Cross interconnection redundancy communication method based on trackside safety communication platform
By splitting the communication node into four PIDs and crossing redundant configurations, the problem that external security devices have difficulty distinguishing the main and backup messages of the rail-side security communication platform is solved, and higher data transmission reliability and system availability are achieved.
Patent Information
- Application Number
- CN202510040449.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-23
AI Technical Summary
In the prior art, external security equipment is difficult to distinguish between primary and secondary messages in the rail-side security communication platform, resulting in the reliability and security of data transmission being affected.
Split a communication node into four PIDs and cross-redundantly configured on the rail-side security communication platform A and B and external security equipment A and B machines. During data transmission processing, different data fills the main and backup PIDs; during data reception processing, the main calculation processing unit MPU distinguishes the communication main PID according to its own main and backup state, and discards the message of the communication backup PID and does not perform processing.
It realizes the differential processing of data from different communication links by external security devices, improves the reliability of data transmission and the availability of the system, and increases the universality of the rail-side security communication platform.
Smart Images

Figure CN120034757A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of trackside safety communication platforms, and more specifically to a cross-connection redundant communication method based on trackside safety communication platforms. Background Art
[0002] For trackside products, reliability, correctness and safety are the indicators that must be met first. The safety level of the trackside safety communication platform is SIL4, and it adopts a two-by-two system architecture, including machine A and machine B with the same structure. One main and one standby dual machine hot standby operation. In any system, there are two main processing units MPU1 and MPU2, and multiple communication units MNCU. Different operating systems and compilers are used on MPU1 and MPU2, and the upper-level application software running is the same. There are multiple independent network ports on the communication unit MNCU for sending and receiving data. When the system receives data, the data is received by the communication unit MNCU and transmitted to the main processing unit MPU via the bus.
[0003] When the trackside safety communication platform interacts with external safety devices such as the train control center (TCC), unlimited block center (RBC) and temporary speed limit server (TSRS) for safety data, the communication unit MNCU generally adopts a red and blue network redundant network structure, and the main processing unit MPU dual system performs logical operations and data processing at the same time. In order to ensure the reliability of safety data transmission during communication, the external safety equipment also adopts a dual-machine hot standby method, but the host of the external safety device only processes the data sent by the trackside safety communication platform main system. Therefore, the data sent by the trackside safety communication platform backup system should be different from the main system to facilitate the distinction between the main and backup messages.
[0004] In the prior art, the patent with publication number CN119105880A discloses a multi-channel data receiving and processing method and device for a secure computer system, the secure computer system includes a data processing unit and multiple communication units, the method includes the following steps: first, each communication unit performs channel separation and extraction on the multi-channel message received from the external device, and then uses the data security mask and the software security mask to process the separated message into a bus message, and broadcasts it to all data processing units through the bus; after the FPGA of the data processing unit obtains the bus message, it uses the hardware security mask to process it to obtain the message rBusMsg, and sends it to the data processing unit; the data processing unit performs channel restoration, merging and verification on the received message rBusMsg, and sends it to the application. Compared with the prior art, the present invention has the advantages of improving the stability, reliability and security of multi-channel data transmission in the secure computer system.
