Control logic hot update system, method and device
By working in tandem with the digital base station and the local controller, the control logic of the building automation system is updated hot, which solves the problem of equipment interruption during the controller update process and ensures the continuity and stability of equipment operation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-17
- Publication Date
- 2026-04-07
AI Technical Summary
In existing technologies, the controller of a building automation system must suspend control of the terminal devices during the update process, which leads to equipment service interruption, affects environmental stability and the continuous operation of critical equipment.
By working together with the local controller, the control logic can be hot-updated. The digital dock takes over the control authority and maintains the device operation. After the update is completed, the control authority is returned to the local controller to ensure a seamless switch.
It achieves seamless control of end devices during control logic updates, avoids interruption of device operation, and ensures the continuity and stability of control tasks.
Smart Images

Figure CN121806594A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of building automation technology, and in particular to a control logic hot update system, method and apparatus. Background Technology
[0002] Building Automation Systems (BAS) are the core of ensuring the comfortable, energy-efficient, and safe operation of modern buildings. This system connects a large number of local controllers deployed in the field via a network. These controllers are directly connected to end-user physical devices such as air conditioners, lighting, and water pumps, and execute preset control logic to achieve automated operation. To ensure continuous optimization of system functions and bug fixing, updating the internal control logic of the controllers is a routine maintenance requirement.
[0003] Currently, the common method for updating the logic of such controllers is remote program flashing. Specifically, maintenance personnel select the target controller through central management software, upload the new program file, and then issue an update command. Upon receiving the command, the controller stops the currently executing control task and enters program update mode. In this mode, the control output between the controller and the end devices is cut off. The controller resumes operation only after the new logic is written and the device restarts.
[0004] However, with existing technologies, the controller must suspend control of the terminal devices during the update process, which directly leads to service interruptions for the controlled physical equipment (such as operating air conditioning units). This interruption not only disrupts the stability and comfort of the building environment but may also pose a risk to the continuous operation of critical equipment. Summary of the Invention
[0005] This application provides a control logic hot update system, method, and apparatus to solve the problem in the prior art that the controller must suspend control of the end device during the update process.
[0006] In a first aspect, this application provides a control logic hot update system, method, and apparatus, including: a digital base and at least one local controller communicatively connected to the digital base; The local controller is configured as follows: In response to the control logic update command from the digital base station, the set of key operating status parameters representing the current operating status is uploaded to the digital base station, the execution of the current control logic is paused, and the control authority over the terminal device is transferred to the digital base station. After completing the control logic update indicated by the control logic update instruction, receive the takeover status parameter set generated during the takeover period issued by the digital base station; The updated control logic is started based on the takeover status parameter set, and a request to restore control authority is sent to the digital base station. The digital dock is configured as follows: Send the control logic update command to the target local controller; The system receives the set of key operating status parameters uploaded by the target local controller and initiates virtual control logic based on the set of key operating status parameters to take over control of the end device. During the control of the terminal device, the operating status of the terminal device is recorded to generate the takeover status parameter set; After confirming that the target local controller has completed the control logic update, the takeover status parameter set is sent to the target local controller. In response to a request to restore control authority from the target local controller, control authority over the end device is transferred.
[0007] In one possible implementation, the system further includes a management platform communicatively connected to the digital dock; The management platform is configured to generate encrypted update commands based on user operations on the visual interface. The digital base station is further configured to: receive the encryption update instruction and send the encryption update instruction as the control logic update instruction to the target local controller; The local controller is further configured to: receive and decrypt the control logic update instruction, and then execute the steps of uploading the set of key operating status parameters representing the current operating status to the digital base, pausing the execution of the current control logic, and transferring control authority over the terminal device to the digital base.
[0008] In one possible implementation, when no control logic update is triggered, the system is configured to perform a routine data synchronization process, wherein: The local controller is further configured to: collect the operating data of the terminal device at a preset period and synchronize the operating data to the digital base station; The digital base is further configured to: receive the operation data, verify the integrity of the operation data, store the operation data in a time-series database after the verification is successful, and forward the operation data to the management platform for display.
[0009] In one possible implementation, it is characterized by The local controller is further configured to: enable local caching to store the running data to be uploaded and send a synchronization fault notification to the digital base when the number of consecutive failures to upload data to the digital base reaches a preset threshold. The digital base station is further configured to: in response to the synchronization failure notification, send a synchronization failure alarm to the management platform, and when an abnormality is detected in the communication link with the local controller, switch to the backup communication link, and receive cached data uploaded by the local controller after the link is restored to normal.
[0010] In one possible implementation, it is characterized by The digital dock is further configured to send an update completion message to the management platform after transferring control of the terminal device. The management platform is configured to receive the update completion message and provide interface prompts and log recordings based on the update completion message.
[0011] In one possible implementation, it is characterized by The digital base station is further configured to: after taking over control of the terminal device based on the key operating status parameter set, if no effective feedback is received from the terminal device within a preset time period, send an emergency switchback command to the local controller and send a takeover abnormality alarm to the management platform. The local controller is further configured to: in response to the emergency switchback command, initiate the original control logic to take over control of the end device again.
[0012] In one possible implementation, it is characterized by The local controller is further configured to: after uploading the set of key operating status parameters to the digital base, start a timer to receive confirmation and wait for confirmation. If no confirmation of receipt is received from the digital base within the preset waiting time, a retransmission confirmation process is executed until the confirmation of receipt is received or the number of times the retransmission confirmation process is executed reaches a preset threshold. The retransmission confirmation process includes: after a timeout, delaying for a preset period of time, and then re-uploading the set of key operating status parameters.
[0013] In one possible implementation, it is characterized by The local controller is further configured to perform a control logic update operation after transferring control of the end device to the digital dock. The control logic update operation includes: downloading a new version of the control logic program package from the digital base station, replacing the current control logic with the new version of the control logic program package, and performing an integrity check on the new version of the control logic program package during the replacement process; After the replacement is completed and the verification is successful, an update success notification indicating that the control logic update has been completed is sent to the digital base.
