A hybrid critical system based on TSN and an industrial control method
By introducing partitions and partition kernels into the TSN network, combined with TSN network cards and dual redundant connections, the communication challenges in hybrid mission-critical systems are addressed, achieving efficient real-time data transmission and system fault tolerance, and improving the determinism of time-critical tasks.
Patent Information
- Application Number
- CN202311399885.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-25
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2043-10-25
AI Technical Summary
The application of TSN technology in hybrid critical systems faces challenges such as network deployment complexity, integration difficulty, and network security, making it difficult to achieve efficient real-time communication and deterministic data transmission.
A hybrid critical system based on TSN is adopted, which maps the scheduling time slots of real-time partitions to the communication time slots of the TSN network through partitioning and partition kernel. Combined with the TSN network card to provide synchronous clock and dual redundant connection, the determinism of communication latency is improved. Furthermore, by adapting the partition task priority to the TSN service priority, it supports the mixed transmission of strong real-time, soft real-time and non-real-time data.
A time-deterministic network for hybrid critical systems was implemented, which improved the determinism of time-critical tasks, controlled communication latency within the microsecond level, and enhanced the system's fault tolerance and communication time determinism.
Smart Images

Figure CN117411584B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial control, and more particularly to a hybrid critical system based on TSN and an industrial control method. Background Technology
[0002] Time-Sensitive Networking (TSN) is a standard technology defined by IEEE, located at Layer 2 (Data Link Layer) of the OSI model. It extends the functionality of current Ethernet networks, enabling deterministic message passing over standard Ethernet. TSN technology ensures deterministic communication by utilizing time synchronization methods (IEEE 802.1AS) and time-division multiplexing methods (IEEE 802.1Qbv). Compared to traditional Ethernet communication, TSN technology can combine real-time and non-real-time communication.
[0003] The current application areas of TSN technology are as follows:
[0004] Industrial Automation: TSN technology has great application potential in the field of industrial automation. It can provide deterministic real-time communication, optimizing the performance of industrial control systems. TSN can be used for real-time control, data acquisition and transmission, and device connectivity.
[0005] In the automotive sector, TSN technology is increasingly being used. It can be used for real-time data transmission, time synchronization in vehicle networks, and high-reliability communication. TSN technology helps support Advanced Driver Assistance Systems (ADAS) and connected vehicle applications in automobiles.
[0006] Aerospace: The aerospace industry has high demands for real-time and reliable communication, and TSN technology can meet these requirements. It can be used for data transmission, time synchronization, and network characteristic control in aerospace communication systems.
[0007] In the medical field: Real-time communication is crucial for monitoring and control in medical devices and systems. TSN technology can provide precise data transmission and time synchronization, helping medical systems achieve efficient and accurate operation.
[0008] Currently, TSN technology is widely used in these fields and continues to make progress. However, the application of TSN still faces some challenges and limitations, such as the complexity of network deployment, integration with existing technologies, and network security. To better promote the development of TSN technology in hybrid mission-critical systems, it is necessary to further address these challenges and continue research and innovation. Summary of the Invention
[0009] In view of this, embodiments of the present invention provide a hybrid critical system and industrial control method based on TSN. The critical system includes partitions and partition kernels. The partitions are deployed on the partition kernels of the physical nodes, including real-time partitions, and each physical node is connected to the TSN network. The partition kernel is used to map the scheduling time slots of the real-time partitions on the physical node to the communication time slots of the TSN network. The partition kernel is also used to map the task priorities of the real-time partitions on the physical node to the service priorities of the TSN network. Embodiments of the present invention realize a time-deterministic network for information communication in hybrid critical systems, improve the determinism of time-critical tasks, and control the communication latency within the microsecond level.
[0010] In a first aspect, embodiments of the present invention provide a hybrid critical system based on TSN, comprising: a partition and a partition kernel; the partition is deployed on the partition kernel of the physical node, including a real-time partition, and each physical node is connected to the TSN network; the partition kernel is used to map the scheduling time slots of the real-time partition of the physical node to the communication time slots of the TSN network; the partition kernel is also used to map the task priority of the real-time partition of the physical node to the service priority of the TSN network.
[0011] As described above, by mapping partition scheduling time slots to TSN forwarding time slots, a time-deterministic network for information communication in hybrid critical systems is realized, supporting the mixed transmission of strong real-time, soft real-time, and non-real-time data, improving the determinism of time-critical tasks, and controlling communication latency within the microsecond level. Furthermore, by adapting the task priorities of partitions to the service priorities of TSNs, the time determinism of data transmission in high-priority partitions is further improved.
[0012] In one possible implementation of the first aspect, it further includes: a TSN network interface card (NIC) for connecting the physical node to the TSN network and providing a synchronization clock for the real-time partition kernel and partitions of the physical node. In some embodiments, the TSN NIC provides a synchronization clock for the real-time partition kernel and partitions of the physical node via the 802.1As protocol.
