Redundancy real-time control system based on TSN

By adopting TSN-based technology in the redundant real-time control system, combining centralized clock configuration and time-sensitive network switches, the problems of low transmission efficiency and high deployment cost are solved, and a real-time control system with high bandwidth, low cost and high reliability is realized.

CN119937279APending Publication Date: 2025-05-06北京东土军悦科技有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510115570.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, the redundant control system based on buses has low transmission efficiency, cannot meet the bandwidth requirements of modern control systems, and has high deployment costs.

Method used

Using a redundant real-time control system based on TSN, the combination of CTC, controller, input and output IO devices and time-sensitive network TSN switches is configured with a centralized clock to achieve unified bearer of real-time services and non-real-time services, and high-precision clock synchronization and deterministic transmission are carried out through the TSN switch.

Benefits of technology

It improves the transmission bandwidth of the redundant real-time control system, reduces deployment costs, enhances the reliability and real-time nature of the system, and can meet the real-time services with higher time certainty requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119937279A_ABST
    Figure CN119937279A_ABST
Patent Text Reader

Abstract

The invention provides a redundancy real-time control system based on a TSN. The redundancy real-time control system comprises a CTC, a controller, IO equipment and a time sensitive network TSN switch. Each main controller is provided with one or more standby controllers in a working state, each main IO device is provided with one or more standby IO devices in a working state, and each main TSN switch is provided with one or more standby TSN switches in a working state; the controller and the IO equipment in the system form a switched network through the TSN switch; at least two TSN switches are respectively provided with clock sources, the clock sources comprise a main clock source and at least one standby clock source, and the clock sources transmit clock signals outwards hop by hop through adjacent links; the CTC is connected to each clock source, the CTC comprises a main CTC and a standby CTC, and the CTC is used for managing a clock domain of the system and sensing clock synchronization states of all nodes in the system. The technical problem of low transmission efficiency of a bus-based redundancy control system in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of real-time control technology, and in particular to a redundant real-time control system based on TSN. Background Art

[0002] In the related art, the ARINC659 bus (a high reliability and high fault tolerance serial communication bus designed specifically for avionics systems) adopts a communication mechanism of command table driven proportional access (TDPA). The compiled command table is loaded into the bus module. When the system is powered on, the BIU of each bus module starts to read the command table and parse the commands to be executed, and transmits bus data and synchronizes pulses according to the pre-set command table content format. Each bus module contains two bus interface units BIU (BIUx, BIUy), and each BIU has two bus pairs, A and B, and each bus pair contains two buses, "x" and "y", that is, 4 buses, Ax, Ay, Bx, and By. Each bus has a separate clock line and 2 data lines, and can transmit 2 data bits in each clock cycle. BIUx and BIUy send data on their respective buses respectively, and each BIU can receive data on 4 buses. Each bus has its own transceiver. The ARINC659 bus data is cross-checked for error detection and fault tolerance, and the detection rules are Ax=Ay, Bx=By, Ax=By and Bx=Ay. The data check is cross-checked by 4 bus pairs, so it can achieve a good fault tolerance effect and the complexity is not high. However, the maximum rate supported by the ARINC659 bus is 60Mb / s, which is obviously unable to meet the bandwidth requirements of the control system in today's increasingly developed information and intelligence. The 1394 bus CC (Control Computer) node, as the node controller of the 1394 bus, sends a frame start (STOF) message periodically to notify all nodes on the bus of the start of a new frame, and completes the synchronization of the bus through the STOF message. The RN (Remote Node) node, as a remote terminal, binds different node IDs and channel numbers according to the pre-allocated bus channel. After receiving the STOF message, the RN node confirms the start of a new frame and sends data when its own node time offset arrives according to the pre-allocated time offset and bandwidth. Like all buses, all nodes of the 1394 bus share bandwidth. Any transmission must wait until the previous transmission is completed before it can be initiated, which leads to low transmission efficiency. The traditional ARINC659 bus and 1394 bus face low bandwidth and limited aviation-specific technology suppliers, resulting in high deployment costs.

[0003] With respect to the above-mentioned problems existing in the related technologies, no efficient and accurate solutions have been found yet. Summary of the invention

[0004] The present invention provides a TSN-based redundant real-time control system to solve the technical problem of low transmission efficiency of bus-based redundant control systems in related technologies, realize unified carrying of real-time and non-real-time services in redundant real-time control systems, and ensure deterministic transmission of real-time control services.

[0005] According to one embodiment of the present invention, a TSN-based redundant real-time control system is provided, including: a centralized clock configuration CTC, a controller, an input and output IO device, and a time-sensitive network TSN switch; each main controller is provided with one or more standby controllers in a working state, each main IO device is provided with one or more standby IO devices in a working state, and each main TSN switch is provided with one or more standby TSN switches in a working state; the controllers and IO devices in the system form a switching network through the TSN switch; at least two TSN switches are respectively deployed with clock sources, including a main clock source and at least one standby clock source, and the clock sources transmit clock signals hop by hop through adjacent links; the CTC accesses each of the clock sources, the CTC includes a main CTC and a standby CTC, and the CTC is used to manage the clock domain of the system and perceive the clock synchronization status of all nodes in the system.

[0006] Optionally, the redundant real-time control system is a dual-redundant real-time control system, including two controllers and two TSN switches, one of the two TSN switches deploys a main clock source and the other deploys a backup clock source.

[0007] Optionally, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and two TSN switches, one of the two TSN switches deploys a main clock source and the other deploys a backup clock source.

[0008] Optionally, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and four TSN switches, wherein one of the four TSN switches is deployed with a main clock source and another one is deployed with a backup clock source.

[0009] Optionally, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and four TSN switches, one of the four TSN switches is deployed with a main clock source, and the other three are deployed with backup clock sources.

