Time synchronization method based on TSN network
By constructing a multi-clock domain redundancy architecture and the 802.1AS protocol, the problem of insufficient reliability of traditional TSN in aviation/aerospace networks is solved, high availability time synchronization is achieved, costs are reduced and system availability is improved.
Patent Information
- Application Number
- CN202511227328.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-14
AI Technical Summary
Traditional TSN single-clock domain architecture is not reliable enough in aviation/aerospace multi-redundant networks and cannot meet the 99.9999% availability requirement of avionics. In addition, traditional avionics networks are not directly compatible with TSN, resulting in high hardware costs and increased cabling complexity.
A multi-clock-domain redundant architecture is constructed, adopting the 802.1AS protocol. Through dynamic switching mechanism and tolerance arbitration strategy, high-availability time synchronization without service interruption in fault scenarios is achieved. Time synchronization in aviation/aerospace networks is realized by utilizing the redundant architecture and clock domain switching mechanism.
While ensuring the time synchronization accuracy of all network nodes, it significantly improves the availability of system time synchronization and reduces the cost of building a high-bandwidth, high-availability time synchronization system, making it suitable for safety-critical application fields such as aviation and aerospace.
Smart Images

Figure CN120956375A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a time synchronization method based on a TSN network, belonging to the field of safety-critical distributed systems. Background Technology
[0002] In the field of avionics data networks, modern avionics systems impose stringent requirements on network communication: flight control commands and sensor data must meet strong real-time constraints with end-to-end latency ≤1 millisecond and jitter ≤1 microsecond; high-resolution video streams require 1-10 Gbps bandwidth support; and critical services such as navigation commands require a bit error rate of less than 10⁻¹². Traditional avionics networks (such as AFDX or Fibre Channel FC based on ARINC664 Part 7) achieve multi-level redundancy through virtual link static routing, dual-redundant physical links, and hot backup nodes, but still have significant limitations—their time synchronization mechanism relies on a centralized global master clock. If the master clock or synchronization path fails, the system requires hundreds of microseconds of switching time, making it difficult to meet the 99.9999% availability requirement of avionics. Meanwhile, while existing TSN (Time-Sensitive Networking) technology achieves microsecond-level synchronization in industrial applications through the IEEE 802.1AS protocol, its single-clock domain architecture carries a single point of failure risk and lacks the external system time synchronization capabilities required for avionics scenarios. More importantly, TSN has never been applied in the aviation field before, and traditional avionics networks cannot be directly compatible with TSN's open ecosystem, resulting in high hardware costs (30%-50% higher than TSN solutions) and a 40% increase in cabling complexity. This technological vacuum makes building a highly available time synchronization system that combines deterministic communication, multi-level fault tolerance, and low-cost scalability the core bottleneck for avionics upgrades. Summary of the Invention
[0003] The purpose of this invention is to provide a time synchronization system based on TSN network, which can solve the problem of insufficient reliability of traditional TSN single clock domain in aviation / aerospace multi-redundant networks. By constructing a multi-clock domain redundancy architecture, dynamic switching mechanism and tolerance arbitration strategy, it can achieve high-availability time synchronization without service interruption in fault scenarios.
[0004] To solve the above-mentioned technical problems, the present invention is implemented using the following technical solution.
[0005] On one hand, the present invention provides a time synchronization method based on a TSN network, applied to a time synchronization system, the method comprising: Based on the quantitative indicators of the time synchronization system, determine the redundancy architecture and clock domain size of the time synchronization system; Based on the aforementioned redundant architecture and clock domain size, one clock domain is statically configured as the primary clock domain, and the remaining clock domains are configured as backup clock domains. Obtain the system absolute time of each node in the TSN network in each clock domain, and calculate the difference between the system absolute times of any two clock domains. If the difference exceeds the preset time synchronization error window, mark the current clock domain pair as out of tolerance. Collect the time synchronization status and out-of-range conditions reported by each node in each clock domain; The decision to switch clock domains is made based on the clock domain time synchronization status and the out-of-tolerance situation. If the decision is to switch clock domains, a clock domain switching command is broadcast to the time synchronization system. Upon receiving the clock domain switching command, all control nodes stop the correction of the original master clock domain, select a target clock domain from the backup clock domains according to the preset priority order, and activate the target clock domain as the new master clock domain. The master clock node in the new master clock domain is connected to an external synchronization signal to calibrate the local clock, and the time synchronization of all nodes in the time synchronization system is completed through a time synchronization protocol.
