Fine-grained coordination of local archives in a host / host scenario for infrastructure servers
By continuously storing data and recording health status on the operator station server, the synchronization of data archives is optimized, the problem of data inconsistency in redundant design is solved, and efficient merging of high-quality data is achieved, thereby improving the reliability and availability of the control system.
Patent Information
- Application Number
- CN202211005197.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-08-23
- Filing Date
- 2022-08-22
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2042-08-22
AI Technical Summary
In the prior art, redundantly designed operator station servers may cause inconsistent data archiving when the facility bus fails, potentially leading to loss of high-quality data or increased storage requirements, and a complex reconstruction process.
By continuously storing data on the operator station servers and recording the health status and master/slave functionality, the synchronization process of the data archive is optimized so that after a master/slave scenario, the data of the server with the best health status is selected to be merged into the archive.
It achieves efficient merging of high-quality data archives after a facility bus failure, reduces storage requirements, ensures data consistency and reliability, and improves the operability and availability of the control system.
Smart Images

Figure CN115712495B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a control system for a technical installation, in particular a processing or production installation, comprising a first operator station server and a second operator station server, wherein one of the operator station servers is configured to operate as a master and the other of the operator station servers is configured to operate as a slave, wherein the slave is configured to take over the functions of the master in the event of a master failure, wherein a first data archive is implemented on the first operator station server and a second data archive is implemented on the second operator station server, wherein the first operator station server and the second operator station server are configured to receive and store data of the technical installation in respective data archives, and wherein the first operator station server and the second operator station server are each configured to determine a respective health status. Furthermore, the present invention relates to a use of the control system for operating a technical installation and a method for operating a redundantly configured control system for a technical installation. Background Art
[0002] In order to improve the availability caused by hardware failures, components are usually combined redundantly in technical installations, such as in the processing industry. If a component fails, it is directly replaced by its redundant partner.
[0003] Especially in the case of operator station servers of the control system of a processing plant, their availability plays a decisive role in the operability and visibility of the processing plant. The operator station servers are usually operated in so-called hot standby mode - that is, the process images of the two operator station servers (master and slave) are always up-to-date and can be compared with each other.
[0004] Both the master and the slave receive value changes from the automation device. During a comparison, the slave compares the value changes received from the automation device with those forwarded by the master M. If the value changes match, the slave writes them to the process image. If the master fails, a slave can be immediately replaced (without startup or general comparison) (new master) – in this case, any value changes that have not yet been compared are incorporated into the process image for seamless operation and observation / history recording.
[0005] This configuration, known per se, is exemplified in Figure 1. The control system 1 of the technical facility includes a first operator station server 2 and a second operator station server 3. In addition, the control system 1 includes an operator station client 4, an automation device 5 and a peripheral device 6. The automation device 5 (for example, SIMATIC PCS7.S7-400 of Siemens) and the peripheral device (for example, ET 200SP of Siemens) are connected to each other via a fieldbus 7 (the fieldbus is based on PROFIBUS DP, for example). The two operator station servers 2 and 3 are connected to the automation device 5 and to each other via a facility bus 8. The two operator station servers 2 and 3 are connected to the operator station client 4 via a terminal bus 9. The facility bus 8 and the terminal bus 9 can be designed as Industrial Ethernet, for example, but are not limited thereto.
[0006] The first operator system server 2 and the second operator system server 3 are designed redundantly. The first operator system server 1 acts as the master and is responsible for archiving, operation, and monitoring by the operator system clients 4. This means that measured values (e.g., process values) are written by the automation device 5 or manipulated values are set by the operator only at the master, which then performs a comparison with the second operator system server 4, acting as a slave.
[0007] The first operator station server 2 (as the master) is compared with the second operator station server 3 (as the slave), as shown in Figure 1 8 via the (fail-safe and correspondingly capable) facility bus 8. In addition to information such as process images, status information about the health status (health index) of the two operator system servers 2, 3 can also be exchanged so that the operator system server 2, 3 with the best health status can be appointed as the master in a coordinated manner.
[0008] As long as the master can be clearly identified, a failure or partial failure of the operator system servers 2, 3 can be completely blocked and the availability of the technical installation can be ensured. If a so-called master / master scenario arises due to certain circumstances, redundantly designed operator system servers 2, 3, using a known configuration via the installation bus 8 (also in the case of two-way redundancy), lead to the problems described below.
