Triple redundant data synchronization method and system based on dynamic priority weighting
Through the dynamic priority weighted triple redundant data synchronization method, the module health is evaluated in real time and the weight is adjusted, which solves the reliability problem of traditional TMR in complex environments, and achieves higher fault tolerance and resource utilization.
Patent Information
- Application Number
- CN202510905568.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-02
AI Technical Summary
When traditional triple redundant systems face industrial environments such as electromagnetic interference, vibration and high temperature, the module instantaneous failure or data drift, resulting in a simple majority vote that may adopt wrong results. The static redundant mode does not take into account the real-time health status of the module, affecting the system reliability.
The triple redundant data synchronization method based on dynamic priority weighting is adopted. By collecting multi-source data, the health index of the processor module is calculated, its weight is dynamically adjusted, and the module health is automatically isolated and hot backup is started when the module health declines.
It improves the system's fault tolerance and resource utilization, improves reliability and real-time performance in complex industrial environments, can identify potential faults in advance and automatically isolate low-health modules, reducing the risk of system downtime.
Smart Images

Figure CN120407689A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of automation, and in particular, relates to a triple modular redundancy data synchronization method and system based on dynamic priority weighting. Background Art
[0002] The triple modular redundancy system (TMR) is a technology that improves the reliability and fault tolerance of a system through redundant design and is widely used in safety-critical fields (such as aerospace, nuclear power, rail transit, etc.). The triple modular redundancy system consists of three identical functional modules running in parallel, and each module independently processes the input and generates an output. The outputs of the three modules are compared in real time, and the majority voting (2-out-of-3) principle is adopted. The core idea is to shield single faults through the majority voting mechanism to ensure the continuous normal operation of the system. In the triple modular redundancy system (TMR), the synchronous voting mechanism is the core link to ensure that the outputs of the three redundant modules can be correctly compared and the final result can be generated. Its design directly affects the fault tolerance, real-time performance, and reliability of the system.
[0003] The existing synchronous voting mechanism of TMR is as follows: First, the three input modules receive the same input data, and strict synchronization of the input is ensured through a hardware clock or a software protocol. Then, the input is independently processed by three independent processor modules to generate output results. Finally, the output results are sent to a voter, and the voter compares the three results. If the three are exactly the same, the result is directly output; if two of them are the same and one is different, the majority result is selected, and the faulty module is marked; if all three are different, error handling is triggered, such as system reset or switching to a standby module. The marked faulty module can be isolated, restarted, or repaired online, and at the same time, the system continues to run based on the remaining modules.
[0004] Triple modular redundancy (TMR) performs the same task through three independent modules and votes on the output, and theoretically can tolerate single-module faults. The traditional synchronous voting method has the following defects: Existing safety control systems, such as gas turbine speed control, reactor temperature monitoring, and rail transit signal systems, have electromagnetic interference, vibration, high temperature, etc. in the industrial field, which can cause instantaneous faults or data drift of the modules. Traditional TMR adopts simple majority voting, such as two-out-of-three voting. If two modules make mistakes simultaneously due to instantaneous interference, the system will adopt the wrong result. Secondly, the static redundancy mode of traditional TMR does not consider the real-time health status of the modules (such as temperature and voltage fluctuations), and the faulty module still has full voting rights, which may long-term affect the effective reliability of the system. Summary of the Invention
[0005] To solve the above technical problems, the present invention proposes a technical solution of a triple-redundancy data synchronization method based on dynamic priority weighting to solve the above technical problems.
[0006] The first aspect of the present invention discloses a triple-redundancy data synchronization method based on dynamic priority weighting, including three processor modules of A, B, and C. The method includes: Step S1: In each cycle, collect multi-source data from the three processor modules of A, B, and C; the multi-source data includes: processor module input values, environmental sensor data, historical error records, and mean time between failures. Step S2: Calculate the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures; the health index includes: logical error rate, environmental immunity, and historical reliability. Step S3: Calculate the dynamic weight of each processor module according to the health index of each processor module, and normalize the dynamic weight. Step S4: Calculate the weighted support degree of the input value according to the processor module input value and the normalized dynamic weight; vote and select the input value according to the weighted support degree as the voting output of the three processor modules. Step S5: If the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a continuous preset number of cycles, an alarm will be triggered, the processor module will be automatically isolated, and hot backup will be started.
[0007] According to the method of the first aspect of the present invention, in the step S1, The processor module input value is an industrial parameter; The environmental sensor data includes: temperature, voltage, and vibration amplitude; The historical error record includes: the number of CRC check failures in the predefined sub-synchronization period of the processor module; The mean time between failures includes: the mean time between failures extracted from the log.
