Background technology
It is general mainly comprising Vehicle Controller, zone controller, data storage list in current rail traffic control system
Member, interlock device etc..These equipment based on safety computer platform, it is grouped together into a Train Detection and Identification and prevents
Protecting system.But these equipment are all in the cycle of operation work oneself fixed, such as the cycle of operation of certain mobile unit
200ms, the cycle of operation of certain zone controller is 400ms.
It is main to use fpga chip or embedded chip to be controlled as core in common 2oo2 safety computer platforms
Device carrys out the dividing system cycle of operation, mainly there is following several ways:Cycle division is fixed based on clock, each cycle, which is sent, to be referred to
Control main frame etc. is made to run;Cycle is fixed based on clock, each cycle carries out microcycle division, each or some microcycles again
Send instruction control main frame operation.
Each equipment is set at a fixed cycle, the principle one of this cycle design in train operation control system
As be that system processing power meets that the train quantity of railroad embankment is maximum and required.Premise of the cycle of equipment in meet demand
Under, what can typically be designed is bigger than normal, such as completely runs at most operation n trains, and the design section controller cycle of operation is m millis
Second.But assume only to have run n/2 trains during actual operation, the zone controller cycle of operation remains as m milliseconds, so each cycle
In may process computing the m/3 times, other times are all idle and waited.This is a kind of waste of process performance,
Drag the reaction time of slow equipment and system.
When equipment is run with a fixed cycle, the reaction time minimum of this equipment is the time of a fixed cycle.
When normal operation, various instructions are performed according to normal loop cycle.Although normal perform can also have data
Delay, but the operation of whole system is not influenceed.But when breaking down, the equipment of these fixed cycles from trouble point to
When central apparatus or neighbouring device report failure, a bigger delay is just had.
What this delay occurred is the reaction time accumulation of every aspect equipment at all.For example, some sets when rows of cars
Standby failure causes brake hard, and mobile unit needs to warn center personnel to handle or inform the urgent of this car of fore-aft vehicle at once
During state, failure exported in the cycle end of mobile unit, can now be calculated as a process cycle delay.Between car and car
There is no direct communication path, fault message is sent to zone controller by usually fault car, by zone controller one
After the processing of the individual cycle of operation, then the mobile authorization after processing is transmitted to Adjacent vehicles, rear car at least after a cycle
Newest control result can be exported.This is a longer information transmission processing path, about includes the intrinsic processing week of 3 equipment
Phase.This path is exactly the reaction treatment bottleneck of emergency, and the bottleneck of system running speed.
Although existing method realizes the security incident response of train operation control system, but still has some problems not solve
Certainly, as in equipment running process, equipment performance is underused, it is more containing free time in the cycle;The overall failure of system
Response time can be elongated because of the accumulation of fixed cycle;A kind of complete loop cycle verification scheme etc. is not formed.
The content of the invention
The present invention provides a kind of adaptive cycle dynamicses design method designed suitable for 2oo2 safety computer platforms, should
Method can realize the features such as security platform equipment periodic adjust automatically, real time fail processing, loop cycle self checking, ensure week
Equipment processing speed is greatly improved while the correctness of phase circulation.
According to above-mentioned purpose, the invention provides a kind of cycle dynamicses design method of 2oo2 safety computer platforms, institute
The method of stating includes:
S1, the control device of the 2oo2 safety computer platforms proceed by micro- after microcycle sign on is sent
The timing of gate;
S2, after the microcycle is received within the time limit in microcycle completing signal, terminate the microcycle, and under starting
One microcycle.
Wherein, the step S2 also includes:
When the control device receive microcycle complete signal and judge the microcycle complete result it is incorrect or
When the microcycle completion signal is not received within the time limit of setting, the control device dwelling period circulation.
Wherein, the microcycle sign on is sent to the processing unit of connected main frame by the control device,
And the processing unit starts to perform the microcycle after the microcycle sign on is received.
Wherein, also include before the step S1:
The control device is initialized with the processing unit, and the processing unit initialization complete after to
After the control device sends initialization completion signal, the timing in initial latency time limit is then carried out, if in the initial latency time limit
The interior control device does not export microcycle sign on or the processing unit does not receive the microcycle sign on,
Then the processing unit judges control system failure, and failure to the safe side output state, otherwise performs step S1.
Wherein, also include before the step S1:
Before the control device sends the microcycle sign on to the processing unit, the microcycle is opened
Beginning instruction is verified, and when verification is correct to the microcycle sign on, the microcycle sign on is sent into institute
Processing unit is stated, otherwise dwelling period circulates.
Wherein, after the processing unit terminates each microcycle, start waiting for the timing in time limit, with etc. it is to be received described
Next microcycle sign on that control device is sent.
Wherein, the control device is fault-tolerant and security managing unit.