[0006] In conjunction with the first aspect, further, determining the redundancy architecture and clock domain size of the time synchronization system includes: Based on the reliability and availability indicators of the time synchronization system for data communication and time synchronization functions, as well as the required network margin, the corresponding redundant network topology and the number of clock domains are determined, and a master clock node is assigned to each clock domain. Starting from the master clock node, a clock tree structure is planned according to the time synchronization protocol, and the port roles of each node in the clock tree are statically assigned.
[0007] In conjunction with the first aspect, the static allocation of port roles for each node in the clock tree must further satisfy the following constraints: a. Each clock domain has only one node as the master clock node; b. The same node can be the master clock node of at most one clock domain across multiple clock domains; c. Each clock domain covers all nodes in the time synchronization system, and each node in the same clock domain calibrates its local clock through a time synchronization protocol; d. Each clock domain has a time synchronization processing entity to handle the time synchronization behavior of the current clock domain; e. At any given time, there is one and only one clock domain as the master clock domain; f. In each node, the local clock of the current node is calibrated only by the time synchronization processing entity of the master clock domain.
[0008] In conjunction with the first aspect, the marking process for the clock domain pairs further includes: Within each node, using the time synchronization protocol, the time synchronization processing entity configured for each clock domain monitors and updates the time synchronization status of the current node in the specified clock domain, and calculates the system absolute time corresponding to each clock domain. Each node is equipped with a time synchronization error window and calculates the difference in absolute system time between clock domains; The difference is compared with the time synchronization error window to obtain the deviation result; wherein, when the difference is not greater than the time synchronization error window, the corresponding clock domain pair is marked as normal, and when the difference is greater than the time synchronization error window, the corresponding clock domain pair is marked as out of tolerance. Based on the marking results of all clock domains, determine the faulty clock domain and the clock domain switching scheme.
[0009] In conjunction with the first aspect, further, the determination of the fault clock domain and the clock domain switching scheme includes: The network time management unit within the time synchronization system receives and processes the time synchronization status and out-of-tolerance status of faulty clock domains reported by each node. Based on the received time synchronization status and the out-of-tolerance status of the faulty clock domain, verify whether the clock domain switching scheme is met. If it is met, the time synchronization management unit triggers the clock domain decision switching and broadcasts the clock domain switching command to all nodes in the time synchronization system. Upon receiving the clock domain switching command, all nodes are controlled to stop the correction of the original master clock domain and activate the new master clock domain within the same synchronization cycle.
[0010] In conjunction with the first aspect, further, the triggering of the clock domain decision switch and the broadcasting of the clock domain switch command to all nodes within the time synchronization system includes: By statically configuring one of the network time management nodes as the primary time management node and the rest as backup time management nodes; Each time management node receives clock domain status information from all nodes in the time synchronization system and performs clock domain fault judgment and decision calculation. Each time management node exchanges its decision calculation results. If the decision calculation results are consistent, the master time management node issues a clock domain switching command to the time synchronization system. If the decision calculation results are inconsistent, the clock domain switching command is issued according to the decision calculation results consistent by the majority of time management nodes. If the master time management node itself makes a decision error or fails, a new master time management node is elected from the backup time management nodes according to a predetermined election strategy to issue the switching command.
[0011] In conjunction with the first aspect, the node types in the time synchronization system further include switch nodes and terminal nodes; The network time management unit node can reside on any switch node or terminal node.
[0012] In conjunction with the first aspect, the triggering of the clock domain decision switching must further satisfy the following conditions: (1) Switch nodes belonging to the master clock domain cannot complete the time synchronization process or the synchronization accuracy is out of tolerance; (2) Terminal nodes with security-critical mission nodes cannot complete the time synchronization process or the synchronization accuracy is out of tolerance; (3) Multiple leaf nodes belonging to the master clock domain cannot complete the time synchronization process; (4) After all clock domains are synchronized, the master clock node, which is the backup clock domain, detects that the time of the master clock domain is out of sync with the time input from the external system.
