Traction system redundancy control method, device and readable storage medium

By employing a dual central processing unit redundancy control method, the master and slave control units are monitored and switched in real time, which solves the problem of high failure rate of the central processing unit board, improves the stability and reliability of the traction system, reduces the failure rate, and ensures the long-term stable operation of the traction system.

CN115145198BActive Publication Date: 2025-11-11CHINA ACADEMY OF RAILWAY SCI CORP LTD +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210760339.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-11-11
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

In existing technologies, the high failure rate of central processing unit boards leads to traction system failure, affecting the stability and reliability of traction control units and increasing the failure rate of EMU trains.

Method used

A dual-central processing unit redundancy control method is adopted. Through the master-slave redundancy working mode, the status of the first central processing unit is monitored in real time. If a fault occurs, the second central processing unit is switched to become the master control unit, and the first central processing unit is restarted as the backup control unit, thereby improving the redundancy and reliability of the system.

Benefits of technology

It improves the stability of the traction system and the overall reliability of the machine, reduces the failure rate, avoids downtime due to malfunctions, and ensures the long-term stable operation of the traction system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115145198B_ABST
    Figure CN115145198B_ABST
Patent Text Reader

Abstract

This invention discloses a redundancy control method, apparatus, and readable storage medium for a traction system. The traction system has at least a first central processing unit (CPU) and a second CPU that can be controlled. The redundancy control method includes: determining that the first CPU is the primary control unit, and the second CPU is the backup control unit; monitoring the operating status of the first CPU; if the first CPU fails, switching the second CPU to the primary control unit and activating the first CPU as the backup control unit. This invention solves the technical problem that a single CPU board has a high failure rate, which can easily lead to traction system failure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication control, and further relates to a redundancy control method, apparatus, and readable storage medium for a traction system, particularly to a dual-chip control method, apparatus, and readable storage medium for a train traction system control unit. Background Technology

[0002] The traction system is one of the core systems in a high-speed train. As the core controller of the traction system, the traction control unit (TCU, also known as the automatic transmission control unit) plays a crucial role in the overall vehicle operation control. The controlled objects of the traction control unit include the traction transformer, traction converter, and traction motor.

[0003] The traction control unit includes a central processing unit (CPU) board, input / output management (IOM) board, signal processing (DSP) board, communication (MVB) board, analog input / output (IOA) board, digital input board, digital output board, inverter monitoring board, synchronization signal board, temperature acquisition board, output pulse amplifier (OPA), input voltage-to-frequency converter (IVF), power management board, power supply board, power supply board, and fan, etc. Among these, the CPU board interacts with other boards via a bus, performs core control logic calculations and management, and undertakes crucial functions of the entire system. Therefore, the stability and reliability of the CPU board are of paramount importance.

[0004] The existing central processing unit board consists of a control chip based on an x86 chip that interacts with other boards via buses (PCI and ISA). The board has internal memory (such as NVSRAM). When the control chip fails, the entire traction control unit will fail, resulting in a traction converter failure. If this occurs during train operation, it will lead to a partial loss of power, affecting the stability and reliability of the traction control unit and increasing the failure rate of the train.

[0005] There is currently no effective solution to the problem that the single central processing unit board in related technologies has a high failure rate and is prone to causing the traction system to fail.

[0006] Therefore, based on years of experience and practice in related industries, the inventor proposes a traction system redundancy control method, device, and readable storage medium to overcome the shortcomings of the prior art. Summary of the Invention

[0007] The purpose of this invention is to provide a redundancy control method, device, and readable storage medium for a traction system, which has at least two core control units, thereby improving redundancy. During operation, the two control units can operate in a master-slave redundancy mode, improving the reliability and stability of the system and the whole machine, reducing the failure rate, and ensuring the stable operation of the traction system.

