Dual line routing device and method for bringing field devices into a safe state

CN120731405BActive Publication Date: 2026-08-21FISHER ROSEMOUNT SYST INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202480011141.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2023-02-07
Filing Date
2024-02-02
Publication Date
2026-08-21
Estimated Expiration
2044-02-02

AI Technical Summary

Benefits of technology

[0006]The method may further include: the router electronic controller of the two-line routing device determining a field device identifier based on a security status command to identify the field device indicated by the field device identifier; and the transmission of the security status command by the router electronic controller via a two-line communication and power interface may include: converting the security status command from a first protocol to a two-line digital protocol, and driving the two-line communication and power interface according to the two-line digital protocol to transmit the security status command to the field device. The security status command received by the two-line routing device may be packetized communication of the first protocol, the packetized communication including the security status command as one or more data payload packets and a packet header containing an address as the field device identifier. The dual-line routing device can be a modular dual-line routing device installed in a multi-module backplane, and the method may further include: receiving a corresponding field device characterization module by each module bracket in a plurality of module bays of the multi-module backplane; routing messages between the controller and each field device characterization module received in the plurality of module bays by a backplane microcontroller communicatively coupled to the controller and each field device characterization module received in the plurality of module bays; transmitting communication between the backplane microcontroller and each field device characterization module received in the plurality of module bays by a communication bus coupled to the backplane microcontroller and each module bay; and supplying power to each field device characterization module received in the plurality of module bays by a power supply, wherein the modular dual-line routing device may be a first field device characterization module of the field device characterization module, which is installed in a first module bay in the plurality of module bays, communicatively coupled to the backplane microcontroller, and powered by the power supply. The upstream communication interface of the dual-line routing device may be coupled to the backplane microcontroller via a communication bus to enable communication with the backplane microcontroller, and security status commands received by the dual-line routing device from the controller may be received via the backplane microcontroller via the communication bus. The determination of a secondary power-off scheme by the dual-wire routing device can be in response to receiving a command from the controller to initiate a secondary power-off scheme, addressed to the dual-wire routing device. The determination of a secondary power-off scheme by the dual-wire routing device can also be in response to determining that a watchdog timer has expired. The field device can be the first field device among a plurality of field devices coupled to the dual-wire routing device, and the execution of the secondary power-off scheme in response to determining that the watchdog timer has expired can further include cutting off power to each output field device (including the first field device) among the plurality of field devices, while allowing power to continue flowing to each non-output field device among the plurality of field devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120731405B_ABST
    Figure CN120731405B_ABST
Patent Text Reader

Abstract

A two-wire routing device (102, 122, 124) includes an upstream communication interface for communicating with a controller (112), a two-wire communication and power interface configured to communicate communications and power to a field device (116) over a two-wire link, and a router electronic controller. The router electronic controller is coupled to the upstream communication interface and the two-wire communication and power interface. The router electronic controller receives a safety state command from the controller via the upstream communication interface and transmits the safety state command to the field device over the two-wire link via the two-wire communication and power interface. The router electronic controller also executes a secondary power down scheme for the field device to control a power switch to shut off power to the field device over the two-wire link.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to the control of safety field devices in a safety instrumented system (SIS) or distributed control system (DCS) using digital communication protocols, and more specifically, to the de-energization of safety field devices using digital communication protocols. Background Technology

[0002] A typical field device control system may interface with hundreds to thousands of field devices, such as transmitters, thermocouples, and switches that provide indications of various process parameters; solenoid valves and digital valve controllers that control valve operation; lights or other indicators that provide field indications of process status; and other types of process inputs and outputs. These field devices may be distributed over a very large physical area, and most devices communicate with the control system via wires that form separate circuits between the control system and each field device (such as a pair of wires carrying analog signals via current flowing through the circuit, an open or closed circuit indicating the status of process parameters, or putting a process control device in a specific state). In a typical control system, the wires connecting hundreds or thousands of field devices to the control system are routed through a series of field cabling, junction boxes, and trunk cables to various assembly points (e.g., assembly cabinets) where the wires coupled to the individual field devices are "marshalled" so that they can be connected to the control system's I / O interfaces. Summary of the Invention

[0003] A two-wire routing device includes: an upstream communication interface for communicating with a controller; a two-wire communication and power interface configured to deliver communication and power to field devices via a two-wire link; and a router electronic controller. The router electronic controller is coupled to the upstream communication interface and the two-wire communication and power interface. The router electronic controller is configured to: receive a security status command from the controller via the upstream communication interface, the security status command including a field device identifier; transmit the security status command as a digital signal via the two-wire communication and power interface to the field device indicated by the field device identifier via the two-wire link; and after transmitting the security status command to the field device, execute a secondary power-off scheme for the field device to control a power switch to cut off power to the field device via the two-wire link.

[0004] The router electronic controller may include a network switch configured to determine a field device identifier based on a security status command to identify the field device indicated by the field device identifier. To enable the router electronic controller to transmit the security status command via a two-wire communication and power interface, the network switch may also be configured to convert the security status command from a first protocol to a two-wire digital protocol and drive the two-wire communication and power interface according to the two-wire digital protocol to deliver the security status command to the field device. The security status command received from the upstream communication interface may be received by the router electronic controller as packetized communication of the first protocol, the packetized communication including the security status command as one or more data payload packets and a packet header containing an address as the field device identifier. A dual-line routing device can be a modular dual-line routing device mounted in a multi-module backplane, wherein the multi-module backplane includes: multiple module bays, each module bay configured to receive a corresponding field device characterization module; a backplane microcontroller communicatively coupled to a controller and each field device characterization module received in the multiple module bays, and configured to route messages between the controller and each field device characterization module received in the multiple module bays; a communication bus coupled to the backplane microcontroller and each module bay to enable communication between the backplane microcontroller and each field device characterization module received in the multiple module bays; and a power supply configured to supply power to each field device characterization module received in the multiple module bays. The modular dual-line routing device can be a field device characterization module mounted in a first module bay of the multiple module bays, communicatively coupled to the backplane microcontroller, and powered by the power supply. An upstream communication interface can be coupled to the backplane microcontroller via the communication bus to enable communication with the backplane microcontroller, and security status commands received by the router electronic controller from the controller can be received via the communication bus through the backplane microcontroller. The router electronic controller can also be configured to: in response to receiving a command from the controller to initiate a secondary power-off scheme, determine to execute the secondary power-off scheme, the command being addressed to the dual-line routing device. The router electronic controller can also be configured to: in response to determining that a watchdog timer has expired, determine to execute the secondary power-off scheme. The field device can be the first field device among a plurality of field devices coupled to the dual-line routing device, wherein, in order to execute the secondary power-off scheme in response to determining that the watchdog timer has expired, the router electronic controller can be configured to: disconnect power to each output field device (including the first field device) among the plurality of field devices, while allowing power to continue flowing to each non-output field device among the plurality of field devices.The field device may be the first of a plurality of field devices coupled to a two-wire routing device. Each of the field devices is coupled to a two-wire communication and power interface via a corresponding two-wire link and a corresponding power switch along that two-wire link. The router electronic controller may also be configured to selectively control each corresponding power switch to selectively enable and disable power to the plurality of field devices. The device may also include a housing housing the router electronic controller and the power switches. The device may further include a housing housing the router electronic controller, with the power switches located outside the housing. The two-wire link may include a pair of twisted conductors extending through a shielded conduit.

[0005] A method for putting a field device into a safe state. The method includes: receiving a safe state command from a controller via an upstream communication interface by a two-wire routing device. The safe state command includes a field device identifier. The method further includes: transmitting the safe state command as a digital signal via a two-wire communication and power interface by the two-wire routing device to the field device indicated by the field device identifier via a two-wire link, which also provides power to the field device. The method further includes: after transmitting the safe state command to the field device, executing a secondary power-off scheme for the field device by the two-wire routing device. The secondary power-off scheme includes: controlling a power switch by the two-wire routing device to cut off power to the field device via the two-wire link.