[0013] As described above, the TSN network card provides a synchronization clock for the operating system and partitions of its physical node, realizing clock synchronization between partitions and between partitions and the TSN network, thereby improving the time determinism of partition TSN communication.
[0014] In one possible implementation of the first aspect, the real-time partition directly performs TSN de-framing and re-framing by calling the TSN de-framing and re-framing functions of the partition kernel of the physical node.
[0015] As described above, by calling the deframe and reframe functions in the partition kernel directly to perform TSN deframe and reframe in the partition, the TSN protocol stack is avoided in the operating system kernel for deframe and reframe, reducing the time jitter of TSN data deframe and reframe, and further improving the time determinism of partition TSN communication.
[0016] In one possible implementation of the first aspect, the partition kernel is further configured to dispatch interrupts to the partitions of the physical node, wherein the TSN communication interrupts of the real-time partitions have a higher priority than other service interrupts.
[0017] Therefore, by increasing the priority of TSN communication interrupts, the timing determinism of partitioned TSN communication is further improved, allowing TSN communication interrupts to be dispatched and processed with priority.
[0018] In one possible implementation of the first aspect, the partition kernel maps the scheduling time slots of the real-time partitions of the physical node to the communication time slots of the TSN network through a partition time scheduling table. In some embodiments, the communication time slots are forwarding time slots in the 802.1Qbv protocol of the TSN.
[0019] As described above, by using a partition time scheduling table to map the partition's scheduling time slots to the TSN network's communication time slots, the partition's data can be sent in a timely manner through the corresponding TSN node's forwarding time slot, further improving the time determinism of partition TSN communication.
[0020] In one possible implementation of the first aspect, the TSN network card further includes: prioritizing the transmission of TSN data with higher service priority within its transmission buffer.
[0021] As described above, by prioritizing the transmission of high-priority TSN data within the TSN network card's transmit buffer, the time determinism of high-priority TSN data transmission is improved.
[0022] In one possible implementation of the first aspect, the TSN network card and the TSN network are connected with dual redundancy.
[0023] As described above, the dual redundant connection between the TSN NIC and the TSN network further improves the time determinism of time-critical tasks in hybrid critical systems.
[0024] In one possible implementation of the first aspect, when the critical system is used for remote control, it further includes: a remote control unit connected to the TSN network and the controlled system, used to collect data from the controlled system and issue control commands to the controlled system, the remote control unit being clock-synchronized with the TSN network and having TSN node functionality. The remote control unit, the TSN network, and each TSN network interface card form a deterministic network.
[0025] As described above, a deterministic network is formed by the remote control unit, the TSN network, and each TSN network card, enabling real-time control of the controlled system.
[0026] In one possible implementation of the first aspect, the remote control unit and the TSN network are connected with dual redundancy.
[0027] As described above, the dual redundant connection between the remote control unit and the TSN network further improves the time determinism of time-critical tasks in hybrid critical systems.
[0028] In one possible implementation of the first aspect, the physical nodes employ N+1 backup.
[0029] As described above, physical nodes achieve fault tolerance for partitions through N+1 backups, thereby improving the fault tolerance of hybrid critical systems.
[0030] Secondly, embodiments of the present invention provide an industrial control method for controlling an industrial system using a hybrid critical system based on TSN. The hybrid critical system includes partitions and partition kernels. Partitions are deployed on the partition kernels of their respective physical nodes and include real-time partitions. Each physical node is connected to a TSN network. The scheduling time slots of the real-time partitions are mapped to the communication time slots of the TSN network, and the task priorities of the real-time partitions are mapped to the service priorities of the TSN network. The method includes: a computing partition using the communication partition of its physical node to acquire field data of the industrial system through the TSN network, wherein the computing partition is a partition that performs computational decisions, and the communication partition is a real-time partition that performs TSN communication; the computing partition performs computational decisions based on the field data and sends the results of the computational decisions to a control partition, wherein the control partition is a real-time partition that performs real-time control of the industrial system. When the control partition and the computing partition are not on the same physical node, the results are forwarded through the corresponding communication partition; the control partition generates control commands in real-time based on the results and sends them to the industrial system through the communication partition of its physical node to perform real-time control of the industrial system.
[0031] As described above, by synchronizing the clock across the entire system and mapping the partitioned scheduling time slots to the TSN forwarding time slots, a time-deterministic network for information communication in hybrid critical systems is realized, supporting the mixed transmission of strong real-time, soft real-time, and non-real-time data, improving the determinism of time-critical tasks, and thus enabling real-time control of industrial systems.
[0032] In one possible implementation of the second aspect, the hybrid critical system further includes: a TSN network interface card (NIC) for connecting to a TSN network; an industrial control method further includes: the TSN NIC providing a synchronization clock for the real-time partition kernel and partitions of its physical node.
