A clock synchronization control method and system for a multiple redundant control system

By implementing unified selection and phase-locked loop of clock sources through FPGA hardware, the problems of low synchronization accuracy and large switching jitter in multi-redundant control systems are solved. High-precision clock synchronization and disturbance-free switching between controllers are achieved, improving the reliability and response speed of the system.

CN121325550BActive Publication Date: 2026-04-07BEIJING CONSEN AUTOMATION CONTROL
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In the existing technology, clock synchronization in multi-redundant control systems suffers from low synchronization accuracy, large switching jitter, and reliance on software intervention, resulting in inconsistent outputs, system response delays, and switching shocks.

Method used

The unified selection and phase-locked loop of the clock source are implemented using FPGA hardware. By combining clock broadcasting, health diagnosis, master/slave status decision and phase-locked loop (PLL), high-precision synchronization at the microsecond or even nanosecond level is achieved, and there is no disturbance during master/slave switching.

Benefits of technology

It achieves high-precision clock synchronization between controllers, eliminates frequency deviation, avoids clock jumps, improves system robustness and response speed, and reduces CPU load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121325550B_ABST
    Figure CN121325550B_ABST
Patent Text Reader

Abstract

The application provides a clock synchronization control method and system of a multiple redundancy control system. It relates to the technical field of industrial automation control. The method comprises the following steps: each controller broadcasts and receives a synchronization clock and a synchronization pulse; a high-frequency diagnostic clock is used to perform health diagnosis on the clock signal; the master-slave state is determined in combination with the processor state and the master-slave switching logic; the target clock source is selected through a priority strategy according to the health state and the master-slave state; the target clock source is input into a phase-locked loop for locking and smoothing to generate a system driving clock; the clock is used to drive the local timing, and the synchronization time count value of the master controller is loaded through a backplane data link to realize initial absolute time synchronization. The application realizes the unified selection and phase locking of the clock source through FPGA hardware, prevents multiple master conflicts in combination with a double-timer mechanism, realizes microsecond-level high-precision synchronization and clock non-disturbance transition during master-slave switching, and improves the reliability and real-time performance of the system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of industrial automation control technology, in particular to a multiple redundant control system and a clock synchronization control method applied in a safety instrumented system (SIS), a distributed control system (DCS) or a programmable logic controller (PLC), and more particularly to a clock synchronization control method and system of a multiple redundant control system. BACKGROUND

[0002] Currently, in the field of industrial process control safety, in order to improve the reliability and safety of the system, a multiple redundant control system is usually used, such as a dual, triple or quadruple redundant system. In these systems, multiple redundant controllers need to run synchronously: simultaneously collect inputs, execute the same control logic, and simultaneously output control signals.

[0003] If the time synchronization between the redundant controllers is deviated, the following problems will be caused:

[0004] 1. Inconsistent output: Asynchronous may cause different handling times of the same event by the controllers, and then cause inconsistent output results in a short time, affecting the voting mechanism of the system.

[0005] 2. System response delay: In order to wait for synchronization, the system may need to artificially increase the waiting period, reducing the overall response speed.

[0006] 3. Switching jitter: When the main controller fails and needs to be switched, if the clock of the standby controller is greatly deviated from that of the main controller, it will cause the jump of the control period, and in severe cases, it will trigger the safety interlock to cause shutdown.

[0007] In the prior art, such as the patent with publication number CN104796213B, a software adjustment or a simple hardware counter correction method is usually used. These methods have the following significant defects:

[0008] 1. Strong software dependence: The CPU needs to calculate the deviation periodically and adjust it, which consumes CPU resources and is affected by software interruption, and the jitter is large.

[0009] 2. Local crystal oscillator cumulative error: Even if periodic calibration is performed, between two calibration points, each controller still relies on the local crystal oscillator to run, and the temperature drift and frequency deviation of the crystal oscillator itself will cause the phase to gradually diverge.

[0010] 3. Switching impact: When the reference clock source fails, directly switching to another clock source often causes phase mutation.

[0011] Therefore, there is an urgent need for a clock synchronization scheme based on the hardware bottom layer, which can achieve microsecond-level or even nanosecond-level high-precision synchronization, and has no disturbance during the switching of the master and the backup. SUMMARY

[0012] The purpose of this invention is to provide a multi-redundant control system and a clock synchronization control method, which realizes the unified selection and phase-locking of the clock source through FPGA hardware, and solves the problems of low synchronization accuracy, large switching jitter and reliance on software intervention in traditional solutions.

[0013] To address the aforementioned technical problems, this invention proposes a clock synchronization control method for a multi-redundant control system.

