Fine-grained reconciliation of local archives in master / master scenarios of servers of a technical installation

DE502021007332D1Active Publication Date: 2025-05-15SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502021007332
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-23
Publication Date
2025-05-15
Estimated Expiration
2041-08-23

AI Technical Summary

Technical Problem

In technical systems with redundant operator station servers, such as those in process or manufacturing systems, the occurrence of a 'master/master scenario' leads to independent filling of measurement archives, resulting in potential data loss and increased storage needs when trying to synchronize data post-recovery.

Method used

A guiding system that continuously stores data received from the technical system in respective data archives on each operator station server, taking into account the health status and role (master or slave) of each server, to effectively synchronize the data archives and ensure high-quality data storage.

Benefits of technology

The proposed solution ensures that only high-quality data is stored and synchronized across the redundant operator station servers, avoiding potential data loss and reducing storage requirements by prioritizing data from servers with better health states.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a control system for a technical plant, in particular a process or production plant, which has a first operator station server and a second operator station server, wherein one of these operator station servers is designed to operate as a master and the other of these operator station servers is designed to operate as a slave, and wherein the slave is designed to take over the function of the master in the event that the master fails, and wherein a first data archive is implemented on the first operator station server, and wherein a second data archive is implemented on the second operator station server, and wherein the first operator station server and the second operator station server are designed to receive data from the technical plant and to store it in the respective data archive, and wherein the first operator station server and the second operator station server are each designed toto determine a respective state of health. Furthermore, the invention relates to the use of a control system for operating a technical system and a method for operating a redundant control system for a technical system.

[0002] To improve availability in the event of hardware failures, components in technical systems, for example in the process industry, are often designed redundantly. If a component fails, it is immediately replaced by its redundant counterpart.

[0003] Especially for operator station servers in a process plant's control system, their availability plays a crucial role in the process plant's ability to operate and monitor the system. Operator station servers are typically operated in what's known as hot standby mode—that is, the process images of both operator station servers (master and slave) are always up to date and synchronized with each other.

[0004] Both the master and the slave receive value changes from the automation system. During synchronization, the slave compares the value changes received from the automation system with the value changes forwarded by the master M. If these match, the slave writes the value changes to the process image. If the master fails, the slave can immediately take over (without booting up or performing a general synchronization) as the new master. The value changes that have not yet been synchronized are then transferred to the process image for seamless operation and monitoring / history.

[0005] Such a known configuration is exemplified in FIG 1 shown. A control system 1 of a technical plant comprises a first operator station server 2 and a second operator station server 3. The control system 1 also comprises an operator station client 4, an automation device 5 and an I / O device 6. The automation device 5 (for example a SIMATIC PCS7 S7-400 from SIEMENS) and the I / O device (for example an ET 200 SP from SIEMENS) are connected to one another via a fieldbus 7 (which is based on PROFIBUS DP, for example). The two operator station servers 2, 3 are connected to the automation device 5 and to one another via a plant bus 8. The two operator station servers 2, 3 are connected to the operator station client 4 via a terminal bus 9. The plant bus 8 and the terminal bus 9 can, for example, be designed as Industrial Ethernet, without being limited to this.

[0006] The first Operator Station Server 2 and the second Operator Station Server 3 are designed to be redundant. The first Operator Station Server 1 acts as the master and is responsible for archiving, operation, and monitoring by the Operator Station Client 4. This means that the writing of measured values ​​(e.g., process values) by the automation device 5 or the setting of control values ​​by an operator only takes place on the master, which then performs the synchronization with the second Operator Station Server 4 as the slave.

[0007] The synchronization of the first Operator Station Server 2 (as master) with the second Operator Station Server 3 (as slave) is carried out as in FIG 1 shown) via the (fail-safe and correspondingly powerful) plant bus 8. In addition to information such as a process image, status information on the health index of the two Operator Station Servers 2, 3 (here bidirectional) is also exchanged in order to be able to coordinately appoint the Operator Station Server 2, 3 with the best health as the master.

[0008] As long as a master can be clearly identified, failures or partial failures of an Operator Station Server 2, 3 can be fully mitigated, ensuring the availability of the technical system. If so-called master / master scenarios occur under certain circumstances, the familiar configuration of redundantly designed Operator Station Servers 2, 3 with synchronization via the system bus 8 (even with 2-way redundancy) can lead to the problems described below.

