Control system and control method

By employing distributed deployment and dynamic switching of multiple controller devices in different environments within the factory process control system, the problem of achieving high availability in cloud environments in existing technologies has been solved, thus realizing high availability and flexibility in factory process control.

CN116360302BActive Publication Date: 2025-11-25YOKOGAWA ELECTRIC CORP +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211607349.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-12-17
Filing Date
2022-12-14
Publication Date
2025-11-25
Estimated Expiration
2042-12-14

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to achieve remote operation and collaboration with external systems when the factory process controller is deployed locally, and it is difficult to achieve the same high availability requirements in a cloud environment as when deployed locally.

Method used

Multiple controller devices are deployed in different local and cloud environments, connected to input/output devices through different communication networks, and control switching and monitoring devices are set up to realize dynamic switching of controller states to reduce downtime and improve availability.

Benefits of technology

In a cloud environment, high availability of factory process control is achieved, downtime of controller devices is reduced, and system reliability and flexibility are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116360302B_ABST
    Figure CN116360302B_ABST
Patent Text Reader

Abstract

An efficient plant process control maintaining high availability can be realized. A process control system (100) has a plurality of controller devices (10) that execute process control of a plant, and an input / output device (20) connected to an object device of the process control. The input / output device (20) is provided in a local deployment environment different from the plurality of controller devices (10), and the plurality of controller devices (10) are connected to the input / output device (20) through respective closed loop networks (40) to transmit and receive information related to the process control of the plant between the input / output device (20).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a control system and a control method. Background Technology

[0002] Currently, the controller devices for process control in the plant are deployed in an on-premises environment (hereinafter, appropriately abbreviated as "on-premises") within the plant.

[0003] At this point, the controller device is constructed from dedicated hardware, resulting in a structure that is less prone to failure and has high availability. Furthermore, the controller device can also implement a redundant structure, thus achieving an even higher availability.

[0004] Patent Document 1: Japanese Patent No. 4099816 5 Summary of the Invention

[0005] However, in the aforementioned prior art, the controller devices for process control are locally deployed, making remote operation and collaboration with external systems (System of Systems) difficult. On the other hand, when a control system is built on a cloud environment (hereinafter appropriately referred to as "the cloud"), the cloud infrastructure and communication infrastructure do not meet the availability requirements for the factory's process control, making it very difficult to achieve the same level of availability as local deployment.

[0006] The purpose of this invention is to achieve effective process control in a factory that maintains high availability.

[0007] 5. To solve the above problems and achieve the objective, the control system involved in this invention has:

[0008] Multiple controller devices that perform process control in a plant; and input / output devices connected to the objects of the process control, wherein the input / output devices are located in a different local deployment environment than the multiple controller devices, the multiple controller devices having a control unit connected to the input / output devices via different communication networks, and the control unit sending and receiving information related to the process control with the input / output devices.

[0009] Furthermore, the control method involved in this invention is a control method executed by a control system, which has: a plurality of controller devices that perform process control of a plant; and input / output devices connected to the object of the process control, wherein the input / output devices are located in a different local deployment environment than the plurality of controller devices, and the plurality of controller devices are connected to the input / output devices through different communication networks to perform processing of sending and receiving information related to the process control with the input / output devices.

[0010] The effects of the invention

[0011] In this invention, effective process control of the factory that maintains high availability can be achieved. Attached Figure Description

[0012] Figure 1 This is a diagram illustrating an example of the structure of the process control system involved in the implementation method.

[0013] Figure 2 It is a diagram that shows an overview of the current process control system.

[0014] Figure 3 This is a block diagram illustrating structural examples of the various devices involved in the implementation of the process control system.

[0015] Figure 4 This is a diagram illustrating a specific example 1 of the process control system involved in the implementation method.

[0016] Figure 5 This is a diagram illustrating a specific example 2 of the process control system involved in the implementation method.

[0017] Figure 6 This is a diagram illustrating a specific example 3 of the process control system involved in the implementation method.

[0018] Figure 7 This is a flowchart illustrating an example of the process control processing involved in the implementation method.

[0019] Figure 8 This is a flowchart illustrating an example of the process control processing involved in the implementation method.

[0020] Figure 9 This is a diagram illustrating an example of the hardware structure of the controller device according to the implementation method. Detailed Implementation

[0021] Hereinafter, with reference to the accompanying drawings, a detailed description will be given of the embodiments (appropriately referred to as embodiments) for carrying out the control system and control method involved in the present invention. Furthermore, the present invention is not limited to the embodiments described below.

[0022] [Implementation Method]

[0023] The following sections will describe in sequence the structure of the process control system 100 involved in the embodiments, the overview of the current process control system 100-P, the structure of each device involved in the embodiments, specific examples of the process control system 100, the flow of each process, and finally the effects of the embodiments.

[0024] [1. Structure of the process control system 100]

[0025] use Figure 1 The structure of the process control system 100 involved in the implementation method will be described in detail. Figure 1 This is a diagram illustrating the structure of the process control system involved in the embodiment. Below, based on an example showing the structure of the entire process control system 100, the explanation will proceed in the order of control data transmission and reception processing, state switching processing of the external monitoring device 60, and state switching processing of the internal monitoring device 70.

