Cloud platform architecture for maintaining function security and secure computer platform construction method

By constructing a primary two-out-of-two and backup two-out-of-two safety computer platform in the cloud platform, and using a safety management machine to monitor the operating status of the processor and functional circuits, the problem that existing cloud platforms cannot achieve the SIL-4 safety level is solved, and real-time functional safety of the train control system is realized.

CN120915804APending Publication Date: 2025-11-07BEIJING URBAN CONSTR INTELLIGENT CONTROL TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510819062.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-11-07

Smart Images

  • Figure CN120915804A_ABST
    Figure CN120915804A_ABST
Patent Text Reader

Abstract

The invention relates to a cloud platform architecture for maintaining function security and a secure computer platform construction method. The cloud platform architecture for maintaining the function security comprises N processors and N functional circuits, wherein one processor is connected with one functional circuit to form a data processing module; wherein N is greater than or equal to 4; the safety management machine is connected with the N processors and the N functional circuits through an internal Ethernet; wherein the safety management machine is used for constructing a main system two-out-of-two safety computer platform and a standby system two-out-of-two safety computer platform based on the operation environment and the operation state of the N processors and the N functional circuits, so that the safety computer platform capable of multiplying by two-out-of-two is arranged in the cloud platform architecture in real time, and the safety computer platform is used for a train control system. Therefore, the function security application of the SIL-4 security level is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of rail transit, in particular to a cloud platform architecture for maintaining functional safety and a method for constructing a safety computer platform in the cloud platform architecture. BACKGROUND

[0002] In the field of rail transit, a safety computer platform is the core equipment of a train control system, which ensures the safe operation of the train control system. Electronic and electrical equipment of the train control system needs to meet certain safety standards, but a single system cannot meet the requirements, and therefore these safety architectures must be used. In this regard, a cloud platform, as a new computing and networking technology, can use a set of platforms to undertake multiple applications, can highly integrate the train control system, and can reduce the number of devices of the train control system and the construction and maintenance costs. However, the existing cloud platforms generally cannot provide a safety computer platform architecture, cannot achieve a safety level of SIL-4, and cannot be used for the train control system. SUMMARY

[0003] Therefore, the embodiments of the present disclosure aim to provide a cloud platform architecture for maintaining functional safety and a method for constructing a safety computer platform in the cloud platform architecture.

[0004] The technical solution of the present disclosure is implemented as follows:

[0005] In a first aspect, the present disclosure provides a cloud platform architecture for maintaining functional safety.

[0006] The cloud platform architecture for maintaining functional safety provided by the embodiments of the present disclosure is applied to a train control system, and the cloud platform architecture comprises:

[0007] N processors and N functional circuits; wherein one processor is connected with one functional circuit to form one data processing module; and wherein N is greater than or equal to 4;

[0008] a safety management machine connected with the N processors and the N functional circuits through an internal Ethernet; wherein the safety management machine is configured to acquire running environments and states of the N processors and the N functional circuits, and to construct a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform based on the running environments and states of the N processors and the N functional circuits;

[0009] an external execution layer device connected with the safety management machine, the N processors and the N functional circuits through an output Ethernet; wherein the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the safety management machine are configured to perform data processing on data input by the external execution layer device, and to issue execution instructions to the external execution layer device.

[0010] In some embodiments, the running environment and the running state of the N processors and the N functional circuits are used to build a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform, including:

[0011] four data processing modules are determined from the N processors and the N functional circuits, whose running environment and running state meet the running standard;

[0012] any two data processing modules from the four data processing modules whose running environment and running state meet the running standard are used to build the primary two-out-of-two safety computer platform;

[0013] two data processing modules from the four data processing modules, which are not used to build the primary two-out-of-two safety computer platform, are used to build the backup two-out-of-two safety computer platform.

[0014] In some embodiments, the any two data processing modules from the four data processing modules whose running environment and running state meet the running standard are used to build the primary two-out-of-two safety computer platform, including:

[0015] IP addresses of the two data processing modules used to build the primary two-out-of-two safety computer platform are set through a communication bus;

[0016] a VLAN virtual private network is established based on the IP addresses of the two data processing modules, so that CPU data in the two data processing modules are synchronized, and communication isolation is achieved between the two data processing modules and CPUs outside the two data processing modules.

[0017] In some embodiments, the internal Ethernet includes a first Ethernet and a second Ethernet;

[0018] The security management machine is connected with the N processors and the N functional circuits through the first Ethernet; before the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform are built, the security management machine communicates with the N processors and the N functional circuits through the first Ethernet, and determines four data processing modules used to build the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform;

[0019] The security management machine is connected with the N processors and the N functional circuits through the second Ethernet; after the four data processing modules used to build the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform are determined, the security management machine determines the four data processing modules to the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform through the second Ethernet.

