Safe vehicle-mounted platform data synchronization system and method based on multi-core CPU
Periodic synchronization between multiple cores is performed through the RPMSG mechanism, and combined with the TSN bus and direct network cable, periodic data synchronization between the main and standby MPUs is achieved, solving the data synchronization problem in the multi-core CPU system and improving the real-time and stability of the system.
Patent Information
- Application Number
- CN202411975172.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art has failed to effectively solve the data synchronization problem between the main and standby MPUs in multi-core CPU systems, especially when the synchronization periods between different cores are different, making it difficult to choose a suitable synchronization strategy.
Periodic synchronization between multiple cores is performed through the RPMSG mechanism, so that the periodic alignment between the platform core and the application core is aligned, and data synchronization is performed through the minimum common multiple cycle between the cores. Using the combination of TSN bus and direct network cable, the various platform cores and application cores of the main MPU and the backup MPU can be synchronized periodically, and the 2oo2 mechanism is used to verify the synchronization results to ensure the consistency of the synchronization results.
The periodic consistency between the main and standby MPUs is achieved, ensuring the consistency of data between different cores, improving the real-time and stability of the system, enhancing the fault tolerance of the system, and selecting appropriate synchronization strategies through different synchronization cycles, improving the synchronization effect.
Smart Images

Figure CN120067206A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data synchronization, and in particular to a data synchronization system and method for a secure vehicle-mounted platform based on a multi-core CPU. Background Art
[0002] In a train vehicle-mounted platform based on a multi-core CPU, the cooperative work of multiple processor cores (CPU cores) is an important means to improve computing power and system redundancy. Especially when using the main-backup MPU redundancy architecture, the data synchronization between each core of the main MPU and the backup MPU is particularly crucial. The multi-core system can improve efficiency through parallel computing, but in the main-backup redundancy mode, ensuring data consistency and coherence between different cores and avoiding data conflicts or losses are the core issues to ensure the stable and reliable operation of the multi-core system.
[0003] The invention patent with the publication number CN115481073A discloses a fast recovery method when data exchange fails between heterogeneous multi-core processors, which includes when it is detected that the data update in the shared buffer times out or frames are lost, if the MCU microprocessor core is in a stopped state, starting the MCU microprocessor core and sending the sampling command to the MCU microprocessor core through the virtual IO; the MCU microprocessor core re-initializes the timer according to the obtained sampling frequency, triggers the ADC to perform sampling, stores the data in the shared buffer, and sends relevant events to the MPU application processing core when the shared buffer is full, and the MPU application processing core reads the data from the shared buffer; after the data transfer is completed, notifying the ADC to perform calculations, and the data exchange between the MPU application processing core and the MCU microprocessor core returns to normal through the buffer; this patent does not reflect the synchronization process of multiple cores in the MPU; nor does it reflect the selection of different strategies for synchronization during different synchronization cycles.
[0004] Therefore, providing a data synchronization method for a multi-core secure vehicle-mounted platform that synchronizes different cycles is an urgent problem to be solved at present. Summary of the Invention
[0005] The purpose of the present invention is to overcome the defects existing in the above-mentioned prior art and provide a data synchronization system and method for a secure vehicle-mounted platform based on a multi-core CPU.
[0006] The purpose of the present invention can be achieved by the following technical solutions:
[0007] According to the first aspect of the present invention, a data synchronization system for a secure vehicle-mounted platform based on a multi-core CPU is provided, which includes a main MPU and a standby MPU. Both the main MPU and the standby MPU include two CPUs. Each CPU includes one platform core and two application cores. The platform cores of the main MPU and the standby MPU send status messages MSG_STATE to each other at a set period. The platform cores of the main MPU and the standby MPU are cycle-aligned. The platform core and the application core of the main MPU or the standby MPU are cycle-aligned. The platform core of the main MPU determines whether data synchronization is required currently according to MSG_STATE. If it is in a non-application synchronization period and the standby MPU needs synchronization, or in an application synchronization period and the standby MPU needs synchronization, and the standby MPU is in an initialization state, the main MPU sorts out the synchronization data and sends it to the standby MPU. The standby MPU verifies the synchronization data and performs synchronization after passing the verification. At the same time, after the synchronization is completed, when receiving the clock message MSG_CLOCK of the main MPU, it enters the main security task running mode.
