Seamless system switching system and method for 2*2002 secure computer platform based on multiple cores

By adopting a multi-core 2x2002 secure computer platform in the rail transit signal control system, using the redundant communication and multi-threaded parallel technology of the main and standby system, the existing system's insufficient reliability and maintenance difficulties in large-scale network interconnection and complex operating environments are solved, and seamless switching and failure recovery of high reliability and security are achieved.

CN120068052APending Publication Date: 2025-05-30TRAFFIC CONTROL TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411931848.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing rail transit signal control system has insufficient reliability and maintenance difficulties in large-scale interconnection and complex operating environments. In particular, the third-party arbitration mechanism increases operational costs and maintenance difficulties, and communication interruption redundancy detection cannot achieve seamless switching, resulting in poor availability.

Method used

The 2x2002 secure computer platform based on multi-core is adopted, and the two same master and standby systems are paired with each other, and the serial port and Ethernet are used to communicate redundantly to realize the state transition of the master and standby system without the need for a third-party arbitration mechanism. Multi-core uses multi-threaded parallelism to improve response speed and data processing capabilities.

Benefits of technology

It improves the reliability and security of the system, realizes seamless switching and failure recovery between processing units while keeping the system running continuously, reducing operational costs and maintenance difficulties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068052A_ABST
    Figure CN120068052A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a seamless switching system for a 2 * 2002 secure computer platform based on multiple cores. The system is applied to the technical field of rail transit and comprises a main system and a standby system which are the same, and the main system and the standby system are opposite systems; wherein the main system comprises two independent CPUs (Central Processing Unit) which are connected with each other; the standby system comprises two independent CPUs which are connected with each other; the system is characterized in that the first CPU of the main system is connected with the first CPU of the standby system through a serial port and the Ethernet; the second CPU of the main system is connected with the second CPU of the standby system through a serial port and the Ethernet; wherein the serial port interacts with the hot standby state information, and the Ethernet interacts with the hot standby state information and the synchronous data; and according to a system preset state transition rule, performing state transition on the main system and the standby system. In this way, seamless switching of the system can be achieved, so that the reliability and safety of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of rail transit, and in particular, to a system and method for seamless switching of a 2×2002 safety computer platform based on multi-cores. Background Art

[0002] In a rail transit system, a signal control system is the key to ensuring the safe operation of trains and improving transportation efficiency. Traditional signal control systems usually adopt a safety computer platform with a third-party arbitration and communication interruption redundancy detection scheme. However, when dealing with large-scale network interconnection and complex operating environments, this architecture has problems such as insufficient reliability and difficult maintenance. Among them, the third-party arbitration mechanism will increase the number of devices, resulting in disadvantages such as increased operating costs and increased maintenance difficulties; communication interruption redundancy detection cannot achieve true seamless switching and has poor availability while ensuring safety. In recent years, safety computer platforms based on multi-core processors have gradually become a research hotspot. By introducing multi-core technology, the processing ability and fault tolerance performance of the system can be improved. Summary of the Invention

[0003] The present disclosure provides a system and method for seamless switching of a 2x2002 safety computer platform based on multi-cores, which solves the problems of insufficient reliability and difficult maintenance in existing signal control systems, and improves the reliability and safety of the system.

[0004] According to the first aspect of the present disclosure, there is provided a system for seamless switching of a 2x2002 safety computer platform based on multi-cores. The system includes two identical primary and standby systems, and the primary system and the standby system are each other's paired systems; wherein, the primary system includes two independent CPUs connected to each other; the standby system includes two independent CPUs connected to each other; and it is characterized in that:

[0005] The first CPU of the primary system is connected to the first CPU of the standby system through a serial port and Ethernet;

[0006] The second CPU of the primary system is connected to the second CPU of the standby system through a serial port and Ethernet;

[0007] Among them, the serial port exchanges hot standby status information, and Ethernet exchanges hot standby status information and synchronizes data;

[0008] According to the preset state transition rules of the system, the primary system and the standby system perform state conversion.

