Cooperative management method and system of multi-domain FC-AE-1553 network
By configuring globally unique addresses and security partitioning policies for multi-domain FC-AE-1553 networks, and dynamically monitoring and authorizing switch configurations, the problems of resource sharing and fault takeover among multi-domain FC-AE-1553 networks are solved, improving system reliability and resource utilization.
Patent Information
- Application Number
- CN202511534693.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-27
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-10-27
AI Technical Summary
Existing technologies cannot effectively solve the problems of resource sharing and fault takeover between multi-domain FC-AE-1553 networks, resulting in resource waste, high costs and system reliability bottlenecks. Traditional backup solutions cannot provide redundancy support across network boundaries.
By configuring a globally unique 24-bit FC address for each network controller and terminal, a security partitioning policy is implemented, the status of the network controller is monitored, and the switch is dynamically authorized and configured in case of failure, enabling cross-subnet communication and fault takeover.
It enables cross-network resource sharing, reduces hardware costs and power consumption, improves system reliability and survivability, and ensures efficient transmission of critical traffic and fault recovery.
Smart Images

Figure CN121012736A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, in particular to a method and system for cooperative management of a multi-domain FC-AE-1553 network. BACKGROUND
[0002] With the increasing complexity of avionics, spacecraft and high-performance shipboard vehicle systems, multi-domain cooperative systems composed of multiple FC-AE-1553 networks (Fiber Channel-Avinonics Environment-Upper Layer Protocl, where FC: Fiber Channel) interconnected have gradually become the norm. As a new generation of avionics standard, FC-AE-1553 network realizes a huge leap in data throughput by transplanting the command / response mechanism of MIL-STD-1553B bus to fiber channel infrastructure while inheriting determinism and reliability. FC-AE-1553 network is mainly composed of network controller, network terminal and switch, as shown in Figure 1 FC-AE-1553 network includes a network controller responsible for traffic management, multiple distributed network terminals and a switch as a communication hub. All nodes are directly connected to different physical ports of the switch through independent fiber links, thus forming a star-shaped switched fiber network topology centered on the switch. This architecture ensures that the network controller and each network terminal can establish a high-bandwidth, full-duplex point-to-point dedicated communication channel through the switch. The network controller is responsible for initiating and controlling all communication traffic according to the FC-AE-1553 protocol in the entire FC-AE-1553 network, while each network terminal responds to the instructions of the network controller to complete specific data transmission or reception tasks. The switch plays a key role in unblocking data exchange and provides a deterministic low-latency transmission path for data flow between all nodes. This basic network architecture is the physical and logical basis for implementing more complex multi-domain FC-AE-1553 network cooperative management.
[0003] FC-AE-1553 network is widely used in military and civil avionics systems, spacecraft, and integrated electronic systems of ships and ground vehicles with extreme requirements for performance and reliability. In such complex systems, the traditional reliability guarantee scheme is limited within a single FC-AE-1553 network, for example, configuring a primary and backup network controller for each independent FC-AE-1553 network or using a hot backup with fiber interface. This approach has inherent defects: the backup network controller of each network is in an idle state for a long time, resulting in low hardware resource utilization, high system cost, and limited scalability; more importantly, it cannot cope with the extreme case where the primary and backup network controllers of a network both fail, and the backup resources cannot provide redundant support across network boundaries for other FC-AE-1553 networks. When the primary and backup network controllers both fail, the communication services of the failed network are completely interrupted, and the network controllers of other networks cannot take over the devices of the failed network across network boundaries, which greatly reduces the overall mission reliability and survivability of large multi-domain network systems.
[0004] To solve the problem of single node function fixation and improve hardware flexibility, a node hardware scheme with role reconfigurability has appeared in the prior art. For example, a specific hardware design is proposed in Chinese Patent No. CN103905281A, entitled "FC-AE-1553 bus node card capable of realizing network controller and network terminal functions interchangeably". The node card integrates an FC-AE protocol processing unit, a programmable logic controller, and different application interfaces, which can be connected to the host computer as a network controller for remote monitoring or connected to the peripheral device as a network terminal for data exchange by selecting different configurations at the physical layer, thereby realizing one card with two node functions and improving the flexibility and versatility of a single node.
[0005] However, this node reconfiguration scheme at the hardware level still focuses on function switching within a single device and does not solve the problem of coordinated management between multi-domain FC-AE-1553 networks from the system architecture level. It cannot achieve dynamic sharing and unified scheduling of resources across FC-AE-1553 subnets, nor can it establish a system-level management mechanism that can quickly and orderly take over the failure and restore services across network boundaries when a failure occurs. For a multi-domain system composed of multiple FC-AE-1553 networks, the network controller resources of each subnet cannot be efficiently backed up and shared across domains. Therefore, even if a single node has role exchange capability, the problems of resource waste, high cost, and system reliability bottleneck of multi-domain FC-AE-1553 networks have not been fundamentally solved without corresponding cross-network coordinated management methods.
[0006] Therefore, for a complex system of a multi-domain FC-AE-1553 network, a system-level cooperative management method is urgently needed, which can realize resource backup and fault takeover across networks while keeping each FC-AE-1553 subnet running independently by default, thereby fundamentally improving the reliability, resource utilization and scalability at the system level. The present application is proposed based on this purpose. SUMMARY
[0007] The technical problem to be solved by the present application is to overcome the deficiencies of the prior art, and specifically provides a cooperative management method and system for a multi-domain FC-AE-1553 network, as follows: 1) In a first aspect, the present application provides a cooperative management method for a multi-domain FC-AE-1553 network, and the specific technical solutions are as follows: The multi-domain FC-AE-1553 network includes a plurality of FC-AE-1553 subnets interconnected by switches, each FC-AE-1553 subnet includes a network controller, a network terminal and a switch, and the method includes: Each network controller and each network terminal is configured with an address, and a security zoning policy is implemented on the switch of each FC-AE-1553 subnet, so that each FC-AE-1553 subnet runs independently by default and cross-subnet communication is prohibited; The running state of the network controller of each FC-AE-1553 subnet is monitored and fault judgment is performed; When the network controller of the first FC-AE-1553 subnet is confirmed to have failed, an authorized configuration operation is performed to allow cross-subnet communication by the switch of the first FC-AE-1553 subnet, and the second FC-AE-1553 subnet takes over the service of the network terminal of the first FC-AE-1553 subnet; When the network controller of the first FC-AE-1553 subnet recovers, a recovery operation is performed to restore the management authority of the network controller of the second FC-AE-1553 subnet and the communication policy of the related switch to the default state; Wherein, the first FC-AE-1553 subnet and the second FC-AE-1553 subnet are two different FC-AE-1553 subnets in the multi-domain FC-AE-1553 network.
[0008] The cooperative management method for a multi-domain FC-AE-1553 network provided by the present application has the following advantages: By constructing the cooperative management mechanism across the FC-AE-1553 subnets, the network controller resources of each subnet can provide backup capability for other subnets, the resource sharing mode of 'one backup for multiple' is realized, thereby the hardware quantity of the redundant network controller is reduced, the overall cost, weight and power consumption of the system are directly reduced, and the utilization rate of the hardware resources is greatly improved. The method breaks through the limitation of the traditional single-network internal redundancy, realizes the system-level fault backup across the subnets through dynamic authorization configuration, when the network controller of a subnet fails, the system can quickly take over the functions of the network controller of the other healthy subnet, effectively avoids the serious consequences of the communication service interruption of the whole subnet caused by the failure of a single node, and fundamentally improves the overall task reliability and survivability of the multi-domain system. In addition, the architecture design of the method is independent of the number of subnets, and the newly added FC-AE-1553 subnet only needs to be connected to the existing interconnection architecture to obtain the cooperative management capability, without changing the hardware connection and management logic of the existing subnet, and has good scalability and deployment flexibility.
[0009] On the basis of the above scheme, a cooperative management method of a multi-domain FC-AE-1553 network of the application can be further improved as follows.
