Rapid clock synchronization system and method based on virtualization technology

By using the secure clock virtual machine (STVM) and TSN switch on the virtualization platform, fast and accurate clock synchronization is achieved, solving the problems of clock drift and insufficient synchronization accuracy of traditional clock synchronization protocols on the virtualization platform, simplifying the synchronization process and improving the reliability and accuracy of synchronization.

CN120602033APending Publication Date: 2025-09-05CASCO SIGNAL LTD

Patent Information

Application Number
CN202510749233.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Traditional clock synchronization protocols have problems with clock drift and insufficient synchronization accuracy on virtualized platforms, which cannot meet the high-precision clock synchronization requirements of security systems. Existing methods also require separate calculation of network transmission delays.

Method used

The secure clock virtual machine (STVM) is used as the only clock synchronization source. Fixed-period clock synchronization messages are transmitted to virtual machines through the multicast network and TSN switches. Independent clock synchronization sending and receiving tasks are created. The working virtual machine directly obtains the clock synchronization message and determines the task cycle time point based on the count value, simplifying the synchronization process.

Benefits of technology

It achieves fast and accurate clock synchronization, avoids the problems of clock drift and insufficient synchronization accuracy, simplifies the clock synchronization process, and improves the reliability and accuracy of synchronization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602033A_ABST
    Figure CN120602033A_ABST
Patent Text Reader

Abstract

The invention relates to a rapid clock synchronization system and method based on a virtualization technology. The system comprises a secure clock virtual machine STVM, a working virtual machine VM, a clock card and a TSN switch. The STVM is directly connected with a clock card through a virtualization technology to generate a unique clock; the TSN switch establishes a multicast communication network of a secure clock virtual machine STVM and each working virtual machine VM, and is used for transmitting a clock synchronization message of a set period; the STVM sends a clock synchronization message with a corresponding cycle length to each multicast network; and the working virtual machine VM creates a periodic clock synchronization receiving task and receives a clock synchronization signal with a period length. Compared with the prior art, the clock synchronization method has the advantages that the clock synchronization process is simplified, fast and periodic clock synchronization is realized, and meanwhile, the clock synchronization precision is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to clock synchronization technology, and in particular to a fast clock synchronization system and method based on virtualization technology. Background Art

[0002] With the widespread application of cloud computing, traditional embedded security applications have been migrated to virtualization-based cloud servers, making security application deployment and maintenance more flexible. At the same time, virtualization-based cloud servers can deploy more applications, which can better reduce hardware costs compared to embedded boards.

[0003] Clock synchronization is a key technology for deploying and running security applications on cloud servers. The business communications of virtual machines (VMs) running security services require high-precision clock synchronization. The traditional clock synchronization protocol, NTP, has relatively long time synchronization intervals and insufficient clock synchronization accuracy. PTP provides shorter time synchronization, but due to the stability of the local clock, clock synchronization has low synchronization accuracy or delay jitter problems, which cannot meet the clock synchronization requirements of the security system.

[0004] Traditional clock synchronization methods rely on a single channel sending clock synchronization messages to other channels. The receiving channel must consider network transmission latency. Eliminating virtual machine clock stability issues and achieving fast and high-precision clock synchronization is particularly important for secure applications running on virtualized platforms.

[0005] After searching, Chinese patent publication number CN113691342A discloses a method and system for time synchronization of a virtualization platform, which specifically discloses creating a first virtual machine in the virtualization platform, and obtaining an external PTP clock based on the first virtual machine as the system clock of the first virtual machine; configuring the first virtual machine as the NTP server of the virtualization platform, and configuring the virtual machines in the virtualization platform that need time synchronization as NTP clients; based on the time synchronization services configured in the first virtual machine and the virtual machines that need time synchronization, time synchronization of each virtual machine in the virtualization platform is achieved, wherein each virtual machine in the virtualization platform is interconnected based on the configured virtual network card. However, the clock synchronization method of the existing patent uses traditional clock synchronization protocols such as NTP and PTP. These clock synchronization protocols have problems with clock drift or insufficient synchronization accuracy. The clock synchronization implemented by the existing patent adopts a method of sending periodic clock synchronization from one channel to another channel, which requires separate calculation of transmission delay and uses the local clock of the virtual machine. There are problems such as low synchronization accuracy due to the local virtual machine clock drift. Summary of the Invention

