Method and device for performing software updates in system formed by plurality of entities, in particular machines and / or devices, in particular in industrial environment
By coordinating the timing and parameters of software updates in an industrial environment, the downtime caused by inter-device dependencies was resolved, enabling uninterrupted software updates and shortening system-level activation time.
Patent Information
- Application Number
- CN202480049870.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-07-28
- Filing Date
- 2024-07-03
- Publication Date
- 2026-02-27
AI Technical Summary
In industrial environments, due to the interdependencies between devices, software updates typically require downtime, resulting in high costs and prolonged downtime, making uninterrupted updates impossible.
By distributing software updates to various entities and coordinating local installations in a timely manner, and by using relevant parameters and dynamic physical quantities for coordination, we can ensure that startup and system-level activation occur at the optimal time and avoid interruptions.
It enables uninterrupted software updates in industrial environments, shortens the duration of system-level activation, and reduces downtime and costs.
Smart Images

Figure CN121586893A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The invention relates to a method for performing a software update in a system formed by a plurality of entities, in particular machines and / or devices, in particular in an industrial environment, according to the preamble of claim 1, and to an apparatus for performing a software update in a system formed by a plurality of entities, in particular machines and / or devices, in an industrial environment, according to the preamble of claim 13. BACKGROUND
[0002] It is known that, for example in an industrial environment, the software update, i.e. the loading and commissioning of software upgrades and software updates (in the context of this disclosure, both are used synonymously) of a complex system consisting of a plurality of devices or machines, is more challenging than for a simple system consisting of one or a few devices. The reason for this is mainly due to the fact that, in a networked production cell, which is common in industrial environments, there are always dependencies between the devices due to their interaction in the manufacturing process, in particular more extensive dependencies in terms of whether and how the devices communicate with each other.
[0003] Here, the new software version usually contains error fixes (so-called "bug-fixes") and / or functional extensions, which often affect not a single device, but an entire group of devices.
[0004] If, for this purpose, the devices are provided with the new software version in sequence in the industrial environment, the entire system or production usually has to be completely stopped. This is particularly true if the new software version leads to a change in the interaction with the environment or other (production) devices.
[0005] Since this is almost the norm, the disadvantage is that, according to the prior art, it is common practice to update the devices involved only when the system is down, i.e. for example when the production facility is down. This involves a lot of work, can take a long time and is associated with high costs. SUMMARY
[0006] The invention is therefore based on the object of specifying a solution to overcome the disadvantages of the prior art, in particular the object of specifying a solution in which a software update can be performed as interruption-free as possible while a process in an industrial environment is ongoing.
[0007] The method for performing a software update in a system formed by a plurality of entities, in particular machines and / or devices, in an industrial environment, according to the preamble of claim 1, is achieved by its features and the apparatus according to the preamble of claim 11 is achieved by its characteristic features.
[0008] In a method for performing a software update in a system formed by a plurality of entities, in particular machines and / or devices, in particular in an industrial environment, a software update is distributed to the entities and a local installation of the software update on the entities is performed in time coordinated with one another, such that, depending on at least one parameter related to at least the respective entity, at least a start, a flow and / or a system-wide activation of the respective local software update is performed at a time point individually assigned to the entities.
[0009] The invention enables an interruption-free installation of a software update or software upgrade, in particular in an industrial environment, in that for each entity a start, a flow and / or a system-wide activation can be performed individually at an optimal time point, since a consideration of the relevant parameters of the respective local installation is possible, such that no disturbances occur which would cause an interruption. Furthermore, based on this consideration, further optimizations are possible. For example, the total duration until the system-wide activation can be shortened.
[0010] Apparatus for performing a software update in a system formed by a plurality of entities, in particular machines and / or devices, in particular in an industrial environment, characterized by means for performing the method and / or one of its extensions.
[0011] The apparatus according to the invention enables the method according to the invention and / or its extensions, and thereby, with necessary modifications, the advantages of the method and / or its extensions.
[0012] Advantageous design and extension of the invention are described by the dependent claims.
