Fusion equipment control method based on rail transit network, fusion equipment and storage medium

By configuring the networking parameters and security policies of the switching chip and firewall chip, controlling the sleep state of the control module, and optimizing the primary and backup redundancy system, the communication interruption problem caused by the independent deployment of firewalls and switches in rail transit was solved, and the operating efficiency and stability of the rail transit network were improved.

CN121940280APending Publication Date: 2026-04-28深圳市三旺通信股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
深圳市三旺通信股份有限公司
Filing Date
2025-12-26
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

In rail transit, the redundancy mechanism resulting from the independent deployment of firewalls and switches in existing technologies is device-level backup, which can easily cause critical communication interruptions and affect the quality of rail transit communication.

Method used

By receiving the convergence function activation command, the system configures the networking parameters and security policies of the switching chip and firewall chip, parses the function start/stop sub-commands to control the sleep state of the control module, and initiates the primary/backup redundancy configuration synchronization process to optimize the primary/backup redundancy system.

Benefits of technology

It improves the resource utilization efficiency, functional adaptability and consistency of the rail transit network, and ensures the continuous and uninterrupted execution of rail transit networking and safety protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940280A_ABST
    Figure CN121940280A_ABST
Patent Text Reader

Abstract

The invention discloses a fusion equipment control method based on a rail transit network, fusion equipment and a storage medium, and relates to the technical field of rail transit trains, and the method comprises the steps: receiving a user fusion function enabling instruction, configuring rail transit networking parameters and security policy parameters of a switching chip and a firewall chip, and forming a fusion hardware architecture; analyzing a function start-stop sub-instruction in the instruction, controlling resources corresponding to the firewall module, the switch module and the dormancy non-enabled module, and outputting a function operation state; starting a main and standby redundancy configuration synchronization process according to the state, and setting a built-in related unit according to a redundancy configuration strategy to obtain a main and standby redundancy system; and in response to a system verification instruction, verifying master-slave synchronization of the configuration file and the operation event, generating a configuration adjustment strategy and optimizing the system. According to the method and the device, the fusion function starting instruction configuration parameters are received, the unused resources are dormant, and the main and standby synchronous verification is performed to optimize the rail transit system, so that the problem of poor rail transit quality is solved, and the stability of the rail transit fusion equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of rail transit train technology, and in particular to a method for controlling fusion equipment based on rail transit networks, fusion equipment, and storage medium. Background Technology

[0002] In rail transit and industrial communication scenarios, network data forwarding and security protection are core requirements for ensuring stable communication. Related technologies typically employ independent deployment of firewalls and switches. These independently deployed devices require external methods such as ring networks and stacking for redundancy. This redundancy mechanism is often device-level backup, which can easily lead to interruptions in critical rail transit communications, resulting in poor communication quality.

[0003] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention

[0004] The main objective of this application is to provide a method for controlling converged equipment, converged equipment, and storage medium based on rail transit networks, aiming to solve the technical problem of poor communication quality in rail transit.

[0005] To achieve the above objectives, this application proposes a method for integrated equipment control based on rail transit networks, the method comprising: Receive the user's command to enable the converged function, configure the rail transit networking parameters and security policy parameters corresponding to the switching chip and firewall chip respectively, and obtain the converged hardware architecture; The function start / stop sub-instructions in the fusion function enable instruction are parsed, the firewall module and switch module are controlled according to the function start / stop sub-instructions, the resources corresponding to the inactive modules are set to a dormant state, and the function operation status that meets the scenario requirements is output. The primary and backup redundancy configuration synchronization process is initiated according to the functional operation status. The relevant units built into the switching chip and the firewall chip are set according to the redundancy configuration strategy to obtain the primary and backup redundancy system. In response to system verification commands, the system verifies the configuration files and runtime events of the primary and backup redundant system for primary and backup synchronization, generates a configuration adjustment strategy, and optimizes the primary and backup redundant system using the configuration adjustment strategy.

[0006] In one embodiment, the function activation requirements, rail transit dedicated communication protocol adaptation requirements, and security protection level parameters contained in the received fusion function activation instruction are parsed and used to form a hardware initialization trigger signal; The switching chip and the firewall chip are connected through a physical interface, and the management ports of the two chips are sequentially connected to the external switching chip and the panel management port to obtain the hardware infrastructure. Configure the rail transit network topology configuration parameters of the switching chip according to the instruction parameter set corresponding to the hardware infrastructure, and configure the rail transit network boundary security protection strategy of the firewall chip according to the security protection level parameters corresponding to the hardware infrastructure, and integrate to generate the converged hardware architecture.

[0007] In one embodiment, the function start / stop sub-instructions in the converged function enable instruction are parsed to extract the specific requirements for independent enable, independent disable, and collaborative enable of the switch module and firewall module, as well as the module operation priority parameters, and to integrate and generate a function start / stop requirement set. Based on the module start / stop requirements in the function start / stop requirement set, determine the resource status of the firewall module and the switch module, complete the status configuration of resource hibernation and rail transit service parameter loading, and generate a pre-run architecture; Based on the pre-running architecture, the service operation process is started, the data interaction path between modules is verified, and it is confirmed that the resources of the hibernation module are not occupied by any service process. The basic functional operation status of the firewall module and the switch module is output.

[0008] In one embodiment, the current hardware computing resource occupancy status and software process running status of each module in the pre-running architecture are verified, and a list of modules that need to be kept in hibernation and a list of modules that need to be kept active are extracted to form a module status verification list. According to the module status list, the basic function operation status is matched and verified, the resources of the dormant and inactive modules are put into hibernation, the rail transit business parameters of the enabled modules are confirmed, and the initial tuning architecture matching the module status is output. Based on the initial tuning architecture, the service connectivity of the confirmation module and the resource status of the dormant module are determined, and the parameters of the initial tuning architecture are adjusted in conjunction with the corresponding rail transit scenario to generate the functional operation status that conforms to the rail transit scenario.

[0009] In one embodiment, based on the function's operating status, a primary / backup redundancy configuration synchronization process is initiated. According to the redundancy configuration strategy, the central processing unit built into the switching chip is set as the primary processing unit, and the central processing unit built into the firewall chip is set as the backup processing unit, thus forming a basic redundancy architecture. Based on the aforementioned basic redundancy architecture, the fusion function configuration information is sent to the primary processing unit, and then synchronized by the primary processing unit to the backup processing unit to output the pre-redundancy system. Verify the cyclic redundancy of the primary and backup processing unit configuration files in the pre-redundancy system, and output the primary and backup redundancy system after the configurations are completely consistent.

[0010] In one embodiment, the verification range specified in the system verification instruction is parsed, the integrity dimension of the configuration file and the timeliness dimension of the running event synchronization that need to be verified are extracted, and the preset verification benchmark rules in the primary and backup redundancy system are retrieved to form a detailed list of verification tasks. According to the detailed list of verification tasks, check the running event logs of the primary and backup processing units to complete the synchronization status verification, record the specific modules and contents that passed or failed the verification, and obtain the primary and backup synchronization status verification result set. For configuration file differences that fail verification, a strategy is generated for the backup processing unit to synchronize the configuration from the primary processing unit, and a strategy is generated for the primary processing unit to resend event information for unsynchronized running events. The configuration adjustment strategy is then integrated to generate the above strategy.

[0011] In one embodiment, the configuration synchronization type, event resending requirement, and state maintenance instruction in the configuration adjustment strategy are parsed to obtain the adjustment parameters; Optimize the system parameters of the primary and backup redundant system according to the adjustment parameters, and generate a redundant system to be verified. The configuration file cyclic redundancy check is re-executed on the primary and backup processing units of the redundancy system to be verified, and the forwarding status and blocking status of the management port of the primary and backup processing units are confirmed to obtain the intermediate redundancy system. Verify the connectivity of the heartbeat path of the interrupt signal pins between the primary and backup processing units and the functionality of data transmission, and output the optimized primary and backup redundancy system.

[0012] In one embodiment, the interrupt pin heartbeat interaction process between the primary processor and the backup processor of the firewall is initiated, and the heartbeat signal is transmitted according to a preset fixed period to output a monitoring system with heartbeat monitoring capability. When the monitoring system detects the disappearance of the heartbeat signal of the primary processor, it triggers a role switching mechanism, switches itself to become the backup processor and takes over the system control of the entire fusion device, generating an emergency primary and backup redundant operation system. When the monitoring system detects that the primary processor has returned to normal and the heartbeat signal has been restored, it triggers the role switching mechanism to switch the system control back to the primary processor and obtain the fault file.

[0013] In addition, to achieve the above objectives, this application also proposes a fusion device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the fusion device control method based on rail transit network as described above.

[0014] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the integrated equipment control method based on rail transit network as described above.

[0015] This application provides a method for controlling converged equipment based on rail transit networks. The method includes receiving a converged function activation command from a user, configuring the rail transit networking parameters corresponding to the switching chip and the security policy parameters corresponding to the firewall chip to construct a converged hardware architecture, parsing the function start / stop sub-commands in the activation command, controlling the start / stop of the firewall module and the switching module, and setting the resources corresponding to the inactive modules to a dormant state to output a functional operating status that meets the scenario requirements. Subsequently, based on this functional operating status, a primary / backup redundancy configuration synchronization process is initiated. The relevant built-in units of the two chips are configured according to the redundancy configuration strategy to form a primary / backup redundancy system. Finally, a system verification command is responded to to verify the configuration files and operating event synchronization status of the primary / backup redundancy system, generate and execute a configuration adjustment strategy to optimize the system. This method solves the technical problems of low resource utilization, inflexible function switching, inconsistent primary / backup redundancy configurations, and insufficient system reliability caused by the separate deployment of switching and security protection equipment in rail transit networks. It improves the resource utilization efficiency, functional adaptability flexibility, consistency, and stability of the primary / backup redundancy system of converged rail transit network equipment, ensuring the continuous and uninterrupted execution of rail transit networking and security protection tasks.

