Vehicle safety clock system based on time synchronization protocol
By introducing a vehicle-wide safety clock system based on a time synchronization protocol into the vehicle, the problems of long clock synchronization acquisition time, poor stability, limited accuracy and insufficient safety in the existing technology are solved, and high-precision, stable and safe vehicle clock synchronization is achieved.
Patent Information
- Application Number
- CN202510116481.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-01-24
AI Technical Summary
In the existing technology, vehicle clock synchronization has problems such as long acquisition time, susceptibility to interference, limited accuracy, and failure to consider functional safety and information security requirements.
A vehicle-wide safety clock system based on a time synchronization protocol is proposed. The system consists of a master node, slave nodes, and edge nodes. Each node includes a clock distribution module, a clock protection module, a clock synchronization module, and a clock configuration management module. The system ensures functional safety and information security through the clock protection module, synchronizes time references across the network through the clock synchronization module, and configures clock identities and priorities through the clock configuration management module.
It achieves high precision, stability and security of vehicle clock synchronization, can quickly switch clock sources, meet the requirements of functional safety and information security, and provide a time infrastructure that can operate in the event of a failure.
Smart Images

Figure CN119561642B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to time synchronization technology, and in particular to a vehicle safety clock system based on a time synchronization protocol. Background Art
[0002] In traditional vehicles, to achieve relatively accurate time accuracy, a controller (e.g., a remote communication terminal or intelligent driving controller) connected to a GNSS (Global Navigation Satellite System) receiver often serves as the vehicle's clock source for time broadcasting. For example, this involves periodic CAN synchronization messages or gPTP synchronization via the controller. However, this approach presents the following issues:
[0003] The acquisition time of the clock source is relatively long. A conventional cold start requires several processes including satellite search, capture, tracking, decoding, pseudorange measurement and positioning calculation. The whole process takes at least 30 seconds to 1 minute.
[0004] Clock source stability is susceptible to RF signal interruption and interference. For example, multipath effects such as driving into an underground parking lot, under an overpass, or near tall buildings can cause satellite signals to be reflected. This can cause timing interruptions or jumps in the GNSS clock source.
[0005] The accuracy of the clock source is limited. The GNSS clock is derived from the PPS signal in the receiver. While this can achieve nanosecond-level accuracy with no cumulative error, the GNSS receiver outputs UTC time as rising edges in whole seconds. This means that the clock accuracy for vehicle network synchronization is limited to seconds. This may not be possible for services that rely on smaller units for data fusion.
[0006] Simply applying the gPTP protocol for synchronization does not take into account the functional safety requirements of the synchronization process. If the clock synchronization process is affected by permanent hardware failure, random failure, or external interference, the clock system itself cannot notify other nodes through explicit fault markings to enter a safe state for related functions, nor can it provide a redundant backup clock that can operate in the event of a failure for a period of emergency operation.
[0007] The simple application of the gPTP protocol for synchronization does not take into account the information security requirements of the synchronization process, making the vehicle clock system message have anti-tampering and anti-replay mechanisms, unable to authenticate the clock source identity and corresponding authorization, unable to prevent middlemen from intercepting and deleting synchronization messages, or maliciously adding data delays to manipulate measurement messages to modify the vehicle synchronization time base. Summary of the Invention
[0008] In order to solve the deficiencies in the prior art, the present invention aims to provide a vehicle safety clock system based on a time synchronization protocol.
[0009] To achieve the purpose of the present invention, the technical solution adopted by the present invention is:
[0010] A vehicle safety clock system based on a time synchronization protocol, including a master node / backup master node, slave nodes, and boundary nodes. Each node includes a clock publishing module, a clock protection module, a clock synchronization module, and a clock configuration management module.
[0011] The clock publishing module publishes the corresponding clock reference and its functional safety status and information security status to other applications that require the clock reference;
[0012] The clock protection module protects the functional safety integrity and information security integrity status of the time base. When the corresponding integrity loss is diagnosed in the system, the module will issue a failure alarm or actively switch strategies;
[0013] The clock synchronization module obtains the configured clock source based on the clock identity configured in the clock configuration management module, switches the clock source according to the policy, and uses the time synchronization protocol to synchronize the time reference in the network;
[0014] The clock configuration management module configures other sub-module information, including the controller unique identifier, clock reference, clock source, clock source interface, clock acquisition mode, clock source priority, clock source switching threshold, clock source sampling period, target synchronization object, functional safety deviation threshold and functional safety deviation threshold, and redundant path key.