[0014] The first aspect of this invention discloses a clock synchronization control method for a multi-redundant control system; applied to a redundant control system including at least two controllers, the controllers being interconnected via a backplane bus and a data communication link; each controller includes a processor, an FPGA module, a local clock source, and a local clock timing module; the method includes the following steps:

[0015] Step S1 Clock Broadcasting and Receiving: Each controller generates a synchronization clock and synchronization pulse using its local clock source and broadcasts them to the backplane bus; at the same time, it receives synchronization clocks and synchronization pulses broadcast by other controllers.

[0016] Step S2 Clock Health Diagnosis: Perform real-time diagnosis of the synchronization clock frequency and synchronization pulse period of this controller and other controllers received, and generate clock health status;

[0017] Step S3 Primary / Backup Status Decision: Based on the processor health status and the clock health status, and combined with the preset primary / backup switching logic, determine the primary / backup status of this controller and broadcast it to other controllers;

[0018] Step S4 Clock source selection: Based on the clock health status and master / standby status of each controller, select a set of all available synchronization clocks and synchronization pulses as the target synchronization clock and target synchronization pulse;

[0019] Step S5 Clock Locking and Smoothing: Input the selected target synchronization clock into the phase-locked loop (PLL) for phase locking and jitter filtering, and output the system drive clock;

[0020] Step S6 Synchronization Timing: The system drive clock drives the local clock timing module to perform timing; in the initial synchronization phase, the backup controller loads the synchronization time based on the synchronization time count value sent by the primary controller through the data communication link and the target synchronization pulse, thereby achieving absolute time synchronization.

[0021] Preferably, the specific method for clock health diagnosis in step S2 is as follows:

[0022] A diagnostic clock with a frequency N times higher than the synchronous clock is used as a reference;

[0023] The interval between two consecutive rising edges of the synchronous clock being diagnosed is counted. If the deviation of the count value from the nominal value N exceeds the preset frequency deviation threshold, the synchronous clock frequency is determined to be abnormal.

[0024] The diagnostic clock is used to measure the time interval between two adjacent synchronization pulses. If the deviation of this time interval from the nominal period exceeds a preset period deviation threshold, the synchronization pulse is determined to be abnormal.

[0025] Preferably, the specific logic for clock source selection in step S4 is as follows:

[0026] Determine if a primary controller exists in the current system;

[0027] If there is a single master controller and its clock health is normal, then the synchronization clock and synchronization pulse of the master controller are selected as the target clock source.

[0028] If there are multiple master controllers, compare the priorities of each master controller and select the synchronization clock and synchronization pulse of the master controller with the highest priority as the target clock source;

[0029] If there is no primary controller, or the primary controller clock is abnormal, then the local synchronization clock and synchronization pulse of this controller shall be selected as the target clock source.

[0030] Preferably, the master / slave status decision in step S3 includes logic to prevent contention and multi-master conflicts, specifically including:

[0031] Principal promotion logic: When this controller is in standby mode and no primary controller is detected in the system, a principal promotion timer is started; the duration of the principal promotion timer is related to the priority of this controller, the higher the priority, the shorter the duration; when the principal promotion timer expires and no other primary controller is detected, this controller switches to primary mode.

[0032] Backup logic: When this controller is in primary mode and detects that there are multiple primary controllers in the system, including itself, a multi-primary backup timer is started; the duration of the multi-primary backup timer is related to the priority of this controller, and the lower the priority, the shorter the duration; when the multi-primary backup timer expires and multi-primary conflicts still exist, this controller switches to standby mode.

[0033] Preferably, the priority of the controller is determined based on the hardware slot ID of the controller; the smaller the hardware slot ID value, the higher the corresponding priority, the shorter the duration of the master promotion timer, and the longer the duration of the multi-master demotion timer.

[0034] Preferably, the initial synchronization step of the backup controller in step S6 specifically includes:

[0035] The primary controller predicts the synchronization time count value when the next synchronization pulse arrives and sends the count value to the backup controller via the data communication link.

[0036] The backup controller receives the count value and temporarily stores it in the preload register;

[0037] When the backup controller detects the arrival of the effective edge of the target synchronization pulse, it immediately writes the count value in the preload register into the counter of the local clock timing module.

[0038] Preferably, in step S5, the phase-locked loop (PLL) is configured to maintain the continuity of the output phase and smoothly transition the output of the system drive clock when the source of the input target synchronization clock is switched.