[0010] Optionally, the main CTC is also used to: after the node performs clock synchronization with the clock source, receive clock synchronization status reporting events reported by each of the nodes, wherein the clock synchronization status reporting event is used to characterize whether the current node has completed clock synchronization with the clock source; the node is any one of a controller, an IO device, and a TSN switch; and send a notification message to all nodes according to the clock synchronization status reporting event, wherein the notification message is used to indicate that all nodes of the redundant real-time control system have completed system-level synchronization.

[0011] Optionally, sending a notification message to all nodes according to the clock synchronization status reporting event includes: judging whether all nodes have completed clock synchronization with the clock source based on the clock synchronization status reporting event; after all nodes have completed clock synchronization with the main clock source, the main CTC sends a notification message to all nodes.

[0012] Optionally, before receiving the clock synchronization status reporting events reported by each of the nodes, the master CTC is also used to: monitor whether the master CTC receives a master clock source failure alarm; if the master CTC receives a master clock source failure alarm, send a clock domain switching message to all nodes so that all nodes uniformly switch the master clock source to a backup clock source.

[0013] Optionally, after sending a notification message to all nodes according to the clock synchronization status reporting event, the main CTC is also used to: read the flag bit status of the target flag bit, wherein the flag bit status is used to indicate whether the gating effective time needs to be announced; determine whether the flag bit status is set; if the flag bit status is set, the main CTC announces the gating effective time to all nodes and clears the target flag bit.

[0014] Optionally, the master CTC notifies all nodes of the gating effective time, including: obtaining the set delay time of the redundancy real-time control system, and obtaining the current system time of the master CTC when completing system-level synchronization; calculating the gating effective time based on the set delay time and the current system time; the master CTC notifies all nodes of the gating effective time.

[0015] Optionally, obtaining the set delay time of the redundancy real-time control system includes: obtaining the relative time between the task scheduling time and the reference time of the controller in the redundancy real-time control system in the current business cycle; and determining the relative time as the set delay time.

[0016] Optionally, after clearing the target flag bit, the method further includes: determining whether the main CTC receives a system-level fault message; if the main CTC receives a system-level fault message, configuring the flag bit state of the target flag bit to a set state.

[0017] According to another aspect of an embodiment of the present application, there is also provided an electronic device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; wherein: the memory is used to store computer programs; and the processor is used to execute the steps in the above method by running the program stored in the memory.

[0018] According to yet another embodiment of the present invention, a storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any one of the above-mentioned device embodiments when running.

[0019] The embodiments of the present invention solve the technical problem of low transmission efficiency of a redundant control system based on a bus in the related art, improve the transmission bandwidth of the redundant real-time control system, and reduce the deployment cost of the redundant real-time control system.

[0020] It solves the technical problem that when TSN is applied to redundant real-time control systems, the redundant real-time control system needs to wait for a certain period of time before starting to work, which affects the real-time performance of the system because the existing TSN technology has no mechanism to perceive the whole network nodes to complete system-level synchronization. It improves the reliability and real-time performance of the redundant real-time control system and can complete real-time services with higher requirements for time certainty.

[0021] The time for completing system-level synchronization is determined according to the time when all nodes complete clock synchronization with the master clock source, so that the time for completing clock synchronization of all network nodes can be perceived in the application process of redundant real-time system, thereby improving the accuracy of perceiving the completion of system-level synchronization of all network nodes;

[0022] By sending clock domain switching messages to the master CTC and all network nodes, the technical problem that all network nodes cannot uniformly switch clock domains after the master clock source fails is solved, and the fault tolerance of redundant real-time control systems is improved;

[0023] A scheme for notifying the gating effective time of all nodes in the redundant real-time control system has been implemented. The main CTC sends the gating effective time to all nodes in the entire network, which can align the gating scheduling starting points of the terminals and networks in the redundant real-time control system and achieve the effect of clock synchronization.

[0024] The delay time can be set for the redundant real-time control system, which improves the flexibility of clock synchronization. The redundant real-time control system can be compatible with various types of controllers, which improves the compatibility of the redundant real-time control system;

[0025] When the redundant control system migrates from bus-based interconnection to switched network communication mechanism, relative time processing can be considered to be compatible with the linear scheduling mechanism of the traditional bus. The absolute time of TSN high-precision clock synchronization can be mapped to the relative time of non-real-time services, avoiding major modifications to the upper-layer applications of the controller that processes non-real-time services.

[0026] TSN's gated effective time supports secondary configuration, which improves the fault tolerance and reliability of redundant real-time control systems when system-level failures occur. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0028] Figure 1 is a hardware structure block diagram of a flight control computer according to an embodiment of the present invention;

[0029] Figure 2 is a schematic diagram of a TSN-based redundancy real-time control system according to an embodiment of the present invention;

[0030] Figure 3 It is a general architecture diagram of a dual-redundancy real-time control system based on TSN in an embodiment of the present invention;

[0031] Figure 4 It is a schematic diagram of clock synchronization of a dual-redundancy real-time control system in an embodiment of the present invention;

[0032] Figure 5 This is a general architecture diagram of a TSN-based quad-redundant real-time control system in an embodiment of the present invention;

[0033] Figure 6 It is a schematic diagram of clock synchronization of a four-redundancy real-time control system in an embodiment of the present invention;

[0034] Figure 7 It is another principle diagram of clock synchronization of a quadruple-redundant real-time control system in an embodiment of the present invention;

[0035] Figure 8 It is another principle diagram of clock synchronization of a quadruple-redundant real-time control system in an embodiment of the present invention;

[0036] Fig. 9is a flow chart of a clock management method of a redundant real-time control system based on TSN according to an embodiment of the present invention;

[0037] Fig.10 It is a flowchart of CTC service processing in an embodiment of the present invention. DETAILED DESCRIPTION

[0038] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work should fall within the scope of protection of the present application. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0039] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0040] Example 1

