System redundancy communication method and distributed control system

By receiving and parsing messages from various communication modules in a distributed control system, and combining identity authentication and message reassembly, the controller manages redundant channels, thus solving the problem of limited deployment of redundant communication modules and achieving stable operation and high reliability of the system.

CN119788499BActive Publication Date: 2025-11-21SUPCON TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411863315.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-11-21
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

In distributed industrial control systems, the deployment of redundant communication modules is limited by rack constraints, making it impossible to deploy them in physical locations at great distances, thus preventing the establishment of dedicated physical connections to achieve redundant communication.

Method used

By receiving and parsing messages from each communication module, and combining authentication and message reassembly, the controller manages redundant channels to achieve redundant communication without the need for dedicated physical redundant channels, ensuring stable system operation.

Benefits of technology

Without requiring dedicated physical redundancy channels, it improves the redundancy handling capability and data communication continuity of the distributed control system, ensuring stable system operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788499B_ABST
    Figure CN119788499B_ABST
Patent Text Reader

Abstract

The application discloses a system redundancy communication method and a distributed control system. The method comprises the following steps: receiving first messages sent by a plurality of communication modules respectively; analyzing and recombining the first message sent by each communication module to obtain a second message corresponding to the communication module, and sending the second message to other communication modules except the communication module; when the communication state of the first communication module in the main state is an abnormal state, receiving a first switching message sent by the first communication module, the first switching message carrying an IP address of a second communication module with a network state next to the first communication module, analyzing and recombining the first switching message to obtain a second switching message, and sending the second switching message to the second communication module. The application solves the technical problem that the deployment of the input / output module limited by the rack is limited because the distributed control system installs the redundant communication modules on the same base.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of industrial control technology, and more specifically, to a system redundancy communication method and a distributed control system. Background Technology

[0002] In traditional distributed industrial control systems, controllers are typically connected to redundant communication modules mounted on a rack. These redundant communication modules are then connected to input / output modules via a rack to achieve the input / output functions of the control system. However, this architecture requires the redundant communication modules and input / output modules to be deployed in a unified cabinet and connected via the rack, resulting in limited deployment distance. Furthermore, the redundant communication modules need to be installed on the same rack for redundant interaction.

[0003] With the development of Ethernet technology, especially Advanced Physical Layer (APL) technology, the deployment of input / output modules is no longer limited to the rack and can be flexibly deployed via APL cables. Therefore, communication modules and input / output modules are no longer centrally deployed; the rack and base station are replaced by Ethernet connections. However, this leads to a problem: redundant communication modules may be distributed in two physically distant locations, deployed at the head and tail of a cascaded network. Therefore, it is impossible to establish a dedicated physical connection (such as a base station) as a redundant channel to achieve redundant communication.

[0004] There is currently no effective solution to the above problems. Summary of the Invention

[0005] This application provides a system redundancy communication method and a distributed control system to at least solve the technical problem that the deployment of rack-limited input / output modules is restricted because the distributed control system installs redundant communication modules on the same base.

[0006] According to one aspect of the embodiments of this application, a system redundancy communication method is provided, comprising: receiving a first message sent by a plurality of communication modules in a distributed control system, wherein the plurality of communication modules are deployed in different networks, the first message carries at least the communication status of the communication module, and the communication status is used to reflect the network status of the network in which the communication module is located; parsing and reassembling the first message sent by each communication module to obtain a second message corresponding to the communication module, and sending the second message to other communication modules besides the communication module, wherein each communication module is used to determine whether its working state is a primary state based on the received second message and its own communication status; when the communication status of the first communication module whose working state is a primary state is an abnormal state, receiving a first switching message sent by the first communication module that carries at least the Internet Protocol IP address of a second communication module whose network status is second only to the first communication module, parsing and reassembling the first switching message to obtain a corresponding second switching message, and sending the second switching message to the second communication module, wherein the second communication module is used to switch its working state from a standby state to a primary state.

[0007] Optionally, before receiving the first message sent by each of the multiple communication modules within the distributed control system, the method further includes: receiving authentication request messages sent by each of all communication modules within the distributed control system, wherein the authentication request message carries at least the identity information of the communication module, and the identity information includes at least one of the following: the Internet Protocol IP address of the communication module, the configuration check code of the communication module, the module identifier and module address of each input / output module connected to the communication module; authenticating each communication module according to the authentication request message sent by each communication module; and storing the module identifier and module address of each input / output module connected to the communication module in a preset database if any communication module passes the authentication.