According to another aspect of the present invention, there is provided a kind of control device for 2oo2 safety computer platforms, it is described
Control device includes:
Instruction sending unit, for sending microcycle sign on;
Timing unit, for carrying out timing after microcycle sign on is sent, and judge whether micro- week more than setting
In time limit phase, terminate to run if more than if;
Signal receiving unit, for receipt completion signal, and judge whether to terminate this microcycle, carry out next micro- week
Phase.
Wherein, the control device also includes:
Verification unit, the microcycle sign on for being sent to the instruction sending unit verify.
Adaptive the cycle dynamicses design method and system of the 2oo2 safety computer platforms of the present invention, ran in equipment
Equipment performance is made full use of in journey, dynamically each cycle is adjusted, is disposed and starts next in a cycle
The processing in cycle so that the response time of each equipment shortens, and then the overall failure response time of system greatly shortens;And lead to
Processing unit and FTSM loop cycle process interactions are crossed, forms a kind of loop cycle system by time constraints, so as to
The features such as realizing security platform equipment periodic adjust automatically, real time fail processing, loop cycle self checking, significantly improves system
Operation disposal ability, shorten the fault reaction time, improve security of system.The even a whole set of train fortune of machine platform is calculated for safety reasons
The high speed of row control system, efficient, reliability service etc. lay good basis.
Embodiment
Below in conjunction with accompanying drawing, embodiments of the present invention is described in detail.
In the present embodiment, controlled using fault-tolerant and security managing unit (FTSM) as the core of safety computer platform
Device, but be not restricted to that using FTSM, other have the controller of said function equally within the scope of the restriction of the present invention.
Fig. 1 shows the processing unit of two redundancies in 1 system in the 2oo2 safety computer platforms of embodiments of the invention
With FTSM connection diagram.
Reference picture 1, FTSM are connected by Ethernet (but being not limited to ethernet communication mode) with the controlled main frame of needs,
And cycleoperation is sent to processing unit by Ethernet and instructed, performed also by Ethernet reception processing unit and complete feedback.
Wherein, processing unit is that the computer based on business complete machine (but is not limited to computer, can be flush bonding module
Deng);FTSM core controller is programmed using programming device such as embeded processor or FPGA, when can complete to be based on
Cycle division, instruction distribution, time limit counting and the loop cycle verifying work of clock.
Fig. 2 shows the loop cycle of the adaptive cycle dynamicses design method of the 2oo2 safety computer platforms of the present invention
Schematic diagram.
The method of the present invention needs to define in whole cycle circulation process according to design requirement, during each Cycle Length maximum
Limit, each microcycle maximum time limit, main frame wait instruction time limit, and the instruction definition in each cycle.Then FTSM is according to place
The signal instruction of unit Real-time Feedback is managed, dynamically adjusts the end time in each microcycle.
Specifically, FTSM controls the circulation main steps in cycle, and processing unit one side is controlled by FTSM loop cycle
Host process, on the one hand by " waiting the time limit " auxiliary constraint main steps.It is interrelated and constrained each other can protect between each process
System failure to the safe side is exported in time under card occurrence count timeout case
With reference to Fig. 1 and 2, connected and operated to FTSM with the processing unit of two redundancies in 1 system in safety computer platform
Example, its loop cycle specifically include:
After device power, each several part is required for entering by upper an electricity and initialization procedure, setting FTSM loop cycles
Journey is host process, and its toggle speed is faster than processing unit toggle speed, so ensures that " the main frame that processing unit is sent will not be omitted
Synchronizing signal ".Processing unit is initialized successfully and after sending synchronizing signal, then starts " initial latency time limit " timing of oneself,
FTSM must export cycle sign within the time limit, otherwise processing unit decision-making system fault-safety principle output shape itself
State.
After the completion of initial synchronisation, host process proceeds by loop cycle, and the cycle 1 starts.Cycle 1 is divided into n microcycle, first
The counting in microcycle 1 is first carried out, and sends " microcycle 1 instructs " simultaneously.Processing unit starts to perform after receiving instruction, performs
After the completion of return " perform complete instruction 1 ".When host process detects the feedback of two processing units within the time limit, it is necessary to confirm
Whether the result of processing unit is correct, and dwelling period circulates and exports system failure to the safe side if mistake, if just
It is true then terminate this microcycle and automatically begin to the operation in microcycle 2.Within the cycle 1 n micro- weeks are completed according to this cyclic process
The circulation of phase, and start the cycle 2 and circulate, similarly later.
In addition, when carrying out the microcycle, when host process does not receive the completion of processing unit transmission within the time limit of setting
During signal, FTSM dwelling periods circulate and export system failure to the safe side.
, it is necessary to there is one to wait the time limit to wait FTSM next microcycle after each microcycle main frame is finished
Sign on.The failure that can so prevent FTSM host process mistakes from causing main frame not run, main frame can pass through this simultaneously
Time limit judges whether to enter Safety output pattern.In general, this waits network delay of the time limit based on Intranet, stand-by period amount
Level is Millisecond.