[0008] According to the method of the first aspect of the present invention, in the step S2, the calculation of the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures includes: Calculate the logical error rate according to the number of CRC check failures. The specific formula is:
[0009] Where, represents the logical error rate of the i th processor module; represents the iThe number of CRC check failures of a processor module; Indicates a predefined number of synchronization cycles; ; Calculate the environmental immunity according to the temperature, voltage and vibration amplitude, specific formula:
[0010] Wherein, Indicates the i th environmental immunity of the processor module; Indicates the i th temperature of the processor module; Indicates the i th voltage of the processor module; Indicates the i th vibration amplitude of the processor module; Indicates the temperature weight; Indicates the voltage weight; Indicates the vibration amplitude weight; And Indicates the maximum operating temperature and the set operating temperature; And Indicates the maximum operating voltage and the rated operating voltage; Indicates the maximum operating vibration amplitude; Calculate the historical reliability according to the mean time between failures, specific formula:
[0011] Wherein, Indicates the i th historical reliability of the processor module; Indicates the i th mean time between failures of the processor module; Indicates the mean time between failures of the A processor module; Indicates the mean time between failures of the B processor module; Indicates the mean time between failures of the C processor module.
[0012] According to the method of the first aspect of the present invention, in the step S3, the calculating the dynamic weight of each processor module according to the health index of each processor module includes:
[0013] Wherein, Indicates the i th dynamic weight of the processor module; Indicates the i th logical error rate of the processor module; Indicates thei The environmental immunity of a processor module; denote the i historical reliability of the , and denote the weights of the logical error rate, environmental immunity, and historical reliability, where α + β + γ = 1, and α, β, γ are adjustable coefficients; .
[0014] According to the method of the first aspect of the present invention, in the step S3, normalizing the dynamic weights includes:
[0015] wherein, denote the i normalized dynamic weights of the denote the dynamic weight of processor module A; denote the dynamic weight of processor module B; denote the dynamic weight of processor module C.
[0016] According to the method of the first aspect of the present invention, in the step S4, calculating the weighted support degree of the input value according to the processor module input value and the normalized dynamic weights includes:
[0017] wherein, denote the weighted support degree of the input value; denote the i normalized dynamic weights of the denote the i input value of the denote the input value of a certain processor module.
[0018] According to the method of the first aspect of the present invention, in the step S4, voting and selecting the input value according to the weighted support degree as the voting output of the triple modular redundant processor module includes: Select the input value with the largest weighted support degree as the voting output.
[0019] The second aspect of the present invention discloses a triple modular redundant data synchronization system based on dynamic priority weighting, and the system includes: A first processing module, configured to collect multi-source data for the A, B, and C triple modular redundant processor modules respectively in each cycle; the multi-source data includes: processor module input values, environmental sensor data, historical error records, and mean time between failures; A second processing module, configured to calculate a health metric for each processor module according to the environmental sensor data, historical error records, and mean time between failures; the health metric includes: a logical error rate, environmental immunity, and historical reliability; A third processing module, configured to calculate a dynamic weight for each processor module according to the health metric of each processor module, and normalize the dynamic weight; A fourth processing module, configured to calculate a weighted support degree of the input value according to the processor module input value and the normalized dynamic weight; vote and select the input value according to the weighted support degree as the voting output of the triple processor module; A fifth processing module, configured to trigger an alarm if the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a continuously preset number of cycles, automatically isolate the processor module, and start hot backup.
[0020] A third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps in any one of the first aspects of the present disclosure, a triple redundant data synchronization method based on dynamic priority weighting, are implemented.
[0021] A fourth aspect of the present invention discloses a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps in any one of the first aspects of the present disclosure, a triple redundant data synchronization method based on dynamic priority weighting, are implemented.
