Train dynamic redundancy switching system

CN119840691BActive Publication Date: 2026-09-08CRRC QINGDAO SIFANG ROLLING STOCK RESEARCH INSTITUTE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510234481.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2026-09-08
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

[0005]本申请实施例提供了一种列车动态冗余切换系统,以至少解决相关技术中静态冗余模式灵活度低,效率不高,且资源占用过多的问题

Benefits of technology

[0008]In some embodiments, the redundancy mode information includes multiple redundancy information, the processing core includes multiple cores, and multiple judgment threshold intervals are set in ascending order. When the error rate is within a judgment threshold interval, the safety manager activates the corresponding redundancy mode and generates redundancy information corresponding to the redundancy mode. At the same time, the selector opens one or more channels for the communication module to transmit train data to one or more cores corresponding to the redundancy information based on the received redundancy information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119840691B_ABST
    Figure CN119840691B_ABST
Patent Text Reader

Abstract

The application relates to a train dynamic redundancy switching system, which is connected with a train central control unit and comprises the following: a communication module configured to communicate with the train central control unit and receive train data; a processor comprising a processing core, which is configured to generate check information according to the train data; a safety manager configured to receive the check information, judge whether the check information is correct according to the check information, and obtain a judgment frequency and an error frequency; calculate the quotient of the error frequency and the judgment frequency to obtain a real-time error rate; switch a redundancy mode and generate redundancy mode information according to the real-time error rate and a judgment threshold; and a gate configured to control the opening or closing of a path through which the communication module transmits the train data to the processing core according to the redundancy mode information. Through the application, the problems of resource waste and work efficiency reduction of a traditional redundancy strategy in a high-speed rail control system are solved, the flexibility and work efficiency of redundancy switching are improved, and resource waste is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of high-speed rail control systems, and in particular to train dynamic redundancy switching systems. Background Technology

[0002] Currently, in order to correctly execute corresponding operations during train operation, it is necessary to judge whether the received instructions or data are correct and establish an appropriate fault-tolerant system to improve the train's fault tolerance rate and enhance its autonomous operation capability.

[0003] In existing technologies, fault-tolerant designs using traditional hardware are widely employed, with static redundancy strategies being particularly common. Static redundancy strategies include fixed dual-module redundancy or triple-module redundancy. During the operational period, regardless of the actual failure rate or the reliability requirements of the train's operating environment, the internal modules of dual-module and triple-module redundancy remain operational.

[0004] However, when existing technologies are applied to high-speed rail control systems, which have dynamic workloads and variable reliability requirements, there are significant problems of resource waste and efficiency reduction. Summary of the Invention

[0005] This application provides a train dynamic redundancy switching system to at least solve the problems of low flexibility, low efficiency, and excessive resource consumption in the static redundancy mode in related technologies.

[0006] In a first aspect, embodiments of this application provide a train dynamic redundancy switching system, the switching system being connected to the train central control unit, comprising: The communication module is configured to communicate with the train's central control unit and receive train data. The processor includes a processing core configured to generate verification information based on train data. The security manager is configured to receive verification information, determine whether the verification information is correct based on the verification information, and obtain the number of judgments and the number of errors; calculate the quotient of the number of errors and the number of judgments to obtain the real-time error rate; and switch the redundancy mode and generate redundancy mode information based on the real-time error rate and the judgment threshold. The selector is configured to control the opening or closing of the communication module's path for transmitting train data to the processing core, based on redundancy mode information.

[0007] The system switches between redundancy modes in real time based on train data to improve system reliability, stability, and response speed.

[0008] In some embodiments, the redundancy mode information includes multiple redundancy information, the processing core includes multiple cores, and multiple judgment threshold intervals are set in ascending order. When the error rate is within a judgment threshold interval, the safety manager activates the corresponding redundancy mode and generates redundancy information corresponding to the redundancy mode. At the same time, the selector opens one or more channels for the communication module to transmit train data to one or more cores corresponding to the redundancy information based on the received redundancy information.

[0009] By precisely controlling the data path based on redundancy mode information, the effectiveness and real-time nature of redundancy switching can be ensured, thereby improving system stability.

