A multi-entity-based multi-level redundancy control method and system

By controlling the entity cluster to negotiate and divide primary and backup redundant entities and generate redundant data objects, the problems of over-configuration of resources and large switching disturbances in the existing control system are solved, realizing flexible redundancy configuration and high-reliability switching, and reducing costs.

CN120722822BActive Publication Date: 2025-12-02ZHEJIANG SUPCON RES +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511221244.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-12-02
Estimated Expiration
2045-08-29

AI Technical Summary

Technical Problem

Existing redundancy design schemes for control systems suffer from problems such as over-allocation of resources, high cost, large switching disturbances, and low fault margin, making it difficult to make flexible adjustments based on differences in data reliability requirements.

Method used

By periodically negotiating with the control entity cluster, it is divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities. Redundant data object information is generated and synchronized. The data user entity verifies the data object according to the role identifier and validity, realizing the primary/standby switchover and the seamless switching of data objects.

Benefits of technology

It enables flexible configuration based on differences in data reliability requirements, reduces system costs, improves redundancy reliability and seamless switching, and ensures high reliability and economy of the control system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120722822B_ABST
    Figure CN120722822B_ABST
Patent Text Reader

Abstract

This invention relates to the field of industrial control automation technology, and particularly to a multi-entity, multi-level redundancy control method and system, comprising: S1: A control entity cluster periodically sends master-slave negotiation messages, and the control entities are divided into master control entities, hot standby control entities, and cold standby control entities according to the master-slave negotiation messages; S2: The master control entity and the hot standby control entity generate redundant data object information and synchronize the redundant data object information to the data user entity in real time; S3: The data user entity receives the redundant data objects sent by the master control entity and the hot standby control entity, and selects the redundant data object k1 generated by the master control entity first according to the data object role identifier. If k1 is invalid, the current master control entity is released, and the hot standby control entity is switched to the master control entity to ensure the ratio of master control entities to hot standby control entities. This invention ensures seamless switching of control entities, realizes effective data element replacement, and improves redundancy reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control automation technology, and in particular to a multi-entity multi-level redundancy control method and system. Background Technology

[0002] With the rapid development of communication technology, control systems are showing a significant trend towards automation and networking. Against this backdrop, to improve the reliability of control systems, traditional technologies typically employ redundancy design schemes, mainly encompassing cold standby redundancy, 1:1 hot standby redundancy, and triple or quadruple redundancy techniques.

[0003] In cold standby redundancy, the backup device remains dormant during operation. When the primary device fails, manual intervention is required to bring the backup device into operation, which limits the system's real-time response capability to some extent. 1:1 hot standby redundancy is based on nodes. During normal operation, the primary node handles system tasks, and if the primary node fails, the backup node immediately takes over. However, due to the time delay in switching between primary and backup nodes, a completely smooth, disturbance-free switch cannot be achieved, affecting the continuity and stability of system operation. While triple or quadruple redundancy schemes effectively solve the switching disturbance problem, the overall system availability decreases with the increase in the number of redundant nodes, while also significantly increasing hardware and maintenance costs. Furthermore, all the above redundancy systems are based on nodes. When the number of system failures exceeds the designed fault margin, even if the faulty nodes have different locations, the entire system will still fail, making it difficult to guarantee the continuous and stable operation of the control system.

[0004] In practical applications, the reliability and fault tolerance requirements of various input and output data in a control system differ significantly. While critical data is less numerous, it demands extremely high reliability; whereas most ordinary data has relatively lower reliability requirements. However, traditional redundant design schemes for control systems are difficult to change once the architecture is determined, as all data is processed using a uniform architecture. This forces the control system to be laid out according to the highest reliability requirements of critical data, resulting in over-allocation of system design resources, a significant increase in control system costs, and obvious shortcomings in terms of economy and practicality. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a multi-entity, multi-level redundancy control method, comprising the following steps:

[0006] S1: The control entity cluster periodically sends master-slave negotiation messages including the control entity ID, role status and priority. The n control entities are divided into 1 master control entity, m-1 hot standby control entities and nm cold standby control entities according to the master-slave negotiation messages.

[0007] S2: The main control entity and the hot standby control entity generate redundant data object information including data object role identifier, data object validity, data element and data element validity, and synchronize the redundant data object information to the data user entity q in real time;

[0008] S3: The data uses entity q to receive redundant data objects k1~k1 sent by the main control entity and the hot standby control entity. m Based on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first, and the validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1.