[0033] As described above, the TSN network card provides a synchronization clock for the operating system and partitions of its physical node, realizing clock synchronization between partitions and between partitions and the TSN network, thereby improving the time determinism of partition TSN communication.
[0034] In one possible implementation of the second aspect, it further includes: the real-time partition calls the TSN deframe and reframe functions of the partition kernel of the physical node where it is located to directly perform TSN deframe and reframe in the partition.
[0035] As described above, by calling the TSN partition kernel's TSN deframing and reframing functions directly within the partition, TSN deframing and reframing are performed directly within the partition. This avoids using the TSN protocol stack in the operating system kernel for deframing and reframing, reducing the time jitter of TSN data deframing and reframing, and further improving the time determinism of partition TSN communication.
[0036] In one possible implementation of the second aspect, it further includes: the partition kernel dispatching an interrupt to the partition of the physical node, wherein the TSN communication interrupt of the real-time partition has a higher priority than other service interrupts.
[0037] Therefore, by increasing the priority of TSN communication interrupts, the timing determinism of partitioned TSN communication is further improved, allowing TSN communication interrupts to be dispatched and processed with priority.
[0038] In one possible implementation of the second aspect, the method further includes: the partition kernel mapping the scheduling time slots of the real-time partitions of the physical node to the communication time slots of the TSN network through a partition time scheduling table. In some embodiments, the communication time slots are forwarding time slots in the 802.1Qbv protocol of TSN.
[0039] As described above, by using a partition time scheduling table to map the partition's scheduling time slots to the TSN network's communication time slots, the partition's data can be sent in a timely manner through the corresponding TSN node's forwarding time slot, further improving the time determinism of partition TSN communication.
[0040] In one possible implementation of the second aspect, the TSN network card further includes: prioritizing the transmission of TSN data with higher service priority within its transmission buffer.
[0041] As described above, by prioritizing the transmission of high-priority TSN data within the TSN network card's transmit buffer, the time determinism of high-priority TSN data transmission is improved.
[0042] In one possible implementation of the second aspect, the TSN network card and the TSN network are connected with dual redundancy.
[0043] As described above, the dual redundant connection between the TSN NIC and the TSN network further improves the time determinism of time-critical tasks in hybrid critical systems.
[0044] In one possible implementation of the second aspect, when the critical system is used for remote control, it further includes: a remote control unit; which connects the TSN network and the controlled system. An industrial control method further includes: the remote control unit acquiring data from the controlled system and issuing control commands to the controlled system; the remote control unit is clock-synchronized with the TSN network and has TSN node functionality. The remote control unit, the TSN network, and each TSN network interface card form a deterministic network.
[0045] As described above, a deterministic network is formed by the remote control unit, the TSN network, and each TSN network card, enabling real-time control of the controlled system.
[0046] In one possible implementation of the second aspect, the remote control unit and the TSN network are connected with dual redundancy.
[0047] As described above, the dual redundant connection between the remote control unit and the TSN network further improves the time determinism of time-critical tasks in hybrid critical systems.
[0048] In one possible implementation of the second aspect, the physical node employs N+1 backup.
[0049] As described above, physical nodes achieve fault tolerance for partitions through N+1 backups, thereby improving the fault tolerance of hybrid critical systems.
[0050] Thirdly, embodiments of the present invention provide an industrial control system, including: the key system described in any embodiment of the first aspect.
[0051] Therefore, by using hybrid critical systems that support time-critical tasks for industrial control, the time determinism of industrial control systems can be improved. Attached Figure Description
[0052] Figure 1 This is a schematic diagram of a first embodiment of a hybrid critical system based on TSN according to the present invention;
[0053] Figure 2 This is a schematic diagram of a second embodiment of a hybrid critical system based on TSN according to the present invention;
[0054] Figure 3 A schematic diagram of the TSN queue switch;
[0055] Figure 4 A diagram illustrating the queue switch status and duration of a custom TSN node;
[0056] Figure 5 This is a schematic diagram illustrating the mapping between the partitioned time scheduling table and the TSN flow forwarding scheduling in a second embodiment of a TSN-based hybrid critical system according to the present invention.
[0057] Figure 6 This is a schematic flowchart of an embodiment of an industrial control method according to the present invention. Detailed Implementation
[0058] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0059] In the following description, the terms “first, second, third, etc.” or module A, module B, module C, etc. are used only to distinguish similar objects or different embodiments and do not represent a specific ordering of objects. It is understood that a specific order or sequence may be interchanged where permitted so that the embodiments of the invention described herein can be implemented in an order other than that illustrated or described herein.
[0060] In the following description, the labels of the steps, such as S110, S120, etc., do not necessarily mean that the steps will be executed in this way. The order of the steps can be interchanged or executed simultaneously if permitted.