[0016] In summary, this application solves the technical problem of poor rail transit communication quality by receiving the integration function activation command to configure rail transit networking and security policy parameters, parsing the function start / stop sub-commands to hibernate unused resources, and starting the primary and backup redundancy synchronization and verification optimization system. This improves the operating efficiency, resource utilization and system stability of rail transit integration equipment. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating the first embodiment of the integrated equipment control method based on rail transit networks in this application; Figure 2 This is a block diagram of the system functions of this application; Figure 3 This is a hardware module diagram of the system in this application; Figure 4 This is a schematic diagram of the circuit for abnormal operating scenarios in this application; Figure 5 This application presents a schematic diagram of the fusion device.

[0020] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0021] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0022] In related technologies, firewalls and switches are usually deployed independently. Such independently deployed devices need to achieve redundancy through external methods such as ring networks and stacking. The redundancy mechanism of this method is mostly device-level backup, which can easily cause the interruption of critical rail transit communications, resulting in poor rail transit communication quality.

[0023] This application provides a solution as follows: First, it receives a converged function activation command issued by the user, configures the rail transit networking parameters and security policy parameters corresponding to the switching chip and firewall chip respectively, and obtains the converged hardware architecture. Then, it parses the function start / stop sub-commands in the converged function activation command, controls the firewall module and the switching module according to the function start / stop sub-commands, sets the resources corresponding to the inactive modules to a dormant state, outputs the function operation status that meets the scenario requirements, and then starts the primary and backup redundancy configuration synchronization process according to the function operation status. It sets the relevant units built into the switching chip and the firewall chip according to the redundancy configuration strategy to obtain the primary and backup redundancy system. Finally, it responds to the system verification command, verifies the primary and backup synchronization of the configuration file and running events of the primary and backup redundancy system, generates a configuration adjustment strategy, and optimizes the primary and backup redundancy system through the configuration adjustment strategy.

[0024] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or converged device capable of performing the above functions. The following description uses a converged device as an example to illustrate this embodiment and the subsequent embodiments.

[0025] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0026] This application provides a method for controlling integrated equipment based on rail transit networks, referring to... Figure 1 , Figure 1This is a flowchart illustrating the first embodiment of the integrated equipment control method based on rail transit networks in this application.

[0027] In this embodiment, the integrated equipment control method based on the rail transit network includes steps S10 to S40: Step S10: Receive the user's command to enable the converged function, configure the rail transit networking parameters and security policy parameters corresponding to the switching chip and firewall chip respectively, and obtain the converged hardware architecture.

[0028] In this embodiment, the convergence function activation command is a control command issued by the user to the device to enable the converged switching and firewall services. The switching chip is a hardware unit that implements network data forwarding. The firewall chip is a hardware unit that performs network security protection. The rail transit network parameters are network configuration items adapted to the communication needs of rail transit. The security policy parameters are protection rule configuration items that ensure the network security of rail transit. The converged hardware architecture is a hardware operating platform that integrates switching and firewall functions and completes the corresponding parameter configuration.

[0029] As an optional implementation, the system receives a user-issued command to enable the converged function and performs an integrity check on the command. After confirming that the command includes configuration requirements for the switching chip and firewall chip, it first retrieves a preset rail transit network parameter template and configures the switching chip's port communication mode, data forwarding path, network segment isolation rules, etc., according to the template. After the switching chip is configured and passes its self-test, it retrieves a security policy parameter template and configures the firewall chip's packet filtering rules, access control permissions, data interaction monitoring logic, etc., item by item. After configuration, a hardware communication link connectivity check between the two chips is triggered. Once the link is confirmed to be normal, the configuration status of the two chips is integrated to form a converged hardware architecture. This method has a clear configuration process logic, strong parameter adaptability, and is less prone to configuration conflicts.

[0030] As an alternative implementation, upon receiving the user's command to enable the converged function, the command is first parsed and separated into configuration commands for the rail transit networking parameters of the switching chip and the security policy parameters of the firewall chip. Two independent configuration threads are simultaneously started. One thread retrieves the rail transit networking parameter configuration list and synchronously writes parameters and debugs the status of the networking-related hardware units of the switching chip. The other thread retrieves the security policy parameter configuration list and performs rule entry and function verification for the security protection-related hardware units of the firewall chip. Real-time interaction nodes are set up during the configuration process to allow the two threads to synchronize status information at key configuration nodes to avoid configuration conflicts. After both threads have completed their configuration tasks and passed their self-checks, a collaborative connectivity test between the two chips is triggered. Once the collaborative operation is confirmed to be error-free, the converged hardware architecture is completed. This method, employing a parallel configuration mode, significantly shortens the architecture development time and improves overall configuration efficiency, while ensuring configuration coordination through interaction nodes.

[0031] Step S20: parse the function start / stop sub-instructions in the converged function enable instruction, control the firewall module and switch module according to the function start / stop sub-instructions, set the resources corresponding to the inactive modules to a dormant state, and output the function operation status that meets the scenario requirements.

[0032] In this embodiment, the function start / stop sub-instruction is a subdivided instruction embedded within the merged function enable instruction, used to specify the start / stop status of the firewall module and the switch module. The firewall module is a functional unit integrating a firewall chip and corresponding software logic. The switch module is a functional unit integrating a switch chip and corresponding software logic. The resources corresponding to an inactive module are the idle hardware computing resources and software process resources when the module is not enabled. The sleep state is a resource state where idle resources stop actively running to reduce power consumption. The function operation state that meets the scenario requirements is the overall module operation mode that matches the function start / stop requirements and has a reasonable resource state.

[0033] As an optional implementation, this method receives the configured converged hardware architecture and corresponding converged function activation instructions, and performs layered parsing on these instructions. First, the overall framework information of the instruction is extracted, and then the function start / stop sub-instructions are extracted and their completeness and validity are verified. After confirming that the sub-instruction contains start / stop identifiers for two modules, the current operating status of the switch modules is retrieved. According to the sub-instruction requirements, the configured rail transit networking parameters are loaded onto the switch modules to be enabled, and the service processes are started. For the switch modules to be shut down, a process pause instruction is triggered. Subsequently, the same logic is used to perform start / stop control on the firewall modules. Then, for the modules that are not enabled, their idle hardware computing resources and software process resources are identified one by one, triggering resource hibernation scheduling and locking the hibernation state. Finally, it is verified whether the start / stop states of all modules and the resource hibernation states match the sub-instruction requirements, and the functional operating status that meets the scenario requirements is output. This method has a clear layered process and multiple status verification steps, which can minimize start / stop control errors.

[0034] As an alternative implementation, upon receiving the converged hardware architecture and converged function activation command, the command is first rapidly deconstructed, extracting the function start / stop sub-commands and separating them into independent start / stop commands for the switch module and firewall module. Simultaneously, two parallel processing links are initiated. One link specifically handles the start / stop control of the switch module, first verifying the module's current status, then completing the module start / stop according to the independent start / stop command and synchronously marking its idle resources. The other link uses the same logic to complete the start / stop control and idle resource marking of the firewall module. After both links complete the module start / stop control, a unified resource hibernation scheduling thread is started to batch identify the inactive resources of the two modules and synchronously trigger hibernation operations. After hibernation is completed, cross-module status synchronization verification is initiated. After confirming that the start / stop status of the two modules does not conflict with the resource hibernation status, the running data of all modules is integrated, and the functional running status that meets the scenario requirements is output. This method, employing a parallel processing mode, significantly reduces the overall time consumption of command parsing and module control. Batch execution of resource hibernation further improves process efficiency, balancing efficiency with the uniformity of resource management.

[0035] Step S30: Start the primary / backup redundancy configuration synchronization process according to the function operation status, and set the relevant units built into the switching chip and the firewall chip according to the redundancy configuration strategy to obtain the primary / backup redundancy system.

[0036] In this embodiment, the primary / backup redundancy configuration synchronization process refers to the process of synchronizing the configuration information of the primary unit to the backup unit to ensure that the configurations of the two are consistent. The redundancy configuration strategy refers to pre-defined rules used to divide the roles of primary and backup units and standardize the synchronization logic. The related units built into the switching chip refer to the core hardware and software components in the switching chip that are responsible for data forwarding and status monitoring. The related units built into the firewall chip refer to the core hardware and software components in the firewall chip that are responsible for security policy execution and anomaly detection. The primary / backup redundancy system refers to a highly reliable operating system with consistent primary and backup unit configurations and the ability to handle faults.

[0037] As an optional implementation, a primary / backup redundancy configuration synchronization process is initiated based on the functional operating status. First, a preset redundancy configuration policy is retrieved, and the primary / backup roles of relevant units built into the switching chip are defined according to the policy. The core data forwarding unit is set as the primary, and the backup unit is set to standby. Then, the rail transit networking parameters of the primary unit are fully synchronized to the backup unit, and consistency is verified. After the switching chip unit configuration is completed, the primary / backup roles of relevant units built into the firewall chip are defined using the same logic. The security policy execution unit is set as the primary, and the backup unit is set to standby. The security policy parameters of the primary unit are synchronized and verified. Finally, a collaborative status verification across primary and backup units is initiated. After confirming that the primary / backup roles of all units are consistent with the configuration information, they are integrated to form a primary / backup redundancy system. This method features a sequential configuration process with rigorous logic, minimizing conflicts between primary / backup roles and configurations, and reducing the risk of redundancy failure due to configuration deviations.