[0009] Preferably, in step S1, the n control entities are divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities according to the primary / standby negotiation message, including:

[0010] The control entity broadcasts the primary / backup negotiation message, including the IP address, within a preset event window;

[0011] The hot standby control entity with the highest priority weight is selected as the main control entity. If the priorities are the same, the one with the larger IP address wins as the main control entity. After the election, the main control entity sends a role allocation confirmation message to all control entities, including information on the generated redundant data objects and the validity of the data objects. The first m-1 control entities with the second highest priority are selected as the hot standby control entities, and the remaining control entities are selected as the cold standby control entities.

[0012] Preferably, in step S2, the main control entity and the hot standby control entity generate redundant data object information and synchronize the redundant data object information to the data user entity q in real time, including:

[0013] After updating its own data object, the master control entity sends a redundancy mutual exclusion message, including the data object version number and the redundant data object information, to the hot standby control entity.

[0014] After receiving the redundant mutual exclusion message, the hot standby control entity verifies the data object version number and data element. If they are inconsistent, it requests the main control entity to retransmit. If the verification passes, the hot standby control entity updates its own data object and returns an acknowledgment response. It also synchronizes the redundant data object information of all the hot standby control entities and the main control entity to the data user entity q in real time.

[0015] Preferably, the data object role identifier, data object validity, data element, and data element validity include:

[0016] The data object role identifier of the redundant data object information includes a primary control role or a hot standby control role, wherein the primary control role is a data object generated by the primary control entity, and the hot standby control role is a data object generated by the hot standby control entity;

[0017] The validity of the data object includes a timestamp and a checksum;

[0018] The data element is the actual data transmitted by the data object;

[0019] The validity of the data element is used to mark the trust status of a single data element and includes the data object priority. The control entity q selects the data object with higher priority to obtain the data based on the priority.

[0020] Preferably, in step S3, verifying the validity of the redundant data object k1 further includes:

[0021] Verify whether the main control role of the redundant data object k1 is valid. If the identifier format does not meet the preset requirements, the redundant data object k1 is determined to be invalid. Verify the signature and priority weight of the data object validity and verify the credibility of each data element.

[0022] If the main control role of the redundant data object is valid, the signature and priority weight verification pass, and all data elements are valid, then the redundant data object is considered completely valid. If the redundant data object k1 has some invalid data elements, but overall meets the usage requirements, then the redundant data object is considered partially valid. If the main control role of the redundant data object is invalid, the signature or priority weight verification fails, or the number of invalid data elements exceeds the threshold, then the redundant data object is considered completely invalid. Here, "overall meets the usage requirements" means that the invalid data elements of the redundant data object k1 are removed by selecting redundant data objects k2 to k3 of the hot standby control entity. m The valid data elements in the data are used to replace the invalid data elements, making the redundant data object k1 valid as a whole.

[0023] Preferably, in step S3, if the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1, further including:

[0024] When the redundant data object k1 is invalid, the data-using entity q sends an error response to the main control entity, and, based on the data object role identifier and data object validity priority, retrieves the redundant data objects k2 to k1 from the hot standby control entity. m-1 Select the hot standby data object;

[0025] In response to the error response, the main control entity releases its main control role, selects the hot standby control entity as the main control entity, and triggers the cold standby control entity to join the hot standby control entity group to maintain a 1:m-1 hot standby ratio.

[0026] Preferably, triggering the cold standby control entity to join the hot standby control entity group includes:

[0027] Available entities are selected based on the self-diagnostic results of the cold standby control entity;

[0028] Update the data object role identifier of the newly added hot standby control entity to hot standby status;

[0029] Send a hot standby group update notification to the data using entity q.

[0030] Based on the same concept, the present invention also provides a multi-entity, multi-level redundant control system, including:

[0031] The primary / standby negotiation module is used to control the entity cluster to periodically send primary / standby negotiation messages, including the control entity ID, role status, and priority. n control entities are divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities according to the primary / standby negotiation messages.

[0032] The redundant data object generation module generates redundant data object information, including data object role identifier, data object validity, data element and data element validity, and synchronizes the redundant data object information to the data user entity q in real time.

[0033] The data fault tolerance module receives redundant data objects k1 to k from the main control entity and the hot standby control entity via entity q. m Based on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first, and the validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1.

[0034] Preferably, verifying the validity of the redundant data object k1 further includes:

[0035] Verify whether the main control role of the redundant data object k1 is valid. If the identifier format does not meet the preset requirements, the redundant data object k1 is determined to be invalid. Verify the signature and priority weight of the data object validity and verify the credibility of each data element.