[0015] Furthermore, functional safety integrity protection includes: For nodes configured as system master nodes, backup master nodes, or boundary nodes, hardware fault diagnosis of the clock source is performed; for nodes configured as slave nodes, failure alarms and active redundant clock switching strategies are triggered when the clock deviation between the redundant path and the primary path reaches a configured threshold;
[0016] Information security integrity protection includes: authentication and authorization of clock identities in the network, prevention of middleman deception, integrity of redundant path and primary path protocol data packets, data availability and anti-replay protection, and receiving the configuration management module's configuration of redundant path clock deviation thresholds and primary path and redundant path keys.
[0017] Furthermore, two different in-vehicle clock references are defined: the vehicle business clock reference and the vehicle cumulative operation clock reference;
[0018] The vehicle's business clock reference is absolute time, which is obtained from high-precision time sources based on GNSS, NITZ, and NTP in the vehicle and is the same as the user's real time;
[0019] The vehicle's cumulative running clock benchmark is relative time. When the master clock controller node responsible for the vehicle's cumulative running clock enters working mode, timing begins. When the master clock controller node responsible for the vehicle's cumulative running clock enters sleep mode, timing stops, indicating the vehicle's cumulative running time.
[0020] Furthermore, for the clock deviation between the redundant path and the main path, the functional safety of the vehicle clock system is achieved. The clock slave node configures the source of the redundant clock path, uses a fully hardware redundant safety mechanism, or implements the decomposition of safety goals at the system architecture level through redundant application messages to avoid the overall clock synchronization violating the safety goals. When the clock slave node determines that the time base deviation value between the redundant path and the main path exceeds the set threshold, the corresponding clock slave node should enter the functional safety state.
[0021] Furthermore, information security integrity judgment and alarm are realized for the clock of the vehicle safety clock system by confirming the authenticity of the clock identity of each node; comparing the deviation of the time base of the redundant path and the main path from the node and implementing different information security measures for the redundant path and the main path.
[0022] Furthermore, the vehicle safety clock system determines and switches the clock source priority. The vehicle business clock master node has multiple clock sources at the same time. When the set conditions are met, the clock source is switched according to the configured priority and deviation value, including: the deviation between the new business clock source and the current business clock source exceeds X seconds; the new business clock source has the same or higher priority than the current business clock source.
[0023] Furthermore, the clock source hardware fault diagnosis of the vehicle safety clock system is carried out. The clock master node detects the hardware elements related to the correctness of the vehicle business clock and the vehicle cumulative clock during the system initialization phase and operation. If there is a fault in the clock hardware related to the vehicle business clock, the business clock master node determines that the current business clock is in a faulty state and sends a fixed value of time.
[0024] When the fault is judged to be mature, the current clock synchronization status needs to be marked as invalid, or in a fault silent state, and no time synchronization message will be generated; when the clock slave node sends a fault explicit flag through the master clock or the time synchronization message is judged to have timed out, it should be judged that the master clock fault is mature, and a new system clock synchronization should be started immediately from the universal master clock.
[0025] The beneficial effect of this invention lies in that, compared with the existing technology, it proposes a solution for defining and using different vehicle clock references within a centralized architecture for in-vehicle scenarios, providing specifications for the deployment and use of time-related functions within the vehicle. The solution for defining and coordinating in-vehicle clock references is integrated with the overall architecture design, and, based on typical business scenarios, demonstrates the system's flexible and adaptable configuration methods, enabling rapid multi-clock source configuration, clock source priority management, and switching strategies between different time sources.
[0026] The present invention proposes a standardized clock synchronization module for the entire vehicle, which can be quickly integrated and configured, and establishes a vehicle-wide clock synchronization mechanism that meets the security goals of functional safety and information security. It ensures that the clock system does not produce functional safety issues and handles the threat scenarios commonly faced by the vehicle-wide clock system, meets the functional requirements of failure-operation, and provides a reliable security environment and infrastructure. At the same time, it will not significantly reduce the synchronization accuracy and performance of the time synchronization system itself. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 Schematic diagram of the vehicle safety clock system based on the time synchronization protocol according to the present invention;
[0028] Figure 2 This is a conceptual diagram of the functional safety of the vehicle clock system. DETAILED DESCRIPTION
[0029] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings and embodiments. The following embodiments are only used to more clearly illustrate the technical solution of the present invention and are not intended to limit the scope of protection of this application.
