Multi-voting fault-tolerant structure safety control method, system and device

Through the signal processing of multiple three-out-of-two fault-tolerant structures, the problems of high false shutdown rate and high dangerous failure rate in the existing safety control system are solved, and higher system reliability and real-time performance are achieved.

CN115509181BActive Publication Date: 2025-09-12CHINA PETROLEUM & CHEMICAL CORP +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110695790.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-23
Publication Date
2025-09-12
Estimated Expiration
2041-06-23

AI Technical Summary

Technical Problem

The existing two-out-of-one, two-out-of-two and three-out-of-two structures have problems with high false shutdown rates or high dangerous failure rates in safety control systems, and cannot meet the requirements of petrochemical production safety.

Method used

It adopts a multiple three-out-of-two fault-tolerant structure, realizes multiple fault-tolerant processing of signals through the first, third and second fault-tolerant voting operations of three parallel channels, and combines hardware and software three-out-of-two fault-tolerant voting circuits.

Benefits of technology

It significantly improves the system's redundant fault tolerance, reduces the system's dangerous failure rate and false shutdown rate, and ensures the reliability and real-time performance of the petrochemical safety control system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115509181B_ABST
    Figure CN115509181B_ABST
Patent Text Reader

Abstract

The present invention provides a multi-voting fault-tolerant structure safety control method, system, and device, belonging to the field of petrochemical production safety. The method comprises: inputting three identical signals acquired from the same site into each of three parallel channels of a first-level fault-tolerant voting system, performing a two-out-of-three fault-tolerant voting operation on each channel, and outputting a first-level voting result; inputting the first-level voting result into each of N parallel channels of a second-level fault-tolerant voting system, performing a two-out-of-three fault-tolerant voting operation on each channel, and outputting a second-level voting result; inputting the second-level voting result into each of M parallel channels of a third-level fault-tolerant voting system, performing a two-out-of-three fault-tolerant voting operation on each channel, and outputting the third-level voting result as the final voting result. The solution of the present invention can implement multi-three-out-of-two fault-tolerant signal processing, significantly improving redundancy and fault tolerance, and reducing the system's dangerous failure rate and false shutdown rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of petrochemical production safety, and in particular to a multiple voting fault-tolerant structure safety control method, a multiple voting fault-tolerant structure safety control system and a multiple voting fault-tolerant structure safety control device. Background Art

[0002] Safety control systems are one of the most important equipment to ensure safe production in the petrochemical industry. They are used to monitor potential dangers in industrial processes, issue alarms in a timely manner, or automatically execute predetermined protection functions to prevent dangerous incidents in petrochemical processes or mitigate their consequences, thereby ensuring the safety of personnel, equipment, and the surrounding environment of the factory.

[0003] With the development of safety control systems and the in-depth research on fault tolerance and voting technologies, redundant voting structures are increasingly being used in safety control interlocking systems. Because system redundancy can ensure real-time performance and reliability, multi-module redundant structures are often used in safety interlocking systems. Common structures include two-out-of-one, two-out-of-two, and three-out-of-two.

[0004] In a two-out-of-one configuration, if a hazard is detected in one of the circuits, the device will be shut down. Therefore, if one channel fails and a dangerous failure occurs, the other channel can function normally, and the system can remain safe. While this configuration reduces the probability of dangerous system failure, it also has a higher rate of false shutdowns than a simpler system, which is detrimental to the continuity and sustainability of the production process.

[0005] The two-out-of-two structure requires that both channels must operate simultaneously. That is to say, if there is a dangerous failure in any of the channels, the system will lose all safety functions. Although the false shutdown rate is low, the dangerous failure rate is higher than that of a simple system, which makes it impossible to meet the requirements of a safety control system.

[0006] The two-out-of-three architecture is the most commonly used fault-tolerant design. When a system uses a two-out-of-three architecture, three modules simultaneously perform the same operation, synchronously collect the same input information, and use a two-out-of-three voting method to determine the final output. Although the two-out-of-three architecture can achieve fault tolerance, typical two-out-of-three systems still have limitations in terms of detection and computational speed. This means that if a single channel fails, the system may be unable to detect it, resulting in the failure not being discovered in a timely manner. Furthermore, the slow computational speed can cause a delay in system response, posing a safety hazard. Summary of the Invention

[0007] To solve the above problems, the purpose of the embodiments of the present invention is to provide a multiple voting fault-tolerant structure safety control method, a multiple voting fault-tolerant structure safety control system and a multiple voting fault-tolerant structure safety control device.

[0008] To achieve the above objectives, the present invention provides a first aspect of a multi-voting fault-tolerant structure safety control method for petrochemical safety control, the method comprising:

[0009] Input three identical signals obtained from the same site into each of the three parallel channels of the first fault-tolerant voting, perform the first two-out-of-three fault-tolerant voting operation on each channel, and output the first two-out-of-three fault-tolerant voting result;

[0010] Inputting the first two-out-of-three fault-tolerant voting result into each of the N parallel channels of the second fault-tolerant voting, performing a second two-out-of-three fault-tolerant voting operation on each channel, and outputting the second two-out-of-three fault-tolerant voting result, where 3≥N≥2;

[0011] The second-level two-out-of-three fault-tolerant voting result is input into each of the M parallel channels of the third-level fault-tolerant voting, and the third-level two-out-of-three fault-tolerant voting operation is performed on each channel, and the third-level two-out-of-three fault-tolerant voting result is output as the final voting result, 3≥M≥1.

