Double-PLC redundant backup method and system
Through the dual PLC redundant backup method, real-time monitoring and positioning of faults, and selecting appropriate conduction PLCs, ensuring that the lock control system can recover quickly in the event of a fault, solving the problem of lock operation interruption caused by PLC failure, and achieving continuous and efficient operation of the lock.
Patent Information
- Application Number
- CN202510732378.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-03
AI Technical Summary
The existing PLC redundant backup solution cannot effectively solve the lock operation interruption caused by IO module and network failures, and the CPU downtime caused by the PLC's own system or program reasons is long, which cannot meet the requirements of continuous and efficient operation of the lock.
The dual PLC redundant backup method is adopted. By determining the backup level, selecting the appropriate conduction PLC, connecting in parallel and physical isolation, monitoring the working status in real time, positioning the fault location and type, determining the working time of the backup PLC according to the fault status type, and executing the corresponding function to ensure the continuous operation of the system.
It improves the anti-interference capability of the system, shortens the troubleshooting time, reduces downtime, ensures the continuity and reliability of the lock control system, and realizes rapid failure recovery and system switching.
Smart Images

Figure CN120276364A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of lock control, and particularly to a dual PLC redundant backup method and system. Background Art
[0002] A lock is an important hydraulic structure that helps navigating ships overcome water level differences, canalize waterways, and create a "water highway". With the country's strong promotion of water transportation infrastructure construction, locks and other infrastructure are facing increasing navigation pressure. Ensuring the safe, continuous, and efficient operation of locks has always been the most concerned issue for lock operation and management units. As the "brain" of lock operation, the reliability of the control system plays a decisive role in ensuring the continuous and efficient operation of locks. As the core and main equipment of the lock control system, the reliability of the PLC (Programmable Logic Controller) determines the safety and reliability of the lock control system.
[0003] Currently, the measure to improve the reliability of the PLC is to adopt a dual CPU and dual power supply hot standby redundancy scheme. When the CPU and power supply modules of the PLC have hardware failures, they can be automatically switched without causing downtime. However, when the IO (switching quantity, analog quantity, high-speed counting, etc. input and output signals) modules of the PLC and the control system network have failures, and when the CPU module fails and stops due to the PLC's own system reasons or bugs in the program, it is necessary to stop the machine and wait for the failure to be repaired, replace the faulty module, or solve the problem in the program. The failure repair time is in hours or days, and the lock operation process is also interrupted accordingly.
[0004] Currently, the measure to improve the reliability of the PLC is to adopt a dual CPU and dual power supply hot standby redundancy scheme. This scheme cannot solve the lock operation interruption or even navigation suspension accidents caused by the IO modules and network failures with the highest failure rate of the PLC, nor can it solve the CPU failure and shutdown caused by the PLC's own system or program reasons (such failures are often the most difficult to solve and require a lot of time for troubleshooting). When the current control system PLC fails, it can only resume operation after being repaired on-site, and cannot support the application of remote centralized control and on-site unattended mode for locks.
[0005] Nowadays, more and more lock control systems adopt semi-automatic and fully automatic operation modes. When the current lock control system PLC fails, both the semi-automatic and fully automatic operation processes will be interrupted. After the PLC resumes operation, it can only adopt the manual single-item control mode to complete the subsequent processes of this lock cycle and then re-enter the semi-automatic and fully automatic operation modes of the next lock cycle, which cannot meet the requirements of continuous and efficient operation of locks. Summary of the Invention
[0006] In view of this, this application provides a dual PLC redundant backup method and system, which can meet the requirements of continuous and efficient operation of locks.
[0007] Specifically, the present application is implemented through the following technical solutions: The first aspect of the present application provides a dual PLC redundant backup method, and the method includes: Determine the backup levels of the first PLC and the second PLC, and determine the conducting PLC based on the backup levels. The conducting PLC is either the first PLC or the second PLC. Wherein, the first PLC and the second PLC are power interlocked, the first PLC and the second PLC are connected in parallel to the control circuit, the connections of the first PLC, the second PLC to the control circuit are physically isolated, and the switching control module controls the switching of the conducting direction of the power interlock. Control the control circuit to act based on the conducting PLC, and monitor the real-time working state of the conducting PLC. Locate the fault state position and the fault state type based on the real-time working state. Determine the working duration of the standby PLC based on the fault state type. The standby PLC is the PLC other than the conducting PLC among the first PLC and the second PLC. Calculate the execution function of the standby PLC based on the working duration and the fault state position. The execution function is a partial process for controlling the control circuit to act. Analyze the variable content of the execution function, and determine the associated function based on the variable content. Obtain the execution function and the associated function from the switching control module, and execute the execution function and the associated function based on the calculation variable information before the failure of the conducting PLC to control the control circuit to act.
[0008] The second aspect of the present application provides a dual PLC redundant backup system. The system includes a first PLC and a second PLC. The first PLC and the second PLC adopt a 1:1 full replication architecture, with the same functions and being backup to each other. A host computer. The first PLC and the second PLC are respectively connected to the host computer. The host computer is used to store the full-automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the host computer to ensure that the full-automatic and semi-automatic operation processes of the ship lock are not interrupted. Field devices. The field devices are connected to the first PLC and the second PLC. The currently working PLC performs logical operations and processing based on the action control function of the control circuit and the input signals received from the field devices, and generates control instructions to control the operation of the field devices.
