Edge devices and methods for providing redundancy on edge devices
By loading application software onto edge devices, redundant functions of the redundant protocol are implemented, solving the problems of communication link interruption and equipment modification, providing a fast and low-cost solution for upgrading redundant functions, and improving the reliability and flexibility of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-18
- Publication Date
- 2026-04-03
AI Technical Summary
In existing industrial automation systems, communication link interruptions lead to information loss and system failures. Furthermore, modifying or retrofitting existing redundant protocol devices requires significant effort or is impossible, making it difficult to quickly provide redundant functionality.
By loading application software on edge devices, redundancy functions of redundancy protocols are implemented. Independent of hardware, redundancy functions can be quickly configured and provided. It supports multiple redundancy protocols, such as MRP, HSR, and PRP, and can be flexibly upgraded to ring redundancy manager, ring redundancy client, dual-connection node, etc.
It enables rapid and low-cost provision of redundancy for industrial communication networks, supports multiple protocols, improves system reliability and flexibility, and avoids system failures caused by communication interruptions.
Smart Images

Figure CN116491108B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to an edge device according to the present invention, a method for providing redundancy on an edge device according to the present invention, and application software according to the present invention. Background Technology
[0002] Industrial automation systems typically comprise a large number of industrial automation devices that are connected to the Internet via industrial communication networks to control or regulate systems, machines, or equipment within the scope of manufacturing or process automation. Due to the time-critical framework of the technical systems using industrial automation devices for automation, real-time communication protocols (such as PROFINET, PROFIBUS, real-time Ethernet, or Time-Sensitive Networking) are primarily used in industrial communication networks to enable communication between automated devices (TSN).
[0003] A disruption of the communication link between computer units in an industrial automation system or equipment is highly problematic because it leads to information loss and consequently system, machine, or equipment malfunctions. Furthermore, it can cause unwanted or unnecessary retransmission of service requests. This places an additional load on the communication link of the industrial automation system, leading to further system failures or errors. Additionally, untransmitted or incompletely transmitted messages may prevent the industrial automation system from transitioning to or remaining in a safe operating state. In the worst case, the entire production facility may fail, resulting in costly production downtime. A particular problem in industrial automation systems is often caused by message traffic consisting of relatively large numbers of short messages, which exacerbates the aforementioned issues.
[0004] To compensate for failures in communication ports or devices, communication protocols such as Media Redundancy Protocol, High Availability Seamless Redundancy, Parallel Redundancy Protocol, or (Fast) Spanning Tree Protocol have been developed for highly available, redundant industrial communication networks.
[0005] Media Redundancy Protocol (MRP), defined in the IEC 62439-2 standard, compensates for individual connection failures in a network through redundant message transmission. In this scenario, the network comprises multiple communication devices connected within a ring topology, each device including two connections for connecting to the ring topology. One communication device in the ring topology is designated as the so-called "ring redundancy manager." The other communication devices are referred to as "ring clients." The ring redundancy manager monitors the ring topology for interruptions based on sent test messages and, upon detecting an interruption, controls the forwarding of messages carrying user data between its two connections.
[0006] The IEC 62439-3 standard defines High Availability Seamless Redundancy (HSR) and Parallel Redundancy Protocol (PRP), enabling seamless redundant message transmission, especially preventing switching surges when the topology changes. According to HSR and PRP, each message is copied by the sending communication device and sent to the receiver via the network in two different ways. The receiving communication device filters out redundant messages indicating duplication from the received data stream.
[0007] In redundant HSR or PRP communication networks, network components providing access to the redundant communication network can play different roles. The simplest form of network component supporting HSR / PRP is called a dual-connection node (DAN). A network component that exchanges datagrams between subscribers or terminals in the HSR or PRP communication network and terminals or network segments without HSR / PRP functionality is called an HSR / PRP agent or RedBox. In principle, a network component can also connect multiple HSR rings or convert communication between HSR and PRP network segments into a redundant HSR or PRP communication network. In this case, the network component is called an HSR-HSR coupler, a QuadBox, or an HSR-PRP coupler.
