A Clock Synchronization Method for a High-Reliability Triplicated Safety Control System
Through the method of processing time stamps by hardware logic units, the response time extension caused by clock inconsistency in triple-transformed security control system is solved, and high-precision time synchronization and system reliability and real-time performance are achieved.
Patent Information
- Application Number
- CN202510191976.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-02-21
AI Technical Summary
In the existing triple safety control system, inconsistent clocks of the controller lead to an extended response time, affecting the real-time and security of the system. It is easy to cause interrupt control when replacing the controller online, affecting the system security.
A high-confidence clock synchronization method is adopted to process time stamps through hardware logic units, reducing the uncertainty caused by software execution time and network delay, and improving the time synchronization accuracy. This method enters the initial synchronization state when the system is powered on, synchronizes the declaration frame and follow frame by sending and receiving the initial state, record the reception time, selects the system time based on the time selection logic, and provides a clock synchronization source and obtains clock data to update the system time in the normal synchronization state.
It significantly improves the accuracy of time synchronization, enhances the reliability and real-time of the system, supports online distraction-free replacement of controllers, simplifies the initialization process, reduces the risk of configuration errors, speeds up the system startup speed, avoids additional interruption control, and optimizes resource utilization and data exchange.
Smart Images

Figure CN119689965B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial automation control, and particularly to a clock synchronization method for a highly reliable triple modular redundant safety control system. Background Art
[0002] In the field of industrial automation control, the SIS system (Safety Instrumented System) is widely used in high-risk industries such as oil, gas, chemical, pharmaceutical, and power generation. By continuously monitoring the process status of potential hazards and taking measures to keep it within the safe operating range, the safety of personnel, assets, and the environment can be ensured. To meet the requirements of the SIL3 safety level, the SIS system usually adopts a triple modular redundant (multiple independent channels) design. After voting on the execution results of each channel, the final control output is obtained to ensure normal safety functions even in the case of one or several channel failures.
[0003] In the triple modular redundant design, a clock synchronization mechanism is used between each channel to ensure that their execution start and end times are consistent. The higher the synchronization accuracy between channels, the better the real-time responsiveness of the system. The triple modular redundant system supports online hot-swap in the case of a channel failure, and the newly replaced channel cannot affect the clocks of the channels in the normal operating state.
[0004] With the popularization of the SIS system, safety control systems have been used in many petrochemical plants. The safety control system has relatively high requirements for the response time to execute safety functions after a fault occurs at the site. If the response time is too long, the fault cannot be isolated in time, and even the fault may spread further. This safety hazard is not acceptable to users in high-risk industries.
[0005] Taking the controller in the current mainstream triple modular redundant control system as an example, there are three independent controllers in the triple modular redundant system. In each control cycle, each controller will perform the following processes: collect data of its own channel, obtain the data collected by the other two controllers, perform a voting process on the data collected by the three controllers, perform logical calculations on the voted data, output the result data, obtain the data calculated by the other two controllers, vote on the result data of the three channels, and output the voted data to the actuator. In these two processes of obtaining the collected data and the calculated result data of the other two controllers, the obtained values may be those of the previous cycle due to the inconsistent operating clocks of each controller, and the input value at the current moment will only be obtained in the next cycle. This will lead to an increase in the response time from input to output. In the worst case, the response time will be delayed to 4 times the control cycle. In such a case, many application scenarios cannot meet the requirements.
[0006] At present, the conventional solution is to connect to each controller through a hardware connection line. One of the multiple controllers is selected as the master clock server of the clock. The controller acting as the master clock server controls the level signal of this line according to the control period. Other controllers monitor the level change of this line through the interrupt reception method to achieve the purpose of periodic synchronization. Although there is a good synchronization effect in this solution, it introduces interrupt control, and in the SIS system, the less interrupt control, the better. At the same time, in the redundant system, online replacement of a certain controller is supported. When a certain controller needs to be replaced online, the plugging and unplugging process will inevitably affect the disturbance of the hardware connection line, which will in turn cause other controllers to have frequent interrupts, directly affecting the safety of the entire system. This risk cannot be accepted, so it needs to be improved. Summary of the Invention
[0007] In view of the deficiencies of the prior art, the present application provides a clock synchronization method for a highly reliable triple redundant safety control system, aiming to solve the above problems.
