Summary of the invention
The objective of the invention is to: in order to improve state synchronized reliability, real-time and the validity of main control unit hot backup system; Protection is professional to greatest extent is not interrupted, reduces because of main control unit CPU (central processing unit) resource, reduction system software complexity that pass-along message between main control board and the slave control board consumes, and a kind of novel a kind of main control unit Hot Spare implementation method and system based on the data sync controller are provided.
Main control unit hot backup system based on the data sync controller of the present invention is made up of the identical master control borad of two block structures, motherboard and an above business board; The data of master control borad, address bus, control signal link to each other with data address bus, the control pin of each business board through motherboard; Master control borad all is fixed on the motherboard through connector with each business board; Be responsible for communicating by letter as the master control borad of main usefulness with business board, and the control total system; Two master control borads are formed by central processing unit (CPU), backup arbitration unit, buses isolator, data sync controller; Central processing unit (CPU): control whole master control borad; The data bus of central processing unit, address bus and read-write, chip selection signal are connected with the data sync controller with the buses isolator of this master control borad respectively; Central processing unit is provided with a pin; Pulse heartbeat signal of this pin output is to backup arbitration unit, supplies backup arbitration unit to detect the CPU operate as normal of whether working; Backup arbitration unit: the primary and backup relation that is used for confirming two master control borads; In system when operation,, whether the heartbeat signal that is used to detect this master control borad is normal; When the work of this master control borad is undesired; This master control borad CPU stops to export heartbeat signal immediately; This moment, this backup arbitration unit notified this buses isolator to cut off being electrically connected of main control board and total system; And master control borad is set to alarm status, simultaneously former slave control board upgraded to main control board, and the notice buses isolator that upgrades to the new main control board of main control board is opened being electrically connected of this master control borad and system; Take over total system by new main control board, guaranteed professional uninterrupted normal operation; Buses isolator: be used for being electrically connected between opening/closing master control borad and the motherboard.Buses isolator has two ports; One of two ports link to each other with data, address bus and the control signal of the central processing unit of this master control borad, and the another port then links to each other with data, address bus and the control signal of business board, and the enable signal of buses isolator links to each other with the backup arbitration unit of this master control borad; When the bus enable signal is effective; Two ports are got through, and the data flow of two ports of direction control signal control bus isolator is when direction control signal when being high; Data flow direction be a port flow to the another port, otherwise then data flow is opposite; Data sync controller: be used for data sync between main control board and the slave control board; During business board data arrives main control board; The data sync controller transfers to slave control board simultaneously with the new business data; Make the time strict synchronism of the business datum that obtains between main control board and the slave control board, after main control board and slave control board obtain professional new data simultaneously, carry out identical treatment scheme; Make the state consistency of main control board and slave control board, accomplished main control board and slave control board state synchronized.
The data sync controller of master control borad of the present invention all adopts hardware to realize that the bus data of can running simultaneously has two bus ports that independently are used for reading and writing data, address strobe and signal controlling respectively.