[0006] The method may further include: the router electronic controller of the two-line routing device determining a field device identifier based on a security status command to identify the field device indicated by the field device identifier; and the transmission of the security status command by the router electronic controller via a two-line communication and power interface may include: converting the security status command from a first protocol to a two-line digital protocol, and driving the two-line communication and power interface according to the two-line digital protocol to transmit the security status command to the field device. The security status command received by the two-line routing device may be packetized communication of the first protocol, the packetized communication including the security status command as one or more data payload packets and a packet header containing an address as the field device identifier. The dual-line routing device can be a modular dual-line routing device installed in a multi-module backplane, and the method may further include: receiving a corresponding field device characterization module by each module bracket in a plurality of module bays of the multi-module backplane; routing messages between the controller and each field device characterization module received in the plurality of module bays by a backplane microcontroller communicatively coupled to the controller and each field device characterization module received in the plurality of module bays; transmitting communication between the backplane microcontroller and each field device characterization module received in the plurality of module bays by a communication bus coupled to the backplane microcontroller and each module bay; and supplying power to each field device characterization module received in the plurality of module bays by a power supply, wherein the modular dual-line routing device may be a first field device characterization module of the field device characterization module, which is installed in a first module bay in the plurality of module bays, communicatively coupled to the backplane microcontroller, and powered by the power supply. The upstream communication interface of the dual-line routing device may be coupled to the backplane microcontroller via a communication bus to enable communication with the backplane microcontroller, and security status commands received by the dual-line routing device from the controller may be received via the backplane microcontroller via the communication bus. The determination of a secondary power-off scheme by the dual-wire routing device can be in response to receiving a command from the controller to initiate a secondary power-off scheme, addressed to the dual-wire routing device. The determination of a secondary power-off scheme by the dual-wire routing device can also be in response to determining that a watchdog timer has expired. The field device can be the first field device among a plurality of field devices coupled to the dual-wire routing device, and the execution of the secondary power-off scheme in response to determining that the watchdog timer has expired can further include cutting off power to each output field device (including the first field device) among the plurality of field devices, while allowing power to continue flowing to each non-output field device among the plurality of field devices. Attached Figure Description

[0007] Figure 1 This is a diagram illustrating the various components of a control system according to one aspect of this disclosure.

[0008] Figure 2 It is based on one aspect of this disclosure. Figure 1A diagram of the high-level physical layer (APL) routing devices of the control system.

[0009] Figure 3 It is based on one aspect of this disclosure. Figure 2 A diagram of the router's electronic controller for APL routing devices.

[0010] Figure 4 It is based on one aspect of this disclosure. Figure 2 A diagram of the APL interface of the APL routing device.

[0011] Figure 5 It is a diagram of the field equipment according to one aspect of this disclosure.

[0012] Figure 6 This is a diagram of the backplane of an APL routing device according to one aspect of this disclosure.

[0013] Figure 7 This is a flowchart illustrating a process for de-energizing field equipment according to one aspect of this disclosure. Detailed Implementation

[0014] Field device control systems, such as safety instrumented systems (SIS) or distributed control systems (DCS), can control one or more processes in an industrial plant. Such control systems can periodically determine the presence of an accident or safety condition in the system and bring one or more field devices to a safe state. Many analog systems include methods for de-energizing field devices to ensure the process enters a safe state. For example, a control system may include an analog communication link in the form of analog control signals (e.g., between 4 and 20 mA) to control each corresponding field device. The field device will control its components (e.g., valve position) based on the current intensity of the analog control signal. When the analog control signal is disconnected, the field device may simultaneously have a controllable safe state and a default safe state. The controllable safe state may be caused, for example, by a 4 mA signal at an input of the field device, which controls the controllable component of the field device (e.g., a valve) to enter a safe state (e.g., fully closed, fully open, etc.). The default (power-off) safe state may be caused when the analog control signal is disconnected (e.g., causing 0 mA at an input of the field device), in which case the field device will return to a safe state (e.g., valve position fully closed, fully open, etc.).

[0015] In recent years, all-digital systems have been introduced, in which field devices communicate with the control system solely using digital communication (e.g., the HART-IP communication protocol). In such systems, there is no longer an analog communication link between the field device and the control system. Therefore, auxiliary or backup technologies for placing field devices into a safe state may not be available. Consequently, when digital communication used to control a field device to a safe state fails to bring it into a safe state, the field device may continue to operate contrary to the request to enter a safe state.

[0016] The embodiments described herein address one or more of these and other challenges to provide systems and methods with secondary power-off capability for field devices communicating using fully digital protocols.

[0017] Figure 1 The diagram illustrates a control system 100 comprising one or more Advanced Physical Layer (APL) routing devices 102 in accordance with the teachings of this disclosure. The control system 100 also includes a field network 104 comprising network controllers (such as DeltaV™ PK controller 106, Ethernet I / O card (EIOC) 108, DeltaV™ SX controller 110, Safety Instrumented System (SIS) controller 112, etc.), one or more communication buses 113, 114, one or more field devices 116, and one or more intermediate network devices (such as backplane 120, modular APL switch 122, APL switch 124, etc.). The network controllers (e.g., network controllers 106, 108, 110, 112) are communicatively coupled to one or more field devices 116 via one or more communication buses 113, 114 and one or more intermediate network devices. The intermediate network devices (e.g., modular APL switch 122 and APL switch 124) to which the field devices 116 are directly coupled may be referred to as input / output interfaces of the control system 100. In some examples, a first subset of control system 100 (including SIS controller 112, APL routing device 102, field device 116, and communication bus 113) may be referred to as a Safety Instrumented System (SIS system); and a second subset of control system 100 (including one or more of network controllers 106, 108, 110, intermediate network devices, field device 116, and communication bus 114) may be referred to as a Distributed Control System (DCS system) or a Basic Process Control System (BPCS system). In some examples, communication buses 113 and 114 are isolated from each other. In some examples, communication buses 113 and 114, or portions thereof, are integrated into a shared communication bus shared between one or more components of the SIS system and the DCS system.

[0018] System 100 also includes a regional control network (ACN) 130, which includes back-end computing devices that provide monitoring, maintenance, engineering, and operational control functions for the devices in the field network 104. For example, the back-end computing devices may include one or more application stations 132, maintenance stations 134, engineering stations 136, and operator stations 138. Each back-end computing device may include one or more computing devices (e.g., laptops, desktops, tablets, mobile phones, etc.) that, for example, execute local software and / or access cloud-based services to provide the aforementioned functions. The back-end computing devices are coupled to a network controller (e.g., network controllers 106, 108, 110, 112) via an ACN bus 140. In some examples, the back-end computing devices are used to program the network controller (e.g., set parameters, schedule operations, etc. for field devices controlled or supervised by the network controller), retrieve information from the network controller (e.g., data logs of field devices or the network controller, program schedules, parameter settings, etc.), to control or schedule maintenance performed on or by the network controller, etc.

[0019] Field devices 116 can take many forms and perform a variety of functions. For example, field devices 116 may include transmitters, thermocouples, and switches that provide indications of various process parameters; solenoid valves and digital valve controllers (DVCs) that control the operation of valves; lights or other indicators that provide field indications of process status; and other types of process input and output devices. Field devices 116 can each be classified as output field devices, input field devices, or indicator field devices. Output field devices are field devices that are operable to control the outputs of the system processes of control system 100. For example, output field devices may include motors, valves, solenoid valves, or other actuated elements configured to stop, start, or regulate the flow of materials, fluids, or gases; regulate the position of movable components (e.g., open or close doors, rotate gears, or drive shafts); control heating or cooling elements; enable or disable power to components; and so on. Input field devices are field devices that (e.g., via sensors) acquire process parameters of control system 100 and provide indications of these process parameters to control system 100 (e.g., for determining how to control output field devices). An indicator field device is a field device configured to provide indication of the process status of the control system 100 in the field (e.g., a light, speaker, or other controllable indicator via an indicator field device). Some field devices 116 can perform more than one of controlling process outputs, providing process inputs, and providing indication of the process status of the control system 100. In this case, the field device is considered, for example, an output field device, an input field device, and an indicator field device. Furthermore, a non-output field device can be a field device not classified as an output field device, such as a field device classified as an input field device and / or an indicator field device that does not directly control process outputs.

[0020] As described above, the control system 100 includes one or more APL routing devices 102, also referred to as APL routers or APL switches. Generally, the APL routing device 102 is configured to route messages between field devices 116 coupled to the APL routing device 102 and upstream devices (such as SIS controller 112 and / or another network controller). This routing may include one or more of the following: receiving messages, identifying the intended recipient of the messages, translating the messages into a communication protocol suitable for the recipient, and transmitting the translated messages. Furthermore, the APL routing device 102 is configured to communicate using a two-wire digital protocol that uses a two-wire link for transmitting power and communication signals between devices, such as Ethernet Advanced Physical Layer (referred to herein as Ethernet-APL or APL). Ethernet-APL is a physical layer for Ethernet-based communication that enables high-speed and long-distance communication. Ethernet-APL uses a two-wire link for transmitting power supply and communication signals between (to one or more) communication devices. This two-wire link comprises a single twisted-pair (2-wire) cable that can extend through an external shield. Ethernet-APL is a subset of the Ethernet standard specifically designed for communication in industrial environments with field devices that may be distributed over large distances, rely on high-speed communication, and may be located in explosion-hazardous areas. While this document describes several devices as APL devices, and such devices can communicate using Ethernet-APL, in some examples, these devices may implement an alternative two-wire digital protocol that includes power and communication transmission. Therefore, the APL routing device 102 may also be referred to as a two-wire routing device or a two-wire power and digital communication routing device, which can be configured to communicate and provide power according to Ethernet-APL and / or another two-wire digital protocol that includes power and communication transmission.

