Information processing apparatus, protection control device, and watch dog timer operating method

The information processing device addresses the challenge of detecting abnormal states in multi-core CPUs by using a watchdog timer clear signal generation unit and detection unit, ensuring real-time operation and reliability in protection and control devices.

JP2025079264APending Publication Date: 2025-05-21HITACHI LTD

Patent Information

Application Number
JP2023191853
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-09
Publication Date
2025-05-21

AI Technical Summary

Technical Problem

Existing technologies for detecting abnormal states in multi-core CPUs used in protection and control devices are not suitable for real-time operation and device reliability, particularly when virtualization is applied.

Method used

An information processing device with a watchdog timer clear signal generation unit that monitors periodic clear signals from multiple CPUs or cores and outputs a timer clear signal when a predetermined number of normal signals are received, and a watchdog timer detection unit that sends a detection signal upon continued abnormal state.

Benefits of technology

Effectively detects abnormal states of calculation processing units, ensuring real-time operation and device reliability in protection and control devices, even under virtualization scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025079264000001_ABST
    Figure 2025079264000001_ABST
Patent Text Reader

Abstract

To favorably detect an abnormal state of an arithmetic processing unit.SOLUTION: An information processing apparatus includes: an arithmetic processing unit that includes one or more CPUs each including one or more cores; a watch dog timer clear signal generation unit that outputs a first timer clear signal on the basis of the number of clear signals in which a change in a value is normal, of a plurality of clear signals periodically output from the arithmetic processing unit; and a first watch dog timer detection unit that sends a first watch dog detection signal on the basis of an abnormal state of the first timer clear signal, and is provided in hardware in an IC common to the arithmetic processing unit. Output sources of the plurality of clear signals include at least one of: when the arithmetic processing unit includes a plurality of CPUs, the plurality of CPUs; when at least one of the one or more CPUs includes a plurality of cores, the plurality of cores in the CPU; and a plurality of tasks processed in the arithmetic processing unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an information processing device, a protection and control device, and a watchdog timer operation method. [Background technology]

[0002] In information processing devices and protection control devices, the performance of arithmetic processing units including a CPU (Central Processing Unit) has improved, and configurations are known in which not only the operating clock has been improved but also multiple CPUs are employed in the device to distribute processing. In addition, WDT (WatchDog Timer) detection is known as a method for detecting abnormal states such as CPU runaway.

[0003] In addition, digital protection and control systems are beginning to be applied, in which the functions of conventional protection and control systems are divided into MUs (Merging Units) and protection and control devices, and these are connected by a transmission network. IEC (International Electrotechnical Commission) 61850 is known as the international standard for this configuration.

[0004] In a digital protection and control system based on IEC61850, the MU acquires the electrical quantities (current and voltage) of the power system (hereafter, current and voltage are referred to as electrical quantities). The MU performs A / D (Analog to Digital) conversion of the acquired electrical quantity signals, and transmits the A / D converted digital signals to the protection and control device via process bus transmission.

[0005] Background art of this technical field includes JP 2011-2993 A (Patent Document 1) and JP 2021-149436 A (Patent Document 2).

[0006] Patent Document 1 states that "The WDT monitoring device has a reset flag for each CPU that resets the WDT. If the reset flag is not on, this indicates that an abnormality has occurred in that CPU" (see paragraph

[0016] ).

[0007] Patent document 1 also states that "When the standby flag is on (1), it indicates that the CPU is in standby mode, and when the reset flag is on (1), it indicates that the CPU is operating normally" (see paragraph

[0022] ).

[0008] Furthermore, Patent Document 1 states that "the WDT reset signal generating unit generates a reset signal and supplies it to the WDT when all of the CPUs are normal, and does not generate a reset signal when any one or more of the CPUs are not normal" (see paragraph

[0023] ).

[0009] Furthermore, Patent Document 1 states, "Therefore, the OR circuit and the AND circuit are logic circuit representations of the WDT reset signal generating unit. The AND circuit outputting "1" corresponds to the WDT reset signal generating unit outputting a reset signal" (see paragraph

[0040] ).

[0010] Furthermore, Patent Document 2 states that "the controller of the image forming apparatus includes a main CPU and a sub CPU. The controller further includes a first WDT circuit and a second WDT circuit that detect abnormal operation of the sub CPU. The image forming apparatus extends the second WDT reset time to a predetermined time and executes a reboot process of the controller in accordance with a first interrupt signal output from the first WDT circuit based on a timeout of the first WDT reset time. The image forming apparatus also executes a system reset process in accordance with a second interrupt signal output from the second WDT circuit based on a timeout of the extended second WDT reset time" (see abstract). [Prior art documents] [Patent documents]

[0011] [Patent Document 1] JP 2011-2993 A [Patent Document 2] JP 2021-149436 A Summary of the Invention [Problem to be solved by the invention]

[0012] The technology described in Patent Document 1 aggregates reset flags from multiple CPUs using AND circuits and OR circuits and uses them for WDT detection, but there must be a timing at which all reset flags from each CPU become 1, which poses the problem of the need to adjust the timing between each CPU.

[0013] Moreover, real-time operation and device reliability are required for the protection and control device. Therefore, when a multi-core CPU mounted on a system-on-chip is used for the protection and control device, particularly when virtualization is applied to execute a bare metal application for each core, it is desirable to execute WDT detection for each core. On the other hand, the technology described in Patent Document 1 has a problem in that it does not provide a WDT detection configuration suitable for the above-mentioned protection and control system.

[0014] Therefore, one aspect of the present invention is to effectively detect an abnormal state of a calculation processing unit. [Means for solving the problem]

[0015] In order to solve the above problem, one aspect of the present invention employs the following configuration: An information processing device for detecting an abnormality in a processing unit includes the processing unit, a watchdog timer clear signal generation unit that receives a plurality of clear signals periodically output from the processing unit, monitors whether changes in values ​​of the plurality of clear signals are normal or abnormal, and outputs a first timer clear signal when the number of the clear signals whose values ​​are normal reaches a predetermined number, and a first watchdog timer detection unit that receives the first timer clear signal and sends a first watchdog detection signal when an abnormal state of the first timer clear signal continues for a first predetermined time, the processing unit includes one or more CPUs, each of the one or more CPUs includes one or more cores, and the output sources of the plurality of clear signals input to the watchdog timer clear signal generation unit include a plurality of CPUs when the processing unit includes a plurality of CPUs, a plurality of cores in the CPU when at least one of the one or more CPUs includes a plurality of cores, and at least one of a plurality of tasks processed in the processing unit, and the watchdog timer clear signal generation unit is provided in hardware in an IC common to the processing unit.

[0016] Moreover, one aspect of the present invention employs the following configuration: A protection control device that detects an abnormality in an arithmetic processing unit includes the arithmetic processing unit, the arithmetic processing unit includes one or more CPUs, each of the one or more CPUs includes one or more cores, the protection control device divides a software process for realizing a protection control function into a plurality of processes, and assigns the divided plurality of software processes to any of a plurality of CPUs when the arithmetic processing unit includes a plurality of CPUs, a plurality of cores in a CPU when at least one of the one or more CPUs includes a plurality of cores, or a plurality of tasks processed in the arithmetic processing unit for distributed execution, a watchdog timer clear signal generation unit that receives a plurality of clear signals periodically output from the plurality of software processes, monitors whether changes in values ​​of the plurality of clear signals are normal or abnormal, and outputs a first timer clear signal when the number of the clear signals whose value changes are normal reaches a predetermined number, and a first watchdog timer detection unit that receives the first timer clear signal and outputs a first watchdog detection signal when an abnormal state of the first timer clear signal continues for a first predetermined time, the watchdog timer clear signal generation unit being provided in hardware in an IC common to the arithmetic processing unit.

