Method for processing controller state, related device and computer readable medium
By detecting the communication status of redundant channels and the fault time interval, the causes of channel disconnection and controller power failure can be distinguished, thus solving the state switching error caused by communication failure in the automated control system and ensuring the normal operation of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SUPCON TECH CO LTD
- Filing Date
- 2022-12-23
- Publication Date
- 2026-05-29
AI Technical Summary
In automated control systems, when a single redundant channel is disconnected, causing a communication failure between controllers, the controllers operating normally cannot determine the cause of the failure, leading to incorrect state switching and causing system malfunctions.
By detecting the communication status of the first redundant channel and the second redundant channel, it can be determined whether the communication failure time interval exceeds the threshold, distinguish whether the fault is caused by a channel disconnection or a power failure of the controller, and then correctly handle the controller status.
This ensures that only one controller remains operational in the event of a communication failure in the automated control system, maintaining normal system operation and preventing system failures caused by incorrect state switching.
Smart Images

Figure CN115903450B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automation control technology, and in particular to a method for processing controller states, related equipment, and a computer-readable medium. Background Technology
[0002] In the current field of automation control technology, to improve the safety and stability of automation control systems, controllers are typically redundant between racks. Specifically, one existing method of controller redundancy between racks involves placing two controllers in different control rooms, with the two controllers communicating via a single redundant channel. This ensures that if the entire rack containing one controller experiences a power outage, causing a communication failure between the controllers, the other controller can still be set to an active state to maintain the normal operation of the automation control system.
[0003] However, in the current field of automation control technology, there are still situations where communication failures between controllers occur due to the disconnection of a single redundant channel. When a single redundant channel disconnects, the controller operating normally cannot determine whether the communication failure is caused by the disconnection of the single redundant channel or by a power outage of another controller. This can lead to errors in the subsequent state settings of the controller, causing malfunctions in the automation control system. For example, when a single redundant channel disconnects, the standby controller, upon detecting the communication failure, may treat it as a power outage of another controller and switch itself from standby to operating mode. Consequently, after the single redundant channel resumes communication, two controllers appear in the system in an operating state, preventing the automation control system from functioning properly. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a method for processing controller status, related equipment, and a computer-readable medium, which detects the cause of communication failure between two controllers by using the time interval between a first communication failure time and a second communication failure time, so as to ensure the normal operation of the automated control system.
[0005] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:
[0006] In a first aspect, this application discloses a method for processing controller states, applied to a controller, wherein the controller and another controller are connected via a first redundant channel and a second redundant channel, and the states of the controller and the other controller are different; the state of the controller is either a working state or a standby state; the method for processing the controller states includes:
[0007] The communication status of the first redundant channel and the second redundant channel is detected; wherein the communication status is either a communication failure status or a communication normal status.
[0008] If both the first redundant channel and the second redundant channel are detected to be in a communication failure state, then it is determined whether the time interval between the first communication failure time and the second communication failure time is greater than a time interval threshold; wherein, the first communication failure time is the time when the first redundant channel is detected to be in a communication failure state; and the second communication failure time is the time when the second redundant channel is detected to be in a communication failure state.
[0009] If it is determined that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold, then the controller itself is controlled to be in the working state.
[0010] If it is determined that the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold, then the controller itself remains unchanged.
[0011] Optionally, in the above-described controller state processing method, after detecting the communication state of the first redundant channel and the second redundant channel, the method further includes:
[0012] If it is detected that at least one of the redundant channels is in a normal communication state between the first redundant channel and the second redundant channel, the controller itself remains unchanged.
[0013] Optionally, in the above-described controller state processing method, detecting the communication state of the first redundant channel and the second redundant channel includes:
[0014] According to the heartbeat packet transmission cycle, heartbeat packets are sent to the other controller through the first redundant channel and the second redundant channel, respectively.
[0015] The system receives heartbeat packets sent by the other controller through the first redundant channel and through the second redundant channel.
[0016] If a heartbeat packet sent by the other controller is not received through the first redundant channel for a preset time period, the communication status of the first redundant channel is determined to be a communication failure state.
[0017] If a heartbeat packet sent by the other controller is detected to be received through the first redundant channel within a preset time period, the communication status of the first redundant channel is determined to be a normal communication status.
[0018] If a heartbeat packet sent by the other controller is not received through the second redundant channel for a preset time period, the communication status of the second redundant channel is determined to be a communication failure state.
[0019] If a heartbeat packet sent by the other controller is detected to be received through the second redundant channel within a preset time period, the communication status of the second redundant channel is determined to be a normal communication status.
[0020] After determining that the communication status of the first redundant channel is a communication failure state, the method further includes:
[0021] The time when the communication status of the first redundant channel is determined to be in a communication failure state is recorded as the first communication failure time.
[0022] After determining that the communication status of the second redundant channel is a communication failure state, the method further includes:
[0023] The time when the communication status of the second redundant channel is determined to be in a communication failure state is recorded as the second communication failure time.
[0024] Optionally, in the above method for handling controller states, if the current state of the controller is a working state, the method for handling controller states further includes:
[0025] If a fault is detected in the controller itself, it is determined whether the controller itself needs to stop working based on the fault level of the detected fault.
[0026] If it is determined that the controller itself needs to stop working, a switching message is sent to the other controller, and the controller itself stops working; wherein, the switching message is used to notify the other controller to switch to working state.
[0027] Optionally, in the above-described method for processing the controller state, after sending heartbeat packets to the other controller via the first redundant channel and the second redundant channel according to the heartbeat packet sending cycle, the method further includes:
[0028] When the heartbeat packet transmission period arrives, it is determined whether a heartbeat packet sent by the other controller has been received through the first redundant channel, and whether a heartbeat packet sent by the other controller has been received through the second redundant channel;
[0029] If it is determined that a heartbeat packet sent by the other controller is received through the first redundant channel, the first redundancy timeout duration is cleared to zero; wherein, the first redundancy timeout duration is the duration during which a heartbeat packet sent by the other controller is not received through the first redundant channel;
[0030] If it is determined that a heartbeat packet sent by the other controller has not been received through the first redundant channel, the currently recorded first redundancy timeout duration is increased by the value of the heartbeat packet sending cycle.