[0006] The purpose of the present invention is to provide a fast clock synchronization system and method based on virtualization technology in order to overcome the defects of the above-mentioned prior art.

[0007] The purpose of the present invention can be achieved by the following technical solutions:

[0008] According to a first aspect of the present invention, a fast clock synchronization system based on virtualization technology is provided, the system comprising a secure time virtual machine (STVM), a working virtual machine (VM), a clock card, and a TSN switch;

[0009] The secure clock virtual machine (STVM) generates a unique clock by directly passing through the clock card through virtualization technology;

[0010] The TSN switch establishes a multicast communication network between the secure clock virtual machine STVM and each working virtual machine VM for transmitting clock synchronization messages of a set period;

[0011] The secure clock virtual machine STVM sends a clock synchronization message of corresponding cycle length to each multicast network;

[0012] The working virtual machine VM creates a periodic clock synchronization receiving task to receive a clock synchronization signal with a period length.

[0013] As a preferred technical solution, the secure clock virtual machine STVM and the working virtual machine VM are created on a virtualization platform of a server, and each server has a unique secure clock virtual machine STVM.

[0014] As a preferred technical solution, the TSN switch controls the transmission time of data packets through traffic scheduling and priority management.

[0015] As a preferred technical solution, the clock card includes a safety clock for safety task scheduling and a calibration clock for verifying the accuracy of the safety clock and verifying the length of periodic tasks.

[0016] As a preferred technical solution, the clock card sends a safety clock interrupt signal every T time based on the safety clock, and calculates a count value of the time length between each safety clock interrupt signal based on the check clock.

[0017] As an optimal technical solution, after the secure clock virtual machine STVM receives the secure clock interrupt signal from the clock card, it forwards the secure clock interrupt signal to each working virtual machine VM through the virtualization layer, reads the verification count value, adjusts the secure clock count value as needed, accumulates the received secure clock interrupt count value, and finally completes the clear interrupt operation.

[0018] As an optimal technical solution, after the working virtual machine VM receives the secure clock interrupt signal, it reads and verifies the count value, adjusts the secure clock count value and updates the secure clock interrupt count value as needed, and implements task scheduling according to the secure clock interrupt signal.

[0019] As a preferred technical solution, the working virtual machine VM verifies the safety clock and the task cycle length according to the verification clock count value, and if the verification fails, it is directed to the safe state.

[0020] According to a second aspect of the present invention, a synchronization method for the virtualization-based fast clock synchronization system is provided, the synchronization method comprising:

[0021] Step S1, the secure clock virtual machine STVM configures the clock synchronization cycle length based on the secure clock interrupt count value, and selects to create one or more periodic clock synchronization tasks according to the different system cycle lengths; and sets multiple multicast addresses in the communication network, each multicast transmission setting a clock synchronization message of the cycle length;

[0022] Step S2, the secure clock virtual machine STVM sends a clock synchronization message of corresponding cycle length to each multicast network;

[0023] Step S3: the working virtual machine VM creates a periodic clock synchronization receiving task to receive a clock synchronization signal with a period length field;

[0024] Step S4, when the working virtual machine VM receives the clock synchronization message, it verifies the consistency between the cycle length in the clock synchronization message and the cycle length of its own task. If the verification is consistent, the initialization phase task enters the main cycle at the next safe clock after the clock synchronization message is received; the main cycle task determines the start time point of the task cycle based on the time when the clock synchronization message is received and the safe clock count value; if the verification is inconsistent, the clock synchronization message is discarded.