The present invention also provides a kind of main control unit hot backup system main control unit heat backup method based on the data sync controller, may further comprise the steps:
(a) system powers on, and a backup arbitration unit confirms that according to system state the master of this plate uses, stand-by state:
Backup arbitration unit judges at first whether the other side's master control borad is the main state of using; If the other side's master control borad has been the main state of using; Then backup arbitration unit unconditionally is changed to stand-by state with this master control borad, if the other side's master control borad is a stand-by state, this backup arbitration unit detects " whether heartbeat signal is normal " of central processing unit; If normal, then this master control borad is changed to the main state of using; Otherwise, this master control borad is changed to stand-by state, and this master control borad of alarm prompt fault;
(b) corresponding buses isolator is electrically connected according to the bus that the master uses or standby opens or closes between this master control borad and the motherboard:
Be in the master and open this master control borad buses isolator with the master control borad in the state; Two ports of the buses isolator of this master control borad are got through; The data, address bus and the control signal that are central processing unit are communicated with business board data, address bus and control pin; Be in the master and weigh, can control total system with the operation that the master control borad in the state has obtained whole external bus; Simultaneously, the backup arbitration unit of this master control borad is closed reading and writing data, the address strobe port of this plate data sync controller, makes to be in to lead can only obtain data from external data bus with the master control borad in the state;
Another master control borad then is a stand-by state; The backup arbitration unit of this master control borad is closed the buses isolator of this master control borad; Two ports of this buses isolator all are blocked; Be data, address bus and control signal and business board data, address bus and the blocking-up of control pin of the central processing unit of this plate, the master control borad of stand-by state is abandoned the operation power of whole external bus, uncontrollable total system; Simultaneously; The master control borad backup arbitration unit of stand-by state is opened reading and writing data, the address strobe port of the data sync controller of this master control borad; Make the port data of this plate data sync controller come into force, make the master control borad of stand-by state obtain data from reading and writing data, the address strobe port of the data sync controller of this master control borad;
(c) after slave control board powered on, initiatively with the main control board contact, the request main control board sent " system status information ";
(d) after main control board is received " request transmitting system state " order that slave control board sends, start " initial data transfer module " system status information is sent to slave control board;
(e) slave control board starts the status data that " primary data is accepted module " receives the main control board transmission, accomplishes the initialization of slave control board state, makes its state consistent with main control board;
(f) after the above-mentioned completion of step; The reading and writing data of the data sync controller of slave control board, address strobe port obtain main control board from business board data deposit the data sync controller of slave control board in; Incense is read notebook data with master control borad from the read-write of this plate data sync controller data, address strobe port; Slave control board is identical with the data that main control board obtains; So main control board and slave control board are then carried out identical flow chart of data processing, realize the main control board and the slave control board state synchronized of main control unit.
(g) when the backup arbitration unit of main control board detects this master control borad operation irregularity; Promptly when the heartbeat signal of main control board central processing unit stops; The backup arbitration unit of main control board notifies the buses isolator of this master control borad to cut off this master control borad and external data, address bus and control signal; And this master control borad is changed to stand-by state, and this master control borad of alarm prompt fault;
When (h) subsequent use backup arbitration unit detects main control board and transfers stand-by state to; Immediately this master control borad is changed to the main state of using; Simultaneously; The backup arbitration unit of this master control borad enables the buses isolator of this plate, and two ports of this master control borad buses isolator are all got through, and promptly the data of the central processing unit of this master control borad, address bus and control signal are communicated with business board data, address bus and control pin; This master control borad has obtained the operation power of whole external bus, can control total system; Simultaneously; The backup arbitration unit of this master control borad is closed the reading and writing data address port enable signal of its data sync controller; The control port data of notebook data isochronous controller are invalid, make this master control borad obtain data from external data bus, and this master control borad upgrades to main control board; Take over former main control board and work on, the control total system.
System status information described in the inventive method comprises: loop trunks application status, digital junction state.
The transmission of system state data according to the invention and acceptance just power on the back execution once at slave control board.
Said data sync controller is separately all arranged in main control board according to the invention and the slave control board; When professional new data arrives the master control main board; The data sync controller copies to self storage unit according to the data synchronizing signal on the main control board with the business board data sync on the slave control board, and incense is read with master control borad.In the data sync controller relation of address and data fully and business board transfer to main control board address and data consistent.
The situation of main control board operation irregularity according to the invention comprises: the main control board that main control board program fleet, master control borad fault, hand-reset and a variety of causes cause restarts.