[0009] A master / master scenario can occur if both operator station servers 2, 3 have lost contact with each other, for example because the system bus 8 is severed or an intermediate (in FIG 1 A network device (not shown) or a network card has failed. The consequence of this master / master scenario is that two measurement archives implemented on Operator Station Servers 2 and 3 are simultaneously filled with measurement data independently of each other. It is known that one of the two archives should be discarded after redundancy has been restored. This is usually the archive of the slave determined after the restoration. This can be correct, partially correct, or completely incorrect - depending on which time-varying faults occurred on Operator Station Servers 2 and 3 during the master / master scenario.

[0010] Other approaches pursue long-term archiving of both archives, but this leads to a huge increase in storage requirements. Furthermore, the resulting duplicate archive must be cleaned up again, because a clear "historical thread" must be present at the very latest when accessing archived data (e.g., when opening a trend display).

[0011] Known control systems that present plant images with different objects to an operator by means of several operator station servers are disclosed, for example, in EP 3 637 205 A1 and EP 3 736 647 A1.

[0012] The invention is based on the object of providing a redundantly designed control system for a technical system that enables improved archiving of data from the technical system.

[0013] This object is achieved by a control system for a technical plant, in particular a manufacturing or processing plant, having the features of claim 1. In addition, the object is achieved by a method for operating a redundantly designed control system for a technical plant having the features of claim 4. In addition, the object is achieved by the use of a control system for operating a technical plant according to claim 7. Advantageous further developments arise from the dependent claims.

[0014] A control system of the type described above is characterized according to the invention in that the first operator station server and the second operator station server are designed to continuously store in the respective data archive at specified time intervals the state of health of the respective operator station server when receiving and storing the data of the technical system, and whether the respective operator station server functions as a master or as a slave in the respective time interval.

[0015] In this context, a control system is understood to be a computer-aided technical system that includes functionalities for displaying, operating, and managing a technical system such as a manufacturing or production facility. In addition to the two operator station servers, the control system can include an operator station client and, for example, so-called process- or production-related components that serve to control actuators or sensors.

[0016] The technical plant can be a plant from the process industry, such as a chemical, pharmaceutical, petrochemical, or food and beverages industry. This also includes any plant from the production industry, such as factories where cars or goods of all kinds are produced. Technical plants suitable for carrying out the method according to the invention can also come from the field of energy generation. Wind turbines, solar systems, or power plants for energy generation are also encompassed by the term "technical plant."

[0017] An "Operator Station Server" is defined here as a server that centrally records data from an operating and monitoring system, as well as, typically, alarm and measured value archives from a control system of a technical plant, and makes them available to users. The Operator Station Server typically establishes a communication connection to automation systems (such as an automation device) of the technical plant and forwards data from the technical plant to so-called "Operator Station Clients," which are used to operate and monitor the operation of the individual functional elements of the technical plant.

[0018] The operator station server itself can have client functions to access the data (archives, messages, tags, variables) of other operator station servers. This allows images of the operation of a technical plant on the operator station server to be combined with variables from other operator station servers (server-to-server communication). The operator station server can be, but is not limited to, a SIMATIC PCS 7 Industrial Workstation Server from SIEMENS.

[0019] An operator is defined as a human operator of a technical system. The operator interacts with the technical system or its control system using special user interfaces and controls specific technical functions of the system. To this end, the operator can use the control system's operating and monitoring system with the operator station servers and, if present, an operator station client.

[0020] In the case of a process plant, the data from the technical system can be process data such as pressure values, temperature values, or fill level values, but also messages, for example. The data can represent raw data from sensors. However, it can also have been processed by a transmitter, a peripheral device, an automation device, or another device designed for this purpose.

[0021] The two redundantly designed operator station servers of the control system according to the invention continuously store the received data in a respective data archive. The data is stored at arbitrary, predefined time intervals. The two operator station servers are particularly advantageously configured to store a health status of the respective operator station server in the data archives, corresponding to the received data. The two operator station servers are capable of determining their own health status (server health) in a known manner. An exemplary disclosure regarding the transmission of information regarding the health status of servers can be found in WO 2014 / 099906 A1. The health status can be expressed, for example, on a scale of 1 (unhealthy) to 6 (healthy).