[0025] As a preferred technical solution, the secure clock virtual machine STVM sends a clock synchronization message containing a masked cycle length field, and the working virtual machine VM performs unmasking processing on the cycle length field after receiving the clock synchronization message.

[0026] As a preferred technical solution, the starting time point of the task cycle in step S4 is specifically determined as follows:

[0027] For a task cycle of 500ms, when the next clock synchronization message is received and the safe clock count value of this cycle is 250, it means that the clock synchronization of 500ms is accurate, and the task cycle of the virtual machine VM itself starts at the next safe clock.

[0028] As a preferred technical solution, the method sets delay forgiveness conditions as needed, specifically including:

[0029] 1) When the safety clock count value of this cycle reaches 250 and no clock synchronization message has been received, the next safety clock interrupt will directly start a new cycle and the safety clock count value will be recounted;

[0030] 2) When the current cycle's secure clock count is less than or equal to 2, a new clock message is received, indicating that the local secure clock count is faster than the cycle synchronization clock, and a new cycle begins early. The channel should recount the secure clock count and set the clock synchronization state to synchronized. If the count is greater than 2 and a new clock message is received, it is considered that the message delay is large, and the clock synchronization state is set to asynchronous. The main cycle continues to run. If the synchronization state is asynchronous for three consecutive times, it returns to the secure state.

[0031] 3) When the safety clock count value of this cycle is greater than or equal to 248, a new clock message is received, which means that the local safety clock count value is slower than the periodic synchronization clock. When the clock message is received, a new cycle should be started with the next safety clock, the safety clock count value is recounted, and the clock synchronization state is set to synchronized. When the count value of this cycle is less than 248, a new clock message is received, and the clock synchronization state is set to asynchronous. The main cycle continues to run. If the synchronization state is asynchronous for three consecutive times, it will be directed to the safe state.

[0032] As a preferred technical solution, the method starts each cycle by exchanging a secure clock count value between the VMs communicating with each other.

[0033] Since the set cycle synchronization tolerance is 2 count values, its own count value is sent at the third count value at the beginning of the cycle. The count value difference is received and checked to see if it is within the tolerance range. If it is within the tolerance range, the backup system adjusts its own safety clock count value according to the master system's count value; if it is not within the tolerance range, the clock synchronization state is set to asynchronous. If the synchronization state is asynchronous for three consecutive times, it will be directed to the safe state. If the safe clock count message is not read, the clock synchronization state is set to asynchronous.

[0034] Compared with the prior art, the present invention has the following advantages:

[0035] 1) This invention replaces the existing method of sending clock synchronization messages from one channel to other channels. Instead, it uses a separate STVM to send clock messages to VMs that need clock synchronization at a fixed period. For all receiving VMs, the synchronous data transmission link is the same, and network transmission delay is no longer calculated separately.

[0036] 2) The present invention replaces the traditional clock synchronization method and does not rely on the local clock of the virtual machine, avoiding the problems of clock drift and insufficient synchronization accuracy in traditional clock synchronization. The present invention creates independent clock synchronization sending and receiving tasks, and the working VM directly obtains the clock synchronization message. The task cycle time point is determined based on the received clock synchronization message and the security clock count value, which simplifies the clock synchronization process, realizes fast-cycle clock synchronization, and improves the accuracy of clock synchronization. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 Schematic diagram of a virtualization-based secure clock synchronization system according to the present invention;

[0038] Figure 2 This is a schematic diagram of a periodic clock synchronization network of the present invention;

[0039] Figure 3 This is a schematic diagram of multicasting clock synchronization messages according to cycle lengths according to the present invention;

[0040] Figure 4 This is a schematic diagram of the clock synchronization process framework for sequentially starting multiple virtual machines according to the present invention;

