Method for synchronizing a secure computer system and corresponding system, device

By outputting the business data of the previous period in the current period and the business data of the current period in the next period in the secure computer system, the problem of low efficiency caused by waiting for data synchronization between the two systems is solved, and bumpless switching and efficient operation are achieved.

CN115687509BActive Publication Date: 2026-01-06BYD CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110865117.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-29
Publication Date
2026-01-06
Estimated Expiration
2041-07-29

AI Technical Summary

Technical Problem

In secure computer systems, data cannot be output until the two systems have completed data synchronization, resulting in low system efficiency.

Method used

At the beginning of the current cycle, the business data obtained in the previous cycle is output. After the output is completed, the input data of the current cycle is collected and the collected input data is processed to obtain the business data of the current cycle. However, the business data of the current cycle is not output in the current cycle, but waits until the start of the next cycle to be output.

Benefits of technology

Data can be output without waiting for data synchronization to complete, which improves system operating efficiency and ensures that both systems output to the outside world at the same time within the same cycle, achieving seamless switching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115687509B_ABST
    Figure CN115687509B_ABST
Patent Text Reader

Abstract

This disclosure relates to a synchronization method and corresponding system and apparatus for a secure computer system. The method includes: after the start of the current cycle, determining the primary / backup status of the current system in the current cycle; if the current system was the primary system in both the current and previous cycles, obtaining the output data of the current system based on the business data obtained by the current system in the previous cycle; if the current system was the backup system in both the current and previous cycles, retrieving the synchronization data sent by the neighboring system in the previous cycle from the data buffer to obtain the output data of the current system; outputting the output data to the backend device; acquiring the input data of the current cycle and performing business processing to obtain the business data of the current cycle; if the current system is the primary system in the current cycle, sending the business data of the current cycle as synchronization data to the neighboring system. In this technical solution, outputting the business data of the previous cycle at the beginning of the current cycle can effectively save the time spent waiting for data synchronization to complete and improve system operating efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and more specifically, to a synchronization method and corresponding system and apparatus for a secure computer system. Background Technology

[0002] The two-out-of-two secure computer system consists of two functionally identical subsystems. The two subsystems collect the same node / device data and perform corresponding business processing based on the collected data. The two subsystems compare the processing results by taking two out of two to detect subsystem failures in a timely manner and switch to the other system, thereby achieving dual-system hot standby redundancy. The processing flow of the secure computer system in one cycle includes: (1) Both systems acquire the input data of the current cycle; (2) Both systems perform business processing on the input data to obtain the business data of the current cycle; (3) The primary system synchronizes the business data of the current cycle to the backup system, and the backup system responds to the synchronization operation of the primary system after receiving the synchronized business data from the primary system; (4) Both systems output data respectively.

[0003] To achieve seamless switching under dual-system hot standby redundancy, according to the above process, the two systems need to wait for data synchronization to be completed before outputting data. Since data synchronization between the two systems takes a certain amount of time, it reduces the system's operating efficiency. Summary of the Invention

[0004] The purpose of this disclosure is to provide a synchronization method and corresponding system and apparatus for a secure computer system, in order to solve the problem of low system operating efficiency caused by the need for data synchronization between two systems in a secure computer system before data can be output.

[0005] To achieve the above objectives, in a first aspect, embodiments of this application provide a synchronization method for a secure computer system, the secure computer system comprising a first system and a second system that execute the method and are adjacent to each other; the method includes:

[0006] After the start of the current cycle, determine the status of the primary and backup systems in the current cycle;

[0007] If this system is the primary system in both the current period and the previous period, then the output data of this system is obtained based on the business data obtained after the system performs business processing in the previous period; if this system is the backup system in both the current period and the previous period, then the synchronization data sent by the neighboring system in the previous period is retrieved from the data buffer, and the output data of this system is obtained based on the synchronization data.

[0008] The output data is output to the backend device;

[0009] Obtain the input data for the current period and perform business processing based on the input data to obtain the business data for the current period;

[0010] If this system is the master system in the current period, then the business data of the current period will be sent to the neighboring system as synchronization data.

[0011] Optionally, the method further includes:

[0012] If this system is the primary system in the current period and the backup system in the previous period, then the synchronization data sent by the neighboring system in the previous period in the data buffer is discarded, and the output data of this system is obtained based on the business data obtained after the business processing of this system in the previous period; if this system is the backup system in the current period and the primary system in the previous period, then this system is set not to output data to the backend device in the current period.