[0031] If it is determined that a heartbeat packet sent by the other controller is received through the second redundant channel, the second redundancy timeout duration is cleared to zero; wherein, the second redundancy timeout duration is the duration during which a heartbeat packet sent by the other controller is not received through the second redundant channel;
[0032] If it is determined that a heartbeat packet sent by the other controller has not been received through the second redundancy channel, the currently recorded second redundancy timeout duration is increased by the value of the heartbeat packet sending cycle.
[0033] Secondly, this application discloses a controller state processing device applied to a controller, wherein the controller and another controller are connected via a first redundant channel and a second redundant channel, and the states of the controller and the other controller are different; the state of the controller is either an operating state or a standby state; the controller state processing device includes:
[0034] A detection unit is used to detect the communication status of the first redundant channel and the second redundant channel; wherein the communication status is a communication failure status or a communication normal status;
[0035] The first judgment unit is configured to determine whether the time interval between the first communication failure time and the second communication failure time is greater than a time interval threshold if both the communication status of the first redundant channel and the second redundant channel are detected to be in a communication failure state; wherein, the first communication failure time is the time when the first redundant channel is detected to be in a communication failure state; and the second communication failure time is the time when the second redundant channel is detected to be in a communication failure state.
[0036] The control unit is configured to control the controller itself to a working state if it is determined that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold.
[0037] The first maintenance unit is configured to maintain the controller's own state unchanged if it is determined that the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold.
[0038] Optionally, the above-mentioned controller state processing device further includes:
[0039] The second maintenance unit is used to maintain the state of the controller itself unchanged if it is detected that at least one of the redundant channels is in a normal communication state.
[0040] Thirdly, this application discloses a controller state processing system, comprising:
[0041] Two controllers, each of which is configured to perform the method as described in any of the first aspects above;
[0042] A first redundant channel, which is connected to the two controllers respectively, is used to establish a communication connection between the two controllers.
[0043] A second redundant channel, connected to each of the two controllers, is used to establish a communication connection between the two controllers.
[0044] Fourthly, this application discloses a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the first aspects above.
[0045] Fifthly, this application discloses a controller state processing device, comprising:
[0046] One or more processors;
[0047] A storage device on which one or more programs are stored;
[0048] When the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the method as described in any of the first aspects above.
[0049] Based on the controller state processing method provided in the above embodiments of the present invention, the method is applied to a controller that communicates with another controller through a first redundant channel and a second redundant channel. By detecting the communication state of the first redundant channel and the second redundant channel, when both the first redundant channel and the second redundant channel are detected to be in a communication failure state, it is determined whether the time interval between the first communication failure time and the second communication failure time is greater than a time interval threshold. If it is determined that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold, it indicates that the failure is caused by a power outage of the other controller, and therefore the controller itself is set to a working state. If it is determined that the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold, it indicates that the communication failure is caused by the disconnection of both redundant channels, and therefore the controller maintains its own state unchanged. Since in this embodiment, the controller can determine whether the communication failure is caused by the disconnection of the redundant channel or by a power outage of the other controller by the time interval between the first communication failure time and the second communication failure time, the controller can subsequently process its own state correctly, ensuring the normal operation of the automated control system. Attached Figure Description
[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0051] Figure 1 This is a schematic diagram of the structure of a controller state processing system proposed in an embodiment of this application;
[0052] Figure 2 This is a schematic diagram of the structure of another controller state processing system proposed in an embodiment of this application;
[0053] Figure 3 This is a flowchart illustrating a controller state processing method proposed in an embodiment of this application;
[0054] Figure 4 This is a flowchart illustrating a method for detecting the communication status of a redundant channel according to an embodiment of this application.
[0055] Figure 5 This is a flowchart illustrating a method for recording the duration of a heartbeat packet not being received, as proposed in an embodiment of this application.
[0056] Figure 6This is a flowchart illustrating another method for processing controller states proposed in an embodiment of this application;
[0057] Figure 7 This is a schematic diagram of the structure of a controller state processing device proposed in an embodiment of this application. Detailed Implementation
[0058] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0059] In this application, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0060] See Figure 1 This application proposes a controller state processing system 100, including: a controller 101, a controller 102, a first redundant channel 103, and a second redundant channel 104. The first redundant channel 103 is connected to both controller 101 and controller 102, and the second redundant channel 104 is also connected to both controller 101 and controller 102. The states of controller 101 and controller 102 are different; the controller is in either a working state or a standby state. A controller in the working state controls modules within the automation control system to achieve specific functions. A controller in the standby state does not control modules within the automation control system and is in a standby ready state. The controller state processing system 100 can be understood as a system included within the automation control system.
[0061] Specifically, the controller state processing process within the controller state processing system 100 is as follows: both controller 101 and controller 102 detect the communication status of the first redundant channel 103 and the second redundant channel 104. The communication status is either a communication failure state or a normal communication state. If both controller 101 and controller 102 detect a communication failure state for both the first redundant channel 103 and the second redundant channel 104, they determine whether the time interval between the first and second communication failure times is greater than a time interval threshold.
[0062] If controller 101 determines that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold, it indicates that controller 102 is powered off at this time, and therefore controller 101 controls itself to the working state. Similarly, if controller 102 determines that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold, it indicates that controller 101 is powered off at this time, and therefore controller 102 controls itself to the working state.
[0063] If controller 101 determines that the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold, it indicates that both the first redundant channel 103 and the second redundant channel 104 are disconnected, and therefore controller 101 maintains its own state unchanged. Similarly, if controller 102 determines that the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold, it maintains its own state unchanged.
[0064] The first communication failure time is the time when the first redundant channel 103 is detected to be in a communication failure state, and the second communication failure time is the time when the second redundant channel 104 is detected to be in a communication failure state.
[0065] It should be noted that when controllers 101 and 102 are in a power-off state, they cannot execute the above-mentioned judgment and detection logic. Through the above processing flow, controllers 101 and 102 can ensure that in the entire controller state processing system, no matter what type of communication failure occurs, one of the controllers will be in working state to control the modules in the automation control system in order to maintain the normal operation of the automation control system.
