A method and system for DCS system I / O module address self-check recovery and fault location
By using the DCS system I/O module address self-test recovery and fault location method, the problems of communication blockage and data verification failure in the power plant environment are solved, thereby improving the system stability and reliability and supporting rapid module integration and seamless expansion.
Patent Information
- Application Number
- CN202511052305.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-07-29
AI Technical Summary
In existing technologies, DCS systems in power plant environments suffer from problems such as electromagnetic interference, increased address signal error rate, address conflicts, signal attenuation, and protocol mismatch, leading to communication blockages, data verification failures, and timing disorders, which affect data acquisition accuracy and control loop stability.
The DCS system I/O module address self-test recovery and fault location method is adopted. Through system configuration, address latching and verification, parity check, dynamic reconfiguration of field programmable logic devices and self-test mechanism, the address identification is accurate and the recovery is fast when communication is abnormal.
It effectively reduces the system's sensitivity to external environmental interference, reduces address conflicts and communication errors, ensures the stability and reliability of data transmission, supports rapid module integration, reduces system upgrade and expansion costs, and improves versatility and applicability.
Smart Images

Figure CN120802880B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial automation control technology, and in particular to a method and system for self-testing and recovering the address of I / O modules in a DCS system and for fault location. Background Technology
[0002] In modern power plant automation control, the distributed control system (DCS) is the core component ensuring the efficient and safe operation of power generation equipment. Within DCS, the data processing unit (DPU) and I / O modules achieve distributed communication through address matching, directly impacting system response speed and control accuracy. Achieving efficient collaboration between these two components is crucial for improving power plant production stability and energy utilization, and is a key technology for the intelligent development of the power industry. Currently, existing technologies have significant shortcomings in the complex environment of power plants. For example, electromagnetic interference from high-power equipment leads to increased address signal error rates, temperature and humidity fluctuations affect component stability, and mechanical vibration exacerbates connection failures. In the data link layer, problems such as address conflicts, signal attenuation, and protocol mismatches occur frequently, causing communication blockages, data verification failures, and timing disorders, severely affecting data acquisition accuracy and even causing control loop failures.
[0003] To address these issues, we have designed a method and system for DCS system I / O module address self-test recovery and fault location. Summary of the Invention
[0004] The purpose of this invention is to address the shortcomings of existing technologies, such as increased address signal error rate due to electromagnetic interference, address conflicts, signal attenuation, protocol mismatch, etc., which cause communication blockage, data verification failure, and timing disorder. This invention proposes a method and system for address self-test recovery and fault location of DCS system I / O modules.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: A method for address self-test recovery and fault location of DCS system I / O modules includes the following steps: Step 1: System configuration. The data processing unit is connected to multiple I / O modules via a communication bus, and the data processing unit is connected to the engineering station via a network cable. The data processing unit identifies the I / O module through the unique address configured for each I / O module. Step 2: After the system signals and power supply stabilize, the I / O module performs the first address latch and verification. After comparing the latched address with the real-time address multiple times, it outputs a stable address. Step 3: The data collected by the I / O module is transmitted to the data processing unit via the communication bus. After being summarized by the data processing unit, it is sent to the engineering station via the network cable. The control commands of the engineering station are parsed by the data processing unit and forwarded to the corresponding I / O module via the communication bus to complete the data interaction. Step 4: Real-time parity check is used to verify the communication bus. When a parity error or abnormal communication bus level is detected, dynamic reconstruction of the communication bus is triggered, and field-programmable logic devices are used to dynamically reconstruct the communication bus. Step 5: When the communication bus hardware fault detection passes, but the data processing unit and the I / O module communication is abnormal, the data processing unit starts the self-test mechanism and retransmission strategy, and marks the I / O module fault and abnormal address.
