Unified Communications Modul (UCM)

The UCM addresses redundancy and integration challenges in fault tolerance systems by integrating a three-port switch for secure data communication, enhancing redundancy and system reliability in process control systems.

DE102015222010B4Active Publication Date: 2025-11-06SCHNEIDER ELECTRIC SYST USA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102015222010
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2014-11-14
Filing Date
2015-11-09
Publication Date
2025-11-06
Estimated Expiration
2035-11-09

AI Technical Summary

Technical Problem

Existing fault tolerance systems in process control systems, such as DCS, face challenges in achieving efficient redundancy, integration with safety systems, and reducing hardware components while maintaining uninterrupted operation and security functionality.

Method used

A unified communications module (UCM) with a distributed control engine and on-board communication link integrates a fault tolerance controller, incorporating a three-port switch to connect safety and field device system integration modules, ensuring redundancy and secure data communication between networks.

Benefits of technology

The UCM provides uninterrupted fault-tolerant redundant pairs, enhances redundancy between controllers, and integrates safety and process control systems without additional hardware, ensuring secure data communication and preventing unauthorized changes, thus improving system reliability and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Fault-tolerant control system that includes: a process control system workstation that is effectively connected to a first network; a fault-tolerant safety controller that is effectively connected to a second network; an interface between the process control workstation and the fault-tolerant safety controller, wherein the interface includes: a process control module that is effectively connected to the first network; a security control module that is effectively connected to a second network; and a field device system integration module for communicating safety information from the safety control module to the process control module; wherein the process control module, the safety control module and the field device system integration module are arranged together on a network interface card, characterized in that the fault-tolerant control system further comprises a three-port switch arranged on the network interface card, wherein the three-port switch is configured to communicate with the safety control module and the field device system integration module via a selected connection between them, wherein the selected connection maintains a functional and physical separation between the first network and the second network.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] In a process control system, such as a distributed process control system (DCS), fault tolerance allows operation to continue in the event of component failure or if the system encounters temporary faults from various sources. A common aspect of fault tolerance systems is the concept of redundancy, which can be simply described as backup components that take over in the event of a failure, allowing the system to continue operating as intended. A safety information system (SIS) is known in the prior art to continue operation in a "safe state" to avoid adverse consequences for safety and overall health by employing fault tolerance control. Such fault tolerance controls are often used in hazard protection systems (i.e., systems that regulate the operation of nuclear power plants, turbomachinery, fire and gas detection systems, and the like).

[0002] The control components of well-known fault-tolerance controllers employ parallel control and comprehensive diagnostics to ensure uninterrupted process operation. One example of a fault-tolerance controller is the TRICON controller available from Invensys Systems, Inc. The TRICON controller features a triple modular redundancy (TMR) architecture, utilizing three separate parallel control systems and comprehensive diagnostics integrated into a single system. The system employs a two-out-of-three selection to provide error-free, uninterrupted, high-integrity process operation without a single point of failure. Fault-tolerance controllers of this type are connected not only to various other components but also to modules of the process control system, which provide both control and communication functions.

[0003] All improvements that enhance the efficient interaction (in terms of protocol support, applications, or graphical user interface navigation of the system) between the SIS and the process control system, while simultaneously maintaining safety functionality, are highly desirable. Various improvements aimed at reducing the number of hardware components required for implementing fault tolerance control, as well as enabling the controller to communicate effectively with the process control system, have been attempted without complete success.

[0004] US Patent 6,975,966 B2 discloses a fault-tolerant control system according to the preamble of claim 1. EP Patent 1,751,896 B1 discloses a communication interface in the form of a circuit for signal transmission in a network node, comprising a first module connected to a regulatory network, a second module effectively connectable to a safety network, and a third module for communicating information between the modules. The circuit further comprises a multi-port switch configured to connect the modules to each other via a selected connection. SUMMARY

[0005] In short, various aspects of the present invention relate to a Unified Communications Module (UCM) that provides an embedded functional safety core and a distributed control engine with an onboard communication link in an industrial process control environment. Advantageously, various aspects of the invention enable redundancy between the control devices of the control section of a process control system, such as a DCS, to create a fully uninterrupted, fault-tolerant, redundant, pairwise configurable control network. Furthermore, various aspects of the invention allow the integration of a switch between the safety core and a field device system integrator (FDSI), which collects data from various field devices such as pumps, valves, and flow meters and communicates the data to the DCS application interface.This allows the security application to read and write alias control data while preventing changes to the security control from control network sources.

[0006] One aspect of the present invention comprises a fault tolerance control system, wherein a process control workstation is connected to a first network and a fault tolerance safety controller is connected to a second network, wherein a process control module, a safety control module and a field device system integration module are jointly arranged on a power interface card.

[0007] In another aspect, a communication interface for a fault tolerance controller includes the power interface card with a three-port switch configured to connect the safety control module and the field device system integration module, resulting in the communication interface appearing as a control station on a control network.

[0008] In yet another aspect, a fault tolerance controller comprises a modified backplate interface, a main processor, and a network interface card. The modified backplate interface is configured to interconnect redundant network interface cards.