[0066] For example, in one specific embodiment of this application, the controller state processing system 100 further includes a first rack, a second rack, a first attached module, and a second attached module. The first rack is used to fix the controller 101 and the first attached module, and the second rack is used to fix the controller 102 and the second attached module. The first attached module is used to execute corresponding functions under the control of the controller 101. The second attached module is used to execute corresponding functions under the control of the controller 102.
[0067] For example, such as Figure 2 The diagram illustrates a real-world scenario of the controller status processing system. The engineer station, operator station, and two controllers are all connected to the control network. The two controllers are connected via redundant channels A and B. Redundant channel A (equivalent to the aforementioned first redundant channel) and redundant channel B (equivalent to the aforementioned second redundant channel) can be communication channels formed by fiber optic cables, network cables, etc. Rack 0 and rack 1 each house a power supply, controller, and downstream module. The engineer station and operator station can issue control commands to the two controllers via the control network.
[0068] During the controller state processing process within the controller state processing system 100, both controller 101 and controller 102 can determine whether the communication failure is caused by the disconnection of the redundant channel or by the power failure of another controller besides themselves by the time interval between the first communication failure time and the second communication failure time. Consequently, both controller 101 and controller 102 can correctly process their own states, ensuring that only one controller among controller 101 and controller 102 is in a functional transition state, thus maintaining the normal operation of the automated control system.
[0069] For the process of handling the controller state within the controller state handling system 100, please refer to the relevant description of the controller state handling method disclosed in the embodiments of this application below, which will not be repeated here.
[0070] See Figure 3 Based on the controller state processing system proposed in the above embodiments of this application, this application discloses a controller state processing method applied to a controller. This controller can be included in any of the controller state processing systems proposed in the above embodiments of this application (for example, the controller can be controller 101 or controller 102 mentioned above). The controller and another controller are connected via a first redundant channel and a second redundant channel. The controller's state is either a working state or a standby state. Both the controller and the other controller execute... Figure 3 The method shown Figure 3 The method for handling the controller state shown specifically includes the following steps:
[0071] S301. Detect the communication status of the first redundant channel and the second redundant channel, wherein the communication status is either a communication failure status or a communication normal status.
[0072] The communication status of the first and second redundant channels reflects whether normal communication is possible between the two controllers. When at least one of the redundant channels is in a normal communication state, the two controllers can communicate through that channel. When both channels are in a communication failure state, normal communication between the two controllers is impossible. By detecting the communication status of the first and second redundant channels, it is possible to determine whether a communication failure (i.e., inability to communicate normally) exists between the two controllers.
[0073] Specifically, when the communication status of the first redundant channel is in a communication failure state, the controller cannot communicate with another controller through the first redundant channel. When the communication status of the first redundant channel is in a communication normal state, the controller can communicate with another controller through the first redundant channel. Similarly, when the communication status of the second redundant channel is in a communication failure state, the controller cannot communicate with another controller through the second redundant channel. When the communication status of the second redundant channel is in a communication normal state, the controller can communicate with another controller through the second redundant channel.
[0074] Based on the communication status of the first and second redundant channels detected in step S101, if it is determined that the two controllers can communicate normally, no other operations need to be performed. At this time, the two controllers can communicate to ensure that their states are different; one controller is in the active state, and the other is in the standby state. The controller in the active state performs automated control of the modules and equipment in the automation control system. The controller in the standby state is equivalent to being in standby mode. If the controller in the active state malfunctions and can no longer perform automated control of the modules and equipment, the controller in the standby state needs to switch to the active state to maintain the normal operation of the automation control system.
[0075] If, based on the communication status of the first redundant channel and the second redundant channel detected in step S101, it is determined that the two controllers cannot communicate normally, that is, both the first redundant channel and the second redundant channel are detected to be in a communication failure state, then step S302 is executed.
[0076] Optionally, see Figure 4In one specific embodiment of this application, one implementation of step S301 includes:
[0077] S401. According to the heartbeat packet sending cycle, send heartbeat packets to another controller through the first redundant channel and the second redundant channel respectively.
[0078] The controller sends heartbeat packets to another controller via a first redundant channel and a second redundant channel, according to a preset heartbeat packet sending period. The preset heartbeat packet sending period could be, for example, 10ms. Every 10ms, the heartbeat packet sending period arrives, triggering the controller to send a heartbeat packet to the other controller.
[0079] S402, Receive heartbeat packets sent by another controller through the first redundant channel, and receive heartbeat packets sent by another controller through the second redundant channel.
[0080] In this embodiment of the application, another controller is also used to execute the controller state processing method proposed in this embodiment of the application. Therefore, the other controller will also send heartbeat packets to the controller through the first redundant channel and the second redundant channel according to the heartbeat packet sending cycle. Therefore, when the communication status of the first redundant channel is normal, the controller can receive the heartbeat packet sent by the other controller through the first redundant channel. Similarly, when the communication status of the second redundant channel is normal, the controller can receive the heartbeat packet sent by the other controller through the second redundant channel.
[0081] It should be noted that the heartbeat packet sending periods of the two controllers can be the same or different. In some embodiments, when performing step S401 above, the controller may receive a heartbeat packet sent by the other controller and then reply with a heartbeat packet on the corresponding redundant channel. Therefore, under normal communication conditions, the controller can receive heartbeat packets according to the heartbeat packet sending period through the first redundant channel and the second redundant channel respectively, and reply with a heartbeat packet accordingly (i.e., send a heartbeat packet). Alternatively, regardless of whether a heartbeat packet has been received, the controller may send a heartbeat packet to the other controller according to the heartbeat packet sending period through the first redundant channel and the second redundant channel respectively.
[0082] S403. Check if the preset time has elapsed and no heartbeat packet has been received from another controller through the first redundant channel.
[0083] As described above in steps S401 and S402, under normal communication conditions, the controller can receive heartbeat packets sent by the other controller through the first redundant channel according to the heartbeat packet sending cycle of the other controller. However, if there is a communication failure in the first redundant channel, the controller will not receive heartbeat packets sent by the other controller for a long time. Therefore, if it is detected that no heartbeat packets sent by the other controller have been received through the first redundant channel for a period of time (i.e., longer than the preset time), it means that the controller has been unable to receive heartbeat packets sent by the other controller through the first redundant channel for a long time, that is, there is a communication failure in the communication state of the first redundant channel, and step S404 is executed.
