End system redundancy management method in case of packet loss and disorder in AFDX (Avionics Full Duplex Switched Ethernet) network

By introducing cache queues and dual deduplication mechanisms into the AFDX network, the problem of error discarding legal packets in packet loss and out-of-order scenarios is solved, and the correct reception and sorting of packets is achieved, meeting the real-time and reliability requirements of avionics systems.

CN120281435APending Publication Date: 2025-07-08上海涵鲲科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510616015.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The redundant management algorithm of the existing AFDX network cannot effectively judge the validity of packets in packet loss and out of order scenarios, resulting in the error discarding of legitimate packets and failure to realize packet sorting.

Method used

The cache queue and dual deduplication mechanism are used to determine the validity of the packet by comparing the frame sequence numbers (FSN and PFSN), and sorting them in the queue. The maximum tolerance delay timer is set to ensure that the critical packets are sent in a timely manner.

Benefits of technology

Ensure complete reception and sorting of packets in packet loss and out of order scenarios, be compatible with existing hardware architecture, and meet the real-time and reliability requirements of avionics systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281435A_ABST
    Figure CN120281435A_ABST
Patent Text Reader

Abstract

The invention discloses an end system redundancy management method during packet loss and disorder in an AFDX (Avionics Full Duplex Switched Ethernet) network. The method comprises the following steps of: initializing a previous frame sequence number PFSN into an invalid value; receiving a first frame of a channel A or B according to a time sequence, putting the first frame into a queue when the first frame is valid, and updating the PFSN; receiving the next frame of the channel A or B according to a time sequence, judging the sequence number FSN! Of the current frame to be equal to PFSN, if not, discarding the current frame, if so, enabling the current frame to be valid, updating the PFSN to be equal to the FSN, putting the message into a queue, sorting the message according to the SN from small to large, and discarding the message if the message is found to be repeated with the SN in the queue; and if the cache queue is full, sending the first message from the queue head. The invention also introduces a control method of the maximum tolerant delay timer. The method has the advantages that the Skew value does not need to be judged, the system overhead is saved, the problem that legal messages are mistakenly discarded under dual-channel packet loss and out-of-order scenes is solved, and the algorithm is more reliable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0002] The present invention belongs to the technical field of avionics network communication, and particularly relates to a method for end-system redundancy management when packet loss and out-of-order occur in an AFDX network (Avionics Full-Duplex Switched Ethernet). Background Art

[0003] AFDX (Avionics Full-Duplex Switched Ethernet) technology is defined in the ARINC664P7 standard and is a communication network technology for data transmission between aircraft avionics systems. AFDX has been improved in terms of delay guarantee and high reliability based on traditional Ethernet technology. The AFDX technology uses a dual-transmission and selective-reception network-level redundancy backup mechanism to achieve high-reliability transmission. At the sending end, the RM (redundent managment) module sends the same message from multiple ports, and at the receiving end, the RM module performs message validity judgment and duplicate removal operations based on the first-come-first-served principle. Currently, the ARINC664P7 standard does not define a specific end-system redundancy management check method, but only describes the redundancy management requirements, such as judging whether a message is valid based on the received FSN, and judging whether a message is valid based on Skew, and requiring the redundancy management to forward messages in order. Each message has a sequence number SN (sequence number) to identify the message sending order; PFSN (previous frame sequence number) is the SN of the previously received message, and FSN (frame sequence number) is the SN of the currently received message.

[0004] Skew is defined in the standard, which refers to the maximum time difference between two paths when the same data frame is transmitted through redundant paths. In AFDX, the frames of each virtual link (VL) are transmitted through two independent physical paths (channels A and B), and the receiving end needs to merge or select redundant frames. Skew is the time difference between the arrival times of these two redundant frames at the receiving end. It is necessary to reasonably plan the skew of each VL (virtual link). When the number of VLs is large and the network topology is complex, it is difficult to plan a reasonable skew, and the RM module needs to record the arrival time of each message and calculate the Skew, which consumes a large amount of system processing resources.