[0010] In some embodiments, the multiple cores include a first core, a second core, and a third core, and the gating is further configured to: When the redundancy mode information is the first redundancy information, the communication module is opened to transmit train data to the first core. When the redundancy mode information is the second redundancy information, the communication module is opened to transmit train data to the first core and the second core. When the redundancy mode information is the third redundancy information, the communication module is enabled to transmit train data to the first core, the second core, and the third core.

[0011] By progressively increasing the number of cores, data processing capabilities are further improved, and the redundancy and reliability of the system are enhanced.

[0012] In some embodiments, the security manager is further configured to: receive the verification information of a core in a redundant mode corresponding to the core, verify whether the verification information is correct, and if not, accumulate the error count and recalculate the error rate.

[0013] The security manager continuously verifies the core verification information and automatically handles errors when they occur, effectively improving the stability and reliability of the system.

[0014] In some embodiments, it also includes: The interrupt controller is configured to receive interrupt information and redundancy mode information, and send the interrupt information to the core corresponding to the redundancy mode information.

[0015] By implementing real-time monitoring and interruption control, system resources can be avoided and rapid responses can be made at critical moments.

[0016] In some embodiments, it also includes: The clock manager is configured to receive redundancy mode information and control the startup of the core corresponding to that redundancy mode information.

[0017] By controlling the clock manager, it is ensured that each core starts at the appropriate time, avoiding system instability caused by timing errors.

[0018] In some embodiments, it also includes: The reset manager is configured to control the processor reset when the error rate equals the fourth judgment threshold.

[0019] This ensures that if the error rate is too high, the system can be reinitialized to restore normal operation.

[0020] In some embodiments, it also includes: The memory controller is configured to receive and store correct data sent by the security manager if the verification information is correct in the security manager.

[0021] When the security manager verifies that the verification information is correct, the memory controller receives and stores this data to ensure the accuracy and durability of the data and to prevent data loss or errors.

[0022] In some embodiments, it also includes: The information acquisition module is configured to acquire the train's real-time operating status and the type of task it is currently performing. The control module is configured to switch to redundancy mode according to preset rules based on the train's real-time operating status and the type of task it is performing.

[0023] By acquiring the train's operating status in real time, the control module can adjust the redundancy mode according to the actual situation, thereby improving the system's intelligence level.

[0024] In some embodiments, it also includes: The comparison module is configured to determine whether the redundancy mode level of the safety manager switching is higher than the redundancy mode level of the control module switching. If so, the train is controlled to execute the redundancy mode of the control module switching; otherwise, the train is controlled to execute the redundancy mode of the safety manager switching.

[0025] Through the comparison mechanism of the comparison module, the system can flexibly select the most suitable redundancy mode according to the level of different redundancy modes, thereby improving fault tolerance.

[0026] Compared to related technologies, the train dynamic redundancy switching system provided in this application analyzes the error rate, the type of task received by the train, and the real-time working status of the train to execute the corresponding redundancy mode and can dynamically switch the redundancy mode. This solves the problem of resource waste and reduced work efficiency of traditional redundancy strategies in application scenarios such as high-speed rail control systems with dynamic workloads and variable reliability requirements. It improves the flexibility of redundancy switching, increases work efficiency, and reduces resource waste.

[0027] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description

[0028] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a structural block diagram of a train dynamic redundancy switching system according to an embodiment of this application; Figure 2 This is a flowchart of the train dynamic redundancy switching system switching redundancy mode according to an embodiment of this application; Figure 3 This is a flowchart of the train dynamic redundancy switching system switching redundancy mode according to an embodiment of this application; Figure 4 This is a structural block diagram of a train dynamic redundancy switching system according to an embodiment of this application; Figure 5 This is a structural block diagram of the processor in the train dynamic redundancy switching system according to an embodiment of this application.

[0029] In the picture: 101. Train Central Control Unit; 102. Communication Module; 103. Processor; 104. Safety Manager; 105. Selector; 401. Interrupt controller; 402. Clock controller; 403. Reset manager; 404. Memory controller; 405. On-chip memory unit; 406. DDR memory unit; 407. GPIO controller; 408. Timer; 409. GPIO pin; 410. Other peripheral controller; 411. Other peripherals; 501, the first core; 502, the second core; 503, the third core. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of this application clearer, the application is described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.