[0020] In some embodiments, after determining the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform, the security management machine monitors output data of the primary two-out-of-two safety computer platform through the output Ethernet; and

[0021] Based on data analysis of the output data, the running state of the primary two-out-of-two safety computer platform is determined, and a primary-backup system switching is performed when the primary two-out-of-two safety computer platform has a running problem.

[0022] In a second aspect, the disclosure provides a method for constructing a safety computer platform in a cloud platform architecture, the cloud platform architecture comprising: N processors and N functional circuits; wherein one processor is connected with one functional circuit to form one data processing module; wherein N≥4; a security management machine connected with the N processors and the N functional circuits through an internal Ethernet; and an external execution layer device connected with the security management machine, the N processors and the N functional circuits through an output Ethernet.

[0023] The method comprises:

[0024] The security management machine acquires running environments and running states of the N processors and the N functional circuits;

[0025] Based on the running environments and the running states of the N processors and the N functional circuits, a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform are constructed; wherein the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the security management machine are used for data processing of data input by the external execution layer device and issuing execution instructions to the external execution layer device.

[0026] In some embodiments, the construction of the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform based on the running environments and the running states of the N processors and the N functional circuits comprises:

[0027] Four data processing modules with running environments and running states meeting running standards are determined from the N processors and the N functional circuits;

[0028] Any two data processing modules of the four data processing modules with running environments and running states meeting running standards are used to construct the primary two-out-of-two safety computer platform;

[0029] The two data processing modules of the four data processing modules that are not used to construct the primary two-out-of-two safety computer platform are used to construct the backup two-out-of-two safety computer platform.

[0030] In some embodiments, the two data processing modules of the four data processing modules satisfying the operation environment and the operation state are used to construct the main two-out-of-two safety computer platform, including:

[0031] The IP addresses of the two data processing modules used to construct the main two-out-of-two safety computer platform are set through a communication bus;

[0032] Based on the IP addresses of the two data processing modules, a VLAN virtual private network is established to synchronize the CPU data in the two data processing modules and to realize communication isolation with the CPUs outside the two data processing modules.

[0033] In a third aspect, the present disclosure provides a computer readable storage medium having a cloud platform architecture safety computer platform construction program stored thereon, and the cloud platform architecture safety computer platform construction program, when executed by a processor, implements the cloud platform architecture safety computer platform construction method of the first aspect.

[0034] In a fourth aspect, the present disclosure provides an electronic device including a memory, a processor, and a cloud platform architecture safety computer platform construction program stored on the memory and executable on the processor, and the cloud platform architecture safety computer platform construction program, when executed by the processor, implements the cloud platform architecture safety computer platform construction method of the first aspect.

[0035] The cloud platform architecture for maintaining functional safety provided by the embodiments of the present disclosure is applied to a train control system, and the cloud platform architecture comprises N processors and N functional circuits; one processor is connected with one functional circuit to form one data processing module; N is greater than or equal to 4; a safety management machine is connected with the N processors and the N functional circuits through an internal Ethernet; the safety management machine is used to acquire running environments and running states of the N processors and the N functional circuits, and construct a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform based on the running environments and the running states of the N processors and the N functional circuits; an external execution layer device is connected with the safety management machine, the N processors and the N functional circuits through an output Ethernet; the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the safety management machine are used to process data input by the external execution layer device and issue execution instructions to the external execution layer device. In the present application, the running environments and the running states of the N processors and the N functional circuits in the cloud platform are monitored by the safety management machine, and the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform are constructed based on the running environments and the running states of the N processors and the N functional circuits, so that the cloud platform architecture has a two-out-of-two safety computer platform in real time, which is used for the train control system to realize functional safety application of a SIL-4 safety level.

[0036] Additional aspects and advantages of the present disclosure will be in part apparent and in part pointed out hereinafter. BRIEF DESCRIPTION OF DRAWINGS

[0037] Figure 1 is a cloud platform architecture structure diagram for maintaining functional safety according to an exemplary embodiment;

[0038] Figure 2 is a safety computer platform construction method flow chart in a cloud platform architecture according to an exemplary embodiment;

[0039] Figure 3 is a two-out-of-two safety computer platform construction flow chart according to an exemplary embodiment. DETAILED DESCRIPTION

[0040] The embodiments of the present disclosure are described in detail below, and examples of the embodiments are shown in the drawings, in which the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below are exemplary and are intended to explain the present disclosure, and cannot be understood as a limitation of the present disclosure.

[0041] In the field of railway, the safety computer platform is the core equipment of the train control system, which ensures the safe operation of the train control system. The electronic and electrical equipment of the train control system needs to meet certain safety standards, but the single system cannot meet it, and must use these safety architectures. In this regard, the cloud platform, as a new computing and network technology, can use a set of platform to undertake multiple applications, can highly integrate the train control system, reduce the number of train control system equipment, and reduce the construction and maintenance cost. However, the existing cloud platform generally cannot provide a safety computer platform architecture, cannot achieve a safety level of SIL-4, and cannot be used for train control systems.