[0013] In conjunction with the first aspect, it further includes: Before any clock domain is synchronized, each node is prohibited from initiating the transmission of service data; If all clock domains fail, force all nodes to shut down service data transmission.
[0014] In conjunction with the first aspect, further, the master clock node of the new master clock domain connects to an external synchronization signal to calibrate the local clock, including: The master clock node of each clock domain can obtain clock synchronization signals from external systems; The master clock node, which assumes the function of the master clock domain, uses the clock synchronization signal to write the external time into the local clock to obtain the calibrated time, and then spreads the calibrated time to all nodes in the TSN network through the time synchronization protocol. The master clock node, which does not assume the function of the master clock domain, uses the clock synchronization signal input from the external system to verify the local time obtained through the time synchronization protocol. If the deviation between the local time and the clock synchronization signal input from the external system exceeds a preset threshold, the relevant node reports the fault to the network time management unit and waits for a decision to switch over.
[0015] Compared with existing technologies, the beneficial effects achieved by this invention are as follows: The system time synchronization scheme proposed in this patent utilizes the 802.1AS protocol's time synchronization method to construct multiple simultaneously operating time synchronization domains in the multi-margin network topology of aviation and aerospace, significantly improving the availability of system time synchronization while ensuring the time synchronization accuracy of all network nodes. Furthermore, through the external time synchronization input interface provided by the system, time synchronization between the network system and external systems can be achieved, further expanding the system's application scenarios. The well-designed clock domain switching mechanism ensures that normal business data in the network is not affected during clock domain switching. Therefore, this invention has broad application scenarios in safety-critical application fields such as aviation and aerospace. This patent utilizes the mature mechanisms in the 802.1AS protocol, greatly reducing the construction cost of building high-bandwidth, high-availability time synchronization systems in safety-critical application fields. Attached Figure Description
[0016] Figure 1 The diagram shown is a schematic diagram of the three-clock domain structure of the dual-redundancy network provided in an embodiment of the present invention. Figure 2 The diagram shown is a schematic diagram of the three-clock domain structure of a three-redundancy network provided in an embodiment of the present invention. Figure 3 The diagram shown illustrates the data exchange between the ES and the HOST CPU according to an embodiment of the present invention. Figure 4 The diagram shown illustrates the working principle of the time management unit provided in an embodiment of the present invention. Detailed Implementation
[0017] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations thereof. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0018] The term "and / or" simply describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Example 1
[0019] This embodiment introduces a time synchronization method based on a TSN network, applied to a time synchronization system. This method achieves high-availability time synchronization through the following process, significantly improving system reliability while ensuring microsecond-level synchronization accuracy across the entire network, as detailed below: During the system initialization phase, the redundancy architecture and clock domain size of the time synchronization system are determined based on the quantitative indicators of the time synchronization system. The system uses a static configuration method to designate one clock domain as the primary clock domain and the remaining clock domains as backup clock domains.
[0020] It should be noted that, in order to ensure the determinism of system behavior, when there is a lack of synchronization between nodes or the time synchronization between nodes exceeds the limit, the system can automatically switch to the backup clock domain to maintain the time synchronization of the entire system.
[0021] During the operation and monitoring phase, the system absolute time (BaseTime_X) of each node in the TSN network in each clock domain is obtained, and the difference (delta-T_XX) between the system absolute times of any two clock domains is calculated. When the difference exceeds the preset time synchronization error window (Threshold), the current clock domain pair is marked as out of tolerance. At the same time, the time synchronization status and error situation of each node in each clock domain are collected. During the fault decision-making phase, the clock domain is switched based on the reported results, namely the clock domain time synchronization status and the out-of-tolerance situation. If the decision is to switch the clock domain, the clock domain switching command is broadcast to the time synchronization system. After receiving the switching command, all nodes stop the correction of the original master clock domain and select a target clock domain from the backup clock domains according to the preset priority order. The target clock domain is then activated as the new master clock domain to perform the correction function. During the post-switch synchronization phase, the master clock (GM) node in the new master clock domain connects to an external synchronization signal to calibrate the local clock, and achieves time synchronization of the time synchronization system through a time synchronization protocol.
