Phase synchronization system for triple modular redundancy controller
By designing a phase synchronization system for MCU and FPGA in a three-redundant controller system, and using clock diagnostics and communication diagnostic data for voting synchronization, the problem of insufficient synchronization performance in the prior art is solved, and high fault tolerance and low cost phase synchronization effects are achieved.
Patent Information
- Application Number
- PCT/CN2024/079327
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-20
- Filing Date
- 2024-02-29
- Publication Date
- 2025-05-30
AI Technical Summary
The synchronization technology of the existing three redundant controllers has shortcomings in system complexity, fault tolerance and synchronization performance, and cannot be diagnosed and switched to a normal clock controller in time, and the development and maintenance costs are high.
A phase synchronization system including an MCU and an FPGA is designed. The MCU includes a communication module, a phase counting module and a voting synchronization module. The FPGA includes a clock output module and a clock diagnostic module. Through real-time transmission and voting synchronization of clock diagnostics and communication diagnostic data, the main clock controller is determined and phase adjustment is performed.
It realizes efficient phase synchronization between the three redundant controllers, can detect abnormalities of the main clock in a timely manner and switch, improves the system's fault tolerance and synchronization performance, and reduces hardware composition and development and maintenance costs.
Smart Images

Figure CN2024079327_30052025_PF_FP_ABST
Abstract
Description
A phase synchronization system for triple redundant controllers Technical Field
[0001] The present invention relates to the field of automatic control, and in particular to a phase synchronization system for a triple redundant controller. Background Art
[0002] Triple-redundant control systems are widely used in various scenarios requiring high reliability, such as nuclear power, petrochemicals, aerospace, and automotive manufacturing. In these scenarios, the system must be highly reliable and secure to avoid accidents or incidents caused by equipment failure or control system instability. In a triple-redundant control system, each redundant module runs the same control algorithm and processes input and output data identically. Clock synchronization allows the three controllers to receive and process input and output data simultaneously, enabling rapid system recovery in the event of a failure, thereby increasing system availability and stability.
[0003] In the existing technology, there are various methods for synchronizing three redundant controllers. For example, communication between redundant controllers can be used to synchronize the controllers. However, in this solution, the clocks between the controllers cannot diagnose each other. When the clock of the main controller fails, it is impossible to switch to the normal controller in time. Another method is to use a common clock signal to connect multiple controllers to achieve synchronization. However, if the clock source in this solution fails, the entire system will not operate normally. Another method is to use independent software and hardware clock synchronization modules to synchronize the clocks between redundant controllers. However, this solution has high development and maintenance costs and fails to properly utilize the powerful communication and computing capabilities of the controllers, making it uneconomical. In short, existing controller synchronization technology still has room for improvement in terms of system complexity, fault tolerance, and synchronization performance.
[0004] Summary of the Invention
[0005] Purpose of the invention: The technical problem to be solved by the present invention is to address the deficiencies of the existing technology and provide a phase synchronization system for triple redundant controllers. The system includes three redundant controllers, each of which includes an MCU and an FPGA. The MCU includes a communication module, a phase counting module, and a voting synchronization module. The FPGA includes a clock output module and a clock diagnosis module. The phase refers to the operating beat of the controller in each control cycle.
[0006] The FPGA clock output module outputs a fixed-frequency clock signal, which is connected to the phase counting module for phase value update. The clock signal is also connected to the clock diagnostic module of the controller's own FPGA and the clock diagnostic modules of the other two controller FPGAs;
[0007] The clock diagnosis module of the FPGA diagnoses the frequencies of the three clock signals simultaneously to obtain clock diagnosis data of the controller;
[0008] The communication module of the MCU is used to communicate with the other two controllers and obtain communication diagnostic data of the controller according to the communication status;
[0009] The communication module of the MCU sends the diagnostic data of the controller, the diagnostic data of the other two controllers, and the phase data of the controller to the other two controllers in each control cycle. The controller that receives the message data needs to send a response message within the timeout period;
[0010] The diagnostic data includes clock diagnostic data and communication diagnostic data;
[0011] The phase data includes a control period of the controller and a real-time phase value of the controller;
[0012] The voting synchronization module of the MCU votes according to the diagnostic data, determines the master clock controller, and calculates the difference between the master clock phase value and the phase value of the controller to obtain the phase adjustment value Adj, which is used to adjust the control period of the controller and perform phase synchronization.