[0042] In view of the above, the present disclosure provides a cloud platform architecture for maintaining functional safety. Figure 1 is a schematic diagram of a cloud platform architecture for maintaining functional safety according to an exemplary embodiment. As shown in Figure 1 The cloud platform architecture for maintaining functional safety is applied to a train control system, and the cloud platform architecture includes:

[0043] N processors and N functional circuits; wherein one processor is connected with one functional circuit to form one data processing module; wherein N≥4;

[0044] A safety management machine 01 is connected with the N processors and the N functional circuits through an internal Ethernet; wherein the safety management machine is used to acquire the running environment and the running state of the N processors and the N functional circuits, and to construct a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform based on the running environment and the running state of the N processors and the N functional circuits;

[0045] An external execution layer device 05 is connected with the safety management machine, the N processors and the N functional circuits through an output Ethernet 04; wherein the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the safety management machine are used to process data input by the external execution layer device, and to issue execution instructions to the external execution layer device.

[0046] In the present exemplary embodiment, the running environment includes the power supply voltage and the clock accuracy of the N processors and the N functional circuits, and other running environment information.

[0047] The running state includes the running state information of the N processors and the N functional circuits, such as CPU core temperature, memory usage and self-checking state, etc.

[0048] In the example embodiment, the security management machine can monitor the running environment and state of the N processors and N function circuits in real time, so as to select the processors and function circuits suitable for constructing the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform among the N processors and N function circuits. Meanwhile, if any processor and function circuit in the primary two-out-of-two safety computer platform has an abnormal running state, the backup two-out-of-two safety computer platform can be upgraded to the primary two-out-of-two safety computer platform, and a new backup two-out-of-two safety computer platform is reconstructed based on the running environment and state of the N processors and N function circuits, so that the cloud platform architecture has a real-time two-out-of-two safety computer platform, which is used for the train control system to realize the functional safety application of the SIL-4 safety level.

[0049] In the example embodiment, the supervision of the security management machine on each CPU and function circuit is periodic. Once a fault such as a self-check failure, temperature exceeding the threshold, or voltage fluctuation exceeding the threshold of a certain CPU and function circuit is found, the security management machine can perform a shutdown or restart process on the corresponding CPU according to the data.

[0050] The cloud platform architecture for maintaining functional safety provided by the example embodiment of the disclosure is applied to a train control system, and the cloud platform architecture comprises: N processors and N function circuits; wherein one processor is connected with one function circuit to form one data processing module; wherein N≥4; a security management machine connected with the N processors and N function circuits through an internal Ethernet; wherein the security management machine is configured to acquire the running environment and state of the N processors and N function circuits, and construct a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform based on the running environment and state of the N processors and N function circuits; and an external execution layer device connected with the security management machine, N processors and N function circuits through an output Ethernet; wherein the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the security management machine are configured to process data input by the external execution layer device and issue execution instructions to the external execution layer device. In the application, the security management machine monitors the running environment and state of the N processors and N function circuits in the cloud platform, and constructs the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform based on the running environment and state of the N processors and N function circuits, so that the cloud platform architecture has a real-time two-out-of-two safety computer platform, which is used for the train control system to realize the functional safety application of the SIL-4 safety level.

[0051] In some embodiments, the construction of the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform based on the running environment and state of the N processors and N function circuits comprises:

[0052] determining four data processing modules in which both the running environment and the running state meet the running standard among the N processors and the N functional circuits;

[0053] constructing the primary two-out-of-two secure computer platform by any two data processing modules in which both the running environment and the running state meet the running standard;

[0054] constructing the standby two-out-of-two secure computer platform by the two data processing modules in which both the running environment and the running state meet the running standard among the four data processing modules.

[0055] In the present exemplary embodiment, when the four data processing modules in which both the running environment and the running state meet the running standard are determined among the N processors and the N functional circuits, the four processors and the corresponding functional circuits in which both the running environment and the running state meet the running standard can be selected at random or in sequence number order among the N processors and the N functional circuits, to construct the primary two-out-of-two secure computer platform and the standby two-out-of-two secure computer platform. The primary two-out-of-two secure computer platform and the standby two-out-of-two secure computer platform are both constructed by two processors and functional circuits in which both the running environment and the running state meet the running standard. As shown in the figure, the four processors and the corresponding functional circuits in which both the running environment and the running state meet the running standard are sequentially determined from sequence number 1 to N. For example, the running environment and the running state of CPU and functional circuit 1, CPU and functional circuit 2, CPU and functional circuit 4, and CPU and functional circuit 5 meet the running standard, and then CPU and functional circuit 1, CPU and functional circuit 2, CPU and functional circuit 4, and CPU and functional circuit 5 are selected to construct the primary two-out-of-two secure computer platform and the standby two-out-of-two secure computer platform.

