Temperature standby control system

By using dual redundant PLC configuration and relay in industrial water supply systems to achieve automatic fault switching, the problem of long recovery time of existing systems when the main PLC fails is solved, and the reliability and stability of the system are improved.

CN119914508APending Publication Date: 2025-05-02SHANGHAI LIANCHENG(GRP) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311419152.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-30
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

When the main PLC fails, the existing industrial water supply system is restored for a long time, which affects production, and has poor system stability, so it is impossible to determine the failure recovery time.

Method used

Using a dual redundant PLC configuration, the main and backup controller realizes automatic fault switching through hardware fault detection relays, software fault detection relays and rotation control relays to ensure seamless system switching.

Benefits of technology

It greatly improves the reliability and stability of the system, reduces failure time, achieves uninterrupted production, and improves the degree of automation of the system and human-computer interactivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119914508A_ABST
    Figure CN119914508A_ABST
Patent Text Reader

Abstract

The invention relates to the field of industrial water supply systems, and discloses a temperature standby control system. The water pump unit comprises a plurality of water pumps and alternating current contactors corresponding to the water pumps; the main control unit comprises a main controller, and a hardware fault detection relay, a software fault detection relay and an alternate control relay of the main controller; the standby control unit comprises a standby controller and an alternate control relay of the standby controller; wherein the output end of the main controller is connected with an alternating current contactor of the water pump to control the water pump, and the main controller transmits a fault signal and an alternating signal to the standby controller through the hardware fault detection relay, the software fault detection relay and the alternating control relay; the standby controller takes over control over the water pump when detecting the fault of the main controller or an alternating signal, and seamless switching between the standby controller and the water pump is achieved. The fault time of the system is remarkably shortened, and the stability and effectiveness of the system are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of industrial water supply systems, and in particular to a temperature standby control system based on redundant PLC. Background Art

[0002] Currently, most PLC-based water supply systems utilize a single PLC to control multiple pumps. While the electrical technology for this system is mature, its most notable characteristic is that it only contains a single PLC. Even when backup is employed, it is typically a cold standby system, where the backup PLC is stored in a warehouse and replaced only if the primary PLC fails. This cold standby system rarely considers response time and is limited by the proficiency of maintenance personnel. Consequently, when the primary PLC fails, system recovery takes a significant time, resulting in significant production losses, particularly in the industrial cooling water circulation sector.

[0003] This single PLC control has the following disadvantages: (1) Long system downtime: After the main PLC fails, it must wait for the operation and maintenance personnel to replace it. The recovery time depends on the response time and proficiency, which is uncertain. (2) Poor system stability: Replacing the PLC takes a certain amount of time, during which the system cannot work, affecting the stability and efficiency of the system. Summary of the Invention

[0004] The purpose of this application is to provide a temperature standby control system to solve the problems raised in the above background technology.

[0005] The present application discloses a temperature standby control system, comprising:

[0006] The water pump unit includes multiple water pumps and an AC contactor corresponding to each water pump;

[0007] A main control unit, comprising a main controller, a hardware fault detection relay, a software fault detection relay and a rotation control relay of the main controller;

[0008] The standby control unit includes a standby controller and a rotation control relay of the standby controller; wherein,

[0009] The output end of the main controller is connected to the AC contactor of the water pump to control the water pump, and the main controller transmits the fault signal and the rotation signal to the standby controller through the hardware fault detection relay, the software fault detection relay, and the rotation control relay. When the standby controller detects a fault or a rotation signal of the main controller, it takes over the control of the water pump to achieve seamless switching between the two.

[0010] In a preferred embodiment, the standby control unit further comprises a hardware fault detection relay and a software fault detection relay of the standby controller respectively connected to the main controller, wherein:

[0011] The hardware fault detection relay of the backup controller is used to transmit the hardware fault signal of the backup controller to the main controller, and the software fault detection relay is used to transmit the software fault signal of the backup controller to the main controller. When the main controller detects the fault or rotation signal of the backup controller, it takes over the control of the water pump to achieve seamless switching between the two.

[0012] In a preferred example, the water pump unit further includes a manual-automatic water pump conversion switch corresponding to each water pump, the output end of the manual-automatic water pump conversion switch is connected to the corresponding water pump, for controlling the start and stop of the water pump, and the input end of the manual-automatic water pump conversion switch is connected to the main controller and the backup controller, for feeding back the manual or automatic working mode of the water pump to the main controller and the backup controller.

[0013] In a preferred example, the water pump unit further includes a water pump thermal relay corresponding to each water pump, wherein the input end of the water pump thermal relay is connected to the output end of the corresponding water pump AC contactor, and the output end of the water pump thermal relay is connected to the input end of the corresponding water pump. The water pump thermal relay is used to monitor and protect the overload condition of the water pump in real time, and disconnect the circuit when the water pump overload is detected.

[0014] In a preferred example, the water pump unit further includes a circuit breaker corresponding to each water pump, wherein the input end of the circuit breaker is connected to an AC power supply, and the output end is connected to the corresponding water pump. The circuit breaker is used to isolate and protect the power supply line of the water pump and disconnect the circuit when a water pump fails.

[0015] In a preferred example, the main control unit also includes a protection fuse for the main controller, the input end of the main controller protection fuse is connected to the AC power supply, and the output end is connected to the power input end of the main controller, and the main controller protection fuse is used to protect the power line of the main controller from overload and short circuit.

[0016] In a preferred example, the backup control unit also includes a protection fuse for the backup controller, the input end of the backup controller protection fuse is connected to the AC power supply, and the output end is connected to the power input end of the backup controller, and the backup controller protection fuse is used to protect the power line of the backup controller from overload and short circuit.

[0017] In a preferred example, a control circuit protection fuse is also included, the input end of the control circuit protection fuse is connected to the AC power supply, and the output end is connected to the power input end of the control circuit. The control circuit protection fuse is used to protect the power line of the control circuit from overload and short circuit.

[0018] In a preferred embodiment, the main controller and the backup controller are two identical programmable logic controllers with the same model and performance parameters.

[0019] In the implementation mode of the present application, a dual redundant PLC configuration is adopted, which greatly improves the reliability of the system. The mutual inspection and interconnection between the PLCs can realize automatic fault switching and uninterrupted production. The on-site operation switch ensures the controllability of the water pump. The intermediate relay isolates the signal transmission and improves the anti-interference performance. Thermal relays, fuses and other protective devices improve the self-protection capability of the system. In summary, the system makes full use of the PLC redundant configuration and the intermediate relay for interlocking monitoring, achieving high reliability, high availability and good human-computer interactivity of the water pump control.

