A master-slave redundant control system and a control method
By using programmable logic devices to build a redundant switching link in the master-slave redundant control system, the problems of long redundant switching cycles and poor real-time performance in the prior art are solved, and the master-slave switching and high reliability in microseconds are achieved.
Patent Information
- Application Number
- CN202210830298.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-15
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-07-15
AI Technical Summary
The prior art has a long switching cycle and poor real-time performance when the controller is redundant. As the controller load increases, the switching cycle and jitter will increase, making it difficult to achieve microsecond master-slave switching.
Programmable logic devices are used to build a redundant switching link, and the master-slave switching logic is written and read through the SPI interface between the processor and the logic device. The logic device realizes efficient communication without the participation of the processor, and reduces processor load and switching jitter through the serial transceiver module and the redundant state change module.
The redundant switching period is achieved to the microsecond level, reducing the jitter of the switching period, decoupling the redundant switching process from the controller load, and improving the reliability and applicability of the redundant control system.
Smart Images

Figure CN115113516B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for redundant communication and master-slave switching applied to a master-slave redundant control system. Background Art
[0002] In the field of industrial automation with high reliability requirements, the method of controller hot standby redundancy is adopted to improve the reliability of the entire system. Currently, the control system adopts methods such as controller redundancy, module redundancy, communication link redundancy, power supply redundancy, and network device redundancy to improve the reliability of the system.
[0003] Among them, for controller redundancy, two or more redundant controllers need to control data synchronization and master-slave control switching. In the event of a failure of the master controller, it should be promptly switched to a slave controller, and at the same time, the slave controller as a redundant backup should be promptly switched to the master controller.
[0004] Currently, the main methods adopted are as follows: 1. A redundant switching circuit composed of a hardware circuit. The main advantage of this method is that the circuit is simple and reliable, but the disadvantage is poor scalability, simple information for master-slave switching of the controller, and inability to increase the judgment logic for redundant switching according to the expansion of the system; 2. Using a dedicated communication link for redundant switching communication. The advantages of this method are simple circuit and expandable communication information, but the disadvantage is poor real-time performance. Especially as the load of the controller increases, the cycle of redundant communication is uncertain, there is a switching cycle jitter, and it is also difficult to achieve microsecond-level master-slave switching; 3. Using a dedicated logic device to construct a communication link. This method combines the advantages of the above-mentioned schemes, has scalability, simplified circuit, verifiable communication data, high real-time performance, reaches a microsecond-level communication cycle, small switching jitter, reduces the controller load, and does not increase the redundant switching cycle as the load of the controller increases. It is suitable for some application scenarios with fast and non-disruptive switching. Summary of the Invention
[0005] The present invention aims to reduce the master-slave switching cycle of the hot standby redundant controller, reduce the jitter of the switching cycle, decouple the redundant switching process from the load of the controller, increase the verification of communication data, and thus improve the reliability of the redundant control system. Achieving a microsecond-level accuracy of the redundant switching cycle makes the control system more applicable to different industrial application scenarios.
[0006] The technical solution adopted by the present invention is as follows:
[0007] A master-slave redundant control system includes two controllers that can perform master-slave switching according to the working state; one controller works in the master state, and the other controller works in the slave state as a redundant backup and performs master-slave switching according to the working state. Each controller includes:
[0008] A processor to implement the control logic of the master and slave controllers;
[0009] A communication interface, serving as the transmission interface for the synchronization status message of the controller;
[0010] An Ethernet interface, serving as the transmission interface for the synchronization data message of the controller;
[0011] A logic device, implementing the transceiver control for master-slave switching and master-slave synchronization logic.
[0012] The logic device adopts a programmable logic device to construct a redundant switching link. The main purpose is to solve the problem of redundant switching by the controller directly participating in constructing the communication link. Whether in the way of periodic query or interruption for the direct communication link of the controller, it will increase the controller load. At the same time, as the peripheral control logic of the controller increases, the redundant switching period will also increase accordingly, and the jitter of redundant switching will also increase. The programmable logic device can achieve efficient communication between the master and slave controllers without the participation of the controller, and will not increase the redundant switching period with the increase of the controller load, with small switching jitter. At the same time, it has high communication scalability. After adding communication data verification, the communication reliability increases, and the redundant switching period can reach the microsecond level.