[0022] It should be noted that the clock domain switching decision in the system is handled by the network time synchronization management unit. The GM node of the backup clock domain will transmit the time synchronization information obtained from the primary clock domain in the backup clock domain, thereby ensuring that the time of the backup clock domain of all nodes in the system remains synchronized with that of the primary domain. Example 2
[0023] This embodiment, based on Embodiment 1, describes the specific implementation of a time synchronization system under a redundant architecture. The system comprises network nodes (terminals and switches), a time synchronization management unit, and an external system synchronization signal interface unit. Redundant synchronization is achieved through the following four stage domains: System initialization phase: In this embodiment of the invention, based on the 802.1AS time synchronization protocol, multiple clock domains can operate simultaneously in a multi-redundant network topology. The network margin (dual redundancy, triple redundancy, or higher margin) can be selected according to the system's reliability and availability indicators for data communication and time synchronization functions, thereby determining the corresponding redundant network topology and the number of different clock domains (two clock domains, three clock domains, or more clock domains), thus significantly improving the reliability and availability of the system's clock synchronization function.
[0024] The more clock domains there are, the higher the reliability and availability of the system clock synchronization function. For example, for general safety-critical systems (such as high-speed trains and aviation), a dual-redundant network topology can be used, with each system containing two clock domains, which is generally sufficient to meet application requirements; for high safety-critical systems (such as satellites and spacecraft), a triple-redundant network topology can be used, with each system containing three or more clock domains to meet the system's design requirements.
[0025] Furthermore, for each clock domain, a node is selected to assume the GM function, namely the GM node (master clock node); among which, the device assuming the GM role must be, but is not limited to, an end device (ES) or a switch component (SW).
[0026] After the GM node of a specific clock domain is determined, the clock tree structure is planned according to the time synchronization protocol (802.1AS) starting from the GM node, ensuring that any node in the TSN network can be included in the clock tree structure of the domain, and the port role of each node in the clock tree is statically assigned.
[0027] Furthermore, the static allocation of port roles for each node in the clock tree must satisfy the following constraints: a. Each clock domain has only one node acting as the GM node, which initiates the time synchronization behavior of its own clock domain; b. The same node can be a GM node in at most one clock domain across multiple clock domains; c. Each clock domain covers all nodes in the system. Nodes in the same clock domain use a time synchronization protocol (802.1AS) to calibrate their local clocks to maintain time synchronization. d. Each clock domain has a time synchronization processing entity to handle the time synchronization behavior of the current clock domain; e. At any given time, there is only one clock domain that is the master clock domain, which is responsible for maintaining the time synchronization of the entire TSN network. Each node in the master clock domain controls the service data processing behavior of each node according to the correction result (Correction) calculated by the master clock domain. Other clock domains only correct parameters and do not perform correction behavior. f. Within each node, the local clock of the current node is calibrated only by the time synchronization processing entity of its master clock domain.
[0028] Operation monitoring phase: Set a threshold to promptly identify out-of-tolerance nodes in a specific clock domain.
[0029] Specifically, within each node, a time synchronization protocol, such as 802.1AS, is used to detect and update the time synchronization status of the current node in the specified clock domain by the time synchronization processing entity configured for each clock domain, and at the same time calculate the system absolute time (BaseTime_X) corresponding to each clock domain. Each node is configured with a time synchronization tolerance window (e.g., ≤1μs in a maritime scenario), and checks the difference (delta-T_XX) between the absolute times of the systems in each clock domain. The expression for this difference is: delta-T_AB = | BaseTime_A - BaseTime_B | Where delta-T_AB represents the system absolute time difference between clock domain A and clock domain B; BaseTimeA represents the system absolute time calculated based on clock domain A; and BaseTimeB represents the system absolute time calculated based on clock domain B.
[0030] The difference between any two clock domains is compared with the time synchronization error window to obtain the deviation result. When the difference is less than or equal to the time synchronization error window, it is marked as 1, that is, the corresponding clock domain pair is marked as normal; when the difference is greater than the time synchronization error window, it is marked as 0, that is, the corresponding clock domain pair is marked as out of tolerance.
[0031] The time synchronization management unit determines the faulty clock domain and the clock domain switching scheme based on the marking results of all clock domains. For example, if only delta-T_AB=1 and the others are 0, then domain A or B is determined to be faulty; if delta-T_AB=1 and delta-T_AC=1, then domain A is determined to be faulty (because both A and B / C are out of tolerance).