[0041] Figure 5 Schematic diagram of the clock synchronization process framework of the main cycle of multiple virtual machines of the present invention;

[0042] Figure 6 This is a complete clock synchronization logic diagram of the present invention. DETAILED DESCRIPTION

[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0044] Example 1

[0045] The present invention proposes a fast clock synchronization system based on virtualization technology, which uses a secure clock virtual machine as the only clock synchronization source and provides clock synchronization services of different periods to each virtual machine through a multicast network and a TSN switch. The present invention realizes the transmission of clock synchronization messages by creating independent clock synchronization sending and receiving tasks, replacing the traditional clock synchronization method. It does not rely on the local clock of the virtual machine and avoids the problems of clock drift and insufficient synchronization accuracy in traditional clock synchronization. The working virtual machine directly obtains the clock synchronization message and determines the task cycle time point based on the received clock synchronization message and the secure clock count value. There is no need to calculate the transmission delay separately, which simplifies the clock synchronization process, realizes fast cycle clock synchronization, and improves the accuracy of clock synchronization.

[0046] like Figure 1 As shown, the fast clock synchronization system of the present invention includes a secure clock virtual machine STVM, a working virtual machine VM, a clock card and a TSN switch.

[0047] Create a working virtual machine (VM) and a secure clock virtual machine (STVM) on the server's virtualization platform;

[0048] Configure TSN switches and establish a multicast communication network for STVMs and VMs. Each multicast network transmits clock synchronization messages of a specific period.

[0049] STVM uses virtualization technology to directly pass through the clock card to generate a unique clock.

[0050] Set the cycle length of STVM clock synchronization, establish the communication task of periodic clock synchronization, and provide periodic clock synchronization messages to all working VMs through the TSN switch.

[0051] STVM implements interrupt notification and sends a secure clock signal to all working VMs on the same server.

[0052] The working VM verifies the accuracy of the secure clock and implements task scheduling based on interrupt notifications.

[0053] The working VM determines the safety task periodic synchronization time point based on the received periodic clock synchronization message and the safety clock count value.

[0054] Work VM cycle synchronization reliability check.

[0055] The working VM runs a secure business system, relies on a secure clock for task scheduling, and enjoys exclusive memory, CPU, network and other resources.

[0056] The STVM obtains the clock source and provides a secure clock for each working VM in the server. Each server has a unique STVM. In the entire clock synchronization system, one STVM is selected as the periodic clock synchronization source for the entire system.

[0057] The TSN switch features deterministic transmission, ensuring that critical data streams reach their destination devices at the scheduled time. Through traffic scheduling and priority management, the TSN switch controls the transmission time of data packets, ensuring that mission-critical data is not delayed or lost.

[0058] The periodic clock synchronization signal is transmitted through the TSN switch to ensure the stability and reliability of periodic clock synchronization.

[0059] The safety clock card provides a safety clock and a check clock. The safety clock is used for safety task scheduling, and the check clock is used to verify the accuracy of the safety clock and the length of periodic tasks.

[0060] Based on existing secure clock solutions, this paper designs a method for implementing fast clock synchronization. The secure clock system includes components such as a hardware server, a clock card, virtualization software, a virtual machine, and a switch. Using bare-metal virtualization technology, physical resources such as the CPU, memory, and network interface card are virtualized, and the client's operating system runs on the virtualized platform. Multiple virtual machines are deployed on the server, one of which is virtualized as the secure clock virtual machine (STVM), and the others as working virtual machines (VMs).

[0061] Secure clock solution:

[0062] A secure clock card, built with dual clock sources, provides a reliable secure clock for each working VM. The dual clock sources can use an XHz crystal oscillator and an XKHz crystal oscillator. One XHz clock source provides the secure clock, while the other XKHz clock source serves as the check clock. The clock card is directly connected to the secure clock virtual machine (STVM). Based on the secure clock, the clock card sends a secure clock interrupt signal every T time. The check clock calculates the time between each secure clock interrupt signal.