[0006] Further, in step two, after completing the system configuration, wait for the power and signal to stabilize. During the system startup phase, perform the initial address latch and verification of the I / O module: After the system receives the start command, when the address latch and dynamic verification module is working, it enters the initialization standby state when the reset signal is valid. In the initialization standby state, it completes the initialization operations of clearing the check count and resetting the timeout count to zero, and starts the timeout countdown to prepare for address verification.
[0007] Furthermore, during the initialization operation, a mapping table between the communication bus and the redundant bus is established.
[0008] Furthermore, in step two, after repeatedly comparing the latched address with the real-time address to ensure consistency, the process of outputting the stable address is as follows: After the I / O module completes the initial address latch and verification, it enters the countdown monitoring state. In the countdown monitoring state, the timeout count is continuously checked. If no timeout occurs, the countdown monitoring state is maintained and the countdown continues. After the countdown ends, it switches to the initial latch state. In the initial latch state, the address is latched for the first time and the timeout countdown restarts. Then it moves to the secondary countdown monitoring state to continuously monitor the timeout countdown. After the countdown ends, it enters the address comparison state. When executing the address comparison state, the system compares the real-time address with the previously latched address. If the two are the same and the number of checks is greater than 0, the number of checks is reduced and the system returns to the first latch state for the next round of checks. If the number of checks reaches the preset number, the system jumps to the check pass state, outputs the current address, enters the address ready state, sets the address valid signal, marks the address as ready, and outputs a stable address.
[0009] Furthermore, in step four, parity checking is used to perform real-time hardware-level communication bus verification. When a parity error or abnormal communication bus level is detected, dynamic reconstruction of the communication bus is triggered, including the following: The status of the parallel communication bus is monitored in real time. The data transmitted on the bus is verified at the hardware level using parity check technology. If a verification error or abnormal bus level is detected for three consecutive clock cycles, the communication bus is immediately dynamically reconfigured and switched to the available line of the two redundant buses to continue working.
[0010] Furthermore, step four, using field-programmable logic devices (FPGAs) for dynamic reconfiguration of the communication bus, includes: when a communication failure occurs between the data processing unit and the I / O module, or when the data processing unit receives multiple communication message responses from at least two I / O modules to the same address within a specified time, resulting in data conflicts and inability to accurately obtain the required information, the data processing unit first sends an identification signal through the communication bus and the redundant bus when the two communication messages are idle. When the I / O module receives the correct data, it returns the identification signal. After the data processing unit receives the correct return data, the bus fault detection is completed, and normal message interaction is then performed. If the transmitted and received data are inconsistent after the communication bus fault detection is completed, dynamic reconfiguration of the communication bus is initiated. Based on the established mapping table between the communication bus and the redundant bus, the switching path is directly determined, and the redundant bus is reconfigured to construct a new transmission path.
[0011] Furthermore, in step five, if the communication bus hardware fault detection passes, but the communication between the data processing unit and the I / O module is abnormal, the data processing unit initiates a self-test mechanism, as follows: The data processing unit sequentially polls and sends broadcast self-test messages according to the I / O module addresses. After receiving the broadcast self-test message, the I / O module performs an address self-test, comparing the current address with the power-on latched address. If they match, the I / O module outputs the current address and sends a correct signal to the data processing unit; if they do not match, the I / O module outputs the latched address as the current I / O module address and sends an error feedback signal to the data processing unit. The data processing unit compares the feedback information from the I / O modules. If all I / O module addresses send correct signals, but the data processing unit still receives multiple communication message responses from at least two I / O modules to the same address within a specified time, the engineering station will display a module fault and mark the I / O module as faulty. If the I / O module detects an address inconsistency during address self-test, it will automatically restore the latched address, restore the abnormal address, and attach a diagnostic code to locate the I / O module fault.
[0012] Furthermore, when the bus hardware fault detection passes but communication between the data processing unit and the I / O module is abnormal, the data processing unit initiates a self-test process. For unresponsive I / O modules, the data processing unit initiates a retransmission strategy. After the data processing unit sends a broadcast self-test message, it sets a timer. If no response is received from a certain I / O module within the specified time, it will resend the message. If there is still no response, the I / O module will be marked as faulty, and the fault code will be displayed on the engineering station. The unit will actively check the I / O module. After receiving the message, the I / O module will add a tag to the response type value and feed it back to the engineering station to display the I / O module's abnormal address.