[0038] As an alternative implementation, after receiving the functional operation status that meets the scenario requirements, the primary / backup redundancy configuration synchronization process is initiated. First, the redundancy configuration policy is parsed and split into a policy specific to the switching chip and a policy specific to the firewall chip. Simultaneously, two independent configuration links are started. One link targets the relevant units built into the switching chip, synchronously completing the primary / backup role assignment, primary / backup synchronization of rail transit network parameters, and consistency verification. The other link targets the relevant units built into the firewall chip, synchronously completing the primary / backup role allocation, primary / backup synchronization of security policy parameters, and accuracy verification. During the configuration process, multiple rounds of cross-link status interaction nodes are set to ensure that the primary / backup role assignments of the two chips are conflict-free and that the synchronization progress matches. After both links have completed configuration and verification, system-level primary / backup redundancy status integration is initiated to confirm that the communication channels between the primary and backup units are unobstructed and that status information is mutually exchanged, ultimately forming a primary / backup redundant system. This method, employing a parallel configuration mode, significantly shortens the overall time spent on synchronization and setting, resulting in a significant improvement in configuration efficiency.

[0039] Step S40: Respond to the system verification command, verify the configuration file and primary / backup synchronization of the primary / backup redundant system, generate a configuration adjustment strategy, and optimize the primary / backup redundant system through the configuration adjustment strategy.

[0040] In this embodiment, the system verification command is a control command used to trigger the verification of the synchronization status of the primary and standby redundant systems. The configuration file is a file that records the operating parameters and rules of the primary and standby units. Operating events are records of state changes and operations generated during the operation of the primary and standby units. Primary-standby synchronization is the process of ensuring that the configuration files and operating events of the primary and standby units are consistent. The configuration adjustment strategy is a set of correction rules and execution plans formulated to address synchronization deviations.

[0041] As an optional implementation, upon receiving the system verification command and the primary / standby redundant system, a serial verification process is initiated first. The configuration files of the primary and standby units are extracted first, and each configuration item is compared for consistency according to preset verification rules, recording the specific content and location of configuration deviations in detail. After the configuration file verification is complete, the runtime event logs of the primary and standby units are checked sequentially along a timeline, marking any unsynchronized event entries. Based on the configuration deviation records and the list of unsynchronized events, a targeted configuration adjustment strategy is generated, clarifying the configuration correction order and event completion logic. Subsequently, according to the strategy, the deviation configuration items of the primary unit are first synchronized to the standby unit, and then the unsynchronized runtime event information is supplemented. A local synchronization verification is performed after each correction is completed. After all correction operations are completed, a system-level full synchronization verification is initiated. After confirming that there are no deviations in the configuration files and runtime events, the optimization of the primary / standby redundant system is completed. This method provides meticulous verification and precise correction, completely eliminating minor synchronization deviations and improving the long-term stability of the system.

[0042] As an alternative implementation, upon receiving the system verification command and the primary / standby redundant system, the verification task is split into two parallel links: configuration file verification and runtime event verification. Simultaneously, all configuration items of the primary and standby units are compared in batches, and runtime event logs are checked synchronously by time interval. The two links aggregate their respective deviation information in real time and upload it to a unified processing node. This processing node integrates the deviation data, generates a batch adjustment strategy, and determines the batch execution logic for configuration correction and event completion. Then, it sends all deviation configuration correction data to the standby unit at once, while simultaneously batch-uploading any unsynchronized runtime events. After completion, a single system-level synchronous verification is initiated to check the overall consistency between the configuration file and runtime events. If residual deviations exist, a supplementary correction is triggered until the verification passes, completing the optimization of the primary / standby redundant system. This method, with its parallel verification and batch correction, significantly reduces optimization time and improves overall efficiency.

[0043] For example, refer to Figure 2 , Figure 2This is a block diagram of the system functional modules in this application. In a rail transit network scenario, the user issues a converged function activation command through the operating system's user management module. The device management module then schedules the configuration management module to configure the rail transit networking parameters (e.g., the network segment 192.168.1.0 / 24 bound to the rail transit protocol) of the corresponding switching chip (model S5735) for switching function management, and the security policy parameters (e.g., allowing rail transit services to pass through TCP port 80) of the corresponding firewall chip (model FW5000) for firewall function management. This, combined with the driver module and physical module, results in a converged hardware architecture. The system parses the function start / stop sub-commands in the command, controls the firewall module and switch module, puts inactive backup module resources into hibernation, records this operation in the log function, and outputs the function's running status. The system initiates a primary / backup redundancy synchronization process, setting the chip's built-in unit to obtain a primary / backup redundancy system. It responds to verification commands, verifies the configuration file (primary / backup consistency rate 99.5%) and running events (log synchronization delay 0.8s), generates an adjustment strategy to optimize the system, and the alarm module does not trigger abnormally during the process.

[0044] By integrating modules such as device management and configuration management, coordinating the management of switching and firewall functions, adapting to rail transit protocols, and relying on driver and physical modules, the problem of dispersed device functions and poor configuration coordination in industrial automation rail transit scenarios has been solved, improving the resource utilization rate, configuration efficiency, and operational reliability of the primary and backup redundant systems of the integrated devices.

[0045] Based on any of the above embodiments, in Embodiment 2 of this application, step S10 includes steps A11 to A13: Step A11: Parse the function activation requirements, rail transit dedicated communication protocol adaptation requirements, and security protection level parameters contained in the received fusion function activation instruction to form a hardware initialization trigger signal.

[0046] In this embodiment, the function activation requirement refers to the specific type and scope of enabling the switching and firewall functions as defined in the instruction. The rail transit-specific communication protocol adaptation requirement is the communication protocol matching specification set in the instruction for rail transit scenarios. The security protection level parameter is the configuration index corresponding to the security protection strength specified in the instruction. The hardware initialization trigger signal is a signal used to initiate hardware configuration after integrating the above requirements, specifications, and parameters.

[0047] As an optional implementation, upon receiving the fusion function activation command, the command is first parsed layer by layer. The overall command framework is extracted, and then the function activation requirements are separated to determine the types and scope of functions covered. Next, the rail transit-specific communication protocol adaptation requirements are extracted, and the protocol matching rules and adaptation conditions are analyzed. Then, security protection level parameters are extracted, and the corresponding protection configuration indicators are determined. The completeness and validity of these three parts are verified respectively. After confirming that there are no missing or conflicting parts, the identifiers corresponding to the function activation requirements, the specifications corresponding to the rail transit-specific communication protocol adaptation requirements, and the indicators corresponding to the security protection level parameters are sequentially integrated according to a preset signal format to generate a hardware initialization trigger signal. This method provides sufficiently detailed parsing and verification of each part, preventing invalid information from being mixed into the trigger signal.

[0048] Step A12: Connect the switching chip and the firewall chip through a physical interface, and then connect the management ports of the two chips to the external switching chip and the panel management port in sequence to obtain the hardware infrastructure.

[0049] In this embodiment, the physical interface is an interface component used for physical connection between hardware units. The management port is a port on the hardware unit used for configuration, monitoring, and other management operations. The external switching chip is an independent chip component used to switch between different hardware unit management paths. The panel management port is a port provided externally for user management operations. The hardware infrastructure is the basic hardware combination form after all hardware units and ports are connected.

[0050] As an optional implementation, the physical interface locations of the switching chip and firewall chip are first identified, and the physical interfaces of the two chips are connected accordingly. After the connection is completed, an interface connectivity test is performed. Once the path is confirmed to be normal, the management port of the switching chip is retrieved and connected to the corresponding interface of the external switching chip. Subsequently, the management port of the firewall chip is connected to the remaining interfaces of the external switching chip in the same way. After completion, the communication status between the external switching chip and the management ports of the two chips is verified. After confirming normal operation, the external interface of the external switching chip is connected to the panel management port. Finally, a full-link connectivity test is initiated to verify whether the overall path of the physical interfaces, management ports, external switching chips, and panel management ports is smooth. Upon completion, the hardware infrastructure is obtained. This method involves sequential and step-by-step connection operations, with each step accompanied by connectivity verification, enabling timely detection and correction of connection anomalies and reducing the risk of subsequent operational failures.

[0051] Step A13: Configure the rail transit network topology configuration parameters of the switching chip according to the instruction parameter set corresponding to the hardware infrastructure, and configure the rail transit network boundary security protection strategy of the firewall chip according to the security protection level parameters corresponding to the hardware infrastructure, and integrate to generate the converged hardware architecture.

[0052] In this embodiment, the instruction parameter set is a set of parameters used to configure the switching chip, which is matched with the hardware infrastructure. The rail transit network topology configuration parameters are configuration items related to the switching chip network structure adapted to the rail transit scenario. The security protection level parameters are parameters corresponding to the hardware infrastructure, specifying the firewall protection strength. The rail transit network boundary security protection strategy is the boundary security control rule set by the firewall chip for the rail transit scenario.

[0053] As an optional implementation, after receiving the hardware infrastructure, the system retrieves the matching instruction parameter set, extracts the rail transit network topology configuration parameters, and sequentially writes the network structure-related configurations of the switching chip item by item according to the parameters. After each configuration is completed, a parameter validity check is performed. Once all network topology parameters are confirmed to be correct and effective, the system retrieves the security protection level parameters corresponding to the hardware infrastructure and sets the rail transit network boundary security protection policy for the firewall chip based on these parameters. Similarly, each policy item is configured and verified synchronously. After all the firewall chip's protection policies are configured and effective, a configuration coordination verification between the switching chip and the firewall chip is initiated. After confirming that there are no conflicts between the two configurations, the configuration states of the two chips are integrated with the hardware infrastructure to generate a converged hardware architecture. This method's configuration operation proceeds in stages according to the chip, with each step accompanied by verification, which can minimize configuration deviations and conflicts.

[0054] For example, refer to Figure 3 , Figure 3 This is a hardware module diagram of the system in this application. In the context of a rail transit network, the received converged function activation command is parsed, extracting the function activation requirements for simultaneously enabling switching and firewall functions, the rail transit-specific communication protocol adaptation requirements for the rail transit Ethernet protocol, and the security protection level parameters for security protection level 3, forming a hardware initialization trigger signal. The switching chip (model S5720 with built-in CPU) and the firewall chip (model FW5100 with built-in CPU) are connected via the MII interface, and then connected to the management ports of the two chips, an external switch (model KVM100), and the panel management port, resulting in the hardware infrastructure. Based on the instruction parameter set corresponding to the hardware infrastructure, the rail transit network topology configuration parameters of the switching chip are configured (dividing into two rail transit-specific network segments), and the rail transit network boundary security protection strategy of the firewall chip (intercepting non-rail transit protocol packets) is configured according to security protection level 3. This integration generates the converged hardware architecture. During the process, the built-in CPUs of the two chips interact and configure their states via IRQ.

