Two-taking checking method and system based on assembly line mechanism
By adopting a 2-checking method based on pipeline mechanism in a multi-core CPU environment, using a three-processor architecture and dual-interface memory, the performance reduction problems caused by the unutilization of parallel computing advantages and synchronization in the traditional method are solved, and efficient data output frequency is achieved.
Patent Information
- Application Number
- CN202411961786.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-27
AI Technical Summary
The traditional dual-machine 2-checking method cannot take advantage of the advantages of parallel computing in a multi-core CPU environment, resulting in wasted computing resources, and the need for task-level synchronization leads to performance reduction and data output frequency is limited.
The 2-checking method based on the pipeline mechanism is adopted, and the three-processor architecture and dual-interface memory are used to realize parallel computing through pipelined processing steps to avoid task-level synchronization and increase data output frequency.
It realizes the effective utilization of parallel computing power in a multi-core CPU environment, avoids the consumption of synchronous waiting time, and significantly improves the data output frequency.
Smart Images

Figure CN120044895A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial control technologies, and particularly to a fetch-two verification method based on a pipeline mechanism, a fetch-two verification system based on a pipeline mechanism, an electronic device, and a computer-readable medium. Background Art
[0002] In the field of industrial control, in order to improve the security of computer control devices and reduce the probability of serious accidents caused by random hardware failures, the output instructions generated by a computer often need to be compared by two machines fetching two, and can be output only after being confirmed as safe. That is, two devices respectively calculate and output control instructions for the same input information. If the output control instructions of the two devices are exactly the same, they are output; otherwise, they are not output.
[0003] The two-machine fetch-two algorithm generally requires two completely independent computing units to cooperate with each other and periodically execute specific steps in a synchronous serial manner to obtain the periodically output safe control instructions.
[0004] Its working process generally requires the following Figure 1 5 basic steps as shown: 1. Allocate input information. 2. First-stage output: Calculate non-safe control instructions. 3. Second-stage output: Perform fetch-two verification on the consistency of the non-safe control instructions. 4. Calculate the safe output. 5. System output: Output safe control instructions.
[0005] Since the output of each step has to be used as the input of the next step of this computing unit and another computing unit, it must be serially executed under the condition of step synchronization.
[0006] Disadvantages of existing two-machine fetch-two verification methods and reasons for these disadvantages:
[0007] 1. Multiple steps are serially executed, and the parallel computing advantage of a multi-core CPU cannot be exerted.
[0008] In recent years, the space for improving the computing power of a processor by increasing the processor main frequency has become smaller and smaller. The mainstream technology development direction has turned to improving the computing power of a processor through multi-core parallel computing. Since the traditional two-machine fetch-two process is implemented based on a synchronous serial mechanism, it cannot utilize the parallel computing advantage even when running on a multi-core processor, thus causing waste of computing resources.
[0009] 2. It is necessary to use task-level synchronization to achieve data interaction between two independent computing units.
[0010] To ensure the consistency of the instructions to be verified, the information to be verified must be calculated using exactly the same input data and verified. Therefore, task-level synchronization operations must be inserted in each step of the dual-machine fetch-two verification to enable the two computing units to start the next operation simultaneously. So the synchronization operation will additionally increase the execution time of the task and reduce the system performance.
[0011] 3. The data output frequency is limited by the fetch-two verification period.
[0012] The traditional dual-machine fetch-two verification process must use a multi-step synchronous serial mechanism. These steps can perform an output only once per cycle. That is to say, the output frequency of the control instructions of the traditional dual-machine fetch-two verification is limited by the operating cycle of the multi-step synchronous serial mechanism and cannot be higher than the operating cycle of the fetch-two verification. Summary of the Invention
[0013] In view of the above problems, the present invention is proposed to provide a fetch-two verification method based on a pipeline mechanism and a corresponding fetch-two verification system based on a pipeline mechanism, an electronic device, and a computer-readable medium that overcome the above problems or at least partially solve the above problems.
[0014] The present invention discloses a fetch-two verification method based on a pipeline mechanism, which is applied to a fetch-two verification device. The fetch-two verification device is a three-processor architecture. The three-processor architecture includes a first processor, a second processor, and a third processor. A first dual-ported memory is provided between the first processor and the second processor, a second dual-ported memory is provided between the first processor and the third processor, and a third dual-ported memory is provided between the second processor and the third processor. The method includes:
[0015] If the detected cycle number is the initial cycle number, call the initialization functions of the first processor, the second processor, and the third processor to initialize the first dual-ported memory, the second dual-ported memory, and the third dual-ported memory;
[0016] The first processor receives the input data sent to the fetch-two verification device, standardizes the input data into the input data frame format within the fetch-two verification device, writes the standardized input data into the first dual-ported memory and the second dual-ported memory, periodically sends an interrupt signal to the second processor and the third processor, and writes the current interrupt cycle number into the first dual-ported memory and the second dual-ported memory;
[0017] The second processor and the third processor respectively generate a first-stage output frame according to the standardized input data and write it into the third dual-ported memory;
[0018] The second processor and the third processor respectively generate a second-stage output frame according to the first-stage output frame and write it into the third dual-ported memory;
[0019] The second processor and the third processor respectively generate secure output frames based on the two-stage output frames and write them into the first dual-interface memory and the second dual-interface memory respectively;
[0020] The first processor generates a system output frame of the fetch-2 verification device using the secure output frame and sends it to the outside of the system.