[0056] In some embodiments, the construction of the primary two-out-of-two secure computer platform by any two data processing modules in which both the running environment and the running state meet the running standard includes:

[0057] setting the IP addresses of the two data processing modules used to construct the primary two-out-of-two secure computer platform through a communication bus;

[0058] establishing a VLAN virtual private network based on the IP addresses of the two data processing modules, so that the CPU data in the two data processing modules are synchronized, and the communication between the two data processing modules and the CPUs outside the two data processing modules is isolated.

[0059] In the example embodiment, the communication bus can be a low-speed communication bus with a lower communication rate relative to an Ethernet communication rate. The low-speed communication bus undertakes the configuration functions of the safety management machine to the respective CPU machine function circuits, such as configuration of IP addresses, master and standby system working modes, etc. The communication bus can generally use a CAN bus, a CAN FD bus, or an RS485 bus, etc. which is easy to network and supports a safety communication protocol. When the communication bus uses a CAN bus, a CAN FD bus, or an RS485 bus, a bus topology can be used to avoid single node failure and cause the entire network to be paralyzed.

[0060] In the example embodiment, in order to realize communication isolation of the two processors and corresponding function circuits in the master two-out-of-two safety computer platform from other processors and corresponding function circuits, and to reduce communication interference of the other processors and corresponding function circuits, the safety management machine can establish a VLAN virtual private network based on the IP addresses of the two data processing modules in the master two-out-of-two safety computer platform, so that the CPU data in the two data processing modules are synchronized, and communication isolation is realized with the CPUs outside the two data processing modules. Similarly, in order to realize communication isolation of the two processors and corresponding function circuits in the standby two-out-of-two safety computer platform from other processors and corresponding function circuits, and to reduce communication interference of the other processors and corresponding function circuits, the safety management machine can establish a VLAN virtual private network based on the IP addresses of the two data processing modules in the standby two-out-of-two safety computer platform, so that the CPU data in the two data processing modules are synchronized, and communication isolation is realized with the CPUs outside the two data processing modules.

[0061] In some embodiments, as shown in Figure 1 The internal Ethernet includes a first Ethernet 02 and a second Ethernet 03;

[0062] The safety management machine 01 is connected with the N processors and N function circuits through the first Ethernet 02. Before the master two-out-of-two safety computer platform and the standby two-out-of-two safety computer platform are constructed, the safety management machine communicates with the N processors and N function circuits through the first Ethernet, and determines four data processing modules for constructing the master two-out-of-two safety computer platform and the standby two-out-of-two safety computer platform.

[0063] The safety management machine 01 is connected with the N processors and N function circuits through the second Ethernet 03. After the four data processing modules for constructing the master two-out-of-two safety computer platform and the standby two-out-of-two safety computer platform are determined, the safety management machine determines the four data processing modules to the master two-out-of-two safety computer platform and the standby two-out-of-two safety computer platform through the second Ethernet.

[0064] In the present exemplary embodiment, as shown in Figure 1 The safety management machine can be connected with the N processors and the N function circuits through the first Ethernet and the second Ethernet. Before the primary and standby two-out-of-two safety computer platforms are constructed, the safety management machine communicates with the N processors and the N function circuits through the first Ethernet. After the four data processing modules for constructing the primary and standby two-out-of-two safety computer platforms are determined, the safety management machine determines the four data processing modules to the primary and standby two-out-of-two safety computer platforms through the second Ethernet and communicates with the primary and standby two-out-of-two safety computer platforms.

[0065] In some embodiments, after the primary and standby two-out-of-two safety computer platforms are determined, the safety management machine monitors the output data of the primary two-out-of-two safety computer platform through the output Ethernet.

[0066] Based on the data analysis of the output data, the running state of the primary two-out-of-two safety computer platform is determined, and the primary and standby system switching is performed when the primary two-out-of-two safety computer platform has a running problem.

[0067] In the present exemplary embodiment, the output Ethernet is used for the safety management machine to receive the input data of the external execution layer device and send the control data to the Ethernet device such as a switch of the external execution layer device after the cloud platform internally constructs the safety computer platform. The safety management machine can monitor the output data of the primary and standby two-out-of-two safety computer platforms through the output Ethernet and monitor the data. When the data check error, output time error, etc. of the primary two-out-of-two safety computer platform are found, the primary two-out-of-two safety computer platform output can be closed, and the primary and standby system switching of the safety computer platform, etc. is guided. For example, the standby two-out-of-two safety computer platform is upgraded to the primary two-out-of-two safety computer platform.