[0008] The objective of this invention can be achieved through the following methods:

[0009] This invention provides a redundancy control method for a traction system, wherein the traction system has at least a first central processing unit and a second central processing unit that can be controlled thereon, and the redundancy control method includes:

[0010] If the first central processing unit is determined to be the main control unit, then the second central processing unit is the backup control unit;

[0011] Monitor the working status of the first central processing unit;

[0012] If the first central processing unit fails, the second central processing unit is switched to the main control unit, and the first central processing unit is activated as the backup control unit.

[0013] In a preferred embodiment of the present invention, determining the first central processing unit as the main control unit and the second central processing unit as the backup control unit includes: when the first central processing unit and the second central processing unit are started, if the first central processing unit has entered a standby state in advance, then the first central processing unit is determined to be the main control unit.

[0014] In a preferred embodiment of the present invention, the first central processing unit pre-entering a ready state includes:

[0015] If the first central processing unit reads the identity information before the second central processing unit, then the first central processing unit enters a pre-ready state.

[0016] If the first central processing unit writes address information into the register within a preset time, then the first central processing unit is marked as the main control unit, and the second central processing unit is marked as the backup control unit.

[0017] If the first central processing unit fails to write address information into the register within a preset time, the first central processing unit is reset and restarted, and the second central processing unit is marked as a backup control unit.

[0018] In a preferred embodiment of the present invention, monitoring the operating status of the first central processing unit includes:

[0019] The system provides data to be processed to the first central processing unit and periodically reads the processing results from the first central processing unit.

[0020] If the processing result does not meet the expected result, the first central processing unit is determined to have malfunctioned.

[0021] In a preferred embodiment of the present invention, the step of providing data to be processed to the first central processing unit and periodically reading processing results from the first central processing unit includes:

[0022] Two random data sets to be processed are periodically provided to the first central processing unit;

[0023] After reading the two random data, the first central processing unit performs a bitwise XOR operation on the two random data and writes the processing result into a register.

[0024] Real-time monitoring to determine if the processing results written into the register meet the expected results;

[0025] If the expected result is met, two more random data points to be processed are provided to the first central processing unit, and the next monitoring process is executed.

[0026] In a preferred embodiment of the present invention, if the processing result is not in accordance with the expected result for n consecutive times, the first central processing unit is determined to have malfunctioned; wherein, n≥5.

[0027] In a preferred embodiment of the present invention, the step of switching the second central processing unit to the main control unit and activating the first central processing unit as the backup control unit if the first central processing unit fails includes:

[0028] If the first central processing unit malfunctions, the operating status of the second central processing unit is detected.

[0029] If the second central processing unit is marked as a standby control unit, then the second central processing unit is switched to run as the main control unit;

[0030] Reset the first central processing unit;

[0031] The first central processing unit serves as a backup control unit after it is started.

[0032] In a preferred embodiment of the present invention, if the second central processing unit is not marked as a backup control unit, the system is determined to be faulty, and the traction system is powered off and then powered on again.

[0033] This invention provides a traction system redundancy control device, comprising at least a first central processing unit and a second central processing unit capable of controlling the traction system, and further comprising:

[0034] The primary / standby determination unit is used to determine that the first central processing unit is the primary control unit, and the second central processing unit is the standby control unit.

[0035] The monitoring unit is used to monitor the working status of the first central processing unit;

[0036] The processing unit is configured to, if the first central processing unit fails, switch the second central processing unit to the main control unit and activate the first central processing unit as the backup control unit.

[0037] In a preferred embodiment of the present invention, the primary / backup determination unit includes:

[0038] The information recognition module is used so that if the first central processing unit reads the identity recognition information before the second central processing unit, the first central processing unit enters a preparatory state in advance.

[0039] The first processing module is configured to mark the first central processing unit as the main control unit and the second central processing unit as the backup control unit if the first central processing unit writes address information into the register within a preset time.

[0040] The second processing module is configured to reset and restart the first central processing unit if the first central processing unit fails to write address information into the register within a preset time, and to mark the second central processing unit as a standby control unit.