[0009] In the above aspect and any possible implementation manner, a further implementation manner is provided. The two CPUs of the primary system perform synchronous communication, and determine whether the synchronous communication data of the two CPUs is consistent. If so, the data is output and sent to the CPUs of the standby system for synchronous data following; if not, the two CPUs of the primary system are shut down for system switching;

[0010] Two CPUs of the standby system are used to receive the synchronization data sent by the main system, synchronize with the CPU of the main system, and switch to the CPU of the main system when the main system crashes.

[0011] In the aspect and any possible implementation described above, an implementation is further provided, where the hot standby status information is processed by an independent thread, and the synchronization data is processed by the main thread; where

[0012] The independent thread sets a large period and a small period. The large period and the main thread of the system are synchronized and run through a semaphore; the small period runs within the large period.

[0013] According to a second aspect of the present disclosure, a method for seamless switching of a 2x2002 secure computer platform based on multi-core is provided. The method includes:

[0014] Obtain the system to be converted and the hot standby status information of the pair system;

[0015] Perform state conversion of the system to be converted according to the preset state transition rules of the system;

[0016] Wherein, the system to be converted is the main system or the standby system, and the main system and the standby system are each other's pair systems;

[0017] The state of the main system or the standby system is one of the main system state, standby system state, pre-ascending main state, crashed state, and offline state.

[0018] The present disclosure provides a system and method for seamless switching of a 2x2002 secure computer platform based on multi-core. The system includes two identical main-standby systems, and the main system and the standby system are each other's pair systems; where the main system includes two independent CPUs connected to each other; the standby system includes two independent CPUs connected to each other; the main system is connected to the standby system through a serial port and Ethernet, and realizes state conversion of the main-standby systems according to the preset state transition rules of the system. The system can realize seamless switching and fault recovery between processing units while keeping the system running continuously.

[0019] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Combined with the drawings and referring to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more obvious. The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. In the drawings, the same or similar reference numerals represent the same or similar elements, where:

[0021] Figure 1 Shows the system architecture diagram of seamless switching of a multi-core based 2x2002 security computer platform according to an embodiment of the present disclosure;

[0022] Figure 2 Shows the system thread parallel architecture diagram according to an embodiment of the present disclosure;

[0023] Figure 3 Shows the flowchart of a method for seamless switching of a multi-core based 2x2002 security computer platform according to an embodiment of the present disclosure;

[0024] Figure 4 Shows the state switching logic diagram according to an embodiment of the present disclosure. Detailed implementation manners

[0025] To make the objectives, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.

[0026] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the front and back associated objects.

[0027] In the present disclosure, a system for seamless switching of a multi-core based 2x2oo2 security computer platform is provided, including a primary-backup system. The primary-backup systems perform redundant communication through a serial port and Ethernet, improving the accuracy of communication detection. The system does not require a third-party arbitration mechanism and uses multi-core to achieve multi-thread parallelism, improving the response speed and data processing ability.

[0028] Figure 1 Shows the system architecture diagram of seamless switching of a multi-core based 2x2002 security computer platform according to an embodiment of the present disclosure. As Figure 1 shown:

[0029] The system includes two identical primary-backup systems, and the primary system and the backup system are each other's paired systems; the primary system includes two independent CPUs connected to each other; the backup system includes two independent CPUs connected to each other; wherein,

[0030] The first CPU of the primary system is connected to the first CPU of the backup system through a serial port and Ethernet;

[0031] The second CPU of the primary system is connected to the second CPU of the standby system through a serial port and Ethernet;

[0032] Among them, the serial port exchanges hot standby status information, and Ethernet exchanges hot standby status information and synchronizes data;

[0033] According to the system preset state transition rules, the primary system and the standby system perform state transitions.

[0034] The states of the primary and standby systems are one of the primary system state, standby system state, downtime state, pre-elevation of the primary state, and offline state.

[0035] In some embodiments, each CPU is provided with a self-checking serial port to detect the accuracy of the serial port data transmission of the primary and standby systems, ensuring that the hot standby status information has no errors or losses during transmission.