[0005] In the above patents, in order to ensure the reliability of secure data transmission, two security devices are generally connected in the form of dual-system cross-connection. A dual-system cross-connected communication node consists of four peripheral node numbers PID, with a total of eight channels. However, the external security device does not perform differential processing on the data of different communication links in a communication node, which makes it difficult to distinguish between primary and standby messages. Summary of the invention
[0006] In order to overcome the defects in the above-mentioned prior art, the present invention discloses a cross-connection redundant communication method based on a trackside safety communication platform. The purpose of the present invention is to meet the requirements of external safety equipment for different processing of different communication link data in a communication node. The present invention splits a communication node into four PIDs, and the four PIDs are cross-redundantly configured on the trackside safety communication platform A, B system and the external safety equipment A, B machine. When sending and processing data, the four communication nodes are grouped in pairs, divided into two communication main PIDs and two communication standby PIDs. The main operation processing unit MPU can fill the main and standby PIDs with different data respectively, meeting the diversified requirements of different external safety equipment, and increasing the versatility of the trackside safety communication platform; when receiving and processing data, the trackside safety communication platform also only processes the data sent by the main system of the external safety equipment. Therefore, after the communication unit MNCU of the trackside safety communication platform receives the messages of the four PIDs respectively, the main operation processing unit MPU first distinguishes the communication main PID according to its own main and standby status, and then discards the message of the communication standby PID without processing, while ensuring the transmission reliability, it does not affect the performance of the trackside safety communication platform. The present invention satisfies the requirement of external security equipment for differential processing of different communication link data in a communication node, while improving the reliability of data transmission and the availability of the system. In order to achieve the above objectives, the technical solution adopted by the present invention is: A cross-connected redundant communication method based on a trackside safety communication platform includes: two redundant external safety devices are arranged to communicate with two trackside safety communication platforms, the two external safety devices are set with the same communication node address, the two external safety devices communicate with the same communication node at the same time, one communication node includes four communication node unit PIDs, two of the four PIDs are grouped in pairs, and are divided into two communication main PIDs and two communication standby PIDs, the four PIDs are cross-configured on the trackside safety communication platform and the external safety device, wherein: When processing data transmission, the trackside safety communication platform performs differential processing according to the current active and standby status of the trackside safety communication platform and the requirements of the external safety equipment for receiving data, and fills different data into the active PID and standby PID respectively; When receiving and processing data, the trackside safety communication platform distinguishes between primary and backup communications through the PID of the message, and only processes the messages corresponding to the primary system PID of the trackside safety communication platform. The messages corresponding to the backup system PID of the trackside safety communication platform are directly filtered by the main processing unit MPU of the trackside safety communication platform.
[0007] Preferably, each PID is equipped with two channels to satisfy the dual network redundant communication of the red network and the blue network.
[0008] Preferably, the two redundant external safety devices are peripheral A and peripheral B. During operation, one of the peripheral A and peripheral B serves as a host and the other serves as a standby. The peripheral A corresponds to PID0 and PID1 of the four PIDs, and the peripheral B corresponds to PID2 and PID3 of the four PIDs. The setting method of a group of four PIDs is: PID0 % 4 = 1, communicating with the trackside safety communication platform A; PID1 = PID0 + 1, communicating with the trackside safety communication platform B; PID2 = PID0 + 2, communicating with the trackside safety communication platform A; PID3 = PID0 + 3, communicates with the trackside safety communication platform B.
[0009] Preferably, the trackside safety communication platform comprises a trackside safety communication platform system A and a trackside safety communication platform system B of a two-by-two structure; during operation, one of the trackside safety communication platform system A and the trackside safety communication platform system B is a main system, and the other is a backup system, and the two machines, one main and one backup, are in hot standby operation; In the main system and the backup system, any system includes a main processing unit MPU1 and a main processing unit MPU2, and multiple communication units MNCU; the main processing unit MPU1 and the main processing unit MPU2 use different operating systems and compilers, and run the same upper-level application software; the communication unit MNCU is provided with multiple independent network ports for sending and receiving data; when receiving data, the data is received by the communication unit MNCU and transmitted to the main processing unit MPU via the bus.
[0010] Preferably, the data transmission process comprises the following steps: S101, read the security data RSD that the application needs to send, and sequentially pass it into the protocol security layer sending queue and the protocol communication layer sending queue, and perform protocol security layer SFM processing and protocol communication layer CFM processing; S102, taking out the application sending safety data RSD processed by the protocol in the first channel of the current PID; S103, processing the retrieved application-sent safety data RSD, and reconstructing the safety data RSD sent externally by the main system and the backup system of the trackside safety communication platform; Preferably, step S103 includes: judging the message type that needs to reconstruct the message header according to whether the current system is the main system or the backup system of the trackside safety communication platform, and whether it is the A system or the B system, and filling the data header of the safety data RSD sent by the application, and reassigning the first byte and the second byte of the safety data RSD when filling; The message types include A master message reconstruction Rebuild_A_Master, B master message reconstruction Rebuild_B_Master, A standby message reconstruction Rebuild_A_Slave and B standby message reconstruction Rebuild_B_Slave.
[0011] S104, calculating the CRC16 of the reconstructed application-sent safety data RSD, and filling it to the last two bytes of the data of the application-sent safety data RSD; S105, respectively obtaining the PIDs of the main system and the backup system of the trackside safety communication platform for external communication; Preferably, in step S105, the PIDs of the main system of the trackside safety communication platform for external communication are Master_Pid_a and Master_Pid_b; the PIDs of the standby system of the trackside safety communication platform for external communication are Slave_Pid_a and Slave_Pid_b.