[0021] Figure 1 The illustration shows two types of this APL routing device 102: a modular APL switch 122 and an APL switch 124. The modular APL switch 122 is housed in a module bay on a backplane 120. As shown below (for example, regarding...) Figure 5 As described further, backplane 120 may include multiple module trays, each configured to receive a corresponding field device characterization module, such as modular APL switch 122. Backplane 120 may also include: a housing or chassis supporting the module trays; a microcontroller for routing messages between upstream devices and field device characterization modules; an interconnect communication bus (or multiple buses) for interconnecting the microcontroller and field device characterization modules; and a power supply for powering the microcontroller and field device characterization modules. Modular APL switch 122 also includes a housing 123 supporting the components of modular APL switch 122.

[0022] APL switch 124 can be a physically and functionally independent unit; for example, its housing 125 may contain or be coupled to a separate power supply and not be mounted to a backplane configured to accommodate multiple modular APL switches or other routing devices. In other examples, APL switch 124 is a functionally independent unit but is housed within a chassis along with other routing devices and hardware. In such examples, APL switch 124 may or may not contain housing 125. In some examples, APL switch 124 is configured to interface with more than one field device 116, while modular APL switch 122 is configured to interface with a single field device 116. In other examples, APL switch 124 is configured to interface with a single field device 116, and / or modular APL switch 122 is configured to interface with more than one field device 116.

[0023] The SIS controller 112, also known as a logic resolver, can be the controller of the safety instrumented system (SIS) of the control system 100. Therefore, the SIS controller 112 can receive and analyze system data (e.g., from field device 116, from intermediate network devices (e.g., modular APL switch 122 or APL switch 124), and from other network controllers) to determine if a safety condition exists. In response to determining the existence of a safety condition, the SIS controller 112 can control the control system 100 to stop certain processes or functions, which may include controlling field device 116 to a power-off state. To analyze system data to determine the existence of a safety condition, the SIS controller 112 can compare the parameters indicated by the system data with one or more thresholds that define the operating range of the corresponding parameters. When the SIS controller 112 determines that one or more parameters are outside the defined operating range, the SIS controller 112 can determine that a safety condition exists. The SIS controller 112 can also determine the existence of a safety condition based on a direct or binary indication of the existence of a safety condition received from another device in the control system 100.

[0024] Like other network controllers, the SIS controller 112 may include a memory storing software and an electronic processor configured to retrieve and execute software to implement the functions of the SIS controller 112 described herein. The memory may include read-only memory (ROM), random access memory (RAM), other non-transitory computer-readable media, or combinations thereof. The electronic processor may include one or more processors, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other processing circuitry systems that operate individually or in combination to implement the functions of the SIS controller 112 described herein. In some examples, the SIS controller 112 includes redundant components (e.g., redundant electronic processors and memory mirrored with the (main) electronic processor and memory already described) to provide backup functionality in the event of a failure or malfunction of the main component.

[0025] Other network controllers, such as network controller 106, can implement the system processes of control system 100. For example, a network controller may have process control logic defined in its memory, which is executed by the network controller's electronic processor. By executing the process control logic, network controller 106 can receive system data (e.g., from field device 116) indicating system parameters of control system 100, process the system data (e.g., according to settings, thresholds, etc. defined in memory), and generate operational controls and transmit them to field device 116 to control field device 116, thereby implementing the system processes.

[0026] Figure 2 A more detailed illustration is provided of a control system based on some examples (e.g., Figure 1 The APL routing device 102 (also known as a dual-line routing device) of the control system 100 in the system. Figure 2 The APL routing device 102 is suitable for Figure 1 Block diagrams of various examples of both the APL switch 124 and the modular APL switch 122. (See attached diagram.) Figure 2 As shown, APL routing device 102 can be coupled to upstream network controller 201 via communication bus 203. Network controller 201 can be, for example, an SIS controller (e.g., similar to SIS controller 112), a DCS controller (e.g., similar to...) Figure 1The communication bus 203 may be one of controllers 106, 108, or 110, or other types of network controllers. The communication bus 203 may be, for example, a communication bus similar to communication bus 113 or communication bus 114. In some examples, one or more intermediate devices 204 are provided (logically and / or physically) along the communication bus 203 between the APL routing device 102 and the network controller 201. The intermediate device 204 may include one or more microcontrollers, gateway devices, additional routing devices, etc., such as a backplane (e.g., backplane 120). Figure 1 As shown, in Figure 2 In this context, APL routing device 102 is also coupled to one or more ( n 116 field devices (of which) n ≥1), respectively marked as field equipment 116-1, 116-2 to 116- n .

[0027] APL routing device 102 includes an upstream communication interface 210, a router electronic controller 212, and an APL interface 214, also known as a two-wire communication and power interface or a two-wire interface. The upstream communication interface 210 includes the physical circuitry (e.g., ports, antennas, filters, drivers, transceivers, etc.) that couples the APL routing device 102 to the communication bus 203. The upstream communication interface 210 enables the router electronic controller 212 to couple to the communication bus 203 and communicate with upstream devices. Therefore, the upstream communication interface 210 communicatively couples the router electronic controller 212 (and thus the APL routing device 102) with the network controller 201 and other upstream devices in the control system 100.

[0028] APL interface 214 includes a link that couples APL routing device 102 to two-wire links 220-1 to 220-1. n The physical circuitry (e.g., ports, antennas, filters, drivers, transceivers, etc.) communicates with field devices 116. The APL interface 214 enables the router electronic controller 212 to communicate via corresponding two-wire links 220-1 to 220- n Coupled to one or more field devices 116. Therefore, the APL interface 214 communicatively couples the router electronic controller 212 (and thus the APL routing device 102) to one or more field devices 116. The following is about... Figure 4 Further examples of APL interface 214 are described below.

[0029] Router electronic controller 212 is configured via interfaces 210 and 214 to route messages between one or more field devices 116 coupled to APL routing device 102 and upstream devices such as network controller 201 and / or other network controllers. This routing may include one or more of the following: receiving messages, identifying the intended recipient of the messages, translating the messages into a communication protocol suitable for the recipient, and transmitting the translated messages.

[0030] Figure 3 A more detailed illustration of an example of a router electronic controller 212 is provided. As shown, the router electronic controller 212 includes a microcontroller 300, a network switch 304, and one or more (…). n APL physical interface 310 (also known as two-wire physical interface 310). n Each of the APL physical interfaces 310 can communicate with n A corresponding one of the field devices 116 is associated, and more specifically, can be connected via APL interface 214 and n One of the corresponding ones in each of the two-wire links 220 n One of the corresponding couplings in each of the field devices 116.

[0031] In some examples, microcontroller 300 includes an electronic processor and a memory storing instructions retrieved and executed by the electronic processor to perform the functions of microcontroller 300 as described herein. The memory may include read-only memory (ROM), random access memory (RAM), other non-transitory computer-readable media, or combinations thereof. The electronic processor may include one or more processors, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other processing circuitry systems that operate individually or in combination to implement the functions of microcontroller 300 as described herein. Microcontroller 300 is configured to communicate with one or more network controllers (including network controller 201) of control system 100. More specifically, microcontroller 300 may be associated with a unique address, enabling network controller 201 to send and receive messages from microcontroller 300 (and thus to router electronic controller 212 and APL routing device 102).

[0032] The microcontroller 300 can also be configured to generate a switch control signal 320 for controlling a power switch associated with a two-wire link 220 of the field device 116. As shown, the switch control signal 320 is provided to a reference. Figure 4The APL interface 214 is described in more detail. The switch control signal 320 may contain one control signal for each power switch. The switch control signal 320 may be provided via one or more control lines (e.g., one for each power switch), which connect the microcontroller 300 to each corresponding power switch. As described further below, using the switch control signal 320, the microcontroller 300 is configured to selectively de-energize the field device 116, providing the network controller 201 (and the control system 100) with an auxiliary technique for de-energizing the field device 116.

[0033] Network switch 304 is configured to route messages between upstream and downstream devices in control system 100, and between router electronic controller 212 in control system 100 and upstream and downstream devices. For example, network switch 304 may be an Ethernet switch configured to receive communications sent from upstream devices (such as network controller 201, network controller 106, network controller 108, or network controller 110) via upstream communication interface 210, according to Ethernet communication protocols (e.g., IEEE 802.3 or 802.11 as defined by standards under IEEE 802). Network switch 304 can parse each communication (which may include a series of packets containing headers and payload packets) to identify the intended recipient based on the address or identifier in the header. Network switch 304 can then route the communication to the intended recipient (e.g., to one of field devices 116, or to microcontroller 300 representing APL routing device 102). To route communication to microcontroller 300, network switch 304 can transmit communication to microcontroller 300 via bus 330. Network switch 304 can transmit communication via bus 330 in the same format as the received communication. Microcontroller 300 can then parse the communication, identify that the communication is for microcontroller 300 based on the address or identifier in the header, and then process the payload. To route communication to one of field devices 116, microcontroller 300 can transmit communication via bus 312 to APL physical interface 310 associated with (and coupled to) the field device 116 as the intended recipient of the message. APL physical interface 310 can then convert packetized communication from Ethernet protocol to digital two-wire protocol (e.g., APL protocol) and transmit the communication to APL interface 214 via two-wire connector 314. For ease of description, two-wire connector 314 will be referred to as internal connector 314, but unless otherwise stated, this naming should not be construed as requiring two-wire connector 314 to be fully built-in. As per the above Figure 4 Further described, the APL interface 214 couples the internal connector 314 to one of the two-wire links 220 and ultimately to one of the field devices 116 intended to receive communication.