The present invention is through hardware circuit and combine software mode; Realize a kind of reliable main control unit Hot Spare; Improve synchronous efficiency and reliability between main control unit main control board and the slave control board, the postrun data of system/state renewal process is accomplished by hardware, need not software behind system's power-up initializing and accomplishes data/state renewal through the form of sending " data-message "; Improved resource utilization ratio; Reduce the complexity of system software, strengthened the real-time of active/standby state synchronized, and do not influenced normal communication service.Compare with prior art, the invention has the advantages that:
System and method of the present invention is to guarantee that business datum arrives main control board and slave control board simultaneously; Because main control board and slave control board are the synchronization gain business datums; And carried out identical program circuit; So the state of main control board and slave control board is consistent, also just realized the state backup of slave control board, in case the main control board operation irregularity to main control board; Immediately slave control board is switched to the master and use major state, take over former main control board and work on.Different with other master control borad backups is; The data sync mode that the transmission data that native system and method do not need central processing unit (CPU) between main control board and slave control board, not stop reach main control board and slave control board realizes main control plate thermal redundancy; The postrun Data Update of system does not rely on software and accomplishes; The master adopts duplicate hardware circuit with master control and subsequent use master control, uses identical application software, has reduced the complexity of Hot Spare.The data sync controller is based on the hardware circuit completion, has improved central processing unit (CPU) operational efficiency and resource utilization ratio, and has strengthened the real-time of backup, greatly reduces professional interrupted probability.
Embodiment
Below in conjunction with embodiment and contrast accompanying drawing the present invention is elaborated.
The main control unit hot backup system of present embodiment is made up of the identical master control borad of two block structures (master control borad A and master control borad B), motherboard and n business board.The data address bus of master control borad, control signal link to each other with data address bus, the control pin of each business board through motherboard.Master control borad and business board all are fixed on the motherboard through connector.Master control borad is responsible for communicating by letter with business board, and the control total system.
Master control borad A: form by central processing unit (CPU) A1, backup arbitration unit A2, buses isolator A3, data sync controller A4.As shown in Figure 1.
Master control borad central processing unit (CPU) A1 is common central processing unit, is responsible for the whole master control borad of control.The data bus of central processing unit A1, address bus and read-write, chip selection signal are connected with data sync controller A4 with buses isolator A3 respectively.Central processing unit A1 is provided with a pin, and a pulse of output (being commonly called as heartbeat signal) supplies active and standby stamping-out unit A2 to detect whether operate as normal of this master control borad A central processing unit A1 to backup arbitration unit A2 on this pin.
Backup arbitration unit A2 is used for confirming the primary and backup relation of two master control borads; In system when operation,, whether the heartbeat signal that is used to detect master control borad A is normal; When master control borad A works when undesired, the CPU of master control borad A stops to export heartbeat signal immediately, and this moment, backup arbitration unit A2 notice buses isolator A3 cut off being electrically connected of main control board A and total system, and master control borad A is set to alarm status.Simultaneously former slave control board (master control borad B) is upgraded to main control board; Notice buses isolator B3 opens being electrically connected of new main control board (master control borad B) and system; Take over total system by new main control board (master control borad B), guaranteed professional uninterrupted normal operation.
Buses isolator A3: be used for the bus between opening/closing master control borad A and the motherboard.Buses isolator A3 has A11 and two bus ports of A12, and bus enable signal and data direction control signal are arranged.When the bus enable signal was effective, A11 bus port and A12 bus port were got through.The data flow of data direction control signal control A11, A12 bus port.When direction control signal when being high, data flow direction be through the A11 port flow to the A12 port, otherwise data stream through the A12 port flow to the A11 port.The A11 port of buses isolator A3 links to each other with data, the address bus of central processing unit A1; The A12 port links to each other with data, the address bus of business board.The enable signal of buses isolator A3 links to each other with backup arbitration unit A2, and direction control signal links to each other with the read signal of central processing unit A1.
Data sync controller A4: be used for data sync between main control board and the slave control board.During business board data arrives main control board, the data sync controller transfers to slave control board simultaneously with the new business data.Make the time strict synchronism of the business datum that obtains between main control board and the slave control board.After main control board and slave control board obtain professional new data simultaneously, carry out identical treatment scheme, make the state consistency of main control board and slave control board, accomplished main control board and slave control board state synchronized.
