Multi-core heterogeneous controller and real-time task scheduling method for a shouge barren environment
Patent Information
- Application Number
- CN202610956987.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-30
- Publication Date
- 2026-09-18
AI Technical Summary
[0008]虽然已有一些关于混合关键性系统调度的研究提出了在过载时舍弃低关键性任务的策略,但这些方案多集中于调度算法本身,未能与多核异构硬件架构深度协同,以充分发挥不同类型处理核心的专长,从而在极端环境下实现硬实时任务的绝对可靠、软实时任务的高效处理以及系统资源的智能优化配置
1.构建了解决极端环境下任务异构性矛盾的基础硬件平台,通过划分“确定性处理核心”和“高性能处理核心”,该架构在硬件层面将“硬实时任务”与“软实时/通用任务”的执行路径物理隔离。这从根本上避免了单一类型处理器在处理两类任务时相互干扰、难以兼顾的固有矛盾,为分别采用最适合的调度策略(时间触发vs.动态优先级抢占)提供了硬件基础。
Smart Images

Figure CN122776754A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of industrial automation control and embedded systems technology, and in particular to a multi-core heterogeneous controller and real-time task scheduling method for use in desert environments. Background Technology
[0002] The statements in this section are merely background information related to this application and do not necessarily constitute prior art.
[0003] In extreme environments such as deserts, Gobi, and wastelands (collectively referred to as "desert-gobi-desert"), industrial control systems deployed for tasks such as water resource regulation, monitoring of new energy power generation facilities, and meteorological station data collection face enormous challenges. These regions experience extreme diurnal temperature variations, strong sandstorms, high ultraviolet radiation, and long-term unattended operation, placing extremely high demands on the reliability, real-time performance, and environmental adaptability of controllers.
[0004] Currently, industrial controllers mostly employ single-core processors or homogeneous multi-core architectures, and their task scheduling mechanisms are typically based on fixed-priority preemption algorithms or time-triggered scheduling strategies. However, these existing solutions have the following shortcomings when dealing with the complex task requirements and dynamic operating conditions of the desert environment: First, there are shortcomings in terms of the heterogeneity of task processing. Taking the Shagohuang water resource regulation system as an example, it needs to perform both hard real-time valve control tasks (requiring millisecond-level deterministic response) and computationally intensive soft real-time tasks (such as environmental data analysis or artificial intelligence prediction) simultaneously on the same processor. Traditional homogeneous processing architectures struggle to handle these two types of tasks with drastically different requirements for computing resources and real-time performance on the same processor, often resulting in fluctuating response times for hard real-time tasks or limited computational performance for soft real-time tasks.
[0005] Secondly, the fixed-priority scheduling mechanism is not adaptable enough to dynamic environments. In unattended desert environments, the system may encounter emergencies such as sudden sensor alarms or equipment failures, causing the criticality of certain tasks to increase dramatically. However, the fixed-priority setting cannot reflect such dynamic changes, and may miss the response window for urgent tasks, affecting system security.
[0006] Furthermore, while pure time-triggered scheduling can provide deterministic guarantees for critical tasks, it suffers from poor flexibility and low resource utilization. This method pre-allocates a fixed execution time window for each task. When the task load is light or a critical task completes ahead of schedule, the idle time slices cannot be flexibly utilized by other tasks, resulting in a waste of processor resources and reducing the overall system efficiency.
[0007] Finally, existing scheduling mechanisms generally lack the ability to perceive and adaptively adjust to the drastically changing system states in the desert environment (such as fluctuations in solar power supply, increased communication latency, and processor performance degradation due to temperature changes). They struggle to dynamically adjust scheduling strategies to prioritize the execution of the most critical tasks and optimize resource utilization when resources are limited or conditions deteriorate.
[0008] Although some studies on scheduling of hybrid critical systems have proposed strategies to discard low-critical tasks under overload, these solutions mostly focus on the scheduling algorithm itself and fail to deeply collaborate with multi-core heterogeneous hardware architectures to fully leverage the expertise of different types of processing cores, thereby achieving absolute reliability of hard real-time tasks, efficient processing of soft real-time tasks, and intelligent optimization of system resources in extreme environments.
[0009] Therefore, there is an urgent need for an innovative controller architecture and scheduling method that can effectively solve the above problems and meet the stringent requirements of industrial control systems in the extreme environment of the desert for high reliability, strong real-time performance and excellent adaptability. Summary of the Invention
[0010] To overcome the shortcomings of the prior art, this application provides a multi-core heterogeneous controller and a real-time task scheduling method for the desert environment, which meets the stringent requirements of industrial control systems for high reliability, strong real-time performance and excellent adaptability in the extreme environment of the desert.
[0011] To achieve the above objectives, this application provides the following technical solution: Firstly, a multi-core heterogeneous controller for a desert environment is provided, comprising a deterministic processing core, a high-performance processing core, and shared memory. The deterministic processing core and the high-performance processing core are interconnected via an on-chip bus and are capable of inter-core communication; wherein: The deterministic processing core is a processing core implemented using a real-time processor with deterministic interrupt response latency, configured with a runtime-triggered scheduling mechanism to execute hard real-time tasks. The high-performance processing core is a processing core implemented using a general-purpose reduced instruction set processor, configured to run a real-time operating system to preemptively schedule soft real-time tasks based on the dynamic priority of the tasks.
[0012] Furthermore, it also includes an artificial intelligence acceleration core, which is a processing core implemented using a neural network processing unit, a graphics processing unit, or a field-programmable gate array, and is communicatively connected to the high-performance processing core through a dedicated driver interface. The artificial intelligence acceleration core is configured to execute deep learning inference, pattern recognition, or optimization computing tasks assigned by the high-performance processing core.
[0013] Furthermore, the deterministic processing core is a real-time processor with deterministic interrupt response capability and low task switching overhead, and is equipped with tightly coupled memory and a dedicated interrupt controller to ensure the deterministic execution of the hard real-time task.
[0014] Furthermore, the shared memory is connected to the deterministic processing core and the high-performance processing core via a multi-port storage controller, which allocates an independent access channel and the highest access priority to the deterministic processing core.
[0015] Furthermore, the shared memory is provided with a storage protection unit, which divides the address space of the shared memory into dedicated memory regions corresponding to each processing core, so as to achieve memory access isolation between cores.
[0016] Secondly, a real-time task scheduling method for the desert environment is provided, applied to the multi-core heterogeneous controller as described above, the method comprising: On the deterministic processing core, each hard real-time task is periodically executed according to a pre-generated time-triggered scheduling table within a fixed time window pre-allocated to each hard real-time task. On the high-performance processing core, scheduling priorities are determined based on criticality scores dynamically calculated for each soft real-time task, and preemptive scheduling is performed on the ready soft real-time tasks according to the scheduling priorities. Detect the system load of the high-performance processing core; When the system load exceeds a preset threshold, an overload protection operation is performed.
[0017] Furthermore, the criticality score is calculated using a predefined evaluation model, where a higher score corresponds to a higher scheduling priority. The calculation formula for the evaluation model is as follows: K i (t)=α(t)·K i0 +β(t)·f'(w i (t) / L i , (t))+γ(t)·g(S(t))+δ(t)·h(E(t)) Among them, K i (t) represents the criticality score of task i at time t, K i0 For the initial critical level, w i (t) represents the waiting time, L iLet S(t) be the delay tolerance threshold, S(t) be the state vector representing the system load, E(t) be the state variable representing the energy state, α(t), β(t), γ(t), and δ(t) be weighting coefficients dynamically adjusted according to the environmental stress coupling exponent Φ(t), and f' be the enhancement mapping function containing inter-core coupling parameters. (t) represents the average execution time margin of the deterministic processing core feedback, and g and h represent the preset mapping functions.
[0018] Furthermore, the environmental stress coupling index Φ(t) is calculated using the following formula: Φ(t)=max(Φ coupling (t),Φ floor (t)) Where, Φ coupling (t)=[ (t)] a ×[1-Ê(t)] b ×[1+λ· (t)] c For multi-factor coupling terms, Φ floor (t)=max(μ T · (t),μ E ·(1-Ê(t)),μ D · (t) is a single-factor catch-all term; (t) represents the normalized temperature stress. (t)=(T(t)-T low ) / (T high -T low ), where T(t) is the current ambient temperature, T low and T high These represent the lower and upper limits of the controller's rated operating temperature, respectively; Ê(t) is the normalized energy availability, Ê(t) = E avail (t) / E rated ; (t) represents the normalized dust disturbance index; a, b, and c are coupling indices greater than or equal to 1; λ is the dust sensitivity coefficient; μ T μ E μ D This serves as a safety net contribution coefficient for each individual factor.
[0019] Furthermore, the weighting coefficients are dynamically adjusted based on the environmental stress coupling index Φ(t), including: α(t) = α0·[1 + σ α ·Φ(t)] β(t) = β0·[1 + σ β ·Φ(t)] γ(t)=γ0·[1+σ γ ·Φ(t)] δ(t)=δ0·[1+σ δ ·Φ(t)] Where α0, β0, γ0, and δ0 are the benchmark weighting coefficients, and σ α σ β σ γ σ δ The sensitivity coefficient of each weight to environmental stress is given, wherein the sensitivity coefficient takes different preset values under different operating modes to achieve coordinated linkage between weight adjustment and mode switching.
[0020] Furthermore, the expression for the enhanced mapping function f' is: f'(x, )=x n / max(1-x m +ε+ρ· (t),ε min ) in, ρ is the average execution time margin of all hard real-time tasks in the deterministic processing core feedback, ρ is the inter-core coupling coefficient, n and m are positive integers, and ε is a positive minimal constant. min This is a lower bound protection constant for the denominator, ensuring that the denominator is always positive.
[0021] Furthermore, at the end of each time window, the deterministic processing core calculates the execution time margin η of the current hard real-time task. i (t), its calculation formula is: η i (t)=(G i -C i,actual (t)) / G i Among them, G i The current time window width allocated to task i, C i,actual (t) represents the actual execution time, and η is... i (t) Write to the execution telemetry region of the shared memory; The high-performance processing core periodically reads the execution telemetry region and calculates the weighted average execution time margin. (t)=Σ(K i0 ·η i (t)) / Σ(K i0 ), and will (t) is substituted into the enhanced mapping function f' to participate in the criticality score calculation.
[0022] Furthermore, the high-performance processing core calculates the protection margin adjustment amount for each hard real-time task based on the environmental stress coupling index Φ(t), and transmits the protection margin adjustment amount to the deterministic processing core through the scheduling parameter area of the shared memory. The deterministic processing core adjusts the time window width of the corresponding task in the time trigger scheduling table according to the protection margin adjustment amount at the next main cycle boundary.
[0023] Furthermore, the overload protection operation includes at least one of the following operations: Reduce the execution frequency of tasks with a criticality score below the first threshold; Suspend tasks whose criticality score is below the second threshold; The multi-core heterogeneous controller is controlled to enter emergency mode, in which only tasks with a criticality score higher than the third threshold are scheduled for execution.
[0024] Furthermore, the method also includes: Based on the comprehensive evaluation value M(t) of mode switching, adaptive switching is performed between multiple preset operating modes, including at least normal mode, high load mode and emergency mode; M(t) is calculated using the following formula: M(t) = ω1·Φ(t) + ω2·L hp (t)+ω3·(dΦ / dt) + Where Φ(t) is the environmental stress coupling index, L hp (t) represents the normalized load rate of the high-performance processing core, (dΦ / dt) + ω1, ω2, and ω3 are the positive values of the rate of change of the environmental stress coupling index, and ω1, ω2, and ω3 are the mode switching weight coefficients. The adaptive switching includes hysteresis constraints: the threshold for uplink switching is higher than the threshold for downlink switching, and the dwell time of any mode is not lower than the preset minimum dwell time.