[0012] Optionally, the first two-out-of-three fault-tolerant voting operation and the second two-out-of-three fault-tolerant voting operation are implemented using computer program instructions, and the third two-out-of-three fault-tolerant voting operation is implemented using a hardware two-out-of-three fault-tolerant voting circuit.

[0013] Optionally, the three channels of the first fault-tolerant voting use different processors to perform the first two-out-of-three fault-tolerant voting operation, and the N channels of the second fault-tolerant voting use different processors to perform the second two-out-of-three fault-tolerant voting operation.

[0014] A second aspect of the present invention provides a multi-voting fault-tolerant structure safety control system for implementing the above-mentioned safety control method, the safety control system comprising:

[0015] The first fault-tolerant voting module includes three channels connected in parallel and a voting operation module provided on each channel;

[0016] The second fault-tolerant voting module includes N channels connected in parallel and a voting operation module provided on each channel, 3≥N≥2;

[0017] Each voting operation module includes a memory and a processor, wherein the memory stores program instructions for software two-out-of-three voting operation, and the processor is used to execute the program instructions in the memory;

[0018] The third fault-tolerant voting module includes M channels connected in parallel and a hardware two-out-of-three voting circuit provided on each channel for implementing hardware two-out-of-three voting, where 3≥M≥1;

[0019] An input module, used for inputting three identical signals obtained from the same site into the first fault-tolerant voting module;

[0020] A first communication module is used to input the two-out-of-three fault-tolerant voting result output by the first fault-tolerant voting module into the second fault-tolerant voting module;

[0021] The second communication module is used to input the two-out-of-three fault-tolerant voting result output by the second fault-tolerant voting module into the third fault-tolerant voting module.

[0022] Optionally, the input module includes: three input channels, and an input quantity detector, a first safety barrier, and an input terminal board provided on each input channel;

[0023] The input quantity detector is connected to the first safety barrier and is used to detect field signals;

[0024] The first safety barrier is connected to the input terminal board for signal transmission safety limiting;

[0025] The input terminal board is connected to the first fault-tolerant voting module and is used to divide the same signal into three signals and input the three signals into each channel of the first fault-tolerant voting module.

[0026] Optionally, the first communication module includes three parallel LVDS communication cards, each LVDS communication card is connected to the voting operation module of the corresponding channel in the first fault-tolerant voting module, and is used to receive the first three-out-of-two fault-tolerant voting result output by the voting operation module of the channel, and input the first three-out-of-two fault-tolerant voting result into each channel of the second fault-tolerant voting module.

[0027] Optionally, the second communication module includes three parallel channels, and each channel of the second communication module is connected in series with an LVDS communication card and an output card;

[0028] The LVDS communication card of each channel of the second communication module is connected to the voting operation module of the corresponding channel of the second fault-tolerant voting module, and is used to receive the second two-out-of-three fault-tolerant voting result output by the voting operation module, and input the second two-out-of-three fault-tolerant voting result to the output card connected in series with the LVDS communication card;

[0029] Each output card of the second communication module is connected to each channel of the third fault-tolerant voting module, and is used to input the second two-out-of-three fault-tolerant voting result received by the output card to each channel of the third fault-tolerant voting module.

[0030] Optionally, each channel of the first fault-tolerant voting module further includes an input card for receiving a signal input to the channel and converting and outputting each signal input to the channel;

[0031] The voting operation module on each channel of the first fault-tolerant voting module is a CPU card.

[0032] Optionally, the voting operation module on each channel of the second fault-tolerant voting module is a TMCR card, and each TMCR card includes three independent CPU modules.

[0033] Optionally, each channel of the third fault-tolerant voting module is provided with an output terminal board, and each output terminal board has a built-in hardware two-out-of-three voting circuit for implementing hardware two-out-of-three voting.

[0034] Optionally, the output cards on the three parallel channels of the second communication module all use output contacts to output the voting signals received by the output cards in pairs, and the output cards on the three parallel channels are output card A, output card B, and output card C respectively;

[0035] in,

[0036] The voting signals output by output card A are voting signal A1 and voting signal A2;

[0037] The voting signals output by output card B are voting signal B1 and voting signal B2;

[0038] The voting signals output by the output card C are voting signal C1 and voting signal C2.

[0039] Optionally, the two-out-of-three hardware voting circuit includes six switch terminals, namely a first switch terminal, a second switch terminal, a third switch terminal, a fourth switch terminal, a fifth switch terminal, and a sixth switch terminal, wherein the first to sixth switch terminals are controlled by voting signal A1, voting signal B2, voting signal B1, voting signal C2, voting signal C1, and voting signal A2, respectively;

[0040] The first switch terminal and the second switch terminal are connected in parallel to form a first parallel circuit, the third switch terminal and the fourth switch terminal are connected in parallel to form a second parallel circuit, and the fifth switch terminal and the sixth switch terminal are connected in parallel to form a third parallel circuit;

[0041] The first parallel circuit is connected in series with the second parallel circuit, and the second parallel circuit is connected in series with the third parallel circuit to form a hardware two-out-of-three voting circuit;

[0042] The first to sixth switch terminals are in a normally open state. When the voting signal controlling the switch terminal is a valid signal, the switch terminal is triggered to close, causing the hardware voting circuit to be turned on and output the valid voting signal.

