Computer hardware synchronization method

A hardware-based synchronization method using a configurable integrated circuit addresses the limitations of existing computer synchronization by enhancing accuracy and robustness through precise timing adjustments and reconfiguration capabilities.

FR3168999A1Pending Publication Date: 2026-05-29SAFRAN ELECTRONICS & DEFENSE (FR)

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
SAFRAN ELECTRONICS & DEFENSE (FR)
Filing Date
2024-11-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing computer synchronization mechanisms suffer from limited synchronization accuracy and robustness due to digital communication buses and latency variance, and they do not allow for reconfiguration of calculation cycles in the event of multiple failures.

Method used

A hardware-based synchronization method using a configurable integrated circuit, such as a field-programmable gate array (FPGA), to synchronize computers by detecting synchronization signals and adjusting calculation cycles based on predefined durations, ensuring higher accuracy and fault robustness.

Benefits of technology

The method achieves enhanced synchronization accuracy and fault tolerance by independently synchronizing computers without software instructions, allowing for reconfiguration in case of repeated failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Hardware synchronization method for computers. One aspect of the invention relates to a method, implemented by a synchronization device, for synchronizing a second computer with a first computer, the synchronization device being included in the second computer, the synchronization device being a configurable integrated circuit.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Hardware synchronization method for computers. TECHNICAL FIELD OF THE INVENTION

[0001] The technical field of the invention is that of the synchronization of computers.

[0002] The present invention relates in particular to a method of synchronizing one computer with another computer. TECHNOLOGICAL BACKGROUND OF THE INVENTION

[0003] The synchronicity of computing operations in a system comprising several computers is essential to ensure the cohesion and proper functioning of that system, for example, for reasons of fault robustness, data consolidation, or the availability of one or more applications of which multiple instances are running. Synchronizing the computers in a system makes it possible, in fact, to eliminate time phase shifts and clock biases between several computers. This is particularly true for a system such as an aircraft.

[0004] Software mechanisms for synchronizing computers are known, such as the one proposed by US patent 10528077B2. The drawback is that these mechanisms have limited synchronization accuracy due to the use of digital communication buses and the presence of a non-negligible latency variance (in English, "jitter").

[0005] Furthermore, these mechanisms have a limited synchronization performance due to the fact that they can only tolerate a certain number of temporal desynchronizations.

[0006] Furthermore, state-of-the-art mechanisms do not offer reconfiguration of the synchronization of a computer's calculation cycles, but rather take into account desynchronization when the computer is subject to more than one synchronization fault. State-of-the-art systems are therefore not robust in the event of multiple failures.

[0007] There is therefore a need for a mechanism for synchronizing computers with each other with improved robustness and accuracy compared to known approaches, while allowing the resynchronization of the calculation cycles of a computer in the event of multiple synchronicity failures. Summary of the invention

[0008] The invention offers a solution to the problems mentioned above, by allowing the synchronization of computers in a system via a mechanism implemented by an integrated circuit, therefore entirely hardware-based, and possibly reconfigurable.

[0009] A first aspect of the invention relates to a method, implemented by a synchronization device, for synchronizing a second computer with a first computer, the synchronization device being included in the second computer, the synchronization device being a configurable integrated circuit, the method comprising: • Initialize a new calculation cycle for the second computer, based on the detection of a synchronization signal associated with the first computer, the initialization taking place: • At the end of a current calculation cycle of the second computer when the synchronization signal associated with the first computer has been detected for less than a predefined duration at the end of the current calculation cycle; or • Upon detection of the synchronization signal associated with the first computer when said synchronization signal associated with the first computer is detected after the end of the current calculation cycle and before the end of a second predefined duration beginning at the end of the current calculation cycle; or • At the end of the second predefined duration starting at the end of the current calculation cycle when the synchronization signal associated with the first calculator is not detected before the end of the second predefined duration starting at the end of the current calculation cycle.

[0010] A "configurable integrated circuit" is defined as an integrated circuit that can be configured to perform any desired function, in particular, here, to implement the method according to the first aspect. The configurable integrated circuit can be any type of configurable integrated circuit, for example, a field-programmable gate array (FPGA).

[0011] The term "synchronization signal" refers to a signal indicating that the first computer has reached a specific instant during its operation. This specific instant is, for example, the beginning or end of a calculation cycle of the first computer. This signal can therefore take any form and be of any nature. Preferably, this signal is an electrical signal, for example, a binary signal, indicating that the first computer has reached the specific instant at which the second computer must synchronize. In other words, this synchronization signal opens a synchronization window between the first and second computers.