[0008] As a preferred technical solution, the cycle alignment is to adjust the cycles of the platform core and the application core so that the starting points of the cycles are the same.
[0009] As a preferred technical solution, each CPU is provided with a number, and the CPU numbers of the main MPU and the standby MPU correspond to each other.
[0010] According to another aspect of the present invention, a method for the data synchronization system for a secure vehicle-mounted platform based on a multi-core CPU as described above is provided. The method includes:
[0011] S1. The platform cores of the main MPU and the standby MPU send MSG_STATE at a set period.
[0012] S2. The platform core of the main MPU broadcasts MSG_CLOCK to align the cycle start points.
[0013] S3. In the main MPU or the standby MPU, the platform core sends MSG_CLOCK information to the application core through the remote processor message RPMSG for kernel cycle alignment.
[0014] S4. The main MPU determines whether it is in a non-application synchronization period and the standby MPU needs synchronization, or in an application synchronization period and the standby MPU needs synchronization according to MSG_STATE.
[0015] S5. If it is in a non-application synchronization period and the standby MPU needs synchronization, the main MPU will sort out the synchronization data and send it to the standby MPU. The standby MPU verifies the synchronization data and performs synchronization after passing the verification.
[0016] S6. If it is in the application synchronization period and the standby MPU needs to be synchronized and the standby MPU is in the initialization state, the platform core of the main MPU requests synchronization data from the application core. After receiving the synchronization data, the platform core sends it to the standby MPU, and the standby MPU verifies the synchronization data and performs synchronization after the verification passes;
[0017] S7. After the standby MPU completes the synchronization operation in all non-application synchronization periods and application synchronization periods, it sends the synchronization completion information to the main MPU. The main MPU no longer sends synchronization data to the standby MPU, and after the standby MPU receives the MSG_CLOCK sent by the main MPU, it immediately enters the main security task operation mode.
[0018] As a preferred technical solution, both the MSG_STATE and the synchronization data are sent through the TSN bus and the direct connection network cable.
[0019] As a preferred technical solution, the MSG_STATE includes the operation state and whether the standby MPU synchronizes successfully. The operation state includes initialization and normal operation states.
[0020] As a preferred technical solution, the synchronization data includes input data, protocol data, and intermediate variables.
[0021] As a preferred technical solution, the verification of the synchronization data includes legality verification and 2oo2 judgment of the synchronization data.
[0022] As a preferred technical solution, S5 specifically includes:
[0023] S51. The two platform cores of the main MPU respectively send the synchronization data to the two platform cores of the standby MPU. The two platform cores of the standby MPU receive the synchronization data and judge the legality of the synchronization data. If it is illegal, no synchronization operation is performed this time, and wait for the next non-application synchronization period to perform the synchronization operation again;
[0024] S52. If it is legal, the two platform cores of the standby MPU respectively generate two cyclic redundancy checksums (CRC) according to the received synchronization data;
[0025] S53. The standby MPU performs a 2oo2 judgment on the synchronization data according to the two CRCs. If the 2oo2 judgment results of the synchronization data are consistent, the two platform cores of the standby MPU perform synchronization according to the synchronization data, and at the same time send the synchronization data to the application cores in the same CPU for synchronization respectively. If they are inconsistent, no synchronization is performed;
[0026] S54. The application cores respectively feedback the synchronization results to the platform cores in the same CPU, and the MPU performs a 2oo2 judgment on the synchronization results;
[0027] S55. If the synchronization results are consistent in the 2oo2 scenario and both synchronization results are successful, the standby MPU synchronization is completed.
[0028] As a preferred technical solution, the S6 specifically includes:
[0029] S61. Within the same CPU, the platform core of the primary MPU sends a synchronization data request to the application core of the primary MPU, and the platform core remains blocked and waits for the synchronization data from the application core.