[0005] The standard requires that the processing method of the redundancy management algorithm only ensures the in-order forwarding of messages and does not support message sorting. Its typical defects are as follows: 1. When packet loss occurs on one link, the backup messages on the standby link will be incorrectly discarded, and the reliable transmission effect of the messages is not achieved. As shown in the appendix Figure 1As shown, in the case of packet loss at port A, the backup packet 3 at port B is discarded.

[0006] 2. When out-of-order occurs in the network, legitimate packets will be discarded. As shown in the appendix Figure 2 As shown, in the case of out-of-order at port A, packets 3 at both ports A and B are discarded.

[0007] In summary, the standard redundancy management algorithm does not consider the incorrect judgment of the validity of packets in the case of packet loss and out-of-order, and does not even have a sorting function, resulting in the discarding of legitimate packets. Summary of the Invention

[0008] The present invention aims to solve the limitations of the existing AFDX network redundancy management algorithm, and provides a method for end-system redundancy management that does not require judging the Skew value, saves system overhead, solves the problem of incorrect discarding of legitimate packets in the case of dual-channel packet loss and out-of-order, and has a more reliable algorithm.

[0009] To achieve the above object, the present invention adopts the following technical solutions: A method for end-system redundancy management in an AFDX network when packet loss and out-of-order occur, the parameters including frame sequence number SN, previous frame sequence number PFSN, current frame sequence number FSN, and buffer length n, comprising the following steps: S1: Initialize PFSN to an invalid value; S2: Receive the first frame of channel A or B in sequence, record the FSN value; judge FSN!= PFSN, if valid, put it into the queue, and update PFSN = FSN; S3: Receive the next frame of channel A or B in sequence, record the FSN value; judge FSN!= PFSN: if yes, it is valid, put it into the queue, and sort it in ascending order according to SN, and update PFSN = FSN; otherwise repeat and discard; S4: Repeat step S3; if the buffer queue is full, send the first packet from the head of the queue.

[0010] Preferably, in the above method for end-system redundancy management in an AFDX network when packet loss and out-of-order occur, a maximum tolerance delay timer is set for each packet, which is started when the packet is stored in the buffer queue, and when the timer expires, the packet is sent from the queue.

[0011] Preferably, in the above method for end-system redundancy management in an AFDX network when packet loss and out-of-order occur, the maximum tolerance delay timer for each packet can be independently configured.

[0012] Preferably, in the above method for end-system redundancy management in an AFDX network when packet loss and out-of-order occur, the value of n is 3 - 6.

[0013] Preferably, in the method for end - system redundancy management when packet loss and out - of - order occur in the above - mentioned AFDX network, the value of n is 4.

[0014] The present invention adopts the above - mentioned technical solutions, is constructed based on the A664P7 protocol, and fully considers the problem of erroneously discarding legal packets in common packet - loss and out - of - order scenarios of dual channels. By introducing a cache queue, sorting, and dual - deduplication mechanisms, that is, comparing the packet FSN with the PFSN of the existing queue, if they are not equal, the new packet is incorporated into the queue, and sorting and deduplication are performed in the queue; when the queue is full, the first packet in the queue is automatically sent out, and when the maximum tolerance delay timer of a certain packet expires, it is sent out. Compared with the prior art, it has the following advantages: 1. In the scenario of packet loss at a certain port, by receiving backup packets and automatically sorting them in the cache queue, the correct reception of packets is completed.

[0015] 2. In the scenario of out - of - order at a certain port, by dual - deduplication of packets and automatically sorting them in the cache queue, the correct reception of packets is completed.

[0016] 3. Define the maximum delay tolerance value, which can be set independently, and periodically check the maximum delay of each packet put into the cache queue to ensure that the service - processing delay requirements are met.

