Duplex bus for automation control and management systems
By combining the redundant management and message filtering services of the OSI model with the duplex bus and Turbo Ring technology, the data exchange problem of the EN bus during broadcast storms is solved, and the reliability and data transmission integrity of the industrial automation system are improved.
Patent Information
- Application Number
- CN202180053582.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-03-03
- Filing Date
- 2021-12-27
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2041-12-27
AI Technical Summary
The existing EN bus can disrupt data exchange between automation processors when a broadcast storm occurs, and the existing protocol takes too long to reconfigure large networks, making it unable to meet the reliability requirements of industrial-grade automation systems.
It adopts a duplex bus structure and connects two independent EN buses into a virtual ring through Turbo Ring technology. It combines the physical layer, link layer and application layer protocols of the OSI model and introduces redundancy management and message filtering services to ensure normal data transmission even in broadcast storms.
Improves the reliability of the automation system, prevents communication module processor overload and broadcast message delay, ensures the integrity and reliability of data transmission, and reduces network reconfiguration time.
Smart Images

Figure CN116324746B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of automation and computing equipment and can be applied to process automation control and management systems for industrial projects such as nuclear power plants. Background Art
[0002] In the process automation management and control systems of nuclear power plants, the system bus connects up to 800 bus users in terms of information and management, namely the automation machines and instrument computers that are part of the overall safety management system of normal operating hardware and software.
[0003] The EN-type duplex system bus, based on an Industrial Ethernet switched interface and full-duplex point-to-point connections, is widely used in modern nuclear power plant process automation and control systems. Russian Federal Patent No. 2431174, International Patent Classification G05B 19 / 418, October 10, 2011; Russian Federal Patent No. 2430400, International Patent Classification G05B 19 / 418, September 27, 2011.
[0004] EN bus redundancy is achieved by reconfiguring the data transmission medium using Turbo Ring technology. This technology is based on a so-called "virtual ring" consisting of serially connected converters. One converter, designated as a backup management unit, maintains the ring open and controls the integrity of the links between converters in the ring by sending control messages at one end and receiving them at the other. If the integrity of the links in the ring is compromised, the backup management unit restores the integrity of the links by closing the ring at a control point.
[0005] With a ring segment reset time of approximately 20ms when the number of network switches in the ring does not exceed 250 and a minimum number of redundant links for restoring the network working state, this technology has found widespread application in process automation control systems for industrial projects.
[0006] Automation processor-based non-duplex and duplex devices connect to the EN bus via two user links, A and B. Link A connects to one network switch within the same virtual ring, and link B connects to another network switch. If a switch fails, the redundancy management unit resets the bus and switches the automation processor connected to that link to another link, ensuring bus availability.
[0007] Data is transmitted via the EN bus in the form of addresses and broadcast messages, according to the Industrial Ethernet interface link and physical layer standard protocols of the automation processor communication modules that make up the bus and ensure that the automation processor is logically and physically connected to the bus.
[0008] At the EN bus application level, the process and nuclear power plant process automation management and control system detection simulation and discrete information transmission protocol is adopted.
[0009] At the Industrial Ethernet interface link level, address application messages are transmitted under the LLC protocol in Data Transfer Mode 3 (LLC3) according to IEEE 802.2 and IEEE 802.3 standards. LLC messages confirm delivery via a received exchange. If the received exchange fails to accept the message, it is redundantly sent up to n times. The LLC3 protocol uses address message numbering based on mod 2, distinguishing between new and redundant messages upon receipt. Before transmission, the individual number of a new message is incremented by 1 based on mod 2. The numbers of newly transmitted messages remain unchanged.
[0010] Switched Industrial Ethernet offers high-speed data transmission of up to 100 Mbit / s, ensuring both limited data transfer and random bus access. However, Ethernet interfaces also have a significant disadvantage: when a bus segment is closed into a physical ring due to a failure or installation error during commissioning, a dense stream of public messages, known as a "broadcast storm," occurs on the bus. This "broadcast storm" includes not only broadcast messages but also address messages transmitted in broadcast mode when an automation device is unavailable due to a failure or shutdown. Experience with the EN bus has shown that physical rings can form in buses based on Industrial Ethernet using virtual ring technology. This can be caused by a bus failure or, more commonly, installation errors during commissioning. This "broadcast storm" can cause the send and receive buffers of bus users and switches to overfill, disrupting data exchange between users. Furthermore, if their processing capacity is insufficient, it can overload the processing of user communication modules, causing the automation processor to stop performing other functions unrelated to managing data transfer via the EN bus, such as data exchange with process communication modules or disruption of the automation processor's operation on the safety management system bus. Russian Federation Patent No. 2430400, International Patent Classification G05B 19 / 418, 27.09.2011.
[0011] The main drawback of the above solution is that, since the EN bus is established as a universal data transmission medium with relational reconfiguration redundancy, a "broadcast storm" occurring on the bus leads to a disruption of data exchange between the automation processors connected to it.
[0012] Known protocols include STP (Spanning Tree Protocol), IEEE 802.1D, and RSTP (Rapid Spanning Tree Protocol), IEEE 802.1D-2004. These protocols allow for the creation of fail-safe network structures over common data transmission media, ensuring link lockout for broadcast messages and preventing "broadcast storms" through network reconfiguration. However, the relatively long network reconfiguration times of over one minute for STP and over one second for RSTP, when the number of switches in a network is less than seven, prohibit their use in industrial automation systems. A significant drawback of these protocols is the high number of redundant network connections, resulting in significant equipment costs for process automation management and control systems in distributed nuclear power plants across large sites.
[0013] A duplex EN bus in a control and management automation hardware and software architecture is known. The duplex bus consists of two independent, informationally and physically disconnected ENa and ENb bus systems, established using "virtual ring" technology. Each of the non-duplexed automation processors and each of the two redundant automation processors is connected to the network switch of the ENa bus via the same network link and to the network switch of the ENb bus via another link. The redundant automation processors are interconnected via two interfaces that establish hot redundancy management based on the processors' built-in self-control automation functions. Russian Federation Patent No. 2450305, International Patent Classification G05B19 / 00, dated 10 May 2012. This technical solution has been accepted as a prototype.
[0014] The address message is sent by only one of the two duplex automation processors, the active automation processor, on an ENa or ENb bus that was reachable when the message recipient automation processor last sent the message, the second automation processor and the second bus being in hot standby mode. The address message is sent by the active automation processor on the ENa or ENb bus on which the message arrived.
[0015] Broadcast message sending and receiving are performed simultaneously on the ENa and ENb buses by the existing automation processor.
[0016] On a bus, such as ENa, if a recipient automation processor becomes unreachable after n redundant transmissions using the LLC protocol, the recipient's address is added to the list of unreachable automation processors on that bus. The message is then forwarded via the ENb bus, typically with n = 2. The message forwarding process ends after two redundant transmissions via the ENb bus or, if the recipient is unreachable, two redundant transmissions. If the transmission via the ENb bus link is successful, new messages destined for the same recipient are forwarded by the recipient according to the information in the unreachability icon on the ENb bus.