[0017] Moreover, one aspect of the present invention employs the following configuration: In a watchdog timer operation method for detecting an abnormality in an arithmetic processing unit included in an information processing device, the information processing device includes the arithmetic processing unit, a watchdog timer clear signal generation unit that receives a plurality of clear signals periodically output from the arithmetic processing unit, monitors whether changes in values ​​of the plurality of clear signals are normal or abnormal, and outputs a first timer clear signal when the number of the clear signals whose value changes are normal reaches a predetermined number, a first watchdog timer detection unit that receives the first timer clear signal and sends a first watchdog detection signal when an abnormal state of the first timer clear signal continues for a first predetermined time, a second watchdog timer detection unit that receives one or more clear signals periodically output from the arithmetic processing unit, and sends a second watchdog detection signal when an abnormal state of the input one or more clear signals continues for a second predetermined time shorter than the first predetermined time, and a restart of the information processing device in response to the second watchdog detection signal. and a restart information recording unit that records information related to the second watchdog detection signal, wherein the arithmetic processing unit includes one or more CPUs, each of the one or more CPUs including one or more cores, and sources of the multiple clear signals input to the watchdog timer clear signal generating unit include multiple CPUs when the arithmetic processing unit includes multiple CPUs, multiple cores in a CPU when at least one of the one or more CPUs includes multiple cores, and at least one of multiple tasks processed in the arithmetic processing unit, and the watchdog timer clear signal generating unit is provided in hardware within an IC common to the arithmetic processing unit, and the watchdog timer operation method includes acquiring information related to the restart recorded in the restart information recording unit, determining whether the acquired information related to the restart satisfies a predetermined condition, and if it is determined that the predetermined condition is satisfied, disabling the restart of the information processing device based on the output of the second watchdog detection signal. Effect of the Invention

[0018] According to one aspect of the present invention, it is possible to effectively detect an abnormal state of a calculation processing unit.

[0019] Problems, configurations and effects other than those described above will become apparent from the following description of the embodiments. [Brief description of the drawings]

[0020] [Figure 1] FIG. 2 is a block diagram showing an example of a configuration related to watchdog timer detection in the protection and control device according to the first embodiment. [Diagram 2] 1 is a block diagram showing a configuration example of a protection and control device according to a first embodiment. [Diagram 3] FIG. 2 is an explanatory diagram illustrating an example of a station bus and a process bus in the first embodiment. [Figure 4] FIG. 2 is an explanatory diagram illustrating a configuration example of a WDT clear signal generating unit in the first embodiment; [Diagram 5] FIG. 4 is an explanatory diagram illustrating an example of a timing chart of internal signals in a WDT clear signal generating unit and a first WDT detecting unit in the first embodiment. [Figure 6] FIG. 4 is an explanatory diagram illustrating an example of a timing chart of internal signals in a WDT clear signal generating unit and a first WDT detecting unit in the first embodiment. [Figure 7] 11 is a flowchart illustrating an example of a continuous monitoring process in the first embodiment. [Figure 8] FIG. 11 is a block diagram showing an example of a configuration related to watchdog timer detection in a protection control device according to a second embodiment. [Figure 9] 13 is a flowchart illustrating an example of an apparatus startup process according to the second embodiment. [Figure 10] FIG. 11 is an explanatory diagram showing an example of use of a second WDT detection unit. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0021] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. In this embodiment, the same components are generally designated by the same reference numerals, and repeated explanations are omitted. Note that this embodiment is merely an example for realizing the present invention, and does not limit the technical scope of the present invention. EXAMPLES

[0022] Fig. 2 is a block diagram showing an example of the configuration of the protection and control device 1, and Fig. 1 is a block diagram showing an example of the configuration related to watchdog timer detection in the protection and control device 1. In this embodiment, the watchdog timer is abbreviated as WDT (WatchDog Timer), the virtual machine is abbreviated as VM (Virtual Machine), and the communication interface is abbreviated as communication IF. Also, the system on chip is abbreviated as SoC (System On Chip).

[0023] The protection and control device 1 includes, for example, an integrated circuit unit 10, a first WDT detection unit 40, a non-volatile memory 60, communication IFs 71 to 74, and a communication IF 75. The integrated circuit unit 10 is a single IC (Integrated Circuit) SoC, and includes, for example, an arithmetic processing unit 20, an FPGA (Field Programmable Gate Array) circuit unit 30, a second WDT detection unit 50, a restart control unit 51, an internal memory 61, and multiple I / O (Input / Output) 62.

[0024] The arithmetic processing unit 20, FPGA circuit unit 30, second WDT detection unit 50, restart control unit 51, built-in memory 61, and multiple I / O 62 included in the integrated circuit unit 10 are connected to each other by an internal bus, and the internal bus is shown by a thick line in Figure 2.

[0025] The arithmetic processing unit 20 includes a plurality of CPUs (Central Processing Units), and includes a first CPU 200 and a second CPU 210 in the example of FIGS.

[0026] The FPGA circuit unit 30 includes a WDT clear signal generating unit 301 and a transmission / reception circuit 302. The WDT clear signal generating unit 301 receives a plurality of clear signals periodically sent from the arithmetic processing unit 20, and sends a timer clear signal WDT_CLR to the outside of the integrated circuit unit 10. The WDT clear signal generating unit 301 will be described in detail later.

[0027] The transmission / reception circuit 302 performs processing for transmitting and receiving data via the communication IFs 71 to 74. The communication IFs 71 and 72 are connected to a transmission path called a station bus, and the communication IFs 73 and 74 are connected to a transmission path called a process bus. Details of the station bus and the process bus will be described later with reference to FIG.

[0028] The first WDT detection unit 40 receives as input the first timer clear signal WDT_CLR1 sent from the integrated circuit unit 10, and sends a first watchdog detection signal WDT_DET1 to the outside of the protection and control device 1 when it determines that the first timer clear signal WDT_CLR1 has been interrupted for a predetermined period of time.

[0029] The WDT_DET1 signal is a signal that indicates an external alarm, and is input to another device (not shown). The WDT_DET1 signal notifies the upper system of an abnormal state of the protection and control device 1, and the output of the protection and control device 1 is locked.

[0030] The integrated circuit unit 10 has a built-in WDT detection unit as a function of the SoC (referred to as a second WDT detection unit 50 in this embodiment). Furthermore, the integrated circuit unit 10 has a restart control unit 51 capable of restarting the integrated circuit unit 10 as a function of the SoC. In this embodiment, an operation of restarting the integrated circuit unit 10 is executed depending on the result of abnormality detection by the second WDT detection unit 50.

[0031] Further, the multiple I / O 62 is a circuit that realizes an interface with an external circuit, and the integrated circuit unit 10 is connected to the non-volatile memory 60 and the communication IF 75 via the multiple I / O 62 .

[0032] 3 is an explanatory diagram showing an example of a station bus and a process bus. The protection and control device 1 is connected to a transmission path called a station bus and a transmission path called a process bus. The station bus and the process bus are made redundant, and the protection and control device 1 has two communication IFs for each bus.

[0033] The protection and control device 1 is connected to an MU (Merging Unit) device via a process bus. The MU device acquires electrical quantities (current and voltage) of the power system. The MU device A / D (Analog to Digital) converts the acquired electrical quantity signals and transmits the A / D converted digital information via process bus transmission. The protection and control device 1 receives the electrical quantity information transmitted from the MU device via communication IF 73 and communication IF 74. At this time, a communication method called SV (Sampled Value) is used.

[0034] The protection and control device 1 performs protection relay calculations based on the information on the electrical quantity, and when the relay operation conditions are met, it transmits a trip signal to the MU device. At this time, a communication method called GOOSE (Generic Object Oriented Substation Events) is used. As shown in Figure 3, multiple MU devices may be installed in a substation, for example.

[0035] The protection and control device 1 is also connected to a higher-level device, a supervisory control and data acquisition (SCADA) device 100, via a station bus. The protection and control device 1 transmits its own device status and the like to the SCADA device 100, and receives command information from the SCADA device 100. At this time, a communication method called MMS (Manufacturing Messaging Specification) is used. Communication methods such as SV, GOOSE, and MMS are specified in the international standard IEC (International Electrotechnical Commission) 61850.

[0036] The protection and control device 1 is also connected to the HI-PC via a communication IF 75. The settings of the protection and control device 1 can be checked and changed by operating the HI-PC.

[0037] The WDT detection function in the protection and control device 1 of this embodiment, and the processing contents calculated in each CPU and each core will be described with reference to Fig. 1. The first CPU 200 is a multi-core CPU including four cores 201 to 204, and the second CPU 210 is a multi-core CPU including two cores 211 and 212. The first CPU 200 and the second CPU 210 have different architectures, and the second CPU 210 is the CPU that can be configured to perform processing more specialized for real-time processing.

[0038] A plurality of VM virtual machines are implemented in the first CPU 200 by virtualization technology. In this embodiment, three virtual machines, VM 205, VM 206, and VM 207, are operated on the first CPU 200. At this time, in virtualization, a virtual CPU is assigned to each virtual machine, and from the viewpoint of ensuring real-time performance, it is desirable that the virtual CPU and the physical CPU cores (cores 201 to 204 in this embodiment) correspond one-to-one. In this embodiment, it is assumed that the virtual CPU and the physical CPU core correspond one-to-one, and the virtual CPU will not be mentioned.

