An industrial process controller redundant operation method and system

By decoupling redundant logic and link decomposition methods, high reliability and short delay switching of industrial process controllers are achieved, solving the problems of high cost and long switching time of redundant systems in the prior art, and improving the redundancy and reliability of the system.

CN116699964BActive Publication Date: 2025-07-22NR ELECTRIC CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310677694.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-08
Publication Date
2025-07-22
Estimated Expiration
2043-06-08

AI Technical Summary

Technical Problem

The redundant systems of existing industrial process controllers have problems of high cost and long switching time during switching, making it difficult to improve the reliability of the system and the average failure-free time without increasing hardware costs.

Method used

By decoupling the controller redundant operation logic into state redundant logic, configuration redundant logic, data redundant logic and task redundant logic, and decoupling the physical link layer of the Ethernet network from the data link layer, the redundant Ethernet network is used to realize the independent redundant operation of each logic, reducing the system complexity.

Benefits of technology

It realizes high reliability and short delay switching of the controller without increasing hardware costs, improves the system's redundancy and reliability, and facilitates online maintenance and upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116699964B_ABST
    Figure CN116699964B_ABST
Patent Text Reader

Abstract

The present invention provides an industrial process controller redundant operation method and system. Two industrial process controllers perform redundant information interaction through a redundant Ethernet network to achieve redundant operation of the controllers. The redundant operation logic of the controllers is decoupled into state redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic. The physical link layer and data link layer of the Ethernet network are decoupled, and the data link layer is decomposed into state redundancy links, configuration redundancy links, data redundancy links, and task redundancy links. Each redundant link uses the redundant Ethernet network to perform redundant information interaction for the corresponding logic, realizing independent redundant operation among the redundant logics. Through redundant logic decoupling and design, and redundant link decomposition, the present invention reduces the complexity of the redundant system, ensures the reliability of redundant operation, and achieves a redundant effect of high reliability in operation and short delay in switching without increasing the hardware cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of redundant operation of automation equipment, and relates to a method and system for redundant operation of an industrial process controller. Background Art

[0002] Currently, industrial process controllers generally adopt 1:1 module-level dual redundancy for key components to achieve dual-host hot standby redundant operation, so as to avoid accidents such as shutdown caused by single-module failures of the controller, facilitate online maintenance and upgrade of the system, and improve the mean time between failures of the system.

[0003] The hot standby redundancy consists of two completely identical subsystems, and these two subsystems form a relationship of one working and one standby. They run exactly the same program simultaneously, forming two completely parallel operation modes. In the hot standby redundant system, both of the two mutually redundant subsystems simultaneously receive inputs, execute calculations, and perform diagnostics, but the standby subsystem does not enable outputs and does not actively send monitoring data.

[0004] The use of hot standby redundancy technology is mainly to improve the fault tolerance of the controller. Therefore, an important function of hot standby redundancy is to achieve redundancy switching based on faults: both the working controller and the standby controller perform self-diagnostics and mutual diagnostics. When the working controller fails and the standby controller is normal, the master-slave relationship is automatically switched, so that the controller in the fault situation becomes the standby state, and the controller with normal diagnostics becomes the working state. To avoid / reduce disturbances to the controlled object, the switching time is required to be as short as possible.

[0005] According to the redundancy implementation method, it can generally be divided into hardware redundancy and software redundancy.

[0006] The redundant structure of the hardware redundancy system ensures the system reliability at any time. For example, all important components are redundantly configured. This includes redundant CPUs, power supply modules, and synchronization modules for redundant CPU communication. When a fault occurs, it automatically switches to the standby controller, and the switching process does not stop the machine. However, the cost of hardware redundancy is relatively high, and it is generally used in systems with high reliability requirements.

[0007] Software redundancy is achieved by software programming to switch to the standby controller when a fault is detected. It requires the platform or user to write control logic with redundant functions and participate in the fault diagnosis decision and status matching of the redundancy throughout the process. If there is no dedicated redundant communication channel, there will be a lag in redundant data synchronization and status switching, and the cost is relatively low, and the switching time is relatively long. Summary of the Invention

[0008] To address the deficiencies in the existing technology, the present invention provides a redundant operation method and system for an industrial process controller. By means of redundant logic decoupling and design, as well as redundant link decomposition, the complexity of the redundant system is reduced, ensuring the reliability of redundant operation. Without increasing the hardware cost, software redundancy achieves a redundant effect of high reliability in operation and short delay in switching, realizing the hot standby redundancy function of the controller in the industrial control system, facilitating online maintenance and upgrade of the system, and increasing the mean time between failures of the system.