[0022] In addition to the health status, it is recorded for each time period whether the respective Operator Station Server performed the role of a master or a slave.

[0023] The inventive design of the control system or its operator station server allows the data archives of the two operator station servers to be effectively synchronized by optimizing their health status and / or their function as master / server.

[0024] Preferably, the control system is configured to synchronize the two data archives of the first operator station server and the second operator station server after storing the data, the health status, and the master / slave function in such a way that, after synchronization, the data of the operator station server with the best health status in the respective time period is stored in both data archives for each time period. In other words, for each time period, the data of the operator station server with the higher health status in the time period is selected for merging the data archives.

[0025] Such synchronization of the two redundantly designed operator station servers makes it possible to merge the data archives in such a fine-grained manner that both data archives contain precisely the data from the time periods that provide the higher-quality data.

[0026] Particularly preferably, the control system is designed to synchronize the two data archives of the first operator station server and the second operator station server after the occurrence of a master / master scenario in a time period as previously explained. The term "master / master scenario" means that both the first operator station server and the second operator station server have performed the function of the master in one (or more) time periods. This can occur, for example, if a connection between the two operator station servers (temporarily) fails and the two operator station servers, lacking knowledge of the function of the other operator station server, assume the function of the master in order to maintain operation of the technical system.

[0027] The above-stated object is further achieved by a method for operating a redundantly designed control system for a technical plant, in particular a process or production plant, which has a first operator station server and a second operator station server, wherein one of these operator station servers is designed to operate as a master and the other of these operator station servers is designed to operate as a slave, and wherein the slave is designed to take over the function of the master in the event that the master fails, and wherein a first data archive is implemented on the first operator station server, and wherein a second data archive is implemented on the second operator station server, and wherein the first operator station server and the second operator station server are designed to receive data from the technical plant and store it in the respective data archive,and wherein the first operator station server and the second operator station server are each configured to determine a respective health status.,

[0028] The procedure includes the following steps: a) Continuously receiving data from the technical system and storing the data in the respective archives, whereby the data is divided into specific time periods, b) For each time period, determining the respective health status by each of the two operator station servers and, for each time period, assigning the health status of the respective operator station server to the data, c) For each time period, storing in the respective data archive whether the respective operator station server functions as master or slave in the time period.

[0029] Preferably, the two data archives of the first operator station server and the second operator station server are synchronized after storing the data, the health status and the master / slave function in such a way that after synchronization, the data of the operator station server that has the best health status in the respective time period is stored in both data archives for each time period.

[0030] Particularly preferably, the two data archives of the first operator station server and the second operator station server are synchronized after the occurrence of a master / master scenario in a time period as previously explained.

[0031] The task explained above is also solved by using a control system to operate a technical plant, in particular a manufacturing or process plant.

[0032] The above-described properties, features, and advantages of this invention, as well as the manner in which they are achieved, will become clearer and more readily understood in connection with the following description of an embodiment, which is explained in more detail in conjunction with the drawings. FIG 2 shows a content of data archives of operator station servers according to a first aspect; FIG 3 shows a content of data archives of operator station servers according to a second aspect; and FIG 4 shows a control system according to the invention in a schematic diagram.

[0033] In FIG 2 The contents of a first data archive 10 of a first operator station server OS1 and the contents of a second data archive 11 of a second operator station server OS1' are shown. The two operator station servers OS1, OS1' are part of a control system for a technical plant and are designed for redundant operation.

[0034] On the left side of FIG 2 The contents of the two data archives 10, 11 are shown before synchronization of the two data archives 10, 11. The first line of the data archives 10, 11 shows whether the corresponding operator station server OS1, OS1' functioned as master (M) or slave (S) during the respective time period t1, t2, t3, t4. The second line shows the health status of the respective operator station server OS1, OS1'. The value 5 indicates a health status of "healthy" or "very good," while the value 1 indicates a health status of "unhealthy" or "very poor."

[0035] The third line indicates which Operator Station Server OS1, OS1' the values ​​stored in the respective data archive 10, 11 originate from. This depends on whether an Operator Station Server OS1, OS1' functions as a master or slave. For example, for the data archive 10 of the first Operator Station Server OS1, all data (e.g., process data) originate from the first Operator Station Server OS1 itself (indicated by "A1"), since this server acted as the master in all four time periods.

