Method for operating an automation system, automation system, and control system

By adopting a redundant structure control system in the cloud computing structure, and using the collaborative work of the main device and the backup device, the problem of insufficient real-time capability and reliability of the cloud-based automation facility control system is solved, and more efficient response and system availability are achieved.

CN115145188BActive Publication Date: 2025-07-29SIEMENS AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210320755.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-03-30
Filing Date
2022-03-29
Publication Date
2025-07-29
Estimated Expiration
2042-03-29

AI Technical Summary

Technical Problem

Cloud-based automation facility control systems have shortcomings in real-time capabilities and reliability, resulting in fluctuations in response time and usage limitations.

Method used

A cloud-based control system with a redundant structure uses control applications set at different locations as the master and backup devices, and processes control programs almost simultaneously and transmits data packets over the network to ensure the redundancy and real-timeness of the system.

Benefits of technology

Improves the response time and system availability of automation facilities, enables complex and long-term control functions, while reducing the negative impact of long transmission time on control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115145188B_ABST
    Figure CN115145188B_ABST
Patent Text Reader

Abstract

The present invention relates to a cloud-based automation solution with high availability and optimized transmission time. The real-time capabilities should be improved in a cloud-based control system for an automation facility (AA). For this purpose, a redundantly configured cloud-based control system is proposed, which has a plurality of computing resources distributed over a network (N), the computing resources having control applications running thereon, and the control applications implemented as master device (PR) and backup devices (BU; BU1 - BU4) process control programs almost simultaneously and send the corresponding program instructions to the automation facility (AA). Thus, the long transmission times of the individual computing resources do not negatively affect the control of the automation facility (AA).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for operating an automation system, which includes at least one automation facility to be controlled located at a facility location and at least two control applications provided for controlling the automation facility. The control applications form part of a cloud computing architecture, the computing resources of the control applications are set at different locations, and the control applications are communicatively connected to each other via a network and communicatively connected to the automation facility. The network has a plurality of communication nodes and communication paths connecting the communication nodes to each other, wherein a first control application among the control applications operates as a master device and at least one second control application among the control applications operates as a backup device.

[0002] The present invention also relates to an automation facility for performing such a method and a redundant cloud-based control system. Background Art

[0003] There have been recent attempts to run control functions for automation facilities based on computing resources in a cloud environment. Here, the control program for controlling the automation facility is processed by a control application on an application server and communicates with the local peripheral units of the automation facility via a global network (Internet).

[0004] This processing method has some advantages, such as the problem-free scalability of control functions when the requirements for control tasks change.

[0005] In addition, it is easier to update application software (especially control programs) and system software (especially control applications).

[0006] Here, a major challenge is that cloud-based services are currently less reliable, and the communication between the application server and the peripheral units lacks real-time capabilities. This results in strongly fluctuating response times and thus limits the usage possibilities of cloud-based automation.

[0007] Due to the poor availability of cloud-based services and the lack of real-time capabilities in the global network (Internet), currently installed automation systems with dedicated hardware are used today.

[0008] A redundant automation system and a method for operating such an automation system are known from EP 2657797 A1. The automation system includes first and second subsystems, wherein the subsystems respectively process control programs in parallel during the control engineering process, wherein one of the subsystems operates as a host and the other subsystem operates as a slave, and wherein in the case of failure of the host, the slave takes over the functions of the host.

[0009] An automated system having at least two subsystems and a method for operating such an automated system are known from EP 2667269 A1, wherein the subsystems each have a control program, and wherein, in order to transition process control from the individual operation of one of the subsystems to a redundant control operation, data of one subsystem that is relevant to another subsystem in the subsystem is transmitted to the other subsystem within the update phase of the automated system. SUMMARY OF THE INVENTION

[0010] An object of the present invention is to improve the real-time capability in the control of an automated facility based on computing resources in a cloud environment.

[0011] The object is achieved by the method of the present invention, that is, a method for operating an automated system is proposed, the automated system including at least one automated facility to be controlled disposed at a facility location and at least two control applications provided for controlling the automated facility, the control applications forming part of a cloud computing architecture, the computing resources of the control applications being located at different positions, and the control applications being communicatively connected to each other via a network and communicatively connected to the automated facility via a network, wherein the network has a plurality of communication nodes and communication paths connecting the communication nodes to each other, wherein a first control application among the control applications operates as a master device and at least one second control application among the control applications operates as a backup device, wherein the master device receives a first data packet output by the automated facility via the network, the first data packet including input values of the automated facility, wherein the master device processes the input values according to specific program instructions of a control program and generates output values for actuators included in the automated facility therefrom, wherein the control applications include program instructions, and the program instructions are present in at least substantially the same form in the master device and the backup device, wherein a second data packet including the input values is transmitted to the backup device via the network, wherein a permission is transmitted from the master device to the backup device, wherein the program instructions of the control program to be processed by the backup device are processed based on the permission, the program instructions corresponding to the processed specific program instructions of the control program to be processed by the master device, and the backup device also generates output values for actuators included in the automated facility therefrom, wherein a third data packet including the corresponding output values is sent to the automated facility from both the master device and the backup device, and wherein the third data packet that first arrives at the automated facility is used for controlling the actuators.

[0012] The advantage provided by this processing method is that in the cloud computing architecture according to the present invention, a plurality of control applications process the control program almost simultaneously and send corresponding control instructions to the automated facility, wherein the cloud computing architecture is configured redundantly (redundant), in the form of a cloud-based control system. Therefore, the long transmission times of the individual computing resources do not have a negative impact on the control of the automated facility.

[0013] Advantageously, during operation of the automation system, a first data packet with a corresponding current input value is continuously generated by the automation facility and transmitted to the master device, a second data packet with an input value is generated by the automation facility or the master device and transmitted to the backup device, and a third data packet with a corresponding current output value is generated by the master device and the backup device and transmitted to the automation facility.

[0014] The generation and reading of the first data packet can be initiated by the automation facility. Advantageously, the peripheral unit sends the input value to the master device and all backup devices via all available logical connections, for example according to the PROFINET standard for system redundancy, in particular by multicast.

[0015] The peripheral unit preferably sends the current input data to the master device periodically (in particular in the case of using the PROFINET standard). The master device stores the data in a buffer. In the buffer, the data is continuously updated by the peripheral unit and overwritten here. The master device accesses the buffer when needed.

[0016] Optionally, the data is read from the automation facility on the part of the master device. This means that: the master device initiates the generation and reading of the first data packet on the part of the automation facility by means of a corresponding read access.

[0017] The input value can be any value from the control application, which is taken into account by the control application when controlling the automation facility. For example, it can be an actual value or a sensor value detected by a sensor. However, the input value can also be generated from one or more sensor values, for example as a result of signal processing performed in the automation facility. In addition, the input value can also relate to the state of the automation facility or be generated from such a state. The value of a specific parameter or a specific variable also belongs to the term "input value".

[0018] The input value is taken into account when processing the control program, and an output value related to the input value is generated for the actuator included in the automation facility. In particular, the output value is a control instruction for the actuator. Thus, a regulator structure can be implemented by means of a cloud-based control system, in which the actual value in the form of an input value is detected by a sensor, the actual value is compared by the control system with a predetermined value, and an output value in the form of a manipulated variable for the actuator is generated therefrom and fed to the actuator.