[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein is for the purpose of describing embodiments of the invention only and is not intended to limit the invention.
[0062] This invention provides a hybrid critical system and industrial control method based on TSN. The critical system includes partitions and partition kernels. The partitions are deployed on the partition kernels of the physical nodes and include real-time partitions. Each physical node is connected to the TSN network. The partition kernel is used to map the scheduling time slots of the real-time partitions on the physical nodes to the communication time slots of the TSN network. The partition kernel is also used to map the task priorities of the real-time partitions on the physical nodes to the service priorities of the TSN network.
[0063] This invention provides real-time control for industrial systems, including industrial automation systems, aerospace systems, and automotive electrification systems. The technical solution of this invention achieves a time-deterministic network for information communication in hybrid critical systems by mapping global clock synchronization and partitioned scheduling time slots to TSN forwarding time slots. It supports the mixed transmission of strong real-time, soft real-time, and non-real-time data, improving the determinism of time-critical tasks, with communication latency controlled within the microsecond level.
[0064] The key aspect of the embodiments of this invention is that the partitioning tasks in the application layer have security or time priorities, and therefore require real-time time determinism. The hybrid approach of the embodiments of this invention involves application layer partitioning tasks having different time determinism requirements, with distinctions between real-time and non-real-time, and further distinctions between strong real-time and soft real-time within the real-time category.
[0065] The embodiments of the present invention will now be described in conjunction with the accompanying drawings. Figure 1 This paper introduces an embodiment of a hybrid critical system based on TSN according to the present invention.
[0066] Figure 1 The structure of a hybrid critical system based on TSN is shown in Embodiment 1, including: application layer 100, operating system layer 200 and network layer 400.
[0067] The application layer 100 and the operating system layer 200 are distributed on one or more physical nodes from top to bottom. Figure 1 The diagram shows two physical nodes, 10 and 20, but in a real-world scenario, multiple physical nodes may be included. The following description in this embodiment uses two physical nodes, 10 and 20, as an example.
[0068] In some embodiments, physical nodes employ N+1 backups to achieve N+1 backups of partitions and partition kernels on them, providing fault tolerance for industrial control tasks.
[0069] Network layer 400 is a TSN network. Its TSN gateway 410 is used to enable communication between physical nodes across partitions on physical node 10 and physical node 20, and also for partitions on physical node 10 and physical node 20 to communicate with other systems connected to network layer 400, such as industrial systems. Network layer 400, together with physical node 10 and physical node 20, forms a deterministic network. The partitions of physical node 10 and physical node 20 synchronize their clocks through the TSN network.
[0070] In some embodiments, the TSN network of network layer 400 is a dual-redundant star topology, including two TSN gateways, to realize redundant connections between the TSN network and each physical node, thereby improving the fault tolerance capability of hybrid critical system communication.
[0071] Application layer 100 includes partitions, each a time-division partition, used to perform partition tasks such as computational decision-making, TSN communication, and real-time control. Partitions performing different tasks have corresponding priorities. For example, the priority of a partition performing TSN communication is generally higher than that of a partition performing real-time control, and the priority of a partition performing real-time control is generally higher than that of a partition performing computational decision-making. Partitions performing TSN communication and real-time control are generally real-time partitions, while some computational decision-making partitions have long execution times or are even non-real-time partitions.
[0072] The application layer 100 partitions on physical node 10 include partitions 110, 111, and 112. The application layer 100 partitions on physical node 20 include partitions 120, 121, and 122. In a real-world scenario, multiple physical nodes may be included, and each physical node may include multiple partitions.
[0073] The operating system layer 200 includes a partition kernel, which provides partition management and TSN driver for the partitions on it. The partition management provides conventional partition management functions such as partition resource management and partition time scheduling. The TSN driver implements the mapping of the communication time slots of the partitions used for TSN communication to the communication time slots of TSN, and also improves the time determinism of partition communication.
[0074] The TSN driver is also used to adapt the task priority of the partition used for TSN communication on its physical node to the TSN service priority, thereby further improving the time determinism of high-priority partitions used for TSN communication with the TSN network.
[0075] The operating system layer 200 includes a partition kernel 210 on the physical node 10. The partition kernel 210 includes a TSN driver 211, which enables each partition of the physical node 10 to communicate with the TSN network.
[0076] The operating system layer 200 includes a partition kernel 220 on the physical node 20. The partition kernel 220 includes a TSN driver 221, which enables partitions 120, 121, and 122 to communicate with the TSN network.
[0077] In some embodiments, when the TSN driver implements the mapping between the communication time slots of a partition used for TSN communication and the communication time slots of the TSN, it specifically uses a time scheduling table to map the scheduling time slots of the partition to the communication time slots of the corresponding TSN node in the TSN protocol, thereby achieving time determinism between the partition used for TSN communication and the TSN network communication. The correspondence between the TSN communication partition and the TSN node in the TSN protocol is configurable.