[0017] A duplex bus consisting of two buses, each with its own data transmission medium, maintains availability at the physical level when one of the lines closes the physical loop by transmitting data error-free on the other intact physical bus not affected by a broadcast storm on a failed bus. However, this duplex bus lacks a means to completely protect the communication module processor from the effects of a "broadcast storm." Consequently, this bus has the following disadvantages:
[0018] - If the processor speed is not high enough, there is a possibility of overloading the communication module processor, if one of the two buses is closed at a certain stage into a physical loop and disrupts the processor's functions;
[0019] - "Broadcast storms" are the possibility of delayed address and broadcast message reception and execution containing outdated data in the failure vertical, thus disrupting message processing procedures at the application level.
[0020] The present invention eliminates the disadvantages indicated. Summary of the Invention
[0021] The technical result of the invention is to improve the reliability of the automation complex by organizing its error-free operation in the event of switching failures and errors that lead to the closing of the total current phase into a physical loop causing a "broadcast storm".
[0022] Technical results achieved through the EN-2 duplex bus include:
[0023] Based on the switched Industrial Ethernet standard and "point-to-point" links, the network switches are connected in series to form a "virtual" ring using TurboRing technology, with the first and second buses not connected to each other;
[0024] A communication module for connecting redundant automation processors to the bus via first and second links: the first link to the switch of the first director, and the second link to the switch of the second bus, wherein each pair of redundant automation processors is linked via an interface between the processors, has a common network address and internal self-control and redundancy management devices;
[0025] At this time, according to the OSI (Open Systems Interconnection) final machine communication information model, the Ethernet interface standard protocols for managing data transmission via the bus are installed in the automation processor communication module: the physical protocol PHY (PHYsical) on the OSI physical layer 1, the LLC (Logical Link Control) logical interface protocol and the MAC (Medium Access Control) data transmission access protocol on the OSI layer 2 link, as well as the APM (Application Program Module) standard application protocol on the OSI layer 7;
[0026] The present invention comprises a duplex bus system comprising a communication module that connects a redundant gateway interface to the bus. The module transmits process data and detection information between the bottom automation machine and the upper system of the module according to the information model of the final machine communication of the OSI layers 1, 2, and 7. The module is an independent device with its own network address and redundant management by the upper system of the module.
[0027] In the communication module of the automation processor and gateway interface, an RPM (Reserving Program Module) redundancy service is installed at OSI layer 7 in the general protocol for data transmission at OSI layer 7 and the standard protocol for OSI layers 1 and 2. This service manages the synchronous transmission of address and broadcast messages via the first and second duplex buses according to the LLC protocol in mode 1. The delivery of address messages via at least one bus is confirmed in the RPM service. Upon message reception, address messages are individually numbered according to the L module. Upon message reception, message transmission sequence analysis is performed relative to the last received message number, and delayed copies of previously received messages are discarded.
[0028] A TF (TelegramFilter) filtering service is installed on the first and second links of the OSI layer 2 MAC sublayer of the automation processor for message traffic consisting of broadcast messages and address messages sent in broadcast mode when the recipient is unreachable during a "broadcast storm." A second TF1 filtering service for this message traffic is installed on the first and second links of the gateway interface of the OSI layer 2 MAC sublayer. This filtering service prevents overloading of the processors of the corresponding communication modules of the automation processor and the gateway interface, as well as preventing the execution of messages that are delayed and contain outdated data during a "broadcast storm." BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The nature of the invention is illustrated by the accompanying drawings.
[0030] Figure 1The above provides a schematic diagram of a multiple bus in a ring stage according to the Turbo Ring technology in the automation system composition, wherein:
[0031] 1 is a duplex bus;
[0032] 1a is the first physical bus for data transmission of the duplex bus 1;
[0033] 1b is the second physical bus for data transmission of duplex bus 1;
[0034] 2a is the network switch of the first bus 1a;
[0035] 2b is the network switch of the second bus 1b;
[0036] 3 11 ,3 12 –3 n1 ,3 n2 redundant automation processors with internal management redundancy;
[0037] 4 11 ,4 12 –4 m1 ,4 m2 It is the redundant gateway interface with external management honors of SVBU11;
[0038] 5a is a network switch 2a that connects the first data transmission link of the communication module to the bus 1a;
[0039] 5b is a 2b network switch that connects the second link of the communication module to the 1b bus;
[0040] 6 11 ,6 12 –6 n1 ,6 n2 3 is a component of bus 1 11, 3 12 –3 n1 ,3 n2 Communication module for automation processor;
[0041] 7 11 ,7 12 –7 m1 ,7 m2 It is a 4-bit component of bus 1. 11 ,4 12 –4 m1 ,4 m2 A communication module combined with a switch;
[0042] 8a is the communication trunk cable of 1a bus 2a network switch;
[0043] 8b is the communication trunk cable of 1b bus 2b network switch;
[0044] 9 is an automatic processor redundancy management circuit;
[0045] 10 is process management equipment;
[0046] 11 is the module upper management level system (SVBU);
[0047] Figure 2 and Figure 3 The structure of the multibus information model is shown in schematic form, which is correspondingly implemented in the communication module 6 of the automation processor 3 and the communication module 7 of the gateway interface 4 as components of the multibus 1, wherein:
[0048] 1 is the part of the multiplex bus;
[0049] 1a is the first physical bus for data transmission of the multiplex bus 1;
[0050] 1b is the second physical bus for data transmission of duplex bus 1;
[0051] 3 is the automation processor;
[0052] 4 is the gateway interface;
[0053] 6 is an automation processor communication module;
[0054] 7 is a gateway interface communication module;
[0055] 12 is the physical layer 1 of the seven-layer information model of the OSI (Open Systems Interconnection) network standard;
[0056] 13 is the OSI Network Information Model Link Layer 2;
[0057] 14 is the OSI network information model application layer 7;
[0058] 15a is the message arrival line through the first link 40a of the communication module 6 of the automation processor 3 and the first link 50a of the communication module 7 of the gateway interface 4, and correspondingly to the first filtering service 22a of the automation processor and the second filtering service 25a of the gateway interface;
[0059] 15b is the message arrival line through the second link 40b of the communication module 6 of the automation processor 3 and the second link 50b of the communication module 7 of the gateway interface 4, and correspondingly to the first filtering service 22a of the automation processor and the second filtering service 25a of the gateway interface;
[0060] 16a, 16b are the corresponding protocols from 22a, 22b sorting services to the communication module 6 LLC 23 of the automation processor 3 and the corresponding protocols from the sorting services 25a, 25b to the gateway interface 4 LLC
[0061] 23 protocol, corresponding to the message transmission line through the first and second links; 17a, 17b are the corresponding time synchronization SYN broadcast message transmission lines from the first two sorting services 22a, 22b to the real-time counter 49 of the automation processor 3, through the communication module 6 of the automation processor 3 corresponding to the first and second links;