[0012] By "binary state" it is meant that when the state of this signal is equal to a first value, for example "0" or "low" or "FALSE" or other, the signal is not emitted or corresponds to an electrical signal of constant value zero; and that when the state If this signal is equal to a second value, for example "1" or "high" or "TRUE" or other, the signal is emitted or corresponds to an electrical signal of constant non-zero value, for example strictly greater than 0. The synchronization signal can thus appear as a square wave signal.

[0013] The term "associated with a computer" means that the synchronization signal corresponds to the computer to which it is associated, for example because it is emitted by a synchronization device of the computer in question.

[0014] The term "current" calculation cycle refers to a calculation cycle of the second computer that is in progress at the time the method is implemented according to the first aspect. The term "new" calculation cycle refers to the calculation cycle that directly follows the current calculation cycle; in other words, it is the calculation cycle of the second computer that follows the current calculation cycle. Each calculation cycle of the computer is, for example, a calculation cycle of a computing component of said computer, for example, a processor.

[0015] The term "end of a calculation cycle" refers to the instant following the completion of the calculation cycle in question, in terms of calculation cycle instructions. In other words, it is the instant at which the last instruction of the calculation cycle in question is completed.

[0016] The term "first predefined duration" refers to a duration determined before the implementation of the method according to the first aspect. This duration defines a tolerance margin for the detection of the synchronization signal relative to the end of the current calculation cycle of the second computer. This first predefined duration is, for example, proportional to a portion of a calculation cycle of the second computer, typically less than or equal to half a calculation cycle of the second computer.

[0017] The term "half-cycle of calculation" means a duration equal to half of a calculation cycle of the second computer.

[0018] The term "second predefined duration" refers to a predetermined duration, defined before the implementation of the method according to the first aspect, which serves as a time buffer at the end of the current calculation cycle to synchronize the second computer with the first computer. The second predefined duration is shorter than half the calculation cycle of the second computer. The duration of the second predefined duration is predetermined according to the application under consideration and the desired synchronization accuracy. Indeed, the longer this second predefined duration, the lower the synchronization accuracy, since the tolerance for a delay in detecting the synchronization signal is controlled by the definition of this second predefined duration. The second predefined duration corresponds to the duration of the synchronization window.

[0019] Thanks to the invention, it is possible to synchronize one computer with another computer, independently of software instructions (i.e. instructions written in a digital programming language), with higher synchronization accuracy and fault robustness than using a state-of-the-art mechanism (i.e., a mechanism based on software instructions). Synchronization accuracy depends, in particular, on the transmission delay of the synchronization signals, typically carried out via an Ethernet connection. A "failure" is defined as a lack of synchronization or a desynchronization of one computer with another.

[0020] In particular, the detection of the synchronization signal allows the second computer to initialize its new calculation cycle based on the operation of the first computer, via the detection of the synchronization signal associated with that first computer. The synchronization window of the second computer is here equal to the duration of the second predefined duration.

[0021] Advantageously, when the first and second computers are not perfectly synchronized, the proposed approach makes it possible, in particular, to force the second computer to wait for the first computer when the latter is behind the second computer. The delay corresponds to a synchronization delay at the start and / or end of the respective calculation cycles of the first and second computers. This waiting period is made possible by using the second predefined duration, which delays the initialization of the new calculation cycle of the second computer.

[0022] The proposed approach also makes it possible to force the second computer to trigger its new calculation cycle as soon as possible after the end of the current calculation cycle, thus avoiding a cumulative delay while waiting for the end of the second predefined duration. This immediate triggering is made possible by using the first predefined duration, during which detection of the synchronization signal is permitted.

[0023] Advantageously, it is possible to implement the method in a circular and repeated manner, that is, by implementing the method through the synchronization device of the first computer to synchronize it repeatedly with the second computer, concurrently with its repeated implementation by the second computer. This maintains the synchronization of the computers by making the faster one wait until the slower one finishes its calculation cycle, respecting a maximum delay defined by the second predefined duration.

[0024] By extension, the method can also be implemented by the synchronization device of several computers in a circular and repeated manner, so that each computer synchronizes with a different computer, thus forming a synchronization loop. The closed-loop implementation of the method for these several computers then makes it possible to guarantee the synchronization of the entire chain of calculations with higher synchronization accuracy and fault robustness than using a state-of-the-art mechanism.

[0025] Furthermore, the proposed approach is simple to implement since it only requires the use of a configurable integrated circuit capable, at a minimum, of detecting the synchronization signal and triggering the initiation of the new calculation cycle at the appropriate time, or even of counting down the time elapsed between the detection of the synchronization signal and the end of the current calculation cycle. The approach can also be combined with known computer synchronization techniques, typically based on software instructions.

[0026] Finally, the use of a configurable integrated circuit allows for reconfiguration of this circuit in the event of repeated failure of synchronization of the second computer with the first computer.