[0008] Optionally, authentication is performed on each communication module based on the authentication request messages sent by each communication module. This includes: for each communication module, matching the identity information in the authentication request message sent by the communication module with a preset database, wherein the database stores: configuration configuration information of all communication modules in the distributed control system, and the configuration configuration information includes at least one of the following: the IP address of the communication module, the configuration check code of the communication module, the module identifier and module address of each input / output module connected to the communication module; if the identity information in the authentication request message of any communication module successfully matches the database, the communication module is determined to have passed authentication; if the identity information in the authentication request message of any communication module fails to match the database, the communication module is determined to have failed authentication.

[0009] Optionally, the first message sent by each communication module is parsed and reassembled to obtain the second message corresponding to the communication module. This includes: parsing and verifying the first message sent by each communication module, wherein the first message also carries a first message sequence number, the module address of the target input / output module that sent the first message, and the module identifier; if the first message sent by any communication module passes the verification, the second message corresponding to the communication module is reassembled from the new first message sequence number, the module address of the target input / output module that sent the first message, and the module identifier.

[0010] Optionally, the first message sent by each communication module is parsed and verified, including: for each first message sent by a communication module, the first message is parsed to obtain at least the first message sequence number, the module address and module identifier of the target input / output module that sent the first message; it is determined whether the module address and module identifier of the target input / output module in the first message match a preset database, wherein the database includes the module addresses and module identifiers of all input / output modules connected to the authentication-enabled communication modules within the distributed control system; if the module address and module identifier of the target input / output module in the first message match the database, it is further determined whether the first message sequence number is continuous with the message sequence number of the previous message; if the first message sequence number of the first message is continuous with the message sequence number of the previous message, the first message is determined to pass the verification; if the module address and module identifier of the target input / output module in the first message fail to match the database and / or the message sequence number of the first message is not continuous with the message sequence number of the previous message, the first message is determined to fail the verification.

[0011] Optionally, the first handover message is parsed and reassembled to obtain the corresponding second handover message, including: parsing and verifying the first handover message, wherein the first handover message also carries a second message sequence number, a handover operation instruction and a corresponding command code; if the first handover message passes the verification, the second handover message is reassembled from the new first message sequence number, the handover operation instruction and the corresponding command code.

[0012] Optionally, parsing and verifying the first handover message includes: parsing the first handover message to obtain at least the second message sequence number of the first handover message and the command code corresponding to the handover operation instruction; determining whether the second message sequence number of the first handover message is continuous with the message sequence number of the previous message; if the first message sequence number of the first handover message is continuous with the message sequence number of the previous message, then further determining whether the command code in the first handover message is valid; if the command code in the first handover message is valid, then the first handover message is determined to have passed the verification; if the second message sequence number of the first handover message is not continuous with the message sequence number of the previous message and / or the command code in the first handover message is invalid, then the first handover message is determined to have failed the verification.

[0013] According to another aspect of the embodiments of this application, a distributed control system is also provided. This distributed control system includes: a controller, multiple communication modules, and multiple input / output modules. The multiple communication modules are deployed in different networks. Each communication module is used to send a first message to the controller. The first message carries at least the communication status of the communication module, and the communication status reflects the network status of the network in which the communication module is located. The controller is used to parse and reassemble the first message sent by each communication module to obtain a second message corresponding to the communication module, and then send the second message to the other communication modules besides the first communication module. Each communication module is also used to receive second messages corresponding to other communication modules sent by the controller, and determine whether its own working state is the primary state based on its own communication status. The communication module whose working state is the primary state is the first communication module. The first communication module is used to send a first switching message to the controller when its own communication status is abnormal, carrying at least the IP address of the second communication module whose network status is second only to the first communication module. The controller is also used to parse and reassemble the first switching message to obtain the corresponding second switching message, and send the second switching message to the second communication module. The second communication module is used to switch its own working state from the standby state to the primary state.

[0014] According to another aspect of the embodiments of this application, a computer program product is also provided, the computer program product comprising: a computer program, wherein the computer program, when executed by a processor, implements the above-described system redundancy communication method.

[0015] According to another aspect of the embodiments of this application, an electronic device is also provided, the electronic device including: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the above-described system redundancy communication method through the computer program.