[0013] According to an extension of the method according to the application, for the coordination at least one entity-related variable is taken into account which influences the process time, such as delay times, switching times, influences on the entity embedded in the overall system, device types, success of software updates and other influencing variables, in particular time-critical influencing variables, as relevant parameters. By taking one or more entity-related variables into account, the application can also take individual characteristics of the entities into account for the coordination which leads to the optimization, and here, dynamic physical quantities, i.e. physical quantities which change during operation, and / or fixed variables, which can be given, for example, by the type of device or machine, the mode of operation, the operating parameters, such as the physical properties of the environment of use, and / or the settings, are added. A failed installation on an entity can be at least time-critical and can even cause a complete breakdown of the system-level update. This can also be solved with the current extension, since, for example, the system-level activation is only carried out after a successful feedback has been received, and / or, in time, only after such a feedback, a separate activation time point is specified for the coordination / scheduling of the activation. Here, a previous negative feedback can be followed by a positive feedback, for example, after an error handler has been executed.
[0014] Alternatively or preferably in addition, the method according to the application can be extended in such a way that, for the coordination, at least one system-related variable is taken into account which influences the process time, such as system utilization, system size, system complexity, system components and other influencing variables, in particular time-critical influencing variables, as relevant parameters. In this way, an overall consideration is achieved which takes into account the interaction of the entities in the system and its consequences, so that the optimization is further improved by taking one or more of the influencing physical quantities which exist due to the system into account for the coordination. Here, too, dynamic and fixed physical quantities can be used.
[0015] For this purpose, the method according to the application is preferably extended in such a way that, in particular by means of the central entity, at least one variable is provided which influences the process time and which can be called up by manual input and / or automatic detection. In this way, it can be ensured in the method according to the application that current values are always available for the optimization, which can be fixedly supplemented or replaced for each entity once for the method for the specified relevant parameters.
[0016] In general, in systems, in particular systems used in industrial environments, there is one or more control devices, i.e. entities, which provide control functions and / or master functions for other entities of the system in terms of master / slave functionality. The method according to the application is thus extended in such a way that a control device functionally related to the system, in particular integrated in a control device of the system, is operated as a central authority, which enables easy implementation of the method according to the application into the system, while avoiding changes to the known structure as far as possible.
[0017] If the method according to the application is extended in such a way that, for coordination, the local times of the entities are synchronized to a value, in particular a value in the range of a maximum deviation of + / - 100 ns, by the central authority, there is one of the values particularly suitable for optimization for this coordination. Here, this can include a one-time operation or a repeated operation, in particular a periodically repeated operation, which causes the synchronization, so that the synchronization is always ensured.
[0018] If the method according to the application is extended in such a way that, for coordination, the entities can be operated in such a way that, in particular by operating suitable hardware, a time base (known as a so-called "Clock") of the entities is ensured, which has a system-adapted accuracy, in particular in the range of 1 ppm to 100 ppm. "System-adapted accuracy" means that depending on the system type, which can differ, for example, depending on the field of application / case of application, the ensured accuracy value can change. "Ensured" means that the value is to be followed exactly, for each system, as a separate target value. This enables flexible use of the application, for example in power plants, in industrial environments and / or in earthquake-related applications, such as raw material extraction in the upstream industry, for example oil production or mining. For example, earthquake-related applications will generally require an accuracy in the range of 1 ppm, while, for example, for applications in industrial environments, the application can generally be implemented with lower accuracy, for example in the range of 100 ppm. In this case, "in the range of" means that the sufficient accuracy value according to the application is ultimately determined by the relevant parameters and / or system adaptation. These range boundaries or their values should thus not be seen as hard limits, but rather the actually implemented values can well exceed or be below these limits, in particular taking into account the hardware used. However, for actual values in the ranges mentioned above, in particular in the above-mentioned cases of application, the best results can be expected when using the application.
[0019] If, for the purpose of synchronization, these entities are at least once transmitted, in particular a "Global Positioning System" GPS time and / or an absolute time specified by a high-precision, in particular satellite-based, time reference system, as well as a local time, there is a further advantageous extension of the method according to the application. Via this, the device is enabled at one or more, in particular periodically repeated, time points to always have a reference for at least partially separate execution time points within the framework of a start, a procedure and / or a system-level activation, which ensures that the time difference between the entities is a minimum value, in particular "zero".