[0021] Optionally, if the detected number of cycles is the initial number of cycles, the initialization functions of the first processor, the second processor, and the third processor are called to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory, including:
[0022] If the detected number of cycles is the initial number of cycles, the input areas of the first dual-interface memory and the second dual-interface memory are cleared by calling the first processor initialization function; the input areas of the first dual-interface memory and the second dual-interface memory are used to store the standardized input data and the current interrupt cycle number written by the first processor;
[0023] If the detected number of cycles is the initial number of cycles, the output area of the first dual-interface memory is cleared by calling the second processor initialization function, and the area written by the second processor in the third dual-interface memory is cleared; the output area of the first dual-interface memory is used to store the secure output frame written by the second processor, and the area written by the second processor in the third dual-interface memory is used to store the first-stage output frame and the second-stage output frame written by the second processor;
[0024] If the detected number of cycles is the initial number of cycles, the output area of the second dual-interface memory is cleared by calling the third processor initialization function, and the area written by the third processor in the third dual-interface memory is cleared; the output area of the second dual-interface memory is used to store the secure output frame written by the third processor, and the area written by the third processor in the third dual-interface memory is used to store the first-stage output frame and the second-stage output frame written by the third processor.
[0025] Optionally, the second processor and the third processor respectively generate first-stage output frames based on the standardized input data and write them into the third dual-interface memory, including:
[0026] The second processor reads the standardized input data and the current interrupt cycle number from the first dual-interface memory and performs frame self-verification. If the frame self-verification passes, a first-stage output frame of the second processor is generated and written into the third dual-interface memory; the frame self-verification includes integrity check and checking whether it has the expected cycle information;
[0027] The third processor reads the standardized input data and the current interrupt cycle number from the second dual-interface memory, and performs frame self-check. If the frame self-check passes, it generates a first-stage output frame of the third processor and writes it into the third dual-interface memory; the frame self-check includes integrity check and checking whether it has the expected cycle information.
[0028] Optionally, the second processor and the third processor respectively generate second-stage output frames according to the first-stage output frames and write them into the third dual-interface memory, including:
[0029] The second processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the first dual-interface memory, and performs frame self-check. If the frame self-check passes, it judges whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, it generates a second-stage output frame of the second processor and writes it into the third dual-interface memory;
[0030] The third processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the second dual-interface memory, and performs frame self-check. If the frame self-check passes, it judges whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, it generates a second-stage output frame of the third processor and writes it into the third dual-interface memory.
[0031] Optionally, the second processor and the third processor respectively generate secure output frames according to the second-stage output frames and write them into the first dual-interface memory and the second dual-interface memory respectively, including:
[0032] The second processor reads the second-stage output frame of the second processor and the second-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the first dual-interface memory, and performs frame self-check. If the frame self-check passes, it judges whether the second-stage output frame of the second processor and the second-stage output frame of the third processor are consistent. If they are consistent, it generates a secure output frame of the second processor and writes it into the first dual-interface memory;
[0033] The third processor reads the second-stage output frame of the second processor and the second-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the second dual-interface memory, and performs frame self-check. If the frame self-check passes, it judges whether the second-stage output frame of the second processor and the second-stage output frame of the third processor are consistent. If they are consistent, it generates a secure output frame of the third processor and writes it into the second dual-interface memory.
[0034] Optionally, the first processor generates a system output frame of the fetch-2 check device using the secure output frame and sends it to the outside of the system, including:
[0035] The first processor reads the second-processor secure output frame from the first dual-interface memory, reads the third-processor secure output frame from the second dual-interface memory, and performs frame self-verification. If the frame self-verification passes, it determines whether the second-processor secure output frame and the third-processor secure output frame are consistent. If they are consistent, it generates the system output frame of the take-two verification device and sends it to the outside of the system.
[0036] Optionally, the method further includes:
[0037] When the frame self-verification fails or the consistency verification fails, the second processor or the third processor generates a fault frame, and then the first processor has no output.
[0038] Optionally, the method further includes:
[0039] The first processor is a CPU, and the CPU executes all steps of the first processor;
[0040] The second processor is a CPU, and the CPU executes all steps of the second processor;
[0041] The third processor is a CPU, and the CPU executes all steps of the third processor.
[0042] Optionally, the method further includes:
[0043] The first processor is multiple CPUs, and each CPU executes at least one step of the first processor;
[0044] And / or,
[0045] The second processor is multiple CPUs, and each CPU executes at least one step of the second processor;
[0046] And / or,
[0047] The third processor is multiple CPUs, and each CPU executes at least one step of the third processor.
[0048] The present invention also discloses a take-two verification system based on a pipeline mechanism, which is applied to a take-two verification device. The take-two verification device is a three-processor architecture, and the three-processor architecture includes a first processor, a second processor, and a third processor. A first dual-interface memory is provided between the first processor and the second processor, a second dual-interface memory is provided between the first processor and the third processor, and a third dual-interface memory is provided between the second processor and the third processor. The system includes:
[0049] The storage area initialization module is used to call the initialization functions of the first processor, the second processor, and the third processor to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory if it is detected that the number of cycles is the initial number of cycles;
[0050] The timing interrupt module is used for the first processor to receive the input data sent to the fetch 2 verification device, standardize the input data into the input data frame format in the fetch 2 verification device, write the standardized input data into the first dual-interface memory and the second dual-interface memory, send an interrupt signal to the second processor and the third processor at regular intervals, and write the current interrupt cycle number into the first dual-interface memory and the second dual-interface memory;
[0051] The first-stage output frame generation module is used for the second processor and the third processor to generate the first-stage output frames respectively according to the standardized input data and write them into the third dual-interface memory;
[0052] The second-stage output frame generation module is used for the second processor and the third processor to generate the second-stage output frames respectively according to the first-stage output frames and write them into the third dual-interface memory;
[0053] The secure output frame generation module is used for the second processor and the third processor to generate the secure output frames respectively according to the second-stage output frames and write them into the first dual-interface memory and the second dual-interface memory respectively;
[0054] The system output frame generation module is used for the first processor to generate the system output frame of the fetch 2 verification device by using the secure output frame and send it to the outside of the system.