[0068] In the present exemplary embodiment, the first Ethernet, the second Ethernet and the output Ethernet, etc. can be three independent physical devices or the same physical device divided by logic. In order to improve the availability and avoid the whole network paralysis caused by the single device failure, three independent physical devices can be used in the present application.

[0069] The present disclosure provides a secure computer platform construction method in a cloud platform architecture. The cloud platform architecture comprises N processors and N functional circuits. One processor is connected with one functional circuit to form one data processing module. N is greater than or equal to 4. A security management machine is connected with the N processors and the N functional circuits through an internal Ethernet. An external execution layer device is connected with the security management machine, the N processors and the N functional circuits through an output Ethernet. Figure 2 FIG. 1 is a flow chart of a secure computer platform construction method in a cloud platform architecture according to an example embodiment. As shown in FIG. 1, the method comprises the following steps. Figure 2

[0070] Step 20: obtaining running environment and running state of the N processors and the N functional circuits through the security management machine.

[0071] Step 21: constructing a primary two-out-of-two secure computer platform and a backup two-out-of-two secure computer platform based on the running environment and the running state of the N processors and the N functional circuits. The primary two-out-of-two secure computer platform and the backup two-out-of-two secure computer platform constructed by the security management machine are used for data processing of data input by the external execution layer device and issuing execution instructions to the external execution layer device.

[0072] In the example embodiment, the running environment includes running environment information such as power supply voltage and clock accuracy of the N processors and the N functional circuits.

[0073] The running state includes running state information of the N processors and the N functional circuits, such as CPU core temperature, memory usage and self-checking state.

[0074] In the example embodiment, the security management machine can monitor the running environment and the running state of the N processors and the N functional circuits in real time, so as to select the processors and the functional circuits suitable for constructing the primary two-out-of-two secure computer platform and the backup two-out-of-two secure computer platform from the N processors and the N functional circuits. Meanwhile, if any processor and functional circuit in the primary two-out-of-two secure computer platform has abnormal running state, the backup two-out-of-two secure computer platform can be upgraded to the primary two-out-of-two secure computer platform, and a new backup two-out-of-two secure computer platform is constructed based on the running environment and the running state of the N processors and the N functional circuits, so that the cloud platform architecture has a two-out-of-two secure computer platform in real time, which is used for train control system to realize SIL-4 safety level functional safety application.

[0075] ​In the present exemplary embodiment, the supervision of the security management machine on each CPU and functional circuit is periodic. Once a fault is found, such as a self-check failure, temperature exceeding the threshold, or voltage fluctuation exceeding the threshold, the security management machine can perform a shutdown or restart process on the corresponding CPU according to the data.

[0076] The cloud platform architecture provided by the embodiments of the present disclosure provides a method for constructing a secure computer platform. The security management machine acquires the running environment and running state of the N processors and N functional circuits. Based on the running environment and running state of the N processors and N functional circuits, a primary two-out-of-two secure computer platform and a backup two-out-of-two secure computer platform are constructed. The primary two-out-of-two secure computer platform and the backup two-out-of-two secure computer platform constructed by the security management machine are used to process data input by the external execution layer device and issue execution instructions to the external execution layer device. In the present application, the security management machine monitors the running environment and running state of the N processors and N functional circuits in the cloud platform, and constructs a primary two-out-of-two secure computer platform and a backup two-out-of-two secure computer platform based on the running environment and running state of the N processors and N functional circuits. This makes the cloud platform architecture have a real-time two-out-of-two secure computer platform, which is used in a train control system to achieve a SIL-4 safety level functional safety application.

[0077] In some embodiments, the primary two-out-of-two secure computer platform and the backup two-out-of-two secure computer platform are constructed based on the running environment and running state of the N processors and N functional circuits, including:

[0078] Four data processing modules are determined in the N processors and N functional circuits, whose running environment and running state meet the running standard;

[0079] Any two data processing modules of the four data processing modules whose running environment and running state meet the running standard are used to construct the primary two-out-of-two secure computer platform;

[0080] The two data processing modules of the four data processing modules that are not used to construct the primary two-out-of-two secure computer platform are used to construct the backup two-out-of-two secure computer platform.

[0081] In the present exemplary embodiment, when four data processing modules are determined in the N processors and N functional circuits, the running environment and the running state of which meet the running standard, any of the four processors and the corresponding functional circuits, the running environment and the running state of which meet the running standard, can be selected or can be selected in sequence number order, to construct the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform. The primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform are both constructed by two processors and functional circuits, the running environment and the running state of which meet the running standard. As shown in the figure, from sequence number 1 to N, four processors and the corresponding functional circuits, the running environment and the running state of which meet the running standard, are sequentially determined. For example, the running environment and the running state of CPU and functional circuit 1, CPU and functional circuit 2, CPU and functional circuit 4, and CPU and functional circuit 5 all meet the running standard, so CPU and functional circuit 1, CPU and functional circuit 2, CPU and functional circuit 4, and CPU and functional circuit 5 are selected to construct the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform.