[0025] Furthermore, when the deterministic processing core reports that any hard real-time task has timed out consecutively a preset fault threshold N, fault At that time, regardless of the value of M(t), immediately switch to emergency mode.
[0026] Compared with the prior art, the beneficial effects of this application are as follows: 1. A foundational hardware platform was constructed to resolve the contradiction of task heterogeneity in extreme environments. By dividing the system into "deterministic processing cores" and "high-performance processing cores," this architecture physically isolates the execution paths of "hard real-time tasks" and "soft real-time / general-purpose tasks" at the hardware level. This fundamentally avoids the inherent contradiction of mutual interference and difficulty in handling two types of tasks by a single type of processor, providing a hardware foundation for adopting the most suitable scheduling strategies (time-triggered vs. dynamic priority preemption) respectively.
[0027] 2. It provides a core scheduling strategy that perfectly coordinates with dedicated hardware architectures, achieving a balance between "deterministic guarantees for hard real-time tasks" and "flexible and efficient soft real-time tasks," while also possessing basic overload handling capabilities. A hybrid scheduling framework is adopted. This method uses static, offline planning-based "time-triggered scheduling" on the deterministic core to ensure the periodicity and predictability of hard real-time tasks; on the high-performance core, it employs dynamic, online decision-making-based "preemptive scheduling based on criticality scoring" to fully utilize remaining resources for soft real-time tasks. This framework combines the advantages of two classic scheduling methods at the strategy level, resolving the traditional contradiction between determinism and flexibility.
[0028] 3. A nonlinear coupled sensing mechanism for multiple environmental stress factors was achieved. Through an original environmental stress coupling exponent Φ(t), the three environmental factors—temperature, energy, and dust—were elevated from independent processing to product-coupled modeling, capturing the superlinear amplification effect when multiple factors deteriorate simultaneously. This coupling exponent drives adaptive adjustment of scheduling weights, enabling the system to make timely and sufficient scheduling responses in hidden danger scenarios where a single factor changes slightly but multiple factors deteriorate jointly. This coupled sensing capability is a fundamental transcendence of existing linear independent processing methods and cannot be achieved by any single sensing mechanism independently implementing temperature sensing, energy sensing, or dust sensing.
[0029] 4. A runtime bidirectional closed-loop feedback mechanism was constructed between the deterministic core and the high-performance core. This mechanism enables the real-time state of the hardware execution layer to adjust the decision parameters of the software scheduling layer, while the environmental awareness of the software scheduling layer can be fed forward to the time window configuration of the hardware execution layer. This closed-loop coupling produces three synergistic effects that cannot be achieved by implementing feedback in either direction alone: first, a margin adaptation effect—the execution margin of the deterministic core affects the tightness of soft real-time scheduling through the enhanced mapping function f'; second, an environmental early warning feedforward effect—environmental deterioration information simultaneously drives both hard real-time prevention and soft real-time contraction paths; and third, an anti-oscillation stabilization effect—the bidirectional feedback forms a natural negative feedback loop, effectively suppressing mode switching oscillations.
[0030] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures pointed out in the description, claims and drawings.
[0031] The present application will be further described below with reference to the accompanying drawings. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 This is a schematic diagram of the overall architecture of a multi-core heterogeneous controller for a desert environment according to an embodiment of this application; Figure 2 This is a flowchart illustrating a real-time task scheduling method for a desert environment according to an embodiment of this application; Figure 3 This is a flowchart illustrating another embodiment of the real-time task scheduling method for a desert environment according to this application. Detailed Implementation
[0034] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0035] like Figure 1 As shown, one embodiment of this application provides a multi-core heterogeneous controller for a desert environment, including a deterministic processing core, a high-performance processing core, and shared memory. The deterministic processing core and the high-performance processing core are interconnected via an on-chip bus and are capable of inter-core communication; wherein: The deterministic processing core is a processing core implemented using a real-time processor with deterministic interrupt response latency, configured with a runtime-triggered scheduling mechanism to execute hard real-time tasks. The high-performance processing core is a processing core implemented using a general-purpose reduced instruction set processor, configured to run a real-time operating system to preemptively schedule soft real-time tasks based on the dynamic priority of the tasks.
[0036] The above technical solution constructs a basic hardware platform to resolve the contradiction of task heterogeneity in extreme environments, laying the foundation for software and hardware co-optimization at the physical level. Its technical effects are reflected in at least the following aspects: Architecture Partitioning: By dividing the system into "deterministic processing cores" and "high-performance processing cores," this architecture physically isolates the execution paths of "hard real-time tasks" from those of "soft real-time / general-purpose tasks" at the hardware level. This fundamentally avoids the inherent contradiction of mutual interference and difficulty in handling two types of tasks by a single type of processor, providing a hardware foundation for adopting the most suitable scheduling strategies (time-triggered vs. dynamic priority preemption) respectively.
[0037] Dedicated Cores for Dedicated Tasks: The "deterministic processing core" is explicitly defined as running a "time-triggered scheduling mechanism," while the "high-performance processing core" is defined as running a "real-time operating system" and performing "dynamic priority" scheduling. This clarifies the specific purpose and design goals of each core. This transforms the controller design from a mere stack of general-purpose computing units into a heterogeneous system tailored to specific task requirements. Its hardware selection and resource configuration directly serve the invention's objectives of achieving determinism, flexibility, and adaptability.
[0038] Basic communication guarantee: It is clear that "shared memory" and "inter-core communication" are essential elements of the architecture, ensuring that multiple cores can effectively coordinate and exchange data, which is a prerequisite for realizing software and hardware collaboration and cross-core task cooperation.
[0039] This solution, for the first time at the hardware architecture level, creatively decouples "deterministic real-time control" from "high-performance flexible computing" to meet the specific needs of the desert environment, and equips each with the most suitable processor core and scheduling strategy prototype. This solution lays the foundation for this application: while ensuring absolute determinism for hard real-time tasks, it reserves flexible and efficient space for processing soft real-time tasks, and integrates the two into a unified controller through an inter-core collaboration mechanism. This is the prerequisite and carrier for realizing all the more advanced technical effects of subsequent technical solutions, such as dynamic scheduling and adaptive protection.
[0040] As a preferred technical solution, the multi-core heterogeneous controller further includes an artificial intelligence acceleration core. The artificial intelligence acceleration core is a processing core implemented using a neural network processing unit, a graphics processing unit, or a field-programmable gate array, and is communicatively connected to the high-performance processing core through a dedicated driver interface. The artificial intelligence acceleration core is configured to execute deep learning inference, pattern recognition, or optimization calculation tasks assigned by the high-performance processing core.
[0041] This embodiment adds an AI acceleration core, expanding the controller's intelligent computing and complex task processing capabilities. It achieves heterogeneous collaboration between control, computing, and AI inference, improving the overall system performance and intelligence level. By introducing a dedicated NPU, GPU, or FPGA as the AI acceleration core, this solution provides the system with powerful parallel computing and deep learning inference capabilities. This enables the controller to efficiently process computationally intensive AI tasks such as pattern recognition, time-series prediction, and image analysis locally (at the edge), reducing the burden on the high-performance processing core and significantly improving energy efficiency and speed in handling such tasks. The solution also clarifies that the AI acceleration core is "controlled" and "allocated" tasks by the high-performance processing core, forming a master-slave collaborative computing model. Complex computing tasks can be offloaded from the main CPU to the dedicated accelerator, allowing the high-performance processing core to focus more on core management functions such as system scheduling and communication coordination, optimizing the entire system's task pipeline.
[0042] As a preferred technical solution, the deterministic processing core is a real-time processor with deterministic interrupt response capability and low task switching overhead, and is equipped with tightly coupled memory and a dedicated interrupt controller to ensure the deterministic execution of the hard real-time task.
[0043] This embodiment systematically eliminates or strictly limits timing uncertainties at three crucial hardware levels: processor core performance, memory access paths, and interrupt management mechanisms. This provides a solid and reliable physical platform guarantee for the "deterministic execution" of hard real-time tasks. Specifically, the deterministic processor provides fast and predictable scheduling and computation capabilities; tightly coupled memory provides deterministic, low-latency instruction and data supply; and a dedicated interrupt controller provides a deterministic, undisturbed "triggering" mechanism. The combination of these three elements creates a highly isolated, resource-dedicated, and predictable execution environment for hard real-time tasks at the hardware level. This environment is the physical basis for the "time-triggered scheduling mechanism" described in the aforementioned scheme to strictly adhere to its timetable in reality, and it is also the key hardware support for achieving the core beneficial effect of "deterministic guarantee of hard real-time tasks" in the extreme environment of the Gobi Desert.
[0044] In some preferred embodiments, the deterministic processing core has an interrupt response latency of less than 1 microsecond, a task switching overhead of less than 100 clock cycles, and is equipped with tightly coupled memory and a dedicated interrupt controller to ensure the deterministic execution of the hard real-time task. This embodiment defines specific performance parameters for the deterministic processing core, providing concrete and measurable hardware performance guarantees for the "determinism" of the hard real-time task, which is the key material basis for ensuring that the deadline is met in the worst case. Among them, parameters such as "interrupt response latency of less than 1 microsecond" and "task switching overhead of less than 100 clock cycles" quantify the real-time performance of the processing core from both time and cycle dimensions; this transforms "determinism" from an abstract concept into a designable and verifiable technical indicator, ensuring that in extreme cases, the response time jitter of the hard real-time task is strictly limited to an acceptablely low range. "Equipped with tightly coupled memory and a dedicated interrupt controller" is the key hardware support for ensuring the realization of the above performance parameters; the tightly coupled memory provides low-latency data access, and the dedicated interrupt controller ensures the predictability of interrupt response, avoiding competition and uncertainty in hardware resources, and together constructing a "fast track" for the hard real-time task.
[0045] As a preferred technical solution, the shared memory is connected to the deterministic processing core and the high-performance processing core through a multi-port storage controller, and the multi-port storage controller allocates an independent access channel and the highest access priority to the deterministic processing core.
[0046] This embodiment defines the access control mechanism for shared memory, ensuring absolute priority and low latency for deterministic processing cores when accessing shared resources. This is the "lifeline" for preventing execution blockage and guaranteeing the determinism of hard real-time tasks. Specifically, allocating an "independent access channel" to the deterministic core means that its physical path to access shared memory is not interfered with by traffic from other cores, avoiding random latency caused by bus contention. Assigning it "highest access priority" in the multi-port memory controller means that when access conflicts occur, the requests of the deterministic core will be served first. The combination of these two measures eliminates the timing uncertainties that may be introduced by resource contention at the memory subsystem level, a key aspect of hardware isolation design, and directly supports the reliable execution of hard real-time tasks.
[0047] As a preferred technical solution, the shared memory is provided with a storage protection unit, which divides the address space of the shared memory into dedicated memory regions corresponding to each processing core, so as to achieve memory access isolation between cores.