[0034] Network switch 304 is also configured to receive communication from microcontroller 300 and field devices 116 and to route the communication appropriately to, for example, network controller 201 or other upstream devices. For example, network switch 304 can parse each communication (which may include a series of packets containing headers and payload packets) to identify the intended recipient based on the address or identifier in the header. Network switch 304 can then route the communication to the intended recipient (e.g., one of SIS controller 112, network controller 106, network controller 108, network controller 110, etc.). To route communication from microcontroller 300, network switch 304 can receive communication from microcontroller 300 via bus 330. Network switch 304 can transmit communication via upstream communication interface 210 through bus 203 in the same format as the received communication. Communication from one of the field devices 116 can first be received by the APL physical interface 310 associated with (and coupled to) the field device 116 that is transmitting the message. The APL physical interface 310 can then convert communication from a digital two-wire protocol (e.g., the APL protocol) to an Ethernet protocol and provide the communication to the network switch 304 via bus 312. In at least some examples, the conversion between communication and a digital two-wire protocol (e.g., the APL protocol) can use standard network conversion techniques. The network switch 304 can then route the communication to the intended recipient (e.g., to one of the SIS controller 112, network controller 106, network controller 108, network controller 110, etc.).

[0035] In some examples, APL routing device 102 is coupled to one or more upstream devices via another two-wire link and is configured to use the APL protocol for upstream communication (i.e., in addition to using the APL protocol for downstream communication). In such examples, an additional APL physical interface 310 may be provided between network switch 304 and upstream communication interface 210 to convert or convert communication to or from the APL protocol.

[0036] Although the microcontroller 300, network switch 304, and APL physical interface 310 are illustrated as separate components, in some examples, one or more of these components are integrated into a single device. For example, a shared electronic processor and memory may be used as the electronic processor and memory (i.e., to perform their functions) for both network switch 304 and microcontroller 300, both network switch 304 and APL physical interface 310, or network switch 304, microcontroller 304, and APL physical interface 310.

[0037] Figure 4A more detailed example of the APL interface 214 is illustrated. As shown, the APL interface 214 includes the other end of an internal connector 314 from the router electronic controller 212 and receives switch control signals 320 from the router electronic controller 212 along a switch control line. The APL interface 214 includes one or more ( n Each sub-APL interface 402 (referred to herein as sub-interface 402) provides a separate connection or interface point for the corresponding field device in field device 116. Although APL interface 214 is illustrated as ( n ) Sub-interface 402 coupled to n Two-line link 220 and n There are 116 field devices, but in some examples, the number of sub-interfaces 402 of APL interface 214 is greater than the number of field devices 116 (e.g., m One sub-interface 402, of which m>n This means that some of them (i.e., mn The sub-interface 402 can be in an open or unused state and can be used to couple to other field devices 116. In other words, even though the APL interface 214 is operable to independently couple to 10 field devices (e.g., having 10 sub-interfaces 402), the APL interface 214 can also couple to only 1, 2, 5, or other number of field devices, which is less than the total capacity of the APL interface 214. However, for ease of discussion, the description will generally refer to those with... n The system includes a sub-interface 402, a two-wire link 220, and a field device 116.

[0038] APL interface 214 also includes a power supply 403, which includes connections 404 for coupling to a primary field power supply 406 and a secondary field power supply 408. The secondary field power supply 408 can be a redundant power supply providing backup power in the event of an interruption of the primary field power supply 406. Both the primary field power supply 406 and the secondary field power supply 408 can provide DC power to the APL routing device 102 via connections 404. Each connection 404 is coupled to the power supply node 410 via a corresponding diode 412. Each diode 412 prevents reverse power flow (e.g., from the primary field power supply 406 to the secondary field power supply 408 and vice versa).

[0039] Each sub-interface 402 is coupled to a power supply node 410, a ground 414, an internal connector 314, and one of the two-wire links 220 (e.g., two-wire link 220-1). For example, referring to sub-interface 402 of field device 116-1, the internal connector 314 is connected to a corresponding capacitor 420, the capacitor 420 is connected to a corresponding port 422, and the port 422 is connected to two-wire link 220-1. Furthermore, the power supply node 410 is coupled via inductor 424 to the node between a first capacitor in capacitor 420 and a first port in port 422, and the ground 414 is coupled via inductor 426 to the node between a second capacitor in capacitor 420 and a second port in port 422. Each sub-interface 402 also includes a pair of power switches 430, with one power switch corresponding to each branch of the associated two-wire link 220. For example, the first power switch 430-1a is coupled downstream of the node connected to inductor 424, and the second power switch 430-1b is coupled downstream of the node connected to inductor 426. The power switch 430 can be collectively referred to as power switch 430, and is further designated as 430-1a, 430-1b, 430-2a, 430-2b, ... up to 430- n a、430- n b. Each power switch 430 may be, for example, a transistor (e.g., a field-effect transistor (FET), a metal-oxide-semiconductor field-effect transistor (MOSFET), a bipolar junction transistor (BJT), a relay, etc.). The description of the sub-interface 402 associated with the two-wire link 220-1 applies similarly to the other sub-interfaces 402.

[0040] In some examples, the switch control signal 320 (also labeled SW1-n) may include multiple control signals, one for each power switch 430. Each control signal may be provided (e.g., along a conductive path) to the control gate of the associated power switch 430. For example, as shown, the switch control signal 320 may include a first switch control signal SW1a (for controlling power switch 430-1a), a second switch control signal SW1b (for controlling power switch 430-1b), a third switch control signal SW2a (for controlling power switch 430-2a), a fourth switch control signal SW2b (for controlling power switch 430-2b), and so on, up to the control signal SW. n a and SW n b. In some examples, the switch control signal 320 includes a shared control signal provided to more than one power switch 430. For example, a single shared control signal can be provided to the control gate of each power switch 430 to control them in parallel, such that ( Figure 3The microcontroller 300 can generate a single all-on or all-off control signal to selectively enable all power switches 430 or disable all power switches 430 in parallel. In other embodiments, one or more shared control signals of the switch control signals 320 can be provided to a subset of the power switches (i.e., fewer than all power switches 430). In any case, each power switch 430 can receive a control signal from the switch control signals 320, whether it is shared by one or more other power switches 430 or is specific to that particular power switch 430.

[0041] Figure 4 The two-wire link 220 is also illustrated in more detail. For example, as shown, two-wire link 220-1 includes a pair of twisted pairs 440, wherein a first wire of the twisted pair is coupled to a first port 422 and a second port 442 of field device 116-1, and a second wire of the twisted pair is coupled to a second port 422 and a second port 444 of field device 116-1. Furthermore, the twisted pair 440 extends through a shield 450. The shield 450 may be a conduit that defines the tubular volume in which the twisted pair 440 resides. The shield 450 may include a conductive layer and may be coupled to a port 452 of the APL interface 214, which may be grounded. The shield 450 protects the twisted pair 440 from interference that could interrupt communication along the two-wire link 220. The description of two-wire link 220-1 also applies to other two-wire links 220 (e.g., two-wire links 220-2 to 220-n).

[0042] Although Figure 4 Power switch 430 is illustrated as being located within APL interface 214, but in some other examples, power switch 430 is located outside APL routing device 102. For example, power switch 430 may be located outside the housing of APL routing device 102 along the respective two-wire link 220 and at another location between APL routing device 102 and associated field device 116. Switch control signals 320 configured to control each respective power switch 430 may be provided to a particular power switch 430 along a cable or other communication connection. For example, as described below... Figure 6 The power switch 430 may be located outside the APL routing device 102 and is part of the backplane of the APL routing device 102. In other examples, the power switch 430 may be located further downstream along the dual-line link 220 and therefore not part of the backplane. In some examples, some power switches 430 are located inside the APL routing device 102 and some power switches 430 are located outside the APL routing device 102.

[0043] Figure 5 The illustration shows an example of one of the field devices 116, such as Figure 1 ,2 Field devices 116-1 in section 4. As described above, each field device 116 is configured to receive power and communication from APL routing device 102 via a corresponding two-wire link 220. Each field device 116 may include a field device controller 502, one or more field device components 504, and a field device APL interface 506. The field device APL interface 506 may include ports 442 and 444, a power supply circuit system 508, and connections from ports 442 and 444 to the field device controller 502 and the power supply circuit system 508. Field device components 504 may include one or more controllable output components 510 (e.g., digital valve controllers, frequency converters, solenoids, etc.), one or more sensing components 512 (e.g., pressure sensors, temperature sensors, flow sensors, current sensors, voltage sensors, etc.), and / or one or more indicating components 514 (e.g., speakers, lights, LED displays, etc.). The power supply circuit system 508 can receive, regulate, and supply power received via two-wire link 220 to other components of field device 116, such as field device controller 502 and one or more field device components 504.

