Time synchronization method and device, electronic equipment and storage medium

By introducing redundant design of the main operating domain and the backup domain in the time synchronization system, stable transmission of time reference in the case of failure is achieved, time synchronization instability caused by a single point of failure is solved, and the security and reliability of the advanced intelligent driving system are improved.

CN120454911APending Publication Date: 2025-08-08CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510799767.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing time synchronization system based on in-vehicle Ethernet has a single point of failure risk, resulting in the loss of time reference and affecting the synchronization stability and security of high-end intelligent driving systems, especially in complex working conditions or high-speed scenarios.

Method used

The redundant design of the main operating domain and the backup domain is introduced, including the main clock, the main link, the main redundant link, the hot standby master clock, the backup link and the emergency link. It quickly switches through real-time monitoring of the status flag bits to ensure the stable transmission of the time reference.

Benefits of technology

In the event of a failure, it can quickly switch to the main redundant link or hot standby master clock, ensuring the continuous stability and security of the time reference and improving the stability and security of system time synchronization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120454911A_ABST
    Figure CN120454911A_ABST
Patent Text Reader

Abstract

The invention relates to a time synchronization method and device, electronic equipment and a storage medium. A state flag bit of a time synchronization system is monitored in real time; under the condition that the state flag bit represents that the main link fails, the main operation domain is switched to transmit the synchronous message through the main redundant link; under the condition that the state flag bit represents the master clock fault, the time synchronization system is switched from the master operation domain to the backup domain, and the backup domain transmits a synchronization message through a backup link; under the condition that the state flag bit represents that the master clock fails and the backup link fails, the hot standby master clock sends a timestamp message to the master clock through the emergency link; and the master clock transmits the synchronization message through the main link based on the timestamp message. According to the method, when a fault occurs, the main redundant link or the hot standby main clock can be quickly switched, and when the main clock fails and the standby link fails, the hot standby main clock can still maintain transmission of the synchronous message through the emergency link, so that the synchronization of the time reference is ensured, and the stability and the safety of system time synchronization are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of time synchronization technology, and in particular to a time synchronization method, device, electronic device and storage medium. Background Art

[0002] In advanced intelligent driving systems, the continuity and accuracy of the time base are crucial to vehicle control and driving safety. Existing time synchronization systems based on automotive Ethernet often rely on a single master clock or single link design, which presents a significant risk of single point failure. Failure of the master clock or link interruption will result in the loss of the time base, impacting the stable synchronization between controllers. Especially in complex operating conditions or high-speed scenarios, the accumulation of time deviations will severely impact the reliability and real-time performance of multi-controller collaboration, posing a serious threat to system safety. Therefore, maintaining stable time synchronization in the event of partial functional failure or malfunction has become an urgent issue. Summary of the Invention

[0003] In order to solve the above technical problems or at least partially solve the above technical problems, the present application provides a time synchronization method, device, electronic device and storage medium.

[0004] In a first aspect, the present application provides a time synchronization method, the method comprising:

[0005] Real-time monitoring of the status flag of the time synchronization system; wherein the time synchronization system includes a primary operation domain and a backup domain, the primary operation domain includes a master clock, a primary link, and a primary redundant link, and the backup domain includes a hot standby master clock, a backup link, and an emergency link; the hot standby master clock is connected to the master clock via the emergency link; when the time synchronization system operates normally, the primary operation domain transmits synchronization messages via the primary link to output the time reference of the master clock;

[0006] When the status flag indicates that the primary link fails, the primary operation domain switches to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock;

[0007] When the status flag indicates that the master clock fails, the time synchronization system switches from the primary operation domain to the backup domain, and the backup domain transmits the synchronization message through the backup link to output the time reference of the backup clock; wherein the time reference of the backup clock is the same as the time reference of the master clock;

[0008] When the status flag indicates that the master clock fails and the backup link fails, the hot standby master clock sends a timestamp message to the master clock through the emergency link; the master clock transmits the synchronization message through the main link based on the timestamp message to output the time reference of the master clock.