[0013] The three redundant controllers are respectively denoted as controller A, controller B, and controller C. The left-right relationship between the controllers is defined as: C is on the left of A and B is on the right of A; A is on the left of B and C is on the right of B; B is on the left of C and A is on the right of C.
[0014] The phase counting module is used to perform the following calculation: when the clock signal has a rising edge, 1 is added. The phase value range is [0, N], where N is the upper limit of the phase value. The calculation method is: N = T*F / 1000-1+Adj
[0015] Where T is the control period set in the configuration project, F is the frequency of the clock signal, and Adj is the phase adjustment value calculated this time.
[0016] When the phase value is 0, it represents the starting moment of a single control cycle of the controller; when the phase value is N, it represents the ending moment of a single control cycle of the controller; when the phase value changes from N to 0 and starts to increase again, it means that the controller starts a new control cycle.
[0017] The control cycles of the three redundant controllers are all equal.
[0018] The communication module of controller A uses two independent Gigabit Ethernet networks to conduct point-to-point high-speed Ethernet communication with the communication modules of the other two controllers. The Ethernet message of the MCU of the controller is sent directly to the other controller through the Ethernet hardware link layer without passing through the Ethernet protocol stack, so as to reduce the link transmission delay and ensure the real-time performance of the data and the stability of the link delay.
[0019] The communication diagnostic data is updated at the end of the control cycle and is used to indicate whether the communication between the controller A and the other two controllers is normal; if the controller C sends a response message in time during the control cycle, and the diagnostic data message actively sent by the controller C is received during the control cycle, then the communication of the controller C is determined to be normal, otherwise the communication is abnormal; if the controller B sends a response message in time during the control cycle, and the diagnostic data message actively sent by the controller B is received during the control cycle, then the communication of the controller B is determined to be normal, otherwise the communication is abnormal; if the data message of the controller C or B is not received during the control cycle, the diagnostic data of the controller C or B stored in the controller A are reset to empty;
[0020] The data sent by controller A's communication module to controllers C and B includes not only the diagnostic data and phase data of controller A itself, but also the diagnostic data of controllers C and B. If a communication anomaly occurs between two controllers, the two controllers can still obtain each other's diagnostic data through a third controller. For example, if a communication anomaly occurs between controllers B and C, controller B can obtain controller C's diagnostic data from data received from controller A, and controller C can obtain controller B's diagnostic data from data received from controller A.
[0021] The calculation formula of the phase adjustment value Adj is: Adj=Cnt1-Cnt0-TxDelay,
[0022] Among them, Cnt0 is the count value received by the slave clock controller from the master clock controller, Cnt1 is the count value of the local controller, and TxDelay is the link transmission delay time;
[0023] When Adj is a positive number, it means that the phase of this controller is ahead of the phase of the master clock. The phase upper limit value N of this control cycle will increase by Adj, so that the current control cycle will be "extended" in order to "wait" for the master clock controller.
[0024] When Adj is a negative number, it means that the phase of this controller is "lagging behind" that of the master clock. The phase upper limit value N of this cycle will be reduced by Adj, so that the current control cycle is "compressed" in order to "catch up" with the master clock controller.
[0025] Adj only affects the phase upper limit value N of the controller's current control cycle. When the phase value is reset to 0, Adj is also reset to 0;
[0026] Each control cycle is divided into multiple phases, namely: input data acquisition, input data synchronous voting, configuration logic calculation, output data synchronous voting, output data refresh, controller self-diagnosis, and idle;
[0027] Set the idle phase value to Idle. When the phase adjustment value Adj is negative, the current control cycle of the controller is compressed. In order not to affect the normal function of the controller, the minimum value of Adj is -Idle. The limited range of Adj is [-Idle, T*F / 2].
[0028] The voting synchronization module votes according to the diagnostic data to determine the master clock controller, specifically including the following steps:
[0029] Step 1: When a controller is judged by any left or right controller to have abnormal communication or empty data, the controller becomes a slave clock controller and no longer participates in voting; the number M of controllers participating in voting is obtained;
[0030] Step 2: Determine the voting method based on the number M of controllers with normal communication to determine whether the controller clock is normal. When M is 3, the voting method is 2 out of 3, i.e., the minority obeys the majority principle. When M is 2, the voting method is 1 out of 2, i.e., only when both results are normal is the controller considered normal. When M is 1, the diagnostic result is used directly. If the clock voting result is abnormal, the controller is designated as a slave clock controller. If the clock voting result is normal, proceed to step 3.