[0048] This embodiment defines a memory isolation mechanism for shared memory, achieving logical isolation and protection of memory access between multiple cores. This improves system reliability and security, and prevents cross-core data corruption caused by software errors. Specifically, by dividing "dedicated memory regions" through a storage protection unit, it ensures that each processing core can only access its authorized memory space. This prevents accidental modification of critical data on another core due to software faults on one core (such as pointer out-of-bounds errors), which is particularly important in long-term unattended, high-reliability environments. Memory isolation is not only a security feature but also indirectly ensures determinism. It avoids damage to critical task data or program anomalies caused by memory overflows, thereby reducing unexpected task execution time fluctuations and enhancing the overall robustness of the system.
[0049] As a preferred technical solution, the multi-core heterogeneous controller further includes an input / output interface module, which includes: a first type of interface, directly connected to the deterministic processing core, for connecting sensors and actuators that have a first requirement for control real-time performance; and a second type of interface, connected to the high-performance processing core, for connecting devices that have a second requirement for communication real-time performance; wherein the first requirement is higher than the second requirement.
[0050] This embodiment defines differentiated connection methods for input / output interfaces, optimizes I / O paths, and shortens end-to-end latency in critical control loops, making it a crucial design for meeting millisecond-level response requirements in hard real-time tasks. Specifically, sensors and actuators with the highest real-time requirements ("Type 1 interfaces") are directly connected to the deterministic processing core, eliminating the software overhead and scheduling latency associated with the operating system, driver layer, and potential inter-core communication; this achieves the most direct and fastest physical path from signal acquisition to control response. Communication devices with relatively lower real-time requirements ("Type 2 interfaces") are connected to the high-performance processing core and managed uniformly by the operating system. This differentiated I / O architecture design, while keeping costs and complexity under control, precisely allocates valuable low-latency hardware resources to the most needed control loops, achieving optimal system efficiency.
[0051] like Figure 2As shown, one embodiment of this application also provides a real-time task scheduling method for a desert environment, applied to the multi-core heterogeneous controller described above. The method includes: on the deterministic processing core, periodically executing each hard real-time task within a fixed time window pre-allocated to each hard real-time task according to a pre-generated time-triggered scheduling table; on the high-performance processing core, determining a scheduling priority based on a criticality score dynamically calculated for each soft real-time task, and performing preemptive scheduling on the ready soft real-time tasks according to the scheduling priority; detecting the system load of the high-performance processing core; and performing overload protection operation when the system load exceeds a preset threshold.
[0052] The above technical solution provides a core scheduling strategy that perfectly coordinates with dedicated hardware architecture, achieving a balance between "hard real-time deterministic guarantees" and "soft real-time flexibility and efficiency," and possessing basic overload handling capabilities. Specifically: Hybrid scheduling framework: This method employs static, offline planning-based "time-triggered scheduling" on the deterministic core to ensure the periodicity and predictability of hard real-time tasks; on the high-performance core, it adopts dynamic, online decision-making-based "preemptive scheduling based on criticality scoring" to fully utilize remaining resources for soft real-time tasks. This framework combines the advantages of two classic scheduling methods at the policy level, resolving the traditional contradiction between determinism and flexibility.
[0053] Overload protection entry point: It explicitly includes the steps of "detecting load" and "performing overload protection operation", which makes the method inherently equipped with a defense mechanism to deal with sudden high loads. It provides a strategic basis for the system to maintain core functions when resources are scarce, and enhances robustness.
[0054] In some preferred embodiments, the method further includes: collecting current environmental temperature, energy availability, and dust disturbance data; calculating an environmental stress coupling index based on the current environmental temperature, energy availability, and dust disturbance data; and dynamically adjusting the weight coefficients in the criticality score according to the environmental stress coupling index.
[0055] In some preferred embodiments, the method further includes: receiving the execution time margin rate of each hard real-time task fed back by the deterministic processing core, and calculating the statistical value (i.e., weighted average) of the execution time margin rate. (t) is fed back as an inter-core coupling parameter to the criticality score calculation process (i.e., the calculation of the enhanced mapping function f').
[0056] In some preferred embodiments, dynamically calculating the criticality score for each soft real-time task includes: acquiring static attribute parameters of the task, including an initial criticality level and a latency tolerance threshold; collecting dynamic system status parameters, including processor load rate and power status; monitoring dynamic information of the task, including the waiting time of the task since its last execution; and calculating the criticality score using a predefined evaluation model based on the static attribute parameters, the system dynamic status parameters, and the dynamic information, wherein a higher score corresponds to a higher scheduling priority.
[0057] This embodiment defines the calculation elements of dynamic criticality scoring, which defines an intelligent evaluation model for scheduling decisions. This model enables task priorities to comprehensively reflect their inherent attributes, real-time urgency, and system environment status, and is the core of achieving dynamic adaptation. Specifically: Multi-dimensional perception: This model no longer relies solely on statically preset priorities, but integrates three major categories of information: 1) static attributes of tasks (such as initial importance, degree of delay, etc.); 2) dynamic information of tasks (such as how long they have been waiting); 3) dynamic status of the system (such as load, power, etc.). This enables the scheduler to act like an "intelligent butler," comprehensively perceiving internal and external situations and making more reasonable decisions.
[0058] Dynamic response foundation: It is precisely because of the introduction of variables such as "waiting time" and "system state" that the criticality of the task can be dynamically adjusted over time and as conditions change, laying the foundation for subsequent implementation of functions such as delay penalty and environmental adaptation.
[0059] The core algorithms of the dynamic scoring model (formula, environmental index, weight adjustment, and enhanced mapping function) will be explained in further detail below.
[0060] As a preferred technical solution, the criticality score is calculated using a predefined evaluation model, where a higher score corresponds to a higher scheduling priority; the calculation formula for the evaluation model is as follows: K i (t)=α(t)·K i0 +β(t)·f'(w i (t) / L i , (t))+γ(t)·g(S(t))+δ(t)·h(E(t)) Among them, K i (t) represents the criticality score of task i at time t, K i0 For the initial critical level, w i (t) represents the waiting time, L iLet S(t) be the delay tolerance threshold, S(t) be the state vector representing the system load, E(t) be the state variable representing the energy state, α(t), β(t), γ(t), and δ(t) be weighting coefficients dynamically adjusted according to the environmental stress coupling exponent Φ(t), and f' be the enhancement mapping function containing inter-core coupling parameters. (t) represents the average execution time margin of the deterministic processing core feedback, and g and h represent the preset mapping functions.
[0061] This embodiment provides a way to integrate multi-dimensional information (K) i0 ,w i (t) / L i S(t), E(t)) are merged into a single comparable score K i The mathematical framework of (t) is introduced. Time-varying weights α(t), β(t), γ(t), δ(t) and parameters including inter-kernel coupling are introduced. The enhanced mapping function f' of (t) lays the foundation for dynamic adaptation.
[0062] It should be noted that existing solutions generally treat environmental factors (temperature, energy, dust, etc.) as independent disturbance variables, failing to capture the coupled amplification effect when multiple environmental stresses occur simultaneously. Taking a desert environment as an example, when a dust storm strikes, the simultaneous action of three factors—a sharp drop in photovoltaic power generation (energy deterioration), a decrease in sensor accuracy (increased dust interference), and processor frequency reduction due to heat dissipation difficulties (increased temperature stress)—poses a far greater combined threat to the reliability of system scheduling than the simple superposition of the three factors' independent effects. Existing linear superposition or independent threshold judgment methods cannot reflect this nonlinear coupling characteristic, potentially leading to an underestimation of risk and insufficient response in scenarios where multiple factors deteriorate together. To overcome the shortcomings of existing solutions, this embodiment introduces an environmental stress coupling index Φ(t) and dynamically adjusts the weighting coefficients α(t), β(t), γ(t), and δ(t) based on the environmental stress coupling index Φ(t).
[0063] As a preferred technical solution, the environmental stress coupling index Φ(t) is calculated using the following formula: Φ(t)=max(Φ coupling (t),Φ floor (t)) Where, Φ coupling (t)=[ (t)] a ×[1-Ê(t)] b ×[1+λ· (t)] c For multi-factor coupling terms, Φ floor (t)=max(μ T · (t),μE ·(1-Ê(t)),μ D · (t) is a single-factor catch-all term; (t) represents the normalized temperature stress. (t)=(T(t)-T low ) / (T high -T low ), where T(t) is the current ambient temperature, T low and T high These represent the lower and upper limits of the controller's rated operating temperature, respectively; Ê(t) is the normalized energy availability, Ê(t) = E avail (t) / E rated ; (t) represents the normalized dust disturbance index; a, b, and c are coupling indices greater than or equal to 1; λ is the dust sensitivity coefficient; μ T μ E μ D This represents the catch-all contribution coefficient for each individual factor. The single-factor catch-all term ensures that when any one environmental factor deteriorates severely while the others remain normal, the environmental stress coupling index still reflects the independent threat posed by that single factor.
[0064] In this embodiment, the current ambient temperature T(t) and available energy E are collected. avail (t) and dust disturbance data Calculate the environmental stress coupling index Φ(t); dynamically adjust the weight coefficients α(t), β(t), γ(t), and δ(t) in the criticality score based on the environmental stress coupling index Φ(t), so that each weight coefficient adaptively increases as the degree of environmental stress increases.
[0065] This embodiment provides a formula for calculating the environmental stress coupling index Φ(t), which is the core of realizing nonlinear coupling sensing of multiple environmental factors. Its technical advantages are as follows: 1. Capturing superlinear amplification effect: through the product-form coupling term Φ coupling (t) indicates that when multiple factors such as temperature, energy, and dust storms deteriorate simultaneously, their combined threat is nonlinearly amplified, rather than simply added together. This more accurately reflects the actual harm caused by extreme events such as dust storms.
[0066] 2. Eliminate perceptual blind spots: Introduce a single-factor catch-all term Φ through maximum value calculation. floor (t) ensures that when one factor (such as energy) is normal while another factor (such as temperature) deteriorates significantly, the index can still effectively reflect the independent threat of that single factor, avoiding the perception failure caused by the product returning to zero.
[0067] As a preferred technical solution, the weighting coefficients are dynamically adjusted based on the environmental stress coupling index Φ(t), including: α(t) = α0·[1 + σ α ·Φ(t)];β(t)=β0·[1+σ β ·Φ(t)]; γ(t)=γ0·[1+σ γ ·Φ(t)];δ(t)=δ0·[1+σ δ ·Φ(t)].
[0068] Where α0, β0, γ0, and δ0 are the benchmark weighting coefficients, and σ α σ β σ γ σ δ The sensitivity coefficient of each weight to environmental stress is given, wherein the sensitivity coefficient takes different preset values under different operating modes to achieve coordinated linkage between weight adjustment and mode switching.
[0069] This embodiment quantifies the degree of environmental stress as the adjustment intensity of the scheduling strategy. Among them, the weight coefficients α(t), β(t), etc. increase linearly with Φ(t), which means that when the environment deteriorates, the scheduler will increase its overall sensitivity to all evaluation factors (task inherent attributes, delay urgency, system state, energy state), so that the system enters an "alert" or "defensive" state, responds more actively to various changes, and prioritizes the protection of core tasks.
[0070] As a preferred technical solution, the enhanced mapping function f' is a nonlinear monotonically increasing function containing inter-kernel coupling parameters, and the function output value increases sharply when the input value approaches 1. The expression of the enhanced mapping function f' is: f'(x, )=x n / max(1-x m +ε+ρ· (t),ε min ) Where n and m are positive integers, ε is a small positive constant used to prevent division by zero errors, and ρ is the inter-nuclear coupling coefficient (typically 0.05-0.5). The weighted average execution time margin of all hard real-time tasks for deterministic processing of core feedback. When When the value is positive (sufficient deterministic core margin), the denominator increases, and the delay penalty effect is mitigated; when When ε is negative (indicating tight margin), the denominator decreases, and the penalty effect intensifies. min The lower bound protection constant for the denominator is ε, which ensures that the denominator is always positive. min(Typical values 0.005-0.02) Ensure that in extreme cases (such as...) When x is a large negative value and x is close to 1, the denominator will not drop to zero or a negative number, thus ensuring that the output of function f' is always a finite positive value and avoiding score overflow that could cause scheduling logic disorder.
