Dual PLC redundant backup method and system

Through the dual PLC redundant backup method, the interruption problem of the PLC control system in the event of failure is solved, the continuous and efficient operation and remote control of the lock are realized, and the system reliability and monitoring accuracy are improved.

CN120276364BActive Publication Date: 2025-08-26BEIJING RES INST OF AUTOMATION FOR MACHINERY IND +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510732378.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-08-26
Estimated Expiration
2045-06-03

AI Technical Summary

Technical Problem

The existing PLC control system cannot effectively solve the lock operation interruption caused by IO module and network failure in the event of a failure, and cannot achieve remote centralized control and unattended operation, affecting the continuous and efficient operation of the lock.

Method used

The dual PLC redundant backup method is adopted to determine the backup level, monitor the real-time working status, locate the fault status and type, and use the backup PLC to execute functions and association functions to ensure that the system quickly resumes operation in the event of failure, avoid restarting the monitoring program, and maintain data coherence and system stability.

Benefits of technology

It improves the reliability and monitoring accuracy of the PLC control system, realizes continuous and efficient operation of the ship lock, supports remote centralized control and unattended control, and reduces the impact of fault repair time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120276364B_ABST
    Figure CN120276364B_ABST
Patent Text Reader

Abstract

The present application provides a dual PLC redundant backup method and system, which belongs to the field of ship lock control. The method includes: determining the backup level of the first PLC and the second PLC, and determining the on-state PLC based on the backup level; controlling the control circuit action based on the on-state PLC, and monitoring the real-time working status of the on-state PLC; locating the fault state position and the fault state type based on the real-time working status; determining the working time of the standby PLC based on the fault state type; calculating the execution function of the standby PLC based on the working time and the fault state position; analyzing the variable content of the execution function, and determining the associated function based on the variable content; obtaining the execution function and the associated function from the switching control module, and executing the execution function and the associated function based on the calculated variable information before the on-state PLC fails, and controlling the control circuit action. The dual PLC redundant backup method and system provided by the present application can meet the requirements for continuous and efficient operation of ship locks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of ship lock control technology, and in particular to a dual PLC redundant backup method and system. Background Art

[0002] Locks are crucial hydraulic structures that help navigable ships overcome water level differences, channelize waterways, and create "water highways." With China's vigorous development of water transportation, locks and other infrastructure face increasing pressure on navigation. Ensuring the safe, continuous, and efficient operation of locks remains a top priority for lock management. The control system, the "brain" of lock operations, ensures continuous and efficient operation, and its reliability is crucial. The PLC (Programmable Logic Controller), the core and primary component of lock control systems, determines their safety and reliability.

[0003] The current approach to improving PLC reliability is to implement dual CPU and dual power supply hot standby redundancy. This allows the PLC's CPU and power supply modules to automatically switch to another module in the event of hardware failure, preventing downtime. However, if the PLC's IO (input and output signals such as digital, analog, and high-speed counters) modules or control system network fail, or if the PLC's own system or program bugs cause the CPU module to shut down, the system must be down for repairs, requiring replacement of the faulty module or resolving the program issue. This can take hours or days to repair, disrupting the lock's operations.

[0004] The current approach to improving PLC reliability is to implement a dual-CPU, dual-power supply hot standby redundancy solution. However, this solution cannot address the interruptions and even suspensions of ship lock operations caused by IO module and network failures, which are the most common PLC failures. It also cannot address CPU downtime caused by faults within the PLC's own system or program (this type of failure is often the most difficult to resolve and requires significant time to troubleshoot). When a PLC failure occurs in the current control system, operation can only resume after on-site repairs, making it unable to support remote centralized control of ship locks or on-site unmanned operation.

[0005] Nowadays, more and more ship lock control systems adopt semi-automatic and fully automatic operation modes. When the PLC of the current ship lock control system fails, the semi-automatic and fully automatic operation processes will be interrupted. After the PLC resumes operation, it can only use manual single-item control mode to complete the subsequent processes of this lock and then re-switch to the semi-automatic and fully automatic operation mode of the next lock, which cannot meet the requirements of continuous and efficient operation of the lock. Summary of the Invention

[0006] In view of this, the present application provides a dual PLC redundant backup method and system that can meet the requirements of continuous and efficient operation of the lock.

[0007] Specifically, this application is implemented through the following technical solutions:

[0008] A first aspect of the present application provides a dual PLC redundant backup method, the method comprising:

[0009] Determine the backup levels of the first PLC and the second PLC, and determine a conducting PLC based on the backup levels, where the conducting PLC is any one of the first PLC and the second PLC;

[0010] The first PLC and the second PLC are interlocked in power supply, the first PLC and the second PLC are connected in parallel to a control circuit, the connection points between the first PLC and the second PLC and the control circuit are physically isolated, and a switching control module controls the switching of the conduction direction of the power interlock;

[0011] Controlling the control circuit action based on the conduction PLC and monitoring the real-time working status of the conduction PLC;

[0012] Locating the fault state position and the fault state type based on the real-time working state;

[0013] Determine the working time of a standby PLC based on the fault state type, where the standby PLC is the PLC other than the conducting PLC among the first PLC and the second PLC;

[0014] Calculating an execution function of the standby PLC based on the working duration and the fault state location, wherein the execution function is a partial process for controlling the operation of the control circuit;

[0015] Analyzing variable contents of the execution function and determining an associated function based on the variable contents;

[0016] The execution function and the correlation function are obtained from the switching control module, and the execution function and the correlation function are executed based on the calculated variable information before the PLC fault is turned on to control the operation of the control circuit.