[0020] If the method according to the application is operated in such a way that, for the purpose of coordination, the system, in particular the entities, is operated according to the so-called "Precision Timing Protocol" PTP, in particular according to IEEE 1588-2008, there is an implementation that is particularly suitable for implementing the application. This protocol provides a series of functions that can be implemented using the application. These functions are also proven and easy to implement and have a low complexity. Thus, by appropriately modifying, for example, the driver software, it is possible to retrofit parts of the existing hardware to execute the method according to the application. There are also hardware that can be obtained cost-effectively in the form of Ethernet PHY chips, which already use this protocol and which can be used in or implemented together with the device according to the application.
[0021] In particular when the method according to the application is extended in such a way that: a) a software update is distributed to the entities that make up the system; b) the entities store the respective software update locally on the entities; c) for each entity, a time is specified on the entity for the local execution of the software update; d) the respective local times of the entities are synchronized; e) the local software update is installed based on the time specification until the software update has been completed on all entities that have stored the software update; f) after the completion of all locally executed software updates, the software updated by the software update is activated system-wide at a separately specified time point. Via this, it is ensured that on all entities, the new software is used almost simultaneously, i.e. taking into account delays, which are compensated with regard to the disturbing influences by the separate time points according to the application, etc.
[0022] In this case, "after completion" means that the installation on the respective device has successfully ended. That is, according to the application, advantageously, there is a separate activation point in time within the framework of the system-level activation only after completion in time, i.e. only when the condition is met that the entire system is not brought into an uncontrolled state due to a failed individual installation. This can be achieved, for example, in such a way that the separate point in time is planned only after completion; and / or in such a way that the system-level update is started at the separately distributed point in time of activation only after feedback of the completion of the installation, and / or is suspended until the successful completion has been fed back.
[0023] In particular by this extension, the multi-stage nature of the method according to the application is highlighted, which can consist in that: • it is possible to install the new software version as early as possible, in particular during the running of the old version and in particular while the previous SW (software) version is running, for example, there is already enough time to detect data and to build up the state according to the new software without being able to influence the output / environment; and • it is possible to activate or hand over the control to the new SW version, for example by the output / control, at a precisely defined and possibly device-specific point in time of the coordinated system-level switch (activation), and still to allow a coordinated interaction of the devices during the switch.
[0024] By this approach, it is ensured that the new version can reliably, seamlessly and without major interruptions take over the control.
[0025] Alternatively or additionally, the method according to the application can be extended in such a way that the entities are operated in that, before the point in time of the system-level activation of the updated software, a debugging of the updated software is carried out on the entity for which the installation of the software update has been completed, so that the real detectable mode of action, in particular the state and the functionality, of the entity is determined by the previous software version for the time of the parallel running and, after the debugging, by the updated software. This can further improve the above-mentioned compensation, since the new software is essentially running, but according to the application is operated in a sandboxed manner so that it does not have an impact on the outside. Thereby, the switch can take place almost immediately and "seamless" for the respective entity and the system.
[0026] An advantageous extension of the method according to the application is given in that on the entities, the activation is triggered by sending a message, by reaching a specified start time point and / or at least a time point derivable from the flow of the entities, the activation being triggered in particular by the control device upon completion of all locally performed software updates. By this, the switchover can be controlled and performed in order to contribute to an optimization. BRIEF DESCRIPTION OF DRAWINGS
[0027] Further advantages and details of the application are explained on the basis of the embodiments shown or described in the only drawing. Herein: The drawing schematically shows an embodiment of the method according to the application, which is explained together with features of an embodiment of the device according to the application. DETAILED DESCRIPTION
[0028] The embodiments explained in the following in the drawing are preferred embodiments and extensions of the application.
[0029] In the embodiments, the described components of the embodiments are respectively individual features of the application, which are to be considered independently of one another, which respectively extend the application independently of one another and which can therefore also be considered components of the application individually or in other combinations than the ones shown.