[0012] S106, generating a message header of a multicast message sent to the communication unit MNCU based on the acquired PID; Preferably, step S106 includes: combining the message header of the safety data RSD reconstructed in step S103 and the message tail of the CRC check code in step S104 as the message header of the message to be sent to the communication unit MNCU.
[0013] S107, combining the message header of the multicast message and the reconstructed safety data RSD into a multicast message sent to the communication unit MNCU, and sending the multicast message to the communication unit MNCU via the bus; S108, the communication unit MNCU parses the bus message, restores the four PIDs in the multicast message respectively, and reconstructs the message of the main PID and the message of the backup PID respectively according to the requirements of the external safety device for receiving data; S109. The communication unit MNCU sends a reconstruction message to an external safety device.
[0014] Preferably, the data receiving process comprises the following steps: S201, after receiving the safety data RSD sent by the external safety device, the communication unit MNCU transmits it to the main processing unit MPU via the bus; S202, the main processing unit MPU reads the safety data RSD, extracts the PID of the safety data RSD and records it; S203, the main processing unit MPU determines whether the active / standby status of the trackside safety communication platform in this cycle has changed compared with the previous cycle. If so, the main PID of the communication is recalculated according to whether the trackside safety communication platform is system A or system B in this cycle and the active / standby status, and the process goes to step S204; if not, the process goes directly to step S204; Preferably, step S203 includes: the main processing unit MPU obtains the system master-slave status of the current subsystem in this cycle and the previous cycle respectively. If the previous cycle was the master system and the current cycle became the standby system, or the previous cycle was the standby system and the current cycle became the master system, then the main PID of the communication is recalculated according to whether the subsystem is machine A or machine B in this cycle and the master-slave status.
[0015] S204, filtering the received safety data RSD sent to the backup system of the trackside safety communication platform: comparing the calculated PID value of the main system of the trackside safety communication platform with the four PIDs of the current communication node. If the PID value of the four PIDs is different from the PID value of the main system, the safety data RSD corresponding to the PID is filtered and no subsequent processing is performed. Otherwise, the process goes to step S205; Preferably, step S204 includes: according to the current master-slave status of the trackside safety communication platform, transferring four PIDs of a communication node into the msater_rets array or the slave_rets array for comparison; If the trackside safety communication platform is the master system, the four PIDs are respectively transferred to the master_rets array. If they are different from the main PID values of the communication, the safety data RSD corresponding to the PID in the array is filtered without subsequent processing, otherwise it goes to step S205; If the trackside safety communication platform is a backup system, the four PIDs are respectively transferred into the slave_rets array. If they are different from the main PID values of the communication, the safety data RSD corresponding to the PID in the array is filtered without subsequent processing, otherwise it goes to step S205; Among them, master_rets is the array of the trackside safety platform master system filtering external safety equipment and sending to the trackside safety platform backup system, and slave_rets is the array of the trackside safety platform backup system filtering external safety equipment and sending to the trackside safety platform backup system.
[0016] S205, the safety data RSD sent by the external safety device to the main system of the trackside safety communication platform is sequentially transmitted to the communication layer receiving queue and the safety layer receiving queue, and the protocol communication layer CFM processing and the protocol safety layer SFM processing are performed; S206. Pass the security data RSD processed by the protocol to the upper layer application.
[0017] Beneficial effects of the present invention: 1. The present invention splits a communication node of a trackside safety communication platform and an external safety device into four PIDs, and the four PIDs are cross-redundantly configured on the trackside safety communication platform A, B system and the external safety devices A, B. When receiving and processing data, the main processing unit MPU first distinguishes the communication main PID according to its own main and standby status, and then discards the message of the communication standby PID without processing, while ensuring the transmission reliability, it does not affect the performance of the trackside safety communication platform; when sending and processing data, different data is filled for the main and standby PIDs, meeting the different requirements of the external safety device for the corresponding channel data of different PIDs while supporting the diversified needs of different external safety devices, increasing the versatility of the trackside safety communication platform.
[0018] 2. The present invention expands a communication node from a dual-channel to an eight-channel channel, which greatly increases the stability and reliability of data transmission while ensuring safety. When a series of external safety devices fails, four-channel redundant data transmission can still be performed through two PIDs of the trackside safety communication platform in a single-system cross-interconnection manner, thereby increasing the availability of the system.