[0071] When the average execution margin of the deterministic processing core When the value is reduced, the delay penalty effect of the enhanced mapping function f' is amplified; the lower bound protection constant ε in the denominator is also enhanced. min Ensure when When the value is negative, the denominator will not become zero or negative, ensuring the numerical stability of the formula under any operating condition.
[0072] Specifically, in the above expression for the augmenting mapping function f', x is the first independent variable of the augmenting mapping function, corresponding to the master formula K. i The normalized waiting time w substituted into (t) i (t) / L i w i (t) represents the cumulative waiting time of task i at time t, L i Let x be the latency tolerance threshold for task i. Therefore, x is a dimensionless quantity and its value usually falls within the range of [0,1]. When x approaches 0, the task has just arrived and the latency pressure is small. When x approaches 1, the task is about to time out and needs to be urgently scheduled. To enhance the second independent variable of the mapping function, the corresponding variable substituted in the main formula is... That is, the weighted average execution time margin of all hard real-time tasks in the deterministic processing core feedback, the value of which is determined by... =Σ(K i0 ·η i (t)) / Σ(K i0 The calculation yields η, where η is the η of ... i (t)=(G i C i,actual (t)) / G i G represents the single-task execution time margin of task i. i The current time window width allocated to task i, C i,actual (t) represents the actual execution time of task i, K i0 The initial criticality level for task i; Both are dimensionless quantities. A value greater than zero indicates sufficient deterministic core margin. A value less than zero indicates a tight margin or even an over-limit.
[0073] This embodiment integrates the "delay penalty effect" and "inter-core state feedback," and has at least the following characteristics: 1. Non-linear delay penalty: The basic form of the enhanced mapping function f' ensures that when the task waiting time approaches the tolerance limit (x→1), the output value increases sharply, forcibly increasing the priority of the task and preventing timeout.
[0074] 2. Regulation of internuclear coupling: Introduced into the denominator The key is the item. When the deterministic core execution margin is sufficient ( When the denominator is positive, the penalty effect is moderately reduced, avoiding unnecessary emergency allocation; when the margin is tight ( When the value is negative, the denominator decreases, the penalty effect intensifies, and the scheduling of high-performance cores becomes more stringent to match the pressure state of the hardware layer. This achieves coordination between the execution states of software and hardware.
[0075] 3. Numerical stability guarantee: Lower bound protection constant ε in the denominator min Ensure the function works under all operating conditions (such as...) (For larger negative values) The denominator is not zero or negative to ensure stable operation of the algorithm.
[0076] Therefore, it can be seen that the core algorithm of the above dynamic scoring model (formula, environmental index, weight adjustment, and enhanced mapping function) provides a precise, computable algorithm system with environmental coupling perception and inter-kernel state feedback.
[0077] In some preferred embodiments, the criticality score is updated at a fixed time period or via event triggering. The default value for the fixed time period is 50 milliseconds, and the events include task state change events and system state limit exceedance events. This embodiment defines the criticality score update mechanism, balancing the timeliness of scheduling decisions with system overhead, ensuring that the scheduler can respond quickly to changes without wasting resources due to excessively frequent calculations. The "fixed period" (e.g., 50ms) update provides a basic rhythm and stability, ensuring that the state of all tasks can be evaluated periodically. "Event triggering" updates (e.g., task completion, state limit exceedance) provide immediate response capabilities, ensuring that urgent changes can be immediately detected and handled. Clearly defining the update period and triggering events makes the computational overhead of this dynamic scoring algorithm controllable and predictable, meeting the dual requirements of determinism and efficiency for embedded real-time systems.
[0078] In some preferred embodiments, the time-triggered scheduling table is generated by: obtaining the worst-case execution time and execution cycle of each hard real-time task; calculating the total utilization: U=∑(C i / T i ), where U is the total utilization rate, C i Let T be the worst-case execution time of task i. i Let U be the execution cycle of task i; verify whether the total utilization U satisfies U ≤ U bound, among which, U bound The upper bound of utilization is set as a preset limit. This embodiment defines the method for generating the time-triggered scheduling table, providing a theoretical schedulability guarantee for the time-triggered scheduling of hard real-time tasks. This ensures that, during the offline design phase, all hard real-time tasks can be accommodated and completed on time even in the worst-case scenario. Mathematical verification is performed during the design phase by analyzing the "worst-case execution time" and "cycle" of each task and verifying whether the "total utilization" is less than or equal to the "upper bound of utilization." This scheme theoretically proves that as long as the actual running time does not exceed the preset worst-case scenario, all hard real-time tasks can be completed within their allocated time windows without timeouts due to accumulated latency competing with each other. This is the gold standard and cornerstone of security in hard real-time system design.
[0079] In some preferred embodiments, the deterministic processing core and the high-performance processing core achieve runtime collaboration through a bidirectional closed-loop feedback mechanism between cores: at the end of each time window, the deterministic processing core calculates the execution time margin of the current hard real-time task. The execution telemetry region of the shared memory is written; the high-performance processing core reads the execution time margin rate and averages it. As an inter-core coupling parameter, it is fed back to the enhanced mapping function f' of the criticality score. At the same time, the protection margin adjustment of each hard real-time task is calculated according to the environmental stress coupling index Φ(t) and passed to the deterministic processing core through the scheduling parameter area of the shared memory.
[0080] As a preferred technical solution, the deterministic processing core calculates the execution time margin rate of the current hard real-time task at the end of each time window. The calculation formula is as follows: η i (t)=(G i -C i,actual (t)) / G i Among them, G i The current time window width allocated to task i, C i,actual (t) represents the actual execution time, and η is... i (t) Write to the execution telemetry region of the shared memory; The high-performance processing core periodically reads the execution telemetry region and calculates the weighted average execution time margin. (t)=Σ(K i0 ·η i (t)) / Σ(K i0 ), and will Substitute it into the enhanced mapping function f' to participate in the criticality score calculation.
[0081] This embodiment defines reverse feedback (margin ratio acquisition and calculation), the technical effect of which is to quantify the real-time status of the hardware execution layer (the ratio of the actual execution time of each hard real-time task to the time window) and feed it back to the software scheduling layer. Through the "execution telemetry region" of shared memory and periodic read calculations, the high-performance processing core can obtain a comprehensive indicator reflecting the overall deterministic core load and health status. (t) is used as a key parameter input to the scheduling algorithm (i.e., the enhanced mapping function f'), thereby realizing the perception of the actual hardware performance by the scheduling decision.
[0082] As a preferred technical solution, the high-performance processing core also calculates the protection margin adjustment amount ΔG for each hard real-time task based on the environmental stress coupling index Φ(t). i (t), and transmits the protection margin adjustment amount to the deterministic processing core through the scheduling parameter area of the shared memory. The deterministic processing core adjusts the time window width of the corresponding task in the time trigger scheduling table according to the protection margin adjustment amount at the next main cycle boundary.
[0083] This embodiment defines a forward feedback (protection margin adjustment) mechanism. Its technical effect is to feed forward the software scheduling layer's ability to perceive environmental threats to the hardware execution layer's time resource allocation. The high-performance processing core calculates the required "protection margin adjustment" for each hard real-time task based on the environmental stress coupling index Φ(t), and transmits it to the deterministic processing core through the "scheduling parameter region," enabling it to dynamically adjust the width of the time window in the next cycle. For example, when the environment deteriorates and the processor may reduce its frequency, the time window is extended for highly critical tasks, reserving more execution time and thus preventing timeout risks due to performance degradation. This constitutes a feedforward protection path from environmental perception to hardware resource pre-configuration.
[0084] This embodiment constructs a runtime, bidirectional, closed-loop collaborative adaptive mechanism between the deterministic processing core and the high-performance processing core through reverse feedback (margin rate acquisition and calculation) and forward feedback (protection margin adjustment), generating a synergistic effect of "1+1>2".
[0085] It should be noted that existing multi-core heterogeneous controllers lack a runtime bidirectional feedback mechanism between the deterministic core and the high-performance core. The actual execution status of the deterministic core (such as whether each task completes ahead of schedule and the utilization rate of the time window) is not fed back to the scheduling decision of the high-performance core, making the scheduling strategy of the high-performance core "invisible" to the actual hardware operating status. At the same time, the scheduling adjustments made by the high-performance core according to environmental changes cannot be fed forward to the deterministic core to adjust the time window configuration in advance. This "information silo" relationship between cores makes it impossible for the system to achieve collaborative adaptation between the hardware execution layer and the software scheduling layer, making it difficult to make a globally optimal response when the environment changes drastically. To overcome the shortcomings of existing solutions, this application adds the aforementioned reverse feedback (margin rate acquisition and calculation) and forward feedback (protection margin adjustment), thereby constructing a runtime bidirectional closed-loop feedback mechanism between the deterministic core and the high-performance core.
[0086] As a preferred technical solution, the overload protection operation includes at least one of the following operations: reducing the execution frequency of tasks with a criticality score below a first threshold; suspending tasks with a criticality score below a second threshold; controlling the multi-core heterogeneous controller to enter an emergency mode, in which only tasks with a criticality score above a third threshold are scheduled for execution.
[0087] This embodiment details the specific measures for overload protection, providing a tiered, progressive resource contraction strategy based on criticality scoring. This allows the system to "gracefully degrade" under overload conditions, prioritizing the protection of the most critical functions and preventing system crashes. The measures, from least to most severe, are "reducing frequency," "suspending tasks," and "entering emergency mode." This forms a gradually tightening resource loop, first attempting to reduce the service quality of secondary tasks, temporarily suspending them if ineffective, and finally retaining only core functions in extreme cases. This strategy maximizes the continuity of system functionality. All measures are based on "criticality scoring," ensuring that the least important tasks are sacrificed during resource contraction, thus optimizing the allocation of limited resources and protecting the system's core missions even under overload conditions.
[0088] As a preferred technical solution, the method further includes: adaptively switching between multiple preset operating modes based on a comprehensive evaluation value M(t) for mode switching, wherein the operating modes include at least a normal mode, a high-load mode, and an emergency mode; and M(t) is calculated using the following formula: M(t) = ω1·Φ(t) + ω2·L hp (t)+ω3·(dΦ / dt) + Where Φ(t) is the environmental stress coupling index, L hp(t) represents the normalized load rate of the high-performance processing core, (dΦ / dt) + ω1, ω2, and ω3 are the positive values of the rate of change of the environmental stress coupling index, and ω1, ω2, and ω3 are the mode switching weight coefficients. The adaptive switching includes hysteresis constraints: the threshold for uplink switching is higher than the threshold for downlink switching, and the dwell time of any mode is not lower than the preset minimum dwell time.
[0089] In this embodiment, (dΦ / dt) is introduced. + The system achieves predictive pre-switching: even if the current Φ(t) has not yet reached the switching threshold, if it is increasing rapidly, the system can enter the defensive mode in advance.