[0022] In summary, the solution proposed by the present invention can dynamically adjust its voting weight by real-time evaluating the module health, combine weighted voting with a fault pre-isolation mechanism, and improve the system fault tolerance and resource utilization rate. Description of the Drawings
[0023] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 It is a flowchart of a triple redundant data synchronization method based on dynamic priority weighting according to an embodiment of the present invention; Figure 2 It is a structural diagram of a triple redundant data synchronization system based on dynamic priority weighting according to an embodiment of the present invention; Figure 3 Structural diagram of an electronic device according to an embodiment of the present invention. Detailed implementation manners
[0025] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0026] The first aspect of the present invention discloses a triple-redundancy data synchronization method based on dynamic priority weighting. Figure 1 Flowchart of a triple-redundancy data synchronization method based on dynamic priority weighting according to an embodiment of the present invention, as Figure 1 shown, the method includes: Step S1: Collect multi-source data for processor modules A, B, and C respectively in each cycle; the multi-source data includes: processor module input value, environmental sensor data, historical error records, and mean time between failures. Step S2: Calculate the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures; the health index includes: logical error rate, environmental immunity, and historical reliability. Step S3: Calculate the dynamic weight of each processor module according to the health index of each processor module, and normalize the dynamic weight. Step S4: Calculate the weighted support degree of the input value according to the processor module input value and the normalized dynamic weight; vote and select the input value according to the weighted support degree as the voting output of the triple processor module. Step S5: If the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a continuous preset number of cycles, an alarm will be triggered, and the processor module will be automatically isolated and hot backup will be started.
[0027] In step S1, collect multi-source data for processor modules A, B, and C respectively in each cycle; the multi-source data includes: processor module input value, environmental sensor data, historical error records, and mean time between failures.
[0028] In some embodiments, in step S1, the processor module input value is an industrial parameter, such as industrial parameters like temperature and pressure); The environmental sensor data includes: temperature, voltage, and vibration amplitude, (monitored independently for each module); The historical error records include: the number of CRC check failures in the predefined subsynchronous cycle of the processor module; The mean time between failures includes: the mean time between failures extracted from the log.
[0029] In step S2, calculate the health index of each processor module according to the environmental sensor data, historical error records and mean time between failures; the health index includes: logical error rate, environmental immunity and historical reliability.
[0030] In some embodiments, in step S2, calculating the health index of each processor module according to the environmental sensor data, historical error records and mean time between failures includes: Calculate the logical error rate according to the number of CRC check failures, and the specific formula is:
[0031] Wherein, represents the logical error rate of the i th processor module; represents the i th processor module's number of CRC check failures; [[ID=z6]]represents the predefined number of synchronization cycles; ; Logical error rate directly reflects the current calculation or communication anomalies of the module, and can detect transient errors in the first time, such as bit flips caused by electromagnetic pulses. By sliding window to count the number of errors in the recent N synchronization cycles, it avoids the excessive interference of single accidental errors on the weight. In industrial control, logical errors are often caused by signal interference, software deadlocks, etc. This index is the first line of defense for the fault-tolerant system. For example, if module A has CRC check failures or outputs out-of-range pressure values for 3 consecutive cycles, its error rate rises and the weight immediately drops to prevent the spread of errors.
[0032] Calculate the environmental immunity according to the temperature, voltage and vibration amplitude, and the specific formula is:
[0033] Wherein, represents the environmental immunity of the i th processor module; represents the i th processor module's temperature; represents the i th processor module's voltage; represents the i th processor module's vibration amplitude; Represents the temperature weight; Represents the voltage weight; Represents the vibration amplitude weight; And Represents the maximum operating temperature and the set operating temperature; And Represents the maximum operating voltage and the rated operating voltage; Represents the maximum operating vibration amplitude; , , Default is 1 / 3; Through sensor data such as temperature, voltage, and vibration, the identification module can identify the gradual physical deterioration, such as performance degradation caused by poor heat dissipation, loose connectors, etc. In industrial environments (such as power plants, chemical plants), physical interferences such as high temperature and vibration may affect multiple modules simultaneously. This indicator can provide early warnings of common cause risks. Continuous high vibration or over-temperature signals indicate hardware aging, and the module needs to be replaced in advance. For example, when the temperature of module B rises to 70°C (exceeding the rated 50°C) due to a cooling fan failure, its P B Decreases. Even if the logic does not report an error, the weight will also decrease to avoid potential failures caused by high temperature.
[0034] Calculate the historical reliability according to the mean time between failures, and the specific formula is:
[0035] Wherein, Represents the historical reliability of the i th processor module; Represents the mean time between failures of the i th processor module; Represents the mean time between failures of processor module A; Represents the mean time between failures of processor module B; Represents the mean time between failures of processor module C.
[0036] Quantify the inherent reliability of the module based on MTBF (mean time between failures) and identify "high failure tendency" modules. If a module is stable for a long time (high MTBF), a single instantaneous error will not significantly reduce its weight, avoiding overreaction. Guide the system to give priority to trusting modules with excellent historical performance and reduce the overall maintenance cost. For example, module C has been fault-free in the past year (MTBF = 10,000 hours). During a certain interference, it made a short-term error. Due to being relatively high, the weight only decreased slightly, and the system still tended to trust its data.