[0044] The field device controller 502 may include an electronic processor and a memory. The memory may store instructions retrieved and executed by the electronic processor to implement the functions of the field device controller 502 described herein. The electronic processor may include one or more processors, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other processing circuitry systems that operate individually or in combination to implement the functions of the field device controller 502 described herein. For example, the field device controller 502 may receive and process communications transmitted via two-wire link 220 (e.g., originating from APL routing device 102, network controller 201, or another controller of control system 100). To process the communications, the field device controller 502 may identify that the communications are addressed to a field device based on a field device identifier in the communications (e.g., an address in the header of a communications associated with a field device). In response to determining that the communications are addressed to field device 116, the field device controller 502 may interpret and execute commands or respond to requests indicated in the payload of the communications. For example, a command may request information from a sensor in sensing component 512, in which case the field device controller 502 can respond to the requesting device using the requested sensor information; a command may request the field device to control a controllable output component 510 (e.g., a valve) to open or close a specific amount or to a specific setpoint, in which case the field device controller 502 can respond by controlling the controllable element according to the command; a command may request the field device to control an indicator component 514 (e.g., a lamp) to illuminate, in which case the field device controller 502 can respond by controlling the indicator component 514 to illuminate according to the command; and many other potential commands. In some examples, the command may be a safety state command requesting field device 116 to enter a safe state. In response, the field device controller 502 may control one or more field device components 504 to enter a safe state (e.g., appropriately controlling a valve to be fully open or fully closed, controlling a motor to be shut down, etc.). The safe state matches the power-off state of the field device. For example, when field device 116 is a control valve controlled by a digital valve controller (DVC), the valve can enter a safe state (e.g., closed) because (1) the DVC is commanded to close the valve and the valve closure is successfully completed according to the normal operation of the DVC; or (2) the DVC is de-energized and the mechanical configuration of the control valve (e.g., the valve actuator contains a spring for driving the valve to the closed position) causes the control valve to enter a closed safe state.

[0045] Furthermore, the field device controller 502 can generate and transmit communications via the two-wire link 220 (e.g., via the field device APL interface 506 and according to the APL protocol). The field device controller 502 can generate and transmit these communications in response to requests (e.g., requests for sensor information), based on programming that allows the field device controller 502 to periodically transmit sensor information or field device status information, or based on programming that causes the field device controller 502 to generate and transmit communications according to defined conditions or triggers. To send and receive communications via the two-wire link 220, the field device controller 502 may include or implement a physical layer interface similar to the APL physical interface 310.

[0046] Figure 6 A more detailed illustration is provided. Figure 1 Figure 600 shows an example of a backplane 120. Backplane 120 includes a backplane microcontroller 602, a communication bus 604, a backplane power supply 606, and multiple module bays 610. Each module bay 610 is configured to receive a field device characterization module, such as a modular APL switch 122. The communication bus 604 provides a communication link between the backplane microcontroller 602 and devices (e.g., the modular APL switch 122) within the module bays 610. The backplane microcontroller 602 is an intermediate device provided between the modular APL switch 122 and network controller 201 and / or other network controllers (e.g., Figure 2 (Example of intermediate device 204). Backplane microcontroller 602 can perform routing functions similar to network switch 304 to route communication from upstream devices (e.g., network controller 201 and / or other controllers) to modular APL switch 122 and / or field device 116, and to route communication from modular APL switch 122 and / or field device 116 to upstream devices. Backplane microcontroller 602 can also be configured to: identify the field device characterization module after it is inserted into the module tray of module tray 610, verify the compatibility of the inserted module with backplane 120, and then control backplane power supply 606 to provide power to the inserted module. Although module tray 610 is illustrated to accommodate one modular APL switch 122 per module tray, in some examples, one or more of module trays 610 are empty and / or accommodate another (non-APL) field characterization module, such as a module coupled to a field device via a conventional analog connection.

[0047] Each module bay 610 includes physical and electrical interfaces for receiving and coupling to associated field device characterization modules, such as the modular APL switch 122. For example, regarding the electrical interfaces, each module bay 610 may include an upstream communication interface for connecting a communication bus 604 to the modular APL switch 122 (see, for example, [link to relevant documentation]). Figure 2 The terminals shown are: the upstream communication interface 210; terminals for connecting the modular APL switch 122 to the backplane power supply 606 to receive power (e.g., to power the router electronics controller 212 of the modular APL switch 122); terminals for connecting the modular APL switch 122 to the power supply node 410; and terminals for connecting the modular APL switch 122 to the power switch 430 and the two-wire link 220. Regarding the physical interface, each module bracket 610 may include retaining elements such as physical slots, threaded bosses for receiving screws, friction-fitting terminal walls, etc., to selectively retain modules (e.g., the modular APL switch 122) within the module bracket 610 and allow selective removal of the module (e.g., for replacement).

[0048] Back panel 120 also includes the above regarding Figure 4 A similar two-wire interface power supply is described. Specifically, the backplane includes connections 404 for coupling to a primary field power supply 406 and a secondary field power supply 408. The secondary field power supply 408 can be a redundant power supply providing backup power in the event of an interruption of the primary field power supply 406. Both the primary field power supply 406 and the secondary field power supply 408 can provide DC power to the modular APL switch 122 via connections 404 for powering and communicating with field devices 116. Each connection 404 is coupled to a power node 410 via a corresponding diode 412. Each diode 412 prevents reverse power flow (e.g., from the primary field power supply 406 to the secondary field power supply 408 and vice versa). Each modular APL switch 122 is coupled to a power supply node 410, which communicates with... Figure 4 It is further coupled to the upstream side of the power switch 430 in a manner similar to that shown and described.

[0049] exist Figure 6 In the middle, power switch 430 (including power switches 430-1a to 430- n b) Integrated into backplane 120, located outside the modular APL switch 122. For example, backplane 120 physically supports power switch 430 and provides an electrical connection between module bracket 610 and power switch 430 to transmit switch control signals 320. Therefore, each modular APL switch 122 outputs corresponding switch control signals SW1a, SW1b, SW2a, SW2b received by the corresponding power switch 430 to SW1a, SW1b, SW2a, SW2b. n a and SW n b, also known as switch control signal 320 (see...) Figure 3 and Figure 4 ).Although Figure 6The power switch 430 is illustrated as part of the backplane 120 and located outside the modular APL switch 122, but in other examples, the power switch 430 is incorporated into the modular APL switch 122, similar to... Figure 4 The power switch 430 shown is shown.

[0050] Figure 7 The diagram illustrates process 700 for de-energizing field equipment. For illustrative purposes, process 700 is typically described as being performed by... Figures 2 to 4 APL routing device 102 in Figure 1 The APL routing device 102 is implemented within the context of the control system 100. As described above, the APL routing device 102 can be implemented as, for example, an APL switch 124 or an APL device housed in a backplane (e.g., Figure 1 and Figure 6 (Modular APL switch 122 in backplane 120). In some embodiments, other systems may implement process 700. Furthermore, although the individual blocks of process 700 are shown in a specific order, in some embodiments, one or more blocks may be executed partially or entirely in parallel, or may be implemented in conjunction with... Figure 7 The different execution sequences shown may be possible or can be bypassed.

[0051] In box 705, the Advanced Physical Layer (APL) routing device receives a security status command containing field device identifiers from the controller. For example, refer to... Figure 2 The APL routing device 102 can receive security status commands from the network controller 201 via the communication bus 203. The APL routing device 102 can receive security status commands from the network controller 201 directly via the communication bus 203 or via one or more intermediate devices 204. For example, refer to... Figure 6 The APL routing device 102 (implemented as an APL switch 124) can receive security status commands via the backplane microcontroller 602. The upstream communication interface 210 of the APL routing device 102 can receive the security status commands and provide them to the router electronic controller 212. Ultimately, as further described below, a security status command is a command that causes a field device 116 (a field device identified by a field device identifier) ​​to enter a specific security state. The security status command can be packetized communication of a first protocol (e.g., an Ethernet protocol such as IEEE 802.3 or 802.11), which includes the security status command as one or more data payload packets and a packet header containing the address of the field device commanded to enter the security state as a field device identifier.

[0052] Network controller 201 can generate a safety status command received in block 705 based on one or more factors. For example, as previously described, network controller 201 112 can generate a safety status command in response to determining that a safety condition exists in control system 100. For example, network controller 201 can analyze system data of control system 100 (e.g., provided by one or more input field devices 116) to determine whether a safety condition exists. To analyze the system data, network controller 201 can compare the parameters indicated by the system data with one or more thresholds that define the range of operation for the corresponding parameters. When network controller 201 determines that one or more parameters are outside the defined operating range, network controller 201 can determine that a safety condition exists. Network controller 201 can also determine the existence of a safety condition based on a direct or binary indication of the existence of a safety condition received from another device in control system 100.