[0017] A second aspect of the present application provides a dual PLC redundant backup system, the system comprising a first PLC and a second PLC, wherein the first PLC and the second PLC adopt a 1:1 fully replicated architecture, and both have exactly the same functions and serve as backup for each other;

[0018] A host computer, wherein the first PLC and the second PLC are respectively connected to the host computer, and the host computer is used to store the fully automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the host computer to ensure that the fully automatic and semi-automatic operation processes of the ship lock are not interrupted;

[0019] A field device is connected to the first PLC and the second PLC. The PLC currently in operation performs logical operations and processing based on the action control function of the control circuit and the input signal received from the field device to generate control instructions to control the operation of the field device.

[0020] The dual PLC redundant backup method and system provided by the present application, by adopting dual PLCs and determining the backup level, can reasonably select the conducting PLC according to the capabilities of different PLCs and the requirements of the control circuit, thereby reducing the risk of system shutdown due to insufficient performance or failure of a single PLC. In the event of a fault, the method provided by the present application can locate the fault point based on the execution status information. Considering that the fault location may be in the middle of a sub-function execution or at the end of a sub-function execution, in order to cope with the possible locations of various faults, the method provided by the present application will search for the acquired execution function and associated function and send them to the backup PLC, thereby being able to continue the execution result of the fault location, continue monitoring and control, avoid restarting all monitoring programs, and improve the efficiency of monitoring execution. In addition, the redundant backup provided by the present invention is not a direct switch. Considering that the on-state PLC is more suitable for monitoring and control after selection, the type of fault occurring in the on-state PLC is first used to determine how long it will take to repair. During this repair time, the backup PLC will take over, and the length of the backup PLC's execution function is determined by the repair time. The short replacement calculation does not require excessive initialization settings for the backup PLC, simplifying the operation of the PLC backup. At the same time, the on-state PLC is always used as the main operating PLC, ensuring monitoring performance and improving monitoring accuracy. The monitoring of the on-state PLC's real-time working status, fault location, type judgment, and determination of the backup PLC's working time, execution function, and related functions enable the system to respond to faults quickly and accurately. During the switching process, the calculated variable information of the on-state PLC before the fault is used to execute related functions, as well as the upload and management of variable data, ensures the consistency and integrity of the system data. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 Flowchart of Example 1 of the dual PLC redundant backup method provided by this application;

[0022] Figure 2 This is a structural diagram of the second embodiment of the dual PLC redundant backup system provided by this application. DETAILED DESCRIPTION

[0023] Exemplary embodiments are described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, identical numerals in different drawings represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with this application.

[0024] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a," "the," and "the" used in this application are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0025] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0026] Specific embodiments are given below to introduce the technical solutions of the present application in detail.

[0027] Example 1:

[0028] Figure 1 This is a flowchart of the first embodiment of the dual PLC redundant backup method provided by this application. Figure 1 The method provided in this embodiment may include:

[0029] S101 , determining backup levels of a first PLC and a second PLC, and determining a conducting PLC based on the backup levels, where the conducting PLC is any one of the first PLC and the second PLC.

[0030] The first and second PLCs use the same model, but due to different commissioning times, their service life varies, potentially leading to different degrees of performance degradation. The first and second PLCs are power-interlocked, connected in parallel to a control circuit, and physically isolated from the connections between the first and second PLCs and the control circuit. A switching control module controls the switching of the power-interlocking conduction direction.

[0031] It should be noted that the power interlock between the first and second PLCs is an electrical protection mechanism (a domestically produced controllable PLC and an imported brand PLC can be used as the first and second PLCs, respectively). Its purpose is to ensure that only one PLC is powered on at any given time, preventing problems such as signal conflicts, power overloads, or control confusion caused by powering both PLCs simultaneously. The first and second PLCs are connected to the control circuit in parallel, meaning they each have independent lines connected to the control circuit, capable of simultaneously receiving input signals from the control circuit and outputting control signals to it. This connection ensures that under normal circumstances, both PLCs have access to the control circuit. During the switching process, the input and output relationships of the control circuit remain unchanged, ensuring system continuity. Compared to a series connection, a parallel connection offers higher reliability. If one PLC fails, it will not affect the other PLC's connection to the control circuit; the other PLC can still receive and process control signals normally, thus maintaining basic system operation.

[0032] Physical isolation is used at the connection between the first and second PLCs and the control circuit. Common physical isolation methods include optocoupler isolation and transformer isolation. Optocoupler isolation uses optical signals to transmit electrical signals, electrically isolating the input and output circuits, effectively preventing the propagation of electrical interference between the PLC and control circuits. Transformer isolation uses the principle of electromagnetic induction to achieve electrical isolation while transmitting signals. The main function of physical isolation is to improve the system's anti-interference capabilities. In industrial environments, there are various sources of electromagnetic interference, such as electromagnetic radiation generated by equipment such as motors and inverters. Without physical isolation, these interference signals may enter the PLC or control circuit, causing signal distortion, malfunctions, and other problems.

[0033] The switch control module monitors the operating status of the primary and secondary PLCs and determines when and how to switch the power interlock circuit based on pre-set rules and conditions. For example, if a fault is detected in the currently active PLC, the switch control module issues a control signal to change the power interlock circuit state, enabling the standby PLC to power on.

[0034] It should be noted that determining the backup levels of the first PLC and the second PLC includes:

[0035] (1) Obtain resource information of the first PLC and the second PLC.

[0036] It should be noted that resource information includes, but is not limited to, CPU performance (such as computing speed and number of cores), memory capacity, storage capacity, and the maximum number of supported I / O points. For example, if the first PLC has a CPU computing speed of 1 GHz, 512 MB of memory, and 1 GB of storage, it can support 200 I / O points; the second PLC has a CPU computing speed of 800 MHz, 256 MB of memory, and 500 MB of storage, it can support 150 I / O points. This information can be obtained by consulting the PLC's product manual or using its configuration software.

[0037] (2) Obtaining the action control function of the control circuit.

