Data output system and control method of wayside safety platform, electronic device and storage medium
By employing locking and locking value mechanisms and a high-precision clock synchronization protocol, the problem of unique data output between the primary and backup centers is solved, ensuring that the backup center can take over in a timely manner when the primary center fails, thereby achieving unique data output and system stability, and providing alarm signals to restore communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CASCO SIGNAL LTD
- Filing Date
- 2024-12-03
- Publication Date
- 2026-05-29
AI Technical Summary
In existing technologies, it is difficult to guarantee the uniqueness of data output from primary and backup centers, which may lead to control conflicts and inconsistent data output in emergency situations.
A locking and locking value mechanism is adopted, and data output is controlled through an arbitration module to ensure that only the central module holding the lock and having a lock value greater than 0 can output data. In the event of a failure of the main center, the backup center takes over and uses a high-precision clock synchronization protocol to maintain synchronization.
This enables the backup center to promptly take over data output in the event of a failure in the primary center, avoiding control conflicts, ensuring the uniqueness of data output and the stability of the system, and providing alarm signals to remind maintenance personnel to restore communication.
Smart Images

Figure CN119389277B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data output control technology, and in particular to a data output system and control method, electronic device, and storage medium for a trackside safety platform. Background Technology
[0002] Each of the primary and backup centers is equipped with a 2x2 safety platform system. In the event of a failure in the primary center, the backup center can quickly take over and maintain normal system operation. Both the primary and backup centers are responsible for processing the input and output of various protocol messages. The primary center can output data to external systems, while the backup center serves as a redundant system, maintaining synchronization with the primary center to take over its functions in emergencies. For external systems communicating with the trackside safety platform, the primary and backup centers are transparent; therefore, ensuring that only one primary center outputs data is crucial.
[0003] The invention patent with publication number CN112172879A discloses a method for switching between primary and backup control centers and a comprehensive monitoring system for rail transit. In this invention, the operating mode is determined by a unique arbitration node in the network, and the determined operating mode is distributed to the primary control center, backup control center, and station nodes, ensuring consistency of operating modes and preventing control conflicts. This patent receives operating data uploaded by the primary control center and backup control center through the arbitration node and switches the operating mode. However, this patent does not solve the problem of ensuring the uniqueness of the data output from the primary and backup centers.
[0004] Therefore, providing a control method with only one external data output is an urgent problem to be solved. Summary of the Invention
[0005] The purpose of this invention is to overcome the defects of the prior art by providing a data output system and control method, electronic device and storage medium for a trackside safety platform.
[0006] The objective of this invention can be achieved through the following technical solutions:
[0007] According to a first aspect of the present invention, a data output system for a trackside safety platform is provided, comprising a main center module, multiple backup center modules and an arbitration module, wherein the main center module and the backup center modules are respectively communicatively connected to the arbitration module, and both the main center module and the backup center modules include an MPU unit, wherein the main center module sends a main center heartbeat, the backup center modules send a normal heartbeat, and the arbitration module controls the system output by sending lock or updating lock value information;
[0008] If the MPU unit of the backup center module does not receive the heartbeat from the main center, the backup center module sends a normal heartbeat and requests a lock from the arbitration module. If the lock is received and the lock value is greater than 0, data is output, and the lock value is decremented by one after each output. Alternatively, the arbitration module sends an update lock value information to the main center module. If the MPU unit of the main center module receives the update lock value information, the lock value is updated. Output stops when the lock value is 0.
[0009] As a preferred technical solution, the main center module and the backup center module communicate using a high-precision clock synchronization protocol.
[0010] According to a second aspect of the present invention, a control method for a data output system of any of the trackside safety platforms described above is provided, the method comprising the following steps:
[0011] S1. When the MPU unit of the backup center module enters the first cycle, it determines whether it has received the main center heartbeat sent by the main center module.
[0012] S11. If the MPU unit does not receive the main center heartbeat, the backup center module to which the MPU unit belongs will broadcast a normal heartbeat and request a lock from the arbitration module.
[0013] S12, The arbitration module sends a lock;
[0014] S13. If the MPU unit receives a lock, determine whether the lock value is greater than 0;
[0015] S14. If the lock value is greater than 0, then send out the main center heartbeat and output data. After each output, the lock value is decremented by one.