[0055] The present invention has the following advantages:
[0056] The fetch 2 verification method based on the pipeline mechanism of the present invention is applied to a fetch 2 verification device with a three-processor architecture, which includes the first, second, and third processors, and three dual-interface memories between them. At the initial number of cycles, the three processors initialize the memories. The first processor receives the input data, standardizes it and writes it into two memories, and sends an interrupt signal and the number of cycles to the other two processors. Subsequently, the second and third processors generate the first-stage and second-stage output frames respectively, and finally generate the secure output frames. Each output frame is written into the corresponding memory after generation. The first processor uses these secure output frames to generate the system output frame and send it to the outside of the system. By adopting the pipeline mechanism, the present invention effectively solves the serial execution and task-level synchronization problems in the traditional synchronous serial algorithm dual-machine fetch 2 verification mechanism, not only realizes the parallel processing of each verification step in the multi-core CPU, but also avoids the time consumption of synchronous waiting, thus significantly improving the data output frequency. Description of the Drawings
[0057] Figure 1 It is a flowchart of the traditional dual - machine fetch - 2 verification method;
[0058] Figure 2 It is a step - flowchart of a fetch - 2 verification method based on a pipeline mechanism provided by an embodiment of the present invention;
[0059] Figure 3 It is a schematic diagram of the hardware structure of a fetch - 2 verification device provided by an embodiment of the present invention;
[0060] Figure 4 It is a data - flow diagram of operations executed by each processor provided by an embodiment of the present invention;
[0061] Figure 5 It is a schematic diagram of data - frame description symbols provided by an embodiment of the present invention;
[0062] Figure 6 It is a DPRAM - C data organization diagram provided by an embodiment of the present invention;
[0063] Figure 7 It is a DPRAM - A data organization diagram provided by an embodiment of the present invention;
[0064] Figure 8 It is a DPRAM - B data organization diagram provided by an embodiment of the present invention;
[0065] Figure 9 It is a flowchart of storage - area initialization provided by an embodiment of the present invention;
[0066] Figure 10 It is a flowchart of frame self - verification provided by an embodiment of the present invention;
[0067] Figure 11 It is a flowchart of one - stage output - frame generation provided by an embodiment of the present invention;
[0068] Figure 12 It is a flowchart of two - stage output - frame and secure output - frame generation provided by an embodiment of the present invention;
[0069] Figure 13 It is a flowchart of system output - frame generation provided by an embodiment of the present invention. Detailed implementation manners
[0070] To make the above - mentioned objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners.
[0071] Referring to Figure 2 , a step - flowchart of a fetch - 2 verification method based on a pipeline mechanism provided in an embodiment of the present invention is shown, which may specifically include the following steps:
[0072] Step 201: If the number of cycles detected is the initial number of cycles, call the initialization functions of the first processor, the second processor, and the third processor to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory.
[0073] Step 202: The first processor receives the input data sent to the fetch-2 verification device, standardizes the input data into the input data frame format within the fetch-2 verification device, writes the standardized input data into the first dual-interface memory and the second dual-interface memory, periodically sends an interrupt signal to the second processor and the third processor, and writes the current interrupt cycle number into the first dual-interface memory and the second dual-interface memory.
[0074] Step 203: The second processor and the third processor respectively generate a first-stage output frame based on the standardized input data and write it into the third dual-interface memory.
[0075] Step 204: The second processor and the third processor respectively generate a second-stage output frame based on the first-stage output frame and write it into the third dual-interface memory.
[0076] Step 205: The second processor and the third processor respectively generate a secure output frame based on the second-stage output frame and write it into the first dual-interface memory and the second dual-interface memory respectively.
[0077] Step 206: The first processor generates a system output frame of the fetch-2 verification device using the secure output frame and sends it to the outside of the system.
[0078] The fundamental reason for the three disadvantages of the traditional dual-machine fetch-2 verification method is that there are two characteristics in the dual-machine fetch-2 verification process: task synchronization and serial execution. Therefore, only by using a dual-machine fetch-2 method without these characteristics can the defects of the traditional dual-machine fetch-2 verification be overcome.
[0079] The pipeline mechanism is an execution mechanism that divides a task into a series of subtasks, enabling each subtask to be executed concurrently in each stage of the pipeline. Pipeline processing can significantly improve the system performance of a computer and is a very economical method for implementing parallel computing on a computer.
[0080] On the one hand, the present invention proposes a hardware structure for providing a necessary operating environment for a dual-machine fetch-2 verification algorithm based on the pipeline mechanism. On the other hand, it also proposes the steps of the fetch-2 verification algorithm based on the pipeline mechanism to replace the existing synchronous serial mechanism, thereby effectively overcoming the defects of the traditional dual-machine fetch-2 verification method.
[0081] Specifically, referring to Figure 3 , the hardware structure of the fetch-2 verification device of the present invention is as follows:
[0082] The algorithm for dual-machine taking-2 verification based on the pipeline mechanism runs on the verification calculation board. The verification calculation board adopts a 3-processor architecture. One processor (CPU-C) is responsible for input and output, and the other two processors (CPU-A and CPU-B) are responsible for the taking-2 verification calculation. These three processors are connected using dual-port RAM. Among them, CPU-C is responsible for receiving the input data sent to the verification calculation device from the communication interface, standardizing it into the input data frame format within the system, and then parallelly inputting it to CPU-A and CPU-B. At the same time, it also organizes the taking-2 comparison results generated by CPU-A and CPU-B into a format that can be externally output and sends it to the outside of the system through the communication interface.