[0009] This summary is given to present, in simplified form, a selection of concepts that are described in more detail below in the Detailed Description. This summary is neither intended to identify key features or essential characteristics of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.

[0010] Other features will be partially revealed and partially highlighted in the following sections. BRIEF DESCRIPTION OF THE DRAWINGS Fig. Figure 1 is a diagram showing a UCM and various relevant communication networks linked by the UCM according to an embodiment of the invention. Fig. Figure 2 is a diagram showing three UCM components according to one embodiment of the invention. Fig. Figure 3 is a block diagram of the first of three UCM components according to an embodiment of the invention. Fig. Figure 4 is a block diagram of the second of three UCM components according to an embodiment of the invention. Fig. Figure 5 is a block diagram of the third of three UCM components according to an embodiment of the invention. Fig. Figure 6 is a block diagram of an Ethernet switch and relevant structural components in an embodiment of the invention. Fig. Figure 7 shows a detailed view of a backplate slot used by the UCM according to an embodiment of the invention. Fig. Figure 8 is a block diagram showing a functional redundancy feature of the UCM according to one aspect of the invention.

[0011] Corresponding reference symbols indicate corresponding parts in all drawings. DETAILED DESCRIPTION

[0012] Several aspects of the invention relate to hardware and software components for use in distributed process control environments, in particular for integrating the functionality of process control-related hardware and software. One UCM embodying several aspects of the invention comprises a semi-fault-tolerant 3-to-1 interface between its communication ports and the main processors (MPs) of a fault-tolerant controller.

[0013] In Fig. Figure 1 is a fault-tolerant controller, globally designated by 210, embodying various aspects of the invention. As can be seen, a UCM 214 is located within a chassis 222 of a fault-tolerant controller. In one embodiment, the fault-tolerant controller contains a plurality of UCMs 214 that operate independently of one another and are capable of providing true control network redundancy, as will be described in more detail below. Three separate modules are shown within the UCM 214, which, among other advantages, provide the physical and functional separation of at least two individual networks. A control processor 226 is the first module relevant to the UCM.The control processor 226 provides regulatory, logical, time-based, and sequential control through a mesh network 230, which is the regulatory network connecting the control processor 226 from each UCM to a workstation 234 running process control automation software. In one embodiment, the mesh network 230 is also connected to a control processor, which is then connected, for example, via a parallel input / output (PIO) bus 242 to a fieldbus module 246 of the process control system. In one embodiment, a suitable control processor 226 is a CP270 control processor available from Invensys Systems, Inc.

[0014] Furthermore, how from Fig. As can be seen in Figure 1, an FDSI 250 collects data from various field devices such as pumps, valves, and flow meters and communicates the collected data to the meshed network 230. An example of an FDSI 250 is a Field Device System Integrator Module FBM233, available from Invensys Systems, Inc. Furthermore, one or more safety modules 254, embedded in the fault-tolerant controller 210, allow flexible communication between safety systems implementing the aforementioned "safe state" and the distributed control systems in one embodiment. For example, the safety module 254 is embodied by a communication module TRICON (TCM). The safety modules 254 are interconnected by a safety configuration network 258, referred to as "Net1," which connects multiple fault-tolerant controllers. Additionally, a safety workstation 262 is connected to Net1 258.

[0015] Furthermore, a three-port switch 264, such as an Ethernet switch, connects the safety module 254, the FDSI 250, and a third network, designated “Net2” 268. In this embodiment, communication signals pass through the processor of the FDSI 250 before reaching the control processor 226. The communication signals must pass separately through various components within the chassis 222 before reaching the safety devices, which are effectively connected to the fault tolerance controller 210. The fault tolerance controller includes, among other components, at least one main processor 272, which is effectively connected to the safety module 254, and at least one input / output (I / O) card 276.

[0016] The communication protocol used at the three-port switch 264 includes a common protocol capable of sending communications to both the FDSI 250 and the safety module 254. An example of a protocol used at the three-port switch 264 to communicate through the Net2 268 includes a protocol such as the TRICONEX System Access Application (TSAA), which enables client / server communication between safety controllers and personal computers. Two example client / server programs that use a TSAA protocol to exchange data with fault-tolerant safety controllers include OPC Server and DDE Server. The TSAA protocol can also be used to enable other programs to influence access points in SISs for Safety Integrity Level (SIL) 3 or SIL 2 applications.The TSAA protocol differs from the protocol used by the DCS components on the mesh network 230. Integrating the three-port switch 264 into the UCM 214 allows the SIS to read and write alias control data while maintaining write protection to prevent any changes to a safety controller originating from sources within the process control system communicating via the mesh network 230 in one embodiment. This dual functionality enables secure communication over the three-port switch 264 while maintaining a clear separation between communication occurring on the mesh network 230 and that occurring on Net1 258.