[0030] like Figure 1 As shown, the vehicle safety clock system based on the time synchronization protocol described in the present invention is a flexibly deployable software standardized module that can adjust the clock identity according to the actual needs of the vehicle electronic architecture design, including master nodes / backup master nodes, slave nodes and boundary nodes. Regardless of the controller chip type, whether it is MCU (Microcontroller Unit) or SOC (System on Chip), it can be deployed on different nodes in the form of CDD (Complex Device Driver) files and software libraries.
[0031] In the vehicle's safety clock system, multiple time domains can be set up for time acquisition, timing distribution, and time synchronization management. Master and slave nodes for clock synchronization can be configured based on the characteristics of each clock reference, as well as different clock processing strategies. Backup master nodes can typically create redundant time domains identical to those of the master node to ensure real-time slave node failover in the event of a master node clock synchronization failure (slave nodes must receive time synchronization messages from both the master and backup master clocks). The time references between the master and backup master nodes are periodically aligned.
[0032] In the vehicle safety clock system, each node includes a clock release module, a clock protection module, a clock synchronization module, and a clock configuration management module. The functions of each sub-module are as follows:
[0033] Clock publishing module: Publishes the corresponding clock reference and the functional safety status and information security status of the clock reference to other applications that require the clock reference. If the node is configured as the system master node, backup master node or boundary node, the clock reference will also be published to the clock synchronization module and broadcast in the regional network in the form of a clock synchronization protocol.
[0034] Clock protection module: mainly protects the functional safety integrity and information security integrity status in the time base. When the corresponding integrity loss is diagnosed in the system, the system can use this module to issue a failure alarm or actively switch strategies.
[0035] Functional safety integrity protection includes: For nodes configured as system master nodes, backup master nodes, or boundary nodes, clock source hardware fault diagnosis (including initialization and periodic diagnosis) is performed. For nodes configured as slave nodes, failure alarms and active redundant clock switching strategies are triggered when the clock deviation between the redundant path and the primary path reaches a configured threshold.
[0036] The concept of information security integrity protection includes: authentication and authorization of clock identities in the network, prevention of middleman deception, integrity of redundant path and primary path protocol data packets, data availability and anti-replay protection, and receiving the configuration management module's configuration of redundant path clock deviation thresholds and primary path and redundant path keys.
[0037] Clock synchronization module: mainly obtains the configured clock source based on the clock identity configured in the clock configuration management module, switches the clock source according to the policy, and uses the time synchronization protocol to synchronize the time reference in the network.
[0038] Clock Configuration Management Module: Configures other submodules. The following information can be configured: controller unique identifier (UUID), clock reference (vehicle business clock or vehicle cumulative clock), clock source (PTP / RTC / GNSS / SYSTEM / NTP...), clock source interface, clock acquisition method (local or network), clock source priority, clock source switching (election) threshold, clock source sampling period, target synchronization object (local system clock / PTP or dedicated timer), functional safety deviation threshold and functional safety deviation threshold, and redundant path key configuration.
[0039] In order to standardize the clock reference for all possible vehicle-mounted scenarios, two different in-vehicle clock references are defined, namely the vehicle business clock reference and the vehicle cumulative operation clock reference.
[0040] The vehicle business clock benchmark refers to a classification based on the purpose and characteristics of the clock. It is absolute time and is obtained from high-precision time sources such as GNSS, NITZ (Network Identity and Time Zone, time information from operator base stations), and NTP (Network Time Protocol, from globally distributed high-precision time servers). It comes with user time zone information and is the same as the user's real-time time (wall clock).
[0041] Based on the characteristics of the vehicle business clock benchmark, it can be used in the following scenarios: it can be used for user clock display, it can be used as the time benchmark for freeze frame of vehicle electronic unit failure, it can be used as the time benchmark for recording global software logs, and it can be used as a task timer for vehicle collaboration.