[0020] The specification of this application records a large number of technical features, which are distributed in various technical solutions. If all possible combinations of technical features of this application (i.e., technical solutions) are to be listed, the specification will be too lengthy. In order to avoid this problem, the various technical features disclosed in the above content of this application, the various technical features disclosed in the various embodiments and examples below, and the various technical features disclosed in the accompanying drawings can be freely combined with each other to form various new technical solutions (these technical solutions are all deemed to have been recorded in this specification), unless such a combination of technical features is technically infeasible. For example, in one example, feature A+B+C is disclosed, and in another example, feature A+B+D+E is disclosed. Features C and D are equivalent technical means that play the same role. Technically, only one of them can be used, and it is impossible to use them at the same time. Feature E can be technically combined with feature C. Then, the solution of A+B+C+D should not be considered as having been recorded because it is technically infeasible, while the solution of A+B+C+E should be considered as having been recorded. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 1 is a schematic structural diagram of a temperature standby control system according to the first embodiment of the present application;

[0022] Figure 2 is another structural schematic diagram of the temperature standby control system according to the first embodiment of the present application;

[0023] Figure 3 is another structural schematic diagram of the temperature standby control system according to the first embodiment of the present application;

[0024] Figure 4 It is a schematic diagram of the working principle of the temperature standby control system according to the first embodiment of the present application. DETAILED DESCRIPTION

[0025] In the following description, many technical details are provided to help readers better understand this application. However, those skilled in the art will understand that even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in this application can be implemented.

[0026] Description of some concepts:

[0027] A PLC (Programmable Logic Controller) is a programmable digital electronic device used to perform logical operations, sequential control, timing scheduling, and counting calculations in industrial process control. Following user-programmed control logic programs, the PLC acquires real-time field input signals and, through internal logic operations, generates output control signals, enabling real-time monitoring and automatic control of industrial processes.

[0028] Warm standby control, a hot backup control system, uses a primary and backup controller to achieve high-reliability redundant control. This refers to the use of a primary and backup controller within a control system to provide redundant control tasks. The primary controller provides real-time control of the process, while the backup controller can quickly take over control in the event of a primary controller failure, significantly improving system reliability. This dual-redundant hot backup control method ensures seamless system failover and uninterrupted process control in the event of a primary controller failure.

[0029] An AC contactor is an electromagnetic switching device used to connect and disconnect loads. It is a type of electromagnetic switching device used to connect and disconnect AC circuits. It can be remotely operated and automatically controlled, and is typically used to isolate and protect load circuits. It uses the principle of electromagnetic attraction to connect and disconnect moving contacts by switching a coil.

[0030] Intermediate relays are electrical devices used for signal transmission and logic control between electrical circuits. They implement functions such as signal isolation, transmission, delay, and identification between electrical automatic control circuits. The contacts of intermediate relays can implement different logic control and signal transmission connections based on control requirements.

[0031] A fuse is a device used to protect circuits from overloads and overcurrents. It contains a fusible link that melts when excessive current flows, thus disconnecting the circuit and providing protection. The link must be replaced before reclosing the fuse.

[0032] Thermal relays are used to protect motors from overload. They use a thermistor to detect motor current and, in the event of an overload, thermally disconnect the motor's power contactor coil circuit, effectively breaking the motor's circuit.

[0033] The following is a summary of some of the innovative features of this application:

[0034] In response to the aforementioned technical problems, the inventors of this application have creatively proposed a new type of redundant PLC-based warm standby control system, the main structure of which includes: N water pumps, two logic controllers, low-voltage electrical components and other units. Taking the control system of two water pumps as an example, Figure 1 、 Figure 2 and Figure 3 The water pump group 1 (M1, M2) is controlled and operated by a programmable controller 5 (PLC1, PLC2). The two programmable controllers (PLC1, PLC2) are completely identical configuration components and are in a master-slave relationship; PLC1 is the master, and PLC2 is on standby and does not operate in a redundant warm standby state; when a hardware failure or software failure occurs in the master controller PLC1, it can automatically switch to the standby controller PLC2 for operation in the shortest possible time. According to the technical solution of the present application, there are significant technical effects: the system is equipped with two programmable controllers, and the control logic of the entire system is completely consistent. After the master PLC1 fails, the redundant warm standby PLC2 can respond and be put into operation control in the shortest possible time, and the subsequent PLC fault maintenance process is carried out without sacrificing process control, thereby reducing the system's failure time and improving the stability and effectiveness of the entire system. At the same time, the PLC of the system can perform a timed rotation function to avoid aging and damage to the PLC due to long-term use of a single PLC, thereby affecting the normal operation of the system.

[0035] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0036] The first embodiment of the present application relates to a temperature standby control system, the structure of which is as follows: Figure 1 , Figure 2 and Figure 3 As shown, the system includes the following main components:

[0037] Multiple water pumps:

[0038] M1, i.e., the first water pump; M2, i.e., the second water pump;

[0039] AC contactor for each water pump:

[0040] KM1, i.e., the first water pump AC contactor; KM2, i.e., the second water pump AC contactor;

[0041] Transfer switch for each pump:

[0042] SA1, i.e., the first water pump manual switch; SA2, i.e., the second water pump manual switch.

[0043] Circuit breaker for each pump:

[0044] QF10, i.e., the first water pump circuit breaker; QF11, i.e., the second water pump circuit breaker;

[0045] Thermal relay for each water pump:

[0046] KH1 is the first water pump thermal relay; KH2 is the second water pump thermal relay.

[0047] Master and standby controller PLC:

[0048] PLC1, i.e., the main controller; PLC2, i.e., the backup controller;

[0049] Multiple intermediate relays:

[0050] KA1, i.e., the manual-automatic transfer switch for the water pump; KA2, i.e., the manual-automatic transfer switch for the water pump; KA3, i.e., the PLC1 hardware fault detection relay; KA4, i.e., the PLC1 software fault detection relay; KA5, i.e., the PLC2 hardware fault detection relay; KA6, i.e., the PLC2 software fault detection relay; KA7, i.e., the PLC1 rotation control relay; KA8, i.e., the PLC2 rotation control relay;

[0051] Indicator Lights:

[0052] HL1, i.e., the system power indicator light; HL2, i.e., the first water pump running indicator light; HL3, i.e., the second water pump running indicator light; HL4, i.e., the PLC1 hardware normal indicator light; HL5, i.e., the PLC1 software normal indicator light; HL6, i.e., the PLC2 hardware normal indicator light; HL7, i.e., the PLC2 software normal indicator light;

[0053] Fuse:

[0054] FU1, that is, PLC1 protection fuse; FU2, that is, PLC2 protection fuse; FU3, that is, control circuit protection fuse;

[0055] The temperature standby control system of this embodiment will be described in further detail below with reference to the accompanying drawings.