[0039] Preferably, the data communication link is a backplane low-voltage differential signal LVDS high-speed serial link. A second aspect of this invention discloses a multi-redundancy control system; the system employs the clock synchronization control method of the aforementioned multi-redundancy control system. The system includes at least two controllers interconnected via a backplane, each controller including a processor, a local clock source, and an FPGA chip, wherein the FPGA chip is internally configured with:

[0040] The clock diagnostic module is used to receive the synchronization clock and synchronization pulse from this controller and other controllers, perform frequency and period detection using a high-frequency diagnostic clock, and output the clock health status.

[0041] The master / standby switching module is used to determine the master / standby status of this controller by executing the logic of promoting to master or delegating to standby based on the processor health status, clock health status, and master / standby status broadcast on the backplane.

[0042] The clock source selection module is used to select the target synchronization clock and target synchronization pulse from multiple signals according to the clock health status and master / slave status, and according to a preset priority strategy.

[0043] A phase-locked loop (PLL) is connected to the output of the clock source selection module and is used to perform phase-locking and filtering on the target synchronization clock to output a low-jitter system drive clock.

[0044] The clock timing module is connected to the phase-locked loop and the processor, and uses the system-driven clock for timing; the clock timing module is also connected to the data communication link, and is used to load the time count value sent by the master controller during initial synchronization.

[0045] Furthermore, the system is a dual-redundant, triple-redundant, or quadruple-redundant control system.

[0046] The beneficial effects of this invention are:

[0047] 1. Extremely high synchronization accuracy: By using clock source selection and phase-locked loop, all controllers can share a common reference clock frequency at the physical layer, eliminating frequency deviation and achieving synchronization accuracy at the FPGA clock cycle level.

[0048] 2. Seamless switching: The phase-locked loop (PLL) has phase holding and inertia characteristics. When the master clock source is lost or switched to a local or other clock source, the PLL can smoothly transition, avoiding the impact of clock jumps on the control logic.

[0049] 3. High reliability: The dual timer mechanism (promotion / demotion) effectively prevents multi-master conflicts and masterless deadlock, enhancing the robustness of the system.

[0050] 4. Reduced CPU load: All synchronization logic is completed within the FPGA, and the processor only needs to handle the initial time setting, freeing up CPU computing power to run the core control algorithm. Attached Figure Description

[0051] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0052] Figure 1 A flowchart of a clock synchronization control method for a multi-redundancy control system according to an embodiment of the present invention;

[0053] Figure 2 This is a schematic diagram of the overall architecture of the triple redundancy control system in an embodiment of the present invention;

[0054] Figure 3 This is the logic flowchart for initial time counter synchronization (two-step synchronization).

[0055] Figure 4 This is the logic control block diagram of the clock source selection module;

[0056] Figure 5 It is a detailed block diagram of the status transition and timing logic of the master / slave switchover module;

[0057] Figure 6 yes Figure 2 The enlarged view at point A is a detailed schematic diagram of the internal module connections of a single controller (Controller A). Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0059] The first aspect of this invention discloses a clock synchronization control method for a multi-redundant control system. Figure 1 This is a flowchart of a clock synchronization control method for a multi-redundancy control system according to an embodiment of the present invention, as shown below. Figure 1 As shown, the method is applied in a redundant control system comprising at least two controllers interconnected via a backplane bus and a data communication link; each controller includes a processor, an FPGA module, a local clock source, and a local clock timing module; the method includes the following steps: The method includes:

[0060] Step S1 Clock Broadcasting and Receiving: Each controller generates a synchronization clock and synchronization pulse using its local clock source and broadcasts them to the backplane bus; at the same time, it receives synchronization clocks and synchronization pulses broadcast by other controllers.

[0061] Step S2 Clock Health Diagnosis: Perform real-time diagnosis of the synchronization clock frequency and synchronization pulse period of this controller and other controllers received, and generate clock health status;

[0062] The specific method for clock health diagnosis in step S2 is as follows:

[0063] A diagnostic clock with a frequency N times higher than the synchronous clock is used as a reference;

[0064] The interval between two consecutive rising edges of the synchronous clock being diagnosed is counted. If the deviation of the count value from the nominal value N exceeds the preset frequency deviation threshold, the synchronous clock frequency is determined to be abnormal.

[0065] The diagnostic clock is used to measure the time interval between two adjacent synchronization pulses. If the deviation of this time interval from the nominal period exceeds a preset period deviation threshold, the synchronization pulse is determined to be abnormal.

[0066] Step S3 Primary / Standby Status Decision: Based on the processor health status and the clock health status, and combined with the preset primary / standby switching logic, determine the primary / standby status (primary or standby) of this controller, and broadcast it to other controllers;

[0067] The primary / standby state decision in step S3 includes logic to prevent contention and multi-primary conflicts, specifically including:

[0068] Principal promotion logic: When this controller is in standby mode and no primary controller is detected in the system, a principal promotion timer is started; the duration of the principal promotion timer is related to the priority of this controller, the higher the priority, the shorter the duration; when the principal promotion timer expires and no other primary controller is detected, this controller switches to primary mode.