[0008] In network components or communication equipment, redundancy functions (such as MRP ring redundancy manager functions and HSR duplicate filtering functions) are typically provided by field-programmable gate arrays (FPGAs), see, for example, EP 2 838 220 A1, or implemented in firmware. Therefore, they are closely tied to the device's hardware. Consequently, subsequent changes or modifications to such redundancy functions in the device require significant effort or are simply impossible.
[0009] WO 2016 / 097459 A1 in Figure 4A PRP conversion unit (e.g., RedBox) is disclosed, having a communication port to a first conventional network (e.g., the device's office network, but not directly to the Internet), a first PRP communication port (interface) to a Layer 3 switch of the first PRP network, and a second PRP communication port to a Layer 3 switch of a second PRP network. The PRP conversion unit provides redundancy for the PRP redundancy protocol. More precise details regarding the structure of the PRP conversion unit are not disclosed. For example, Belden Inc.'s Hirschmann RSP 25 RSP switch is referenced to, where the running software can be updated via an SD card (see Hirschmann, Anwender-Handbuch, Installation Industrial Ethernet Rail Switch Power, RSP20 / 25 / 30 / 35, Publication Date 16, 12 / 2019, Page 30). EP 2 784 988 A1 Figure 1 A modular control device is disclosed, having multiple connections for fieldbus communication ports to automated equipment and a connection for an industrial communication network comprising two sub-networks. The modular control device can be connected to a control system via the industrial communication network. The modular control device includes an interface module with a signal processing unit, preferably implemented using an FPGA. The signal processing unit provides redundancy functionality with perturbation redundancy protocols (e.g., MRP) and non-perturbation redundancy protocols (e.g., HSR or PRP), thereby enabling selective switching between these protocols.
[0010] US 407,582 B2 discloses a communication device having a connection to a SCADA system and connections to two redundant PRP subnets. The communication device includes a signal processing unit implemented using an FPGA. The signal processing unit provides redundancy functionality for the PRP redundancy protocol to the PRP subnets. In principle, communication can also be performed using the HSR redundancy protocol. Summary of the Invention
[0011] Therefore, the purpose of this invention is to provide a device that can provide, modify, or add redundancy to redundant industrial communication networks in a fast and inexpensive manner.
[0012] This objective is achieved through an edge device according to the invention. Advantageous improvements are the subject of the invention. Methods for providing redundancy functionality according to industrial redundancy protocols on an edge device are the subject of the invention. Application software is the subject of the invention.
[0013] This invention is based on the understanding that edge devices can be very advantageously used to flexibly provide redundant functionality. Industrial automation systems or industrial communication networks typically operate in "island-like" data technology environments, i.e., as dedicated networks separated from public networks (especially the Internet). This is used, for example, to prevent technical data attacks on automation systems. However, there is a growing recognition of the significant benefits of being able to exchange data with public networks, especially data clouds (hereinafter also referred to as "the cloud"). The reasons are varied; for example, it should be possible to connect different local automation systems to the Internet, to inspect production operations from different locations around the world, to transmit orders to automated devices, and to read production data.
[0014] To regulate and control data exchange between private networks and public networks, especially the cloud, so-called edge devices or edge equipment are used at the boundary between private and public networks.
[0015] The edge device according to the invention includes a first communication port to a first network (which is a public network) and at least two second communication ports to a second network, particularly to a private industrial network. This connection is also commonly referred to as an "interface".
[0016] According to the present invention, the edge device includes application software that can be loaded into the edge device via a first communication port. The edge device is designed and configured such that the port (interface) can be configured using the application software to configure a second communication port (interface) for redundant operation of a second network according to a redundancy protocol, wherein the application software is designed and configured to perform the redundant functions of the redundancy protocol.
[0017] According to the invention, the provision of redundancy is entirely software-based, and therefore independent of the edge device's hardware. Since the application software and redundancy are provided via the first communication port, this can also be accomplished after the edge device has been actually manufactured. In general, redundancy can be provided, modified, or retrofitted quickly and effortlessly. Advantageously, even edge devices unrelated to the second network can receive redundancy and thus be used for redundant operation of the second network.
[0018] In their primary functions, edge devices can function as, for example, cloud gateways, switches, I / O stations, or programmable logic controllers (PLCs). If the edge device has appropriate data technology capabilities, applications and processes can also run on it—for example, those that cannot run on a PLC. These include complex calculations, evaluation of production data, archiving tasks, etc.