[0036] If the main control role of the redundant data object is valid, the signature and priority weight verification pass, and all data elements are valid, then the redundant data object is considered completely valid. If the redundant data object k1 has some invalid data elements, but overall meets the usage requirements, then the redundant data object is considered partially valid. If the main control role of the redundant data object is invalid, the signature or priority weight verification fails, or the number of invalid data elements exceeds the threshold, then the redundant data object is considered completely invalid. Here, "overall meets the usage requirements" means that the invalid data elements of the redundant data object k1 are removed by selecting redundant data objects k2 to k3 of the hot standby control entity. m The valid data elements in the data are used to replace the invalid data elements, making the redundant data object k1 valid as a whole.

[0037] Preferably, if the verification result is invalid, the current primary control entity is released, and the hot standby control entity is switched to the primary control entity to ensure that the ratio of the primary control entity to the hot standby control entity is 1:m-1, further including:

[0038] When the data object k1 is invalid, the data-using entity q sends an error response to the main control entity, and, based on the data object role identifier and data object validity priority, retrieves redundant data objects k2 to k1 from the hot standby control entity. m Select the hot standby data object;

[0039] In response to the error response, the main control entity releases its main control role, selects the hot standby control entity as the main control entity, and triggers the cold standby control entity to join the hot standby control entity group to maintain a 1:m-1 hot standby ratio.

[0040] Compared with the prior art, the beneficial effects of the present invention are:

[0041] This invention achieves a high redundancy architecture by controlling a cluster of entities to periodically send master-slave negotiation messages. Based on these messages, n control entities are divided into one master control entity, m-1 hot standby control entities, and nm cold standby control entities. Redundant data objects are generated by the n control entities, while lower-level data is generated by the master control entity, thus ensuring reliability and reducing costs.

[0042] This invention generates redundant data object information, including data object role identifier, data object validity, data element, and data element validity, through a main control entity and a hot standby control entity. The redundant data object information is synchronized to the data user entity q in real time, so that both the main control entity and the hot standby control entity send the redundant data object information to the control entity that uses the redundant data object. The data user entity q that uses the redundant data object information completes the deduplication and regeneration of the data.

[0043] This invention uses a data usage entity q to receive redundant data objects k1~redundant data objects k sent by the main control entity and the hot standby control entity. m-1 Based on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first. The validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1. This ensures that when the data object issued by the main control entity is invalid, the data from the backup hot standby control entity is switched immediately, thus ensuring a seamless switch. When a data element in the data object is invalid, it is replaced by a valid data element, thereby maximizing the redundancy reliability and providing high reliability and flexibility. Attached Figure Description

[0044] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention.

[0045] Figure 1 This is a flowchart of the multi-entity multi-level redundancy control method of the present invention;

[0046] Figure 2 This is a structural diagram of the multi-entity multi-level redundancy control method of the present invention;

[0047] Figure 3 This is a schematic diagram of redundant data object information in the multi-entity multi-level redundancy control method of the present invention;

[0048] Figure 4 This is a flowchart illustrating the verification process of the multi-entity, multi-level redundancy control method of the present invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention. Obviously, the described embodiments are only some, not all, of the embodiments described in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without creative effort are within the scope of protection of this application.

[0050] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a” and “an” used herein, and “the”, may also include the plural forms. It should be further understood that the term “comprising” as used in this specification means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0051] The technical terms involved in the embodiments of this invention are defined as follows:

[0052] 1. Control entity: It is the producer and consumer of data, as well as the carrier of data objects. It consists of an actual controller or a virtual program.

[0053] 2. Published Data Object: A data fragment is the smallest unit used by a control entity to publish data. It consists of a data object ID, alias, data, and data description. A published data object is generated by a source control entity and published to one or more target control entities through communication. The target control entities use the data of the published data object by running control logic.

[0054] 3. Data Object: A data fragment, the smallest unit used to control the interaction of data between entities. Each data object can independently define its sending and receiving mechanism to ensure that sending and receiving behavior has minimal impact on the controlling entity. Each data object has a unique identifier, and the controlling entity must provide a unique identifier when using data object data.

[0055] Example 1

[0056] This embodiment describes a graphical configuration method for collaborative parameters between multiple entities in a control system, applicable to field engineering projects such as ships, marine engineering, and engineering vehicles. It introduces the concept of a data object, visualizing the data to be published as a data object. A control entity generates the data object and publishes it to the control entities using the data. A visual connection is established between the two. Furthermore, this embodiment establishes a locking mechanism for multi-user use; the control entity being edited by the current user is automatically locked and marked, preventing other users from editing it and thus avoiding potential unintended modifications.