[0017] The UCM 214 is an interface module of a distributed control system that, among other advantages, is able to provide the following additional communication features to the fault-tolerant safety system: • Single or redundant module operation, • One logical slot or two physical slots of UCMs in the system (SLOT 2 - COM slot). Module keying should conform to the TRICON module keying standard. • Two optically separated RS-232 / RS-485 serial ports per UCM, with firmware configurable by TMR TRISTATION for Modbus, GPS, etc. • Two 10 / 100 basic fiber network ports are available per UCM; specifically, two fiber-optic-type Ethernet ports with two LC connectors and two fiber-optic-type Ethernet ports with MT-RJ connectors are available, resulting in network connections on the UCM with fiber optic connections. • All ports can provide 500VDC galvanic isolation from TRICON logic ground (FE), • TCP / IP / TSAA network protocols supported on both network ports for TRISTATION, SOE, TRILOG, HP printers, WONDERWARE HMI and other DDE compatible applications, • V9 peer-to-peer and V9 time synchronization protocols supported on network ports, • Optional global time synchronization receiver interface using Modbus port one, • TMR COMM bus, consisting of three 2Mb HDLC RS485 communication channels, one for each TRICON main processor (MP) limb, • UCM development ports: One optically isolated RS-232 debug port and one JTAG connection per UCM, • Based on MOTOROLA MPC8270 QUICC.

[0018] In suitable configurations, various protocols can be implemented on different UCM networks, including Net1 258 and Net2 268. Suitable application protocols include TCP / IP for network-connected TCP / IP printers and Modbus primary or secondary communication. A simple network time protocol (SNTP) is also available. Furthermore, with respect to a UDP / IP protocol, application protocols include TRICONEX time synchronization, TSAA client / server communication with IP multicast, and TRICONEX peer-to-peer communication. TRISTATION and TSAA client / server communication are also available. Regarding network protocols available on Net1 258 and Net2 268, TCP / IP, SNTP, UDP / IP, and an Internet Control Message Protocol (ICMP) are available.

[0019] Advantageously, the Fault Tolerance Controller 210, which includes the UCM 214, supports Event Sequence (SOE) data. This differs from real-time data in that the Fault Tolerance Controller 210 saves and buffers the data to preserve its timestamp and sequence of occurrence. This is an improvement over the Advanced Communication Module (ACM), which enabled the TRICON controller to communicate more effectively with the DCS. While the ACM improved integration between safety and process control, it introduced issues with redundancy, speed, and system configuration, all of which were addressed by the Fault Tolerance Controller 210. Furthermore, the ACM required additional hardware and lacked several desirable features.

[0020] In one embodiment, the UCM 214 incorporates the control processor 226, which is nearly identical to a regulatory control processor located outside the safety system. The control processor 226 in the UCM 214 includes additional features such as upgradable control software and 100 Basic FX fiber Ethernet. Furthermore, the use of the depicted control processor 226 allows for the addition of hardware and application software to the DCS, as well as system management tools to support the UCM 214. The use of this control processor 226 results in a holistic presentation of information from the SIS systems to the DCS, including SOE and SIS time-stamped data, system general status, equipment general status, and other information.Regulatory control addressing, such as the MAC address and SLOT ID, can also be configured and set as if it were in a regulatory control processor located outside the security system, as well as in the FDSI 250.

[0021] Furthermore, control hardware can be upgraded with modifications without compromising safety functionality. Additionally, the control network can be added online without adding any hardware or software—an improvement achieved by considering form factor, heat dissipation, current sequences, and power dissipation.

[0022] The fault-tolerant controller 210 also offers advantages over alternatives to the ACM. For example, configuring a control processor (providing regulatory, logical, time-based, and sequential control) with an FDSI, and including safety modules placed in the chassis of a fault-tolerant controller, also cannot provide the advantages of the fault-tolerant controller 210 embodying aspects of the invention, which includes the UCM 214. The control processor 226 and the FDSI 250 are connected to the fault-tolerant controller 210 by cables. Redundancy can be provided in other ways, such as by providing an additional control processor and FDSI outside the chassis, or by placing an additional control processor and an additional FDSI on a single base plate.However, in this embodiment, the cables from the redundant components are connected to the TSAA ports, which requires the consumer to pay for the additional ports needed to implement the alternative configuration and increases the necessary installation time.

[0023] Several aspects of the invention replace the ACM and the conventional alternative configuration and represent significant advances in integrating the SIS / DCS connection, such as enabling redundancy between controllers of the regulatory or controlling part of a process control system, such as the DCS, to create a fully uninterrupted, fault-tolerant, redundant, pairwise configurable control network. Furthermore, several aspects of the invention allow the integration of a switch between the safety core and a field device system integrator (FDSI), which collects data from various field devices such as pumps, valves, and flow meters and communicates the data to the DCS application interface. This enables the safety application to read and write alias control data while preventing changes to the safety control from control network sources.Furthermore, a fault-tolerant control system embodying aspects of the invention allows the addition of serial ports to the rear panel to complement the dense UCM module front panel interface connections, and the addition of an Ethernet switch for connecting to the security network. The rear panel is also preferably custom-designed to accommodate additional control network signals, including dedicated slots for the UCM 214.

[0024] Furthermore, mesh network Ethernet connections are added to the UCM module front panel, creating a rational front panel connection between the mesh network hardware and software and the MP modules, after taking into account factors such as form factor, heat dissipation, power sequencing and power dissipation.

