Redundant Switching Unit for Reliable IEEE 1588 Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computer systems, existing methods for clock synchronization over Ethernet lack reliability, as faults in the modification of time-interval correction fields in synchronization messages can result in faulty messages being output, and existing solutions are not compatible with Ethernet standards, leading to challenges in establishing a fault-tolerant and fail-silent environment for real-time systems.

Innovation Solution

A switching unit composed of four fault-containment units (FCUs): an input system, two independent switching systems, and an output system, which processes synchronization messages by analyzing and modifying the time-interval correction field to identify and correct delays, ensuring that only correct messages or identifiable faulty messages are transmitted, utilizing a cut-through method to maintain message integrity and prevent storage-induced faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single switching unit modifies the TIC field in synchronization messages, then the device complexity is reduced, but the reliability deteriorates due to potential faults in message modification

Engineering Contradiction:
Improvereliability of synchronization message switchingVSAvoidcomplexity of switching unit structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The switching unit is segmented into four independent fault-containment units: input system EIN, two switching systems VER1 and VER2, and output system AUS. Each FCU processes synchronization messages independently, with VER1 and VER2 performing redundant TIC field modifications. This segmentation isolates faults to specific FCUs, preventing single-point failures and improving overall reliability without requiring a complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements redundant copying by having two independent switching systems VER1 and VER2 process the same synchronization messages simultaneously. Each system independently modifies the TIC field and generates output messages. The output system AUS then compares the results from both copies to detect and correct faults, ensuring high reliability through redundancy.

Inventive Principle:
Principle #26Copying

2Manufacturing precision

If synchronization messages are stored in the switching unit for processing, then the TIC field can be accurately modified, but faults may be introduced during storage

Engineering Contradiction:
Improveprecision of delay period determinationVSAvoidintegrity of synchronization message
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

The patent employs cut-through processing where synchronization messages are forwarded immediately from the input system EIN through the switching systems VER1 and VER2 to the output system AUS without being stored in buffers or memory. This rushing through the processing pipeline eliminates storage-induced faults while maintaining the ability to accurately modify the TIC field by calculating delay periods based on arrival times at different FCUs.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If fault detection mechanisms are added to the switching unit, then the reliability improves, but the device complexity increases

Engineering Contradiction:
Improvefault detection capabilityVSAvoidcomplexity of fault detection system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The output system AUS implements feedback by comparing the output messages from VER1 and VER2. When discrepancies are detected in the TIC fields or message contents, the system generates feedback signals to identify and correct faults. This feedback mechanism provides reliable fault detection without requiring complex external monitoring systems, as the redundancy within the existing structure enables self-diagnosis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9503521B2Method and switching unit for the reliable switching of synchronization of messages
Publication Date: 2016.11.22 TTTECH COMPUTERTECHNIK AG
  • US9503521B2 patent drawing
  • US9503521B2 patent drawing

AI summary

The invention relates to a method for the reliable switching of synchronization messages in a distributed computer system consisting of a number of node computers, wherein the management of a transparent clock conforming to IEEE Standard 1588 is supported, wherein a switching unit consists of four separate FCUs, specifically an input system EIN, two independent switching systems VER1 and VER2, and an output system AUS, and wherein a message arriving at EIN from a transmitting node computer is forwarded immediately in unmodified form from EIN directly to the two independent switching systems VER1 and VER2, and wherein VER1 provides the event of the arrival of the message with a timestamp, analyses the message and switches said message to (an) output port(s) associated with an address field of the message, and wherein VER1 opens the message and modifies a TIC field within the message in order to determine the delay period of the message in VER1, and wherein VER1 closes the message again by re-calculating a CRC field of the modified message and forwarding the closed message to AUS, and wherein VER2 provides the event of the arrival of the message with a timestamp, analyses the message and switches said message to the output port(s) associated with the address field of the message, and wherein VER2 opens the message and modifies the TIC field within the message in order to determine the delay period of the message in VER2, and wherein VER2 closes the message again by re-calculating the CRC field of the modified message and forwarding the closed message to AUS, and wherein AUS checks whether the content of the message delivered from VER1 matches the content of the message delivered from VER2, and wherein AUS checks whether the interval between the moment of receipt of the message delivered from VER1 and the moment of receipt of the message delivered from VER2 is smaller than a first interval determined a priori, referred to hereinafter as the interval_1, and whether the absolute value of the difference of the delay values stored in the two TIC fields is smaller than a second interval known a priori, referred to hereinafter as the interval_2, and wherein, in the case that one of these checks is negative, AUS interrupts the transmission of the message that is outbound via the addressed output ports or changes the outbound message in such a way that each message receiver identifies the incoming message as faulty.