Method and system for providing time-critical services

By building isolated software containers and virtual IP stacks in industrial automation systems, combined with directory service components and aggregator components, the reliability issues of service identification and provision in container virtualization environments are solved, and efficient and reliable deployment and management of time-critical services are achieved, which is suitable for time-sensitive networks of industrial automation systems.

CN116210215BActive Publication Date: 2025-09-23SIEMENS AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180053348.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-08-31
Filing Date
2021-06-30
Publication Date
2025-09-23
Estimated Expiration
2041-06-30

AI Technical Summary

Technical Problem

In industrial automation systems, especially in container virtualization environments, existing service identification methods have difficulty in reliably discovering and providing time-critical services, resulting in communication interruptions and service quality degradation, especially when transmitting real-time data streams in Ethernet communication networks.

Method used

By forming an isolated software container on the host operating system of the server device, building a virtual IP stack and a virtual switch, combining the directory service component and the aggregator component, forming a side channel and an aggregator component, reliable discovery and provision of services are achieved, and rapid deployment and management of multiple similar or identical server components are supported.

Benefits of technology

It achieves the reliable provision of time-critical services in a container virtualization environment, reduces system integration costs, improves the efficiency and reliability of service discovery, supports rapid application deployment and management, and is suitable for time-sensitive networks in industrial automation systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116210215B_ABST
    Figure CN116210215B_ABST
Patent Text Reader

Abstract

In order to provide time-critical services, the services are each assigned at least one server component (111, 121), which is formed by a software container that can be loaded into a process control environment (102) and executed there. A virtual IP stack is provided for each server component, which is connected to a virtual switch (104) included in the process control environment. The services also each include a directory service component (112, 122) for determining the services provided within the process control environment. The directory service components are connected to each other via a communication interface (105) that is separate from the virtual switch and the virtual IP stack of the server components. An aggregator component (131) formed by a further software container is connected to the separate communication interface and makes comparative information about the services provided by the server components available outside the process control environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and a system for providing time-critical services, in particular in industrial automation systems. Background Art

[0002] Industrial automation systems typically consist of numerous automation devices interconnected via industrial communication networks and used to control or regulate facilities, machines, or equipment within the context of production or process automation. Due to the time-critical nature of industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, Real-Time Ethernet, or Time-Sensitive Networking (TSN) are primarily used for communication between automation devices. Control services or control applications can be automatically and workload-dependently distributed across available servers or virtual machines in the industrial automation system.

[0003] Interruptions in communication connections between computer units in industrial automation systems or automation devices can result in unwanted or unnecessary repetition of service request transmissions. In addition, untransmitted or incompletely transmitted messages can prevent the industrial automation system from transitioning to or remaining in a safe operating state.

[0004] Problems can arise in Ethernet-based communication networks when network resources used to transmit data streams or data frames with real-time requirements are used to compete for the transmission of data frames with large user data content but without specific quality of service requirements. Ultimately, this can result in the data streams or data frames with real-time requirements not being transmitted with the requested or required quality of service.

[0005] An earlier international patent application, PCT / EP2020 / 063144, discloses a method for providing a control application. A monitoring device retrieves the communication network address of a process control component providing the control application, along with an identifier of the process control component or a server device on which the process control component is implemented. A configuration control device generates configuration information for a forwarding device based on the retrieved communication network address and identifier, as well as the name of the control application. The forwarding device receives a request from a terminal to use the control application and forwards it to the corresponding process control component based on the configuration information.

[0006] An earlier European patent application with the application number 19166203.0 describes a method for automatically configuring an automation device, in which a device management unit monitors whether an automation system identifier has been assigned to the automation device. If the device management unit detects such an assignment, it queries the central management unit of the cluster whether a description object storing the automation system identifier assigned to the automation device already exists in a cluster state database comprising description objects for at least one node of the cluster. If no such description object exists, or if such a description object exists but is declared inactive, the device management unit generates a description object in the cluster state database for the node identifier assigned to the automation device, with the automation identifier assigned to the automation device stored in this description option.

[0007] Existing service identification methods (service / device discovery), particularly for OPC UA, are primarily designed to identify services that can be used with the help of hypervisor-based physical or virtual machines. In particular, the relatively high operating and maintenance costs of hypervisor-based virtual machines make virtualization concepts with lower resource requirements, such as container virtualization, increasingly attractive compared to complete system virtualization. This also applies to industrial automation systems.

[0008] The OPC UA specification provides a Local Discovery Server (LDS) for OPC UA-based services. However, using appropriate discovery methods, only hosts within a broadcast domain can be discovered. Furthermore, multicast communication within systems used for container virtualization is often blocked. Summary of the Invention

[0009] The object of the present invention is to provide a method for providing time-critical services, which method enables users to reliably determine services provided by means of container virtualization or similar virtualization concepts, and to specify a suitable device for carrying out the method.