[0013] Optionally, determining the primary / backup system status of the system in the current cycle includes:

[0014] Obtain the tangent determination result of this system in the previous period;

[0015] Obtain the status of the associated relays in this system; wherein the associated relays in this system are interlocked with the associated relays in neighboring systems, and the status includes being pulled up or released;

[0016] If the system switching determination result indicates that the system needs to be switched to the main system in the current cycle and the state of the associated relay is activated, then the system is determined to be the main system in the current cycle; if the system switching determination result indicates that the system needs to be switched to the backup system in the current cycle and the state of the associated relay is deactivated, then the system is determined to be the backup system in the current cycle.

[0017] Optionally, the method further includes:

[0018] After obtaining the business data for the current period, the cut-off suggestion scores of the current system and neighboring systems are obtained, and the cut-off judgment result of the current system is obtained by comparing the cut-off suggestion scores of the current system and neighboring systems.

[0019] If the system switching judgment result indicates that the system needs to switch to the main system in the next cycle, then the associated relay of the system is activated; if the system switching judgment result indicates that the system needs to switch to the standby system in the next cycle, then the associated relay of the system is deactivated.

[0020] Optionally, the method further includes: synchronizing the clock with a neighboring system at a preset time point before the end of the current cycle.

[0021] Optionally, if the current system is the primary system in the current period, then the current system is configured to encapsulate the current period's business data into at least one data packet after obtaining the business data of the current period through business processing, and send the at least one data packet to the neighboring system. The current system is also configured to perform subsequent steps if the neighboring system does not respond to the at least one data packet.

[0022] If the current system is a backup system in the current period, the current system is configured to receive data packets sent by neighboring systems through a data buffer, and the current system is configured to perform subsequent steps after obtaining the service data of the current period through service processing, if no data packets sent by neighboring systems are received.

[0023] Optionally, the method further includes:

[0024] After synchronizing the clock with a neighboring system, if the current system is the master system in the current period, then obtain the list of data packets sent by the neighboring system. The list of data packets represents all data packets received by the neighboring system. Based on the list of data packets, determine whether the number of data packets received by the neighboring system is the same as the number of data packets sent by the current system to the neighboring system. If they are different, retransmit the data packets that are not in the list of data packets.

[0025] If the current system is a backup system in the current period, a list of data packets is sent to neighboring systems.

[0026] Optionally, retrieving synchronization data from neighboring systems in the previous period from the data buffer and obtaining the output data of the current system based on the synchronization data includes:

[0027] Retrieve all data packets sent by neighboring systems in the previous period from the data buffer;

[0028] Verify the integrity of each data packet;

[0029] If all data packets are complete, then the output data of this system is composed of all the data packets.

[0030] Optionally, the method further includes:

[0031] Before synchronizing with neighboring systems, a self-test of the operating environment is performed, which includes at least one of a processor, memory, and a watchdog timer.

[0032] Secondly, embodiments of this application provide a secure computer system, the secure computer system comprising a first system and a second system that are adjacent to each other, both the first system and the second system being used to perform the method as described in the first aspect.

[0033] Thirdly, embodiments of this application provide a computing device, including:

[0034] processor;

[0035] Memory used to store processor-executable instructions;

[0036] The processor is configured to execute the method as described in the first aspect when the instructions are executed.

[0037] Fourthly, embodiments of this application provide a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, implement the method described in the first aspect.

[0038] In the technical solution provided in this application, business data obtained from the previous cycle is output at the beginning of the current cycle. After the output is completed, input data for the current cycle is collected and processed to obtain business data for the current cycle. However, the business data for the current cycle is not output within the current cycle but waits until the start of the next cycle before being output. Therefore, the two systems can output data without waiting for data synchronization to complete, which saves the time spent waiting for data synchronization to complete, improves system operating efficiency, and ensures that under any circumstances, the two systems will output externally at the same time within the same cycle. The output is no longer constrained by the data synchronization process, achieving a seamless switching effect between the two systems.

[0039] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0040] The accompanying drawings are provided to further illustrate the present disclosure and form part of the specification. They are used together with the following detailed description to explain the present disclosure, but do not constitute a limitation thereof. In the drawings:

[0041] Figure 1 A flowchart illustrating the synchronization method of the secure computer system provided in an embodiment of this application is shown;

[0042] Figure 2 Another flowchart of the synchronization method for a secure computer system provided in an embodiment of this application is shown;

[0043] Figure 3 Another flowchart of the synchronization method for a secure computer system provided in an embodiment of this application is shown;

[0044] Figure 4 It shows Figure 2 The detailed flowchart of step S110;

[0045] Figure 5 It shows Figure 2 The detailed flowchart of step S120;

[0046] Figure 6 A schematic flowchart of a synchronization method for a secure computer system provided in an embodiment of this application is shown;

[0047] Figure 7 A schematic diagram of a computing device provided in an embodiment of this application is shown. Detailed Implementation

[0048] The specific embodiments of this disclosure will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit this disclosure.