[0008] A clock synchronization method for a highly reliable triple redundant safety control system includes the following steps:
[0009] Step S1: When the system is powered on, each interconnected controller enters the initialization synchronization state. In the initialization synchronization state, it runs according to its own clock and periodically sends an initial state synchronization declaration frame and an initial state synchronization follow-up frame. When sending the initial state synchronization declaration frame, the hardware logic unit of the controller will save the sending time T1, and T1 is sent out together with the initial state follow-up frame.
[0010] Step S2: Each controller receives the initial state synchronization declaration frame and the initial state synchronization follow-up frame sent by the adjacent controller. When each controller receives the initial state declaration frames of two adjacent controllers, the hardware logic unit of the controller respectively records the received times T2 and T3. When each controller receives the initial state synchronization follow-up frame sent by the adjacent controller, the hardware logic unit of the controller respectively records the received times T4 and T5, and selects an appropriate time as its own system time based on these time information through the set time selection logic.
[0011] Step S3: Each controller switches from the initial synchronization state to the normal synchronization state. In the normal synchronization state, the controller provides a clock synchronization source to the adjacent system and obtains clock data from the adjacent system to update its own clock.
[0012] By adopting the above technical solution, the hardware logic unit processes the timestamp, reducing the uncertainty brought by software execution time and network latency, significantly improving the accuracy of time synchronization. The method adopts redundant design. Even if one or two controllers fail, the third controller can still maintain correct clock synchronization, enhancing the reliability of the system. And it supports online non-disruptive replacement of a certain channel, enabling maintenance or replacement without affecting other running channels, simplifying the initialization process, reducing the risk of configuration errors, and accelerating the system startup speed. In the normal synchronization state, the controller provides a clock synchronization source to adjacent systems and obtains clock data from adjacent systems to update its own clock, avoiding additional interrupt control, optimizing resource utilization, and ensuring efficient data exchange. In addition, the hardware state machine manages state transitions, ensuring accuracy and timeliness, and can ensure overall clock convergence through the reverse synchronization process in case of communication failures, increasing the flexibility and robustness of the system. It meets the extremely high requirements of the industry for real-time performance and security, promoting the stability and consistency of the entire system.
[0013] Optionally, the time selection logic set in step S2 is as follows:
[0014] When T2 ≥ T4 and T3 ≥ T5, if T2 - T4 ≥ T3 - T5, the system time of this controller is adjusted to T4, and the adjustment method is to subtract the value of (T2 - T4) from the current system time as the system time;
[0015] When T2 ≥ T4 and T3 ≥ T5, if T2 - T4 ≤ T3 - T5, the system time of this controller is adjusted to T5, and the adjustment method is to subtract the value of (T2 - T5) from the current system time as the system time;
[0016] When T2 ≥ T4 and T3 ≤ T5, the system time of this controller is adjusted to T4, and the adjustment method is to subtract the value of (T2 - T4) from the current system time as the system time;
[0017] When T2 ≤ T4 and T3 ≥ T5, the system time of this controller is adjusted to T5, and the adjustment method is to subtract the value of (T2 - T5) from the current system time as the system time;
[0018] When T2 ≤ T4 and T3 ≤ T5, the system time of this controller is not adjusted; each controller executes the above logic at least 3 times.
[0019] By adopting the above technical solution, this set time selection logic significantly improves the synchronization accuracy and the overall performance of the system in the triple modular safety control system. By comparing the received time and the transmitted timestamp and selecting the minimum time as the system time according to the predefined rules, this logic effectively reduces the time deviation caused by network latency and hardware differences, ensuring that all controllers can achieve time synchronization quickly and accurately. Each controller executes according to the above logic at least 3 times, accelerating the synchronization convergence speed of the entire system, while avoiding system oscillations caused by frequent adjustments, enhancing the stability and reliability of the system. This set of logic is not only applicable to ideal communication environments but also can flexibly handle complex actual working conditions, simplifying the system configuration and startup process and reducing the possibility of errors. By preferentially selecting earlier time sources, protecting the existing time, and flexibly handling mixed situations, it ensures that the time of all controllers remains consistent, promoting coordinated operation among multiple controllers.
[0020] Optionally, when the controller is in the initial synchronization state, if it receives a normal state synchronization declaration frame from an adjacent controller, it stops sending the initial state declaration frame and the initial state following frame to this adjacent controller and starts receiving the normal synchronization clock of this adjacent controller to complete the system time synchronization process.