[0009] The dual PLC redundant backup method and system provided by this application can reasonably select the conducting PLC according to the capabilities of different PLCs and the requirements of the control circuit by using dual PLCs and determining the backup level, reducing the risk of system downtime caused by insufficient performance or failure of a single PLC. When a failure occurs, the method provided by this application can locate the failure point based on the execution status information. Considering that the failure location may be in the middle of the execution of a sub-function or at the end of the execution of a sub-function, in order to handle various possible locations of failures, the method provided by this application sends the obtained execution functions and associated functions to the standby PLC after searching, and then can continue the execution results at the failure occurrence location and continue monitoring and control, avoiding restarting all monitoring programs and improving the efficiency of monitoring execution. In addition, the redundant backup provided by the present invention is not a direct switch. Considering that the conducting PLC is more suitable for monitoring and control after selection, therefore, first, the type of failure that occurs in the conducting PLC is used to determine how long the repair time is required, and within this repair time, the standby PLC is used instead. Thus, the repair time determines the length of the functions executed by the standby PLC. The replacement calculation for a short time does not require excessive initialization settings for the standby PLC, simplifying the operation of PLC backup. At the same time, the conducting PLC is always used as the main running PLC, ensuring the monitoring performance and improving the monitoring accuracy. A series of operations such as monitoring the real-time working status of the conducting PLC, fault location, type judgment, and determining the working duration, execution functions, and associated functions of the standby PLC enable the system to quickly and accurately respond to failures. During the switching process, relevant functions are executed using the calculation variable information of the conducting PLC before the failure, as well as the uploading and management of variable data, ensuring the coherence and integrity of the system data. Description of the Drawings
[0010] Figure 1 It is a flowchart of the first embodiment of the dual PLC redundant backup method provided by this application; Figure 2 It is a schematic structural diagram of the second embodiment of the dual PLC redundant backup system provided by this application. Detailed Implementation Modes
[0011] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with this application.
[0012] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a", "the", and "said" used in this application are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0013] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0014] Specific embodiments are given below to introduce the technical solutions of this application in detail.
[0015] Embodiment 1: Figure 1 This is a flowchart of Embodiment 1 of the dual PLC redundant backup method provided for this application. Please refer to Figure 1 , the method provided in this embodiment may include: S101. Determine the backup levels of the first PLC and the second PLC, and determine the conducting PLC based on the backup levels, where the conducting PLC is either the first PLC or the second PLC.
[0016] Among them, the first PLC and the second PLC adopt the same product model, but due to different commissioning times, there are differences in their usage durations, and thus there may also be differences in the degrees of performance degradation. The first PLC and the second PLC are power interlocked, the first PLC and the second PLC are connected in parallel to the control circuit, the connections between the first PLC, the second PLC and the control circuit are physically isolated, and the switching control module controls the switching of the conducting direction of the power interlock.
[0017] It should be noted that the power interlock between the first PLC and the second PLC is an electrical protection mechanism (domestically produced and independently controllable PLCs and imported brand PLCs can be used as the first PLC and the second PLC respectively). Its purpose is to ensure that only one PLC is in the powered-on working state at any time, preventing problems such as signal conflicts, power overloads, or control chaos caused by the simultaneous power-on of the two PLCs. The first PLC and the second PLC are connected to the control circuit in parallel, indicating that they both have independent lines connected to the control circuit, can simultaneously receive input signals from the control circuit, and output control signals to the control circuit. This connection method ensures that under normal circumstances, both PLCs have the opportunity to operate on the control circuit, and during the switching process, the input-output relationship of the control circuit will not change, ensuring the continuity of the system. Compared with series connection, parallel connection has higher reliability. If one of the PLCs fails, it will not affect the connection between the other PLC and the control circuit, and the other PLC can still normally receive and process control signals, thus maintaining the basic operation of the system.
[0018] Physical isolation means are adopted at the connection points of the first PLC, the second PLC, and the control circuit. Common physical isolation methods include optocoupler isolation, transformer isolation, etc. Among them, optocoupler isolation uses optical signals to transmit electrical signals, electrically isolating the input and output circuits, effectively preventing the propagation of electrical interference between the PLC and the control circuit; transformer isolation realizes electrical isolation while transmitting signals through the principle of electromagnetic induction. The main function of physical isolation is to improve the anti-interference ability of the system. In an industrial environment, there are various electromagnetic interference sources, such as electromagnetic radiation generated by equipment such as motors and frequency converters. Without physical isolation, these interference signals may enter the PLC or the control circuit, resulting in problems such as signal distortion and misoperation.
[0019] The switching control module is responsible for monitoring the working states of the first PLC and the second PLC, and deciding when and how to switch the conduction direction of the power interlock according to preset rules and conditions. For example, when it detects that the currently conducting PLC fails, the switching control module will send a control signal to change the state of the power interlock circuit, enabling the standby PLC to be powered on and work.
[0020] It should be noted that determining the backup levels of the first PLC and the second PLC includes: (1) Obtaining the resource information of the first PLC and the second PLC.
[0021] It should be noted that the resource information includes, but is not limited to, CPU performance (such as computing speed, number of cores, etc.), memory capacity, storage capacity, the maximum number of supported I / O points, etc. For example, if the CPU computing speed of the first PLC is 1 GHz, the memory capacity is 512 MB, the storage capacity is 1 GB, and it can support 200 I / O points; the CPU computing speed of the second PLC is 800 MHz, the memory capacity is 256 MB, the storage capacity is 500 MB, and it can support 150 I / O points. This information can be obtained by checking the product manual of the PLC or querying in its configuration software.
[0022] (2) Obtain the action control function of the control circuit.
[0023] It should be noted that as the core component of the control system, the PLC is followed by the control circuit. The main function of the PLC is to effectively control the control circuit. Among them, the action control function is a mathematical expression or program logic for the control circuit to complete various operations. Its essence is to control the level change of the circuit, and then achieve precise control of the on / off state of the field device. For example, in a motor control circuit, the action control function may involve the logic of starting, stopping, and speed regulation of the motor, such as the functional relationship for adjusting the motor speed according to signals such as temperature and pressure feedback from sensors. These functions are usually written in the PLC program by engineers. Through dynamic adjustment of the control circuit level, they accurately drive the motor to work according to the predetermined operation mode, ensuring the stable operation of the entire system.
[0024] (3) Calculate the function complexity according to the action control function.