[0031] Step 3, determine the master clock controller: when the clock signal of only one controller is voted as normal, then the controller is the master clock controller; when the clock signals of more than two controllers are voted as normal, the master clock controller is determined based on the position of the controller as the priority, and the priority is: controller A>controller B>controller C. Beneficial effects:
[0032] The three controllers of the present invention can diagnose each other's clocks and communication links in real time, can promptly detect anomalies of the master clock and select a normal controller as the master clock through a voting process, and have high fault tolerance;
[0033] The present invention makes full use of the Gigabit Ethernet high-speed link of the controller to transmit diagnostic messages, realizes phase synchronization, and can achieve higher synchronization performance;
[0034] The hardware structure of the phase synchronization system of the present invention only requires an MCU and an FPAG, and the system solution is relatively simple and low in cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, and the above and / or other advantages of the present invention will become more apparent.
[0036] FIG1 is a schematic diagram of the triple-redundant control system structure of the present invention.
[0037] Figure 2 is a block diagram of the diagnostic data structure.
[0038] FIG3 is a schematic diagram showing the contents of a data message.
[0039] Figure 4 is a flow chart of communication diagnosis.
[0040] Figure 5 is a clock diagnosis flow chart.
[0041] FIG6 is a schematic diagram of the phase stage of each controller. DETAILED DESCRIPTION
[0042] Referring to Figure 1 , one embodiment of the present invention provides a phase synchronization system for triple-redundant controllers. The system includes three redundant controllers: controller A, controller B, and controller C. The controllers are composed of an MCU and an FPGA. The MCU includes a communication module 101, a phase counting module 102, and a voting synchronization module 103. The FPGA includes a clock output module 201 and a clock diagnostic module 202.
[0043] The FPGA's clock output module 201 outputs a fixed-frequency clock signal 203, a square wave signal that is connected to the MCU's phase counter module 102 for phase value updates. The clock signal 203 is also connected to the controller's own FPGA's clock diagnostic module 202 and the clock diagnostic modules 202 of two other controller FPGAs. The FPGA's clock diagnostic module 202 simultaneously diagnoses the three clock signals 203 to obtain clock diagnostic data for the controller.
[0044] The MCU's communication module 101 communicates with the left and right controllers and obtains the controller's communication diagnostic data based on the communication status. The MCU's communication module 101 sends the controller's diagnostic data, the left and right controller's diagnostic data, and the controller's phase data to the other two controllers during each control cycle. The controller that receives the message data must send a response message within a timeout period.
[0045] 2 , the diagnostic data includes diagnostic data of the controller for the three clock signals 203 and communication diagnostic data of the controller for the left and right controllers.
[0046] The phase data includes a control period of the controller and a real-time phase value of the controller.
[0047] The voting synchronization module 103 of the MCU votes based on the diagnostic data to determine the master clock controller, and calculates the difference between the master clock phase value and the phase value of the current controller to obtain the phase adjustment value Adj, which is used to adjust the control period of this controller for clock synchronization.
[0048] The three redundant controllers are controller A, controller B, and controller C. The left-right relationship between the controllers is defined as: C is on the left of A and B is on the right of A; A is on the left of B and C is on the right of B; B is on the left of C and A is on the right of C.
[0049] The phase counting module of the MCU is used to update the phase value. The GPIO port of the MCU connected to the clock signal 203 is set to the rising edge interrupt mode. When the clock signal 203 has a rising edge, the phase value is increased by 1 in the interrupt service function. The range of the phase value is [0, N], where N is the upper limit of the phase value. If the current phase value is N, the next time the clock signal 203 has a rising edge, the phase value will become 0. The calculation method of the upper limit N is: N = T*F / 1000-1+Adj (1)
[0050] Where: T is the control period set in the configuration project, in milliseconds. The configuration project is typically edited by the user in configuration programming software and then downloaded to the controller. It includes data such as hardware configuration and logic algorithms. F is the frequency of clock signal 203, in Hertz. Adj is the phase adjustment value for this calculation. For example, if the frequency of clock signal 203 is 1000 Hz and the user-set controller period is 100 ms, when Adj is 0, the value of N is 99, meaning that the phase value increases from 0 to 99 and then starts to increase again from 0.