[0014] Secondly, this application provides a control logic hot-update method applied to a digital dock, wherein the digital dock is communicatively connected to at least one local controller, the method comprising: Send a control logic update command to the target local controller; The system receives a set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and initiates virtual control logic based on the set of key operating status parameters to take over control of the end devices. During the control of the terminal device, the operating status of the terminal device is recorded to generate a takeover status parameter set; After confirming that the target local controller has completed the control logic update, the takeover status parameter set is sent to the target local controller so that the target local controller can start the updated control logic based on the takeover status parameter set. In response to a request to restore control authority from the target local controller, control authority over the end device is transferred.
[0015] Thirdly, this application provides a control logic hot-update device applied to a digital dock, the digital dock being communicatively connected to at least one local controller, the device comprising: The first sending module is used to send control logic update instructions to the target local controller; The takeover module is used to receive a set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and to start virtual control logic based on the set of key operating status parameters to take over the control of the end device. A recording module is used to record the operating status of the terminal device during the control of the terminal device, so as to generate a takeover status parameter set; The second sending module is used to send the takeover status parameter set to the target local controller after confirming that the target local controller has completed the control logic update, so that the target local controller can start the updated control logic based on the takeover status parameter set. The handover module is used to hand over control rights over the end device in response to a request to restore control rights from the target local controller.
[0016] Compared with the prior art, the technical solution provided in this application has the following advantages: In the system provided in this application, after the local controller responds to the update command, it first uploads the key operating status parameter set, laying a precise state foundation for the smooth transfer of control authority. Then, the local controller suspends operation and transfers control authority, while the digital base station immediately starts the corresponding virtual control logic based on the received complete status parameters, achieving seamless takeover of the end device. Thus, during the entire time period when the local controller is performing the logic update, the real-time control of the end device is continuously maintained by the digital base station, avoiding any interruption of control functions. After the local controller completes the update, the digital base station sends back the operating status parameter set recorded during this period, enabling the local controller to accurately restore the control logic and regain control authority based on the latest system state. This process, through bidirectional migration of state data and real-time takeover by the virtual controller, ensures that the control logic update operation does not affect the continuous operation of the controlled device at the functional and execution levels, thereby achieving uninterrupted execution of control tasks without manual intervention. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0020] Figure 1 A schematic diagram of a control logic hot update system provided in this application embodiment; Figure 2 A schematic diagram illustrating the interaction between the digital dock and the local controller provided in an embodiment of this application; Figure 3 A flowchart illustrating an embodiment of a control logic hot update method provided in this application; Figure 4 A block diagram illustrating an embodiment of a control logic hot-update device provided in this application; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0022] The following disclosure provides numerous different embodiments or examples for implementing various structures of this application. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of this application. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.
[0023] To address the technical problem that controllers must pause control of end devices during the update process in existing technologies, this application provides a control logic hot update system that enables uninterrupted execution of control tasks without manual intervention.
[0024] Figure 1 This is a schematic diagram of a control logic hot update system provided in an embodiment of this application. Figure 1 As shown, the control logic hot update system includes a digital base and at least one local controller that is communicatively connected to the digital base; The local controller is configured to: in response to a control logic update command from the digital base station, upload a set of key operating status parameters representing the current operating status to the digital base station, suspend the execution of the current control logic, and transfer control authority over the end device to the digital base station; after completing the control logic update indicated by the control logic update command, receive a takeover status parameter set generated during the takeover period from the digital base station; start the updated control logic based on the takeover status parameter set, and send a request to the digital base station to restore control authority; The digital dock is configured to: issue a control logic update instruction to a target local controller; receive the key operating status parameter set uploaded by the target local controller, and initiate virtual control logic based on the key operating status parameter set to take over control of the end device; record the operating status of the end device during control of the end device to generate the takeover status parameter set; after confirming that the target local controller has completed the control logic update, issue the takeover status parameter set to the target local controller; and transfer control authority over the end device in response to a request to restore control authority from the target local controller.
[0025] In this context, "end-point equipment" refers to electromechanical equipment within the building, such as air conditioning units, lighting, and water supply and drainage systems, along with their associated sensors and actuators. "Local controller" refers to a programmable logic control unit deployed at the building's field equipment layer, directly connected to the end-point equipment via protocols such as RS-485 or LoRa, responsible for real-time data collection and precise adjustment tasks based on built-in control logic. "Digital base" refers to a central management platform deployed in the cloud or at the edge, with a built-in containerized platform (such as Docker) and virtual control logic execution module, used to collect, manage, and analyze all data and control logic within the building. In this application, the digital base is the core scheduling center for realizing hot updates of control logic and automated operation and maintenance.
[0026] In this embodiment of the application, the interaction process between the digital base and the local controller is as follows: Figure 2 As shown, specifically, when maintenance personnel select the target local controller, upload the new version of the control logic program package, and click to start the update through the management platform (i.e., the management side computer), the management platform generates an update instruction (including device identifier, program package identifier, and timestamp) and forwards it to the target local controller through the digital dock.
[0027] Upon receiving the instruction, the local controller immediately collects the key operating status parameter set of the current control program. This parameter set includes at least the execution phase and core dynamic parameters. Taking an air conditioning unit as an example: the operating phase includes "normal operation," "pre-cooling mode," "standby," and "fault protection," etc., and the core parameters include: temperature setpoint 25℃, humidity setpoint 50%RH, fan speed 1500rpm, electric valve opening 60%, real-time return air temperature 24.5℃, fault code 0 (no fault), and cumulative running time 3600s, etc. Taking a chiller unit as an example: the operating phase includes "loaded operation," "unloaded operation," and "standby," etc., and the core parameters include: outlet water temperature setpoint 7℃, real-time return water temperature 12℃, water pump operating frequency 50Hz, electric butterfly valve opening 45%, compressor start / stop status (operation), and high-pressure protection threshold 1.8MPa, etc. Then, the key operating status parameter set is encapsulated as a data snapshot and uploaded to the digital base station; subsequently, the current control logic is paused, and control authority over the terminal equipment is transferred.