[0049] In view of the problem of low system operating efficiency in the existing technology, the present application provides a synchronization method for a secure computer system. Figure 1 This is a simplified flowchart of the synchronization method provided according to the embodiments of this application, such as... Figure 1 As shown, the synchronization method includes:

[0050] Step 1: After the current cycle begins, perform output processing;

[0051] Step two: Input processing;

[0052] Step 3: Perform data synchronization.

[0053] In the above process, the business data obtained from the previous cycle is output at the beginning of the current cycle. After the output is completed, the input data of the current cycle is collected and processed to obtain the business data of the current cycle. However, the business data of the current cycle is not output within the current cycle, but waits until the start of the next cycle before being output. Therefore, the two systems can output data without waiting for data synchronization to complete, saving the time spent waiting for data synchronization and improving system operating efficiency.

[0054] Specifically, this application provides a specific embodiment of the synchronization method for the aforementioned secure computer system. The secure computer system includes a first system and a second system, which are adjacent to each other and have identical hardware configurations. The first and second systems are used to collect the same node / device data and perform corresponding business processing based on the collected data. The first and second systems are mutually hot-standby redundant; when the first system is the master system, the second system is the backup system, and when the first system is the backup system, the second system is the master system.

[0055] Both the first system and the second system implement the synchronization method provided in this embodiment. Therefore, the synchronization method provided in this embodiment will be described from the perspective of either the first system or the second system below. Figure 2 A flowchart of the synchronization method is shown below. Please refer to it. Figure 2 The synchronization method includes:

[0056] Step S110: After the start of the current cycle, determine the status of the primary and backup systems in the current cycle.

[0057] After the current cycle begins, the status of associated relays in this system is collected, including whether they are activated or deactivated. The associated relays in this system are interlocked with those in adjacent systems. When an associated relay in this system is activated, the associated relay in the adjacent system is deactivated; conversely, when an associated relay in this system is deactivated, the associated relay in the adjacent system is activated. This interlocking ensures that only one system (either the first or second system) can activate a relay at a time, achieving a single master system and preventing conflicts caused by two systems simultaneously activating.

[0058] After collecting the status of the associated relays in this system, the current status of the main or backup system in this system during the current cycle is determined based on the current status of the associated relays, such as whether this system is the main system or the backup system during the current cycle.

[0059] Step S120: Determine the output data of this system based on the status of the primary and backup systems in the current cycle and the previous cycle.

[0060] The status of the primary and backup systems in the current cycle and the previous cycle can be as follows:

[0061] 1) This system is the principal system in both the current period and the previous period, and correspondingly, the neighboring system is the backup system in both the current period and the previous period.

[0062] 2) If the current system is a backup system in the current period and the previous period, then the neighboring system is the principal system in the current period and the previous period.

[0063] 3) If the current system is the principal system in the current cycle and the secondary system in the previous cycle, then the adjacent system is the secondary system in the current cycle and the principal system in the previous cycle.

[0064] 4) If a system is a backup system in the current cycle and a main system in the previous cycle, then the adjacent system is a main system in the current cycle and a backup system in the previous cycle.

[0065] If a system is the primary system in both the current and previous periods, its output data is obtained based on the business data it received after processing business data in the previous period. If a system is the backup system in both periods, it retrieves the synchronization data sent by the neighboring system in the previous period from the data buffer, and obtains its output data based on this synchronization data, which is the business data received by the neighboring system after processing business data in the previous period. In other words, if the primary / backup system status in the current period remains unchanged compared to the previous period, the primary system outputs based on the synchronization data it received after processing business data in the previous period, and the backup system outputs based on the synchronization data synchronized from the primary system in the previous period.

[0066] If a system is the primary system in the current cycle and the backup system in the previous cycle, then the synchronization data sent by neighboring systems in the previous cycle is discarded from the data buffer. The system's output data is then derived from the business data obtained after processing business data in the previous cycle. In other words, if a system has just been promoted from backup to primary system in the current cycle, it indicates that its own state is better than that of its neighboring systems. Therefore, it does not use the synchronization data sent by neighboring systems in the previous cycle, but instead outputs data based on its own business data obtained after processing business data in the previous cycle.