[0026] (1-1. Structural Example of a Process Control System 100)

[0027] First, the structure of the entire process control system (hereinafter also appropriately referred to as the System) 100 involved in the implementation will be described in detail. Furthermore, in this implementation, a factory process control is described as an example, but the application is not limited to this; it can be applied to various systems that control target equipment based on the controller device 10.

[0028] This system 100 includes controller devices 10 (10A, 10B), input / output devices 20, local deployment terminals 30 (30A, 30B), closed-loop network 40 (40A, 40B), control switching devices 50 (50A, 50B), external monitoring devices 60, internal monitoring devices 70 (70A, 70B), and field devices 90 (sensors 91, actuators 92). Furthermore, as an environment for setting up the aforementioned devices, this system 100 includes data centers 1, 2, and 3 for building cloud environments, and local deployments within factory premises, etc.

[0029] exist Figure 1 Data center 1 is equipped with an active controller device 10A, a control switching device 50A, and an internal monitoring device 70A. The controller device 10A, control switching device 50A, and internal monitoring device 70A are communicatively connected via a wired or wireless communication network (not shown). Each of the aforementioned controller device 10A, control switching device 50A, and internal monitoring device 70A is implemented using cloud services. For example, each device can be implemented as a virtual machine, container, etc., virtually generated using physical resources such as physical memory, physical processors, and physical disks within data center 1. Furthermore, each device is not limited to cloud services such as virtual machines; it can be implemented by a shell, a host, or a physically installed physical device. Moreover, data center 1 may contain multiple controller devices 10A, multiple control switching devices 50A, and multiple internal monitoring devices 70A.

[0030] exist Figure 1Data center 2 is equipped with a controller device 10B, a control switching device 50B, and an internal monitoring device 70B in standby mode. The controller device 10B, control switching device 50B, and internal monitoring device 70B are communicatively connected via a specified communication network (not shown) through wired or wireless means. Each of the aforementioned controller device 10B, control switching device 50B, and internal monitoring device 70B is implemented using cloud services. For example, each device can be virtually implemented using physical resources within data center 2. Furthermore, each device can be implemented using a housing, a host, or a physical device. Moreover, data center 2 can contain multiple controller devices 10B, multiple control switching devices 50B, and multiple internal monitoring devices 70B.

[0031] exist Figure 1 The data center 3 is equipped with external monitoring devices 60, which are implemented using physical devices or virtually implemented using physical resources. The data center 3 may contain multiple external monitoring devices 60.

[0032] exist Figure 1 In the example shown, two different data centers equipped with controller devices 10 are illustrated, but there may also be three or more different data centers equipped with controller devices 10. Additionally, there may be two or more different data centers equipped with external monitoring devices 60. Furthermore, the various devices contained in each data center can be communicatively connected via a specified communication network (not shown) through wired or wireless means.

[0033] exist Figure 1 The local deployment includes input / output devices 20, local deployment terminals 30A and 30B. The input / output devices 20, local deployment terminals 30A and 30B are communicatively connected via a defined communication network using wired or wireless means. Furthermore, the aforementioned local deployment may include multiple input / output devices 20, multiple local deployment terminals 30A, and multiple local deployment terminals 30B.

[0034] Here, the input / output device 20 is implemented by a physically installed device, deployed in a local environment, i.e., a factory, and connected to field devices 90 such as sensors 91 and actuators 92. Furthermore, the input / output device 20 is connected to the controller device 10A located in data center 1 via a closed-loop network 40A (as a dedicated line) and a local deployment terminal 30A (as a data gateway, etc.). Similarly, the input / output device 20 is connected to the controller device 10B located in data center 2 via a closed-loop network 40B and a local deployment terminal 30B. Additionally, the input / output device 20 can also be connected to the controller device 10 located in a data center (not shown) via a closed-loop network 40 and a local deployment terminal 30.

[0035] (1-2. Control data transmission and reception processing)

[0036] Next, the processing of control data transmission and reception will be explained as part of the process control system 100. For example... Figure 1 As shown, the controller device 10A, which is in the active state and located in data center 1, transmits and receives control data with the input / output device 20 (see reference). Figure 1 (1)).

[0037] For example, controller device 10A receives control data acquired by input / output device 20 from field device 90 within the factory. On the other hand, input / output device 20 receives control data from controller device 10A and supplies it to field device 90 within the factory. Through this processing, the control data is reflected in the factory's process control. Furthermore, in Figure 1 In the example, the controller device 10B in the standby state of the data center 2 does not send or receive control data with the input / output device 20, but multiple controller devices 10 in the active state can send and receive control data.

[0038] Here, control data refers to data including process data and control parameters. Examples of process data include the detection results (e.g., pressure, temperature, flow rate, etc.) of sensor 91, which is a field device 90. Examples of control parameters include the setting parameters for plant operation control, such as the set value of actuator 92, which is a field device 90. Each controller device 10 uses the control data to perform simulations and other calculations, and uses the calculation results to perform plant control. Furthermore, plant control includes various controls that contribute to the safe operation of the plant, such as changes in valve opening / closing amounts and changes in resource flow within the plant.

[0039] (1-3. Status switching process for external monitoring device 60)

[0040] Next, the state switching process of the external monitoring device 60 will be explained as part of the process control system 100's processing. For example... Figure 1 As shown, the external monitoring device 60 installed in data center 3 switches between active and standby states under the pretext of planned maintenance (see reference). Figure 1 (2)).