[0019] Therefore, according to the present invention, the edge device is designed and configured to receive application software through a first communication port and execute it after receiving it.
[0020] It is particularly advantageous if, apart from the aforementioned application software, no other software components must be loaded into the edge device to perform redundant functions—that is, no operating system software, drivers, IP stack, or the like. This differs from firmware, which typically includes such additional software components.
[0021] To this end, edge devices can also have dedicated installation software that stores application software in the edge device's memory and enables any necessary configuration of the application software.
[0022] Configuring a second communication port (interface) is necessary, for example, in order to
[0023] - Assign a second communication port (interface) to a real or virtual communication network (e.g., interconnection or link of second communication ports for ring function).
[0024] - Depending on the role of the edge device in the redundancy protocol, activate the datagram blocking function (e.g., in the case of an MRP host) or the datagram forwarding function (e.g., in the case of an MRP client) in the second communication port (interface).
[0025] - Activate or deactivate monitoring of the connection status of the second communication port (interface), such as link uplink monitoring or link downlink monitoring.
[0026] - Always open or close the second communication port (e.g., activate or deactivate "Link active").
[0027] To this end, an edge device can include a memory unit for non-volatile storage of application software program code, a processor for processing the program code, and working memory into which the program code can be loaded for execution. The memory unit, main memory, processor, and operating system installed on the edge device can then be used to create a process control environment for executing the application software.
[0028] The second communication port (interface) is preferably connected to a data bus, which is particularly designed as a backplane switch, and the data bus is designed so that the interconnection of the second communication port (interface) on the data bus can be configured using application software.
[0029] For example, an edge device or data bus may have one or more registers (i.e., data storage) for defining the interconnection (or link) of a second communication port (interface), and application software may have write access to these registers in order to define the interconnection of the second communication port (interface).
[0030] In principle, this invention can be used for a large number of redundant protocols in highly available, redundantly operating industrial communication networks.
[0031] According to an advantageous embodiment, the redundancy protocol is the Media Redundancy Protocol (MRP) according to IEC 62439-2.
[0032] The application software can then be advantageously designed and configured to selectively execute either the ring redundancy manager's functions or the ring redundancy client's functions. Therefore, the edge device can be flexibly upgraded to either a ring redundancy manager or a ring redundancy client according to the MRP protocol. Advantageously, both the ring redundancy manager's functions and the ring redundancy client's functions can be executed by the application software, which provides a user interface for selecting which of these two functions to execute.
[0033] According to another advantageous embodiment, the redundancy protocol is a High Availability Seamless Redundancy Protocol (HSR) or a Parallel Redundancy Protocol (PRP) based on IEC 62439-3.
[0034] Then it is possible to design and configure the application software so that the functions of the dual-connection node (DAN), Redbox or Quadbox according to IEC 62439-3 can be performed selectively through the application software.
[0035] Therefore, edge devices can be flexibly upgraded to dual-connection nodes (DAN), redboxes, or quadboxes according to the HSR or PRP protocol. Advantageously, the application software can perform the functions of dual-connection nodes (DAN), redboxes, and quadboxes, and the application software provides a user interface for selecting one of the three functions to perform.
[0036] According to the present invention, the application software provides a user interface for the logical allocation of second communication ports (interfaces), namely, exclusively allocating selected second communication ports (interfaces) and linking them together in an exchange manner to forward datagrams. The user interface is also capable of providing options for selecting redundancy functions or their parameterization.
[0037] To avoid failures from the outset, the application software according to the present invention provides a testing function that tests whether the edge device is suitable for performing the redundancy function of the redundancy protocol. This testing function can, for example, be performed during the application software initialization process. The edge device's hardware can query the number of available second communication ports (interfaces) through the testing function. For example, if at least two second communication ports (interfaces) are unavailable, the edge device is not suitable for performing the redundancy function. Such a query can be performed by the application software, for example, by reading the edge device's hardware registers (e.g., the data bus to which the second communication ports are connected).
[0038] According to another advantageous embodiment, the edge device includes a process control environment designed and configured to run on a host operating system installed on the edge device, application software can be loaded into the process control environment for execution there, and wherein the process control environment includes an interface for accessing a second communication port.