[0037] Specifically, the collaborative design logic of the three health indicators is shown in Table 1.
[0038] Table 1
[0039] The industrial TMR system is required to cover all failure modes (physical + logical + long-term / short-term), and the combination of the three indicators can achieve: short-term fault tolerance (E), medium-term early warning (P), and long-term optimization (H). The covered fault types include: random hardware faults, systematic faults, and environmental faults.
[0040] In step S3, calculate the dynamic weight of each processor module according to the health index of each processor module, and normalize the dynamic weight.
[0041] In some embodiments, in step S3, calculating the dynamic weight of each processor module according to the health index of each processor module includes:
[0042] where represents the dynamic weight of the i th processor module; represents the logical error rate of the i th processor module; represents the environmental immunity of the i th processor module; represents the historical reliability of the i th processor module; , and represent the weights of the logical error rate, environmental immunity, and historical reliability, α + β + γ = 1, and α, β, γ are adjustable coefficients. It is recommended that α = 0.6, β = 0.3, and γ = 0.1; .
[0043] Normalizing the dynamic weight includes:
[0044] where represents the normalized dynamic weight of the i th processor module; represents the dynamic weight of processor module A; represents the dynamic weight of processor module B; represents the dynamic weight of processor module C.
[0045] Specifically, the determination of parameters needs to be optimized in combination with the specific requirements of industrial control scenarios. In industrial control systems, instantaneous logic errors (such as communication packet loss and data verification failure) are the most frequent direct causes of control failure. Therefore, in an environment with strong electromagnetic interference (such as near a frequency converter), the weight of α (logic error rate) needs to be appropriately increased. Abnormal physical parameters such as temperature and vibration are usually precursors of hardware failures, but their effects lag behind logic errors. Therefore, in harsh environments such as a metallurgical workshop with high temperature / high vibration, the weight of β (environmental immunity) can be increased to 0.4; in a constant temperature and clean environment such as a laboratory, the weight of β (environmental immunity) can be reduced to 0.1. MTBF reflects the long-term stability of the module, but its contribution to real-time fault response is limited. Therefore, when there are large differences in the quality of module batches, such as mixing new and old hardware, γ (historical reliability) needs to be increased to 0.3 to distinguish reliability. When the modules are highly homogeneous, such as in the same batch, γ can be reduced to 0.05.
[0046] The determination of the α, β, and γ coefficients can also be adaptively adjusted according to different operating stages. For example, in the startup stage, since the environmental parameters are not stable, such as during the equipment preheating period, the weight of β (environmental immunity) is increased; during the stable operation period, the standard weight dominated by α (logic error rate) is restored; during the system maintenance period, the weight of γ (historical reliability) is increased to identify modules that are about to reach the end of their lifespan.
[0047] In step S4, according to the input value of the processor module and the normalized dynamic weight, calculate the weighted support degree of the input value; vote and select the input value according to the weighted support degree as the voting output of the three-system processor module.
[0048] In some embodiments, in the step S4, the calculating the weighted support degree of the input value according to the input value of the processor module and the normalized dynamic weight includes:
[0049] where represents the weighted support degree of the input value; represents the normalized dynamic weight of the i th processor module; represents the input value of the i th processor module; represents the input value of a certain processor module.
[0050] The voting and selecting the input value according to the weighted support degree as the voting output of the three-system processor module includes: Select the input value with the largest weighted support degree as the voting output.
[0051] Specifically, for example, the module input value , and the weight of module A = 0.6 (Healthy), weight of Module B = 0.3 (Occasional recent errors), weight of Module C = 0.1 (High - temperature alarm).
[0052] The data of A and B are consistent, C is different, W(100)=(0.6 + 0.3)>W(105)=0.1, and the final result adopts the data of A / B .
[0053] For another example, the input value of the module , and the weight of Module A = 0.6 (Healthy), weight of Module B = 0.3 (Occasional recent errors), weight of Module C = 0.1 (High - temperature alarm).
[0054] The collected values of processors A, B, and C are different, W(100)=0.6>W(102)=0.3>W(105)=0.1, and the final result adopts the data of A .
[0055] In step S5, if the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a continuous preset number of cycles, an alarm will be triggered, the processor module will be automatically isolated, and the hot backup will be started.
[0056] Specifically, , for K consecutive cycles. It is usually set to 0.2, K = 5.
[0057] Example 1: The following is a complete digital deduction example for the temperature control of a chemical reactor, showing how the dynamic weighting algorithm copes with sensor drift and sudden interference. The system needs to maintain a temperature set value of 150 °C, including the detailed data changes in 5 consecutive cycles.