[0041] For example, external monitoring device 60 receives a notification regarding planned maintenance of cloud infrastructure and communication infrastructure. In this case, if controller device 10A is the target of maintenance, external monitoring device 60 sends a state switching notification to control switching device 50A. Upon receiving this notification, control switching device 50A switches the state of controller device 10A from active state to standby state, then to stopped state, at a specified time. Conversely, external monitoring device 60 sends a state switching notification to control switching device 50B. Upon receiving this notification, control switching device 50B switches the state of controller device 10B from standby state to active state, at a specified time.

[0042] (1-4. State switching process for internal monitoring device 70)

[0043] Finally, as part of the process control system 100's processing, the state switching process implemented based on the internal monitoring device 70 will be explained. For example... Figure 1 As shown, the internal monitoring device 70, installed in data center 1 or data center 2, switches between active and standby states under the pretext of cloud or communication failures (see reference). Figure 1 (3)).

[0044] For example, internal monitoring devices 70 (70A, 70B) monitor the status of cloud infrastructure and communication infrastructure. If an anomaly occurs in the cloud infrastructure or communication infrastructure, the internal monitoring device 70 sends a notification to the control switching device 50. Specifically, if an anomaly occurs in the cloud infrastructure related to data center 1, the internal monitoring device 70A detects the anomaly and sends a notification related to the anomaly to the control switching device 50A. Upon receiving the notification, the control switching device 50A switches the state of the controller device 10A from active to standby / stop at a specified time. Conversely, upon receiving the notification, the control switching device 50B switches the state of the controller device 10B from standby to active at a specified time.

[0045] [2. Overview of the current process control system]

[0046] Here, the differences between the current process control system 100-P and the process control system 100 according to the embodiment will be explained. Below, based on the explanation of the current process control system 100-P, the process control system 100 according to the embodiment will be explained.

[0047] (2-1. Current process control system 100-P)

[0048] use Figure 2 The current process control system 100-P is described. Figure 2This is a diagram showing an overview of the current process control system. For example... Figure 2 As shown, the current process control system 100-P has an active controller device 10 and input / output devices 20. Furthermore, the controller device 10 and input / output devices 20 are installed in a local deployment environment such as within a factory. In this case, the controller device 10 is constructed using dedicated hardware, thus forming a structure that is less prone to failure and has high availability. In addition, the controller device 10 can also be redundant, thus achieving even higher availability.

[0049] However, the current process control system 100-P has the following problems. First, the current process control system 100-P is locally deployed, making remote operation and collaboration with external systems difficult. Second, the current process control system 100-P has hardware devices, thus increasing maintenance costs.

[0050] To address the aforementioned issues with on-premises deployment, the flexible application of controller device 10 in a cloud environment was considered, but the following problems exist. As a prerequisite, the high availability of controller device 10, which performs process control in factories, etc., means ensuring the continuous operation of a control system with a periodic cycle, such as a 1-second cycle, 24 / 7, 365 days a year. That is, when building a control system in the cloud, the cloud infrastructure, such as data centers, and the communication infrastructure between the cloud and on-premises deployments, need to meet this requirement. However, there are no cloud providers or communication infrastructure providers capable of guaranteeing this requirement, making it very difficult to achieve the same level of availability in the cloud as on-premises deployments.

[0051] (2-2. Process Control System 100)

[0052] In contrast, as described above, the implementation methods involve Figure 1 The process control system 100 shown includes: multiple controller devices 10 that perform process control in the plant; and input / output devices 20 connected to the devices to be controlled by the process. Here, the input / output devices 20 are located in a different local deployment environment than the multiple controller devices 10. Furthermore, the multiple controller devices 10 are connected to the input / output devices 20 via different closed-loop networks 40, and exchange process control-related information with the input / output devices 20. In this way, the process control system 100 places the multiple controller devices 10 in different data centers and connects them using different communication paths, thereby minimizing the possibility of all multiple controller devices 10 being in a stopped state and reducing downtime.

[0053] Furthermore, as described above, the implementation methods involve Figure 1The process control system 100 shown further includes: a control switching device 50 that switches the state of a plurality of controller devices 10 to an active state, a standby state, or a stopped state; and a monitoring device that receives information related to the switching of the state of the controller devices 10 (e.g., planned maintenance notification, cloud, communication failure). Here, upon receiving a notification related to the state switching from the monitoring device, the control switching device 50 switches the state of at least one of the plurality of controller devices 10 to an active state. That is, the process control system 100 notifies the planned maintenance in advance and switches the active and standby states of the controller devices 10 in advance, thereby reducing the downtime of the controller devices 10. In addition, when a fault occurs or when there are signs of a fault that affect the operation of the controller devices 10, the process control system 100 switches the active and standby states of the controller devices 10 in advance, thereby reducing the downtime of the controller devices 10.

[0054] [3. Processing of each device]

[0055] use Figure 3 The processing of each device constituting the process control system 100 is described in detail. Figure 3 This is a block diagram illustrating the structural examples of each device in the process control system according to the embodiment. The following description follows the order of controller device 10 (10A, 10B), input / output device 20, local deployment terminal 30 (30A, 30B), closed-loop network 40 (40A, 40B), control switching device 50 (50A, 50B), external monitoring device 60, and internal monitoring device 70 (70A, 70B).