[0010] According to the method for providing time-critical services of the present invention, each service includes at least one server component, each of which is implemented as a software container. This software container runs within a process control environment on a host operating system of a server device, isolated from other software containers or groups of containers. The process control environment includes a virtual switch, and each software container utilizes the kernel of the host operating system of the server device together with other software containers running on the corresponding server device. A virtual IP stack is provided for each server component, and this virtual IP stack is connected to the virtual switch.

[0011] The process control environment can include, for example, a Docker engine running on a server device. The memory image for the software container can be retrieved, for example, from a storage system and provisioning system accessible to multiple users for reading or writing.

[0012] According to the present invention, the services each additionally include a directory service component, formed as a separate software container, for deriving the services provided within the process control environment. The directory service components are connected to one another via a communication interface that is separate from the virtual switch and the virtual IP stack of the server component and forms a side channel for communication between the server component and the process control environment.

[0013] Furthermore, according to the present invention, an aggregator component, formed by a separate software container and connected to a separate communication interface, makes information about services provided by the server components available outside the process control environment. To this end, the aggregator component is provided with a virtual IP stack connected to a virtual IP switch. The directory service components compare information about the individually derived services with each other or with the aggregator component. The aggregator component provides the compared information outside the process control environment. Advantageously, the services or functions of the industrial automation system are provided by the server component services. A service can accordingly include multiple similar or identical server components, each provided by different server devices.

[0014] In particular, the present invention enables the simultaneous installation and execution of multiple applications provided by process control components without requiring configuration work or adjustments to the applications for user-initiated service identification. Consequently, providers of the corresponding applications, particularly providers of OPC UA server functionality, can significantly reduce system integration costs and thus offer applications quickly and cost-effectively.

[0015] The directory service components are advantageously generated when the server components are first started for the corresponding services. In addition, for example, the directory service components can be connected to each other by means of a bidirectional communication link for inter-process communication within the data processing device, or to each other by means of a separate transport layer, or to a directory service client assigned to the aggregator component. On this basis, the directory service components can compare information about the services obtained respectively with each other or with the directory service client. The comparison of the obtained services between the directory service components or with the directory service client can be carried out cyclically by means of polling or in an event-controlled manner. According to another advantageous design solution of the present invention, the separate communication interface includes a bidirectional communication connection and / or a transport layer connection for inter-process communication.

[0016] Based on the above design, according to the present invention, a process control environment is provided with the aid of a server device. Software containers can be individually migrated from a server device to another server device for execution there, or can be simultaneously executed on another server device. Preferably, a monitoring device assigned to multiple server devices detects the creation, deletion, or modification of software containers. The creation, deletion, or modification of software containers includes the allocation or release of resources in the corresponding server device. Furthermore, the monitoring device registers services with their respective execution states. This allows for the reliable orchestration of interdependent services.

[0017] A system for providing time-critical services according to the present invention is provided for executing the aforementioned method and includes a process control environment, a virtual switch included in the process control environment, and a plurality of server components, each of which is included in the service. The server components are each implemented as a software container, which is designed and configured to run within the process control environment on a host operating system of a server device, isolated from other software containers or groups of containers, and to share the host operating system's kernel with the other software containers running on the server device. The server components are each provided with a virtual IP stack, which is connected to the virtual switch.

[0018] Furthermore, the system according to the present invention includes a plurality of directory service components, each of which is additionally included in the service, and is used to retrieve services provided by the process control environment. The directory service components are each implemented as a separate software container. Furthermore, the directory service components are interconnected via a communication interface that is separate from the virtual switch and virtual IP stack of the server component and forms a side channel for communication between the server component and the process control environment.

[0019] Furthermore, according to the present invention, an aggregator component is provided, formed by means of a separate software container, which is connected to a separate communication interface and is therefore designed and configured to make information about services provided by the server components available outside the process control environment. The aggregator component comprises a virtual IP stack connected to a virtual IP switch. Furthermore, the directory service components are each designed and configured to compare information about the services provided with each other or with the aggregator component. Accordingly, the aggregator components are designed and configured to provide the compared information outside the process control environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The present invention will be explained in more detail below with the aid of the embodiments shown in the accompanying drawings.

[0021] Figure 1The schematic diagram shows an arrangement having a server device for providing services of an industrial automation system or a control and monitoring application to at least one user of a terminal device via a communication network. DETAILED DESCRIPTION

[0022] The arrangement shown in the figure includes a server device 100 having multiple virtual hosts 110, 120, and 130, which are used to provide services or control and monitoring applications for industrial automation systems. The services or control and monitoring applications for industrial automation systems are exemplary time-critical services. In this embodiment, the services or control and monitoring applications are provided based on OPC UA.