[0017] 4. Be compatible with the A664P7 standard, without modifying the existing hardware architecture, and support the real - time and reliability requirements of avionics systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 : Processing example 1 of the redundancy management algorithm specified by the A664P7 standard; Figure 2 : Processing example 2 of the redundancy management algorithm specified by the A664P7 standard; Figure 3 : Flowchart of the end - system redundancy management method of the present invention; Figure 4 : Embodiment 1 of the end - system redundancy management method of the present invention; Figure 5 : Embodiment 2 of the end - system redundancy management method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0019] As Figure 3 shown in the flowchart, a method for end - system redundancy management when packet loss and out - of - order occur in an AFDX network of the present invention, the parameters include frame sequence number SN, previous frame sequence number PFSN, current frame sequence number FSN, and buffer length n, and includes the following steps: S1: Initialize PFSN to an invalid value; S2: Receive the first frame of Channel A or B in sequence, record the FSN value; determine that FSN != PFSN. Since PFSN is an invalid value at this time, FSN must be valid. Put it into the queue and update PFSN = FSN. S3: Receive the next frame of Channel A or B in sequence, record the FSN value; determine that FSN != PFSN: Otherwise, repeat and discard; if yes, it is valid. Update PFSN = FSN, put the message into the queue, and sort it in ascending order according to SN. If it is found that the SN is repeated in the queue, discard the message; this step includes two deduplication processes. The first is to judge FSN and PFSN by formula, and the second is to check if there are duplicate values during the sorting in the queue.

[0020] S4: Repeat S3; if the buffer queue is full, send the first message from the head of the queue.

[0021] The impact of the buffer size on the message forwarding delay depends on the MAC layer forwarding delay and the message rate. Taking the 100Mbps Ethernet port as an example for the evaluation of the forwarding delay impact, the MAC message forwarding delay of a typical packet length of 100 bytes is 9.4us. When the buffer queue is 4, the delay = 4 * 9.4 = 37.6us; when the queue is 3, the delay = 3 * 9.4 = 28.2us. Taking the sending frequency of 1ms as an example for the evaluation of the message rate impact, when the buffer queue is 4, the delay = 4 * 1 = 4ms, and when the queue is 3, the delay = 3 * 1 = 3ms. According to a large number of tests, it is found that when the value of n is 3 - 6, it can ensure a better balance of the access efficiency, network delay, system overhead, and message accuracy of the present invention. In the usual scenario, the value of n is 4 is more optimal.

[0022] For the large packet burst scenario and the situation of insufficient traffic, in order to avoid excessive delay of critical messages and ensure the timely sending of messages, the present invention also sets a maximum tolerance delay timer for each message, and the parameters can be independently configured. It is started when the message is stored in the buffer queue, and when the timer expires, the message is sent from the queue. The maximum tolerance delay timer is not necessary, it can be enabled or disabled depending on the scenario, so it is represented by a dotted line in the flowchart. Embodiment 1

[0023] In the background art, taking Figure 1 as an example, the processing example 1 of the redundancy management algorithm specified in the A664P7 standard is introduced, and its processing result has been detailed in the background art. Figure 4 For the same input, the processing result after using the present invention. The input of Port A is 1 → 2 → 4 → 5, and the input of Port B is 1 → 2 → 3 → 4 → 5. Port B is slightly delayed compared to Port A. Set the buffer length n = 4. The judgment steps are as follows: Step1: The initial PFSN is an invalid value. Receive FSN = 1 from port A. Determine that PFSN != FSN. The message is valid and enters the queue. PFSN = FSN. The message starts a timer. Step2: Receive FSN = 1 from port B. Determine that PFSN == FSN and discard it repeatedly. Step3: Receive FSN = 2 from port A. Determine that PFSN != FSN. The message is valid and enters the queue. PFSN = FSN. The message starts a timer. Step4: Receive FSN = 2 from port B. Process it the same as step2. Step5: Receive FSN = 4 from port A. Process it the same as step3. Step6: Receive FSN = 3 from port B. Process it the same as step3 and sort it in the queue. Step7: Receive FSN = 5 from port A. Process it the same as step3. When the queue is full, the first message in the queue is dequeued. Step8: Receive FSN = 4 from port B. Process it the same as step3 and discard it repeatedly in the queue. Step9: Receive FSN = 5 from port B. Process it the same as step3 and discard it repeatedly in the queue. Step10: The timer of message 2 expires and the message is dequeued.

