A system for judging the dual-system master-slave status that meets the safety level of SIL4

By using the same structure single-mode channel and hard-wire synchronization circuit in the dual-machine hot standby system, the problem of main and standby status judgment caused by communication interference is solved, and a high-security level dual-system main and standby status judgment is achieved to prevent the dual-main status and ensure the stable operation of the system.

CN114675583BActive Publication Date: 2025-08-01SHENZHEN METRO OPERATION GRP CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210463311.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-03-31
Filing Date
2022-04-28
Publication Date
2025-08-01
Estimated Expiration
2042-04-28

AI Technical Summary

Technical Problem

In a dual-machine hot standby system, communication interference causes information to be unable to be exchanged between the two systems and the main standby state cannot be judged, which may lead to a dual main state and affect system security.

Method used

The first single-mode channel and the second single-mode channel with the same structure are adopted, including the first CPU, the second CPU, the first FPGA module and the second FPGA module, data exchange is performed through the external bus EMIF, and hard-wire synchronization and data isolation is used using a field effect tube relay and a photocoupler. Combined with the SPI communication interface circuit, the judgment of the dual-system main and standby state is realized.

Benefits of technology

Effectively judge the dual-system main and standby status, prevent the dual-main status, ensure the safety and reliability of the system, and comply with the SIL4 safety level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114675583B_ABST
    Figure CN114675583B_ABST
Patent Text Reader

Abstract

The present invention discloses a system for judging the primary / backup status of a dual system that meets the safety level of SIL4, which relates to the technical field of dual-machine hot standby systems; it includes a first single-mode channel and a second single-mode channel that are both connected to the backplane and have the same structure; the first single-mode channel includes a first CPU, a second CPU, a first FPGA module, a second FPGA module, and a backplane interface. The first FPGA module and the second FPGA module are both connected to the backplane interface, and a master / slave status output circuit and a master / slave status acquisition circuit are provided between the first FPGA module and the backplane interface and between the second FPGA module and the backplane interface respectively; the first single-mode channel and the second single-mode channel are respectively connected to the backplane through their respective backplane interfaces, and the first single-mode channel and the second single-mode channel respectively output two groups of SPI signals through the SPI communication interface circuit between them and the backplane interface; the beneficial effect of the present invention is that it can effectively judge the primary / backup status of the dual system and ensure data exchange between the dual systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of dual - machine hot - standby systems. More specifically, the present invention relates to a system for judging the primary - standby state of a dual - system that meets the safety level of SIL4. Background Art

[0002] Due to its high availability and reliability, and at the same time having a certain fault - tolerance ability, and being convenient for operators to maintain, the dual - machine hot - standby system is widely used in various control systems.

[0003] In a dual - machine hot - standby system, the presetting and switching of the "primary system" and the "standby system" are the keys to realizing the functions of the dual - machine hot - standby system. In a dual - machine hot - standby system, the interlock logic implemented by hardware or software is relied on between the two systems to confirm the "primary" or "standby" state of the two systems. Information is exchanged between the two systems through a specific communication method to implement the interlock logic between the two systems.

[0004] In the prior art, since the information exchange depends on the mutual communication between the two systems, and the communication is bound to be affected by various interferences. In extreme cases, once the communication between the two systems is cut off, the interlock logic between the two systems cannot exchange information, and it cannot be judged whether the "system" of the other party in the dual - machine hot - standby system exists. As a result, the original "primary" system still maintains the primary state, and the original "standby" system mistakenly upgrades to the "primary" system, thus resulting in a dual - primary state. The dual - primary state will affect the control logic of the dual - machine hot - standby system and bring greater risks to the normal operation of the dual - machine hot - standby system and enter an unsafe state. Summary of the Invention

[0005] In order to overcome the deficiencies of the prior art, the present invention provides a system for judging the primary - standby state of a dual - system that meets the safety level of SIL4.