[0027] In addition to the characteristics just mentioned, the method according to the first aspect of the invention may have one or more complementary characteristics from among the following, considered individually or according to all technically possible combinations.

[0028] In one embodiment, the first computer is selected from a plurality of computers including the second computer, the first computer being considered as non-defective.

[0029] The term "failing" means that the computer in question is recognized as being out of sync with the second computer, for example because it has a delay in the execution of its instructions strictly greater than a predefined delay, or because of a loss of the synchronization signal, for example because the latter remains at the first value or the second value for more than one calculation cycle.

[0030] In one embodiment, the plurality of computers is ordered according to a predefined order, the second computer being the last computer of the plurality of computers according to the predefined order, the first computer being the computer of the plurality of computers which is, according to the predefined order, the first to be considered as non-defective.

[0031] The advantage of defining a synchronization order is to ensure that all the computers that are to be synchronized are synchronized in a closed loop according to the predefined order, since the computers will only synchronize with each other on the computers that are not faulty according to this order.

[0032] In one embodiment, a computer of the plurality of computers is considered to be non-faulty by the second computer when a synchronization signal associated with said computer is detected before the end of the second predefined duration starting at the end of each calculation cycle of the previous calculation cycles of the second computer.

[0033] In one embodiment, a computer in the plurality of computers is considered to be - faulty when said computer is considered to be faulty by at least one computer in the plurality of computers which are considered to be non-faulty.

[0034] In other words, the identification of a faulty computer is disseminated to the other computers, for example to their respective synchronization device, so as not to synchronize these other computers with this faulty computer.

[0035] These two embodiments also make it possible to guarantee that non-faulty computers will continue to synchronize with each other, while disconnecting from computers considered to be faulty.

[0036] In one embodiment, when the synchronization signal associated with the first computer is not detected before the end of the second predefined duration starting at the end of the current calculation cycle of the second computer, the first computer is considered by the second computer to be faulty.

[0037] Thus, when the synchronization signal is received after the second predefined duration or is not received at all, the first computer is identified as being out of sync, i.e., its delay is no longer within the tolerance margin set by the second predefined duration. This identification can be disseminated to the other computers so that they do not synchronize with this first computer, which is considered faulty.

[0038] In one embodiment, the synchronization signal associated with the first computer is emitted by a synchronization device of the first computer.

[0039] In one embodiment, the method further comprises: • At the end of the current calculation cycle, transmit a synchronization signal associated with the second computer to a third computer.

[0040] Thus, as soon as the end of the current calculation cycle of the second computer is reached, whether or not it is synchronized with the first computer, the synchronization signal associated with the second computer is sent to the third computer so that this third computer can carry out the synchronization procedure by implementing the method according to the first aspect.

[0041] In one embodiment, the second computer is considered to be faulty, the second computer being considered to be faulty when the synchronization signal associated with the second computer is not detected before the end of the second predefined duration starting at the end of a current calculation cycle of the third computer, the method comprising: • Resynchronize the second computer by: Detection of a resynchronization command; • Resetting the current calculation cycle of the second computer when a synchronization signal associated with the third computer is detected before the end of a third predefined duration elapsed since the detection of the resynchronization command.

[0042] It is therefore possible to resynchronize the second computer when it is faulty by forcing the reset of its current calculation cycle.

[0043] A second aspect of the invention relates to a method for reprogramming a synchronization device of a computer, the method comprising reprogramming said synchronization device in the event of repeated synchronization failure of said computer, the reprogramming comprising configuring the synchronization device to implement a synchronization method according to the first aspect.

[0044] The term "synchronization failure" refers to the inability of the second computer to synchronize with the first computer using the method described in the first aspect. This therefore constitutes a synchronization failure, the cause of which can be of any origin.

[0045] Thanks to the method according to this second aspect, it is possible to reconfigure the synchronization device to correct any configuration errors, in order to reconfigure it again to implement the method according to the first aspect.

[0046] A third aspect of the invention relates to a computer comprising a synchronization device adapted to implement the method according to the first aspect, the synchronization device being a programmable logic circuit.

[0047] In one embodiment, the calculator according to the third aspect is configured to implement the reprogramming method according to the second aspect.

[0048] A fourth aspect of the invention relates to a system comprising a set of computers, each computer in the set of computers being according to the third aspect.

[0049] In one embodiment, each synchronization device of each computer in the set of computers concurrently implements the method according to the first aspect.

[0050] A fifth aspect of the invention relates to a computer program product comprising instructions which, when the program is executed on a computer, lead the computer to implement the steps of the method according to the first and / or the second aspect.