The time that processing unit performs depends primarily on computing power and data volume, and performance height is then held when data volume is consistent
Row is fast, and performance is low then to be performed slowly;When computing power is consistent, the small then processing of data volume is fast, and data volume then automatically prolongs greatly the cycle,
But not exceed the maximum cycle time limit.Once more than " the time limit counting " in microcycle and cycle, FTSM is then actively by processing unit
Handled to ensure Safety output.Based on data volume and computing power difference, FTSM can be made suitable with adjustment period length
Answering property changes, while remains time limit monitoring function.
Counted and can mutually constrained based on the time limit between processing unit and FTSM, ensureing can be timely after the failure of system
It was found that.But the loop cycle host processes of FTSM in itself are in leading position, it is necessary to make verification for the correctness of this process
And troubleshooting.
Fig. 3 shows the microcycle verification schematic diagram of the present invention.
Reference picture 3, in order to be verified to loop cycle, special loop cycle correction verification module is devised, independently of week
Outside phase loop-body.This module is a state machine, and it records all possible periodic state, and stores as needed
The cycle output operation note of multiple host process, and prejudge subsequent operation pattern.When loop-body needs execution, " cycle starts to refer to
Make " operation when, communicate first with correction verification module, correction verification module confirm this operator scheme with anticipation unanimously, then sending effectively makes
Can, host process starts the instruction of beginning from transmission this week.Otherwise, termination device is run to ensure that system failure to the safe side exports shape
State.
State machine receives " initial sync signal of processing unit " judgement system and the shape of microcycle 1 is directly entered after bringing into operation
State, now host process should also be expected the output in microcycle 1, the sign on of microcycle 1 is output to state machine first, state machine is sentenced
Disconnected correct then return normally exports enabled and is transferred to the state in next microcycle, and wait verifies next time.
Fig. 4 shows the specific implementation of the adaptive cycle dynamicses design method of the 2oo2 safety computer platforms of the present invention
The loop cycle schematic diagram of example.
Reference picture 4, by taking a zone controller 400ms a cycle as an example, calculated according to the fixed cycle, then microcycle 1
It is 100ms, the microcycle 2 is 200ms, and the microcycle 3 is 100ms, and whole cycle operation, which finishes, needs 400ms.And according to dynamic week
After phase is set, the time limit in microcycle is 100ms, 200ms, 100ms respectively, but because smaller actual perform of data volume is probably
According to the most long processing time in each cycle shown in accompanying drawing 3 and:20ms+5ms+50ms+5ms+10ms=90ms, thus calculate knot
The processing time of fruit arrangement known shortens obvious.
Assuming that in fixed cycle system, rear car learns front truck emergency brake signal and makes the reaction needs " front truck of this car
Export failure (200ms) "+" zone controller handles (400ms) "+" rear car processing information (200ms) "+" network delay
(20ms) "=820ms.And after using cycle dynamicses, it is assumed that the equipment reaction time shortens to original 1/4, then total elapsed time
220ms is shorten to, wherein network delay is fixed as 20ms, then the processing speed of system improves and ultimately results in fault reaction
Time shortens.
Fig. 5 shows a kind of structured flowchart of control device for 2oo2 safety computer platforms of the present invention.
According to another aspect of the present invention, there is provided a kind of control device for 2oo2 safety computer platforms, it is described
Control device includes:
Instruction sending unit 10, for sending microcycle sign on;
Timing unit 20, for carrying out timing after microcycle sign on is sent, and judge whether micro- more than setting
Gate, terminate to run if more than if;
Signal receiving unit 30, for receipt completion signal, and judge whether to terminate this microcycle, carry out next micro-
Cycle.
Wherein, the control device also includes:
Verification unit 40, the microcycle sign on for being sent to the instruction sending unit verify.
The adaptive cycle dynamicses design method of the 2oo2 safety computer platforms of the present invention, fills in equipment running process
Point equipment performance is utilized, dynamically each cycle is adjusted, be disposed in a cycle and start next cycle
Processing so that the response time of each equipment shortens, and then the overall failure response time of system greatly shortens;And pass through processing
Unit and FTSM loop cycle process interactions, form a kind of loop cycle system by time constraints, so as to realize peace
The features such as full platform device cycle adjust automatically, real time fail processing, loop cycle self checking, significantly improve the operation of system
Disposal ability, shorten the fault reaction time, improve security of system.Machine platform even a whole set of Train Detection and Identification is calculated for safety reasons
The high speed of system, efficient, reliability service etc. lay good basis.
Meanwhile the invention provides a kind of method of itself cycle verification, it is ensured that the correctness of loop cycle.Work as week
When phase circulation makes a mistake, controller can find mistake and carry out correction processing in itself.
Although being described in conjunction with the accompanying embodiments of the present invention, those skilled in the art can not depart from this hair
Various modifications and variations are made in the case of bright spirit and scope, such modifications and variations are each fallen within by appended claims
Within limited range.