[0006] The technical solution adopted by the present invention to solve its technical problems is as follows: A system for judging the primary - standby state of a dual - system that meets the safety level of SIL4, the improvement lies in that it includes a first single - mode channel and a second single - mode channel that are both connected to the backplane and have the same structure;

[0007] The first single - mode channel includes a first CPU, a second CPU, a first FPGA module, a second FPGA module, and a backplane interface. Data exchange between the first FPGA module and the first CPU and between the second FPGA module and the second CPU is carried out through the external bus EMIF. The GPIO signals between the first FPGA module and the first CPU and between the second FPGA module and the second CPU are used for hard - wire synchronization between the first CPU and the second CPU and output of the current primary - use state;

[0008] The described first FPGA module and second FPGA module are both connected to the backplane interface. A master-slave status output circuit and a master-slave status acquisition circuit are provided between the first FPGA module and the backplane interface, and between the second FPGA module and the backplane interface;

[0009] The first single-mode channel and the second single-mode channel are respectively connected to the backplane through their respective backplane interfaces. The first single-mode channel and the second single-mode channel respectively output two groups of SPI signals through the SPI communication interface circuit between them and the backplane interface, and output them to the backplane after isolation for data transmission between the first single-mode channel and the second single-mode channel.

[0010] Furthermore, the first CPU and the second CPU are TI's secure MCU chips, which meet the ISO 26262 ASIL D and IEC 61508 SIL 3 certifications, and are a high-performance automotive-grade series of microcontrollers for safety systems.

[0011] Furthermore, there are a synchronization line and a communication line between the first FPGA module and the second FPGA module, which are used for data synchronization and exchange between the first single-mode channel and the second single-mode channel after isolation.

[0012] Furthermore, the master-slave status output circuit between the first FPGA module and the backplane interface includes a field-effect transistor relay RL6. The signal input pin of the field-effect transistor relay RL6 is connected to the first FPGA module, and the output pin of the field-effect transistor relay RL6 is connected to the backplane interface.

[0013] Furthermore, the model of the field-effect transistor relay RL6 is G3VM-201G1.

[0014] Furthermore, the master-slave status acquisition circuit between the first FPGA module and the backplane interface includes an optocoupler U64. The input end of the optocoupler U64 is connected to the backplane interface, and the output end is connected to the first FPGA module;

[0015] The master-slave status acquisition circuit between the second FPGA module and the backplane interface includes an optocoupler U68. The input end of the optocoupler U68 is connected to the backplane interface, and the output end is connected to the second FPGA module.

[0016] Furthermore, the models of the optocoupler U64 and the optocoupler U68 are TLP281.

[0017] Furthermore, the SPI communication interface circuit includes a chip U35, and the model of the chip U35 is ADUM7643.

[0018] The beneficial effects of the present invention are as follows: A system for judging the master-slave status of a dual system that meets the SIL4 safety level of the present invention can effectively judge the master-slave status of the dual system, ensure data exchange between the dual systems, and effectively prevent the occurrence of a dual-master status. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 It is a schematic framework diagram of a system for judging the master-slave status of a dual system that meets the SIL4 safety level of the present invention.

[0020] Figure 2 It is a schematic structural diagram of the master-slave status output circuit in the present invention.

[0021] Figure 3 、 Figure 4 It is a schematic structural diagram of the master-slave status acquisition circuit in the present invention.

[0022] Figure 5 It is a schematic structural diagram of the SPI communication interface circuit in the present invention.

[0023] Figure 6 It is a schematic diagram of the redundant status determination process in the initialization stage of the present invention.

[0024] Figure 7 It is a schematic diagram of the periodic redundancy control process of the present invention.

[0025] Figure 8 It is a schematic diagram of the communication-based redundancy process of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] The present invention will be further described below in conjunction with the drawings and embodiments.

[0027] The concept, specific structure and technical effects of the present invention will be clearly and completely described below in conjunction with the embodiments and drawings to fully understand the purpose, features and effects of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, other embodiments obtained by those skilled in the art without creative efforts shall fall within the scope of protection of the present invention. In addition, all the connection / connection relationships involved in the patent do not refer to the direct connection of components alone, but refer to the more optimal connection structure that can be formed by adding or reducing connection accessories according to the specific implementation situation. The various technical features in the present invention can be combined with each other without conflicting with each other.