[0036] In some embodiments, the two CPUs of the primary system perform synchronous communication, and determine whether the synchronous communication data of the two CPUs is consistent. If so, the data is output and sent to the CPU of the standby system for synchronous data following; if not, the two CPUs of the primary system are down and the system is switched.

[0037] The two CPUs of the standby system are used to receive the synchronous data sent by the primary system, synchronize with the CPU of the primary system, and convert to the CPU of the primary system when the primary system is down.

[0038] Figure 2 Shows a system thread parallel architecture diagram according to an embodiment of the present disclosure.

[0039] The hot standby status information in the system is processed by an independent thread, and the synchronous data is processed by the main thread; among them, the independent thread sets a large period and a small period, and the large period and the system main thread are synchronously operated through a semaphore; the small period runs within the large period.

[0040] In some embodiments, the system adopts a multi-threaded architecture, and different threads are responsible for different functions, and work together to ensure the stable operation of the system. Among them, the 2x state switching thread is mainly responsible for the switching processing of the hot standby state of the system, the platform main thread is responsible for the interaction of platform input synchronous data, platform following data, application following data, and output verification data. In order to ensure the effectiveness and timeliness of the synchronous data, the non-primary system needs to complete the time synchronization with the primary system before it can receive the synchronous data of the primary system, and the application thread processes the specific application logic.

[0041] In some embodiments, the independent thread sets a large period and a small period. The large period and the platform main thread are synchronized through semaphore control (starting from the start of the main thread period and ending before the main thread sends safely). The main thread period - 60 ms is used as the running time of the large period of the independent thread. The small period runs once every 40 ms within the large period, and the number of runs = floor((main thread period - 60 ms) / 40 ms).

[0042] Specifically, the 2x state switching thread includes button state monitoring, 2-channel communication, 2x communication, and state switching. The 2x state switching thread runs in a cycle with a period of 40 ms. Within each cycle, it performs a series of operations related to hot standby state switching. In the last small period, the 2x state switching thread does not perform state switching but only performs dual-master detection to prevent inconsistent states of the primary and standby systems.

[0043] In some embodiments, the state switching can also be controlled by buttons and remote switching. Among them, the button switching and the AID remote switching are only switched in the first small period to prevent the degradation of the main system caused by abnormal switching failure.

[0044] In some embodiments, before the independent thread finishes running, all primary and standby states are independent of the main thread and the output. The main thread waits for the independent thread to end and then obtains the hot standby state and updates the 2x thread parameters. That is to say, after the 2x state switching thread completes a full running cycle, the main thread will obtain the updated dual-machine hot standby state information and perform subsequent operations accordingly, such as data synchronization and control of application threads.

[0045] Figure 3 The flowchart of a seamless switching method for a 2x2002 security computer platform based on multi-core according to an embodiment of the present disclosure is shown. This method is applied to the above system. As Figure 3 shown:

[0046] S301, obtain the system to be converted and the hot standby state information of the system;

[0047] S302, perform state conversion of the system to be converted according to the preset state transition rules of the system.

[0048] Among them, the system to be converted is the primary system or the standby system, and the primary system and the standby system are each other's paired systems;

[0049] The state of the primary system or the standby system is one of the primary system state, standby system state, pre-elevated primary state, down state, and offline state.

[0050] There are three ways to determine whether the system to be converted is the primary system or the standby system:

[0051] 1) Determine whether the system to be converted is the primary system or the standby system according to the current state of the system to be converted. In the ideal operating state, the system in the primary state is the primary system, and the system in the standby state is the standby system. Communication between the primary system and the standby system is normal. When one of the systems is in a down state, there is only the other system left in the platform, and the primary and standby systems are no longer distinguished.

[0052] 2) Distinguish the primary system and the standby system according to the state of the system. If the system is in the primary state, as long as the system to be converted is not in a down state, the system to be converted is the standby system.

[0053] 3) Distinguish the primary system and the standby system according to the next state of the system to be converted and the corresponding system. For example, if the system to be converted is in the pre - elevation primary state and the standby system is in the offline state, and obviously the system to be converted will be elevated to the primary state next step, then the system to be converted is the primary system.