[0053] In block 710, an APL routing device (e.g., APL routing device 102) transmits security status commands as digital signals via a two-wire communication and power interface to a field device (e.g., one of field devices 116) indicated by a field device identifier, which also provides power to that field device. For example, as part of implementing block 710, refer to... Figure 3 The router electronic controller 212 can process security status commands received in block 705. To process the security status command, the router electronic controller 212 (e.g., via network switch 304) can parse the command to identify the intended recipient from the command header. More specifically, the network switch 304 can determine a field device identifier from the header, which indicates the intended recipient of the security status command. For illustrative purposes, in this example, the field device identifier can be considered as indicating field device 116-1 among field devices 116. The network switch 304 can then transmit the security status command via the corresponding bus 312 to the APL physical interface 310 associated with the identified field device (e.g., the APL physical interface 310 associated with field device 116-1). For example, the network switch 304 can maintain a mapping between the field device identifier of field device 116 and the corresponding APL physical interface 310, for example, in the memory of the network switch 304. Therefore, network switch 304 can compare the determined field device identifier extracted from the received communication (e.g., security status command) with the mapping to identify which APL physical interface 310 the network switch 304 should transmit the received communication to.

[0054] Upon receiving the security status command, the APL physical interface 310 converts the command into two-wire communication (e.g., according to the APL communication protocol) and outputs the converted command along the internal connector 314 to the APL interface 214. By outputting the converted security status command to the APL interface 214, the router electronic controller 212 drives the APL interface 214 to transmit the security status command to the field device 116-1. More specifically, refer to... Figure 4 The sub-interface 402 associated with field device 116-1 transmits safety status commands to field device 116-1 via communication link 220-1. During transmission, power switches 430-1a and 430-1b can be enabled (e.g., by closing control signals SW1a and SW1b based on switch control signals 320 from microcontroller 300) to allow the transmission of safety status commands and power to field device 116-1 via communication link 220-1.

[0055] In block 715, the APL routing device (e.g., APL routing device 102) can determine whether to execute a secondary power-down scheme. When the APL routing device determines to execute a secondary power-down scheme, the APL routing device proceeds to block 720. When APL routing device 102 determines not to execute a secondary power-down scheme (e.g., after a certain period of time, or based on communication from network controller 201 indicating an undesirable secondary power-down scheme), process 700 can terminate at block 725. APL routing device 102 can determine to execute a secondary power-down scheme in response to receiving a command to execute a secondary power-down scheme (secondary power-down command) from network controller 201. The secondary power-down command can be addressed to APL routing device 102 through network controller 201. For example, the secondary power-down command may include the address of APL routing device 102 in the command header, where the address indicates that APL routing device 102 is the intended recipient of the command and that the command is intended for execution by APL routing device 102. In addition, the secondary power-off command may include an identifier of the field device 116 to be powered off using the secondary power-off scheme (e.g., field device 116-1 previously indicated in the safety status command received in block 705).

[0056] Network controller 201 may send a secondary power-down command to APL routing device 102 for one or more reasons. For example, network controller 201 may send a secondary power-down command in response to network controller 201's inability to determine or confirm the validity of a safety status command. For example, network controller 201 may be unable to confirm the validity of a safety status command when network controller 201 confirms that field device 116 has not entered a safety status and / or when network controller 201 cannot confirm whether field device 116 has entered a safety status. Network controller 201 may determine that the safety status command is invalid (i.e., field device 116 has not entered a safety status) based on one or more of the following: (1) communication from field device 116-1 indicating that field device 116-1 is not in a safety status, (2) sensing from another field device 116 (or multiple field devices 116) one or more parameters indicating that field device 116-1 has not entered a safety status (e.g., no change or specific change in fluid pressure, flow rate, temperature, etc.), and other techniques for determining that the safety status command is invalid.

[0057] Conversely, network controller 201 may determine not to send a secondary power-off command in response to acknowledging the validity of a safety status command. Network controller 201 may determine that a safety status command is valid for a specific field device 116 (e.g., field device 116-1) based on one or more of the following: (1) field device 116-1 has received acknowledgment of the safety status command; (2) acknowledgment message from field device 116-1 confirming that field device 116-1 has entered a safety status; (3) one or more parameters indicating that field device 116-1 has entered a safety status are sensed from another field device 116 (or multiple field devices 116) (e.g., fluid pressure loss below a threshold, fluid pressure increase above a threshold, fluid flow rate change exceeding a threshold, temperature or absolute temperature change exceeding a threshold, and many other possible parameter-based indications), and other techniques for determining the validity of the safety status command.

[0058] In some examples, network controller 201 can send a secondary power-down command to APL routing device 102 regardless of whether the safety status command is valid. For example, in response to a detected network storm or a request to shut down control system 100 or a specific field device 116, network controller 201 can transmit both a safety status command addressed to field device 116 and a secondary power-down command addressed to APL routing device 102 (and instruct field device 116 to power down). In other words, regardless of whether it is based on a safety status command or a secondary power-down command, network controller 201 can send the secondary power-down command as redundant communication to ensure that field device 116 is powered down.

[0059] In some examples, network controller 201 may send a secondary power-down command to APL routing device 102 in response to determining that communication interruption between network controller 201 and field device 116 has exceeded a predetermined amount of time. To make this determination, network controller 201 may maintain a watchdog timer, which is periodically refreshed by network controller 201 in response to receiving corresponding periodic communications from field device 116. When the watchdog timer expires, since no timely communication from field device 116 has been received to refresh the watchdog timer, network controller 201 determines that communication with field device 116 has been interrupted for a predetermined amount of time. In response, network controller 201 transmits a secondary power-down command to APL routing device 102 and uses this command to identify the field device 116 to be powered down.

[0060] In some examples, APL routing device 102 determines to execute a secondary power-off scheme based on: (i) determining that network controller 201 commands field device 116 to enter a safe state; and (ii) that the command for field device 116 to enter a safe state is invalid. For example, in some examples, APL routing device 102 “sniffs” communication from network controller 201 to field device 116. In such an example, APL routing device 102 can determine that network controller 201 is commanding field device 116 to enter a safe state by sniffing (detecting) communication addressing field device 116 containing a safe state command received in box 705. APL routing device 102 can then detect that field device 116 has not yet entered a safe state based on further communication received from field device 116 or other techniques, such as one of the techniques for network controller 201 to detect whether the safe state command is valid. When APL routing device 102 detects that field device 116 has not yet entered a safe state, even though network controller 201 has detected an attempt to command field device 116 to enter a safe state, APL routing device 102 can determine to execute a secondary power-down scheme (e.g., and proceed to block 720 of process 700). In other examples, communication between network controller 201 and field device 116 is encrypted or otherwise opaque to APL routing device 102, and APL routing device 102 cannot sniff out safe state commands addressed to one of field devices 116. In such examples, APL routing device 102 determines whether to execute a secondary power-down scheme based on one of the other techniques described.

[0061] In block 720, after transmitting a safety status command to a field device (e.g., field device 102), the APL routing device performs a secondary power-off scheme for that field device. The secondary power-off scheme includes the APL routing device controlling a power switch to cut off power to the field device via the two-wire link. For example, refer to... Figure 3and Figure 4 The APL routing device 102 (e.g., router electronic controller 212, and more particularly, microcontroller 300) can generate one or more switch control signals 320. These one or more switch control signals 320 may include control signals for power switches 430 corresponding to the two-wire link 220-1 and field device 116-1 (i.e., control signals SW1a and SW1b for power switches 430-1a and 430-1b, respectively). These one or more switch control signals 320 are configured to control the opening of power switches 430-1a and 430-1b associated with the two-wire link 220-1 and field device 116-1, thereby cutting off or stopping power from the power supply node 410 and ground 414 to the field device 116-1 via the two-wire link 220-1. Reference Figure 6 In the example where the APL routing device 102 is implemented as a modular APL switch 122 in the backplane 120, similarly, power switches 430-1a and 430-1b are controlled to open by switch control signals SW1a and SW1b to cut off power to field device 116-1 via two-wire link 220-1.

[0062] In some examples, APL routing device 102 may implement a modified process 700, which includes blocks 715 and 720, wherein blocks 705 and 710 are absent or present but optional. For example, APL routing device 102 may execute a secondary power-down scheme based on the expiration of a watchdog timer maintained by APL routing device 102, the expiration of which indicates that a communication link between APL routing device 102 and network controller 201 has been lost. In such an example, APL routing device 102 may implement a modified process 700, including block 715 (where APL routing device 102 determines to implement a secondary power-down scheme in response to the expiration of the watchdog timer) and block 720 (where APL routing device 102 executes a secondary power-down scheme to power down field device 116), wherein blocks 705 and 710 are absent or present but optional. More specifically, microcontroller 300 may also be configured to perform a watchdog timer function, wherein microcontroller 300 periodically acknowledges the existence of a communication link with network controller 201. For example, microcontroller 300 can implement a countdown timer (as a watchdog timer) that resets when it receives watchdog timer communication from network controller 201. Network controller 201 is configured to periodically send watchdog timer communication to repeatedly reset the countdown timer and prevent it from expiring (e.g., reaching zero). When microcontroller 300 determines that the countdown timer has expired, it determines that the communication link with network controller 201 is broken or nonexistent (e.g., due to an interruption of communication bus 203, a failure of network controller 201, etc.). In response, microcontroller 300 can then determine in block 715 of process 700 to execute a secondary power-down scheme to de-energize one or more field devices 116. In block 720, in response to this determination, microcontroller 300 can then execute a secondary power-down scheme to de-energize one or more field devices 116 by controlling one or more associated power switches 430 to cut off power to the field devices 116 via two-wire link 220.