[0056] (3-1. Controller device 10)

[0057] The controller unit 10 performs process control in the factory. At this time, multiple controller units 10 (10A, 10B) are connected to the input / output device 20 via different communication networks. For example, multiple controller units 10 (10A, 10B) are connected to the input / output device 20 via different closed-loop networks 40 (40A, 40B) or the Internet. Furthermore, the multiple controller units 10 (10A, 10B) are located in different data centers.

[0058] The control unit 11 (11A, 11B) of the controller device 10 sends and receives information (control data) related to process control with the input / output device 20.

[0059] (3-2. Input / output devices 20)

[0060] Input / output device 20 is connected to the process control device and sends and receives control data with it. For example, input / output device 20 may be located in a local deployment environment different from the multiple controller devices 10, and send and receive control data with the process control device. Specifically, input / output device 20 may be connected to field devices 90 such as sensors 91 and actuators 92 in a factory under local deployment, and acquire control data from these field devices 90. In this case, as control data, input / output device 20 acquires process data such as the detection results (e.g., pressure, temperature, flow rate, etc.) of sensor 91 (which is a field device 90), and control parameters such as the setpoints of actuators 92 (which is a field device 90).

[0061] (3-3. Locally deployed terminal 30)

[0062] As a data gateway such as a router, the local deployment terminal 30 relays data communication between the controller device 10 and the input / output device 20. For example, the local deployment terminal 30 is connected to the input / output device 20, and also connected to the controller device 10 through a closed-loop network 40, relaying the transmission and reception of control data between the controller device 10 and the input / output device 20.

[0063] (3-4. Closed-loop network 40)

[0064] The closed-loop network 40 is an example of a communication network used to implement periodic communication such as a 1-second cycle. For example, it can be connected as a dedicated line for controller devices 10 located in various data centers to enable data communication between controller devices 10 and input / output devices 20. For example, multiple closed-loop networks 40 (40A, 40B) are connected to multiple controller devices 10 (10A, 10B) respectively in a manner that enables the transmission and reception of control data. In addition, the closed-loop network 40 is connected to the input / output devices 20 via a local deployment terminal 30 in a manner that enables the transmission and reception of control data.

[0065] In addition, Figure 1 , Figure 3 In the example, the use of closed-loop network 40 as a communication network is not particularly limited as long as it connects the cloud to the local deployment. For example, in the process control system 100, the Internet can be used instead of closed-loop network 40 as the aforementioned communication network. Furthermore, in order to achieve periodicity such as a 1-second cycle in the process control system 100, it is preferable to use closed-loop network 40, which has lower communication latency compared to the Internet.

[0066] (3-5. Control switching device 50)

[0067] The switching control unit 51 of the control switching device 50 switches the state of the controller device 10 to an active state, a standby state, or a stopped state. For example, when a notification related to the switching of the state of the controller device 10 is received from an external monitoring device 60 or an internal monitoring device 70, the switching control unit 51 of the control switching device 50 switches the state of at least one of the multiple controller devices 10 to an active state. Furthermore, details of the state switching process of the control switching device 50 will be described later in [4. Specific Examples of the Process Control System 100] and [5. Flowcharts of Each Process].

[0068] (3-6. External monitoring device 60)

[0069] The receiving unit 61 of the external monitoring device 60 receives information related to the switching of the state of the controller device 10. Additionally, the notification unit 62 of the external monitoring device 60 sends notifications related to the switching of the state of the controller device 10 to each control switching device 50 (50A, 50B) installed in each data center. At this time, the external monitoring device 60 is installed in a different data center than each data center where multiple controller devices 10 (10A, 10B) are respectively installed.

[0070] As a specific example, the receiving unit 61 of the external monitoring device 60 receives planned maintenance information from a cloud provider or communication provider, as information related to the switching of the state of the controller device 10. This planned maintenance is related to the operation of each data center and each controller device 10. For example, maintenance may include maintenance within each data center that provides physical resources to each controller device 10, and may include version upgrades of various software such as processor and hardware enhancements, virtualization software such as virtual machines, and container software that implements containers.

[0071] (3-7. Internal monitoring device 70)

[0072] The receiving unit 71 of the internal monitoring device 70 receives information related to the state switching of the controller device 10. Additionally, the notification unit 72 of the internal monitoring device 70 sends notifications related to the state switching of the controller device 10 to the control switching devices 50 installed in each data center. At this time, the internal monitoring device 70 is installed in each data center where multiple controller devices 10 (10A, 10B) are respectively installed.

[0073] As a specific example, the receiving unit 71 of the internal monitoring device 70 receives information related to faults in the cloud infrastructure or communication infrastructure, as information related to the switching of the state of the controller device 10. Here, the receiving unit 71 of the internal monitoring device 70 can detect the depletion of hardware resources within the data center and receive it as fault-related information. For example, the receiving unit 71 of the internal monitoring device 70 detects insufficient physical memory, insufficient virtual memory, interruption or convergence of communication paths within the data center, interruption or convergence of communication paths between data centers, and a decrease in communication speed between the data center and local deployments. Furthermore, known fault detection software can be used for detection.

[0074] [4. Specific examples of process control system 100]

[0075] use Figures 4-6 A specific example of the process control system 100 involved in the implementation method will be described in detail. Figures 4-6 This is a diagram illustrating a specific example of the process control system involved in the implementation method.