[0025] It should be noted that the function complexity can be measured in various ways. A common method is to calculate the number of operators, variables, nesting levels, etc. in the action control function. For example, a simple addition function y = a + b has a low complexity, while a function containing multiple nested loops, conditional judgments, and involving a large number of variable operations has a high complexity. Weights can be assigned to each operator, variable, and nesting level, and the function complexity can be calculated by weighted summation. Suppose a function has 5 operators, 3 variables, and 2 levels of nesting, and the complexity value is 10 after the set weight calculation (the weight and calculation method here are only examples).
[0026] (4) Evaluate the processing ability based on the resource information.
[0027] Evaluate the processing capacity based on the obtained PLC resource information, in combination with its hardware architecture and performance metrics. For example, for a PLC with fast computing speed and large memory, its ability to process complex functions is relatively strong. An evaluation criterion can be formulated, such as scoring according to indicators such as CPU computing speed and memory capacity, and dividing the processing capacity into different levels such as high, medium, and low. For example, a PLC with a CPU computing speed above 800 MHz and a memory capacity above 512 MB has a high processing capacity, and those below this standard are medium or low.
[0028] (5)Match the function complexity with the processing capacity to determine the backup level.
[0029] Match the calculated function complexity with the evaluated PLC processing capacity. If the function complexity is high and the PLC processing capacity is strong, the backup level may be lower because the PLC has sufficient ability to handle complex functions and only requires fewer switching backups; conversely, if the function is complex but the PLC processing capacity is low, the backup level is higher.
[0030] It should also be noted that after determining the backup level, it includes: determining the conducting PLC based on the backup level; importing the action control function of the control circuit into the conducting PLC; adjusting the conducting direction of the power interlock part to turn on the power supply of the conducting PLC. This can ensure that the selected conducting PLC correctly loads the control function and obtains power supply, so as to smoothly carry out the control operation of the control circuit, maintain the normal operation of the system, and ensure the effective operation of the dual-PLC redundant backup.
[0031] The method provided by the present invention, compared with the method of determining the primary and backup levels according to experience in the prior art, can comprehensively consider the complexity of function execution and the execution ability of the PLC, improve the scientificity of level determination, and ensure the execution efficiency.
[0032] S102. Control the action of the control circuit based on the conducting PLC, and monitor the real-time working state of the conducting PLC.
[0033] It should be noted that controlling the action of the control circuit based on the conducting PLC and monitoring the real-time working state of the conducting PLC includes: (1)The conducting PLC runs the action control function of the control circuit.
[0034] After determining the conducting PLC, it will drive the control circuit to work according to the action control function pre-written in its program. For example, in the control of an automated production line, the conducting PLC will calculate the rotation speed and direction of the motor based on information such as the product position and speed detected by sensors through the action control function, so as to control the operation of the conveyor belt.
[0035] (2) Upload the local variables that complete the calculations in each sub - function of the action control function to the switching control module as a backup, and save the global variables of the action control function and the temporary calculation results of the local variables in each sub - function to the conducting PLC.
[0036] During the execution of the action control function, each sub - function will generate many local variables. For example, in a data - processing sub - function, local variables such as intermediate results and temporary counts may be calculated. Upload these local variables that have completed the calculations to the switching control module as a backup in a timely manner. In this way, when it is necessary to switch to the standby PLC, the standby PLC can quickly obtain these key intermediate data, reducing the time for recalculation and possible errors. Among them, the switching control module usually has a certain storage capacity and data management function, and can classify and store the uploaded local variables and quickly retrieve them.
[0037] (3) The conducting PLC monitors its own real - time working state and estimates the fault time based on the real - time working state.
[0038] There is a self - checking program inside the conducting PLC, which continuously monitors its own hardware state (such as CPU temperature, memory usage, I / O module status, etc.) and software running state (such as whether the program has a deadlock, abnormal interrupts, etc.). By monitoring these states and analyzing historical data, the time when a fault may occur can be estimated. For example, if it is found that the CPU temperature continues to rise within a certain period of time and approaches its critical temperature, and at the same time the memory usage increases rapidly and approaches saturation, combined with the empirical data of similar situations in the past, it is estimated that a fault may occur within the next 10 minutes.
[0039] (4) Adjust the upload mechanism of variables based on the estimated fault time.
[0040] When the conducting PLC estimates that the fault time is approaching, it will immediately adjust the upload mechanism of variables. Under normal circumstances, variables may be uploaded at a certain time interval (such as every 5 seconds), but when the estimated fault time is within a few minutes, the upload frequency will increase significantly, for example, it is changed to upload once every 1 second. The purpose of this is to ensure that as many important variable data as possible can be uploaded to the switching control module before the fault occurs, so as to ensure that the standby PLC can obtain more complete data when taking over.
[0041] The method provided by the present invention first saves important data by reporting after each sub - function is executed. However, when the PLC is running, the time when a fault may occur is estimated through the change of the real - time running state, and then the backup frequency is increased in advance, and then the variables in the process of executing the sub - function are saved, improving the data integrity for dealing with faults.
[0042] S103. Locate the fault status position and fault status type based on the real-time working status.
[0043] It should be noted that locating the fault status position and fault status type based on the real-time working status includes: (1) Continuously monitor the real-time working status of the conducting PLC.
[0044] It should be noted that through the self-check program of the conducting PLC or external monitoring equipment, its working status information is continuously obtained, such as hardware sensor data, software operation flag bits, etc. For example, the CPU usage rate of the PLC and the input / output values of the I / O module are read every 1 second.
[0045] (2) If the real-time working status is a fault, the switching control module locates the fault position based on the variable data before the fault status, and the fault position includes at least the middle part of the sub-function.
[0046] If the real-time working status is a fault, the switching control module locates the fault position based on the variable data before the fault status. The fault position may be in the middle part of the sub-function. For example, in a complex calculation sub-function, due to an error in a certain intermediate variable, the calculation result is abnormal. By analyzing the variable data uploaded before the fault and the execution logic of the sub-function, it can be determined which specific calculation step in the sub-function has a problem; the fault position may also be at the node position, such as at the data transfer node between different sub-functions, where data is lost or incorrect during the transfer process. By checking the variable values and data flow before and after the node, the fault can be located.