[0082] In some embodiments, the construction of the primary two-out-of-two safety computer platform by any two of the four data processing modules, the running environment and the running state of which meet the running standard, comprises:

[0083] The IP addresses of the two data processing modules used to construct the primary two-out-of-two safety computer platform are set through a communication bus;

[0084] Based on the IP addresses of the two data processing modules, a VLAN virtual private network is established to synchronize the CPU data in the two data processing modules and to realize communication isolation with the CPUs outside the two data processing modules.

[0085] In the present exemplary embodiment, the communication bus can be a low-speed communication bus with a relatively low Ethernet communication rate. The low-speed communication bus undertakes the configuration functions of the safety management machine to each CPU machine functional circuit, such as configuring IP addresses, primary and backup system working modes, etc. The communication bus can generally use CAN bus, CAN FD bus or RS485, etc. communication bus which is easy to network and supports safety communication protocol. When the communication bus uses CAN bus, CAN FD bus or RS485 bus, bus topology can be used to avoid single node failure and cause the entire network to be paralyzed.

[0086] In the present exemplary embodiment, in order to realize the communication isolation of the two processors and the corresponding functional circuits in the primary two-out-of-two safety computer platform and other processors and the corresponding functional circuits, and to reduce the communication interference of the other processors and the corresponding functional circuits, the security management machine can establish a VLAN virtual private network based on the IP addresses of the two data processing modules in the primary two-out-of-two safety computer platform, so that the CPU data in the two data processing modules are synchronized, and the communication isolation with the CPUs outside the two data processing modules is realized. Similarly, in order to realize the communication isolation of the two processors and the corresponding functional circuits in the standby two-out-of-two safety computer platform and other processors and the corresponding functional circuits, and to reduce the communication interference of the other processors and the corresponding functional circuits, the security management machine can establish a VLAN virtual private network based on the IP addresses of the two data processing modules in the standby two-out-of-two safety computer platform, so that the CPU data in the two data processing modules are synchronized, and the communication isolation with the CPUs outside the two data processing modules is realized.

[0087] Figure 3 is a two-by-two two-out-of-two safety computer platform construction flowchart according to an exemplary embodiment. As shown in Figure 3 , the two-by-two two-out-of-two safety computer platform construction flowchart includes:

[0088] Step 30, start;

[0089] Step 31, the security management machine obtains the self-checking information of each processor and functional circuit through the low-speed communication bus;

[0090] Step 32, the security management machine obtains the voltage, temperature and clock accuracy information of each processor and functional circuit through the low-speed communication bus;

[0091] Step 33, the security management machine selects two CPUs and functional circuits to form a two-out-of-two architecture;

[0092] Step 34, the security management machine establishes a VLAN on the first Ethernet network, so that the A system and the B system can synchronize data;

[0093] Step 35, the security management machine selects another two CPUs and functional circuits to form a B system;

[0094] Step 36, the security management machine sets up a VLAN on the second Ethernet network, and the two selected CPUs start to perform periodic data synchronization and are set as the A system;

[0095] Step 37, the security management machine issues IP addresses and other configuration information to the two CPUs through the low-speed communication bus;

[0096] Step 38, since A system first completes self-checking, A system is set as master, B system is set as backup, B system obtains data of A system through first Ethernet;

[0097] Step 39, A system and B system run application software at the same time, wherein A system outputs to output Ethernet, and B system does not output;

[0098] Step 40, safety management machine supervises output of A system through output Ethernet, and synchronously supervises states of A system and B system;

[0099] Step 41, end.

[0100] Wherein, safety communication protocol should be used when data is synchronized between two systems and when it is outputted to outside, and safety management machine checks data sent to management Ethernet and output Ethernet to ensure data correctness in communication process.

[0101] Meanwhile, safety management machine supervises running period of A system and B system composed of cloud platform. Safety management machine sends a synchronization signal, and A system and B system start running according to the period. When A system and B system end the period, safety management machine checks running time of two systems to ensure that time is consistent and large running deviation does not occur. Wherein, clock synchronization can be based on IEEE1588, and special hardware is not needed.

[0102] In running process, if safety management machine finds that A system is abnormal in self-checking, or working environment temperature, voltage and the like exceed set threshold value through low-speed communication bus, safety management machine controls A system to reduce, B system is upgraded to master, and starts output. A system is reset, two two-out-of-two CPUs and functional circuits are disassembled into single machines. CPU selects two normal CPUs and functional circuits again, two-out-of-two is formed, becomes new A system, and new A system and B system form two-by-two architecture, wherein B system is master, and new A system is backup. B system sends data to be synchronized to new A system through first Ethernet, and new A system and B system realize data synchronization.

