Dual-processor independent voting secure lidar control method and system

CN122776789APending Publication Date: 2026-09-18JINING KELI PHOTOELECTRIC IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611282952.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-24
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

传统安全激光雷达采用单处理器架构,一旦处理器发生故障,系统将丧失安全防护能力,可能导致严重安全事故

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122776789A_ABST
    Figure CN122776789A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of industrial safety protection and laser radar, and especially provides a safety laser radar control method and system based on double-processor independent voting. The method comprises the following steps: constructing a double-processor independent voting architecture, allowing a safety output only when the outputs of the two paths of the double processor are consistent; designing a four-layer diagnosis link, which comprises FPGA layer diagnosis, processor layer diagnosis, host computer layer diagnosis and communication layer diagnosis; configuring a closed-loop management mechanism, which comprises configuration generation, configuration verification, configuration delivery and read-back comparison; designing a complete redundancy mechanism of hardware, software and communication, which comprises double-processor independent calculation, double-channel OSSD output and dynamic pulse watchdog link; and optimizing a safety control process to meet safety protection requirements. The method effectively improves the safety, reliability and maintainability of the safety laser radar by constructing a double-processor independent voting architecture, a complete diagnosis link and a configuration closed-loop management mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of industrial safety protection and lidar technology, and in particular to a safety lidar control method and system with dual processors and independent voting, which is applicable to safety protection in industrial automated production lines, robot collaboration, and automated guided vehicle (AGV) navigation scenarios. Background Technology

[0002] As a key safety device in modern industrial automation, the safety and reliability of safety lidar directly affect personnel safety and production efficiency. Safety lidar establishes a protected area using an invisible laser beam to protect hazardous areas and achieve hazard point protection, access control, or hazardous area protection. Once an object enters the protected area, the safety lidar switches its signal at the safety output terminal to output the detection status to the monitored equipment or its control system. The latter then performs a safety analysis of the signal and terminates the hazardous state.

[0003] Despite the promising application prospects of security lidar, existing methods still face the following technical challenges in achieving efficient security protection: First, the risk of single-point failure is high. Traditional security lidar uses a single-processor architecture; once the processor fails, the system loses its security protection capability, potentially leading to serious safety incidents. The typical failure rate is as high as 10%. -5The current system suffers from several drawbacks. First, it fails to meet SIL2 safety requirements. Processor failures can manifest in various ways, such as program crashes, memory corruption, and clock anomalies, which a single-processor architecture cannot effectively handle. Second, it lacks diagnostic capabilities. While existing systems possess basic fault detection capabilities, they lack a complete diagnostic chain, making it difficult to accurately pinpoint the cause of failures. This results in low maintenance efficiency, with an average fault repair time exceeding two hours. When a system failure occurs, maintenance personnel struggle to quickly locate the faulty module, resorting to replacement methods for piecemeal troubleshooting, increasing maintenance costs and downtime. Third, there is a delay in safety response. The safety response time of some systems is relatively long (100-500ms), failing to meet the safety protection requirements of high-speed automated production lines and potentially leading to personnel injury or equipment damage. On high-speed production lines, when personnel or objects enter hazardous areas, the system needs to respond within a very short time, which traditional systems cannot adequately meet. Fourth, there are configuration management risks. Safety parameter configurations lack effective verification mechanisms; configuration errors can lead to safety function failures. Existing systems lack configuration readback and comparison functions, making configuration errors difficult to detect. The protection zone, encoder parameters, and safety output configuration of a safety lidar directly affect the correctness of its safety functions; incorrect configuration can lead to serious consequences. Fifth, the redundancy design is inadequate. Existing redundancy designs often only focus on the hardware level, lacking complete redundancy mechanisms at the software and communication levels, resulting in low overall system reliability. While hardware redundancy can handle some hardware failures, software logic errors and communication failures require redundancy mechanisms at the software and communication levels to address them.

[0004] Current technologies generally assume that redundancy design for secure lidar only needs to focus on the hardware level, neglecting redundancy at the software and communication levels. This technological bias leads to low overall system reliability, making it difficult to effectively handle issues such as software logic errors and communication failures. Existing systems lack a complete diagnostic link, making fault tracing difficult; they also lack closed-loop configuration management, making configuration errors difficult to detect. Summary of the Invention

[0005] In view of this, the present invention provides a method and system for controlling a secure lidar with independent voting by dual processors, so as to effectively improve the security, reliability and maintainability of the secure lidar.

[0006] In a first aspect, the present invention provides a secure lidar control method with dual-processor independent voting, the method comprising:

[0007] Step 1: Construct a dual-processor independent voting architecture, allowing safe output only when the outputs of the two processors are consistent; Step 2: Based on Step 1, design a four-layer diagnostic link, which includes FPGA layer diagnostics, processor layer diagnostics, host computer layer diagnostics, and communication layer diagnostics. Step 3: Based on Step 2, configure a closed-loop management mechanism, which includes configuration generation, configuration verification, configuration distribution, and readback comparison. Step 4: Based on Step 3, design a complete redundancy mechanism for hardware, software and communication, including independent computing by dual processors, dual-channel OSSD output, and dynamic pulse watchdog link. Step 5: Based on Step 4, optimize the safety control process to meet safety protection requirements.

[0008] Optionally, step 1 includes: The two processors independently calculate the zone intrusion status and perform cross-verification through mutual check frames. Safe output is allowed only when the outputs of the two processors are consistent, so as to ensure dangerous output in case of single point of failure. Step 11: Read measurement data: The two processors independently acquire laser ranging data from the FPGA, including distance, intensity, and angle information; Step 12, Area Protection Determination: The two processors independently determine whether the target is within the protection area, based on the preset protection area parameters; Step 13, Safety Status Calculation: Each of the two processors independently calculates the safety status based on the judgment result and outputs a safety or danger signal; Step 14, Regional Cyclic Redundancy Check (CRC): The two processors independently calculate the CRC checksum for each zone, which is used for subsequent cross-checking. Step 15, Cross-checking of mutual check frames: The two processors exchange calculation results through mutual check frames. When the two outputs are consistent, safe output is allowed. When the two outputs are inconsistent, a safe response is triggered. The comparison field includes timestamp, hardware and software version, calibration parameters, CRC checksum of each zone, OSSD1 / 2 status of dual-channel pulse output signal, static zone Z1~Z6, EDM1 / 2 status, encoder speed 1~4, motor speed, and reference distance; The comparison thresholds are set to GRAVE_FAULT_MAX = 6 times for fatal faults and COMMON_FAULT_MAX = 10 times for common faults; when the comparison exceeds the threshold, -1 / -2 is returned respectively to trigger a safe state.