[0051] The frequency value F of the clock signal 203 is determined during product design and is related to the computing power of the MCU. When the computing power of the MCU is strong, the frequency value F can be designed to be larger. When the control period T remains unchanged, according to Formula 1, N will become larger accordingly, thereby improving the phase granularity of the phase counting module.
[0052] The control cycle of the controller is determined by the engineering designer and distributed to the three controllers through a configuration project. The smaller the control cycle, the higher the real-time control performance. After the three controllers are powered on together, if the configuration projects of the controllers are consistent, the control cycle is consistent. If the configuration of a controller is inconsistent with the left and right controllers, the configuration projects are synchronized through the communication module based on the principle of majority rule. After synchronization, the control cycles of the three controllers are consistent. If the configuration projects of the three controllers are not identical, synchronization between the controllers cannot be achieved, and the configuration projects must be downloaded again.
[0053] The MCU's communication module uses two independent Gigabit Ethernet channels to conduct point-to-point high-speed Ethernet communication with the communication modules of two other controllers. The controller's MCU packages messages in a buffer and then directly sends them to the other controllers using the MCU's Ethernet peripheral. The MCUs of the other controllers immediately parse and process the messages after receiving them from the Ethernet peripherals. From the perspective of the OSI communication model, this message transmission process directly sends application layer messages to the other controllers via the data link layer. Messages received by the controllers then directly reach the application layer for processing from the data link layer, thereby improving the real-time nature of data transmission and reception and reducing the jitter of message transmission link delays.
[0054] 3 , the message data is composed of: message header, current controller phase data, left controller diagnostic data, right controller diagnostic data, and check value. The check value is the MD5 check result from the message header to the right controller diagnostic data.
[0055] Referring to FIG4 , the communication diagnostic data is updated at the end of the control cycle, and the determination process is as follows:
[0056] S100, check whether the other controller responds in time after sending the message data to the other controller in this cycle. If it responds in time, then go to S101; if it responds in time, then go to S103 to determine if the communication with the other controller is abnormal;
[0057] S101, check whether the data message actively sent by the other controller is received in this cycle. If it is received, enter S102 to determine that the communication with the other controller is normal. If not, enter S103 to determine that the communication with the other controller is abnormal, and set the diagnostic data of the other controller to "null";
[0058] Referring to FIG5 , the FPGA clock diagnostic module monitors the signal periods of the three clock signals in real time. If the difference between the measured signal period and the designed signal period does not exceed the judgment threshold, the clock signal is judged to be normal. Otherwise, the clock signal is abnormal. Assuming that the clock signal frequency is 1 kHz, that is, the designed signal period is 1 ms, and the error threshold is 0.5%, the working process is as follows:
[0059] S200, it is known that the theoretical signal period of the clock signal is 1000us, and the error threshold of 0.5% corresponds to a difference of ±5us;
[0060] S201, save the current timestamp Stamp1 at the first rising edge of the clock signal;
[0061] S202, saving the current timestamp Stamp2 at the second rising edge of the clock signal;
[0062] S203, calculating error Err = Stamp2 - Stamp1;
[0063] S204: Compare the error Err to see if it is less than ±5us. If it is within the range of ±5us, proceed to S205 to determine if the clock of the other controller is normal. If it is greater than the range of ±5us, proceed to S206 to determine if the clock of the other controller is abnormal.
[0064] The phase adjustment value Adj is calculated as follows: Adj = Cnt1 - Cnt0 - TxDelay (2)
[0065] Among them, Cnt0 is the count value sent by the master clock controller, Cnt1 is the phase value of the slave clock controller, and TxDelay is the phase value corresponding to the link transmission delay time.
[0066] TxDelay can be calculated by averaging the link delays of multiple messages. Toggle a GPIO on the MCU at the moment a message is sent, and then toggle a GPIO on the MCU at the moment the message is received. Using an oscilloscope, measure the time difference between the two GPIOs to calculate the link delay for this data transmission.
[0067] The following example illustrates the phase adjustment process:
[0068] Assume the controller's control period is 50ms, the clock signal frequency is 4kHz, and the link transmission delay is 50µs. Assume that controller B is the master clock and controller A is the slave clock. Without phase adjustment, according to Formula 1, N ranges from [0, 199]. That is, after N increases from 0 to 199, it will restart from 0 the next time. A phase value of 50µs corresponds to 0.2, which means a TxDelay of 0.2.