[0021] By adopting the above technical solution, the synchronization speed is significantly accelerated. By quickly responding and switching to the normal synchronization state, the time required for the initialization phase is reduced; at the same time, it effectively reduces the network load, avoids unnecessary communication overhead, reduces the data traffic in the network, and improves the overall communication efficiency; more importantly, this mechanism prevents time conflicts, ensuring that all controllers are synchronized based on the latest and accurate time information, maintaining the stability and consistency of the system; in addition, the automated processing of the state transition logic simplifies the system management and configuration process, reduces the need for manual intervention, and reduces the risk of operation errors.
[0022] Optionally, step S3 specifically includes the following steps:
[0023] Step S3.1: Send a normal state synchronization declaration frame from the communication port of one controller to the corresponding communication port of the adjacent controller and record the transmission time M1;
[0024] Step S3.2: The adjacent controller receives the normal state synchronization declaration frame and saves and records the received time M2;
[0025] Step S3.3: The sending controller then sends a normal state synchronization following frame containing the timestamp M1 to the receiving controller;
[0026] Step S3.4: After receiving the synchronization following frame, the receiver controller saves the time M1 carried therein, the receiver controller sends a response frame to the sender controller, and records the time when the response frame is sent as M3;
[0027] Step S3.5: After receiving the response frame, the sender controller records the reception time as M4, and sends a synchronization completion frame with timestamp M4 to the receiver controller;
[0028] Step S3.6: The receiver controller saves the received time M4, calculates the clock deviation offset and transmission delay based on the four accurate timestamps M1, M2, M3, and M4, and adjusts its own system time.
[0029] By adopting the above technical solution, through precise timestamp exchange and calculation, the accuracy of clock synchronization is significantly improved, ensuring that all controllers achieve highly consistent time synchronization; by recording and exchanging four timestamps, and using this time information to calculate the clock deviation and transmission delay, the time error caused by network delay and hardware differences is effectively reduced; the entire synchronization process is efficient and orderly, reducing unnecessary communication overhead, accelerating the transition from initialization to normal synchronization state, and improving the startup efficiency of the system; at the same time, it avoids system oscillations caused by frequent time adjustments, ensuring the consistency and stability of clock synchronization; the automated processing of timestamp recording and synchronization logic reduces the need for manual intervention, reduces the risk of configuration errors, and simplifies the management and maintenance of the system; in addition, by directly processing key tasks such as timestamp generation and parsing through hardware logic, the need for software interrupts is reduced, the CPU load is reduced, and the system efficiency is improved.
[0030] Optionally, the calculation methods of the clock deviation offset and transmission delay in step S3.6 are as follows:
[0031] offset = ((M2 - M1) - (M4 - M3)) / 2;
[0032] delay = ((M2 - M1) + (M4 - M3)) / 2;
[0033] When offset + delay = 0, the receiver controller does not adjust the system time;
[0034] When offset + delay > 0, the receiver controller does not adjust the system time, and the receiver controller executes a clock synchronization process to the sender controller;
[0035] When offset + delay < 0, the receiver controller adjusts the system time to the value of the current system time minus (offset + delay).
[0036] By adopting the above technical solution, through precise calculation of clock deviation and transmission delay, this method can effectively reduce the time error caused by network latency and hardware differences, ensure highly consistent time synchronization for all controllers, and improve the overall accuracy of the system.
[0037] Optionally, each controller has two communication ports, respectively set as COM1 and COM2. The communication ports of each controller are connected end to end. During the periodic time synchronization process of the controller sending to adjacent controllers, the COM2 of the controller defaults to receiving the clock synchronization process of the adjacent controller. Only when offset + delay > 0, the controller will send a clock synchronization process to the adjacent controller from COM2.
[0038] By adopting the above technical solution, through clear communication port division of labor and conditional clock synchronization process, the efficiency, stability and resource utilization of the system are significantly improved; COM2 defaults to receiving the clock synchronization information of adjacent controllers, ensuring that all controllers can continuously receive the latest time data, maintaining high-precision time synchronization, while reducing unnecessary communication traffic and improving the utilization rate of network bandwidth; strictly controlling the trigger conditions of clock synchronization, preventing system oscillations caused by frequent time adjustments, enhancing the stability and reliability of the system, and being able to quickly respond to any potential time inconsistency problems.