[0009] Optionally, before monitoring the status flag of the time synchronization system in real time, the method further includes:

[0010] Configuring the primary operation domain and the backup domain;

[0011] Determining that the primary operation domain and the backup domain are operating normally;

[0012] The master operation domain transmits synchronization messages via the master link to output the time reference of the master clock.

[0013] Optionally, the emergency link is a controller area network bus, and the hot standby master clock is connected to the master clock via the controller area network bus.

[0014] Optionally, the method further includes:

[0015] The backup clock performs clock calibration based on the synchronization message of the master clock at intervals of a first preset time length.

[0016] Optionally, after the primary operation domain switches to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock, the method further includes:

[0017] When the status flag indicates that the primary link has returned to normal, obtaining a duration of the normal state of the primary link;

[0018] If the normal state of the primary link lasts longer than or equal to a second preset time period, the primary operation domain switches to transmitting the synchronization message through the primary link to output the time reference of the master clock and closes the primary redundant link.

[0019] Optionally, after the backup domain transmits the synchronization message through the backup link to output the time reference of the backup clock, the method further includes:

[0020] When the status flag indicates that the master clock has returned to normal, obtaining a duration of the normal state of the master clock;

[0021] If the normal state of the master clock lasts for a period greater than or equal to a third preset period, the time synchronization system switches from the backup domain to the main operation domain, and the main operation domain transmits the synchronization message through the main link to output the time base of the master clock, and stops the backup domain from transmitting the synchronization message through the backup link.

[0022] Optionally, after the master clock transmits the synchronization message through the primary link based on the timestamp message to output the time reference of the master clock, the method further includes:

[0023] When the status flag indicates that the master clock has returned to normal, the master clock calibrates the local clock based on the timestamp message;

[0024] After the master clock calibration is completed, the synchronization message is transmitted through the main link to output the time reference of the master clock, and the hot standby master clock is stopped from sending the timestamp message to the master clock through the emergency link.

[0025] In a second aspect, the present application provides a time synchronization device, the device comprising:

[0026] A monitoring module for monitoring the status flag of a time synchronization system in real time; wherein the time synchronization system includes a primary operation domain and a backup domain, the primary operation domain including a master clock, a primary link, and a primary redundant link, and the backup domain including a hot standby master clock, a backup link, and an emergency link; the hot standby master clock is connected to the master clock via the emergency link; when the time synchronization system operates normally, the primary operation domain transmits synchronization messages via the primary link to output the time reference of the master clock;

[0027] A first switching module is configured to, when the status flag indicates that the primary link has failed, cause the primary operation domain to switch to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock;

[0028] a second switching module, configured to, when the status flag indicates that the master clock has failed, switch the time synchronization system from the primary operation domain to the backup domain, and the backup domain transmit the synchronization message through the backup link to output the time reference of the backup clock; wherein the time reference of the backup clock is the same as the time reference of the master clock;

[0029] The third switching module is used to, when the status flag indicates that the master clock fails and the backup link fails, the hot standby master clock sends a timestamp message to the master clock through the emergency link; the master clock transmits the synchronization message through the main link based on the timestamp message to output the time reference of the master clock.

[0030] In a third aspect, the present application provides an electronic device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0031] Memory for storing computer programs;

[0032] The processor is used to implement the steps of the time synchronization method described in any one of the embodiments of the first aspect when executing the program stored in the memory.

[0033] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the time synchronization method as described in any one of the embodiments of the first aspect.

