Distributed heterogeneous redundant programmable logic controller and operation method thereof
By using heterogeneous redundant design of ARM and FPGA processors in industrial control systems and dual network redundant configurations of ECN and CAN buses, the unreliability and high complexity problems caused by a single failure of existing systems are solved, and the improvement of high reliability and real-time response capabilities are achieved.
Patent Information
- Application Number
- CN202510166747.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-27
AI Technical Summary
The existing industrial control system cannot work properly due to the failure of a single processor or communication method, and the system is complex and difficult to manage, which increases costs and delay overhead.
The programmable logic controller with distributed heterogeneous redundancy is adopted, and ARM and FPGA processors are used as heterogeneous redundant processors. The ARM subsystem and FPGA subsystem are mutually reserved control units. The dual network redundant configuration of ECN and CAN buses is adopted to achieve the system's high reliability and real-time response capabilities.
Through heterogeneous redundant design and dual network redundant configuration, single point of failure and common cause failure risks are avoided, ensuring that the system can still operate normally when the processor or communication network fails, and improving the reliability and real-time of the system.
Smart Images

Figure CN120044847A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of industrial control automation, and particularly relates to a programmable logic controller with distributed heterogeneous redundancy and an operation method thereof. Background Art
[0002] The structures of modern industrial equipment and systems are becoming increasingly complex, and the application of electrical and electronic devices is increasing. The interconnection and interoperability between various electronic devices are also becoming increasingly complex and diverse. It is particularly important for various systems to coordinate and operate safely and reliably. If a single processor or a single communication method is used, once the processor fails or the communication is abnormal, the entire system will not be able to work.
[0003] The patent with the publication number CN118192192A realizes a non-symmetric heterogeneous redundant control system with a communication triple redundancy configuration and a two-out-of-three voting mechanism. First, due to the involvement of multiple signals and complex logical judgments in this solution, the development, maintenance, and debugging of the system are relatively complex. Second, this system allows one signal source to fail, but if two signal sources fail simultaneously, the system will not be able to make a correct decision.
[0004] The patent with the publication number CN110891007A realizes a system with a dual redundant high-speed bus. This system includes two CAN buses and two Ethernet buses, with a total of four bus redundancies. First, due to the involvement of multiple bus communication judgments in this solution, the overall complexity and management difficulty of the system are increased. Second, multiple redundant buses require additional hardware resources, including more lines, interfaces, and controllers, etc. These additional hardwares will increase the physical space requirements and energy consumption of the system, thus increasing the overall cost. Summary of the Invention
[0005] To solve the above problems, the object of the present invention is to provide a programmable logic controller with distributed heterogeneous redundancy and an operation method thereof. By designing a high-speed real-time Ethernet (ECN bus) and a CAN bus, heterogeneous redundancy of the communication network is realized. Using ARM and FPGA as heterogeneous redundant processors, the ARM subsystem and the FPGA subsystem are mutually primary and backup control units, and a dual-processor dual-network heterogeneous redundancy technology with different processors and different communication protocols is adopted to enhance the functional safety characteristics. This solution can solve the overall complexity of the prior art and the problems of excessive delay overhead caused by common cause failure problems and system communication interaction efficiency.
[0006] The technical solution provided by the present invention is: A programmable logic controller with distributed heterogeneous redundancy, comprising: ARM processor and FPGA processor, where the ARM processor and the FPGA processor are heterogeneous redundant processors with each other. The ARM subsystem is the main control unit and the FPGA subsystem is the standby control unit. The ARM processor and the FPGA processor monitor each other's operating status. When the communication data of the main control unit is abnormal, the standby control unit obtains the main control right of the on-site side device, thus realizing the high reliability of the system; The external communication of the ARM subsystem is based on ECN communication, and the external communication of the FPGA subsystem is based on CAN communication. The ARM subsystem and the FPGA subsystem adopt a dual-processor and dual-network heterogeneous redundant configuration with different processors and different communication protocols to enhance the functional safety characteristics.
[0007] Preferably, the ARM processor and the FPGA processor monitor each other's operating status and periodically exchange data to determine whether the other is working properly.
[0008] Preferably, after the system is powered on, the ARM subsystem and the FPGA subsystem are started simultaneously for preliminary self-check. After the self-check is correct, by default, the ARM processor is the main control unit and the FPGA processor is the standby control unit.