[0010] Further, an address is configured for each network controller and each network terminal, comprising: A globally unique 24-bit FC address is allocated for each network controller and each network terminal, and the 24-bit FC address contains domain identification, area identification and port identification, wherein the domain identification is used to uniquely identify the FC-AE-1553 subnet to which the network controller and the network terminal belong.
[0011] The beneficial effects of the above further scheme are that a globally unique 24-bit FC address containing domain identification, area identification and port identification is allocated for each network controller and network terminal, and a unified cross-network addressing system is established. The domain identification ensures that each node can be uniquely identified as the FC-AE-1553 subnet to which it belongs, which provides a fundamental basis for the switch to accurately judge whether the data frame is an internal communication of the subnet or needs to be forwarded across the subnet, thereby laying a reliable addressing foundation for subsequent implementation of logical isolation and on-demand cross-network communication under the security partition strategy, and ensuring the accuracy and reliability of data routing in the cross-network fault takeover process.
[0012] Further, the method further comprises: Classifying and configuring the service quality priority of the business traffic scheduled by the network controller of the second FC-AE-1553 subnet, and configuring the forwarding priority of the critical management traffic from the network terminal of the taken-over first FC-AE-1553 subnet to be higher than that of the regular task data.
[0013] The beneficial effects of adopting the above-mentioned further solution are as follows: Classifying and configuring quality of service (QoS) priorities for service traffic scheduled by the network controller of the second FC-AE-1553 subnet ensures that, in cross-network takeover scenarios, critical management traffic from network terminals of the taken-over first FC-AE-1553 subnet is forwarded with priority over regular task data. This effectively guarantees the timeliness and reliability of the transmission of management messages with high real-time requirements, such as heartbeats and status commands, during fault takeover, avoiding critical communication congestion caused by surges in service traffic, thereby maintaining the stability of the basic control link of the taken-over network. This is an important guarantee for improving the task continuity of the entire system under collaborative management.
[0014] Furthermore, monitor the operating status of the network controller in each FC-AE-1553 subnet and perform fault diagnosis, including: The operating status of the network controller of each FC-AE-1553 subnet is monitored and fault diagnosis is performed using heartbeat telemetry information.
[0015] The beneficial effects of adopting the above-mentioned further solution are as follows: By continuously monitoring the heartbeat telemetry information from the network controllers of each FC-AE-1553 subnet, real-time and reliable fault detection capabilities are provided. This monitoring mechanism based on periodic status reports can promptly detect abnormal states of network controllers and serve as an accurate basis for triggering subsequent cross-network collaborative management processes, thereby ensuring the timeliness and accuracy of fault diagnosis. This lays a key foundation for the rapid and automatic fault takeover and recovery of the entire multi-domain FC-AE-1553 network, effectively improving overall survivability.
[0016] 2) Secondly, the present invention also provides a collaborative management system for a multi-domain FC-AE-1553 network, the specific technical solution of which is as follows: The multi-domain FC-AE-1553 network includes multiple FC-AE-1553 subnets interconnected by switches. Each FC-AE-1553 subnet contains a network controller, network terminals, and switches. The system includes a configuration implementation module, a monitoring and fault diagnosis module, an authorization configuration module, and an execution recovery module. The configuration implementation module is used to: configure addresses for each network controller and each network terminal, and implement security partitioning policies on the switches of each FC-AE-1553 subnet, so that each FC-AE-1553 subnet can operate independently by default and cross-subnet communication is prohibited; The fault diagnosis module is used to monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault diagnosis. The authorization configuration module is used to: when the network controller of the first FC-AE-1553 subnet is confirmed to have failed, enable the switches of the first FC-AE-1553 subnet to allow cross-subnet communication through authorization configuration operations, and enable the second FC-AE-1553 subnet to take over the services of the network terminals of the first FC-AE-1553 subnet. The recovery module is used to: after the network controller of the first FC-AE-1553 subnet recovers, perform a recovery operation to restore the management permissions of the network controller of the second FC-AE-1553 subnet and the communication policies of the relevant switches to the default state; Among them, the first FC-AE-1553 subnet and the second FC-AE-1553 subnet are two different FC-AE-1553 subnets in the multi-domain FC-AE-1553 network.
[0017] Based on the above scheme, the collaborative management system for a multi-domain FC-AE-1553 network of the present invention can be further improved as follows.
[0018] Furthermore, the configuration implementation module is specifically used to: allocate a globally unique 24-bit FC address to each network controller and each network terminal. The 24-bit FC address contains a domain identifier, a region identifier, and a port identifier. The domain identifier is used to uniquely identify the FC-AE-1553 subnet to which the network controller and network terminal belong.
[0019] Furthermore, it also includes a priority configuration module, which is used to: classify and configure quality of service priorities for service traffic scheduled by the network controller of the second FC-AE-1553 subnet, and configure a higher forwarding priority for critical management traffic from network terminals of the first FC-AE-1553 subnet that has been taken over than for regular task data.
[0020] Furthermore, the fault diagnosis module is specifically used to monitor the operating status of the network controller of each FC-AE-1553 subnet through heartbeat telemetry information and to diagnose faults.
[0021] 3) In a third aspect, the present invention also provides an electronic device, the electronic device including a processor coupled to a memory, the memory storing at least one computer program, the at least one computer program being loaded and executed by the processor, so as to enable the electronic device to implement any of the above-mentioned collaborative management methods for multi-domain FC-AE-1553 networks.
[0022] 4) In a fourth aspect, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the above-mentioned collaborative management methods for multi-domain FC-AE-1553 networks.
[0023] It should be noted that the beneficial effects of the technical solutions of the second to fourth aspects of the present invention and their corresponding possible implementations can be found in the above description of the technical effects of the first aspect and its corresponding possible implementations, and will not be repeated here. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments of the present invention will be briefly introduced below: Figure 1 This is a schematic diagram of the FC-AE-1553 network structure; Figure 2 This is a flowchart illustrating a collaborative management method for a multi-domain FC-AE-1553 network according to an embodiment of the present invention. Figure 3 A schematic diagram of the interconnection architecture of a multi-domain FC-AE-1553 network; Figure 4 A diagram illustrating the allocation of FC addresses; Figure 5 This is a schematic diagram of the data flow in cross-network communication; Figure 6 This is a schematic diagram of the structure of a collaborative management system for a multi-domain FC-AE-1553 network according to an embodiment of the present invention. Detailed Implementation
[0025] The principles and features of the present invention are described below. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0026] The technical solution of the present invention and how the technical solution of the present invention solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present invention will now be described with reference to the accompanying drawings.
[0027] like Figure 2 As shown in the figure, a collaborative management method for a multi-domain FC-AE-1553 network according to an embodiment of the present invention includes the following steps: S1. Configure addresses for each network controller and each network terminal, and implement a security partitioning policy on the switch of each FC-AE-1553 subnet so that each FC-AE-1553 subnet can operate independently by default and cross-subnet communication is prohibited. The multi-domain FC-AE-1553 network includes multiple FC-AE-1553 subnets interconnected by switches. Each FC-AE-1553 subnet contains a network controller, network terminals, and switches.
[0028] Each independent FC-AE-1553 subnet is a fully functional standard FC-AE-1553 network, comprising one or more network controllers, several network terminals, and one or more switches. During network deployment, each network terminal and network controller is directly connected to a specific physical port of the switch via its own fiber optic cable, forming a star-shaped switched fiber optic network topology. Within the FC-AE-1553 subnet, the network controller plays a management role, initiating and controlling all communication tasks according to the command and response mechanism defined in the FC-AE-1553 protocol. Network terminals, as controlled nodes, respond to instructions issued by the network controller, completing data transmission or reception tasks. The switch, as the communication hub of the subnet, provides high-bandwidth, full-duplex, and non-blocking point-to-point data exchange channels for all devices connected to its ports, ensuring deterministic and low-latency communication within the FC-AE-1553 subnet.