[0042] The cumulative running clock benchmark of the entire vehicle is relative time. It starts timing when the master clock controller node responsible for the cumulative running clock of the entire vehicle enters the working mode, and stops timing when the master clock controller node responsible for the cumulative running clock of the entire vehicle enters sleep mode, indicating the cumulative running time of the vehicle. It is persistently stored by the master clock responsible for the cumulative running clock of the entire vehicle when it is in sleep mode, and will not start from zero when the vehicle starts.
[0043] Based on the cumulative operating clock benchmark characteristics of the entire vehicle, it can be used in the following scenarios: it can be used to coordinate the time base alignment of the entire vehicle's sensor sampling data and actuators, it can be used to coordinate the timing and execution synchronization of the entire vehicle's tasks, it can be used as a reference for the freshness of internal vehicle communication messages, it can be used for vehicle maintenance and repair, it can be used to evaluate the safety of autonomous driving systems, it can be used to evaluate scenarios related to vehicle usage frequency, and it can be used to evaluate the impact of vehicles on the environment.
[0044] For the clock deviation between redundant paths and main paths, the functional safety concept of the vehicle clock system is realized. The clock slave node configures the source of the redundant clock path, for example: the redundant clock path source is the clock synchronization message of the universal master clock or the redundant application message. Use a complete hardware redundant safety mechanism, or implement the decomposition of safety goals at the system architecture level through redundant application messages to avoid the overall clock synchronization from violating the safety goal (assuming that the safety goal is that the time base deviation of the whole vehicle synchronization exceeds a threshold that affects safety). Figure 2 The functional safety decomposition shown in the figure shows that even if the clock synchronization passes through a bridge node that cannot prove its safety integrity, or the module responsible for clock synchronization cannot prove its safety integrity, the safety integrity of the overall clock system will not be affected because the clock safety protection module establishes a redundant channel for secure clock synchronization through the redundant channel, thus being able to prove the safety integrity of the vehicle clock synchronization.
[0045] When the clock slave node determines that the time base deviation value between the redundant path and the main path exceeds the set threshold, the corresponding clock slave node should enter the safe state of functional safety.
[0046] For the vehicle safety clock system clock, information security integrity judgment and alarm are realized by confirming the authenticity of the clock identity of each node; comparing the deviation of the time base of the redundant path and the main path from the node and implementing different information security measures for the redundant path and the main path.
[0047] Clock authentication and authorization mechanisms are designed to prevent attackers from impersonating legitimate clocks, slave servers, or intermediate clocks by sending malicious messages to the master server. This could cause the master server to respond to legitimate clocks with protocol packets based on spoofed messages, resulting in an incorrect clock reference or the clock delay calculation being based on erroneous information, indirectly affecting the clock references of other systems. To prevent attackers from impersonating legitimate nodes in the vehicle service clock and modifying the vehicle service clock reference, the master node of the vehicle service clock should have a clock identity identification and authentication mechanism. Slave nodes can only synchronize their clocks after authenticating the master node and proving that they are legitimate master or backup master nodes. Authorization, on the other hand, verifies whether a peer clock is permitted to play its role in the protocol. For example, certain nodes may be permitted to become legitimate participating nodes in the clock synchronization system.
[0048] The vehicle's secure clock system prioritizes and switches clock sources. The vehicle's service clock master node (including backup master nodes) supports multiple clock sources. When specified conditions are met, the clock source switches based on the configured priority and offset. For example, if the deviation between the new service clock source and the current service clock source exceeds X seconds (including the clock offset calculation), the new service clock source has the same or higher priority than the current service clock source. This allows changes in lower-priority clock sources to remain unchanged without affecting the current service time, thus preventing frequent service clock changes.
[0049] Hardware fault diagnosis of the clock source of the vehicle safety clock system. The clock master node should detect the hardware elements related to the correctness of the vehicle business clock and the vehicle cumulative clock during the system initialization phase and operation. The detection content and detection cycle can be modified according to the configuration.
[0050] If the vehicle's business clock hardware fails, the business clock master node determines that the current business clock is in a faulty state and sends a fixed time value, such as 00:00 on January 1, 1970, and marks it as invalid. If the business time obtained by the clock protection module of the vehicle's business clock slave node is earlier than January 1, 2020, the current vehicle's business clock is determined to be untrustworthy.