[0058] Initial parameter setting Module health status: Module A: MTBF = 9,000 hours, initial temperature = 148 °C (slight negative drift of the sensor) Module B: MTBF = 6,000 hours, initial temperature = 150 °C (sensitive to voltage fluctuations) Module C: MTBF = 12,000 hours, initial temperature = 151 °C Weight coefficients: α = 0.6 (logic error rate), β = 0.25 (environmental immunity), γ = 0.15 (historical reliability) Dynamic threshold: Temperature tolerance ±2 °C, voltage fluctuation > 10% triggers weight reduction Error rate window: N = 5 (count the number of errors in the last 5 cycles) Alarm rule: (If it is lower than this value for 2 consecutive cycles, the module will be isolated.)
[0059] Deduction of cycles 1-5 in the implementation example of gas turbine speed control is shown in Table 2.
[0060] Table 2
[0061] Cycle 2: Voltage dip event The supply voltage of Module B drops by 10%, and the output abnormal temperature is 145°C (5°C lower than the set value).
[0062] Health calculation: Logic error rate: =1 / 5 = 0.2 Environmental immunity: =1 - [0.5×0.1 (voltage) + 0.5×(5 / 150) (temperature)] = 0.933 Historical reliability: =6,000 / (9,000 + 6,000 + 12,000) = 0.222 =0.6×(1 - 0.2) + 0.25×0.933 + 0.15×0.222 = 0.747 Weight update: =0.35, =0.29, =0.36 Voting result: W(148) = 0.35, W(145) = 0.29, W(151) = 0.36, and the output C value is 151°C.
[0063] Cycle 3: Superposition of sensor drift and voltage fault Module A has a continuous drift of -2°C, and the voltage of Module B has not recovered.
[0064] Weight change: Because =0.2 drops to 0.33, Because =0.4 further drops to 0.27.
[0065] System action: The weight of Module B is <0.3 for 2 consecutive cycles, triggering the isolation process.
[0066] Cycle 5: Activation of standby module The new module D (high MTBF) is added, and the weight is initialized to 0.40, and the system restores balanced voting.
[0067] In summary, the solution proposed by the present invention presents a dynamic priority weighted synchronization algorithm, which dynamically adjusts its voting weight by real-time evaluating the module health. A multi-dimensional health model is adopted to comprehensively quantify the module health status in terms of logical error rate, physical environment parameters, and historical reliability. Combining weighted voting with a fault isolation mechanism enhances the system's fault tolerance and resource utilization.
[0068] The health status of the processor module is quantified through a dynamic weight mechanism. The healthy module obtains a higher voting weight, suppressing the influence of the low-health module, significantly enhancing the reliability of the TMR system in an industrial complex environment, and having the advantages of real-time performance and maintainability, being suitable for safety-critical control fields.
[0069] In addition, the present invention can automatically isolate continuously low-weight modules and activate standby units. The faulty module can be repaired or replaced in the background without affecting the system operation. Potential faulty modules can be identified in advance to avoid sudden shutdowns.
[0070] The second aspect of the present invention discloses a triple modular redundant data synchronization system based on dynamic priority weighting. Figure 2 It is a structural diagram of a triple modular redundant data synchronization system according to an embodiment of the present invention; as Figure 2 shown, the system 100 includes: The first processing module 101 is configured to collect multi-source data for the processor modules of the three systems A, B, and C respectively in each cycle; the multi-source data includes: processor module input values, environmental sensor data, historical error records, and mean time between failures; The second processing module 102 is configured to calculate the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures; the health index includes: logical error rate, environmental immunity, and historical reliability; The third processing module 103 is configured to calculate the dynamic weight of each processor module according to the health index of each processor module and normalize the dynamic weight; The fourth processing module 104 is configured to calculate the weighted support degree of the input value according to the processor module input value and the normalized dynamic weight; vote and select the input value according to the weighted support degree as the voting output of the three-system processor module; The fifth processing module 105 is configured to, if the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a continuous preset number of cycles, trigger an alarm, automatically isolate the processor module, and start the hot backup.
[0071] For the system according to the second aspect of the present invention, the first processing module 101 is specifically configured to, the processor module input value is an industrial parameter, (such as industrial parameters like temperature, pressure, etc.); The environmental sensor data includes: temperature, voltage, and vibration amplitude, (each module monitors independently); The historical error record includes: the number of times of CRC check failure in the predefined subsynchronous cycle of the processor module; The mean time between failures includes: the mean time between failures extracted from the log.