[0062] 18a, 18b are the transmission / reception lines of the first and second link TLB (TeLegram-Broadcast) broadcast messages to / from the application protocol 26 through the corresponding first and second links of the gateway interface 4; 20a is the Industrial Ethernet interface PHY physical protocol of the first link of the communication modules 6 and 7, IEEE 802.3, 2000 Edition standard;
[0063] 20b is the Industrial Ethernet interface physical protocol of the second link of communication modules 6 and 7, IEEE
[0064] 802.3,2000Edition standard;
[0065] 21a is the Industrial Ethernet interface data transmission medium MAC protocol of the first link of the communication modules 6 and 7, IEEE 802.3, 2000 Edition standard;
[0066] 21b is the Industrial Ethernet interface data transmission medium MAC protocol of the second link of the communication modules 6 and 7, IEEE 802.3, 2000 Edition standard;
[0067] 22a is a first TF sorting service for messages received via the first bus 1a, additionally installed on the first link 40a of the communication module 6 to the automation processor 3 according to the present invention; 22b is a first TF sorting service for messages received via the second bus 1b, additionally installed on the second link 40b of the communication module 6 to the automation processor 3 according to the present invention; 23a is the IEEE 802.21998 Edition Industrial Ethernet Interface Logic Component LLC protocol for the first link of the communication modules 6 and 7;
[0068] 23b is the IEEE 802.21998 Edition standard Industrial Ethernet interface logic component LLC protocol of the second link of the communication modules 6 and 7;
[0069] 24 is an RPM redundancy service added to the standard information model RPM redundancy service at OSI layer 147 according to the present invention;
[0070] 25a is a second TF1 sorting service for messages received via the first bus 1a, which is additionally installed on the first link 50a of the gateway interface communication module 7 according to the present invention;
[0071] 25b is a second TF1 sorting service for messages received via the second bus 1b, which is additionally installed on the second link 50b to the gateway interface communication module 7 according to the present invention;
[0072] 26 is the universal application protocol of EN bus;
[0073] 27a is the first link application address message TLA to / from the automation processor 3 communication module 6 and the gateway interface 4 communication module 7 R (Telegram Address) in RPM service mode and determines the message ACK (ACK noledge) sending / receiving line;
[0074] 27b is the second link application address message TLA to / from the automation processor 3 communication module 6 and the gateway interface 4 communication module 7 R In RPM service mode and confirming message ACK
[0075] (ACKnoledge) send / receive line;
[0076] 28 is the application address message TLA sending / receiving line;
[0077] 40a, 40b are the first and second links of the communication module 6 of the automation processor 3;
[0078] 49 is an automation processor real-time counter;
[0079] 50a, 50b are the first and second links of the communication module 7 of the gateway interface 4;
[0080] Figure 4 The above diagram shows that the numbered application address message TLA is transmitted through two buses. R The transmission structure on the RPM 24 service layer: between automated machines, via the first bus 1a and the second bus 1b of the duplex bus: further via the ASj (Automatic device Source) message sending automated machines (hereinafter referred to as senders) and the ADi (Automatic device – Destination) message receiving automated machines (hereinafter referred to as receivers), taking the message exchange between two non-redundant automated processors as an example, wherein:
[0081] 1a, 1b are the first and second physical buses of the duplex bus;
[0082] 3j, 3i are the automation processors representing the sending machine ASj and the receiving machine ADi, respectively;
[0083] 12 is the physical layer 1 of the OSI network standard 7-layer information model;
[0084] 13 is the OSI Network Information Model Link Layer 2;
[0085] 14 is the OSI network information model application layer 7;
[0086] 19a, 19b refer to TLAs between the automation processors 3j, 3i redundant service RPMs via the corresponding LLC messages introduced into the link layer 13 in RPM service mode. R (INji, FNji, TLA) are the assumed transmission lines of the first bus 1a and the second bus 1b for application address messages;
[0087] INji (Individual Number) in the song refers to the individual number of the message, FNji (Frame
[0088] Number)—refers to the redundant film number;
[0089] 24j refers to the sending machine 3j redundant service RPM;
[0090] 24i refers to the acceptance of machine 3i redundant service RPM;
[0091] 26j refers to the application protocol APM of the sending machine 3j;
[0092] 26i refers to the application protocol APM that accepts machine 3i;
[0093] 29a, 29b refer to the assumed transmission lines of the first bus 1a and the second bus 1b of the message between the automation processors 3j, 3i redundant service RPM by the corresponding ACK (IDij, IFij, STij) inserted into the LLC message in the RPM service mode; wherein IDij (IDentifier)
[0094] —Identifier for identifying the message, IFij (Frame IDentifier)—Identifier for identifying the message, STij (STatus)—Address receiving machine APM 26 i The status of the application protocol.
[0095] Figure 5The diagram shows the state changes of the address message identification number cycle counter NTCji (Number Telegram Counter) formed on the time axis according to the L model and the changes of the identification number INji transmitted in series between the network sending machine ASj and the receiving machine ADi, as well as the formation of the message acceptance / non-acceptance logic condition based on the analysis of the receiver relative to the last received INRij message identification number. If the value Δ=(INR ij –L / 2)>0, where:
[0096] 30 refers to the time axis of the NTCji counter according to the L modulus state change;
[0097] 31 is the time axis of the changes in the identification number of the message INji transmitted in series between the sending machine ASj and the receiving machine ADi;
[0098] 32 is the range of messages INji that are not accepted by the receiving machine, under the following conditions: INji≤INRji;
[0099] 33 is the message INji range accepted by the ADi receiving machine;
[0100] 33.1 is the range of INji points of the message received by the ADi receiving machine, under the following conditions: INji>
[0101] INRij;
[0102] 33.2 is the range of INji points of the received message, under the following conditions: (Inji–Δ)≤0;
[0103] 34 is the current formation cycle of the message identification number in the NTCji counter.
[0104] exist Figure 6 The figure shows the changes of the state of the cycle counter NTCji on the time axis 30 according to the L modulus and the changes of the identification number INji transmitted in series between the sending machine ASj and the receiving machine ADi on the time axis 31, as well as the formation of the message acceptance / non-acceptance logic condition based on the analysis by the receiver relative to the number of the message INRij received last. If the value Δ=(INR ij –L / 2)≤0, where:
[0105] 35 is the message INji range that the ADi receiving machine does not accept;
[0106] 35.1 is the range of the message INji that the ADi receiving machine does not accept, under the following conditions: INji
[0107] ≤INRij;
[0108] 35.2 is the range of unacceptable messages, under the following conditions: (INji–L+Δ)≥0;
[0109] 36 is the range of messages INji accepted by the ADi receiving machine, under the following conditions: INji>INRji.
[0110] exist Figure 7 Above, taking the address message identification number formed by the periodic counter according to the modulus L=8 as an example, a list of formats of the decision on message acceptance made by the receiving machine under any combination of the incoming address message identification number INji=0÷7 and the most recently received message identification number INRij=0÷7 is shown, which is shown as an indication of a value of 1, or the decision on not accepting the message is shown as an indication of a value of 0.