[0028] After receiving a complete set of status parameters, the digital dock initiates virtual control logic that is completely consistent with the current control logic of the local controller, thereby taking over real-time control of the end devices. In one specific implementation, this can be achieved by loading a copy of the current control logic of the local controller into its internal containerized environment. Thus, the digital dock maintains continuous control over the devices during updates, ensuring their stable operation. Simultaneously, the local controller downloads the new control logic package from the digital dock and performs update operations such as erasing the old logic, writing the new logic, and performing integrity checks.
[0029] During the takeover control period, the digital base station continuously records the operating status of the end devices, forming a takeover status parameter set. Once the digital base station confirms that the local controller has completed the update (e.g., upon receiving an update completion command), it sends this takeover status parameter set. Upon receiving the parameter set, the local controller initiates the updated control logic based on this set and sends a request to the digital base station to restore control authority. The digital base station responds to this request, returning control of the end devices to the local controller. Subsequently, the local controller synchronizes the updated control logic to the digital base station, ensuring consistency between the two systems; the digital base station then reports update completion to the management side.
[0030] The system provided in this application embodiment, after the local controller responds to the update command, first uploads a set of key operating status parameters, laying a precise state foundation for the smooth transfer of control authority. Then, the local controller suspends operation and transfers control authority, while the digital base station immediately starts the corresponding virtual control logic based on the received complete status parameters, achieving seamless takeover of the end device. Thus, throughout the entire time the local controller is updating its logic, real-time control of the end device is continuously maintained by the digital base station, avoiding any interruption of control functions. Once the local controller completes the update, the digital base station sends back the set of operating status parameters recorded during this period, enabling the local controller to accurately restore the control logic and regain control authority based on the latest system state. This process, through bidirectional migration of state data and real-time takeover by the virtual controller, ensures that the control logic update operation does not affect the continuous operation of the controlled device at the functional and execution levels, thereby achieving uninterrupted execution of control tasks without manual intervention.
[0031] Furthermore, the system may further include a management platform communicatively connected to the digital dock to provide a secure and auditable update triggering mechanism. Specifically, the management platform is configured to generate encrypted update instructions based on user operations on the visual interface; the digital dock is further configured to receive the encrypted update instructions and send them as control logic update instructions to the target local controller; the local controller is further configured to receive and decrypt the control logic update instructions, and then execute the steps of uploading a set of key operating status parameters representing the current operating status to the digital dock, pausing the execution of the current control logic, and transferring control over the terminal devices to the digital dock.
[0032] Management platform: refers to an operation and maintenance management software system that provides a visual human-computer interaction interface and is deployed on the user terminal (e.g., Figure 1 (Computer in the middle); Encrypted update command: refers to the control command generated by the management platform, which contains metadata such as target controller identifier, new logic program identifier and timestamp, and has been encrypted.
[0033] In this embodiment, the update process is initiated by maintenance personnel on the management platform. Specifically, after logging into the system, the maintenance personnel enter the "Control Logic Update" function module, perform operations such as selecting the target local controller, uploading the new control logic program package, and clicking the "Start Update" button. In response to these operations, the management platform generates an encrypted update instruction containing necessary metadata such as the target device identifier, program package identifier, and timestamp, and sends it to the digital dock.
[0034] As the system's command distribution center, the digital dock receives the encrypted update command and forwards it directly to the target local controller as a control logic update command. Upon receiving the command, the local controller first performs a decryption operation to obtain the plaintext command, then triggers and executes the hot update process, which involves collecting and uploading its current key operating status parameters to the digital dock, pausing the execution of existing control logic, and transferring control of the end devices to the digital dock.
[0035] This embodiment transforms standardized user interface operations into encrypted instruction chains securely forwarded via a digital base station, providing a standardized startup entry point with clear permissions and auditable processes for the entire hot update process. While ensuring the authorization of update operations and data integrity, it seamlessly connects to the automated and uninterrupted core hot switching process.
[0036] To ensure the reliability and data integrity of the system during daily operation, the system is configured to perform a daily data synchronization process when no control logic update is triggered. Specifically, the local controller is further configured to: collect operating data from the terminal devices at a preset period and synchronize the operating data to the digital dock; the digital dock is further configured to: receive the operating data, verify the integrity of the operating data, store the operating data in a time-series database after successful verification, and forward the operating data to the management platform for display.
[0037] Time-series database: refers to a database management system specifically optimized for processing timestamped sequential data, suitable for high-frequency data storage and retrieval in industrial IoT scenarios. Operational data: refers to information generated by or reflecting the operational status of end devices, including at least device status quantities (such as operating stage, fault codes), process variables (such as temperature, pressure, speed), and actuator status (such as valve opening degree, switch position).
[0038] In this routine data synchronization process, the local controller collects operating data from end devices (such as air conditioning units) at a preset collection cycle (e.g., every second or every few seconds) and synchronizes the data packets to the digital base station via the TCP / IP protocol. Upon receiving the data, the digital base station first performs integrity verification (e.g., CRC32 check). If the verification passes, the data is stored in a time-series database. Simultaneously, the digital base station forwards the verified data to the management platform in real time for dynamic display on its interface.