[0067] If this system is a backup system in the current cycle and a primary system in the previous cycle, then this system is set not to output data to the backend device in the current cycle. That is, when this system is downgraded from a primary to a backup system in the current cycle, it indicates an anomaly in its status. Since this system was a primary system in the previous cycle and the neighboring system was a backup system, the neighboring system did not synchronize data to this system in the previous cycle. Therefore, this system's data buffer does not contain the synchronized data from the neighboring system in the previous cycle. After entering the current cycle, to prevent conflict with the neighboring system's output, this system will be forcibly set not to output in the current cycle. Normal output will occur in the next cycle after the neighboring system synchronizes the business data for the current cycle, thus ensuring that the output between the two systems is not disordered.

[0068] Step S130: Output the output data to the backend device.

[0069] Backend equipment includes, but is not limited to, signals, turnouts, and trackside equipment. In one embodiment, if the backend equipment is a turnout, the output data may be a turnout activation command or a turnout locking command.

[0070] Step S140: Obtain the input data for the current period and perform business processing based on the input data to obtain the business data for the current period.

[0071] After completing the output, the input data for the current period is obtained. This input data includes, but is not limited to, surrounding sensor data or line data. After obtaining the input data for the current period, the input data can first undergo service preprocessing (such as unpacking, jitter elimination, etc.), and then the preprocessed data is processed according to the field backend and preset processing logic to obtain the service data for the current period.

[0072] It is understandable that the first and second systems collect the same input node / device data (if there is a fault such as a disconnection between a system and one or more sensing devices, the input data collected by the first and second systems may be inconsistent), and perform corresponding business processing on the collected input data (if the input data collected by the first and second systems is inconsistent, there may be slight differences in the processing tasks between the two systems), and both obtain the business data for the current period.

[0073] Step S150: Perform data synchronization with neighboring systems to send the primary system's business data for the current period as synchronization data to the backup system.

[0074] In step S150, the data synchronization operation with the neighboring system includes: if the current system is the master system in the current period, the current system sends the current period's business data obtained in step S140 as synchronization data to the backup system; if the current system is the backup system in the current period, the current system receives the synchronization data sent by the neighboring system, that is, the current period's business data obtained by the neighboring system through step S140, and stores it in the data buffer.

[0075] The synchronization method for a secure computer system provided in this application embodiment can keep the output of the backup system consistent with the primary system through synchronization between the primary system and the backup system. When the primary system fails, the backup system can immediately switch to the primary system and retain the normal working state before the primary system crashes, so that the output to the backend equipment is seamless and achieves a smooth switching.

[0076] Optional, please refer to Figure 3 The method also includes:

[0077] Step S210: After obtaining the business data for the current period, obtain the cutting suggestion scores of the current system and neighboring systems, and obtain the cutting judgment result of the current system by comparing the cutting suggestion scores of the current system and neighboring systems.

[0078] After each business process is completed and the business data for the current period is obtained, both the primary and backup systems provide a switching recommendation score based on factors such as their processing speed, connected nodes / devices, and communication status, to determine whether a primary / backup system switchover should be initiated. When calculating the switching recommendation score, different weights can be assigned to each factor based on the current application context of the system, and the switching recommendation score is obtained by weighting multiple factors. For example, if communication status is more important in the current application context, then the communication status factor is given a higher weight; similarly, if the number of external nodes / devices is more important in the current application context, then the connected node / device factor is given a higher weight.

[0079] After receiving their cut-off scores, both departments send their cut-off scores to their respective neighboring departments. This allows the primary department to receive its own cut-off scores along with those of its backup department, and vice versa. Each department then compares its own cut-off scores with those of its neighboring departments to determine its cut-off decision. This decision indicates whether the department will not cut off its lineage in the next cycle, or whether it will cut off to the primary or backup department. After comparison, the following scenarios can be identified:

[0080] A. If the cut-line suggestion score of this system is higher than that of the neighboring system, it indicates that the state of this system is better than that of the neighboring system. Therefore, the cut-line judgment result of this system is that this system will be cut as the main system in the next cycle.

[0081] B. If the cut-off score of this system is lower than that of the neighboring system, it indicates that the state of this system is worse than that of the neighboring system. Therefore, the cut-off judgment result of this system is that this system should be cut off as a backup system in the next cycle.

[0082] C. If the cut-off score of the current system is equal to that of the neighboring system, it indicates that the current system is in the same state as the neighboring system. The cut-off judgment result of the current system is to maintain the original state, that is, not to cut off the system.