[0056] PLC1, the master controller:

[0057] PLC1 is the main controller in the system, implemented using a programmable logic controller. Its inputs are connected to the pump's manual-automatic transfer switches KA1 and KA2. PLC1 executes control logic based on the pump's status, as reported by the manual-automatic transfer switches KA1 and KA2. Its outputs are connected to the pump's AC contactors KM1 and KM2, implementing pump control. PLC1's outputs are connected to relays KA3 and KA4, transmitting their own status signals. PLC1's inputs are connected to relay KA7, detecting the rotation signal from the redundant PLC2. PLC1 implements the automatic control and fault monitoring procedures for the pump. PLC1 is connected to the HMI for process monitoring and operating parameter setting. After system startup, PLC1 becomes the main controller, executing the pump's control logic. PLC1 and the redundant PLC2 form a primary-backup redundancy mechanism, improving system reliability. In summary, PLC1 is the main controller that executes the main control logic for the pump, and it automatically switches control with PLC2.

[0058] PLC2, i.e., the standby controller

[0059] PLC2 and PLC1 are identical programmable logic controllers, with identical models and performance parameters. PLC2 serves as the system's redundant, warm-standby controller, automatically taking over pump control if PLC1 fails. Its inputs are connected to the pumps' manual-to-automatic transfer switches, KA1 and KA2, to receive pump status information. Its inputs are connected to KA3 and KA7 to detect hardware and software fault signals from PLC1. PLC2's outputs are connected to each pump's AC contactor to control the pumps. PLC2's outputs are connected to KA5 and KA6 to provide feedback on its status to PLC1. After system power is applied, PLC2 assumes redundant, warm-standby mode, ready to take over at any time. If PLC1 fails, PLC2 determines the fault type and immediately assumes pump control. After PLC2 switches, it controls each pump's operation through its AC contactor. Seamless switchover between PLC2 and PLC1 ensures reliable system operation. In summary, PLC2, acting as a backup controller, automatically assumes pump control if the primary controller fails, ensuring system reliability.

[0060] M1, i.e., the first water pump, M2, i.e., the second water pump

[0061] M1 and M2 are the two water pumps in pump group 1, each driven by an electric motor. The power supplies for M1 and M2 are connected to the output terminals of circuit breakers QF10 and QF11, respectively. The motors for M1 and M2 are connected to the PLC digital outputs via KM1 and KM2, respectively. The activation of KM1 and KM2 is controlled by PLC1 or PLC2, respectively, enabling remote control of the water pumps. M1 and M2 are connected to thermal relays KH1 and KH2, respectively, for overload protection. M1 and M2 have manual switches SA1 and SA2, respectively, for on-site control. Together, M1 and M2 perform water pumping and delivery functions. The combined operation of M1 and M2 enables redundant water supply. The PLC controls M1 and M2 in a coordinated manner based on control logic.

[0062] KM1, i.e., the first water pump AC contactor

[0063] The input end of KM1 is connected to the three-phase power supply line of the first water pump M1. The output end of KM1 is connected to the three-phase winding of the M1 motor. The coil input end of KM1 is connected to the digital output point Q0.0 of PLC1 and PLC2 respectively. The KM1 coil is energized to attract, connect the three-phase power supply of M1, and start M1. PLC1 or PLC2 starts or stops M1 by controlling the attraction and release of KM1. KM1 plays the role of automatic control function of isolating and attracting the power supply of the first water pump M1. KM1 cooperates with the thermal relay KH1 to protect M1 from overload. The use of KM1 enhances the control reliability of the first water pump M1. KM1 realizes remote automatic operation control of the first water pump M1. In summary, KM1 is the AC isolation and attraction control device of the first water pump M1, and remote automatic control is realized by PLC.

[0064] KM2, i.e., the second water pump AC contactor

[0065] The input end of KM2 is connected to the three-phase power supply line of the second water pump M2. The output end of KM2 is connected to the three-phase winding of the M2 motor. The coil input end of KM2 is connected to the digital output point Q0.1 of PLC1 and PLC2 respectively. The coil of KM2 is energized, causing it to attract, connecting the three-phase power supply of M2 and starting M2. PLC1 or PLC2 starts or stops M2 by controlling the attraction and release of KM2. KM2 performs the automatic control function of isolating and attracting the power supply of the second water pump M2. KM2 cooperates with the thermal relay KH2 to protect M2 from overload. The use of KM2 enhances the control reliability of the second water pump M2. KM2 realizes remote automatic operation control of the second water pump M2. In summary, KM2 is the AC isolation and attraction control device of the second water pump M2, and remote automatic control is realized by PLC.

[0066] KA1, i.e., water pump manual-automatic transfer switch

[0067] The coil of KA1 is connected to the Q0.2 digital output point of the main controller PLC1. The normally closed contact of KA1 is connected to the I0.2 digital input point of the backup controller PLC2. When PLC1 is operating normally, Q0.2 has an output, the KA1 coil is energized, and the normally closed contact is open. When a hardware fault occurs in PLC1, Q0.2 has no output, the KA1 coil is de-energized, and the normally closed contact is closed. PLC2 determines whether there is a hardware fault in PLC1 by monitoring the input status of I0.2. KA1 plays the role of transmitting the hardware fault signal from PLC1 to PLC2. When the normally closed contact of KA1 is closed, PLC2 determines that PLC1 has a hardware fault and initiates the backup takeover. KA1 realizes the interconnection and interoperability of the hardware fault status between the main and backup PLCs. KA1 enables PLC2 to accurately determine the hardware fault status of PLC1. The use of KA1 enhances the reliability of the system based on redundant PLCs.

[0068] KA2, i.e., water pump manual-automatic transfer switch

[0069] KA2 is the status feedback relay for the manual / automatic switch SA2 corresponding to the second water pump M2. KA2's coil is connected to the output terminal of SA2. KA2's normally open contact is connected to input point I0.1 of PLC1 and PLC2. When SA2 is manually closed, KA2's coil is de-energized, and the normally open contact closes, providing feedback to PLC1 and PLC2 on M2's manual shutdown status. When SA2 is automatically closed, KA2's coil is energized, and the normally open contact opens, providing feedback to PLC1 and PLC2 on M2's automatic operation status. SA2's status feedback allows PLC1 and PLC2 to determine whether M2 is currently in manual or automatic control mode. Based on M2's control mode, PLC1 and PLC2 implement corresponding logic to ensure reliable system operation. The coordinated use of KA2 and SA2 enhances the control reliability of water pump M2. In the event of a PLC1 failure, KA2 provides feedback to PLC2 on M2's operating status. KA2 enables feedback and transmission of M2's status signals to both PLCs. In summary, KA2 is an intermediate relay that implements manual / automatic status feedback of the second water pump M2, and implements M2's operating status feedback to PLC1 and PLC2.

[0070] KA3, i.e., PLC1 hardware fault detection relay

[0071] The KA3 coil is connected to the Q0.2 digital output of the primary controller, PLC1. KA3's normally closed contact is connected to the I0.2 digital input of the backup controller, PLC2. When PLC1 is operating normally, Q0.2 outputs, KA3 coil is energized, and the normally closed contact opens. When a hardware fault occurs in PLC1, Q0.2 stops outputting, KA3 coil is de-energized, and the normally closed contact closes. PLC2 monitors the I0.2 input status to determine if PLC1 has a hardware fault. KA3 transmits hardware fault signals from PLC1 to PLC2. When KA3's normally closed contact closes, PLC2 detects a hardware fault in PLC1 and initiates takeover of the backup controller. KA3 enables interoperability between the primary and backup PLCs. KA3 enables PLC2 to accurately determine the hardware fault status of PLC1. The use of KA3 enhances the reliability of redundant PLC systems. In summary, KA3 acts as an intermediate relay that transmits PLC1's hardware fault status signal, implementing hardware fault detection interlocking between the primary and backup PLCs.