[0025] Fig. Figure 2 shows a block diagram of the three components of the UCM 214 together with other connections to various modules and networks in one embodiment of the present invention. The control processor 226, also referred to as the I / A engine, is a distributed, optionally fault-tolerant, field-mounted controller that performs process control and warning functions according to a user-defined control strategy. The software system design is performed by distributed control system software, such as the FOXBORO EVO or FOXBORO I / A SERIES, available from Invensys Systems, Inc. The FDSI 250 integrates safety devices, such as the TRICON and TRIDENT devices, using the TSAA protocol in an I / A SERIES system. As above, the software design is performed by distributed control system software, such as the FOXBORO EVO or FOXBORO I / A SERIES. B. the FOXBORO EVO or FOXBORO I / A SERIES, which are manufactured by Invensys System, Inc.The Safety Module 254, also known as the Safety Interface Engine (SIE), is embodied by a modified TCOM and is the module's main control board. The Safety Module 254 is the interface to the SIS (also known as the TRICON Safety System) and is responsible for the overall health and status of the entire module and its diagnostics, dictating the entire system startup process (including when the control devices come online).

[0026] What's next? Fig. As can be seen in Figure 2, various interconnection capabilities of the components of the UCM 214 are provided by different connection types, enabling the display of status messages and connectivity according to various aspects of the invention. Among other interconnection capabilities, the front panel interfaces 125 of the safety module 254, such as those designated as the debug port, Net1, and Net2, are interconnected with a front panel 130 of the chassis 222. For example, the debug port has a 2kV isolation implemented by the safety module 254. The debug port isolation is achieved via a transformer, while data signals pass through optocouplers. Furthermore, some interconnection is performed by a three-port switch 264, which is described in more detail below and is capable of providing structural and functional isolation between different networks.The rear panel interfaces 140 of the safety module 254, such as those designated COMBUS A, COMBUS B, COMBUS C, redundancy connection, Serial 1 and Serial 2, provide an existing interface via the rear panel of the chassis 222, which includes a rear plate 145.

[0027] It is still being used on Fig. 2. Referenced. The FDSI 250 further includes front panel interfaces 150, such as the interfaces that display status LEDs, and interfaces to the three-port switch 254, as well as rear panel interfaces 160, such as a connection to a redundant module via new interfaces. Furthermore, the control processor 226 also includes front panel interfaces 165, such as status LEDs and those labeled matrix A, matrix B, IR, and time sync, as well as rear panel interfaces 170 to the rear panel 145, such as a connection to a redundant module via new interfaces. Finally, the connection via PIO connections 180 and PIO connections 175 provides the connection between the control processor 226 and the FDSI 250; as well as between both modules and the rear panel 145.

[0028] Fig. Figure 3 shows a block diagram of the first of three UCM components, namely the safety module 254, in one embodiment of the invention. A first "main" microprocessor 310, shown here as an MPC8270, performs high-level protocol functions. A second "secondary" microprocessor 315, also shown here as an MPC8270, performs COMBUS communication functions. Other components include those that support the secondary microprocessor 315, including at least one gatekeeper complex programmable logic device (CPLD) 320 and a hot spare connection 325. Further components and connections are being considered, such as... B. SD-RAM components 330, Bulk-Flash 335 and Flash memory components 340, EEPROM components 345, 60x Bus 350 and 60x Buffered Bus 355 connections and serial interfaces including a Serial-1 interface 360 ​​and a Serial-2 interface 365.

[0029] Fig. Figure 4 is a block diagram of the second of the three UCM components, namely FDSI 250, in one embodiment of the present invention. The FDSI 250 is shown with various relevant interface connections. To accommodate two printed circuit board assemblies (PCBAs) within the UCM 214, the PCBAs are combined to form a single PCBA. Physical layers, transceivers, and status indicators—components previously housed on an FDSI—are located on a UCM network interface card (PIB). As will be explained in more detail, Net2 268 is connected to the FDSI 250 via an LXT 971 transceiver 420 and an Ethernet switch 425, which embodies the three-port switch 264. Among other functions, it provides the capability to maintain physically and functionally distinct networks between the meshed network 230 and Net1 258.

[0030] Fig. Figure 5 is a block diagram of the third of the three UCM components, namely a control processor 226, in one embodiment of the invention. In one embodiment, the control processor 226 is connected to various components and indicators, such as the status indicator lights, via various rear panel interface connections 515 and various front panel interface connections 520. In another embodiment, the control processor 226 is connected to modules such as the FDSI 250 via FDSI interface connections 525. In one embodiment, the connection is facilitated by a first LXT971-based Ethernet physical layer (PHY) 530 and a second LXT971-based Ethernet PHY 535, as well as by an IR encoder / decoder 540.