[0063] The secure clock virtual machine (STVM) provides a precise secure clock for all working VMs in the server. After receiving a secure clock interrupt signal from the clock card, the STVM forwards the secure clock interrupt signal to each working VM through the virtualization platform. It then reads the verification count, adjusts the secure clock count as needed, accumulates the received secure clock interrupt count, and finally clears the interrupt. After receiving the secure clock interrupt signal, the VM reads and verifies the count, adjusts the secure clock count as needed, updates the secure clock interrupt count, and schedules tasks based on the secure clock interrupt signal. The VM verifies the secure clock and task cycle length based on the verification count. If the verification fails, the VM enters a secure state.

[0064] The improvements of the present invention include:

[0065] 1. Traditional clock synchronization methods use a single channel to send clock synchronization messages to other channels, and the receiving channel needs to consider network transmission delays. This solution implements a synchronization method that uses a separate STVM to send clock messages to the VMs that need clock synchronization at a fixed period. For all receiving VMs, the synchronous data transmission link is the same, and network transmission delays are no longer calculated separately.

[0066] 2. Traditionally, local clocks are synchronized through clock synchronization messages, and then the local clock is retrieved when synchronization is required. This reliance on the local clock during periodic synchronization can lead to drift in the virtual machine's local clock. Traditional clock synchronization protocols, such as PTP, also suffer from clock drift and insufficient synchronization accuracy. This solution creates independent clock synchronization sending and receiving tasks, establishes a unique clock synchronization sender, and the receiver determines the cycle start time based on the clock synchronization message and the security clock count. This solution does not rely on the local clock, enabling faster clock synchronization within the task cycle and improving clock synchronization accuracy.

[0067] Example 2

[0068] The present invention further provides a synchronization method for the fast clock synchronization system based on virtualization technology described in Example 1, the synchronization method comprising:

[0069] The STVM configures the clock synchronization cycle length based on the secure clock interrupt count. Depending on the system cycle length, it creates one or more periodic clock synchronization tasks. Multiple multicast addresses are set up in the communication network, each of which transmits clock synchronization messages of a specific cycle length. The STVM sends clock synchronization messages of the corresponding cycle length to each multicast network. The sent clock synchronization messages contain the cycle length field using a mask.

[0070] The working VM creates a periodic clock synchronization receiving task to receive clock synchronization signals with a period length field. Upon receiving a clock synchronization message, the period length field is unmasked and the consistency of the period length in the message is verified against the period length of the task itself. If the verification is consistent, the initialization phase task enters the main period at the next secure clock after the clock synchronization message is received. The main periodic task then determines the start time of the task period based on the time the clock synchronization message was received and the secure clock count value. If the verification is inconsistent, the clock message is discarded.

[0071] Determining the task cycle start time: The working VM's own secure clock count value is used to verify the accuracy of cycle synchronization. The secure clock count value verifies the periodic clock synchronization message interval. If the periodic clock synchronization interval is 500ms and the secure clock interval T is 2ms, 250 secure clock count values ​​should be added within the 500ms periodic synchronization interval. The secure clock count value is reset at the start of each cycle. Since a new cycle begins with the next secure clock after receiving a clock synchronization message, if the secure clock count value for the current cycle is 250 when the next clock synchronization message is received, the 500ms clock synchronization is accurate, and the VM's own task cycle begins at the next secure clock.

[0072] Taking into account the possible delay of clock synchronization messages, delay tolerance conditions are set as needed. This article sets the clock synchronization tolerance of two secure clocks.

[0073] 1) When the safety clock count value of this cycle reaches 250 and no clock synchronization message is received, the next safety clock interrupt directly starts a new cycle and the safety clock count value should be recounted.