[0039] Then, the application software can include one or more software containers that are designed and configured to run in isolation from other software containers or groups of containers within process control on the host operating system.
[0040] Different applications can then be executed in isolation and independently within a process control environment or in another process control environment in order to enable different functions of the edge device.
[0041] In principle, application software can also use alternative microvirtualization concepts, such as snapshots. Therefore, the process control environment can include Docker Engine or Snap Core running on edge devices.
[0042] Advantageously, the process control environment includes software components that—in the sense of an adapter between the application software and the hardware—directly access the second port (interface) and provide the edge device with the necessary hardware resources (buffer memory, interrupt lines to the CPU, etc.) for performing redundant functions. This ensures good interaction between the application software and hardware of the edge device.
[0043] The adapter software component is advantageously designed and configured to filter and evaluate datagrams received through the second port (interface) according to the redundancy functions specified by the application software. Therefore, the adapter software component can ensure, for example, in the function of an edge device acting as an MRP redundancy manager, that the rings are ordered and that ring switching is performed in the event of an error.
[0044] Furthermore, the present invention includes a method for providing redundancy functionality according to an industrial redundancy protocol on an edge device, the device comprising...
[0045] -To the first communication port of the first network, which is a public network.
[0046] -To at least two second communication ports of a second network, particularly a private industrial network.
[0047] The method includes the following steps:
[0048] a) Load the application software onto the edge device via the first communication port.
[0049] b) Configure the second communication port using application software for redundant operation of the second network according to the redundancy protocol.
[0050] c) The application software performs the redundancy function of the redundancy protocol.
[0051] According to the present invention, step b) includes the following steps:
[0052] - Check whether the hardware of the edge device is suitable for performing redundant functions through application software, especially check whether there is a necessary number of second communication ports.
[0053] - If the check is unsuccessful: terminate the method.
[0054] -If the check is successful: the method continues with the following steps:
[0055] - Request information regarding the configuration of the second communication ports, especially their (logical) interconnection, and / or information regarding the selection of redundancy features.
[0056] - Obtain information about the configuration of the second configuration ports, especially their (logical) interconnection, and / or information about the selection of redundancy features.
[0057] - Configure the second communication port, especially the (logical) interconnection of the second port, and / or set up selected redundancy functions in the application software, depending on the configuration information obtained.
[0058] - Connect the second network physical to the second communication port.
[0059] The application software according to the invention is designed and configured to enable, in the case of the aforementioned edge device, the application software to be loaded into and executed thereon via a first communication port, wherein the application software includes instructions for causing the edge device to perform steps b) and c) of the method described above.
[0060] For example, the application software must be sized based on the amount of data or file size so that the edge device can receive it through its primary communication port and store it in the edge device's memory. Furthermore, it must be designed and configured to run on the edge device's operating system or execution environment. For example, if Docker Engine is used as the execution environment, the application software must be a container of that Docker Engine. Additionally, the application software must be designed and configured to be installed and configured on the edge device via an installer.
[0061] Application software can also be part of an application package. Such an application package is typically an archive, containing all the necessary files and (uninstall) installation routines. Executing the archive launches an installer, which is part of the edge device's operating system. Attached Figure Description
[0062] The invention and its further advantageous designs will now be explained in more detail with reference to the embodiments shown in the accompanying drawings. Corresponding parts are given the same reference numerals. The figures show:
[0063] Figure 1 An edge device according to the present invention is shown.
[0064] Figure 2 This demonstrates the use of the Media Redundancy Protocol (MRP) to... Figure 1 Edge devices are integrated into a redundantly operating network.
[0065] Figure 3 This demonstrates the use of the High Availability Seamless Redundancy Protocol (HSR) to... Figure 1 Edge devices are integrated into a redundantly operating network.
[0066] Figure 4 It shows the use of in Figure 1 The method and process of providing redundancy functions according to the industrial redundancy protocol on edge devices. Detailed Implementation
[0067] Figure 1 A simplified schematic diagram of an edge device 1 according to the present invention is shown, the edge device having access to a first network 3 (see...). Figure 2 ), especially to the first communication port (interface) 2 of a public network such as the Internet, and to the second network 20 (see Figure 2 This is especially true for multiple second communication ports in private industrial networks, such as four communication ports (interfaces) 4a-4d. The transmitting and receiving unit 6 is assigned to each of ports 2, 4a-4d respectively.