[0039] Optionally, when the controller is in the normal synchronization state and receives the initial state synchronization declaration frame of the adjacent controller, the controller acts as a clock source to send a clock synchronization process to this adjacent controller.
[0040] By adopting the above technical solution, the response speed and consistency of the system are significantly improved, ensuring that new nodes or controllers after restart can quickly complete time synchronization, reducing the online time and maintaining the clock consistency of the entire system.
[0041] In summary, the present application includes at least one of the following beneficial technical effects:
[0042] 1. By processing timestamps through hardware logic units, the uncertainty caused by software execution time and network latency is reduced, significantly improving the accuracy of time synchronization. This method adopts redundant design. Even if one or two controllers fail, the third controller can still maintain correct clock synchronization, enhancing the reliability of the system. Moreover, it supports online non-disruptive replacement of a certain channel, enabling maintenance or replacement without affecting other running channels, simplifying the initialization process, reducing the risk of configuration errors, and accelerating the system startup speed. In the normal synchronization state, the controller provides a clock synchronization source to adjacent systems and obtains clock data from adjacent systems to update its own clock, avoiding additional interrupt control, optimizing resource utilization, and ensuring efficient data exchange. In addition, the hardware state machine manages state transitions, ensuring accuracy and timeliness, and can ensure overall clock convergence through the reverse synchronization process in case of communication failures, increasing the flexibility and robustness of the system. It meets the extremely high requirements of the industry for real-time and security, promoting the stability and consistency of the entire system.
[0043] 2. This set time selection logic significantly improves the synchronization accuracy and the overall performance of the system in a triple modular redundant safety control system. By comparing the received time and the sent timestamp and selecting the minimum time as the system time according to predefined rules, this logic effectively reduces the time deviation caused by network latency and hardware differences, ensuring that all controllers can achieve time synchronization quickly and accurately. Each controller executes according to the above logic at least 3 times, accelerating the synchronization convergence speed of the entire system and avoiding system oscillations caused by frequent adjustments, enhancing the stability and reliability of the system. This set of logic is not only applicable to ideal communication environments but can also flexibly handle complex actual working conditions, simplifying the system configuration and startup process and reducing the possibility of errors. By preferentially selecting earlier time sources, protecting the existing time, and flexibly handling mixed situations, it ensures that the time of all controllers remains consistent, promoting coordinated operation among multiple controllers.
[0044] 3. By means of precise timestamp exchange and calculation, the accuracy of clock synchronization is significantly improved, ensuring that all controllers achieve a highly consistent time synchronization. By recording and exchanging four timestamps and using this time information to calculate clock deviation and transmission delay, the time error caused by network latency and hardware differences is effectively reduced. The entire synchronization process is efficient and orderly, reducing unnecessary communication overhead, accelerating the transition from initialization to the normal synchronization state, and enhancing the startup efficiency of the system. At the same time, it avoids system oscillations caused by frequent time adjustments, ensuring the consistency and stability of clock synchronization. The automated processing of timestamp recording and synchronization logic reduces the need for manual intervention, lowers the risk of configuration errors, and simplifies the management and maintenance of the system. In addition, by directly processing key tasks such as timestamp generation and parsing through hardware logic, the need for software interrupts is reduced, the CPU load is lowered, and the system efficiency is improved.
[0045] 4. Through clear communication port division of labor and conditional clock synchronization processes, the efficiency, stability, and resource utilization of the system are significantly improved. COM2 is default set to receive clock synchronization information from adjacent controllers, ensuring that all controllers can continuously receive the latest time data, maintaining high-precision time synchronization, while reducing unnecessary communication traffic and improving the utilization rate of network bandwidth. Strictly controlling the triggering conditions of clock synchronization prevents system oscillations caused by frequent time adjustments, enhances the stability and reliability of the system, and can quickly respond to any potential time inconsistency issues. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 is a flowchart of an embodiment of the present application.
[0047] Figure 2 is a schematic diagram of the connection relationship of each controller in an embodiment of the present application.
[0048] Figure 3 is a schematic diagram of the process of step S3 in an embodiment of the present application.