[0055] By integrating firewall chips and switching chips with built-in CPUs, relying on MII interfaces and external switches to build a hardware architecture, adapting to rail transit protocols and configuring protection policies, the problems of scattered switching and security equipment and poor protocol compatibility in rail transit networks have been solved, improving the integration of rail transit network equipment, the accuracy of protocol adaptation, and the ability to protect boundary security.

[0056] Based on any of the above embodiments, in Embodiment 3 of this application, step S20 includes steps B11 to B13: Step B11: parse the function start / stop sub-instructions in the converged function enable instruction, extract the specific requirements for independent enable, independent disable, and collaborative enable of the switch module and firewall module, as well as the module operation priority parameters, and integrate them to generate a function start / stop requirement set.

[0057] In this embodiment, independent activation refers to the requirement of enabling a single module independently. Independent deactivation refers to the requirement of deactivating a single module independently. Collaborative activation refers to the requirement of enabling two modules simultaneously. The module running priority parameter is a configuration indicator that specifies the running priority of a module. The function start / stop requirement set is a collection that integrates the above requirements and parameters.

[0058] As an optional implementation, upon receiving the convergence function activation command, the command is first deconstructed layer by layer to locate the command segment containing the function start / stop sub-commands. Then, the independent activation and shutdown requirements of the switch module are gradually extracted, followed by the independent activation and shutdown requirements of the firewall module. Subsequently, the collaborative activation requirements of the two modules are identified, and the module operation priority parameters are separated. The validity of each extracted requirement and parameter is verified. After confirming that there are no conflicts among the requirements and that the parameters conform to the specifications, the switch module requirements, firewall module requirements, collaborative activation requirements, and module operation priority parameters are sequentially integrated according to a preset set format to form a function start / stop requirement set. This method refines the parsing process layer by layer, fully identifying requirement details and avoiding information omissions or confusion.

[0059] Step B12: Based on the module start / stop requirements in the function start / stop requirement set, determine the resource status of the firewall module and the switch module, complete the status configuration of resource hibernation and rail transit service parameter loading, and generate the pre-run architecture.

[0060] In this embodiment, the module start / stop requirement is the specific instruction for starting or stopping the module as defined in the requirement set. Resource status refers to the module's current resource usage, availability, and other status information. Resource hibernation is the operation of stopping idle resources of an inactive module from actively running. Rail transit service parameter loading is the operation of importing rail transit-related configuration parameters into the activated module. The pre-running architecture is the operating platform for the module after resource hibernation and parameter loading are completed.

[0061] As an optional implementation, after receiving the set of function start / stop requests, the module start / stop requirements are first extracted. The current resource status of the firewall and switch modules is then retrieved sequentially, and the resource usage and availability of each module are determined one by one. For modules that need to be shut down, their idle resources are identified and a resource hibernation operation is triggered until the hibernation state stabilizes. Then, for modules that need to be enabled, the corresponding items of the rail transit business parameters are loaded one by one. During the loading process, the compatibility between parameters and modules is simultaneously verified, and the resource allocation weight of enabled modules is adjusted according to the module running priority parameters. After each operation is completed, the module status is verified to match the start / stop requirements. Once the resource hibernation and parameter loading of all modules are completed and the status meets the requirements, the running status of the two modules is integrated to generate a pre-run architecture. This method proceeds sequentially with each step accompanied by verification, which can fully ensure the accuracy of resource status and parameter loading.

[0062] Step B13: Start the service operation process based on the pre-running architecture, verify the data interaction path between modules, confirm that the resources of the hibernation module are not occupied by service processes, and output the basic function operation status of the firewall module and the switch module.

[0063] In this embodiment, the service execution process is the execution flow that starts the module's service functions. The data interaction path is the link for transmitting data between modules. "Resources not occupied by service processes" means that the idle resources of the dormant module are not occupied by running service processes. The basic function running state is an integrated form of the module's service running state, interaction path state, and dormant module resource state.

[0064] As an optional implementation, after receiving the pre-running architecture, the business operation process is initiated. First, the corresponding business processes for each enabled module are started one by one, with the startup status and parameter compatibility of the processes being verified simultaneously during startup. Once all enabled module business processes are running stably, the data interaction paths between modules are verified, testing the connectivity and smoothness of data transmission for each path and recording the path's operational status. Subsequently, the resources of the dormant modules are checked, identifying resource types and confirming whether any business processes are occupying them, recording the resource status after each check. After the business process startup, interaction path verification, and dormant resource verification are all completed, and all verification results meet the requirements, the business operation status of the enabled modules, the connectivity status of the interaction paths, and the resource occupancy status of the dormant modules are integrated to output the basic functional operation status of the firewall module and the switch module. This method provides sufficiently detailed verification of business processes, interaction paths, and resource status, enabling a comprehensive investigation of potential operational anomalies.

[0065] For example, in a rail transit network scenario, the switch functionality is integrated with a firewall: This application's device integrates a switching chip and a firewall chip, connected via a GMII interface. This ensures the device includes both the basic switching capabilities of a switch (such as VLAN segmentation, link aggregation, spanning tree protocol, rail transit-related protocols, etc.) and the security capabilities of a firewall (such as packet filtering, ACL, NAT, stateful inspection, etc.). Flexible combination of firewall and switching functions is supported: This application allows for the independent activation of either the firewall or switching functions, providing great flexibility for on-site applications. When the user disables the firewall function via configuration or command line, the related resources are in a dormant state, with only the switching module operating normally; similarly, disabling the switching function puts the switching-related resources into a dormant state. Dual-system redundancy backup is provided: Both the switching chip and the firewall chip have built-in CPUs, connected via interrupt pins (IRQs). At system startup, the switch chip's CPU is the primary CPU by default, while the firewall chip's CPU is in standby mode. The CPU management ports of both chips are connected to the panel management port via an external switch chip. Only the primary CPU's management port is in forwarding mode, while the standby CPU's management port is in block mode.

[0066] By analyzing function start / stop requirements, configuring resources and rail transit parameters, and verifying operating status, the problem of disordered module start / stop and resource waste in industrial automation scenarios has been solved, thereby improving equipment operating efficiency and resource utilization.

[0067] Based on any of the above embodiments, in Embodiment 4 of this application, step S20 includes steps C11 to C13: Step C11: Verify the current hardware computing resource usage status and software process running status of each module in the pre-running architecture, and extract the list of modules that need to be kept in hibernation and the list of modules that need to be kept active, forming a module status verification list.

[0068] In this embodiment, hardware computing resource occupancy status refers to the resource usage of the hardware computing units within the module. Software process running status refers to the start / stop and load status of various business and management processes within the module. The list of modules that need to remain in sleep mode is a list of modules that should maintain a resource sleep state. The list of modules that need to remain active is a list of modules that should maintain a business running state. The module status verification list is a summary verification document that integrates the above two types of lists.

[0069] As an optional implementation, after receiving the pre-running architecture, the hardware computing resource usage status of each module is retrieved sequentially according to module type. The core computing usage percentage, memory allocation, and interface bandwidth utilization of each module are verified item by item. After completing the hardware status verification, the software process running status of each module is checked, verifying the integrity of business process startup, the communication stability of management processes, and resource contention between processes. Modules with high hardware resource idle percentages and no core business processes running are classified into a list of modules that need to remain dormant. Modules with hardware resource usage matching business needs and stable software process operation are classified into a list of modules that need to remain active. The module information in the two lists is cross-verified, and after confirming no classification discrepancies, they are integrated to form a module status verification list. This method, with hardware and software layered verification and item-by-item checking, can accurately determine the module status and avoid list classification errors.

[0070] Step C12: According to the module status list, match and verify the basic function operation status, hibernate unused module resources, confirm the rail transit service parameters of the enabled module, and output the initial tuning architecture of the module status matching.

[0071] In this embodiment, the basic function operating status is an integrated form of the service operating status, interaction path status, and dormant module resource status of the firewall module and switch module. Inactive module resources are the idle hardware computing resources and software process resources of modules that are not in use. Enabled module rail transit service parameters are the configuration parameters imported into the enabled module to adapt to rail transit services. The initial debugging architecture is the initial debugging and operation platform for the modules after completing module status matching, resource dormancy, and parameter confirmation.

[0072] As an optional implementation, after receiving the module status list and basic function operation status, the system first matches the corresponding basic function operation status one by one according to the module categories in the list, verifying whether the current operation status of each module is consistent with the list requirements. For modules with mismatched statuses, the deviation points are marked. Then, for the inactive modules in the list that need to remain dormant, all their idle resources are identified and dormant operations are triggered layer by layer. During the dormant process, the dormant status of resources is verified simultaneously to ensure that there are no residual running processes. After the dormant process is completed, for the modules in the list that need to remain active, the completeness and adaptability of their rail transit business parameters are verified item by item, missing parameters are supplemented, and deviation parameters are corrected. After completion, a full verification of the overall module status is initiated. After confirming that all module statuses match the list requirements, resources are in dormant, and parameters are accurate, the system integrates and generates and outputs the initial tuning architecture that matches the module status. This method proceeds step by step with verification at each stage, which can eliminate status deviations and parameter errors to the greatest extent and ensure the accuracy of the initial tuning architecture.

[0073] Step C13: Based on the initial tuning architecture, confirm the service connectivity of the module and the resource status of the dormant module, and adjust the initial tuning architecture parameters in combination with the corresponding rail transit scenario to generate the functional operation status that conforms to the rail transit scenario.

