Data integrity protection method, system and server for building automatic control system

By using a data frame sequence number and hash comparison verification mechanism in the building automation system, the problem of incomplete synchronization of redundant data was solved, achieving efficient and accurate synchronization of redundant data and ensuring the stable operation of the backup controller.

CN120892256APending Publication Date: 2025-11-04GREE ELECTRIC APPLIANCE INC OF ZHUHAI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511198245.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

In building automation systems, during the synchronization of redundant data between the main controller and the backup controller, incomplete data may occur, leading to abnormal operation of the backup controller.

Method used

By setting data frame sequence numbers, hierarchical labels, and redundant data content in incremental data frames, the standby controller performs sequence number continuity checks and hash comparison checks based on the verification fields to ensure the integrity of redundant data.

Benefits of technology

It improves the integrity and accuracy of redundant data synchronization and reduces the possibility of abnormal operation of the backup controller due to data loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120892256A_ABST
    Figure CN120892256A_ABST
Patent Text Reader

Abstract

The invention provides a data integrity protection method and system for a building automatic control system and a server. The method comprises the steps that a main controller writes change information of redundant data into an incremental data frame, the incremental data frame comprises a data frame serial number, a grading label and redundant data content, the grading label is used for identifying the type of the redundant data content, and under the condition that the redundant data content is key data, the incremental data frame further comprises a verification field; the standby controller receives the incremental data frame from the main controller and executes serial number continuity verification according to the data frame serial number in the incremental data frame; under the condition that the serial number continuity verification succeeds and the redundant data content identified by the hierarchical tag is key data, the standby controller performs hash comparison verification based on the verification field; and under the condition that the hash comparison verification fails, the standby controller informs the main controller to retransmit the key data or the key data item identification field needing to be retransmitted in the key data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of data security, and in particular, to a data integrity protection method, system and server for a building automation system. BACKGROUND

[0002] In a building automation system, in order to guarantee high availability of the system, a controller is often deployed in a redundant manner as a master controller and a backup controller. In the related art, the switching scheme of the master controller and the backup controller relies on simple heartbeat detection or a single verification mechanism. In the process of synchronizing redundant data between the master controller and the backup controller, the synchronized redundant data may have the problem of data incompleteness, which easily leads to abnormal operation of the backup controller due to receiving incomplete data. SUMMARY

[0003] One technical problem solved by the present disclosure is that in the process of synchronizing redundant data between the master controller and the backup controller, the synchronized redundant data may have the problem of data incompleteness.

[0004] According to one aspect of the present disclosure, a data integrity protection method is provided, comprising: a master controller writing change information of redundant data into an incremental data frame in a case where the master controller detects that the redundant data has changed, wherein the incremental data frame comprises a data frame serial number, a hierarchical label and redundant data content, the hierarchical label is used to identify the type of the redundant data content, and in a case where the redundant data content is critical data, the incremental data frame further comprises a verification field; a backup controller receiving the incremental data frame from the master controller, and performing serial number continuity verification according to the data frame serial number in the incremental data frame; in a case where the serial number continuity verification is successful and the hierarchical label identifies that the redundant data content is critical data, the backup controller performs hash comparison verification based on the verification field; and in a case where the hash comparison verification fails, the backup controller notifies the master controller to retransmit the critical data or a critical data item identification field that needs to be retransmitted in the critical data.

[0005] In some embodiments, the data frame serial number is a globally unique monotonically increasing serial number; performing serial number continuity verification according to the data frame serial number in the incremental data frame comprises: in a case where the data frame serial number is not the first data frame serial number, judging whether the data frame serial number is consistent with the sum of the data frame serial number in the previous incremental data frame and 1; in a case where the data frame serial number is consistent with the sum of the data frame serial number in the previous incremental data frame and 1, determining that the serial number continuity verification is successful; and in a case where the data frame serial number is not consistent with the sum of the data frame serial number in the previous incremental data frame and 1, determining that the serial number continuity verification fails.

[0006] In some embodiments, the performing the sequence number continuity check according to the data frame sequence number in the incremental data frame further comprises: in a case that the data frame sequence number is a first data frame sequence number, determining that the sequence number continuity check is successful.

[0007] In some embodiments, the data integrity protection method further comprises: in a case that the sequence number continuity check fails, the backup controller notifying the primary controller to retransmit the incremental data frame.

[0008] In some embodiments, the check field is a first check code calculated by the primary controller using a hash algorithm on the key data; and the performing the hash comparison check based on the check field comprises: the backup controller calculating a second check code using the hash algorithm on the key data; comparing the second check code with the first check code; in a case that the second check code is consistent with the first check code, determining that the hash comparison check is successful; and in a case that the second check code is not consistent with the first check code, determining that the hash comparison check fails.

[0009] In some embodiments, the primary controller is a primary virtual controller; and the backup controller is a backup virtual controller.