[0029] After successfully constructing multiple independent FC-AE-1553 subnets, these subnets are interconnected to form a multi-domain FC-AE-1553 network. The interconnection is achieved by connecting the switches in different FC-AE-1553 subnets via cross-network fiber optic links. These interconnection links are typically configured on designated high-speed ports on the switches, specifically for handling data flows between different FC-AE-1553 subnets. This cascading method physically merges multiple FC-AE-1553 subnets, forming a unified network infrastructure with wider coverage and a larger number of nodes.
[0030] The multi-domain FC-AE-1553 network employs a strict security partitioning strategy. Although the FC-AE-1553 subnets are interconnected, each subnet remains logically isolated and independent by default. The switch's security partitioning policy is configured to ensure that network controllers and network terminals within each FC-AE-1553 subnet can only communicate freely within their respective subnets. Any communication request attempting to travel from one FC-AE-1553 subnet to another is discarded by the switch by default. This design guarantees the inherent independence, security, and deterministic communication behavior of each FC-AE-1553 subnet during daily operation, preventing unauthorized cross-network access and potential problems.
[0031] The collaborative management capabilities of the entire multi-domain FC-AE-1553 network are based on this "physical interconnection, logical isolation" architecture. When cross-network fault takeover or global task scheduling is required, authorization commands are issued to specific network controllers and switches, dynamically modifying their configurations. The network controllers then update their communication management object lists, and the switches temporarily open cross-subnet communication paths. This design allows the network to maintain the stable and independent operation of each subnet under normal circumstances, while also rapidly integrating resources when necessary, achieving cross-domain collaborative management and high reliability assurance. This constitutes a comprehensive network solution that combines flexibility, scalability, and high survivability.
[0032] Specifically, addresses are configured for each network controller and each network terminal, including: Each network controller and each network terminal is assigned a globally unique 24-bit FC address. The 24-bit FC address contains a domain identifier, a region identifier, and a port identifier. The domain identifier is used to uniquely identify the FC-AE-1553 subnet to which the network controller and network terminal belong.
[0033] When constructing a multi-domain FC-AE-1553 network, the first step is to assign a globally unique 24-bit FC address to each network controller and each network terminal within the network. This address allocation process is fundamental to achieving cross-network collaborative management. In practice, designers can perform static or dynamic configuration based on a pre-defined global addressing scheme, either through network management configuration tools or directly in the firmware of each network controller and network terminal. During power-on initialization, the assigned FC address is written into the device's Fibre Channel hardware register and serves as the unique identifier for that network controller or network terminal in all subsequent Fibre Channel communications. Switches in the multi-domain FC-AE-1553 network automatically discover and maintain the mapping between these FC addresses and the switch's physical ports through the Fibre Channel protocol's learning mechanism, thereby establishing accurate data forwarding paths within the network. This complete global addressing scheme logically ensures that within the entire multi-domain FC-AE-1553 network, any network controller in any FC-AE-1553 subnet can uniquely and accurately address the target device using its FC address, even if the target network controller or network terminal is located in a different FC-AE-1553 subnet. This addressing capability is a technical prerequisite for enabling cross-subnet fault takeover functionality of the network controller.
[0034] In this invention, the FC address refers to a 24-bit numerical code used to uniquely identify each network controller and each network terminal at the network layer. This FC address strictly adheres to the Fibre Channel protocol standard definition and is carried in the header of each FC network frame to clearly indicate the originating node and the receiving destination node of the data frame. Its function is to provide a precise addressing system for the entire Fibre Channel network, ensuring that data can be correctly routed and delivered by network devices. This 24-bit FC address space is not arbitrarily allocated but is systematically divided into three fields with specific functions. These three fields together constitute a clear, easily managed, and expandable addressing structure.
[0035] The domain identifier, occupying 8 bits, is the highest-level and most widely covered identifier in the entire address structure. In the address planning of multi-domain FC-AE-1553 networks, each physically independent and logically autonomous FC-AE-1553 subnet is assigned a unique domain identifier code that is distinct from all other subnets. When a switch in the network processes each data frame flowing through it, the first step in its routing decision is to parse the domain identifier information contained in the destination FC address. By comparing the domain identifier of the data frame with the identifier of the subnet served by the switch, the switch can immediately determine whether the data frame's destination is within its own subnet or needs to be sent to another subnet. This determination is the fundamental basis for determining the subsequent flow of the data frame and is key to achieving logical isolation and controllable connectivity between subnets.
[0036] The area identifier, an 8-bit field adjacent to the domain identifier, provides a secondary hierarchical logical structure within the subnet defined by the domain identifier. The area identifier is used for finer-grained grouping of network controllers and network terminals within the same FC-AE-1553 subnet. This division is not based on physical location, but on logical factors such as function, service type, or management policy. By introducing the area identifier layer, network administrators can more precisely plan traffic paths within the subnet, implement access control policies, and optimize broadcast domains, thereby improving network manageability and operational efficiency. Based on a known target subnet, switches can further utilize the area identifier to narrow down the addressing range, enabling faster and more accurate data frame switching.
[0037] The port identifier, the lowest 8 bits of the 24-bit FC address, represents the most crucial location information in the entire addressing system. The port identifier typically has a direct or indirect mapping to a specific physical port number on the switch. Its main function is to uniquely identify the final network controller or network terminal device within a logical packet determined by both the domain identifier and the area identifier. When a data frame traverses the routing path and finally reaches the target area within the target subnet, the switch performs the final step: accurately forwarding the data frame to the target device connected to the corresponding physical port based on the lowest 8 bits of the port identifier in the FC address. The port identifier ensures that each network node has a unique identifier within the smallest logical unit, thus perfectly achieving end-to-end precise positioning from the macro-level subnet, to the meso-level area, and finally to the micro-level specific device.
[0038] Specifically, a security partitioning policy is implemented on the switches of each FC-AE-1553 subnet to ensure that each FC-AE-1553 subnet operates independently by default and prohibits cross-subnet communication. The specific implementation process is as follows: Based on a pre-planned global addressing scheme, the domain identifier range corresponding to each FC-AE-1553 subnet needs to be clearly defined. Subsequently, by configuring the switch, a dedicated logical partition is created for each independent FC-AE-1553 subnet. When creating a partition, the globally unique FC addresses of all network controllers and network terminals belonging to this FC-AE-1553 subnet need to be added to the partition's member list. The switch's internal policy enforcement engine checks each passing data frame according to this partition configuration. In default operation, the switch is configured with a strict partitioning policy. When the switch receives a data frame, it extracts the destination FC address of the frame and checks its domain identifier. If the domain identifier does not match the domain identifier of the partition to which the receiving port belongs, it is determined to be a cross-subnet communication request. The switch will discard this data frame directly according to the preset security partitioning policy, without forwarding it from the cross-network interconnection port. This mechanism enforces logical isolation at the data link layer, ensuring the communication boundaries of each FC-AE-1553 subnet. To enable dynamic switching during fault takeover, both switches and network controllers must support dynamic reconfiguration capabilities. When cross-network takeover is confirmed, an authorization command is sent to the switches in the relevant subnets. Upon receiving the authorization command, the switches dynamically adjust their partitioning policies, temporarily modifying rules for specific cross-network interconnection ports to allow previously blocked communication data destined for or originating from the designated faulty subnet to pass through. Similarly, after fault recovery, the switches receive the command again and restore the partitioning policies to the default isolation state, thus achieving flexible and reliable switching between independent operation and collaborative management modes of the network.
[0039] The security partitioning strategy is an access control mechanism in Fibre Channel networks that restricts communication capabilities between nodes by establishing logical isolation boundaries on switches. Specifically, in the multi-domain FC-AE-1553 network of this invention, the security partitioning strategy is used to divide each physically interconnected FC-AE-1553 subnet into an independent logical partition. The rule is that unimpeded communication is allowed between network controllers and network terminals within a partition, but any data frame exchange between different partitions is prohibited by default. The implementation of this strategy is based on the global FC address of the node. The switch determines the partition to which a data frame belongs based on the domain identifier in the source and destination addresses and performs allow or drop actions accordingly. This strategy not only achieves logical isolation and secure autonomy for each subnet, preventing unauthorized cross-network access and the spread of broadcast storms, but more importantly, it provides a controllable communication foundation for cross-network fault takeover. Specific cross-subnet communication paths can be opened as needed, while ensuring security, by dynamically adjusting partition members or rules.