[0074] 2) If the current cycle's secure clock count is less than or equal to 2 and a new clock message is received, this means the local secure clock count is faster than the cycle synchronization clock, leading to an early start of the new cycle. The channel should recount the secure clock count and set the clock synchronization status to synchronized. If the count is greater than 2 and a new clock message is received, the message delay is considered significant and the clock synchronization status is set to out of sync, continuing the main cycle. If the synchronization status is out of sync for three consecutive times, the channel enters the secure state.

[0075] 3) If the current cycle's safe clock count is greater than or equal to 248 and a new clock message is received, this means the local safe clock count is slower than the cycle's synchronization clock. Upon receiving the clock message, a new cycle should begin with the next safe clock, recounting the safe clock count and setting the clock synchronization status to synchronized. If the current cycle's count is less than 248 and a new clock message is received, the clock synchronization status is set to out of sync, and the main cycle continues. If the synchronization status is out of sync for three consecutive times, the system returns to the safe state.

[0076] Periodic clock synchronization check:

[0077] At the start of each cycle, communicating VMs exchange a secure clock count value for the start of each cycle. Since the cycle synchronization tolerance is set to two counts, the backup system sends its own count value at the third count from the start of the cycle. The backup system then checks whether the difference between the counts is within the tolerance range. If it is within the tolerance range, the backup system adjusts its secure clock count value based on the master system's count value. If it is not within the tolerance range, the clock synchronization state is set to out of sync. If the synchronization state is out of sync for three consecutive times, the system enters the secure state. If no secure clock count message is received, the clock synchronization state is set to out of sync.

[0078] Example 3

[0079] (1) Figure 1 As shown, bare-metal virtualization technology is used to virtualize physical resources such as CPU, memory, and network cards, and the client's operating system runs on the virtualization platform. Multiple virtual machines are deployed on the server, one of which is used as the secure clock virtual machine (STVM). The clock signal from the clock card is provided to the secure clock virtual machine through pass-through technology. The other virtual machines are used as ordinary client virtual machines (VMs).

[0080] The secure clock virtual machine (STVM) provides accurate secure clocks for all VMs in the server. After receiving the secure clock interrupt signal from the clock card, the STVM reads the checksum count value through the interface provided by the clock card and forwards the secure clock interrupt signal to each VM through the virtualization platform.

[0081] (2) Figure 2 Figure 2 shows a network connection diagram for periodic clock synchronization. Since all VMs in a specific period need to be synchronized, an STVM is selected as the only clock synchronization source. The clock synchronization signal is sent to the working VM that needs clock synchronization through the TSN switch. Other STVMs are not used as clock synchronization sources.

[0082] (3) Figure 3 As shown in the figure, the task cycle lengths of the working VM are divided into 500ms and 300ms. Two multicast networks are set up. The clock synchronization source STVM sends a clock synchronization message every 500ms, which is sent to the working VM with a 500ms cycle through multicast address 1; the clock synchronization source STVM sends a clock synchronization message every 300ms, which is sent to the working VM with a 300ms cycle through multicast address 1.

[0083] (4) Figure 4As shown in the figure, in a clock synchronization scenario where multiple virtual machines are started sequentially, after the last system completes its initialization and meets the conditions for entering the main cycle, it can enter the main cycle at the next safe clock after receiving the clock synchronization message. After entering the main cycle, the interactive cycle begins counting values ​​and verifies the difference with the count value of the first system.

[0084] (5) Figure 5 The following figure illustrates clock synchronization scenarios after multiple virtual machines enter the main cycle. After receiving the clock synchronization message, the system enters the main cycle at the next safe clock. After entering the main cycle, the interactive cycle begins counting values, verifying the difference in count values ​​between multiple systems.