[0016] S2. If the arbitration module receives the heartbeat from the main center, the arbitration module sends the update lock value information to the main center module, and the MPU unit of the main center module receives the update lock value information and updates the lock value.
[0017] As a preferred technical solution, if an MPU unit receives a lock, the backup center module to which the MPU unit belongs becomes the main center module.
[0018] As a preferred technical solution, step S11 further includes:
[0019] S111. If a primary center heartbeat is received, the central module to which the MPU unit belongs acts as a backup center module and broadcasts a normal heartbeat.
[0020] As a preferred technical solution, step S13 further includes:
[0021] S131. If no lock is received, determine whether the master center heartbeat has been received.
[0022] As a preferred technical solution, step S14 further includes:
[0023] S141. If the lock value is 0, determine whether the main center heartbeat has been received.
[0024] As a preferred technical solution, the process of the arbitration module sending the lock further includes:
[0025] S121. The arbitration module initializes the lock value and assigns it to 0. If the lock value is 0, then the lock is allocated.
[0026] S122. If a lock request is received and the arbitration module determines whether a master center heartbeat exists, and if the lock value is greater than 0 and a master center heartbeat is received, then no lock is allocated.
[0027] As a preferred technical solution, the process of updating the lock value by the arbitration module further includes:
[0028] S21. If the arbitration module does not receive the main center heartbeat, it will subtract the period m of the lock request from the period n of the last lock value update to obtain the first difference and determine whether it is greater than the last updated lock value.
[0029] S211. If the first difference is greater than the lock value updated last time, then allocate a new lock;
[0030] S22. The arbitration module periodically checks whether it has received a heartbeat from the main center;
[0031] S221. If a heartbeat from the main center is received periodically, the lock value is updated periodically.
[0032] As a preferred technical solution, if the arbitration module does not receive a normal heartbeat from the backup center module, an alarm for communication failure will be triggered.
[0033] According to a third aspect of the present invention, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, characterized in that the processor, when executing the program, implements the method as described in any of the preceding claims.
[0034] According to a fourth aspect of the present invention, a computer-readable storage medium is provided having a computer program stored thereon, characterized in that the program, when executed by a processor, implements the method as described in any of the preceding claims.
[0035] Compared with the prior art, the present invention has the following beneficial effects:
[0036] 1. This invention ensures that only the central module holding the lock is the main central module by setting locks and lock values. At the same time, data can only be output when the lock value is greater than 0. The lock value is decremented by one once every cycle. When the lock value is 0, it means that the lock has been reclaimed and no data can be output. By controlling the lock and the increase and decrease of the lock value, the output is controlled.
[0037] 2. In the absence of a main central module outputting data, the arbitration module can independently select a central module as the main central module and output data externally.
[0038] 3. When the present invention does not receive a heartbeat from a central module, it can generate an alarm signal to remind maintenance personnel to restore communication with the center.
[0039] 4. This invention uses a high-precision time synchronization protocol to keep the backup center module and the main center module in periodic synchronization; the backup center module synchronously learns the main center data, and when the main center module loses power, the backup center module can take over the main center in time and continue the system's data output. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of the overall structure of the present invention;
[0041] Figure 2 This is a flowchart of the MPU unit data processing of the present invention;
[0042] Figure 3 This is a flowchart of the MPU unit, the central module of this invention.
[0043] Figure 4 This is a flowchart of the arbitration module of the present invention. Detailed Implementation
[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0045] Both the primary and backup centers are equipped with a 2x2-out-of-2 security platform system. In the event of a failure in the primary center, the backup center can quickly take over and maintain normal system operation. Both the primary and backup centers are responsible for processing the input and output of various protocol messages. The primary center can output data to external systems, while the backup center serves as a redundant system, maintaining synchronization with the primary center to take over its functions in emergencies.
[0046] For external systems communicating with the trackside safety platform, the main and backup centers of the safety platform are transparent. Ensuring that only one main center outputs data is crucial. This invention proposes a control method for data output from both main and backup centers, ensuring that only one main center outputs data. In the event of a power outage at the main center, the backup center can promptly take over the main center's data output.