[0010] According to another aspect of the present disclosure, there is provided a data integrity protection system, comprising: a primary controller configured to, in a case that a change in redundant data is detected, write change information of the redundant data into an incremental data frame, wherein the incremental data frame comprises a data frame sequence number, a hierarchical label and redundant data content, the hierarchical label is used to identify a type of the redundant data content, and in a case that the redundant data content is key data, the incremental data frame further comprises a check field; and a backup controller configured to receive the incremental data frame from the primary controller, and perform a sequence number continuity check according to the data frame sequence number in the incremental data frame, in a case that the sequence number continuity check is successful and the hierarchical label identifies that the redundant data content is key data, perform a hash comparison check based on the check field, and in a case that the hash comparison check fails, the backup controller notifying the primary controller to retransmit the key data or a key data item identification field in the key data that needs to be retransmitted.

[0011] In some embodiments, the data frame sequence number is a globally unique monotonically increasing sequence number; and the backup controller is configured to, in a case that the data frame sequence number is not a first data frame sequence number, determine whether the data frame sequence number is consistent with a sum of a data frame sequence number in a previous incremental data frame and 1, determine that the sequence number continuity check succeeds in a case that the data frame sequence number is consistent with the sum of the data frame sequence number in the previous incremental data frame and 1, and determine that the sequence number continuity check fails in a case that the data frame sequence number is not consistent with the sum of the data frame sequence number in the previous incremental data frame and 1.

[0012] In some embodiments, the backup controller is configured to, in a case that the data frame sequence number is a first data frame sequence number, determine that the sequence number continuity check succeeds.

[0013] In some embodiments, the backup controller is further configured to, in a case that the sequence number continuity check fails, notify the primary controller to resend the incremental data frame.

[0014] In some embodiments, the check field is a first check code calculated by the primary controller using a hash algorithm on the key data; and the backup controller is configured to calculate a second check code using the hash algorithm on the key data, compare the second check code with the first check code, determine that the hash comparison check succeeds in a case that the second check code is consistent with the first check code, and determine that the hash comparison check fails in a case that the second check code is not consistent with the first check code.

[0015] In some embodiments, the primary controller is a primary virtual controller; and the backup controller is a backup virtual controller.

[0016] According to another aspect of the present disclosure, there is provided a data integrity protection system, comprising: a memory; and a processor coupled to the memory, the processor being configured to perform the data integrity protection method as previously described based on instructions stored in the memory.

[0017] According to another aspect of the present disclosure, there is provided a server, comprising: the data integrity protection system as previously described, wherein the primary controller is a primary virtual controller, and the backup controller is a backup virtual controller.

[0018] According to another aspect of the present disclosure, there is provided a building automation system, comprising: the data integrity protection system as previously described, or the server as previously described.

[0019] According to another aspect of the present disclosure, there is provided a computer readable storage medium having stored thereon computer instructions which, when executed by a processor, implement the data integrity protection method as previously described.

[0020] According to another aspect of the present disclosure, there is provided a computer program product comprising computer programs or instructions which, when executed by a processor, implement the data integrity protection method as previously described.

[0021] In the above method, by setting the data frame serial number, hierarchical label and redundant data content in the incremental data frame, the standby controller performs serial number continuity verification according to the data frame serial number in the incremental data frame and hash comparison verification based on the verification field, so that it can be determined whether the synchronized redundant data is complete, thereby improving the integrity of the synchronized redundant data.

[0022] Other features of the present disclosure, and their advantages, will become apparent from the following detailed description of exemplary embodiments of the present disclosure, with reference to the drawings. BRIEF DESCRIPTION OF DRAWINGS

[0023] The accompanying drawings, which form a part of the specification, illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0024] The present disclosure can be understood more readily by reference to the following detailed description of exemplary embodiments of the present disclosure and the attached drawings, of which:

[0025] Figure 1 is a flowchart illustrating a data integrity protection method according to some embodiments of the present disclosure;

[0026] Figure 2 is an architectural diagram of a data integrity protection system according to some embodiments of the present disclosure;

[0027] Figure 3 is a structural diagram of an incremental data frame according to some embodiments of the present disclosure;

[0028] Figure 4 is a structural diagram of an incremental data frame according to some other embodiments of the present disclosure;

[0029] Figure 5 is a flowchart illustrating a data integrity protection method according to some other embodiments of the present disclosure;

[0030] Figure 6 is a structural block diagram of a data integrity protection system according to some embodiments of the present disclosure;

[0031] Figure 7 is a structural block diagram of a data integrity protection system according to some other embodiments of the present disclosure;

[0032] Figure 8 is a structural block diagram showing a data integrity protection system according to some embodiments of the present disclosure. DETAILED DESCRIPTION

[0033] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. Note that the relative arrangement, numerical expressions, and numerical values of components and steps set forth in these embodiments are not limiting to the scope of the present disclosure unless otherwise specifically stated.