[0009] When the facility bus 8 is disconnected or connected (in Figure 1A master / master scenario is only set up if a network device or network card (not shown) fails, causing the two operator station servers 2 and 3 to lose contact with each other. This master / master scenario results in two measurement archives, executed on the operator station servers 2 and 3, being simultaneously and independently populated with measurement data. As is known, after redundant reconstruction, one of the two archives is discarded. This is typically the archive of the slave identified after reconstruction. This depends on whether any time-variable disturbances occur on the operator station servers 2 and 3 during the master / master scenario, resulting in correct, partially correct, or completely incorrect results.
[0010] Other methods keep track of both archives for a long time, which, however, leads to a significant increase in storage requirements. In addition, the archives created twice must also be cleaned again, because a clear "history line" must exist at the latest when the archived data is accessed (e.g. when a trend display is opened).
[0011] For example, EP 3 637 205 A1 and EP 3 736 647 A1 disclose known control systems which present an image of a facility having various objects to an operator by means of a plurality of operator station servers. Summary of the Invention
[0012] The invention is based on the object of specifying a redundantly designed control system for a technical installation, which control system enables improved archiving of the data of the technical installation.
[0013] The object is achieved by a control system according to the present invention for a technical facility, in particular a processing or production facility. This object is also achieved by a method according to the present invention for operating a redundantly designed control system for a technical facility. This object is also achieved by the use of a control system according to the present invention for operating a technical facility. Advantageous developments result from the present invention.
[0014] According to the invention, a control system of the type described at the outset is characterized in that the first operator station server and the second operator station server are configured to continuously store in a corresponding data archive, over fixed time periods, the health status of the corresponding operator station server when receiving and storing data of the technical installation and whether the corresponding operator station server acted as a master or slave in the corresponding time period.
[0015] In this context, a control system is understood to be a computer-aided technical system that includes functions for displaying, operating, and controlling technical systems, such as a manufacturing or production facility. In addition to the two operator station servers, the control system can also include operator station clients and so-called process- or production-related components, such as for controlling actuators or sensors.
[0016] Technical facilities can be facilities from the process industry, such as chemical, pharmaceutical, petrochemical, or food and beverage industries. This also includes any facilities from the production industry, factories, or factories where, for example, all types of vehicles or goods are produced. Technical facilities suitable for carrying out the method according to the invention can also be from the energy production sector. Wind turbines, solar power plants, or power plants used for energy production are also encompassed by the term technical facility.
[0017] Currently, an "operator server" is understood to be a server that centrally records and monitors system data, and typically records alarms and measured values from the control system of a technical installation, and makes them available to users. The operator server typically establishes a communication connection with the automation system of the technical installation (e.g., automated devices) and forwards the data from the technical installation to so-called "operator clients," which are used to operate and monitor the operation of the individual functional elements of the technical installation.
[0018] An operator station server can have client functionality to access data (archives, messages, tags, variables) from other operator station servers. This allows the operational image of the technical facilities on this operator station server to be combined with the variables of other operator station servers (server-to-server communication). An operator station server can be, but is not limited to, a Siemens SIMATIC PCS 7 Industrial Workstation Server.
[0019] An operator is understood to be a human operator of a technical installation. The operator interacts with the technical installation or its control system using a specific user interface and controls specific technical functions of the installation. To this end, the operator can use the control system's operating and monitoring system, along with an operator station server and, if available, an operator station client.
[0020] In the case of a processing facility, the data from the technical facility can be process data (e.g., pressure, temperature, or fill level values), but can also be messages, for example. The data can represent raw data from sensors. However, the data can also be processed by measuring transducers, peripheral devices, automation systems, or other devices designed for this purpose.
[0021] The two redundantly designed operator station servers of the control system according to the invention continuously store the received data in corresponding data archives. The data is stored for any specified time period. In this case, the two operator station servers are configured in a particularly advantageous manner to also store the health status of the respective operator station server in the data archive corresponding to the received data. The two operator station servers can determine their own health status ("server health") in a manner known per se. An exemplary disclosure of the transmission of information about the health status of the servers can be found in WO 2014 / 099906 A1. The health status can be expressed, for example, on a scale from 1 (unhealthy) to 6 (healthy).
[0022] In addition to the health status, the following information is stored for each time period: whether the corresponding operator station server has performed the role of master or slave.
[0023] The embodiment according to the invention of the control system or its operator station server allows the data archives of the two operator station servers to be synchronized efficiently in such a way that an optimization is performed with regard to the health status and / or the functionality as a host / server.