[0069] In scenario 1, at a certain moment, slave controller A receives a data packet from controller B. Parsing the packet data reveals that controller B's phase value is 95. At this point, the phase value read from controller A is 100, indicating that controller A's phase is ahead of controller B. Formula 2 yields: Adj = 100 - 95 - 0.2 = 4.8. Formula 1 yields N for this cycle as 203.8. Since N is a positive integer, it is rounded to 204. This means that slave controller A's phase limit for this cycle, originally 199, has been increased to 204, extending the cycle. This means that it takes longer to enter the next cycle, allowing it to "wait" for the master clock controller.
[0070] In scenario 2, at a certain moment, slave controller A receives a data packet from controller B. Parsing the packet data reveals that controller B's phase value is 105. At this point, the phase value read from controller A is 100, indicating that controller A's phase is lagging behind controller B. Formula 2 yields: Adj = 100 - 105 - 0.2 = -5.2. Formula 1 yields N for this cycle as 193.8. Since N is a positive integer, it is rounded to 194. This means that slave controller A's phase upper limit, N, for this cycle was originally 199, but has been reduced to 193.8. This compresses the cycle, shortening the time it takes to enter the next cycle and catching up with the master clock controller.
[0071] Referring to FIG6 , the controller is divided into multiple phases at each stage, specifically:
[0072] S300, input data collection;
[0073] S301, synchronous voting of input data;
[0074] S302, configuration logic calculation;
[0075] S303, output data synchronous voting;
[0076] S304, output data refresh;
[0077] S305, controller self-diagnosis;
[0078] S306, idle;
[0079] The controller's control cycle "stretching" or "compressing" only adjusts the phase occupied by the idle phase and does not affect the timing of other phases, as this would affect the normal operation of the controller. Assuming the idle phase value occupies Idle, the phase adjustment value Adj provided by the present invention is limited to the range of [-Idle, T*F / 2].
[0080] The voting process of the master clock controller is specifically as follows:
[0081] Voting step 1: Exclude controllers with abnormal communication or "empty" diagnostic data. If a controller is identified as abnormal by either left or right controller, or its data is "empty," it becomes a slave clock controller and no longer participates in step 2. Controllers with normal communication participate in step 2.
[0082] Voting step 2: Determine the voting method based on the number M of controllers with normal communication to determine whether the controller clock is normal. When M is 3, vote according to the principle of 2 out of 3, that is, the minority obeys the majority. When M is 2, vote according to the principle of 1 out of 2, that is, both results are normal for it to be considered normal. When M is 1, directly use the diagnostic result. If the clock voting result is "abnormal", the controller is a slave clock controller. If the clock voting result is "normal", proceed to step 3.
[0083] Voting step three: Determine the master clock controller: When the clock signal of only one controller is voted as "normal", then the controller is the master clock controller; when the clock signals of more than two controllers are voted as "normal", the master clock controller is determined based on the position of the controller, and the priority is: controller A>controller B>controller C.
[0084] The following examples illustrate the triple-redundant control system described in this invention under normal conditions and under single-point failure conditions. A single-point failure refers to a system with only one fault. Upon occurrence, on-site troubleshooting and repairs are immediately carried out to eliminate the fault. Multiple fault conditions are beyond the scope of this invention. Failures or anomalies are marked "Bad," normal conditions are marked "Good," and empty data is marked "Empty."
[0085] In case 1, the triple redundant control system is completely normal. Table 1 and Table 2 are the communication diagnosis and clock diagnosis data of the three controllers respectively.
[0086] Table 1
[0087] Table 2
[0088] Voting step 1: If no controller data is "empty", all proceed to step 2;
[0089] Voting step 2: If the communication between the three controllers is normal, proceed to step 3;
[0090] Voting step 3: The number of controllers with normal communication, M, is 3. A 2-out-of-3 voting method is used to vote on the clock diagnosis results. If the clocks of all three controllers are normal, proceed to step 4.
[0091] Voting step 4: If the clocks of all three controllers are normal, controller A is determined as the master clock controller based on the principle of position priority, and the remaining controllers are determined as slave clock controllers;
[0092] In case 2, the Ethernet line between controller A and controller B is disconnected. Tables 3 and 4 show the communication diagnosis and clock diagnosis data of the three controllers, respectively.