[0057] Please see Figure 1 and Figure 2 As shown in the figure, this embodiment provides a multi-entity-based multi-level redundancy control method, which includes the following steps:

[0058] S1: The control entity cluster periodically sends master-slave negotiation messages including the control entity ID, role status, and priority. The n control entities are divided into 1 master control entity, m-1 hot standby control entities, and nm cold standby control entities according to the master-slave negotiation messages. Specifically, in this embodiment, the m-1 hot standby control entities are hot standby control entities 2 to m. The role status is the current role of cold standby control entity, hot standby control entity, or cold standby control entity. The master control entity is the node with the highest priority. If the priorities are the same, the one with the smallest ID can be selected. The hot standby control entity is the node with the second highest priority. The cold standby control entities are the remaining nodes, which only listen and do not participate in fast switching.

[0059] Preferably, in step S1, the n control entities are divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities according to the primary / standby negotiation message, including:

[0060] The control entity broadcasts a primary / backup negotiation message, including the IP address, within a preset event window. Specifically, in this embodiment, the power-on control entity actively sends a primary / backup negotiation message to all nodes in the control domain. The primary / backup negotiation message also declares its own health status (hardware / software status score), performance metrics (CPU / memory utilization, etc.), and generates a list of data objects (including data object k).

[0061] The hot standby control entity with the highest priority weight is selected as the master control entity. If the priorities are the same, the one with the larger IP address wins as the master control entity. After the election, the master control entity sends a role allocation confirmation message to all control entities, including information on the generated redundant data objects and the validity of the data objects. The top m-1 control entities with the second highest priority are selected as hot standby control entities, and the remaining control entities are selected as cold standby control entities. Specifically, in this embodiment, the hot standby control entity selects the master and standby entities based on strategies such as health priority, performance priority, address priority, and custom priority.

[0062] With n=5, m=3, and the node priorities as follows, Node A has the highest priority, and Node A is selected as the main control entity:

[0063] Node A (ID=1, priority=100)

[0064] Node B (ID=2, priority=90)

[0065] Node C (ID=3, priority=90)

[0066] Node D (ID=4, priority=80)

[0067] Node E (ID=5, priority=70).

[0068] Furthermore, this embodiment implements a mechanism of 1 main control entity, m hot standby control entities, and n-m cold standby control entities, with a fault margin of n-1, meaning that the system will only fail if the invalid data elements in the data object k generated by the n control entities are the same.

[0069] S2: The main control entity and the hot standby control entity generate redundant data object information, including data object role identifiers, data object validity, data elements, and data element validity, and synchronize the redundant data object information to the data user entity q in real time. Specifically, in this embodiment, please refer to... Figure 3 As shown, redundant data object information is a data segment. The data segment contains four types of information: data object role identifier, data object validity, several data elements and their validity. Data user entity q can select which entity's data to use based on the priority of the primary control entity and the hot standby control entity. That is, the primary control entity's data is used first, and the hot standby control entity's data is used only when the primary control entity's data is invalid or unavailable.

[0070] Preferably, in step S2, the main control entity and the hot standby control entity generate redundant data object information and synchronize the redundant data object information to the data user entity q in real time, including:

[0071] After updating its own data objects, the master control entity sends a redundancy mutual exclusion message, including the data object version number and redundant data object information, to the hot standby control entity. Specifically, in this embodiment, when the control entities 1 to n that generated the data object list k have completed the negotiation and there are already m hot standby control entities, the master control entity sends a redundancy mutual exclusion message to the control entity that actively initiated the master-standby negotiation message, and the control entity enters a silent state.

[0072] After receiving the redundancy mutual exclusion message, the hot standby control entity verifies the data object version number and data element. If they are inconsistent, it requests the main control entity to retransmit. If the verification passes, the hot standby control entity updates its own data object and returns an acknowledgment response. It also synchronizes the redundant data object information of all hot standby control entities and the main control entity to the data user entity q in real time. Specifically, in this embodiment, the data user entity q can receive data from the main control entity and multiple hot standby control entities at the same time, and adopts strategies such as majority voting or the primary priority principle to handle the data inconsistency.

[0073] Preferably, the data object role identifier, data object validity, data element, and data element validity include:

[0074] The data object role identifier of the redundant data object information includes a function to identify the primary control role or the hot standby control role. The primary control role is a data object generated by the primary control entity, and the hot standby control role is a data object generated by the hot standby control entity. Specifically, in this embodiment, the control entity q preferentially selects the primary control role.