[0009] Optionally, step 2 includes dual-track fault codes at the FPGA layer, fault response at the processor layer, status verification at the host computer layer, and error detection at the communication layer, so as to make the fault traceable. Step 21: The FPGA layer is used for fault detection in the underlying hardware; First, dual-track fault codes are determined: the FPGA internally uses ErrP and ErrN dual-track fault codes. When both ErrP and ErrN are high, a fault is indicated, which is used to indicate an internal FPGA fault. Second, 8B10B error detection is performed: optical link transmission errors are detected, and an error flag is triggered when invalid codes are detected. Then, CRC16 verification is performed: data integrity is verified, and an error flag is triggered when the CRC verification fails. Finally, 12 types of error counters are counted: the number of occurrences of each type of error is counted, and a fault alarm is triggered when the number of errors exceeds a threshold. Step 22: The processor layer is used for fault detection in security logic; First, FPGA fault response: The processor periodically reads the FPGA status register, and triggers a safety response when an FPGA fault is detected. Second, mutual check timeout detection: The two processors exchange information through mutual check frames. If one processor does not receive a mutual check frame from the other within 300ms, it is determined that the mutual check has timed out, and a safety response is triggered. Third, self-test mechanism: The processor periodically executes a self-test program to check the status of the core components, the CPU, Flash memory, and RAM. Finally, STL safety self-test: The X-CUBE-STL library is used to test the CPU, Flash, and RAM to detect hardware faults. Step 23: The host computer layer is used for system-level fault detection; First, perform OSSD status verification: the host computer periodically reads the OSSD output status, and triggers an alarm when an abnormal OSSD output is detected. Second, perform configuration readback and comparison: after the host computer sends the configuration parameters to the lidar, it reads back the lidar's internal configuration and compares it with the sent configuration. If the comparison is inconsistent, an alarm is triggered. Finally, perform error log recording: error information is recorded to a log file, including error type, error time, error location, etc., for fault analysis.

[0010] Step 24: The communication layer is used for fault detection in data transmission; First, a communication timeout detection is performed: if data transmission is delayed beyond a preset time, it is considered a communication timeout and an error flag is triggered. Second, a data integrity verification is performed: the CRC check algorithm is used to verify data integrity, and an error flag is triggered when the CRC check fails. Finally, an error retransmission mechanism is implemented: when a data transmission error is detected, the erroneous data is automatically retransmitted, with a maximum of 3 retransmissions.

[0011] Optionally, step 3 includes: Step 31: Configuration Generation. The configuration is edited using the host computer software. The configuration includes the protected area, encoder parameters, and safety parameters. First, set the protected area: in the host computer software, set the protected area coordinates (Xmin, Ymin, Xmax, Ymax) and the safety distance threshold [0.1m, 10m]. Second, set the encoder parameters: in the host computer software, set the encoder pulse ratio [10, 100]. Then, set the safety parameters: in the host computer software, set the OSSD output mode parameters. Finally, serialize the configuration: the host computer software serializes the configuration parameters into binary format. Step 32: Configuration verification. The system has 79 built-in TÜV verification rules, which are verified item by item before the configuration is issued. First, encoder pulse ratio range verification: verify whether the encoder pulse ratio is within the range of [10, 100]; second, EDM. OSSD interlock verification: Verify whether the interlock relationship between EDM and OSSD is correct; then, protection area rationality verification: verify whether the coordinates of the protection area are reasonable and whether they are greater than the measurement range of the lidar; finally, safety distance threshold range verification: verify whether the safety distance threshold is within the range of [0.1m, 10m]. Verification method: Item-by-item verification is performed, and only if all items pass can the data be distributed; if any item fails the verification, distribution will be rejected and an error message will be displayed; Verification result recording: The verification results will be recorded in a log file, including the verification time, verification rules, and verification result information; Step 33: Configuration distribution. After the configuration verification is successful, the configuration parameters are distributed to the LiDAR via TCP protocol. First, the host computer packages the configuration parameters into a binary format, including the configuration parameters and a CRC-16 / Modbus checksum. Second, the host computer establishes a connection with the LiDAR via TCP protocol, port 1002. Then, the host computer sends the configuration parameters to the LiDAR via the TCP connection. Finally, the LiDAR receives the configuration and returns an acknowledgment message. Step 34: Read back and compare. After the configuration is issued, read back the radar's internal configuration and compare it with the issued configuration. First, read back the configuration: read the configuration parameters from the internal Flash memory of the LiDAR; second, compare item by item: compare the issued configuration with the read configuration one by one; finally, judge the result: if the issued configuration is consistent with the read configuration, the configuration takes effect; if the issued configuration is inconsistent with the read configuration, an alarm is triggered and the error information is recorded in the log file.

