Storage, LittleFS FIFO & MicroSD Dual-Mirror Architecture
The Aslandi Edge Converter is engineered to maintain complete data integrity in harsh industrial environments characterized by sudden power cuts, electrical brownouts, and intermittent connectivity. Its persistence model utilizes a dual-tier storage strategy: an internal wear-leveled flash queue and an external microSD authenticated mirror.
1. Storage Hierarchy Overview
flowchart TD
Reading["Raw Meter Reading (Modbus RTU)"] --> Formatter["Telemetry Formatter (Schema v3 JSON)"]
subgraph Tier1["Tier 1: High-Speed On-Chip Flash (4 MiB QSPI)"]
LFS["LittleFS Wear-Leveled Ring Buffer
• 64 KiB dedicated partition
• Capacity: ~205,000 telemetry records
• Immediate commit on read"]
ConfigBanks["Redundant Config Banks (Slot 1 & 2)
• Atomic two-phase write
• CRC32 / HMAC validation"]
end
subgraph Tier2["Tier 2: High-Capacity Removable Storage (MicroSD)"]
SDMirror["Dual-Mirror Block Storage Engine
• Primary Block Copy (Bank A)
• Secondary Block Copy (Bank B)
• Monotonic Generation Counter
• AES-256-GCM authenticated tags"]
end
subgraph CloudUplink["Cloud Delivery & Retirement"]
MQTTClient["MQTT QoS 1 Client (mTLS)"]
end
Formatter --> LFS
Formatter --> SDMirror
LFS -->|Drain Queue| MQTTClient
MQTTClient -->|PUBACK Received| AckHandler["Retire Record from LittleFS FIFO"]
2. LittleFS On-Chip Circular FIFO Buffer
The internal flash contains a dedicated 64 KiB region formatted with LittleFS (a fail-safe, wear-leveled filesystem designed for microcontrollers):
- FIFO Queue Capacity: Holds approximately 205,000 records in a compact binary-tagged ring format.
- Downtime Buffering: At a standard 60-second polling interval for 10 meters, the internal flash queue provides over 14 days of offline storage without any cloud connectivity.
- Transactional Pop Operation: Records are only unlinked/retired from the LittleFS FIFO after receiving explicit acknowledgment from the cloud MQTT broker (
PUBACK). If power is lost mid-transmission, unacknowledged records remain safe in flash and are resent on boot.
3. MicroSD Dual-Mirror Block Architecture
For long-term audit logs and multi-month historical archives, the converter writes each telemetry block to the external microSD card using dual-mirror redundancy:
flowchart LR
subgraph LogicalBlock["Logical Block N"]
Payload["Telemetry Records + Timestamps"]
end
subgraph MirrorEngine["Dual-Mirror Block Controller"]
GenCount["Increment Monotonic Generation Counter (e.g. Gen: 1042)"]
end
subgraph PhysicalSD["Physical MicroSD Sectors"]
SectorA["Sector Copy A
'Gen: 1042 | Payload | AES-256-GCM Tag'"]
SectorB["Sector Copy B
'Gen: 1042 | Payload | AES-256-GCM Tag'"]
end
LogicalBlock --> MirrorEngine
MirrorEngine --> SectorA
SectorA -->|Verification Success| SectorB
Generation Counter & Corruption Recovery
- Alternating Block Writes: When updating block $N$, the firmware writes to Copy A, checks write status, verifies the AES-256-GCM tag, and only then updates Copy B.
- Power-Loss During Write: If power cuts out while Copy A is being written, Copy B remains intact with generation $G-1$. On recovery, the firmware detects the generation mismatch, validates the GMAC tag of Copy B, and repairs Copy A automatically.
- Card Hot-Plug & Absence: If the microSD card is removed or damaged, the converter logs an
SD_MISSINGalarm to internal flash and continues operating exclusively from the LittleFS buffer without halting Modbus polling.
4. Redundant Flash Configuration Banks
Converter network parameters, meter addresses, poll intervals, and broker endpoints are persisted in two alternating configuration banks:
| Slot Name | Address Range | Status Flag | Validation Scheme |
|---|---|---|---|
| Config Slot 1 | 0x3D0000 - 0x3DFFFF | Active / Candidate | CRC32 Header + Payload HMAC |
| Config Slot 2 | 0x3E0000 - 0x3EFFFF | Active / Backup | CRC32 Header + Payload HMAC |
- Two-Phase Commit: When changing parameters via the local panel, the candidate slot is erased, written, and validated. Only once the CRC32 and HMAC checks pass is the active bank pointer flipped.
- Safe Fallback: If active bank corruption is detected during boot, the bootloader automatically reverts to the backup configuration bank and flags an administrative alert.