Device for industrial automation and processes
The device addresses reliability issues by allowing the primary microprocessor to take over communication functions from a faulty secondary unit, maintaining operation and fault notification, thus enhancing reliability and response times.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2026-04-23
AI Technical Summary
Existing industrial automation devices face reliability issues due to faults in secondary microprocessor units, leading to communication disruptions and the inability to inform higher-level control systems of such faults.
A device configuration that allows switching from a first operating mode to a second mode upon detecting a fault in the secondary microprocessor, enabling the primary microprocessor to take over communication functions and send diagnostic information via the communication system, thereby ensuring continuous functionality and fault notification.
Ensures the device remains operational and informs higher-level systems of faults, reducing monitoring overhead and enabling faster response times without the need for periodic polling.
Smart Images

Figure 00000009_0000 
Figure 00000009_0001
Abstract
Description
[0001] The invention relates to a device, in particular a field device, for industrial automation, comprising a first microprocessor device for communicative integration of the device into a communication system, in particular for communication with a higher-level controller, further comprising a second microprocessor device which is configured to define communication information to be sent via the communication system in a first operating mode of the device and to transmit the communication information to the first microprocessor device so that the first microprocessor device sends the communication information via the communication system.
[0002] The first microprocessor unit is, for example, an ASIC specifically designed for communication. The second microprocessor unit is, for example, a microprocessor that performs, in particular, general tasks, such as application tasks, and preferably at least one communication function, such as performing batch protocol processing and / or the aforementioned determination of the communication information.
[0003] One objective of the invention is to increase the reliability of the device.
[0004] The problem is solved by a device according to claim 1. The device is configured to switch from the first operating mode to a second operating mode in response to a fault condition of the second microprocessor unit. In the second operating mode, the first microprocessor unit is configured to take over a communication function from the second microprocessor unit, which relates to communication via the communication system, and / or to send diagnostic information concerning the fault condition via the communication system. The takeover of the communication function is effected in such a way that, after the takeover, the communication function is provided by the first microprocessor unit and, in particular, is no longer provided by the second microprocessor unit.
[0005] Consequently, even in the event of a fault in the second microprocessor unit, the device can continue to function as a (particularly active) participant in the communication system and / or, expediently, remains accessible via the communication system even in the event of a fault. Furthermore, this ensures that the higher-level control system is informed of the fault.
[0006] Advantageous further training is the subject of the sub-claims.
[0007] According to a preferred embodiment, the second microprocessor unit is configured to output fault condition information to the first microprocessor unit in response to the fault condition, and the device is configured to switch from the first operating mode to the second operating mode in response to the fault condition information. In particular, the first microprocessor unit is configured to provide the communication function and / or to transmit the diagnostic information concerning the fault condition via the communication system in response to the fault condition information.
[0008] Consequently, the first microprocessor unit can be informed about the error state without the first microprocessor unit having to perform a regular query – in particular a polling – of the second microprocessor unit.
[0009] The invention further relates to a method for operating the device, comprising the steps of: - in the first operating mode, by means of the second microprocessor unit, specifying the communication information to be sent via the communication system and transmitting the communication information to the first microprocessor unit, and, by means of the first microprocessor unit, sending the communication information via the communication system, - in response to a fault condition of the second microprocessor device, switching from the first operating mode to the second operating mode, and - in the second operating mode, by means of the first microprocessor unit, taking over the communication function, which concerns communication via the communication system, from the second microprocessor unit and / or sending diagnostic information concerning the fault condition via the communication system.
[0010] Further exemplary details and embodiments are explained below with reference to the figures. Fig. 1 a schematic representation of a system with a device according to a first embodiment and Fig. 2 a device according to a second embodiment.
[0011] The Fig. Figure 1 shows a system 1, which is specifically designed as an industrial automation system.
[0012] System 1 comprises a device 2, which is exemplified as a field device. Device 2 is used in particular for industrial automation and can also be referred to as an industrial automation device. System 1 expediently includes a communication device 3 and / or a communication link 4, via which device 2 can expediently communicate with the communication device 3. Preferably, System 1 includes a higher-level controller 8, which is in particular implemented as a programmable logic controller (PLC).
[0013] System 1 represents an exemplary application environment for device 2. Device 2 can also be deployed independently – that is, specifically without the other components of System 1.