[0063] In some examples, in response to determining to execute a secondary power-off scheme based on the expiration of a watchdog timer, the microcontroller 300 may (i) generate a switch control signal 320 to control each power switch 430 to open, thereby cutting off power to each field device 116 coupled to the APL routing device 102; or (ii) generate a switch control signal 320 to control each power switch 430 associated with the field device 116 as an output field device to open, thereby cutting off power to each output field device. In the latter example, the microcontroller may leave the power switches 430 of other non-output field devices unchanged, so that the powered non-output field devices can remain powered even if the watchdog timer expires. These non-output field devices can remain powered because they collect and (e.g., provide information about the control system 100 and / or the user) information about the control system 100, and continuing to receive this information may be advantageous, and because they do not directly control the system processes. To selectively power off output field devices 116 while keeping non-output field devices 116 powered on, microcontroller 300 can maintain a mapping or table for each field device 116 coupled to APL routing device 102, indicating the type of each field device 116 (e.g., output field device, non-output field device, indicator field device, input field device, etc.). In one example, this mapping can be automatically generated based on microcontroller 300's knowledge of the types of modules represented by field devices mounted in a particular module bay 610 (e.g., the type of modular APL switch 122). In response to a watchdog timer expiring and microcontroller 300 determining to initiate a secondary power-down scheme, microcontroller 300 can access the mapping or table to identify which field devices 116 coupled to APL routing device 102 are output field devices, identify the power switch 430 associated with each such output field device, and then control the power switch 430 identified as associated with each output field device to open (to cut off power to each output field device).

[0064] In some examples, APL routing device 102 executes a secondary power-off scheme based on a watchdog timer maintained by network controller 201 for one or more field devices 116. The watchdog timer for each field device 116 can be periodically reset by network controller 201 based on communications from the field device 116 corresponding to that watchdog timer. These communications from the field device 116 indicate that the field device 116 is still present in control system 100 and is communicatively coupled to network controller 201 (via APL routing device 102). If such communication is not received within the set time of the watchdog timer, the watchdog timer expires, indicating that the communication link between field device 116 and network controller 201 has been lost. In such an example, network controller 201 may send a secondary power-off command to APL routing device 102 coupled to the field device 116 that has lost its communication link. APL routing device 102 can then respond to this command by executing the secondary power-off scheme by opening the power switch 430 corresponding to the field device 116. Therefore, APL routing device 102 can implement the modified process 700, including block 715 (for determining to execute a secondary power-down scheme in response to receiving a secondary power-down command from network controller 201 when the watchdog timer expires) and block 720 (for executing the secondary power-down scheme to power down field device 116), wherein blocks 705 and 710 are absent or present but optional.

[0065] In some examples, before process 700 begins (e.g., during the initialization phase) or after routing device 102 turns on one or more power switches 430 in block 720 to de-energize one or more field devices 116 (e.g., during the reset phase), network controller 201 transmits a command to routing device 102 to close one or more power switches 430 to energize one or more field devices 116.

[0066] As described above, while this document describes multiple devices as APL devices (e.g., APL routing devices 102, 122, 124, APL interface 214, APL physical interface 310, etc.), and such devices can communicate using Ethernet-APL, in some examples, these devices can implement an alternative two-wire digital protocol that includes power and communication transmissions. Therefore, these devices may also be referred to as two-wire routing devices, two-wire interfaces, two-wire physical interfaces, etc., and they can be configured to communicate and send or receive power according to Ethernet-APL and / or an alternative two-wire digital protocol that includes power and communication transmissions. Similarly, although process 700 is described with respect to a control system implementing APL communication, process 700 can also be implemented by such two-wire routing devices (in conjunction with two-wire interfaces) according to an alternative (non-APL) two-wire digital protocol that includes power and communication transmissions.

[0067] The application of this disclosure is not limited to the details of the construction and component arrangement set forth in this specification or shown in the accompanying drawings. This disclosure is capable of other embodiments and can be practiced or implemented in various ways. Furthermore, it should be understood that the wording and terminology used herein are for descriptive purposes only and should not be considered limiting. The terms “comprising,” “including,” “containing,” or “having,” and variations thereof, as used herein, are intended to cover the items listed thereafter and their equivalents, as well as additional items. Unless otherwise stated or limited, the terms “mounting,” “connection,” “support,” and “coupling,” and variations thereof, are used extensively and cover direct and indirect mounting, connection, support, and coupling. Furthermore, “connection” and “coupling” are not limited to physical or mechanical connections or couplings.

[0068] Some embodiments (including computerized implementations of the methods according to this disclosure) can be implemented as systems, methods, apparatus, or articles of art using standard programming or engineering techniques to produce software, firmware, hardware, or any combination thereof to control processor devices (e.g., serial or parallel processor chips, single-core or multi-core chips, microprocessors, field-programmable gate arrays, control units, arithmetic logic units, and any combination of processor registers, etc.), computers (e.g., processor devices operatively coupled to memory), or other electronic operating controllers to implement the aspects detailed herein. Thus, for example, embodiments of this disclosure can be implemented as a set of instructions tangibly implemented on a non-transitory computer-readable medium such that a processor device can implement these instructions based on instructions read from the computer-readable medium. Some embodiments of this disclosure may include (or utilize) control devices consistent with the discussion below, such as automation equipment, computers comprising various computer hardware, software, firmware, etc. As specific examples, control devices may include processors, microcontrollers, field-programmable gate arrays, programmable logic controllers, logic gates, etc., and other typical components known in the art for implementing appropriate functions (e.g., memory, communication systems, power supplies, user interfaces, and other inputs, etc.). Furthermore, functions performed by multiple components can be combined and performed by a single component. Similarly, functions described herein as being performed by one component can be performed by multiple components in a distributed manner. Additionally, components described as performing specific functions can also perform additional functions not described herein. For example, a device or structure "configured" in a certain way is configured at least in that way, but may also be configured in ways not listed.

[0069] As used herein, the term "article of art" is intended to cover a computer program accessible from any computer-readable device, carrier (e.g., a non-transitory signal), or medium (e.g., a non-transitory medium). For example, a non-transitory computer-readable medium may include, but is not limited to, magnetic storage devices (e.g., hard disks, floppy disks, magnetic stripes, etc.), optical discs (e.g., compact discs ("CDs"), digital versatile discs ("DVDs"), etc.), smart cards, and flash memory devices (e.g., cards, sticks, etc.). Furthermore, it should be recognized that carrier waves can be used to carry computer-readable electronic data, such as data used for transmitting and receiving emails or accessing networks such as the Internet or local area networks ("LANs"). Those skilled in the art will recognize that many modifications can be made to these configurations without departing from the scope or spirit of the claimed subject matter.

[0070] Operations of methods or systems performing these methods according to this disclosure may be schematically represented in the figures or otherwise discussed herein. Unless otherwise stated or limited, specific operations represented in a particular spatial order in the figures do not necessarily require these operations to be performed in a specific sequence corresponding to that particular spatial order. Accordingly, certain operations represented in the figures or otherwise disclosed herein may be performed in an order different from that explicitly stated or described, depending on a particular embodiment of this disclosure. Furthermore, in some embodiments, certain operations may be performed in parallel, including by a dedicated parallel processing device or a separate computing device configured to interoperate as part of a large system.

[0071] As used herein in the context of computer implementation, unless otherwise stated or limited, the terms “component,” “system,” “module,” etc., are intended to cover part or all of computer-related systems, including hardware, software, combinations of hardware and software, or software in execution. For example, a component can be (but is not limited to) a processor device, a process executed (or executable) by a processor device, an object, an executable file, a thread of execution, a computer program, or a computer. For instance, an application running on a computer and the computer itself can both be components. One or more components (or systems, modules, etc.) may reside within a process or thread of execution, may be located on a single computer, may be distributed across two or more computers or other processor devices, or may be contained within another component (or system, module, etc.).

[0072] In some embodiments, the devices or systems disclosed herein may be utilized or installed using methods that implement aspects of this disclosure. Accordingly, the descriptions herein of particular features, capabilities, or intended uses of devices or systems are generally intended to include methods of disclosing the use of such features for their intended uses, methods of achieving such capabilities, and methods of installing disclosed (or otherwise known) components to support such purposes or capabilities. Similarly, unless otherwise stated or limited, the discussion herein of any methods of making or using a particular device or system (including installing such device or system) is intended to inherently include disclosures of features utilized and capabilities achieved by such devices or systems as embodiments of this disclosure.