[0072] For the system according to the second aspect of the present invention, the second processing module 102 is specifically configured that calculating the health index of each processor module according to the environmental sensor data, historical error record, and mean time between failures includes: Calculating the logic error rate according to the number of times of CRC check failure, the specific formula:
[0073] Wherein, represents the logic error rate of the i th processor module; represents the i th processor module; represents the predefined number of times of the synchronization cycle; ; Logic error rate directly reflects the current calculation or communication anomaly of the module, can detect transient errors in the first time, such as bit flips caused by electromagnetic pulses. By statistically counting the number of errors in the recent N synchronization cycles through a sliding window, it avoids excessive interference of single accidental errors on the weight. In industrial control, logic errors are often caused by signal interference, software deadlocks, etc. This index is the first line of defense for the fault-tolerant system. For example, if module A has CRC check failures or outputs out-of-range pressure values for 3 consecutive cycles, its error rate rises and the weight immediately drops to prevent the spread of errors.
[0074] Calculating the environmental immunity according to the temperature, voltage, and vibration amplitude, the specific formula:
[0075] Wherein, represents the environmental immunity of the i th processor module; represents the i th processor module; represents the i th processor module; represents the i th processor module; represents the temperature weight; represents the voltage weight; represents the vibration amplitude weight; and represents the maximum operating temperature and the set operating temperature; and represents the maximum operating voltage and the rated operating voltage; represents the maximum operating vibration amplitude; , , the default is 1 / 3; Through sensor data such as temperature, voltage, and vibration, the recognition module identifies the gradual physical deterioration, such as performance degradation caused by poor heat dissipation, loose connectors, etc. In industrial environments (such as power plants and chemical plants), physical interferences such as high temperature and vibration may affect multiple modules simultaneously. This indicator can early warn of the common cause risk. Continuous high vibration or over-temperature signals indicate hardware aging, and the module needs to be replaced in advance. For example, when the temperature of module B rises to 70 °C (exceeding the rated 50 °C) due to a cooling fan failure, its P B decreases. Even if the logic does not report an error, the weight will also decrease to avoid potential failures caused by high temperature.
[0076] Calculate the historical reliability according to the mean time between failures, and the specific formula:
[0077] Among them, represents the historical reliability of the i th processor module; represents the mean time between failures of the i th processor module; represents the mean time between failures of processor module A; represents the mean time between failures of processor module B; represents the mean time between failures of processor module C.
[0078] Quantify the inherent reliability of the module based on MTBF (mean time between failures), and identify the "high failure tendency" module. If a module is stable for a long time (high MTBF), a single instantaneous error will not significantly reduce its weight, avoiding overreaction. Guide the system to give priority to trusting the modules with excellent historical performance, reducing the overall maintenance cost. For example, module C has been fault-free in the past year (MTBF = 10,000 hours). During a certain interference, it made a brief error. Due to being relatively high, the weight only decreased slightly, and the system still tended to trust its data.
[0079] Specifically, the industrial TMR system requires covering all failure modes (physical + logical + long-term / short-term), and the three-index combination can achieve: short-term fault tolerance (E), medium-term early warning (P), and long-term optimization (H). The covered fault types include: random hardware faults, systematic faults, and environmental faults.
[0080] For the system according to the second aspect of the present invention, the third processing module 103 is specifically configured such that calculating the dynamic weight of each processor module according to the health index of each processor module includes:
[0081] Wherein, represents the dynamic weight of the i th processor module; represents the logical error rate of the i th processor module; represents the environmental immunity of the i th processor module; represents the historical reliability of the i th processor module; , and represent the weights of the logical error rate, environmental immunity, and historical reliability, α + β + γ = 1, and α, β, γ are adjustable coefficients. It is recommended that α = 0.6, β = 0.3, γ = 0.1; .
[0082] Normalizing the dynamic weight includes:
[0083] Wherein, represents the normalized dynamic weight of the i th processor module; represents the dynamic weight of processor module A; represents the dynamic weight of processor module B; represents the dynamic weight of processor module C.