[0084] It should be noted that the preset duration is longer than the heartbeat packet transmission period. For example, if another controller's heartbeat packet transmission period is 10ms, then the preset duration can be set to 50ms. That is, if a controller fails to receive a heartbeat packet from the other controller through the first redundant channel for five consecutive heartbeat packet transmission periods, it indicates that there is a communication failure in the first redundant channel.
[0085] Conversely, if a heartbeat packet sent by another controller is detected within a preset time period (i.e., less than or equal to the preset time period) through the first redundant channel, the current communication status of the first redundant channel is considered to be normal, and step S405 is executed.
[0086] It should be noted that step S403 is a repetitive step. For example, step S403 can be executed in real time, or it can be executed periodically according to the heartbeat packet sending cycle.
[0087] S404. The communication status of the first redundant channel is determined to be a communication failure state.
[0088] When step S403 detects that no heartbeat packet has been received from another controller through the first redundant channel for a preset time period, the controller can determine that the current communication status of the first redundant channel is a communication failure state.
[0089] Optionally, in a specific embodiment of this application, after executing step S404, the method further includes: marking (or setting) the communication status of the first redundant channel as a communication failure state. There are many ways to set the communication status of the first redundant channel as a communication failure state, such as by adding a tag indicating that the first redundant channel is in a communication failure state, or by setting the communication status bit of the first redundant channel to a communication failure status bit.
[0090] S405. The communication status of the first redundant channel is determined to be normal.
[0091] If step S403 detects that a heartbeat packet sent by another controller is received through the first redundant channel within a preset time period, then the communication status of the first redundant channel is determined to be a normal communication status.
[0092] Optionally, in a specific embodiment of this application, after executing step S405, the method further includes: marking (or setting) the communication status of the first redundant channel to a normal communication status. There are many ways to set the communication status of the first redundant channel to a normal communication status, such as by adding a tag indicating that the first redundant channel is in a normal communication status, or by setting the communication status bit of the first redundant channel to a normal communication status bit.
[0093] S406. Check if a heartbeat packet sent by another controller has been received through the second redundant channel for a preset time period.
[0094] The execution process and principle of step S406 can be referred to step S403, with the only difference being the different redundant channels, which will not be repeated here. It should be noted that the execution order of steps S403 and S406 is not limited in this embodiment of the application, and they can also be executed in parallel.
[0095] If no heartbeat packet is received from another controller through the second redundant channel for more than a preset time period, proceed to step S407. If a heartbeat packet is received from another controller through the second redundant channel within the preset time period, proceed to step S408.
[0096] S407. The communication status of the second redundant channel is determined to be a communication failure state.
[0097] The execution process and principle of step S407 can be referred to step S404, with the only difference being the different redundant channels, which will not be elaborated here.
[0098] Optionally, in a specific embodiment of this application, after executing step S407, the method further includes: marking (or setting) the communication status of the second redundant channel as a communication failure state. There are many ways to set the communication status of the second redundant channel to a communication failure state, such as by adding a tag indicating that the second redundant channel is in a communication failure state, or by setting the communication status bit of the second redundant channel to a communication failure status bit.
[0099] S408. The communication status of the second redundant channel is determined to be normal.
[0100] The execution process and principle of step S408 can be referred to step S405, with the only difference being the different redundant channels, which will not be elaborated here.
[0101] Optionally, in a specific embodiment of this application, after executing step S408, the method further includes: marking (or setting) the communication status of the second redundant channel to a normal communication status. There are many ways to set the communication status of the second redundant channel to a normal communication status, such as by adding a tag indicating that the second redundant channel is in a normal communication status, or by setting the communication status bit of the second redundant channel to a normal communication status bit.
[0102] Optionally, in a specific embodiment of this application, after performing step S404, the method further includes:
[0103] S409. The time when the communication status of the first redundant channel is determined to be a communication failure state is recorded as the first communication failure time.
[0104] The first communication failure time can be understood as the time when the first redundant channel is detected to be in a communication failure state.
[0105] Optionally, in a specific embodiment of this application, after performing step S408, the method further includes:
[0106] S410. Record the time when the communication status of the second redundant channel is determined to be a communication failure state as the second communication failure time.
[0107] The second communication failure time can be understood as the time when the second redundant channel is detected to be in a communication failure state.
[0108] Optionally, see Figure 5 In a specific embodiment of this application, after executing step S401, it can also be done by... Figure 5 The steps shown record the first redundancy timeout duration and the second redundancy timeout duration. Step S403 can be executed based on the first redundancy timeout duration, and step S406 can be executed based on the second redundancy timeout duration. The first redundancy timeout duration is the duration during which a heartbeat packet from another controller is not received through the first redundancy channel, and the second redundancy timeout duration is the duration during which a heartbeat packet from another controller is not received through the second redundancy channel. Specifically, Figure 5 The illustrated process includes the following steps:
[0109] S501. When the heartbeat packet transmission cycle arrives, determine whether a heartbeat packet sent by another controller has been received through the first redundant channel.
[0110] If it is determined that a heartbeat packet sent by another controller is received through the first redundant channel, then step S503 is executed; if it is determined that a heartbeat packet sent by another controller is not received through the first redundant channel, then step S504 is executed.
[0111] S502. When the heartbeat packet transmission period arrives, determine whether a heartbeat packet sent by another controller has been received through the second redundant channel.
[0112] If it is determined that a heartbeat packet sent by another controller is received through the second redundant channel, then step S505 is executed; if it is determined that a heartbeat packet sent by another controller is not received through the second redundant channel, then step S506 is executed.
[0113] It should be noted that steps S501 and S502 are both triggered when the heartbeat packet sending cycle arrives. Therefore, the execution order of steps S501 and S502 does not affect the implementation of the embodiments of this application, and steps S501 and S502 can also be executed simultaneously.
[0114] S503. Clear the first redundancy timeout duration to zero, where the first redundancy timeout duration is the duration during which a heartbeat packet sent by another controller is not received through the first redundancy channel.