[0038] It's important to note that the PLC, as the core component of a control system, connects directly to the control circuit. The PLC's primary function is to effectively control the control circuit. The action control function is the mathematical expression or program logic that enables the control circuit to perform various operations. Essentially, it precisely controls the on / off state of field equipment by controlling the voltage levels in the circuit. For example, in a motor control circuit, the action control function might involve logic for starting, stopping, and regulating the motor, such as adjusting the motor's speed based on sensor feedback like temperature and pressure. These functions are typically written into the PLC program by engineers based on control requirements. By dynamically adjusting the voltage levels in the control circuit, they precisely drive the motor to operate according to the predetermined operating mode, ensuring stable operation of the entire system.

[0039] (3) Calculate the function complexity based on the action control function.

[0040] It should be noted that function complexity can be measured in a variety of ways. A common method is to count the number of operators, variables, and nesting levels in an action control function. For example, a simple addition function y = a + b has a low complexity, while a function containing multiple nested loops, conditional judgments, and involving a large number of variable operations has a higher complexity. Each operator, variable, and nesting level can be assigned a certain weight, and the function complexity can be calculated by weighted summation. Suppose a function has 5 operators, 3 variables, and 2 nesting levels. After calculating the set weights, the resulting complexity value is 10 (the weights and calculation method here are only examples).

[0041] (4) Evaluate processing capabilities based on the resource information.

[0042] Processing capacity can be assessed based on the acquired PLC resource information, combined with its hardware architecture and performance metrics. For example, a PLC with fast computing speed and large memory capacity is relatively capable of processing complex functions. An evaluation standard can be established, such as scoring based on indicators such as CPU computing speed and memory capacity, to categorize processing capacity into high, medium, and low levels. For example, a PLC with a CPU computing speed of 800MHz or higher and a memory capacity of 512MB or higher would be considered high, while those below this standard would be considered medium or low.

[0043] (5) Match the function complexity with the processing capability to determine the backup level.

[0044] The calculated function complexity is matched with the assessed PLC processing capability. If the function complexity is high and the PLC processing capability is strong, the backup level may be low because the PLC has sufficient capacity to handle complex functions and requires less switching backup. Conversely, if the function is complex but the PLC processing capability is low, the backup level is high.

[0045] It should also be noted that after determining the backup level, the following steps are performed: determining a PLC to be connected based on the backup level; importing the control circuit's motion control function into the PLC; and adjusting the conduction direction of the power interlock to connect the power to the PLC. This ensures that the selected PLC correctly loads the control function and receives power, allowing for smooth control of the control circuit, maintaining normal system operation, and ensuring the effective operation of the dual PLC redundancy backup.

[0046] Compared with the prior art method of determining the master / slave level based on experience, the method provided by the present invention can comprehensively consider the complexity of function execution and the execution capability of the PLC, thereby improving the scientific nature of level determination and ensuring execution efficiency.

[0047] S102: Control the control circuit action based on the conduction PLC and monitor the real-time working status of the conduction PLC.

[0048] It should be noted that controlling the control circuit action based on the conduction PLC and monitoring the real-time working status of the conduction PLC include:

[0049] (1) The PLC is turned on to run the action control function of the control circuit.

[0050] Once a PLC is activated, it drives the control circuitry according to the pre-programmed motion control functions. For example, in an automated production line, the PLC uses motion control functions to calculate the motor speed and direction based on information such as product position and speed detected by sensors, thereby controlling the operation of the conveyor belt.

[0051] (2) The local variables calculated in each sub-function of the action control function are uploaded to the switching control module as a backup, and the temporary calculation results of the global variables of the action control function and the local variables in each sub-function are saved to the conduction PLC.

[0052] During the execution of an action control function, each sub-function generates many local variables. For example, a data processing sub-function may calculate local variables such as intermediate results and temporary counts. These calculated local variables are promptly uploaded to the switch control module as a backup. This allows the backup PLC to quickly access this critical intermediate data when a switchover is needed, reducing recalculation time and potential errors. The switch control module typically has sufficient storage capacity and data management capabilities to categorize and quickly retrieve uploaded local variables.

[0053] (3) The PLC monitors its own real-time working status and estimates the fault time based on the real-time working status.

[0054] Daotong PLCs have an internal self-test program that continuously monitors their hardware status (such as CPU temperature, memory usage, and I / O module status) and software operation status (such as whether the program is deadlocked or has experienced any abnormal interruptions). By monitoring these statuses and analyzing historical data, it is possible to estimate when a failure is likely to occur. For example, if the CPU temperature continues to rise and approaches its critical temperature over a period of time, while memory usage increases rapidly and approaches saturation, combined with historical experience with similar situations, a failure is estimated to occur within the next 10 minutes.

[0055] (4) An upload mechanism for adjusting variables based on the estimated failure time.

[0056] When the on-state PLC predicts a failure is imminent, it immediately adjusts its variable upload mechanism. Under normal circumstances, variables might be uploaded at a regular interval (e.g., every 5 seconds). However, when the predicted failure is within a few minutes, the upload frequency is significantly increased, for example, to every 1 second. This ensures that as much important variable data as possible is uploaded to the switchover control module before a failure occurs, ensuring that the standby PLC has more complete data when it takes over.

[0057] The method provided by the present invention first saves important data by reporting after each sub-function is executed. However, when the PLC is running, the time when a fault may occur is estimated by the change of the real-time running status, thereby increasing the backup frequency in advance, and then saving the variables in the process of executing the sub-function, thereby improving the data integrity in response to faults.

[0058] S103: Locate the fault status position and the fault status type based on the real-time working status.

[0059] It should be noted that locating the fault position and fault type based on the real-time working status includes:

[0060] (1) Circularly monitor the real-time working status of the PLC.

[0061] It should be noted that by turning on the PLC's self-test program or external monitoring equipment, its working status information is continuously obtained, such as hardware sensor data, software operation flags, etc. For example, the PLC's CPU usage, I / O module input and output values, and other information can be read every 1 second.

[0062] (2) If the real-time working state is a fault, the switching control module locates the fault position based on the variable data before the fault state, and the fault position at least includes the middle part of the sub-function.

