sharing according to each bit value of the respective redundant code; Step S10, the GPIO timing output is sent to the shift register and the shift signal of the channel is triggered at the same time; Step S11, the redundant code information after serial-to-parallel conversion by the shift register is compared with the value comparator, and if the preset state is consistent with the redundant code information, it is output, and if it is inconsistent, it is not output; The step S1, the dual-channel software self-checks separately, specifically: each channel performs an online self-check of the software according to the original software self-check logic, and reflects the self-check result on the software characteristic value; the software self-check fault information and the fault information detected during the operation are fed back to the software-specific non-volatile storage area that can be written by the software.

2. The safety cut-off method based on eigenvalue virtual fuses according to claim 1, characterized in that, The step S3, the dual-channel hardware self-check is specifically: each channel performs an online hardware self-check according to the original hardware self-check logic, and reflects the self-check result on the hardware characteristic value.

3. The safety cut-off method based on eigenvalue virtual fuses according to claim 2, characterized in that, The hardware's self-test fault information and the fault information detected during operation are fed back to the hardware-specific non-volatile storage area that can be written by the software.

4. The safety cut-off method based on eigenvalue virtual fuses according to claim 1, characterized in that, The step S5 of performing a self-check on the read / write capability of the non-volatile storage area used is specifically as follows: The non-volatile storage area used is tested for read and write of all 0s, all 1s, and random values.

5. The safety cut-off method based on eigenvalue virtual fuses according to claim 4, characterized in that, The read-write detection includes a temporary storage area and an exclusive area for characteristic values. The temporary storage area is detected first, and then the exclusive area is detected. The characteristic value needs to be transferred when the corresponding area is self-checked, so as to ensure that the characteristic value remains unchanged before and after the exclusive area self-check.

6. The safety cut-off method based on eigenvalue virtual fuses according to claim 1, characterized in that, The method mutually checks and stores fault information through dual CPU channels.

7. The safety cut-off method based on eigenvalue virtual fuses according to claim 1, characterized in that, The software and hardware failures of this method can be effectively cut off from output in a timely manner through eigenvalue coding.

8. A safety cut-off device based on eigenvalue virtual fuses, characterized in that, The device includes: Software self-check module, used for self-check of dual-channel software; A software self-test result storage module is used to store the characteristic value of the software's self-test result in a non-volatile storage area dedicated to the software; Hardware self-test module, used for dual-channel hardware self-test; A hardware self-test result storage module is used to store the characteristic value of the hardware self-test result in a hardware-specific non-volatile storage area; A read / write capability self-check module is used to perform a read / write capability self-check on the non-volatile storage area used; A storage module for storing self-test results is used to store the characteristic value of the self-test result of the non-volatile storage area into the memory area; The interaction module is used to exchange all the characteristic values ​​of the self-test results of software and hardware through the data channel between the two channels, and store them in the non-volatile storage area of ​​the other party; A redundant code generation module, used to combine these characteristic values ​​into a redundant code value with unique correctness through a fusion algorithm; The GPIO setting module is used to set the GPIO in a timed interrupt of a dual channel according to the value of each bit of the respective redundant code; The shift register serial-to-parallel module is used to send the GPIO timing output to the shift register and trigger the shift signal of the channel at the same time; A comparison module is used to compare the redundant code information after the serial-to-parallel conversion by the shift register with the value comparator, and output if the preset state is consistent with the redundant code information, and not output if they are inconsistent; The dual-channel software self-check is specifically as follows: each channel performs an online self-check of the software according to the original software self-check logic, and reflects the self-check result on the software characteristic value; the software self-check fault information and the fault information detected during operation are fed back to the software-specific non-volatile storage area that can be written by the software.

9. An electronic device, comprising a memory and a processor, wherein a computer program is stored on the memory, characterized in that, When the processor executes the program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Relay protection device multi-core CPU embedded system processing method and platform

    CN108155619A

  • Function self-monitoring and measurement signal processor for vibration-fill-state limit switches - has parallel-working microprocessors each associated with pair of safety relays, which are switched-over for each self-test while maintaining connection state with external relay

    DE4232720C1