[0041] The method embodiment provided in the first embodiment of the present application can be executed in a flight control computer, a clock module, an aerospace equipment, a controller or a similar equipment management device. Taking running on a flight control computer as an example, Figure 1 FIG. 1 is a hardware structure diagram of a flight control computer according to an embodiment of the present invention. Figure 1 As shown, the flight control computer may include one or more ( Figure 1 Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Optionally, the flight control computer may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1The structure shown is for illustration only and does not limit the structure of the flight control computer. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0042] The memory 104 can be used to store flight control computer programs, for example, software programs and modules of application software, such as a flight control computer program corresponding to a clock management method for a redundant real-time control system based on TSN in an embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the flight control computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the flight control computer via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0043] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the flight control computer. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0044] Figure 2The present invention is a schematic diagram of a redundant real-time control system based on TSN according to an embodiment of the present invention, including: CTC (Central Time Configuration), controller, IO (Input Output) device, and TSN (Time Sensitive Networking) switch, each main controller is provided with one or more standby controllers in working state, each main IO device is provided with one or more standby IO devices in working state, and each main TSN switch is provided with one or more standby TSN switches in working state; the controllers and IO devices in the system form a switching network through TSN switches; at least two TSN switches are respectively deployed with clock sources, including a main clock source and at least one standby clock source, and the clock sources transmit clock signals hop by hop through adjacent links; the CTC accesses each of the clock sources, the CTC includes a main CTC and a standby CTC, and the CTC is used to manage the clock domain of the system and perceive the clock synchronization status of all nodes in the system.

[0045] The redundancy real-time control system of this embodiment can be applied in scenarios such as aerospace, ships, and vehicles, such as a flight control redundancy system.

[0046] The redundant real-time control system of this embodiment includes multiple nodes, such as controllers, IO devices, network nodes, etc. The multiple controllers are used to respond to the same task request and execute the same operation in parallel.

[0047] TSN switches can realize unified carrying of real-time control services and non-real-time high-traffic services, and can ensure the deterministic transmission of real-time control services. They also have the advantages of high transmission bandwidth, mature industrial chain, low deployment cost and great development potential.

[0048] By adopting the scheme of this embodiment, a control architecture of a switched redundant real-time control system based on TSN is realized. All nodes are centered on the TSN switch, and the clock source is deployed on the TSN switch. Data interaction within a single redundancy, data crossing between redundancies, and high-precision clock synchronization between redundancies are all centered on the TSN switch. Through the TSN gating list scheduling mechanism, deterministic transmission of control services is achieved, and the technical problem of low transmission bandwidth of bus-based redundant control systems in related technologies is solved, the transmission bandwidth of redundant real-time control systems is improved, and the deployment cost of redundant real-time control systems is reduced. By introducing CTC, unified clock management of multiple nodes in redundant real-time control systems is achieved.

[0049] Optionally, the redundant real-time control system can be a dual-redundancy control system, a quad-redundancy control system, etc. The quad-redundancy control system is divided into a low-cost version and a standard version according to the number of TSN switches deployed.

[0050] In order to improve the reliability of transmission services and avoid single point failure of TSN switches, the redundant real-time control system of this embodiment deploys redundant protocols (such as IEEE 802.1CB) on the end side. In the dual-redundancy control system / quadruple-redundancy control system (low-cost), two copies of the same data are transmitted in parallel at the same time, and in the quadruple-redundancy control system (standard), four copies of the same data are transmitted in parallel. Any transmission link failure will not affect service transmission, and zero packet loss can be achieved in the redundant real-time control system.

[0051] In an implementation scenario of this embodiment, the redundant real-time control system is a dual-redundant real-time control system, including two controllers and two TSN switches, one of the two TSN switches deploys a main clock source and the other deploys a backup clock source.

[0052] Figure 3 It is the overall architecture diagram of the dual-redundancy real-time control system based on TSN in an embodiment of the present invention. Two TSN switches and two controllers are deployed. Each TSN switch is connected to the two controllers at the same time to form a switched network. Each TSN switch is connected to the two controllers and two IO devices. Controller 1 and controller 2 in the dual-redundancy real-time control system simultaneously perform the same dual-redundancy operation. Two copies of the same data are transmitted in parallel in the switched network at the same time.

[0053] Figure 4 This is a schematic diagram of clock synchronization of a dual-redundancy real-time control system in an embodiment of the present invention. The dual-redundancy control system deploys two clock domains, with two TSN switches as the master and backup clock sources respectively. The clock (including the master clock and the backup clock) is the host (Master, M), and the corresponding nodes (such as the controller and IO) are slaves (Slave, S). The master clock and the backup clock are master-slave to each other. When the controller performs clock synchronization, the master clock and the backup clock simultaneously provide time to the controller and IO devices. The blue clock domain (master clock) is the TSN switch on the left (deployed with the master clock ), the clock signal is transmitted to the outside through three links (blue dotted links), and after being transmitted to the TSN switch on the right (deployed with a backup clock), the switch on the right will transmit it to controller 2 and IO_2 through two links (blue dotted links). Similarly, the controller and IO select the time of the master clock for synchronization. If the master clock fails, the time of the backup clock is selected for synchronization. The dotted line indicates the clock synchronization link between the host and the slave, and the solid line indicates the connection link between the master and backup CTCs, and the connection link between the master and backup CTCs and the master and backup clocks.

[0054] In another implementation scenario of this embodiment, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and two TSN switches, one of the two TSN switches deploys a main clock source and the other deploys a backup clock source.

[0055] In another implementation scenario of this embodiment, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and four TSN switches, one of the four TSN switches deploys a main clock source and the other deploys a backup clock source.

[0056] In another implementation scenario of this embodiment, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and four TSN switches, one of the four TSN switches is deployed with a main clock source, and the other three are deployed with backup clock sources.

[0057] Figure 5 This is an overall architecture diagram of a TSN-based quad-redundant real-time control system in an embodiment of the present invention. It is a low-cost version of a quad-redundant real-time control system. Two TSN switches are deployed. Each TSN switch is connected to four controllers at the same time to form a switched network. Each TSN switch is connected to four controllers and four IOs. Controllers 1 to 4 in the quad-redundant real-time control system simultaneously perform the same quad-redundant operation. Two copies of the same data are transmitted in parallel in the switched network.