[0051] A sixth aspect of the invention relates to a computer-readable recording medium comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method according to the first and / or the second aspect.

[0052] The invention and its various applications will be better understood upon reading the following description and examining the accompanying figures. BRIEF DESCRIPTION OF THE FIGURES

[0053] The figures are presented for illustrative purposes only and are in no way limiting of the invention. • The [Fig. 1] is a synoptic diagram illustrating the sequence of steps of a method according to the invention. • Fig. 2 is a schematic representation of different cases of synchronization of a computer on a synchronization signal. • Fig. 3 is a schematic representation of another case of synchronizing a computer to a synchronization signal. • Fig. 4 is a schematic representation of another case of synchronizing a computer to a synchronization signal. • Fig. 5 is a schematic representation of a computer resynchronization case. • Fig. 6 is a schematic representation of an implementation of the synchronization of computers with each other according to the method of Fig. 1. DETAILED DESCRIPTION

[0054] Unless otherwise specified, the same element appearing on different figures has a unique reference.

[0055] The invention relates to a method for synchronizing a second computer with a first computer. This method thus makes it possible to synchronize the second computer with the first computer. In particular, this method makes it possible to synchronize their respective operations. Preferably, these two computers have the same characteristics, i.e., are of the same model.

[0056] The method is implemented by a synchronization device of the second computer. This synchronization device is a configurable integrated circuit, for example a programmable logic circuit or FPGA (Field-Programmable Gate Array).

[0057] Synchronization method 100 includes, in connection with [Fig. 1], at least one step 140 for initializing a new calculation cycle of the second computer. Indeed, when method 100 is implemented, the second computer is in a current calculation cycle, i.e., in execution, and it is desired to synchronize the next calculation cycle of this second computer with the operation of the first computer, for example, with the beginning of one of the calculation cycles of the first computer.

[0058] To this end, the next calculation cycle of the second computer, called the new calculation cycle, is initialized, at step 140, according to a synchronization signal associated with the first computer. In particular, depending on the detection of this signal, especially its detection time by the synchronization device of the second computer, the initialization of this new calculation cycle of the second computer may be delayed.

[0059] Three scenarios are distinguished: • In the first case, the synchronization signal is detected for less than a predefined initial duration at the end of the current calculation cycle; • In the second case, the synchronization signal is detected after the end of the current calculation cycle but before the end of a second predefined duration starting at the end of the current calculation cycle; • In the third case, the synchronization signal is not received before the end of the second predefined period beginning at the end of the current calculation cycle.

[0060] The synchronization device is therefore configured to count down the time elapsed from the detection of the synchronization signal associated with the first calculator until the end of the current calculation cycle and / or until the end of the second predefined period beginning at the end of the current calculation cycle. The synchronization device is also configured to count down the time elapsed from the end of the current calculation cycle and the end of the second predefined period beginning at the end of the current calculation cycle.

[0061] In the first case, in relation to [Fig. 2], the initiation of the next calculation cycle takes place at the end of the current calculation cycle. Therefore, there is no delay in triggering this new calculation cycle after the current calculation cycle.

[0062] The first predefined duration is predefined by an operator, supervisor, or user of the computer, depending on the desired synchronization accuracy between the computers. The first predefined duration is, for example, less than or equal to half a calculation cycle of the second computer, for example, less than or equal to one-third of a calculation cycle, or even less than or equal to one-quarter of a calculation cycle of that second computer.

[0063] Figure 2 illustrates three configurations: • On [Fig.2] a), the synchronization signal associated with the first computer “Signal_l” is detected at the beginning of the first predefined duration “dl”, here equal to half a calculation cycle of the second computer, before the end “i_end” of the current calculation cycle “i”; • On [Fig.2] b), the synchronization signal is detected during the first predefined duration dl. • In [Fig.2] c), the synchronization signal is detected shortly before the end of the current calculation cycle.

[0064] In these three configurations, the initialization of the new calculation cycle "i+1" is triggered at the end of the current calculation cycle i.

[0065] In the second case, related to [Fig. 3], the initialization of the next calculation cycle takes place between the end of the current calculation cycle and the end of a second predefined period following the end of the current calculation cycle. The next calculation cycle is therefore delayed, possibly up to a period equal to the second predefined period, until it detects the synchronization signal associated with the first calculator.

[0066] The second predefined duration is predefined by the supervisor or the computer user, depending on the desired synchronization accuracy between the computers. The second predefined duration is, for example, less than or equal to 200 ps, ​​or even less than or equal to 150 ps, ​​or less than or equal to 100 ps, ​​or even less than or equal to 50 ps.

[0067] Figure 3 illustrates the triggering of the new calculation cycle i+1 on detection of the synchronization signal associated with the first computer Signal_l, during the second predefined duration "d2", starting at the end i_end of the current calculation cycle i.