[0034] At the same time, it should be understood that the size of each part shown in the drawings is not drawn in accordance with the actual proportional relationship for the convenience of description.

[0035] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way limiting to the scope of the present disclosure and its applications or uses.

[0036] Techniques, methods, and devices known to those of ordinary skill in the relevant art can not be discussed in detail herein, but should be considered as part of the specification, where appropriate.

[0037] In all examples shown and discussed herein, any specific values should be interpreted as merely illustrative and not as a limitation. Thus, other examples of the exemplary embodiments can have different values.

[0038] Note that similar reference numerals and letters refer to like items in the following drawings, and thus, once an item is defined in one drawing, it need not be discussed further in subsequent drawings.

[0039] In some embodiments of the present disclosure, a data integrity protection method is provided to improve the data integrity of the controller in the building automation system, improve the integrity of the redundant data in the transmission process, and reduce the possibility of abnormal operation of the backup controller due to data loss.

[0040] Here, before describing the data integrity protection method of the embodiments of the present disclosure, the architecture of the data integrity protection system according to some embodiments of the present disclosure can be described in conjunction with the drawings.

[0041] For example, Figure 2 is a structural block diagram showing a data integrity protection system according to some embodiments of the present disclosure. As Figure 2As shown, the data integrity protection system includes a master controller 20 and a backup controller 30. The master controller 20 includes a first redundancy unit 210 and a first switching unit 220. The backup controller 30 includes a second redundancy unit 310 and a second switching unit 320. The first redundancy unit 210 and the second redundancy unit 310 are configured to perform a synchronization operation of redundant data. The first switching unit 220 and the second switching unit 320 are configured to perform a switching operation of the master controller and the backup controller. Here, the redundant data includes data such as a running state of the master controller, and the backup controller is synchronized to the master controller so as to operate in a hot standby state.

[0042] With the cloudization and virtualization trend of the building automation system, it is an industry consensus to use a software-defined virtual controller in the server. Therefore, the master controller 20 and the backup controller 30 can both be virtual controllers, i.e., the master controller is a master virtual controller, and the backup controller is a backup virtual controller. The master virtual controller and the backup virtual controller are located in the server of the building automation system. That is, a group of master-standby virtual controllers are pre-configured in the server of the building automation system, and a unified control application program is installed, which can realize the cloudization and virtualization of the building automation system.

[0043] Of course, in other embodiments, the master controller 20 and the backup controller 30 can both be hardware controllers, which can also constitute the above-mentioned data integrity protection system.

[0044] As shown in Figure 2 , the master controller can operate in a master mode, and the backup controller can operate in a backup mode. The two controllers complete data interaction through an inter-process communication mechanism (for example, shared memory, message queue, etc.) and configure global session parameters. For example, the global session parameters include a sending window, a retransmission number, a timeout threshold, a heartbeat period, etc.

[0045] The system startup process is as follows:

[0046] 1. When the master controller 20 starts, the first redundancy unit 210 sends a configuration information frame to the backup controller 30. The configuration information frame contains system global session parameters. The backup controller 30 parses the content of the configuration information frame and completes parameter configuration.

[0047] 2. The master controller 20 confirms the online state with the backup controller 30 through a heartbeat mode. For example, as shown in Figure 2 , the master controller 20 periodically sends a heartbeat frame (i.e., heartbeat data) to the second switching unit 320 of the backup controller 30 through the first switching unit 220 in the case of normal operation. The heartbeat data is used to mark the online state of the master controller.

[0048] Figure 1is a flowchart illustrating a data integrity protection method according to some embodiments of the present disclosure. The method can be performed by a data integrity protection system. The data integrity protection system includes a primary controller and a backup controller. For example, the primary controller is a primary virtual controller, and the backup controller is a backup virtual controller. As shown in Figure 1 the method includes steps S102-S108.

[0049] At step S102, the primary controller writes change information of the redundant data into an incremental data frame in a case where a change in the redundant data is detected.

[0050] In some embodiments, as shown in Figure 3 the incremental data frame includes a data frame sequence number, a hierarchical label, and redundant data content. The hierarchical label is used to identify a type of the redundant data content. The type of the redundant data content includes critical data and normal data. That is, the hierarchical label can identify whether the redundant data content is critical data or normal data. For example, the critical data includes at least one of a control logic execution state, a critical point state, a control parameter, and an alarm record. For example, the normal data includes at least one of a general environment detection type point, a general operation log, and an electric quantity type metering data.

[0051] For example, as shown in Figure 4 the hierarchical label can include a first hierarchical label and a second hierarchical label. The first hierarchical label is used to identify that the redundant data content is critical data. The second hierarchical label is used to identify that the redundant data content is normal data.

[0052] As shown in Figure 4 in a case where the redundant data content is critical data, the incremental data frame further includes a check field. For example, the check field is located between the data frame sequence number and the first hierarchical label.