[0075] Data object validity includes timestamps and checksums (hash values ​​of all data elements);

[0076] Data elements are the actual data passed to the data object (e.g., control cycle = 50ms).

[0077] Data element validity is used to mark the trust status of a single data element and includes data object priority. The control entity q selects the data object with higher priority to obtain data based on the priority.

[0078] Please see Figure 4 As shown, the data uses entity q to receive redundant data objects k1~redundant data objects k sent by the main control entity and the hot standby control entity. m Based on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first, and the validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1. Specifically, in this embodiment, the control entity q does not pay attention to the main standby negotiation of control entities 1 to n, but only to the main standby information of data object k. The control entity q uses data object k to complete the control function. When using data, the data object k is first confirmed as the main data object k1. When the main control entity and the hot standby control entities 1 to m fail, a control entity is elected from the cold standby control entities m+1 to n to join the hot standby control entity to complete the replacement and maintain the 1:m hot standby state.

[0079] Furthermore, this embodiment implements a triple verification mechanism for redundant data object k, namely, the control entity q performs validity checks on data object k through primary / backup identifier, data object validity identifier, and data element validity identifier, so as to ensure the most complete data validity in the event of an anomaly.

[0080] Preferably, in step S3, verifying the validity of the redundant data object k1 further includes:

[0081] The main control role of the redundant data object k1 is verified to be valid. If the identifier format does not meet the preset requirements, the redundant data object k1 is determined to be invalid. Specifically, in this embodiment, the validity of the main control role can be verified based on specific string format, length limit, character range, etc. If the identifier format does not meet the preset requirements, the data object is determined to be invalid, the data object is directly rejected, and an error log can be recorded. At the same time, error information is fed back to the sender.

[0082] The signature and priority weight for verifying the validity of a data object are specifically defined in this embodiment. Signature verification involves extracting signature information from the data object. The signature is typically generated by encrypting key information of the data object (such as data content, version number, timestamp, etc.) using the sender's private key. The data object entity q decrypts the signature using the sender's public key and compares it with the hash value of the locally calculated key information. If the decrypted signature matches the locally calculated hash value, the signature verification is successful, and the data object has not been tampered with during transmission. Otherwise, the data object is deemed invalid and its use is rejected. Priority weight verification checks whether the priority weight of the data object is within a reasonable range. The priority weight range can be set from 0 to 100. If the priority weight exceeds the preset range, the data object is deemed invalid and its use is rejected. An error log can be recorded, and error information can be fed back to the sender.

[0083] The validity of each data element is verified item by item to ensure its credibility. Specifically, in this embodiment, if data object k1 is invalid, the validity identifier is marked as invalid, and the data using entity q will invalidate data object k1 and send a redundant data object k1 error response to the main control entity to maintain the overall validity of data object k.

[0084] Preferably, the validity of each data element is verified item by item to check the credibility of the data element, including:

[0085] Check if the data type of the data element matches the expectation. For example, if a data element should be an integer type, but is actually received as a string type, then the data element is considered invalid.

[0086] For numerical data elements, check whether their values ​​are within a reasonable range. For example, the reasonable range for a temperature data element is 0-100℃. If the received value exceeds this range, the data element is considered invalid.

[0087] For string data elements, check if their format conforms to specific rules. For example, the format of a date data element should be "YYYY-MM-DD". If the actual received format does not meet the requirements, the data element is considered invalid.

[0088] There may be dependencies between some data elements. Check whether these dependencies are satisfied. For example, the value of one data element must be greater than the value of another data element. If this condition is not met, the relevant data element is considered invalid.

[0089] If the main control role of the redundant data object is valid, the signature and priority weight are verified, and all data elements are valid, then the data object is considered to be completely valid, and the data entity q can use the data object normally for business processing.

[0090] If a redundant data object contains some invalid data elements, but still meets the overall usage requirements, then the data object is considered partially valid. Here, meeting the usage requirements means that the invalid data elements of redundant data object k1 are removed by selecting redundant data objects k2 through the hot standby control entity. m In the data object k1, valid data elements are used to replace invalid data elements, making the redundant data object k1 valid as a whole. For example, if an error is diagnosed in the main control room physical channel, causing data elements k of data object k1 to be invalidated, the invalid data elements will be replaced. 1.i When data element k is no longer trusted, 1.i If the validity identifier is marked as invalid, the control entity q will retrieve the simultaneously received hot standby data objects k2~k based on the priority in the data object validity. m Select redundant data objects k2 to k. m valid data element k in x.i Replace invalid data element k in data object k1 1.i This makes the redundant data object k1 effective as a whole.