[0012] Optionally, step 4 includes: a. Design a dynamic pulse watchdog link using a 74123 monostable multivibrator, a 1MΩ timing resistor, a 1μF timing capacitor, and a 1s timeout. First, the processor outputs a watchdog toggle signal via GPIO, with a 128ms cycle and a 50% duty cycle. Second, the monostable multivibrator receives the watchdog signal; when a rising edge is detected, it outputs a high-level drv signal and starts timing. Then, timeout detection occurs: if no next rising edge is detected within the timeout period, the monostable multivibrator times out, and the drv signal goes low. Finally, a logic gate controls the output: the logic gate receives both the watchdog and drv signals and outputs a zero signal to control the safety output. b. The watchdog link works as follows: First, the processor continuously toggles the WatchDog signal every 128ms. Second, the monostable multivibrator is reset: the 74123 monostable multivibrator receives the WatchDog signal and resets its timer each time a rising edge is detected. Then, normal operation is checked: if the processor is working normally, the WatchDog signal continues to toggle, and the drv signal remains high. Next, fault detection occurs: if the processor fails, the WatchDog signal stops toggling, the monostable multivibrator times out, and the drv signal goes low. Finally, the safety output is turned off: after the logic gate detects that the drv signal has gone low, it outputs a 0 signal to turn off the safety output. c. Independent channel design: Four independent watchdog channels are designed, each channel independently monitors the security output; First, channel allocation: channels 1 and 3 are controlled by MCU-A, which monitors the outputs of OSSD1 and OSSD3; channels 2 and 4 are controlled by MCU-B, which monitors the outputs of OSSD2 and OSSD4. Second, independent operation: each channel operates independently without interference. Finally, fault isolation: when any channel detects a fault, the corresponding safety output of the current channel is automatically shut down.

[0013] Optionally, step 5 includes: The safety control process is optimized to ensure a safety response time of less than 10ms, meeting the safety protection requirements of high-speed automated production lines. h. The safety control process is as follows: laser emission, echo reception, TDC time measurement, dual-channel comparison, area detection, independent voting, EN_O3 / O4 shutdown right, dynamic watchdog chain, OSSD output, and safety shutdown. Laser emission: 10-100ns, the laser emits a laser pulse; Echo reception: 1-10μs, the receiver receives the reflected laser light; TDC time measurement: 1-10μs, calculates the laser flight time; Dual-channel comparison: 10-50μs, compares data between the main channel and the monitoring channel; Area detection: 10-50μs, determines whether an object is in a danger zone; Independent voting: 10-100μs, two processors independently determine whether it is safe; EN_O3 / O4 shutdown right: 1-10μs, shuts down the safety output; Dynamic watchdog chain: 1-10μs, checks whether the processor is working properly; OSSD output: 1-10ms, outputs a safety signal; Safety shutdown: depends on external equipment; i. Optimized response time, with a security response time of less than 10ms; Signal acquisition stage: response time for laser emission, echo reception, and TDC time measurement is 20-120μs; signal processing stage: response time for dual-channel comparison, region detection, and independent voting is 30-200μs; output control stage: response time for EN_O3 / O4 shutdown rights, dynamic watchdog chain, and OSSD output is 2-20ms; total security response time is less than 10ms.

[0014] Secondly, the present invention provides a secure lidar control system with dual-processor independent voting, the system being used to implement the secure lidar control method with dual-processor independent voting in the first aspect or any possible implementation of the first aspect; the system adopts a four-layer architecture, from bottom to top being a physical sensing layer, a measurement processing layer, a security control layer and an application configuration layer. The physical sensing layer is used to collect environmental data and includes a laser emitting module, a photoelectric receiving module, and a TDC time measurement module. The laser emitting module uses a 905nm laser diode to emit laser pulses through a constant current driving circuit. The pulse width is 10-100ns, the driving current is 0-100A, and the repetition frequency is 10-100kHz. The photoelectric receiving module uses an APD detector to convert the reflected laser into an electrical signal. The sensitivity is -65dBm, and the dynamic range is 40dB. The TDC time measurement module uses an MS1005 chip to measure the flight time of the laser from emission to reception with an accuracy of ±1mm. It is connected to the FPGA through an LVDS interface. The measurement processing layer is used to process raw data, and it includes a first FPGA and a second FPGA. The first FPGA uses WIL5025-7I to acquire TDC data, process multi-echo signals, perform angle interpolation, and transmit the data through 8B10B encoding. The second FPGA uses WIL5025-7I to receive optical link data, perform frame synchronization processing, and distribute the data to the two processors through the SPI interface. The security control layer is used for security decisions and includes a first processor and a second processor. The first processor uses a GD32H789, runs an RTX5 RTOS, and performs security logic processing, zone protection decisions, Ethernet gateway, and OSSD A-line driver. The second processor uses a GD32H789, runs a hyperloop, and performs redundant security logic, cross-checking, and OSSD B-line driver. The two processors perform independent calculations and cross-checking through mutual check frames. The application configuration layer is used for configuration and monitoring, and it includes host computer software; the host computer software is used to configure the protection zone, view real-time data, and record fault logs.

[0015] Optionally, the mutual inspection frame format includes: a 4-byte preamble, a 2-byte length, a 2-byte CRC-16, a 1-byte command type, a 1-byte subcommand, and an N-byte comparison field.

[0016] The technical solution provided by this invention includes a method that constructs a dual-processor independent voting architecture, allowing safe output only when the outputs of the two processors are consistent; designs a four-layer diagnostic link, including FPGA layer diagnostics, processor layer diagnostics, host computer layer diagnostics, and communication layer diagnostics; configures a closed-loop management mechanism, including configuration generation, configuration verification, configuration distribution, and readback comparison; designs a complete redundancy mechanism for hardware, software, and communication, including independent computing by dual processors, dual-channel OSSD output, and a dynamic pulse watchdog link; and optimizes the safety control process to meet safety protection requirements. This method effectively improves the safety, reliability, and maintainability of the safety lidar by constructing a dual-processor independent voting architecture, a complete diagnostic link, and a configuration closed-loop management mechanism. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A flowchart of a secure lidar control method with dual-processor independent voting provided in an embodiment of the present invention; Figure 2 A schematic diagram of a secure lidar system architecture with independent voting by dual processors provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of a dual-processor independent voting architecture provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the safety control process provided in an embodiment of the present invention; Figure 5 This is a schematic diagram of the configuration closed-loop management process provided in an embodiment of the present invention; Figure 6 This is a schematic diagram of the mutual inspection frame format provided in an embodiment of the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “a,” “the,” and “the” used in the embodiments of this invention are also intended to include the plural forms unless the context clearly indicates otherwise.