[0090] This embodiment defines the comprehensive evaluation of mode switching and hysteresis constraints. The comprehensive evaluation value of mode switching M(t) integrates the current environmental stress Φ(t) and the system load L. hp (t) and environmental degradation trend (dΦ / dt) + These three dimensions enable the switching decision to combine current situational awareness and trend prediction capabilities, allowing for early entry into a defensive state. The design of hysteresis constraints (uplink threshold being higher than downlink threshold) and minimum dwell time effectively prevents repeated mode switching (oscillation) caused by minor parameter fluctuations near the switching threshold, ensuring the stability of system operation.
[0091] As a preferred technical solution, when the deterministic processing core reports that any hard real-time task has timed out consecutively a preset fault threshold N, fault At that time, regardless of the value of M(t), immediately switch to emergency mode.
[0092] This embodiment defines a hard fault pass-through rule, which is a key safety fallback mechanism. Its technical effect is that when an actual failure occurs in the hardware execution layer (continuous timeout of hard real-time tasks), the system can bypass the complex evaluation process based on M(t) and directly force entry into the highest protection level (emergency mode), ensuring the fastest and most decisive response to hardware-level failures, which is the ultimate guarantee of system security.
[0093] As can be seen, this application upgrades adaptive mode switching from simple threshold judgment to a predictive state machine based on a comprehensive evaluation value M(t). M(t) integrates the current environmental stress value Φ(t) and the system load L. hp (t) and environmental degradation trend (dΦ / dt) +The three dimensions of information enable switching decisions to incorporate both current situational awareness and trend prediction capabilities. The hysteresis interval design (uplink threshold higher than downlink threshold) prevents mode oscillations caused by repeated switching near the threshold. Minimum dwell time constraints ensure the system runs for at least sufficient time in each mode to complete policy adjustments. Hard fault pass-through rules ensure that when an actual hardware failure occurs, the system can bypass M(t) evaluation and directly enter the highest protection state.
[0094] Through the above-mentioned comprehensive evaluation of mode switching, hysteresis constraints, and hard fault pass-through rules, the system can proactively, smoothly, and oscillatingly switch between global operating strategies based on environmental stress, system load, and environmental deterioration trends, achieving macro-level self-adaptation.
[0095] In some preferred embodiments, when executing the hard real-time task on the deterministic processing core, a time isolation mechanism is employed: if the current task completes before the end of the allocated time window, the deterministic processing core remains idle until the start of the next time window; if the current task times out, the task is interrupted and the system switches to the task corresponding to the next time window. This embodiment defines a time isolation mechanism, strictly maintaining the boundaries and order of the hard real-time task time windows, ensuring that the determinism of the time-triggered scheduling table is not compromised, and providing a standard for fault-tolerant processing. The rule of "idle waiting if completed early" prevents task execution "pre-flow," where one task occupies the time window of the next task, thus ensuring the strict periodicity and predictability of the execution sequence of all hard real-time tasks—a core principle of time-triggered scheduling. The rule of "forced switch and recording exceptions if timeout" prevents the entire deterministic core scheduling from paralyzing due to a single task failure (such as an infinite loop); it achieves time isolation of faults, ensuring that an exception in one task will not indefinitely block all subsequent tasks, and by recording exceptions, it provides diagnostic information for remote operation and maintenance, improving the system's fault tolerance and maintainability.
[0096] Therefore, the technical solution of this application addresses the harsh conditions faced by industrial control systems in desert environments, such as high temperatures, extreme cold, strong sandstorms, high ultraviolet radiation, and long-term unattended operation. By intelligently scheduling real-time tasks with different levels of criticality on a multi-core heterogeneous processing platform, it achieves deterministic execution of critical control tasks and efficient utilization of system resources. This application belongs to the interdisciplinary field of industrial automation control and real-time computer technology and can be widely applied to scenarios such as desert water resource regulation, unattended site equipment management, desert photovoltaic power station monitoring, and wind farm operation and maintenance.
[0097] To make the above-mentioned multi-core heterogeneous controller and real-time task scheduling method for the desert environment clearer, the following will provide further explanation in conjunction with the above-mentioned preferred technical solutions.
[0098] This application provides a multi-core heterogeneous controller architecture and a real-time task dynamic scheduling algorithm suitable for the extreme environment of the Gobi Desert. Through the synergistic effect of this architecture and algorithm, while strictly ensuring the hard real-time requirements of critical tasks, it can significantly improve the system's processing efficiency for non-critical tasks and the overall resource utilization rate, and realize the dynamic evaluation of the criticality of tasks and the adaptive adjustment of scheduling strategies, thereby ensuring the long-term reliable operation of the entire control system in harsh, unattended environments.
[0099] This application provides a multi-core heterogeneous controller architecture suitable for desert environments. The core design concept of this architecture is to match the most suitable processing core to the characteristics of different tasks, thereby optimizing and isolating task execution at the hardware level. The architecture includes various types of processing cores, specifically including deterministic processing cores dedicated to hard real-time tasks, high-performance processing cores for soft real-time or general-purpose computing tasks, and optional artificial intelligence acceleration processing cores.
[0100] The deterministic processing core is implemented using a highly reliable, low-power control processor, such as an ARM Cortex-R series real-time processor or a dedicated digital signal processor. It runs a streamlined real-time kernel or bare-metal control loop, exhibiting deterministic interrupt response latency and extremely low task switching overhead, specifically designed for executing control tasks with extremely high time determinism requirements. The high-performance processing core is implemented using a general-purpose RISC processor, such as an ARM Cortex-A series or RISC-V architecture processor, running a complete embedded operating system and responsible for executing computationally intensive tasks such as communication protocol stacks, data processing, and human-computer interaction. The artificial intelligence acceleration core can be implemented using a neural network processor, graphics processing unit (GPU), or field-programmable gate array (FPGA) to execute complex algorithms such as deep learning inference and pattern recognition.
[0101] The various processing cores are interconnected via a high-speed on-chip bus or on-chip network, sharing main memory and peripheral interfaces to form a fully functional heterogeneous multi-core controller hardware platform. To ensure the real-time performance of the deterministic processing cores, the architecture design allocates dedicated high-speed caches and dedicated memory areas for them, and employs storage protection mechanisms to avoid resource contention with other cores. Specifically, a dedicated data storage area is designated as a restricted access area based on data confidentiality levels, and access priority authorization and intelligent dynamic arbitration algorithms are designed for priority ranking. Furthermore, the architecture provides rich input / output interfaces, including analog-to-digital conversion interfaces, digital output interfaces, and various communication interfaces to connect to various sensors and actuators in the desert environment.
[0102] This application also proposes a real-time task scheduling method, including: A time-triggered scheduling strategy is adopted for hard real-time tasks. A fixed time window is pre-allocated to each hard real-time task on the deterministic processing core, and the tasks are executed periodically according to the predetermined time-triggered scheduling table. A priority preemption strategy is used to schedule soft real-time tasks. On the high-performance processing core, the real-time operating system performs preemptive scheduling based on the dynamic priority of the tasks. The dynamic priority is determined based on a task criticality score, which is calculated through the following steps: obtaining static task attributes, including initial criticality level, execution cycle, deadline, and latency tolerance; collecting system dynamic status, including processor load rate, task queue depth, power status, and environmental monitoring results; tracking task dynamic information, including waiting time and cumulative latency since the last execution; and calculating the criticality score of each task using a predefined evaluation algorithm based on the task static attributes, system dynamic status, and task dynamic information, with higher scores indicating higher priority. When the temperature rises, the system automatically reduces the frequency, intelligently sorts tasks and adjusts power to achieve a balance between heat generation caused by important tasks and heat generation caused by short-term task execution, while ensuring the operation of important tasks.
[0103] When the system load approaches its processing capacity limit, an overload protection mechanism is activated, which includes reducing the execution frequency of low-critical tasks, temporarily suspending unnecessary tasks, or entering emergency mode to keep only high-critical tasks running.
[0104] The overload protection mechanism is based on a weighted judgment of CPU utilization and core temperature, with a preset normal operating frequency of 100 points. When the score exceeds 70 points, the overload protection mechanism is executed. The task suspension and degradation mechanism is based on a weighted score of user-set task priority, current task criticality, and allowable delay time, etc., to determine the order.
[0105] The evaluation algorithm uses a weighted summation method, and the formula for calculating the criticality score is as follows: K i (t)=α(t)·K i0 +β(t)·f'(w i (t) / L i , (t))+γ(t)·g(S(t))+δ(t)·h(E(t)) Among them, K i (t) represents the criticality score of task i at time t, K i0 For the initial critical level, w i (t) represents the waiting time, L iLet S(t) be the delay tolerance threshold, S(t) be the state vector representing the system load, E(t) be the state variable representing the energy state, α(t), β(t), γ(t), and δ(t) be weighting coefficients dynamically adjusted according to the environmental stress coupling exponent Φ(t), and f' be the enhancement mapping function containing inter-core coupling parameters. (t) represents the average execution time margin of the deterministic processing core feedback, and g and h represent the preset mapping functions.
[0106] The calculation of task criticality score is performed at a fixed period or by event triggering. The default value of the fixed period is 50 milliseconds. The events include task completion events, task ready events, and system state change events.
[0107] The construction of the time-triggered scheduling table includes: analyzing the worst-case execution time and execution cycle of each hard real-time task, and verifying that the total utilization U satisfies the schedulability condition: U = ∑(C i / T i )≤U bound C i Let T be the worst-case execution time of task i. i For the execution cycle of task i, U bound This represents the upper bound of utilization.
[0108] In some preferred embodiments, the formula and parameters for calculating M(t) are: ω1=0.4, ω2=0.35, ω3=0.25. (dΦ / dt) + Δt = 1s is calculated using the difference method.
[0109] Switching threshold: M up1 =0.55, M down1 =0.40 (hysteresis 0.15); M up2 =0.80, M down2 =0.65 (hysteresis 0.15). T dwell1 =5s, T dwell2 =3s,T recover1 =60s, T recover2 =30s. N fault =3 (Hard fault pass-through).
[0110] Normal mode: All tasks are scheduled normally according to the score. Sensitivity coefficient σ α σ β σ γ σ δ Use the baseline value.
[0111] High Load Mode: Rating <Th reduce (30 points) Task frequency reduced by 1 / 2; Score <Th suspend(15 points) suspended. The overall sensitivity coefficient is reduced to 70% of the baseline value (i.e., σ). α,H =0.7·σ α (etc.), because the mode switch has completed macro-level resource contraction, and the weighted paths no longer need to be superimposed at full intensity, thus avoiding compression of the scoring differentiation of the remaining active tasks. σ δ (Energy sensitivity) unusually increases to 1.5 times the baseline value instead of decreasing. This is because high-load modes are typically triggered by energy shortages (dust storms shading solar panels and causing a decrease in E(t) is one of the most common triggering paths). In this case, the influence of the energy factor h(E(t)) on scheduling decisions needs to be strengthened rather than weakened. If energy sensitivity is reduced during energy shortages, the system will be unable to adjust task priorities sufficiently according to energy changes, potentially leading to low-critical tasks consuming too much remaining power and jeopardizing the power supply for high-critical tasks. Therefore, σ δ The adjustment direction is opposite to that of the other sensitivity coefficients, forming a differentiated coordination strategy of "overall convergence and energy enhancement".
[0112] Emergency Mode: Rating Only > Th emergency (60 points) Task execution. The overall sensitivity coefficient was reduced to 40% of the baseline value (i.e., σ). α,E =0.4·σ α (etc.), κ increases to 2 times. At this point, mode switching has placed the system in the highest protection state, and the main role of the weighted path changes from "driving resource contraction" to "maintaining the fine priority ranking among the remaining tasks", thus reducing the sensitivity coefficient to maintain the stability and discriminativeness of the score.