[0041] In a preferred embodiment of the present invention, the monitoring unit includes:

[0042] The data processing module is used to provide the data to be processed to the first central processing unit and to periodically read the processing results from the first central processing unit.

[0043] The fault determination module is used to determine that the first central processing unit has malfunctioned if the processing result does not meet the expected result.

[0044] In a preferred embodiment of the present invention, the processing unit includes:

[0045] The fault handling module is used to detect the working status of the second central processing unit if the first central processing unit fails.

[0046] The master / standby switching module is used to switch the second central processing unit to run as the master control unit if the second central processing unit is marked as the standby control unit.

[0047] A reset module is used to reset the first central processing unit;

[0048] The restart module is used as a backup control unit after the first central processing unit starts up.

[0049] In a preferred embodiment of the present invention, the first central processing unit and the second central processing unit are integrated on a baseboard via a connector, and the first central processing unit and the second central processing unit are respectively connected to the FPGA chip via a bus.

[0050] In a preferred embodiment of the present invention, the first central processing unit and the second central processing unit each have an independent hard disk and a double-rate synchronous dynamic random access memory.

[0051] In a preferred embodiment of the present invention, the first central processing unit and the second central processing unit are respectively connected to an Ethernet interface via a switch.

[0052] In a preferred embodiment of the present invention, the network ports of the first central processing unit and the second central processing unit are respectively connected to the connectors on the front panel via a switching chip; the switching enable pin of the switching chip is connected to the FPGA chip.

[0053] The present invention provides a computer-readable storage medium storing a computer program that performs the above-described traction system redundancy control method.

[0054] As described above, the characteristics and advantages of the traction system redundancy control method, device, and readable storage medium of the present invention are as follows: the traction system has at least a first central processing unit and a second central processing unit that can be controlled. The first central processing unit can be determined as the main control unit, and the second central processing unit is the backup control unit. During operation, the first and second central processing units can be in a master-slave redundancy working mode, that is, the first central processing unit is in the working state, while the second central processing unit is in the standby state. While working, the working status of the first central processing unit is monitored in real time. If the first central processing unit fails, the second central processing unit, which is in the standby state, is switched to the main control unit, and the first central processing unit is restarted and used as the backup control unit. This improves the redundancy of the system, enhances the reliability and stability of the system and the whole machine, reduces the failure rate, avoids downtime due to failure, and ensures the long-term and stable operation of the traction system. Attached Figure Description

[0055] The accompanying drawings are intended only to illustrate and explain the present invention and do not limit the scope of the invention.

[0056] in:

[0057] Figure 1 This is one of the flowcharts for the redundancy control method of the traction system of the present invention.

[0058] Figure 2 This is the second flowchart of the redundancy control method for the traction system of the present invention.

[0059] Figure 3 This is the third flowchart of the redundancy control method for the traction system of the present invention.

[0060] Figure 4 This is the fourth flowchart of the redundancy control method for the traction system of the present invention.

[0061] Figure 5 This is one of the structural block diagrams of the redundant control device for the traction system of the present invention.

[0062] Figure 6 This is the second structural block diagram of the redundant control device for the traction system of the present invention.

[0063] Figure 7 This is the third structural block diagram of the redundant control device for the traction system of the present invention.

[0064] Figure 8 This is the fourth structural block diagram of the redundant control device for the traction system of the present invention.

[0065] Figure 9 : This is a diagram of the board structure of the redundant control device for the traction system of the present invention.

[0066] Figure 10 : This is a diagram showing the network interface connection structure of the board in the redundant control device of the traction system of the present invention.