[0036] The second operator station server OS1' acted as a slave in the first time period t1 and in the third time period t3, which is why it stored the data of the first operator station server 10 in its data archive 11. In the second time period t2 and in the third time period t3, it acted as a master, which is why it stored its own data in the second data archive 11 (marked by "A1'"). It can be seen that both operator station servers OS1, OS1' z.B. due to a network failure, acted as master in the second time period t2 and the third time period t3. This is referred to as a master / master scenario. After the network failure is resolved, both operator station servers OS1, OS1' must be resynchronized in order to resume redundant operation.

[0037] It is known that when reuniting or synchronizing the two Operator Station Servers OS1, OS1' (in FIG 2 shown on the right side of the arrow), when the data archives 10, 11 are synchronized, only the values ​​of the data archive 10, 11 are (completely) adopted (compare the respective third line), which belongs to the operator station server OS1, OS1', which emerges as the master after the reunification. In the present example, this is the first operator station server OS1. It can be seen that in both data archives 10, 11, the values ​​of the first operator station server OS1, OS1' are adopted for the third time period t3, even though the first operator station server OS1 has a very poor health status (value 1) in the time period t3. The adopted data is therefore of potentially poor quality. The higher quality data from the second operator station server OS1' is discarded.

[0038] In FIG 3 Two data archives 10, 11 of operator station servers OS1, OS1' are shown, which are part of a control system according to the invention. In contrast to the FIG 2 The known methods explained in the presentation in FIG 3 illustrates that when synchronizing the Operator Station Server OS1, OS1' the respective health status (second line) and the function as master or slave (third line) are taken into account.

[0039] The overlapping master function master / master in the second time period t2 triggers a synchronization of the two data archives 10, 11. In the third time period t3, in which the first operator station server OS1 is in a very poor health state, the (process) values ​​for both data archives 10, 11 (symbolized by A1') that the second, healthy operator station server OS1' received in the time period t3 are adopted during synchronization.

[0040] This design of the control system or this method for operating a technical system can efficiently prevent potentially higher-quality values ​​from being lost.

[0041] In FIG 4 A part of a control system 12 according to the invention for a technical system designed as a process plant, i.e., as a process engineering plant, is shown. The control system 12 comprises a first operator station server 13, a second operator station server (not shown), and an operator station client 14.

[0042] The first operator station server 13, the second operator station server and the operator station client 14 are connected to each other via a terminal bus 15 and optionally to other components of the control system 12, such as an engineering station server, not shown.

[0043] A user or operator can access the operator station server 13 for the purpose of operating and monitoring via the operator station client 14 using the terminal bus 15. The terminal bus 15 can, for example, be configured as Industrial Ethernet, but is not limited to this.

[0044] The two Operator Station Servers 13, 14 are identically constructed, which is why FIG 4 only the structure of the first operator station server 13 will be discussed (hereinafter referred to as "operator station server 13"). The operator station server 13 has a device interface 16 connected to a plant bus 17. Via this device interface 16, the operator station server 13 can communicate with an automation device 18 as well as with optionally available additional components of the process plant, such as peripheral devices (not shown). The plant bus 17 can, for example, be designed as Industrial Ethernet, without being limited thereto. The automation device 18 can be connected to any number of subsystems (not shown).

[0045] A redundancy service 19, a process image 20, and a data archive 21 are implemented (among other things) on the operator station server 13. The operator station client 14 is designed to display a plant image for operating and monitoring the process plant, which will not be discussed further here.

[0046] The automation device 18 is designed to control and monitor the automation of the process plant. For this purpose, a control program is implemented on the automation device 18, which was loaded onto the automation device 18 as part of the process plant automation configuration. The automation device 18 receives process data from the process plant and transmits it to the process image 20 of the operator station server 13.

[0047] The redundancy service 19 determines a health index of the operator station server 13 in a conventional manner, stores it in the process image 20 of the operator station server 13, and archives it in the data archive 21. This makes the health index available after the termination of a master / master scenario of the two redundantly configured operator station servers 13 when merging / synchronizing the data archives 21. Furthermore, the functions performed by the operator station server 13 during a specific time period are stored as "server states" (master / slave) in the process image 20 and archived in the data archive 21 in order to precisely localize the time period for a master / master scenario (OS1=M, OS1'=M).