[0019] An actuator in the sense of the present invention is generally a structural unit that performs an action in the automation facility. Here, it is in particular an actuator that causes the movement of a component of the automation facility or causes a change in a physical variable, such as pressure or temperature. For example, the actuator is a drive, a valve or a switch.

[0020] Therefore, the reason for calling it an "input value" or "output value" is that from the perspective of the control system, it is an input value or an output value.

[0021] Obviously, for example, if the automation facility includes a machine with multiple axes that move jointly, a data packet can also contain more than one input value or more than one output value, that is, the actual values of all axes or the control instructions for the axes. Therefore, generally, the first data packet includes multiple actual values or input values from the automation facility, and the third data packet includes multiple output values or manipulated variables or control variables.

[0022] In addition to the shortened response time, the present invention also provides the following advantages: With the aid of the automation system, complex control functions and control functions extending over a long period of time can also be executed. Overall, the availability of the control system according to the present invention is improved compared to traditional cloud-based control devices.

[0023] In a design of the present invention, the second data packet including the (current) input value is transmitted from the master device to the backup device via the network. Thereby, the master device has control over which data packet is transmitted to the backup device.

[0024] Generally, the cloud computing architecture does not include only one backup device, but multiple backup devices. Therefore, the above and the following statements about the "backup device" similarly apply to all backup devices of the cloud computing architecture.

[0025] In the cloud computing architecture, the master device is responsible for synchronizing the individual participants. The possibility of achieving the synchronization lies in that the master device sends the current input values to all backup devices as simultaneously as possible by means of the second data packet.

[0026] In an alternative design of the present invention, the second data packet including the input value is transmitted directly from the automation facility to the backup device via the network, that is, without passing through the route of the master device.

[0027] In particular, the first and second data packets belonging to a specific input value are almost the same. Then, the data packets may only differ in one or more recipient network addresses.

[0028] This design sometimes brings a time advantage compared to the previously mentioned design. Of course, the synchronization must be carried out in a different way, for example, via a permission signal, as will be explained in more detail below.

[0029] Therefore, the first data packet is characterized in that it is respectively generated by the automation facility, includes the current input value at the generation time point, and is transmitted from the automation facility to the master device.

[0030] The second data packet is characterized in that it is generated either by an automation facility or by the master device, includes the input values current at the time of transmission, and is transmitted to the backup device.

[0031] The third data packet is characterized in that it is generated by the master device and the backup device, includes the output values current at the time of transmission, in particular one or more current control instructions, and is transmitted to the automation facility.

[0032] The master device and one or more backup devices are also referred to hereinafter as "one subsystem" or "multiple subsystems".

[0033] The synchronization between the master device and one backup device (or multiple backup devices) by means of a license is described in more detail below. As will be explained in more detail later, "synchronization" in the context of the present invention does not mean that two subsystems (master device and backup device) precisely execute the same program steps simultaneously. Rather, synchronization should be understood as follows: The two subsystems are not permitted to process the program independently of each other, but there is a coupling of the subsystems during program processing, which will be explained in more detail below. Therefore, "synchronization" in the context of the present invention can also be referred to as "path synchronization", which should mean that all synchronized subsystems must pass through the same program path, although not precisely simultaneously.

[0034] According to one embodiment of the method for operating a redundant automation system according to the present invention, wherein the automation system has at least one first and second subsystem, and the subsystems respectively process a control program during the control of the automation facility, and wherein one of the subsystems operates as a master device and the other subsystem operates as a backup device, this embodiment is characterized in that

[0035] - Processing a processing segment of the control program to be processed by the master device

[0036] - After an event occurs, at the time point when the breakpoint that occurs after the event occurs, transmitting a license from the master device to the backup device, and the master device continues to process its control program to be processed, and

[0037] - The license of the backup device indicates up to which processing segment the backup device should process its control program.

[0038] In one embodiment of the present invention, due to the license, a processing segment of the control program to be processed by the backup device is processed, and this processing segment corresponds to the processed processing segment of the control program to be processed by the master device from the previous license to this license.

[0039] An alternative design of the present invention proposes that the master device grants the backup device a permission to process a specific segment of the control program, which is also processed by the master device but is granted before the master device finishes processing this part of the control program. This processing method is particularly meaningful when it is clear which processing steps this part will include before the end of processing a specific segment of the control program by the master device. The backup device thus does not have to wait for the end of processing of the processing steps by the master device, and the processing of the corresponding segment of the control program can be carried out in the subsystem at least approximately in parallel and simultaneously.

[0040] The advantage in the shown processing method is that the master device does not have to (actively) wait for the response of the backup device in order to continue its program processing. The transmission time of all relevant information is asynchronous from the master device to the backup device. Thus, the processing capacity of the master device is decoupled from the communication bandwidth available synchronously for events, which is particularly important in terms of the increasing imbalance between the increase in the processing capacity of the processor on the one hand and the increase in the communication capacity on the other hand, because the communication capacity usually cannot keep up with the improvement of the processing capacity.

[0041] Regarding the synchronization of program processing on two subsystems, the present invention provides the following advantages: It is possible to dispense with time-synchronized communication between users.

[0042] The two subsystems proceed synchronously after an event occurs, such that the master device and the backup device pass through the same program path due to the event, where the time is asynchronous. This means that the master device runs ahead of the backup device in terms of program processing or editing in time, or the backup device runs behind the master device in time. In this context, "running behind" or "running ahead" is understood as: the time difference between the start of processing a processing segment by the master device and the start of processing the processing segment by the backup device, which corresponds to the time point when the permission signal appears in the backup device.

[0043] Due to the time-asynchronous communication between the master device and the backup device, it is feasible to also use a slow communication connection to build a redundant automation system. This means that a communication connection that is poor in terms of transmission bandwidth or response time can also be provided, or a communication connection that is also used by other communication participants and thus is not exclusively provided for the two participants for synchronization purposes can also be provided. Thus, a separate physical synchronization connection can be dispensed with. This is specifically for Internet-based cloud environments where there is no exclusive connection.

[0044] In addition, a large distance between the two participants can also be covered without degrading the system capacity too much due to long signal propagation times or long waiting times. In particular, the master device and the backup device can be interconnected only via the Internet for data transmission and for synchronization.

[0045] In one design of the present invention, it is proposed that at the time point of transmitting the current permission, the facility input value is also transmitted to the backup device by means of the master device. First, the information relevant to the backup device is aggregated or collected, and finally transmitted to the backup device. Different from the known time synchronization method, this means that the relevant information must be immediately sent to the backup device within its scope, and the "management cost" for the master device and the backup device is significantly reduced.

[0046] In another design of the present invention, it is proposed that the backup device confirms the corresponding permission of the master device after editing the corresponding processing segment. The number of unconfirmed permissions indicates to the master device that the backup device is currently running behind, so that the master device can take appropriate measures to prevent the time lag from becoming too large.

[0047] As already mentioned, a preferred design of the present invention includes a plurality of control applications operating as backup devices. The computing resources of the control applications are set at different locations, and the control applications are communicatively connected to the automation facility and the master device via a network. The automation facility and the master device belong to a redundant automation system, receive a first data packet from the automation facility and the master device, and generate and transmit a third data packet to the automation facility.