[0040] S2. Monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault diagnosis. Specifically, monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault diagnosis through heartbeat telemetry information. The specific implementation process is as follows: ① Each FC-AE-1553 subnet's network controller periodically generates and broadcasts heartbeat telemetry information. This information is encapsulated in specific Fibre Channel frames, transmitted within its subnet via the connected switches, and then relayed across network interconnect links to monitoring modules throughout the multi-domain FC-AE-1553 network. A monitoring module can typically be a standalone ground monitoring station or a centralized network management unit that continuously listens for and receives these periodic heartbeat signals from the network controllers of all FC-AE-1553 subnets.
[0041] ② The monitoring module internally maintains a status table and timer corresponding to each network controller. Whenever a valid heartbeat frame is received, the status record of the corresponding network controller is updated, and its timer is reset. The heartbeat telemetry information contains a series of key status parameters, which collectively reflect the health of the network controller. The fault diagnosis logic of the monitoring module performs two tasks in parallel: first, it strictly monitors whether the heartbeat signal times out; that is, if the heartbeat signal of any network controller is not received within a preset time window, a timeout alarm is immediately triggered; second, it analyzes the key status parameters carried in the heartbeat frame and checks whether their values are within the preset normal operating range.
[0042] ③ Fault diagnosis is a multi-step confirmation process. When the monitoring module first detects potential fault signs, such as heartbeat timeout or abnormal critical parameters, it does not immediately determine a fault. Instead, it initiates a short confirmation period, during which it attempts to re-establish communication with the target network controller or waits for subsequent heartbeat frames. If the target network controller's heartbeat status has not returned to normal after the confirmation period ends, or if critical telemetry information received by ground operators via the downlink channel also corroborates the abnormal state, the monitoring module ultimately confirms that the network controller has failed. Once the fault is confirmed, the monitoring module or ground operators generate and send the corresponding fault confirmation command and subsequent authorization configuration command uplink, thereby triggering the cross-network takeover process.
[0043] Heartbeat telemetry information is a status message periodically and proactively sent by the network controller to declare its own liveness and report key operational parameters. This information is encapsulated in a specific Fibre Channel data frame, typically containing a unique controller identifier, a sequence number for detecting packet loss, timestamp information, and a series of key parameters reflecting the controller's internal operating status, such as processor load, memory usage, temperature, power status, and connection status with critical network terminals. Its function is to provide a real-time, lightweight operational status indication channel for upper-layer monitoring modules, enabling these modules to continuously and efficiently assess the health status of network controllers distributed across multiple domains without frequent large-scale polling, and providing a decisive basis for rapid and accurate fault detection and diagnosis.
[0044] S3. When the network controller of the first FC-AE-1553 subnet is confirmed to have failed, an authorized configuration operation is performed to enable cross-subnet communication for the switches of the first FC-AE-1553 subnet, allowing the second FC-AE-1553 subnet to take over the services of the network terminals of the first FC-AE-1553 subnet. Specifically: ① When the network controller of the first FC-AE-1553 subnet is confirmed to have failed, the monitoring module or ground control station generates and sends specific authorized configuration commands uplink. These commands are then sent to the switches of the first FC-AE-1553 subnet and the network controller of the second FC-AE-1553 subnet respectively through dedicated control channels.
[0045] ② Upon receiving the authorization command, the switch in the first FC-AE-1553 subnet performs a configuration switchover operation. The switch will dynamically adjust its security partitioning policy, specifically by enabling its cross-network interconnection ports, modifying port forwarding rules, and allowing previously prohibited cross-subnet communication data to pass through. This means that data frames destined for or originating from other FC-AE-1553 subnets and destined for network terminals within the first FC-AE-1553 subnet will be allowed to be transmitted through this interconnection port. Simultaneously, the switch may, based on the command, increase the quality of service (QoS) priority of specific management traffic to ensure that critical commands during the takeover process are forwarded with priority and low latency.
[0046] The authorization configuration procedures for the switches in the second FC-AE-1553 subnet during the cross-network takeover process are as follows: When the monitoring system or ground control station confirms a network controller failure in the first FC-AE-1553 subnet, it generates specific authorization configuration instructions and sends them to the switch in the second FC-AE-1553 subnet via a dedicated control channel. Upon receiving the authorization instructions, the switch first verifies their legitimacy and validity, then initiates a dynamic reconfiguration process. The core configuration operation of the switch is adjusting its security partitioning policy, specifically enabling its cross-network interconnection port, modifying the access control rules for that port to allow communication data from the first FC-AE-1553 subnet to pass through, and configuring cross-network transmission permissions for broadcast messages according to the instructions. Regarding Quality of Service (QoS) configuration, the switch enables a service level-based priority scheduling mechanism on its ports, configuring higher forwarding priority for critical management traffic from the taken-over subnet, ensuring that this traffic is processed before regular task data. Furthermore, the switch updates its routing table, directing data frames destined for network terminals within the first FC-AE-1553 subnet to the cross-network interconnection port for forwarding. These configuration changes enable the switches in the second FC-AE-1553 subnet to correctly identify and forward all FC-AE-1553 protocol command frames sent by their network controller to network terminals in the first FC-AE-1553 subnet, while also reliably receiving response data from these network terminals. This provides a stable and reliable underlying communication guarantee for cross-network service takeover. The entire configuration process ensures that while maintaining normal communication within the subnet, a dedicated, high-quality transmission channel is established for cross-domain management traffic.
[0047] ③ The network controller of the second FC-AE-1553 subnet also receives the corresponding authorization instruction. This instruction triggers the network controller to update its communication management policy by dynamically switching its communication whitelist. By default, this whitelist only contains network terminal addresses within the second FC-AE-1553 subnet. Upon receiving authorization, the network controller adds the globally unique FC addresses of all network terminals within the first FC-AE-1553 subnet to its list of valid communication targets. This step logically greatly expands the management authority and communication scope of the network controller of the second FC-AE-1553 subnet, granting it the legitimate right to establish communication sessions with network terminals within the faulty subnet.
[0048] ④ After completing the aforementioned key authorization configuration operations, the service takeover phase begins. Based on the updated communication whitelist, the network controller of the second FC-AE-1553 subnet begins sending command frames specified by the FC-AE-1553 protocol to network terminals in the first FC-AE-1553 subnet. These command frames, originating from the network controller of the second FC-AE-1553 subnet, enter the switches of the first FC-AE-1553 subnet via the cross-network interconnection ports of the subnet's switches, and are ultimately routed to the target network terminals. Upon receiving a valid command from this new network controller, the network terminal will respond according to the protocol specifications, thereby completing the transmission and reception of service data. Throughout the takeover process, the switches of the two subnets collaborate, using the global addressing scheme and the updated forwarding policy to ensure that cross-network data flows can be accurately and reliably routed, ultimately achieving a comprehensive and seamless takeover of the network terminal services of the first FC-AE-1553 subnet by the network controller of the second FC-AE-1553 subnet.
[0049] Among them, the first FC-AE-1553 subnet and the second FC-AE-1553 subnet are two different FC-AE-1553 subnets in the multi-domain FC-AE-1553 network.