[0103] If A system is not abnormal, and B system is abnormal, B system is disassembled into single machine, and is reset. Safety management machine finds new CPU and functional circuit to form new two-out-of-two computer C system, still A system is master, and C system replaces B system to become backup, and C system and A system realize synchronization. Here, abnormality of B system includes voltage, temperature, self-checking abnormality, and also includes abnormality that safety management machine finds that B system and A system cannot be synchronized or clock deviation is large.

[0104] In addition to switching from one system to another after discovering an abnormality, the security management machine can periodically switch systems according to the running time. For example, from 0 to N periods, system A is the master system and system B is the slave system. At the Nth period, the security management machine controls system A to degrade to a standby system and system B to upgrade to a master system. After M periods, the systems are switched again so that system A is the master system and system B is the slave system, and so on.

[0105] The present disclosure provides a computer readable storage medium, having stored thereon a secure computer platform construction program in a cloud platform architecture, which, when executed by a processor, implements the secure computer platform construction method in a cloud platform architecture of any of the above embodiments.

[0106] The present disclosure provides an electronic device, comprising a memory, a processor, and a secure computer platform construction program in a cloud platform architecture stored on the memory and executable on the processor, wherein the processor implements the secure computer platform construction method in a cloud platform architecture of any of the above embodiments when executing the secure computer platform construction program in a cloud platform architecture.

[0107] It should be noted that the logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a list of executable instructions for implementing logic functions, which can be embodied in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, processor- based system, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions, or in conjunction with which the instructions can be executed. For purposes of this specification, a "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of the computer-readable medium include the following: an electrical connection having one or more wires (electrical apparatus), a portable computer diskette (magnetic apparatus), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber (optical apparatus), and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium can even be paper or another suitable medium upon which the program can be printed, as the program can be electronically captured, for example, by the optical scanner of a device or appropriate circuitry associated with the other suitable medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and stored in a computer memory in an electronic form.

[0108] It should be understood that portions of the present disclosure can be realized with hardware, software, firmware or a combination thereof. In the foregoing embodiments, a plurality of steps or methods can be realized with software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if realized with hardware, and as in another embodiment, it can be realized with any one or a combination of the following technologies known in the art: discrete logic circuit having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.

[0109] In the description of the present disclosure, the description of the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present disclosure. In the present description, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0110] In the description of the present disclosure, it should be understood that the terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise", "axial", "radial", "circumferential" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present disclosure and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present disclosure.

[0111] In addition, the terms "first", "second", and the like used in the embodiments of the present disclosure are only for the purpose of description and can not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated in the embodiments. Therefore, the features defined with "first", "second" and the like in the embodiments of the present disclosure can explicitly or implicitly indicate that the embodiments include at least one of the features. In the description of the present disclosure, the meaning of the word "plurality" is at least two or two or more, such as two, three, four, etc., unless otherwise specifically limited in the embodiments.

[0112] In the present disclosure, unless otherwise explicitly specified and limited in the embodiments, the terms "mounting", "connecting", "connecting" and "fixing" and the like appearing in the embodiments should be understood in a broad sense, for example, the connection can be a fixed connection, or a detachable connection, or integrated, which can be understood, or mechanical connection, electrical connection, etc. Of course, it can also be directly connected, or indirectly connected through an intermediate medium, or the internal communication of two elements, or the interaction relationship of two elements. For those skilled in the art, the specific meaning of the above terms in the present disclosure can be understood according to the specific implementation situation.

[0113] In the present disclosure, unless otherwise explicitly specified and limited, the first feature is "on" or "under" the second feature. The first and second features can be in direct contact, or the first and second features can be indirectly in contact through an intermediate medium. Moreover, the first feature can be above, above and above the second feature, or only indicate that the first feature is higher than the second feature in horizontal height. The first feature can be below, below and below the second feature, or only indicate that the first feature is lower than the second feature in horizontal height.

[0114] Although the embodiments of the present disclosure have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present disclosure, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A cloud platform architecture for maintaining functional safety, characterized in that, The cloud platform architecture is applied to a train control system and comprises the following: N processors and N functional circuits; one processor is connected with one functional circuit to form one data processing module; N≥4; a security management machine connected with the N processors and the N functional circuits through an internal Ethernet; the security management machine is used to acquire the running environment and the running state of the N processors and the N functional circuits, and to construct a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform based on the running environment and the running state of the N processors and the N functional circuits; an external execution layer device connected with the security management machine, the N processors and the N functional circuits through an output Ethernet; the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the security management machine are used to process data input by the external execution layer device and to issue execution instructions to the external execution layer device.