[0016] In this embodiment, the controller receives first messages sent by multiple communication modules within the distributed control system. These communication modules are deployed in different networks. The first message carries at least the communication status of the communication module, reflecting the network status of the network in which the communication module resides. The controller parses and reassembles the first messages sent by each communication module to obtain a second message corresponding to that module. The second message is then sent to other communication modules besides the first communication module. Each communication module determines whether its operating state is primary based on the received second message and its own communication status. If the communication status of the primary communication module is abnormal, the controller receives a first switching message sent by the first communication module, which carries at least the IP address of a second communication module whose network status is second only to the first communication module. The controller parses and reassembles the first switching message to obtain a corresponding second switching message, which is then sent to the second communication module. The second communication module switches its operating state from standby to primary. The entire redundancy processing process uses the controller as a redundancy channel manager to ensure the high reliability of communication modules and the continuity of data communication in the system without the need for dedicated physical redundancy channels. This achieves the goal of improving the redundancy processing capability of distributed control system equipment and ensuring stable system operation in scenarios where modules are deployed in a distributed manner in industrial fields. In turn, it solves the technical problem that the deployment of input / output modules is limited by rack constraints because the distributed control system installs redundant communication modules on the same base. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0018] Figure 1 This is a schematic diagram of an optional distributed control system architecture according to an embodiment of this application;

[0019] Figure 2 This is a flowchart illustrating an optional system redundancy communication method according to an embodiment of this application;

[0020] Figure 3 This is a schematic diagram of an alternative distributed control system architecture according to an embodiment of this application;

[0021] Figure 4 This is a schematic diagram of the structure of an optional electronic device according to an embodiment of this application. Detailed Implementation

[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0023] It should be noted that the terms "first," "second," etc., used in the specification, claims, and drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0024] To better understand the embodiments of this application, the following is a translation and explanation of some nouns or terms that appear in the description of the embodiments of this application:

[0025] A distributed control system (DCS), also known as a distributed control system, is a computer control system that centrally manages and disperses control of a production process. It is a comprehensive control system that has emerged with the continuous improvement of automation levels in modern large-scale industrial production and the increasing complexity of process control requirements. It integrates computer technology, network technology, communication technology, and automatic control technology, and is a new type of control system that disperses hazards and centralizes and optimizes control.

[0026] Ethernet-APL (Advanced Physical Layer) is a new end-to-end Ethernet communication standard applicable to a wide range of field devices. This standard fully considers the specific needs of the process industry, thus introducing a "two-wire" configuration. This two-wire configuration is used in the concept of two-wire intrinsically safe Ethernet protection devices, enabling not only long-distance cable transmission and intrinsically safe applications, but also powering connected field devices. For networks in the process industry, this new technology provides comprehensive interoperability and greater flexibility.

[0027] Example 1

[0028] This application provides a distributed control system, wherein... Figure 1 This is a schematic diagram of an optional distributed control system 10 according to an embodiment of this application, as shown below. Figure 1 As shown. The system 10 includes:

[0029] Controller 12, also known as control unit, has the ability to connect to and manage communication modules, and can perform data processing and logical operations;

[0030] Multiple communication modules 14 can be connected to the controller 12 via conventional Ethernet (such as Ethernet / IP, HART-IP, OPC UA, etc.); at the same time, they can be connected to multiple input / output modules 16 via the Ethernet APL communication standard to collect and forward control data.

[0031] Multiple input / output modules 16 are capable of acquiring input and output signal data and transmitting it to multiple communication modules 14 via the Ethernet APL communication standard.

[0032] The aforementioned multiple communication modules 14 are deployed in different networks, and each of the multiple communication modules 14 is connected to each input / output module 16k in the distributed control system, so that even if the network where any communication module 14i is located malfunctions, the distributed control system 10 can still transmit control data through redundant communication modules.

[0033] Specifically, the various modules within the distributed control system 10 can implement the system's redundancy function according to the following process:

[0034] Step 1: Each communication module 14i can first send a first message to the controller 12. The first message carries at least the communication status of the communication module 14i, and the communication status is used to reflect the network status of the network in which the communication module 14i is located.

[0035] Step 2: The controller 12 parses and reassembles the first message sent by each communication module 14i to obtain the second message corresponding to the communication module 14i, and sends the second message to the other communication modules 14j (i≠j) except for the communication module 14i.

[0036] Step 3: Each communication module 14i can also receive the second message corresponding to other communication modules 14j sent by the controller 12, and determine whether its own working state is the primary state based on its own communication status. Among them, the communication module 14i whose working state is the primary state is the first communication module.

[0037] Step 4: When the communication status of the first communication module 14i is abnormal, it sends a first switching message to the controller 12, which carries at least the IP address of the second communication module 14k whose network status is second only to its own.

[0038] Step 5: The controller 12 parses and reassembles the first handover message sent by the first communication module 14i to obtain the corresponding second handover message, and sends the second handover message to the second communication module 14j;

[0039] Step 6: The second communication module 14j switches its working status from standby to primary.