[0024] The control system is preferably configured to synchronize the two data archives of the first operator station server and the second operator station server after saving the data, health status, and master / slave functions, such that after synchronization, the data of the operator station server having the best health status during the respective time period is stored in the two data archives for each time period. In other words, for each time period, the data of the operator station server having the highest health status during that time period is selected for merging the data archives.
[0025] This synchronization of two redundantly designed operator system servers enables the merging of data archives in a fine-grained manner, so that data from precisely that time period which provides data of higher quality is stored in both data archives.
[0026] The control system is particularly preferably configured to synchronize the two data archives of the first operator station server and the second operator station server, as explained above, after a master / master scenario occurs within a time period. The term "master / master scenario" here means that the first operator station server and the second operator station server perform the functions of a master for one (or more) time periods. This can occur, for example, if the connection between the two operator station servers (temporarily) fails and the two operator station servers, lacking knowledge of the functions of the respective other operator station server, assume the functions of a master in order to maintain operation of the technical installation.
[0027] The above-mentioned object is also achieved by a method for operating a redundantly designed control system for a technical installation, in particular a processing or production installation, the control system having a first operator station server and a second operator station server, wherein one of the operator station servers is configured to operate as a master and the other of the operator station servers is configured to operate as a slave, and wherein the slave is configured to take over the functions of the master in the event of a master failure, and wherein a first data archive is implemented on the first operator station server and wherein a second data archive is implemented on the second operator station server, and wherein the first operator station server and the second operator station server are configured to receive data of the technical installation and store them in corresponding data archives, and wherein the first operator station server and the second operator station server are each configured to determine a corresponding health status.
[0028] The method comprises the following steps:
[0029] a) continuously receiving data from technical installations and storing the data in corresponding archives, wherein the data are divided into specific time periods,
[0030] b) for each time period, determining a corresponding health status by each of the two operator station servers, and assigning the health status of the corresponding operator station server to the data for each time period,
[0031] c) For each time period, it is stored in the corresponding data archive whether the corresponding operator station server functions as a master or a slave within the time period.
[0032] Preferably, after saving the data, health status and master / slave functions, the two data archives of the first operator station server and the second operator station server are synchronized so that after the synchronization, the data of the operator station server having the best health status in the corresponding time period are stored in the two data archives for each time period.
[0033] Particularly preferably, after a master / master scenario has occurred within a time period, the two data archives of the first operator station server and the second operator station server are synchronized as explained above.
[0034] The above-mentioned object is also achieved by the use of a control system for operating a technical installation, in particular a production or processing installation. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The above-mentioned characteristics, features and advantages of the present invention and the manner and method of achieving them will become more clear and apparent with reference to the following description of the embodiments, which are explained in more detail with reference to the accompanying drawings. The accompanying drawings show:
[0036] Figure 1 Showing the configuration in the prior art;
[0037] Figure 2 showing the contents of the data archive of the operator station server according to the first aspect;
[0038] Figure 3 showing the contents of the data archive of the operator station server according to the second aspect; and
[0039] Figure 4 A schematic diagram of the principle of a control system according to the present invention is shown. DETAILED DESCRIPTION
[0040] Figure 2 The contents of a first data archive 10 of a first operator system server OS1 and a second data archive 11 of a second operator system server OS1' are shown. The two operator system servers OS1, OS1' are part of a control system for a technical installation and are designed for redundant operation.
[0041] The contents of the two data archives 10 and 11 before the synchronization of the two data archives 10 and 11 are displayed in Figure 2 The first row of data archives 10, 11 indicates whether the associated operator system server OS1, OS1' functioned as a master (M) or a slave (S) during the relevant time periods t1, t2, t3, t4. The health status of the respective operator system server OS1, OS1' is shown in the second row. A value of 5 indicates a "healthy" or "very good" health status, while a value of 1 indicates an "unhealthy" or "very poor" health status.
[0042] The third row indicates which operator system server OS1, OS1' the values stored in the respective data archive 10, 11 originate from. This depends on whether the operator system server OS1, OS1' functions as a master or a slave. For the data archive 10 of the first operator system server OS1, all data (e.g., process data) originate, for example, from the first operator system server OS1 itself (identified by "A1"), since it functions as the master in all four time periods.