[0014] For example, communication device 3 serves to provide a communication link to the higher-level controller 8, in particular the PLC. For instance, communication device 3 can be implemented as a gateway through which communication from device 2 to the higher-level controller 8 takes place. Alternatively, communication device 3 can itself be implemented as the higher-level controller, in particular as a PLC.
[0015] The communication link 4 preferably comprises at least one device 5, or, by way of example, several devices 5, which are in particular connected in series, for example, between the communication device 3 and the device 2. Optionally, one, several, or all of the devices 5 are designed like the device 2 and / or as field devices. Each device 5 can also be referred to as an "additional device." The additional devices 5 are expediently separate from the device 2. In particular, the additional devices each have their own external housing and / or are arranged separately from the device 2 (and / or from each other).
[0016] Device 2, communication device 3, and communication link 4 together form a communication system, which, by way of example, has a (particularly physical) line topology. The communication system can also have a different topology, e.g., a ring topology, tree topology, or bus topology.
[0017] For example, the participants in the communication system—device 2, communication device 3, and the other devices 5—communicate with each other using data telegrams, which sequentially travel along a communication path. Communication via the communication system, particularly via the communication path, preferably occurs in real time. Optionally, a precise clock cycle is defined for each data telegram to transmit it along the communication path. Preferably, communication via the data path is synchronous; for example, the communication of all participants in the communication system is synchronized via the data stream transmitted over the communication path. For instance, the data stream contains an embedded clock, defined, for example, by the time interval between symbols in the data stream, which can be referred to as the symbol clock.
[0018] Preferably, the communication path passes through each participant in the communication system at least once. For example, the communication path runs from a first participant – exemplified as communication device 3 – through a plurality of further participants – exemplified as the 5 further devices – to a final participant – exemplified as device 2 – and, in reverse direction and sequence, from the final participant through the plurality of further participants back to the first participant. In the example shown, device 2 is the final participant (particularly in the physical line topology); alternatively, device 2 could also be located in a different position, e.g., it could be positioned between the first and final participants.
[0019] The device 2 preferably comprises a sensor unit 6, for example a pressure sensor and / or a displacement sensor, and / or an actuator unit 7, for example a valve and / or a drive.
[0020] Device 2 comprises a first microprocessor unit 11. The first microprocessor unit 11 serves, in particular, to integrate device 2 into the communication system. By integrating device 2 into the communication system—that is, by making device 2 a participant in the communication system—device 2 is enabled to communicate with the communication device 3 and / or the higher-level control unit 8 (for example, via the communication device 3). By way of example, the first microprocessor unit 11 is communicatively connected to the communication link 4, in particular, communicatively connected to it. For example, the first microprocessor unit 11 can be connected to a communication line, in particular a communication cable, over which the communication path runs.The first microprocessor unit 11 is suitably designed to receive incoming data telegrams via the communication path (in particular via the communication line 4) and / or to output data telegrams to the communication path (in particular to the communication line 4).
[0021] By way of example, the first microprocessor device 11 comprises a first microprocessor unit 21, which preferably has a first microprocessor 31, a first main memory 41, and a first microprocessor unit package 51. Preferably, the first microprocessor unit 21 comprises a first non-volatile memory. By way of example, the first microprocessor device 11 is implemented as the first microprocessor unit 21; i.e., the first microprocessor device 11 is the first microprocessor unit 21, as in the Fig. Figure 1 shows the first microprocessor unit 21, which is specifically designed as an ASIC (Application-specific integrated circuit).
[0022] Device 2 comprises a second microprocessor unit 12. The second microprocessor unit 12 is used in particular to execute application tasks of the device 2 application, for example, processing application process data, performing application diagnostics, and / or processing application parameters. The application specifically concerns the operation of the sensor unit 6 and / or the actuator unit 7. For example, the second microprocessor unit 12 is used to read and / or control the sensor unit 6 and / or the actuator unit 7.As explained in more detail below, the second microprocessor unit 12 is further involved in the communication taking place via the communication system, in particular by providing a communication function for this purpose, for example by determining communication information to be transmitted and / or by performing protocol batch processing.