[0039] The specific choice of time-series database can be adapted to the deployment scenario: When deploying a digital base station on the resource-constrained edge, the Apache IoTDB lightweight mode can be selected. It adopts columnar storage and TsFile format, supports tens of thousands of data points written per second, and its memory usage can be controlled within 50MB. It also has time partition index optimization, which can quickly locate data associated with "device ID + timestamp". It has the characteristics of high write efficiency and low memory usage. When deploying a digital base station in the cloud or data center that needs to associate business data, TimescaleDB based on PostgreSQL can be selected. It is built on PostgreSQL and supports SQL (Structured Query Language) syntax and relational data fusion query. At the same time, it realizes efficient archiving and tracing of historical data through automatic time partitioning. In conventional scenarios, InfluxDB with efficient compression and indexing capabilities can be selected. It has native timestamp index and data compression algorithm, which is suitable for the high-frequency and low-latency data storage needs of building automation. When storing data, a combined unique index is built based on "device ID + timestamp" to ensure that data at different points in time on a single device can be accurately traced. At the same time, a data TTL (Time To Live) policy is configured to automatically manage historical data archiving (such as retaining 90 days of historical data) and optimize storage resource usage.
[0040] This solution enables the periodic collection, reliable transmission, efficient storage, and real-time visualization of equipment operation data. It not only provides continuous data support for operation and maintenance monitoring, but also accumulates a complete data foundation for in-depth analysis of the digital infrastructure (such as digital twin modeling) and potential hot update decisions.
[0041] To address potential communication anomalies during routine data synchronization, the local controller is further configured to: enable local caching to store the operational data to be uploaded and send a synchronization failure notification to the digital base when the number of consecutive failed data uploads to the digital base reaches a preset threshold; the digital base is further configured to: respond to the synchronization failure notification, send a synchronization failure alarm to the management platform, and switch to a backup communication link when an anomaly is detected in the communication link with the local controller, and receive the cached data uploaded by the local controller after the link is restored to normal.
[0042] Local cache: refers to the non-volatile storage medium built into or external to the local controller, used to temporarily store data to be uploaded in the event of communication failure; Backup communication link: refers to another physical or logical communication channel pre-configured in the system, which is different from the primary link, such as when switching from a wired network to a wireless cellular network.
[0043] In this anomaly handling process, if the local controller fails to upload operational data to the digital base station multiple times (e.g., 3 times) consecutively, it is considered a communication anomaly. At this point, the local controller automatically activates its local cache to temporarily store subsequently collected operational data, preventing unnecessary retransmission attempts. Simultaneously, it sends a synchronous fault notification to the digital base station to inform it of the anomaly. Upon receiving this notification, the digital base station immediately sends a synchronous fault alarm to the management platform to alert maintenance personnel. Simultaneously, it actively checks the communication link with the local controller. If a link anomaly is confirmed, it automatically switches to a preset backup communication link. Once the backup link is successfully established and normal communication is restored, the digital base station prioritizes requesting the upload of its cached operational data from the local controller, ensuring no data loss during the anomaly period.
[0044] This solution establishes a robust handling mechanism for communication anomalies by implementing data caching on the local controller side and link redundancy and proactive alarms on the digital base station side. This mechanism ensures that operational data is reliably stored during consecutive upload failures, without being lost. Simultaneously, the system automatically detects faults, switches communication paths, and issues explicit alarms to maintenance personnel, enabling data retransmission after the link is restored. This fundamentally solves the problem of data packet loss or synchronization interruption caused by network instability, guarantees eventual consistency of the data stream, and significantly improves the system's self-healing capabilities and operational transparency in unreliable network environments.
[0045] Furthermore, after the hot update control is handed over, in order to provide clear operational feedback to the maintenance personnel, the digital base station is further configured to: send an update completion message to the management platform after transferring control of the terminal device; the management platform is configured to: receive the update completion message and provide interface prompts and log recordings based on the update completion message.
[0046] Update complete message: refers to the notification message generated by the digital dock, which includes at least the target device identifier, the new program version number, and metadata such as the time taken for this update; Interface prompt: refers to the information presented on the management platform user interface through visual methods such as pop-ups and status bar changes.
[0047] In this feedback process, once the digital dock responds to the local controller's request to restore control authority and completes the authority transfer, it immediately generates a structured update completion message and sends it to the management platform. Upon receiving this message, the management platform immediately provides a clear completion prompt to the maintenance personnel on the user interface (e.g., a pop-up "Update Successful" window). Simultaneously, it persistently stores the key content of the message (such as device identifier, new program version number, timestamp, and operation result) as a record in the system log. This solution synchronously feeds back the final state of a complete hot update operation (from triggering on the management platform to securely returning control) to the human-machine interface and system logs in a readable and traceable manner. This provides maintenance personnel with clear confirmation of the operation result and generates a complete electronic record for auditing and problem tracing, thereby achieving closed-loop management and auditability of the hot update maintenance process.
[0048] To ensure the safety and reliability of the control takeover process and prevent system loss of control due to device unresponsiveness, the digital base station is further configured to: after taking over control of the terminal device based on the key operating status parameter set, if no valid feedback is received from the terminal device within a preset time period, send an emergency switchback command to the local controller and send a takeover anomaly alarm to the management platform; the local controller is further configured to: respond to the emergency switchback command, activate the original control logic to retake control of the terminal device.
[0049] Effective feedback: refers to the response signal of the end device to the control command issued by the digital base station, which conforms to the expected protocol format, such as status confirmation or data readback; Emergency switchback command: refers to the highest priority command issued by the digital base station when it determines that the takeover is abnormal, requiring the local controller to immediately resume control.
[0050] In this security process, after the digital base station initiates virtual control logic and declares takeover based on the received set of status parameters, it starts a timer and continuously monitors the end devices for a preset duration (e.g., 10 seconds) to see if they return valid feedback. If no valid feedback is received within this period, it is determined to be a takeover anomaly or a device communication failure. At this time, the digital base station immediately performs two key operations: first, it sends an emergency switchback command to the local controller; second, it simultaneously sends a takeover anomaly alarm to the management platform. Upon receiving the emergency switchback command, the local controller unconditionally and immediately starts its original, unupdated control logic, regains control of the end devices, and thus forcibly reverts the system control state to a known safe baseline.