[0019] 3. The trackside safety communication platform and external safety equipment of the present invention both adopt a dual-machine hot standby working mode, realizing data transmission between the dual systems and having the advantage of high reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a structural schematic diagram of the trackside safety communication platform of the present invention; Figure 2 It is a schematic diagram of cross-connection between the trackside safety communication platform and external safety equipment of the present invention; Figure 3 The present invention is a specific sending and processing flow of eight-channel cross-connection safety data messages; Figure 4 The present invention provides a specific receiving and processing flow of eight-channel cross-connection safety data messages. DETAILED DESCRIPTION
[0021] The concept, specific structure and technical effects of the present invention will be clearly and completely described below in conjunction with the embodiments and drawings to fully understand the purpose, characteristics and effects of the present invention.
[0022] Example 1 A cross-connection redundant communication method based on a trackside safety communication platform, the method comprising the following contents: Communication configuration rules: (1) The two external safety devices (referred to as peripheral A and peripheral B) that communicate with the trackside safety communication platform should be set with the same communication node address Node_Addr, that is, the two external safety devices communicate with the same communication node at the same time.
[0023] (2) A communication node Node corresponds to four PIDs, which are cross-configured on the trackside safety communication platform and external safety devices. Among them, external safety device A corresponds to PID0 and PID1, and external safety device B corresponds to PID2 and PID3. The setting rules for a group of PIDs are: PID0 % 4 = 1, communicating with the trackside safety platform A; PID1 = PID0 + 1, communicating with the trackside safety platform B system; PID2 = PID0 + 2, communicating with the trackside safety platform A; PID3 = PID0 + 3, communicates with the trackside safety platform B system.
[0024] Through this configuration rule, the trackside safety platform can distinguish between active and standby communications by the PID of the message when receiving and processing; when sending and processing, the trackside safety communication platform can make differential processing according to the active and standby status of the current system and the requirements of the external safety equipment for receiving data, and fill different data into the active and standby PIDs respectively.
[0025] (3) When receiving and processing data, only the messages corresponding to the main system PID sent to the trackside safety communication platform are processed, and the messages corresponding to the backup system PID are directly filtered in the main processing unit MPU without being processed.
[0026] (4) Each PID is equipped with two communication channels to meet the dual-network redundant communication of the red and blue networks.
[0027] Trackside safety communication platform processing principles: 1. Data transmission and processing: (1) Read the security data RSD that the application needs to send, and pass it to the protocol security layer send queue and the protocol communication layer send queue in turn, perform protocol security layer (SFM) and protocol communication layer (CFM) processing, and obtain the application send data after protocol processing.
[0028] (2) Take out the application-sent security data RSD after protocol processing in the first channel of the current PID.
[0029] (3) According to whether the current system is the main system or backup system of the trackside safety communication platform, and whether it is machine A or machine B, determine the message type that needs to be reconstructed (the message type can be divided into A master message reconstruction Rebuild_A_Master, B master message reconstruction Rebuild_B_Master, A backup message reconstruction Rebuild_A_Slave and B backup message reconstruction Rebuild_B_Slave), and fill in the data header of the safety data RSD sent by the application.
[0030] (4) Calculate the CRC16 of the security data RSD sent by the current application and fill it into the last two bytes of the data of the security data RSD sent by the application for the external security device to verify the integrity and correctness of the data.
[0031] (5) Obtain the PIDs of the trackside safety communication platform host for external communication: Master_Pid_a, Master_Pid_b; and the PIDs of the trackside safety communication platform standby for external communication: Slave_Pid_a, Slave_Pid_b.
[0032] (6) Generate a message header for the multicast message to be sent to the communication unit MNCU. Combine the message header of the safety data RSD and the message footer of the CRC check code to form the message header of the message to be sent to the communication unit MNCU.
[0033] (7) The message header of the multicast message and the reconstructed safety data RSD are combined into a multicast message to be sent to the communication unit MNCU, and then sent to the communication unit MNCU via the bus.
[0034] (8) The communication unit MNCU parses the bus message and recovers the messages of the four PIDs in the multicast message: Master_Pid_a, Master_Pid_b, Slave_Pid_a and Slave_Pid_b. According to the requirements of the external safety device for receiving data, the messages of the main communication PID and the backup communication PID are reconstructed respectively.