[0013] A system for address self-test recovery and fault location of I / O modules in a DCS system, the system comprising an engineering workstation, a data processing unit and I / O modules; The data processing unit is connected to the engineering workstation via a network cable and physically connected to the I / O module via a communication bus interface. The I / O module includes a communication protocol parsing module, an address comparison module, and an address latching and dynamic verification module. The processor of the I / O module uses an FPGA device. The communication protocol parsing module is connected to the communication bus and parses the communication protocol between the I / O module and the data processing unit. The address comparison module establishes a connection with the communication protocol parsing module and the address latching and dynamic verification module. The address latching and dynamic verification module performs initialization operations on the I / O module, verifies the address, and sends the latched address to the address comparison module. The address comparison module performs address self-test, compares the current address with the power-on latched address, and sends a feedback signal to the communication protocol parsing module.
[0014] Compared with existing technologies, the beneficial effects of this invention are as follows: The address detection and latching enhancement mechanism plays a crucial role in the startup phase. Combined with multiple verifications of the latched address, it effectively reduces the system's sensitivity to external environmental interference, minimizes address conflicts and communication errors, and provides a solid foundation for stable system operation. Through the triggered I / O module self-test and address conflict handling optimization mechanism, I / O module address errors can be quickly identified. I / O module self-tests resolve address conflicts or configuration problems. The retransmission strategy and fault marking mechanism further enhance the reliability and flexibility of the I / O module, ensuring accurate real-time address identification and supporting rapid integration of new modules. A parallel communication bus fault detection and recovery mechanism is also included. When communication is abnormal, the system accurately locates the fault and utilizes dynamic bus reconfiguration to ensure transmission continuity with minimal redundant resources, effectively preventing control loop failures. The system architecture and processing scheme exhibit excellent compatibility. The design, based on the unique address identification of each I / O module to initiate the corresponding communication waveform, enables seamless integration with various I / O modules of different models and specifications. This eliminates the need for complex hardware or software adaptations for different modules, significantly reducing the cost and difficulty of system upgrades and expansions. It also allows users to flexibly select and replace I / O modules according to their actual needs, improving the system's versatility and applicability, and contributing to the widespread application of DCS systems in different industries and application scenarios. Attached Figure Description
[0015] Figure 1 This is a flowchart illustrating the method for address self-test recovery and fault location of DCS system I / O modules proposed in this invention. Figure 2 This is a schematic diagram of the address latching dynamic verification process in the DCS system I / O module address self-test recovery and fault location method proposed in this invention; Figure 3 This is a block diagram of the logical composition of the system proposed in this invention for the method of address self-test recovery and fault location of DCS system I / O modules. Detailed Implementation
[0016] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0017] A method for address self-test recovery and fault location of DCS system I / O modules, such as... Figure 1 As shown, the method includes the following steps: Step one, system configuration, consists of an engineering workstation, a data processing unit (DPU), and various functional I / O modules. The DPU connects to multiple I / O modules via a communication bus and to the engineering workstation via a network cable. To ensure the DPU can accurately identify and communicate with each I / O module, it uses a unique address configured for each module. Three flexible configuration methods are provided: physical encoding, software settings, and automatic hardware identification, which can be selected according to actual site requirements. Through address configuration, each I / O module has a unique "identity," enabling the DPU to accurately address data during transmission. This provides an address foundation for stable operation and accurate data interaction after system startup, avoiding communication errors caused by address confusion. The I / O modules all use general-purpose domestic FPGA devices or MCUs as core processors, covering various types such as digital input / output modules to meet the real-time acquisition and precise control needs of power plants for various data types. The communication bus adopts a parallel bus to achieve high-speed and stable data transmission; at the same time, a network cable is used to establish a connection between the data processing unit and the engineering station, building a full-link data transmission channel from field data acquisition, central processing to the issuance of operation instructions.
