Double-CPU redundant PLC master-slave switching method and system for nuclear power industry

By employing dual-CPU redundancy design and real-time heartbeat monitoring and data synchronization, the problems of long master-slave switching time and poor stability of PLCs in the nuclear power industry have been solved, achieving fast and reliable master-slave switching and system stability.

CN121348938APending Publication Date: 2026-01-16CGN DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511494878.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

In the nuclear power industry, the switching time for PLC master-slave switching in existing technologies is relatively long, and the stability of the system after switching is difficult to guarantee.

Method used

The system employs a dual-CPU redundancy design, using FPGA modules and hardwiring to achieve real-time heartbeat monitoring and data synchronization between CPUs. Combined with network communication, it ensures rapid switching between master and slave modes in the event of CPU failure. Redundancy is also achieved through hardwiring and network to ensure the consistency of application programs and running data.

Benefits of technology

It enables fast and reliable master-slave switching in the event of CPU failure, avoiding dual-master or dual-slave scenarios, ensuring system stability and data consistency, and guaranteeing seamless system switching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121348938A_ABST
    Figure CN121348938A_ABST
Patent Text Reader

Abstract

The invention discloses a double-CPU redundant PLC master-slave switching method and system for the nuclear power industry. The method comprises the steps that S1, when two CPUs are powered on, the two CPUs continuously monitor the heartbeat of each other; s2, according to a first preset rule, one CPU is set to be in a master CPU mode, and the other CPU is set to be in a slave CPU mode; s3, the CPU in the slave CPU mode actively synchronizes the application program of the CPU in the master CPU mode; s4, the CPU in the master CPU mode synchronizes state data and operation data to the CPU in the slave CPU mode; and S5, when one CPU is abnormal or reset, the two CPUs run after switching the master-slave mode states according to a second preset rule. According to the double-CPU redundant PLC master-slave switching method and system for the nuclear power industry, when the master CPU breaks down, the other CPU can be immediately switched to enter the master CPU mode to work, and the switching reliability of the system can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A method and system for master-slave switching of dual-CPU redundant PLCs in the nuclear power industry Technical Field This invention belongs to the field of nuclear power system technology, and in particular relates to a dual-CPU redundant PLC master-slave switching method and system for the nuclear power industry. Background Technology

[0002] In the nuclear power industry, programmable logic controllers (PLCs) are used as controllers for related non-safety equipment. However, these non-safety equipment in nuclear power plants also require high reliability and safety. In this system, redundancy design is typically used to improve system safety. When one PLC fails, another PLC can immediately take over and control the entire system without disruption. The most complex aspects are when to switch over, the lengthy switching time, and ensuring system stability after the switch. Summary of the Invention

[0003] In order to solve the problems in the prior art, the present invention aims to provide a dual-CPU redundant PLC master-slave switching method and system for the nuclear power industry, which can immediately switch the other CPU to work in the master CPU mode when the CPU in the master CPU mode fails, and can ensure the reliability of the system switching.

[0004] To achieve the above objectives, this invention provides a dual-CPU redundant PLC master-slave switching method for the nuclear power industry, comprising the following steps: S1: When the two CPUs are powered on, they begin to continuously monitor each other's heartbeats; S2: According to the first preset rule, set the master-slave mode of one CPU to master CPU mode, and set the master-slave mode of another CPU to slave CPU mode; S3: The application program of the CPU in the slave CPU mode actively synchronizes with the CPU in the master CPU mode; S4: The CPU in the master CPU mode synchronizes status data and running data with the CPU in the slave CPU mode; S5: When one of the CPUs malfunctions or is reset, the two CPUs switch between master and slave modes according to the second preset rule and then run.

[0005] In one implementation, the two CPUs are each connected to an FPGA module, the two CPUs are connected via network communication, and the two CPUs are connected via at least six hardwired connections between their respective FPGA modules. In step S1: when the two CPUs are powered on at the same time, they begin to continuously monitor each other's heartbeats through the first hardwire and the second hardwire, respectively.