[0031] Obviously, the accompanying drawings described below are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar scenarios based on these drawings without any inventive effort. Furthermore, it is understood that although the efforts made in this development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, any changes to design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as insufficient disclosure of the content of this application.

[0032] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.

[0033] Unless otherwise defined, the technical or scientific terms used in this application shall have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms “a,” “an,” “an,” “the,” and similar words used in this application do not indicate quantity limitation and may indicate singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units not listed, or may include other steps or units inherent to these processes, methods, products, or devices. The terms “connected,” “linked,” “coupled,” and similar words used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. “Multiple” used in this application refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following objects are in an "or" relationship. The terms "first," "second," and "third" used in this application are merely to distinguish similar objects and do not represent a specific ordering of the objects.

[0034] In traditional hardware fault-tolerant design, static redundancy is widely used to improve system reliability. However, such redundant systems suffer from significant resource waste and efficiency degradation, especially in application scenarios like high-speed rail control systems, which have dynamic workloads and varying reliability requirements.

[0035] In static redundancy mode, all modules are always in operation regardless of the actual failure rate and the reliability requirements of the train operating environment. This results in low flexibility and occupies most of the resources, leading to resource waste.

[0036] To address the aforementioned issues, this embodiment provides a train dynamic redundancy switching system. Figure 1 This is a structural block diagram of a train dynamic redundancy switching system according to an embodiment of this application, such as... Figure 1 As shown, the switching system is connected to the train's central control unit 101, and the switching system includes: Communication module 102 is configured to communicate with the train central control unit 101 and receive train data. Processor 103 includes a processing core configured to generate verification information based on train data. Security Manager 104 is configured to receive verification information, determine whether the verification information is correct based on the verification information, and obtain the number of judgments and the number of errors; calculate the quotient of the number of errors and the number of judgments to obtain the real-time error rate; and switch the redundancy mode and generate redundancy mode information based on the real-time error rate and the judgment threshold. The selector 105 is configured to control the communication module 102 to open or close the path for transmitting train data to the processing core based on redundancy mode information.

[0037] This embodiment utilizes the communication module 102 to establish data communication with the train central control unit 101 and transmits the received train data to the processor 103. The processing core in the processor 103 parses the data and generates verification information according to a preset algorithm. The safety manager 104 receives the verification information and verifies it to determine the correctness of the data. Using the safety manager 104 for real-time monitoring can effectively reduce the risk of system failure and ensure the safety of train operation.

[0038] During the judgment process, the security manager 104 counts the number of errors and judgments, and calculates the real-time error rate. This error rate is compared with a preset judgment threshold, and based on this, it determines whether to perform a redundancy mode switch. This allows for timely judgment of whether the system needs to perform a redundancy mode switch, improving the system's intelligence level.

[0039] The selector 105 controls the data transmission path of the communication module 102 based on the redundancy mode information generated by the safety manager 104, so as to ensure that the train data is transmitted to the correct processing core, thereby realizing dynamic redundancy switching and improving the system's reliability, stability and system response speed.

[0040] The redundancy mode information includes multiple redundancy information points, and the processing core includes multiple cores. Multiple progressively increasing judgment threshold intervals are set. When the error rate falls within a certain threshold interval, the safety manager activates the corresponding redundancy mode and generates redundancy information corresponding to that mode. Simultaneously, the selector, based on the received redundancy information, opens one or more communication modules to transmit train data to one or more cores corresponding to that redundancy information.

[0041] The redundancy mode information includes first redundancy information, second redundancy information, and third redundancy information, and the processing core includes multiple cores. When the error rate is higher than a first judgment threshold but lower than a second judgment threshold, the safety manager 104 activates the first redundancy mode and generates first redundancy information; when the error rate is higher than the second judgment threshold but lower than a third judgment threshold, the safety manager 104 activates the second redundancy mode and generates second redundancy information; when the error rate is higher than the third judgment threshold but lower than a fourth judgment threshold, the safety manager 104 activates the third redundancy mode and generates third redundancy information. Simultaneously, the selector 105, based on the received redundancy mode information, opens multiple paths for the communication module 102 to transmit train data to one or more cores corresponding to the redundancy mode information.