[0074] In this embodiment, module service connectivity refers to the smoothness and effectiveness of the link for transmitting service data between enabled modules. Dormant module resource status refers to the dormant stability and process-free state of idle resources in inactive modules. Rail transit scenario adjustment parameters are dedicated configuration indicators adapted to rail transit service requirements.

[0075] As an optional implementation, after receiving the initial tuning architecture, single-point tests are first performed on the service connectivity links of each enabled module to verify the transmission stability and data interaction effectiveness of the links. After completion, the various resources of the dormant modules are checked item by item to confirm that all resources are in a stable dormant state without process occupation. Then, the corresponding rail transit scenario adjustment parameters are retrieved, and the module operation thresholds and service forwarding rules of the initial tuning architecture are corrected one by one according to the parameter items. After each parameter adjustment, the service connectivity of the module is simultaneously verified to ensure it is not affected. Once all parameters are adjusted and the service connectivity and dormant resource status meet the requirements, the final operating data of all modules are integrated to generate a functional operating status that conforms to the rail transit scenario. This method's operation process proceeds sequentially, with verification at each stage, maximizing the accuracy of parameter adjustments and status verification, avoiding operational deviations in the architecture, and providing an unbiased state foundation for subsequent system operation.

[0076] For example, in a rail transit network scenario, the pre-running architecture is verified by checking that the switch module (model S5735) has 40% hardware computing resource usage and its software processes are running normally, while the firewall module (model FW5100) has 35% hardware computing resource usage and its software processes are waiting to be activated. A list of firewall modules that need to remain dormant and a list of switch modules that need to remain active are extracted to form a module status verification list. The basic function operation status is verified according to this list (switch service process startup rate 100%), and the resources of inactive firewall modules are put into hibernation (hibernation rate 100%). The integrity of rail transit service parameters for active switch modules is confirmed to be 99%, and an initial tuning architecture matching the module status is output. Based on the initial tuning architecture, the module service connectivity rate is confirmed to be 99.8%, and the resource usage of dormant modules is 0%. Three parameters, including the data forwarding threshold, are adjusted according to the rail transit scenario to generate a functional operation status that conforms to the rail transit scenario.

[0077] By verifying module status, matching operating status, and adapting to rail transit parameters, the problems of inaccurate control of rail transit network module status and poor scenario adaptability have been solved, thereby improving the matching degree of module status, the stability of business connectivity, and the accuracy of scenario adaptation.

[0078] Based on any of the above embodiments, in Embodiment 5 of this application, step S30 includes steps D11 to D13: Step D11: Based on the function's operating status, initiate the primary / backup redundancy configuration synchronization process. According to the redundancy configuration strategy, set the central processing unit built into the switching chip as the primary processing unit and set the central processing unit built into the firewall chip as the backup processing unit, thus forming a basic redundancy architecture.

[0079] In this embodiment, the primary / backup redundancy configuration synchronization process is a process of synchronizing the configuration of the primary unit to the backup unit to ensure configuration consistency. The redundancy configuration strategy is a pre-defined rules for defining the roles of primary and backup units and standardizing the configuration synchronization logic. The primary processing unit is the core unit responsible for handling the main business processing tasks. The backup processing unit is a core unit in standby mode that can take over tasks in the event of a failure of the primary unit. The basic redundancy architecture is the fundamental high-reliability operating architecture that completes the setting and configuration synchronization of the primary and backup processing units.

[0080] As an optional implementation, after receiving the operational status of the receiving function, the primary / backup redundancy configuration synchronization process is initiated first. The preset redundancy configuration policy is retrieved and parsed item by item. First, the central processing unit (CPU) built into the switching chip is located and set as the primary processing unit according to the policy. Then, the service configuration parameters of the primary processing unit are retrieved and their integrity is verified. Next, the CPU built into the firewall chip is located and set as the backup processing unit. The configuration parameters of the primary processing unit are synchronized to the backup processing unit one by one. During the synchronization process, a consistency verification is performed after each parameter transmission is completed. After confirming no parameter deviation, a communication link connectivity test is initiated between the primary and backup processing units to verify the smoothness of the status interaction path. Once configuration synchronization is complete and the communication link test passes, the role settings and configuration status of the primary and backup processing units are integrated to form a basic redundancy architecture. This method, with configuration synchronization and role setting proceeding sequentially and each step verified, can minimize primary / backup role conflicts and parameter synchronization deviations, ensuring the accuracy of the architecture configuration.

[0081] Step D12: Based on the basic redundancy architecture, the fusion function configuration information is sent to the primary processing unit, and then synchronized by the primary processing unit to the backup processing unit to output the pre-redundancy system.

[0082] In this embodiment, the pre-redundant system is a preliminary redundant operating system after the master and backup of the fusion function configuration information has been synchronized.

[0083] As an optional implementation, after receiving the basic redundancy architecture, complete converged function configuration information is retrieved and prioritized according to the importance of each configuration item. Core business linkage configuration information is first sent to the primary processing unit, with the primary processing unit's configuration reception status verified concurrently during the sending process. After confirming that the core configuration has been received correctly and is initially effective, secondary auxiliary configuration information is then sent. Once all converged function configuration information has been sent to the primary processing unit, a configuration integrity check is initiated to verify the accuracy and logical compatibility of all configuration items. Subsequently, a configuration synchronization process from the primary processing unit to the backup processing unit is triggered, transmitting configuration information item by item in the order of core to secondary. After each synchronization is completed, a primary-backup configuration consistency comparison is performed, and deviations are marked and corrected. After all configuration synchronization is complete and consistency verification passes, a configuration linkage test between the primary and backup processing units is initiated. Once it is confirmed that the configurations of both units can collaboratively support converged services, a pre-redundant system is output. This method, with its priority-based, layered configuration sending and synchronization and multiple rounds of verification, maximizes the accuracy and consistency of primary and backup configurations and avoids configuration logic conflicts.

[0084] Step D13: Verify the cyclic redundancy of the primary and backup processing unit configuration files in the pre-redundancy system. Output the primary and backup redundancy system after the configurations are completely consistent.

[0085] In this embodiment, the pre-redundant system is a preliminary redundant operating system after the primary and backup configuration information for the converged functions has been synchronized. The primary and backup processing units refer to the primary unit responsible for handling major business processes and the backup unit ready to take over. The configuration file is the core file that records the unit's operating parameters and business rules. Cyclic redundancy is a verification mechanism used to check the integrity and consistency of the configuration file.

[0086] As an optional implementation, after receiving the pre-redundancy system, the full configuration files of the primary and backup processing units are first retrieved. These files are then divided into several verification segments according to their functional modules. The cyclic redundancy feature value of the primary unit is extracted from the first verification segment. Next, the cyclic redundancy feature value of the corresponding verification segment of the backup unit is extracted. The two feature values ​​are then precisely compared, and the comparison result is recorded. The same logic is then applied to extract and compare the cyclic redundancy feature values ​​of all verification segments sequentially. After all verification segments have been compared, the results are integrated. If there is a feature value deviation, the deviation verification segment is located, and configuration resynchronization is triggered. After the deviation segment completes resynchronization and the second verification passes, the global cyclic redundancy feature value of the entire configuration file of the primary and backup processing units is extracted for a final comparison. Once the global feature values ​​are confirmed to be completely consistent, the primary and backup redundancy system is output. This method performs segment-by-segment layer-by-layer verification with a corresponding deviation correction mechanism, which can completely eliminate minor deviations in the configuration file.

[0087] For example, in a rail transit network scenario, based on the functional operating status conforming to the rail transit scenario, a primary / backup redundancy configuration synchronization process is initiated. According to the redundancy configuration strategy, the central processing unit built into the switching chip (model S5735) is set as the primary processing unit, and the central processing unit built into the firewall chip (model FW5100) is set as the backup processing unit, forming a basic redundancy architecture. Based on this architecture, 128 converged function configuration information items are distributed to the primary processing unit, which then synchronizes them to the backup processing unit (synchronization success rate 100%), outputting a pre-redundant system. The cyclic redundancy of the primary and backup processing unit configuration files in the pre-redundant system is verified. After three rounds of verification confirming a 100% configuration consistency rate, the primary / backup redundancy system is output.

[0088] By setting up primary and backup processing units, synchronizing and merging configurations, and verifying consistency, the problems of asynchronous redundant configurations and high risk of fault takeover in rail transit networks have been solved, thereby improving configuration consistency and system redundancy reliability.

[0089] Based on any of the above embodiments, in Embodiment Six of this application, step S40 includes steps E11 to E13: Step E11: Parse the verification range specified in the system verification instruction, extract the integrity dimension of the configuration file and the timeliness dimension of the running event synchronization that need to be verified, and retrieve the preset verification benchmark rules in the primary and backup redundant system to form a detailed list of verification tasks.

[0090] In this embodiment, the verification scope refers to the system dimensions and content boundaries to be verified as specified in the instruction. The runtime event synchronization timeliness dimension is a verification dimension that evaluates the timeliness of runtime event transmission and updates between the primary and backup units. The verification task detail list is a list of specific verification tasks after integrating the verification dimensions and benchmark rules.

[0091] As an optional implementation, upon receiving a system verification command, the command is first deconstructed layer by layer, locating the specified verification scope layer by layer. First, the configuration file integrity dimension is separated from the scope, determining the sub-items to be verified under this dimension, such as configuration item coverage and file format standardization. Then, the runtime event synchronization timeliness dimension is extracted, defining sub-indicators such as event synchronization delay threshold and log update frequency. Subsequently, the preset verification benchmark rules in the primary / standby redundancy system are retrieved, and the benchmark rules are aligned one by one with the extracted verification sub-items and sub-indicators according to the dimensions, matching each sub-item with the corresponding judgment standard. Simultaneously, the execution priority of each verification task is marked, and the integrity of all aligned content is verified. After confirming that no tasks are omitted or rules are mismatched, a detailed list of verification tasks is formed. This method, with its layer-by-layer refinement of the parsing and alignment process, can accurately cover all verification requirements and avoid task omissions.