[0083] The functions of CPU-A and CPU-B are to use the input information provided by CPU-C to generate safe control instructions through calculation, and this instruction is finally organized by CPU-C and externally output.
[0084] The function descriptions of each component are shown in Table 1.
[0085] Table 1 Function Descriptions of Each Component of the Taking-2 Verification Device
[0086]
[0087] Refer to Figure 4 , the specific process of the taking-2 verification method based on the pipeline mechanism of the present invention is as follows:
[0088] Each CPU performs the operations shown in the following table during the interrupt cycle and inserts the generated information into the corresponding queues in DPRAM-A / B / C.
[0089] Table 2 Operation Descriptions of Each Component of the Taking-2 Verification Device. The source language symbols used are explained as follows:
[0090]
[0091] 1. Data frame description symbol
[0092] Refer to Figure 5 , if each field in the symbol is not used, it means that the information of that field is not specified. For example, C-A represents the C-class frame generated by CPU-A, and the cycle number is not specified.
[0093] 2. Frame type code definition
[0094] Table 3 Frame Type Code Definition
[0095]
[0096] 3. Data planning in DPRAM
[0097] (1) Data in DPRAM-C
[0098] Refer to Figure 6 , DPRAM-C serves as a temporary storage area for the data exchanged between CPU-A and CPU-B. It is divided into Area A and Output Area B. Area A stores the first-stage output frame queue (QA-C) and the second-stage output frame queue (QA-S) of the input provided by interface CPU-A to CPU-B. Area B stores the first-stage output frame queue (QB-C) and the second-stage output frame queue (QB-S) of the input provided by interface CPU-B to CPU-A.
[0099] (2) Data in DRPAM-A and DPRAM-B
[0100] Refer to Figure 7 , DPRAM-A serves as a temporary storage area for the data exchanged between CPU-A and CPUC. It is divided into Input (IN) Area and Output (OUT) Area. The Input Area stores the input data INx-A and the current cycle number information TIMEx provided by interface CPU-C to CPU-A. The Output Area stores the secure output information Ox-A provided by CPU-A to CPU-C.
[0101] Refer to Figure 8 , DPRAM-B serves as a temporary storage area for the data exchanged between CPU-B and CPUC. It is divided into Input (IN) Area and Output (OUT) Area. The Input Area stores the input data INx-B and the current cycle number information TIMEx provided by interface CPU-C to CPU-B. The Output Area stores the secure output information Ox-B provided by CPU-B to CPU-C.
[0102] Among them, INx-A, INx-B, Ox-A, Ox-B, and TIMEx are all immediate information. They are generated only once and used only once.
[0103] 4. Description of the implementation process
[0104] (1) Frame names and function descriptions used in the algorithm
[0105] Table 4 Frame names and function descriptions
[0106]
[0107]
[0108] Note: The cycle information TIMEX carried in each frame is the cycle number of the input information frame IN associated with the frame.
[0109] (2) Data structure of the interaction in DPRAM
[0110] Table 5 Description of the data structure in DPRAM
[0111]
[0112] In an embodiment of the present invention, if the detected number of cycles is the initial number of cycles, the initialization functions of the first processor, the second processor, and the third processor are called to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory, including:
[0113] If the detected number of cycles is the initial number of cycles, the input areas of the first dual-interface memory and the second dual-interface memory are cleared by calling the first processor initialization function; the input areas of the first dual-interface memory and the second dual-interface memory are used to store the standardized input data and the current interrupt cycle number written by the first processor;
[0114] If the detected number of cycles is the initial number of cycles, the output area of the first dual-interface memory is cleared by calling the second processor initialization function, and the second-processor writing area of the third dual-interface memory is cleared; the output area of the first dual-interface memory is used to store the secure output frame written by the second processor, and the second-processor writing area of the third dual-interface memory is used to store the first-stage output frame and the second-stage output frame written by the second processor;
[0115] If the detected number of cycles is the initial number of cycles, the output area of the second dual-interface memory is cleared by calling the third processor initialization function, and the third-processor writing area of the third dual-interface memory is cleared; the output area of the second dual-interface memory is used to store the secure output frame written by the third processor, and the third-processor writing area of the third dual-interface memory is used to store the first-stage output frame and the second-stage output frame written by the third processor.
[0116] In this embodiment, the initialization work is performed by calling INIT(CPU-X). Specifically:
[0117] Table 6 Function INIT(CPU-X) Description and Explanation
[0118]
[0119] Refer to Figure 9 , if CPU-C, CPU-A, and CPU-B find that the number of cycles is TIME0 during an interruption, INIT(CPU-C), INIT(CPU-A), and INIT(CPU-B) are respectively called to perform the initialization work.
[0120] When INIT(CPU-C) is called, the IN area in DPRAM-A is cleared to 0, and the IN area in DPRAM-B is cleared to 0;
[0121] When INIT(CPU-A) is called, the OUT area in DPRAM-A is cleared to 0, and the A area in DPRAM-C is cleared to 0;
[0122] When INIT(CPU-B) is called, the OUT area in DPRAM-B is cleared to 0, and the B area in DPRAM-C is cleared to 0.
[0123] In an embodiment of the present invention, the second processor and the third processor respectively generate a first-stage output frame based on the standardized input data and write it into the third dual-port memory, including:
[0124] The second processor reads the standardized input data and the current interrupt cycle number from the first dual-port memory, and performs frame self-check. If the frame self-check passes, it generates a first-stage output frame of the second processor and writes it into the third dual-port memory; the frame self-check includes integrity check and checking whether it has the expected cycle information;
[0125] The third processor reads the standardized input data and the current interrupt cycle number from the second dual-port memory, and performs frame self-check. If the frame self-check passes, it generates a first-stage output frame of the third processor and writes it into the third dual-port memory; the frame self-check includes integrity check and checking whether it has the expected cycle information.