[0072] KA4, i.e., PLC1 software fault detection relay

[0073] The KA4 coil is connected to the Q0.3 digital output of the primary controller, PLC1. KA4's normally open contact is connected to the I0.3 digital input of the backup controller, PLC2. When PLC1 is operating normally, Q0.3 has no output, the KA4 coil is de-energized, and the normally open contact opens. When a software fault occurs in PLC1, Q0.3 has an output, the KA4 coil is energized, and the normally open contact closes. PLC2 monitors the I0.3 input status to determine whether PLC1 has a software fault. KA4 transmits a software fault signal from PLC1 to PLC2. When the KA4 normally open contact closes, PLC2 identifies a software fault in PLC1 and initiates backup takeover. KA4 enables interoperability between the primary and backup PLCs regarding software fault status. KA4 enables PLC2 to accurately determine the software fault status of PLC1. The use of KA4 enhances the reliability of redundant PLC systems. In summary, KA4 acts as an intermediate relay that transmits PLC1's software fault status signal, implementing software fault detection interlocking between the primary and backup PLCs.

[0074] KA5, PLC2 hardware fault detection relay

[0075] The KA5 coil is connected to the Q0.2 digital output point of the standby controller PLC2. The normally closed contact of KA5 is connected to the I0.2 digital input point of the main controller PLC1. When PLC2 is operating normally, Q0.2 has an output, the KA5 coil is energized, and the normally closed contact is open. When a hardware fault occurs in PLC2, Q0.2 has no output, the KA5 coil is de-energized, and the normally closed contact is closed. PLC1 determines whether PLC2 has a hardware fault by monitoring the I0.2 input status. KA5 transmits the hardware fault signal from PLC2 to PLC1. When the KA5 normally closed contact is closed, PLC1 determines that PLC2 has a hardware fault and does not switch control. KA5 realizes the interconnection and interoperability of the hardware fault status between the main and standby PLCs.

[0076] KA5 enables PLC1 to accurately determine if PLC2 has hardware faults. The use of KA5 enhances the reliability of redundant PLC systems. In summary, KA5 is an intermediate relay that transmits PLC2 hardware fault status signals, enabling interlocking of active and standby PLC hardware fault determination.

[0077] KA6, PLC2 software fault detection relay

[0078] The KA6 coil is connected to the Q0.3 digital output of the backup controller, PLC2. KA6's normally open contact is connected to the I0.3 digital input of the primary controller, PLC1. When PLC2 is operating normally, Q0.3 has no output, the KA6 coil is de-energized, and the normally open contact opens. When a software fault occurs in PLC2, Q0.3 has an output, the KA6 coil is energized, and the normally open contact closes. PLC1 monitors the I0.3 input status to determine whether PLC2 has a software fault. KA6 transmits a software fault signal from PLC2 to PLC1. When the KA6 normally open contact closes, PLC1 determines that PLC2 has a software fault and does not transfer control. KA6 enables interoperability between the primary and standby PLCs regarding software fault status. KA6 enables PLC1 to accurately determine the software fault status of PLC2. The use of KA6 enhances the reliability of redundant PLC systems. In summary, KA6 serves as an intermediate relay that transmits the PLC2 software fault status signal, enabling interlocking of primary and standby PLC software fault detection.

[0079] KA7, i.e., PLC1 rotation control relay

[0080] The KA7 coil is connected to the Q0.4 digital output of the primary controller, PLC1. KA7's normally open contact is connected to the I0.4 digital input of the backup controller, PLC2. When control rotation is not required, Q0.4 has no output, the KA7 coil is de-energized, and the normally open contact opens. When control rotation is required, Q0.4 has an output, the KA7 coil is energized, and the normally open contact closes. PLC2 determines whether control rotation is necessary by monitoring the state of the I0.4 input. KA7 transmits a control rotation instruction signal from PLC1 to PLC2. When the KA7 normally open contact closes, PLC2 takes over control, completing a seamless switchover with PLC1. KA7 implements controller rotation linkage between the primary and standby PLCs. KA7 enables the system to automatically and reliably switch between PLCs. The use of KA7 enhances the reliability of systems based on redundant PLCs. In summary, KA7 is an intermediate relay that sends PLC control rotation instructions, enabling seamless switching between the primary and standby PLCs.

[0081] KA8, i.e., PLC2 rotation control relay

[0082] The KA8 coil is connected to the Q0.4 digital output of the backup controller, PLC2. KA8's normally open contact is connected to the I0.4 digital input of the primary controller, PLC1. When control rotation is not required, Q0.4 has no output, the KA8 coil is de-energized, and the normally open contact opens. When control rotation is required, Q0.4 has an output, the KA8 coil is energized, and the normally open contact closes. PLC1 determines whether control rotation is necessary by monitoring the state of the I0.4 input. KA8 functions as a signal from PLC2 to PLC1 for controller rotation. When the KA8 normally open contact closes, PLC1 relinquishes control, completing a seamless switchover with PLC2. KA8 implements controller rotation linkage between the primary and standby PLCs. KA8 enables the system to automatically and reliably switch between PLCs. The use of KA8 enhances the reliability of systems based on redundant PLCs. In summary, KA8 is an intermediate relay that sends PLC control rotation commands, enabling seamless switching between the primary and standby PLCs.

[0083] HL1, i.e., system power indicator

[0084] The HL1 input is connected to the positive line of the system power supply. When the system power supply is connected and the circuit is energized, the HL1 lights up. The HL1 indicates the system power supply status. The on / off status of the HL1 indicates whether the system power supply is functioning properly. The HL1 typically uses a green indicator light. Checking the HL1 helps monitor the system power supply quality. In summary, the HL1 is a power supply status indicator that monitors the system power supply, and its on / off status indicates whether the system power supply is functioning properly.

[0085] HL2, i.e., the first water pump running indicator light

[0086] The input of HL2 is connected to the digital output Q0.0 of PLC1 and PLC2. When Q0.0 has an output, HL2 lights up. HL2 is used to indicate the operating status of the first water pump M1. When HL2 is on, it indicates that the first water pump M1 is running. When HL2 is off, it indicates that the first water pump M1 is stopped. HL2 typically uses a green indicator light. The on and off of HL2 reflects the remote signaling status of water pump M1. The display of HL2 allows operators to intuitively understand the operation of M1. The use of HL2 improves the visual monitoring of the water pump's operating status. In summary, HL2 is an indicator light that monitors the operating status of the first water pump M1. Its on and off status reflects the remote signaling feedback and status of M1 in real time.