[0092] Step E12: According to the verification task details list, check the running event logs of the primary and backup processing units to complete the synchronization status verification, record the specific modules and contents that passed or failed the verification, and obtain the primary and backup synchronization status verification result set.

[0093] In this embodiment, the specific modules and contents that pass or fail the verification refer to the units marked as compliant or abnormal after verification and their corresponding log entries. The master-slave synchronization status verification result set is a summary verification result document that integrates all verification records.

[0094] As an optional implementation, after receiving the detailed list of verification tasks, the tasks are first sorted by priority. The primary processing unit's runtime event logs are retrieved first, and then the log segments are broken down by timeline. Next, the log segments for the corresponding time period from the backup processing unit are retrieved synchronously. The completeness of the content and the consistency of the timestamps for each log segment are verified item by item. Simultaneously, the synchronization status is determined by comparing the verification results with the baseline rules in the list. The specific module and log entry for each log segment are marked as passed or failed. For failed entries, the deviation type and degree are recorded. After verifying all log segments, the verification records are integrated by module. The records are then cross-checked to confirm no omissions, ultimately yielding the primary / backup synchronization status verification result set. This method's verification process proceeds segment by segment and item by item with corresponding checks, accurately capturing subtle deviations in log synchronization and ensuring the accuracy and comprehensiveness of the result set.

[0095] Step E13: For configuration file differences that fail verification, generate a strategy for the backup processing unit to synchronize configurations from the primary processing unit, and generate a strategy for the primary processing unit to resend event information for unsynchronized running events, and integrate these to generate the configuration adjustment strategy.

[0096] In this embodiment, the unsynchronized runtime events are runtime event records that have not been synchronized in the primary and backup processing units. The strategy for resending event information is that the primary processing unit sends the execution plan of the unsynchronized events to the backup processing unit.

[0097] As an optional implementation, after receiving the primary / standby synchronization status verification result set, the configuration file differences that failed verification are extracted one by one, categorized according to their importance, and an incremental synchronization strategy is formulated for core configuration differences, determining the synchronization triggering time, data transmission path, and integrity verification standard. A timed full synchronization strategy is formulated for auxiliary configuration differences. Then, unsynchronized runtime events are extracted, sorted by event timestamp, and marked as urgent or ordinary events. An immediate reissue strategy is formulated for urgent events, determining reissue priority and reset mechanism; a batch summary reissue strategy is formulated for ordinary events, setting a reissue time window. Subsequently, conflict verification is performed on the two types of strategies. After confirming that there are no time or resource conflicts between synchronization and reissue operations, they are integrated according to the principle of prioritizing configuration synchronization and urgent event reissue to generate a configuration adjustment strategy. This method's strategy formulation closely matches the characteristics of the differences, is highly targeted, and can accurately solve different types of synchronization problems, ensuring the effectiveness of primary / standby synchronization repair.

[0098] For example, in the context of a rail transit network, the system analyzes the verification scope specified in the verification command, extracts the integrity dimension of the configuration file (including 108 core configuration items) and the timeliness dimension of runtime event synchronization (synchronization delay threshold of 50ms) to be verified, and retrieves the preset verification benchmark rules in the primary and backup redundant systems (primary: S5735 switching chip built-in CPU, backup: FW5100 firewall chip built-in CPU) to form a detailed list of verification tasks. The system checks the 32 runtime event logs of the primary and backup processing units according to the list to complete the synchronization status verification, records the two configuration file differences that failed verification (switching chip routing configuration, firewall access control list) and the three runtime event non-synchronized items, and obtains the primary and backup synchronization status verification result set. A strategy for incremental synchronization of the primary unit configuration by the backup processing unit is generated for the differences, and a strategy for batch resending event information by the primary unit (resending window of 5 minutes) is generated for the non-synchronized items. These are then integrated to generate a configuration adjustment strategy.

[0099] By clarifying the verification dimensions, checking the synchronization status, and formulating targeted adjustment strategies, the problem of inaccurate repair of primary and backup synchronization deviations in the rail transit network has been solved, improving configuration consistency and the timeliness of event synchronization.

[0100] Based on any of the above embodiments, in Embodiment Seven of this application, step S40 includes steps F11 to F14: Step F11: parse the configuration synchronization type, event resending requirement, and state maintenance instruction in the configuration adjustment strategy to obtain the adjustment parameters.

[0101] In this embodiment, the configuration synchronization type is the specific method by which the backup processing unit obtains configuration from the primary processing unit, as specified in the configuration adjustment strategy. The event retransmission requirement is the execution specification in the configuration adjustment strategy for retransmitting unsynchronized events to the primary processing unit. The state maintenance instruction is the control instruction in the configuration adjustment strategy used to ensure stable system operation during the adjustment process. The adjustment parameters are the set of directly executable parameters obtained after parsing the above three types of content.

[0102] As an optional implementation, after receiving the configuration adjustment strategy, the strategy is first deconstructed layer by layer, locating the configuration synchronization type layer by layer, and determining the synchronization triggering conditions, data transmission range, and verification standards under that configuration synchronization type. Then, the event resending requirements are extracted in depth, defining the priority of resending events, transmission batches, and retry mechanisms. Subsequently, state maintenance instructions are selected, confirming the system resource locking range and state monitoring nodes corresponding to the instructions, and performing validity and logical consistency checks on these three types of content respectively. After confirming that there are no conflicts among the contents, each type of content is converted into quantifiable specific parameters in the order of configuration synchronization, event resending, and state maintenance. The converted parameters are cross-verified to ensure that there are no logical contradictions between the parameters, and finally integrated to form the adjustment parameters. This method, with its layer-by-layer refinement and multi-round verification process, can maximize the accuracy and completeness of the adjustment parameters.

[0103] Step F12: Optimize the system parameters of the primary and backup redundant system according to the adjustment parameters to generate a redundant system to be verified.

[0104] In this embodiment, the system parameters are the core configuration and status parameters that support the stable operation of the primary and backup redundant system. The redundant system to be verified is a transitional redundant system that awaits consistency and stability verification after the system parameters have been optimized.

[0105] As an optional implementation, after receiving the adjustment parameters, they are first categorized into configuration synchronization parameters, event retransmission parameters, and state maintenance parameters based on their functional attributes. The corresponding system parameter module of the primary processing unit in the primary / standby redundant system is retrieved first. Configuration synchronization parameters are imported item by item, overwriting existing deviation parameters. After each parameter import is completed, a parameter validity and logical compatibility verification is performed. Once no conflicts are confirmed, the same configuration synchronization parameter import operation is performed on the standby processing unit, synchronously verifying the consistency of this type of parameter between the primary and standby units. Subsequently, event retransmission parameters are imported, and the event retransmission process of the primary unit is triggered, synchronously monitoring the retransmission progress and the standby unit's receiving status. Finally, state maintenance parameters are imported, core system resources are locked, and operational status monitoring is enabled. After all parameter imports and process triggering are completed and the initial state is stable, the parameter configurations and operational statuses of the primary and standby units are integrated to generate a redundant system to be verified. This method of parameter optimization proceeds step-by-step by category, with each step accompanied by verification, which can maximize the accuracy of parameter import and the stability of the system state, avoiding new operational deviations caused by the optimization process.

[0106] Step F13: Re-execute the configuration file cyclic redundancy check on the primary and backup processing units of the redundancy system to be verified, and confirm the forwarding status and blocking status of the management port of the primary and backup processing units to obtain the intermediate redundancy system.

[0107] In this embodiment, the management port forwarding state refers to the unimpeded transmission of management commands through the management ports of the primary and backup processing units. The management port blocking state refers to whether the management ports of the primary and backup processing units are in a state where data transmission is prohibited. The intermediate redundancy system is a transitional, highly reliable redundant system after configuration verification and port status confirmation are completed.

[0108] As an optional implementation, after receiving the redundant system to be verified, the full configuration files of the primary and backup processing units are first retrieved and divided into several verification segments according to the configuration modules. Cyclic redundancy feature values ​​are extracted from the first verification segment of the primary unit. Then, feature values ​​for the corresponding verification segments of the backup unit are extracted and precisely compared, and the comparison results are recorded. The same logic is used to complete the comparison of all verification segments. If a deviation exists, the deviation module is marked and a local configuration resynchronization is triggered. After all cyclic redundancy verifications of the configuration files pass, the status of the management ports of the primary and backup processing units is checked one by one. First, the smoothness of instruction transmission in the forwarding state is verified, and then the effectiveness of control over the blocking state is confirmed. The result is recorded after each port status confirmation is completed. Once all port statuses meet the preset standards, the configuration verification results and port status information are integrated to generate an intermediate redundant system. This method's verification process proceeds segment by segment and port by port with corresponding deviation correction, thoroughly investigating potential problems in the configuration and ports, ensuring the accuracy of the system status, and reducing the risk of final system failure.

[0109] Step F14: Verify the connectivity of the heartbeat path of the interrupt signal pins between the primary and backup processing units and the functionality of data transmission, and output the optimized primary and backup redundancy system.

[0110] In this embodiment, the interrupt signal pin heartbeat path is a hardware connection link for transmitting heartbeat monitoring signals between the primary and backup units. Connectivity refers to the smoothness of the physical connection of this path. Data transmission function refers to the path's ability to transmit heartbeat signals and status data normally.