[0042] In this implementation, when a change in error rate is detected, the redundancy mode is dynamically adjusted based on multiple preset judgment thresholds. When the error rate exceeds a certain threshold, the security manager 104 generates corresponding redundancy mode information to improve the system's fault tolerance.

[0043] By employing a tiered redundancy mechanism, the system's adaptability is improved, enabling it to select appropriate redundancy modes based on different error rates, avoiding excessive or insufficient redundancy switching. The selector 105 can precisely control the data path based on redundancy mode information, ensuring the effectiveness and real-time nature of redundancy switching and improving system stability.

[0044] Figure 2 A flowchart illustrating the switching of redundancy modes in a train dynamic redundancy switching system. (Example) Figure 2As shown, the first redundancy mode is SMR mode, the second redundancy mode is DMR mode, and the third redundancy mode is TMR mode. The redundancy level of SMR, DMR, and TMR modes gradually increases. The first judgment threshold can be set to 0. The second judgment threshold can be set to 50%. The third judgment threshold can be set to 80%. The fourth judgment threshold can be set to 100%. During the initial operation of the train dynamic redundancy switching system, the switching system is in SMR mode. It is determined whether the error rate calculated by the safety manager 104 is greater than 50%. If not, the SMR mode is maintained; if so, it is upgraded to DMR level. After the switching system enters DMR mode, it is determined whether the error rate calculated by the safety manager 104 is greater than 80%. If so, it is upgraded to TMR mode; if not, it is further determined whether the error rate is less than 50%. If so, the switching system is adjusted to SMR mode; if the error rate is greater than 50% but less than 80%, the DMR mode is maintained. After the switching system enters TMR mode, it determines whether the error rate calculated by the security manager 104 is greater than or equal to 100%. If so, the reset manager 403 resets the switching system. If not, it further determines whether the error rate is less than 80%. If so, the switching system is adjusted to DMR mode. If not, it remains in TMR mode.

[0045] In some of these embodiments, such as Figure 5 As shown, the multiple cores include a first core 501, a second core 502, and a third core 503, and the selector 105 is further configured as follows: When the redundancy mode information is the first redundancy information, the communication module 102 is opened to transmit train data to the first core 501.

[0046] When the redundancy mode information is the second redundancy information, the communication module 102 is opened to transmit train data to the first core 501 and the second core 502.

[0047] When the redundancy mode information is the third redundancy information, the communication module 102 is opened to transmit train data to the first core 501, the second core 502 and the third core 503.

[0048] After the safety manager 104 adjusts the redundancy mode according to the error rate, the selector 105 controls the data channel, enabling train data to be transmitted to different numbers of cores to enhance the system's redundancy and reduce the impact of single-point failures. By progressively increasing the number of cores, the data processing capability is further improved, enhancing the system's redundancy and reliability. When a single core fails, data can be transmitted to multiple cores, ensuring continuous system operation and improving fault tolerance.

[0049] Multiple cores can be RISC-V (Reduced Instruction Set Computer - Five) cores.

[0050] In some embodiments, the security manager 104 is further configured to: receive the verification information of a core in a redundant mode corresponding to the core, verify whether the verification information is correct, and if not, accumulate the error count and recalculate the error rate.

[0051] In the redundancy mode of each core, the security manager 104 receives verification information from that core and determines whether the information matches the predetermined data. If the verification information is incorrect, the error count is incremented, the real-time error rate is recalculated, and the stability of that core continues to be monitored. This process ensures that the system continuously detects and responds to potential faults during real-time operation. The security manager 104 continuously verifies the core's verification information and automatically handles errors when they occur, effectively improving the stability and reliability of the system.

[0052] In some embodiments, when the first redundancy mode is started and the first redundancy information is generated, the verification information of the first core 501 is received, and the verification information of the first core 501 is verified to be correct. If not, the error count is increased by one, and the error rate is calculated again.

[0053] In some embodiments, when the second redundancy mode is activated and the second redundancy information is generated, the verification information of the first core 501 and the second core 502 are received respectively, and it is determined whether the verification information of the first core 501 and the verification information of the second core 502 are the same. If not, the error count is increased by one, and the error rate is calculated again.