[0050] S4. After the network controller of the first FC-AE-1553 subnet recovers, perform a recovery operation to restore the management permissions of the network controller of the second FC-AE-1553 subnet and the communication policies of the relevant switches to their default states. Specifically: After the ground monitoring module or centralized management unit confirms that the original faulty network controller has stably returned to normal operation, it will generate and send a sequence of recovery instructions. These instructions are first issued to the network controller of the second FC-AE-1553 subnet, commanding it to restore the communication whitelist from the extended list in the takeover state to the default configuration, i.e., removing all network terminal addresses belonging to the first FC-AE-1553 subnet from its list of valid communication objects. This operation logically releases the network controller of the second FC-AE-1553 subnet from its management rights over the network terminals of the first FC-AE-1553 subnet. The recovery instructions are simultaneously sent to the relevant switches, namely the switches of the first FC-AE-1553 subnet and the switches of the second FC-AE-1553 subnet. Upon receiving the instructions, these switches will immediately execute a rollback operation of the communication policy. They will disable advanced forwarding permissions on cross-network interconnection ports temporarily opened for cross-network takeover and reactivate the strict default security partition policy. This policy forces switches to resume domain-identity-based filtering checks. All FC frames with source or destination addresses whose domain identifiers do not belong to this subnet will be blocked and discarded. Simultaneously, the network controller of the first FC-AE-1553 subnet, which has recovered, begins reinitialization, loading its default configuration. Its communication whitelist only includes network terminal addresses within this subnet, and it resumes sending heartbeat telemetry information, declaring itself the legitimate controller of the network. This recovery operation ensures that the network controller of the second FC-AE-1553 subnet releases its temporarily acquired external management privileges, and the data planes of all relevant switches revert to a strict intra-domain communication mode. This allows both FC-AE-1553 subnets to exit collaborative management mode and fully revert to their initial, isolated, independent operating mode.
[0051] The management authority of the network controller in the second FC-AE-1553 subnet refers to its legitimate qualification to communicate and control network terminals within the first FC-AE-1553 subnet during authorized cross-network takeover. Operationally, this authority manifests as a communication whitelist containing globally unique FC addresses of all network terminals within the first FC-AE-1553 subnet. This allows the controller to send command frames to these terminals and receive responses according to the FC-AE-1553 protocol specifications, thereby scheduling and managing their communication services. By default, this network controller does not possess this cross-subnet management authority.
[0052] The communication policy of the relevant switches refers to the set of forwarding and filtering rules applied by the switches of the first FC-AE-1553 subnet and the switches of the second FC-AE-1553 subnet during collaborative management, which allow specific cross-subnet communication data to pass through. This includes temporary modifications to security partition policies to enable cross-network communication, special permission rules set for cross-network interconnection ports, and quality of service priority settings that may be adjusted to protect takeover traffic. The recovery operation is to revert these policies that were temporarily changed to support cross-network takeover.
[0053] The default state refers to the baseline operating configuration of the multi-domain FC-AE-1553 network when no collaborative management mechanism is triggered. In this state, each FC-AE-1553 subnet is a logically self-consistent and closed independent system. Specifically, the communication whitelist of each subnet's network controller only contains the network terminal addresses within its own subnet, and each subnet's switch enforces a strict security partitioning policy. This policy prohibits any FC data frames whose domain identifier does not belong to its own subnet from passing through, thereby achieving complete isolation between subnets at the communication layer and ensuring the independence and determinism of each network.
[0054] Optionally, the above technical solution also includes: The service traffic scheduled by the network controller of the second FC-AE-1553 subnet is classified and configured with quality of service (QoS) priorities. Critical management traffic from network terminals in the taken-over first FC-AE-1553 subnet is configured with a higher forwarding priority than regular task data. The specific implementation process is as follows: ① The network controller of the second FC-AE-1553 subnet identifies and classifies all service traffic that needs to be scheduled. When the network controller of the second FC-AE-1553 subnet takes over the network terminal services of the first FC-AE-1553 subnet, the data flow it schedules will simultaneously include services from its original subnet and services from the subnet being taken over. According to a predefined strategy, these service traffic are divided into different categories based on the content, source, or type of the data frames. Specifically, heartbeat information, status acknowledgment messages, and control command responses from network terminals of the first FC-AE-1553 subnet being taken over are identified as critical management traffic. Non-critical batch data transmission, routine file exchange, or application data with low real-time requirements from both subnets are classified as routine task data.
[0055] ② After traffic classification is completed, the network controller and switches will collaboratively execute Quality of Service (QoS) priority configuration. When generating or forwarding data frames, the network controller writes the corresponding priority flag in the service type or priority field of the Fibre Channel frame header based on the classification results. Data frames identified as critical management traffic are marked with the highest priority; regular task data are marked with the standard priority. Subsequently, the switches carrying these data streams, especially the switches in the second FC-AE-1553 subnet and the first FC-AE-1553 subnet, will enable a service level-based priority scheduling mechanism on their ports. The switch hardware will detect the priority flag of inbound data frames and place them into the corresponding priority output queue. In the event of network congestion, the switch's scheduling algorithm will ensure that the queue of critical management traffic marked with the highest priority is prioritized for scheduling and forwarding, while the queue of regular task data is processed subsequently. This complete mechanism from traffic identification and frame marking to queue scheduling ensures that critical management commands can be transmitted in a low-latency, highly reliable manner during the special period of cross-network takeover, thereby maintaining the basic control and stability of the entire taken-over network.
[0056] Critical management traffic refers to a series of communication data necessary to maintain the basic control functions of the taken-over subnet during cross-network takeover. This type of traffic typically features small data volume, short intervals, but extremely high requirements for transmission timeliness and reliability. Specifically, it includes heartbeat messages for continuously monitoring the liveness of network terminals, response messages to confirm whether control commands have been correctly received and executed, reconfiguration commands for emergency situations, and status synchronization data to maintain basic management functions. Their smooth transmission directly affects the effectiveness and stability of control during fault recovery.
[0057] Routine task data refers to application-layer business data generated by network terminals performing their designated functions during normal network operation. This type of data typically constitutes the main part of the network load. Its characteristics include potentially large data volumes, but relatively low sensitivity to transmission latency and jitter, and the ability to tolerate a certain degree of queuing and bandwidth fluctuations. Specifically, it can include batch-recorded data collected from sensors, log files from non-real-time tasks, pre-loaded task parameter packages, and non-critical periodic telemetry data. When resources are strained, the transmission of this type of data can be appropriately delayed to ensure the timeliness of critical management traffic.
[0058] Another embodiment will be used to further explain the collaborative management method of a multi-domain FC-AE-1553 network according to the present invention.
[0059] For the complex system of a multi-domain FC-AE-1553 network consisting of multiple FC-AE-1553 subnets interconnected by switches, this invention provides a collaborative management method for multi-domain FC-AE-1553 networks. The core of this method lies in proposing a complete collaborative management scheme for multi-domain FC-AE-1553 networks. This scheme specifically covers the establishment of the interconnection architecture of the multi-domain FC-AE-1553 networks, the network configuration strategy for cross-network collaborative management, the complete process of network controllers taking over network terminals in faulty subnets across networks, and exiting takeover after fault recovery. By constructing a physical foundation based on dedicated optical fiber interconnection, implementing network configuration centered on global addressing and logical security partitioning, and defining clear operation sequences for fault monitoring, confirmation, configuration switching, service takeover, and state recovery, this scheme achieves cross-domain sharing and mutual backup of network controller resources in each FC-AE-1553 subnet. This method effectively overcomes the limitations of traditional independent redundancy schemes, such as low resource utilization and inability to handle cross-network faults, thus achieving a comprehensive goal of low cost, high resource utilization, and high reliability at the system level. Specifically: (1) Establishment of the interconnection architecture of the multi-domain FC-AE-1553 network: In a multi-domain FC-AE-1553 network, each FC-AE-1553 subnet is a standard and fully functional FC-AE-1553 network. All FC-AE-1553 subnets share the same network components, including their respective network controllers, network terminals, and switches. Each independent FC-AE-1553 subnet is interconnected via dedicated cross-network fiber optic cables between its switches, thus achieving physical bridging of multiple FC-AE-1553 subnets. The switches in each FC-AE-1553 subnet identify and forward cross-network communication data as needed according to configured policies, providing underlying communication support for cross-network collaborative management. For example... Figure 3 As shown, three independent FC-AE-1553 subnets are illustrated, labeled FC Subnet 1, FC Subnet 2, and FC Subnet 3. Each FC-AE-1553 subnet contains a network controller as the control core, multiple network terminals as service execution units, and a switch as a communication hub. All network controllers and network terminals within a subnet are connected to the subnet's switch via fiber optic links. The key to achieving cross-subnet interconnection lies in the interconnection of the switches in each subnet through dedicated cross-network fiber optic links. These interconnection links connect the switches in FC Subnet 1, FC Subnet 2, and FC Subnet 3, forming a unified physical network infrastructure. This architecture ensures that each FC-AE-1553 subnet can operate independently under the default logical isolation policy. At the same time, when collaborative management is required, it provides a stable and reliable data transmission channel for the network controller to take over the network terminal services of a faulty subnet across networks.