[0051] When a fault is determined to be mature, the current clock synchronization status is marked as invalid or in a fault-silent state, with no further time synchronization messages. If the test type is "runtime cycle check," the fault diagnosis interval is periodic based on the configuration. If the test type is "initializing check," the fault diagnosis interval (FHTI) is performed once per vehicle "on-off" cycle.
[0052] When the clock slave node detects a fault dominant flag sent by the master clock or determines that the time synchronization message has timed out, it should determine that the master clock failure is mature and immediately start a new system clock synchronization from the universal master clock.
[0053] To ensure that the system time base does not switch repeatedly due to frequent master clock resets, after the current time base switches from the master clock to the universal master clock, the universal system master clock is always responsible for clock synchronization within the current working cycle (power off to on). If there is no subsequent hot backup clock source, some safety-related applications may need to operate in degraded mode (Emergency operation mode).
[0054] To enhance the security of the vehicle's clock system, the master clock node (including the service clock and accumulated running time) is determined by the configuration file deployed on each node, and does not require or can be dynamically elected. Before the entire vehicle system synchronizes its clocks, the key distribution center verifies the certificate ID or the clock service ID used in the region based on each node's predefined identity in the network. It then creates a communication ticket based on fixed identity information or a symmetric key dedicated to secure clock synchronization communication to protect the integrity of the clock synchronization protocol.
[0055] Comparing the time base deviation between the redundant path and the primary path means that, in addition to clock synchronization via gPTP, the vehicle clock master node also sends vehicle clock messages on the bus and uses application-layer integrity protection and freshness verification measures. Boundary clock nodes or clock slave nodes determine the deviation between the vehicle's service clock and its own synchronized system time. If any of the following conditions are met: the time in the message deviates from the currently synchronized service clock source by more than X seconds; or no message is received from the redundant path for more than X seconds, the clock protection module determines the clock status as CS Protection Status and notifies clock applications using the relevant clock base that the current clock is unsafe through the clock distribution module.
[0056] Implementing different information security measures for redundant paths and primary paths means using additional transport layer communication protection mechanisms for the primary path (for example, using hardware-supported MACSec or IPSec protocols). After the time synchronization message timestamp is generated, a tamper-proof check code (for example, HMAC) is generated based on the content. This helps calculate the protection and verification time during the communication process as the link delay time, thereby facilitating the time accuracy of the time synchronization network. Using application layer protection mechanisms for redundant paths, the tamper-proof check code and freshness value are placed in the application message for transmission. When the boundary clock node and the clock slave node receive the redundant path and primary path clock synchronization protocols, the clock protection module uses the tamper-proof check code and freshness information to verify whether the synchronized time stamp in the link has been tampered with or replayed. If it is determined to have been tampered with or replayed, the information security protection state is entered, and the clock publishing module notifies the upper-layer application that the current clock is unsafe.
[0057] The beneficial effect of the present invention is that, compared with the existing technology, the present invention provides a standardized software module for rapid integration of controller units in different hardware environments, reduces development workload, provides an open clock source selection strategy, and defines two different standard vehicle clock references, so that personnel who develop and design vehicle electronics and electrical systems can directly determine detailed designs such as master clock, slave clock deployment and priority through configuration.
[0058] The present invention provides high-functional safety vehicle clock synchronization, improving the safety integrity of business functions that rely on the clock foundation. At the same time, the system design describes a clock synchronization solution with fault tolerance, providing a time infrastructure that can operate despite failures.
[0059] The present invention provides high-performance vehicle clock synchronization that meets information security requirements, such as using relative clocks as FVs in secure communications or aligning task execution scheduling; and using absolute clocks to record security-related data or events, such as security logs, diagnostic freeze frames, and intelligent task reservations.
[0060] The design of the security mechanism adopted in the vehicle clock system of the present invention will not significantly reduce the quality of time transmission, especially the vehicle cumulative running time benchmark which is more sensitive to accuracy and performance.
[0061] The applicant of the present invention has made a detailed explanation and description of the implementation examples of the present invention in conjunction with the drawings in the specification. However, those skilled in the art should understand that the above implementation examples are only preferred implementation plans of the present invention, and the detailed description is only to help readers better understand the spirit of the present invention, and is not a limitation on the scope of protection of the present invention. On the contrary, any improvements or modifications based on the inventive spirit of the present invention should fall within the scope of protection of the present invention.