[0009] The present invention adopts the following technical solutions.

[0010] A redundant operation method for an industrial process controller, in which two industrial process controllers perform redundant information interaction through a redundant Ethernet network to achieve redundant operation of the controllers;

[0011] Preferably, the redundant operation logic of the controller is decoupled into state redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic;

[0012] The physical link layer and the data link layer of the Ethernet network are decoupled, where the physical link layer includes physical links A and B, and physical links A and B form a redundant Ethernet network. The data link layer performs redundant link decomposition to obtain a state redundancy link, a configuration redundancy link, a data redundancy link, and a task redundancy link;

[0013] Each redundant link uses the redundant Ethernet network to perform redundant information interaction for the corresponding logic, realizing independent redundant operation among the redundant logics.

[0014] Preferably, the state redundancy logic includes a redundant state negotiation logic for power-on operation, a logic for the slave to actively promote to the master when the host is offline, a logic for the slave to judge the fault level and actively promote to the master, and a logic for the host to force the master-slave switch when receiving a tool command.

[0015] Preferably, the redundant state negotiation logic for power-on operation is used to confirm the states of the master and slave controllers, specifically:

[0016] The controller is powered on and initialized for operation, and obtains the default settings of its respective redundant master-slave states;

[0017] When the default setting is the slave state, the controller sets its own side to the initial slave state after a delay;

[0018] When the default setting is the master state, the controller immediately sets its own side to the initial slave state without delay;

[0019] After the controller enters the initial slave state, it sends a heartbeat message to the opposite side through the state redundancy link;

[0020] When the heartbeat message is not replied for consecutive timeouts, the controller enters the master state;

[0021] When the heartbeat message receives a reply from the peer host, the controller maintains the slave state.

[0022] Preferably, after confirming the master-slave controller status, the slave controller periodically sends a heartbeat message to the master controller through the status redundancy link. After receiving the heartbeat message, the master controller replies with a heartbeat message to the slave controller;

[0023] The heartbeat message includes the local fault level, forced switch flag, and master-slave status flag;

[0024] Among them, the fault level is agreed upon for specific fault types. When a fault occurs in the master controller, the local fault level is set to the corresponding agreed value and sent to the slave through the heartbeat reply message.

[0025] Preferably, the specific logic for the slave to actively promote to the master when the host is offline is as follows:

[0026] If the slave controller continuously times out receiving the heartbeat reply message, it indicates that the host is offline. The slave controller on this side switches to the master, and then continuously sends a message to force the peer to switch to the slave.

[0027] Preferably, the logic for the slave to actively promote to the master by judging the fault level cooperates with the application logic to achieve the slave to actively promote to the master by judging the fault level. Specifically:

[0028] The application logic is: The slave controller receives the peer fault level in the heartbeat reply message and compares it with the local fault level;

[0029] The logic for the slave to actively promote to the master by judging the fault level is: When it is concluded through the application logic comparison that the peer fault level in the heartbeat reply message received by the slave controller is continuously higher than the local fault level, the local side switches to the master, and then continuously sends a message to force the peer to switch to the slave; After receiving the message to force the local side to switch to the slave, the host immediately sets itself as the slave.

[0030] Preferably, the logic for the host to receive a tool command to force master-slave switching is as follows:

[0031] After receiving the master-slave switching command from the debugging tool side, the master controller sets the forced switch flag bit when replying to the heartbeat message this time;

[0032] If the forced switch flag bit is set in the heartbeat message received by the slave controller, the local side switches to the master, and then continuously sends a message to force the peer to switch to the slave;

[0033] After receiving the message to force the local side to switch to the slave, the host immediately sets itself as the slave.