[0058] Figure 6 1 is a schematic diagram of clock synchronization of a quad-redundant real-time control system in an embodiment of the present invention. It is a low-cost version of a quad-redundant real-time control system. Two TSN switches and two clock domains are deployed. A master clock source and a backup clock source are deployed on the corresponding two TSN switches. When the controller performs clock synchronization, the master clock and the backup clock simultaneously provide time to the controller and IO devices. The blue clock domain (master clock) is the switch on the left (with the master clock deployed). It transmits the clock signal to the outside through five links (blue dotted links). After being transmitted to the switch on the right (with the backup clock deployed), the switch on the right transmits the clock signal through four links (blue The dashed line link) is then transmitted to controller 3, controller 4, IO_3, and IO_4. The red clock domain (backup clock) is similar. The controller and IO select the time of the master clock for synchronization. If the master clock fails, the backup clock time is selected for synchronization. In the four-redundancy real-time control system, the clock (including the master clock and the backup clock) is the master (Master, M), and the corresponding controller and IO are the slaves (Slave, S). The master clock and the backup clock are master and slave to each other. The dashed line illustrates the clock synchronization link between the master and the slave, and the solid line illustrates the connection link between the master and backup CTCs, and the connection link between the master and backup CTCs and the master and backup clocks.

[0059] Figure 7 It is a schematic diagram of another clock synchronization of a quad-redundant real-time control system in an embodiment of the present invention, which is a standard version of a quad-redundant real-time control system. Two clock domains are deployed, and a master clock source and a backup clock source are respectively deployed on two TSN switches in the four TSN switches. When the controller performs clock synchronization, the master clock and the backup clock (two channels simultaneously provide time to the controller and IO devices. The blue clock domain (master clock) is the switch on the left. It will transmit the clock signal to the outside through four links (blue dotted links). After being transmitted to the right switch (backup clock), the right switch will transmit it to the controller 3, IO_3, and the switch on the right side of the backup clock through three links (blue dotted links). Similarly, the controller and IO select the time of the master clock for synchronization. If the master clock fails, the time of the backup clock is selected for synchronization.

[0060] Figure 8 It is another schematic diagram of clock synchronization of a quad-redundant real-time control system in an embodiment of the present invention, which is another standard version of a quad-redundant real-time control system. Four clock domains are deployed, including one master clock source and three backup clock sources. One master clock source and three backup clock sources are deployed on four TSN switches respectively. When the controller performs clock synchronization, the master clock and the backup clock four-way simultaneously provide time to the controller and IO devices. The blue clock domain (master clock) is the leftmost switch, which transmits the clock signal to the outside through three links (blue dotted links). After being transmitted to the switch on its right (backup clock 1), the switch on the right transmits it to controller 2 and IO_2 through three links (blue dotted links). , the switch on the right side of backup clock 1 (backup clock 2), backup clock 2 will continue to pass through three links (blue dotted links) to controller 3, IO_3, the switch on the right side of backup clock 2 (backup clock 3), backup clock 3 will continue to pass through two links (blue dotted links) to controller 4, IO_4, red clock domain (backup clock 1), green clock domain (backup clock 2), and purple clock domain (backup clock 3) Similarly, controllers and IOs select the time of the master clock for synchronization. If the master clock fails, one of the remaining three backup clocks is selected for clock synchronization according to priority. The quad-redundant real-time control system (standard) can deploy two clock domains (such as Figure 7 ) or 4 clock domains (as shown Figure 8 As shown), Figure 7 As shown in the figure, when there are two clock domains, TSN switch 2 and TSN switch 3 are used as the main and standby clock sources respectively. Figure 8As shown, the four clock domains use TSN switch 1 as the master clock and TSN switch 2 to TSN switch 4 as the backup clock 3. In the redundant real-time control system, the clock (including the master clock and the backup clock) is the master (Master, M), and the corresponding controller and IO are the slave (Slave, S). The master clock and the backup clock are master and slave to each other. The dotted line illustrates the clock synchronization link between the master and the slave, and the solid line illustrates the connection link between the master and backup CTCs, and the connection link between the master and backup CTCs and the master and backup clocks.

[0061] At present, the standard TSN clock synchronization adopts a master-slave step-by-step synchronization architecture. Each device can only interact with adjacent devices. The clock synchronizes its own clock signal to adjacent nodes through the 1588 protocol, and then synchronizes to its adjacent nodes through adjacent nodes. Therefore, the distributed nature of the current standard TSN clock synchronization protocol makes the synchronization state of each device stored locally. The master-slave step-by-step synchronization architecture means that each device can only interact with adjacent devices. All nodes in the system cannot perceive the synchronization state of other nodes except adjacent nodes, causing the upper-layer application to be unable to determine when to start. The redundant real-time control system needs to wait for a certain period of time before it can start working. However, the redundant control system, especially the flight control system, has very high real-time requirements. The waiting time for startup will seriously affect the real-time performance of the redundant system. In order to solve the above technical problems, the present invention also provides a method that can perceive the completion of synchronization of nodes in the entire network. It is as follows:

[0062] In an embodiment of the present invention, a clock management method for a redundant real-time control system based on TSN is provided. Fig. 9 is a flowchart of a clock management method for a redundant real-time control system based on TSN according to an embodiment of the present invention, which is applied to the main CTC of the redundant real-time control system, such as Fig. 9 As shown, the process includes the following steps:

[0063] Step S92: After the node performs clock synchronization with the clock source, receiving clock synchronization status reporting events reported by each of the nodes, wherein the clock synchronization status reporting events are used to indicate whether the current node has completed clock synchronization with the clock source.

[0064] Among them, the node in the embodiment of the present invention is any one of a controller, an IO device and a TSN switch.

[0065] Before the clock source performs clock synchronization, the target host is configured as the main CTC and the backup CTC on each node (including terminal nodes and network nodes) of the redundant real-time control system network, and each node sends a clock synchronization status reporting event to the target host.