2. The cloud platform architecture for maintaining functional safety according to claim 1, wherein, The primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform are constructed based on the running environment and the running state of the N processors and the N functional circuits, comprising: four data processing modules with the running environment and the running state meeting the running standard are determined from the N processors and the N functional circuits; any two data processing modules of the four data processing modules with the running environment and the running state meeting the running standard are used to construct the primary two-out-of-two safety computer platform; two data processing modules of the four data processing modules which are not used to construct the primary two-out-of-two safety computer platform are used to construct the backup two-out-of-two safety computer platform.

3. The cloud platform architecture for maintaining functional safety according to claim 2, wherein, The primary two-out-of-two safety computer platform is constructed by any two data processing modules of the four data processing modules with the running environment and the running state meeting the running standard, comprising: IP addresses of the two data processing modules used to construct the primary two-out-of-two safety computer platform are set through a communication bus; a VLAN virtual private network is established based on the IP addresses of the two data processing modules to synchronize CPU data in the two data processing modules and to realize communication isolation with CPUs outside the two data processing modules.

4. The cloud platform architecture for maintaining functional safety according to claim 2, wherein, The internal Ethernet comprises a first Ethernet and a second Ethernet; the security management machine is connected with the N processors and the N functional circuits through the first Ethernet; before the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform are constructed, the security management machine communicates with the N processors and the N functional circuits through the first Ethernet to determine four data processing modules used to construct the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform; The security management machine is connected with the N processors and the N functional circuits through the second Ethernet; wherein, after determining four data processing modules for constructing the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform, the security management machine determines the four data processing modules to the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform through the second Ethernet.

5. The cloud platform architecture for maintaining functional safety according to claim 4, wherein, After determining the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform, the security management machine monitors the output data of the primary two-out-of-two safety computer platform through the output Ethernet; and Based on the data analysis of the output data, the running state of the primary two-out-of-two safety computer platform is determined, and the primary and backup system switching is performed when the primary two-out-of-two safety computer platform has a running problem.

6. A secure computer platform construction method in a cloud platform architecture, characterized by, The cloud platform architecture comprises: N processors and N functional circuits; wherein, one processor is connected with one functional circuit to form one data processing module; wherein, the N≥4; a security management machine is connected with the N processors and the N functional circuits through an internal Ethernet; an external execution layer device is connected with the security management machine, the N processors and the N functional circuits through an output Ethernet; The method comprises: acquiring, by the security management machine, the running environment and the running state of the N processors and the N functional circuits; constructing a primary two-out-of-two safety computer platform and a backup two-out-of-two safety computer platform based on the running environment and the running state of the N processors and the N functional circuits; wherein, the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform constructed by the security management machine are used for data processing on the data input by the external execution layer device, and issuing an execution instruction to the external execution layer device.

7. The method of claim 6, wherein the cloud platform architecture is constructed by, The method for constructing the primary two-out-of-two safety computer platform and the backup two-out-of-two safety computer platform based on the running environment and the running state of the N processors and the N functional circuits comprises: determining four data processing modules in the N processors and the N functional circuits, wherein the running environment and the running state of the four data processing modules meet the running standard; constructing the primary two-out-of-two safety computer platform by using any two data processing modules of the four data processing modules, wherein the running environment and the running state of the two data processing modules meet the running standard; constructing the backup two-out-of-two safety computer platform by using the other two data processing modules of the four data processing modules, wherein the running environment and the running state of the two data processing modules do not meet the running standard.

8. The method of claim 7, wherein the cloud platform architecture is constructed by, The method for constructing the primary two-out-of-two safety computer platform by using any two data processing modules of the four data processing modules, wherein the running environment and the running state of the two data processing modules meet the running standard, comprises: setting the IP addresses of the two data processing modules for constructing the primary two-out-of-two safety computer platform through a communication bus; based on the IP addresses of the two data processing modules, establishing a VLAN virtual private network to synchronize the CPU data in the two data processing modules and realize communication isolation with the CPUs outside the two data processing modules.

9. A computer-readable storage medium, characterized in that, A computer readable storage medium having stored thereon a cloud platform architecture security computer platform construction program which, when executed by a processor, implements the cloud platform architecture security computer platform construction method of any one of claims 1-5.

10. An electronic device, comprising: A computer readable storage medium having stored thereon a cloud platform architecture security computer platform construction program which, when executed by a processor, implements the cloud platform architecture security computer platform construction method of any one of claims 1-5.

Citation Information

Patent Citations

  • Security computer platform in the field of railway signals

    CN110361979A

  • Safety computer platform of railway signal control system

    CN117724325A

  • Ground railway signal cloud platform with redundant structure

    CN117880313A

  • Secure computer architectures, systems, and applications

    US20140096226A1

  • Synchronizing method for two out of two-by-two system and computer device

    WO2019011063A1