[0113] The task execution on the deterministic processing core adopts a time isolation mechanism. When a task is completed ahead of schedule, the core enters an idle waiting state until the next time window begins. When a task times out abnormally, it is forcibly switched to the next task and the abnormal event is recorded.
[0114] When the system detects multiple consecutive timeouts of a hard real-time task, or when a new task is added via remote command, the system can enter a protected "reconfiguration mode." In this mode, the feasibility of recalculating the scheduling table by the high-performance core is verified (total utilization U≤U). bound After a main cycle ends, it atomically switches to a new scheduler to ensure that the continuity of deterministic core operation is not affected.
[0115] The hardware architecture design, task classification and criticality definition, and hybrid scheduling algorithm process of this application will be further explained below.
[0116] Hardware architecture design Reference Figure 1As shown, the hardware of the industrial controller in this application adopts a multi-core heterogeneous architecture, including the following core modules.
[0117] The high-performance processing core is implemented using an ARM Cortex-A72 or RISC-V RV64GC architecture processor, with a clock speed exceeding 1.5GHz. It is equipped with a 32KB L1 instruction cache, a 32KB L1 data cache, and a 512KB L2 cache. This core runs an embedded Linux operating system or a real-time operating system, responsible for executing most soft real-time tasks and general tasks, including TCP / IP protocol stack processing, data compression and decompression, log management, and the human-computer interaction interface. The high-performance processing core boasts strong computing performance and rich peripheral support capabilities, enabling it to handle complex calculations and multi-task concurrent scheduling.
[0118] The deterministic processing core is implemented using an ARM Cortex-R5 or TI C28xx series digital signal processor, equipped with tightly coupled memory and a dedicated interrupt controller. This core runs a streamlined real-time kernel or bare-metal control loop, specifically designed for performing hard real-time tasks such as closed-loop control algorithm calculations, emergency safety monitoring, and protection interlocking logic. The deterministic processing core features deterministic interrupt response latency (less than 1 microsecond) and extremely low task switching overhead (less than 100 clock cycles), and interfaces with sensors and actuators via direct memory access channels.
[0119] The AI acceleration core is an optional configuration and can be implemented using a neural network processing unit, a graphics processing unit, or a field-programmable gate array (FPGA). This core is controlled by a high-performance processing core via a dedicated driver interface and is used to handle computationally intensive tasks such as deep learning inference, image recognition, and time-series prediction. AI tasks are typically not strictly real-time and can be executed asynchronously in the background, with their computation results passed to other cores via a shared memory region.
[0120] The high-performance core sends inference requests to the AI core (i.e., the artificial intelligence acceleration core) via a message queue and sets a timeout. After the AI core completes the calculation, it notifies the high-performance core via an interrupt. The shared memory area adopts a double buffering mechanism to ensure the atomicity of data reading and writing. If the AI task times out, the scheduler can discard the current result and use the previous valid result or the default value.
[0121] The shared memory is implemented using 4th generation synchronous dynamic random access memory with double data rate, and has a capacity of 1GB to 4GB. It is connected to each processing core through a multi-port memory controller. To ensure the real-time performance of the deterministic processing cores, the memory controller allocates independent access channels and the highest access priority to them, and uses memory protection units to divide the dedicated memory area for each core.
[0122] The shared memory is divided into two dedicated regions: Execute telemetry region (deterministic core write / high-performance core read): 24 bytes per record (task ID 4B+G) i 4B+C i,actual 4B+η i (4 bytes + 8 bytes for timestamp). N ≤ 16 tasks, total ≤ 384 bytes.
[0123] Scheduling parameter area (high-performance core write / deterministic core read): 12 bytes per entry (task ID + ΔG) i (t) + effective period number). Double buffering mechanism ensures data consistency.
[0124] Reverse channel: η is calculated at the end of each window in the deterministic core. i (t)=(G i C i,actual (t)) / G i Write to the back buffer. The high-performance core reads and calculates the weighted average every 50ms: (t)=Σ(K i0 ·η i (t)) / Σ(K i0 ) Forward path: Calculate ΔG per main cycle (100ms) for high-performance cores. i (t). For K i Task 0=5: ΔG i (t)=round(G i,base ·κ·Φ(t)), κ typically ranges from 0.1 to 0.3. For K i0 Tasks <5: ΔG i (t)= round(G i,base ·κ′·Φ(t) / K i0 Total utilization rate U′=Σ((C) i +ΔG i ) / T i )≤U bound constraint.
[0125] It should be noted that the protection margin adjustment amount ΔG i (t) takes effect only at the next master cycle boundary of the deterministic core, with a response latency of at most one master cycle (typically 100 milliseconds). This latency will not cause hard real-time tasks to time out for the following reasons: During the offline design phase, the baseline time window width G for each hard real-time task is... i,baseThe execution time has been allocated according to the worst-case scenario at the processor's lowest allowed operating frequency, with a safety margin. Therefore, even without ΔG extension, the task can still be completed within the baseline window under downclocking conditions. ΔG i The role of (t) is to provide additional protection margin beyond the baseline safety margin; it is more of a "nice-to-have" than a "lifeline." Furthermore, when the rate of change (dΦ / dt) of the environmental stress coupling index Φ(t)... + Exceeding the emergency threshold Th ΔG,urgent At this time, the high-performance processing core immediately notifies the deterministic processing core of the protection margin adjustment amount through inter-core interrupt, bypassing the main cycle boundary waiting, reducing the response latency from 100 milliseconds to the interrupt response latency level (microseconds), and realizing rapid feedforward protection against sudden environmental deterioration.
[0126] Enhanced mapping function effect: in f'(x, )=x n / max(1 x m +ε+ρ· (t),ε min In this context, ρ typically ranges from 0.05 to 0.5, and ε... min Typical value: 0.01. When the value is positive, the denominator increases and the penalty decreases (e.g., ρ=0.2). When the denominator is 0.5, the denominator increases by 0.1. When the value is negative, the denominator decreases and the penalty increases.
[0127] Meanwhile, the architecture includes non-volatile memory (such as NOR flash and eMMC) for persistent storage of program code and configuration data.
[0128] The input / output interface (i.e., the aforementioned input / output interface module) includes multiple analog-to-digital conversion channels (16-bit precision, sampling rate up to 1MSPS), digital input / output ports, pulse width modulation output, quadrature encoder input, industrial Ethernet interface (supporting EtherCAT and PROFINET protocols), RS-485 / RS-232 serial communication interface, controller area network bus interface, and wireless communication module interface. The deterministic processing core prioritizes direct control of key sensors and actuators to reduce intermediate layer processing latency; the high-performance processing core handles non-time-sensitive data exchange and remote communication tasks.
[0129] Task classification and criticality definition In the system of this application, tasks are divided into two main categories: hard real-time tasks and soft real-time tasks, based on the strictness of the task's response time.
[0130] Hard real-time tasks refer to those tasks that must be completed within a strict timeframe, with any delay resulting in unacceptable consequences for the system. These tasks are typically directly related to system security and the normal operation of core functions. Taking the Shagohuang unmanned water resource dispatch station as an example, hard real-time tasks include opening or closing gates on schedule to prevent reservoir overflow, cutting off power based on emergency sensor signals to prevent accidents, self-checking equipment malfunctions and implementing protective interlocks, and over-limit protection for pressure vessels. For hard real-time tasks, this application assigns fixed operating cycles and timings to them on a deterministic processing core to ensure that their worst-case response time does not exceed the set value.
[0131] Soft real-time tasks refer to tasks with certain completion time requirements but allowing for moderate delays, which may only lead to performance degradation rather than catastrophic consequences. Soft real-time tasks include periodic reporting of environmental data, processing and storage of surveillance videos, execution of artificial intelligence prediction algorithms, organization and uploading of runtime logs, and remote configuration updates. These tasks can be slightly delayed or have their execution frequency reduced during peak load periods. Soft real-time tasks are primarily scheduled and executed by high-performance processing cores.
[0132] Each task is assigned an initial criticality level during the system configuration phase, using a five-level classification from 1 to 5, with 5 being the highest criticality level. A latency tolerance parameter is also defined for each task, representing the maximum tolerable latency relative to its ideal scheduling time. For example, if an environmental data reporting task is set to execute every 10 seconds, and its latency tolerance is 5 seconds, it means that completing the task within a maximum interval of 15 seconds will not affect system functionality.
[0133] In a further embodiment of this application, an environmental stress coupling sensing mechanism is proposed. In the industrial control scenario of desert areas, the environmental threats faced by the system have significant multi-factor coupling characteristics. During sandstorms, three types of factors deteriorate simultaneously: increased temperature stress (deteriorating heat dissipation leads to processor frequency reduction); reduced energy availability (photovoltaic power generation drops sharply to 10%-30% due to shading); and enhanced sandstorm interference (decreased sensor accuracy and communication attenuation). The combined effect of these three factors is amplified superlinearly.
[0134] To quantify the coupling effect, the environmental stress coupling exponent Φ(t) is defined: Φ(t)=max(Φ coupling (t),Φ floor (t)) Among them, the coupling term: Φ coupling (t)=[ (t)] a ×[1 Ê(t)] b ×[1+λ· (t)] c Cusp item: Φ floor (t)=max(μ T · (t),μ E ·(1 Ê(t)),μ D · (t)) Normalized temperature stress (t)=(T(t) T low ) / (T high T low T(t) represents the ambient temperature (°C). low Typical value 40℃, T high Typical value +85℃. When T(t) ≤ T low When T(t) ≥ T, the value is 0; when T(t) ≥ T high Take 1 at the time.
[0135] Normalized energy availability Ê(t) = E avail (t) / E rated E avail (t) represents the sum of the remaining battery capacity and the expected photovoltaic output (Wh). rated This is the rated energy. When Ê(t) ≥ 1, it is taken as 1, at which point [1] Ê(t)] b =0.
[0136] Normalized Dust Disturbance Index (t)=min(C PM10 (t) / C ref ,1), C ref Typical value: 1000 μg / m³.
[0137] The coupling index is determined based on the following criteria: a) typical value of 1.5-2.5 (reflecting the exponential impact of high temperature on processor leakage power consumption); b) typical value of 1.5-3.0 (reflecting the sharp drop in power caused by increased battery internal resistance at low battery levels); c) typical value of 1.0-2.0; λ value of 0.5-3.0.
[0138] Cusp contribution coefficient μ T μ E μ D The value of μ is determined by: T Typical values are 0.3-0.5, reflecting the impact of high temperature alone on processor throttling; μ E Typical values are 0.4-0.6, reflecting the threat posed by insufficient energy sources alone to the sustainable operation of the system; μ D Typical values are 0.2-0.4, reflecting the interference of individual dust particles on sensor accuracy. In the scenario of a water resource control station, μ is used.T =0.4, μ E =0.5, μ D =0.3.
[0139] The technical significance of introducing the catch-all term lies in the fact that the product-form coupling term Φ coupling (t) can capture the superlinear amplification effect when multiple factors deteriorate simultaneously, but when a certain factor is within the normal range (e.g., when energy is sufficient to make [1-Ê(t)]... b When ≈0), the product will approach zero, making it imperceptible even if the other factors deteriorate significantly. (Catch-all term Φ) floor (t) By taking the maximum value of the independent contribution of each single factor, it ensures that severe deterioration of any single factor can be detected. The design of taking the maximum value of both ensures that Φ(t) is dominated by the coupling term in multi-factor coupled scenarios (because the product amplification effect is usually greater than the linear value of a single factor), and is covered by the fallback term in single-factor extreme scenarios, eliminating the blind spot of the product returning to zero.