[0035] (II) Data reception and processing: (1) After the communication unit MNCU receives the safety data RSD sent by the external safety device, it transmits it to the main processing unit MPU via the bus.
[0036] (2) The main processing unit MPU determines whether the active / standby status of the trackside safety platform has changed in this cycle compared to the previous cycle. The active / standby status of the current subsystem in this cycle and the previous cycle is obtained respectively. If the previous cycle was the active system and the current cycle became the standby system, or the previous cycle was the standby system and the current cycle became the active system, then the main PID of the communication needs to be recalculated based on whether the subsystem is A or B in this cycle and the active / standby status.
[0037] (3) Filter the received safety data RSD and compare the calculated PID value of the main system of the trackside safety platform with the four PIDs of the current communication node. master_rets is the array of the main system of the trackside safety platform filtering the external safety equipment to the standby system of the trackside safety platform, and slave_rets is the array of the standby system of the trackside safety platform filtering the external safety equipment to the standby system of the trackside safety platform. If the PID value is different from that of the main system, it is filtered and no subsequent processing is performed; otherwise, it goes to (4).
[0038] (4) The safety data sent by the external safety device to the main system of the trackside safety platform is transmitted to the communication layer receiving queue for protocol communication layer (CFM) processing.
[0039] (5) The safety data sent by the external safety device to the main system of the trackside safety platform is transmitted to the security layer receiving queue for protocol security layer (SFM) processing.
[0040] (6) The message is passed to the upper-layer application. Example 2 This embodiment is further described on the basis of embodiment 1. Figure 1 The schematic diagram of the structure of the trackside safety communication platform. A two-by-two-out-of-two structure trackside safety platform includes machine A and machine B with the same structure, with one main and one standby dual machine hot standby operation. In any system, it includes two main processing units MPU1 and MPU2 and multiple communication units MNCU. MPU1 and MPU2 use different operating systems and compilers, and run the same upper-layer application software. The communication unit MNCU has multiple independent network ports for sending and receiving data. When the system receives data, the data is received by the communication unit MNCU and transmitted to the main processing unit MPU via the bus.
[0041] One communication node Node corresponds to four PIDs, which are cross-configured on the trackside safety communication platform and external safety devices. Among them, the external safety device A corresponds to PID0 and PID1, and the external safety device B corresponds to PID2 and PID3, which is composed of eight channels in total. In the trackside safety platform, the configuration method is generally: PID0 % 4 = 1, communicating with the trackside safety platform A; PID1 = PID0 + 1, communicating with the trackside safety platform B system; PID2 = PID0 + 2, communicating with the trackside safety platform A; PID3 = PID0 + 3, communicates with the trackside safety platform B system.
[0042] When the trackside safety platform communicates with external safety equipment, the eight channels will receive messages with the same data content. After receiving and processing, the communication unit MNCU broadcasts the messages of the eight channels to the main processing unit MPU for further processing.
[0043] Figure 2 The figure is a schematic diagram of the cross-connection between the trackside safety communication platform and the external safety equipment. It is assumed that the trackside safety communication platform A is the main system and the external safety equipment A is the host.
[0044] Example 3 This embodiment is further described on the basis of embodiment 2. Figure 3 The specific sending and processing flow of the eight-channel cross-connection safety data message is shown in the figure, taking the sending of a node message of eight channels of a dual-system cross-connection as an example.
[0045] Step 1-1: Read the security data RSD that the application needs to send, and pass it into the protocol security layer sending queue for protocol security layer processing.
[0046] Step 1-2: The safety data RSD processed by the protocol security layer is transmitted to the sending queue of the protocol communication layer, and the protocol communication layer processes it to obtain the safety data RSD processed by the protocol.
[0047] Step 1-3: Get the RSD of the safety data after single-channel protocol processing. Because the data of the two channels in a PID are consistent, the RSD of the safety data of the first channel in the PID red and blue network after processing in steps 1-1 and 1-2 is obtained.
[0048] Step 1-4: Reconstruct the safety data RSD sent by the trackside safety communication platform master system. Taking the trackside safety communication platform A as an example, reconstruct the A master safety data RSD message header Rebuild_A_Master. Reassign the first byte and the second byte of the safety data RSD. Taking the RSSP-I communication protocol as an example, because the current trackside safety communication platform A machine is the master system, the first byte is assigned 0x01, representing the master system data; the second byte is assigned 0x80, representing the A machine.
