An application redundancy management platform based on a hardware and software fault monitoring mechanism
By adopting a dual-redundancy, hot-backup hardware and software fault monitoring mechanism in the avionics system, the reliability and continuity of the avionics system during master-slave redundancy switching are achieved, solving the reliability problem of the avionics system and ensuring flight safety and mission execution stability.
Patent Information
- Application Number
- CN202411957027.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-29
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-12-29
AI Technical Summary
In existing technologies, avionics systems lack sufficient reliability and continuity during master-slave redundancy switching, making it difficult to guarantee flight safety and mission stability.
An application redundancy management platform based on hardware and software fault monitoring mechanism is adopted. Through dual redundancy and hot backup, GSM software and avionics application software reside in two IOM modules respectively. Health status monitoring and master-slave switching are performed using discrete fault indication signals to ensure cross-synchronization of key information and system continuity.
It achieves reliability and continuity of the avionics system during master-slave redundancy switching, ensures the stability and reliability of the avionics system's operating status, and meets the reliability requirements of the avionics system.
Smart Images

Figure CN119902917B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of integrated core processing systems, and particularly provides an application redundancy management platform based on a software and hardware fault monitoring mechanism. BACKGROUND
[0002] In an integrated modular avionics system, important avionics applications generally adopt a dual-redundancy and hot backup working mode, and the master and slave redundancies are respectively located in two independent processing modules and simultaneously run, but only the master redundancy outputs running results at the same time. The master and slave redundancies periodically cross-synchronize key running information. When the master redundancy fails, the general system management (GSM) software controls the application to perform master-slave switching, the slave redundancy is switched to the master redundancy, and starts to output running data, thereby ensuring the continuity of the avionics system running state.
[0003] Therefore, a reliable application redundancy management scheme is crucial for the flight safety and task execution of an airplane. SUMMARY
[0004] The application aims to solve the redundancy management problem of important applications, so as to meet the reliability requirement of an avionics system.
[0005] In order to achieve the above object, the application adopts the following technical scheme: an application redundancy management platform based on a software and hardware fault monitoring mechanism, the platform comprises two IOM modules interconnected through an FC network, the IOM module software is based on a multi-core operating system, adopts a bound multi-core processing running mode, and runs the resident GSM software and each avionics application software on the specified processor core through a configuration partition scheduling table.
[0006] The application redundancy management platform based on the software and hardware fault monitoring mechanism also has the following technical features: the two IOM modules are cross-connected through a fault indication discrete signal, and are used for supporting health state monitoring.
[0007] The application redundancy management platform based on the software and hardware fault monitoring mechanism also has the following technical features: the GSM software adopts a dual-redundancy and hot backup working mode, and the master and slave redundancies are respectively located in two IOM modules and simultaneously run, and only the master redundancy outputs running results at the same time.
[0008] The application redundancy management platform based on the software and hardware fault monitoring mechanism also has the following technical features: the master and slave redundancies of the GSM software monitor the health state of each other through a fault indication discrete signal, and the GSM software performs master-slave switching when the master redundancy fails.
[0009] The application margin management platform based on the software and hardware fault monitoring mechanism also has the technical features that the GSM software of each avionics application software adopts a double-redundancy and hot backup working mode, the master and slave redundancies are respectively located in two IOM modules and run simultaneously, only the master redundancy outputs the running result at the same time, the master and slave of each avionics application software are consistent with the master and slave of the GSM software, and the key running information is cross-synchronized between the master and slave redundancies through the FC network periodically.
[0010] The application margin management platform based on the software and hardware fault monitoring mechanism also has the technical features that the GSM software monitors the hardware state of the IOM module through the power-on BIT, the periodic BIT and the maintenance BIT, monitors the running state of each avionics application software through the online state monitoring, and monitors the running state of itself through the hardware watchdog.
[0011] The application margin management platform based on the software and hardware fault monitoring mechanism also has the technical features that the GSM software controls the master and slave switching of each avionics application software.