[0040] Based on the aforementioned distributed control system 10, this application embodiment also provides a system redundancy communication method applied to the aforementioned controller 12. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than that shown here.

[0041] Figure 2 This is a flowchart illustrating a system redundancy communication method according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:

[0042] Step S202: Receive the first message sent by each of the multiple communication modules in the distributed control system. The multiple communication modules are deployed in different networks. The first message carries at least the communication status of the communication module, and the communication status is used to reflect the network status of the network in which the communication module is located.

[0043] Step S204: Parse and reassemble the first message sent by each communication module to obtain the second message corresponding to the communication module, and send the second message to other communication modules except the communication module. Each communication module is used to determine whether its working state is the primary state based on the received second message and its own communication state.

[0044] Step S206: When the communication status of the first communication module in the primary working state is abnormal, the system receives a first switching message sent by the first communication module, which carries at least the Internet Protocol IP address of the second communication module whose network status is second only to the first communication module. The system then parses and reassembles the first switching message to obtain the corresponding second switching message and sends the second switching message to the second communication module. The second communication module is used to switch its own working state from the standby state to the primary working state.

[0045] The following section describes each step of the system redundancy communication method in conjunction with the specific implementation process.

[0046] As an optional implementation, since control systems frequently handle sensitive data and critical operations, unauthorized access by devices may introduce security vulnerabilities or even lead to system attacks. Therefore, in the distributed control system of this application embodiment, before receiving the first message sent by each of the multiple communication modules, the controller may perform the following steps to verify the legitimacy of each communication module, to prevent unauthorized modules from accessing the system and ensure network and data security:

[0047] Step S1: Receive authentication request messages sent by all communication modules within the distributed control system.

[0048] Specifically, the aforementioned authentication request message carries at least the identity information of the communication module, which includes, but is not limited to: the communication module's Internet Protocol (IP) address, the module identifiers and addresses of each input / output module connected to the communication module, etc., wherein:

[0049] The communication module's IP address is a digital tag assigned to the communication module. In distributed industrial control systems, each communication module is typically assigned one or more IP addresses so that other devices (such as controllers) can find and communicate with it via the network. IP addresses can be statically assigned or dynamically acquired, and are usually formatted as four groups of numbers, each between 0 and 255, separated by dots, such as 192.168.1.2.

[0050] The configuration checksum of the communication module is a specific value generated after the control system is configured. It is used to verify the integrity and consistency of the system configuration. The checksum is updated accordingly when the control system is configured or changed. During communication, comparing the configuration checksums of the sender and receiver ensures that the configuration information received by the receiver has not been tampered with or corrupted. This is crucial for ensuring the control system operates as expected and for maintaining system security.

[0051] The module identifier and module address (also known as module ID) of each input / output module connected to the communication module: This is a unique number assigned to each input / output module in the control system. It can generally be preset by the manufacturer, or it can be set as needed during system installation or configuration, ensuring that each module has a unique identity within the system. Therefore, the module identifier can identify and locate each input / output module in the system.

[0052] It should be noted that the controller can also encrypt the identity information in the authentication request message before transmission, and the encryption key can be determined by the communication module and the controller in advance, thereby ensuring that the authentication request message can be transmitted securely during transmission and preventing the identity information of the communication module from being tampered with, which would lead to unreliable authentication results.

[0053] Step S2: Authenticate each communication module based on the authentication request message sent by each communication module.

[0054] In the technical solution provided in step S2 above, the controller verifies the identity information in the identity authentication request messages sent by each communication module to confirm its legality and consistency.

[0055] Optionally, the controller may authenticate each communication module by following these steps:

[0056] First, the identity information in the authentication request message sent by the communication module is matched with the preset database.

[0057] The database stores the configuration information of all communication modules in the distributed control system, and the configuration information includes at least one of the following: the IP address of the communication module, the configuration check code of the communication module, the module identifier and module address of each input / output module connected to the communication module.

[0058] If the identity information in any authentication request message from a communication module successfully matches the database, the communication module is deemed to have passed authentication.

[0059] If the identity information in any authentication request message from a communication module fails to match the database, it is determined that the communication module has failed authentication.

[0060] During the aforementioned authentication process, the controller executes the authentication procedure based on the extracted identity information to verify whether the communication module is a legitimate member in the control system's preset configuration. Only communication modules that pass authentication are considered valid components of the network; modules that fail authentication will be denied access, thereby ensuring network security and data integrity.

[0061] Step S3: If any communication module passes authentication, store the module identifiers and module addresses of each input / output module connected to the communication module in a preset database.