[0083] Since the system and its neighboring system are determined based on the same two cut-system suggestion scores, their cut-system decision results are opposite. For example, if the cut-system suggestion score of the first system is higher than that of the second system, then the cut-system decision for the first system is that it will be designated as the primary system in the next cycle, while the cut-system decision for the second system will necessarily be that it will be designated as the backup system in the next cycle. It should be noted that this cut-system decision only affects the primary / backup system status in the next cycle, but does not affect the primary / backup system status in the current cycle.

[0084] Step S220: Control the associated relays of this system according to the system judgment result.

[0085] Specifically, if the system switching judgment result indicates that the system will not switch in the next cycle, the existing state of the associated relays of the system is maintained; if the system switching judgment result indicates that the system needs to switch to the main system in the next cycle, the associated relays of the system are controlled to be activated. At this time, the system switching judgment result obtained by the neighboring system indicates that the neighboring system needs to switch to the standby system in the next cycle, and the neighboring system controls its associated relays to be deactivated; if the system switching judgment result indicates that the system needs to switch to the standby system in the next cycle, the associated relays of the system are controlled to be deactivated. At this time, the system switching judgment result obtained by the neighboring system indicates that the neighboring system needs to switch to the main system in the next cycle, and the neighboring system controls its associated relays to be activated.

[0086] Similarly, in the previous cycle, this system also obtains a system disconnection judgment result, which indicates that it is expected that this system will not disconnect in the next cycle (i.e., the current cycle), or will disconnect to the main system or the backup system, and the associated relays will be controlled according to the system disconnection judgment result.

[0087] Please refer to Figure 4 In step S110, the step of determining the primary and backup system status of the system in the current cycle includes:

[0088] Step S111: Obtain the tangent system judgment result of this system in the previous period.

[0089] Step S112: Obtain the status of the associated relays in this system.

[0090] Step S113: If the system switching judgment result indicates that the system needs to be switched to the main system in the current cycle and the state of the associated relay is activated, then the system is determined to be the main system in the current cycle.

[0091] Step S114: If the system switching judgment result indicates that the system needs to be switched to the backup system in the current cycle and the state of the associated relay is down, then the system is determined to be the backup system in the current cycle.

[0092] If the previous cycle's system switching determination result indicates that this system needs to switch to the main system in the current cycle (i.e., the cycle following the previous cycle), and the acquired associated relay status is active, it indicates that the system switching is successful, and this system can be determined to be the main system in the current cycle. If the system switching determination result indicates that this system needs to switch to the main system in the current cycle, but the acquired associated relay status is deactivated, it indicates that the system switching is abnormal.

[0093] If the previous cycle's system switching determination result indicates that this system needs to be switched to standby in the current cycle, and the acquired status of the associated relay is down, it indicates that the system switching was successful, and this system can be determined to be standby in the current cycle. If the system switching determination result indicates that this system needs to be standby in the current cycle, but the acquired status of the associated relay is up, it indicates that the system switching has encountered an anomaly.

[0094] In the event of any abnormality in the above-mentioned cutting system, the pre-set abnormality handling procedure can be followed.

[0095] If the system switching judgment result of the previous cycle is that the system will not switch in the current cycle, then the associated relay was not operated in step S220 of the previous cycle. Therefore, the main and backup system status can be determined according to the current status of the associated relay. If the status of the associated relay is energized, the system is determined to be the main system in the current cycle. If the status of the associated relay is de-energized, the system is determined to be the backup system in the current cycle.

[0096] By using the above methods, we can determine whether the system switching operation was successful, thereby ensuring that the system switching is normal, usable, and safe.

[0097] Optionally, after performing the data synchronization operation with the neighboring system in step S150, the local system synchronizes its clock with the neighboring system at a preset time point before the end of the current cycle. The method may further include: performing a self-test of the operating environment before synchronizing the clock with the neighboring system, the operating environment including at least one of a processor, memory, and a watchdog timer.

[0098] It is important to note that if this system is the primary system in the current cycle, it needs to send the current cycle's business data as synchronization data to neighboring systems. Therefore, this system is configured to, after obtaining the current cycle's business data through business processing, encapsulate the current cycle's business data into at least one data packet and send this at least one data packet to the neighboring system. Furthermore, this system is configured to execute subsequent steps if the neighboring system does not respond to this at least one data packet. If this system is the backup system in the current cycle, it is configured to receive data packets sent by the neighboring system through a data buffer. This system is also configured to, after obtaining the current cycle's business data through business processing, execute subsequent steps if it does not receive a data packet from the neighboring system.