[0069] Backup logic: When this controller is in primary mode and detects that there are multiple primary controllers in the system, including itself, a multi-primary backup timer is started; the duration of the multi-primary backup timer is related to the priority of this controller, and the lower the priority, the shorter the duration; when the multi-primary backup timer expires and multi-primary conflicts still exist, this controller switches to standby mode.

[0070] The priority of this controller is determined based on the hardware slot ID of the controller; the smaller the hardware slot ID value, the higher the corresponding priority, the shorter the duration of the master promotion timer, and the longer the duration of the multi-master demotion timer.

[0071] Step S4 Clock source selection: Based on the clock health status and master / standby status of each controller, select a set of all available synchronization clocks and synchronization pulses as the target synchronization clock and target synchronization pulse (collectively referred to as the target clock source).

[0072] The specific logic for clock source selection in step S4 is as follows:

[0073] Determine if a primary controller exists in the current system;

[0074] If there is a single master controller and its clock health is normal, then the synchronization clock and synchronization pulse of the master controller are selected as the target clock source.

[0075] If there are multiple master controllers, compare the priorities of each master controller and select the synchronization clock and synchronization pulse of the master controller with the highest priority as the target clock source;

[0076] If there is no primary controller, or the primary controller clock is abnormal, then the local synchronization clock and synchronization pulse of this controller shall be selected as the target clock source.

[0077] Step S5 Clock Locking and Smoothing: Input the selected target synchronization clock into the phase-locked loop (PLL) for phase locking and jitter filtering, and output the system drive clock;

[0078] In step S5, the phase-locked loop (PLL) is configured to maintain the continuity of the output phase and smoothly transition the output of the system drive clock when the source of the input target synchronization clock is switched.

[0079] Step S6 Synchronization timing: The local clock timing module is driven by the system driving clock to perform timing; in the initial synchronization phase, the backup controller loads the synchronization time based on the synchronization time count value sent by the primary controller through the data communication link and the target synchronization pulse to achieve absolute time synchronization.

[0080] The initial synchronization step of the backup controller in step S6 specifically includes:

[0081] The primary controller predicts the synchronization time count value when the next synchronization pulse arrives and sends the count value to the backup controller via the data communication link.

[0082] The backup controller receives the count value and temporarily stores it in the preload register;

[0083] When the backup controller detects the arrival of the effective edge (rising edge or falling edge) of the target synchronization pulse, it immediately writes the count value in the preload register into the counter of the local clock timing module.

[0084] In addition, the data communication link is a backplane low-voltage differential signal LVDS high-speed serial link.

[0085] Based on the clock synchronization control method of the aforementioned multi-redundancy control system, in some specific embodiments, the method is applied and implemented as follows:

[0086] Example 1: System Architecture

[0087] like Figure 2 and Figure 6 As shown, this system takes triple redundancy (controllers A, B, and C) as an example. The controllers transmit broadband signals (synchronization clock CLK, synchronization pulse PPS, and status bits) through the backplane bus and transmit high-speed data (time count values) through a dedicated LVDS link.

[0088] Each controller's FPGA contains core synchronization logic. The local crystal oscillator (e.g., 50MHz) serves only as an alternative source and diagnostic reference for this controller and does not directly drive system timing unless this controller is the primary one or the system is in stand-alone operation mode.

[0089] like Figure 2 As shown, this system includes three controllers (controllers A, B, and C). Each controller includes a processor, an FPGA, and a local clock. The FPGA internally includes a master / slave switching module, a clock diagnostic module, a clock source selection module, a phase-locked loop, and a clock timing module.

[0090] The at least two controllers are interconnected via a backplane bus. Each controller broadcasts its own synchronization clock and synchronization pulse signal to the backplane bus. Similarly, each controller also receives the synchronization clock and synchronization pulse signals from all other controllers from the backplane bus. Each controller broadcasts its own master / standby status and health status signals to the backplane bus. Likewise, each controller also receives the master / standby status and health status signals from all other controllers from the backplane bus.

[0091] The at least two controllers are interconnected via a backplane LVDS data communication link. The primary controller sends synchronization time count data packets to the backup controller via the backplane LVDS data communication link, and similarly, the backup controller also receives synchronization time count data packets from the primary controller via the backplane LVDS data communication link.

[0092] The local clock is a local clock source, which is output to the clock diagnostic module and clock source selection module of this controller and other controllers.