[0047] This invention provides a data output system and control method for a trackside safety platform. By setting locks and lock values, this invention ensures that only the central module holding the lock is the primary central module. Data output is only possible when the lock value is greater than 0. The lock value is decremented by one each cycle. A lock value of 0 indicates the lock has been reclaimed and no data output is possible. Controlling the locks and their values controls the output. When no primary central module is outputting data, the arbitration module can automatically select a central module as the primary central module and output data. When no heartbeat is received from a central module, an alarm signal is generated to remind maintenance personnel to restore communication with the central module. This invention uses a high-precision time synchronization protocol to maintain periodic synchronization between the backup and primary central modules. The backup central module synchronously learns data from the primary central module, and when the primary central module loses power, the backup central module can promptly take over and continue the system's data output.
[0048] Example 1
[0049] like Figure 1 and Figure 2 As shown, a data output system for a trackside safety platform includes a main center module, multiple backup center modules, and an arbitration module. The main center module and backup center modules are communicatively connected to the arbitration module. Both the main center module and backup center modules include an MPU unit. The main center module sends a main center heartbeat, and the backup center modules send ordinary heartbeats. The arbitration module controls the system output by sending lock or updating lock value information.
[0050] If the MPU unit of the backup center module does not receive the heartbeat from the main center, the backup center module sends a normal heartbeat and requests a lock from the arbitration module. If the lock is received and the lock value is greater than 0, data is output, and the lock value is decremented by one after each output. Alternatively, the arbitration module sends an update lock value information to the main center module. If the MPU unit of the main center module receives the update lock value information, the lock value is updated. Output stops when the lock value is 0.
[0051] The main center module and the backup center module communicate using a high-precision clock synchronization protocol.
[0052] In this embodiment, there is a main center module, multiple backup center modules, and an arbitration module. The arbitration module adopts a distributed arbitration module. The backup center module with a lock is the main center module. There is only one main center module in the system. Only the main center module can send the main center heartbeat. The backup center modules send ordinary heartbeats. The main center module, backup center modules, and arbitration module are connected by an internal high-performance network.
[0053] Each of the main and backup center modules has a 2x2 out-of-2 system, including a dual-system processing board (MPU) and a communication unit. The 2x2 out-of-2 system is connected via a high-speed bus, maintaining tick-level clock synchronization between the two systems. When the main system's data is out of sync with the backup system, it sends synchronization data to the backup system, which then maintains synchronization with the main system. The main and backup center modules communicate using a high-precision clock synchronization protocol, maintaining periodic clock synchronization. The main center module periodically sends synchronization data to the backup center, and the backup center module periodically performs synchronization data education. An arbitration module is used to make decisions between the main and backup center modules and uses a locking mechanism to ensure that only one center module can output data to external systems at a time.
[0054] Both the primary and backup central modules are connected to external systems and periodically process input and output data. However, only the primary central module can output data to external systems. Simultaneously, the primary central module periodically sends synchronization data to the backup central module, which in turn periodically performs synchronization data education. The backup central module maintains periodic clock synchronization with the primary central module, ensuring both systems perform normal input / output processing while maintaining synchronization data education. In the event of a primary central module failure, the backup central module can be activated, upgraded to become the primary central module, and promptly output data.
[0055] Example 2
[0056] like Figure 3 and Figure 4 As shown, a control method for a data output system of a trackside safety platform includes the following steps:
[0057] S1. When the MPU unit of the backup center module enters the first cycle, it determines whether it has received the main center heartbeat sent by the main center module.
[0058] S11. If the MPU unit does not receive the main center heartbeat, the backup center module to which the MPU unit belongs will broadcast a normal heartbeat and request a lock from the arbitration module.
[0059] S12, The arbitration module sends a lock;
[0060] S13. If the MPU unit receives a lock, determine whether the lock value is greater than 0;
[0061] S14. If the lock value is greater than 0, then send out the main center heartbeat and output data. After each output, the lock value is decremented by one.
[0062] S2. If the arbitration module receives the heartbeat from the main center, the arbitration module sends the update lock value information to the main center module, and the MPU unit of the main center module receives the update lock value information and updates the lock value.
[0063] If an MPU unit receives a lock, then the backup center module to which that MPU unit belongs becomes the main center module.
[0064] Step S11 further includes:
[0065] S111. If a primary center heartbeat is received, the central module to which the MPU unit belongs acts as a backup center module and broadcasts a normal heartbeat.
[0066] Step S13 further includes:
[0067] S131. If no lock is received, determine whether the master center heartbeat has been received.