[0032] Fault decision-making phase: Through a unified arbitration control mechanism, it is ensured that the time synchronization accuracy between nodes in the network does not exceed the tolerance during clock domain switching, and normal communication services will not be affected.
[0033] Specifically, after each node detects a clock domain time synchronization error, its behavior is determined based on the number of clock domains, the extent of the error, and the impact on security. The node behavior scenarios for different situations are shown in Table 1 below: Table 1
[0034] See Figure 4 Each node periodically reports the synchronization status and out-of-tolerance status of its own clock domains to the nodes of the network time synchronization management unit, which includes switch nodes and terminal nodes. The nodes of the network time synchronization management unit determine management actions based on the time synchronization status and fault information of all nodes in the time synchronization system, i.e., the marked out-of-tolerance events. The process of determining management actions is as follows: Through network time management within the time synchronization system, the system receives and processes the time synchronization status reported by each node and the out-of-tolerance status of faulty clock domains. Based on the received time synchronization status and the out-of-tolerance status of the faulty clock domain, verify whether the clock domain switching scheme is met. If it is met, the time synchronization management unit triggers the clock domain decision switching. After the clock domain decision-making switch, the clock domain switch command is broadcast to all nodes in the time synchronization system; Finally, upon receiving the clock domain switching command, all control nodes stop modifying the original master clock domain and activate the new master clock domain within the same synchronization cycle.
[0035] To ensure the availability of the time management node function, multiple time management nodes are set up in the system. For example, two nodes can detect faults, and three or more nodes can confirm faults. Furthermore, the time management nodes can reside in any terminal node in the TSN network.
[0036] Furthermore, after the clock domain decision-making switch, the clock domain switch command is broadcast to all nodes in the time synchronization system, including: By statically configuring one of the network time management nodes as the primary time management node and the rest as backup time management nodes; Each time management node receives clock domain status information from all nodes in the system and performs clock domain fault judgment and decision calculation. Each time management node exchanges its decision calculation results. If the decision calculation results are consistent, the master time management node issues a clock domain switching command to the time synchronization system. If the decision calculation results are inconsistent, the clock domain switching command is issued according to the decision calculation results consistent by the majority of time management nodes. If the master time management node itself makes a decision error or fails, a new master time management node is elected from the backup time management nodes according to a predetermined election strategy to issue the switching command.
[0037] In this embodiment of the invention, the node types in the system include switch nodes and terminal nodes, and the network time management unit node can reside on any switch node or terminal node.
[0038] Furthermore, the conditions for triggering a decision switch must meet the following: (1) If a switch node belonging to the master clock domain cannot complete the time synchronization process or the synchronization accuracy is out of tolerance, an available clock domain should be selected for switching. (2) If a terminal node with a safety-critical task node cannot complete the time synchronization process or the synchronization accuracy is out of tolerance, an available clock domain should be selected for switching. (3) If multiple leaf nodes belonging to the master clock domain cannot complete the time synchronization process (the planned clock tree structure is broken), an available clock domain should be selected for switching. (4) After all clock domains have been synchronized, the GM node, which is the backup clock domain, detects that the time of the master clock domain is out of sync with the time input from the external system and should select an available clock domain to switch to.
[0039] It should be noted that before any clock domain is synchronized, each node is prohibited from starting the transmission of service data; if all clock domains fail, all nodes will be forced to shut down the transmission of service data.
[0040] Synchronization phase after switchover: It should be noted that after the GM node of each clock domain starts up, it receives the external synchronization signal through its external signal synchronization interface unit and uses it to calibrate the local clock (RTC), thereby realizing the synchronization of the TSN network with the external system time. Before any clock domain has completed synchronization, all nodes are prohibited from starting service data transmission, and the first clock domain to complete time synchronization is set as the master clock domain.