[0018] It should be noted that the communication waveforms between the I / O modules and the Data Processing Unit (DPU) are diverse, covering reading module types, reading digital input data, burst reading of multiple words without specifying an address, writing digital output data, reading multiple words at a specified address, reading a single word at a specified address, writing a single word at a specified address, and writing multiple words at a specified address. To improve design efficiency, the system employs communication function waveform multiplexing technology, using the unique address identification of the I / O module to initiate the corresponding communication waveform. Therefore, the address of all I / O modules must be uniquely set.
[0019] Step two: After the system signals and power supply stabilize, the I / O module performs the first address latch and verification. After comparing the latched address with the real-time address multiple times, it outputs a stable address.
[0020] In this step, such as Figure 2 As shown, after completing the system configuration, wait for the power and signal to stabilize. During the system startup phase, perform the first address latch and verification of the I / O module: After receiving the start command, the system waits 200ms to allow the power supply and signals to stabilize. When the address latch and dynamic verification module is working, it enters the initialization standby state when the reset signal is valid. In the initialization standby state, it completes the initialization operations of clearing the check count and resetting the timeout count to zero, and starts the timeout countdown to prepare for address verification.
[0021] During initialization, a mapping table between the communication bus and the redundant bus is established. When a fault occurs, the switching path can be quickly determined directly based on this mapping table without temporary calculation, which greatly improves the switching speed.
[0022] Address verification, the process of outputting a stable address after repeatedly comparing the latched address with the real-time address, is as follows: After the I / O module completes the initial address latch and verification, it enters the countdown monitoring state. In the countdown monitoring state, the timeout count is continuously checked. If no timeout occurs, the countdown monitoring state is maintained and the countdown continues. After the countdown ends, it switches to the initial latch state. In the initial latch state, the address is latched for the first time and the timeout countdown restarts. Then, it moves to the secondary countdown monitoring state. The logic of the secondary countdown monitoring state is similar to that of the countdown monitoring state. It continuously monitors the timeout countdown. After the countdown ends, it enters the address comparison state.
[0023] When executing the address comparison state, the system compares the real-time address with the previously latched address. If the two are the same and the number of checks is greater than 0, the number of checks is reduced and the system returns to the first latch state for the next round of checks. If the number of checks reaches the preset number (in this embodiment, the preset number can be set to 3 times), the system jumps to the check passed state, outputs the current address, enters the address ready state, sets the address valid signal, marks the address ready, and outputs a stable address.
[0024] If the address does not match, the check count is reset to 3, and the system returns to the initial latch state for rechecking. The address ready state is the final state, in which the address validity signal remains at 1. If an unexpected situation occurs, the system is immediately reset back to the initial standby state.
[0025] This dynamic verification mechanism ensures accurate address latching through multiple matching processes, enhancing the system's adaptability and fault tolerance to environmental changes, thereby improving the system's reliability and stability.
[0026] Step 3: The data collected by the I / O module is transmitted to the data processing unit via the communication bus. After being summarized by the data processing unit, it is sent to the engineering station via the network cable. The control commands of the engineering station are parsed by the data processing unit and forwarded to the corresponding I / O module via the communication bus to complete the data interaction.
[0027] To address the issue of address signal transmission errors caused by inconsistencies in clock domains between different modules within the FPGA, a cross-clock domain address handling mechanism is employed, ensuring accurate system startup addresses while mitigating the risk of errors. By introducing a double buffer as temporary storage for address signals, secure signal transmission between different clock domains is achieved, effectively avoiding misreading issues caused by clock asynchrony. Signal synchronization is achieved using D flip-flops, and a validity flag is set to determine signal validity. Address signals are latched only when the validity flag is valid, effectively preventing misreading and data conflicts caused by clock asynchrony, ensuring reliable address signal transmission between modules, and significantly reducing the risk of verification errors caused by signal interference and attenuation. This improves communication reliability between different modules and ensures the accuracy and stability of data transmission. This management mechanism is particularly suitable for cross-clock sections of the system, providing a solid guarantee for the stable operation of the FPGA system.