[0043] The second operator system server OS1′ functions as a slave during the first time period t1 and the third time period t3, which is why it stores the data of the first operator system server 10 in its data archive 11. During the second time period t2 and the third time period t3, it functions as a master, which is why it stores its own data in the second data archive 11 (indicated by "A1'"). It can be seen that both operator system servers OS1 and OS1′ function as masters, for example, due to a network failure during the second time period t2 and the third time period t3. This is known as a master / master scenario. After the network failure is resolved, the two operator system servers OS1 and OS1′ must be synchronized again to resume redundant operation.
[0044] It is known that when the two operator station servers OS1, OS1' are reunited or synchronized (in Figure 2 (shown on the right side of the arrow in the example), when comparing data archives 10, 11, only the values belonging to the operator system server OS1, OS1' that became the master after re-federation are (completely) taken over (see the corresponding third row). In this example, this is the first operator system server OS1. It can be seen that, although the first operator system server OS1 had a very poor health status (value 1) during time period t3, in both data archives 10, 11, the values of the first operator system server OS1, OS1' were taken over during the third time period t3. Therefore, the taken-over data may be of poor quality. The higher-quality data from the second operator system server OS1' is discarded.
[0045] exist Figure 3 In FIG. 1 , two data archives 10 , 11 of operator station servers OS1 , OS1 ′ are shown, which are part of the control system according to the invention. Figure 2 In contrast to the known method explained in Figure 3 The diagram in shows that, when synchronizing the operator station servers OS1, OS1', the respective health status (second row) and the function as a master or slave (third row) are taken into account.
[0046] The superimposed master function master / master in the second time period t2 triggers the synchronization of the two data archives 10, 11. In a third time period t3, in which the first operator system server OS1 has a very poor health status, the (process) values (denoted by A1') for the two data archives 10, 11 are taken over during the synchronization, which the healthy second operator system server OS1' receives in time period t3.
[0047] By configuring the control system in this manner or by the described method for operating a technical installation, it is possible to effectively avoid the loss of values of higher quality.
[0048] exist Figure 4 1 and 2. A part of a control system 12 designed as a processing facility, ie, as a process technology facility, is shown in FIG. The control system 12 comprises a first operator station server 13, a second operator station server (not shown) and an operator station client 14.
[0049] The first operator station server 13 , the second operator station server and the operator station client 14 are connected to one another via a terminal bus 15 , and optionally to other components (not shown) of the control system 12 , such as an engineering station server.
[0050] For operating and monitoring purposes, a user or operator can access the operator station server 13 via an operator station client 14 by means of a terminal bus 15. The terminal bus 15 can be designed as an Industrial Ethernet, for example, but is not limited thereto.
[0051] The two operator station servers 13, 14 are identically constructed, which is why Figure 4 The structure of only the first operator station server 13 (hereinafter referred to as "operator station server 13") is shown in FIG. The operator station server 13 has a device interface 16 connected to a facility bus 17. The operator station server 13 can communicate with automation devices 18 and optionally other components of the processing facility, such as peripheral devices (not shown), via the device interface 16. The facility bus 17 can be designed, for example, as Industrial Ethernet, but is not limited thereto. The automation devices 18 can be connected to any number of subsystems (not shown).
[0052] Among other things, redundancy services 19, process images 20, and data archives 21 are implemented on the operator station server 13. The operator station client 14 is provided for displaying a system image for operating and monitoring the processing system, but will not be discussed further here.
[0053] The automation device 18 is provided for controlling and monitoring the automation of the processing plant. To this end, a control program is implemented on the automation device 18, which was loaded onto the automation device 18 as part of planning the automation of the processing plant. The automation device 18 receives process data from the processing plant and transmits this data to the process image 20 of the operator station server 13.
[0054] The redundancy service 19 determines the health status (health index) of the operator control servers 13 in a manner known per se, stores it in the process image 20 of the operator control servers 13, and archives it in the data archive 21. Thus, when the data archives 21 are merged / synchronized, a health status is available after the master / master scenario of the two redundantly configured operator control servers 13 has concluded. Furthermore, the functions executed by the operator control servers 13 within a specific time period are stored as "server status" (master / slave) in the process image 20 and archived in the data archive 21, so that the time period for the master / master scenario (OS1=M, OS1′=M) can be precisely determined.
[0055] According to the health status and function of each operator station server 13, Figure 3 The method explained performs a merge service in the data archives 21 of the two operator station servers 13. After comparing the data archives 21, as Figure 3 As shown, the contents of the two data archives 21 are once again identical. From this point on, the data of the two data archives 21 can be transferred to a central archive (not shown) of the control system 12 in order to perform long-term archiving of the data. If the contents of the (local) data archives 21 are to be transferred to the central archive, they can also be discarded after the comparison of the (local) data archives 21.