[0099] For example, assuming that in the current cycle, the first system is the primary system and the second system is the backup system, and the first and second systems synchronize data via Ethernet. After obtaining the service data for the current cycle through service processing, the first system encapsulates the obtained service data into at least one data packet. For example, if the service data for the current cycle is 20KB in size, this 20KB data is framed using Ethernet and encapsulated into multiple Ethernet data packets. Then, the first system sends this at least one data packet to the second system via Ethernet, and can perform subsequent steps, such as performing a self-check of the operating environment, without waiting for a response from the second system.

[0100] After obtaining the business data for the current period, the second system can execute subsequent steps without waiting for data packets from the first system. For example, it can perform a self-check even if it hasn't received data packets from the first system. The second system receives data packets from the first system through a data buffer. When the second system receives a data packet from the first system, it stores it in the data buffer and does not need to respond to the first system temporarily.

[0101] In the data synchronization process of related technologies, the data synchronization link is an interactive handshake process. In this interactive handshake process, the data sender sends a data packet to the data receiver, and the data receiver will respond immediately. When a data packet transmission error occurs, the data sender immediately retransmits the data packet. After the retransmission is successful, the data sender sends the next data packet to be sent. This packet-by-packet confirmation synchronization method will cause synchronization interaction time between the two systems, resulting in a longer data synchronization time.

[0102] In the data synchronization process described above in this embodiment, the primary system, as the data sender, is only responsible for sending data, and the backup system, as the data receiver, is only responsible for receiving data. The two systems do not consider responding to data packets at this stage; that is, in step S150, the backup system does not respond to the data packets sent by the primary system. However, the two systems can pre-agree on a unified time to centrally process the response to data packets, thereby reducing the synchronization interaction time consumed by the data synchronization handshake process.

[0103] Optionally, the agreed-upon unified time between the two systems can be after clock synchronization is completed. After the primary and backup systems synchronize their clocks, the backup system responds centrally to the primary system for all received data packets.

[0104] Specifically, if the current system is the primary system in the current cycle, it obtains a list of data packets sent by neighboring systems. This list represents all data packets received by the neighboring (backup) system. It then checks if the number of data packets received by the neighboring system matches the number of data packets sent by the current system. If they differ, data packets not in the list are retransmitted. If they match, it indicates that no data packets were missed by the backup system, and the data synchronization process for the current cycle ends. If the current system is the backup system in the current cycle, the backup system generates a data packet list based on all data packets sent by the neighboring (primary) system received in its data buffer and sends this list to the neighboring system. Therefore, the primary system only needs to perform a single unified confirmation based on the data packet list sent by the backup system, avoiding multiple confirmations and reducing synchronization interaction time.

[0105] In the above process, the primary system verifies whether there are any missing data packets during data transmission based on the data packet list. For example, if the business data for the current period is 20KB in size, the primary system will perform Ethernet framing on this 20KB data and encapsulate it into 18 Ethernet data packets. If the backup system only receives 15 data packets in the data packet list sent by the backup system, the primary system will retransmit the 3 data packets that are not in the data packet list.

[0106] Once the next cycle begins and the status of the primary and backup systems for that cycle is determined, the backup system will verify the integrity of each data packet to further determine whether any errors occurred during transmission.

[0107] Please refer to Figure 5 In step S120, if the current system is a backup system in both the current period and the previous period, the step of retrieving synchronization data sent by a neighboring system in the previous period from the data buffer and obtaining the output data of the current system based on this synchronization data includes a data packet integrity verification step, specifically including:

[0108] Step S121: Retrieve all data packets sent by neighboring systems in the previous period from the data buffer.

[0109] Step S122: Verify the integrity of each data packet. If all data packets pass verification, proceed to step S123; if any data packet fails verification, proceed to step S124.

[0110] Step S123: Combine all the data packets into the output data of this system.

[0111] Step S124: Set the system to not output or redirect output to the safety side in the current cycle.

[0112] In the above process, the integrity of each data packet is verified. If all data packets are complete, the verification passes, and the output data of this system is composed of all data packets to ensure consistency with neighboring systems. If any data packet is incomplete, it indicates an error in the data transmission process, and the verification fails. In this case, all data packets received in the data buffer can be discarded, and no output can be set for the current period to prevent conflict with the output of neighboring systems. Alternatively, the output can be guided towards the safe side according to the "fault-oriented safety" principle. However, on railways, it is generally considered relatively safe for the train to stop.