[0030] S62. The application core of the primary MPU sends synchronization data to the platform core of the primary MPU.
[0031] S63. The two platform cores of the primary MPU send the synchronization data to the two platform cores of the standby MPU respectively. The two platform cores of the standby MPU receive the synchronization data and judge the legality of the synchronization data. If it is illegal, no synchronization operation is performed this time, and wait for the next non-application synchronization cycle to perform the synchronization operation again.
[0032] S64. If it is legal, the two platform cores of the standby MPU generate two CRCs respectively according to the received synchronization data.
[0033] S65. Perform a 2oo2 judgment on the synchronization data according to the two CRCs. If the 2oo2 results of the synchronization data are consistent, the platform cores of the standby MPU perform synchronization according to the synchronization data, and at the same time send the synchronization data to the application cores within the same CPU and perform synchronization. If they are inconsistent, no synchronization is performed.
[0034] S66. The application cores feedback the synchronization results to the platform cores within the same CPU respectively, and the standby MPU performs a 2oo2 judgment on the synchronization results.
[0035] S67. If the 2oo2 results of the synchronization results are consistent and both synchronization results are successful, the standby MPU synchronization is completed.
[0036] Compared with the prior art, the present invention has the following beneficial effects:
[0037] 1. To ensure the cycle consistency between the primary and standby MPUs, the present invention performs multi-core cycle synchronization through the RPMSG mechanism, enabling the cycle alignment between the platform core and the application core. On the basis of this synchronization, data synchronization can be further performed through the least common multiple cycle between the cores to ensure that there are no timing errors in the data during the synchronization process.
[0038] 2. Through the combination of the TSN bus and the direct-connected network cable in the present invention, the various platform cores and application cores of the primary MPU and the standby MPU achieve periodic synchronization, ensuring the consistency of data between different cores. The transmission of synchronized data not only includes data between platform cores but also covers data interaction between application cores, effectively improving the real-time performance and stability of the entire system.
[0039] 3. The present invention adopts the 2oo2 mechanism to verify the synchronization result, ensuring the consistency of the synchronization results among multiple cores of the primary and standby MPU. By comparing the data synchronization results of two platform cores (such as CRC check), only when the synchronization results of the two platform cores are consistent is the data synchronization considered successful, further enhancing the fault tolerance of the system.
[0040] 4. The present invention divides the synchronization period into an application synchronization period and a non-application synchronization period, and selects different data synchronization strategies according to different periods, resulting in better synchronization effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a schematic diagram of the architectures of the primary MPU and the standby MPU of the present invention;
[0042] Figure 2 It is a schematic diagram of the synchronization period of the present invention;
[0043] Figure 3 It is a schematic diagram of the synchronization process of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0045] In a train on-vehicle platform based on a multi-core CPU, the collaborative work of multiple processor cores (CPU cores) is an important means to improve computing power and system redundancy. Especially when using the primary and standby MPU redundancy architecture, the data synchronization between the cores of the primary MPU and the standby MPU is particularly crucial. A multi-core system can improve efficiency through parallel computing, but in the primary and standby redundancy mode, ensuring the data consistency and coherence between different cores and avoiding data conflicts or losses is the core issue to ensure the stable and reliable operation of the multi-core system.
[0046] In this environment, multiple CPU cores (including platform cores and application cores) of the MPU board need to ensure data consistency among cores between the primary and standby MPU through a specific data synchronization mechanism. Especially when the primary and standby MPU boards do not run simultaneously, during the alternating switch between the primary and standby MPU, if the data consistency and coherence between different cores of the primary and standby boards cannot be ensured, the stable operation of the system under high load and high real-time requirements cannot be guaranteed. Therefore, how to ensure that the data of each core of the primary and standby MPU boards in the multi-core system can be synchronized quickly and accurately has become a key technical issue for improving the safety and reliability of the vehicle-mounted platform.