[0093] The clock diagnostic module receives synchronization clocks and pulses output from this controller and other controllers, diagnoses the frequency of the synchronization clocks and the period of the synchronization pulses, and outputs the health status of the synchronization clocks and pulses of this controller and other controllers to the clock source selection module and the master / standby switching module. The clock diagnostic module integrates a reference counter, which uses the diagnostic clock of this controller for timing. The diagnostic clock is an N-fold multiple of the synchronization clock. This module counts the interval between two consecutive rising edges of the synchronized clock being diagnosed, obtaining a count value. This count value is compared with a preset nominal value N. If the deviation exceeds a preset frequency deviation threshold (e.g., N=100, error threshold 1%, frequency deviation threshold is 1), the frequency of the synchronized clock is determined to be unhealthy. Simultaneously, the time between two adjacent synchronization pulses is measured using the reference counter. If this time is not equal to the nominal period (e.g., 1 second) ± a preset period deviation threshold (e.g., error threshold 0.5%, then period deviation threshold ± 5ms), the synchronization pulse is determined to be unhealthy.

[0094] The master / standby switching module receives the processor health status output by the processor itself and the health status of the controller's synchronization clock and synchronization pulse output by the clock diagnostic module. Based on the processor health status, synchronization clock health status, and synchronization pulse health status, it calculates the health status of the controller itself and outputs this health status to other controllers. The master / standby switching module also receives the master / standby status and health status output by other controllers. According to the master / standby switching logic, it performs the master / standby promotion / demotion of the controller and outputs the master / standby status of the controller itself to other controllers. Simultaneously, it outputs the master / standby status of the controller itself and that of other controllers to the clock source selection module and the processor.

[0095] The clock source selection module receives the synchronization clock and synchronization pulse output by this controller and other controllers, receives the health status of the synchronization clock and synchronization pulse of this controller and other controllers output by the clock diagnostic module, receives the master / slave status of this controller and other controllers output by the master / slave switching module, selects the master synchronization clock and synchronization pulse according to the source selection logic, and outputs the source-selected synchronization clock to the phase-locked loop and outputs the source-selected synchronization pulse to the clock timing module.

[0096] The phase-locked loop receives the synchronous clock output from the clock source selection module and outputs the locked synchronous clock to the clock timing module.

[0097] The clock timing module uses a synchronous clock output from a phase-locked loop for time counting and outputs the count value to the processor. At the exact second of the count, the clock timing module outputs a synchronization pulse to the clock diagnostic and clock source selection modules of this controller and other controllers. The standby controller's clock timing module receives the time setpoint written by the processor and the synchronization pulse input from the clock source selection module. On the rising edge of the synchronization pulse, it writes the time setpoint to the time counter, completing the initial time synchronization with the main controller. After initial time synchronization, it outputs a synchronization completion status to the processor.

[0098] The processor interconnects with the processors of other controllers via the LVDS data communication link on the backplane. When the primary controller detects a new controller joining the system, it actively sends the synchronization time count value corresponding to the next synchronization pulse to the new controller. After receiving the synchronization time count value from the primary controller, the newly joined controller writes the received synchronization time count value into its local clock timing module. When a master-slave switchover occurs, the new primary controller broadcasts its synchronization time count value corresponding to the next synchronization pulse to all standby controllers. After receiving the synchronization time count value from the primary controller, the standby controller writes the received synchronization time count value into its local clock timing module.

[0099] Example 2: Clock Source Selection and Phase Locking

[0100] refer to Figure 4 The clock source selection module is the core of synchronization.

[0101] Assume controller A is the primary controller, and B and C are backup controllers.

[0102] 1. A, B, and C all broadcast their own clocks CLK_A, CLK_B, and CLK_C.

[0103] 2. If the clock source selection modules of B and C detect that A is the master and A's clock is healthy (confirmed by the diagnostic module), then both B and C will select CLK_A as the input source.

[0104] 3. The selected CLK_A enters the phase-locked loop (PLL) of B and C. The PLL outputs clean SYS_CLK_B and SYS_CLK_C.

[0105] 4. At this point, the timing modules of the three controllers A, B, and C are actually all driven by CLK_A (and its derived clocks).

[0106] Therefore, their timing speeds are completely consistent and will not drift over time.