[0054] In some embodiments, when the third redundancy mode is activated and the third redundancy information is generated, the verification information of the first core 501, the second core 502 and the third core 503 are received respectively, and it is determined whether the verification information of the first core 501, the second core 502 and the third core 503 are all different. If so, the error count is increased by one, and the error rate is calculated again.

[0055] The error rate is calculated as follows: Error rate = Number of errors / Total execution cycles.

[0056] In some embodiments, the BCH (Bose-Chaudhuri-Hocquenghem Code) is used as the error correction code (ECC) mechanism. ECC hardware logic is integrated within the switching system, enabling rapid generation of check bits during the operation of the first core 501, second core 502, and third core 503. After receiving the computational logic from multiple cores, the security manager 104 directly verifies the data transmitted and the accompanying ECC bits.

[0057] In some of these embodiments, such as Figure 4 As shown, the switching system also includes an interrupt controller 401, which is configured to receive interrupt information and redundancy mode information, and send the interrupt information to the core corresponding to the redundancy mode information.

[0058] Upon receiving redundancy mode information, the interrupt controller 401 triggers a corresponding interrupt operation based on that information. By dynamically monitoring and switching the redundancy modes of each core, when a specific error or abnormal situation is detected, the interrupt controller 401 immediately sends an interrupt signal to the relevant core, instructing it to perform necessary self-checks or recovery operations. This interrupt mechanism enables the system to be interrupted promptly and handle necessary situations in the event of unexpected events, ensuring that the train system is not affected. Real-time monitoring and interrupt control prevent waste of system resources and allow for rapid response at critical moments.

[0059] In some embodiments, when the redundancy mode information is the first redundancy information, the interrupt information is sent to the first core 501.

[0060] In some embodiments, when the redundancy mode information is the second redundancy information, some interrupt information is sent to the first core 501, and the remaining interrupt information is sent to the second core 502.

[0061] In some embodiments, when the redundancy mode information is third redundancy information, a portion of the interrupt information is sent to the first core 501, a portion of the interrupt information is sent to the second core 502, and the remaining interrupt information is sent to the third core 503. In some of these embodiments, such as Figure 4 As shown, the switching system also includes a clock manager, configured to receive redundancy mode information and control the startup of the core corresponding to the redundancy mode information.

[0062] Based on redundancy mode information, the clock manager automatically adjusts the startup order and timing of each core in the system. For each redundancy mode, the clock manager controls the startup timing of the relevant cores to ensure that the cores can work collaboratively in different redundancy modes, maximizing processing efficiency and ensuring smooth system operation under different working conditions. Through the control of the clock manager, it ensures that each core starts at the appropriate time, avoiding system instability caused by timing errors.

[0063] In some embodiments, when the redundancy mode information is the first redundancy information, the first core 501 is controlled to be turned on.

[0064] In some embodiments, when the redundancy mode information is the second redundancy information, both the first core 501 and the second core 502 are enabled.

[0065] In some embodiments, when the redundancy mode information is the third redundancy information, the first core 501, the second core 502, and the third core 503 are all enabled.

[0066] In practical applications, after power-on, the switching system defaults to SMR mode. Clock controller 402 provides a standard clock to the first core 501, while the second core 502 and third core 503 do not. Therefore, the first core 501 operates normally, while the second core 502 and third core 503 are in a disabled state and do not operate. Selector 105 opens the data transmission channel between the first core 501 and the communication module 102. Interrupt controller 401 sends all interrupt information generated by peripherals to the first core 501.

[0067] In SMR mode, the security manager 104 uses an error correction code mechanism to verify the logical operation results of the first core 501. When a verification error occurs, it increments the error counter by 1 and calculates the error rate.

[0068] When the error rate is below 50%, the redundancy mode remains unchanged; when the error rate is between 50% and 80%, the security manager 104 adjusts the redundancy mode to DMR mode.

[0069] In DMR mode, clock controller 402 provides a normal clock to the second core 502, while the other cores remain unchanged. Selector 105 enables data transmission channels between the first core 501, the second core 502, and communication module 102. Interrupt controller 401 migrates some interrupt information from the first core 501 to the second core 502, reducing the load on the first core 501.