[0047] In view of the above problems, the present invention provides a data synchronization system and method for a secure vehicle-mounted platform based on multi-core CPUs. To ensure cycle consistency between the primary and standby MPU, cycle synchronization among multi-cores is performed through the RPMSG mechanism, enabling cycle alignment between the platform core and the application core. On this synchronization basis, data synchronization can be further performed through the least common multiple cycle between cores to ensure that no timing errors occur during the data synchronization process. Through the combination of the TSN bus and the direct-connected network cable, the present invention realizes periodic synchronization of each platform core and application core of the primary and standby MPU, ensuring data consistency between different cores. The transmission of synchronized data not only includes data between platform cores but also covers data interaction between application cores, effectively improving the real-time performance and stability of the entire system. The present invention uses the 2oo2 mechanism to verify the synchronization result, ensuring the consistency of the synchronization results among multiple cores of the primary and standby MPU. By comparing the data synchronization results of two platform cores (such as CRC check), data synchronization is considered successful only when the synchronization results of the two platform cores are consistent, further enhancing the fault tolerance of the system. The present invention divides the synchronization cycle into an application synchronization cycle and a non-application synchronization cycle, and selects different data synchronization strategies according to different cycles, resulting in better synchronization effects.
[0048] Embodiment 1
[0049] As Figure 1As shown in the figure, a data synchronization system for a secure vehicle-mounted platform based on a multi-core CPU includes a primary MPU and a standby MPU. Both the primary MPU and the standby MPU include two CPUs. Each CPU includes one platform core and two application cores. The platform cores of the primary MPU and the standby MPU send status messages MSG_STATE to each other at a set period. The platform cores of the primary MPU and the standby MPU are cycle-aligned, and the platform core and the application core of the primary MPU or the standby MPU are cycle-aligned. The platform core of the primary MPU determines whether data synchronization is required currently according to MSG_STATE. If it is in a non-application synchronization period and the standby MPU needs to synchronize, or in an application synchronization period and the standby MPU needs to synchronize, and the standby MPU is in an initialization state, the primary MPU sorts out the synchronization data and sends it to the standby MPU. The standby MPU verifies the synchronization data and performs synchronization after passing the verification. At the same time, after the synchronization is completed and it receives the clock message MSG_CLOCK of the primary MPU, it enters the primary security task running mode.
[0050] The cycle alignment is to adjust the cycles of the platform core and the application core so that the starting points of the cycles are the same.
[0051] Each CPU is provided with a number, and the CPU numbers of the primary MPU and the standby MPU correspond.
[0052] In this embodiment, the system includes the following parts:
[0053] MPU board: The main computing unit board of the secure vehicle-mounted platform, the main computing unit of the system, including CPU1 and CPU2 processing modules. CPU1 and CPU2 interact with each other through a serial port to form 2oo2. The primary and standby MPU boards form a redundant relationship, and the CPU1 and CPU2 of the primary and standby boards can communicate through the TSN bus. At the same time, there are direct network cable connections between CPU1 and CPU1, and between CPU2 and CPU2 of the primary and standby MPU boards. Among them, the CPU1 module mainly includes 1 CPU (3 cores, one platform core for running MPU platform software, and 2 application cores for running ASW software); the CPU2 module mainly includes 1 CPU (3 cores, one platform core for running MPU platform software, and 2 application cores for running ASW software).
[0054] The descriptions of the application core and the platform core are as follows: The real-time operating system runs on the Platform Core (platform core), and the MPU platform software (mainly used to execute BIT, process input data, process intermediate key data, process output data, manage the primary and standby states, and realize data interaction with the application core, etc.) runs on this operating system.