[0111] Figure 8 The above shows the corresponding first sorting service structure of broadcast and address messages received via the first 1a and second 1b duplex buses in the first 40a and second 40b links of the communication module 6 of the automation processor 3, wherein:
[0112] 15a is the message arrival line from the first link 40a of the communication module 6 of the automation processor 3 to the first sorting service 22a of the automation processor;
[0113] 15b is the message arrival line from the second link 40b of the communication module 6 of the automation processor 3 to the first sorting service 22b of the automation processor;
[0114] 16a, 16b are the transmission lines of the address message in the first and second links of the automation processors 40a, 40b corresponding to the LLC protocol 23a, 23b;
[0115] 17a, 17b are lines for transmitting time synchronization broadcast messages from the corresponding message processors 45a, 45b of the first and second links 40a, 40b of the automation processor to the real-time counter 49;
[0116] 22a, 22b are the first sorting services of the corresponding messages in the first and second links of the automation processors 40a, 40b;
[0117] 40a, 40b are the first and second links of the automation processor;
[0118] 41a, 41b are direct access links to the first and second 40a, 40b link memories of the automation processor;
[0119] 43a, 43b are message receiving buffers for the first sorting service of the corresponding messages of the first and second links of the automation processors 40a, 40b;
[0120] 44a, 44b are message counters for the first sorting service of the corresponding messages in the first and second links of the automation processors 40a, 40b;
[0121] 45a, 45b are message processors for the first sorting service of the corresponding messages of the first and second links of the automation processors 40a, 40b;
[0122] 46a, 46b are first timeouts of the first sorting services of the corresponding messages of the first and second links of the automation processors 40a, 40b;
[0123] 47a, 47b are second timeouts of the first sorting service of the corresponding messages of the first and second links of the automation processors 40a, 40b;
[0124] 48 is a 100Hz timer of the communication module 6 of the automation processor 3;
[0125] 49 Automation Processors 3 Real-time Counters, Figure 8 、 Figure 2 ;
[0126] 60a, 60b are the lines for reading the message from the receiving buffer, corresponding to 43a, 43b;
[0127] 63a, 63b is the first timeout opening of the line according to the first received message 46a, 46b on the first and second 40a, 40b corresponding links of the automation processor after the current timeout of the link ends;
[0128] 64a, 64b are first timeout opening lines corresponding to 47a, 47b of the first received message after the current timeout of the link ends on the first and second links 40a, 40b of the automation processor;
[0129] 65a, 65b are lines for reading the first timeout end state of the first and second links 46a, 46b of the automation processors 40a, 40b, respectively;
[0130] 66a, 66b are the time synchronization SYN of the corresponding two links 47a, 47b within the second timeout period.
[0131] Broadcast computer execution inhibit circuit;
[0132] 67a, 67b are the corresponding message counters of 44a, 44b overflow until the first timeout ends, respectively, 43a, 43b, interrupting the blocking processing line of the incoming receive buffer; 68a, 68b are the first timeouts of the first and second links of the automation processor, respectively 46a,
[0133] 46b, after the countdown ends, the message counter reset line, respectively 44a, 44b; 69 is the counting signal line of the first timeout of 46a, 46b and the second timeout of 47a, 47b of the first filtering service from the 48 timer of the 100Hz frequency;
[0134] 71a is the transmission line for the SVBU notification message about "broadcast storm" to enter bus 1b through bus 1a;
[0135] 71b is the transmission line for the SVBU notification message about "broadcast storm" to enter bus 1a through bus 1b;
[0136] 72a, 72b are message counter overflow signals, which are 44a and 44b respectively.
[0137] Figure 8 The links of the automation processor first filtering services 22a, 22b and the bus information model protocols 23a, 23b, 24, 26 are also shown in dotted lines. Figure 2 .
[0138] Figure 9 The structure of the second filtering service for broadcast and address messages received on the first and second buses 1a and 1b of the duplex bus in the first and second links of the communication module 7 of the gateway interface 4 is shown. Figure 3 ,in:
[0139] 15a is the gateway interface 4, Figure 9 , Figure 4 The communication module 7 enters the gateway 4 through the first channel message, the second filtering service 25a line;
[0140] 15b is the gateway interface 4 ( Figure 9 , 4) the communication module 7 inputs the message transmission line of the second filtering service 25b of the gateway interface 4 through the second link;
[0141] 16a, 16b are transmission lines for delivering the processed address message to the LLC protocol 23a, 23b in the first and second channels 50a, 50b of the gateway interface, respectively. Figure 9 , Figure 4 ;
[0142] 25a, 25b are the second filtering services of the packets in the first and second links 50a, 50b of the gateway interface. Figure 9 , Figure 4 ;
[0143] 50a, 50b are the first and second channels of the gateway interface. Figure 9 , Figure 4 ;
[0144] 51a, 51b are direct memory access links of the first and second links 50a, 50b of the gateway interface;
[0145] 53a, 53b are the message receiving buffers of the second filtering service in the first and second links 50a, 50b of the gateway interface;
[0146] 54a, 54b are packet counters of the second filtering service in the first and second links 50a, 50b of the gateway interface;
[0147] 55a, 55b are the packet processors of the second filtering service in the first and second links 50a, 50b of the gateway interface
[0148] 56a, 56b are the first timeouts in the first and second links 50a, 50b of the gateway interface; 58 is the 100 Hz timer of the communication module of the gateway interface;
[0149] 80a and 80b are lines for reading messages from the receive buffer, which are 53a and 53b respectively;
[0150] 83a, 83b are the first timeout start lines of the first message received from the first and second links 50a, 50b of the gateway interface after the first timeout of the corresponding link is completed, which are 56a, 56b respectively;
[0151] 85a, 85b are the first and second links 50a, 50b of the automation processor reading the first timeout end state line, which are 56a, 56b respectively;
[0152] 87a, 87b are before the first timeout, 56a, 56b respectively, the corresponding message counter overflow
[0153] When output, they are 54a and 54b respectively, interrupting the message blocking processing circuit entering the receive buffer, with decibels of 53a and 53b;
[0154] 88a, 88b are the first timeout countdown results in the first and second links 50a, 50b of the gateway interface.
[0155] After the end, they are 56a, 56b, the message counter reset lines, respectively 54a, 54b; 89 is the signal counting line of the first timeout 56a, 56b of the second filtering service of the 100Hz frequency timer 58;
[0156] 91a is the transmission line that transmits the "broadcast storm" SVBU notification message through bus 1a to bus 1b;
[0157] 91b is the transmission line that transmits the "broadcast storm" SVBU notification message via bus 1b to bus 1a;
[0158] 92a, 92b are message counter overflow signals, which are 54a and 54b respectively;
[0159] Figure 9 The links of the second filtering services 25a, 25b of the gateway interface to the bus information model protocols 23a, 23b, 24, 26 are also shown with dashed lines. Figure 3 . DETAILED DESCRIPTION
[0160] Figure 1 The schematic diagram shows that the redundant bus 1 provides the following functions of the redundant software / hardware complex for the automated process control: data exchange between the redundant automation processors 3 required for the automated process control 10; the automation processors receive commands for remote control of process actuators from the modular upper-level system 11 via the redundant gateway interface 4 and execute such commands; the automation processors 3 transmit status data about the process and the automation complex to the gateway interface 4 for subsequent transmission to the modular upper-level system for analysis and control.