[0068] Furthermore, edge device 1 includes a processor 7 for processing program code, working memory 8 (on which program code can be loaded), and storage unit 9, particularly a hard disk, flash memory, or SSD, for non-volatile storage of program code. A host operating system 10 is installed on edge device 1, on which a process control environment 11, such as a Docker engine, runs using the processor 7, working memory 8, and storage unit 9, for application software 12, 13, and 14 in the form of software containers 5. Process control environment 11 uses drivers from host operating system 10 to access data bus 18 and send / receive unit 6. It also provides appropriate interfaces for the software containers 5 of application software 12, 13, and 14, which can be loaded into process control environment 11 for execution there. Here, the software containers 5 with application software are configured to run in isolation from other software containers or groups of containers within process control environment 11. On the other hand, software containers 5 use the kernel of host operating system 10 of edge device 1, respectively, along with other software containers running on edge device 1.
[0069] The isolation of software containers 5, or the isolation of selected operating system devices from each other, can be achieved, in particular, through control groups and namespaces. Control groups can be used to define process groups, thereby limiting the resources available to selected groups. Individual processes or control groups can be isolated or hidden from other processes or control groups via namespaces. For example, the memory image of a software container can be retrieved from a storage and provisioning system that can be accessed by a large number of users in a read-write manner.
[0070] Application software 12 is used here to provide redundancy functionality according to an industrial redundancy protocol on edge device 1. For this purpose, application software 12 is designed and configured to be used in a container 5 of process control environment 11 (e.g., Docker engine), and can be loaded into edge device 1 via first port 2 (i.e., stored in memory unit 9) and executed therein, for example by means of application software 13.
[0071] For this purpose, application software 13 can include a special installer that stores application software 12 in storage unit 9 and implements any necessary configuration of application software 12.
[0072] A particular advantage is that, apart from the aforementioned application software 12, no other software components need to be loaded into the edge device 1 to perform redundant functions; that is, for example, no operating system software, drivers, IP stack, or the like are required. This differs from firmware, which typically includes such additional software components.
[0073] The application software 12 can be used to configure the second ports (interfaces) 4a-4b for redundant operation of the second network 20 according to the industrial redundancy protocol, and the application software 12 is designed and configured to perform the redundancy function of the redundancy protocol.
[0074] The configuration of the second communication port (interface) 4a-4d is necessary, for example, in order to
[0075] - Assign the second communication port (interface) 4a-4d to a real or virtual second network (e.g., the interconnection or link of two second communication ports in a ring function).
[0076] - Depending on the role of edge device 1 in the redundancy protocol, the second communication port (interface) is used to activate the datagram blocking function (e.g., in the case of an MRP host) or the datagram forwarding function (e.g., in the case of an MRP client).
[0077] -Activate or deactivate monitoring of the connection status of the second communication ports (interfaces) 4a-4d, such as uplink or downlink monitoring.
[0078] - Basically, turn the second communication port 4a-4d on or off (e.g., activate or deactivate "link activity").
[0079] The redundancy protocol can be, for example, the Media Redundancy Protocol (MRP) according to IEC 62439-2. The application software 12 is then advantageously designed and configured so that the functions of the ring redundancy manager or the ring redundancy client can be selectively executed through the application software. Therefore, a ring redundancy manager or ring redundancy client according to the MRP protocol can be flexibly provided or modified in the edge device 1.
[0080] According to another advantageous embodiment, the redundancy protocol is a High Availability Seamless Redundancy Protocol (HSR) or a Parallel Redundancy Protocol (PRP) based on IEC 62439-3. Application software 12 is then designed and configured to enable, in particular selective execution, of the functions of a dual-connection node (DAN), redbox, or quadbox. Therefore, dual-connection node (DAN), redbox, or quadbox based on the HSR or PRP protocol can be flexibly provided or retrofitted in edge device 1.