[0115] Since a heartbeat packet has already been received through the first redundant channel within the current heartbeat packet transmission cycle, the duration during which a heartbeat packet from another controller is not received through the first redundant channel needs to be updated to 0. Subsequently, when executing step S403, it can be detected whether the first redundancy timeout duration exceeds a preset duration. Since the first redundancy timeout duration has been cleared, step S403 will detect that the first redundancy timeout duration does not exceed the preset duration, meaning it detects that a heartbeat packet from another controller was received through the first redundant channel within the preset duration.
[0116] S504. Increase the first redundancy timeout duration of the current record by the value of the heartbeat packet sending cycle.
[0117] Since no heartbeat packet was received through the first redundancy channel during the current heartbeat packet transmission cycle, the duration for which a heartbeat packet from another controller was not received through the first redundancy channel needs to be updated. The first redundancy timeout duration is increased by the value of one heartbeat packet transmission cycle. For example, if the value of the first redundancy timeout duration recorded in the previous heartbeat packet transmission cycle was 10ms, and no heartbeat packet was received through the first redundancy channel when the current heartbeat packet transmission cycle arrives, then the value of the first redundancy timeout duration is updated to 20ms.
[0118] When performing step S403, it can be detected whether the first redundancy timeout duration exceeds the preset duration. Since the first redundancy timeout duration has increased, step S403 may detect that the first redundancy timeout duration exceeds the preset duration, that is, it may detect that the heartbeat packet sent by another controller has not been received through the first redundancy channel for more than the preset duration, or it may detect that the first redundancy timeout duration has not exceeded the preset duration.
[0119] S505. Clear the second redundancy timeout duration to zero, where the second redundancy timeout duration is the duration during which a heartbeat packet sent by another controller is not received through the second redundancy channel.
[0120] The execution process and principle of step S505 can be referred to step S503, the difference being the different redundant channels, which will not be repeated here.
[0121] S506. Increase the current recorded second redundancy timeout duration by the value of the heartbeat packet sending cycle.
[0122] The execution process and principle of step S506 can be referred to step S504, the difference being the different redundant channels, which will not be elaborated here.
[0123] S302. If it is detected that the communication status of both the first redundant channel and the second redundant channel is in a communication failure state, then determine whether the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold, wherein the first communication failure time is the time when the first redundant channel is detected to be in a communication failure state, and the second communication failure time is the time when the second redundant channel is detected to be in a communication failure state.
[0124] Specifically, step S301 obtains the current communication status of the first and second redundant channels. The controller can then determine whether both the first and second redundant channels are in a communication failure state based on the detected communication status. If both are determined to be in a communication failure state, it indicates that the two controllers cannot communicate normally, and the controller cannot determine through the redundant channels whether the other controller still exists (i.e., whether it is powered off). Therefore, it is necessary to further determine whether the time interval between the first and second communication failure times is greater than a time interval threshold to determine the cause of the current communication failure between the two controllers.
[0125] When the time interval between the first and second communication failure times is determined to be greater than the time interval threshold, it indicates that the first and second redundant channels did not fail simultaneously. This suggests that the first and second redundant channels were disconnected due to external forces causing them to break sequentially, or that maintenance personnel mistakenly disconnected a normal redundant channel during maintenance when one of the redundant channels was malfunctioning. However, neither controller actually experienced a problem and continued to operate normally. Therefore, step S304 needs to be executed to maintain the normal operation of the automated control system.
[0126] When the time interval between the first and second communication failure times is determined to be less than or equal to the time interval threshold, it indicates that the first and second redundant channels experienced communication failures almost simultaneously. The only possible reasons for this simultaneous failure are either a power outage caused by an abnormality in another controller, or the power supply to another controller being disconnected, causing a break in connection with the redundant channels. In summary, when the time interval between the first and second communication failure times is determined to be less than the time interval threshold, it indicates that the current communication failure is caused by the disconnection of another controller. Therefore, step S303 needs to be executed to maintain the stability of the automated control system.
[0127] It should be noted that the method of setting the time interval threshold is not limited in this application embodiment. For example, it can be set based on multiple tests.
[0128] Optionally, in a specific embodiment of this application, after performing step S301, the method further includes:
[0129] If it is detected that at least one of the redundant channels is in a normal communication state between the first and second redundant channels, the controller's own state remains unchanged.
[0130] If at least one of the redundant channels is detected to be in a normal communication state, it indicates that either both redundant channels are in a normal communication state, or one redundant channel is in a normal communication state while the other is in a communication failure state. As long as at least one of the redundant channels is in a normal communication state, it means that the two controllers can currently communicate normally using the redundant channel in a normal communication state. Therefore, communication between the two controllers is normal, and there is no need to change the controller's own state; simply maintain its original state. For example, if one controller was originally in an active state and the other was in a standby state, and normal communication between the two controllers has been confirmed, both controllers can continue to maintain their original states.
[0131] Optionally, in a specific embodiment of this application, the method further includes: if both the communication states of the first redundant channel and the second redundant channel are detected to be in a communication failure state, then marking (or setting) the current redundant communication failure (i.e., the two controllers cannot communicate normally). If it is determined that the time interval between the first communication failure time and the second communication failure time is greater than a time interval threshold, then marking (or setting) the existence of the other controller (i.e., the other controller is not powered off). If it is determined that the time interval between the first communication failure time and the second communication failure time is less than or equal to the time interval threshold, then marking (or setting) the non-existence of the other controller (i.e., the other controller has been disconnected).
[0132] Optionally, in a specific embodiment of this application, it further includes: if it is detected that there is a redundant channel in a normal communication state among the communication states of the first redundant channel and the second redundant channel (i.e., both redundant channels are in a normal state, or one of the redundant channels is in a normal communication state), then mark (or set) the current redundant communication to be normal (i.e., the two controllers can communicate normally), and mark (or set) the existence of another controller.
[0133] By setting (or marking) the above operations, the detection results of the current communication between the two controllers, as well as the detection results of whether the other controller still exists, can be recorded, which makes it easier to trigger the corresponding subsequent processing measures through the setting operations.
[0134] The embodiments of this application do not limit the methods of setting the current redundant communication failure, setting the current redundant communication failure, setting the existence of another controller, and setting the non-existence of another controller.