[0161] In a redundant automation system, the control data exchange via the multibus and its processing according to the applied automation algorithm is performed by one of the redundant automation processors 3, for example 3 11 , currently active, another automation processor, respectively 3 12 , currently in passive state, operating in hot standby state. Redundant automation processor 3, e.g. 3 11 , 3 12 , built-in self-monitoring and hot standby management, are interconnected through two independent serial interfaces 9, through which the automation processor receives information about the partner's performance based on the self-control results, respectively 3 12 , 3 11 Based on the evaluation of the information and on the basis of predetermined criteria, the active automated processor 3, for example 3 11 , can switch to the state of passive automation processor 3, respectively 3 12 , and the passive processor switches to the active state, meaning the automation processor switches to the standby state. Automation processor 3 switches to the standby state as well, periodically to check the performance of the redundant automation processor according to the actual operating algorithm. The redundant automation processor is represented on the bus by the network address of the active automation processor; this address remains the same regardless of which of the redundant automation processors is active.
[0162] Different from the automation processor, the redundant gateway interface 4 is independent and unrelated to the external redundant control device of the module upper-level system, and is represented by a different network address on the multibus 1 .
[0163] The duplex bus 1 is based on an Industrial Ethernet interface and comprises: two directly unconnected first 1a and second 1b buses made using Turbo Ring technology and connected in series via a trunk link 8 of a network switch 2; an automation processor communication module 6 and a gateway interface communication module 7.
[0164] Two redundant automation processors 3 11 ,3 12 ;…3 n1 ,3 n2 Each of the communication modules 6, for example 3 11 , connecting the automation processor to the redundant bus via two links: via a first link - via a communication line 5a to the network switch 2a of the first bus 1a, and via a second link - via a communication line 5b to the network switch 2b of the second bus 1b, thus ensuring operability in the event of any multiple failure of one of the two buses (network switch 2, communication trunk 8, communication line 5 with the communication module of the network switch of this bus) while maintaining the operability of the other bus.
[0165] In this case, the communication modules of the two redundant automation processors are each connected to two switches 2a of a first bus 1a with their first links and to two network switches 2b of a second bus 1b with their second links.
[0166] Each of the two buses utilizes ring technology and is made redundant through ring reconfiguration. This process is performed by one of the network switches connected in series to the ring via a backbone connection. This switch, designated as the redundancy manager, maintains the ring and monitors its integrity by sending control messages from one end of the ring and receiving them from the other end, connected to the two trunk ports of the redundancy manager switch. If the integrity of the ring connection is compromised, the redundancy manager restores connectivity by reconfiguring the bus to logically close the ring at the control point.
[0167] When a single failure occurs in the trunk connection of one of the two buses 1a, 1b, the affected bus will automatically recover through ring reconfiguration and maintain the operability of both buses.
[0168] In the event of a single failure in a communication module connection, the connection to the automation devices connected to this bus will be interrupted. Switching the automation processor to a redundant processor connected to an available switch via an intact connection can fully restore the operability of the duplex bus on both buses.
[0169] If the communication module loses its connection to the switches in both buses, the processor's self-controller automatically switches it to the redundant automation processor connected to the bus via the intact connection 5. The operability of both buses is maintained.
[0170] When the connection between the two buses 1a, 1b is interrupted due to a communication module failure caused by a loss of ring integrity and a link to the automation processor, the redundancy manager performs a bus reconfiguration. During this time, as the reconfiguration continues, the automation processor is switched to the redundant processor of the intact switch connected to the duplex bus, thus restoring the operability of both buses.
[0171] In the event of any two failures of the network devices in the two buses, the operability of the duplex bus is maintained: trunk connections 8, links between communication modules and switches 5, network switches 2, communication modules 6 of the automation processors and communication modules 7 of the interface gateways, the same number of network devices.
[0172] The transmission of TLA address messages and TLB broadcast messages through the EN-2 duplex bus is based on Figure 2 As shown, the processor 3 and Figure 3 The information model is implemented using the EN-2 bus information model for the gateway interface 4 shown. The information model is based on the three standard layers of the Ethernet interface of the OSI 7-layer model: Layer 1 - the physical layer 12 using the PHY protocol 20, Layer 2 - the data transmission medium using the access MAC protocol 21 and the link 13 using the logical link LLC protocol 23, and Layer 7 - the application protocol 14 using the APM 26. According to the present invention, this is supplemented by the RPM 24 redundancy service on the application layer 14, the first filtering service TF 22 for messages received in the channel 40 of the automation processor 3, Figure 2 , and the second filtering service TF125 receives the message in the channel 50 of the gateway interface 4 on the MAC 21 sublayer of the OSI 13 layer 2, Figure 3 .
[0173] according to Figure 4The application address message TLA is transmitted simultaneously by the transmission device ASj 3j to the network receiver via two independent buses 1a and 1b, via conditional lines 19a and 19b of the ADi 3i RPM24 redundant service, in the form of two identical TLAR (INji, FNji, TLA) frames. These frames contain the application address message TLA, its individual number INji, and the redundant frame number FNji generated by the RPM service. The ADi 3i receiver uses the address message individual numbering mechanism outlined below to receive one of the two incoming message frames, extract the TLA application message from this frame, and transmit it to the APM application layer. It then transmits the ACK reply message (IDij, IFij, STij) via conditional lines 29a and 29b of buses 1a and 1b, using the RPM service, in the form of two identical frames encapsulated within an LLC message in mode 1. IFij is the redundant frame identifier for the reply message, and STij is the APM protocol status in the 3i device, conveying the TLA message sender's address.
[0174] The current status of ASj and ADi devices during the process of sending the address message with confirmation is determined by the user status parameter in the RPM service.
[0175] The state of the transmitter ASj is determined by the following parameters:
[0176] NTCji (Number Telegram Counter) is a value of the message number cycle counter of the L module.
[0177] RCji (Repeat Counter) is the value of the message retransmission counter when the previous message has not been transmitted.
[0178] The state of the ADi receiver is determined by the following parameters:
[0179] INRij is the stored value of the individual number of the last received TLA message;
[0180] STij is the message transmission status value of the APM layer and can take one of the following values:
[0181] STij=01-----The message was not delivered to the APM layer due to a temporary error and can be delivered during retransmission;
[0182] STij=10-----Due to a persistent error, the message was not delivered to the APM layer and could not be delivered during retransmission;
[0183] STij=11–-----The message has been successfully delivered to the APM layer and does not need to be retransmitted.
[0184] Before transmitting the TLA address message, the transmitter generates and assigns a separate INji number and redundant frame transmission number FNji to it, and places the number together with the application message in the TLA of the address message. R In the frame, the format is RPM:TLA R (INji, FNji, TLA).
[0185] An individual number for address messages is set for each pair of automation devices: a transmitter ASj and an automation receiver ADi. The individual number INji of an address message transmitted from an ASj device to an ADi device is formed modulo L by circulating the message number counter NTCji, where L is the maximum number of different individual numbers. Before transmitting the next TLA message, the ASj transmitter increments the NTCji counter by 1 modulo L, depending on the sequence of message transmissions, and assigns this value to the INji individual number.
[0186] If a new message or the previous redundant frame is not transmitted to the receiver within the timeout Tout = 30ms, or is transmitted in the case of temporary error state STij = 01 of the ADi device, then before transmitting the next redundant frame, the ASj device increments the redundant counter RCji by 1 and assigns its value to the TLA R The redundancy number FNji in the message (INji, FNji, TLA). The value of INji does not change during the transmission of redundant frames. The maximum number of redundant frames transmitted and the corresponding maximum value of the counter RCji = 2.
