Fault-Tolerant Ethernet Time Synchronization via Link Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Ethernet protocol in vehicle systems lacks fault-tolerant time synchronization methods, particularly in the presence of hardware or link failures, which restricts data rate and causes timing issues in advanced vehicle communication systems.
Innovation Solution
A method and apparatus for fault-tolerant Ethernet time synchronization in a multiple time domain system, where a time synchronization signal is generated and transmitted through multiple links, with switches detecting link failures and re-routing the signal to maintain a common time base without time jumps, using a grandmaster clock and follow-up frames to track latency and synchronize clocks across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If Ethernet is deployed as a vehicle communications system to address data rate restrictions, then data rate is improved, but fault tolerance in time synchronization is worsened
Solution Approach 1:
The system designates a backup grandmaster clock in advance before any failure occurs. When the primary grandmaster fails, the backup is already prepared and can immediately take over, preventing time synchronization disruptions. This preliminary preparation resolves the contradiction by ensuring fault tolerance is built into the system architecture from the start, allowing Ethernet to provide high data rates while maintaining reliable time synchronization.
Solution Approach 2:
The patent implements redundant time synchronization paths and backup grandmaster clocks that act as a cushion against failures. These redundant components are prepared in advance and remain standby, cushioning the system against the harmful effect of grandmaster failures. This allows the system to maintain stable time synchronization even when using Ethernet for high-speed communications, thus resolving the reliability concern.
2Adaptability or versatility
If multiple time domains are used in vehicle subsystems, then system functionality is improved, but time synchronization reliability is worsened
Solution Approach 1:
The patent segments the vehicle communication system into multiple time domains, each with its own grandmaster clock, while implementing a hierarchy where domain grandmasters synchronize to a vehicle-wide grandmaster. This segmentation allows different subsystems to maintain their own timing requirements for functionality, while the hierarchical structure ensures overall time synchronization reliability across the entire vehicle system.
Solution Approach 2:
The patent introduces intermediate grandmaster clocks that act as mediators between individual time domains and the vehicle-wide time synchronization system. These intermediate grandmasters translate and coordinate timing signals across different domains, enabling multiple time domains to coexist while maintaining reliable synchronization to the vehicle-wide time base, thus resolving the contradiction between functionality and reliability.
3Reliability
If link failure detection is implemented, then fault tolerance is improved, but system complexity is worsened
Solution Approach 1:
The patent implements a self-service mechanism where the backup grandmaster automatically detects failures of the primary grandmaster through monitoring mechanisms and autonomously takes over time synchronization responsibilities. This self-service approach improves fault tolerance without requiring complex external intervention systems, as the system monitors and responds to failures internally through pre-configured protocols and automatic failover logic.
Data Source
AI summary
The present application generally relates to network timing synchronization in the presence of link faults including apparatus and methods In various embodiments, a method includes generating a time synchronization signal, transmitting the time synchronization signal from a first switch to a second switch via a first link and from the first switch to a third switch via a second link, detecting a link failure of the first link, and transmitting the time synchronization signal from the second switch to the third switch via a third link in response to the link failure.