[0006] As an implementation form, in the S2 step, the first preset rule is that: The master-slave mode state of the CPU with the smaller backplane slot number is set to the master CPU mode, and the master-slave mode state of the CPU with the larger backplane slot number is set to the slave CPU mode.

[0007] As an implementation form, in the S2 step: After the CPU determines the master-slave mode state of itself, the two CPUs respectively send the master-slave mode state of themselves to the other CPU through the third hardwired line and the fourth hardwired line.

[0008] As an implementation form, in the S3 step: The CPU in the slave CPU mode actively synchronizes the application program of the CPU in the master CPU mode through the network.

[0009] As an implementation form, in the S4 step: The CPU in the master CPU mode sends and synchronizes the state data and the running data to the CPU in the slave CPU mode through the network, the fifth hardwired line and the sixth hardwired line.

[0010] As an implementation form, in the S5 step, when a CPU monitors that the network communication of another CPU is timed out, there is no heartbeat, the fifth hardwired line communication is timed out and the sixth hardwired line communication is timed out, it is judged that the CPU is abnormal or reset.

[0011] As an implementation form, the S5 includes the steps of: S51: When a CPU is abnormal or reset, the CPU which is not abnormal or reset judges the master-slave mode state of itself: when the master-slave mode state is the master CPU mode, the master-slave mode state is kept unchanged; when the master-slave mode state is the slave CPU mode, the master-slave mode state is changed to the master CPU mode and runs, and when the CPU whose original master-slave mode state is the master CPU mode is restarted and initialized, the master-slave mode state is changed to the slave CPU mode and runs; S52: When a CPU is restarted and initialized, the heartbeat and the master-slave mode state of another CPU which is not restarted are monitored: when the master-slave mode state of the CPU which is not restarted is the master CPU mode, the CPU which is restarted sets the master-slave mode state to the slave CPU mode and runs.

[0012] As an implementation form, each CPU is respectively connected with an IO module through two CCU modules; after the S4 step, the method further includes the steps of: When the CPU in the master CPU mode monitors that the communication with the CCU module and the IO module is timed out, and the CPU in the slave CPU mode monitors that the communication with the CCU module and the IO module is normal, the master-slave mode state of the CPU in the master CPU mode is changed to the slave CPU mode, and the master-slave mode state of the CPU in the slave CPU mode is changed to the master CPU mode.

[0013] The application discloses a double-CPU redundant PLC master-slave switching system for a nuclear power industry. Two CPUs are connected through network communication. Two FPGA modules are connected to the two CPUs respectively. At least six hardwires are arranged between the two FPGA modules to connect the two CPUs. Two CCU modules are arranged. An IO module is connected to each CPU through the two CCU modules. A heartbeat monitoring module is arranged to monitor the heartbeat of the other CPU when the two CPUs are powered on. A master-slave mode setting module is arranged to set the master-slave mode state of one CPU to the master CPU mode and set the master-slave mode state of the other CPU to the slave CPU mode according to a first preset rule. An application program synchronization module is arranged to synchronize the application program of the CPU in the master CPU mode to the CPU in the slave CPU mode. A running data synchronization module is arranged to synchronize the state data and running data of the CPU in the master CPU mode to the CPU in the slave CPU mode. An abnormality or reset switching module is arranged to switch the master-slave mode state of the two CPUs according to a second preset rule and then run when one CPU is abnormal or reset.