[0049] Figure 4 is a schematic diagram of the connection relationship when a fault occurs in the connection between adjacent controllers in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] For ease of understanding the present application, the present application will be described in more detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that when an element is expressed as "fixed to" another element, it can be directly on the other element, or there can be one or more intermediate elements therebetween. When an element is expressed as "connected to" another element, it can be directly connected to the other element, or there can be one or more intermediate elements therebetween. The terms "vertical", "horizontal", "left", "right" and similar expressions used in this specification are for illustrative purposes only.
[0051] Unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. The term "and / or" used in this specification includes any and all combinations of one or more of the related listed items.
[0052] An embodiment of the present application discloses a clock synchronization method for a highly reliable triple redundant safety control system. Refer to Figure 1 and Figure 2, including the following steps: Step S1: When the system is powered on, each interconnected controller enters the initialization synchronization state. In the initialization synchronization state, it runs according to its own clock and periodically sends an initial state synchronization declaration frame and an initial state synchronization follow-up frame. When sending the initial state synchronization declaration frame, the hardware logic unit of the controller saves the sending time T1, and T1 is sent out together with the initial state follow-up frame; Step S2: Each controller receives the initial state synchronization declaration frame and the initial state synchronization follow-up frame sent by the adjacent controller. When each controller receives the initial state declaration frames of two adjacent controllers, the hardware logic unit of the controller records the received times T2 and T3 respectively. When each controller receives the initial state synchronization follow-up frame sent by the adjacent controller, the hardware logic unit of the controller records the received times T4 and T5 respectively, and selects an appropriate time as its own system time based on these time information through the set time selection logic; Step S3: Each controller switches from the initial synchronization state to the normal synchronization state. In the normal synchronization state, the controller provides a clock synchronization source to the adjacent system and obtains clock data from the adjacent system to update its own clock. By processing timestamps through the hardware logic unit, the uncertainty caused by software execution time and network latency is reduced, and the accuracy of time synchronization is significantly improved. This method adopts redundant design. Even if one or two controllers fail, the third controller can still maintain correct clock synchronization, enhancing the reliability of the system; and it supports online non-disruptive replacement of a certain channel, and can be maintained or replaced without affecting other running channels, simplifying the initialization process, reducing the risk of configuration errors, and accelerating the system startup speed. In the normal synchronization state, the controller provides a clock synchronization source to the adjacent system and obtains clock data from the adjacent system to update its own clock, avoiding additional interrupt control, optimizing resource utilization, and ensuring efficient data exchange at the same time; in addition, the hardware state machine manages state transitions, ensuring accuracy and timeliness, and can ensure overall clock convergence through the reverse synchronization process in case of communication failures, increasing the flexibility and robustness of the system; meeting the extremely high requirements of the industry for real-time and security, promoting the stability and consistency of the entire system.
[0053] Refer to Figure 1 and Figure 2, the time selection logic set in step S2 is as follows: When T2≥T4 and T3≥T5, if T2 - T4≥T3 - T5, the system time of this controller is adjusted to T4, and the adjustment method is to subtract the value of (T2 - T4) from the current system time as the system time; When T2≥T4 and T3≥T5, if T2 - T4≤T3 - T5, the system time of this controller is adjusted to T5, and the adjustment method is to subtract the value of (T2 - T5) from the current system time as the system time; When T2≥T4 and T3≤T5, the system time of this controller is adjusted to T4, and the adjustment method is to subtract the value of (T2 - T4) from the current system time as the system time; When T2≤T4 and T3≥T5, the system time of this controller is adjusted to T5, and the adjustment method is to subtract the value of (T2 - T5) from the current system time as the system time; When T2≤T4 and T3≤T5, the system time of this controller is not adjusted; Each controller executes the above logic 3 times, and the time of all controllers is the same as that of the controller with the smallest system time. This set time selection logic significantly improves the synchronization accuracy and the overall performance of the system in the triple modular redundant safety control system. By comparing the received time and the send timestamp and selecting the smallest time as the system time according to the predefined rules, this logic effectively reduces the time deviation caused by network latency and hardware differences, ensures that all controllers can achieve time synchronization quickly and accurately, speeds up the synchronization convergence speed of the entire system, and at the same time avoids system oscillation caused by frequent adjustment, enhancing the stability and reliability of the system. This set of logic is not only applicable to the ideal communication environment, but also can flexibly handle complex actual working conditions, simplifies the system configuration and startup process, and reduces the possibility of errors. By preferentially selecting earlier time sources, protecting the existing time, and flexibly handling mixed situations, it ensures that the time of all controllers remains consistent and promotes the coordinated operation between multiple controllers.