[0063] If the real-time operating status is faulty, the switching control module locates the fault based on the variable data before the fault. This could be somewhere in the middle of a sub-function. For example, in a complex calculation sub-function, an error in an intermediate variable could lead to an abnormal result. By analyzing the variable data uploaded before the fault and the sub-function's execution logic, the specific calculation step within the sub-function can be determined to be the cause of the problem. Alternatively, the fault could be located at a node, such as a data transfer node between different sub-functions. If data is lost or erroneous during the transfer process, the fault can be located by examining the variable values ​​and data flow before and after the node.

[0064] If the working status is normal, the subsequent operation steps will continue to be executed according to the established program flow. The PLC continuously runs the action control function of the control circuit and uploads the local variables calculated in each sub-function of the action control function to the switching control module for backup at the specified time interval. At the same time, the PLC locally saves the temporary calculation results of the global variables of the action control function and the local variables in each sub-function. In addition, the PLC continuously monitors its own real-time working status, estimates the fault time based on the real-time working status, and dynamically adjusts the variable upload mechanism based on the estimated fault time to ensure that the system can operate stably and efficiently under any circumstances, ensuring the continuity and reliability of the lock control process.

[0065] Specifically, the fault location and fault type are located based on the real-time working status, including:

[0066] (1) Obtain historical work status data.

[0067] Obtain the working status data of the PLC over the past period of time from the PLC's storage device or external data recording system, including hardware monitoring data (such as temperature, voltage, current, etc.) and software operation logs (such as program execution steps, error information, etc.).

[0068] (2) Predicting an estimated working state of the conducting PLC within a first time range based on the historical working state data.

[0069] Based on historical operating status data, data analysis algorithms (such as time series analysis and machine learning algorithms) are used to predict the estimated operating status of the PLC within the first timeframe. For example, by analyzing past CPU temperature data, a linear regression algorithm is used to predict the CPU temperature trend within the next hour. By analyzing program execution logs, a machine learning classification algorithm is used to predict the likelihood of a software failure.

[0070] (3) Based on the estimated working state, predict the fault state switching process of the conductive PLC.

[0071] Based on the estimated operating state, combined with the PLC's hardware architecture and software operating mechanisms, the PLC's fault state transition process can be predicted. For example, if the CPU temperature is predicted to rise sharply and exceed a critical value, the possible fault state transition processes, such as CPU overheat protection triggering and program interruption, can be inferred, as well as the likely sequence and time interval of these processes.

[0072] (4) Obtain the latest real-time working status of the PLC.

[0073] The latest real-time working status of the PLC can be obtained through high-speed data transmission with the PLC's communication interface (such as Ethernet, serial port, etc.).

[0074] (5) Based on the latest real-time working status, the prediction result of the fault state switching process is corrected.

[0075] After obtaining the latest real-time operating status, compare and analyze it with the previous prediction results. If the actual CPU temperature rises faster than predicted, or the memory usage growth trend does not match the prediction, then the prediction results of the fault state switching process need to be corrected promptly. For example, the original prediction of CPU overheat protection is that it will activate in 30 minutes, but the latest data shows that the CPU temperature is approaching the critical value and may trigger the protection mechanism within 10 minutes. At this time, it is necessary to urgently adjust the prediction results and take appropriate emergency measures, such as preparing the switch of the backup PLC in advance or notifying maintenance personnel to conduct an on-site inspection.

[0076] (6) Predict the fault location based on the corrected prediction results.

[0077] The fault location is predicted based on the corrected prediction results. If a hardware module is predicted to fail due to overheating, the fault location can be determined to be in that hardware module; if a program error is predicted to occur in a specific calculation link, the fault location is in the corresponding software code section.

[0078] (7) Adjust the data backup mechanism based on the predicted fault location.

[0079] The data backup mechanism is adjusted based on the relationship between the predicted fault location and the function's end point, as well as the possible fault type. If the predicted fault location is close to the function's end point and there's a risk of data loss, the data backup frequency is increased to ensure that important data can be quickly stored in the switching control module. If the predicted fault location is far from the function's end point and the impact on data integrity is minimal, the backup frequency can be appropriately reduced to conserve system resources, improve overall system efficiency, ensure the rationality and effectiveness of data backup under different fault risk scenarios, and guarantee stable system operation. Specifically, if the fault location is close to the function's end point, it means there may be only a few remaining computational steps. If data loss occurs in this situation, the entire control process may not be fully completed or may produce erroneous results. Therefore, the data backup frequency needs to be increased to ensure data security. On the other hand, if the fault location is far from the function's end point, many computational and control steps have already been completed before the fault occurs, leaving more room for subsequent adjustments and recovery. Appropriately reducing the backup frequency will not significantly impact overall system operation. This avoids excessive system resource usage due to excessive backups, helping to improve system efficiency and resource utilization.

[0080] (3) The switching control module determines the faulty component according to the fault location and the real-time working status at the time of the fault, and determines the fault status type based on the faulty component.

[0081] The switch control module identifies the faulty component based on the located fault location and the real-time operating status at the time of the fault. If a CPU operation error occurs, the faulty component is the CPU; if an I / O module's input or output is abnormal, the faulty component is the corresponding I / O module. The faulty component is then used to further determine the fault type, such as hardware failure (e.g., chip damage, circuit short circuit) or software failure (e.g., program vulnerability, memory overflow).

[0082] S104: Determine the operating duration of a standby PLC based on the fault state type, where the standby PLC is the PLC other than the conducting PLC among the first PLC and the second PLC.

[0083] Different fault status types require different repair times. To maximize the use of the PLC to run action control functions, it is necessary to estimate the repair time of the PLC. Then, within this time range, select execution functions and associated functions that are longer than this time to ensure that the PLC can complete the repair.

[0084] It should be noted that determining the operating time of the standby PLC based on the fault state type includes:

[0085] (1) Determine the fault repair time based on the fault status type.