[0066] When the clock source is performing clock synchronization, it can use protocols such as 1588. The clock source synchronizes the time of the atomic clock on the TSN switch to the adjacent node. The adjacent node calculates the time of the current node based on the communication delay from the previous node to itself, plus the time in the message of a node, and so on. That is, each node calculates its own time. After each node completes the calculation, it reports it to the main CTC through the clock synchronization status reporting event.

[0067] In this embodiment, the redundant real-time control system can use an external clock source, or a TSN switch with a built-in rubidium clock as the system's clock source, and distribute high-precision time to each node through a network composed of TSN switches; use an external configuration mode to improve the efficiency of clock switching; deploy multi-domain clocks corresponding to multiple clock sources, and cooperate with CTC to achieve unified and fast clock domain switching across the entire network.

[0068] Step S94, sending a notification message to all nodes according to the clock synchronization state reporting event, wherein the notification message is used to indicate that all nodes of the redundant real-time control system have completed system-level synchronization;

[0069] Among them, completing system-level synchronization means that all nodes of the redundant real-time control system complete clock synchronization.

[0070] Through the above steps, after the node starts to synchronize the clock with the clock source, the clock synchronization status reporting event reported by each node is received, wherein the clock synchronization status reporting event is used to indicate whether the current node has completed the clock synchronization with the clock source; a notification message is sent to all nodes according to the clock synchronization status reporting event, wherein the notification message is used to indicate that all nodes of the redundant real-time control system have completed the system-level synchronization, and the completion of the system-level synchronization of the nodes in the whole network is perceived through the clock synchronization status reporting event reported by the node to the CTC, which solves the technical problem that when TSN is applied to the redundant real-time control system in the relevant technology, the redundant real-time control system needs to wait for a certain time to start working, which affects the real-time performance of the system because the existing TSN technology has no mechanism to perceive that the nodes in the whole network have completed the system-level synchronization, thereby improving the reliability and real-time performance of the redundant real-time control system, and can complete real-time services with higher requirements for time certainty.

[0071] The master CTC and the standby CTC of this embodiment monitor each other through heartbeat messages. The master CTC and the standby CTC simultaneously receive clock synchronization status reporting events, master clock source failure alarms, and clock desynchronization alarm information of all network nodes. By default, the master CTC notifies all nodes in the network of the time when all nodes complete clock synchronization, the unified clock domain switching time, and the gating effective time. When the master CTC fails, the standby TCT is upgraded to the master TCT to perform related work on its behalf.

[0072] Optionally, after determining the main centralized clock configuration CTC and the backup CTC of the redundancy real-time control system, it also includes: judging at the backup CTC whether the heartbeat message of the main CTC is normal; if the heartbeat message of the main CTC is abnormal; performing a master-slave switching on the redundancy real-time control system, switching the backup CTC to the main CTC.

[0073] The main CTC and the standby CTC set heartbeat detection messages, and the message detection period is adjustable. If the heartbeat message of the other party is not received for more than a preset number of periods, the other party is judged to be faulty. For example, if the standby CTC does not receive the heartbeat message of the main CTC for more than 3 periods, the standby CTC is upgraded to the main CTC.

[0074] In this embodiment, sending a notification message to all nodes according to the clock synchronization status reporting event includes: judging whether all nodes have completed clock synchronization with the clock source based on the clock synchronization status reporting event; after all nodes have completed clock synchronization with the main clock source, the main CTC sends a notification message to all nodes.

[0075] Optionally, the main CTC may send a notification message to all nodes after a designated node in the redundancy real-time control system (such as a node deployed farthest from the main clock source, a node to execute services, etc.) or a preset number of nodes completes clock synchronization with the main clock source.

[0076] By parsing the node identifier in each clock synchronization status reporting event and counting whether all nodes of the redundant real-time control system report the clock synchronization status reporting event to the main CTC, if all nodes report the clock synchronization status reporting event to the main CTC, it is determined that all nodes have completed the clock synchronization with the main clock source.

[0077] Optionally, the notification message may also carry the time when the system-level synchronization is completed, that is, the time when all nodes complete the clock synchronization. The redundancy control system may also uniformly determine the sending time of the notification message as the time when the system-level synchronization is completed.

[0078] By adopting the solution of this embodiment, the time for completing system-level synchronization is determined according to the time when all nodes complete clock synchronization with the main clock source. The time for completing clock synchronization of all nodes in the entire network can be perceived during the application of redundant real-time systems, thereby improving the accuracy of perceiving the completion of system-level synchronization of all nodes in the entire network.

[0079] In one implementation of this embodiment, the redundancy real-time control system includes a main clock source and several backup clock sources, each of the main clock source and the backup clock source is deployed on a TSN switch, and before the main CTC receives the clock synchronization status reporting event reported by each of the nodes, it also includes: monitoring whether the main CTC receives a main clock source failure alarm; if the main CTC receives a main clock source failure alarm, sending a clock domain switching message to all nodes so that all nodes uniformly switch the main clock source to the backup clock source.

[0080] In this implementation, the master clock source and several backup clock sources monitor each other through heartbeat messages. When the backup clock source detects an abnormality in the heartbeat detection between the master and backup clock sources, the backup clock source reports a master clock source fault alarm to the master CTC and the backup CTC, and the master CTC notifies all nodes of the clock domain switching message. Based on the hot backup mechanism of protocols such as 802.1ASdm, all nodes in the entire network can uniformly switch the clock source.

[0081] By adopting the solution of this embodiment, the clock domain switching message is sent to the master CTC and all the nodes in the network, which solves the technical problem that all the nodes in the network cannot uniformly switch the clock domain after the main clock source fails, and improves the fault tolerance of the redundant real-time control system.