[0047] If the working status is normal, continue to execute the subsequent operation steps according to the established program flow. The conducting PLC continuously runs the action control function of the control circuit, and uploads the local variables completed in each sub-function in the action control function to the switching control module for backup at regular time intervals. At the same time, the global variables of the action control function and the temporary calculation results of the local variables in each sub-function are saved locally in the conducting PLC. Moreover, the conducting PLC continuously monitors its own real-time working status, estimates the fault time based on the real-time working status, and dynamically adjusts the variable upload mechanism according to the estimated fault time to ensure that the system can operate stably and efficiently under any circumstances, and guarantee the continuity and reliability of the ship lock control process.
[0048] Specifically, locating the fault status position and fault status type based on the real-time working status includes: (1) Obtain historical working status data.
[0049] Obtain the working state data of the conducting PLC in the past period from the storage device of the PLC or an external data recording system, including hardware monitoring data (such as temperature, voltage, current, etc.) and software operation logs (such as program execution steps, error messages, etc.).
[0050] (2)Predict the estimated working state of the conducting PLC within the first time range based on the historical working state data.
[0051] Based on the historical working state data, use data analysis algorithms (such as time series analysis, machine learning algorithms, etc.) to predict the estimated working state of the conducting PLC within the first time range. For example, by analyzing the past CPU temperature data, use the linear regression algorithm to predict the change trend of the CPU temperature within the next 1 hour; by analyzing the program operation logs, use the machine learning classification algorithm to predict whether a software failure is likely to occur.
[0052] (3)Predict the fault state switching process of the conducting PLC based on the estimated working state.
[0053] According to the estimated working state, combined with the hardware architecture and software operation mechanism of the PLC, predict the fault state switching process of the conducting PLC. For example, if it is predicted that the CPU temperature will rise sharply and exceed the critical value, then it can be speculated that there may be fault state switching processes such as CPU overheat protection triggering and program interruption, as well as the sequence and time intervals in which these processes may occur.
[0054] (4)Obtain the latest real-time working state of the conducting PLC.
[0055] The latest real-time working state of the conducting PLC can be obtained by high-speed data transmission through the communication interface of the PLC (such as Ethernet, serial port, etc.).
[0056] (5)Based on the latest real-time working state, correct the prediction result of the fault state switching process.
[0057] After obtaining the latest real-time working state, compare and analyze it with the previous prediction result. If it is found that the actual CPU temperature rises faster than predicted, or the growth trend of the memory usage does not match the prediction, then it is necessary to correct the prediction result of the fault state switching process in a timely manner. For example, if it was originally predicted that the CPU overheat protection would start after 30 minutes, but the latest data shows that the CPU temperature is already close to the critical value and the protection mechanism may be triggered within 10 minutes, then it is necessary to urgently adjust the prediction result and take corresponding emergency measures, such as preparing in advance for the switching of the standby PLC or notifying the maintenance personnel to conduct on-site inspections.
[0058] (6)Predict the fault location based on the corrected prediction result.
[0059] Predict the fault location based on the corrected prediction results. If it is predicted that a certain hardware module may fail due to overheating, then the fault location can be determined to be in that hardware module; if it is predicted that an error may occur in a specific calculation step of the program, then the fault location is in the corresponding software code part.
[0060] (7) Adjust the data backup mechanism based on the predicted fault location.
[0061] Adjust the data backup mechanism according to the relationship between the predicted fault location and the end of the function and the possible fault types. If the predicted fault location is close to the end of the function and there is a risk of data loss, then increase the data backup frequency to ensure that important data can be quickly stored in the switching control module; if the predicted fault location is far from the end of the function and has little impact on data integrity, then the backup frequency can be appropriately reduced to save system resources, improve the overall operation efficiency of the system, ensure the rationality and effectiveness of data backup work in different fault risk scenarios, and ensure the stable operation of the system. Specifically, if the fault location is close to the end of the function, it means that there may be only a small number of remaining calculation steps in the future. At this time, if data loss occurs, it may cause the entire control process to be unable to be completed completely or result in incorrect results, so it is necessary to increase the data backup frequency to ensure data security. If the fault location is far from the end of the function, a large number of calculation and control steps have been completed before the fault occurs, and there is a large adjustment and recovery space in the future. Appropriately reducing the backup frequency will not have a serious impact on the overall operation of the system, which can avoid occupying too much system resources due to excessive backup and help improve the operation efficiency and resource utilization rate of the system.
[0062] (3) The switching control module determines the faulty component according to the real-time working state of the fault location and the fault moment, and determines the fault state type based on the faulty component.
[0063] The switching control module determines the faulty component according to the located fault location and the real-time working state of the fault moment. If an error occurs in the CPU operation, then the faulty component is the CPU; if the input and output of a certain I / O module are abnormal, the faulty component is the corresponding I / O module. Further determine the fault state type based on the faulty component, such as hardware faults (such as chip damage, circuit short circuit, etc.) or software faults (such as program vulnerabilities, memory overflow, etc.).
[0064] S104. Determine the working duration of the standby PLC based on the fault state type, where the standby PLC is the PLC other than the conducting PLC among the first PLC and the second PLC.
[0065] Different types of fault states require repair times of different durations. In order to use the conduction PLC operation control function as much as possible, it is necessary to estimate the repair time of the conduction PLC, and then select an execution function and associated functions that are longer than this time within this time range to ensure that the PLC can complete the repair.
[0066] It should be noted that determining the working duration of the standby PLC based on the fault state type includes: (1) Determining the fault repair duration based on the fault state type.