[0081] Application software 12 provides a user interface 15 via the first port 2 for the logical allocation of second ports (interfaces) 4a-4d by the user of the edge device 1, that is, exclusively allocating selected second ports (interfaces) 4a-4d and linking the second ports in a connected manner for forwarding datagrams. Here, the user interface 15 can also provide the feasibility for selecting redundancy functions or their parameterization.
[0082] In particular, the data bus 18, which is configured as a backplane switch, is configured to enable the interconnection of the second communication ports (interfaces) 4a-4d on the data bus 18 to be configured by means of application software 12.
[0083] For example, edge device 1 or data bus 18 may have one or more registers (i.e., data memory) that define the interconnect (or link) of the second communication port (interface), and application software 12 may have write access to these registers to define the interconnect of the second communication port (interface).
[0084] In the case of the MRP protocol, the application software 12 can advantageously perform the functions of the ring redundancy manager and the ring redundancy client, and select one of these two functions via the user interface 15 to perform that function.
[0085] In the case of HSR or PRP protocols, application software 12 can perform the functions of dual-connection node (DAN), redbox, and quadbox, and select one of the three functions via user interface 15 to perform that function.
[0086] To prevent malfunctions from the outset, application software 12 advantageously provides a test function 16, which tests whether edge device 1 is suitable for performing the redundancy function of the desired redundancy protocol. This test function can be performed, for example, during the initialization process of application software 12. The hardware of edge device 1 can use the test function to query the number of available second communication ports (interfaces). For example, if at least two second communication ports (interfaces) are unavailable, edge device 1 is not suitable for performing redundancy. Such a query can be performed by the application software, for example, by reading registers in the edge device's hardware (e.g., the data bus 18 to which the second communication ports are connected).
[0087] The process control environment 11 advantageously includes a software component 17, which directly accesses the second ports (interfaces) 4a-4d in the sense of an adapter between the application software 12 and the hardware, and provides the edge device 1 with the necessary hardware resources (buffer memory for forwarding datagrams, access time, interrupt lines to the CPU 7, etc.) for performing redundant functions. This ensures good interaction between the application software 12 and the hardware of the edge device 1.
[0088] Software component 17 is advantageously configured and set up to filter and evaluate datagrams received via the second ports (interfaces) 4a-4d according to redundancy functions predetermined by application software 12. Thus, it can, for example, act as an MRP redundancy manager in the function of edge device 1 to ensure ring order and perform ring switching in case of errors.
[0089] Other application software, such as application software 14, can provide services or functions of industrial automation systems via public networks 3 with cloud or other automation systems, such as control tasks, data acquisition / output tasks, complex calculations, production data evaluation, archiving tasks, or secure data exchange.
[0090] Figure 2 This illustrates, for example, using the Media Redundancy Protocol (MRP) to... Figure 1 Edge device 1 is integrated into a redundantly operating PROFINET network 20. Here, the ring network 20 connects to ports 4a and 4b of edge device 1. Numerous communication or automation devices are connected to network 20. For example, this could be a PROFINET-enabled switch 21 or automation devices with integrated PROFINET interfaces, such as a programmable logic controller (PLC) 22, an operation and monitoring station 23, or an I / O station 24. Figure 2 In such cases, the programmable logic controller (PLC) 22 is used, for example, to control equipment 25 or machine 26. The I / O station 24 is used to acquire measured values and output control variables from the equipment and machine, or to output control variables to the equipment and machine. The operation and monitoring station 23 is used to visualize process data or measured and control variables.
[0091] Here, the participant at network 20 must assume the role of ring redundancy manager according to the MRP protocol, while all other participants assume the role of ring redundancy client. Edge device 1 is now able to flexibly assume either the role of ring redundancy manager or the role of ring redundancy client.
[0092] Communication port 2 connects to a public network 3, such as the Internet, and communicates with a cloud server (not shown in detail) in cloud 29. PROFINET network 20 is a private network within the facility. Edge device 1 is therefore located on the boundary between the public and private areas, indicated by the dashed dividing line 28.
[0093] Figure 3 This demonstrates an exemplary use of the High Availability Seamless Redundancy Protocol (HSR) to... Figure 1 Edge device 1 is integrated into a redundantly operating industrial Ethernet network 30. There is also a ring network 30 connected to ports 4a and 4b of edge device 1. Numerous communication or automation devices are connected to network 30. According to IEC 62439-3, these are categorized as dual-connection nodes (DAN), redboxes, or quadboxes.