[0021] It should be understood that the term "and / or" used in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0022] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0023] This invention provides a secure lidar control method with dual-processor independent voting, such as... Figures 1 to 6 As shown, the method includes: Step 1: Construct a dual-processor independent voting architecture, allowing safe output only when the outputs of the two processors are consistent; In this embodiment of the invention, step 1 includes: The two processors independently calculate the zone intrusion status and perform cross-verification through mutual check frames. Safe output is allowed only when the outputs of the two processors are consistent, so as to ensure dangerous output in case of single point of failure. Step 11: Read measurement data: The two processors independently acquire laser ranging data from the FPGA, including distance, intensity, and angle information; Step 12, Area Protection Determination: The two processors independently determine whether the target is within the protection area, based on the preset protection area parameters; Step 13, Safety Status Calculation: Each of the two processors independently calculates the safety status based on the judgment result and outputs a safety or danger signal; Step 14, Regional Cyclic Redundancy Check (CRC): The two processors independently calculate the CRC checksum for each zone, which is used for subsequent cross-checking. Step 15, Cross-checking of mutual check frames: The two processors exchange calculation results through mutual check frames. When the two outputs are consistent, safe output is allowed. When the two outputs are inconsistent, a safe response is triggered. Traditional solutions employ a single-processor architecture, which renders the system incapable of security protection if the processor fails. This invention utilizes a dual-processor independent voting architecture, where two processors independently calculate the intrusion status of the protected zone and perform cross-verification using mutual check frames. A secure output is only allowed when both outputs are consistent, thus resolving the high risk of single-point failure in traditional solutions.

[0024] The comparison field includes timestamp, hardware and software version, calibration parameters, CRC checksum of each zone, OSSD1 / 2 status of dual-channel pulse output signal, static zone Z1~Z6, EDM1 / 2 status, encoder speed 1~4, motor speed, and reference distance; The comparison thresholds are set to GRAVE_FAULT_MAX = 6 times for fatal faults and COMMON_FAULT_MAX = 10 times for common faults; when the comparison exceeds the threshold, -1 / -2 is returned respectively to trigger a safe state.

[0025] Step 2: Based on Step 1, design a four-layer diagnostic link, which includes FPGA layer diagnostics, processor layer diagnostics, host computer layer diagnostics, and communication layer diagnostics. In this embodiment of the invention, step 2 includes dual-track fault codes at the FPGA layer, fault response at the processor layer, status verification at the host computer layer, and error detection at the communication layer, so as to make the fault traceable. Step 21: The FPGA layer is used for fault detection in the underlying hardware; First, dual-track fault codes are determined: the FPGA internally uses ErrP and ErrN dual-track fault codes. When both ErrP and ErrN are high, a fault is indicated, which is used to indicate an internal FPGA fault. Second, 8B10B error detection is performed: optical link transmission errors are detected, and an error flag is triggered when invalid codes are detected. Then, CRC16 verification is performed: data integrity is verified, and an error flag is triggered when the CRC verification fails. Finally, 12 types of error counters are counted: the number of occurrences of each type of error is counted, and a fault alarm is triggered when the number of errors exceeds a threshold.

[0026] Traditional solutions only count the total number of errors, failing to accurately pinpoint the fault type. This invention designs 12 types of error counters, each counting different types of errors. When the number of errors exceeds a threshold, a fault alarm is triggered, solving the problem of traditional solutions' inability to accurately identify the fault type.

[0027] Step 22: The processor layer is used for fault detection in security logic; First, FPGA fault response: The processor periodically reads the FPGA status register, and triggers a safety response when an FPGA fault is detected. Second, mutual check timeout detection: The two processors exchange information through mutual check frames. If one processor does not receive a mutual check frame from the other within 300ms, it is determined that the mutual check has timed out, and a safety response is triggered. Third, self-test mechanism: The processor periodically executes a self-test program to check the status of the core components, the central processing unit (CPU), flash memory (Flash), and random access memory (RAM). Finally, STL safety self-test: The X-CUBE-STL library is used to test the CPU, Flash, and RAM to detect hardware faults.

[0028] Traditional solutions use one-way heartbeat detection, which can only detect whether the other party is alive, but cannot grasp the other party's operational status. This invention uses bidirectional mutual inspection frame exchange. The mutual inspection frames contain information such as processor status and fault codes, solving the problem of traditional solutions' inability to grasp the other party's operational status. Traditional solutions use self-written self-check programs, resulting in low self-check coverage and failing to meet SIL2 security certification requirements. This invention uses the X-CUBE-STL library, which is SIL2 certified and has high self-check coverage, solving the problem of low self-check coverage and failure to meet security certification requirements in traditional solutions. Step 23: The host computer layer is used for system-level fault detection; First, perform OSSD status verification: the host computer periodically reads the OSSD output status, and triggers an alarm when an abnormal OSSD output is detected. Second, perform configuration readback and comparison: after the host computer sends the configuration parameters to the lidar, it reads back the lidar's internal configuration and compares it with the sent configuration. If the comparison is inconsistent, an alarm is triggered. Finally, perform error log recording: error information is recorded to a log file, including error type, error time, error location, etc., for fault analysis.

[0029] Step 24: The communication layer is used for fault detection in data transmission; First, a communication timeout detection is performed: if data transmission is delayed beyond a preset time, it is considered a communication timeout and an error flag is triggered. Second, a data integrity verification is performed: the CRC check algorithm is used to verify data integrity, and an error flag is triggered when the CRC check fails. Finally, an error retransmission mechanism is implemented: when a data transmission error is detected, the erroneous data is automatically retransmitted, with a maximum of 3 retransmissions.