[0067] Estimate the time required for repair according to the fault state type. Specifically, for hardware faults, if a common I / O module is damaged and there is a standby module on site, replacement and debugging may take 30 minutes; if it is a CPU fault and a new CPU needs to be purchased from the manufacturer, it may take several days. For software faults, if it is a simple program logic error, it may be repaired within 1 hour through remote debugging; if it is a complex system vulnerability, it may take the development team several weeks to solve. These estimates of repair durations can be based on past maintenance experience and information provided by equipment suppliers.
[0068] (2) Determining the function execution range according to the fault state position and the fault repair duration.
[0069] For example, if the fault state position is in the middle of a control process and the fault repair duration is long, then it may be necessary for the standby PLC to execute the function starting from a certain key node before the fault state position to ensure the continuity of the entire control process. Starting from the function statement before the fault state position, the function range with an execution duration reaching the fault repair duration is the function execution range.
[0070] (3) Adjusting the function execution range based on the function integrity within the function execution range.
[0071] In order to ensure the integrity of the execution function as much as possible, avoid passing intermediate variables to other PLCs for interrupted calculation, simplify the backup switching process, and ensure the accuracy of calculation, it is also necessary to calculate the function integrity after determining the function execution range. The integrity refers to whether the sub-function has been executed completely and whether all calculations of the sub-function have been completed. If the integrity is insufficient, the function execution range is expanded to ensure the complete execution of the sub-function.
[0072] If there are some function parts that depend on the faulty component or may be affected by the fault within the determined execution range, it is necessary to further adjust the execution range to exclude these parts that may cause problems. For example, in a data processing function, if the faulty component affects the acquisition and preprocessing of some data, then when the standby PLC executes, it is necessary to adjust the function execution range to skip these affected data processing links and directly start processing from the reliable data part.
[0073] (4)Calculate the function execution time based on the adjusted function execution range.
[0074] Calculate the function execution time according to the adjusted function execution range and the performance of the standby PLC. For example, when the standby PLC executes the adjusted function, it needs to traverse a certain number of data points and perform calculations. According to its CPU operation speed and data processing volume, the calculated execution time is 20 minutes.
[0075] It should also be noted that when calculating the total duration of the function execution time, it is necessary to distinguish between parallel statements and serial statements. The time calculation of parallel statements should take the maximum value among them because they are executed simultaneously; while the time of serial statements is added up sequentially. For example, for a function that contains both parallel and serial parts, first calculate the execution time of each statement in the parallel part separately, take the maximum value as the time of the parallel part, then add up the time of the serial part sequentially, and finally add the time of the parallel part to the total time of the serial part to obtain the total duration of the function.
[0076] (5)Take the maximum value of the function execution time and the fault repair duration as the working duration.
[0077] Suppose the function execution time is 20 minutes and the fault repair duration is 30 minutes, then the working duration of the standby PLC is determined to be 30 minutes. This can ensure that the standby PLC can operate stably during the fault repair period, avoid problems before the repair is completed due to too long execution time, and also avoid repeated switching.
[0078] S105. Calculate the execution function of the standby PLC based on the working duration and the fault status position, and the execution function is a partial process for controlling the action of the control circuit.
[0079] It should be noted that calculating the execution function of the standby PLC based on the working duration and the fault status position includes: (1)Locate the faulty sub-function in the execution function according to the fault status position.
[0080] It should be noted that the action control function of the control circuit is usually composed of multiple sub-functions, and these sub-functions cooperate with each other to complete specific control tasks. Specifically, the sub-function containing the fault is located in the entire control program according to the fault status position. For example, in a control system program, if a fault occurs in the control logic part of a certain device, by analyzing the program structure and fault information, it can be determined which specific sub-function has a problem, such as the motor speed regulation sub-function or the valve control sub-function, etc.
[0081] (2) Calculate the execution duration of the faulty sub-function.
[0082] To calculate the execution duration of the faulty sub-function, it is necessary to comprehensively consider the code structure inside the sub-function, the involved operation complexity, and the performance parameters of the standby PLC. For the code structure, analyze factors such as the number and nested levels of loop structures and conditional judgment statements contained therein. For example, a sub-function containing multiple nested loops usually takes longer to execute than simple sequential execution code. At the same time, consider the operation complexity. For example, a sub-function involving complex mathematical calculations such as a large number of floating-point operations and matrix operations will also consume more execution time. Based on the CPU operation speed of the standby PLC, estimate by combining the above factors. Assume that the CPU operation speed of the standby PLC is 1 GHz, and the faulty sub-function contains a simple addition operation with a loop executed 100 times and a multiplication operation with two nested loops. After estimating and accumulating the clock cycles required for each operation step, the execution duration of the faulty sub-function on the standby PLC is calculated to be approximately 15 minutes.
[0083] (3) Locate the execution segment of the faulty sub-function based on the difference between the execution duration and the working duration, and the execution duration of the execution segment is less than the execution duration of the faulty sub-function.
[0084] After determining the execution duration of the faulty sub-function and the working duration of the standby PLC, calculate the difference between the two. Assume that the working duration of the standby PLC is 30 minutes and the execution duration of the faulty sub-function is 15 minutes, then the difference is 15 minutes. According to this difference, select a suitable execution segment in the faulty sub-function. If the faulty sub-function is a combination of multiple steps executed sequentially and the previous steps are more critical for the emergency control and stability of the system, then the first half (execution duration is about 7.5 minutes) can be selected as the execution segment. The purpose of such selection is to ensure that the standby PLC can execute the most critical control operations within the limited working duration, maintain the basic operation of the system, and avoid executing the subsequent parts that may cause problems. When selecting the execution segment, it is also necessary to consider the data dependency relationship and logical integrity within the sub-function to ensure that the selected segment can still work properly and produce meaningful control outputs when executed separately from the original faulty sub-function.