[0067] The reference numerals in the accompanying drawings of this invention are:

[0068] 100. Primary / Backup Determination Unit; 1001. Information Identification Module;

[0069] 1002. First processing module; 1003. Second processing module;

[0070] 200. Monitoring Unit; 2001. Data Processing Module;

[0071] 2002. Fault diagnosis module; 300. Processing unit;

[0072] 3001. Fault handling module; 3002. Primary / backup switching module;

[0073] 3003. Reset module; 3004. Restart module. Detailed Implementation

[0074] To provide a clearer understanding of the technical features, objectives, and effects of the present invention, specific embodiments of the present invention will now be described with reference to the accompanying drawings.

[0075] Implementation Method 1

[0076] like Figures 1 to 4 As shown, this invention provides a redundancy control method for a traction system. The traction system has at least a first central processing unit (CPUA) and a second central processing unit (CPUB), both of which can function as a main control unit to control the traction system. The redundancy control method includes:

[0077] Step S1: If the first central processing unit (CPUA) is determined to be the main control unit, then the second central processing unit (CPUB) is the backup control unit.

[0078] In step S1, the determination of the main control unit after power-on is based on whether the first central processing unit (CPUA) or the second central processing unit (CPUB) has pre-completed a specified operation. That is, when starting the first CPUA and the second CPUB, if the first CPUA has pre-entered a standby state, then the first CPUA is determined to be the main control unit. Conversely, if the second CPUB has pre-entered a standby state, then the second CPUB is determined to be the main control unit, and in this case, the first CPUA becomes the standby control unit.

[0079] In an optional embodiment of the present invention, step S1 specifically includes:

[0080] Step S101: Determine which control unit, the first central processing unit CPUA or the second central processing unit CPUB, reads the identification information CPU_ID through the PCI bus first. If the first central processing unit CPUA reads the identification information CPU_ID before the second central processing unit CPUB, then the first central processing unit CPUA enters the preparatory state in advance.

[0081] Step S102: If the first central processing unit CPUA enters the standby state in advance, it must write address information 0x05 to the CSR register PRI_ID in the FPGA chip within a preset time. If the first central processing unit CPUA writes address information 0x05 to the CSR register PRI_ID within the preset time, the FPGA chip marks the first central processing unit CPUA as the main control unit and marks the second central processing unit CPUB as the backup control unit.

[0082] Step S103: If the first central processing unit CPUA does not write address information 0x05 to the CSR register PRI_ID within the preset time, the first central processing unit CPUA is reset and restarted, and the second central processing unit CPUB is marked as a backup control unit.

[0083] Step S2: Monitor the operating status of the first central processing unit (CPUA);

[0084] In an optional embodiment of the present invention, such as Figure 2 As shown, step S2 includes:

[0085] Step S201: Provide the data to be processed to the first central processing unit CPUA, and periodically read the processing results from the first central processing unit CPUA;

[0086] Furthermore, step S201 includes:

[0087] Step S2011: The FPGA chip periodically provides two random data (which can be random numbers) WDG_FPGA_REG1 and WDG_FPGA_REG2 to the first central processing unit CPUA;

[0088] Step S2012: After the first central processing unit (CPU) of the main control unit reads the above two random data, it performs bitwise XOR processing on the two random data WDG_FPGA_REG1 and WDG_FPGA_REG2 and writes the processing result into the CSR register WDG_CPU_ACK.

[0089] Step S2013: After the FPGA chip provides two random data WDG_FPGA_REG1 and WDG_FPGA_REG2 to the first central processing unit CPUA, the value of the CSR register WDG_CPU_ACK is detected in real time to determine whether the written processing result meets the expected result (i.e., whether the value of the CSR register WDG_CPU_ACK has changed to the expected value).

[0090] Step S2014: If the expected result is met (i.e., the value of the CSR register WDG_CPU_ACK has become the expected value), the FPGA chip will provide the first central processing unit CPUA with two more random data to be processed and execute the next monitoring process.

[0091] Step S202: If the processing result does not meet the expected result within the preset time (i.e., the value of the CSR register WDG_CPU_ACK does not change to the expected value), then it is determined that the first central processing unit CPUA has failed.