[0068] In the third case, related to [Fig. 4], the initiation of the next calculation cycle takes place at the end of the second predefined duration, which begins at the end of the current calculation cycle. The next calculation cycle is therefore delayed by the second predefined duration.

[0069] Figure 4 illustrates the triggering of the new calculation cycle i+1 at the end of the second predefined duration d2, starting at the end i_end of the current calculation cycle i, whether or not the synchronization signal Signal_l associated with the first calculator is detected after this second predefined duration d2.

[0070] In other words, the initialization of the new calculation cycle of the second computer takes place: • At the end of the current calculation cycle of the second computer, when the synchronization signal associated with the first computer has been detected for less than a predefined duration at the end of the current calculation cycle; or • Upon detection of the synchronization signal associated with the first computer when said synchronization signal associated with the first computer is detected after the end of the current calculation cycle and before the end of the second predefined duration beginning at the end of the current calculation cycle; or • At the end of the second predefined duration starting at the end of the current calculation cycle when the synchronization signal associated with the first calculator is not detected before the end of the second predefined duration starting at the end of the current calculation cycle.

[0071] In one embodiment, method 100 is implemented at each calculation cycle of the second computer.

[0072] In one embodiment, the synchronization signal associated with the first computer is emitted by a synchronization device of the first computer or by the first computer directly, for example under the effect of an emission command issued by the synchronization device of the first computer to that first computer, typically at the end of a current calculation cycle of the first computer.

[0073] Generally, a synchronization signal associated with a computer is emitted by a synchronization device of that computer or by that computer in question, for example under the effect of an emission command issued by the synchronization device of that computer to that computer, typically at the end of a current calculation cycle of that computer.

[0074] In a particular case, only the first and second computers need to be synchronized. In this case, it is also possible to implement method 100 concurrently to synchronize the first computer with the second computer, i.e., on the second computer, thus forming a closed synchronization loop between these two computers. Method 100 is then implemented by both the synchronization device of the first computer and the synchronization device of the second computer.

[0075] In this embodiment, when method 100 is implemented by the synchronization device of the first computer, the synchronization signal associated with the second computer, used to synchronize the first computer to the second computer, is emitted by the synchronization device of the second computer.

[0076] Typically, at the initialization of the joint synchronization process, the first computer may find itself in a situation corresponding to [Fig.2] b) or in the situation corresponding to [Fig.3], and the second computer may find itself in the situation corresponding to [Fig.3] or in the situation corresponding to [Fig.2] b), then, as the respective calculation cycles of these two computers progress, they will converge towards a quasi-synchronized state, corresponding to the situation in [Fig.2] a).

[0077] In a more general embodiment, several computers, including the first and second computers, need to be synchronized with each other. The idea is then to synchronize each computer with another computer so that each computer synchronizes with a different computer. Preferably, this synchronization is done in a closed loop.

[0078] Thus, in this embodiment, the first computer can be selected from among a plurality of computers, including the second computer. The selection of this computer is made on the condition that the first computer is considered non-faulty, that is, that it is not out of sync with the second computer and / or with any other computer from the plurality of computers. It should be noted that the second computer is, by definition, synchronized with itself.

[0079] In this embodiment, method 100 then includes a step 120 of selecting the first computer from among the plurality of computers, the first computer being a non-failing computer from the plurality of computers.

[0080] In one embodiment, the plurality of computers is ordered according to a predefined order. The predefined order is, for example, predefined by the supervisor or the user, depending on the application case, or by any other means.

[0081] In this embodiment, the first computer is the one that is the first non-faulty computer in the predefined order. In other words, the first computer is the computer among the plurality of computers that is, according to the predefined order, the first to be considered non-faulty.

[0082] When method 100 is concurrently implemented on several computers in the plurality of computers, it is possible that, depending on the computer considered, the predefined order may differ from that used to synchronize the other computers. This predefined order may also be the same for all computers or be different for all computers.

[0083] In one embodiment, the predefined order used to implement method 100 in order to synchronize the first computer corresponds to the predefined order used to implement method 100 in order to synchronize the second computer to which an offset of one computer is applied.

[0084] In one embodiment, considering that the plurality of calculators comprises P calculators, the predefined order for the p-th calculator is {p-1, p-2, ...,1,P, Pl, P-2, ..., p+1] and the predefined order for the p+l-th calculator is {p, p-1, p-2, .. .,1,P, Pl, P-2, ..., p+2], and the predefined order for the pl-th calculator is {p-2, p-3, ...,1,P, Pl, P-2, ..., p+1, p}.