[0055] The real-time operating system runs on ASW Core 1 (Application Core 1). On this operating system, in-vehicle platform software runs (mainly performing BIT, realizing data interaction with application software, and realizing data interaction with the platform core) and ASW Core 1 software runs (such as ATP software, etc.). The real-time operating system runs on ASW Core 2 (Application Core 2). On this operating system, in-vehicle platform software runs (mainly performing BIT, realizing data interaction with application software, and realizing data interaction with the platform core) and ASW Core 2 software runs (such as ATO software, etc.). The Platform Core and the ASW Core can achieve data transmission through the inter-core communication mechanism IPC (Inter-Processor Communication). For example, RPMSG (Remote Processor Messaging) transmits information with high real-time requirements, and data with a large word data volume is transmitted through shared memory.
[0056] When sending synchronous data, CPU1 of the primary MPU sends it to CPU1 of the standby MPU, and CPU2 of the primary MPU sends it to CPU2 of the standby MPU.
[0057] Embodiment 2
[0058] Such as Figure 2 And Figure 3 As shown, a method for a safety in-vehicle platform data synchronization system based on a multi-core CPU, the method includes:
[0059] S1. MSG_STATE is sent between the platform cores of the primary MPU and the standby MPU at a set period.
[0060] S2. The platform core of the primary MPU broadcasts MSG_CLOCK to align the cycle start points.
[0061] S3. In the primary MPU or the standby MPU, the platform core sends MSG_CLOCK information to the application core through the remote processor message RPMSG for kernel cycle alignment.
[0062] S4. The primary MPU judges according to MSG_STATE whether it is in a non-application synchronization cycle and the standby MPU needs synchronization, or in an application synchronization cycle and the standby MPU needs synchronization.
[0063] S5. If it is in a non-application synchronization cycle and the standby MPU needs synchronization, the primary MPU will send the synchronization data to the standby MPU, and the standby MPU will verify the synchronization data and perform synchronization after the verification passes.
[0064] S6. If it is in the application synchronization period and the standby MPU needs to be synchronized and the standby MPU is in the initialization state, the platform core of the primary MPU requests synchronization data from the application core. After receiving the synchronization data, the platform core sends it to the standby MPU, and the standby MPU verifies the synchronization data and performs synchronization after the verification passes;
[0065] S7. After the standby MPU completes the synchronization operation in all non-application synchronization periods and application synchronization periods, it sends the synchronization completion information to the primary MPU. The primary MPU no longer sends synchronization data to the standby MPU, and after the standby MPU receives the MSG_CLOCK sent by the primary MPU, it immediately enters the primary security task running mode.
[0066] The specific content of S5 includes:
[0067] S51. The two platform cores of the primary MPU respectively send synchronization data to the two platform cores of the standby MPU. The two platform cores of the standby MPU receive the synchronization data and judge the legality of the synchronization data. If it is illegal, no synchronization operation is performed this time, and wait for the next non-application synchronization period to perform the synchronization operation again;
[0068] S52. If it is legal, the two platform cores of the standby MPU respectively generate two cyclic redundancy checksums (CRC) according to the received synchronization data;
[0069] S53. The standby MPU performs a 2oo2 judgment on the synchronization data according to the two CRCs. If the 2oo2 judgment results of the synchronization data are consistent, the two platform cores of the standby MPU perform synchronization according to the synchronization data, and at the same time send the synchronization data to the application cores in the same CPU for synchronization respectively. If they are inconsistent, no synchronization is performed;
[0070] S54. The application cores respectively feedback the synchronization results to the platform cores in the same CPU, and the MPU performs a 2oo2 judgment on the synchronization results;
[0071] S55. If the 2oo2 results of the synchronization results are consistent and the synchronization results are all synchronization successes, the standby MPU completes the synchronization.