[0091] If the master control role of a data object is invalid, the signature or priority weight verification fails, or the number of invalid data elements exceeds the threshold, the data object is determined to be completely invalid. The data user entity q refuses to use the data object and can take corresponding measures, such as requesting the sender to resend the data or switching to other available data objects.

[0092] Furthermore, in this embodiment, data objects k are prioritized according to a preset strategy to obtain priority weights, where the main control entity has the highest priority, and the priority of the hot standby control entity is adjusted according to the preset strategy, so that the control entity q receives k1~k m When the primary data object k1 is abnormal, the data object k2 with the highest priority is selected to replace it.

[0093] Preferably, in step S3, if the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1, further including:

[0094] When data object k1 is invalid, the data use entity q sends an error response to the main control entity, and, based on the data object role identifier and data object validity priority, retrieves redundant data objects k2 to k1 from the hot standby control entity. m-1 Select the hot standby data object;

[0095] In response to an error response, the primary control entity releases its primary control role, selects a hot standby control entity as the primary control entity, and triggers a cold standby control entity to join the hot standby control entity group to maintain a 1:m-1 hot standby ratio. Specifically, in this embodiment, after receiving an error response message for data object k1, the primary control entity selects to release its primary control role or continue to maintain it according to a preset strategy. After the primary control role is released, a new primary control entity is designated to generate data object k. This primary / standby switchover is only effective for data object k, and other data objects are not affected. At the same time, the new primary control entity selects a new control entity from control entities m+1 to n to join the hot standby control entity, maintaining a 1:m-1 hot standby ratio. This ensures that the system can still guarantee the validity of 1:m data objects without degradation before nm faults occur. The cold standby entities m+1 to n only self-diagnose to ensure they have the ability to generate data objects. When they do not have the ability, they issue a fault alarm to the diagnostic system.

[0096] Preferably, triggering the cold standby control entity to join the hot standby control entity group includes:

[0097] Based on the self-diagnostic results of the cold standby control entity, available entities are screened. Specifically, in this embodiment, after the main control entity releases its main control role, it broadcasts a message to all cold standby control entities to trigger joining the hot standby group. After receiving the message, the cold standby control entity immediately starts a self-diagnostic program to check whether its own hardware devices are working properly, such as CPU, memory, storage devices, network interfaces, etc., whether the running software programs are working properly, including operating system, application programs, drivers, etc., and whether the data objects stored locally are consistent with the data objects in the current hot standby group. The consistency of the data can be determined by comparing the version number, checksum, and other information of the data objects.

[0098] The newly added hot standby control entity updates its data object role identifier to a hot standby state. Specifically, in this embodiment, the main control entity selects a suitable entity from the available cold standby control entities (based on preset rules such as priority and performance) to join the hot standby group, and then sends a role update instruction to the newly added cold standby control entity, requesting it to update its data object role identifier to a hot standby state. After receiving the role update instruction, the newly added cold standby control entity updates its own data object role identifier from a cold standby state to a hot standby state. Simultaneously, based on the latest data object information provided by the main control entity, the local data objects are updated to ensure consistency with the data in the hot standby group.

[0099] A hot standby group update notification is sent to the data user entity q. Specifically, in this embodiment, the main control entity (temporary coordinating role) prepares the hot standby group update notification. The notification content includes relevant information of the newly added hot standby control entity, such as control entity ID, IP address, data object version number, etc., as well as the latest status information of the hot standby group.

[0100] Furthermore, in this embodiment, the redundancy of the control system only switches the primary and backup data object k. Other data objects generated by the control entity are not affected. When the control entity q detects invalid data elements in a data object, it replaces them with valid data elements in the highest priority data object k. Even if n control entities fail at the same time, as long as the invalid data is not the same data element in the same redundant data object, this embodiment can still achieve a delay-free and disturbance-free switch, thereby improving the fault tolerance of data objects.

[0101] Example 2

[0102] Based on the same concept, this embodiment also provides a multi-entity, multi-level redundant control system, including:

[0103] The primary / standby negotiation module is used to control the entity cluster to periodically send primary / standby negotiation messages, including the control entity ID, role status, and priority. n control entities are divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities according to the primary / standby negotiation messages.

[0104] The redundant data object generation module generates redundant data object information, including data object role identifier, data object validity, data elements, and data element validity, and synchronizes the redundant data object information to the data user entity q in real time.