[0085] In this respect, Figure 6 illustrates this closed-loop synchronization principle using four computers C2, C3, and C4. In Figure 6(a), each computer is synchronized with the one preceding it, in ascending order from 1 to 4. Computer C1 is therefore synchronized with computer C4, computer C2 is synchronized with computer C3, computer C3 is synchronized with computer C2, and computer C4 is synchronized with computer C3. In Figure 6(b), computer C3 is considered to be faulty by computer C4. Computer C4 is then synchronized with computer C2, and computer C3 continues to synchronize with the calculator C2 since this calculator is not considered to be faulty by calculator C3.

[0086] In one embodiment, when the first computer is the second computer, the initialization of the new calculation cycle of the second computer is performed at the end of the current calculation cycle of that second computer. Alternatively, the initialization of the new calculation cycle is, in this particular case, performed at the end of the second predefined duration beginning at the end of the current calculation cycle.

[0087] In one embodiment, a computer in the plurality of computers is considered by at least one other computer in the plurality of computers, for example by the second computer, to be faulty when that computer is out of sync with the second computer. In particular, that computer is considered to be non-faulty when a synchronization signal associated with said computer is detected before the end of the second predefined duration beginning at the end of each calculation cycle of the preceding calculation cycles of at least one other computer in the plurality of computers, typically the second computer.This computer is therefore considered to be faulty when the synchronization signal associated with said computer is not received or is received after the end of the second predefined duration starting at the end of at least one of the previous calculation cycles of at least one other computer in the plurality of computers (for example, the second computer).

[0088] The term "previous" calculation cycles means all calculation cycles that preceded, in chronological order, the current calculation cycle and during which method 100 was implemented (possibly only one, part or all of the previous calculation cycles, depending on whether method 100 is implemented in only one, part or each calculation cycle of the second computer).

[0089] In one embodiment, the computers of the plurality of computers can communicate data with each other, in particular data indicating that a given computer considers another computer to be faulty. This information can be communicated between the computers themselves or between the synchronization devices of the computers. Thus, if one of the computers, for example the second computer, considers one of the other computers to be faulty, then this computer considered faulty by the second computer is also considered faulty by the other computers.

[0090] In this variant, a computer in the plurality of computers is, in addition, considered to be non-failing when said computer is considered non-failing by all other computers in the plurality of computers, preferably considered as such by all computers in the plurality of computers which are considered to be non-failing.

[0091] In other words, in this variant, a computer is considered to be faulty if at least one computer, preferably itself non-faulty, of the plurality of computers considers it to be faulty. In particular, a computer is considered to be non-faulty by another computer when that other computer has detected a synchronization signal associated with said computer before the end of the second predefined duration beginning at the end of each calculation cycle of the preceding calculation cycles of that other computer (possibly only one, part or all of the preceding calculation cycles, depending on whether method 100 is implemented on only one, part or each calculation cycle of the second computer).

[0092] That is to say, a computer in the plurality of computers is considered to be faulty when said computer is considered to be faulty by at least one computer in the plurality of computers which is considered to be non-faulty.

[0093] In one embodiment, a computer is also, or alternatively, considered to be faulty when the frequency of the synchronization signal differs from the expected synchronization frequency for that signal. Indeed, a synchronization device expects to receive a signal of a certain frequency to trigger the synchronization of the computer to which it is associated, and when this frequency is not the expected one, then the computer corresponding to that synchronization signal is considered to be faulty. For example, when a difference between the frequency of the synchronization signal and the expected frequency for that signal exceeds a predefined threshold, then the computer associated with that synchronization signal is considered to be faulty.

[0094] The predefined threshold is, for example, predefined by the supervisor or the user, in any known way, for example on the basis of their knowledge in the matter or on technical data, typically supplied by the manufacturer of the synchronizing device and / or the computer.

[0095] In one embodiment, a computer is also, or alternatively, considered to be faulty by at least one other computer in the plurality of computers, for example by the second computer, when the synchronization signal associated with that computer is detected too early, in this case before the end of the current calculation cycle of the computer including the synchronization device that performs the detection of said synchronization signal. In particular, the computer associated with the synchronization signal is considered to be faulty when it is detected before a duration ending at the end of the current calculation cycle. This duration corresponds to a margin of error due to a clock bias of the computer including the synchronization device that performs the detection. The margin of error is typically on the order of a microsecond, for example less than or equal to 10 ps, ​​or less than or equal to 8 ps, or even less than or equal to 5 ps, or even less than or equal to 2 ps.