[0023] By way of example, the second microprocessor device 12 comprises a second microprocessor unit 22, which preferably has a second microprocessor 32, a second main memory 42, and a second microprocessor unit package 52. Preferably, the second microprocessor unit 22 comprises a second non-volatile memory. By way of example, the second microprocessor device 12 is implemented as the second microprocessor unit 22; i.e., the second microprocessor device 12 is the second microprocessor unit 22, as in the Fig. Figure 1 shows that the second microprocessor unit 12 is preferably designed differently from the first microprocessor unit 11. For example, the second microprocessor unit 12 is designed to be more powerful than the first microprocessor unit 11. For example, the second microprocessor unit 22 has higher computing power and / or more memory than the first microprocessor unit 21. Preferably, the second microprocessor unit 12 is designed as a microcontroller.
[0024] The second microprocessor unit 12 is communicatively connected to the first microprocessor unit 11. The first microprocessor unit 11 and the second microprocessor unit 12, in particular the first microprocessor unit 21 and the second microprocessor unit 22, are preferably configured to communicate with each other via an internal communication link 14. The internal communication link 14 is provided, for example, by means of GPIO (General Purpose Input / Output), SPI (Serial Peripheral Interface), QSPI (Quad Serial Peripheral Interface), and / or a parallel interface.
[0025] The device 2 preferably comprises a device outer housing 13 in which the first microprocessor unit 11, the second microprocessor unit 12 and preferably the internal communication link 14, the sensor unit 6 and / or the actuator unit 7 are arranged.
[0026] The Fig. Figure 2 shows a device 2 according to a second embodiment. The device 2 according to the second embodiment can be used in the system 1 instead of the device 2 according to the first embodiment described above. Except for the differences explained below, the second embodiment corresponds to the first embodiment, so that the explanations relating to the first embodiment also apply to the second embodiment. In the second embodiment, the first microprocessor unit 11 (in addition to the first microprocessor unit 21) comprises a third microprocessor unit 23, which has a third microprocessor 33, a third working memory 43, and a third microprocessor unit housing 53. Preferably, the third microprocessor unit 23 is connected between the first microprocessor unit 21 and the second microprocessor unit 22.
[0027] The following section will describe in more detail the operation of device 2.
[0028] Device 2 has a first operating mode, which is, for example, a normal operating mode, and a second operating mode, which is, for example, an emergency operating mode.
[0029] The second microprocessor unit 12 is configured, in the first operating mode of the device 2, to define communication information to be sent via the communication system and to transmit this communication information to the first microprocessor unit 11 (for example, via the internal communication link 14) so that the first microprocessor unit 11 can send the communication information via the communication system. The communication information to be sent relates, for example, to an application of the device 2. For example, the communication information includes process data and / or a parameter. For example, the communication information relates to the sensor unit 6 and / or the actuator unit 7. For example, the communication information includes a sensor value acquired by the sensor unit 6.The communication information may also include status information and / or diagnostic information, in particular regarding the second microprocessor unit 22, the sensor unit 6 and / or the actuator unit 7. For example, the communication information is sent via the communication system by the first microprocessor unit 11 inserting the communication information into a data telegram and sending the data telegram via the communication path.
[0030] Preferably, the communication information is a response to a query received by device 2. The query originates, for example, from the higher-level controller 8. The query serves, in particular, to determine whether device 2 is addressable via the communication system—that is, specifically, whether device 2 can receive a data telegram via the communication system and / or respond to it. For example, the query is transmitted to device 2 via the communication path by means of a data telegram. The first microprocessor unit 11 receives the data telegram and transmits the query contained in the data telegram to the second microprocessor unit 12. The second microprocessor unit 12 receives the query, defines the communication information as the response to the query, and transmits the communication information to the first microprocessor unit 11.The first microprocessor unit 11 inserts the communication information into a data telegram and sends the data telegram via the communication path. The response to the query by the second microprocessor unit 12 is, for example, toggle bit handling. The query originates, for example, from the higher-level controller 8 and / or the communication device 3.
[0031] Device 2 is configured to switch from the first operating mode to the second operating mode in response to a fault condition of the second microprocessor unit 12. In the second operating mode, the first microprocessor unit 11 is configured to take over a communication function from the second microprocessor unit 12, which involves communication via the communication system, and / or to send diagnostic information concerning the fault condition via the communication system. The diagnostic information indicates, in particular, that the second microprocessor unit 12 is in a fault condition.