[0087] HL3, that is, the second water pump running indicator light

[0088] The input of HL3 is connected to digital output Q0.1 of PLC1 and PLC2. When Q0.1 outputs, HL3 illuminates. HL3 indicates the operating status of the second water pump M2. When HL3 illuminates, it indicates that the second water pump M2 is running. When HL3 is off, it indicates that the second water pump M2 is stopped. HL3 typically uses a green indicator light. The on / off status of HL3 reflects the remote signaling status of water pump M2. The HL3 display allows operators to intuitively understand the operation of M2. The use of HL3 improves visual monitoring of the water pump's operating status. In summary, HL3 is an indicator light that monitors the operating status of the second water pump M2. Its on / off status reflects the remote signaling feedback and status of M2 in real time.

[0089] HL4, that is, PLC1 hardware normal indicator light

[0090] The input of HL4 is connected to digital output Q0.2 of the main controller PLC1. When the PLC1 hardware is in normal condition, Q0.2 outputs, and HL4 illuminates. HL4 indicates whether the PLC1 hardware is in normal condition. When HL4 is on, the PLC1 hardware is operating normally and without faults. When HL4 is off, it indicates a possible fault in the PLC1 hardware. HL4 typically uses a green indicator light. The on / off status of HL4 reflects the status of the PLC1 hardware. HL4 allows operators to intuitively understand the status of the PLC1 hardware. The use of HL4 enhances the system's self-test and monitoring capabilities. In summary, HL4 is an indicator light that monitors the status of the PLC1 hardware, and its on / off status reflects the reliability of the PLC1 hardware in real time.

[0091] HL5, that is, PLC1 software normal indicator light

[0092] The input of HL5 is connected to digital output Q0.3 of the main controller PLC1. When the PLC1 software is operating normally, Q0.3 outputs, and HL5 illuminates. HL5 indicates whether the PLC1 software is operating normally. When HL5 is on, the PLC1 software is operating normally and without faults. When HL5 is off, it indicates a possible fault in the PLC1 software. HL5 typically uses a green indicator light. The on / off status of HL5 reflects the status of the PLC1 software, allowing operators to intuitively monitor the software's status. In summary, HL5 is an indicator light that monitors the PLC1 software's status, and its on / off status provides real-time information about the software's reliability.

[0093] HL6, that is, PLC2 hardware normal indicator light

[0094] The input of HL6 is connected to digital output Q0.2 of the backup controller PLC2. When the PLC2 hardware is in normal condition, Q0.2 outputs, and HL6 illuminates. HL6 indicates whether the PLC2 hardware is in normal condition. When HL6 is on, the PLC2 hardware is operating normally and without faults. When HL6 is off, it indicates a possible fault in the PLC2 hardware. HL6 typically uses a green indicator light. The on / off status of HL6 reflects the status of the PLC2 hardware. HL6 allows operators to intuitively understand the status of the PLC2 hardware. The use of HL6 enhances the system's self-testing and monitoring capabilities. In summary, HL6 is an indicator light that monitors the status of the PLC2 hardware, and its on / off status reflects the reliability of the PLC2 hardware in real time.

[0095] HL7, that is, PLC2 software normal indicator

[0096] The input of the HL7 is connected to digital output Q0.3 of the backup controller, PLC2. When the PLC2 software is operating normally, Q0.3 outputs, and the HL7 illuminates. The HL7 indicates whether the PLC2 software is operating normally. An HL7 illuminated indicates that the PLC2 software is operating normally and without faults. An HL7 off indicates a possible fault in the PLC2 software. The HL7 typically uses a green indicator light. The on / off status of the HL7 reflects the status of the PLC2 software. The HL7 allows operators to intuitively understand the status of the PLC2 software. The use of the HL7 enhances the system's self-testing and monitoring capabilities. In summary, the HL7 is an indicator light that monitors the status of the PLC2 software, and its on / off status reflects the reliability of the PLC2 software in real time.

[0097] QF10, i.e., the first water pump circuit breaker

[0098] QF10 is connected to the power supply circuit of the first water pump M1. Its input is connected to a three-phase AC power source. Its output is connected to the motor input of the first water pump M1. QF10 protects the power supply circuit of the first water pump M1. QF10 can connect and disconnect the water pump circuit.

[0099] QF10 protects water pump M1 from overload and short circuit conditions. It can manually or remotely start and stop water pump M1. The use of QF10 improves the reliability of the water pump's power supply. Its proper disconnection ensures safe water pump maintenance. In summary, QF10 is a dedicated power supply protection circuit breaker for the first water pump, M1, providing isolation and control of the pump and ensuring power supply reliability.

[0100] QF11, i.e., the second water pump circuit breaker

[0101] QF11 is connected to the power supply circuit of the second water pump M2. The input end of QF11 is connected to a three-phase AC power supply. The output end of QF11 is connected to the motor input end of the second water pump M2. QF11 is used to protect the power supply circuit of the second water pump M2. QF11 can complete the connection and disconnection operations of the water pump circuit. QF11 protects the water pump M2 from overload, short circuit and other conditions. QF11 can manually or remotely control the start and stop of the water pump M2. The use of QF11 improves the power supply reliability of the water pump. The normal disconnection of QF11 contributes to the safety of water pump maintenance. In summary, QF11 is a power supply protection circuit breaker dedicated to the second water pump M2, which implements isolation control of the water pump and ensures power supply reliability.

[0102] KH1, i.e., the first water pump thermal relay

[0103] KH1 is connected to the power supply circuit of the first water pump M1. The input of KH1 is connected to the output of the AC contactor KM1. The output of KH1 is connected to the motor input of the first water pump M1. KH1 provides overload protection for the first water pump M1. When M1 is overloaded, KH1 disconnects the circuit to protect the water pump motor. KH1 provides enhanced overload protection for the water pump and prevents the pump from burning out due to overload.

[0104] The normal operation of KH1 is conducive to the safe operation of the water pump. In summary, KH1 is a dedicated overload protection thermal relay for the first water pump M1. It monitors the water pump current in real time and protects the water pump in the event of overload.

[0105] KH2, that is, the second water pump thermal relay

[0106] KH2 is connected to the power supply circuit of the second water pump M2. The input of KH2 is connected to the output of the AC contactor KM2. The output of KH2 is connected to the motor input of the second water pump M2. KH2 is used to protect the second water pump M2 from overload. When M2 is overloaded, KH2 disconnects the circuit to protect the water pump motor. The use of KH2 improves the overload protection of the water pump. KH2 prevents the water pump from burning due to overload. The normal operation of KH2 is conducive to the safe operation of the water pump. In summary, KH2 is an overload protection thermal relay dedicated to the second water pump M2. It monitors the water pump current in real time and protects the water pump in the event of an overload.