[0126] In an embodiment of the present invention, the second processor and the third processor respectively generate a second-stage output frame based on the first-stage output frame and write it into the third dual-port memory, including:
[0127] The second processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-port memory, reads the current interrupt cycle number from the first dual-port memory, and performs frame self-check. If the frame self-check passes, it determines whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, it generates a second-stage output frame of the second processor and writes it into the third dual-port memory;
[0128] The third processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-port memory, reads the current interrupt cycle number from the second dual-port memory, and performs frame self-check. If the frame self-check passes, it determines whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, it generates a second-stage output frame of the third processor and writes it into the third dual-port memory.
[0129] In an embodiment of the present invention, the second processor and the third processor respectively generate a secure output frame based on the second-stage output frame and write it into the first dual-port memory and the second dual-port memory respectively, including:
[0130] The second processor reads the second-processor two-stage output frame and the third-processor two-stage output frame from the third dual-interface memory, reads the current interrupt cycle count from the first dual-interface memory, and performs frame self-verification. If the frame self-verification passes, it determines whether the second-processor two-stage output frame and the third-processor two-stage output frame are consistent. If they are consistent, it generates a second-processor secure output frame and writes it into the first dual-interface memory.
[0131] The third processor reads the second-processor two-stage output frame and the third-processor two-stage output frame from the third dual-interface memory, reads the current interrupt cycle count from the second dual-interface memory, and performs frame self-verification. If the frame self-verification passes, it determines whether the second-processor two-stage output frame and the third-processor two-stage output frame are consistent. If they are consistent, it generates a third-processor secure output frame and writes it into the second dual-interface memory.
[0132] In an embodiment of the present invention, the first processor generates a system output frame of the secure output frame generation fetch-2 verification device and sends it to the outside of the system, including:
[0133] The first processor reads the second-processor secure output frame from the first dual-interface memory, reads the third-processor secure output frame from the second dual-interface memory, and performs frame self-verification. If the frame self-verification passes, it determines whether the second-processor secure output frame and the third-processor secure output frame are consistent. If they are consistent, it generates a system output frame of the fetch-2 verification device and sends it to the outside of the system.
[0134] In an embodiment of the present invention, the method further includes:
[0135] When the frame self-verification fails or the consistency verification fails, the second processor or the third processor generates a fault frame, and then the first processor has no output.
[0136] During the process of generating the first-stage output frame, the second-stage output frame, the secure output frame, and the system output frame, the processor will perform frame self-verification to check whether the frame to be verified is complete and whether it has the expected cycle information. During the process of generating the second-stage output frame, the secure output frame, and the system output frame, the processor will perform consistency verification to determine whether to output a secure control instruction or a fault frame.
[0137] The frame self-verification is performed by calling CHK_SELF(M, T). Specifically:
[0138] Table 7 Function CHK_SELF(M, T) Description
[0139]
[0140]
[0141] Refer to Figure 10 , determine whether the frame type in M is a legal value, determine whether the cycle number description in M is equal to T, T > 0, and the integrity check of M passes, then the frame self-check passes.
[0142] Generate a first-stage output frame by calling GEN_APP(M, T). Specifically:
[0143] Table 8 Function GEN_APP(M, T) Description
[0144]
[0145] Refer to Figure 11 , the second processor reads the normalized input data and the current interrupt cycle number from the first dual-interface memory, and performs frame self-check. If the frame self-check passes, generate a first-stage output frame for the second processor and write it into the third dual-interface memory; the third processor reads the normalized input data and the current interrupt cycle number from the second dual-interface memory, and performs frame self-check. If the frame self-check passes, generate a first-stage output frame for the third processor and write it into the third dual-interface memory.
[0146] Generate a second-stage output frame and a secure output frame by calling GEN_CHK(GUE_M, GUE_N, T). Specifically:
[0147] Table 9 Function GEN_CHK(GUE_M, GUE_N, T) Description
[0148]
[0149] Refer to Figure 12 , the second processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the first dual-interface memory, and performs frame self-check. If the frame self-check passes, determine whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, generate a second-stage output frame for the second processor and write it into the third dual-interface memory; the third processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the second dual-interface memory, and performs frame self-check. If the frame self-check passes, determine whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, generate a second-stage output frame for the third processor and write it into the third dual-interface memory.
[0150] The second processor reads the second-processor two-stage output frame and the third-processor two-stage output frame from the third dual-interface memory, reads the current interrupt cycle count from the first dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it determines whether the second-processor two-stage output frame and the third-processor two-stage output frame are consistent. If they are consistent, it generates a second-processor secure output frame and writes it into the first dual-interface memory; The third processor reads the second-processor two-stage output frame and the third-processor two-stage output frame from the third dual-interface memory, reads the current interrupt cycle count from the second dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it determines whether the second-processor two-stage output frame and the third-processor two-stage output frame are consistent. If they are consistent, it generates a third-processor secure output frame and writes it into the second dual-interface memory.
[0151] The system output frame is generated by calling GEN_CHK(M, N, T). Specifically:
[0152] Table 10 Function GEN_CHK(M, N, T) Description
[0153]
[0154] Refer to Figure 13 The first processor reads the second-processor secure output frame from the first dual-interface memory, reads the third-processor secure output frame from the second dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it determines whether the second-processor secure output frame and the third-processor secure output frame are consistent. If they are consistent, it generates the system output frame of the fetch 2 checking device and sends it to the outside of the system.
[0155] In an embodiment of the present invention, the method further includes:
[0156] The first processor is a CPU, and the CPU executes all steps of the first processor;
[0157] The second processor is a CPU, and the CPU executes all steps of the second processor;
[0158] The third processor is a CPU, and the CPU executes all steps of the third processor.