[0068] Step S14 further includes:
[0069] S141. If the lock value is 0, determine whether the main center heartbeat has been received.
[0070] The process of sending the lock by the arbitration module also specifically includes:
[0071] S121. The arbitration module initializes the lock value and assigns it to 0. If the lock value is 0, then the lock is allocated.
[0072] S122. If a lock request is received and the arbitration module determines whether a master center heartbeat exists, and if the lock value is greater than 0 and a master center heartbeat is received, then no lock is allocated.
[0073] The process of updating the lock value by the arbitration module also specifically includes:
[0074] S21. If the arbitration module does not receive the main center heartbeat, it will subtract the period m of the lock request from the period n of the last lock value update to obtain the first difference and determine whether it is greater than the last updated lock value.
[0075] S211. If the first difference is greater than the lock value updated last time, then allocate a new lock;
[0076] S22. The arbitration module periodically checks whether it has received a heartbeat from the main center;
[0077] S221. If a heartbeat from the main center is received periodically, the lock value is updated periodically.
[0078] If the arbitration module does not receive a normal heartbeat from the backup center module, an alarm for communication failure will be triggered.
[0079] In this embodiment, the workflow of the MPU unit is as follows:
[0080] After each central module is initialized and started, the MPU should determine whether it has received a heartbeat from the main center when entering the first main cycle;
[0081] If received, the central module acts as a backup central module, broadcasting a normal heartbeat HB_Common(n, current_ticks) with the current period n and the current tick count value, maintaining communication connections with the distributed arbitration point and other centers;
[0082] If no heartbeat is received from the main center, it means that there may not be a main center in the system yet. Broadcast a normal heartbeat and request a lock ReqLock(n, current_ticks) from the distributed arbitration point.
[0083] If no lock is received, continue to check if the master center heartbeat has been received.
[0084] If a lock is received, check if the lock value is greater than 0 (the lock value is greater than 0 when the lock is first assigned). If it is 0, it means that the lock has been reclaimed. Continue to check if the main center heartbeat has been received and return to step 2.
[0085] If the lock value is greater than 0, the main center heartbeat HB_Active(n,current_ticks) is sent. While the lock value is greater than 0, data can be output to the external system. After each output cycle, the lock value should be decremented by one. Once the lock value reaches 0, it will not be decremented further.
[0086] If a lock value update UpdateLock(p,lockValue) is received from the distributed arbitration point, the lock value should be updated, starting from period p, and the lock value can be held for periods lockValue.
[0087] The arbitration module's workflow includes the following steps:
[0088] The process of sending and allocating a lock: The distributed arbitrator point initializes the lock value to 0; upon receiving a lock request, it should determine whether the system has a master center; if the arbitrator point lock value is 0, it means that the system has just started and there is no master center, so the lock can be allocated; if the lock value is greater than 0, it should be determined whether a heartbeat from the master center is received periodically; if so, the lock is not allocated.
[0089] The process of updating the lock value is as follows: If no heartbeat is received from the main center, it is determined whether the difference between the period m of the lock request and the period n of the last lock value update is greater than the last updated lock value. If it is greater, it means that the last updated lock value was 0 in period m, and the old lock can be reclaimed. A new lock AllocateLock(p, lockValue) is allocated, with the allocation period p and the corresponding lock value lockValue (lockValue, the number of periods for which the lock is held, determined according to the system communication grace time; the main center can hold the lock for lockValue periods starting from period p). The distributed arbitration point should periodically check whether it has received the heartbeat HB_Active(n, current_ticks) from the main center. If it has, it periodically updates the lock value UpdateLock(p, lockValue), with the allocation period p and the corresponding lockValue, and sends it to the main center for update.
[0090] If no heartbeat is received from a center, an alarm should be triggered indicating a communication failure, prompting maintenance personnel to restore communication with the center. The allocation period p is generally assigned the value of the lock request period m, the heartbeat, or the current_ticks in the request. It can be used to assist in adjusting the allocation period p (there are k ticks in one period).
[0091] Example 3
[0092] An electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method as described in any of the preceding claims.
[0093] A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method as described in any of the preceding claims.
[0094] In this embodiment, those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the described module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0095] The electronic device of this invention includes a central processing unit (CPU), which can perform various appropriate actions and processes according to computer program instructions stored in read-only memory (ROM) or loaded from a storage unit into random access memory (RAM). The RAM may also store various programs and data required for device operation. The CPU, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.