[0031] Fig. Figure 6 is a block diagram of the Ethernet switch 425 and relevant structural components in one embodiment of the present invention. The Ethernet switch 425, e.g., an 88E6060 Ethernet switch, is used in the UCM-PIB to facilitate communication between an FDSI card 615 (e.g., a control card of the FDSI 250) and a security control card 620 (e.g., a control card of the security module 254), while maintaining functional and physical separation between the mesh network 230 and Net1 258. The transformers 625 and 630 provide connections between the FDSI card 615 and the Ethernet switch 610. An MII connection 635 between the Ethernet switch 425 and a first MTRJ connection 640 via a first LXT971A transceiver 645 provides, among other things, a connection to an external network Net2 268.An MII2 connection 655 between the Ethernet switch 610 and the security control card 620 communicates via an MII1 connection 660 with a second LXT971A transceiver 665, which in turn communicates via a second MTRJ connection 670, which provides, among other things, a connection to the Net1 258, which also includes a SIS network in one embodiment.

[0032] Still referring to Fig. It is understood that in one embodiment, when communication signals are routed from Net2 268 to the FDSI card 615 via transformers 625 and 630, the signals must be sent through at least one first processor located on the FDSI card 615. It is understood that in one embodiment, when communication signals are routed from Net2 268 to the security control card 620 via MII2 655, the signals must be sent through at least one second processor located on the security control card 620. In one embodiment, it is understood that the signals sent through the first processor located on the FDSI card 615 are ultimately sent to components in the meshed network 230.In one embodiment, it is understood that the signals transmitted through the second processor arranged on the safety control card 620 are ultimately sent to components in the SIS network.

[0033] In Fig. It is understood that the Ethernet switch is configured during initialization to shield data from the Net2 268 from reaching the transformers 625 and 630. This shielding is achieved by configuring the Ethernet switch 425 using software during initialization. It is understood that VLAN is implemented on the Ethernet switch 425 to control communication with the FDSI card 615. As is generally known in engineering, VLAN is a programmable way to "hardwire" a specific communication path in a multi-port switch to prevent packets from being sent to every port, and provides additional security and data capture capabilities.

[0034] Configuring the Ethernet switch 425 as a VLAN prevents any irrelevant messages from the mesh network 230 from reaching the security control card 620 via the FDSI card 615. Among the advantages gained by eliminating these irrelevant messages is the provision of TÜV certification for control processor components, which is not possible if they are located outside the chassis 222 of the fault-tolerant controller 210. As is generally known in engineering, TÜV certification requires a customer to demonstrate, among other things, that the security system is not disrupted by external interfaces by adhering to rigorous time limits for specific applications. For example, there is a predefined time limit for burner management (e.g.,(in milliseconds), within which the safety module 254 of a safety controller closes the gas supply line if the flame has gone out. To guarantee that the supply line is closed within the specified time limit, no external interface of the main processor 272, which is effectively connected to the safety module 254, may interfere. The TÜV certification can now be applied to components that were previously outside the fault-tolerant controller 210 because communications of the mesh network 230 within the UCM are certified to avoid interfering with communications to the SIS interface, the safety module 254.

[0035] It is understood that the configuration of the UCM 214 prevents external interference in various ways. It is understood that rearranging equipment components by integrating the Security Module 254, the FDSI 250, and the Control Processor 250 prevents external interference by blocking access to the internal cards. It is understood that the Ethernet Switch 425 is configured by internal configuration logic that cannot be altered by external interference. Another advantage of the internal configuration logic is the elimination of human error in setting up a VLAN, which can be complex and requires network expertise. Configuring a VLAN between the Security Module 254 and the FDSI 250, as well as between the Security Module 254 and a PHY Transceiver 645, yields similar benefits to those achieved by implementing a firewall, such as...Increased data protection, communication security, reduction of communication interference between the security module 254, the FDSI 250 and the control processor 226, and data integrity.

[0036] More precisely, it is understood that the VLAN improves data integrity by allowing the replacement of the cabling between the Net2 268 port and the FDSI 250 ports with a shorter connection implemented on a circuit board. It is understood that the Ethernet switch 425 is configurable via a computer. And it is understood that the ports on the Ethernet switch 425 are configurable by software during initialization, so that the DCS, via the FDSI card 615, is shielded from data arriving from the Net2 268, and only the SIE, via the security control card 620, receives the incoming data.

[0037] Fig. Figure 8 shows redundant UCMe 214 units installed in chassis 222 according to an embodiment of the present invention. The backplate 145 contains a serial port 810 connected to a serial cable 815. A meshed network fiber cable 820 from the UCM 214 communicates with the meshed network 230 via a meshed splitter / combiner 825 and meshed fiber cables 825, e.g., to the workstation 234 of the process control system. In one embodiment, a first UCM 830 (e.g., UCM 214) and a second UCM 835 (e.g., UCM 214) are installed in a redundant configuration in slot 2 of chassis 222. In addition, redundant power supplies 840, a first of three main processors 845 installed in a triple redundant configuration, and a safety controller 254 (or SIE) are installed in the chassis 222 in one embodiment.