[0051] This solution sets up a clear safety timeout and automatic rollback strategy for the critical operation of control takeover, effectively preventing the risk of system loss of control due to communication failure between the virtual controller and the end device or control logic mismatch. Through rapid and automatic degradation recovery, it ensures the most basic safe operation of the controlled device under any abnormal situation and provides real-time fault alarms to the operation and maintenance personnel.
[0052] To ensure reliable delivery of critical status data during hot update startup, the local controller is further configured to: after uploading the critical operating status parameter set to the digital base, initiate a receive confirmation waiting timer; if no receive confirmation information is received from the digital base within a preset waiting time, execute a retransmission confirmation process until the receive confirmation information is received or the number of times the retransmission confirmation process is executed reaches a preset threshold; wherein, the retransmission confirmation process includes: after a timeout, delaying for a preset time and re-uploading the critical operating status parameter set.
[0053] Receiving confirmation information: refers to the confirmation signal returned by the digital base station to the local controller after successfully receiving and verifying the set of key operating status parameters; Retransmission confirmation process: refers to the process by which the local controller repeatedly attempts to send data according to a preset strategy until it succeeds when it does not receive confirmation.
[0054] In this reliability assurance process, after uploading the set of critical operating status parameters, the local controller immediately starts a timer and waits for confirmation from the digital dock. If no confirmation is received within a preset waiting time (e.g., 3 seconds), the upload is considered to have failed. At this point, the controller does not immediately perform subsequent high-risk operations such as permission transfer, but instead enters a controlled retransmission confirmation process: first, it waits for a preset delay interval, then re-uploads the complete set of status parameters, and starts the timer again to wait for confirmation. This "wait-timeout-delayed retransmission" loop continues until a successful confirmation is received, or the total number of loops reaches a preset limit (e.g., 2 times).
[0055] This solution ensures that the digital base station has obtained a complete and accurate state snapshot before taking over control through proactive confirmation and limited retries. This fundamentally avoids the digital base station taking over based on an incorrect or missing state due to a single network packet loss or momentary delay, laying a critical foundation for data reliability for seamless switching of the entire hot update process.
[0056] During the digital dock takeover control, to ensure the secure replacement of the local controller's own logic, the local controller is further configured to: after transferring control of the end device to the digital dock, perform a control logic update operation; the control logic update operation includes: downloading a new version of the control logic program package from the digital dock, replacing the current control logic with the new version of the control logic program package, and performing integrity verification on the new version of the control logic program package during the replacement process; after the replacement is completed and the verification passes, sending a notification of successful update of control logic update to the digital dock.
[0057] Integrity verification: refers to the verification process of verifying that program data has not been erroneous or tampered with during transmission and writing by calculating and comparing checksums (such as CRC or hash values); Update success notification: refers to the status message sent by the local controller to the digital dock after confirming that it has successfully updated, which contains the update result and the new program version number.
[0058] In this logic update process, after transferring control authority, the local controller immediately downloads the new control logic program package from the digital dock. Once downloaded, the controller performs a program replacement operation, specifically erasing the old logic from its memory and writing the new logic program. During this writing process, the controller simultaneously performs real-time integrity verification on the newly written program data. If the verification passes, it indicates that the new logic has been correctly written, and the controller immediately sends an update success notification to the digital dock, explicitly including a "success" status and the new version number.
[0059] This solution combines the high-risk operation of program replacement with real-time verification, ensuring the correctness and integrity of the new control logic on the controller. It prevents the controller from failing to start due to corrupted programs caused by transmission errors or storage anomalies, thus providing a reliable software foundation for safe and accurate recovery of operation based on the returned status.
[0060] To address potential program anomalies during the update operation, the system is equipped with an automatic rollback mechanism. The local controller is further configured to: revert to the control logic before the update if the integrity verification of the new control logic program package fails, and send an update failure notification to the digital base station; the digital base station is further configured to: send an alarm signal to the management platform in response to the update failure notification.
[0061] Automatic rollback mechanism: refers to the self-recovery function that allows the system to automatically restore to a known stable state before the update without manual intervention when an update process detects a failure; Update failure notification: refers to a status message generated by the local controller that clearly indicates the failure of the update operation and its cause (such as verification failure).
[0062] In this exception handling process, if the local controller fails to perform integrity verification on the downloaded new control logic package (e.g., checksum mismatch), the current update process is immediately aborted, and a rollback operation is automatically performed: restoring the erased or partially written storage area to the original, normally functioning control logic. Subsequently, the local controller sends an update failure notification to the digital docking station, clearly indicating that the update was unsuccessful. Upon receiving this notification, the digital docking station will not continue with the subsequent status feedback and permission handover process, but will maintain its virtual control logic's takeover of the end devices. Simultaneously, it immediately sends an alarm signal to the management platform to trigger an audible and visual alarm on the management interface and notify maintenance personnel to manually intervene and investigate.
[0063] This solution provides a critical fault-safe boundary for online program updates of the controller, ensuring that any software-level update failure will not lead to system out of control, but will automatically fall back to a safe and usable older version. At the same time, it exposes anomalies to maintenance personnel through timely alarms, thereby making update risks controllable and maintenance responses proactive.
[0064] Before restoring control, to ensure that the new logic starts based on the accurate state, the local controller is further configured to: after receiving the takeover state parameter set generated during the takeover period from the digital base station, perform a validity check on the takeover state parameter set; after the validity check passes, load the takeover state parameter set to start the updated control logic, and send a request to restore control permission to the digital base station.
[0065] Legality verification: refers to the multi-level verification of the returned takeover status parameter set, including at least the reasonableness of parameter format and physical range, the consistency of logical association between parameters, and the integrity of core parameters necessary to start new logic.