[0060] The multi-domain FC-AE-1553 network is physically connected via dedicated cross-network fiber optic interconnects between the switches of each FC-AE-1553 subnet. However, it needs to maintain isolation in its design logic. During normal operation, each FC-AE-1553 subnet maintains its inherent independence and determinism through logical isolation and security partitioning policies implemented on its switches. Controllable cross-network communication is only conducted under specific requirements, such as fault takeover or global task scheduling, through authorized configuration operations. The dedicated interconnects between the switches used to cascade the FC-AE-1553 subnets in the multi-domain FC-AE-1553 network must have sufficient bandwidth and deterministic low latency to meet the real-time requirements of critical management information such as fault takeover commands during cross-network transmission. The interconnection architecture of this multi-domain FC-AE-1553 network has good scalability and can support the flexible increase of the number of FC-AE-1553 subnets. To add an FC-AE-1553 subnet, you only need to connect its switch to the existing interconnection architecture through a dedicated cross-network fiber optic cable. There is no need to change the core interconnection and collaborative management principles such as cross-network redundancy backup and takeover of the network controller, routing of switches based on domain identifiers, and dynamic reconfiguration capabilities.
[0061] (2) Network configuration for cross-network collaborative management: To enable cross-network fault takeover by the network controller in a multi-domain FC-AE-1553 network, in addition to the dedicated cross-network fiber optic interconnection between the switches of each FC-AE-1553 subnet, a complete logical management strategy is required for network configuration. The core design principle of this strategy is default isolation and on-demand connectivity. Specifically, in the default state, strict logical isolation and security partitioning policies are configured on the switches of each FC-AE-1553 subnet to ensure that each subnet operates independently and prohibits any cross-subnet communication. When fault takeover or global task scheduling is required, the communication whitelist of the network controller and the communication policies of relevant switches are dynamically adjusted through authorized configuration operations, temporarily and controllably opening cross-network communication paths. This allows the network controller to take over network terminal services in the faulty subnet, specifically including: 1) Logical isolation and security partitioning strategies: ① Default Configuration (Isolated State): A strict security partitioning policy needs to be established and implemented in the switch configuration of each FC-AE-1553 subnet. Each independent FC-AE-1553 subnet is logically divided into its own dedicated partition. This partitioning rule ensures unimpeded communication between network controllers and network terminals within the subnet, while strictly prohibiting any communication across FC-AE-1553 subnets. Each FC-AE-1553 subnet's network controller can freely communicate with all network terminals within its subnet through the subnet's switch. Any communication request attempting to access devices within another FC-AE-1553 subnet from one subnet, such as accessing a network terminal in subnet 2 from subnet 1, will be directly discarded by the switch of its originating subnet according to the security partitioning policy. This effectively prevents unauthorized cross-network access and potential broadcast storms, ensuring the security boundaries of each FC-AE-1553 subnet. The globally unique FC address of each network controller and network terminal of the FC-AE-1553 subnet should be configured within the dedicated partition planned by the subnet switch. In addition, the communication whitelist configured inside the network controller of each FC-AE-1553 subnet by default only includes the network terminal addresses within the dedicated partition of its own subnet. This configuration works together to ensure the determinism and real-time performance of its FC-AE-1553 subnet when operating independently.
[0062] ② Collaborative Management Configuration (Connectivity State): When collaborative management is enabled, switches in this FC-AE-1553 subnet will receive authorization commands from the management system. For identified cross-subnet communication requests, these requests will be transmitted from the cross-network interconnection port to other FC-AE-1553 subnets. When switches in this FC-AE-1553 subnet do not receive takeover authorization, only point-to-point cross-network access communication requests are allowed; broadcast messages are prohibited from passing through the cross-network interconnection port. When switches in this FC-AE-1553 subnet receive takeover authorization, broadcast messages can also be transmitted across networks. When the network controller of this FC-AE-1553 subnet does not receive takeover authorization, its communication whitelist only includes network terminal addresses within the subnet's dedicated partition. When the network controller of this FC-AE-1553 subnet receives takeover authorization, its communication whitelist will include not only the network terminal addresses within its own subnet's dedicated partition, but also the network terminal addresses within the dedicated partition of the subnet being taken over. This enables the network controller to take over all network terminal services within the faulty subnet across networks, facilitating multi-domain FC-AE-1553 network collaborative management. Both switches and network controllers need to have dynamic reconfiguration capabilities, allowing them to enter collaborative management mode to perform takeover functionality based on authorization commands, and to exit collaborative management mode to restore independent subnet operation after fault recovery.
[0063] 2) Global addressing scheme: To ensure correct message routing across the network, a globally unified address planning scheme is required for the multi-domain FC-AE-1553 network. Each network controller or network terminal node must have a unique FC address within the global network. This FC address is a 24-bit address in the Fibre Channel standard. In this scheme, it can be structurally broken down into three core fields, each with a specific meaning: domain identifier, area identifier, and port identifier. Each identifier field consists of 8 bits. The combination of these three fields constitutes a 24-bit global address that conforms to the FC standard and has a clear hierarchical semantics, such as... Figure 4 As shown.
[0064] In this globally unified address planning scheme, domain identifiers are assigned specific codes, such as 00H for subnet 1, 01H for subnet 2, and 02H for subnet 3. The domain identifier is the highest-order and most crucial component of the FC address; it uniquely identifies the FC-AE-1553 subnet to which a node belongs. It is also the key identifier that switches first check during routing decisions to distinguish between local and cross-network messages. Area identifiers can be flexibly defined according to the actual network topology and management needs. For example, the address range 00H to 0FH can be allocated to backbone network devices, and the address range 10H to 1FH can be allocated to access network devices. Port identifiers are typically associated with or directly mapped to the physical port number of the switch. Based on the address allocation strategy for each FC-AE-1553 subnet node, the switch in each FC-AE-1553 subnet can correctly route messages within its subnet based on the domain identifier field in the FC address. Under the default isolation configuration, if a switch detects that the domain identifier of a data frame does not belong to its FC-AE-1553 subnet, it will discard the frame directly according to the security partitioning policy. Table 1 illustrates the application of this addressing and naming method with specific examples.
[0065] Table 1: This hierarchical addressing scheme, consisting of domain identifiers, area identifiers, and port identifiers, combined with the management mechanism of the switch making routing decisions based on domain identifiers, forms the core foundation for the FC-AE-1553 network to be efficiently and reliably extended to a large-scale multi-domain system management architecture. It also provides the lowest-level, reliable global addressing and accurate routing guarantee for the solution of network controllers taking over network terminal services in faulty subnets across networks.
[0066] 3) Quality of Service (QoS) configuration: When a network controller takes over all network terminal nodes in a faulty subnet, the workload of the unified scheduling by the network controller will increase. To ensure the real-time performance of critical management traffic during the takeover process, all traffic flowing through the network controller needs to be reclassified and its quality of service (QoS) priorities configured. Based on the network's original default traffic classification, traffic demands from network terminals in the taken-over subnet need to be specifically identified and included. For example, critical short messages such as heartbeat messages and status acknowledgments from the taken-over subnet must be guaranteed to be transmitted in real-time and need to be marked as the highest priority; while routine task data from the taken-over subnet has relatively low real-time requirements and can be marked as standard priority. Correspondingly, a service level-based priority scheduling mechanism must be enabled and configured on the physical ports of the relevant switches. By detecting the priority markers of data frames and sending them to the corresponding output queues, it is ensured that in the event of network congestion, high-priority cross-domain management traffic is scheduled and forwarded with absolute priority over low-priority routine task data.