[0070] In DMR mode, the security manager 104 receives the logical operation results from the first core 501 and the second core 502. After verification, it compares the two sets of data. If the data matches, it sends the data to the memory manager. If the data does not match, the error count is incremented by 1, and the error rate is calculated in real time.

[0071] When the error rate reaches 80% or higher, the security manager 104 switches the redundancy mode to TMR mode. If the error rate gradually decreases to below 50%, the security manager 104 switches the redundancy mode back to SMR mode.

[0072] When switching back to SMR mode, the security manager 104 notifies the interrupt controller 401 to migrate the interrupt information located in the second core 502 to the first core 501, and then notifies the selector 105 to close the data transmission channel between the second core 502 and the communication module 102. After completion, the clock controller 402 is notified to turn off the clock of the second core 502, so that the second core 502 is in the off state.

[0073] In TMR mode, the clock controller 402 provides normal clocks for the first core 501, the second core 502, and the third core 503. The selector 105 opens all channels for data transmission between the first core 501, the second core 502, and the third core 503 and the communication module 102. The interrupt controller 401 redistributes all interrupt information evenly to the first core 501, the second core 502, and the third core 503.

[0074] In TMR mode, the security manager 104 will receive the logical operation results from the first core 501, the second core 502 and the third core 503. After verification, the data of the three cores will be compared. If two of them are the same, the data will be taken as the correct data and sent to the memory controller 404. If the data of the three cores are completely different, the error count will be incremented by 1 and the error rate will be calculated in real time.

[0075] If the error rate is greater than or equal to 100%, the security manager 104 will notify the reset manager 403 to perform a system-wide reset. If the error rate gradually decreases to below 80%, the security manager 104 will switch the redundancy mode back to DMR mode.

[0076] Switching back to DMR mode, the security manager 104 notifies the interrupt controller 401 to migrate the interrupt information located in the third core 503 to the first core 501 and the second core 502, and then notifies the selector 105 to close the data transmission channel between the third core 503 and the communication module 102. After completion, the clock controller 402 is notified to turn off the clock of the third core 503, so that the third core 503 is in the off state.

[0077] In some of these embodiments, such as Figure 4 As shown, the switching system also includes a reset manager 403, configured to control the processor 103 to reset when the error rate is equal to the fourth judgment threshold.

[0078] The reset manager 403 monitors the system's error rate in real time. Once the error rate reaches or exceeds the fourth judgment threshold, the reset manager 403 immediately triggers a reset operation on the processor 103. This ensures that the system can be reinitialized to restore normal operation in the event of an excessively high error rate. Timely reset when the system error rate is too high can prevent the fault from spreading and protect the overall stability of the system. The automatic reset function allows for rapid system recovery without manual intervention, reducing troubleshooting time.

[0079] In some of these embodiments, such as Figure 4 As shown, the switching system also includes a memory controller 404, which is configured to receive and store the correct data sent by the security manager 104 if the verification information is correct in the security manager 104.

[0080] When the security manager 104 verifies that the checksum information is correct, the memory controller 404 receives and stores this data to ensure its accuracy and durability, preventing data loss or errors. This data can be used for further analysis or recovery operations in subsequent processing, ensuring data integrity during long-term system operation and enabling rapid reconstruction of the operating state during fault recovery, reducing recovery time.

[0081] In some embodiments, the switching system further includes an information acquisition module configured to acquire the real-time operating status of the train and the type of task it is performing.

[0082] The control module is configured to switch to redundancy mode according to preset rules based on the train's real-time operating status and the type of task it is performing.

[0083] The information acquisition module monitors the train's operating status in real time and acquires information based on the train's task type, transmitting it to the control module. The control module dynamically selects and switches redundancy modes based on this information and preset rules to optimize the train system's operating efficiency. By acquiring the train's operating status in real time, the control module can adjust the redundancy mode according to actual conditions, improving the system's intelligence level. Flexible switching of redundancy modes based on task type helps optimize system resource utilization and avoid unnecessary redundant consumption.