The described data sync controller of present embodiment A4 is different with general data sync controller, and the notebook data isochronous controller adopts hardware to realize the bus data of can running simultaneously.Generally speaking, two central processing units are operated a logical outside parallel bus (can be expressed as data, the address bus of business board herein) simultaneously, will inevitably cause bus collision, cause bus work gross error.Notebook data isochronous controller A4 is made up of two sets of data read-writes, address strobe and control port and built-in shared drive zone; Two overlap independently, and port is A13 port and A14 port.A13 port data, address bus link to each other with data, the address bus of central processing unit A1; A13 port reads, write signal link to each other with the reading and writing signal of the central processing unit A1 of master control borad A, and the enabling of the backup arbitration unit A2 of A13 port enable signal and this plate exported signal and linked to each other.The data of A14 port, address bus link to each other with the data address bus of business board, and the read signal of A14 port is unsettled, and the write signal of A14 port links to each other with the read signal of business board, and the enable signal of A14 port links to each other with the enable signal of business board.A13 port and A14 port all can carry out read-write operation to built-in shared drive.
As shown in Figure 1, master control borad B and master control borad A structure are identical, are made up of central processing unit (CPU) B1, backup arbitration unit B2, buses isolator B3, data sync controller B4.Buses isolator B3 has B11 and two bus ports of B12, and bus enable signal and data direction control signal are arranged.Data sync controller B4 is made up of two sets of data read-writes, address strobe and control port and built-in shared drive zone; Two overlap independently, and port is B13 port and B14 port, and the B11-B14 port function of master control borad B and connected mode are all identical with master control borad A.That is: B13 port data, the address bus of data sync control B link to each other with data, the address bus of central processing unit B1; B13 port reads, write signal link to each other with the reading and writing signal of the central processing unit B1 of master control borad B; The enabling of the backup arbitration unit B2 of B13 port enable signal and this plate exported signal and linked to each other; The data of B14 port, address bus link to each other with the data address bus of business board; The read signal of B14 port is unsettled, and the write signal of B14 port links to each other with the read signal of business board, and the enable signal of B14 port links to each other with the enable signal of business board.
When master control borad A is in mainly when use state, backup arbitration unit A2 closes the A13 port Enable Pin of data sync controller A4, makes data sync controller A4 inefficacy.Master control borad B is in stand-by state; The B13 port Enable Pin of backup arbitration unit B2 activation data isochronous controller B4; At this moment; As long as master control borad A read-write external business plate data; The data that the data sync controller B4 of master control borad B can read master control borad A are automatically write by the B14 port in the built-in shared drive of data sync controller B4, and the central processing unit of slave control board (master control borad B) can fetch data through the B13 port reads of data sync controller B4, has realized the data sync between main control board and the slave control board.
Present embodiment related based on data sync controller main control unit heat backup method, can realize the main control board of main control unit and the state of slave control board are carried out synchronously, this method may further comprise the steps:
(1) system powers on, and backup arbitration unit confirms that according to system state the master of this master control borad uses, stand-by state.
As shown in Figure 2, backup arbitration unit judges at first whether the other side's master control borad is that the master uses state, uses state if the other side's master control borad has been the master, and then backup arbitration unit unconditionally is changed to stand-by state with this master control borad.If the other side's master control borad is a stand-by state, backup arbitration unit detects " whether heartbeat signal is normal " of central processing unit, if normal, then this master control borad is changed to the main state of using; Otherwise, this master control borad is changed to stand-by state, and this master control borad of alarm prompt fault.
This instance is illustrated with " master control borad A serve as main use state, master control borad B be stand-by state " a kind of situation, and other situation all can be implemented with reference to this situation.
(2) buses isolator is electrically connected according to the bus between main usefulness/standby this master control borad of opening/closing and the motherboard, and is as shown in Figure 3.
Because master control borad A is the main state of using; Backup arbitration unit A2 enables buses isolator A3; A11 port and the A12 port of buses isolator A3 are got through, and promptly the data of central processing unit A1, address bus and control signal are communicated with external devices (like business board) data, address bus and control pin.Master control borad A has obtained the operation power of whole external bus, can control total system.Simultaneously, backup arbitration unit A2 closes the A13 port enable signal of data sync controller A4, and the A13 port data of data sync controller A4 is invalid, makes master control borad A obtain data from external data bus.