[0078] In some embodiments, the partition of application layer 100 calls the deframe and reframe functions in the TSN driver of the operating system layer 200 on the physical node to directly perform TSN deframe and reframe on the partition. This further improves the time determinism of the partition of application layer 100 communicating with the TSN network compared to deframe and reframe through the protocol stack of the partition kernel.
[0079] In some embodiments, the operating system layer 200 is also used to dispatch interrupts to its partitions, wherein the priority of TSN communication interrupts is higher than that of other service interrupts, so that TSN communication interrupts are dispatched and processed first, thereby further improving the time determinism of the application layer 100 partitions communicating with the TSN network.
[0080] In some embodiments, the physical node also includes a TSN network interface card (NIC) to provide communication between the partition of the physical node and the TSN network.
[0081] In some embodiments, the TSN network card prioritizes sending TSN data with high service priority in its transmit buffer.
[0082] In some embodiments, when the network layer 400 includes two TSN gateways, each TSN network card is connected to the two TSN gateways respectively to achieve redundant connection and improve the fault tolerance capability of the TSN network card in communicating with the network layer 400.
[0083] In some embodiments, the hybrid critical system further includes a remote control layer, which includes remote control units for acquiring data from the industrial system and issuing control commands to the industrial system via the TSN network, thereby enabling control of the industrial system. The remote control units are clock-synchronized with the TSN network and have TSN node functionality, thereby enabling deterministic communication between the application layer 100 partitions and the remote control units.
[0084] In some embodiments, when the network layer 400 includes two TSN gateways, the remote control unit connects to the two TSN gateways respectively to achieve redundant connection and improve the fault tolerance capability of communication between the remote control layer and the network layer 400.
[0085] In summary, the TSN-based hybrid critical system embodiment one is used for real-time control of industrial systems. By synchronizing the clock of the entire system and mapping the partitioned scheduling time slots with the TSN forwarding time slots, a time deterministic network for information communication in hybrid critical systems is realized. It supports the mixed transmission of strong real-time, soft real-time and non-real-time data, improves the determinism of time-critical tasks, and controls the communication latency within the microsecond level.
[0086] A second embodiment of a TSN-based hybrid critical system inherits all the structures of a first embodiment of a TSN-based hybrid critical system and has all its advantages. It provides detailed implementation methods for partitioned task priority mapping and partitioned scheduling time slot mapping, and also adds redundant structures for the hybrid critical system and time deterministic design of the operating system layer and hardware layer.
[0087] Figure 2 The diagram illustrates the structure of a second embodiment of a hybrid critical system based on TSN. Based on a first embodiment of a hybrid critical system based on TSN, a hardware layer 300 and a remote control layer 500 are added. The network layer 400, together with the hardware layer 300 and the remote control layer 500, forms a deterministic network. The layers of the hybrid critical system are clock synchronized through the TSN network.
[0088] Add physical nodes 30 and 40 to the physical node list. Physical node 40 can be considered a 3+1 backup of physical nodes 10, 20, and 30. Physical nodes 30 and 40 include corresponding partitions, partition kernels, and TSN network cards. In practical scenarios, more physical nodes can be added to achieve an N+1 configuration.
[0089] On the TSN network at network layer 400, redundant TSN gateways 420 are added, and each TSN network card at hardware layer 300 is connected to each TSN gateway to achieve dual redundancy.
[0090] Hardware layer 300 includes TSN network interface cards (NICs), with one TSN NIC per physical node. TSN NIC 310, located on physical node 10, enables communication between the partitions of physical node 10 and the TSN network, and provides clock synchronization for the partitions and their kernels on physical node 10. TSN NIC 320, located on physical node 20, enables communication between the partitions of physical node 20 and the TSN network, and provides clock synchronization for the partitions and their kernels on physical node 10. TSN NIC 330, located on physical node 30, enables communication between the partitions of physical node 30 and the TSN network, and provides clock synchronization for the partitions and their kernels on physical node 30. TSN NIC 340, located on physical node 40, enables communication between the partitions of physical node 40 and the TSN network, and provides clock synchronization for the partitions and their kernels on physical node 40.
[0091] Among them, the TSN network card prioritizes sending TSN data with high service priority in its transmission buffer.
[0092] Each TSN network card is connected to TSN gateway 410 and TSN gateway 420 respectively, realizing redundant connection with the TSN network and improving the fault tolerance capability of communication between hardware layer 300 and network layer 400.
[0093] The remote control units on the remote control layer 500 have a redundant structure, consisting of remote control unit 510 and remote control unit 520. Each remote control unit is synchronized with the TSN network clock and has TSN node functionality. Each remote control unit is connected to each TSN gateway, achieving dual redundancy. In practical scenarios, more remote control units can be added.