[0187] TLA at the RPM layer R (INji, FNji, TLA) numbered application address message ( Figure 4 ) is encapsulated in the data field of the LLC message ( Figure 2 、 3 ) and through the LLCa and LLCb program modules ( Figure 2 ,3) transmitted to the ADi device, which receives the message through the same model and selects the TLA of the RPM layer from it R Frame, which is equal to Figure 4 Direct exchanges between ASJ and ADI via lines 19a, 19b, 29a, 29b are shown.
[0188] To transmit numbered-address messages, using the LLC protocol type 1, there's no need to perform pre-LLC layer connection establishment and transmission confirmation on both links A and B. After the next address message is sent and the ACK message is received at the RPM layer on either bus, the next new message or reframe can be transmitted. There's no need to wait for the ACK message on the other bus. This ensures synchronous message transmission and operational redundancy, and also eliminates the impact of increased transit time on the duplex bus due to a bus impairment.
[0189] The receiver transmitter receiver ADi analyzes the sequence of the transmitter's outgoing messages, associated with the INRij number value of the last message received via one of the EN-2a, EN-2b buses and stored in the RPM service, based on the individually numbered TLA messages transmitted via the two buses. The receiver accepts a message if it was sent later than the last received message (new message), if it was sent simultaneously with the last received message but on a different bus (a copy of the last received message is in the receive buffer), or if it was sent before the last received message (a delayed copy of a previously received message or a delayed but not yet received message).
[0190] The reception of the address destination message is acknowledged on one of the buses by a dedicated ACK acknowledgement reply message, which the receiver ADi of the address message generates in the RPM redundant service and transmits in the form of 2 identical application frames via buses 1a and 1b to the transmitter ASj.
[0191] Before sending the ACK message, the receiver ADi of the target message generates and places the message IDij, redundant frame ID FIij and the delivery status STij of the TLA message to the APM application layer in the data field of the ACK message. ACK(IDij,IFij,STij) message is generated.
[0192] The identification code IDij of the ACK message is generated by the ADi device by assigning it the value of the individual number INji of the received target address message: IDij:=INji.
[0193] The frame identification code FIij of the ACK message is generated by the device ADi by assigning to it the value of the number FNji of the received and received redundant frames of the TLA message: FIij := FNji.
[0194] Individual numbers are not used when transmitting ACK messages.
[0195] According to the operation code and identification code IDij, IFij, the ASj device in the RPM service identifies the target TLA that responds to it. R The received ACK message or its redundant frame, or TLAR Redundant frame of the message. If IDij = NTCji and FIij = RCji, the device ASj receives the ACK. If IDij ≠ NTCji or FIij ≠ RCji, the ACK message will not be received.
[0196] The STij status of the ACK message indicates the result of transmitting the address message from the RPM service to the APM application layer of device ADi. Device ASj completes the message transmission based on the STij value. If STij = 11, the registration message is successfully delivered; if STij = 10, the registration message fails. If device ASj receives a message with a STij = 01 status or fails to receive an ACK message within the 30ms timeout period, it retransmits the message up to two times and analyzes the response. This process ends with either failure to transmit the message or successful transmission.
[0197] Two algorithms are proposed, one is a calculation algorithm and the other is a list algorithm. The two algorithms are used to determine the RPM service acceptance / non-acceptance conditions of the current address message through the individual number INji of the current address message and the individual number value of the last received message INRij stored in RPM.
[0198] The calculation algorithm used to determine the conditions for receiving / not receiving address messages is as follows Figure 5 、 6 shown.
[0199] These figures show the periodic change of the NTCji counter status from 0 to L-1 during the transmission of the address message and the position of the individual number INji of the currently received message.
[0200] At this time, regardless of the position of the last received message number within the current change cycle of the NTCji counter, the number of received messages numbered INRij sent later than the last received message is (L / 2-1) and is different from the number of unreceived messages (L / 2+1) sent earlier than the last received message, that is, all numbers in the range of L are unique, regardless of the value of the INRij number.
[0201] The expression of the message received / not received to calculate the connection depends on the position of the INRij message in the NTCji counter state change cycle, that is, the displacement value Δ of the position relative to the state of the counter NTCji=L / 2 to the right ( Figure 5 ) or left ( Figure 6 ) displacement.
[0202] Figure 5 Displays the conditional calculation for message reception / non-reception when Δ = (INRij – L / 2) > 0.
[0203] Two message number ranges, 32 and 33, are displayed, each corresponding to the INRij number of L / 2. Messages with numbers INji in range 32 are not received. Messages in range 33 are received, except for messages with numbers INji = INRij.
[0204] Range 33 includes two subranges: 33.1 and 33.2. Message numbers in subrange 33.1 fall within the same NTCji counter cycle as the message number INRij. These messages are accepted based on the comparison of Inji > INRij. Message numbers in range 33.2 fall within the next NTCji change cycle. These messages are issued later than the message numbered INRij, but their numbers satisfy Inji ≤ INRij.
[0205] according to Figure 5 , the conditions for receiving / not receiving a message are calculated as follows:
[0206] 1) If (INji–Δ)>0 (INji range: 32, 33.1), then
[0207] If INJI-INRij>0, the message is accepted.
[0208] If INji–INRij ≤ 0 (range 32), the message is not received.
[0209] 2) If (INji–Δ)≤0 (INji range: 33.2), the message is received.
[0210] Figure 6 The conditional calculation of received / non-received messages when Δ = (INRij – L / 2) ≤ 0 is shown.
[0211] Two message number ranges 35 and 36 are shown relative to the INRij number. Messages with the number INji in range 35 are not received. Messages in the number range 36 are received, except for messages with the number INji = INRij.
[0212] The 35 range consists of two sub-ranges: 35.1 and 35.2. Messages in sub-range 35.1 are numbered within the same NTCji change cycle as the INRij number. Based on the comparison of INji ≤ INRij, such messages are not received. Messages in sub-range 35.2 are numbered within the previous NTCji change cycle. These messages are sent before the INRij numbered message, but their numbers are INji > INRij.
[0213] according to Figure 6 , the conditions for receiving / not receiving a message are calculated as follows:
[0214] 1) If (INij–L+Δ)<0 (INij range: 35.1, 36), then
[0215] If INji-iNRij>0, (range INji: 36), the message is received,
[0216] If INji–INRij≤0 (INji range: 35.1), the message was not received.
[0217] 2) If (INji–L+Δ)≥0 (INji range: 35.2), the message was not received.
[0218] Figure 7 This table shows the conditions for determining whether an address message is received or not, using the example of a table constructed with L = 8. The individual message number list modulo 8 shows the conditions for receiving or not receiving the individual numbered message INji = 0 ÷ 7. The last received message number, INRij = 0 ÷ 7, has the value INRij.
[0219] The number 1 at the intersection of the column numbered INji and the row numbered INRij in the table indicates that the message is received when using such values of the INji and INRij numbers, and the number 0 indicates that the message is not received.
[0220] The list method requires no computation and offers higher evaluation performance, but the list requires memory, the amount of which depends on the selected value of L. For L = 256 (NTCji counter - 8 bits) and a byte representation of the list data, 64KB of memory is required, which is acceptable. For larger values of L, a computational algorithm for analyzing the message number is more desirable.