[0093] Table 3
[0094] Table 4
[0095] Voting step 1: If no controller data is "empty", all proceed to step 2.
[0096] Voting step 2: Since controllers A and N determine that each other's communication is abnormal, only controller C proceeds to step 3.
[0097] Voting step three: The number of controllers M with normal communication is 1. Select the 1-out-of-1 method to vote on the clock diagnosis result. That is, only focus on the clock diagnosis result of controller C. If the result is Good, go to step four.
[0098] Voting step 4: If only controller C is Good, controller C becomes the master clock controller, and the remaining controllers are slave clock controllers.
[0099] In case 3, controller A is removed, and only controllers B and C remain in the system. Tables 5 and 6 show the communication diagnosis and clock diagnosis data of the three controllers, respectively.
[0100] Table 5
[0101] Table 6
[0102] Voting step 1: Controller A's data is "empty" and does not participate in the voting. Subsequently, only the data of controllers B and C need to be considered, and the process goes to step 2.
[0103] Voting step 2: If the communication between controller B and controller C is normal, proceed to step 3.
[0104] Voting step three: The number M of controllers with normal communication is 2. A 1-out-of-2 method is selected to vote on the clock diagnosis results. The result is that the clocks of both controllers are normal, and the process goes to step four.
[0105] Voting step 4: If the clocks of both controllers are normal, controller B is determined as the master clock controller based on the principle of position priority, and the remaining controllers are determined as slave clock controllers.
[0106] In case 4, the clock signal of controller A is abnormal. Tables 7 and 8 are the communication diagnosis and clock diagnosis data of the three controllers respectively.
[0107] Table 7
[0108] Table 8
[0109] Voting step 1: If no controller data is "empty", all proceed to step 2.
[0110] Voting step 2: If the communication of all controllers is normal, proceed to step 3.
[0111] Voting step three: The number M of controllers with normal communication is 3. Select the 3 out of 2 method to vote on the clock diagnosis result. Controller A is determined to be abnormal, and controllers B and C are normal. Go to step four.
[0112] Voting step 4: If the clocks of both controllers are normal, controller B is determined as the master clock controller based on the principle of position priority, and the remaining controllers are determined as slave clock controllers.
[0113] The present invention provides a triple-redundant control system for phase synchronization. There are numerous methods and approaches for implementing this technical solution. The foregoing description is merely a preferred embodiment of the present invention. It should be noted that those skilled in the art may make various improvements and modifications without departing from the principles of the present invention, and such improvements and modifications are also within the scope of protection of the present invention. Any components not specified in this embodiment may be implemented using existing technologies.
Claims
1. A phase synchronization system for a triple redundant controller, characterized in that: The system includes three redundant controllers, each controller includes an MCU and an FPGA, wherein the MCU includes a communication module, a phase counting module and a voting synchronization module; the FPGA includes a clock output module and a clock diagnosis module, and the phase refers to the operating beat of the controller in each control cycle; The clock output module of the FPGA outputs a clock signal of a fixed frequency, the clock signal is connected to the phase counting module for updating the phase value, and the clock signal is also connected to the clock diagnosis module of the controller's own FPGA and the clock diagnosis modules of the other two controller FPGAs; The clock diagnosis module of the FPGA diagnoses the frequencies of the three clock signals simultaneously to obtain clock diagnosis data of the controller; The communication module of the MCU is used to communicate with the other two controllers and obtain communication diagnostic data of the controller according to the communication conditions; The communication module of the MCU sends the diagnostic data of the controller, the diagnostic data of the other two controllers, and the phase data of the controller to the other two controllers in each control cycle. The controller that receives the message data needs to send a response message within the timeout period. The diagnostic data includes clock diagnostic data and communication diagnostic data; The phase data includes a control cycle of the controller and a real-time phase value of the controller; The voting synchronization module of the MCU votes according to the diagnostic data, determines the master clock controller, and calculates the difference between the master clock phase value and the phase value of this controller to obtain a phase adjustment value Adj, which is used to adjust the control period of this controller for phase synchronization.
2. The system according to claim 1, characterized in that The three redundant controllers are respectively denoted as controller A, controller B, and controller C. The left-right relationship between the controllers is defined as: C is on the left of A and B is on the right of A; A is on the left of B and C is on the right of B; B is on the left of C and A is on the right of C.