[0086] Estimate the repair time based on the fault type. Specifically, for a hardware fault involving a common I / O module failure and a spare module available on-site, replacement and debugging might take 30 minutes. A CPU failure requiring a new CPU from the manufacturer might take several days. For software faults, simple program logic errors might be fixed within an hour through remote debugging. Complex system vulnerabilities might require the development team to resolve over several weeks. These repair time estimates can be based on previous repair experience and information provided by the equipment supplier.

[0087] (2) Determine the function execution range based on the fault state location and fault repair time.

[0088] For example, if a fault condition occurs in the middle of a control flow and the fault recovery time is long, the standby PLC may need to start executing functions at a key node before the fault condition to ensure continuity of the entire control process. The function execution range is defined as the function statement that begins before the fault condition and lasts until the fault recovery time is reached.

[0089] (3) Adjusting the function execution scope based on the function completeness within the function execution scope.

[0090] To ensure the integrity of function execution, avoid passing intermediate variables to other PLCs for interrupted calculations, simplify the backup switching process, and ensure calculation accuracy, after determining the function execution scope, it is necessary to calculate the function's completeness. This completeness refers to whether the sub-function has been executed and all calculations have been completed. If the completeness is insufficient, the function execution scope is expanded to ensure the complete execution of the sub-function.

[0091] If there are parts of the function within the specified execution scope that depend on the faulty component or may be affected by the fault, the execution scope needs to be further adjusted to exclude these parts that may cause problems. For example, in a data processing function, if the faulty component affects the collection and preprocessing of some data, the backup PLC needs to adjust the function execution scope to skip the affected data processing steps and directly start processing the reliable data.

[0092] (4) Calculate the function execution time based on the adjusted function execution range.

[0093] Calculate the function execution time based on the adjusted function execution scope and the standby PLC's performance. For example, the standby PLC needs to traverse a certain number of data points and perform calculations to execute the adjusted function. Based on its CPU speed and data processing capacity, the execution time is calculated to be 20 minutes.

[0094] It's also important to note that when calculating the total execution time of a function, it's important to distinguish between parallel statements and serial statements. The maximum value of the parallel statement execution time should be used, as they execute simultaneously; the serial statement execution time, on the other hand, is summed up. For example, for a function containing both parallel and serial parts, first calculate the execution time of each statement in the parallel part, taking the maximum value as the parallel part execution time. Then, sum the serial part execution times one by one. Finally, add the sum of the parallel and serial times to obtain the total execution time of the function.

[0095] (5) The maximum value of the function execution time and the fault repair time is the working time.

[0096] Assuming the function execution time is 20 minutes and the fault repair time is 30 minutes, the standby PLC's operating time is set to 30 minutes. This ensures stable operation of the standby PLC during the fault repair period, preventing problems that may occur before the repair is complete due to extended execution times, and also avoids repeated switching.

[0097] S105 . Calculate an execution function of the standby PLC based on the working duration and the fault state location, where the execution function is a partial process for controlling the operation of the control circuit.

[0098] It should be noted that the execution function of the standby PLC is calculated based on the working time and the fault state location, including:

[0099] (1) Locate the fault sub-function in the execution function according to the fault status position.

[0100] It's important to note that a control circuit's motion control function typically consists of multiple sub-functions that collaborate to complete specific control tasks. Specifically, the fault's location within the entire control program is used to locate the sub-function containing the fault. For example, if a fault occurs in the control logic of a device within a control system program, analyzing the program structure and fault information can pinpoint the specific sub-function causing the problem, such as the motor speed control sub-function or the valve control sub-function.

[0101] (2) Calculate the execution time of the fault sub-function.

[0102] To calculate the execution time of a faulty subroutine, it's necessary to comprehensively consider the subroutine's internal code structure, the complexity of the operations involved, and the performance parameters of the backup PLC. Regarding the code structure, factors such as the loop structure, the number of conditional statements, and the level of nesting are analyzed. For example, a subroutine containing multiple layers of nested loops typically takes longer to execute than simple sequential code. Furthermore, considering the complexity of the operations, subroutine operations involving complex mathematical calculations such as large floating-point operations and matrix operations will also consume more execution time. Based on the CPU speed of the backup PLC and combining these factors, an estimate is made. Assuming the backup PLC's CPU speed is 1 GHz, and the faulty subroutine contains a simple addition operation executed 100 times in a loop and a multiplication operation nested in two layers of loops, by estimating and accumulating the clock cycles required for each operation step, the execution time of the faulty subroutine on the backup PLC is calculated to be approximately 15 minutes.

[0103] (3) Locating the execution segment of the fault sub-function based on the difference between the execution duration and the working duration, where the execution duration of the execution segment is less than the execution duration of the fault sub-function.

[0104] After determining the execution time of the fault subfunction and the operating time of the backup PLC, calculate the difference between the two. Assuming the operating time of the backup PLC is 30 minutes and the operating time of the fault subfunction is 15 minutes, the difference is 15 minutes. Based on this difference, select an appropriate execution segment within the fault subfunction. If the fault subfunction consists of multiple steps executed sequentially, and the earlier steps are more critical to the system's emergency control and stability, then the first half (with an execution time of approximately 7.5 minutes) can be selected as the execution segment. The purpose of this selection is to ensure that the backup PLC can execute the most critical control operations within the limited operating time, maintaining basic system operation, while avoiding executing subsequent steps that may cause problems. When selecting an execution segment, it is also necessary to consider the data dependencies and logical integrity within the subfunction to ensure that the selected segment can still function normally and produce meaningful control output when executed separately from the original fault subfunction.