[0084] In some embodiments, the switching system further includes a comparison module configured to determine whether the level of the redundancy mode switched by the safety manager 104 is higher than the level of the redundancy mode switched by the control module; if so, the train is controlled to execute the redundancy mode switched by the control module; if not, the train is controlled to execute the redundancy mode switched by the safety manager 104.

[0085] The comparison module compares the redundancy mode levels selected by the safety manager 104 and the control module to determine which mode is more suitable. If the redundancy mode level selected by the safety manager 104 is higher, the selection by the safety manager 104 is executed first; otherwise, the redundancy mode selected by the control module is executed to ensure that the system operates according to the highest level of redundancy. Through the comparison mechanism of the comparison module, the system can flexibly select the most suitable redundancy mode according to different redundancy levels, improving fault tolerance. Selecting a more efficient redundancy mode according to actual conditions helps to improve the working efficiency and safety of the train system.

[0086] like Figure 3 As shown, the switching system is adapted to software. After startup, the switching system enters the default SMR mode, and the software acquires the train's current operating status and task type in real time. The train's current operating status includes, but is not limited to: starting phase, acceleration phase, constant speed operation phase, deceleration or braking phase, stopping and standby phase, etc. Task types include, but are not limited to, data reception, data parsing, and data output. In data reception, the switching system can receive speed signals and braking signals. In data output, the system can output switch control and pantograph raising / lowering information.

[0087] The current software determines whether the SMR mode meets the conditions based on the train's current working status or task type.

[0088] For example, SMR mode can be selected during train stops or constant speed phases. During train acceleration, where the error rate is lower but real-time performance is critical, DMR mode can be selected. During train braking, where the highest reliability is required, TMR mode is used.

[0089] For example, data reception and transmission, and emergency braking tasks require the highest level of redundancy, so the TMR mode is selected to ensure the reliability of train operation.

[0090] If the conditions are met, the SMR mode is maintained. If not, the software retrieves the real-time redundancy mode of the processor 103 from the security manager 104.

[0091] If the acquired redundancy level meets the current working state and task type, the software updates its own redundancy level parameters. If the current hardware redundancy level does not meet the requirements, the software will issue a higher-level redundancy mechanism mode. For example, initially, the software maintains SMR mode. If the software needs to upgrade to DMR mode, but the hardware is currently in TMR mode, it can switch to DMR if the error rate is below 80%, and remain unchanged if the error rate is above 80%.

[0092] When the software determines that the current working status and task type are compatible with a lower level of redundancy mode, it will issue a redundancy mode of a lower level than the current redundancy mode.

[0093] To prevent conflicts between the redundancy mode adjusted by the switching system based on the error rate and the redundancy mode adjusted by software commands, and to ensure system reliability and security, the following conditions are set: If the redundancy mode level issued by the software is lower than the redundancy mode level currently used by the switching system based on the real-time error rate, the redundancy mode remains unchanged. If the redundancy mode level issued by the software is higher than the redundancy mode level of the current switching system, the system immediately switches to the redundancy level mode issued by the software, and sets a "cannot be downgraded" flag to prevent the switching system from automatically adjusting the redundancy mode based on the error rate, which would lead to a decrease in the redundancy mode level. If the real-time error rate gradually exceeds the judgment threshold, the switching system automatically adjusts the redundancy mode and increases the redundancy mode level. If the redundancy level issued by the software is lower than the current hardware redundancy level, and the hardware error rate at this time meets the issued redundancy level, the system switches to the issued redundancy level. If the redundancy level issued by the software is SMR mode, after the switching system switches to SMR mode, the "cannot be downgraded" flag is cleared, and the switching system automatically adjusts the redundancy mode and the redundancy mode level.

[0094] like Figure 4 As shown, the train dynamic redundancy switching system also includes an on-chip memory unit 405 and a DDR memory unit 406. The memory controller 404 is connected to and communicates with the on-chip memory unit 405 and the DDR memory unit 406 respectively, and controls the on-chip memory unit 405 and the DDR memory unit 406 to store data.

[0095] The DDR memory unit 406 can be configured as a double data rate synchronous dynamic random access memory.