[0066] In this recovery startup process, after receiving the takeover status parameter set from the digital dock, the local controller does not load it directly, but first performs a rigorous validity check. This check process can specifically include the following steps: Step 1: Parameter format and physical range verification (basic legality verification) The local controller first verifies the "correctness of data format" and "reasonableness of physical / logical range" of the returned parameters, rejecting abnormal parameters that exceed reasonable boundaries. Specific verification rules are illustrated below with examples of typical building automation equipment (taking air conditioning unit parameters as an example): Temperature parameters: Real-time return air temperature (must be between -10℃ and 50℃; exceeding this range is considered abnormal due to the physical operating range limitations of the air conditioning equipment), and set temperature (must be between 16℃ and 30℃; exceeding this range is considered abnormal as it does not meet the building's comfort temperature control requirements). Actuator parameters: Valve opening (must be between 0% and 100%, otherwise it will be considered abnormal due to the mechanical stroke limitation of electric valves), fan speed (must be between 0 rpm and 3000 rpm, otherwise it will be considered abnormal, matching the rated speed of the fan motor). Status parameters: operating phase (only four enumerated values are allowed: "standby", "normal operation", "precooling / preheating" and "fault protection". Other values are considered abnormal), fault codes (must be in the range of 0 to 999 and must match the local controller's preset fault code table. If no matching item is found, it is considered abnormal); when verification fails: the local controller sends a "parameter abnormality request retransmission" command to the digital base station and waits for the digital base station to resend the corrected parameter packet. It can retry a maximum of 2 times.
[0067] Step 2: Verify the logical correlation of parameters (to avoid parameter contradictions) After confirming the validity of the format / range of individual parameters, further verify the logical relationship between parameters to avoid confusion in the execution of the new logic due to parameter inconsistencies. Specific verification rules are shown in the following example: If the operation phase is "fault protection", the fault code cannot be 0 (no fault), and the actuator parameters must meet the fault protection status (e.g., the fan speed should be 0 rpm and the valve opening should be 0%). If "fault protection + fan speed 1500 rpm" occurs, it is considered a logical contradiction. If the operation phase is "normal", the difference between the temperature setpoint and the real-time value must be within a reasonable range (e.g., ≤10℃; if the setpoint is 25℃ and the real-time value is 5℃, a difference of 20℃ is considered abnormal, which may be due to parameter errors caused by sensor failure). When the verification fails: the local controller marks the contradictory parameters and sends a "parameter logic contradiction" alarm to the digital base.
[0068] Step 3: Data integrity verification (ensuring that core parameters are not missing) Finally, verify that the "core parameters required for the new logic startup" in the returned data packet are complete. If any required parameters are missing, the packet is deemed invalid. The specific list of required parameters can be determined based on the device type. A specific example is shown below: Required parameters for air conditioning units: operating stage, temperature setpoint, valve opening, and fan speed (all four items must be present; the absence of any one item will result in an incomplete assessment). Required parameters for chiller units: operating stage, outlet water temperature setpoint, pump frequency, and compressor start / stop status (all 4 items must be present); When the verification fails: The local controller sends a "parameter missing request to be retransmitted" command to the digital base station, and the new logic will be started after the parameters are completed.
[0069] In this state recovery startup process, after receiving the takeover status parameter set from the digital base station, the local controller performs the three verification steps mentioned above in sequence. Only after all verifications pass will the local controller load the parameter set and start the updated control logic based on this accurate, consistent, and complete state context, and then send a request to the digital base station to restore control authority.
[0070] This solution systematically eliminates the risk of control logic startup failure or execution chaos caused by data errors, contradictions, or missing data through a multi-layered verification mechanism, ensuring the reliability and security of the hot update state recovery process.
[0071] To ensure long-term consistency of system logic after hot updates, the local controller is further configured to: synchronize the updated control logic to the digital base after successfully starting the updated control logic based on the takeover state parameter set; the digital base is further configured to: receive the updated control logic and update the virtual control logic using the updated control logic, so that the virtual control logic is consistent with the control logic in the local controller.
[0072] Logic synchronization: refers to the process of transmitting the core instructions or complete image of the updated control logic from the local controller to the digital base station; Virtual control logic update: refers to the digital base station using the received logic data to replace or upgrade the logic copy running in its internal virtual controller.
[0073] In this consistency assurance process, once the local controller successfully starts the updated control logic based on the takeover status parameter set, it immediately performs a reverse synchronization operation: uploading its internally running new version of control logic (usually a verified core program or configuration file) to the digital dock. Upon receiving this logic data, the digital dock uses it to update and replace the virtual control logic running in its own virtualization environment, thereby ensuring that the logic copy held by the digital dock is completely consistent with the actual running logic in the physical local controller.
[0074] This solution establishes a two-way synchronization mechanism to ensure the real-time unification of the virtual logic in the digital base and the logic of the field controller after this hot update. This provides an accurate and consistent logical foundation for possible subsequent hot updates, fault takeovers, or digital twin simulations, fundamentally maintaining the integrity and reliability of the control logic layer of the system during long-term operation.
[0075] As a safety fallback strategy, when the update process ultimately cannot be completed automatically by the system, the digital dock is further configured to: if it receives an update failure notification from the local controller, maintain its virtual control logic's takeover of the end device and send an alarm requiring manual intervention to the management platform.
[0076] In this anomaly handling process, when the digital dock receives an update failure notification from the local controller (indicating that the local controller attempted to update but ultimately failed and could not automatically roll back), the digital dock will no longer attempt to automatically relinquish control or restart the update process. Instead, it will immediately enter a stable backup state: continuing to maintain its virtual control logic's takeover and control of the end devices to ensure the most basic continuous operation of the devices and avoid device downtime due to controller logic anomalies. Simultaneously, the digital dock sends a highest-priority "manual intervention required" alarm to the management platform. This alarm explicitly notifies maintenance personnel that on-site inspection and manual handling are mandatory. This solution ensures that even in the worst-case scenario where any automatic step fails, the system can still maintain basic control functions through the digital dock and clearly report the problem, thus completely eliminating the risk of complete loss of control of on-site devices due to update failure. This elevates system reliability from the automation level to an ultimate guarantee level with manual backup.