[0094] exist Figure 3In this case, reference numeral 31 indicates a Redbox, through which devices that do not support HSR (such as protection device 35) are connected to network 30. A programmable logic controller (PLC) 32 for controlling machine 36 has HSR capability and is therefore connected to network 30 as a "Dual Connectivity Node for HSR Implementation" (DANH). Reference numeral 34 indicates a Quadbox, which connects HSR network 30 to another HSR network 39 and filters data traffic on the network and forwards it to the appropriate other network. Operation and monitoring station 33 and I / O station 37 have HSR capability and are therefore connected to network 30 as "Dual Connectivity Nodes for HSR Implementation" (DANH).
[0095] In the future, Time-Sensitive Networking (TSN) based on IEEE 802.1Q, IEEE 802.1AB, IEEE 802.1AS, IEEE 802.1BA, or IEEE 802.1CB will be increasingly used in such networks.
[0096] Application software 12 is advantageously designed and configured to enable the selective execution of functions that implement the dual-connection node (DANH), Redbox, or Quadbox of HSR via application software, and application software 12 provides the feasibility of one of the selected three functions to execute the function via user interface 15.
[0097] Therefore, it is possible to flexibly provide or modify dual-connection nodes (DANH), Redboxes, or Quadboxes according to the HSR protocol in edge device 1, and perform HSR duplicate filtering functions thereon.
[0098] Figure 4 The invention illustrates a method for use in Figure 1 Method flow 40 for providing redundancy functionality according to the Industrial Redundancy Protocol on edge device 1.
[0099] In the first step 41, the user loads the application software 12 onto the edge device 1 via the application software 13 and the user interface provided by it through the public network 3 and port 2, stores the application software in the edge device, and executes the application software.
[0100] In the second step 42, the application software 12 now checks whether the hardware of the edge device 1 is suitable for performing the redundancy function, and in particular checks whether there are the necessary number of second ports (interfaces) 4a-4d, i.e., at least two ports (interfaces). The check is performed using the software component 17 of the process control environment 11.
[0101] Such queries can be performed by application software 12, for example by reading registers in the hardware of edge device 1 (e.g., data bus 18).
[0102] If the check is unsuccessful, for example, if two ports (interfaces) do not exist, the method is terminated by application software 12 in step 43 with an error message (see path B).
[0103] If the check is successful (see path A), in a further step 44, the application software 12 queries the user via the user interface 15 for information about the configuration of the second port (interface), especially the selected second port (interface) and its logical interconnection information, and is used to select a redundancy function (e.g., in the case of the MRP protocol, whether the edge device 1 should perform the role of ring redundancy manager or ring redundancy client).
[0104] This information is acquired by application software 12 in step 45, and then in step 46, the selected second port (interface) is logically interconnected. Furthermore, the selected redundancy function is set or configured in application software 12.
[0105] For example, edge device 1 or data bus 18 may have one or more registers (i.e., data memory) that define the interconnect (or link) of the second communication port (interface), and application software 12 has write access to these registers to define the interconnect of the second communication port (interface).
[0106] In the final step 47, network 20 or 30 is then able to physically connect to the selected and logically interconnected second port (interface).
Claims
1. An edge device (1), comprising: -To the first communication port (2) of the first network (3), wherein the first network is a public network. -At least two second communication ports (4a, 4b, 4c, 4d) to the second network (20, 30), and - Application software (12) that can be loaded into the edge device (1) via the first port (2). The edge device (1) is designed and configured to configure the second communication ports (4a, 4b, 4c, 4d) for redundant operation of the second network (20, 30) according to an industrial redundancy protocol by means of the application software (12), and the application software (12) is designed and configured to perform the redundancy function of the redundancy protocol, characterized in that, The edge device (1) is designed and configured to receive the application software (12) via the first communication port (2) and execute the application software after receiving it. - Wherein, the provision of the redundancy function is based solely on software implementation, and therefore the provision is independent of the hardware of the edge device. -The application software (12) provides a testing function (16) that checks whether the edge device (1) is suitable for performing the redundancy function of the redundancy protocol, and -The application software (12) provides a user interface (15) for the logical allocation of the second communication ports (4a, 4b, 4c, 4d).