[0054] When the controller is in the initial synchronization state, if it receives a normal state synchronization declaration frame from an adjacent controller, it stops sending the initial state declaration frame and the initial state follow-up frame to this adjacent controller, and starts to receive the normal synchronization clock of this adjacent controller to complete the system time synchronization process. It significantly speeds up the synchronization speed, reduces the time required for the initialization phase by quickly responding and switching to the normal synchronization state; At the same time, it effectively reduces the network load, avoids unnecessary communication overhead, reduces the data traffic in the network, and improves the overall communication efficiency; More importantly, this mechanism prevents time conflicts, ensures that all controllers are synchronized based on the latest and accurate time information, and maintains the stability and consistency of the system; In addition, the automated processing of the state transition logic simplifies the system management and configuration process, reduces the need for manual intervention, and reduces the risk of operation errors.
[0055] Refer toFigure 1 , Figure 2 and Figure 3 , assume that the three controllers are controller A, controller B, and controller C respectively. Each controller has two communication ports, which are set as COM1 and COM2 respectively, and the communication ports of each controller are connected end to end. When the controller is in the normal synchronization state and receives the initial state synchronization declaration frame of the adjacent controller, the controller acts as a clock source and sends a clock synchronization process to this adjacent controller.
[0056] Referring to Figure 1 , Figure 2 and Figure 3 , step S3 specifically includes the following steps: Step S3.1: Send a normal state synchronization declaration frame through the communication port of a controller to the corresponding communication port of the adjacent controller, and record the sending time M1; Step S3.2: The adjacent controller receives the normal state synchronization declaration frame and saves and records the receiving time M2; Step S3.3: The sending controller then sends a normal state synchronization follow-up frame containing the timestamp M1 to the receiving controller; Step S3.4: After receiving the synchronization follow-up frame, the receiving controller saves the time M1 carried therein, the receiving controller sends a response frame to the sending controller, and records the moment of sending this response frame as M3; Step S3.5: After receiving the response frame, the sending controller records the receiving moment as M4, and sends a synchronization completion frame with the timestamp M4 to the receiving controller; Step S3.6: The receiving controller saves the received time M4, calculates the clock deviation offset and transmission delay based on the four accurate timestamps M1, M2, M3, and M4, and adjusts its own system time. Through the exchange and calculation of accurate timestamps, the accuracy of clock synchronization is significantly improved, ensuring that all controllers achieve highly consistent time synchronization; by recording and exchanging four timestamps and using this time information to calculate the clock deviation and transmission delay, the time error caused by network delay and hardware differences is effectively reduced; the entire synchronization process is efficient and orderly, reducing unnecessary communication overhead, accelerating the transition from initialization to the normal synchronization state, and improving the startup efficiency of the system; at the same time, it avoids system oscillations caused by frequent time adjustments, ensuring the consistency and stability of clock synchronization; the automated processing of timestamp recording and synchronization logic reduces the need for manual intervention, reduces the risk of configuration errors, and simplifies the management and maintenance of the system; in addition, by directly processing key tasks such as timestamp generation and parsing through hardware logic, the need for software interrupts is reduced, the CPU load is reduced, and the system efficiency is improved. The calculation methods of the clock deviation offset and transmission delay in step S3.6 are as follows:
[0057] offset = ((M2 - M1) - (M4 - M3)) / 2;
[0058] delay = ((M2 - M1)+(M4 - M3)) / 2;
[0059] When offset + delay = 0, the receiver controller does not adjust the system time;
[0060] When offset + delay > 0, the receiver controller does not adjust the system time, and the receiver controller performs a clock synchronization process to the sender controller once;
[0061] When offset + delay < 0, the receiver controller adjusts the system time to the value of the current system time minus (offset + delay). By accurately calculating the clock deviation and transmission delay, this method can effectively reduce the time error caused by network delay and hardware differences, ensure that all controllers achieve highly consistent time synchronization, and improve the overall accuracy of the system. During the periodic time synchronization process of the controller to the adjacent controller, the COM2 of the controller defaults to receiving the clock synchronization process of the adjacent controller. Only when offset + delay > 0, the controller will send a clock synchronization process to the adjacent controller from COM2.