[0140] Specific implementation example (water resource regulation station) parameters: a=2.0, b=2.0, c=1.5, λ=1.5, T low = 40℃, T high =+85℃, C ref =1000μg / m³, prediction window 30min.
[0141] Hybrid scheduling algorithm process like Figure 3 As shown, the scheduling algorithm of this application (i.e., the real-time task scheduling method for the desert environment) combines time-triggered and priority-preemptive mechanisms, and its execution process is divided into the following stages.
[0142] During system initialization, the deterministic processing core loads a pre-designed time-triggered scheduler. This scheduler is generated based on the cycle time and worst-case execution time of all hard real-time tasks, listing the execution sequence of each task within a main cycle. The main cycle length is typically taken as the least common multiple of the cycles of all tasks or set to a fixed value (e.g., 100 milliseconds). The scheduler ensures that all critical tasks are scheduled at least once within each main cycle, and the execution time windows of each task do not overlap.
[0143] During the periodic execution phase, the deterministic processing core operates strictly according to the time-triggered schedule. When the timer reaches the execution time of a task, the core immediately begins executing the task until it is completed or the time window boundary is reached. If a task completes ahead of schedule, the core enters an idle waiting state until the next time window begins. If a task times out abnormally, the core records the exception event and forcibly switches to the next task to avoid chained delays.
[0144] Meanwhile, the high-performance processing core runs the task scheduler of the real-time operating system. The scheduler periodically calls the criticality assessment model to update the criticality scores of all soft real-time tasks. During score updates, the scheduler first collects environmental temperature, energy, and dust data to calculate the environmental stress coupling index Φ(t), and dynamically adjusts the weighting coefficients α(t), β(t), γ(t), and δ(t) accordingly. Then, it reads the average margin rate from the deterministic core feedback. Substituting (t) into the enhancement mapping function f', the criticality score K~i~(t) of each task is finally calculated and converted into task priority. The scheduler always selects the highest priority task among the currently ready tasks for execution. When a new task becomes ready or the criticality of a task changes significantly, causing its priority to exceed that of the currently running task, a preemptive task switch occurs.
[0145] During the load management phase, if the system detects that the total load on the high-performance processing cores is approaching its processing capacity limit, the scheduler will activate the overload protection mechanism. First, it reduces the execution frequency of low-criticality tasks, for example, by doubling the execution interval of some periodic tasks; if the load is still too high, it temporarily suspends several tasks with the lowest criticality; in extreme cases, the system enters emergency mode, keeping only tasks with a criticality score exceeding a preset threshold running.
[0146] The working process of this application will be explained below through specific application scenarios.
[0147] Environmental conditions: Summer high of 55℃, winter low of At 35℃, sandstorms occur 3-5 times per month on average, with PM10 levels reaching over 2000 μg / m³. The system includes a 500W photovoltaic power unit and a 5kWh battery.
[0148] Hard real-time task: A water level gate control (100ms / 35ms / K) A0 =5), B pipe pressure (50ms / 15ms / K) B0 =5), Device C self-test (1000ms / 200ms / K) C0 =4). Soft real-time task: D status message (5s / K) D0 =3 / L D =10s), E runtime log (10s / K) E0 =2 / L E =30s), FAI prediction (60s / K) F0 =2 / L F =120s), G image analysis (300s / K) G0 =1 / L G =600s).
[0149] Parameters: a=2.0, b=2.0, c=1.5, λ=1.5, ρ=0.2, κ=0.2, κ′=0.15.
[0150] Normal operation: air temperature 35℃, photovoltaic power 400W, no sand and dust. =0.60, Ê≈1.0, ≈0. Φ coupling (t)=0.60 2 ×0×1=0;Φ floor (t)=max(0.4×0.60,0.5×0,0.3×0)=0.24; Φ(t)=max(0,0.24)=0.24. Although the system has sufficient energy and no dust, it still maintains a basic awareness of temperature stress. ≈0.55, M(t)=0.14, which is far below the threshold.
[0151] Dust storm hits: PM10 rises to 800 μg / m³ =0.8), photovoltaic power drops to 100W, Ê drops to 0.7, and chassis temperature reaches 50℃. Φ coupling (t)=0.72 2 ×(1 0.7) 2 ×(1+1.2) 1.5 =0.518×0.09×3.26≈0.152; Φ floor (t)=max(0.4×0.72,0.5×0.3,0.3×0.8)=max(0.288,0.15,0.24)=0.288; Φ(t)=max(0.152,0.288)=0.288 (At this stage, the catch-all term dominates, and the temperature stress alone has become a significant stress).
[0152] The condition continued to worsen after 15 minutes (Ê=0.4, =0.80, =1.0): Φ coupling (t)=0.80 2 ×0.6 2 ×(1+1.5) 1.5 =0.64×0.36×3.95≈0.910; Φ floor (t)=max(0.4×0.80,0.5×0.6,0.3×1.0)=max(0.32,0.30,0.30)=0.32; Φ(t)=max(0.910,0.32)=0.910 (The coupling term dominates in this stage, reflecting multi-factor superlinear amplification).
[0153] Inter-core coupling: Processor downclocking caused the execution time of task A to swell from 35ms to 42ms, ηA =0.16, It decreases from 0.55 to 0.25. In the denominator of f', ρ· The penalty is increased by 15% as it decreases from 0.11 to 0.05. The positive pass increases the margin ΔG for task A. A =round(50×0.2×0.910)=9ms, the window expands from 50 to 59ms. Task C compresses ΔG. C = 7ms.
[0154] Mode switching: M(t) = 0.647 > M up1 =0.55 for 5 seconds → High load mode. Task G is suspended, and F frequency is reduced. The situation continues to worsen until M(t) = 0.85 > M. up2 →Emergency Mode. Only Task D executes.
[0155] A 50MW photovoltaic power plant with 20 distributed controller nodes. Differentiated configuration: λ=2.5 (dust has a more direct impact on photovoltaic panels), a=2.5, b=1.5, c=2.0. Hard real-time task: MPPT tracking (20ms / 8ms / K). i0 =5), overvoltage protection (10ms / 3ms / K) i0 =5), grid synchronization (50ms / 18ms / K) i0 =5).
[0156] The special effect of inter-core coupling: MPPT execution time increases from 5ms to 7-8ms due to light fluctuations, while η decreases from 0.375 to 0.0. Deterministic cores transmit data via a reverse channel to high-performance cores, which automatically enhance power prediction task priority and reduce cleanliness AI assessment priority.
[0157] Phase 1 (T=0~10min, normal mode): Warning signal arrives. =0.2, ≈0.60, Ê≈1.0. Φ coupling (t)≈0 (because Ê≈1.0); Φ floor (t) = max(0.4×0.60, 0.5×0, 0.3×0.2) = 0.24; Φ(t) = 0.24. M(t) = 0.4×0.24 + 0.35×0.40 + 0.25×0.005 ≈ 0.096 + 0.14 + 0.001 = 0.24, which is still lower than M. up1 =0.55. (dΦ / dt) + It begins to contribute to trend prediction at approximately 0.005 / s.
[0158] Phase 2 (T=10~25min, triggered by high load mode): PM10=1500μg / m³ =1.0), photovoltaic 50W, Ê=0.35, =0.78. Φ coupling (t)=0.78 2 ×0.65 2 ×2.5 1.5 =0.608×0.423×3.95≈1.015; Φ floor M(t) = max(0.4×0.78, 0.5×0.65, 0.3×1.0) = max(0.312, 0.325, 0.30) = 0.325; Φ(t) = max(1.015, 0.325) = 1.015 (coupling term dominant). M(t) > 0.55 for 5 seconds → switch to high load mode. Reduced to 0.18, positive channel expansion margin +12ms. G / F suspended, E downclocked.
[0159] Phase 3 (T=25min~3h, Emergency Mode): Φ>1.5, M>0.80. Only Task D is executed (score 85+). κ increased to 0.4, protection margin +24ms. =0.08, ρ· =0.016, the penalty is close to the maximum.
[0160] Phase 4 (T=3~5h, Emergency → High Load Recovery): PM10 drops to 600 ( =0.6), photovoltaic 200W, Ê=0.55, ≈0.68. Φ coupling (t)=0.68 2 ×0.45 2 ×(1+0.9) 1.5 =0.462×0.203×2.63≈0.247; Φ floor (t)=max(0.4×0.68,0.5×0.45,0.3×0.6)=max(0.272,0.225,0.18)=0.272; Φ(t)=max(0.247,0.272)=0.272. M(t)=0.4×0.272+0.35×0.50+0.25×0=0.109+0.175=0.284 <M down2 =0.65, lasting 30 seconds without timeout → rollback to high load mode. The frequency increased by 0.32, E returned to normal frequency, and F resumed frequency reduction.
[0161] Phase 5 (T=5~8h+, High Load → Normal Recovery): The environment has basically recovered. ≈0.60, Ê rose back to 0.9, It dropped to 0.1. Φ coupling (t)≈0.60 2 ×0.1 2 ×(1+0.15) 1.5 ≈0.36×0.01×1.23≈0.004; Φ floor (t) = max(0.4×0.60, 0.5×0.1, 0.3×0.1) = max(0.24, 0.05, 0.03) = 0.24; Φ(t) = 0.24 (the catch-all term dominates, reverting to the normal baseline level). M(t) = 0.4×0.24 + 0.35×0.35 + 0 = 0.096 + 0.123 = 0.22 <M down1 =0.40, lasting 60s → revert to normal mode. All tasks resume. The entire process was smooth and oscillating. It is worth noting that during normal operation and recovery phases, although sufficient energy leads to the coupling term Φ... coupling (t) is close to zero, but the catch-all term Φ floor (t) consistently maintains a baseline value of approximately 0.24 (due to temperature stress). =0.60 contribution), enabling the system to maintain basic temperature sensing capabilities and preventing complete blindness to other factors due to the normality of a single factor.
[0162] Key observation: Throughout the 8-hour process, hard real-time tasks A and B consistently executed on time, never missing their deadlines. The extended protection margin of the forward channel ensured sufficient execution time even with frequency reduction; the reverse channel's... Information enables high-performance cores to accurately sense hardware stress, avoiding "blind optimism" or "overly conservative" scheduling.
[0163] Worst-case real-time guarantee analysis This application pays particular attention to real-time performance guarantees under worst-case conditions. For critical hard real-time tasks, this application ensures the upper limit of response time under worst-case conditions through rigorous scheduling feasibility analysis during the design phase.
[0164] For each hard real-time task, worst-case execution time analysis is performed. A combination of static analysis and experimental methods is used to determine its maximum possible execution time, and a time slot slightly longer than this time is allocated to the time-triggered scheduling table to allow for a safety margin. The total processor utilization of each critical task must meet the schedulability condition. Since these tasks execute independently on deterministic processing cores and are not subject to preemption, only the timing of similar tasks needs to be considered. A reasonable schedule design can ensure that all hard real-time tasks complete on schedule even in the worst-case scenario.