[0221] The TLB application layer broadcast message is generated by the APM application protocol service 26 of the sender. Figure 2 、 3 ,: gateway interface or automation processor and transmitted to the receiver via LLC 23 protocol in mode 1 without transfer confirmation in the LLC protocol in the form of two identical frames without individual numbers via the communication module and the two links of the bus 1a, 1b.
[0222] Gateway interface 4( Figure 1 、 3 ) According to the sequence set by the SVBU 11, the broadcast time synchronization message SYN is transmitted from the specified redundancy time of 5 seconds to 20 seconds ( Figure 1 ).
[0223] Automation Processor 3( Figure 1 、 2) conveys ANZ type broadcast messages informing the SVBU 11 about the status of the automation processor 3 and the bus 1. Such messages are sent at random intervals by different automation processors.
[0224] According to the connection to the multiplex bus 1 ( Figure 1 )'s automation equipment's methods for filtering and receiving broadcast messages are divided into two groups.
[0225] Group 1 includes lower-level automation devices, such as automation processor 3, which receives and executes SYN time synchronization broadcast messages transmitted via buses 1a, 1b. Of the two frames transmitted via buses 1a, 1b, this device receives one frame as if it were a TLA address message and discards the second frame (duplicate) received on the other bus.
[0226] The remaining broadcast messages transmitted along bus 1, including messages of ANZ type warnings, are not used in group 1 devices and are discarded by the first TF 22 filter service ( Figure 2 ). Detecting an overload of one of the two buses 1a, 1b due to a "broadcast storm", the filtering service 22 of the automation processor 3 ( Figure 1 、 2 ) By periodically interrupting the processor's processing, all broadcast and address messages stored in the input buffer and transmitted in the transmit buffer are interrupted during the message traffic calculation interval to prevent processor overload. When an overload is detected, the filtering service 22 also prohibits the execution of SYN messages and address messages received on the bus for the entire duration of the "storm" to eliminate the possibility of delayed execution of SYN messages with outdated data due to the bus incident and further reduce the processor load.
[0227] Group 2 includes gateway interface 4.
[0228] Gateway interface 4( Figure 1 、 3 ) In normal operating mode, it receives broadcast messages of the ANZ type notifying events in the automation complex and the bus, as well as address messages, for transmission to the SVBU ( Figure 1 ANZ messages concerning the status of one of the two buses in a duplex are typically transmitted over the intact bus and contain information about the type of incident and its identification code on the other bus. Therefore, ANZ application messages for both buses arrive at the application layer of the gateway interface in a common file and are stored in this format in the SVBU 11 archive. This isolation allows identification of the bus 1a or 1b experiencing the incident. Broadcast SYN messages are discarded by the gateway interface's filtering service.
[0229] The address message is received by whichever bus is sent first. According to the individual numbering procedure, the copy of the message received by the other bus and the delayed address message are discarded and the data is sent to the SVBU 11 ( Figure 1 ) and used for processing analysis.
[0230] When a "broadcast storm" is detected on one of the two buses 1a, 1b, the second filtering service 25 of the gateway interface 4 interrupts the storage and transmission of all broadcast and address messages in the receive buffer during the overload calculation interval, thereby preventing overload of the processor of the bus. Filtering service 25 also prohibits the transmission of ANZ messages and address messages carrying outdated data due to delays in the affected bus on the bus for the entire duration of the "storm," further reducing the load on the gateway interface communication module processor.
[0231] In order to analyze the events of the automation systems and buses under normal operating conditions (in the absence of broadcast storms) in the SVBU archive, files are used of address message data received via the two buses 1a, 1b according to the individual numbering procedure and of application broadcast messages ANZ received via the two buses and indicating accidents on the other bus or on the module link connected to the other bus.
[0232] To analyze the events in the automation system and the bus during a broadcast storm, the ANZ broadcast messages generated in the communication module during overload registration and transmitted via the intact bus were used, as well as the address messages transmitted via the intact bus.
[0233] Figure 8 Lists the filtering structures in the automation processor.
[0234] All messages ( Figure 1 ), transmitted via the direct access link 41a / 41b to the corresponding receive buffer 43a / 43b of the first / second link 40a / 40b of the communication module of the automation processor.
[0235] In each link of the communication modules of the automation processor, after a message has been written to the corresponding receive buffer 43a / 43b, an interrupt is generated, upon which control is transferred to the message processing program 43a / 43b of the first filtering service TF 22a / 22b, which reads the message that caused the interrupt from the receive buffer via the lines 60a / 60b and processes it.
[0236] The message processor 45a of the first filtering service TF 22a performs the following functions in the first group of automation devices for the message received via the first link:
[0237] 1) When a broadcast message is transmitted via line 63a or an address message is transmitted via line 60a, a first timeout 46a is sent periodically, with a default duration of 2 seconds. The timeout 46a is counted by an interrupt from timer 48, with a frequency of 100 Hz, via line 69.
[0238] 2) By counting messages in counter 44a, the counter capacity is N, within the timeout 46a interval, and recording the overflow counter overload displayed on line 72a, broadcast messages and address messages are regularly counted, including broadcast messages SYN, ANZ and broadcast messages not related to duplex bus 1.
[0239] 3) If there is no overload and counter 44a overflows during timeout 46a, message processor 45a writes the incoming SYN message with the current time value from the message data field directly to the real-time counter 49 of the communication module of the automation processor via line 17a; transmits the TLA address message to LLC protocol 23a via line 16a and further to RPM 24 redundancy service via line 27a for analysis and processing according to the numbering process and subsequent execution in application protocol 26; discards other types of broadcast messages, including ANZ messages.
[0240] 4) After the SYN message is received for execution, the message processor starts the second timeout 47a of 5 seconds by default through line 64. This timeout prohibits the execution of a copy of the SYN message from another bus during this time, and prohibits the execution of a new SYN message transmitted between the two buses within an unregulated time interval of less than 5 seconds after the execution of the message. In addition, it prohibits the execution of a SYN message caused by a "broadcast storm" transmitted during the overload measurement period through the first timeout 46a.
[0241] 5) During a "broadcast storm," the receive buffer 43a receives broadcast and address messages, stored in the receive buffer, and the incoming buffer, interrupted via line 67a during the time interval initiated by the timeout 46a. This prevents the module processor from being overloaded with broadcast and address messages via the damaged bus. When message counter 44a overflows, message processing is blocked from the time the counter overflows until the timeout 46a expires.
[0242] 6) When counter 44a overflows for the first time, the message processor sets the overload flag to state 1. The overload flag is set to 1 for the duration of the broadcast storm. It also disables the transmission of the world value from the data field of messages to the real-time counter 49 via line 17a and disables the LLC 23 protocol from sending address messages via line 16a. This disables the execution of SYN messages. This is set to prevent the execution of delayed messages with outdated data on the damaged bus.
[0243] 6) After registering 10 times (default) of no overload continuously through 10 timeouts on the 72a line, the overload flag is set to 0, and the prohibition on executing SYN messages and address messages is lifted.