[0014] The application has the following beneficial effects: In the application, the two CPUs interact with each other through a network and seven hardwires provided by respective FPGA modules, when the CPU judges that the other CPU appears network communication timeout, no heartbeat and FPGA simulated serial communication timeout, the system immediately switches the master-slave mode state, the master-slave mode state switching must simultaneously satisfy the three conditions, so as to satisfy the reliability of the system switching, avoid the occurrence of double master or double slave; the timeout time is set to 2-3 times the communication cycle time, so as to ensure that the system can quickly switch when a problem occurs; the network is a gigabit network, which is used to synchronize the application program and the running data of the master-slave CPU, the serial port simulated by the FPGA module synchronizes the state data and the running data through the hardwire, and forms redundancy with the network, so as to ensure that the application program and the running program of the two CPUs are consistent, so the master-slave disturbance-free switching can be ensured. When the master CPU is abnormal or restarts, the slave CPU immediately disturbance-free switches to the master CPU, and when the slave CPU is abnormal and restarts, the master CPU still runs in the state of the master CPU. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0016] Figure 1 The bottom plate connection structure schematic diagram of the dual-CPU redundant PLC master-slave switching method for nuclear power industry of the embodiment of the present application; Figure 2 The connection structure schematic diagram of the two CPUs of the dual-CPU redundant PLC master-slave switching method for nuclear power industry of the embodiment of the present application; Figure 3 The connection structure schematic diagram of the system of the dual-CPU redundant PLC master-slave switching method for nuclear power industry of the embodiment of the present application; Figure 4 The flow chart of the dual-CPU redundant PLC master-slave switching method for nuclear power industry of the embodiment of the present application. DETAILED DESCRIPTION

[0017] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0018] Please refer to Figure 2 andFigure 4 The embodiment of the application is a double-CPU redundant PLC master-slave switching method for the nuclear power industry, comprising the following steps: S1: When the two CPUs are powered on, start continuously monitoring the heartbeat of each other; The two CPUs are respectively connected to a FPGA module, and the two CPUs are connected through network communication and at least six hard-wired communication connections set between the corresponding FPGA modules. In this embodiment, the network uses a gigabit network, mainly for synchronizing the application programs and data in the running process of the two CPUs.

[0019] In the S1 step: When the two CPUs are powered on at the same time, start continuously monitoring the heartbeat of each other through the first hard-wired 91 and the second hard-wired 92 respectively.

[0020] In this embodiment, the first CPU 1 is connected to the first FPGA module 81, the second CPU 4 is connected to the second FPGA module 82, the first CPU 1 and the second CPU 4 are connected through network communication, and the first CPU 1 and the second CPU 4 are connected through at least six hard-wired communication connections set between the first FPGA module 81 and the second FPGA module 82. When the first CPU 1 and the second CPU 4 are powered on, start continuously monitoring the heartbeat of each other through the first hard-wired 91 and the second hard-wired 92 respectively.

[0021] The FPGA module, the first hard-wired 91 and the second hard-wired 92 detect the heartbeat signal in real time through hardware, the response speed is fast, and it does not depend on the software state. Even if the target CPU is completely deadlocked, enters an abnormal state, the FPGA module can still accurately determine whether the heartbeat is stopped.

[0022] S2: According to the first preset rule, set the master-slave mode state of one CPU to master CPU mode, and set the master-slave mode state of the other CPU to slave CPU mode. Please refer to Figure 1 In the S2 step, the first preset rule is: Set the master-slave mode state of the CPU with a smaller slot number of the bottom plate 7 to master CPU mode, and set the master-slave mode state of the other CPU with a larger slot number of the bottom plate 7 to slave CPU mode.

[0023] In the S2 step: After the CPU determines its own master-slave mode state, the two CPUs respectively send their own master-slave mode state to each other through the third hard-wired 93 and the fourth hard-wired 94.

[0024] In this embodiment, the slot numbers on the base plate 7 increase sequentially from left to right. When the two CPUs are powered on together, the master-slave mode of the first CPU 1 with the smaller slot number is set to master CPU mode, and the master-slave mode of the second CPU 4 is set to slave CPU mode.

[0025] The first CPU1 can obtain the heartbeat of the second CPU through the second hardwired connection, and the second CPU can also obtain the heartbeat of the first CPU1 through the first hardwired connection. However, neither of them can obtain the master-slave status of the other through the third and fourth hardwired connections.

[0026] Once the first CPU1 and the second CPU4 determine their own master-slave mode status, the first CPU1 and the second CPU4 respectively send their own master-slave mode status to each other through the third hardwire 93 and the fourth hardwire 94.

[0027] S3: The application program of the CPU in the slave CPU mode actively synchronizes with the CPU in the master CPU mode; In step S3: The CPU in slave CPU mode actively synchronizes the application program of the CPU in master CPU mode through the network, thereby ensuring that the application programs running on the CPU in master CPU mode and the CPU in slave CPU mode are consistent, so that the system can still maintain normal operation and use the same application programs after a subsequent switch.