[0043] Optionally, the input card and / or the output card are both dual cards, so as to achieve redundancy processing when a single input card and / or output card fails.

[0044] A third aspect of the present invention provides a multi-voting fault-tolerant structure safety control device, which is implemented based on the above-mentioned safety control system and includes: P TMCR chassis, three I / O chassis and M output terminal boards, where 2≥P≥1 and 3≥M≥1;

[0045] Each TMCR chassis consists of two identical components, forming a redundant configuration. Each component includes multiple slots for inserting cards, including TMCR cards and LVDS communication cards.

[0046] Each I / O chassis includes a plurality of slots into which cards are inserted, wherein the cards include a CPU card, an LVDS communication card, an input card, and an output card;

[0047] Each I / O chassis and each TMCR chassis achieve two-way high-speed communication through LVDS communication card;

[0048] Each output terminal board is connected to an output card of each I / O chassis.

[0049] Optionally, the safety control device further comprises: an input quantity detector, a first safety barrier, an input terminal board, a second safety barrier and an actuator;

[0050] The input quantity detector is connected to the first safety barrier for signal acquisition;

[0051] The first safety barrier is connected to the input terminal board for safety energy limiting;

[0052] The input terminal board is connected to the input card of each of the three I / O chassis, and is used to divide the signal into three identical signals and respectively send them to the input card of each of the three I / O chassis;

[0053] The second safety barrier is connected to the output terminal board and is used to receive the hardware voting signal output by the output terminal board and input the hardware voting signal to the actuator.

[0054] Through the above technical solution, multiple signals from the same site are subjected to multiple three-out-of-two fault-tolerant processing on each redundant channel, which significantly improves the system's redundant fault-tolerant capability and effectively reduces the system's dangerous failure rate and false shutdown rate.

[0055] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following detailed description, they are used to explain the embodiments of the present invention, but do not constitute a limitation of the embodiments of the present invention. In the accompanying drawings:

[0057] Figure 1 This is a block diagram of a multi-voting fault-tolerant structure safety control system provided by one embodiment of the present invention;

[0058] Figure 2 This is a schematic diagram of a multi-voting fault-tolerant structure safety control system provided by one embodiment of the present invention;

[0059] Figure 3 This is a structural diagram of a hardware two-out-of-three voting circuit for a multi-voting fault-tolerant safety control system provided by one embodiment of the present invention;

[0060] Figure 4 This is a schematic diagram of an I / O chassis of a multi-voting fault-tolerant structure safety control device provided by one embodiment of the present invention;

[0061] Figure 5 This is a schematic diagram of a TMCR chassis of a multi-voting fault-tolerant structure safety control device provided by one embodiment of the present invention;

[0062] Figure 6 This is a cabinet structure diagram of a multi-voting fault-tolerant safety control device provided by an embodiment of the present invention.

[0063] Description of Reference Numerals

[0064] 100-slot; 200-first component; 300-second component;

[0065] 201-TMCR card; 202-first LVDS communication card; 203-second LVDS communication card. DETAILED DESCRIPTION

[0066] The following describes the specific embodiments of the present invention in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the present invention and are not intended to limit the present invention.

[0067] Example 1

[0068] An embodiment of the present invention provides a multi-voting fault-tolerant structure safety control method for petrochemical safety control, the method comprising:

[0069] Input three identical signals obtained from the same site into each of the three parallel channels of the first fault-tolerant voting, perform the first two-out-of-three fault-tolerant voting operation on each channel, and output the first two-out-of-three fault-tolerant voting result;

[0070] Inputting the first two-out-of-three fault-tolerant voting result into each of the N parallel channels of the second fault-tolerant voting, performing a second two-out-of-three fault-tolerant voting operation on each channel, and outputting the second two-out-of-three fault-tolerant voting result, where 3≥N≥2;

[0071] The second-level two-out-of-three fault-tolerant voting result is input into each of the M parallel channels of the third-level fault-tolerant voting, and the third-level two-out-of-three fault-tolerant voting operation is performed on each channel, and the third-level two-out-of-three fault-tolerant voting result is output as the final voting result, 3≥M≥1.

[0072] The safety control method employs a first-level, two-out-of-three fault-tolerant voting operation performed on three mutually redundant parallel channels, outputting the first-level, two-out-of-three fault-tolerant voting result to achieve fault tolerance for three signals from the same site. A second-level, two-out-of-three fault-tolerant voting operation is performed on N mutually redundant parallel channels, outputting the second-level, two-out-of-three fault-tolerant voting result to achieve fault tolerance for the first-level, two-out-of-three fault-tolerant voting result. A third-level, two-out-of-three fault-tolerant voting operation is performed on M mutually redundant parallel channels, outputting the third-level, two-out-of-three fault-tolerant voting result to achieve fault tolerance for the second-level, two-out-of-three fault-tolerant voting result.