[0032] Preferably, the second microprocessor unit 12 is configured to output fault condition information to the first microprocessor unit 11 in response to the fault condition. The device 2 is particularly configured to switch from the first operating mode to the second operating mode in response to the fault condition information.
[0033] For example, the second microprocessor unit 22, upon receiving a hard fault notification, can inform the first microprocessor unit 21, which is not affected by the hard fault, about the hard fault (using the fault state information), for example, through a corresponding configuration of a hard fault handler (especially in the second microprocessor unit 22). The fault state information is transmitted, in particular, via the internal communication link 14, for example, via GPIO, GSPI, SPI, and / or parallel interface. Subsequently, the "healthy" first microprocessor unit 21 can take over one or more tasks from the affected second microprocessor unit 22.
[0034] The described approach allows, in particular, the replacement of external monitoring of hard faults (of the second microprocessor unit 22) with self-detection, specifically self-diagnosis, of the second microprocessor unit 22 and active notification of the "healthy" microprocessor unit 21. Consequently, monitoring overhead in the first microprocessor unit 21, which would otherwise be required to monitor the second microprocessor unit 22, can be saved. This also reduces the complexity of software development for the first microprocessor unit 21. Specifically, it is not necessary for the first microprocessor unit 21 to monitor the second microprocessor unit 22 using polling and / or a watchdog timer.
[0035] Furthermore, the described approach enables a faster response of the first microprocessor unit 21 to the hard fault of the second microprocessor unit 22. Because the second microprocessor unit 22 actively informs the first microprocessor unit 21 about the hard fault, the cycle time of the polling process does not need to be waited for before the first microprocessor unit 21 is informed about the hard fault, unlike with periodic polling of the second microprocessor unit.
[0036] The fault state information conveniently indicates the fault state of the second microprocessor unit 12. The fault state information can be represented, for example, by a single bit, particularly in the case where the fault state information is transmitted via GPIO.
[0037] Optionally, the second microprocessor unit 12 can have an additional microprocessor besides the second microprocessor 32, and the additional microprocessor can be configured to monitor the second microprocessor 32 in order to detect the fault condition and preferably, in response to the fault condition, to transmit the fault condition information to the first microprocessor unit 11.
[0038] Preferably, the second microprocessor 32 is configured to detect its own fault state and to transmit the fault state information to the first microprocessor device 11, in particular the first microprocessor 31.
[0039] The fault condition is preferably a hard fault. In particular, the fault condition is a state in which the second microprocessor 32 of the second microprocessor unit 12 executes an invalid instruction or accesses an invalid memory address. In particular, the fault condition includes one or more of the following: corrupt memory, defective memory, failure of an internal communication bus (especially of the second microprocessor unit 12), implausibility of measured values, communication delay, an incorrect voltage value, and / or an initialization error of a software component.
[0040] The fault condition is, in particular, a critical fault in which the integrity of the second microprocessor unit 12 can no longer be guaranteed. For example, in the fault condition, it cannot be guaranteed that the second microprocessor unit 12 will correctly perform the protocol batch processing and / or be able to send diagnostic information. The protocol batch processing is, in particular, real-time protocol batch processing.
[0041] As explained above, in the second operating mode, the first microprocessor unit 11 can assume a communication function for the second microprocessor unit 12. Preferably, the first microprocessor unit 11 is configured to perform the communication function of at least part of the protocol batch processing of the communication taking place via the communication system from the second microprocessor unit 12. For example, the first microprocessor unit 11 is configured to perform the communication function of handling the response of a query from the higher-level controller 8 to the second microprocessor unit 12.
[0042] In particular, the response to the query already explained above is handled, which serves primarily to determine whether device 2 is addressable via the communication system. For example, the query is transmitted to device 2 via the communication path by means of a data telegram. In the second operating mode, the first microprocessor unit 11 receives the data telegram. Preferably, the query contained in the data telegram is not transmitted to the second microprocessor unit 12 in the second operating mode. The first microprocessor unit 11 defines the communication information as the response to the query, inserts the communication information into a data telegram, and sends the data telegram via the communication path.
[0043] In the second operating mode, the second microprocessor unit 12 is no longer involved in answering the query. Instead, the first microprocessor unit 11 answers the query.