[0092] In this invention, to improve the accuracy of fault diagnosis, the first central processing unit can be determined to have malfunctioned after n consecutive processing results that do not meet expectations, thereby avoiding misjudgments. Preferably, n ≥ 5.

[0093] Step S3: If the first central processing unit CPUA fails, the second central processing unit CPUB is switched to the main control unit, and the first central processing unit CPUA is started as the backup control unit.

[0094] In an optional embodiment of the present invention, such as Figure 3 As shown, step S3 includes:

[0095] Step S301: If it is determined that the first central processing unit CPUA has failed, the FPGA chip detects the working status of the second central processing unit CPUB.

[0096] Step S302: If the FPGA chip detects that the second central processing unit CPUB is marked as a standby control unit (i.e., the second central processing unit CPUB is in standby state), the FPGA chip immediately switches the second central processing unit CPUB to run as the main control unit.

[0097] Step S303: The FPGA chip restarts and resets the first central processing unit CPUA;

[0098] Step S304: After the first central processing unit CPUA is started, it is put into standby mode and used as a standby control unit.

[0099] In step S302 above, if the second central processing unit CPUB is not marked as a standby control unit, the system is judged to be faulty, the traction system is powered off and then powered on again, and then continues to work.

[0100] The features and advantages of the traction system redundancy control method of the present invention are as follows:

[0101] In this traction system redundancy control method, a first central processing unit (CPUA) and a second central processing unit (CPUB) are set up to control the traction system. The first CPUA and the second CPUB can operate in a master-slave redundancy mode. While operating, the working status of the first CPUA is monitored in real time. If the first CPUA fails, the second CPUB, which is in standby mode, is switched to become the master control unit, and the first CPUA is restarted and used as the standby control unit. This improves the redundancy of the system, enhances the reliability and stability of the system and the whole machine, reduces the failure rate, avoids downtime due to failure, and ensures the long-term and stable operation of the traction system.

[0102] Implementation Method 2

[0103] like Figures 5 to 10 As shown, the present invention provides a traction system redundancy control device, which includes at least a first central processing unit (CPUA) and a second central processing unit (CPUB) capable of controlling the traction system. The traction system redundancy control device further includes:

[0104] The primary / backup determination unit 100 is used to determine that the first central processing unit CPUA is the primary control unit, and the second central processing unit CPUB is the backup control unit.

[0105] In an optional embodiment of the present invention, such as Figure 6 As shown, the primary / backup determination unit 100 includes:

[0106] The information recognition module 1001 is used to enable the first central processing unit (CPUA) to enter a preparatory state if the first CPUA reads the identity recognition information before the second CPUB. Specifically, it determines which control unit, the first CPUA or the second CPUB, reads the identity recognition information CPU_ID through the PCI bus first. If the first CPUA reads the identity recognition information CPU_ID before the second CPUB, the first CPUA enters a preparatory state.

[0107] The first processing module 1002 is configured to mark the first central processing unit (CPUA) as the main control unit and the second central processing unit (CPUB) as the backup control unit if the first CPUA writes address information into the register within a preset time. Specifically, if the first CPUA enters a pre-emptive state, it must write address information 0x05 into the CSR register PRI_ID within the FPGA chip within a preset time. If the first CPUA writes address information 0x05 into the CSR register PRI_ID within the preset time, the FPGA chip marks the first CPUA as the main control unit and the second CPUB as the backup control unit.

[0108] The second processing module 1003 is configured to reset and restart the first central processing unit (CPUA) if it fails to write address information into the register within a preset time, and to designate the second central processing unit (CPUB) as a backup control unit. Specifically, if the first CPUA fails to write address information 0x05 into the CSR register PRI_ID within the preset time, the first CPUA will reset and restart, and the second CPUB will be designated as a backup control unit.