[0034] Beneficial effects of this application:

[0035] The time synchronization method provided in an embodiment of the present application monitors the status flag of the time synchronization system in real time; wherein, the time synchronization system includes a main operating domain and a backup domain, the main operating domain includes a master clock, a main link, and a master redundant link, and the backup domain includes a hot standby master clock, a backup link, and an emergency link; the hot standby master clock is connected to the master clock through the emergency link; when the time synchronization system operates normally, the main operating domain transmits a synchronization message through the main link to output the time reference of the master clock. When the status flag indicates a failure of the primary link, the primary operating domain switches to transmitting the synchronization message via the primary redundant link to output the time base of the master clock. When the status flag indicates a failure of the master clock, the time synchronization system switches from the primary operating domain to the backup domain, and the backup domain transmits the synchronization message via the backup link to output the time base of the backup clock. The time base of the backup clock is the same as the time base of the primary clock. When the status flag indicates a failure of the primary clock and the backup link, the hot standby master clock sends a timestamp message to the master clock via the emergency link. The master clock transmits the synchronization message based on the timestamp message via the primary link to output the time base of the master clock. Due to the introduction of link redundancy, master clock redundancy, and emergency link redundancy, this method can quickly switch to the primary redundant link or the hot standby master clock when a failure occurs, ensuring the continued stability of the time base. In the extreme case of a failure of the primary clock and the backup link, the hot standby master clock can still maintain the transmission of synchronization messages via the emergency link to ensure the synchronization of the time base, thereby improving the stability and security of system time synchronization. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0038] Figure 1 A system architecture diagram of a time synchronization method provided in one embodiment of the present application;

[0039] Figure 2 A flowchart of a time synchronization method provided in one embodiment of the present application;

[0040] Figure 3 A schematic diagram of a main link failure provided in one embodiment of the present application;

[0041] Figure 4 A schematic diagram of a master clock failure provided in one embodiment of the present application;

[0042] Figure 5 A schematic diagram of a master clock failure and a backup link failure provided in one embodiment of the present application;

[0043] Figure 6 A flowchart of a time synchronization method provided in one embodiment of the present application;

[0044] Figure 7 A schematic diagram of the structure of a time synchronization device provided in one embodiment of the present application;

[0045] Figure 8 A schematic structural diagram of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0046] The following will describe the embodiments of the present application with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand the other advantages and effects of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be understood that the preferred embodiments are only for the purpose of illustrating the present application and are not intended to limit the scope of protection of the present application.

[0047] The first embodiment of the present application provides a time synchronization method, which can be applied to Figure 1The system architecture shown in FIG. 1 includes at least a master clock (ECU1) and a hot standby master clock (ECU4). ECU2 represents a slave node that receives synchronization messages from the master clock, and ECU3 represents a slave node that can receive synchronization messages via the hot standby master clock. Upon receiving synchronization messages via the hot standby master clock, ECU3 can forward the synchronization messages to ECU2 via a primary redundant link. Specifically, ECU1 is connected to ECU2 and ECU4 via a primary link, and ECU4 is also connected to ECU3 via a primary link. ECU3 is connected to ECU2 via a primary redundant link, and ECU4 is connected to ECU1 via an independent emergency link. Backup links are connected between ECU4 and ECU3, between ECU3 and ECU2, and between ECU2 and ECU1. The primary link, primary redundant link, and backup link can be Ethernet-based links that support time synchronization using the Generalized Precision Time Protocol (gPTP). The emergency link can be an independent non-Ethernet link that supports time synchronization using the gPTP protocol, such as a Controller Area Network (CAN) bus. ECU refers to an Electronic Control Unit (ECU). Specifically, the system architecture can be a vehicle, such as a fuel vehicle, a pure electric vehicle, a hybrid vehicle or a fuel cell vehicle that supports autonomous driving, etc., without limitation.

[0048] Next, based on the system architecture, the time synchronization method is described in detail. Figure 2 , the time synchronization method includes:

[0049] Step 201 monitors the status flag of the time synchronization system in real time; wherein, the time synchronization system includes a main operation domain and a backup domain, the main operation domain includes a master clock, a main link, and a main redundant link, and the backup domain includes a hot standby master clock, a backup link, and an emergency link; the hot standby master clock is connected to the master clock via the emergency link; when the time synchronization system operates normally, the main operation domain transmits synchronization messages via the main link to output the time reference of the master clock.