[0028] In this embodiment, the second CPU4 in slave CPU mode actively synchronizes the application of the first CPU1 in master CPU mode through the network.

[0029] S4: The CPU in the master CPU mode synchronizes status data and running data with the CPU in the slave CPU mode; In step S4: The CPU in the master CPU mode sends and synchronizes the status data and the running data to the CPU in the slave CPU mode via the network, the fifth hardwire 95, and the sixth hardwire 96.

[0030] In this embodiment, the first CPU1 in the master CPU mode sends and synchronizes the running status and running data to the second CPU4 in the slave CPU mode through the network, the fifth hardwire 95 and the sixth hardwire 96 in each task cycle; thereby ensuring that the variable values ​​of the CPU in the master CPU mode and the CPU in the slave CPU mode are the same, so as to achieve seamless switching between master and slave.

[0031] The serial port simulated by the FPGA module synchronizes status data and running data through hardwiring, forming redundancy with the network. This ensures that the application programs and running programs of the two CPUs are consistent, thus guaranteeing seamless master-slave switching.

[0032] S5: When one of the CPUs malfunctions or is reset, the two CPUs switch between master and slave modes according to the second preset rule and then run.

[0033] In step S5, when one of the CPUs detects that the network communication of another CPU has timed out, there is no heartbeat, the fifth hardwire 95 communication has timed out, and the sixth hardwire 96 communication has timed out, it is determined that the CPU has malfunctioned or needs to be reset.

[0034] In this embodiment, the communication timeout is set to 2 to 3 times the communication cycle time to ensure that the system can switch quickly when problems occur.

[0035] The S5 includes the following steps: S51: When one of the CPUs experiences an error or resets, the CPUs that do not experience an error or reset determine their own master-slave mode state; when the master-slave mode state is master CPU mode, the master-slave mode state remains unchanged; when the master-slave mode state is slave CPU mode, the master-slave mode state is changed to master CPU mode and the CPU runs; when the CPU whose original master-slave mode state was master CPU mode restarts and initializes, the master-slave mode state is changed to slave CPU mode and the CPU runs. S52: When one of the CPUs restarts and initializes, the heartbeat and master-slave mode status of the other CPU that has not restarted are monitored: when the master-slave mode status of the non-restarted CPU is master CPU mode, the restarted CPU sets the master-slave mode status to slave CPU mode and runs.

[0036] Taking the failure of the first CPU1 in the system of this embodiment as an example: When the second CPU4 detects that the network communication of the first CPU1 has timed out, there is no heartbeat, the communication of the fifth hardwire 95 has timed out, and the communication of the sixth hardwire 96 has timed out, it determines that the first CPU1 has an abnormality or has been reset. The second CPU4 determines its own master-slave mode status; if the current master-slave mode status is slave CPU mode, the second CPU4's master-slave mode status is changed to master CPU mode. Then, when the first CPU1 restarts and initializes, it monitors the heartbeat of the second CPU4 and the master-slave mode status; the master-slave mode status of the second CPU4 is master CPU mode, and the restarted first CPU1 sets the master-slave mode status to slave CPU mode.

[0037] Taking the failure of the second CPU4 in the system of this embodiment as an example: When the first CPU1 detects that the network communication of the second CPU4 has timed out, there is no heartbeat, the communication of the fifth hardwire 95 has timed out, and the communication of the sixth hardwire 96 has timed out, it determines that the second CPU4 has malfunctioned or has been reset. The first CPU1 determines its own master-slave mode status; if the current master-slave mode status is master CPU mode, then the master-slave mode status of the first CPU1 remains master CPU mode. Then, when the second CPU4 restarts and initializes, it monitors the heartbeat of the first CPU1 and the master-slave mode status; the master-slave mode status of the first CPU1 is master CPU mode, and the restarted second CPU4 sets the master-slave mode status to slave CPU mode.