[0062] Specifically, for communication modules that have passed authentication, the controller further stores the module identifiers and module addresses of the input / output modules connected to them in the database. This storage operation provides a foundation for subsequent data communication and redundancy management, ensuring that the control system accurately tracks and manages legitimate input / output module information, which is beneficial for optimized system configuration and rapid fault location.

[0063] It should be noted that the database updates are dynamic. As communication modules are added, removed, or their status changes, the controller continuously updates the stored information in the database to reflect the latest network status. This dynamic maintenance mechanism ensures the timeliness and accuracy of the control system configuration, providing a reliable information source for real-time data processing and the implementation of redundancy mechanisms.

[0064] As an optional implementation, in the technical solution provided in step S204, the controller can receive and forward messages from each communication module according to the following steps:

[0065] In step S2041, the controller parses and verifies the first message sent by the communication module.

[0066] The first message mentioned above can be a detection message, a real-time status message, a switching message, etc. In addition to the communication status of the communication module, the first message sent by the communication module also carries the first message sequence number, the module address of the target input / output module sending the first message, and the module identifier (module ID).

[0067] Considering that different network communication protocols have different requirements for message format, in order to avoid communication errors caused by protocol incompatibility in the messages transmitted by the communication module, after receiving the first message sent by a certain communication module, the controller can first parse the message to obtain the key information in the message, and then verify this information to ensure normal redundant communication.

[0068] Specifically, the controller can verify the first message sent by each communication module according to the following steps:

[0069] First, the first message is parsed to identify each field in the message, so as to obtain at least the first message sequence number (also known as the serial number), the module address of the target input / output module that sent the first message, and the module identifier.

[0070] Determine whether the module address and module identifier of the target input / output module in the first message match the preset database, wherein the database includes the module addresses and module identifiers of all input / output modules connected to the authentication-enabled communication module within the distributed control system;

[0071] If the module address and module identifier of the target input / output module in the first message match the database successfully, then continue to determine whether the sequence number of the first message is consecutive with the sequence number of the previous message, that is, determine whether the sequence number of the first message matches the next value of the sequence number in the previous message, so as to prevent message loss or duplication.

[0072] If the sequence number of the first message is consecutive to the sequence number of the previous message, then the first message is determined to have passed the verification.

[0073] If the module address and module identifier of the target input / output module in the first message fail to match the database and / or the message sequence number of the first message is not consecutive with the message sequence number of the previous message (which indicates that the data packet is lost or there is a transmission error), then the first message is determined to have failed the verification.

[0074] It should be noted that the above verification process is only an example for illustration. The verification content involved in the verification of the first message, such as checking the continuity of the sequence number, verifying whether the module address and identifier are consistent with the information previously stored in the database, and confirming whether the message format (such as the format and sequence number range) and content meet the expected communication protocol standard, can be set according to the actual application scenario.

[0075] In step S2042, if the first message sent by any communication module passes the verification, the second message corresponding to the communication module is reassembled from the new first message sequence number, the module address of the target input / output module that sent the first message, and the module identifier.

[0076] In other words, once the first message passes verification, the controller will reassemble it into a second message based on the verified information, namely the new first message sequence number, the module address of the target input / output module, and the module identifier. This reassembly process typically involves encapsulating the verified information into the new message according to a specific format (i.e., the message format corresponding to the protocol of the network where other communication modules reside).

[0077] It should be noted that during the reassembly process, the controller can also add additional control information or security authentication information to the second message to ensure that the message can be correctly identified and processed in subsequent transmissions.

[0078] Step S2043: Send the second message to each of the other communication modules except the communication module.

[0079] In other words, the controller reassembles the first messages sent by each communication module into a second message and sends it to other communication modules except itself. This allows each communication module to determine whether it is in the primary state based on the second message received from the controller and its own communication status.

[0080] After each communication module receives the second message sent by the controller corresponding to other communication modules, it can determine whether its own operating state is in the primary state based on the received second message and its own communication status. In other words, the basis for each communication module to determine whether its operating state is in the primary state is the "communication status." Since the communication status reflects the network status of the network in which the communication module is located, and the network status can be reflected by whether the network is faulty and the network fault level (e.g., a high fault level corresponds to a network device fault, and a low fault level corresponds to an excessively long network response event), each communication module can determine whether its own operating state is in the primary state according to the following rules:

[0081] If the communication status of the second message sent by another communication module is abnormal while the communication status of communication module A itself is normal, then communication module A decides to become the primary communication module and updates its working status flag to the primary status.