[0084] Specifically, the determination of parameters needs to be optimized in combination with the specific requirements of the industrial control scenario. In an industrial control system, instantaneous logic errors (such as communication packet loss and data verification failure) are the most frequent reasons directly leading to control failure. Therefore, in an environment with strong electromagnetic interference (such as near a frequency converter), the weight of α (logic error rate) needs to be appropriately increased. Abnormal physical parameters such as temperature and vibration are usually precursors of hardware failures, but the impact lags behind logic errors. Therefore, in a harsh environment scenario, such as a metallurgical workshop with high temperature / high vibration, the weight of β (environmental immunity) can be increased to 0.4; in a constant temperature and clean environment, such as a laboratory, the weight of β (environmental immunity) can be reduced to 0.1. MTBF reflects the long-term stability of the module, but its contribution to real-time fault response is limited. Therefore, when there are large differences in the quality of module batches, such as mixing new and old hardware, γ (historical reliability) needs to be increased to 0.3 to distinguish reliability. When the modules are highly homogeneous, such as in the same batch, γ can be reduced to 0.05.
[0085] The determination of the α, β, and γ coefficients can also be adaptively adjusted according to different operating stages. For example, in the startup stage, the environmental parameters are not stable, such as during the equipment preheating period, the weight of β (environmental immunity) is increased; in the stable operation period, the standard weight dominated by α (logic error rate) is restored; in the system maintenance period, the weight of γ (historical reliability) is increased to identify modules that are about to reach the end of their lifespan.
[0086] In the system according to the second aspect of the present invention, the fourth processing module 104 is specifically configured that calculating the weighted support degree of the input value according to the input value of the processor module and the normalized dynamic weight includes:
[0087] wherein, represents the weighted support degree of the input value; represents the normalized dynamic weight of the i th processor module; represents the input value of the i th processor module; represents the input value of a certain processor module.
[0088] Voting and selecting the input value according to the weighted support degree as the voting output of the three-system processor module includes: Select the input value with the largest weighted support degree as the voting output.
[0089] Specifically, for example, the module input value , and the weight of module A = 0.6 (healthy), the weight of module B = 0.3 (occasional recent errors), and the weight of module C = 0.1 (high temperature alarm).
[0090] The data of A and B are consistent, while that of C is different. W(100) = (0.6 + 0.3) > W(105) = 0.1, and the final result adopts the data of A / B. 。
[0091] For another example, the input value of the module , and the weight of module A = 0.6 (healthy), the weight of module B = 0.3 (occasional recent errors), and the weight of module C = 0.1 (high - temperature alarm).
[0092] The collected values of processors A, B, and C are different. W(100) = 0.6 > W(102) = 0.3 > W(105) = 0.1, and the final result adopts the data of A. 。
[0093] According to the system of the second aspect of the present invention, the fifth processing module 105 is specifically configured to , for K consecutive cycles. It is usually set to 0.2, and K = 5.
[0094] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor. When the processor executes the computer program stored in the memory, it implements the steps in any one of the methods for triple redundant data synchronization based on dynamic priority weighting in the first aspect disclosed by the present invention.
[0095] Figure 3 As shown in Figure 3 which is a structural diagram of an electronic device according to an embodiment of the present invention, the electronic device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non - volatile storage medium and an internal memory. The non - volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non - volatile storage medium. The communication interface of the electronic device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, near - field communication (NFC), or other technologies. The display screen of the electronic device can be a liquid crystal display screen or an electronic ink display screen. The input device of the electronic device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the electronic device, or an external keyboard, a touchpad, or a mouse, etc.
[0096] Those skilled in the art can understand, Figure 3The structure shown is only a structural diagram of the part related to the technical solution of the present disclosure, and does not constitute a limitation on the electronic device to which the solution of this application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have a different component layout.
[0097] The fourth aspect of the present invention discloses a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps in a triple redundant data synchronization method based on dynamic priority weighting according to any one of the first aspect of the present invention are implemented.
[0098] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification. The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A triple-redundancy data synchronization method based on dynamic priority weighting, comprising: A, B, and C series processor modules, characterized in that the method includes: Step S1: In each cycle, collect multi-source data for the A, B, and C series processor modules respectively; the multi-source data includes: processor module input values, environmental sensor data, historical error records, and mean time between failures; Step S2: Calculate the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures; the health index includes: logical error rate, environmental immunity, and historical reliability; Step S3: Calculate the dynamic weight of each processor module according to the health index of each processor module, and normalize the dynamic weight; Step S4: Calculate the weighted support degree of the input value according to the processor module input value and the normalized dynamic weight; vote and select the input value according to the weighted support degree as the voting output of the three-series processor module; Step S5: If the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a continuously preset number of cycles, an alarm will be triggered, the processor module will be automatically isolated, and hot backup will be started.
2. The triple redundant data synchronization method based on dynamic priority weighting according to claim 1, characterized in that In the step S1, The processor module input value is an industrial parameter; The environmental sensor data includes: temperature, voltage, and vibration amplitude; The historical error record includes: the number of CRC check failures in the predefined sub-synchronous cycle of the processor module; The mean time between failures includes: the mean time between failures extracted from the log.