[0056] Overall, the control system 12 according to the invention and the resulting method allow a fine-grained comparison of the data archive 21 with the best possible process data. The invention can contribute to a higher reliability and improved operability of the control system of a technical installation.
Claims
1. A control system (12) for a technical installation, comprising a first operator station server (13) and a second operator station server, wherein: One of the operator station servers (13) is configured to operate as a master, and another of the operator station servers (13) is configured to operate as a slave, wherein the slave is configured to take over the functions of the master in the event of a failure of the master, and wherein a first data archive (21) is implemented on the first operator station server (13), and wherein a second data archive is implemented on the second operator station server, and wherein the first operator station server (13) and the second operator station server are configured to receive and store data of the technical installation in corresponding data archives (21), And wherein the first operator station server (13) and the second operator station server are respectively configured to obtain corresponding health states, It is characterized by: The first operator station server (13) and the second operator station server are configured to continuously store in the corresponding data archive (21) during specific time periods (t1, t2, t3, t4, t5, t6): what health status the corresponding operator station server (13) had when receiving and storing the data of the technical installation, and whether the corresponding operator station server (13) acted as a master or a slave during the corresponding time period (t1, t2, t3, t4, t5, t6).
2. The control system (12) according to claim 1, wherein: The technical facilities are processing or production facilities.
3. The control system (12) according to claim 1, wherein: The control system (12) is configured to synchronize the two data archives (21) of the first operator station server (13) and the second operator station server after saving the data, the health status and the master / slave function, so that after the synchronization, the data of the operator station server (13) are stored in the two data archives (21) for each time period, and the operator station server has an optimal health status in the corresponding time period (t1, t2, t3, t4, t5, t6).
4. The control system (12) according to claim 3, wherein: The control system (12) is configured to synchronize the two data archives (21) of the first operator station server (13) and the second operator station server according to claim 3 after a master / master scenario occurs within a time period (t1, t2, t3, t4, t5, t6).
5. A method for operating a control system (12) which is designed redundantly for a technical installation, the control system having a first operator station server (13) and a second operator station server, wherein: One of the operator station servers (13) is configured to operate as a master, and another of the operator station servers (13) is configured to operate as a slave, wherein the slave is configured to take over the functions of the master in the event of a failure of the master, and wherein a first data archive (21) is implemented on the first operator station server (13), and wherein a second data archive is implemented on the second operator station server, and wherein the first operator station server (13) and the second operator station server are configured to receive and store data of the technical installation in corresponding data archives (21), And wherein the first operator station server (13) and the second operator station server are respectively configured to obtain corresponding health states, The method comprises: a) continuously receiving data from the technical installation and storing the data in a corresponding data archive (21), wherein the data are divided into specific time periods (t1, t2, t3, t4, t5, t6), b) for each time period (t1, t2, t3, t4, t5, t6), a respective health status is determined by each of the two operator station servers (13), and for each time period (t1, t2, t3, t4, t5, t6), the health status of the respective operator station server (13) is assigned to the data, c) For each time period (t1, t2, t3, t4, t5, t6), it is respectively stored in the corresponding data archive (21): whether the corresponding operator station server (13) acts as a master or a slave in the time period.
6. The method according to claim 5, wherein: The technical facilities are processing or production facilities.
7. The method according to claim 5, wherein: After saving the data, the health status and the master / slave functions, the data archives (21) of the first operator station server (13) and the second operator station server are synchronized so that after the synchronization, the data of the operator station server (13) are stored in the two data archives (21) for each time period (t1, t2, t3, t4, t5, t6), and the operator station server has the best health status in the corresponding time period (t1, t2, t3, t4, t5, t6).
8. The method according to claim 7, wherein: After a master / master scenario occurs within a time period (t1, t2, t3, t4, t5, t6), the data archives (21) of the first operator system server (13) and the second operator system server are synchronized according to claim 7.
9. A method for using a control system (12) according to any one of claims 1 to 4 for operating a technical installation.
Citation Information
Patent Citations
Dependencies between process objects
EP3736647A1
Exchange of server status and client information through headers for request management and load balancing
WO2014099906A1
Shared-use data processing for process control systems
CN1561472A
Image activation on an operator station client
EP3637205A1