[0077] In addition, to enhance the predictive maintenance capabilities of the system, the digital base is also equipped with intelligent analysis functions. The digital base is further configured to: construct and maintain a digital twin virtual model of the terminal device based on the operating data of the terminal device synchronized from the local controller; compare the real-time received operating data with the preset normal operating condition model in the digital twin virtual model and calculate the deviation coefficient; and generate an early warning message when the deviation coefficient exceeds a preset threshold.
[0078] Digital twin virtual model: refers to a simulation model created in digital space that can map the static attributes and dynamic behavior of physical terminal devices; Deviation coefficient: refers to a comprehensive index calculated by an algorithm to quantify the degree of deviation between real-time operating data and the normal operating condition model.
[0079] In this intelligent analysis process, the digital base continuously receives and accumulates end-device operating data (such as temperature, pressure, and speed) synchronized from the local controller. Based on this data, it constructs and dynamically updates a digital twin virtual model of the corresponding device, which reflects the device's healthy operating baseline. The system compares the real-time incoming operating data with the normal operating conditions in this model from multiple dimensions, and calculates the real-time deviation coefficient using a preset algorithm (such as calculating the weighted sum of deviations of key parameters). When this coefficient exceeds a preset safety threshold, the digital base determines that the device's operating status is abnormal and automatically generates a warning message (which may include an abnormal device identifier, parameters exceeding the standard, and deviation values).
[0080] This solution can detect abnormal trends in the early stages of equipment performance degradation or failure by analyzing and comparing data models, thereby upgrading the operation and maintenance mode from post-maintenance to predictive maintenance, significantly improving the system's availability, security, and level of intelligent operation and maintenance.
[0081] In summary, the control logic hot update system provided in this application provides a complete technical solution by constructing a collaborative architecture with a digital base as the core scheduling and execution hub and local controllers as field execution units. This solution first resolves the core contradiction of the incompatibility between online updates of controller logic and continuous equipment operation. Its key lies in achieving lossless, bidirectional migration of control authority and runtime state between the physical controller and the virtualization platform. Building upon this, the system further integrates capabilities such as highly reliable data synchronization, multi-layer security verification, multi-scenario anomaly self-healing, and digital twin-based state monitoring. Reliable synchronization provides the foundation for state migration; security verification ensures process recovery; anomaly self-healing ensures the process can still achieve a safe state under partial failures; and digital twin monitoring provides intelligent support for update decisions and system health assessments.
[0082] Therefore, this application constructs a fully automated closed-loop process from update triggering, state takeover, logic replacement to secure recovery, and expands upon this to a comprehensive operation and maintenance support system covering routine monitoring, anomaly handling, and predictive early warning. It achieves a shift in operation and maintenance mode from passive response to proactive management, and from single-point maintenance to system-level collaboration, significantly improving the maintainability and intelligence level of industrial automatic control systems while ensuring maximum availability.
[0083] Figure 3 This is a flowchart illustrating a control logic hot-update method provided in an embodiment of this application. This control logic hot-update method is specifically applied to the digital docking station side to achieve coordination with the local controller, enabling uninterrupted logic updates. Figure 3 As shown, the specific steps include: Step 301: Send a control logic update command to the target local controller; Step 302: Receive the set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and start the virtual control logic based on the set of key operating status parameters to take over the control of the terminal device; Step 303: During the control of the terminal device, record the operating status of the terminal device to generate a takeover status parameter set; Step 304: After confirming that the target local controller has completed the control logic update, the takeover status parameter set is sent to the target local controller so that the target local controller can start the updated control logic based on the takeover status parameter set. Step 305: In response to the request to restore control authority from the target local controller, transfer control authority over the end device.
[0084] For ease of understanding, steps 301-305 are explained uniformly below: In this embodiment, the digital base station first sends a control logic update command to the target local controller. Upon receiving the command, the target local controller uploads its current set of key operating status parameters. Based on this parameter set, the digital base station initiates a virtual control logic that is completely identical to it, thereby taking over real-time control of the end devices. During the takeover, the digital base station continuously records the operating status of the end devices, forming a takeover status parameter set. After confirming that the local controller has completed the logic update, the digital base station sends the takeover status parameter set back to the local controller, allowing it to initiate the updated control logic based on the latest system status. Finally, the digital base station responds to the local controller's request to restore control authority and returns control of the end devices.
[0085] This solution enables a smooth and uninterrupted switch of control permissions between the "local controller - digital dock - local controller". The digital dock, acting as a "temporary host", maintains continuous and stable control over the end devices using virtual control logic throughout the process of the local controller updating its internal logic, thereby ensuring zero interruption in production or operation.
[0086] Figure 4 This is a block diagram illustrating an embodiment of a control logic hot-update device provided in this application. Figure 4 As shown, the device includes: The first sending module 41 is used to send control logic update instructions to the target local controller; The takeover module 42 is used to receive a set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and to start virtual control logic based on the set of key operating status parameters to take over the control of the end device. Recording module 43 is used to record the operating status of the terminal device during the control of the terminal device, so as to generate a takeover status parameter set; The second sending module 44 is used to send the takeover status parameter set to the target local controller after confirming that the target local controller has completed the control logic update, so that the target local controller can start the updated control logic based on the takeover status parameter set. The handover module 45 is used to hand over control rights over the end device in response to a request to restore control rights from the target local controller.
[0087] like Figure 5As shown in the figure, this application provides a device including a processor 111, a communication interface 112, a memory 113, and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114. Memory 113 is used to store computer programs; In one embodiment of this application, when the processor 111 executes a program stored in the memory 113, it implements the control logic hot update method provided in any of the foregoing method embodiments, including: Send a control logic update command to the target local controller; The system receives a set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and initiates virtual control logic based on the set of key operating status parameters to take over control of the end devices. During the control of the terminal device, the operating status of the terminal device is recorded to generate a takeover status parameter set; After confirming that the target local controller has completed the control logic update, the takeover status parameter set is sent to the target local controller so that the target local controller can start the updated control logic based on the takeover status parameter set. In response to a request to restore control authority from the target local controller, control authority over the end device is transferred.