[0082] If the communication status of the second message received by communication module A from other communication modules is abnormal (such as network device failure, excessively long response time, etc.), and the communication status of communication module A itself is normal, then communication module A needs to make a decision based on its own fault level and the fault levels of other communication modules. If the fault level of communication module A is higher, it decides to become the backup communication module and updates its working status identifier to the backup status; if the fault level of communication module A is lower, it decides to become the primary communication module and updates its working status identifier to the primary status.

[0083] After each communication module determines its primary operating state through the above steps, this module can be designated as the first communication module. If the primary communication module's communication status becomes abnormal, it will proactively send a first switchover message to the controller, carrying at least the IP address of the second communication module whose network status is second only to the primary module, to ensure the normal operation of the distributed control system. Simultaneously, the primary communication module needs to synchronously switch its operating state from primary to standby. The controller can receive and forward this first switchover message according to the following process:

[0084] Upon receiving the first handover message, the controller, taking into account the different communication protocols of the networks where the first and second communication modules reside, can parse and reassemble the first handover message according to the following process to obtain the corresponding second handover message, including:

[0085] Step S2061: Receive a first handover message sent by the first communication module, which carries at least the IP address of a second communication module whose network status is second only to the first communication module.

[0086] Step S2062: The first handover message is parsed and verified. The first handover message also carries the second message sequence number, the handover operation instruction and the corresponding command code.

[0087] Specifically, the controller can verify the first handover message by following these steps:

[0088] First, parse the first handover message to obtain at least the second message sequence number of the first handover message and the command code corresponding to the handover operation instruction;

[0089] Determine whether the sequence number of the second message in the first handover message is consecutive to the sequence number of the previous message;

[0090] If the sequence number of the first switching message is consecutive to the sequence number of the previous message, then continue to determine whether the command code in the first switching message is valid, that is, determine whether the command code is consistent with the command code corresponding to the switching operation predefined in the preset operation command library.

[0091] If the command code in the first handover message is valid, then the first handover message is determined to have passed the verification.

[0092] If the sequence number of the second message in the first handover message is not consecutive with the sequence number of the previous message and / or the command code in the first handover message is invalid, then the first handover message is determined to have failed the verification.

[0093] It should be noted that the above verification process is only an example for illustration. The verification content involved in the first handover message verification—checking the continuity of the sequence number, verifying the validity of the command code, confirming whether the message format (such as the format and range of the sequence number) and content conform to the expected communication protocol standard—can be set according to the actual application scenario. Step S2063: If the first handover message passes the verification, the second handover message is reconstructed from the new second message sequence number, the handover operation instruction, and the corresponding command code.

[0094] Step S2064: Send the second switching message to the second communication module.

[0095] Finally, the second communication module that receives the second switching message can respond to the message to switch its operating state from standby to active state, thereby ensuring that the entire control system can work normally.

[0096] For example, Figure 3 This is an architecture diagram of an optional distributed control system according to an embodiment of this application, such as... Figure 3 As shown. The system includes a controller, two APL communication modules deployed on network A and network B respectively, and multiple input / output modules, which are connected to the two APL communication modules respectively via the Ethernet-APL communication standard.

[0097] Therefore, the APL communication modules on both sides can first send a first message to the controller, and the first message carries their respective communication status; the controller can parse and reassemble the first messages of the APL communication modules on both sides to obtain the corresponding second message, and send the obtained second message to the APL communication module on the other side.

[0098] Next, each of the two APL communication modules can compare the communication status of the other APL communication module with its own communication status in the received second message. If its network is fault-free or the fault level is lower than that of the other APL communication module, it will mark itself as the primary APL communication module.

[0099] Then, if the communication status of the primary APL communication module is abnormal, and a fault occurs or the fault level is higher than that of the counterpart APL communication module, the primary APL communication module will send a first switching message to the controller and update its own mark as the backup APL communication module. The controller can obtain the corresponding second switching message from the first switching message and send the obtained second switching message to the counterpart APL communication module.

[0100] Finally, the APL communication module on the other side receives the second switching message and changes its own marker from the backup APL communication module to the primary APL communication module.

[0101] In the above embodiments, the controller can manage message information from multiple remote communication modules. Each communication module can determine whether its working state is primary based on its own communication status and the communication status of other communication modules sent by the controller. If the communication status of the primary communication module is abnormal, the controller can receive a first switching message sent by the primary communication module, which carries at least the IP address of a second communication module whose network status is second only to the primary communication module. The controller then parses and reassembles the first switching message to obtain a corresponding second switching message, and sends the second switching message to the second communication module. Accordingly, the second communication module can switch its working state from standby to primary based on the second switching message. The entire redundancy processing process uses the controller as a redundancy channel manager to ensure the high reliability of communication modules and the continuity of data communication in the system without the need for dedicated physical redundancy channels. This achieves the goal of improving the redundancy processing capability of distributed control system equipment and ensuring stable system operation in scenarios where modules are deployed in a distributed manner in industrial settings.