[0072] The specific content of S6 includes:
[0073] S61. In the same CPU, the platform core of the primary MPU sends a synchronization data request to the application core of the primary MPU, and the platform core remains blocked and waits for the synchronization data from the application core;
[0074] S62. The application core of the primary MPU sends synchronization data to the platform core of the primary MPU;
[0075] S63. The two platform cores of the main MPU send the synchronization data to the two platform cores of the standby MPU respectively. The two platform cores of the standby MPU receive the synchronization data and judge the legality of the synchronization data. If it is illegal, no synchronization operation will be performed this time, and wait for the next non-application synchronization cycle to perform the synchronization operation again;
[0076] S64. If it is legal, the two platform cores of the standby MPU generate two CRCs respectively according to the received synchronization data;
[0077] S65. Perform 2oo2 judgment on the synchronization data according to the two CRCs. If the 2oo2 result of the synchronization data is the same, the platform cores of the standby MPU will perform synchronization according to the synchronization data, and at the same time send the synchronization data to the application cores in the same CPU and perform synchronization. If they are inconsistent, no synchronization will be performed;
[0078] S66. The application cores feedback the synchronization results to the platform cores in the same CPU respectively, and the standby MPU performs 2oo2 judgment on the synchronization results;
[0079] S67. If the 2oo2 results of the synchronization results are the same and the synchronization results are all synchronization successes, the synchronization of the standby MPU is completed.
[0080] Both the MSG_STATE and the synchronization data are sent through the TSN bus and the direct connection network cable.
[0081] The MSG_STATE includes the running state and the information on whether the standby MPU is synchronized successfully. The running state includes initialization and normal running state.
[0082] The synchronization data includes input data, protocol data and intermediate variables.
[0083] The verification of the synchronization data includes legality verification and 2oo2 judgment of the synchronization data.
[0084] In this embodiment, when the main task of the main MPU and the standby MPU are in a data out-of-sync state, the main MPU and the standby MPU should perform data synchronization operations to ensure the consistency and coherence of the data between each core of the main and standby.
[0085] The Platform Cores of each CPU of the main MPU and the standby MPU will periodically send the status message MSG_STATE through the TSN bus (broadcast) and the direct connection network cable (point-to-point). The status message contains information such as the running state (initialization or normal running state) and whether the synchronization is successful.
[0086] The Platform Core of the main MPU will broadcast the MSG_CLOCK information through the TSN bus for the alignment operation of the cycle start point. At the same time, the Platform Core of each MPU board will send the MSG_CLOCK information to other ASW Cores through RPMSG at the beginning of the cycle for the cycle alignment operation between CPU cores.
[0087] The ASW cycle on each ASW Core is an integer multiple of the MPU cycle. The least common multiple of the ASW cycles of two ASW Cores is selected as the synchronization cycle. In this cycle, the MPU software can obtain the synchronized data of the two ASWs completely. For example, if the cycle of ASW Core1 is 100 ms, the cycle of ASW Core2 is 50 ms, and the cycle of the Platform Core is 50 ms, then the synchronization cycle is 100 ms.
[0088] In the non-application synchronization cycle:
[0089] After the main MPU receives the MSG_STATE message sent by the standby MPU;
[0090] If it is judged that the synchronization state of the standby MPU is not successful, the main board will collect all the data to be synchronized MSG_SYN_DATA (such as input data, protocol data, intermediate variables, etc.) and send it to the same CPU of the standby MPU through the TSN bus and the direct-connected network cable (CPU1 sends to CPU1, CPU2 sends to CPU2).
[0091] The Platform Core of the standby MPU board will block and wait for the main MPU to send the synchronization data MSG_SYN_DATA. After receiving the synchronization data, the standby MPU board will verify the legality of the synchronization data. After passing the verification, CPU1 and CPU2 need to interact the total CRC of the synchronized data in a 2oo2 manner; if the 2oo2 results are consistent, the Platform Core synchronizes the data that needs to be synchronized by the platform core, and at the same time sends the synchronized data to the ASW Core through the inter-core memory sharing mechanism; after receiving the synchronized data, the ASW Core performs the synchronization operation and feeds back the synchronization result to the Platform Core through RPMSG. After receiving the synchronization result of the ASW Core, the two CPUs need to interact the synchronization result in a 2oo2 manner. If the synchronization results of CPU1 and CPU2 are both OK, the synchronization of this cycle is successful.