[0030] Furthermore, the described embodiments can also be supplemented by other features of the already described features of the application.
[0031] In the drawing, an embodiment of the method according to the application is schematically shown in the form of a flow chart. The flow of the method according to the application requires a device designed according to the application, so that for the understanding of the embodiment of the application, the features of the embodiment are explained in advance and together with the method features.
[0032] An embodiment of the device according to the application, in which all machines, i.e. all devices, of a system are intended to be able to implement a software update performed according to the application, mainly has the features explained in the following.
[0033] For example, according to the embodiment of the device, the devices involved have a mechanism for upgrading / updating while running.
[0034] The mechanism can for example be implemented in the form of a "seamless upgrade" mode, which enables the parallel execution of old and new versions and a controlled switchover between the two with a known delay. This can be done in a controlled manner using existing controllers or processors, so that this functions like a module providing the above-mentioned functions (parallel execution, coordinated switchover) or is an implementation variant of this module.
[0035] Since, generally, in such a system there will be a processor / controller, this can also be brought into the system as a computer program product and executed in a controlled manner.
[0036] Equating or specifying the time value on all machines as a further feature of an embodiment of the device according to the application. "Equating" in the context of the application or in a system with transit times and delays means that a minimum deviation is allowed as a tolerance. For example, according to an embodiment of the application, the time on all devices will be synchronized with a deviation of approximately + / - 100 ns.
[0037] To this end, an embodiment of the application provides that all devices support PTP (Precision Timing Protocol, IEEE 1588-2008), according to which, according to the embodiment, PTP provides precise time by a central entity via a precision clock generator, the so-called GPS and "Miniatur Atomic Clock" MAC.
[0038] Here, PTP has the advantage that, unlike the known NTP (Network Timing Protocol), it takes into account the transit times in the network (Internet) and can take into account different signal transit times.
[0039] According to an embodiment of the method according to the application, each machine uses the PTP protocol on the one hand in such a way that it executes the method steps according to or based on the protocol, i.e. as implemented software, but on the other hand also based on a platform that supports this in hardware (example: Ethernet Phy: "Broadcom BCM5421").
[0040] With the embodiment of the method according to the application and the device according to the application, which supports PTP on the software and hardware side, the application can implement the transmission and coordination of precise time information between various devices in a simple and efficient manner, especially in networks formed in an industrial environment, and here, one or more functions of PTP are utilized, such as time stamping, delay compensation, periodic updating, and measures to ensure accurate precision and compensation.
[0041] Here, the time stamping can be implemented by the central device periodically generating timing messages, which can be designed as so-called sync frames and subsequent frames, which are sent to the devices. These frames contain a time stamp reflecting the point in time of transmission and thus provide a reference value at regular intervals.
[0042] This can be implemented, for example, using the PTP protocol in conjunction with a Linux driver, and then has to be adopted into the application programs on the entities respectively.
[0043] Delay compensation can be carried out by means of timestamps obtaining the timing messages from the central entity, calculating the transmission delays, and compensating the transmission delays accordingly in order to achieve a more precise synchronization.
[0044] This is carried out, for example, at the hardware level, in particular the so-called physical layer, for example by means of a PHY chip.
[0045] According to PTP, it is possible to determine the central entity, alternatively or in addition, for example, the device with the most precise internal clock can be selected as the central authority. In particular in an industrial environment, as an extension, the use of an immutable entity, for example an existing control device, would have a beneficial effect, for example because this can be implemented into the existing structure less complex and / or with a minimum of effort.
[0046] For the exact precision and compensation, according to an extension, PTP can also use algorithms for calculating the precision of the internal clock of the device and for compensating for interference factors such as network delays and jitter in order to achieve a more precise synchronization.
[0047] By means of the PTP protocol, as an extension of the application, periodic updating of the synchronization information can be achieved, which has the advantage that deviations in the internal clock of the compensation node are compensated for and a constant precision is ensured.