[0048] The use of each new backup device with different network paths potentially reduces the probability of long transmission times. However, with each additional backup device, the network load is also increased, which tends to result in longer transmission times. Therefore, starting from a certain number of backup devices, only fewer advantages can be achieved with each additional backup device. Therefore, it is only conditionally meaningful to have a very large number of backup devices.

[0049] The editing of the third data packet transmitted to the automation facility and especially the order of editing are advantageously carried out according to the so-called sequence number. The use of sequence numbers is common and well-known when transmitting data over a network.

[0050] In particular, a unique sequence number is preset for each first data packet containing the actual value transmitted from the automation facility to the master device (either on the side of the automation facility or on the side of the master device). In particular, the sequence number starts from an initial value and is updated with each new actual value or data packet, especially increased or decreased by one. However, (in addition to increasing or decreasing the value by one respectively) other methods are also known to determine the unique order of the sequence number.

[0051] The corresponding sequence number can be included in the first and / or second data packets and can thus also be transmitted from the automation facility or the master device to the backup device. However, it is also feasible for the backup device to adapt the current value of the sequence number accordingly, in particular by incrementing or decrementing by one, with each new actual value or each newly arrived data packet. In this variant, the transmission of the sequence number from the automation facility or the master device to the backup device should not take place.

[0052] In one design of the invention, the first data packets output by the automation facility each provide a unique sequence number, and the master device and the backup device each provide a sequence number corresponding to the sequence number of the first data packet for the third data packet corresponding to the first data packet, which is the same in particular on all backup devices.

[0053] The common feature of all variants is that for each input value there is a unique and identical sequence number in the master device and in the backup device, the sequence number being included in the corresponding third data packet containing the relevant control instructions, and the third data packet being sent from the master device or the backup device to the automation facility.

[0054] The automation facility then identifies, based on the sequence number included in the corresponding third data packet transmitted to the automation facility, which of the third data packets transmitted to the automation facility that correspond to a specific first data packet and thus to a specific data value arrives at the automation facility first, processes this data packet, and in particular continues to process the output value included therein.

[0055] Subsequently, the third data packet that arrives at the automation facility and has the relevant sequence number is ignored.

[0056] Thus, based on a specific first data packet output by the automation facility with a specific input value, the third data packet that arrives at the automation facility first can be uniquely identified, and the relevant control instructions are executed or implemented in the automation facility, where the third data packet has an output value or control instructions that are precisely based on the specific input value.

[0057] Thereby, the corresponding fastest data packet or the output value included therein or the control instructions included therein become effective at the output of the peripheral unit to the actuator. The transmission time of the fastest data packet follows a different distribution function in a redundant control system, where shorter transmission times are more likely to occur than in the case where there is only a single control device in the network.

[0058] In one design of the invention, the transmission of the first data packet and / or the second data packet and / or the third data packet between the components of the automation system takes place according to the PROFINET standard. This standard is widely used in industry and already allows multiple control units to be connected or logically linked to a device or facility.

[0059] In a design of the present invention, within the scope of the so-called "update phase", at least one additional control application operating as an additional backup device is connected to the automation system. Here, it also continues to apply that the method shown below for connecting another backup device to the cloud computing system (hereinafter also referred to as "update") can be similarly used in combination with other, especially any number of backup devices.

[0060] According to the present invention, a design of a method for operating an automation system having a first subsystem (main) and at least one second subsystem (backup device) is proposed, wherein each subsystem provides a control program, and in order to connect another subsystem (another backup device) also provided with a control program to the automation system, relevant data of the first subsystem is transmitted to the other subsystem within the scope of the automation system update phase. The design is characterized in that

[0061] - At the start of the update phase, the first subsystem compiles a local copy of its relevant data (parameters, variables, internal states, etc.).

[0062] - During the update phase, the copy is transmitted by the first subsystem, especially in segments, to the other system, and the input values of the staging facility and the permissions of the first subsystem are temporarily stored, where the permissions indicate which processing segment of the control program the first subsystem has processed.

[0063] - The permitted processing segments of the control program of the other subsystem are processed in a time-lagged manner by the other subsystem with consideration of the temporarily stored input values after the copy is transmitted, where the processing segments correspond to the processing segments of the control program of the first subsystem. In order to reduce the time lag of the processing, especially to a preset value, the processing segments of the control program are processed more quickly in the other subsystem relative to the corresponding processing segments of the control program processed in the first subsystem.

[0064] Advantageously, the input values of the facility and the permissions are temporarily stored in the first subsystem (master device).

[0065] By this processing method, it is achieved that another subsystem (another backup device) is connected to the cloud computing structure and synchronized with the first subsystem (master device) and the remaining subsystems (backup devices) included in the cloud computing structure to such an extent that the control program processed by the other backup device is processed synchronously with the control programs processed by the remaining backup devices respectively. Here, "synchronization" again means that the individual processing steps of the control program are not processed absolutely simultaneously in different backup devices and the master device, but are processed with an offset determined by the use and transmission of the permissions.

[0066] The described method for connecting another subsystem to a cloud computing architecture can similarly be transferred to multiple other backup devices, in which relevant data of a first subsystem (master device) is transferred to another subsystem (another backup device) within the scope of an automated system update phase in the cloud computing architecture, where multiple additional backup devices are to be reconnected to the automated system. Then, with the permission, the backup devices reconnected to the automated system are continuously synchronized with the remaining subsystems of the redundant, cloud-based control system by the master device, and a third data packet is generated and sent to the automated facility.

[0067] Advantageously, in this method, for example, the costly "Dirty Bit mechanism" can be dispensed with. At the beginning of the update phase, the first subsystem (master device) creates a copy of its relevant data, which represents the internal state of the master device at the beginning of the update phase, where the data is particularly transferred in segments to the "updated" or reconnected subsystem, i.e., another (or "new") backup device. The internal state is basically determined or preset by static and dynamic data, data blocks, facility input / output values, and configuration data. The new backup device finally approaches the internal state of the master device step by step via the permission or synchronously with the current processing of the control program by the master device, where the new backup device only starts to edit the permission when it has completely obtained the copy. The new backup device passes through the same program path with the relevant data with a time delay according to the permission, where the master device has passed through the program path. This means that the master device runs ahead of the backup device in terms of program processing or editing, or the backup device runs behind the master device. In this context, "running behind" or "running ahead" is also understood in this regard as the time difference between the start of processing a processing segment by the master device and the start of processing the same processing segment by the backup device, which corresponds to the time point when the permission or permission signal appears. In addition, it should be noted that the program is understood not only as the program itself, but also as subroutines, parts of the program, partial programs, tasks, threads, organizational modules, functional modules, or any program code suitable for implementing automated functions, where the programs of the automated facility are usually assigned priorities and are edited or executed according to the priorities assigned to them.

[0068] At the time point when the new backup device catches up with the running-behind or the running-behind position or the running-behind is below a preset or preset and considered non-critical time slice or tolerable degree, the update phase ends, and the automated system works in a redundant operating mode with an increased number of backup devices starting from this time point.

[0069] It is feasible due to the time-asynchronous communication between the master device and the backup device during the update phase to also use a slow communication connection. This means that a communication connection that is itself poor in terms of transmission bandwidth or response time can also be provided, or a communication connection can also be provided that is also used by other communication participants and thus does not exclusively provide for the coupling process and the update process. Therefore, a separate synchronization connection can be dispensed with. In addition, a large distance between the two systems can also be overcome without significantly degrading the system capabilities due to long signal runtimes or long waiting times. Thus, the automation system according to the invention is optimally suitable for a cloud computing architecture with subsystems connected via the Internet.