[0039] The allocation of cores to three virtual machines will be described. Core 201 and core 202 are allocated to VM 205, which is a virtual machine that implements an OS (Operating System). VM 205 performs, for example, a web server for HI-PC and MMS communication processing. In this embodiment, from the viewpoint of ensuring the above-mentioned real-time performance, the execution of each task is also allocated to a single physical core. Specifically, for example, a web server processing task for HI-PC is executed in core 201, and an MMS communication processing task is executed in core 202.

[0040] Core 203 is assigned to VM 206, and core 204 is assigned to VM 207. VM 206 and VM 207 are OS-less virtual machines that implement bare metal applications. VM 2 performs relay calculations, and VM 207 performs GOOSE communication processing. In VM 206 and VM 207, the OS is not involved and applications are executed directly by the (virtual) CPU, making them more suitable for executing processes that require real-time performance than when processing is executed on the OS.

[0041] A bare metal application is implemented in each core of the second CPU 210. The core 211 performs processing to analyze SV data (information on the amount of electricity) sent from the MU device.

[0042] The core 212 performs a constant monitoring process. In the constant monitoring process, the core 212 monitors whether each function constituting the protection control device 1 and each software process executed in the protection control device 1 are operating properly, and performs a predetermined process when it detects a problem with the soundness. In the constant monitoring process, the core 211 also stores a constant monitoring log in the non-volatile memory 60.

[0043] Through the operation of each core described above, information on electrical quantities sent from the MU device via the process bus is analyzed as SV data by core 211, relay calculations using that information are performed by core 203, and then GOOSE communication processing is performed by core 204. In addition, constant monitoring processing for monitoring the soundness of functions is performed by core 212. All four of these processes require real-time performance, and are therefore implemented as OS-less bare metal applications.

[0044] On the other hand, the VM 205 to which the cores 201 and 202 are assigned executes processes that require a relatively low level of real-time performance, such as a web server for a HI-PC or MMS communication processing.

[0045] Next, a description will be given of the clear signal transmitted from each core to the WDT clear signal generating unit 301. In the core on which the bare metal application runs, the bare metal application running in each core performs processing for transmitting the clear signal.

[0046] For example, in the core 211, a process of transmitting a clear signal is performed within an SV data analysis process. Also, in the core 203, a process of transmitting a clear signal is performed within a relay calculation process that operates on the virtual machine VM 206. As a result, a clear signal is transmitted from each core in the CPU.

[0047] In addition, in the virtual machine VM205 that implements the OS, a process of transmitting a clear signal is performed in each task that is processed on the OS. The web server processing task for the HI-PC and the MMS communication processing task each perform a process of transmitting an individual clear signal. Therefore, as shown in FIG. 1, two clear signals are transmitted from VM205 to the WDT clear signal generating unit 301.

[0048] Next, the WDT detection process in this embodiment will be described. The protection and control device 1 of this embodiment has two WDT detection units.

[0049] In this embodiment, the timeout period of the first WDT detection unit 40 is set to 10 seconds (longer than the period of any clear signal output from each core to the WDT clear signal generation unit 301). That is, the first WDT detection unit 40 performs watchdog detection when it determines that the input signal to itself has been interrupted for 10 seconds. The timeout period of the second WDT detection unit 50 is set to 5 seconds (longer than the period of any clear signal output from each core to the second WDT detection unit 50 and shorter than the timeout period of the first WDT detection unit 40).

[0050] First, a description will be given of the second WDT detection unit 50. The second WDT detection unit 50 is a built-in function of the integrated circuit unit 10. The second WDT detection unit 50 in this embodiment includes a first WDT detection unit 501 for CPU and a second WDT detection unit 502 for CPU.

[0051] The first CPU WDT detection unit 501 receives the WDT_CLR2_1 signal transmitted from the first CPU 200, and detects a watchdog when it is determined that the WDT_CLR2_1 signal has been interrupted for a predetermined time. The second CPU WDT detection unit 502 receives the WDT_CLR2_2 signal transmitted from the second CPU 210, and detects a watchdog when it is determined that the WDT_CLR2_2 signal has been interrupted for a predetermined time.

[0052] The second WDT detector 50 sends out a WDT_DET2 signal when a watchdog event is detected by either the first WDT detector 501 for the CPU or the second WDT detector 502 for the CPU.

[0053] The timeout period of the first CPU WDT detection unit 501 and the second CPU WDT detection unit 502 is set to 5 seconds (longer than the period of any clear signal output from each core to the second WDT detection unit 50 and shorter than the timeout period of the first WDT detection unit 40). That is, each of the first CPU WDT detection unit 501 and the second CPU WDT detection unit 502 performs watchdog detection when it is determined that the input signal to itself has been interrupted for 5 seconds.

[0054] Since the second WDT detection unit 50 is a built-in function of the integrated circuit unit 10, when virtualization is performed, the WDT cannot be detected for each core. Therefore, one signal is input from each CPU to the second WDT detection unit 50. In this embodiment, the WDT_CLR2_1 signal is transmitted from the core 203 in which the VM 206 that performs relay calculation operates, and the WDT_CLR2_2 signal is transmitted from the core 211 that performs SV data analysis processing. Among the processes executed by each CPU, the relay calculation and the SV data analysis processing are particularly important processes in terms of realizing the protection control function. In this way, a configuration is adopted that detects runaway of the calculation function for processes that are particularly important in each CPU.

[0055] The second WDT detection unit 50 sends a detection signal WDT_DET2 to the core 212 that performs the constant monitoring process. This may be implemented as an interrupt for the core 212, for example. When the core 212 receives WDT_DET2 while performing the constant monitoring process, it sends a RST signal to the restart control unit 51 to restart the integrated circuit unit 10. Details of the constant monitoring process by the core 212 will be described later with reference to FIG. 7.

[0056] The following describes the first WDT detection unit 40 and the WDT clear signal generation unit 301. The first WDT detection unit 40 is an IC having a watchdog timer function, and is an IC different from the ICs constituting the integrated circuit unit 10. The first WDT detection unit 40 in this embodiment is a dedicated IC for performing WDT detection.

[0057] The first WDT detector 40 receives the WDT_CLR1 signal transmitted from the WDT clear signal generator 301, and sends out a first watchdog detection signal WDT_DET1 when it determines that the WDT_CLR1 signal has been interrupted for a predetermined period of time. The WDT_DET1 signal is a signal indicating an external alarm.

[0058] The WDT clear signal generating unit 301 is hardware configured by an FPGA circuit in the integrated circuit unit 10. The WDT clear signal generating unit 301 receives a plurality of clear signals periodically sent from the arithmetic processing unit 20, monitors changes in the values ​​of the plurality of clear signals, and outputs a first timer clear signal WDT_CLR1 when the number of clear signals whose values ​​have changed reaches a predetermined number.

[0059] In this embodiment, the number of clear signals input to the WDT clear signal generation unit 301 is six, and the WDT clear signal generation unit 301 outputs the first timer clear signal WDT_CLR1 when the number of clear signals whose values ​​have changed reaches six. The WDT clear signal generation unit 301 in this embodiment also has a function of stopping WDT detection in the first WDT detection unit 40.

[0060] 4 is an explanatory diagram showing a configuration example of the WDT clear signal generating unit 301. The WDT clear signal generating unit 301 includes High level holding circuits 3011 to 3016 and an AND condition satisfied signal generating circuit 3017. Input signals 1 to 6 (clear signals) are all logic signals taking values ​​of 0 or 1, and a value of 1 indicates clear. Note that a description of the function of stopping WDT detection in the first WDT detecting unit 40 will be omitted.

[0061] The high level holding circuits 3011 to 3016 monitor the values ​​of the input signals 1 to 6, respectively, and hold the value when the value they are monitoring changes to 1. As a result, when a clear signal is sent from the arithmetic processing unit 20, the value is held by one of the high level holding circuits 3011 to 3016 corresponding to that clear signal.

[0062] The AND condition satisfied signal generation circuit 3017 takes the AND of the outputs of the high level holding circuits 3011 to 3016, and outputs a high level for a predetermined period if the result of the AND is 1. The output signal of the AND condition satisfied signal generation circuit 3017 is the first timer clear signal WDT_CLR1.

[0063] As a result, the AND condition satisfied signal generation circuit 3017 outputs the WDT_CLR1 signal when the number of clear signals whose values ​​have changed reaches 6. The AND condition satisfied signal generation circuit 3017 also outputs the WDT_CLR1 signal to the high level holding circuits 3011 to 3016, and the high level holding circuits 3011 to 3016 reset the values ​​they are holding when the WDT_CLR1 signal is input.