[0028] Refer to Figure 1As shown in the figure, the present invention discloses a system for judging the dual-system primary and standby states that meets the safety level of SIL4. Specifically, the system includes a first single-mode channel and a second single-mode channel that are both connected to the backplane and have the same structure. Since the first single-mode channel and the second single-mode channel have the same structure, only the structure of the first single-mode channel will be described in detail hereinafter. This system adopts a 2×2oo2 system architecture, and the single-board main control circuit is designed with a 2oo2 architecture.

[0029] In this embodiment, the first single-mode channel includes a first CPU, a second CPU, a first FPGA module, a second FPGA module, and a backplane interface. The first CPU and the second CPU are TI's safety MCU chips, which meet the ISO26262 ASIL D and IEC 61508 SIL 3 certifications and are a high-performance automotive-grade series of microcontrollers for safety systems. The first FPGA module exchanges data with the first CPU through the external bus EMIF, and the second FPGA module exchanges data with the second CPU through the external bus EMIF. The GPIO signals between the first FPGA module and the first CPU and between the second FPGA module and the second CPU are used for hardwired synchronization between the first CPU and the second CPU and the output of the current primary state.

[0030] Furthermore, the first FPGA module and the second FPGA module are both connected to the backplane interface. A master-slave state output circuit and a master-slave state acquisition circuit are provided between the first FPGA module and the backplane interface and between the second FPGA module and the backplane interface respectively. The first single-mode channel and the second single-mode channel are respectively connected to the backplane through their respective backplane interfaces. The first single-mode channel and the second single-mode channel output two groups of SPI signals through the SPI communication interface circuit between them and the backplane interface, and output them to the backplane after isolation for data transmission between the first single-mode channel and the second single-mode channel. In addition, there are a synchronization line and a communication line between the first FPGA module and the second FPGA module, which are used to achieve data synchronization and exchange between the first single-mode channel and the second single-mode channel after isolation.

[0031] Therefore, the first CPU and the second CPU of the first single-mode channel communicate with the first FPGA module and the second FPGA module respectively through the EMIF. The first FPGA module and the second FPGA module communicate through the serial port and then to the FPGA module of the other channel after isolation, and the FPGA module is for transparent transmission.

[0032] Refer to Figure 2As shown, for the master-slave status output circuit described above, the present invention provides a specific embodiment. The master-slave status output circuit between the first FPGA module and the backplane interface includes a field-effect transistor relay RL6. The signal input pin of the field-effect transistor relay RL6 is connected to the first FPGA module, and the output pin of the field-effect transistor relay RL6 is connected to the backplane interface. In this embodiment, the model of the field-effect transistor relay RL6 is G3VM-201G1. The master status instruction is issued by the CPU, driven by the field-effect transistor relay RL6 after passing through the FPGA module, and then isolated and output, and output to the pair system through the backplane to collect this status.

[0033] Referring to Figure 3 As shown, for the master-slave status acquisition circuit described above, the present invention provides a specific embodiment. The master-slave status acquisition circuit between the first FPGA module and the backplane interface includes an optocoupler U64. The input end of the optocoupler U64 is connected to the backplane interface, and the output end is connected to the first FPGA module; Referring to Figure 4 As shown, the master-slave status acquisition circuit between the second FPGA module and the backplane interface includes an optocoupler U68. The input end of the optocoupler U68 is connected to the backplane interface, and the output end is connected to the second FPGA module. In this embodiment, the models of the optocoupler U64 and the optocoupler U68 are TLP281. For the master-slave status acquisition circuit, one path acquires the master status output of the local module channel of this system, and the other path acquires the master status output of the single-module channel of the pair system.