Because master control borad B is a stand-by state; Backup arbitration unit B2 closes buses isolator B3; B11 port and the B12 port of buses isolator B3 are blocked, i.e. the data of central processing unit, address bus and control signal and external devices (like business board) data, address bus and the blocking-up of control pin.Master control borad B has abandoned the operation power of whole external bus, uncontrollable total system.Simultaneously, backup arbitration unit B2 opens the B13 port enable signal of data sync controller B4, and the B13 port data of data sync controller B4 comes into force, and makes master control borad B obtain data from the A13 port of data sync controller B4.
(3) after slave control board (being master control borad B) powered on, initiatively with main control board (master control borad A) contact, request master control borad A sent " system status information ".System status information comprises: loop trunks application status table, digital junction state table.
(4) after main control board (being master control borad A) is received " request transmitting system state " order that master control borad B sends, start " initial data transfer module " system status information is sent to slave control board
(5) slave control board (master control borad B) starts the status data that " primary data is accepted module " receives the main control board transmission, accomplishes the initialization of this slave control board state, makes its state consistent with main control board (master control borad A).
(6) after step (5) is accomplished; The B14 port of the data sync controller B4 of master control borad B deposits master control borad A the built-in shared drive of data sync controller B4 in from the data that external devices or integrated circuit board (like business board) obtain, and supplies master control borad B to fetch data from the B13 port reads of data sync controller B4.Because slave control board (master control borad B) is identical with the data that main control board (master control borad A) obtains, so master control borad A and master control borad B just carry out identical flow chart of data processing, has realized the main control board and the slave control board state synchronized of main control unit.
(7) when backup arbitration unit A2 detects master control borad A operation irregularity (heartbeat signal like central processing unit A1 stops); Backup arbitration unit A2 notice buses isolator A3 cuts off master control borad A and external data, address bus and control signal; And master control borad A is changed to stand-by state, and this master control borad of alarm prompt fault.
When (8) backup arbitration unit detects B and detects master control borad A and be stand-by state, immediately master control borad B is changed to the main state of using.Simultaneously; Backup arbitration unit B2 enables buses isolator B3; B11 port and the B12 port of buses isolator B3 are got through, and promptly the data of central processing unit B1, address bus and control signal are communicated with external devices (like business board) data, address bus and control pin.Master control borad B has obtained the operation power of whole external bus, can control total system.Simultaneously, backup arbitration unit B2 closes the B13 port enable signal of data sync controller B4, and the B13 port data of data sync controller B4 is invalid, makes master control borad B obtain data from external data bus.Master control borad B upgrades to main control board, takes over former main control board (master control borad A) and works on, the control total system.
Wherein, in the said step (1), said plate backup arbitration unit confirmed the main and standby relation of this plate according to system state, is to be accomplished by hardware circuit fully, and main control board and slave control board all have " backup arbitration unit " separately.
Wherein, in the said step (2), said buses isolator is by " arbitration control module " control, and buses isolator opens or closes the bus between local terminal master control borad and the bus according to the arbitration control module, and buses isolator is made up of hardware circuit.
Wherein, in the said step (3) (4) (5), the transmission of system state data and acceptance just power on the back execution once at slave control board.In execution in step (3) (4) (5), the data sync controller of master control borad A and master control borad B is not all worked
Wherein, in the said step (6), said data sync controller is separately arranged all in main control board and the slave control board.When professional new data arrived the master control main board, the data sync controller copied to self storage unit according to the data synchronizing signal on the main control board with the business board data sync on the slave control board, and incense is read with master control borad.In the data sync controller relation of address and data fully and business board transfer to main control board address and data consistent.
Wherein, in the said step (6), the data sync controller is meant the data sync controller on the slave control board, and the data sync controller of main control board is not worked, and the business datum of main board directly obtains from business board.
Wherein, in the said step (7), the situation of main control board operation irregularity comprises: the main control board that main control board program fleet, master control borad fault, hand-reset and a variety of causes cause restarts.
The above is merely preferred embodiment of the present invention, is not limited to the present invention, and is all within spirit of the present invention and principle, any modification of being made, is equal to replacement, improvement etc., all should be included within protection scope of the present invention.