[0102] Example 2

[0103] According to an embodiment of this application, a computer program product is also provided, which includes a computer program, wherein when the computer program is executed by a processor, it implements the system redundancy communication method in embodiment 1.

[0104] According to an embodiment of this application, a non-volatile storage medium is also provided, which includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the system redundancy communication method in Embodiment 1 by running the computer program.

[0105] According to an embodiment of this application, a processor is also provided for running a computer program, wherein the computer program executes the system redundancy communication method in embodiment 1 during runtime.

[0106] According to an embodiment of this application, an electronic device is also provided, comprising: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the system redundancy communication method of Embodiment 1 through the computer program.

[0107] Specifically, the computer program executes the following steps during runtime: receiving first messages sent by multiple communication modules within the distributed control system, wherein the multiple communication modules are deployed in different networks, and the first message carries at least the communication status of the communication module, which reflects the network status of the network in which the communication module is located; parsing and reassembling the first message sent by each communication module to obtain a second message corresponding to the communication module, and sending the second message to other communication modules besides the first communication module, wherein each communication module determines whether its working state is the primary state based on the received second message and its own communication status; if the communication status of the first communication module in the primary state is abnormal, receiving a first switching message sent by the first communication module that carries at least the Internet Protocol IP address of the second communication module whose network status is second only to the first communication module, parsing and reassembling the first switching message to obtain the corresponding second switching message, and sending the second switching message to the second communication module, wherein the second communication module switches its working state from the standby state to the primary state.

[0108] As an alternative implementation, the above-mentioned electronic device may exist in the form of a mobile terminal, a computer terminal, or a similar computing device. Figure 4 A hardware block diagram of an electronic device for implementing a system redundancy communication method is shown. (See diagram for example.) Figure 4 As shown, the electronic device 40 may include one or more processors 402 (shown as 402a, 402b, ..., 402n in the figure) 402 (processor 402 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 404 for storing data, and a transmitting device 406 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 4 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, electronic device 40 may also include... Figure 4 The more or fewer components shown, or having the same Figure 4 The different configurations shown.

[0109] It should be noted that the aforementioned one or more processors 402 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element of the electronic device 40. As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0110] The memory 404 can be used to store software programs and modules of application software, such as the program instruction / data storage device corresponding to the system redundancy communication method in this embodiment. The processor 402 executes various functional applications and data processing by running the software programs and modules stored in the memory 404, thereby implementing the above-mentioned application vulnerability detection method. The memory 404 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 404 may further include memory remotely located relative to the processor 402, and these remote memories can be connected to the electronic device 40 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0111] The transmitting device 406 is used to receive or transmit data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the electronic device 40. In one example, the transmitting device 406 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmitting device 406 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0112] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the electronic device 40.

[0113] The sequence numbers of the above embodiments are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0114] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0115] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0116] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0117] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0118] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0119] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A system redundancy communication method, characterized in that, include: The system receives first messages sent by multiple communication modules within a distributed control system. The multiple communication modules are deployed in different networks. The first message carries at least the communication status of the communication module, and the communication status reflects the network status of the network in which the communication module is located. The first message sent by each of the communication modules is parsed and reassembled to obtain the second message corresponding to the communication module, and the second message is sent to other communication modules besides the communication module. Each of the communication modules is used to determine whether its working state is the primary state based on the second message received and its own communication state. When the communication status of the first communication module, which is in the primary working state, is in an abnormal state, the system receives a first switching message sent by the first communication module, which carries at least the Internet Protocol IP address of the second communication module whose network status is second only to the first communication module. The system then parses and reassembles the first switching message to obtain the corresponding second switching message and sends the second switching message to the second communication module. The second communication module is used to switch its own working state from the standby state to the primary working state.

2. The method according to claim 1, characterized in that, Before receiving the first message sent by each of the multiple communication modules within the distributed control system, the method further includes: The system receives authentication request messages sent by each of the communication modules within the distributed control system. Each authentication request message carries at least the identity information of the communication module, and the identity information includes at least one of the following: the Internet Protocol IP address of the communication module, the configuration check code of the communication module, and the module identifier and module address of each input / output module connected to the communication module. Each communication module is authenticated based on the authentication request message sent by each of the communication modules. If any of the communication modules passes authentication, the module identifiers and module addresses of each input / output module connected to the communication module in the authentication request message are stored in a preset database.