[0030] Step 3: Based on Step 2, configure a closed-loop management mechanism, which includes configuration generation, configuration verification, configuration distribution, and readback comparison. In this embodiment of the invention, a closed-loop management mechanism for configuration is designed to ensure that configuration parameters are 100% correct and to prevent configuration errors from causing security function failures. Step 3 includes: Step 31: Configuration Generation. The configuration is edited using the host computer software. The configuration includes the protected area, encoder parameters, and safety parameters. First, set the protected area: in the host computer software, set the protected area coordinates (Xmin, Ymin, Xmax, Ymax) and the safety distance threshold [0.1m, 10m]. Second, set the encoder parameters: in the host computer software, set the encoder pulse ratio [10, 100]. Then, set the safety parameters: in the host computer software, set the OSSD output mode parameters. Finally, serialize the configuration: the host computer software serializes the configuration parameters into binary format. Step 32: Configuration verification. The system has 79 built-in TÜV verification rules, which are verified item by item before the configuration is issued. First, encoder pulse ratio range verification: verify whether the encoder pulse ratio is within the range of [10, 100]; second, EDM. OSSD interlock verification: Verify whether the interlock relationship between EDM and OSSD is correct; then, protection area rationality verification: verify whether the coordinates of the protection area are reasonable and whether they are greater than the measurement range of the lidar; finally, safety distance threshold range verification: verify whether the safety distance threshold is within the range of [0.1m, 10m]. Verification method: Item-by-item verification is performed, and only if all items pass can the data be distributed; if any item fails the verification, distribution will be rejected and an error message will be displayed; Verification result recording: The verification results will be recorded in a log file, including the verification time, verification rules, and verification result information; Step 33: Configuration distribution. After the configuration verification is successful, the configuration parameters are distributed to the LiDAR via TCP protocol. First, the host computer packages the configuration parameters into a binary format, including the configuration parameters and a CRC-16 / Modbus checksum. Second, the host computer establishes a connection with the LiDAR via TCP protocol, port 1002. Then, the host computer sends the configuration parameters to the LiDAR via the TCP connection. Finally, the LiDAR receives the configuration and returns an acknowledgment message. Step 34: Read back and compare. After the configuration is issued, read back the radar's internal configuration and compare it with the issued configuration. First, read back the configuration: read the configuration parameters from the internal Flash memory of the LiDAR; second, compare item by item: compare the issued configuration with the read configuration one by one; finally, judge the result: if the issued configuration is consistent with the read configuration, the configuration takes effect; if the issued configuration is inconsistent with the read configuration, an alarm is triggered and the error information is recorded in the log file.

[0031] Traditional solutions only distribute configurations without verification, making it difficult to detect configuration errors. This invention adds configuration readback comparison, triggering an alarm when discrepancies are found, thus solving the problem of difficult-to-detect configuration errors in traditional solutions.

[0032] Step 4: Based on Step 3, design a complete redundancy mechanism for hardware, software and communication, including independent computing by dual processors, dual-channel OSSD output, and dynamic pulse watchdog link to improve the overall reliability of the system. In this embodiment of the invention, a dynamic pulse watchdog chain is designed to monitor whether the processor is working properly in real time. When the processor fails, the safety output is automatically shut down. Step 4 includes: a. Design a dynamic pulse watchdog link using a 74123 monostable multivibrator, a 1MΩ timing resistor, a 1μF timing capacitor, and a 1s timeout. First, the processor outputs a watchdog toggle signal via GPIO, with a toggle frequency of 128ms (7.8Hz) and a 50% duty cycle. Second, the monostable multivibrator receives the watchdog signal; when a rising edge is detected, it outputs a high-level drv signal and starts timing. Then, timeout detection occurs: if no next rising edge is detected within the timeout period, the monostable multivibrator times out, and the drv signal goes low. Finally, a logic gate controls the output: the logic gate receives both the watchdog and drv signals and outputs a zero signal to control the safety output. b. The watchdog link works as follows: First, the processor continuously toggles the WatchDog signal, changing it every 128ms. Second, the monostable multivibrator is reset: the 74123 monostable multivibrator receives the WatchDog signal and resets the timer each time a rising edge is detected. Then, normal operation is checked: if the processor is working normally, the WatchDog signal continues to toggle, and the drv signal remains high. Next, fault detection occurs: if the processor malfunctions (e.g., program crashes, clock error), the WatchDog signal stops toggling, the monostable multivibrator times out, and the drv signal goes low. Finally, the safety output is turned off: after the logic gate detects that the drv signal has gone low, it outputs a 0 signal to turn off the safety output. Traditional solutions use a static watchdog timer, which can only detect whether the processor is alive, but cannot detect whether the processor is working properly. This invention uses a dynamic pulse watchdog chain, which determines whether the processor is working properly by detecting the toggling state of the WatchDog signal, thus solving the problem that traditional solutions cannot detect whether the processor is working properly.

[0033] c. Independent channel design: Four independent watchdog channels are designed, each channel independently monitors the security output; First, channel allocation: channels 1 and 3 are controlled by MCU-A, which monitors the outputs of OSSD1 and OSSD3; channels 2 and 4 are controlled by MCU-B, which monitors the outputs of OSSD2 and OSSD4. Second, independent operation: each channel operates independently without interference, improving system reliability. Finally, fault isolation: when any channel detects a fault, the corresponding safety output of the current channel is automatically shut down.

[0034] Traditional solutions use a single watchdog channel; if the watchdog fails, all safety outputs will fail. This invention employs a four-channel independent design, with each channel independently monitoring one safety output, thus solving the problem of all safety outputs failing due to a single channel failure in traditional solutions.

[0035] Step 5: Based on Step 4, optimize the safety control process to meet safety protection requirements.

[0036] In this embodiment of the invention, a complete safety control process is designed, with clear time requirements for each step from laser emission to safe shutdown. Step 5 includes: The safety control process is optimized to ensure a safety response time of less than 10ms, meeting the safety protection requirements of high-speed automated production lines. h. The safety control process is as follows: laser emission, echo reception, TDC time measurement, dual-channel comparison, area detection, independent voting, EN_O3 / O4 shutdown right, dynamic watchdog chain, OSSD output, and safety shutdown. Laser emission: 10-100ns, the laser emits a laser pulse; Echo reception: 1-10μs, the receiver receives the reflected laser light; TDC time measurement: 1-10μs, calculates the laser flight time; Dual-channel comparison: 10-50μs, compares data between the main channel and the monitoring channel; Area detection: 10-50μs, determines whether an object is in a danger zone; Independent voting: 10-100μs, two processors independently determine whether it is safe; EN_O3 / O4 shutdown right: 1-10μs, shuts down the safety output; Dynamic watchdog chain: 1-10μs, checks whether the processor is working properly; OSSD output: 1-10ms, outputs a safety signal; Safety shutdown: depends on external equipment; i. Optimized response time, with a security response time of less than 10ms; Signal acquisition stage: response time for laser emission, echo reception, and TDC time measurement is 20-120μs; signal processing stage: response time for dual-channel comparison, region detection, and independent voting is 30-200μs; output control stage: response time for EN_O3 / O4 shutdown rights, dynamic watchdog chain, and OSSD output is 2-20ms; total security response time is less than 10ms.