[0085] (6) Figure 6 As shown, after receiving a secure clock interrupt, the STVM verifies the secure clock accuracy by reading the checksum. It then sends a secure clock interrupt to all VMs on the server through the virtualization platform, accumulating the secure clock interrupt count. The STVM then creates a periodic synchronization task, sets the periodic clock synchronization length based on the count, and multicasts a clock synchronization message. When a working VM enters a new cycle, it resets the secure clock count on the first secure clock. When a working VM receives a secure clock interrupt, it verifies the secure clock accuracy by reading the checksum count. If verification passes, it schedules tasks based on the secure clock interrupt and accumulates the secure count. If verification fails, it enters the secure state. Upon receiving a clock synchronization message, the working VM unmasks the period length field in the clock synchronization message to determine whether it matches its own period length. If verification fails, the message is discarded. If verification fails, the new cycle start time is determined based on the clock synchronization message and the secure clock.

[0086] 1) If the working VM determines that its initialization is complete and is waiting to enter the main cycle, it will enter the main cycle when the next safety clock arrives.

[0087] 2) If the working VM determines that it is in the main cycle, it further determines whether the time point of receiving the clock synchronization message is the last safe clock of the main cycle:

[0088] 1) If yes, the next safe clock starts a new cycle.

[0089] II) If not, determine whether it was received during the forgiveness period:

[0090] A) If not, set the synchronization status value to out of sync.

[0091] B) If so, further determine whether it is received before the last safe clock of the main cycle: if it is received before the last safe clock of the main cycle, the next safe clock starts a new cycle; if it is received after the last safe clock of the main cycle, use its own safe clock count value, that is, the next safe clock of the last clock to start a new cycle, and reset its own safe clock count value after receiving the clock synchronization message.

[0092] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A fast clock synchronization system based on virtualization technology, characterized in that: The system includes a secure clock virtual machine (STVM), a working virtual machine (VM), a clock card, and a TSN switch; The secure clock virtual machine (STVM) generates a unique clock by directly passing through the clock card through virtualization technology; The TSN switch establishes a multicast communication network between the secure clock virtual machine STVM and each working virtual machine VM for transmitting clock synchronization messages of a set period; The secure clock virtual machine STVM sends a clock synchronization message of corresponding cycle length to each multicast network; The working virtual machine VM creates a periodic clock synchronization receiving task to receive a clock synchronization signal with a period length.

2. The fast clock synchronization system based on virtualization technology according to claim 1, characterized in that: The secure clock virtual machine STVM and the working virtual machine VM are created on a virtualization platform of a server, and each server has a unique secure clock virtual machine STVM.

3. The fast clock synchronization system based on virtualization technology according to claim 1, characterized in that: The TSN switch controls the transmission time of data packets through traffic scheduling and priority management.

4. The fast clock synchronization system based on virtualization technology according to claim 1, characterized in that: The clock card includes a safety clock for safety task scheduling and a verification clock for verifying the accuracy of the safety clock and verifying the length of periodic tasks.

5. The fast clock synchronization system based on virtualization technology according to claim 4, characterized in that: The clock card sends a safety clock interrupt signal every T time based on the safety clock, and calculates a count value of the time length between each safety clock interrupt signal based on the check clock.

6. The fast clock synchronization system based on virtualization technology according to claim 4, characterized in that: After the secure clock virtual machine STVM receives the secure clock interrupt signal from the clock card, it forwards the secure clock interrupt signal to each working virtual machine VM through the virtualization layer, reads the verification count value, adjusts the secure clock count value as needed, accumulates the received secure clock interrupt count value, and finally completes the clear interrupt operation.

7. The fast clock synchronization system based on virtualization technology according to claim 6, characterized in that: After receiving the secure clock interrupt signal, the working virtual machine VM reads and verifies the count value, adjusts the secure clock count value and updates the secure clock interrupt count value as needed, and implements task scheduling according to the secure clock interrupt signal.

8. The fast clock synchronization system based on virtualization technology according to claim 6, characterized in that: The working virtual machine VM verifies the safety clock and the task cycle length according to the verification clock count value, and if the verification fails, it is directed to the safe state.