[0013] In the redundant hot standby controller of the present invention, redundant switching messages and redundant data messages are distributed and transmitted through the communication interface and the Ethernet interface to ensure the real-time performance of redundant switching.
[0014] Among them, the processor provides an SPI interface to communicate with the logic device. The SPI interface provided by the processor realizes the transceiver of bidirectional data, including writing status information to the logic device and reading status information. The SPI interface provided by the processor only realizes the writing and reading of the master-slave switching logic. The processor writes the status of the local machine within the control cycle. The processor reads the redundant status in an interrupt manner. By this way, the load of the processor can be reduced, and in addition, the speed of the processor to obtain the redundant status can be improved. The processor to obtain the redundant status does not only support the interrupt mode. The full-duplex communication mode of SPI also supports obtaining the redundant status while the processor issues the status of the local machine.
[0015] Further, the above-mentioned logic device includes:
[0016] An SPI interface, connected to the processor, receiving the status information of the local machine issued by the processor and updating it into the local machine status, and at the same time responding to the command of the processor to read the redundant status and sending the redundant status to the processor;
[0017] A serial transceiver module, including serial sending and serial receiving to form the full-duplex communication of the serial transceiver module. This module receives the redundant status while sending the status of the local machine;
[0018] The redundancy status change module issues an interrupt to the processor when a redundancy status change is detected.
[0019] The present invention reduces the load of the processor and improves the speed at which the processor obtains the redundancy status through the redundancy status change module. When the redundancy status has not changed, no interrupt is generated and the processor does not read the redundancy status; when the redundancy status changes, an interrupt is generated and the processor reads the redundancy status. And a serial receiving and sending module is used for data receiving and sending, which does not occupy the processing time of the processor, and the local machine status is sent to the redundancy controller in a calculable time and cycle, and at the same time, the status of the redundancy controller is obtained to the local machine. The serial receiving and sending module constructs a communication message, and the sending message of the serial sending module includes the local machine status and check information; at the same time, the serial receiving module receives the message, and the received message needs to be checked. When there is no error in the message, the redundancy status is updated, and when there is an error in the message check, an error flag is sent to the processor.
[0020] The present invention also provides a master-slave redundancy control method, which adopts the following redundancy switching logic: the processor sends the local machine status to the logic device according to the status of the present controller, the logic device obtains the local machine status, adds check information, and sends a message within a fixed period; the logic device simultaneously receives the message, checks the received message data, updates the redundancy status when the checked message has no error, and when it detects that the redundancy status has changed, sends an interrupt to the processor, and the processor reads the redundancy status; the logic device sends an error flag to the processor when the checked message is in error.
[0021] The logic control message for redundancy switching in the present invention is transmitted in the communication interface, and this interface only transmits the messages for redundancy switching, which improves the real-time performance of redundancy switching. The processor is not directly involved in data receiving and sending, so the level of the processor load does not affect the data receiving and sending cycle, and this method solves the jitter of the redundancy switching cycle caused by different processor loads.
[0022] More specifically, the master-slave redundancy control method includes the following steps:
[0023] The processor periodically sends the local machine status to the SPI interface of the logic device according to the status of the present controller;
[0024] After the SPI interface receives the local machine status, it enters the next waiting period;
[0025] After the serial sending module obtains the local machine status, it adds CRC8 check information and sends a message;
[0026] The communication interface receives the status message sent by the redundancy controller;
[0027] The redundancy status change module updates the redundancy status according to the reception of the status message of the redundancy controller; in the case of a change in the redundancy status, an interrupt is sent to the processor.
[0028] The processor reads the redundancy status in an interrupt manner. After the reading is completed, the redundancy status change module clears the interrupt and proceeds to the next monitoring redundancy status cycle.
[0029] Furthermore, the master-slave redundancy control method also uses an Ethernet interface to send and receive control data messages of the master and slave controllers. This Ethernet interface mainly serves as the communication interface for redundancy switch data messages, and its main function is the control data synchronization between the master controller and the slave controller.