[0067] (3) Cross-network communication data flow: Taking the example of the network controller of FC subnet 1 needing to send a message to the network terminal NTx_2 of FC subnet 2, the specific data flow process is as follows: Network controller NC_1 encapsulates the generated service data in an FC frame, setting the destination address of the FC frame to the globally unique FC address of the target network terminal NTx_2; then, network controller NC_1 sends this FC frame to the switch SW_1 of its directly connected FC subnet; after receiving the FC frame, switch SW_1 parses the domain identifier field in its destination FC address, finds that the domain identifier does not belong to FC subnet 1, and therefore uses its pre-defined... The configured cross-network routing port forwards the FC frame to the switch SW_2 in the interconnected FC subnet 2. After the FC frame is routed to the switch SW_2 in the FC subnet 2 where the target domain identifier is located via the interconnection link, the switch SW_2 further performs a precise route lookup within the FC subnet 2 based on the area identifier and port identifier contained in the destination address inside the FC frame, and finally delivers the FC frame accurately to the target network terminal NTx_2. After the target network terminal NTx_2 successfully receives the FC frame, its reply message will follow the reverse path back to the network controller NC_1 that initiated the request. Figure 5 This complete process is described. Figure 5The diagram illustrates how network controller NC_1, located in FC subnet 1 on the left, initiates communication. The FC frame it generates is transmitted through switch SW_1 in this FC subnet. After identifying the destination address as an address across FC subnets, the switch forwards the FC frame to switch SW_2 in FC subnet 2 on the right via the cross-network interconnection link. Switch SW_2 then delivers the frame to the target network terminal NTx_2. The diagram clearly shows the arrows indicating the flow of the FC frame from NC_1 to SW_1 and then to SW_2, finally reaching NTx_2, as well as the reverse path of the response frame from NTx_2 through SW_2 and SW_1 back to NC_1, intuitively demonstrating the bidirectional data flow of end-to-end communication across FC subnets.
[0068] (4) Takeover process for cross-network collaborative management: Based on the aforementioned multi-domain FC-AE-1553 network interconnection architecture and technical solution, the complete takeover and recovery process for cross-network collaborative management is as follows: First, a status monitoring step is executed. This involves continuously receiving and analyzing key telemetry information, such as heartbeats, periodically transmitted by the network controllers of each independently operating FC-AE-1553 subnet to monitor their operational status. Next, a fault confirmation step is performed. When the ground monitoring system comprehensively judges and confirms, based on the received key telemetry information, that a network controller of a certain FC-AE-1553 subnet has failed and its managed network services have been interrupted, a network configuration switching step is initiated. The ground system sends an uplink command to the network controller of the faulty network to power it down, and simultaneously sends an uplink command to the switch of the faulty network to authorize it to enable cross-network takeover functionality. After receiving authorization, the faulty network switch enables its cross-network interconnection port and configures it to allow cross-network data transmission and broadcast messages required for takeover. Simultaneously, the ground system sends an uplink command to the network controller in the healthy network that is scheduled to perform takeover, authorizing it to switch its communication whitelist, ensuring that its communication whitelist includes network terminals within its own subnet. Based on the existing address, the system adds the addresses of all network terminals within the faulty subnet partition and sends uplink commands to the switches in the healthy subnet, authorizing them to enable cross-network interconnection ports and takeover configurations, allowing broadcast messages to be transmitted across networks. Then, the system proceeds to the service takeover step. After the communication whitelist is switched, the taking-over network controller can establish communication with all network terminals in the faulty subnet through the cross-network path formed by the subnet switches and the faulty subnet switches, and ensure high-priority transmission of critical management traffic according to the preset quality of service policy. Finally, after the faulty network controller is repaired, the system executes the status recovery step. The ground system sends uplink commands to cause the taking-over network controller to exit takeover mode, switches its communication whitelist back to the default configuration that only includes the addresses of network terminals in its own subnet, and instructs the switches in both the faulty and taking-over subnets to revert to the default configuration that prohibits cross-subnet communication. After the original faulty network controller is powered on, it is reinitialized and restored to normal working mode, resuming its role as the network controller of its subnet and as a potential backup node for other subnets in the system, thus completing the entire management cycle of cross-network fault takeover and recovery.
[0069] In another possible approach, a dedicated backup network controller is configured independently for each FC-AE-1553 subnet. When the primary network controller of a subnet fails, its internally configured dedicated backup network controller immediately takes over control functions. However, in this scheme, each subnet's backup network controller remains idle for extended periods while its primary network controller is operating normally, resulting in wasted hardware resources. Furthermore, this scheme can only handle the failure of a single network controller and cannot effectively address subnet-level system-wide failures or extreme scenarios where both primary and backup network controllers fail, thus failing to fundamentally improve system-level reliability. Additionally, the backup network controller resources of each subnet cannot be shared and coordinated across subnets, lacking global resource optimization and configuration capabilities.
[0070] In another feasible approach, a dedicated, powerful global backup network controller is set up. If the network controller of any FC-AE-1553 subnet fails, this centralized global backup network controller takes over. However, this global backup network controller, as an independent physical node, also faces the risk of a single point of failure. If this central node fails, the redundancy backup function of the entire multi-domain FC-AE-1553 network will completely fail, introducing a new critical vulnerability into the architecture. The dedicated global backup network controller in this solution also increases hardware costs, and the system architecture of the entire multi-domain FC-AE-1553 network becomes more complex to achieve its connection and control with all subnets.
[0071] In traditional solutions, each FC-AE-1553 subnet requires an independent configuration of one primary and one backup network controller, or even multiple controllers, leading to long-term idle backup resources and significant waste of hardware and space resources. As complexity increases, and as a single FC-AE-1553 network evolves into a multi-domain FC-AE-1553 network composed of interconnected subnets, this invention innovatively adopts a "one-backup-many" resource-sharing model. This allows the network controller resources of each FC-AE-1553 subnet to provide backup capabilities for other FC-AE-1553 subnets, thereby reducing the number of redundant network controllers. This directly reduces the overall cost, weight, and power consumption of the multi-domain FC-AE-1553 network, achieving a balance between optimized resource allocation and cost control. Meanwhile, this solution overcomes the limitations of traditional single-network internal redundancy, achieving fault-tolerant backup across FC-AE-1553 subnets. When the network controller of one FC-AE-1553 subnet fails, its functions can be quickly taken over by the network controllers of other healthy FC-AE-1553 subnets, thus avoiding the serious consequence of a single node failure causing the entire subnet's communication service to be interrupted. The architecture design of this invention is independent of the number of FC-AE-1553 subnets; adding a new FC-AE-1553 subnet only requires interconnecting it with the existing architecture via a switch, without modifying the hardware connections of existing FC-AE-1553 subnets, thus possessing excellent scalability and deployment flexibility. Ultimately, the technical solution of this invention fundamentally improves the task continuity and survivability of complex large-scale systems composed of multiple FC-AE-1553 networks, making it particularly suitable for fields with extremely high reliability requirements, such as aviation, aerospace, and military industries. This invention, through its innovative distributed, cross-network, and resource-sharing architecture, successfully avoids the drawbacks of resource waste, reliability defects, and high implementation complexity, thereby improving overall performance and providing a superior technical path.
[0072] Although the steps have been numbered in the above embodiments, they are only specific embodiments given by the present invention. Those skilled in the art can adjust the execution order of the steps according to the actual situation, which is also within the protection scope of the present invention. It can be understood that some embodiments may include some or all of the above embodiments.