[0049] Step 1-5: Reconstruct the safety data RSD sent by the standby system of the trackside safety communication platform. Taking the trackside safety communication platform B as an example, reconstruct the B standby safety data RSD message header Rebuild_B_Slave. Reassign the first byte and the second byte of the safety data RSD. Taking the RSSP-I communication protocol as an example, because the current trackside safety communication platform B is a standby system, the first byte is assigned 0x02, representing the standby system data; the second byte is assigned 0x81, representing the B machine.
[0050] Step 1-6: Calculate the CRC16 of the reconstructed application-sent safety data RSD, and fill it to the last 2 bytes of the data of the application-sent safety data RSD for the external safety device to verify the integrity and correctness of the data.
[0051] Step 1-7: Get the PIDs of the trackside safety communication platform for external communication respectively. If it is the master, the PIDs of the trackside safety communication platform master for external communication are Master_Pid_a and Master_Pid_b; if it is the backup, the PIDs of external communication are Slave_Pid_a and Slave_Pid_b. Taking trackside safety communication platform A as an example, Master_Pid_a = PID0, Master_Pid_b = PID2, Slave_Pid_a = PID1, and Slave_Pid_b = PID3.
[0052] Step 1-8: Generate a message header for the multicast message to be sent to the communication unit MNCU. Combine the message header of the safety data RSD obtained through steps 1-4, 1-5 and 1-6 with the message footer of the CRC checksum as the message header of the message to be sent to the communication unit MNCU. Taking the host machine A of the trackside safety communication platform as an example, the message headers are generated according to the PIDs. There are a total of four message headers for the multicast message sent to the communication unit MNCU, among which the message header contents of Master_Pid_a and Master_Pid_b are the same; the message header contents of Slave_Pid_a and Slave _Pid_b are the same.
[0053] Step 1-9: Generate a message for sending a multicast message to the communication unit MNCU. Combine the message header of the multicast message generated in step 1-8 and the safety data RSD reconstructed in steps 1-4 and 1-5 into a multicast message sent to the communication unit MNCU.
[0054] Step 1-10: Send to the communication unit MNCU via the bus.
[0055] Step 1-11: The communication unit MNCU parses the bus message and recovers the messages of the four PIDs in the multicast message: Master_Pid_a, Master_Pid_b, Slave_Pid_a and Slave_Pid_b. According to the requirements of the external safety device for receiving data, the messages of the main communication PID and the backup communication PID can be reconstructed respectively. Taking RSSP-I as an example, when the external safety device requires the data sent by the backup machine of the trackside safety communication platform to be 0, the safety data RSD corresponding to Slave_Pid_a and Slave_Pid_b are all set to 0 on the communication unit MNCU.
[0056] Example 4 This embodiment is further described on the basis of embodiment 3. Figure 4 The specific receiving and processing flow of the eight-channel cross-connection safety data message is shown below, taking the reception of a node message of an eight-channel dual-system cross-connection as an example.
[0057] Step 1-1: After receiving and processing, the communication unit MNCU broadcasts the messages of the eight channels to the main processing unit MPU respectively.
[0058] Step 1-2: The main processing unit MPU reads the safety data RSD received from the external safety device from the received message global variable memory pool, extracts the PID of the safety data RSD, and records it.
[0059] Step 1-3: Recalculate the main PID of the communication. The main processing unit MPU determines whether the master-slave status of the trackside safety platform has changed in this cycle relative to the previous cycle. If the previous cycle was the master system and the current cycle was the slave system, or the previous cycle was the slave system and the current cycle was the master system, the main PID will be switched. Taking trackside safety communication platform A as an example, if the previous cycle was the master system and the current cycle was the slave system, the main PID will be switched from PID0 and PID2 to PID1 and PID3; if the previous cycle was the slave system and the current cycle was the master system, the main PID will be switched from PID1 and PID3 to PID0 and PID2.