[0105] Generally speaking, since functions are usually executed sequentially, their execution order cannot be skipped at will. Therefore, when determining the execution segment, it is necessary to strictly follow the order of duration. In the process of execution in order of duration, it is necessary to clearly define the execution cutoff position. The determination of this position should be based on the working time of the standby PLC and the logical structure and time distribution within the sub-function. For example, for a sub-function with a long execution time, it can be divided into multiple logical units, each of which has relatively independent functions and required execution time. According to the working time of the standby PLC and the execution time of each logical unit, the execution cutoff position is accurately determined to ensure that the part before the cutoff position can be fully and effectively executed to achieve the expected control function.

[0106] At the same time, the data upload also needs to be determined. During the execution of the execution segment, it is necessary to clarify at which key nodes to upload data and what data to upload. The timing and content of data upload are crucial for system monitoring, fault analysis, and subsequent system recovery. According to the logical key points and data processing flow within the sub-function, data upload operations can be performed after the important steps of the execution segment are completed. For example, after completing a key calculation or data processing step, the current intermediate results or status information are uploaded to the switching control module or other storage location for subsequent fault diagnosis and system recovery. This can not only ensure that key operations are completed within a limited working time, but also provide sufficient data support for subsequent system maintenance and fault handling, thereby ensuring the reliability and stability of the system.

[0107] (4) Using the execution fragment as the execution function of the standby PLC.

[0108] It should be noted that using the execution fragment as the execution function of the standby PLC buys time for subsequent fault repair and system recovery. At the same time, when using the execution fragment as an execution function, it is also necessary to perform some necessary packaging and interface processing on it so that it can be smoothly integrated with the operating environment and other related functions of the standby PLC to ensure the consistency and stability of the entire control process.

[0109] S106: Analyze the variable content of the execution function, and determine the associated function based on the variable content.

[0110] It should be noted that analyzing the variable content of the execution function and determining the associated function based on the variable content includes:

[0111] (1) Calculating a first working duration of an execution function of the standby PLC.

[0112] Analyze the code structure and computational complexity of the backup PLC's execution function, taking into account factors such as the number of loops involved, the number and complexity of conditional judgments, and the amount of data processed. For example, the execution function includes a simple data comparison operation that loops 50 times and a weighted summation calculation of 10 data points. Combined with the backup PLC's performance indicators, such as CPU speed and memory read / write speed, estimate the initial operating time of the execution function. Assuming the backup PLC's CPU speed is 800MHz, by calculating and accumulating the clock cycles required for each operation, the execution function's initial operating time is approximately 8 minutes.

[0113] (2) Calculating a second working time based on a difference between the working time and the first working time.

[0114] Given the total operating time of the standby PLC (assuming it's 30 minutes), subtract the first operating time from the total operating time to obtain the second operating time. In the above example, the second operating time is 30 - 8 = 22 minutes. This difference represents the time remaining for the associated function to execute after the primary function completes, providing a basis for determining the appropriate time limit for the associated function.

[0115] (3) Determine the input variables and intermediate call functions of the execution function of the standby PLC.

[0116] Study the code logic of the execution function and identify all input variables. These variables may come from sensor data, outputs from other control modules, or system parameters. For example, in the execution function of a temperature control system, the input variables may include the current value collected by the temperature sensor, the set target temperature value, etc. At the same time, identify the intermediate call functions called by the execution function during execution. These functions may be functional modules used for data processing, algorithm calculations, or interaction with other system modules. For example, the execution function may call a data filtering function to process the data collected by the temperature sensor. This data filtering function is an intermediate call function.

[0117] (4) Determine a first correlation function based on the input variable, and determine a second correlation function based on the intermediate call function.

[0118] For each input variable, analyze its source and subsequent processing, and identify other related functions as the first associated function. For example, if the input variable is data collected by a sensor, there may be a function to calibrate and initialize the sensor, as well as a function to convert the sensor data into appropriate units. These functions are all first associated functions. For intermediate calling functions, identify other functions on which it depends as second associated functions. For example, a data filtering function may rely on a specific math library function to implement the filtering algorithm. This math library function is the second associated function.

[0119] (5) Taking the set of the first correlation function and the second correlation function as the initial correlation function, respectively calculating the third working time and the fourth working time of the first correlation function and the second correlation function.

[0120] These first and second correlation functions are combined to form an initial correlation function. For each first and second correlation function, the execution time is estimated based on the code structure, computational complexity, and the performance indicators of the backup PLC, similar to the method used to calculate the execution time of the execution function. These execution times are recorded as the third and fourth working times, respectively. For example, a first correlation function containing a simple linear transformation calculation and a small amount of data storage operations has an estimated third working time of approximately 3 minutes; a second correlation function involving complex matrix operations and multiple function calls has an estimated fourth working time of approximately 10 minutes.

[0121] (6) Adjusting the initial correlation function based on the difference between the sum of the third working time and the fourth working time and the second working time to obtain a final correlation function.

[0122] Calculate the sum of the third working time and the fourth working time, and compare it with the second working time. If the sum is less than the second working time, it means that there is still time left. You can consider adding some associated functions related to system stability or data integrity to make full use of the working time of the standby PLC and improve the reliability of the system. For example, you can add a data backup function to regularly back up critical data to redundant storage devices. If the sum is greater than the second working time, some associated functions need to be deleted to avoid the standby PLC from being unable to complete all tasks within the working time due to excessive execution time. After such an adjustment process, the appropriate set of associated functions is finally determined to ensure that within the working time of the standby PLC, both the key operations of the execution function can be completed and the related auxiliary functions can be taken into account.

[0123] S107 , obtaining the execution function and the correlation function from the switching control module, executing the execution function and the correlation function based on the calculated variable information before the PLC fault is turned on, and controlling the operation of the control circuit.

[0124] When a switchover is required to the standby PLC, it quickly retrieves the pre-determined execution functions and associated functions from the switchover control module. The switchover control module plays a key role in data storage and coordination, ensuring that the standby PLC can accurately obtain the required information.

[0125] It should be noted that, the execution function and the associated function are executed based on the calculated variable information before the PLC fault is turned on, and the control circuit action is controlled, and then the following steps are included:

[0126] (1) Monitor the real-time execution progress of the standby PLC.

