PTP Gateway Timing Redundancy for Near-Hitless Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Satellite communication systems using PTP networks are susceptible to synchronization errors and failures due to component breakdowns in the communication path between grandmaster clocks and end nodes, leading to outages and communication faults.
Innovation Solution
A redundant architecture for PTP networks is implemented, featuring multiple grandmaster clocks and PTP aware switches that provide multiple communication paths for timing synchronization, enabling failover with minimal physical layer packet loss by detecting and switching to standby components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single PTP network with one grandmaster clock is used, then the system is simple to operate, but the reliability is low due to susceptibility to component failures
Solution Approach 1:
The PTP network is segmented into multiple independent paths, each with its own grandmaster clock and PTP-aware switches. This segmentation allows the system to isolate failures to individual segments while maintaining synchronization through alternative paths, thereby improving reliability without requiring a complete system redesign.
Solution Approach 2:
Standby grandmaster clocks and PTP-aware switches are pre-configured and synchronized in advance before failures occur. When a primary component fails, the system can immediately switch to the pre-synchronized standby components without requiring time-consuming re-synchronization, thus maintaining high reliability while managing complexity through automated failover mechanisms.
2Reliability
If multiple PTP networks with standby grandmaster clocks are provided, then the reliability is improved, but the device complexity increases
Solution Approach 1:
The PTP-aware switches are equipped with automated failure detection and failover capabilities that operate without manual intervention. The switches independently monitor the health of primary grandmaster clocks and automatically switch to standby clocks when failures are detected, making the complex multi-network system as easy to operate as a single network while maintaining improved reliability.
Solution Approach 2:
The system implements continuous feedback monitoring where PTP-aware switches track the synchronization status and health of grandmaster clocks in real-time. This feedback mechanism enables automatic detection of failures and triggers appropriate failover actions, simplifying operation by eliminating the need for manual monitoring and intervention in the complex multi-network architecture.
3Reliability
If failover switching is implemented, then the reliability is improved, but the timing synchronization precision may be affected during transition
Solution Approach 1:
Standby grandmaster clocks and PTP-aware switches are pre-synchronized to the same timing reference before any failure occurs. This preliminary synchronization ensures that when a failover switch is triggered, the timing offset precision is maintained because the standby components are already aligned with the correct time reference, eliminating synchronization disruptions during the transition.
Solution Approach 2:
The system maintains multiple pre-synchronized timing paths simultaneously, creating a buffer or cushion against timing disruptions. When a failure occurs, the pre-existing synchronized standby path immediately absorbs the transition without causing timing offset errors, thereby maintaining both reliability and precision during failover events.
Data Source
AI summary
A redundant architecture for a Precision Time Protocol (PTP) network includes a plurality of PTP grandmaster clocks that provide first timing messages to a plurality of PTP aware switches based on a timing reference. The PTP aware switches determine respective first timing offsets based on the timing messages received from a primary grandmaster clock and provide second timing messages to an end node of the network based on the first timing offsets. The end node determines a second timing offset for the end node based on the second timing messages received from a primary PTP aware switch and adjusts its clock based on the second timing offset. When a failure of the primary grandmaster clock and/or the primary PTP aware switch is detected, a different grandmaster clock and/or a different PTP aware switch is designated as the primary grandmaster clock and the primary PTP aware switch, respectively.