[0034] For the two-way SPI communication interface circuit, referring to Figure 5 As shown, the SPI communication interface circuit includes a chip U35, and the model of the chip U35 is ADUM7643. The SPI communication interface circuit is mainly used for communication synchronization between the two systems and transmitting the master status between the primary and standby systems to prevent the occurrence of a dual-master status, which may cause a dangerous output to the VIO board. The inter-system communication uses 32-bit CRC verification, and the CPU only uses the correctly parsed communication data to ensure the security of the communication data. The two-way SPI interfaces are in master-slave mode respectively. The communication master module serves as the data sender, and the communication slave module serves as the data receiver.

[0035] Combined with the above structure, a system for judging the master-slave state of dual systems that meets the SIL4 safety level in the present invention. The redundant mode of the dual-system includes two states: the master mode (ACTIVE state) and the standby mode (STANDBY state). The redundant control management is divided into initialization-phase redundant management and periodic-operation-phase redundant management according to different operation stages. The dual-system redundancy adopts defensive programming: all parameters affecting the logic determination of system switching are subjected to legality judgment. When any parameter is illegal, it is considered that the adjustment fails and the software exits. The master-slave state mode returned by this module needs to pass the 2oo2 verification before the subsequent parts can continue to be used.

[0036] Combined Figure 6 As shown, it is a schematic diagram of the redundant state determination process in the initialization phase. The dual-system redundancy adopts a communication-based redundant control method. Independent hardware channels are used between the two systems for redundant information interaction, and the interaction information adopts 32-bit CRC verification. After the redundant control is started, it first waits to receive the redundant control information of the peer CPU of the opposite system. The timeout threshold is 2 seconds. If the redundant information sent by the other party is not received within 2s, the master-slave state of the opposite system is obtained by reading the hardware channel, and the master-slave state mode of this system is set according to the master-slave state of the opposite system. If the status information of the opposite system is not received within 2s timeout, the current master-slave state is determined according to the RTC time, and the redundant state information is interacted with the opposite CPU. If the redundant control information of the opposite system is not received, the current master-slave state is determined through the master-slave information of the hardware channel. If the redundant state information of the opposite system is received, it is determined whether there is a conflict with the state of this system. If there is no conflict, the current master-slave state mode is maintained. If there is a conflict, the current master-slave state is determined according to the A / B system (that is, the master-slave state of the first single-mode channel and the second single-mode channel).

[0037] Combined Figure 7 As shown, it is a schematic diagram of the periodic redundant control process. The periodic redundant management is based on software communication redundancy. According to the communication result returned by the software communication redundancy, the redundant state is determined whether there is a dual-master conflict through the hardware channel, and finally the system redundant mode is obtained.

[0038] The communication-based redundant process is part of the periodic redundant management. The detailed process is as Figure 8 shown. The communication-based dual-system redundant control interacts the current state information through the inter-system communication channel. The dual CPUs synchronously receive the redundant messages of the opposite system. When both CPUs receive the redundant messages of the opposite system, the redundant messages received by Machine A are defaultly adopted. If the information from the opposite end is received, after passing the 2oo2 consistency determination, the channel disconnection count is cleared to 0, and it is determined whether the state of this system is consistent with that of the opposite system, and corresponding processing is carried out. Furthermore, the VIO board has an anti-dual-master design. When the VIO board receives the output data frames of both the A and B systems at the same time, the VIO board does not execute the output instruction, and will immediately direct to the safe side (safe shutdown), and report the fault at the same time.

[0039] In summary, a system for judging the primary and standby states of a dual system that meets the SIL4 safety level according to the present invention can effectively judge the primary and standby states of the dual system, ensure data exchange between the dual systems, and can effectively prevent the occurrence of a dual-primary state.

[0040] The above is a specific description of the preferred embodiment of the present invention, but the present invention is not limited to the described embodiment. Those skilled in the art can make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of this application.