[0111] As an optional implementation, after receiving the intermediate redundancy system, the interrupt signal pins of the primary and backup processing units are first located to check the heartbeat path interface. The physical connection status of each path is checked one by one to confirm that the pins are not loose and the contact is not poor. Then, the bidirectional heartbeat signal transmission test of the primary and backup units is started. The primary processing unit sends heartbeat data packets to the backup unit at a preset frequency, and the sending time, transmission delay, and reception feedback of each data packet are recorded in real time, and the data packet transmission success rate is statistically analyzed. Subsequently, the direction is switched so that the backup unit sends heartbeat signals to the primary unit. The stability and integrity of data transmission are also verified. For any delay exceeding the standard or packet loss during transmission, the corresponding path is located and troubleshooted. After the success rate and delay of the bidirectional heartbeat data transmission meet the preset standards, it is confirmed that there are no hidden problems with the connectivity and functionality of the heartbeat path. The optimized primary and backup redundancy system is then output. This method performs a path-by-path, bidirectional, and detailed review, which can thoroughly investigate hidden link problems and ensure the stability of the heartbeat link.

[0112] By analyzing and adjusting parameters, optimizing system parameters, and verifying configuration ports and heartbeat pathways, the problems of parameter deviation and abnormal status in the primary and backup redundancy system of the rail transit network have been resolved, thereby improving the system redundancy reliability and the timeliness of fault takeover.

[0113] Based on any of the above embodiments, in Embodiment 8 of this application, after step S40, steps G11~G13 are further included: Step G11: Initiate the heartbeat interaction process between the primary and backup processors of the firewall via the interrupt pins, transmit heartbeat signals according to a preset fixed cycle, and output a monitoring system with heartbeat monitoring capabilities.

[0114] In this embodiment, the primary processor of the firewall is the core processing unit responsible for main business processing and system management tasks. The backup processor is a standby processing unit that can take over tasks in case the primary processor fails. The interrupt pin heartbeat interaction process is an interaction between the primary and backup processors that transmits heartbeat signals through interrupt pin links to sense each other's operating status. The preset fixed period is a pre-set, unchanging heartbeat signal transmission time interval. The heartbeat signal is a signal transmitted between the primary and backup processors to identify their own operating status. A monitoring system with heartbeat monitoring capability is a system that can receive and identify heartbeat signals to determine the operating status of the primary and backup processors.

[0115] As an optional implementation, after receiving the process start command, the interrupt pin links of the primary and backup processors are first located, and the initialization configuration of each link is completed one by one to confirm the physical connectivity of the links. Then, preset fixed-cycle parameters are retrieved and configured into the heartbeat sending module of the primary processor and the heartbeat receiving module of the backup processor, respectively. Subsequently, the heartbeat signal sending process of the primary processor is started, and the heartbeat receiving monitoring function of the backup processor is enabled. During each heartbeat signal transmission, the integrity of the signal format and identification information is checked to confirm that the signal is not damaged and the status identification is clear. If a signal abnormality occurs, the corresponding information is recorded and the link operation is maintained. After the heartbeat transmission rhythm is stable and the monitoring function can accurately identify the signal, a monitoring system with heartbeat monitoring capability is output. This method has meticulous link initialization and sequential signal verification, which can ensure the initial stability and signal accuracy of heartbeat transmission.

[0116] As an alternative implementation, when initiating the interrupt pin heartbeat interaction process between the primary and backup processors, a fixed-period heartbeat signal transmission is not used. Instead, the heartbeat period is dynamically adjusted based on the current system load. When the system load is low, the heartbeat period is appropriately shortened to improve monitoring sensitivity. When the system load rises to a preset range, the heartbeat period is moderately extended to reduce resource consumption. Simultaneously, during the period adjustment process, period change information is fed back to the monitoring system to ensure that the monitoring logic and transmission period remain consistent, ultimately outputting a heartbeat monitoring system with dynamic adaptability.

[0117] As an alternative implementation, when initiating the heartbeat interaction process between the primary and backup processors, instead of relying on a single interrupt pin link to transmit the heartbeat signal, multiple independent interrupt pin links are simultaneously activated as redundant transmission paths. Each link transmits the heartbeat signal according to the same logic, and the monitoring system simultaneously receives the heartbeat data from each link and performs cross-verification. If the heartbeat signal of a certain link is abnormal, that link is immediately marked, and the status is determined only based on the signals of the remaining normal links, ensuring the reliability of heartbeat transmission and outputting a monitoring system with multi-link redundancy verification capabilities.

[0118] As another optional implementation, when outputting a monitoring system with heartbeat monitoring capabilities, instead of monitoring only the heartbeat signal status, the heartbeat monitoring is linked with the configuration file integrity verification: while receiving the heartbeat signal, the monitoring system periodically triggers the configuration file consistency verification between the primary and backup processors. If the heartbeat signal is normal but the configuration file is inconsistent, the system immediately reports the abnormal information and initiates the configuration synchronization process; if the heartbeat signal is abnormal and the configuration file has a deviation, the role switching related process is triggered first to ensure that the system configuration remains consistent when the heartbeat is normal, thus outputting a monitoring system with the ability to verify the linkage between heartbeat and configuration.

[0119] Step G12: When the monitoring system detects the disappearance of the heartbeat signal of the primary processor, it triggers the role switching mechanism, switches itself to become the backup processor, and takes over the system control of the entire fusion device, generating an emergency primary / backup redundant operating system.

[0120] In this embodiment, the monitoring system is capable of receiving heartbeat signals and determining the operating status of the primary and backup processors. The disappearance of the primary processor's heartbeat signal means that the primary processor stops transmitting signals used to identify its normal operating status. The role switching mechanism refers to pre-defined process rules for changing the task assignment roles between the primary and backup processors. Taking over system control of the entire converged device means acquiring control and management authority over all functional modules of the converged device. A converged device is a device integrating multiple functional modules. An emergency primary / backup redundant operation system refers to a device operation system with redundant operation capabilities after the primary and backup processors complete role switching.

[0121] As an optional implementation, after receiving feedback from the monitoring system that the primary processor's heartbeat signal has disappeared, the status is first verified multiple times to confirm that the signal disappearance is not due to temporary transmission fluctuations. Then, a role switching mechanism is triggered. A preset list of role permissions is retrieved, and the system takes over control of the system step-by-step, starting with the core functional modules, according to their priority. For each module taken over, its operational stability is simultaneously verified. Once the core modules have been taken over and are functioning normally, the non-core functional modules are taken over sequentially. After all modules have been taken over, a global check of the overall system's operational status is performed. Once it is confirmed that all modules are under control, an emergency primary / backup redundant operating system is generated. This method, with its priority-based, step-by-step takeover process and accompanying status verification at each stage, minimizes the risk of functional abnormalities during takeover, ensures system stability, and reduces the risk of equipment failure caused by role switching.

[0122] As an alternative implementation, when the monitoring system detects the disappearance of the primary processor's heartbeat signal and triggers a role switching mechanism, it does not directly take over all system control. Instead, it adopts a tiered takeover approach: first, it takes over control of the core functional modules of the converged equipment to ensure the continuous operation of core services. After the core module takeover is stable, it gradually takes over control of non-core functional modules. Simultaneously, it monitors the module's operating status at each level of takeover. If an anomaly occurs, it pauses subsequent takeovers and maintains the current state. After completing the tiered takeover, an emergency primary / backup redundant operating system is generated.

[0123] Step G13: When the monitoring system detects that the primary processor has returned to normal and the heartbeat signal has been restored, it triggers the role switching mechanism to switch the system control back to the primary processor and obtain the fault file.

[0124] In this embodiment, "primary processor recovery" means that the previously faulty primary processor returns to a stable operating state. "Heartbeat signal recovery" means that the primary processor resumes transmitting signals indicating its normal operating status. "Role switching mechanism" refers to pre-defined process rules that transfer system control from the currently running standby processor back to the primary processor. "Fault file" refers to a document that records information about the primary processor failure, role switching, and the entire switching process.

[0125] As an optional implementation, after receiving the primary processor recovery information from the monitoring system, the primary processor's operating status is first verified in multiple dimensions, including configuration file integrity and the stability of core functional modules. Once all verification items meet preset standards, a role switchback mechanism is triggered, gradually switching control back to the primary processor based on the priority of functional modules, starting with non-core modules. For each module switched back, its operating status under the primary processor's control is simultaneously verified. After the non-core modules have switched back and their status is stable, the core functional modules are switched back. After all modules have switched back, a final verification of the primary processor's global control status is performed, and the entire process from the occurrence of the fault to the completion of the switchback is recorded and compiled into a fault file. This method's step-by-step switchback process, coupled with multiple rounds of status verification, ensures the stable operation of the system after the switchback and prevents the primary processor from experiencing anomalies again.

[0126] As an alternative implementation, when the monitoring system detects the recovery of the primary processor's heartbeat signal, it does not directly trigger the role switchover mechanism. Instead, it first performs multi-dimensional status verification on the primary processor: verifying the consistency of its configuration file with the current standby processor, the operational stability of core functional modules, load-bearing capacity, etc. After all verification items meet the preset standards, the system control is gradually switched back from the standby processor to the primary processor. During the switchover process, the operating status of the primary processor is monitored simultaneously to ensure a smooth switchover process. After the switchover is completed, a fault file recording the complete verification and switchover process is obtained.

[0127] For example, refer to Figure 4 , Figure 4 This is a schematic diagram of the circuit for an abnormal operating scenario in this application. In a rail transit network scenario, taking a converged device in an industrial automation scenario as an example, the device includes a firewall chip (FW6200 with built-in CPU, primary processor) and a switching chip (S6720 with built-in CPU, backup processor). The two are connected via a GMII interface. The firewall chip transmits data to the switch module via a forwarding link, and the switching chip interacts with the switch module via a block link. The device is equipped with 8 GE interfaces, a MII interface, and a TRC link. An interrupt pin heartbeat interaction process is initiated between the primary and backup processors, transmitting heartbeat signals via the TRC link at a preset fixed period of 100ms, outputting a monitoring system with heartbeat monitoring capabilities. When the monitoring system detects the primary processor's heartbeat signal disappearing for 3 consecutive cycles (300ms), a role switching mechanism is triggered. The backup processor takes over system control of the switch module and the 8 GE interfaces via the MII interface, generating an emergency primary / backup redundant operating system. When the heartbeat signal of the primary processor is detected to have recovered and been transmitted stably for 5 cycles (500ms), the role switchover mechanism is triggered to switch control back to the primary processor and obtain a fault file recording the switchover process.