[0127] The progress of the standby PLC executing the function and related functions can be tracked in real time by setting an execution progress flag in the standby PLC or utilizing an external monitoring device. For example, a counter can be updated after a key step in the function is completed, and the external monitoring device can periodically read the value of this counter to understand the execution progress.

[0128] (2) Determine the execution stop time of the standby PLC based on the relationship between the real-time execution progress and the working time and the execution completion status of the execution function and the associated function.

[0129] If the execution progress is close to the working duration and the execution function and associated functions are largely completed, the execution stop time can be determined to be imminent. If the execution progress is slow but the execution function and associated functions have completed key parts, the stop time can also be determined in advance based on the situation. For example, if the execution progress of the standby PLC reaches 90% and the core functions of the execution function and associated functions are completed, the execution stop time can be determined to be within the next few minutes to facilitate subsequent switchover and data processing operations.

[0130] (3) Based on the relationship between the execution stop time and the working duration, adjusting the contents of the execution function and the associated function, wherein the adjustment includes increasing or decreasing the execution function or the associated function.

[0131] Adjust the content of execution functions and associated functions based on the relationship between the execution stop time and the work duration. If the execution stop time is early, you may need to reduce some non-critical operations or data processing steps to ensure that critical tasks are completed before the stop time. If the execution stop time is delayed and there is sufficient time, you can add some auxiliary functions or data verification operations. For example, if the execution progress is too fast and there is still a long time before the work duration, you can add some associated functions for data integrity checks to improve system reliability.

[0132] (4) After the standby PLC completes the control of the working duration, the execution variable data of the standby PLC is uploaded to the switching control module.

[0133] After the standby PLC completes the control of the working time, it uploads its execution variable data to the switching control module. This data can be used for subsequent system analysis, troubleshooting, or as reference data for the next switching.

[0134] (5) Switching the power supply paths of the conducting PLC and the backup PLC based on the fault status of the conducting PLC.

[0135] When it is determined that the on-state PLC has failed and the standby PLC has completed the control of its working time, the power interlock device is controlled by the switching control module to cut off the power supply of the failed on-state PLC and provide a stable power supply to the standby PLC to ensure that the system can continue to operate stably.

[0136] It should also be noted that the first PLC and the second PLC are respectively connected to the host computer, which is used to store the fully automatic and semi-automatic operation status words of the lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status words from the host computer to ensure that the fully automatic and semi-automatic operation processes of the lock are not interrupted.

[0137] The method provided in this embodiment rationally selects the active PLC by determining the backup levels of the first and second PLCs, enabling the system to adapt to different control requirements and PLC performance, reducing the probability of system failures caused by PLC problems and ensuring reliable control device operation under various working conditions. By setting up power interlocking, parallel connection, and physical isolation, it effectively prevents power conflicts, signal interference, and other problems, ensuring system stability during operation and switching, reducing failures caused by electrical problems, and improving the overall system's anti-interference capability. Comprehensive monitoring of the active PLC's real-time working status and fault location and type determination based on this monitoring can quickly and accurately identify the root cause of the problem, providing a key basis for subsequent response measures, significantly shortening troubleshooting time, improving maintenance efficiency, and reducing downtime. The operating time of the standby PLC is determined based on the fault status type, and the execution function and associated functions of the standby PLC are accurately calculated, ensuring that the standby PLC can perform key tasks in a targeted manner when taking over, maintaining basic system functions within a limited time, avoiding complete system paralysis due to faults, and achieving rapid fault recovery and system switching. Timely upload of local variables in the action control function to the switching control module and temporary storage of global and local variables in the PLC can ensure the continuity of the control process when the PLC switches, avoid errors caused by data loss and recalculation, and ensure the accuracy and stability of system operation. In addition, the effective management and utilization of variable data throughout the process, as well as the dynamic adjustment of execution functions and associated functions based on fault conditions, further enhance the security of data and the reliability of system operation, so that the system can adapt to complex and changing operating environments and fault conditions.

[0138] Corresponding to the aforementioned embodiment of a dual PLC redundant backup method, the present application also provides an embodiment of a dual PLC redundant backup system.

[0139] Example 2:

[0140] Figure 2 This is a schematic diagram of the structure of the second embodiment of the dual PLC redundant backup system provided by this application. Figure 2 The system provided in this embodiment includes a first PLC and a second PLC. The first PLC and the second PLC adopt a 1:1 complete replication architecture. The two PLCs have exactly the same functions and serve as backup for each other.

[0141] A host computer, wherein the first PLC and the second PLC are respectively connected to the host computer, and the host computer is used to store the fully automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the host computer to ensure that the fully automatic and semi-automatic operation processes of the ship lock are not interrupted;

[0142] A field device is connected to the first PLC and the second PLC. The PLC currently in operation performs logical operations and processing based on the action control function of the control circuit and the input signal received from the field device to generate control instructions to control the operation of the field device.

[0143] It should be noted that the IO signals of all sensors, actuators, and other on-site systems are physically isolated and connected to the primary and secondary PLCs, respectively. The power supplies of the primary and secondary PLCs are interlocked to ensure that only one PLC is powered on at any given time, preventing damage to both the primary and backup systems from extreme operating conditions such as lightning strikes (locks are located near rivers and streams, which are high-risk areas for lightning strikes) and external power intrusion.

[0144] The system of this embodiment can be used to perform Figure 1 The steps, specific implementation principles and implementation processes of the method embodiment shown are similar and will not be repeated here.