[0023] Therefore, the service or the control and monitoring application comprises an interface definition, which can be used to permanently access the service or the control and monitoring application.

[0024] A service can include multiple similar or identical control and monitoring applications, each provided by different server devices or virtual hosts. By providing multiple similar control applications on different server devices or via different virtual hosts, for example, the monitoring device 300 can be controlled using Kubernetes Daemon Sets, which are administratively assigned to the server devices or virtual hosts.

[0025] The arrangement shown in the figure also includes at least one terminal 500, which is assigned to at least one user and, in the present embodiment, sends a request 501 for using a service to a server device 100 via a communication network 400 in accordance with OPC UA and correspondingly receives a response 502 or measured value and status information from the server device. The communication network 400 is preferably in the form of a time-sensitive network, in particular in accordance with IEEE 802.1Q, IEEE 802.1AB, IEEE 802.1AS, IEEE 802.1BA, or IEEE 802.1CB.

[0026] Virtual hosts 110, 120 preferably implement the functionality of a control device of an industrial automation system, such as a programmable logic controller, or a field device (e.g., a sensor or actuator). In this embodiment, virtual hosts 110, 120 are used to exchange control and measurement parameters with machines or devices 301-302 controlled by server device 100 or virtual hosts 110, 120. In particular, virtual hosts 110, 120 are configured to derive appropriate control parameters from detected measurement parameters.

[0027] In the present embodiment, terminal 500 is an operating and monitoring station and is used to visualize process data or measurement and control parameters processed or detected by server device 100, virtual hosts 110, 120, or other automation devices. In particular, terminal 500 is used to display values ​​of control circuits and to change control parameters or control programs.

[0028] Each service includes at least one server component 111, 121, which is formed by a software container that runs in isolation from other software containers or container groups within a process control environment 102 on a host operating system 101 of a server device 100. Typically, the software container, together with the other software containers running on the respective server device, uses the kernel of the host operating system of the server device.

[0029] The process control environment 102 includes a virtual switch 104. Conversely, server components 111, 121 are provided with virtual IP stacks 113, 123, which are connected to the virtual switch 104 and configured to process a communication protocol stack. In the present exemplary embodiment, the virtual switch 104 is formed using the IP stack 103 assigned to the process control environment 102, which is configured to process a communication protocol stack.

[0030] The process control environment 102 is provided by means of the server device 100 and is installed there as an application on the host operating system 101 of the server device 100. Furthermore, software containers can be migrated from the server device 100 to other server devices for similar or simultaneous execution on other server devices.

[0031] Isolation of software containers from virtual hosts 110, 120, 130, or isolation of selected operating systems from one another can be achieved, in particular, through control groups and namespaces. Control groups can be used to define groups of processes in order to limit the resources available to selected groups. Namespaces can be used to isolate or hide individual processes or control groups from other processes or control groups. For example, a storage image for a software container can be retrieved from a storage and provisioning system that has read or write access to a large number of users.

[0032] To provide services within the process control environment 102, the services additionally each include a directory service component 112, 122, each formed as a separate software container. The directory service components 112, 122 are connected to one another via a communication interface 105, which is separate from the virtual switch 104 and the virtual IP stack 113, 123 of the server components 111, 121 and forms a side channel for communication between the server components 111, 121 and the process control environment 102.

[0033] Furthermore, an aggregator component 131 is connected to the separate communication interface 105 and is formed using a separate software container. Information about services provided by the server components 111 and 121 is made available outside the process control environment 102 or outside the server device 100. The directory service components 112 and 122 compare the information about the services thus obtained with each other or with the aggregator component 131. The aggregator component 131 provides the compared information outside the process control environment 102 or outside the server device 100. In particular, this compared information can be retrieved by a user of the terminal device 500.

[0034] A virtual IP stack 132 is provided for the aggregator component 131 and is connected to the virtual IP switch 104. In the current embodiment, the virtual host 130 includes the aggregator component 131 and its virtual IP stack 132. Specifically, when the software container is loaded into the process control environment 102 and executed there, the virtual host 130 is formed by means of the software container for the aggregator component 131.

[0035] When the server components 111, 121 are started for the first time for the corresponding service, the directory service components 112, 122 are generated. In the present embodiment, the software containers of the server components 111, 121 (including their virtual IP stacks 113, 123) and the software containers of the directory service components 112, 122 form the virtual hosts 110, 120 when these are loaded into the process control environment 102 and executed there.

[0036] Directory service components 112, 122 are preferably connected to each other and / or to a directory service client 131 assigned to the aggregator component via a bidirectional communication connection for inter-process communication within server device 100 and / or via a separate transport layer connection. Based on this, directory service components 112, 122 can compare information about the corresponding services with each other or with the directory service client. In particular, the bidirectional communication connection or transport layer connection for inter-process communication includes a communication interface 105 that is separate from the virtual IP stacks 113, 123 and virtual switch 104 of server components 111, 121.