[0012] Beneficial effects
[0013] The application margin management function of the application margin management platform based on the software and hardware fault monitoring mechanism is realized by the general system management (GSM) software. The GSM software and a plurality of application softwares are simultaneously located in the IOM module, the GSM software monitors the hardware working state of the IOM module through the power-on BIT, the periodic BIT and the maintenance BIT program, monitors the running state of the application software located in the IOM module through the online state monitoring program, and monitors the running state of itself through the hardware watchdog. When the IOM module has a hardware fault or any partition located in the IOM module has a software fault, the GSM software controls the master and slave switching of the application software located in the IOM module. The continuity of the avionics system running state is maintained, the application margin management problem of important applications is solved, and the reliability requirement of the avionics system is met. BRIEF DESCRIPTION OF DRAWINGS
[0014] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings needed to be used in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and other drawings can also be obtained by those skilled in the art without any creative effort on the basis of these drawings.
[0015] Figure 1 The IOM module hardware architecture schematic diagram provided by the embodiments of the present disclosure;
[0016] Figure 2Residence schematic diagram of IOM module software provided by the embodiment of the application. DETAILED DESCRIPTION
[0017] The application will be described in further detail below with reference to the drawings and embodiments, but it should be noted that these embodiments are not limiting to the application, and equivalent transformations or substitutions of function, method or structure made by those skilled in the art based on the embodiments are within the protection scope of the application.
[0018] In the description of the embodiments of the application, it should be understood that the terms "center", "longitudinal", "transverse", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the purpose of facilitating the description of the application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting to the application.
[0019] In addition, the terms "first", "second", "third" and the like are only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" and the like can explicitly or implicitly include one or more of the features. In the description of the application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0020] The terms "mounting", "connection", "connection" should be broadly understood, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be directly connected, or indirectly connected through intermediate medium, or the communication between two elements. For those skilled in the art, the specific meaning of the above terms in the application can be understood according to the specific circumstances.
[0021] As shown in Figures 1-2 A hardware and software fault monitoring mechanism based application margin management platform is provided, the platform comprises two IOM modules interconnected through FC network, the IOM module software is based on multi-core operating system, adopts binding multi-core processing operation mode, and through configuration of partition scheduling table, the resident GSM software and each avionics application software are respectively bound to the specified processor core for operation.
[0022] In the above embodiments, the multi-core processor is selected as FT-2000 / 4 of Feiteng, and the working frequency is 1GHz; the processor is connected with the FC interface through the PCI e bus; the discrete quantity interface is connected through the PCI e bus or the SPI bus; the two IOM modules are interconnected through the FC network, and are cross-connected through the fault indication discrete signal; the hardware architecture of the IOM module is shown in Figure 1 The software of the IOM module is based on the 3-partition multi-core operating system of Tianmai, adopts the BMP running mode, and multiple software partitions are resident in the IOM module, including the GSM partition and multiple application partitions, each software partition is respectively bound to a specified processor core for running through the configuration of the partition scheduling table; four software partitions are resident in the IOM module, wherein the GSM partition and the application partition 1 are bound to the processor core 0, the application partition 2 is bound to the processor core 1, the application partition 3 is bound to the processor core 2, and the processor core 3 is idle; the software resident in the IOM module is shown in Figure 2 .
[0023] In some embodiments, the two IOM modules are cross-connected through the fault indication discrete signal, which is used to support the health state monitoring.
[0024] In some embodiments, the GSM software adopts the working mode of double redundancy and hot backup, the master and slave redundancies are respectively resident in the two IOM modules, and run simultaneously, and only the master redundancy outputs the running result at the same time.
[0025] In some embodiments, after the system is powered on, the master and slave states are confirmed according to the health states of the system itself and the opposite end, the IOM1 module and the resident GSM software are the master by default, and the IOM2 module and the resident GSM software are the slave; the master and slave GSM softwares monitor the health states of each other through the fault indication discrete signal, when the fault indication discrete signal state of the master IOM module changes, the discrete interface circuit of the slave IOM module notifies the processor through a hardware interrupt, and after the slave GSM software receives the interrupt, the master and slave switching is performed.
[0026] In some embodiments, the master and slave redundancies of the GSM software monitor the health states of each other through the fault indication discrete signal, when the master redundancy fails, the master and slave switching of the GSM software is performed.
[0027] In some embodiments, the GSM software of each avionics application software adopts the working mode of double redundancy and hot backup, the master and slave redundancies are respectively resident in the two IOM modules, and run simultaneously, and only the master redundancy outputs the running result at the same time, the master and slave of each avionics application software are consistent with the master and slave of the GSM software, and the master and slave redundancies periodically cross-synchronize the key running information through the FC network.