[0028] Step four: Use parity check to perform real-time communication bus verification. When a verification error or abnormal communication bus level is detected, trigger dynamic reconstruction of the communication bus and use field-programmable logic devices to perform dynamic reconstruction of the communication bus.
[0029] This includes triggering dynamic reconfiguration of the communication bus, quickly identifying physical link problems through a parallel bus hardware detection mechanism, and performing real-time hardware-level communication bus verification using parity checking. For example, when a parity error or abnormal communication bus level is detected for three consecutive clock cycles, dynamic reconfiguration of the communication bus is triggered, including the following: The status of the parallel communication bus is monitored in real time. The data transmitted on the bus is verified at the hardware level using parity check technology. If a verification error or abnormal bus level is detected for three consecutive clock cycles, the communication bus is immediately dynamically reconfigured and switched to the available line of the two redundant buses to continue working.
[0030] Dynamic reconfiguration of the communication bus using field-programmable logic devices (FPGAs) includes: when a communication failure occurs between the data processing unit and the I / O module, or when the data processing unit receives multiple communication message responses from at least two I / O modules to the same address within a specified time, resulting in data conflicts and inability to accurately obtain the required information, the communication anomaly may be caused by factors such as I / O module failure, parallel communication bus failure, or signal interference.
[0031] When two communication frames are idle, the data processing unit first sends an identification signal through the communication bus and the redundant bus. When the I / O module receives the correct data, it returns the identification signal. After the data processing unit receives the correct return data, it completes the bus fault detection and then performs normal message interaction. If the transmitted and received data are inconsistent after the communication bus fault detection is completed, the dynamic reconstruction of the communication bus is initiated. According to the established mapping table between the communication bus and the redundant bus, the switching path is directly determined, the redundant bus is reconfigured, and a new transmission path is constructed to achieve redundancy with fewer bus resources.
[0032] Step 5: When the communication bus hardware fault detection passes, but the communication between the data processing unit and the I / O module is abnormal (such as timeout, data conflict, or multiple responses at the same address), the data processing unit starts the self-test mechanism and retransmission strategy, and marks the I / O module fault and abnormal address.
[0033] When the communication bus hardware fault detection passes, but the communication between the data processing unit and the I / O module is abnormal, the data processing unit initiates a self-test mechanism, as follows: The data processing unit sequentially polls and sends broadcast self-test messages according to the I / O module addresses. After receiving the broadcast self-test message, the I / O module performs an address self-test, comparing the current address with the power-on latched address. If they match, the I / O module outputs the current address and sends a correct signal to the data processing unit. If they do not match, the I / O module outputs the latched address as the current I / O module address and sends an error feedback signal to the data processing unit. The data processing unit compares the feedback information from the I / O modules. If all I / O module addresses send correct signals, but the data processing unit still receives multiple communication message responses from at least two I / O modules to the same address within a specified time, the engineering station will display a module fault and mark the I / O module as faulty.
[0034] If the I / O module detects an address inconsistency during address self-test, it will automatically restore the latched address, restore the abnormal address, and attach a diagnostic code (the diagnostic code can be 8 bits) to locate the I / O module fault, making it easier to quickly locate the problem.
[0035] The broadcast self-test message includes a start identifier, message length, control word, data field, checksum field, and end identifier. Finally, based on feedback from the data processing unit, the engineering workstation updates and displays the error function codes of the corresponding I / O modules in real time, enabling operators to quickly identify and handle potential address conflicts or configuration errors.