[0038] In this embodiment, each CPU is communicatively connected to an I / O module 5 via two CCU modules; the step S4 is followed by the following step: When the CPU in the master CPU mode detects a communication timeout with the CCU module and the IO module 5, and the CPU in the slave CPU mode detects normal communication with the CCU module and the IO module 5, the master-slave mode state of the CPU in the master CPU mode is changed to slave CPU mode, and the master-slave mode state of the CPU in the slave CPU mode is changed to master CPU mode.

[0039] In this embodiment, the first CPU1 is communicatively connected to the IO module 5 through the first CCU module 2 and the second CCU module 3; the second CPU4 is communicatively connected to the IO module 5 through the first CCU module 2 and the second CCU module 3; taking the CPU in the current main CPU mode as the first CPU1 and the CPU in the secondary CPU mode as the second CPU4 as an example: When the first CPU1 in master CPU mode detects a communication timeout between the first CCU module 2, the second CCU module 3, and the IO module 5, and the second CPU4 in slave CPU mode detects that the communication between the first CCU module 2, the second CCU module 3, and the IO module 5 is normal, the master-slave mode of the first CPU1 is changed to slave CPU mode, and the master-slave mode of the second CPU4 is changed to master CPU mode.

[0040] Please see Figures 1-3 An embodiment of the present invention provides a dual-CPU redundant PLC master-slave switching system based on the dual-CPU redundant PLC master-slave switching method for the nuclear power industry described in this invention, comprising: Two CPUs are connected via network communication; in this embodiment, the CPUs include a first CPU1 and a second CPU4. Two FPGA modules are provided, and the two CPUs are respectively connected to one of the FPGA modules; in this embodiment, the FPGA module includes a first FPGA module 81 and a second FPGA module 82. At least six hardwires are provided, and the two CPUs are connected via the hardwires between the two FPGA modules. Two CCU modules; In this embodiment, the CCU module is a central communication unit, and the CCU module includes a first CCU module 2 and a second CCU module 3; One IO module 5, each of the CPUs is connected to the IO module 5 through two CCU modules respectively; A heartbeat monitoring module is used to continuously monitor each other's heartbeats when the two CPUs are powered on. A master-slave mode setting module is used to set the master-slave mode state of one CPU to master CPU mode and the master-slave mode state of another CPU to slave CPU mode according to a first preset rule. An application synchronization module is used to actively synchronize the application of the CPU in slave CPU mode with the application of the CPU in master CPU mode. A data synchronization module is used to synchronize status data and running data between the CPU in master CPU mode and the CPU in slave CPU mode; and An exception or reset switching module is provided, which is used to switch the master-slave mode state of the two CPUs according to a second preset rule when one of the CPUs experiences an exception or reset.

[0041] In this embodiment, the hardwired connections include a first hardwire 91, a second hardwire 92, a third hardwire 93, a fourth hardwire 94, a fifth hardwire 95, a sixth hardwire 96, and a seventh hardwire 97. The first and second hardwires 91 and 92 are used to transmit heartbeat signals between the two CPUs; the third and fourth hardwires 93 and 94 are used to transmit master-slave mode status signals between the two CPUs; the fifth and sixth hardwires 95 and 96 serve as input / output serial ports for data transmission; and the seventh hardwire 97 is a spare line. The IO module 5 includes a DIO module 51, an AIO module 52, an RS module 53, a CAN communication unit 54, and a DP communication unit 55. The DIO module 51 is a digital input / output unit, the AIO module 52 is an analog output / output unit, and the RS module 53 is a serial communication unit. It also includes a first power supply module 61 and a second power supply module 62 for power supply.

[0042] In this embodiment, the heartbeat monitoring module is used to continuously monitor each other's heartbeats through the first hardwire 91 and the second hardwire 92 when the two CPUs are powered on at the same time. The first preset rule is: set the master-slave mode of the CPU with the smaller slot number in slot 7 of the base plate to master CPU mode, and set the master-slave mode of the other CPU with the larger slot number in slot 7 of the base plate to slave CPU mode.