[0050] The status flags of each hardware register in the time synchronization system can be monitored in real time. A status flag of 0 indicates normal operation, while a status flag of 1 indicates a failure. For example, the status of the path connectivity of the primary link and primary redundant link in the primary operation domain (also referred to as domain 0), the path connectivity of the backup link in the backup domain (also referred to as domain 1), the phase-lock status of the master clock and the hot standby master clock, and the interface readiness status of the emergency link can be monitored. This allows real-time capture of component failure events and provides a basis for hierarchical response. When the time synchronization system is operating normally, that is, when the status flags of each of the aforementioned hardware registers are all 0, the primary operation domain transmits synchronization messages via the primary link to output the time reference of the master clock.

[0051] In one embodiment, before monitoring the status flag of the time synchronization system in real time, the method also includes: configuring the main operating domain and the backup domain; determining that the main operating domain and the backup domain are operating normally; and the main operating domain transmitting a synchronization message through the main link to output the time reference of the master clock.

[0052] In this embodiment, when configuring the time synchronization system, functional domain division can be first performed, and the time synchronization system can be divided into a main operation domain and a backup domain, wherein the main operation domain provides a global time reference through the master clock, and the backup domain provides redundancy for the main clock through the hot standby master clock. Specifically, the main operation domain is configured with a main link and a main redundant link that carry the gPTP protocol, and the backup domain uses an independent logical link. Of course, the backup domain can share a physical network with the main operation domain (only logically independent in use), or use a separate physical network (both logically and physically independent in use), without restriction. The master clock of the main operation domain is set as the reference source, and the hot standby master clock of the backup domain can synchronize the master clock in real time. When both the main operation domain and the backup domain are operating normally, the main operation domain outputs the synchronization message of the master clock through the main link to provide a time reference for each slave node connected to the master clock.

[0053] In one embodiment, the emergency link is a controller area network bus, and the hot standby master clock is connected to the master clock via the controller area network bus.

[0054] In this embodiment, the emergency link can be a CAN bus, and the hot standby master clock is connected to the master clock through a CAN bus direct connection channel, thereby providing a heterogeneous emergency channel independent of the Ethernet for the master clock. When the backup links of the master clock and the backup domain fail at the same time, the time synchronization of the master clock can be restored through the main link of the master clock based on the hot standby master clock.

[0055] Step 202: When the status flag indicates that the primary link is faulty, the primary operation domain switches to transmitting synchronization messages via the primary redundant link to output the time reference of the primary clock.

[0056] In this embodiment, the main link failure diagram is as follows: Figure 3 When the status flag indicates that the main link between the master clock and the slave node has failed, it indicates that the main link for directly transmitting the synchronization message from the master clock to the slave node ECU2 is unavailable. At this time, the main redundant link between ECU2 and ECU3 can be enabled, and the synchronization message can be transmitted through the main redundant link. Specifically, the synchronization message of the master clock can be transmitted to ECU2 in sequence through the hot standby master clock ECU4, the slave node ECU3, and the main redundant link, so as to realize the output of the time reference from the master clock to the slave node ECU2.

[0057] In one embodiment, the method further includes: at intervals of a first preset time duration, the backup clock performs clock calibration based on a synchronization message of the master clock.

[0058] In this embodiment, to ensure synchronization between the master and backup clocks, the backup clock is calibrated based on the master clock's synchronization message at intervals of a first preset duration, thereby maintaining constant synchronization between the master and backup clocks. The first preset duration is not limited; to maintain clock synchronization accuracy, a shorter duration can be selected, for example, clock calibration can be performed every time a synchronization message is received.

[0059] In one embodiment, after the main operation domain switches to transmitting synchronization messages through the main redundant link to output the time base of the main clock, the method also includes: when the status flag indicates that the main link has returned to normal, obtaining the duration of the normal state of the main link; if the duration of the normal state of the main link is greater than or equal to the second preset duration, the main operation domain switches to transmitting synchronization messages through the main link to output the time base of the main clock, and closes the main redundant link.