[0009] Preferably, during normal operation, the ARM processor continuously prepares and generates communication data. The ARM processor synchronizes the current communication data to the FPGA processor in real time through an incremental synchronization method. During the communication failure of only the ARM processor or the FPGA processor, the ARM processor synchronizes the module data to the FPGA processor in real time, while the communication data is not synchronized.
[0010] Preferably, after the communication data synchronization is completed, the ARM processor loads the data and sends it through the ECN network, and the FPGA processor splits the data and sends it in packets through the CAN network.
[0011] Based on the same concept, the present invention also provides a method for operating a distributed heterogeneous redundant programmable logic controller, including the following steps: After the system is powered on, the ARM subsystem and the FPGA subsystem that are hot standby with each other are started simultaneously for preliminary self-check. After the self-check is correct, by default, the ARM processor is the main control unit and the FPGA processor is the standby control unit; The ARM processor and the FPGA processor monitor each other's status information in real time, and the ARM processor periodically interacts with the FPGA processor through heartbeat information and system status information; The external communication of the ARM subsystem is based on ECN communication, and the external communication of the FPGA subsystem is based on CAN communication.
[0012] Preferably, during normal operation, the ARM processor continuously prepares and generates communication data. The ARM processor synchronizes the current communication data to the FPGA processor in real time through incremental synchronization. During the communication failure of only the ARM processor or the FPGA processor, the ARM processor synchronizes module data to the FPGA processor in real time, while the communication data is not synchronized.
[0013] Preferably, after the communication data synchronization is completed, the ARM processor loads the data and sends it through the ECN network, and the FPGA processor splits the data and sends it in packets through the CAN network.
[0014] Due to the adoption of the above technical solutions, the present invention has the following advantages and positive effects compared with the prior art: In the present invention, the ARM processor and the FPGA processor are heterogeneous redundant processors to each other. The ARM subsystem is the main control unit, and the FPGA subsystem is the backup control unit. When the main control unit (ARM) has abnormal communication data or fails, the backup control unit (FPGA) can immediately take over the main control right to ensure the continuous operation of the system and avoid the system failure caused by single-point failure. The ARM subsystem is based on ECN communication, and the FPGA subsystem is based on CAN communication. The two different communication protocols are backed up to each other. When one communication network fails, the other communication network can continue to work to ensure the continuity and integrity of data transmission. The ARM processor and the FPGA processor run independently and in parallel, and monitor the operating status of each other in real time. Through the periodic interaction of heartbeat information and status information, the system can quickly detect anomalies and respond, ensuring real-time requirements. The main processor (ARM) synchronizes the communication data to the backup processor (FPGA) in real time through incremental synchronization to ensure data consistency. The combination of the high bandwidth of the ECN network and the low latency characteristics of the CAN network further improves the real-time response ability of the system. The adoption of heterogeneous redundant design (ARM and FPGA) and dual-network redundant configuration (ECN and CAN) avoids the risk of common cause failure caused by a single design defect or quality problem. Even if a certain processor or communication network fails, the system can still operate normally. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The following further elaborates on the specific embodiments of the present invention in conjunction with the drawings, where: Figure 1 is the system architecture diagram of the distributed heterogeneous redundant programmable logic controller; Figure 2 is the data transmission mechanism diagram of the present invention; Figure 3 is the working flow diagram of the heterogeneous redundant architecture. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. The advantages and features of the present invention will become clearer according to the following description and claims. It should be noted that the accompanying drawings are all in a very simplified form and use non-precise ratios, only for the purpose of facilitating and clearly assisting in explaining the embodiments of the present invention.
[0017] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship and movement conditions between components in a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.
[0018] First Embodiment As Figure 1 shown in a system architecture diagram of a distributed heterogeneous redundant programmable logic controller, including: an ARM processor and an FPGA processor, the ARM processor and the FPGA processor are heterogeneous redundant processors to each other, the ARM subsystem is the main control unit, the FPGA subsystem is the backup control unit, the ARM processor and the FPGA processor monitor each other's operating states, and when the communication data of the main control unit is abnormal, the backup control unit obtains the master control right of the on-site side equipment, thus realizing the high reliability of the system; the ARM subsystem communicates externally based on ECN communication, the FPGA subsystem communicates externally based on CAN communication, and the ARM subsystem and the FPGA subsystem adopt a dual-processor and dual-network heterogeneous redundant configuration with different processors and different communication protocols to enhance the functional safety characteristics.