[0165] For soft real-time tasks, the worst-case scenario may involve task backlog or low-priority tasks remaining unexecuted for extended periods. To address this, the dynamic scheduling strategy proposed in this application provides an effective mitigation measure: when a task's waiting time approaches the latency tolerance threshold, its criticality score increases sharply, driving the scheduler to prioritize the task and expedite its execution. Under extreme overload conditions, the system sacrifices some non-critical functions to ensure the execution of core tasks. This planned degradation strategy ensures that the deadlines of critical tasks are always met with priority.
[0166] Under the inter-nuclear two-way feedback mechanism, the protection margin adjustment ΔG i (t) Constrained by total utilization, ensure that after adjustment U'=Σ((C) i +ΔG i (t)) / T i )≤U bound This ensures that the feasibility of the scheduling table is not compromised by runtime adjustments. Inter-core coupling parameters. The introduction of (t) allows the delay penalty effect to be fine-tuned according to the actual operating state of the hardware, which can be moderately relaxed when the deterministic core is ample and doubled when it is strained.
[0167] Regarding the time-delay security of protection margin adjustment: ΔG i (t) takes effect at the next master cycle boundary, with a maximum latency of one master cycle length (typically 100 milliseconds). Within this latency window, the execution safety of hard real-time tasks is determined by the baseline time window G. i,base Offline design margin guarantee - G i,base The worst-case execution time C at the processor's minimum allowed frequency has been calculated. i,WCET,min Distribute the allocation to satisfy G. i,base ≥C i,WCET,min +G i,margin G i,margin This represents the static safety margin. Therefore, in ΔG i (t) Within a major cycle before it takes effect, the task can still be safely completed within the baseline window. When environmental changes cause (dΦ / dt) to... + When the emergency threshold is exceeded, the emergency ΔG pass-through mechanism shortens the latency to the microsecond level through inter-core interrupts, further eliminating the residual risk within the latency window.
[0168] Compared with existing technologies, this application provides a multi-core heterogeneous controller architecture that coordinates deterministic processing cores and high-performance processing cores, a hybrid scheduling mechanism that combines time-triggered and priority-preemptive scheduling, an adaptive overload and mode-switching strategy for extreme desert environments, and a task scheduling and adjustment mechanism that combines energy status and environmental awareness. Therefore, this application has at least the following significant features: 1. Regarding deterministic assurance for hard real-time tasks, this application introduces a dedicated deterministic processing core into a heterogeneous multi-core architecture and employs a time-triggered scheduling strategy, which strictly guarantees the completion of critical tasks within a specified time. The deterministic processing core features extremely low interrupt latency and task switching overhead. Combined with a carefully designed time-triggered scheduling table, even under the most severe load conditions, critical tasks can still execute on time according to predetermined time slots, unaffected by other tasks. This design significantly improves the reliability and security of the system when performing critical control tasks in a desert environment.
[0169] 2. Regarding system resource utilization and scheduling flexibility, the hybrid scheduling algorithm in this application combines the deterministic advantages of time-triggered scheduling with the flexibility of priority-based preemption. While ensuring the reliable operation of critical tasks, soft real-time tasks fully utilize the remaining system processing capacity through a dynamic priority preemption mechanism. Under normal operating conditions, the high-performance processing core can handle a large number of data analysis, communication, and artificial intelligence computing tasks, significantly improving the overall system throughput. In emergency situations, the scheduling mechanism can promptly reduce the execution of low-priority tasks and concentrate resources on processing high-priority tasks, achieving the optimal balance between efficiency and real-time performance.
[0170] 3. In terms of leveraging the advantages of heterogeneous hardware, the multi-core heterogeneous architecture enables different types of tasks to run on the most suitable cores: hard real-time control tasks run on deterministic processing cores to achieve the lowest response time jitter; complex computing tasks run on artificial intelligence acceleration cores or high-performance processing cores to achieve the highest computing efficiency. Each type of core performs its specific function and works collaboratively, achieving optimal performance and energy efficiency in power-constrained environments.
[0171] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0172] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0173] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0174] The parts not mentioned in the above embodiments are the same as or can be implemented using existing technologies, and will not be further described here.
[0175] Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A multi-core heterogeneous controller for use in desert environments, characterized in that, It includes a deterministic processing core, a high-performance processing core, and shared memory. The deterministic processing core and the high-performance processing core are interconnected via an on-chip bus and are capable of inter-core communication; wherein: The deterministic processing core is a processing core implemented using a real-time processor with deterministic interrupt response latency, configured with a runtime-triggered scheduling mechanism to execute hard real-time tasks. The high-performance processing core is a processing core implemented using a general-purpose reduced instruction set processor, configured to run a real-time operating system to preemptively schedule soft real-time tasks based on the dynamic priority of the tasks.
2. The multi-core heterogeneous controller according to claim 1, characterized in that, It also includes an artificial intelligence acceleration core, which is a processing core implemented using a neural network processing unit, a graphics processing unit, or a field-programmable gate array, and is connected to the high-performance processing core through a dedicated driver interface. The artificial intelligence acceleration core is configured to perform deep learning inference, pattern recognition, or optimization computing tasks assigned by the high-performance processing core.
3. The multi-core heterogeneous controller according to claim 1, characterized in that, The deterministic processing core is a real-time processor with deterministic interrupt response capability and low task switching overhead, and is equipped with tightly coupled memory and a dedicated interrupt controller to ensure the deterministic execution of the hard real-time task.
4. The multi-core heterogeneous controller according to claim 1, characterized in that, The shared memory is connected to the deterministic processing core and the high-performance processing core through a multi-port storage controller, which allocates an independent access channel and the highest access priority to the deterministic processing core.
5. The multi-core heterogeneous controller according to claim 1 or 4, characterized in that, The shared memory is equipped with a storage protection unit, which divides the address space of the shared memory into dedicated memory regions corresponding to each processing core, so as to achieve memory access isolation between cores.
6. A real-time task scheduling method for a desert environment, applied to the multi-core heterogeneous controller described in any one of claims 1-5, characterized in that, The method includes: On the deterministic processing core, each hard real-time task is periodically executed according to a pre-generated time-triggered scheduling table within a fixed time window pre-allocated to each hard real-time task. On the high-performance processing core, scheduling priorities are determined based on criticality scores dynamically calculated for each soft real-time task, and preemptive scheduling is performed on the ready soft real-time tasks according to the scheduling priorities. Detect the system load of the high-performance processing core; When the system load exceeds a preset threshold, an overload protection operation is performed.
7. The method according to claim 6, characterized in that, The criticality score is calculated using a predefined evaluation model, where a higher score corresponds to a higher scheduling priority. The calculation formula for the evaluation model is as follows: K i (t)=α(t)·K i0 +β(t)·f’(w i (t) / L i , (t))+γ(t)·g(S(t))+δ(t)·h(E(t)) Among them, K i (t) represents the criticality score of task i at time t, K i0 For the initial critical level, w i (t) represents the waiting time, L i Let S(t) be the delay tolerance threshold, S(t) be the state vector representing the system load, E(t) be the state variable representing the energy state, α(t), β(t), γ(t), and δ(t) be weighting coefficients dynamically adjusted according to the environmental stress coupling exponent Φ(t), and f' be the enhancement mapping function containing inter-core coupling parameters. (t) represents the average execution time margin of the deterministic processing core feedback, and g and h represent the preset mapping functions.
8. The method according to claim 7, characterized in that, The environmental stress coupling index Φ(t) is calculated using the following formula: Φ(t) = max(Φ coupling (t), Φ floor (t)) Where, Φ coupling (t)=[ (t)] a ×[1-Ê(t)] b ×[1+λ· (t)] c For multi-factor coupling terms, Φ floor (t)=max(μ T · (t),μ E ·(1-Ê(t)),μ D · (t) is a single-factor catch-all term; (t) represents the normalized temperature stress. (t)=(T(t)-T low ) / (T high -T low ), where T(t) is the current ambient temperature, T low and T high These represent the lower and upper limits of the controller's rated operating temperature, respectively; Ê(t) is the normalized energy availability, Ê(t) = E avail (t) / E rated ; (t) represents the normalized dust disturbance index; a, b, and c are coupling indices greater than or equal to 1; λ is the dust sensitivity coefficient; μ T μ E μ D This serves as a safety net contribution coefficient for each individual factor.
9. The method according to claim 7 or 8, characterized in that, The weighting coefficients are dynamically adjusted based on the environmental stress coupling index Φ(t), including: α(t)=α0·[1+σ α ·Φ(t)] β(t)=β0·[1+σ β ·Φ(t)] γ(t)=γ0·[1+σ γ ·Φ(t)] δ(t)=δ0·[1+σ δ ·Φ(t)] Where α0, β0, γ0, and δ0 are the benchmark weighting coefficients, and σ α σ β σ γ σ δ The sensitivity coefficient of each weight to environmental stress is given; wherein the sensitivity coefficient takes different preset values under different operating modes to achieve coordinated linkage between weight adjustment and mode switching.
10. The method according to claim 7, characterized in that, The expression for the enhanced mapping function f' is: f'(x, )=x n / max(1-x m +e+r· (t),e min ) in, ρ is the average execution time margin of all hard real-time tasks in the deterministic processing core feedback, ρ is the inter-core coupling coefficient, n and m are positive integers, and ε is a positive constant. min This is the lower bound protection constant for the denominator.
11. The method according to claim 10, characterized in that, The deterministic processing core calculates the execution time margin η of the current hard real-time task at the end of each time window. i (t), its calculation formula is: η i (t)=(G i -C i,actual (t)) / G i Among them, G i The current time window width allocated to task i, C i,actual (t) represents the actual execution time, and η is... i (t) Write to the execution telemetry region of the shared memory; The high-performance processing core periodically reads the execution telemetry region and calculates the weighted average execution time margin. (t)=Σ(K i0 ·η i (t)) / Σ(K i0 ), and will (t) is substituted into the enhanced mapping function f' to participate in the criticality score calculation.
12. The method according to claim 8, characterized in that, The high-performance processing core also calculates the protection margin adjustment amount for each hard real-time task based on the environmental stress coupling index Φ(t), and transmits the protection margin adjustment amount to the deterministic processing core through the scheduling parameter area of the shared memory. The deterministic processing core adjusts the time window width of the corresponding task in the time trigger scheduling table according to the protection margin adjustment amount at the next main cycle boundary.
13. The method according to claim 6, characterized in that, The overload protection operation includes at least one of the following operations: Reduce the execution frequency of tasks with a criticality score below the first threshold; Suspend tasks whose criticality score is below the second threshold; The multi-core heterogeneous controller is controlled to enter emergency mode, in which only tasks with a criticality score higher than the third threshold are scheduled for execution.
14. The method according to claim 6, characterized in that, The method further includes: Based on the comprehensive evaluation value M(t) of mode switching, adaptive switching is performed between multiple preset operating modes, including at least normal mode, high load mode and emergency mode; M(t) is calculated using the following formula: M(t)=ω1·Φ(t)+ω2·L hp (t)+ω3·(dΦ / dt) + Where Φ(t) is the environmental stress coupling index, L hp (t) represents the normalized load rate of the high-performance processing core, (dΦ / dt) + ω1, ω2, and ω3 are the positive values of the rate of change of the environmental stress coupling index, and ω1, ω2, and ω3 are the mode switching weight coefficients. The adaptive switching includes hysteresis constraints: the threshold for uplink switching is higher than the threshold for downlink switching, and the dwell time of any mode is not lower than the preset minimum dwell time.
15. The method according to claim 14, characterized in that, When the deterministic processing core reports that any hard real-time task has timed out consecutively a preset fault threshold N, fault If necessary, immediately switch to emergency mode.