[0060] Step 1-4: Filter the safety data RSD received and sent to the trackside safety platform backup system according to the PID extracted from the safety data RSD in step 1-2 and the recalculated main PID of the communication. Compare the calculated PID value of the trackside safety platform main system with the 4 PIDs of the current communication node. master_rets is an array of the trackside safety platform main system filtering external safety devices sent to the trackside safety platform backup system, and slave_rets is an array of the trackside safety platform backup system filtering external safety devices sent to the trackside safety platform backup system. If it is different from the PID value of the main system, filter it and exit the receiving process directly; otherwise, proceed to the next step.
[0061] Step 1-5: The safety data sent by the external safety device to the main system of the trackside safety platform is transmitted to the communication layer receiving queue for protocol communication layer (CFM) processing.
[0062] Step 1-6: The safety data sent by the external safety device to the main system of the trackside safety platform is transferred to the safety layer receiving queue for protocol safety layer (SFM) processing.
[0063] Step 1-7: Pass the message after removing the protocol encapsulation to the upper-layer application.
[0064] The above is a specific description of the implementation mode of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present invention, and these equivalents or substitutions are all included in the scope defined by the claims of the present invention.
Claims
1. A cross-connection redundant communication method based on a trackside safety communication platform, characterized in that: include: Two redundant external safety devices are provided to communicate with two trackside safety communication platforms. The two external safety devices are provided with the same communication node address. The two external safety devices communicate with the same communication node at the same time. One communication node includes four communication node unit PIDs. The four PIDs are grouped in pairs, and are divided into two communication main PIDs and two communication standby PIDs. The four PIDs are cross-configured on the trackside safety communication platform and the external safety device, wherein: When processing data transmission, the trackside safety communication platform performs differential processing according to the current active and standby status of the trackside safety communication platform and the requirements of the external safety equipment for receiving data, and fills different data into the active PID and standby PID respectively; When receiving and processing data, the trackside safety communication platform distinguishes between primary and backup communications through the PID of the message, and only processes the messages corresponding to the primary system PID of the trackside safety communication platform. The messages corresponding to the backup system PID of the trackside safety communication platform are directly filtered by the main processing unit MPU of the trackside safety communication platform.
2. The cross-connection redundant communication method according to claim 1, characterized in that: Each PID is equipped with two channels to meet the dual-network redundant communication of the red and blue networks.
3. The cross-connection redundant communication method according to claim 1, characterized in that: The two redundant external safety devices are peripheral A and peripheral B. During operation, one of them is used as the host and the other as the standby. Peripheral A corresponds to PID0 and PID1 of the four PIDs, and peripheral B corresponds to PID2 and PID3 of the four PIDs. The setting method for a group of four PIDs is as follows: PID0 % 4 = 1, communicating with the trackside safety communication platform A; PID1 = PID0 + 1, communicating with the trackside safety communication platform B; PID2 = PID0 + 2, communicating with the trackside safety communication platform A; PID3 = PID0 + 3, communicates with the trackside safety communication platform B.
4. The cross-connection redundant communication method according to claim 1, characterized in that: The trackside safety communication platform includes a trackside safety communication platform A system and a trackside safety communication platform B system in a two-by-two structure; during operation, one of the trackside safety communication platform A system and the trackside safety communication platform B system is a main system and the other is a backup system, and the two systems are in hot standby operation; In the main system and the backup system, any system includes a main processing unit MPU1 and a main processing unit MPU2, and multiple communication units MNCU; the main processing unit MPU1 and the main processing unit MPU2 use different operating systems and compilers, and run the same upper-level application software; the communication unit MNCU is provided with multiple independent network ports for sending and receiving data; when receiving data, the data is received by the communication unit MNCU and transmitted to the main processing unit MPU via the bus.
5. The cross-connection redundant communication method according to claim 1, characterized in that: The data transmission process includes the following steps: S101, read the security data RSD that the application needs to send, and sequentially pass it into the protocol security layer sending queue and the protocol communication layer sending queue, and perform protocol security layer SFM processing and protocol communication layer CFM processing; S102, taking out the application sending safety data RSD processed by the protocol in the first channel of the current PID; S103, processing the retrieved application-sent safety data RSD, and reconstructing the safety data RSD sent externally by the main system and the backup system of the trackside safety communication platform; S104, calculating the CRC16 of the reconstructed application-sent safety data RSD, and filling it to the last two bytes of the data of the application-sent safety data RSD; S105, respectively obtaining the PIDs of the main system and the backup system of the trackside safety communication platform for external communication; S106, generating a message header of a multicast message sent to the communication unit MNCU based on the acquired PID; S107, combining the message header of the multicast message and the reconstructed safety data RSD into a multicast message sent to the communication unit MNCU, and sending the multicast message to the communication unit MNCU via the bus; S108, the communication unit MNCU parses the bus message, restores the four PIDs in the multicast message respectively, and reconstructs the message of the main PID and the message of the backup PID respectively according to the requirements of the external safety device for receiving data; S109. The communication unit MNCU sends a reconstruction message to an external safety device.