[0054] It can be understood that the above three methods are only applicable to the case where communication between the primary system and the standby system is normal. When communication between the two is interrupted, there may also be a situation where, due to the inability to update the current state of the corresponding system in a timely manner, both systems consider themselves to be the primary system or the standby system.

[0055] Figure 4 Shows the state transition logic diagram according to an embodiment of the present disclosure. As Figure 4 shown, the state transition matrix is shown in Table 1:

[0056]

[0057]

[0058] Table 1

[0059] It can be understood that Figure 4 the relationship between the conditions is "or", that is, as long as one of the conditions in the corresponding rule is met, the state conversion of the system to be converted can be completed.

[0060] Downtime: An intolerable fault is detected, and the platform and application threads are locked at the current execution position and no longer continue to run periodically.

[0061] Primary system: Both software and hardware are normal and it is the current master device. The platform software and application software both run periodically and output externally, and synchronize data to the corresponding system every cycle.

[0062] Standby system: Both software and hardware are normal and it is the current standby system. It can be upgraded to the primary system when necessary to take over the external output of the corresponding system. The platform software and application software both run periodically but do not output externally. Currently, it has been synchronized with the primary system and continues to be synchronized with the primary system every cycle.

[0063] Offline: The hardware is normal, but the software does not yet have the condition for master control output, has not been synchronized with the master system, and cannot be upgraded to the master system output. The platform software and application software both run periodically but do not output externally. When the system is the master system, it will be synchronized with the master system every cycle.

[0064] Pre-upgrade to master: Both the software and hardware are normal. The platform software and application software both run periodically but do not output externally, announcing that this system is about to be upgraded to the master system, mainly used for competing to become the master system when both systems are offline.

[0065] In S302, the preset state transition rules of the system include state transition rules for converting other states to the downtime state, where,

[0066] When the system to be converted is in the master system state, if a serious fault occurs in the self-check of the system to be converted, or in the dual-master detection and the system to be converted and the paired system were both in the master system state in the previous cycle, then the system to be converted transitions from the master system state to the downtime state; where, the dual-master detection means that the system to be converted and the paired system both consider themselves to be in the master system state; corresponding to item 1 and item 8 in Table 1;

[0067] When the system to be converted is in the standby system state, if a serious fault occurs in the self-check of the system to be converted, or all communications between the system to be converted and the paired system are interrupted simultaneously and there is a disconnection, or the comparison with the output of the master system is inconsistent, then the system to be converted transitions from the standby system state to the downtime state; where, corresponding to item 1, item 13, and item 17 in Table 1;

[0068] When the system to be converted is in the pre-upgrade to master state or the offline state, if a serious fault occurs in the self-check of the system to be converted, then the system to be converted transitions from the pre-upgrade to master or offline state to the downtime state; where, corresponding to item 1 in Table 1.

[0069] In S302, the preset state transition rules include the mutual conversion rules between the master system state and the standby system state, where,

[0070] When the system to be converted is in the master system state, if in the dual-master detection, the system to be converted and the paired system were not both in the master system state in the previous cycle, and the system to be converted was in the standby system state in the previous cycle, or the paired system is in the standby system state, and the dual-system switching buttons on both sides are pressed for more than the preset time, or the paired system is in the standby system state and the remote switching states of both systems allow switching, then the system to be converted transitions from the master system state to the standby system state; where, corresponding to item 9, item 10, and item 11 in Table 1.

[0071] When the system to be converted is in the standby system state, if all communications between the system to be converted and the counterpart system are interrupted simultaneously and the interruption time lasts for 1 cycle, and there is no disconnection, or the counterpart system is currently in the offline state, or the counterpart system is not in the main system state currently, and the system to be converted was in the main system state in the previous cycle; or the counterpart system is in the main system state and in the system switching state and there is a normally operating communication channel, then the system to be converted switches from the standby system state to the main system state; among them, corresponding to item 12, item 14, item 15 and item 16 in Table 1.

