Redundant Grandmaster Clocks for Fault-Tolerant Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing clock synchronization methods in distributed networks are vulnerable to faults, particularly in mission-critical applications where reliable and seamless transition between primary and backup grandmaster clocks is essential to maintain network synchronization.
Innovation Solution
The implementation of redundant grandmaster clocks, where a primary grandmaster clock (pGM) and a backup grandmaster clock (bGM) are preconfigured or dynamically selected using algorithms like BMCA, ensuring seamless transition and synchronization, with the bGM taking over in case of pGM failure, and both clocks being synchronized to maintain clock accuracy and tolerance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single primary grandmaster clock is used for clock synchronization in distributed networks, then the device complexity is reduced, but the reliability deteriorates due to vulnerability to faults and failures
Solution Approach 1:
The system pre-configures a backup grandmaster clock alongside the primary grandmaster clock, performing the redundancy setup in advance before any failure occurs. This preliminary action ensures that when the primary clock fails, the backup is already in place and can immediately take over, maintaining continuous clock synchronization without interruption and resolving the reliability concern.
Solution Approach 2:
By implementing a backup grandmaster clock that remains on standby, the system creates a cushion against potential failures of the primary clock. This beforehand cushioning mechanism protects the clock synchronization system from faults by having a pre-prepared alternative that can compensate for the primary clock's failure, thereby improving reliability without requiring complex real-time failover decision logic.
2Reliability
If redundant backup grandmaster clocks are implemented to improve reliability, then the reliability improves, but the device complexity increases due to additional clock synchronization mechanisms
Solution Approach 1:
The backup grandmaster clock automatically monitors the status of the primary clock and takes over synchronization functions without requiring external intervention or complex management overhead. The system performs self-service failover by detecting primary clock failures and activating the backup through predefined protocols, thereby improving fault tolerance while minimizing the complexity of clock management.
Solution Approach 2:
The backup grandmaster clock is configured as a copy of the primary clock with identical synchronization parameters and functionality. This copying approach simplifies the overall system design by using standardized clock modules that can be replicated, rather than creating complex custom failover mechanisms. The duplicate clock structure ensures that the backup can seamlessly assume the primary's role while maintaining synchronization accuracy.
3Reliability
If seamless transition between primary and backup grandmaster clocks is implemented, then the reliability improves, but the measurement precision requirements increase due to synchronization tolerance constraints
Solution Approach 1:
The backup clock is pre-synchronized with the primary clock using the same reference signal and synchronization protocol before any failure occurs. This preliminary synchronization action ensures that when the failover event happens, the time and frequency offsets between the two clocks are already minimal, enabling seamless transition without introducing significant synchronization errors or disrupting continuous operation.
Solution Approach 2:
The system maintains a cushion of synchronization accuracy by continuously monitoring and adjusting the backup clock's timing parameters relative to the primary clock. This beforehand cushioning ensures that even if the primary clock experiences drift or instability, the backup clock remains within acceptable synchronization tolerances, thereby enabling reliable failover without compromising measurement precision requirements.
Data Source
AI summary
Fault tolerant and redundant grand master clock scheme may reduce or eliminate precision time transition caused by a network link or device failure. A primary synchronization message may be sent by a primary grandmaster clock and one or more backup synchronization message may be sent by respective backup grandmaster clocks. The primary and backup grandmaster clocks may be concurrently operated. The primary and backup synchronization messages may be sent to an end station over a network. The end station may derive a local clock based on one, some, or all of the received messages. The end station may or may not distinguish between the messages based on the clock source. The end station may validate messages received from a particular clock source.