[0159] In this embodiment, the processor is a single CPU. However, in the same cycle, there is no input-output relationship between several steps included in each CPU cycle function (CPU-X-CIRCLE(X)), and they can be executed in parallel.
[0160] In an embodiment of the present invention, the method further includes:
[0161] The first processor is a plurality of CPUs, and each CPU executes at least one step of the first processor;
[0162] and / or,
[0163] The second processor is a plurality of CPUs, and each CPU executes at least one step of the second processor;
[0164] and / or,
[0165] The third processor is a plurality of CPUs, and each CPU executes at least one step of the third processor.
[0166] Since there is no input-output relationship between several steps included in each CPU cycle function (CPU-X-CIRCLE(X)) in the same cycle, based on the foregoing solution, in this embodiment, each step in the cycle function of each CPU is separately run on different CPU cores for simultaneous parallel computing, so the cycle calculation takes less time and the system execution efficiency is higher. It is also possible to separately run each step in the cycle function of some CPUs on different CPU cores for simultaneous parallel computing, and run each step in the cycle function of some CPUs on one CPU core for simultaneous parallel computing.
[0167] The present invention has the following advantages:
[0168] 1. For the dual-machine fetch-2 verification mechanism of the traditional synchronous serial algorithm, multiple steps need to be executed serially, and the parallel computing advantage of the multi-core CPU cannot be exerted.
[0169] The present invention replaces the traditional synchronous serial verification process by using a pipeline mechanism. So that each step of the dual-machine fetch-2 verification does not need to be serially executed in the same cycle, so each step can be dispersed to different CPU cores for parallel execution, improving the calculation speed of the dual-machine fetch-2 process.
[0170] 2. For the dual-machine fetch-2 verification mechanism of the traditional synchronous serial algorithm, it is necessary to use task-level synchronization to achieve data interaction between two independent computing units.
[0171] The present invention replaces the traditional synchronous serial verification process by using a pipeline mechanism. Using a pipeline replaces the task-level synchronization in the traditional working mechanism, avoiding the time consumed due to synchronization deadlocks between two independent computing units and improving the efficiency.
[0172] 3. For the dual-machine fetch-2 verification mechanism of the traditional synchronous serial algorithm, the data output frequency is limited by the fetch-2 verification cycle.
[0173] If the fetch-2 processing flow requires N steps, and each step takes time T, under the condition of using the traditional serial synchronous processing mechanism, the time taken to generate X output data is X * N * T, and the instruction output period is NT.
[0174] If the N steps are decomposed into an N-level pipeline processing mechanism, then the time taken to generate X output data is (N + X - 1)T. When X is much larger than N, the output period is T.
[0175] Therefore, when the value of X is much larger than N, the output speed of the pipeline check is N times that of the time-sharing serial check output speed.
[0176] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0177] A fetch-2 check system based on a pipeline mechanism provided in an embodiment of the present invention is applied to a fetch-2 check device. The fetch-2 check device is a three-processor architecture, and the three-processor architecture includes a first processor, a second processor, and a third processor. A first dual-port memory is provided between the first processor and the second processor, a second dual-port memory is provided between the first processor and the third processor, and a third dual-port memory is provided between the second processor and the third processor. Specifically, it may include the following modules:
[0178] A storage area initialization module, configured to, if it detects that the cycle number is the initial cycle number, call the initialization functions of the first processor, the second processor, and the third processor to initialize the first dual-port memory, the second dual-port memory, and the third dual-port memory;
[0179] A timing interrupt module, configured to receive input data sent to the fetch-2 check device by the first processor, standardize the input data into the input data frame format within the fetch-2 check device, write the standardized input data into the first dual-port memory and the second dual-port memory, periodically send an interrupt signal to the second processor and the third processor, and write the current interrupt cycle number into the first dual-port memory and the second dual-port memory;
[0180] A first-stage output frame generation module, configured to the second processor and the third processor respectively generate a first-stage output frame according to the standardized input data and write it into the third dual-port memory;
[0181] The two-stage output frame generation module is used for the second processor and the third processor to generate two-stage output frames respectively according to the one-stage output frames and write them into the third dual-port memory;
[0182] The secure output frame generation module is used for the second processor and the third processor to generate secure output frames respectively according to the two-stage output frames and write them into the first dual-port memory and the second dual-port memory respectively;
[0183] The system output frame generation module is used for the first processor to generate the system output frame of the fetch-2 verification device by using the secure output frame and send it to the outside of the system.
[0184] Optionally, the storage area initialization module includes:
[0185] The first initialization sub-module is used to call the first processor initialization function to clear the input areas of the first dual-port memory and the second dual-port memory if the detected cycle number is the initial cycle number; the input areas of the first dual-port memory and the second dual-port memory are used to store the standardized input data and the current interrupt cycle number written by the first processor;
[0186] The second initialization sub-module is used to call the second processor initialization function to clear the output area of the first dual-port memory and the second-processor writing area of the third dual-port memory if the detected cycle number is the initial cycle number; the output area of the first dual-port memory is used to store the secure output frame written by the second processor, and the second-processor writing area of the third dual-port memory is used to store the one-stage output frame and the two-stage output frame written by the second processor;
[0187] The third initialization sub-module is used to call the third processor initialization function to clear the output area of the second dual-port memory and the third-processor writing area of the third dual-port memory if the detected cycle number is the initial cycle number; the output area of the second dual-port memory is used to store the secure output frame written by the third processor, and the third-processor writing area of the third dual-port memory is used to store the one-stage output frame and the two-stage output frame written by the third processor.