[0064] 5 and 6 are explanatory diagrams showing examples of timing charts of internal signals in the WDT clear signal generating unit 301 and the first WDT detecting unit 40 in this embodiment. Timing charts 511 and 611 show changes in the clear signals output from the VM 205 (i.e., the cores 201 and 202).

[0065] Note that a total of two clear signals are output from VM 205, one from each of cores 201 and 202, but for the sake of simplicity, the two timing charts are the same in the examples of Figures 5 and 6. The timing charts of the two signals are shown as a single common timing chart 511 and timing chart 611.

[0066] Timing charts 512 and 612 show changes in the clear signal output from the VM 206 (i.e., the core 203). Timing charts 513 and 613 show changes in the clear signal output from the VM 207 (i.e., the core 204).

[0067] The timing charts 514 and 614 show changes in the clear signal output from the core 211. The timing charts 515 and 615 show changes in the clear signal output from the core 212.

[0068] Timing charts 516 and 616 show changes in the number of signals whose values ​​have changed to 1 among the input signals to the AND condition satisfied signal generating circuit 3017. Timing charts 517 and 617 show changes in the WDT_CLR1 signal. Timing charts 518 and 618 show changes in the internal count value of the first WDT detection section 40 (a value corresponding to the elapsed time since the WDT_CLR1 signal was last input to the first WDT detection section 40). Timing charts 519 and 619 show changes in the WDT_DET1 signal.

[0069] It should be noted that the numbers of signals shown in the timing charts 516 and 616 and the internal count values ​​shown in the timing charts 518 and 618 are not the signals shown in FIG. 4, but are a schematic representation of the internal operations of the AND condition satisfied signal generating circuit 3017 and the first WDT detection unit 40.

[0070] Fig. 5 is an example of a timing chart of internal signals when all cores are operating normally. The WDT clear signal generating unit 301 of this embodiment monitors changes in the values ​​of six input signals by using high level holding circuits 3011 to 3016, and determines when the number of clear signals whose values ​​have changed reaches six. Therefore, as shown in Fig. 5, the WDT clear signal generating unit 301 can operate normally even if the timing at which each signal changes to 1 does not coincide.

[0071] Even if the cores have different periods for periodically sending out the clear signal, the WDT clear signal generator 301 can operate normally. In Fig. 5, the periods of the input signal from the VM 207 (core 204) shown in a timing chart 513 and the input signal from the core 212 shown in a timing chart 515 are shorter than the periods of the other input signals.

[0072] Even in this case, since each of the high level holding circuits 3011 to 3016 holds the input clear signal at a high level, it is possible to detect that "the number of clear signals whose values ​​have changed has reached six."

[0073] In addition, in the example of Figure 5, the length of time that each core keeps the clear signal value at 1 is the same, but the WDT clear signal generation unit 301 can operate normally even if the length of time that some or all of the cores keep the clear signal value at 1 differs.

[0074] When there is no disruption in the period of the clear signal from each core, the WDT_CLR1 signal shown in timing chart 517 periodically (at a period shorter than the timeout time of the first WDT detection unit 40) becomes 1. As a result, the internal count value shown in timing chart 518 never reaches the timeout time of the first WDT detection unit 40 (the horizontal dotted line in timing chart 518), so the first WDT detection unit 40 never detects the WDT (i.e., the WDT_DET1 signal shown in timing chart 519 never becomes 1).

[0075] Fig. 6 is an example of a timing chart when some cores operate abnormally. Fig. 6 shows an example in which the change in the value of the clear signal from the core 211, shown in a timing chart 614, is interrupted midway. After the clear signal from the core 211 is interrupted, the output of the high level holding circuit 3015 does not change to 1, so that the WDT_CLR1 signal, which is the output signal of the AND condition satisfied signal generating circuit 3017, remains at 0, as shown in a timing chart 617.

[0076] As a result, the internal count value shown in timing chart 618 reaches the timeout time of the first WDT detection unit 40 (the horizontal dotted line in timing chart 618), and the first WDT detection unit 40 sends out WDT_DET1 (i.e., the WDT_DET1 signal shown in timing chart 619 becomes 1).

[0077] 7 is a flowchart showing an example of a constant monitoring process executed by the core 212. As shown in FIG. 1, in the constant monitoring process by the core 212, a second watchdog detection signal WDT_DET2 output by the second WDT detection unit 50 is input to the core 212.

[0078] When the core 212 starts the constant monitoring process (step S701), it executes the constant monitoring process other than the WDT detection and collects the monitoring results (step S702). The core 212 determines whether or not there is an abnormality in the monitoring results collected in step S702 (step S703).

[0079] When the core 212 determines that an abnormality has occurred in any of the continuous monitoring items other than the WDT detection (step S702: YES), it saves a log of the continuous monitoring result in the non-volatile memory 60 (step S703) and executes an error process according to the error content (step S704). Since the present embodiment describes the WDT detection, details of the continuous monitoring process in step S702 and the error process in step S704 will be omitted.

[0080] When it is determined that there is no abnormality in the constant monitoring items other than the WDT detection (step S702: NO), the core 212 determines whether the value of the second watchdog detection signal WDT_DET2 is 1 (step S705).

[0081] If the core 212 determines that the value of the second watchdog detection signal WDT_DET2 is not 1 (step S705: NO), this means that soundness has been confirmed for all constant monitoring items including the WDT, so the core 212 transmits a clear signal to the WDT clear signal generating unit 301 (step S706) and returns to step S702. As a result, when the system is operating normally, constant monitoring and transmission of the clear signal from the core 212 are repeated.

[0082] If the core 212 determines that the value of the second watchdog detection signal WDT_DET2 is 1 (step S705: YES), this means that the transmission of the clear signal from any core has ceased for 5 seconds and the WDT has been detected by the second WDT detection unit 50. Therefore, the core 212 obtains the restart log from the non-volatile memory 60 (step S707) and determines whether the number of restarts in the last three days (within a specified period) is less than three times (a specified number of times) (step S708).

[0083] When the core 212 determines that the number of restarts in the last three days is less than three (step S708: YES), the core 212 proceeds to restart processing of the protection and control device 1. Specifically, the core 212 saves a log of the restart occurrence in the non-volatile memory 60 (step S709), and instructs the WDT clear signal generation unit 301 to stop detection by the first WDT detection unit 40 (step S710).

[0084] After that, the core 212 instructs the restart control unit 51 to restart by transmitting a RST signal to the restart control unit 51 (step S711). By the process of step S711, the restart control unit 51 starts the restart process of the protection and control device 1.

[0085] Furthermore, by instructing the first WDT detection unit 40 to stop detection in step S710, the core 212 can prevent the first WDT detection unit 40 from detecting the WDT during the restart process of the protection and control device 1. Note that the WDT detection by the first WDT detection unit 40 is resumed during the restart or after the restart is completed (the WDT detection by the first WDT detection unit 40 is not an operation included in the continuous monitoring process, and is therefore not shown in FIG. 7).

[0086] On the other hand, when the core 212 determines that the number of restarts in the last three days is not less than three times (a predetermined number of times) (step S708: NO), the restart process of the protection and control device 1 is not executed and an external alarm is output. Specifically, the core 212 saves a log of the occurrence of the device abnormality in the non-volatile memory 60 (step S712) and ends the continuous monitoring process (step S713).

[0087] This operation stops the transmission of the clear signal from the core 212 to the WDT clear signal generation unit 301, so that the first WDT detection unit 40 detects the WDT and outputs a WDT_DET1 signal indicating an external alarm.

[0088] The effects of this embodiment are described below: The first effect is that an abnormal state of the arithmetic processing unit can be detected effectively.

[0089] Since IEC61850 uses multiple protocols, there are processes that require high-load software processing such as protocol analysis processing, which is different from conventional protection and control devices to which IEC61850 does not apply, and which also require real-time processing. Specifically, four processes fall into this category: SV data analysis processing, relay calculation processing, GOOSE communication processing, and continuous monitoring processing. It is desirable to assign a physical CPU core exclusively to these processes that require real-time processing.

[0090] On the other hand, as described above, the first CPU 200 and the second CPU 210 have different architectures, and the CPU that can be configured to perform processing more specialized for real-time processing is the second CPU 210. However, since the second CPU 210 is a two-core CPU, the number of cores is insufficient to assign a core exclusively to each of the above four processes.

[0091] In this embodiment, in order to solve this problem, virtualization technology is applied to the first CPU 200, and VMs 206 and 207 that perform OS-less processing are implemented. This makes it possible to allocate physical CPU cores to processes that require real-time performance.