[0113] Reference Figure 6 The flowchart shown illustrates the synchronization method for a secure computer system provided in this application embodiment. At the beginning of the current cycle, business data obtained in the previous cycle is output, and at the beginning of the next cycle, business data obtained in the current cycle is output. This ensures that, regardless of the circumstances, the first system and the second system always output at the same time point within the same cycle, making the output unaffected by the data synchronization process. This solves the problem of reduced system operating efficiency caused by waiting for data synchronization to complete in the prior art. Furthermore, during data synchronization between the two systems, the first system acts as the primary system, and the second system as the backup system. The first system only needs to send data packets to the second system and can execute subsequent self-check steps without waiting for a response from the second system. Similarly, the second system does not need to wait for data packets from the first system to execute subsequent self-check steps. Even if there are processing deviations between the two systems due to inconsistencies in processing tasks or external acquisition conditions, the data synchronization process remains unaffected, significantly reducing the synchronization requirements for the simultaneous operation of the two systems. The two systems agree to process data packets in a unified manner after clock synchronization. At this time, if the data packets received by the second system are missing, the first system can resend the missing data packets during transmission. In this way, even if the data packets of the first system are not responded to in the first time, it will not affect the synchronization effect of the two systems. The output result is guaranteed to be controllable and acceptable through the data packet response process and the data packet integrity verification process at the beginning of the next cycle.

[0114] Based on the same inventive concept, embodiments of this application provide a secure computer system. This secure computer system includes a first system and a second system, which are adjacent to each other and have identical hardware configurations. The first and second systems are used to collect the same node / device data and perform corresponding business processing based on the data. The first and second systems are hot-standby redundant; when the first system is the master system, the second system is the backup system, and when the first system is the backup system, the second system is the master system. Both the first and second systems are pre-programmed with computer programs capable of implementing the synchronization method provided in the embodiments of this application. When the first and second systems execute the computer program, the synchronization method provided in the above-described method embodiments is implemented.

[0115] This application also provides a computing device, including:

[0116] processor;

[0117] Memory used to store processor-executable instructions;

[0118] The processor is configured to execute the synchronization method provided in the embodiments of this application when the instructions are executed.

[0119] This application also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, implement the synchronization method provided in this application.

[0120] Figure 7 This is a block diagram illustrating a computing device 300 according to an exemplary embodiment. Figure 7 As shown, the computing device 300 may include a processor 301 and a memory 302. The computing device 300 may also include one or more of a multimedia component 303, an input / output (I / O) interface 304, and a communication component 305.

[0121] The processor 301 controls the overall operation of the computing device 300 to complete all or part of the steps in the aforementioned synchronization method for a secure computer system. The memory 302 stores various types of data to support the operation of the computing device 300. This data may include, for example, instructions for any application or method operating on the computing device 300, and application-related data, such as acquired sensor data or line data, or current cycle business data. The memory 302 can be implemented using any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. Multimedia component 303 may include a screen and an audio component. The screen may be, for example, a touchscreen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signals may be further stored in memory 302 or transmitted via communication component 305. The audio component also includes at least one speaker for outputting audio signals. I / O interface 304 provides an interface between processor 301 and other interface modules, such as a keyboard, mouse, buttons, etc. These buttons may be virtual or physical buttons. Communication component 305 is used for wired or wireless communication between the computing device 300 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, 4G, NB-IoT, eMTC, or other 5G technologies, or combinations thereof, is not limited here. Therefore, the corresponding communication component 305 may include: a Wi-Fi module, a Bluetooth module, an NFC module, etc.

[0122] In an exemplary embodiment, the computing device 300 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the synchronization method of the security computer system described above.

[0123] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided, which, when executed by a processor, implement the steps of the above-described synchronization method for a secure computer system. For example, the computer-readable storage medium may be the memory 302 including program instructions, which may be executed by the processor 301 of the computing device 300 to complete the above-described synchronization method for a secure computer system.

[0124] In another exemplary embodiment, a computer program product is also provided, the computer program product comprising a computer program executable by a programmable device, the computer program having a code portion for performing the synchronization method of the security computer system described above when executed by the programmable device.

[0125] The preferred embodiments of this disclosure have been described in detail above with reference to the accompanying drawings. However, this disclosure is not limited to the specific details of the above embodiments. Within the scope of the technical concept of this disclosure, various simple modifications can be made to the technical solutions of this disclosure, and these simple modifications all fall within the protection scope of this disclosure.

[0126] Furthermore, various different embodiments of this disclosure can be combined in any way, as long as they do not violate the spirit of this disclosure, they should also be regarded as the content disclosed in this disclosure.