[0053] In some cases, as shown in Figure 4 the incremental data frame includes the data frame sequence number, the check field, the first hierarchical label, the critical data, the second hierarchical label, and the normal data. That is, there is a case where the incremental data frame contains both critical data and normal data.

[0054] In another case, the incremental data frame includes the data frame sequence number, the check field, the first hierarchical label, and the critical data. That is, there is a case where the incremental data frame contains only critical data.

[0055] In another case, the incremental data frame includes the data frame sequence number, the second hierarchical label, and the normal data. That is, there is a case where the incremental data frame contains only normal data.

[0056] In some embodiments, the first redundancy unit of the master controller can periodically detect changes in the redundancy data, for example, the changes can be the addition of new redundancy data, or the change of existing redundancy data. The first redundancy unit of the master controller can write the change information (for example, the newly added redundancy data or the changed redundancy data, etc.) to different positions of the incremental data frame according to the hierarchical tags, as shown in Figure 3 or Figure 4 The incremental data frame includes a data frame sequence number, a hierarchical tag, and data content, wherein a verification field (for example, a SHA-256 hash value) is attached in front of the content marked as key data. For example, the data frame sequence number is a globally unique monotonically increasing sequence number. After the incremental data frame is constructed, it is placed in the sending queue and waits to be sent.

[0057] In some embodiments, in order to balance the data consistency guarantee and system performance optimization in the redundancy data synchronization process of the building automation system, the redundancy data can be classified and managed and hierarchical verification can be performed. For example, in some cases, only key data can be subjected to integrity verification operation, and ordinary data can be subjected to a verification-free mechanism, thereby improving synchronization efficiency without sacrificing system reliability. The system supports customizing key data fields through configuration files to meet the needs of different business scenarios.

[0058] In step S104, the standby controller receives the incremental data frame from the master controller, and performs sequence number continuity verification according to the data frame sequence number in the incremental data frame.

[0059] In some embodiments, the data frame sequence number is a globally unique monotonically increasing sequence number. In this case, according to the data frame sequence number in the incremental data frame, the sequence number continuity verification includes: in the case that the data frame sequence number is not the first data frame sequence number, judging whether the data frame sequence number is consistent with the sum of the data frame sequence number in the last incremental data frame and 1; in the case that the data frame sequence number is consistent with the sum of the data frame sequence number in the last incremental data frame and 1, determining that the sequence number continuity verification is successful; and in the case that the data frame sequence number is not consistent with the sum of the data frame sequence number in the last incremental data frame and 1, determining that the sequence number continuity verification fails.

[0060] That is, in the above embodiments, since the data frame sequence number is a globally unique monotonically increasing sequence number, whether the current data frame sequence number is consistent with the sum of the last data frame sequence number and 1 can be determined to determine whether the current data frame sequence number meets the sequence number continuity, that is, whether these data frame sequence numbers are sequentially continuous. If consistent, it indicates that the data frame sequence number is continuous, otherwise, the data frame sequence number is discontinuous, that is, the synchronized redundancy data can not meet the integrity requirement. In this way, whether the synchronized redundancy data is complete can be determined, thereby improving the integrity of the synchronized redundancy data.

[0061] The above embodiments describe the case where the current data frame sequence number is not the first data frame sequence number. For the case where the current data frame sequence number is the first data frame sequence number, the following method can be used.

[0062] That is, in other embodiments, according to the data frame sequence number in the incremental data frame, the sequence number continuity check is performed, and further includes: in the case where the data frame sequence number is the first data frame sequence number, determining that the sequence number continuity check is successful. That is, if the current data frame sequence number is the first data frame sequence number, there is no other data frame sequence number before the first data frame sequence number, and therefore, it is directly determined that the sequence number continuity check is successful. In this way, the sequence number continuity check process in the case where the current data frame sequence number is the first data frame sequence number is realized, and the executable of the method is improved.

[0063] In step S106, in the case where the sequence number continuity check is successful and the hierarchical label identifies the redundant data content as the critical data, the standby controller performs a hash comparison check based on the check field.

[0064] In some embodiments, the check field is a first check code obtained by the primary controller using a hash algorithm to calculate the critical data. In such a case, the above step S106 includes: the standby controller using the above hash algorithm to calculate the critical data to obtain a second check code; comparing the second check code with the first check code; in the case where the second check code is consistent with the first check code, determining that the hash comparison check is successful; and in the case where the second check code is inconsistent with the first check code, determining that the hash comparison check fails.

[0065] That is, the check field is a first check code obtained by the primary controller using a hash algorithm to hash calculate the critical data, and when the standby controller performs a hash comparison check, the same hash algorithm is used to hash calculate the critical data in the incremental data frame to obtain a second check code. In this way, the second check code can be compared with the first check code. If they are consistent, it is determined that the hash comparison check is successful, indicating that the critical data in the current incremental data frame is complete and correct. If they are inconsistent, it is determined that the hash comparison check fails, indicating that the critical data in the current incremental data frame is missing or incorrect, and then the relevant data can be retransmitted in the subsequent steps. Since the critical data is important data, through such a check, the integrity and accuracy of the synchronization of the critical data can be improved, and thus the integrity of the synchronized redundant data is improved.