[0107] Specifically, the controller determines whether a master controller exists. If a master controller exists, it determines whether multiple master controllers exist. If multiple master controllers exist, the synchronization clock and synchronization pulse of the master controller with the highest priority are selected as the master synchronization clock and synchronization pulse. If only one master controller exists, its synchronization clock and synchronization pulse are selected as the master synchronization clock and synchronization pulse. If no master controller exists, the synchronization clock and synchronization pulse of this controller are selected as the master synchronization clock and synchronization pulse. The clock source selection module is implemented through the programmable logic of the FPGA. Through the clock source selection module, all controllers use the same synchronization clock for synchronization time counter counting, thereby achieving the goal of completely consistent counting frequencies of the synchronization clock counters of all controllers.

[0108] Example 3: Master / Slave Switchover and Anti-Content Contention Mechanism

[0109] refer to Figure 5 To address the common "who's in charge" problem in redundant systems, this invention designs a priority-based timer mechanism. Assume controller A has the highest priority (ID=1), followed by B (ID=2), and C has the lowest priority (ID=3).

[0110] Scenario 1: The system is powered on but there is no owner.

[0111] A, B, and C simultaneously start the master timer.

[0112] Set the timing threshold for A to 10ms, for B to 20ms, and for C to 30ms.

[0113] A was the first to complete the count, immediately ascended to the Lord and broadcast, "I am the Lord."

[0114] Upon receiving the master state broadcast from A, B and C immediately stop their own master promotion timers, switch to standby state, and begin following A's clock.

[0115] Scenario 2: Main controller A loses power.

[0116] B and C detected the main disappearance.

[0117] B and C restart the master timer (B=20ms, C=30ms).

[0118] B's countdown reaches full first, and B becomes the master. C detects that B has become the master, stops timing, and starts following B.

[0119] At this point, the clock source selection module activates, and both B and C (as well as the subsequently restored A) will switch to selecting CLK_B as the clock source. The PLL smoothly transitions during this process.

[0120] Scenario 3: Split-brain (multiple masters).

[0121] If a brief communication failure causes both A and B to believe they are the master.

[0122] After communication is restored, A and B exchange status updates.

[0123] Both A and B start multi-primary failover timers. The policy is set to failover first for the lower priority component.

[0124] The timing threshold for B (low priority) is set to a shorter time (e.g., 5ms), while that for A (high priority) is set to a longer time (e.g., 100ms).

[0125] B reaches its maximum capacity first and automatically degrades to standby. A remains in primary state. The system then reverts to a single primary state.

[0126] Specifically, the controller initializes its primary / standby state as a standby controller. This controller checks its own health status. If the health status is abnormal, the controller immediately and unconditionally degrades to a standby controller. If the health status is normal, it checks if a primary controller exists. If there is only one primary controller, no action is taken. If multiple primary controllers exist, including this controller, it checks if the multi-primary / standby timer for this controller has reached its full count. If it has, it immediately degrades to standby; otherwise, no action is taken. If no primary controller exists, it checks if the primary timer for this controller has reached its full count. If it has, it immediately becomes the primary controller; otherwise, no action is taken. The primary / standby switching module is implemented using the programmable logic of the FPGA, enabling fast and seamless switching between controllers.

[0127] The purpose of the master election timer is to implement priority arbitration and avoid contention. When no master controller exists, all healthy standby controllers start their own master election timer. The timer duration is set according to the controller's priority (e.g., determined by the hardware slot ID; the smaller the ID, the shorter the timer duration). The controller whose timer expires first will become the master and broadcast its master status. Other controllers, upon receiving this, will stop their own master election timers. This ensures that in a masterless state, there is always one and only one controller with the highest priority that becomes the master.

[0128] The multi-master standby timer is designed to address the "split-brain" problem, where multiple masters exist in the system due to communication failures. When a controller detects the presence of multiple masters, including itself, it starts the timer. The timer duration is linked to priority (longer timer for controllers with smaller IDs), and controllers with larger IDs will be the first to reach their timer limit and be demoted to standby, ultimately leaving only the highest-priority controller as the master.

[0129] Example 4: Initial Absolute Time Synchronization

[0130] refer to Figure 3 To ensure that the newly added controller is not only frequency synchronized, but also that its absolute time values ​​(year-month-day-hour-minute-second-microsecond) are consistent:

[0131] 1. The time value at which the main controller A predicts the arrival of the next PPS pulse is Tnext = Tcurrent + 1s.

[0132] 2. A uses LVDS to... Tnext The data packet is sent to the newly added backup controller C.

[0133] 3. C receives and verifies the data, and stores it in the "preload register".

[0134] 4. When the rising edge of the next PPS pulse arrives, the FPGA hardware logic of C directly changes the value in the register. Tnext Write to the real-time counter.

[0135] 5. After that, C continues to accumulate the count by relying on the clock source locked by the PLL, keeping synchronized with A.