[0073] The voting mechanism for the three-out-of-two fault-tolerant voting uses a majority of identical signals as the correct output for the three-out-of-two fault-tolerant voting. That is, when two of the three signals are valid, the valid signals are output as the voting result. The multiple three-out-of-two fault-tolerant processing provided by the method significantly improves the system's redundancy and fault tolerance. When a channel in a three-out-of-two fault-tolerant operation fails, the other channels can continue to operate, and the system remains in a normal state, effectively reducing the system's dangerous failure rate and false shutdown rate.

[0074] Furthermore, the first and second three-out-of-two fault-tolerant voting operations are implemented using computer program instructions, and the third three-out-of-two fault-tolerant voting operation is implemented using a hardware three-out-of-two fault-tolerant voting circuit. The voting signal output by the hardware three-out-of-two fault-tolerant voting circuit is the final control signal.

[0075] Furthermore, the three parallel channels of the first-level fault-tolerant voting use different processors to execute the first-level three-out-of-two fault-tolerant voting operation, so that the signals from the same site and the same time are in the same voting cycle when the first three-out-of-two fault-tolerant voting is performed, thereby achieving synchronization of the results of the first three-out-of-two fault-tolerant voting operation. The N parallel channels of the second-level fault-tolerant voting use different processors to execute the second three-out-of-two fault-tolerant voting operation, so that the three voting results from the first three-out-of-two fault-tolerant voting at the same time are in the same voting cycle when the second three-out-of-two fault-tolerant voting is performed, thereby achieving synchronization of the results of the second three-out-of-two fault-tolerant voting operation. The first three-out-of-two fault-tolerant voting and the second three-out-of-two fault-tolerant voting use different processors to execute three-out-of-two fault-tolerant voting, thereby reducing the computational load of the processor executing each three-out-of-two fault-tolerant voting operation and increasing the computational speed, thereby making the overall system response faster.

[0076] Example 2

[0077] An embodiment of the present invention provides a multi-voting fault-tolerant structure safety control system that implements the above embodiment and the above safety control method. The safety control system includes:

[0078] The first fault-tolerant voting module includes three channels connected in parallel and a voting operation module provided on each channel;

[0079] The second fault-tolerant voting module includes N channels connected in parallel and a voting operation module provided on each channel, 3≥N≥2;

[0080] Each voting operation module includes a memory and a processor, wherein the memory stores program instructions for software three-out-of-two voting operation, and the processor is used to execute the program instructions in the memory to implement software three-out-of-two voting;

[0081] The third fault-tolerant voting module includes M channels connected in parallel and a hardware three-out-of-two voting circuit provided on each channel for implementing hardware three-out-of-two voting, and outputting a voting signal of the hardware three-out-of-two voting as a final control signal, 3 ≥ M ≥ 1;

[0082] An input module, used for inputting three identical signals obtained from the same site into the first fault-tolerant voting module;

[0083] A first communication module is used to input the two-out-of-three fault-tolerant voting result output by the first fault-tolerant voting module into the second fault-tolerant voting module;

[0084] The second communication module is used to input the two-out-of-three fault-tolerant voting result output by the second fault-tolerant voting module into the third fault-tolerant voting module.

[0085] Figure 1 This is a block diagram of a multi-voting fault-tolerant structure safety control system provided by one embodiment of the present invention. Figure 1 As shown, the input module includes: three input channels, and an input quantity detector, a first safety barrier, and an input terminal board arranged on each input channel;

[0086] The input quantity detector is connected to the first safety barrier and is used to detect field signals;

[0087] The first safety barrier is connected to the input terminal board for signal transmission safety limiting;

[0088] The input terminal board is connected to the first fault-tolerant voting module, and is used to divide the same signal into three signals and input them into each channel of the first fault-tolerant voting module;

[0089] The three input quantity detectors on the three input channels acquire signals from the same field, and the input quantity detectors include digital quantity detectors or analog quantity detectors.

[0090] Further, such as Figure 1 As shown, the first communication module includes three parallel LVDS communication cards. Each LVDS communication card is connected to the voting operation module of the corresponding channel in the first fault-tolerant voting module. The LVDS communication card is used to receive the first two-out-of-three fault-tolerant voting result output by the voting operation module of the channel and input the first two-out-of-three fault-tolerant voting result into each channel of the second fault-tolerant voting module. This allows the first and second fault-tolerant voting modules to communicate quickly via the LVDS communication cards in the first communication module.

[0091] Further, such as Figure 1 As shown, the second communication module includes three parallel channels, and each channel of the second communication module is connected in series with an LVDS communication card and an output card.

[0092] The LVDS communication card of each channel of the second communication module is connected to the voting operation module of the corresponding channel of the second fault-tolerant voting module, and is used to receive the second three-out-of-two fault-tolerant voting result output by the voting operation module, and input the second three-out-of-two fault-tolerant voting result to the output card connected in series with the LVDS communication card.