[0066] In step S108, in the case where the hash comparison check fails, the standby controller notifies the primary controller to retransmit the critical data or the critical data item identification field in the critical data that needs to be retransmitted.

[0067] That is, if the hash comparison check fails, it means that the synchronized key data is missing or incorrect, and the backup controller can notify the master controller so that the master controller retransmits the key data, or, in the case where the backup controller learns that there is a certain field or certain fields missing or incorrect in the key data, the backup controller notifies the master controller so that the master controller retransmits the key data item identification field that needs to be retransmitted in the key data, that is, the certain field or certain fields missing or incorrect in the key data learned by the backup controller. In this way, the integrity and accuracy of the key data synchronization can be improved, and the integrity of the synchronized redundant data can be improved.

[0068] For example, in the case where the hash comparison check fails, the backup controller can send a key data feedback frame to the master controller to notify the master controller that the currently transmitted key data is missing or incorrect, so that the master controller retransmits the key data to the backup controller.

[0069] For another example, in the key data field of the incremental data frame, a plurality of sub-key data fields can be included, and a sub-check field is set before each sub-key data field, and each sub-check field is a first sub-check code obtained by the master controller using a hash algorithm to hash the corresponding sub-key data field. In the case where the backup controller determines that the hash comparison check fails, the backup controller can further hash compare each first sub-check code, for example, can hash each sub-key data field based on the same hash algorithm to obtain a second sub-check code, and compare each second sub-check code with the corresponding first sub-check code, that is, compare the second sub-check code and the first sub-check code corresponding to the same sub-key data field, if they are consistent, it is determined that the sub-key data field corresponding to the current first sub-check code is correct, otherwise it is determined that the sub-key data field corresponding to the current first sub-check code is missing or incorrect, and the sub-key data field is the key data item identification field that needs to be retransmitted. In this way, the field that needs to be retransmitted in the key data is more accurately determined, so that the master controller can only retransmit these fields when retransmitting the key data, reducing the burden of data retransmission and improving efficiency.

[0070] To sum up, the data integrity protection method according to some embodiments of the present disclosure is provided. The method comprises: the master controller writes the change information of the redundant data into the incremental data frame in the case of detecting that the redundant data changes, wherein the incremental data frame comprises a data frame serial number, a hierarchical label and redundant data content, the hierarchical label is used to identify the type of the redundant data content, and the incremental data frame further comprises a check field in the case of the redundant data content being key data; the standby controller receives the incremental data frame from the master controller and performs serial number continuity verification according to the data frame serial number in the incremental data frame; in the case of successful serial number continuity verification and the hierarchical label identifying that the redundant data content is key data, the standby controller performs hash comparison verification based on the check field; and in the case of failed hash comparison verification, the standby controller informs the master controller to retransmit the key data or the key data item identification field in the key data that needs to be retransmitted. In the method, by setting the data frame serial number, the hierarchical label and the redundant data content in the incremental data frame, the standby controller performs serial number continuity verification according to the data frame serial number in the incremental data frame and performs hash comparison verification based on the check field, so as to determine whether the synchronized redundant data is complete, thereby improving the integrity of the synchronized redundant data.

[0071] In addition, by performing hash comparison verification based on the check field, the above method can also improve the accuracy of key data synchronization.

[0072] In some embodiments, the data integrity protection method can further comprise: in the case of failed serial number continuity verification, the standby controller informs the master controller to retransmit the incremental data frame. That is, after determining that the serial number continuity verification fails, the standby controller triggers the whole frame retransmission, for example, the standby controller replies NACK-ALL data frame to the master controller, requiring the master controller to retransmit the incremental data frame. In this embodiment, by making the master controller retransmit the incremental data frame in the case of failed serial number continuity verification, the integrity of the synchronized redundant data can be improved.

[0073] In some embodiments, the data integrity protection method can further comprise: in the case of successful serial number continuity verification and hash comparison verification, the standby controller stores the current incremental data frame. That is, in the case of successful serial number continuity verification and hash comparison verification, it is determined that the data integrity verification of the current incremental data frame is successful, that is, the current incremental data frame is complete and continuous with the previous incremental data frame, therefore, the standby controller stores the current incremental data frame, that is, the current synchronized redundant data is successful.

[0074] Figure 5is a flow chart showing a data integrity protection method according to some other embodiments of the present disclosure. In the method, the primary controller is a primary virtual controller, and the backup controller is a backup virtual controller. The method can be implemented in a server. The method comprises steps S502-S508.

[0075] At step S502, the primary virtual controller sends an incremental data frame. The incremental data frame comprises a data frame sequence number, a hierarchical label, and redundant data content. In the case that the redundant data content is critical data, the incremental data frame further comprises a check field. The check field is a first check code obtained by the primary virtual controller hashing the critical data using a hash algorithm.