[0070] In one design of the invention, it is proposed that the facility input values are transmitted to another subsystem together with the permissions. Information relevant to the other subsystem is first aggregated or collected and finally transmitted to the other subsystem. Thereby, the "administrative effort" for the two subsystems is reduced.

[0071] Preferably, other backup devices are connected to the automation system, in particular according to the described procedure for "updating", until a termination criterion is reached.

[0072] For example, the termination criterion can be a preset or presettable maximum number of backup devices present in the automation system, for example 100.

[0073] Another termination criterion can relate to an expected shortening of the response time caused by another backup device in the system. Thus, the incorporation of other backup devices can only be stopped if the expected shortening of the response time due to the incorporation of the designed other backup device is below a specific threshold, for example below 1 ms. The threshold is particularly relevant to the specific application. Thus, in a specific application, a threshold of 10 ms or 100 ms or almost any other value can be meaningful.

[0074] In one design of the invention, it is determined according to a statistical method to what extent the incorporation of one or more additional backup devices into the automation system reduces the achievable response time in the automation system, and one or more additional backup devices are incorporated into the automation system as necessary (automatically) based on the result obtained.

[0075] The fewer backup devices the automation facility includes, the more the additional backup devices contribute to reducing the transmission time. However, from a specific number of backup devices related to multiple factors, further improvement can hardly be achieved. Since the additional data traffic generated by each backup device in the network even causes a point from which additional backup devices lead to a deterioration of the transmission time. This state should be avoided.

[0076] Advantageously, the control system is reconfigured dynamically. This means that not only can new backup devices be connected to the system, but they can also be removed from it again. Thus, it is achieved that in the case of network load fluctuations, the optimally best setting in terms of response time can always be derived and configured automatically again. The dynamic reconfiguration continuously finds the possible minimum of the response time.

[0077] The advantage of this solution is that it is possible to reduce or optimize the response time of cloud-based automation solutions, thereby making their use possible. The network load is only increased to the extent necessary for the given requirements by the method according to the invention.

[0078] One embodiment of the invention proposes adding new logical connections (new backup devices) until the probability of a long transmission time is less than the probability of failure of the automation system. The failure of the facility can be caused either by a hardware fault or by an excessive response time. For example, the probability of a hardware fault can be derived from the failure rate of the facility components. The criterion here is that the excessive transmission time occurs with a sufficiently low probability so that the overall failure probability is not significantly increased thereby.

[0079] In one design of the invention, during the operation of the automation system, the assignment of roles of specific control applications as the main device and the backup device is switched to maintain redundancy. The switching can be carried out due to a special event, such as a particularly long measured response time of the main device here, or it can also be carried out periodically at preset or presettable time intervals.

[0080] Especially when determining the transmission time from the data packets output by the automation facility and / or the data packets received by the automation facility, it can be determined which backup devices have particularly short transmission times. Then, advantageously, the role is assigned as the "main device" shaped for a specific control application according to the derived transmission time. Thus, in particular, the control application with the shortest overall transmission time within a specific time period can assume the role of the main device.

[0081] The invention is not limited to a specific type of automation facility, but in principle can be used in combination with any automation facility, which is, for example, a production facility, a processing or manufacturing facility, a facility from the processing industry, etc. In particular, the automation facility can also have only a single machine or a single facility controlled solely by a control system. However, the automation facility controlled according to the invention generally includes a plurality of machines and / or devices.

[0082] The automation facility includes at least one sensor providing a sensor signal and at least one actuator controlled according to the sensor signal. Here, "controlled" should not be understood in the strict sense of control, but also includes the control process.

[0083] According to the invention, the control function is carried out by the control application involved. In particular, the control application carries out the control function of an industrial personal computer (PC), a programmable logic controller (SPS), a numerical control device (CNC) or other industrial control devices.

[0084] In one design of the invention, the license is transferred from the master device to the backup device whenever a preset time interval expires or a specific event occurs. Thereby it is precisely determined how and at what intervals the synchronization of the subsystem is caused (in the context of the invention). In particular, the lag time between the master device and the backup device can thus be influenced.

[0085] The object set out at the beginning is also achieved by an automation system (1) for carrying out the method according to the invention, the automation system comprising an automation facility (AA) and a redundant cloud-based control system, wherein the cloud-based control system comprises a control application forming part of a cloud computing architecture, the computing resources of the control application being arranged at different locations, and the control applications being communicatively connected to one another via a network and to the automation facility to be controlled, wherein the network has a plurality of communication nodes and communication paths connecting the communication nodes to one another.

[0086] Furthermore, the object set out at the beginning is achieved by a redundant cloud-based control system for an automation system (1) according to the invention, wherein the cloud-based control system comprises a control application forming part of a cloud computing architecture, the computing resources of the control application being arranged at different locations, and the control applications being communicatively connected to one another via a network (N) and to the automation facility (AA) to be controlled, wherein the network has a plurality of communication nodes (KP) and communication paths (P) connecting the communication nodes to one another. Description of the Drawings

[0087] Below, the invention will be described and explained in more detail by way of example according to embodiments. It is shown here:

[0088] Figure 1 The transmission time during data transmission in a computer network is shown,

[0089] Figure 2 A cloud computing architecture for controlling an automation facility with one master device and a plurality of backup devices is shown, the master device and the backup devices being interconnected via a network and connected to the automation facility for controlling the automation facility,

[0090] Figure 3 The synchronization between the master device and the backup device is shown,

[0091] Figure 4 The transition of the master device role is shown,

[0092] Figure 5 Shows the time difference operation between the master device and the backup device

[0093] Figure 6 Shows the update of the new backup device

[0094] Figure 7 Schematically shows the influence of the method on the distribution function of the transmission time from the control device to the peripheral unit

[0095] Figure 8 Shows the method steps in the execution of the method according to the invention Detailed implementation mode

[0096] Figure 1 Shows the typical transmission time distribution during data transmission in a computer network, such as the Internet. The minimum transmission time is determined by the physical conditions of the transmission route. In addition, via this transmission route, there is a large transmission time bandwidth up to very large values, which is however observed with a low probability

[0097] Therefore, the automation facilities to be controlled via the computer network must tolerate relatively large delays, which is only feasible for very few facilities. So far, this has significantly limited the usage possibilities of cloud-based automation devices

[0098] From Figure 2 it can be seen the redundant automation system 1 according to the invention

[0099] The automation system 1 includes at least one automation facility AA to be controlled located at the facility location and five control applications provided for controlling the automation facility AA, which form part of a cloud computing structure. The computing resources of the control applications are set at different locations and the control applications are communicatively connected to each other and to the automation facility AA via a network N, in particular the Internet, where the network has a plurality of communication nodes KP and communication paths P connecting the communication nodes to each other. For clarity, in Figure 2 only some of the communication nodes KP or communication paths P are provided with the corresponding reference signs KP or P

[0100] In this embodiment, one of the control applications is configured as the master device PR, and the other four control applications are configured as backup devices BU1 to BU4. The master device PR and the backup devices BU1 to BU4 together form a redundant cloud-based control system, also referred to as a cloud computing structure, for controlling the automation facility AA

[0101] The automation facility AA is also connected to the network N via a computer, referred to as the peripheral unit PE, which is included in the automation facility AA. The peripheral unit PE in particular ensures the network connection of the automation facility AA and thus the data transmission between the automation facility AA and the control system. The peripheral unit PE preferably also has a certain intelligence, for example for processing and preparing sensor data before it is transmitted to the master device. It is also conceivable that the control instructions transmitted from the control system to the automation facility AA are first prepared or processed in the peripheral unit PE before being fed to the actuators of the automation facility AA.