[0092] In the application synchronization cycle:
[0093] After the main MPU receives the MSG_STATE message sent by the standby MPU;
[0094] If it is determined that the standby MPU is in the initialization state and the standby MPU synchronization state is unsuccessful, the main MPU needs to send a synchronization data request message to the ASWCore via RPMSG, and perform a blocking wait operation after sending; after receiving the synchronization data request, the ASW Core sends the synchronization data required by the application core to the Platform Core; the Platform Core collects all the data MSG_SYN_DATA to be synchronized (such as input data, protocol data, intermediate variables, and application core synchronization data, etc.) and sends it to the same CPU of the standby MPU through the TSN bus and direct network cable (CPU1 sends to CPU1, CPU2 sends to CPU2).
[0095] The Platform Core of the standby MPU board will block and wait for the main MPU to send the synchronization data MSG_SYN_DATA. After receiving the synchronization data, the standby MPU board checks the legality of the synchronization data. After passing the check, CPU1 and CPU2 need to interact with the total CRC of the synchronization data in a 2oo2 manner; if the 2oo2 results are consistent, the Platform Core synchronizes the data that the platform core needs to synchronize, and at the same time sends the synchronization data to the ASW Core through the inter-core memory sharing mechanism; after receiving the synchronization data, the ASW Core performs a synchronization operation and feeds back the synchronization result to the Platform Core via RPMSG. After receiving the synchronization result of the ASW Core, the two CPUs need to interact with the synchronization result in a 2oo2 manner. If the synchronization results of CPU1 and CPU2 are both OK, the synchronization of this cycle is successful.
[0096] If all consecutive non-application cycles and application cycles of the dual CPUs of the standby MPU are successfully synchronized and the 2oo2 interaction synchronization results are consistent, the standby system synchronization is successful, and the synchronization state of MSG_STATE will be set to synchronization successful. After receiving the MSG_STATE status message, if the main MPU finds that the standby MPU has successfully completed the synchronization operation, it will no longer send MSG_SYN_DATA to the standby MPU.
[0097] After the standby MPU synchronization is successful, when it receives the MSG_CLOCK from the main MPU next time, it immediately enters the main security task running mode, so as to ensure the consistency and coherence of data between the cores of the main and standby MPUs.
[0098] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A secure vehicle platform data synchronization system based on a multi-core CPU, comprising a main MPU and a backup MPU, wherein the main MPU and the backup MPU each comprise two CPUs, wherein the CPU comprises a platform core and two application cores, wherein: The platform cores of the main MPU and the standby MPU send status messages MSG_STATE to each other according to the set period, the platform cores of the main MPU and the standby MPU perform period alignment, the platform core of the main MPU or the standby MPU and the application core perform period alignment, the platform core of the main MPU determines whether data synchronization is currently required based on MSG_STATE, if it is in a non-application synchronization period and the standby MPU needs to be synchronized or if it is in an application synchronization period and the standby MPU needs to be synchronized and the standby MPU is in an initialization state, the main MPU organizes the synchronization data and sends it to the standby MPU, the standby MPU verifies the synchronization data and synchronizes after the verification is passed, and after the synchronization is completed, receives the clock message MSG_CLOCK from the main MPU to enter the main safety task operation mode.
2. The secure vehicle platform data synchronization system based on multi-core CPU according to claim 1, characterized in that: The cycle alignment is to adjust the cycles of the platform core and the application core so that the starting points of the cycles are the same.
3. A secure vehicle platform data synchronization system based on multi-core CPU according to claim 2, characterized in that: The CPUs are all numbered, and the CPU number of the main MPU corresponds to the CPU number of the standby MPU.