[0076] At step S504, the backup virtual controller receives the incremental data frame.

[0077] At step S506, it is determined whether the data frame sequence number is consistent with the sum of the previous data frame sequence number and 1. That is, it is determined whether the current data frame sequence number is equal to the previous data frame sequence number plus 1. If yes, the process proceeds to step S508, otherwise, the backup virtual controller returns a NACK-ALL frame to the primary virtual controller, so that the primary virtual controller retransmits the entire incremental data frame.

[0078] At step S508, it is determined whether the second check code is consistent with the first check code. That is, the backup virtual controller hashes the critical data in the incremental data frame using the same hash algorithm to obtain a second check code, and compares the second check code with the first check code to determine whether the second check code is consistent with the first check code. If yes, the backup virtual controller returns an ACK frame to the primary virtual controller to determine that the current synchronization redundant data is successful; otherwise, the backup virtual controller returns a NACK-PART frame (as an error feedback frame) to the primary virtual controller, only identifying the critical data item identification field that needs to be retransmitted, so that the primary virtual controller retransmits the critical data item identification field in the critical data.

[0079] So far, the data integrity protection method according to some other embodiments of the present disclosure is provided. The method can determine whether the synchronized redundant data is complete, thereby improving the integrity of the synchronized redundant data. Moreover, by performing hash comparison check based on the check field, the accuracy of the synchronization of the critical data can also be improved.

[0080] In the above embodiment, in order to improve the reliability of the redundancy data synchronization between the primary virtual controller and the standby virtual controller, the primary virtual controller uses a synchronization and integrity check mechanism based on the data hierarchical tag to synchronize the redundancy data to the standby virtual controller, so that the standby virtual controller can quickly take over the primary virtual controller to run through the redundancy data. Through the sending of the hierarchical redundancy data and the combination of the integrity check mechanism, the efficiency and integrity of the redundancy data synchronization are realized.

[0081] In the method of some embodiments of the present disclosure, after the standby virtual controller receives the incremental data frame, it judges whether to perform integrity check according to the tag field of the data item, performs serial number continuity check on all data, and increases hash comparison for key data. When the serial number check fails, the standby virtual controller triggers the whole frame retransmission; when the hash check of the key data fails, the standby virtual controller does not trigger the whole frame retransmission, but constructs an accurate error feedback frame (for example, NACK-PART frame) to identify the key data item identification field that needs to be retransmitted. The primary virtual controller reconstructs the retransmission frame containing the failed item according to this and sends it to the standby controller for repair synchronization.

[0082] Further, the standby controller (for example, the standby virtual controller) writes the received redundancy data into the corresponding data storage area, provides data basis for the quick takeover after the primary-standby switching, and supports hot standby recovery.

[0083] Figure 6 is a structural block diagram of a data integrity protection system according to some embodiments of the present disclosure. As shown in Figure 6 , the data integrity protection system includes a primary controller 20 and a standby controller 30. For example, the primary controller 20 is a primary virtual controller, and the standby controller is a standby virtual controller. For example, the primary virtual controller and the standby virtual controller are located in the same server.

[0084] The primary controller 20 is configured to write the change information of the redundancy data into an incremental data frame when detecting that the redundancy data has changed, wherein the incremental data frame includes a data frame serial number, a hierarchical tag, and redundancy data content, the hierarchical tag is used to identify the type of the redundancy data content, and when the redundancy data content is key data, the incremental data frame further includes a check field.

[0085] The standby controller 30 is configured to receive the incremental data frame from the primary controller, and perform serial number continuity check according to the data frame serial number in the incremental data frame, perform hash comparison check based on the check field when the serial number continuity check is successful and the hierarchical tag identifies that the redundancy data content is key data, and notify the primary controller to retransmit the key data or the key data item identification field that needs to be retransmitted when the hash comparison check fails.

[0086] In the data integrity protection system, by setting the data frame sequence number, the hierarchical label and the redundant data content in the incremental data frame, the standby controller performs the sequence number continuity check according to the data frame sequence number in the incremental data frame and the hash comparison check based on the check field, so as to determine whether the synchronized redundant data is complete, thereby improving the integrity of the synchronized redundant data. In addition, by performing the hash comparison check based on the check field, the above system can also improve the accuracy of the key data synchronization.

[0087] In some embodiments, the data frame sequence number is a globally unique monotonically increasing sequence number. The standby controller 30 can be configured to, in a case where the data frame sequence number is not the first data frame sequence number, determine whether the data frame sequence number is consistent with the sum of the data frame sequence number in the last incremental data frame and 1, determine that the sequence number continuity check is successful in a case where the data frame sequence number is consistent with the sum of the data frame sequence number in the last incremental data frame and 1, and determine that the sequence number continuity check fails in a case where the data frame sequence number is not consistent with the sum of the data frame sequence number in the last incremental data frame and 1. In this way, it can be determined whether the synchronized redundant data is complete, thereby improving the integrity of the synchronized redundant data.