[0188] Optionally, the one-stage output frame generation module includes:
[0189] The second-processor one-stage output frame generation sub-module is used for the second processor to read the standardized input data and the current interrupt cycle number from the first dual-port memory and perform frame self-verification. If the frame self-verification passes, it generates the second-processor one-stage output frame and writes it into the third dual-port memory; the frame self-verification includes integrity check and checking whether it has the expected cycle information;
[0190] The third-processor first-stage output frame generation sub-module is used for the third processor to read the standardized input data and the current interrupt cycle number from the second dual-interface memory, and perform frame self-checking. If the frame self-checking passes, it generates a third-processor first-stage output frame and writes it into the third dual-interface memory; the frame self-checking includes integrity checking and checking whether it has the expected cycle information.
[0191] Optionally, the second-stage output frame generation module includes:
[0192] The second-processor second-stage output frame generation sub-module is used for the second processor to read the second-processor first-stage output frame and the third-processor first-stage output frame from the third dual-interface memory, read the current interrupt cycle number from the first dual-interface memory, and perform frame self-checking. If the frame self-checking passes, it determines whether the second-processor first-stage output frame and the third-processor first-stage output frame are consistent. If they are consistent, it generates a second-processor second-stage output frame and writes it into the third dual-interface memory;
[0193] The third-processor second-stage output frame generation sub-module is used for the third processor to read the second-processor first-stage output frame and the third-processor first-stage output frame from the third dual-interface memory, read the current interrupt cycle number from the second dual-interface memory, and perform frame self-checking. If the frame self-checking passes, it determines whether the second-processor first-stage output frame and the third-processor first-stage output frame are consistent. If they are consistent, it generates a third-processor second-stage output frame and writes it into the third dual-interface memory.
[0194] Optionally, the secure output frame generation module includes:
[0195] The second-processor secure output frame generation sub-module is used for the second processor to read the second-processor second-stage output frame and the third-processor second-stage output frame from the third dual-interface memory, read the current interrupt cycle number from the first dual-interface memory, and perform frame self-checking. If the frame self-checking passes, it determines whether the second-processor second-stage output frame and the third-processor second-stage output frame are consistent. If they are consistent, it generates a second-processor secure output frame and writes it into the first dual-interface memory;
[0196] The third-processor secure output frame generation sub-module is used for the third processor to read the second-processor second-stage output frame and the third-processor second-stage output frame from the third dual-interface memory, read the current interrupt cycle number from the second dual-interface memory, and perform frame self-checking. If the frame self-checking passes, it determines whether the second-processor second-stage output frame and the third-processor second-stage output frame are consistent. If they are consistent, it generates a third-processor secure output frame and writes it into the second dual-interface memory.
[0197] Optionally, the system output frame generation module includes:
[0198] A system output frame generation sub-module, configured to enable a first processor to read a second-processor secure output frame from a first dual-interface memory, read a third-processor secure output frame from a second dual-interface memory, and perform frame self-verification. If the frame self-verification passes, it determines whether the second-processor secure output frame and the third-processor secure output frame are consistent. If they are consistent, it generates a system output frame of the fetch-two verification device and sends it to the outside of the system.
[0199] Optionally, the system further includes:
[0200] A verification failure module, configured to, when the frame self-verification fails or the consistency verification fails, enable a second processor or a third processor to generate a fault frame, and then the first processor has no output.
[0201] Optionally, the system further includes:
[0202] A first single-CPU module, configured to enable the first processor to be a single CPU, and the CPU executes all steps of the first processor;
[0203] A second single-CPU module, configured to enable the second processor to be a single CPU, and the CPU executes all steps of the second processor;
[0204] A third single-CPU module, configured to enable the third processor to be a single CPU, and the CPU executes all steps of the third processor.
[0205] Optionally, the system further includes:
[0206] A first multi-CPU module, configured to enable the first processor to be multiple CPUs, and each CPU executes at least one step of the first processor;
[0207] And / or,
[0208] A second multi-CPU module, configured to enable the second processor to be multiple CPUs, and each CPU executes at least one step of the second processor;
[0209] And / or,
[0210] A third multi-CPU module, configured to enable the third processor to be multiple CPUs, and each CPU executes at least one step of the third processor.
[0211] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0212] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.
[0213] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for the relevant content.
[0214] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.
Claims
1. A 2-check method based on pipeline mechanism, characterized in that: The method is applied to a 2-check device, wherein the 2-check device is a three-processor architecture, the three-processor architecture includes a first processor, a second processor, and a third processor, a first dual-interface memory is provided between the first processor and the second processor, a second dual-interface memory is provided between the first processor and the third processor, and a third dual-interface memory is provided between the second processor and the third processor, and the method includes: If it is detected that the cycle number is the initial cycle number, calling the initialization function of the first processor, the second processor, and the third processor to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory; The first processor receives input data sent to the take 2 check device, standardizes the input data into the input data frame format in the take 2 check device, writes the standardized input data into the first dual-interface memory and the second dual-interface memory, sends interrupt signals to the second processor and the third processor at regular intervals, and writes the current interrupt cycle number into the first dual-interface memory and the second dual-interface memory; The second processor and the third processor respectively generate a first-stage output frame according to the standardized input data, and write the frame into the third dual-interface memory; The second processor and the third processor respectively generate a second-stage output frame according to the first-stage output frame, and write the frame into a third dual-interface memory; The second processor and the third processor generate a safety output frame according to the second-stage output frame, and write the frames into the first dual-interface memory and the second dual-interface memory respectively; The first processor uses the safety output frame to generate a system output frame of the 2-check device and sends it to the outside of the system.