[0028] In some embodiments, the GSM software monitors the hardware state of the IOM module through power-on BIT, periodic BIT and maintenance BIT, and outputs a fault indication discrete signal when a hardware fault occurs in the functional circuit of the IOM module during the BIT detection process. The running state of each avionics application software is monitored through online state monitoring, and all application partitions set their online state to the GSM software at a period of 250 ms in a critical task. When the GSM software detects that the application partition is not online for three consecutive periods, the GSM software determines that the application partition has an abnormal running state and a software fault occurs, and the GSM software residing in the IOM module actively outputs a fault indication discrete signal. The running state of the GSM software is monitored through a hardware watchdog, and the GSM partition executes a watchdog feeding operation at a period of 250 ms in a critical task. When the hardware watchdog detects that the GSM software has not been fed for three consecutive periods, it is determined that the GSM software partition has an abnormal running state and a software fault occurs, and the hardware watchdog automatically outputs a fault indication discrete signal.
[0029] In some embodiments, the GSM software is also used for application redundancy management. When a hardware fault occurs in the main IOM module or a software fault occurs in any partition residing in the main IOM module during system operation, the main IOM module fault indication discrete signal state changes are detected by the discrete interface circuit of the slave IOM module, and the processor is notified through a hardware interrupt. After the GSM software identifies that the main IOM module fault indication discrete signal has changed, the master-slave switching is performed, and the role of the GSM software is set to the main role to ensure the continuity of the avionics system running state.
[0030] In some embodiments, the GSM software performs master-slave switching control on each avionics application software. After the GSM software performs master-slave switching, the master-slave roles of all application software residing in the IOM module are consistent with the GSM software, and the master-slave switching is performed. All application software residing in the slave IOM module is switched to the main redundancy, starts to output the software running result, and ensures the continuity of the avionics system running state.
[0031] The above only describes the preferred embodiments of the present application and should not be used to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application should be included in the protection scope of the present application. The above only describes the preferred embodiments of the present application, and it should be pointed out that, for ordinary skilled in the art, without departing from the technical principles of the present application, a number of improvements and modifications can be made, and these improvements and modifications should be regarded as the protection scope of the present application.
Claims
1. An application redundancy management platform based on a hardware and software fault monitoring mechanism, characterized in that, The platform comprises two IOM modules interconnected through an FC network, wherein each IOM module comprises a multi-core processor, an FC interface and a discrete quantity interface, the multi-core processor is connected with the FC interface through a PCIe bus and connected with the discrete quantity interface through a PCIe bus or an SPI bus; The IOM module software is based on a multi-core operating system, adopts a bound multi-core processor running mode, and binds the resident general system management software and each avionics application software to a specified processor core for running through a configuration partition scheduling table; the general system management software and each avionics application software both adopt a dual-redundancy and hot backup working mode, the master and slave redundancies are resident in the two IOM modules and run simultaneously, only the master redundancy outputs a running result at the same time, the master and slave of each avionics application software are consistent with the master and slave of the general system management software, and the master and slave redundancies cross-synchronize key running information through the FC network periodically; The two IOM modules are cross-connected through a fault indication discrete quantity signal for supporting health state monitoring; The master and slave redundancies of the general system management software monitor the health state of each other through a fault indication discrete quantity signal, when the master redundancy fails, the general system management software performs master-slave switching; The general system management software monitors the hardware state of the IOM module through power-on BIT, periodic BIT and maintenance BIT, monitors the running state of each avionics application software through online state monitoring, and monitors the running state of itself through a hardware watchdog, when the master IOM module fails in hardware or any partition resident therein fails in software, the discrete quantity interface circuit of the slave IOM module detects that the fault indication discrete quantity signal state of the master IOM module changes, notifies the multi-core processor through a hardware interrupt, and after the general system management software identifies that the fault indication discrete quantity signal of the master IOM module changes, performs master-slave switching and sets the role as the master; the general system management software also controls the master-slave switching of each avionics application software.
Citation Information
Patent Citations
Asymmetric software triple-computer hot backup fault-tolerant method
CN101876926A
Dual-redundancy general processing module and information synchronization method thereof
CN115185877A