[0088] In some embodiments, the standby controller 30 can be configured to determine that the sequence number continuity check is successful in a case where the data frame sequence number is the first data frame sequence number. In this way, the sequence number continuity check process in the case where the current data frame sequence number is the first data frame sequence number is realized, and the executability of the method is improved.

[0089] In some embodiments, the standby controller 30 can also be configured to, in a case where the sequence number continuity check fails, notify the main controller to retransmit the incremental data frame. This can improve the integrity of the synchronized redundant data.

[0090] In some embodiments, the check field is a first check code obtained by the main controller using a hash algorithm to calculate the key data. The standby controller 30 can be configured to calculate the key data using the hash algorithm to obtain a second check code, compare the second check code with the first check code, determine that the hash comparison check is successful in a case where the second check code is consistent with the first check code, and determine that the hash comparison check fails in a case where the second check code is not consistent with the first check code. Through such a check, the accuracy of the key data synchronization can be improved, and thus the integrity of the synchronized redundant data is improved.

[0091] Figure 7 is a structural block diagram illustrating a data integrity protection system according to some other embodiments of the present disclosure. The data integrity protection system includes a memory 610 and a processor 620. Among them:

[0092] The memory 610 can be a disk, a flash memory, or any other non-volatile storage medium. The memory is used to store Figure 1 and / or Figure 5 instructions of the corresponding embodiments.

[0093] The processor 620 is coupled to the memory 610 and can be implemented as one or more integrated circuits, such as a microprocessor or a microcontroller. The processor 620 is used to execute the instructions stored in the memory, thereby implementing the integrity of the synchronized redundant data.

[0094] In one embodiment, the data integrity protection system 600 can also include a memory 610 and a processor 620, as shown. Figure 8 The processor 620 is coupled to the memory 610 through a BUS 630. The data integrity protection system 600 can also be connected to an external storage device 650 through a storage interface 640 to invoke external data, and can also be connected to a network or another computer system (not shown) through a network interface 660, which will not be described in detail here.

[0095] In this embodiment, the data instructions are stored in the memory, and the above instructions are processed by the processor, thereby improving the integrity of the synchronized redundant data.

[0096] In some embodiments of the present disclosure, a server is also provided, which includes the data integrity protection system as described above. In the data integrity protection system of the server, the main controller is a main virtual controller, and the backup controller is a backup virtual controller.

[0097] In some embodiments of the present disclosure, a building automation system is also provided, which includes the data integrity protection system as described above, or the server as described above.

[0098] In some embodiments, the present disclosure also provides a computer readable storage medium (for example, a non-transitory computer readable storage medium) having computer program instructions stored thereon, which, when executed by a processor, implement the steps of the method in the corresponding embodiments. Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, device, or computer program product. Therefore, the present disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer usable non-transitory storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code. Figure 1 and / or Figure 5 instructions of the corresponding embodiments. Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, device, or computer program product. Therefore, the present disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer usable non-transitory storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0099] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.

[0100] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.

[0101] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks ​ means for functionally implementing the steps listed in the flowchart block or blocks.

[0102] In some embodiments of the present disclosure, a computer program product is also provided, which includes a computer program or instructions, which, when executed by a processor, implement the data integrity protection method as described above.

[0103] In some embodiments of the present disclosure, a computer program is also provided, which includes: instructions, which, when executed by a processor, cause the processor to perform the data integrity protection method as described above.

[0104] So far, the present disclosure has been described in detail. In order to avoid obscuring the concept of the present disclosure, some details known in the art are not described. Those skilled in the art can fully understand how to implement the technical solutions disclosed herein according to the above description.

[0105] While certain embodiments of the disclosure have been described herein in detail as presently preferred, many modifications and variations thereof will be apparent to those skilled in the art, without departing from the scope and spirit of the disclosure. It is to be understood that those skilled in the art will be able to devise many embodiments of the disclosure which, while not explicitly described or shown herein, embody the principles of the disclosure and are included within its spirit and scope. Accordingly, all such suitable modifications and equivalents should be considered as within the scope of the disclosure. The scope of the disclosure is to be indicated by the appended claims, rather than the foregoing description, and all changes that come within the meaning and range of equivalents are intended to be embraced therein.

Claims

1. A data integrity protection method for a building automation system, comprising: When the main controller detects a change in redundant data, it writes the change information of the redundant data into an incremental data frame. The incremental data frame includes a data frame sequence number, a hierarchical label, and redundant data content. The hierarchical label is used to identify the type of the redundant data content. If the redundant data content is critical data, the incremental data frame also includes a verification field. The backup controller receives the incremental data frame from the main controller and performs a sequence number continuity check based on the data frame sequence number in the incremental data frame; If the sequence number continuity check is successful, and the hierarchical label identifies the redundant data content as critical data, the backup controller performs a hash comparison check based on the check field; and In the event of a hash comparison verification failure, the backup controller notifies the main controller to retransmit the critical data or the identifier field of the critical data item that needs to be retransmitted.