[0041] Specifically, each GM node in the clock domain (regardless of whether it is primary or backup) obtains the clock synchronization signal from the external system through its external signal synchronization interface unit; The GM node, which assumes the function of the master clock domain, receives the clock synchronization signal through the external signal synchronization interface unit, and uses the clock synchronization signal to write the external time into the local clock to obtain the calibrated time. Then, it spreads the calibrated time to all nodes in the TSN network through the time synchronization protocol, thereby realizing the clock synchronization of all nodes in the time synchronization system. GM nodes that do not assume the function of master clock domain also receive clock synchronization signals input from external systems through their external signal synchronization interface units, and verify the local time obtained through the time synchronization protocol (802.1AS). If the deviation between the local time and the clock synchronization signal input from the external system exceeds a preset threshold, the relevant nodes report the fault to the network time management and wait for decision-making and switching. Example 3
[0042] See Figure 1 and Figure 2The TSN network consists of two components: terminals (ES) and switches (SW). The blue bidirectional arrows between the components indicate the physical link connection between the components, and the dashed one-way arrows of different colors indicate the clock synchronization information transmission path of different clock domains (the colored dashed one-way arrows = the synchronization message path of each clock domain, and different colors indicate different domains).
[0043] Each component in the network plays a different role in different clock domains. Each clock domain has only one GM node, which is responsible for initiating the time synchronization behavior of its own clock domain (i.e., there is only one GM in each domain responsible for sending synchronization messages). However, at any given time, only one master clock domain controls the correction of the local clock to ensure that each node completes the sending and receiving of business data according to the configuration. The backup clock domain is responsible for tracking the time synchronization behavior of the master clock domain to ensure the time synchronization between each node in its own clock domain.
[0044] When the master clock domain fails, the system selects a backup clock domain as the master clock domain to continue maintaining time synchronization across the entire network. The original master clock domain is switched to the backup clock domain until the GM of the current master clock domain can receive time synchronization signals from external systems to ensure time synchronization between the network system and external systems.
[0045] See Figure 3 The ES (Executable Executor) and the HOST CPU (the main processing unit in the terminal) support data exchange between upper-layer applications and applications residing on other nodes within the system via application data links (such as PCI bus, PCIE bus, RAPIDIO bus, Local BUS, etc.). The ES provides a time synchronization signal to the HOST CPU based on the business data transmission cycle. The HOST CPU then controls the task scheduling of residing applications based on the time synchronization signal generated by the ES, thereby ensuring the synchronization of the entire system and significantly reducing end-to-end data transmission latency.
[0046] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.
Claims
1. A time synchronization method based on a TSN network, characterized in that, The method, applied to a time synchronization system, includes: Based on the quantitative indicators of the time synchronization system, determine the redundancy architecture and clock domain size of the time synchronization system; Based on the aforementioned redundant architecture and clock domain size, one clock domain is statically configured as the primary clock domain, and the remaining clock domains are configured as backup clock domains. Obtain the system absolute time of each node in the TSN network in each clock domain, and calculate the difference between the system absolute times of any two clock domains. If the difference exceeds the preset time synchronization error window, mark the current clock domain pair as out of tolerance. Collect the time synchronization status and out-of-range conditions reported by each node in each clock domain; The decision to switch clock domains is made based on the clock domain time synchronization status and the out-of-tolerance situation. If the decision is to switch clock domains, a clock domain switching command is broadcast to the time synchronization system. Upon receiving the clock domain switching command, all control nodes stop the correction of the original master clock domain, select a target clock domain from the backup clock domains according to the preset priority order, and activate the target clock domain as the new master clock domain. The master clock node in the new master clock domain is connected to an external synchronization signal to calibrate the local clock, and the time synchronization of all nodes in the time synchronization system is completed through a time synchronization protocol.
2. The time synchronization method based on a TSN network according to claim 1, characterized in that, Determining the redundancy architecture and clock domain size of the time synchronization system includes: Based on the reliability and availability indicators of the time synchronization system for data communication and time synchronization functions, as well as the required network margin, the corresponding redundant network topology and the number of clock domains are determined, and a master clock node is assigned to each clock domain. Starting from the master clock node, a clock tree structure is planned according to the time synchronization protocol, and the port roles of each node in the clock tree are statically assigned.
3. The time synchronization method based on a TSN network according to claim 2, characterized in that, The static allocation of port roles for each node in the clock tree must satisfy the following constraints: a. Each clock domain has only one node as the master clock node; b. The same node can be the master clock node of at most one clock domain across multiple clock domains; c. Each clock domain covers all nodes in the time synchronization system, and each node in the same clock domain calibrates its local clock through a time synchronization protocol; d. Each clock domain has a time synchronization processing entity to handle the time synchronization behavior of the current clock domain; e. At any given time, there is one and only one clock domain as the master clock domain; f. In each node, the local clock of the current node is calibrated only by the time synchronization processing entity of the master clock domain.