[0038] Fig. Figure 7 shows a detailed view of the backplate slot used by the UCM according to an embodiment of the present invention. More precisely, the J42 and J47 backplate connections, globally designated 705, are shown and described in more detail in Table A, which further describes the relevant connections by their PIN numbers. In one embodiment, a left-hand row of control processor network bus connections 710, which connects to a first control processor module housed in a first redundant UCM (e.g., UCM 214), is networked via a customized backplate with a right-hand row of control processor network bus connections 715, which connect to a second control processor module housed in a second redundant UCM (e.g., UCM 214).In one embodiment, a left-hand row of fieldbus module networking bus connections 720, which are connected to a first FDSI module housed in a first redundant UCM (e.g. UCM 214), are networked via a customized backplate with a right-hand row of fieldbus module networking bus connections 725, which are connected to a second FDSI module housed in a second redundant UCM (e.g. UCM 214).

[0039] Fig. Figure 8 shows a block diagram, globally designated 805, illustrating the functionality of the redundancy feature of UCM 214 according to one aspect of the invention. A left-hand UCM 810 (e.g., UCM 214) further comprises a first control processor 815 (e.g., control processor 226), a first FDSI 820 (e.g., FDSI 250), and a first safety controller 825 (e.g., safety module 254). A right-hand UCM 830 (e.g., UCM 214) comprises a second control processor 835 (e.g., control processor 226), a second FDSI 840 (e.g., FDSI 250), and a second safety controller 845 (e.g., safety module 254). The first control processor 815 and the second control processor 835 are connected by a first network bus 850. The first FDSI 820 and the second FDSI 840 are connected by a second network bus 850.In one embodiment, the first networking bus 850 and the second networking bus 855 are configured to use the customized backplate as with reference to . Fig. The communication described in Figure 7 and Table A is intended to be carried out. For demonstration purposes only, it is assumed that if a UCM component fails, such as the first FDSI 820 of the left-hand UCM 810, a switchover to a redundant module occurs, such as the second FDSI 840 of the right-hand UCM 830. This is made possible by the custom backplate connection via the first network bus 50. At the same time, a message informs an operator that the first FDSI 820 needs to be replaced. The operator can quickly physically remove the failed module or force a switchover from the module to the redundant module using the process management software for the distributed control system (DCS). At the time of removal, the remaining component, such as the first control processor 815, also switches over to the redundant component.

[0040] Redundant UCMs 214 are installed in the chassis 222 according to one embodiment of the present invention. The backplate 145 contains serial ports connected by serial cables. In one embodiment, the backplate 145 contains serial ports dedicated to the redundant UCMs 214. Meshed network fiber cables from the redundant UCMs 214 communicate with the meshed network 230 via a meshed splitter / combiner, and meshed network fiber cables connect, for example, to the workstation 234 of the process control system. In one embodiment, a first UCM (e.g., UCM 214) and a second UCM (e.g., UCM 214) are installed in a redundant configuration in slot 2 of the chassis 222. In addition, redundant power supplies, a first of three main processors installed in a triple redundant configuration, and safety controller 254 (or SIE) are installed in chassis 222 in one embodiment.

[0041] For illustrative purposes, programs and other executable program components (such as the operating system) are represented here as individual blocks. However, it must be acknowledged that such programs and components reside in different memory components of a computing device at different times and are executed by a data processor (or processors) of the device.

[0042] Although embodiments of aspects of the invention have been described in connection with an exemplary computer system environment, they can be operated with numerous other generally applicable or specifically applicable computer system environments or configurations. The computer system environment is not intended to impose any limitation on the scope of use or functionality of any aspect of the invention. Furthermore, the computer system environment should not be interpreted as imposing any dependency or requirement with respect to the components or combinations of components shown in the exemplary operating environment.Without being limited thereto, examples of generally known computing systems, environments and / or configurations that may be suitable for use with aspects of the invention include personal computers, server computers, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, peripheral devices, programmable consumer electronics, mobile phones, network PCs, minicomputers, mainframe computers, distributed computing environments incorporating any of the above-mentioned systems or devices, or the like.

[0043] Embodiments of the invention can be implemented in the general context of data and / or processor-executable instructions, such as program modules stored on one or more physical, non-volatile storage media and executed by one or more processors or other devices. Without limitation, program modules generally include routines, programs, objects, components, and data structures that perform specific tasks or implement special abstract data types. Aspects of the invention can also be implemented in distributed computing environments, where tasks are performed by remote processing devices connected by a communication network. In a distributed computing environment, program modules can be located on both local and remote storage media, including memory storage devices.

[0044] During operation, processors, computers and / or server processors can execute executable instructions (e.g., software, firmware and / or hardware) such as those shown here to implement aspects of the invention.

[0045] Embodiments of the aspects of the invention can be implemented using processor-executable instructions. These instructions can be organized in one or more processor-executable components or modules on a physical, processor-readable storage medium. Aspects of the invention can be implemented with any number and organization of such components and modules. For example, aspects of the invention are not limited to the specific processor-executable instructions or the components and modules shown and described in the figures. Other embodiments of the aspects of the invention may use different processor-executable instructions or components that have more or less functionality than shown and described here.