4. A method for a secure vehicle platform data synchronization system based on a multi-core CPU as claimed in any one of claims 1 to 3, characterized in that: The method comprises: S1, the platform cores of the main MPU and the standby MPU send MSG_STATE according to a set period; S2, the platform core of the main MPU broadcasts MSG_CLOCK to align the cycle start point, S3, in the main MPU or the standby MPU, the platform core sends MSG_CLOCK information to the application core through the remote processor message RPMSG to align the kernel cycle; S4, the master MPU determines according to MSG_STATE whether it is currently in a non-application synchronization cycle and the standby MPU needs to be synchronized, or in an application synchronization cycle and the standby MPU needs to be synchronized; S5. If it is in a non-application synchronization cycle and the standby MPU needs to be synchronized, the main MPU sends the synchronization data to the standby MPU, and the standby MPU verifies the synchronization data and synchronizes after the verification passes; S6. If it is in the application synchronization cycle and the standby MPU needs to be synchronized and the standby MPU is in the initialization state, the platform core of the main MPU requests synchronization data from the application core, and the platform core sends the synchronization data to the standby MPU after receiving it. The standby MPU verifies the synchronization data and synchronizes after the verification passes. S7. After the standby MPU completes the synchronization operation in all non-application synchronization cycles and application synchronization cycles, it sends the synchronization completion information to the main MPU. The main MPU no longer sends synchronization data to the standby MPU, and after the standby MPU receives the MSG_CLOCK sent by the main MPU, it immediately enters the main safety task operation mode.
5. The method according to claim 4, characterized in that The MSG_STATE and synchronization data are sent via the TSN bus and the direct network cable.
6. The method according to claim 5, characterized in that The MSG_STATE includes the running status and whether the standby MPU is synchronized successfully, and the running status includes initialization and normal running status.
7. The method according to claim 4, characterized in that The synchronization data includes input data, protocol data and intermediate variables.
8. The method according to claim 4, characterized in that The verification of synchronization data includes legality verification and synchronization data 2oo2 judgment.
9. The method according to claim 8, characterized in that The S5 specifically includes: S51, the two platform cores of the main MPU send synchronization data to the two platform cores of the standby MPU respectively, and the two platform cores of the standby MPU receive the synchronization data and determine the legitimacy of the synchronization data. If it is not legal, the synchronization operation is not performed this time, and the synchronization operation is performed again in the next non-application synchronization cycle; S52, if legal, the two platform cores of the standby MPU respectively generate two cyclic redundancy checks CRC according to the received synchronization data; S53, the standby MPU performs a 2oo2 judgment on the synchronization data according to the two CRCs. If the 2oo2 judgment results of the synchronization data are consistent, the two platform cores of the standby MPU are synchronized according to the synchronization data, and the synchronization data are sent to the application cores in the same CPU for synchronization. If they are inconsistent, no synchronization is performed; S54, the application core feeds back the synchronization results to the platform cores in the same CPU respectively, and the MPU performs 2oo2 judgment on the synchronization results; S55. If the synchronization results 2oo2 are consistent and the synchronization results are all successful, the standby MPU synchronization is completed.
10. The method according to claim 8, characterized in that The S6 specifically includes: S61. In the same CPU, the platform core of the master MPU sends a synchronization data request to the application core of the master MPU, and the platform core remains blocked and waits for synchronization data from the application core; S62, the application core of the master MPU sends synchronization data to the platform core of the master MPU; S63, the two platform cores of the master MPU send the synchronization data to the two platform cores of the standby MPU respectively, and the two platform cores of the standby MPU receive the synchronization data and determine the legitimacy of the synchronization data. If it is not legal, the synchronization operation is not performed this time, and the synchronization operation is performed again in the next non-application synchronization cycle; S64, if legal, the two platform cores of the standby MPU respectively generate two CRCs according to the received synchronization data; S65, perform 2oo2 synchronization data judgment based on the two CRCs. If the 2oo2 synchronization data results are consistent, the platform cores of the standby MPU are synchronized according to the synchronization data, and the synchronization data are sent to the application cores in the same CPU for synchronization. If they are inconsistent, no synchronization is performed. S66, the application core feeds back the synchronization results to the platform cores in the same CPU respectively, and the standby MPU performs 2oo2 judgment on the synchronization results; S67. If the synchronization results 2oo2 are consistent and the synchronization results are all successful, the standby MPU synchronization is completed.
Citation Information
Patent Citations
Quick recovery method for failure of data exchange between heterogeneous multi-core processors
CN115481073A