Claims

1. A synchronization method of a secure computer system, characterized by, The safety computer system comprises a first system and a second system which are adjacent to each other and perform the method; the method comprises: After the start of the current period, determining the master-slave system state of the current period of the system; If the system is the master in the current period and the previous period, obtaining the output data of the system according to the service data obtained after the system performs service processing in the previous period; if the system is the standby in the current period and the previous period, taking out the synchronization data sent by the adjacent system in the previous period from the data buffer, and obtaining the output data of the system according to the synchronization data; Outputting the output data to the backend device; Obtaining the input data of the current period and performing service processing according to the input data to obtain the service data of the current period; If the system is the master in the current period, sending the service data of the current period to the adjacent system as synchronization data.

2. The method of claim 1, wherein, The method further comprises: If the system is the master in the current period and the standby in the previous period, discarding the synchronization data sent by the adjacent system in the previous period in the data buffer, and obtaining the output data of the system according to the service data obtained after the system performs service processing in the previous period; if the system is the standby in the current period and the master in the previous period, setting the system to not output data to the backend device in the current period.

3. The method of claim 1, wherein, The determination of the master-slave system state of the current period of the system comprises: Obtaining the system switching judgment result of the previous period of the system; Obtaining the state of the associated relay of the system; wherein the associated relay of the system is interlocked with the associated relay of the adjacent system, and the state comprises being pulled up or pulled down; If the system switching judgment result indicates that the system needs to be switched to the master in the current period and the state of the associated relay is pulled up, it is determined that the system is the master in the current period; if the system switching judgment result indicates that the system needs to be switched to the standby in the current period and the state of the associated relay is pulled down, it is determined that the system is the standby in the current period.

4. The method of claim 3, wherein, The method further comprises: After obtaining the service data of the current period, obtaining the system switching suggestion score of the system and the adjacent system, and obtaining the system switching judgment result by comparing the system switching suggestion scores of the system and the adjacent system; If the system switching judgment result indicates that the system needs to be switched to the master in the next period, the associated relay of the system is controlled to be pulled up; if the system switching judgment result indicates that the system needs to be switched to the standby in the next period, the associated relay of the system is controlled to be pulled down.

5. The method of claim 1, wherein, The method further comprises: At a preset time point before the end of the current period, performing clock synchronization with the adjacent system.

6. The method of claim 5, wherein, If the system is the master in the current period, the system is configured to encapsulate the service data of the current period into at least one data packet after obtaining the service data of the current period by performing service processing, and send the at least one data packet to the adjacent system, and the system is configured to be able to execute the subsequent steps in the case that the adjacent system does not respond to the at least one data packet; If the current period is a standby period for the current system, the current system is configured to receive data packets sent by the neighbor system through the data buffer, and after obtaining service data of the current period by processing services, if the data packets sent by the neighbor system are not received, the subsequent step is performed.

7. The method of claim 6, wherein, The method further comprises: After clock synchronization with the neighbor system, if the current period is a master period for the current system, a data packet list sent by the neighbor system is obtained, the data packet list represents all data packets received by the neighbor system, whether the number of data packets received by the neighbor system is the same as the number of data packets sent by the current system to the neighbor system is determined according to the data packet list, and if not, the data packets not in the data packet list are retransmitted; If the current period is a standby period for the current system, the data packet list is sent to the neighbor system.

8. The method of claim 7, wherein, The synchronization data sent by the neighbor system in the previous period is taken out from the data buffer, and output data of the current system is obtained according to the synchronization data, comprising: All data packets sent by the neighbor system in the previous period are taken out from the data buffer; The integrity of each data packet is checked; If all data packets are complete, the output data of the current system is composed according to all data packets.

9. The method according to any one of claims 5-8, characterized in that, The method further comprises: Before clock synchronization with the neighbor system, self-checking of a running environment is performed, the running environment comprising at least one of a processor, a memory and a watchdog.

10. A secure computer system, characterized by The secure computer system comprises a first system and a second system which are neighbors of each other, and the first system and the second system are used to execute the method according to any one of claims 1-9.

11. A computing device, comprising: Comprise: A processor; A memory for storing processor-executable instructions; Wherein the processor is configured to execute the method according to any one of claims 1-9 when executing the instructions.

12. A computer-readable storage medium having stored thereon computer program instructions, wherein, The computer program instructions are executed by the processor to implement the method according to any one of claims 1-9. The computer program instructions are executed by the processor to implement the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Task synchronization method

    CN103713959A

  • Host and backup system high-speed switching method based on IO interlocking

    CN103885416A