[0072] In S302, the preset state transition rules include the mutual transition rules between the offline state and the pre-elevated main state, where

[0073] When the system to be converted is in the offline state, if the counterpart system is neither in the main system state nor in the pre-elevated main state, and the continuous offline time reaches 5 cycles, then the system to be converted switches from the offline state to the pre-elevated main state; among them, corresponding to item 3 in Table 1;

[0074] When the system to be converted is in the pre-elevated main state, if the counterpart system is currently in the main system state or the standby system state, or the counterpart system is also in the pre-elevated main state currently, then the system to be converted switches from the pre-elevated main state to the offline state; among them, corresponding to item 5 and item 6 in Table 1.

[0075] In S302, the preset state transition rules include the relevant transition rules between the offline state and the standby system state, where

[0076] When the system to be converted is in the offline state, if the counterpart system is in the main system state, and the follow-up data is successfully synchronized, the output comparison is consistent, the time synchronization is successful, and the application of the follow-up data is set successfully, then the system to be converted switches from the offline state to the standby system state; among them, corresponding to item 4 in Table 1;

[0077] When the system to be converted is in the standby system state, if it has not been synchronized with the main system state for more than 5 cycles, or the application of the follow-up data is inconsistent with that of the main system state, or the application follow-up data of the main system state has not been received, then the system to be converted switches from the standby system state to the offline state; among them, corresponding to item 18, item 20 and item 21 in Table 1.

[0078] In S302, the preset state transition rules include the state transition rules for the system to be converted to switch from the main system state to the offline state, where

[0079] When the system to be converted is in the main system state, if the main system state receives the unexpected state data of the standby system state, then the system to be converted switches from the main system state to the offline state; among them, corresponding to item 19 in Table 1.

[0080] In S302, the preset state transition rules include the state transition rules for the system to be converted to switch from the pre-elevated main state to the main system state, where

[0081] When the system to be converted is in the pre-ascending main state, if the system to be converted remains in the pre-ascending main state for 5 cycles, the system to be converted will be converted from the pre-ascending main state to the main system state; where it corresponds to No. 7 in Table 1.

[0082] In the embodiments of the present disclosure, the system can achieve state transition without a third-party arbitration mechanism, thereby improving the operating efficiency of the system. By using multiple cores to implement multi-thread parallelism, the response speed and data processing ability are improved. Through the redundant communication method of serial port and Ethernet, the accuracy of communication detection is improved.

[0083] It should be understood that the various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, and no limitations are imposed herein.

[0084] The above specific implementation manners do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.

Claims

1. A system for seamless switching of a multi-core 2x2002 secure computer platform, comprising two identical master and slave systems, wherein the master system and the slave system are mutually paired systems; wherein: The main system includes two independent CPUs connected to each other; the standby system includes two independent CPUs connected to each other; the characteristics are: The first CPU of the main system is connected to the first CPU of the standby system via a serial port and Ethernet; The second CPU of the main system is connected to the second CPU of the standby system via a serial port and Ethernet; Among them, serial port interactive hot standby status information, Ethernet interactive hot standby status information and synchronization data; According to the system's preset state transfer rules, the main system and the backup system perform state transition.

2. The system according to claim 1, characterized in that The two CPUs of the main system perform synchronous communication and determine whether the synchronous communication data of the two CPUs are consistent. If so, the data is output and sent to the CPU of the standby system for synchronous data following; if not, the two CPUs of the main system are down and the system is switched; The two CPUs of the standby system are used to receive synchronization data sent by the main system, synchronize with the CPU of the main system, and switch to the CPU of the main system when the main system fails.

3. The system according to claim 1, characterized in that The hot standby status information is processed by an independent thread, and the synchronization data is processed by the main thread; wherein, Independent threads set large cycles and small cycles. The large cycle runs synchronously with the system main thread through semaphore control; the small cycle runs within the large cycle.