[0076] (4-1. Specific example 1)

[0077] As a specific example 1, using Figure 4 An example of the structure of a process control system 100-1 that does not have a control switching device 50, an external monitoring device 60, an internal monitoring device 70, or other monitoring devices will be described. Furthermore, in Figure 4 in, omit Figure 1 as well as Figure 3 The factory and its constituent structures are shown. Additionally, the structures of the controller device 10, input / output devices 20, local deployment terminals 30, and closed-loop network 40 are described. Figure 1 and Figure 3 Since they are the same, the explanation is omitted.

[0078] Below, on Figure 4 The key features of the process control system 100-1 shown will be explained below. First, in the process control system 100-1, controller devices 10A and 10B are located in data centers 1 and 2, which serve as external data centers. Second, in the process control system 100-1, the communication path is configured as a low-latency environment using a closed-loop network 40, etc. Third, in the process control system 100-1, the controller devices 10 are configured with a redundant structure of active and standby states, as described above, and are located in different data centers. Furthermore, in the process control system 100-1, separate communication paths are pre-prepared, thereby referring to the controller devices 10 to the input / output devices 20 as different systems.

[0079] As with the process control system 100-1 described above, the process control system 100 can also be implemented without a control switching device 50, an external monitoring device 60, an internal monitoring device 70, or other monitoring devices. In the process control system 100-1, the controller devices 10 are made redundant, thereby preventing both controller devices 10 from stopping due to a single failure or maintenance, whether in active or standby state. Furthermore, in the process control system 100-1, communication paths for each controller device 10 are provided, allowing for a structure that adheres to a 1-second cycle for process control.

[0080] (4-2. Specific example 2)

[0081] As a specific example 2, using Figure 5 An example of the structure of a process control system 100-2 that only has an external monitoring device 60 as a monitoring device will be described. Furthermore, in Figure 5 In Chinese, only means Figure 1 and Figure 3 The structures contained in Data Center 1 and Data Center 3 are shown; other structures are omitted.

[0082] Below, on Figure 5 The key points of the process control system 100-2 shown will be explained. First, in the process control system 100-2, an external monitoring device 60 is installed for monitoring cloud infrastructure and communication infrastructure. Figure 5 In this case, the external monitoring device 60 is located in a data center 3 that is different from the data centers 1 and 2 that are equipped with controller devices 10A and 10B, but it can also be configured in the same data center as the controller device 10.

[0083] Secondly, in the process control system 100-2, the control switching device 50 is located in the same data center as the controller device 10. Figure 5 In this case, the control switching device 50A is installed in the data center 1 where the controller device 10A is installed, but it can also be configured in other data centers not shown.

[0084] Third, in the process control system 100-2, when switching control of the controller device 10's state is required to monitor the status of the cloud infrastructure and communication infrastructure, the external monitoring device 60 notifies the control switching device 50. For example... Figure 5 As shown, the external monitoring device 60 obtains cloud infrastructure maintenance information from the cloud provider. Similarly, the external monitoring device 60 obtains communication infrastructure maintenance information from the communication provider. Furthermore, the determination of whether to perform handover control can be based on a pre-set benchmark by the system administrator, or it can be configured so that the system administrator can manually perform the handover control.

[0085] Fourth, in the process control system 100-2, if the control switching device 50 acquires the aforementioned known information, the state switch of the controller device 10 is performed before the planned maintenance indicated by the known information is stopped. For example... Figure 5 As shown, the control switching device 50 obtains known information from the external monitoring device 60, including time information related to planned maintenance, and switches the active controller device 10A to a standby state or a stopped state. At this time, the control switching device 50 obtains the aforementioned known information via email or SMS (Short Message Service), but the method of acquisition is not particularly limited. Additionally, the control switching device 50 can obtain time information related to planned maintenance (e.g., maintenance start time, maintenance end time, etc.) from the external monitoring device 60, or it can obtain it as input data from operators, etc. Furthermore, the control switching device 50 performs state switching control of the controller device 10A via API (Application Programming Interface), but the switching method is not particularly limited.

[0086] As with the process control system 100-2 described above, the process control system 100 can also be configured to have a control switching device 50 and an external monitoring device 60, but without an internal monitoring device 70. In this case, even if the controller device 10, which is activated due to planned maintenance, stops, the process control system 100-2 can still comply with the 1-second cycle of the plant's process control.

[0087] (4-3. Specific example 3)

[0088] As a specific example 3, using Figure 6 A structural example of a process control system 100-3, which only has an internal monitoring device 70 as a monitoring device, will be described. Furthermore, in... Figure 6 In Chinese, only means Figure 1 and Figure 3 The structures included in Data Center 1 shown are omitted except for those other than those shown.

[0089] Below, on Figure 6 The key points of the process control system 100-3 shown will be explained. First, the process control system 100-3 includes an internal monitoring device 70 for monitoring cloud infrastructure and communication infrastructure. Figure 6 In this case, the internal monitoring device 70A is installed in the data center 1 where the controller device 10A is installed, but it can also be configured in a different data center than the controller device 10A.

[0090] Secondly, in the process control system 100-3, the control switching device 50 is located in the same data center as the controller device 10. Figure 6 In this case, the control switching device 50A is installed in the data center 1 where the controller device 10A is installed, or it can be configured in other data centers not shown.