[0094] The remote control unit 510 includes a real-time control module 511, a real-time control module 512, and a real-time control module 513. The real-time control module 511 and the real-time control module 512 collect data from the sensors 611 and 612 of the industrial system 600, respectively, and send control commands to the controller 613 of the industrial system 600.
[0095] The remote control unit 520 correspondingly includes real-time control modules 521, 522, and 623, which are respectively connected to sensors 621, 622, and controller 623 of the industrial system 600. Each remote control unit is connected to each TSN gateway, achieving dual redundancy. In practical scenarios, more remote control units can be added.
[0096] The following details a time-deterministic design for a hybrid critical system based on TSN, embodiment two.
[0097] (1) Clock synchronization design of application layer 100.
[0098] When implementing clock synchronization, the application layer 100, operating system layer 200, hardware layer 300, network layer 400, and remote control layer 500 use the TSN network card, TSN network, and remote control unit to achieve clock synchronization according to the TSN network 802.1AS protocol. For example, clock synchronization is achieved through the gPTP method of the 802.1AS protocol. The TSN network card provides a synchronization clock for the operating system and partition of its physical node, and the clock of the TSN network and the clock of the real-time partition operating system are synchronized.
[0099] As described above, the clock synchronization design of application layer 100 enables inter-regional clock synchronization of application layer 100, including inter-regional clock synchronization on different physical nodes, which improves the real-time deterministic communication of inter-regional communication. It also enables precise time synchronization between the partitions of application layer 100 and each remote control unit in remote control layer 500, improving the real-time deterministic communication between the partitions and remote control units.
[0100] (2) Time deterministic design of application layer 100.
[0101] Application layer 100 partitions are time-sharing partitions, based on the time scheduling table and priority hybrid scheduling mechanism provided by the corresponding partition kernel on operating system layer 200, to ensure the orderly operation of time-critical partition tasks.
[0102] The partition kernel of operating system layer 200 utilizes the TSN driver to establish a mapping mechanism between the communication time slots of the partition and the communication time slots of the TSN through a time scheduling table. The 802.1Qbv protocol of the TSN supports allowing designated critical services to enter designated interface forwarding queues, and then flexibly and periodically scheduling these queues to achieve zero congestion and packet loss when the device forwards these critical service traffic.
[0103] 1. Provides the ability to map between the task priority (0-256) of the partition and the service priority (0-7) of the TSN network.
[0104] To avoid packet loss due to network congestion, TSN uses forwarding queues to send packets. Each interface has 8 forwarding queues, numbered from 0 to 7. When an interface needs to send a packet, it first puts the packet into the corresponding queue according to certain rules. For packets in the same queue, the packet that entered first is forwarded first.
[0105] In this embodiment, the TSN driver in the partition kernel of the operating system layer 200 provides the ability to map between the priority (0-256) of partition tasks and the service priority (0-7) of the TSN network. By using a fitting algorithm, the task priority values (0-256) are fitted to the service priority values (0-7) of the TSN network, and data is automatically sent to the corresponding TSN queue according to the partition priority.
[0106] 2. Time scheduling table and TSN stream forwarding scheduling mapping
[0107] The TSN flow forwarding scheduling control list is used to implement the scheduling of the interface forwarding queue and the forwarding of packets. The 802.1Qbv control list contains a maximum of 16 nodes. A node is a logical concept; each node defines three attributes, which are used to complete a node's execution operation.
[0108] • Node Numbering: A maximum of 16 nodes can be defined in the control list, with node numbers ranging from 1 to 16. 802.1Qbv schedules nodes sequentially in ascending order of their node numbers.
[0109] • Queue switch status: Figure 3 The diagram shows a TSN queue switch. The switch state of the interface forwarding queue is represented by an 8-bit binary string (XXXXXXXX). When the switch state of a queue is 0, it means that the queue is closed, that is, the queue is not allowed to send packets in the queue; when the switch state of a queue is 1, it means that the queue is open, that is, the queue is allowed to send packets in the queue.
[0110] • Duration of switch state: The duration of the switch state of the interface forwarding queue in the TSN node. When this time is reached, the process continues to the next TSN node and switches to the queue switch state in the next TSN node.
[0111] Figure 4 The queue switching states and duration of the switching states for custom TSN nodes 1-5 are shown.
[0112] In this embodiment, the TSN driver in the partition kernel of the operating system layer 200 synchronizes the time scheduling table of the partition kernel with the TSN flow forwarding scheduling mapping, thereby realizing the mapping between the scheduling time slots of the partition used for TSN communication and the corresponding forwarding time slots of the TSN node, improving the actual determinism of the communication between the partition used for TSN communication and the TSN network. The correspondence between the partition used for TSN communication and the TSN node is configurable.