[0093] Each output card of the second communication module is connected to each channel of the third fault-tolerant voting module, and is used to convert the second three-out-of-two fault-tolerant voting result received by the output card and input it into the hardware three-out-of-two voting circuit of each channel of the third fault-tolerant voting module.

[0094] Further, such as Figure 1As shown, each channel of the first fault-tolerant voting module further includes an input card for receiving signals input to the channel and converting and outputting each signal input to the channel. The input card includes a digital input DI card or an analog input AI card.

[0095] Figure 2 It is a schematic diagram of a multi-voting fault-tolerant structure safety control system provided by one embodiment of the present invention.

[0096] like Figure 2 As shown, the input module of the safety control system includes three parallel input channels, and each input channel is provided with a digital detector, a first safety barrier, and an input terminal board.

[0097] like Figure 2 As shown, the first fault-tolerant voting module of the safety control system includes three channels in parallel, and a digital input DI card and a CPU card connected in series on each channel. The first communication module includes three LVDS communication cards in parallel. The second fault-tolerant voting module includes two channels in parallel, and a TMCR (TPU Module Configuration Register, TPU module configuration register, hereinafter referred to as TMCR) card arranged on each channel. The second communication module includes three channels in parallel, and an LVDS communication card and a digital output DO card are connected in series on each channel. The third fault-tolerant voting module includes two channels in parallel and an output terminal board arranged on each channel, and each output terminal board has a built-in hardware three-out-of-two voting circuit for realizing hardware three-out-of-two fault-tolerant voting.

[0098] Further, such as Figure 2 As shown, the voting operation module on each channel of the first-level fault-tolerant voting module is a CPU card. The voting operation module on each channel of the second-level fault-tolerant voting module is a TMCR card. Each TMCR card includes three independent CPU modules, which are used to achieve time synchronization of the first-level fault-tolerant voting results output by the three parallel channels of the first-level fault-tolerant voting module, and to perform the second-level three-out-of-two fault-tolerant voting operation. Adding a TMCR card to perform the second-level three-out-of-two fault-tolerant voting operation allows the computing load of multiple three-out-of-two fault-tolerant voting operations to be shared, greatly improving the system's computing processing speed. The TMCR card can load large-scale and complex user programs, can include complex computing processes, and has a wide range of applications. In addition, the TMCR card also has powerful processing power and communication networking capabilities, providing an isolated port for realizing OPC UA communication functions.

[0099] like Figure 2As shown, each input terminal board splits the signal into three identical signals, which are then fed into each digital input DI card on the three parallel channels of the first-level fault-tolerant voting module. Each digital input DI card converts each received signal into a computer-readable signal value and sends it to a CPU card connected in series with the digital input DI card for software-based two-out-of-three voting, outputting the first-level two-out-of-three fault-tolerant voting result. The first-level two-out-of-three fault-tolerant voting result output by each CPU card is sent via the corresponding LVDS communication card in the first communication module to the TMCR card in the second-level fault-tolerant voting module. The TMCR card then performs a second-level software-based two-out-of-three voting and outputs the second-level two-out-of-three fault-tolerant voting result. The second-level 2-out-of-3 fault-tolerant voting result output by each TMCR card is input to the corresponding LVDS communication card in the second communication module. This LVDS communication card then sends the result to the digital output DO card connected in series. The digital output DO card converts the received second-level 2-out-of-3 fault-tolerant voting result into a signal that can be received by the hardware 2-out-of-3 voting circuit in the third-level fault-tolerant voting module. The signal is then input to the hardware 2-out-of-3 voting circuit of each output terminal board in the third-level fault-tolerant voting module. The output terminal board performs the hardware 2-out-of-3 voting and outputs the third-level 2-out-of-3 fault-tolerant voting result as a control signal. This control signal is then sent to the actuator via the second safety barrier.

[0100] Furthermore, the input card and / or the output card are both dual cards, which are used to implement redundancy processing when a single input card and / or output card fails. Figure 2 As shown, both the digital input DI card and / or the digital output DO card are dual cards, which are used to implement redundancy processing when a single digital input DI card and / or digital output DO card fails. When one of the dual cards fails, the other card can still ensure normal operation of the system.

[0101] Furthermore, the output cards on the three parallel channels of the second communication module all use output contacts to output the voting signals received by the output cards in pairs, and the output cards on the three parallel channels are output card A, output card B and output card C respectively; wherein,

[0102] The voting signals output by output card A are voting signal A1 and voting signal A2;

[0103] The voting signals output by output card B are voting signal B1 and voting signal B2;

[0104] The voting signals output by the output card C are voting signal C1 and voting signal C2.