[0091] Third, in the process control system 100-3, the internal monitoring device 70 monitors the status of the cloud infrastructure and communication infrastructure, and notifies the control switching device 50 when a switch control of the controller device 10's status is required. Figure 6 As shown, the internal monitoring device 70A monitors the monitored objects 80 (80A, 80B, 80C, 80D) within the data center 1 to obtain various information. At this time, the internal monitoring device 70 monitors the resource status (e.g., CPU (Central Processing Unit), disk I / O) within the cloud infrastructure, and notifies the control switching device 50 if there is a possibility that it may affect the execution of the controller device 10. Furthermore, as a sensor virtual machine, the internal monitoring device 70 periodically monitors the communication path from the cloud to the local deployment, and notifies the control switching device if unacceptable communication delays occur. Moreover, the determination of whether to perform switching control can be based on a pre-set benchmark by the system administrator, or it can be configured so that the system administrator can manually perform switching control.

[0092] Fourth, in the process control system 100-3, in situations that may affect the execution of the controller device 10, the control switching device 50 switches the state of the controller device 10. That is, upon receiving a notification (fault control notification) from the internal monitoring device 70 indicating a detected anomaly, the control switching device 50 switches the state of the controller device 10. Figure 6 As shown, the control switching device 50 obtains a fault control notification from the internal monitoring device 70, acquires time information related to the fault, and switches the active controller device 10A to a standby state or a stopped state. At this time, the control switching device 50 obtains the aforementioned fault control notification via an API system call, but the method of acquisition is not particularly limited. Alternatively, the control switching device 50 can obtain fault-related time information (e.g., the time period during which a communication fault is anticipated) from the internal monitoring device 70, or it can obtain it as input data from operators, etc. Furthermore, the control switching device 50 performs state switching control of the controller device 10A via an API, but the switching method is not particularly limited.

[0093] Like the process control system 100-3 described above, the process control system 100 can also be configured to have a control switching device 50 and an internal monitoring device 70, but without an external monitoring device 60. In this case, even if the controller device 10, which is in an active state, stops due to a failure of the cloud infrastructure or communication infrastructure, the process control system 100-3 can still comply with the 1-second cycle of the plant's process control.

[0094] [5. Process flow for each step]

[0095] use Figure 7 and Figure 8 The process control procedures involved in the implementation method are described. Figure 7 and Figure 8 This is a flowchart illustrating an example of the process control processing involved in the implementation method. The flow chart for the state switching processing of the external monitoring device 60 and the internal monitoring device 70 will be described in detail below, in particular.

[0096] (5-1. Flowchart for the state switching of external monitoring device 60)

[0097] use Figure 7 The process for handling the state switching of the external monitoring device 60 is described in detail. Furthermore, steps S101 to S111 below can be executed in a different order. Additionally, omitted processes and states from steps S101 to S111 below may also be included.

[0098] like Figure 1 As shown, an example is given in which the controller device 10A located in data center 1 is in an active state (step S101) and the controller device 10B located in data center 2 is in a standby state (step S102).

[0099] First, the external monitoring device 60, located in data center 3, obtains maintenance information as planned maintenance information from the cloud provider and communication provider (step S103). Next, the external monitoring device 60 sends a maintenance control notification for planned maintenance to the control switching device 50A located in data center 1 (step S104). Additionally, the external monitoring device 60 sends a maintenance control notification for planned maintenance to the control switching device 50B located in data center 2 (step S105).

[0100] Next, the control switching device 50A acquires time information such as the implementation period of the planned maintenance (step S106). Similarly, the control switching device 50B acquires time information such as the implementation period of the planned maintenance (step S107). At this time, the control switching devices 50A and 50B can acquire the aforementioned time information from the external monitoring device 60, or as input data from operators or the like.

[0101] Furthermore, the control switching device 50A performs a state switch on the controller device 10A (step S108). As a result, the controller device 10A, which is in an active state, switches to a standby state or a stopped state (step S110). On the other hand, the control switching device 50B performs a state switch on the controller device 10B (step S109). As a result, the controller device 10A, which is in a standby state, switches to an active state (step S111).

[0102] (5-2. Flowchart for state switching of internal monitoring device 70)

[0103] use Figure 8 The process for handling the state switching of the internal monitoring device 70 is described in detail. Furthermore, steps S201 to S212 can be executed in a different order. Additionally, omitted processes and states from steps S201 to S212 may also be included.

[0104] like Figure 1 As shown, an example is given in which the controller device 10A located in data center 1 is in an active state (step S201) and the controller device 10B located in data center 2 is in a standby state (step 202).

[0105] First, the internal monitoring device 70A, located in data center 1, acquires monitoring results of internal resources related to the cloud infrastructure and communication infrastructure of data center 1, i.e., internal resource information (step S203). Similarly, the internal monitoring device 70B, located in data center 2, acquires monitoring results of internal resources related to the cloud infrastructure and communication infrastructure of data center 2, i.e., internal resource information (step S204). At this time, the internal monitoring devices 70A and 70B can share the internal resource information via a communication network (not shown).

[0106] Next, in the event that a failure may occur due to the aforementioned internal resource information, the internal monitoring device 70A sends a fault control notification to the control switching device 50A located in data center 1, citing a failure of the cloud infrastructure or communication infrastructure as the reason (step S205). Additionally, the internal monitoring device 70B sends a fault control notification to the control switching device 50B located in data center 2, citing a failure of the cloud infrastructure or communication infrastructure as the reason (step S206).