[0036] When the bus hardware fault detection passes, but communication between the data processing unit and the I / O module is abnormal, the data processing unit initiates a self-test process. For unresponsive I / O modules, the data processing unit initiates a retransmission strategy. After the data processing unit sends a broadcast self-test message (which can be retransmitted up to 3 times), it sets a timer. After the first transmission, an exponential backoff timer of 100ms is set, and the timer duration doubles with each retry. If no response is received from an I / O module within the specified time, it will retransmit. If there is still no response, the I / O module is marked as faulty, and a fault code is displayed on the engineering station. The unit actively checks the I / O module. After receiving the message, the I / O module adds a tag to the response type value and feeds it back to the engineering station to display the I / O module's fault address.
[0037] like Figure 3 As shown, this embodiment also proposes a system for address self-test recovery and fault location of I / O modules in a DCS system. This system consists of an engineering workstation, a DPU (Data Processing Unit), and several I / O modules. This embodiment uses a single I / O module as an example. The I / O module determines its address through any method such as DIP switches, software settings, or automatic hardware identification. Its core processor uses a general-purpose FPGA device. The communication bus interface includes high / low data (HI / LO), data input / output (IN / OUT), address (Addr), read data (Data), write data (Latch), communication enable (Ack), feedback (Xack), parity check (PARITY), communication bus control interface (XRD), and redundant bus.
[0038] An engineer workstation is a computer in a DCS system used to configure process control software, diagnose and monitor the operation of process control stations, and is used by DCS engineers to develop, test, and maintain the DCS system.
[0039] The data processing unit (DPU) is connected to the engineering workstation via a network cable, and the data processing unit is physically connected to multiple I / O modules via a communication bus interface.
[0040] The I / O module includes a communication protocol parsing module, an address comparison module, and an address latching and dynamic verification module. The communication protocol parsing module is connected to the communication bus and parses the communication protocol between the I / O module and the data processing unit. The address comparison module establishes a connection with the communication protocol parsing module and the address latching and dynamic verification module. The address latching and dynamic verification module performs initialization operations on the I / O module, verifies the address, and sends the latched address to the address comparison module. The address comparison module performs address self-test, compares the current address with the power-on latched address, and sends a feedback signal to the communication protocol parsing module.
[0041] In addition, the I / O modules also include digital input modules, digital output modules, eight-channel DC analog signal acquisition modules, eight-channel RTD signal measurement modules, eight-channel thermocouple signal measurement modules, eight-channel DC analog output modules, eight-channel pulse counting modules, and other special modules.
[0042] The technical solution provided by this invention plays a crucial role in stability through the address detection and latch enhancement mechanism during the startup phase. After system power-on, a 200ms stabilization period is allowed, coupled with multiple checks of the latched address, effectively reducing the system's sensitivity to transient interference and minimizing communication errors, thus providing a solid foundation for stable system operation. The clock domain crossing management mechanism employs a double-buffer strategy, D-flip-flop synchronization technology, and validity flags to ensure secure signal transmission between different clock domains, avoiding misreadings caused by clock asynchrony, reducing the risk of verification errors due to signal interference and attenuation, and comprehensively improving the reliability of communication between different modules of the system, ensuring stable system operation.
[0043] In terms of reliability, the I / O module self-test and address conflict handling optimization mechanism triggered by the Data Processing Unit (DPU) enables the DPU to quickly identify module address errors and notify the I / O module to perform self-tests via broadcast self-test messages, promptly detecting and resolving address conflicts or misconfigurations. The retransmission strategy and fault marking mechanism further enhance the reliability and flexibility of the I / O modules, ensuring accurate real-time address identification and supporting rapid response and seamless integration of new modules. The parallel communication bus fault detection and recovery mechanism can accurately analyze the cause of faults when communication is abnormal. By sending specific data to detect the bus, it quickly switches redundant buses, enhancing the system's fault tolerance, improving fault diagnosis accuracy, and significantly improving system reliability in complex environments.
[0044] In terms of data processing efficiency, the parallel communication bus fault detection and recovery mechanism can quickly switch over in the event of a bus failure, reducing communication interruption time and ensuring the continuity of data transmission. Meanwhile, the clock domain traversal management mechanism ensures accurate and stable data transmission, providing strong support for efficient data processing in practical industrial applications, improving the overall system operating efficiency and security, and is of great significance to fields such as industrial production.