[0060] In this embodiment, after the primary link fails and the synchronization message transmission is switched to the primary redundant link, after the status flag indicates that the primary link has returned to normal, if the duration for which the primary link remains normal is greater than or equal to a second preset time period (e.g., 5 seconds), the primary operation domain is switched back to transmitting the synchronization message through the primary link, and the primary redundant link is closed, i.e., the blocked state of the primary redundant link is restored. The primary redundant link is then reactivated when the primary link fails again.

[0061] In step 203, when the status flag indicates that the master clock fails, the time synchronization system switches from the primary operation domain to the backup domain, and the backup domain transmits synchronization messages through the backup link to output the time base of the backup clock; wherein the time base of the backup clock is the same as the time base of the master clock.

[0062] In this embodiment, the main clock failure diagram is as follows: Figure 4 When the status flag indicates a master clock failure, it indicates that the master clock ECU1 cannot send a synchronization message to the slave node ECU2. At this time, the hot standby master clock ECU4 can be enabled, and ECU4 transmits a synchronization message to ECU2 through ECU3 via the backup link. Since the time base of the backup clock is consistent with the time base of the master clock, the time base of the backup clock output to ECU2 is the same as the time base output by the master clock to ECU2 before the master clock fails, thereby ensuring the synchronization of the time base and improving the stability of the system time synchronization.

[0063] In one embodiment, after the backup domain transmits a synchronization message through a backup link to output the time base of the backup clock, the method further includes: when the status flag indicates that the main clock has returned to normal, obtaining the duration of the normal state of the main clock; if the duration of the normal state of the main clock is greater than or equal to a third preset duration, the time synchronization system switches from the backup domain to the main operation domain, the main operation domain transmits a synchronization message through the main link to output the time base of the main clock, and stops the backup domain from transmitting the synchronization message through the backup link.

[0064] In this embodiment, after the master clock fails and switches to the backup domain to transmit synchronization messages through the backup link, after the status flag indicates that the master clock has returned to normal, if the master clock remains in a normal state for a duration greater than or equal to a third preset time length (for example, 5 seconds), the time synchronization system switches from the backup domain back to the main operation domain, and the main operation domain transmits synchronization messages through the main link again, and stops the backup domain from transmitting synchronization messages through the backup link. When the master clock fails again, the backup domain and backup link are restarted to transmit synchronization messages.

[0065] In step 204, when the status flag indicates that the master clock is faulty and the backup link is faulty, the hot standby master clock sends a timestamp message to the master clock via the emergency link; the master clock transmits a synchronization message based on the timestamp message via the main link to output the time reference of the master clock.

[0066] In this embodiment, the main clock fails and the backup link fails as shown in the following diagram: Figure 5 In the case of a dual fault, where the status flag indicates a master clock failure and a backup link failure, the hot standby master clock sends a timestamp message to the master clock via the emergency link. Although the master clock fails and cannot transmit synchronization messages, it can still parse the timestamp message and transmit the synchronization message via the main link based on the timestamp message. It should be noted that the hot standby master clock needs to continuously send timestamp messages to the master clock via the emergency link to maintain the master clock's ability to transmit synchronization messages via the main link and output the master clock's time base. Since the emergency link is a CAN bus independent of Ethernet, the emergency link can be guaranteed to be normal in the case of a dual fault of the master clock and the backup link. The hot standby master clock can then send timestamp messages to the master clock via the emergency link to maintain the master clock's ability to transmit synchronization messages via the main link, thereby ensuring the stability of system time synchronization.

[0067] It should be noted that the order of the above steps 202, 203 and 204 is not limited, that is, step 203 can be executed first, and then step 204 or step 202, or step 204 can be executed first, and then step 202 or step 203. That is, the execution order is determined according to the actual fault that occurs. If only one fault occurs, only one of steps 202, 203 and 204 can be executed without limitation.