[0109] Monitoring unit 200 is used to monitor the working status of the first central processing unit CPUA;

[0110] In an optional embodiment of the present invention, such as Figure 7 As shown, the monitoring unit 200 includes:

[0111] The data processing module 2001 is used to provide data to be processed to the first central processing unit (CPUA) and periodically read the processing results from the first CPUA. Specifically, the FPGA chip periodically provides two random data sets (which can be random numbers) WDG_FPGA_REG1 and WDG_FPGA_REG2 to the first CPUA. After reading the two random data sets, the first CPUA, acting as the main control unit, performs a bitwise XOR operation on the two random data sets WDG_FPGA_REG1 and WDG_FPGA_REG2 and writes the processing result to the CSR register WDG_C. PU_ACK; After the FPGA chip provides two random data WDG_FPGA_REG1 and WDG_FPGA_REG2 to the first central processing unit CPUA, it monitors the value of the CSR register WDG_CPU_ACK in real time to determine whether the written processing result meets the expected result (i.e., whether the value of the CSR register WDG_CPU_ACK has changed to the expected value); if it meets the expected result (i.e., the value of the CSR register WDG_CPU_ACK has changed to the expected value), the FPGA chip provides two more random data to be processed to the first central processing unit CPUA and executes the next monitoring process.

[0112] The fault diagnosis module 2002 is used to determine that the first central processing unit (CPUA) has failed if the processing result does not meet the expected result. Specifically, if the processing result does not meet the expected result within a preset time (i.e., the value of the CSR register WDG_CPU_ACK does not change to the expected value), the first central processing unit (CPUA) is determined to have failed.

[0113] The processing unit 300 is used to switch the second central processing unit CPUB as the main control unit and start the first central processing unit CPUA as the backup control unit if the first central processing unit CPUA fails.

[0114] In an optional embodiment of the present invention, such as Figure 8 As shown, the processing unit 300 includes:

[0115] The fault handling module 3001 is used to detect the working status of the second central processing unit CPUB if the first central processing unit CPUA fails.

[0116] The master / standby switching module 3002 is used to switch the second central processing unit CPUB to run as the master control unit if the second central processing unit CPUB is marked as the standby control unit.

[0117] Specifically, if the FPGA chip detects that the second central processing unit (CPUB) is marked as a standby control unit (i.e., the second central processing unit (CPUB) is in standby mode), the FPGA chip immediately switches the second central processing unit (CPUB) to run as the main control unit; if the second central processing unit (CPUB) is not marked as a standby control unit, the system is judged to be faulty, the system is powered off and then powered on again, and then continues to work.

[0118] The reset module 3003 is used by the FPGA chip to restart and reset the first central processing unit CPUA.

[0119] Restart module 3004 is used as a backup control unit after the first central processing unit CPUA starts up.

[0120] In an optional embodiment of the present invention, such as Figure 9 As shown, the first central processing unit (CPUA) and the second central processing unit (CPUB) are integrated on a baseboard via a COME connector. The baseboard is equipped with a 5V power supply and a power supply adapter. CPUA is connected to the FPGA chip via the Southbridge ICH8M and the PCIA bus, and CPUB is connected to the FPGA chip via the Southbridge ICH8M and the PCIB bus. The FPGA chip implements redundancy switching logic control using Verilog language, that is, it detects the status of CPUA and CPUB respectively based on the FPGA chip (a watchdog timer can be used to detect the status of CPUA and CPUB respectively; the main function of the watchdog timer is a timer, if the program...). If a specified statement or data cannot be processed within a certain time, the watchdog will reset the system to prevent an infinite loop. Based on the detection results, the watchdog determines the selection of the main control unit between the first central processing unit (CPUA) and the second central processing unit (CPUB). The FPGA chip converts the main control unit's PCI bus to an ISA bus and connects two memories (NVRAMA and NVRAMB) and a backplane. At the same time, it implements a non-transparent bridging mapping between the main control unit and other boards (i.e., the resources and addresses contained in the main control unit are not visible to the main system of the main control unit, allowing the local processors of other boards to independently configure and control the subsystem of the main control unit, the clock and address of the main control unit are completely independent from those of the other boards, and address translation can be performed between the main control unit and the other boards).