[0048] In this embodiment, hardware support can advantageously be used as an extension of the device according to the application, which hardware support is present, for example, when using the "Ethernet PHY Broadcom BCM5421", which is present, for example, on a "Raspberry, Compute Modul 4 Platform", i.e. "CM4". However, alternatively or in addition, for example, a so-called ASIC can also be used as suitable hardware for this, which ASIC is only modified accordingly as support hardware with the driver software implementing the method according to the application.
[0049] In addition to the synchronization of the devices, an embodiment of the device according to the application also achieves the time precision required for carrying out the method according to the application.
[0050] To this end, in accordance with the embodiment, the local clock time of the device, i.e. Clock, is provided with sufficient accuracy, in the embodiment approximately 100 ppm. By this, in accordance with the experience of the present invention, it will generally be ensured in industrial environments that no significant time "drift" can occur even in the case of longer upgrade times. In other words, by this, any downtime of the PTP protocol is measured or taken into account accordingly.
[0051] In other applications of the present invention, different accuracy values can be used.
[0052] The present invention is not, however, limited to this. If the device, for example, has a local time reference with an accuracy of approximately 10 ppm, for example in the case of so-called "temperature compensated oscillators", then sufficient accuracy already exists in the system itself, so that the individual or all extensions mentioned in relation to the accuracy within the scope of the present disclosure can be dispensed with or designed in an alternative manner and, as long as they are covered by the scope of protection of the claims, fall within the present invention.
[0053] According to the extension of the present invention, therefore, the role of the system adaptivity is that the value depends on the application case, i.e. on the variables given by the system and / or on the requirements of the specific application case for the system, which variables also give or determine the relevant parameters. In the seismic exploration industry, the clocks used have an accuracy of 1 ppm in the temperature range of -40°C...80°C, in accordance with the experience of the present invention, for most industrial facilities, a value in the range of 1 ppm is not necessary, but of course, a more accurate value can still be specified there in order to make the method particularly robust.
[0054] The present invention entails that the switching points in time at which the respective devices of the system switch to the new software version are known for all devices involved and / or coordinated with one another in order to be able to implement a coordinated switch. This can be determined, for example, by system tests before the specification of these points in time.
[0055] However, in the first design variant of the present invention, this can also be achieved relatively easily, for example, by switching all devices at the same time, especially for simple systems. Alternatively or additionally, however, the present invention can also be extended in such a way that the switching takes place, especially partially with a time offset, on the basis of knowledge about the entire system, its processes, its communication patterns and its components.
[0056] Here, the present invention, especially the explained embodiments, can be extended in such a way that this knowledge is provided manually or, if necessary, also determined automatically.
[0057] The present application, in particular the embodiments presented and the extensions, makes it possible to coordinate and synchronize the upgrade (or update) of all the devices or machines involved, which can be centrally controlled and triggered, wherein "synchronization" means that the upgrade takes place at time points coordinated with one another, which are assigned with a time offset depending on the relevant parameters.
[0058] Here, the simple embodiment of the method according to the application, which is shown schematically in simplified form, can be implemented such that, starting from a first state Z1 in which the system with a plurality of entities, i.e. devices or machines, on which software is running, is in a running state, in a first step S1 it is identified that a software update is available. Even if not explicitly stated, the terms "update" and "upgrade" in this document always refer to one another and vice versa. The same applies to "machine(s)" and "device(s)".
[0059] This can be achieved, for example, by actively querying the system parameters, as shown in the figure, or can be triggered directly by a trigger signal. If, upon identification in the first step S1, it is found that a software update is available, embodiments of the method according to the application, in a second step, distribute the software update to the devices and each device stores the software update locally. The software update is to be understood as the data required for installation on the device, such as executable files and / or other data required in the scope of the update, in particular organized as files.
[0060] Such data can be, for example, configuration parameters (such as for programmable hardware, e.g. so-called "Field-Programmable Gate Arrays"), compiled code (so-called "source interpreted" code, e.g. Python code), images and / or other data with which the functionality of the device can be updated.
[0061] Here, in the first state Z1, the PTP-based functionality, as already explained, sets the synchronization and the local time of the devices, so that the shown embodiment is given for at least the time setting of the devices considered for the update / upgrade that are exactly coordinated with one another. Therefore, the measures provided, preferably according to PTP, are carried out for this purpose, in particular also periodically during the running.