[0107] Next, the control switching device 50A acquires time information such as the period when the communication failure occurred (step S207). Similarly, the control switching device 50B acquires time information such as the period when the communication failure occurred (step S208). At this time, the control switching devices 50A and 50B can acquire the aforementioned time information from the internal monitoring device 70A or the internal monitoring device 70B, or they can acquire it as input data from operators or the like.

[0108] Furthermore, the control switching device 50A performs a state switch on the controller device 10A (step S209). As a result, the controller device 10A, which is in an active state, switches to a standby state or a stopped state (step S211). On the other hand, the control switching device 50B performs a state switch on the controller device 10B (step S210). As a result, the controller device 10A, which is in a standby state, switches to an active state (step S212).

[0109] [6. Effects of the Implementation Method]

[0110] First, the process control system 100 according to this embodiment includes: multiple controller devices 10 that perform process control of the factory; and input / output devices 20 connected to the process control objects. The input / output devices 20 are located in a different local deployment environment than the multiple controller devices 10. The multiple controller devices 10 are connected to the input / output devices 20 through different communication networks and exchange information related to process control with the input / output devices 20. Therefore, the process control system 100 enables effective factory process control with high availability.

[0111] Secondly, in the process control system 100 described in this embodiment, multiple controller devices 10 are located in different data centers. The process control system 100 further includes: a control switching device 50 that switches the state of the multiple controller devices 10 to an active state, a standby state, or a stopped state; and a monitoring device that receives information related to the switching of the state of the controller devices 10. Upon receiving a notification related to the switching of the state of the controller devices 10 from the monitoring device, the control switching device 50 switches the state of at least one of the multiple controller devices 10 to an active state. Therefore, in the process control system 100, effective factory process control with high availability can be achieved in a cloud environment.

[0112] Third, in the process control system 100 described in this embodiment, the monitoring device is located in a different data center than each data center where multiple controller devices 10 are respectively located, and sends notifications related to the switching of the state of the controller devices 10 to each control switching device 50 located in each data center. Therefore, in the process control system 100, in a cloud environment, effective factory process control with high availability can be achieved through an external monitoring device.

[0113] Fourth, in the process control system 100 described in this embodiment, the monitoring device receives planned maintenance information from a cloud provider or communication provider as information related to the switching of the state of the controller device 10. Therefore, in the process control system 100, even in a cloud environment where planned maintenance of cloud infrastructure or communication infrastructure is required using an external monitoring device, effective factory process control with high availability can be achieved.

[0114] Fifth, in the process control system 100 described in this embodiment, a monitoring device is installed in each data center where multiple controller devices are respectively installed, and the monitoring device sends notifications related to the switching of the state of the controller device 10 to the control switching devices installed in each data center. Therefore, in the process control system 100, in a cloud environment, effective factory process control with high availability can be achieved by utilizing the internal monitoring device.

[0115] Sixth, in the process control system 100 described in this embodiment, the monitoring device receives information related to the switching of the state of the controller device 10, as well as information related to faults in the cloud infrastructure or communication infrastructure. Therefore, in the process control system 100, even in a cloud environment where faults in the cloud infrastructure or communication infrastructure occur using the internal monitoring device, effective factory process control with high availability can be achieved.

[0116] Seventh, in the process control system 100 described in this embodiment, multiple controller devices 10 are connected to the input / output devices 20 using different closed-loop networks 40, and exchange information related to process control with the input / output devices 20. Therefore, in the process control system 100, effective factory process control with high availability and lower communication latency can be achieved.

[0117] [system]

[0118] The processing order, control order, specific names, and information including various data and parameters shown in the above-mentioned specification and figures may be changed arbitrarily, except where specifically stated.

[0119] Furthermore, the structural elements of each device illustrated are functional concepts and do not require them to be physically arranged as shown in the diagram. That is, the specific distribution and integration of the devices are not limited to the manner illustrated. In other words, they can be distributed / integrated functionally or physically in any unit according to various loads, usage conditions, etc., to constitute all or part of them.

[0120] Furthermore, all or any part of the processing functions performed in each device can be implemented by a CPU and a program executed by the CPU, or can be implemented as wired logic-based hardware.

[0121] [hardware]

[0122] Next, an example of the hardware structure of the controller device 10 will be described. Other devices may also be configured with the same hardware structure. Figure 9 This diagram illustrates an example of the hardware structure involved in the implementation method. For example... Figure 9 As shown, the controller device 10 includes a communication device 10a, an HDD (Hard Disk Drive) 10b, a memory 10c, and a processor 10d. Additionally, Figure 9 The various parts shown are connected to each other by buses, etc.

[0123] Communication device 10a is a network interface card, etc., used for communication with other servers. HDD 10b is used for... Figure 3 The program that performs the shown functions is stored in the database.

[0124] Processor 10d reads and executes data from HDD10b, etc. Figure 3 The program shown is processed and expanded in memory 10c, thereby enabling execution. Figure 3 The process of performing each function as described in the text will be carried out.

[0125] Thus, the controller device 10 operates as a means of reading and executing programs to perform various processing methods. Furthermore, the controller device 10 can also read the aforementioned program from a recording medium via a media reading device and execute the read program, thereby achieving the same functionality as in the above-described embodiment. Moreover, the programs described in other embodiments are not limited to execution by the controller device 10. For example, the present invention can also be applied when other computers or servers execute programs, or when the aforementioned devices cooperate in executing programs.