[0045] In terms of compatibility, the architecture and processing scheme of this invention exhibit excellent compatibility. The communication function waveform multiplexing technology and the design based on the unique address identification of the I / O module to initiate the corresponding communication waveform enable the system to seamlessly interface with various I / O modules of different models and specifications, without requiring complex hardware or software adaptation adjustments for different modules. This significantly reduces the cost and difficulty of system upgrades and expansions, allowing users to flexibly select and replace I / O modules according to actual needs, improving the system's versatility and applicability, and contributing to the widespread application of DCS systems in different industries and application scenarios.
[0046] It should be noted that any parts not covered in this invention are the same as or can be implemented using existing technology. The above description is merely a preferred embodiment of this invention, but the scope of protection of this invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in this invention, based on the technical solution and inventive concept of this invention, should be covered within the scope of protection of this invention.
Claims
1. A method for address self-test recovery and fault location of DCS system I / O modules, characterized in that, Includes the following steps: Step 1: System configuration. The data processing unit is connected to multiple I / O modules via a communication bus, and the data processing unit is connected to the engineering station via a network cable. The data processing unit identifies the I / O module through the unique address configured for each I / O module. Step 2: After the system signals and power supply stabilize, the I / O module performs the first address latch and verification. After comparing the latched address with the real-time address multiple times, it outputs a stable address. Step 3: The data collected by the I / O module is transmitted to the data processing unit via the communication bus. After being summarized by the data processing unit, it is sent to the engineering station via the network cable. The control commands of the engineering station are parsed by the data processing unit and forwarded to the corresponding I / O module via the communication bus to complete the data interaction. Step 4: Real-time parity check is used to verify the communication bus. When a parity error or abnormal communication bus level is detected, dynamic reconstruction of the communication bus is triggered, and field-programmable logic devices are used to dynamically reconstruct the communication bus. Step 5: When the communication bus hardware fault detection passes, but the data processing unit and the I / O module communication is abnormal, the data processing unit starts the self-test mechanism and retransmission strategy, and marks the I / O module fault and abnormal address.
2. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 1, characterized in that, Step two: After completing the system configuration, wait for the power and signal to stabilize. During the system startup phase, perform the initial address latch and verification of the I / O module. After the system receives the start command, when the address latch and dynamic verification module is working, it enters the initialization standby state when the reset signal is valid. In the initialization standby state, it completes the initialization operations of clearing the check count and resetting the timeout count to zero, and starts the timeout countdown to prepare for address verification.
3. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 2, characterized in that, During initialization, a mapping table between the communication bus and the redundant bus is established.
4. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 3, characterized in that, Step two, after repeatedly comparing the latched address with the real-time address to ensure they match, the process of outputting the stable address is as follows: After the I / O module completes the initial address latch and verification, it enters the countdown monitoring state. In the countdown monitoring state, the timeout count is continuously checked. If no timeout occurs, the countdown monitoring state is maintained and the countdown continues. After the countdown ends, it switches to the initial latch state. In the initial latch state, the address is latched for the first time and the timeout countdown restarts. Then it moves to the secondary countdown monitoring state to continuously monitor the timeout countdown. After the countdown ends, it enters the address comparison state. When executing the address comparison state, the system compares the real-time address with the previously latched address. If the two are the same and the number of checks is greater than 0, the number of checks is reduced and the system returns to the first latch state for the next round of checks. If the number of checks reaches the preset number, the system jumps to the check pass state, outputs the current address, enters the address ready state, sets the address valid signal, marks the address as ready, and outputs a stable address.
5. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 1, characterized in that, Step four: Perform real-time hardware-level communication bus verification using parity checking. When a parity error or abnormal communication bus level is detected, trigger dynamic reconstruction of the communication bus, including the following: The status of the parallel communication bus is monitored in real time. The data transmitted on the bus is verified at the hardware level using parity check technology. If a parity error or abnormal bus level is detected for three consecutive clock cycles, the bus is immediately dynamically reconfigured and switched to an available line in the two redundant buses to continue working.
6. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 5, characterized in that, Step four, dynamic reconfiguration of the communication bus using field-programmable logic devices, includes: When a communication failure occurs between the data processing unit and the I / O module, or when the data processing unit receives multiple communication message responses from at least two I / O modules to the same address within a specified time, resulting in data conflict and inability to accurately obtain the required information, the data processing unit first sends an identification signal through the communication bus and the redundant bus when the two communication frames are idle. When the I / O module receives the correct data, it returns the identification signal. After the data processing unit receives the correct return data, the bus fault detection is completed, and normal message interaction is then performed. If the transmitted and received data are inconsistent after the communication bus fault detection is completed, the dynamic reconstruction of the communication bus is initiated. Based on the established mapping relationship table between the communication bus and the redundant bus, the switching path is directly determined, the redundant bus is reconfigured, and a new transmission path is constructed.
7. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 1, characterized in that, Step 5: When the communication bus hardware fault detection passes, but the communication between the data processing unit and the I / O module is abnormal, the data processing unit starts a self-test mechanism, as follows: The data processing unit sequentially polls and sends broadcast self-test messages according to the I / O module addresses. After receiving the broadcast self-test message, the I / O module performs an address self-test, comparing the current address with the power-on latched address. If they match, the I / O module outputs the current address and sends a correct signal to the data processing unit; if they do not match, the I / O module outputs the latched address as the current I / O module address and sends an error feedback signal to the data processing unit. The data processing unit compares the feedback information from the I / O modules. If all I / O module addresses send correct signals, but the data processing unit still receives multiple communication message responses from at least two I / O modules to the same address within a specified time, the engineering station will display a module fault and mark the I / O module as faulty. If the I / O module detects an address inconsistency during address self-test, it will automatically restore the latched address, restore the abnormal address, and attach a diagnostic code to locate the I / O module fault.
8. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 7, characterized in that, When the bus hardware fault detection passes, but communication between the data processing unit and the I / O module is abnormal, the data processing unit initiates a self-test process. For unresponsive I / O modules, the data processing unit initiates a retransmission strategy. After the data processing unit sends a broadcast self-test message, it sets a timer. If no response is received from a certain I / O module within the specified time, it retransmits the message. If there is still no response, the I / O module is marked as faulty, and a fault code is displayed on the engineering station. The unit actively checks the I / O module. After receiving the message, the I / O module adds a tag to the response type value and feeds back to the engineering station to display the I / O module's abnormal address.
9. The method for address self-test recovery and fault location of DCS system I / O modules according to claim 7, characterized in that, The broadcast self-test message includes a start identifier, message length, control word, data field, check field, and end identifier.
10. A system applied to the method for address self-test recovery and fault location of DCS system I / O modules according to any one of claims 1-9, characterized in that, The system includes an engineering workstation, a data processing unit, and I / O modules; The data processing unit is connected to the engineering workstation via a network cable and physically connected to the I / O module via a communication bus interface. The I / O module includes a communication protocol parsing module, an address comparison module, and an address latching and dynamic verification module. The processor of the I / O module uses an FPGA device. The communication protocol parsing module is connected to the communication bus and parses the communication protocol between the I / O module and the data processing unit. The address comparison module establishes a connection with the communication protocol parsing module and the address latching and dynamic verification module. The address latching and dynamic verification module performs initialization operations on the I / O module, verifies the address, and sends the latched address to the address comparison module. The address comparison module performs address self-test, compares the current address with the power-on latched address, and sends a feedback signal to the communication protocol parsing module.
Citation Information
Patent Citations
Method for communication redundant data during address communication on multi-path multi-use address / data bus
CN101189593A
Parallel communication system based on FPGA
CN117609138A