[0044] Preferably, in the first operating mode, the first microprocessor unit 11 forwards communication information between the communication path and the second microprocessor unit 12 and preferably does not itself act as a logical participant in the communication system. Preferably, in the second operating mode, the first microprocessor unit 11 acts as a logical participant in the communication system and determines the content of the communication information to be transmitted via the communication system.
[0045] According to a preferred embodiment, the first microprocessor unit 11, in particular the first microprocessor unit 21, performs basic parameter processing and / or basic diagnostics in the first operating mode. Advantageously, in the first operating mode, the part of the protocol batch processing that is performed by the second microprocessor unit 12 is deactivated in the first microprocessor unit 11.
[0046] Preferably, in the second operating mode, the protocol batch processing and / or the processing of process data of the application and / or the performance of a diagnosis of the application and / or the processing of parameters of the application is deactivated in the second microprocessor device 12.
[0047] Optionally, in the second operating mode, the first microprocessor unit 11 can take over at least some of the application tasks - for example, at least some of the processing of process data and / or parameters and / or at least some of the diagnostics of the application - from the second microprocessor unit 12.
[0048] Furthermore, the first microprocessor unit 11 can be configured not to perform one or more tasks of the second microprocessor unit 12, for example, process data processing, in the second operating mode.
[0049] In particular, there is no complete redundancy between the first microprocessor unit 11 and the second microprocessor unit 12. The first microprocessor unit 11 is specifically not designed (and, for example, not capable in terms of performance) to take over all the tasks of the second microprocessor unit 12.
[0050] According to a preferred embodiment, the device 2 is configured to perform a reset of the second microprocessor unit 12 in response to an error condition. For example, the second microprocessor unit 12 detects its own error condition and performs the reset in response to this detection. During the reset, the second microprocessor unit 22 is advantageously restarted and / or, in particular, the second working memory 42 is erased and rewritten. Optionally, the second microprocessor unit 22 rewrites its non-volatile memory, in particular its EEPROM, after the reset. The reset is, in particular, a soft reset.
[0051] Optionally, the device 2 is configured to switch from the second operating mode to the first operating mode after the reset of the second microprocessor unit 12.
[0052] The following describes the operational process of the [company name] in the Fig. 1 device 2 shown according to the first embodiment will be explained.
[0053] Device 2 is operating in the first operating mode. A hard fault occurs in the second microprocessor 32. The second microprocessor 32 detects this hard fault and, in response to the hard fault, transmits the fault condition information to the first microprocessor 31 to inform it of the hard fault. In response to the fault condition information, device 2 switches from the first operating mode to the second operating mode, and the first microprocessor 31 sends the diagnostic information indicating the hard fault via the communication system to the communication device 3 and / or the higher-level controller 8. If the diagnostic information is sent to the communication device 3, the communication device 3 transmits the diagnostic information to the higher-level controller 8.
[0054] The following describes the operational process of the [company name] in the Fig. The device 2 shown in the second embodiment will be explained in detail below. The device 2 is designed with a particular focus on safety and, for this purpose, includes the third microprocessor unit 23.
[0055] The second microprocessor unit 22 is suitably configured to output the fault condition information to the third microprocessor unit 23 in response to the fault condition, and the first microprocessor unit 21 and / or the third microprocessor unit 23 is configured to take over the communication function from the second microprocessor unit 22 in the second operating mode and / or to send the diagnostic information concerning the fault condition via the communication system.
[0056] Device 2 is operating in the first operating mode. A hard fault occurs in the second microprocessor 32. The second microprocessor 32 detects this hard fault and, in response to the hard fault, transmits the fault condition information to the third microprocessor 33 to inform it of the hard fault. In response to the fault condition information, device 2 switches from the first operating mode to the second operating mode.
[0057] According to a first variant, the third microprocessor 33 informs the first microprocessor 31 about the hard fault of the second microprocessor 32, specifically in response to the fault condition information. The first microprocessor 31 sends the diagnostic information indicating the hard fault via the communication system to the communication device 3 and / or the higher-level controller 8. If the diagnostic information is sent to the communication device 3, the communication device 3 transmits the diagnostic information to the higher-level controller 8.