[0102] The automation facility AA also includes, for example, sensors S and actuators A. Of course, the automation facility AA according to the invention can have a plurality of sensors S and actuators A. Therefore, the functional principle of the invention will be explained with the aid of the exemplary automation facility AA. The sensors S generate sensor signals, from which actual values valid for a specific point in time are directly obtained or obtained after processing, such as filtering.

[0103] In the case of the automation facility AA, in particular in the case of the peripheral unit PE of the automation facility AA, a first data packet DP1 containing actual values (input values) is now sent to the master device PR via the network N. Here, the peripheral unit PE can transmit the actual values itself, for example periodically, to the master device PR. However, the first data packet can also be transmitted to the master device PR due to a read-out process initiated by the master device PR.

[0104] The master device PR generates actual values according to specific program instructions of the control program and generates control instructions (output values) from them for the actuators A included in the automation facility AA, where the program instructions are included in the control application and the program instructions exist in substantially the same form at least in the master device PR and the backup devices BU1 to BU4.

[0105] In addition, a second data packet DP2 including the current actual values starts to be transmitted via the network N from the peripheral unit PE or the master device PR to the backup devices BU1 to BU4.

[0106] In addition, the master device PR transmits, in particular, after the expiration of a specific time interval (Zi, i = 1, 2,...) or after the occurrence of an event (such as "the master device PR has completed editing" or "the master device PR has performed a task switch"), permissions (F1, F2,...) to the backup devices BU1 to BU4, from which it can be derived which specific program instructions of the control program are permitted to be processed by the backup devices BU1 to BU4. The permissions are also transmitted via the network N.

[0107] In particular, due to the license, backup devices BU1 to BU4 process the same specific program instructions of the control program, which have been processed by the master device PR before the license. Here, the following actual values are considered by the corresponding program instructions, and the same actual values are also considered by the master device. Backup devices BU1 to BU4 thus also generate control instructions for the actuator A included in the automation facility AA regarding the current actual values.

[0108] Both the master device PR and the backup devices BU1 to BU4 generate a third data packet DP3 including the corresponding control instructions and send the third data packet (also via the network N) to the automation facility AA.

[0109] Finally, only the third data packet Dp3 that arrives at the automation facility AA first is used for the control of the actuator A.

[0110] In addition, by Figure 2 It indicates the switching of the master device role. Explanation of the master device role: Which control application within the cloud computing structure currently occupies the role of the master device. According to this embodiment, it is proposed that the master device role switches between control applications at specific time intervals or due to specific events. The switching can be performed, for example, periodically at a fixed preset time interval. It is also feasible to detect the transmission time within the network N, and the control application with a particularly short, especially the shortest transmission time within a specific time period assumes the master device role.

[0111] In Figure 2 The switching of the master device role between the current master device PR and the backup device BU1 is indicated by the transfer arrow T. This should mean that the current backup device BU1 below assumes the role of the master device, and the current master device PR assumes the role of the backup device BU1. Obviously, the switching of the master device role can also be performed with any other backup devices BU2 to BU4 in the control system.

[0112] It also needs to be supplemented that "switching the master device role" can also be understood as a backup device already integrated into the system or a newly integrated backup device assuming the role of the master device in the future, while removing the master device up to now from the control system, that is, not assuming the role of the backup device.

[0113] The synchronization function principle on which the present invention is based is explained below without loss of generality according to the master device and a single backup device. However, in practice, the automation system according to the present invention includes multiple backup devices, and these backup devices are synchronized with the master device in a similar manner.

[0114] In accordance with Figure 2In an embodiment, the peripheral unit PE obtains, via an input line, signals from a measuring transducer or a measuring value detector (sensor S) for detecting the status of a facility, and outputs the signals to an actuator (actuator) A via an output line, and influences an automation facility AA by means of the actuator. The control applications (subsystems) PR and BU1 to BU4 operate periodically and process the same control program substantially synchronously.

[0115] To explain the event-synchronized processing of the control program, reference is made below to Figure 3 , which shows the process of time-asynchronous coupling of two subsystems, namely the master device PR and the backup device BU, which control an engineering process. In this context, "event-synchronized processing" means that both the master device PR and the backup device BU pass through the same program path of the corresponding control program due to an event, where this passage occurs asynchronously in time.

[0116] The master device PR is in the lead with respect to the engineering process control, where the master device PR reads input values from the peripheral unit PE and provides them to the backup device BU asynchronously in time, where the input values are also referred to below as process input information, process input values, facility input information, or facility input values.

[0117] Optionally, the backup device BU can also directly read values from the peripheral unit PE or directly receive data packets sent from the peripheral unit PE, but the editing of the data packets should only start after being commissioned by the master device PR (via the corresponding permission).

[0118] The master device PR processes a program P1 for the engineering process control, where the backup device BU also processes a program P2 corresponding to the control program P1. Both of these control programs P1, P2 have a plurality of processing segments (Va) of different durations, where the control programs P1, P2 can be interrupted at the respective start and respective end of each processing segment Va. The start and end of each processing segment Va generally include a plurality of program codes and thus represent interruptible programs or interrupt points 0, 1, 2,...y. At these points 0, 1, 2,...y, the corresponding control programs P1, P2 can be interrupted, if necessary, by means of the master device PR and the backup device BU, so that appropriate reactions can be taken after an event or a process alarm occurs. In addition, the corresponding control programs P1, P2 are interrupted at these interrupt points 0, 1, 2,...y so that the master device PR and the backup device BU can exchange only permissions, confirmations, or other information via the network.

[0119] After the expiration of the corresponding preset or preset time intervals Zi, i = 1, 2,... and at the corresponding time points at which a subsequent breakpoint (preferably the first breakpoint following the corresponding time interval Zi) appears after the expiration of the corresponding time interval Zi, the master device PR transmits a permission or permission signal to the backup device BU, and the permission or permission signal shows the backup device BU which processing segment Va of the control program P2 it should process until. The processing segment Va of the control program P2 corresponds to those processing segments that the master device PR has processed during the processing of the control program P1. In this embodiment, it is assumed that after the expiration of the time interval Z1, at time points t1 and t2, the master device PR transmits a permission F1 to the backup device BU, where at time points t1 and t2, the first breakpoint P1_6 (breakpoint 6) follows the time interval Z1. The permission F1 includes information for the backup device BU, that is, the backup device should process the control program P2 it is to process until the breakpoint P2_6 (breakpoint 6), where the breakpoint P2_6 of the control program P2 corresponds to the breakpoint P1_6 of the control program P1. This means that: due to the permission, the backup device BU can process the processing segment Va of the control program P2, and the processing segment until the time point when the permission or permission signal is generated corresponds to the processing segment Va of the control program P1, where in this example, for simplicity, it is assumed that the time point when the permission is generated corresponds to the time point when the permission is transmitted to the backup device BU. Therefore, the processing of the processing step Va by means of the backup device BU and the processing of the corresponding processing segment Va by means of the master device PR are asynchronous in time. After the processing segment Va of the control program P2 is processed by the backup device BU, when the master device PR transmits another permission to the backup device BU, the backup device BU edits other processing segments Ba. The time points at which the breakpoints P1_6, P2_6 (breakpoint 6) appear represent the start of the time interval Z2 following the time interval Z1.