[0034] Preferably, the configuration redundancy logic includes the slave power-on synchronization configuration logic and the online update configuration logic;

[0035] The slave power-on synchronization configuration logic is specifically as follows:

[0036] After the controller is powered on and initialized to run and is determined to be a slave through redundant status negotiation, it sends a configuration information request message to the host through the configured redundant link.

[0037] After the slave obtains the check code of the host configuration information, it compares it with the local configuration information. If the verification information is consistent, the configuration synchronization ends; if the verification information is inconsistent, the configuration file is synchronized.

[0038] Preferably, the online update configuration logic is specifically as follows:

[0039] When the debugging tool connects to the master controller and issues an online update configuration command, the host downloads the update message and forwards it to the slave through the configured redundant link. After receiving the downloaded update message, the slave updates the local configuration file.

[0040] Among them, the debugging tool only establishes a connection with the current master controller and issues an online update configuration command to the master controller when online update configuration is required.

[0041] Preferably, the data redundancy logic is specifically as follows:

[0042] The controller tasks are divided into periodic tasks, free tasks, status-triggered tasks, and event-triggered tasks.

[0043] When the controller is initialized to run, it selects and sets the periodic task or free task with the highest priority level as the highest priority task; when the highest priority levels of the periodic task and the free task are the same, the periodic task is selected as the highest priority task.

[0044] Before executing the highest priority task, the master controller sends a data synchronization message through the data redundancy link. After receiving the data synchronization message, the slave controller updates the local data and executes the highest priority task.

[0045] Preferably, the task redundancy logic is specifically as follows:

[0046] Based on the data redundancy logic combination, the highest priority task synchronization and data redundancy are realized.

[0047] Before executing a non-highest priority task, the master controller sends a task synchronization command through the task redundancy link. After receiving the task synchronization command, the slave controller executes the corresponding task.

[0048] An industrial process controller redundant operation system includes two industrial process controllers and a redundant Ethernet network.

[0049] Each controller is provided with a status redundancy module, a configuration redundancy module, a data redundancy module, and a task redundancy module, which are used to execute status redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic respectively;

[0050] The redundant Ethernet network is provided with a status redundancy link, a configuration redundancy link, a data redundancy link, and a task redundancy link;

[0051] The status redundancy module, configuration redundancy module, data redundancy module, and task redundancy module operate independently of each other, each using an independent thread to complete related logic tasks, and respectively using the status redundancy link, configuration redundancy link, data redundancy link, and task redundancy link to exchange data.

[0052] Preferably, the two industrial process controllers are exactly the same and are interconnected through physical links A and B of the redundant Ethernet network;

[0053] The base of the controller is equipped with a hardware DIP switch module for manually setting one side as the main controller by default and the other side as the slave controller;

[0054] The redundant status result negotiated by the status redundancy module can be accessed by other modules and participate in the operation logic of other modules; at the same time, the status redundancy module also exchanges the operating status on both sides;

[0055] The status redundancy link alternately uses physical links A and B to send data, and when the acknowledgment data sent by physical link A or B is not received continuously, it is determined that the corresponding physical link is disconnected;

[0056] The configuration redundancy link, data redundancy link, and task redundancy link use the physical link detected by the status redundancy link to be connected to send data.

[0057] A terminal includes a processor and a storage medium; the storage medium is used to store instructions;

[0058] The processor is used to operate according to the instructions to execute the steps of the method.

[0059] A computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the method are implemented.

[0060] The beneficial effects of the present invention are as follows. Compared with the prior art, the redundant controller of the present invention completes redundant information interaction through redundant Ethernet, enabling hot standby redundant operation of the controller. Only redundant communication ports are added on the basis of the conventional controller hardware, making full use of the physical bandwidth and improving the redundancy and reliability of the system. Through redundant logic decoupling and design, as well as redundant link decomposition, the present invention reduces the complexity of the redundant system and ensures the reliability of redundant operation. Without increasing the hardware cost of the redundant system, the present invention achieves a redundant effect of high reliability in operation and short delay in switching through software redundancy. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 is a schematic diagram of the controller redundant system architecture of the present invention;

[0062] Figure 2 is a flowchart of the redundant state negotiation and interaction during the power-on of the controller of the present invention;