[0062] However, the software update distributed in this way has not yet been installed or executed.
[0063] If no software update is available, the system remains running without the additional steps of this embodiment, which is symbolically represented by switching to the first state Z1. "Symbolically" means that even in the case where an update is identified, running is maintained, i.e. the system is always in the first state, but in this first state the steps according to the application are additionally performed.
[0064] Now, in a third step S3, the precise and, if necessary, individual first time points for installing the update and the precise individual second time points for subsequently activating the new version are distributed for each machine by the central entity. This can advantageously be performed by means of the PTP protocol, as already explained above.
[0065] These time points can be the same for a plurality of devices, but they can also differ depending on the device type, the upgrade behavior (switching delay) and the embedding of the device into the overall system.
[0066] Now, in a fourth step S4, a smooth switchover is made, for example by the central entity, in particular by means of messages and / or other signaling, that is to say the machines to which the distribution is directed will now independently and at their individual first time points start installing the upgrade; and / or in a fifth step S5, after the installation has been successfully completed, the new version will be activated when the respective second time point is reached. Alternatively or additionally, it is also conceivable that at least part of the devices to be addressed can do this without an external trigger, or that one of the two phases, the installation phase and the update phase, requires a trigger. Furthermore, it is also conceivable that the central entity which makes the distribution is a different entity of the system than the one which sets the trigger. That is to say, in particular the entity specified for performing one or more of the second to fourth steps S2... S4 acts as the central entity.
[0067] The installation time point only needs to be earlier than the moment of the activation time point, and the respective installation must have been successfully completed. By specifying the second time point, the new version is thus given sufficient time to start up, for example to build or take over its state. This multi-phase nature, which is given by the possibility of separate installation and separate activation which is performed precisely in time, supports the software update according to the application while running in a particularly effective manner.
[0068] With the approach shown, in particular the suspension of the activation until the optimum individual point in time in the fifth step S5, it is ensured that the behavior of all devices, for example all processes, functions, features and non-functional properties, is always compatible, since the system is scheduled by specifying the times according to the application in such a way that the installed software updates run on the respective devices, in particular in parallel to the old software version, so that the behavior of the device remains according to the old software version for the other devices, and only when the specified according to the application, in particular individually deviating, point in time is reached, does the situation change, i.e. from these points in time on, the behavior according to the updated software can also be seen for the other devices.
[0069] Here, the application can also be extended in such a way that with this extension, changes that have an influence on other devices, in particular on non-targeted devices, can also be taken into account accordingly.
[0070] Alternatively or additionally, feedback can be made after successful installation / activation as a further step not shown, so that in the event of individual installation failures, the update can be suspended until the failure is eliminated. It is also conceivable to extend the application in such a way that the second point in time is only precisely determined after all installations have been successfully completed, taking into account the relevant parameters, and is planned and specified individually for each device.
[0071] By means of feedback, error states can be responded to and, before activation, eliminated by means of error elimination programs.
[0072] Thus, with the application, the main advantage that can be achieved is that upgrades that are coordinated with one another are distributed to a plurality of devices, of the same or different type, in a coordinated manner while they are running.
[0073] Here, according to the advantageous design of the embodiment, the central clock generator or timer distributes the GPS time, i.e. the absolute time, once and the relative time with an accuracy of approximately + / - 100 ns by means of the PTP protocol by means of the MAC, wherein the application also takes into account here that depending on the time of day, it can take several minutes until all devices are synchronized to this time.
[0074] In the implementation of this distributed and coordinated upgrade according to the embodiment, it is ensured that the switching points in time of all devices are precisely coordinated with one another.
[0075] By this, it can be ensured that the new software versions start their operation at the correct point in time, but not necessarily simultaneously as described in the embodiment, and the behavior of all devices in the overall system is correctly coordinated with one another during and after the switch.
[0076] A further advantage of the present application and all its extensions falling within the scope of protection of the claims and combinations thereof is that with this method, the frequency of complete system or facility downtimes can be minimized, since instead, the simplified and cost-effective updating / upgrade process according to the application enables more frequent updates while running.