2. The method according to claim 1, characterized in that If it is detected that the cycle number is the initial cycle number, the initialization function of the first processor, the second processor, and the third processor is called to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory, including: If it is detected that the cycle number is the initial cycle number, the first processor initialization function is called to clear the input area of the first dual-interface memory and the second dual-interface memory; the input area of the first dual-interface memory and the second dual-interface memory is used to store the standardized input data written by the first processor and the current interrupt cycle number; If it is detected that the cycle number is the initial cycle number, the second processor initialization function is called to clear the output area of the first dual-interface memory and the second processor write area of the third dual-interface memory; the output area of the first dual-interface memory is used to store the safety output frame written by the second processor, and the second processor write area of the third dual-interface memory is used to store the first-stage output frame and the second-stage output frame written by the second processor; If it is detected that the number of cycles is the initial number of cycles, the third processor initialization function is called to clear the output area of the second dual-interface memory and the third processor write area of the third dual-interface memory; the output area of the second dual-interface memory is used to store the security output frame written by the third processor, and the third processor write area of the third dual-interface memory is used to store the first-stage output frame and the second-stage output frame written by the third processor.
3. The method according to claim 1, characterized in that The second processor and the third processor respectively generate a first-stage output frame according to the standardized input data and write the frame into the third dual-interface memory, including: The second processor reads the standardized input data and the current interrupt cycle number from the first dual-interface memory, and performs a frame self-check. If the frame self-check passes, a first-stage output frame of the second processor is generated and written into the third dual-interface memory; the frame self-check includes an integrity check and a check whether it has expected cycle information; The third processor reads the standardized input data and the current interrupt cycle number from the second dual-interface memory, and performs frame self-checking. If the frame self-checking passes, a first-stage output frame of the third processor is generated and written into the third dual-interface memory; the frame self-checking includes an integrity check and a check whether it has the expected cycle information.
4. The method according to claim 3, characterized in that The second processor and the third processor generate a second-stage output frame according to the first-stage output frame, and write the second-stage output frame into a third dual-interface memory, including: The second processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the first dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it is determined whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, the second-stage output frame of the second processor is generated and written into the third dual-interface memory; The third processor reads the first-stage output frame of the second processor and the first-stage output frame of the third processor from the third dual-interface memory, reads the current interrupt cycle number from the second dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it determines whether the first-stage output frame of the second processor and the first-stage output frame of the third processor are consistent. If they are consistent, the second-stage output frame of the third processor is generated and written into the third dual-interface memory.
5. The method according to claim 4, characterized in that The second processor and the third processor generate a safety output frame according to the second-stage output frame, and write the frame into the first dual-interface memory and the second dual-interface memory, respectively, including: The second processor reads the second processor second-stage output frame and the third processor second-stage output frame from the third dual-interface memory, reads the current interrupt cycle number from the first dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it is determined whether the second processor second-stage output frame and the third processor second-stage output frame are consistent. If they are consistent, a second processor safety output frame is generated and written into the first dual-interface memory; The third processor reads the second processor second-stage output frame and the third processor second-stage output frame from the third dual-interface memory, reads the current interrupt cycle number from the second dual-interface memory, and performs frame self-checking. If the frame self-checking passes, it determines whether the second processor second-stage output frame and the third processor second-stage output frame are consistent. If they are consistent, a third processor security output frame is generated and written into the second dual-interface memory.
6. The method according to claim 5, characterized in that The first processor uses the security output frame to generate a system output frame of the 2-check device and sends it to the outside of the system, including: The first processor reads the second processor security output frame from the first dual-interface memory, reads the third processor security output frame from the second dual-interface memory, and performs frame self-verification. If the frame self-verification passes, it determines whether the second processor security output frame and the third processor security output frame are consistent. If they are consistent, a system output frame of the 2-check device is generated and sent to the outside of the system.
7. The method according to any one of claims 3 to 6, characterized in that: The method further comprises: When the frame self-check fails or the consistency check fails, the second processor or the third processor generates a fault frame, and the first processor has no output.
8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: The first processor is a CPU, and the CPU executes all steps of the first processor; The second processor is a CPU, and the CPU executes all steps of the second processor; The third processor is a CPU, and the CPU executes all steps of the third processor.
9. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: The first processor is a plurality of CPUs, each CPU executing at least one step of the first processor; and / or, The second processor is a plurality of CPUs, each CPU executing at least one step of the second processor; and / or, The third processor is a plurality of CPUs, and each CPU executes at least one step of the third processor.
10. A pipeline-based 2-check system, characterized in that: The system is applied to a 2-check device, wherein the 2-check device is a three-processor architecture, the three-processor architecture includes a first processor, a second processor, and a third processor, a first dual-interface memory is provided between the first processor and the second processor, a second dual-interface memory is provided between the first processor and the third processor, and a third dual-interface memory is provided between the second processor and the third processor, and the system includes: A storage area initialization module, for calling the initialization functions of the first processor, the second processor, and the third processor to initialize the first dual-interface memory, the second dual-interface memory, and the third dual-interface memory if it is detected that the cycle number is the initial cycle number; A timing interrupt module is used for the first processor to receive input data sent to the take 2 verification device, and standardize the input data into the input data frame format in the take 2 verification device, write the standardized input data into the first dual-interface memory and the second dual-interface memory, regularly send interrupt signals to the second processor and the third processor and write the current interrupt cycle number into the first dual-interface memory and the second dual-interface memory; A first-stage output frame generation module is used for the second processor and the third processor to generate a first-stage output frame according to the standardized input data, and write it into the third dual-interface memory; A second-stage output frame generation module, used for the second processor and the third processor to generate a second-stage output frame according to the first-stage output frame, and write the second-stage output frame into the third dual-interface memory; A safety output frame generation module is used for the second processor and the third processor to generate safety output frames according to the second-stage output frames, and write them into the first dual-interface memory and the second dual-interface memory respectively; The system output frame generation module is used for the first processor to use the security output frame to generate the system output frame of the 2-check device and send it to the outside of the system.