[0121] Furthermore, such as Figure 9As shown, the first central processing unit CPUA and the second central processing unit CPUB each have independent hard disks and double-rate synchronous dynamic random access memory (DDR). The first central processing unit CPUA and the second central processing unit CPUB are respectively connected to the Ethernet interface through a switch, and the network card chip is connected to the front panel.

[0122] Furthermore, such as Figure 9 As shown, the first central processing unit CPUA and the second central processing unit CPUB are respectively connected to the VGA interface or USB interface through the corresponding southbridge ICH8M.

[0123] In an optional embodiment of the present invention, the first central processing unit CPUA and the second central processing unit CPUB can be implemented using an Intel x86 architecture processor, with the CPU model being N455SLBX9BAG559, a main frequency of 1.66GHz, and DDR3 64-bit 2G memory; the hard drive uses a SATA interface with a capacity of 8G, and the network card chip can be implemented using Intel's WG82574L.

[0124] In an optional embodiment of the present invention, such as Figure 10 As shown, both the first central processing unit (CPUA) and the second central processing unit (CPUB) (i.e., the main control unit and the backup control unit) can be accessed via network ports. Each of the main and backup control units is connected to one 100Mbps network. The networks of both CPUA and CPUB are connected to a connector M12 on the front panel via a switching chip MUX. Additionally, the PCIe buses of the main and backup control units are each extended with one 100Mbps network via a gigabit network card 82574, which is also connected to another connector M12 on the front panel via the switching chip MUX. The switching enable pin SW of the switching chip MUX is connected to the FPGA chip. When the switching enable pin SW of the switching chip MUX is high, the FPGA chip enables the network of the main control unit, and the main control unit is in normal operation while the backup control unit is in standby mode. When the switching enable pin SW of the switching chip MUX is low, the FPGA chip enables the network of the backup control unit, switching the original backup control unit to the main control unit and the original main control unit to the backup control unit, which then enters standby mode after a reset.

[0125] Implementation Method 3

[0126] The present invention provides a computer-readable storage medium storing a computer program that performs the above-described traction system redundancy control method.

[0127] Specifically, computer-readable storage media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer-readable storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable storage media does not include transient media, such as modulated data signals and carrier waves.

[0128] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0129] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0130] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0131] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0132] The above description is merely an illustrative embodiment of the present invention and is not intended to limit the scope of the invention. Any equivalent changes and modifications made by those skilled in the art without departing from the concept and principles of the present invention should fall within the scope of protection of the present invention.

Claims

1. A redundancy control method for a traction system, characterized in that, The traction system has at least a first central processing unit and a second central processing unit that can be controlled thereon, and the redundancy control method includes: If the first central processing unit is determined to be the main control unit, then the second central processing unit is the backup control unit; Monitor the working status of the first central processing unit; The monitoring of the working status of the first central processing unit includes: Two random data sets to be processed are periodically provided to the first central processing unit; After reading the two random data, the first central processing unit performs a bitwise XOR operation on the two random data and writes the processing result into a register. Real-time monitoring to determine if the processing results written into the register meet the expected results; If the expected result is met, then two more random data to be processed are provided to the first central processing unit, and the next monitoring process is executed. If the processing results obtained n times consecutively do not meet the expected results, it is determined that the first central processing unit has failed; if the first central processing unit fails, the second central processing unit is switched to the main control unit, and the first central processing unit is activated as the backup control unit.

2. The traction system redundancy control method as described in claim 1, characterized in that, The step of determining the first central processing unit as the main control unit and the second central processing unit as the backup control unit includes: when the first central processing unit and the second central processing unit are started, if the first central processing unit has entered a standby state in advance, then the first central processing unit is determined to be the main control unit.