[0092] On the other hand, for web servers for HI-PCs and MMS communication processing based on TCP / IP communication, the real-time requirement level is relatively low, and more advanced processing can be implemented by running them as applications on the OS rather than as bare metal applications, since the OS functions can be used in conjunction with them. For this reason, by applying virtualization technology, it is possible to achieve both real-time performance and the construction of advanced systems that use OS functions in conjunction with them.

[0093] However, while the above configuration achieves real-time performance, it also creates a problem that the built-in watchdog detection function cannot handle the configuration. Unlike conventional protection and control devices, the protection and control device 1 of this embodiment executes SV data analysis processing, relay calculation processing, and GOOSE communication processing in distributed cores, but the protection and control function cannot be maintained if any one of them stops. Therefore, in a protection and control device that requires stable operation, it is desirable to monitor whether the calculation processing in each core is being performed properly.

[0094] In order to solve this problem, the protection and control device 1 of this embodiment is provided with a WDT clear signal generation unit 301. The WDT clear signal generation unit 301 receives a plurality of clear signals periodically sent from the calculation processing unit 20, monitors changes in the values ​​of the plurality of clear signals, and outputs a first timer clear signal WDT_CLR1 when the number of the clear signals whose values ​​have changed reaches a predetermined number. In addition, the WDT clear signal generation unit 301 supplies the first timer clear signal WDT_CLR1 to a first WDT detection unit 40 which is an IC different from the ICs constituting the integrated circuit unit 10.

[0095] This allows the protection and control device 1 of this embodiment to solve the problem that the number of detectable cores is insufficient in the WDT detection built into the SoC. Also, in the WDT detection by the second WDT detection unit 50 built into the SoC of this embodiment, as can be seen from the fact that the second watchdog detection signal WDT_DET2 is received once by the constant monitoring process by the core 212, software processing is involved until the restart is executed.

[0096] In this embodiment, if the constant monitoring process by the core 212 goes out of control, the runaway of the constant monitoring process is detected by the first WDT detection unit 40, which is a dedicated IC for WDT detection. For this reason, the WDT detection by the first WDT detection unit 40, which is a separate IC provided outside the SoC, is more reliable than the WDT function by the second WDT detection unit 50 built into the SoC.

[0097] Therefore, the output signal of the WDT clear signal generation unit 301 is output not to the second WDT detection unit 50 built into the SoC, but to the first WDT detection unit 40 which is an IC different from the IC constituting the arithmetic processing unit 20. By providing the final WDT detection in an IC different from the IC constituting the arithmetic processing unit 20 as in this embodiment, the reliability of the WDT detection can be improved.

[0098] Patent Document 1 describes a virtual CPU, but it is merely a description of extending a CPU to a virtual CPU, and the technology described in Patent Document 1 does not take into consideration the allocation of cores to VMs. For example, a configuration in which two VMs are constructed on a two-core CPU and two cores are assigned to each VM is also a form of virtualization. However, when this form is adopted, even if one of the cores fails, each VM may continue to operate on one core, and physical failure of the core cannot be accurately detected.

[0099] In this embodiment, core 203 is assigned to VM 206, and core 204 is assigned to VM 207. In other words, each core constituting a CPU is assigned to one of the virtual machines. As a result, if core 203 fails, the clear signal from VM 206 to which core 203 is assigned stops. As a result, the protection and control device 1 of this embodiment can accurately detect a physical failure of a core.

[0100] Furthermore, in this embodiment, the WDT detection is performed for each task running on the OS, which makes it possible to more effectively detect an abnormal state of the arithmetic processing unit 20. In the conventional technology, the survival of the OS could be detected by the WDT detection, but the soundness of each task running on the OS depended on the detection by the OS.

[0101] In the prior art, although alive monitoring of the task itself exists as a function of the OS, the task itself appears to be alive even if the processing within the task goes out of control and is not being performed normally.To correctly detect whether the processing of a task is being performed normally, it is desirable to send a WDT clear signal from each task and detect it with the WDT detection function as in this embodiment.

[0102] Furthermore, in this embodiment, the execution of each task is assigned to a single physical core. As a result, if core 201 fails, clearing of the web server processing task for the HI-PC that was assigned to and executed by core 201 is stopped, and if core 202 fails, clearing of the MMS communication processing that was assigned to and executed by core 202 is stopped. In this way, in this embodiment, by assigning one or more tasks that send a clear signal to each core assigned to the OS as processing by a single core, a physical failure of a core can be accurately detected.

[0103] In this embodiment, the clear signal is transmitted from two tasks running on the OS running on the two cores 201 and 202, but the clear signal may be transmitted from three or more tasks, the number of tasks being greater than the number of cores assigned to the OS. Even in this case, it is desirable to assign at least one of the three tasks to each of the two cores 201 and 202 assigned to the OS as single-core processing.

[0104] In addition, the configuration in which each task is assigned to a single physical core for execution is also effective when virtualization is not performed. For example, the configuration can be similarly applied to a case in which the OS is operated without using virtualization in the first CPU 200, which is a four-core CPU.

[0105] In addition, since the WDT detection is executed to detect software processing runaway, it is preferable that the WDT detection does not involve software. Although the function of the WDT clear signal generation unit 301 can be configured by software, in this embodiment, it is configured as hardware, that is, an FPGA circuit. Therefore, in this embodiment, the WDT detection can be performed satisfactorily without the intervention of software processing.

[0106] Furthermore, this embodiment is particularly suitable for the case where the integrated circuit unit 10 is an SoC incorporating the FPGA circuit unit 30. In this embodiment, there are six signals input to the WDT clear signal generation unit 301. If the FPGA circuit unit 30 is not a common IC with the arithmetic processing unit 20 but is a separate IC, it is necessary to output six signal lines from the IC of the arithmetic processing unit 20, wire them on the board, and input them to the FPGA.

[0107] However, in this embodiment, these six signals are internal signals of the SoC, and can be realized without increasing the number of wirings on the board or IC pins. That is, this is particularly suitable for the case where the WDT clear signal generation unit 301 and the arithmetic processing unit 20 are configured as hardware in a common IC.

[0108] In addition, in this embodiment, unlike the technology described in Patent Document 1, the FPGA circuit is configured, and therefore there are no restrictions on the timing and period at which each clear signal changes, or the time during which the value of the clear signal changes, as described with reference to Fig. 5. This is advantageous in terms of ensuring real-time performance of software processing.

[0109] If it is necessary to adjust the timing between the cores, communication processing between the cores will occur accordingly. Furthermore, the relay calculation processing in the core 203 needs to be executed every 30 electrical degrees. However, since the SV reception processing in the core 211 is a process that analyzes received data each time, it is not necessary to execute the processing every 30 electrical degrees, and executing the processing every 30 electrical degrees would actually be a constraint.

[0110] As described above, since the processing performed by each core in the protection and control device 1 of this embodiment is different, adopting a WDT detection configuration that has no restrictions on the timing and period at which each clear signal changes, and the time over which the value of the clear signal changes, is advantageous in ensuring the real-time nature of the protection and control function.

[0111] Furthermore, in this embodiment, by configuring the WDT clear signal generation unit 301 as an FPGA circuit, it is possible to freely design the number of clear signals input to the WDT clear signal generation unit 301. In addition, the WDT clear signal generation unit 301 designed as a circuit that accepts six input signals as in this embodiment can also have a function of reducing the number of clear signals to be input. Thus, this embodiment is particularly suitable for an SoC in which the arithmetic processing unit 20 and the FPGA circuit are mounted on a common IC.

[0112] A second effect of this embodiment is that the arithmetic processing unit 20 can be restored satisfactorily from an abnormal state.

[0113] Conventional protection and control devices, which require high reliability, send an external alarm when a WDT is detected and lock the output of the conventional protection and control device to prevent malfunction. However, in this case, there is a problem that even if the malfunction is a temporary one, the output of the conventional protection and control device is locked and becomes unavailable.

[0114] Furthermore, the technology described in Patent Document 2 recovers from a transient malfunction by restarting the device upon WDT detection. However, in a protection and control system, if the cause of WDT detection is a permanent fault, it is desirable to send an external alarm instead of repeating restarts. Therefore, the technology described in Patent Document 2 has a problem in that it can only handle either a transient malfunction or a permanent malfunction.

[0115] On the other hand, according to the configuration of this embodiment, when software processing in any of the cores goes out of control, the second WDT detection unit 50 detects the WDT after 5 seconds, and the protection and control device 1 undergoes restart processing. This makes it possible to recover from a transient malfunction. This solves the problem in the prior art that an external alarm is output due to a transient malfunction, and the output of the device is locked and made unavailable.