[0105] The data fault tolerance module uses entity q to receive redundant data objects k1~redundant data objects k sent by the main control entity and the hot standby control entity. mBased on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first, and the validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1.

[0106] Preferably, verifying the validity of the redundant data object k1 further includes:

[0107] Verify whether the main control role of the redundant data object k1 is valid. If the identifier format does not meet the preset requirements, the redundant data object k1 is determined to be invalid. Verify the signature and priority weight of the data object validity and verify the credibility of each data element.

[0108] If the main control role of the redundant data object is valid, the signature and priority weight verification pass, and all data elements are valid, then the redundant data object is considered completely valid. If the redundant data object k1 has some invalid data elements, but overall meets the usage requirements, then the redundant data object is considered partially valid. If the main control role of the redundant data object is invalid, the signature or priority weight verification fails, or the number of invalid data elements exceeds the threshold, then the redundant data object is considered completely invalid. Here, "overall meets the usage requirements" means that the invalid data elements of the redundant data object k1 are removed by selecting redundant data objects k2 to k3 of the hot standby control entity. m The valid data elements in the data are used to replace the invalid data elements, making the redundant data object k1 valid as a whole.

[0109] Preferably, if the verification result is invalid, the current primary control entity is released, and the hot standby control entity is switched to the primary control entity to ensure that the ratio of the primary control entity to the hot standby control entity is 1:m-1, further including:

[0110] When the data object k1 is invalid, the data-using entity q sends an error response to the main control entity, and, based on the data object role identifier and data object validity priority, selects redundant data objects k2 to k1 from the hot standby control entity. m Select the hot standby data object;

[0111] In response to the error response, the main control entity releases its main control role, selects the hot standby control entity as the main control entity, and triggers the cold standby control entity to join the hot standby control entity group to maintain a 1:m-1 hot standby ratio.

[0112] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A multi-entity-based multi-level redundancy control method, characterized in that, Includes the following steps: S1: The control entity cluster periodically sends master-slave negotiation messages including the control entity ID, role status and priority. The n control entities are divided into 1 master control entity, m-1 hot standby control entities and nm cold standby control entities according to the master-slave negotiation messages. S2: The main control entity and the hot standby control entity generate redundant data object information including data object role identifier, data object validity, data element and data element validity, and synchronize the redundant data object information to the data user entity q in real time; S3: The data uses entity q to receive redundant data objects k1~k1 sent by the main control entity and the hot standby control entity. m Based on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first, and the validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1.

2. The multi-entity-based multi-level redundancy control method according to claim 1, characterized in that, In step S1, the n control entities are divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities according to the primary / standby negotiation message, including: The control entity broadcasts the primary / backup negotiation message, including the IP address, within a preset event window; The hot standby control entity with the highest priority weight is selected as the main control entity. If the priorities are the same, the one with the larger IP address wins as the main control entity. After the election, the main control entity sends a role allocation confirmation message to all control entities, including information on the generated redundant data objects and the validity of the data objects. The first m-1 control entities with the second highest priority are selected as the hot standby control entities, and the remaining control entities are selected as the cold standby control entities.

3. The multi-entity-based multi-level redundancy control method according to claim 1, characterized in that, In step S2, the main control entity and the hot standby control entity generate redundant data object information and synchronize the redundant data object information to the data user entity q in real time, including: After updating its own data object, the master control entity sends a redundancy mutual exclusion message, including the data object version number and the redundant data object information, to the hot standby control entity. After receiving the redundant mutual exclusion message, the hot standby control entity verifies the data object version number and data element. If they are inconsistent, it requests the main control entity to retransmit. If the verification passes, the hot standby control entity updates its own data object and returns an acknowledgment response. It also synchronizes the redundant data object information of all the hot standby control entities and the main control entity to the data user entity q in real time.

4. The multi-entity-based multi-level redundancy control method according to claim 3, characterized in that, Data object role identification, data object validity, data elements, and data element validity, including: The data object role identifier of the redundant data object information includes a primary control role or a hot standby control role, wherein the primary control role is a data object generated by the primary control entity, and the hot standby control role is a data object generated by the hot standby control entity; The validity of the data object includes a timestamp and a checksum; The data element is the actual data transmitted by the data object; The validity of the data element is used to mark the trust status of a single data element and includes the priority of the data object. The control entity q selects a redundant data object with a higher priority to obtain data based on the priority.