[0063] Figure 3 is a flowchart of the interaction process in which the slave actively promotes to the master when the host goes offline of the present invention;

[0064] Figure 4 is a flowchart of the interaction process in which the slave judges the fault level and actively promotes to the master of the present invention;

[0065] Figure 5 is a flowchart of the interaction process of forced master-slave switching when the host receives a tool command of the present invention;

[0066] Figure 6 is a flowchart of the interaction process of power-on synchronization configuration of the slave of the present invention;

[0067] Figure 7 is a flowchart of the interaction process of online configuration update of the present invention;

[0068] Figure 8 is a flowchart of the data redundancy interaction of the present invention;

[0069] Figure 9 is a flowchart of the task redundancy interaction of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0070] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. The embodiments described in this application are only a part of the embodiments of the present invention, rather than all embodiments. Based on the spirit of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0071] Embodiment 1 of the present invention provides a redundant operation method for industrial process controllers. Two industrial process controllers perform redundant information interaction through a redundant Ethernet network to achieve redundant operation of the controllers. In a preferred but non-limiting embodiment of the present invention, the method decouples the redundant operation logic of the controllers into state redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic;

[0072] Decouple the physical link layer and the data link layer of the Ethernet network, where the physical link layer includes physical links A and B, and physical links A and B form a redundant Ethernet network. The data link layer performs redundant link decomposition to obtain a state redundancy link, a configuration redundancy link, a data redundancy link, and a task redundancy link;

[0073] Each redundant link uses the redundant Ethernet network to perform redundant information interaction for the corresponding logic, achieving independent redundant operation between the redundant logics.

[0074] That is, a master-slave redundant controller is formed by connecting two controllers with a redundant Ethernet network. The controllers obtain their respective redundant master-slave default state settings and complete master-slave state negotiation by combining the redundant information exchanged through the redundant Ethernet. Redundant information interaction includes master-slave state negotiation, master-slave state switching, operating state information exchange, configuration synchronization, data synchronization, and task synchronization. Redundant information interaction is decomposed into a state redundancy module, a configuration redundancy module, a data redundancy module, and a task redundancy module according to the logical function. The redundant modules operate independently and exchange data using the state redundancy link, the configuration redundancy link, the data redundancy link, and the task redundancy link respectively.

[0075] The slave controller periodically sends a heartbeat message to the master controller through the state redundancy link. After receiving the heartbeat message, the master controller replies with a heartbeat message to the slave controller. The redundant controller performs master-slave state negotiation, master-slave state switching, and operating state information exchange through the heartbeat message interaction. The master controller sends configuration information through the configuration redundancy link, and the slave controller receives the configuration information and updates its local configuration. After the slave control configuration information is synchronized, it waits for the master controller to send a switching configuration command.

[0076] The slave controller does not run tasks through its own task scheduling module. Before executing the highest-priority task, the master controller sends a data synchronization message through the data redundancy link. The slave controller receives the data synchronization message, updates its local data, and executes the highest-priority task. Before executing a non-highest-priority task, the master controller sends a task synchronization command through the task redundancy link. The slave controller receives the task synchronization command and executes the corresponding task.

[0077] Embodiment 2 of the present invention provides an industrial process controller redundant operation system, including two redundant controllers and a redundant Ethernet network;

[0078] Each controller is provided with a status redundancy module, a configuration redundancy module, a data redundancy module, and a task redundancy module, which are used to execute status redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic respectively;

[0079] The redundant Ethernet network is provided with a status redundancy link, a configuration redundancy link, a data redundancy link, and a task redundancy link;

[0080] The status redundancy module, the configuration redundancy module, the data redundancy module, and the task redundancy module operate independently. Each uses an independent thread to complete relevant logic tasks and uses the status redundancy link, the configuration redundancy link, the data redundancy link, and the task redundancy link to exchange data respectively.

[0081] Further preferably, in combination with Figure 1 The redundant operation system architecture of the controller of the present invention is described as follows:

[0082] Two industrial process controllers are completely the same and are interconnected through physical links A and B of the redundant Ethernet network, and the flow control functions of the Ethernet ports of physical links A and B are turned off;

[0083] The base of the controller has a hardware DIP function, and one side can be manually set as the main controller and the other side as the slave controller.