[0048] Based on the archived health statuses and the functions of the individual Operator Station Servers 13, a merge service in the data archives 21 of the two Operator Station Servers 13 carries out the FIG 3 After comparing the data archives 21, the content of the two data archives 21 is as shown in FIG 3 shown, are again identical. From this moment on, the data from the two data archives 21 can be transferred to a central archive (not shown) of the control system 12 for long-term archiving. If contents of the (local) data archives 21 have already been transferred to the central archive, they can also be discarded after the (local) data archives 21 have been compared.

[0049] Overall, the control system 12 according to the invention and the associated method enable a fine-grained comparison of the data archives 21 with the best possible process data. The invention can contribute to greater reliability and improved operability of the control system of the technical plant.

Claims

1. Control system (12) for a technical installation, in particular process or manufacturing installation, which has a first operator station server (13) and a second operator station server, wherein one of these operator station servers (13) is embodied to operate as master and the other of these operator station servers (13) is embodied to operate as slave, and wherein the slave is embodied to inherit the function of master in the event that the master fails, characterised in that a first data archive (21) is implemented on the first operator station server (13), and a second data archive is implemented on the second operator station server, the first operator station server (13) and the second operator station server are embodied to receive data of the technical installation and to record it in the respective data archive (21), the first operator station server (13) and the second operator station server are in each case embodied to ascertain a respective health state, and the first operator station server (13) and the second operator station server are embodied to continuously record in the respective data archive (21), at specified time intervals (t1, t2, t3, t4, t5, t6), which inherent health state the respective operator station server (13) has when receiving and recording the data of the technical installation, and whether the respective operator station server (13) acts as master or as slave in the respective time interval (t1, t2, t3, t4, t5, t6).

2. Control system (1) according to claim 1, in which the control system (12) is embodied to synchronise the two data archives (21) of the first operator station server (13) and the second operator station server following the storing of the data, the health state and the master / slave function in such a manner that, following the synchronisation in both data archives (21), for each time interval the data of the operator station server (13) that has the best health state in the respective time interval (t1, t2, t3, t4, t5, t6) is recorded.

3. Control system (12) according to claim 2, in which the control system (12) is embodied to synchronise the two data archives (21) of the first operator station server (13) and the second operator station server, following the occurrence of a master / master scenario in a time interval (t1, t2, t3, t4, t5, t6), according to claim 2.

4. Method for operating a control system (12) designed with redundancy for a technical installation, in particular process or manufacturing installation, which has a first operator station server (13) and a second operator station server, wherein one of these operator station servers (13) is embodied to operate as master and the other of these operator station servers (13) is embodied to operate as slave, and wherein the slave is embodied to inherit the function of master in the event that the master fails, and wherein a first data archive (21) is implemented on the first operator station server (13), and wherein a second data archive is implemented on the second operator station server, and wherein the first operator station server (13) and the second operator station server are embodied to receive data of the technical installation and to record it in the respective data archive (21), and wherein the first operator station server (13) and the second operator station server are in each case embodied to ascertain a respective inherent health state, the method comprising: a) continuously receiving data of the technical installation and recording the data in the respective data archives (21), wherein the data is divided into certain time intervals (t1, t2, t3, t4, t5, t6), b) for each time interval (t1, t2, t3, t4, t5, t6), in each case ascertaining the respective health state by way of each of the two operator station servers (13) and, for each time interval (t1, t2, t3, t4, t5, t6), assigning the inherent health state of the respective operator station server (13) to the data, c) for each time interval (t1, t2, t3, t4, t5, t6), in each case recording in the respective data archive (21) whether the respective operator station server (13) acts as master or as slave in the time interval.

5. Method according to claim 4, in which the data archives (21) of the first operator station server (13) and the second operator station server, following the storing of the data, the health state and the master / slave function, are synchronised in such a manner that, following the synchronisation in both data archives (21), for each time interval (t1, t2, t3, t4, t5, t6) the data of the operator station server (13) that has the best health state in the respective time interval (t1, t2, t3, t4, t5, t6) is recorded.

6. Method according to claim 5, in which the data archives (21) of the first operator station server (13) and the second operator station server, following the occurrence of a master / master scenario in a time interval (t1, t2, t3, t4, t5, t6), are synchronised according to claim 5.

7. Use of a control system (12) according to one of claims 1 to 3 for operation of a technical installation, in particular manufacturing or process installation.