3. The system according to claim 2, characterized in that The phase counting module is used to perform the following calculation: when the clock signal has a rising edge, it is increased by 1, and the phase value range is [0, N], where N is the upper limit of the phase value, and the calculation method is: N = T*F / 1000-1+Adj Where T is the control period set in the configuration project, F is the frequency value of the clock signal, and Adj is the phase adjustment value calculated this time; When the phase value is 0, it represents the starting time of a single control cycle of the controller; when the phase value is N, it represents the ending time of a single control cycle of the controller; when the phase value changes from N to 0 and starts to increase again, it means that the controller starts a new control cycle.
4. The system according to claim 3, characterized in that The control cycles of the three redundant controllers are all equal.
5. The system according to claim 4, characterized in that The communication module of the controller A uses two independent Ethernets to perform point-to-point Ethernet communication with the communication modules of the other two controllers respectively; the Ethernet message of the MCU of the controller is sent directly to the other controller through the Ethernet hardware link layer without passing through the Ethernet protocol stack.
6. The system according to claim 5, characterized in that The communication diagnostic data is updated at the end of the control cycle and is used to indicate whether the communication between the controller A and the other two controllers is normal; if the controller C sends a response message in time during the control cycle, and the diagnostic data message actively sent by the controller C is received during the control cycle, then the communication of the controller C is judged to be normal, otherwise the communication is abnormal; if the controller B sends a response message in time during the control cycle, and the diagnostic data message actively sent by the controller B is received during the control cycle, then the communication of the controller B is judged to be normal, otherwise the communication is abnormal; if the data message from the controller C or B is not received during the control cycle, the diagnostic data of the controller C or B stored in the controller A are reset to empty.
7. The system according to claim 6, characterized in that The data sent by the communication module of the controller A to the controllers C and B include not only the diagnostic data of the controller A and the phase data of the controller A, but also the diagnostic data of the controllers C and B.
8. The system according to claim 7, characterized in that The calculation formula of the phase adjustment value Adj is: Adj=Cnt1-Cnt0-TxDelay, Among them, Cnt0 is the count value received by the slave clock controller from the master clock controller, Cnt1 is the count value of the local controller, and TxDelay is the link transmission delay time; When Adj is a positive number, it means that the phase of this controller is ahead of the phase of the master clock, and the phase upper limit value N of this control cycle will increase by Adj; When Adj is a negative number, it means that the phase of this controller lags behind the phase of the master clock, and the phase upper limit value N of this cycle will be reduced by Adj; Adj only affects the phase upper limit value N of the controller's current control cycle. When the phase value is reset to 0, Adj also Reset to 0.
9. The system according to claim 8, characterized in that Each control cycle is divided into multiple phases, namely: input data acquisition, input data synchronous voting, configuration logic calculation, output data synchronous voting, output data refresh, controller self-diagnosis, and idle; Set the idle phase phase value to occupy Idle. When the phase adjustment value Adj is a negative number, the current control cycle of the controller is compressed. The minimum value of Adj is -Idle, and the limited range of Adj is [-Idle, T*F / 2].
10. The system according to claim 9, characterized in that The voting synchronization module votes according to the diagnostic data to determine the master clock controller, which specifically includes the following steps: Step 1: When a controller is judged by any left or right controller to have abnormal communication or the data is empty, the controller is a slave clock controller and no longer participates in voting; Get the number M of controllers participating in the voting; Step 2, determine the voting method according to the number M of controllers with normal communication, which is used to vote whether the controller clock is normal. When M is 3, vote according to 3 out of 2; when M is 2, vote according to 2 out of 1; when M is 1, directly use the diagnosis result; if the clock voting result is abnormal, the controller is a slave clock controller; if the clock voting result is normal, go to step 3; Step 3, determine the master clock controller: when the clock signal of only one controller is voted as normal, then the controller is the master clock controller; when the clock signals of more than two controllers are voted as normal, the master clock controller is determined based on the position of the controller, and the priority is: controller A>controller B>controller C.
Citation Information
Patent Citations
Clock synchronizing control system and method of multi-redundancy controller
CN104796213A
Method for synchronizing three-redundancy computers
CN106774635A
Three-redundancy computer synchronizing method
CN107239433A
Triple-modular redundancy clock synchronization device and method, electronic device and storage medium
CN115632754A
Real-time Ethernet on-card system architecture
CN116094639A