[0037] The arrangement shown in the figure also includes a monitoring device 300, assigned to server devices 100, for example, within a computer cluster. Monitoring device 300 uses corresponding monitoring tasks 301 to detect the creation, deletion, or modification of software containers or Kubernetes pods comprised by the software containers, and uses the corresponding feedback of their execution status 302 to register services or control and monitoring applications. Monitoring device 300 is preferably designed as a Kubernetes API server. In this embodiment, the creation, deletion, or modification of software containers or pods specifically involves the allocation or release of resources in the corresponding server devices.

Claims

1. A method for providing a time-critical service, wherein The services each comprise at least one server component (111, 121), which is formed by a software container, which runs within a process control environment (102) on a host operating system (101) of the server device (100) in isolation from other software containers or container groups, wherein: The process control environment includes a virtual switch (104), and the software containers each use a kernel of the host operating system of the server device together with another software container running on the corresponding server device. - providing a virtual IP stack (113, 123) for each of the server components, wherein the virtual IP stack is connected to the virtual switch (104), - the service additionally comprises a directory service component (112, 122) formed by a separate software container, the directory service component being used to retrieve services provided within the process control environment, wherein the directory service components are connected to one another via a communication interface (105), the communication interface being separate from the virtual switch and the virtual IP stack of the server component and forming a side channel for communication between the server component and the process control environment, - an aggregator component (131) formed by means of a further software container connected to a separate communication interface (105), information about the services provided by means of the server component being available outside the process control environment, - comparing information about the respectively derived services between the catalog service components and / or between the catalog service component and the aggregator component, - the aggregator component provides comparative information outside of the process control environment, - providing the aggregator component (131) with a virtual IP stack (132), said virtual IP stack being connected to the virtual switch (104).

2. The method according to claim 1, wherein The directory service components (112, 122) are respectively generated when the server components (111, 121) are started for the first time for the corresponding services.

3. The method according to claim 1 or 2, wherein The directory service components are each connected to one another and / or to a directory service client assigned to the aggregator component by means of a bidirectional communication connection for inter-process communication within the data processing device or by means of a separate transport layer connection.

4. The method according to claim 3, wherein: The separate communication interface includes a bidirectional communication connection for the inter-process communication and / or the transport layer connection.

5. The method according to claim 1 or 2, wherein: The process control environment (102) is provided by means of a server device (100), wherein the software containers can be respectively migrated from the server device to another server device for execution there and / or the software containers can be executed simultaneously on another server device.

6. The method according to claim 5, wherein: A monitoring device (300) assigned to a plurality of server devices detects the creation, deletion and / or change of the software container and registers the service with the corresponding execution status of the creation, deletion and / or change of the software container, and wherein the creation, deletion and / or change of the software container respectively includes the allocation or release of resources in the corresponding server device.

7. The method according to claim 1 or 2, wherein: The memory image for the software container can be retrieved from a storage system and a provisioning system that is accessible to a large number of users and can be read from and / or written to.

8. The method according to claim 1 or 2, wherein: Services and / or functions of the industrial automation system are provided by means of the server components.

9. The method according to claim 8, wherein The services each include a plurality of similar or identical server components, and the service components are respectively provided by different server devices.

10. A system for providing time-critical services, comprising: -Process Control Environment (102); - a virtual switch (104) included in the process control environment; - a plurality of server components (111, 121), each of which is comprised by a service and each of which is formed by a software container, wherein the software container is designed and arranged to run in isolation from other software containers or container groups within a process control environment (102) on a host operating system (101) of a server device (100) and to use the kernel of the host operating system together with the other software containers running on the server device, wherein: The server components each have a virtual IP stack (113, 123), and the virtual IP stack is connected to the virtual switch; a plurality of directory service components (112, 122), each of which is additionally comprised by a service and formed by means of a separate software container, for deriving services provided within the process control environment, wherein the directory service components are connected to one another via a communication interface (105), which is separate from the virtual switch and the virtual IP stack of the server component and forms a side channel for communication between the server component and the process control environment; an aggregator component (131) formed by means of a further software container and connected to a separate communication interface and designed and arranged to make information about services provided by means of the server component available outside the process control environment, wherein the aggregator component (131) has a virtual IP stack (132) connected to the virtual switch (104); wherein the directory service components are each designed and configured to compare information about the respectively determined services with one another and / or with the aggregator component, - wherein the aggregator component is designed and arranged to provide comparative information outside of the process control environment.

Citation Information

Patent Citations

  • Method, software agent, networked device and SDN-controller for software defined networking a cyber-physical network of different technical domains, in particular an industry automation network

    CN109845201A

  • Method for operating an automation system and automation system operating according to the method

    CN110622131A