[0126] The program can be configured via networks such as the Internet. Furthermore, the program is recorded on computer-readable media such as hard disks, floppy disks (FD), CD-ROMs, MO (Magneto-Optical disk), and DVDs (Digital Versatile Discs), and can be read and executed by a computer from the recording medium.

[0127] [other]

[0128] The following are some examples of combinations of the disclosed technical features.

[0129] (1) A control system comprising: a plurality of controller devices that perform process control of a plant; and input / output devices connected to the object of the process control, wherein the input / output devices are located in a local deployment environment different from the plurality of controller devices, the plurality of controller devices having a control unit connected to the input / output devices via different communication networks, and receiving and sending information related to the process control with the input / output devices.

[0130] (2) The control system according to (1), wherein the plurality of controller devices are located in different data centers, the control system further comprises: a control switching device that switches the state of the plurality of controller devices to an active state, a standby state, or a stopped state; and a monitoring device that receives information related to the switching of the state, the control switching device switching control unit that, upon receiving a notification related to the switching of the state from the monitoring device, switches the state of at least one of the plurality of controller devices to an active state.

[0131] (3) According to the control system described in (2), wherein the monitoring device has a notification unit located in a data center different from each data center in which the plurality of controller devices are respectively located, and sends a notification related to the switching of the state to each control switching device located in each data center.

[0132] (4) The control system according to (2) or (3), wherein the monitoring device has a receiving unit that receives planned maintenance information from a cloud provider or communication provider as information related to the switching of the state.

[0133] (5) The control system according to any one of (2) to (4), wherein the monitoring device is provided in each data center where the plurality of controller devices are respectively provided, and the notification unit of the monitoring device sends a notification related to the switching of the state to the control switching device provided in each data center.

[0134] (6) The control system according to any one of (2) to (5), wherein the receiving unit of the monitoring device receives information related to the failure of the cloud infrastructure or communication infrastructure as information related to the switching of the state.

[0135] (7) The control system according to any one of (1) to (6), wherein the communication network is a closed-loop network.

[0136] (8) A control method, which is a control method executed by a control system, the control system having: a plurality of controller devices that perform process control of a plant; and input / output devices connected to the object of the process control, wherein the input / output devices are located in a local deployment environment different from the plurality of controller devices, the plurality of controller devices being connected to the input / output devices through different communication networks, and performing processing of sending and receiving information related to the process control with the input / output devices.

Claims

1. A control system having: Multiple controller devices that perform process control in the plant; Input / output devices connected to the object device being controlled in the process; A control switching device that switches the states of the plurality of controller devices to an active state, a standby state, or a stopped state; and A monitoring device that receives information related to the switching of the stated state. in, The control switching device includes a switching control unit that, upon receiving a notification from the monitoring device related to the state switching, switches the state of at least one of the plurality of controller devices to an active state. The input / output devices are configured in a different local deployment environment than the plurality of controller devices. The plurality of controller devices each have a control unit that is connected to the input / output devices via different communication networks, and that communicates with the input / output devices to send and receive information related to the process control. The monitoring device has: An external monitoring device, located in a different data center from the data centers where the plurality of controller devices are respectively located, monitors planned maintenance information notified from cloud providers and communication providers, and switches the status of the controller devices based on the planned maintenance information; as well as Multiple internal monitoring devices are installed in each data center where the multiple controller devices are respectively installed, to monitor information related to faults in cloud infrastructure or communication infrastructure, and to switch the state of the controller devices according to the fault information.

2. The control system according to claim 1, wherein, The external monitoring device has a notification unit that sends notifications related to the state switching to each control switching device located in each of the data centers.

3. The control system according to claim 1, wherein, The external monitoring device has a receiving unit that receives planned maintenance information from a cloud provider or communications provider as information related to the switching of the state.

4. The control system according to claim 1, wherein, Each of the internal monitoring devices has a notification unit that sends notifications related to the state switching to the control switching devices located in each of the data centers.

5. The control system according to claim 1, wherein, Each of the internal monitoring devices has a receiving unit that receives information related to faults in the cloud infrastructure or communication infrastructure as information related to the switching of the state.

6. A control method, which is a control method executed by a control system, the control system having: Multiple controller devices that perform process control in the plant; Input / output devices connected to the object device being controlled in the process; A control switching device that switches the states of the plurality of controller devices to an active state, a standby state, or a stopped state; and A monitoring device that receives information related to the switching of the stated state. in, Upon receiving a notification from the monitoring device related to the state switch, the control switching device switches the state of at least one of the plurality of controller devices to an active state. The input / output devices are configured in a different local deployment environment than the plurality of controller devices. The plurality of controller devices are connected to the input / output devices through different communication networks, and exchange information related to the process control with the input / output devices. The monitoring device performs the following processing: Located in a different data center from the data centers where the multiple controller devices are respectively located, the controller device monitors planned maintenance information notified from cloud providers and communication providers, and switches the status of the controller device based on the planned maintenance information. as well as Located in each data center where the multiple controller devices are respectively installed, the controller devices monitor information related to faults in the cloud infrastructure or communication infrastructure and switch the state of the controller devices based on the fault information.

Citation Information

Patent Citations

  • Fault-tolerant computer system capable of preventing acquisition of an input / output information path by a processor in which a failure occurs

    US5630053A