[0116] The protection and control device 1 of this embodiment also has a first WDT detection unit 40. In this embodiment, when software processing in any of the cores goes out of control, the WDT is detected by the first WDT detection unit 40 after 10 seconds, and an external alarm is transmitted. In other words, the protection and control device 1 of this embodiment transmits an external alarm when a permanent malfunction occurs.

[0117] In a protection and control system, if the cause of WDT detection is a permanent fault, it is desirable to send an external alarm instead of repeating restarts, because the protection and control device 1 cannot perform the protection and control function during restart, and the restart period should be as infrequent as possible.

[0118] To solve this problem, the protection and control device 1 of this embodiment has a non-volatile memory 60 that records information regarding restart, and if the information regarding restart recorded in the non-volatile memory 60 meets certain conditions, it determines that the malfunction is permanent rather than transient, and does not execute a restart of the protection and control device 1.

[0119] Furthermore, in this embodiment, the timeout time of the second WDT detection unit 50 is shorter than the timeout time of the first WDT detection unit 40. This enables the protection and control device 1 of this embodiment to first attempt recovery from a transient malfunction, and to output an external alarm if the malfunction is not transient.

[0120] Furthermore, many SoCs have a built-in function such as the restart control unit 51 of this embodiment. In this embodiment, since the second WDT detection circuit is realized by a built-in function of the SoC, the notification signal to the restart control unit 51 is an internal signal of the SoC (integrated circuit unit 10), and can be realized without increasing the number of wiring on the board or IC pins. In other words, this embodiment is particularly suitable when the WDT detection unit that performs the restart operation upon WDT detection, i.e., the second WDT detection unit 50, is a built-in function of an IC common to the arithmetic processing unit 20.

[0121] The scope of application of the WDT detection configuration in this embodiment is not limited to the protection and control device 1, and is applicable to information processing devices in general. However, in that a WDT detection function is strongly required from the viewpoint of the necessity for stable operation, and in that virtualization technology needs to be used to achieve real-time performance, applying the WDT detection in this embodiment to the protection and control device 1 is particularly effective.

[0122] Fig. 10 is an explanatory diagram showing an example of use of the second WDT detection unit 50. Even the second WDT detection unit 50 of this embodiment is considered to be sufficient as a WDT detection function in some devices when an OS is mounted on each CPU and the device is used as a multi-core CPU, for example, as in the integrated circuit unit 10 shown in Fig. 10.

[0123] However, in a protection control device that has a high requirement for real-time performance, such as the protection control device 1 of this embodiment, or more specifically, in a protection control device that applies IEC 61850, which requires high-load software processing such as protocol analysis processing, it is necessary to implement a protection control function using an OS-less bare metal application, and the inventor has found that the configuration of this embodiment is necessary to achieve both the improvement in real-time performance through virtualization and the improvement in the reliability of WDT detection.

[0124] In this embodiment, the second watchdog detection signal WDT_DET2 is received once by the core 212 that performs constant monitoring processing, but the second watchdog detection signal WDT_DET2 may also be received by a dedicated CPU or CPU core provided in the SoC rather than a user-programmable CPU.

[0125] With the above configuration, it is possible to effectively detect an abnormal state of the arithmetic processing unit 20 and recover from the abnormal state. EXAMPLES

[0126] In the first embodiment, the second watchdog detection signal WDT_DET2 is received once by the core 212 that is constantly monitoring, and the restart process is executed by sending a RST signal after software processing is performed. On the other hand, in the present embodiment, software processing is not performed in the restart process. Below, differences from the first embodiment will be mainly described, and explanations of similarities to the first embodiment will be omitted as appropriate.

[0127] 8 is a block diagram showing an example of a configuration related to watchdog timer detection in the protection and control device 1. The integrated circuit unit 10 of this embodiment differs from the first embodiment in that it has a restart control unit 52 instead of the restart control unit 51.

[0128] An example of the configuration of the protection and control device 1 of this embodiment is similar to that of FIG. 2 in the first embodiment, except that it has a restart control unit 52 instead of the restart control unit 51, and therefore a description thereof will be omitted.

[0129] The second watchdog detection signal WDT_DET2 output by the second WDT detection unit 50 is directly input to the restart control unit 52. When the second watchdog detection signal WDT_DET2 is input to the restart control unit 52, the restart control unit 52 has a function of executing restart processing of the protection and control device 1. The restart control unit 52 can also disable the restart function based on the WDT_DET2 signal.

[0130] Furthermore, the restart control unit 52 has a recording unit that records whether or not the restart was due to the WDT_DET2 signal (restart cause information), and can refer to this information the next time the device is started up.

[0131] 9 is a flow chart showing an example of the device startup process. Note that the device startup process is assumed to be executed by the first CPU 200.

[0132] When the first CPU 200 starts the device startup process (step S901), it executes an initialization process of the second WDT detection unit 50 (step S902). When the initialization process in step S902 starts, it is assumed that the second WDT detection unit 50 starts WDT detection. Note that, although a description of the transmission process of the clear signal from the first CPU 200 will be omitted in the following steps, it is assumed that the clear signal is transmitted periodically as in the first embodiment.

[0133] The first CPU 200 performs reset release processing of the FPGA circuit unit 30 (step S903) and multiple I / O initialization processing (step S904), and executes a bare metal application running on each core or an OS startup processing and a task startup processing running on the OS (step S905). After that, the first CPU 200 waits until the startup is completed (step S906).

[0134] When the first CPU 200 determines that the startup process of step S905 is completed (S906: YES), it acquires restart cause information from the restart control unit 52 (step S907). The first CPU 200 refers to the acquired restart cause information and determines whether the device startup process being executed is a restart caused by the WDT_DET2 signal (step S908).

[0135] When the first CPU 200 determines that the device startup process being executed is not a restart caused by the WDT_DET2 signal (step S908: NO), the first CPU 200 proceeds to step S912, which will be described later.

[0136] When the first CPU 200 determines that the device startup process being executed is a restart caused by the WDT_DET2 signal (step S908: YES), the first CPU 200 saves a log of the restart occurrence together with time information and the like in the non-volatile memory 60 (step S909). At this time, the first CPU 200 also acquires log information of past restart occurrences.

[0137] The first CPU 200 refers to the log information on the occurrence of the restart, and determines whether the number of restarts in the last three days (within a predetermined period) is less than two (less than a predetermined number) (step S910). When the first CPU 200 determines that the number of restarts in the most recent three days is less than two (step S910: YES), the first CPU 200 proceeds to step S912, which will be described later.

[0138] When the first CPU 200 determines that the number of restarts in the most recent three days is not less than two (step S910: NO), it disables the restart function in the restart control unit 52 that is triggered by detection by the second WDT detection unit 50 (step S911). As a result, even if a WDT is detected by the second WDT detection unit 50 thereafter, restart is not executed by the restart control unit 52, and as a result, WDT detection is performed by the first WDT detection unit 40. After step S911, the process proceeds to step S912.

[0139] The first CPU 200 instructs the WDT clear signal generating unit 301 to start detection by the first WDT detecting unit 40 (step S912), and ends the device startup process (step S913).

[0140] In addition to the effects of the first embodiment, the effect of the present embodiment is that the arithmetic processing unit 20 can be more effectively restored from an abnormal state. According to the present embodiment, the restart process after the WDT is detected by the second WDT detection unit 50 does not involve software processing. Therefore, the arithmetic processing unit 20 can be more effectively restored from an abnormal state.

[0141] In the first embodiment, a recording section for recording information indicating that a restart has been performed based on the WDT detection result in the second WDT detection section 50 is included in the non-volatile memory 60, and a process for determining whether the malfunction is a transient malfunction or a permanent malfunction from the information is performed before the restart.

[0142] On the other hand, in the second embodiment, a recording unit that records information indicating that a restart has been performed based on the WDT detection result in the second WDT detection unit 50 is included in the restart control unit 52, and a process of determining whether the malfunction is a transient malfunction or a permanent malfunction from the information is performed after the restart.

[0143] In this way, there are various possible ways to realize the recording unit that records the information indicating that a restart has been performed based on the WDT detection result in the second WDT detection unit 50, and the timing to perform the process of determining whether the malfunction is a transient malfunction or a permanent malfunction from that information, and the configuration described in this embodiment is merely one example.

[0144] In the above embodiment, the restart log is stored in the non-volatile memory 60. However, the restart log may be stored in a storage location other than the non-volatile memory 60. For example, the restart log may be stored in the SCADA device 100 external to the protection and control device 1, or the restart log may be stored in the built-in memory 61.