[0046] The order in which the operations are performed or carried out in embodiments of the aspects of the invention presented and described herein is not important unless otherwise specified. That is to say, unless otherwise specified, the operations can be performed in any order, and embodiments of the aspects of the invention may include additional or fewer operations than those disclosed herein. For example, it is envisaged that performing or carrying out a particular operation before, simultaneously with, or after another operation is within the scope of aspects of the invention.

[0047] When elements of aspects of the invention or its embodiments are presented, the articles "a", "an", "one", and "the" mean that there is one or more of the elements. The terms "comprise", "have", "include", and "have" are to be interpreted in an open-ended manner and mean that additional elements or elements other than those specified may be present.

[0048] In light of the above, it is evident that some advantages of the aspects of the invention will be achieved and other advantageous results will be obtained.

[0049] Not all of the components shown or described are necessary. Furthermore, some applications and embodiments may include additional components. Modifications to the arrangement and nature of the components are permissible without deviating from the spirit or scope of the claims stated herein. Additionally, different or fewer components may be provided, and components may be combined. Alternatively or additionally, a single component may be implemented by multiple components.

[0050] The above description presents aspects of the invention by means of examples and not in a limiting sense. This description enables the person skilled in the art to make and use the aspects of the invention and describes several embodiments, adaptations, modifications, alternatives, and uses of the aspects of the invention, including the one currently considered to be the best way of carrying out the aspects of the invention. Furthermore, it is understood that the aspects of the invention, in their application, are not limited to the design details and arrangement of components set forth in the following description or illustrated in the drawings. The aspects of the invention may have other embodiments and may be implemented or carried out in various ways.It is also understood that the expressions and terms used here are for explanatory purposes and should not be considered restrictive.

[0051] Having described aspects of the invention in detail, it is evident that modifications and variations are possible without deviating from the scope of the aspects of the invention as defined by the appended claims. It is considered that various modifications could be made to the above designs, products, and method without deviating from the scope of the aspects of the invention. In the preceding description, various preferred embodiments were described with reference to the accompanying drawings. However, it is obvious that various modifications and changes can be made to these, and further embodiments can be implemented, without deviating from the broader scope of the aspects of the invention as set forth in the following claims. Accordingly, the description and the drawings are to be understood in an explanatory rather than a limiting sense.

[0052] The summary is intended to help the reader quickly grasp the content of the technical description. It is provided with the understanding that it is not intended to interpret or limit the scope or meaning of the claims.

[0053] Accordingly, the invention also relates to a fault-tolerant control system that provides an embedded functional safety kernel and a distributed control engine with an onboard communication link in an industrial process control environment. The fault-tolerant control system comprises a process control workstation connected to a first network and a fault-tolerant safety controller connected to a second network, wherein a process control module, a safety control module, and a field device system integration module are jointly arranged on a network interface card. Table A: Backplate network interface card with connector pinout 96-pin DIN male connectors; PINS A, B and C PIN-Nr. A SIGNALNAME BEMERKUNGEN 1 FBDATPOSA Feldbus 2 FBDATNEGA 3 FBSH 4 JGSER_1 5 JRXD_1 Serieller Port-1 6 JTXD_1 7 JDTR_1 8 JDSR_1 9 JGSER_1 10 OS_IN State-Exchange CLK IN 11 INSH Inter Link Bus von CP270 12 INSH 13 INTXNEGB 14 INTXPOSB 15 INRXNEGB 16 INRXPOSB 17 INTXNEGA 18 INTXPOSA 19 INRXNEGA 20 INRXPOSA 21 DPHY_SHIELD D-Bus Common 22 DPHY_SHIELD 23 DPHY_SHIELD 24 DPHY_SHIELD 25 CPHY_SHIELD C-Bus Common 26 CPHY_SHIELD 27 CPHY_SHIELD 28 CPHY_SHIELD 29 SPHY_SHIELD State Bus Common 30 SPHY_SHIELD 31 SPHY_SHIELD 32 SPHY_SHIELD PIN - NR. B SIGNALNAME BEMERKUNGEN 1 FBSH Feldbus 2 FBSH 3 FBSH 4 JCTS_2 5 JCD_2 6 JRTS_2 7 JCD_1 8 JRTS_1 9 JCTS_1 10 Logic GND 11 Logic GND 12 Logic GND 13 Logic GND 14 Logic GND 15 Logic GND 16 Logic GND 17 Logic GND 18 Logic GND 19 Logic GND 20 Logic GND 21 DPHY_TPFON D-Bus Ethernet Schnittstelle 22 DPHY_TPFOP 23 DPHY_TPFIN 24 DPHY_TPFIP 25 CPHY_TPFON C-Bus Ethernet Schnittstelle 26 CPHY_TPFOP 27 CPHY_TPFIN 28 CPHY_TPFIP 29 SPHY_TPFON State Bus Ethernet Schnittstelle 30 SPHY_TPFOP 31 SPHY_TPFIN 32 SPHY_TPFIP PIN - NR. C SIGNALNAME BEMERKUNGEN 1 FBDATPOSB Feldbus 2 FBDATNEGB 3 FBSH 4 JGSER_2 5 JRXD_2 Serieller Port -2 6 JTXD_2 7 JDTR_2 8 JDSR_2 9 JGSER_2 10 OS_OUT State_Exchange CLK OUT 11 RXTX_SH State_Exchange E / ASchnittstelle von CP270 12 TX186NEG 13 TX186POS 14 RX186NEG 15 RX186POS 16 RXTX_SH 17 AB_DT_POSA Inter Link Bus vonFBM233 18 AB_DT_POSB 19 AB_DT_NEGA 20 AB_DT_NEGB 21 DPHY_SHIELD D-Bus Common 22 DPHY_SHIELD 23 DPHY_SHIELD 24 DPHY_SHIELD 25 CPHY_SHIELD C-Bus Common 26 CPHY_SHIELD 27 CPHY_SHIELD 28 CPHY_SHIELD 29 SPHY_SHIELD State Bus Common 30 SPHY_SHIELD 31 SPHY_SHIELD 32 SPHY_SHIELD