[0096] The interrupt controller 401 of the train dynamic redundancy switching system communicates with the GPIO controller 407, timer 408, and other peripheral controllers 410 to receive interrupt signals. These interrupt signals include those generated from the serial port and network card. The interrupt signals are used to notify the train dynamic redundancy switching system that external data needs processing. When an external device requires data processing from the train dynamic redundancy switching system, it sends an interrupt signal to the system.

[0097] The GPIO controller 407 can be configured as a general-purpose input / output controller. The GPIO controller 407 communicates with GPIO pins 409.

[0098] Other peripheral controllers 410 connect and communicate with other peripherals 411. It should be noted that the above modules can be functional modules or program modules, and can be implemented by software or hardware. For modules implemented by hardware, the above modules can be located in the same processor 103; or the above modules can be located in different processors 103 in any combination.

[0099] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0100] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A train dynamic redundancy switching system, wherein the switching system is connected to the train central control unit, characterized in that, include: The communication module is configured to communicate with the train's central control unit and receive train data. The processor includes a processing core configured to generate verification information based on train data. The security manager is configured to receive verification information, determine whether the verification information is correct based on the verification information, and obtain the number of judgments and the number of errors. Calculate the ratio of the number of errors to the number of judgments to obtain the real-time error rate; based on the real-time error rate and the judgment threshold, switch the redundancy mode and generate redundancy mode information; The selector is configured to control the opening or closing of the communication module's path for transmitting train data to the processing core based on redundancy mode information. The redundancy mode information includes first redundancy information, second redundancy information, and third redundancy information, and the processing core includes multiple cores. When the error rate is higher than the first judgment threshold but lower than the second judgment threshold, the safety manager activates the first redundancy mode and generates the first redundancy information. When the error rate is higher than the second judgment threshold but lower than the third judgment threshold, the safety manager activates the second redundancy mode and generates the second redundancy information. When the error rate is higher than the third judgment threshold but lower than the fourth judgment threshold, the safety manager activates the third redundancy mode and generates the third redundancy information. At the same time, the selector opens multiple channels for the communication module to transmit train data to one or more cores corresponding to the redundancy mode information based on the received redundancy mode information. The multiple cores include a first core, a second core, and a third core, and the gating is further configured as follows: When the redundancy mode information is the first redundancy information, the communication module is opened to transmit train data to the first core. When the redundancy mode information is the second redundancy information, the communication module is opened to transmit train data to the first core and the second core. When the redundancy mode information is the third redundancy information, the communication module is enabled to transmit train data to the first core, the second core, and the third core.

2. The train dynamic redundancy switching system according to claim 1, characterized in that, The security manager is further configured to: receive the verification information of a core in a redundant mode corresponding to the core, verify whether the verification information is correct, and if not, accumulate the error count and recalculate the error rate.

3. The train dynamic redundancy switching system according to claim 1, characterized in that, Also includes: The interrupt controller is configured to receive interrupt information and redundancy mode information, and send the interrupt information to the core corresponding to the redundancy mode information.

4. The train dynamic redundancy switching system according to claim 1, characterized in that, Also includes: The clock manager is configured to receive redundancy mode information and control the startup of the core corresponding to that redundancy mode information.

5. The train dynamic redundancy switching system according to claim 1, characterized in that, Also includes: The reset manager is configured to control the processor reset when the error rate equals the fourth judgment threshold.

6. The train dynamic redundancy switching system according to claim 1, characterized in that, Also includes: The memory controller is configured to receive and store correct data sent by the security manager if the verification information is correct in the security manager.

7. The train dynamic redundancy switching system according to claim 1, characterized in that, Also includes: The information acquisition module is configured to acquire the train's real-time operating status and the type of task it is currently performing. The control module is configured to switch to redundancy mode according to preset rules based on the train's real-time operating status and the type of task it is performing.

8. The train dynamic redundancy switching system according to claim 7, characterized in that, Also includes: The comparison module is configured to determine whether the redundancy mode level of the safety manager switching is higher than the redundancy mode level of the control module switching. If so, the train is controlled to execute the redundancy mode of the control module switching; otherwise, the train is controlled to execute the redundancy mode of the safety manager switching.

Citation Information

Patent Citations

  • Train redundancy dynamic configuration method and system

    CN105099743A

  • Method and device for monitoring communication of train network control system

    CN118605457A