3. The traction system redundancy control method as described in claim 2, characterized in that, The first central processing unit enters the pre-ready state, including: If the first central processing unit reads the identity information before the second central processing unit, then the first central processing unit enters a pre-ready state. If the first central processing unit writes address information into the register within a preset time, then the first central processing unit is marked as the main control unit, and the second central processing unit is marked as the backup control unit. If the first central processing unit fails to write address information into the register within a preset time, the first central processing unit is reset and restarted, and the second central processing unit is marked as a backup control unit.

4. The traction system redundancy control method as described in claim 1, characterized in that, If the first central processing unit fails, switching the second central processing unit to the main control unit and activating the first central processing unit as the backup control unit includes: If the first central processing unit malfunctions, the operating status of the second central processing unit is detected. If the second central processing unit is marked as a standby control unit, then the second central processing unit is switched to run as the main control unit; Reset the first central processing unit; The first central processing unit serves as a backup control unit after it is started.

5. The traction system redundancy control method as described in claim 4, characterized in that, If the second central processing unit is not marked as a backup control unit, a system error is determined, and the traction system is powered off and then powered on again.

6. A traction system redundancy control device, used to implement the traction system redundancy control method according to any one of claims 1 to 5, characterized in that, The traction system redundancy control device includes at least a first central processing unit and a second central processing unit capable of controlling the traction system, and further includes: The primary / standby determination unit is used to determine that the first central processing unit is the primary control unit, and the second central processing unit is the standby control unit. The monitoring unit is used to monitor the working status of the first central processing unit; The processing unit is configured to, if the first central processing unit fails, switch the second central processing unit to the main control unit and activate the first central processing unit as the backup control unit.

7. The traction system redundancy control device as described in claim 6, characterized in that, The primary / standby determination unit includes: The information recognition module is used so that if the first central processing unit reads the identity recognition information before the second central processing unit, the first central processing unit enters a preparatory state in advance. The first processing module is configured to mark the first central processing unit as the main control unit and the second central processing unit as the backup control unit if the first central processing unit writes address information into the register within a preset time. The second processing module is configured to reset and restart the first central processing unit if the first central processing unit fails to write address information into the register within a preset time, and to mark the second central processing unit as a standby control unit.

8. The traction system redundancy control device as described in claim 6, characterized in that, The monitoring unit includes: The data processing module is used to provide the data to be processed to the first central processing unit and to periodically read the processing results from the first central processing unit. The fault determination module is used to determine that the first central processing unit has malfunctioned if the processing result does not meet the expected result.

9. The traction system redundancy control device as described in claim 6, characterized in that, The processing unit includes: The fault handling module is used to detect the working status of the second central processing unit if the first central processing unit fails. The master / standby switching module is used to switch the second central processing unit as the master control unit if the second central processing unit is marked as the standby control unit. A reset module is used to reset the first central processing unit; The restart module is used as a backup control unit after the first central processing unit starts up.

10. The traction system redundancy control device as described in claim 6, characterized in that, The first central processing unit and the second central processing unit are integrated on a baseboard via connectors, and the first central processing unit and the second central processing unit are respectively mounted on the FPGA chip via a bus.

11. The traction system redundancy control device as described in claim 6, characterized in that, The first central processing unit and the second central processing unit each have an independent hard disk and a double-rate synchronous dynamic random access memory.

12. The traction system redundancy control device as described in claim 6, characterized in that, The first central processing unit and the second central processing unit are respectively connected to an Ethernet interface via a switch.

13. The traction system redundancy control device as described in claim 6, characterized in that, The network ports of the first central processing unit and the second central processing unit are respectively connected to the connectors on the front panel through a switching chip; the switching enable pin of the switching chip is connected to the FPGA chip.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that performs the traction system redundancy control method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Redundancy control equipment of digital instrument control system, digital instrument control system and control method

    CN105974879A