[0128] By initiating heartbeat interaction between the primary and backup processors and triggering role switching / return switching through the linkage device interfaces and modules, the problem of system interruption caused by the failure of the primary processor of the fusion device in industrial automation scenarios is solved, thereby improving the continuity of equipment operation and the reliability of system management.

[0129] This application provides a fusion device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to execute the fusion device control method based on the rail transit network in Embodiment 1 above.

[0130] The following is for reference. Figure 5The diagram illustrates a structural schematic suitable for implementing the converged device in the embodiments of this application. The converged device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, secure switching all-in-one machines, personal digital assistants (PDAs), tablet computers (PADs), portable media players (PMPs), redundant secure switching devices, etc., as well as fixed terminals such as multi-service secure switching gateways, desktop computers, etc. Figure 5 The fusion device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0131] like Figure 5 As shown, the fusion device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.) that can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the fusion device. The processing unit 1001, the ROM 1002, and the RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the converged device to communicate wirelessly or wiredly with other devices to exchange data. While the figure shows a converged device with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0132] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0133] The fusion device provided in this application, employing the fusion device control method based on rail transit networks in the above embodiments, can solve the technical problem of poor rail transit communication quality. Compared with the prior art, the beneficial effects of the fusion device provided in this application are the same as those of the fusion device control method based on rail transit networks provided in the above embodiments, and other technical features of this fusion device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0134] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0135] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0136] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the integrated equipment control method based on rail transit network in the above embodiments.

[0137] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, radio frequency (RF), etc., or any suitable combination thereof.

[0138] The aforementioned computer-readable storage medium may be included in the fusion device or may exist independently and not assembled into the fusion device.

[0139] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the converged device, the converged device: receives a converged function activation command issued by the user; configures the rail transit networking parameters and security policy parameters corresponding to the switching chip and firewall chip respectively, thereby obtaining a converged hardware architecture; parses the function start / stop sub-instructions in the converged function activation command; controls the firewall module and switching module according to the function start / stop sub-instructions; sets the resources corresponding to the inactive modules to a dormant state; and outputs a function operation status that meets the scenario requirements; initiates a primary / backup redundancy configuration synchronization process according to the function operation status; sets the relevant units built into the switching chip and firewall chip according to the redundancy configuration strategy, thereby obtaining a primary / backup redundancy system; responds to a system verification command; verifies the primary / backup synchronization of the configuration file and running events of the primary / backup redundancy system; generates a configuration adjustment strategy; and optimizes the primary / backup redundancy system through the configuration adjustment strategy.

[0140] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0141] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0142] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0143] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described integrated equipment control method based on rail transit networks, thereby solving the technical problem of poor rail transit communication quality. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the integrated equipment control method based on rail transit networks provided in the above embodiments, and will not be repeated here.

[0144] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A method for controlling integrated equipment based on rail transit networks, characterized in that, The method includes: Receive the user's command to enable the converged function, configure the rail transit networking parameters and security policy parameters corresponding to the switching chip and firewall chip respectively, and obtain the converged hardware architecture; The function start / stop sub-instructions in the fusion function enable instruction are parsed, the firewall module and switch module are controlled according to the function start / stop sub-instructions, the resources corresponding to the inactive modules are set to a dormant state, and the function operation status that meets the scenario requirements is output. The primary and backup redundancy configuration synchronization process is initiated according to the functional operation status. The relevant units built into the switching chip and the firewall chip are set according to the redundancy configuration strategy to obtain the primary and backup redundancy system. In response to system verification commands, the system verifies the configuration files and runtime events of the primary and backup redundant system, generates a configuration adjustment strategy, and optimizes the primary and backup redundant system using the configuration adjustment strategy.

2. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, The steps of receiving the user-issued convergence function activation command, configuring the rail transit networking parameters and security policy parameters corresponding to the switching chip and firewall chip respectively, and obtaining the converged hardware architecture include: The function activation requirements, rail transit dedicated communication protocol adaptation requirements, and security protection level parameters contained in the received fusion function activation instruction are analyzed and used to form a hardware initialization trigger signal; The switching chip and the firewall chip are connected through a physical interface, and the management ports of the two chips are sequentially connected to the external switching chip and the panel management port to obtain the hardware infrastructure. Configure the rail transit network topology configuration parameters of the switching chip according to the instruction parameter set corresponding to the hardware infrastructure, and configure the rail transit network boundary security protection strategy of the firewall chip according to the security protection level parameters corresponding to the hardware infrastructure, and integrate to generate the converged hardware architecture.

3. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, The steps of parsing the function start / stop sub-instructions in the convergence function enable instruction and controlling the firewall module and switch module according to the function start / stop sub-instructions include: The function start / stop sub-instructions in the converged function enable instruction are analyzed to extract the specific requirements for independent enable, independent disable, and collaborative enable of the switch module and firewall module, as well as the module operation priority parameters, and integrated to generate a function start / stop requirement set. Based on the module start / stop requirements in the function start / stop requirement set, determine the resource status of the firewall module and the switch module, complete the status configuration of resource hibernation and rail transit service parameter loading, and generate a pre-run architecture; Based on the pre-running architecture, the service operation process is started, the data interaction path between modules is verified, and it is confirmed that the resources of the hibernation module are not occupied by any service process. The basic functional operation status of the firewall module and the switch module is output.

4. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, The steps of setting the resources corresponding to the inactive modules to a dormant state and outputting the functional running status that meets the scenario requirements include: Verify the current hardware computing resource usage and software process running status of each module in the pre-running architecture, and extract the list of modules that need to be kept in hibernation and the list of modules that need to be kept active, forming a module status verification list; According to the module status list, the basic function operation status is matched and verified, the resources of the dormant and inactive modules are put into hibernation, the rail transit business parameters of the enabled modules are confirmed, and the initial tuning architecture matching the module status is output. Based on the initial tuning architecture, the service connectivity of the confirmation module and the resource status of the dormant module are determined, and the parameters of the initial tuning architecture are adjusted in conjunction with the corresponding rail transit scenario to generate the functional operation status that conforms to the rail transit scenario.

5. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, The steps of initiating the primary / standby redundancy configuration synchronization process according to the functional operating status, and setting the relevant units built into the switching chip and firewall chip according to the redundancy configuration strategy to obtain the primary / standby redundancy system include: Based on the function's operating status, initiate the primary / backup redundancy configuration synchronization process. In accordance with the redundancy configuration strategy, set the central processing unit built into the switching chip as the primary processing unit and the central processing unit built into the firewall chip as the backup processing unit, thus forming a basic redundancy architecture. Based on the aforementioned basic redundancy architecture, the fusion function configuration information is sent to the primary processing unit, and then synchronized by the primary processing unit to the backup processing unit to output the pre-redundancy system. Verify the cyclic redundancy of the primary and backup processing unit configuration files in the pre-redundancy system, and output the primary and backup redundancy system after the configurations are completely consistent.

6. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, The steps of responding to the system verification command, verifying the configuration file and runtime events of the primary / standby redundant system for primary / standby synchronization, and generating a configuration adjustment strategy include: The system analyzes the specified verification range in the system verification instruction, extracts the integrity dimension of the configuration file and the timeliness dimension of the running event synchronization that need to be verified, and retrieves the preset verification benchmark rules in the primary and backup redundant system to form a detailed list of verification tasks. According to the detailed list of verification tasks, check the running event logs of the primary and backup processing units to complete the synchronization status verification, record the specific modules and contents that passed or failed the verification, and obtain the primary and backup synchronization status verification result set. For configuration file differences that fail verification, a strategy is generated for the backup processing unit to synchronize the configuration from the primary processing unit, and a strategy is generated for the primary processing unit to resend event information for unsynchronized running events. The configuration adjustment strategy is then integrated to generate the above strategy.

7. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, The steps of optimizing the primary / standby redundancy system through the configuration adjustment strategy include: The configuration synchronization type, event resending requirement, and state maintenance instruction in the configuration adjustment strategy are analyzed to obtain the adjustment parameters; Optimize the system parameters of the primary and backup redundant system according to the adjustment parameters, and generate a redundant system to be verified. The configuration file cyclic redundancy check is re-executed on the primary and backup processing units of the redundancy system to be verified, and the forwarding status and blocking status of the management port of the primary and backup processing units are confirmed to obtain the intermediate redundancy system. Verify the connectivity of the heartbeat path of the interrupt signal pins between the primary and backup processing units and the functionality of data transmission, and output the optimized primary and backup redundancy system.

8. The integrated equipment control method based on rail transit network as described in claim 1, characterized in that, After the steps of responding to the system verification command, verifying the configuration file and primary / backup synchronization of the primary / backup redundant system, generating a configuration adjustment strategy, and optimizing the primary / backup redundant system through the configuration adjustment strategy, the integrated equipment control method based on the rail transit network further includes: Initiate the heartbeat interaction process between the primary and backup processors of the firewall via interrupt pins, transmit heartbeat signals according to a preset fixed cycle, and output a monitoring system with heartbeat monitoring capabilities. When the monitoring system detects the disappearance of the heartbeat signal of the primary processor, it triggers a role switching mechanism, switches itself to become the backup processor and takes over the system control of the entire fusion device, generating an emergency primary and backup redundant operation system. When the monitoring system detects that the primary processor has returned to normal and the heartbeat signal has been restored, it triggers the role switching mechanism to switch the system control back to the primary processor and obtain the fault file.

9. A fusion device, characterized in that, The fusion device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the fusion device control method based on a rail transit network as described in any one of claims 1 to 8.

10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the integrated equipment control method based on rail transit network as described in any one of claims 1 to 8.