[0068] In this embodiment and the above embodiments, due to the introduction of link redundancy, master clock redundancy and emergency link redundancy, when a failure occurs, it is possible to quickly switch to the main redundant link or the hot standby master clock to ensure the continuous stability of the time base, and in the extreme case of a master clock failure and a backup link failure, the hot standby master clock can still maintain the transmission of synchronization messages through the emergency link to ensure the synchronization of the time base, thereby improving the stability and security of system time synchronization.

[0069] In one embodiment, after the master clock transmits a synchronization message based on the timestamp message through the main link to output the time base of the master clock, the method also includes: when the status flag indicates that the master clock has returned to normal, the master clock calibrates the local clock based on the timestamp message; after the master clock calibration is completed, the synchronization message is transmitted through the main link to output the time base of the master clock, and the hot standby master clock is stopped from sending timestamp messages to the master clock through the emergency link.

[0070] In this embodiment, after a double fault occurs, if the status flag indicates that the master clock has returned to normal, the local clock can be calibrated based on the timestamp message sent by the hot standby master clock. This is called calibrating the master clock. After the master clock calibration is complete, synchronization message transmission via the primary link through the master clock of the primary operational domain is resumed, and the hot standby master clock stops sending timestamp messages to the master clock via the emergency link. Of course, during this process, the backup link in the backup domain should also be repaired as much as possible to improve the redundancy of the time synchronization system.

[0071] In a specific embodiment, the time synchronization method is as follows: Figure 6 ,include:

[0072] Step 601, initialize the main running domain (domain 0) and the backup domain (domain 1);

[0073] Step 602: Domain 0 and Domain 1 configure the master clock, primary link, redundant link, hot standby master clock, backup link, and emergency link.

[0074] Step 603: Monitor the system health status through the hardware register status code; and execute steps 604, 614, and 624 to determine the fault status;

[0075] Step 604, main link fault determination; if it is determined that the main link is faulty, step 605 is executed; if the main link is not faulty, the main link is continuously determined to be faulty;

[0076] Step 605: Switch to the primary redundant link of domain 0; after the switch is completed, execute step 606;

[0077] Step 606: Determine if the main link fault has been restored. If so, proceed to step 607. If not, continue to determine if the main link fault has been restored.

[0078] Step 607: Switch back to the primary link, and the primary redundant link returns to the blocked state;

[0079] Step 614, master clock fault determination; if it is determined that the master clock is faulty, step 615 is executed; if the master clock is not faulty, the determination of whether the master clock is faulty is continued;

[0080] Step 615: Switch to the hot standby master clock of domain 1 and perform time synchronization through the backup link of domain 1. After the switch is completed, execute step 616.

[0081] Step 616, determining whether the master clock fault has been restored; if restored, executing step 617; if not, continuing to determine whether the master clock fault has been restored;

[0082] Step 617: Switch back to the master clock, and the hot standby master clock stops sending time synchronization messages;

[0083] Step 624, dual fault determination; that is, determining whether both the master clock failure and the backup link failure occur simultaneously. If so, executing step 625; if not, continuing the dual fault determination;

[0084] Step 625, the hot standby master clock synchronizes the master clock via the CAN signal;

[0085] Step 626, double fault recovery determination; if recovered, proceed to step 627, if not, continue to determine whether the double fault is recovered;

[0086] Step 627: The hot standby master clock stops sending CAN signals, and the domain 0 main link resumes time synchronization.