2. The data integrity protection method according to claim 1, wherein: The data frame sequence number is a globally unique monotonically increasing sequence number; Based on the sequence number of the data frame in the incremental data frame, perform a sequence number continuity check, including: If the data frame sequence number is not the first data frame sequence number, determine whether the data frame sequence number is consistent with the sum of the data frame sequence number and 1 in the previous incremental data frame; If the sequence number of the data frame matches the sum of the sequence number of the data frame in the previous incremental data frame and 1, the sequence number continuity check is deemed successful; and If the sequence number of the data frame is inconsistent with the sum of the sequence number of the data frame in the previous incremental data frame and 1, the sequence number continuity check is determined to have failed.

3. The data integrity protection method according to claim 2, wherein, Based on the sequence number of the data frame in the incremental data frame, a sequence number continuity check is performed, which also includes: If the data frame sequence number is the sequence number of the first data frame, then the sequence number continuity check is considered successful.

4. The data integrity protection method according to claim 1 further includes: If the sequence number continuity check fails, the backup controller notifies the main controller to retransmit the incremental data frame.

5. The data integrity protection method according to claim 1, wherein: The verification field is a first verification code obtained by the main controller using a hash algorithm to calculate the key data; Hash comparison verification based on the verification field includes: The backup controller uses the hash algorithm to calculate the key data to obtain a second checksum; Compare the second verification code with the first verification code; If the second checksum matches the first checksum, the hash comparison verification is deemed successful; and If the second check code does not match the first check code, the hash comparison check is determined to have failed.

6. The data integrity protection method according to any one of claims 1 to 5, wherein: The main controller is the main virtual controller; The backup controller is a backup virtual controller.

7. A data integrity protection system for building automation systems, comprising: The main controller, upon detecting a change in redundant data, writes the change information of the redundant data into an incremental data frame. The incremental data frame includes a data frame sequence number, a hierarchical label, and redundant data content. The hierarchical label identifies the type of the redundant data content. If the redundant data content is critical data, the incremental data frame also includes a verification field. A backup controller is configured to receive the incremental data frame from the main controller and perform a sequence number continuity check based on the data frame sequence number in the incremental data frame. If the sequence number continuity check is successful and the hierarchical tag identifies the redundant data content as critical data, a hash comparison check is performed based on the check field. If the hash comparison check fails, the backup controller notifies the main controller to retransmit the critical data or the critical data item identifier field that needs to be retransmitted.

8. The data integrity protection system according to claim 7, wherein: The data frame sequence number is a globally unique monotonically increasing sequence number; The backup controller is used to determine whether the data frame sequence number is consistent with the sum of the data frame sequence number and 1 in the previous incremental data frame when the data frame sequence number is not the first data frame sequence number; if the data frame sequence number is consistent with the sum of the data frame sequence number and 1 in the previous incremental data frame, the sequence number continuity check is determined to be successful; and if the data frame sequence number is inconsistent with the sum of the data frame sequence number and 1 in the previous incremental data frame, the sequence number continuity check is determined to be unsuccessful.

9. The data integrity protection system according to claim 8, wherein, The backup controller is used to determine that the sequence number continuity check is successful when the data frame sequence number is the first data frame sequence number.

10. The data integrity protection system according to claim 7, wherein, The backup controller is also used to notify the main controller to retransmit the incremental data frame if the sequence number continuity check fails.

11. The data integrity protection system according to claim 7, wherein: The verification field is a first verification code obtained by the main controller using a hash algorithm to calculate the key data; The backup controller is used to calculate the key data using the hash algorithm to obtain a second check code, compare the second check code with the first check code, and determine that the hash comparison verification is successful if the second check code matches the first check code, and determine that the hash comparison verification fails if the second check code does not match the first check code.

12. The data integrity protection system according to any one of claims 7 to 11, wherein: The main controller is the main virtual controller; The backup controller is a backup virtual controller.

13. A data integrity protection system for a building automation system, comprising: Memory; as well as A processor coupled to the memory, the processor being configured to execute the data integrity protection method as described in any one of claims 1 to 6 based on instructions stored in the memory.

14. A server, comprising: The data integrity protection system as described in any one of claims 7 to 13, wherein the main controller is the main virtual controller and the backup controller is the backup virtual controller.

15. A building automation system, comprising: The data integrity protection system as described in any one of claims 7 to 13, or the server as described in claim 14.

16. A computer-readable storage medium having stored thereon computer instructions that, when executed by a processor, implement the data integrity protection method as described in any one of claims 1 to 6.

17. A computer program product comprising a computer program or instructions that, when executed by a processor, implement the data integrity protection method as described in any one of claims 1 to 6.