4. The time synchronization method based on a TSN network according to claim 3, characterized in that, The marking process for the clock domain pairs includes: Within each node, using the time synchronization protocol, the time synchronization processing entity configured for each clock domain monitors and updates the time synchronization status of the current node in the specified clock domain, and calculates the system absolute time corresponding to each clock domain. Each node is equipped with a time synchronization error window and calculates the difference in absolute system time between clock domains; The difference is compared with the time synchronization error window to obtain the deviation result; wherein, when the difference is not greater than the time synchronization error window, the corresponding clock domain pair is marked as normal, and when the difference is greater than the time synchronization error window, the corresponding clock domain pair is marked as out of tolerance. Based on the marking results of all clock domains, determine the faulty clock domain and the clock domain switching scheme.
5. The time synchronization method based on a TSN network according to claim 4, characterized in that, The determination of the faulty clock domain and the clock domain switching scheme includes: The network time management unit within the time synchronization system receives and processes the time synchronization status and out-of-tolerance status of faulty clock domains reported by each node. Based on the received time synchronization status and the out-of-tolerance status of the faulty clock domain, verify whether the clock domain switching scheme is met. If it is met, the time synchronization management unit triggers the clock domain decision switching and broadcasts the clock domain switching command to all nodes in the time synchronization system. Upon receiving the clock domain switching command, all nodes are controlled to stop the correction of the original master clock domain and activate the new master clock domain within the same synchronization cycle.
6. The time synchronization method based on a TSN network according to claim 5, characterized in that, The triggering of the clock domain decision switch and broadcasting the clock domain switch command to all nodes in the time synchronization system includes: By statically configuring one of the network time management nodes as the primary time management node and the rest as backup time management nodes; Each time management node receives clock domain status information from all nodes in the time synchronization system and performs clock domain fault judgment and decision calculation. Each time management node exchanges its decision calculation results. If the decision calculation results are consistent, the master time management node issues a clock domain switching command to the time synchronization system. If the decision calculation results are inconsistent, the clock domain switching command is issued according to the decision calculation results consistent by the majority of time management nodes. If the master time management node itself makes a decision error or fails, a new master time management node is elected from the backup time management nodes according to a predetermined election strategy to issue the switching command.
7. The time synchronization method based on a TSN network according to claim 6, characterized in that, The node types in the time synchronization system include switch nodes and terminal nodes; The network time management unit node can reside on any switch node or terminal node.
8. The time synchronization method based on a TSN network according to claim 7, characterized in that, The triggering of the clock domain decision switching must meet the following conditions: (1) Switch nodes belonging to the master clock domain cannot complete the time synchronization process or the synchronization accuracy is out of tolerance; (2) Terminal nodes with security-critical mission nodes cannot complete the time synchronization process or the synchronization accuracy is out of tolerance; (3) Multiple leaf nodes belonging to the master clock domain cannot complete the time synchronization process; (4) After all clock domains are synchronized, the master clock node, which is the backup clock domain, detects that the time of the master clock domain is out of sync with the time input from the external system.
9. The time synchronization method based on a TSN network according to claim 5, characterized in that, Also includes: Before any clock domain is synchronized, each node is prohibited from initiating the transmission of service data; If all clock domains fail, force all nodes to shut down service data transmission.
10. The time synchronization method based on a TSN network according to claim 1, characterized in that, The new master clock domain's master clock node connects to an external synchronization signal to calibrate its local clock, including: The master clock node of each clock domain can obtain clock synchronization signals from external systems; The master clock node, which assumes the function of the master clock domain, uses the clock synchronization signal to write the external time into the local clock to obtain the calibrated time, and then spreads the calibrated time to all nodes in the TSN network through the time synchronization protocol. The master clock node, which does not assume the function of the master clock domain, uses the clock synchronization signal input from the external system to verify the local time obtained through the time synchronization protocol. If the deviation between the local time and the clock synchronization signal input from the external system exceeds a preset threshold, the relevant node reports the fault to the network time management unit and waits for a decision to switch over.