[0120] The additional time asynchronous processing of the control programs P1, P2 is carried out in the described manner and method. At the time point t3 when the first breakpoint P1_A appears after the expiration of the time interval Z2, the master device PR transmits another permission F2 to the backup device BU, and the other permission shows the backup device BU that it can edit another processing segment Va until the breakpoint P2_A. The processing segment Va again corresponds to those processing segments that the master device PR has processed from the time point t2 until the time point t3, that is, until the breakpoint P1_A. This means that: the backup device BU processes the processing segment Va from the time point t2 of the previous permission F1 until the time point t3 of the current permission F2. The time point t3 when the first breakpoint P1_A appears after the expiration of the time interval Z2 is the start of the time interval Z3 following the time interval Z2.

[0121] Now, the following occurs: an event occurs during a certain time interval, such as an event in the form of a process alarm. In this embodiment, such an event is denoted by E, and the master device PR must appropriately react according to the control program P1 at the time point t4 during the time interval Z3. In this case, the master device PR does not permit the transmission of F3 to the backup device BU at the time point that occurs at the interruption point after the time interval Z3, but transmits it at the time point t5 when the interruption point P1_C (interruption point C) occurs after the occurrence of the event E. This means that: the time interval Z3 is shortened due to the event E, where the time point t5 is the start of the subsequent time interval Z4. Due to the permission F3 transmitted to the backup device BU, the backup device BU processes the processing segment Va of the control program P2, and the processing segment corresponds to the processing segment Va that the master device PR of the control program P1 has processed between the time point t3 and the time point t5.

[0122] Due to the event E, the master device PR processes a processing segment Va with a higher priority during the time interval Z4. For example, the master device PR performs a thread switch at the time point t5, and after the time interval t6 expires, transmits the permission F4 at the time point t6 at the time point t7 when the first interruption point P1_12 (interruption point 12) occurs after the time interval Z4. The backup device BU processes the processing segment Va until the interruption point P2_12 (interruption point 12) of the control program P2 due to the said permission, where the processing segment Va corresponds to the processing segment Va between the time point t5 and the time point t7 of the control program P1, and the backup device BU also performs a thread change.

[0123] As mentioned above, the permission of the master device PR places the backup device BU in a state where it can go through the same "thread stack" as the master device PR, which means that: the backup device BU performs a "thread switch" at the following point in the control program P2, and the point corresponds to the point in the control program P1. The backup device BU only continues its boundary when the master device PR requests the backup device to edit through permission. In terms of processing the processing segment, the master device PR processes the processing segment in real time as in independent operation or as in non-redundant operation, and grants permission for the backup device BU to process the corresponding processing segment at regular time intervals and after the occurrence of an event, where the master device PR continues to process its control program P1 and does not actively wait for the response of the backup device BU. Regarding the processing of the corresponding processing segment, the backup device BU lags behind the master device PR in operation and processes the processing segment due to the granted permission.

[0124] In the following, reference is made to Figure 4 , which shows the transition of the master device role from the master device PR to the backup device BU.

[0125] In the manner and method described, the master device PR will permit the transmission of F5, F6, and F7 to the backup device BU, where it is assumed that the master device PR ends the master device role at time point t8. The end of the master device role depends on: the master device PR sets the master device role itself and transmits said role to the backup device BU in the control system. The backup device BU can inform the master device PR up to this point of this situation via a corresponding signal. Optionally, it is even considered that the backup device BU takes over the master device role on its own (i.e., without a corresponding signal from the master device PR up to this point). Thus, it is even feasible that the control system maintains its control task in the event of the failure of the master device PR up to this point.

[0126] Due to the permission of F5 to F7, the backup device BU processes the processing segment Va of the control program P4 until the transition point P4_B (transition point B), where the processing segment Va corresponds to the following processing segment Va of the control program P3 until the transition point P3_B (transition point B), where the processing segment Va has been processed by means of the master device PR.

[0127] At time points te1, te2, the master device PR accesses the peripheral unit PE in a read manner within the scope of processing the control program P3, which means that: the master device PR reads the facility input values Ew1, Ew2, the facility input values are processed according to the control program P3 and generate output values Aw1, Aw2, and the output values are subsequently also used as process output information, process output values, facility output information or facility output values, and the master device PR transmits the output values to the peripheral unit PE at time points ta1, ta2. The master device PR transmits the process input values Ew1, Ew2 to the backup device BU, which is represented by curves L1, L2 in the attached figure. The transmission is carried out together with the permissions F5, F7 in order not to increase the communication load between the master device PR and the backup device BU during the processing of the processing segment Va until the permissions F5, F7. The backup device BU also processes the process input values Ew1, Ew2 according to the control program P4 and also generates process output values Aw1, Aw2, and the backup device BU transmits the process output values to the peripheral unit PE. Here, it is assumed that: the peripheral unit PE is an "accessible" peripheral unit with a main terminal and a secondary terminal. The main terminal is set to receive the process output value of the master device PR, and the secondary terminal is set to receive the process output value of the backup device BU, where if the backup device BU recognizes that the so-far master device PR has relinquished its master device role, the backup device BU switches the peripheral unit PE from the main terminal to the secondary terminal. This is preferably done by: the so-far master device PR transmits a corresponding signal to the selected backup device BU. However, it is also feasible that: the backup device BU takes over the master device role by itself, for example because it no longer receives a signal from the master device PR over a specific period of time and thus the master device may have failed. In addition, it is also feasible that: the master device role is switched between subsystems periodically, especially at fixed preset time intervals or at fixed preset time points. In this case, no signal from the so-far master device PR to the backup device BU is required to trigger the switch of the master device role.

[0128] As explained, it is assumed that the master role of the master device PR ends at time point t8. The backup device BU identifies this situation, for example, in such a way that the master device PR sends a corresponding message to the backup device BU. After the backup device BU identifies at time point t9, for example, that the master role of the master device PR up to this point has ended, the backup device BU does not immediately take over the master role because at time point t9, the system state of the backup device BU is different from that of the master device PR, and thus a seamless handover or transition is not possible. At this time point t9, the backup device BU only processes the dark Va until the transition point P4_6 (transition point 6). The corresponding processing segment Va of the master device PR up to the transition point P3_6 (transition point 6) is thus "in" the past. Only after the transition, that is, after the backup device BU has processed the permitted processing segment Va by means of the permission F7 until the transition point P4_B at time point t10, does the backup device BU take over the master role and thus take over the control of the automation facility, where at this time point t10 the backup device BU switches the peripheral unit PE from the main terminal to the secondary terminal. Therefore, during this transition, the (former) backup device BU also passes through the same thread stack in a path-synchronized manner and processes the same process input values as the (former) master device PR before its failure, where the (former) backup device BU derives the same process output values as the (former) master device PR due to these input values. When the last permitted target is reached (in this example, processing the processing segment Va until the breakpoint P4_B), the transition ends.