[0096] In one embodiment, method 100 also includes a detection step 130 of the synchronization signal associated with the first computer. The detection can be performed via any known technique, such as by detecting a change in value at an input of the synchronization device, the input adapted to receive the synchronization signal associated with the first computer. For example, when the synchronization signal is emitted by the first computer itself or the synchronization device of said first computer, the synchronization device of the second computer is connected, typically an input of said device of the second computer is connected, to the first computer or to its synchronization device, typically to an output of said second computer or its synchronization device.

[0097] In the example shown in Figures 2 to 4, the synchronization signal Signal_l is a binary state signal, where the input of the synchronization device of the second module does not detect the synchronization signal, which is then in an inactive state, until it transitions to an active state, for example, a high state, or TRUE, or 1, or another. At the end of a synchronization time window, corresponding to the duration during which the synchronization signal Signal_l is in the active state, the synchronization signal Signal_l returns to the inactive state. In other words, the synchronization signal Signal_l is a square wave signal, with a duration equal to the duration of the synchronization time window.

[0098] In one embodiment, it is possible that the synchronization signal associated with the first computer may not be detected in time by the second computer, that is, before the end of the second predefined period beginning at the end of the current calculation cycle. It is indeed possible that the first computer may become desynchronized, that this signal may be detected after the second predefined period, or even that it may not be detected at all (possibly because it was not emitted), whatever the cause. In this case, the first computer is considered to be faulty.

[0099] In other words, when the synchronization signal associated with the first computer is not detected before the end of the second predefined duration starting at the end of the current calculation cycle of the second computer, the first computer is considered to be faulty.

[0100] Method 100 can thus include a step 150 of determining that the first computer is faulty, when the synchronization signal associated with the first computer is not detected before the end of the second predefined duration starting at the end of the current calculation cycle of the second computer.

[0101] In one embodiment, as shown in Figures 2 to 5, Method 100 also includes a step 160 of transmitting a synchronization signal "Signal_2" associated with the second computer. This Signal_2 is transmitted to a third computer, for example, to the synchronization device of that third computer. This synchronization signal, Signal_2, can, for example, be used to synchronize the third computer with the second computer during the implementation of Method 100 by the synchronization device of the third computer.

[0102] In one embodiment, the third computer is a computer of the plurality of computers, for example, it is the computer which precedes the second computer in the predefined order (corresponding to the predefined order in the implementation of method 100 to synchronize the second computer with the first computer).

[0103] The emission is, for example, implemented at the end of the current calculation cycle of the second computer.

[0104] In one embodiment, the second computer may become desynchronized from the third computer, which may be the first computer. In this case, the second computer can be resynchronized by detecting a resynchronization command and resetting the current calculation cycle of the second computer. This reset is performed upon detection of a synchronization signal associated with the third computer, provided that this detection occurs before the end of a third predefined period elapsed since the detection of the resynchronization command.

[0105] In other words, in this embodiment, method 100 also includes a step 170 for resynchronizing the second computer when the second computer is considered to be faulty. The second computer is considered to be faulty when the synchronization signal associated with the second computer is not detected before the end of the second predefined duration beginning at the end of a current calculation cycle of the third computer. The third computer may, in some cases, be the first computer.

[0106] In connection with [Fig. 5], this resynchronization step 170 includes a substep 171 for detecting the synchronization command "Command". The synchronization command "Command" can be generated by any technique known per se (the command is represented here by a transition to a high state in the timing diagram corresponding to the "Command" line). For example, this synchronization command "Command" can be issued by the computer itself, by another computer from the plurality of computers, or by a third-party device, for example, a computer supervising the actions of the computers from the plurality of computers.

[0107] The resynchronization step 170 also includes a substep 172 of resetting the current calculation cycle i of the second computer when the synchronization signal Signal_3 associated with the third computer is detected before the end of a third predefined duration "d3" elapsed since the detection of the resynchronization command.

[0108] The third predefined duration d3 is defined before the implementation of method 100, for example by the supervisor or the user, and / or via any known technique. The third predefined duration is, for example, equal to or less than the duration of a calculation cycle of the second computer.

[0109] This step 170 can be implemented either before or after step 140 of initializing the new calculation cycle of the second computer.

[0110] In one embodiment, method 100 also includes an initialization step 110 of the synchronization method. At this step, the first and second computers are defined as non-faulty. If applicable, the first computer of the plurality of computers is, in the predefined order, defined as the first computer.

[0111] Another aspect of the invention relates to a method for reprogramming a synchronization device of a computer, for example, resynchronizing the synchronization device of a second computer, particularly when this synchronization device is a programmable logic circuit or FPGA. The reprogramming is implemented when the computer in question, for example the second computer, fails several times in succession to synchronize with a computer in the plurality of computers, for example the first computer, regardless of the origin of this synchronization failure.