[0082] In the traditional bus-based redundancy control system, the bus controller broadcasts a T0 time before the start of each business cycle. During this cycle, each node uses T0 as a reference and sends and receives data according to the planned schedule table offset. When migrating from "bus interconnection" to "switched network", it is necessary to be compatible with the linear scheduling mechanism of the traditional bus, and try to avoid major modifications to upper-layer applications. The processing of relative time T0 needs to be considered, and there is currently no relevant solution in the industry. The embodiment of the present invention proposes to calculate the absolute time value TSN gating effective time and send it to all nodes in the entire network by CTC, align the gating scheduling starting points of terminals and networks, and achieve an effect similar to the relative time T0 of the traditional bus, and the TSN gating effective time supports secondary configuration and high-reliability deployment.

[0083] In one implementation of the present embodiment, after sending a notification message to all nodes according to the clock synchronization status reporting event, it also includes: reading the flag bit status of the target flag bit, wherein the flag bit status is used to indicate whether the gating effective time needs to be announced; judging whether the flag bit status is set; if the flag bit status is set, the main CTC announces the gating effective time to the nodes in the system, such as the multiple controllers and IO devices, and clears the target flag bit.

[0084] Optionally, the target flag is a "gating effective time reconfiguration" flag, including two flag states: a set state and a non-set state, which can be represented by 1 and 0 respectively. The set state indicates that the gating effective time needs to be notified, and the non-set state indicates that the gating effective time does not need to be notified. The target flag is set by default. After the gating effective time notification is completed, this flag is cleared to avoid repeated notification of the gating effective time.

[0085] When the main CTC determines that all nodes have completed clock synchronization based on the clock synchronization status reporting events of each node, if it is necessary to notify the gating effective time, it will uniformly notify each node that the system-level synchronization has been completed, and the main CTC will back up the synchronization status of each node to the backup CTC; all nodes in the entire network of the redundancy real-time control system use the gating effective time as the reference time to carry out deterministic business scheduling and transmission.

[0086] By adopting the solution of this embodiment, a solution for notifying the gating effective time of all nodes in the redundant real-time control system is realized. The main CTC sends the gating effective time to all nodes in the entire network, which can align the gating scheduling starting points of the terminals and networks in the redundant real-time control system and achieve the effect of clock synchronization.

[0087] In one example, in order to wait for all nodes to complete clock synchronization and for the computing node application layer scheduling to be ready, the main CTC sets a delay time before notifying the gating effective time.

[0088] The master CTC notifies all nodes of the gating effective time, including: obtaining the set delay time of the redundancy real-time control system, and obtaining the current system time of the master CTC when completing system-level synchronization; calculating the gating effective time based on the set delay time and the current system time; the master CTC notifies all nodes of the gating effective time.

[0089] In this example, the redundancy real-time control system supports setting a delay time from the completion of system-level synchronization to the gating effective time. The delay time can be adjusted according to the needs of the actual deployment scenario. If the gating effective time does not require a delay, the delay time is set to 0, and the gating effective time is directly calculated based on the current system time when the main CTC completes system-level synchronization, and the current system time is notified to all nodes as the gating effective time.

[0090] If the set delay time is greater than 0, the main CTC starts to calculate the delay from the current system time when the system-level synchronization is completed. When the delay reaches the set delay time, and the "Gating Effective Time Reconfiguration" flag is set, the current system time + set delay time is used as the gating effective time to notify all nodes. All nodes in the entire network use this time as a benchmark to carry out deterministic business scheduling and transmission. The application layer of the redundant real-time control system sends data, and the network layer opens the corresponding gating list. The main CTC is synchronized and backed up to the backup CTC, and the "Gating Effective Time Reconfiguration" flag is cleared.

[0091] By adopting the solution of this example, a delay time can be set for the redundant real-time control system, thereby improving the flexibility of clock synchronization. The redundant real-time control system can be compatible with various types of controllers, thereby improving the compatibility of the redundant real-time control system.

[0092] In one implementation scenario, obtaining the set delay time of the redundancy real-time control system includes: obtaining the relative time between the task scheduling time and the reference time of the controller in the redundancy real-time control system in the current business cycle; and determining the relative time as the set delay time.

[0093] Optionally, the controller on the redundant real-time control system can execute various types of tasks, and the delay time is set to be greater than 0. The set delay time can be read from the controller's scheduling table, and the scheduling table stores the offset (relative time) between the scheduling time of each task and the reference time. When the controller executes a task, if it is based on a bus-type interconnection network, the main controller broadcasts a T0 moment as a reference time before the start of the current business cycle. During this cycle, each node uses T0 moment as a reference time to schedule tasks. In the switching network of this embodiment, when the controller in the redundant real-time control system schedules tasks, the relative time between the task scheduling time of the current business cycle and the reference time is determined as the set delay time to achieve compatibility with the bus-type interconnection. The CTC sends the gated effective time of the absolute time value to all nodes in the entire network, aligning the gated scheduling starting points of the terminals and the network, and achieving an effect similar to the relative time T0 in the bus-type interconnection network.

[0094] By adopting the solution of this embodiment, when the redundancy control system migrates from the bus-type interconnection to the switching network communication mechanism, the processing of relative time is considered. By setting the delay time, the gating effectiveness time of the network layer is aligned with the task scheduling time of the application layer. This can be compatible with the linear scheduling mechanism of the traditional bus, and the absolute time of the TSN high-precision clock synchronization can be mapped to the relative time of the bus-type interconnection, avoiding major modifications to the upper-layer applications of the controller.

[0095] Optionally, after clearing the target flag bit, the method further includes: determining whether the main CTC receives a system-level fault message; if the main CTC receives a system-level fault message, configuring the flag bit state of the target flag bit to a set state.

[0096] Optionally, system-level failures may be common cause failures, interaction failures, voting and monitoring failures, etc.