[0037] Traditional solutions have a response time of 100-500ms, which cannot meet the safety protection requirements of high-speed automated production lines. This invention optimizes the safety control process to achieve a safety response time of less than 10ms, solving the problem of long response times and inability to meet the safety protection requirements of high-speed production lines caused by traditional solutions.

[0038] In this embodiment of the invention, system performance verification and experimental result analysis are conducted through rigorous experimental verification to ensure that the design goals and security certification requirements are met.

[0039] 1. Evaluation indicators; Safety level: SIL2 / PL d (IEC 61496 Type 3), meeting industrial safety standards; response time less than 10ms, the time from the detection of a hazard to the response; MTBF greater than 50,000 hours, the system's mean time between failures; diagnostic coverage greater than 90%, the proportion of faults that the system can detect.

[0040] 2. Performance comparison experiments are shown in Table 1; Table 1 Performance Comparison ; Experimental Conclusion: This invention outperforms existing technologies in terms of safety level, response time, reliability, diagnostic capabilities, and configuration security, meeting the stringent requirements of industrial safety scenarios. Traditional solutions can only achieve SIL1 / PL c safety levels, failing to meet higher safety level requirements. This invention, through innovative designs such as a dual-processor independent voting architecture, a complete diagnostic link, and closed-loop configuration management, achieves SIL2 / PL d safety levels, solving the problem that traditional solutions cannot meet higher safety level requirements.

[0041] This invention provides a dual-processor independent voting safety lidar control system, as shown in the figure. The system is used to implement the above-mentioned dual-processor independent voting safety lidar control method. The system adopts a four-layer architecture, which consists of a physical sensing layer, a measurement processing layer, a safety control layer, and an application configuration layer from bottom to top. The physical sensing layer is used to collect environmental data and includes a laser emitting module, a photoelectric receiving module, and a TDC time measurement module. The laser emitting module uses a 905nm laser diode to emit laser pulses through a constant current driving circuit. The pulse width is 10-100ns, the driving current is 0-100A, and the repetition frequency is 10-100kHz. The photoelectric receiving module uses an APD detector to convert the reflected laser into an electrical signal. The sensitivity is -65dBm, and the dynamic range is 40dB. The TDC time measurement module uses an MS1005 chip to measure the flight time of the laser from emission to reception with an accuracy of ±1mm. It is connected to the FPGA through an LVDS interface. The measurement processing layer is used to process raw data, and it includes a first FPGA and a second FPGA. The first FPGA uses WIL5025-7I to acquire TDC data, process multi-echo signals, perform angle interpolation, and transmit the data through 8B10B encoding. The second FPGA uses WIL5025-7I to receive optical link data, perform frame synchronization processing, and distribute the data to the two processors through the SPI interface. The security control layer is used for security decisions and includes a first processor and a second processor. The first processor uses a GD32H789, runs an RTX5 RTOS, and performs security logic processing, zone protection decisions, Ethernet gateway, and OSSD A-line driver. The second processor uses a GD32H789, runs a hyperloop, and performs redundant security logic, cross-checking, and OSSD B-line driver. The two processors perform independent calculations and cross-checking through mutual check frames. The application configuration layer is used for configuration and monitoring, and it includes host computer software; the host computer software is used to configure the protection zone, view real-time data, and record fault logs.

[0042] In embodiments of the present invention, such as Figure 6As shown, the mutual inspection frame format includes: a 4-byte preamble, a 2-byte length, a 2-byte CRC-16 ...

[0043] In this embodiment of the invention, the failure rate is reduced to <10% through a dual-processor independent voting architecture. -6 / h, the failure rate of the traditional solution is 10 -5 / h, with a security response time of less than 10ms, compared to 100-500ms for traditional solutions, and a diagnostic coverage of >90%.

[0044] Compared with the prior art, the present invention has the following advantages: High security: Dual-processor independent voting architecture ensures that a single point of failure does not lead to dangerous output, meeting SIL2 / PLd safety level requirements. The two processors independently calculate the zone intrusion status, performing cross-verification via mutual check frames, allowing safe output only when both outputs are consistent.

[0045] Rapid Response: Safety response time <10ms, meeting the safety protection requirements of high-speed automated production lines. By optimizing the safety control process, a rapid response from laser emission to equipment shutdown is achieved.

[0046] Complete diagnostics: A four-layer diagnostic chain ensures fault traceability and an average fault repair time of less than 30 minutes. This includes dual-track fault codes at the FPGA layer, fault responses at the processor layer, error detection at the communication layer, and status verification at the host computer layer.

[0047] High reliability: Complete redundancy in hardware, software and communication, MTBF>50,000 hours, including independent computing by dual processors, dual-channel OSSD output, dynamic pulse watchdog chain, etc.

[0048] Security Configuration: 79 verification rules, closed-loop management to prevent configuration errors. A complete closed loop for configuration generation, verification, distribution, and readback comparison.

[0049] The technical solution provided by this invention includes a method that constructs a dual-processor independent voting architecture, allowing safe output only when the outputs of the two processors are consistent; designs a four-layer diagnostic link, including FPGA layer diagnostics, processor layer diagnostics, host computer layer diagnostics, and communication layer diagnostics; configures a closed-loop management mechanism, including configuration generation, configuration verification, configuration distribution, and readback comparison; designs a complete redundancy mechanism for hardware, software, and communication, including independent computing by dual processors, dual-channel OSSD output, and a dynamic pulse watchdog link; and optimizes the safety control process to meet safety protection requirements. This method effectively improves the safety, reliability, and maintainability of the safety lidar by constructing a dual-processor independent voting architecture, a complete diagnostic link, and a configuration closed-loop management mechanism.