[0105] Figure 3 This is a circuit diagram of a hardware three-out-of-two voting system for a multi-voting fault-tolerant safety control system provided by one embodiment of the present invention. Figure 3As shown, an embodiment of the present invention provides a safety control system hardware three-out-of-two voting circuit, including six switch terminals, namely a first switch terminal, a second switch terminal, a third switch terminal, a fourth switch terminal, a fifth switch terminal and a sixth switch terminal, wherein the first to sixth switch terminals are controlled by voting signal A1, voting signal B2, voting signal B1, voting signal C2, voting signal C1 and voting signal A2 respectively;

[0106] The first switch terminal and the second switch terminal are connected in parallel to form a first parallel circuit, the third switch terminal and the fourth switch terminal are connected in parallel to form a second parallel circuit, and the fifth switch terminal and the sixth switch terminal are connected in parallel to form a third parallel circuit;

[0107] The first, second and third parallel circuits are sequentially connected in series, that is, the first parallel circuit is connected in series with the second parallel circuit, and the second parallel circuit is connected in series with the third parallel circuit, together forming a hardware two-out-of-three voting circuit;

[0108] The first to sixth switch terminals are in a normally open state. When the voting signal controlling the switch terminal is a valid signal, the switch terminal is triggered to close, causing the hardware voting circuit to be turned on and output the valid voting signal.

[0109] Example 3

[0110] An embodiment of the present invention provides a multi-voting fault-tolerant structure safety control device, which is implemented based on the safety control system of the second embodiment, and includes: P TMCR chassis, three I / O chassis, and M output terminal boards, where 2≥P≥1 and 3≥M≥1;

[0111] Each TMCR chassis consists of two identical components, forming a redundant configuration. Each component includes multiple slots for inserting cards, including TMCR cards and LVDS communication cards.

[0112] Each I / O chassis includes a plurality of slots into which cards are inserted, wherein the cards include a CPU card, an LVDS communication card, an input card, and an output card;

[0113] Each I / O chassis and each TMCR chassis achieve two-way high-speed communication through LVDS communication card;

[0114] Each output terminal board is connected to an output card of each I / O chassis.

[0115] Figure 4 This is a schematic diagram of an I / O chassis of a multi-voting fault-tolerant structure safety control device provided by an embodiment of the present invention. Figure 4As shown, a typical I / O chassis includes fifteen slots 100 for inserting cards. The first slot 100 on the far left is fixed to the controller CPU card, while the other slots 100 can be freely configured. A typical I / O chassis configuration is that the second and third slots 100 are inserted with LVDS communication cards, the fourth through ninth slots 100 are inserted with digital input (DI) cards, the tenth and eleventh slots 100 are inserted with analog input (AI) cards, and the twelfth through fifteenth slots 100 are inserted with digital output (DO) cards.

[0116] Figure 5 This is a schematic diagram of a TMCR chassis of a multi-voting fault-tolerant structure safety control device provided by an embodiment of the present invention. A typical TMCR chassis is divided into two identical parts, the left and the right. Figure 5 As shown, it includes a first component 200 and a second component 300. Each component includes four slots for inserting card components, and the two components form a redundant configuration. Figure 5 As shown, the first component 200 includes a TMCR card 201, a first LVDS communication card 202, and a second LVDS communication card 203. The TMCR card is composed of three identical, independent CPU modules. The TMCR card is two slots wide. The first LVDS communication card is used for fast communication with the LVDS communication card in the I / O chassis. The second LVDS communication card is used to communicate with the I / O chassis in the second cabinet when the system capacity is large and two cabinets are required.

[0117] Figure 6 This is a structural diagram of a safety control device cabinet provided by an embodiment of the present invention. Figure 6 As shown in Figure 2, a typical safety control device consists of three identical I / O chassis and one TMCR chassis. Figure 4 As shown in the figure, the three I / O chassis are I / O chassis A, I / O chassis B, and I / O chassis C, and the one TMCR chassis is TMCR chassis M. The three I / O chassis and one TMCR chassis are placed in a cabinet with a length × width × height = 800 × 800 × 2000 mm. Figure 6 As shown in the figure, the I / O chassis and TMCR chassis respectively realize bidirectional high-speed communication through LVDS communication cards.

[0118] like Figure 6 As shown, the input of the TMCR chassis comes from the first two-out-of-three fault-tolerant voting result output by the CPU card in the I / O chassis. The TMCR chassis will output the second two-out-of-three fault-tolerant voting result calculated and output by the TMCR cards in the first component 200 and the second component 300 to the digital output DO card of each I / O chassis, and then output it to the output terminal board through the digital output DO card of the I / O chassis.

[0119] When the device needs to output, the three I / O chassis each output a voting signal corresponding to the result of the second, two-out-of-three fault-tolerant voting via their I / O pins. When the I / O chassis are functioning normally, each will output two identical voting signals. If an output failure occurs in one I / O chassis, the faulty I / O chassis will not output due to the fault. However, the other two healthy I / O chassis will continue to function normally and output normally. The present invention's multiple, two-out-of-three fault-tolerant voting structure remains functional, and the system can continue to output normal control signals.

[0120] Furthermore, the safety control device further comprises: an input quantity detector, a first safety barrier, an input terminal board, a second safety barrier and an actuator;

[0121] The input quantity detector is connected to the first safety barrier for signal acquisition;

[0122] The first safety barrier is connected to the input terminal board for safety energy limiting;

[0123] The input terminal board is connected to the input card of each of the three I / O chassis, and is used to divide the signal into three identical signals and respectively send them to the input card of each of the three I / O chassis;

[0124] The second safety barrier is connected to the output terminal board and is used to receive the hardware voting signal output by the output terminal board and input the hardware voting signal to the actuator.