[0097] Common cause failures include failures caused by environmental factors and failures caused by design or manufacturing defects. Failures caused by environmental factors are extreme temperature changes that may affect all channels of the redundant real-time control system. For example, the temperature is extremely low at high altitudes. If the thermal insulation design of the flight control system is not good, it may cause the performance of electronic components to deteriorate, and key components such as sensors and processors of multiple channels may experience parameter drift or abnormal operation at the same time. Electromagnetic interference is also an important factor. If the aircraft encounters a strong electromagnetic pulse, such as flying near a thunderstorm or being attacked by enemy electromagnetic weapons, multiple channels of the redundant real-time control system may be interfered with at the same time, signal transmission errors may occur, and the normal operation of the system may be affected. Failures caused by design or manufacturing defects are loopholes in software design that may affect all channels. If the flight control system software has defects in algorithm design, such as errors in flight control law calculation, then all channels based on the software will operate according to wrong instructions, resulting in serious consequences such as loss of control of flight attitude. Components with quality problems are used in the hardware manufacturing process. For example, a batch of chips has internal short circuit risks. When these chips are installed in multiple channels, multiple channels will fail at the same time.

[0098] Interaction failures include inter-channel communication failures and resource competition failures. Inter-channel communication failures are caused by the fact that a large amount of data communication is required between channels of a redundant real-time control system to coordinate work. If there is a problem with the communication link, such as damage to the data bus or errors in the communication protocol, the channels cannot effectively share data and status information. A channel failure may propagate error signals to other channels through the communication line. For example, if a sensor of a channel fails and sends incorrect flight attitude data, after transmitting it to other channels through the communication link, it may cause other channels to make incorrect judgments. Resource competition failures occur when multiple channels compete for limited system resources (such as computing resources, storage resources, etc.) at the same time, which may cause system failures. For example, under high load conditions, multiple channels require a large amount of CPU calculations to process complex flight control tasks. If the processor's computing power is insufficient, the computing speed of each channel may decrease, and the correct control instructions may not be output in time. Storage resource competition may also cause problems. If multiple channels write data to a storage device at the same time, data conflicts may occur, causing some data to be lost or damaged, thereby affecting the normal operation of the system.

[0099] Voting and monitoring failures include voting machine failures and monitoring system failures. The voting machine in the voting machine failure is a key component in the redundant real-time control system, which is used to integrate the information of multiple channels and make the final decision. If the voting machine itself has a hardware failure, such as internal circuit damage, it may not be able to correctly compare and select channel data. Voting algorithm errors are also a potential problem. If the voting algorithm cannot effectively identify and exclude the data of the wrong channel, it may cause the wrong control instructions to be output. For example, in the majority voting mechanism, if the correct data of a few channels is mistakenly judged as abnormal, and the data of the majority of wrong channels is used, the flight control of the aircraft will deviate.

[0100] In the case of a monitoring system failure, the monitoring system is used to monitor the working status of each channel of the redundant real-time control system. If the monitoring system sensor fails, such as the sensor used to monitor the temperature of the channel processor, it will not be able to detect abnormal conditions such as channel overheating in time. There may also be problems with the software part of the monitoring system. For example, the alarm threshold is set incorrectly, and when a minor fault occurs in the channel, the alarm is not triggered in time, resulting in further development of the fault, which ultimately affects the normal operation of the entire system.

[0101] When the main CTC receives a system-level fault report, each node of the redundancy real-time control system sets the target flag again, triggering another notification of the gating effective time. The main CTC reads the target flag as a set state, notifies the gating effective time to multiple nodes of the redundancy real-time control system again, and clears the target flag.

[0102] By adopting the solution of this embodiment, the gate effectiveness time of TSN supports secondary configuration, thereby improving the fault tolerance and reliability of the redundant real-time control system when a system-level failure occurs.

[0103] The solution of this embodiment provides a high-real-time and high-reliability redundant data transmission solution based on TSN technology for scenarios such as aviation equipment flight control and ship real-time control. It provides solutions to the problems faced by TSN technology in the application of redundant real-time systems, such as the inability to perceive the clock synchronization time of all network nodes, the inability of all network nodes to uniformly switch clock domains after the main clock source fails, and the inability of traditional bus task scheduling relative time T0 to correspond to TSN absolute time. It also configures and selects TSN technical protocols in a scenario-based manner based on the business characteristics of the real-time system, providing a system-level solution for building redundant real-time systems based on TSN technology.

[0104] Fig.10 : is a schematic diagram of the process of CTC service processing in an embodiment of the present invention, including:

[0105] Set the main CTC and backup CTC roles;

[0106] Configure the target host IP address on each node in the entire network (including controllers, IO devices, etc.) as the IP address of the primary CTC and the backup CTC, so that each node can send information such as clock synchronization completion events, primary clock source failure alarms, and clock out-of-sync alarms to the primary CTC / backup CTC;

[0107] The main CTC and the standby CTC set up heartbeat detection messages to determine whether the heartbeat messages between the main CTC and the standby CTC are normal. If abnormal, the standby CTC is upgraded to the main CTC. If normal, the main CTC continues to execute. The main CTC and the standby CTC simultaneously receive clock synchronization status reporting events, main clock source failure alarms, and clock desynchronization alarm information from all network nodes. By default, the main CTC notifies all network nodes of the time when all nodes complete clock synchronization, the unified clock domain switching time, and the gating effectiveness time. When the main CTC fails, the standby TTC is upgraded to the main CTC and performs related work on its behalf. The following is an explanation of the main CTC processing flow, and the standby CTC processing flow is similar;

[0108] Determine whether the master CTC has received the master clock source fault alarm, and perform heartbeat message detection between the master and standby clock sources. When the standby clock source detects that the heartbeat between the master and standby clock sources is abnormal, the standby clock source reports the master clock source fault alarm to the master CTC / standby CTC. If the master clock source fault alarm is received, the master CTC notifies all nodes of the clock domain switching message, so that all nodes in the entire network can uniformly switch the clock source.