[0244] 7) When the first link registers an overload, the overload flag is set to 1, and a warning message ANZ9811 (about bus 1a overload SVBU 11) is generated and sent to the intact bus 1b via line 71a. Figure 1 ).
[0245] 8) It is found that there is no overload on the first link, and the overload flag is set to 0. An SVBU warning message ANZ9821 for eliminating the overload of bus 1a is generated and sent to bus 1b through line 71a.
[0246] The message filtering service TF 22b on the second link performs a message filtering function similar to that of the TF 22a service. In this case, the functions of the messages ANZ9811, ANZ9821 generated by the TF 22a service are performed by the messages ANZ9812, ANZ9822 generated by the TF 22b service.
[0247] Figure 9 Shows the filtering structure in the gateway interface.
[0248] Input Gateway Interface 4 ( Figure 1 ) All messages of the communication module 7 are transmitted to the first / second link 50a / 50b of the receiving buffer 53a / 53b of the corresponding gateway interface communication module through the direct access link 51a / 51b.
[0249] In each link of the gateway communication module 7, after the message is written to the corresponding buffer 53a / 53b, an interrupt is generated, and control is transferred to the program 25a / 25b of the message processor 55a / 55b of the filtering service TF1 based on the interrupt, which reads and processes the message that caused the interrupt from the receiving buffer.
[0250] The message processor 55a of the second filtering service 25a of the message received via the first link performs the following functions in the second group of network devices:
[0251] 1) When a broadcast or address message is received via line 80a, an overload registration timeout 56a is periodically triggered on line 83a, with a default duration of 2 seconds. The overload timeout 56a is counted by an interrupt from timer 58 at a frequency of 100 Hz.
[0252] 2) By counting the messages on line 80a and within the overload timeout 56a, record the overflow of line 92a of counter 54a, with a capacity of N messages, and regularly measure the broadcast and address message flow, including broadcast messages SYN, ANZ and broadcast messages not related to the EN2 bus.
[0253] 3) In the absence of an overload and corresponding expiration of counter 54a within timeout 56a, the message processor transfers the ANZ message to the LLC 23a protocol for further transmission via line 18a to a separate common file of the application protocol for recording ANZ messages on buses 1a, 1в, and transfers the TLA address message to the LLC 23a protocol via line 16a for further execution in protocol 26 of one of two identical RPM 24 messages, which is selected according to the numbering process in the RPM redundancy protocol. In addition, the message processor discards other types of messages, including SYN messages.
[0254] Similarly, filtering service TF125b transfers ANZ messages via link B to a common file that transfers ANZ messages via link A.
[0255] 4) During a "broadcast storm," overload of the communication module processor of bus 1a is prevented by interrupt processing on line 87a of all broadcast and address messages buffered in receive buffer 53a during the overload measurement interval initiated by overload timeout 56a. When message counter 54a, indicated on line 92a, overflows, processing of interrupt messages is prevented from the time of the overflow until the expiration of timeout 56a.
[0256] 5) When the first registration counter 54a overflows, the message processor sets the overload flag to state 1. This flag prohibits the recording of ANZ messages into the LLC 23a protocol via line 17a and further transmission along line 18a to the separate common message file of the application protocol 26 on buses 1a and 1c for the entire duration of the broadcast storm, thereby preventing the execution of ANZ messages. The overload flag also prohibits the transmission of TLA address messages via line 16a to the LLC 23a protocol, allowing them to be transmitted to the application protocol via line 18a according to the numbering procedure and further executed after selecting one of the two identical messages within the RPM 24 redundancy service.
[0257] The purpose of the disable is to prevent delayed messages with outdated data from being executed on a damaged bus.
[0258] 6) After 10 consecutive timeouts 56a without overload registration, when the bus overload flag is 0, the prohibition of writing ANZ messages into the LLC1 protocol is cancelled.
[0259] 7) When the overload is registered in the first link and the overload flag is set to 1, an internal message ANZ9811 regarding the SVBU notification of overload on bus 1a is generated and output via bus link 1b.
[0260] 8) When it is detected that the first link is not overloaded and the overload flag is set to 0, an SVBU notification internal message ANZ9821 regarding elimination of overload on bus 1a is generated and output via bus link 1b.
[0261] The message filtering service TF125b, like the TF125a service, performs a filtering function on link B. At this time, the messages ANZ9812 and ANZ9822 generated by the service TF125b perform the functions of the messages ANZ9811 and ANZ9821 generated by the service TF125a.
[0262] Filtration efficiency depends on Figure 8 and Figure 9 Selection of the capacity value N of the message counters 44, 54 and the value of the overload timeout 46, 56 ( Figure 8 、 9 The selected value of N and the overload timeout value should provide reliable registration of broadcast storms and exclude false registration of storms in normal message flows. The default value of N is set to N = 1000 to prevent false storm registrations when the maximum number of automation processors simultaneously sends an ANZ message, which can reach up to nearly 800 in modern nuclear power plant automation systems.
Claims
1. A duplex bus, comprising: The first and second buses are not connected to each other and are configured as point-to-point links according to the switched industrial Ethernet standard, with network switches connected in series to form a virtual ring using Turbo Ring technology; a communication module connecting the redundant automation processors to the bus via first and second links: a switch connected to the first bus via the first link, and a switch connected to the second bus via the second link, wherein each pair of redundant automation processors is linked via an interface between the processors, has a common network address and internal self-control and redundancy management devices; Among them, according to the information model of OSI final machine communication, Ethernet interface standard protocols for managing data transmission via the bus are installed in the communication module of the automation processor: physical protocol PHY on the OSI 1 physical layer, LLC logical boundary protocol and MAC data transmission access protocol on the OSI 2 layer link, as well as APM standard application protocol on the OSI 7 application layer; The invention is characterized in that a communication module is additionally provided in the duplex bus composition to connect the redundant gateway interface to the bus, the module transmits process data and detection information between the bottom automation machine and the upper system of the module according to the information model of the final machine communication of the OSI layers 1, 2, and 7, and has its own network address and is an independent device redundantly managed by the upper system of the module; In the communication module of the automation processor and gateway interface, an RPM redundancy service is added to the OSI layer 7 data transmission general protocol and the OSI layer 1 and 2 standard protocol at OSI layer 7. This service manages the synchronous transmission of address messages and broadcast messages via the first bus and the second bus of the duplex bus according to the LLC protocol in mode 1. The delivery of the address message via at least one bus is confirmed in the RPM service. When receiving the message, the address message is individually numbered according to the L module. When receiving the message, the message sending sequence is analyzed relative to the last received message number and delayed copies of the previously received message are discarded. A message traffic TF filtering service is installed on the first and second links of the OSI layer 2 MAC sublayer of the automation processor for a message traffic consisting of broadcast messages and address messages sent in broadcast mode when the recipient is unreachable, which occurs during a "broadcast storm." A second filtering service TF1 for this message traffic is installed on the first and second links of the OSI layer 2 MAC sublayer gateway interface. This filtering service prevents overloading of the processors of the corresponding communication modules of the automation processor and the gateway interface, as well as preventing the execution of messages that are delayed and contain outdated data during a "broadcast storm."
Citation Information
Patent Citations
Reception of redundant and non-redundant frames
CN101057483A
High redundancy automated control ware able to programme
CN205581535U