[0125] Those skilled in the art will appreciate that all or part of the steps in the methods of the aforementioned embodiments can be accomplished by instructing the relevant hardware through a program, which is stored in a storage medium and includes a number of instructions for causing a single-chip microcomputer, chip, or processor to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0126] The above describes in detail the optional embodiments of the present invention in conjunction with the accompanying drawings. However, the embodiments of the present invention are not limited to the specific details in the above embodiments. Within the technical concept of the embodiments of the present invention, a variety of simple modifications can be made to the technical solutions of the embodiments of the present invention, and these simple modifications all fall within the scope of protection of the embodiments of the present invention. It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner unless there is any contradiction. In order to avoid unnecessary repetition, the embodiments of the present invention will no longer describe the various possible combinations separately.

[0127] In addition, the various embodiments of the present invention may be arbitrarily combined, and as long as they do not violate the concept of the embodiments of the present invention, they should also be regarded as the contents disclosed in the embodiments of the present invention.

Claims

1. A multi-voting fault-tolerant structure safety control method for petrochemical safety control, characterized by: The method comprises: Input three identical signals obtained from the same site into each of the three parallel channels of the first fault-tolerant voting, perform the first two-out-of-three fault-tolerant voting operation on each channel, and output the first two-out-of-three fault-tolerant voting result; Inputting the first two-out-of-three fault-tolerant voting result into each of the N parallel channels of the second fault-tolerant voting, performing a second two-out-of-three fault-tolerant voting operation on each channel, and outputting the second two-out-of-three fault-tolerant voting result, where 3≥N≥2; Input the second two-out-of-three fault-tolerant voting result into each of the M parallel channels of the third-level fault-tolerant voting, perform the third two-out-of-three fault-tolerant voting operation on each channel, and output the third two-out-of-three fault-tolerant voting result as the final voting result, 3≥M≥1; Among them, the three channels of the first-level fault-tolerant voting use different CPU cards to perform the first-level three-out-of-two fault-tolerant voting operation, so that the signals from the same site and the same time are in the same voting cycle when performing the first-level three-out-of-two fault-tolerant voting, thereby achieving synchronization of the first-level three-out-of-two fault-tolerant voting operation results; the N channels of the second-level fault-tolerant voting use different TMCR cards to perform the second-level three-out-of-two fault-tolerant voting operation, so that the three voting results from the first-level three-out-of-two fault-tolerant voting at the same time are in the same voting cycle when performing the second-level three-out-of-two fault-tolerant voting, thereby achieving synchronization of the second-level three-out-of-two fault-tolerant voting operation results, and each TMCR card includes three independent CPU modules; the three CUP cards are deployed in three identical I / O chassis respectively, and the N TMCR cards are deployed in N identical TMCR chassis respectively. Bidirectional high-speed communication is achieved between the I / O chassis and the TMCR chassis through an LVDS communication card; the third-level fault-tolerant voting is performed through the built-in switch terminal circuit of the output terminal board, and each output terminal board is connected to the output card of each I / O chassis.

2. The safety control method according to claim 1, characterized in that: The first two-out-of-three fault-tolerant voting operation and the second two-out-of-three fault-tolerant voting operation are implemented using computer program instructions, and the third two-out-of-three fault-tolerant voting operation is implemented using a hardware two-out-of-three fault-tolerant voting circuit.

3. A multi-voting fault-tolerant safety control system that implements the safety control method according to any one of claims 1 to 2, characterized in that: The safety control system includes: The first fault-tolerant voting module includes three channels connected in parallel and a voting operation module provided on each channel. The three channels of the first fault-tolerant voting use different CPU cards to perform the first three-out-of-two fault-tolerant voting operation. This ensures that signals from the same site and at the same time are in the same voting cycle when performing the first three-out-of-two fault-tolerant voting, thereby achieving synchronization of the first three-out-of-two fault-tolerant voting operation results. The second fault-tolerant voting module includes N channels connected in parallel and a voting operation module provided on each channel, where 3≥N≥2, and the N channels of the second fault-tolerant voting use different TMCR cards to perform the second three-out-of-two fault-tolerant voting operation, so that three voting results from the first three-out-of-two fault-tolerant voting at the same time are in the same voting cycle when the second three-out-of-two fault-tolerant voting is performed, thereby achieving synchronization of the second three-out-of-two fault-tolerant voting operation results. Each TMCR card includes three independent CPU modules, and the three CUP cards are respectively deployed in three identical I / O chassis. The N TMCR cards are respectively deployed in N identical TMCR chassis, and two-way high-speed communication is achieved between the I / O chassis and the TMCR chassis via an LVDS communication card. Each voting operation module includes a memory and a processor, wherein the memory stores program instructions for software two-out-of-three voting operation, and the processor is used to execute the program instructions in the memory; A third-level fault-tolerant voting module includes M channels connected in parallel and a hardware two-out-of-three voting circuit provided on each channel for implementing hardware two-out-of-three voting, where 3≥M≥1. Each channel of the third-level fault-tolerant voting module is provided with an output terminal board, each output terminal board is connected to an output card of each I / O chassis, and each output terminal board has a built-in hardware two-out-of-three voting circuit for implementing hardware two-out-of-three voting. An input module, used for inputting three identical signals obtained from the same site into the first fault-tolerant voting module; A first communication module is used to input the two-out-of-three fault-tolerant voting result output by the first fault-tolerant voting module into the second fault-tolerant voting module; The second communication module is used to input the two-out-of-three fault-tolerant voting result output by the second fault-tolerant voting module into the third fault-tolerant voting module.