3. A triple-redundancy data synchronization method based on dynamic priority weighting according to claim 2, wherein In the step S2, the calculation of the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures includes: Calculating the logical error rate according to the number of CRC check failures, the specific formula: Among them, represents the logical error rate of the i th processor module; represents the number of CRC check failures of the i th processor module; represents the predefined number of synchronization cycles; ; Calculating the environmental immunity according to the temperature, voltage, and vibration amplitude, the specific formula: Among them, represents the environmental immunity of the i th processor module; represents the temperature of the i th processor module; represents the voltage of the i th processor module; represents the vibration amplitude of the i th processor module; represents the temperature weight; represents the voltage weight; represents the vibration amplitude weight; and represents the maximum operating temperature and the set operating temperature; and represents the maximum operating voltage and the rated operating voltage; represents the maximum operating vibration amplitude; Calculating the historical reliability according to the mean time between failures, the specific formula: in, Indicates the i Historical reliability of each processor module; Indicates the i MTBF per processor module; Indicates the mean time between failures of processor module A; Indicates the mean time between failures of the B processor module; Indicates the mean time between failures of the C processor module.
4. A triple-redundancy data synchronization method based on dynamic priority weighting according to claim 1, characterized in that In the step S3, the calculation of the dynamic weight of each processor module according to the health index of each processor module includes: Among them, represents the dynamic weight of the i th processor module; represents the logical error rate of the i th processor module; represents the environmental immunity of the i th processor module; represents the historical reliability of the i th processor module; , and represent the weights of the logical error rate, environmental immunity, and historical reliability, where α + β + γ = 1, and α, β, γ are adjustable coefficients; .
5. A triple-redundancy data synchronization method based on dynamic priority weighting according to claim 4, characterized in that In the step S3, the normalization of the dynamic weight includes: Among them, represents the normalized dynamic weight of the i th processor module; represents the dynamic weight of processor module A; represents the dynamic weight of processor module B; represents the dynamic weight of processor module C.
6. A triple-redundancy data synchronization method based on dynamic priority weighting according to claim 1, characterized in that In the step S4, the calculation of the weighted support degree of the input value according to the processor module input value and the normalized dynamic weight includes: Among them, represents the weighted support degree of the input value; represents the normalized dynamic weight of the i th processor module; represents the input value of the i th processor module; represents the input value of a certain processor module.
7. A triple-redundancy data synchronization method based on dynamic priority weighting according to claim 1, characterized in that In the step S4, the voting and selection of the input value according to the weighted support degree as the voting output of the three-series processor module includes: Select the input value with the largest weighted support degree as the voting output.
8. A triple-redundancy data synchronization system for dynamic priority weighting, characterized in that The system includes: The first processing module is configured to collect multi-source data for the A, B, and C series processor modules respectively in each cycle; the multi-source data includes: processor module input values, environmental sensor data, historical error records, and mean time between failures; The second processing module is configured to calculate the health index of each processor module according to the environmental sensor data, historical error records, and mean time between failures; the health index includes: logical error rate, environmental immunity, and historical reliability; The third processing module is configured to calculate the dynamic weight of each processor module according to the health index of each processor module and normalize the dynamic weight; The fourth processing module is configured to calculate the weighted support degree of the input value according to the input value of the processor module and the normalized dynamic weight; vote and select the input value according to the weighted support degree as the voting output of the triple processor module; The fifth processing module is configured to trigger an alarm if the normalized dynamic weight of a certain processor module is lower than a predefined threshold for a preset number of consecutive cycles, automatically isolate the processor module and start hot backup.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor. When the processor executes the computer program stored in the memory, the steps in any one of claims 1 to 7 of a triple redundant data synchronization method based on dynamic priority weighting are implemented.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps in any one of claims 1 to 7 of a triple redundant data synchronization method based on dynamic priority weighting are implemented.
Citation Information
Patent Citations
Ship dynamic positioning three-redundancy computer data voting synchronization method
CN105334747A
Synchronizing and self-checking voting circuit
CN110134554A
Voting algorithm of three-redundancy dynamic positioning system based on improved historical information
CN110347033A
Health modeling and calculating method for voting structure in health state laminar flow logic
CN111553057A
Equipment health evaluation method and system, equipment and storage medium
CN115190039A
Cited By
Fine-grained multi-level management system for audio frequency integrated signal processing
CN120803738A