[0062] Refer to Figure 1 、 Figure 2 and Figure 3 Taking the clock synchronization process from COM1 of controller A to COM2 of controller B as an example for illustration. First, COM1 of controller A sends a time normal state synchronization declaration frame to COM2 of controller B, and at the same time, the hardware logic unit saves the time of sending the declaration frame as M1. After controller B receives the normal synchronization declaration frame from controller A, the hardware logic unit saves the received time M2. Controller A sends a normal state synchronization follow-up frame with timestamp M1 to controller B. After controller B receives the normal state synchronization follow-up frame, it saves the time M1 carried in the data frame. After controller B receives the normal state synchronization follow-up frame, it sends a response frame to controller A, and the hardware logic unit saves the time M3 of sending the response frame. After controller A receives the response frame, the hardware logic unit saves the received moment as M4, and sends a synchronization completion frame with M4 timestamp to controller B. After controller A receives the synchronization completion frame, it saves the time M4.
[0063] Controller B can obtain the clock deviation offset and transmission delay with controller A through the four accurate timestamp information of M1, M2, M3, and M4. The calculation method is as follows:
[0064] offset = ((M2 - M1)-(M4 - M3)) / 2;
[0065] delay = ((M2 - M1)+(M4 - M3)) / 2;
[0066] When offset + delay = 0, Controller B does not adjust the system time.
[0067] When offset + delay > 0, Controller B does not adjust the system time, and Controller B performs a clock synchronization process to Controller A once.
[0068] When offset + delay < 0, Controller B adjusts the system time to the value of the current system time minus (offset + delay).
[0069] COM1 of each controller periodically sends a time synchronization process to the adjacent controller. COM2 defaults to receiving the clock synchronization process of the adjacent controller. Only when offset + delay > 0, the controller will send a clock synchronization process to the adjacent controller from COM2 once. When the controller's COM1 receives the clock synchronization frame from the adjacent controller, the controller adjusts the system time of this controller according to the method of calculating the synchronization time as described above, and leaves one cycle empty without obtaining the clock from COM2 to prevent clock synchronization oscillation.
[0070] Refer to Figure 2 、 Figure 3 and Figure 4 , in this way, it can also effectively solve the situation where the clock cannot converge when any two controllers in the triple modular redundant controller have communication failures. If there is a communication failure between Controller B and Controller C, Controller C cannot obtain the clock from Controller B. At this time, if the clock of Controller B is ahead of the clock of Controller A, then Controller A will synchronize the clock to Controller C in reverse once, so as to make the clock of the whole system converge to the minimum clock.
[0071] The implementation principle of the clock synchronization method for a highly reliable triple-redundancy safety control system in an embodiment of this application is as follows: By processing timestamps through a hardware logic unit, the uncertainty brought by software execution time and network latency is reduced, and the accuracy of time synchronization is significantly improved. This method adopts a redundant design. Even if one or two controllers fail, the third controller can still maintain correct clock synchronization, enhancing the reliability of the system. And it supports online non-disruptive replacement of a certain channel, enabling maintenance or replacement without affecting other running channels, simplifying the initialization process, reducing the risk of configuration errors, and accelerating the system startup speed. In the normal synchronization state, the controller provides a clock synchronization source to the adjacent system and obtains clock data from the adjacent system to update its own clock, avoiding additional interrupt control, optimizing resource utilization, and ensuring efficient data exchange. In addition, the hardware state machine manages state transitions, ensuring accuracy and timeliness, and can ensure overall clock convergence through a reverse synchronization process in case of communication failures, increasing the flexibility and robustness of the system. It meets the extremely high requirements of the industry for real-time performance and security, promoting the stability and consistency of the entire system.
[0072] The above are all preferred embodiments of this application. The protection scope of this application is not limited thereby. Therefore, any equivalent changes made according to the structure, shape, and principle of this application shall be covered within the protection scope of this application.