5. The multi-entity-based multi-level redundancy control method according to claim 1, characterized in that, In step S3, verifying the validity of the redundant data object k1 further includes: Verify whether the main control role of the redundant data object k1 is valid. If the identifier format does not meet the preset requirements, the redundant data object k1 is determined to be invalid. Verify the signature and priority weight of the data object validity and verify the credibility of each data element. If the main control role of the redundant data object is valid, the signature and priority weight verification pass, and all data elements are valid, then the redundant data object is considered completely valid. If the redundant data object k1 has some invalid data elements, but overall meets the usage requirements, then the redundant data object is considered partially valid. If the main control role of the redundant data object is invalid, the signature or priority weight verification fails, or the number of invalid data elements exceeds the threshold, then the redundant data object is considered completely invalid. Here, "overall meets the usage requirements" means that the invalid data elements of the redundant data object k1 are removed by selecting redundant data objects k2 to k3 of the hot standby control entity. m The valid data elements in the data are used to replace the invalid data elements, making the redundant data object k1 valid as a whole.

6. The multi-entity-based multi-level redundancy control method according to claim 5, characterized in that, In step S3, if the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1. This further includes: When the redundant data object k1 is invalid, the data use entity q sends an error response to the main control entity, and, based on the data object role identifier and data object validity priority, selects the redundant data objects k2 to k1 from the redundant data objects of the hot standby control entity. m Select the hot standby data object; In response to the error response, the main control entity releases its main control role, selects the hot standby control entity as the main control entity, and triggers the cold standby control entity to join the hot standby control entity group to maintain a 1:m-1 hot standby ratio.

7. The multi-entity-based multi-level redundancy control method according to claim 6, characterized in that, Triggering the cold standby control entity to join the hot standby control entity group includes: Available entities are selected based on the self-diagnostic results of the cold standby control entity; Update the data object role identifier of the newly added hot standby control entity to hot standby status; Send a hot standby group update notification to the data using entity q.

8. A multi-entity, multi-level redundant control system, characterized in that, include: The primary / standby negotiation module is used to control the entity cluster to periodically send primary / standby negotiation messages, including the control entity ID, role status, and priority. n control entities are divided into 1 primary control entity, m-1 hot standby control entities, and nm cold standby control entities according to the primary / standby negotiation messages. The redundant data object generation module generates redundant data object information, including data object role identifier, data object validity, data element and data element validity, and synchronizes the redundant data object information to the data user entity q in real time. The data fault tolerance module receives redundant data objects k1~k from the main control entity and the hot standby control entity via entity q. m Based on the data object role identifier, the redundant data object k1 generated by the main control entity is selected first, and the validity of the redundant data object k1 is verified. If the verification result is invalid, the current main control entity is released, and the hot standby control entity is switched to the main control entity to ensure that the ratio of the main control entity to the hot standby control entity is 1:m-1.

9. The multi-entity-based multi-level redundancy control system according to claim 8, characterized in that, The verification of the validity of the redundant data object k1 further includes: Verify whether the main control role of the redundant data object k1 is valid. If the identifier format does not meet the preset requirements, the redundant data object k1 is determined to be invalid. Verify the signature and priority weight of the data object validity and verify the credibility of each data element. If the main control role of the redundant data object is valid, the signature and priority weight verification pass, and all data elements are valid, then the redundant data object is considered completely valid. If the redundant data object k1 has some invalid data elements, but overall meets the usage requirements, then the redundant data object is considered partially valid. If the main control role of the redundant data object is invalid, the signature or priority weight verification fails, or the number of invalid data elements exceeds the threshold, then the redundant data object is considered completely invalid. Here, "overall meets the usage requirements" means that the invalid data elements of the redundant data object k1 are removed by selecting redundant data objects k2 to k3 of the hot standby control entity. m The valid data elements in the data are used to replace the invalid data elements, making the redundant data object k1 valid as a whole.

10. The multi-entity-based multi-level redundancy control system according to claim 9, characterized in that, If the verification result is invalid, the current primary control entity is released, and the hot standby control entity is switched to the primary control entity to ensure that the ratio of the primary control entity to the hot standby control entity is 1:m-1, further including: When the data object k1 is invalid, the data-using entity q sends an error response to the main control entity, and, based on the data object role identifier and data object validity priority, retrieves redundant data objects k2 to k1 from the hot standby control entity. m Select the hot standby data object; In response to the error response, the main control entity releases its main control role, selects the hot standby control entity as the main control entity, and triggers the cold standby control entity to join the hot standby control entity group to maintain a 1:m-1 hot standby ratio.

Citation Information

Patent Citations

  • High-availability function block redundancy method

    CN101751020A

  • Industrial control network redundancy fault-tolerant system

    CN101907879A