Claims

1. A system for judging the dual-system primary and standby status that meets the safety level of SIL4, characterized in that, It includes a first single-mode channel and a second single-mode channel that are both connected to the backplane and have the same structure; The first single-mode channel includes a first CPU, a second CPU, a first FPGA module, a second FPGA module, and a backplane interface. Data exchange between the first FPGA module and the first CPU and between the second FPGA module and the second CPU is carried out through the external bus EMIF. The GPIO signals between the first FPGA module and the first CPU and between the second FPGA module and the second CPU are used for hardwired synchronization between the first CPU and the second CPU and the output of the current active state; Both the first FPGA module and the second FPGA module are connected to the backplane interface. A master-slave state output circuit and a master-slave state acquisition circuit are provided between the first FPGA module and the backplane interface and between the second FPGA module and the backplane interface; The first single-mode channel and the second single-mode channel are respectively connected to the backplane through their respective backplane interfaces. The first single-mode channel and the second single-mode channel respectively output two groups of SPI signals through the SPI communication interface circuit between them and the backplane interface, and output them to the backplane after isolation for data transmission between the first single-mode channel and the second single-mode channel; Applied to the target single-mode channel, the target single-mode channel is the first single-mode channel or the second single-mode channel; The dual-system redundancy control method adopted by the system that meets the SIL4 safety level for dual-system master-slave state judgment is: Obtain the redundancy control information of the peer CPU of the target single-mode channel in the pair system, and judge whether the acquisition time exceeds the timeout threshold; If the acquisition time does not exceed the timeout threshold, read the hardware channel to obtain the master-slave state of the pair system, and set the master-slave state of the local system of the target single-mode channel according to the master-slave state of the pair system; Otherwise, determine the master-slave state of the local system of the target single-mode channel according to the RTC time, and request to obtain the redundancy control information of the pair system. If the redundancy control information of the pair system is successfully obtained, calibrate the master-slave state of the local system according to the redundancy control information of the pair system. If the redundancy control information of the pair system is obtained unsuccessfully, read the hardware channel to obtain the master-slave state of the pair system, and set the master-slave state of the local system of the target single-mode channel according to the master-slave state of the pair system.

2. A system for judging the dual-system primary and standby status that meets the SIL4 safety level according to claim 1, characterized in that, The first CPU and the second CPU are TI's safety MCU chips, and this chip meets the ISO 26262 ASIL D and IEC 61508 SIL 3 certifications.

3. A system for judging the dual-system primary and standby status that meets the SIL4 safety level according to claim 1, characterized in that, There are a synchronization line and a communication line between the first FPGA module and the second FPGA module, which are used for data synchronization and exchange between the first single-mode channel and the second single-mode channel after isolation.

4. A system for judging the dual-system master-slave status and meeting the SIL4 safety level according to claim 1, characterized in that The master-slave state output circuit between the first FPGA module and the backplane interface includes a field-effect transistor relay RL6. The signal input pin of the field-effect transistor relay RL6 is connected to the first FPGA module, and the output pin of the field-effect transistor relay RL6 is connected to the backplane interface.

5. A system for judging the dual-system primary and standby status that meets the SIL4 safety level according to claim 4, characterized in that The model of the field-effect transistor relay RL6 is G3VM-201G1.

6. A system for judging the dual-system primary and standby status conforming to the SIL4 safety level according to claim 1, characterized in that, The master-slave status acquisition circuit between the first FPGA module and the backplane interface includes an optocoupler U64. The input end of the optocoupler U64 is connected to the backplane interface, and the output end is connected to the first FPGA module; The master-slave status acquisition circuit between the second FPGA module and the backplane interface includes an optocoupler U68. The input end of the optocoupler U68 is connected to the backplane interface, and the output end is connected to the second FPGA module.

7. A system for judging the dual-system master-slave state conforming to the SIL4 safety level according to claim 6, characterized in that, The models of the optocoupler U64 and the optocoupler U68 are TLP281.

8. A system for judging the dual-system primary and standby status conforming to the SIL4 safety level according to claim 1, characterized in that, The SPI communication interface circuit includes a chip U35, and the model of the chip U35 is ADUM7643.

Citation Information

Patent Citations

  • Hot Standby ATO equipment fault detecting and switching system

    CN110843857A