Claims
1. A clock synchronization method for a triple safety control system with high reliability, characterized in that: The following steps are involved: Step S1: When the system is powered on, each interconnected controller enters an initialization synchronization state, runs according to its own clock in the initialization synchronization state and periodically sends an initial state synchronization declaration frame and an initial state synchronization follow-up frame. When sending the initial state synchronization declaration frame, the hardware logic unit of the controller will save the sending time T1, and T1 is sent out together with the initial state follow-up frame; Step S2: Each controller receives the initial state synchronization declaration frame and the initial state synchronization follow frame sent by the adjacent controller. When each controller receives the initial state declaration frames from two adjacent controllers, the hardware logic unit of the controller records the receiving times T2 and T3 respectively. When each controller receives the initial state synchronization follow frame sent by the adjacent controller, the hardware logic unit of the controller records the receiving times T4 and T5 respectively, and selects the appropriate time as its own system time based on the time information through the set time selection logic; Step S3: Each controller switches from the initial synchronization state to the normal synchronization state. In the normal synchronization state, the controller provides a clock synchronization source to the adjacent system and obtains clock data from the adjacent system to update its own clock.
2. The clock synchronization method of a triple safety control system with high reliability according to claim 1 is characterized in that: The time selection logic set in step S2 is: When T2≥T4, T3≥T5, if T2-T4≥T3-T5, the system time of this controller is adjusted to T4. The adjustment method is to subtract (T2-T4) from the current system time as the system time; When T2≥T4, T3≥T5, if T2-T4≤T3-T5, the system time of this controller is adjusted to T5. The adjustment method is to subtract (T2-T5) from the current system time as the system time; When T2≥T4, T3≤T5, the system time of this controller is adjusted to T4. The adjustment method is to subtract (T2-T4) from the current system time as the system time; When T2≤T4, T3≥T5, the system time of this controller is adjusted to T5. The adjustment method is to subtract (T2-T5) from the current system time as the system time; When T2≤T4, T3≤T5, the system time of this controller will not be adjusted; each controller executes the above logic at least 3 times.
3. The clock synchronization method of a triple safety control system with high reliability according to claim 2 is characterized in that: When the controller is in the initial synchronization state, if it receives the normal state synchronization declaration frame from the adjacent controller, it stops sending the initial state declaration frame and the initial state follow frame to this adjacent controller, and starts receiving the normal synchronization clock of this adjacent controller to complete the synchronization process of the system time.
4. The clock synchronization method of a triple safety control system with high reliability according to claim 1 is characterized in that: Step S3 specifically includes the following steps: Step S3.1: Send a normal state synchronization declaration frame to the corresponding communication port of an adjacent controller through the communication port of one controller, and record the sending time M1; Step S3.2: The adjacent controller receives the normal state synchronization declaration frame and saves and records the reception time M2; Step S3.3: The sending controller then sends a normal state synchronization follow frame containing a timestamp M1 to the receiving controller; Step S3.4: After receiving the synchronization follow-up frame, the receiving controller saves the time M1 carried therein, and sends a response frame to the sending controller, and records the time of sending the response frame as M3; Step S3.5: After receiving the response frame, the sending controller records the receiving time as M4, and sends a synchronization completion frame with a timestamp of M4 to the receiving controller; Step S3.6: The receiving controller saves the received time M4, calculates the clock deviation offset and transmission delay delay based on the four precise timestamps M1, M2, M3 and M4, and adjusts its own system time.
5. The clock synchronization method of a triple safety control system with high reliability according to claim 4 is characterized in that: The clock deviation offset and transmission delay delay in step S3.6 are calculated as follows: offset = ((M2-M1)-(M4-M3)) / 2; delay=((M2-M1)+(M4-M3)) / 2; When offset+delay=0, the receiving controller does not adjust the system time; When offset+delay>0, the receiving controller does not adjust the system time, and the receiving controller performs a clock synchronization process with the sending controller; When offset+delay<0, the receiving controller adjusts the system time to the current system time minus (offset+delay).
6. The clock synchronization method of a triple safety control system with high reliability according to claim 5 is characterized in that: Each controller has two communication ports, which are set as COM1 and COM2. The communication ports of each controller are connected end to end. The controller periodically sends time synchronization to the adjacent controller. The controller's COM2 receives the clock synchronization process of the adjacent controller by default. Only when offset+delay >0, the controller will send a clock synchronization process from COM2 to the adjacent controller.
7. The clock synchronization method of a triple safety control system with high reliability according to claim 1 is characterized in that: When the controller is in the normal synchronization state and receives the initial state synchronization declaration frame from the adjacent controller, the controller acts as a clock source to send the clock synchronization process to the adjacent controller.
Citation Information
Patent Citations
Controller, multi-redundancy control system and synchronous control method thereof
CN103197978A
Synchronous communication method based on Ethernet
CN110492960A