4. The safety control system according to claim 3, characterized in that: The input module includes: three input channels, and an input quantity detector, a first safety barrier, and an input terminal board arranged on each input channel; The input quantity detector is connected to the first safety barrier and is used to detect field signals; The first safety barrier is connected to the input terminal board for signal transmission safety limiting; The input terminal board is connected to the first fault-tolerant voting module and is used to divide the same signal into three signals and input the three signals into each channel of the first fault-tolerant voting module.

5. The safety control system according to claim 4, characterized in that: The first communication module includes three parallel LVDS communication cards, each LVDS communication card is connected to the voting operation module of the corresponding channel in the first fault-tolerant voting module, and is used to receive the first three-out-of-two fault-tolerant voting result output by the voting operation module of the channel, and input the first three-out-of-two fault-tolerant voting result into each channel of the second fault-tolerant voting module.

6. The safety control system according to claim 5, characterized in that: The second communication module includes three parallel channels, and each channel of the second communication module is connected in series with an LVDS communication card and an output card; The LVDS communication card of each channel of the second communication module is connected to the voting operation module of the corresponding channel of the second fault-tolerant voting module, and is used to receive the second two-out-of-three fault-tolerant voting result output by the voting operation module, and input the second two-out-of-three fault-tolerant voting result to the output card connected in series with the LVDS communication card; Each output card of the second communication module is connected to each channel of the third fault-tolerant voting module, and is used to input the second two-out-of-three fault-tolerant voting result received by the output card to each channel of the third fault-tolerant voting module.

7. The safety control system according to claim 6, characterized in that: Each channel of the first fault-tolerant voting module further includes an input card for receiving signals input into the channel and converting and outputting each signal input into the channel.

8. The safety control system according to claim 7, characterized in that: The output cards on the three parallel channels of the second communication module all use output contacts to output the voting signals received by the output cards in pairs, and the output cards on the three parallel channels are output card A, output card B and output card C respectively; in, The voting signals output by output card A are voting signal A1 and voting signal A2; The voting signals output by output card B are voting signal B1 and voting signal B2; The voting signals output by the output card C are voting signal C1 and voting signal C2.

9. The safety control system according to claim 8, characterized in that: The two-out-of-three hardware voting circuit includes six switch terminals, namely a first switch terminal, a second switch terminal, a third switch terminal, a fourth switch terminal, a fifth switch terminal, and a sixth switch terminal, wherein the first to sixth switch terminals are controlled by voting signal A1, voting signal B2, voting signal B1, voting signal C2, voting signal C1, and voting signal A2, respectively; The first switch terminal and the second switch terminal are connected in parallel to form a first parallel circuit, the third switch terminal and the fourth switch terminal are connected in parallel to form a second parallel circuit, and the fifth switch terminal and the sixth switch terminal are connected in parallel to form a third parallel circuit; The first parallel circuit is connected in series with the second parallel circuit, and the second parallel circuit is connected in series with the third parallel circuit to form a hardware two-out-of-three voting circuit; The first to sixth switch terminals are in a normally open state. When the voting signal controlling the switch terminal is a valid signal, the switch terminal is triggered to close, causing the hardware voting circuit to be turned on and output the valid voting signal.

10. The safety control system according to any one of claims 7 to 9, characterized in that: The input card and / or the output card are both dual cards, which are used to achieve redundancy processing when a single input card and / or output card fails.

11. A multi-voting fault-tolerant structure safety control device, characterized in that: The device is implemented based on the safety control system according to any one of claims 3 to 10, comprising: P TMCR chassis, three I / O chassis and M output terminal boards, 2 ≥ P ≥ 1, 3 ≥ M ≥ 1; Each TMCR chassis consists of two identical components, forming a redundant configuration. Each component includes multiple slots for inserting cards, including TMCR cards and LVDS communication cards. Each I / O chassis includes a plurality of slots into which cards are inserted, wherein the cards include a CPU card, an LVDS communication card, an input card, and an output card; Each I / O chassis and each TMCR chassis achieve two-way high-speed communication through LVDS communication card; Each output terminal board is connected to an output card of each I / O chassis.

12. The safety control device according to claim 11, characterized in that: The safety control device further comprises: an input quantity detector, a first safety barrier, an input terminal board, a second safety barrier and an actuator; The input quantity detector is connected to the first safety barrier for signal acquisition; The first safety barrier is connected to the input terminal board for safety energy limiting; The input terminal board is connected to the input card of each of the three I / O chassis, and is used to divide the signal into three identical signals and respectively send them to the input card of each of the three I / O chassis; The second safety barrier is connected to the output terminal board and is used to receive the hardware voting signal output by the output terminal board and input the hardware voting signal to the actuator.

Citation Information

Patent Citations

  • Two-out-of-three voting control system

    CN111694268A