[0085] Generally speaking, since functions are usually executed sequentially and their execution order cannot be skipped arbitrarily, when determining the execution segment, it is necessary to execute strictly in the order of duration. During the execution in the order of duration, it is necessary to clarify the position where the execution ends. The determination of this position should be based on the working duration of the standby PLC and the logical structure and time distribution within the sub-function. For example, for a sub-function with a long execution duration, it can be divided into multiple logical units, each logical unit having relatively independent functions and required execution times. According to the working duration of the standby PLC and the execution times of each logical unit, accurately determine the execution end position to ensure that the part before the end position can be executed completely and effectively to achieve the expected control function.
[0086] At the same time, it is also necessary to determine the data upload. During the execution of the execution segment, it is necessary to clarify at which key nodes to upload data and what data to upload. The timing and content of data upload are crucial for system monitoring, fault analysis, and subsequent system recovery. It is possible to perform data upload operations after the completion of important steps in the execution segment according to the logical key points and data processing flow within the sub-function. For example, after completing a key calculation or data processing step, upload the current intermediate results or status information to the switching control module or other storage locations for use during subsequent fault diagnosis and system recovery. This can not only ensure the completion of key operations within the limited working duration but also provide sufficient data support for subsequent system maintenance and fault handling to ensure the reliability and stability of the system.
[0087] (4) Use the execution segment as the execution function of the standby PLC.
[0088] It should be noted that using the execution segment as the execution function of the standby PLC buys time for subsequent fault repair and system recovery. At the same time, when using the execution segment as the execution function, some necessary encapsulation and interface processing are also required to enable it to be smoothly integrated with the operating environment of the standby PLC and other related functions to ensure the coherence and stability of the entire control process.
[0089] S106. Analyze the variable content of the execution function and determine the associated function based on the variable content.
[0090] It should be noted that analyzing the variable content of the execution function and determining the associated function based on the variable content includes: (1) Calculate the first working duration of the execution function of the standby PLC.
[0091] Analyze the code structure and computational complexity of the execution function of the standby PLC, considering factors such as the number of loops involved, the quantity and complexity of conditional judgments, and the amount of data processing. For example, the execution function contains a simple data comparison operation that loops 50 times and a calculation process for weighted summation of 10 data points. Combining with the performance indicators of the standby PLC, such as the CPU operation speed and memory read / write speed, estimate the first working duration of this execution function. Assume the CPU operation speed of the standby PLC is 800 MHz. After calculating and accumulating the clock cycles required for each operation, it is concluded that the first working duration of this execution function is approximately 8 minutes.
[0092] (2)Calculate the second working duration based on the difference between the working duration and the first working duration.
[0093] Given the total working duration of the standby PLC (assumed to be 30 minutes), subtract the first working duration from the total working duration to obtain the second working duration. In the above example, the second working duration is 30 - 8 = 22 minutes. This difference represents the remaining time available for the associated function to execute after the main execution function is completed, providing a basis for the time limit for determining the appropriate associated function.
[0094] (3)Determine the input variables and intermediate call functions of the execution function of the standby PLC.
[0095] Study the code logic of the execution function to identify all input variables, which may come from sensor data, the output of other control modules, or system setting parameters, etc. For example, in the execution function of a temperature control system, the input variables may include the value collected by the current temperature sensor, the set target temperature value, etc. At the same time, find out the intermediate call functions called during the execution of the execution function. These functions may be functional modules for data processing, algorithm calculation, or interaction with other system modules. For example, the execution function may call a function for data filtering to process the data collected by the temperature sensor, and this data filtering function is the intermediate call function.
[0096] (4)Determine the first associated function based on the input variables and the second associated function based on the intermediate call functions.
[0097] For each input variable, analyze its source and subsequent processing procedures to determine other functions related to it as the first associated functions. For example, if the input variable is data collected by a sensor, there may be a function for calibrating and initializing the sensor, and a function for converting the sensor data into appropriate units. These functions all belong to the first associated functions. For intermediate calling functions, find other functions on which they depend as the second associated functions. For instance, a data filtering function may depend on a specific mathematical library function to implement the filtering algorithm, and this mathematical library function is the second associated function.
[0098] (5) Use the sets of the first associated functions and the second associated functions as the initial associated functions, and calculate the third working duration and the fourth working duration executed by the first associated functions and the second associated functions respectively.
[0099] Combine these first associated functions and second associated functions together to form the initial associated functions. For each first associated function and second associated function, estimate their respective execution times according to a method similar to calculating the working duration of the execution function, based on their code structures, operation complexities, and the performance indicators of the standby PLC, and record them as the third working duration and the fourth working duration respectively. For example, a first associated function includes a simple linear transformation calculation and a small amount of data storage operations, and its estimated third working duration is about 3 minutes; a second associated function involves complex matrix operations and multiple function calls, and its fourth working duration is about 10 minutes.
[0100] (6) Adjust the initial associated functions based on the difference between the sum of the third working duration and the fourth working duration and the second working duration to obtain the final associated functions.
[0101] Calculate the total sum of the third working duration and the fourth working duration, and compare it with the second working duration. If the total sum is less than the second working duration, it means there is remaining time, and some associated functions related to system stability or data integrity can be considered to be added to make full use of the working time of the standby PLC and improve the reliability of the system. For example, a data backup function can be added to regularly back up key data to a redundant storage device. If the total sum is greater than the second working duration, some associated functions need to be deleted to avoid the situation that the standby PLC cannot complete all tasks within the working duration due to too long execution time. Through such an adjustment process, finally determine a suitable set of associated functions to ensure that within the working duration of the standby PLC, both the key operations of the execution function can be completed and the relevant auxiliary functions can be taken into account.
[0102] S107. Obtain the execution function and the associated functions from the switching control module, and execute the execution function and the associated functions based on the calculation variable information before the conduction PLC fails, to control the control circuit to act.
[0103] When it is necessary to switch to the standby PLC, it quickly obtains the pre-determined execution function and associated functions from the switching control module. The switching control module plays a key role in data storage and coordination, ensuring that the standby PLC can accurately obtain the required information.