[0135] In this embodiment, the controller can determine whether the current communication failure between the two controllers is caused by the disconnection of the redundant channel or by the power failure of the other controller by the time interval between the first communication failure time and the second communication failure time. Therefore, the controller can correctly handle its own state and ensure the normal operation of the automated control system.
[0136] S303, The controller itself is in the working state.
[0137] Since the time interval between the first and second communication failure times is less than or equal to the time interval threshold, it indicates that the current communication failure between the two controllers is caused by the disconnection of another controller. Therefore, the controller needs to maintain its working state to ensure the normal operation of the automated control system. Specifically, if the controller was already in a working state, it does not need to perform the operation of setting itself to a working state; it only needs to maintain its original state. If the controller was originally in a standby state, it needs to switch its state to a working state, that is, reset the controller's own state.
[0138] S304, Maintain the controller's own state unchanged.
[0139] Since the time interval between the first and second communication failure times is greater than the time interval threshold, it indicates that the current communication failure between the two controllers is caused by the disconnection of both redundant channels. Therefore, it is only necessary to maintain the controller's own state unchanged. Thus, after the two redundant channels are repaired, only one controller will still be in working state, while the other controller will be in standby state. The automatic control system will not fail to operate normally due to the controller arbitrarily switching states.
[0140] Compared to existing technologies that fail to identify the cause of communication failure between two controllers, leading to errors when the controller switches its own state, this application embodiment can accurately determine whether the communication failure is caused by the disconnection of the redundant channel or by the power failure of another controller by using the time interval between the first and second communication failure times. This allows the controller to correctly set its own state, ensuring that only one controller is in working state between the two controllers, thereby controlling the automated control system and ensuring that the automated control system can execute control logic normally.
[0141] Optionally, see Figure 6 In a specific embodiment of this application, if the current state of the controller is a working state, the controller state processing method further includes the following steps:
[0142] S601. Check if the controller itself is faulty.
[0143] The controller performs a self-check to see if there are any faults. A fault could be an indicator light not illuminating, or certain functions failing to execute. If a fault is detected, step S602 is executed to determine whether the controller needs to be shut down, i.e., to stop controlling the modules in the automated control system.
[0144] S602. Determine whether the controller itself needs to stop working based on the fault level of the detected fault.
[0145] A pre-defined correspondence between various fault types and fault levels is established. This correspondence determines the fault level of the fault detected in step S601. Then, based on the fault level, it is determined whether the controller itself needs to cease operation.
[0146] Specifically, the fault level reflects the severity of the damage caused by the fault. The greater the severity reflected by the fault level, the more necessary it is for the controller to stop its operation.
[0147] For example, one implementation of step S602 includes: determining whether the fault level of the detected fault is greater than a fault level threshold; if it is greater than the fault level threshold, then determining that the controller itself needs to stop working; if it is less than or equal to the fault level threshold, then determining that the controller itself does not need to stop working. The higher the fault level, the greater the degree of harm reflected by the fault level.
[0148] It should be noted that there are many specific ways to determine whether the controller needs to stop working based on the fault level of the detected fault, including but not limited to the content proposed in the embodiments of this application.
[0149] When step S602 determines that the controller itself needs to stop working, step S603 is executed. When step S602 determines that the controller itself does not need to stop working, no operation is performed, that is, the controller maintains its original working state without making any changes.
[0150] S603. Send a switching message to another controller and stop the controller's own working state. The switching message is used to notify the other controller to switch to the working state.
[0151] After receiving the switching information, the other controller can first check whether it meets the conditions for being in the working state. If it detects that it meets the conditions for being in the working state, it means that the other controller can switch to the working state. Therefore, the other controller switches its own state from the standby state to its own state. At this time, the controller also stops its own working state, and the automation control system is controlled and operated by the other controller.
[0152] There are many ways for the controller to stop its own operation, such as switching to standby mode or shutting down the power.
[0153] pass Figure 6The steps shown can maintain the normal operation of the automated control system by stopping the controller itself and switching another controller to work when the controller experiences a serious fault, thereby improving the reliability and safety of the automated control system.
[0154] Refer to Table 1, when Figure 1 When both controllers in the system shown execute the controller state processing method proposed in the embodiments of this application, the normal operation of the automated control system can be maintained through the controller state processing method proposed in the embodiments of this application under several abnormal conditions shown in Table 1.
[0155] Specifically, the working controller mentioned in Table 1 below can be understood as a controller in a working state, and the backup controller can be understood as a controller in a backup state. As shown in Table 1 below, when the working controller experiences an abnormal power failure, the backup controller performs redundancy judgment processing by executing the controller state processing method proposed in the embodiments of this application. It detects that the abnormal redundant communication is caused by the simultaneous disconnection of two redundant channels, and switches to the working state to ensure that a single controller is in a working state, maintaining the normal operation of the automation control system on site. Referring to Table 1 again, if the working controller is accidentally unplugged during maintenance, the backup controller can perform redundancy judgment processing by executing the controller state processing method proposed in the embodiments of this application. It detects that the two redundant channels are simultaneously disconnected, switches to the working state, and maintains normal operation on site. There are many other abnormal or maintenance situations, corresponding redundancy judgment processing methods, and processing results applicable to the controller state processing method proposed in the embodiments of this application. For details, please refer to the content shown in Table 1, which will not be repeated here.
[0156] Table 1
[0157]
[0158] The controller state processing method provided in this embodiment of the invention is applied to a controller that communicates with another controller through a first redundant channel and a second redundant channel. By detecting the communication states of the first and second redundant channels, when both channels are detected to be in a communication failure state, the method determines whether the time interval between the first and second communication failure times is greater than a time interval threshold. If the time interval is not greater than the threshold, it indicates that the failure is caused by a power outage in the other controller, and the controller is set to a working state. If the time interval is greater than the threshold, it indicates that the failure is caused by the disconnection of both redundant channels, and the controller maintains its own state unchanged. In this embodiment, the controller can determine whether the communication failure is caused by the disconnection of a redundant channel or by a power outage in the other controller by using the time interval between the first and second communication failure times. Therefore, the controller can correctly process its own state and ensure the normal operation of the automated control system.