[0112] This method therefore includes reprogramming said synchronization device in the event of repeated synchronization failure of said control unit. The reprogramming includes configuring the synchronization device to implement synchronization method 100.

[0113] In one embodiment, the second predefined duration is predefined to account for a margin of error, typically on the order of microseconds, for example less than or equal to 10 ps, ​​or even less than or equal to 8 ps, or even less than or equal to 5 ps, or even less than or equal to 2 ps. This makes it possible to account for a possible clock bias of the second computer. For example, the second duration could be 55 ps, including 5 ps for the margin of error.

[0114] In one embodiment, the first predefined duration, the second predefined duration and / or the third predefined duration are stored in a memory of the synchronization device of the second computer.

[0115] In an alternative embodiment: • the first predefined duration is the same or is different for all or part of the calculators of the plurality of calculators; • the second predefined duration is the same or different for all or some of the computers in the plurality of computers; and / or • the third predefined duration is the same or is different for all or part of the calculators of the plurality of calculators.

[0116] Another aspect of the invention relates to a computer, which includes a synchronizing device adapted to implement the synchronization method 100. The synchronizing device is, for example, a programmable logic circuit or FPGA. The computer can be any known type of computer capable of understanding the synchronizing device.

[0117] In other words, the synchronization device is configured, for example programmed, to implement method 100.

[0118] In one embodiment, the computer is configured to implement the reprogramming method for the synchronization device it includes.

[0119] Another aspect of the invention relates to a system comprising a set of computers, in which each computer in the set of computers is as mentioned above.

Claims

Demands

1. Method (100), implemented by a synchronization device, of synchronizing a second computer with a first computer, the synchronization device being included in the second computer, the synchronization device being a configurable integrated circuit, the method comprising: - Initializing (140) a new calculation cycle of the second computer, based on the detection of a synchronization signal associated with the first computer, the initialization taking place: • At the end of a current calculation cycle of the second computer when the synchronization signal associated with the first computer has been detected for less than a first predefined duration at the end of the current calculation cycle;or • Upon detection of the synchronization signal associated with the first computer when said synchronization signal associated with the first computer is detected after the end of the current calculation cycle and before the end of a second predefined duration starting at the end of the current calculation cycle; or • At the end of the second predefined duration starting at the end of the current calculation cycle when the synchronization signal associated with the first computer is not detected before the end of the second predefined duration starting at the end of the current calculation cycle.

2. Method (100) according to the preceding claim, wherein the first computer is selected (120) from a plurality of computers including the second computer, the first computer being considered as non-defective.

3. Method (100) according to claim 2, wherein the plurality of computers is ordered according to a predefined order, the second computer being the last computer of the plurality of computers according to the predefined order, the first computer being the computer of the plurality of computers which is, according to the predefined order, the first to be considered as non-defective.

4. Method (100) according to any one of claims 1 to 3, wherein a computer of the plurality of computers is considered by the second computer to be non-faulty when a synchronization signal associated with said computer is detected (130) before the end of the second predefined duration beginning at the end of each calculation cycle of the previous calculation cycles of the second computer.

5. Method (100) according to any one of the preceding claims, wherein, when the synchronization signal associated with the first computer is not detected before the end of the second predefined duration starting at the end of the current calculation cycle of the second computer, the first computer is considered (150) by the second computer to be faulty.

6. Method (100) according to claim 5, wherein a computer in the plurality of computers is considered to be faulty when said computer is considered to be faulty by at least one of the computers in the plurality of computers which are considered to be non-faulty.

7. Method (100) according to any one of the preceding claims, further comprising: - Emitting (160), at the end of the current calculation cycle, a synchronization signal associated with the second computer to a third computer.

8. Method (100) according to the preceding claim, wherein the second computer is considered to be faulty, the second computer being considered to be faulty when the synchronization signal associated with the second computer is not detected before the end of the second predefined time starting at the end of a current calculation cycle of the third computer, the method comprising: - Resynchronizing (170) the second computer by: • Detection of a resynchronization command; • Resetting the current calculation cycle of the second computer when a synchronization signal associated with the third computer is detected before the end of a third predefined time elapsed since the detection of the resynchronization command.

9. A method for reprogramming a synchronizing device of a computer, the method comprising reprogramming said synchronizing device in the event of repeated synchronization failure of said computer, the reprogramming comprising configuring the synchronizing device to implement a synchronization method (100) according to any one of claims 1 to R

10. 1 a O. Calculator comprising a synchronizing device adapted to implement method (100) according to any one of claims 1 to 8, the synchronizing device being a programmable logic circuit.

11. Calculator according to claim 10, configured to implement a reprogramming method according to claim 9.

12. System comprising a plurality of computers, each computer of the plurality of computers being defined according to any one of claims 10 to 11.