[0136] Specifically, the controller determines whether it is the primary controller. If it is the primary controller, it checks if a new backup controller has been added. If so, it sends the synchronization time count value corresponding to the next synchronization pulse to the newly added controller via the data communication link; otherwise, it does nothing. If it is a backup controller, it checks whether it has received the synchronization time count value sent by the primary controller. If so, it immediately writes the synchronization time counter value into the local synchronization clock timing module; otherwise, it does nothing. The newly promoted primary controller sends the local synchronization time count value corresponding to the next synchronization pulse to all backup controllers.

[0137] When the backup controller's clock timing module receives the next synchronization pulse, it writes the synchronization time count value of the primary controller, which was written by the receiving processor, into the local synchronization time counter, thereby achieving complete synchronization of the initial time values ​​of the synchronization time counters of all controllers.

[0138] This invention, through the above-mentioned hardware and software combination and hardware-based control strategy, perfectly solves the clock synchronization problem of multi-redundant control systems, and is suitable for industrial scenarios with extremely high requirements for safety and real-time performance.

[0139] In summary, the proposed solution achieves high-precision clock synchronization among controllers by using a single clock for synchronized timing across all controllers through clock source selection logic. This solves the problems of poor synchronization accuracy and jitter in traditional synchronization schemes. The master-slave switching logic increases the system's fault tolerance and reliability, while also improving the switching speed and eliminating the switching delay and clock jump issues caused by software-based reference controller switching in traditional synchronization schemes. The addition of a phase-locked loop between the clock source selection module and the clock timing module further reduces clock jitter during switching, achieving seamless clock source switching. Finally, by sending a synchronization time count value from the master controller to the standby controller, and coordinating with the master controller's synchronization pulses, a high-precision initial synchronization time counter is achieved, enabling all controllers to share a fully synchronized clock counter. This solves the problem that traditional clock synchronization schemes only achieve periodic synchronization and cannot obtain absolute synchronization time.

[0140] A second aspect of this invention discloses a multi-redundancy control system, wherein the system employs the clock synchronization control method of the aforementioned multi-redundancy control system. The system includes at least two controllers interconnected via a backplane, each controller including a processor, a local clock source, and an FPGA chip, wherein the FPGA chip is internally configured with:

[0141] The clock diagnostic module is used to receive the synchronization clock and synchronization pulse from this controller and other controllers, perform frequency and period detection using a high-frequency diagnostic clock, and output the clock health status.

[0142] The master / standby switching module is used to determine the master / standby status of this controller by executing the logic of promoting to master or delegating to standby based on the processor health status, clock health status, and master / standby status broadcast on the backplane.

[0143] The clock source selection module is used to select the target synchronization clock and target synchronization pulse from multiple signals according to the clock health status and master / slave status, and according to a preset priority strategy.

[0144] A phase-locked loop (PLL) is connected to the output of the clock source selection module and is used to perform phase-locking and filtering on the target synchronization clock to output a low-jitter system drive clock.

[0145] The clock timing module is connected to the phase-locked loop and the processor, and uses the system-driven clock for timing; the clock timing module is also connected to the data communication link, and is used to load the time count value sent by the master controller during initial synchronization.

[0146] Furthermore, the system is a dual-redundant, triple-redundant, or quadruple-redundant control system.

[0147] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments have been described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification. The above embodiments only illustrate several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be pointed out that for those skilled in the art, several modifications and improvements can be made without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A clock synchronization control method for a multi-redundant control system, characterized in that, It is applied in a redundant control system that includes at least two controllers, which are interconnected via a backplane bus and a data communication link; each controller includes a processor, an FPGA module, a local clock source, and a local clock timing module; The method includes the following steps: Step S1 Clock Broadcasting and Receiving: Each controller generates a synchronization clock and synchronization pulse using its local clock source and broadcasts them to the backplane bus; at the same time, it receives synchronization clocks and synchronization pulses broadcast by other controllers. Step S2 Clock Health Diagnosis: Perform real-time diagnosis of the synchronization clock frequency and synchronization pulse period of this controller and other controllers received, and generate clock health status; Step S3 Primary / Backup Status Decision: Based on the processor health status and the clock health status, and combined with the preset primary / backup switching logic, determine the primary / backup status of this controller and broadcast it to other controllers; Step S4 Clock source selection: Based on the clock health status and master / standby status of each controller, select a set of all available synchronization clocks and synchronization pulses as the target synchronization clock and target synchronization pulse; Step S5 Clock Locking and Smoothing: Input the selected target synchronization clock into the phase-locked loop (PLL) for phase locking and jitter filtering, and output the system drive clock; Step S6 Synchronization Timing: The system drive clock drives the local clock timing module to perform timing; in the initial synchronization phase, the backup controller loads the synchronization time based on the synchronization time count value sent by the primary controller through the data communication link and the target synchronization pulse, thereby achieving absolute time synchronization.