[0050] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A dual-processor independent-vote secure lidar control method, characterized by, The method includes: Step 1: Construct a dual-processor independent voting architecture, allowing safe output only when the outputs of the two processors are consistent; Step 2: Based on Step 1, design a four-layer diagnostic link, which includes FPGA layer diagnostics, processor layer diagnostics, host computer layer diagnostics, and communication layer diagnostics. Step 3: Based on Step 2, configure a closed-loop management mechanism, which includes configuration generation, configuration verification, configuration distribution, and readback comparison. Step 4: Based on Step 3, design a complete redundancy mechanism for hardware, software and communication, including independent computing by dual processors, dual-channel OSSD output, and dynamic pulse watchdog link. Step 5: Based on Step 4, optimize the safety control process to meet safety protection requirements.

2. The method of claim 1, wherein, Step 1 includes: The two processors independently calculate the zone intrusion status and perform cross-verification through mutual check frames. Safe output is allowed only when the outputs of the two processors are consistent, so as to ensure dangerous output in case of single point of failure. Step 11: Read measurement data: The two processors independently acquire laser ranging data from the FPGA, including distance, intensity, and angle information; Step 12, Area Protection Determination: The two processors independently determine whether the target is within the protection area, based on the preset protection area parameters; Step 13, Safety Status Calculation: Each of the two processors independently calculates the safety status based on the judgment result and outputs a safety or danger signal; Step 14, Regional Cyclic Redundancy Check (CRC): The two processors independently calculate the CRC checksum for each zone, which is used for subsequent cross-checking. Step 15, Cross-checking of mutual check frames: The two processors exchange calculation results through mutual check frames. When the two outputs are consistent, safe output is allowed. When the two outputs are inconsistent, a safe response is triggered. The comparison field includes timestamp, hardware and software version, calibration parameters, CRC checksum of each zone, OSSD1 / 2 status of dual-channel pulse output signal, static zone Z1~Z6, EDM1 / 2 status, encoder speed 1~4, motor speed, and reference distance; The comparison thresholds are set to GRAVE_FAULT_MAX = 6 times for fatal faults and COMMON_FAULT_MAX = 10 times for common faults; when the comparison exceeds the threshold, -1 / -2 is returned respectively to trigger a safe state.

3. The method of claim 2, wherein, Step 2 includes dual-track fault codes at the FPGA layer, fault response at the processor layer, status verification at the host computer layer, and error detection at the communication layer, in order to make the fault traceable. Step 21: The FPGA layer is used for fault detection in the underlying hardware; First, determine the dual-track fault code: The FPGA internally uses ErrP and ErrN dual-track fault codes. When ErrP and ErrN are both high, it indicates a fault and is used to indicate an internal FPGA fault. Second, perform 8B10B error detection: detect optical link transmission errors. When invalid codes are detected, an error flag is triggered. Then, a CRC16 check is performed: to verify data integrity, and to trigger an error flag when the CRC check fails. Finally, 12 error counters are used to count the number of errors of each type. When the number of errors exceeds the threshold, a fault alarm is triggered. Step 22: The processor layer is used for fault detection in security logic; First, FPGA fault response: The processor periodically reads the FPGA status register, and triggers a safety response when an FPGA fault is detected. Second, mutual check timeout detection: The two processors exchange information through mutual check frames. If one processor does not receive a mutual check frame from the other within 300ms, it is determined that the mutual check has timed out, and a safety response is triggered. Third, self-test mechanism: The processor periodically executes a self-test program to check the status of the core components, the CPU, Flash memory, and RAM. Finally, STL safety self-test: The X-CUBE-STL library is used to test the CPU, Flash, and RAM to detect hardware faults. Step 23: The host computer layer is used for system-level fault detection; First, OSSD status verification is performed: the host computer periodically reads the OSSD output status, and triggers an alarm when an abnormal OSSD output is detected. Second, configuration readback and comparison are performed: after the host computer sends the configuration parameters to the lidar, it reads back the lidar's internal configuration and compares it with the sent configuration. An alarm is triggered when the comparison is inconsistent. Finally, error log recording is performed: error information is recorded to a log file, including error type, error time, error location, etc., for fault analysis. Step 24: The communication layer is used for fault detection in data transmission; First, a communication timeout detection is performed: if data transmission is delayed beyond a preset time, it is determined to be a communication timeout and an error flag is triggered. Secondly, data integrity is verified: the CRC check algorithm is used to verify data integrity, and an error flag is triggered when the CRC check fails; finally, an error retransmission mechanism is implemented: when a data transmission error is detected, the erroneous data is automatically retransmitted, with a maximum of 3 retransmissions.

4. The method according to claim 3, characterized in that, Step 3 includes: Step 31: Configuration Generation. The configuration is edited using the host computer software. The configuration includes the protected area, encoder parameters, and safety parameters. First, set the protected area: in the host computer software, set the protected area coordinates (Xmin, Ymin, Xmax, Ymax) and the safety distance threshold [0.1m, 10m]. Second, set the encoder parameters: in the host computer software, set the encoder pulse ratio [10, 100]. Then, set the safety parameters: in the host computer software, set the OSSD output mode parameters. Finally, serialize the configuration: the host computer software serializes the configuration parameters into binary format. Step 32: Configuration verification. The system has 79 built-in TÜV verification rules, which are verified item by item before the configuration is issued. First, encoder pulse ratio range verification: verify whether the encoder pulse ratio is within the range of [10, 100]; second, EDM. OSSD interlock verification: Verify whether the interlock relationship between EDM and OSSD is correct; then, protection area rationality verification: verify whether the coordinates of the protection area are reasonable and whether they are greater than the measurement range of the lidar; finally, safety distance threshold range verification: verify whether the safety distance threshold is within the range of [0.1m, 10m]. Verification method: Item-by-item verification is performed, and only if all items pass can the data be distributed; if any item fails the verification, distribution will be rejected and an error message will be displayed; Verification result recording: The verification results will be recorded in a log file, including the verification time, verification rules, and verification result information; Step 33: Configuration distribution. After the configuration verification is successful, the configuration parameters are distributed to the LiDAR via TCP protocol. First, the host computer packages the configuration parameters into a binary format, including the configuration parameters and a CRC-16 / Modbus checksum. Second, the host computer establishes a connection with the LiDAR via TCP protocol, port 1002. Then, the host computer sends the configuration parameters to the LiDAR via the TCP connection. Finally, the LiDAR receives the configuration and returns an acknowledgment message. Step 34: Read back and compare. After the configuration is issued, read back the radar's internal configuration and compare it with the issued configuration. First, read back the configuration: read the configuration parameters from the internal Flash memory of the LiDAR; second, compare item by item: compare the issued configuration with the read configuration one by one; finally, judge the result: if the issued configuration is consistent with the read configuration, the configuration takes effect; if the issued configuration is inconsistent with the read configuration, an alarm is triggered and the error information is recorded in the log file.