2. The edge device (1) according to claim 1, comprising a data bus (18) designed as a backplane switch, wherein, The second communication port (4a, 4b, 4c, 4d) is connected to the data bus (18), wherein the data bus (18) is designed to be able to configure the interconnection between the second communication port (4a, 4b, 4c, 4d) and the data bus (18) by means of the application software (12).
3. The edge device (1) according to claim 1 or 2, wherein, The redundancy protocol is the media redundancy protocol according to IEC 62439-2.
4. The edge device (1) according to claim 3, wherein, The application software (12) is designed and configured to perform the functions of a ring redundancy manager or ring redundancy client according to IEC 62439-2.
5. The edge device (1) according to claim 1 or 2, wherein, The redundancy protocol is a high-availability seamless redundancy protocol or a parallel redundancy protocol according to IEC 62439-3.
6. The edge device (1) according to claim 5, wherein, The application software (12) is designed and configured to perform the functions of a dual-connection node, a Redbox, or a Quadbox according to IEC 62439-3.
7. The edge device (1) according to claim 1 or 2, wherein, The application software (12) provides a user interface (15) for selecting redundant functions.
8. The edge device (1) according to claim 1 or 2, comprising a process control environment (11), the process control environment being designed and configured to run on a host operating system (10) installed in the edge device (1), wherein, The application software (12) can be loaded into the process control environment (11) for execution in the process control environment, wherein the process control environment (11) has an interface for accessing the second communication port (4a, 4b, 4c, 4d).
9. The edge device (1) according to claim 8, wherein, The application software (12) includes one or more software containers designed and configured to run on the host operating system (10) in an isolated manner from other software containers or groups of containers within the process control environment (11).
10. The edge device (1) according to claim 8, wherein, The process control environment (11) includes a software component (17) that directly accesses the second communication port (4a, 4b, 4c, 4d) and provides the edge device (1) with the necessary hardware resources to perform the redundant functions.
11. The edge device (1) according to claim 10, wherein, The software component (17) filters and evaluates datagrams received via the second communication port (4a, 4b, 4c, 4d).
12. A method for providing redundancy functionality according to an industrial redundancy protocol on an edge device (1), the edge device comprising: - Connected to the first communication port (2) of the first network (3), wherein the first network is a public network. - At least two second communication ports (4a, 4b, 4c, 4d) connected to the second network (20, 30). The method includes the following steps: a) Load the application software (12) onto the edge device (1) via the first communication port (2). b) Using the application software (12), the second communication ports (4a, 4b, 4c, 4d) are configured for redundant operation of the second network (20, 30) according to the redundancy protocol. c) Execute the redundancy function of the redundancy protocol through the application software (12), wherein the provision of the redundancy function is based solely on software implementation and is therefore independent of the hardware of the edge device, and wherein step b) includes the following steps: - The application software (12) checks whether the hardware of the edge device (1) is suitable for performing the redundancy function. - If the check is unsuccessful: terminate the method. -If the check is successful: the method continues with the following steps: - Request information regarding the configuration of the second communication ports (4a, 4b, 4c, 4d), wherein the application software (12) provides a user interface (15) for the logical allocation of the second communication ports (4a, 4b, 4c, 4d). - Obtain information regarding the configuration of the second configuration ports (4a, 4b, 4c, 4d). - Configure the second communication port (4a, 4b, 4c, 4d). - Connect the second network (20, 30) to the second communication port (4a, 4b, 4c, 4d).
13. An application software (12) designed and configured such that the application software can be loaded into and executed in an edge device (1) via a first communication port (2) according to any one of claims 1 to 11, wherein, The application software includes instructions that cause the edge device (1) to perform steps b) and c) of the method according to claim 12.
Citation Information
Patent Citations
Communication interface module for a modular control device of an industrial automation system
EP2784988A1
Method for the redundant transmission of messages in an industrial communication network and communication device
EP2838220A1
Shackle
US407582A
Redundancy in process control system
WO2016097459A1
Method for traffic management at network node, and network node in packet-switched network
CN107431665A