[0145] In this embodiment, the condition for determining whether to execute a restart based on the WDT detection result in the second WDT detection unit 50 is based on the number of restarts in the most recent three days indicated by the restart cause information. However, the period of three days and the number of restarts are merely examples of predetermined conditions for determining whether a malfunction is a temporary malfunction or a permanent malfunction.

[0146] In this embodiment, an example has been described in which the protection and control device 1 includes one integrated circuit unit 10. However, in the protection and control device 1, a configuration is known in which the main detection (main element) and the fault detection (FD (Fault Detect) element) are configured as separate hardware within the protection and control device.

[0147] In this configuration, the final trip command is a signal obtained by ANDing the trip command from the main element and the trip element from the FD element. In this way, this embodiment is also applicable to the case where the protection and control device 1 includes multiple integrated circuit units 10.

[0148] Furthermore, the protection and control device 1 may be made redundant. In this manner, in a configuration including a main element and an FD element, or in a configuration in which the protection and control device 1 itself is made redundant, the protection and control function is maintained for the entire system even if WDT detection is performed in the integrated circuit unit 10. That is, it is preferable to use this embodiment in combination with a configuration including a main element and an FD element, or in which the protection and control device 1 itself is made redundant.

[0149] In this embodiment, an example of a digital protection and control system based on IEC61850 has been described, but the WDT detection method in this embodiment can be similarly applied to a protection and control device 1 that does not use IEC61850.

[0150] In this embodiment, the protection and control device 1 has been described, but the present invention is not limited to the protection and control device 1, and the WDT detection method in this embodiment can be applied to information processing devices in general.

[0151] As an example other than the protection and control device 1, for example, the WDT detection method in this embodiment can be applied to an automobile having an automatic driving function using an image from an on-board camera. As a modification of the first embodiment, an example of the processing calculated in each CPU and each core when the configuration related to the WDT detection in the first embodiment (FIG. 1) is applied to an automobile having an automatic driving function is shown.

[0152] VM205, which is a virtual machine with an OS implemented, performs advanced arithmetic processing such as driving trajectory calculation for automatic driving calculation, video output processing related to the car navigation system, and communication processing with the outside. That is, similar to the first embodiment, VM205 is assigned with processing that has a relatively low requirement for real-timeness and requires advanced processing implemented as an application on the OS.

[0153] VM206 performs analysis of the video received from the vehicle-mounted camera. VM206 performs primary processing of the data received periodically based on the frame rate using a bare metal application, and passes the data to the driving trajectory calculation of VM205. VM207 also performs vehicle body control such as steering.

[0154] The two cores constituting the second CPU 210, which is a CPU capable of implementing processes more specialized for real-time processing, each execute engine control and a constant monitoring process similar to that in the first embodiment.

[0155] In this way, the present embodiment is not limited to the protection and control device 1 but can be applied to information processing devices in general.

[0156] In addition, in the WDT detection method of the present embodiment, as described with reference to Fig. 6, a change in the value of the clear signal is determined as normal, and a change in the value of the clear signal is determined as abnormal when the change in the value stops midway, but the WDT detection method is not limited to this. The above WDT detection method can detect, for example, a case where the transmission process of the clear signal cannot be executed due to a runaway of software processing.

[0157] However, the abnormal mode of the software processing is not limited to the above case, and there may be a case where the clear signal transmission process is executed frequently due to a breakdown in the software processing.

[0158] For example, there are cases where the value of the clear signal changes every 0.1 seconds under normal circumstances, but changes every 0.01 seconds under abnormal circumstances. In order to detect such abnormalities, in addition to detecting whether the period during which the value of the clear signal changes is equal to or longer than a specific period, it is also possible to detect whether the period during which the value of the clear signal changes is equal to or shorter than a specific period. Furthermore, in addition to monitoring the period during which the value of the clear signal changes, the time during which the clear signal becomes 1 may also be monitored.

[0159] In this way, the WDT detection method is not limited to monitoring "whether the value of the clear signal has changed" and can be generalized to "monitor whether the change in the value of the clear signal is normal or abnormal." The present invention can be similarly applied to the above-mentioned cases.

[0160] That is, the WDT clear signal generating unit 301 of the first embodiment may monitor whether the changes in values ​​of multiple clear signals are normal or abnormal, and output the first timer clear signal WDT_CLR1 when the number of clear signals whose value changes are normal reaches a predetermined number.

[0161] Furthermore, the first WDT detection unit 40 of the first embodiment may receive the first timer clear signal WDT_CLR1 sent from the integrated circuit unit 10 as input, and may send a first watchdog detection signal WDT_DET1 if an abnormal state of the change in the value of the first timer clear signal WDT_CLR1 continues for a predetermined period of time.

[0162] In the first embodiment, the timeout time of the second WDT detection unit 50 is set shorter than the timeout time of the first WDT detection unit 40. This is also to accommodate cases where an abnormality is determined when the change in the value of the clear signal stops midway. The timeout time in this embodiment is the time required to determine that the change in the value of the clear signal has stopped, in other words, the time required to determine that an abnormal state has continued. Therefore, the timeout time in this embodiment can be generalized as "the time during which the abnormal state of the clear signal continues."

[0163] For example, in the first embodiment, in the case where the process of transmitting a clear signal is executed frequently, as an example, the first WDT detection unit 40 detects whether the period during which the value of the input signal changes is equal to or shorter than a specific period, and when the state of being equal to or shorter than the specific period continues for 10 seconds, the first WDT detection unit 40 may detect a watchdog.

[0164] Similarly, the second WDT detection unit 50 detects whether the cycle in which the input signal value changes is equal to or shorter than a specific cycle, and performs watchdog detection when the state in which the cycle is equal to or shorter than the specific cycle continues for 5 seconds. By configuring in this way, it is possible to achieve the same effect as the above-mentioned embodiment. That is, in the case of a temporary malfunction, recovery is possible, and in the case of a permanent malfunction, an external alarm can be sent.

[0165] The above embodiment has been described with the arithmetic processing unit 20 being configured with a plurality of CPUs (the first CPU 200 and the second CPU 210), each of which is configured with a plurality of cores. However, various modifications are possible for the configuration of the arithmetic processing unit to which the present invention can be applied.

[0166] For example, the arithmetic processing unit may be configured only with the first CPU 200, and a clear signal may be sent from each core. Even in this case, the WDT clear signal generating unit monitors changes in the values ​​of multiple clear signals from each core, and when the number of clear signals whose values ​​have changed reaches a predetermined number, the first timer clear signal WDT_CLR1 can be output.

[0167] Alternatively, the arithmetic processing unit may be composed of multiple CPUs, each of which is composed of a single core. Even in this case, the WDT clear signal generating unit monitors changes in the values ​​of multiple clear signals from each CPU, and outputs the first timer clear signal WDT_CLR1 when the number of clear signals whose values ​​have changed reaches a predetermined number.

[0168] Furthermore, the arithmetic processing unit may be a single CPU consisting of a single core, on which an OS runs, and clear signals may be sent from multiple tasks running on the OS. Even in this case, the WDT clear signal generating unit monitors changes in the values ​​of multiple clear signals from each task, and outputs the first timer clear signal WDT_CLR1 when the number of clear signals whose values ​​have changed reaches a predetermined number. By configuring the WDT detection to be performed for each task running on the OS, abnormal states of the arithmetic processing unit can be detected more effectively.

[0169] In this manner, in an embodiment to which the present invention can be applied, the output sources of the multiple clear signals input to the watchdog timer clear signal generating unit are characterized by including multiple CPUs when the arithmetic processing unit includes multiple CPUs, multiple cores within a CPU when at least one of the CPUs of the arithmetic processing unit includes multiple cores, and at least one of the multiple tasks processed in the arithmetic processing unit.

[0170] The present invention is not limited to the above-mentioned embodiment, and includes various modifications other than the above-mentioned modifications. For example, the above-mentioned embodiment has been described in detail to easily explain the present invention, and is not necessarily limited to those having all of the configurations described. It is also possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of one embodiment. It is also possible to add, delete, or replace a part of the configuration of each embodiment with another configuration.

[0171] In addition, the above-mentioned configurations, functions, processing units, processing means, etc. may be realized in part or in whole by hardware, for example, by designing them as integrated circuits. In addition, the above-mentioned configurations, functions, etc. may be realized in software by a processor interpreting and executing a program that realizes each function. Information such as the program, table, file, etc. that realizes each function can be stored in a memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.