[0159] See Figure 7 Based on the controller state processing method proposed in the above embodiments of this application, this application also discloses a controller state processing device, applied to a controller. The controller and another controller are connected via a first redundant channel and a second redundant channel. The states of the controller and the other controller are different. The controller state is either a working state or a standby state. The controller state processing device includes: a detection unit 701, a first judgment unit 702, a control unit 703, and a first maintenance unit 704.
[0160] The detection unit 701 is used to detect the communication status of the first redundant channel and the second redundant channel. The communication status is either a communication failure status or a communication normal status.
[0161] The first judgment unit 702 is used to determine whether the time interval between the first communication failure time and the second communication failure time is greater than a time interval threshold if both the communication status of the first redundant channel and the second redundant channel are detected to be in a communication failure state. The first communication failure time is the time when the first redundant channel is detected to be in a communication failure state. The second communication failure time is the time when the second redundant channel is detected to be in a communication failure state.
[0162] The control unit 703 is configured to control the controller itself to be in a working state if it is determined that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold.
[0163] The first maintenance unit 704 is used to maintain the controller's own state unchanged if it is determined that the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold.
[0164] Optionally, in one specific embodiment of this application, the controller state processing device further includes:
[0165] The second maintenance unit is used to maintain the controller's own state unchanged if it is detected that at least one of the redundant channels is in a normal communication state between the communication states of the first redundant channel and the second redundant channel.
[0166] Optionally, in a specific embodiment of this application, the detection unit 701 includes: a first transmitting subunit, a receiving subunit, a first determining subunit, a second determining subunit, a third determining subunit, and a fourth determining subunit.
[0167] The first transmitting subunit is used to transmit heartbeat packets to another controller through the first redundant channel and the second redundant channel according to the heartbeat packet transmission cycle.
[0168] The receiving subunit is used to receive heartbeat packets sent by another controller through a first redundant channel and through a second redundant channel.
[0169] The first determining subunit is used to determine the communication status of the first redundant channel as a communication failure state if it is detected that no heartbeat packet has been received from another controller through the first redundant channel for a preset time period.
[0170] The second determining subunit is used to determine the communication status of the first redundant channel as normal if it detects that a heartbeat packet sent by another controller is received through the first redundant channel within a preset time period.
[0171] The third determining subunit is used to determine the communication status of the second redundant channel as a communication failure state if it is detected that no heartbeat packet has been received from another controller through the second redundant channel for a preset time period.
[0172] The fourth determining subunit is used to determine the communication status of the second redundant channel as normal if it detects that a heartbeat packet sent by another controller is received through the second redundant channel within a preset time period.
[0173] The controller state processing device further includes a first recording unit and a second recording unit.
[0174] The first recording unit is used to record the time when the communication status of the first redundant channel is determined to be a communication failure state as the first communication failure time.
[0175] The second recording unit is used to record the time when the communication status of the second redundant channel is determined to be a communication failure state as the second communication failure time.
[0176] Optionally, in a specific embodiment of this application, if the current state of the controller is a working state, the controller state processing device further includes: a determining unit, a sending unit, and a stopping unit.
[0177] The determination unit is used to determine whether the controller itself needs to stop working, based on the fault level of the detected fault, if a fault is detected in the controller itself.
[0178] The sending unit is used to send switching information to another controller if it determines that the controller itself needs to stop working. The switching information is used to notify the other controller to switch to the working state.
[0179] The stop unit is used to stop the controller from operating itself.
[0180] Optionally, in one specific embodiment of this application, the controller state processing device further includes:
[0181] The second judgment unit is used to determine whether a heartbeat packet sent by another controller has been received through the first redundant channel and whether a heartbeat packet sent by another controller has been received through the second redundant channel when the heartbeat packet sending period arrives.
[0182] The first clearing unit is used to clear the first redundancy timeout duration to zero if it determines that a heartbeat packet sent by another controller has been received through the first redundancy channel. The first redundancy timeout duration is the duration during which a heartbeat packet sent by another controller has not been received through the first redundancy channel.
[0183] The first incrementing unit is used to increase the currently recorded first redundancy timeout duration by the value of the heartbeat packet transmission period if it is determined that a heartbeat packet sent by another controller has not been received through the first redundancy channel.
[0184] The second clearing unit is used to clear the second redundancy timeout duration to zero if it is determined that a heartbeat packet sent by another controller has been received through the second redundancy channel. The second redundancy timeout duration is the duration during which a heartbeat packet sent by another controller has not been received through the second redundancy channel.
[0185] The second addition unit is used to increase the currently recorded second redundancy timeout duration by the value of the heartbeat packet transmission period if it is determined that a heartbeat packet sent by another controller has not been received through the second redundancy channel.
[0186] The working principle and execution process of each unit and subunit in the controller state processing device of this application embodiment can be found in the controller state processing method proposed in the foregoing embodiment of this application, and will not be repeated here.
[0187] The controller state processing device provided in this embodiment of the invention is applied to a controller that communicates with another controller via a first redundant channel and a second redundant channel. The detection unit 701 in this device detects the communication status of the first and second redundant channels. When both the first and second redundant channels are in a communication failure state, the first judgment unit 702 determines whether the time interval between the first and second communication failure times is greater than a time interval threshold. If the time interval is not greater than the threshold, it indicates that the failure is caused by a power outage in the other controller, and the control unit 703 controls the controller to operate. If the time interval is greater than the threshold, it indicates that the communication failure is caused by the disconnection of both redundant channels, and the first maintenance unit 704 maintains the controller's state unchanged. Since the first judgment unit 702 can determine whether the communication failure is caused by a disconnection of a redundant channel or a power outage in the other controller based on the time interval between the first and second communication failure times, the controller can subsequently process its own state correctly, ensuring the normal operation of the automated control system.
[0188] This application also discloses a computer-readable medium storing a computer program thereon, wherein when the program is executed by a processor, it implements a controller state processing method as described in any of the above embodiments of this application.
[0189] This application also discloses a controller state processing device, including: one or more processors; a storage device storing one or more programs thereon; when the one or more programs are executed by the one or more processors, the controller state processing method as described in any of the above embodiments of this application is performed.