[0145] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A dual PLC redundant backup method, characterized in that: The method comprises: Determine the backup levels of the first PLC and the second PLC, and determine a conducting PLC based on the backup levels, where the conducting PLC is any one of the first PLC and the second PLC; The first PLC and the second PLC are interlocked in power supply, the first PLC and the second PLC are connected in parallel to a control circuit, the connection points between the first PLC and the second PLC and the control circuit are physically isolated, and a switching control module controls the switching of the conduction direction of the power interlock; Controlling the control circuit action based on the conduction PLC and monitoring the real-time working status of the conduction PLC; Locating the fault state position and the fault state type based on the real-time working state; Determine the working time of a standby PLC based on the fault state type, where the standby PLC is the PLC other than the conducting PLC among the first PLC and the second PLC; Calculating an execution function of the standby PLC based on the working duration and the fault state location, wherein the execution function is a partial process for controlling the operation of the control circuit; Analyzing variable contents of the execution function and determining an associated function based on the variable contents; The method further comprises: obtaining the execution function and the correlation function from the switching control module, executing the execution function and the correlation function based on the calculated variable information before the PLC fault is turned on, and controlling the operation of the control circuit; and analyzing the variable content of the execution function and determining the correlation function based on the variable content, including: Calculating a first working duration of an execution function of the standby PLC; Calculating a second working time based on a difference between the working time and the first working time; Determining input variables and intermediate call functions of the execution function of the standby PLC; determining a first correlation function based on the input variable, and determining a second correlation function based on the intermediate call function; Taking the set of the first correlation function and the second correlation function as an initial correlation function, respectively calculating a third working time and a fourth working time executed by the first correlation function and the second correlation function; Adjusting the initial correlation function based on the difference between the sum of the third working duration and the fourth working duration and the second working duration to obtain a final correlation function; Among them, the sum of the third working time and the fourth working time is calculated and compared with the second working time. If the sum is less than the second working time, the correlation function related to system stability or data integrity is added; if the sum is greater than the second working time, the correlation function is deleted.

2. The method according to claim 1, characterized in that Determining the backup levels of the first PLC and the second PLC includes: Obtain resource information of the first PLC and the second PLC; Acquiring an action control function of the control circuit; Calculating function complexity according to the action control function; evaluating processing capabilities based on the resource information; The function complexity is matched with the processing capability to determine the backup level.

3. The method according to claim 1, characterized in that The controlling the control circuit action based on the conducting PLC and monitoring the real-time working state of the conducting PLC include: The conducting PLC runs the action control function of the control circuit; Uploading the local variables calculated in each sub-function of the action control function to the switching control module as a backup, and saving the temporary calculation results of the global variables of the action control function and the local variables in each sub-function to the conduction PLC; The PLC monitors its own real-time working status and estimates the fault time based on the real-time working status; An upload mechanism for adjusting variables based on the estimated failure time.

4. The method according to claim 1, wherein The locating the fault state position and the fault state type based on the real-time working state includes: Circularly monitoring the real-time working status of the conduction PLC; If the real-time working state is a fault, the switching control module locates the fault position based on the variable data before the fault state, and the fault position at least includes the middle part of the sub-function; The switching control module determines a faulty component according to the fault location and the real-time working status at the time of the fault, and determines a fault status type based on the faulty component.

5. The method according to claim 1, wherein The determining the operating time of the standby PLC based on the fault state type includes: Determining a fault repair time based on the fault status type; Determine the function execution scope according to the fault state location and fault repair time; Adjusting the function execution scope based on the function completeness within the function execution scope; Calculate the function execution time based on the adjusted function execution scope; The maximum value of the function execution time and the fault repair time is the working time.

6. The method according to claim 1, characterized in that The calculating of the execution function of the standby PLC based on the working time and the fault state location includes: Locate the fault sub-function in the execution function according to the fault status position; Calculate the execution time of the fault sub-function; Locating an execution segment of the faulty sub-function based on a difference between the execution duration and the working duration, wherein the execution duration of the execution segment is less than the execution duration of the faulty sub-function; The execution segment is used as the execution function of the standby PLC.

7. The method according to claim 1, characterized in that The method further comprises: executing the execution function and the correlation function based on the calculated variable information before the PLC fault is turned on, and controlling the control circuit action; and then comprising: monitoring the real-time execution progress of the standby PLC; Determining an execution stop time of the standby PLC based on a relationship between the real-time execution progress and the working duration and the execution completion status of the execution function and the associated functions; Adjusting the contents of the execution function and the associated function based on the relationship between the execution stop time and the working duration, wherein the adjustment includes adding or reducing the execution function or the associated function; After the standby PLC completes the control of the working duration, uploading the execution variable data of the standby PLC to the switching control module; The power supply paths of the conducting PLC and the backup PLC are switched based on the fault status of the conducting PLC.

8. The method according to claim 1, characterized in that The locating the fault state position and the fault state type based on the real-time working state includes: Obtain historical work status data; Predicting an estimated working state of the on-state PLC within a first time range based on the historical working state data; Based on the estimated working state, predicting the fault state switching process of the conductive PLC; Obtain the latest real-time working status of the PLC; Based on the latest real-time working status, correct the prediction result of the fault state switching process; Predicting the fault location based on the corrected prediction results; Adjust data backup mechanisms based on predicted failure locations.

9. A dual PLC redundant backup system, characterized in that: The system is applied to the dual PLC redundant backup method according to any one of claims 1 to 8, wherein the system includes a first PLC and a second PLC, wherein the first PLC and the second PLC adopt a 1:1 complete replication architecture, have identical functions, and serve as backup for each other; A host computer, wherein the first PLC and the second PLC are respectively connected to the host computer, and the host computer is used to store the fully automatic and semi-automatic operation status words of the ship lock. When the first PLC switches to the second PLC, the second PLC reads the current operation status word from the host computer to ensure that the fully automatic and semi-automatic operation processes of the ship lock are not interrupted; A field device is connected to the first PLC and the second PLC. The PLC currently in operation performs logical operations and processing based on the action control function of the control circuit and the input signal received from the field device to generate control instructions to control the operation of the field device.

Citation Information

Patent Citations

  • Safety redundant PLC communication control system

    CN119065228A