[0096] Multiple components in the device are connected to an I / O interface, including: input units such as a keyboard, mouse, etc.; output units such as various types of displays, speakers, etc.; storage units such as disks, optical disks, etc.; and communication units such as network interface cards, modems, wireless transceivers, etc. The communication unit allows the device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks. The processing unit performs the various methods and processes described above, such as the method of the present invention. For example, in some embodiments, the method of the present invention may be implemented as a computer software program tangibly contained in a machine-readable medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed on the device via ROM and / or the communication unit. When the computer program is loaded into RAM and executed by the CPU, one or more steps of the method of the present invention described above may be performed. Alternatively, in other embodiments, the CPU may be configured to execute the method of the present invention by any other suitable means (e.g., by means of firmware).
[0097] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0098] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0099] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0100] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A data output system for a trackside safety platform, comprising a main center module, multiple backup center modules, and an arbitration module, wherein the main center module and backup center modules are respectively communicatively connected to the arbitration module, and each of the main center module and backup center modules includes an MPU unit; the main center module emits a main center heartbeat, and the backup center modules emit ordinary heartbeats, characterized in that... The arbitration module controls the system output by sending lock or updating lock value information; If the MPU unit of the backup center module does not receive the heartbeat from the main center, the backup center module sends a normal heartbeat and requests a lock from the arbitration module. If the lock is received and the lock value is greater than 0, data is output, and the lock value is decremented by one after each output; or the arbitration module sends an update lock value information to the main center module. If the MPU unit of the main center module receives the update lock value information, the lock value is updated; when the lock value is 0, output stops. A control method for a data output system of a trackside safety platform, the method comprising the following steps: S1. When the MPU unit of the backup center module enters the first cycle, it determines whether it has received the main center heartbeat sent by the main center module. S11. If the MPU unit does not receive the main center heartbeat, the backup center module to which the MPU unit belongs will broadcast a normal heartbeat and request a lock from the arbitration module. S12, The arbitration module sends a lock; S13. If the MPU unit receives a lock, determine whether the lock value is greater than 0; S14. If the lock value is greater than 0, then send out the main center heartbeat and output data. After each output, the lock value is decremented by one. S2. If the arbitration module receives the heartbeat from the main center, the arbitration module sends the update lock value information to the main center module, and the MPU unit of the main center module receives the update lock value information and updates the lock value. The process of sending the lock by the arbitration module also specifically includes: S121. The arbitration module initializes the lock value and assigns it to 0. If the lock value is 0, then the lock is allocated. S122. If a lock request is received and the arbitration module determines whether a main center heartbeat exists, and if the lock value is greater than 0 and a main center heartbeat is received, then no lock is allocated. The process of updating the lock value by the arbitration module also specifically includes: S21. If the arbitration module does not receive the main center heartbeat, it will subtract the period m of the lock request from the period n of the last lock value update to obtain the first difference and determine whether it is greater than the last updated lock value. S211. If the first difference is greater than the lock value updated last time, then allocate a new lock; S22. The arbitration module periodically checks whether it has received a heartbeat from the main center; S221. If a heartbeat from the main center is received periodically, the lock value is updated periodically.
2. The data output system for a trackside safety platform according to claim 1, characterized in that, The main center module and the backup center module communicate using a high-precision clock synchronization protocol.
3. The data output system according to claim 1, characterized in that, If an MPU unit receives a lock, then the backup center module to which that MPU unit belongs becomes the main center module.
4. The data output system according to claim 1, characterized in that, Step S11 further includes: S111. If a primary center heartbeat is received, the central module to which the MPU unit belongs acts as a backup center module and broadcasts a normal heartbeat.
5. The data output system according to claim 1, characterized in that, Step S13 further includes: S131. If no lock is received, determine whether the master center heartbeat has been received.
6. The data output system according to claim 1, characterized in that, Step S14 further includes: S141. If the lock value is 0, determine whether the main center heartbeat has been received.
7. The data output system according to claim 1, characterized in that, If the arbitration module does not receive a normal heartbeat from the backup center module, an alarm for communication failure will be triggered.
8. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the program, it implements the data output system as described in any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the data output system as described in any one of claims 1 to 7.