[0107] FU1, i.e., PLC1 protection fuse

[0108] FU1 is connected to the input power line of the main controller PLC1. The input of FU1 is connected to the AC power supply. The output of FU1 is connected to the power input of PLC1. FU1 is used to provide short-circuit protection for PLC1's power line. When the PLC1 power line short-circuits, FU1 fuses open, cutting off power. The use of FU1 improves short-circuit protection for PLC1. FU1 prevents the risk of short-circuit faults spreading to other parts of PLC1. The normal operation of FU1 ensures the reliability of PLC1's power supply. In summary, FU1 is a dedicated power supply short-circuit protection fuse for PLC1, monitoring current in real time and protecting PLC1 in the event of a short circuit.

[0109] FU2, i.e., PLC2 protection fuse

[0110] FU2 is connected to the input power line of the backup controller PLC2. The input of FU2 is connected to the AC power supply. The output of FU2 is connected to the power input of PLC2. FU2 is used to provide short-circuit protection for PLC2's power line. When the PLC2 power line short-circuits, FU2 fuses open, cutting off power. The use of FU2 improves short-circuit protection for PLC2. FU2 prevents the short-circuit fault from spreading to other parts of PLC2. The normal operation of FU2 ensures the reliability of PLC2's power supply. In summary, FU2 is a dedicated power supply short-circuit protection fuse for PLC2, monitoring the current in real time and protecting PLC2 in the event of a short circuit.

[0111] FU3, i.e., control circuit protection fuse

[0112] FU3 is connected to the input power supply line of the secondary control circuit. The input of FU3 is connected to the AC power supply. The output of FU3 is connected to the power input of the control circuit. FU3 is used to provide short-circuit protection for the power supply line of the secondary control circuit. When a short circuit occurs in the control circuit, FU3 fuses open, cutting off the power supply. The use of FU3 improves short-circuit protection for the control circuit. FU3 prevents the spread of short-circuit faults to other parts of the control circuit. The normal operation of FU3 ensures the reliability of the power supply to the control circuit. In summary, FU3 is a dedicated power supply short-circuit protection fuse for the secondary control circuit. It monitors the current in real time and protects the control circuit in the event of a short circuit.

[0113] SA1, that is, the first water pump manual switch

[0114] The input of SA1 is connected to an operating button. The output of SA1 is connected to the coil of the intermediate relay KA1. When SA1 is operated, the KA1 coil is switched on and off, changing the state of its contacts. SA1 is used to manually control the start and stop of the first water pump M1. When SA1 is pressed, KA1 is activated and M1 starts; when SA1 is released, KA1 is reset and M1 stops. SA1 allows direct on-site control of the first water pump. Manual control of SA1 is independent of the PLC control logic. The use of SA1 improves the operability of the water pump. The SA1 button form is simple and reliable. The use of SA1 enhances the flexibility and maintainability of the system. In summary, SA1 is the local manual start and stop button for the first water pump M1, enabling direct manual control of the water pump.

[0115] SA2, that is, the second water pump manual switch

[0116] The input of SA2 is connected to an operating button. The output of SA2 is connected to the coil of intermediate relay KA2. When SA2 is operated, the KA2 coil switches on and off, changing the state of its contacts. SA2 is used to manually control the start and stop of the second water pump M2. When SA2 is pressed, KA2 activates and M2 starts; when SA2 is released, KA2 resets and M2 stops. SA2 allows direct on-site control of the second water pump. Manual control of SA2 is independent of the PLC control logic. The use of SA2 improves the operability of the water pump. The SA2 button form is simple and reliable. The use of SA2 enhances the flexibility and maintainability of the system. In summary, SA2 is the local manual start and stop button for the second water pump M2, enabling direct manual control of the water pump.

[0117] Working principle:

[0118] The system utilizes dual redundant PLCs (PLC1 and PLC2). Normally, PLC1 serves as the primary controller for operating the pump, while PLC2 serves as the backup redundant controller. PLC1 and PLC2 monitor each other for hardware and software faults, as well as timed rotation signals, via intermediate relays KA3, KA4, KA7, and KA8. If a PLC1 fault is detected, PLC2 immediately takes over pump control, achieving seamless master / slave switching. Furthermore, PLC2 faults are monitored by PLC1 to prevent them from spreading. Manual / automatic switches SA1 and SA2 are also located at the pump for on-site operational control.

[0119] Technical effects:

[0120] The adoption of a dual-redundant PLC configuration significantly improves system reliability. Mutual inspection and interconnection between the PLCs enable automatic fault switching, ensuring uninterrupted production. An on-site operation switch ensures the controllability of the water pump. Intermediate relays isolate signal transmission, improving interference resistance. Protective devices such as thermal relays and fuses enhance the system's self-protection capabilities. Indicator lights provide a direct reflection of the system's operating status. Overall, the system offers reliable control, a high degree of automation, and flexible operation, significantly improving the availability of the water pump. In summary, the system fully utilizes the redundant PLC configuration and intermediate relays for interlocking monitoring, achieving high reliability, high availability, and good human-machine interaction for water pump control.

[0121] In order to better understand the technical solution of the present application, a specific example is provided below for illustration. The details listed in the example are mainly for ease of understanding and are not intended to limit the scope of protection of the present application.

[0122] like Figure 1 、 Figure 2 、 Figure 3 As shown in the figure, this example proposes a temperature standby control system based on redundant PLC, the structure of which includes: N water pumps, 2 logic controllers, low-voltage electrical components, etc.

[0123] Attachment Figure 1 Reclaimed water pump group 1 (M1, M2) is attached Figure 3 The switch 6 (SA1, SA2) is connected to the Figure 2 The programmable controller 5 (PLC1, PLC2) controls the operation; after the system is powered on, the programmable controller 5 (PLC1, PLC2) are both powered, at this time PLC1 is the main one and PLC2 is the redundant warm standby state; PLC1 and PLC2 are two identical programmable controllers. Figure 3 The intermediate transfer switches 6 (SA1, SA2) are connected to the coils of the intermediate relays 7 (KA1, KA2) respectively. The normally open contacts of the intermediate relays (KA1, KA2) are connected to the coils of the intermediate relays 7 (KA1, KA2) respectively. Figure 2 The input points (I0.0, I0.1) of the programmable controller 5 (PLC1, PLC2) are connected; the relay output points (Q0.0, Q0.1) of the programmable controller 5 (PLC1, PLC2) are connected to the attached Figure 3 The coils of the AC contactors 9 (KM1, KM2) are connected to the indicator lights 8 (HL2, HL3); the output points (Q0.2, Q0.3) of the programmable controller 5 (PLC1) are connected to the attached Figure 3 The coils of the intermediate relay 7 (KA3, KA4) are connected to the indicator lights 8 (HL4, HL5); the output points (Q0.2, Q0.3) of the programmable controller 5 (PLC2) are connected to the attached Figure 3The coil of the intermediate relay 7 (KA5, KA6) is connected to the indicator light 8 (HL6, HL7); the normally closed / open contacts of the intermediate relay 7 (KA3, KA4) are connected to the input points (I0.2, I0.3) of the programmable controller 5 (PLC2); the normally closed / open contacts of the intermediate relay 7 (KA5, KA6) are connected to the input points (I0.2, I0.3) of the programmable controller 5 (PLC1). The output point (Q0.4) of the programmable controller 5 (PLC1, PLC2) is connected to the attached Figure 3 The coils of intermediate relay 7 (KA7, KA8) are connected; the normally open contact of intermediate relay 7 (KA7) is connected to the input point (I0.4) of programmable controller 5 (PLC2); the normally open contact of intermediate relay 7 (KA8) is connected to the input point (I0.4) of programmable controller 5 (PLC1).