[0113] The partition's time scheduling table is configured according to the main frame time, and the same main frame is repeatedly executed during scheduling. Figure 5 This diagram illustrates how the time-based scheduling of partitions can be mapped to the forwarding schedule of TSN flows. For example, the scheduling time of partition 1 is synchronized with the forwarding time (i.e., scheduling queue time) of TSN node 1, and the scheduling time of partition 3 is synchronized with the forwarding time (i.e., scheduling queue time) of TSN node 3.
[0114] (3) Deterministic time design of operating system layer 200.
[0115] The TSN driver in the partition kernel on operating system layer 200 sends TSN data directly to the corresponding partition on application layer 100. The corresponding partition on application layer 100 calls the deframe and frame assembly functions in the TSN driver to directly perform TSN framing / deframeing on the TSN data, bypassing the network protocol stack of the partition kernel, shortening data transmission time and reducing transmission jitter.
[0116] The kernel partitioned by the operating system layer 200 elevates the interrupt priority of TSN communication interrupts (from TSN network cards on the same physical node) to higher level than other service interrupts. TSN communication interrupts are dispatched and processed with priority, further reducing transmission jitter.
[0117] (4) Time-deterministic design of hardware layer 300
[0118] The TSN network card at hardware layer 300 completes the transmission and reception of network packets between the CPU and the network card through the PCIe bus, and completes the transmission and reception of time-deterministic data by combining the global synchronization clock and time scheduling table.
[0119] When sending data, the real-time requirements of the three types of data streams—strong real-time, soft real-time, and non-real-time—are determined according to the priority of the TSN service. For the strong real-time, soft real-time, and non-real-time data buffers, the strong real-time data stream is processed first.
[0120] (5) Deterministic Time Design of Network Layer 400
[0121] The network layer 400 is mainly composed of TSN switches, and the TSN gateway (also a type of TSN switch) adopts a dual-redundant star topology. TSN switches provide fully deterministic real-time communication through TSN network technology, ensuring the delivery of time-sensitive data. Through traffic scheduling, they guarantee ultra-low latency for data passing through the switches, achieving deterministic delivery of traffic.
[0122] Network layer 400 adopts a dual-redundant star topology, with at least two paths between the ingress and egress of TSN flows. It can also enable the 802.1CB protocol to further enhance the time determinism of TSN communication within the TSN network through flow replication, including the time determinism of communication between partitions within application layer 100, as well as the time determinism of communication between application layer 100 and remote control layer 500.
[0123] (6) Deterministic Time Design of Remote Control Layer 500
[0124] The remote control layer 500 includes remote control units mounted on a time-deterministic network. These units primarily acquire sensor information, output control commands, and synchronize sensor input data using a global synchronization clock. This improves the time determinism of input data for safety-critical tasks and enhances the time determinism of output control commands.
[0125] In summary, the second embodiment of a TSN-based hybrid critical system, based on the first embodiment, achieves global clock synchronization through the 802.1AS protocol, maps partitioned scheduling time slots to TSN forwarding time slots through 802.1QBV and partitioned scheduling time slices, implements direct frame de-framing / reassembly at the operating system layer and sets high TSN communication interrupt priority, prioritizes the transmission of high-priority data in the buffer at the hardware layer, and adds a redundant structure to the hybrid critical system. This not only further improves the timing determinism of the hybrid critical system but also enhances its fault tolerance.
[0126] The following is combined Figure 6 This paper introduces an industrial control method.
[0127] An embodiment of an industrial control method operates on either a TSN-based hybrid critical system embodiment one or a TSN-based hybrid critical system embodiment two, and accordingly has all the advantages of either a TSN-based hybrid critical system embodiment one or a TSN-based hybrid critical system embodiment two.
[0128] Figure 6 A flow chart of an embodiment of an industrial control method is shown, including steps S610 to S630.
[0129] S610: The computing partition uses the communication partition of its physical node to obtain field data of the industrial system through the TSN network.
[0130] The computation partition is the partition where the application layer performs computational decisions. The computation partition that performs time-critical tasks is a real-time partition to ensure the determinism of computation time, while the computation partition that performs non-time-critical tasks is a non-real-time partition. The communication partition is the real-time partition where the application layer performs TSN communication. Communication through the communication partition is time-deterministic communication.
[0131] The calculation partition shall obtain field data in at least one of the following ways:
[0132] The computing partition actively requests data from the remote control layer through the communication partition of its physical node. The remote control layer sends field data to the communication partition of the physical node where the computing partition is located. The communication partition then forwards the field data to the computing partition within the physical node.
[0133] After the remote control layer generates field data for the industrial system, it actively sends the field data to the communication partition of the physical node where the computing partition that needs the field data is located. The communication partition then forwards the field data to the computing partition within the physical node.
[0134] S620: The calculation zone makes calculations and decisions based on field data and sends the results of the calculations and decisions to the control zone.
[0135] The computation partition makes computational decisions, and the computational task can be a real-time task or a non-real-time task.
[0136] Among them, the control partition is a real-time partition in which the application layer performs real-time control on the industrial system.