[0077] A further advantageous additional effect of the above-mentioned advantages is that by installing software versions simultaneously and switching between them, critical time periods are also minimized, during which power interruptions, in particular due to complete or partial switching off and on, or other events can lead to a failed upgrade, so that the devices involved can be completely unusable without corresponding precautions, such as support for automatic version rollback. However, as a further extension, the above-mentioned rollback can still advantageously complement the present application and thus counteract unforeseen states or negative consequences thereof.
[0078] The expressions used in the above show or imply grammatical gender and / or other features suitable for distinguishing between people or can be considered as doing so, without these expressions being discriminatory but rather inclusive, that is, all people, regardless of their established, self-accepted or assumed personal characteristics, are considered equal.
Claims
1. A method for performing software updates in a system comprised of multiple entities, particularly machines and / or equipment, especially in an industrial environment. Its features are, The software update is distributed to the entity, and the software update is installed locally on the entity in a time-coordinated manner, such that, based on at least one parameter associated with at least the respective entity, at a time point individually assigned to the entity, at least the corresponding local software update is initiated, processed, and / or activated at the system level.
2. The method according to the preceding claim, Its features are, To facilitate coordination, at least one entity-related variable that affects process time, such as delay time, switchover time, impact on the entity embedded in the system, device type, success or failure of the software update installation, and other time-critical variables, are considered as relevant parameters.
3. The method according to any one of the preceding two claims, Its features are, To facilitate coordination, at least one system-related variable that affects process time, such as system utilization, system size, system complexity, system components, and other variables that are particularly time-critical, should be considered as relevant parameters.
4. The method according to any one of the preceding two claims, Its features are, In particular, through a central entity, at least one variable that affects process time is provided, which can be invoked through manual input and / or automatic detection.
5. The method according to the preceding claim, Its features are, The control device, which operates in a functionally related manner to the system and is particularly integrated into the control unit of the system, serves as the central mechanism.
6. The method according to any one of the preceding claims, Its features are, For coordination purposes, the local time of the entities is synchronized to a certain value, particularly a value within a range of + / - 100 ns with a maximum deviation, through a central authority.
7. The method according to any one of the preceding claims, Its features are, In order to coordinate, the entity is operated such that the entity's known time reference, which is called a "clock," has system-adaptive accuracy, particularly in the range of 1 ppm to 100 ppm.
8. The method according to any one of the preceding two claims, Its features are, In order to synchronize, the entity is transmitted, at least once, in particular GPS time and / or absolute time and local time specified by a high-precision, especially satellite-based, time reference system.
9. The method according to any one of the preceding claims, Its features are, For coordination purposes, the system, and in particular the entity, operates in accordance with the so-called "Precise Timing Protocol" (PTP) as specified in IEEE 1588-2008.
10. The method according to any one of the preceding claims, Its features are, a) Distributing software updates to the entities that constitute the system; b) The entity stores the corresponding software updates locally on the entity; c) For each entity, specify the time on the entity for performing the software update locally; d) Synchronize the corresponding local time of the entity; e) Install local software updates based on time constraints until all entities for which the software update has been stored have completed their software updates; f) After all locally executed software updates are completed, at a separately designated time point, perform system-level activation of the software updated through the software updates.
11. The method according to any one of the preceding claims, Its features are, The entity operates in such a manner that, prior to the system-level activation of the updated software, debugging of the updated software is performed on the entity where the software update has been installed, decoupling the parallel operation of the updated software and the previous software version on the entity. This decouples the entity's verifiable mode of operation, especially its state and functions, from those of the previous software version during the parallel operation period, and from those of the updated software after debugging.
12. The method according to any one of the preceding claims, Its features are, On the entity, activation is triggered by sending a message, by reaching a specified start time point, and / or by a time point that can at least be deduced from the entity's process, particularly by the control device when all locally executed software updates are completed.
13. An apparatus for performing software updates in a system comprised of multiple entities, particularly machines and / or equipment, especially in an industrial environment, characterized in that: Apparatus for performing the method according to any one of the preceding claims.