[0084] The controller software includes a status redundancy module, a configuration redundancy module, a data redundancy module, a task redundancy module, an application logic module, etc.

[0085] The redundant modules operate independently. Each uses an independent thread to complete relevant tasks and uses the status redundancy link, the configuration redundancy link, the data redundancy link, and the task redundancy link to exchange data respectively.

[0086] Among them, the redundant status result negotiated by the status redundancy module can be accessed by other modules and participate in the operation logic of other modules.

[0087] At the same time, the status redundancy module also exchanges the operating states on both sides, including operating information such as load, temperature, and memory usage rate.

[0088] The status redundancy link alternately uses physical links A and B to send data, making full use of the physical bandwidth; the sent data includes a data number, and when no response data sent by physical link A or B is received continuously, it is determined that the corresponding physical link is disconnected;

[0089] The configured redundant link, data redundant link, and task redundant link send data through the physical link detected by the status redundant link for connectivity, improving the redundancy and reliability of the system. That is, physical links A and B are defaultly connected simultaneously. The data continuously sent by the status redundant link is sent alternately using physical links A and B. The configured redundant link, data redundant link, and task redundant link can choose any one of the physical links to send data;

[0090] When the status redundant link determines that a physical link is disconnected, it indicates that the physical link has a fault. At this time, the configured redundant link, data redundant link, and task redundant link use the other connected physical link. When both physical links have faults, an error is reported.

[0091] The specific introduction of the above-mentioned status redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic is as follows:

[0092] As Figure 2 shown, the redundant status negotiation logic for the controller to power on and run is specifically as follows:

[0093] The controller powers on and initializes to run, and obtains the default redundant master-slave status settings for each.

[0094] Further preferably, the controller base provides a DIP switch to set the default redundant master-slave status, and the controller obtains the relevant settings by collecting the base hardware signals.

[0095] In the implementation scheme without hardware conditions, the method of setting parameters by software can also achieve the default redundant master-slave status setting.

[0096] When the default setting is the slave state, the controller sets its own side to the initial slave state after a delay of T;

[0097] When the default setting is the master state, the controller immediately sets its own side to the initial slave state without delay.

[0098] After the controller enters the initial slave state, it sends a heartbeat message to the opposite side through the status redundant link.

[0099] When the heartbeat message times out for ΔT without reply for N consecutive frames, the controller enters the master state;

[0100] When the heartbeat message gets a reply from the opposite master, the controller maintains the slave state.

[0101] To sum up, before the two-side controllers officially run, they first enter the initial slave state and send a heartbeat message request to be promoted to the master. By setting the delay T, the master-slave state competition relationship that may occur when the two-side controllers power on and run simultaneously can be solved.

[0102] After the master-slave controller status is confirmed, the slave controller periodically sends heartbeat messages to the master controller according to ΔT through the status redundancy link. After receiving the heartbeat message, the master controller replies with a heartbeat message to the slave controller.

[0103] The heartbeat message includes the local fault level, forced switch flag, and master-slave status flag.

[0104] As Figure 3 shown, the specific logic for the slave controller to actively promote itself to the master when the controller host is offline is as follows:

[0105] When the host is offline due to abnormal operation or power failure, the slave controller periodically sends heartbeat messages to the master controller according to ΔT through the status redundancy link. When the heartbeat reply message reception times out for N consecutive frames, the local side switches to the master, and then continuously sends messages to force the opposite side to switch to the slave.

[0106] As Figure 4 shown, the specific logic for the slave controller of the controller to actively promote itself to the master by judging the fault level is to cooperate with the application logic to achieve the slave controller to actively promote itself to the master by judging the fault level. Specifically:

[0107] The controller heartbeat message contains a fault level field. The fault level ranges from 0 to 255, and the larger the number, the higher the fault level. Corresponding fault levels are respectively agreed for specific abnormal types such as bus anomaly, power failure, and human-machine interface failure. When the master controller fails, set the local fault level to the corresponding non-zero value and send it to the slave through the heartbeat reply message.