[0030] Furthermore, when the communication interface does not receive the status message sent by the redundancy controller within a communication cycle, it is determined that the redundancy controller does not exist, the redundancy status is cleared, the processor is notified, and the local controller enters the single-machine operation state. In this state, it continuously waits for the message data received by the communication interface and exits the single-machine mode when data is received; when the communication interface receives the status message sent by the redundancy controller and there is no error after data verification, the redundancy status is updated, and the control system enters the dual-machine redundancy control state.
[0031] The present invention has the following advantages compared with the prior art:
[0032] 1) In the control system of the present invention, the redundancy hot standby controllers transmit redundancy switch messages and redundancy data messages through the communication interface and the Ethernet interface respectively, ensuring the real-time nature of redundancy switching.
[0033] 2) The programmable logic device is used for the sending and receiving of the redundancy switch message. The length of the redundancy switch message can be extended, and the message contains the network diagnosis information, power supply diagnosis information, and module diagnosis information of the present controller, so as to facilitate the controller to support more complex redundancy switching logic, and check information is added to the message, making the communication more reliable.
[0034] 3) The logic device transmits the redundancy switch message, and the processor does not participate in the sending and receiving of the message. On the one hand, the logic device sends an interrupt to the processor after detecting a status change, reducing the load of the processor. On the other hand, the message sending period of the logic device is fixed, reducing the switching jitter of the redundancy controller. The entire communication cycle of the redundancy switch message is within 7.52 us, the message processing cycle is within 50 us, and the redundancy switching cycle is within 100 us. Compared with the method controlled by the processor within 1 - 10 ms, the redundancy switching speed is increased by more than 10 times. Description of the Drawings
[0035] Figure 1 This is the topological structure of the present invention.
[0036] Figure 2This is the block diagram of the redundant switching module of the controller of the present invention.
[0037] Figure 3 This is the state machine jump diagram of the logic device in the present invention. Specific embodiments
[0038] The present invention will be further described below with reference to the accompanying drawings.
[0039] The present invention is a method for redundant communication and redundant switching applied to a master-slave redundant control system, and this method is applied to the master-slave synchronization and master-slave switching between redundant controllers. The main purpose is to achieve the rapid switching of the master-slave controllers, reduce the cycle jitter of the master-slave switching, and at the same time make the master-slave switching have the characteristics of functional scalability and high reliability. The state transition control of the master-slave controllers is realized by a programmable logic device, which solves the problem of the change in switching speed caused by directly performing redundant switching by the CPU, reduces the influence of the controller communication cycle on the redundant switching cycle, and also reduces the controller switching cycle jitter. The master and slave controllers send the state of the slave controller to the master controller in the form of a message within a fixed cycle, and at the same time send the state of the master controller to the slave controller. This message contains the states of the master and slave controllers and data verification information. The communication message is realized by the programmable logic device for sending and receiving. By adopting the message method, the problem of the scalability of the master-slave switching composed of fixed connection lines is solved, and at the same time, verification information can be added to ensure the reliability of communication.
[0040] As Figure 1 , the present invention includes two completely identical controllers 1 and 2, and the controller 1 and the controller 2 are redundant backups for each other. One of the controller 1 or the controller 2 works in the master controller state, is responsible for the processing of the entire control logic, monitors the communication of the device, controls the field device, and at the same time actively transmits the control data to the redundant controller through the Ethernet interface 14. The other controller is in the redundant backup state, receives the control data sent by the master controller through the Ethernet interface 14, and achieves complete synchronization with the master controller. Under the condition that the master controller sends a fault, two processing logics are generated. One is that the master controller actively sends the fault information of the master controller to the slave controller through the communication interface 13. When the slave controller switches itself to the master controller, it will send a state transition message to switch the master controller to the slave controller; in another case, when the master controller fails and is unable to send a state message, within the time when the slave controller sends the state to the master controller through the communication interface 13 and does not receive the state message sent by the master controller, it is determined that the master controller has gone offline, and the slave controller actively switches to the master controller.
