Skip to content

Storage, LittleFS FIFO & MicroSD Dual-Mirror Architecture

The Aslandi Edge Converter is engineered to maintain complete data integrity in harsh industrial environments characterized by sudden power cuts, electrical brownouts, and intermittent connectivity. Its persistence model utilizes a dual-tier storage strategy: an internal wear-leveled flash queue and an external microSD authenticated mirror.


1. Storage Hierarchy Overview

flowchart TD
    Reading["Raw Meter Reading (Modbus RTU)"] --> Formatter["Telemetry Formatter (Schema v3 JSON)"]
    
    subgraph Tier1["Tier 1: High-Speed On-Chip Flash (4 MiB QSPI)"]
        LFS["LittleFS Wear-Leveled Ring Buffer
• 64 KiB dedicated partition
• Capacity: ~205,000 telemetry records
• Immediate commit on read"] ConfigBanks["Redundant Config Banks (Slot 1 & 2)
• Atomic two-phase write
• CRC32 / HMAC validation"] end subgraph Tier2["Tier 2: High-Capacity Removable Storage (MicroSD)"] SDMirror["Dual-Mirror Block Storage Engine
• Primary Block Copy (Bank A)
• Secondary Block Copy (Bank B)
• Monotonic Generation Counter
• AES-256-GCM authenticated tags"] end subgraph CloudUplink["Cloud Delivery & Retirement"] MQTTClient["MQTT QoS 1 Client (mTLS)"] end Formatter --> LFS Formatter --> SDMirror LFS -->|Drain Queue| MQTTClient MQTTClient -->|PUBACK Received| AckHandler["Retire Record from LittleFS FIFO"]

2. LittleFS On-Chip Circular FIFO Buffer

The internal flash contains a dedicated 64 KiB region formatted with LittleFS (a fail-safe, wear-leveled filesystem designed for microcontrollers):

  • FIFO Queue Capacity: Holds approximately 205,000 records in a compact binary-tagged ring format.
  • Downtime Buffering: At a standard 60-second polling interval for 10 meters, the internal flash queue provides over 14 days of offline storage without any cloud connectivity.
  • Transactional Pop Operation: Records are only unlinked/retired from the LittleFS FIFO after receiving explicit acknowledgment from the cloud MQTT broker (PUBACK). If power is lost mid-transmission, unacknowledged records remain safe in flash and are resent on boot.

3. MicroSD Dual-Mirror Block Architecture

For long-term audit logs and multi-month historical archives, the converter writes each telemetry block to the external microSD card using dual-mirror redundancy:

flowchart LR
    subgraph LogicalBlock["Logical Block N"]
        Payload["Telemetry Records + Timestamps"]
    end

    subgraph MirrorEngine["Dual-Mirror Block Controller"]
        GenCount["Increment Monotonic Generation Counter (e.g. Gen: 1042)"]
    end

    subgraph PhysicalSD["Physical MicroSD Sectors"]
        SectorA["Sector Copy A
'Gen: 1042 | Payload | AES-256-GCM Tag'"] SectorB["Sector Copy B
'Gen: 1042 | Payload | AES-256-GCM Tag'"] end LogicalBlock --> MirrorEngine MirrorEngine --> SectorA SectorA -->|Verification Success| SectorB

Generation Counter & Corruption Recovery

  1. Alternating Block Writes: When updating block $N$, the firmware writes to Copy A, checks write status, verifies the AES-256-GCM tag, and only then updates Copy B.
  2. Power-Loss During Write: If power cuts out while Copy A is being written, Copy B remains intact with generation $G-1$. On recovery, the firmware detects the generation mismatch, validates the GMAC tag of Copy B, and repairs Copy A automatically.
  3. Card Hot-Plug & Absence: If the microSD card is removed or damaged, the converter logs an SD_MISSING alarm to internal flash and continues operating exclusively from the LittleFS buffer without halting Modbus polling.

4. Redundant Flash Configuration Banks

Converter network parameters, meter addresses, poll intervals, and broker endpoints are persisted in two alternating configuration banks:

Slot NameAddress RangeStatus FlagValidation Scheme
Config Slot 10x3D0000 - 0x3DFFFFActive / CandidateCRC32 Header + Payload HMAC
Config Slot 20x3E0000 - 0x3EFFFFActive / BackupCRC32 Header + Payload HMAC
  • Two-Phase Commit: When changing parameters via the local panel, the candidate slot is erased, written, and validated. Only once the CRC32 and HMAC checks pass is the active bank pointer flipped.
  • Safe Fallback: If active bank corruption is detected during boot, the bootloader automatically reverts to the backup configuration bank and flags an administrative alert.