[0129] In order to keep the time lag of the backup device relative to the master device PR within a tolerable range, as described in Figure 5 , if the backup device BU finishes the corresponding editing, then each permission F8 to F12 of the master device PR is asynchronously confirmed by the backup device BU by means of the corresponding acknowledgments Q8 to Q12. The master device PR evaluates the number of unacknowledged permissions and derives from it the current time lag of the backup device BU. For the case where the time lag is too high or excessive, this may lead to a redundancy loss, for example. The master device PR takes appropriate measures to reduce the time lag or prevent it from becoming too large.

[0130] For example, as a reaction to an excessive time lag, the master device PR can pause or delay the processing of threads with lower priority, where the processing of threads with higher priority requires significantly less than 100% of the computing time. Therefore, the master device PR goes through fewer processing segments and generates fewer permissions, enabling the backup device BU to "catch up".

[0131] Update reference regarding the new backup device Figure 6 , which shows the update process of the automation system.

[0132] Before the actual update process begins, it must first be ensured that: in the backup device BU to be newly connected to the control system, there is a control program that is the same as that in the master device PR. If this is not the case, the new backup device BU preferably first extracts the control program from the network. The control program can be downloaded from the master device PR, from a backup device already integrated into the control system, or in principle from any other computer provided for this purpose in the network.

[0133] The update process starts at time point t11 until the master device PR recognizes that: the new backup device BU is coupled to the network, where the update phases of both the master device PR and the backup device BU start from time point t11. From this time point t11 onwards, the master device PR creates a local copy K of all relevant data, which represents its internal state up to time point t11, where the master device PR also controls the automation facility and processes the processing segment Va of the control program P5. From time point t12 to time point t13, the master device PR transfers the copy K to the backup device BU in a segmented manner, which is represented by the arrow Kf in the drawing, where the update phase of the master device PR ends at time point t13, and the backup device BU completely receives the copy until time point t14. Now, at time point t14, the backup device BU has the same internal state as the master device PR at time point t11. In addition, from time t12 onwards, all permissions of the master device PR and all facility input values read by the master device PR from the peripheral unit PE are temporarily stored on the master device PR, the backup device BU, or another subsystem of the automation system, where the permissions are enabled only after the copy K is completely received across the boundary of the backup device BU. In this embodiment, it is assumed that: during the time period from time point t11 to time point t13, the master device PR generates permissions F13, F14, F15, F16 and also reads in the facility input values Ew3, Ew4, where the transfer of the copy K ends at time point t13. The copies F13 to F16 and the process input values Ew3, Ew4 are enabled for the backup device BU only from time point t14 onwards, that is, at the time point when the internal state of the master device PR is completely provided to the backup device BU, which is represented by the arrow Fs and by the curves L3, L4 in the drawing. After this enabling by the master device PR, the backup device BU approaches the internal state of the master device PR by: the backup device BU processes the data of the copy K according to the permissions F13 to F16. Here, the backup device BU processes the processing segment Va of its control program P6, which corresponds to the processing segment Va of the control program P5 of the master device PR up to time point t13, where the backup device BU takes into account the process input values Ew3, Ew4 in the processing of the control program P6.

[0134] Since the backup device BU approaches the internal state of the primary device PR asynchronously in terms of time, in the processing of the corresponding processing segment Va of the control program P6, the backup device BU lags behind the primary device PR in operation. Among them, the time lag in operation must be reduced to a tolerable level because excessive time lag in operation will lead to loss of redundancy. In order to reduce this time lag in operation, it is proposed that the processing speed of the backup device BU is higher than that of the primary device PR, which is shown in the figure in the form of the processing segment Va of "shortening" in the control program P6. This relative increase in the processing speed of the backup device BU can be caused, for example, by the backup device BU processing the processing segment Va of its program P6 more quickly, or the primary device PR processing the processing segment Va of its program P5 more slowly. When the lag in operation is caught up or reduced to a tolerable level or reduced to a preset value, the update phase of the backup device BU and then the automation system starting at time point t12 ends.

[0135] Within the update phase of the backup device BU, the backup device BU edits the permissions F13 to F16 temporarily stored during the transfer copy K and the permissions F17, F18, F19 of the primary device PR during the transfer until the transfer to the backup device BU from time point t14 until time point t15. The permissions F17 to F19 show the backup device BU which processing segments Va of the control program P6 still need to be processed by the backup device BU, where the processing segment Va corresponds to the processing segment Va that the primary device PR of the control program P5 has processed since time point t14. In other words, after the primary device PR completely transfers the copy to the backup device BU or the backup device BU completely receives the copy K, the backup device BU processes all the permission processing segments Va of its control program P6 from time point t14 until time point t16, and the processing segment corresponds to the processing segment that the primary device PR has processed from time point t11 to time point t15.

[0136] Since time point t15, the update phase ends, and the redundant automation facility extends the backup device BU. Since time point t6, the further course of the corresponding program paths on the primary device PR and the backup device BU runs asynchronously in time in the manner and method described above.

[0137] As already explained above, preferably another backup device is connected to the automation system (especially in combination with the described processing method for updating) until the abort criterion is reached.

[0138] Figure 7 Schematically shows the influence of this method on the transfer time distribution function between the control system and the peripheral unit. Shown is the probability P(t 传输= t), i.e., the probability P that the delay exactly corresponds to time t. It can also be seen from this figure the minimum transfer times t min A, t min B, and t min C of subsystems TSA, TS B, and TS C. If it is assumed that the required transfer time t min , then the probability of being below the said transfer time increases with each additional logical connection to the peripheral unit, i.e., with each additional backup device in the control system. Even if only one of the said logical connections has a small probability for a short transfer time, the resulting transfer time is further improved. Only when the minimum transfer time exceeds the required transfer time does no positive contribution occur (see the upper right of Figure 7 ). However, nevertheless, no deterioration of the resulting distribution occurs because the long transfer times are ignored by the peripheral unit.

[0139] As can be seen from Figure 7 : In this embodiment, the required transfer time t min is lower than the transfer time t min,Ges that can be achieved by the control system.

[0140] With each new logical connection potentially reducing the probability of long transfer times, the said new logical connection uses a different network path. However, with each additional logical connection, the load on the network also increases, which tends to result in longer transfer times.

[0141] Advantageously, new logical connections (additional backup devices) are added until

[0142] - the probability of long transfer times increases again, for example due to increased network traffic;

[0143] - the probability of long transfer times is less than the probability of control system failure.

[0144] Here, a transfer time higher than the required transfer time is represented by a long transfer time. By this process, it is ensured that the best achievable transfer time in the said network is realized without unnecessarily loading the network.

[0145] Below, the basic method steps in performing the method according to the present invention are again illustrated herein in the form of a flowchart according to Figure 8 .

[0146] In a first method step S1, an automation system is provided, which automation system includes at least one automation facility to be controlled, arranged at a facility location, and at least two control applications provided for controlling the automation facility, which control applications form part of a cloud computing architecture, the computing resources of the control applications being arranged at different locations, and the control applications being communicatively connected to each other via a network and to the automation facility, wherein the network has a plurality of communication nodes and communication paths connecting the communication nodes to each other, wherein a first control application of the control applications operates as a master device, and at least one second control application of the control applications operates as a backup device.