[0041] The logic device 12 is responsible for implementing the data link layer of redundant data communication and redundant status communication. It communicates externally with the communication interface 13 and the Ethernet interface 14, and internally with the processor 11, decoupling the internal and external communications to prevent the increase in the load of the processor 11 from affecting the cycles of redundant data communication and redundant status communication, and at the same time preventing external data communication from increasing the load of the processor 11. Without the participation of the processor 11, the logic device actively sends and receives redundant status data, receives the status information sent by the processor 11, and actively sends status information to the processor 11 when the redundant status changes.
[0042] As Figure 2 shown, the redundant switching logic block diagram in the controller. The processor 11 includes a peripheral that can act as an SPI master. SPI supports full-duplex communication. The communication cycle of a single byte is 320 ns at a 25 MHz clock, and this interface can receive the redundant status 124 while sending the local status 123.
[0043] First, the processor 11 periodically sends the local status 123 to the SPI 121 of the logic device 12 through the SPI peripheral according to the status of this controller (information such as network status, power status, device communication status, etc.). Due to the full-duplex communication mode of SPI 121, the processor 11 can receive the redundant status 124 while sending. This method is the way for the processor 11 to actively query the redundant status 124 when the redundant status 124 has not changed. At the same time, the processor 11 supports reading the redundant status in the form of an interrupt when the redundant status 124 changes. These two methods ensure the periodic diagnosis of the working status of the controller by the processor 11 and the immediate response processing of the status change of the master and slave controllers. The task cycle of the periodic diagnosis of the processor is 50 us.
[0044] The logic device 12 includes an SPI 121, which is a slave device in the SPI master-slave communication. The slave device cannot send communication clocks and can only respond to the communication commands of the SPI master device of the processor 11. Therefore, the SPI 121 of the logic device 12 cannot initiate communication actively and can only wait for the commands of the processor 11. The logic device 12 includes a serial transceiver module 122, which includes two parts: serial transmission and serial reception. This module sends the parallel data at a baud rate of 2.5 MHz.
[0045] After the serial transmission module obtains the local status 123, it adds CRC8 check information, constructs a transmission message, and hands the transmission message to the serial transmission module for sending;
[0046] The serial receiving module receives a message, which contains redundant status information and CRC8 check information. After the serial receiving module converts the serial data into parallel data and temporarily stores it, it checks the received data. If the message is error-free, it updates the redundant status 124. If there is an error in the message check, it sends an error flag to the processor 11.
[0047] The logic device 12 includes a redundant status change module 125, which can effectively reduce the load of the processor 11 and improve the response speed of the processor 11, thereby improving the master-slave switching speed of the redundant control system. When the redundant status change module 125 detects a change in the redundant status 124, it generates an interrupt to the processor 11. After the processor 11 quickly responds to the interrupt, it reads the redundant status 124 through the SPI interface.
[0048] As Figure 3 shown, it is the state machine jump diagram of the logic device 12. The functional requirements of this logic device 12 are: ① Respond to the data sent by the processor 11; ② Send the local status 123 within a fixed period; ③ Wait to receive data, initially judge the status of the redundant controller according to the received data, and send the data to the processor 11 under specific circumstances.
[0049] Figure 3 The state jump of the logic device 12 is as follows. After the controller 1 and the controller 2 are started, the logic device 12 simultaneously creates four functional modules, which are responsible for SPI reception, sending the local status, receiving the redundant status, and redundant status change respectively. The four functional modules execute in parallel.
[0050] SPI reception: After the controller 1 or the controller 2 is powered on, it always waits for the communication command of the processor 11. After receiving the data (local status 123), it enters the next waiting cycle.
[0051] Sending the local status: After the controller 1 or the controller 2 is powered on, it has been sending the local status 123 received by SPI. During the startup process of the processor 11, the local status 123 is all 0. This status is sent to the redundant controller, and the redundant controller can judge that this controller exists but is in the startup process. Therefore, the periodic sending of the local status module cannot be interrupted. After the interruption, the redundant controller judges that the local controller does not exist and will switch the redundant controller to the master controller status. After the controller 1 or the controller 2 is normally started, the SPI will receive the local status 123 information sent by the processor 11, and this information will be updated to the local status sending module.