[0073] As used herein, unless otherwise defined or limited, ordinal numbers are generally used in this document based on the order in which a particular component appears in the relevant section of this disclosure for ease of reference. In this respect, for example, names such as “first”, “second”, etc., generally indicate only the order in which the relevant components are introduced into the discussion and generally do not indicate or require a particular spatial arrangement, function, or structural priority or order.

[0074] As used herein, unless otherwise defined or limited, directional terms are used for the convenience of referring to a particular figure or example in the discussion. For example, references to downward (or other) directions or top (or other) positions may be used to discuss aspects of a particular example or figure, but it is not required that similar orientations or geometries be present in all installations or configurations.

[0075] As used herein, unless otherwise defined or limited, the phrase “and / or” for two or more items is intended to cover or include a single item as well as all items. For example, a device with “a and / or b” is intended to cover or include: a device with a (but not b); a device with b (but a); and a device with both a and b.

[0076] This discussion is intended to enable those skilled in the art to make and use embodiments of this disclosure. Various modifications to the illustrated examples will be apparent to those skilled in the art, and the general principles herein can be applied to other examples and applications without departing from the principles disclosed herein. Therefore, the embodiments of this disclosure are not intended to be limited to those illustrated, but are intended to be accorded the widest scope consistent with the principles and features disclosed herein and the appended claims. The detailed description provided should be read with reference to the figures, wherein the same elements in the different figures have the same reference numerals. The figures are not drawn to scale and are used only to depict selected examples and are not intended to limit the scope of this disclosure. Those skilled in the art will recognize that the examples provided herein have many useful alternatives, all of which are within the scope of this disclosure.

[0077] Although the invention disclosed herein has been described with reference to specific embodiments and applications, those skilled in the art can make various modifications and variations thereto without departing from the scope of the invention as set forth in the claims.

Claims

1. A dual-line routing device, the dual-line routing device comprising: Upstream communication interface, used for communication with the controller; The two-wire communication and power interface is configured to deliver communication and power to field devices via a two-wire link; as well as A router electronic controller, coupled to the upstream communication interface and the two-wire communication and power interface, is configured to: Receive a safety status command from the controller via the upstream communication interface, the safety status command including a field device identifier; The safety status command is transmitted as a digital signal to the field device indicated by the field device identifier via the two-wire communication and power interface and the two-wire link. as well as After sending the safety status command to the field device, a secondary power-off scheme for the field device is executed to control the power switch to cut off the power to the field device through the two-wire link.

2. The dual-line routing device as described in claim 1, The router electronic controller includes a network switch configured to determine the field device identifier from the security status command to identify the field device indicated by the field device identifier; and in, In order for the router's electronic controller to send the security status command via the two-wire communication and power interface, the network switch is further configured to: The security status command is converted from the first protocol to a two-line digital protocol; as well as The two-wire communication and power interface is driven according to the two-wire digital protocol to transmit the safety status command to the field device.

3. The dual-line routing device as claimed in claim 2, wherein the security status command received by the upstream communication interface is received by the router electronic controller as packetized communication in a first protocol, the packetized communication comprising the security status command as one or more data payload packets and a packet header containing an address as a field device identifier.

4. The dual-line routing device as claimed in claim 1, wherein the dual-line routing device is a modular dual-line routing device installed in a multi-module backplane, the multi-module backplane comprising: Multiple module brackets, each configured to receive a corresponding field device characterization module; A backplane microcontroller is communicatively coupled to the controller and each field device characterization module received in the plurality of module brackets, and is configured to route messages between the controller and each field device characterization module received in the plurality of module brackets; A communication bus couples the backplane microcontroller and each module bracket to enable communication between the backplane microcontroller and each field device characterization module received in the plurality of module brackets; as well as The power supply is configured to supply power to each field device characterization module received in the plurality of module brackets. The modular dual-line routing device is a field device characterization module that is communicatively coupled to the backplane microcontroller and powered by the power supply, and is installed in the first module bracket among the plurality of module brackets.

5. The dual-line routing device of claim 4, wherein the upstream communication interface is coupled to the backplane microcontroller via the communication bus to enable communication with the backplane microcontroller, and wherein the security status command received by the router electronic controller from the controller is received via the backplane microcontroller through the communication bus.

6. The dual-line routing device of claim 1, wherein the router electronic controller is further configured to determine to execute the secondary power-off scheme in response to receiving a command from the controller to initiate the secondary power-off scheme, the command being addressed to the dual-line routing device.

7. The dual-line routing device of claim 1, wherein the router electronic controller is further configured to determine to execute the secondary power-off scheme in response to determining that a watchdog timer has expired.

8. The dual-line routing device of claim 7, wherein the field device is a first field device among a plurality of field devices coupled to the dual-line routing device, wherein, In order to execute the secondary power-off scheme in response to determining that the watchdog timer has expired, the router electronic controller is configured to: Disconnect power to each of the plurality of field devices, including the first field device, and Power is allowed to continue flowing to each of the multiple field devices that are not output field devices.

9. The two-line routing device of claim 1, wherein the field device is a first field device among a plurality of field devices coupled to the two-line routing device, each of the plurality of field devices being coupled to the two-line communication and power interface via a corresponding two-line link and a corresponding power switch along the two-line link, wherein the router electronic controller is further configured to selectively control each corresponding power switch to selectively enable and disable power to the plurality of field devices.

10. The dual-line routing device as claimed in claim 1, further comprising: A housing that accommodates the router's electronic controller and the power switch.

11. The dual-line routing device as claimed in claim 1, further comprising: A housing that houses the router's electronic controller, wherein the power switch is located outside the housing.

12. The dual-line routing device of claim 1, wherein the dual-line link comprises a pair of twisted conductors extending through a shielded conduit.

13. A method for bringing field equipment into a safe state, the method comprising: The two-wire routing device transmits a safety status command as a digital signal to the field device via a two-wire link based on the field device identifier through a two-wire communication and power interface. The two-wire link also provides power to the field device. as well as After the safety status command is sent to the field device, the dual-line routing device executes a secondary power-off scheme for the field device, the secondary power-off scheme including the dual-line routing device controlling a power switch to cut off power to the field device through the dual-line link.

14. The method of claim 13, further comprising: The dual-line router receives the safety status command from the controller before sending the safety status command to the field device; as well as The dual-line routing device identifies the field device by extracting the field device identifier from the security status command; The transmission of the safety status command from the dual-line routing device to the field device via the dual-line communication and power interface includes: The security status command is converted from the first protocol to a two-line digital protocol; as well as The two-wire digital protocol drives the two-wire communication and power interface to transmit the safety status command to the field device.

15. The method of claim 14, wherein the security status command received by the dual-line device from the controller is packetized communication in a first protocol, the packetized communication comprising a security status command as one or more data payload packets and a packet header containing an address as an identifier of the field device.

16. The method of claim 14, wherein the dual-line routing device is a modular dual-line routing device mounted in a multi-module backplane, the method further comprising: Each module bracket in the multi-module backplane receives the corresponding field device characterization module; A backplane microcontroller, communicatively coupled to the controller and each field device characterization module housed in the plurality of module brackets, routes messages between the controller and each field device characterization module housed in the plurality of module brackets; Communication is transmitted between each field device characterization module received in the backplane microcontroller and the plurality of module brackets via a communication bus that couples the backplane microcontroller and each module bracket. as well as Power is supplied from the power supply to each field device characterization module housed in the plurality of module brackets. The modular dual-line routing device is a first field device characterization module installed in the first module bracket among the plurality of module brackets, communicatively coupled to the backplane microcontroller, and powered by the power supply.

17. The method of claim 16, wherein the dual-line routing device is coupled to the backplane microcontroller via the communication bus to enable communication with the backplane microcontroller, and wherein the security status command received by the dual-line routing device from the controller is received via the backplane microcontroller through the communication bus.

18. The method of claim 14, wherein the execution of a secondary power-off scheme for the field device by the dual-line routing device is in response to receiving a command from the controller to initiate the secondary power-off scheme, the command being addressed to the dual-line routing device.

19. The method of claim 13, wherein the secondary power-off scheme for the field device executed by the dual-line routing device is in response to determining that the watchdog timer has expired.

20. The method of claim 19, wherein the field device is a first field device among a plurality of field devices coupled to the two-way routing device, and wherein executing the secondary power-off scheme in response to determining that the watchdog timer has expired further comprises: Disconnect power to each of the plurality of field devices, including the first field device, and Power is allowed to continue flowing to each of the multiple field devices that are not output field devices.

Citation Information

Patent Citations

  • Two-wire communication system for high-speed data and power distribution

    CN103946829A

  • Two-wire communication system for high-speed data and power distribution

    CN105119794A