[0124] The specific working principle of this example in actual operation is as follows:

[0125] See also Figure 4 After the system is started, the programmable controllers PLC1 and PLC2 are powered on at the same time. The programmable controller PLC1 is the main one, and PLC2 is in redundant warm standby state, ready to be put into use at any time.

[0126] When the main PLC1 is operating normally, its Q0.2 outputs a relay signal and the intermediate relay KA3 coil is energized, which indicates that PLC1 is operating normally without any hardware fault.

[0127] Connect the normally closed contact of the intermediate relay KA3 to the I0.2 input point of the redundant warm standby PLC2 to determine whether there is a hardware fault in PLC1 in PLC2.

[0128] If there is a hardware fault in PLC1, PLC1's Q0.2 will not output relays, the coil of intermediate relay KA3 will not be energized, and KA3's normally closed contact will be closed. At this time, PLC2's I0.2 port will detect an input signal, indicating that PLC1 has a hardware fault. PLC2 will then be put into system operation, and PLC1 will be disconnected.

[0129] If there is a software fault in PLC1, Q0.3 of PLC1 outputs a relay signal, energizing the coil of intermediate relay KA4, closing the normally open contact of KA4. At this point, I0.3 of PLC2 detects an input signal, indicating that there is a software fault in PLC1. PLC2 is then put into system operation, and PLC1 is disconnected.

[0130] PLC1 begins timing while running. When the countdown reaches the set rotation time, PLC1's Q0.4 receives a relay output signal, energizing the coil of intermediate relay KA7, closing KA7's normally open contact. At this point, PLC2's I0.4 detects an input signal, signaling a rotation. PLC2 is then put into system operation, and two seconds later, PLC1 is disconnected, completing the seamless rotation between the two PLCs.

[0131] When PLC2 is put into operation, its fault detection and rotation principles are the same as those of the main PLC1.

[0132] The main advantages of this example include:

[0133] Reduce system failure time: When the main PLC1 in the system fails, the system can complete the switching of the redundant warm standby PLC2 within milliseconds, ensuring the normal operation of the entire system when the main PLC1 fails.

[0134] High degree of automation: The system realizes fully automatic control, and the detection and switching of PLC faults are all carried out in a fully intelligent manner;

[0135] Enhanced system stability and effectiveness: Since the system can automatically switch to the redundant warm standby PLC2 when the main PLC1 fails, the system failure time is reduced, the normal working time of the system is increased, and the normal water supply for production and life is guaranteed, which improves the stability and effectiveness of the system;

[0136] When the system's PLC is used daily, it can be switched in a scheduled rotation to avoid aging and damage of the PLC due to long-term use, which would affect the normal operation of the system.

[0137] This example is described in further detail below.

[0138] More specifically, in this example, a redundant PLC is added to a traditional PLC control system. The system structure includes: N water pumps (N≤6), two logic controllers (PLC1, PLC2), low-voltage electrical components, etc.

[0139] The number N of the water pumps is an integer of 2≤N≤6.

[0140] like Figure 1 、 Figure 2 and Figure 3As shown, the control system includes: 2 water pumps (M1, M2), 2 logic controllers (PLC1, PLC2), 2 circuit breakers (QF10, QF11), 2 AC contactors (KM1, KM2), 2 thermal relays (KH1, KH2), 8 intermediate relays (KA1, KA2, KA3, KA4, KA5, KA6, KA7, KA8), 3 fuses (FU1, FU2, FU3), 7 indicator lights (HL1, HL2, HL3, HL4, HL5, HL6, HL7), and 2 transfer switches (SA1, SA2).

[0141] Attachment Figure 1 In the middle, (L1, L2, L3, N) are AC380V / 50Hz three-phase four-wire power lines, which supply power to the system. The circuit breakers (QF10, QF11) are respectively connected to the main contacts of two AC contactors (KM1, KM2). When the coils of the AC contactors are energized, their main contacts are attracted, connecting the main circuit, and the water pump is powered and running; the circuit breaker is mainly used to complete the connection and disconnection of the circuit and protect the water pump motor from short circuit, overload, undervoltage, etc.

[0142] The main contact output lines of the AC contactors (KM1, KM2) are connected to thermal relays (KH1, KH2) respectively. The main function of the thermal relays is to provide overload protection for the water pump motor. The output lines of the thermal relays are directly connected to the water pump motor.

[0143] Fuses (FU1, FU2, FU3) are connected to the power supply lines of the main PLC1, redundant PLC2 and secondary control circuit respectively, and are used to protect PLC1, PLC2 and secondary control circuit from short circuits.

[0144] Attachment Figure 2 There are two identical programmable controllers (PLC1, PLC2), of which PLC1 is the main one and PLC2 is the redundant warm standby one. When the main PLC1 is operating normally, its Q0.2 has a relay output signal. Figure 3 The coil of the intermediate relay KA3 is energized, indicating that PLC1 is operating normally without hardware failure. Figure 3 The middle indicator light HL4 is on.

[0145] Connect the normally closed contact of the intermediate relay KA3 to the I0.2 port of PLC2 to determine whether there is a hardware fault in PLC1 in PLC2.

[0146] If PLC1 has a hardware fault, PLC1's Q0.2 will have no relay output, intermediate relay KA3 will not be energized, and KA3's normally closed contact will be closed. At this time, PLC2's I0.2 port will detect an input signal, indicating that PLC1 has a hardware fault. PLC2 will immediately start operating, and PLC1 will be disconnected. If PLC1 has a software fault, PLC1's Q0.3 will have a relay output signal, intermediate relay KA4 will be energized, KA4's normally open contact will be closed, and indicator light HL5 will illuminate. At this time, PLC2's I0.3 port will detect an input signal, indicating that PLC1 has a software fault. PLC2 will then start operating, and the active PLC1 will be disconnected.

[0147] Attachment Figure 2 The main PLC1 starts timing when it is running. When the timing reaches the set rotation time, PLC1's Q0.4 has a relay output signal, the intermediate relay KA7 coil is energized, and KA7's normally open contact is closed. At this time, PLC2's I0.4 port detects an input signal, which is determined to be a rotation. At this time, the redundant PLC2 is put into system operation, and the main PLC1 is disconnected 2 seconds later, completing the seamless connection of the two PLC rotations.