[0019] The ARM processor and the FPGA processor are heterogeneous redundant processors. The ARM subsystem is the main control unit, and the FPGA subsystem is the backup control unit. When the main control unit (ARM) has communication data anomalies or malfunctions, the backup control unit (FPGA) can immediately take over the main control power to ensure the continuous operation of the system and avoid system failure caused by single-point failures. The ARM subsystem is based on ECN communication, and the FPGA subsystem is based on CAN communication. The two different communication protocols are backed up each other. When one communication network fails, the other communication network can continue to work to ensure the continuity and integrity of data transmission. The ARM processor and the FPGA processor operate independently and in parallel, and monitor the operating status of each other in real time. Through the periodic interaction of heartbeat information and status information, the system can quickly detect anomalies and respond, ensuring real-time requirements. The main processor (ARM) synchronizes communication data to the backup processor (FPGA) in real time through incremental synchronization to ensure data consistency. The combination of the high bandwidth of the ECN network and the low latency characteristics of the CAN network further improves the real-time response ability of the system. The heterogeneous redundant design (ARM and FPGA) and the dual-network redundant configuration (ECN and CAN) are adopted to avoid the risk of common-cause failures caused by single design defects or quality problems. Even if a certain processor or communication network fails, the system can still operate normally.
[0020] Common-cause failure refers to the risk of system factor failure of units implemented using related technologies due to the same design defect or quality problem. For example, if serious logical defects are found in the CAN bus or other unknown design defects exist, once a failure occurs, all interfaces using this technology may fail. This may lead to system interaction failure and system failure caused by a common design. The ARM communicates externally using ECN communication, and the FPGA communicates externally using CAN communication. The dual-processor and dual-network heterogeneous redundant technology with different processors and different communication protocols is adopted to enhance functional safety characteristics. This solution can solve the overall complexity of the existing technology and the problems of excessive delay overhead caused by common-cause failure problems and system communication interaction efficiency.
[0021] Preferably, the ARM processor and the FPGA processor monitor each other's operating status and interact with each other periodically to determine whether the other is working properly.
[0022] Through the periodic interaction of heartbeat information and status information, the system can quickly detect anomalies and respond, ensuring real-time requirements.
[0023] Such as Figure 2shows a diagram of the data transmission mechanism. The data transmission between intelligent controllers needs to be sent on both the CAN communication channel and the ECN communication channel to achieve information redundancy and prevent the phenomenon of inability to transmit data in real time and accurately due to the abnormality of a processor or communication channel. To achieve this purpose, an efficient transmission mechanism for synchronizing data, organizing data, loading data, and generating message transmission as shown in Figure 2 is adopted.
[0024] As Figure 3 shows the working flow chart of the heterogeneous redundancy architecture. The specific operation steps of the heterogeneous redundant programmable logic controller are as follows: Step 1: After the system is powered on, the main control processor (ARM) and the backup processor (FPGA) start simultaneously for preliminary self-check. After the self-check is correct, the ARM processor is defaulted as the main control system, and the FPGA processor is in the hot backup system mode. The main processor is responsible for the main control and data processing of the system, while the slave processor is responsible for the communication of this bus.
[0025] Step 2: The main and backup processors monitor each other's status information in real time. The main processor periodically interacts with the backup processor through heartbeat information, system status information, etc. If the main processor appears in an abnormal working state, the hot backup processor obtains the main control right of the system, queries in real time whether the status information of the faulty system has been restored, and reports the fault situation.
[0026] Step 3: During normal operation, the main processor will continuously prepare and generate communication data. To ensure that the backup processor can synchronously send communication data, the main processor will synchronize the current communication data to the backup processor in real time through the incremental synchronization method. During the communication fault process of a certain controller, the main processor will synchronize the module data to the backup processor in real time, while the communication data is not synchronized.
[0027] Step 4: After the communication data synchronization is completed, the ARM processor loads the data and sends it through the ECN network. Since the transmission bandwidth of the ECN communication network is greater than that of the CAN communication network, the data length of the ECN network message is greater than that of the CAN communication message. Therefore, the FPGA processor needs to split the data and send it in packets through the CAN network.
[0028] Step 5: The FPGA processor on the receiving-end PLC reorganizes the data according to the data packets received through the CAN network to ensure data integrity. The main and slave processors first verify the message. After the verification passes, corresponding processing or feedback is performed according to the protocol.