[0043] In this embodiment, the master-slave mode setting module is further used to: after the CPU determines its own master-slave mode state, the two CPUs respectively send their own master-slave mode state to each other through the third hardwire 93 and the fourth hardwire 94.

[0044] In this embodiment, the application synchronization module is used for the CPU in slave CPU mode to actively synchronize the application of the CPU in master CPU mode through the network.

[0045] In this embodiment, the running data synchronization module is used by the CPU in the master CPU mode to send and synchronize the running data to the CPU in the slave CPU mode through the network, the fifth hardwire 95 and the sixth hardwire 96.

[0046] In this embodiment, the fault or reset switching module further performs the following steps: When one of the CPUs detects that the network communication of another CPU has timed out, there is no heartbeat, the fifth hardwire 95 communication has timed out, and the sixth hardwire 96 communication has timed out, it is determined that the CPU has malfunctioned or has been reset. S51: When a CPU experiences an error or reset, the CPU that does not experience an error or reset determines its master-slave mode state; when the master-slave mode state is master CPU mode, the master-slave mode state remains unchanged; when the master-slave mode state is slave CPU mode, the master-slave mode state of the CPU that did not experience an error or reset is changed to master CPU mode. S52: When one of the CPUs restarts and initializes, the heartbeat and master-slave mode status of the other CPU that has not restarted are monitored; when the master-slave mode status of the non-restarted CPU is master CPU mode, the restarted CPU sets the master-slave mode status to slave CPU mode; when the master-slave mode status of the non-restarted CPU is slave CPU mode, the restarted CPU sets the master-slave mode status to master CPU mode.

[0047] In this embodiment, a communication fault switching module is also included, which is used to change the master-slave mode of the CPU in the master CPU mode to slave CPU mode and the master-slave mode of the CPU in the slave CPU mode to master CPU mode when the CPU in the master CPU mode detects a communication timeout with the CCU module and the IO module 5, and the CPU in the slave CPU mode detects that the communication with the CCU module and the IO module 5 is normal.

[0048] In this embodiment of the invention, the two CPUs interact with each other via a network and seven hardwired connections provided by their respective FPGA modules. When a CPU determines that the other CPU has experienced a network communication timeout, no heartbeat, or a serial communication timeout simulating the FPGA, the system immediately switches the CPU to master-slave mode. This master-slave mode switch must simultaneously meet these three conditions to ensure system reliability and avoid dual-master or dual-slave scenarios. The timeout period is set to 2-3 times the communication cycle time to ensure rapid switching in case of problems. The network is a gigabit network used to synchronize the application programs and running data of the master and slave CPUs. The serial port simulated by the FPGA module synchronizes status and running data via hardwired connections, creating redundancy with the network. This ensures that the application programs and running programs of both CPUs are consistent, thus guaranteeing a seamless master-slave switch. When the master CPU malfunctions or restarts, the slave CPU immediately and seamlessly switches to become the master CPU. When the slave CPU restarts abnormally, the master CPU continues to operate as the master CPU.

[0049] It should be noted that while the preferred embodiments of the present invention are provided in the specification and accompanying drawings, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are not intended to impose additional limitations on the content of the present invention; their purpose is to provide a more thorough and comprehensive understanding of the disclosure of the present invention. Furthermore, the above-described technical features can be combined with each other to form various embodiments not listed above, all of which are considered to be within the scope of the present invention specification. Moreover, those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.

[0050] The present invention has been described in detail above with reference to the accompanying drawings and embodiments. Those skilled in the art can make various modifications to the present invention based on the above description. Therefore, certain details in the embodiments should not be construed as limiting the present invention, and the scope of protection of the present invention shall be defined by the appended claims.

Claims

1. A master-slave switching method for dual-CPU redundant PLCs in the nuclear power industry, comprising the steps of: S1: starting mutual continuous monitoring of the heartbeat of the other CPU when both CPUs are powered on; S2: setting the master-slave mode state of one CPU to master CPU mode and setting the master-slave mode state of the other CPU to slave CPU mode according to a first preset rule; S3: the CPU in slave CPU mode actively synchronizes the application program of the CPU in master CPU mode; S4: the CPU in master CPU mode synchronizes state data and running data to the CPU in slave CPU mode; S5: when one CPU has an exception or is reset, both CPUs switch the master-slave mode state according to a second preset rule and then run.

2. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 1, characterized in that, Both CPUs are connected to a FPGA module, and the two CPUs are connected by network communication, and the two CPUs are connected by at least six hardwires set between the corresponding FPGA modules; In the S1 step: when both CPUs are powered on, they start mutual continuous monitoring of the heartbeat of the other CPU through the first and second hardwires.

3. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 2, characterized in that, In the S2 step, the first preset rule is: setting the master-slave mode state of the CPU with a smaller backplane slot number to master CPU mode and setting the master-slave mode state of the other CPU with a larger backplane slot number to slave CPU mode.

4. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 2 or 3, characterized in that, In the S2 step: After the CPU determines its master-slave mode state, both CPUs send their master-slave mode state to the other CPU through the third and fourth hardwires.

5. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 4, characterized in that, In the S3 step: The CPU in slave CPU mode actively synchronizes the application program of the CPU in master CPU mode through the network.

6. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 5, characterized in that, In the S4 step: The CPU in master CPU mode sends and synchronizes the state data and running data to the CPU in slave CPU mode through the network, the fifth hardwire, and the sixth hardwire.

7. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 6, characterized in that, In the S5 step, when one CPU monitors that the network communication of the other CPU is timed out, there is no heartbeat, the fifth hardwire communication is timed out, and the sixth hardwire communication is timed out, it is determined that the CPU has an exception or is reset.

8. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 7, characterized in that, The S5 includes the steps of: S51: when one CPU has an exception or is reset, the CPU that has not had an exception or been reset determines its master-slave mode state: when the master-slave mode state is master CPU mode, the master-slave mode state remains unchanged; when the master-slave mode state is slave CPU mode, the master-slave mode state is changed to master CPU mode and runs, and when the CPU whose original master-slave mode state is master CPU mode is restarted and initialized, the master-slave mode state is changed to slave CPU mode and runs; S52: when one CPU is restarted and initialized, monitor the heartbeat and master-slave mode state of the other CPU that has not been restarted: when the master-slave mode state of the CPU that has not been restarted is master CPU mode, the restarted CPU sets the master-slave mode state to slave CPU mode and runs.

9. The master-slave switching method of dual-CPU redundant PLC for nuclear power industry according to claim 8, characterized in that, Each of the CPUs is in communication connection with an IO module through two CCU modules; the S4 step further comprises the steps of: When the CPU in the master CPU mode detects that the communication with the CCU module and the IO module is timed out, and the CPU in the slave CPU mode detects that the communication with the CCU module and the IO module is normal, the master-slave mode state of the CPU in the master CPU mode is changed to the slave CPU mode, and the master-slave mode state of the CPU in the slave CPU mode is changed to the master CPU mode.

10. A dual CPU redundant PLC master-slave switching system for nuclear power industry according to the master-slave switching method of any one of claims 1 to 9, characterized in that, Comprise: Two CPUs, the two CPUs are in communication connection through a network; Two FPGA modules, each of the two CPUs is connected with one of the FPGA modules; At least six hardwires, the two CPUs are in communication connection through the hardwires arranged between the two FPGA modules; Two CCU modules; An IO module, each of the CPUs is in communication connection with the IO module through the two CCU modules; A heartbeat monitoring module, used for starting to continuously monitor the heartbeat of the other CPU when the two CPUs are powered on; A master-slave mode setting module, used for setting the master-slave mode state of one of the CPUs to the master CPU mode and setting the master-slave mode state of the other CPU to the slave CPU mode according to a first preset rule; An application program synchronization module, used for the CPU in the slave CPU mode to actively synchronize the application program of the CPU in the master CPU mode; A running data synchronization module, used for the CPU in the master CPU mode to synchronize the state data and the running data to the CPU in the slave CPU mode; And An exception or reset switching module, used for switching the master-slave mode state of the two CPUs according to a second preset rule and then running when an exception or reset occurs in one of the CPUs.