[0108] The application logic is as follows: The slave controller receives the fault level (i.e., operating status) of the opposite side in the heartbeat reply message and compares it with the local fault level;

[0109] The logic for the slave controller to actively promote itself to the master by judging the fault level is as follows: If it is obtained through the application logic comparison that the fault level of the opposite side in the heartbeat reply message received by the slave controller is higher than the local fault level for 3 consecutive frames, then the local side switches to the master, and then continuously sends messages to force the opposite side to switch to the slave;

[0110] After receiving the message to force the local side to switch to the slave, the host immediately sets itself as the slave.

[0111] As Figure 5 shown, the specific logic for the master-slave switch of the controller host when receiving a tool command is as follows.

[0112] The controller heartbeat message contains a forced switch field. This field is 0 during normal operation. When it is 0x5A, it means that the debugging tool issues a command to force the master-slave status switch of the redundant controller.

[0113] The debugging tool only establishes communication with the current master controller.

[0114] After the master controller receives the master-slave switch command from the debugging tool side, it sets the forced switch flag bit to 0x5A in the current heartbeat response message.

[0115] If the forced switch flag bit in the heartbeat message received by the slave controller is set to 0x5A, this side switches to the master, and then continuously sends a message to force the opposite side to switch to the slave.

[0116] After the master receives the message to force this side to switch to the slave, it immediately sets to the slave.

[0117] As Figure 6 shown, the power-on synchronization configuration logic of the controller slave is specifically as follows:

[0118] After the controller powers on and initializes and runs and is determined to be a slave through redundant negotiation, the slave initiates a configuration information request message to the master through the configured redundant link.

[0119] After the master receives the slave configuration information request message, it sends all the configuration files on this side to the slave according to the file name + valid flag + check code.

[0120] After the slave obtains the master configuration information, it uses the file name as the associated information to compare with the local configuration files. First, it compares the valid flags of the configuration files. When the valid flag bit is invalid, the slave deletes the local configuration file. Otherwise, it further compares the check codes of the configuration files. When the check codes are inconsistent, the slave subsequently obtains the inconsistent configuration files in turn. Otherwise, the configuration synchronization ends.

[0121] As Figure 7 shown, the online update configuration logic of the controller is specifically as follows:

[0122] The debugging tool only establishes communication with the current master controller. When online configuration update is required, the tool sends a download request, file transfer, download confirmation, and configuration update command to the master controller.

[0123] When the master controller receives the above commands, it forwards them to the slave controller through the configured redundant link.

[0124] After the slave controller receives the above commands, it processes them according to the same logic as the commands issued by the tool.

[0125] As Figure 8 shown, the controller data redundancy logic is introduced.

[0126] Controller tasks are generally divided into task scheduling methods such as periodic tasks, free tasks, status-triggered tasks, and event-triggered tasks. Among them, free tasks are tasks that are not triggered by periods, status, or events.

[0127] When the controller is initialized and runs, it selects the periodic task or free task with the highest priority level setting as the highest priority task; when the highest priority levels of the periodic task and the free task are the same, the periodic task is selected as the highest priority task.

[0128] The slave controller does not trigger the execution of periodic tasks, free tasks, status-triggered tasks, and event-triggered tasks through the local task scheduling module of the controller itself; that is, the host is the task scheduling module that triggers the execution of periodic tasks, free tasks, status-triggered tasks, and event-triggered tasks; the slave does not trigger, and the data redundancy and task redundancy modules are fully responsible for triggering periodic tasks, free tasks, status-triggered tasks, and event-triggered tasks.

[0129] Before the highest priority task is executed, the master controller sends a data synchronization message through the data redundancy link, and then executes the highest priority task.

[0130] After receiving the data synchronization message, the slave controller updates the local data and executes the highest priority task after receiving all the data.

[0131] As Figure 9 shown, the specific task redundancy logic of the controller is as follows:

[0132] The synchronization of the highest priority tasks and the combination of data redundancy of the redundant controller are realized, avoiding the problem of data and task out-of-sync.

[0133] The non-highest priority tasks are coordinated and completed through the task redundancy module.

[0134] Before the non-highest priority task is executed, the master controller sends a task synchronization command through the task redundancy link, and then executes the corresponding task.

[0135] The above command content includes the ID of the task to be executed this time, and the task IDs of the master and slave controllers are the same.