Claims

[1] Fault-tolerant control system that includes: a process control system workstation that is effectively connected to a first network; a fault-tolerant safety controller that is effectively connected to a second network; an interface between the process control workstation and the fault-tolerant safety controller, wherein the interface includes: a process control module that is effectively connected to the first network; a security control module that is effectively connected to a second network; and a field device system integration module for communicating safety information from the safety control module to the process control module; wherein the process control module, the safety control module and the field device system integration module are arranged together on a network interface card, characterized by, that the fault-tolerant control system further comprises a three-port switch arranged on the network interface card, wherein the three-port switch is configured to communicate with the safety control module and the field device system integration module via a selected link between them, the selected link maintaining a functional and physical separation between the first network and the second network. [2] Fault-tolerant control system according to claim 1, wherein the first network comprises a distributed control system (DCS) network and wherein the second network comprises a safety system (SIS) network. [3] Fault-tolerant control system according to claim 1 or claim 2, wherein the interface is configured to implement a redundancy procedure on the SIS network. [4] Fault-tolerant control system according to claim 3, wherein the interface is further configured to adapt the redundancy approach of the SIS network to the DCS network. [5] Fault-tolerant control system according to any one of claims 2 to 4, wherein the interface is configured to implement a redundancy procedure on the DCS network. [6] Fault-tolerant control system according to any one of claims 2 to 4, wherein the interface is configured for the holistic presentation of information in the DCS network. [7] Fault-tolerant control system according to claim 6, wherein the information comprises SIS network information. [8] Fault-tolerant control system according to claim 6 or claim 7, wherein the information comprises one or more of the following: event sequence (SOE) data, SIS time-stamped data, system general status data and equipment general status data. [9] Fault-tolerant control system according to any of the preceding claims, wherein the modules comprise a plurality of input / output (I / O) cards effectively connected to the network interface card. [10] Fault-tolerant control system according to claim 9, further comprising a chassis for housing the I / O cards and the network interface card. [11] Fault-tolerant control system according to claim 10, wherein the chassis accommodates a backplate configured to accommodate the network interface card. [12] Communication interface for a fault-tolerant controller, which includes: a process control module that is effectively connected to a regulatory network; a security control module that is effectively connected to a security network; a field device system integration module for communicating safety information from the safety control module to the process control module; and a three-port switch configured to connect the safety control module and the field device system integration module via a selected connection; wherein the three-port switch isolates communications from the process control module via the field device system integration module to the safety control module, and wherein the communication interfaces appear as a control station on the regulatory network. [13] Communication interface according to claim 12, wherein the modules comprise a plurality of input / output (I / O) cards effectively connected to a network interface card. [14] Communication interface according to claim 13, further comprising a chassis for housing the I / O cards and the network interface card. [15] Communication interface according to claim 14, wherein the chassis further accommodates a backplate configured to accommodate the network interface card. [16] Communication interface according to any one of claims 12 to 15, wherein the three-port switch comprises an Ethernet switch. [17] Communication interface according to claim 16, wherein the selected connection further maintains a functional and physical separation between the regulatory network and the security network. [18] Fault-tolerant control, which includes: a modified backplate interface; a main processor effectively connected to the modified backplate interface; and a network interface card effectively connected to the modified backplate interface, the network interface card comprising: a process control module; a safety control module that is effectively connected to the main processor; a field device system integration module; and a three-port switch that is effectively connected to the safety control module and the field device system integration module; where the three-port switch is configured to communicate with the safety control module and the field device system integration module via a selected connection. [19] Fault-tolerant control according to claim 18, further comprising a second network interface card which is installed in a redundant configuration in the modified backplate interface. [20] Fault-tolerant control according to any one of claims 18 to 19, wherein the three-port switch further comprises an Ethernet switch. [21] Fault-tolerant control according to any one of claims 18 to 20, wherein the selected connection maintains a functional and physical separation between a first network and a second network.

Citation Information

Patent Citations

  • Circuit for transmitting signals in a network node, particularly for a channel card for an optical wavelength division multiplex (WDM) signal transmitting device

    EP1751896B1

  • Integrated diagnostics in a process plant having a process control system and a safety system

    US6975966B2