[0147] In a further method step S2, the master device receives, via the network, a first data packet output by the automation facility, which first data packet includes input values of the automation facility.

[0148] In a further method step S3, the input values are processed according to specific program instructions of a control program and output values (control instructions) for actuators comprised by the automation facility are generated therefrom, wherein the program instructions are comprised by the control application and are present in substantially the same form at least in the master device and the backup device.

[0149] In a further method step S4, the master device or the automation facility transmits, via the network, a second data packet including the input values to the backup device.

[0150] In a further method step S5, the master device transmits permissions (F1, F2,...) to the backup device.

[0151] In a further method step S6, the backup device processes, due to the permissions, the program instructions of the control program, which program instructions correspond to specific program instructions that have been processed by the master device of the control program, and the backup device likewise generates output values therefrom for actuators comprised by the automation facility.

[0152] In a further method step S7, a third data packet including the respective output values is sent from the master device and from the backup device to the automation facility.

[0153] In a further method step S8, the third data packet that first arrives at the automation facility and the output values comprised therein are used to control the actuators. A third data packet including the relevant output values that arrives at the automation facility at a later point in time is not considered in the further course.

Claims

1. A method for operating an automation system (1), the automation system (1) comprising at least one automation facility (AA) to be controlled located at a facility location and at least two control applications provided for controlling the automation facility (AA), the control applications forming part of a cloud computing architecture, the computing resources of the control applications being located at different locations, and the control applications being communicatively connected to each other via a network (N) and communicatively connected to the automation facility (AA), wherein, The network (N) has a plurality of communication nodes (KP) and communication paths (P) interconnecting the communication nodes (KP), wherein a first control application among the control applications operates as a master device (PR), and at least one second control application among the control applications operates as a backup device, wherein the master device (PR) receives a first data packet output by the automation facility (AA) via the network (N), the first data packet including input values of the automation facility (AA), wherein the master device (PR) processes the input values according to specific program instructions of a control program and generates output values for the actuator from the processing, wherein the control application includes the program instructions and the program instructions exist in the same form at least in the master device (PR) and the backup device, and the automation facility (AA) includes the actuator, wherein a second data packet including the input values is transmitted via the network (N) to the backup device, wherein a permission is transmitted from the master device (PR) to the backup device, wherein the program instructions of the control program to be processed by the backup device are processed based on the permission, the program instructions corresponding to the processed specific program instructions of the control program to be processed by the master device (PR), and the backup device also generates the output values for the actuator included in the automation facility (AA) from the processing of the backup device, wherein a third data packet including the respective output values is sent from both the master device (PR) and the backup device to the automation facility (AA), and wherein the third data packet that first arrives at the automation facility (AA) is used for controlling the actuator.

2. The method according to claim 1, characterized in that, During operation of the automation system (1), the first data packet is continuously generated by the automation facility (AA) and transmitted to the master device (PR), the second data packet is generated by the automation facility (AA) or the master device (PR) and transmitted to the backup device, and the third data packet is generated by the master device (PR) and the backup device and transmitted to the automation facility (AA).

3. The method according to claim 1 or 2, wherein The second data packet including the input values is transmitted from the master device (PR) via the network (N) to the backup device.

4. The method according to claim 1 or 2, wherein The second data packet including the input values is transmitted from the automation facility (AA) via the network (N) to the backup device.

5. The method according to claim 1 or 2, wherein The automation system (1) includes a plurality of control applications operating as backup devices, wherein the computing resources of the control applications are located at different positions and the control applications are communicatively connected to the automation facility (AA) and the master device (PR) via the network (N), and the first data packet is received by the automation facility (AA) or the master device (PR) and the third data packet is generated and transmitted to the automation facility (AA).

6. The method according to claim 1 or 2, wherein The automation facility (AA) provides unique serial numbers for the first data packets output by the automation facility (AA), and the master device (PR) and the backup device respectively provide serial numbers corresponding to the serial numbers for the third data packets corresponding to the first data packets, and the automation facility (AA) identifies, based on the serial numbers included in the respective third data packets transmitted to the automation facility (AA): which of the third data packets in the third data packets corresponding to a specific first data packet transmitted to the automation facility (AA) arrives at the automation facility (AA) first, and the automation facility (AA) continues to process this third data packet.

7. The method according to claim 6, wherein The automation facility (AA) ignores the third data packets that arrive subsequently in time and have associated serial numbers.

8. The method according to claim 1 or 2, wherein The transmission of the first data packet and / or the second data packet and / or the third data packet between the components of the automation system (1) is carried out according to the PROFINET standard.

9. The method according to claim 1 or 2, wherein, Within the scope of the update phase, at least one additional control application operating as an additional backup device is incorporated into the automation system (1).

10. The method according to claim 9, wherein, The incorporation of the additional backup device into the automation system (1) continues until a termination criterion is reached.

11. The method according to claim 10, wherein, It is determined according to a statistical method to what extent the incorporation of the additional backup device into the automation system (1) reduces the response time achievable in the automation system (1), and the additional backup device is incorporated into the automation system (1) based on the result of the determination.

12. The method according to claim 1 or 2, wherein During the operation of the automation system (1), the assignment of the role of a specific control application as the master device (PR) or the backup device is switched.

13. The method according to claim 12, wherein, During the operation of the automation system (1), the assignment of the role of a specific control application as the master device (PR) or the backup device is periodically switched.

14. The method according to claim 12, wherein The transmission time for the data packets output by the automation facility (AA) and / or the transmission time for the data packets received by the automation facility (AA) is determined, and the assignment of the role of the master device (PR) is carried out based on the determined transmission time.

15. The method according to claim 14, wherein, The transmission time is periodically determined.

16. The method according to claim 1 or 2, wherein The control application in the automation facility (AA) executes the control function of a programmable logic controller.

17. The method according to claim 1 or 2, wherein After a preset time interval has expired or after an event has occurred, the permission is transmitted from the master device (PR) to the backup device.

18. An automated system (1) for performing the method according to any one of claims 1 to 17, the automated system (1) comprising an automation facility (AA) and a redundant cloud-based control system, wherein, The cloud-based control system includes a control application that forms part of a cloud computing architecture, the computing resources of the control application being located at different positions, and the control applications being communicatively connected to each other via a network (N) and communicatively connected to the automation facility (AA) to be controlled, wherein the network (N) has a plurality of communication nodes (KP) and communication paths (P) connecting the communication nodes (KP) to each other.

19. A redundant cloud-based control system for an automated system (1) according to claim 18, wherein, The cloud-based control system includes a control application that forms part of a cloud computing architecture, where the computing resources of the control application are located at different positions, and the control applications are communicatively connected to each other via a network (N) and communicatively connected to an automation facility (AA) to be controlled, wherein the network (N) has a plurality of communication nodes (KP) and communication paths (P) interconnecting the communication nodes (KP).

Citation Information

Patent Citations

  • Method for operating a redundant automation system

    EP2657797A1

  • Method for operating a redundant automation system

    EP2667269A1

  • Method for establishing a redundant communication connection and fail-safe control unit

    EP3547618A1

  • Redundancy In A Network Centric Process Control System

    US20200280615A1