6. The cross-connection redundant communication method according to claim 1, characterized in that: The data receiving process includes the following steps: S201, after receiving the safety data RSD sent by the external safety device, the communication unit MNCU transmits it to the main processing unit MPU via the bus; S202, the main processing unit MPU reads the safety data RSD, extracts the PID of the safety data RSD and records it; S203, the main processing unit MPU determines whether the active / standby status of the trackside safety communication platform in this cycle has changed compared with the previous cycle. If so, the main PID of the communication is recalculated according to whether the trackside safety communication platform is system A or system B in this cycle and the active / standby status, and the process goes to step S204; if not, the process goes directly to step S204; S204, filtering the received safety data RSD sent to the backup system of the trackside safety communication platform: comparing the calculated PID value of the main system of the trackside safety communication platform with the four PIDs of the current communication node. If the PID value of the four PIDs is different from the PID value of the main system, the safety data RSD corresponding to the PID is filtered and no subsequent processing is performed. Otherwise, the process goes to step S205; S205, the safety data RSD sent by the external safety device to the main system of the trackside safety communication platform is sequentially transmitted to the communication layer receiving queue and the safety layer receiving queue, and the protocol communication layer CFM processing and the protocol safety layer SFM processing are performed; S206. Pass the security data RSD processed by the protocol to the upper layer application.
7. The cross-connection redundant communication method according to claim 5, characterized in that: Step S103 includes: judging the message type that needs to reconstruct the message header according to whether the current system is the main system or the backup system of the trackside safety communication platform, and whether it is the A system or the B system, and filling the data header of the safety data RSD sent by the application, and reassigning the first byte and the second byte of the safety data RSD when filling; The message types include A master message reconstruction Rebuild_A_Master, B master message reconstruction Rebuild_B_Master, A standby message reconstruction Rebuild_A_Slave and B standby message reconstruction Rebuild_B_Slave.
8. The cross-connection redundant communication method according to claim 5, characterized in that: In step S105, the PIDs of the main system of the trackside safety communication platform for external communication are Master_Pid_a and Master_Pid_b; the PIDs of the standby system of the trackside safety communication platform for external communication are Slave_Pid_a and Slave_Pid_b.
9. The cross-connection redundant communication method according to claim 5, characterized in that: Step S106 includes: combining the message header of the safety data RSD reconstructed in step S103 and the message tail of the CRC check code in step S104 as the message header of the message to be sent to the communication unit MNCU.
10. The cross-connection redundant communication method according to claim 6, characterized in that: Step S203 includes: the main processing unit MPU obtains the system master / slave status of the current subsystem in the current cycle and the previous cycle respectively, if the previous cycle was the master system and the current cycle became the slave system or the previous cycle was the slave system and the current cycle became the master system, then according to whether the subsystem is A or B in the current cycle and the master / slave status, recalculates the main PID of the communication; Step S204 includes: according to the current active / standby status of the trackside safety communication platform, transferring four PIDs of a communication node into the msater_rets array or the slave_rets array for comparison; If the trackside safety communication platform is the master system, the four PIDs are respectively transferred to the master_rets array. If they are different from the main PID values of the communication, the safety data RSD corresponding to the PID in the array is filtered without subsequent processing, otherwise it goes to step S205; If the trackside safety communication platform is a backup system, the four PIDs are respectively transferred into the slave_rets array. If they are different from the main PID values of the communication, the safety data RSD corresponding to the PID in the array is filtered without subsequent processing, otherwise it goes to step S205; Among them, master_rets is the array of the trackside safety platform master system filtering external safety equipment and sending to the trackside safety platform backup system, and slave_rets is the array of the trackside safety platform backup system filtering external safety equipment and sending to the trackside safety platform backup system.
Citation Information
Patent Citations
Multi-channel data receiving and processing method and device for secure computer system
CN119105880A