5. The method according to claim 4, characterized in that, Step 4 includes: a. Design a dynamic pulse watchdog link using a 74123 monostable multivibrator, a 1MΩ timing resistor, a 1μF timing capacitor, and a 1s timeout. First, the processor outputs a watchdog toggle signal via GPIO, with a 128ms cycle and a 50% duty cycle. Second, the monostable multivibrator receives the watchdog signal; when a rising edge is detected, it outputs a high-level drv signal and starts timing. Then, timeout detection occurs: if no next rising edge is detected within the timeout period, the monostable multivibrator times out, and the drv signal goes low. Finally, a logic gate controls the output: the logic gate receives both the watchdog and drv signals and outputs a zero signal to control the safety output. b. The watchdog link works as follows: First, the processor continuously toggles the WatchDog signal every 128ms. Second, the monostable multivibrator is reset: the 74123 monostable multivibrator receives the WatchDog signal and resets its timer each time a rising edge is detected. Then, normal operation is checked: if the processor is working normally, the WatchDog signal continues to toggle, and the drv signal remains high. Next, fault detection occurs: if the processor fails, the WatchDog signal stops toggling, the monostable multivibrator times out, and the drv signal goes low. Finally, the safety output is turned off: after the logic gate detects that the drv signal has gone low, it outputs a 0 signal to turn off the safety output. c. Independent channel design: Four independent watchdog channels are designed, each channel independently monitors the security output; First, channel allocation: channels 1 and 3 are controlled by MCU-A, which monitors the outputs of OSSD1 and OSSD3; channels 2 and 4 are controlled by MCU-B, which monitors the outputs of OSSD2 and OSSD4. Second, independent operation: each channel operates independently without interference. Finally, fault isolation: when any channel detects a fault, the corresponding safety output of the current channel is automatically shut down.

6. The method according to claim 5, characterized in that, Step 5 includes: The safety control process is optimized to ensure a safety response time of less than 10ms, meeting the safety protection requirements of high-speed automated production lines. h. The safety control process is as follows: laser emission, echo reception, TDC time measurement, dual-channel comparison, area detection, independent voting, EN_O3 / O4 shutdown right, dynamic watchdog chain, OSSD output, and safety shutdown. Laser emission: 10-100ns, the laser emits a laser pulse; Echo reception: 1-10μs, the receiver receives the reflected laser light; TDC time measurement: 1-10μs, calculates the laser flight time; Dual-channel comparison: 10-50μs, compares data between the main channel and the monitoring channel; Area detection: 10-50μs, determines whether an object is in a danger zone; Independent voting: 10-100μs, two processors independently determine whether it is safe; EN_O3 / O4 shutdown right: 1-10μs, shuts down the safety output; Dynamic watchdog chain: 1-10μs, checks whether the processor is working properly; OSSD output: 1-10ms, outputs a safety signal; Safety shutdown: depends on external equipment; i. Optimized response time, with a security response time of less than 10ms; Signal acquisition stage: response time for laser emission, echo reception, and TDC time measurement is 20-120μs; signal processing stage: response time for dual-channel comparison, region detection, and independent voting is 30-200μs; output control stage: response time for EN_O3 / O4 shutdown rights, dynamic watchdog chain, and OSSD output is 2-20ms; total security response time is less than 10ms.

7. A secure lidar control system with dual processors and independent voting, characterized in that, The system is used to implement the dual-processor independent voting secure lidar control method as described in claim 1. The system adopts a four-layer architecture, which consists of a physical perception layer, a measurement processing layer, a security control layer, and an application configuration layer from bottom to top. The physical sensing layer is used to collect environmental data and includes a laser emitting module, a photoelectric receiving module, and a TDC time measurement module. The laser emitting module uses a 905nm laser diode to emit laser pulses through a constant current driving circuit. The pulse width is 10-100ns, the driving current is 0-100A, and the repetition frequency is 10-100kHz. The photoelectric receiving module uses an APD detector to convert the reflected laser into an electrical signal. The sensitivity is -65dBm, and the dynamic range is 40dB. The TDC time measurement module uses an MS1005 chip to measure the flight time of the laser from emission to reception with an accuracy of ±1mm. It is connected to the FPGA through an LVDS interface. The measurement processing layer is used to process the raw data, which includes a first FPGA and a second FPGA. The first FPGA adopts WIL5025-7I, which acquires TDC data, processes multi-echo signals, performs angle interpolation, and transmits the data through 8B10B encoding. The second FPGA uses WIL5025-7I to receive optical link data, perform frame synchronization processing, and distribute it to the two processors via the SPI interface. The security control layer is used for security decisions and includes a first processor and a second processor. The first processor uses a GD32H789, runs an RTX5 RTOS, and performs security logic processing, zone protection decisions, Ethernet gateway, and OSSD A-line driver. The second processor uses a GD32H789, runs a hyperloop, and performs redundant security logic, cross-checking, and OSSD B-line driver. The two processors perform independent calculations and cross-checking through mutual check frames. The application configuration layer is used for configuration and monitoring, and it includes host computer software; the host computer software is used to configure the protection zone, view real-time data, and record fault logs.

8. The system according to claim 7, characterized in that, The mutual inspection frame format includes: a 4-byte preamble, a 2-byte length, a 2-byte CRC-16, a 1-byte command type, a 1-byte subcommand, and an N-byte comparison field.