4. A method for seamlessly switching between 2x2002 secure computer platforms based on multiple cores, applied to the system described in claims 1-3, characterized in that: The method comprises the following steps: Obtaining the system to be converted and the hot standby status information of the system; According to the system preset state transfer rules, the state of the system to be converted is converted; Wherein, the system to be converted is a main system or a backup system, and the main system and the backup system are paired systems to each other; The state of the primary system or the backup system is one of a primary system state, a backup system state, a pre-upgrade primary state, a downtime state, and an offline state.

5. The method according to claim 4, characterized in that The preset state transition rule includes a state transition rule for converting other states into a downtime state, wherein, when the system to be converted is in the master system state, if a serious fault occurs in the self-check of the system to be converted, or dual master detection occurs and both the system to be converted and the opposite system are in the master system state in the previous cycle, then the system to be converted is converted from the master system state to the downtime state; wherein, dual master detection means that the system to be converted and the opposite system both believe that they are in the master system state; when the system to be converted is in the standby system state, if a serious fault occurs in the self-check of the system to be converted, or all communications between the system to be converted and the opposite system are interrupted at the same time and there is a line break, or the output is inconsistent with the master system, then the system to be converted is converted from the standby system state to the downtime state; When the system to be converted is in the pre-upgrade state or the offline state, if a serious fault occurs in the self-check of the system to be converted, the system to be converted is converted from the pre-upgrade state or the offline state to the downtime state.

6. The method according to claim 4, characterized in that The preset state transfer rules include the mutual conversion rules between the main system state and the standby system state, wherein: When the system to be converted is in the master system state, if the dual master detection shows that the cycle of the system to be converted and the opposite system are not in the master system state at the same time, and the cycle of the system to be converted is in the standby system state, or the opposite system is in the standby system state, the switch buttons of both systems are pressed for more than the preset time, or the opposite system is in the standby system state, and the remote switch states of both systems are to allow switch, then the system to be converted is converted from the master system state to the standby system state; When the system to be converted is in the standby state, if all communications between the system to be converted and the control system are interrupted at the same time and the interruption time is as long as 1 cycle, and there is no disconnection, or the control system is currently in the offline state, or the system is not currently in the main system state, and the system to be converted was in the main system state in the previous cycle; or the system is in the main system state and is in the cut-off state and there is a normal working communication channel, then the system to be converted is converted from the standby state to the main system state.

7. The method according to claim 4, characterized in that The preset state transfer rules include the mutual conversion rules between the offline state and the pre-upgrade master state, wherein: When the system to be converted is in offline state, if the system is neither in the master state nor in the pre-upgrade master state, and the continuous offline time reaches 5 cycles, the system to be converted is converted from the offline state to the pre-upgrade master state; When the system to be converted is in the pre-upgraded master state, if the system is currently in the master state or the standby state, or the system is also currently in the pre-upgraded master state, the system to be converted is converted from the pre-upgraded master state to the offline state.

8. The method according to claim 4, characterized in that The preset state transfer rules include the relevant conversion rules of the offline state and the standby state, wherein: When the system to be converted is in offline state, if the system is in master state, and the follow-up data is successfully synchronized, the output is relatively consistent, the time synchronization is successful, and the application follow-up data is successfully set, the system to be converted is converted from offline state to standby state; When the system to be converted is in the standby state, if it is out of synchronization with the main state for more than 5 cycles, or the application follow-up data of the main state is inconsistent, or the application follow-up data of the main state is not received, the system to be converted is converted from the standby state to the offline state.

9. The method according to claim 4, characterized in that The preset state transition rule includes a state transition rule for the system to be converted from the main system state to the offline state, wherein: When the system to be converted is in the master system state, if the master system state receives unexpected state data from the standby system state, the system to be converted is converted from the master system state to the offline state.

10. The method according to claim 4, characterized in that The preset state transition rule includes a state transition rule for the system to be converted from the pre-upgrade main state to the main system state, wherein: When the system to be converted is in the pre-upgraded main state, if the system to be converted continues to be in the pre-upgraded main state for 5 cycles, the system to be converted is converted from the pre-upgraded main state to the main state.