Claims
1. A vehicle safety clock system based on a time synchronization protocol, characterized in that: It includes master node / backup master node, slave node and boundary node. Each node includes clock release module, clock protection module, clock synchronization module and clock configuration management module. The clock publishing module publishes the corresponding clock reference and its functional safety status and information security status to other applications that require the clock reference; The clock protection module protects the functional safety integrity and information security integrity status of the time base. When the corresponding integrity loss is diagnosed in the system, the module will issue a failure alarm or actively switch strategies; The clock synchronization module obtains the configured clock source based on the clock identity configured in the clock configuration management module, switches the clock source according to the policy, and uses the time synchronization protocol to synchronize the time reference in the network; The clock configuration management module configures other sub-module information, including the controller unique identifier, clock reference, clock source, clock source interface, clock acquisition mode, clock source priority, clock source switching threshold, clock source sampling period, target synchronization object, functional safety deviation threshold and functional safety deviation threshold, and redundant path key; Functional safety integrity protection includes: For nodes configured as system master nodes, backup master nodes, or boundary nodes, hardware fault diagnosis of the clock source is performed; for nodes configured as slave nodes, failure alarms and active redundant clock switching strategies are triggered when the clock deviation between the redundant path and the primary path reaches the configured threshold; Information security integrity protection includes: authentication and authorization of clock identities in the network, prevention of middleman deception, integrity of redundant path and primary path protocol data packets, data availability and anti-replay protection, and receiving the configuration management module's configuration of redundant path clock deviation thresholds and primary path and redundant path keys.
2. The vehicle safety clock system based on the time synchronization protocol according to claim 1 is characterized in that: Define two different in-vehicle clock references: the vehicle business clock reference and the vehicle cumulative operation clock reference; The vehicle's business clock reference is absolute time, which is obtained from high-precision time sources based on GNSS, NITZ, and NTP in the vehicle and is the same as the user's real time; The vehicle's cumulative running clock benchmark is relative time. When the master clock controller node responsible for the vehicle's cumulative running clock enters working mode, timing begins. When the master clock controller node responsible for the vehicle's cumulative running clock enters sleep mode, timing stops, indicating the vehicle's cumulative running time.
3. The vehicle safety clock system based on the time synchronization protocol according to claim 1 is characterized in that: To achieve functional safety of the vehicle clock system due to clock deviation between redundant paths and main paths, the clock slave node configures the source of the redundant clock path, uses a fully hardware redundant safety mechanism, or implements the decomposition of safety goals at the system architecture level through redundant application messages to avoid overall clock synchronization violating safety goals. When the clock slave node determines that the time base deviation value between the redundant path and the main path exceeds the set threshold, the corresponding clock slave node should enter the functional safety state.
4. The vehicle safety clock system based on the time synchronization protocol according to claim 1 is characterized in that: For the vehicle safety clock system clock, information security integrity judgment and alarm are realized by confirming the authenticity of the clock identity of each node; comparing the deviation of the time base of the redundant path and the main path from the node and implementing different information security measures for the redundant path and the main path.
5. The vehicle safety clock system based on the time synchronization protocol according to claim 1 is characterized in that: The vehicle safety clock system determines and switches the clock source priority. The vehicle business clock master node has multiple clock sources at the same time. When the set conditions are met, the clock source is switched according to the configured priority and deviation value, including: the deviation between the new business clock source and the current business clock source exceeds X seconds; the new business clock source has the same or higher priority than the current business clock source.
6. The vehicle safety clock system based on the time synchronization protocol according to claim 1 is characterized in that: Hardware fault diagnosis of the vehicle safety clock system's clock source. The clock master node detects hardware elements related to the vehicle's business clock and the correctness of the vehicle's cumulative clock during system initialization and operation. If there is a fault in the vehicle's business clock-related clock hardware, the business clock master node determines that the current business clock is in a faulty state and sends a fixed time value. When the fault is determined to be mature, the current clock synchronization status needs to be marked as invalid, or in a fault silent state, and no time synchronization messages will be generated; When the clock slave node detects a fault dominant flag sent by the master clock or determines that the time synchronization message has timed out, it should determine that the master clock failure is mature and immediately start a new system clock synchronization from the universal master clock.
Citation Information
Patent Citations
Method, system and equipment for protecting rearrange
CN101378311A
System and method for synchronizing path redundancy based on gPTP clock
CN119052165A