[0087] In this embodiment, the master clock of domain 0 is set as the reference source, the hot standby clock of domain 1 synchronizes the clock of domain 0 in real time, and a CAN signal is added to the hot standby master clock of domain 1, which is physically directly connected to the master clock of domain 0. The emergency link directly connected to CAN can avoid the dependence on the Ethernet protocol stack and prevent the risk of time base interruption caused by dual single point failures of the master clock and the backup link. Domain 0, as the main operating domain, is responsible for the time base synchronization task of the intelligent driving system, and domain 1, as the backup domain, is only enabled when the master clock of domain 0 fails. In the time synchronization method of this embodiment, redundant switching of the time synchronization link and the master clock can be realized, and the time base can be maintained through the CAN direct emergency link when both the master clock and the backup link fail, thereby significantly improving the fault tolerance and stability of the system.

[0088] Based on the same technical concept, the second embodiment of the present application provides a time synchronization device, such as Figure 7 , the device comprises:

[0089] Monitoring module 701 is configured to monitor the status flag of a time synchronization system in real time. The time synchronization system includes a primary operation domain and a backup domain. The primary operation domain includes a master clock, a primary link, and a primary redundant link. The backup domain includes a hot standby master clock, a backup link, and an emergency link. The hot standby master clock is connected to the master clock via the emergency link. When the time synchronization system operates normally, the primary operation domain transmits synchronization messages via the primary link to output the time reference of the master clock.

[0090] A first switching module 702 is configured to, when the status flag indicates that the primary link has failed, switch the primary operation domain to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock;

[0091] A second switching module 703 is configured to, when the status flag indicates that the master clock has failed, switch the time synchronization system from the primary operation domain to the backup domain, and the backup domain transmits the synchronization message through the backup link to output the time reference of the backup clock; wherein the time reference of the backup clock is the same as the time reference of the master clock;

[0092] The third switching module 704 is used to, when the status flag indicates that the master clock fails and the backup link fails, the hot standby master clock sends a timestamp message to the master clock through the emergency link; the master clock transmits the synchronization message through the main link based on the timestamp message to output the time reference of the master clock.

[0093] Since the device introduces link redundancy, master clock redundancy and emergency link redundancy, it can quickly switch to the main redundant link or hot standby master clock when a fault occurs, ensuring the continuous stability of the time base. In addition, in the extreme case of a master clock failure and a backup link failure, the hot standby master clock can still maintain the transmission of synchronization messages through the emergency link, ensuring the synchronization of the time base, thereby improving the stability and security of system time synchronization.

[0094] like Figure 8 As shown, the third embodiment of the present application provides an electronic device, including a processor 111, a communication interface 112, a memory 113 and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114.

[0095] Memory 113, for storing computer programs;

[0096] In one embodiment, the processor 111 is configured to implement the time synchronization method provided by any one of the aforementioned method embodiments when executing a program stored in the memory 113 .

[0097] The memory and processor in the electronic device communicate via a communication bus and a communication interface. The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The communication bus can be divided into an address bus, a data bus, a control bus, and the like.

[0098] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0099] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0100] A fourth embodiment of the present application provides a computer-readable medium having non-volatile program code executable by a processor.

[0101] Optionally, in an embodiment of the present application, a computer-readable medium is configured to store program code for a processor to execute the above method.

[0102] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and this embodiment will not be described in detail here.

[0103] When implementing the embodiments of the present application, reference may be made to the above embodiments, which have corresponding technical effects.

[0104] It is understood that the embodiments described herein may be implemented using hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit may be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application, or a combination thereof.

[0105] For software implementation, the technology herein can be implemented by a unit that performs the functions herein. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or external to the processor.

[0106] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0107] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0108] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0109] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0110] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0111] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

[0112] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device that includes the element.

[0113] The above embodiments are only preferred embodiments for fully illustrating the present application, and the protection scope of the present application is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art based on the present application are within the protection scope of the present application.