[0136] After receiving the task synchronization command, the slave controller executes the corresponding task.

[0137] Embodiment 3 of the present invention provides a terminal, including a processor and a storage medium; the storage medium is used to store instructions;

[0138] The processor is used to operate according to the instructions to execute the steps of the method according to Embodiment 1.

[0139] Embodiment 4 of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps of the method according to Embodiment 1.

[0140] The beneficial effects of the present invention are as follows. Compared with the prior art, the redundant controller of the present invention completes redundant information interaction through redundant Ethernet, enabling the hot standby redundant operation of the controller. Only redundant communication ports are added on the basis of the conventional controller hardware. Through redundant logic decoupling and design, and redundant link decomposition, the complexity of the redundant system is reduced, ensuring the reliability of redundant operation. Without increasing the hardware cost of the redundant system, the redundant effect of high reliable operation and short switching delay is achieved through software redundancy.

[0141] The present disclosure can be a system, a method, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0142] A computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punch card or raised structures in grooves having instructions stored thereon, and any suitable combination of the foregoing. The computer-readable storage medium used herein is not construed as an instantaneous signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.

[0143] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.

[0144] Computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer-readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer-readable program instructions to implement various aspects of the present disclosure.

[0145] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific embodiments of the present invention, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. A redundant operation method for an industrial process controller, where two industrial process controllers perform redundant information interaction through a redundant Ethernet network to achieve redundant operation of the controllers. The method is characterized in that: The redundant operation logic of the controller is decoupled into state redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic; the configuration redundancy logic includes slave power-on synchronization configuration logic and online update configuration logic; The slave power-on synchronization configuration logic is specifically as follows: After the controller is powered on and initialized and determined to be a slave through redundant state negotiation, it sends a configuration information request message to the master through the configuration redundant link; After the slave obtains the check code of the master configuration information and compares it with the local configuration information, if the verification information is consistent, the configuration synchronization ends; if the verification information is inconsistent, the configuration file is synchronized; The data redundancy logic is specifically as follows: The controller tasks are divided into periodic tasks, free tasks, state-triggered tasks, and event-triggered tasks; When the controller is initialized and runs, it selects and sets the periodic task or free task with the highest priority level as the highest priority task; when the highest priority levels of the periodic task and the free task are set to the same, the periodic task is selected as the highest priority task; Before the master controller executes the highest priority task, it sends a data synchronization message through the data redundant link. After the slave controller receives the data synchronization message, it updates the local data and executes the highest priority task; The task redundancy logic is specifically as follows: Based on the data redundancy logic combination, the highest priority task synchronization and data redundancy are realized; Before the master controller executes a non-highest priority task, it sends a task synchronization command through the task redundant link. After the slave controller receives the task synchronization command, it executes the corresponding task; The physical link layer and the data link layer of the Ethernet network are decoupled. The physical link layer includes physical link A and B, and physical link A and B form a redundant Ethernet network. The data link layer is decomposed into a state redundant link, a configuration redundant link, a data redundant link, and a task redundant link; Each redundant link uses the redundant Ethernet network to perform redundant information interaction for the corresponding logic, realizing independent redundant operation among the redundant logics.

2. The redundant operation method for an industrial process controller according to claim 1, characterized in that: The state redundancy logic includes redundant state negotiation logic for power-on operation, master-offline slave-active master-ascending logic, slave-judging fault level and active master-ascending logic, and master-receiving tool command and forced master-slave switching logic.

3. The redundant operation method for an industrial process controller according to claim 2, characterized in that: The redundant state negotiation logic for power-on operation is used to confirm the states of the master and slave controllers, specifically as follows: When the controller is powered on and initialized, it obtains the respective redundant master-slave default state settings; When the default setting is the slave state, the controller sets its own side to the initial slave state after a delay; When the default setting is the master state, it immediately sets its own side to the initial slave state without delay; After the controller enters the initial slave state, it sends a heartbeat message to the opposite side through the state redundant link; When the heartbeat message is not replied continuously and timed out, the controller enters the master state; When the heartbeat message receives a reply from the peer host, the controller maintains the slave state.