[0172] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and not all control lines and information lines in the product are necessarily shown. In reality, it can be considered that almost all components are connected to each other. [Explanation of symbols]

[0173] 1 protection control device, 10 integrated circuit unit, 20 arithmetic processing unit, 30 FPGA circuit unit, 40 first WDT detection unit, 50 second WDT detection unit, 51 restart control unit, 52 restart control unit, 60 non-volatile memory, 61 built-in memory, 62 multiple I / O, 71 communication IF, 75 communication IF, 100 SCADA device, 101 MU device, 104 HI-PC, 200 first CPU, 210 second CPU, 201 core, 202 core, 203 core, 204 core, 205 VM, 206 VM, 207 VM, 211 core, 212 core, 301 WDT clear signal generation unit, 302 transmission transmission / reception circuit, 501 first CPU WDT detection unit, 502 second CPU WDT detection unit, 3011 High level holding circuit, 3017 AND condition establishment signal generation circuit

Claims

1. An information processing device for detecting an abnormality in a calculation processing unit, The arithmetic processing unit; a watchdog timer clear signal generation unit which receives a plurality of clear signals periodically output from the arithmetic processing unit, monitors whether changes in the values ​​of the plurality of clear signals are normal or abnormal, and outputs a first timer clear signal when the number of the clear signals whose value changes are normal reaches a predetermined number; a first watchdog timer detection unit that receives the first timer clear signal and sends a first watchdog detection signal when an abnormal state of the first timer clear signal continues for a first predetermined time, The arithmetic processing unit includes one or more CPUs, each of the one or more CPUs includes one or more cores; an output source of the plurality of clear signals input to the watchdog timer clear signal generation unit includes a plurality of CPUs when the arithmetic processing unit includes a plurality of CPUs, a plurality of cores in at least one of the one or more CPUs when the at least one of the one or more CPUs includes a plurality of cores, and at least one of a plurality of tasks processed in the arithmetic processing unit; The information processing device, wherein the watchdog timer clear signal generating unit is provided in hardware within an IC shared with the arithmetic processing unit.

2. 2. The information processing device according to claim 1, The information processing device, wherein the watchdog timer clear signal generating unit is provided in an FPGA circuit in an IC shared with the arithmetic processing unit.

3. 2. The information processing device according to claim 1, At least one of the one or more CPUs is divided into a plurality of virtual machines; the plurality of virtual machines includes a virtual machine assigned to a single core; the clear signal is output from the virtual machine to which the single core is assigned to the watchdog timer clear signal generation unit.

4. 2. The information processing device according to claim 1, An OS runs on at least one of the one or more CPUs; an information processing device, wherein at least one or more cores in the CPU assigned to the OS are assigned to execute a task of transmitting the clear signal to the watchdog timer clear signal generation unit;

5. 2. The information processing device according to claim 1, a second watchdog timer detection unit that receives one or more clear signals periodically output from the arithmetic processing unit and outputs a second watchdog detection signal when an abnormal state of the one or more clear signals input continues for a second predetermined time; an operation of the information processing device when the first watchdog detection signal is output; The operation of the information processing device when the second watchdog detection signal is output is different from that of the information processing device when the second watchdog detection signal is output.

6. 6. The information processing device according to claim 5, An information processing device, wherein a set of signals input to the second watchdog timer detection unit is not identical to a set of signals input to the first watchdog timer detection unit.

7. 6. The information processing device according to claim 5, restarting the information processing device based on the output of the second watchdog detection signal, and sending a signal indicating an abnormality to the outside of the information processing device based on the output of the first watchdog detection signal; 13. An information processing apparatus, comprising: a first predetermined time period and a second predetermined time period;

8. 8. An information processing device according to claim 5, the first watchdog timer detection unit is an IC different from an IC in which the arithmetic processing unit is provided, The second watchdog timer detection unit is a built-in function of an IC in which the arithmetic processing unit is provided.

9. The information processing device according to claim 7, When executing a restart based on the second watchdog detection signal, stopping detection by the first watchdog timer detection unit; The information processing device is characterized in that detection by the first watchdog timer detection unit is resumed during the restart or after the restart is completed.

10. The information processing device according to claim 7, a restart information recording unit that records information regarding a restart of the information processing device in response to the second watchdog detection signal, When the information regarding the restart recorded in the restart information recording unit satisfies a predetermined condition, the information processing device disables the restart of the information processing device based on the output of the second watchdog detection signal.

11. The information processing device according to claim 10, The predetermined condition is that the number of restarts of the information processing device within a predetermined period is equal to or greater than a predetermined number.

12. A protection and control device that detects an abnormality in a calculation processing unit, The arithmetic processing unit is included, The arithmetic processing unit includes one or more CPUs, each of the one or more CPUs includes one or more cores; The protection and control device includes: The software processing required to realize the protection and control functions is divided into multiple parts, assigning the divided software processes to a plurality of CPUs in the case where the arithmetic processing unit includes a plurality of CPUs, a plurality of cores in a CPU in the case where at least one of the one or more CPUs includes a plurality of cores, or a plurality of tasks processed in the arithmetic processing unit, and executing the software processes in a distributed manner; a watchdog timer clear signal generation unit which receives a plurality of clear signals which are periodically output from the plurality of software processes, monitors whether changes in values ​​of the plurality of clear signals are normal or abnormal, and outputs a first timer clear signal when the number of the clear signals which are normal in value changes reaches a predetermined number; a first watchdog timer detection unit that receives the first timer clear signal and outputs a first watchdog detection signal when an abnormal state of the first timer clear signal continues for a first predetermined time, The protection and control device, wherein the watchdog timer clear signal generation unit is provided in hardware within an IC common to the arithmetic processing unit.

13. The protection and control device according to claim 12, At least one of the one or more CPUs is divided into a plurality of virtual machines; A protection control device, wherein at least one of the plurality of virtual machines executes the software processing without being equipped with an OS.

14. The protection and control device according to claim 12, The protection and control function is realized by receiving information on the amount of electricity sent via a network, performing relay calculation processing, and sending a trip command via the network. A protection and control device in which the relay calculation processing and the analysis processing of information transmitted and received via the network are distributed and executed by either a plurality of CPUs when the calculation processing unit includes a plurality of CPUs, a plurality of cores within a CPU when at least one of the one or more CPUs includes a plurality of cores, or the plurality of tasks processed in the calculation processing unit.

15. A watchdog timer operation method for detecting an abnormality in a processing unit included in an information processing device, comprising: The information processing device includes: The arithmetic processing unit; a watchdog timer clear signal generation unit which receives a plurality of clear signals periodically output from the arithmetic processing unit, monitors whether changes in the values ​​of the plurality of clear signals are normal or abnormal, and outputs a first timer clear signal when the number of the clear signals whose value changes are normal reaches a predetermined number; a first watchdog timer detection unit that receives the first timer clear signal and sends a first watchdog detection signal when an abnormal state of the first timer clear signal continues for a first predetermined time; a second watchdog timer detection unit which receives one or more clear signals periodically output from the arithmetic processing unit and sends a second watchdog detection signal when an abnormal state of the one or more clear signals continues for a second predetermined time which is shorter than the first predetermined time; a restart information recording unit that records information regarding a restart of the information processing device in response to the second watchdog detection signal, The arithmetic processing unit includes one or more CPUs, each of the one or more CPUs includes one or more cores; an output source of the plurality of clear signals input to the watchdog timer clear signal generation unit includes a plurality of CPUs when the arithmetic processing unit includes a plurality of CPUs, a plurality of cores in at least one of the one or more CPUs when the at least one of the one or more CPUs includes a plurality of cores, and at least one of a plurality of tasks processed in the arithmetic processing unit; the watchdog timer clear signal generating unit is provided in hardware within an IC shared with the arithmetic processing unit, The watchdog timer operation method includes: Acquire information regarding the restart recorded in the restart information recording unit; determining whether the acquired restart information satisfies a predetermined condition; when it is determined that the predetermined condition is satisfied, disabling a restart of the information processing device based on the output of the second watchdog detection signal.

Citation Information

Patent Citations

  • Watchdog timer monitoring device, and watchdog timer monitoring method

    JP2011002993A

  • Information processing unit

    JP2011258032A

  • Information processing apparatus, monitoring device, and control device

    JP2014146131A

  • Virtualization system and method of monitoring the same

    JP2022170005A

  • Embedded processor with watchdog timer for programmable logic

    US7340596B1

Cited By

  • Information processing device, protection control device, and watchdog timer operation method

    EP4807558A1

  • Information processing device, protection control device, and watchdog timer operation method

    WO2025100042A1