3. The method according to claim 2, characterized in that, Authentication is performed on each communication module based on the authentication request message sent by each of the communication modules, including: For each of the communication modules, the identity information in the authentication request message sent by the communication module is matched with a preset database. The database stores the configuration information of all communication modules in the distributed control system, and the configuration information includes at least one of the following: the IP address of the communication module, the configuration check code of the communication module, the module identifier and module address of each input / output module connected to the communication module. If the identity information in any of the authentication request messages of the communication module is successfully matched with the database, it is determined that the communication module has passed the authentication. If the identity information in any of the authentication request messages of the communication module fails to match the database, it is determined that the communication module has failed authentication.

4. The method according to claim 1, characterized in that, The first message sent by each of the communication modules is parsed and reassembled to obtain the second message corresponding to the communication module, including: The first message sent by each of the communication modules is parsed and verified, wherein the first message also carries the first message sequence number, the module address of the target input / output module that sent the first message, and the module identifier; If the first message sent by any of the communication modules passes the verification, the second message corresponding to the communication module is reconstructed from the new first message sequence number, the module address of the target input / output module that sent the first message, and the module identifier.

5. The method according to claim 4, characterized in that, The first message sent by each of the communication modules is parsed and verified, including: For each of the communication modules sending a first message, the first message is parsed to obtain at least the first message sequence number of the first message, the module address of the target input / output module that sent the first message, and the module identifier. Determine whether the module address and module identifier of the target input / output module in the first message match a preset database, wherein the database includes the module addresses and module identifiers of all input / output modules connected to the authentication-enabled communication module within the distributed control system; If the module address and module identifier of the target input / output module in the first message match the database, then continue to determine whether the sequence number of the first message is consecutive to the sequence number of the previous message. If the sequence number of the first message is consecutive to the sequence number of the previous message, then the first message is determined to have passed the verification. If the module address and module identifier of the target input / output module in the first message fail to match the database and / or the message sequence number of the first message is not continuous with the message sequence number of the previous message, then the first message is determined to have failed the verification.

6. The method according to claim 1, characterized in that, The first handover message is parsed and reassembled to obtain the corresponding second handover message, including: The first switching message is parsed and verified, wherein the first switching message also carries a second message sequence number, a switching operation instruction and a corresponding command code; If the first handover message passes the verification, the second handover message is reassembled from the new second message sequence number, the handover operation instruction, and the corresponding command code.

7. The method according to claim 6, characterized in that, The first handover message is parsed and verified, including: The first handover message is parsed to obtain at least the second message sequence number of the first handover message and the command code corresponding to the handover operation instruction; Determine whether the sequence number of the second message of the first switching message is consecutive to the sequence number of the previous message; If the sequence number of the first message in the first switching message is consecutive to the sequence number of the previous message, then continue to determine whether the command code in the first switching message is valid. If the command code in the first handover message is valid, then the first handover message is determined to have passed the verification. If the sequence number of the second message in the first switching message is not consecutive with the sequence number of the previous message and / or the command code in the first switching message is invalid, then the first switching message is determined to have failed the verification.

8. A distributed control system, characterized in that, The distributed control system includes: a controller, multiple communication modules, and multiple input / output modules, wherein the multiple communication modules are deployed in different networks. Each of the plurality of communication modules is used to send a first message to the controller, wherein the first message carries at least the communication status of the communication module, and the communication status is used to reflect the network status of the network in which the communication module is located. The controller is used to parse and reassemble the first message sent by each of the communication modules to obtain the second message corresponding to the communication module, and send the second message to other communication modules besides the communication module. Each of the plurality of communication modules is also used to receive the second message corresponding to other communication modules sent by the controller, and determine whether its own working state is the primary state based on its own communication state, wherein the communication module whose working state is the primary state is the first communication module. The first communication module is used to send a first switching message to the controller when its own communication status is abnormal, carrying at least the IP address of a second communication module whose network status is second only to the first communication module. The controller is further configured to parse and reassemble the first switching message to obtain a corresponding second switching message, and send the second switching message to the second communication module; The second communication module is used to switch its working state from standby state to primary state.

9. A computer program product, characterized in that, include: A computer program, wherein when executed by a processor, the computer program implements the system redundancy communication method according to any one of claims 1 to 7.

10. An electronic device, characterized in that, include: A memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the system redundancy communication method of any one of claims 1 to 7 through the computer program.

Citation Information

Patent Citations

  • Method for switching DCS redundant communication module

    CN107992027A

  • PAS100 control system's controller and redundant framework of bus

    CN204883338U