[0052] Receiving the redundant status (executed by the serial transceiver module): After the controller 1 or the controller 2 is powered on, it always waits for the data input by the communication interface 13. As Figure 3As shown, the data input by the communication interface 13 is divided into two different situations. In one situation, if no data sent by the redundant controller is received within a communication cycle, it is determined that the redundant controller does not exist. After clearing the redundant state 124, the processor 11 is notified, and controller 1 or controller 2 enters the single-machine operation state. In the single-machine operation state, the serial transceiver module is also continuously waiting for the data input by the communication interface 13. If data is received, the single-machine mode is exited. In the other situation, if the communication interface 13 receives the data sent by the redundant controller and there is no error after data verification, the redundant state 124 is updated, and the control system enters the dual-machine redundant control state.
[0053] Redundant state change (executed by the redundant state change module). After controller 1 or controller 2 is powered on, it has been monitoring the redundant state 124. After the redundant state 124 changes, an interrupt is sent to the processor 11 and waits for the processor 11 to read the redundant state 124. After the processor 11 sends a read command through the SPI peripheral and the reading is completed, the redundant state change module needs to clear this interrupt and start the next cycle of monitoring the redundant state 124.
[0054] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, several improvements can be made without departing from the principle of the present invention, and these improvements should also be regarded as the protection scope of the present invention.
Claims
1. A master-slave redundant control system, comprising two controllers that can be switched between master and slave according to the working state; Characterized in that, Each controller includes: A processor to implement the control logic of the master and slave controllers; A communication interface, serving as the transmission interface for the synchronization status messages of the controller; An Ethernet interface, serving as the transmission interface for the synchronization data messages of the controller; A logic device to implement the transceiver control of the master-slave switch and master-slave synchronization logic; The logic device includes: An SPI interface, connected to the processor, receiving the local status information sent by the processor and updating it to the local status, and at the same time responding to the command of the processor to read the redundancy status and sending the redundancy status to the processor; A serial transceiver module, including serial transmission and serial reception to form the full-duplex communication of the serial transceiver module, which receives the redundancy status while sending the local status; A redundancy status change module that issues an interrupt to the processor when it detects a change in the redundancy status.
2. A master-slave redundant control method using the master-slave redundant control system according to claim 1, Characterized in that, The following redundancy switching logic is adopted: The processor sends the local status to the logic device according to the status of the local controller. The logic device obtains the local status, adds check information, and sends messages within a fixed period; The logic device simultaneously receives messages, checks the received message data. When the message check has no error, it updates the redundancy status, and when it detects a change in the redundancy status, it sends an interrupt to the processor, and the processor reads the redundancy status; The logic device sends an error flag to the processor when the message check is incorrect.
3. According to the master-slave redundant control method described in claim 2, Characterized in that, The master-slave redundant control method includes the following steps: The processor periodically sends the local status to the SPI interface of the logic device according to the status of the local controller; After the SPI interface receives the local status, it enters the next waiting period; After the serial transmission module obtains the local status, it adds CRC8 check information and sends a message; The communication interface receives the status message sent by the redundant controller; The redundancy status change module updates the redundancy status according to the reception of the status message of the redundant controller; when the redundancy status changes, it issues an interrupt to the processor; The processor reads the redundancy status in the form of an interrupt. After the reading is completed, the redundancy status change module clears the interrupt and proceeds to the next monitoring redundancy status cycle.
4. According to the master-slave redundant control method described in claim 3, Characterized in that, The master-slave redundant control method also uses the Ethernet interface to send and receive the control data messages of the master and slave controllers.
5. According to the master-slave redundant control method described in claim 4, Characterized in that, When the communication interface does not receive the status message sent by the redundant controller within a communication cycle, it is determined that the redundant controller does not exist, the redundant status is cleared, the processor is notified, and the local controller enters the single-machine operation state. In this state, it continuously waits for the message data received by the communication interface and exits the single-machine mode when data is received; when the communication interface receives the status message sent by the redundant controller and there is no error after data verification, the redundant status is updated and the control system enters the dual-machine redundant control state.
Citation Information
Patent Citations
Duplex system state confirming circuit
JP1994110859A
Duplex control device and redundancy method of its control right setting signal
JP2008146236A