[0029] Compared with the prior art, the present invention has significant advantages. Through a dual redundant architecture and an efficient data transmission mechanism, this intelligent control system can maintain the stability and reliability of the system under various fault conditions. It has the following advantages: High reliability: Using two sets of systems avoids system failures caused by common cause failures. The system can automatically switch when there are hardware failures, communication interruptions, or processor crashes, ensuring that critical tasks are not interrupted. High real-time performance: Through two independent communication channels and multiple redundant computing units, the system can quickly respond to external environmental changes and internal faults, meeting real-time requirements. Strong fault tolerance: Even if one or more modules fail, the system can still ensure the continuous transmission of data and the execution of control tasks, avoiding the risks brought by single-point failures.
[0030] Those skilled in the art can clearly understand that for the sake of convenience and brevity of description, the specific identification content of the system and equipment described above can refer to the corresponding processes in the foregoing method embodiments.
[0031] The embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings, but the present invention is not limited to the above embodiments. Even if various changes are made to the present invention, provided that these changes fall within the scope of the claims of the present invention and their equivalent technologies, they still fall within the protection scope of the present invention.
Claims
1. A distributed heterogeneous redundant programmable logic controller, characterized in that: include: ARM processor and FPGA processor, the ARM processor and the FPGA processor are mutually heterogeneous redundant processors, the ARM subsystem is the main control unit, and the FPGA subsystem is the standby control unit, the ARM processor and the FPGA processor monitor each other's operating status, when the communication data of the main control unit is abnormal, the standby control unit obtains the master control right of the field side device, thereby achieving high reliability of the system; The ARM subsystem external communication is based on ECN communication, and the FPGA subsystem external communication is based on CAN communication. The ARM subsystem and the FPGA subsystem adopt dual processors with different processors and different communication protocols, and dual network heterogeneous redundant configuration to improve functional safety characteristics.
2. The distributed heterogeneous redundant programmable logic controller according to claim 1, characterized in that: The ARM processor and the FPGA processor monitor each other's operating status and periodically interact with each other to determine whether the other party is working normally.
3. The distributed heterogeneous redundant programmable logic controller according to claim 1, characterized in that: After the system is powered on, the ARM subsystem and the FPGA subsystem are started simultaneously and perform a preliminary self-check. After the self-check is correct, the ARM processor is used as the main control unit and the FPGA processor is used as the backup control unit by default.
4. The distributed heterogeneous redundant programmable logic controller according to claim 1, characterized in that: During normal operation, the ARM processor continuously prepares and generates communication data. The ARM processor synchronizes the current communication data to the FPGA processor in real time through incremental synchronization. During a communication failure of the ARM processor or the FPGA processor, the ARM processor synchronizes module data to the FPGA processor in real time, while the communication data is not synchronized.
5. The distributed heterogeneous redundant programmable logic controller according to claim 4, characterized in that: After the communication data synchronization is completed, the ARM processor loads the data and sends it through the ECN network, and the FPGA processor splits the data and sends it in packets through the CAN network.
6. A distributed heterogeneous redundant programmable logic controller operation method, characterized in that: The steps include: After the system is powered on, the ARM subsystem and FPGA subsystem, which are hot standby for each other, start up at the same time to perform a preliminary self-check. After the self-check is successful, the ARM processor is the main control unit and the FPGA processor is the backup control unit by default. The ARM processor and FPGA processor monitor each other's status information in real time. The ARM processor periodically interacts with the FPGA processor through heartbeat information and system status information; The ARM subsystem external communication is based on ECN communication, and the FPGA subsystem external communication is based on CAN communication.
7. The distributed heterogeneous redundant programmable logic controller operation method according to claim 6, characterized in that: During normal operation, the ARM processor continuously prepares and generates communication data. The ARM processor synchronizes the current communication data to the FPGA processor in real time through incremental synchronization. During a communication failure of the ARM processor or the FPGA processor, the ARM processor synchronizes module data to the FPGA processor in real time, while the communication data is not synchronized.
8. The distributed heterogeneous redundant programmable logic controller operation method according to claim 7, characterized in that: After the communication data synchronization is completed, the ARM processor loads the data and sends it through the ECN network, and the FPGA processor splits the data and sends it in packets through the CAN network.
Citation Information
Patent Citations
Laser equipment communication system of dual-redundancy high-speed bus
CN110891007A
Asymmetric heterogeneous redundancy control system
CN118192192A