9. A synchronization method for the fast clock synchronization system based on virtualization technology according to claim 1, characterized in that: The synchronization method includes: Step S1, the secure clock virtual machine STVM configures the clock synchronization cycle length based on the secure clock interrupt count value, and selects to create one or more periodic clock synchronization tasks according to the different system cycle lengths; and sets multiple multicast addresses in the communication network, each multicast transmission setting a clock synchronization message of the cycle length; Step S2, the secure clock virtual machine STVM sends a clock synchronization message of corresponding cycle length to each multicast network; Step S3: the working virtual machine VM creates a periodic clock synchronization receiving task to receive a clock synchronization signal with a period length field; Step S4, when the working virtual machine VM receives the clock synchronization message, it verifies the consistency between the cycle length in the clock synchronization message and the cycle length of its own task. If the verification is consistent, the initialization phase task enters the main cycle at the next safe clock after the clock synchronization message is received; the main cycle task determines the start time point of the task cycle based on the time when the clock synchronization message is received and the safe clock count value; if the verification is inconsistent, the clock synchronization message is discarded.

10. A synchronization method based on virtualization technology according to claim 9, characterized in that: The secure clock virtual machine STVM sends a clock synchronization message containing a masked cycle length field. After receiving the clock synchronization message, the working virtual machine VM performs a demasking process on the cycle length field.

11. The synchronization method based on virtualization technology according to claim 9, characterized in that: The starting time point of the task cycle in step S4 is specifically: For a task cycle of 500ms, when the next clock synchronization message is received and the safe clock count value of this cycle is 250, it means that the clock synchronization of 500ms is accurate, and the task cycle of the virtual machine VM itself starts at the next safe clock.

12. The synchronization method based on virtualization technology according to claim 9, characterized in that: This method sets delay forgiveness conditions as needed, specifically including: 1) When the safety clock count value of this cycle reaches 250 and no clock synchronization message has been received, the next safety clock interrupt will directly start a new cycle and the safety clock count value will be recounted; 2) When the current cycle's secure clock count is less than or equal to 2, a new clock message is received, indicating that the local secure clock count is faster than the cycle synchronization clock, and a new cycle begins early. The channel should recount the secure clock count and set the clock synchronization state to synchronized. If the count is greater than 2 and a new clock message is received, it is considered that the message delay is large, and the clock synchronization state is set to asynchronous. The main cycle continues to run. If the synchronization state is asynchronous for three consecutive times, it returns to the secure state. 3) When the safety clock count value of this cycle is greater than or equal to 248, a new clock message is received, which means that the local safety clock count value is slower than the periodic synchronization clock. When the clock message is received, a new cycle should be started with the next safety clock, the safety clock count value is recounted, and the clock synchronization state is set to synchronized. When the count value of this cycle is less than 248, a new clock message is received, and the clock synchronization state is set to asynchronous. The main cycle continues to run. If the synchronization state is asynchronous for three consecutive times, it will be directed to the safe state.

13. A synchronization method based on virtualization technology according to claim 12, characterized in that: In this method, at the beginning of each cycle, the VMs communicating with each other exchange a secure clock count value at the beginning of the cycle; Since the set cycle synchronization tolerance is 2 count values, its own count value is sent at the third count value at the beginning of the cycle. The count value difference is received and checked to see if it is within the tolerance range. If it is within the tolerance range, the backup system adjusts its own safety clock count value according to the master system's count value; if it is not within the tolerance range, the clock synchronization state is set to asynchronous. If the synchronization state is asynchronous for three consecutive times, it will be directed to the safe state. If the safe clock count message is not read, the clock synchronization state is set to asynchronous.

Citation Information

Patent Citations

  • Method and system for time synchronization of virtualization platform

    CN113691342A

Cited By

  • Multi-application security clock verification system, method and device for cloud security platform and medium

    CN121857913A

  • Clock interruption method and device

    CN121940088A