[0058] According to a second variant, the second microprocessor 33 sends the diagnostic information indicating the hard fault via the communication system to the communication device 3 and / or the higher-level controller 8, particularly in response to the fault condition information. If the diagnostic information is sent to the communication device 3, the communication device 3 transmits the diagnostic information to the higher-level controller 8.
Claims
[1] Device (2), in particular field device, for industrial automation, comprising a first microprocessor unit (11) for communicative integration of the device (2) into a communication system, in particular for communication with a higher-level controller (8), further comprising a second microprocessor unit (12) configured to define communication information to be sent via the communication system in a first operating mode of the device (2) and to transmit the communication information to the first microprocessor unit (11) so that the first microprocessor unit (11) sends the communication information via the communication system, wherein the device (2) is configured to switch from the first operating mode to a second operating mode in response to an error condition of the second microprocessor unit (12), and the first microprocessor unit (11) is configured to perform a communication function in the second operating mode,which concerns communication via the communication system, to be taken over by the second microprocessor unit (12) and / or to send diagnostic information concerning the fault condition via the communication system. [2] Device (2) according to claim 1, wherein the second microprocessor device (12) is configured to output fault state information to the first microprocessor device (11) in response to the fault state and the device (2) is configured to switch from the first operating mode to the second operating mode in response to the fault state information. [3] Device (2) according to claim 1 or 2, wherein the fault condition is a hard fault, in particular a condition in which a microprocessor (32) of the second microprocessor unit (12) executes an invalid instruction or accesses an invalid memory address, and / or wherein the fault condition comprises corrupt memory, defective memory, failure of an internal communication bus of the second microprocessor unit (12), implausibility of measured values, communication delay, incorrect voltage value and / or an initialization error of a software component. [4] Device (2) according to one of the preceding claims, wherein the first microprocessor unit (11) is configured to perform the communication function, at least part of a protocol batch processing of the communication taking place via the communication system, from the second microprocessor unit (). [5] Device (2) according to one of the preceding claims, wherein the first microprocessor device (11) is configured to perform the communication function of responding to a query from a higher-level control (8) to the second microprocessor device (12). [6] Device (2) according to one of the preceding claims, wherein the device (2) is configured to perform a reset of the second microprocessor device (12) in response to the fault condition. [7] Device (2) according to claim 6, wherein the device (2) is configured to switch from the second operating mode to the first operating mode after the reset. [8] Device (2) according to one of the preceding claims, wherein the first microprocessor arrangement (11) comprises a first microprocessor unit (21) having a first microprocessor (31), a first main memory (41) and a first microprocessor unit housing (51), and wherein the second microprocessor arrangement (12) comprises a second microprocessor unit (22) having a second microprocessor (32), a second main memory (42) and a second microprocessor unit housing (52). [9] Device (2) according to claim 8, wherein the first microprocessor device (11) is configured as the first microprocessor unit (21) and the second microprocessor device (12) is configured as the second microprocessor unit (22). [10] Device (2) according to claim 8, wherein the first microprocessor device (11) further comprises a third microprocessor unit (23) which has a third microprocessor (33), a third working memory (43) and a third microprocessor unit housing (53), wherein the second microprocessor unit (22) is configured to output fault condition information to the third microprocessor unit (23) in response to the fault condition, and the first microprocessor unit (21) and / or the third microprocessor unit (23) are configured to take over the communication function from the second microprocessor unit (22) in the second operating mode and / or to send the diagnostic information concerning the fault condition via the communication system. [11] Method for operating a device (2) according to any one of the preceding claims, comprising the steps: - in the first operating mode, by means of the second microprocessor unit (12), specifying the communication information to be sent via the communication system and transmitting the communication information to the first microprocessor unit (11), and, by means of the first microprocessor unit (11), sending the communication information via the communication system, - in response to a fault condition of the second microprocessor unit (12), switching from the first operating mode to the second operating mode, and - in the second operating mode, by means of the first microprocessor unit (11), taking over the communication function relating to communication via the communication system from the second microprocessor unit (12) and / or sending diagnostic information relating to the fault condition via the communication system.
Citation Information
Patent Citations
CN000108388108A
CN000213341751U
SELF-DIAGNOSIS DEVICE AND SELF-DIAGNOSIS SYSTEM
DE112022000759T5