[0088] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the control logic hot update method provided in any of the foregoing method embodiments.
[0089] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0090] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented using software plus a general-purpose hardware platform, or of course, using hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0091] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also include the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that additional or alternative steps may be used.
[0092] The above description is merely a specific embodiment of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A control logic hot update system, method, and apparatus, characterized in that, Includes a digital dock and at least one local controller communicatively connected to the digital dock; The local controller is configured as follows: In response to the control logic update command from the digital base station, the set of key operating status parameters representing the current operating status is uploaded to the digital base station, the execution of the current control logic is paused, and the control authority over the terminal device is transferred to the digital base station. After completing the control logic update indicated by the control logic update instruction, receive the takeover status parameter set generated during the takeover period issued by the digital base station; The updated control logic is started based on the takeover status parameter set, and a request to restore control authority is sent to the digital base station. The digital dock is configured as follows: Send the control logic update command to the target local controller; The system receives the set of key operating status parameters uploaded by the target local controller and initiates virtual control logic based on the set of key operating status parameters to take over control of the end device. During the control of the terminal device, the operating status of the terminal device is recorded to generate the takeover status parameter set; After confirming that the target local controller has completed the control logic update, the takeover status parameter set is sent to the target local controller. In response to a request to restore control authority from the target local controller, control authority over the end device is transferred.
2. The system according to claim 1, characterized in that, The system also includes a management platform that is communicatively connected to the digital base station; The management platform is configured to generate encrypted update commands based on user operations on the visual interface. The digital base station is further configured to: receive the encryption update instruction and send the encryption update instruction as the control logic update instruction to the target local controller; The local controller is further configured to: receive and decrypt the control logic update instruction, and then execute the steps of uploading the set of key operating status parameters representing the current operating status to the digital base, pausing the execution of the current control logic, and transferring control authority over the terminal device to the digital base.
3. The system according to claim 2, characterized in that, When no control logic update is triggered, the system is configured to perform a routine data synchronization process, wherein: The local controller is further configured to: collect the operating data of the terminal device at a preset period and synchronize the operating data to the digital base station; The digital base is further configured to: receive the operation data, verify the integrity of the operation data, store the operation data in a time-series database after the verification is successful, and forward the operation data to the management platform for display.
4. The system according to claim 3, characterized in that, The local controller is further configured to: enable local caching to store the running data to be uploaded and send a synchronization fault notification to the digital base when the number of consecutive failures to upload data to the digital base reaches a preset threshold. The digital base station is further configured to: in response to the synchronization failure notification, send a synchronization failure alarm to the management platform, and when an abnormality is detected in the communication link with the local controller, switch to the backup communication link, and receive cached data uploaded by the local controller after the link is restored to normal.
5. The system according to claim 2, characterized in that, The digital dock is further configured to send an update completion message to the management platform after transferring control of the terminal device. The management platform is configured to receive the update completion message and provide interface prompts and log recordings based on the update completion message.
6. The system according to claim 2, characterized in that, The digital base station is further configured to: after taking over control of the terminal device based on the key operating status parameter set, if no effective feedback is received from the terminal device within a preset time period, send an emergency switchback command to the local controller and send a takeover abnormality alarm to the management platform. The local controller is further configured to: in response to the emergency switchback command, initiate the original control logic to take over control of the end device again.
7. The system according to claim 1, characterized in that, The local controller is further configured to: after uploading the set of key operating status parameters to the digital base, start a timer to receive confirmation and wait for confirmation. If no confirmation of receipt is received from the digital base within the preset waiting time, a retransmission confirmation process is executed until the confirmation of receipt is received or the number of times the retransmission confirmation process is executed reaches a preset threshold. The retransmission confirmation process includes: after a timeout, delaying for a preset period of time, and then re-uploading the set of key operating status parameters.
8. The system according to claim 1, characterized in that, The local controller is further configured to perform a control logic update operation after transferring control of the end device to the digital dock. The control logic update operation includes: downloading a new version of the control logic program package from the digital base station, replacing the current control logic with the new version of the control logic program package, and performing an integrity check on the new version of the control logic program package during the replacement process; After the replacement is completed and the verification is successful, an update success notification indicating that the control logic update has been completed is sent to the digital base.
9. A method for hot updating control logic, characterized in that, Applied to a digital docking station, the digital docking station being communicatively connected to at least one local controller, the method includes: Send a control logic update command to the target local controller; The system receives a set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and initiates virtual control logic based on the set of key operating status parameters to take over control of the end devices. During the control of the terminal device, the operating status of the terminal device is recorded to generate a takeover status parameter set; After confirming that the target local controller has completed the control logic update, the takeover status parameter set is sent to the target local controller so that the target local controller can start the updated control logic based on the takeover status parameter set. In response to a request to restore control authority from the target local controller, control authority over the end device is transferred.
10. A control logic hot-update device, characterized in that, Applied to a digital docking station, the digital docking station being communicatively connected to at least one local controller, the device includes: The first sending module is used to send control logic update instructions to the target local controller; The takeover module is used to receive a set of key operating status parameters uploaded by the target local controller to characterize the current operating status, and to start virtual control logic based on the set of key operating status parameters to take over the control of the end device. A recording module is used to record the operating status of the terminal device during the control of the terminal device, so as to generate a takeover status parameter set; The second sending module is used to send the takeover status parameter set to the target local controller after confirming that the target local controller has completed the control logic update, so that the target local controller can start the updated control logic based on the takeover status parameter set. The handover module is used to hand over control rights over the end device in response to a request to restore control rights from the target local controller.