[0024] This embodiment details a method for complementing messages through a backup line in a packet loss scenario, and also shows the use of a timer and the automatic transmission of the first message in the queue when the queue is full. The output result after processing by the redundancy management algorithm specified in the A664P7 standard is 1 → 2 → 4 → 5, and message 3 is lost. However, the output result after processing by the present invention is the complete 1 → 2 → 3 → 4 → 5. Embodiment 2

[0025] In the background art, Figure 2 is taken as an example to introduce Example 2 of the redundancy management algorithm specified in the A664P7 standard, and its processing result has been detailed in the background art. Figure 5 For the same input, the processing result after processing by the present invention. The input from port A is 1 → 2 → 4 → 3 → 5, and the input from port B is 1 → 2 → 3 → 4 → 5. The input from port B is slightly delayed compared to port A. Set the buffer length n = 4. The judgment steps are as follows: Step1: The initial PFSN is an invalid value. Receive FSN = 1 from port A. Determine that PFSN != FSN. The message is valid and enters the queue. PFSN = FSN. The message starts a timer. Step2: Receive FSN = 1 from port B. Determine that PFSN == FSN and discard it repeatedly. Step3: Receive FSN = 2 from port A. Determine that PFSN != FSN. The message is valid and enters the queue. PFSN = FSN. The message starts a timer. Step4: Receive FSN = 2 at port B and process it in the same way as step2; Step5: Receive FSN = 4 at port A and process it in the same way as step3; Step6: Receive FSN = 3 at port B and process it in the same way as step3, queue it for sorting, and start a timer for the message; At this time, PFSN is updated to 3; Step7: Receive FSN = 3 at port A and process it in the same way as step2; Step8: Receive FSN = 4 at port B. Although FSN!= PFSN, when queuing for sorting, it is found that there is an SN of 4 in the queue, and the queue discards it repeatedly, that is, it fails to pass the second deduplication; Step9: Receive FSN = 5 at port A and process it in the same way as step3. The queue is full and 1 dequeues; Step10: Receive FSN = 5 at port B and process it in the same way as step2.

[0026] This embodiment details a method for complementing messages through an alternative line in an out-of-order scenario. The output result after processing by the redundancy management algorithm specified in the A664P7 standard is 1→2→4→5, resulting in the loss of message 3 at both port A and port B. However, the output result after processing by the present invention is the complete 1→2→3→4→5.

[0027] The above two embodiments demonstrate the excellent performance of the present invention in packet loss and out-of-order scenarios. It is not difficult to see that in an actual operating scenario where packet loss and out-of-order occur jointly, the performance of the present invention has great advantages compared with the traditional standard-defined methods. It can not only ensure the complete reception and sorting of messages but also ensure that critical messages are sent on time with the help of a timer.

[0028] The above description of the disclosed embodiments is only to enable those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for end - system redundancy management in case of packet loss and out - of - order in an AFDX network, with parameters including frame sequence number SN, previous frame sequence number PFSN, current frame sequence number FSN, and buffer length n, characterized in that, It includes the following steps: S1: Initialize PFSN to an invalid value; S2: Receive the first frame of channel A or B in sequence, record the FSN value; judge whether FSN!= PFSN. If it is valid, put it into the queue and update PFSN = FSN; S3: Receive the next frame of channel A or B in sequence, record the FSN value; judge whether FSN!= PFSN: if not, repeat and discard; if so, it is valid, update PFSN = FSN, put the message into the queue, and sort it in ascending order of SN. If it is found that the SN is repeated in the queue, discard the message; S4: Repeat S3; if the cache queue is full, send the first message from the head of the queue.

2. The method for end - system redundancy management in case of packet loss and out - of - order in an AFDX network as claimed in claim 1, wherein, Set a maximum tolerance delay timer for each message, start it when the message is stored in the cache queue, and send the message from the queue when the timer expires.

3. The method for end - system redundancy management in case of packet loss and out - of - order in an AFDX network as described in claim 2, wherein, The maximum tolerance delay timer for each message can be configured independently.

4. A method for end-system redundancy management in case of packet loss and out-of-order in an AFDX network, as described in any one of claims 1-3, characterized in that The value of n is 3 - 6.

5. The method for end - system redundancy management in case of packet loss and out - of - order in an AFDX network as described in claim 4, characterized in that, The value of n is 4.