4. An industrial process controller redundancy operation method according to claim 3, characterized in that: After confirming the states of the master and slave controllers, the slave controller periodically sends heartbeat messages to the master controller through the status redundancy link. After receiving the heartbeat messages, the master controller replies with heartbeat messages to the slave controller; The heartbeat message includes the local fault level, forced switch flag, and master-slave status flag; Among them, the fault level is agreed upon for specific fault types. When the master controller fails, the local fault level is set to the corresponding agreed value and sent to the slave through the heartbeat reply message.

5. An industrial process controller redundancy operation method according to claim 4, characterized in that: The specific logic for the slave to actively promote to the master when the host is offline is as follows: If the slave controller continuously times out when receiving the heartbeat reply message, it means the host is offline. The slave controller on its side switches to the master, and then continuously sends messages to force the peer to switch to the slave.

6. An industrial process controller redundancy operation method according to claim 4, characterized in that: The logic for the slave to judge the fault level and actively promote to the master cooperates with the application logic to realize the slave to judge the fault level and actively promote to the master. Specifically: The application logic is: the slave controller receives the peer fault level in the heartbeat reply message and compares it with the local fault level; The logic for the slave to judge the fault level and actively promote to the master is: when it is obtained through the application logic comparison that the peer fault level in the heartbeat reply message received by the slave controller is continuously higher than the local fault level, the local side switches to the master, and then continuously sends messages to force the peer to switch to the slave; after the master receives the message to force the local side to switch to the slave, it immediately sets itself as the slave.

7. An industrial process controller redundancy operation method according to claim 4, characterized in that: The logic for the master to receive the tool command to force the master-slave switch is as follows: After the master controller receives the master-slave switch command from the debugging tool side, it sets the forced switch flag bit when replying to the heartbeat message this time; If the forced switch flag bit in the heartbeat message received by the slave controller is set, the local side switches to the master, and then continuously sends messages to force the peer to switch to the slave; After the master receives the message to force the local side to switch to the slave, it immediately sets itself as the slave.

8. An industrial process controller redundancy operation method according to claim 1, characterized in that: The specific logic for online configuration update is as follows: When the debugging tool connects to the master controller and issues an online configuration update command, the host downloads the update message and forwards it to the slave through the configuration redundancy link. After receiving the downloaded update message, the slave updates the local configuration file; Among them, the debugging tool only establishes a connection with the current master controller and issues an online configuration update command to the master controller when online configuration update is required.

9. An industrial process controller redundancy operation system for implementing the method described in any one of claims 1-8, characterized in that: The system includes two industrial process controllers and a redundant Ethernet network; Each controller is provided with a status redundancy module, a configuration redundancy module, a data redundancy module, and a task redundancy module, which are used to execute status redundancy logic, configuration redundancy logic, data redundancy logic, and task redundancy logic respectively; The redundant Ethernet network is provided with a status redundancy link, a configuration redundancy link, a data redundancy link, and a task redundancy link; The status redundancy module, the configuration redundancy module, the data redundancy module, and the task redundancy module operate independently, each using an independent thread to complete related logic tasks, and using the status redundancy link, the configuration redundancy link, the data redundancy link, and the task redundancy link to exchange data respectively.

10. An industrial process controller redundant operation system according to claim 9, wherein: The two industrial process controllers are exactly the same and are interconnected through the physical links A and B of the redundant Ethernet network; The base of the controller is provided with a hardware DIP switch module for manually setting one side as the master controller by default and the other side as the slave controller; The redundant status result negotiated by the status redundancy module can be accessed by other modules and participate in the operation logic of other modules; at the same time, the status redundancy module also exchanges the operation status of both sides; The status redundancy link alternately uses the physical links A and B to send data, and determines that the corresponding physical link is disconnected when the acknowledgment data sent by the physical link A or B is not received continuously; The configuration redundancy link, the data redundancy link, and the task redundancy link use the physical link detected by the status redundancy link to be connected to send data.

11. A terminal, comprising a processor and a storage medium; wherein: The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method according to any one of claims 1-8.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, the steps of the method according to any one of claims 1-8 are implemented.

Citation Information

Patent Citations

  • Main control station and hot standby redundancy control method thereof

    CN114355760A