[0137] Specifically, when the control partition and the computing partition are not on the same physical node, the result of the computing decision is forwarded through the corresponding communication partition to improve the time determinism of the forwarding of the computing decision result.
[0138] S630: The control partition generates control commands in real time based on the results of the calculation and decision, and sends them to the industrial system through the communication partition of its physical node to control the industrial system in real time.
[0139] Among them, the control partition is a real-time partition, which generates control commands in real time. The control commands can be a single command or multiple real-time serial commands for a process.
[0140] Control commands are forwarded through communication partitions to improve the time determinism of control command forwarding.
[0141] The remote control layer uses multiple control methods, such as PLC master station, to control the industrial system in real time through control commands.
[0142] In summary, an embodiment of an industrial control method operates on either the TSN-based hybrid critical system embodiment one or the TSN-based hybrid critical system embodiment two. By synchronizing the clock of the entire system and mapping the partitioned scheduling time slots to the TSN forwarding time slots, a time-deterministic network for information communication in hybrid critical systems is realized. This supports the mixed transmission of strong real-time, soft real-time, and non-real-time data, improves the determinism of time-critical tasks, and thus enables real-time control of industrial systems.
[0143] This invention also provides an industrial control system, including: a critical system according to either the first embodiment of a TSN-based hybrid critical system or the second embodiment of a TSN-based hybrid critical system, for real-time control of an industrial system.
[0144] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, all of which fall within the scope of protection of the present invention.
Claims
1. A hybrid critical system based on TSN, characterized in that, include: Partitions and partition kernels; The partitions are deployed on the partition kernel of the physical node, including real-time partitions, and each physical node is connected to the TSN network; The partition kernel is used to map the scheduling time slots of the real-time partitions of the physical node to the communication time slots of the TSN network, and to align the scheduling time slots of the real-time partitions used for TSN communication in the physical node with the forwarding time slots corresponding to the TSN nodes on the TSN network. The partitioning kernel is also used to map the task priority of the real-time partitioning on the physical node to the service priority of the TSN network.
2. The key system according to claim 1, characterized in that, Also includes: The TSN network interface card is used to connect the physical node to the TSN network and provide a synchronization clock for the real-time partition kernel and partitions of the physical node.
3. The key system according to claim 1, characterized in that, The real-time partitioning performs TSN deframing and reframing directly within the partition by calling the TSN deframing and reframing functions of the partition kernel on the physical node.
4. The key system according to claim 1, characterized in that, The partition kernel is also used to dispatch interrupts to the partitions of the physical node, wherein the TSN communication interrupt of the real-time partition has a higher priority than other service interrupts.
5. The key system according to claim 1, characterized in that, The partition kernel uses a partition time scheduling table to map the scheduling time slots of the real-time partitions on the physical node to the communication time slots of the TSN network.
6. The key system according to claim 2, characterized in that, The TSN network card prioritizes sending TSN data with higher service priority in its transmission buffer.
7. The key system according to claim 2, characterized in that, The TSN network card and the TSN network are connected with dual redundancy.
8. The key system according to claim 1, characterized in that, When the critical system is used for remote control, it also includes: a remote control unit, which connects the TSN network and the controlled system, for collecting data from the controlled system and issuing control commands to the controlled system.
9. An industrial control method, characterized in that, Industrial system control is achieved through a TSN-based hybrid critical system. The hybrid critical system includes partitions and partition kernels. Partitions are deployed on the partition kernels of physical nodes and include real-time partitions. Each physical node is connected to a TSN network. The scheduling time slots of the real-time partitions are mapped to the communication time slots of the TSN network, and the task priorities of the real-time partitions are mapped to the service priorities of the TSN network. This aligns the scheduling time slots of the real-time partitions used for TSN communication in the physical node with the forwarding time slots corresponding to the TSN nodes on the TSN network. The method includes: The computing partition uses the communication partition of its physical node to obtain field data of the industrial system through the TSN network. The computing partition is the partition that performs computational decisions, and the communication partition is the real-time partition that performs TSN communication. The computing partition performs calculations and decisions based on the field data, and sends the results of the calculations and decisions to the control partition. The control partition is a real-time partition that performs real-time control of the industrial system. When the control partition and the computing partition are not on the same physical node, the results are forwarded through the corresponding communication partition. The control partition generates control commands in real time based on the results and sends them to the industrial system through the communication partition of its physical node to control the industrial system in real time.
10. The method according to claim 9, characterized in that, The hybrid critical system also includes: a TSN network interface card (NIC) for connecting to the TSN network and providing a synchronization clock for the real-time partition kernel and partitions of its physical node.
Citation Information
Patent Citations
Architecture for Converged Industrial Control and Real Time Applications
US20190044894A1
Device, System, and Method for Synchronizing Time Partition Windows
US20190064873A1