[0190] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and relevant parts can be referred to the descriptions in the method embodiments. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0191] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0192] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for processing controller states, characterized in that, This is applied to a controller, which communicates with another controller via a first redundant channel and a second redundant channel. The states of the controller and the other controller are different; the controller's state is either active or standby; the method for processing the controller's state includes: The communication status of the first redundant channel and the second redundant channel is detected; wherein the communication status is either a communication failure status or a communication normal status. If both the first redundant channel and the second redundant channel are detected to be in a communication failure state, then the first communication failure time and the second communication failure time are obtained, and the time interval between the first communication failure time and the second communication failure time is calculated; and it is determined whether the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold; wherein, the first communication failure time is the time when the first redundant channel is detected to be in a communication failure state; and the second communication failure time is the time when the second redundant channel is detected to be in a communication failure state. If it is determined that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold, then it is determined that the peer controller is faulty, and the controller itself is controlled to be in working state. If the time interval between the first communication failure time and the second communication failure time is determined to be greater than the time interval threshold, then it is determined to be a redundant channel failure, and the controller itself remains unchanged.
2. The method according to claim 1, characterized in that, After detecting the communication status of the first redundant channel and the second redundant channel, the method further includes: If it is detected that at least one of the redundant channels is in a normal communication state between the first redundant channel and the second redundant channel, the controller itself remains unchanged.
3. The method according to claim 1, characterized in that, The detection of the communication status of the first redundant channel and the second redundant channel includes: According to the heartbeat packet transmission cycle, heartbeat packets are sent to the other controller through the first redundant channel and the second redundant channel, respectively. The system receives heartbeat packets sent by the other controller through the first redundant channel and through the second redundant channel. If a heartbeat packet sent by the other controller is not received through the first redundant channel for a preset time period, the communication status of the first redundant channel is determined to be a communication failure state. If a heartbeat packet sent by the other controller is detected to be received through the first redundant channel within a preset time period, the communication status of the first redundant channel is determined to be a normal communication status. If a heartbeat packet sent by the other controller is not received through the second redundant channel for a preset time period, the communication status of the second redundant channel is determined to be a communication failure state. If a heartbeat packet sent by the other controller is detected to be received through the second redundant channel within a preset time period, the communication status of the second redundant channel is determined to be a normal communication status. After determining that the communication status of the first redundant channel is a communication failure state, the method further includes: The time when the communication status of the first redundant channel is determined to be a communication failure state is recorded as the first communication failure time. After determining that the communication status of the second redundant channel is a communication failure state, the method further includes: The time when the communication status of the second redundant channel is determined to be in a communication failure state is recorded as the second communication failure time.
4. The method according to claim 1, characterized in that, If the controller is currently in a working state, the method for processing the controller state further includes: If a fault is detected in the controller itself, it is determined whether the controller itself needs to stop working based on the fault level of the detected fault. If it is determined that the controller itself needs to stop working, a switching message is sent to the other controller, and the controller itself stops working; wherein, the switching message is used to notify the other controller to switch to working state.
5. The method according to claim 3, characterized in that, After sending heartbeat packets to the other controller via the first redundant channel and the second redundant channel according to the heartbeat packet sending cycle, the method further includes: When the heartbeat packet transmission period arrives, it is determined whether a heartbeat packet sent by the other controller has been received through the first redundant channel, and whether a heartbeat packet sent by the other controller has been received through the second redundant channel. If it is determined that a heartbeat packet sent by the other controller is received through the first redundant channel, the first redundancy timeout duration is cleared to zero; wherein, the first redundancy timeout duration is the duration during which a heartbeat packet sent by the other controller is not received through the first redundant channel; If it is determined that a heartbeat packet sent by the other controller has not been received through the first redundant channel, the currently recorded first redundancy timeout duration is increased by the value of the heartbeat packet sending cycle. If it is determined that a heartbeat packet sent by the other controller is received through the second redundant channel, the second redundancy timeout duration is cleared to zero; wherein, the second redundancy timeout duration is the duration during which a heartbeat packet sent by the other controller is not received through the second redundant channel; If it is determined that a heartbeat packet sent by the other controller has not been received through the second redundancy channel, the currently recorded second redundancy timeout duration is increased by the value of the heartbeat packet sending cycle.
6. A controller state processing device, characterized in that, Applied to a controller, the controller and another controller are connected via a first redundant channel and a second redundant channel, and the states of the controller and the other controller are different; the state of the controller is either an operating state or a standby state; the device for processing the controller state includes: A detection unit is used to detect the communication status of the first redundant channel and the second redundant channel; wherein the communication status is a communication failure status or a communication normal status; The first judgment unit is configured to, if it is detected that the communication states of the first redundant channel and the second redundant channel are both in a communication failure state, acquire the first communication failure time and the second communication failure time, calculate the time interval between the first communication failure time and the second communication failure time, and determine whether the time interval between the first communication failure time and the second communication failure time is greater than a time interval threshold; wherein, the first communication failure time is the time when the first redundant channel is detected to be in a communication failure state; and the second communication failure time is the time when the second redundant channel is detected to be in a communication failure state. The control unit is configured to determine that the peer controller is faulty if it is determined that the time interval between the first communication failure time and the second communication failure time is not greater than the time interval threshold, and to control the controller itself to be in working state. The first maintenance unit is configured to determine a redundant channel failure if the time interval between the first communication failure time and the second communication failure time is greater than the time interval threshold, and to maintain the controller's own state unchanged.
7. The apparatus according to claim 6, characterized in that, Also includes: The second maintenance unit is used to maintain the state of the controller itself unchanged if it is detected that at least one of the redundant channels is in a normal communication state.
8. A controller state processing system, characterized in that, include: Two controllers, each of which is configured to perform the method as described in any one of claims 1 to 5; A first redundant channel, which is connected to the two controllers respectively, is used to establish a communication connection between the two controllers. A second redundant channel, connected to each of the two controllers, is used to establish a communication connection between the two controllers.
9. A computer-readable medium, characterized in that, It stores a computer program thereon, wherein the program, when executed by a processor, implements the method as described in any one of claims 1 to 5.
10. A device for processing controller states, characterized in that, include: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the method as described in any one of claims 1 to 5.