[0148] When the redundant temperature standby controller PLC2 is put into operation, its fault detection and rotation principles are the same as those of the active PLC1.

[0149] Attachment Figure 3 When the intermediate transfer switch SA1 is closed, the coil of the intermediate relay KA1 is energized and its normally open contacts are connected to the attached Figure 2 In the example, the input points I0.0 of PLC1 and PLC2 are connected. If the main PLC1 is running and PLC2 is in redundant warm standby state, after the internal logic operation of PLC1, its Q0.0 outputs a relay signal. Figure 3 The AC contactor's coil KM1 is energized, KM1's main contacts close, and pump M1 starts operating. Indicator light HL2 illuminates. If the primary PLC2 fails, redundant PLC2 operates, following the same principles as the primary PLC1.

[0150] Attachment Figure 3 When the intermediate transfer switch SA2 is closed, the principle is the same as SA1 closing, controlling the operation of the water pump M2.

[0151] In this embodiment, it can be seen that the two PLCs equipped in the system have completely consistent control logic for the entire system. After the main PLC1 fails, the redundant warm standby PLC2 can respond and put into operation control in the shortest time. At the same time, the subsequent fault maintenance process is carried out without sacrificing process control, thereby improving the stability and effectiveness of the entire system.

[0152] Effect comparison

[0153] Testers conducted a one-year survey of the system in Example 1 and conducted follow-up investigations on 10 systems on site, obtaining the following results:

[0154] The average total number of failures of the dual PLCs in this system is 0.3 times, the average repair time for each failure is 5 days, the failure rate is 0.41%, the downtime days are 0 days, the work efficiency is 100%, and it is easy to use.

[0155] Comparative Example 1

[0156] Comparative Example 1 adopts system a (the specifications of the water pump and programmable controller (PLC) in system a are the same as those in the embodiment), wherein system a is a single PLC + 2 water pumps.

[0157] Testers conducted a survey on a system over a year and conducted follow-up surveys on 10 systems on site, obtaining the following results:

[0158] The average number of failures per PLC in system a is 0.9, and the average repair time per failure is 5 days. The failure rate is 1.23%, the average downtime is 4.5 days, and the work efficiency is 98.77%.

[0159] Comparative testing reveals that, given the same programmable controller (PLC) model and the same number of pumps, a system using only one PLC experienced water supply failures on an average of four days per year. By adding a redundant PLC for thermal backup, even if one PLC experienced a single failure, the system remained operational during the failure period, enabling continuous operation 365 days a year with the redundant PLC, achieving 100% operational efficiency. This also reduced the failure rate in Comparative Example 1 from 1.23% to 0.41%.

[0160] In other words, after adopting the dual-redundant PLC configuration of the above embodiment, the failure rate dropped by 66.7%, thereby greatly reducing the failure rate of the PLC and significantly improving the working efficiency of the system.

[0161] It should be noted that in this patent application, relational terms such as first and second, etc., are used solely to distinguish one entity or operation from another, and do not necessarily require or imply any actual relationship or order between these entities or operations. Furthermore, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, an element specified by the phrase "comprising a" does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element. In this patent application, reference to performing an action in accordance with an element means performing the action in accordance with at least that element, including two situations: performing the action in accordance with that element alone, and performing the action in accordance with that element and other elements. Expressions such as "plurality," "multiple times," and "many" include "two," "twice," "two kinds," and "more than two," "more than two times," and "more than two kinds."

[0162] All documents mentioned in this application are considered to be included in their entirety in the disclosure of this application so that they can be used as a basis for modification when necessary. In addition, it should be understood that after reading the above disclosure of this application, those skilled in the art may make various changes or modifications to this application, and these equivalent forms also fall within the scope of protection claimed in this application.

Claims

1. A temperature standby control system, characterized in that: Include: A water pump unit, comprising a plurality of water pumps and an AC contactor corresponding to each water pump; A main control unit, including a main controller, a hardware fault detection relay, a software fault detection relay and a rotation control relay of the main controller; The standby control unit includes a standby controller and a rotation control relay of the standby controller; wherein, The output end of the main controller is connected to the AC contactor of the water pump to control the water pump, and the main controller transmits the fault signal and the rotation signal to the standby controller through the hardware fault detection relay, the software fault detection relay, and the rotation control relay. When the standby controller detects a fault or a rotation signal of the main controller, it takes over the control of the water pump to achieve seamless switching between the two.

2. The system according to claim 1, characterized in that The standby control unit further comprises a hardware fault detection relay and a software fault detection relay of the standby controller respectively connected to the main controller, wherein: The hardware fault detection relay of the backup controller is used to transmit the hardware fault signal of the backup controller to the main controller, and the software fault detection relay is used to transmit the software fault signal of the backup controller to the main controller. When the main controller detects a fault or rotation signal of the backup controller, it takes over the control of the water pump to achieve seamless switching between the two.

3. The system according to claim 1, characterized in that The water pump unit also includes a manual-automatic water pump conversion switch corresponding to each water pump, wherein the output end of the manual-automatic water pump conversion switch is connected to the corresponding water pump for controlling the start and stop of the water pump, and the input end of the manual-automatic water pump conversion switch is connected to the main controller and the backup controller for feeding back the manual or automatic working mode of the water pump to the main controller and the backup controller.

4. The system according to claim 1, characterized in that The water pump unit also includes a water pump thermal relay corresponding to each water pump, wherein the input end of the water pump thermal relay is connected to the output end of the corresponding water pump AC contactor, and the output end of the water pump thermal relay is connected to the input end of the corresponding water pump. The water pump thermal relay is used to monitor and protect the overload condition of the water pump in real time, and disconnect the circuit when the water pump overload is detected.

5. The system according to claim 1, characterized in that The water pump unit also includes a circuit breaker corresponding to each water pump, wherein the input end of the circuit breaker is connected to an AC power supply, and the output end is connected to the corresponding water pump. The circuit breaker is used to isolate and protect the power supply line of the water pump and disconnect the circuit when a water pump fails.

6. The system according to claim 1, characterized in that The main control unit also includes a protection fuse for the main controller, the input end of the main controller protection fuse is connected to the AC power supply, and the output end is connected to the power input end of the main controller. The main controller protection fuse is used to protect the power line of the main controller from overload and short circuit.

7. The system according to claim 1, characterized in that The backup control unit also includes a protection fuse for a backup controller, the input end of the backup controller protection fuse is connected to an AC power supply, and the output end is connected to the power input end of the backup controller. The backup controller protection fuse is used to protect the power line of the backup controller from overload and short circuit.

8. The system of claim 1, wherein: It also includes a control circuit protection fuse, the input end of the control circuit protection fuse is connected to the AC power supply, and the output end is connected to the power input end of the control circuit. The control circuit protection fuse is used to protect the power line of the control circuit from overload and short circuit.

9. The system of claim 1, wherein: The main controller and the standby controller are two completely identical programmable logic controllers, and the models and performance parameters of the two are the same.