[0104] It should be noted that, based on the calculation variable information of the conducting PLC before the fault, the execution function and the associated function are executed to control the operation of the control circuit. After that, it includes: (1) Monitoring the real-time execution progress of the standby PLC.
[0105] By setting an execution progress flag bit in the standby PLC or using an external monitoring device, the progress of the standby PLC in executing the function and the associated function is tracked in real time. For example, a counter is updated after the completion of key steps of the execution function, and the external monitoring device can regularly read the value of this counter to understand the execution progress.
[0106] (2) Determining the execution stop time of the standby PLC based on the relationship between the real-time execution progress and the working duration and the execution completion status of the execution function and the associated function.
[0107] If the execution progress is close to the working duration and the execution function and the associated function are basically completed, then it can be determined that the execution stop time is approaching; if the execution progress is slow but the key parts of the execution function and the associated function have been completed, the stop time can also be determined in advance according to the situation. For example, when the execution progress of the standby PLC reaches 90% and the core functions of the execution function and the associated function have been completed, at this time, it can be determined that the execution stop time is within the next few minutes for subsequent switching and data processing operations.
[0108] (3) Adjusting the content of the execution function and the associated function based on the relationship between the execution stop time and the working duration, and the adjustment includes increasing or decreasing the execution function or the associated function.
[0109] Based on the relationship between the execution stop time and the working duration, adjust the content of the execution function and the associated function. If the execution stop time is advanced, some non-critical operations or data processing links may need to be reduced to ensure the completion of key tasks before the stop time; if the execution stop time is delayed and there is enough time, some auxiliary functions or data verification operations can be added. For example, if it is found that the execution progress is too fast and there is still a long time until the working duration, some associated functions for data integrity checking can be added to improve the reliability of the system.
[0110] (4) After the standby PLC completes the control of the working duration, uploading the execution variable data of the standby PLC to the switching control module.
[0111] After the standby PLC completes the control of the working duration, its execution variable data is uploaded to the switching control module, and this data can be used for subsequent system analysis, troubleshooting, or as reference data for the next switch.
[0112] (5) Switch the power paths of the conducting PLC and the standby PLC based on the fault status of the conducting PLC.
[0113] When it is determined that the conducting PLC has a fault and the standby PLC has completed the control of its working duration, the switching control module controls the power interlock device to cut off the power of the faulty conducting PLC, and at the same time provides a stable power supply for the standby PLC to ensure the continuous and stable operation of the system.
[0114] It should also be noted that the first PLC and the second PLC are respectively connected to the upper computer, and the upper computer is used to store the full-automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the upper computer to ensure that the full-automatic and semi-automatic operation processes of the ship lock are not interrupted.
[0115] The method provided in this embodiment reasonably selects the PLC to be turned on by determining the backup level of the first PLC and the second PLC, so that the system can be adapted according to different control requirements and PLC performance, reduce the probability of system failure caused by PLC problems, and ensure reliable control equipment operation under various working conditions; by setting power interlocking, parallel connection and physical isolation, etc., it effectively prevents power supply conflicts, signal interference and other problems, ensures the stability of the system during operation and switching, reduces failures caused by electrical problems, and improves the anti-interference ability of the overall system. Comprehensive monitoring of the real-time working status of the PLC and fault location and type judgment based on this can quickly and accurately find the root cause of the problem, provide key basis for subsequent response measures, greatly shorten the troubleshooting time, improve maintenance efficiency, and reduce downtime; determine the working time of the standby PLC according to the type of fault state, and accurately calculate the execution function and association function of the standby PLC, to ensure that the standby PLC can perform key tasks in a targeted manner when taking over the work, maintain the basic functions of the system within a limited time, avoid the complete paralysis of the system due to faults, and achieve rapid fault recovery and system switching. Timely upload the local variables in the action control function to the switching control module and save the temporary calculation results of the global and local variables locally in the PLC. These data can be used to ensure the continuity of the control process when the PLC switches, avoid errors caused by data loss and recalculation, and ensure the accuracy and stability of the system operation. In addition, the effective management and utilization of variable data throughout the process, as well as the dynamic adjustment of execution functions and associated functions based on fault conditions, further enhance the data security and reliability of system operation, so that the system can adapt to complex and changeable operating environments and fault conditions.
[0116] Corresponding to the aforementioned embodiment of a dual PLC redundant backup method, the present application also provides an embodiment of a dual PLC redundant backup system.
[0117] Embodiment 2: Figure 2 This is a schematic diagram of the structure of the second embodiment of the dual PLC redundant backup system provided by this application. Figure 2 The system provided in this embodiment includes a first PLC and a second PLC, wherein the first PLC and the second PLC adopt a 1:1 fully replicated architecture, and both have exactly the same functions and serve as backup for each other; A host computer, wherein the first PLC and the second PLC are connected to the host computer respectively, and the host computer is used to store the fully automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the host computer to ensure that the fully automatic and semi-automatic operation process of the ship lock is not interrupted; A field device is connected to the first PLC and the second PLC. The PLC currently in working state performs logical operations and processing according to the action control function of the control circuit and the input signal received from the field device to generate control instructions to control the operation of the field device.
[0118] It should be noted that the IO signals of all sensors and actuators on site are connected to the first PLC and the second PLC in a physically isolated manner. The power supplies of the first PLC and the second PLC are interlocked to ensure that only one set of PLCs is powered on at any time to avoid damage to the main and backup systems caused by extreme working conditions such as lightning strikes (the ship locks are all set up near rivers and are high-risk areas for lightning strikes) and external power intrusion.
[0119] The system of this embodiment can be used to perform Figure 1 The steps, specific implementation principles and implementation processes of the method embodiment shown are similar and will not be repeated here.