[0073] like Figure 6As shown in the figure, a collaborative management system 200 for a multi-domain FC-AE-1553 network according to an embodiment of the present invention is provided. The multi-domain FC-AE-1553 network includes multiple FC-AE-1553 subnets interconnected by switches. Each FC-AE-1553 subnet includes a network controller, a network terminal and a switch. The collaborative management system 200 for the multi-domain FC-AE-1553 network includes a configuration implementation module 201, a monitoring and fault judgment module 202, an authorization configuration module 203 and an execution recovery module 204. The configuration implementation module 201 is used to: configure addresses for each network controller and each network terminal, and implement security partitioning policies on the switches of each FC-AE-1553 subnet, so that each FC-AE-1553 subnet can operate independently by default and cross-subnet communication is prohibited; The fault detection module 202 is used to: monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault detection; The authorization configuration module 203 is used to: when the network controller of the first FC-AE-1553 subnet is confirmed to have failed, through authorization configuration operation, enable the switch of the first FC-AE-1553 subnet to allow cross-subnet communication, and enable the second FC-AE-1553 subnet to take over the services of the network terminals of the first FC-AE-1553 subnet; The recovery module 204 is used to: after the network controller of the first FC-AE-1553 subnet is restored, perform a recovery operation to restore the management authority of the network controller of the second FC-AE-1553 subnet and the communication policy of the relevant switches to the default state; Among them, the first FC-AE-1553 subnet and the second FC-AE-1553 subnet are two different FC-AE-1553 subnets in the multi-domain FC-AE-1553 network.
[0074] Optionally, in the above technical solution, the configuration implementation module 201 is further specifically used to: allocate a globally unique 24-bit FC address to each network controller and each network terminal. The 24-bit FC address includes a domain identifier, a region identifier, and a port identifier. The domain identifier is used to uniquely identify the FC-AE-1553 subnet to which the network controller and network terminal belong.
[0075] Optionally, the above technical solution also includes a priority configuration module, which is used to: classify and configure quality of service priorities for service traffic scheduled by the network controller of the second FC-AE-1553 subnet, and configure a higher forwarding priority for critical management traffic from network terminals of the first FC-AE-1553 subnet that has been taken over than for regular task data.
[0076] Optionally, in the above technical solution, the fault monitoring and judgment module 202 is specifically used to: monitor the operating status of the network controller of each FC-AE-1553 subnet through heartbeat telemetry information and perform fault judgment.
[0077] It should be noted that the beneficial effects of the multi-domain FC-AE-1553 network collaborative management system 200 provided in the above embodiments are the same as those of the multi-domain FC-AE-1553 network collaborative management method described above, and will not be repeated here. Furthermore, the system provided in the above embodiments is only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the system can be divided into different functional modules according to the actual situation to complete all or part of the functions described above. In addition, the system and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiments, and will not be repeated here.
[0078] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the above-described collaborative management methods for multi-domain FC-AE-1553 networks. The electronic device can also be a terminal device, which can be any device capable of installing applications, including at least one of smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, smart TVs, and smart in-vehicle devices.
[0079] An embodiment of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the above-described collaborative management methods for multi-domain FC-AE-1553 networks.
[0080] It should be understood that the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0081] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this invention.
[0082] It should be noted that the terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and represent a limitation on a specific order or sequence. Where appropriate, the order of use for similar objects can be interchanged so that the embodiments of this application described herein can be implemented in an order other than that shown or described.
[0083] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A collaborative management method for a multi-domain FC-AE-1553 network, characterized in that, A multi-domain FC-AE-1553 network comprises multiple FC-AE-1553 subnets interconnected by switches. Each FC-AE-1553 subnet includes a network controller, network terminals, and switches. The method includes: Configure addresses for each network controller and each network terminal separately, and implement a security partitioning policy on the switch of each FC-AE-1553 subnet so that each FC-AE-1553 subnet can operate independently by default and cross-subnet communication is prohibited. Monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault diagnosis; When the network controller of the first FC-AE-1553 subnet is confirmed to have failed, an authorized configuration operation is performed to enable the switches of the first FC-AE-1553 subnet to allow cross-subnet communication, and to enable the second FC-AE-1553 subnet to take over the services of the network terminals of the first FC-AE-1553 subnet. After the network controller of the first FC-AE-1553 subnet is restored, a restoration operation is performed to restore the management permissions of the network controller of the second FC-AE-1553 subnet and the communication policies of the relevant switches to the default state. The first FC-AE-1553 subnet and the second FC-AE-1553 subnet are two different FC-AE-1553 subnets in the multi-domain FC-AE-1553 network.
2. The collaborative management method for a multi-domain FC-AE-1553 network according to claim 1, characterized in that, Configure addresses for each network controller and each network terminal separately, including: Each network controller and each network terminal is assigned a globally unique 24-bit FC address. The 24-bit FC address includes a domain identifier, a region identifier, and a port identifier. The domain identifier is used to uniquely identify the FC-AE-1553 subnet to which the network controller and network terminal belong.
3. The collaborative management method for a multi-domain FC-AE-1553 network according to claim 1, characterized in that, Also includes: The service traffic scheduled by the network controller of the second FC-AE-1553 subnet is classified and service quality priority is configured. The critical management traffic from the network terminals of the first FC-AE-1553 subnet that is being taken over is configured with a higher forwarding priority than regular task data.
4. A collaborative management method for a multi-domain FC-AE-1553 network according to any one of claims 1 to 3, characterized in that, Monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault diagnosis, including: The operating status of the network controller of each FC-AE-1553 subnet is monitored and fault diagnosis is performed using heartbeat telemetry information.
5. A collaborative management system for a multi-domain FC-AE-1553 network, characterized in that, The multi-domain FC-AE-1553 network includes multiple FC-AE-1553 subnets interconnected by switches. Each FC-AE-1553 subnet contains a network controller, network terminals, and switches. The system includes a configuration implementation module, a monitoring and fault diagnosis module, an authorization configuration module, and an execution recovery module. The configuration implementation module is used to: configure addresses for each network controller and each network terminal respectively, and implement a security partitioning policy on the switch of each FC-AE-1553 subnet, so that each FC-AE-1553 subnet can operate independently by default and cross-subnet communication is prohibited; The monitoring and fault judgment module is used to: monitor the operating status of the network controller of each FC-AE-1553 subnet and perform fault judgment; The authorization configuration module is used to: when the network controller of the first FC-AE-1553 subnet is confirmed to have failed, through authorization configuration operation, enable the switch of the first FC-AE-1553 subnet to allow cross-subnet communication, and enable the second FC-AE-1553 subnet to take over the services of the network terminals of the first FC-AE-1553 subnet; The execution recovery module is used to: when the network controller of the first FC-AE-1553 subnet recovers, perform a recovery operation to restore the management authority of the network controller of the second FC-AE-1553 subnet and the communication policy of the relevant switches to the default state; The first FC-AE-1553 subnet and the second FC-AE-1553 subnet are two different FC-AE-1553 subnets in the multi-domain FC-AE-1553 network.
6. The collaborative management system for a multi-domain FC-AE-1553 network according to claim 5, characterized in that, The configuration implementation module is further specifically used to: allocate a globally unique 24-bit FC address to each network controller and each network terminal. The 24-bit FC address includes a domain identifier, a region identifier, and a port identifier. The domain identifier is used to uniquely identify the FC-AE-1553 subnet to which the network controller and network terminal belong.
7. The collaborative management system for a multi-domain FC-AE-1553 network according to claim 5, characterized in that, It also includes a priority configuration module, which is used to: classify and configure quality of service priorities for service traffic scheduled by the network controller of the second FC-AE-1553 subnet, and configure a higher forwarding priority for critical management traffic from network terminals of the first FC-AE-1553 subnet that has been taken over than for regular task data.
8. A collaborative management system for a multi-domain FC-AE-1553 network according to any one of claims 5 to 7, characterized in that, The monitoring and fault judgment module is specifically used to: monitor the operating status of the network controller of each FC-AE-1553 subnet through heartbeat telemetry information and make fault judgments.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the collaborative management method for a multi-domain FC-AE-1553 network as described in any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements a collaborative management method for a multi-domain FC-AE-1553 network as described in any one of claims 1 to 4.
Citation Information
Patent Citations
FC-AE-1553 bus node card capable of interchangeably achieving functions of network controller and network terminal
CN103905281A
Cross-network message forwarding method and switch system
CN102340436A
Heterogeneous FC-AE-1553 network system and exchange method
CN104618207A
Multi-NC (network controller) star topological structure on basis of FC-AE-1553 (fiber channel-avionics environment-1553) protocols
CN104954217A
Multi-functional domain multi-master control FC-AE-1553 switching network model and management method
CN108600871A