Claims

1. A time synchronization method, characterized in that: The method comprises: Real-time monitoring of the status flag of the time synchronization system; wherein the time synchronization system includes a primary operation domain and a backup domain, the primary operation domain includes a master clock, a primary link, and a primary redundant link, and the backup domain includes a hot standby master clock, a backup link, and an emergency link; the hot standby master clock is connected to the master clock via the emergency link; when the time synchronization system operates normally, the primary operation domain transmits synchronization messages via the primary link to output the time reference of the master clock; When the status flag indicates that the primary link fails, the primary operation domain switches to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock; When the status flag indicates that the master clock fails, the time synchronization system switches from the primary operation domain to the backup domain, and the backup domain transmits the synchronization message through the backup link to output the time reference of the backup clock; wherein the time reference of the backup clock is the same as the time reference of the master clock; When the status flag indicates that the master clock fails and the backup link fails, the hot standby master clock sends a timestamp message to the master clock through the emergency link; the master clock transmits the synchronization message through the main link based on the timestamp message to output the time reference of the master clock.

2. The method according to claim 1, characterized in that Before monitoring the status flag of the time synchronization system in real time, the method further includes: Configuring the primary operation domain and the backup domain; Determining that the primary operation domain and the backup domain are operating normally; The master operation domain transmits synchronization messages via the master link to output the time reference of the master clock.

3. The method according to claim 1, characterized in that The emergency link is a controller area network bus, and the hot standby master clock is connected to the master clock via the controller area network bus.

4. The method according to claim 1, wherein The method further comprises: The backup clock performs clock calibration based on the synchronization message of the master clock at intervals of a first preset time length.

5. The method according to claim 1, wherein After the primary operation domain switches to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock, the method further includes: When the status flag indicates that the primary link has returned to normal, obtaining a duration of the normal state of the primary link; If the normal state of the primary link lasts longer than or equal to a second preset time period, the primary operation domain switches to transmitting the synchronization message through the primary link to output the time reference of the master clock and closes the primary redundant link.

6. The method according to claim 1, characterized in that After the backup domain transmits the synchronization message through the backup link to output the time reference of the backup clock, the method further includes: When the status flag indicates that the master clock has returned to normal, obtaining a duration of the normal state of the master clock; If the normal state of the master clock lasts for a period greater than or equal to a third preset period, the time synchronization system switches from the backup domain to the main operation domain, and the main operation domain transmits the synchronization message through the main link to output the time base of the master clock, and stops the backup domain from transmitting the synchronization message through the backup link.

7. The method according to claim 1, characterized in that After the master clock transmits the synchronization message based on the timestamp message through the primary link to output a time reference of the master clock, the method further includes: When the status flag indicates that the master clock has returned to normal, the master clock calibrates the local clock based on the timestamp message; After the master clock calibration is completed, the synchronization message is transmitted through the main link to output the time reference of the master clock, and the hot standby master clock is stopped from sending the timestamp message to the master clock through the emergency link.

8. A time synchronization device, characterized in that: The device comprises: A monitoring module for monitoring the status flag of a time synchronization system in real time; wherein the time synchronization system includes a primary operation domain and a backup domain, the primary operation domain including a master clock, a primary link, and a primary redundant link, and the backup domain including a hot standby master clock, a backup link, and an emergency link; the hot standby master clock is connected to the master clock via the emergency link; when the time synchronization system operates normally, the primary operation domain transmits synchronization messages via the primary link to output the time reference of the master clock; A first switching module is configured to, when the status flag indicates that the primary link has failed, cause the primary operation domain to switch to transmitting the synchronization message through the primary redundant link to output the time reference of the master clock; a second switching module, configured to, when the status flag indicates that the master clock has failed, switch the time synchronization system from the primary operation domain to the backup domain, and the backup domain transmit the synchronization message through the backup link to output the time reference of the backup clock; wherein the time reference of the backup clock is the same as the time reference of the master clock; The third switching module is used to, when the status flag indicates that the master clock fails and the backup link fails, the hot standby master clock sends a timestamp message to the master clock through the emergency link; the master clock transmits the synchronization message through the main link based on the timestamp message to output the time reference of the master clock.

9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor, configured to implement the method according to any one of claims 1 to 7 when executing a program stored in a memory.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.