[0120] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A dual PLC redundant backup method, characterized in that, The method includes: Determine the backup levels of the first PLC and the second PLC, and determine the conducting PLC based on the backup levels, where the conducting PLC is either the first PLC or the second PLC; Wherein, the first PLC and the second PLC are power interlocked, the first PLC and the second PLC are connected in parallel to the control circuit, the connection points of the first PLC, the second PLC and the control circuit are physically isolated, and the switching control module controls the switching of the conducting direction of the power interlock; Control the control circuit to act based on the conducting PLC, and monitor the real-time working state of the conducting PLC; Locate the fault state position and fault state type based on the real-time working state; Determine the working duration of the standby PLC based on the fault state type, where the standby PLC is the PLC other than the conducting PLC among the first PLC and the second PLC; Calculate the execution function of the standby PLC based on the working duration and the fault state position, where the execution function is part of the process of controlling the control circuit to act; Analyze the variable content of the execution function, and determine the associated function based on the variable content; Obtain the execution function and the associated function from the switching control module, and execute the execution function and the associated function based on the calculation variable information before the conducting PLC fails, to control the control circuit to act.
2. The method according to claim 1, characterized in that, The determining the backup levels of the first PLC and the second PLC includes: Obtain the resource information of the first PLC and the second PLC; Obtain the action control function of the control circuit; Calculate the function complexity according to the action control function; Evaluate the processing ability based on the resource information; Match the function complexity with the processing ability to determine the backup level.
3. The method according to claim 1, wherein The controlling the control circuit to act based on the conducting PLC and monitoring the real-time working state of the conducting PLC includes: The conducting PLC runs the action control function of the control circuit; Upload the local variables that have completed calculations in each sub-function in the action control function to the switching control module as a backup, and save the global variables of the action control function and the temporary calculation results of the local variables in each sub-function to the conducting PLC; The conducting PLC monitors its own real-time working state and estimates the fault time based on the real-time working state; Adjust the variable uploading mechanism based on the estimated fault time.
4. The method according to claim 1, wherein The locating the fault state position and fault state type based on the real-time working state includes: Circularly monitor the real-time working state of the conducting PLC; If the real-time working state is a fault, the switching control module locates the fault position based on the variable data before the fault state, and the fault position includes at least the middle part of the sub-function; The switching control module determines the faulty component according to the fault position and the real-time working state at the fault moment, and determines the fault state type based on the faulty component.
5. The method according to claim 1, wherein The determining the working duration of the standby PLC based on the fault state type includes: Determine the fault repair duration based on the fault state type; Determine the function execution range according to the fault state position and the fault repair duration; Adjust the function execution range based on the integrity of the function within the function execution range; Calculate the function execution time based on the adjusted function execution range; Use the maximum value of the function execution time and the fault repair duration as the working duration.
6. The method according to claim 1, wherein The calculating the execution function of the standby PLC based on the working duration and the fault state position includes: Locate the faulty sub-function in the execution function according to the fault state position; Calculate the execution duration of the faulty sub-function; Locate the execution segment of the faulty sub-function based on the difference between the execution duration and the working duration, and the execution duration of the execution segment is less than that of the faulty sub-function; Use the execution segment as the execution function of the standby PLC.
7. The method according to claim 1, wherein The analyzing the variable content of the execution function and determining the associated function based on the variable content includes: Calculate the first working duration of the execution function of the standby PLC; Calculate the second working duration based on the difference between the working duration and the first working duration; Determine the input variables and intermediate call functions of the execution function of the standby PLC; Determine the first associated function based on the input variables and the second associated function based on the intermediate call functions; Use the set of the first associated function and the second associated function as the initial associated function, and calculate the third working duration and the fourth working duration of the execution of the first associated function and the second associated function respectively; Adjust the initial associated function based on the gap between the sum of the third working duration and the fourth working duration and the second working duration to obtain the final associated function.
8. The method according to claim 1, wherein After executing the execution function and the associated function based on the calculation variable information before the conduction PLC fails and controlling the control circuit to act, it includes: Monitor the real-time execution progress of the standby PLC; Determine the execution stop time of the standby PLC based on the relationship between the real-time execution progress and the working duration and the execution completion status of the execution function and the associated function; Adjust the content of the execution function and the associated function based on the relationship between the execution stop time and the working duration, and the adjustment includes adding or reducing the execution function or the associated function; After the standby PLC completes the control of the working duration, upload the execution variable data of the standby PLC to the switching control module; Switch the power supply paths of the conduction PLC and the standby PLC based on the fault state of the conduction PLC.
9. The method according to claim 1, wherein The locating the fault state position and the fault state type based on the real-time working state includes: Obtain historical working state data; Predict the estimated working state of the conduction PLC within the first time range based on the historical working state data; Predict the fault state switching process of the conduction PLC based on the estimated working state; Obtain the latest real-time working state of the conduction PLC; Correct the prediction result of the fault state switching process based on the latest real-time working state; Predict the fault location based on the corrected prediction result; Adjust the data backup mechanism based on the predicted fault location.
10. A dual PLC redundant backup system, characterized in that, The system is applied to the dual-PLC redundant backup method described in any one of claims 1-9. The system includes a first PLC and a second PLC. The first PLC and the second PLC adopt a 1:1 full-copy architecture, with the same functions and being backup for each other. A host computer. The first PLC and the second PLC are respectively connected to the host computer. The host computer is used to store the full-automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the host computer to ensure that the full-automatic and semi-automatic operation processes of the ship lock are not interrupted. Field devices. The field devices are connected to the first PLC and the second PLC. The PLC in the current working state performs logical operations and processing based on the action control function of the control circuit and the input signals received from the field devices, and generates control instructions to control the operation of the field devices.
Citation Information
Patent Citations
Safety control method of industrial safety PLC
CN111580454A
Redundant hot standby control system and control device, redundant hot standby method and computer-readable storage medium
CN112639640A
Vehicle-mounted annunciator control method and system based on dual-control redundancy design
CN118770307A
Safety redundant PLC communication control system
CN119065228A
Electrical control device for underwater vehicle
CN119828446A