2. The method according to claim 1, characterized in that, The specific method for clock health diagnosis in step S2 is as follows: A diagnostic clock with a frequency N times higher than the synchronous clock is used as a reference; The interval between two consecutive rising edges of the synchronous clock being diagnosed is counted. If the deviation of the count value from the nominal value N exceeds the preset frequency deviation threshold, the synchronous clock frequency is determined to be abnormal. The diagnostic clock is used to measure the time interval between two adjacent synchronization pulses. If the deviation of this time interval from the nominal period exceeds a preset period deviation threshold, the synchronization pulse is determined to be abnormal.

3. The method according to claim 1, characterized in that, The specific logic for clock source selection in step S4 is as follows: Determine if a primary controller exists in the current system; If there is a single master controller and its clock health is normal, then the synchronization clock and synchronization pulse of the master controller are selected as the target clock source. If there are multiple master controllers, compare the priorities of each master controller and select the synchronization clock and synchronization pulse of the master controller with the highest priority as the target clock source; If there is no primary controller, or the primary controller clock is abnormal, then the synchronization clock and synchronization pulse generated by the local clock source of this controller shall be selected as the target clock source.

4. The method according to claim 1, characterized in that, The primary / standby state decision in step S3 includes logic to prevent contention and multi-primary conflicts, specifically including: Principal promotion logic: When this controller is in standby mode and no primary controller is detected in the system, a principal promotion timer is started; the duration of the principal promotion timer is related to the priority of this controller, the higher the priority, the shorter the duration; when the principal promotion timer expires and no other primary controller is detected, this controller switches to primary mode. Backup logic: When this controller is in primary mode and detects that there are multiple primary controllers in the system, including itself, a multi-primary backup timer is started; the duration of the multi-primary backup timer is related to the priority of this controller, and the lower the priority, the shorter the duration; when the multi-primary backup timer expires and multi-primary conflicts still exist, this controller switches to standby mode.

5. The method according to claim 4, characterized in that, The priority of this controller is determined based on the hardware slot ID of the controller; the smaller the hardware slot ID value, the higher the corresponding priority, the shorter the duration of the master promotion timer, and the longer the duration of the multi-master demotion timer.

6. The method according to claim 1, characterized in that, The initial synchronization step of the backup controller in step S6 specifically includes: The primary controller predicts the synchronization time count value when the next synchronization pulse arrives and sends the count value to the backup controller via the data communication link. The backup controller receives the count value and temporarily stores it in the preload register; When the backup controller detects the arrival of the effective edge of the target synchronization pulse, it immediately writes the count value in the preload register into the counter of the local clock timing module.

7. The method according to claim 1, characterized in that, In step S5, the phase-locked loop (PLL) is configured to maintain the continuity of the output phase and smoothly transition the output of the system drive clock when the source of the input target synchronization clock is switched.

8. The method according to claim 1, characterized in that, The data communication link is a backplane low-voltage differential signal LVDS high-speed serial link.

9. A multi-redundancy control system, comprising at least two controllers interconnected via a backplane, characterized in that, Each controller includes a processor, a local clock source, and an FPGA chip, wherein the FPGA chip is internally configured with: The clock diagnostic module is used to receive the synchronization clock and synchronization pulse from this controller and other controllers, perform frequency and period detection using a high-frequency diagnostic clock, and output the clock health status. The master / standby switching module is used to determine the master / standby status of this controller by executing the logic of promoting to master or delegating to standby based on the processor health status, clock health status, and master / standby status broadcast on the backplane. The clock source selection module is used to select the target synchronization clock and target synchronization pulse from multiple signals according to the clock health status and master / slave status, and according to a preset priority strategy. A phase-locked loop (PLL) is connected to the output of the clock source selection module and is used to perform phase-locking and filtering on the target synchronization clock to output a low-jitter system drive clock. The clock timing module is connected to the phase-locked loop and the processor, and uses the system-driven clock for timing; the clock timing module is also connected to the data communication link, and is used to load the time count value sent by the master controller during initial synchronization.

10. The system according to claim 9, characterized in that, The system is a dual-redundant, triple-redundant, or quadruple-redundant control system.

Citation Information

Patent Citations

  • A clock synchronization control system and method with multiple redundant controllers

    CN104796213B

  • Time synchronized redundant sensors

    CN104038333A

  • Method for real-time synchronization and online switching of redundancy control system

    CN119225157A