[0109] The main CTC determines whether all nodes have completed clock synchronization. The main CTC receives the clock synchronization status reporting events reported by each node. When the main CTC determines that all nodes have completed clock synchronization based on the clock synchronization status reporting events of each node, it uniformly notifies each node that the system-level synchronization has been completed, and backs up the synchronization status of each node to the standby CTC;

[0110] The main CTC determines whether the set delay time has arrived;

[0111] After the set delay time is reached, determine whether the "Gating Effective Time Reconfiguration" flag is set. If the "Gating Effective Time Reconfiguration" flag is set, the current system time + delay time is used as the gating effective time to be notified to all nodes. All nodes in the entire network use this time as a benchmark to carry out deterministic business scheduling and transmission. Synchronously back up to the backup CTC node, and clear the "Gating Effective Time Reconfiguration" flag. Pre-set the "Gating Effective Time Reconfiguration" flag, which is set by default. After the gating effective time notification is completed, this flag is cleared, and the gating effective time will not be notified repeatedly.

[0112] When the main CTC receives a system-level fault report, it will set this flag again to trigger another notification of the gating effectiveness time.

[0113] By adopting the solution of this embodiment, the redundant real-time control system based on TSN can realize the unified bearing of real-time and non-real-time services, and can ensure the deterministic transmission of real-time control services, which can lay the foundation for the unified network bearing of the whole aircraft / whole ship. In addition to the high reliability, high real-time and high security characteristics of traditional buses, the redundant real-time control system based on TSN also has the advantages of high transmission bandwidth, mature industrial chain, low deployment cost and great development potential.

[0114] The TSN-based redundant real-time control system of this embodiment can be applied to flight control systems / navigation control systems, which will realize the transformation of aviation equipment flight control systems / ship real-time control systems from a "computing-centric" architecture to a "switch-centric" architecture, and from a "bus-based interconnection" to a "switch-based network", compressing the signal transmission path, flattening information interaction, increasing bandwidth while improving transmission efficiency, promoting the development of the next generation of airborne / shipborne electronic architecture, and improving the performance of airborne / shipborne equipment.

[0115] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present invention.

[0116] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments and optional implementation modes, and this embodiment will not be described in detail here.

[0117] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0118] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0119] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0120] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0121] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0122] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a controller or a network device, etc.) to perform all or part of the steps of each embodiment method of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk, etc., various media that can store program codes.

[0123] The above are only preferred implementations of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A redundant real-time control system based on TSN, comprising: Centralized clock configuration CTC, controller, input and output IO devices, and time-sensitive network TSN switches; Each main controller is provided with one or more standby controllers in working state, each main IO device is provided with one or more standby IO devices in working state, and each main TSN switch is provided with one or more standby TSN switches in working state; the controllers and IO devices in the system form a switching network through the TSN switch; At least two TSN switches are deployed with clock sources, including a main clock source and at least one backup clock source. The clock sources transmit clock signals hop by hop through adjacent links. The CTC is connected to each of the clock sources. The CTC includes a master CTC and a backup CTC. The CTC is used to manage the clock domain of the system and sense the clock synchronization status of all nodes in the system.

2. According to the system of claim 1, the redundant real-time control system is a dual-redundant real-time control system, including two controllers and two TSN switches, one of the two TSN switches deploys a main clock source and the other deploys a backup clock source.

3. According to the system of claim 1, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and two TSN switches, one of the two TSN switches deploys a main clock source and the other deploys a backup clock source.

4. According to the system of claim 1, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and four TSN switches, one of the four TSN switches deploys a main clock source and the other deploys a backup clock source.

5. According to the system of claim 1, the redundant real-time control system is a quad-redundant real-time control system, including four controllers and four TSN switches, one of the four TSN switches is deployed with a main clock source, and the other three are deployed with backup clock sources.

6. The system according to any one of claims 1 to 5, characterized in that: The main CTC is also used to: After the node performs clock synchronization with the clock source, receiving a clock synchronization status reporting event reported by each of the nodes, wherein the clock synchronization status reporting event is used to indicate whether the current node has completed clock synchronization with the clock source; the node is any one of a controller, an IO device, and a TSN switch; A notification message is sent to all nodes according to the clock synchronization state reporting event, wherein the notification message is used to indicate that all nodes of the redundant real-time control system have completed system-level synchronization.

7. The system according to claim 6, characterized in that Sending a notification message to all nodes according to the clock synchronization status reporting event includes: Determine whether all nodes have completed clock synchronization with the clock source based on the clock synchronization status reporting event; After all nodes complete clock synchronization with the master clock source, the master CTC sends a notification message to all nodes.

8. The system according to claim 6, characterized in that The redundant real-time control system includes a main clock source and a plurality of backup clock sources, each of the main clock source and the backup clock source is deployed on a TSN switch, and before receiving the clock synchronization status reporting event reported by each of the nodes, the main CTC is further used to: Monitoring whether the master CTC receives a master clock source failure alarm; If the master CTC receives a master clock source failure alarm, it sends a clock domain switching message to all nodes so that all nodes uniformly switch the master clock source to a backup clock source.

9. The system according to claim 6, characterized in that After sending a notification message to all nodes according to the clock synchronization state reporting event, the master CTC is further used to: Reading a flag bit state of a target flag bit, wherein the flag bit state is used to indicate whether a gating effective time needs to be notified; Determine whether the flag bit state is a set state; If the flag bit is in the set state, the master CTC notifies all nodes of the gating effective time and clears the target flag bit.

10. The system according to claim 9, characterized in that The main CTC notifies all nodes of the gate control effective time including: Obtaining the set delay time of the redundancy real-time control system, and obtaining the current system time of the main CTC when completing system-level synchronization; Calculate the gating effective time based on the set delay time and the current system time; The master CTC notifies all nodes of the gating effective time.

11. The system according to claim 10, characterized in that Obtaining the set delay time of the redundancy real-time control system includes: Obtaining the relative time between the task scheduling time of the controller in the redundancy real-time control system in the current business cycle and the reference time; The relative time is determined as the set delay time.

12. The system according to claim 9, characterized in that After clearing the target flag, the method further includes: Determining whether the master CTC receives a system-level fault message; If the master CTC receives a system-level fault message, the flag bit state of the target flag bit is configured to be a set state.

Citation Information

Cited By

  • Flight control and avionics integrated processing platform and method based on function separation multi-core processor

    CN121680225A